starting build "08f2e8db-12fb-423e-a139-49e97e3c4b6a" FETCHSOURCE BUILD Starting Step #0 Step #0: Already have image (with digest): gcr.io/cloud-builders/git Step #0: Cloning into 'oss-fuzz'... Finished Step #0 Starting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd" Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Already have image (with digest): gcr.io/cloud-builders/docker Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Sending build context to Docker daemon 5.12kB Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Step 1/5 : FROM gcr.io/oss-fuzz-base/base-builder-rust Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": latest: Pulling from oss-fuzz-base/base-builder-rust Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b549f31133a9: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6e628c8ef21f: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": f53ab3868c1c: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": a55801351b59: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 3bb5606c96f9: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 04679461c0a4: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6202956b2fc8: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6de59df1d969: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": e94fca21036a: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": f06e7a843c98: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6202956b2fc8: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": e94fca21036a: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6de59df1d969: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 2e63cbce29d6: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": f06e7a843c98: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 8fce8f94211f: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c26bd18729a4: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 1425e2da3d0f: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c26bd18729a4: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 24218bda6367: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b31a426d2518: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 84cf1ab1e9f9: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 2c2b7d72eac9: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 24218bda6367: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 1425e2da3d0f: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 710430df408b: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b31a426d2518: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 26ec0ac61159: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 84cf1ab1e9f9: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 2c2b7d72eac9: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 710430df408b: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 557ca0d2b5c7: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 986c94e54976: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": cbac95d8da00: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 5a7a3f93fe73: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 26ec0ac61159: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 7a93d1a7fb44: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": dac0759625b9: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": d1cb5c7641a2: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 02eb0541e91a: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 986c94e54976: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 52ae1ac2675c: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 5129b6a32636: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 5a7a3f93fe73: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": f712ebbbd8d9: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 0df20a1baa3e: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": cbac95d8da00: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6dd08d591949: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c9de98ed230e: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c4d8394d753c: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 5da0bdfffdca: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 08d89138e853: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b9b3a87688da: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 72ea7412c90a: Pulling fs layer Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 7a93d1a7fb44: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": dac0759625b9: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": d1cb5c7641a2: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c9de98ed230e: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6dd08d591949: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 02eb0541e91a: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c4d8394d753c: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 5da0bdfffdca: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 0df20a1baa3e: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 08d89138e853: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 5129b6a32636: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 557ca0d2b5c7: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 72ea7412c90a: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b9b3a87688da: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": f712ebbbd8d9: Waiting Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 3bb5606c96f9: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 3bb5606c96f9: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": f53ab3868c1c: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": f53ab3868c1c: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6202956b2fc8: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6de59df1d969: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6de59df1d969: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b549f31133a9: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b549f31133a9: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": a55801351b59: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": a55801351b59: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 2e63cbce29d6: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 2e63cbce29d6: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 8fce8f94211f: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 8fce8f94211f: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 1425e2da3d0f: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 1425e2da3d0f: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c26bd18729a4: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c26bd18729a4: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6e628c8ef21f: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6e628c8ef21f: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": f06e7a843c98: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": f06e7a843c98: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b31a426d2518: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b31a426d2518: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 24218bda6367: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 24218bda6367: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 2c2b7d72eac9: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 2c2b7d72eac9: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 710430df408b: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 710430df408b: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 84cf1ab1e9f9: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 84cf1ab1e9f9: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 26ec0ac61159: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 26ec0ac61159: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 986c94e54976: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 986c94e54976: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 557ca0d2b5c7: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 557ca0d2b5c7: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": cbac95d8da00: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": cbac95d8da00: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 5a7a3f93fe73: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b549f31133a9: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 7a93d1a7fb44: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 7a93d1a7fb44: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": d1cb5c7641a2: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": dac0759625b9: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 02eb0541e91a: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 02eb0541e91a: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 52ae1ac2675c: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 52ae1ac2675c: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 0df20a1baa3e: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": f712ebbbd8d9: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 5129b6a32636: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 5129b6a32636: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": e94fca21036a: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": e94fca21036a: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c9de98ed230e: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c9de98ed230e: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6dd08d591949: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6dd08d591949: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 5da0bdfffdca: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c4d8394d753c: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b9b3a87688da: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b9b3a87688da: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 08d89138e853: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 08d89138e853: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 04679461c0a4: Verifying Checksum Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 04679461c0a4: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6e628c8ef21f: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": f53ab3868c1c: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 72ea7412c90a: Download complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": a55801351b59: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 3bb5606c96f9: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 04679461c0a4: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6202956b2fc8: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6de59df1d969: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": e94fca21036a: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": f06e7a843c98: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 2e63cbce29d6: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 8fce8f94211f: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c26bd18729a4: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 1425e2da3d0f: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 24218bda6367: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b31a426d2518: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 84cf1ab1e9f9: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 2c2b7d72eac9: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 710430df408b: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 26ec0ac61159: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 557ca0d2b5c7: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 986c94e54976: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": cbac95d8da00: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 5a7a3f93fe73: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 7a93d1a7fb44: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": dac0759625b9: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": d1cb5c7641a2: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 02eb0541e91a: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 52ae1ac2675c: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 5129b6a32636: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": f712ebbbd8d9: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 0df20a1baa3e: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 6dd08d591949: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c9de98ed230e: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": c4d8394d753c: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 5da0bdfffdca: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 08d89138e853: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": b9b3a87688da: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": 72ea7412c90a: Pull complete Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Digest: sha256:433319ea1a6bbea6c1db1915a5d385021908cc62026d9f0efda2270ef6060de3 Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Status: Downloaded newer image for gcr.io/oss-fuzz-base/base-builder-rust:latest Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": ---> 6a3c6c2f7901 Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Step 2/5 : RUN rustup toolchain install nightly Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": ---> Running in 2da00e46e89f Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": info: syncing channel updates for nightly-x86_64-unknown-linux-gnu Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": info: latest update on 2026-09-15 for version 1.100.0-nightly (574ff7d98 2026-09-14) Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": info: downloading 3 components Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd":  Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": nightly-x86_64-unknown-linux-gnu installed - rustc 1.100.0-nightly (574ff7d98 2026-09-14) Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": info: checking for self-update (current version: 1.29.0) Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": info: downloading self-update (new version: 1.29.1) Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Removing intermediate container 2da00e46e89f Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": ---> 249cc6380b1d Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Step 3/5 : RUN git clone --depth 1 https://github.com/typst/typst.git typst Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": ---> Running in 65b44a0771f4 Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Cloning into 'typst'... Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Removing intermediate container 65b44a0771f4 Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": ---> 10b2bb556753 Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Step 4/5 : WORKDIR typst Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": ---> Running in 82194e4c75b1 Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Removing intermediate container 82194e4c75b1 Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": ---> a4cf0428731c Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Step 5/5 : COPY build.sh $SRC/ Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": ---> df4ca9e77ffe Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Successfully built df4ca9e77ffe Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Successfully tagged gcr.io/oss-fuzz/typst:latest Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd": Successfully tagged us-central1-docker.pkg.dev/oss-fuzz/unsafe/typst:latest Finished Step #1 - "build-407ed8dc-ef22-4a46-8ce9-facc6d7465fd" Starting Step #2 - "srcmap" Step #2 - "srcmap": Already have image: gcr.io/oss-fuzz/typst Step #2 - "srcmap": ++ tempfile Step #2 - "srcmap": + SRCMAP=/tmp/fileeWq0DN Step #2 - "srcmap": + echo '{}' Step #2 - "srcmap": + PATHS_TO_SCAN=/src Step #2 - "srcmap": + [[ rust == \g\o ]] Step #2 - "srcmap": ++ find /src -name .git -type d Step #2 - "srcmap": + for DOT_GIT_DIR in $(find $PATHS_TO_SCAN -name ".git" -type d) Step #2 - "srcmap": ++ dirname /src/typst/.git Step #2 - "srcmap": + GIT_DIR=/src/typst Step #2 - "srcmap": + cd /src/typst Step #2 - "srcmap": ++ git config --get remote.origin.url Step #2 - "srcmap": + GIT_URL=https://github.com/typst/typst.git Step #2 - "srcmap": ++ git rev-parse HEAD Step #2 - "srcmap": + GIT_REV=586e1bd43fae6c9a973218163d3165c53ab8d16d Step #2 - "srcmap": + jq_inplace /tmp/fileeWq0DN '."/src/typst" = { type: "git", url: "https://github.com/typst/typst.git", rev: "586e1bd43fae6c9a973218163d3165c53ab8d16d" }' Step #2 - "srcmap": ++ tempfile Step #2 - "srcmap": + F=/tmp/fileFVZoh9 Step #2 - "srcmap": + cat /tmp/fileeWq0DN Step #2 - "srcmap": + jq '."/src/typst" = { type: "git", url: "https://github.com/typst/typst.git", rev: "586e1bd43fae6c9a973218163d3165c53ab8d16d" }' Step #2 - "srcmap": + mv /tmp/fileFVZoh9 /tmp/fileeWq0DN Step #2 - "srcmap": ++ find /src -name .svn -type d Step #2 - "srcmap": ++ find /src -name .hg -type d Step #2 - "srcmap": + '[' '' '!=' '' ']' Step #2 - "srcmap": + cat /tmp/fileeWq0DN Step #2 - "srcmap": + rm /tmp/fileeWq0DN Step #2 - "srcmap": { Step #2 - "srcmap": "/src/typst": { Step #2 - "srcmap": "type": "git", Step #2 - "srcmap": "url": "https://github.com/typst/typst.git", Step #2 - "srcmap": "rev": "586e1bd43fae6c9a973218163d3165c53ab8d16d" Step #2 - "srcmap": } Step #2 - "srcmap": } Finished Step #2 - "srcmap" Starting Step #3 - "compile-libfuzzer-coverage-x86_64" Step #3 - "compile-libfuzzer-coverage-x86_64": Already have image (with digest): gcr.io/cloud-builders/docker Step #3 - "compile-libfuzzer-coverage-x86_64": --------------------------------------------------------------- Step #3 - "compile-libfuzzer-coverage-x86_64": vm.mmap_rnd_bits = 28 Step #3 - "compile-libfuzzer-coverage-x86_64": Compiling libFuzzer to /usr/lib/libFuzzingEngine.a... done. Step #3 - "compile-libfuzzer-coverage-x86_64": --------------------------------------------------------------- Step #3 - "compile-libfuzzer-coverage-x86_64": CC=clang Step #3 - "compile-libfuzzer-coverage-x86_64": CXX=clang++ Step #3 - "compile-libfuzzer-coverage-x86_64": CFLAGS=-O1 -fno-omit-frame-pointer -gline-tables-only -Wno-error=incompatible-function-pointer-types -Wno-error=int-conversion -Wno-error=deprecated-declarations -Wno-error=implicit-function-declaration -Wno-error=implicit-int -Wno-error=unknown-warning-option -Wno-error=vla-cxx-extension -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION -fprofile-instr-generate -fcoverage-mapping -pthread -Wl,--no-as-needed -Wl,-ldl -Wl,-lm -Wno-unused-command-line-argument Step #3 - "compile-libfuzzer-coverage-x86_64": CXXFLAGS=-O1 -fno-omit-frame-pointer -gline-tables-only -Wno-error=incompatible-function-pointer-types -Wno-error=int-conversion -Wno-error=deprecated-declarations -Wno-error=implicit-function-declaration -Wno-error=implicit-int -Wno-error=unknown-warning-option -Wno-error=vla-cxx-extension -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION -fprofile-instr-generate -fcoverage-mapping -pthread -Wl,--no-as-needed -Wl,-ldl -Wl,-lm -Wno-unused-command-line-argument -stdlib=libc++ Step #3 - "compile-libfuzzer-coverage-x86_64": RUSTFLAGS=--cfg fuzzing -Cdebuginfo=1 -Cforce-frame-pointers -Cinstrument-coverage -C link-arg=-lc++ Step #3 - "compile-libfuzzer-coverage-x86_64": --------------------------------------------------------------- Step #3 - "compile-libfuzzer-coverage-x86_64": + cd tests/fuzz Step #3 - "compile-libfuzzer-coverage-x86_64": + cargo +nightly fuzz build -O --debug-assertions Step #3 - "compile-libfuzzer-coverage-x86_64": warning: unused workspace dependency `ctrlc` Step #3 - "compile-libfuzzer-coverage-x86_64": --> Cargo.toml:54:1 Step #3 - "compile-libfuzzer-coverage-x86_64": | Step #3 - "compile-libfuzzer-coverage-x86_64": 54 | ctrlc = "3.4.1" Step #3 - "compile-libfuzzer-coverage-x86_64": | ^^^^^ Step #3 - "compile-libfuzzer-coverage-x86_64": | Step #3 - "compile-libfuzzer-coverage-x86_64": = note: `cargo::unused_workspace_dependencies` is set to `warn` by default Step #3 - "compile-libfuzzer-coverage-x86_64": help: consider removing the workspace dependency `ctrlc` Step #3 - "compile-libfuzzer-coverage-x86_64": warning: unused workspace dependency `typst-cli` Step #3 - "compile-libfuzzer-coverage-x86_64": --> Cargo.toml:21:1 Step #3 - "compile-libfuzzer-coverage-x86_64": | Step #3 - "compile-libfuzzer-coverage-x86_64": 21 | typst-cli = { path = "crates/typst-cli", version = "0.15.1" } Step #3 - "compile-libfuzzer-coverage-x86_64": | ^^^^^^^^^ Step #3 - "compile-libfuzzer-coverage-x86_64": | Step #3 - "compile-libfuzzer-coverage-x86_64": help: consider removing the workspace dependency `typst-cli` Step #3 - "compile-libfuzzer-coverage-x86_64": warning: unused workspace dependency `typst-ide` Step #3 - "compile-libfuzzer-coverage-x86_64": --> Cargo.toml:24:1 Step #3 - "compile-libfuzzer-coverage-x86_64": | Step #3 - "compile-libfuzzer-coverage-x86_64": 24 | typst-ide = { path = "crates/typst-ide", version = "0.15.1" } Step #3 - "compile-libfuzzer-coverage-x86_64": | ^^^^^^^^^ Step #3 - "compile-libfuzzer-coverage-x86_64": | Step #3 - "compile-libfuzzer-coverage-x86_64": help: consider removing the workspace dependency `typst-ide` Step #3 - "compile-libfuzzer-coverage-x86_64": warning: workspace (manifest) generated 3 warnings Step #3 - "compile-libfuzzer-coverage-x86_64": warning: missing `[lints]` to inherit `[workspace.lints]` Step #3 - "compile-libfuzzer-coverage-x86_64": --> crates/typst/Cargo.toml Step #3 - "compile-libfuzzer-coverage-x86_64": = note: `cargo::missing_lints_inheritance` is set to `warn` by default Step #3 - "compile-libfuzzer-coverage-x86_64": help: to inherit `workspace.lints, add: Step #3 - "compile-libfuzzer-coverage-x86_64": | Step #3 - "compile-libfuzzer-coverage-x86_64": 34 ~ typst-svg = { workspace = true } Step #3 - "compile-libfuzzer-coverage-x86_64": 35 + [lints] Step #3 - "compile-libfuzzer-coverage-x86_64": 36 + workspace = true Step #3 - "compile-libfuzzer-coverage-x86_64": | Step #3 - "compile-libfuzzer-coverage-x86_64": help: to clarify your intent to not inherit, add: Step #3 - "compile-libfuzzer-coverage-x86_64": | Step #3 - "compile-libfuzzer-coverage-x86_64": 34 ~ typst-svg = { workspace = true } Step #3 - "compile-libfuzzer-coverage-x86_64": 35 + [lints] Step #3 - "compile-libfuzzer-coverage-x86_64": | Step #3 - "compile-libfuzzer-coverage-x86_64": warning: `typst` (manifest) generated 1 warning Step #3 - "compile-libfuzzer-coverage-x86_64":  Updating crates.io index Step #3 - "compile-libfuzzer-coverage-x86_64":  Updating git repository `https://github.com/LaurenzV/hayro` Step #3 - "compile-libfuzzer-coverage-x86_64":  Updating git repository `https://github.com/typst/typst-assets` Step #3 - "compile-libfuzzer-coverage-x86_64":  Updating git repository `https://github.com/typst/typst-dev-assets` Step #3 - "compile-libfuzzer-coverage-x86_64":  Updating git repository `https://github.com/LaurenzV/krilla` Step #3 - "compile-libfuzzer-coverage-x86_64":  Updating git repository `https://github.com/linebender/vello` Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloading crates ... Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded phf_generator v0.13.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded phf v0.13.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded phf_shared v0.13.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded adler2 v2.0.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded phf_macros v0.13.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded heck v0.5.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unicode-properties v0.1.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded rustc-hash v2.1.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded same-file v1.0.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded rand_chacha v0.3.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded strum v0.27.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded serde_spanned v0.6.8 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded siphasher v1.0.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unicode-vo v0.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded xmlwriter v0.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded itoa v1.0.14 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded linked-hash-map v0.5.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded num-conv v0.2.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded stable_deref_trait v1.2.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded imagesize v0.14.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_locale_fallback_data v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_provider_blob v2.2.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded idna_adapter v1.2.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded mutate_once v0.1.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded potential_utf v0.1.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded scopeguard v1.2.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded toml_datetime v0.6.8 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded version_check v0.9.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded powerfmt v0.2.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unic-langid-macros-impl v0.9.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded tinyvec_macros v0.1.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unicode-ccc v0.4.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unicode-math-class v0.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded proc-macro-hack v0.5.20+deprecated Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded typed-arena v2.0.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unicode-bidi-mirroring v0.4.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unic-langid-macros v0.9.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded approx v0.5.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded percent-encoding v2.3.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded roman-numerals-rs v3.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unscanny v0.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded ciborium-ll v0.2.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded zerofrom-derive v0.1.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded utf16_iter v1.0.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded utf8_iter v1.0.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded write16 v1.0.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded zerofrom v0.1.8 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unic-langid v0.9.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded arrayref v0.3.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_locale_fallback v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded infer v0.19.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded jobserver v0.1.32 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded libz-rs-sys v0.5.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded linebender_resource_handle v0.1.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded num-integer v0.1.46 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded strict-num v0.1.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded xmp-writer v0.3.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded parking_lot_core v0.9.10 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded simd-adler32 v0.3.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded quick-error v2.0.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded time-core v0.1.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded palette_derive v0.7.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded walkdir v2.5.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded wasmi_collections v1.0.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded writeable v0.6.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded yoke-derive v0.8.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded chinese-number v0.7.8 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded lipsum v0.9.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded litemap v0.8.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded lock_api v0.4.12 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded memmap2 v0.9.11 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded once_cell v1.21.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded parking_lot v0.12.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded paste v1.0.15 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded peniko v0.6.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded ppv-lite86 v0.2.20 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded rand_core v0.6.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded rgb v0.8.53 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded semver v1.0.25 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded serde_path_to_error v0.1.20 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded shlex v1.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded simplecss v0.2.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded slab v0.4.11 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded stacker v0.1.21 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded synstructure v0.13.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded thiserror v2.0.18 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unicode-script v0.5.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded yaml-rust v0.4.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded zerocopy-derive v0.7.35 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded zerovec-derive v0.11.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded zune-core v0.5.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded arbitrary v1.4.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded arrayvec v0.7.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded autocfg v1.4.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded color_quant v1.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_locale v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_normalizer_data v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_provider v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded image-webp v0.2.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded indexmap v2.12.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded kamadak-exif v0.6.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded log v0.4.29 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded miniz_oxide v0.8.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded num-traits v0.2.19 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded pico-args v0.5.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded polycool v0.4.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unsafe-libyaml v0.2.11 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded wasmi_core v1.0.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded wasmi_ir v1.0.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded weezl v0.1.12 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded yoke v0.8.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded byteorder v1.5.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded chinese-variant v1.1.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded font-types v0.12.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded fontconfig-parser v0.5.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_collections v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_locale_core v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded quote v1.0.45 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded thiserror-impl v2.0.18 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded url v2.5.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded zerotrie v0.2.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded zune-jpeg v0.5.15 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded bytemuck_derive v1.10.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded core_maths v0.1.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded deranged v0.5.8 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded displaydoc v0.2.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded ecow v0.2.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded enum-ordinalize v4.3.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded flate2 v1.1.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_properties v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded libfuzzer-sys v0.4.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded libm v0.2.11 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded memchr v2.8.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded num-bigint v0.4.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded pixglyph v0.6.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded ryu v1.0.19 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded spin v0.9.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded strum_macros v0.27.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded subsetter v0.2.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded svgtypes v0.16.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded thin-vec v0.2.18 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded time-macros v0.2.32 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded tinystr v0.8.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded tinyvec v1.8.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unicode-bidi v0.3.18 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unicode-ident v1.0.16 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unicode-segmentation v1.12.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded bincode v1.3.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded ciborium v0.2.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded fnv v1.0.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded half v2.4.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_properties_data v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded idna v1.0.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded postcard v1.1.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded proc-macro2 v1.0.101 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded psm v0.1.24 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded roxmltree v0.20.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded roxmltree v0.21.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded serde_core v1.0.228 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded serde_derive v1.0.228 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded serde_yaml v0.9.34+deprecated Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded slotmap v1.0.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded smallvec v1.15.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded tiny-skia-path v0.12.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded toml v0.8.19 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded usvg v0.47.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded zerocopy v0.7.35 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded zerovec v0.11.8 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded az v1.2.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded bit-set v0.8.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded by_address v1.2.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded crossbeam-utils v0.8.21 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded fastrand v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded fontdb v0.23.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded form_urlencoded v1.2.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded kurbo v0.13.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded plist v1.8.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded rayon-core v1.13.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded winnow v0.7.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded zlib-rs v0.5.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded aho-corasick v1.1.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded bitflags v2.11.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded citationberg v0.7.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded float-cmp v0.9.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded font-types v0.11.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded moxcms v0.8.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded rand v0.8.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded color v0.3.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded comemo-macros v0.5.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded csv-core v0.1.11 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded data-url v0.3.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded fearless_simd v0.4.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded glidesort v0.1.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded guillotiere v0.7.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded palette v0.7.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded resvg v0.47.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded serde v1.0.228 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded write-fonts v0.48.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded comemo v0.5.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded toml_edit v0.22.23 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unic-langid-impl v0.9.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded wasmi v1.0.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded wasmparser v0.228.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded bit-vec v0.8.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded bumpalo v3.20.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded crc32fast v1.5.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded equivalent v1.0.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded fancy-regex v0.16.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded gif v0.14.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded image v0.25.10 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded pic-scale v0.7.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded rust_decimal v1.36.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded unicode-normalization v0.1.24 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded base64 v0.22.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded enum-ordinalize-derive v4.3.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded png v0.18.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded ciborium-io v0.2.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded cobs v0.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded crossbeam-deque v0.8.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded either v1.13.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded fast-srgb8 v1.0.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded hayagriva v0.10.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded rayon v1.12.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded serde_json v1.0.138 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded biblatex v0.12.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded bytemuck v1.25.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded byteorder-lite v0.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded cfg-if v1.0.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded crossbeam-epoch v0.9.21 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded euclid v0.22.14 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded portable-atomic v1.10.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded codex v0.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded ttf-parser v0.25.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded harfrust v0.12.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_collator_data v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_normalizer v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded quick-xml v0.38.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded cc v1.2.11 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded hypher v0.1.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded regex v1.11.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded syn v2.0.98 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded tiny-skia v0.12.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded libc v0.2.169 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded rustybuzz v0.20.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded skrifa v0.42.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded skrifa v0.44.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded syn v3.0.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded time v0.3.55 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded fdeflate v0.3.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded regex-syntax v0.8.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded foldhash v0.2.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_collator v2.3.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded read-fonts v0.39.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded read-fonts v0.41.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded regex-automata v0.4.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded hashbrown v0.17.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded hashbrown v0.16.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded syntect v5.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded pxfm v0.1.24 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_locale_data v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded pdf-writer v0.15.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded csv v1.3.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_segmenter_data v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded two-face v0.4.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Downloaded icu_segmenter v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling proc-macro2 v1.0.101 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling quote v1.0.45 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unicode-ident v1.0.16 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling serde_core v1.0.228 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling serde v1.0.228 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling autocfg v1.4.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling smallvec v1.15.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling cfg-if v1.0.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling stable_deref_trait v1.2.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling libc v0.2.169 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling memchr v2.8.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling thiserror v2.0.18 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling crossbeam-utils v0.8.21 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling crossbeam-epoch v0.9.21 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling simd-adler32 v0.3.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling crc32fast v1.5.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling adler2 v2.0.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling zlib-rs v0.5.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling rayon-core v1.13.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling libm v0.2.11 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling arrayvec v0.7.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling either v1.13.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling writeable v0.6.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling itoa v1.0.14 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling log v0.4.29 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling equivalent v1.0.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hashbrown v0.16.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling siphasher v1.0.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling ryu v1.0.19 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling rustc-hash v2.1.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling fearless_simd v0.4.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling zune-core v0.5.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling utf8_iter v1.0.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling once_cell v1.21.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_normalizer_data v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_properties_data v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling base64 v0.22.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling miniz_oxide v0.8.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling fdeflate v0.3.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling parking_lot_core v0.9.10 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hayro-ccitt v0.3.0 (https://github.com/LaurenzV/hayro?rev=d8e24e29eda62581e1ea15497effb2a884fb1608#d8e24e29) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling polycool v0.4.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling tinyvec_macros v0.1.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling quick-error v2.0.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling proc-macro-hack v0.5.20+deprecated Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling scopeguard v1.2.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling zune-jpeg v0.5.15 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling tinyvec v1.8.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_locale_fallback_data v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling version_check v0.9.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling byteorder-lite v0.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling weezl v0.1.12 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling color_quant v1.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling serde_json v1.0.138 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling utf16_iter v1.0.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling num-traits v0.2.19 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling lock_api v0.4.12 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling phf_shared v0.13.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling fastrand v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling write16 v1.0.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling kurbo v0.13.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling arrayref v0.3.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling num-conv v0.2.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling time-core v0.1.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling regex-syntax v0.8.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling roxmltree v0.20.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling heck v0.5.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unicode-script v0.5.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling slotmap v1.0.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling image-webp v0.2.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling aho-corasick v1.1.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling semver v1.0.25 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling bit-vec v0.8.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling phf_generator v0.13.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling imagesize v0.14.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling gif v0.14.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling time-macros v0.2.32 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling core_maths v0.1.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling paste v1.0.15 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling ttf-parser v0.25.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling powerfmt v0.2.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling syn v2.0.98 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling syn v3.0.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling portable-atomic v1.10.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unicode-properties v0.1.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling byteorder v1.5.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling crossbeam-deque v0.8.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling memmap2 v0.9.11 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling fontconfig-parser v0.5.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_locale_data v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unicode-bidi-mirroring v0.4.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling xmlwriter v0.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling deranged v0.5.8 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unicode-ccc v0.4.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_collator_data v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling parking_lot v0.12.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling bit-set v0.8.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling roxmltree v0.21.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling simplecss v0.2.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling half v2.4.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling wasmparser v0.228.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling slab v0.4.11 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling percent-encoding v2.3.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling same-file v1.0.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling data-url v0.3.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling float-cmp v0.9.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling pxfm v0.1.24 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling svgtypes v0.16.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling num-integer v0.1.46 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling strict-num v0.1.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unscanny v0.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-utils v0.15.1 (/src/typst/crates/typst-utils) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unicode-vo v0.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling ciborium-io v0.2.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling winnow v0.7.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling pico-args v0.5.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling linked-hash-map v0.5.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unicode-bidi v0.3.18 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling rand_core v0.6.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling ciborium-ll v0.2.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling form_urlencoded v1.2.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling rayon v1.12.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling num-bigint v0.4.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling yaml-rust v0.4.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling jobserver v0.1.32 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling walkdir v2.5.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unicode-normalization v0.1.24 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling wasmi_core v1.0.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unsafe-libyaml v0.2.11 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling bumpalo v3.20.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling rust_decimal v1.36.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling by_address v1.2.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling regex-automata v0.4.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling time v0.3.55 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling roman-numerals-rs v3.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling fnv v1.0.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unicode-math-class v0.1.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling shlex v1.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling palette v0.7.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling thin-vec v0.2.18 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling codex v0.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling chinese-variant v1.1.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unicode-segmentation v1.12.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling az v1.2.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling cc v1.2.11 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling rand v0.8.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling approx v0.5.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling csv-core v0.1.11 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling fast-srgb8 v1.0.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_segmenter_data v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling spin v0.9.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling mutate_once v0.1.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling wasmi_collections v1.0.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling euclid v0.22.14 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling bitflags v2.11.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling litemap v0.8.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling serde_path_to_error v0.1.20 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling kamadak-exif v0.6.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling foldhash v0.2.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling wasmi_ir v1.0.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling fontdb v0.23.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-assets v0.15.1 (https://github.com/typst/typst-assets?rev=94dcb99#94dcb990) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling glidesort v0.1.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hayro-postscript v0.1.0 (https://github.com/LaurenzV/hayro?rev=d8e24e29eda62581e1ea15497effb2a884fb1608#d8e24e29) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling linebender_resource_handle v0.1.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typed-arena v2.0.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hashbrown v0.17.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hypher v0.1.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hayro-cmap v0.1.0 (https://github.com/LaurenzV/hayro?rev=d8e24e29eda62581e1ea15497effb2a884fb1608#d8e24e29) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling pdf-writer v0.15.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling libz-rs-sys v0.5.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling flate2 v1.1.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling moxcms v0.8.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling guillotiere v0.7.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling pic-scale v0.7.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling xmp-writer v0.3.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling pixglyph v0.6.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling zerovec-derive v0.11.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling infer v0.19.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling synstructure v0.13.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling png v0.18.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling arbitrary v1.4.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hayro-jbig2 v0.3.0 (https://github.com/LaurenzV/hayro?rev=d8e24e29eda62581e1ea15497effb2a884fb1608#d8e24e29) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hayro-jpeg2000 v0.4.0 (https://github.com/LaurenzV/hayro?rev=d8e24e29eda62581e1ea15497effb2a884fb1608#d8e24e29) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling psm v0.1.24 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling indexmap v2.12.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling stacker v0.1.21 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling libfuzzer-sys v0.4.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling serde_derive v1.0.228 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling zerofrom-derive v0.1.7 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling yoke-derive v0.8.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling bytemuck_derive v1.10.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling displaydoc v0.2.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling thiserror-impl v2.0.18 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling zerocopy-derive v0.7.35 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling phf_macros v0.13.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling strum_macros v0.27.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling comemo-macros v0.5.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling enum-ordinalize-derive v4.3.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling palette_derive v0.7.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-macros v0.15.1 (/src/typst/crates/typst-macros) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hayro-syntax v0.7.2 (https://github.com/LaurenzV/hayro?rev=d8e24e29eda62581e1ea15497effb2a884fb1608#d8e24e29) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling tinystr v0.8.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling fancy-regex v0.16.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling regex v1.11.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling enum-ordinalize v4.3.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling comemo v0.5.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling chinese-number v0.7.8 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unic-langid-impl v0.9.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling zerocopy v0.7.35 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling phf v0.13.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unic-langid-macros-impl v0.9.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling bytemuck v1.25.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling cobs v0.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling zerofrom v0.1.8 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling yoke v0.8.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling font-types v0.11.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling tiny-skia-path v0.12.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling rustybuzz v0.20.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling color v0.3.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling font-types v0.12.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling rgb v0.8.53 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling ppv-lite86 v0.2.20 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling read-fonts v0.41.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling read-fonts v0.39.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling strum v0.27.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling rand_chacha v0.3.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling peniko v0.6.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling tiny-skia v0.12.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling lipsum v0.9.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling vello_common v0.0.9 (https://github.com/linebender/vello?rev=8442ef4#8442ef44) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hayro-write v0.7.0 (https://github.com/LaurenzV/hayro?rev=d8e24e29eda62581e1ea15497effb2a884fb1608#d8e24e29) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling image v0.25.10 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling wasmi v1.0.9 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling zerovec v0.11.8 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling postcard v1.1.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling quick-xml v0.38.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling serde_spanned v0.6.8 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling toml_datetime v0.6.8 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling bincode v1.3.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling ecow v0.2.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling serde_yaml v0.9.34+deprecated Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling ciborium v0.2.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling csv v1.3.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling toml_edit v0.22.23 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling vello_cpu v0.0.9 (https://github.com/linebender/vello?rev=8442ef4#8442ef44) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling usvg v0.47.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-timing v0.15.1 (/src/typst/crates/typst-timing) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling plist v1.8.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling citationberg v0.7.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling zerotrie v0.2.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling potential_utf v0.1.5 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_collections v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_locale_core v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unic-langid-macros v0.9.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling unic-langid v0.9.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling biblatex v0.12.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling syntect v5.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling toml v0.8.19 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-syntax v0.15.1 (/src/typst/crates/typst-syntax) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling resvg v0.47.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_provider v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_normalizer v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_properties v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_locale_fallback v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_provider_blob v2.2.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_locale v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_segmenter v2.3.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling two-face v0.4.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling skrifa v0.42.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling write-fonts v0.48.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling idna_adapter v1.2.2 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling icu_collator v2.3.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling idna v1.0.3 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling url v2.5.4 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hayagriva v0.10.1 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling harfrust v0.12.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling skrifa v0.44.0 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hayro-interpret v0.7.0 (https://github.com/LaurenzV/hayro?rev=d8e24e29eda62581e1ea15497effb2a884fb1608#d8e24e29) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-library v0.15.1 (/src/typst/crates/typst-library) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hayro v0.7.0 (https://github.com/LaurenzV/hayro?rev=d8e24e29eda62581e1ea15497effb2a884fb1608#d8e24e29) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling hayro-svg v0.7.0 (https://github.com/LaurenzV/hayro?rev=d8e24e29eda62581e1ea15497effb2a884fb1608#d8e24e29) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling subsetter v0.2.6 Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling krilla v0.8.2 (https://github.com/LaurenzV/krilla?rev=7772dbe#7772dbee) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling krilla-svg v0.8.1 (https://github.com/LaurenzV/krilla?rev=7772dbe#7772dbee) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-layout v0.15.1 (/src/typst/crates/typst-layout) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-eval v0.15.1 (/src/typst/crates/typst-eval) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-svg v0.15.1 (/src/typst/crates/typst-svg) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-render v0.15.1 (/src/typst/crates/typst-render) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-pdf v0.15.1 (/src/typst/crates/typst-pdf) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-html v0.15.1 (/src/typst/crates/typst-html) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-realize v0.15.1 (/src/typst/crates/typst-realize) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-bundle v0.15.1 (/src/typst/crates/typst-bundle) Step #3 - "compile-libfuzzer-coverage-x86_64": warning: overflow evaluating the requirement `comemo::internal::Cache, Result>>: Sync` Step #3 - "compile-libfuzzer-coverage-x86_64": --> crates/typst-bundle/src/lib.rs:149:1 Step #3 - "compile-libfuzzer-coverage-x86_64": | Step #3 - "compile-libfuzzer-coverage-x86_64": 149 | #[comemo::memoize] Step #3 - "compile-libfuzzer-coverage-x86_64": | ^^^^^^^^^^^^^^^^^^ Step #3 - "compile-libfuzzer-coverage-x86_64": | Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `LazyLock, Result>>>>: Sync` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `lock_api::rwlock::RwLock, Result>>>: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `comemo::memoize::CacheData, Result>>: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `comemo::tree::CallTree, comemo::memoize::CacheEntry, _>>: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `slab::Slab, Result>>>>: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `Vec, Result>>>>>: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `alloc::raw_vec::RawVec, Result>>>>>: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `PhantomData, Result>>>>>: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `slab::Entry, Result>>>>: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `comemo::tree::LeafNode, Result>>>: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `comemo::memoize::CacheEntry, Result>>: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `Result>: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `Bundle: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `Arc>: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: which requires `IndexMap: Send` Step #3 - "compile-libfuzzer-coverage-x86_64": = note: and so on... Step #3 - "compile-libfuzzer-coverage-x86_64": = help: consider adding a manual `impl` of auto traits like `Send` for intermediate types, if auto traits are involved Step #3 - "compile-libfuzzer-coverage-x86_64": = help: or consider increasing the recursion limit by adding a `#![recursion_limit = "256"]` attribute to your crate (`typst_bundle`) Step #3 - "compile-libfuzzer-coverage-x86_64": = note: this lint is attached to the whole crate and can't be disabled on a per-function basis Step #3 - "compile-libfuzzer-coverage-x86_64": = warning: this was previously accepted by the compiler but is being phased out; it will become a hard error in a future release! Step #3 - "compile-libfuzzer-coverage-x86_64": = note: for more information, see issue #159228 Step #3 - "compile-libfuzzer-coverage-x86_64": = note: `#[warn(recursion_depth_exceeding_limit)]` (part of `#[warn(future_incompatible)]`) on by default Step #3 - "compile-libfuzzer-coverage-x86_64": = note: this warning originates in the attribute macro `comemo::memoize` (in Nightly builds, run with -Z macro-backtrace for more info) Step #3 - "compile-libfuzzer-coverage-x86_64": Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst v0.15.1 (/src/typst/crates/typst) Step #3 - "compile-libfuzzer-coverage-x86_64":  Compiling typst-fuzz v0.15.1 (/src/typst/tests/fuzz) Step #3 - "compile-libfuzzer-coverage-x86_64": warning: `typst-bundle` (lib) generated 1 warning Step #3 - "compile-libfuzzer-coverage-x86_64":  Finished `release` profile [optimized + debuginfo] target(s) in 8m 38s Step #3 - "compile-libfuzzer-coverage-x86_64": + FUZZ_TARGET_OUTPUT_DIR=/src/typst/target/x86_64-unknown-linux-gnu/release Step #3 - "compile-libfuzzer-coverage-x86_64": + for f in src/bin/*.rs Step #3 - "compile-libfuzzer-coverage-x86_64": ++ basename src/bin/html Step #3 - "compile-libfuzzer-coverage-x86_64": + FUZZ_TARGET_NAME=html Step #3 - "compile-libfuzzer-coverage-x86_64": + cp /src/typst/target/x86_64-unknown-linux-gnu/release/html /workspace/out/libfuzzer-coverage-x86_64/ Step #3 - "compile-libfuzzer-coverage-x86_64": + for f in src/bin/*.rs Step #3 - "compile-libfuzzer-coverage-x86_64": ++ basename src/bin/paged Step #3 - "compile-libfuzzer-coverage-x86_64": + FUZZ_TARGET_NAME=paged Step #3 - "compile-libfuzzer-coverage-x86_64": + cp /src/typst/target/x86_64-unknown-linux-gnu/release/paged /workspace/out/libfuzzer-coverage-x86_64/ Step #3 - "compile-libfuzzer-coverage-x86_64": + for f in src/bin/*.rs Step #3 - "compile-libfuzzer-coverage-x86_64": ++ basename src/bin/parse Step #3 - "compile-libfuzzer-coverage-x86_64": + FUZZ_TARGET_NAME=parse Step #3 - "compile-libfuzzer-coverage-x86_64": + cp /src/typst/target/x86_64-unknown-linux-gnu/release/parse /workspace/out/libfuzzer-coverage-x86_64/ Finished Step #3 - "compile-libfuzzer-coverage-x86_64" Starting Step #4 Step #4: Pulling image: gcr.io/oss-fuzz-base/base-runner Step #4: Using default tag: latest Step #4: latest: Pulling from oss-fuzz-base/base-runner Step #4: b549f31133a9: Already exists Step #4: 6e628c8ef21f: Already exists Step #4: f53ab3868c1c: Already exists Step #4: cac03dd67be9: Pulling fs layer Step #4: 6ad67417113a: Pulling fs layer Step #4: 0f23db3019f6: Pulling fs layer Step #4: f7f923ac7112: Pulling fs layer Step #4: 5ac5fd5c9155: Pulling fs layer Step #4: e55f3aeb0db5: Pulling fs layer Step #4: 99a80ef90662: Pulling fs layer Step #4: ed071ff265fb: Pulling fs layer Step #4: 8ea7612e89e3: Pulling fs layer Step #4: 5acd3defd0b1: Pulling fs layer Step #4: cb9fc028b38c: Pulling fs layer Step #4: f875d495afb8: Pulling fs layer Step #4: 75f78d57ea55: Pulling fs layer Step #4: 17240e9f55fc: Pulling fs layer Step #4: 5ca435cbfcbd: Pulling fs layer Step #4: 943a3a494328: Pulling fs layer Step #4: 7104cb51b378: Pulling fs layer Step #4: 4065365cc179: Pulling fs layer Step #4: da4c240a289d: Pulling fs layer Step #4: ed67bd6f81a3: Pulling fs layer Step #4: c18ae4e7737a: Pulling fs layer Step #4: 99a80ef90662: Waiting Step #4: 5328ac88bd50: Pulling fs layer Step #4: ed071ff265fb: Waiting Step #4: 26af48add3c9: Pulling fs layer Step #4: 4569a447ea85: Pulling fs layer Step #4: 8ea7612e89e3: Waiting Step #4: 5acd3defd0b1: Waiting Step #4: 91359fd5dc87: Pulling fs layer Step #4: cb9fc028b38c: Waiting Step #4: 17240e9f55fc: Waiting Step #4: f875d495afb8: Waiting Step #4: 5ca435cbfcbd: Waiting Step #4: 75f78d57ea55: Waiting Step #4: 943a3a494328: Waiting Step #4: c18ae4e7737a: Waiting Step #4: 5328ac88bd50: Waiting Step #4: 26af48add3c9: Waiting Step #4: 4569a447ea85: Waiting Step #4: 91359fd5dc87: Waiting Step #4: da4c240a289d: Waiting Step #4: ed67bd6f81a3: Waiting Step #4: 0f23db3019f6: Verifying Checksum Step #4: 0f23db3019f6: Download complete Step #4: 5ac5fd5c9155: Verifying Checksum Step #4: 5ac5fd5c9155: Download complete Step #4: cac03dd67be9: Verifying Checksum Step #4: cac03dd67be9: Download complete Step #4: f7f923ac7112: Verifying Checksum Step #4: f7f923ac7112: Download complete Step #4: 6ad67417113a: Download complete Step #4: 99a80ef90662: Verifying Checksum Step #4: 99a80ef90662: Download complete Step #4: ed071ff265fb: Download complete Step #4: cac03dd67be9: Pull complete Step #4: 8ea7612e89e3: Verifying Checksum Step #4: 8ea7612e89e3: Download complete Step #4: f875d495afb8: Verifying Checksum Step #4: f875d495afb8: Download complete Step #4: 75f78d57ea55: Verifying Checksum Step #4: 75f78d57ea55: Download complete Step #4: cb9fc028b38c: Verifying Checksum Step #4: cb9fc028b38c: Download complete Step #4: e55f3aeb0db5: Verifying Checksum Step #4: e55f3aeb0db5: Download complete Step #4: 6ad67417113a: Pull complete Step #4: 5ca435cbfcbd: Verifying Checksum Step #4: 5ca435cbfcbd: Download complete Step #4: 0f23db3019f6: Pull complete Step #4: 7104cb51b378: Verifying Checksum Step #4: 7104cb51b378: Download complete Step #4: 4065365cc179: Verifying Checksum Step #4: 4065365cc179: Download complete Step #4: 5acd3defd0b1: Verifying Checksum Step #4: 5acd3defd0b1: Download complete Step #4: c18ae4e7737a: Verifying Checksum Step #4: c18ae4e7737a: Download complete Step #4: f7f923ac7112: Pull complete Step #4: ed67bd6f81a3: Verifying Checksum Step #4: ed67bd6f81a3: Download complete Step #4: 5ac5fd5c9155: Pull complete Step #4: 26af48add3c9: Download complete Step #4: 5328ac88bd50: Verifying Checksum Step #4: 5328ac88bd50: Download complete Step #4: 91359fd5dc87: Download complete Step #4: da4c240a289d: Verifying Checksum Step #4: da4c240a289d: Download complete Step #4: 17240e9f55fc: Verifying Checksum Step #4: 17240e9f55fc: Download complete Step #4: 4569a447ea85: Verifying Checksum Step #4: 4569a447ea85: Download complete Step #4: 943a3a494328: Verifying Checksum Step #4: 943a3a494328: Download complete Step #4: e55f3aeb0db5: Pull complete Step #4: 99a80ef90662: Pull complete Step #4: ed071ff265fb: Pull complete Step #4: 8ea7612e89e3: Pull complete Step #4: 5acd3defd0b1: Pull complete Step #4: cb9fc028b38c: Pull complete Step #4: f875d495afb8: Pull complete Step #4: 75f78d57ea55: Pull complete Step #4: 17240e9f55fc: Pull complete Step #4: 5ca435cbfcbd: Pull complete Step #4: 943a3a494328: Pull complete Step #4: 7104cb51b378: Pull complete Step #4: 4065365cc179: Pull complete Step #4: da4c240a289d: Pull complete Step #4: ed67bd6f81a3: Pull complete Step #4: c18ae4e7737a: Pull complete Step #4: 5328ac88bd50: Pull complete Step #4: 26af48add3c9: Pull complete Step #4: 4569a447ea85: Pull complete Step #4: 91359fd5dc87: Pull complete Step #4: Digest: sha256:51304a6c0524956a6dc45df99478e1ab1d1869e27c21c95a56ab34f709472326 Step #4: Status: Downloaded newer image for gcr.io/oss-fuzz-base/base-runner:latest Step #4: gcr.io/oss-fuzz-base/base-runner:latest Finished Step #4 Starting Step #5 Step #5: Already have image (with digest): gcr.io/oss-fuzz-base/base-runner Step #5: Running html Step #5: Running paged Step #5: Running parse Step #5: Error occured while running parse: Step #5: Cov returncode: 0, grep returncode: 0 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1800919856 Step #5: INFO: Loaded 1 modules (81927 inline 8-bit counters): 81927 [0x55ba0975c410, 0x55ba09770417), Step #5: INFO: Loaded 1 PC tables (81927 PCs): 81927 [0x55ba09770418,0x55ba098b0488), Step #5: MERGE-OUTER: 19453 files, 0 in the initial corpus, 0 processed earlier Step #5: MERGE-OUTER: attempt 1 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1801051953 Step #5: INFO: Loaded 1 modules (81927 inline 8-bit counters): 81927 [0x55f89e27b410, 0x55f89e28f417), Step #5: INFO: Loaded 1 PC tables (81927 PCs): 81927 [0x55f89e28f418,0x55f89e3cf488), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge63.txt' Step #5: MERGE-INNER: 19453 total files; 0 processed earlier; will process 19453 files now Step #5: #1 pulse cov: 161 ft: 162 exec/s: 0 rss: 39Mb Step #5: #2 pulse cov: 264 ft: 298 exec/s: 0 rss: 40Mb Step #5: #4 pulse cov: 344 ft: 447 exec/s: 0 rss: 40Mb Step #5: #8 pulse cov: 384 ft: 508 exec/s: 0 rss: 40Mb Step #5: #16 pulse cov: 484 ft: 634 exec/s: 0 rss: 40Mb Step #5: #32 pulse cov: 583 ft: 739 exec/s: 0 rss: 41Mb Step #5: #64 pulse cov: 981 ft: 1264 exec/s: 0 rss: 42Mb Step #5: #128 pulse cov: 1405 ft: 1848 exec/s: 0 rss: 44Mb Step #5: #256 pulse cov: 1574 ft: 2135 exec/s: 0 rss: 46Mb Step #5: #512 pulse cov: 2129 ft: 3315 exec/s: 0 rss: 50Mb Step #5: #1024 pulse cov: 2593 ft: 4353 exec/s: 0 rss: 58Mb Step #5: #2048 pulse cov: 3340 ft: 6662 exec/s: 0 rss: 61Mb Step #5: #4096 pulse cov: 4226 ft: 11635 exec/s: 2048 rss: 64Mb Step #5: #8192 pulse cov: 5798 ft: 23537 exec/s: 1638 rss: 69Mb Step #5: #16384 pulse cov: 6076 ft: 45829 exec/s: 248 rss: 513Mb Step #5: ==69== ERROR: libFuzzer: out-of-memory (used: 2128Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 1183525066 bytes in 80743 chunks; quarantined: 8866484 bytes in 41 chunks; 2356569 other chunks; total chunks: 2437353; showing top 95% (at most 8 unique contexts) Step #5: 1132871680 byte(s) (95%) in 1 allocation(s) Step #5: #0 0x55f89db352d1 in realloc (out/libfuzzer-coverage-x86_64/parse+0x33c2d1) Step #5: #1 0x55f89da98ba4 in alloc::alloc::realloc_nonnull /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:233:14 Step #5: #2 0x55f89da98ba4 in ::grow_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:357:31 Step #5: #3 0x55f89da98ba4 in ::grow_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:460:9 Step #5: #4 0x55f89da98ba4 in ::grow /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:573:23 Step #5: #5 0x55f89da98ba4 in ::finish_grow /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:572:28 Step #5: #6 0x55f89da97fb3 in ::grow_amortized /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:542:33 Step #5: #7 0x55f89da97fb3 in >::reserve::do_reserve_and_handle:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:682:44 Step #5: #8 0x55f89de4663c in ::reserve /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:691:17 Step #5: #9 0x55f89de4663c in >::reserve /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:350:29 Step #5: #10 0x55f89de4663c in >::reserve /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:1469:18 Step #5: #11 0x55f89de4663c in >::extend_trusted::>> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:4173:18 Step #5: #12 0x55f89df13a7e in as alloc::vec::spec_extend::SpecExtend>>>::spec_extend /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_extend.rs:27:14 Step #5: #13 0x55f89df13a7e in as alloc::vec::spec_extend::SpecExtend<&typst_syntax::node::SyntaxNode, core::slice::iter::Iter>>::spec_extend /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_extend.rs:47:14 Step #5: #14 0x55f89df13a7e in >::extend_from_slice /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3644:14 Step #5: #15 0x55f89df13a7e in ::memoize_parsed_nodes /src/typst/crates/typst-syntax/src/parser.rs:1931:25 Step #5: #16 0x55f89df13a7e in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1067:7 Step #5: #17 0x55f89df0c10e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #18 0x55f89df0c10e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #19 0x55f89df14370 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #20 0x55f89df14370 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1060:9 Step #5: #21 0x55f89df0c10e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #22 0x55f89df0c10e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #23 0x55f89df14370 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #24 0x55f89df14370 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1060:9 Step #5: #25 0x55f89df0c10e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #26 0x55f89df0c10e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #27 0x55f89df14370 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #28 0x55f89df14370 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1060:9 Step #5: #29 0x55f89df0c10e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #30 0x55f89df0c10e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #31 0x55f89df0d0ce in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:673:13 Step #5: #32 0x55f89df14370 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #33 0x55f89df14370 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1060:9 Step #5: #34 0x55f89df0c10e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #35 0x55f89df0c10e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #36 0x55f89df14370 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #37 0x55f89df14370 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1060:9 Step #5: #38 0x55f89df0c10e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #39 0x55f89df0c10e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #40 0x55f89df14370 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #41 0x55f89df14370 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1060:9 Step #5: #42 0x55f89df0c10e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #43 0x55f89df0c10e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #44 0x55f89df14370 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #45 0x55f89df14370 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1060:9 Step #5: #46 0x55f89df0c10e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #47 0x55f89df0c10e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #48 0x55f89df14370 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #49 0x55f89df14370 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1060:9 Step #5: #50 0x55f89df0c10e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #51 0x55f89df0c10e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #52 0x55f89df14370 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #53 0x55f89df14370 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1060:9 Step #5: #54 0x55f89df0c10e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #55 0x55f89df0c10e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #56 0x55f89df14370 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #57 0x55f89df14370 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1060:9 Step #5: #58 0x55f89df0c10e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #59 0x55f89df0c10e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #60 0x55f89df14370 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #61 0x55f89df14370 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1060:9 Step #5: #62 0x55f89df0c10e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #63 0x55f89df0c10e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #64 0x55f89df14370 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #65 0x55f89df14370 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1060:9 Step #5: Step #5: DEDUP_TOKEN: __interceptor_realloc--alloc::alloc::realloc_nonnull--::grow_impl_runtime Step #5: 24383088 byte(s) (2%) in 11 allocation(s) Step #5: #0 0x55f89db34ec4 in malloc (out/libfuzzer-coverage-x86_64/parse+0x33bec4) Step #5: #1 0x55f89dfe86a3 in operator new(unsigned long) cxa_noexception.cpp Step #5: #2 0x55f89dfba4d2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #3 0x7f26a00c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--operator new(unsigned long)--main Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-889414c50d0bca62b1cbf42945f5518040ce2cfa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2775507551 Step #5: INFO: Loaded 1 modules (81927 inline 8-bit counters): 81927 [0x564c4862e410, 0x564c48642417), Step #5: INFO: Loaded 1 PC tables (81927 PCs): 81927 [0x564c48642418,0x564c48782488), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge63.txt' Step #5: MERGE-INNER: '/corpus/parse/regressions/889414c50d0bca62b1cbf42945f5518040ce2cfa' caused a failure at the previous merge step Step #5: MERGE-INNER: 19453 total files; 19288 processed earlier; will process 165 files now Step #5: #1 pulse cov: 1484 ft: 1485 exec/s: 0 rss: 47Mb Step #5: #2 pulse cov: 1774 ft: 2249 exec/s: 0 rss: 282Mb Step #5: #4 pulse cov: 2878 ft: 5269 exec/s: 0 rss: 282Mb Step #5: #8 pulse cov: 3292 ft: 7628 exec/s: 0 rss: 282Mb Step #5: #16 pulse cov: 3623 ft: 9960 exec/s: 0 rss: 282Mb Step #5: #32 pulse cov: 4323 ft: 16606 exec/s: 0 rss: 1792Mb Step #5: #64 pulse cov: 4696 ft: 22946 exec/s: 0 rss: 1792Mb Step #5: #128 pulse cov: 4766 ft: 25047 exec/s: 0 rss: 1792Mb Step #5: #165 DONE cov: 4775 ft: 25482 exec/s: 0 rss: 1792Mb Step #5: MERGE-OUTER: successful in 2 attempt(s) Step #5: MERGE-OUTER: the control file has 2315862 bytes Step #5: MERGE-OUTER: consumed 1Mb (69Mb rss) to parse the control file Step #5: MERGE-OUTER: 12765 new files with 47439 new features added; 6172 new coverage edges Step #5: warning: /workspace/out/libfuzzer-coverage-x86_64/dumps/parse.13374324871374090359_0.profraw: raw profile version mismatch: Profile uses raw profile format version = 11; expected version = 10 Step #5: PLEASE update this tool to version in the raw profile, or regenerate raw profile with expected version. Step #5: error: no profile can be merged Step #5: [2026-09-15 07:45:34,515 INFO] Finding shared libraries for targets (if any). Step #5: [2026-09-15 07:45:34,526 INFO] Finished finding shared libraries for targets. Step #5: error: /workspace/out/libfuzzer-coverage-x86_64/dumps/parse.profdata: could not read profile data!No such file or directory Step #5: Coverage error, creating log file: /workspace/out/libfuzzer-coverage-x86_64/fuzzer_stats/parse_error.log Step #5: error: /workspace/out/libfuzzer-coverage-x86_64/dumps/parse.profdata: could not read profile data!No such file or directory Step #5: Error occured while running html: Step #5: Cov returncode: 0, grep returncode: 0 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1800302815 Step #5: INFO: Loaded 1 modules (1627851 inline 8-bit counters): 1627851 [0x5647e67ddfe0, 0x5647e696b6ab), Step #5: INFO: Loaded 1 PC tables (1627851 PCs): 1627851 [0x5647e696b6b0,0x5647e8242360), Step #5: MERGE-OUTER: 18371 files, 0 in the initial corpus, 0 processed earlier Step #5: MERGE-OUTER: attempt 1 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1800468715 Step #5: INFO: Loaded 1 modules (1627851 inline 8-bit counters): 1627851 [0x55606169bfe0, 0x5560618296ab), Step #5: INFO: Loaded 1 PC tables (1627851 PCs): 1627851 [0x5560618296b0,0x556063100360), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge42.txt' Step #5: MERGE-INNER: 18371 total files; 0 processed earlier; will process 18371 files now Step #5: #1 pulse cov: 5905 ft: 5906 exec/s: 0 rss: 142Mb Step #5: #2 pulse cov: 6102 ft: 6720 exec/s: 0 rss: 144Mb Step #5: #4 pulse cov: 6585 ft: 8072 exec/s: 0 rss: 147Mb Step #5: #8 pulse cov: 6871 ft: 8881 exec/s: 0 rss: 151Mb Step #5: #16 pulse cov: 7913 ft: 10367 exec/s: 0 rss: 158Mb Step #5: #32 pulse cov: 8412 ft: 11007 exec/s: 32 rss: 160Mb Step #5: #64 pulse cov: 8696 ft: 11361 exec/s: 32 rss: 160Mb Step #5: #128 pulse cov: 10028 ft: 13809 exec/s: 32 rss: 162Mb Step #5: #256 pulse cov: 12808 ft: 17940 exec/s: 28 rss: 169Mb Step #5: #512 pulse cov: 16694 ft: 25551 exec/s: 28 rss: 174Mb Step #5: #1024 pulse cov: 17452 ft: 28719 exec/s: 28 rss: 175Mb Step #5: #2048 pulse cov: 19342 ft: 35446 exec/s: 27 rss: 176Mb Step #5: #4096 pulse cov: 21040 ft: 47835 exec/s: 27 rss: 178Mb Step #5: #8192 pulse cov: 30361 ft: 92834 exec/s: 26 rss: 230Mb Step #5: #16384 pulse cov: 31654 ft: 135199 exec/s: 22 rss: 443Mb Step #5: ALARM: working on the last Unit for 133 seconds Step #5: and the timeout value is 100 (use -timeout=N to change) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./timeout-7796a0afd5de6e47ed8262ac9b060fa17a74a509 Step #5: ==45== ERROR: libFuzzer: timeout after 133 seconds Step #5: #0 0x556059b95531 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/html+0x2f01531) Step #5: #1 0x55605ed2ee28 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55605ed128eb in fuzzer::Fuzzer::AlarmCallback() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:304:5 Step #5: #3 0x7f51778b241f (/lib/x86_64-linux-gnu/libpthread.so.0+0x1441f) (BuildId: 9753720502573b97dbac595b61fd72c2df18e078) Step #5: #4 0x55605e14d9a8 in >::header /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:618:9 Step #5: #5 0x55605e14d9a8 in >::capacity /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:154:14 Step #5: #6 0x55605e14d9a8 in >::push_unchecked /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:256:39 Step #5: #7 0x55605e126872 in >::extend_from_slice /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:492:22 Step #5: #8 0x55605e126872 in as core::convert::From<&[u8]>>::from /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:970:13 Step #5: #9 0x55605e126872 in ::from_slice /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/dynamic.rs:93:33 Step #5: #10 0x55605e126872 in ::from_str /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/string.rs:103:14 Step #5: #11 0x55605e126872 in >::from /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/string.rs:445:9 Step #5: #12 0x55605e126872 in <&str as core::convert::Into>::into /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/core/src/convert/mod.rs:780:9 Step #5: #13 0x55605e126872 in ::hint::<&str> /src/typst/crates/typst-syntax/src/lexer.rs:86:32 Step #5: #14 0x55605e126872 in ::invalid_char_in_code /src/typst/crates/typst-syntax/src/lexer.rs:915:22 Step #5: #15 0x55605e0f9aaf in ::code /src/typst/crates/typst-syntax/src/lexer.rs:893:23 Step #5: #16 0x55605e0f9aaf in ::next /src/typst/crates/typst-syntax/src/lexer.rs:120:42 Step #5: #17 0x55605e11940d in ::lex /src/typst/crates/typst-syntax/src/parser.rs:1857:42 Step #5: #18 0x55605e118fdf in ::eat /src/typst/crates/typst-syntax/src/parser.rs:1771:22 Step #5: #19 0x55605e1739c8 in ::eat_and_get /src/typst/crates/typst-syntax/src/parser.rs:1735:14 Step #5: #20 0x55605e1739c8 in ::unexpected /src/typst/crates/typst-syntax/src/parser.rs:2056:14 Step #5: #21 0x55605e1739c8 in typst_syntax::parser::import_items /src/typst/crates/typst-syntax/src/parser.rs:949:15 Step #5: #22 0x55605e1784f0 in typst_syntax::parser::module_import /src/typst/crates/typst-syntax/src/parser.rs:936:13 Step #5: #23 0x55605e179335 in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:723:31 Step #5: #24 0x55605e179335 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #25 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #26 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #27 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #28 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #29 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #30 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #31 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #32 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #33 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #34 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #35 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #36 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #37 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #38 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #39 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #40 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #41 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #42 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #43 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #44 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #45 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #46 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #47 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #48 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #49 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #50 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #51 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #52 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #53 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #54 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #55 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #56 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #57 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #58 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #59 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #60 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #61 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #62 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #63 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #64 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #65 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #66 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #67 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #68 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #69 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #70 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #71 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #72 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #73 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #74 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #75 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #76 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #77 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #78 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #79 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #80 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #81 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #82 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #83 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #84 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #85 0x55605e1775bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #86 0x55605e189345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #87 0x55605e182c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #88 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #89 0x55605e182c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #90 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #91 0x55605e181327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #92 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #93 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #94 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #95 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #96 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #97 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #98 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #99 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #100 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #101 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #102 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #103 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #104 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #105 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #106 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #107 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #108 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #109 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #110 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #111 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #112 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #113 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #114 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #115 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #116 0x55605e1775bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #117 0x55605e189345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #118 0x55605e182c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #119 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #120 0x55605e182c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #121 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #122 0x55605e181327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #123 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #124 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #125 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #126 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #127 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #128 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #129 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #130 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #131 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #132 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #133 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #134 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #135 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #136 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #137 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #138 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #139 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #140 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #141 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #142 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #143 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #144 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #145 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #146 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #147 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #148 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #149 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #150 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #151 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #152 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #153 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #154 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #155 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #156 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #157 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #158 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #159 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #160 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #161 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #162 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #163 0x55605e1775bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #164 0x55605e189345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #165 0x55605e182c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #166 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #167 0x55605e182c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #168 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #169 0x55605e181327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #170 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #171 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #172 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #173 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #174 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #175 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #176 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #177 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #178 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #179 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #180 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #181 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #182 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #183 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #184 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #185 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #186 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #187 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #188 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #189 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #190 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #191 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #192 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #193 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #194 0x55605e1775bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #195 0x55605e189345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #196 0x55605e182c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #197 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #198 0x55605e182c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #199 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #200 0x55605e181327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #201 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #202 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #203 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #204 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #205 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #206 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #207 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #208 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #209 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #210 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #211 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #212 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #213 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #214 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #215 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #216 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #217 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #218 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #219 0x55605e17a42e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:673:13 Step #5: #220 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #221 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #222 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #223 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #224 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #225 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #226 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #227 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #228 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #229 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #230 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #231 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #232 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #233 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #234 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #235 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #236 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #237 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #238 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #239 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #240 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #241 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #242 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #243 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #244 0x55605e17a42e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:673:13 Step #5: #245 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #246 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #247 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #248 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #249 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #250 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #251 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #252 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #253 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #254 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #255 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #256 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #257 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #258 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #259 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #260 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #261 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #262 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #263 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #264 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #265 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #266 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #267 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #268 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #269 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #270 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #271 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #272 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #273 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #274 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #275 0x55605e1775bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #276 0x55605e189345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #277 0x55605e182c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #278 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #279 0x55605e182c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #280 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #281 0x55605e181327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #282 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #283 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #284 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #285 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #286 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #287 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #288 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #289 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #290 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #291 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #292 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #293 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #294 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #295 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #296 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #297 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #298 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #299 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #300 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #301 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #302 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #303 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #304 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #305 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #306 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #307 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #308 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #309 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #310 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #311 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #312 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #313 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #314 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #315 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #316 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #317 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #318 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #319 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #320 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #321 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #322 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #323 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #324 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #325 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #326 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #327 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #328 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #329 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #330 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #331 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #332 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #333 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #334 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #335 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #336 0x55605e1775bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #337 0x55605e189345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #338 0x55605e182c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #339 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #340 0x55605e182c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #341 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #342 0x55605e181327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #343 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #344 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #345 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #346 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #347 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #348 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #349 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #350 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #351 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #352 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #353 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #354 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #355 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #356 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #357 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #358 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #359 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #360 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #361 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #362 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #363 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #364 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #365 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #366 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #367 0x55605e1775bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #368 0x55605e189345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #369 0x55605e182c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #370 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #371 0x55605e182c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #372 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #373 0x55605e181327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #374 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #375 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #376 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #377 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #378 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #379 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #380 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #381 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #382 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #383 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #384 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #385 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #386 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #387 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #388 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #389 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #390 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #391 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #392 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #393 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #394 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #395 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #396 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #397 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #398 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #399 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #400 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #401 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #402 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #403 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #404 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #405 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #406 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #407 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #408 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #409 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #410 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #411 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #412 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #413 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #414 0x55605e1775bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #415 0x55605e189345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #416 0x55605e182c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #417 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #418 0x55605e182c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #419 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #420 0x55605e181327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #421 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #422 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #423 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #424 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #425 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #426 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #427 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #428 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #429 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #430 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #431 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #432 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #433 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #434 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #435 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #436 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #437 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #438 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #439 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #440 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #441 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #442 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #443 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #444 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #445 0x55605e1775bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #446 0x55605e189345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #447 0x55605e182c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #448 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #449 0x55605e182c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #450 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #451 0x55605e181327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #452 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #453 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #454 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #455 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #456 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #457 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #458 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #459 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #460 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #461 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #462 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #463 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #464 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #465 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #466 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #467 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #468 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #469 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #470 0x55605e17a42e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:673:13 Step #5: #471 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #472 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #473 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #474 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #475 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #476 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #477 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #478 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #479 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #480 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #481 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #482 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #483 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #484 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #485 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #486 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #487 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #488 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #489 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #490 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #491 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #492 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #493 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #494 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #495 0x55605e17a42e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:673:13 Step #5: #496 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #497 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #498 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #499 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #500 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #501 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #502 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #503 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #504 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #505 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #506 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #507 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #508 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #509 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #510 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #511 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #512 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #513 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #514 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #515 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #516 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #517 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #518 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #519 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #520 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #521 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #522 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #523 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #524 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #525 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #526 0x55605e1775bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #527 0x55605e189345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #528 0x55605e182c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #529 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #530 0x55605e182c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #531 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #532 0x55605e181327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #533 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #534 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #535 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #536 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #537 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #538 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #539 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #540 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #541 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #542 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #543 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #544 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #545 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #546 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #547 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #548 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #549 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #550 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #551 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #552 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #553 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #554 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #555 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #556 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #557 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #558 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #559 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #560 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #561 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #562 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #563 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #564 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #565 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #566 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #567 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #568 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #569 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #570 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #571 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #572 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #573 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #574 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #575 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #576 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #577 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #578 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #579 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #580 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #581 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #582 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #583 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #584 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #585 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #586 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #587 0x55605e1775bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #588 0x55605e189345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #589 0x55605e182c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #590 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #591 0x55605e182c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #592 0x55605e182c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #593 0x55605e181327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #594 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #595 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #596 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #597 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #598 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #599 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #600 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #601 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #602 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #603 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #604 0x55605e184373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #605 0x55605e184373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #606 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #607 0x55605e184373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #608 0x55605e184373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #609 0x55605e1802da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #610 0x55605e17946e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #611 0x55605e17946e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #612 0x55605e1875a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #613 0x55605e1875a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #614 0x55605e1875a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #615 0x55605e1875a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #616 0x55605e1875a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #617 0x55605e1799c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #618 0x55605e1775bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::AlarmCallback() Step #5: SUMMARY: libFuzzer: timeout Step #5: MERGE-OUTER: attempt 2 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3127008262 Step #5: INFO: Loaded 1 modules (1627851 inline 8-bit counters): 1627851 [0x5577fd44ffe0, 0x5577fd5dd6ab), Step #5: INFO: Loaded 1 PC tables (1627851 PCs): 1627851 [0x5577fd5dd6b0,0x5577feeb4360), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge42.txt' Step #5: MERGE-INNER: '/corpus/html/regressions/7796a0afd5de6e47ed8262ac9b060fa17a74a509' caused a failure at the previous merge step Step #5: MERGE-INNER: 18371 total files; 17914 processed earlier; will process 457 files now Step #5: ALARM: working on the last Unit for 101 seconds Step #5: and the timeout value is 100 (use -timeout=N to change) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./timeout-b9ccfbc12046b8ac8ba45433ca6a921731713dc1 Step #5: ==103650== ERROR: libFuzzer: timeout after 101 seconds Step #5: #0 0x5577f5949531 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/html+0x2f01531) Step #5: #1 0x5577faae2e28 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5577faac68eb in fuzzer::Fuzzer::AlarmCallback() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:304:5 Step #5: #3 0x7fe1154e641f (/lib/x86_64-linux-gnu/libpthread.so.0+0x1441f) (BuildId: 9753720502573b97dbac595b61fd72c2df18e078) Step #5: #4 0x5577f9f018ad in >::align /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:672:13 Step #5: #5 0x5577f9f018ad in >::offset /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:681:39 Step #5: #6 0x5577f9f018ad in >::allocation /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:601:44 Step #5: #7 0x5577f9f018ad in >::header::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:619:38 Step #5: #8 0x5577f9f018ad in ::then::<&ecow::vec::Header, >::header::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/core/src/bool.rs:66:24 Step #5: #9 0x5577f9f018ad in >::header /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:619:14 Step #5: #10 0x5577f9f018ad in >::is_unique /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:778:14 Step #5: #11 0x5577f9f018ad in >::push_unchecked /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:255:28 Step #5: #12 0x5577f9ed9c16 in >::extend_from_slice /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:492:22 Step #5: #13 0x5577f9ed9c16 in as core::convert::From<&[u8]>>::from /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/vec.rs:970:13 Step #5: #14 0x5577f9ed9c16 in ::from_slice /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/dynamic.rs:93:33 Step #5: #15 0x5577f9ed9c16 in ::from_str /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/string.rs:103:14 Step #5: #16 0x5577f9ed9c16 in >::from /rust/registry/src/index.crates.io-1949cf8c6b5b557f/ecow-0.2.6/src/string.rs:445:9 Step #5: #17 0x5577f9ed9c16 in <&str as core::convert::Into>::into /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/core/src/convert/mod.rs:780:9 Step #5: #18 0x5577f9ed9c16 in ::hint::<&str> /src/typst/crates/typst-syntax/src/lexer.rs:86:32 Step #5: #19 0x5577f9ed9c16 in ::invalid_char_in_code /src/typst/crates/typst-syntax/src/lexer.rs:909:22 Step #5: #20 0x5577f9eadaaf in ::code /src/typst/crates/typst-syntax/src/lexer.rs:893:23 Step #5: #21 0x5577f9eadaaf in ::next /src/typst/crates/typst-syntax/src/lexer.rs:120:42 Step #5: #22 0x5577f9ecd40d in ::lex /src/typst/crates/typst-syntax/src/parser.rs:1857:42 Step #5: #23 0x5577f9eccfdf in ::eat /src/typst/crates/typst-syntax/src/parser.rs:1771:22 Step #5: #24 0x5577f9f29b4f in ::expect /src/typst/crates/typst-syntax/src/parser.rs:1992:18 Step #5: #25 0x5577f9f29b4f in typst_syntax::parser::import_items /src/typst/crates/typst-syntax/src/parser.rs:966:15 Step #5: #26 0x5577f9f2c4f0 in typst_syntax::parser::module_import /src/typst/crates/typst-syntax/src/parser.rs:936:13 Step #5: #27 0x5577f9f2d335 in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:723:31 Step #5: #28 0x5577f9f2d335 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #29 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #30 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #31 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #32 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #33 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #34 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #35 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #36 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #37 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #38 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #39 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #40 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #41 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #42 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #43 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #44 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #45 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #46 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #47 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #48 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #49 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #50 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #51 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #52 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #53 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #54 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #55 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #56 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #57 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #58 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #59 0x5577f9f2b5bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #60 0x5577f9f3d345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #61 0x5577f9f36c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #62 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #63 0x5577f9f36c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #64 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #65 0x5577f9f35327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #66 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #67 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #68 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #69 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #70 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #71 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #72 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #73 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #74 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #75 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #76 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #77 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #78 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #79 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #80 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #81 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #82 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #83 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #84 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #85 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #86 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #87 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #88 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #89 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #90 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #91 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #92 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #93 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #94 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #95 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #96 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #97 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #98 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #99 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #100 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #101 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #102 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #103 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #104 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #105 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #106 0x5577f9f2b5bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #107 0x5577f9f3d345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #108 0x5577f9f36c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #109 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #110 0x5577f9f36c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #111 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #112 0x5577f9f35327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #113 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #114 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #115 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #116 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #117 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #118 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #119 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #120 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #121 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #122 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #123 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #124 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #125 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #126 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #127 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #128 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #129 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #130 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #131 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #132 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #133 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #134 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #135 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #136 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #137 0x5577f9f2b5bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #138 0x5577f9f3d345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #139 0x5577f9f36c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #140 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #141 0x5577f9f36c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #142 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #143 0x5577f9f35327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #144 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #145 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #146 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #147 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #148 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #149 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #150 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #151 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #152 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #153 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #154 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #155 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #156 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #157 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #158 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #159 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #160 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #161 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #162 0x5577f9f2e42e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:673:13 Step #5: #163 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #164 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #165 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #166 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #167 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #168 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #169 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #170 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #171 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #172 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #173 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #174 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #175 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #176 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #177 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #178 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #179 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #180 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #181 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #182 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #183 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #184 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #185 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #186 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #187 0x5577f9f2e42e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:673:13 Step #5: #188 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #189 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #190 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #191 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #192 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #193 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #194 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #195 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #196 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #197 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #198 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #199 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #200 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #201 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #202 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #203 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #204 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #205 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #206 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #207 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #208 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #209 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #210 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #211 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #212 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #213 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #214 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #215 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #216 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #217 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #218 0x5577f9f2b5bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #219 0x5577f9f3d345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #220 0x5577f9f36c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #221 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #222 0x5577f9f36c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #223 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #224 0x5577f9f35327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #225 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #226 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #227 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #228 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #229 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #230 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #231 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #232 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #233 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #234 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #235 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #236 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #237 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #238 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #239 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #240 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #241 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #242 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #243 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #244 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #245 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #246 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #247 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #248 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #249 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #250 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #251 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #252 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #253 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #254 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #255 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #256 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #257 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #258 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #259 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #260 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #261 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #262 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #263 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #264 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #265 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #266 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #267 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #268 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #269 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #270 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #271 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #272 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #273 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #274 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #275 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #276 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #277 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #278 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #279 0x5577f9f2b5bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #280 0x5577f9f3d345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #281 0x5577f9f36c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #282 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #283 0x5577f9f36c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #284 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #285 0x5577f9f35327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #286 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #287 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #288 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #289 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #290 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #291 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #292 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #293 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #294 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #295 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #296 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #297 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #298 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #299 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #300 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #301 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #302 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #303 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #304 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #305 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #306 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #307 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #308 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #309 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #310 0x5577f9f2b5bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #311 0x5577f9f3d345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #312 0x5577f9f36c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #313 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #314 0x5577f9f36c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #315 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #316 0x5577f9f35327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #317 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #318 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #319 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #320 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #321 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #322 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #323 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #324 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #325 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #326 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #327 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #328 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #329 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #330 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #331 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #332 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #333 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #334 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #335 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #336 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #337 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #338 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #339 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #340 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #341 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #342 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #343 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #344 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #345 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #346 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #347 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #348 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #349 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #350 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #351 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #352 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #353 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #354 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #355 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #356 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #357 0x5577f9f2b5bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #358 0x5577f9f3d345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #359 0x5577f9f36c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #360 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #361 0x5577f9f36c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #362 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #363 0x5577f9f35327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #364 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #365 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #366 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #367 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #368 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #369 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #370 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #371 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #372 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #373 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #374 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #375 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #376 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #377 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #378 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #379 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #380 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #381 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #382 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #383 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #384 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #385 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #386 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #387 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #388 0x5577f9f2b5bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #389 0x5577f9f3d345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #390 0x5577f9f36c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #391 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #392 0x5577f9f36c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #393 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #394 0x5577f9f35327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #395 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #396 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #397 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #398 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #399 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #400 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #401 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #402 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #403 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #404 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #405 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #406 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #407 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #408 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #409 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #410 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #411 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #412 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #413 0x5577f9f2e42e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:673:13 Step #5: #414 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #415 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #416 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #417 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #418 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #419 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #420 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #421 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #422 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #423 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #424 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #425 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #426 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #427 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #428 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #429 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #430 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #431 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #432 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #433 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #434 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #435 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #436 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #437 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #438 0x5577f9f2e42e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:673:13 Step #5: #439 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #440 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #441 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #442 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #443 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #444 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #445 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #446 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #447 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #448 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #449 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #450 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #451 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #452 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #453 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #454 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #455 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #456 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #457 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #458 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #459 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #460 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #461 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #462 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #463 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #464 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #465 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #466 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #467 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #468 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #469 0x5577f9f2b5bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #470 0x5577f9f3d345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #471 0x5577f9f36c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #472 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #473 0x5577f9f36c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #474 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #475 0x5577f9f35327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #476 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #477 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #478 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #479 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #480 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #481 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #482 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #483 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #484 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #485 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #486 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #487 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #488 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #489 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #490 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #491 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #492 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #493 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #494 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #495 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #496 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #497 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #498 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #499 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #500 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #501 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #502 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #503 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #504 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #505 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #506 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #507 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #508 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #509 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #510 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #511 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #512 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #513 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #514 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #515 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #516 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #517 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #518 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #519 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #520 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #521 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #522 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #523 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #524 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #525 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #526 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #527 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #528 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #529 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #530 0x5577f9f2b5bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #531 0x5577f9f3d345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #532 0x5577f9f36c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #533 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #534 0x5577f9f36c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #535 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #536 0x5577f9f35327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #537 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #538 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #539 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #540 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #541 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #542 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #543 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #544 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #545 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #546 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #547 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #548 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #549 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #550 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #551 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #552 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #553 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #554 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #555 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #556 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #557 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #558 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #559 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #560 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #561 0x5577f9f2b5bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #562 0x5577f9f3d345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #563 0x5577f9f36c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #564 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #565 0x5577f9f36c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #566 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #567 0x5577f9f35327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #568 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #569 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #570 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #571 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #572 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #573 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #574 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #575 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #576 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #577 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #578 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #579 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #580 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #581 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #582 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #583 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #584 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #585 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #586 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #587 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #588 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #589 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #590 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #591 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #592 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #593 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #594 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #595 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #596 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #597 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #598 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: #599 0x5577f9f342da in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1025:16 Step #5: #600 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #601 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #602 0x5577f9f3b5a4 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #603 0x5577f9f3b5a4 in typst_syntax::parser::arg /src/typst/crates/typst-syntax/src/parser.rs:1249:5 Step #5: #604 0x5577f9f3b5a4 in typst_syntax::parser::args::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1217:17 Step #5: #605 0x5577f9f3b5a4 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #606 0x5577f9f3b5a4 in typst_syntax::parser::args /src/typst/crates/typst-syntax/src/parser.rs:1207:11 Step #5: #607 0x5577f9f2d9c1 in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:629:13 Step #5: #608 0x5577f9f2b5bd in typst_syntax::parser::pattern_leaf /src/typst/crates/typst-syntax/src/parser.rs:1448:5 Step #5: #609 0x5577f9f3d345 in typst_syntax::parser::pattern /src/typst/crates/typst-syntax/src/parser.rs:1338:14 Step #5: #610 0x5577f9f36c88 in typst_syntax::parser::destructuring_item /src/typst/crates/typst-syntax/src/parser.rs:1410:9 Step #5: #611 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1362:13 Step #5: #612 0x5577f9f36c88 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #613 0x5577f9f36c88 in typst_syntax::parser::destructuring_or_parenthesized /src/typst/crates/typst-syntax/src/parser.rs:1353:7 Step #5: #614 0x5577f9f35327 in typst_syntax::parser::expr_with_paren /src/typst/crates/typst-syntax/src/parser.rs:1056:9 Step #5: #615 0x5577f9f2d46e in typst_syntax::parser::code_primary /src/typst/crates/typst-syntax/src/parser.rs:714:34 Step #5: #616 0x5577f9f2d46e in typst_syntax::parser::code_expr_prec /src/typst/crates/typst-syntax/src/parser.rs:623:9 Step #5: #617 0x5577f9f38373 in typst_syntax::parser::code_expr /src/typst/crates/typst-syntax/src/parser.rs:602:5 Step #5: #618 0x5577f9f38373 in typst_syntax::parser::array_or_dict_item /src/typst/crates/typst-syntax/src/parser.rs:1156:5 Step #5: #619 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict::{closure#0} /src/typst/crates/typst-syntax/src/parser.rs:1110:13 Step #5: #620 0x5577f9f38373 in ::with_nl_mode:: /src/typst/crates/typst-syntax/src/parser.rs:1834:9 Step #5: #621 0x5577f9f38373 in typst_syntax::parser::parenthesized_or_array_or_dict /src/typst/crates/typst-syntax/src/parser.rs:1098:7 Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::AlarmCallback() Step #5: SUMMARY: libFuzzer: timeout Step #5: MERGE-OUTER: attempt 3 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3229405748 Step #5: INFO: Loaded 1 modules (1627851 inline 8-bit counters): 1627851 [0x55e6d59b6fe0, 0x55e6d5b446ab), Step #5: INFO: Loaded 1 PC tables (1627851 PCs): 1627851 [0x55e6d5b446b0,0x55e6d741b360), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge42.txt' Step #5: MERGE-INNER: '/corpus/html/regressions/b9ccfbc12046b8ac8ba45433ca6a921731713dc1' caused a failure at the previous merge step Step #5: MERGE-INNER: 18371 total files; 17915 processed earlier; will process 456 files now Step #5: #1 pulse cov: 4570 ft: 4571 exec/s: 0 rss: 153Mb Step #5: #2 pulse cov: 5364 ft: 6298 exec/s: 1 rss: 206Mb Step #5: #4 pulse cov: 6652 ft: 9632 exec/s: 1 rss: 206Mb Step #5: #8 pulse cov: 7311 ft: 14061 exec/s: 1 rss: 206Mb Step #5: #16 pulse cov: 7671 ft: 18543 exec/s: 1 rss: 206Mb Step #5: #32 pulse cov: 7895 ft: 23012 exec/s: 1 rss: 226Mb Step #5: #64 pulse cov: 8207 ft: 27502 exec/s: 1 rss: 262Mb Step #5: #128 pulse cov: 8635 ft: 33392 exec/s: 0 rss: 413Mb Step #5: #256 pulse cov: 13398 ft: 46756 exec/s: 0 rss: 718Mb Step #5: #456 DONE cov: 14073 ft: 52425 exec/s: 0 rss: 1385Mb Step #5: MERGE-OUTER: successful in 3 attempt(s) Step #5: MERGE-OUTER: the control file has 3581768 bytes Step #5: MERGE-OUTER: consumed 2Mb (150Mb rss) to parse the control file Step #5: MERGE-OUTER: 12979 new files with 137711 new features added; 32076 new coverage edges Step #5: warning: /workspace/out/libfuzzer-coverage-x86_64/dumps/html.2602470493731073293_0.profraw: raw profile version mismatch: Profile uses raw profile format version = 11; expected version = 10 Step #5: PLEASE update this tool to version in the raw profile, or regenerate raw profile with expected version. Step #5: error: no profile can be merged Step #5: [2026-09-15 08:08:00,872 INFO] Finding shared libraries for targets (if any). Step #5: [2026-09-15 08:08:00,882 INFO] Finished finding shared libraries for targets. Step #5: error: /workspace/out/libfuzzer-coverage-x86_64/dumps/html.profdata: could not read profile data!No such file or directory Step #5: Coverage error, creating log file: /workspace/out/libfuzzer-coverage-x86_64/fuzzer_stats/html_error.log Step #5: error: /workspace/out/libfuzzer-coverage-x86_64/dumps/html.profdata: could not read profile data!No such file or directory Step #5: Error occured while running paged: Step #5: Cov returncode: 124, grep returncode: 0 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1800925773 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b3ded8f810, 0x55b3def7901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b3def79020,0x55b3e0e110e0), Step #5: MERGE-OUTER: 11029 files, 0 in the initial corpus, 0 processed earlier Step #5: MERGE-OUTER: attempt 1 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1801055996 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed7f7ba810, 0x55ed7f9a401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed7f9a4020,0x55ed8183c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: 11029 total files; 0 processed earlier; will process 11029 files now Step #5: ==67== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ed762af9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed7c914898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed7c8f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed7c8f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed762b5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed76216b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed76211355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed762a7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed79276f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed79276f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed79276f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed79276f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed79276f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed79276f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed79276f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed79276f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed79276f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed79276f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed7b50bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed78238b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed78243be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed77fefc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed77fefc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed77ff0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed77fef874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed77fef874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed77fef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed7c8f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed7c902928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed7c8ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed7c915112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc6f3d99082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed7620fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42, Step #5: B Step #5: artifact_prefix='./'; Test unit written to ./oom-ae4f281df5a5d0ff3cad6371f76d5c29b6d953ec Step #5: Base64: Qg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1801502665 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a7fb865810, 0x55a7fba4f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a7fba4f020,0x55a7fd8e70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ae4f281df5a5d0ff3cad6371f76d5c29b6d953ec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1 processed earlier; will process 11028 files now Step #5: ==106== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a7f235a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a7f89bf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a7f89a25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a7f89a24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a7f2360d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a7f22c1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a7f22bc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a7f2352c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a7f5321f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a7f5321f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a7f5321f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a7f5321f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a7f5321f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a7f5321f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a7f5321f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a7f5321f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a7f5321f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a7f5321f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a7f75b6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a7f42e3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a7f42eebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a7f409ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a7f409ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a7f409b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a7f409a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a7f409a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a7f409a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a7f89a4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a7f89ad928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a7f8995699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a7f89c0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27e0b53082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a7f22bab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d, Step #5: } Step #5: artifact_prefix='./'; Test unit written to ./oom-c2b7df6201fdd3362399091f0a29550df3505b6a Step #5: Base64: fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1801912614 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56479babc810, 0x56479bca601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56479bca6020,0x56479db3e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c2b7df6201fdd3362399091f0a29550df3505b6a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2 processed earlier; will process 11027 files now Step #5: ==142== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5647925b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564798c16898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564798bf95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564798bf94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647925b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564792518b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564792513355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647925a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564795578f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564795578f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564795578f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564795578f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564795578f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564795578f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564795578f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564795578f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564795578f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564795578f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56479780df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56479453ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564794545be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647942f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647942f1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647942f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647942f1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647942f1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647942f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564798bfbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564798c04928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564798bec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564798c17112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f35bb1a7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564792511b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50, Step #5: P Step #5: artifact_prefix='./'; Test unit written to ./oom-511993d3c99719e38a6779073019dacd7178ddb9 Step #5: Base64: UA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1802322725 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563db6def810, 0x563db6fd901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563db6fd9020,0x563db8e710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/511993d3c99719e38a6779073019dacd7178ddb9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3 processed earlier; will process 11026 files now Step #5: ==178== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563dad8e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563db3f49898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563db3f2c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563db3f2c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563dad8ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563dad84bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563dad846355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563dad8dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563db08abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563db08abf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563db08abf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563db08abf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563db08abf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563db08abf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563db08abf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563db08abf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563db08abf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563db08abf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563db2b40f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563daf86db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563daf878be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563daf624c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563daf624c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563daf625738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563daf624874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563daf624874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563daf624874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563db3f2eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563db3f37928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563db3f1f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563db3f4a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5c8578d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563dad844b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27, Step #5: ' Step #5: artifact_prefix='./'; Test unit written to ./oom-bb589d0621e5472f470fa3425a234c74b1e202e8 Step #5: Base64: Jw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1802734124 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc99ec1810, 0x55cc9a0ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc9a0ab020,0x55cc9bf430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bb589d0621e5472f470fa3425a234c74b1e202e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4 processed earlier; will process 11025 files now Step #5: ==214== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cc909b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc9701b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc96ffe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc96ffe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc909bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc9091db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc90918355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc909aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc9397df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc9397df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc9397df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc9397df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc9397df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc9397df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc9397df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc9397df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc9397df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc9397df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc95c12f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc9293fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc9294abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc926f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc926f6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc926f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc926f6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc926f6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc926f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc97000abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc97009928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc96ff1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc9701c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f803300c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc90916b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26, Step #5: & Step #5: artifact_prefix='./'; Test unit written to ./oom-7c4d33785daa5c2370201ffa236b427aa37c9996 Step #5: Base64: Jg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1803140639 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5648d399b810, 0x5648d3b8501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5648d3b85020,0x5648d5a1d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7c4d33785daa5c2370201ffa236b427aa37c9996' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5 processed earlier; will process 11024 files now Step #5: #1 pulse cov: 3377 ft: 3378 exec/s: 0 rss: 152Mb Step #5: ==250== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5648ca4909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5648d0af5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5648d0ad85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5648d0ad84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5648ca496d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5648ca3f7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5648ca3f2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5648ca488c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5648cd457f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5648cd457f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5648cd457f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5648cd457f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5648cd457f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5648cd457f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5648cd457f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5648cd457f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5648cd457f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5648cd457f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5648cf6ecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5648cc419b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5648cc424be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5648cc1d0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5648cc1d0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5648cc1d1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5648cc1d0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5648cc1d0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5648cc1d0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5648d0adaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5648d0ae3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5648d0acb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5648d0af6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8f7ca18082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5648ca3f0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a, Step #5: : Step #5: artifact_prefix='./'; Test unit written to ./oom-05a79f06cf3f67f726dae68d18a2290f6c9a50c9 Step #5: Base64: Og== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 7 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1803591310 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558eed014810, 0x558eed1fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558eed1fe020,0x558eef0960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/05a79f06cf3f67f726dae68d18a2290f6c9a50c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7 processed earlier; will process 11022 files now Step #5: #1 pulse cov: 3370 ft: 3371 exec/s: 0 rss: 152Mb Step #5: ==286== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558ee3b099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558eea16e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558eea1515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558eea1514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558ee3b0fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558ee3a70b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558ee3a6b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558ee3b01c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558ee6ad0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558ee6ad0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558ee6ad0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558ee6ad0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558ee6ad0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558ee6ad0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558ee6ad0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558ee6ad0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558ee6ad0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558ee6ad0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558ee8d65f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ee5a92b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ee5a9dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ee5849c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ee5849c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ee584a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ee5849874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ee5849874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ee5849874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558eea153abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558eea15c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558eea144699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558eea16f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc95a464082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558ee3a69b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x67, Step #5: g Step #5: artifact_prefix='./'; Test unit written to ./oom-54fd1711209fb1c0781092374132c66e79e2241b Step #5: Base64: Zw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 8 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1804046671 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a56aee2810, 0x55a56b0cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a56b0cc020,0x55a56cf640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/54fd1711209fb1c0781092374132c66e79e2241b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 9 processed earlier; will process 11020 files now Step #5: ==322== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a5619d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a56803c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a56801f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a56801f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a5619ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a56193eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a561939355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a5619cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a56499ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a56499ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a56499ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a56499ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a56499ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a56499ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a56499ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a56499ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a56499ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a56499ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a566c33f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a563960b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a56396bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a563717c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a563717c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a563718738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a563717874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a563717874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a563717874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a568021abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a56802a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a568012699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a56803d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb6961fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a561937b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0, Step #5: \360 Step #5: artifact_prefix='./'; Test unit written to ./oom-efe43def97eb295fe99c3753f2d740d7b36df689 Step #5: Base64: 8A== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 9 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1804445923 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca5d98b810, 0x55ca5db7501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca5db75020,0x55ca5fa0d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/efe43def97eb295fe99c3753f2d740d7b36df689' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 10 processed earlier; will process 11019 files now Step #5: ==358== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ca544809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca5aae5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca5aac85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca5aac84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca54486d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca543e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca543e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca54478c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca57447f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca57447f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca57447f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca57447f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca57447f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca57447f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca57447f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca57447f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca57447f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca57447f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca596dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca56409b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca56414be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca561c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca561c0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca561c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca561c0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca561c0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca561c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca5aacaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca5aad3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca5aabb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca5aae6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1e4222c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca543e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1, Step #5: \001 Step #5: artifact_prefix='./'; Test unit written to ./oom-bf8b4530d8d246dd74ac53a13471bba17941dff7 Step #5: Base64: AQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 10 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1804858642 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610de23d810, 0x5610de42701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610de427020,0x5610e02bf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf8b4530d8d246dd74ac53a13471bba17941dff7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 11 processed earlier; will process 11018 files now Step #5: ==394== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5610d4d329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610db397898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610db37a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610db37a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610d4d38d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610d4c99b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610d4c94355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610d4d2ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610d7cf9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610d7cf9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610d7cf9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610d7cf9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610d7cf9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610d7cf9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610d7cf9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610d7cf9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610d7cf9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610d7cf9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610d9f8ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610d6cbbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610d6cc6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610d6a72c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610d6a72c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610d6a73738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610d6a72874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610d6a72874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610d6a72874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610db37cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610db385928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610db36d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610db398112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4753f7d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610d4c92b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73, Step #5: s Step #5: artifact_prefix='./'; Test unit written to ./oom-a0f1490a20d0211c997b44bc357e1972deab8ae3 Step #5: Base64: cw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 11 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1805276213 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a6b2dbb810, 0x55a6b2fa501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a6b2fa5020,0x55a6b4e3d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a0f1490a20d0211c997b44bc357e1972deab8ae3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 12 processed earlier; will process 11017 files now Step #5: ==430== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a6a98b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a6aff15898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a6afef85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a6afef84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a6a98b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a6a9817b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a6a9812355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a6a98a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a6ac877f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a6ac877f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a6ac877f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a6ac877f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a6ac877f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a6ac877f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a6ac877f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a6ac877f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a6ac877f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a6ac877f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a6aeb0cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a6ab839b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a6ab844be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a6ab5f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a6ab5f0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a6ab5f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a6ab5f0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a6ab5f0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a6ab5f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a6afefaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a6aff03928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a6afeeb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a6aff16112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0a686ba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a6a9810b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b, Step #5: [ Step #5: artifact_prefix='./'; Test unit written to ./oom-1e5c2f367f02e47a8c160cda1cd9d91decbac441 Step #5: Base64: Ww== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 12 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1805693532 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561579008810, 0x5615791f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5615791f2020,0x56157b08a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e5c2f367f02e47a8c160cda1cd9d91decbac441' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 13 processed earlier; will process 11016 files now Step #5: ==466== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56156fafd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561576162898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5615761455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5615761454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56156fb03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56156fa64b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56156fa5f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56156faf5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561572ac4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561572ac4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561572ac4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561572ac4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561572ac4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561572ac4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561572ac4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561572ac4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561572ac4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561572ac4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561574d59f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561571a86b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561571a91be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56157183dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56157183dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56157183e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56157183d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56157183d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56157183d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561576147abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561576150928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561576138699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561576163112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5f69c5a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56156fa5db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f, Step #5: ? Step #5: artifact_prefix='./'; Test unit written to ./oom-5bab61eb53176449e25c2c82f172b82cb13ffb9d Step #5: Base64: Pw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 13 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1806116826 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610b868d810, 0x5610b887701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610b8877020,0x5610ba70f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5bab61eb53176449e25c2c82f172b82cb13ffb9d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 14 processed earlier; will process 11015 files now Step #5: ==502== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5610af1829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610b57e7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610b57ca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610b57ca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610af188d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610af0e9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610af0e4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610af17ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610b2149f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610b2149f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610b2149f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610b2149f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610b2149f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610b2149f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610b2149f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610b2149f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610b2149f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610b2149f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610b43def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610b110bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610b1116be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610b0ec2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610b0ec2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610b0ec3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610b0ec2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610b0ec2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610b0ec2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610b57ccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610b57d5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610b57bd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610b57e8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f38c073b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610af0e2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x40, Step #5: @ Step #5: artifact_prefix='./'; Test unit written to ./oom-9a78211436f6d425ec38f5c4e02270801f3524f8 Step #5: Base64: QA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 14 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1806545170 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556843b97810, 0x556843d8101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556843d81020,0x556845c190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9a78211436f6d425ec38f5c4e02270801f3524f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 15 processed earlier; will process 11014 files now Step #5: ==538== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55683a68c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556840cf1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556840cd45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556840cd44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55683a692d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55683a5f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55683a5ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55683a684c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55683d653f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55683d653f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55683d653f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55683d653f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55683d653f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55683d653f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55683d653f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55683d653f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55683d653f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55683d653f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55683f8e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55683c615b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55683c620be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55683c3ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55683c3ccc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55683c3cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55683c3cc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55683c3cc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55683c3cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556840cd6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556840cdf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556840cc7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556840cf2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1ad66f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55683a5ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x17, Step #5: \027 Step #5: artifact_prefix='./'; Test unit written to ./oom-094d98b399bf4ace7b8899ab7081e867fb03f869 Step #5: Base64: Fw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 15 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1806963966 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c707c70810, 0x55c707e5a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c707e5a020,0x55c709cf20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/094d98b399bf4ace7b8899ab7081e867fb03f869' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 16 processed earlier; will process 11013 files now Step #5: ==574== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c6fe7659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c704dca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c704dad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c704dad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c6fe76bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6fe6ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6fe6c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c6fe75dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c70172cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c70172cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c70172cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c70172cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c70172cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c70172cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c70172cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c70172cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c70172cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c70172cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7039c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7006eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7006f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7004a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7004a5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7004a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7004a5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7004a5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7004a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c704dafabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c704db8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c704da0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c704dcb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5b3f0ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6fe6c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2, Step #5: \002 Step #5: artifact_prefix='./'; Test unit written to ./oom-c4ea21bb365bbeeaf5f2c654883e56d11e43c44e Step #5: Base64: Ag== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 16 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1807380255 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea71f38810, 0x55ea7212201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea72122020,0x55ea73fba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c4ea21bb365bbeeaf5f2c654883e56d11e43c44e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 17 processed earlier; will process 11012 files now Step #5: ==610== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ea68a2d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea6f092898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea6f0755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea6f0754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea68a33d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea68994b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea6898f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea68a25c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea6b9f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea6b9f4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea6b9f4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea6b9f4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea6b9f4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea6b9f4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea6b9f4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea6b9f4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea6b9f4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea6b9f4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea6dc89f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea6a9b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea6a9c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea6a76dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea6a76dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea6a76e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea6a76d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea6a76d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea6a76d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea6f077abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea6f080928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea6f068699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea6f093112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ccce07082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea6898db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25, Step #5: % Step #5: artifact_prefix='./'; Test unit written to ./oom-4345cb1fa27885a8fbfe7c0c830a592cc76a552b Step #5: Base64: JQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 17 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1807798235 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555943c4f810, 0x555943e3901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555943e39020,0x555945cd10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4345cb1fa27885a8fbfe7c0c830a592cc76a552b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 18 processed earlier; will process 11011 files now Step #5: ==646== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55593a7449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555940da9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555940d8c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555940d8c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55593a74ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55593a6abb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55593a6a6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55593a73cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55593d70bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55593d70bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55593d70bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55593d70bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55593d70bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55593d70bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55593d70bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55593d70bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55593d70bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55593d70bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55593f9a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55593c6cdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55593c6d8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55593c484c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55593c484c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55593c485738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55593c484874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55593c484874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55593c484874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555940d8eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555940d97928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555940d7f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555940daa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fafe236d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55593a6a4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x10, Step #5: \020 Step #5: artifact_prefix='./'; Test unit written to ./oom-6e14a407faae939957b80e641a836735bbdcad5a Step #5: Base64: EA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 18 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1808214654 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55861daaf810, 0x55861dc9901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55861dc99020,0x55861fb310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6e14a407faae939957b80e641a836735bbdcad5a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 19 processed earlier; will process 11010 files now Step #5: ==682== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5586145a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55861ac09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55861abec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55861abec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5586145aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55861450bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558614506355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55861459cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55861756bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55861756bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55861756bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55861756bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55861756bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55861756bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55861756bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55861756bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55861756bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55861756bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558619800f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55861652db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558616538be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5586162e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5586162e4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5586162e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5586162e4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5586162e4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5586162e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55861abeeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55861abf7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55861abdf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55861ac0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1ab2faf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558614504b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20, Step #5: Step #5: artifact_prefix='./'; Test unit written to ./oom-b858cb282617fb0956d960215c8e84d1ccf909c6 Step #5: Base64: IA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 19 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1808609130 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b5a6130810, 0x55b5a631a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b5a631a020,0x55b5a81b20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b858cb282617fb0956d960215c8e84d1ccf909c6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 20 processed earlier; will process 11009 files now Step #5: ==718== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b59cc259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b5a328a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b5a326d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b5a326d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b59cc2bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b59cb8cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b59cb87355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b59cc1dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b59fbecf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b59fbecf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b59fbecf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b59fbecf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b59fbecf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b59fbecf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b59fbecf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b59fbecf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b59fbecf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b59fbecf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b5a1e81f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b59ebaeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b59ebb9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b59e965c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b59e965c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b59e966738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b59e965874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b59e965874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b59e965874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b5a326fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b5a3278928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b5a3260699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b5a328b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7710afb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b59cb85b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdd, Step #5: \335 Step #5: artifact_prefix='./'; Test unit written to ./oom-a4ac408fb9d6def070ad3a76312ca092863048e5 Step #5: Base64: 3Q== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 20 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1809009071 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652621f6810, 0x5652623e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652623e0020,0x5652642780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a4ac408fb9d6def070ad3a76312ca092863048e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 21 processed earlier; will process 11008 files now Step #5: ==754== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x565258ceb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56525f350898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56525f3335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56525f3334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565258cf1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565258c52b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565258c4d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565258ce3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56525bcb2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56525bcb2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56525bcb2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56525bcb2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56525bcb2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56525bcb2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56525bcb2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56525bcb2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56525bcb2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56525bcb2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56525df47f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56525ac74b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56525ac7fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56525aa2bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56525aa2bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56525aa2c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56525aa2b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56525aa2b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56525aa2b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56525f335abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56525f33e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56525f326699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56525f351112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff2af0ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565258c4bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31, Step #5: 1 Step #5: artifact_prefix='./'; Test unit written to ./oom-356a192b7913b04c54574d18c28d46e6395428ab Step #5: Base64: MQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 21 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1809419100 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562792a14810, 0x562792bfe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562792bfe020,0x562794a960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/356a192b7913b04c54574d18c28d46e6395428ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 22 processed earlier; will process 11007 files now Step #5: ==790== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5627895099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56278fb6e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56278fb515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56278fb514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56278950fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562789470b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56278946b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562789501c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56278c4d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56278c4d0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56278c4d0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56278c4d0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56278c4d0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56278c4d0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56278c4d0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56278c4d0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56278c4d0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56278c4d0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56278e765f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56278b492b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56278b49dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56278b249c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56278b249c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56278b24a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56278b249874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56278b249874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56278b249874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56278fb53abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56278fb5c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56278fb44699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56278fb6f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f24a2549082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562789469b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x11, Step #5: \021 Step #5: artifact_prefix='./'; Test unit written to ./oom-a8abd012eb59b862bf9bc1ea443d2f35a1a2e222 Step #5: Base64: EQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 22 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1809831352 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562989e68810, 0x56298a05201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56298a052020,0x56298beea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a8abd012eb59b862bf9bc1ea443d2f35a1a2e222' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 23 processed earlier; will process 11006 files now Step #5: ==826== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56298095d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562986fc2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562986fa55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562986fa54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562980963d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629808c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629808bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562980955c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562983924f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562983924f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562983924f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562983924f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562983924f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562983924f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562983924f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562983924f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562983924f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562983924f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562985bb9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629828e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629828f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56298269dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56298269dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56298269e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56298269d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56298269d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56298269d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562986fa7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562986fb0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562986f98699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562986fc3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9d004a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629808bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7f, Step #5: \177 Step #5: artifact_prefix='./'; Test unit written to ./oom-23833462f55515a900e016db2eb943fb474c19f6 Step #5: Base64: fw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 23 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1810243378 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555eb93fe810, 0x555eb95e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555eb95e8020,0x555ebb4800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/23833462f55515a900e016db2eb943fb474c19f6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 24 processed earlier; will process 11005 files now Step #5: ==862== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555eafef39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555eb6558898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555eb653b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555eb653b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555eafef9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555eafe5ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555eafe55355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555eafeebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555eb2ebaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555eb2ebaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555eb2ebaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555eb2ebaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555eb2ebaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555eb2ebaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555eb2ebaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555eb2ebaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555eb2ebaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555eb2ebaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555eb514ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555eb1e7cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555eb1e87be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555eb1c33c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555eb1c33c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555eb1c34738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555eb1c33874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555eb1c33874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555eb1c33874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555eb653dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555eb6546928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555eb652e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555eb6559112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f436007f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555eafe53b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x58, Step #5: X Step #5: artifact_prefix='./'; Test unit written to ./oom-c032adc1ff629c9b66f22749ad667e6beadf144b Step #5: Base64: WA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 24 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1810655499 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55602618e810, 0x55602637801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556026378020,0x5560282100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c032adc1ff629c9b66f22749ad667e6beadf144b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 25 processed earlier; will process 11004 files now Step #5: ==898== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55601cc839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5560232e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5560232cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5560232cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55601cc89d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55601cbeab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55601cbe5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55601cc7bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55601fc4af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55601fc4af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55601fc4af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55601fc4af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55601fc4af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55601fc4af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55601fc4af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55601fc4af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55601fc4af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55601fc4af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556021edff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55601ec0cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55601ec17be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55601e9c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55601e9c3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55601e9c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55601e9c3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55601e9c3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55601e9c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5560232cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5560232d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5560232be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5560232e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf8f06d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55601cbe3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xfe, Step #5: \376 Step #5: artifact_prefix='./'; Test unit written to ./oom-b68542373c05c0ed25231d09955b2c699d37c45b Step #5: Base64: /g== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 25 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1811055167 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c9b7e38810, 0x55c9b802201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c9b8022020,0x55c9b9eba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b68542373c05c0ed25231d09955b2c699d37c45b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 26 processed earlier; will process 11003 files now Step #5: ==934== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c9ae92d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c9b4f92898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9b4f755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9b4f754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9ae933d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9ae894b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c9ae88f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9ae925c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c9b18f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c9b18f4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c9b18f4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c9b18f4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c9b18f4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c9b18f4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c9b18f4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c9b18f4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c9b18f4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c9b18f4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c9b3b89f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9b08b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9b08c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c9b066dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c9b066dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c9b066e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c9b066d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c9b066d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c9b066d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c9b4f77abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c9b4f80928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c9b4f68699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c9b4f93112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2cefaaf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c9ae88db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf7, Step #5: \367 Step #5: artifact_prefix='./'; Test unit written to ./oom-73b74736664ad85828ce1be2e29fb4a68d24402b Step #5: Base64: 9w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 26 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1811454265 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560634977810, 0x560634b6101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560634b61020,0x5606369f90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/73b74736664ad85828ce1be2e29fb4a68d24402b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 27 processed earlier; will process 11002 files now Step #5: ==970== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56062b46c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560631ad1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560631ab45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560631ab44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56062b472d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56062b3d3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56062b3ce355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56062b464c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56062e433f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56062e433f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56062e433f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56062e433f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56062e433f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56062e433f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56062e433f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56062e433f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56062e433f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56062e433f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606306c8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56062d3f5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56062d400be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56062d1acc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56062d1acc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56062d1ad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56062d1ac874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56062d1ac874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56062d1ac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560631ab6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560631abf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560631aa7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560631ad2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd2cbe1d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56062b3ccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69, Step #5: i Step #5: artifact_prefix='./'; Test unit written to ./oom-042dc4512fa3d391c5170cf3aa61e6a638f84342 Step #5: Base64: aQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 27 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1811869305 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ae29cea810, 0x55ae29ed401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ae29ed4020,0x55ae2bd6c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/042dc4512fa3d391c5170cf3aa61e6a638f84342' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 28 processed earlier; will process 11001 files now Step #5: ==1006== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ae207df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ae26e44898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ae26e275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ae26e274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ae207e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ae20746b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ae20741355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ae207d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ae237a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ae237a6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ae237a6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ae237a6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ae237a6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ae237a6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ae237a6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ae237a6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ae237a6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ae237a6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ae25a3bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ae22768b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ae22773be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ae2251fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ae2251fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ae22520738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ae2251f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ae2251f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ae2251f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ae26e29abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ae26e32928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ae26e1a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ae26e45112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6c8ff55082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ae2073fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1d, Step #5: \035 Step #5: artifact_prefix='./'; Test unit written to ./oom-5983ad8f6bfea1deda79409c844f51379c52be2d Step #5: Base64: HQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 28 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1812278226 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562079461810, 0x56207964b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56207964b020,0x56207b4e30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5983ad8f6bfea1deda79409c844f51379c52be2d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 29 processed earlier; will process 11000 files now Step #5: ==1042== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56206ff569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5620765bb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56207659e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56207659e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56206ff5cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56206febdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56206feb8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56206ff4ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562072f1df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562072f1df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562072f1df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562072f1df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562072f1df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562072f1df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562072f1df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562072f1df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562072f1df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562072f1df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5620751b2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562071edfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562071eeabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562071c96c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562071c96c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562071c97738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562071c96874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562071c96874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562071c96874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5620765a0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5620765a9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562076591699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5620765bc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf24d5e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56206feb6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32, Step #5: 2 Step #5: artifact_prefix='./'; Test unit written to ./oom-da4b9237bacccdf19c0760cab7aec4a8359010b0 Step #5: Base64: Mg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 29 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1812684169 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5653e07c7810, 0x5653e09b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5653e09b1020,0x5653e28490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/da4b9237bacccdf19c0760cab7aec4a8359010b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 30 processed earlier; will process 10999 files now Step #5: #1 pulse cov: 3438 ft: 3439 exec/s: 0 rss: 153Mb Step #5: ==1078== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5653d72bc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5653dd921898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5653dd9045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5653dd9044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5653d72c2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5653d7223b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5653d721e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5653d72b4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5653da283f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5653da283f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5653da283f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5653da283f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5653da283f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5653da283f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5653da283f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5653da283f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5653da283f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5653da283f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5653dc518f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5653d9245b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5653d9250be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5653d8ffcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5653d8ffcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5653d8ffd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5653d8ffc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5653d8ffc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5653d8ffc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5653dd906abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5653dd90f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5653dd8f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5653dd922112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f931b73c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5653d721cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4b, Step #5: K Step #5: artifact_prefix='./'; Test unit written to ./oom-a7ee38bb7be4fc44198cb2685d9601dcf2b9f569 Step #5: Base64: Sw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 30 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1813134826 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f5d9f1a810, 0x55f5da10401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f5da104020,0x55f5dbf9c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a7ee38bb7be4fc44198cb2685d9601dcf2b9f569' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 32 processed earlier; will process 10997 files now Step #5: ==1114== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f5d0a0f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f5d7074898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f5d70575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f5d70574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f5d0a15d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f5d0976b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f5d0971355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f5d0a07c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f5d39d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f5d39d6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f5d39d6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f5d39d6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f5d39d6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f5d39d6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f5d39d6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f5d39d6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f5d39d6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f5d39d6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f5d5c6bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f5d2998b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f5d29a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f5d274fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f5d274fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f5d2750738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f5d274f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f5d274f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f5d274f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f5d7059abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f5d7062928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f5d704a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f5d7075112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa00d40a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f5d096fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3b, Step #5: ; Step #5: artifact_prefix='./'; Test unit written to ./oom-2d14ab97cc3dc294c51c0d6814f4ea45f4b4e312 Step #5: Base64: Ow== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 31 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1813555602 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5614563ed810, 0x5614565d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5614565d7020,0x56145846f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2d14ab97cc3dc294c51c0d6814f4ea45f4b4e312' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 33 processed earlier; will process 10996 files now Step #5: ==1150== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56144cee29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561453547898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56145352a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56145352a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56144cee8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56144ce49b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56144ce44355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56144cedac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56144fea9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56144fea9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56144fea9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56144fea9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56144fea9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56144fea9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56144fea9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56144fea9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56144fea9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56144fea9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56145213ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56144ee6bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56144ee76be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56144ec22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56144ec22c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56144ec23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56144ec22874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56144ec22874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56144ec22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56145352cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561453535928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56145351d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561453548112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1e47d14082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56144ce42b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0, Step #5: \000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ba93c9db0cff93f52b521d7420e43f6eda2784f Step #5: Base64: AA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 32 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1813976802 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b057ff810, 0x560b059e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b059e9020,0x560b078810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ba93c9db0cff93f52b521d7420e43f6eda2784f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 34 processed earlier; will process 10995 files now Step #5: ==1186== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560afc2f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b02959898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b0293c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b0293c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560afc2fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560afc25bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560afc256355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560afc2ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560aff2bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560aff2bbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560aff2bbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560aff2bbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560aff2bbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560aff2bbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560aff2bbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560aff2bbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560aff2bbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560aff2bbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b01550f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560afe27db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560afe288be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560afe034c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560afe034c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560afe035738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560afe034874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560afe034874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560afe034874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b0293eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b02947928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b0292f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b0295a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f79d127c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560afc254b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63, Step #5: c Step #5: artifact_prefix='./'; Test unit written to ./oom-84a516841ba77a5b4648de2cd0dfcb30ea46dbb4 Step #5: Base64: Yw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 33 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1814395609 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560d4c3d8810, 0x560d4c5c201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560d4c5c2020,0x560d4e45a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/84a516841ba77a5b4648de2cd0dfcb30ea46dbb4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 35 processed earlier; will process 10994 files now Step #5: ==1222== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560d42ecd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560d49532898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560d495155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560d495154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560d42ed3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560d42e34b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560d42e2f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560d42ec5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560d45e94f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560d45e94f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560d45e94f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560d45e94f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560d45e94f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560d45e94f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560d45e94f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560d45e94f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560d45e94f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560d45e94f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560d48129f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560d44e56b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560d44e61be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560d44c0dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560d44c0dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560d44c0e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560d44c0d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560d44c0d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560d44c0d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560d49517abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560d49520928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560d49508699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560d49533112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda453f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560d42e2db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30, Step #5: 0 Step #5: artifact_prefix='./'; Test unit written to ./oom-b6589fc6ab0dc82cf12099d1c2d40ab994e8410c Step #5: Base64: MA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 34 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1814810414 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5653cd2c8810, 0x5653cd4b201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5653cd4b2020,0x5653cf34a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b6589fc6ab0dc82cf12099d1c2d40ab994e8410c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 36 processed earlier; will process 10993 files now Step #5: ==1258== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5653c3dbd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5653ca422898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5653ca4055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5653ca4054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5653c3dc3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5653c3d24b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5653c3d1f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5653c3db5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5653c6d84f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5653c6d84f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5653c6d84f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5653c6d84f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5653c6d84f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5653c6d84f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5653c6d84f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5653c6d84f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5653c6d84f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5653c6d84f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5653c9019f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5653c5d46b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5653c5d51be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5653c5afdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5653c5afdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5653c5afe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5653c5afd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5653c5afd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5653c5afd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5653ca407abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5653ca410928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5653ca3f8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5653ca423112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7ff4ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5653c3d1db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c, Step #5: < Step #5: artifact_prefix='./'; Test unit written to ./oom-c4dd3c8cdd8d7c95603dd67f1cd873d5f9148b29 Step #5: Base64: PA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 35 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1815224347 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563f86df8810, 0x563f86fe201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563f86fe2020,0x563f88e7a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c4dd3c8cdd8d7c95603dd67f1cd873d5f9148b29' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 37 processed earlier; will process 10992 files now Step #5: ==1294== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563f7d8ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563f83f52898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563f83f355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563f83f354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563f7d8f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563f7d854b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563f7d84f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563f7d8e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563f808b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563f808b4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563f808b4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563f808b4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563f808b4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563f808b4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563f808b4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563f808b4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563f808b4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563f808b4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563f82b49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563f7f876b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563f7f881be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563f7f62dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563f7f62dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563f7f62e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563f7f62d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563f7f62d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563f7f62d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563f83f37abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563f83f40928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563f83f28699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563f83f53112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f008e22a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563f7d84db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x38, Step #5: 8 Step #5: artifact_prefix='./'; Test unit written to ./oom-fe5dbbcea5ce7e2988b8c69bcfdfde8904aabc1f Step #5: Base64: OA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 36 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1815639084 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558f14188810, 0x558f1437201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558f14372020,0x558f1620a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fe5dbbcea5ce7e2988b8c69bcfdfde8904aabc1f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 38 processed earlier; will process 10991 files now Step #5: ==1330== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558f0ac7d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558f112e2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558f112c55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558f112c54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f0ac83d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f0abe4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f0abdf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f0ac75c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f0dc44f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f0dc44f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f0dc44f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f0dc44f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f0dc44f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f0dc44f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f0dc44f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f0dc44f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f0dc44f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f0dc44f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558f0fed9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f0cc06b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f0cc11be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f0c9bdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f0c9bdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f0c9be738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f0c9bd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f0c9bd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f0c9bd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558f112c7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558f112d0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558f112b8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558f112e3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fef27608082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f0abddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x34, Step #5: 4 Step #5: artifact_prefix='./'; Test unit written to ./oom-1b6453892473a467d07372d45eb05abc2031647a Step #5: Base64: NA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 37 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1816052141 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f18e6ad810, 0x55f18e89701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f18e897020,0x55f19072f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b6453892473a467d07372d45eb05abc2031647a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 39 processed earlier; will process 10990 files now Step #5: ==1366== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f1851a29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f18b807898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f18b7ea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f18b7ea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f1851a8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f185109b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f185104355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f18519ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f188169f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f188169f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f188169f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f188169f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f188169f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f188169f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f188169f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f188169f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f188169f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f188169f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f18a3fef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f18712bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f187136be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f186ee2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f186ee2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f186ee3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f186ee2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f186ee2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f186ee2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f18b7ecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f18b7f5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f18b7dd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f18b808112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ada103082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f185102b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd, Step #5: \015 Step #5: artifact_prefix='./'; Test unit written to ./oom-11f4de6b8b45cf8051b1d17fa4cde9ad935cea41 Step #5: Base64: DQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 38 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1816448313 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56013a335810, 0x56013a51f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56013a51f020,0x56013c3b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/11f4de6b8b45cf8051b1d17fa4cde9ad935cea41' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 40 processed earlier; will process 10989 files now Step #5: ==1402== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560130e2a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56013748f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601374725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601374724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560130e30d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560130d91b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560130d8c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560130e22c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560133df1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560133df1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560133df1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560133df1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560133df1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560133df1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560133df1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560133df1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560133df1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560133df1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560136086f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560132db3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560132dbebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560132b6ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560132b6ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560132b6b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560132b6a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560132b6a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560132b6a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560137474abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56013747d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560137465699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560137490112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f37f1d0f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560130d8ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44, Step #5: D Step #5: artifact_prefix='./'; Test unit written to ./oom-50c9e8d5fc98727b4bbc93cf5d64a68db647f04f Step #5: Base64: RA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 39 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1816869714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d99bd8c810, 0x55d99bf7601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d99bf76020,0x55d99de0e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/50c9e8d5fc98727b4bbc93cf5d64a68db647f04f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 41 processed earlier; will process 10988 files now Step #5: ==1438== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d9928819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d998ee6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d998ec95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d998ec94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d992887d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d9927e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d9927e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d992879c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d995848f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d995848f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d995848f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d995848f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d995848f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d995848f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d995848f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d995848f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d995848f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d995848f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d997addf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d99480ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d994815be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d9945c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d9945c1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d9945c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d9945c1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d9945c1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d9945c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d998ecbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d998ed4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d998ebc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d998ee7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb0276e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d9927e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f, Step #5: o Step #5: artifact_prefix='./'; Test unit written to ./oom-7a81af3e591ac713f81ea1efe93dcf36157d8376 Step #5: Base64: bw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 40 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1817294367 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556aece25810, 0x556aed00f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556aed00f020,0x556aeeea70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7a81af3e591ac713f81ea1efe93dcf36157d8376' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 42 processed earlier; will process 10987 files now Step #5: ==1474== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556ae391a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556ae9f7f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556ae9f625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556ae9f624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556ae3920d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556ae3881b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556ae387c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556ae3912c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556ae68e1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556ae68e1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556ae68e1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556ae68e1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556ae68e1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556ae68e1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556ae68e1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556ae68e1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556ae68e1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556ae68e1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556ae8b76f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556ae58a3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556ae58aebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556ae565ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556ae565ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556ae565b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556ae565a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556ae565a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556ae565a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556ae9f64abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556ae9f6d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556ae9f55699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556ae9f80112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e08fcb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556ae387ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa, Step #5: \012 Step #5: artifact_prefix='./'; Test unit written to ./oom-adc83b19e793491b1c6ea0fd8b46cd9f32e592fc Step #5: Base64: Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 41 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1817698293 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55610f797810, 0x55610f98101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55610f981020,0x5561118190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/adc83b19e793491b1c6ea0fd8b46cd9f32e592fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 43 processed earlier; will process 10986 files now Step #5: ==1510== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55610628c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55610c8f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55610c8d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55610c8d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556106292d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5561061f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5561061ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556106284c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556109253f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556109253f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556109253f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556109253f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556109253f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556109253f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556109253f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556109253f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556109253f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556109253f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55610b4e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556108215b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556108220be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556107fccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556107fccc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556107fcd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556107fcc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556107fcc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556107fcc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55610c8d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55610c8df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55610c8c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55610c8f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda94c97082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5561061ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x9e, Step #5: \236 Step #5: artifact_prefix='./'; Test unit written to ./oom-a2dfa9429bf2a04d8f23fe980209bd5315f80523 Step #5: Base64: ng== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 42 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1818106730 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55794c798810, 0x55794c98201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55794c982020,0x55794e81a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2dfa9429bf2a04d8f23fe980209bd5315f80523' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 44 processed earlier; will process 10985 files now Step #5: ==1546== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55794328d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5579498f2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5579498d55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5579498d54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557943293d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5579431f4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5579431ef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557943285c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557946254f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557946254f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557946254f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557946254f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557946254f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557946254f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557946254f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557946254f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557946254f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557946254f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579484e9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557945216b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557945221be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557944fcdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557944fcdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557944fce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557944fcd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557944fcd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557944fcd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5579498d7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5579498e0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5579498c8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5579498f3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb867db6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5579431edb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46, Step #5: F Step #5: artifact_prefix='./'; Test unit written to ./oom-e69f20e9f683920d3fb4329abd951e878b1f9372 Step #5: Base64: Rg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 43 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1818537320 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ebacc22810, 0x55ebace0c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ebace0c020,0x55ebaeca40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e69f20e9f683920d3fb4329abd951e878b1f9372' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 45 processed earlier; will process 10984 files now Step #5: ==1582== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eba37179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eba9d7c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eba9d5f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eba9d5f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eba371dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eba367eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eba3679355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eba370fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eba66def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eba66def10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eba66def10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eba66def10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eba66def10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eba66def10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eba66def10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eba66def10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eba66def10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eba66def10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eba8973f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eba56a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eba56abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eba5457c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eba5457c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eba5458738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eba5457874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eba5457874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eba5457874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eba9d61abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eba9d6a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eba9d52699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eba9d7d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f732eec1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eba3677b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x51, Step #5: Q Step #5: artifact_prefix='./'; Test unit written to ./oom-c3156e00d3c2588c639e0d3cf6821258b05761c7 Step #5: Base64: UQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 44 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1818960043 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d8df777810, 0x55d8df96101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d8df961020,0x55d8e17f90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c3156e00d3c2588c639e0d3cf6821258b05761c7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 46 processed earlier; will process 10983 files now Step #5: ==1618== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d8d626c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d8dc8d1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d8dc8b45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d8dc8b44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d8d6272d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d8d61d3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d8d61ce355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d8d6264c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d8d9233f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d8d9233f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d8d9233f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d8d9233f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d8d9233f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d8d9233f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d8d9233f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d8d9233f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d8d9233f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d8d9233f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d8db4c8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d8d81f5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d8d8200be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d8d7facc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d8d7facc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d8d7fad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d8d7fac874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d8d7fac874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d8d7fac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d8dc8b6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d8dc8bf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d8dc8a7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d8dc8d2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa680db0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d8d61ccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4e, Step #5: N Step #5: artifact_prefix='./'; Test unit written to ./oom-b51a60734da64be0e618bacbea2865a8a7dcd669 Step #5: Base64: Tg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 45 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1819381440 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562da024b810, 0x562da043501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562da0435020,0x562da22cd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b51a60734da64be0e618bacbea2865a8a7dcd669' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 47 processed earlier; will process 10982 files now Step #5: ==1654== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562d96d409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d9d3a5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d9d3885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d9d3884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d96d46d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d96ca7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d96ca2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d96d38c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d99d07f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d99d07f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d99d07f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d99d07f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d99d07f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d99d07f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d99d07f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d99d07f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d99d07f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d99d07f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d9bf9cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d98cc9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d98cd4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d98a80c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d98a80c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d98a81738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d98a80874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d98a80874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d98a80874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d9d38aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d9d393928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d9d37b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d9d3a6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f96e0194082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d96ca0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x16, Step #5: \026 Step #5: artifact_prefix='./'; Test unit written to ./oom-a9d3c9cd54b1a392b21ea14904d9a318f74636b7 Step #5: Base64: Fg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 46 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1819799148 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af20d3e810, 0x55af20f2801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af20f28020,0x55af22dc00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9d3c9cd54b1a392b21ea14904d9a318f74636b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 48 processed earlier; will process 10981 files now Step #5: ==1690== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55af178339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af1de98898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af1de7b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af1de7b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55af17839d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55af1779ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55af17795355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55af1782bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55af1a7faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55af1a7faf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55af1a7faf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55af1a7faf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55af1a7faf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55af1a7faf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55af1a7faf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55af1a7faf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55af1a7faf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55af1a7faf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af1ca8ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af197bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af197c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af19573c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af19573c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af19574738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af19573874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af19573874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af19573874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af1de7dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af1de86928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af1de6e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af1de99112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f044cf4d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55af17793b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72, Step #5: r Step #5: artifact_prefix='./'; Test unit written to ./oom-4dc7c9ec434ed06502767136789763ec11d2c4b7 Step #5: Base64: cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 47 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1820216777 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558bcf54a810, 0x558bcf73401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558bcf734020,0x558bd15cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4dc7c9ec434ed06502767136789763ec11d2c4b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 49 processed earlier; will process 10980 files now Step #5: ==1726== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558bc603f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558bcc6a4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558bcc6875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558bcc6874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558bc6045d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558bc5fa6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558bc5fa1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558bc6037c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558bc9006f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558bc9006f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558bc9006f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558bc9006f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558bc9006f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558bc9006f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558bc9006f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558bc9006f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558bc9006f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558bc9006f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558bcb29bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558bc7fc8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558bc7fd3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558bc7d7fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558bc7d7fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558bc7d80738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558bc7d7f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558bc7d7f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558bc7d7f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558bcc689abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558bcc692928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558bcc67a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558bcc6a5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27bc49c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558bc5f9fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7a, Step #5: z Step #5: artifact_prefix='./'; Test unit written to ./oom-395df8f7c51f007019cb30201c49e884b46b92fa Step #5: Base64: eg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 48 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1820637363 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f886bde810, 0x55f886dc801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f886dc8020,0x55f888c600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/395df8f7c51f007019cb30201c49e884b46b92fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 50 processed earlier; will process 10979 files now Step #5: ==1762== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f87d6d39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f883d38898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f883d1b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f883d1b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f87d6d9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f87d63ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f87d635355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f87d6cbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f88069af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f88069af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f88069af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f88069af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f88069af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f88069af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f88069af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f88069af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f88069af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f88069af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f88292ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f87f65cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f87f667be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f87f413c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f87f413c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f87f414738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f87f413874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f87f413874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f87f413874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f883d1dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f883d26928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f883d0e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f883d39112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0404934082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f87d633b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d, Step #5: M Step #5: artifact_prefix='./'; Test unit written to ./oom-c63ae6dd4fc9f9dda66970e827d13f7c73fe841c Step #5: Base64: TQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 49 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1821062421 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f1628a0810, 0x55f162a8a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f162a8a020,0x55f1649220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c63ae6dd4fc9f9dda66970e827d13f7c73fe841c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 51 processed earlier; will process 10978 files now Step #5: ==1798== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f1593959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f15f9fa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f15f9dd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f15f9dd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f15939bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f1592fcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f1592f7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f15938dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f15c35cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f15c35cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f15c35cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f15c35cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f15c35cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f15c35cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f15c35cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f15c35cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f15c35cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f15c35cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f15e5f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f15b31eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f15b329be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f15b0d5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f15b0d5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f15b0d6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f15b0d5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f15b0d5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f15b0d5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f15f9dfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f15f9e8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f15f9d0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f15f9fb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f18e006e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f1592f5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28, Step #5: ( Step #5: artifact_prefix='./'; Test unit written to ./oom-28ed3a797da3c48c309a4ef792147f3c56cfec40 Step #5: Base64: KA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 50 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1821479825 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a60d02810, 0x555a60eec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a60eec020,0x555a62d840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/28ed3a797da3c48c309a4ef792147f3c56cfec40' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 52 processed earlier; will process 10977 files now Step #5: ==1834== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555a577f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a5de5c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a5de3f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a5de3f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a577fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a5775eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a57759355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a577efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a5a7bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a5a7bef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a5a7bef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a5a7bef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a5a7bef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a5a7bef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a5a7bef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a5a7bef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a5a7bef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a5a7bef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a5ca53f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a59780b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a5978bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a59537c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a59537c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a59538738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a59537874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a59537874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a59537874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a5de41abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a5de4a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a5de32699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a5de5d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9eac6b9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a57757b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d, Step #5: = Step #5: artifact_prefix='./'; Test unit written to ./oom-21606782c65e44cac7afbb90977d8b6f82140e76 Step #5: Base64: PQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 51 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1821893204 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dc7c3cc810, 0x55dc7c5b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dc7c5b6020,0x55dc7e44e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/21606782c65e44cac7afbb90977d8b6f82140e76' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 53 processed earlier; will process 10976 files now Step #5: #1 pulse cov: 3353 ft: 3354 exec/s: 0 rss: 153Mb Step #5: ==1870== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dc72ec19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dc79526898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dc795095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dc795094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dc72ec7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dc72e28b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dc72e23355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dc72eb9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dc75e88f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dc75e88f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dc75e88f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dc75e88f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dc75e88f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dc75e88f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dc75e88f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dc75e88f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dc75e88f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dc75e88f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dc7811df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dc74e4ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dc74e55be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dc74c01c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dc74c01c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dc74c02738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dc74c01874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dc74c01874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dc74c01874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dc7950babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dc79514928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dc794fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dc79527112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f476da17082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dc72e21b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x59, Step #5: Y Step #5: artifact_prefix='./'; Test unit written to ./oom-23eb4d3f4155395a74e9d534f97ff4c1908f5aac Step #5: Base64: WQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 52 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1822351618 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562562d75810, 0x562562f5f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562562f5f020,0x562564df70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/23eb4d3f4155395a74e9d534f97ff4c1908f5aac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 55 processed earlier; will process 10974 files now Step #5: ==1906== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56255986a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56255fecf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56255feb25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56255feb24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562559870d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625597d1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625597cc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562559862c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56255c831f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56255c831f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56255c831f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56255c831f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56255c831f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56255c831f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56255c831f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56255c831f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56255c831f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56255c831f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56255eac6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56255b7f3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56255b7febe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56255b5aac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56255b5aac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56255b5ab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56255b5aa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56255b5aa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56255b5aa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56255feb4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56255febd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56255fea5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56255fed0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe1de911082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625597cab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d, Step #5: - Step #5: artifact_prefix='./'; Test unit written to ./oom-3bc15c8aae3e4124dd409035f32ea2fd6835efc9 Step #5: Base64: LQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 53 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1822776119 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56266cf73810, 0x56266d15d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56266d15d020,0x56266eff50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3bc15c8aae3e4124dd409035f32ea2fd6835efc9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 56 processed earlier; will process 10973 files now Step #5: ==1942== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562663a689c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56266a0cd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56266a0b05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56266a0b04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562663a6ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5626639cfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5626639ca355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562663a60c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562666a2ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562666a2ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562666a2ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562666a2ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562666a2ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562666a2ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562666a2ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562666a2ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562666a2ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562666a2ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562668cc4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5626659f1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5626659fcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5626657a8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5626657a8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5626657a9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5626657a8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5626657a8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5626657a8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56266a0b2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56266a0bb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56266a0a3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56266a0ce112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f69adfdf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5626639c8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa7, Step #5: \247 Step #5: artifact_prefix='./'; Test unit written to ./oom-dcf5bf6c63ba8e32483f75660b3a6a0f5d764483 Step #5: Base64: pw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 54 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1823183244 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fb0e192810, 0x55fb0e37c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fb0e37c020,0x55fb102140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dcf5bf6c63ba8e32483f75660b3a6a0f5d764483' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 57 processed earlier; will process 10972 files now Step #5: ==1978== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fb04c879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fb0b2ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fb0b2cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fb0b2cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fb04c8dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fb04beeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fb04be9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fb04c7fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fb07c4ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fb07c4ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fb07c4ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fb07c4ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fb07c4ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fb07c4ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fb07c4ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fb07c4ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fb07c4ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fb07c4ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fb09ee3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fb06c10b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fb06c1bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fb069c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fb069c7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fb069c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fb069c7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fb069c7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fb069c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fb0b2d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fb0b2da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fb0b2c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fb0b2ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f09ef12c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fb04be7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b, Step #5: { Step #5: artifact_prefix='./'; Test unit written to ./oom-60ba4b2daa4ed4d070fec06687e249e0e6f9ee45 Step #5: Base64: ew== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 55 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1823609200 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5646a8935810, 0x5646a8b1f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5646a8b1f020,0x5646aa9b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/60ba4b2daa4ed4d070fec06687e249e0e6f9ee45' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 58 processed earlier; will process 10971 files now Step #5: ==2014== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56469f42a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5646a5a8f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5646a5a725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5646a5a724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56469f430d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56469f391b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56469f38c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56469f422c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5646a23f1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5646a23f1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5646a23f1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5646a23f1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5646a23f1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5646a23f1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5646a23f1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5646a23f1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5646a23f1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5646a23f1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5646a4686f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5646a13b3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5646a13bebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5646a116ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5646a116ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5646a116b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5646a116a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5646a116a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5646a116a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5646a5a74abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5646a5a7d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5646a5a65699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5646a5a90112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1fd1fca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56469f38ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5a, Step #5: Z Step #5: artifact_prefix='./'; Test unit written to ./oom-909f99a779adb66a76fc53ab56c7dd1caf35d0fd Step #5: Base64: Wg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 56 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1824030742 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d0380d810, 0x563d039f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d039f7020,0x563d0588f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/909f99a779adb66a76fc53ab56c7dd1caf35d0fd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 59 processed earlier; will process 10970 files now Step #5: ==2050== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563cfa3029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d00967898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d0094a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d0094a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563cfa308d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563cfa269b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563cfa264355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563cfa2fac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563cfd2c9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563cfd2c9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563cfd2c9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563cfd2c9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563cfd2c9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563cfd2c9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563cfd2c9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563cfd2c9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563cfd2c9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563cfd2c9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563cff55ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563cfc28bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563cfc296be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563cfc042c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563cfc042c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563cfc043738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563cfc042874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563cfc042874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563cfc042874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d0094cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d00955928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d0093d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d00968112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efc1c0fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563cfa262b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x57, Step #5: W Step #5: artifact_prefix='./'; Test unit written to ./oom-e2415cb7f63df0c9de23362326ad3c37a9adfc96 Step #5: Base64: Vw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 57 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1824449721 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5648218c0810, 0x564821aaa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564821aaa020,0x5648239420e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e2415cb7f63df0c9de23362326ad3c37a9adfc96' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 60 processed earlier; will process 10969 files now Step #5: ==2086== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5648183b59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56481ea1a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56481e9fd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56481e9fd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5648183bbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56481831cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564818317355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5648183adc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56481b37cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56481b37cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56481b37cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56481b37cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56481b37cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56481b37cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56481b37cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56481b37cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56481b37cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56481b37cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56481d611f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56481a33eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56481a349be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56481a0f5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56481a0f5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56481a0f6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56481a0f5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56481a0f5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56481a0f5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56481e9ffabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56481ea08928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56481e9f0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56481ea1b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f48a954f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564818315b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xbd, Step #5: \275 Step #5: artifact_prefix='./'; Test unit written to ./oom-9034aaf45143996a2b14465c352ab0c6fa26b221 Step #5: Base64: vQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 58 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1824855990 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562252443810, 0x56225262d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56225262d020,0x5622544c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9034aaf45143996a2b14465c352ab0c6fa26b221' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 61 processed earlier; will process 10968 files now Step #5: ==2122== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562248f389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56224f59d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56224f5805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56224f5804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562248f3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562248e9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562248e9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562248f30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56224befff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56224befff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56224befff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56224befff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56224befff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56224befff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56224befff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56224befff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56224befff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56224befff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56224e194f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56224aec1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56224aeccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56224ac78c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56224ac78c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56224ac79738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56224ac78874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56224ac78874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56224ac78874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56224f582abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56224f58b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56224f573699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56224f59e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9e0a77b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562248e98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc, Step #5: \014 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e32e3c360501a0ede378bc45a24420dc2e53fba Step #5: Base64: DA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 59 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1825262585 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fd430c1810, 0x55fd432ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fd432ab020,0x55fd451430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e32e3c360501a0ede378bc45a24420dc2e53fba' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 62 processed earlier; will process 10967 files now Step #5: ==2158== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fd39bb69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fd4021b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fd401fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fd401fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fd39bbcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fd39b1db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fd39b18355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fd39baec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fd3cb7df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fd3cb7df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fd3cb7df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fd3cb7df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fd3cb7df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fd3cb7df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fd3cb7df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fd3cb7df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fd3cb7df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fd3cb7df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fd3ee12f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fd3bb3fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fd3bb4abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fd3b8f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fd3b8f6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fd3b8f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fd3b8f6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fd3b8f6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fd3b8f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fd40200abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fd40209928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fd401f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fd4021c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8747f10082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fd39b16b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c, Step #5: l Step #5: artifact_prefix='./'; Test unit written to ./oom-07c342be6e560e7f43842e2e21b774e61d85f047 Step #5: Base64: bA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 60 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1825681129 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556ba51ec810, 0x556ba53d601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556ba53d6020,0x556ba726e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/07c342be6e560e7f43842e2e21b774e61d85f047' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 63 processed earlier; will process 10966 files now Step #5: ==2194== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556b9bce19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556ba2346898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556ba23295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556ba23294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b9bce7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b9bc48b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b9bc43355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b9bcd9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b9eca8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b9eca8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b9eca8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b9eca8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b9eca8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b9eca8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b9eca8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b9eca8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b9eca8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b9eca8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556ba0f3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b9dc6ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b9dc75be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b9da21c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b9da21c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b9da22738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b9da21874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b9da21874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b9da21874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556ba232babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556ba2334928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556ba231c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556ba2347112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f13f054c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b9bc41b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c, Step #5: | Step #5: artifact_prefix='./'; Test unit written to ./oom-3eb416223e9e69e6bb8ee19793911ad1ad2027d8 Step #5: Base64: fA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 61 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1826104413 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7fa785810, 0x55f7fa96f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7fa96f020,0x55f7fc8070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3eb416223e9e69e6bb8ee19793911ad1ad2027d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 64 processed earlier; will process 10965 files now Step #5: ==2230== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f7f127a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7f78df898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7f78c25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7f78c24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f7f1280d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f7f11e1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f7f11dc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f7f1272c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7f4241f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7f4241f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7f4241f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7f4241f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7f4241f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7f4241f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7f4241f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7f4241f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7f4241f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7f4241f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7f64d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f7f3203b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f7f320ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f7f2fbac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f7f2fbac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f7f2fbb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f7f2fba874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f7f2fba874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f7f2fba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7f78c4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7f78cd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7f78b5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7f78e0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6eccd10082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f7f11dab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6d, Step #5: m Step #5: artifact_prefix='./'; Test unit written to ./oom-6b0d31c0d563223024da45691584643ac78c96e8 Step #5: Base64: bQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 62 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1826523538 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b353d22810, 0x55b353f0c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b353f0c020,0x55b355da40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b0d31c0d563223024da45691584643ac78c96e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 65 processed earlier; will process 10964 files now Step #5: ==2266== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b34a8179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b350e7c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b350e5f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b350e5f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b34a81dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b34a77eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b34a779355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b34a80fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b34d7def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b34d7def10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b34d7def10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b34d7def10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b34d7def10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b34d7def10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b34d7def10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b34d7def10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b34d7def10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b34d7def10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b34fa73f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b34c7a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b34c7abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b34c557c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b34c557c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b34c558738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b34c557874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b34c557874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b34c557874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b350e61abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b350e6a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b350e52699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b350e7d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd45bf47082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b34a777b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66, Step #5: f Step #5: artifact_prefix='./'; Test unit written to ./oom-4a0a19218e082a343a1b17e5333409af9d98f0f5 Step #5: Base64: Zg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 63 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1826940730 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556fc4b40810, 0x556fc4d2a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556fc4d2a020,0x556fc6bc20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4a0a19218e082a343a1b17e5333409af9d98f0f5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 66 processed earlier; will process 10963 files now Step #5: ==2302== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556fbb6359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556fc1c9a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556fc1c7d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556fc1c7d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556fbb63bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556fbb59cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556fbb597355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556fbb62dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556fbe5fcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556fbe5fcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556fbe5fcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556fbe5fcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556fbe5fcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556fbe5fcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556fbe5fcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556fbe5fcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556fbe5fcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556fbe5fcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556fc0891f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556fbd5beb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556fbd5c9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556fbd375c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556fbd375c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556fbd376738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556fbd375874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556fbd375874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556fbd375874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556fc1c7fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556fc1c88928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556fc1c70699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556fc1c9b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fecd3fbb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556fbb595b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74, Step #5: t Step #5: artifact_prefix='./'; Test unit written to ./oom-8efd86fb78a56a5145ed7739dcb00c78581c5375 Step #5: Base64: dA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 64 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1827360139 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5585900f5810, 0x5585902df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5585902df020,0x5585921770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8efd86fb78a56a5145ed7739dcb00c78581c5375' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 67 processed earlier; will process 10962 files now Step #5: ==2338== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558586bea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55858d24f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55858d2325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55858d2324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558586bf0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558586b51b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558586b4c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558586be2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558589bb1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558589bb1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558589bb1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558589bb1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558589bb1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558589bb1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558589bb1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558589bb1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558589bb1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558589bb1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55858be46f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558588b73b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558588b7ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55858892ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55858892ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55858892b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55858892a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55858892a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55858892a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55858d234abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55858d23d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55858d225699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55858d250112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f57e40df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558586b4ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xff, Step #5: \377 Step #5: artifact_prefix='./'; Test unit written to ./oom-85e53271e14006f0265921d02d4d736cdc580b0b Step #5: Base64: /w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 65 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1827800590 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b9bab46810, 0x55b9bad3001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b9bad30020,0x55b9bcbc80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/85e53271e14006f0265921d02d4d736cdc580b0b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 68 processed earlier; will process 10961 files now Step #5: #1 pulse cov: 3380 ft: 3381 exec/s: 0 rss: 153Mb Step #5: #2 pulse cov: 3440 ft: 3500 exec/s: 0 rss: 154Mb Step #5: ==2374== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b9b163b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b9b7ca0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b9b7c835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b9b7c834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b9b1641d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b9b15a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b9b159d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b9b1633c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b9b4602f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b9b4602f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b9b4602f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b9b4602f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b9b4602f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b9b4602f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b9b4602f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b9b4602f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b9b4602f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b9b4602f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b9b6897f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b9b35c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b9b35cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b9b337bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b9b337bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b9b337c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b9b337b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b9b337b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b9b337b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b9b7c85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b9b7c8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b9b7c76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b9b7ca1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b2c970082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b9b159bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x47, Step #5: G Step #5: artifact_prefix='./'; Test unit written to ./oom-a36a6718f54524d846894fb04b5b885b4e43e63b Step #5: Base64: Rw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 66 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1828298422 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d96f25810, 0x563d9710f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d9710f020,0x563d98fa70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a36a6718f54524d846894fb04b5b885b4e43e63b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 71 processed earlier; will process 10958 files now Step #5: ==2410== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563d8da1a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d9407f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d940625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d940624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d8da20d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d8d981b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d8d97c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d8da12c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d909e1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d909e1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d909e1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d909e1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d909e1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d909e1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d909e1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d909e1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d909e1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d909e1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d92c76f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d8f9a3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d8f9aebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d8f75ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d8f75ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d8f75b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d8f75a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d8f75a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d8f75a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d94064abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d9406d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d94055699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d94080112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f56db19c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d8d97ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb, Step #5: \013 Step #5: artifact_prefix='./'; Test unit written to ./oom-067d5096f219c64b53bb1c7d5e3754285b565a47 Step #5: Base64: Cw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 67 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1828707019 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555850ab4810, 0x555850c9e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555850c9e020,0x555852b360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/067d5096f219c64b53bb1c7d5e3754285b565a47' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 72 processed earlier; will process 10957 files now Step #5: ==2446== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5558475a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55584dc0e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55584dbf15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55584dbf14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5558475afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555847510b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55584750b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5558475a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55584a570f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55584a570f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55584a570f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55584a570f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55584a570f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55584a570f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55584a570f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55584a570f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55584a570f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55584a570f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55584c805f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555849532b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55584953dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5558492e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5558492e9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5558492ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5558492e9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5558492e9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5558492e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55584dbf3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55584dbfc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55584dbe4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55584dc0f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f143399f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555847509b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65, Step #5: e Step #5: artifact_prefix='./'; Test unit written to ./oom-58e6b3a414a1e090dfc6029add0f3555ccba127f Step #5: Base64: ZQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 68 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1829134076 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f18389e810, 0x55f183a8801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f183a88020,0x55f1859200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58e6b3a414a1e090dfc6029add0f3555ccba127f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 73 processed earlier; will process 10956 files now Step #5: ==2482== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f17a3939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f1809f8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1809db5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1809db4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f17a399d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f17a2fab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f17a2f5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f17a38bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f17d35af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f17d35af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f17d35af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f17d35af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f17d35af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f17d35af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f17d35af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f17d35af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f17d35af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f17d35af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f17f5eff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f17c31cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f17c327be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f17c0d3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f17c0d3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f17c0d4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f17c0d3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f17c0d3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f17c0d3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f1809ddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f1809e6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f1809ce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f1809f9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8e5e15a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f17a2f3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x9, Step #5: \011 Step #5: artifact_prefix='./'; Test unit written to ./oom-ac9231da4082430afe8f4d40127814c613648d8e Step #5: Base64: CQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 69 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1829546545 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db4d3d7810, 0x55db4d5c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db4d5c1020,0x55db4f4590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ac9231da4082430afe8f4d40127814c613648d8e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 74 processed earlier; will process 10955 files now Step #5: ==2518== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55db43ecc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db4a531898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db4a5145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db4a5144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db43ed2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db43e33b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db43e2e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db43ec4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db46e93f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db46e93f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db46e93f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db46e93f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db46e93f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db46e93f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db46e93f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db46e93f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db46e93f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db46e93f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db49128f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db45e55b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db45e60be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db45c0cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db45c0cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db45c0d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db45c0c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db45c0c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db45c0c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db4a516abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db4a51f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db4a507699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db4a532112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53574b2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db43e2cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41, Step #5: A Step #5: artifact_prefix='./'; Test unit written to ./oom-6dcd4ce23d88e2ee9568ba546c007c63d9131c1b Step #5: Base64: QQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 70 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1829971443 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf63e46810, 0x55bf6403001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf64030020,0x55bf65ec80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6dcd4ce23d88e2ee9568ba546c007c63d9131c1b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 75 processed earlier; will process 10954 files now Step #5: ==2554== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bf5a93b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf60fa0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf60f835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf60f834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf5a941d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf5a8a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf5a89d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf5a933c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf5d902f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf5d902f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf5d902f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf5d902f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf5d902f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf5d902f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf5d902f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf5d902f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf5d902f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf5d902f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf5fb97f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf5c8c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf5c8cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf5c67bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf5c67bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf5c67c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf5c67b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf5c67b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf5c67b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf60f85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf60f8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf60f76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf60fa1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7ada36b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf5a89bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4f, Step #5: O Step #5: artifact_prefix='./'; Test unit written to ./oom-08a914cde05039694ef0194d9ee79ff9a79dde33 Step #5: Base64: Tw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 71 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1830395695 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ac5c384810, 0x55ac5c56e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ac5c56e020,0x55ac5e4060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08a914cde05039694ef0194d9ee79ff9a79dde33' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 76 processed earlier; will process 10953 files now Step #5: ==2590== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ac52e799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ac594de898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ac594c15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ac594c14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ac52e7fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ac52de0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ac52ddb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ac52e71c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ac55e40f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ac55e40f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ac55e40f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ac55e40f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ac55e40f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ac55e40f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ac55e40f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ac55e40f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ac55e40f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ac55e40f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ac580d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ac54e02b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ac54e0dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ac54bb9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ac54bb9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ac54bba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ac54bb9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ac54bb9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ac54bb9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ac594c3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ac594cc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ac594b4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ac594df112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f36b6c9d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ac52dd9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77, Step #5: w Step #5: artifact_prefix='./'; Test unit written to ./oom-aff024fe4ab0fece4091de044c58c9ae4233383a Step #5: Base64: dw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 72 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1830824268 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55be977f1810, 0x55be979db01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55be979db020,0x55be998730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aff024fe4ab0fece4091de044c58c9ae4233383a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 77 processed earlier; will process 10952 files now Step #5: ==2626== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55be8e2e69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55be9494b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55be9492e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55be9492e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55be8e2ecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55be8e24db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55be8e248355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55be8e2dec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55be912adf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55be912adf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55be912adf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55be912adf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55be912adf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55be912adf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55be912adf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55be912adf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55be912adf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55be912adf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55be93542f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55be9026fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55be9027abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55be90026c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55be90026c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55be90027738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55be90026874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55be90026874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55be90026874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55be94930abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55be94939928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55be94921699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55be9494c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f845efd6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55be8e246b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c, Step #5: \\ Step #5: artifact_prefix='./'; Test unit written to ./oom-08534f33c201a45017b502e90a800f1b708ebcb3 Step #5: Base64: XA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 73 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1831243277 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b8dba9b810, 0x55b8dbc8501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b8dbc85020,0x55b8ddb1d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08534f33c201a45017b502e90a800f1b708ebcb3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 78 processed earlier; will process 10951 files now Step #5: ==2662== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b8d25909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b8d8bf5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b8d8bd85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b8d8bd84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b8d2596d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b8d24f7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b8d24f2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b8d2588c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b8d5557f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b8d5557f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b8d5557f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b8d5557f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b8d5557f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b8d5557f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b8d5557f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b8d5557f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b8d5557f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b8d5557f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b8d77ecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b8d4519b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b8d4524be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b8d42d0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b8d42d0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b8d42d1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b8d42d0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b8d42d0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b8d42d0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b8d8bdaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b8d8be3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b8d8bcb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b8d8bf6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f01f1632082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b8d24f0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e, Step #5: . Step #5: artifact_prefix='./'; Test unit written to ./oom-3a52ce780950d4d969792a2559cd519d7ee8c727 Step #5: Base64: Lg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 74 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1831665761 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5560b3d3d810, 0x5560b3f2701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5560b3f27020,0x5560b5dbf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a52ce780950d4d969792a2559cd519d7ee8c727' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 79 processed earlier; will process 10950 files now Step #5: ==2698== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5560aa8329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5560b0e97898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5560b0e7a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5560b0e7a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5560aa838d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5560aa799b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5560aa794355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5560aa82ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5560ad7f9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5560ad7f9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5560ad7f9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5560ad7f9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5560ad7f9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5560ad7f9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5560ad7f9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5560ad7f9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5560ad7f9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5560ad7f9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5560afa8ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5560ac7bbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5560ac7c6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5560ac572c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5560ac572c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5560ac573738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5560ac572874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5560ac572874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5560ac572874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5560b0e7cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5560b0e85928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5560b0e6d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5560b0e98112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc595fe8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5560aa792b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x18, Step #5: \030 Step #5: artifact_prefix='./'; Test unit written to ./oom-c2143b1a0db17957bec1b41bb2e5f75aa135981e Step #5: Base64: GA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 75 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1832089155 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f913811810, 0x55f9139fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f9139fb020,0x55f9158930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c2143b1a0db17957bec1b41bb2e5f75aa135981e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 80 processed earlier; will process 10949 files now Step #5: ==2734== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f90a3069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f91096b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f91094e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f91094e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f90a30cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f90a26db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f90a268355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f90a2fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f90d2cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f90d2cdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f90d2cdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f90d2cdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f90d2cdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f90d2cdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f90d2cdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f90d2cdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f90d2cdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f90d2cdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f90f562f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f90c28fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f90c29abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f90c046c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f90c046c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f90c047738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f90c046874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f90c046874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f90c046874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f910950abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f910959928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f910941699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f91096c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f71d9121082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f90a266b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21, Step #5: ! Step #5: artifact_prefix='./'; Test unit written to ./oom-0ab8318acaf6e678dd02e2b5c343ed41111b393d Step #5: Base64: IQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 76 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1832513948 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557686af0810, 0x557686cda01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557686cda020,0x557688b720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0ab8318acaf6e678dd02e2b5c343ed41111b393d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 81 processed earlier; will process 10948 files now Step #5: ==2770== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55767d5e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557683c4a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557683c2d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557683c2d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55767d5ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55767d54cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55767d547355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55767d5ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576805acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576805acf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576805acf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576805acf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576805acf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576805acf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576805acf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576805acf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576805acf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576805acf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557682841f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55767f56eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55767f579be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55767f325c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55767f325c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55767f326738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55767f325874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55767f325874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55767f325874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557683c2fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557683c38928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557683c20699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557683c4b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0eb656b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55767d545b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e, Step #5: ~ Step #5: artifact_prefix='./'; Test unit written to ./oom-fb3c6e4de85bd9eae26fdc63e75f10a7f39e850e Step #5: Base64: fg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 77 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1832934479 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e5decd810, 0x555e5e0b701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e5e0b7020,0x555e5ff4f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fb3c6e4de85bd9eae26fdc63e75f10a7f39e850e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 82 processed earlier; will process 10947 files now Step #5: ==2806== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555e549c29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e5b027898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e5b00a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e5b00a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e549c8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e54929b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e54924355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e549bac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e57989f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e57989f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e57989f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e57989f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e57989f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e57989f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e57989f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e57989f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e57989f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e57989f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e59c1ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e5694bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e56956be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e56702c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e56702c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e56703738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e56702874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e56702874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e56702874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e5b00cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e5b015928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e5affd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e5b028112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe4cf406082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e54922b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6a, Step #5: j Step #5: artifact_prefix='./'; Test unit written to ./oom-5c2dd944dde9e08881bef0894fe7b22a5c9c4b06 Step #5: Base64: ag== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 78 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1833358291 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564a8f745810, 0x564a8f92f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564a8f92f020,0x564a917c70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c2dd944dde9e08881bef0894fe7b22a5c9c4b06' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 83 processed earlier; will process 10946 files now Step #5: ==2842== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564a8623a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564a8c89f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564a8c8825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564a8c8824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564a86240d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564a861a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564a8619c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564a86232c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564a89201f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564a89201f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564a89201f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564a89201f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564a89201f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564a89201f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564a89201f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564a89201f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564a89201f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564a89201f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564a8b496f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564a881c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564a881cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564a87f7ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564a87f7ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564a87f7b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564a87f7a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564a87f7a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564a87f7a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564a8c884abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564a8c88d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564a8c875699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564a8c8a0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fedf0a4b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564a8619ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x29, Step #5: ) Step #5: artifact_prefix='./'; Test unit written to ./oom-e7064f0b80f61dbc65915311032d27baa569ae2a Step #5: Base64: KQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 79 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1833777341 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563ffe176810, 0x563ffe36001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563ffe360020,0x5640001f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e7064f0b80f61dbc65915311032d27baa569ae2a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 84 processed earlier; will process 10945 files now Step #5: ==2878== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563ff4c6b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563ffb2d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563ffb2b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563ffb2b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563ff4c71d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563ff4bd2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563ff4bcd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563ff4c63c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563ff7c32f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563ff7c32f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563ff7c32f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563ff7c32f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563ff7c32f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563ff7c32f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563ff7c32f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563ff7c32f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563ff7c32f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563ff7c32f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563ff9ec7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563ff6bf4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563ff6bffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563ff69abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563ff69abc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563ff69ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563ff69ab874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563ff69ab874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563ff69ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563ffb2b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563ffb2be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563ffb2a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563ffb2d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2175a3d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563ff4bcbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33, Step #5: 3 Step #5: artifact_prefix='./'; Test unit written to ./oom-77de68daecd823babbb58edb1c8e14d7106e83bb Step #5: Base64: Mw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 80 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1834197132 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d708b02810, 0x55d708cec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d708cec020,0x55d70ab840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/77de68daecd823babbb58edb1c8e14d7106e83bb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 85 processed earlier; will process 10944 files now Step #5: ==2914== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d6ff5f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d705c5c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d705c3f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d705c3f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d6ff5fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d6ff55eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d6ff559355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d6ff5efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d7025bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d7025bef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d7025bef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d7025bef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d7025bef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d7025bef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d7025bef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d7025bef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d7025bef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d7025bef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d704853f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d701580b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d70158bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d701337c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d701337c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d701338738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d701337874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d701337874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d701337874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d705c41abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d705c4a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d705c32699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d705c5d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa46659c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d6ff557b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b, Step #5: + Step #5: artifact_prefix='./'; Test unit written to ./oom-a979ef10cc6f6a36df6b8a323307ee3bb2e2db9c Step #5: Base64: Kw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 81 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1834622588 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55967aad4810, 0x55967acbe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55967acbe020,0x55967cb560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a979ef10cc6f6a36df6b8a323307ee3bb2e2db9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 86 processed earlier; will process 10943 files now Step #5: ==2950== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5596715c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559677c2e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559677c115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559677c114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5596715cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559671530b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55967152b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5596715c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559674590f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559674590f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559674590f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559674590f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559674590f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559674590f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559674590f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559674590f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559674590f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559674590f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559676825f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559673552b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55967355dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559673309c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559673309c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55967330a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559673309874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559673309874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559673309874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559677c13abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559677c1c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559677c04699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559677c2f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9014d38082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559671529b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3e, Step #5: > Step #5: artifact_prefix='./'; Test unit written to ./oom-091385be99b45f459a231582d583ec9f3fa3d194 Step #5: Base64: Pg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 82 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1835048404 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5601edfeb810, 0x5601ee1d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5601ee1d5020,0x5601f006d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/091385be99b45f459a231582d583ec9f3fa3d194' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 87 processed earlier; will process 10942 files now Step #5: ==2986== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5601e4ae09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601eb145898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601eb1285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601eb1284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5601e4ae6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601e4a47b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601e4a42355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5601e4ad8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601e7aa7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601e7aa7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601e7aa7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601e7aa7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601e7aa7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601e7aa7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601e7aa7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601e7aa7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601e7aa7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601e7aa7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5601e9d3cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601e6a69b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601e6a74be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5601e6820c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5601e6820c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5601e6821738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5601e6820874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5601e6820874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5601e6820874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5601eb12aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5601eb133928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5601eb11b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601eb146112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6237ecf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601e4a40b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x37, Step #5: 7 Step #5: artifact_prefix='./'; Test unit written to ./oom-902ba3cda1883801594b6e1b452790cc53948fda Step #5: Base64: Nw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 83 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1835470182 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e494c7810, 0x559e496b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e496b1020,0x559e4b5490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/902ba3cda1883801594b6e1b452790cc53948fda' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 88 processed earlier; will process 10941 files now Step #5: ==3022== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559e3ffbc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e46621898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e466045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e466044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e3ffc2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e3ff23b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e3ff1e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e3ffb4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e42f83f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e42f83f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e42f83f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e42f83f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e42f83f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e42f83f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e42f83f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e42f83f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e42f83f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e42f83f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e45218f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e41f45b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e41f50be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e41cfcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e41cfcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e41cfd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e41cfc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e41cfc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e41cfc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e46606abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e4660f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e465f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e46622112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f133b429082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e3ff1cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3, Step #5: \363 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a80baa1797615faddb0ccfaa6d46382a6b3e0e2 Step #5: Base64: 8w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 84 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1835882539 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5629d666f810, 0x5629d685901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5629d6859020,0x5629d86f10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a80baa1797615faddb0ccfaa6d46382a6b3e0e2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 89 processed earlier; will process 10940 files now Step #5: ==3058== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5629cd1649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5629d37c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5629d37ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5629d37ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5629cd16ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629cd0cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629cd0c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5629cd15cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5629d012bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5629d012bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5629d012bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5629d012bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5629d012bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5629d012bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5629d012bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5629d012bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5629d012bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5629d012bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5629d23c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629cf0edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629cf0f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629ceea4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629ceea4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629ceea5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629ceea4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629ceea4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629ceea4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5629d37aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5629d37b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5629d379f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5629d37ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4eb69a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629cd0c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x36, Step #5: 6 Step #5: artifact_prefix='./'; Test unit written to ./oom-c1dfd96eea8cc2b62785275bca38ac261256e278 Step #5: Base64: Ng== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 85 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1836306382 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564652f84810, 0x56465316e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56465316e020,0x5646550060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c1dfd96eea8cc2b62785275bca38ac261256e278' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 90 processed earlier; will process 10939 files now Step #5: ==3094== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564649a799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5646500de898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5646500c15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5646500c14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564649a7fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5646499e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5646499db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564649a71c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56464ca40f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56464ca40f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56464ca40f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56464ca40f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56464ca40f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56464ca40f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56464ca40f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56464ca40f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56464ca40f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56464ca40f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56464ecd5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56464ba02b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56464ba0dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56464b7b9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56464b7b9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56464b7ba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56464b7b9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56464b7b9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56464b7b9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5646500c3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5646500cc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5646500b4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5646500df112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3200a85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5646499d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x56, Step #5: V Step #5: artifact_prefix='./'; Test unit written to ./oom-c9ee5681d3c59f7541c27a38b67edf46259e187b Step #5: Base64: Vg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 86 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1836732580 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5583ed2f2810, 0x5583ed4dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5583ed4dc020,0x5583ef3740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9ee5681d3c59f7541c27a38b67edf46259e187b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 91 processed earlier; will process 10938 files now Step #5: ==3130== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5583e3de79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5583ea44c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583ea42f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583ea42f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5583e3dedd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5583e3d4eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5583e3d49355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5583e3ddfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5583e6daef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5583e6daef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5583e6daef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5583e6daef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5583e6daef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5583e6daef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5583e6daef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5583e6daef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5583e6daef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5583e6daef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5583e9043f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5583e5d70b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5583e5d7bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5583e5b27c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5583e5b27c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5583e5b28738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5583e5b27874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5583e5b27874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5583e5b27874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5583ea431abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5583ea43a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5583ea422699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5583ea44d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc70fec2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5583e3d47b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6b, Step #5: k Step #5: artifact_prefix='./'; Test unit written to ./oom-13fbd79c3d390e5d6585a21e11ff5ec1970cff0c Step #5: Base64: aw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 87 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1837155481 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e45d8ad810, 0x55e45da9701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e45da97020,0x55e45f92f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/13fbd79c3d390e5d6585a21e11ff5ec1970cff0c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 92 processed earlier; will process 10937 files now Step #5: ==3166== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e4543a29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e45aa07898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e45a9ea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e45a9ea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4543a8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e454309b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e454304355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e45439ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e457369f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e457369f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e457369f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e457369f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e457369f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e457369f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e457369f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e457369f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e457369f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e457369f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4595fef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e45632bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e456336be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4560e2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4560e2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4560e3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4560e2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4560e2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4560e2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e45a9ecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e45a9f5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e45a9dd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e45aa08112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc11aad1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e454302b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xaa, Step #5: \252 Step #5: artifact_prefix='./'; Test unit written to ./oom-52538a80094f7b62948fd31e68fd17a315d8dc91 Step #5: Base64: qg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 88 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1837561018 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7fe14d810, 0x55b7fe33701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7fe337020,0x55b8001cf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/52538a80094f7b62948fd31e68fd17a315d8dc91' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 93 processed earlier; will process 10936 files now Step #5: ==3202== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b7f4c429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b7fb2a7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b7fb28a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b7fb28a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b7f4c48d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b7f4ba9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b7f4ba4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b7f4c3ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b7f7c09f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b7f7c09f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b7f7c09f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b7f7c09f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b7f7c09f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b7f7c09f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b7f7c09f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b7f7c09f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b7f7c09f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b7f7c09f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b7f9e9ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b7f6bcbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b7f6bd6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b7f6982c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b7f6982c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b7f6983738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b7f6982874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b7f6982874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b7f6982874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b7fb28cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b7fb295928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b7fb27d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b7fb2a8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c70025082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b7f4ba2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x45, Step #5: E Step #5: artifact_prefix='./'; Test unit written to ./oom-e0184adedf913b076626646d3f52c3b49c39ad6d Step #5: Base64: RQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 89 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1837979082 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56311b311810, 0x56311b4fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56311b4fb020,0x56311d3930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e0184adedf913b076626646d3f52c3b49c39ad6d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 94 processed earlier; will process 10935 files now Step #5: ==3238== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563111e069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56311846b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56311844e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56311844e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563111e0cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563111d6db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563111d68355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563111dfec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563114dcdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563114dcdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563114dcdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563114dcdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563114dcdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563114dcdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563114dcdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563114dcdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563114dcdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563114dcdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563117062f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563113d8fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563113d9abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563113b46c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563113b46c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563113b47738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563113b46874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563113b46874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563113b46874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563118450abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563118459928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563118441699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56311846c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7054ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563111d66b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4c, Step #5: L Step #5: artifact_prefix='./'; Test unit written to ./oom-d160e0986aca4714714a16f29ec605af90be704d Step #5: Base64: TA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 90 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1838396684 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647de946810, 0x5647deb3001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5647deb30020,0x5647e09c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d160e0986aca4714714a16f29ec605af90be704d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 95 processed earlier; will process 10934 files now Step #5: ==3274== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5647d543b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647dbaa0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647dba835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647dba834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647d5441d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647d53a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647d539d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647d5433c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647d8402f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647d8402f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647d8402f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647d8402f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647d8402f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647d8402f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647d8402f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647d8402f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647d8402f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647d8402f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647da697f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647d73c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647d73cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647d717bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647d717bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647d717c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647d717b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647d717b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647d717b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647dba85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647dba8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647dba76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647dbaa1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5cdeee2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647d539bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xfd, Step #5: \375 Step #5: artifact_prefix='./'; Test unit written to ./oom-b54664965911c6fe91e18cd01b68a75c8183b530 Step #5: Base64: /Q== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 91 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1838807097 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a09d82810, 0x561a09f6c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a09f6c020,0x561a0be040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b54664965911c6fe91e18cd01b68a75c8183b530' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 96 processed earlier; will process 10933 files now Step #5: ==3310== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561a008779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561a06edc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561a06ebf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561a06ebf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561a0087dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561a007deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561a007d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561a0086fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561a0383ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561a0383ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561a0383ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561a0383ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561a0383ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561a0383ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561a0383ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561a0383ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561a0383ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561a0383ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561a05ad3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561a02800b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561a0280bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561a025b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561a025b7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561a025b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561a025b7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561a025b7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561a025b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561a06ec1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561a06eca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561a06eb2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561a06edd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f292fa5c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561a007d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3, Step #5: \003 Step #5: artifact_prefix='./'; Test unit written to ./oom-9842926af7ca0a8cca12604f945414f07b01e13d Step #5: Base64: Aw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 92 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1839226714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5630f9fa8810, 0x5630fa19201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5630fa192020,0x5630fc02a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9842926af7ca0a8cca12604f945414f07b01e13d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 97 processed earlier; will process 10932 files now Step #5: ==3346== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5630f0a9d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5630f7102898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5630f70e55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5630f70e54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5630f0aa3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5630f0a04b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5630f09ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5630f0a95c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5630f3a64f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5630f3a64f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5630f3a64f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5630f3a64f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5630f3a64f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5630f3a64f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5630f3a64f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5630f3a64f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5630f3a64f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5630f3a64f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5630f5cf9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5630f2a26b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5630f2a31be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5630f27ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5630f27ddc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5630f27de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5630f27dd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5630f27dd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5630f27dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5630f70e7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5630f70f0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5630f70d8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5630f7103112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff621962082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5630f09fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1f, Step #5: \037 Step #5: artifact_prefix='./'; Test unit written to ./oom-953efe8f531a5a87f6d2d5a65b78b05e55599abc Step #5: Base64: Hw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 93 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1839646389 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55587166b810, 0x55587185501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555871855020,0x5558736ed0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/953efe8f531a5a87f6d2d5a65b78b05e55599abc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 98 processed earlier; will process 10931 files now Step #5: ==3382== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5558681609c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55586e7c5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55586e7a85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55586e7a84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555868166d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5558680c7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5558680c2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555868158c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55586b127f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55586b127f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55586b127f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55586b127f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55586b127f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55586b127f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55586b127f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55586b127f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55586b127f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55586b127f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55586d3bcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55586a0e9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55586a0f4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555869ea0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555869ea0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555869ea1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555869ea0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555869ea0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555869ea0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55586e7aaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55586e7b3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55586e79b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55586e7c6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f852a9bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5558680c0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x62, Step #5: b Step #5: artifact_prefix='./'; Test unit written to ./oom-e9d71f5ee7c92d6dc9e92ffdad17b8bd49418f98 Step #5: Base64: Yg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 94 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1840071770 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564537e67810, 0x56453805101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564538051020,0x564539ee90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e9d71f5ee7c92d6dc9e92ffdad17b8bd49418f98' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 99 processed earlier; will process 10930 files now Step #5: ==3418== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56452e95c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564534fc1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564534fa45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564534fa44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56452e962d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56452e8c3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56452e8be355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56452e954c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564531923f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564531923f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564531923f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564531923f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564531923f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564531923f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564531923f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564531923f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564531923f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564531923f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564533bb8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5645308e5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5645308f0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56453069cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56453069cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56453069d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56453069c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56453069c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56453069c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564534fa6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564534faf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564534f97699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564534fc2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0680a01082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56452e8bcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd2, Step #5: \322 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8998da85fb12d4e8a858d364ab485dfad0863b4 Step #5: Base64: 0g== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 95 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1840473705 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557548786810, 0x55754897001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557548970020,0x55754a8080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8998da85fb12d4e8a858d364ab485dfad0863b4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 100 processed earlier; will process 10929 files now Step #5: ==3454== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55753f27b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5575458e0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5575458c35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5575458c34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55753f281d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55753f1e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55753f1dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55753f273c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557542242f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557542242f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557542242f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557542242f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557542242f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557542242f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557542242f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557542242f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557542242f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557542242f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5575444d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557541204b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55754120fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557540fbbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557540fbbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557540fbc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557540fbb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557540fbb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557540fbb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5575458c5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5575458ce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5575458b6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5575458e1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f32824b5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55753f1dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43, Step #5: C Step #5: artifact_prefix='./'; Test unit written to ./oom-32096c2e0eff33d844ee6d675407ace18289357d Step #5: Base64: Qw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 96 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1840890773 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a8651d5810, 0x55a8653bf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a8653bf020,0x55a8672570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/32096c2e0eff33d844ee6d675407ace18289357d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 101 processed earlier; will process 10928 files now Step #5: ==3490== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a85bcca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a86232f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a8623125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a8623124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a85bcd0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a85bc31b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a85bc2c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a85bcc2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a85ec91f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a85ec91f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a85ec91f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a85ec91f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a85ec91f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a85ec91f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a85ec91f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a85ec91f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a85ec91f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a85ec91f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a860f26f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a85dc53b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a85dc5ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a85da0ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a85da0ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a85da0b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a85da0a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a85da0a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a85da0a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a862314abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a86231d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a862305699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a862330112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f4958c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a85bc2ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4, Step #5: \004 Step #5: artifact_prefix='./'; Test unit written to ./oom-a42c6cf1de3abfdea9b95f34687cbbe92b9a7383 Step #5: Base64: BA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 97 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1841314859 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f012f6f810, 0x55f01315901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f013159020,0x55f014ff10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a42c6cf1de3abfdea9b95f34687cbbe92b9a7383' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 102 processed earlier; will process 10927 files now Step #5: #1 pulse cov: 3361 ft: 3362 exec/s: 0 rss: 151Mb Step #5: ==3526== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f009a649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f0100c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f0100ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f0100ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f009a6ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f0099cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f0099c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f009a5cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f00ca2bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f00ca2bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f00ca2bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f00ca2bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f00ca2bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f00ca2bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f00ca2bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f00ca2bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f00ca2bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f00ca2bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f00ecc0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f00b9edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f00b9f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f00b7a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f00b7a4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f00b7a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f00b7a4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f00b7a4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f00b7a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f0100aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f0100b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f01009f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f0100ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f49c8e66082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f0099c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x75, Step #5: u Step #5: artifact_prefix='./'; Test unit written to ./oom-51e69892ab49df85c6230ccc57f8e1d1606caccc Step #5: Base64: dQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 98 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1841770501 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e69c2e1810, 0x55e69c4cb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e69c4cb020,0x55e69e3630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/51e69892ab49df85c6230ccc57f8e1d1606caccc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 104 processed earlier; will process 10925 files now Step #5: ==3562== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e692dd69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e69943b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e69941e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e69941e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e692ddcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e692d3db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e692d38355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e692dcec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e695d9df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e695d9df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e695d9df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e695d9df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e695d9df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e695d9df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e695d9df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e695d9df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e695d9df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e695d9df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e698032f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e694d5fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e694d6abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e694b16c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e694b16c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e694b17738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e694b16874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e694b16874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e694b16874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e699420abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e699429928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e699411699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e69943c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f815e2a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e692d36b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53, Step #5: S Step #5: artifact_prefix='./'; Test unit written to ./oom-02aa629c8b16cd17a44f3a0efec2feed43937642 Step #5: Base64: Uw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 99 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1842188041 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fac8969810, 0x55fac8b5301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fac8b53020,0x55faca9eb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/02aa629c8b16cd17a44f3a0efec2feed43937642' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 105 processed earlier; will process 10924 files now Step #5: ==3598== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fabf45e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fac5ac3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fac5aa65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fac5aa64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fabf464d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fabf3c5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fabf3c0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fabf456c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fac2425f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fac2425f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fac2425f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fac2425f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fac2425f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fac2425f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fac2425f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fac2425f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fac2425f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fac2425f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fac46baf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fac13e7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fac13f2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fac119ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fac119ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fac119f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fac119e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fac119e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fac119e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fac5aa8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fac5ab1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fac5a99699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fac5ac4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f65f5f51082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fabf3beb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22, Step #5: \" Step #5: artifact_prefix='./'; Test unit written to ./oom-2ace62c1befa19e3ea37dd52be9f6d508c5163e6 Step #5: Base64: Ig== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 100 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1842610507 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558622152810, 0x55862233c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55862233c020,0x5586241d40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2ace62c1befa19e3ea37dd52be9f6d508c5163e6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 106 processed earlier; will process 10923 files now Step #5: ==3634== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558618c479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55861f2ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55861f28f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55861f28f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558618c4dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558618baeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558618ba9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558618c3fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55861bc0ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55861bc0ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55861bc0ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55861bc0ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55861bc0ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55861bc0ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55861bc0ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55861bc0ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55861bc0ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55861bc0ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55861dea3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55861abd0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55861abdbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55861a987c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55861a987c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55861a988738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55861a987874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55861a987874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55861a987874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55861f291abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55861f29a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55861f282699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55861f2ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb5e4af0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558618ba7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2c, Step #5: , Step #5: artifact_prefix='./'; Test unit written to ./oom-5c10b5b2cd673a0616d529aa5234b12ee7153808 Step #5: Base64: LA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 101 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1843035393 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c2788d3810, 0x55c278abd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c278abd020,0x55c27a9550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c10b5b2cd673a0616d529aa5234b12ee7153808' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 107 processed earlier; will process 10922 files now Step #5: ==3670== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c26f3c89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c275a2d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c275a105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c275a104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c26f3ced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c26f32fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c26f32a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c26f3c0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c27238ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c27238ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c27238ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c27238ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c27238ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c27238ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c27238ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c27238ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c27238ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c27238ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c274624f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c271351b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c27135cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c271108c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c271108c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c271109738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c271108874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c271108874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c271108874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c275a12abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c275a1b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c275a03699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c275a2e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0e903cb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c26f328b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x54, Step #5: T Step #5: artifact_prefix='./'; Test unit written to ./oom-c2c53d66948214258a26ca9ca845d7ac0c17f8e7 Step #5: Base64: VA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 102 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1843455052 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55604ff9e810, 0x55605018801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556050188020,0x5560520200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c2c53d66948214258a26ca9ca845d7ac0c17f8e7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 108 processed earlier; will process 10921 files now Step #5: ==3706== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556046a939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55604d0f8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55604d0db5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55604d0db4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556046a99d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5560469fab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5560469f5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556046a8bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556049a5af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556049a5af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556049a5af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556049a5af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556049a5af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556049a5af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556049a5af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556049a5af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556049a5af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556049a5af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55604bceff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556048a1cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556048a27be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5560487d3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5560487d3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5560487d4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5560487d3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5560487d3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5560487d3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55604d0ddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55604d0e6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55604d0ce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55604d0f9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f792a78e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5560469f3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1e, Step #5: \036 Step #5: artifact_prefix='./'; Test unit written to ./oom-7fd88c329b63b57572a0032cf14e3e9ec861ce5f Step #5: Base64: Hg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 103 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1843875511 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d6a1445810, 0x55d6a162f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d6a162f020,0x55d6a34c70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7fd88c329b63b57572a0032cf14e3e9ec861ce5f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 109 processed earlier; will process 10920 files now Step #5: ==3742== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d697f3a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d69e59f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d69e5825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d69e5824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d697f40d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d697ea1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d697e9c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d697f32c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d69af01f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d69af01f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d69af01f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d69af01f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d69af01f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d69af01f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d69af01f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d69af01f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d69af01f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d69af01f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d69d196f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d699ec3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d699ecebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d699c7ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d699c7ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d699c7b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d699c7a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d699c7a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d699c7a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d69e584abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d69e58d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d69e575699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d69e5a0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc6e66c1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d697e9ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x8, Step #5: \010 Step #5: artifact_prefix='./'; Test unit written to ./oom-8d883f1577ca8c334b7c6d75ccb71209d71ced13 Step #5: Base64: CA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 104 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1844301176 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647dfed4810, 0x5647e00be01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5647e00be020,0x5647e1f560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d883f1577ca8c334b7c6d75ccb71209d71ced13' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 110 processed earlier; will process 10919 files now Step #5: ==3778== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5647d69c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647dd02e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647dd0115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647dd0114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647d69cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647d6930b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647d692b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647d69c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647d9990f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647d9990f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647d9990f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647d9990f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647d9990f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647d9990f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647d9990f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647d9990f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647d9990f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647d9990f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647dbc25f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647d8952b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647d895dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647d8709c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647d8709c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647d870a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647d8709874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647d8709874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647d8709874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647dd013abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647dd01c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647dd004699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647dd02f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb16dc77082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647d6929b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x5, Step #5: +\005 Step #5: artifact_prefix='./'; Test unit written to ./oom-c22a45bb1e6dd3772187f60986fce38daf4ebeb8 Step #5: Base64: KwU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 105 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1844721490 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557c824a4810, 0x557c8268e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557c8268e020,0x557c845260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c22a45bb1e6dd3772187f60986fce38daf4ebeb8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 111 processed earlier; will process 10918 files now Step #5: ==3814== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557c78f999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557c7f5fe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557c7f5e15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557c7f5e14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557c78f9fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557c78f00b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557c78efb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557c78f91c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557c7bf60f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557c7bf60f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557c7bf60f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557c7bf60f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557c7bf60f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557c7bf60f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557c7bf60f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557c7bf60f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557c7bf60f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557c7bf60f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557c7e1f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557c7af22b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557c7af2dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557c7acd9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557c7acd9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557c7acda738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557c7acd9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557c7acd9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557c7acd9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557c7f5e3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557c7f5ec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557c7f5d4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557c7f5ff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc9d16d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557c78ef9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x35,0x2e, Step #5: 5. Step #5: artifact_prefix='./'; Test unit written to ./oom-d2835fcfb3bce92c9b822f1932f63e4e027da70d Step #5: Base64: NS4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 106 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1845147417 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dc452ad810, 0x55dc4549701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dc45497020,0x55dc4732f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d2835fcfb3bce92c9b822f1932f63e4e027da70d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 112 processed earlier; will process 10917 files now Step #5: ==3850== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dc3bda29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dc42407898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dc423ea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dc423ea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dc3bda8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dc3bd09b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dc3bd04355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dc3bd9ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dc3ed69f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dc3ed69f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dc3ed69f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dc3ed69f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dc3ed69f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dc3ed69f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dc3ed69f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dc3ed69f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dc3ed69f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dc3ed69f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dc40ffef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dc3dd2bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dc3dd36be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dc3dae2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dc3dae2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dc3dae3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dc3dae2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dc3dae2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dc3dae2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dc423ecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dc423f5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dc423dd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dc42408112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb159378082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dc3bd02b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa1,0x0, Step #5: \241\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0b91ff744f525abb88d3b74a29b82b3461601889 Step #5: Base64: oQA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 107 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1845560753 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d2f11a2810, 0x55d2f138c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d2f138c020,0x55d2f32240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b91ff744f525abb88d3b74a29b82b3461601889' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 113 processed earlier; will process 10916 files now Step #5: ==3886== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d2e7c979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d2ee2fc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d2ee2df5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d2ee2df4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d2e7c9dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d2e7bfeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d2e7bf9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d2e7c8fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d2eac5ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d2eac5ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d2eac5ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d2eac5ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d2eac5ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d2eac5ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d2eac5ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d2eac5ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d2eac5ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d2eac5ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d2ecef3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d2e9c20b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d2e9c2bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d2e99d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d2e99d7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d2e99d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d2e99d7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d2e99d7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d2e99d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d2ee2e1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d2ee2ea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d2ee2d2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d2ee2fd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f748e9f3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d2e7bf7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3e,0x58, Step #5: >X Step #5: artifact_prefix='./'; Test unit written to ./oom-912162280b9be2f4fbfef5b2cce5451d6569d3c8 Step #5: Base64: Plg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 108 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1845983788 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56319fd5a810, 0x56319ff4401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56319ff44020,0x5631a1ddc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/912162280b9be2f4fbfef5b2cce5451d6569d3c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 114 processed earlier; will process 10915 files now Step #5: ==3922== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56319684f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56319ceb4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56319ce975dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56319ce974fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563196855d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5631967b6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5631967b1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563196847c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563199816f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563199816f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563199816f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563199816f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563199816f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563199816f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563199816f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563199816f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563199816f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563199816f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56319baabf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5631987d8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5631987e3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56319858fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56319858fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563198590738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56319858f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56319858f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56319858f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56319ce99abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56319cea2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56319ce8a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56319ceb5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe42f71d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5631967afb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x68,0xf5, Step #5: h\365 Step #5: artifact_prefix='./'; Test unit written to ./oom-fef014e3f6581801769ee8a87ba219e5750df8f1 Step #5: Base64: aPU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 109 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1846410531 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d1002d810, 0x561d1021701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d10217020,0x561d120af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fef014e3f6581801769ee8a87ba219e5750df8f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 115 processed earlier; will process 10914 files now Step #5: ==3958== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561d06b229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d0d187898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d0d16a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d0d16a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d06b28d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d06a89b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d06a84355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d06b1ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d09ae9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d09ae9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d09ae9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d09ae9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d09ae9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d09ae9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d09ae9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d09ae9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d09ae9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d09ae9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d0bd7ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d08aabb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d08ab6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d08862c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d08862c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d08863738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d08862874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d08862874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d08862874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d0d16cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d0d175928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d0d15d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d0d188112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feb4046a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d06a82b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x39,0x2e, Step #5: 9. Step #5: artifact_prefix='./'; Test unit written to ./oom-5c72da08f13e3df6d60f53d6513dd6552e66c36a Step #5: Base64: OS4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 110 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1846828808 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c6715f810, 0x564c6734901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c67349020,0x564c691e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c72da08f13e3df6d60f53d6513dd6552e66c36a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 116 processed earlier; will process 10913 files now Step #5: ==3994== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564c5dc549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c642b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c6429c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c6429c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c5dc5ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c5dbbbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c5dbb6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c5dc4cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c60c1bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c60c1bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c60c1bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c60c1bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c60c1bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c60c1bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c60c1bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c60c1bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c60c1bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c60c1bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c62eb0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c5fbddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c5fbe8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c5f994c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c5f994c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c5f995738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c5f994874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c5f994874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c5f994874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c6429eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c642a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c6428f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c642ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8def263082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c5dbb4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x38,0x14, Step #5: 8\024 Step #5: artifact_prefix='./'; Test unit written to ./oom-ccd6e0afee7af28ca399ec1a3b8ef301ecbb2d82 Step #5: Base64: OBQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 111 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1847247200 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a054daa810, 0x55a054f9401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a054f94020,0x55a056e2c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ccd6e0afee7af28ca399ec1a3b8ef301ecbb2d82' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 117 processed earlier; will process 10912 files now Step #5: ==4030== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a04b89f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a051f04898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a051ee75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a051ee74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a04b8a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a04b806b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a04b801355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a04b897c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a04e866f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a04e866f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a04e866f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a04e866f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a04e866f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a04e866f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a04e866f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a04e866f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a04e866f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a04e866f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a050afbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a04d828b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a04d833be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a04d5dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a04d5dfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a04d5e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a04d5df874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a04d5df874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a04d5df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a051ee9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a051ef2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a051eda699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a051f05112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7671092082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a04b7ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x2f, Step #5: \001/ Step #5: artifact_prefix='./'; Test unit written to ./oom-87dfa8dd501cceafd6b478922c0f50ded4cf79be Step #5: Base64: AS8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 112 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1847661642 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff1c4d2810, 0x55ff1c6bc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff1c6bc020,0x55ff1e5540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87dfa8dd501cceafd6b478922c0f50ded4cf79be' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 118 processed earlier; will process 10911 files now Step #5: ==4066== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ff12fc79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff1962c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff1960f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff1960f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff12fcdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff12f2eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff12f29355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff12fbfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff15f8ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff15f8ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff15f8ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff15f8ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff15f8ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff15f8ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff15f8ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff15f8ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff15f8ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff15f8ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff18223f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff14f50b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff14f5bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff14d07c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff14d07c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff14d08738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff14d07874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff14d07874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff14d07874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff19611abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff1961a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff19602699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff1962d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f90d4feb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff12f27b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x5a, Step #5: \\Z Step #5: artifact_prefix='./'; Test unit written to ./oom-2f88fa0b60564b0dea0ce8cf54e11752cb8bf66a Step #5: Base64: XFo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 113 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1848075017 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5634384e8810, 0x5634386d201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5634386d2020,0x56343a56a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f88fa0b60564b0dea0ce8cf54e11752cb8bf66a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 119 processed earlier; will process 10910 files now Step #5: ==4102== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56342efdd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563435642898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634356255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634356254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56342efe3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56342ef44b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56342ef3f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56342efd5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563431fa4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563431fa4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563431fa4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563431fa4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563431fa4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563431fa4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563431fa4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563431fa4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563431fa4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563431fa4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563434239f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563430f66b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563430f71be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563430d1dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563430d1dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563430d1e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563430d1d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563430d1d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563430d1d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563435627abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563435630928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563435618699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563435643112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5b40720082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56342ef3db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6d,0x29, Step #5: m) Step #5: artifact_prefix='./'; Test unit written to ./oom-bbc02a77fa6c2e5963c93187fd39e43076b7e29d Step #5: Base64: bSk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 114 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1848482417 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555c24e9d810, 0x555c2508701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555c25087020,0x555c26f1f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bbc02a77fa6c2e5963c93187fd39e43076b7e29d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 120 processed earlier; will process 10909 files now Step #5: ==4138== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555c1b9929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555c21ff7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555c21fda5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555c21fda4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555c1b998d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555c1b8f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555c1b8f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555c1b98ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555c1e959f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555c1e959f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555c1e959f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555c1e959f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555c1e959f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555c1e959f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555c1e959f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555c1e959f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555c1e959f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555c1e959f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555c20beef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555c1d91bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555c1d926be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555c1d6d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555c1d6d2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555c1d6d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555c1d6d2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555c1d6d2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555c1d6d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555c21fdcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555c21fe5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555c21fcd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555c21ff8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f370f497082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555c1b8f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x4d, Step #5: AM Step #5: artifact_prefix='./'; Test unit written to ./oom-80d305c58f97edfae92a3627f5a66d9bef4d8d46 Step #5: Base64: QU0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 115 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1848892332 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5572359e0810, 0x557235bca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557235bca020,0x557237a620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/80d305c58f97edfae92a3627f5a66d9bef4d8d46' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 121 processed earlier; will process 10908 files now Step #5: ==4174== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55722c4d59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557232b3a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557232b1d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557232b1d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55722c4dbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55722c43cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55722c437355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55722c4cdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55722f49cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55722f49cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55722f49cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55722f49cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55722f49cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55722f49cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55722f49cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55722f49cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55722f49cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55722f49cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557231731f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55722e45eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55722e469be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55722e215c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55722e215c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55722e216738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55722e215874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55722e215874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55722e215874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557232b1fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557232b28928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557232b10699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557232b3b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe55fb91082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55722c435b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x58, Step #5: \"X Step #5: artifact_prefix='./'; Test unit written to ./oom-2f450c6f58a464501c103b96cdbf5743776727fd Step #5: Base64: Ilg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 116 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1849302755 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f0a585810, 0x556f0a76f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f0a76f020,0x556f0c6070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f450c6f58a464501c103b96cdbf5743776727fd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 122 processed earlier; will process 10907 files now Step #5: ==4210== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556f0107a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f076df898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f076c25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f076c24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f01080d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f00fe1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f00fdc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f01072c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f04041f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f04041f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f04041f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f04041f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f04041f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f04041f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f04041f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f04041f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f04041f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f04041f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f062d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f03003b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f0300ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f02dbac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f02dbac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f02dbb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f02dba874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f02dba874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f02dba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f076c4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f076cd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f076b5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f076e0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdffacac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f00fdab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x45, Step #5: =E Step #5: artifact_prefix='./'; Test unit written to ./oom-add0fd3c2be52079d8e3184f4934a42fdedb36bb Step #5: Base64: PUU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 117 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1849718714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d120d60810, 0x55d120f4a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d120f4a020,0x55d122de20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/add0fd3c2be52079d8e3184f4934a42fdedb36bb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 123 processed earlier; will process 10906 files now Step #5: ==4246== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d1178559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d11deba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d11de9d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d11de9d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d11785bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1177bcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1177b7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d11784dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d11a81cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d11a81cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d11a81cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d11a81cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d11a81cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d11a81cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d11a81cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d11a81cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d11a81cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d11a81cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d11cab1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1197deb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1197e9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d119595c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d119595c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d119596738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d119595874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d119595874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d119595874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d11de9fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d11dea8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d11de90699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d11debb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f973bc1e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1177b5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2f, Step #5: \005/ Step #5: artifact_prefix='./'; Test unit written to ./oom-f615b1febee82e6ce83c5f2be79cb687451cc766 Step #5: Base64: BS8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 118 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1850139989 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559f9e59e810, 0x559f9e78801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559f9e788020,0x559fa06200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f615b1febee82e6ce83c5f2be79cb687451cc766' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 124 processed earlier; will process 10905 files now Step #5: ==4282== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559f950939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559f9b6f8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559f9b6db5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559f9b6db4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559f95099d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559f94ffab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559f94ff5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559f9508bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559f9805af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559f9805af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559f9805af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559f9805af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559f9805af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559f9805af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559f9805af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559f9805af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559f9805af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559f9805af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559f9a2eff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559f9701cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559f97027be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559f96dd3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559f96dd3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559f96dd4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559f96dd3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559f96dd3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559f96dd3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559f9b6ddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559f9b6e6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559f9b6ce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559f9b6f9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fef3ca51082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559f94ff3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4b,0x3b, Step #5: K; Step #5: artifact_prefix='./'; Test unit written to ./oom-939959f9e4f323bd3845d7986e2c4d763336f418 Step #5: Base64: Szs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 119 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1850550077 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b2cc4d6810, 0x55b2cc6c001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b2cc6c0020,0x55b2ce5580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/939959f9e4f323bd3845d7986e2c4d763336f418' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 125 processed earlier; will process 10904 files now Step #5: ==4318== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b2c2fcb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b2c9630898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b2c96135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b2c96134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b2c2fd1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b2c2f32b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b2c2f2d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b2c2fc3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b2c5f92f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b2c5f92f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b2c5f92f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b2c5f92f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b2c5f92f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b2c5f92f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b2c5f92f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b2c5f92f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b2c5f92f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b2c5f92f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b2c8227f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b2c4f54b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b2c4f5fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b2c4d0bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b2c4d0bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b2c4d0c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b2c4d0b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b2c4d0b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b2c4d0b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b2c9615abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b2c961e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b2c9606699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b2c9631112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fce51ff3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b2c2f2bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x2d, Step #5: ^- Step #5: artifact_prefix='./'; Test unit written to ./oom-fe4cd9ca3a9eb28f7b8896024cd7671400a752da Step #5: Base64: Xi0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 120 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1850960157 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aee7cba810, 0x55aee7ea401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aee7ea4020,0x55aee9d3c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fe4cd9ca3a9eb28f7b8896024cd7671400a752da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 126 processed earlier; will process 10903 files now Step #5: ==4354== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55aede7af9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aee4e14898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aee4df75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aee4df74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aede7b5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aede716b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aede711355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aede7a7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aee1776f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aee1776f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aee1776f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aee1776f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aee1776f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aee1776f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aee1776f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aee1776f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aee1776f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aee1776f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aee3a0bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aee0738b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aee0743be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aee04efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aee04efc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aee04f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aee04ef874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aee04ef874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aee04ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aee4df9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aee4e02928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aee4dea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aee4e15112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d313e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aede70fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x25, Step #5: 1% Step #5: artifact_prefix='./'; Test unit written to ./oom-a78a731c5a6e500a99ac9aab58e38e2b342e4f0d Step #5: Base64: MSU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 121 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1851375458 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af04760810, 0x55af0494a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af0494a020,0x55af067e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a78a731c5a6e500a99ac9aab58e38e2b342e4f0d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 127 processed earlier; will process 10902 files now Step #5: ==4390== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55aefb2559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af018ba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af0189d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af0189d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aefb25bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aefb1bcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aefb1b7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aefb24dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aefe21cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aefe21cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aefe21cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aefe21cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aefe21cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aefe21cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aefe21cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aefe21cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aefe21cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aefe21cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af004b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aefd1deb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aefd1e9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aefcf95c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aefcf95c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aefcf96738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aefcf95874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aefcf95874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aefcf95874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af0189fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af018a8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af01890699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af018bb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcbf9bcd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aefb1b5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x25, Step #5: %% Step #5: artifact_prefix='./'; Test unit written to ./oom-e11557a88106e7fe5bb613921c6f637bccd31989 Step #5: Base64: JSU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 122 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1851790996 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555865346810, 0x55586553001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555865530020,0x5558673c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e11557a88106e7fe5bb613921c6f637bccd31989' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 128 processed earlier; will process 10901 files now Step #5: #1 pulse cov: 3415 ft: 3416 exec/s: 0 rss: 151Mb Step #5: ==4426== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55585be3b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5558624a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5558624835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5558624834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55585be41d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55585bda2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55585bd9d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55585be33c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55585ee02f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55585ee02f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55585ee02f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55585ee02f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55585ee02f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55585ee02f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55585ee02f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55585ee02f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55585ee02f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55585ee02f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555861097f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55585ddc4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55585ddcfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55585db7bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55585db7bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55585db7c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55585db7b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55585db7b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55585db7b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555862485abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55586248e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555862476699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5558624a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5c8552c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55585bd9bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x55, Step #5: \000U Step #5: artifact_prefix='./'; Test unit written to ./oom-91418a422359befed98b3bfab17cf0b725b5e7e6 Step #5: Base64: AFU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 123 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1852249784 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564443dda810, 0x564443fc401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564443fc4020,0x564445e5c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/91418a422359befed98b3bfab17cf0b725b5e7e6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 130 processed earlier; will process 10899 files now Step #5: ==4462== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56443a8cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564440f34898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564440f175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564440f174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56443a8d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56443a836b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56443a831355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56443a8c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56443d896f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56443d896f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56443d896f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56443d896f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56443d896f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56443d896f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56443d896f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56443d896f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56443d896f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56443d896f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56443fb2bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56443c858b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56443c863be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56443c60fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56443c60fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56443c610738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56443c60f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56443c60f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56443c60f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564440f19abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564440f22928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564440f0a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564440f35112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fef6cb24082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56443a82fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x7a, Step #5: dz Step #5: artifact_prefix='./'; Test unit written to ./oom-57f378cca8e1bd5ea94400ff922e6451409e0765 Step #5: Base64: ZHo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 124 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1852665420 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565099426810, 0x56509961001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565099610020,0x56509b4a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/57f378cca8e1bd5ea94400ff922e6451409e0765' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 131 processed earlier; will process 10898 files now Step #5: ==4498== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56508ff1b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565096580898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5650965635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5650965634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56508ff21d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56508fe82b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56508fe7d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56508ff13c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565092ee2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565092ee2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565092ee2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565092ee2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565092ee2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565092ee2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565092ee2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565092ee2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565092ee2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565092ee2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565095177f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565091ea4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565091eafbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565091c5bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565091c5bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565091c5c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565091c5b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565091c5b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565091c5b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565096565abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56509656e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565096556699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565096581112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f80b98aa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56508fe7bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0xd, Step #5: \015\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-d67d4422dccb731ed3fcb61ffdb76a979af68dde Step #5: Base64: DQ0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 125 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1853061302 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b38005810, 0x555b381ef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b381ef020,0x555b3a0870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d67d4422dccb731ed3fcb61ffdb76a979af68dde' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 132 processed earlier; will process 10897 files now Step #5: ==4534== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555b2eafa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b3515f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b351425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b351424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b2eb00d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b2ea61b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b2ea5c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b2eaf2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b31ac1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b31ac1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b31ac1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b31ac1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b31ac1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b31ac1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b31ac1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b31ac1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b31ac1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b31ac1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b33d56f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b30a83b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b30a8ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b3083ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b3083ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b3083b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b3083a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b3083a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b3083a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b35144abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b3514d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b35135699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b35160112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffb52d5f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b2ea5ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24, Step #5: $$ Step #5: artifact_prefix='./'; Test unit written to ./oom-89f0403865a685eab3831c406205bbfe40f946d4 Step #5: Base64: JCQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 126 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1853477314 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c580b30810, 0x55c580d1a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c580d1a020,0x55c582bb20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/89f0403865a685eab3831c406205bbfe40f946d4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 133 processed earlier; will process 10896 files now Step #5: ==4570== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c5776259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c57dc8a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c57dc6d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c57dc6d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c57762bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c57758cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c577587355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c57761dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c57a5ecf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c57a5ecf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c57a5ecf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c57a5ecf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c57a5ecf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c57a5ecf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c57a5ecf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c57a5ecf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c57a5ecf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c57a5ecf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c57c881f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c5795aeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c5795b9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c579365c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c579365c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c579366738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c579365874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c579365874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c579365874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c57dc6fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c57dc78928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c57dc60699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c57dc8b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efc09def082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c577585b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0xbb, Step #5: \337\273 Step #5: artifact_prefix='./'; Test unit written to ./oom-eb2d143c24fa95837538b25c55acfcdcb4a486ca Step #5: Base64: 37s= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 127 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1853892334 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563b716bf810, 0x563b718a901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563b718a9020,0x563b737410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eb2d143c24fa95837538b25c55acfcdcb4a486ca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 134 processed earlier; will process 10895 files now Step #5: ==4606== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563b681b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563b6e819898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563b6e7fc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563b6e7fc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563b681bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563b6811bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563b68116355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563b681acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563b6b17bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563b6b17bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563b6b17bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563b6b17bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563b6b17bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563b6b17bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563b6b17bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563b6b17bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563b6b17bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563b6b17bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563b6d410f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563b6a13db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563b6a148be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563b69ef4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563b69ef4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563b69ef5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563b69ef4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563b69ef4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563b69ef4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563b6e7feabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563b6e807928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563b6e7ef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563b6e81a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ceed28082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563b68114b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0x25, Step #5: ?% Step #5: artifact_prefix='./'; Test unit written to ./oom-fc0521f02cd0d2a1ac6beeee7e4cfc92202e0953 Step #5: Base64: PyU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 128 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1854316791 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56276212f810, 0x56276231901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562762319020,0x5627641b10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc0521f02cd0d2a1ac6beeee7e4cfc92202e0953' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 135 processed earlier; will process 10894 files now Step #5: ==4642== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562758c249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56275f289898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56275f26c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56275f26c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562758c2ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562758b8bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562758b86355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562758c1cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56275bbebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56275bbebf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56275bbebf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56275bbebf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56275bbebf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56275bbebf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56275bbebf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56275bbebf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56275bbebf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56275bbebf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56275de80f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56275abadb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56275abb8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56275a964c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56275a964c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56275a965738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56275a964874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56275a964874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56275a964874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56275f26eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56275f277928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56275f25f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56275f28a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbbb5356082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562758b84b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa0,0x83, Step #5: \240\203 Step #5: artifact_prefix='./'; Test unit written to ./oom-76ac85c99550aeb8790de299ad4dd6c3aa233315 Step #5: Base64: oIM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 129 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1854718807 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee12fda810, 0x55ee131c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee131c4020,0x55ee1505c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/76ac85c99550aeb8790de299ad4dd6c3aa233315' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 136 processed earlier; will process 10893 files now Step #5: ==4678== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ee09acf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee10134898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee101175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee101174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee09ad5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee09a36b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee09a31355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee09ac7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee0ca96f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee0ca96f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee0ca96f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee0ca96f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee0ca96f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee0ca96f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee0ca96f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee0ca96f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee0ca96f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee0ca96f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee0ed2bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee0ba58b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee0ba63be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee0b80fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee0b80fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee0b810738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee0b80f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee0b80f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee0b80f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee10119abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee10122928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee1010a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee10135112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0493f12082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee09a2fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x29,0x29, Step #5: )) Step #5: artifact_prefix='./'; Test unit written to ./oom-4f51b4c667c3dcfab932d2b098c3a3eecffb6256 Step #5: Base64: KSk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 130 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1855142042 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5625f912a810, 0x5625f931401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625f9314020,0x5625fb1ac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f51b4c667c3dcfab932d2b098c3a3eecffb6256' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 137 processed earlier; will process 10892 files now Step #5: ==4714== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5625efc1f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5625f6284898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625f62675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625f62674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5625efc25d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625efb86b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625efb81355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5625efc17c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5625f2be6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5625f2be6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5625f2be6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5625f2be6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5625f2be6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5625f2be6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5625f2be6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5625f2be6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5625f2be6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5625f2be6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5625f4e7bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625f1ba8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5625f1bb3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5625f195fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5625f195fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5625f1960738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5625f195f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5625f195f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5625f195f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5625f6269abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5625f6272928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5625f625a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5625f6285112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f43a744e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625efb7fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4e,0x47, Step #5: NG Step #5: artifact_prefix='./'; Test unit written to ./oom-224d733e3ac2260ce34b5981dc16e230662c72af Step #5: Base64: Tkc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 131 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1855574848 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a2a4efb810, 0x55a2a50e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a2a50e5020,0x55a2a6f7d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/224d733e3ac2260ce34b5981dc16e230662c72af' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 138 processed earlier; will process 10891 files now Step #5: ==4750== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a29b9f09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a2a2055898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2a20385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2a20384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a29b9f6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a29b957b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a29b952355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a29b9e8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a29e9b7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a29e9b7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a29e9b7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a29e9b7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a29e9b7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a29e9b7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a29e9b7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a29e9b7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a29e9b7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a29e9b7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a2a0c4cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a29d979b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a29d984be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a29d730c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a29d730c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a29d731738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a29d730874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a29d730874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a29d730874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a2a203aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a2a2043928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2a202b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a2a2056112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff6ac6eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a29b950b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc,0xc, Step #5: \014\014 Step #5: artifact_prefix='./'; Test unit written to ./oom-5df9b5633e8ea2c33bb86c4eb4c2c39bed290561 Step #5: Base64: DAw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 132 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1855999079 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ac1b1a8810, 0x55ac1b39201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ac1b392020,0x55ac1d22a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5df9b5633e8ea2c33bb86c4eb4c2c39bed290561' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 139 processed earlier; will process 10890 files now Step #5: ==4786== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ac11c9d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ac18302898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ac182e55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ac182e54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ac11ca3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ac11c04b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ac11bff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ac11c95c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ac14c64f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ac14c64f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ac14c64f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ac14c64f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ac14c64f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ac14c64f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ac14c64f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ac14c64f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ac14c64f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ac14c64f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ac16ef9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ac13c26b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ac13c31be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ac139ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ac139ddc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ac139de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ac139dd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ac139dd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ac139dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ac182e7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ac182f0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ac182d8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ac18303112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ad3ba9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ac11bfdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6d,0x6d, Step #5: mm Step #5: artifact_prefix='./'; Test unit written to ./oom-b8d09b4d8580aacbd9efc4540a9b88d2feb9d7e5 Step #5: Base64: bW0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 133 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1856438572 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f84e976810, 0x55f84eb6001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f84eb60020,0x55f8509f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b8d09b4d8580aacbd9efc4540a9b88d2feb9d7e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 140 processed earlier; will process 10889 files now Step #5: ==4822== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f84546b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f84bad0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f84bab35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f84bab34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f845471d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8453d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8453cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f845463c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f848432f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f848432f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f848432f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f848432f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f848432f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f848432f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f848432f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f848432f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f848432f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f848432f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f84a6c7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f8473f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f8473ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8471abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8471abc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8471ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8471ab874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8471ab874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8471ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f84bab5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f84babe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f84baa6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f84bad1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f16eac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8453cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x0, Step #5: \003\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-688934845f22049cb14668832efa33d45013b6b9 Step #5: Base64: AwA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 134 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1856875495 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0f528a810, 0x55a0f547401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0f5474020,0x55a0f730c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/688934845f22049cb14668832efa33d45013b6b9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 141 processed earlier; will process 10888 files now Step #5: ==4858== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a0ebd7f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0f23e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0f23c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0f23c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0ebd85d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0ebce6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0ebce1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0ebd77c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0eed46f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0eed46f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0eed46f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0eed46f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0eed46f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0eed46f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0eed46f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0eed46f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0eed46f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0eed46f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0f0fdbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0edd08b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0edd13be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0edabfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0edabfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0edac0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0edabf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0edabf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0edabf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0f23c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0f23d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0f23ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0f23e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b20af5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0ebcdfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0x3d, Step #5: \015= Step #5: artifact_prefix='./'; Test unit written to ./oom-050dc032cf71bd509f8b98d54b18f1bf729ee893 Step #5: Base64: DT0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 135 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1857296083 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb7bf49810, 0x55bb7c13301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb7c133020,0x55bb7dfcb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/050dc032cf71bd509f8b98d54b18f1bf729ee893' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 142 processed earlier; will process 10887 files now Step #5: ==4894== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bb72a3e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb790a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb790865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb790864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb72a44d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb729a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb729a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb72a36c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb75a05f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb75a05f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb75a05f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb75a05f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb75a05f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb75a05f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb75a05f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb75a05f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb75a05f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb75a05f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb77c9af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb749c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb749d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb7477ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb7477ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb7477f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb7477e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb7477e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb7477e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb79088abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb79091928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb79079699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb790a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd5cdd64082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb7299eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xde,0x80, Step #5: \336\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-c9046012bc6665e959a901060409356a337165b3 Step #5: Base64: 3oA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 136 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1857714905 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d9eaac9810, 0x55d9eacb301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d9eacb3020,0x55d9ecb4b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9046012bc6665e959a901060409356a337165b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 143 processed earlier; will process 10886 files now Step #5: ==4930== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d9e15be9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d9e7c23898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d9e7c065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d9e7c064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d9e15c4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d9e1525b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d9e1520355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d9e15b6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d9e4585f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d9e4585f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d9e4585f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d9e4585f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d9e4585f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d9e4585f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d9e4585f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d9e4585f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d9e4585f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d9e4585f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d9e681af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d9e3547b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d9e3552be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d9e32fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d9e32fec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d9e32ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d9e32fe874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d9e32fe874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d9e32fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d9e7c08abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d9e7c11928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d9e7bf9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d9e7c24112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4234948082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d9e151eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0x63, Step #5: :c Step #5: artifact_prefix='./'; Test unit written to ./oom-516957e653d8f6be0ec7a766870297980290faac Step #5: Base64: OmM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 137 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1858136390 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d04fedb810, 0x55d0500c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d0500c5020,0x55d051f5d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/516957e653d8f6be0ec7a766870297980290faac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 144 processed earlier; will process 10885 files now Step #5: ==4966== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d0469d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d04d035898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d04d0185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d04d0184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d0469d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d046937b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d046932355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d0469c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d049997f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d049997f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d049997f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d049997f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d049997f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d049997f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d049997f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d049997f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d049997f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d049997f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d04bc2cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d048959b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d048964be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d048710c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d048710c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d048711738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d048710874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d048710874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d048710874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d04d01aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d04d023928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d04d00b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d04d036112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcd2ed85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d046930b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0xa, Step #5: \015\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-ba8ab5a0280b953aa97435ff8946cbcbb2755a27 Step #5: Base64: DQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 138 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1858543015 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5626c9cbf810, 0x5626c9ea901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5626c9ea9020,0x5626cbd410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba8ab5a0280b953aa97435ff8946cbcbb2755a27' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 145 processed earlier; will process 10884 files now Step #5: ==5002== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5626c07b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5626c6e19898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5626c6dfc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5626c6dfc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5626c07bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5626c071bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5626c0716355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5626c07acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5626c377bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5626c377bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5626c377bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5626c377bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5626c377bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5626c377bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5626c377bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5626c377bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5626c377bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5626c377bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5626c5a10f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5626c273db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5626c2748be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5626c24f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5626c24f4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5626c24f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5626c24f4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5626c24f4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5626c24f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5626c6dfeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5626c6e07928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5626c6def699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5626c6e1a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f432e491082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5626c0714b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x34,0x7d, Step #5: 4} Step #5: artifact_prefix='./'; Test unit written to ./oom-e20b35ed30c70770e13a928519aa91468bd08d65 Step #5: Base64: NH0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 139 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1858962661 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5644ebf04810, 0x5644ec0ee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5644ec0ee020,0x5644edf860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e20b35ed30c70770e13a928519aa91468bd08d65' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 146 processed earlier; will process 10883 files now Step #5: ==5038== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5644e29f99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5644e905e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5644e90415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5644e90414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5644e29ffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5644e2960b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5644e295b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5644e29f1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5644e59c0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5644e59c0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5644e59c0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5644e59c0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5644e59c0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5644e59c0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5644e59c0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5644e59c0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5644e59c0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5644e59c0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5644e7c55f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5644e4982b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5644e498dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5644e4739c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5644e4739c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5644e473a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5644e4739874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5644e4739874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5644e4739874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5644e9043abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5644e904c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5644e9034699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5644e905f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9cfc268082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5644e2959b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x60, Step #5: `` Step #5: artifact_prefix='./'; Test unit written to ./oom-222b2b4ab2fdd2dd8ef261d8953351ac6bc457fa Step #5: Base64: YGA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 140 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1859493319 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557cdd28a810, 0x557cdd47401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557cdd474020,0x557cdf30c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/222b2b4ab2fdd2dd8ef261d8953351ac6bc457fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 147 processed earlier; will process 10882 files now Step #5: ==5074== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557cd3d7f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557cda3e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557cda3c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557cda3c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557cd3d85d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557cd3ce6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557cd3ce1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557cd3d77c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557cd6d46f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557cd6d46f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557cd6d46f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557cd6d46f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557cd6d46f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557cd6d46f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557cd6d46f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557cd6d46f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557cd6d46f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557cd6d46f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557cd8fdbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557cd5d08b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557cd5d13be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557cd5abfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557cd5abfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557cd5ac0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557cd5abf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557cd5abf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557cd5abf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557cda3c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557cda3d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557cda3ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557cda3e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f20723af082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557cd3cdfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcb,0x81, Step #5: \313\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-e6b7f3d9b617f1d00d3b23b476f18a1dcb8b90a5 Step #5: Base64: y4E= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 141 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1859912313 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b16d534810, 0x55b16d71e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b16d71e020,0x55b16f5b60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e6b7f3d9b617f1d00d3b23b476f18a1dcb8b90a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 148 processed earlier; will process 10881 files now Step #5: ==5110== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b1640299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b16a68e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b16a6715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b16a6714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b16402fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b163f90b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b163f8b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b164021c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b166ff0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b166ff0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b166ff0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b166ff0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b166ff0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b166ff0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b166ff0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b166ff0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b166ff0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b166ff0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b169285f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b165fb2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b165fbdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b165d69c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b165d69c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b165d6a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b165d69874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b165d69874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b165d69874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b16a673abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b16a67c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b16a664699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b16a68f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f612250a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b163f89b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0x76, Step #5: :v Step #5: artifact_prefix='./'; Test unit written to ./oom-5ff572ca7c69f86f416f8f4dd907e2e6df55909a Step #5: Base64: OnY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 142 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1860333439 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559939b08810, 0x559939cf201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559939cf2020,0x55993bb8a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ff572ca7c69f86f416f8f4dd907e2e6df55909a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 149 processed earlier; will process 10880 files now Step #5: #1 pulse cov: 6467 ft: 6469 exec/s: 0 rss: 164Mb Step #5: ==5146== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5599305fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559936c62898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559936c455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559936c454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559930603d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559930564b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55993055f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5599305f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5599335c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5599335c4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5599335c4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5599335c4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5599335c4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5599335c4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5599335c4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5599335c4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5599335c4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5599335c4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559935859f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559932586b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559932591be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55993233dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55993233dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55993233e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55993233d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55993233d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55993233d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559936c47abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559936c50928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559936c38699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559936c63112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d5f059082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55993055db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3d, Step #5: == Step #5: artifact_prefix='./'; Test unit written to ./oom-6947818ac409551f11fbaa78f0ea6391960aa5b8 Step #5: Base64: PT0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 143 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1860798923 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a90e45810, 0x555a9102f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a9102f020,0x555a92ec70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6947818ac409551f11fbaa78f0ea6391960aa5b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 151 processed earlier; will process 10878 files now Step #5: ==5182== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555a8793a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a8df9f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a8df825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a8df824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a87940d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a878a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a8789c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a87932c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a8a901f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a8a901f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a8a901f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a8a901f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a8a901f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a8a901f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a8a901f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a8a901f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a8a901f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a8a901f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a8cb96f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a898c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a898cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a8967ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a8967ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a8967b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a8967a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a8967a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a8967a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a8df84abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a8df8d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a8df75699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a8dfa0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a2b9cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a8789ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x4d, Step #5: MM Step #5: artifact_prefix='./'; Test unit written to ./oom-4a3a8927b85daa16f0fe11b6bbb759eee3095858 Step #5: Base64: TU0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 144 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1861219667 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e8a54d8810, 0x55e8a56c201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e8a56c2020,0x55e8a755a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4a3a8927b85daa16f0fe11b6bbb759eee3095858' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 152 processed earlier; will process 10877 files now Step #5: ==5218== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e89bfcd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e8a2632898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e8a26155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e8a26154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e89bfd3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e89bf34b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e89bf2f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e89bfc5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e89ef94f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e89ef94f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e89ef94f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e89ef94f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e89ef94f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e89ef94f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e89ef94f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e89ef94f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e89ef94f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e89ef94f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e8a1229f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e89df56b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e89df61be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e89dd0dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e89dd0dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e89dd0e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e89dd0d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e89dd0d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e89dd0d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e8a2617abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e8a2620928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e8a2608699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e8a2633112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa9f40fb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e89bf2db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x7f, Step #5: -\177 Step #5: artifact_prefix='./'; Test unit written to ./oom-3c9eb921ca2d4f4f404ad203d62811d5970c4489 Step #5: Base64: LX8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 145 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1861637129 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf6ab60810, 0x55bf6ad4a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf6ad4a020,0x55bf6cbe20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3c9eb921ca2d4f4f404ad203d62811d5970c4489' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 153 processed earlier; will process 10876 files now Step #5: ==5254== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bf616559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf67cba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf67c9d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf67c9d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf6165bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf615bcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf615b7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf6164dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf6461cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf6461cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf6461cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf6461cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf6461cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf6461cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf6461cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf6461cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf6461cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf6461cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf668b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf635deb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf635e9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf63395c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf63395c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf63396738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf63395874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf63395874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf63395874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf67c9fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf67ca8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf67c90699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf67cbb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feaf056a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf615b5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x0, Step #5: B\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ab69fa1ab6bb831506efcad83900fee751e85f6f Step #5: Base64: QgA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 146 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1862065654 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557546175810, 0x55754635f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55754635f020,0x5575481f70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ab69fa1ab6bb831506efcad83900fee751e85f6f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 154 processed earlier; will process 10875 files now Step #5: ==5290== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55753cc6a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5575432cf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5575432b25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5575432b24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55753cc70d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55753cbd1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55753cbcc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55753cc62c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55753fc31f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55753fc31f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55753fc31f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55753fc31f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55753fc31f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55753fc31f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55753fc31f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55753fc31f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55753fc31f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55753fc31f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557541ec6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55753ebf3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55753ebfebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55753e9aac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55753e9aac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55753e9ab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55753e9aa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55753e9aa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55753e9aa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5575432b4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5575432bd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5575432a5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5575432d0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f5369a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55753cbcab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xce,0x91, Step #5: \316\221 Step #5: artifact_prefix='./'; Test unit written to ./oom-56ef110565e8b5c12f9f7e4066673a87dd94c9ac Step #5: Base64: zpE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 147 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1862491024 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5629da44f810, 0x5629da63901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5629da639020,0x5629dc4d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56ef110565e8b5c12f9f7e4066673a87dd94c9ac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 155 processed earlier; will process 10874 files now Step #5: ==5326== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5629d0f449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5629d75a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5629d758c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5629d758c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5629d0f4ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629d0eabb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629d0ea6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5629d0f3cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5629d3f0bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5629d3f0bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5629d3f0bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5629d3f0bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5629d3f0bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5629d3f0bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5629d3f0bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5629d3f0bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5629d3f0bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5629d3f0bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5629d61a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629d2ecdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629d2ed8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629d2c84c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629d2c84c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629d2c85738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629d2c84874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629d2c84874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629d2c84874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5629d758eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5629d7597928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5629d757f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5629d75aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5c091b7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629d0ea4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x2d, Step #5: ~- Step #5: artifact_prefix='./'; Test unit written to ./oom-977014b1ee2a39f414ea34da42cafd40e3847427 Step #5: Base64: fi0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 148 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1862908504 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c78375f810, 0x55c78394901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c783949020,0x55c7857e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/977014b1ee2a39f414ea34da42cafd40e3847427' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 156 processed earlier; will process 10873 files now Step #5: ==5362== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c77a2549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7808b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c78089c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c78089c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c77a25ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c77a1bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c77a1b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c77a24cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c77d21bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c77d21bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c77d21bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c77d21bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c77d21bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c77d21bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c77d21bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c77d21bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c77d21bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c77d21bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c77f4b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c77c1ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c77c1e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c77bf94c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c77bf94c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c77bf95738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c77bf94874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c77bf94874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c77bf94874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c78089eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7808a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c78088f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7808ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdcdc8ad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c77a1b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0x9, Step #5: \015\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf7f6cad30f4b0c598985b7e799f505f59821e45 Step #5: Base64: DQk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 149 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1863316395 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f0ce9d3810, 0x55f0cebbd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f0cebbd020,0x55f0d0a550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf7f6cad30f4b0c598985b7e799f505f59821e45' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 157 processed earlier; will process 10872 files now Step #5: ==5398== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f0c54c89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f0cbb2d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f0cbb105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f0cbb104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f0c54ced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f0c542fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f0c542a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f0c54c0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f0c848ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f0c848ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f0c848ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f0c848ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f0c848ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f0c848ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f0c848ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f0c848ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f0c848ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f0c848ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f0ca724f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f0c7451b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f0c745cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f0c7208c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f0c7208c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f0c7209738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f0c7208874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f0c7208874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f0c7208874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f0cbb12abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f0cbb1b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f0cbb03699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f0cbb2e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3931082082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f0c5428b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x27, Step #5: }' Step #5: artifact_prefix='./'; Test unit written to ./oom-69b832bec722a825df3b6a18ee4d5ed1241b01b6 Step #5: Base64: fSc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 150 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1863738075 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56437cf70810, 0x56437d15a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56437d15a020,0x56437eff20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/69b832bec722a825df3b6a18ee4d5ed1241b01b6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 158 processed earlier; will process 10871 files now Step #5: ==5434== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564373a659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56437a0ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56437a0ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56437a0ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564373a6bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643739ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643739c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564373a5dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564376a2cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564376a2cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564376a2cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564376a2cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564376a2cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564376a2cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564376a2cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564376a2cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564376a2cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564376a2cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564378cc1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643759eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643759f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643757a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643757a5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643757a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643757a5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643757a5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643757a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56437a0afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56437a0b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56437a0a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56437a0cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f430e183082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643739c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0xbf, Step #5: \337\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-300f01aa690f416a005dfb5fd24a7b2f3243f686 Step #5: Base64: 378= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 151 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1864156763 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557924683810, 0x55792486d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55792486d020,0x5579267050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/300f01aa690f416a005dfb5fd24a7b2f3243f686' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 159 processed earlier; will process 10870 files now Step #5: ==5470== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55791b1789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5579217dd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5579217c05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5579217c04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55791b17ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55791b0dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55791b0da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55791b170c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55791e13ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55791e13ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55791e13ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55791e13ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55791e13ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55791e13ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55791e13ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55791e13ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55791e13ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55791e13ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579203d4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55791d101b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55791d10cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55791ceb8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55791ceb8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55791ceb9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55791ceb8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55791ceb8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55791ceb8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5579217c2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5579217cb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5579217b3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5579217de112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2cf25f5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55791b0d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdd,0x80, Step #5: \335\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-b4125bc162e82d1b43018cc73becd538b97fbeb0 Step #5: Base64: 3YA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 152 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1864571822 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56464e898810, 0x56464ea8201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56464ea82020,0x56465091a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b4125bc162e82d1b43018cc73becd538b97fbeb0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 160 processed earlier; will process 10869 files now Step #5: ==5506== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56464538d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56464b9f2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56464b9d55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56464b9d54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564645393d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5646452f4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5646452ef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564645385c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564648354f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564648354f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564648354f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564648354f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564648354f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564648354f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564648354f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564648354f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564648354f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564648354f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56464a5e9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564647316b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564647321be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5646470cdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5646470cdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5646470ce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5646470cd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5646470cd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5646470cd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56464b9d7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56464b9e0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56464b9c8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56464b9f3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faade360082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5646452edb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x61,0x8, Step #5: a\010 Step #5: artifact_prefix='./'; Test unit written to ./oom-1436c49b27e334782f2fd587dfca3263612a3675 Step #5: Base64: YQg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 153 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1864991380 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c36142f810, 0x55c36161901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c361619020,0x55c3634b10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1436c49b27e334782f2fd587dfca3263612a3675' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 161 processed earlier; will process 10868 files now Step #5: ==5542== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c357f249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c35e589898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c35e56c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c35e56c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c357f2ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c357e8bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c357e86355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c357f1cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c35aeebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c35aeebf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c35aeebf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c35aeebf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c35aeebf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c35aeebf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c35aeebf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c35aeebf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c35aeebf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c35aeebf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c35d180f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c359eadb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c359eb8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c359c64c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c359c64c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c359c65738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c359c64874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c359c64874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c359c64874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c35e56eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c35e577928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c35e55f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c35e58a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb331163082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c357e84b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdc,0xb8, Step #5: \334\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-6dbbd4386d98401453b8d69faa8e03ea7c5af70f Step #5: Base64: 3Lg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 154 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1865418407 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561815dd1810, 0x561815fbb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561815fbb020,0x561817e530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6dbbd4386d98401453b8d69faa8e03ea7c5af70f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 162 processed earlier; will process 10867 files now Step #5: ==5578== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56180c8c69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561812f2b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561812f0e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561812f0e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56180c8ccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56180c82db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56180c828355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56180c8bec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56180f88df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56180f88df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56180f88df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56180f88df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56180f88df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56180f88df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56180f88df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56180f88df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56180f88df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56180f88df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561811b22f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56180e84fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56180e85abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56180e606c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56180e606c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56180e607738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56180e606874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56180e606874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56180e606874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561812f10abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561812f19928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561812f01699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561812f2c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1784827082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56180c826b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0xb0, Step #5: \337\260 Step #5: artifact_prefix='./'; Test unit written to ./oom-36e94f025d21074fcb7030aadc4bfa07ca2b7b7a Step #5: Base64: 37A= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 155 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1865839971 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56037c261810, 0x56037c44b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56037c44b020,0x56037e2e30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/36e94f025d21074fcb7030aadc4bfa07ca2b7b7a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 163 processed earlier; will process 10866 files now Step #5: ==5614== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560372d569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5603793bb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56037939e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56037939e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560372d5cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560372cbdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560372cb8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560372d4ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560375d1df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560375d1df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560375d1df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560375d1df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560375d1df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560375d1df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560375d1df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560375d1df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560375d1df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560375d1df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560377fb2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560374cdfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560374ceabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560374a96c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560374a96c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560374a97738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560374a96874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560374a96874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560374a96874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5603793a0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5603793a9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560379391699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5603793bc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ae29d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560372cb6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x34, Step #5: |4 Step #5: artifact_prefix='./'; Test unit written to ./oom-7d3ef85a50063c2afed6dc77afe3729c54979508 Step #5: Base64: fDQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 156 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1866256554 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555af0ecc810, 0x555af10b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555af10b6020,0x555af2f4e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d3ef85a50063c2afed6dc77afe3729c54979508' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 164 processed earlier; will process 10865 files now Step #5: ==5650== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555ae79c19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555aee026898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555aee0095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555aee0094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ae79c7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ae7928b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ae7923355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ae79b9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555aea988f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555aea988f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555aea988f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555aea988f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555aea988f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555aea988f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555aea988f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555aea988f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555aea988f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555aea988f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555aecc1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ae994ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ae9955be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ae9701c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ae9701c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ae9702738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ae9701874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ae9701874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ae9701874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555aee00babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555aee014928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555aedffc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555aee027112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f57325a9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ae7921b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x2b, Step #5: {+ Step #5: artifact_prefix='./'; Test unit written to ./oom-425047c038625bcecd4f691e0365190485985a27 Step #5: Base64: eys= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 157 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1866673682 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55558d560810, 0x55558d74a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55558d74a020,0x55558f5e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/425047c038625bcecd4f691e0365190485985a27' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 165 processed earlier; will process 10864 files now Step #5: ==5686== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5555840559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55558a6ba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55558a69d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55558a69d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55558405bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555583fbcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555583fb7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55558404dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55558701cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55558701cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55558701cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55558701cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55558701cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55558701cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55558701cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55558701cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55558701cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55558701cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5555892b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555585fdeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555585fe9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555585d95c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555585d95c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555585d96738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555585d95874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555585d95874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555585d95874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55558a69fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55558a6a8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55558a690699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55558a6bb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd660d36082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555583fb5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0xb, Step #5: \013\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-528f35403f03cffb7c48def06f9729651237f5ff Step #5: Base64: Cws= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 158 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1867081713 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56370b633810, 0x56370b81d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56370b81d020,0x56370d6b50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/528f35403f03cffb7c48def06f9729651237f5ff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 166 processed earlier; will process 10863 files now Step #5: ==5722== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5637021289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56370878d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5637087705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5637087704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56370212ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56370208fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56370208a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563702120c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5637050eff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5637050eff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5637050eff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5637050eff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5637050eff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5637050eff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5637050eff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5637050eff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5637050eff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5637050eff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563707384f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5637040b1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5637040bcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563703e68c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563703e68c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563703e69738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563703e68874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563703e68874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563703e68874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563708772abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56370877b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563708763699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56370878e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f508cc2b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563702088b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x67,0x67, Step #5: gg Step #5: artifact_prefix='./'; Test unit written to ./oom-f3226f91f77a87d909b8920adc91f9a301a7316b Step #5: Base64: Z2c= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 159 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1867499631 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5650528e1810, 0x565052acb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565052acb020,0x5650549630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f3226f91f77a87d909b8920adc91f9a301a7316b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 167 processed earlier; will process 10862 files now Step #5: ==5758== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5650493d69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56504fa3b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56504fa1e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56504fa1e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5650493dcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56504933db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565049338355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5650493cec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56504c39df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56504c39df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56504c39df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56504c39df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56504c39df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56504c39df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56504c39df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56504c39df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56504c39df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56504c39df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56504e632f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56504b35fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56504b36abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56504b116c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56504b116c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56504b117738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56504b116874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56504b116874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56504b116874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56504fa20abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56504fa29928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56504fa11699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56504fa3c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0f6a07a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565049336b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x32, Step #5: P2 Step #5: artifact_prefix='./'; Test unit written to ./oom-f0b89ee9977fb93bf3a71343d5a95ac58463bb40 Step #5: Base64: UDI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 160 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1867923978 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5604df571810, 0x5604df75b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604df75b020,0x5604e15f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f0b89ee9977fb93bf3a71343d5a95ac58463bb40' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 168 processed earlier; will process 10861 files now Step #5: ==5794== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5604d60669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5604dc6cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5604dc6ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5604dc6ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5604d606cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5604d5fcdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5604d5fc8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5604d605ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5604d902df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5604d902df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5604d902df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5604d902df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5604d902df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5604d902df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5604d902df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5604d902df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5604d902df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5604d902df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5604db2c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5604d7fefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5604d7ffabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5604d7da6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5604d7da6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5604d7da7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5604d7da6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5604d7da6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5604d7da6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5604dc6b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5604dc6b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5604dc6a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5604dc6cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9630b6b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5604d5fc6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc8,0xa0, Step #5: \310\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-da366823fe847be8e2dcc8984824a372548708b7 Step #5: Base64: yKA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 161 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1868339490 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b2091d5810, 0x55b2093bf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b2093bf020,0x55b20b2570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/da366823fe847be8e2dcc8984824a372548708b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 169 processed earlier; will process 10860 files now Step #5: #1 pulse cov: 3420 ft: 3421 exec/s: 0 rss: 151Mb Step #5: ==5830== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b1ffcca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b20632f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b2063125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b2063124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b1ffcd0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b1ffc31b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b1ffc2c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b1ffcc2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b202c91f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b202c91f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b202c91f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b202c91f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b202c91f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b202c91f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b202c91f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b202c91f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b202c91f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b202c91f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b204f26f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b201c53b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b201c5ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b201a0ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b201a0ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b201a0b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b201a0a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b201a0a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b201a0a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b206314abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b20631d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b206305699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b206330112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e9507a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b1ffc2ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x9f, Step #5: \333\237 Step #5: artifact_prefix='./'; Test unit written to ./oom-15ca59afdbcfbda0855ad34d4909e5dda2157d22 Step #5: Base64: 258= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 162 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1868792886 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5628eb943810, 0x5628ebb2d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5628ebb2d020,0x5628ed9c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/15ca59afdbcfbda0855ad34d4909e5dda2157d22' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 171 processed earlier; will process 10858 files now Step #5: ==5866== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5628e24389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5628e8a9d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5628e8a805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5628e8a804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5628e243ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5628e239fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5628e239a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5628e2430c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5628e53fff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5628e53fff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5628e53fff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5628e53fff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5628e53fff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5628e53fff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5628e53fff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5628e53fff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5628e53fff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5628e53fff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5628e7694f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5628e43c1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5628e43ccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5628e4178c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5628e4178c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5628e4179738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5628e4178874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5628e4178874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5628e4178874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5628e8a82abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5628e8a8b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5628e8a73699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5628e8a9e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffb90e28082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5628e2398b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0xb8, Step #5: \302\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-756515a75ad2f92f30c281cb747eee315a22ea8a Step #5: Base64: wrg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 163 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1869215776 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d3e6bd810, 0x563d3e8a701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d3e8a7020,0x563d4073f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/756515a75ad2f92f30c281cb747eee315a22ea8a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 172 processed earlier; will process 10857 files now Step #5: ==5902== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563d351b29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d3b817898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d3b7fa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d3b7fa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d351b8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d35119b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d35114355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d351aac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d38179f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d38179f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d38179f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d38179f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d38179f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d38179f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d38179f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d38179f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d38179f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d38179f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d3a40ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d3713bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d37146be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d36ef2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d36ef2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d36ef3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d36ef2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d36ef2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d36ef2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d3b7fcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d3b805928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d3b7ed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d3b818112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe4048a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d35112b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0xbd, Step #5: \337\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-8f33f14f402f89f17b4b9370f8f0ba0ae929a94d Step #5: Base64: 370= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 164 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1869637420 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652d5c4b810, 0x5652d5e3501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652d5e35020,0x5652d7ccd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8f33f14f402f89f17b4b9370f8f0ba0ae929a94d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 173 processed earlier; will process 10856 files now Step #5: ==5938== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5652cc7409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652d2da5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652d2d885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652d2d884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5652cc746d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5652cc6a7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5652cc6a2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5652cc738c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5652cf707f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5652cf707f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5652cf707f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5652cf707f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5652cf707f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5652cf707f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5652cf707f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5652cf707f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5652cf707f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5652cf707f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652d199cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5652ce6c9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5652ce6d4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652ce480c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652ce480c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652ce481738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652ce480874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652ce480874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652ce480874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652d2d8aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652d2d93928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652d2d7b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652d2da6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f43a596e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5652cc6a0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x38, Step #5: -8 Step #5: artifact_prefix='./'; Test unit written to ./oom-413eb32104d697d2d75b5dfde422a9c299130f44 Step #5: Base64: LTg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 165 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1870058521 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a347d0810, 0x559a349ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a349ba020,0x559a368520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/413eb32104d697d2d75b5dfde422a9c299130f44' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 174 processed earlier; will process 10855 files now Step #5: ==5974== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559a2b2c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a3192a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a3190d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a3190d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a2b2cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a2b22cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a2b227355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a2b2bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a2e28cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a2e28cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a2e28cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a2e28cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a2e28cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a2e28cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a2e28cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a2e28cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a2e28cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a2e28cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a30521f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a2d24eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a2d259be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a2d005c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a2d005c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a2d006738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a2d005874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a2d005874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a2d005874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a3190fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a31918928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a31900699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a3192b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb95ed79082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a2b225b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5a,0xc2, Step #5: Z\302 Step #5: artifact_prefix='./'; Test unit written to ./oom-39883220a318fef789c5eb8f13680b6c6fbd3529 Step #5: Base64: WsI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 166 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1870474874 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e82315810, 0x555e824ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e824ff020,0x555e843970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/39883220a318fef789c5eb8f13680b6c6fbd3529' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 175 processed earlier; will process 10854 files now Step #5: ==6010== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555e78e0a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e7f46f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e7f4525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e7f4524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e78e10d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e78d71b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e78d6c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e78e02c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e7bdd1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e7bdd1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e7bdd1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e7bdd1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e7bdd1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e7bdd1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e7bdd1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e7bdd1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e7bdd1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e7bdd1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e7e066f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e7ad93b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e7ad9ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e7ab4ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e7ab4ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e7ab4b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e7ab4a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e7ab4a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e7ab4a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e7f454abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e7f45d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e7f445699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e7f470112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc3108dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e78d6ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc5,0x80, Step #5: \305\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-1a687df598ea74c17de01a00731ab6d893ad567c Step #5: Base64: xYA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 167 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1870892734 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564ed0d99810, 0x564ed0f8301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564ed0f83020,0x564ed2e1b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1a687df598ea74c17de01a00731ab6d893ad567c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 176 processed earlier; will process 10853 files now Step #5: ==6046== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564ec788e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564ecdef3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564ecded65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564ecded64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ec7894d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ec77f5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ec77f0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ec7886c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564eca855f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564eca855f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564eca855f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564eca855f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564eca855f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564eca855f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564eca855f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564eca855f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564eca855f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564eca855f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564eccaeaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564ec9817b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564ec9822be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564ec95cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564ec95cec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564ec95cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564ec95ce874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564ec95ce874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564ec95ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564ecded8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564ecdee1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564ecdec9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564ecdef4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb8b33fe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ec77eeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xa, Step #5: =\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-9ae22869553bb63a4f4133b33d9b0e315b842f7e Step #5: Base64: PQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 168 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1871299143 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565449ffd810, 0x56544a1e701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56544a1e7020,0x56544c07f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9ae22869553bb63a4f4133b33d9b0e315b842f7e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 177 processed earlier; will process 10852 files now Step #5: ==6082== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x565440af29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565447157898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56544713a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56544713a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565440af8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565440a59b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565440a54355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565440aeac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565443ab9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565443ab9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565443ab9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565443ab9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565443ab9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565443ab9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565443ab9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565443ab9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565443ab9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565443ab9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565445d4ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565442a7bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565442a86be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565442832c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565442832c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565442833738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565442832874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565442832874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565442832874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56544713cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565447145928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56544712d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565447158112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc6a32b9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565440a52b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x11, Step #5: \001\021 Step #5: artifact_prefix='./'; Test unit written to ./oom-51c6a3c0b55b51f8cfb2144afd716577a1b41906 Step #5: Base64: ARE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 169 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1871722984 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e2a9597810, 0x55e2a978101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e2a9781020,0x55e2ab6190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/51c6a3c0b55b51f8cfb2144afd716577a1b41906' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 178 processed earlier; will process 10851 files now Step #5: ==6118== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e2a008c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e2a66f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e2a66d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e2a66d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e2a0092d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e29fff3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e29ffee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e2a0084c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e2a3053f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e2a3053f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e2a3053f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e2a3053f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e2a3053f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e2a3053f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e2a3053f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e2a3053f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e2a3053f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e2a3053f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e2a52e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e2a2015b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e2a2020be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e2a1dccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e2a1dccc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e2a1dcd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e2a1dcc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e2a1dcc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e2a1dcc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e2a66d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e2a66df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e2a66c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e2a66f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa6fef71082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e29ffecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc3,0xb3, Step #5: \303\263 Step #5: artifact_prefix='./'; Test unit written to ./oom-a6abd767c025f163792b3f6d1fec94a731abce06 Step #5: Base64: w7M= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 170 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1872138153 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a1c95b810, 0x555a1cb4501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a1cb45020,0x555a1e9dd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a6abd767c025f163792b3f6d1fec94a731abce06' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 179 processed earlier; will process 10850 files now Step #5: ==6154== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555a134509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a19ab5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a19a985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a19a984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a13456d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a133b7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a133b2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a13448c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a16417f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a16417f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a16417f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a16417f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a16417f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a16417f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a16417f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a16417f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a16417f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a16417f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a186acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a153d9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a153e4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a15190c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a15190c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a15191738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a15190874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a15190874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a15190874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a19a9aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a19aa3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a19a8b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a19ab6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0dfc3ac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a133b0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa, Step #5: \012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-71853c6197a6a7f222db0f1978c7cb232b87c5ee Step #5: Base64: Cgo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 171 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1872550302 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55be50566810, 0x55be5075001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55be50750020,0x55be525e80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/71853c6197a6a7f222db0f1978c7cb232b87c5ee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 180 processed earlier; will process 10849 files now Step #5: ==6190== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55be4705b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55be4d6c0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55be4d6a35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55be4d6a34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55be47061d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55be46fc2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55be46fbd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55be47053c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55be4a022f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55be4a022f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55be4a022f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55be4a022f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55be4a022f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55be4a022f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55be4a022f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55be4a022f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55be4a022f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55be4a022f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55be4c2b7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55be48fe4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55be48fefbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55be48d9bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55be48d9bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55be48d9c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55be48d9b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55be48d9b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55be48d9b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55be4d6a5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55be4d6ae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55be4d696699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55be4d6c1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4c5d43c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55be46fbbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x7e, Step #5: 0~ Step #5: artifact_prefix='./'; Test unit written to ./oom-d9dc4752a25d754c51d466823879b43997c6e571 Step #5: Base64: MH4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 172 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1872975330 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5622a6946810, 0x5622a6b3001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622a6b30020,0x5622a89c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d9dc4752a25d754c51d466823879b43997c6e571' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 181 processed earlier; will process 10848 files now Step #5: ==6226== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56229d43b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5622a3aa0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5622a3a835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5622a3a834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56229d441d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56229d3a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56229d39d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56229d433c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5622a0402f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5622a0402f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5622a0402f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5622a0402f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5622a0402f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5622a0402f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5622a0402f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5622a0402f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5622a0402f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5622a0402f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5622a2697f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56229f3c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56229f3cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56229f17bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56229f17bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56229f17c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56229f17b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56229f17b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56229f17b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5622a3a85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5622a3a8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5622a3a76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5622a3aa1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac3cb90082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56229d39bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x6a, Step #5: tj Step #5: artifact_prefix='./'; Test unit written to ./oom-546b05909706652891a87f7bfe385ae147f61f91 Step #5: Base64: dGo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 173 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1873390651 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557961070810, 0x55796125a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55796125a020,0x5579630f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/546b05909706652891a87f7bfe385ae147f61f91' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 182 processed earlier; will process 10847 files now Step #5: ==6262== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557957b659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55795e1ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55795e1ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55795e1ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557957b6bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557957accb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557957ac7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557957b5dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55795ab2cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55795ab2cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55795ab2cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55795ab2cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55795ab2cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55795ab2cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55795ab2cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55795ab2cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55795ab2cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55795ab2cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55795cdc1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557959aeeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557959af9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5579598a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5579598a5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5579598a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5579598a5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5579598a5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5579598a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55795e1afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55795e1b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55795e1a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55795e1cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5693c91082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557957ac5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa, Step #5: -\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-60215a10e730f79c20b7d4fcaabec120335e379e Step #5: Base64: LQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 174 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1873806263 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5590f7e85810, 0x5590f806f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5590f806f020,0x5590f9f070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/60215a10e730f79c20b7d4fcaabec120335e379e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 183 processed earlier; will process 10846 files now Step #5: ==6298== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5590ee97a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5590f4fdf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5590f4fc25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5590f4fc24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5590ee980d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5590ee8e1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5590ee8dc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5590ee972c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5590f1941f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5590f1941f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5590f1941f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5590f1941f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5590f1941f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5590f1941f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5590f1941f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5590f1941f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5590f1941f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5590f1941f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5590f3bd6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5590f0903b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5590f090ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5590f06bac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5590f06bac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5590f06bb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5590f06ba874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5590f06ba874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5590f06ba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5590f4fc4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5590f4fcd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5590f4fb5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5590f4fe0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f763e3cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5590ee8dab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x14, Step #5: \002\024 Step #5: artifact_prefix='./'; Test unit written to ./oom-05b83a77daca077292b7f960a5ab31451dc08d50 Step #5: Base64: AhQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 175 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1874221316 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b35872810, 0x560b35a5c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b35a5c020,0x560b378f40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/05b83a77daca077292b7f960a5ab31451dc08d50' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 184 processed earlier; will process 10845 files now Step #5: ==6334== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560b2c3679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b329cc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b329af5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b329af4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b2c36dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b2c2ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b2c2c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b2c35fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b2f32ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b2f32ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b2f32ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b2f32ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b2f32ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b2f32ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b2f32ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b2f32ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b2f32ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b2f32ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b315c3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b2e2f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b2e2fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b2e0a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b2e0a7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b2e0a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b2e0a7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b2e0a7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b2e0a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b329b1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b329ba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b329a2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b329cd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2a3665a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b2c2c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0xa3, Step #5: \\\243 Step #5: artifact_prefix='./'; Test unit written to ./oom-ca65efd4798518d8db5c0cad67015b768f577587 Step #5: Base64: XKM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 176 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1874635289 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56196590b810, 0x561965af501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561965af5020,0x56196798d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca65efd4798518d8db5c0cad67015b768f577587' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 185 processed earlier; will process 10844 files now Step #5: ==6370== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56195c4009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561962a65898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561962a485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561962a484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56195c406d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56195c367b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56195c362355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56195c3f8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56195f3c7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56195f3c7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56195f3c7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56195f3c7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56195f3c7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56195f3c7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56195f3c7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56195f3c7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56195f3c7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56195f3c7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56196165cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56195e389b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56195e394be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56195e140c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56195e140c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56195e141738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56195e140874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56195e140874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56195e140874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561962a4aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561962a53928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561962a3b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561962a66112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff3f7034082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56195c360b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x22, Step #5: \"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-dd29ecf524b030a65261e3059c48ab9e1ecb2585 Step #5: Base64: IiI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 177 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1875050237 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5644e929f810, 0x5644e948901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5644e9489020,0x5644eb3210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dd29ecf524b030a65261e3059c48ab9e1ecb2585' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 186 processed earlier; will process 10843 files now Step #5: ==6406== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5644dfd949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5644e63f9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5644e63dc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5644e63dc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5644dfd9ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5644dfcfbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5644dfcf6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5644dfd8cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5644e2d5bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5644e2d5bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5644e2d5bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5644e2d5bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5644e2d5bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5644e2d5bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5644e2d5bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5644e2d5bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5644e2d5bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5644e2d5bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5644e4ff0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5644e1d1db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5644e1d28be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5644e1ad4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5644e1ad4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5644e1ad5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5644e1ad4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5644e1ad4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5644e1ad4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5644e63deabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5644e63e7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5644e63cf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5644e63fa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f308542c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5644dfcf4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3d, Step #5: <= Step #5: artifact_prefix='./'; Test unit written to ./oom-8a681a2f041f4625cceacf20f0cf8ebf4248b5f1 Step #5: Base64: PD0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 178 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1875467284 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb454d7810, 0x55bb456c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb456c1020,0x55bb475590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8a681a2f041f4625cceacf20f0cf8ebf4248b5f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 187 processed earlier; will process 10842 files now Step #5: ==6442== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bb3bfcc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb42631898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb426145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb426144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb3bfd2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb3bf33b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb3bf2e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb3bfc4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb3ef93f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb3ef93f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb3ef93f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb3ef93f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb3ef93f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb3ef93f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb3ef93f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb3ef93f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb3ef93f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb3ef93f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb41228f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb3df55b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb3df60be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb3dd0cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb3dd0cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb3dd0d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb3dd0c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb3dd0c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb3dd0c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb42616abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb4261f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb42607699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb42632112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fad940b5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb3bf2cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0x85, Step #5: \302\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-207344f7426e2ec664f98775fad0ff35b164eefd Step #5: Base64: woU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 179 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1875870310 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e8858e2810, 0x55e885acc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e885acc020,0x55e8879640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/207344f7426e2ec664f98775fad0ff35b164eefd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 188 processed earlier; will process 10841 files now Step #5: ==6478== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e87c3d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e882a3c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e882a1f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e882a1f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e87c3ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e87c33eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e87c339355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e87c3cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e87f39ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e87f39ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e87f39ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e87f39ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e87f39ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e87f39ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e87f39ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e87f39ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e87f39ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e87f39ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e881633f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e87e360b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e87e36bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e87e117c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e87e117c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e87e118738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e87e117874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e87e117874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e87e117874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e882a21abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e882a2a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e882a12699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e882a3d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f72cdac1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e87c337b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33,0x31, Step #5: 31 Step #5: artifact_prefix='./'; Test unit written to ./oom-632667547e7cd3e0466547863e1207a8c0c0c549 Step #5: Base64: MzE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 180 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1876282891 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563b673d6810, 0x563b675c001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563b675c0020,0x563b694580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/632667547e7cd3e0466547863e1207a8c0c0c549' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 189 processed earlier; will process 10840 files now Step #5: ==6514== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563b5decb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563b64530898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563b645135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563b645134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563b5ded1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563b5de32b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563b5de2d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563b5dec3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563b60e92f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563b60e92f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563b60e92f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563b60e92f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563b60e92f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563b60e92f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563b60e92f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563b60e92f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563b60e92f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563b60e92f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563b63127f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563b5fe54b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563b5fe5fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563b5fc0bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563b5fc0bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563b5fc0c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563b5fc0b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563b5fc0b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563b5fc0b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563b64515abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563b6451e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563b64506699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563b64531112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd976eb3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563b5de2bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0xbb, Step #5: \333\273 Step #5: artifact_prefix='./'; Test unit written to ./oom-4bc6e4c25fe60d30c976d7718c4103472db79dcb Step #5: Base64: 27s= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 181 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1876700250 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f91fad810, 0x556f9219701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f92197020,0x556f9402f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4bc6e4c25fe60d30c976d7718c4103472db79dcb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 190 processed earlier; will process 10839 files now Step #5: ==6550== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556f88aa29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f8f107898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f8f0ea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f8f0ea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f88aa8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f88a09b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f88a04355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f88a9ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f8ba69f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f8ba69f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f8ba69f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f8ba69f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f8ba69f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f8ba69f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f8ba69f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f8ba69f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f8ba69f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f8ba69f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f8dcfef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f8aa2bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f8aa36be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f8a7e2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f8a7e2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f8a7e3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f8a7e2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f8a7e2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f8a7e2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f8f0ecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f8f0f5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f8f0dd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f8f108112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc9fc3f8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f88a02b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x75,0x64, Step #5: ud Step #5: artifact_prefix='./'; Test unit written to ./oom-29b1930481ec92d813a66ca893468ae710b71a85 Step #5: Base64: dWQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 182 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1877113690 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d093518810, 0x55d09370201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d093702020,0x55d09559a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/29b1930481ec92d813a66ca893468ae710b71a85' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 191 processed earlier; will process 10838 files now Step #5: ==6586== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d08a00d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d090672898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d0906555dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d0906554fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d08a013d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d089f74b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d089f6f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d08a005c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d08cfd4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d08cfd4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d08cfd4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d08cfd4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d08cfd4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d08cfd4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d08cfd4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d08cfd4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d08cfd4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d08cfd4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d08f269f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d08bf96b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d08bfa1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d08bd4dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d08bd4dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d08bd4e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d08bd4d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d08bd4d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d08bd4d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d090657abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d090660928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d090648699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d090673112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb015b83082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d089f6db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x21, Step #5: #! Step #5: artifact_prefix='./'; Test unit written to ./oom-2d46bc445fe5eef1125228cce271ca63a02b246d Step #5: Base64: IyE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 183 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1877516226 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564a94d58810, 0x564a94f4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564a94f42020,0x564a96dda0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2d46bc445fe5eef1125228cce271ca63a02b246d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 192 processed earlier; will process 10837 files now Step #5: ==6622== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564a8b84d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564a91eb2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564a91e955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564a91e954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564a8b853d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564a8b7b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564a8b7af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564a8b845c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564a8e814f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564a8e814f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564a8e814f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564a8e814f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564a8e814f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564a8e814f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564a8e814f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564a8e814f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564a8e814f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564a8e814f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564a90aa9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564a8d7d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564a8d7e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564a8d58dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564a8d58dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564a8d58e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564a8d58d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564a8d58d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564a8d58d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564a91e97abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564a91ea0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564a91e88699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564a91eb3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f387f91f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564a8b7adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x20, Step #5: x Step #5: artifact_prefix='./'; Test unit written to ./oom-93bb4c5d2dc83169102545d02af706edf8e38bb6 Step #5: Base64: eCA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 184 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1877934932 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559417850810, 0x559417a3a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559417a3a020,0x5594198d20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93bb4c5d2dc83169102545d02af706edf8e38bb6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 193 processed earlier; will process 10836 files now Step #5: ==6658== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55940e3459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5594149aa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55941498d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55941498d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55940e34bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55940e2acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55940e2a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55940e33dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55941130cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55941130cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55941130cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55941130cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55941130cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55941130cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55941130cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55941130cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55941130cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55941130cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5594135a1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5594102ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5594102d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559410085c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559410085c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559410086738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559410085874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559410085874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559410085874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55941498fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559414998928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559414980699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5594149ab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f66079d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55940e2a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xde,0xb6, Step #5: \336\266 Step #5: artifact_prefix='./'; Test unit written to ./oom-1128415b8b72ea41b312c2d633d23df2bf17e9b2 Step #5: Base64: 3rY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 185 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1878351292 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55793ffa9810, 0x55794019301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557940193020,0x55794202b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1128415b8b72ea41b312c2d633d23df2bf17e9b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 194 processed earlier; will process 10835 files now Step #5: ==6694== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557936a9e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55793d103898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55793d0e65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55793d0e64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557936aa4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557936a05b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557936a00355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557936a96c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557939a65f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557939a65f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557939a65f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557939a65f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557939a65f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557939a65f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557939a65f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557939a65f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557939a65f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557939a65f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55793bcfaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557938a27b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557938a32be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5579387dec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5579387dec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5579387df738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5579387de874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5579387de874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5579387de874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55793d0e8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55793d0f1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55793d0d9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55793d104112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f319ad01082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5579369feb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x2b, Step #5: B+ Step #5: artifact_prefix='./'; Test unit written to ./oom-a96ddd562d17c0ce477825adcff2ef5c3f14c3b3 Step #5: Base64: Qis= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 186 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1878765063 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56186728f810, 0x56186747901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561867479020,0x5618693110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a96ddd562d17c0ce477825adcff2ef5c3f14c3b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 195 processed earlier; will process 10834 files now Step #5: ==6730== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56185dd849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5618643e9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5618643cc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5618643cc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56185dd8ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56185dcebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56185dce6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56185dd7cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561860d4bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561860d4bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561860d4bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561860d4bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561860d4bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561860d4bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561860d4bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561860d4bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561860d4bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561860d4bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561862fe0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56185fd0db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56185fd18be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56185fac4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56185fac4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56185fac5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56185fac4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56185fac4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56185fac4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5618643ceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5618643d7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5618643bf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5618643ea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f20918e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56185dce4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x3e, Step #5: p> Step #5: artifact_prefix='./'; Test unit written to ./oom-7f7467397cea7de51f29dc50cac2190d921b443e Step #5: Base64: cD4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 187 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1879183534 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c1eff4e810, 0x55c1f013801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c1f0138020,0x55c1f1fd00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f7467397cea7de51f29dc50cac2190d921b443e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 196 processed earlier; will process 10833 files now Step #5: ==6766== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c1e6a439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c1ed0a8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c1ed08b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c1ed08b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c1e6a49d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c1e69aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c1e69a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c1e6a3bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c1e9a0af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c1e9a0af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c1e9a0af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c1e9a0af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c1e9a0af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c1e9a0af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c1e9a0af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c1e9a0af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c1e9a0af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c1e9a0af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c1ebc9ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c1e89ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c1e89d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c1e8783c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c1e8783c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c1e8784738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c1e8783874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c1e8783874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c1e8783874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c1ed08dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c1ed096928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c1ed07e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c1ed0a9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9a7ba83082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c1e69a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x20, Step #5: Step #5: artifact_prefix='./'; Test unit written to ./oom-099600a10a944114aac406d136b625fb416dd779 Step #5: Base64: ICA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 188 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1879585268 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557c38cf1810, 0x557c38edb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557c38edb020,0x557c3ad730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/099600a10a944114aac406d136b625fb416dd779' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 197 processed earlier; will process 10832 files now Step #5: #1 pulse cov: 3524 ft: 3525 exec/s: 0 rss: 154Mb Step #5: ==6802== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557c2f7e69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557c35e4b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557c35e2e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557c35e2e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557c2f7ecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557c2f74db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557c2f748355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557c2f7dec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557c327adf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557c327adf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557c327adf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557c327adf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557c327adf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557c327adf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557c327adf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557c327adf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557c327adf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557c327adf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557c34a42f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557c3176fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557c3177abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557c31526c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557c31526c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557c31527738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557c31526874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557c31526874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557c31526874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557c35e30abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557c35e39928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557c35e21699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557c35e4c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f30241f8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557c2f746b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x52,0x7d, Step #5: R} Step #5: artifact_prefix='./'; Test unit written to ./oom-74df03bcb36ae030d669f9da8ef9cab66f9b16d8 Step #5: Base64: Un0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 189 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1880043886 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55791a49d810, 0x55791a68701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55791a687020,0x55791c51f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/74df03bcb36ae030d669f9da8ef9cab66f9b16d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 199 processed earlier; will process 10830 files now Step #5: ==6838== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557910f929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5579175f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5579175da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5579175da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557910f98d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557910ef9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557910ef4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557910f8ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557913f59f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557913f59f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557913f59f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557913f59f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557913f59f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557913f59f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557913f59f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557913f59f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557913f59f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557913f59f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579161eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557912f1bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557912f26be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557912cd2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557912cd2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557912cd3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557912cd2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557912cd2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557912cd2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5579175dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5579175e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5579175cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5579175f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbef717c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557910ef2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0x62, Step #5: :b Step #5: artifact_prefix='./'; Test unit written to ./oom-b93ccefa28585e0321e57bd439d521347671fff9 Step #5: Base64: OmI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 190 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1880460870 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ef7db3d810, 0x55ef7dd2701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ef7dd27020,0x55ef7fbbf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b93ccefa28585e0321e57bd439d521347671fff9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 200 processed earlier; will process 10829 files now Step #5: ==6874== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ef746329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ef7ac97898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ef7ac7a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ef7ac7a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef74638d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef74599b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef74594355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef7462ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef775f9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef775f9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef775f9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef775f9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef775f9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef775f9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef775f9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef775f9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef775f9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef775f9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef7988ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef765bbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef765c6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef76372c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef76372c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef76373738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef76372874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef76372874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef76372874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ef7ac7cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ef7ac85928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ef7ac6d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ef7ac98112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f09819d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef74592b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6,0x58, Step #5: \006X Step #5: artifact_prefix='./'; Test unit written to ./oom-61a6cc0e0b32b26b5a281e3d6cf689c7bd4f9cd8 Step #5: Base64: Blg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 191 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1880880369 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5608cc172810, 0x5608cc35c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5608cc35c020,0x5608ce1f40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/61a6cc0e0b32b26b5a281e3d6cf689c7bd4f9cd8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 201 processed earlier; will process 10828 files now Step #5: ==6910== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5608c2c679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5608c92cc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608c92af5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608c92af4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5608c2c6dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5608c2bceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5608c2bc9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5608c2c5fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5608c5c2ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5608c5c2ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5608c5c2ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5608c5c2ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5608c5c2ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5608c5c2ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5608c5c2ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5608c5c2ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5608c5c2ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5608c5c2ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608c7ec3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5608c4bf0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5608c4bfbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5608c49a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5608c49a7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5608c49a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5608c49a7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5608c49a7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5608c49a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5608c92b1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5608c92ba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5608c92a2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5608c92cd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb119f1f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5608c2bc7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f, Step #5: // Step #5: artifact_prefix='./'; Test unit written to ./oom-ebbffb7d7ea5362a22bfa1bab0bfdeb1617cd610 Step #5: Base64: Ly8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 192 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1881288617 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5561489ec810, 0x556148bd601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556148bd6020,0x55614aa6e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ebbffb7d7ea5362a22bfa1bab0bfdeb1617cd610' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 202 processed earlier; will process 10827 files now Step #5: ==6946== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55613f4e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556145b46898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556145b295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556145b294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55613f4e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55613f448b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55613f443355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55613f4d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5561424a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5561424a8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5561424a8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5561424a8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5561424a8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5561424a8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5561424a8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5561424a8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5561424a8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5561424a8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55614473df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55614146ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556141475be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556141221c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556141221c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556141222738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556141221874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556141221874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556141221874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556145b2babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556145b34928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556145b1c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556145b47112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f04a508c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55613f441b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd0,0x82, Step #5: \320\202 Step #5: artifact_prefix='./'; Test unit written to ./oom-4a3534317f31a18033ccc2856a238d8b504e6b11 Step #5: Base64: 0II= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 193 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1881707292 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5648f548f810, 0x5648f567901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5648f5679020,0x5648f75110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4a3534317f31a18033ccc2856a238d8b504e6b11' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 203 processed earlier; will process 10826 files now Step #5: ==6982== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5648ebf849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5648f25e9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5648f25cc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5648f25cc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5648ebf8ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5648ebeebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5648ebee6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5648ebf7cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5648eef4bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5648eef4bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5648eef4bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5648eef4bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5648eef4bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5648eef4bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5648eef4bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5648eef4bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5648eef4bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5648eef4bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5648f11e0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5648edf0db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5648edf18be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5648edcc4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5648edcc4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5648edcc5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5648edcc4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5648edcc4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5648edcc4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5648f25ceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5648f25d7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5648f25bf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5648f25ea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1333f92082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5648ebee4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x41, Step #5: DA Step #5: artifact_prefix='./'; Test unit written to ./oom-593c323390e39a524395f3227c9aef6ba349fd18 Step #5: Base64: REE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 194 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1882121953 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558111339810, 0x55811152301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558111523020,0x5581133bb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/593c323390e39a524395f3227c9aef6ba349fd18' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 204 processed earlier; will process 10825 files now Step #5: ==7018== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558107e2e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55810e493898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55810e4765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55810e4764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558107e34d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558107d95b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558107d90355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558107e26c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55810adf5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55810adf5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55810adf5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55810adf5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55810adf5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55810adf5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55810adf5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55810adf5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55810adf5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55810adf5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55810d08af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558109db7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558109dc2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558109b6ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558109b6ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558109b6f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558109b6e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558109b6e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558109b6e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55810e478abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55810e481928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55810e469699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55810e494112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9b516f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558107d8eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd1,0xa0, Step #5: \321\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-66171f13d83204083bd22e3a5881edfc602d6318 Step #5: Base64: 0aA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 195 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1882537278 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b705ea2810, 0x55b70608c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b70608c020,0x55b707f240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/66171f13d83204083bd22e3a5881edfc602d6318' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 205 processed earlier; will process 10824 files now Step #5: ==7054== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b6fc9979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b702ffc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b702fdf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b702fdf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6fc99dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6fc8feb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6fc8f9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6fc98fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b6ff95ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b6ff95ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b6ff95ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b6ff95ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b6ff95ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b6ff95ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b6ff95ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b6ff95ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b6ff95ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b6ff95ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b701bf3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6fe920b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6fe92bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6fe6d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6fe6d7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6fe6d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6fe6d7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6fe6d7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6fe6d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b702fe1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b702fea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b702fd2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b702ffd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1fda628082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6fc8f7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x56,0x4, Step #5: V\004 Step #5: artifact_prefix='./'; Test unit written to ./oom-8cf383be82f3e9e4c87eb09082b77ea5f672b0a0 Step #5: Base64: VgQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 196 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1882952917 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56536decb810, 0x56536e0b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56536e0b5020,0x56536ff4d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8cf383be82f3e9e4c87eb09082b77ea5f672b0a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 206 processed earlier; will process 10823 files now Step #5: ==7090== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5653649c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56536b025898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56536b0085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56536b0084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5653649c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565364927b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565364922355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5653649b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565367987f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565367987f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565367987f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565367987f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565367987f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565367987f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565367987f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565367987f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565367987f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565367987f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565369c1cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565366949b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565366954be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565366700c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565366700c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565366701738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565366700874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565366700874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565366700874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56536b00aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56536b013928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56536affb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56536b026112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe6397fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565364920b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd3,0x9e, Step #5: \323\236 Step #5: artifact_prefix='./'; Test unit written to ./oom-5eff8e9d5a4491e0a48117a5d68ee542bd1419a2 Step #5: Base64: 054= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 197 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1883366631 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d7b10ca810, 0x55d7b12b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d7b12b4020,0x55d7b314c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5eff8e9d5a4491e0a48117a5d68ee542bd1419a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 207 processed earlier; will process 10822 files now Step #5: #1 pulse cov: 3432 ft: 3433 exec/s: 0 rss: 153Mb Step #5: ==7126== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d7a7bbf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d7ae224898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7ae2075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7ae2074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d7a7bc5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d7a7b26b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d7a7b21355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d7a7bb7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d7aab86f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d7aab86f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d7aab86f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d7aab86f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d7aab86f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d7aab86f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d7aab86f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d7aab86f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d7aab86f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d7aab86f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d7ace1bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d7a9b48b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d7a9b53be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d7a98ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d7a98ffc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d7a9900738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d7a98ff874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d7a98ff874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d7a98ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d7ae209abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d7ae212928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d7ae1fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d7ae225112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3fc8018082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d7a7b1fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x22, Step #5: \\\" Step #5: artifact_prefix='./'; Test unit written to ./oom-ab006bb8aacdf6e68299bc1dffccc9bcc8ac3eaf Step #5: Base64: XCI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 198 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1883826649 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1256c1810, 0x55d1258ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1258ab020,0x55d1277430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ab006bb8aacdf6e68299bc1dffccc9bcc8ac3eaf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 209 processed earlier; will process 10820 files now Step #5: ==7162== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d11c1b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d12281b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1227fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1227fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d11c1bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d11c11db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d11c118355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d11c1aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d11f17df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d11f17df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d11f17df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d11f17df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d11f17df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d11f17df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d11f17df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d11f17df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d11f17df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d11f17df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d121412f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d11e13fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d11e14abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d11def6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d11def6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d11def7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d11def6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d11def6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d11def6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d122800abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d122809928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1227f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d12281c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f151301e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d11c116b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x39,0x35, Step #5: 95 Step #5: artifact_prefix='./'; Test unit written to ./oom-8e63fd3e77796b102589b1ba1e4441c7982e4132 Step #5: Base64: OTU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 199 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1884243585 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5634940a1810, 0x56349428b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56349428b020,0x5634961230e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8e63fd3e77796b102589b1ba1e4441c7982e4132' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 210 processed earlier; will process 10819 files now Step #5: ==7198== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56348ab969c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5634911fb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634911de5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634911de4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56348ab9cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56348aafdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56348aaf8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56348ab8ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56348db5df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56348db5df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56348db5df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56348db5df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56348db5df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56348db5df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56348db5df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56348db5df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56348db5df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56348db5df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56348fdf2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56348cb1fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56348cb2abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56348c8d6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56348c8d6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56348c8d7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56348c8d6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56348c8d6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56348c8d6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5634911e0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5634911e9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5634911d1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5634911fc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff18ee63082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56348aaf6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf,0xf, Step #5: \017\017 Step #5: artifact_prefix='./'; Test unit written to ./oom-9af20251e31f563588a4c4a674a397350b2191e3 Step #5: Base64: Dw8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 200 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1884670932 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643c2221810, 0x5643c240b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643c240b020,0x5643c42a30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9af20251e31f563588a4c4a674a397350b2191e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 211 processed earlier; will process 10818 files now Step #5: ==7234== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5643b8d169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643bf37b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643bf35e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643bf35e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643b8d1cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643b8c7db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643b8c78355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643b8d0ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643bbcddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643bbcddf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643bbcddf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643bbcddf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643bbcddf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643bbcddf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643bbcddf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643bbcddf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643bbcddf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643bbcddf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643bdf72f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643bac9fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643bacaabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643baa56c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643baa56c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643baa57738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643baa56874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643baa56874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643baa56874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643bf360abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643bf369928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643bf351699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643bf37c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f716fb5f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643b8c76b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0x80, Step #5: \337\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-824ab64f3a678275c864d1b52da7b11d3406664b Step #5: Base64: 34A= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 201 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1885090909 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f1e143a810, 0x55f1e162401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f1e1624020,0x55f1e34bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/824ab64f3a678275c864d1b52da7b11d3406664b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 212 processed earlier; will process 10817 files now Step #5: ==7270== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f1d7f2f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f1de594898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1de5775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1de5774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f1d7f35d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f1d7e96b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f1d7e91355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f1d7f27c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f1daef6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f1daef6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f1daef6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f1daef6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f1daef6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f1daef6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f1daef6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f1daef6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f1daef6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f1daef6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f1dd18bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f1d9eb8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f1d9ec3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f1d9c6fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f1d9c6fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f1d9c70738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f1d9c6f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f1d9c6f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f1d9c6f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f1de579abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f1de582928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f1de56a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f1de595112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd70796f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f1d7e8fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd0,0xbf, Step #5: \320\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-9caf4a95f812be6ab203095bb2ffda9f7256fe6a Step #5: Base64: 0L8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 202 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1885507740 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ac7f08810, 0x555ac80f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ac80f2020,0x555ac9f8a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9caf4a95f812be6ab203095bb2ffda9f7256fe6a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 213 processed earlier; will process 10816 files now Step #5: ==7306== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555abe9fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ac5062898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ac50455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ac50454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555abea03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555abe964b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555abe95f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555abe9f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ac19c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ac19c4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ac19c4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ac19c4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ac19c4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ac19c4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ac19c4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ac19c4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ac19c4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ac19c4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555ac3c59f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ac0986b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ac0991be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ac073dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ac073dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ac073e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ac073d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ac073d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ac073d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ac5047abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ac5050928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ac5038699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ac5063112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe961261082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555abe95db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc3,0x9f, Step #5: \303\237 Step #5: artifact_prefix='./'; Test unit written to ./oom-00b39d61cc9b61a36437c4de643ec56b831e36d5 Step #5: Base64: w58= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 203 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1885917062 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558d6be46810, 0x558d6c03001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558d6c030020,0x558d6dec80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/00b39d61cc9b61a36437c4de643ec56b831e36d5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 214 processed earlier; will process 10815 files now Step #5: ==7342== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558d6293b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558d68fa0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558d68f835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558d68f834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558d62941d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558d628a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558d6289d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558d62933c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558d65902f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558d65902f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558d65902f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558d65902f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558d65902f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558d65902f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558d65902f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558d65902f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558d65902f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558d65902f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558d67b97f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558d648c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558d648cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558d6467bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558d6467bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558d6467c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558d6467b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558d6467b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558d6467b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558d68f85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558d68f8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558d68f76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558d68fa1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb489aae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558d6289bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0x38, Step #5: n8 Step #5: artifact_prefix='./'; Test unit written to ./oom-8474f7b38e608554cdf62452ff87d009cab04549 Step #5: Base64: bjg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 204 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1886329923 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed526f5810, 0x55ed528df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed528df020,0x55ed547770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8474f7b38e608554cdf62452ff87d009cab04549' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 215 processed earlier; will process 10814 files now Step #5: ==7378== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ed491ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed4f84f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed4f8325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed4f8324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed491f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed49151b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed4914c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed491e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed4c1b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed4c1b1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed4c1b1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed4c1b1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed4c1b1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed4c1b1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed4c1b1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed4c1b1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed4c1b1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed4c1b1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed4e446f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed4b173b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed4b17ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed4af2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed4af2ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed4af2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed4af2a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed4af2a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed4af2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed4f834abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed4f83d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed4f825699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed4f850112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3f3785d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed4914ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x2c, Step #5: ', Step #5: artifact_prefix='./'; Test unit written to ./oom-809401f14c20f5e5a279a9efaa4c97436332a2a1 Step #5: Base64: Jyw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 205 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1886742928 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5613fa4b3810, 0x5613fa69d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5613fa69d020,0x5613fc5350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/809401f14c20f5e5a279a9efaa4c97436332a2a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 216 processed earlier; will process 10813 files now Step #5: ==7414== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5613f0fa89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5613f760d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613f75f05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613f75f04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5613f0faed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5613f0f0fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5613f0f0a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5613f0fa0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5613f3f6ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5613f3f6ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5613f3f6ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5613f3f6ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5613f3f6ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5613f3f6ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5613f3f6ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5613f3f6ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5613f3f6ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5613f3f6ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5613f6204f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5613f2f31b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5613f2f3cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5613f2ce8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5613f2ce8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5613f2ce9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5613f2ce8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5613f2ce8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5613f2ce8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5613f75f2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5613f75fb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5613f75e3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5613f760e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5873a2c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5613f0f08b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6a,0x7a, Step #5: jz Step #5: artifact_prefix='./'; Test unit written to ./oom-4e375e814be137a4f94f9d2b2a5f4ca930cc7a5a Step #5: Base64: ano= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 206 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1887155044 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5597dcc1c810, 0x5597dce0601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5597dce06020,0x5597dec9e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e375e814be137a4f94f9d2b2a5f4ca930cc7a5a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 217 processed earlier; will process 10812 files now Step #5: ==7450== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5597d37119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5597d9d76898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5597d9d595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5597d9d594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5597d3717d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5597d3678b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5597d3673355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5597d3709c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5597d66d8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5597d66d8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5597d66d8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5597d66d8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5597d66d8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5597d66d8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5597d66d8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5597d66d8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5597d66d8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5597d66d8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5597d896df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5597d569ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5597d56a5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5597d5451c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5597d5451c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5597d5452738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5597d5451874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5597d5451874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5597d5451874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5597d9d5babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5597d9d64928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5597d9d4c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5597d9d77112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3623315082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5597d3671b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x19,0x1, Step #5: \031\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-9cd8d204202598ce7de6a301ea4a5de001876308 Step #5: Base64: GQE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 207 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1887566643 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c80198810, 0x562c8038201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c80382020,0x562c8221a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9cd8d204202598ce7de6a301ea4a5de001876308' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 218 processed earlier; will process 10811 files now Step #5: ==7486== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562c76c8d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c7d2f2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c7d2d55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c7d2d54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c76c93d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c76bf4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c76bef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c76c85c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c79c54f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c79c54f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c79c54f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c79c54f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c79c54f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c79c54f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c79c54f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c79c54f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c79c54f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c79c54f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c7bee9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562c78c16b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562c78c21be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562c789cdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562c789cdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562c789ce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562c789cd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562c789cd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562c789cd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c7d2d7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c7d2e0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c7d2c8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c7d2f3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f38cd977082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c76bedb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0x77, Step #5: \013w Step #5: artifact_prefix='./'; Test unit written to ./oom-2a084d4cc0a1af20e2ca59f5a7b6ee842a67ee8e Step #5: Base64: C3c= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 208 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1887985309 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561274b13810, 0x561274cfd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561274cfd020,0x561276b950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2a084d4cc0a1af20e2ca59f5a7b6ee842a67ee8e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 219 processed earlier; will process 10810 files now Step #5: ==7522== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56126b6089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561271c6d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561271c505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561271c504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56126b60ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56126b56fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56126b56a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56126b600c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56126e5cff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56126e5cff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56126e5cff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56126e5cff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56126e5cff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56126e5cff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56126e5cff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56126e5cff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56126e5cff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56126e5cff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561270864f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56126d591b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56126d59cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56126d348c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56126d348c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56126d349738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56126d348874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56126d348874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56126d348874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561271c52abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561271c5b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561271c43699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561271c6e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f45daad2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56126b568b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x22, Step #5: '\" Step #5: artifact_prefix='./'; Test unit written to ./oom-ce4310c274a623bf708c2156890bf00667718582 Step #5: Base64: JyI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 209 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1888409245 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561e308a9810, 0x561e30a9301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561e30a93020,0x561e3292b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce4310c274a623bf708c2156890bf00667718582' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 220 processed earlier; will process 10809 files now Step #5: ==7558== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561e2739e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561e2da03898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561e2d9e65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561e2d9e64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561e273a4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561e27305b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561e27300355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561e27396c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561e2a365f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561e2a365f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561e2a365f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561e2a365f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561e2a365f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561e2a365f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561e2a365f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561e2a365f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561e2a365f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561e2a365f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561e2c5faf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561e29327b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561e29332be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561e290dec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561e290dec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561e290df738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561e290de874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561e290de874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561e290de874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561e2d9e8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561e2d9f1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561e2d9d9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561e2da04112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa94244a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561e272feb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0x97, Step #5: \337\227 Step #5: artifact_prefix='./'; Test unit written to ./oom-b6a88117a976fc912ab9c438e291b84c2e59d0c5 Step #5: Base64: 35c= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 210 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1888833177 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5580f2a77810, 0x5580f2c6101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5580f2c61020,0x5580f4af90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b6a88117a976fc912ab9c438e291b84c2e59d0c5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 221 processed earlier; will process 10808 files now Step #5: ==7594== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5580e956c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5580efbd1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5580efbb45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5580efbb44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5580e9572d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5580e94d3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5580e94ce355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5580e9564c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5580ec533f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5580ec533f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5580ec533f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5580ec533f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5580ec533f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5580ec533f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5580ec533f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5580ec533f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5580ec533f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5580ec533f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5580ee7c8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5580eb4f5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5580eb500be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580eb2acc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580eb2acc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580eb2ad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580eb2ac874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580eb2ac874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580eb2ac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5580efbb6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5580efbbf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5580efba7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5580efbd2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6a8a048082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5580e94ccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x2d, Step #5: =- Step #5: artifact_prefix='./'; Test unit written to ./oom-0021b2b4b9f15dd7038c16779068114ecec5be13 Step #5: Base64: PS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 211 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1889252709 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b6e35a6810, 0x55b6e379001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b6e3790020,0x55b6e56280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0021b2b4b9f15dd7038c16779068114ecec5be13' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 222 processed earlier; will process 10807 files now Step #5: #1 pulse cov: 3422 ft: 3423 exec/s: 0 rss: 154Mb Step #5: ==7630== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b6da09b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b6e0700898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b6e06e35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b6e06e34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6da0a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6da002b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6d9ffd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6da093c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b6dd062f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b6dd062f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b6dd062f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b6dd062f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b6dd062f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b6dd062f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b6dd062f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b6dd062f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b6dd062f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b6dd062f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b6df2f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6dc024b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6dc02fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6dbddbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6dbddbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6dbddc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6dbddb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6dbddb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6dbddb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b6e06e5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b6e06ee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b6e06d6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b6e0701112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d6efbc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6d9ffbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x71,0x52, Step #5: qR Step #5: artifact_prefix='./'; Test unit written to ./oom-95955b6461512cb08586c3fa871f117fea39ba0b Step #5: Base64: cVI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 212 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1889722740 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5592c932c810, 0x5592c951601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5592c9516020,0x5592cb3ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/95955b6461512cb08586c3fa871f117fea39ba0b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 224 processed earlier; will process 10805 files now Step #5: ==7666== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5592bfe219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5592c6486898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5592c64695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5592c64694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592bfe27d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592bfd88b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592bfd83355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592bfe19c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592c2de8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592c2de8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592c2de8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592c2de8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592c2de8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592c2de8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592c2de8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592c2de8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592c2de8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592c2de8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592c507df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592c1daab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592c1db5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5592c1b61c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5592c1b61c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5592c1b62738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5592c1b61874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5592c1b61874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5592c1b61874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5592c646babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5592c6474928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5592c645c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5592c6487112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f77f08dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592bfd81b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x35,0x40, Step #5: 5@ Step #5: artifact_prefix='./'; Test unit written to ./oom-3a59146c793108f8f188cf1784d67915983c00d2 Step #5: Base64: NUA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 213 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1890141141 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5609f3e4d810, 0x5609f403701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5609f4037020,0x5609f5ecf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a59146c793108f8f188cf1784d67915983c00d2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 225 processed earlier; will process 10804 files now Step #5: ==7702== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5609ea9429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5609f0fa7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5609f0f8a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5609f0f8a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5609ea948d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5609ea8a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5609ea8a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5609ea93ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5609ed909f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5609ed909f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5609ed909f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5609ed909f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5609ed909f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5609ed909f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5609ed909f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5609ed909f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5609ed909f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5609ed909f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5609efb9ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5609ec8cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5609ec8d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5609ec682c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5609ec682c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5609ec683738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5609ec682874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5609ec682874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5609ec682874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5609f0f8cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5609f0f95928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5609f0f7d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5609f0fa8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8435561082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5609ea8a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6d,0x46, Step #5: mF Step #5: artifact_prefix='./'; Test unit written to ./oom-f3b7b4d8014783269099a7416ad6e596f26af61d Step #5: Base64: bUY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 214 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1890556331 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5649f8351810, 0x5649f853b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5649f853b020,0x5649fa3d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f3b7b4d8014783269099a7416ad6e596f26af61d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 226 processed earlier; will process 10803 files now Step #5: ==7738== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5649eee469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5649f54ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5649f548e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5649f548e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5649eee4cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649eedadb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649eeda8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5649eee3ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5649f1e0df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5649f1e0df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5649f1e0df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5649f1e0df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5649f1e0df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5649f1e0df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5649f1e0df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5649f1e0df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5649f1e0df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5649f1e0df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5649f40a2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649f0dcfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649f0ddabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5649f0b86c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5649f0b86c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5649f0b87738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5649f0b86874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5649f0b86874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5649f0b86874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5649f5490abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5649f5499928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5649f5481699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5649f54ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f188a6bd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649eeda6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x13, Step #5: \003\023 Step #5: artifact_prefix='./'; Test unit written to ./oom-86a28da5df902414af3bd99e1164487f6e741e9a Step #5: Base64: AxM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 215 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1890969180 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec6da7d810, 0x55ec6dc6701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec6dc67020,0x55ec6faff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/86a28da5df902414af3bd99e1164487f6e741e9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 227 processed earlier; will process 10802 files now Step #5: ==7774== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ec645729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec6abd7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec6abba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec6abba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec64578d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec644d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec644d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec6456ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec67539f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec67539f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec67539f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec67539f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec67539f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec67539f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec67539f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec67539f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec67539f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec67539f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec697cef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec664fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec66506be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec662b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec662b2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec662b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec662b2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec662b2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec662b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec6abbcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec6abc5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec6abad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec6abd8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fefd84a3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec644d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x2e, Step #5: <. Step #5: artifact_prefix='./'; Test unit written to ./oom-9186eeba7415eeb2feace4cdeda47122075e5702 Step #5: Base64: PC4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 216 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1891389654 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564b1acdc810, 0x564b1aec601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564b1aec6020,0x564b1cd5e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9186eeba7415eeb2feace4cdeda47122075e5702' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 228 processed earlier; will process 10801 files now Step #5: ==7810== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564b117d19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564b17e36898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564b17e195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564b17e194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564b117d7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564b11738b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564b11733355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564b117c9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564b14798f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564b14798f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564b14798f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564b14798f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564b14798f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564b14798f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564b14798f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564b14798f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564b14798f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564b14798f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564b16a2df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564b1375ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564b13765be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564b13511c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564b13511c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564b13512738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564b13511874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564b13511874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564b13511874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564b17e1babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564b17e24928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564b17e0c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564b17e37112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcdbb347082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564b11731b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x61, Step #5: da Step #5: artifact_prefix='./'; Test unit written to ./oom-cdd4f874095045f4ae6670038cbbd05fac9d4802 Step #5: Base64: ZGE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 217 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1891809150 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d3e45c810, 0x563d3e64601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d3e646020,0x563d404de0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cdd4f874095045f4ae6670038cbbd05fac9d4802' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 229 processed earlier; will process 10800 files now Step #5: ==7846== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563d34f519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d3b5b6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d3b5995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d3b5994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d34f57d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d34eb8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d34eb3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d34f49c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d37f18f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d37f18f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d37f18f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d37f18f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d37f18f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d37f18f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d37f18f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d37f18f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d37f18f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d37f18f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d3a1adf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d36edab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d36ee5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d36c91c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d36c91c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d36c92738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d36c91874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d36c91874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d36c91874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d3b59babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d3b5a4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d3b58c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d3b5b7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb48cffe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d34eb1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x34,0x7b, Step #5: 4{ Step #5: artifact_prefix='./'; Test unit written to ./oom-212bbdfc5828efb2397caaeb2738f85ba1f48d18 Step #5: Base64: NHs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 218 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1892219852 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b1fc671810, 0x55b1fc85b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b1fc85b020,0x55b1fe6f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/212bbdfc5828efb2397caaeb2738f85ba1f48d18' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 230 processed earlier; will process 10799 files now Step #5: ==7882== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b1f31669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b1f97cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1f97ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1f97ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b1f316cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b1f30cdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b1f30c8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b1f315ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b1f612df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b1f612df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b1f612df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b1f612df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b1f612df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b1f612df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b1f612df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b1f612df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b1f612df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b1f612df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b1f83c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b1f50efb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b1f50fabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b1f4ea6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b1f4ea6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b1f4ea7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b1f4ea6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b1f4ea6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b1f4ea6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b1f97b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b1f97b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b1f97a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b1f97cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9d0eec6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b1f30c6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0x3f, Step #5: \013? Step #5: artifact_prefix='./'; Test unit written to ./oom-70e9ba7b936289d1ac909cfa3c96e2b09a63d87a Step #5: Base64: Cz8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 219 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1892637089 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557cc065c810, 0x557cc084601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557cc0846020,0x557cc26de0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70e9ba7b936289d1ac909cfa3c96e2b09a63d87a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 231 processed earlier; will process 10798 files now Step #5: ==7918== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557cb71519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557cbd7b6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557cbd7995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557cbd7994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557cb7157d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557cb70b8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557cb70b3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557cb7149c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557cba118f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557cba118f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557cba118f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557cba118f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557cba118f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557cba118f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557cba118f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557cba118f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557cba118f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557cba118f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557cbc3adf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557cb90dab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557cb90e5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557cb8e91c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557cb8e91c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557cb8e92738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557cb8e91874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557cb8e91874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557cb8e91874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557cbd79babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557cbd7a4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557cbd78c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557cbd7b7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ba77ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557cb70b1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x38,0x62, Step #5: 8b Step #5: artifact_prefix='./'; Test unit written to ./oom-2a8e26e8fcd7896301e9cc38ce6a001900857fad Step #5: Base64: OGI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 220 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1893050135 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563904a23810, 0x563904c0d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563904c0d020,0x563906aa50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2a8e26e8fcd7896301e9cc38ce6a001900857fad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 232 processed earlier; will process 10797 files now Step #5: ==7954== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5638fb5189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563901b7d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563901b605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563901b604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5638fb51ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5638fb47fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5638fb47a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5638fb510c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5638fe4dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5638fe4dff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5638fe4dff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5638fe4dff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5638fe4dff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5638fe4dff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5638fe4dff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5638fe4dff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5638fe4dff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5638fe4dff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563900774f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5638fd4a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5638fd4acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5638fd258c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5638fd258c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5638fd259738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5638fd258874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5638fd258874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5638fd258874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563901b62abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563901b6b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563901b53699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563901b7e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4f8237082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5638fb478b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0x6e, Step #5: in Step #5: artifact_prefix='./'; Test unit written to ./oom-af10ef20dd9060bbeead0afbc55381a66af442ef Step #5: Base64: aW4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 221 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1893462812 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560249549810, 0x56024973301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560249733020,0x56024b5cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af10ef20dd9060bbeead0afbc55381a66af442ef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 233 processed earlier; will process 10796 files now Step #5: ==7990== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56024003e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5602466a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602466865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602466864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560240044d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56023ffa5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56023ffa0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560240036c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560243005f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560243005f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560243005f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560243005f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560243005f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560243005f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560243005f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560243005f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560243005f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560243005f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56024529af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560241fc7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560241fd2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560241d7ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560241d7ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560241d7f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560241d7e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560241d7e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560241d7e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560246688abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560246691928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560246679699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5602466a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ea87fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56023ff9eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2d, Step #5: /- Step #5: artifact_prefix='./'; Test unit written to ./oom-dfec926c1e11575719960ca972a0834a44a5eef0 Step #5: Base64: Ly0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 222 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1893878082 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c35c2ba810, 0x55c35c4a401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c35c4a4020,0x55c35e33c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dfec926c1e11575719960ca972a0834a44a5eef0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 234 processed earlier; will process 10795 files now Step #5: ==8026== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c352daf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c359414898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c3593f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c3593f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c352db5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c352d16b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c352d11355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c352da7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c355d76f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c355d76f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c355d76f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c355d76f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c355d76f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c355d76f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c355d76f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c355d76f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c355d76f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c355d76f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c35800bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c354d38b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c354d43be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c354aefc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c354aefc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c354af0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c354aef874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c354aef874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c354aef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c3593f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c359402928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c3593ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c359415112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68f7e6a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c352d0fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x40, Step #5: \000@ Step #5: artifact_prefix='./'; Test unit written to ./oom-b428cbaf48c7b3c08d326789913e6c8f6edb46e9 Step #5: Base64: AEA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 223 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1894287116 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560e07d01810, 0x560e07eeb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560e07eeb020,0x560e09d830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b428cbaf48c7b3c08d326789913e6c8f6edb46e9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 235 processed earlier; will process 10794 files now Step #5: ==8062== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560dfe7f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560e04e5b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560e04e3e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560e04e3e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560dfe7fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560dfe75db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560dfe758355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560dfe7eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560e017bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560e017bdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560e017bdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560e017bdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560e017bdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560e017bdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560e017bdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560e017bdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560e017bdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560e017bdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560e03a52f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560e0077fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560e0078abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560e00536c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560e00536c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560e00537738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560e00536874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560e00536874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560e00536874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560e04e40abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560e04e49928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560e04e31699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560e04e5c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc36bb9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560dfe756b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x42, Step #5: BB Step #5: artifact_prefix='./'; Test unit written to ./oom-71c9db717578b9ee49a59e69375c16c0627dffef Step #5: Base64: QkI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 224 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1894703089 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56009836e810, 0x56009855801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560098558020,0x56009a3f00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/71c9db717578b9ee49a59e69375c16c0627dffef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 236 processed earlier; will process 10793 files now Step #5: ==8098== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56008ee639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5600954c8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5600954ab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5600954ab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56008ee69d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56008edcab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56008edc5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56008ee5bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560091e2af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560091e2af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560091e2af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560091e2af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560091e2af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560091e2af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560091e2af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560091e2af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560091e2af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560091e2af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5600940bff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560090decb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560090df7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560090ba3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560090ba3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560090ba4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560090ba3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560090ba3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560090ba3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5600954adabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5600954b6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56009549e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5600954c9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f301cf6b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56008edc3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x7d, Step #5: [} Step #5: artifact_prefix='./'; Test unit written to ./oom-c608d68482a21298534e47f1f3d5581383518707 Step #5: Base64: W30= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 225 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1895117416 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564f70d9f810, 0x564f70f8901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564f70f89020,0x564f72e210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c608d68482a21298534e47f1f3d5581383518707' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 237 processed earlier; will process 10792 files now Step #5: ==8134== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564f678949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f6def9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f6dedc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f6dedc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f6789ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f677fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f677f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f6788cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f6a85bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f6a85bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f6a85bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f6a85bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f6a85bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f6a85bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f6a85bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f6a85bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f6a85bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f6a85bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f6caf0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f6981db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f69828be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f695d4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f695d4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f695d5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f695d4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f695d4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f695d4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f6dedeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f6dee7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f6decf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f6defa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e31220082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f677f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xd,0x72, Step #5: =\015r Step #5: artifact_prefix='./'; Test unit written to ./oom-c93c6bbb0639ee2a508540e4f37f695a6e056173 Step #5: Base64: PQ1y Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 226 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1895538282 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d36534e810, 0x55d36553801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d365538020,0x55d3673d00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c93c6bbb0639ee2a508540e4f37f695a6e056173' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 238 processed earlier; will process 10791 files now Step #5: ==8170== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d35be439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d3624a8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d36248b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d36248b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d35be49d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d35bdaab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d35bda5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d35be3bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d35ee0af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d35ee0af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d35ee0af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d35ee0af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d35ee0af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d35ee0af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d35ee0af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d35ee0af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d35ee0af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d35ee0af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d36109ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d35ddccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d35ddd7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d35db83c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d35db83c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d35db84738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d35db83874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d35db83874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d35db83874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d36248dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d362496928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d36247e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d3624a9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7effdd6a2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d35bda3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xb1,0x96, Step #5: \340\261\226 Step #5: artifact_prefix='./'; Test unit written to ./oom-3e39b5d430887acaba3ad886aac9c67b6e38173a Step #5: Base64: 4LGW Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 227 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1895953807 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d8bff2810, 0x563d8c1dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d8c1dc020,0x563d8e0740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3e39b5d430887acaba3ad886aac9c67b6e38173a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 239 processed earlier; will process 10790 files now Step #5: ==8206== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563d82ae79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d8914c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d8912f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d8912f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d82aedd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d82a4eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d82a49355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d82adfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d85aaef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d85aaef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d85aaef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d85aaef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d85aaef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d85aaef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d85aaef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d85aaef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d85aaef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d85aaef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d87d43f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d84a70b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d84a7bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d84827c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d84827c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d84828738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d84827874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d84827874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d84827874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d89131abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d8913a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d89122699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d8914d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f18315a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d82a47b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x24,0x24, Step #5: \012$$ Step #5: artifact_prefix='./'; Test unit written to ./oom-b8c3ebab05fbab81ebd434de438e9272fb773612 Step #5: Base64: CiQk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 228 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1896358300 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55995094e810, 0x559950b3801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559950b38020,0x5599529d00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b8c3ebab05fbab81ebd434de438e9272fb773612' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 240 processed earlier; will process 10789 files now Step #5: ==8242== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5599474439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55994daa8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55994da8b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55994da8b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559947449d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5599473aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5599473a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55994743bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55994a40af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55994a40af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55994a40af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55994a40af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55994a40af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55994a40af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55994a40af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55994a40af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55994a40af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55994a40af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55994c69ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5599493ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5599493d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559949183c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559949183c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559949184738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559949183874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559949183874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559949183874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55994da8dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55994da96928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55994da7e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55994daa9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f887caad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5599473a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x80,0xab, Step #5: \343\200\253 Step #5: artifact_prefix='./'; Test unit written to ./oom-2d172f92c25d5a7cd15294bc8398d51879ed6689 Step #5: Base64: 44Cr Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 229 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1896774144 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ddd740e810, 0x55ddd75f801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ddd75f8020,0x55ddd94900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2d172f92c25d5a7cd15294bc8398d51879ed6689' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 241 processed earlier; will process 10788 files now Step #5: #1 pulse cov: 3424 ft: 3425 exec/s: 0 rss: 153Mb Step #5: ==8278== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ddcdf039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ddd4568898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ddd454b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ddd454b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ddcdf09d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ddcde6ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ddcde65355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ddcdefbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ddd0ecaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ddd0ecaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ddd0ecaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ddd0ecaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ddd0ecaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ddd0ecaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ddd0ecaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ddd0ecaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ddd0ecaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ddd0ecaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ddd315ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ddcfe8cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ddcfe97be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ddcfc43c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ddcfc43c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ddcfc44738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ddcfc43874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ddcfc43874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ddcfc43874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ddd454dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ddd4556928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ddd453e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ddd4569112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff59009f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ddcde63b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x61,0x6d,0x70, Step #5: amp Step #5: artifact_prefix='./'; Test unit written to ./oom-65f59ec6b1ecd6170d5044474043cca9560a8071 Step #5: Base64: YW1w Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 230 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1897219335 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc8abee810, 0x55fc8add801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc8add8020,0x55fc8cc700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/65f59ec6b1ecd6170d5044474043cca9560a8071' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 243 processed earlier; will process 10786 files now Step #5: ==8314== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fc816e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc87d48898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc87d2b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc87d2b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc816e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc8164ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc81645355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc816dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc846aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc846aaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc846aaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc846aaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc846aaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc846aaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc846aaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc846aaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc846aaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc846aaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc8693ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc8366cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc83677be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc83423c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc83423c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc83424738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc83423874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc83423874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc83423874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc87d2dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc87d36928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc87d1e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc87d49112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f01cb2d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc81643b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x83,0xa7, Step #5: \342\203\247 Step #5: artifact_prefix='./'; Test unit written to ./oom-a881f521cdd2876dfe70f9c9fe3a69063f9c81e8 Step #5: Base64: 4oOn Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 231 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1897628879 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bbc6b9f810, 0x55bbc6d8901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bbc6d89020,0x55bbc8c210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a881f521cdd2876dfe70f9c9fe3a69063f9c81e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 244 processed earlier; will process 10785 files now Step #5: ==8350== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bbbd6949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bbc3cf9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bbc3cdc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bbc3cdc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bbbd69ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bbbd5fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bbbd5f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bbbd68cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bbc065bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bbc065bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bbc065bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bbc065bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bbc065bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bbc065bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bbc065bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bbc065bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bbc065bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bbc065bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bbc28f0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bbbf61db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bbbf628be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bbbf3d4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bbbf3d4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bbbf3d5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bbbf3d4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bbbf3d4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bbbf3d4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bbc3cdeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bbc3ce7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bbc3ccf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bbc3cfa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc398442082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bbbd5f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xed,0x9f,0xb7, Step #5: \355\237\267 Step #5: artifact_prefix='./'; Test unit written to ./oom-94e2b58e98806e5044bc8e0c97a79acfa61be612 Step #5: Base64: 7Z+3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 232 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1898039358 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d20fb2a810, 0x55d20fd1401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d20fd14020,0x55d211bac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/94e2b58e98806e5044bc8e0c97a79acfa61be612' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 245 processed earlier; will process 10784 files now Step #5: ==8386== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d20661f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d20cc84898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d20cc675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d20cc674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d206625d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d206586b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d206581355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d206617c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d2095e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d2095e6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d2095e6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d2095e6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d2095e6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d2095e6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d2095e6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d2095e6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d2095e6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d2095e6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d20b87bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d2085a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d2085b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d20835fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d20835fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d208360738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d20835f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d20835f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d20835f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d20cc69abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d20cc72928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d20cc5a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d20cc85112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fabad621082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d20657fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x55,0x58,0x45, Step #5: UXE Step #5: artifact_prefix='./'; Test unit written to ./oom-b7df275e728fad550e74a5e2b837bb3cf8df4db3 Step #5: Base64: VVhF Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 233 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1898449735 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557aee437810, 0x557aee62101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557aee621020,0x557af04b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7df275e728fad550e74a5e2b837bb3cf8df4db3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 246 processed earlier; will process 10783 files now Step #5: ==8422== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557ae4f2c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557aeb591898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557aeb5745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557aeb5744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557ae4f32d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557ae4e93b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557ae4e8e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557ae4f24c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557ae7ef3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557ae7ef3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557ae7ef3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557ae7ef3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557ae7ef3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557ae7ef3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557ae7ef3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557ae7ef3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557ae7ef3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557ae7ef3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557aea188f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557ae6eb5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557ae6ec0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557ae6c6cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557ae6c6cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557ae6c6d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557ae6c6c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557ae6c6c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557ae6c6c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557aeb576abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557aeb57f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557aeb567699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557aeb592112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f281ebe1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557ae4e8cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xb9, Step #5: \357\273\271 Step #5: artifact_prefix='./'; Test unit written to ./oom-bae05ef8acb4c5cf1f3cf13acba05b10e7699d2a Step #5: Base64: 77u5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 234 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1898861303 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff970f9810, 0x55ff972e301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff972e3020,0x55ff9917b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bae05ef8acb4c5cf1f3cf13acba05b10e7699d2a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 247 processed earlier; will process 10782 files now Step #5: ==8458== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ff8dbee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff94253898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff942365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff942364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff8dbf4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff8db55b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff8db50355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff8dbe6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff90bb5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff90bb5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff90bb5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff90bb5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff90bb5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff90bb5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff90bb5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff90bb5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff90bb5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff90bb5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff92e4af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff8fb77b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff8fb82be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff8f92ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff8f92ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff8f92f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff8f92e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff8f92e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff8f92e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff94238abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff94241928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff94229699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff94254112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f13ac45a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff8db4eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x9f,0xb7, Step #5: \343\237\267 Step #5: artifact_prefix='./'; Test unit written to ./oom-58b492174446c13e8978029fe6732c6e917bf0c0 Step #5: Base64: 45+3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 235 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1899278909 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ffc7d4810, 0x561ffc9be01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ffc9be020,0x561ffe8560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58b492174446c13e8978029fe6732c6e917bf0c0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 248 processed earlier; will process 10781 files now Step #5: ==8494== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561ff32c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561ff992e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561ff99115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561ff99114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561ff32cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561ff3230b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561ff322b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561ff32c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561ff6290f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561ff6290f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561ff6290f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561ff6290f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561ff6290f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561ff6290f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561ff6290f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561ff6290f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561ff6290f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561ff6290f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561ff8525f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561ff5252b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561ff525dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561ff5009c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561ff5009c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561ff500a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561ff5009874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561ff5009874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561ff5009874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561ff9913abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561ff991c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561ff9904699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561ff992f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f755f5f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561ff3229b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x7b,0xf5, Step #5: %{\365 Step #5: artifact_prefix='./'; Test unit written to ./oom-885ff7c160224c06c4fd180930de6ba3bd1b9537 Step #5: Base64: JXv1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 236 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1899685937 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fa1ef4d810, 0x55fa1f13701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fa1f137020,0x55fa20fcf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/885ff7c160224c06c4fd180930de6ba3bd1b9537' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 249 processed earlier; will process 10780 files now Step #5: ==8530== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fa15a429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fa1c0a7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fa1c08a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fa1c08a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fa15a48d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fa159a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fa159a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fa15a3ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fa18a09f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fa18a09f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fa18a09f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fa18a09f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fa18a09f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fa18a09f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fa18a09f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fa18a09f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fa18a09f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fa18a09f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fa1ac9ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fa179cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fa179d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fa17782c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fa17782c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fa17783738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fa17782874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fa17782874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fa17782874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fa1c08cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fa1c095928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fa1c07d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fa1c0a8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f15d4bc7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fa159a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x57,0x3a,0x30, Step #5: W:0 Step #5: artifact_prefix='./'; Test unit written to ./oom-da1ad0f59c055426f1e68c588063c6dbb5197df8 Step #5: Base64: Vzow Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 237 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1900097162 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563643ff4810, 0x5636441de01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5636441de020,0x5636460760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/da1ad0f59c055426f1e68c588063c6dbb5197df8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 250 processed earlier; will process 10779 files now Step #5: ==8566== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56363aae99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56364114e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636411315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636411314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56363aaefd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56363aa50b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56363aa4b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56363aae1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56363dab0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56363dab0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56363dab0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56363dab0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56363dab0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56363dab0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56363dab0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56363dab0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56363dab0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56363dab0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56363fd45f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56363ca72b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56363ca7dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56363c829c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56363c829c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56363c82a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56363c829874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56363c829874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56363c829874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563641133abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56364113c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563641124699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56364114f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f37ef294082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56363aa49b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xea,0x8f,0x8f, Step #5: \352\217\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-cd8ea845bda81369b5f6685d05c78b52345b54a7 Step #5: Base64: 6o+P Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 238 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1900510462 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5584ea3c0810, 0x5584ea5aa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5584ea5aa020,0x5584ec4420e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd8ea845bda81369b5f6685d05c78b52345b54a7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 251 processed earlier; will process 10778 files now Step #5: ==8602== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5584e0eb59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5584e751a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5584e74fd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5584e74fd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5584e0ebbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5584e0e1cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5584e0e17355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5584e0eadc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5584e3e7cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5584e3e7cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5584e3e7cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5584e3e7cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5584e3e7cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5584e3e7cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5584e3e7cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5584e3e7cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5584e3e7cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5584e3e7cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5584e6111f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5584e2e3eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5584e2e49be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5584e2bf5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5584e2bf5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5584e2bf6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5584e2bf5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5584e2bf5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5584e2bf5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5584e74ffabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5584e7508928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5584e74f0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5584e751b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f597eff9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5584e0e15b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x27,0x27, Step #5: ['' Step #5: artifact_prefix='./'; Test unit written to ./oom-e716589d09e16cf4a48d2c7f1d357bb481aaf3bc Step #5: Base64: Wycn Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 239 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1900922862 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562398b36810, 0x562398d2001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562398d20020,0x56239abb80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e716589d09e16cf4a48d2c7f1d357bb481aaf3bc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 252 processed earlier; will process 10777 files now Step #5: ==8638== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56238f62b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562395c90898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562395c735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562395c734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56238f631d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56238f592b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56238f58d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56238f623c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5623925f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5623925f2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5623925f2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5623925f2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5623925f2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5623925f2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5623925f2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5623925f2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5623925f2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5623925f2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562394887f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5623915b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5623915bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56239136bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56239136bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56239136c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56239136b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56239136b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56239136b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562395c75abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562395c7e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562395c66699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562395c91112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f259ae58082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56238f58bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x32, Step #5: FU2 Step #5: artifact_prefix='./'; Test unit written to ./oom-ddc7e267fcd357eb02fd382e8750ae4f3021baf7 Step #5: Base64: RlUy Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 240 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1901328904 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fa233d8810, 0x55fa235c201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fa235c2020,0x55fa2545a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ddc7e267fcd357eb02fd382e8750ae4f3021baf7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 253 processed earlier; will process 10776 files now Step #5: ==8674== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fa19ecd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fa20532898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fa205155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fa205154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fa19ed3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fa19e34b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fa19e2f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fa19ec5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fa1ce94f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fa1ce94f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fa1ce94f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fa1ce94f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fa1ce94f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fa1ce94f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fa1ce94f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fa1ce94f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fa1ce94f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fa1ce94f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fa1f129f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fa1be56b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fa1be61be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fa1bc0dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fa1bc0dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fa1bc0e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fa1bc0d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fa1bc0d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fa1bc0d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fa20517abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fa20520928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fa20508699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fa20533112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0c0d138082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fa19e2db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x66,0x5, Step #5: Pf\005 Step #5: artifact_prefix='./'; Test unit written to ./oom-2aad3da6b35d85334086910a81b67884256cb078 Step #5: Base64: UGYF Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 241 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1901739066 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56505dd73810, 0x56505df5d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56505df5d020,0x56505fdf50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2aad3da6b35d85334086910a81b67884256cb078' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 254 processed earlier; will process 10775 files now Step #5: ==8710== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5650548689c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56505aecd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56505aeb05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56505aeb04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56505486ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5650547cfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5650547ca355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565054860c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56505782ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56505782ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56505782ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56505782ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56505782ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56505782ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56505782ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56505782ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56505782ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56505782ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565059ac4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5650567f1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5650567fcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5650565a8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5650565a8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5650565a9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5650565a8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5650565a8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5650565a8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56505aeb2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56505aebb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56505aea3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56505aece112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc40335a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5650547c8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xee,0x90,0x87, Step #5: \356\220\207 Step #5: artifact_prefix='./'; Test unit written to ./oom-be431467c8f203373bc0916fb07325df6b31ec68 Step #5: Base64: 7pCH Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 242 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1902149431 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55be0aee8810, 0x55be0b0d201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55be0b0d2020,0x55be0cf6a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/be431467c8f203373bc0916fb07325df6b31ec68' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 255 processed earlier; will process 10774 files now Step #5: ==8746== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55be019dd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55be08042898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55be080255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55be080254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55be019e3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55be01944b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55be0193f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55be019d5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55be049a4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55be049a4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55be049a4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55be049a4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55be049a4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55be049a4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55be049a4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55be049a4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55be049a4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55be049a4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55be06c39f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55be03966b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55be03971be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55be0371dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55be0371dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55be0371e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55be0371d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55be0371d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55be0371d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55be08027abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55be08030928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55be08018699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55be08043112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f29acfdc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55be0193db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0xcd,0x84, Step #5: w\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-0cf8f7c55eeb70d9b9415a1667f0c98299e31eed Step #5: Base64: d82E Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 243 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1902558107 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5603c9d8c810, 0x5603c9f7601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5603c9f76020,0x5603cbe0e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0cf8f7c55eeb70d9b9415a1667f0c98299e31eed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 256 processed earlier; will process 10773 files now Step #5: ==8782== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5603c08819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5603c6ee6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5603c6ec95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5603c6ec94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5603c0887d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5603c07e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5603c07e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5603c0879c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5603c3848f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5603c3848f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5603c3848f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5603c3848f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5603c3848f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5603c3848f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5603c3848f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5603c3848f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5603c3848f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5603c3848f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5603c5addf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5603c280ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5603c2815be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5603c25c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5603c25c1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5603c25c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5603c25c1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5603c25c1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5603c25c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5603c6ecbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5603c6ed4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5603c6ebc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5603c6ee7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ff9900082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5603c07e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x25,0x60, Step #5: `%` Step #5: artifact_prefix='./'; Test unit written to ./oom-128cc5fd032db964245830c5c3cba5e0cb754e00 Step #5: Base64: YCVg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 244 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1903088552 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ad6fa41810, 0x55ad6fc2b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ad6fc2b020,0x55ad71ac30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/128cc5fd032db964245830c5c3cba5e0cb754e00' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 257 processed earlier; will process 10772 files now Step #5: ==8818== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ad665369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ad6cb9b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ad6cb7e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ad6cb7e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ad6653cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ad6649db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ad66498355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ad6652ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ad694fdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ad694fdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ad694fdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ad694fdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ad694fdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ad694fdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ad694fdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ad694fdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ad694fdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ad694fdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ad6b792f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ad684bfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ad684cabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ad68276c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ad68276c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ad68277738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ad68276874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ad68276874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ad68276874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ad6cb80abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ad6cb89928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ad6cb71699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ad6cb9c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6019304082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ad66496b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x2e,0x2e, Step #5: {.. Step #5: artifact_prefix='./'; Test unit written to ./oom-983ef74b7822393aa9b8661d8c0114dd3aa81716 Step #5: Base64: ey4u Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 245 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1903496743 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9eb166810, 0x55a9eb35001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a9eb350020,0x55a9ed1e80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/983ef74b7822393aa9b8661d8c0114dd3aa81716' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 258 processed earlier; will process 10771 files now Step #5: ==8854== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a9e1c5b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a9e82c0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9e82a35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9e82a34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a9e1c61d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a9e1bc2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a9e1bbd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a9e1c53c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9e4c22f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9e4c22f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9e4c22f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9e4c22f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9e4c22f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9e4c22f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9e4c22f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9e4c22f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9e4c22f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9e4c22f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a9e6eb7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a9e3be4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a9e3befbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a9e399bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a9e399bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a9e399c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a9e399b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a9e399b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a9e399b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a9e82a5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a9e82ae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a9e8296699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a9e82c1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f514e8cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a9e1bbbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xa,0x2d, Step #5: =\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-88b77a488ff1fb97222c25ca6ef57742c602ccc1 Step #5: Base64: PQot Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 246 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1903907510 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5573e2037810, 0x5573e222101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5573e2221020,0x5573e40b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88b77a488ff1fb97222c25ca6ef57742c602ccc1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 259 processed earlier; will process 10770 files now Step #5: ==8890== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5573d8b2c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5573df191898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5573df1745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5573df1744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5573d8b32d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5573d8a93b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5573d8a8e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5573d8b24c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5573dbaf3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5573dbaf3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5573dbaf3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5573dbaf3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5573dbaf3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5573dbaf3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5573dbaf3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5573dbaf3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5573dbaf3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5573dbaf3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5573ddd88f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5573daab5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5573daac0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5573da86cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5573da86cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5573da86d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5573da86c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5573da86c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5573da86c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5573df176abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5573df17f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5573df167699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5573df192112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f534c6dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5573d8a8cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xac,0x9e, Step #5: \357\254\236 Step #5: artifact_prefix='./'; Test unit written to ./oom-26243bce85d536c665ddf7737f240db639fac4df Step #5: Base64: 76ye Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 247 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1904318002 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c5a54c2810, 0x55c5a56ac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c5a56ac020,0x55c5a75440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/26243bce85d536c665ddf7737f240db639fac4df' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 260 processed earlier; will process 10769 files now Step #5: ==8926== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c59bfb79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c5a261c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c5a25ff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c5a25ff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c59bfbdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c59bf1eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c59bf19355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c59bfafc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c59ef7ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c59ef7ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c59ef7ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c59ef7ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c59ef7ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c59ef7ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c59ef7ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c59ef7ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c59ef7ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c59ef7ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c5a1213f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c59df40b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c59df4bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c59dcf7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c59dcf7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c59dcf8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c59dcf7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c59dcf7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c59dcf7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c5a2601abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c5a260a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c5a25f2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c5a261d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f73fe727082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c59bf17b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x8,0x3d, Step #5: \003\010= Step #5: artifact_prefix='./'; Test unit written to ./oom-b83431aa86105e70e76f009146611941846672b3 Step #5: Base64: Awg9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 248 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1904729947 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55da36896810, 0x55da36a8001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55da36a80020,0x55da389180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b83431aa86105e70e76f009146611941846672b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 261 processed earlier; will process 10768 files now Step #5: ==8962== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55da2d38b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55da339f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55da339d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55da339d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55da2d391d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55da2d2f2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55da2d2ed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55da2d383c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55da30352f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55da30352f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55da30352f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55da30352f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55da30352f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55da30352f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55da30352f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55da30352f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55da30352f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55da30352f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55da325e7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55da2f314b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55da2f31fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55da2f0cbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55da2f0cbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55da2f0cc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55da2f0cb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55da2f0cb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55da2f0cb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55da339d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55da339de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55da339c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55da339f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa50cf0b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55da2d2ebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x59,0x26,0x2d, Step #5: Y&- Step #5: artifact_prefix='./'; Test unit written to ./oom-03c4a0e59f4a379ee81fec35d405c363719484fc Step #5: Base64: WSYt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 249 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1905139299 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b9531e5810, 0x55b9533cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b9533cf020,0x55b9552670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03c4a0e59f4a379ee81fec35d405c363719484fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 262 processed earlier; will process 10767 files now Step #5: ==8998== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b949cda9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b95033f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b9503225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b9503224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b949ce0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b949c41b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b949c3c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b949cd2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b94cca1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b94cca1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b94cca1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b94cca1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b94cca1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b94cca1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b94cca1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b94cca1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b94cca1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b94cca1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b94ef36f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b94bc63b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b94bc6ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b94ba1ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b94ba1ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b94ba1b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b94ba1a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b94ba1a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b94ba1a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b950324abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b95032d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b950315699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b950340112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff5121f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b949c3ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x3a,0x7e, Step #5: \000:~ Step #5: artifact_prefix='./'; Test unit written to ./oom-910598e4bc3ad9fa7ff06aff5ddf249c274a34e6 Step #5: Base64: ADp+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 250 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1905544943 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc89704810, 0x55fc898ee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc898ee020,0x55fc8b7860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/910598e4bc3ad9fa7ff06aff5ddf249c274a34e6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 263 processed earlier; will process 10766 files now Step #5: ==9034== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fc801f99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc8685e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc868415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc868414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc801ffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc80160b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc8015b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc801f1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc831c0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc831c0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc831c0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc831c0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc831c0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc831c0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc831c0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc831c0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc831c0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc831c0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc85455f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc82182b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc8218dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc81f39c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc81f39c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc81f3a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc81f39874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc81f39874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc81f39874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc86843abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc8684c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc86834699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc8685f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3daee55082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc80159b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xd,0x2d, Step #5: -\015- Step #5: artifact_prefix='./'; Test unit written to ./oom-b3560ebf65b4aa2457eecd175082cd0d67b5e9ed Step #5: Base64: LQ0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 251 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1905954393 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d936998810, 0x55d936b8201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d936b82020,0x55d938a1a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3560ebf65b4aa2457eecd175082cd0d67b5e9ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 264 processed earlier; will process 10765 files now Step #5: ==9070== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d92d48d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d933af2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d933ad55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d933ad54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d92d493d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d92d3f4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d92d3ef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d92d485c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d930454f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d930454f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d930454f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d930454f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d930454f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d930454f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d930454f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d930454f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d930454f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d930454f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d9326e9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d92f416b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d92f421be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d92f1cdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d92f1cdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d92f1ce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d92f1cd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d92f1cd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d92f1cd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d933ad7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d933ae0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d933ac8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d933af3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d4c7d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d92d3edb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x52,0x45,0x58, Step #5: REX Step #5: artifact_prefix='./'; Test unit written to ./oom-b4cd47e3a08f966997dfaa92482c8b1977772ad8 Step #5: Base64: UkVY Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 252 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1906362330 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f008fc0810, 0x55f0091aa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f0091aa020,0x55f00b0420e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b4cd47e3a08f966997dfaa92482c8b1977772ad8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 265 processed earlier; will process 10764 files now Step #5: ==9106== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55efffab59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f00611a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f0060fd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f0060fd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55efffabbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55efffa1cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55efffa17355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55efffaadc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f002a7cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f002a7cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f002a7cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f002a7cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f002a7cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f002a7cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f002a7cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f002a7cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f002a7cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f002a7cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f004d11f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f001a3eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f001a49be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f0017f5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f0017f5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f0017f6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f0017f5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f0017f5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f0017f5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f0060ffabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f006108928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f0060f0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f00611b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0f933af082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55efffa15b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x37,0x2c,0x38, Step #5: 7,8 Step #5: artifact_prefix='./'; Test unit written to ./oom-845a834068a059432c13383f36222f98efad9747 Step #5: Base64: Nyw4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 253 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1906774565 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c5087b810, 0x561c50a6501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c50a65020,0x561c528fd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/845a834068a059432c13383f36222f98efad9747' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 266 processed earlier; will process 10763 files now Step #5: ==9142== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561c473709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c4d9d5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c4d9b85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c4d9b84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c47376d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c472d7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c472d2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c47368c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c4a337f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c4a337f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c4a337f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c4a337f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c4a337f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c4a337f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c4a337f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c4a337f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c4a337f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c4a337f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c4c5ccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c492f9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c49304be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c490b0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c490b0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c490b1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c490b0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c490b0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c490b0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c4d9baabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c4d9c3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c4d9ab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c4d9d6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f48356db082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c472d0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd9,0x8e,0x1f, Step #5: \331\216\037 Step #5: artifact_prefix='./'; Test unit written to ./oom-aa50618f35519acfb1726dacc4714114ec69361f Step #5: Base64: 2Y4f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 254 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1907178363 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558384f7a810, 0x55838516401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558385164020,0x558386ffc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aa50618f35519acfb1726dacc4714114ec69361f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 267 processed earlier; will process 10762 files now Step #5: ==9178== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55837ba6f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5583820d4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583820b75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583820b74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55837ba75d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55837b9d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55837b9d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55837ba67c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55837ea36f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55837ea36f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55837ea36f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55837ea36f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55837ea36f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55837ea36f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55837ea36f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55837ea36f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55837ea36f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55837ea36f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558380ccbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55837d9f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55837da03be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55837d7afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55837d7afc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55837d7b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55837d7af874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55837d7af874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55837d7af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5583820b9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5583820c2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5583820aa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5583820d5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7ac8d7f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55837b9cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x4a,0x0, Step #5: tJ\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-29096adb754e6f339e426342d0d0604ff7570a41 Step #5: Base64: dEoA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 255 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1907587179 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559f5db7a810, 0x559f5dd6401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559f5dd64020,0x559f5fbfc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/29096adb754e6f339e426342d0d0604ff7570a41' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 268 processed earlier; will process 10761 files now Step #5: ==9214== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559f5466f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559f5acd4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559f5acb75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559f5acb74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559f54675d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559f545d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559f545d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559f54667c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559f57636f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559f57636f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559f57636f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559f57636f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559f57636f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559f57636f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559f57636f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559f57636f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559f57636f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559f57636f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559f598cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559f565f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559f56603be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559f563afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559f563afc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559f563b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559f563af874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559f563af874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559f563af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559f5acb9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559f5acc2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559f5acaa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559f5acd5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ba5d0e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559f545cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xb1,0x82, Step #5: \341\261\202 Step #5: artifact_prefix='./'; Test unit written to ./oom-014fb59c67bc931072a451efb8858955a6c39219 Step #5: Base64: 4bGC Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 256 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1908000021 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ac3501f810, 0x55ac3520901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ac35209020,0x55ac370a10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/014fb59c67bc931072a451efb8858955a6c39219' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 269 processed earlier; will process 10760 files now Step #5: ==9250== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ac2bb149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ac32179898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ac3215c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ac3215c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ac2bb1ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ac2ba7bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ac2ba76355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ac2bb0cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ac2eadbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ac2eadbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ac2eadbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ac2eadbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ac2eadbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ac2eadbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ac2eadbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ac2eadbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ac2eadbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ac2eadbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ac30d70f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ac2da9db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ac2daa8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ac2d854c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ac2d854c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ac2d855738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ac2d854874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ac2d854874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ac2d854874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ac3215eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ac32167928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ac3214f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ac3217a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1b91dfd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ac2ba74b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53,0x3a,0x21, Step #5: S:! Step #5: artifact_prefix='./'; Test unit written to ./oom-c651fdc7ad1ade44871da1e83871b5e93e3a14bf Step #5: Base64: Uzoh Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 257 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1908410656 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c89236810, 0x562c8942001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c89420020,0x562c8b2b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c651fdc7ad1ade44871da1e83871b5e93e3a14bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 270 processed earlier; will process 10759 files now Step #5: ==9286== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562c7fd2b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c86390898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c863735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c863734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c7fd31d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c7fc92b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c7fc8d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c7fd23c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c82cf2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c82cf2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c82cf2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c82cf2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c82cf2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c82cf2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c82cf2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c82cf2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c82cf2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c82cf2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c84f87f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562c81cb4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562c81cbfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562c81a6bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562c81a6bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562c81a6c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562c81a6b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562c81a6b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562c81a6b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c86375abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c8637e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c86366699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c86391112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9b62769082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c7fc8bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x59,0x5d, Step #5: [Y] Step #5: artifact_prefix='./'; Test unit written to ./oom-87628f313c8f8d100d347e013cfdbbf10dbe3c6e Step #5: Base64: W1ld Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 258 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1908817412 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f0848d4810, 0x55f084abe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f084abe020,0x55f0869560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87628f313c8f8d100d347e013cfdbbf10dbe3c6e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 271 processed earlier; will process 10758 files now Step #5: ==9322== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f07b3c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f081a2e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f081a115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f081a114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f07b3cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f07b330b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f07b32b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f07b3c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f07e390f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f07e390f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f07e390f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f07e390f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f07e390f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f07e390f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f07e390f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f07e390f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f07e390f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f07e390f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f080625f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f07d352b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f07d35dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f07d109c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f07d109c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f07d10a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f07d109874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f07d109874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f07d109874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f081a13abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f081a1c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f081a04699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f081a2f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5afa7c9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f07b329b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x20,0x22, Step #5: \" \" Step #5: artifact_prefix='./'; Test unit written to ./oom-654e0aaee80e38636c503629d32225db31a616de Step #5: Base64: IiAi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 259 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1909230665 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562da5d76810, 0x562da5f6001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562da5f60020,0x562da7df80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/654e0aaee80e38636c503629d32225db31a616de' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 272 processed earlier; will process 10757 files now Step #5: #1 pulse cov: 3381 ft: 3382 exec/s: 0 rss: 154Mb Step #5: ==9358== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562d9c86b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562da2ed0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562da2eb35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562da2eb34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d9c871d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d9c7d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d9c7cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d9c863c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d9f832f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d9f832f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d9f832f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d9f832f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d9f832f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d9f832f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d9f832f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d9f832f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d9f832f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d9f832f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562da1ac7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d9e7f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d9e7ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d9e5abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d9e5abc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d9e5ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d9e5ab874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d9e5ab874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d9e5ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562da2eb5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562da2ebe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562da2ea6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562da2ed1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb4dd9e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d9c7cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x52,0x6d, Step #5: fRm Step #5: artifact_prefix='./'; Test unit written to ./oom-ae9fb5f8d32ba152bbf78d0a71c61daf023d2117 Step #5: Base64: ZlJt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 260 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1909684876 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f4c575e810, 0x55f4c594801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f4c5948020,0x55f4c77e00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ae9fb5f8d32ba152bbf78d0a71c61daf023d2117' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 274 processed earlier; will process 10755 files now Step #5: ==9394== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f4bc2539c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f4c28b8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f4c289b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f4c289b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f4bc259d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f4bc1bab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f4bc1b5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f4bc24bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f4bf21af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f4bf21af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f4bf21af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f4bf21af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f4bf21af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f4bf21af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f4bf21af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f4bf21af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f4bf21af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f4bf21af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4c14aff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4be1dcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4be1e7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f4bdf93c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f4bdf93c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f4bdf94738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f4bdf93874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f4bdf93874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f4bdf93874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f4c289dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f4c28a6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f4c288e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f4c28b9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f65aa06f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f4bc1b3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x13,0x13,0x14, Step #5: \023\023\024 Step #5: artifact_prefix='./'; Test unit written to ./oom-60a78cfb6c88b107c2ffbdfad6f5e0658c3f9b66 Step #5: Base64: ExMU Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 261 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1910094820 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56506c1cf810, 0x56506c3b901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56506c3b9020,0x56506e2510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/60a78cfb6c88b107c2ffbdfad6f5e0658c3f9b66' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 275 processed earlier; will process 10754 files now Step #5: ==9430== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x565062cc49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565069329898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56506930c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56506930c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565062ccad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565062c2bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565062c26355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565062cbcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565065c8bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565065c8bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565065c8bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565065c8bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565065c8bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565065c8bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565065c8bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565065c8bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565065c8bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565065c8bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565067f20f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565064c4db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565064c58be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565064a04c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565064a04c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565064a05738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565064a04874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565064a04874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565064a04874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56506930eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565069317928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5650692ff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56506932a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe3a1124082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565062c24b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x54,0x48,0x2e, Step #5: TH. Step #5: artifact_prefix='./'; Test unit written to ./oom-721fd69df9ac77c28cc3d99a4856d6e521fabe96 Step #5: Base64: VEgu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 262 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1910500560 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5653c04df810, 0x5653c06c901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5653c06c9020,0x5653c25610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/721fd69df9ac77c28cc3d99a4856d6e521fabe96' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 276 processed earlier; will process 10753 files now Step #5: ==9466== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5653b6fd49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5653bd639898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5653bd61c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5653bd61c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5653b6fdad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5653b6f3bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5653b6f36355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5653b6fccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5653b9f9bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5653b9f9bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5653b9f9bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5653b9f9bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5653b9f9bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5653b9f9bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5653b9f9bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5653b9f9bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5653b9f9bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5653b9f9bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5653bc230f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5653b8f5db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5653b8f68be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5653b8d14c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5653b8d14c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5653b8d15738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5653b8d14874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5653b8d14874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5653b8d14874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5653bd61eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5653bd627928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5653bd60f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5653bd63a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9088bfb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5653b6f34b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xd,0x3a, Step #5: -\015: Step #5: artifact_prefix='./'; Test unit written to ./oom-dbbf6d535afdaa63e1f44b5b88aebcfa108b6dd4 Step #5: Base64: LQ06 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 263 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1910911341 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b560ba6810, 0x55b560d9001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b560d90020,0x55b562c280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dbbf6d535afdaa63e1f44b5b88aebcfa108b6dd4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 277 processed earlier; will process 10752 files now Step #5: ==9502== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b55769b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b55dd00898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b55dce35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b55dce34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b5576a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b557602b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b5575fd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b557693c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b55a662f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b55a662f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b55a662f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b55a662f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b55a662f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b55a662f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b55a662f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b55a662f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b55a662f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b55a662f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b55c8f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b559624b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b55962fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b5593dbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b5593dbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b5593dc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b5593db874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b5593db874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b5593db874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b55dce5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b55dcee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b55dcd6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b55dd01112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f94447b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b5575fbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0xa, Step #5: //\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-8d06436c33a3086259f2f1ccaf03425707eeff17 Step #5: Base64: Ly8K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 264 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1911309201 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565194c20810, 0x565194e0a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565194e0a020,0x565196ca20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d06436c33a3086259f2f1ccaf03425707eeff17' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 278 processed earlier; will process 10751 files now Step #5: #1 pulse cov: 3476 ft: 3477 exec/s: 0 rss: 153Mb Step #5: ==9538== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56518b7159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565191d7a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565191d5d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565191d5d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56518b71bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56518b67cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56518b677355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56518b70dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56518e6dcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56518e6dcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56518e6dcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56518e6dcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56518e6dcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56518e6dcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56518e6dcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56518e6dcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56518e6dcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56518e6dcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565190971f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56518d69eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56518d6a9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56518d455c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56518d455c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56518d456738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56518d455874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56518d455874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56518d455874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565191d5fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565191d68928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565191d50699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565191d7b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b8128a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56518b675b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbf,0xbf, Step #5: \357\277\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-c6d9a44d71abe180a4025ae4005313e09b917437 Step #5: Base64: 77+/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 265 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1911757936 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ccd11a0810, 0x55ccd138a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ccd138a020,0x55ccd32220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c6d9a44d71abe180a4025ae4005313e09b917437' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 280 processed earlier; will process 10749 files now Step #5: #1 pulse cov: 3486 ft: 3487 exec/s: 0 rss: 152Mb Step #5: ==9574== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ccc7c959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ccce2fa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ccce2dd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ccce2dd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ccc7c9bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ccc7bfcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ccc7bf7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ccc7c8dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cccac5cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cccac5cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cccac5cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cccac5cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cccac5cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cccac5cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cccac5cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cccac5cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cccac5cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cccac5cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ccccef1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ccc9c1eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ccc9c29be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ccc99d5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ccc99d5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ccc99d6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ccc99d5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ccc99d5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ccc99d5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ccce2dfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ccce2e8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ccce2d0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ccce2fb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f628c0e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ccc7bf5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x3f, Step #5: Step #5: Step #5: #0 0x55ecf360f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ecf9c74898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ecf9c575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ecf9c574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ecf3615d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ecf3576b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ecf3571355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ecf3607c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ecf65d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ecf65d6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ecf65d6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ecf65d6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ecf65d6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ecf65d6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ecf65d6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ecf65d6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ecf65d6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ecf65d6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ecf886bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ecf5598b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ecf55a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ecf534fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ecf534fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ecf5350738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ecf534f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ecf534f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ecf534f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ecf9c59abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ecf9c62928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ecf9c4a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ecf9c75112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f685a705082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ecf356fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x4f,0x4e, Step #5: 'ON Step #5: artifact_prefix='./'; Test unit written to ./oom-21125a762c34b9a216fb309203388a95ff0c0c73 Step #5: Base64: J09O Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 267 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1912626061 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aca0653810, 0x55aca083d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aca083d020,0x55aca26d50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/21125a762c34b9a216fb309203388a95ff0c0c73' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 283 processed earlier; will process 10746 files now Step #5: ==9646== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ac971489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ac9d7ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ac9d7905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ac9d7904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ac9714ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ac970afb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ac970aa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ac97140c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ac9a10ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ac9a10ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ac9a10ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ac9a10ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ac9a10ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ac9a10ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ac9a10ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ac9a10ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ac9a10ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ac9a10ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ac9c3a4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ac990d1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ac990dcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ac98e88c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ac98e88c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ac98e89738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ac98e88874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ac98e88874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ac98e88874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ac9d792abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ac9d79b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ac9d783699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ac9d7ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff81249d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ac970a8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa5,0xa2, Step #5: \341\245\242 Step #5: artifact_prefix='./'; Test unit written to ./oom-d6a1839e3313db98fc7a4f71fccc548fc66ee93d Step #5: Base64: 4aWi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 268 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1913038347 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558d9e55d810, 0x558d9e74701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558d9e747020,0x558da05df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d6a1839e3313db98fc7a4f71fccc548fc66ee93d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 284 processed earlier; will process 10745 files now Step #5: ==9682== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558d950529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558d9b6b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558d9b69a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558d9b69a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558d95058d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558d94fb9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558d94fb4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558d9504ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558d98019f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558d98019f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558d98019f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558d98019f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558d98019f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558d98019f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558d98019f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558d98019f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558d98019f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558d98019f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558d9a2aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558d96fdbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558d96fe6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558d96d92c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558d96d92c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558d96d93738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558d96d92874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558d96d92874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558d96d92874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558d9b69cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558d9b6a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558d9b68d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558d9b6b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2bffa3f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558d94fb2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x7d,0x5e, Step #5: }}^ Step #5: artifact_prefix='./'; Test unit written to ./oom-4b4de95694e3b798f6261e362cc4f0ca43968f25 Step #5: Base64: fX1e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 269 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1913447904 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55562713e810, 0x55562732801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555627328020,0x5556291c00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4b4de95694e3b798f6261e362cc4f0ca43968f25' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 285 processed earlier; will process 10744 files now Step #5: ==9718== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55561dc339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555624298898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55562427b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55562427b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55561dc39d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55561db9ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55561db95355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55561dc2bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555620bfaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555620bfaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555620bfaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555620bfaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555620bfaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555620bfaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555620bfaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555620bfaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555620bfaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555620bfaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555622e8ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55561fbbcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55561fbc7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55561f973c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55561f973c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55561f974738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55561f973874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55561f973874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55561f973874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55562427dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555624286928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55562426e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555624299112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe93bd0a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55561db93b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbe,0x80, Step #5: \357\276\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-e44b211526fd04d50cea9df7b509bf14f4293aac Step #5: Base64: 776A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 270 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1913860378 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cf4c629810, 0x55cf4c81301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cf4c813020,0x55cf4e6ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e44b211526fd04d50cea9df7b509bf14f4293aac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 286 processed earlier; will process 10743 files now Step #5: ==9754== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cf4311e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cf49783898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cf497665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cf497664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cf43124d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cf43085b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cf43080355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cf43116c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cf460e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cf460e5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cf460e5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cf460e5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cf460e5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cf460e5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cf460e5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cf460e5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cf460e5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cf460e5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cf4837af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cf450a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cf450b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cf44e5ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cf44e5ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cf44e5f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cf44e5e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cf44e5e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cf44e5e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cf49768abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cf49771928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cf49759699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cf49784112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3d4f941082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cf4307eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33,0xcb,0xb5, Step #5: 3\313\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-450095ae312677fa0c735f0bb9bd5043c12a0ebc Step #5: Base64: M8u1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 271 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1914276582 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c396e95810, 0x55c39707f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c39707f020,0x55c398f170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/450095ae312677fa0c735f0bb9bd5043c12a0ebc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 287 processed earlier; will process 10742 files now Step #5: ==9790== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c38d98a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c393fef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c393fd25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c393fd24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c38d990d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c38d8f1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c38d8ec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c38d982c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c390951f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c390951f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c390951f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c390951f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c390951f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c390951f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c390951f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c390951f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c390951f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c390951f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c392be6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c38f913b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c38f91ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c38f6cac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c38f6cac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c38f6cb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c38f6ca874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c38f6ca874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c38f6ca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c393fd4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c393fdd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c393fc5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c393ff0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f96e0b90082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c38d8eab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0xde,0xaa, Step #5: \005\336\252 Step #5: artifact_prefix='./'; Test unit written to ./oom-f5c163b24e377b4190904dd3476e1889e839f90f Step #5: Base64: Bd6q Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 272 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1914692522 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a469058810, 0x55a46924201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a469242020,0x55a46b0da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f5c163b24e377b4190904dd3476e1889e839f90f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 288 processed earlier; will process 10741 files now Step #5: #1 pulse cov: 10292 ft: 10293 exec/s: 0 rss: 173Mb Step #5: ==9826== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a45fb4d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a4661b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a4661955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a4661954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a45fb53d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a45fab4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a45faaf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a45fb45c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a462b14f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a462b14f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a462b14f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a462b14f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a462b14f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a462b14f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a462b14f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a462b14f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a462b14f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a462b14f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a464da9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a461ad6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a461ae1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a46188dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a46188dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a46188e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a46188d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a46188d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a46188d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a466197abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a4661a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a466188699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a4661b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f32519d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a45faadb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x54,0x63, Step #5: ITc Step #5: artifact_prefix='./'; Test unit written to ./oom-307fbbdf3a4afa9be3b4cd1773c2e7d751d3e5dd Step #5: Base64: SVRj Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 273 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1915168833 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56426b7f1810, 0x56426b9db01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56426b9db020,0x56426d8730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/307fbbdf3a4afa9be3b4cd1773c2e7d751d3e5dd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 290 processed earlier; will process 10739 files now Step #5: ==9862== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5642622e69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56426894b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56426892e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56426892e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642622ecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56426224db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564262248355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5642622dec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5642652adf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5642652adf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5642652adf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5642652adf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5642652adf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5642652adf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5642652adf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5642652adf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5642652adf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5642652adf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564267542f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56426426fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56426427abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564264026c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564264026c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564264027738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564264026874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564264026874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564264026874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564268930abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564268939928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564268921699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56426894c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f199fa8e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564262246b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x21,0x7b, Step #5: #!{ Step #5: artifact_prefix='./'; Test unit written to ./oom-15e5550f706e26a363ecd990d6d087b8e378f744 Step #5: Base64: IyF7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 274 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1915570140 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a4e026810, 0x563a4e21001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a4e210020,0x563a500a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/15e5550f706e26a363ecd990d6d087b8e378f744' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 291 processed earlier; will process 10738 files now Step #5: ==9898== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563a44b1b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a4b180898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a4b1635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a4b1634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a44b21d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a44a82b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a44a7d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a44b13c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a47ae2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a47ae2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a47ae2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a47ae2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a47ae2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a47ae2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a47ae2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a47ae2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a47ae2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a47ae2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a49d77f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a46aa4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a46aafbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a4685bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a4685bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a4685c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a4685b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a4685b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a4685b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a4b165abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a4b16e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a4b156699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a4b181112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8856c97082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a44a7bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x70,0x3a, Step #5: fp: Step #5: artifact_prefix='./'; Test unit written to ./oom-aeee7c618c783f8fc5b800cce25ee1ed53a4543a Step #5: Base64: ZnA6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 275 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1915982674 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555be7442810, 0x555be762c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555be762c020,0x555be94c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aeee7c618c783f8fc5b800cce25ee1ed53a4543a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 292 processed earlier; will process 10737 files now Step #5: ==9934== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555bddf379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555be459c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555be457f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555be457f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555bddf3dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555bdde9eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555bdde99355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555bddf2fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555be0efef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555be0efef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555be0efef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555be0efef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555be0efef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555be0efef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555be0efef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555be0efef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555be0efef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555be0efef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555be3193f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555bdfec0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555bdfecbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555bdfc77c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555bdfc77c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555bdfc78738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555bdfc77874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555bdfc77874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555bdfc77874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555be4581abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555be458a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555be4572699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555be459d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f769aad7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555bdde97b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x36,0x55,0x25, Step #5: 6U% Step #5: artifact_prefix='./'; Test unit written to ./oom-e836e0bd01062e68b0447f18293422d952d1fc3c Step #5: Base64: NlUl Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 276 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1916396487 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559cc451a810, 0x559cc470401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559cc4704020,0x559cc659c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e836e0bd01062e68b0447f18293422d952d1fc3c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 293 processed earlier; will process 10736 files now Step #5: ==9970== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559cbb00f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559cc1674898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559cc16575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559cc16574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559cbb015d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559cbaf76b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559cbaf71355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559cbb007c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559cbdfd6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559cbdfd6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559cbdfd6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559cbdfd6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559cbdfd6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559cbdfd6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559cbdfd6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559cbdfd6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559cbdfd6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559cbdfd6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559cc026bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559cbcf98b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559cbcfa3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559cbcd4fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559cbcd4fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559cbcd50738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559cbcd4f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559cbcd4f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559cbcd4f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559cc1659abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559cc1662928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559cc164a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559cc1675112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f250889c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559cbaf6fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3c,0x3e, Step #5: <<> Step #5: artifact_prefix='./'; Test unit written to ./oom-689c73cca4e112aa400be7e5a509c6fa4e1afcd4 Step #5: Base64: PDw+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 277 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1916814749 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f910e24810, 0x55f91100e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f91100e020,0x55f912ea60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/689c73cca4e112aa400be7e5a509c6fa4e1afcd4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 294 processed earlier; will process 10735 files now Step #5: ==10006== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f9079199c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f90df7e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f90df615dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f90df614fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f90791fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f907880b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f90787b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f907911c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f90a8e0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f90a8e0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f90a8e0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f90a8e0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f90a8e0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f90a8e0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f90a8e0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f90a8e0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f90a8e0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f90a8e0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f90cb75f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f9098a2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f9098adbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f909659c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f909659c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f90965a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f909659874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f909659874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f909659874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f90df63abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f90df6c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f90df54699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f90df7f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d623da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f907879b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x80,0xa9, Step #5: \342\200\251 Step #5: artifact_prefix='./'; Test unit written to ./oom-bad6b315542d2df789cbd9089d3df8b8b287ab49 Step #5: Base64: 4oCp Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 278 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1917219082 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f109b99810, 0x55f109d8301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f109d83020,0x55f10bc1b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bad6b315542d2df789cbd9089d3df8b8b287ab49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 295 processed earlier; will process 10734 files now Step #5: ==10042== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f10068e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f106cf3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f106cd65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f106cd64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f100694d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f1005f5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f1005f0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f100686c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f103655f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f103655f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f103655f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f103655f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f103655f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f103655f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f103655f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f103655f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f103655f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f103655f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f1058eaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f102617b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f102622be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f1023cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f1023cec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f1023cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f1023ce874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f1023ce874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f1023ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f106cd8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f106ce1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f106cc9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f106cf4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa801ebe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f1005eeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x70,0x3b, Step #5: %p; Step #5: artifact_prefix='./'; Test unit written to ./oom-525215b60d735fcb7bb526d0985b5e6e010354e4 Step #5: Base64: JXA7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 279 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1917631687 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558cdc416810, 0x558cdc60001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558cdc600020,0x558cde4980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/525215b60d735fcb7bb526d0985b5e6e010354e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 296 processed earlier; will process 10733 files now Step #5: ==10078== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558cd2f0b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558cd9570898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558cd95535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558cd95534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558cd2f11d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558cd2e72b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558cd2e6d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558cd2f03c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558cd5ed2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558cd5ed2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558cd5ed2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558cd5ed2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558cd5ed2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558cd5ed2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558cd5ed2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558cd5ed2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558cd5ed2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558cd5ed2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558cd8167f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558cd4e94b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558cd4e9fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558cd4c4bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558cd4c4bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558cd4c4c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558cd4c4b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558cd4c4b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558cd4c4b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558cd9555abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558cd955e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558cd9546699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558cd9571112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7eff4f840082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558cd2e6bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x79,0x3a,0x3e, Step #5: y:> Step #5: artifact_prefix='./'; Test unit written to ./oom-0c70e5946bc0ce1bc4cf2be9326898dd812a2f00 Step #5: Base64: eTo+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 280 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1918043874 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555edffca810, 0x555ee01b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ee01b4020,0x555ee204c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0c70e5946bc0ce1bc4cf2be9326898dd812a2f00' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 297 processed earlier; will process 10732 files now Step #5: ==10114== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555ed6abf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555edd124898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555edd1075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555edd1074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ed6ac5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ed6a26b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ed6a21355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ed6ab7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ed9a86f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ed9a86f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ed9a86f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ed9a86f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ed9a86f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ed9a86f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ed9a86f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ed9a86f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ed9a86f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ed9a86f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555edbd1bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ed8a48b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ed8a53be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ed87ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ed87ffc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ed8800738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ed87ff874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ed87ff874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ed87ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555edd109abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555edd112928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555edd0fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555edd125112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f94a7284082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ed6a1fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x16,0x3d, Step #5: I\026= Step #5: artifact_prefix='./'; Test unit written to ./oom-ad1f9e962ff2c5ca5066f735ff9bbf8abef24d5a Step #5: Base64: SRY9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 281 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1918456786 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f34e8cc810, 0x55f34eab601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f34eab6020,0x55f35094e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad1f9e962ff2c5ca5066f735ff9bbf8abef24d5a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 298 processed earlier; will process 10731 files now Step #5: ==10150== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f3453c19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f34ba26898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f34ba095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f34ba094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f3453c7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f345328b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f345323355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f3453b9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f348388f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f348388f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f348388f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f348388f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f348388f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f348388f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f348388f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f348388f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f348388f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f348388f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f34a61df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f34734ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f347355be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f347101c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f347101c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f347102738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f347101874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f347101874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f347101874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f34ba0babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f34ba14928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f34b9fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f34ba27112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbbceba0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f345321b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbf,0xbd, Step #5: \357\277\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-9bdb77276c1852e1fb067820472812fcf6084024 Step #5: Base64: 77+9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 282 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1918868165 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557453a0e810, 0x557453bf801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557453bf8020,0x557455a900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9bdb77276c1852e1fb067820472812fcf6084024' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 299 processed earlier; will process 10730 files now Step #5: ==10186== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55744a5039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557450b68898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557450b4b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557450b4b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55744a509d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55744a46ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55744a465355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55744a4fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55744d4caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55744d4caf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55744d4caf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55744d4caf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55744d4caf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55744d4caf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55744d4caf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55744d4caf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55744d4caf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55744d4caf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55744f75ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55744c48cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55744c497be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55744c243c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55744c243c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55744c244738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55744c243874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55744c243874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55744c243874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557450b4dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557450b56928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557450b3e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557450b69112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f371b5cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55744a463b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbf,0x88, Step #5: \357\277\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-a59b89ed9e83d711df11a0a3e5ce9cde95127f8e Step #5: Base64: 77+I Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 283 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1919288378 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55674d5d9810, 0x55674d7c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55674d7c3020,0x55674f65b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a59b89ed9e83d711df11a0a3e5ce9cde95127f8e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 300 processed earlier; will process 10729 files now Step #5: ==10222== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5567440ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55674a733898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55674a7165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55674a7164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5567440d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556744035b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556744030355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5567440c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556747095f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556747095f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556747095f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556747095f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556747095f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556747095f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556747095f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556747095f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556747095f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556747095f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55674932af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556746057b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556746062be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556745e0ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556745e0ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556745e0f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556745e0e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556745e0e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556745e0e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55674a718abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55674a721928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55674a709699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55674a734112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2656d7d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55674402eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2a,0x74, Step #5: /*t Step #5: artifact_prefix='./'; Test unit written to ./oom-f73ac82a0969272d0b78a8aa20da8195f2992b4b Step #5: Base64: Lyp0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 284 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1919681758 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ffe734810, 0x559ffe91e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ffe91e020,0x55a0007b60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f73ac82a0969272d0b78a8aa20da8195f2992b4b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 301 processed earlier; will process 10728 files now Step #5: ==10258== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559ff52299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ffb88e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ffb8715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ffb8714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ff522fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ff5190b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ff518b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ff5221c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ff81f0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ff81f0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ff81f0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ff81f0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ff81f0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ff81f0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ff81f0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ff81f0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ff81f0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ff81f0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ffa485f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559ff71b2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559ff71bdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559ff6f69c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559ff6f69c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559ff6f6a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559ff6f69874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559ff6f69874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559ff6f69874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ffb873abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ffb87c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ffb864699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ffb88f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb2e20b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ff5189b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x3c,0x3e, Step #5: e<> Step #5: artifact_prefix='./'; Test unit written to ./oom-8d658082cda438ddd9f4a5925d5bc992e7f0fd38 Step #5: Base64: ZTw+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 285 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1920092648 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563cbafb5810, 0x563cbb19f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563cbb19f020,0x563cbd0370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d658082cda438ddd9f4a5925d5bc992e7f0fd38' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 302 processed earlier; will process 10727 files now Step #5: ==10294== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563cb1aaa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563cb810f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563cb80f25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563cb80f24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563cb1ab0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563cb1a11b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563cb1a0c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563cb1aa2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563cb4a71f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563cb4a71f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563cb4a71f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563cb4a71f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563cb4a71f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563cb4a71f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563cb4a71f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563cb4a71f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563cb4a71f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563cb4a71f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563cb6d06f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563cb3a33b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563cb3a3ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563cb37eac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563cb37eac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563cb37eb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563cb37ea874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563cb37ea874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563cb37ea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563cb80f4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563cb80fd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563cb80e5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563cb8110112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f30d05eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563cb1a0ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd7,0x81,0x8a, Step #5: \327\201\212 Step #5: artifact_prefix='./'; Test unit written to ./oom-c11e4a8a55cba1d7b078755504ef5e729f22575c Step #5: Base64: 14GK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 286 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1920501662 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564bf3be3810, 0x564bf3dcd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564bf3dcd020,0x564bf5c650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c11e4a8a55cba1d7b078755504ef5e729f22575c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 303 processed earlier; will process 10726 files now Step #5: ==10330== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564bea6d89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564bf0d3d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564bf0d205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564bf0d204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564bea6ded42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564bea63fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564bea63a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564bea6d0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564bed69ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564bed69ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564bed69ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564bed69ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564bed69ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564bed69ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564bed69ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564bed69ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564bed69ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564bed69ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564bef934f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564bec661b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564bec66cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564bec418c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564bec418c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564bec419738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564bec418874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564bec418874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564bec418874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564bf0d22abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564bf0d2b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564bf0d13699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564bf0d3e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d31123082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564bea638b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xa4,0xbc, Step #5: \340\244\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7ebb2da1831eebf2ee093ce5b5a1da36c6b284f Step #5: Base64: 4KS8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 287 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1920919165 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56138f204810, 0x56138f3ee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56138f3ee020,0x5613912860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7ebb2da1831eebf2ee093ce5b5a1da36c6b284f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 304 processed earlier; will process 10725 files now Step #5: ==10366== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561385cf99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56138c35e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56138c3415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56138c3414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561385cffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561385c60b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561385c5b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561385cf1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561388cc0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561388cc0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561388cc0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561388cc0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561388cc0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561388cc0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561388cc0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561388cc0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561388cc0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561388cc0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56138af55f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561387c82b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561387c8dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561387a39c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561387a39c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561387a3a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561387a39874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561387a39874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561387a39874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56138c343abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56138c34c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56138c334699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56138c35f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf9e063082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561385c59b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1f,0x2e,0x1f, Step #5: \037.\037 Step #5: artifact_prefix='./'; Test unit written to ./oom-3efb0ad2b49480c0ea2cdb94d15db5a65b4ade1d Step #5: Base64: Hy4f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 288 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1921344632 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7fb749810, 0x55f7fb93301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7fb933020,0x55f7fd7cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3efb0ad2b49480c0ea2cdb94d15db5a65b4ade1d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 305 processed earlier; will process 10724 files now Step #5: ==10402== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f7f223e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7f88a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7f88865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7f88864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f7f2244d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f7f21a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f7f21a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f7f2236c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7f5205f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7f5205f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7f5205f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7f5205f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7f5205f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7f5205f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7f5205f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7f5205f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7f5205f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7f5205f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7f749af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f7f41c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f7f41d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f7f3f7ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f7f3f7ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f7f3f7f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f7f3f7e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f7f3f7e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f7f3f7e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7f8888abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7f8891928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7f8879699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7f88a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d508e1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f7f219eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x80,0x8a, Step #5: \342\200\212 Step #5: artifact_prefix='./'; Test unit written to ./oom-70d38e91909d07126ea55c353b5d63f44b2af7db Step #5: Base64: 4oCK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 289 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1921766310 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f19f8d7810, 0x55f19fac101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f19fac1020,0x55f1a19590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70d38e91909d07126ea55c353b5d63f44b2af7db' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 306 processed earlier; will process 10723 files now Step #5: ==10438== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f1963cc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f19ca31898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f19ca145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f19ca144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f1963d2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f196333b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f19632e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f1963c4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f199393f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f199393f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f199393f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f199393f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f199393f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f199393f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f199393f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f199393f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f199393f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f199393f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f19b628f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f198355b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f198360be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f19810cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f19810cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f19810d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f19810c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f19810c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f19810c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f19ca16abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f19ca1f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f19ca07699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f19ca32112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4691a8a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f19632cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x80,0x90, Step #5: \343\200\220 Step #5: artifact_prefix='./'; Test unit written to ./oom-c9157cedda80ae56112b069bc9be8c3de3f0da43 Step #5: Base64: 44CQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 290 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1922188076 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55efa3cd9810, 0x55efa3ec301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55efa3ec3020,0x55efa5d5b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9157cedda80ae56112b069bc9be8c3de3f0da43' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 307 processed earlier; will process 10722 files now Step #5: ==10474== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ef9a7ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55efa0e33898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55efa0e165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55efa0e164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef9a7d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef9a735b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef9a730355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef9a7c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef9d795f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef9d795f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef9d795f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef9d795f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef9d795f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef9d795f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef9d795f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef9d795f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef9d795f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef9d795f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef9fa2af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef9c757b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef9c762be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef9c50ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef9c50ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef9c50f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef9c50e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef9c50e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef9c50e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55efa0e18abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55efa0e21928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55efa0e09699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55efa0e34112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ac3f3f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef9a72eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0x2e,0x54, Step #5: 2.T Step #5: artifact_prefix='./'; Test unit written to ./oom-3c3cf1fd99238742c778ae18afe866547025261c Step #5: Base64: Mi5U Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 291 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1922605589 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55df7deef810, 0x55df7e0d901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55df7e0d9020,0x55df7ff710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3c3cf1fd99238742c778ae18afe866547025261c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 308 processed earlier; will process 10721 files now Step #5: ==10510== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55df749e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55df7b049898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55df7b02c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55df7b02c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55df749ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55df7494bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55df74946355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55df749dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55df779abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55df779abf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55df779abf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55df779abf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55df779abf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55df779abf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55df779abf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55df779abf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55df779abf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55df779abf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55df79c40f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55df7696db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55df76978be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55df76724c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55df76724c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55df76725738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55df76724874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55df76724874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55df76724874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55df7b02eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55df7b037928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55df7b01f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55df7b04a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efdc2c60082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55df74944b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x45,0x47,0x45, Step #5: EGE Step #5: artifact_prefix='./'; Test unit written to ./oom-97910b40b1de171d3046635733e723344ff45f26 Step #5: Base64: RUdF Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 292 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1923021640 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e04daec810, 0x55e04dcd601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e04dcd6020,0x55e04fb6e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/97910b40b1de171d3046635733e723344ff45f26' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 309 processed earlier; will process 10720 files now Step #5: ==10546== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e0445e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e04ac46898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e04ac295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e04ac294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e0445e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e044548b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e044543355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e0445d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e0475a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e0475a8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e0475a8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e0475a8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e0475a8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e0475a8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e0475a8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e0475a8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e0475a8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e0475a8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e04983df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e04656ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e046575be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e046321c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e046321c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e046322738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e046321874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e046321874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e046321874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e04ac2babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e04ac34928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e04ac1c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e04ac47112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4261895082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e044541b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2d,0x12, Step #5: \000-\022 Step #5: artifact_prefix='./'; Test unit written to ./oom-94b485cd7bf79b274631adbcac318e47014db58f Step #5: Base64: AC0S Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 293 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1923441778 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5569939a7810, 0x556993b9101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556993b91020,0x556995a290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/94b485cd7bf79b274631adbcac318e47014db58f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 310 processed earlier; will process 10719 files now Step #5: ==10582== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55698a49c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556990b01898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556990ae45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556990ae44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55698a4a2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55698a403b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55698a3fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55698a494c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55698d463f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55698d463f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55698d463f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55698d463f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55698d463f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55698d463f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55698d463f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55698d463f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55698d463f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55698d463f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55698f6f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55698c425b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55698c430be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55698c1dcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55698c1dcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55698c1dd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55698c1dc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55698c1dc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55698c1dc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556990ae6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556990aef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556990ad7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556990b02112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f315d177082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55698a3fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x36,0xdc, Step #5: P6\334 Step #5: artifact_prefix='./'; Test unit written to ./oom-b9fa7ee23ae77fa63a9dff4fb4ee7ec6676036bf Step #5: Base64: UDbc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 294 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1923858503 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5622f5932810, 0x5622f5b1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622f5b1c020,0x5622f79b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b9fa7ee23ae77fa63a9dff4fb4ee7ec6676036bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 311 processed earlier; will process 10718 files now Step #5: ==10618== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5622ec4279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5622f2a8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5622f2a6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5622f2a6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5622ec42dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5622ec38eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5622ec389355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5622ec41fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5622ef3eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5622ef3eef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5622ef3eef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5622ef3eef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5622ef3eef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5622ef3eef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5622ef3eef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5622ef3eef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5622ef3eef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5622ef3eef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5622f1683f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5622ee3b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5622ee3bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5622ee167c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5622ee167c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5622ee168738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5622ee167874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5622ee167874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5622ee167874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5622f2a71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5622f2a7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5622f2a62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5622f2a8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f239a1d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5622ec387b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xbc,0x69, Step #5: +\274i Step #5: artifact_prefix='./'; Test unit written to ./oom-a683e18ea147b03ad36ea5b91aa9191deacc8a48 Step #5: Base64: K7xp Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 295 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1924273370 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d78f7e6810, 0x55d78f9d001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d78f9d0020,0x55d7918680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a683e18ea147b03ad36ea5b91aa9191deacc8a48' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 312 processed earlier; will process 10717 files now Step #5: ==10654== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d7862db9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d78c940898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d78c9235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d78c9234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d7862e1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d786242b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d78623d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d7862d3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d7892a2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d7892a2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d7892a2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d7892a2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d7892a2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d7892a2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d7892a2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d7892a2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d7892a2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d7892a2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d78b537f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d788264b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d78826fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d78801bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d78801bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d78801c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d78801b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d78801b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d78801b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d78c925abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d78c92e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d78c916699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d78c941112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff373ef7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d78623bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf,0x40,0x25, Step #5: \017@% Step #5: artifact_prefix='./'; Test unit written to ./oom-0b0c4b60d6a72043f8e0c59b4fdead8fca64a8d7 Step #5: Base64: D0Al Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 296 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1924688823 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555f1f2c1810, 0x555f1f4ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555f1f4ab020,0x555f213430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b0c4b60d6a72043f8e0c59b4fdead8fca64a8d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 313 processed earlier; will process 10716 files now Step #5: ==10690== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555f15db69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555f1c41b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555f1c3fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555f1c3fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555f15dbcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555f15d1db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555f15d18355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555f15daec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555f18d7df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555f18d7df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555f18d7df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555f18d7df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555f18d7df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555f18d7df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555f18d7df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555f18d7df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555f18d7df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555f18d7df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555f1b012f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555f17d3fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555f17d4abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555f17af6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555f17af6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555f17af7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555f17af6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555f17af6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555f17af6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555f1c400abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555f1c409928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555f1c3f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555f1c41c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf9d476082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555f15d16b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xba,0x8c, Step #5: \357\272\214 Step #5: artifact_prefix='./'; Test unit written to ./oom-204c42e70027c9fdd7f008af3f4d666bbfef9792 Step #5: Base64: 77qM Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 297 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1925105652 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f424c0a810, 0x55f424df401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f424df4020,0x55f426c8c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/204c42e70027c9fdd7f008af3f4d666bbfef9792' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 314 processed earlier; will process 10715 files now Step #5: ==10726== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f41b6ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f421d64898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f421d475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f421d474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f41b705d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f41b666b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f41b661355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f41b6f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f41e6c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f41e6c6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f41e6c6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f41e6c6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f41e6c6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f41e6c6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f41e6c6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f41e6c6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f41e6c6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f41e6c6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f42095bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f41d688b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f41d693be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f41d43fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f41d43fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f41d440738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f41d43f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f41d43f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f41d43f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f421d49abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f421d52928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f421d3a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f421d65112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fed8ba35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f41b65fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x68,0x38,0x62, Step #5: h8b Step #5: artifact_prefix='./'; Test unit written to ./oom-188adfb0f3f7d2ca3d201b2c2b73642328a0d448 Step #5: Base64: aDhi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 298 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1925524987 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5620a16ce810, 0x5620a18b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5620a18b8020,0x5620a37500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/188adfb0f3f7d2ca3d201b2c2b73642328a0d448' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 315 processed earlier; will process 10714 files now Step #5: ==10762== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5620981c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56209e828898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56209e80b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56209e80b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5620981c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56209812ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562098125355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5620981bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56209b18af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56209b18af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56209b18af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56209b18af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56209b18af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56209b18af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56209b18af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56209b18af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56209b18af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56209b18af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56209d41ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56209a14cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56209a157be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562099f03c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562099f03c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562099f04738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562099f03874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562099f03874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562099f03874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56209e80dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56209e816928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56209e7fe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56209e829112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fed7a691082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562098123b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x83,0xbd, Step #5: \341\203\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-1f857f4bf2d368b77ca872ab8b15dbded80a2166 Step #5: Base64: 4YO9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 299 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1925941730 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e32c410810, 0x55e32c5fa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e32c5fa020,0x55e32e4920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f857f4bf2d368b77ca872ab8b15dbded80a2166' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 316 processed earlier; will process 10713 files now Step #5: ==10798== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e322f059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e32956a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e32954d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e32954d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e322f0bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e322e6cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e322e67355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e322efdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e325eccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e325eccf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e325eccf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e325eccf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e325eccf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e325eccf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e325eccf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e325eccf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e325eccf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e325eccf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e328161f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e324e8eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e324e99be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e324c45c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e324c45c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e324c46738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e324c45874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e324c45874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e324c45874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e32954fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e329558928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e329540699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e32956b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fca10bfe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e322e65b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x10,0x60, Step #5: `\020` Step #5: artifact_prefix='./'; Test unit written to ./oom-5196fe7c6860c51a30878f7b55eb361f47e42679 Step #5: Base64: YBBg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 300 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1926472730 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563033d0e810, 0x563033ef801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563033ef8020,0x563035d900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5196fe7c6860c51a30878f7b55eb361f47e42679' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 317 processed earlier; will process 10712 files now Step #5: ==10834== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56302a8039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563030e68898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563030e4b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563030e4b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56302a809d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56302a76ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56302a765355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56302a7fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56302d7caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56302d7caf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56302d7caf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56302d7caf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56302d7caf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56302d7caf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56302d7caf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56302d7caf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56302d7caf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56302d7caf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56302fa5ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56302c78cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56302c797be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56302c543c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56302c543c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56302c544738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56302c543874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56302c543874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56302c543874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563030e4dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563030e56928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563030e3e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563030e69112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff794823082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56302a763b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0xd4,0xa7, Step #5: e\324\247 Step #5: artifact_prefix='./'; Test unit written to ./oom-58c9985c8d8bc0d7bf2888b9ac5091f61a949cb2 Step #5: Base64: ZdSn Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 301 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1926887845 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562a4e2e4810, 0x562a4e4ce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562a4e4ce020,0x562a503660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58c9985c8d8bc0d7bf2888b9ac5091f61a949cb2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 318 processed earlier; will process 10711 files now Step #5: ==10870== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562a44dd99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562a4b43e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562a4b4215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562a4b4214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562a44ddfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562a44d40b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562a44d3b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562a44dd1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562a47da0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562a47da0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562a47da0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562a47da0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562a47da0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562a47da0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562a47da0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562a47da0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562a47da0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562a47da0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562a4a035f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562a46d62b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562a46d6dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562a46b19c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562a46b19c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562a46b1a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562a46b19874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562a46b19874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562a46b19874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562a4b423abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562a4b42c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562a4b414699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562a4b43f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fce7f2ad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562a44d39b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d, Step #5: --- Step #5: artifact_prefix='./'; Test unit written to ./oom-58b63e273b964039d6ef432a415df3f177c818e5 Step #5: Base64: LS0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 302 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1927300049 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558066d4e810, 0x558066f3801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558066f38020,0x558068dd00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58b63e273b964039d6ef432a415df3f177c818e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 319 processed earlier; will process 10710 files now Step #5: ==10906== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55805d8439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558063ea8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558063e8b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558063e8b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55805d849d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55805d7aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55805d7a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55805d83bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55806080af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55806080af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55806080af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55806080af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55806080af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55806080af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55806080af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55806080af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55806080af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55806080af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558062a9ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55805f7ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55805f7d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55805f583c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55805f583c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55805f584738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55805f583874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55805f583874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55805f583874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558063e8dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558063e96928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558063e7e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558063ea9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f56a7121082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55805d7a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0xde,0x99, Step #5: \\\336\231 Step #5: artifact_prefix='./'; Test unit written to ./oom-16a3e22ed3f98195f1e35ac5daa04afd5cdb0dfd Step #5: Base64: XN6Z Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 303 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1927715913 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a27994d810, 0x55a279b3701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a279b37020,0x55a27b9cf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16a3e22ed3f98195f1e35ac5daa04afd5cdb0dfd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 320 processed earlier; will process 10709 files now Step #5: ==10942== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a2704429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a276aa7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a276a8a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a276a8a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a270448d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a2703a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a2703a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a27043ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a273409f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a273409f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a273409f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a273409f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a273409f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a273409f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a273409f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a273409f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a273409f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a273409f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a27569ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a2723cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a2723d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a272182c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a272182c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a272183738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a272182874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a272182874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a272182874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a276a8cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a276a95928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a276a7d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a276aa8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f121b8d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a2703a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x69,0x68, Step #5: Bih Step #5: artifact_prefix='./'; Test unit written to ./oom-e88722af7a000688f1fa5a8f808ce1a50b0a4485 Step #5: Base64: Qmlo Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 304 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1928133161 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5604ce789810, 0x5604ce97301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604ce973020,0x5604d080b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e88722af7a000688f1fa5a8f808ce1a50b0a4485' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 321 processed earlier; will process 10708 files now Step #5: ==10978== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5604c527e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5604cb8e3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5604cb8c65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5604cb8c64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5604c5284d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5604c51e5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5604c51e0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5604c5276c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5604c8245f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5604c8245f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5604c8245f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5604c8245f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5604c8245f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5604c8245f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5604c8245f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5604c8245f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5604c8245f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5604c8245f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5604ca4daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5604c7207b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5604c7212be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5604c6fbec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5604c6fbec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5604c6fbf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5604c6fbe874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5604c6fbe874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5604c6fbe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5604cb8c8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5604cb8d1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5604cb8b9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5604cb8e4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f18624e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5604c51deb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x40,0x29,0x0, Step #5: @)\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5003f35de335700f6044bca87bf22367564a3f28 Step #5: Base64: QCkA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 305 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1928547626 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b56f49b810, 0x55b56f68501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b56f685020,0x55b57151d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5003f35de335700f6044bca87bf22367564a3f28' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 322 processed earlier; will process 10707 files now Step #5: ==11014== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b565f909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b56c5f5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b56c5d85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b56c5d84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b565f96d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b565ef7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b565ef2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b565f88c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b568f57f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b568f57f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b568f57f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b568f57f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b568f57f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b568f57f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b568f57f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b568f57f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b568f57f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b568f57f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b56b1ecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b567f19b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b567f24be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b567cd0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b567cd0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b567cd1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b567cd0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b567cd0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b567cd0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b56c5daabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b56c5e3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b56c5cb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b56c5f6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f33545082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b565ef0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x39,0x26,0x53, Step #5: 9&S Step #5: artifact_prefix='./'; Test unit written to ./oom-470eafda977519e3f33e68f48a8e36cc859ef68f Step #5: Base64: OSZT Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 306 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1928962234 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c913aff810, 0x55c913ce901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c913ce9020,0x55c915b810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/470eafda977519e3f33e68f48a8e36cc859ef68f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 323 processed earlier; will process 10706 files now Step #5: ==11050== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c90a5f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c910c59898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c910c3c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c910c3c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c90a5fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c90a55bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c90a556355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c90a5ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c90d5bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c90d5bbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c90d5bbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c90d5bbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c90d5bbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c90d5bbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c90d5bbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c90d5bbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c90d5bbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c90d5bbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c90f850f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c90c57db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c90c588be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c90c334c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c90c334c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c90c335738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c90c334874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c90c334874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c90c334874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c910c3eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c910c47928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c910c2f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c910c5a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f12a7e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c90a554b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x13,0x0, Step #5: A\023\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cfadb53dc36ddf310e1c0a3b586d0ceca0cfd954 Step #5: Base64: QRMA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 307 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1929377447 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55803ed87810, 0x55803ef7101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55803ef71020,0x558040e090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cfadb53dc36ddf310e1c0a3b586d0ceca0cfd954' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 324 processed earlier; will process 10705 files now Step #5: ==11086== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55803587c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55803bee1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55803bec45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55803bec44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558035882d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5580357e3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5580357de355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558035874c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558038843f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558038843f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558038843f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558038843f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558038843f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558038843f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558038843f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558038843f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558038843f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558038843f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55803aad8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558037805b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558037810be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580375bcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580375bcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580375bd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580375bc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580375bc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580375bc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55803bec6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55803becf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55803beb7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55803bee2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f085d891082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5580357dcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc7,0x81,0x0, Step #5: \307\201\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-148501417a026472edd0b5c2d15f59a21ac830b8 Step #5: Base64: x4EA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 308 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1929795210 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5624787f0810, 0x5624789da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5624789da020,0x56247a8720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/148501417a026472edd0b5c2d15f59a21ac830b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 325 processed earlier; will process 10704 files now Step #5: ==11122== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56246f2e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56247594a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56247592d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56247592d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56246f2ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56246f24cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56246f247355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56246f2ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5624722acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5624722acf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5624722acf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5624722acf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5624722acf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5624722acf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5624722acf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5624722acf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5624722acf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5624722acf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562474541f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56247126eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562471279be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562471025c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562471025c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562471026738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562471025874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562471025874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562471025874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56247592fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562475938928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562475920699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56247594b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda6e0a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56246f245b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x71,0xd,0xa, Step #5: q\015\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-cc7c53bb3812eb5d01f09ff1f872ce686a9ae68e Step #5: Base64: cQ0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 309 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1930212500 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56046d63b810, 0x56046d82501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56046d825020,0x56046f6bd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cc7c53bb3812eb5d01f09ff1f872ce686a9ae68e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 326 processed earlier; will process 10703 files now Step #5: ==11158== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5604641309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56046a795898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56046a7785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56046a7784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560464136d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560464097b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560464092355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560464128c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5604670f7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5604670f7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5604670f7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5604670f7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5604670f7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5604670f7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5604670f7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5604670f7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5604670f7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5604670f7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56046938cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5604660b9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5604660c4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560465e70c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560465e70c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560465e71738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560465e70874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560465e70874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560465e70874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56046a77aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56046a783928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56046a76b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56046a796112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4d92fc5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560464090b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xd0,0xb0, Step #5: \"\320\260 Step #5: artifact_prefix='./'; Test unit written to ./oom-3174df16d25cb110c2e7df57cc7bdb9ece3bbd02 Step #5: Base64: ItCw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 310 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1930625491 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563608438810, 0x56360862201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563608622020,0x56360a4ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3174df16d25cb110c2e7df57cc7bdb9ece3bbd02' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 327 processed earlier; will process 10702 files now Step #5: ==11194== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5635fef2d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563605592898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636055755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636055754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5635fef33d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5635fee94b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5635fee8f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5635fef25c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563601ef4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563601ef4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563601ef4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563601ef4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563601ef4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563601ef4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563601ef4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563601ef4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563601ef4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563601ef4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563604189f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563600eb6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563600ec1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563600c6dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563600c6dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563600c6e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563600c6d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563600c6d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563600c6d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563605577abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563605580928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563605568699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563605593112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f78de094082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5635fee8db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4e,0x44,0xa, Step #5: ND\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-80257e1c3def92a619011e2a21c8a7d63360d61d Step #5: Base64: TkQK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 311 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1931035702 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56254066b810, 0x56254085501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562540855020,0x5625426ed0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/80257e1c3def92a619011e2a21c8a7d63360d61d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 328 processed earlier; will process 10701 files now Step #5: ==11230== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5625371609c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56253d7c5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56253d7a85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56253d7a84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562537166d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625370c7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625370c2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562537158c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56253a127f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56253a127f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56253a127f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56253a127f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56253a127f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56253a127f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56253a127f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56253a127f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56253a127f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56253a127f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56253c3bcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625390e9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5625390f4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562538ea0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562538ea0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562538ea1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562538ea0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562538ea0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562538ea0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56253d7aaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56253d7b3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56253d79b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56253d7c6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7cc2e6b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625370c0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x61,0x62,0x63, Step #5: abc Step #5: artifact_prefix='./'; Test unit written to ./oom-a9993e364706816aba3e25717850c26c9cd0d89d Step #5: Base64: YWJj Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 312 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1931445581 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55716288c810, 0x557162a7601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557162a76020,0x55716490e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9993e364706816aba3e25717850c26c9cd0d89d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 329 processed earlier; will process 10700 files now Step #5: ==11266== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5571593819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55715f9e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55715f9c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55715f9c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557159387d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571592e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571592e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557159379c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55715c348f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55715c348f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55715c348f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55715c348f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55715c348f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55715c348f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55715c348f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55715c348f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55715c348f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55715c348f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55715e5ddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55715b30ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55715b315be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55715b0c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55715b0c1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55715b0c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55715b0c1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55715b0c1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55715b0c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55715f9cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55715f9d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55715f9bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55715f9e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c980de082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571592e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc3,0x94,0x0, Step #5: \303\224\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a5578c0cb802828ae9c678ee8a2904f62e7ba42b Step #5: Base64: w5QA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 313 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1931855131 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9c1e20810, 0x55a9c200a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a9c200a020,0x55a9c3ea20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a5578c0cb802828ae9c678ee8a2904f62e7ba42b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 330 processed earlier; will process 10699 files now Step #5: ==11302== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a9b89159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a9bef7a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9bef5d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9bef5d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a9b891bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a9b887cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a9b8877355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a9b890dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9bb8dcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9bb8dcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9bb8dcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9bb8dcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9bb8dcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9bb8dcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9bb8dcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9bb8dcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9bb8dcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9bb8dcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a9bdb71f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a9ba89eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a9ba8a9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a9ba655c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a9ba655c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a9ba656738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a9ba655874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a9ba655874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a9ba655874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a9bef5fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a9bef68928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a9bef50699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a9bef7b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f08338e0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a9b8875b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4c,0x4c,0x2c, Step #5: LL, Step #5: artifact_prefix='./'; Test unit written to ./oom-2705c966a74c0595fc62387129c878f4943296c6 Step #5: Base64: TEws Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 314 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1932265261 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5634f0cec810, 0x5634f0ed601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5634f0ed6020,0x5634f2d6e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2705c966a74c0595fc62387129c878f4943296c6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 331 processed earlier; will process 10698 files now Step #5: ==11338== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5634e77e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5634ede46898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634ede295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634ede294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5634e77e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5634e7748b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5634e7743355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5634e77d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5634ea7a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5634ea7a8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5634ea7a8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5634ea7a8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5634ea7a8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5634ea7a8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5634ea7a8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5634ea7a8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5634ea7a8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5634ea7a8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5634eca3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5634e976ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5634e9775be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5634e9521c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5634e9521c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5634e9522738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5634e9521874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5634e9521874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5634e9521874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5634ede2babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5634ede34928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5634ede1c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5634ede47112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fefe8dd1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5634e7741b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2c,0x2c,0x2c, Step #5: ,,, Step #5: artifact_prefix='./'; Test unit written to ./oom-e7d4683bb2bb44a364ab8a871e9ea252ab6f7993 Step #5: Base64: LCws Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 315 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1932677544 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56519e554810, 0x56519e73e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56519e73e020,0x5651a05d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e7d4683bb2bb44a364ab8a871e9ea252ab6f7993' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 332 processed earlier; will process 10697 files now Step #5: ==11374== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5651950499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56519b6ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56519b6915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56519b6914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56519504fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565194fb0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565194fab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565195041c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565198010f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565198010f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565198010f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565198010f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565198010f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565198010f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565198010f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565198010f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565198010f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565198010f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56519a2a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565196fd2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565196fddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565196d89c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565196d89c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565196d8a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565196d89874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565196d89874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565196d89874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56519b693abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56519b69c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56519b684699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56519b6af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8c7d3ae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565194fa9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0x21,0xd, Step #5: \015!\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-97414ad2eb20046f2ee0a7d5b7b91d841f834057 Step #5: Base64: DSEN Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 316 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1933086191 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56274d117810, 0x56274d30101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56274d301020,0x56274f1990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/97414ad2eb20046f2ee0a7d5b7b91d841f834057' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 333 processed earlier; will process 10696 files now Step #5: ==11410== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562743c0c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56274a271898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56274a2545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56274a2544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562743c12d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562743b73b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562743b6e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562743c04c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562746bd3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562746bd3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562746bd3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562746bd3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562746bd3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562746bd3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562746bd3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562746bd3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562746bd3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562746bd3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562748e68f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562745b95b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562745ba0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56274594cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56274594cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56274594d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56274594c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56274594c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56274594c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56274a256abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56274a25f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56274a247699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56274a272112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9b49d21082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562743b6cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0xb4,0x91, Step #5: \342\264\221 Step #5: artifact_prefix='./'; Test unit written to ./oom-e5966c60655e2be9322c6da0075a597ffaceada3 Step #5: Base64: 4rSR Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 317 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1933499195 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc578c9810, 0x55cc57ab301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc57ab3020,0x55cc5994b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e5966c60655e2be9322c6da0075a597ffaceada3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 334 processed earlier; will process 10695 files now Step #5: ==11446== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cc4e3be9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc54a23898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc54a065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc54a064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc4e3c4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc4e325b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc4e320355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc4e3b6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc51385f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc51385f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc51385f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc51385f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc51385f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc51385f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc51385f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc51385f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc51385f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc51385f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc5361af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc50347b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc50352be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc500fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc500fec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc500ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc500fe874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc500fe874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc500fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc54a08abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc54a11928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc549f9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc54a24112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f092fb33082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc4e31eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xec,0x80,0x84, Step #5: \354\200\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-93363f95eb48e1fde544f6ef53baa08b8f76382b Step #5: Base64: 7ICE Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 318 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1933916494 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a019711810, 0x55a0198fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0198fb020,0x55a01b7930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93363f95eb48e1fde544f6ef53baa08b8f76382b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 335 processed earlier; will process 10694 files now Step #5: ==11482== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a0102069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a01686b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a01684e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a01684e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a01020cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a01016db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a010168355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0101fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0131cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0131cdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0131cdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0131cdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0131cdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0131cdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0131cdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0131cdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0131cdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0131cdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a015462f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a01218fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a01219abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a011f46c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a011f46c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a011f47738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a011f46874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a011f46874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a011f46874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a016850abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a016859928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a016841699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a01686c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f19f6f27082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a010166b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x8f,0xac, Step #5: \341\217\254 Step #5: artifact_prefix='./'; Test unit written to ./oom-70e4e98de8b29a6f52eb81463bdb250d89361485 Step #5: Base64: 4Y+s Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 319 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1934328203 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559f46b29810, 0x559f46d1301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559f46d13020,0x559f48bab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70e4e98de8b29a6f52eb81463bdb250d89361485' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 336 processed earlier; will process 10693 files now Step #5: ==11518== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559f3d61e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559f43c83898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559f43c665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559f43c664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559f3d624d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559f3d585b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559f3d580355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559f3d616c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559f405e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559f405e5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559f405e5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559f405e5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559f405e5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559f405e5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559f405e5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559f405e5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559f405e5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559f405e5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559f4287af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559f3f5a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559f3f5b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559f3f35ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559f3f35ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559f3f35f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559f3f35e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559f3f35e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559f3f35e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559f43c68abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559f43c71928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559f43c59699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559f43c84112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f78109e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559f3d57eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xec,0x80,0x80, Step #5: \354\200\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-bcb64d8b87b1ab82146841cd5dd045dab2a1110e Step #5: Base64: 7ICA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 320 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1934754307 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558bc100d810, 0x558bc11f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558bc11f7020,0x558bc308f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bcb64d8b87b1ab82146841cd5dd045dab2a1110e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 337 processed earlier; will process 10692 files now Step #5: ==11554== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558bb7b029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558bbe167898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558bbe14a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558bbe14a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558bb7b08d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558bb7a69b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558bb7a64355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558bb7afac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558bbaac9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558bbaac9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558bbaac9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558bbaac9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558bbaac9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558bbaac9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558bbaac9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558bbaac9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558bbaac9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558bbaac9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558bbcd5ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558bb9a8bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558bb9a96be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558bb9842c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558bb9842c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558bb9843738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558bb9842874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558bb9842874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558bb9842874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558bbe14cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558bbe155928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558bbe13d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558bbe168112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba6fc5b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558bb7a62b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x37,0x1a, Step #5: P7\032 Step #5: artifact_prefix='./'; Test unit written to ./oom-fae8698977ae2cf90202b89716cea7cea8fb2d32 Step #5: Base64: UDca Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 321 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1935162661 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5578ba926810, 0x5578bab1001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5578bab10020,0x5578bc9a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fae8698977ae2cf90202b89716cea7cea8fb2d32' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 338 processed earlier; will process 10691 files now Step #5: ==11590== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5578b141b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5578b7a80898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5578b7a635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5578b7a634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5578b1421d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5578b1382b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5578b137d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5578b1413c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5578b43e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5578b43e2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5578b43e2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5578b43e2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5578b43e2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5578b43e2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5578b43e2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5578b43e2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5578b43e2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5578b43e2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5578b6677f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5578b33a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5578b33afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5578b315bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5578b315bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5578b315c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5578b315b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5578b315b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5578b315b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5578b7a65abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5578b7a6e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5578b7a56699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5578b7a81112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb13719082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5578b137bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x68,0xd, Step #5: #h\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-2523f0420e16e5024d2121da59b67fe9030ba255 Step #5: Base64: I2gN Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 322 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1935578614 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ffcecbb810, 0x55ffceea501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ffceea5020,0x55ffd0d3d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2523f0420e16e5024d2121da59b67fe9030ba255' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 339 processed earlier; will process 10690 files now Step #5: ==11626== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ffc57b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ffcbe15898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ffcbdf85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ffcbdf84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ffc57b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ffc5717b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ffc5712355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ffc57a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ffc8777f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ffc8777f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ffc8777f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ffc8777f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ffc8777f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ffc8777f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ffc8777f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ffc8777f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ffc8777f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ffc8777f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ffcaa0cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ffc7739b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ffc7744be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ffc74f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ffc74f0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ffc74f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ffc74f0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ffc74f0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ffc74f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ffcbdfaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ffcbe03928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ffcbdeb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ffcbe16112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ff4a1b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ffc5710b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x5b,0x42, Step #5: -[B Step #5: artifact_prefix='./'; Test unit written to ./oom-67320e251c8cc85947a18a8e7f77c3cdb830e721 Step #5: Base64: LVtC Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 323 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1936002852 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5557e195d810, 0x5557e1b4701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5557e1b47020,0x5557e39df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/67320e251c8cc85947a18a8e7f77c3cdb830e721' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 340 processed earlier; will process 10689 files now Step #5: #1 pulse cov: 10245 ft: 10246 exec/s: 0 rss: 172Mb Step #5: ==11662== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5557d84529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5557deab7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557dea9a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557dea9a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557d8458d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557d83b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5557d83b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557d844ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557db419f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557db419f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557db419f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557db419f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557db419f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557db419f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557db419f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557db419f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557db419f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557db419f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5557dd6aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557da3dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557da3e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5557da192c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5557da192c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5557da193738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5557da192874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5557da192874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5557da192874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557dea9cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557deaa5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557dea8d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5557deab8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9b79d67082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5557d83b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0x2e,0xd1, Step #5: ..\321 Step #5: artifact_prefix='./'; Test unit written to ./oom-55067d9854b8342a7e742572e63a485810a0b500 Step #5: Base64: Li7R Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 324 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1936485511 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5580e42c4810, 0x5580e44ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5580e44ae020,0x5580e63460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/55067d9854b8342a7e742572e63a485810a0b500' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 342 processed earlier; will process 10687 files now Step #5: ==11698== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5580dadb99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5580e141e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5580e14015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5580e14014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5580dadbfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5580dad20b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5580dad1b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5580dadb1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5580ddd80f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5580ddd80f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5580ddd80f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5580ddd80f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5580ddd80f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5580ddd80f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5580ddd80f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5580ddd80f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5580ddd80f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5580ddd80f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5580e0015f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5580dcd42b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5580dcd4dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580dcaf9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580dcaf9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580dcafa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580dcaf9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580dcaf9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580dcaf9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5580e1403abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5580e140c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5580e13f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5580e141f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0944ff9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5580dad19b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1f,0xca,0xb5, Step #5: \037\312\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-0836d8e4c52f9f7283da66028bf4d845f8d1b0a2 Step #5: Base64: H8q1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 325 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1936913078 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea6bdea810, 0x55ea6bfd401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea6bfd4020,0x55ea6de6c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0836d8e4c52f9f7283da66028bf4d845f8d1b0a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 343 processed earlier; will process 10686 files now Step #5: ==11734== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ea628df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea68f44898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea68f275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea68f274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea628e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea62846b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea62841355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea628d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea658a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea658a6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea658a6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea658a6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea658a6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea658a6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea658a6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea658a6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea658a6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea658a6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea67b3bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea64868b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea64873be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea6461fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea6461fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea64620738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea6461f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea6461f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea6461f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea68f29abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea68f32928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea68f1a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea68f45112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f79dc59f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea6283fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0xd,0xd, Step #5: \015\015\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-01d94a6f21b47b294553d412889a784d3553cf6f Step #5: Base64: DQ0N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 326 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1937323722 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5580cf688810, 0x5580cf87201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5580cf872020,0x5580d170a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01d94a6f21b47b294553d412889a784d3553cf6f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 344 processed earlier; will process 10685 files now Step #5: ==11770== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5580c617d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5580cc7e2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5580cc7c55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5580cc7c54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5580c6183d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5580c60e4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5580c60df355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5580c6175c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5580c9144f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5580c9144f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5580c9144f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5580c9144f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5580c9144f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5580c9144f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5580c9144f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5580c9144f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5580c9144f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5580c9144f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5580cb3d9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5580c8106b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5580c8111be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580c7ebdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580c7ebdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580c7ebe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580c7ebd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580c7ebd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580c7ebd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5580cc7c7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5580cc7d0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5580cc7b8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5580cc7e3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f591f699082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5580c60ddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0x75,0x65, Step #5: nue Step #5: artifact_prefix='./'; Test unit written to ./oom-00bee9e544617506d4bb2c0ee7d2108812bfc40f Step #5: Base64: bnVl Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 327 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1937748860 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a265f01810, 0x55a2660eb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a2660eb020,0x55a267f830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/00bee9e544617506d4bb2c0ee7d2108812bfc40f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 345 processed earlier; will process 10684 files now Step #5: ==11806== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a25c9f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a26305b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a26303e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a26303e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a25c9fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a25c95db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a25c958355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a25c9eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a25f9bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a25f9bdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a25f9bdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a25f9bdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a25f9bdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a25f9bdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a25f9bdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a25f9bdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a25f9bdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a25f9bdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a261c52f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a25e97fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a25e98abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a25e736c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a25e736c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a25e737738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a25e736874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a25e736874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a25e736874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a263040abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a263049928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a263031699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a26305c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f387a74d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a25c956b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcc,0x86,0xf0, Step #5: \314\206\360 Step #5: artifact_prefix='./'; Test unit written to ./oom-06ec1b48453a79dae454b12a593831af58ed3640 Step #5: Base64: zIbw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 328 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1938173221 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fd39d76810, 0x55fd39f6001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fd39f60020,0x55fd3bdf80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/06ec1b48453a79dae454b12a593831af58ed3640' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 346 processed earlier; will process 10683 files now Step #5: ==11842== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fd3086b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fd36ed0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fd36eb35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fd36eb34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fd30871d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fd307d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fd307cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fd30863c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fd33832f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fd33832f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fd33832f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fd33832f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fd33832f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fd33832f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fd33832f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fd33832f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fd33832f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fd33832f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fd35ac7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fd327f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fd327ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fd325abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fd325abc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fd325ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fd325ab874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fd325ab874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fd325ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fd36eb5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fd36ebe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fd36ea6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fd36ed1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe4343b6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fd307cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x58, Step #5: +\012X Step #5: artifact_prefix='./'; Test unit written to ./oom-351f52f1b08f6ac022592e5f38574ef8394b05ec Step #5: Base64: KwpY Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 329 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1938600189 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e7a595d810, 0x55e7a5b4701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e7a5b47020,0x55e7a79df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/351f52f1b08f6ac022592e5f38574ef8394b05ec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 347 processed earlier; will process 10682 files now Step #5: ==11878== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e79c4529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e7a2ab7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7a2a9a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7a2a9a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e79c458d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e79c3b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e79c3b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e79c44ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e79f419f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e79f419f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e79f419f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e79f419f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e79f419f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e79f419f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e79f419f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e79f419f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e79f419f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e79f419f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e7a16aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e79e3dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e79e3e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e79e192c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e79e192c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e79e193738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e79e192874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e79e192874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e79e192874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e7a2a9cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e7a2aa5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e7a2a8d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e7a2ab8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc9e7fde082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e79c3b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xa0,0x80, Step #5: \357\240\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-1f2e4b87b9bdbe59695a5698ae25d726b239531c Step #5: Base64: 76CA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 330 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1939025278 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5615044de810, 0x5615046c801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5615046c8020,0x5615065600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f2e4b87b9bdbe59695a5698ae25d726b239531c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 348 processed earlier; will process 10681 files now Step #5: ==11914== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5614fafd39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561501638898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56150161b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56150161b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5614fafd9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5614faf3ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5614faf35355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5614fafcbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5614fdf9af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5614fdf9af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5614fdf9af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5614fdf9af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5614fdf9af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5614fdf9af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5614fdf9af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5614fdf9af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5614fdf9af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5614fdf9af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56150022ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5614fcf5cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5614fcf67be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5614fcd13c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5614fcd13c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5614fcd14738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5614fcd13874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5614fcd13874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5614fcd13874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56150161dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561501626928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56150160e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561501639112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa657a67082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5614faf33b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xee,0xbd,0xbd, Step #5: \356\275\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-9d6309ae005072c0b683729784cc445acba86b47 Step #5: Base64: 7r29 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 331 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1939445395 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55878489a810, 0x558784a8401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558784a84020,0x55878691c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9d6309ae005072c0b683729784cc445acba86b47' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 349 processed earlier; will process 10680 files now Step #5: ==11950== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55877b38f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5587819f4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5587819d75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5587819d74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55877b395d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55877b2f6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55877b2f1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55877b387c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55877e356f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55877e356f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55877e356f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55877e356f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55877e356f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55877e356f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55877e356f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55877e356f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55877e356f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55877e356f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5587805ebf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55877d318b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55877d323be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55877d0cfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55877d0cfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55877d0d0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55877d0cf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55877d0cf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55877d0cf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5587819d9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5587819e2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5587819ca699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5587819f5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3af486082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55877b2efb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x65,0x6e, Step #5: Den Step #5: artifact_prefix='./'; Test unit written to ./oom-abc34dace1e53bde84c15a0f168f3203411b130b Step #5: Base64: RGVu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 332 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1939871533 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf83cd4810, 0x55bf83ebe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf83ebe020,0x55bf85d560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/abc34dace1e53bde84c15a0f168f3203411b130b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 350 processed earlier; will process 10679 files now Step #5: ==11986== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bf7a7c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf80e2e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf80e115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf80e114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf7a7cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf7a730b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf7a72b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf7a7c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf7d790f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf7d790f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf7d790f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf7d790f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf7d790f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf7d790f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf7d790f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf7d790f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf7d790f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf7d790f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf7fa25f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf7c752b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf7c75dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf7c509c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf7c509c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf7c50a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf7c509874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf7c509874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf7c509874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf80e13abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf80e1c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf80e04699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf80e2f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c82d7b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf7a729b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd6,0xae,0xd5, Step #5: \326\256\325 Step #5: artifact_prefix='./'; Test unit written to ./oom-a3c909e0b63be23281dc915b72509a7015684e09 Step #5: Base64: 1q7V Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 333 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1940289297 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a2bea15810, 0x55a2bebff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a2bebff020,0x55a2c0a970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a3c909e0b63be23281dc915b72509a7015684e09' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 351 processed earlier; will process 10678 files now Step #5: ==12022== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a2b550a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a2bbb6f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2bbb525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2bbb524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a2b5510d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a2b5471b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a2b546c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a2b5502c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a2b84d1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a2b84d1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a2b84d1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a2b84d1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a2b84d1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a2b84d1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a2b84d1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a2b84d1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a2b84d1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a2b84d1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a2ba766f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a2b7493b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a2b749ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a2b724ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a2b724ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a2b724b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a2b724a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a2b724a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a2b724a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a2bbb54abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a2bbb5d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2bbb45699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a2bbb70112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc8109b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a2b546ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x3f,0x7d, Step #5: {?} Step #5: artifact_prefix='./'; Test unit written to ./oom-915f52746400921fcd08429b96046ef3183601bc Step #5: Base64: ez99 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 334 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1940701068 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b0678d810, 0x555b0697701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b06977020,0x555b0880f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/915f52746400921fcd08429b96046ef3183601bc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 352 processed earlier; will process 10677 files now Step #5: ==12058== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555afd2829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b038e7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b038ca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b038ca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555afd288d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555afd1e9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555afd1e4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555afd27ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b00249f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b00249f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b00249f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b00249f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b00249f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b00249f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b00249f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b00249f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b00249f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b00249f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b024def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555aff20bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555aff216be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555afefc2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555afefc2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555afefc3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555afefc2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555afefc2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555afefc2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b038ccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b038d5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b038bd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b038e8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8865ab0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555afd1e2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x12,0x0,0x12, Step #5: \022\000\022 Step #5: artifact_prefix='./'; Test unit written to ./oom-fe0c0272b4088e37022964fec42c8bda4a5effec Step #5: Base64: EgAS Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 335 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1941115953 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c703c71810, 0x55c703e5b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c703e5b020,0x55c705cf30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fe0c0272b4088e37022964fec42c8bda4a5effec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 353 processed earlier; will process 10676 files now Step #5: ==12094== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c6fa7669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c700dcb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c700dae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c700dae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c6fa76cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6fa6cdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6fa6c8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c6fa75ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c6fd72df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c6fd72df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c6fd72df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c6fd72df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c6fd72df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c6fd72df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c6fd72df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c6fd72df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c6fd72df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c6fd72df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c6ff9c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6fc6efb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c6fc6fabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6fc4a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6fc4a6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6fc4a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6fc4a6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6fc4a6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6fc4a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c700db0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c700db9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c700da1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c700dcc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67019d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6fa6c6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xbd,0xbf, Step #5: \340\275\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-35aaf60156f4e7fb65a03dff232d1394508d1290 Step #5: Base64: 4L2/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 336 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1941528102 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5642c1985810, 0x5642c1b6f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5642c1b6f020,0x5642c3a070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/35aaf60156f4e7fb65a03dff232d1394508d1290' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 354 processed earlier; will process 10675 files now Step #5: ==12130== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5642b847a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5642beadf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5642beac25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5642beac24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642b8480d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5642b83e1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5642b83dc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5642b8472c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5642bb441f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5642bb441f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5642bb441f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5642bb441f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5642bb441f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5642bb441f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5642bb441f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5642bb441f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5642bb441f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5642bb441f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5642bd6d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5642ba403b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5642ba40ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5642ba1bac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5642ba1bac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5642ba1bb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5642ba1ba874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5642ba1ba874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5642ba1ba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5642beac4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5642beacd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5642beab5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5642beae0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1b2a72e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5642b83dab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e, Step #5: ~~~ Step #5: artifact_prefix='./'; Test unit written to ./oom-40ef8e2f391a7167d3643c402aff5290167914a6 Step #5: Base64: fn5+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 337 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1941949278 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5624fb658810, 0x5624fb84201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5624fb842020,0x5624fd6da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40ef8e2f391a7167d3643c402aff5290167914a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 355 processed earlier; will process 10674 files now Step #5: ==12166== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5624f214d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5624f87b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5624f87955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5624f87954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5624f2153d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5624f20b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5624f20af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5624f2145c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5624f5114f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5624f5114f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5624f5114f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5624f5114f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5624f5114f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5624f5114f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5624f5114f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5624f5114f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5624f5114f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5624f5114f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5624f73a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5624f40d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5624f40e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5624f3e8dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5624f3e8dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5624f3e8e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5624f3e8d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5624f3e8d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5624f3e8d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5624f8797abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5624f87a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5624f8788699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5624f87b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba78ca9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5624f20adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xbf, Step #5: \357\273\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-57218c316b6921e2cd61027a2387edc31a2d9471 Step #5: Base64: 77u/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 338 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1942372234 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5629b6274810, 0x5629b645e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5629b645e020,0x5629b82f60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/57218c316b6921e2cd61027a2387edc31a2d9471' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 356 processed earlier; will process 10673 files now Step #5: ==12202== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5629acd699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5629b33ce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5629b33b15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5629b33b14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5629acd6fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629accd0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629acccb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5629acd61c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5629afd30f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5629afd30f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5629afd30f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5629afd30f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5629afd30f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5629afd30f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5629afd30f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5629afd30f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5629afd30f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5629afd30f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5629b1fc5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629aecf2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629aecfdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629aeaa9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629aeaa9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629aeaaa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629aeaa9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629aeaa9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629aeaa9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5629b33b3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5629b33bc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5629b33a4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5629b33cf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7aeb92c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629accc9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0xfe,0x5d, Step #5: d\376] Step #5: artifact_prefix='./'; Test unit written to ./oom-3a16c349e939e0a5c4cbcd03375ca0b6d9bc810d Step #5: Base64: ZP5d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 339 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1942794463 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e61eeb810, 0x562e620d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e620d5020,0x562e63f6d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a16c349e939e0a5c4cbcd03375ca0b6d9bc810d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 357 processed earlier; will process 10672 files now Step #5: ==12238== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562e589e09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e5f045898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e5f0285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e5f0284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e589e6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e58947b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e58942355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e589d8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e5b9a7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e5b9a7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e5b9a7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e5b9a7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e5b9a7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e5b9a7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e5b9a7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e5b9a7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e5b9a7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e5b9a7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e5dc3cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e5a969b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e5a974be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e5a720c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e5a720c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e5a721738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e5a720874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e5a720874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e5a720874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e5f02aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e5f033928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e5f01b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e5f046112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb99420b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e58940b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xb2,0xbe, Step #5: \357\262\276 Step #5: artifact_prefix='./'; Test unit written to ./oom-46718c7289d6f7152b7b930c21a4c829af890fd2 Step #5: Base64: 77K+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 340 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1943214237 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e5cc747810, 0x55e5cc93101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e5cc931020,0x55e5ce7c90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/46718c7289d6f7152b7b930c21a4c829af890fd2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 358 processed earlier; will process 10671 files now Step #5: #1 pulse cov: 3469 ft: 3470 exec/s: 0 rss: 155Mb Step #5: ==12274== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e5c323c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e5c98a1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e5c98845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e5c98844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e5c3242d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e5c31a3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e5c319e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e5c3234c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e5c6203f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e5c6203f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e5c6203f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e5c6203f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e5c6203f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e5c6203f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e5c6203f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e5c6203f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e5c6203f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e5c6203f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e5c8498f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e5c51c5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e5c51d0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e5c4f7cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e5c4f7cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e5c4f7d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e5c4f7c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e5c4f7c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e5c4f7c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e5c9886abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e5c988f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e5c9877699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e5c98a2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e05982082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e5c319cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0xdf,0xbd, Step #5: ^\337\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-fb03aebe482697291747b8f5566bbf69a7f8e1fc Step #5: Base64: Xt+9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 341 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1943672643 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5644d7b24810, 0x5644d7d0e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5644d7d0e020,0x5644d9ba60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fb03aebe482697291747b8f5566bbf69a7f8e1fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 360 processed earlier; will process 10669 files now Step #5: ==12310== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5644ce6199c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5644d4c7e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5644d4c615dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5644d4c614fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5644ce61fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5644ce580b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5644ce57b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5644ce611c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5644d15e0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5644d15e0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5644d15e0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5644d15e0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5644d15e0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5644d15e0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5644d15e0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5644d15e0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5644d15e0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5644d15e0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5644d3875f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5644d05a2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5644d05adbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5644d0359c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5644d0359c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5644d035a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5644d0359874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5644d0359874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5644d0359874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5644d4c63abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5644d4c6c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5644d4c54699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5644d4c7f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c4c250082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5644ce579b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0xdf,0xba, Step #5: ^\337\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-689577d7d15650c265fce2a79ea656cc9bd01e43 Step #5: Base64: Xt+6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 342 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1944098426 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f2c48b4810, 0x55f2c4a9e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f2c4a9e020,0x55f2c69360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/689577d7d15650c265fce2a79ea656cc9bd01e43' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 361 processed earlier; will process 10668 files now Step #5: ==12346== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f2bb3a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f2c1a0e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f2c19f15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f2c19f14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f2bb3afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f2bb310b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f2bb30b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f2bb3a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f2be370f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f2be370f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f2be370f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f2be370f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f2be370f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f2be370f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f2be370f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f2be370f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f2be370f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f2be370f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f2c0605f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f2bd332b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f2bd33dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f2bd0e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f2bd0e9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f2bd0ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f2bd0e9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f2bd0e9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f2bd0e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f2c19f3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f2c19fc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f2c19e4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f2c1a0f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7eeb2f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f2bb309b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x60,0x60, Step #5: \012`` Step #5: artifact_prefix='./'; Test unit written to ./oom-adc83da3952a34f74e17e469ebf30cd7d2a1cbe2 Step #5: Base64: CmBg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 343 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1944629689 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55962f39a810, 0x55962f58401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55962f584020,0x55963141c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/adc83da3952a34f74e17e469ebf30cd7d2a1cbe2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 362 processed earlier; will process 10667 files now Step #5: ==12382== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559625e8f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55962c4f4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55962c4d75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55962c4d74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559625e95d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559625df6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559625df1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559625e87c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559628e56f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559628e56f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559628e56f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559628e56f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559628e56f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559628e56f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559628e56f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559628e56f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559628e56f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559628e56f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55962b0ebf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559627e18b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559627e23be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559627bcfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559627bcfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559627bd0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559627bcf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559627bcf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559627bcf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55962c4d9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55962c4e2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55962c4ca699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55962c4f5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f59d6a70082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559625defb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0xa,0x69, Step #5: .\012i Step #5: artifact_prefix='./'; Test unit written to ./oom-7627632f17554cd52e41ffecc6599a2eced2e8ec Step #5: Base64: Lgpp Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 344 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1945055912 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5565a995a810, 0x5565a9b4401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5565a9b44020,0x5565ab9dc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7627632f17554cd52e41ffecc6599a2eced2e8ec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 363 processed earlier; will process 10666 files now Step #5: ==12418== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5565a044f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5565a6ab4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5565a6a975dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5565a6a974fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5565a0455d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5565a03b6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5565a03b1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5565a0447c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5565a3416f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5565a3416f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5565a3416f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5565a3416f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5565a3416f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5565a3416f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5565a3416f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5565a3416f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5565a3416f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5565a3416f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5565a56abf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5565a23d8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5565a23e3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5565a218fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5565a218fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5565a2190738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5565a218f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5565a218f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5565a218f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5565a6a99abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5565a6aa2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5565a6a8a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5565a6ab5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a8e0e1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5565a03afb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4c,0x2e,0x3e, Step #5: L.> Step #5: artifact_prefix='./'; Test unit written to ./oom-87040ad5fb1888e6eae82bccfdf38ba69cc8319d Step #5: Base64: TC4+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 345 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1945471375 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558112460810, 0x55811264a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55811264a020,0x5581144e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87040ad5fb1888e6eae82bccfdf38ba69cc8319d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 364 processed earlier; will process 10665 files now Step #5: ==12454== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558108f559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55810f5ba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55810f59d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55810f59d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558108f5bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558108ebcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558108eb7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558108f4dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55810bf1cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55810bf1cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55810bf1cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55810bf1cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55810bf1cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55810bf1cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55810bf1cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55810bf1cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55810bf1cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55810bf1cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55810e1b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55810aedeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55810aee9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55810ac95c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55810ac95c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55810ac96738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55810ac95874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55810ac95874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55810ac95874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55810f59fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55810f5a8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55810f590699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55810f5bb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b83e51082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558108eb5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0xa,0xa, Step #5: 1\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-971555ab39d1dfe8dff8b78c2b20e85e01c06595 Step #5: Base64: MQoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 346 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1945884204 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5596e629c810, 0x5596e648601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596e6486020,0x5596e831e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/971555ab39d1dfe8dff8b78c2b20e85e01c06595' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 365 processed earlier; will process 10664 files now Step #5: ==12490== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5596dcd919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5596e33f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5596e33d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5596e33d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5596dcd97d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5596dccf8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5596dccf3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5596dcd89c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5596dfd58f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5596dfd58f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5596dfd58f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5596dfd58f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5596dfd58f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5596dfd58f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5596dfd58f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5596dfd58f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5596dfd58f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5596dfd58f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596e1fedf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5596ded1ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5596ded25be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5596dead1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5596dead1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5596dead2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5596dead1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5596dead1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5596dead1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5596e33dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5596e33e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5596e33cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5596e33f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f92296a8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5596dccf1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x68,0x9, Step #5: Ph\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-7712499daf8a47339144b773f877d59e39e0f3ff Step #5: Base64: UGgJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 347 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1946301806 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564a91bf1810, 0x564a91ddb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564a91ddb020,0x564a93c730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7712499daf8a47339144b773f877d59e39e0f3ff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 366 processed earlier; will process 10663 files now Step #5: ==12526== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564a886e69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564a8ed4b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564a8ed2e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564a8ed2e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564a886ecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564a8864db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564a88648355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564a886dec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564a8b6adf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564a8b6adf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564a8b6adf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564a8b6adf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564a8b6adf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564a8b6adf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564a8b6adf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564a8b6adf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564a8b6adf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564a8b6adf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564a8d942f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564a8a66fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564a8a67abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564a8a426c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564a8a426c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564a8a427738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564a8a426874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564a8a426874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564a8a426874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564a8ed30abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564a8ed39928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564a8ed21699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564a8ed4c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95f9a02082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564a88646b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x20,0x0, Step #5: s \000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7cef94373c90ce4a20d86bf53bf2dd23e4b942d2 Step #5: Base64: cyAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 348 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1946723894 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d144a79810, 0x55d144c6301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d144c63020,0x55d146afb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7cef94373c90ce4a20d86bf53bf2dd23e4b942d2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 367 processed earlier; will process 10662 files now Step #5: ==12562== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d13b56e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d141bd3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d141bb65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d141bb64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d13b574d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d13b4d5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d13b4d0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d13b566c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d13e535f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d13e535f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d13e535f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d13e535f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d13e535f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d13e535f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d13e535f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d13e535f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d13e535f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d13e535f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1407caf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d13d4f7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d13d502be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d13d2aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d13d2aec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d13d2af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d13d2ae874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d13d2ae874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d13d2ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d141bb8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d141bc1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d141ba9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d141bd4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0cbeff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d13b4ceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x9f,0xbf, Step #5: \342\237\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-2683a9b5d4f177ad84ffc4c5c1a85e405661628a Step #5: Base64: 4p+/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 349 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1947147268 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5606d6baa810, 0x5606d6d9401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5606d6d94020,0x5606d8c2c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2683a9b5d4f177ad84ffc4c5c1a85e405661628a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 368 processed earlier; will process 10661 files now Step #5: ==12598== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5606cd69f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5606d3d04898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606d3ce75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606d3ce74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5606cd6a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5606cd606b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5606cd601355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5606cd697c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5606d0666f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5606d0666f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5606d0666f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5606d0666f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5606d0666f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5606d0666f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5606d0666f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5606d0666f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5606d0666f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5606d0666f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606d28fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5606cf628b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5606cf633be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5606cf3dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5606cf3dfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5606cf3e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5606cf3df874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5606cf3df874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5606cf3df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5606d3ce9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5606d3cf2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5606d3cda699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5606d3d05112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f884ecd9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5606cd5ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x7f,0x1e, Step #5: \000\177\036 Step #5: artifact_prefix='./'; Test unit written to ./oom-b5448374e018957f5c414a97aa5aabb1d565fad1 Step #5: Base64: AH8e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 350 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1947569173 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563817dd0810, 0x563817fba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563817fba020,0x563819e520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b5448374e018957f5c414a97aa5aabb1d565fad1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 369 processed earlier; will process 10660 files now Step #5: ==12634== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56380e8c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563814f2a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563814f0d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563814f0d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56380e8cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56380e82cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56380e827355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56380e8bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56381188cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56381188cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56381188cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56381188cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56381188cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56381188cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56381188cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56381188cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56381188cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56381188cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563813b21f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56381084eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563810859be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563810605c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563810605c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563810606738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563810605874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563810605874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563810605874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563814f0fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563814f18928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563814f00699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563814f2b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f34a186e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56380e825b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x52,0x6f,0x30, Step #5: Ro0 Step #5: artifact_prefix='./'; Test unit written to ./oom-753e0f2383fd6ca5006766b8891517bfe86d9096 Step #5: Base64: Um8w Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 351 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1947989540 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5639ae1fc810, 0x5639ae3e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5639ae3e6020,0x5639b027e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/753e0f2383fd6ca5006766b8891517bfe86d9096' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 370 processed earlier; will process 10659 files now Step #5: ==12670== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5639a4cf19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5639ab356898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5639ab3395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5639ab3394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5639a4cf7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5639a4c58b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5639a4c53355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5639a4ce9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5639a7cb8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5639a7cb8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5639a7cb8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5639a7cb8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5639a7cb8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5639a7cb8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5639a7cb8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5639a7cb8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5639a7cb8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5639a7cb8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5639a9f4df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5639a6c7ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5639a6c85be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5639a6a31c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5639a6a31c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5639a6a32738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5639a6a31874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5639a6a31874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5639a6a31874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5639ab33babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5639ab344928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5639ab32c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5639ab357112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f67f34082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5639a4c51b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x58,0x2e,0x30, Step #5: X.0 Step #5: artifact_prefix='./'; Test unit written to ./oom-9b6ecad0d0a509e733ed88ac6b5542ca2b3bcb2d Step #5: Base64: WC4w Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 352 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1948410428 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559467fcf810, 0x5594681b901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5594681b9020,0x55946a0510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9b6ecad0d0a509e733ed88ac6b5542ca2b3bcb2d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 371 processed earlier; will process 10658 files now Step #5: ==12706== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55945eac49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559465129898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55946510c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55946510c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55945eacad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55945ea2bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55945ea26355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55945eabcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559461a8bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559461a8bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559461a8bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559461a8bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559461a8bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559461a8bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559461a8bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559461a8bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559461a8bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559461a8bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559463d20f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559460a4db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559460a58be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559460804c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559460804c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559460805738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559460804874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559460804874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559460804874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55946510eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559465117928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5594650ff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55946512a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efce09e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55945ea24b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4e,0xd9,0xb7, Step #5: N\331\267 Step #5: artifact_prefix='./'; Test unit written to ./oom-0f2b15ff573e76bbb65ad71944560e875809d943 Step #5: Base64: Ttm3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 353 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1948834408 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5606c7883810, 0x5606c7a6d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5606c7a6d020,0x5606c99050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0f2b15ff573e76bbb65ad71944560e875809d943' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 372 processed earlier; will process 10657 files now Step #5: #1 pulse cov: 3446 ft: 3447 exec/s: 0 rss: 156Mb Step #5: ==12742== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5606be3789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5606c49dd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606c49c05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606c49c04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5606be37ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5606be2dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5606be2da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5606be370c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5606c133ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5606c133ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5606c133ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5606c133ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5606c133ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5606c133ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5606c133ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5606c133ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5606c133ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5606c133ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606c35d4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5606c0301b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5606c030cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5606c00b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5606c00b8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5606c00b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5606c00b8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5606c00b8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5606c00b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5606c49c2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5606c49cb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5606c49b3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5606c49de112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f20a8362082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5606be2d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0xd8,0xa0, Step #5: \003\330\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-8f910d72422b8febb78f9a79fb01a4e4e1bb6133 Step #5: Base64: A9ig Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 354 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1949286381 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cfa100f810, 0x55cfa11f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cfa11f9020,0x55cfa30910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8f910d72422b8febb78f9a79fb01a4e4e1bb6133' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 374 processed earlier; will process 10655 files now Step #5: ==12778== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cf97b049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cf9e169898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cf9e14c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cf9e14c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cf97b0ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cf97a6bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cf97a66355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cf97afcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cf9aacbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cf9aacbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cf9aacbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cf9aacbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cf9aacbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cf9aacbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cf9aacbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cf9aacbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cf9aacbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cf9aacbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cf9cd60f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cf99a8db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cf99a98be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cf99844c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cf99844c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cf99845738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cf99844874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cf99844874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cf99844874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cf9e14eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cf9e157928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cf9e13f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cf9e16a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbee38ab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cf97a64b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x41,0xc, Step #5: =A\014 Step #5: artifact_prefix='./'; Test unit written to ./oom-caeb05815fe9870d586fa9750e17896c567ec4df Step #5: Base64: PUEM Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 355 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1949700637 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d4c04e810, 0x556d4c23801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d4c238020,0x556d4e0d00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/caeb05815fe9870d586fa9750e17896c567ec4df' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 375 processed earlier; will process 10654 files now Step #5: #1 pulse cov: 3411 ft: 3412 exec/s: 0 rss: 155Mb Step #5: ==12814== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556d42b439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d491a8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d4918b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d4918b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d42b49d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d42aaab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d42aa5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d42b3bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d45b0af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d45b0af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d45b0af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d45b0af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d45b0af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d45b0af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d45b0af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d45b0af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d45b0af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d45b0af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d47d9ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d44accb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d44ad7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d44883c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d44883c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d44884738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d44883874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d44883874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d44883874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d4918dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d49196928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d4917e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d491a9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1bb3dba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d42aa3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbf,0xaf, Step #5: \357\277\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-e84d59f312345d714845b6d1122138692dd9ed5c Step #5: Base64: 77+v Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 356 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1950155907 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56352816e810, 0x56352835801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563528358020,0x56352a1f00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e84d59f312345d714845b6d1122138692dd9ed5c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 377 processed earlier; will process 10652 files now Step #5: ==12850== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56351ec639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5635252c8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5635252ab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5635252ab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56351ec69d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56351ebcab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56351ebc5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56351ec5bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563521c2af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563521c2af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563521c2af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563521c2af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563521c2af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563521c2af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563521c2af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563521c2af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563521c2af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563521c2af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563523ebff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563520becb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563520bf7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5635209a3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5635209a3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5635209a4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5635209a3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5635209a3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5635209a3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5635252adabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5635252b6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56352529e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5635252c9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2166420082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56351ebc3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0x80, Step #5: \357\273\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-c00df26e311a87642de8d49e02931e8ba4580709 Step #5: Base64: 77uA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 357 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1950568720 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565324a92810, 0x565324c7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565324c7c020,0x565326b140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c00df26e311a87642de8d49e02931e8ba4580709' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 378 processed earlier; will process 10651 files now Step #5: ==12886== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56531b5879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565321bec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565321bcf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565321bcf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56531b58dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56531b4eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56531b4e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56531b57fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56531e54ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56531e54ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56531e54ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56531e54ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56531e54ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56531e54ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56531e54ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56531e54ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56531e54ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56531e54ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5653207e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56531d510b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56531d51bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56531d2c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56531d2c7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56531d2c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56531d2c7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56531d2c7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56531d2c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565321bd1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565321bda928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565321bc2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565321bed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f834f2df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56531b4e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x19,0x28, Step #5: (\031( Step #5: artifact_prefix='./'; Test unit written to ./oom-5c008390d12e7bb5f5dadf2d9852588b437a46e8 Step #5: Base64: KBko Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 358 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1950984655 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555851237810, 0x55585142101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555851421020,0x5558532b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c008390d12e7bb5f5dadf2d9852588b437a46e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 379 processed earlier; will process 10650 files now Step #5: ==12922== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555847d2c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55584e391898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55584e3745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55584e3744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555847d32d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555847c93b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555847c8e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555847d24c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55584acf3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55584acf3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55584acf3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55584acf3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55584acf3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55584acf3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55584acf3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55584acf3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55584acf3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55584acf3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55584cf88f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555849cb5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555849cc0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555849a6cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555849a6cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555849a6d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555849a6c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555849a6c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555849a6c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55584e376abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55584e37f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55584e367699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55584e392112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0a2d4c8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555847c8cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0xda,0xaf, Step #5: !\332\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-e5662fe7d30ba65400bbd2023c42a3abbfba8010 Step #5: Base64: Idqv Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 359 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1951399105 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55621c97c810, 0x55621cb6601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55621cb66020,0x55621e9fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e5662fe7d30ba65400bbd2023c42a3abbfba8010' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 380 processed earlier; will process 10649 files now Step #5: ==12958== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5562134719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556219ad6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556219ab95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556219ab94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556213477d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5562133d8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5562133d3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556213469c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556216438f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556216438f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556216438f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556216438f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556216438f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556216438f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556216438f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556216438f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556216438f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556216438f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5562186cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5562153fab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556215405be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5562151b1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5562151b1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5562151b2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5562151b1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5562151b1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5562151b1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556219abbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556219ac4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556219aac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556219ad7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcd87036082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5562133d1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe5,0xa6,0xb5, Step #5: \345\246\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-fdb6ce762cfd47e0c666496e9e85c8824ce31042 Step #5: Base64: 5aa1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 360 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1951818744 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d8e8302810, 0x55d8e84ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d8e84ec020,0x55d8ea3840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fdb6ce762cfd47e0c666496e9e85c8824ce31042' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 381 processed earlier; will process 10648 files now Step #5: ==12994== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d8dedf79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d8e545c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d8e543f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d8e543f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d8dedfdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d8ded5eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d8ded59355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d8dedefc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d8e1dbef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d8e1dbef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d8e1dbef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d8e1dbef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d8e1dbef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d8e1dbef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d8e1dbef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d8e1dbef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d8e1dbef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d8e1dbef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d8e4053f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d8e0d80b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d8e0d8bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d8e0b37c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d8e0b37c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d8e0b38738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d8e0b37874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d8e0b37874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d8e0b37874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d8e5441abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d8e544a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d8e5432699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d8e545d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fefcd686082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d8ded57b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x31,0x20, Step #5: =1 Step #5: artifact_prefix='./'; Test unit written to ./oom-ed3c2345ab243ef922a635f253c605e69f382487 Step #5: Base64: PTEg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 361 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1952234554 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e2f8399810, 0x55e2f858301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e2f8583020,0x55e2fa41b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ed3c2345ab243ef922a635f253c605e69f382487' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 382 processed earlier; will process 10647 files now Step #5: ==13030== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e2eee8e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e2f54f3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e2f54d65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e2f54d64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e2eee94d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e2eedf5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e2eedf0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e2eee86c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e2f1e55f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e2f1e55f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e2f1e55f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e2f1e55f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e2f1e55f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e2f1e55f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e2f1e55f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e2f1e55f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e2f1e55f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e2f1e55f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e2f40eaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e2f0e17b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e2f0e22be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e2f0bcec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e2f0bcec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e2f0bcf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e2f0bce874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e2f0bce874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e2f0bce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e2f54d8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e2f54e1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e2f54c9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e2f54f4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b3a342082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e2eedeeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xea,0xae,0x8d, Step #5: \352\256\215 Step #5: artifact_prefix='./'; Test unit written to ./oom-5df7a4e014c148a089b5ce0e5a479d00766b4944 Step #5: Base64: 6q6N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 362 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1952649521 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca4cb0a810, 0x55ca4ccf401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca4ccf4020,0x55ca4eb8c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5df7a4e014c148a089b5ce0e5a479d00766b4944' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 383 processed earlier; will process 10646 files now Step #5: ==13066== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ca435ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca49c64898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca49c475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca49c474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca43605d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca43566b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca43561355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca435f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca465c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca465c6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca465c6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca465c6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca465c6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca465c6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca465c6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca465c6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca465c6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca465c6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca4885bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca45588b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca45593be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca4533fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca4533fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca45340738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca4533f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca4533f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca4533f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca49c49abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca49c52928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca49c3a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca49c65112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7eae3fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca4355fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa, Step #5: \012\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-7c338ed2840d2bf55f9f5e4eed04f66c80840eb3 Step #5: Base64: CgoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 363 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1953054925 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f941389810, 0x55f94157301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f941573020,0x55f94340b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7c338ed2840d2bf55f9f5e4eed04f66c80840eb3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 384 processed earlier; will process 10645 files now Step #5: ==13102== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f937e7e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f93e4e3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f93e4c65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f93e4c64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f937e84d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f937de5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f937de0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f937e76c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f93ae45f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f93ae45f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f93ae45f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f93ae45f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f93ae45f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f93ae45f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f93ae45f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f93ae45f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f93ae45f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f93ae45f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f93d0daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f939e07b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f939e12be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f939bbec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f939bbec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f939bbf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f939bbe874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f939bbe874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f939bbe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f93e4c8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f93e4d1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f93e4b9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f93e4e4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fef74119082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f937ddeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x93,0x86, Step #5: \342\223\206 Step #5: artifact_prefix='./'; Test unit written to ./oom-7261f3dce28bb395b7739643ededd00871c23700 Step #5: Base64: 4pOG Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 364 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1953485683 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a804bd5810, 0x55a804dbf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a804dbf020,0x55a806c570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7261f3dce28bb395b7739643ededd00871c23700' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 385 processed earlier; will process 10644 files now Step #5: ==13138== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a7fb6ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a801d2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a801d125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a801d124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a7fb6d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a7fb631b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a7fb62c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a7fb6c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a7fe691f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a7fe691f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a7fe691f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a7fe691f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a7fe691f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a7fe691f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a7fe691f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a7fe691f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a7fe691f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a7fe691f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a800926f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a7fd653b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a7fd65ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a7fd40ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a7fd40ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a7fd40b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a7fd40a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a7fd40a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a7fd40a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a801d14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a801d1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a801d05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a801d30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8857918082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a7fb62ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbc,0x80, Step #5: \357\274\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-1336e6cbf2212d03b8c9da2dff69468b65bce75f Step #5: Base64: 77yA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 365 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1953908473 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5646b99e4810, 0x5646b9bce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5646b9bce020,0x5646bba660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1336e6cbf2212d03b8c9da2dff69468b65bce75f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 386 processed earlier; will process 10643 files now Step #5: #1 pulse cov: 3645 ft: 3646 exec/s: 0 rss: 153Mb Step #5: ==13174== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5646b04d99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5646b6b3e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5646b6b215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5646b6b214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5646b04dfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5646b0440b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5646b043b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5646b04d1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5646b34a0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5646b34a0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5646b34a0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5646b34a0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5646b34a0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5646b34a0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5646b34a0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5646b34a0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5646b34a0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5646b34a0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5646b5735f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5646b2462b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5646b246dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5646b2219c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5646b2219c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5646b221a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5646b2219874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5646b2219874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5646b2219874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5646b6b23abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5646b6b2c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5646b6b14699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5646b6b3f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3c0524082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5646b0439b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x34,0x34,0x2e, Step #5: 44. Step #5: artifact_prefix='./'; Test unit written to ./oom-64eeec06517452f9678c49c78ffb700864e357d0 Step #5: Base64: NDQu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 366 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1954367625 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f346bb8810, 0x55f346da201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f346da2020,0x55f348c3a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/64eeec06517452f9678c49c78ffb700864e357d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 388 processed earlier; will process 10641 files now Step #5: ==13210== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f33d6ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f343d12898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f343cf55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f343cf54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f33d6b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f33d614b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f33d60f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f33d6a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f340674f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f340674f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f340674f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f340674f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f340674f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f340674f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f340674f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f340674f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f340674f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f340674f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f342909f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f33f636b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f33f641be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f33f3edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f33f3edc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f33f3ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f33f3ed874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f33f3ed874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f33f3ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f343cf7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f343d00928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f343ce8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f343d13112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbad008f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f33d60db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x9f,0xb6, Step #5: \341\237\266 Step #5: artifact_prefix='./'; Test unit written to ./oom-d8557607dbe5a8c137edb1dcb27352280d291991 Step #5: Base64: 4Z+2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 367 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1954786027 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cba4153810, 0x55cba433d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cba433d020,0x55cba61d50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d8557607dbe5a8c137edb1dcb27352280d291991' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 389 processed earlier; will process 10640 files now Step #5: ==13246== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cb9ac489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cba12ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cba12905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cba12904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb9ac4ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb9abafb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb9abaa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb9ac40c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb9dc0ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb9dc0ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb9dc0ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb9dc0ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb9dc0ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb9dc0ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb9dc0ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb9dc0ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb9dc0ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb9dc0ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb9fea4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb9cbd1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb9cbdcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb9c988c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb9c988c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb9c989738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb9c988874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb9c988874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb9c988874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cba1292abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cba129b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cba1283699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cba12ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f284fa33082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb9aba8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0xf2, Step #5: - \362 Step #5: artifact_prefix='./'; Test unit written to ./oom-26ead1b8ebe3d0c6510633831076782dea517918 Step #5: Base64: LSDy Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 368 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1955203208 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5597179c3810, 0x559717bad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559717bad020,0x559719a450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/26ead1b8ebe3d0c6510633831076782dea517918' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 390 processed earlier; will process 10639 files now Step #5: ==13282== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55970e4b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559714b1d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559714b005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559714b004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55970e4bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55970e41fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55970e41a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55970e4b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55971147ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55971147ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55971147ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55971147ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55971147ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55971147ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55971147ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55971147ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55971147ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55971147ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559713714f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559710441b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55971044cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5597101f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5597101f8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5597101f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5597101f8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5597101f8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5597101f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559714b02abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559714b0b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559714af3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559714b1e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc543f55082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55970e418b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0x94,0x8c, Step #5: \357\224\214 Step #5: artifact_prefix='./'; Test unit written to ./oom-e04dfbebb77d915e70035eac974edf1cff68eb18 Step #5: Base64: 75SM Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 369 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1955616114 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aef4f92810, 0x55aef517c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aef517c020,0x55aef70140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e04dfbebb77d915e70035eac974edf1cff68eb18' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 391 processed earlier; will process 10638 files now Step #5: ==13318== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55aeeba879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aef20ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aef20cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aef20cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aeeba8dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aeeb9eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aeeb9e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aeeba7fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aeeea4ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aeeea4ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aeeea4ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aeeea4ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aeeea4ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aeeea4ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aeeea4ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aeeea4ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aeeea4ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aeeea4ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aef0ce3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aeeda10b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aeeda1bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aeed7c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aeed7c7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aeed7c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aeed7c7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aeed7c7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aeed7c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aef20d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aef20da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aef20c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aef20ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f966e01c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aeeb9e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xb7,0x8a, Step #5: \340\267\212 Step #5: artifact_prefix='./'; Test unit written to ./oom-c0d5c866b45b34ec6519f419498b172b17cff96a Step #5: Base64: 4LeK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 370 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1956031101 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56014d262810, 0x56014d44c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56014d44c020,0x56014f2e40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c0d5c866b45b34ec6519f419498b172b17cff96a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 392 processed earlier; will process 10637 files now Step #5: ==13354== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560143d579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56014a3bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56014a39f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56014a39f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560143d5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560143cbeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560143cb9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560143d4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560146d1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560146d1ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560146d1ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560146d1ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560146d1ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560146d1ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560146d1ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560146d1ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560146d1ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560146d1ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560148fb3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560145ce0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560145cebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560145a97c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560145a97c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560145a98738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560145a97874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560145a97874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560145a97874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56014a3a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56014a3aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56014a392699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56014a3bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe172877082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560143cb7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0xd,0x2d, Step #5: ?\015- Step #5: artifact_prefix='./'; Test unit written to ./oom-5646ba0f8050984c4a52b72e8342e44993361274 Step #5: Base64: Pw0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 371 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1956447418 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55661129e810, 0x55661148801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556611488020,0x5566133200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5646ba0f8050984c4a52b72e8342e44993361274' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 393 processed earlier; will process 10636 files now Step #5: ==13390== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556607d939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55660e3f8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55660e3db5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55660e3db4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556607d99d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556607cfab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556607cf5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556607d8bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55660ad5af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55660ad5af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55660ad5af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55660ad5af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55660ad5af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55660ad5af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55660ad5af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55660ad5af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55660ad5af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55660ad5af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55660cfeff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556609d1cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556609d27be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556609ad3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556609ad3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556609ad4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556609ad3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556609ad3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556609ad3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55660e3ddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55660e3e6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55660e3ce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55660e3f9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9141e83082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556607cf3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x63,0x66, Step #5: Dcf Step #5: artifact_prefix='./'; Test unit written to ./oom-4d21a1fbb7ea0a55948e09e6f7175e6690a4091e Step #5: Base64: RGNm Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 372 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1956861200 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ef6c043810, 0x55ef6c22d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ef6c22d020,0x55ef6e0c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4d21a1fbb7ea0a55948e09e6f7175e6690a4091e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 394 processed earlier; will process 10635 files now Step #5: ==13426== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ef62b389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ef6919d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ef691805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ef691804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef62b3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef62a9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef62a9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef62b30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef65afff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef65afff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef65afff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef65afff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef65afff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef65afff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef65afff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef65afff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef65afff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef65afff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef67d94f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef64ac1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef64accbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef64878c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef64878c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef64879738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef64878874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef64878874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef64878874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ef69182abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ef6918b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ef69173699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ef6919e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a160ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef62a98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x46,0xa, Step #5: PF\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-07b0efa9272db9b1e8f1d01d21b583d6047e0d31 Step #5: Base64: UEYK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 373 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1957273919 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f16c42810, 0x556f16e2c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f16e2c020,0x556f18cc40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/07b0efa9272db9b1e8f1d01d21b583d6047e0d31' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 395 processed earlier; will process 10634 files now Step #5: ==13462== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556f0d7379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f13d9c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f13d7f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f13d7f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f0d73dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f0d69eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f0d699355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f0d72fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f106fef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f106fef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f106fef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f106fef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f106fef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f106fef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f106fef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f106fef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f106fef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f106fef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f12993f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f0f6c0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f0f6cbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f0f477c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f0f477c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f0f478738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f0f477874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f0f477874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f0f477874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f13d81abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f13d8a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f13d72699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f13d9d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8914fe6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f0d697b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x48,0xa, Step #5: PH\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-71335cc7ebca4b18ce1cba933e743024aa43960d Step #5: Base64: UEgK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 374 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1957694875 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5622303b9810, 0x5622305a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622305a3020,0x56223243b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/71335cc7ebca4b18ce1cba933e743024aa43960d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 396 processed earlier; will process 10633 files now Step #5: ==13498== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562226eae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56222d513898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56222d4f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56222d4f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562226eb4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562226e15b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562226e10355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562226ea6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562229e75f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562229e75f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562229e75f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562229e75f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562229e75f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562229e75f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562229e75f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562229e75f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562229e75f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562229e75f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56222c10af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562228e37b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562228e42be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562228beec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562228beec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562228bef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562228bee874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562228bee874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562228bee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56222d4f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56222d501928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56222d4e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56222d514112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff37e52f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562226e0eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x54,0x75,0x65, Step #5: Tue Step #5: artifact_prefix='./'; Test unit written to ./oom-529541bb390c76152e313351d89de3cd30a1c4bd Step #5: Base64: VHVl Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 375 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1958107625 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560d2518b810, 0x560d2537501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560d25375020,0x560d2720d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/529541bb390c76152e313351d89de3cd30a1c4bd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 397 processed earlier; will process 10632 files now Step #5: ==13534== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560d1bc809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560d222e5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560d222c85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560d222c84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560d1bc86d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560d1bbe7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560d1bbe2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560d1bc78c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560d1ec47f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560d1ec47f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560d1ec47f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560d1ec47f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560d1ec47f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560d1ec47f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560d1ec47f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560d1ec47f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560d1ec47f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560d1ec47f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560d20edcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560d1dc09b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560d1dc14be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560d1d9c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560d1d9c0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560d1d9c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560d1d9c0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560d1d9c0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560d1d9c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560d222caabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560d222d3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560d222bb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560d222e6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1e04c50082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560d1bbe0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0x25, Step #5: -\012% Step #5: artifact_prefix='./'; Test unit written to ./oom-003bfc0ec2fccad39afd2df8a0ba377fb4d869a4 Step #5: Base64: LQol Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 376 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1958523404 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b851959810, 0x55b851b4301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b851b43020,0x55b8539db0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/003bfc0ec2fccad39afd2df8a0ba377fb4d869a4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 398 processed earlier; will process 10631 files now Step #5: ==13570== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b84844e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b84eab3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b84ea965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b84ea964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b848454d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b8483b5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b8483b0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b848446c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b84b415f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b84b415f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b84b415f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b84b415f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b84b415f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b84b415f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b84b415f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b84b415f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b84b415f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b84b415f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b84d6aaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b84a3d7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b84a3e2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b84a18ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b84a18ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b84a18f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b84a18e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b84a18e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b84a18e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b84ea98abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b84eaa1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b84ea89699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b84eab4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27b6d87082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b8483aeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x32,0x30, Step #5: 120 Step #5: artifact_prefix='./'; Test unit written to ./oom-775bc5c30e27f0e562115d136e7f7edbd3cead89 Step #5: Base64: MTIw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 377 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1958938898 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558764ce0810, 0x558764eca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558764eca020,0x558766d620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/775bc5c30e27f0e562115d136e7f7edbd3cead89' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 399 processed earlier; will process 10630 files now Step #5: ==13606== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55875b7d59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558761e3a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558761e1d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558761e1d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55875b7dbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55875b73cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55875b737355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55875b7cdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55875e79cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55875e79cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55875e79cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55875e79cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55875e79cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55875e79cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55875e79cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55875e79cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55875e79cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55875e79cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558760a31f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55875d75eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55875d769be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55875d515c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55875d515c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55875d516738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55875d515874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55875d515874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55875d515874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558761e1fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558761e28928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558761e10699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558761e3b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda483c2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55875b735b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1f,0x9,0x8, Step #5: \037\011\010 Step #5: artifact_prefix='./'; Test unit written to ./oom-b864d074de57a489bf665838134146ab63866686 Step #5: Base64: HwkI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 378 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1959353134 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f458944810, 0x55f458b2e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f458b2e020,0x55f45a9c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b864d074de57a489bf665838134146ab63866686' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 400 processed earlier; will process 10629 files now Step #5: ==13642== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f44f4399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f455a9e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f455a815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f455a814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f44f43fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f44f3a0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f44f39b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f44f431c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f452400f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f452400f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f452400f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f452400f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f452400f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f452400f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f452400f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f452400f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f452400f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f452400f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f454695f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4513c2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4513cdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f451179c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f451179c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f45117a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f451179874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f451179874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f451179874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f455a83abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f455a8c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f455a74699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f455a9f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f160374e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f44f399b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0xa6,0xa5, Step #5: \343\246\245 Step #5: artifact_prefix='./'; Test unit written to ./oom-593f253d776e3ed2aef885506b750118acb7bf27 Step #5: Base64: 46al Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 379 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1959768957 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561e77b72810, 0x561e77d5c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561e77d5c020,0x561e79bf40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/593f253d776e3ed2aef885506b750118acb7bf27' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 401 processed earlier; will process 10628 files now Step #5: #1 pulse cov: 3416 ft: 3417 exec/s: 0 rss: 153Mb Step #5: ==13678== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561e6e6679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561e74ccc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561e74caf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561e74caf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561e6e66dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561e6e5ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561e6e5c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561e6e65fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561e7162ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561e7162ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561e7162ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561e7162ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561e7162ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561e7162ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561e7162ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561e7162ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561e7162ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561e7162ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561e738c3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561e705f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561e705fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561e703a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561e703a7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561e703a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561e703a7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561e703a7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561e703a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561e74cb1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561e74cba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561e74ca2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561e74ccd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e7ecd9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561e6e5c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xc8,0x84, Step #5: \"\310\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-097a617768a8397e312b23e7f01f460a4774056c Step #5: Base64: IsiE Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 380 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1960224178 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56377d7b8810, 0x56377d9a201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56377d9a2020,0x56377f83a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/097a617768a8397e312b23e7f01f460a4774056c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 403 processed earlier; will process 10626 files now Step #5: ==13714== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5637742ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56377a912898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56377a8f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56377a8f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5637742b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563774214b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56377420f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5637742a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563777274f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563777274f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563777274f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563777274f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563777274f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563777274f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563777274f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563777274f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563777274f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563777274f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563779509f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563776236b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563776241be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563775fedc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563775fedc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563775fee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563775fed874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563775fed874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563775fed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56377a8f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56377a900928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56377a8e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56377a913112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f92a5569082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56377420db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x80,0x8a, Step #5: \343\200\212 Step #5: artifact_prefix='./'; Test unit written to ./oom-d0569eb8654db05cbe160e3c6957d47fe41037ff Step #5: Base64: 44CK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 381 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1960640127 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f064d1e810, 0x55f064f0801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f064f08020,0x55f066da00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d0569eb8654db05cbe160e3c6957d47fe41037ff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 404 processed earlier; will process 10625 files now Step #5: ==13750== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f05b8139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f061e78898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f061e5b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f061e5b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f05b819d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f05b77ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f05b775355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f05b80bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f05e7daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f05e7daf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f05e7daf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f05e7daf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f05e7daf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f05e7daf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f05e7daf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f05e7daf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f05e7daf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f05e7daf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f060a6ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f05d79cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f05d7a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f05d553c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f05d553c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f05d554738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f05d553874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f05d553874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f05d553874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f061e5dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f061e66928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f061e4e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f061e79112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f79b6c9c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f05b773b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcb,0x91,0xea, Step #5: \313\221\352 Step #5: artifact_prefix='./'; Test unit written to ./oom-dbc68d1839aefe52933d406c8441a441945e3631 Step #5: Base64: y5Hq Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 382 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1961055058 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e5bb4bd810, 0x55e5bb6a701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e5bb6a7020,0x55e5bd53f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dbc68d1839aefe52933d406c8441a441945e3631' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 405 processed earlier; will process 10624 files now Step #5: ==13786== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e5b1fb29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e5b8617898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e5b85fa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e5b85fa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e5b1fb8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e5b1f19b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e5b1f14355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e5b1faac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e5b4f79f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e5b4f79f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e5b4f79f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e5b4f79f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e5b4f79f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e5b4f79f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e5b4f79f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e5b4f79f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e5b4f79f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e5b4f79f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e5b720ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e5b3f3bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e5b3f46be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e5b3cf2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e5b3cf2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e5b3cf3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e5b3cf2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e5b3cf2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e5b3cf2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e5b85fcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e5b8605928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e5b85ed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e5b8618112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbab2cc4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e5b1f12b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6b,0x3f,0x25, Step #5: k?% Step #5: artifact_prefix='./'; Test unit written to ./oom-52b5a226c529f910940343eb6d6d5849a3e56196 Step #5: Base64: az8l Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 383 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1961464376 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563230613810, 0x5632307fd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5632307fd020,0x5632326950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/52b5a226c529f910940343eb6d6d5849a3e56196' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 406 processed earlier; will process 10623 files now Step #5: #1 pulse cov: 3514 ft: 3515 exec/s: 0 rss: 156Mb Step #5: ==13822== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5632271089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56322d76d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56322d7505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56322d7504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56322710ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56322706fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56322706a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563227100c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56322a0cff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56322a0cff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56322a0cff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56322a0cff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56322a0cff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56322a0cff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56322a0cff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56322a0cff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56322a0cff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56322a0cff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56322c364f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563229091b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56322909cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563228e48c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563228e48c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563228e49738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563228e48874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563228e48874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563228e48874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56322d752abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56322d75b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56322d743699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56322d76e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feda1fdb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563227068b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x7e,0x59, Step #5: =~Y Step #5: artifact_prefix='./'; Test unit written to ./oom-1f7e78614e04d03205b460b0b7ad0429d6ded016 Step #5: Base64: PX5Z Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 384 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1961916697 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5560b6a60810, 0x5560b6c4a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5560b6c4a020,0x5560b8ae20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f7e78614e04d03205b460b0b7ad0429d6ded016' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 408 processed earlier; will process 10621 files now Step #5: ==13858== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5560ad5559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5560b3bba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5560b3b9d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5560b3b9d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5560ad55bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5560ad4bcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5560ad4b7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5560ad54dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5560b051cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5560b051cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5560b051cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5560b051cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5560b051cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5560b051cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5560b051cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5560b051cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5560b051cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5560b051cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5560b27b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5560af4deb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5560af4e9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5560af295c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5560af295c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5560af296738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5560af295874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5560af295874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5560af295874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5560b3b9fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5560b3ba8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5560b3b90699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5560b3bbb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f69f7616082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5560ad4b5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x69,0xff, Step #5: Fi\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-6986f376832aa9aa348f0611673246de9fdce2fd Step #5: Base64: Rmn/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 385 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1962327206 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca0fc92810, 0x55ca0fe7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca0fe7c020,0x55ca11d140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6986f376832aa9aa348f0611673246de9fdce2fd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 409 processed earlier; will process 10620 files now Step #5: ==13894== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ca067879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca0cdec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca0cdcf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca0cdcf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca0678dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca066eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca066e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca0677fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca0974ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca0974ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca0974ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca0974ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca0974ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca0974ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca0974ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca0974ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca0974ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca0974ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca0b9e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca08710b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca0871bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca084c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca084c7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca084c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca084c7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca084c7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca084c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca0cdd1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca0cdda928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca0cdc2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca0cded112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d21236082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca066e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0x4e,0x41, Step #5: CNA Step #5: artifact_prefix='./'; Test unit written to ./oom-6dbbc8758b3ede7abc8a9c9c3a490c8246cae39d Step #5: Base64: Q05B Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 386 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1962746024 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb62244810, 0x55eb6242e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb6242e020,0x55eb642c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6dbbc8758b3ede7abc8a9c9c3a490c8246cae39d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 410 processed earlier; will process 10619 files now Step #5: ==13930== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eb58d399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb5f39e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb5f3815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb5f3814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb58d3fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb58ca0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb58c9b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb58d31c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb5bd00f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb5bd00f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb5bd00f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb5bd00f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb5bd00f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb5bd00f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb5bd00f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb5bd00f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb5bd00f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb5bd00f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb5df95f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb5acc2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb5accdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb5aa79c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb5aa79c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb5aa7a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb5aa79874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb5aa79874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb5aa79874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb5f383abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb5f38c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb5f374699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb5f39f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0347f1e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb58c99b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x2d,0xf6, Step #5: -\366 Step #5: artifact_prefix='./'; Test unit written to ./oom-86b7365c36868b040ca4e4caf5446debe0bf52b4 Step #5: Base64: IC32 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 387 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1963159051 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fb6441d810, 0x55fb6460701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fb64607020,0x55fb6649f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/86b7365c36868b040ca4e4caf5446debe0bf52b4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 411 processed earlier; will process 10618 files now Step #5: ==13966== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fb5af129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fb61577898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fb6155a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fb6155a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fb5af18d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fb5ae79b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fb5ae74355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fb5af0ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fb5ded9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fb5ded9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fb5ded9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fb5ded9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fb5ded9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fb5ded9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fb5ded9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fb5ded9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fb5ded9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fb5ded9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fb6016ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fb5ce9bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fb5cea6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fb5cc52c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fb5cc52c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fb5cc53738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fb5cc52874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fb5cc52874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fb5cc52874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fb6155cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fb61565928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fb6154d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fb61578112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe026efb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fb5ae72b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x56, Step #5: \000\000V Step #5: artifact_prefix='./'; Test unit written to ./oom-84fc0d3933a29894a5aa989d712899445e63b48d Step #5: Base64: AABW Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 388 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1963573238 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fb225d9810, 0x55fb227c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fb227c3020,0x55fb2465b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/84fc0d3933a29894a5aa989d712899445e63b48d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 412 processed earlier; will process 10617 files now Step #5: ==14002== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fb190ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fb1f733898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fb1f7165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fb1f7164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fb190d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fb19035b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fb19030355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fb190c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fb1c095f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fb1c095f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fb1c095f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fb1c095f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fb1c095f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fb1c095f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fb1c095f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fb1c095f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fb1c095f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fb1c095f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fb1e32af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fb1b057b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fb1b062be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fb1ae0ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fb1ae0ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fb1ae0f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fb1ae0e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fb1ae0e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fb1ae0e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fb1f718abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fb1f721928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fb1f709699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fb1f734112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d31451082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fb1902eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0xc2,0xb4, Step #5: %\302\264 Step #5: artifact_prefix='./'; Test unit written to ./oom-e28630c1dc572c0715aac7d46e2357dc59da7e3e Step #5: Base64: JcK0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 389 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1963986988 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564385592810, 0x56438577c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56438577c020,0x5643876140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e28630c1dc572c0715aac7d46e2357dc59da7e3e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 413 processed earlier; will process 10616 files now Step #5: ==14038== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56437c0879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643826ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643826cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643826cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56437c08dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56437bfeeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56437bfe9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56437c07fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56437f04ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56437f04ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56437f04ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56437f04ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56437f04ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56437f04ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56437f04ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56437f04ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56437f04ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56437f04ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643812e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56437e010b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56437e01bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56437ddc7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56437ddc7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56437ddc8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56437ddc7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56437ddc7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56437ddc7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643826d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643826da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643826c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643826ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f640b42e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56437bfe7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x33,0x22, Step #5: P3\" Step #5: artifact_prefix='./'; Test unit written to ./oom-8078dc5ffb120df0873e26a2548a587d8059debb Step #5: Base64: UDMi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 390 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1964398203 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a013a5e810, 0x55a013c4801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a013c48020,0x55a015ae00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8078dc5ffb120df0873e26a2548a587d8059debb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 414 processed earlier; will process 10615 files now Step #5: ==14074== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a00a5539c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a010bb8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a010b9b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a010b9b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a00a559d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a00a4bab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a00a4b5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a00a54bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a00d51af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a00d51af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a00d51af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a00d51af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a00d51af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a00d51af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a00d51af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a00d51af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a00d51af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a00d51af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a00f7aff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a00c4dcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a00c4e7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a00c293c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a00c293c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a00c294738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a00c293874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a00c293874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a00c293874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a010b9dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a010ba6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a010b8e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a010bb9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feb252e8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a00a4b3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x1,0xa, Step #5: \012\001\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-306673d47b0f3bedaf52b95e75d9f40ebd5a18e7 Step #5: Base64: CgEK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 391 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1964816834 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c67d40810, 0x561c67f2a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c67f2a020,0x561c69dc20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/306673d47b0f3bedaf52b95e75d9f40ebd5a18e7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 415 processed earlier; will process 10614 files now Step #5: ==14110== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561c5e8359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c64e9a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c64e7d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c64e7d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c5e83bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c5e79cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c5e797355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c5e82dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c617fcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c617fcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c617fcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c617fcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c617fcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c617fcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c617fcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c617fcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c617fcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c617fcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c63a91f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c607beb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c607c9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c60575c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c60575c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c60576738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c60575874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c60575874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c60575874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c64e7fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c64e88928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c64e70699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c64e9b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb99210e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c5e795b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0x33,0xe1, Step #5: 23\341 Step #5: artifact_prefix='./'; Test unit written to ./oom-d993bb7e2cae96a0d157d89e87d8eaa48b1b04b7 Step #5: Base64: MjPh Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 392 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1965228845 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b6cc79810, 0x561b6ce6301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b6ce63020,0x561b6ecfb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d993bb7e2cae96a0d157d89e87d8eaa48b1b04b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 416 processed earlier; will process 10613 files now Step #5: ==14146== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561b6376e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b69dd3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b69db65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b69db64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b63774d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b636d5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b636d0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b63766c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b66735f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b66735f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b66735f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b66735f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b66735f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b66735f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b66735f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b66735f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b66735f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b66735f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b689caf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b656f7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b65702be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b654aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b654aec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b654af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b654ae874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b654ae874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b654ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b69db8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b69dc1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b69da9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b69dd4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4efe151082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b636ceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x36,0x5f,0x32, Step #5: 6_2 Step #5: artifact_prefix='./'; Test unit written to ./oom-730feb7544e8ec19d790ceacb33fced413b7492d Step #5: Base64: Nl8y Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 393 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1965643452 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd663ae810, 0x55dd6659801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd66598020,0x55dd684300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/730feb7544e8ec19d790ceacb33fced413b7492d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 417 processed earlier; will process 10612 files now Step #5: ==14182== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dd5cea39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd63508898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd634eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd634eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dd5cea9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dd5ce0ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dd5ce05355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dd5ce9bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd5fe6af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd5fe6af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd5fe6af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd5fe6af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd5fe6af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd5fe6af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd5fe6af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd5fe6af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd5fe6af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd5fe6af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd620fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dd5ee2cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dd5ee37be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dd5ebe3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dd5ebe3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dd5ebe4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dd5ebe3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dd5ebe3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dd5ebe3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd634edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd634f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd634de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd63509112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f63742be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dd5ce03b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe4,0xa6,0xa5, Step #5: \344\246\245 Step #5: artifact_prefix='./'; Test unit written to ./oom-5e142f0e41e101a2ffef0a37c26943f53fbea3d7 Step #5: Base64: 5Kal Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 394 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1966061376 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a8b269810, 0x555a8b45301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a8b453020,0x555a8d2eb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e142f0e41e101a2ffef0a37c26943f53fbea3d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 418 processed earlier; will process 10611 files now Step #5: ==14218== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555a81d5e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a883c3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a883a65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a883a64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a81d64d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a81cc5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a81cc0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a81d56c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a84d25f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a84d25f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a84d25f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a84d25f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a84d25f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a84d25f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a84d25f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a84d25f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a84d25f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a84d25f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a86fbaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a83ce7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a83cf2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a83a9ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a83a9ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a83a9f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a83a9e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a83a9e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a83a9e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a883a8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a883b1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a88399699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a883c4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8be8fa0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a81cbeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x74,0x6b, Step #5: ttk Step #5: artifact_prefix='./'; Test unit written to ./oom-858be7b4473a529555819a7c77ccf9358db2f00e Step #5: Base64: dHRr Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 395 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1966475770 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d8b20c810, 0x564d8b3f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d8b3f6020,0x564d8d28e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/858be7b4473a529555819a7c77ccf9358db2f00e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 419 processed earlier; will process 10610 files now Step #5: ==14254== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564d81d019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d88366898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d883495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d883494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d81d07d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d81c68b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d81c63355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d81cf9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d84cc8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d84cc8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d84cc8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d84cc8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d84cc8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d84cc8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d84cc8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d84cc8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d84cc8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d84cc8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d86f5df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d83c8ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d83c95be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d83a41c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d83a41c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d83a42738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d83a41874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d83a41874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d83a41874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d8834babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d88354928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d8833c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d88367112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc6d283b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d81c61b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3d,0x3f, Step #5: <=? Step #5: artifact_prefix='./'; Test unit written to ./oom-f7b62011a4ee56a3ecd16469b80d7a977eec175e Step #5: Base64: PD0/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 396 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1966892729 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f4a25d8810, 0x55f4a27c201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f4a27c2020,0x55f4a465a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7b62011a4ee56a3ecd16469b80d7a977eec175e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 420 processed earlier; will process 10609 files now Step #5: ==14290== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f4990cd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f49f732898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f49f7155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f49f7154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f4990d3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f499034b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f49902f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f4990c5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f49c094f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f49c094f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f49c094f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f49c094f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f49c094f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f49c094f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f49c094f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f49c094f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f49c094f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f49c094f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f49e329f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f49b056b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f49b061be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f49ae0dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f49ae0dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f49ae0e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f49ae0d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f49ae0d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f49ae0d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f49f717abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f49f720928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f49f708699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f49f733112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53d7e6f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f49902db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x4d,0xbc, Step #5: IM\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-02a0a8b32a77218b3d01a51bca023d978ac7f5bb Step #5: Base64: SU28 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 397 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1967308929 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56219fccb810, 0x56219feb501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56219feb5020,0x5621a1d4d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/02a0a8b32a77218b3d01a51bca023d978ac7f5bb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 421 processed earlier; will process 10608 files now Step #5: ==14326== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5621967c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56219ce25898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56219ce085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56219ce084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5621967c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562196727b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562196722355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5621967b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562199787f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562199787f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562199787f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562199787f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562199787f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562199787f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562199787f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562199787f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562199787f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562199787f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56219ba1cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562198749b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562198754be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562198500c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562198500c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562198501738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562198500874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562198500874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562198500874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56219ce0aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56219ce13928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56219cdfb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56219ce26112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efcae24e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562196720b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x2d,0x2d, Step #5: \001-- Step #5: artifact_prefix='./'; Test unit written to ./oom-ddb5ada3772610b10a382947a8239fac4eb573cf Step #5: Base64: AS0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 398 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1967731596 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b2331a5810, 0x55b23338f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b23338f020,0x55b2352270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ddb5ada3772610b10a382947a8239fac4eb573cf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 422 processed earlier; will process 10607 files now Step #5: ==14362== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b229c9a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b2302ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b2302e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b2302e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b229ca0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b229c01b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b229bfc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b229c92c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b22cc61f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b22cc61f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b22cc61f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b22cc61f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b22cc61f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b22cc61f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b22cc61f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b22cc61f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b22cc61f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b22cc61f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b22eef6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b22bc23b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b22bc2ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b22b9dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b22b9dac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b22b9db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b22b9da874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b22b9da874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b22b9da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b2302e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b2302ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b2302d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b230300112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f771758a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b229bfab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x5e,0x5e, Step #5: ^^^ Step #5: artifact_prefix='./'; Test unit written to ./oom-6ef0bd1a89cb34a4cb33d6dd21fe8d1091189612 Step #5: Base64: Xl5e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 399 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1968151649 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560210aa2810, 0x560210c8c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560210c8c020,0x560212b240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ef0bd1a89cb34a4cb33d6dd21fe8d1091189612' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 423 processed earlier; will process 10606 files now Step #5: ==14398== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5602075979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56020dbfc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56020dbdf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56020dbdf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56020759dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5602074feb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5602074f9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56020758fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56020a55ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56020a55ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56020a55ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56020a55ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56020a55ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56020a55ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56020a55ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56020a55ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56020a55ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56020a55ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56020c7f3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560209520b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56020952bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5602092d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5602092d7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5602092d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5602092d7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5602092d7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5602092d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56020dbe1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56020dbea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56020dbd2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56020dbfd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f80a2a9b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5602074f7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0x23,0x76, Step #5: &#v Step #5: artifact_prefix='./'; Test unit written to ./oom-e1e8a2059dbee5df172732c740103c3da1b7eb19 Step #5: Base64: JiN2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 400 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1968573547 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb01111810, 0x55cb012fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb012fb020,0x55cb031930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e1e8a2059dbee5df172732c740103c3da1b7eb19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 424 processed earlier; will process 10605 files now Step #5: ==14434== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55caf7c069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cafe26b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cafe24e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cafe24e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55caf7c0cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55caf7b6db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55caf7b68355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55caf7bfec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cafabcdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cafabcdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cafabcdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cafabcdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cafabcdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cafabcdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cafabcdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cafabcdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cafabcdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cafabcdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cafce62f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55caf9b8fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55caf9b9abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55caf9946c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55caf9946c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55caf9947738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55caf9946874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55caf9946874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55caf9946874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cafe250abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cafe259928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cafe241699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cafe26c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ee5689082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55caf7b66b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xb7,0xb7, Step #5: \341\267\267 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf15ba4f788fd5419e44252af00b1d38e0b186d5 Step #5: Base64: 4be3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 401 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1968995502 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5604e8b52810, 0x5604e8d3c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604e8d3c020,0x5604eabd40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf15ba4f788fd5419e44252af00b1d38e0b186d5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 425 processed earlier; will process 10604 files now Step #5: ==14470== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5604df6479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5604e5cac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5604e5c8f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5604e5c8f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5604df64dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5604df5aeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5604df5a9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5604df63fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5604e260ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5604e260ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5604e260ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5604e260ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5604e260ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5604e260ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5604e260ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5604e260ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5604e260ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5604e260ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5604e48a3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5604e15d0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5604e15dbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5604e1387c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5604e1387c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5604e1388738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5604e1387874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5604e1387874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5604e1387874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5604e5c91abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5604e5c9a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5604e5c82699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5604e5cad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdfe3529082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5604df5a7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x66,0x56, Step #5: =fV Step #5: artifact_prefix='./'; Test unit written to ./oom-1beb7991152365516ee0aee7ac9c226e31e3e8cb Step #5: Base64: PWZW Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 402 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1969414935 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d0051c8810, 0x55d0053b201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d0053b2020,0x55d00724a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1beb7991152365516ee0aee7ac9c226e31e3e8cb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 426 processed earlier; will process 10603 files now Step #5: #1 pulse cov: 3468 ft: 3469 exec/s: 0 rss: 155Mb Step #5: ==14506== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cffbcbd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d002322898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d0023055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d0023054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cffbcc3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cffbc24b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cffbc1f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cffbcb5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cffec84f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cffec84f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cffec84f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cffec84f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cffec84f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cffec84f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cffec84f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cffec84f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cffec84f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cffec84f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d000f19f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cffdc46b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cffdc51be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cffd9fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cffd9fdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cffd9fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cffd9fd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cffd9fd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cffd9fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d002307abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d002310928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d0022f8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d002323112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4764e11082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cffbc1db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7a,0x6f,0x6e,0x65, Step #5: zone Step #5: artifact_prefix='./'; Test unit written to ./oom-b6931b00fd5c406edb24c0ed02274408e63555a0 Step #5: Base64: em9uZQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 403 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1969880326 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5557e6a50810, 0x5557e6c3a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5557e6c3a020,0x5557e8ad20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b6931b00fd5c406edb24c0ed02274408e63555a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 428 processed earlier; will process 10601 files now Step #5: ==14542== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5557dd5459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5557e3baa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557e3b8d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557e3b8d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557dd54bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557dd4acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5557dd4a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557dd53dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557e050cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557e050cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557e050cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557e050cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557e050cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557e050cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557e050cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557e050cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557e050cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557e050cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5557e27a1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557df4ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557df4d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5557df285c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5557df285c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5557df286738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5557df285874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5557df285874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5557df285874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557e3b8fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557e3b98928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557e3b80699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5557e3bab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc5b8b66082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5557dd4a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf4,0x8f,0xab,0xab, Step #5: \364\217\253\253 Step #5: artifact_prefix='./'; Test unit written to ./oom-7197b2ac957e0a9567021073758a6c1553e07d3f Step #5: Base64: 9I+rqw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 404 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1970298449 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563afe562810, 0x563afe74c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563afe74c020,0x563b005e40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7197b2ac957e0a9567021073758a6c1553e07d3f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 429 processed earlier; will process 10600 files now Step #5: ==14578== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563af50579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563afb6bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563afb69f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563afb69f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563af505dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563af4fbeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563af4fb9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563af504fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563af801ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563af801ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563af801ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563af801ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563af801ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563af801ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563af801ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563af801ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563af801ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563af801ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563afa2b3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563af6fe0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563af6febbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563af6d97c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563af6d97c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563af6d98738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563af6d97874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563af6d97874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563af6d97874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563afb6a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563afb6aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563afb692699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563afb6bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ef1de6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563af4fb7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x27,0x5c,0xf9, Step #5: e'\\\371 Step #5: artifact_prefix='./'; Test unit written to ./oom-92919652ea3c54a2c522c8ed46231c8c838a128f Step #5: Base64: ZSdc+Q== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 405 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1970719313 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5637f7e03810, 0x5637f7fed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5637f7fed020,0x5637f9e850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92919652ea3c54a2c522c8ed46231c8c838a128f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 430 processed earlier; will process 10599 files now Step #5: ==14614== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5637ee8f89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5637f4f5d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5637f4f405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5637f4f404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5637ee8fed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5637ee85fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5637ee85a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5637ee8f0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5637f18bff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5637f18bff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5637f18bff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5637f18bff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5637f18bff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5637f18bff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5637f18bff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5637f18bff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5637f18bff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5637f18bff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5637f3b54f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5637f0881b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5637f088cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5637f0638c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5637f0638c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5637f0639738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5637f0638874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5637f0638874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5637f0638874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5637f4f42abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5637f4f4b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5637f4f33699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5637f4f5e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53a1a01082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5637ee858b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0x31,0x32,0x38, Step #5: 2128 Step #5: artifact_prefix='./'; Test unit written to ./oom-78c217d6e87dedb3ff90a522b3b1f9879145c39b Step #5: Base64: MjEyOA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 406 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1971146437 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d5ae75810, 0x561d5b05f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d5b05f020,0x561d5cef70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/78c217d6e87dedb3ff90a522b3b1f9879145c39b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 431 processed earlier; will process 10598 files now Step #5: ==14650== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561d5196a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d57fcf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d57fb25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d57fb24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d51970d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d518d1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d518cc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d51962c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d54931f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d54931f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d54931f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d54931f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d54931f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d54931f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d54931f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d54931f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d54931f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d54931f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d56bc6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d538f3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d538febe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d536aac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d536aac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d536ab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d536aa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d536aa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d536aa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d57fb4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d57fbd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d57fa5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d57fd0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f33c2f6a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d518cab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x7a,0x8e,0x2e, Step #5: sz\216. Step #5: artifact_prefix='./'; Test unit written to ./oom-87a0c8114db3fd16f76c9f58ce72e9eaa3373496 Step #5: Base64: c3qOLg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 407 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1971561395 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e6a23f8810, 0x55e6a25e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e6a25e2020,0x55e6a447a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87a0c8114db3fd16f76c9f58ce72e9eaa3373496' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 432 processed earlier; will process 10597 files now Step #5: ==14686== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e698eed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e69f552898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e69f5355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e69f5354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e698ef3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e698e54b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e698e4f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e698ee5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e69beb4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e69beb4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e69beb4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e69beb4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e69beb4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e69beb4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e69beb4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e69beb4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e69beb4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e69beb4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e69e149f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e69ae76b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e69ae81be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e69ac2dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e69ac2dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e69ac2e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e69ac2d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e69ac2d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e69ac2d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e69f537abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e69f540928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e69f528699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e69f553112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f688941c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e698e4db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x12,0x0,0x42,0x0, Step #5: \022\000B\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f20bf478f9f4a97eecef94be455464f17c55ea4b Step #5: Base64: EgBCAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 408 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1971985933 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559bd95f5810, 0x559bd97df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559bd97df020,0x559bdb6770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f20bf478f9f4a97eecef94be455464f17c55ea4b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 433 processed earlier; will process 10596 files now Step #5: ==14722== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559bd00ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559bd674f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559bd67325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559bd67324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559bd00f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559bd0051b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559bd004c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559bd00e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559bd30b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559bd30b1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559bd30b1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559bd30b1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559bd30b1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559bd30b1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559bd30b1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559bd30b1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559bd30b1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559bd30b1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559bd5346f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559bd2073b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559bd207ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559bd1e2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559bd1e2ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559bd1e2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559bd1e2a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559bd1e2a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559bd1e2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559bd6734abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559bd673d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559bd6725699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559bd6750112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f59f192f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559bd004ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc,0xc,0xc,0xc, Step #5: \014\014\014\014 Step #5: artifact_prefix='./'; Test unit written to ./oom-28f40c9ade49b97b030a35a36f2e0f4c7c3a08f1 Step #5: Base64: DAwMDA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 409 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1972400243 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ad702a810, 0x562ad721401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ad7214020,0x562ad90ac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/28f40c9ade49b97b030a35a36f2e0f4c7c3a08f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 434 processed earlier; will process 10595 files now Step #5: ==14758== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562acdb1f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ad4184898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ad41675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ad41674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562acdb25d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562acda86b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562acda81355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562acdb17c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ad0ae6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ad0ae6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ad0ae6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ad0ae6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ad0ae6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ad0ae6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ad0ae6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ad0ae6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ad0ae6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ad0ae6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ad2d7bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562acfaa8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562acfab3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562acf85fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562acf85fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562acf860738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562acf85f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562acf85f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562acf85f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ad4169abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ad4172928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ad415a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ad4185112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbcae441082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562acda7fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x28,0x46,0x7b, Step #5: t(F{ Step #5: artifact_prefix='./'; Test unit written to ./oom-48799a71b1b4713d1f9b6cdc4525f209db1a7442 Step #5: Base64: dChGew== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 410 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1972809084 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610ae014810, 0x5610ae1fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610ae1fe020,0x5610b00960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/48799a71b1b4713d1f9b6cdc4525f209db1a7442' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 435 processed earlier; will process 10594 files now Step #5: ==14794== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5610a4b099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610ab16e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610ab1515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610ab1514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610a4b0fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610a4a70b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610a4a6b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610a4b01c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610a7ad0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610a7ad0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610a7ad0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610a7ad0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610a7ad0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610a7ad0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610a7ad0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610a7ad0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610a7ad0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610a7ad0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610a9d65f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610a6a92b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610a6a9dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610a6849c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610a6849c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610a684a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610a6849874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610a6849874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610a6849874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610ab153abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610ab15c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610ab144699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610ab16f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efe3f6df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610a4a69b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x36,0x5,0x2f, Step #5: \0006\005/ Step #5: artifact_prefix='./'; Test unit written to ./oom-538bada75ac1d515ec294a29c8ca274c8f402d80 Step #5: Base64: ADYFLw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 411 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1973220922 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558842a92810, 0x558842c7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558842c7c020,0x558844b140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/538bada75ac1d515ec294a29c8ca274c8f402d80' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 436 processed earlier; will process 10593 files now Step #5: ==14830== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5588395879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55883fbec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55883fbcf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55883fbcf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55883958dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588394eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588394e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55883957fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55883c54ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55883c54ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55883c54ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55883c54ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55883c54ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55883c54ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55883c54ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55883c54ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55883c54ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55883c54ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55883e7e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55883b510b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55883b51bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55883b2c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55883b2c7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55883b2c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55883b2c7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55883b2c7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55883b2c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55883fbd1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55883fbda928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55883fbc2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55883fbed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0b7f619082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588394e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x61,0x13,0x0, Step #5: \000a\023\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5b4c7710b7cff37dd6b6b6ea0bf706c085e60844 Step #5: Base64: AGETAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 412 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1973637916 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56156c9a4810, 0x56156cb8e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56156cb8e020,0x56156ea260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5b4c7710b7cff37dd6b6b6ea0bf706c085e60844' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 437 processed earlier; will process 10592 files now Step #5: ==14866== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5615634999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561569afe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561569ae15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561569ae14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56156349fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561563400b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5615633fb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561563491c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561566460f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561566460f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561566460f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561566460f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561566460f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561566460f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561566460f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561566460f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561566460f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561566460f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5615686f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561565422b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56156542dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5615651d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5615651d9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5615651da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5615651d9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5615651d9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5615651d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561569ae3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561569aec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561569ad4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561569aff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f5c746082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5615633f9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x69,0x67,0x72, Step #5: digr Step #5: artifact_prefix='./'; Test unit written to ./oom-6fbb59250dc301a935f8d3fe4e72455a5d359cac Step #5: Base64: ZGlncg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 413 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1974049847 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55888b2d9810, 0x55888b4c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55888b4c3020,0x55888d35b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6fbb59250dc301a935f8d3fe4e72455a5d359cac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 438 processed earlier; will process 10591 files now Step #5: ==14902== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558881dce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558888433898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588884165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588884164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558881dd4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558881d35b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558881d30355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558881dc6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558884d95f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558884d95f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558884d95f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558884d95f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558884d95f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558884d95f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558884d95f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558884d95f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558884d95f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558884d95f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55888702af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558883d57b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558883d62be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558883b0ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558883b0ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558883b0f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558883b0e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558883b0e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558883b0e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558888418abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558888421928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558888409699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558888434112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f49093e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558881d2eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf1,0x9e,0x96,0xa0, Step #5: \361\236\226\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-88b627f2ffb89e078c0d49125eb1969105ff41dd Step #5: Base64: 8Z6WoA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 414 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1974464546 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564e1491b810, 0x564e14b0501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564e14b05020,0x564e1699d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88b627f2ffb89e078c0d49125eb1969105ff41dd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 439 processed earlier; will process 10590 files now Step #5: #1 pulse cov: 3433 ft: 3434 exec/s: 0 rss: 155Mb Step #5: ==14938== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564e0b4109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564e11a75898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564e11a585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564e11a584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564e0b416d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564e0b377b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564e0b372355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564e0b408c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564e0e3d7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564e0e3d7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564e0e3d7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564e0e3d7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564e0e3d7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564e0e3d7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564e0e3d7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564e0e3d7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564e0e3d7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564e0e3d7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564e1066cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564e0d399b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564e0d3a4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564e0d150c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564e0d150c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564e0d151738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564e0d150874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564e0d150874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564e0d150874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564e11a5aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564e11a63928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564e11a4b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564e11a76112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f001c594082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564e0b370b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x25,0x25,0x7c, Step #5: %%%| Step #5: artifact_prefix='./'; Test unit written to ./oom-d0bc5b0d6ac453b5b09428366b890674e7537d71 Step #5: Base64: JSUlfA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 415 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1974922724 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563fba59f810, 0x563fba78901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563fba789020,0x563fbc6210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d0bc5b0d6ac453b5b09428366b890674e7537d71' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 441 processed earlier; will process 10588 files now Step #5: ==14974== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563fb10949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563fb76f9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563fb76dc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563fb76dc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563fb109ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563fb0ffbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563fb0ff6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563fb108cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563fb405bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563fb405bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563fb405bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563fb405bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563fb405bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563fb405bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563fb405bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563fb405bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563fb405bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563fb405bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563fb62f0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563fb301db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563fb3028be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563fb2dd4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563fb2dd4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563fb2dd5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563fb2dd4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563fb2dd4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563fb2dd4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563fb76deabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563fb76e7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563fb76cf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563fb76fa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f991d9f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563fb0ff4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x28,0x28,0x28, Step #5: (((( Step #5: artifact_prefix='./'; Test unit written to ./oom-7e80c5307b5b65c62ce8f97509a3588eaf0ad162 Step #5: Base64: KCgoKA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 416 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1975339075 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f831894810, 0x55f831a7e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f831a7e020,0x55f8339160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7e80c5307b5b65c62ce8f97509a3588eaf0ad162' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 442 processed earlier; will process 10587 files now Step #5: #1 pulse cov: 3635 ft: 3636 exec/s: 0 rss: 156Mb Step #5: ==15010== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f8283899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f82e9ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f82e9d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f82e9d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f82838fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8282f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8282eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f828381c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f82b350f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f82b350f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f82b350f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f82b350f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f82b350f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f82b350f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f82b350f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f82b350f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f82b350f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f82b350f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f82d5e5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f82a312b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f82a31dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f82a0c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f82a0c9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f82a0ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f82a0c9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f82a0c9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f82a0c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f82e9d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f82e9dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f82e9c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f82e9ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fad86a2e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8282e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x2,0x42,0x0, Step #5: 0\002B\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4871f93fee5a71388a436cb2698de6143da565c4 Step #5: Base64: MAJCAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 417 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1975792503 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab13ae4810, 0x55ab13cce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab13cce020,0x55ab15b660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4871f93fee5a71388a436cb2698de6143da565c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 444 processed earlier; will process 10585 files now Step #5: ==15046== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ab0a5d99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab10c3e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab10c215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab10c214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab0a5dfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab0a540b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab0a53b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab0a5d1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab0d5a0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab0d5a0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab0d5a0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab0d5a0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab0d5a0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab0d5a0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab0d5a0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab0d5a0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab0d5a0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab0d5a0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab0f835f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab0c562b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab0c56dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab0c319c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab0c319c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab0c31a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab0c319874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab0c319874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab0c319874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab10c23abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab10c2c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab10c14699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab10c3f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3962577082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab0a539b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x60,0x24,0x60, Step #5: #`$` Step #5: artifact_prefix='./'; Test unit written to ./oom-9983cf8038d28bc49e319d9875228954f5eba7ea Step #5: Base64: I2AkYA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 418 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1976322936 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555946162810, 0x55594634c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55594634c020,0x5559481e40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9983cf8038d28bc49e319d9875228954f5eba7ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 445 processed earlier; will process 10584 files now Step #5: ==15082== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55593cc579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5559432bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55594329f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55594329f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55593cc5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55593cbbeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55593cbb9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55593cc4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55593fc1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55593fc1ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55593fc1ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55593fc1ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55593fc1ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55593fc1ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55593fc1ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55593fc1ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55593fc1ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55593fc1ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555941eb3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55593ebe0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55593ebebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55593e997c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55593e997c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55593e998738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55593e997874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55593e997874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55593e997874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5559432a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5559432aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555943292699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5559432bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe7eb09c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55593cbb7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x2f,0x27,0xaf, Step #5: '/'\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-04ecdaf11b0875466a1c4420c2302c48e737b710 Step #5: Base64: Jy8nrw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 419 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1976743637 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55816da0c810, 0x55816dbf601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55816dbf6020,0x55816fa8e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/04ecdaf11b0875466a1c4420c2302c48e737b710' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 446 processed earlier; will process 10583 files now Step #5: ==15118== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5581645019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55816ab66898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55816ab495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55816ab494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558164507d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558164468b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558164463355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5581644f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5581674c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5581674c8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5581674c8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5581674c8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5581674c8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5581674c8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5581674c8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5581674c8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5581674c8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5581674c8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55816975df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55816648ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558166495be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558166241c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558166241c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558166242738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558166241874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558166241874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558166241874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55816ab4babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55816ab54928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55816ab3c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55816ab67112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ab705c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558164461b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x96,0x84,0xa2, Step #5: \360\226\204\242 Step #5: artifact_prefix='./'; Test unit written to ./oom-bd496627ea28103552fda170511455764bda53dd Step #5: Base64: 8JaEog== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 420 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1977155726 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5559cbee4810, 0x5559cc0ce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5559cc0ce020,0x5559cdf660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bd496627ea28103552fda170511455764bda53dd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 447 processed earlier; will process 10582 files now Step #5: ==15154== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5559c29d99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5559c903e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5559c90215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5559c90214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5559c29dfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5559c2940b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5559c293b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5559c29d1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5559c59a0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5559c59a0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5559c59a0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5559c59a0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5559c59a0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5559c59a0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5559c59a0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5559c59a0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5559c59a0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5559c59a0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5559c7c35f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5559c4962b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5559c496dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5559c4719c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5559c4719c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5559c471a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5559c4719874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5559c4719874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5559c4719874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5559c9023abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5559c902c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5559c9014699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5559c903f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa711e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5559c2939b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x9,0x9,0x9,0x9, Step #5: \011\011\011\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-e0bafe976d92fbad43d8806b0e6d3460192e10aa Step #5: Base64: CQkJCQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 421 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1977552491 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d2181fb810, 0x55d2183e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d2183e5020,0x55d21a27d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e0bafe976d92fbad43d8806b0e6d3460192e10aa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 448 processed earlier; will process 10581 files now Step #5: ==15190== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d20ecf09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d215355898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d2153385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d2153384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d20ecf6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d20ec57b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d20ec52355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d20ece8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d211cb7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d211cb7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d211cb7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d211cb7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d211cb7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d211cb7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d211cb7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d211cb7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d211cb7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d211cb7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d213f4cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d210c79b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d210c84be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d210a30c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d210a30c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d210a31738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d210a30874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d210a30874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d210a30874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d21533aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d215343928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d21532b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d215356112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff57faee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d20ec50b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbe,0xa0,0x0, Step #5: \357\276\240\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7df5c16d00fef608ab5f1a7459e4ba4caec9005 Step #5: Base64: 776gAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 422 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1977966889 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a8fe55810, 0x559a9003f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a9003f020,0x559a91ed70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7df5c16d00fef608ab5f1a7459e4ba4caec9005' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 449 processed earlier; will process 10580 files now Step #5: ==15226== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559a8694a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a8cfaf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a8cf925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a8cf924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a86950d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a868b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a868ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a86942c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a89911f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a89911f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a89911f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a89911f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a89911f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a89911f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a89911f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a89911f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a89911f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a89911f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a8bba6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a888d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a888debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a8868ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a8868ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a8868b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a8868a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a8868a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a8868a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a8cf94abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a8cf9d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a8cf85699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a8cfb0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f13ca19a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a868aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x68,0x74,0x68, Step #5: xhth Step #5: artifact_prefix='./'; Test unit written to ./oom-341b5ad30dbad5c398dee8c52f054d55bba42f90 Step #5: Base64: eGh0aA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 423 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1978384952 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560e2fcea810, 0x560e2fed401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560e2fed4020,0x560e31d6c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/341b5ad30dbad5c398dee8c52f054d55bba42f90' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 450 processed earlier; will process 10579 files now Step #5: ==15262== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560e267df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560e2ce44898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560e2ce275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560e2ce274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560e267e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560e26746b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560e26741355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560e267d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560e297a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560e297a6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560e297a6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560e297a6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560e297a6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560e297a6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560e297a6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560e297a6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560e297a6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560e297a6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560e2ba3bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560e28768b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560e28773be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560e2851fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560e2851fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560e28520738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560e2851f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560e2851f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560e2851f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560e2ce29abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560e2ce32928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560e2ce1a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560e2ce45112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f91e2173082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560e2673fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x39,0x2d,0x34,0xc3, Step #5: 9-4\303 Step #5: artifact_prefix='./'; Test unit written to ./oom-3790a16df7b5f10bc54ded48e3be13cee658c390 Step #5: Base64: OS00ww== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 424 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1978804742 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b75cc78810, 0x55b75ce6201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b75ce62020,0x55b75ecfa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3790a16df7b5f10bc54ded48e3be13cee658c390' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 451 processed earlier; will process 10578 files now Step #5: ==15298== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b75376d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b759dd2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b759db55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b759db54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b753773d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b7536d4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b7536cf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b753765c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b756734f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b756734f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b756734f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b756734f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b756734f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b756734f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b756734f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b756734f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b756734f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b756734f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b7589c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b7556f6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b755701be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b7554adc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b7554adc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b7554ae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b7554ad874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b7554ad874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b7554ad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b759db7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b759dc0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b759da8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b759dd3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0eec6f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b7536cdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x10,0x24,0x2f, Step #5: $\020$/ Step #5: artifact_prefix='./'; Test unit written to ./oom-9e763538b7dec7afbfc30e59cc979f69c64b5892 Step #5: Base64: JBAkLw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 425 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1979223639 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557458970810, 0x557458b5a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557458b5a020,0x55745a9f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9e763538b7dec7afbfc30e59cc979f69c64b5892' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 452 processed earlier; will process 10577 files now Step #5: ==15334== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55744f4659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557455aca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557455aad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557455aad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55744f46bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55744f3ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55744f3c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55744f45dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55745242cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55745242cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55745242cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55745242cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55745242cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55745242cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55745242cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55745242cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55745242cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55745242cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5574546c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5574513eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5574513f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5574511a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5574511a5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5574511a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5574511a5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5574511a5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5574511a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557455aafabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557455ab8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557455aa0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557455acb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6426f47082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55744f3c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0xa,0xa, Step #5: $$\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-00c2fa4eae5010370e9e06244f9b521a1f8d7476 Step #5: Base64: JCQKCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 426 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1979633741 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56468e8db810, 0x56468eac501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56468eac5020,0x56469095d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/00c2fa4eae5010370e9e06244f9b521a1f8d7476' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 453 processed earlier; will process 10576 files now Step #5: ==15370== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5646853d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56468ba35898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56468ba185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56468ba184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5646853d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564685337b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564685332355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5646853c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564688397f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564688397f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564688397f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564688397f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564688397f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564688397f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564688397f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564688397f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564688397f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564688397f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56468a62cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564687359b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564687364be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564687110c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564687110c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564687111738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564687110874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564687110874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564687110874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56468ba1aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56468ba23928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56468ba0b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56468ba36112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0f05e60082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564685330b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53,0xc2,0xbd,0x27, Step #5: S\302\275' Step #5: artifact_prefix='./'; Test unit written to ./oom-77cbd95f053940bfc6ab0060728e2176704a41ff Step #5: Base64: U8K9Jw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 427 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1980045614 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a884129810, 0x55a88431301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a884313020,0x55a8861ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/77cbd95f053940bfc6ab0060728e2176704a41ff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 454 processed earlier; will process 10575 files now Step #5: ==15406== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a87ac1e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a881283898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a8812665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a8812664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a87ac24d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a87ab85b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a87ab80355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a87ac16c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a87dbe5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a87dbe5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a87dbe5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a87dbe5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a87dbe5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a87dbe5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a87dbe5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a87dbe5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a87dbe5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a87dbe5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a87fe7af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a87cba7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a87cbb2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a87c95ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a87c95ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a87c95f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a87c95e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a87c95e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a87c95e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a881268abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a881271928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a881259699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a881284112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe84f978082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a87ab7eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x52,0x41,0x51,0x51, Step #5: RAQQ Step #5: artifact_prefix='./'; Test unit written to ./oom-04dca612fda9e369278031ed294d2611ea8a17e4 Step #5: Base64: UkFRUQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 428 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1980464623 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b8db29810, 0x555b8dd1301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b8dd13020,0x555b8fbab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/04dca612fda9e369278031ed294d2611ea8a17e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 455 processed earlier; will process 10574 files now Step #5: ==15442== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555b8461e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b8ac83898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b8ac665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b8ac664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b84624d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b84585b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b84580355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b84616c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b875e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b875e5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b875e5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b875e5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b875e5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b875e5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b875e5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b875e5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b875e5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b875e5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b8987af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b865a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b865b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b8635ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b8635ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b8635f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b8635e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b8635e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b8635e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b8ac68abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b8ac71928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b8ac59699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b8ac84112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd6e9724082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b8457eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc9,0xa1,0xcd,0x84, Step #5: \311\241\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-2af3842fde194465586526b7ca1d6feae8e181ce Step #5: Base64: yaHNhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 429 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1980879823 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556be0380810, 0x556be056a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556be056a020,0x556be24020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2af3842fde194465586526b7ca1d6feae8e181ce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 456 processed earlier; will process 10573 files now Step #5: ==15478== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556bd6e759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556bdd4da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556bdd4bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556bdd4bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556bd6e7bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556bd6ddcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556bd6dd7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556bd6e6dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556bd9e3cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556bd9e3cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556bd9e3cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556bd9e3cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556bd9e3cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556bd9e3cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556bd9e3cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556bd9e3cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556bd9e3cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556bd9e3cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556bdc0d1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556bd8dfeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556bd8e09be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556bd8bb5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556bd8bb5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556bd8bb6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556bd8bb5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556bd8bb5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556bd8bb5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556bdd4bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556bdd4c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556bdd4b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556bdd4db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa14a35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556bd6dd5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa,0xa, Step #5: \012\012\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-3f3d2d8955322f325af6db2238355fa07007ebd9 Step #5: Base64: CgoKCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 430 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1981289941 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab13aa2810, 0x55ab13c8c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab13c8c020,0x55ab15b240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3f3d2d8955322f325af6db2238355fa07007ebd9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 457 processed earlier; will process 10572 files now Step #5: ==15514== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ab0a5979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab10bfc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab10bdf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab10bdf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab0a59dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab0a4feb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab0a4f9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab0a58fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab0d55ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab0d55ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab0d55ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab0d55ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab0d55ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab0d55ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab0d55ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab0d55ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab0d55ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab0d55ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab0f7f3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab0c520b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab0c52bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab0c2d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab0c2d7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab0c2d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab0c2d7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab0c2d7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab0c2d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab10be1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab10bea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab10bd2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab10bfd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f18c2934082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab0a4f7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf4,0x8f,0xb2,0xbb, Step #5: \364\217\262\273 Step #5: artifact_prefix='./'; Test unit written to ./oom-e845b9fb6d3632af043838ce8a3e85ebf58d6734 Step #5: Base64: 9I+yuw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 431 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1981708009 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d86aa3810, 0x557d86c8d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d86c8d020,0x557d88b250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e845b9fb6d3632af043838ce8a3e85ebf58d6734' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 458 processed earlier; will process 10571 files now Step #5: #1 pulse cov: 3615 ft: 3616 exec/s: 0 rss: 157Mb Step #5: ==15550== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557d7d5989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557d83bfd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557d83be05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557d83be04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557d7d59ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557d7d4ffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557d7d4fa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557d7d590c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557d8055ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557d8055ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557d8055ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557d8055ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557d8055ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557d8055ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557d8055ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557d8055ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557d8055ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557d8055ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557d827f4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557d7f521b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557d7f52cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557d7f2d8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557d7f2d8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557d7f2d9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557d7f2d8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557d7f2d8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557d7f2d8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557d83be2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557d83beb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557d83bd3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557d83bfe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9e71413082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557d7d4f8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xef,0xbf,0xbc, Step #5: \000\357\277\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-0fbbd45e251ade9899fe02addbfdb2d039f24a65 Step #5: Base64: AO+/vA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 432 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1982163695 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d37c6bd810, 0x55d37c8a701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d37c8a7020,0x55d37e73f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0fbbd45e251ade9899fe02addbfdb2d039f24a65' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 460 processed earlier; will process 10569 files now Step #5: ==15586== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d3731b29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d379817898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d3797fa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d3797fa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d3731b8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d373119b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d373114355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d3731aac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d376179f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d376179f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d376179f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d376179f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d376179f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d376179f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d376179f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d376179f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d376179f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d376179f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d37840ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d37513bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d375146be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d374ef2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d374ef2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d374ef3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d374ef2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d374ef2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d374ef2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d3797fcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d379805928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d3797ed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d379818112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb099d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d373112b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0x3a,0x30,0x28, Step #5: 2:0( Step #5: artifact_prefix='./'; Test unit written to ./oom-4bed5e91896e6adc187a3b5b24a21028943faff5 Step #5: Base64: MjowKA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 433 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1982585561 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55581e4a0810, 0x55581e68a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55581e68a020,0x5558205220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4bed5e91896e6adc187a3b5b24a21028943faff5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 461 processed earlier; will process 10568 files now Step #5: ==15622== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555814f959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55581b5fa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55581b5dd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55581b5dd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555814f9bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555814efcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555814ef7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555814f8dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555817f5cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555817f5cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555817f5cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555817f5cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555817f5cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555817f5cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555817f5cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555817f5cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555817f5cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555817f5cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55581a1f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555816f1eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555816f29be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555816cd5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555816cd5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555816cd6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555816cd5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555816cd5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555816cd5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55581b5dfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55581b5e8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55581b5d0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55581b5fb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f44b484d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555814ef5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0xa,0xde,0x99, Step #5: H\012\336\231 Step #5: artifact_prefix='./'; Test unit written to ./oom-146327395fa6a67e28f5a5fa8f2e4978cb1239a8 Step #5: Base64: SAremQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 434 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1983002897 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556ef1a5d810, 0x556ef1c4701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556ef1c47020,0x556ef3adf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/146327395fa6a67e28f5a5fa8f2e4978cb1239a8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 462 processed earlier; will process 10567 files now Step #5: ==15658== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556ee85529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556eeebb7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556eeeb9a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556eeeb9a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556ee8558d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556ee84b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556ee84b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556ee854ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556eeb519f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556eeb519f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556eeb519f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556eeb519f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556eeb519f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556eeb519f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556eeb519f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556eeb519f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556eeb519f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556eeb519f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556eed7aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556eea4dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556eea4e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556eea292c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556eea292c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556eea293738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556eea292874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556eea292874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556eea292874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556eeeb9cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556eeeba5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556eeeb8d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556eeebb8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f426f12d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556ee84b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6,0x0,0x7,0x0, Step #5: \006\000\007\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-201a80fb58cdbe7b0210fc5fe4b2868c65dc19fb Step #5: Base64: BgAHAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 435 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1983418708 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55be53806810, 0x55be539f001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55be539f0020,0x55be558880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/201a80fb58cdbe7b0210fc5fe4b2868c65dc19fb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 463 processed earlier; will process 10566 files now Step #5: ==15694== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55be4a2fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55be50960898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55be509435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55be509434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55be4a301d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55be4a262b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55be4a25d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55be4a2f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55be4d2c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55be4d2c2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55be4d2c2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55be4d2c2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55be4d2c2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55be4d2c2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55be4d2c2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55be4d2c2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55be4d2c2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55be4d2c2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55be4f557f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55be4c284b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55be4c28fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55be4c03bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55be4c03bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55be4c03c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55be4c03b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55be4c03b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55be4c03b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55be50945abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55be5094e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55be50936699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55be50961112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3c5c16082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55be4a25bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xef,0xbe,0xb5, Step #5: \000\357\276\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-7dfa9bf6e6c8861b50d748820b1e160fd66845bb Step #5: Base64: AO++tQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 436 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1983834424 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5641f4579810, 0x5641f476301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5641f4763020,0x5641f65fb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7dfa9bf6e6c8861b50d748820b1e160fd66845bb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 464 processed earlier; will process 10565 files now Step #5: ==15730== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5641eb06e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5641f16d3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5641f16b65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5641f16b64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5641eb074d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641eafd5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641eafd0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5641eb066c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5641ee035f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5641ee035f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5641ee035f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5641ee035f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5641ee035f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5641ee035f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5641ee035f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5641ee035f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5641ee035f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5641ee035f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5641f02caf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5641ecff7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5641ed002be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5641ecdaec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5641ecdaec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5641ecdaf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5641ecdae874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5641ecdae874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5641ecdae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5641f16b8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5641f16c1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5641f16a9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5641f16d4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f65e9687082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641eafceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x3e,0x42, Step #5: - >B Step #5: artifact_prefix='./'; Test unit written to ./oom-3d32fb4a8aacad343dba8e03b9c5cc342a1268d6 Step #5: Base64: LSA+Qg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 437 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1984247322 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561dedf3f810, 0x561dee12901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561dee129020,0x561deffc10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3d32fb4a8aacad343dba8e03b9c5cc342a1268d6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 465 processed earlier; will process 10564 files now Step #5: ==15766== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561de4a349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561deb099898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561deb07c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561deb07c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561de4a3ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561de499bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561de4996355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561de4a2cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561de79fbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561de79fbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561de79fbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561de79fbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561de79fbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561de79fbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561de79fbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561de79fbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561de79fbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561de79fbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561de9c90f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561de69bdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561de69c8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561de6774c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561de6774c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561de6775738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561de6774874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561de6774874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561de6774874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561deb07eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561deb087928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561deb06f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561deb09a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa6f581d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561de4994b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x61,0x6e,0x4d, Step #5: +anM Step #5: artifact_prefix='./'; Test unit written to ./oom-5ac93ec69712c581fbf5f919f2fecd16d25e3499 Step #5: Base64: K2FuTQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 438 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1984663842 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5636b2072810, 0x5636b225c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5636b225c020,0x5636b40f40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ac93ec69712c581fbf5f919f2fecd16d25e3499' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 466 processed earlier; will process 10563 files now Step #5: ==15802== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5636a8b679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5636af1cc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636af1af5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636af1af4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5636a8b6dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5636a8aceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5636a8ac9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5636a8b5fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5636abb2ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5636abb2ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5636abb2ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5636abb2ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5636abb2ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5636abb2ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5636abb2ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5636abb2ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5636abb2ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5636abb2ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5636addc3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5636aaaf0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5636aaafbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5636aa8a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5636aa8a7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5636aa8a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5636aa8a7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5636aa8a7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5636aa8a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5636af1b1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5636af1ba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5636af1a2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5636af1cd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb1db79b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5636a8ac7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0xef,0xbe,0x9e, Step #5: \\\357\276\236 Step #5: artifact_prefix='./'; Test unit written to ./oom-1615b67b46d7a3e955a2e386f2d5bda66e2b1ba0 Step #5: Base64: XO++ng== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 439 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1985078437 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea2a471810, 0x55ea2a65b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea2a65b020,0x55ea2c4f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1615b67b46d7a3e955a2e386f2d5bda66e2b1ba0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 467 processed earlier; will process 10562 files now Step #5: ==15838== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ea20f669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea275cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea275ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea275ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea20f6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea20ecdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea20ec8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea20f5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea23f2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea23f2df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea23f2df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea23f2df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea23f2df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea23f2df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea23f2df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea23f2df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea23f2df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea23f2df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea261c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea22eefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea22efabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea22ca6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea22ca6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea22ca7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea22ca6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea22ca6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea22ca6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea275b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea275b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea275a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea275cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fede0e10082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea20ec6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0xef,0xb7,0xbc, Step #5: n\357\267\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-565282426b5e6935e459e1e09a2bf8df5d1262bf Step #5: Base64: bu+3vA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 440 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1985495975 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5589a5797810, 0x5589a598101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5589a5981020,0x5589a78190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/565282426b5e6935e459e1e09a2bf8df5d1262bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 468 processed earlier; will process 10561 files now Step #5: ==15874== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55899c28c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5589a28f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589a28d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589a28d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55899c292d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55899c1f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55899c1ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55899c284c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55899f253f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55899f253f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55899f253f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55899f253f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55899f253f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55899f253f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55899f253f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55899f253f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55899f253f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55899f253f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589a14e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55899e215b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55899e220be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55899dfccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55899dfccc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55899dfcd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55899dfcc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55899dfcc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55899dfcc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5589a28d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5589a28df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5589a28c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5589a28f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb9b1367082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55899c1ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x20,0x20,0x0, Step #5: \000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ce4a44845af890b67469795a0af2d8dd6858df19 Step #5: Base64: ICAgAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 441 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1985915605 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5566fb558810, 0x5566fb74201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5566fb742020,0x5566fd5da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce4a44845af890b67469795a0af2d8dd6858df19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 469 processed earlier; will process 10560 files now Step #5: ==15910== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5566f204d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5566f86b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5566f86955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5566f86954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5566f2053d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5566f1fb4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5566f1faf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5566f2045c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5566f5014f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5566f5014f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5566f5014f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5566f5014f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5566f5014f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5566f5014f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5566f5014f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5566f5014f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5566f5014f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5566f5014f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5566f72a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5566f3fd6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5566f3fe1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5566f3d8dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5566f3d8dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5566f3d8e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5566f3d8d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5566f3d8d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5566f3d8d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5566f8697abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5566f86a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5566f8688699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5566f86b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f14eb8c2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5566f1fadb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xda,0x82,0x45,0x5, Step #5: \332\202E\005 Step #5: artifact_prefix='./'; Test unit written to ./oom-c75b77eb672f55140015f3b66726230ad5cc8639 Step #5: Base64: 2oJFBQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 442 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1986336207 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d18483a810, 0x55d184a2401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d184a24020,0x55d1868bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c75b77eb672f55140015f3b66726230ad5cc8639' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 470 processed earlier; will process 10559 files now Step #5: ==15946== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d17b32f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d181994898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1819775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1819774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d17b335d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d17b296b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d17b291355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d17b327c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d17e2f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d17e2f6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d17e2f6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d17e2f6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d17e2f6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d17e2f6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d17e2f6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d17e2f6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d17e2f6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d17e2f6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d18058bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d17d2b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d17d2c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d17d06fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d17d06fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d17d070738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d17d06f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d17d06f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d17d06f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d181979abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d181982928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d18196a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d181995112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f691964d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d17b28fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x4f, Step #5: Step #5: Step #5: #0 0x55629edfe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5562a5463898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5562a54465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5562a54464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55629ee04d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55629ed65b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55629ed60355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55629edf6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5562a1dc5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5562a1dc5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5562a1dc5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5562a1dc5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5562a1dc5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5562a1dc5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5562a1dc5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5562a1dc5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5562a1dc5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5562a1dc5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5562a405af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5562a0d87b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5562a0d92be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5562a0b3ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5562a0b3ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5562a0b3f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5562a0b3e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5562a0b3e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5562a0b3e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5562a5448abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5562a5451928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5562a5439699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5562a5464112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0068676082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55629ed5eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x57,0x64,0x62,0x78, Step #5: Wdbx Step #5: artifact_prefix='./'; Test unit written to ./oom-75d4638e749c97fa23b04ff21e53172e362826b5 Step #5: Base64: V2RieA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 444 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1987169689 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5605b6d79810, 0x5605b6f6301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5605b6f63020,0x5605b8dfb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/75d4638e749c97fa23b04ff21e53172e362826b5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 472 processed earlier; will process 10557 files now Step #5: ==16018== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5605ad86e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605b3ed3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605b3eb65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605b3eb64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5605ad874d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605ad7d5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5605ad7d0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5605ad866c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605b0835f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605b0835f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605b0835f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605b0835f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605b0835f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605b0835f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605b0835f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605b0835f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605b0835f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605b0835f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605b2acaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5605af7f7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5605af802be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5605af5aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5605af5aec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5605af5af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5605af5ae874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5605af5ae874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5605af5ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605b3eb8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5605b3ec1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605b3ea9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605b3ed4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ebe0bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5605ad7ceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0x2f,0x2f,0x40, Step #5: &//@ Step #5: artifact_prefix='./'; Test unit written to ./oom-f6cb74968dbb70a690b369ddee555f9f75f319da Step #5: Base64: Ji8vQA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 445 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1987582447 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555d6cdca810, 0x555d6cfb401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555d6cfb4020,0x555d6ee4c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f6cb74968dbb70a690b369ddee555f9f75f319da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 473 processed earlier; will process 10556 files now Step #5: ==16054== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555d638bf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555d69f24898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555d69f075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555d69f074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555d638c5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555d63826b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555d63821355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555d638b7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555d66886f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555d66886f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555d66886f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555d66886f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555d66886f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555d66886f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555d66886f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555d66886f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555d66886f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555d66886f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555d68b1bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555d65848b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555d65853be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555d655ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555d655ffc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555d65600738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555d655ff874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555d655ff874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555d655ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555d69f09abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555d69f12928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555d69efa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555d69f25112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc0fb326082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555d6381fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x1,0xb,0x64, Step #5: B\001\013d Step #5: artifact_prefix='./'; Test unit written to ./oom-dc9f60be844d2a95b10753a179453bb9d615a1ed Step #5: Base64: QgELZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 446 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1988003484 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5579cd226810, 0x5579cd41001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5579cd410020,0x5579cf2a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dc9f60be844d2a95b10753a179453bb9d615a1ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 474 processed earlier; will process 10555 files now Step #5: ==16090== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5579c3d1b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5579ca380898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5579ca3635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5579ca3634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5579c3d21d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5579c3c82b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5579c3c7d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5579c3d13c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5579c6ce2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5579c6ce2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5579c6ce2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5579c6ce2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5579c6ce2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5579c6ce2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5579c6ce2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5579c6ce2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5579c6ce2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5579c6ce2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579c8f77f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5579c5ca4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5579c5cafbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5579c5a5bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5579c5a5bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5579c5a5c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5579c5a5b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5579c5a5b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5579c5a5b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5579ca365abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5579ca36e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5579ca356699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5579ca381112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a3823f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5579c3c7bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x0,0x42,0x0, Step #5: B\000B\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-62eb07eebbb3090ef4ef0f3abeba389043e6009b Step #5: Base64: QgBCAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 447 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1988422870 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9b8042810, 0x55e9b822c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9b822c020,0x55e9ba0c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/62eb07eebbb3090ef4ef0f3abeba389043e6009b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 475 processed earlier; will process 10554 files now Step #5: ==16126== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e9aeb379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9b519c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9b517f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9b517f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9aeb3dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e9aea9eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e9aea99355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9aeb2fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e9b1afef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e9b1afef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e9b1afef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e9b1afef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e9b1afef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e9b1afef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e9b1afef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e9b1afef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e9b1afef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e9b1afef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9b3d93f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e9b0ac0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e9b0acbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9b0877c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9b0877c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9b0878738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9b0877874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9b0877874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9b0877874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e9b5181abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9b518a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e9b5172699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e9b519d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0a27c32082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e9aea97b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x4,0x5c,0x4, Step #5: \\\004\\\004 Step #5: artifact_prefix='./'; Test unit written to ./oom-008036300ee207c7d12970ef54ed1a7b87be39f4 Step #5: Base64: XARcBA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 448 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1988839448 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5646519cb810, 0x564651bb501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564651bb5020,0x564653a4d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/008036300ee207c7d12970ef54ed1a7b87be39f4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 476 processed earlier; will process 10553 files now Step #5: ==16162== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5646484c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56464eb25898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56464eb085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56464eb084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5646484c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564648427b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564648422355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5646484b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56464b487f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56464b487f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56464b487f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56464b487f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56464b487f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56464b487f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56464b487f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56464b487f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56464b487f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56464b487f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56464d71cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56464a449b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56464a454be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56464a200c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56464a200c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56464a201738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56464a200874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56464a200874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56464a200874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56464eb0aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56464eb13928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56464eafb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56464eb26112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffb5e3c2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564648420b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdc,0xbb,0xdc,0xb5, Step #5: \334\273\334\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-9920b2c2c88ca4971191e0e64b1bdc8ed26460f4 Step #5: Base64: 3LvctQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 449 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1989255825 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8f34ee810, 0x55c8f36d801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c8f36d8020,0x55c8f55700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9920b2c2c88ca4971191e0e64b1bdc8ed26460f4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 477 processed earlier; will process 10552 files now Step #5: ==16198== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c8e9fe39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8f0648898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8f062b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8f062b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c8e9fe9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c8e9f4ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c8e9f45355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c8e9fdbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c8ecfaaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c8ecfaaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c8ecfaaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c8ecfaaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c8ecfaaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c8ecfaaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c8ecfaaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c8ecfaaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c8ecfaaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c8ecfaaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c8ef23ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c8ebf6cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c8ebf77be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c8ebd23c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c8ebd23c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c8ebd24738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c8ebd23874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c8ebd23874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c8ebd23874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8f062dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8f0636928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8f061e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8f0649112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ac67cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c8e9f43b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x5f,0x6e,0x4d, Step #5: D_nM Step #5: artifact_prefix='./'; Test unit written to ./oom-68f18288ad6f877cbfde53cd2ff6d716d6d82bd9 Step #5: Base64: RF9uTQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 450 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1989675331 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a655da810, 0x563a657c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a657c4020,0x563a6765c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/68f18288ad6f877cbfde53cd2ff6d716d6d82bd9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 478 processed earlier; will process 10551 files now Step #5: ==16234== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563a5c0cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a62734898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a627175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a627174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a5c0d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a5c036b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a5c031355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a5c0c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a5f096f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a5f096f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a5f096f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a5f096f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a5f096f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a5f096f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a5f096f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a5f096f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a5f096f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a5f096f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a6132bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a5e058b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a5e063be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a5de0fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a5de0fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a5de10738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a5de0f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a5de0f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a5de0f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a62719abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a62722928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a6270a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a62735112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f905f60f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a5c02fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0x9,0x9, Step #5: -\012\011\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-10bfb2cd9e9806a4867c9fded2c1c13b8e157ae4 Step #5: Base64: LQoJCQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 451 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1990091078 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f04d1e810, 0x556f04f0801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f04f08020,0x556f06da00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/10bfb2cd9e9806a4867c9fded2c1c13b8e157ae4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 479 processed earlier; will process 10550 files now Step #5: #1 pulse cov: 3538 ft: 3539 exec/s: 0 rss: 155Mb Step #5: #2 pulse cov: 3715 ft: 4002 exec/s: 0 rss: 157Mb Step #5: ==16270== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556efb8139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f01e78898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f01e5b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f01e5b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556efb819d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556efb77ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556efb775355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556efb80bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556efe7daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556efe7daf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556efe7daf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556efe7daf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556efe7daf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556efe7daf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556efe7daf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556efe7daf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556efe7daf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556efe7daf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f00a6ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556efd79cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556efd7a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556efd553c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556efd553c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556efd554738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556efd553874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556efd553874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556efd553874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f01e5dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f01e66928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f01e4e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f01e79112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f41e8192082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556efb773b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf4,0x8f,0x9f,0xb5, Step #5: \364\217\237\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-1364d85dd47c79cf848fb173e76445e42cba3dd4 Step #5: Base64: 9I+ftQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 452 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1990573181 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c426ae0810, 0x55c426cca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c426cca020,0x55c428b620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1364d85dd47c79cf848fb173e76445e42cba3dd4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 482 processed earlier; will process 10547 files now Step #5: ==16306== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c41d5d59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c423c3a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c423c1d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c423c1d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c41d5dbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c41d53cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c41d537355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c41d5cdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c42059cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c42059cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c42059cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c42059cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c42059cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c42059cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c42059cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c42059cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c42059cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c42059cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c422831f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c41f55eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c41f569be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c41f315c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c41f315c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c41f316738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c41f315874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c41f315874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c41f315874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c423c1fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c423c28928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c423c10699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c423c3b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdd47c25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c41d535b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x2,0x2,0x2b, Step #5: r\002\002+ Step #5: artifact_prefix='./'; Test unit written to ./oom-50470c7bfa39be3b301dcfa56f27197be99a967c Step #5: Base64: cgICKw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 453 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1990987502 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8e39d0810, 0x55c8e3bba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c8e3bba020,0x55c8e5a520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/50470c7bfa39be3b301dcfa56f27197be99a967c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 483 processed earlier; will process 10546 files now Step #5: ==16342== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c8da4c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8e0b2a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8e0b0d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8e0b0d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c8da4cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c8da42cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c8da427355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c8da4bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c8dd48cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c8dd48cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c8dd48cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c8dd48cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c8dd48cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c8dd48cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c8dd48cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c8dd48cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c8dd48cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c8dd48cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c8df721f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c8dc44eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c8dc459be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c8dc205c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c8dc205c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c8dc206738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c8dc205874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c8dc205874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c8dc205874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8e0b0fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8e0b18928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8e0b00699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8e0b2b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f13b43ba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c8da425b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd6,0xb5,0xf3,0x0, Step #5: \326\265\363\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d93467bc4fd53ce5d4cfaf0d82f80c9ccdda7726 Step #5: Base64: 1rXzAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 454 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1991402193 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe3ab08810, 0x55fe3acf201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe3acf2020,0x55fe3cb8a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d93467bc4fd53ce5d4cfaf0d82f80c9ccdda7726' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 484 processed earlier; will process 10545 files now Step #5: ==16378== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fe315fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe37c62898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe37c455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe37c454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe31603d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe31564b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe3155f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe315f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe345c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe345c4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe345c4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe345c4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe345c4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe345c4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe345c4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe345c4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe345c4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe345c4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe36859f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe33586b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe33591be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe3333dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe3333dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe3333e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe3333d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe3333d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe3333d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe37c47abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe37c50928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe37c38699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe37c63112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f660ed21082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe3155db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xbe,0x80,0x95, Step #5: \340\276\200\225 Step #5: artifact_prefix='./'; Test unit written to ./oom-6bdf9c13230506c5e4ac8be1f17556a0c7689735 Step #5: Base64: 4L6AlQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 455 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1991819648 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fa8786d810, 0x55fa87a5701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fa87a57020,0x55fa898ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bdf9c13230506c5e4ac8be1f17556a0c7689735' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 485 processed earlier; will process 10544 files now Step #5: #1 pulse cov: 3406 ft: 3407 exec/s: 0 rss: 154Mb Step #5: ==16414== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fa7e3629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fa849c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fa849aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fa849aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fa7e368d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fa7e2c9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fa7e2c4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fa7e35ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fa81329f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fa81329f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fa81329f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fa81329f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fa81329f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fa81329f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fa81329f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fa81329f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fa81329f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fa81329f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fa835bef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fa802ebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fa802f6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fa800a2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fa800a2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fa800a3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fa800a2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fa800a2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fa800a2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fa849acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fa849b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fa8499d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fa849c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb781c4b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fa7e2c2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0xa0,0xa0, Step #5: \363\240\240\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-ee9cd179e8989ae0c200f44fd8a1d7e590f73e22 Step #5: Base64: 86CgoA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 456 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1992277715 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563eb038c810, 0x563eb057601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563eb0576020,0x563eb240e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee9cd179e8989ae0c200f44fd8a1d7e590f73e22' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 487 processed earlier; will process 10542 files now Step #5: ==16450== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563ea6e819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563ead4e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563ead4c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563ead4c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563ea6e87d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563ea6de8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563ea6de3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563ea6e79c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563ea9e48f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563ea9e48f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563ea9e48f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563ea9e48f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563ea9e48f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563ea9e48f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563ea9e48f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563ea9e48f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563ea9e48f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563ea9e48f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563eac0ddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563ea8e0ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563ea8e15be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563ea8bc1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563ea8bc1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563ea8bc2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563ea8bc1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563ea8bc1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563ea8bc1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563ead4cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563ead4d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563ead4bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563ead4e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb26bd87082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563ea6de1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53,0x3a,0x44,0x3a, Step #5: S:D: Step #5: artifact_prefix='./'; Test unit written to ./oom-ab6e45c38433a164432981363532568b96b21775 Step #5: Base64: UzpEOg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 457 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1992704767 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ba9251810, 0x555ba943b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ba943b020,0x555bab2d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ab6e45c38433a164432981363532568b96b21775' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 488 processed earlier; will process 10541 files now Step #5: ==16486== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555b9fd469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ba63ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ba638e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ba638e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b9fd4cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b9fcadb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b9fca8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b9fd3ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ba2d0df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ba2d0df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ba2d0df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ba2d0df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ba2d0df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ba2d0df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ba2d0df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ba2d0df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ba2d0df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ba2d0df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555ba4fa2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ba1ccfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ba1cdabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ba1a86c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ba1a86c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ba1a87738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ba1a86874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ba1a86874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ba1a86874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ba6390abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ba6399928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ba6381699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ba63ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff3832a3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b9fca6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x26,0xdb,0xbf, Step #5: |&\333\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-755c7185fab0b9e2d3d422062135a9a19f5dfed1 Step #5: Base64: fCbbvw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 458 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1993125207 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b347d50810, 0x55b347f3a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b347f3a020,0x55b349dd20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/755c7185fab0b9e2d3d422062135a9a19f5dfed1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 489 processed earlier; will process 10540 files now Step #5: ==16522== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b33e8459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b344eaa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b344e8d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b344e8d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b33e84bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b33e7acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b33e7a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b33e83dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b34180cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b34180cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b34180cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b34180cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b34180cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b34180cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b34180cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b34180cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b34180cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b34180cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b343aa1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b3407ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b3407d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b340585c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b340585c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b340586738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b340585874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b340585874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b340585874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b344e8fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b344e98928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b344e80699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b344eab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e51bcb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b33e7a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x71,0x62,0x6c, Step #5: sqbl Step #5: artifact_prefix='./'; Test unit written to ./oom-d97669e3674629fd0d40b84d981d5d30a56f1898 Step #5: Base64: c3FibA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 459 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1993541535 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56469e69c810, 0x56469e88601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56469e886020,0x5646a071e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d97669e3674629fd0d40b84d981d5d30a56f1898' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 490 processed earlier; will process 10539 files now Step #5: ==16558== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5646951919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56469b7f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56469b7d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56469b7d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564695197d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5646950f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5646950f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564695189c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564698158f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564698158f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564698158f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564698158f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564698158f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564698158f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564698158f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564698158f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564698158f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564698158f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56469a3edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56469711ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564697125be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564696ed1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564696ed1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564696ed2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564696ed1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564696ed1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564696ed1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56469b7dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56469b7e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56469b7cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56469b7f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f44cbcd9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5646950f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf4,0x88,0x87,0x91, Step #5: \364\210\207\221 Step #5: artifact_prefix='./'; Test unit written to ./oom-48b16eda096070c548621f01eacc8d2600fd3477 Step #5: Base64: 9IiHkQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 460 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1993958812 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555d6e40c810, 0x555d6e5f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555d6e5f6020,0x555d7048e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/48b16eda096070c548621f01eacc8d2600fd3477' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 491 processed earlier; will process 10538 files now Step #5: ==16594== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555d64f019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555d6b566898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555d6b5495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555d6b5494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555d64f07d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555d64e68b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555d64e63355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555d64ef9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555d67ec8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555d67ec8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555d67ec8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555d67ec8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555d67ec8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555d67ec8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555d67ec8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555d67ec8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555d67ec8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555d67ec8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555d6a15df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555d66e8ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555d66e95be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555d66c41c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555d66c41c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555d66c42738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555d66c41874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555d66c41874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555d66c41874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555d6b54babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555d6b554928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555d6b53c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555d6b567112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffb76cee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555d64e61b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x64,0x62,0x6b, Step #5: ddbk Step #5: artifact_prefix='./'; Test unit written to ./oom-1e7b7ea4cd8647d1c05ff8a433c68eb6856b1583 Step #5: Base64: ZGRiaw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 461 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1994370190 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5618c6f87810, 0x5618c717101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5618c7171020,0x5618c90090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e7b7ea4cd8647d1c05ff8a433c68eb6856b1583' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 492 processed earlier; will process 10537 files now Step #5: ==16630== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5618bda7c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5618c40e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5618c40c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5618c40c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5618bda82d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5618bd9e3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5618bd9de355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5618bda74c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5618c0a43f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5618c0a43f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5618c0a43f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5618c0a43f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5618c0a43f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5618c0a43f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5618c0a43f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5618c0a43f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5618c0a43f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5618c0a43f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5618c2cd8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5618bfa05b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5618bfa10be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5618bf7bcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5618bf7bcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5618bf7bd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5618bf7bc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5618bf7bc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5618bf7bc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5618c40c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5618c40cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5618c40b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5618c40e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe1e3d18082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5618bd9dcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0x69,0x6e,0x9d, Step #5: .in\235 Step #5: artifact_prefix='./'; Test unit written to ./oom-a5837326af6fd69bb3e9bb4b771a3cc1420c1407 Step #5: Base64: LmlunQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 462 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1994787396 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a8a01f810, 0x558a8a20901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a8a209020,0x558a8c0a10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a5837326af6fd69bb3e9bb4b771a3cc1420c1407' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 493 processed earlier; will process 10536 files now Step #5: ==16666== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558a80b149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a87179898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a8715c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a8715c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a80b1ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a80a7bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a80a76355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a80b0cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a83adbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a83adbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a83adbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a83adbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a83adbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a83adbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a83adbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a83adbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a83adbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a83adbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a85d70f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a82a9db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a82aa8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a82854c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a82854c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a82855738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a82854874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a82854874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a82854874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a8715eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a87167928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a8714f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a8717a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb6d2a35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a80a74b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc3,0x9e,0xf0,0x8a, Step #5: \303\236\360\212 Step #5: artifact_prefix='./'; Test unit written to ./oom-7750c48d8b6ce50dbc4432a0e2f4637f6ff36e34 Step #5: Base64: w57wig== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 463 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1995203285 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dfbf908810, 0x55dfbfaf201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dfbfaf2020,0x55dfc198a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7750c48d8b6ce50dbc4432a0e2f4637f6ff36e34' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 494 processed earlier; will process 10535 files now Step #5: ==16702== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dfb63fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dfbca62898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dfbca455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dfbca454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dfb6403d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dfb6364b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dfb635f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dfb63f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dfb93c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dfb93c4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dfb93c4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dfb93c4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dfb93c4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dfb93c4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dfb93c4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dfb93c4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dfb93c4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dfb93c4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dfbb659f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dfb8386b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dfb8391be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dfb813dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dfb813dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dfb813e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dfb813d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dfb813d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dfb813d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dfbca47abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dfbca50928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dfbca38699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dfbca63112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f883838b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dfb635db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0xcb,0xab, Step #5: Step #5: Step #5: #0 0x55a0664819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a06cae6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a06cac95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a06cac94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a066487d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0663e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0663e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a066479c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a069448f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a069448f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a069448f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a069448f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a069448f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a069448f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a069448f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a069448f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a069448f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a069448f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a06b6ddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a06840ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a068415be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0681c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0681c1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0681c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0681c1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0681c1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0681c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a06cacbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a06cad4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a06cabc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a06cae7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3d9b0f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0663e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x66,0x7e,0x6, Step #5: tf~\006 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7422e5b797f9eede741c46aebfa3b64bf6a97bd Step #5: Base64: dGZ+Bg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 465 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1996036432 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559498e76810, 0x55949906001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559499060020,0x55949aef80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7422e5b797f9eede741c46aebfa3b64bf6a97bd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 496 processed earlier; will process 10533 files now Step #5: ==16774== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55948f96b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559495fd0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559495fb35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559495fb34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55948f971d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55948f8d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55948f8cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55948f963c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559492932f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559492932f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559492932f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559492932f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559492932f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559492932f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559492932f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559492932f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559492932f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559492932f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559494bc7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5594918f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5594918ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5594916abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5594916abc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5594916ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5594916ab874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5594916ab874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5594916ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559495fb5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559495fbe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559495fa6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559495fd1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2306820082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55948f8cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9d,0x85,0xbd, Step #5: \360\235\205\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-a6ba76a2fca45afee811efa2862e3befe50a01a1 Step #5: Base64: 8J2FvQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 466 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1996453312 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f69fbd8810, 0x55f69fdc201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f69fdc2020,0x55f6a1c5a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a6ba76a2fca45afee811efa2862e3befe50a01a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 497 processed earlier; will process 10532 files now Step #5: #1 pulse cov: 3418 ft: 3419 exec/s: 0 rss: 155Mb Step #5: ==16810== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f6966cd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f69cd32898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f69cd155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f69cd154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f6966d3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f696634b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f69662f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f6966c5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f699694f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f699694f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f699694f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f699694f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f699694f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f699694f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f699694f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f699694f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f699694f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f699694f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f69b929f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f698656b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f698661be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f69840dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f69840dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f69840e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f69840d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f69840d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f69840d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f69cd17abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f69cd20928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f69cd08699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f69cd33112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f887ac1b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f69662db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd8,0xab,0xd7,0xaf, Step #5: \330\253\327\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-ced4b7f94490d92e907ae731c11f18a0359af8b7 Step #5: Base64: 2KvXrw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 467 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1996912402 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a27b86810, 0x560a27d7001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a27d70020,0x560a29c080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ced4b7f94490d92e907ae731c11f18a0359af8b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 499 processed earlier; will process 10530 files now Step #5: ==16846== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560a1e67b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a24ce0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a24cc35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a24cc34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a1e681d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a1e5e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a1e5dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a1e673c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a21642f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a21642f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a21642f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a21642f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a21642f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a21642f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a21642f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a21642f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a21642f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a21642f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a238d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a20604b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a2060fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a203bbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a203bbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a203bc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a203bb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a203bb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a203bb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a24cc5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a24cce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a24cb6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a24ce1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa64b9c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a1e5dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0x52,0x43,0x5f, Step #5: _RC_ Step #5: artifact_prefix='./'; Test unit written to ./oom-b5f91bfe2ebe809978504df1db38404f55fa59d7 Step #5: Base64: X1JDXw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 468 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1997330205 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d5bdf62810, 0x55d5be14c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d5be14c020,0x55d5bffe40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b5f91bfe2ebe809978504df1db38404f55fa59d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 500 processed earlier; will process 10529 files now Step #5: ==16882== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d5b4a579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d5bb0bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d5bb09f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d5bb09f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d5b4a5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d5b49beb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d5b49b9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d5b4a4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d5b7a1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d5b7a1ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d5b7a1ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d5b7a1ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d5b7a1ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d5b7a1ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d5b7a1ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d5b7a1ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d5b7a1ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d5b7a1ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d5b9cb3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d5b69e0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d5b69ebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d5b6797c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d5b6797c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d5b6798738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d5b6797874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d5b6797874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d5b6797874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d5bb0a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d5bb0aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d5bb092699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d5bb0bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd5d93d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d5b49b7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x54,0x41,0x45,0x0, Step #5: TAE\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d3fa89d5a832da0534983b24f65c0fca487bf56f Step #5: Base64: VEFFAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 469 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1997748589 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563cc053f810, 0x563cc072901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563cc0729020,0x563cc25c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d3fa89d5a832da0534983b24f65c0fca487bf56f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 501 processed earlier; will process 10528 files now Step #5: ==16918== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563cb70349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563cbd699898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563cbd67c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563cbd67c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563cb703ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563cb6f9bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563cb6f96355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563cb702cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563cb9ffbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563cb9ffbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563cb9ffbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563cb9ffbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563cb9ffbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563cb9ffbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563cb9ffbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563cb9ffbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563cb9ffbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563cb9ffbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563cbc290f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563cb8fbdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563cb8fc8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563cb8d74c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563cb8d74c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563cb8d75738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563cb8d74874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563cb8d74874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563cb8d74874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563cbd67eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563cbd687928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563cbd66f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563cbd69a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f09106b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563cb6f94b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0x60,0x7e,0x60, Step #5: \015`~` Step #5: artifact_prefix='./'; Test unit written to ./oom-863b53c7aee9667cc086918c427266da68ed8a6a Step #5: Base64: DWB+YA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 470 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1998287810 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5577373b0810, 0x55773759a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55773759a020,0x5577394320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/863b53c7aee9667cc086918c427266da68ed8a6a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 502 processed earlier; will process 10527 files now Step #5: #1 pulse cov: 3467 ft: 3468 exec/s: 0 rss: 155Mb Step #5: ==16954== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55772dea59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55773450a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5577344ed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5577344ed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55772deabd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55772de0cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55772de07355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55772de9dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557730e6cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557730e6cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557730e6cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557730e6cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557730e6cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557730e6cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557730e6cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557730e6cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557730e6cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557730e6cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557733101f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55772fe2eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55772fe39be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55772fbe5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55772fbe5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55772fbe6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55772fbe5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55772fbe5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55772fbe5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5577344efabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5577344f8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5577344e0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55773450b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0b0d628082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55772de05b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x20,0x31,0x24, Step #5: $ 1$ Step #5: artifact_prefix='./'; Test unit written to ./oom-39064bdd89b3dfa0626ca59d843d926ea072830b Step #5: Base64: JCAxJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 471 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1998757499 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5584267a5810, 0x55842698f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55842698f020,0x5584288270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/39064bdd89b3dfa0626ca59d843d926ea072830b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 504 processed earlier; will process 10525 files now Step #5: #1 pulse cov: 3396 ft: 3397 exec/s: 0 rss: 154Mb Step #5: ==16990== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55841d29a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5584238ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5584238e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5584238e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55841d2a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55841d201b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55841d1fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55841d292c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558420261f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558420261f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558420261f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558420261f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558420261f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558420261f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558420261f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558420261f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558420261f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558420261f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5584224f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55841f223b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55841f22ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55841efdac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55841efdac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55841efdb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55841efda874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55841efda874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55841efda874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5584238e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5584238ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5584238d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558423900112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ceb243082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55841d1fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xc,0xc,0xa, Step #5: -\014\014\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-88f4dccc35ea447adee5c7772e05d998a0e01322 Step #5: Base64: LQwMCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 472 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1999220487 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56163972f810, 0x56163991901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561639919020,0x56163b7b10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88f4dccc35ea447adee5c7772e05d998a0e01322' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 506 processed earlier; will process 10523 files now Step #5: ==17026== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5616302249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561636889898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56163686c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56163686c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56163022ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56163018bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561630186355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56163021cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5616331ebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5616331ebf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5616331ebf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5616331ebf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5616331ebf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5616331ebf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5616331ebf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5616331ebf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5616331ebf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5616331ebf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561635480f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5616321adb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5616321b8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561631f64c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561631f64c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561631f65738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561631f64874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561631f64874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561631f64874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56163686eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561636877928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56163685f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56163688a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fed6cdaa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561630184b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0x44,0xb,0xa, Step #5: \013D\013\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-a2a3d85e4ca444145d0339f865dc2e3c1ed5b53b Step #5: Base64: C0QLCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 473 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1999647473 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec6b329810, 0x55ec6b51301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec6b513020,0x55ec6d3ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2a3d85e4ca444145d0339f865dc2e3c1ed5b53b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 507 processed earlier; will process 10522 files now Step #5: ==17062== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ec61e1e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec68483898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec684665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec684664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec61e24d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec61d85b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec61d80355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec61e16c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec64de5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec64de5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec64de5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec64de5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec64de5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec64de5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec64de5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec64de5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec64de5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec64de5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec6707af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec63da7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec63db2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec63b5ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec63b5ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec63b5f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec63b5e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec63b5e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec63b5e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec68468abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec68471928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec68459699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec68484112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f360df26082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec61d7eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x4f,0x46,0x27, Step #5: wOF' Step #5: artifact_prefix='./'; Test unit written to ./oom-4924c0796ac01000a615686d6c1f28a6d43c4a74 Step #5: Base64: d09GJw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 474 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2000077153 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611d78ec810, 0x5611d7ad601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5611d7ad6020,0x5611d996e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4924c0796ac01000a615686d6c1f28a6d43c4a74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 508 processed earlier; will process 10521 files now Step #5: ==17098== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5611ce3e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5611d4a46898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611d4a295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611d4a294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5611ce3e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5611ce348b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5611ce343355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5611ce3d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5611d13a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5611d13a8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5611d13a8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5611d13a8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5611d13a8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5611d13a8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5611d13a8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5611d13a8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5611d13a8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5611d13a8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5611d363df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611d036ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5611d0375be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611d0121c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611d0121c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611d0122738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611d0121874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611d0121874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611d0121874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5611d4a2babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5611d4a34928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611d4a1c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5611d4a47112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa51224082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5611ce341b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x4f,0x34,0x32, Step #5: 0O42 Step #5: artifact_prefix='./'; Test unit written to ./oom-d56b68b9e2cbb02011a146d2a634011bfc1fe8b2 Step #5: Base64: ME80Mg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 475 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2000496338 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561aac19f810, 0x561aac38901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561aac389020,0x561aae2210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d56b68b9e2cbb02011a146d2a634011bfc1fe8b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 509 processed earlier; will process 10520 files now Step #5: ==17134== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561aa2c949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561aa92f9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561aa92dc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561aa92dc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561aa2c9ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561aa2bfbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561aa2bf6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561aa2c8cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561aa5c5bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561aa5c5bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561aa5c5bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561aa5c5bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561aa5c5bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561aa5c5bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561aa5c5bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561aa5c5bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561aa5c5bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561aa5c5bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561aa7ef0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561aa4c1db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561aa4c28be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561aa49d4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561aa49d4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561aa49d5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561aa49d4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561aa49d4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561aa49d4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561aa92deabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561aa92e7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561aa92cf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561aa92fa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1b15081082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561aa2bf4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf4,0x8e,0x87,0x91, Step #5: \364\216\207\221 Step #5: artifact_prefix='./'; Test unit written to ./oom-d3eb8e51a77bcd24266030e1d016bf77fb0763e3 Step #5: Base64: 9I6HkQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 476 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2000921067 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d525ec810, 0x557d527d601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d527d6020,0x557d5466e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d3eb8e51a77bcd24266030e1d016bf77fb0763e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 510 processed earlier; will process 10519 files now Step #5: ==17170== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557d490e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557d4f746898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557d4f7295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557d4f7294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557d490e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557d49048b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557d49043355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557d490d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557d4c0a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557d4c0a8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557d4c0a8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557d4c0a8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557d4c0a8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557d4c0a8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557d4c0a8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557d4c0a8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557d4c0a8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557d4c0a8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557d4e33df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557d4b06ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557d4b075be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557d4ae21c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557d4ae21c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557d4ae22738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557d4ae21874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557d4ae21874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557d4ae21874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557d4f72babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557d4f734928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557d4f71c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557d4f747112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f912e150082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557d49041b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x60,0x60,0x3f, Step #5: +``? Step #5: artifact_prefix='./'; Test unit written to ./oom-2cf6582f60bb603ba94bb44e45a212636e47eed7 Step #5: Base64: K2BgPw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 477 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2001463104 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0f278b810, 0x55b0f297501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b0f2975020,0x55b0f480d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2cf6582f60bb603ba94bb44e45a212636e47eed7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 511 processed earlier; will process 10518 files now Step #5: ==17206== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b0e92809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b0ef8e5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b0ef8c85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b0ef8c84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0e9286d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0e91e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0e91e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0e9278c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b0ec247f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b0ec247f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b0ec247f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b0ec247f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b0ec247f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b0ec247f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b0ec247f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b0ec247f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b0ec247f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b0ec247f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b0ee4dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b0eb209b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b0eb214be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b0eafc0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b0eafc0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b0eafc1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b0eafc0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b0eafc0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b0eafc0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b0ef8caabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b0ef8d3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b0ef8bb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b0ef8e6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f74d81d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0e91e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x3a,0x3f,0x42, Step #5: x:?B Step #5: artifact_prefix='./'; Test unit written to ./oom-db17cfbc1ac8f4f54ebcbf572da7b2c08cb39f7e Step #5: Base64: eDo/Qg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 478 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2001891917 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5592b0495810, 0x5592b067f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5592b067f020,0x5592b25170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/db17cfbc1ac8f4f54ebcbf572da7b2c08cb39f7e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 512 processed earlier; will process 10517 files now Step #5: ==17242== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5592a6f8a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5592ad5ef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5592ad5d25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5592ad5d24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592a6f90d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592a6ef1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592a6eec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592a6f82c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592a9f51f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592a9f51f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592a9f51f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592a9f51f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592a9f51f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592a9f51f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592a9f51f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592a9f51f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592a9f51f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592a9f51f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592ac1e6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592a8f13b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592a8f1ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5592a8ccac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5592a8ccac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5592a8ccb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5592a8cca874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5592a8cca874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5592a8cca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5592ad5d4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5592ad5dd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5592ad5c5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5592ad5f0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f50345c7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592a6eeab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x91,0x84,0x80, Step #5: \360\221\204\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-a3e64ce609486db00614861752524ecd62e95bb3 Step #5: Base64: 8JGEgA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 479 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2002304514 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557f26829810, 0x557f26a1301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557f26a13020,0x557f288ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a3e64ce609486db00614861752524ecd62e95bb3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 513 processed earlier; will process 10516 files now Step #5: #1 pulse cov: 3676 ft: 3677 exec/s: 0 rss: 155Mb Step #5: #2 pulse cov: 3829 ft: 3969 exec/s: 0 rss: 156Mb Step #5: ==17278== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557f1d31e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f23983898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f239665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f239664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f1d324d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f1d285b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f1d280355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f1d316c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f202e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f202e5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f202e5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f202e5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f202e5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f202e5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f202e5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f202e5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f202e5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f202e5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f2257af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f1f2a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f1f2b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f1f05ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f1f05ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f1f05f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f1f05e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f1f05e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f1f05e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f23968abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f23971928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f23959699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f23984112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf00ede082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f1d27eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2e,0x2e,0x2e, Step #5: /... Step #5: artifact_prefix='./'; Test unit written to ./oom-4d790d8f73190a3386fabd13f11d20d5fbd7b0c0 Step #5: Base64: Ly4uLg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 480 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2002796671 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cbd7663810, 0x55cbd784d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cbd784d020,0x55cbd96e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4d790d8f73190a3386fabd13f11d20d5fbd7b0c0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 516 processed earlier; will process 10513 files now Step #5: ==17314== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cbce1589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cbd47bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cbd47a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cbd47a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cbce15ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cbce0bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cbce0ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cbce150c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cbd111ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cbd111ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cbd111ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cbd111ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cbd111ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cbd111ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cbd111ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cbd111ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cbd111ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cbd111ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cbd33b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cbd00e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cbd00ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cbcfe98c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cbcfe98c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cbcfe99738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cbcfe98874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cbcfe98874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cbcfe98874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cbd47a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cbd47ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cbd4793699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cbd47be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f22e9801082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cbce0b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7f,0xa,0x24,0x24, Step #5: \177\012$$ Step #5: artifact_prefix='./'; Test unit written to ./oom-11aff4eec32f2f8a829877d57d9dc6520f9d1cf9 Step #5: Base64: fwokJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 481 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2003212599 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557fa4112810, 0x557fa42fc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557fa42fc020,0x557fa61940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/11aff4eec32f2f8a829877d57d9dc6520f9d1cf9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 517 processed earlier; will process 10512 files now Step #5: ==17350== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557f9ac079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557fa126c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557fa124f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557fa124f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f9ac0dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f9ab6eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f9ab69355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f9abffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f9dbcef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f9dbcef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f9dbcef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f9dbcef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f9dbcef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f9dbcef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f9dbcef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f9dbcef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f9dbcef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f9dbcef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f9fe63f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f9cb90b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f9cb9bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f9c947c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f9c947c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f9c948738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f9c947874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f9c947874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f9c947874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557fa1251abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557fa125a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557fa1242699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557fa126d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa2802cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f9ab67b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33,0x33,0x30,0xe, Step #5: 330\016 Step #5: artifact_prefix='./'; Test unit written to ./oom-d62f249e21508db51095ba19a4e3b305edf56009 Step #5: Base64: MzMwDg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 482 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2003626975 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb29c2a810, 0x55eb29e1401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb29e14020,0x55eb2bcac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d62f249e21508db51095ba19a4e3b305edf56009' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 518 processed earlier; will process 10511 files now Step #5: ==17386== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eb2071f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb26d84898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb26d675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb26d674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb20725d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb20686b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb20681355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb20717c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb236e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb236e6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb236e6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb236e6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb236e6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb236e6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb236e6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb236e6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb236e6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb236e6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb2597bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb226a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb226b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb2245fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb2245fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb22460738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb2245f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb2245f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb2245f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb26d69abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb26d72928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb26d5a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb26d85112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff6bd3b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb2067fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x2d,0x24,0x24, Step #5: 1-$$ Step #5: artifact_prefix='./'; Test unit written to ./oom-c7f693c52650e57115a0a7157703ca48ad62df5c Step #5: Base64: MS0kJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 483 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2004038043 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fcb2f3d810, 0x55fcb312701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fcb3127020,0x55fcb4fbf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c7f693c52650e57115a0a7157703ca48ad62df5c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 519 processed earlier; will process 10510 files now Step #5: ==17422== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fca9a329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fcb0097898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fcb007a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fcb007a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fca9a38d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fca9999b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fca9994355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fca9a2ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fcac9f9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fcac9f9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fcac9f9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fcac9f9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fcac9f9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fcac9f9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fcac9f9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fcac9f9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fcac9f9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fcac9f9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fcaec8ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fcab9bbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fcab9c6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fcab772c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fcab772c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fcab773738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fcab772874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fcab772874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fcab772874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fcb007cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fcb0085928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fcb006d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fcb0098112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f78c3d81082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fca9992b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3c,0x77,0x3e, Step #5: ( Step #5: artifact_prefix='./'; Test unit written to ./oom-b50de48adda629150492e9e7ea831b16a50c9cdd Step #5: Base64: KDx3Pg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 484 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2004452697 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff9482d810, 0x55ff94a1701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff94a17020,0x55ff968af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b50de48adda629150492e9e7ea831b16a50c9cdd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 520 processed earlier; will process 10509 files now Step #5: ==17458== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ff8b3229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff91987898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff9196a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff9196a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff8b328d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff8b289b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff8b284355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff8b31ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff8e2e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff8e2e9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff8e2e9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff8e2e9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff8e2e9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff8e2e9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff8e2e9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff8e2e9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff8e2e9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff8e2e9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff9057ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff8d2abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff8d2b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff8d062c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff8d062c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff8d063738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff8d062874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff8d062874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff8d062874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff9196cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff91975928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff9195d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff91988112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8dc40f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff8b282b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x22,0x22,0x22, Step #5: \"\"\"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-5e7a76d4a38b352010c4a8c8ad4aa461f6218793 Step #5: Base64: IiIiIg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 485 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2004866510 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5588ad5a8810, 0x5588ad79201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5588ad792020,0x5588af62a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e7a76d4a38b352010c4a8c8ad4aa461f6218793' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 521 processed earlier; will process 10508 files now Step #5: ==17494== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5588a409d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5588aa702898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588aa6e55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588aa6e54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588a40a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588a4004b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588a3fff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588a4095c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5588a7064f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5588a7064f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5588a7064f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5588a7064f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5588a7064f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5588a7064f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5588a7064f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5588a7064f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5588a7064f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5588a7064f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5588a92f9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588a6026b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588a6031be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588a5dddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588a5dddc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588a5dde738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588a5ddd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588a5ddd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588a5ddd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5588aa6e7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5588aa6f0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5588aa6d8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5588aa703112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f80c923e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588a3ffdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x6f,0x72,0x6d, Step #5: Form Step #5: artifact_prefix='./'; Test unit written to ./oom-80446347ede53cf9ce56b3d59fda4b5c96dc25c4 Step #5: Base64: Rm9ybQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 486 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2005280708 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55df402ba810, 0x55df404a401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55df404a4020,0x55df4233c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/80446347ede53cf9ce56b3d59fda4b5c96dc25c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 522 processed earlier; will process 10507 files now Step #5: ==17530== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55df36daf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55df3d414898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55df3d3f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55df3d3f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55df36db5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55df36d16b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55df36d11355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55df36da7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55df39d76f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55df39d76f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55df39d76f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55df39d76f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55df39d76f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55df39d76f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55df39d76f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55df39d76f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55df39d76f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55df39d76f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55df3c00bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55df38d38b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55df38d43be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55df38aefc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55df38aefc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55df38af0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55df38aef874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55df38aef874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55df38aef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55df3d3f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55df3d402928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55df3d3ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55df3d415112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e0d25c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55df36d0fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x61,0x5b,0x4,0x5d, Step #5: a[\004] Step #5: artifact_prefix='./'; Test unit written to ./oom-e5b43f2811f601dc7bb0b79cd476f068c09d614c Step #5: Base64: YVsEXQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 487 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2005693657 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55df23861810, 0x55df23a4b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55df23a4b020,0x55df258e30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e5b43f2811f601dc7bb0b79cd476f068c09d614c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 523 processed earlier; will process 10506 files now Step #5: ==17566== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55df1a3569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55df209bb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55df2099e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55df2099e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55df1a35cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55df1a2bdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55df1a2b8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55df1a34ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55df1d31df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55df1d31df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55df1d31df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55df1d31df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55df1d31df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55df1d31df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55df1d31df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55df1d31df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55df1d31df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55df1d31df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55df1f5b2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55df1c2dfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55df1c2eabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55df1c096c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55df1c096c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55df1c097738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55df1c096874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55df1c096874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55df1c096874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55df209a0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55df209a9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55df20991699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55df209bc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0103eaa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55df1a2b6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf4,0x85,0xb6,0x99, Step #5: \364\205\266\231 Step #5: artifact_prefix='./'; Test unit written to ./oom-b3a58ecb90ec107c1278cfcac638354ff0da3172 Step #5: Base64: 9IW2mQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 488 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2006114790 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562fd1af5810, 0x562fd1cdf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562fd1cdf020,0x562fd3b770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3a58ecb90ec107c1278cfcac638354ff0da3172' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 524 processed earlier; will process 10505 files now Step #5: ==17602== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562fc85ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562fcec4f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562fcec325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562fcec324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562fc85f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562fc8551b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562fc854c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562fc85e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562fcb5b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562fcb5b1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562fcb5b1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562fcb5b1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562fcb5b1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562fcb5b1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562fcb5b1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562fcb5b1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562fcb5b1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562fcb5b1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562fcd846f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562fca573b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562fca57ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562fca32ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562fca32ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562fca32b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562fca32a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562fca32a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562fca32a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562fcec34abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562fcec3d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562fcec25699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562fcec50112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4add6b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562fc854ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf4,0x8f,0xba,0x9a, Step #5: \364\217\272\232 Step #5: artifact_prefix='./'; Test unit written to ./oom-c11f8bf63fa73beb9bb72598d0c918795177c79d Step #5: Base64: 9I+6mg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 489 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2006537021 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e0d6263810, 0x55e0d644d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e0d644d020,0x55e0d82e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c11f8bf63fa73beb9bb72598d0c918795177c79d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 525 processed earlier; will process 10504 files now Step #5: ==17638== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e0ccd589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e0d33bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e0d33a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e0d33a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e0ccd5ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e0cccbfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e0cccba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e0ccd50c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e0cfd1ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e0cfd1ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e0cfd1ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e0cfd1ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e0cfd1ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e0cfd1ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e0cfd1ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e0cfd1ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e0cfd1ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e0cfd1ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e0d1fb4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e0cece1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e0cececbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e0cea98c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e0cea98c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e0cea99738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e0cea98874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e0cea98874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e0cea98874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e0d33a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e0d33ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e0d3393699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e0d33be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe837d7c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e0cccb8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x91,0x82,0xba, Step #5: \360\221\202\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-a69894eb72202a11a6f8893d092a7beb3aab7baf Step #5: Base64: 8JGCug== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 490 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2006957206 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a165db6810, 0x55a165fa001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a165fa0020,0x55a167e380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a69894eb72202a11a6f8893d092a7beb3aab7baf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 526 processed earlier; will process 10503 files now Step #5: #1 pulse cov: 3461 ft: 3462 exec/s: 0 rss: 155Mb Step #5: ==17674== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a15c8ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a162f10898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a162ef35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a162ef34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a15c8b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a15c812b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a15c80d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a15c8a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a15f872f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a15f872f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a15f872f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a15f872f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a15f872f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a15f872f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a15f872f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a15f872f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a15f872f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a15f872f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a161b07f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a15e834b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a15e83fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a15e5ebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a15e5ebc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a15e5ec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a15e5eb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a15e5eb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a15e5eb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a162ef5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a162efe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a162ee6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a162f11112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feea658e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a15c80bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0x23,0x30,0xa, Step #5: �\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-5a14fe995564c1980305479d5b18a2c5799b4a1f Step #5: Base64: JiMwCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 491 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2007409901 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5581f69f2810, 0x5581f6bdc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5581f6bdc020,0x5581f8a740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5a14fe995564c1980305479d5b18a2c5799b4a1f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 528 processed earlier; will process 10501 files now Step #5: ==17710== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5581ed4e79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5581f3b4c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5581f3b2f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5581f3b2f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5581ed4edd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5581ed44eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5581ed449355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5581ed4dfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5581f04aef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5581f04aef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5581f04aef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5581f04aef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5581f04aef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5581f04aef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5581f04aef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5581f04aef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5581f04aef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5581f04aef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5581f2743f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5581ef470b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5581ef47bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5581ef227c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5581ef227c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5581ef228738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5581ef227874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5581ef227874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5581ef227874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5581f3b31abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5581f3b3a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5581f3b22699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5581f3b4d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6fbc7cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5581ed447b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf1,0xbf,0xbf,0xbf, Step #5: \361\277\277\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-d01ff39c0800360ff31398cb1d34dea09a6af7d4 Step #5: Base64: 8b+/vw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 492 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2007823820 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1d1bb6810, 0x55a1d1da001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1d1da0020,0x55a1d3c380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d01ff39c0800360ff31398cb1d34dea09a6af7d4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 529 processed earlier; will process 10500 files now Step #5: ==17746== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a1c86ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1ced10898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1cecf35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1cecf34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1c86b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1c8612b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1c860d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1c86a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1cb672f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1cb672f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1cb672f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1cb672f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1cb672f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1cb672f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1cb672f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1cb672f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1cb672f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1cb672f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1cd907f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1ca634b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1ca63fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1ca3ebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1ca3ebc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1ca3ec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1ca3eb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1ca3eb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1ca3eb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a1cecf5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a1cecfe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1cece6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1ced11112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbc76065082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1c860bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x91,0x8b,0x93, Step #5: \360\221\213\223 Step #5: artifact_prefix='./'; Test unit written to ./oom-db218433e7c9d71d74819a70f3dfe4787e67b102 Step #5: Base64: 8JGLkw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 493 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2008239285 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d63f642810, 0x55d63f82c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d63f82c020,0x55d6416c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/db218433e7c9d71d74819a70f3dfe4787e67b102' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 530 processed earlier; will process 10499 files now Step #5: ==17782== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d6361379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d63c79c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d63c77f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d63c77f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d63613dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d63609eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d636099355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d63612fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d6390fef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d6390fef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d6390fef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d6390fef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d6390fef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d6390fef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d6390fef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d6390fef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d6390fef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d6390fef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d63b393f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d6380c0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d6380cbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d637e77c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d637e77c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d637e78738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d637e77874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d637e77874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d637e77874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d63c781abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d63c78a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d63c772699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d63c79d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4c4bf04082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d636097b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x90,0x90,0x80, Step #5: \360\220\220\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-534afaee86a82f32bb592a608a465d996ba0c38d Step #5: Base64: 8JCQgA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 494 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2008652036 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a87823d810, 0x55a87842701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a878427020,0x55a87a2bf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/534afaee86a82f32bb592a608a465d996ba0c38d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 531 processed earlier; will process 10498 files now Step #5: ==17818== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a86ed329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a875397898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a87537a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a87537a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a86ed38d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a86ec99b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a86ec94355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a86ed2ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a871cf9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a871cf9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a871cf9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a871cf9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a871cf9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a871cf9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a871cf9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a871cf9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a871cf9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a871cf9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a873f8ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a870cbbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a870cc6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a870a72c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a870a72c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a870a73738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a870a72874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a870a72874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a870a72874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a87537cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a875385928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a87536d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a875398112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efc410a2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a86ec92b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x4a,0x32,0xf0, Step #5: BJ2\360 Step #5: artifact_prefix='./'; Test unit written to ./oom-f36edf4da3a5f334a0f86a09d8184735e15f79b7 Step #5: Base64: Qkoy8A== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 495 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2009069597 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5590fd6fb810, 0x5590fd8e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5590fd8e5020,0x5590ff77d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f36edf4da3a5f334a0f86a09d8184735e15f79b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 532 processed earlier; will process 10497 files now Step #5: #1 pulse cov: 3397 ft: 3398 exec/s: 0 rss: 154Mb Step #5: ==17854== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5590f41f09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5590fa855898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5590fa8385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5590fa8384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5590f41f6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5590f4157b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5590f4152355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5590f41e8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5590f71b7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5590f71b7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5590f71b7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5590f71b7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5590f71b7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5590f71b7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5590f71b7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5590f71b7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5590f71b7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5590f71b7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5590f944cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5590f6179b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5590f6184be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5590f5f30c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5590f5f30c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5590f5f31738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5590f5f30874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5590f5f30874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5590f5f30874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5590fa83aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5590fa843928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5590fa82b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5590fa856112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f510010c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5590f4150b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xc,0x2f,0x3d, Step #5: <\014/= Step #5: artifact_prefix='./'; Test unit written to ./oom-ff290a97714679e2882103ff47d794c9bba36088 Step #5: Base64: PAwvPQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 496 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2009529368 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5628729b7810, 0x562872ba101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562872ba1020,0x562874a390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ff290a97714679e2882103ff47d794c9bba36088' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 534 processed earlier; will process 10495 files now Step #5: ==17890== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5628694ac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56286fb11898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56286faf45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56286faf44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5628694b2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562869413b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56286940e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5628694a4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56286c473f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56286c473f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56286c473f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56286c473f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56286c473f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56286c473f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56286c473f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56286c473f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56286c473f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56286c473f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56286e708f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56286b435b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56286b440be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56286b1ecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56286b1ecc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56286b1ed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56286b1ec874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56286b1ec874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56286b1ec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56286faf6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56286faff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56286fae7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56286fb12112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0699823082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56286940cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0xaf,0x8e,0xaf, Step #5: \360\257\216\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-48c4713cfdb17e7762a2c489a17713d01b0f1b71 Step #5: Base64: 8K+Orw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 497 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2009947803 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dec3e65810, 0x55dec404f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dec404f020,0x55dec5ee70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/48c4713cfdb17e7762a2c489a17713d01b0f1b71' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 535 processed earlier; will process 10494 files now Step #5: #1 pulse cov: 3538 ft: 3539 exec/s: 0 rss: 157Mb Step #5: ==17926== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55deba95a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dec0fbf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dec0fa25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dec0fa24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55deba960d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55deba8c1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55deba8bc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55deba952c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55debd921f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55debd921f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55debd921f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55debd921f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55debd921f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55debd921f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55debd921f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55debd921f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55debd921f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55debd921f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55debfbb6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55debc8e3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55debc8eebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55debc69ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55debc69ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55debc69b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55debc69a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55debc69a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55debc69a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dec0fa4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dec0fad928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dec0f95699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dec0fc0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8573a05082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55deba8bab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x28,0x29,0x0, Step #5: ^()\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e9aad4357aebda47158acf3a4c9eda001a7c3aa5 Step #5: Base64: XigpAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 498 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2010406300 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5604d4850810, 0x5604d4a3a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604d4a3a020,0x5604d68d20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e9aad4357aebda47158acf3a4c9eda001a7c3aa5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 537 processed earlier; will process 10492 files now Step #5: ==17962== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5604cb3459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5604d19aa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5604d198d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5604d198d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5604cb34bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5604cb2acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5604cb2a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5604cb33dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5604ce30cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5604ce30cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5604ce30cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5604ce30cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5604ce30cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5604ce30cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5604ce30cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5604ce30cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5604ce30cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5604ce30cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5604d05a1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5604cd2ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5604cd2d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5604cd085c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5604cd085c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5604cd086738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5604cd085874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5604cd085874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5604cd085874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5604d198fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5604d1998928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5604d1980699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5604d19ab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcd13b85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5604cb2a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0x3a,0x23,0x68, Step #5: i:#h Step #5: artifact_prefix='./'; Test unit written to ./oom-44eca241f94cfe0bf57d4b5ed36b0cb7ef0be2b0 Step #5: Base64: aTojaA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 499 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2010826906 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5609f1e82810, 0x5609f206c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5609f206c020,0x5609f3f040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/44eca241f94cfe0bf57d4b5ed36b0cb7ef0be2b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 538 processed earlier; will process 10491 files now Step #5: ==17998== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5609e89779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5609eefdc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5609eefbf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5609eefbf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5609e897dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5609e88deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5609e88d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5609e896fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5609eb93ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5609eb93ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5609eb93ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5609eb93ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5609eb93ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5609eb93ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5609eb93ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5609eb93ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5609eb93ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5609eb93ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5609edbd3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5609ea900b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5609ea90bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5609ea6b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5609ea6b7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5609ea6b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5609ea6b7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5609ea6b7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5609ea6b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5609eefc1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5609eefca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5609eefb2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5609eefdd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f115c711082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5609e88d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x6c,0x3a,0x3e, Step #5: Step #5: artifact_prefix='./'; Test unit written to ./oom-24ea30e758ce4da239458494f35a28bb7d7052de Step #5: Base64: PGw6Pg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 500 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2011225177 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f21448e810, 0x55f21467801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f214678020,0x55f2165100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/24ea30e758ce4da239458494f35a28bb7d7052de' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 539 processed earlier; will process 10490 files now Step #5: ==18034== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f20af839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f2115e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f2115cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f2115cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f20af89d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f20aeeab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f20aee5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f20af7bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f20df4af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f20df4af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f20df4af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f20df4af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f20df4af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f20df4af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f20df4af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f20df4af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f20df4af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f20df4af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f2101dff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f20cf0cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f20cf17be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f20ccc3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f20ccc3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f20ccc4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f20ccc3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f20ccc3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f20ccc3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f2115cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f2115d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f2115be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f2115e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8fdc42e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f20aee3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x29,0xdc,0xbd, Step #5: \001)\334\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-a5e9aa335712f9e6a69802305f7e6f5d0d6414ee Step #5: Base64: ASncvQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 501 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2011643147 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56054c748810, 0x56054c93201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56054c932020,0x56054e7ca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a5e9aa335712f9e6a69802305f7e6f5d0d6414ee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 540 processed earlier; will process 10489 files now Step #5: #1 pulse cov: 6471 ft: 6472 exec/s: 0 rss: 169Mb Step #5: ==18070== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56054323d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605498a2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605498855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605498854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560543243d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605431a4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56054319f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560543235c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560546204f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560546204f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560546204f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560546204f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560546204f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560546204f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560546204f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560546204f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560546204f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560546204f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560548499f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5605451c6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5605451d1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560544f7dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560544f7dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560544f7e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560544f7d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560544f7d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560544f7d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560549887abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560549890928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560549878699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605498a3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f38231a7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56054319db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xef,0xbc,0x88, Step #5: <\357\274\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-0f6ea9cd44c02f0e93b000d5060b28c8fb4f3b88 Step #5: Base64: PO+8iA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 502 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2012110478 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c148b55810, 0x55c148d3f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c148d3f020,0x55c14abd70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0f6ea9cd44c02f0e93b000d5060b28c8fb4f3b88' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 542 processed earlier; will process 10487 files now Step #5: ==18106== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c13f64a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c145caf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c145c925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c145c924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c13f650d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c13f5b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c13f5ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c13f642c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c142611f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c142611f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c142611f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c142611f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c142611f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c142611f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c142611f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c142611f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c142611f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c142611f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c1448a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c1415d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c1415debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c14138ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c14138ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c14138b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c14138a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c14138a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c14138a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c145c94abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c145c9d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c145c85699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c145cb0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff13b434082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c13f5aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x40,0xa,0x3d,0x3d, Step #5: @\012== Step #5: artifact_prefix='./'; Test unit written to ./oom-1b391dc7d837273701e4ac0eb8b59aea6db25b3d Step #5: Base64: QAo9PQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 503 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2012529391 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562aab8b7810, 0x562aabaa101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562aabaa1020,0x562aad9390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b391dc7d837273701e4ac0eb8b59aea6db25b3d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 543 processed earlier; will process 10486 files now Step #5: ==18142== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562aa23ac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562aa8a11898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562aa89f45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562aa89f44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562aa23b2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562aa2313b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562aa230e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562aa23a4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562aa5373f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562aa5373f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562aa5373f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562aa5373f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562aa5373f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562aa5373f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562aa5373f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562aa5373f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562aa5373f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562aa5373f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562aa7608f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562aa4335b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562aa4340be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562aa40ecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562aa40ecc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562aa40ed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562aa40ec874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562aa40ec874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562aa40ec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562aa89f6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562aa89ff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562aa89e7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562aa8a12112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2451075082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562aa230cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0xc5,0xbc,0x3a, Step #5: 2\305\274: Step #5: artifact_prefix='./'; Test unit written to ./oom-af9a61f3cb784ffc84e4700c1c83fa0750cd77d3 Step #5: Base64: MsW8Og== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 504 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2012941950 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e970be9810, 0x55e970dd301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e970dd3020,0x55e972c6b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af9a61f3cb784ffc84e4700c1c83fa0750cd77d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 544 processed earlier; will process 10485 files now Step #5: ==18178== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e9676de9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e96dd43898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e96dd265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e96dd264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9676e4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e967645b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e967640355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9676d6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e96a6a5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e96a6a5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e96a6a5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e96a6a5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e96a6a5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e96a6a5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e96a6a5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e96a6a5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e96a6a5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e96a6a5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e96c93af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e969667b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e969672be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e96941ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e96941ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e96941f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e96941e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e96941e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e96941e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e96dd28abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e96dd31928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e96dd19699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e96dd44112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f960dcdb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e96763eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x54,0xc2,0xad,0xad, Step #5: T\302\255\255 Step #5: artifact_prefix='./'; Test unit written to ./oom-9b25bc8e2991ebba4279218b0069a89a43014e93 Step #5: Base64: VMKtrQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 505 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2013355373 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557c2744d810, 0x557c2763701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557c27637020,0x557c294cf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9b25bc8e2991ebba4279218b0069a89a43014e93' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 545 processed earlier; will process 10484 files now Step #5: ==18214== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557c1df429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557c245a7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557c2458a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557c2458a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557c1df48d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557c1dea9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557c1dea4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557c1df3ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557c20f09f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557c20f09f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557c20f09f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557c20f09f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557c20f09f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557c20f09f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557c20f09f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557c20f09f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557c20f09f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557c20f09f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557c2319ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557c1fecbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557c1fed6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557c1fc82c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557c1fc82c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557c1fc83738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557c1fc82874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557c1fc82874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557c1fc82874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557c2458cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557c24595928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557c2457d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557c245a8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f94810ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557c1dea2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x40,0x40,0xc, Step #5: \001@@\014 Step #5: artifact_prefix='./'; Test unit written to ./oom-0f54e37d91b957a4bfd13f03fea70dade3e2f4ec Step #5: Base64: AUBADA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 506 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2013766307 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559bd6419810, 0x559bd660301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559bd6603020,0x559bd849b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0f54e37d91b957a4bfd13f03fea70dade3e2f4ec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 546 processed earlier; will process 10483 files now Step #5: ==18250== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559bccf0e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559bd3573898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559bd35565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559bd35564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559bccf14d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559bcce75b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559bcce70355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559bccf06c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559bcfed5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559bcfed5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559bcfed5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559bcfed5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559bcfed5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559bcfed5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559bcfed5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559bcfed5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559bcfed5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559bcfed5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559bd216af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559bcee97b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559bceea2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559bcec4ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559bcec4ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559bcec4f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559bcec4e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559bcec4e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559bcec4e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559bd3558abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559bd3561928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559bd3549699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559bd3574112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb5177ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559bcce6eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0xb,0xb,0xb, Step #5: \013\013\013\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-cafe11f51cfc647005c116e1eb03c0a34abdf5dc Step #5: Base64: CwsLCw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 507 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2014172069 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d5a928810, 0x561d5ab1201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d5ab12020,0x561d5c9aa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cafe11f51cfc647005c116e1eb03c0a34abdf5dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 547 processed earlier; will process 10482 files now Step #5: ==18286== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561d5141d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d57a82898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d57a655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d57a654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d51423d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d51384b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d5137f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d51415c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d543e4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d543e4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d543e4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d543e4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d543e4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d543e4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d543e4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d543e4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d543e4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d543e4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d56679f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d533a6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d533b1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d5315dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d5315dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d5315e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d5315d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d5315d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d5315d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d57a67abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d57a70928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d57a58699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d57a83112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5da332f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d5137db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x92,0xad,0xbe, Step #5: \360\222\255\276 Step #5: artifact_prefix='./'; Test unit written to ./oom-5df9427c18a1265d6af52e297945d6b204a7b0fa Step #5: Base64: 8JKtvg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 508 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2014591020 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5608cc6f3810, 0x5608cc8dd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5608cc8dd020,0x5608ce7750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5df9427c18a1265d6af52e297945d6b204a7b0fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 548 processed earlier; will process 10481 files now Step #5: ==18322== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5608c31e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5608c984d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608c98305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608c98304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5608c31eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5608c314fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5608c314a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5608c31e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5608c61aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5608c61aff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5608c61aff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5608c61aff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5608c61aff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5608c61aff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5608c61aff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5608c61aff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5608c61aff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5608c61aff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608c8444f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5608c5171b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5608c517cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5608c4f28c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5608c4f28c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5608c4f29738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5608c4f28874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5608c4f28874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5608c4f28874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5608c9832abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5608c983b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5608c9823699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5608c984e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f00f20d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5608c3148b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x41,0x41,0x3e, Step #5: Step #5: artifact_prefix='./'; Test unit written to ./oom-62accfe90d43b78d653d62d6160b8dc494d5ac92 Step #5: Base64: PEFBPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 509 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2015001193 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e62137e810, 0x55e62156801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e621568020,0x55e6234000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/62accfe90d43b78d653d62d6160b8dc494d5ac92' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 549 processed earlier; will process 10480 files now Step #5: ==18358== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e617e739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e61e4d8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e61e4bb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e61e4bb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e617e79d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e617ddab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e617dd5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e617e6bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e61ae3af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e61ae3af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e61ae3af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e61ae3af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e61ae3af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e61ae3af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e61ae3af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e61ae3af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e61ae3af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e61ae3af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e61d0cff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e619dfcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e619e07be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e619bb3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e619bb3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e619bb4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e619bb3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e619bb3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e619bb3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e61e4bdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e61e4c6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e61e4ae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e61e4d9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c22fca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e617dd3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x3a,0x21,0x30, Step #5: A:!0 Step #5: artifact_prefix='./'; Test unit written to ./oom-e632056edf099b196b73fc0a11e50752210b561e Step #5: Base64: QTohMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 510 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2015418021 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c95f55810, 0x564c9613f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c9613f020,0x564c97fd70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e632056edf099b196b73fc0a11e50752210b561e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 550 processed earlier; will process 10479 files now Step #5: ==18394== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564c8ca4a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c930af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c930925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c930924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c8ca50d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c8c9b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c8c9ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c8ca42c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c8fa11f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c8fa11f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c8fa11f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c8fa11f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c8fa11f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c8fa11f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c8fa11f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c8fa11f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c8fa11f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c8fa11f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c91ca6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c8e9d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c8e9debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c8e78ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c8e78ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c8e78b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c8e78a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c8e78a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c8e78a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c93094abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c9309d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c93085699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c930b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe8d9cab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c8c9aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xe2,0xbf,0xa1, Step #5: <\342\277\241 Step #5: artifact_prefix='./'; Test unit written to ./oom-cd976c18af5af82bb1d26d044e75a5730a3665c6 Step #5: Base64: POK/oQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 511 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2015838073 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d7778c7810, 0x55d777ab101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d777ab1020,0x55d7799490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd976c18af5af82bb1d26d044e75a5730a3665c6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 551 processed earlier; will process 10478 files now Step #5: ==18430== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d76e3bc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d774a21898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d774a045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d774a044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d76e3c2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d76e323b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d76e31e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d76e3b4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d771383f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d771383f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d771383f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d771383f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d771383f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d771383f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d771383f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d771383f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d771383f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d771383f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d773618f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d770345b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d770350be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d7700fcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d7700fcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d7700fd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d7700fc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d7700fc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d7700fc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d774a06abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d774a0f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d7749f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d774a22112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efc7de27082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d76e31cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xbd,0xb6,0x3d, Step #5: \340\275\266= Step #5: artifact_prefix='./'; Test unit written to ./oom-866b865ff43d088591b0f5d588bbc57feb08b179 Step #5: Base64: 4L22PQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 512 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2016250165 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5637f18f9810, 0x5637f1ae301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5637f1ae3020,0x5637f397b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/866b865ff43d088591b0f5d588bbc57feb08b179' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 552 processed earlier; will process 10477 files now Step #5: ==18466== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5637e83ee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5637eea53898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5637eea365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5637eea364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5637e83f4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5637e8355b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5637e8350355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5637e83e6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5637eb3b5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5637eb3b5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5637eb3b5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5637eb3b5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5637eb3b5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5637eb3b5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5637eb3b5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5637eb3b5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5637eb3b5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5637eb3b5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5637ed64af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5637ea377b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5637ea382be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5637ea12ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5637ea12ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5637ea12f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5637ea12e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5637ea12e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5637ea12e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5637eea38abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5637eea41928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5637eea29699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5637eea54112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9cb7a3c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5637e834eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xbc,0xbf,0xbf, Step #5: \363\274\277\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-a1490e8cf6f13812b5428c9a7ca7c7f3503f6e3f Step #5: Base64: 87y/vw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 513 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2016664486 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a1e99d810, 0x561a1eb8701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a1eb87020,0x561a20a1f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a1490e8cf6f13812b5428c9a7ca7c7f3503f6e3f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 553 processed earlier; will process 10476 files now Step #5: ==18502== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561a154929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561a1baf7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561a1bada5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561a1bada4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561a15498d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561a153f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561a153f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561a1548ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561a18459f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561a18459f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561a18459f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561a18459f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561a18459f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561a18459f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561a18459f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561a18459f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561a18459f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561a18459f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561a1a6eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561a1741bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561a17426be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561a171d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561a171d2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561a171d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561a171d2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561a171d2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561a171d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561a1badcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561a1bae5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561a1bacd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561a1baf8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb9ff9c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561a153f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0xd,0xd,0x2e, Step #5: \015\015\015. Step #5: artifact_prefix='./'; Test unit written to ./oom-56d28e04c10ac3631cbf61214de5efe5d437858a Step #5: Base64: DQ0NLg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 514 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2017081292 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aeacccd810, 0x55aeaceb701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aeaceb7020,0x55aeaed4f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56d28e04c10ac3631cbf61214de5efe5d437858a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 554 processed earlier; will process 10475 files now Step #5: ==18538== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55aea37c29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aea9e27898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aea9e0a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aea9e0a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aea37c8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aea3729b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aea3724355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aea37bac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aea6789f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aea6789f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aea6789f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aea6789f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aea6789f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aea6789f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aea6789f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aea6789f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aea6789f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aea6789f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aea8a1ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aea574bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aea5756be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aea5502c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aea5502c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aea5503738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aea5502874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aea5502874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aea5502874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aea9e0cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aea9e15928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aea9dfd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aea9e28112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb4aeaf1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aea3722b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf2,0xbe,0xa4,0x80, Step #5: \362\276\244\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-4cbf435b85519599cd17d260a78e74502cab443f Step #5: Base64: 8r6kgA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 515 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2017493563 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5592059c7810, 0x559205bb101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559205bb1020,0x559207a490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4cbf435b85519599cd17d260a78e74502cab443f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 555 processed earlier; will process 10474 files now Step #5: ==18574== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5591fc4bc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559202b21898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559202b045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559202b044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5591fc4c2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5591fc423b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5591fc41e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5591fc4b4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5591ff483f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5591ff483f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5591ff483f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5591ff483f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5591ff483f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5591ff483f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5591ff483f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5591ff483f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5591ff483f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5591ff483f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559201718f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5591fe445b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5591fe450be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5591fe1fcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5591fe1fcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5591fe1fd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5591fe1fc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5591fe1fc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5591fe1fc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559202b06abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559202b0f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559202af7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559202b22112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe6d978e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5591fc41cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0xe1,0x9f,0xb6, Step #5: ?\341\237\266 Step #5: artifact_prefix='./'; Test unit written to ./oom-3dba75b5915cef91a1e07db5b1da21d087368af4 Step #5: Base64: P+Gftg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 516 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2017911951 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564afc3a3810, 0x564afc58d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564afc58d020,0x564afe4250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3dba75b5915cef91a1e07db5b1da21d087368af4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 556 processed earlier; will process 10473 files now Step #5: ==18610== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564af2e989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564af94fd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564af94e05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564af94e04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564af2e9ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564af2dffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564af2dfa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564af2e90c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564af5e5ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564af5e5ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564af5e5ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564af5e5ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564af5e5ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564af5e5ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564af5e5ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564af5e5ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564af5e5ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564af5e5ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564af80f4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564af4e21b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564af4e2cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564af4bd8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564af4bd8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564af4bd9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564af4bd8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564af4bd8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564af4bd8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564af94e2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564af94eb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564af94d3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564af94fe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe34cff8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564af2df8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x41,0x3e,0xc3, Step #5: \303 Step #5: artifact_prefix='./'; Test unit written to ./oom-531ef8da3a6faa2ddd38856cac1ce48812ed0fb3 Step #5: Base64: PEE+ww== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 517 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2018317612 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d50e10b810, 0x55d50e2f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d50e2f5020,0x55d51018d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/531ef8da3a6faa2ddd38856cac1ce48812ed0fb3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 557 processed earlier; will process 10472 files now Step #5: ==18646== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d504c009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d50b265898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d50b2485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d50b2484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d504c06d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d504b67b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d504b62355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d504bf8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d507bc7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d507bc7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d507bc7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d507bc7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d507bc7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d507bc7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d507bc7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d507bc7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d507bc7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d507bc7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d509e5cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d506b89b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d506b94be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d506940c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d506940c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d506941738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d506940874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d506940874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d506940874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d50b24aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d50b253928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d50b23b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d50b266112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f087642f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d504b60b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x24,0x24,0x5b, Step #5: A$$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-a2ad7da1950b5f06d76bb8f8180c383b32e45010 Step #5: Base64: QSQkWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 518 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2018739944 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f4fcab1810, 0x55f4fcc9b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f4fcc9b020,0x55f4feb330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2ad7da1950b5f06d76bb8f8180c383b32e45010' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 558 processed earlier; will process 10471 files now Step #5: ==18682== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f4f35a69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f4f9c0b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f4f9bee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f4f9bee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f4f35acd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f4f350db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f4f3508355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f4f359ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f4f656df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f4f656df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f4f656df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f4f656df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f4f656df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f4f656df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f4f656df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f4f656df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f4f656df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f4f656df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4f8802f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4f552fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4f553abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f4f52e6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f4f52e6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f4f52e7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f4f52e6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f4f52e6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f4f52e6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f4f9bf0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f4f9bf9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f4f9be1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f4f9c0c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68e0e5b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f4f3506b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa,0x7e, Step #5: \012\012\012~ Step #5: artifact_prefix='./'; Test unit written to ./oom-1d8e8fae5586ac9d176ba9da6e2ad6d7ac21a13a Step #5: Base64: CgoKfg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 519 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2019157384 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab07732810, 0x55ab0791c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab0791c020,0x55ab097b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1d8e8fae5586ac9d176ba9da6e2ad6d7ac21a13a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 559 processed earlier; will process 10470 files now Step #5: ==18718== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55aafe2279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab0488c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab0486f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab0486f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aafe22dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aafe18eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aafe189355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aafe21fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab011eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab011eef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab011eef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab011eef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab011eef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab011eef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab011eef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab011eef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab011eef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab011eef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab03483f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab001b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab001bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aafff67c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aafff67c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aafff68738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aafff67874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aafff67874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aafff67874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab04871abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab0487a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab04862699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab0488d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff22096a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aafe187b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x18,0x74,0x74, Step #5: <\030tt Step #5: artifact_prefix='./'; Test unit written to ./oom-94dba2af1022f64da98bc95ff3b3dba00950afc1 Step #5: Base64: PBh0dA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 520 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2019573822 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559b9a0c4810, 0x559b9a2ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559b9a2ae020,0x559b9c1460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/94dba2af1022f64da98bc95ff3b3dba00950afc1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 560 processed earlier; will process 10469 files now Step #5: ==18754== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559b90bb99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559b9721e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559b972015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559b972014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b90bbfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b90b20b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b90b1b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b90bb1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b93b80f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b93b80f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b93b80f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b93b80f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b93b80f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b93b80f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b93b80f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b93b80f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b93b80f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b93b80f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559b95e15f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b92b42b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b92b4dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b928f9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b928f9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b928fa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b928f9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b928f9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b928f9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559b97203abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559b9720c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559b971f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559b9721f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5b65955082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b90b19b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xef,0xb8,0x8f, Step #5: \"\357\270\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-fee0c1539c5a7279c1a51f403bcae093ac6455af Step #5: Base64: Iu+4jw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 521 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2019991615 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3c1089810, 0x55a3c127301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3c1273020,0x55a3c310b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fee0c1539c5a7279c1a51f403bcae093ac6455af' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 561 processed earlier; will process 10468 files now Step #5: ==18790== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a3b7b7e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3be1e3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3be1c65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3be1c64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3b7b84d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a3b7ae5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a3b7ae0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3b7b76c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a3bab45f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a3bab45f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a3bab45f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a3bab45f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a3bab45f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a3bab45f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a3bab45f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a3bab45f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a3bab45f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a3bab45f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3bcddaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3b9b07b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3b9b12be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3b98bec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3b98bec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3b98bf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3b98be874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3b98be874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3b98be874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a3be1c8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a3be1d1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3be1b9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3be1e4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7efb30082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a3b7adeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x80,0x82,0x5b, Step #5: \342\200\202[ Step #5: artifact_prefix='./'; Test unit written to ./oom-a32576da59d087d50a53e9d68ca51efae7add6d4 Step #5: Base64: 4oCCWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 522 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2020407267 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4e2f71810, 0x55e4e315b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4e315b020,0x55e4e4ff30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a32576da59d087d50a53e9d68ca51efae7add6d4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 562 processed earlier; will process 10467 files now Step #5: ==18826== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e4d9a669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4e00cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4e00ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4e00ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4d9a6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4d99cdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4d99c8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4d9a5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4dca2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4dca2df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4dca2df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4dca2df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4dca2df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4dca2df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4dca2df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4dca2df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4dca2df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4dca2df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4decc2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4db9efb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4db9fabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4db7a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4db7a6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4db7a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4db7a6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4db7a6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4db7a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4e00b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4e00b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4e00a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4e00cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f52a8c86082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4d99c6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x1,0x1d,0x4d, Step #5: D\001\035M Step #5: artifact_prefix='./'; Test unit written to ./oom-65324671c009c6add3d99679cc8aeb243bc67359 Step #5: Base64: RAEdTQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 523 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2020834444 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f772956810, 0x55f772b4001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f772b40020,0x55f7749d80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/65324671c009c6add3d99679cc8aeb243bc67359' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 563 processed earlier; will process 10466 files now Step #5: ==18862== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f76944b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f76fab0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f76fa935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f76fa934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f769451d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f7693b2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f7693ad355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f769443c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f76c412f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f76c412f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f76c412f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f76c412f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f76c412f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f76c412f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f76c412f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f76c412f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f76c412f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f76c412f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f76e6a7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f76b3d4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f76b3dfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f76b18bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f76b18bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f76b18c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f76b18b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f76b18b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f76b18b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f76fa95abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f76fa9e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f76fa86699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f76fab1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f513f86c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f7693abb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x79,0x70,0x65, Step #5: type Step #5: artifact_prefix='./'; Test unit written to ./oom-d0a3e7f81a9885e99049d1cae0336d269d5e47a9 Step #5: Base64: dHlwZQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 524 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2021267884 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5562b7896810, 0x5562b7a8001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5562b7a80020,0x5562b99180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d0a3e7f81a9885e99049d1cae0336d269d5e47a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 564 processed earlier; will process 10465 files now Step #5: ==18898== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5562ae38b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5562b49f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5562b49d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5562b49d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5562ae391d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5562ae2f2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5562ae2ed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5562ae383c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5562b1352f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5562b1352f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5562b1352f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5562b1352f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5562b1352f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5562b1352f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5562b1352f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5562b1352f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5562b1352f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5562b1352f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5562b35e7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5562b0314b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5562b031fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5562b00cbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5562b00cbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5562b00cc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5562b00cb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5562b00cb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5562b00cb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5562b49d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5562b49de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5562b49c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5562b49f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d81078082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5562ae2ebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf4,0x8d,0xba,0xbb, Step #5: \364\215\272\273 Step #5: artifact_prefix='./'; Test unit written to ./oom-bb1963b15cc7cd79c2640e471ff3f0a0fef74cc0 Step #5: Base64: 9I26uw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 525 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2021690289 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ce20f36810, 0x55ce2112001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ce21120020,0x55ce22fb80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bb1963b15cc7cd79c2640e471ff3f0a0fef74cc0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 565 processed earlier; will process 10464 files now Step #5: ==18934== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ce17a2b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ce1e090898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ce1e0735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ce1e0734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ce17a31d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ce17992b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ce1798d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ce17a23c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ce1a9f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ce1a9f2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ce1a9f2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ce1a9f2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ce1a9f2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ce1a9f2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ce1a9f2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ce1a9f2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ce1a9f2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ce1a9f2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ce1cc87f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ce199b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ce199bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ce1976bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ce1976bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ce1976c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ce1976b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ce1976b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ce1976b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ce1e075abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ce1e07e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ce1e066699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ce1e091112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ba2b20082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ce1798bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0xe1,0x9f,0x96, Step #5: ?\341\237\226 Step #5: artifact_prefix='./'; Test unit written to ./oom-0582db50fadbc0de1e2447c4dc70c781f7ea9059 Step #5: Base64: P+Gflg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 526 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2022113433 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560e6ed7c810, 0x560e6ef6601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560e6ef66020,0x560e70dfe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0582db50fadbc0de1e2447c4dc70c781f7ea9059' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 566 processed earlier; will process 10463 files now Step #5: ==18970== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560e658719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560e6bed6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560e6beb95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560e6beb94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560e65877d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560e657d8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560e657d3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560e65869c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560e68838f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560e68838f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560e68838f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560e68838f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560e68838f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560e68838f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560e68838f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560e68838f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560e68838f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560e68838f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560e6aacdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560e677fab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560e67805be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560e675b1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560e675b1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560e675b2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560e675b1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560e675b1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560e675b1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560e6bebbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560e6bec4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560e6beac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560e6bed7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a7d21b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560e657d1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0xcc,0x80, Step #5: Step #5: Step #5: #0 0x5605e920c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605ef871898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605ef8545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605ef8544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5605e9212d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605e9173b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5605e916e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5605e9204c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605ec1d3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605ec1d3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605ec1d3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605ec1d3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605ec1d3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605ec1d3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605ec1d3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605ec1d3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605ec1d3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605ec1d3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605ee468f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5605eb195b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5605eb1a0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5605eaf4cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5605eaf4cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5605eaf4d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5605eaf4c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5605eaf4c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5605eaf4c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605ef856abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5605ef85f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605ef847699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605ef872112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1afc439082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5605e916cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x4c,0x20,0x7, Step #5: -L \007 Step #5: artifact_prefix='./'; Test unit written to ./oom-56c57ab2874d46cc1bb8c82048d2b6dd23c3b697 Step #5: Base64: LUwgBw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 528 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2022948988 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55932f749810, 0x55932f93301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55932f933020,0x5593317cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56c57ab2874d46cc1bb8c82048d2b6dd23c3b697' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 568 processed earlier; will process 10461 files now Step #5: ==19042== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55932623e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55932c8a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55932c8865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55932c8864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559326244d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5593261a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5593261a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559326236c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559329205f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559329205f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559329205f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559329205f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559329205f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559329205f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559329205f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559329205f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559329205f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559329205f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55932b49af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5593281c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5593281d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559327f7ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559327f7ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559327f7f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559327f7e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559327f7e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559327f7e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55932c888abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55932c891928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55932c879699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55932c8a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fef1c27a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55932619eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x3c,0xdb,0xbe, Step #5: B<\333\276 Step #5: artifact_prefix='./'; Test unit written to ./oom-fad3c6bed617342683a262598f2f8091940ebf8b Step #5: Base64: Qjzbvg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 529 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2023371804 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e7d384a810, 0x55e7d3a3401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e7d3a34020,0x55e7d58cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fad3c6bed617342683a262598f2f8091940ebf8b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 569 processed earlier; will process 10460 files now Step #5: ==19078== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e7ca33f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e7d09a4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7d09875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7d09874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e7ca345d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e7ca2a6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e7ca2a1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e7ca337c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e7cd306f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e7cd306f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e7cd306f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e7cd306f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e7cd306f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e7cd306f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e7cd306f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e7cd306f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e7cd306f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e7cd306f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e7cf59bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e7cc2c8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e7cc2d3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e7cc07fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e7cc07fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e7cc080738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e7cc07f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e7cc07f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e7cc07f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e7d0989abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e7d0992928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e7d097a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e7d09a5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1f30c02082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e7ca29fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x3a,0x60,0x20, Step #5: `:` Step #5: artifact_prefix='./'; Test unit written to ./oom-412e52d7dc988a56ec5bbc54af51b4322436e5dc Step #5: Base64: YDpgIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 530 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2023903599 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d59f0a810, 0x556d5a0f401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d5a0f4020,0x556d5bf8c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/412e52d7dc988a56ec5bbc54af51b4322436e5dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 570 processed earlier; will process 10459 files now Step #5: ==19114== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556d509ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d57064898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d570475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d570474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d50a05d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d50966b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d50961355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d509f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d539c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d539c6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d539c6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d539c6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d539c6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d539c6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d539c6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d539c6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d539c6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d539c6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d55c5bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d52988b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d52993be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d5273fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d5273fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d52740738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d5273f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d5273f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d5273f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d57049abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d57052928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d5703a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d57065112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd51724e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d5095fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xb0,0x80,0x80, Step #5: \363\260\200\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-7a15e3c35643ec9ce81f0d068c0058ed00fe6913 Step #5: Base64: 87CAgA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 531 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2024317393 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb37866810, 0x55eb37a5001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb37a50020,0x55eb398e80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7a15e3c35643ec9ce81f0d068c0058ed00fe6913' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 571 processed earlier; will process 10458 files now Step #5: #1 pulse cov: 3450 ft: 3451 exec/s: 0 rss: 157Mb Step #5: #2 pulse cov: 3678 ft: 3910 exec/s: 0 rss: 158Mb Step #5: ==19150== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eb2e35b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb349c0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb349a35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb349a34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb2e361d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb2e2c2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb2e2bd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb2e353c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb31322f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb31322f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb31322f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb31322f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb31322f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb31322f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb31322f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb31322f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb31322f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb31322f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb335b7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb302e4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb302efbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb3009bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb3009bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb3009c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb3009b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb3009b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb3009b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb349a5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb349ae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb34996699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb349c1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9a9918b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb2e2bbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0x5f,0x4c,0x52, Step #5: C_LR Step #5: artifact_prefix='./'; Test unit written to ./oom-79801798edbd2125f41d2e2e849df581c37e7d19 Step #5: Base64: Q19MUg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 532 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2024807014 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556cd0685810, 0x556cd086f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556cd086f020,0x556cd27070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/79801798edbd2125f41d2e2e849df581c37e7d19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 574 processed earlier; will process 10455 files now Step #5: ==19186== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556cc717a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556ccd7df898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556ccd7c25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556ccd7c24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556cc7180d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556cc70e1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556cc70dc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556cc7172c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556cca141f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556cca141f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556cca141f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556cca141f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556cca141f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556cca141f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556cca141f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556cca141f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556cca141f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556cca141f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556ccc3d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556cc9103b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556cc910ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556cc8ebac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556cc8ebac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556cc8ebb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556cc8eba874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556cc8eba874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556cc8eba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556ccd7c4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556ccd7cd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556ccd7b5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556ccd7e0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff99b8ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556cc70dab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0xb0,0x80,0x99, Step #5: \360\260\200\231 Step #5: artifact_prefix='./'; Test unit written to ./oom-c39949c5b286c884b0013de0db81f3f19bb5831b Step #5: Base64: 8LCAmQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 533 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2025223669 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c2d84ed810, 0x55c2d86d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c2d86d7020,0x55c2da56f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c39949c5b286c884b0013de0db81f3f19bb5831b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 575 processed earlier; will process 10454 files now Step #5: ==19222== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c2cefe29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c2d5647898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c2d562a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c2d562a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c2cefe8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c2cef49b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c2cef44355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c2cefdac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c2d1fa9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c2d1fa9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c2d1fa9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c2d1fa9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c2d1fa9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c2d1fa9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c2d1fa9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c2d1fa9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c2d1fa9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c2d1fa9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c2d423ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c2d0f6bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c2d0f76be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c2d0d22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c2d0d22c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c2d0d23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c2d0d22874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c2d0d22874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c2d0d22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c2d562cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c2d5635928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c2d561d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c2d5648112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e6e905082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c2cef42b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0x9,0x0, Step #5: -\012\011\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-30d4a897c057051778f888954803347b51a86f0c Step #5: Base64: LQoJAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 534 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2025645385 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d1de66810, 0x556d1e05001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d1e050020,0x556d1fee80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/30d4a897c057051778f888954803347b51a86f0c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 576 processed earlier; will process 10453 files now Step #5: ==19258== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556d1495b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d1afc0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d1afa35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d1afa34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d14961d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d148c2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d148bd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d14953c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d17922f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d17922f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d17922f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d17922f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d17922f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d17922f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d17922f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d17922f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d17922f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d17922f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d19bb7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d168e4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d168efbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d1669bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d1669bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d1669c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d1669b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d1669b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d1669b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d1afa5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d1afae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d1af96699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d1afc1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f06ee486082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d148bbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x58,0x5c,0x58, Step #5: \\X\\X Step #5: artifact_prefix='./'; Test unit written to ./oom-a0a6d51c403dcdfcc0f7fdd36627e238987f6c27 Step #5: Base64: XFhcWA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 535 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2026062963 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a82654810, 0x558a8283e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a8283e020,0x558a846d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a0a6d51c403dcdfcc0f7fdd36627e238987f6c27' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 577 processed earlier; will process 10452 files now Step #5: ==19294== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558a791499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a7f7ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a7f7915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a7f7914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a7914fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a790b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a790ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a79141c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a7c110f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a7c110f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a7c110f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a7c110f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a7c110f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a7c110f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a7c110f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a7c110f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a7c110f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a7c110f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a7e3a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a7b0d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a7b0ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a7ae89c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a7ae89c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a7ae8a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a7ae89874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a7ae89874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a7ae89874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a7f793abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a7f79c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a7f784699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a7f7af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc38498f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a790a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x0,0x6e,0x4d, Step #5: \001\000nM Step #5: artifact_prefix='./'; Test unit written to ./oom-4dbffaa08725156865fe4cef14fa5962030ddb07 Step #5: Base64: AQBuTQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 536 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2026477658 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56186e2e2810, 0x56186e4cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56186e4cc020,0x5618703640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4dbffaa08725156865fe4cef14fa5962030ddb07' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 578 processed earlier; will process 10451 files now Step #5: ==19330== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561864dd79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56186b43c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56186b41f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56186b41f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561864dddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561864d3eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561864d39355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561864dcfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561867d9ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561867d9ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561867d9ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561867d9ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561867d9ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561867d9ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561867d9ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561867d9ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561867d9ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561867d9ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56186a033f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561866d60b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561866d6bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561866b17c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561866b17c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561866b18738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561866b17874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561866b17874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561866b17874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56186b421abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56186b42a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56186b412699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56186b43d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f07939e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561864d37b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x61,0x61,0x20,0x61, Step #5: aa a Step #5: artifact_prefix='./'; Test unit written to ./oom-4d1ab24e80e3f380a70b081bd4c33e6d83a2d340 Step #5: Base64: YWEgYQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 537 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2026896103 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f406993810, 0x55f406b7d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f406b7d020,0x55f408a150e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4d1ab24e80e3f380a70b081bd4c33e6d83a2d340' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 579 processed earlier; will process 10450 files now Step #5: ==19366== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f3fd4889c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f403aed898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f403ad05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f403ad04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f3fd48ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f3fd3efb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f3fd3ea355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f3fd480c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f40044ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f40044ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f40044ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f40044ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f40044ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f40044ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f40044ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f40044ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f40044ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f40044ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4026e4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f3ff411b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f3ff41cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f3ff1c8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f3ff1c8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f3ff1c9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f3ff1c8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f3ff1c8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f3ff1c8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f403ad2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f403adb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f403ac3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f403aee112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc2c9d07082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f3fd3e8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x92,0x80,0x90, Step #5: \360\222\200\220 Step #5: artifact_prefix='./'; Test unit written to ./oom-9622c07642d04e6afe7bcd149d38b491d1dbc51f Step #5: Base64: 8JKAkA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 538 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2027308216 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db7cb1c810, 0x55db7cd0601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db7cd06020,0x55db7eb9e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9622c07642d04e6afe7bcd149d38b491d1dbc51f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 580 processed earlier; will process 10449 files now Step #5: ==19402== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55db736119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db79c76898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db79c595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db79c594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db73617d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db73578b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db73573355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db73609c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db765d8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db765d8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db765d8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db765d8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db765d8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db765d8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db765d8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db765d8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db765d8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db765d8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db7886df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db7559ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db755a5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db75351c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db75351c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db75352738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db75351874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db75351874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db75351874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db79c5babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db79c64928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db79c4c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db79c77112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e7a40e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db73571b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0xcf,0xbe,0x40, Step #5: .\317\276@ Step #5: artifact_prefix='./'; Test unit written to ./oom-73acf5ec2d6869a9736cfd4821036a5138d87bc1 Step #5: Base64: Ls++QA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 539 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2027730207 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5569fb4ab810, 0x5569fb69501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5569fb695020,0x5569fd52d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/73acf5ec2d6869a9736cfd4821036a5138d87bc1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 581 processed earlier; will process 10448 files now Step #5: ==19438== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5569f1fa09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5569f8605898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5569f85e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5569f85e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5569f1fa6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5569f1f07b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5569f1f02355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5569f1f98c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5569f4f67f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5569f4f67f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5569f4f67f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5569f4f67f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5569f4f67f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5569f4f67f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5569f4f67f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5569f4f67f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5569f4f67f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5569f4f67f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5569f71fcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5569f3f29b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5569f3f34be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5569f3ce0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5569f3ce0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5569f3ce1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5569f3ce0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5569f3ce0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5569f3ce0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5569f85eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5569f85f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5569f85db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5569f8606112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa575648082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5569f1f00b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4c,0xa,0xa,0x4, Step #5: L\012\012\004 Step #5: artifact_prefix='./'; Test unit written to ./oom-233eb27687002cf8abaca2dc42a277947c626d3e Step #5: Base64: TAoKBA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 540 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2028149218 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e0ecbb810, 0x562e0eea501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e0eea5020,0x562e10d3d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/233eb27687002cf8abaca2dc42a277947c626d3e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 582 processed earlier; will process 10447 files now Step #5: ==19474== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562e057b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e0be15898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e0bdf85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e0bdf84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e057b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e05717b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e05712355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e057a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e08777f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e08777f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e08777f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e08777f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e08777f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e08777f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e08777f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e08777f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e08777f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e08777f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e0aa0cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e07739b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e07744be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e074f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e074f0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e074f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e074f0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e074f0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e074f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e0bdfaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e0be03928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e0bdeb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e0be16112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0334dcf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e05710b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x74,0x4c,0x3a, Step #5: ftL: Step #5: artifact_prefix='./'; Test unit written to ./oom-b3cb0c154a31a5729737d0ecb0dfead3ab54d01e Step #5: Base64: ZnRMOg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 541 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2028568372 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559bc6f71810, 0x559bc715b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559bc715b020,0x559bc8ff30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3cb0c154a31a5729737d0ecb0dfead3ab54d01e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 583 processed earlier; will process 10446 files now Step #5: ==19510== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559bbda669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559bc40cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559bc40ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559bc40ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559bbda6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559bbd9cdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559bbd9c8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559bbda5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559bc0a2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559bc0a2df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559bc0a2df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559bc0a2df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559bc0a2df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559bc0a2df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559bc0a2df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559bc0a2df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559bc0a2df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559bc0a2df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559bc2cc2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559bbf9efb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559bbf9fabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559bbf7a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559bbf7a6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559bbf7a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559bbf7a6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559bbf7a6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559bbf7a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559bc40b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559bc40b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559bc40a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559bc40cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f47d5238082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559bbd9c6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x2d,0x2d,0x2d, Step #5: f--- Step #5: artifact_prefix='./'; Test unit written to ./oom-2284c502ae73b56a5254ccee61f284e25c90af9b Step #5: Base64: Zi0tLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 542 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2028985636 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8aeaa9810, 0x55c8aec9301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c8aec93020,0x55c8b0b2b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2284c502ae73b56a5254ccee61f284e25c90af9b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 584 processed earlier; will process 10445 files now Step #5: ==19546== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c8a559e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8abc03898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8abbe65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8abbe64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c8a55a4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c8a5505b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c8a5500355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c8a5596c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c8a8565f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c8a8565f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c8a8565f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c8a8565f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c8a8565f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c8a8565f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c8a8565f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c8a8565f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c8a8565f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c8a8565f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c8aa7faf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c8a7527b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c8a7532be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c8a72dec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c8a72dec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c8a72df738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c8a72de874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c8a72de874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c8a72de874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8abbe8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8abbf1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8abbd9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8abc04112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f0eb2c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c8a54feb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x36,0x33,0x2c, Step #5: -63, Step #5: artifact_prefix='./'; Test unit written to ./oom-de861fcca853207e1af8f257718e243e224ed0c2 Step #5: Base64: LTYzLA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 543 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2029400242 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c9dbeaa810, 0x55c9dc09401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c9dc094020,0x55c9ddf2c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de861fcca853207e1af8f257718e243e224ed0c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 585 processed earlier; will process 10444 files now Step #5: ==19582== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c9d299f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c9d9004898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9d8fe75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9d8fe74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9d29a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9d2906b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c9d2901355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9d2997c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c9d5966f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c9d5966f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c9d5966f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c9d5966f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c9d5966f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c9d5966f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c9d5966f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c9d5966f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c9d5966f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c9d5966f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c9d7bfbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9d4928b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9d4933be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c9d46dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c9d46dfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c9d46e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c9d46df874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c9d46df874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c9d46df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c9d8fe9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c9d8ff2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c9d8fda699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c9d9005112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f177e0ad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c9d28ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3a,0xdc,0xbe, Step #5: <:\334\276 Step #5: artifact_prefix='./'; Test unit written to ./oom-150b703a6f314759daa36498e6c5f4e1b2eeb526 Step #5: Base64: PDrcvg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 544 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2029829680 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559709b9f810, 0x559709d8901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559709d89020,0x55970bc210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/150b703a6f314759daa36498e6c5f4e1b2eeb526' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 586 processed earlier; will process 10443 files now Step #5: ==19618== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5597006949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559706cf9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559706cdc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559706cdc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55970069ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5597005fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5597005f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55970068cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55970365bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55970365bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55970365bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55970365bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55970365bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55970365bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55970365bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55970365bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55970365bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55970365bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5597058f0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55970261db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559702628be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5597023d4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5597023d4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5597023d5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5597023d4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5597023d4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5597023d4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559706cdeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559706ce7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559706ccf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559706cfa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2914356082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5597005f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x2f,0x0,0x2f, Step #5: +/\000/ Step #5: artifact_prefix='./'; Test unit written to ./oom-5bd10a6f4cb8403bba2838596285910e8868e676 Step #5: Base64: Ky8ALw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 545 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2030249782 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561451b5d810, 0x561451d4701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561451d47020,0x561453bdf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5bd10a6f4cb8403bba2838596285910e8868e676' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 587 processed earlier; will process 10442 files now Step #5: ==19654== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5614486529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56144ecb7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56144ec9a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56144ec9a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561448658d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5614485b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5614485b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56144864ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56144b619f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56144b619f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56144b619f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56144b619f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56144b619f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56144b619f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56144b619f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56144b619f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56144b619f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56144b619f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56144d8aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56144a5dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56144a5e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56144a392c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56144a392c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56144a393738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56144a392874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56144a392874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56144a392874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56144ec9cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56144eca5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56144ec8d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56144ecb8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe38a979082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5614485b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0xe0,0xb9,0x88, Step #5: 0\340\271\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-93ece7e66fb84947356b8d33f240eaef76d20bca Step #5: Base64: MOC5iA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 546 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2030665444 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5606d2967810, 0x5606d2b5101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5606d2b51020,0x5606d49e90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93ece7e66fb84947356b8d33f240eaef76d20bca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 588 processed earlier; will process 10441 files now Step #5: ==19690== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5606c945c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5606cfac1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606cfaa45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606cfaa44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5606c9462d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5606c93c3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5606c93be355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5606c9454c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5606cc423f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5606cc423f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5606cc423f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5606cc423f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5606cc423f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5606cc423f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5606cc423f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5606cc423f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5606cc423f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5606cc423f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606ce6b8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5606cb3e5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5606cb3f0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5606cb19cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5606cb19cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5606cb19d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5606cb19c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5606cb19c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5606cb19c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5606cfaa6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5606cfaaf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5606cfa97699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5606cfac2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f959fb61082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5606c93bcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x5c,0x78,0xff, Step #5: '\\x\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-9fccb57d2bd6b6dce397e70756dc9c2d541a2f15 Step #5: Base64: J1x4/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 547 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2031085435 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a8a62e2810, 0x55a8a64cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a8a64cc020,0x55a8a83640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9fccb57d2bd6b6dce397e70756dc9c2d541a2f15' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 589 processed earlier; will process 10440 files now Step #5: ==19726== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a89cdd79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a8a343c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a8a341f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a8a341f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a89cdddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a89cd3eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a89cd39355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a89cdcfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a89fd9ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a89fd9ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a89fd9ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a89fd9ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a89fd9ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a89fd9ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a89fd9ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a89fd9ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a89fd9ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a89fd9ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a8a2033f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a89ed60b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a89ed6bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a89eb17c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a89eb17c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a89eb18738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a89eb17874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a89eb17874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a89eb17874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a8a3421abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a8a342a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a8a3412699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a8a343d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3a3c77082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a89cd37b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x31,0x54,0x1a, Step #5: \0121T\032 Step #5: artifact_prefix='./'; Test unit written to ./oom-3742c700a9f5978da05eb06f344de5471e6da05d Step #5: Base64: CjFUGg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 548 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2031501953 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cdf2ded810, 0x55cdf2fd701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cdf2fd7020,0x55cdf4e6f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3742c700a9f5978da05eb06f344de5471e6da05d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 590 processed earlier; will process 10439 files now Step #5: ==19762== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cde98e29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cdeff47898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cdeff2a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cdeff2a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cde98e8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cde9849b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cde9844355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cde98dac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cdec8a9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cdec8a9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cdec8a9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cdec8a9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cdec8a9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cdec8a9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cdec8a9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cdec8a9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cdec8a9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cdec8a9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cdeeb3ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cdeb86bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cdeb876be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cdeb622c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cdeb622c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cdeb623738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cdeb622874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cdeb622874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cdeb622874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cdeff2cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cdeff35928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cdeff1d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cdeff48112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f41bb0ac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cde9842b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd7,0xab,0xd7,0xaf, Step #5: \327\253\327\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-2630ee1a131ef00eab890d5c3b72577324ef2a06 Step #5: Base64: 16vXrw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 549 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2031919166 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55562566f810, 0x55562585901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555625859020,0x5556276f10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2630ee1a131ef00eab890d5c3b72577324ef2a06' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 591 processed earlier; will process 10438 files now Step #5: ==19798== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55561c1649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5556227c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556227ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556227ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55561c16ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55561c0cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55561c0c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55561c15cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55561f12bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55561f12bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55561f12bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55561f12bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55561f12bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55561f12bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55561f12bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55561f12bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55561f12bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55561f12bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5556213c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55561e0edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55561e0f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55561dea4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55561dea4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55561dea5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55561dea4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55561dea4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55561dea4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5556227aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5556227b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55562279f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5556227ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3d2970f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55561c0c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0x85,0xc2,0x85, Step #5: \302\205\302\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-76d14ec0e9c4863455ac7c2d605f0d2f8baa106a Step #5: Base64: woXChQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 550 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2032318339 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559bd07e1810, 0x559bd09cb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559bd09cb020,0x559bd28630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/76d14ec0e9c4863455ac7c2d605f0d2f8baa106a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 592 processed earlier; will process 10437 files now Step #5: ==19834== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559bc72d69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559bcd93b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559bcd91e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559bcd91e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559bc72dcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559bc723db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559bc7238355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559bc72cec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559bca29df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559bca29df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559bca29df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559bca29df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559bca29df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559bca29df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559bca29df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559bca29df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559bca29df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559bca29df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559bcc532f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559bc925fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559bc926abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559bc9016c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559bc9016c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559bc9017738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559bc9016874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559bc9016874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559bc9016874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559bcd920abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559bcd929928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559bcd911699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559bcd93c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f847197b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559bc7236b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x58,0x59,0x58,0x7d, Step #5: XYX} Step #5: artifact_prefix='./'; Test unit written to ./oom-28281e68222e3277005deb07b673d06c3abae786 Step #5: Base64: WFlYfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 551 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2032729893 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0c200b810, 0x55b0c21f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b0c21f5020,0x55b0c408d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/28281e68222e3277005deb07b673d06c3abae786' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 593 processed earlier; will process 10436 files now Step #5: ==19870== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b0b8b009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b0bf165898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b0bf1485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b0bf1484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0b8b06d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0b8a67b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0b8a62355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0b8af8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b0bbac7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b0bbac7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b0bbac7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b0bbac7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b0bbac7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b0bbac7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b0bbac7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b0bbac7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b0bbac7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b0bbac7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b0bdd5cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b0baa89b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b0baa94be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b0ba840c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b0ba840c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b0ba841738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b0ba840874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b0ba840874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b0ba840874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b0bf14aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b0bf153928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b0bf13b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b0bf166112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f04a79d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0b8a60b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xca,0x82,0xca,0x82, Step #5: \312\202\312\202 Step #5: artifact_prefix='./'; Test unit written to ./oom-c07b3fc694d3d9a5c9b04eeb2bc11ec3fde09abe Step #5: Base64: yoLKgg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 552 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2033141947 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557a9d81e810, 0x557a9da0801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557a9da08020,0x557a9f8a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c07b3fc694d3d9a5c9b04eeb2bc11ec3fde09abe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 594 processed earlier; will process 10435 files now Step #5: ==19906== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557a943139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557a9a978898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557a9a95b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557a9a95b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557a94319d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557a9427ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557a94275355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557a9430bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557a972daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557a972daf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557a972daf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557a972daf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557a972daf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557a972daf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557a972daf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557a972daf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557a972daf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557a972daf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557a9956ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557a9629cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557a962a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557a96053c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557a96053c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557a96054738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557a96053874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557a96053874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557a96053874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557a9a95dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557a9a966928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557a9a94e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557a9a979112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b35430082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557a94273b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa1,0x9a,0xbc, Step #5: \363\241\232\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-8db2c477fefc5fe71d34e4997fb98db9315044d1 Step #5: Base64: 86GavA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 553 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2033554938 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559bd6c6e810, 0x559bd6e5801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559bd6e58020,0x559bd8cf00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8db2c477fefc5fe71d34e4997fb98db9315044d1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 595 processed earlier; will process 10434 files now Step #5: ==19942== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559bcd7639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559bd3dc8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559bd3dab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559bd3dab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559bcd769d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559bcd6cab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559bcd6c5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559bcd75bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559bd072af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559bd072af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559bd072af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559bd072af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559bd072af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559bd072af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559bd072af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559bd072af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559bd072af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559bd072af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559bd29bff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559bcf6ecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559bcf6f7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559bcf4a3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559bcf4a3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559bcf4a4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559bcf4a3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559bcf4a3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559bcf4a3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559bd3dadabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559bd3db6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559bd3d9e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559bd3dc9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe75a39d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559bcd6c3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4,0x60,0x21,0x60, Step #5: \004`!` Step #5: artifact_prefix='./'; Test unit written to ./oom-f055539acb9c326d2d98cccff8d22d19268c55fc Step #5: Base64: BGAhYA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 554 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2034094509 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561fed14f810, 0x561fed33901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561fed339020,0x561fef1d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f055539acb9c326d2d98cccff8d22d19268c55fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 596 processed earlier; will process 10433 files now Step #5: ==19978== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561fe3c449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561fea2a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561fea28c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561fea28c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561fe3c4ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561fe3babb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561fe3ba6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561fe3c3cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561fe6c0bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561fe6c0bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561fe6c0bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561fe6c0bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561fe6c0bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561fe6c0bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561fe6c0bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561fe6c0bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561fe6c0bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561fe6c0bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561fe8ea0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561fe5bcdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561fe5bd8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561fe5984c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561fe5984c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561fe5985738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561fe5984874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561fe5984874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561fe5984874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561fea28eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561fea297928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561fea27f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561fea2aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f96ffe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561fe3ba4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf4,0x8f,0xbe,0x80, Step #5: \364\217\276\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-38e1c878e88bc77c7f4b313f2b57ab5056539ecd Step #5: Base64: 9I++gA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 555 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2034512596 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db020be810, 0x55db022a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db022a8020,0x55db041400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/38e1c878e88bc77c7f4b313f2b57ab5056539ecd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 597 processed earlier; will process 10432 files now Step #5: ==20014== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55daf8bb39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55daff218898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55daff1fb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55daff1fb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55daf8bb9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55daf8b1ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55daf8b15355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55daf8babc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dafbb7af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dafbb7af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dafbb7af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dafbb7af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dafbb7af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dafbb7af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dafbb7af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dafbb7af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dafbb7af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dafbb7af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dafde0ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dafab3cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dafab47be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dafa8f3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dafa8f3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dafa8f4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dafa8f3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dafa8f3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dafa8f3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55daff1fdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55daff206928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55daff1ee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55daff219112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88e85a1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55daf8b13b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d, Step #5: DanM Step #5: artifact_prefix='./'; Test unit written to ./oom-2df44406c5ab1ddcb231804f74b442e46a7e462f Step #5: Base64: RGFuTQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 556 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2034931861 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55addacae810, 0x55addae9801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55addae98020,0x55addcd300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2df44406c5ab1ddcb231804f74b442e46a7e462f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 598 processed earlier; will process 10431 files now Step #5: ==20050== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55add17a39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55add7e08898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55add7deb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55add7deb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55add17a9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55add170ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55add1705355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55add179bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55add476af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55add476af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55add476af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55add476af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55add476af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55add476af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55add476af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55add476af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55add476af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55add476af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55add69fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55add372cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55add3737be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55add34e3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55add34e3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55add34e4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55add34e3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55add34e3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55add34e3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55add7dedabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55add7df6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55add7dde699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55add7e09112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e1ba68082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55add1703b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x40,0x20,0x20, Step #5: @ Step #5: artifact_prefix='./'; Test unit written to ./oom-f80c5382a4e5d12d5bf0d9697bdf4ced00785f46 Step #5: Base64: IEAgIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 557 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2035345070 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b5326e0810, 0x55b5328ca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b5328ca020,0x55b5347620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f80c5382a4e5d12d5bf0d9697bdf4ced00785f46' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 599 processed earlier; will process 10430 files now Step #5: #1 pulse cov: 3508 ft: 3509 exec/s: 0 rss: 156Mb Step #5: ==20086== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b5291d59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b52f83a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b52f81d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b52f81d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b5291dbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b52913cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b529137355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b5291cdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b52c19cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b52c19cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b52c19cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b52c19cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b52c19cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b52c19cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b52c19cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b52c19cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b52c19cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b52c19cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b52e431f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b52b15eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b52b169be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b52af15c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b52af15c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b52af16738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b52af15874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b52af15874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b52af15874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b52f81fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b52f828928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b52f810699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b52f83b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f475914a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b529135b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0xe0,0xbc,0xb9, Step #5: t\340\274\271 Step #5: artifact_prefix='./'; Test unit written to ./oom-89f1e42e468794dbd1eced25970f6676491cab7a Step #5: Base64: dOC8uQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 558 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2035798703 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5639f1b7b810, 0x5639f1d6501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5639f1d65020,0x5639f3bfd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/89f1e42e468794dbd1eced25970f6676491cab7a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 601 processed earlier; will process 10428 files now Step #5: ==20122== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5639e86709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5639eecd5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5639eecb85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5639eecb84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5639e8676d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5639e85d7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5639e85d2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5639e8668c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5639eb637f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5639eb637f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5639eb637f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5639eb637f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5639eb637f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5639eb637f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5639eb637f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5639eb637f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5639eb637f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5639eb637f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5639ed8ccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5639ea5f9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5639ea604be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5639ea3b0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5639ea3b0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5639ea3b1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5639ea3b0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5639ea3b0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5639ea3b0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5639eecbaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5639eecc3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5639eecab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5639eecd6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6c0385e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5639e85d0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x4d,0x61,0x6e, Step #5: AMan Step #5: artifact_prefix='./'; Test unit written to ./oom-4d504af3fb04ae90539fa2be2b87309e6aa8423f Step #5: Base64: QU1hbg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 559 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2036209575 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56111fbef810, 0x56111fdd901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56111fdd9020,0x561121c710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4d504af3fb04ae90539fa2be2b87309e6aa8423f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 602 processed earlier; will process 10427 files now Step #5: ==20158== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5611166e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56111cd49898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56111cd2c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56111cd2c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5611166ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56111664bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561116646355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5611166dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5611196abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5611196abf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5611196abf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5611196abf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5611196abf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5611196abf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5611196abf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5611196abf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5611196abf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5611196abf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56111b940f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56111866db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561118678be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561118424c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561118424c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561118425738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561118424874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561118424874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561118424874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56111cd2eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56111cd37928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56111cd1f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56111cd4a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a471d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561116644b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x41,0x47,0x59, Step #5: MAGY Step #5: artifact_prefix='./'; Test unit written to ./oom-e643c54bff94a5ea7e563b9fb2b97669810ed4b3 Step #5: Base64: TUFHWQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 560 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2036620828 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563b3ab26810, 0x563b3ad1001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563b3ad10020,0x563b3cba80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e643c54bff94a5ea7e563b9fb2b97669810ed4b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 603 processed earlier; will process 10426 files now Step #5: ==20194== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563b3161b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563b37c80898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563b37c635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563b37c634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563b31621d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563b31582b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563b3157d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563b31613c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563b345e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563b345e2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563b345e2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563b345e2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563b345e2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563b345e2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563b345e2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563b345e2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563b345e2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563b345e2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563b36877f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563b335a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563b335afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563b3335bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563b3335bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563b3335c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563b3335b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563b3335b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563b3335b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563b37c65abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563b37c6e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563b37c56699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563b37c81112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f7c378082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563b3157bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53,0x0,0xcd,0xac, Step #5: S\000\315\254 Step #5: artifact_prefix='./'; Test unit written to ./oom-2f5763a8826b16b0bf2550f52b0388d1c3f4ac7d Step #5: Base64: UwDNrA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 561 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2037032775 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ede7a7810, 0x555ede99101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ede991020,0x555ee08290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f5763a8826b16b0bf2550f52b0388d1c3f4ac7d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 604 processed earlier; will process 10425 files now Step #5: ==20230== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555ed529c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555edb901898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555edb8e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555edb8e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ed52a2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ed5203b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ed51fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ed5294c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ed8263f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ed8263f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ed8263f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ed8263f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ed8263f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ed8263f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ed8263f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ed8263f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ed8263f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ed8263f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555eda4f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ed7225b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ed7230be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ed6fdcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ed6fdcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ed6fdd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ed6fdc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ed6fdc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ed6fdc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555edb8e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555edb8ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555edb8d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555edb902112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb396742082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ed51fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5c,0xb,0x5c, Step #5: [\\\013\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-0364c0dbb53cc81a6b747eb7d78879c235863bc1 Step #5: Base64: W1wLXA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 562 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2037452862 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5573b9175810, 0x5573b935f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5573b935f020,0x5573bb1f70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0364c0dbb53cc81a6b747eb7d78879c235863bc1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 605 processed earlier; will process 10424 files now Step #5: #1 pulse cov: 3424 ft: 3425 exec/s: 0 rss: 156Mb Step #5: ==20266== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5573afc6a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5573b62cf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5573b62b25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5573b62b24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5573afc70d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5573afbd1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5573afbcc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5573afc62c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5573b2c31f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5573b2c31f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5573b2c31f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5573b2c31f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5573b2c31f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5573b2c31f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5573b2c31f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5573b2c31f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5573b2c31f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5573b2c31f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5573b4ec6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5573b1bf3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5573b1bfebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5573b19aac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5573b19aac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5573b19ab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5573b19aa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5573b19aa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5573b19aa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5573b62b4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5573b62bd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5573b62a5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5573b62d0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d2f1b7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5573afbcab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x33,0x30,0x39, Step #5: \000309 Step #5: artifact_prefix='./'; Test unit written to ./oom-a757edf400abbbc48b8666eb0e74611fa5313a79 Step #5: Base64: ADMwOQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 563 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2037907830 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ef0ef12810, 0x55ef0f0fc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ef0f0fc020,0x55ef10f940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a757edf400abbbc48b8666eb0e74611fa5313a79' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 607 processed earlier; will process 10422 files now Step #5: ==20302== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ef05a079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ef0c06c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ef0c04f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ef0c04f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef05a0dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef0596eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef05969355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef059ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef089cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef089cef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef089cef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef089cef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef089cef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef089cef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef089cef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef089cef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef089cef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef089cef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef0ac63f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef07990b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef0799bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef07747c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef07747c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef07748738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef07747874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef07747874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef07747874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ef0c051abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ef0c05a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ef0c042699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ef0c06d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f62376b8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef05967b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9d,0x85,0xb1, Step #5: \360\235\205\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-beb09eaa338a615348c6a2fe9637f28453761058 Step #5: Base64: 8J2FsQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 564 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2038322814 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f365049810, 0x55f36523301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f365233020,0x55f3670cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/beb09eaa338a615348c6a2fe9637f28453761058' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 608 processed earlier; will process 10421 files now Step #5: ==20338== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f35bb3e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f3621a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f3621865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f3621864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f35bb44d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f35baa5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f35baa0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f35bb36c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f35eb05f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f35eb05f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f35eb05f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f35eb05f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f35eb05f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f35eb05f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f35eb05f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f35eb05f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f35eb05f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f35eb05f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f360d9af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f35dac7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f35dad2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f35d87ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f35d87ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f35d87f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f35d87e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f35d87e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f35d87e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f362188abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f362191928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f362179699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f3621a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12eea6c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f35ba9eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc3,0x8f,0xdf,0x3d, Step #5: \303\217\337= Step #5: artifact_prefix='./'; Test unit written to ./oom-f66e707d2dfe314109fdd84c903caef81e01a710 Step #5: Base64: w4/fPQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 565 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2038737168 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557bbf2d9810, 0x557bbf4c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557bbf4c3020,0x557bc135b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f66e707d2dfe314109fdd84c903caef81e01a710' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 609 processed earlier; will process 10420 files now Step #5: ==20374== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557bb5dce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557bbc433898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557bbc4165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557bbc4164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557bb5dd4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557bb5d35b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557bb5d30355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557bb5dc6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557bb8d95f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557bb8d95f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557bb8d95f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557bb8d95f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557bb8d95f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557bb8d95f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557bb8d95f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557bb8d95f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557bb8d95f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557bb8d95f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557bbb02af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557bb7d57b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557bb7d62be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557bb7b0ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557bb7b0ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557bb7b0f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557bb7b0e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557bb7b0e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557bb7b0e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557bbc418abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557bbc421928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557bbc409699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557bbc434112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f64c2cba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557bb5d2eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x4d,0x4d,0x4d, Step #5: MMMM Step #5: artifact_prefix='./'; Test unit written to ./oom-2f5005d0e6ce2fb551cb5f2bdb9740a5ca7c28db Step #5: Base64: TU1NTQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 566 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2039156978 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e3b66a8810, 0x55e3b689201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e3b6892020,0x55e3b872a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f5005d0e6ce2fb551cb5f2bdb9740a5ca7c28db' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 610 processed earlier; will process 10419 files now Step #5: ==20410== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e3ad19d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e3b3802898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e3b37e55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e3b37e54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e3ad1a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e3ad104b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e3ad0ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e3ad195c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e3b0164f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e3b0164f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e3b0164f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e3b0164f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e3b0164f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e3b0164f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e3b0164f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e3b0164f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e3b0164f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e3b0164f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e3b23f9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e3af126b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e3af131be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e3aeeddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e3aeeddc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e3aeede738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e3aeedd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e3aeedd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e3aeedd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e3b37e7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e3b37f0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e3b37d8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e3b3803112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f586e8fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e3ad0fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd6,0xbc,0xbb,0x3, Step #5: \326\274\273\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-5766bab1c28ce34c20791647e04b1fd9efccc1e9 Step #5: Base64: 1ry7Aw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 567 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2039579263 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5586c2192810, 0x5586c237c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5586c237c020,0x5586c42140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5766bab1c28ce34c20791647e04b1fd9efccc1e9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 611 processed earlier; will process 10418 files now Step #5: ==20446== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5586b8c879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5586bf2ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5586bf2cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5586bf2cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5586b8c8dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5586b8beeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5586b8be9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5586b8c7fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5586bbc4ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5586bbc4ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5586bbc4ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5586bbc4ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5586bbc4ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5586bbc4ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5586bbc4ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5586bbc4ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5586bbc4ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5586bbc4ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5586bdee3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5586bac10b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5586bac1bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5586ba9c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5586ba9c7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5586ba9c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5586ba9c7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5586ba9c7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5586ba9c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5586bf2d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5586bf2da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5586bf2c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5586bf2ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f107df5a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5586b8be7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3a,0xcd,0xad, Step #5: <:\315\255 Step #5: artifact_prefix='./'; Test unit written to ./oom-7925f6f3c1dea95380bb94c2e09ffe2b1cb07f6a Step #5: Base64: PDrNrQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 568 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2039995908 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5573cb8b8810, 0x5573cbaa201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5573cbaa2020,0x5573cd93a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7925f6f3c1dea95380bb94c2e09ffe2b1cb07f6a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 612 processed earlier; will process 10417 files now Step #5: ==20482== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5573c23ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5573c8a12898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5573c89f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5573c89f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5573c23b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5573c2314b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5573c230f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5573c23a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5573c5374f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5573c5374f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5573c5374f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5573c5374f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5573c5374f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5573c5374f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5573c5374f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5573c5374f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5573c5374f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5573c5374f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5573c7609f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5573c4336b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5573c4341be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5573c40edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5573c40edc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5573c40ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5573c40ed874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5573c40ed874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5573c40ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5573c89f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5573c8a00928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5573c89e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5573c8a13112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff7b1d05082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5573c230db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x31,0x20,0xd, Step #5: P1 \015 Step #5: artifact_prefix='./'; Test unit written to ./oom-5247c13a159c4e83b8a8e85169471fa415d2051e Step #5: Base64: UDEgDQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 569 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2040410185 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561861653810, 0x56186183d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56186183d020,0x5618636d50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5247c13a159c4e83b8a8e85169471fa415d2051e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 613 processed earlier; will process 10416 files now Step #5: ==20518== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5618581489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56185e7ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56185e7905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56185e7904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56185814ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5618580afb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5618580aa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561858140c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56185b10ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56185b10ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56185b10ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56185b10ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56185b10ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56185b10ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56185b10ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56185b10ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56185b10ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56185b10ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56185d3a4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56185a0d1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56185a0dcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561859e88c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561859e88c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561859e89738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561859e88874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561859e88874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561859e88874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56185e792abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56185e79b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56185e783699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56185e7ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe778423082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5618580a8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0xad,0xb8,0x88, Step #5: \360\255\270\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-329195a9e1cb4a2b1439bc5d3ce7c8cbc65b6e21 Step #5: Base64: 8K24iA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 570 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2040822362 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558fa5b96810, 0x558fa5d8001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558fa5d80020,0x558fa7c180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/329195a9e1cb4a2b1439bc5d3ce7c8cbc65b6e21' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 614 processed earlier; will process 10415 files now Step #5: ==20554== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558f9c68b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558fa2cf0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558fa2cd35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558fa2cd34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f9c691d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f9c5f2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f9c5ed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f9c683c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f9f652f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f9f652f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f9f652f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f9f652f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f9f652f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f9f652f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f9f652f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f9f652f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f9f652f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f9f652f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558fa18e7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f9e614b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f9e61fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f9e3cbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f9e3cbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f9e3cc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f9e3cb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f9e3cb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f9e3cb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558fa2cd5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558fa2cde928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558fa2cc6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558fa2cf1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e75299082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f9c5ebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5b,0x3a,0x64, Step #5: [[:d Step #5: artifact_prefix='./'; Test unit written to ./oom-e552506791f764731ddfa8300f971b8987c67f0c Step #5: Base64: W1s6ZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 571 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2041239875 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed1cf3c810, 0x55ed1d12601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed1d126020,0x55ed1efbe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e552506791f764731ddfa8300f971b8987c67f0c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 615 processed earlier; will process 10414 files now Step #5: ==20590== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ed13a319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed1a096898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed1a0795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed1a0794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed13a37d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed13998b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed13993355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed13a29c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed169f8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed169f8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed169f8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed169f8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed169f8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed169f8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed169f8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed169f8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed169f8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed169f8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed18c8df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed159bab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed159c5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed15771c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed15771c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed15772738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed15771874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed15771874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed15771874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed1a07babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed1a084928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed1a06c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed1a097112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12c01cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed13991b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdc,0xb1,0x0,0x41, Step #5: \334\261\000A Step #5: artifact_prefix='./'; Test unit written to ./oom-20d94fbcff17896fbf80ba18d548633d82890d70 Step #5: Base64: 3LEAQQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 572 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2041661260 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5620ce467810, 0x5620ce65101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5620ce651020,0x5620d04e90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/20d94fbcff17896fbf80ba18d548633d82890d70' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 616 processed earlier; will process 10413 files now Step #5: ==20626== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5620c4f5c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5620cb5c1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5620cb5a45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5620cb5a44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5620c4f62d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5620c4ec3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5620c4ebe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5620c4f54c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5620c7f23f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5620c7f23f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5620c7f23f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5620c7f23f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5620c7f23f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5620c7f23f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5620c7f23f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5620c7f23f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5620c7f23f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5620c7f23f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5620ca1b8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5620c6ee5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5620c6ef0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5620c6c9cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5620c6c9cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5620c6c9d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5620c6c9c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5620c6c9c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5620c6c9c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5620cb5a6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5620cb5af928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5620cb597699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5620cb5c2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f52f5a2a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5620c4ebcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x6d,0x24,0x6d, Step #5: $m$m Step #5: artifact_prefix='./'; Test unit written to ./oom-2d071d4fab55454afaf682119370590f6af18eaa Step #5: Base64: JG0kbQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 573 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2042088211 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55711a7f0810, 0x55711a9da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55711a9da020,0x55711c8720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2d071d4fab55454afaf682119370590f6af18eaa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 617 processed earlier; will process 10412 files now Step #5: #1 pulse cov: 3470 ft: 3471 exec/s: 0 rss: 157Mb Step #5: ==20662== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5571112e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55711794a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55711792d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55711792d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571112ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55711124cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557111247355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571112ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571142acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571142acf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571142acf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571142acf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571142acf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571142acf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571142acf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571142acf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571142acf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571142acf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557116541f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55711326eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557113279be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557113025c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557113025c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557113026738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557113025874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557113025874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557113025874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55711792fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557117938928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557117920699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55711794b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9944ba9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557111245b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x74,0x63,0x59, Step #5: ttcY Step #5: artifact_prefix='./'; Test unit written to ./oom-4b8ea8d13a0810121fd9880ff9985e51e2d6de2c Step #5: Base64: dHRjWQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 574 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2042552191 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a6d3505810, 0x55a6d36ef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a6d36ef020,0x55a6d55870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4b8ea8d13a0810121fd9880ff9985e51e2d6de2c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 619 processed earlier; will process 10410 files now Step #5: ==20698== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a6c9ffa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a6d065f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a6d06425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a6d06424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a6ca000d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a6c9f61b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a6c9f5c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a6c9ff2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a6ccfc1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a6ccfc1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a6ccfc1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a6ccfc1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a6ccfc1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a6ccfc1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a6ccfc1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a6ccfc1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a6ccfc1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a6ccfc1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a6cf256f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a6cbf83b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a6cbf8ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a6cbd3ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a6cbd3ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a6cbd3b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a6cbd3a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a6cbd3a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a6cbd3a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a6d0644abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a6d064d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a6d0635699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a6d0660112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd19fbf1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a6c9f5ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x3b,0x32,0x2f, Step #5: /;2/ Step #5: artifact_prefix='./'; Test unit written to ./oom-decf69c5ec68e91525975c595cd49cbe266e70b2 Step #5: Base64: LzsyLw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 575 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2042971165 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ba30484810, 0x55ba3066e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ba3066e020,0x55ba325060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/decf69c5ec68e91525975c595cd49cbe266e70b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 620 processed earlier; will process 10409 files now Step #5: ==20734== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ba26f799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ba2d5de898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ba2d5c15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ba2d5c14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ba26f7fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ba26ee0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ba26edb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ba26f71c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ba29f40f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ba29f40f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ba29f40f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ba29f40f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ba29f40f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ba29f40f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ba29f40f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ba29f40f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ba29f40f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ba29f40f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ba2c1d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ba28f02b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ba28f0dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ba28cb9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ba28cb9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ba28cba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ba28cb9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ba28cb9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ba28cb9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ba2d5c3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ba2d5cc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ba2d5b4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ba2d5df112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa29db39082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ba26ed9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0x61,0x70,0x3b, Step #5: ≈ Step #5: artifact_prefix='./'; Test unit written to ./oom-edeb42d0f7ab538e500528d526c922b464c80d91 Step #5: Base64: JmFwOw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 576 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2043389413 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558ae8d70810, 0x558ae8f5a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558ae8f5a020,0x558aeadf20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/edeb42d0f7ab538e500528d526c922b464c80d91' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 621 processed earlier; will process 10408 files now Step #5: ==20770== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558adf8659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558ae5eca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558ae5ead5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558ae5ead4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558adf86bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558adf7ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558adf7c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558adf85dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558ae282cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558ae282cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558ae282cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558ae282cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558ae282cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558ae282cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558ae282cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558ae282cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558ae282cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558ae282cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558ae4ac1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ae17eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ae17f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ae15a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ae15a5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ae15a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ae15a5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ae15a5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ae15a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558ae5eafabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558ae5eb8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558ae5ea0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558ae5ecb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f17c9b62082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558adf7c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0x26,0x7a, Step #5: //&z Step #5: artifact_prefix='./'; Test unit written to ./oom-dfddbd81409335cab48997c438e75714740402f4 Step #5: Base64: Ly8meg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 577 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2043798169 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561f53a61810, 0x561f53c4b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561f53c4b020,0x561f55ae30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dfddbd81409335cab48997c438e75714740402f4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 622 processed earlier; will process 10407 files now Step #5: ==20806== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561f4a5569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561f50bbb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561f50b9e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561f50b9e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561f4a55cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561f4a4bdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561f4a4b8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561f4a54ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561f4d51df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561f4d51df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561f4d51df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561f4d51df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561f4d51df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561f4d51df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561f4d51df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561f4d51df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561f4d51df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561f4d51df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561f4f7b2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561f4c4dfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561f4c4eabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561f4c296c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561f4c296c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561f4c297738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561f4c296874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561f4c296874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561f4c296874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561f50ba0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561f50ba9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561f50b91699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561f50bbc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f61b1c10082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561f4a4b6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x20,0x23,0x76, Step #5: % #v Step #5: artifact_prefix='./'; Test unit written to ./oom-fdc0b7620d414f65b60f204994a8b508f5da486b Step #5: Base64: JSAjdg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 578 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2044215949 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b1e157f810, 0x55b1e176901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b1e1769020,0x55b1e36010e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fdc0b7620d414f65b60f204994a8b508f5da486b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 623 processed earlier; will process 10406 files now Step #5: ==20842== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b1d80749c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b1de6d9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1de6bc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1de6bc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b1d807ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b1d7fdbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b1d7fd6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b1d806cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b1db03bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b1db03bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b1db03bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b1db03bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b1db03bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b1db03bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b1db03bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b1db03bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b1db03bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b1db03bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b1dd2d0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b1d9ffdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b1da008be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b1d9db4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b1d9db4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b1d9db5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b1d9db4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b1d9db4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b1d9db4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b1de6beabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b1de6c7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b1de6af699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b1de6da112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff695717082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b1d7fd4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1e,0x1e,0x13,0x16, Step #5: \036\036\023\026 Step #5: artifact_prefix='./'; Test unit written to ./oom-d1ca276da1d55400a71a49d34ae907cc84db8b7a Step #5: Base64: Hh4TFg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 579 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2044639559 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fa7e82b810, 0x55fa7ea1501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fa7ea15020,0x55fa808ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d1ca276da1d55400a71a49d34ae907cc84db8b7a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 624 processed earlier; will process 10405 files now Step #5: #1 pulse cov: 3602 ft: 3603 exec/s: 0 rss: 158Mb Step #5: ==20878== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fa753209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fa7b985898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fa7b9685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fa7b9684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fa75326d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fa75287b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fa75282355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fa75318c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fa782e7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fa782e7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fa782e7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fa782e7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fa782e7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fa782e7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fa782e7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fa782e7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fa782e7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fa782e7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fa7a57cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fa772a9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fa772b4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fa77060c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fa77060c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fa77061738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fa77060874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fa77060874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fa77060874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fa7b96aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fa7b973928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fa7b95b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fa7b986112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd32216c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fa75280b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0xaf,0xa8,0x9d, Step #5: \360\257\250\235 Step #5: artifact_prefix='./'; Test unit written to ./oom-ee61184811f230ab849352e4f21498b907cecd24 Step #5: Base64: 8K+onQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 580 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2045094502 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f93eea8810, 0x55f93f09201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f93f092020,0x55f940f2a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee61184811f230ab849352e4f21498b907cecd24' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 626 processed earlier; will process 10403 files now Step #5: ==20914== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f93599d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f93c002898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f93bfe55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f93bfe54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f9359a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f935904b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f9358ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f935995c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f938964f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f938964f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f938964f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f938964f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f938964f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f938964f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f938964f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f938964f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f938964f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f938964f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f93abf9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f937926b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f937931be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f9376ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f9376ddc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f9376de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f9376dd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f9376dd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f9376dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f93bfe7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f93bff0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f93bfd8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f93c003112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5ba845e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f9358fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xd2,0xbb,0xa, Step #5: \000\322\273\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-88e0d72650f46a6e71551e19249ee11525016b05 Step #5: Base64: ANK7Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 581 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2045511553 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5623dc8ba810, 0x5623dcaa401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5623dcaa4020,0x5623de93c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88e0d72650f46a6e71551e19249ee11525016b05' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 627 processed earlier; will process 10402 files now Step #5: #1 pulse cov: 3552 ft: 3553 exec/s: 0 rss: 154Mb Step #5: ==20950== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5623d33af9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5623d9a14898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5623d99f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5623d99f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5623d33b5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5623d3316b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5623d3311355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5623d33a7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5623d6376f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5623d6376f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5623d6376f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5623d6376f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5623d6376f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5623d6376f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5623d6376f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5623d6376f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5623d6376f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5623d6376f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5623d860bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5623d5338b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5623d5343be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5623d50efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5623d50efc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5623d50f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5623d50ef874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5623d50ef874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5623d50ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5623d99f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5623d9a02928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5623d99ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5623d9a15112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2317ee8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5623d330fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x9,0x5b,0x9, Step #5: '\011[\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-b0d445c7ba5cd06aca122f0171bc158d3ed43979 Step #5: Base64: JwlbCQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 582 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2045973591 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c58ed2f810, 0x55c58ef1901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c58ef19020,0x55c590db10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b0d445c7ba5cd06aca122f0171bc158d3ed43979' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 629 processed earlier; will process 10400 files now Step #5: ==20986== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c5858249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c58be89898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c58be6c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c58be6c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c58582ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c58578bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c585786355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c58581cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c5887ebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c5887ebf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c5887ebf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c5887ebf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c5887ebf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c5887ebf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c5887ebf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c5887ebf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c5887ebf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c5887ebf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c58aa80f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c5877adb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c5877b8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c587564c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c587564c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c587565738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c587564874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c587564874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c587564874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c58be6eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c58be77928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c58be5f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c58be8a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc7d83a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c585784b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x0,0x0,0x0, Step #5: \001\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3c585604e87f855973731fea83e21fab9392d2fc Step #5: Base64: AQAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 583 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2046391140 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5632a1e19810, 0x5632a200301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5632a2003020,0x5632a3e9b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3c585604e87f855973731fea83e21fab9392d2fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 630 processed earlier; will process 10399 files now Step #5: ==21022== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56329890e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56329ef73898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56329ef565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56329ef564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563298914d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563298875b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563298870355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563298906c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56329b8d5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56329b8d5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56329b8d5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56329b8d5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56329b8d5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56329b8d5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56329b8d5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56329b8d5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56329b8d5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56329b8d5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56329db6af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56329a897b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56329a8a2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56329a64ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56329a64ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56329a64f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56329a64e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56329a64e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56329a64e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56329ef58abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56329ef61928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56329ef49699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56329ef74112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6a2c01b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56329886eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x55,0xa,0x65,0x7e, Step #5: U\012e~ Step #5: artifact_prefix='./'; Test unit written to ./oom-778888c04ee8b617801ed4d8f1c4f87e6e70cbd0 Step #5: Base64: VQplfg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 584 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2046811072 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563776eaf810, 0x56377709901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563777099020,0x563778f310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/778888c04ee8b617801ed4d8f1c4f87e6e70cbd0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 631 processed earlier; will process 10398 files now Step #5: ==21058== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56376d9a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563774009898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563773fec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563773fec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56376d9aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56376d90bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56376d906355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56376d99cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56377096bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56377096bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56377096bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56377096bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56377096bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56377096bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56377096bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56377096bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56377096bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56377096bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563772c00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56376f92db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56376f938be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56376f6e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56376f6e4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56376f6e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56376f6e4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56376f6e4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56376f6e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563773feeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563773ff7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563773fdf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56377400a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4743297082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56376d904b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x8f,0x2e,0x4e, Step #5: \315\217.N Step #5: artifact_prefix='./'; Test unit written to ./oom-894398d8dfba1e33ebadabf6988037e11bac0cec Step #5: Base64: zY8uTg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 585 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2047228626 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55916093b810, 0x559160b2501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559160b25020,0x5591629bd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/894398d8dfba1e33ebadabf6988037e11bac0cec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 632 processed earlier; will process 10397 files now Step #5: ==21094== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5591574309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55915da95898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55915da785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55915da784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559157436d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559157397b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559157392355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559157428c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55915a3f7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55915a3f7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55915a3f7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55915a3f7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55915a3f7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55915a3f7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55915a3f7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55915a3f7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55915a3f7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55915a3f7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55915c68cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5591593b9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5591593c4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559159170c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559159170c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559159171738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559159170874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559159170874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559159170874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55915da7aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55915da83928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55915da6b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55915da96112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4fc01f5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559157390b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd1,0xbc,0x70,0x72,0x6c, Step #5: \321\274prl Step #5: artifact_prefix='./'; Test unit written to ./oom-65ce0f31346226a70888fe206e3cb8eaad2cd07d Step #5: Base64: 0bxwcmw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 586 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2047654490 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55626407d810, 0x55626426701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556264267020,0x5562660ff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/65ce0f31346226a70888fe206e3cb8eaad2cd07d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 633 processed earlier; will process 10396 files now Step #5: ==21130== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55625ab729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5562611d7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5562611ba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5562611ba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55625ab78d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55625aad9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55625aad4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55625ab6ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55625db39f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55625db39f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55625db39f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55625db39f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55625db39f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55625db39f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55625db39f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55625db39f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55625db39f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55625db39f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55625fdcef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55625cafbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55625cb06be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55625c8b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55625c8b2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55625c8b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55625c8b2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55625c8b2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55625c8b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5562611bcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5562611c5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5562611ad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5562611d8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcdd10ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55625aad2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x36,0x45,0x33,0x30,0x38, Step #5: 6E308 Step #5: artifact_prefix='./'; Test unit written to ./oom-3a5396a209b280a0db811d26ab4dbfc289514274 Step #5: Base64: NkUzMDg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 587 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2048080491 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555c1ad78810, 0x555c1af6201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555c1af62020,0x555c1cdfa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a5396a209b280a0db811d26ab4dbfc289514274' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 634 processed earlier; will process 10395 files now Step #5: ==21166== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555c1186d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555c17ed2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555c17eb55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555c17eb54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555c11873d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555c117d4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555c117cf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555c11865c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555c14834f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555c14834f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555c14834f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555c14834f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555c14834f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555c14834f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555c14834f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555c14834f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555c14834f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555c14834f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555c16ac9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555c137f6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555c13801be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555c135adc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555c135adc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555c135ae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555c135ad874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555c135ad874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555c135ad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555c17eb7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555c17ec0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555c17ea8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555c17ed3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcffe0eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555c117cdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x7c,0xe3,0xbf,0x9b, Step #5: \005|\343\277\233 Step #5: artifact_prefix='./'; Test unit written to ./oom-93cf66745a0bc339aa4ee5fe467d8fada9e8616e Step #5: Base64: BXzjv5s= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 588 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2048498614 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55be8ec21810, 0x55be8ee0b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55be8ee0b020,0x55be90ca30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93cf66745a0bc339aa4ee5fe467d8fada9e8616e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 635 processed earlier; will process 10394 files now Step #5: ==21202== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55be857169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55be8bd7b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55be8bd5e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55be8bd5e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55be8571cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55be8567db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55be85678355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55be8570ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55be886ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55be886ddf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55be886ddf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55be886ddf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55be886ddf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55be886ddf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55be886ddf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55be886ddf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55be886ddf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55be886ddf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55be8a972f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55be8769fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55be876aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55be87456c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55be87456c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55be87457738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55be87456874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55be87456874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55be87456874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55be8bd60abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55be8bd69928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55be8bd51699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55be8bd7c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0f80b00082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55be85676b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0xdc,0x80,0x2a,0xdb, Step #5: *\334\200*\333 Step #5: artifact_prefix='./'; Test unit written to ./oom-a555705305fed661fbcfb0ab7e5ac861418927cd Step #5: Base64: KtyAKts= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 589 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2048917226 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55631790a810, 0x556317af401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556317af4020,0x55631998c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a555705305fed661fbcfb0ab7e5ac861418927cd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 636 processed earlier; will process 10393 files now Step #5: ==21238== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55630e3ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556314a64898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556314a475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556314a474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55630e405d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55630e366b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55630e361355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55630e3f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5563113c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5563113c6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5563113c6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5563113c6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5563113c6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5563113c6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5563113c6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5563113c6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5563113c6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5563113c6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55631365bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556310388b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556310393be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55631013fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55631013fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556310140738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55631013f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55631013f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55631013f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556314a49abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556314a52928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556314a3a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556314a65112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba63ce4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55630e35fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x54,0x79,0x3e, Step #5: Step #5: artifact_prefix='./'; Test unit written to ./oom-7fe997baa13f6c19483e9d366a747fa0f2ff5994 Step #5: Base64: PHNUeT4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 590 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2049319659 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560aaef2e810, 0x560aaf11801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560aaf118020,0x560ab0fb00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7fe997baa13f6c19483e9d366a747fa0f2ff5994' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 637 processed earlier; will process 10392 files now Step #5: ==21274== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560aa5a239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560aac088898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560aac06b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560aac06b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560aa5a29d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560aa598ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560aa5985355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560aa5a1bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560aa89eaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560aa89eaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560aa89eaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560aa89eaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560aa89eaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560aa89eaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560aa89eaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560aa89eaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560aa89eaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560aa89eaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560aaac7ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560aa79acb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560aa79b7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560aa7763c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560aa7763c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560aa7764738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560aa7763874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560aa7763874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560aa7763874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560aac06dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560aac076928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560aac05e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560aac089112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac791d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560aa5983b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0xd,0xe2,0x80,0x89, Step #5: ~\015\342\200\211 Step #5: artifact_prefix='./'; Test unit written to ./oom-90eea61aa88040207815d72a3b080d04dc5c34dd Step #5: Base64: fg3igIk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 591 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2049735627 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b54dd6810, 0x557b54fc001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b54fc0020,0x557b56e580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/90eea61aa88040207815d72a3b080d04dc5c34dd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 638 processed earlier; will process 10391 files now Step #5: ==21310== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557b4b8cb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b51f30898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b51f135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b51f134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b4b8d1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b4b832b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b4b82d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b4b8c3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b4e892f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b4e892f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b4e892f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b4e892f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b4e892f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b4e892f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b4e892f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b4e892f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b4e892f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b4e892f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b50b27f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b4d854b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b4d85fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b4d60bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b4d60bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b4d60c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b4d60b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b4d60b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b4d60b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b51f15abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b51f1e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b51f06699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b51f31112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f592b9f0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b4b82bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x90,0xa2,0x81,0x98, Step #5: \360\220\242\201\230 Step #5: artifact_prefix='./'; Test unit written to ./oom-6d21ff6e2eb8d46dcea6e6010f5cf6bd96436968 Step #5: Base64: 8JCigZg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 592 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2050153374 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b01bb4810, 0x561b01d9e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b01d9e020,0x561b03c360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6d21ff6e2eb8d46dcea6e6010f5cf6bd96436968' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 639 processed earlier; will process 10390 files now Step #5: ==21346== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561af86a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561afed0e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561afecf15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561afecf14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561af86afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561af8610b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561af860b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561af86a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561afb670f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561afb670f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561afb670f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561afb670f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561afb670f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561afb670f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561afb670f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561afb670f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561afb670f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561afb670f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561afd905f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561afa632b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561afa63dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561afa3e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561afa3e9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561afa3ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561afa3e9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561afa3e9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561afa3e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561afecf3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561afecfc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561afece4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561afed0f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53200a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561af8609b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0xe1,0xaf,0x90, Step #5: Step #5: Step #5: #0 0x556bdda489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556be40ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556be40905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556be40904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556bdda4ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556bdd9afb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556bdd9aa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556bdda40c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556be0a0ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556be0a0ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556be0a0ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556be0a0ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556be0a0ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556be0a0ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556be0a0ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556be0a0ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556be0a0ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556be0a0ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556be2ca4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556bdf9d1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556bdf9dcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556bdf788c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556bdf788c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556bdf789738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556bdf788874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556bdf788874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556bdf788874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556be4092abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556be409b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556be4083699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556be40ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb7e4ff1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556bdd9a8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53,0x46,0x57,0x39,0x35, Step #5: SFW95 Step #5: artifact_prefix='./'; Test unit written to ./oom-992d45950d1d0740b19b370e06b5f565b9099ca1 Step #5: Base64: U0ZXOTU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 594 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2050994305 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558f0020b810, 0x558f003f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558f003f5020,0x558f0228d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/992d45950d1d0740b19b370e06b5f565b9099ca1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 641 processed earlier; will process 10388 files now Step #5: ==21418== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558ef6d009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558efd365898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558efd3485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558efd3484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558ef6d06d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558ef6c67b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558ef6c62355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558ef6cf8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558ef9cc7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558ef9cc7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558ef9cc7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558ef9cc7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558ef9cc7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558ef9cc7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558ef9cc7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558ef9cc7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558ef9cc7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558ef9cc7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558efbf5cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ef8c89b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ef8c94be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ef8a40c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ef8a40c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ef8a41738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ef8a40874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ef8a40874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ef8a40874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558efd34aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558efd353928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558efd33b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558efd366112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a79672082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558ef6c60b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0xd9,0x98,0x6b,0x5d, Step #5: [\331\230k] Step #5: artifact_prefix='./'; Test unit written to ./oom-ef8984de14eb751a151171177399388b59bef3e8 Step #5: Base64: W9mYa10= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 595 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2051408992 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5601bfe34810, 0x5601c001e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5601c001e020,0x5601c1eb60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ef8984de14eb751a151171177399388b59bef3e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 642 processed earlier; will process 10387 files now Step #5: ==21454== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5601b69299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601bcf8e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601bcf715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601bcf714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5601b692fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601b6890b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601b688b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5601b6921c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601b98f0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601b98f0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601b98f0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601b98f0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601b98f0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601b98f0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601b98f0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601b98f0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601b98f0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601b98f0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5601bbb85f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601b88b2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601b88bdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5601b8669c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5601b8669c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5601b866a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5601b8669874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5601b8669874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5601b8669874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5601bcf73abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5601bcf7c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5601bcf64699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601bcf8f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e5076b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601b6889b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd6,0xa4,0x3,0xfb,0x37, Step #5: \326\244\003\3737 Step #5: artifact_prefix='./'; Test unit written to ./oom-e7c90ba495751eeaa0c4bf7174257c92c8483caf Step #5: Base64: 1qQD+zc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 596 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2051828749 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5616bbddc810, 0x5616bbfc601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5616bbfc6020,0x5616bde5e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e7c90ba495751eeaa0c4bf7174257c92c8483caf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 643 processed earlier; will process 10386 files now Step #5: ==21490== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5616b28d19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5616b8f36898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5616b8f195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5616b8f194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5616b28d7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5616b2838b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5616b2833355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5616b28c9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5616b5898f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5616b5898f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5616b5898f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5616b5898f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5616b5898f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5616b5898f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5616b5898f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5616b5898f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5616b5898f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5616b5898f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5616b7b2df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5616b485ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5616b4865be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5616b4611c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5616b4611c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5616b4612738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5616b4611874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5616b4611874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5616b4611874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5616b8f1babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5616b8f24928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5616b8f0c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5616b8f37112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feeeacfc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5616b2831b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x50,0x2d,0x2e,0x2e, Step #5: dP-.. Step #5: artifact_prefix='./'; Test unit written to ./oom-44a8795d24754f8d6612be83778e2d1c3e8031f1 Step #5: Base64: ZFAtLi4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 597 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2052248240 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55def36b6810, 0x55def38a001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55def38a0020,0x55def57380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/44a8795d24754f8d6612be83778e2d1c3e8031f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 644 processed earlier; will process 10385 files now Step #5: ==21526== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55deea1ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55def0810898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55def07f35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55def07f34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55deea1b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55deea112b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55deea10d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55deea1a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55deed172f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55deed172f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55deed172f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55deed172f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55deed172f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55deed172f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55deed172f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55deed172f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55deed172f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55deed172f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55deef407f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55deec134b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55deec13fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55deebeebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55deebeebc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55deebeec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55deebeeb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55deebeeb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55deebeeb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55def07f5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55def07fe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55def07e6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55def0811112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7b91e70082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55deea10bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x31,0x67, Step #5: Step #5: Step #5: #0 0x5620748f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56207af57898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56207af3a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56207af3a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5620748f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562074859b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562074854355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5620748eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5620778b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5620778b9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5620778b9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5620778b9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5620778b9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5620778b9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5620778b9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5620778b9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5620778b9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5620778b9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562079b4ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56207687bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562076886be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562076632c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562076632c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562076633738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562076632874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562076632874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562076632874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56207af3cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56207af45928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56207af2d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56207af58112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa65c0d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562074852b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x27,0x20,0x31,0x24, Step #5: $' 1$ Step #5: artifact_prefix='./'; Test unit written to ./oom-fdb030eb91392e5319ac6da539595549a3808fa1 Step #5: Base64: JCcgMSQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 599 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2053089047 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5650ab85d810, 0x5650aba4701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5650aba47020,0x5650ad8df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fdb030eb91392e5319ac6da539595549a3808fa1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 646 processed earlier; will process 10383 files now Step #5: ==21598== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5650a23529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5650a89b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5650a899a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5650a899a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5650a2358d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5650a22b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5650a22b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5650a234ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5650a5319f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5650a5319f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5650a5319f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5650a5319f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5650a5319f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5650a5319f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5650a5319f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5650a5319f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5650a5319f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5650a5319f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5650a75aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5650a42dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5650a42e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5650a4092c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5650a4092c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5650a4093738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5650a4092874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5650a4092874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5650a4092874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5650a899cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5650a89a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5650a898d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5650a89b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f08ba446082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5650a22b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x67, Step #5: Step #5: Step #5: #0 0x55fff07069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fff6d6b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fff6d4e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fff6d4e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fff070cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fff066db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fff0668355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fff06fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fff36cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fff36cdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fff36cdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fff36cdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fff36cdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fff36cdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fff36cdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fff36cdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fff36cdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fff36cdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fff5962f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fff268fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fff269abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fff2446c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fff2446c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fff2447738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fff2446874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fff2446874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fff2446874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fff6d50abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fff6d59928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fff6d41699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fff6d6c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f71d1714082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fff0666b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0xa1,0xcd,0xa1,0x3d, Step #5: \315\241\315\241= Step #5: artifact_prefix='./'; Test unit written to ./oom-fbc6109c93eaba6b2547e6efc132acfd6048bc39 Step #5: Base64: zaHNoT0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 601 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2053921959 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0a8282810, 0x55a0a846c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0a846c020,0x55a0aa3040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fbc6109c93eaba6b2547e6efc132acfd6048bc39' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 648 processed earlier; will process 10381 files now Step #5: ==21670== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a09ed779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0a53dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0a53bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0a53bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a09ed7dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a09ecdeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a09ecd9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a09ed6fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0a1d3ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0a1d3ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0a1d3ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0a1d3ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0a1d3ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0a1d3ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0a1d3ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0a1d3ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0a1d3ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0a1d3ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0a3fd3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0a0d00b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0a0d0bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0a0ab7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0a0ab7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0a0ab8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0a0ab7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0a0ab7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0a0ab7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0a53c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0a53ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0a53b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0a53dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1488265082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a09ecd7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x74,0x70,0x3a,0x34, Step #5: ftp:4 Step #5: artifact_prefix='./'; Test unit written to ./oom-2c19e97a881d4aa5245060b6dd51fe611cee70a4 Step #5: Base64: ZnRwOjQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 602 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2054335343 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555bbcc40810, 0x555bbce2a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555bbce2a020,0x555bbecc20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2c19e97a881d4aa5245060b6dd51fe611cee70a4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 649 processed earlier; will process 10380 files now Step #5: ==21706== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555bb37359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555bb9d9a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555bb9d7d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555bb9d7d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555bb373bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555bb369cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555bb3697355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555bb372dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555bb66fcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555bb66fcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555bb66fcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555bb66fcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555bb66fcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555bb66fcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555bb66fcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555bb66fcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555bb66fcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555bb66fcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555bb8991f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555bb56beb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555bb56c9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555bb5475c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555bb5475c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555bb5476738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555bb5475874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555bb5475874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555bb5475874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555bb9d7fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555bb9d88928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555bb9d70699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555bb9d9b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a2d071082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555bb3695b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0xbf,0xc2,0xbf,0x9f, Step #5: \302\277\302\277\237 Step #5: artifact_prefix='./'; Test unit written to ./oom-e6b51f92f7176e56f050b1edff179705943fc105 Step #5: Base64: wr/Cv58= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 603 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2054752563 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cf53e6b810, 0x55cf5405501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cf54055020,0x55cf55eed0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e6b51f92f7176e56f050b1edff179705943fc105' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 650 processed earlier; will process 10379 files now Step #5: ==21742== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cf4a9609c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cf50fc5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cf50fa85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cf50fa84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cf4a966d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cf4a8c7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cf4a8c2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cf4a958c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cf4d927f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cf4d927f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cf4d927f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cf4d927f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cf4d927f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cf4d927f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cf4d927f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cf4d927f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cf4d927f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cf4d927f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cf4fbbcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cf4c8e9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cf4c8f4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cf4c6a0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cf4c6a0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cf4c6a1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cf4c6a0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cf4c6a0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cf4c6a0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cf50faaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cf50fb3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cf50f9b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cf50fc6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f02d80a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cf4a8c0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x0,0x7,0x7,0x7, Step #5: \003\000\007\007\007 Step #5: artifact_prefix='./'; Test unit written to ./oom-761b4e887a35f3949b538c1c58f0b295cb7a7666 Step #5: Base64: AwAHBwc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 604 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2055167994 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5596020e1810, 0x5596022cb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596022cb020,0x5596041630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/761b4e887a35f3949b538c1c58f0b295cb7a7666' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 651 processed earlier; will process 10378 files now Step #5: ==21778== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5595f8bd69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5595ff23b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5595ff21e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5595ff21e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5595f8bdcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5595f8b3db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5595f8b38355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5595f8bcec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5595fbb9df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5595fbb9df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5595fbb9df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5595fbb9df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5595fbb9df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5595fbb9df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5595fbb9df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5595fbb9df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5595fbb9df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5595fbb9df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5595fde32f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5595fab5fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5595fab6abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5595fa916c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5595fa916c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5595fa917738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5595fa916874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5595fa916874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5595fa916874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5595ff220abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5595ff229928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5595ff211699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5595ff23c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0c55721082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5595f8b36b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0xa,0x20,0x20, Step #5: $$\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-3fc6bcbe96306541ee2fd679f3a773c1064d6879 Step #5: Base64: JCQKICA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 605 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2055587908 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b988ed2810, 0x55b9890bc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b9890bc020,0x55b98af540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3fc6bcbe96306541ee2fd679f3a773c1064d6879' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 652 processed earlier; will process 10377 files now Step #5: ==21814== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b97f9c79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b98602c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b98600f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b98600f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b97f9cdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b97f92eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b97f929355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b97f9bfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b98298ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b98298ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b98298ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b98298ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b98298ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b98298ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b98298ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b98298ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b98298ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b98298ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b984c23f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b981950b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b98195bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b981707c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b981707c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b981708738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b981707874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b981707874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b981707874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b986011abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b98601a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b986002699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b98602d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa103dfc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b97f927b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0xf0,0x9f,0x9f,0x98, Step #5: \005\360\237\237\230 Step #5: artifact_prefix='./'; Test unit written to ./oom-1712027ef088b46e02c945b004e6c542d7001205 Step #5: Base64: BfCfn5g= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 606 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2056008830 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55df9e523810, 0x55df9e70d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55df9e70d020,0x55dfa05a50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1712027ef088b46e02c945b004e6c542d7001205' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 653 processed earlier; will process 10376 files now Step #5: ==21850== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55df950189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55df9b67d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55df9b6605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55df9b6604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55df9501ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55df94f7fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55df94f7a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55df95010c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55df97fdff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55df97fdff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55df97fdff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55df97fdff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55df97fdff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55df97fdff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55df97fdff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55df97fdff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55df97fdff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55df97fdff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55df9a274f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55df96fa1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55df96facbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55df96d58c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55df96d58c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55df96d59738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55df96d58874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55df96d58874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55df96d58874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55df9b662abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55df9b66b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55df9b653699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55df9b67e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ded82e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55df94f78b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x36,0x30,0x31,0x31,0x2c, Step #5: 6011, Step #5: artifact_prefix='./'; Test unit written to ./oom-b873142e9c1967b3090b43eaea4b6cd6a50d9341 Step #5: Base64: NjAxMSw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 607 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2056424966 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ccd0c3b810, 0x55ccd0e2501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ccd0e25020,0x55ccd2cbd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b873142e9c1967b3090b43eaea4b6cd6a50d9341' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 654 processed earlier; will process 10375 files now Step #5: ==21886== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ccc77309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cccdd95898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cccdd785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cccdd784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ccc7736d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ccc7697b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ccc7692355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ccc7728c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ccca6f7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ccca6f7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ccca6f7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ccca6f7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ccca6f7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ccca6f7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ccca6f7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ccca6f7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ccca6f7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ccca6f7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cccc98cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ccc96b9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ccc96c4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ccc9470c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ccc9470c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ccc9471738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ccc9470874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ccc9470874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ccc9470874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cccdd7aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cccdd83928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cccdd6b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cccdd96112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc8a9cdf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ccc7690b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xd,0xd,0xe,0x0, Step #5: -\015\015\016\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f629ee397b2f4d141cdd526ef0391e51e443c15a Step #5: Base64: LQ0NDgA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 608 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2056842883 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d62bd9c810, 0x55d62bf8601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d62bf86020,0x55d62de1e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f629ee397b2f4d141cdd526ef0391e51e443c15a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 655 processed earlier; will process 10374 files now Step #5: ==21922== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d6228919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d628ef6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d628ed95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d628ed94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d622897d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d6227f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d6227f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d622889c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d625858f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d625858f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d625858f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d625858f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d625858f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d625858f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d625858f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d625858f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d625858f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d625858f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d627aedf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d62481ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d624825be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d6245d1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d6245d1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d6245d2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d6245d1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d6245d1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d6245d1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d628edbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d628ee4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d628ecc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d628ef7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbb974d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d6227f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0xcc,0x84,0xcc,0x85, Step #5: n\314\204\314\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-9892883857bf214aa17fe879c27c8f63a51133b7 Step #5: Base64: bsyEzIU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 609 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2057269240 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e4560f810, 0x563e457f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e457f9020,0x563e476910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9892883857bf214aa17fe879c27c8f63a51133b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 656 processed earlier; will process 10373 files now Step #5: #1 pulse cov: 3728 ft: 3729 exec/s: 0 rss: 158Mb Step #5: ==21958== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563e3c1049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e42769898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e4274c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e4274c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e3c10ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e3c06bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e3c066355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e3c0fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e3f0cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e3f0cbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e3f0cbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e3f0cbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e3f0cbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e3f0cbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e3f0cbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e3f0cbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e3f0cbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e3f0cbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e41360f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e3e08db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e3e098be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e3de44c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e3de44c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e3de45738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e3de44874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e3de44874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e3de44874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e4274eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e42757928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e4273f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e4276a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67007b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e3c064b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x66,0x66,0x3a,0x3a, Step #5: fff:: Step #5: artifact_prefix='./'; Test unit written to ./oom-15200c8b71cd93667b0c28d56fec7615837bb2a5 Step #5: Base64: ZmZmOjo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 610 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2057738803 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a562b9810, 0x560a564a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a564a3020,0x560a5833b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/15200c8b71cd93667b0c28d56fec7615837bb2a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 658 processed earlier; will process 10371 files now Step #5: ==21994== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560a4cdae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a53413898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a533f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a533f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a4cdb4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a4cd15b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a4cd10355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a4cda6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a4fd75f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a4fd75f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a4fd75f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a4fd75f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a4fd75f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a4fd75f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a4fd75f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a4fd75f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a4fd75f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a4fd75f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a5200af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a4ed37b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a4ed42be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a4eaeec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a4eaeec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a4eaef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a4eaee874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a4eaee874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a4eaee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a533f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a53401928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a533e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a53414112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f542ff98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a4cd0eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xde,0xbb,0x7c,0xde,0xba, Step #5: \336\273|\336\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-7d55fb9521c00694304068abdbc24080b183aa4b Step #5: Base64: 3rt83ro= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 611 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2058157852 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56003e8b8810, 0x56003eaa201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56003eaa2020,0x56004093a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d55fb9521c00694304068abdbc24080b183aa4b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 659 processed earlier; will process 10370 files now Step #5: #1 pulse cov: 3564 ft: 3565 exec/s: 0 rss: 154Mb Step #5: ==22030== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5600353ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56003ba12898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56003b9f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56003b9f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5600353b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560035314b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56003530f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5600353a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560038374f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560038374f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560038374f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560038374f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560038374f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560038374f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560038374f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560038374f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560038374f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560038374f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56003a609f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560037336b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560037341be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5600370edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5600370edc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5600370ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5600370ed874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5600370ed874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5600370ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56003b9f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56003ba00928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56003b9e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56003ba13112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fafc2517082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56003530db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd5,0x83,0x7c,0xd5,0x84, Step #5: \325\203|\325\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-e16215cbd73e8d8cb7ba2c222d49c0725bd8c607 Step #5: Base64: 1YN81YQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 612 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2058617623 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f3c64ab810, 0x55f3c669501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f3c6695020,0x55f3c852d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e16215cbd73e8d8cb7ba2c222d49c0725bd8c607' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 661 processed earlier; will process 10368 files now Step #5: ==22066== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f3bcfa09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f3c3605898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f3c35e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f3c35e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f3bcfa6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f3bcf07b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f3bcf02355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f3bcf98c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f3bff67f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f3bff67f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f3bff67f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f3bff67f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f3bff67f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f3bff67f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f3bff67f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f3bff67f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f3bff67f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f3bff67f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f3c21fcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f3bef29b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f3bef34be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f3bece0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f3bece0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f3bece1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f3bece0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f3bece0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f3bece0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f3c35eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f3c35f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f3c35db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f3c3606112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9abf212082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f3bcf00b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x22,0x22,0x22,0x22, Step #5: <\"\"\"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-603f3d143019819a48a1218c67c6235c67e4fc52 Step #5: Base64: PCIiIiI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 613 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2059040117 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55885d547810, 0x55885d73101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55885d731020,0x55885f5c90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/603f3d143019819a48a1218c67c6235c67e4fc52' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 662 processed earlier; will process 10367 files now Step #5: #1 pulse cov: 3570 ft: 3571 exec/s: 0 rss: 157Mb Step #5: ==22102== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55885403c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55885a6a1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55885a6845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55885a6844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558854042d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558853fa3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558853f9e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558854034c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558857003f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558857003f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558857003f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558857003f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558857003f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558857003f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558857003f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558857003f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558857003f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558857003f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558859298f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558855fc5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558855fd0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558855d7cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558855d7cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558855d7d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558855d7c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558855d7c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558855d7c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55885a686abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55885a68f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55885a677699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55885a6a2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f35f5423082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558853f9cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0xbb,0x7c,0xdf,0xbd, Step #5: \337\273|\337\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-328ccb52df985885aa8a6ab2f6c44c47fce77cf5 Step #5: Base64: 37t8370= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 614 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2059501141 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a26d88a810, 0x55a26da7401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a26da74020,0x55a26f90c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/328ccb52df985885aa8a6ab2f6c44c47fce77cf5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 664 processed earlier; will process 10365 files now Step #5: ==22138== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a26437f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a26a9e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a26a9c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a26a9c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a264385d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a2642e6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a2642e1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a264377c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a267346f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a267346f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a267346f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a267346f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a267346f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a267346f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a267346f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a267346f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a267346f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a267346f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a2695dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a266308b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a266313be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a2660bfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a2660bfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a2660c0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a2660bf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a2660bf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a2660bf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a26a9c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a26a9d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a26a9ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a26a9e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f125e399082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a2642dfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x58,0xc,0x5a,0x5e,0x37, Step #5: X\014Z^7 Step #5: artifact_prefix='./'; Test unit written to ./oom-0722ffebac374c74a8e8fcece92071babeb8d648 Step #5: Base64: WAxaXjc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 615 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2059931569 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e86aa2810, 0x555e86c8c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e86c8c020,0x555e88b240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0722ffebac374c74a8e8fcece92071babeb8d648' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 665 processed earlier; will process 10364 files now Step #5: ==22174== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555e7d5979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e83bfc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e83bdf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e83bdf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e7d59dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e7d4feb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e7d4f9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e7d58fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e8055ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e8055ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e8055ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e8055ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e8055ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e8055ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e8055ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e8055ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e8055ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e8055ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e827f3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e7f520b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e7f52bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e7f2d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e7f2d7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e7f2d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e7f2d7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e7f2d7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e7f2d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e83be1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e83bea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e83bd2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e83bfd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efd94970082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e7d4f7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x80, Step #5: \000\000\000\000\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-fa056d3eebf1859a8b702d2520d3f879913ce8d7 Step #5: Base64: AAAAAIA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 616 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2060355492 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5593719ac810, 0x559371b9601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559371b96020,0x559373a2e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fa056d3eebf1859a8b702d2520d3f879913ce8d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 666 processed earlier; will process 10363 files now Step #5: ==22210== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5593684a19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55936eb06898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55936eae95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55936eae94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5593684a7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559368408b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559368403355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559368499c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55936b468f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55936b468f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55936b468f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55936b468f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55936b468f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55936b468f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55936b468f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55936b468f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55936b468f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55936b468f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55936d6fdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55936a42ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55936a435be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55936a1e1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55936a1e1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55936a1e2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55936a1e1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55936a1e1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55936a1e1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55936eaebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55936eaf4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55936eadc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55936eb07112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a51762082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559368401b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4,0x55,0x1,0x54,0x3d, Step #5: \004U\001T= Step #5: artifact_prefix='./'; Test unit written to ./oom-3bb66e0b2d29f4e72fe2e7107822fff315163520 Step #5: Base64: BFUBVD0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 617 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2060781161 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5562d1d8b810, 0x5562d1f7501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5562d1f75020,0x5562d3e0d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3bb66e0b2d29f4e72fe2e7107822fff315163520' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 667 processed earlier; will process 10362 files now Step #5: ==22246== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5562c88809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5562ceee5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5562ceec85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5562ceec84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5562c8886d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5562c87e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5562c87e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5562c8878c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5562cb847f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5562cb847f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5562cb847f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5562cb847f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5562cb847f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5562cb847f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5562cb847f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5562cb847f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5562cb847f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5562cb847f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5562cdadcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5562ca809b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5562ca814be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5562ca5c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5562ca5c0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5562ca5c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5562ca5c0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5562ca5c0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5562ca5c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5562ceecaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5562ceed3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5562ceebb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5562ceee6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c12b14082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5562c87e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xf4,0x8e,0xbc,0xbe, Step #5: =\364\216\274\276 Step #5: artifact_prefix='./'; Test unit written to ./oom-a2e2c490728e3a7f72a9175064eab6a2ea231ac2 Step #5: Base64: PfSOvL4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 618 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2061206308 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b04d883810, 0x55b04da6d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b04da6d020,0x55b04f9050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2e2c490728e3a7f72a9175064eab6a2ea231ac2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 668 processed earlier; will process 10361 files now Step #5: ==22282== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b0443789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b04a9dd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b04a9c05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b04a9c04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b04437ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0442dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0442da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b044370c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b04733ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b04733ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b04733ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b04733ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b04733ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b04733ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b04733ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b04733ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b04733ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b04733ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b0495d4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b046301b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b04630cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b0460b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b0460b8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b0460b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b0460b8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b0460b8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b0460b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b04a9c2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b04a9cb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b04a9b3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b04a9de112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b07256082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0442d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0xa,0x5c,0xa,0x25, Step #5: e\012\\\012% Step #5: artifact_prefix='./'; Test unit written to ./oom-ae56a812b07fc5b5a52f769ed107eb18b117f190 Step #5: Base64: ZQpcCiU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 619 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2061631191 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560ee701e810, 0x560ee720801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560ee7208020,0x560ee90a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ae56a812b07fc5b5a52f769ed107eb18b117f190' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 669 processed earlier; will process 10360 files now Step #5: ==22318== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560eddb139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560ee4178898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560ee415b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560ee415b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560eddb19d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560edda7ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560edda75355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560eddb0bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560ee0adaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560ee0adaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560ee0adaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560ee0adaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560ee0adaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560ee0adaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560ee0adaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560ee0adaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560ee0adaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560ee0adaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560ee2d6ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560edfa9cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560edfaa7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560edf853c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560edf853c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560edf854738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560edf853874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560edf853874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560edf853874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560ee415dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560ee4166928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560ee414e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560ee4179112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7ba449f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560edda73b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x10,0x0,0x24,0x6e, Step #5: $\020\000$n Step #5: artifact_prefix='./'; Test unit written to ./oom-1958bc6929ce015aa8681ea4b658f99e4b00e02f Step #5: Base64: JBAAJG4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 620 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2062060781 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b97b2d1810, 0x55b97b4bb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b97b4bb020,0x55b97d3530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1958bc6929ce015aa8681ea4b658f99e4b00e02f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 670 processed earlier; will process 10359 files now Step #5: ==22354== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b971dc69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b97842b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b97840e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b97840e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b971dccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b971d2db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b971d28355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b971dbec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b974d8df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b974d8df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b974d8df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b974d8df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b974d8df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b974d8df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b974d8df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b974d8df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b974d8df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b974d8df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b977022f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b973d4fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b973d5abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b973b06c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b973b06c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b973b07738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b973b06874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b973b06874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b973b06874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b978410abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b978419928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b978401699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b97842c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f80e27a1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b971d26b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0x7b,0x5b,0x5e,0x5d, Step #5: :{[^] Step #5: artifact_prefix='./'; Test unit written to ./oom-02e632fc153075df169d48558826dc840e9f8f55 Step #5: Base64: OntbXl0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 621 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2062483489 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5578c2400810, 0x5578c25ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5578c25ea020,0x5578c44820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/02e632fc153075df169d48558826dc840e9f8f55' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 671 processed earlier; will process 10358 files now Step #5: ==22390== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5578b8ef59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5578bf55a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5578bf53d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5578bf53d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5578b8efbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5578b8e5cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5578b8e57355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5578b8eedc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5578bbebcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5578bbebcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5578bbebcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5578bbebcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5578bbebcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5578bbebcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5578bbebcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5578bbebcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5578bbebcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5578bbebcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5578be151f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5578bae7eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5578bae89be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5578bac35c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5578bac35c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5578bac36738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5578bac35874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5578bac35874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5578bac35874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5578bf53fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5578bf548928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5578bf530699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5578bf55b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f33ee2e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5578b8e55b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0xa,0xa,0x2b,0xa, Step #5: c\012\012+\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-deeb56282a4c8946d35f94b1773a4c5e2aace4c9 Step #5: Base64: YwoKKwo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 622 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2062922096 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559f878ad810, 0x559f87a9701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559f87a97020,0x559f8992f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/deeb56282a4c8946d35f94b1773a4c5e2aace4c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 672 processed earlier; will process 10357 files now Step #5: ==22426== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559f7e3a29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559f84a07898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559f849ea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559f849ea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559f7e3a8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559f7e309b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559f7e304355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559f7e39ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559f81369f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559f81369f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559f81369f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559f81369f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559f81369f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559f81369f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559f81369f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559f81369f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559f81369f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559f81369f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559f835fef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559f8032bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559f80336be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559f800e2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559f800e2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559f800e3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559f800e2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559f800e2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559f800e2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559f849ecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559f849f5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559f849dd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559f84a08112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f10b7f10082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559f7e302b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc9,0xa1,0xcd,0x84,0x32, Step #5: \311\241\315\2042 Step #5: artifact_prefix='./'; Test unit written to ./oom-a9be045812d27c835988170e0fa4f5f9350a7783 Step #5: Base64: yaHNhDI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 623 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2063350163 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d884de810, 0x561d886c801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d886c8020,0x561d8a5600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9be045812d27c835988170e0fa4f5f9350a7783' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 673 processed earlier; will process 10356 files now Step #5: ==22462== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561d7efd39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d85638898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d8561b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d8561b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d7efd9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d7ef3ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d7ef35355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d7efcbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d81f9af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d81f9af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d81f9af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d81f9af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d81f9af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d81f9af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d81f9af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d81f9af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d81f9af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d81f9af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d8422ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d80f5cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d80f67be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d80d13c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d80d13c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d80d14738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d80d13874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d80d13874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d80d13874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d8561dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d85626928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d8560e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d85639112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f40ec2d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d7ef33b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0xa,0x2f,0x2f, Step #5: //\012// Step #5: artifact_prefix='./'; Test unit written to ./oom-bfeeb71b271df1009e6fed82e43be1a30ecac053 Step #5: Base64: Ly8KLy8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 624 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2063765505 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b1de2c810, 0x560b1e01601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b1e016020,0x560b1feae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bfeeb71b271df1009e6fed82e43be1a30ecac053' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 674 processed earlier; will process 10355 files now Step #5: #1 pulse cov: 3420 ft: 3421 exec/s: 0 rss: 155Mb Step #5: ==22498== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560b149219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b1af86898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b1af695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b1af694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b14927d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b14888b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b14883355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b14919c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b178e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b178e8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b178e8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b178e8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b178e8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b178e8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b178e8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b178e8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b178e8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b178e8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b19b7df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b168aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b168b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b16661c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b16661c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b16662738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b16661874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b16661874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b16661874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b1af6babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b1af74928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b1af5c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b1af87112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb2e0723082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b14881b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x2d,0x2d,0x24, Step #5: ~$--$ Step #5: artifact_prefix='./'; Test unit written to ./oom-e08f6ffc86b5c4ce448c6fde4ed15ea0707ee74c Step #5: Base64: fiQtLSQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 625 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2064227853 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5607179ef810, 0x560717bd901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560717bd9020,0x560719a710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e08f6ffc86b5c4ce448c6fde4ed15ea0707ee74c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 676 processed earlier; will process 10353 files now Step #5: #1 pulse cov: 3452 ft: 3453 exec/s: 0 rss: 155Mb Step #5: ==22534== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56070e4e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560714b49898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560714b2c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560714b2c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56070e4ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56070e44bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56070e446355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56070e4dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5607114abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5607114abf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5607114abf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5607114abf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5607114abf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5607114abf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5607114abf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5607114abf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5607114abf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5607114abf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560713740f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56071046db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560710478be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560710224c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560710224c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560710225738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560710224874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560710224874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560710224874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560714b2eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560714b37928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560714b1f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560714b4a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6951644082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56070e444b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0xe2,0xb5,0x90, Step #5: Step #5: Step #5: #0 0x55a7054669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a70bacb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a70baae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a70baae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a70546cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a7053cdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a7053c8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a70545ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a70842df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a70842df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a70842df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a70842df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a70842df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a70842df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a70842df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a70842df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a70842df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a70842df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a70a6c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a7073efb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a7073fabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a7071a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a7071a6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a7071a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a7071a6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a7071a6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a7071a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a70bab0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a70bab9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a70baa1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a70bacc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1b81b8f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a7053c6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x38,0x9,0x5e,0x3a, Step #5: \0008\011^: Step #5: artifact_prefix='./'; Test unit written to ./oom-599958b9d55a1ff660751901d4c948ca43a80790 Step #5: Base64: ADgJXjo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 627 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2065116249 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558bbcf0d810, 0x558bbd0f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558bbd0f7020,0x558bbef8f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/599958b9d55a1ff660751901d4c948ca43a80790' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 679 processed earlier; will process 10350 files now Step #5: #1 pulse cov: 3445 ft: 3446 exec/s: 0 rss: 157Mb Step #5: ==22606== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558bb3a029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558bba067898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558bba04a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558bba04a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558bb3a08d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558bb3969b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558bb3964355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558bb39fac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558bb69c9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558bb69c9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558bb69c9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558bb69c9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558bb69c9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558bb69c9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558bb69c9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558bb69c9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558bb69c9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558bb69c9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558bb8c5ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558bb598bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558bb5996be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558bb5742c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558bb5742c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558bb5743738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558bb5742874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558bb5742874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558bb5742874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558bba04cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558bba055928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558bba03d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558bba068112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff1517a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558bb3962b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0x65,0x77,0x2e,0x36, Step #5: new.6 Step #5: artifact_prefix='./'; Test unit written to ./oom-a928f196df166fd6fa5dcc60f21e6dd9e48ca3f5 Step #5: Base64: bmV3LjY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 628 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2065574878 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c1788a810, 0x564c17a7401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c17a74020,0x564c1990c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a928f196df166fd6fa5dcc60f21e6dd9e48ca3f5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 681 processed earlier; will process 10348 files now Step #5: ==22642== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564c0e37f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c149e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c149c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c149c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c0e385d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c0e2e6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c0e2e1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c0e377c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c11346f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c11346f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c11346f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c11346f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c11346f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c11346f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c11346f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c11346f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c11346f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c11346f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c135dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c10308b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c10313be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c100bfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c100bfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c100c0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c100bf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c100bf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c100bf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c149c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c149d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c149ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c149e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fefb506c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c0e2dfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0xd,0xd,0xd,0xd, Step #5: \001\015\015\015\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-de2e62447c04f60c4348bad30d1c4148d580ddbb Step #5: Base64: AQ0NDQ0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 629 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2065996954 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ddbdd9810, 0x561ddbfc301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ddbfc3020,0x561ddde5b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de2e62447c04f60c4348bad30d1c4148d580ddbb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 682 processed earlier; will process 10347 files now Step #5: ==22678== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561dd28ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561dd8f33898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561dd8f165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561dd8f164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561dd28d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561dd2835b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561dd2830355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561dd28c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561dd5895f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561dd5895f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561dd5895f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561dd5895f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561dd5895f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561dd5895f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561dd5895f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561dd5895f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561dd5895f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561dd5895f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561dd7b2af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561dd4857b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561dd4862be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561dd460ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561dd460ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561dd460f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561dd460e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561dd460e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561dd460e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561dd8f18abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561dd8f21928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561dd8f09699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561dd8f34112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3d22edb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561dd282eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5e,0xdf,0xba,0x5d, Step #5: [^\337\272] Step #5: artifact_prefix='./'; Test unit written to ./oom-a16b18d1d114984d46c527c065b20da89ff036f8 Step #5: Base64: W17ful0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 630 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2066416664 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d5a2c5b810, 0x55d5a2e4501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d5a2e45020,0x55d5a4cdd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a16b18d1d114984d46c527c065b20da89ff036f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 683 processed earlier; will process 10346 files now Step #5: ==22714== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d5997509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d59fdb5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d59fd985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d59fd984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d599756d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d5996b7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d5996b2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d599748c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d59c717f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d59c717f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d59c717f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d59c717f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d59c717f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d59c717f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d59c717f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d59c717f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d59c717f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d59c717f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d59e9acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d59b6d9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d59b6e4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d59b490c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d59b490c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d59b491738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d59b490874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d59b490874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d59b490874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d59fd9aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d59fda3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d59fd8b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d59fdb6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0379e46082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d5996b0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x7a,0xb,0x41,0xa, Step #5: \012z\013A\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-a9e86d5000eac49914001a9ab60a58e6f71512b7 Step #5: Base64: CnoLQQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 631 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2066836455 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55894ce65810, 0x55894d04f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55894d04f020,0x55894eee70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9e86d5000eac49914001a9ab60a58e6f71512b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 684 processed earlier; will process 10345 files now Step #5: ==22750== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55894395a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558949fbf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558949fa25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558949fa24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558943960d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5589438c1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5589438bc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558943952c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558946921f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558946921f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558946921f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558946921f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558946921f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558946921f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558946921f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558946921f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558946921f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558946921f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558948bb6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5589458e3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5589458eebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55894569ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55894569ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55894569b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55894569a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55894569a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55894569a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558949fa4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558949fad928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558949f95699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558949fc0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f599d7c7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5589438bab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x60,0x69,0x6e,0xfe, Step #5: ``in\376 Step #5: artifact_prefix='./'; Test unit written to ./oom-6a6931f16e31cd674fce07661c9f457b19b74930 Step #5: Base64: YGBpbv4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 632 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2067375138 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eda9ed0810, 0x55edaa0ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55edaa0ba020,0x55edabf520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a6931f16e31cd674fce07661c9f457b19b74930' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 685 processed earlier; will process 10344 files now Step #5: ==22786== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eda09c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eda702a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eda700d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eda700d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eda09cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eda092cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eda0927355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eda09bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eda398cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eda398cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eda398cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eda398cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eda398cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eda398cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eda398cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eda398cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eda398cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eda398cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eda5c21f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eda294eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eda2959be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eda2705c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eda2705c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eda2706738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eda2705874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eda2705874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eda2705874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eda700fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eda7018928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eda7000699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eda702b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f038dd65082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eda0925b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x20,0x2d,0x31,0xa, Step #5: H -1\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-42b70611c6ddfae44c2d181526e41a61b4b1ef0a Step #5: Base64: SCAtMQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 633 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2067797183 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55afa6f5a810, 0x55afa714401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55afa7144020,0x55afa8fdc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/42b70611c6ddfae44c2d181526e41a61b4b1ef0a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 686 processed earlier; will process 10343 files now Step #5: ==22822== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55af9da4f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55afa40b4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55afa40975dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55afa40974fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55af9da55d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55af9d9b6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55af9d9b1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55af9da47c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55afa0a16f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55afa0a16f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55afa0a16f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55afa0a16f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55afa0a16f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55afa0a16f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55afa0a16f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55afa0a16f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55afa0a16f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55afa0a16f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55afa2cabf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af9f9d8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af9f9e3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af9f78fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af9f78fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af9f790738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af9f78f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af9f78f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af9f78f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55afa4099abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55afa40a2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55afa408a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55afa40b5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0918bb3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55af9d9afb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0xaa,0xa1,0x1,0x24, Step #5: \333\252\241\001$ Step #5: artifact_prefix='./'; Test unit written to ./oom-9587aae387eca6d370b0c905a7169593afd52ff7 Step #5: Base64: 26qhASQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 634 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2068215972 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a31b55810, 0x559a31d3f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a31d3f020,0x559a33bd70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9587aae387eca6d370b0c905a7169593afd52ff7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 687 processed earlier; will process 10342 files now Step #5: ==22858== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559a2864a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a2ecaf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a2ec925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a2ec924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a28650d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a285b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a285ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a28642c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a2b611f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a2b611f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a2b611f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a2b611f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a2b611f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a2b611f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a2b611f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a2b611f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a2b611f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a2b611f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a2d8a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a2a5d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a2a5debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a2a38ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a2a38ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a2a38b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a2a38a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a2a38a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a2a38a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a2ec94abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a2ec9d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a2ec85699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a2ecb0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f30b4fcc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a285aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0x7a,0xe0,0xb8,0xb6, Step #5: &z\340\270\266 Step #5: artifact_prefix='./'; Test unit written to ./oom-79148ac1083f3ce08d2fcd41826c2124905b595d Step #5: Base64: JnrguLY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 635 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2068645213 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55744b7d3810, 0x55744b9bd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55744b9bd020,0x55744d8550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/79148ac1083f3ce08d2fcd41826c2124905b595d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 688 processed earlier; will process 10341 files now Step #5: ==22894== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5574422c89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55744892d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5574489105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5574489104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5574422ced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55744222fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55744222a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5574422c0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55744528ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55744528ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55744528ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55744528ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55744528ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55744528ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55744528ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55744528ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55744528ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55744528ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557447524f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557444251b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55744425cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557444008c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557444008c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557444009738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557444008874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557444008874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557444008874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557448912abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55744891b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557448903699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55744892e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb53591082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557442228b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x72,0x72,0xcc,0x81, Step #5: srr\314\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-6cbed7b573fd3003fe9c97945d636c7d74dc23fb Step #5: Base64: c3JyzIE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 636 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2069069024 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558dc558f810, 0x558dc577901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558dc5779020,0x558dc76110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6cbed7b573fd3003fe9c97945d636c7d74dc23fb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 689 processed earlier; will process 10340 files now Step #5: ==22930== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558dbc0849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558dc26e9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558dc26cc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558dc26cc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558dbc08ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558dbbfebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558dbbfe6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558dbc07cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558dbf04bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558dbf04bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558dbf04bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558dbf04bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558dbf04bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558dbf04bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558dbf04bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558dbf04bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558dbf04bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558dbf04bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558dc12e0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558dbe00db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558dbe018be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558dbddc4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558dbddc4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558dbddc5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558dbddc4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558dbddc4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558dbddc4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558dc26ceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558dc26d7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558dc26bf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558dc26ea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff5fdc54082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558dbbfe4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc,0xc,0xc,0xc,0xc, Step #5: \014\014\014\014\014 Step #5: artifact_prefix='./'; Test unit written to ./oom-ae6141e79b1ae1f340beec127b619e3da0595d5c Step #5: Base64: DAwMDAw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 637 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2069483731 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55881e577810, 0x55881e76101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55881e761020,0x5588205f90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ae6141e79b1ae1f340beec127b619e3da0595d5c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 690 processed earlier; will process 10339 files now Step #5: ==22966== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55881506c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55881b6d1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55881b6b45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55881b6b44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558815072d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558814fd3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558814fce355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558815064c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558818033f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558818033f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558818033f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558818033f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558818033f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558818033f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558818033f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558818033f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558818033f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558818033f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55881a2c8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558816ff5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558817000be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558816dacc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558816dacc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558816dad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558816dac874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558816dac874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558816dac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55881b6b6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55881b6bf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55881b6a7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55881b6d2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1702897082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558814fccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xf3,0xa2,0x9f,0xbf, Step #5: <\363\242\237\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-a8272df3f68d251a192a0c97131b063669eef8a1 Step #5: Base64: PPOin78= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 638 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2069908982 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ce13922810, 0x55ce13b0c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ce13b0c020,0x55ce159a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a8272df3f68d251a192a0c97131b063669eef8a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 691 processed earlier; will process 10338 files now Step #5: #1 pulse cov: 3488 ft: 3489 exec/s: 0 rss: 158Mb Step #5: ==23002== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ce0a4179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ce10a7c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ce10a5f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ce10a5f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ce0a41dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ce0a37eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ce0a379355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ce0a40fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ce0d3def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ce0d3def10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ce0d3def10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ce0d3def10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ce0d3def10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ce0d3def10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ce0d3def10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ce0d3def10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ce0d3def10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ce0d3def10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ce0f673f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ce0c3a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ce0c3abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ce0c157c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ce0c157c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ce0c158738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ce0c157874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ce0c157874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ce0c157874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ce10a61abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ce10a6a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ce10a52699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ce10a7d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4517f99082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ce0a377b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x47,0x5,0x0,0x0,0x0, Step #5: G\005\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-80fbd13347fa5de5f41329e1a11663b4c7557a9a Step #5: Base64: RwUAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 639 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2070377038 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ca3f92810, 0x555ca417c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ca417c020,0x555ca60140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/80fbd13347fa5de5f41329e1a11663b4c7557a9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 693 processed earlier; will process 10336 files now Step #5: ==23038== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555c9aa879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ca10ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ca10cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ca10cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555c9aa8dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555c9a9eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555c9a9e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555c9aa7fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555c9da4ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555c9da4ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555c9da4ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555c9da4ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555c9da4ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555c9da4ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555c9da4ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555c9da4ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555c9da4ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555c9da4ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555c9fce3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555c9ca10b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555c9ca1bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555c9c7c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555c9c7c7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555c9c7c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555c9c7c7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555c9c7c7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555c9c7c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ca10d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ca10da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ca10c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ca10ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa46b272082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555c9a9e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xcf,0xbb,0xbf,0x2f, Step #5: \000\317\273\277/ Step #5: artifact_prefix='./'; Test unit written to ./oom-8972ed5e0101d5ed398cf104f4c6a8ddafa9afb3 Step #5: Base64: AM+7vy8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 640 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2070804763 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a484f25810, 0x55a48510f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a48510f020,0x55a486fa70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8972ed5e0101d5ed398cf104f4c6a8ddafa9afb3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 694 processed earlier; will process 10335 files now Step #5: ==23074== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a47ba1a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a48207f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a4820625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a4820624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a47ba20d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a47b981b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a47b97c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a47ba12c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a47e9e1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a47e9e1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a47e9e1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a47e9e1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a47e9e1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a47e9e1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a47e9e1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a47e9e1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a47e9e1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a47e9e1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a480c76f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a47d9a3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a47d9aebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a47d75ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a47d75ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a47d75b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a47d75a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a47d75a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a47d75a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a482064abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a48206d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a482055699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a482080112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6cff5ab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a47b97ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5a,0x1a,0x1a,0x5a,0x4e, Step #5: Z\032\032ZN Step #5: artifact_prefix='./'; Test unit written to ./oom-403c4aeca9a062759b728758ff1bf17a7b4886b0 Step #5: Base64: WhoaWk4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 641 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2071230167 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d0ae87d810, 0x55d0aea6701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d0aea67020,0x55d0b08ff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/403c4aeca9a062759b728758ff1bf17a7b4886b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 695 processed earlier; will process 10334 files now Step #5: ==23110== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d0a53729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d0ab9d7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d0ab9ba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d0ab9ba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d0a5378d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d0a52d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d0a52d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d0a536ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d0a8339f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d0a8339f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d0a8339f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d0a8339f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d0a8339f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d0a8339f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d0a8339f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d0a8339f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d0a8339f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d0a8339f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d0aa5cef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d0a72fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d0a7306be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d0a70b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d0a70b2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d0a70b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d0a70b2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d0a70b2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d0a70b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d0ab9bcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d0ab9c5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d0ab9ad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d0ab9d8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f265e2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d0a52d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x27,0x3a,0x5c,0x3d, Step #5: \000':\\= Step #5: artifact_prefix='./'; Test unit written to ./oom-aa2585d72fb2805edefb603c02579f46717a1951 Step #5: Base64: ACc6XD0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 642 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2071654056 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564dced64810, 0x564dcef4e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564dcef4e020,0x564dd0de60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aa2585d72fb2805edefb603c02579f46717a1951' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 696 processed earlier; will process 10333 files now Step #5: ==23146== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564dc58599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564dcbebe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564dcbea15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564dcbea14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564dc585fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564dc57c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564dc57bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564dc5851c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564dc8820f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564dc8820f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564dc8820f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564dc8820f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564dc8820f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564dc8820f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564dc8820f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564dc8820f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564dc8820f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564dc8820f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564dcaab5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564dc77e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564dc77edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564dc7599c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564dc7599c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564dc759a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564dc7599874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564dc7599874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564dc7599874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564dcbea3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564dcbeac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564dcbe94699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564dcbebf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0e93c88082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564dc57b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x54,0xe2,0x81,0x80,0xbd, Step #5: T\342\201\200\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-06af46137a9152c88775964351395d621e5b2589 Step #5: Base64: VOKBgL0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 643 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2072078524 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563281f45810, 0x56328212f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56328212f020,0x563283fc70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/06af46137a9152c88775964351395d621e5b2589' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 697 processed earlier; will process 10332 files now Step #5: ==23182== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563278a3a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56327f09f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56327f0825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56327f0824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563278a40d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5632789a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56327899c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563278a32c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56327ba01f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56327ba01f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56327ba01f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56327ba01f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56327ba01f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56327ba01f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56327ba01f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56327ba01f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56327ba01f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56327ba01f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56327dc96f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56327a9c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56327a9cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56327a77ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56327a77ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56327a77b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56327a77a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56327a77a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56327a77a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56327f084abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56327f08d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56327f075699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56327f0a0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d886f2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56327899ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2c,0x27,0x42,0x27,0x27, Step #5: ,'B'' Step #5: artifact_prefix='./'; Test unit written to ./oom-e9299b6f6d94ffe36a654d757695ac95f7911763 Step #5: Base64: LCdCJyc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 644 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2072501316 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9dc0a1810, 0x55e9dc28b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9dc28b020,0x55e9de1230e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e9299b6f6d94ffe36a654d757695ac95f7911763' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 698 processed earlier; will process 10331 files now Step #5: #1 pulse cov: 3577 ft: 3578 exec/s: 0 rss: 157Mb Step #5: ==23218== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e9d2b969c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9d91fb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9d91de5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9d91de4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9d2b9cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e9d2afdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e9d2af8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9d2b8ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e9d5b5df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e9d5b5df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e9d5b5df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e9d5b5df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e9d5b5df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e9d5b5df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e9d5b5df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e9d5b5df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e9d5b5df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e9d5b5df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9d7df2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e9d4b1fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e9d4b2abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9d48d6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9d48d6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9d48d7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9d48d6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9d48d6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9d48d6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e9d91e0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9d91e9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e9d91d1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e9d91fc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7facd95ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e9d2af6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x80,0xa4,0x7e, Step #5: \363\240\200\244~ Step #5: artifact_prefix='./'; Test unit written to ./oom-58997cd37086f976a6970df7cc55de738463d763 Step #5: Base64: 86CApH4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 645 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2072963845 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5653ba9c1810, 0x5653babab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5653babab020,0x5653bca430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58997cd37086f976a6970df7cc55de738463d763' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 700 processed earlier; will process 10329 files now Step #5: ==23254== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5653b14b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5653b7b1b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5653b7afe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5653b7afe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5653b14bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5653b141db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5653b1418355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5653b14aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5653b447df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5653b447df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5653b447df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5653b447df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5653b447df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5653b447df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5653b447df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5653b447df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5653b447df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5653b447df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5653b6712f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5653b343fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5653b344abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5653b31f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5653b31f6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5653b31f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5653b31f6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5653b31f6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5653b31f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5653b7b00abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5653b7b09928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5653b7af1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5653b7b1c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efe675f4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5653b1416b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x76,0x65,0x63,0x24, Step #5: $vec$ Step #5: artifact_prefix='./'; Test unit written to ./oom-72fe98c45669e5617f6dd4ee33a20274316de213 Step #5: Base64: JHZlYyQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 646 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2073388746 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5631a5347810, 0x5631a553101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5631a5531020,0x5631a73c90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/72fe98c45669e5617f6dd4ee33a20274316de213' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 701 processed earlier; will process 10328 files now Step #5: ==23290== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56319be3c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5631a24a1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5631a24845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5631a24844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56319be42d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56319bda3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56319bd9e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56319be34c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56319ee03f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56319ee03f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56319ee03f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56319ee03f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56319ee03f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56319ee03f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56319ee03f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56319ee03f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56319ee03f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56319ee03f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5631a1098f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56319ddc5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56319ddd0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56319db7cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56319db7cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56319db7d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56319db7c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56319db7c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56319db7c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5631a2486abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5631a248f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5631a2477699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5631a24a2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f22a6691082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56319bd9cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x45,0x47,0x49,0x4e, Step #5: BEGIN Step #5: artifact_prefix='./'; Test unit written to ./oom-3598517c826f1480a241800ce73f781ae2b1cd6a Step #5: Base64: QkVHSU4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 647 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2073815354 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556a73b03810, 0x556a73ced01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556a73ced020,0x556a75b850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3598517c826f1480a241800ce73f781ae2b1cd6a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 702 processed earlier; will process 10327 files now Step #5: ==23326== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556a6a5f89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556a70c5d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556a70c405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556a70c404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556a6a5fed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556a6a55fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556a6a55a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556a6a5f0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556a6d5bff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556a6d5bff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556a6d5bff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556a6d5bff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556a6d5bff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556a6d5bff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556a6d5bff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556a6d5bff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556a6d5bff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556a6d5bff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556a6f854f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556a6c581b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556a6c58cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556a6c338c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556a6c338c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556a6c339738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556a6c338874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556a6c338874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556a6c338874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556a70c42abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556a70c4b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556a70c33699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556a70c5e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4333a2f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556a6a558b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x4e,0x44,0x45,0x58, Step #5: INDEX Step #5: artifact_prefix='./'; Test unit written to ./oom-2704c1d8c3fc215c38ee176f6cc30e434a22b7d7 Step #5: Base64: SU5ERVg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 648 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2074244075 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d6c25c810, 0x562d6c44601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d6c446020,0x562d6e2de0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2704c1d8c3fc215c38ee176f6cc30e434a22b7d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 703 processed earlier; will process 10326 files now Step #5: ==23362== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562d62d519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d693b6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d693995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d693994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d62d57d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d62cb8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d62cb3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d62d49c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d65d18f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d65d18f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d65d18f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d65d18f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d65d18f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d65d18f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d65d18f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d65d18f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d65d18f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d65d18f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d67fadf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d64cdab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d64ce5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d64a91c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d64a91c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d64a92738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d64a91874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d64a91874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d64a91874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d6939babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d693a4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d6938c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d693b7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f926816b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d62cb1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0xe,0x0,0x4c,0x0, Step #5: A\016\000L\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9ac6bcf30d2340caaeaa45cde50b5e34c7542963 Step #5: Base64: QQ4ATAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 649 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2074667910 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e8b5f9810, 0x563e8b7e301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e8b7e3020,0x563e8d67b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9ac6bcf30d2340caaeaa45cde50b5e34c7542963' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 704 processed earlier; will process 10325 files now Step #5: ==23398== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563e820ee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e88753898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e887365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e887364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e820f4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e82055b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e82050355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e820e6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e850b5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e850b5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e850b5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e850b5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e850b5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e850b5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e850b5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e850b5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e850b5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e850b5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e8734af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e84077b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e84082be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e83e2ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e83e2ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e83e2f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e83e2e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e83e2e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e83e2e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e88738abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e88741928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e88729699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e88754112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe0880eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e8204eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x66,0xa,0x39,0x35, Step #5: Pf\01295 Step #5: artifact_prefix='./'; Test unit written to ./oom-1ff284cac72b23d803b7a1bcb91452c0910fd379 Step #5: Base64: UGYKOTU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 650 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2075087145 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55779108c810, 0x55779127601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557791276020,0x55779310e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ff284cac72b23d803b7a1bcb91452c0910fd379' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 705 processed earlier; will process 10324 files now Step #5: #1 pulse cov: 6472 ft: 6473 exec/s: 0 rss: 172Mb Step #5: #2 pulse cov: 6878 ft: 7185 exec/s: 0 rss: 174Mb Step #5: ==23434== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557787b819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55778e1e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55778e1c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55778e1c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557787b87d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557787ae8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557787ae3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557787b79c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55778ab48f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55778ab48f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55778ab48f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55778ab48f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55778ab48f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55778ab48f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55778ab48f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55778ab48f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55778ab48f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55778ab48f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55778cdddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557789b0ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557789b15be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5577898c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5577898c1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5577898c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5577898c1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5577898c1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5577898c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55778e1cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55778e1d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55778e1bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55778e1e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf2d8ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557787ae1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33,0x31,0x30,0x36,0x33, Step #5: 31063 Step #5: artifact_prefix='./'; Test unit written to ./oom-ee2bb631c340b11b7a4a3389a1fec7375c75e46c Step #5: Base64: MzEwNjM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 651 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2075591853 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0a2ba0810, 0x55b0a2d8a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b0a2d8a020,0x55b0a4c220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee2bb631c340b11b7a4a3389a1fec7375c75e46c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 708 processed earlier; will process 10321 files now Step #5: ==23470== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b0996959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b09fcfa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b09fcdd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b09fcdd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b09969bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0995fcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0995f7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b09968dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b09c65cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b09c65cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b09c65cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b09c65cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b09c65cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b09c65cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b09c65cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b09c65cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b09c65cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b09c65cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b09e8f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b09b61eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b09b629be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b09b3d5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b09b3d5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b09b3d6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b09b3d5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b09b3d5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b09b3d5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b09fcdfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b09fce8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b09fcd0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b09fcfb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa5d5d05082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0995f5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x67,0x6c,0x79,0xa, Step #5: \012gly\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-21933d8c786ff69ee9d426beadd393bff233716e Step #5: Base64: CmdseQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 652 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2076020074 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7bbfa0810, 0x55b7bc18a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7bc18a020,0x55b7be0220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/21933d8c786ff69ee9d426beadd393bff233716e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 709 processed earlier; will process 10320 files now Step #5: #1 pulse cov: 3460 ft: 3461 exec/s: 0 rss: 157Mb Step #5: ==23506== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b7b2a959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b7b90fa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b7b90dd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b7b90dd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b7b2a9bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b7b29fcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b7b29f7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b7b2a8dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b7b5a5cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b7b5a5cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b7b5a5cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b7b5a5cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b7b5a5cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b7b5a5cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b7b5a5cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b7b5a5cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b7b5a5cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b7b5a5cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b7b7cf1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b7b4a1eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b7b4a29be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b7b47d5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b7b47d5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b7b47d6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b7b47d5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b7b47d5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b7b47d5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b7b90dfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b7b90e8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b7b90d0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b7b90fb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f29e8bb2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b7b29f5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x6e,0x3a,0x6b,0x75, Step #5: dn:ku Step #5: artifact_prefix='./'; Test unit written to ./oom-6b05d2a8b3e77d8f3cd9b08970997cda5bd6356f Step #5: Base64: ZG46a3U= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 653 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2076491334 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ba5d652810, 0x55ba5d83c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ba5d83c020,0x55ba5f6d40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b05d2a8b3e77d8f3cd9b08970997cda5bd6356f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 711 processed earlier; will process 10318 files now Step #5: ==23542== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ba541479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ba5a7ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ba5a78f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ba5a78f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ba5414dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ba540aeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ba540a9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ba5413fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ba5710ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ba5710ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ba5710ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ba5710ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ba5710ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ba5710ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ba5710ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ba5710ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ba5710ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ba5710ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ba593a3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ba560d0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ba560dbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ba55e87c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ba55e87c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ba55e88738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ba55e87874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ba55e87874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ba55e87874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ba5a791abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ba5a79a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ba5a782699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ba5a7ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1480d3b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ba540a7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0xea,0xb6,0xbf,0x5d, Step #5: [\352\266\277] Step #5: artifact_prefix='./'; Test unit written to ./oom-2f6ed2caa6135e7295ceb6bead6ade726f9f0fcd Step #5: Base64: W+q2v10= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 654 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2076913030 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fecfbbb810, 0x55fecfda501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fecfda5020,0x55fed1c3d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f6ed2caa6135e7295ceb6bead6ade726f9f0fcd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 712 processed earlier; will process 10317 files now Step #5: ==23578== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fec66b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55feccd15898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fecccf85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fecccf84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fec66b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fec6617b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fec6612355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fec66a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fec9677f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fec9677f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fec9677f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fec9677f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fec9677f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fec9677f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fec9677f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fec9677f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fec9677f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fec9677f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fecb90cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fec8639b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fec8644be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fec83f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fec83f0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fec83f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fec83f0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fec83f0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fec83f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fecccfaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55feccd03928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55feccceb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55feccd16112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff356508082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fec6610b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0x23,0x31,0x37,0x25, Step #5: % Step #5: artifact_prefix='./'; Test unit written to ./oom-a2f2c68780ee64caaf62f2b15c87c8caee8d793d Step #5: Base64: JiMxNyU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 655 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2077343530 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc4acef810, 0x55cc4aed901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc4aed9020,0x55cc4cd710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2f2c68780ee64caaf62f2b15c87c8caee8d793d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 713 processed earlier; will process 10316 files now Step #5: ==23614== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cc417e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc47e49898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc47e2c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc47e2c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc417ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc4174bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc41746355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc417dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc447abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc447abf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc447abf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc447abf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc447abf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc447abf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc447abf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc447abf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc447abf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc447abf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc46a40f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc4376db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc43778be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc43524c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc43524c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc43525738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc43524874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc43524874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc43524874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc47e2eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc47e37928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc47e1f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc47e4a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f654326d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc41744b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0xa,0x2b,0xa, Step #5: +\012\012+\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-9b7b8b0c5dc91b05514fba99037d1900f46afb47 Step #5: Base64: KwoKKwo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 656 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2077772633 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d1057b810, 0x564d1076501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d10765020,0x564d125fd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9b7b8b0c5dc91b05514fba99037d1900f46afb47' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 714 processed earlier; will process 10315 files now Step #5: ==23650== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564d070709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d0d6d5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d0d6b85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d0d6b84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d07076d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d06fd7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d06fd2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d07068c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d0a037f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d0a037f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d0a037f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d0a037f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d0a037f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d0a037f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d0a037f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d0a037f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d0a037f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d0a037f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d0c2ccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d08ff9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d09004be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d08db0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d08db0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d08db1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d08db0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d08db0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d08db0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d0d6baabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d0d6c3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d0d6ab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d0d6d6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f66a84be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d06fd0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x4c,0xe6,0x92,0xa9, Step #5: \\L\346\222\251 Step #5: artifact_prefix='./'; Test unit written to ./oom-1b204d02dff078f7cef33927f1e5ed91324d0d3a Step #5: Base64: XEzmkqk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 657 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2078199312 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff94c9d810, 0x55ff94e8701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff94e87020,0x55ff96d1f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b204d02dff078f7cef33927f1e5ed91324d0d3a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 715 processed earlier; will process 10314 files now Step #5: ==23686== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ff8b7929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff91df7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff91dda5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff91dda4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff8b798d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff8b6f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff8b6f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff8b78ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff8e759f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff8e759f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff8e759f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff8e759f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff8e759f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff8e759f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff8e759f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff8e759f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff8e759f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff8e759f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff909eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff8d71bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff8d726be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff8d4d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff8d4d2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff8d4d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff8d4d2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff8d4d2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff8d4d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff91ddcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff91de5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff91dcd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff91df8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b73b24082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff8b6f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x67,0x3b,0x22,0x32, Step #5: %g;\"2 Step #5: artifact_prefix='./'; Test unit written to ./oom-74824e2eb28fe8b6ce06a8bf9a7494a081b06123 Step #5: Base64: JWc7IjI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 658 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2078627285 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc2e504810, 0x55fc2e6ee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc2e6ee020,0x55fc305860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/74824e2eb28fe8b6ce06a8bf9a7494a081b06123' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 716 processed earlier; will process 10313 files now Step #5: #1 pulse cov: 3614 ft: 3615 exec/s: 0 rss: 158Mb Step #5: ==23722== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fc24ff99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc2b65e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc2b6415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc2b6414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc24fffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc24f60b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc24f5b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc24ff1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc27fc0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc27fc0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc27fc0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc27fc0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc27fc0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc27fc0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc27fc0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc27fc0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc27fc0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc27fc0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc2a255f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc26f82b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc26f8dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc26d39c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc26d39c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc26d3a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc26d39874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc26d39874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc26d39874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc2b643abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc2b64c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc2b634699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc2b65f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe00c9ab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc24f59b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x46,0xa,0x30,0x58, Step #5: PF\0120X Step #5: artifact_prefix='./'; Test unit written to ./oom-f893781a5c81447612224581c2a45d8264026f88 Step #5: Base64: UEYKMFg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 659 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2079091013 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ab74c3810, 0x561ab76ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ab76ad020,0x561ab95450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f893781a5c81447612224581c2a45d8264026f88' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 718 processed earlier; will process 10311 files now Step #5: #1 pulse cov: 3430 ft: 3431 exec/s: 0 rss: 157Mb Step #5: ==23758== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561aadfb89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561ab461d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561ab46005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561ab46004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561aadfbed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561aadf1fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561aadf1a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561aadfb0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561ab0f7ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561ab0f7ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561ab0f7ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561ab0f7ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561ab0f7ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561ab0f7ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561ab0f7ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561ab0f7ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561ab0f7ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561ab0f7ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561ab3214f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561aaff41b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561aaff4cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561aafcf8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561aafcf8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561aafcf9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561aafcf8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561aafcf8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561aafcf8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561ab4602abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561ab460b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561ab45f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561ab461e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c78304082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561aadf18b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x74,0x3,0x41,0x0, Step #5: ~t\003A\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-15943953e813944480d4105ea69c5fd3af97804c Step #5: Base64: fnQDQQA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 660 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2079561440 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a2c0a9d810, 0x55a2c0c8701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a2c0c87020,0x55a2c2b1f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/15943953e813944480d4105ea69c5fd3af97804c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 720 processed earlier; will process 10309 files now Step #5: ==23794== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a2b75929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a2bdbf7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2bdbda5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2bdbda4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a2b7598d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a2b74f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a2b74f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a2b758ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a2ba559f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a2ba559f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a2ba559f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a2ba559f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a2ba559f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a2ba559f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a2ba559f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a2ba559f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a2ba559f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a2ba559f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a2bc7eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a2b951bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a2b9526be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a2b92d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a2b92d2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a2b92d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a2b92d2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a2b92d2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a2b92d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a2bdbdcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a2bdbe5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2bdbcd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a2bdbf8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f83b10b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a2b74f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0x3b,0x32,0x3a,0x3d, Step #5: :;2:= Step #5: artifact_prefix='./'; Test unit written to ./oom-42c4ecef550fd95c40cb6f9a543b3df2bc1b7906 Step #5: Base64: OjsyOj0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 661 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2079989391 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f50f794810, 0x55f50f97e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f50f97e020,0x55f5118160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/42c4ecef550fd95c40cb6f9a543b3df2bc1b7906' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 721 processed earlier; will process 10308 files now Step #5: ==23830== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f5062899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f50c8ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f50c8d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f50c8d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f50628fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f5061f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f5061eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f506281c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f509250f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f509250f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f509250f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f509250f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f509250f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f509250f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f509250f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f509250f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f509250f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f509250f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f50b4e5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f508212b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f50821dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f507fc9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f507fc9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f507fca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f507fc9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f507fc9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f507fc9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f50c8d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f50c8dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f50c8c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f50c8ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f06e681a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f5061e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4,0x22,0x22,0xde,0x80, Step #5: \004\"\"\336\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-45af5c8d625e14bdf8f08b177f4f942d86db755d Step #5: Base64: BCIi3oA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 662 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2080413101 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a8f7022810, 0x55a8f720c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a8f720c020,0x55a8f90a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/45af5c8d625e14bdf8f08b177f4f942d86db755d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 722 processed earlier; will process 10307 files now Step #5: ==23866== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a8edb179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a8f417c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a8f415f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a8f415f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a8edb1dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a8eda7eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a8eda79355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a8edb0fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a8f0adef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a8f0adef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a8f0adef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a8f0adef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a8f0adef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a8f0adef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a8f0adef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a8f0adef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a8f0adef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a8f0adef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a8f2d73f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a8efaa0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a8efaabbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a8ef857c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a8ef857c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a8ef858738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a8ef857874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a8ef857874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a8ef857874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a8f4161abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a8f416a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a8f4152699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a8f417d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9b0c49d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a8eda77b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0x20,0x20,0x20, Step #5: -\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-7f842834c2479f9afdf5054e8cb32f57bd225d3a Step #5: Base64: LQogICA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 663 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2080838253 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c709af810, 0x559c70b9901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c70b99020,0x559c72a310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f842834c2479f9afdf5054e8cb32f57bd225d3a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 723 processed earlier; will process 10306 files now Step #5: ==23902== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559c674a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c6db09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c6daec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c6daec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c674aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c6740bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c67406355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c6749cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c6a46bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c6a46bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c6a46bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c6a46bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c6a46bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c6a46bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c6a46bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c6a46bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c6a46bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c6a46bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c6c700f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c6942db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c69438be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c691e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c691e4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c691e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c691e4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c691e4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c691e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c6daeeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c6daf7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c6dadf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c6db0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe4fbbae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c67404b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xef,0xbb,0x90,0x2f, Step #5: \000\357\273\220/ Step #5: artifact_prefix='./'; Test unit written to ./oom-a1340d4f5ed1c80b1eabeeebab884f23133f32fc Step #5: Base64: AO+7kC8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 664 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2081268688 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564b016e4810, 0x564b018ce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564b018ce020,0x564b037660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a1340d4f5ed1c80b1eabeeebab884f23133f32fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 724 processed earlier; will process 10305 files now Step #5: ==23938== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564af81d99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564afe83e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564afe8215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564afe8214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564af81dfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564af8140b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564af813b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564af81d1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564afb1a0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564afb1a0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564afb1a0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564afb1a0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564afb1a0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564afb1a0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564afb1a0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564afb1a0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564afb1a0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564afb1a0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564afd435f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564afa162b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564afa16dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564af9f19c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564af9f19c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564af9f1a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564af9f19874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564af9f19874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564af9f19874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564afe823abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564afe82c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564afe814699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564afe83f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc65b743082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564af8139b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0x20,0x3f,0x20,0x21, Step #5: ? ? ! Step #5: artifact_prefix='./'; Test unit written to ./oom-1fdbadfb34c063d6422c04a841ca490663f44f4e Step #5: Base64: PyA/ICE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 665 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2081689824 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610ff9fa810, 0x5610ffbe401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610ffbe4020,0x561101a7c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1fdbadfb34c063d6422c04a841ca490663f44f4e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 725 processed earlier; will process 10304 files now Step #5: ==23974== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5610f64ef9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610fcb54898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610fcb375dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610fcb374fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610f64f5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610f6456b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610f6451355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610f64e7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610f94b6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610f94b6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610f94b6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610f94b6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610f94b6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610f94b6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610f94b6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610f94b6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610f94b6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610f94b6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610fb74bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610f8478b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610f8483be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610f822fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610f822fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610f8230738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610f822f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610f822f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610f822f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610fcb39abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610fcb42928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610fcb2a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610fcb55112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f70bf57e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610f644fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x20,0x0,0x0,0x0, Step #5: \000 \000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fcce5f8c70156a1095fe8e86628960583b0cbde7 Step #5: Base64: ACAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 666 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2082120097 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee8ec16810, 0x55ee8ee0001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee8ee00020,0x55ee90c980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fcce5f8c70156a1095fe8e86628960583b0cbde7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 726 processed earlier; will process 10303 files now Step #5: ==24010== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ee8570b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee8bd70898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee8bd535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee8bd534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee85711d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee85672b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee8566d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee85703c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee886d2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee886d2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee886d2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee886d2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee886d2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee886d2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee886d2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee886d2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee886d2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee886d2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee8a967f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee87694b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee8769fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee8744bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee8744bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee8744c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee8744b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee8744b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee8744b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee8bd55abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee8bd5e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee8bd46699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee8bd71112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd6efdd6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee8566bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe5,0xbe,0xb6,0x7c,0x49, Step #5: \345\276\266|I Step #5: artifact_prefix='./'; Test unit written to ./oom-c5e8ec4092c0c511c8d7bfb035b40003d10c77f3 Step #5: Base64: 5b62fEk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 667 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2082542582 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55763534d810, 0x55763553701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557635537020,0x5576373cf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c5e8ec4092c0c511c8d7bfb035b40003d10c77f3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 727 processed earlier; will process 10302 files now Step #5: ==24046== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55762be429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5576324a7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55763248a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55763248a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55762be48d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55762bda9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55762bda4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55762be3ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55762ee09f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55762ee09f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55762ee09f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55762ee09f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55762ee09f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55762ee09f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55762ee09f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55762ee09f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55762ee09f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55762ee09f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55763109ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55762ddcbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55762ddd6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55762db82c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55762db82c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55762db83738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55762db82874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55762db82874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55762db82874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55763248cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557632495928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55763247d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5576324a8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8bd2817082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55762bda2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x0,0x10,0xd2,0x88, Step #5: =\000\020\322\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-21a6ae434571722baf659971819fa4b552d2864b Step #5: Base64: PQAQ0og= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 668 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2082970833 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c953681810, 0x55c95386b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c95386b020,0x55c9557030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/21a6ae434571722baf659971819fa4b552d2864b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 728 processed earlier; will process 10301 files now Step #5: ==24082== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c94a1769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c9507db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9507be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9507be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c94a17cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c94a0ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c94a0d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c94a16ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c94d13df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c94d13df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c94d13df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c94d13df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c94d13df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c94d13df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c94d13df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c94d13df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c94d13df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c94d13df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c94f3d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c94c0ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c94c10abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c94beb6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c94beb6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c94beb7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c94beb6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c94beb6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c94beb6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c9507c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c9507c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c9507b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c9507dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc6d61a3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c94a0d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-fb850eb0f808c252e819acf127a5f3951c622d0e Step #5: Base64: LS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 669 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2083392996 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d710409810, 0x55d7105f301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d7105f3020,0x55d71248b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fb850eb0f808c252e819acf127a5f3951c622d0e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 729 processed earlier; will process 10300 files now Step #5: ==24118== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d706efe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d70d563898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d70d5465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d70d5464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d706f04d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d706e65b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d706e60355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d706ef6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d709ec5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d709ec5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d709ec5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d709ec5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d709ec5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d709ec5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d709ec5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d709ec5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d709ec5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d709ec5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d70c15af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d708e87b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d708e92be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d708c3ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d708c3ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d708c3f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d708c3e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d708c3e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d708c3e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d70d548abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d70d551928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d70d539699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d70d564112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b8bc75082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d706e5eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xda,0xb8,0x7b,0x36,0x7d, Step #5: \332\270{6} Step #5: artifact_prefix='./'; Test unit written to ./oom-beb9083d3bd23e166f226e85125e58827bac652e Step #5: Base64: 2rh7Nn0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 670 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2083821168 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e435491810, 0x55e43567b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e43567b020,0x55e4375130e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/beb9083d3bd23e166f226e85125e58827bac652e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 730 processed earlier; will process 10299 files now Step #5: #1 pulse cov: 11309 ft: 11310 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 11758 ft: 12522 exec/s: 0 rss: 179Mb Step #5: ==24154== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e42bf869c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4325eb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4325ce5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4325ce4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e42bf8cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e42beedb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e42bee8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e42bf7ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e42ef4df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e42ef4df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e42ef4df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e42ef4df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e42ef4df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e42ef4df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e42ef4df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e42ef4df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e42ef4df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e42ef4df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4311e2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e42df0fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e42df1abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e42dcc6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e42dcc6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e42dcc7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e42dcc6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e42dcc6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e42dcc6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4325d0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4325d9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4325c1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4325ec112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f269daad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e42bee6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0, Step #5: \000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a10909c2cdcaf5adb7e6b092a4faba558b62bd96 Step #5: Base64: AAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 671 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2084393522 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ebaee7b810, 0x55ebaf06501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ebaf065020,0x55ebb0efd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a10909c2cdcaf5adb7e6b092a4faba558b62bd96' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 733 processed earlier; will process 10296 files now Step #5: ==24190== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eba59709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ebabfd5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ebabfb85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ebabfb84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eba5976d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eba58d7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eba58d2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eba5968c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eba8937f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eba8937f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eba8937f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eba8937f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eba8937f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eba8937f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eba8937f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eba8937f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eba8937f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eba8937f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ebaabccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eba78f9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eba7904be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eba76b0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eba76b0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eba76b1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eba76b0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eba76b0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eba76b0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ebabfbaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ebabfc3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ebabfab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ebabfd6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa118969082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eba58d0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xca,0x9f,0xea,0x93,0xbd, Step #5: \312\237\352\223\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-ae321bd38fb5bd0293c5c10e97bf25a15831f2d7 Step #5: Base64: yp/qk70= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 672 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2084835223 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560df085e810, 0x560df0a4801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560df0a48020,0x560df28e00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ae321bd38fb5bd0293c5c10e97bf25a15831f2d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 734 processed earlier; will process 10295 files now Step #5: ==24226== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560de73539c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560ded9b8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560ded99b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560ded99b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560de7359d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560de72bab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560de72b5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560de734bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560dea31af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560dea31af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560dea31af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560dea31af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560dea31af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560dea31af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560dea31af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560dea31af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560dea31af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560dea31af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560dec5aff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560de92dcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560de92e7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560de9093c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560de9093c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560de9094738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560de9093874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560de9093874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560de9093874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560ded99dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560ded9a6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560ded98e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560ded9b9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8bcf3dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560de72b3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x80,0xac,0x63,0x0, Step #5: \343\200\254c\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-64e0e937088f648e3e5412ab46e00626112295c2 Step #5: Base64: 44CsYwA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 673 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2085271972 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cdb5405810, 0x55cdb55ef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cdb55ef020,0x55cdb74870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/64e0e937088f648e3e5412ab46e00626112295c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 735 processed earlier; will process 10294 files now Step #5: ==24262== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cdabefa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cdb255f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cdb25425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cdb25424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cdabf00d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cdabe61b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cdabe5c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cdabef2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cdaeec1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cdaeec1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cdaeec1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cdaeec1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cdaeec1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cdaeec1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cdaeec1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cdaeec1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cdaeec1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cdaeec1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cdb1156f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cdade83b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cdade8ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cdadc3ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cdadc3ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cdadc3b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cdadc3a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cdadc3a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cdadc3a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cdb2544abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cdb254d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cdb2535699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cdb2560112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff01feca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cdabe5ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2c,0xdf,0xad,0x2d,0x40, Step #5: ,\337\255-@ Step #5: artifact_prefix='./'; Test unit written to ./oom-fa114a70cf5c6785d3549442d146ce0642710e1d Step #5: Base64: LN+tLUA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 674 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2085705697 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d75c11c810, 0x55d75c30601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d75c306020,0x55d75e19e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fa114a70cf5c6785d3549442d146ce0642710e1d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 736 processed earlier; will process 10293 files now Step #5: ==24298== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d752c119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d759276898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7592595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7592594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d752c17d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d752b78b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d752b73355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d752c09c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d755bd8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d755bd8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d755bd8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d755bd8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d755bd8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d755bd8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d755bd8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d755bd8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d755bd8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d755bd8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d757e6df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d754b9ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d754ba5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d754951c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d754951c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d754952738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d754951874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d754951874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d754951874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d75925babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d759264928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d75924c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d759277112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff0b28bd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d752b71b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xa,0xa,0x24,0x60, Step #5: `\012\012$` Step #5: artifact_prefix='./'; Test unit written to ./oom-fc614685756cd139897bf673da80446c9574edf2 Step #5: Base64: YAoKJGA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 675 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2086261051 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b10c8d810, 0x557b10e7701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b10e77020,0x557b12d0f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc614685756cd139897bf673da80446c9574edf2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 737 processed earlier; will process 10292 files now Step #5: ==24334== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557b077829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b0dde7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b0ddca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b0ddca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b07788d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b076e9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b076e4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b0777ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b0a749f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b0a749f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b0a749f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b0a749f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b0a749f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b0a749f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b0a749f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b0a749f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b0a749f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b0a749f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b0c9def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b0970bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b09716be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b094c2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b094c2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b094c3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b094c2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b094c2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b094c2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b0ddccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b0ddd5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b0ddbd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b0dde8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53a9a4c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b076e2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x62,0x6a,0x75,0x2c,0x73, Step #5: bju,s Step #5: artifact_prefix='./'; Test unit written to ./oom-c07235896f988841275e73ff850a0ceb00e91695 Step #5: Base64: Ymp1LHM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 676 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2086691693 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed7f05c810, 0x55ed7f24601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed7f246020,0x55ed810de0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c07235896f988841275e73ff850a0ceb00e91695' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 738 processed earlier; will process 10291 files now Step #5: ==24370== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ed75b519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed7c1b6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed7c1995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed7c1994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed75b57d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed75ab8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed75ab3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed75b49c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed78b18f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed78b18f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed78b18f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed78b18f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed78b18f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed78b18f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed78b18f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed78b18f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed78b18f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed78b18f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed7adadf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed77adab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed77ae5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed77891c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed77891c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed77892738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed77891874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed77891874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed77891874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed7c19babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed7c1a4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed7c18c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed7c1b7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe9069cb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed75ab1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0x7c,0xe7,0xbd,0xbd, Step #5: .|\347\275\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-f78bb231416ccd3ac5c9d09d14401ee22f7a7021 Step #5: Base64: Lnznvb0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 677 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2087116360 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d46209b810, 0x55d46228501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d462285020,0x55d46411d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f78bb231416ccd3ac5c9d09d14401ee22f7a7021' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 739 processed earlier; will process 10290 files now Step #5: ==24406== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d458b909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d45f1f5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d45f1d85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d45f1d84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d458b96d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d458af7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d458af2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d458b88c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d45bb57f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d45bb57f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d45bb57f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d45bb57f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d45bb57f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d45bb57f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d45bb57f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d45bb57f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d45bb57f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d45bb57f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d45ddecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d45ab19b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d45ab24be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d45a8d0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d45a8d0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d45a8d1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d45a8d0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d45a8d0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d45a8d0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d45f1daabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d45f1e3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d45f1cb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d45f1f6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f839ef8d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d458af0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x30,0x25,0xe2,0x31, Step #5: #0%\3421 Step #5: artifact_prefix='./'; Test unit written to ./oom-4806fae68640dafbc0a36b79d770e0593231aa33 Step #5: Base64: IzAl4jE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 678 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2087543381 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562020aae810, 0x562020c9801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562020c98020,0x562022b300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4806fae68640dafbc0a36b79d770e0593231aa33' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 740 processed earlier; will process 10289 files now Step #5: ==24442== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5620175a39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56201dc08898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56201dbeb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56201dbeb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5620175a9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56201750ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562017505355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56201759bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56201a56af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56201a56af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56201a56af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56201a56af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56201a56af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56201a56af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56201a56af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56201a56af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56201a56af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56201a56af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56201c7fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56201952cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562019537be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5620192e3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5620192e3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5620192e4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5620192e3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5620192e3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5620192e3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56201dbedabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56201dbf6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56201dbde699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56201dc09112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f75dbee0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562017503b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7,0x0,0xc8,0x9f,0x0, Step #5: \007\000\310\237\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e5a41e07c15ecd32330a4251a9d08811b8d31812 Step #5: Base64: BwDInwA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 679 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2087972128 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5601ba6f9810, 0x5601ba8e301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5601ba8e3020,0x5601bc77b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e5a41e07c15ecd32330a4251a9d08811b8d31812' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 741 processed earlier; will process 10288 files now Step #5: ==24478== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5601b11ee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601b7853898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601b78365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601b78364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5601b11f4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601b1155b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601b1150355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5601b11e6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601b41b5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601b41b5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601b41b5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601b41b5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601b41b5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601b41b5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601b41b5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601b41b5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601b41b5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601b41b5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5601b644af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601b3177b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601b3182be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5601b2f2ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5601b2f2ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5601b2f2f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5601b2f2e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5601b2f2e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5601b2f2e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5601b7838abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5601b7841928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5601b7829699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601b7854112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f97e28f4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601b114eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x5f,0x5f,0x6e,0x4d, Step #5: D__nM Step #5: artifact_prefix='./'; Test unit written to ./oom-e30d6d44a84965a3792805b5c983cdac649a25b4 Step #5: Base64: RF9fbk0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 680 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2088398956 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562467429810, 0x56246761301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562467613020,0x5624694ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e30d6d44a84965a3792805b5c983cdac649a25b4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 742 processed earlier; will process 10287 files now Step #5: ==24514== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56245df1e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562464583898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5624645665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5624645664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56245df24d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56245de85b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56245de80355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56245df16c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562460ee5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562460ee5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562460ee5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562460ee5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562460ee5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562460ee5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562460ee5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562460ee5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562460ee5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562460ee5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56246317af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56245fea7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56245feb2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56245fc5ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56245fc5ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56245fc5f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56245fc5e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56245fc5e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56245fc5e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562464568abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562464571928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562464559699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562464584112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f59adfac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56245de7eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53,0x3a,0x40,0x0,0x1, Step #5: S:@\000\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-cc9dbc2c89587137e5871f37e2d0601cba684b51 Step #5: Base64: UzpAAAE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 681 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2088822064 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb158dc810, 0x55eb15ac601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb15ac6020,0x55eb1795e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cc9dbc2c89587137e5871f37e2d0601cba684b51' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 743 processed earlier; will process 10286 files now Step #5: ==24550== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eb0c3d19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb12a36898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb12a195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb12a194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb0c3d7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb0c338b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb0c333355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb0c3c9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb0f398f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb0f398f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb0f398f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb0f398f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb0f398f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb0f398f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb0f398f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb0f398f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb0f398f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb0f398f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb1162df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb0e35ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb0e365be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb0e111c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb0e111c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb0e112738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb0e111874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb0e111874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb0e111874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb12a1babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb12a24928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb12a0c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb12a37112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8c75a80082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb0c331b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x73, Step #5: DanMs Step #5: artifact_prefix='./'; Test unit written to ./oom-f3deeaf93ddbbc2c0231eda3b83ed837c995a346 Step #5: Base64: RGFuTXM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 682 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2089247325 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56542a0fe810, 0x56542a2e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56542a2e8020,0x56542c1800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f3deeaf93ddbbc2c0231eda3b83ed837c995a346' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 744 processed earlier; will process 10285 files now Step #5: #1 pulse cov: 3522 ft: 3523 exec/s: 0 rss: 156Mb Step #5: ==24586== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x565420bf39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565427258898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56542723b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56542723b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565420bf9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565420b5ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565420b55355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565420bebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565423bbaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565423bbaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565423bbaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565423bbaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565423bbaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565423bbaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565423bbaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565423bbaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565423bbaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565423bbaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565425e4ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565422b7cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565422b87be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565422933c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565422933c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565422934738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565422933874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565422933874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565422933874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56542723dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565427246928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56542722e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565427259112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f916f90e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565420b53b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x53,0x2b,0x5c,0x57, Step #5: \\S+\\W Step #5: artifact_prefix='./'; Test unit written to ./oom-84906ae81f134e7897738ad4ce48fbc505666772 Step #5: Base64: XFMrXFc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 683 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2089707439 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1dd72c810, 0x55d1dd91601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1dd916020,0x55d1df7ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/84906ae81f134e7897738ad4ce48fbc505666772' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 746 processed earlier; will process 10283 files now Step #5: ==24622== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d1d42219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1da886898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1da8695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1da8694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1d4227d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1d4188b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1d4183355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1d4219c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1d71e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1d71e8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1d71e8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1d71e8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1d71e8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1d71e8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1d71e8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1d71e8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1d71e8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1d71e8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1d947df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1d61aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1d61b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1d5f61c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1d5f61c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1d5f62738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1d5f61874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1d5f61874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1d5f61874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1da86babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1da874928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1da85c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1da887112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbc40fde082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1d4181b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x7b,0xe1,0x9f,0x8c, Step #5: r{\341\237\214 Step #5: artifact_prefix='./'; Test unit written to ./oom-64333a0135803b1d8e7e96cdb762ab9a505253de Step #5: Base64: cnvhn4w= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 684 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2090133017 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56178a7ed810, 0x56178a9d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56178a9d7020,0x56178c86f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/64333a0135803b1d8e7e96cdb762ab9a505253de' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 747 processed earlier; will process 10282 files now Step #5: ==24658== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5617812e29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561787947898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56178792a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56178792a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5617812e8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561781249b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561781244355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5617812dac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5617842a9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5617842a9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5617842a9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5617842a9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5617842a9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5617842a9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5617842a9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5617842a9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5617842a9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5617842a9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56178653ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56178326bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561783276be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561783022c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561783022c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561783023738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561783022874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561783022874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561783022874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56178792cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561787935928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56178791d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561787948112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb8bdf21082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561781242b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xb7,0xbc,0xcd,0x84, Step #5: \341\267\274\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-e0498eae6d81ef904f76db846bacb2d7a725f590 Step #5: Base64: 4be8zYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 685 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2090560835 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e62ae07810, 0x55e62aff101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e62aff1020,0x55e62ce890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e0498eae6d81ef904f76db846bacb2d7a725f590' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 748 processed earlier; will process 10281 files now Step #5: #1 pulse cov: 3582 ft: 3583 exec/s: 0 rss: 158Mb Step #5: ==24694== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e6218fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e627f61898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e627f445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e627f444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e621902d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e621863b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e62185e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e6218f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e6248c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e6248c3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e6248c3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e6248c3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e6248c3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e6248c3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e6248c3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e6248c3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e6248c3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e6248c3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e626b58f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e623885b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e623890be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e62363cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e62363cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e62363d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e62363c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e62363c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e62363c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e627f46abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e627f4f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e627f37699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e627f62112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa280f57082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e62185cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0x2d,0x74,0x41,0x59, Step #5: i-tAY Step #5: artifact_prefix='./'; Test unit written to ./oom-0cf02f32a1e24e5407e8651c3dc73aa4f6957a8d Step #5: Base64: aS10QVk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 686 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2091028761 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563629c4e810, 0x563629e3801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563629e38020,0x56362bcd00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0cf02f32a1e24e5407e8651c3dc73aa4f6957a8d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 750 processed earlier; will process 10279 files now Step #5: ==24730== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5636207439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563626da8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563626d8b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563626d8b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563620749d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5636206aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5636206a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56362073bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56362370af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56362370af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56362370af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56362370af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56362370af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56362370af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56362370af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56362370af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56362370af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56362370af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56362599ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5636226ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5636226d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563622483c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563622483c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563622484738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563622483874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563622483874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563622483874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563626d8dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563626d96928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563626d7e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563626da9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f085ec9a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5636206a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x3,0x15,0x0,0x1, Step #5: \003\003\025\000\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-ce9dcd568b0e3751d176f24745d460af46b276c3 Step #5: Base64: AwMVAAE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 687 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2091455617 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1c67a0810, 0x55a1c698a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1c698a020,0x55a1c88220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce9dcd568b0e3751d176f24745d460af46b276c3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 751 processed earlier; will process 10278 files now Step #5: ==24766== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a1bd2959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1c38fa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1c38dd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1c38dd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1bd29bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1bd1fcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1bd1f7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1bd28dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1c025cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1c025cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1c025cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1c025cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1c025cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1c025cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1c025cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1c025cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1c025cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1c025cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1c24f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1bf21eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1bf229be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1befd5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1befd5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1befd6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1befd5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1befd5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1befd5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a1c38dfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a1c38e8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1c38d0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1c38fb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f741effe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1bd1f5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x9,0x2b,0x48,0x48,0x48, Step #5: \011+HHH Step #5: artifact_prefix='./'; Test unit written to ./oom-b78436073b9643604a38c251aba626fe1cabb4ed Step #5: Base64: CStISEg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 688 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2091885077 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c7b3ebc810, 0x55c7b40a601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c7b40a6020,0x55c7b5f3e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b78436073b9643604a38c251aba626fe1cabb4ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 752 processed earlier; will process 10277 files now Step #5: ==24802== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c7aa9b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7b1016898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7b0ff95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7b0ff94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c7aa9b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c7aa918b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c7aa913355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7aa9a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7ad978f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7ad978f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7ad978f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7ad978f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7ad978f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7ad978f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7ad978f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7ad978f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7ad978f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7ad978f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7afc0df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7ac93ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7ac945be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7ac6f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7ac6f1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7ac6f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7ac6f1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7ac6f1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7ac6f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7b0ffbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7b1004928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c7b0fec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7b1017112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27023ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c7aa911b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc9,0xa1,0x7c,0xcd,0x84, Step #5: \311\241|\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-2140d73831f19fd9a83e1d2700fda13e2ceb49b5 Step #5: Base64: yaF8zYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 689 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2092313150 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5568d1a96810, 0x5568d1c8001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5568d1c80020,0x5568d3b180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2140d73831f19fd9a83e1d2700fda13e2ceb49b5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 753 processed earlier; will process 10276 files now Step #5: ==24838== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5568c858b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5568cebf0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5568cebd35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5568cebd34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5568c8591d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5568c84f2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5568c84ed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5568c8583c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5568cb552f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5568cb552f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5568cb552f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5568cb552f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5568cb552f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5568cb552f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5568cb552f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5568cb552f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5568cb552f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5568cb552f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5568cd7e7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5568ca514b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5568ca51fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5568ca2cbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5568ca2cbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5568ca2cc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5568ca2cb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5568ca2cb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5568ca2cb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5568cebd5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5568cebde928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5568cebc6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5568cebf1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbc2d5d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5568c84ebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0xe1,0xa0,0x8f,0xfe, Step #5: 1\341\240\217\376 Step #5: artifact_prefix='./'; Test unit written to ./oom-4140e50dc8bc54a7d0100bd300bb091f9918eb7a Step #5: Base64: MeGgj/4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 690 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2092736093 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eee9047810, 0x55eee923101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eee9231020,0x55eeeb0c90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4140e50dc8bc54a7d0100bd300bb091f9918eb7a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 754 processed earlier; will process 10275 files now Step #5: ==24874== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eedfb3c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eee61a1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eee61845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eee61844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eedfb42d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eedfaa3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eedfa9e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eedfb34c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eee2b03f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eee2b03f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eee2b03f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eee2b03f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eee2b03f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eee2b03f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eee2b03f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eee2b03f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eee2b03f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eee2b03f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eee4d98f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eee1ac5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eee1ad0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eee187cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eee187cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eee187d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eee187c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eee187c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eee187c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eee6186abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eee618f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eee6177699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eee61a2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f915ca58082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eedfa9cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x57,0x6e,0x61,0x6d,0x65, Step #5: Wname Step #5: artifact_prefix='./'; Test unit written to ./oom-e03516898d243eacf3902e363cf6fc9f079aa951 Step #5: Base64: V25hbWU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 691 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2093171360 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e682a19810, 0x55e682c0301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e682c03020,0x55e684a9b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e03516898d243eacf3902e363cf6fc9f079aa951' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 755 processed earlier; will process 10274 files now Step #5: ==24910== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e67950e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e67fb73898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e67fb565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e67fb564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e679514d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e679475b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e679470355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e679506c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e67c4d5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e67c4d5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e67c4d5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e67c4d5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e67c4d5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e67c4d5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e67c4d5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e67c4d5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e67c4d5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e67c4d5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e67e76af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e67b497b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e67b4a2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e67b24ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e67b24ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e67b24f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e67b24e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e67b24e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e67b24e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e67fb58abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e67fb61928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e67fb49699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e67fb74112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0359546082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e67946eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdd,0xbf,0x42,0x27,0x27, Step #5: \335\277B'' Step #5: artifact_prefix='./'; Test unit written to ./oom-3cce79d6e891cbf0bd6a9d76f7723959a751b445 Step #5: Base64: 3b9CJyc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 692 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2093598661 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f0382e9810, 0x55f0384d301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f0384d3020,0x55f03a36b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3cce79d6e891cbf0bd6a9d76f7723959a751b445' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 756 processed earlier; will process 10273 files now Step #5: #1 pulse cov: 3740 ft: 3741 exec/s: 0 rss: 158Mb Step #5: ==24946== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f02edde9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f035443898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f0354265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f0354264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f02ede4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f02ed45b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f02ed40355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f02edd6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f031da5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f031da5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f031da5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f031da5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f031da5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f031da5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f031da5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f031da5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f031da5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f031da5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f03403af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f030d67b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f030d72be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f030b1ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f030b1ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f030b1f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f030b1e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f030b1e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f030b1e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f035428abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f035431928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f035419699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f035444112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe0fd22e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f02ed3eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x29,0x7e,0xd8,0xad, Step #5: 0)~\330\255 Step #5: artifact_prefix='./'; Test unit written to ./oom-63495433bb434121bddf9df7134b203e0227a315 Step #5: Base64: MCl+2K0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 693 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2094071931 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559dc44da810, 0x559dc46c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559dc46c4020,0x559dc655c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/63495433bb434121bddf9df7134b203e0227a315' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 758 processed earlier; will process 10271 files now Step #5: ==24982== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559dbafcf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559dc1634898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559dc16175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559dc16174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559dbafd5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559dbaf36b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559dbaf31355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559dbafc7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559dbdf96f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559dbdf96f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559dbdf96f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559dbdf96f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559dbdf96f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559dbdf96f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559dbdf96f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559dbdf96f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559dbdf96f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559dbdf96f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559dc022bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559dbcf58b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559dbcf63be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559dbcd0fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559dbcd0fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559dbcd10738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559dbcd0f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559dbcd0f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559dbcd0f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559dc1619abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559dc1622928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559dc160a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559dc1635112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f70bf75c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559dbaf2fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x15,0x3f,0xe1,0x9f,0x96, Step #5: \025?\341\237\226 Step #5: artifact_prefix='./'; Test unit written to ./oom-35f691db77a11829fc64bf2d3d652f65ffd7ba5a Step #5: Base64: FT/hn5Y= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 694 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2094497124 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db09275810, 0x55db0945f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db0945f020,0x55db0b2f70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/35f691db77a11829fc64bf2d3d652f65ffd7ba5a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 759 processed earlier; will process 10270 files now Step #5: ==25018== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55daffd6a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db063cf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db063b25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db063b24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55daffd70d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55daffcd1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55daffccc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55daffd62c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db02d31f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db02d31f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db02d31f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db02d31f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db02d31f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db02d31f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db02d31f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db02d31f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db02d31f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db02d31f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db04fc6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db01cf3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db01cfebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db01aaac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db01aaac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db01aab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db01aaa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db01aaa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db01aaa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db063b4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db063bd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db063a5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db063d0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ee3d66082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55daffccab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0xd,0x25,0xd,0x25, Step #5: %\015%\015% Step #5: artifact_prefix='./'; Test unit written to ./oom-75a16952452a841e4062a065c6517794445dde55 Step #5: Base64: JQ0lDSU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 695 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2094930487 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562fef4b2810, 0x562fef69c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562fef69c020,0x562ff15340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/75a16952452a841e4062a065c6517794445dde55' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 760 processed earlier; will process 10269 files now Step #5: ==25054== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562fe5fa79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562fec60c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562fec5ef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562fec5ef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562fe5fadd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562fe5f0eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562fe5f09355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562fe5f9fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562fe8f6ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562fe8f6ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562fe8f6ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562fe8f6ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562fe8f6ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562fe8f6ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562fe8f6ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562fe8f6ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562fe8f6ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562fe8f6ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562feb203f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562fe7f30b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562fe7f3bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562fe7ce7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562fe7ce7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562fe7ce8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562fe7ce7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562fe7ce7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562fe7ce7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562fec5f1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562fec5fa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562fec5e2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562fec60d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc377bea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562fe5f07b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0xcd,0x93, Step #5: Step #5: Step #5: #0 0x562e7bc839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e822e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e822cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e822cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e7bc89d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e7bbeab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e7bbe5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e7bc7bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e7ec4af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e7ec4af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e7ec4af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e7ec4af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e7ec4af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e7ec4af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e7ec4af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e7ec4af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e7ec4af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e7ec4af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e80edff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e7dc0cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e7dc17be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e7d9c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e7d9c3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e7d9c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e7d9c3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e7d9c3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e7d9c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e822cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e822d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e822be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e822e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f047d5fb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e7bbe3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x74,0x72,0xdc,0x81, Step #5: str\334\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-1c98aaf3704e42726c0aa5bf1ca7b551142e693f Step #5: Base64: c3Ry3IE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 697 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2095825526 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564eb7332810, 0x564eb751c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564eb751c020,0x564eb93b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c98aaf3704e42726c0aa5bf1ca7b551142e693f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 763 processed earlier; will process 10266 files now Step #5: ==25126== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564eade279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564eb448c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564eb446f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564eb446f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564eade2dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564eadd8eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564eadd89355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564eade1fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564eb0deef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564eb0deef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564eb0deef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564eb0deef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564eb0deef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564eb0deef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564eb0deef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564eb0deef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564eb0deef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564eb0deef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564eb3083f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564eafdb0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564eafdbbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564eafb67c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564eafb67c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564eafb68738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564eafb67874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564eafb67874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564eafb67874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564eb4471abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564eb447a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564eb4462699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564eb448d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f07321a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564eadd87b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xaf,0x82,0xf4,0x2c, Step #5: \340\257\202\364, Step #5: artifact_prefix='./'; Test unit written to ./oom-04028d5020e2b8d3cce71581642909169b83043e Step #5: Base64: 4K+C9Cw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 698 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2096250473 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56505bc3e810, 0x56505be2801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56505be28020,0x56505dcc00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/04028d5020e2b8d3cce71581642909169b83043e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 764 processed earlier; will process 10265 files now Step #5: ==25162== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5650527339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565058d98898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565058d7b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565058d7b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565052739d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56505269ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565052695355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56505272bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5650556faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5650556faf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5650556faf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5650556faf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5650556faf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5650556faf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5650556faf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5650556faf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5650556faf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5650556faf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56505798ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5650546bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5650546c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565054473c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565054473c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565054474738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565054473874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565054473874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565054473874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565058d7dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565058d86928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565058d6e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565058d99112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa09ae2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565052693b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0xef,0xa0,0xa0,0x0, Step #5: s\357\240\240\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cd92039b61ac8ccfe16efd42acb1f38b9129ed6c Step #5: Base64: c++goAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 699 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2096673025 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ac5f3ec810, 0x55ac5f5d601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ac5f5d6020,0x55ac6146e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd92039b61ac8ccfe16efd42acb1f38b9129ed6c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 765 processed earlier; will process 10264 files now Step #5: #1 pulse cov: 10343 ft: 10344 exec/s: 0 rss: 174Mb Step #5: ==25198== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ac55ee19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ac5c546898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ac5c5295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ac5c5294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ac55ee7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ac55e48b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ac55e43355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ac55ed9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ac58ea8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ac58ea8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ac58ea8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ac58ea8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ac58ea8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ac58ea8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ac58ea8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ac58ea8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ac58ea8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ac58ea8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ac5b13df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ac57e6ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ac57e75be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ac57c21c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ac57c21c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ac57c22738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ac57c21874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ac57c21874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ac57c21874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ac5c52babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ac5c534928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ac5c51c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ac5c547112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff5d96f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ac55e41b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x16,0x6,0x7e,0x0,0x1, Step #5: \026\006~\000\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-71c269d2a72bcd0e203c1a7715f7b4a3fc1eedc8 Step #5: Base64: FgZ+AAE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 700 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2097164376 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556686734810, 0x55668691e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55668691e020,0x5566887b60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/71c269d2a72bcd0e203c1a7715f7b4a3fc1eedc8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 767 processed earlier; will process 10262 files now Step #5: ==25234== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55667d2299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55668388e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5566838715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5566838714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55667d22fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55667d190b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55667d18b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55667d221c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5566801f0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5566801f0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5566801f0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5566801f0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5566801f0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5566801f0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5566801f0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5566801f0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5566801f0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5566801f0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556682485f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55667f1b2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55667f1bdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55667ef69c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55667ef69c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55667ef6a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55667ef69874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55667ef69874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55667ef69874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556683873abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55668387c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556683864699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55668388f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c9f5f5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55667d189b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x2d,0x20,0x3f, Step #5: - - ? Step #5: artifact_prefix='./'; Test unit written to ./oom-db8adca477f5925610f6027e630e78236f0be22e Step #5: Base64: LSAtID8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 701 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2097602997 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559cc25bc810, 0x559cc27a601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559cc27a6020,0x559cc463e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/db8adca477f5925610f6027e630e78236f0be22e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 768 processed earlier; will process 10261 files now Step #5: ==25270== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559cb90b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559cbf716898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559cbf6f95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559cbf6f94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559cb90b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559cb9018b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559cb9013355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559cb90a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559cbc078f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559cbc078f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559cbc078f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559cbc078f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559cbc078f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559cbc078f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559cbc078f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559cbc078f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559cbc078f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559cbc078f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559cbe30df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559cbb03ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559cbb045be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559cbadf1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559cbadf1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559cbadf2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559cbadf1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559cbadf1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559cbadf1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559cbf6fbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559cbf704928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559cbf6ec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559cbf717112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f54c3f0f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559cb9011b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x6e,0x66,0x69,0x70, Step #5: Infip Step #5: artifact_prefix='./'; Test unit written to ./oom-3fe9f65f1abac5c0355dbe60c9dff89da2c5b7c9 Step #5: Base64: SW5maXA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 702 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2098033027 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fa3ee70810, 0x55fa3f05a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fa3f05a020,0x55fa40ef20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3fe9f65f1abac5c0355dbe60c9dff89da2c5b7c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 769 processed earlier; will process 10260 files now Step #5: ==25306== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fa359659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fa3bfca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fa3bfad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fa3bfad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fa3596bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fa358ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fa358c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fa3595dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fa3892cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fa3892cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fa3892cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fa3892cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fa3892cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fa3892cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fa3892cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fa3892cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fa3892cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fa3892cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fa3abc1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fa378eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fa378f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fa376a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fa376a5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fa376a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fa376a5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fa376a5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fa376a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fa3bfafabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fa3bfb8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fa3bfa0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fa3bfcb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f6ae14082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fa358c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x45,0x44,0xd3,0x88, Step #5: wED\323\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-633e3393b84061e060b79d081f74f3226c4664bb Step #5: Base64: d0VE04g= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 703 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2098457902 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5625301ff810, 0x5625303e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625303e9020,0x5625322810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/633e3393b84061e060b79d081f74f3226c4664bb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 770 processed earlier; will process 10259 files now Step #5: ==25342== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562526cf49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56252d359898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56252d33c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56252d33c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562526cfad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562526c5bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562526c56355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562526cecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562529cbbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562529cbbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562529cbbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562529cbbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562529cbbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562529cbbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562529cbbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562529cbbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562529cbbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562529cbbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56252bf50f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562528c7db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562528c88be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562528a34c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562528a34c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562528a35738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562528a34874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562528a34874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562528a34874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56252d33eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56252d347928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56252d32f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56252d35a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f235c3a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562526c54b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x5c,0x75,0x2b,0x22, Step #5: \"\\u+\" Step #5: artifact_prefix='./'; Test unit written to ./oom-82a3514ca031e020f2f663857c04e6fee082fc78 Step #5: Base64: Ilx1KyI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 704 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2098888711 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56551204c810, 0x56551223601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565512236020,0x5655140ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/82a3514ca031e020f2f663857c04e6fee082fc78' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 771 processed earlier; will process 10258 files now Step #5: #1 pulse cov: 6517 ft: 6519 exec/s: 0 rss: 172Mb Step #5: ==25378== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x565508b419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56550f1a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56550f1895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56550f1894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565508b47d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565508aa8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565508aa3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565508b39c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56550bb08f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56550bb08f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56550bb08f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56550bb08f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56550bb08f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56550bb08f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56550bb08f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56550bb08f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56550bb08f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56550bb08f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56550dd9df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56550aacab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56550aad5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56550a881c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56550a881c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56550a882738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56550a881874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56550a881874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56550a881874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56550f18babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56550f194928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56550f17c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56550f1a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f62d73f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565508aa1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0xe1,0x9f,0x96,0x27, Step #5: ?\341\237\226' Step #5: artifact_prefix='./'; Test unit written to ./oom-64c9e7d5a7d142cd6c0ded1ca1c4421f56aaa2cf Step #5: Base64: P+Gflic= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 705 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2099365251 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5568e8c99810, 0x5568e8e8301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5568e8e83020,0x5568ead1b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/64c9e7d5a7d142cd6c0ded1ca1c4421f56aaa2cf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 773 processed earlier; will process 10256 files now Step #5: ==25414== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5568df78e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5568e5df3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5568e5dd65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5568e5dd64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5568df794d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5568df6f5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5568df6f0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5568df786c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5568e2755f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5568e2755f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5568e2755f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5568e2755f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5568e2755f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5568e2755f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5568e2755f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5568e2755f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5568e2755f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5568e2755f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5568e49eaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5568e1717b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5568e1722be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5568e14cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5568e14cec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5568e14cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5568e14ce874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5568e14ce874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5568e14ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5568e5dd8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5568e5de1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5568e5dc9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5568e5df4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc39403a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5568df6eeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0xf1,0xbf,0xbf,0xbf, Step #5: \\\361\277\277\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-b3ee7d85a99cd91a51d6850eb54f18db94ee1e37 Step #5: Base64: XPG/v78= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 706 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2099799609 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e0c4f27810, 0x55e0c511101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e0c5111020,0x55e0c6fa90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3ee7d85a99cd91a51d6850eb54f18db94ee1e37' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 774 processed earlier; will process 10255 files now Step #5: ==25450== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e0bba1c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e0c2081898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e0c20645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e0c20644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e0bba22d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e0bb983b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e0bb97e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e0bba14c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e0be9e3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e0be9e3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e0be9e3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e0be9e3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e0be9e3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e0be9e3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e0be9e3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e0be9e3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e0be9e3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e0be9e3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e0c0c78f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e0bd9a5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e0bd9b0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e0bd75cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e0bd75cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e0bd75d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e0bd75c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e0bd75c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e0bd75c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e0c2066abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e0c206f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e0c2057699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e0c2082112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe1bdc4d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e0bb97cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x61,0x73,0x11,0x7e, Step #5: \000as\021~ Step #5: artifact_prefix='./'; Test unit written to ./oom-4a9a4cd57fa8caf3520e106bd549b3a6d7075b8b Step #5: Base64: AGFzEX4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 707 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2100232240 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559995dec810, 0x559995fd601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559995fd6020,0x559997e6e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4a9a4cd57fa8caf3520e106bd549b3a6d7075b8b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 775 processed earlier; will process 10254 files now Step #5: #1 pulse cov: 3381 ft: 3382 exec/s: 0 rss: 158Mb Step #5: ==25486== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55998c8e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559992f46898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559992f295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559992f294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55998c8e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55998c848b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55998c843355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55998c8d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55998f8a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55998f8a8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55998f8a8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55998f8a8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55998f8a8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55998f8a8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55998f8a8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55998f8a8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55998f8a8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55998f8a8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559991b3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55998e86ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55998e875be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55998e621c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55998e621c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55998e622738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55998e621874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55998e621874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55998e621874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559992f2babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559992f34928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559992f1c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559992f47112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa6091dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55998c841b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x87,0xab,0xe6,0xa4, Step #5: \363\240\207\253\346\244 Step #5: artifact_prefix='./'; Test unit written to ./oom-e25c747a8b87a28e539752a8024888274b4ed08a Step #5: Base64: 86CHq+ak Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 708 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2100701288 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bc1a33a810, 0x55bc1a52401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bc1a524020,0x55bc1c3bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e25c747a8b87a28e539752a8024888274b4ed08a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 777 processed earlier; will process 10252 files now Step #5: ==25522== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bc10e2f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bc17494898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bc174775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bc174774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bc10e35d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bc10d96b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bc10d91355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bc10e27c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bc13df6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bc13df6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bc13df6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bc13df6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bc13df6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bc13df6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bc13df6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bc13df6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bc13df6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bc13df6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bc1608bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bc12db8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bc12dc3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bc12b6fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bc12b6fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bc12b70738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bc12b6f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bc12b6f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bc12b6f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bc17479abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bc17482928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bc1746a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bc17495112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5ac972c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bc10d8fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0xac,0xf4,0x8f,0x96,0x96, Step #5: \333\254\364\217\226\226 Step #5: artifact_prefix='./'; Test unit written to ./oom-7dc669f59bdf4acbd103d9b6e80a2d6a79b3b8a3 Step #5: Base64: 26z0j5aW Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 709 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2101127649 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56268ad7e810, 0x56268af6801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56268af68020,0x56268ce000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7dc669f59bdf4acbd103d9b6e80a2d6a79b3b8a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 778 processed earlier; will process 10251 files now Step #5: ==25558== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5626818739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562687ed8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562687ebb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562687ebb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562681879d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5626817dab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5626817d5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56268186bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56268483af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56268483af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56268483af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56268483af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56268483af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56268483af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56268483af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56268483af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56268483af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56268483af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562686acff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5626837fcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562683807be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5626835b3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5626835b3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5626835b4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5626835b3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5626835b3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5626835b3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562687ebdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562687ec6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562687eae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562687ed9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa55aae0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5626817d3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x14,0x3,0x16,0x0,0x0,0x3, Step #5: \024\003\026\000\000\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-577a40c766aeb0259135f5897874366bcb523ef2 Step #5: Base64: FAMWAAAD Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 710 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2101558160 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55679d495810, 0x55679d67f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55679d67f020,0x55679f5170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/577a40c766aeb0259135f5897874366bcb523ef2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 779 processed earlier; will process 10250 files now Step #5: ==25594== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556793f8a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55679a5ef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55679a5d25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55679a5d24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556793f90d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556793ef1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556793eec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556793f82c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556796f51f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556796f51f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556796f51f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556796f51f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556796f51f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556796f51f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556796f51f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556796f51f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556796f51f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556796f51f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5567991e6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556795f13b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556795f1ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556795ccac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556795ccac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556795ccb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556795cca874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556795cca874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556795cca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55679a5d4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55679a5dd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55679a5c5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55679a5f0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc5bb4ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556793eeab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x84,0x82,0xe1,0x85,0xac, Step #5: \341\204\202\341\205\254 Step #5: artifact_prefix='./'; Test unit written to ./oom-8bf33a087af56ad39f27c523324343f8bac62d7a Step #5: Base64: 4YSC4YWs Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 711 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2101985316 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5582bb5a0810, 0x5582bb78a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5582bb78a020,0x5582bd6220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8bf33a087af56ad39f27c523324343f8bac62d7a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 780 processed earlier; will process 10249 files now Step #5: ==25630== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5582b20959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5582b86fa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5582b86dd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5582b86dd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5582b209bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5582b1ffcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5582b1ff7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5582b208dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5582b505cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5582b505cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5582b505cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5582b505cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5582b505cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5582b505cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5582b505cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5582b505cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5582b505cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5582b505cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5582b72f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5582b401eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5582b4029be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5582b3dd5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5582b3dd5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5582b3dd6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5582b3dd5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5582b3dd5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5582b3dd5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5582b86dfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5582b86e8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5582b86d0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5582b86fb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3f3fb91082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5582b1ff5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3c,0xde,0xac,0x3e, Step #5: (?<\336\254> Step #5: artifact_prefix='./'; Test unit written to ./oom-5bbf3cd8771c2447ab0ec792004a3eb2bb380fb2 Step #5: Base64: KD883qw+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 712 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2102414594 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d46fecc810, 0x55d4700b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d4700b6020,0x55d471f4e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5bbf3cd8771c2447ab0ec792004a3eb2bb380fb2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 781 processed earlier; will process 10248 files now Step #5: ==25666== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d4669c19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d46d026898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d46d0095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d46d0094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d4669c7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d466928b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d466923355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d4669b9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d469988f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d469988f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d469988f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d469988f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d469988f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d469988f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d469988f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d469988f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d469988f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d469988f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d46bc1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d46894ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d468955be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d468701c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d468701c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d468702738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d468701874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d468701874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d468701874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d46d00babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d46d014928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d46cffc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d46d027112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6af16f5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d466921b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x30,0xa,0x30,0xa,0x2d, Step #5: -0\0120\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-5a28057cf4cfa8e48c1e3f19cdb906310dc17c53 Step #5: Base64: LTAKMAot Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 713 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2102838349 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cace18d810, 0x55cace37701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cace377020,0x55cad020f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5a28057cf4cfa8e48c1e3f19cdb906310dc17c53' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 782 processed earlier; will process 10247 files now Step #5: ==25702== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cac4c829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cacb2e7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cacb2ca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cacb2ca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cac4c88d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cac4be9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cac4be4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cac4c7ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cac7c49f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cac7c49f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cac7c49f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cac7c49f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cac7c49f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cac7c49f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cac7c49f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cac7c49f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cac7c49f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cac7c49f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cac9edef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cac6c0bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cac6c16be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cac69c2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cac69c2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cac69c3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cac69c2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cac69c2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cac69c2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cacb2ccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cacb2d5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cacb2bd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cacb2e8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa8b92fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cac4be2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0xa3,0x5c,0xb8,0x0,0x7f, Step #5: \333\243\\\270\000\177 Step #5: artifact_prefix='./'; Test unit written to ./oom-e42d64b6a6a157cec6334c0207d818af9eb8fec2 Step #5: Base64: 26NcuAB/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 714 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2103263541 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56053677c810, 0x56053696601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560536966020,0x5605387fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e42d64b6a6a157cec6334c0207d818af9eb8fec2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 783 processed earlier; will process 10246 files now Step #5: ==25738== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56052d2719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605338d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605338b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605338b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56052d277d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56052d1d8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56052d1d3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56052d269c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560530238f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560530238f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560530238f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560530238f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560530238f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560530238f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560530238f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560530238f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560530238f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560530238f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605324cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56052f1fab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56052f205be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56052efb1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56052efb1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56052efb2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56052efb1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56052efb1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56052efb1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605338bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5605338c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605338ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605338d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f383c966082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56052d1d1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x59,0x0,0xe,0x27,0x24, Step #5: $Y\000\016'$ Step #5: artifact_prefix='./'; Test unit written to ./oom-01906c42ca07039b577fc9a8d18684696d4af6f5 Step #5: Base64: JFkADick Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 715 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2103690228 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56142f451810, 0x56142f63b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56142f63b020,0x5614314d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01906c42ca07039b577fc9a8d18684696d4af6f5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 784 processed earlier; will process 10245 files now Step #5: ==25774== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561425f469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56142c5ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56142c58e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56142c58e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561425f4cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561425eadb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561425ea8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561425f3ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561428f0df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561428f0df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561428f0df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561428f0df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561428f0df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561428f0df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561428f0df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561428f0df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561428f0df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561428f0df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56142b1a2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561427ecfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561427edabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561427c86c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561427c86c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561427c87738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561427c86874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561427c86874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561427c86874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56142c590abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56142c599928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56142c581699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56142c5ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc53d85e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561425ea6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc8,0xac,0xf0,0x9d,0x85,0xaf, Step #5: \310\254\360\235\205\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-11a9bf632d4d5cd3e0156baf93714c4feb3fe55f Step #5: Base64: yKzwnYWv Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 716 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2104116039 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55566d736810, 0x55566d92001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55566d920020,0x55566f7b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/11a9bf632d4d5cd3e0156baf93714c4feb3fe55f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 785 processed earlier; will process 10244 files now Step #5: #1 pulse cov: 3753 ft: 3754 exec/s: 0 rss: 156Mb Step #5: ==25810== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55566422b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55566a890898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55566a8735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55566a8734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555664231d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555664192b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55566418d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555664223c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5556671f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5556671f2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5556671f2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5556671f2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5556671f2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5556671f2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5556671f2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5556671f2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5556671f2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5556671f2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555669487f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5556661b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5556661bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555665f6bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555665f6bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555665f6c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555665f6b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555665f6b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555665f6b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55566a875abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55566a87e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55566a866699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55566a891112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb63def8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55566418bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xde,0xb8,0x7b,0x32,0x37,0x7d, Step #5: \336\270{27} Step #5: artifact_prefix='./'; Test unit written to ./oom-b689c51298dce4bf8718aa478dbb6cea41b17a10 Step #5: Base64: 3rh7Mjd9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 717 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2104583564 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55697001d810, 0x55697020701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556970207020,0x55697209f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b689c51298dce4bf8718aa478dbb6cea41b17a10' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 787 processed earlier; will process 10242 files now Step #5: ==25846== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556966b129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55696d177898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55696d15a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55696d15a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556966b18d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556966a79b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556966a74355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556966b0ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556969ad9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556969ad9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556969ad9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556969ad9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556969ad9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556969ad9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556969ad9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556969ad9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556969ad9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556969ad9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55696bd6ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556968a9bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556968aa6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556968852c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556968852c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556968853738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556968852874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556968852874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556968852874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55696d15cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55696d165928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55696d14d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55696d178112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9c63fdd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556966a72b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0x2d,0x2d,0x62, Step #5: -----b Step #5: artifact_prefix='./'; Test unit written to ./oom-8ac8b49601729060ffe0f48d35fc93900f6a37bd Step #5: Base64: LS0tLS1i Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 718 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2105017617 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b4ac0ee810, 0x55b4ac2d801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b4ac2d8020,0x55b4ae1700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ac8b49601729060ffe0f48d35fc93900f6a37bd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 788 processed earlier; will process 10241 files now Step #5: ==25882== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b4a2be39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b4a9248898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b4a922b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b4a922b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b4a2be9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b4a2b4ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b4a2b45355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b4a2bdbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b4a5baaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b4a5baaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b4a5baaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b4a5baaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b4a5baaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b4a5baaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b4a5baaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b4a5baaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b4a5baaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b4a5baaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b4a7e3ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b4a4b6cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b4a4b77be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b4a4923c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b4a4923c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b4a4924738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b4a4923874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b4a4923874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b4a4923874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b4a922dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b4a9236928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b4a921e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b4a9249112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3073bfd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b4a2b43b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x29,0x7e,0x30,0xd8,0xad, Step #5: 0)~0\330\255 Step #5: artifact_prefix='./'; Test unit written to ./oom-699a9280d3e49d3f9a5bd24fa4238db00571aa92 Step #5: Base64: MCl+MNit Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 719 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2105445660 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5621c3ca6810, 0x5621c3e9001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5621c3e90020,0x5621c5d280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/699a9280d3e49d3f9a5bd24fa4238db00571aa92' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 789 processed earlier; will process 10240 files now Step #5: ==25918== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5621ba79b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5621c0e00898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5621c0de35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5621c0de34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5621ba7a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5621ba702b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5621ba6fd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5621ba793c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5621bd762f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5621bd762f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5621bd762f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5621bd762f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5621bd762f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5621bd762f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5621bd762f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5621bd762f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5621bd762f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5621bd762f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5621bf9f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5621bc724b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5621bc72fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5621bc4dbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5621bc4dbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5621bc4dc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5621bc4db874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5621bc4db874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5621bc4db874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5621c0de5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5621c0dee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5621c0dd6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5621c0e01112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd43c8cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5621ba6fbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0x80,0xf4,0x88,0xb2,0xbb, Step #5: \337\200\364\210\262\273 Step #5: artifact_prefix='./'; Test unit written to ./oom-1c4e6820bdbd6aed0b59ada67c86da33fc117965 Step #5: Base64: 34D0iLK7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 720 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2105867642 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c78c00a810, 0x55c78c1f401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c78c1f4020,0x55c78e08c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c4e6820bdbd6aed0b59ada67c86da33fc117965' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 790 processed earlier; will process 10239 files now Step #5: ==25954== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c782aff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c789164898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7891475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7891474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c782b05d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c782a66b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c782a61355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c782af7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c785ac6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c785ac6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c785ac6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c785ac6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c785ac6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c785ac6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c785ac6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c785ac6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c785ac6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c785ac6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c787d5bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c784a88b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c784a93be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c78483fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c78483fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c784840738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c78483f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c78483f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c78483f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c789149abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c789152928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c78913a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c789165112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f506f138082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c782a5fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x23,0x5b,0x5d,0x2f,0x25, Step #5: /#[]/% Step #5: artifact_prefix='./'; Test unit written to ./oom-7ae752473c6b952c2b9e4f965c2517c25c70b8a6 Step #5: Base64: LyNbXS8l Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 721 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2106286787 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ac1f81810, 0x555ac216b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ac216b020,0x555ac40030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ae752473c6b952c2b9e4f965c2517c25c70b8a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 791 processed earlier; will process 10238 files now Step #5: ==25990== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555ab8a769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555abf0db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555abf0be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555abf0be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ab8a7cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ab89ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ab89d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ab8a6ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555abba3df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555abba3df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555abba3df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555abba3df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555abba3df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555abba3df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555abba3df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555abba3df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555abba3df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555abba3df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555abdcd2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555aba9ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555abaa0abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555aba7b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555aba7b6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555aba7b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555aba7b6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555aba7b6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555aba7b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555abf0c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555abf0c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555abf0b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555abf0dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6be80e8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ab89d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x29,0x5b,0xe1,0x9e,0xbc, Step #5: ()[\341\236\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-2e1c78cc443d205e711886211a46481762b0a960 Step #5: Base64: KClb4Z68 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 722 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2106710521 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562f5ecc0810, 0x562f5eeaa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562f5eeaa020,0x562f60d420e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2e1c78cc443d205e711886211a46481762b0a960' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 792 processed earlier; will process 10237 files now Step #5: ==26026== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562f557b59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562f5be1a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562f5bdfd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562f5bdfd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562f557bbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562f5571cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562f55717355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562f557adc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562f5877cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562f5877cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562f5877cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562f5877cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562f5877cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562f5877cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562f5877cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562f5877cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562f5877cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562f5877cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562f5aa11f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562f5773eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562f57749be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562f574f5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562f574f5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562f574f6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562f574f5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562f574f5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562f574f5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562f5bdffabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562f5be08928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562f5bdf0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562f5be1b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2dbe4e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562f55715b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe0,0xb8,0xb3, Step #5: ws:\340\270\263 Step #5: artifact_prefix='./'; Test unit written to ./oom-43649f7d26e6d0ce0bd15f2b2f2acee15914ed58 Step #5: Base64: d3M64Liz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 723 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2107141565 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5570125f0810, 0x5570127da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5570127da020,0x5570146720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/43649f7d26e6d0ce0bd15f2b2f2acee15914ed58' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 793 processed earlier; will process 10236 files now Step #5: ==26062== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5570090e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55700f74a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55700f72d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55700f72d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5570090ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55700904cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557009047355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5570090ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55700c0acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55700c0acf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55700c0acf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55700c0acf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55700c0acf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55700c0acf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55700c0acf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55700c0acf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55700c0acf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55700c0acf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55700e341f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55700b06eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55700b079be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55700ae25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55700ae25c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55700ae26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55700ae25874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55700ae25874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55700ae25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55700f72fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55700f738928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55700f720699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55700f74b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa57e08e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557009045b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0x24,0x24,0x31,0xde, Step #5: $$$$1\336 Step #5: artifact_prefix='./'; Test unit written to ./oom-9afa3a896487080f74d239f2146986e3c6289709 Step #5: Base64: JCQkJDHe Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 724 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2107570157 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557854700810, 0x5578548ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5578548ea020,0x5578567820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9afa3a896487080f74d239f2146986e3c6289709' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 794 processed earlier; will process 10235 files now Step #5: ==26098== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55784b1f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55785185a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55785183d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55785183d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55784b1fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55784b15cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55784b157355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55784b1edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55784e1bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55784e1bcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55784e1bcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55784e1bcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55784e1bcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55784e1bcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55784e1bcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55784e1bcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55784e1bcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55784e1bcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557850451f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55784d17eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55784d189be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55784cf35c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55784cf35c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55784cf36738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55784cf35874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55784cf35874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55784cf35874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55785183fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557851848928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557851830699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55785185b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a7ed5a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55784b155b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9f,0xbf,0xad,0x7c,0x2f, Step #5: \360\237\277\255|/ Step #5: artifact_prefix='./'; Test unit written to ./oom-46f4ee81d45f52177fbc5c68da2364acccd2c7db Step #5: Base64: 8J+/rXwv Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 725 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2108004305 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e02b7f3810, 0x55e02b9dd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e02b9dd020,0x55e02d8750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/46f4ee81d45f52177fbc5c68da2364acccd2c7db' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 795 processed earlier; will process 10234 files now Step #5: #1 pulse cov: 3677 ft: 3678 exec/s: 0 rss: 157Mb Step #5: ==26134== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e0222e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e02894d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e0289305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e0289304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e0222eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e02224fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e02224a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e0222e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e0252aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e0252aff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e0252aff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e0252aff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e0252aff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e0252aff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e0252aff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e0252aff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e0252aff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e0252aff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e027544f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e024271b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e02427cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e024028c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e024028c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e024029738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e024028874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e024028874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e024028874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e028932abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e02893b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e028923699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e02894e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1879f1d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e022248b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5e,0xa,0x2d,0xdf,0x84, Step #5: [^\012-\337\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-e0b6026330cb787891cb8b2f5c9266f7923f857d Step #5: Base64: W14KLd+E Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 726 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2108473149 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564eb5f56810, 0x564eb614001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564eb6140020,0x564eb7fd80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e0b6026330cb787891cb8b2f5c9266f7923f857d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 797 processed earlier; will process 10232 files now Step #5: ==26170== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564eaca4b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564eb30b0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564eb30935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564eb30934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564eaca51d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564eac9b2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564eac9ad355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564eaca43c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564eafa12f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564eafa12f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564eafa12f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564eafa12f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564eafa12f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564eafa12f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564eafa12f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564eafa12f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564eafa12f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564eafa12f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564eb1ca7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564eae9d4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564eae9dfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564eae78bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564eae78bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564eae78c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564eae78b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564eae78b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564eae78b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564eb3095abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564eb309e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564eb3086699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564eb30b1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff4ef242082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564eac9abb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0x85,0xf4,0x8f,0xb2,0xbb, Step #5: \337\205\364\217\262\273 Step #5: artifact_prefix='./'; Test unit written to ./oom-af0ddf06bc427ebc05366bc0fec1ef91a6e29856 Step #5: Base64: 34X0j7K7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 727 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2108902867 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564cc752a810, 0x564cc771401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564cc7714020,0x564cc95ac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af0ddf06bc427ebc05366bc0fec1ef91a6e29856' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 798 processed earlier; will process 10231 files now Step #5: ==26206== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564cbe01f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564cc4684898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564cc46675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564cc46674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564cbe025d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564cbdf86b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564cbdf81355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564cbe017c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564cc0fe6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564cc0fe6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564cc0fe6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564cc0fe6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564cc0fe6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564cc0fe6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564cc0fe6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564cc0fe6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564cc0fe6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564cc0fe6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564cc327bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564cbffa8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564cbffb3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564cbfd5fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564cbfd5fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564cbfd60738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564cbfd5f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564cbfd5f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564cbfd5f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564cc4669abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564cc4672928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564cc465a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564cc4685112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f89a3563082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564cbdf7fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xb7,0xba,0x24,0x6d,0x24, Step #5: \357\267\272$m$ Step #5: artifact_prefix='./'; Test unit written to ./oom-027e6a70eeb14cd662e018a3d6fd40af9c2e501d Step #5: Base64: 77e6JG0k Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 728 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2109327557 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d9fa78810, 0x556d9fc6201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d9fc62020,0x556da1afa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/027e6a70eeb14cd662e018a3d6fd40af9c2e501d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 799 processed earlier; will process 10230 files now Step #5: ==26242== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556d9656d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d9cbd2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d9cbb55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d9cbb54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d96573d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d964d4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d964cf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d96565c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d99534f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d99534f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d99534f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d99534f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d99534f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d99534f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d99534f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d99534f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d99534f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d99534f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d9b7c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d984f6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d98501be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d982adc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d982adc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d982ae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d982ad874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d982ad874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d982ad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d9cbb7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d9cbc0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d9cba8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d9cbd3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f94010e7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d964cdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x1f,0x7f,0x0,0x0,0x0, Step #5: =\037\177\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0473e09c7eba101939ac2b0df69fc1f5b9f792f2 Step #5: Base64: PR9/AAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 729 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2109752457 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c7ee5da810, 0x55c7ee7c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c7ee7c4020,0x55c7f065c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0473e09c7eba101939ac2b0df69fc1f5b9f792f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 800 processed earlier; will process 10229 files now Step #5: ==26278== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c7e50cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7eb734898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7eb7175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7eb7174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c7e50d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c7e5036b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c7e5031355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7e50c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7e8096f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7e8096f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7e8096f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7e8096f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7e8096f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7e8096f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7e8096f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7e8096f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7e8096f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7e8096f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7ea32bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7e7058b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7e7063be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7e6e0fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7e6e0fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7e6e10738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7e6e0f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7e6e0f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7e6e0f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7eb719abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7eb722928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c7eb70a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7eb735112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6143cdf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c7e502fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x5c,0x22,0xef,0xb8,0xa2, Step #5: \"\\\"\357\270\242 Step #5: artifact_prefix='./'; Test unit written to ./oom-2eaf672c99e535e0e28fee08367acc2a86c683e0 Step #5: Base64: Ilwi77ii Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 730 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2110175390 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5582f176d810, 0x5582f195701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5582f1957020,0x5582f37ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2eaf672c99e535e0e28fee08367acc2a86c683e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 801 processed earlier; will process 10228 files now Step #5: ==26314== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5582e82629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5582ee8c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5582ee8aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5582ee8aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5582e8268d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5582e81c9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5582e81c4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5582e825ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5582eb229f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5582eb229f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5582eb229f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5582eb229f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5582eb229f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5582eb229f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5582eb229f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5582eb229f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5582eb229f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5582eb229f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5582ed4bef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5582ea1ebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5582ea1f6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5582e9fa2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5582e9fa2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5582e9fa3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5582e9fa2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5582e9fa2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5582e9fa2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5582ee8acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5582ee8b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5582ee89d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5582ee8c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f73d2136082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5582e81c2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7a,0x60,0x3b,0x7a,0x60,0x3b, Step #5: z`;z`; Step #5: artifact_prefix='./'; Test unit written to ./oom-d88ff2008fd6fd2218ee781452b1cabc42ba884f Step #5: Base64: emA7emA7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 731 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2110718430 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f278dca810, 0x55f278fb401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f278fb4020,0x55f27ae4c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d88ff2008fd6fd2218ee781452b1cabc42ba884f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 802 processed earlier; will process 10227 files now Step #5: #1 pulse cov: 3625 ft: 3626 exec/s: 0 rss: 159Mb Step #5: ==26350== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f26f8bf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f275f24898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f275f075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f275f074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f26f8c5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f26f826b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f26f821355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f26f8b7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f272886f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f272886f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f272886f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f272886f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f272886f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f272886f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f272886f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f272886f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f272886f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f272886f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f274b1bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f271848b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f271853be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f2715ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f2715ffc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f271600738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f2715ff874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f2715ff874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f2715ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f275f09abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f275f12928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f275efa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f275f25112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb2af5df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f26f81fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x4,0xcc,0xa5,0xca,0xb2, Step #5: r\004\314\245\312\262 Step #5: artifact_prefix='./'; Test unit written to ./oom-26fc48572f621bc84672b0ba26d0a22b24a4f9c6 Step #5: Base64: cgTMpcqy Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 732 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2111182590 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a326d6d810, 0x55a326f5701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a326f57020,0x55a328def0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/26fc48572f621bc84672b0ba26d0a22b24a4f9c6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 804 processed earlier; will process 10225 files now Step #5: ==26386== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a31d8629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a323ec7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a323eaa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a323eaa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a31d868d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a31d7c9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a31d7c4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a31d85ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a320829f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a320829f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a320829f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a320829f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a320829f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a320829f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a320829f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a320829f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a320829f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a320829f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a322abef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a31f7ebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a31f7f6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a31f5a2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a31f5a2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a31f5a3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a31f5a2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a31f5a2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a31f5a2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a323eacabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a323eb5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a323e9d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a323ec8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f557b418082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a31d7c2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x65,0x67,0x72,0x61,0x6c, Step #5: tegral Step #5: artifact_prefix='./'; Test unit written to ./oom-99326e372bcd44d8fbb0d14a1319dbcfa837cf1b Step #5: Base64: dGVncmFs Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 733 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2111608892 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5631a6003810, 0x5631a61ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5631a61ed020,0x5631a80850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/99326e372bcd44d8fbb0d14a1319dbcfa837cf1b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 805 processed earlier; will process 10224 files now Step #5: ==26422== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56319caf89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5631a315d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5631a31405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5631a31404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56319cafed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56319ca5fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56319ca5a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56319caf0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56319fabff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56319fabff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56319fabff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56319fabff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56319fabff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56319fabff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56319fabff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56319fabff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56319fabff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56319fabff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5631a1d54f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56319ea81b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56319ea8cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56319e838c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56319e838c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56319e839738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56319e838874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56319e838874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56319e838874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5631a3142abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5631a314b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5631a3133699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5631a315e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9cfaeb6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56319ca58b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x41,0x6,0x38,0x7d,0x0, Step #5: \002A\0068}\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-af0c3e26de386736b4908e7631eaa65b3196748b Step #5: Base64: AkEGOH0A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 734 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2112034485 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d8405e3810, 0x55d8407cd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d8407cd020,0x55d8426650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af0c3e26de386736b4908e7631eaa65b3196748b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 806 processed earlier; will process 10223 files now Step #5: ==26458== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d8370d89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d83d73d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d83d7205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d83d7204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d8370ded42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d83703fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d83703a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d8370d0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d83a09ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d83a09ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d83a09ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d83a09ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d83a09ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d83a09ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d83a09ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d83a09ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d83a09ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d83a09ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d83c334f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d839061b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d83906cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d838e18c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d838e18c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d838e19738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d838e18874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d838e18874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d838e18874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d83d722abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d83d72b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d83d713699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d83d73e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe976dec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d837038b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6d,0x61,0x78,0x70,0x4d,0x26, Step #5: maxpM& Step #5: artifact_prefix='./'; Test unit written to ./oom-23904fff86e067bd728b16b259f6377704943b68 Step #5: Base64: bWF4cE0m Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 735 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2112457635 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56060f3c3810, 0x56060f5ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56060f5ad020,0x5606114450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/23904fff86e067bd728b16b259f6377704943b68' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 807 processed earlier; will process 10222 files now Step #5: ==26494== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560605eb89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56060c51d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56060c5005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56060c5004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560605ebed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560605e1fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560605e1a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560605eb0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560608e7ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560608e7ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560608e7ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560608e7ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560608e7ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560608e7ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560608e7ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560608e7ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560608e7ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560608e7ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56060b114f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560607e41b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560607e4cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560607bf8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560607bf8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560607bf9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560607bf8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560607bf8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560607bf8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56060c502abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56060c50b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56060c4f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56060c51e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efd703da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560605e18b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x0,0x2b,0xcf,0xa3,0x2, Step #5: =\000+\317\243\002 Step #5: artifact_prefix='./'; Test unit written to ./oom-d9db1a119a422ed45df13bdd54c18257d731bf43 Step #5: Base64: PQArz6MC Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 736 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2112881648 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f67aec1810, 0x55f67b0ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f67b0ab020,0x55f67cf430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d9db1a119a422ed45df13bdd54c18257d731bf43' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 808 processed earlier; will process 10221 files now Step #5: ==26530== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f6719b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f67801b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f677ffe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f677ffe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f6719bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f67191db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f671918355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f6719aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f67497df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f67497df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f67497df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f67497df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f67497df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f67497df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f67497df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f67497df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f67497df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f67497df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f676c12f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f67393fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f67394abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f6736f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f6736f6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f6736f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f6736f6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f6736f6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f6736f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f678000abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f678009928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f677ff1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f67801c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa74a04c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f671916b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xe1,0xb1,0xbf,0x2f,0x3e, Step #5: <\341\261\277/> Step #5: artifact_prefix='./'; Test unit written to ./oom-5da5bf6440996260c5bdf16ba4658e9ecf508a67 Step #5: Base64: POGxvy8+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 737 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2113309418 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bafeb70810, 0x55bafed5a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bafed5a020,0x55bb00bf20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5da5bf6440996260c5bdf16ba4658e9ecf508a67' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 809 processed earlier; will process 10220 files now Step #5: #1 pulse cov: 3565 ft: 3566 exec/s: 0 rss: 159Mb Step #5: ==26566== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55baf56659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bafbcca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bafbcad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bafbcad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55baf566bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55baf55ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55baf55c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55baf565dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55baf862cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55baf862cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55baf862cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55baf862cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55baf862cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55baf862cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55baf862cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55baf862cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55baf862cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55baf862cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bafa8c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55baf75eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55baf75f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55baf73a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55baf73a5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55baf73a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55baf73a5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55baf73a5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55baf73a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bafbcafabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bafbcb8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bafbca0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bafbccb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff39ec35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55baf55c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x0,0x3,0x0,0x3,0x0, Step #5: \003\000\003\000\003\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-da756656b84274eb72d03e97bcc7145930c3b27f Step #5: Base64: AwADAAMA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 738 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2113771552 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c32248e810, 0x55c32267801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c322678020,0x55c3245100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/da756656b84274eb72d03e97bcc7145930c3b27f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 811 processed earlier; will process 10218 files now Step #5: ==26602== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c318f839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c31f5e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c31f5cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c31f5cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c318f89d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c318eeab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c318ee5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c318f7bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c31bf4af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c31bf4af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c31bf4af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c31bf4af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c31bf4af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c31bf4af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c31bf4af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c31bf4af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c31bf4af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c31bf4af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c31e1dff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c31af0cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c31af17be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c31acc3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c31acc3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c31acc4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c31acc3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c31acc3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c31acc3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c31f5cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c31f5d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c31f5be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c31f5e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4d47e8e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c318ee3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53,0xa,0xe2,0x81,0x9f,0xf2, Step #5: S\012\342\201\237\362 Step #5: artifact_prefix='./'; Test unit written to ./oom-39cd1ee5aaef3ddc523154b8440bca5995def8e0 Step #5: Base64: UwrigZ/y Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 739 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2114199956 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56330a928810, 0x56330ab1201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56330ab12020,0x56330c9aa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/39cd1ee5aaef3ddc523154b8440bca5995def8e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 812 processed earlier; will process 10217 files now Step #5: ==26638== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56330141d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563307a82898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563307a655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563307a654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563301423d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563301384b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56330137f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563301415c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5633043e4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5633043e4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5633043e4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5633043e4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5633043e4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5633043e4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5633043e4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5633043e4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5633043e4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5633043e4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563306679f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5633033a6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5633033b1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56330315dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56330315dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56330315e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56330315d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56330315d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56330315d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563307a67abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563307a70928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563307a58699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563307a83112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8648eca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56330137db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0xda,0xb4,0x57,0xda,0xb4, Step #5: /\332\264W\332\264 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb5dfd064308833584dd8e33c8031aa168125aa0 Step #5: Base64: L9q0V9q0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 740 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2114627595 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5629703c5810, 0x5629705af01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5629705af020,0x5629724470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb5dfd064308833584dd8e33c8031aa168125aa0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 813 processed earlier; will process 10216 files now Step #5: ==26674== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562966eba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56296d51f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56296d5025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56296d5024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562966ec0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562966e21b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562966e1c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562966eb2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562969e81f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562969e81f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562969e81f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562969e81f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562969e81f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562969e81f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562969e81f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562969e81f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562969e81f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562969e81f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56296c116f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562968e43b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562968e4ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562968bfac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562968bfac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562968bfb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562968bfa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562968bfa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562968bfa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56296d504abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56296d50d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56296d4f5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56296d520112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f29cb374082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562966e1ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0x66,0x61,0x61,0x61,0x61, Step #5: ifaaaa Step #5: artifact_prefix='./'; Test unit written to ./oom-71b30e66423559ccfbcde22b661ea16c5f39eecf Step #5: Base64: aWZhYWFh Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 741 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2115059271 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b1a581c810, 0x55b1a5a0601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b1a5a06020,0x55b1a789e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/71b30e66423559ccfbcde22b661ea16c5f39eecf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 814 processed earlier; will process 10215 files now Step #5: ==26710== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b19c3119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b1a2976898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1a29595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1a29594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b19c317d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b19c278b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b19c273355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b19c309c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b19f2d8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b19f2d8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b19f2d8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b19f2d8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b19f2d8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b19f2d8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b19f2d8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b19f2d8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b19f2d8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b19f2d8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b1a156df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b19e29ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b19e2a5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b19e051c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b19e051c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b19e052738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b19e051874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b19e051874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b19e051874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b1a295babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b1a2964928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b1a294c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b1a2977112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff3ee57d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b19c271b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x3c,0x5c,0x3c,0x5c,0x3c, Step #5: \\<\\<\\< Step #5: artifact_prefix='./'; Test unit written to ./oom-64d0882e5f557f5c28a1db87fabda3e6a1cfb9b9 Step #5: Base64: XDxcPFw8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 742 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2115489000 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cd65189810, 0x55cd6537301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cd65373020,0x55cd6720b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/64d0882e5f557f5c28a1db87fabda3e6a1cfb9b9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 815 processed earlier; will process 10214 files now Step #5: ==26746== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cd5bc7e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cd622e3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cd622c65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cd622c64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cd5bc84d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cd5bbe5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cd5bbe0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cd5bc76c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cd5ec45f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cd5ec45f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cd5ec45f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cd5ec45f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cd5ec45f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cd5ec45f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cd5ec45f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cd5ec45f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cd5ec45f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cd5ec45f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cd60edaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cd5dc07b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cd5dc12be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cd5d9bec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cd5d9bec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cd5d9bf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cd5d9be874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cd5d9be874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cd5d9be874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cd622c8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cd622d1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cd622b9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cd622e4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff2029fb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cd5bbdeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x6d,0x29,0x24,0x24, Step #5: (?m)$$ Step #5: artifact_prefix='./'; Test unit written to ./oom-c49ff8ec2535a3cd13cedab6d8d272760638d777 Step #5: Base64: KD9tKSQk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 743 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2115918623 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5560e1ac8810, 0x5560e1cb201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5560e1cb2020,0x5560e3b4a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c49ff8ec2535a3cd13cedab6d8d272760638d777' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 816 processed earlier; will process 10213 files now Step #5: ==26782== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5560d85bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5560dec22898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5560dec055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5560dec054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5560d85c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5560d8524b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5560d851f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5560d85b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5560db584f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5560db584f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5560db584f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5560db584f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5560db584f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5560db584f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5560db584f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5560db584f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5560db584f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5560db584f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5560dd819f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5560da546b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5560da551be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5560da2fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5560da2fdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5560da2fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5560da2fd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5560da2fd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5560da2fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5560dec07abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5560dec10928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5560debf8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5560dec23112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b2e4fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5560d851db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x0,0x58,0x76,0x0,0x57, Step #5: A\000Xv\000W Step #5: artifact_prefix='./'; Test unit written to ./oom-ceff1cf6683756ad117ae6a6bb05143edf4ec9c2 Step #5: Base64: QQBYdgBX Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 744 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2116339492 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d69edd810, 0x561d6a0c701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d6a0c7020,0x561d6bf5f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ceff1cf6683756ad117ae6a6bb05143edf4ec9c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 817 processed earlier; will process 10212 files now Step #5: ==26818== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561d609d29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d67037898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d6701a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d6701a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d609d8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d60939b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d60934355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d609cac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d63999f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d63999f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d63999f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d63999f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d63999f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d63999f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d63999f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d63999f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d63999f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d63999f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d65c2ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d6295bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d62966be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d62712c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d62712c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d62713738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d62712874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d62712874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d62712874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d6701cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d67025928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d6700d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d67038112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f029cdbc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d60932b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x54,0x54,0x3d,0x22,0x22, Step #5: ATT=\"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-738913021986de702baa44c6e8ad7e426bcbf9cf Step #5: Base64: QVRUPSIi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 745 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2116762037 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564456a1a810, 0x564456c0401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564456c04020,0x564458a9c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/738913021986de702baa44c6e8ad7e426bcbf9cf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 818 processed earlier; will process 10211 files now Step #5: ==26854== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56444d50f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564453b74898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564453b575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564453b574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56444d515d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56444d476b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56444d471355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56444d507c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5644504d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5644504d6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5644504d6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5644504d6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5644504d6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5644504d6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5644504d6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5644504d6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5644504d6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5644504d6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56445276bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56444f498b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56444f4a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56444f24fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56444f24fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56444f250738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56444f24f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56444f24f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56444f24f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564453b59abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564453b62928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564453b4a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564453b75112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f706f6f8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56444d46fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x3c,0x0,0x50,0x0,0x6c, Step #5: \000<\000P\000l Step #5: artifact_prefix='./'; Test unit written to ./oom-e864b4183704f4c12f3f30100aee48f2349aec14 Step #5: Base64: ADwAUABs Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 746 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2117183893 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b6c1482810, 0x55b6c166c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b6c166c020,0x55b6c35040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e864b4183704f4c12f3f30100aee48f2349aec14' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 819 processed earlier; will process 10210 files now Step #5: ==26890== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b6b7f779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b6be5dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b6be5bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b6be5bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6b7f7dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6b7edeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6b7ed9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6b7f6fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b6baf3ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b6baf3ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b6baf3ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b6baf3ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b6baf3ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b6baf3ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b6baf3ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b6baf3ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b6baf3ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b6baf3ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b6bd1d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6b9f00b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6b9f0bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6b9cb7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6b9cb7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6b9cb8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6b9cb7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6b9cb7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6b9cb7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b6be5c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b6be5ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b6be5b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b6be5dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f55bd6cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6b7ed7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x65,0x2d,0x65,0x6e,0x2d, Step #5: -e-en- Step #5: artifact_prefix='./'; Test unit written to ./oom-a8baca399ae3851d28a73d87a838ae5cd9ef15da Step #5: Base64: LWUtZW4t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 747 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2117613572 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558ff7f9f810, 0x558ff818901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558ff8189020,0x558ffa0210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a8baca399ae3851d28a73d87a838ae5cd9ef15da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 820 processed earlier; will process 10209 files now Step #5: #1 pulse cov: 3382 ft: 3383 exec/s: 0 rss: 157Mb Step #5: ==26926== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558feea949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558ff50f9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558ff50dc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558ff50dc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558feea9ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558fee9fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558fee9f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558feea8cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558ff1a5bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558ff1a5bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558ff1a5bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558ff1a5bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558ff1a5bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558ff1a5bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558ff1a5bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558ff1a5bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558ff1a5bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558ff1a5bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558ff3cf0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ff0a1db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ff0a28be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ff07d4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ff07d4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ff07d5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ff07d4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ff07d4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ff07d4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558ff50deabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558ff50e7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558ff50cf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558ff50fa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe227e80082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558fee9f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x68,0xa,0x2d,0xa,0x2d, Step #5: Ph\012-\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-f647870a09b1a434215a334023e489ce844d8207 Step #5: Base64: UGgKLQot Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 748 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2118085056 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ef81ff5810, 0x55ef821df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ef821df020,0x55ef840770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f647870a09b1a434215a334023e489ce844d8207' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 822 processed earlier; will process 10207 files now Step #5: ==26962== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ef78aea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ef7f14f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ef7f1325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ef7f1324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef78af0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef78a51b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef78a4c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef78ae2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef7bab1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef7bab1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef7bab1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef7bab1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef7bab1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef7bab1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef7bab1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef7bab1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef7bab1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef7bab1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef7dd46f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef7aa73b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef7aa7ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef7a82ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef7a82ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef7a82b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef7a82a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef7a82a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef7a82a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ef7f134abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ef7f13d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ef7f125699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ef7f150112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3be39a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef78a4ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x63,0x24,0x24,0x24,0x25, Step #5: $c$$$% Step #5: artifact_prefix='./'; Test unit written to ./oom-c05901df301d8bf88c3cdb03028d26ffa2fe9d01 Step #5: Base64: JGMkJCQl Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 749 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2118517333 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564f0d7da810, 0x564f0d9c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564f0d9c4020,0x564f0f85c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c05901df301d8bf88c3cdb03028d26ffa2fe9d01' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 823 processed earlier; will process 10206 files now Step #5: ==26998== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564f042cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f0a934898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f0a9175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f0a9174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f042d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f04236b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f04231355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f042c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f07296f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f07296f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f07296f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f07296f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f07296f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f07296f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f07296f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f07296f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f07296f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f07296f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f0952bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f06258b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f06263be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f0600fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f0600fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f06010738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f0600f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f0600f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f0600f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f0a919abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f0a922928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f0a90a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f0a935112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f689c717082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f0422fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0xbf,0x9f,0xb5,0x7c,0x2e, Step #5: \360\277\237\265|. Step #5: artifact_prefix='./'; Test unit written to ./oom-1c146102c694aaf679dfbf41a25d0842912dab4d Step #5: Base64: 8L+ftXwu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 750 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2118942292 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5645f95f4810, 0x5645f97de01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5645f97de020,0x5645fb6760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c146102c694aaf679dfbf41a25d0842912dab4d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 824 processed earlier; will process 10205 files now Step #5: ==27034== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5645f00e99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5645f674e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5645f67315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5645f67314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5645f00efd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5645f0050b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5645f004b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5645f00e1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5645f30b0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5645f30b0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5645f30b0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5645f30b0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5645f30b0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5645f30b0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5645f30b0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5645f30b0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5645f30b0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5645f30b0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5645f5345f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5645f2072b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5645f207dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5645f1e29c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5645f1e29c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5645f1e2a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5645f1e29874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5645f1e29874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5645f1e29874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5645f6733abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5645f673c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5645f6724699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5645f674f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb6ed5a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5645f0049b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcc,0x95,0xf0,0x94,0xc2,0x37, Step #5: \314\225\360\224\3027 Step #5: artifact_prefix='./'; Test unit written to ./oom-c64e9dd40818c2f23356641f064c9f9548a44535 Step #5: Base64: zJXwlMI3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 751 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2119369101 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571d4b87810, 0x5571d4d7101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571d4d71020,0x5571d6c090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c64e9dd40818c2f23356641f064c9f9548a44535' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 825 processed earlier; will process 10204 files now Step #5: ==27070== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5571cb67c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571d1ce1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571d1cc45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571d1cc44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571cb682d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571cb5e3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571cb5de355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571cb674c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571ce643f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571ce643f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571ce643f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571ce643f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571ce643f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571ce643f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571ce643f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571ce643f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571ce643f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571ce643f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571d08d8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571cd605b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571cd610be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571cd3bcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571cd3bcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571cd3bd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571cd3bc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571cd3bc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571cd3bc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571d1cc6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571d1ccf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571d1cb7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571d1ce2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1bd02a3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571cb5dcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x1d,0x66,0x66,0x66,0x71, Step #5: f\035fffq Step #5: artifact_prefix='./'; Test unit written to ./oom-c913a321a458fe278c9c209eac83ad97e80a5122 Step #5: Base64: Zh1mZmZx Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 752 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2119796708 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571a9023810, 0x5571a920d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571a920d020,0x5571ab0a50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c913a321a458fe278c9c209eac83ad97e80a5122' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 826 processed earlier; will process 10203 files now Step #5: ==27106== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55719fb189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571a617d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571a61605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571a61604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55719fb1ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55719fa7fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55719fa7a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55719fb10c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571a2adff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571a2adff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571a2adff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571a2adff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571a2adff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571a2adff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571a2adff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571a2adff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571a2adff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571a2adff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571a4d74f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571a1aa1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571a1aacbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571a1858c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571a1858c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571a1859738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571a1858874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571a1858874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571a1858874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571a6162abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571a616b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571a6153699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571a617e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc96b8da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55719fa78b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x27,0x21,0x31,0x24,0x36, Step #5: $'!1$6 Step #5: artifact_prefix='./'; Test unit written to ./oom-477e110f0ab17cc5149520ebb3c78c7481cd9d11 Step #5: Base64: JCchMSQ2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 753 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2120222579 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5644c4dd3810, 0x5644c4fbd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5644c4fbd020,0x5644c6e550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/477e110f0ab17cc5149520ebb3c78c7481cd9d11' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 827 processed earlier; will process 10202 files now Step #5: ==27142== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5644bb8c89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5644c1f2d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5644c1f105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5644c1f104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5644bb8ced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5644bb82fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5644bb82a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5644bb8c0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5644be88ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5644be88ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5644be88ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5644be88ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5644be88ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5644be88ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5644be88ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5644be88ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5644be88ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5644be88ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5644c0b24f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5644bd851b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5644bd85cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5644bd608c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5644bd608c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5644bd609738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5644bd608874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5644bd608874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5644bd608874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5644c1f12abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5644c1f1b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5644c1f03699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5644c1f2e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f376ebd0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5644bb828b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33,0x32,0x30,0x36,0x36,0x31, Step #5: 320661 Step #5: artifact_prefix='./'; Test unit written to ./oom-83d610cbf331f976d761ba69bbdbe811447de152 Step #5: Base64: MzIwNjYx Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 754 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2120644106 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d375c09810, 0x55d375df301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d375df3020,0x55d377c8b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/83d610cbf331f976d761ba69bbdbe811447de152' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 828 processed earlier; will process 10201 files now Step #5: ==27178== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d36c6fe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d372d63898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d372d465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d372d464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d36c704d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d36c665b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d36c660355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d36c6f6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d36f6c5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d36f6c5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d36f6c5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d36f6c5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d36f6c5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d36f6c5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d36f6c5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d36f6c5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d36f6c5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d36f6c5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d37195af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d36e687b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d36e692be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d36e43ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d36e43ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d36e43f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d36e43e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d36e43e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d36e43e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d372d48abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d372d51928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d372d39699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d372d64112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9bb36e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d36c65eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0x66,0xe2,0x81,0xa6,0x5b, Step #5: if\342\201\246[ Step #5: artifact_prefix='./'; Test unit written to ./oom-eab00202beeb9a370c7fb8cfb0bdaaeba5f5de8f Step #5: Base64: aWbigaZb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 755 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2121067776 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e95789810, 0x562e9597301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e95973020,0x562e9780b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eab00202beeb9a370c7fb8cfb0bdaaeba5f5de8f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 829 processed earlier; will process 10200 files now Step #5: ==27214== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562e8c27e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e928e3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e928c65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e928c64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e8c284d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e8c1e5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e8c1e0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e8c276c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e8f245f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e8f245f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e8f245f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e8f245f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e8f245f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e8f245f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e8f245f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e8f245f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e8f245f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e8f245f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e914daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e8e207b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e8e212be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e8dfbec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e8dfbec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e8dfbf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e8dfbe874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e8dfbe874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e8dfbe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e928c8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e928d1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e928b9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e928e4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa05dafd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e8c1deb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x3f,0x47,0x3a,0x21,0x34, Step #5: F?G:!4 Step #5: artifact_prefix='./'; Test unit written to ./oom-52c2d8cc19dc8e6b9c993ed191357c5ed4873120 Step #5: Base64: Rj9HOiE0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 756 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2121504387 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b2b905810, 0x561b2baef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b2baef020,0x561b2d9870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/52c2d8cc19dc8e6b9c993ed191357c5ed4873120' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 830 processed earlier; will process 10199 files now Step #5: #1 pulse cov: 3457 ft: 3458 exec/s: 0 rss: 159Mb Step #5: ==27250== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561b223fa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b28a5f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b28a425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b28a424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b22400d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b22361b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b2235c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b223f2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b253c1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b253c1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b253c1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b253c1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b253c1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b253c1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b253c1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b253c1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b253c1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b253c1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b27656f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b24383b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b2438ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b2413ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b2413ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b2413b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b2413a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b2413a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b2413a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b28a44abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b28a4d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b28a35699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b28a60112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe8313b0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b2235ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x29,0xf0,0x90,0x80,0x82, Step #5: |)\360\220\200\202 Step #5: artifact_prefix='./'; Test unit written to ./oom-d41a628c9704416bd687ae8c96f924dc502426fb Step #5: Base64: fCnwkICC Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 757 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2121983741 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5604c1e4a810, 0x5604c203401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604c2034020,0x5604c3ecc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d41a628c9704416bd687ae8c96f924dc502426fb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 832 processed earlier; will process 10197 files now Step #5: ==27286== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5604b893f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5604befa4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5604bef875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5604bef874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5604b8945d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5604b88a6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5604b88a1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5604b8937c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5604bb906f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5604bb906f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5604bb906f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5604bb906f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5604bb906f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5604bb906f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5604bb906f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5604bb906f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5604bb906f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5604bb906f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5604bdb9bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5604ba8c8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5604ba8d3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5604ba67fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5604ba67fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5604ba680738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5604ba67f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5604ba67f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5604ba67f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5604bef89abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5604bef92928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5604bef7a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5604befa5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0fdde69082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5604b889fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x60,0xa,0x60,0xbb,0xf5, Step #5: =`\012`\273\365 Step #5: artifact_prefix='./'; Test unit written to ./oom-aba7ee58ac9ae5eaeee6978a3c529bedf492b120 Step #5: Base64: PWAKYLv1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 758 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2122526961 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0e81af810, 0x55b0e839901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b0e8399020,0x55b0ea2310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aba7ee58ac9ae5eaeee6978a3c529bedf492b120' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 833 processed earlier; will process 10196 files now Step #5: #1 pulse cov: 3568 ft: 3569 exec/s: 0 rss: 159Mb Step #5: ==27322== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b0deca49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b0e5309898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b0e52ec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b0e52ec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0decaad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0dec0bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0dec06355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0dec9cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b0e1c6bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b0e1c6bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b0e1c6bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b0e1c6bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b0e1c6bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b0e1c6bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b0e1c6bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b0e1c6bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b0e1c6bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b0e1c6bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b0e3f00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b0e0c2db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b0e0c38be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b0e09e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b0e09e4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b0e09e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b0e09e4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b0e09e4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b0e09e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b0e52eeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b0e52f7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b0e52df699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b0e530a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f402b339082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0dec04b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbf,0xbd,0xef,0xbf,0xbd, Step #5: \357\277\275\357\277\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-8750ec9ddfe293cd1dc39b4245c21c270f8f52b7 Step #5: Base64: 77+977+9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 759 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2122994886 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ae731b8810, 0x55ae733a201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ae733a2020,0x55ae7523a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8750ec9ddfe293cd1dc39b4245c21c270f8f52b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 835 processed earlier; will process 10194 files now Step #5: ==27358== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ae69cad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ae70312898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ae702f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ae702f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ae69cb3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ae69c14b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ae69c0f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ae69ca5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ae6cc74f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ae6cc74f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ae6cc74f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ae6cc74f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ae6cc74f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ae6cc74f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ae6cc74f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ae6cc74f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ae6cc74f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ae6cc74f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ae6ef09f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ae6bc36b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ae6bc41be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ae6b9edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ae6b9edc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ae6b9ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ae6b9ed874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ae6b9ed874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ae6b9ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ae702f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ae70300928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ae702e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ae70313112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f577b7be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ae69c0db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x1f,0x43,0x7c,0x2e,0x2e, Step #5: \001\037C|.. Step #5: artifact_prefix='./'; Test unit written to ./oom-ab56bc052a17eb9c32927b8fb10a026e4cdcc7ef Step #5: Base64: AR9DfC4u Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 760 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2123420976 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3f1d3e810, 0x55a3f1f2801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3f1f28020,0x55a3f3dc00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ab56bc052a17eb9c32927b8fb10a026e4cdcc7ef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 836 processed earlier; will process 10193 files now Step #5: ==27394== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a3e88339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3eee98898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3eee7b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3eee7b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3e8839d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a3e879ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a3e8795355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3e882bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a3eb7faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a3eb7faf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a3eb7faf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a3eb7faf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a3eb7faf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a3eb7faf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a3eb7faf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a3eb7faf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a3eb7faf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a3eb7faf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3eda8ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3ea7bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3ea7c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3ea573c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3ea573c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3ea574738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3ea573874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3ea573874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3ea573874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a3eee7dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a3eee86928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3eee6e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3eee99112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f93cac58082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a3e8793b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x30,0x25,0x21,0xe2,0x31, Step #5: #0%!\3421 Step #5: artifact_prefix='./'; Test unit written to ./oom-4316a4b78128cc16d1dde8456a1fc3583d80f908 Step #5: Base64: IzAlIeIx Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 761 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2123849630 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b6efdbe810, 0x55b6effa801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b6effa8020,0x55b6f1e400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4316a4b78128cc16d1dde8456a1fc3583d80f908' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 837 processed earlier; will process 10192 files now Step #5: #1 pulse cov: 3448 ft: 3449 exec/s: 0 rss: 159Mb Step #5: ==27430== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b6e68b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b6ecf18898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b6ecefb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b6ecefb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6e68b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6e681ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6e6815355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6e68abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b6e987af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b6e987af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b6e987af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b6e987af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b6e987af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b6e987af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b6e987af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b6e987af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b6e987af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b6e987af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b6ebb0ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6e883cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6e8847be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6e85f3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6e85f3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6e85f4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6e85f3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6e85f3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6e85f3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b6ecefdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b6ecf06928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b6eceee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b6ecf19112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f013b94e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6e6813b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x5c,0x75,0x7b,0x42,0x7d, Step #5: '\\u{B} Step #5: artifact_prefix='./'; Test unit written to ./oom-0470f601762207782b08ae4f60bf5ee2b2f5828c Step #5: Base64: J1x1e0J9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 762 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2124313467 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56289d32d810, 0x56289d51701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56289d517020,0x56289f3af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0470f601762207782b08ae4f60bf5ee2b2f5828c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 839 processed earlier; will process 10190 files now Step #5: ==27466== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562893e229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56289a487898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56289a46a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56289a46a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562893e28d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562893d89b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562893d84355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562893e1ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562896de9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562896de9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562896de9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562896de9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562896de9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562896de9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562896de9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562896de9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562896de9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562896de9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56289907ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562895dabb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562895db6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562895b62c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562895b62c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562895b63738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562895b62874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562895b62874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562895b62874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56289a46cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56289a475928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56289a45d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56289a488112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8eb7be0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562893d82b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c,0x49,0x53,0x74,0x65,0x4e, Step #5: lISteN Step #5: artifact_prefix='./'; Test unit written to ./oom-bb8609232ad0c9c91f0ef86dbfe85d8b4c47125e Step #5: Base64: bElTdGVO Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 763 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2124738749 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562b89c79810, 0x562b89e6301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562b89e63020,0x562b8bcfb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bb8609232ad0c9c91f0ef86dbfe85d8b4c47125e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 840 processed earlier; will process 10189 files now Step #5: ==27502== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562b8076e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562b86dd3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562b86db65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562b86db64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b80774d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b806d5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b806d0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b80766c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b83735f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b83735f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b83735f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b83735f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b83735f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b83735f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b83735f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b83735f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b83735f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b83735f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562b859caf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b826f7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b82702be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b824aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b824aec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b824af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b824ae874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b824ae874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b824ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562b86db8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562b86dc1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562b86da9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562b86dd4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0115902082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b806ceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0x5,0xb,0xb,0xb,0xb, Step #5: \013\005\013\013\013\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-e2f39b85aa9714129f53886eae839ba72fc92081 Step #5: Base64: CwULCwsL Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 764 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2125162560 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560cc6eea810, 0x560cc70d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560cc70d4020,0x560cc8f6c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e2f39b85aa9714129f53886eae839ba72fc92081' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 841 processed earlier; will process 10188 files now Step #5: ==27538== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560cbd9df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560cc4044898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560cc40275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560cc40274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560cbd9e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560cbd946b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560cbd941355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560cbd9d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560cc09a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560cc09a6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560cc09a6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560cc09a6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560cc09a6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560cc09a6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560cc09a6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560cc09a6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560cc09a6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560cc09a6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560cc2c3bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560cbf968b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560cbf973be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560cbf71fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560cbf71fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560cbf720738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560cbf71f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560cbf71f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560cbf71f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560cc4029abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560cc4032928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560cc401a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560cc4045112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f578ea55082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560cbd93fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x3a,0xd6,0xba, Step #5: (?i:\326\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-69e46c1ced1fd33551a1f2b8c5a4f0514de6cc3f Step #5: Base64: KD9pOta6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 765 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2125590215 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562260506810, 0x5622606f001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622606f0020,0x5622625880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/69e46c1ced1fd33551a1f2b8c5a4f0514de6cc3f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 842 processed earlier; will process 10187 files now Step #5: ==27574== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562256ffb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56225d660898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56225d6435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56225d6434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562257001d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562256f62b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562256f5d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562256ff3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562259fc2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562259fc2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562259fc2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562259fc2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562259fc2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562259fc2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562259fc2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562259fc2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562259fc2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562259fc2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56225c257f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562258f84b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562258f8fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562258d3bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562258d3bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562258d3c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562258d3b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562258d3b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562258d3b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56225d645abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56225d64e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56225d636699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56225d661112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa71ff99082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562256f5bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x4d,0x4d,0x6e,0x73,0x73, Step #5: rMMnss Step #5: artifact_prefix='./'; Test unit written to ./oom-3d6934fc11e15f15b2fdf05965a4979832dfaae1 Step #5: Base64: ck1NbnNz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 766 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2126009917 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc58f05810, 0x55fc590ef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc590ef020,0x55fc5af870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3d6934fc11e15f15b2fdf05965a4979832dfaae1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 843 processed earlier; will process 10186 files now Step #5: ==27610== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fc4f9fa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc5605f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc560425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc560424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc4fa00d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc4f961b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc4f95c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc4f9f2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc529c1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc529c1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc529c1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc529c1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc529c1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc529c1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc529c1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc529c1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc529c1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc529c1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc54c56f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc51983b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc5198ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc5173ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc5173ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc5173b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc5173a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc5173a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc5173a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc56044abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc5604d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc56035699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc56060112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f79bba98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc4f95ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5e,0xe9,0xbe,0xb6,0x5d, Step #5: [^\351\276\266] Step #5: artifact_prefix='./'; Test unit written to ./oom-1fbaaac64e87015f7e2f7a64df3152e3588d2789 Step #5: Base64: W17pvrZd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 767 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2126434055 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5594a7f8f810, 0x5594a817901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5594a8179020,0x5594aa0110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1fbaaac64e87015f7e2f7a64df3152e3588d2789' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 844 processed earlier; will process 10185 files now Step #5: #1 pulse cov: 3448 ft: 3449 exec/s: 0 rss: 157Mb Step #5: ==27646== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55949ea849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5594a50e9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5594a50cc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5594a50cc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55949ea8ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55949e9ebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55949e9e6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55949ea7cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5594a1a4bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5594a1a4bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5594a1a4bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5594a1a4bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5594a1a4bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5594a1a4bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5594a1a4bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5594a1a4bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5594a1a4bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5594a1a4bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5594a3ce0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5594a0a0db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5594a0a18be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5594a07c4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5594a07c4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5594a07c5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5594a07c4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5594a07c4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5594a07c4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5594a50ceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5594a50d7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5594a50bf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5594a50ea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb19d4f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55949e9e4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x66,0x25,0x66,0x25,0x66, Step #5: %f%f%f Step #5: artifact_prefix='./'; Test unit written to ./oom-a2712e85d74223b8c491a8c885999e2e4e0ffaa5 Step #5: Base64: JWYlZiVm Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 768 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2126905230 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea25640810, 0x55ea2582a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea2582a020,0x55ea276c20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2712e85d74223b8c491a8c885999e2e4e0ffaa5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 846 processed earlier; will process 10183 files now Step #5: ==27682== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ea1c1359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea2279a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea2277d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea2277d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea1c13bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea1c09cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea1c097355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea1c12dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea1f0fcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea1f0fcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea1f0fcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea1f0fcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea1f0fcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea1f0fcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea1f0fcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea1f0fcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea1f0fcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea1f0fcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea21391f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea1e0beb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea1e0c9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea1de75c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea1de75c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea1de76738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea1de75874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea1de75874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea1de75874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea2277fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea22788928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea22770699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea2279b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f521cb0c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea1c095b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x47,0x49,0x46,0x38,0x39,0x9e, Step #5: GIF89\236 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8f7275cca10078e5a6e363b356c91e475eeecb0 Step #5: Base64: R0lGODme Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 769 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2127327530 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56276255d810, 0x56276274701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562762747020,0x5627645df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8f7275cca10078e5a6e363b356c91e475eeecb0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 847 processed earlier; will process 10182 files now Step #5: ==27718== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5627590529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56275f6b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56275f69a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56275f69a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562759058d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562758fb9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562758fb4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56275904ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56275c019f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56275c019f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56275c019f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56275c019f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56275c019f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56275c019f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56275c019f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56275c019f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56275c019f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56275c019f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56275e2aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56275afdbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56275afe6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56275ad92c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56275ad92c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56275ad93738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56275ad92874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56275ad92874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56275ad92874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56275f69cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56275f6a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56275f68d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56275f6b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3f253b6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562758fb2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd7,0xa9,0x1,0x0,0x6,0x74, Step #5: \327\251\001\000\006t Step #5: artifact_prefix='./'; Test unit written to ./oom-1dc8185903783b4d96cf5722743a00eb62e794a7 Step #5: Base64: 16kBAAZ0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 770 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2127752655 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cae07b9810, 0x55cae09a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cae09a3020,0x55cae283b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1dc8185903783b4d96cf5722743a00eb62e794a7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 848 processed earlier; will process 10181 files now Step #5: ==27754== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cad72ae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cadd913898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cadd8f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cadd8f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cad72b4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cad7215b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cad7210355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cad72a6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cada275f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cada275f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cada275f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cada275f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cada275f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cada275f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cada275f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cada275f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cada275f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cada275f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cadc50af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cad9237b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cad9242be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cad8feec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cad8feec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cad8fef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cad8fee874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cad8fee874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cad8fee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cadd8f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cadd901928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cadd8e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cadd914112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f770a4b6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cad720eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x68,0x64,0x6e,0x68,0x64,0x6d, Step #5: hdnhdm Step #5: artifact_prefix='./'; Test unit written to ./oom-e66c1eaa622a48f197270d7c8cbda87c36c4786c Step #5: Base64: aGRuaGRt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 771 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2128174735 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56019c680810, 0x56019c86a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56019c86a020,0x56019e7020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e66c1eaa622a48f197270d7c8cbda87c36c4786c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 849 processed earlier; will process 10180 files now Step #5: ==27790== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5601931759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601997da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601997bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601997bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56019317bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601930dcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601930d7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56019316dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56019613cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56019613cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56019613cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56019613cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56019613cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56019613cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56019613cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56019613cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56019613cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56019613cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5601983d1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601950feb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560195109be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560194eb5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560194eb5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560194eb6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560194eb5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560194eb5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560194eb5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5601997bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5601997c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5601997b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601997db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f987bbcb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601930d5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x79,0x79,0x0,0xa,0x0,0xa, Step #5: yy\000\012\000\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-6802746f5aa30cfd447a183a5104cdb2eb451a62 Step #5: Base64: eXkACgAK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 772 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2128605654 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e882532810, 0x55e88271c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e88271c020,0x55e8845b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6802746f5aa30cfd447a183a5104cdb2eb451a62' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 850 processed earlier; will process 10179 files now Step #5: #1 pulse cov: 10279 ft: 10280 exec/s: 0 rss: 177Mb Step #5: ==27826== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e8790279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e87f68c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e87f66f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e87f66f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e87902dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e878f8eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e878f89355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e87901fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e87bfeef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e87bfeef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e87bfeef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e87bfeef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e87bfeef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e87bfeef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e87bfeef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e87bfeef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e87bfeef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e87bfeef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e87e283f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e87afb0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e87afbbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e87ad67c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e87ad67c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e87ad68738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e87ad67874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e87ad67874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e87ad67874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e87f671abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e87f67a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e87f662699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e87f68d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1fe686f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e878f87b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xaa,0x85,0xe0,0xaa,0x85, Step #5: \340\252\205\340\252\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-7dbdd1420f26a2f157e87fe739e23e70e445b73f Step #5: Base64: 4KqF4KqF Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 773 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2129128235 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9b8f13810, 0x55a9b90fd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a9b90fd020,0x55a9baf950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7dbdd1420f26a2f157e87fe739e23e70e445b73f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 852 processed earlier; will process 10177 files now Step #5: #1 pulse cov: 3660 ft: 3661 exec/s: 0 rss: 159Mb Step #5: ==27862== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a9afa089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a9b606d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9b60505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9b60504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a9afa0ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a9af96fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a9af96a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a9afa00c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9b29cff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9b29cff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9b29cff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9b29cff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9b29cff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9b29cff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9b29cff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9b29cff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9b29cff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9b29cff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a9b4c64f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a9b1991b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a9b199cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a9b1748c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a9b1748c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a9b1749738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a9b1748874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a9b1748874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a9b1748874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a9b6052abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a9b605b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a9b6043699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a9b606e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f319e39b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a9af968b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x9,0x0,0x0,0x0,0x0, Step #5: \001\011\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d851b35d4cdd71c591c7d3bc0ee82afafd5eef8d Step #5: Base64: AQkAAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 774 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2129597579 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560dcfc4b810, 0x560dcfe3501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560dcfe35020,0x560dd1ccd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d851b35d4cdd71c591c7d3bc0ee82afafd5eef8d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 854 processed earlier; will process 10175 files now Step #5: ==27898== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560dc67409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560dccda5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560dccd885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560dccd884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560dc6746d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560dc66a7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560dc66a2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560dc6738c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560dc9707f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560dc9707f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560dc9707f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560dc9707f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560dc9707f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560dc9707f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560dc9707f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560dc9707f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560dc9707f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560dc9707f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560dcb99cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560dc86c9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560dc86d4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560dc8480c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560dc8480c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560dc8481738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560dc8480874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560dc8480874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560dc8480874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560dccd8aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560dccd93928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560dccd7b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560dccda6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f58c4c69082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560dc66a0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5e,0xea,0xbf,0xb6,0x5d, Step #5: [^\352\277\266] Step #5: artifact_prefix='./'; Test unit written to ./oom-7c00c9d5de0502307c7e13fd8cc61e8efd592adb Step #5: Base64: W17qv7Zd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 775 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2130029401 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5624dad0e810, 0x5624daef801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5624daef8020,0x5624dcd900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7c00c9d5de0502307c7e13fd8cc61e8efd592adb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 855 processed earlier; will process 10174 files now Step #5: #1 pulse cov: 10275 ft: 10276 exec/s: 0 rss: 177Mb Step #5: ==27934== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5624d18039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5624d7e68898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5624d7e4b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5624d7e4b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5624d1809d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5624d176ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5624d1765355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5624d17fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5624d47caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5624d47caf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5624d47caf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5624d47caf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5624d47caf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5624d47caf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5624d47caf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5624d47caf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5624d47caf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5624d47caf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5624d6a5ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5624d378cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5624d3797be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5624d3543c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5624d3543c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5624d3544738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5624d3543874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5624d3543874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5624d3543874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5624d7e4dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5624d7e56928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5624d7e3e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5624d7e69112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8242979082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5624d1763b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x2,0xc4,0xb7, Step #5: \000\000\000\002\304\267 Step #5: artifact_prefix='./'; Test unit written to ./oom-a08ff11225a28fecf7a5c8d78da92b5e2c5873a2 Step #5: Base64: AAAAAsS3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 776 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2130513764 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56123c530810, 0x56123c71a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56123c71a020,0x56123e5b20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a08ff11225a28fecf7a5c8d78da92b5e2c5873a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 857 processed earlier; will process 10172 files now Step #5: ==27970== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5612330259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56123968a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56123966d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56123966d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56123302bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561232f8cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561232f87355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56123301dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561235fecf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561235fecf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561235fecf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561235fecf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561235fecf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561235fecf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561235fecf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561235fecf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561235fecf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561235fecf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561238281f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561234faeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561234fb9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561234d65c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561234d65c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561234d66738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561234d65874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561234d65874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561234d65874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56123966fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561239678928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561239660699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56123968b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbfbc013082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561232f85b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0x5b,0x29,0x2d,0x3e,0x5d, Step #5: :[)->] Step #5: artifact_prefix='./'; Test unit written to ./oom-d1da07a8a69debb721f60b4a833e14f84043cc60 Step #5: Base64: OlspLT5d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 777 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2130938931 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ba78001810, 0x55ba781eb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ba781eb020,0x55ba7a0830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d1da07a8a69debb721f60b4a833e14f84043cc60' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 858 processed earlier; will process 10171 files now Step #5: #1 pulse cov: 3694 ft: 3695 exec/s: 0 rss: 160Mb Step #5: ==28006== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ba6eaf69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ba7515b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ba7513e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ba7513e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ba6eafcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ba6ea5db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ba6ea58355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ba6eaeec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ba71abdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ba71abdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ba71abdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ba71abdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ba71abdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ba71abdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ba71abdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ba71abdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ba71abdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ba71abdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ba73d52f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ba70a7fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ba70a8abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ba70836c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ba70836c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ba70837738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ba70836874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ba70836874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ba70836874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ba75140abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ba75149928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ba75131699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ba7515c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f79d25e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ba6ea56b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53,0x3a,0xda,0xb7,0xcc,0xa3, Step #5: S:\332\267\314\243 Step #5: artifact_prefix='./'; Test unit written to ./oom-4c1ae87b458ea9325e328bfb47c74511e5bdadc4 Step #5: Base64: Uzrat8yj Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 778 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2131404797 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5622d3fdf810, 0x5622d41c901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622d41c9020,0x5622d60610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4c1ae87b458ea9325e328bfb47c74511e5bdadc4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 860 processed earlier; will process 10169 files now Step #5: ==28042== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5622caad49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5622d1139898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5622d111c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5622d111c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5622caadad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5622caa3bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5622caa36355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5622caaccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5622cda9bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5622cda9bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5622cda9bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5622cda9bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5622cda9bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5622cda9bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5622cda9bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5622cda9bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5622cda9bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5622cda9bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5622cfd30f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5622cca5db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5622cca68be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5622cc814c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5622cc814c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5622cc815738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5622cc814874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5622cc814874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5622cc814874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5622d111eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5622d1127928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5622d110f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5622d113a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efe61537082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5622caa34b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbd,0xbf,0xef,0xbf,0xbd, Step #5: \357\275\277\357\277\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-5143affd9428c5f25ba72a10d77971d01bb09cf9 Step #5: Base64: 772/77+9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 779 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2131833624 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5604d9849810, 0x5604d9a3301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604d9a33020,0x5604db8cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5143affd9428c5f25ba72a10d77971d01bb09cf9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 861 processed earlier; will process 10168 files now Step #5: ==28078== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5604d033e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5604d69a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5604d69865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5604d69864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5604d0344d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5604d02a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5604d02a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5604d0336c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5604d3305f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5604d3305f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5604d3305f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5604d3305f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5604d3305f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5604d3305f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5604d3305f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5604d3305f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5604d3305f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5604d3305f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5604d559af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5604d22c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5604d22d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5604d207ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5604d207ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5604d207f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5604d207e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5604d207e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5604d207e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5604d6988abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5604d6991928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5604d6979699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5604d69a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa55a04e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5604d029eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x0,0x24,0x0,0x24,0x3d, Step #5: %\000$\000$= Step #5: artifact_prefix='./'; Test unit written to ./oom-b66171dbbe7569cfd672c239874fa7b2d90ab40b Step #5: Base64: JQAkACQ9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 780 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2132258173 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55770f7ae810, 0x55770f99801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55770f998020,0x5577118300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b66171dbbe7569cfd672c239874fa7b2d90ab40b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 862 processed earlier; will process 10167 files now Step #5: ==28114== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5577062a39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55770c908898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55770c8eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55770c8eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5577062a9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55770620ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557706205355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55770629bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55770926af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55770926af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55770926af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55770926af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55770926af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55770926af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55770926af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55770926af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55770926af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55770926af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55770b4fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55770822cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557708237be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557707fe3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557707fe3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557707fe4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557707fe3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557707fe3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557707fe3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55770c8edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55770c8f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55770c8de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55770c909112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff425f8d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557706203b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x2d,0xd,0x2d,0xd,0x2b, Step #5: (-\015-\015+ Step #5: artifact_prefix='./'; Test unit written to ./oom-5ca2d685760018674c353a1d1f523ae55a317b43 Step #5: Base64: KC0NLQ0r Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 781 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2132697449 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555d755ce810, 0x555d757b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555d757b8020,0x555d776500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ca2d685760018674c353a1d1f523ae55a317b43' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 863 processed earlier; will process 10166 files now Step #5: ==28150== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555d6c0c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555d72728898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555d7270b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555d7270b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555d6c0c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555d6c02ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555d6c025355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555d6c0bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555d6f08af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555d6f08af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555d6f08af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555d6f08af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555d6f08af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555d6f08af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555d6f08af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555d6f08af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555d6f08af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555d6f08af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555d7131ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555d6e04cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555d6e057be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555d6de03c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555d6de03c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555d6de04738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555d6de03874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555d6de03874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555d6de03874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555d7270dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555d72716928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555d726fe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555d72729112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f73fe22c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555d6c023b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6d,0x6c, Step #5: Step #5: Step #5: #0 0x55dc885da9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dc8ec3f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dc8ec225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dc8ec224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dc885e0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dc88541b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dc8853c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dc885d2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dc8b5a1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dc8b5a1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dc8b5a1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dc8b5a1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dc8b5a1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dc8b5a1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dc8b5a1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dc8b5a1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dc8b5a1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dc8b5a1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dc8d836f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dc8a563b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dc8a56ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dc8a31ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dc8a31ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dc8a31b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dc8a31a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dc8a31a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dc8a31a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dc8ec24abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dc8ec2d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dc8ec15699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dc8ec40112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f28ef98c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dc8853ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x5c,0xa,0x5c,0xa,0x22, Step #5: \"\\\012\\\012\" Step #5: artifact_prefix='./'; Test unit written to ./oom-b864f623316c8aea046ce832b9bbde745611e655 Step #5: Base64: IlwKXAoi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 783 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2133552477 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564bc4580810, 0x564bc476a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564bc476a020,0x564bc66020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b864f623316c8aea046ce832b9bbde745611e655' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 865 processed earlier; will process 10164 files now Step #5: ==28222== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564bbb0759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564bc16da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564bc16bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564bc16bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564bbb07bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564bbafdcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564bbafd7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564bbb06dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564bbe03cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564bbe03cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564bbe03cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564bbe03cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564bbe03cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564bbe03cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564bbe03cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564bbe03cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564bbe03cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564bbe03cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564bc02d1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564bbcffeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564bbd009be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564bbcdb5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564bbcdb5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564bbcdb6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564bbcdb5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564bbcdb5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564bbcdb5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564bc16bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564bc16c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564bc16b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564bc16db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa2730a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564bbafd5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0x80,0xf0,0x90,0x94,0x8a, Step #5: \302\200\360\220\224\212 Step #5: artifact_prefix='./'; Test unit written to ./oom-6880167f338e32e03533f5498bf8a4a745574163 Step #5: Base64: woDwkJSK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 784 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2133980177 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eeff6a5810, 0x55eeff88f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eeff88f020,0x55ef017270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6880167f338e32e03533f5498bf8a4a745574163' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 866 processed earlier; will process 10163 files now Step #5: ==28258== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eef619a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eefc7ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eefc7e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eefc7e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eef61a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eef6101b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eef60fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eef6192c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eef9161f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eef9161f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eef9161f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eef9161f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eef9161f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eef9161f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eef9161f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eef9161f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eef9161f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eef9161f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eefb3f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eef8123b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eef812ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eef7edac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eef7edac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eef7edb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eef7eda874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eef7eda874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eef7eda874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eefc7e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eefc7ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eefc7d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eefc800112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff802ee9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eef60fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x33,0x32,0x2e,0x36,0x2e, Step #5: e32.6. Step #5: artifact_prefix='./'; Test unit written to ./oom-ad8d0e446222d37853d4352d83faad2b64cef2b9 Step #5: Base64: ZTMyLjYu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 785 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2134403771 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5648148c7810, 0x564814ab101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564814ab1020,0x5648169490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad8d0e446222d37853d4352d83faad2b64cef2b9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 867 processed earlier; will process 10162 files now Step #5: #1 pulse cov: 3510 ft: 3511 exec/s: 0 rss: 157Mb Step #5: ==28294== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56480b3bc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564811a21898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564811a045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564811a044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56480b3c2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56480b323b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56480b31e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56480b3b4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56480e383f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56480e383f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56480e383f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56480e383f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56480e383f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56480e383f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56480e383f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56480e383f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56480e383f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56480e383f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564810618f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56480d345b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56480d350be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56480d0fcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56480d0fcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56480d0fd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56480d0fc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56480d0fc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56480d0fc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564811a06abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564811a0f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5648119f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564811a22112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f74bc333082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56480b31cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xd,0xf2,0xa0,0x80,0x81, Step #5: \"\015\362\240\200\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-a058d21b37481e21204b9f0690ace6d0d79bb31b Step #5: Base64: Ig3yoICB Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 786 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2134869893 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bfede59810, 0x55bfee04301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bfee043020,0x55bfefedb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a058d21b37481e21204b9f0690ace6d0d79bb31b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 869 processed earlier; will process 10160 files now Step #5: ==28330== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bfe494e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bfeafb3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bfeaf965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bfeaf964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bfe4954d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bfe48b5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bfe48b0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bfe4946c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bfe7915f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bfe7915f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bfe7915f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bfe7915f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bfe7915f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bfe7915f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bfe7915f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bfe7915f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bfe7915f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bfe7915f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bfe9baaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bfe68d7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bfe68e2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bfe668ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bfe668ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bfe668f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bfe668e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bfe668e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bfe668e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bfeaf98abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bfeafa1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bfeaf89699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bfeafb4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f14c65fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bfe48aeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0x43,0x46,0x32,0x4, Step #5: $$CF2\004 Step #5: artifact_prefix='./'; Test unit written to ./oom-5df77455526612d30bd1687b8931e8a4aae8621f Step #5: Base64: JCRDRjIE Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 787 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2135291379 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561dd42c8810, 0x561dd44b201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561dd44b2020,0x561dd634a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5df77455526612d30bd1687b8931e8a4aae8621f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 870 processed earlier; will process 10159 files now Step #5: #1 pulse cov: 3577 ft: 3578 exec/s: 0 rss: 161Mb Step #5: ==28366== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561dcadbd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561dd1422898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561dd14055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561dd14054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561dcadc3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561dcad24b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561dcad1f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561dcadb5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561dcdd84f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561dcdd84f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561dcdd84f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561dcdd84f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561dcdd84f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561dcdd84f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561dcdd84f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561dcdd84f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561dcdd84f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561dcdd84f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561dd0019f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561dccd46b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561dccd51be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561dccafdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561dccafdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561dccafe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561dccafd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561dccafd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561dccafd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561dd1407abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561dd1410928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561dd13f8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561dd1423112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdfcd7de082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561dcad1db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x0,0x2d,0xe1,0xb7,0xbf, Step #5: [\000-\341\267\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-8123f0b7f67b05b09c37b5b8d9674257bc2831b4 Step #5: Base64: WwAt4be/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 788 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2135752267 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5588cb70c810, 0x5588cb8f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5588cb8f6020,0x5588cd78e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8123f0b7f67b05b09c37b5b8d9674257bc2831b4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 872 processed earlier; will process 10157 files now Step #5: ==28402== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5588c22019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5588c8866898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588c88495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588c88494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588c2207d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588c2168b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588c2163355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588c21f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5588c51c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5588c51c8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5588c51c8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5588c51c8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5588c51c8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5588c51c8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5588c51c8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5588c51c8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5588c51c8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5588c51c8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5588c745df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588c418ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588c4195be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588c3f41c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588c3f41c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588c3f42738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588c3f41874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588c3f41874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588c3f41874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5588c884babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5588c8854928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5588c883c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5588c8867112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa476899082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588c2161b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xa,0x4,0xdb,0x80,0x0, Step #5: \000\012\004\333\200\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fe95eecfb0b7fdfa8f72d8aa1ffe62b8fdea6470 Step #5: Base64: AAoE24AA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 789 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2136180156 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555dbf2ca810, 0x555dbf4b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555dbf4b4020,0x555dc134c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fe95eecfb0b7fdfa8f72d8aa1ffe62b8fdea6470' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 873 processed earlier; will process 10156 files now Step #5: ==28438== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555db5dbf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555dbc424898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555dbc4075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555dbc4074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555db5dc5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555db5d26b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555db5d21355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555db5db7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555db8d86f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555db8d86f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555db8d86f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555db8d86f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555db8d86f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555db8d86f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555db8d86f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555db8d86f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555db8d86f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555db8d86f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555dbb01bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555db7d48b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555db7d53be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555db7affc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555db7affc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555db7b00738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555db7aff874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555db7aff874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555db7aff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555dbc409abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555dbc412928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555dbc3fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555dbc425112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb9881b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555db5d1fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x34,0x38,0x2d,0x35,0x30,0x30, Step #5: 48-500 Step #5: artifact_prefix='./'; Test unit written to ./oom-8aeb9b6298998effdf750558327f29dec91fb7e4 Step #5: Base64: NDgtNTAw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 790 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2136602560 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558c7e343810, 0x558c7e52d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558c7e52d020,0x558c803c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8aeb9b6298998effdf750558327f29dec91fb7e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 874 processed earlier; will process 10155 files now Step #5: ==28474== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558c74e389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558c7b49d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558c7b4805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558c7b4804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558c74e3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558c74d9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558c74d9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558c74e30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558c77dfff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558c77dfff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558c77dfff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558c77dfff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558c77dfff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558c77dfff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558c77dfff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558c77dfff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558c77dfff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558c77dfff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558c7a094f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558c76dc1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558c76dccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558c76b78c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558c76b78c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558c76b79738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558c76b78874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558c76b78874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558c76b78874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558c7b482abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558c7b48b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558c7b473699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558c7b49e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f772e6a8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558c74d98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc3,0xb4,0xf0,0xb4,0x80,0x80, Step #5: \303\264\360\264\200\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-3d16d8d49fdd80ed77f42b59f6574eed467b8f30 Step #5: Base64: w7TwtICA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 791 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2137025312 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5561e2a2d810, 0x5561e2c1701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5561e2c17020,0x5561e4aaf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3d16d8d49fdd80ed77f42b59f6574eed467b8f30' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 875 processed earlier; will process 10154 files now Step #5: ==28510== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5561d95229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5561dfb87898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5561dfb6a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5561dfb6a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5561d9528d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5561d9489b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5561d9484355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5561d951ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5561dc4e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5561dc4e9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5561dc4e9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5561dc4e9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5561dc4e9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5561dc4e9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5561dc4e9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5561dc4e9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5561dc4e9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5561dc4e9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5561de77ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5561db4abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5561db4b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5561db262c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5561db262c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5561db263738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5561db262874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5561db262874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5561db262874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5561dfb6cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5561dfb75928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5561dfb5d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5561dfb88112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c9b378082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5561d9482b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x2b,0x20,0x27,0x76,0x54, Step #5: + 'vT Step #5: artifact_prefix='./'; Test unit written to ./oom-ad67a45329c2a87e4b3f9cfa55f6df27c4e03498 Step #5: Base64: ICsgJ3ZU Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 792 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2137454277 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559b5b2a9810, 0x559b5b49301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559b5b493020,0x559b5d32b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad67a45329c2a87e4b3f9cfa55f6df27c4e03498' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 876 processed earlier; will process 10153 files now Step #5: ==28546== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559b51d9e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559b58403898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559b583e65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559b583e64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b51da4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b51d05b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b51d00355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b51d96c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b54d65f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b54d65f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b54d65f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b54d65f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b54d65f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b54d65f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b54d65f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b54d65f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b54d65f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b54d65f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559b56ffaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b53d27b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b53d32be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b53adec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b53adec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b53adf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b53ade874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b53ade874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b53ade874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559b583e8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559b583f1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559b583d9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559b58404112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc77bb7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b51cfeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x23,0x30,0x25,0xdb,0x0, Step #5: \000#0%\333\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1610a32305496ae0bfb1e2c95c5e870928c0f834 Step #5: Base64: ACMwJdsA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 793 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2137878033 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5564e7e3b810, 0x5564e802501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564e8025020,0x5564e9ebd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1610a32305496ae0bfb1e2c95c5e870928c0f834' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 877 processed earlier; will process 10152 files now Step #5: ==28582== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5564de9309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564e4f95898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564e4f785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564e4f784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564de936d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5564de897b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5564de892355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564de928c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564e18f7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564e18f7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564e18f7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564e18f7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564e18f7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564e18f7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564e18f7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564e18f7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564e18f7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564e18f7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5564e3b8cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5564e08b9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5564e08c4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5564e0670c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5564e0670c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5564e0671738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5564e0670874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5564e0670874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5564e0670874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564e4f7aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564e4f83928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564e4f6b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564e4f96112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f86ce8c2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5564de890b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0x2f,0xd6,0xa0,0x6e, Step #5: \012\012/\326\240n Step #5: artifact_prefix='./'; Test unit written to ./oom-b27b054bd1064db54f54a834676675e02d334f9e Step #5: Base64: Cgov1qBu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 794 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2138302299 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557cde17a810, 0x557cde36401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557cde364020,0x557ce01fc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b27b054bd1064db54f54a834676675e02d334f9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 878 processed earlier; will process 10151 files now Step #5: #1 pulse cov: 3427 ft: 3428 exec/s: 0 rss: 157Mb Step #5: ==28618== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557cd4c6f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557cdb2d4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557cdb2b75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557cdb2b74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557cd4c75d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557cd4bd6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557cd4bd1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557cd4c67c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557cd7c36f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557cd7c36f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557cd7c36f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557cd7c36f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557cd7c36f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557cd7c36f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557cd7c36f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557cd7c36f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557cd7c36f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557cd7c36f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557cd9ecbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557cd6bf8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557cd6c03be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557cd69afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557cd69afc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557cd69b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557cd69af874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557cd69af874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557cd69af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557cdb2b9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557cdb2c2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557cdb2aa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557cdb2d5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f73efce5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557cd4bcfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2c,0x2c,0x2d,0x2d,0x41,0x2d, Step #5: ,,--A- Step #5: artifact_prefix='./'; Test unit written to ./oom-0b872a83d30987c19e0fb93de7207cb7585b0ebd Step #5: Base64: LCwtLUEt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 795 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2138766630 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5624950c1810, 0x5624952ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5624952ab020,0x5624971430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b872a83d30987c19e0fb93de7207cb7585b0ebd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 880 processed earlier; will process 10149 files now Step #5: #1 pulse cov: 3506 ft: 3507 exec/s: 0 rss: 160Mb Step #5: ==28654== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56248bbb69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56249221b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5624921fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5624921fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56248bbbcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56248bb1db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56248bb18355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56248bbaec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56248eb7df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56248eb7df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56248eb7df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56248eb7df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56248eb7df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56248eb7df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56248eb7df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56248eb7df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56248eb7df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56248eb7df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562490e12f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56248db3fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56248db4abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56248d8f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56248d8f6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56248d8f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56248d8f6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56248d8f6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56248d8f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562492200abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562492209928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5624921f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56249221c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f581e359082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56248bb16b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x80,0x9c,0xe3,0x80,0x90, Step #5: \343\200\234\343\200\220 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ed0ce9e7d6fd1feb0df84fde6cebfed3c86cfe5 Step #5: Base64: 44Cc44CQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 796 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2139238005 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5641cc39f810, 0x5641cc58901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5641cc589020,0x5641ce4210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ed0ce9e7d6fd1feb0df84fde6cebfed3c86cfe5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 882 processed earlier; will process 10147 files now Step #5: ==28690== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5641c2e949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5641c94f9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5641c94dc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5641c94dc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5641c2e9ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641c2dfbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641c2df6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5641c2e8cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5641c5e5bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5641c5e5bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5641c5e5bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5641c5e5bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5641c5e5bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5641c5e5bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5641c5e5bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5641c5e5bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5641c5e5bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5641c5e5bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5641c80f0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5641c4e1db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5641c4e28be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5641c4bd4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5641c4bd4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5641c4bd5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5641c4bd4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5641c4bd4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5641c4bd4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5641c94deabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5641c94e7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5641c94cf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5641c94fa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1da03d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641c2df4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x62,0xe2,0xb1,0x90, Step #5: Step #5: Step #5: #0 0x561b727e29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b78e47898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b78e2a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b78e2a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b727e8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b72749b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b72744355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b727dac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b757a9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b757a9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b757a9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b757a9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b757a9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b757a9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b757a9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b757a9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b757a9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b757a9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b77a3ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b7476bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b74776be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b74522c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b74522c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b74523738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b74522874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b74522874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b74522874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b78e2cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b78e35928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b78e1d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b78e48112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff283482082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b72742b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xa,0x3d,0xa,0x3d,0xa, Step #5: =\012=\012=\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-a2c344a1bcc29a476ca240ae97e72a052065c753 Step #5: Base64: PQo9Cj0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 798 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2140080986 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b34af9810, 0x557b34ce301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b34ce3020,0x557b36b7b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2c344a1bcc29a476ca240ae97e72a052065c753' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 884 processed earlier; will process 10145 files now Step #5: ==28762== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557b2b5ee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b31c53898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b31c365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b31c364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b2b5f4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b2b555b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b2b550355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b2b5e6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b2e5b5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b2e5b5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b2e5b5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b2e5b5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b2e5b5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b2e5b5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b2e5b5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b2e5b5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b2e5b5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b2e5b5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b3084af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b2d577b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b2d582be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b2d32ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b2d32ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b2d32f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b2d32e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b2d32e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b2d32e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b31c38abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b31c41928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b31c29699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b31c54112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f14c89f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b2b54eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x66,0xa,0x0,0xa,0x0, Step #5: Pf\012\000\012\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f1cc76e71b45f07e0666e2d4c51d6c80b58bf443 Step #5: Base64: UGYKAAoA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 799 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2140506774 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c2cf55810, 0x556c2d13f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c2d13f020,0x556c2efd70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f1cc76e71b45f07e0666e2d4c51d6c80b58bf443' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 885 processed earlier; will process 10144 files now Step #5: ==28798== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556c23a4a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c2a0af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c2a0925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c2a0924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556c23a50d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556c239b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556c239ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556c23a42c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556c26a11f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556c26a11f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556c26a11f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556c26a11f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556c26a11f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556c26a11f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556c26a11f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556c26a11f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556c26a11f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556c26a11f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c28ca6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556c259d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556c259debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556c2578ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556c2578ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556c2578b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556c2578a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556c2578a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556c2578a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c2a094abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c2a09d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c2a085699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c2a0b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1775187082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556c239aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x54,0x41,0x47,0x20,0x40, Step #5: %TAG @ Step #5: artifact_prefix='./'; Test unit written to ./oom-8e9bbed190ba91f082f519adb3fbba27e66faa8f Step #5: Base64: JVRBRyBA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 800 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2140929537 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5586e9503810, 0x5586e96ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5586e96ed020,0x5586eb5850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8e9bbed190ba91f082f519adb3fbba27e66faa8f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 886 processed earlier; will process 10143 files now Step #5: ==28834== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5586dfff89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5586e665d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5586e66405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5586e66404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5586dfffed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5586dff5fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5586dff5a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5586dfff0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5586e2fbff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5586e2fbff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5586e2fbff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5586e2fbff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5586e2fbff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5586e2fbff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5586e2fbff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5586e2fbff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5586e2fbff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5586e2fbff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5586e5254f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5586e1f81b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5586e1f8cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5586e1d38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5586e1d38c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5586e1d39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5586e1d38874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5586e1d38874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5586e1d38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5586e6642abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5586e664b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5586e6633699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5586e665e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6409684082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5586dff58b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x91,0x91,0x82,0xcd,0x84, Step #5: \360\221\221\202\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-11e95a92145ea400fc8a0eb3b81d7669843a0bce Step #5: Base64: 8JGRgs2E Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 801 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2141354512 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5567a7237810, 0x5567a742101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5567a7421020,0x5567a92b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/11e95a92145ea400fc8a0eb3b81d7669843a0bce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 887 processed earlier; will process 10142 files now Step #5: #1 pulse cov: 3595 ft: 3596 exec/s: 0 rss: 161Mb Step #5: ==28870== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55679dd2c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5567a4391898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5567a43745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5567a43744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55679dd32d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55679dc93b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55679dc8e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55679dd24c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5567a0cf3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5567a0cf3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5567a0cf3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5567a0cf3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5567a0cf3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5567a0cf3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5567a0cf3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5567a0cf3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5567a0cf3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5567a0cf3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5567a2f88f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55679fcb5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55679fcc0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55679fa6cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55679fa6cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55679fa6d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55679fa6c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55679fa6c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55679fa6c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5567a4376abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5567a437f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5567a4367699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5567a4392112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d1875f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55679dc8cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdc,0xb8,0x19,0xa,0xdc,0xb8, Step #5: \334\270\031\012\334\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-7840a49740a43e8aa33039ae2566136eb375c748 Step #5: Base64: 3LgZCty4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 802 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2141815140 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b5b7bbe810, 0x55b5b7da801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b5b7da8020,0x55b5b9c400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7840a49740a43e8aa33039ae2566136eb375c748' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 889 processed earlier; will process 10140 files now Step #5: ==28906== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b5ae6b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b5b4d18898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b5b4cfb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b5b4cfb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b5ae6b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b5ae61ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b5ae615355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b5ae6abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b5b167af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b5b167af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b5b167af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b5b167af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b5b167af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b5b167af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b5b167af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b5b167af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b5b167af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b5b167af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b5b390ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b5b063cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b5b0647be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b5b03f3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b5b03f3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b5b03f4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b5b03f3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b5b03f3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b5b03f3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b5b4cfdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b5b4d06928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b5b4cee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b5b4d19112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1cb2a3a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b5ae613b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x0,0x2d,0xd9,0xae,0xbc, Step #5: %\000-\331\256\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-7730bef17695345e02fe4353a4d5a33adf20812b Step #5: Base64: JQAt2a68 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 803 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2142240522 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c436db810, 0x562c438c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c438c5020,0x562c4575d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7730bef17695345e02fe4353a4d5a33adf20812b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 890 processed earlier; will process 10139 files now Step #5: ==28942== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562c3a1d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c40835898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c408185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c408184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c3a1d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c3a137b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c3a132355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c3a1c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c3d197f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c3d197f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c3d197f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c3d197f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c3d197f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c3d197f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c3d197f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c3d197f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c3d197f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c3d197f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c3f42cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562c3c159b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562c3c164be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562c3bf10c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562c3bf10c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562c3bf11738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562c3bf10874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562c3bf10874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562c3bf10874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c4081aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c40823928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c4080b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c40836112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f85ddc27082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c3a130b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0x66,0x7d,0xd7,0x91,0x5b, Step #5: if}\327\221[ Step #5: artifact_prefix='./'; Test unit written to ./oom-8201c717c27dd7ae73b2a80c2903eb58dd53ce30 Step #5: Base64: aWZ915Fb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 804 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2142664649 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d07c649810, 0x55d07c83301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d07c833020,0x55d07e6cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8201c717c27dd7ae73b2a80c2903eb58dd53ce30' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 891 processed earlier; will process 10138 files now Step #5: ==28978== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d07313e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d0797a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d0797865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d0797864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d073144d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d0730a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d0730a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d073136c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d076105f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d076105f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d076105f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d076105f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d076105f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d076105f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d076105f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d076105f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d076105f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d076105f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d07839af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d0750c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d0750d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d074e7ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d074e7ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d074e7f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d074e7e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d074e7e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d074e7e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d079788abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d079791928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d079779699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d0797a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8f3ff21082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d07309eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x8,0xcb,0x88,0xdd,0x84,0x8, Step #5: \010\313\210\335\204\010 Step #5: artifact_prefix='./'; Test unit written to ./oom-fee9fb1d7aab74db9db7407b9e5b7d93649e5c3b Step #5: Base64: CMuI3YQI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 805 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2143089031 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5612b1ebf810, 0x5612b20a901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5612b20a9020,0x5612b3f410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fee9fb1d7aab74db9db7407b9e5b7d93649e5c3b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 892 processed earlier; will process 10137 files now Step #5: ==29014== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5612a89b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5612af019898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5612aeffc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5612aeffc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5612a89bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5612a891bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5612a8916355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5612a89acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5612ab97bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5612ab97bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5612ab97bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5612ab97bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5612ab97bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5612ab97bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5612ab97bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5612ab97bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5612ab97bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5612ab97bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5612adc10f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5612aa93db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5612aa948be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5612aa6f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5612aa6f4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5612aa6f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5612aa6f4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5612aa6f4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5612aa6f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5612aeffeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5612af007928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5612aefef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5612af01a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4cf168a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5612a8914b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x40,0x40,0x3,0x60,0x60, Step #5: \003@@\003`` Step #5: artifact_prefix='./'; Test unit written to ./oom-4a4e3d5ceb00dc46725a1cd8ae31ffa6a5246c71 Step #5: Base64: A0BAA2Bg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 806 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2143635450 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55917170d810, 0x5591718f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5591718f7020,0x55917378f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4a4e3d5ceb00dc46725a1cd8ae31ffa6a5246c71' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 893 processed earlier; will process 10136 files now Step #5: ==29050== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5591682029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55916e867898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55916e84a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55916e84a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559168208d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559168169b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559168164355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5591681fac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55916b1c9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55916b1c9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55916b1c9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55916b1c9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55916b1c9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55916b1c9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55916b1c9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55916b1c9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55916b1c9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55916b1c9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55916d45ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55916a18bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55916a196be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559169f42c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559169f42c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559169f43738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559169f42874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559169f42874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559169f42874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55916e84cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55916e855928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55916e83d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55916e868112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f40b3ac2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559168162b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0xa,0x2b,0xa,0x65,0xa, Step #5: :\012+\012e\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-8d11e3240d82b49c38307d5fe8a3133de83fd312 Step #5: Base64: OgorCmUK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 807 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2144070672 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5596e353f810, 0x5596e372901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596e3729020,0x5596e55c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d11e3240d82b49c38307d5fe8a3133de83fd312' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 894 processed earlier; will process 10135 files now Step #5: ==29086== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5596da0349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5596e0699898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5596e067c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5596e067c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5596da03ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5596d9f9bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5596d9f96355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5596da02cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5596dcffbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5596dcffbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5596dcffbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5596dcffbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5596dcffbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5596dcffbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5596dcffbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5596dcffbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5596dcffbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5596dcffbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596df290f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5596dbfbdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5596dbfc8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5596dbd74c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5596dbd74c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5596dbd75738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5596dbd74874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5596dbd74874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5596dbd74874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5596e067eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5596e0687928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5596e066f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5596e069a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fefe9203082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5596d9f94b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x45,0x0,0x5c,0x13,0x0,0x5c, Step #5: E\000\\\023\000\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-a5434c2e2e66d0a47a3b1012a597600a1acb4492 Step #5: Base64: RQBcEwBc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 808 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2144495329 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56131c471810, 0x56131c65b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56131c65b020,0x56131e4f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a5434c2e2e66d0a47a3b1012a597600a1acb4492' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 895 processed earlier; will process 10134 files now Step #5: ==29122== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561312f669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5613195cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613195ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613195ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561312f6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561312ecdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561312ec8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561312f5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561315f2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561315f2df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561315f2df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561315f2df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561315f2df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561315f2df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561315f2df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561315f2df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561315f2df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561315f2df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5613181c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561314eefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561314efabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561314ca6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561314ca6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561314ca7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561314ca6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561314ca6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561314ca6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5613195b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5613195b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5613195a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5613195cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbba50dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561312ec6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x29,0xb,0x29,0xb,0x2e,0xb, Step #5: )\013)\013.\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-a2b80adb30011b6d874bba3759d207ca30ee031a Step #5: Base64: KQspCy4L Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 809 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2144921104 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5580daa73810, 0x5580dac5d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5580dac5d020,0x5580dcaf50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2b80adb30011b6d874bba3759d207ca30ee031a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 896 processed earlier; will process 10133 files now Step #5: ==29158== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5580d15689c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5580d7bcd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5580d7bb05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5580d7bb04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5580d156ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5580d14cfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5580d14ca355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5580d1560c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5580d452ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5580d452ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5580d452ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5580d452ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5580d452ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5580d452ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5580d452ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5580d452ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5580d452ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5580d452ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5580d67c4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5580d34f1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5580d34fcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580d32a8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580d32a8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580d32a9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580d32a8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580d32a8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580d32a8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5580d7bb2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5580d7bbb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5580d7ba3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5580d7bce112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2d74c33082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5580d14c8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x7f,0x0,0x0,0x0, Step #5: = \177\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b6a01743f76ee6d9e035f7ce35d3f3d1f8785a59 Step #5: Base64: PSB/AAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 810 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2145346926 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5583e2b66810, 0x5583e2d5001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5583e2d50020,0x5583e4be80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b6a01743f76ee6d9e035f7ce35d3f3d1f8785a59' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 897 processed earlier; will process 10132 files now Step #5: ==29194== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5583d965b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5583dfcc0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583dfca35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583dfca34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5583d9661d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5583d95c2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5583d95bd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5583d9653c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5583dc622f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5583dc622f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5583dc622f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5583dc622f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5583dc622f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5583dc622f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5583dc622f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5583dc622f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5583dc622f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5583dc622f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5583de8b7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5583db5e4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5583db5efbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5583db39bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5583db39bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5583db39c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5583db39b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5583db39b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5583db39b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5583dfca5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5583dfcae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5583dfc96699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5583dfcc1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa978c38082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5583d95bbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0xe1,0x9f,0xb6,0x7e,0x6f, Step #5: ?\341\237\266~o Step #5: artifact_prefix='./'; Test unit written to ./oom-7d2945249fdceffcbadcb6a19f7e931aa2e226b3 Step #5: Base64: P+Gftn5v Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 811 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2145775678 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff8be17810, 0x55ff8c00101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff8c001020,0x55ff8de990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d2945249fdceffcbadcb6a19f7e931aa2e226b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 898 processed earlier; will process 10131 files now Step #5: ==29230== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ff8290c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff88f71898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff88f545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff88f544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff82912d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff82873b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff8286e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff82904c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff858d3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff858d3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff858d3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff858d3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff858d3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff858d3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff858d3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff858d3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff858d3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff858d3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff87b68f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff84895b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff848a0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff8464cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff8464cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff8464d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff8464c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff8464c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff8464c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff88f56abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff88f5f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff88f47699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff88f72112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6cebf9b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff8286cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd8,0xad,0x29,0x7e,0x3f,0x30, Step #5: \330\255)~?0 Step #5: artifact_prefix='./'; Test unit written to ./oom-5c3e77a4eea06750975834ecbee4fda883ec6bef Step #5: Base64: 2K0pfj8w Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 812 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2146203046 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5559fe850810, 0x5559fea3a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5559fea3a020,0x555a008d20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c3e77a4eea06750975834ecbee4fda883ec6bef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 899 processed earlier; will process 10130 files now Step #5: ==29266== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5559f53459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5559fb9aa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5559fb98d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5559fb98d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5559f534bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5559f52acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5559f52a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5559f533dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5559f830cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5559f830cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5559f830cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5559f830cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5559f830cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5559f830cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5559f830cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5559f830cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5559f830cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5559f830cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5559fa5a1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5559f72ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5559f72d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5559f7085c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5559f7085c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5559f7086738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5559f7085874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5559f7085874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5559f7085874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5559fb98fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5559fb998928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5559fb980699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5559fb9ab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f28a1894082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5559f52a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x34,0x27,0x34,0x27,0x4a, Step #5: +4'4'J Step #5: artifact_prefix='./'; Test unit written to ./oom-501654b5a146aa21e7a487d918aab6ebdfb583c8 Step #5: Base64: KzQnNCdK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 813 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2146631518 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562b342e3810, 0x562b344cd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562b344cd020,0x562b363650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/501654b5a146aa21e7a487d918aab6ebdfb583c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 900 processed earlier; will process 10129 files now Step #5: ==29302== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562b2add89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562b3143d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562b314205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562b314204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b2added42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b2ad3fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b2ad3a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b2add0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b2dd9ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b2dd9ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b2dd9ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b2dd9ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b2dd9ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b2dd9ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b2dd9ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b2dd9ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b2dd9ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b2dd9ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562b30034f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b2cd61b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b2cd6cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b2cb18c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b2cb18c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b2cb19738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b2cb18874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b2cb18874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b2cb18874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562b31422abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562b3142b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562b31413699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562b3143e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2a9fd2a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b2ad38b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x23,0x22,0x5c,0x65,0x22, Step #5: f#\"\\e\" Step #5: artifact_prefix='./'; Test unit written to ./oom-58bacc1f43f477941a0caafc45fc5375ddb6751e Step #5: Base64: ZiMiXGUi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 814 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2147058324 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56152c5de810, 0x56152c7c801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56152c7c8020,0x56152e6600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58bacc1f43f477941a0caafc45fc5375ddb6751e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 901 processed earlier; will process 10128 files now Step #5: ==29338== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5615230d39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561529738898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56152971b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56152971b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5615230d9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56152303ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561523035355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5615230cbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56152609af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56152609af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56152609af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56152609af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56152609af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56152609af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56152609af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56152609af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56152609af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56152609af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56152832ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56152505cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561525067be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561524e13c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561524e13c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561524e14738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561524e13874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561524e13874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561524e13874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56152971dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561529726928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56152970e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561529739112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe23e8bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561523033b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xea,0xaa,0xaf,0xe1,0x86,0xaf, Step #5: \352\252\257\341\206\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-2765812a44bbab58e28f23544e5af520d96d3ad7 Step #5: Base64: 6qqv4Yav Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 815 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2147485482 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564f9e3a6810, 0x564f9e59001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564f9e590020,0x564fa04280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2765812a44bbab58e28f23544e5af520d96d3ad7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 902 processed earlier; will process 10127 files now Step #5: ==29374== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564f94e9b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f9b500898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f9b4e35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f9b4e34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f94ea1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f94e02b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f94dfd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f94e93c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f97e62f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f97e62f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f97e62f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f97e62f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f97e62f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f97e62f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f97e62f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f97e62f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f97e62f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f97e62f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f9a0f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f96e24b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f96e2fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f96bdbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f96bdbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f96bdc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f96bdb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f96bdb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f96bdb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f9b4e5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f9b4ee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f9b4d6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f9b501112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e49823082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f94dfbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd2,0x97,0xf0,0x91,0x80,0x80, Step #5: \322\227\360\221\200\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-28770a9e1173dae2e364166cb5aac4680ca194ae Step #5: Base64: 0pfwkYCA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 816 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2147907590 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564e64ce8810, 0x564e64ed201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564e64ed2020,0x564e66d6a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/28770a9e1173dae2e364166cb5aac4680ca194ae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 903 processed earlier; will process 10126 files now Step #5: ==29410== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564e5b7dd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564e61e42898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564e61e255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564e61e254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564e5b7e3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564e5b744b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564e5b73f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564e5b7d5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564e5e7a4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564e5e7a4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564e5e7a4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564e5e7a4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564e5e7a4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564e5e7a4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564e5e7a4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564e5e7a4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564e5e7a4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564e5e7a4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564e60a39f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564e5d766b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564e5d771be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564e5d51dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564e5d51dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564e5d51e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564e5d51d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564e5d51d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564e5d51d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564e61e27abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564e61e30928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564e61e18699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564e61e43112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f095b39b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564e5b73db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x6,0x3f,0x79, Step #5: \000\000\000\006?y Step #5: artifact_prefix='./'; Test unit written to ./oom-a851b91e2c8a2a43360f6ae87aa00e79b6b52f62 Step #5: Base64: AAAABj95 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 817 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2148335083 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56546ea04810, 0x56546ebee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56546ebee020,0x565470a860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a851b91e2c8a2a43360f6ae87aa00e79b6b52f62' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 904 processed earlier; will process 10125 files now Step #5: ==29446== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5654654f99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56546bb5e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56546bb415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56546bb414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5654654ffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565465460b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56546545b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5654654f1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5654684c0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5654684c0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5654684c0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5654684c0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5654684c0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5654684c0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5654684c0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5654684c0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5654684c0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5654684c0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56546a755f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565467482b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56546748dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565467239c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565467239c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56546723a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565467239874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565467239874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565467239874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56546bb43abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56546bb4c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56546bb34699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56546bb5f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff2050ae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565465459b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x1,0x6,0x2,0x1,0x2, Step #5: \000\001\006\002\001\002 Step #5: artifact_prefix='./'; Test unit written to ./oom-c69e88bdd2144a88a05d67d04305e7fed3c0e3fc Step #5: Base64: AAEGAgEC Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 818 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2148762372 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e293243810, 0x55e29342d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e29342d020,0x55e2952c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c69e88bdd2144a88a05d67d04305e7fed3c0e3fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 905 processed earlier; will process 10124 files now Step #5: #1 pulse cov: 10579 ft: 10580 exec/s: 0 rss: 179Mb Step #5: ==29482== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e289d389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e29039d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e2903805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e2903804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e289d3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e289c9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e289c9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e289d30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e28ccfff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e28ccfff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e28ccfff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e28ccfff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e28ccfff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e28ccfff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e28ccfff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e28ccfff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e28ccfff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e28ccfff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e28ef94f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e28bcc1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e28bcccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e28ba78c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e28ba78c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e28ba79738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e28ba78874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e28ba78874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e28ba78874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e290382abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e29038b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e290373699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e29039e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f13922e8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e289c98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x37,0x0,0xf0,0x90,0x9a,0x84, Step #5: 7\000\360\220\232\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-2faebb81bbb6766a824e1914de0391ec1c379c2e Step #5: Base64: NwDwkJqE Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 819 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2149246734 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fee6947810, 0x55fee6b3101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fee6b31020,0x55fee89c90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2faebb81bbb6766a824e1914de0391ec1c379c2e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 907 processed earlier; will process 10122 files now Step #5: ==29518== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fedd43c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fee3aa1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fee3a845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fee3a844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fedd442d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fedd3a3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fedd39e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fedd434c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fee0403f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fee0403f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fee0403f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fee0403f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fee0403f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fee0403f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fee0403f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fee0403f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fee0403f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fee0403f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fee2698f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fedf3c5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fedf3d0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fedf17cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fedf17cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fedf17d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fedf17c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fedf17c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fedf17c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fee3a86abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fee3a8f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fee3a77699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fee3aa2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f78349b5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fedd39cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0x85,0xc2,0x85,0xc2,0x85, Step #5: \302\205\302\205\302\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-52bdff75b1a9a74f8131d474d05884febf93223e Step #5: Base64: woXChcKF Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 820 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2149663801 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55616c5ed810, 0x55616c7d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55616c7d7020,0x55616e66f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/52bdff75b1a9a74f8131d474d05884febf93223e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 908 processed earlier; will process 10121 files now Step #5: ==29554== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5561630e29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556169747898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55616972a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55616972a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5561630e8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556163049b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556163044355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5561630dac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5561660a9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5561660a9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5561660a9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5561660a9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5561660a9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5561660a9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5561660a9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5561660a9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5561660a9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5561660a9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55616833ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55616506bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556165076be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556164e22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556164e22c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556164e23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556164e22874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556164e22874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556164e22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55616972cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556169735928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55616971d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556169748112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbddbf0d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556163042b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x6f,0x71,0x9,0x2e,0x74, Step #5: \001oq\011.t Step #5: artifact_prefix='./'; Test unit written to ./oom-cb6c473e9f3de366062a062c59c2001bfaf36b70 Step #5: Base64: AW9xCS50 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 821 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2150094983 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa6e66c810, 0x55aa6e85601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa6e856020,0x55aa706ee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb6c473e9f3de366062a062c59c2001bfaf36b70' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 909 processed earlier; will process 10120 files now Step #5: ==29590== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55aa651619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa6b7c6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa6b7a95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa6b7a94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa65167d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa650c8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa650c3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa65159c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa68128f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa68128f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa68128f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa68128f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa68128f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa68128f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa68128f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa68128f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa68128f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa68128f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa6a3bdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa670eab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa670f5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa66ea1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa66ea1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa66ea2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa66ea1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa66ea1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa66ea1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa6b7ababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa6b7b4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa6b79c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa6b7c7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc5eea90082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa650c1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x4d,0x4a,0x0,0x7f, Step #5: DaMJ\000\177 Step #5: artifact_prefix='./'; Test unit written to ./oom-c24517a608c9becc2f61f3f22130cd9a81b9e639 Step #5: Base64: RGFNSgB/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 822 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2150517546 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f8edf6f810, 0x55f8ee15901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f8ee159020,0x55f8efff10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c24517a608c9becc2f61f3f22130cd9a81b9e639' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 910 processed earlier; will process 10119 files now Step #5: ==29626== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f8e4a649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f8eb0c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8eb0ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8eb0ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8e4a6ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8e49cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8e49c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8e4a5cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8e7a2bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8e7a2bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8e7a2bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8e7a2bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8e7a2bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8e7a2bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8e7a2bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8e7a2bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8e7a2bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8e7a2bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f8e9cc0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f8e69edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f8e69f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8e67a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8e67a4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8e67a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8e67a4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8e67a4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8e67a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f8eb0aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f8eb0b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f8eb09f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f8eb0ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fee098cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8e49c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x28,0x5b,0x3f,0xdf, Step #5: (?([?\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-dc7d839f3aa7abd851e4beea0b2126fcd49b0512 Step #5: Base64: KD8oWz/f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 823 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2150941129 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5601b2a24810, 0x5601b2c0e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5601b2c0e020,0x5601b4aa60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dc7d839f3aa7abd851e4beea0b2126fcd49b0512' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 911 processed earlier; will process 10118 files now Step #5: ==29662== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5601a95199c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601afb7e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601afb615dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601afb614fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5601a951fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601a9480b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601a947b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5601a9511c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601ac4e0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601ac4e0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601ac4e0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601ac4e0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601ac4e0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601ac4e0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601ac4e0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601ac4e0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601ac4e0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601ac4e0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5601ae775f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601ab4a2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601ab4adbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5601ab259c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5601ab259c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5601ab25a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5601ab259874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5601ab259874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5601ab259874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5601afb63abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5601afb6c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5601afb54699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601afb7f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffb4c6a9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601a9479b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x81,0x81,0xe2,0x81,0x81, Step #5: \342\201\201\342\201\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-3d4efd635956b4faf1ebac1775cb44b6cbebecc6 Step #5: Base64: 4oGB4oGB Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 824 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2151368263 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561933283810, 0x56193346d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56193346d020,0x5619353050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3d4efd635956b4faf1ebac1775cb44b6cbebecc6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 912 processed earlier; will process 10117 files now Step #5: ==29698== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561929d789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5619303dd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5619303c05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5619303c04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561929d7ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561929cdfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561929cda355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561929d70c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56192cd3ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56192cd3ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56192cd3ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56192cd3ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56192cd3ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56192cd3ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56192cd3ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56192cd3ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56192cd3ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56192cd3ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56192efd4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56192bd01b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56192bd0cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56192bab8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56192bab8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56192bab9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56192bab8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56192bab8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56192bab8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5619303c2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5619303cb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5619303b3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5619303de112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88bab9d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561929cd8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x0,0x2d,0xdf,0xbf,0x5d, Step #5: [\000-\337\277] Step #5: artifact_prefix='./'; Test unit written to ./oom-9a5ac96f2135c940a06ed95b653815131f549250 Step #5: Base64: WwAt379d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 825 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2151794786 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c6e9414810, 0x55c6e95fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c6e95fe020,0x55c6eb4960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9a5ac96f2135c940a06ed95b653815131f549250' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 913 processed earlier; will process 10116 files now Step #5: ==29734== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c6dff099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c6e656e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c6e65515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c6e65514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c6dff0fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6dfe70b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6dfe6b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c6dff01c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c6e2ed0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c6e2ed0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c6e2ed0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c6e2ed0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c6e2ed0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c6e2ed0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c6e2ed0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c6e2ed0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c6e2ed0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c6e2ed0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c6e5165f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6e1e92b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c6e1e9dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6e1c49c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6e1c49c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6e1c4a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6e1c49874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6e1c49874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6e1c49874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c6e6553abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c6e655c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c6e6544699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c6e656f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6569478082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6dfe69b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0xb,0xb,0xb,0xb,0xb, Step #5: \013\013\013\013\013\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-deb92bbb535f00cc7976cbc7532288d9993a6c25 Step #5: Base64: CwsLCwsL Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 826 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2152209791 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5591a40b2810, 0x5591a429c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5591a429c020,0x5591a61340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/deb92bbb535f00cc7976cbc7532288d9993a6c25' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 914 processed earlier; will process 10115 files now Step #5: #1 pulse cov: 3593 ft: 3594 exec/s: 0 rss: 159Mb Step #5: #2 pulse cov: 4083 ft: 4284 exec/s: 0 rss: 160Mb Step #5: ==29770== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55919aba79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5591a120c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5591a11ef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5591a11ef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55919abadd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55919ab0eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55919ab09355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55919ab9fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55919db6ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55919db6ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55919db6ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55919db6ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55919db6ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55919db6ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55919db6ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55919db6ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55919db6ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55919db6ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55919fe03f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55919cb30b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55919cb3bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55919c8e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55919c8e7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55919c8e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55919c8e7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55919c8e7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55919c8e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5591a11f1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5591a11fa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5591a11e2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5591a120d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3168d0f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55919ab07b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x0,0x7d,0x7d,0x7d,0x7d, Step #5: I\000}}}} Step #5: artifact_prefix='./'; Test unit written to ./oom-b54d877dcff5dcdbaef0e6fa752b22f4c5d45434 Step #5: Base64: SQB9fX19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 827 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2152708644 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5613f2687810, 0x5613f287101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5613f2871020,0x5613f47090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b54d877dcff5dcdbaef0e6fa752b22f4c5d45434' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 917 processed earlier; will process 10112 files now Step #5: #1 pulse cov: 3454 ft: 3455 exec/s: 0 rss: 160Mb Step #5: ==29806== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5613e917c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5613ef7e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613ef7c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613ef7c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5613e9182d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5613e90e3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5613e90de355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5613e9174c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5613ec143f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5613ec143f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5613ec143f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5613ec143f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5613ec143f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5613ec143f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5613ec143f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5613ec143f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5613ec143f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5613ec143f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5613ee3d8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5613eb105b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5613eb110be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5613eaebcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5613eaebcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5613eaebd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5613eaebc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5613eaebc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5613eaebc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5613ef7c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5613ef7cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5613ef7b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5613ef7e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff50fb56082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5613e90dcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x5b,0x7a,0xe9,0xf7, Step #5: \000\000[z\351\367 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7f09c332e6e2ba76dd97a83724b04f6cb817b37 Step #5: Base64: AABbeun3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 828 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2153173328 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0d1c7d810, 0x55b0d1e6701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b0d1e67020,0x55b0d3cff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7f09c332e6e2ba76dd97a83724b04f6cb817b37' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 919 processed earlier; will process 10110 files now Step #5: ==29842== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b0c87729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b0cedd7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b0cedba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b0cedba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0c8778d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0c86d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0c86d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0c876ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b0cb739f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b0cb739f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b0cb739f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b0cb739f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b0cb739f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b0cb739f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b0cb739f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b0cb739f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b0cb739f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b0cb739f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b0cd9cef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b0ca6fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b0ca706be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b0ca4b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b0ca4b2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b0ca4b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b0ca4b2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b0ca4b2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b0ca4b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b0cedbcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b0cedc5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b0cedad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b0cedd8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ac9206082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0c86d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6,0x0,0xd2,0x84,0x3c,0x3c, Step #5: \006\000\322\204<< Step #5: artifact_prefix='./'; Test unit written to ./oom-44f413971140c2b0583b3466dd1ecf2dd55bc94d Step #5: Base64: BgDShDw8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 829 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2153592026 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559218b3a810, 0x559218d2401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559218d24020,0x55921abbc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/44f413971140c2b0583b3466dd1ecf2dd55bc94d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 920 processed earlier; will process 10109 files now Step #5: ==29878== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55920f62f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559215c94898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559215c775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559215c774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55920f635d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55920f596b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55920f591355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55920f627c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592125f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592125f6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592125f6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592125f6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592125f6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592125f6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592125f6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592125f6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592125f6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592125f6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55921488bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592115b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592115c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55921136fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55921136fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559211370738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55921136f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55921136f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55921136f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559215c79abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559215c82928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559215c6a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559215c95112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff3ae478082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55920f58fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x46,0x57,0x39,0x35,0x6a, Step #5: sFW95j Step #5: artifact_prefix='./'; Test unit written to ./oom-70136c5ee5947ec1f6be10968cdead9d8cb52cd2 Step #5: Base64: c0ZXOTVq Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 830 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2154013476 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c898867810, 0x55c898a5101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c898a51020,0x55c89a8e90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70136c5ee5947ec1f6be10968cdead9d8cb52cd2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 921 processed earlier; will process 10108 files now Step #5: ==29914== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c88f35c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8959c1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8959a45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8959a44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c88f362d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c88f2c3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c88f2be355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c88f354c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c892323f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c892323f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c892323f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c892323f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c892323f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c892323f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c892323f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c892323f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c892323f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c892323f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c8945b8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c8912e5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c8912f0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c89109cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c89109cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c89109d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c89109c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c89109c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c89109c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8959a6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8959af928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c895997699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8959c2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe77176c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c88f2bcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0xc6,0x86,0xc6,0x87,0x5d, Step #5: [\306\206\306\207] Step #5: artifact_prefix='./'; Test unit written to ./oom-cf21e2aba5085dde2a86fd8b420b36b1def8de2a Step #5: Base64: W8aGxodd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 831 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2154436081 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f203152810, 0x55f20333c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f20333c020,0x55f2051d40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf21e2aba5085dde2a86fd8b420b36b1def8de2a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 922 processed earlier; will process 10107 files now Step #5: ==29950== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f1f9c479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f2002ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f20028f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f20028f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f1f9c4dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f1f9baeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f1f9ba9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f1f9c3fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f1fcc0ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f1fcc0ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f1fcc0ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f1fcc0ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f1fcc0ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f1fcc0ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f1fcc0ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f1fcc0ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f1fcc0ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f1fcc0ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f1feea3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f1fbbd0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f1fbbdbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f1fb987c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f1fb987c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f1fb988738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f1fb987874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f1fb987874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f1fb987874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f200291abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f20029a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f200282699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f2002ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1025fab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f1f9ba7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0xd7,0xa9,0x1,0x37,0x6, Step #5: \001\327\251\0017\006 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb24c9c1d7c36a385d5863493d50fc7c22f87ab0 Step #5: Base64: AdepATcG Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 832 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2154867361 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556ea3fd8810, 0x556ea41c201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556ea41c2020,0x556ea605a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb24c9c1d7c36a385d5863493d50fc7c22f87ab0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 923 processed earlier; will process 10106 files now Step #5: ==29986== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556e9aacd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556ea1132898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556ea11155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556ea11154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556e9aad3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556e9aa34b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556e9aa2f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556e9aac5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556e9da94f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556e9da94f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556e9da94f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556e9da94f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556e9da94f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556e9da94f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556e9da94f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556e9da94f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556e9da94f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556e9da94f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556e9fd29f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556e9ca56b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556e9ca61be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556e9c80dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556e9c80dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556e9c80e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556e9c80d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556e9c80d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556e9c80d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556ea1117abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556ea1120928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556ea1108699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556ea1133112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f178c91f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556e9aa2db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x32,0x0,0x0,0x0,0x0, Step #5: \0012\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3a516e0104c615bca50fe3caf759707ca226914c Step #5: Base64: ATIAAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 833 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2155293484 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a270de810, 0x558a272c801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a272c8020,0x558a291600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a516e0104c615bca50fe3caf759707ca226914c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 924 processed earlier; will process 10105 files now Step #5: ==30022== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558a1dbd39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a24238898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a2421b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a2421b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a1dbd9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a1db3ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a1db35355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a1dbcbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a20b9af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a20b9af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a20b9af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a20b9af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a20b9af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a20b9af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a20b9af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a20b9af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a20b9af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a20b9af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a22e2ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a1fb5cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a1fb67be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a1f913c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a1f913c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a1f914738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a1f913874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a1f913874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a1f913874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a2421dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a24226928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a2420e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a24239112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b1be16082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a1db33b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2a,0xcc,0xa3,0x2a,0x2f, Step #5: /*\314\243*/ Step #5: artifact_prefix='./'; Test unit written to ./oom-58b310de9c0313c69c61389abedb09a493193893 Step #5: Base64: LyrMoyov Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 834 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2155704409 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5616ff0ab810, 0x5616ff29501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5616ff295020,0x56170112d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58b310de9c0313c69c61389abedb09a493193893' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 925 processed earlier; will process 10104 files now Step #5: #1 pulse cov: 3624 ft: 3625 exec/s: 0 rss: 159Mb Step #5: ==30058== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5616f5ba09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5616fc205898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5616fc1e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5616fc1e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5616f5ba6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5616f5b07b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5616f5b02355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5616f5b98c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5616f8b67f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5616f8b67f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5616f8b67f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5616f8b67f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5616f8b67f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5616f8b67f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5616f8b67f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5616f8b67f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5616f8b67f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5616f8b67f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5616fadfcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5616f7b29b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5616f7b34be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5616f78e0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5616f78e0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5616f78e1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5616f78e0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5616f78e0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5616f78e0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5616fc1eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5616fc1f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5616fc1db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5616fc206112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3d9228c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5616f5b00b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x60,0x23,0x1,0x0,0x60, Step #5: \000`#\001\000` Step #5: artifact_prefix='./'; Test unit written to ./oom-aadcf38a8686fc472c96dd746664d98a0e1c582b Step #5: Base64: AGAjAQBg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 835 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2156291003 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564b965df810, 0x564b967c901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564b967c9020,0x564b986610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aadcf38a8686fc472c96dd746664d98a0e1c582b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 927 processed earlier; will process 10102 files now Step #5: ==30094== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564b8d0d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564b93739898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564b9371c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564b9371c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564b8d0dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564b8d03bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564b8d036355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564b8d0ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564b9009bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564b9009bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564b9009bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564b9009bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564b9009bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564b9009bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564b9009bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564b9009bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564b9009bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564b9009bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564b92330f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564b8f05db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564b8f068be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564b8ee14c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564b8ee14c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564b8ee15738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564b8ee14874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564b8ee14874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564b8ee14874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564b9371eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564b93727928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564b9370f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564b9373a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0e7289f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564b8d034b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x61,0x72,0x65,0x61,0x3e, Step #5: Step #5: artifact_prefix='./'; Test unit written to ./oom-3dcbab061d2ad84afb746b0610322947adcfabe7 Step #5: Base64: PGFyZWE+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 836 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2156707030 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b628cb7810, 0x55b628ea101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b628ea1020,0x55b62ad390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3dcbab061d2ad84afb746b0610322947adcfabe7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 928 processed earlier; will process 10101 files now Step #5: ==30130== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b61f7ac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b625e11898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b625df45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b625df44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b61f7b2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b61f713b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b61f70e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b61f7a4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b622773f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b622773f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b622773f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b622773f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b622773f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b622773f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b622773f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b622773f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b622773f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b622773f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b624a08f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b621735b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b621740be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6214ecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6214ecc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6214ed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6214ec874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6214ec874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6214ec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b625df6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b625dff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b625de7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b625e12112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b1cfd9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b61f70cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x2e,0xcd,0x8f,0x22,0x34, Step #5: 1.\315\217\"4 Step #5: artifact_prefix='./'; Test unit written to ./oom-6959fa9b374ff2a94f4899c27f5f31be85ed7bd0 Step #5: Base64: MS7NjyI0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 837 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2157134882 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562721cc9810, 0x562721eb301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562721eb3020,0x562723d4b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6959fa9b374ff2a94f4899c27f5f31be85ed7bd0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 929 processed earlier; will process 10100 files now Step #5: ==30166== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5627187be9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56271ee23898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56271ee065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56271ee064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5627187c4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562718725b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562718720355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5627187b6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56271b785f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56271b785f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56271b785f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56271b785f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56271b785f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56271b785f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56271b785f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56271b785f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56271b785f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56271b785f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56271da1af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56271a747b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56271a752be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56271a4fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56271a4fec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56271a4ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56271a4fe874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56271a4fe874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56271a4fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56271ee08abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56271ee11928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56271edf9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56271ee24112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a2b6b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56271871eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x42,0x27,0x27,0x2b,0x2d, Step #5: -B''+- Step #5: artifact_prefix='./'; Test unit written to ./oom-03a274d2734999acf001412787b7798114aea702 Step #5: Base64: LUInJyst Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 838 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2157563852 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc78cd0810, 0x55cc78eba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc78eba020,0x55cc7ad520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03a274d2734999acf001412787b7798114aea702' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 930 processed earlier; will process 10099 files now Step #5: #1 pulse cov: 3731 ft: 3732 exec/s: 0 rss: 161Mb Step #5: #2 pulse cov: 3843 ft: 4368 exec/s: 0 rss: 162Mb Step #5: ==30202== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cc6f7c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc75e2a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc75e0d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc75e0d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc6f7cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc6f72cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc6f727355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc6f7bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc7278cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc7278cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc7278cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc7278cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc7278cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc7278cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc7278cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc7278cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc7278cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc7278cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc74a21f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc7174eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc71759be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc71505c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc71505c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc71506738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc71505874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc71505874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc71505874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc75e0fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc75e18928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc75e00699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc75e2b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff8817db082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc6f725b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x46,0x4,0x43,0x24,0x32, Step #5: $F\004C$2 Step #5: artifact_prefix='./'; Test unit written to ./oom-c88a2c93c1e9a1354b60f2ee81b6219af8f7a383 Step #5: Base64: JEYEQyQy Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 839 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2158068642 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ba538c810, 0x559ba557601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ba5576020,0x559ba740e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c88a2c93c1e9a1354b60f2ee81b6219af8f7a383' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 933 processed earlier; will process 10096 files now Step #5: #1 pulse cov: 9001 ft: 9002 exec/s: 0 rss: 177Mb Step #5: ==30238== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559b9be819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ba24e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ba24c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ba24c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b9be87d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b9bde8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b9bde3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b9be79c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b9ee48f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b9ee48f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b9ee48f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b9ee48f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b9ee48f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b9ee48f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b9ee48f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b9ee48f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b9ee48f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b9ee48f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ba10ddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b9de0ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b9de15be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b9dbc1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b9dbc1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b9dbc2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b9dbc1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b9dbc1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b9dbc1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ba24cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ba24d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ba24bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ba24e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc4b1256082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b9bde1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7f,0x30,0xdb,0xa4,0x10,0x42, Step #5: \1770\333\244\020B Step #5: artifact_prefix='./'; Test unit written to ./oom-d343a7563205523bd6efd924b6d897bd9ee07c4e Step #5: Base64: fzDbpBBC Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 840 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2158557274 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5641aefc7810, 0x5641af1b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5641af1b1020,0x5641b10490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d343a7563205523bd6efd924b6d897bd9ee07c4e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 935 processed earlier; will process 10094 files now Step #5: ==30274== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5641a5abc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5641ac121898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5641ac1045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5641ac1044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5641a5ac2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641a5a23b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641a5a1e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5641a5ab4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5641a8a83f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5641a8a83f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5641a8a83f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5641a8a83f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5641a8a83f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5641a8a83f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5641a8a83f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5641a8a83f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5641a8a83f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5641a8a83f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5641aad18f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5641a7a45b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5641a7a50be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5641a77fcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5641a77fcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5641a77fd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5641a77fc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5641a77fc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5641a77fc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5641ac106abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5641ac10f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5641ac0f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5641ac122112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f13b2b70082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641a5a1cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x74,0x3e,0x3c,0x2f,0x74, Step #5: Step #5: Step #5: #0 0x55b3f8ee39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b3ff548898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b3ff52b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b3ff52b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b3f8ee9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b3f8e4ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b3f8e45355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b3f8edbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b3fbeaaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b3fbeaaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b3fbeaaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b3fbeaaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b3fbeaaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b3fbeaaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b3fbeaaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b3fbeaaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b3fbeaaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b3fbeaaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b3fe13ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b3fae6cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b3fae77be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b3fac23c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b3fac23c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b3fac24738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b3fac23874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b3fac23874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b3fac23874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b3ff52dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b3ff536928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b3ff51e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b3ff549112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4e5bdc2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b3f8e43b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x84,0xf0,0x91,0x91,0x86, Step #5: \315\204\360\221\221\206 Step #5: artifact_prefix='./'; Test unit written to ./oom-36a1323589f26cd04254dad9ad4fbb4b45166ee3 Step #5: Base64: zYTwkZGG Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 842 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2159421892 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b05bd8810, 0x561b05dc201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b05dc2020,0x561b07c5a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/36a1323589f26cd04254dad9ad4fbb4b45166ee3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 937 processed earlier; will process 10092 files now Step #5: ==30346== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561afc6cd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b02d32898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b02d155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b02d154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561afc6d3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561afc634b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561afc62f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561afc6c5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561aff694f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561aff694f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561aff694f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561aff694f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561aff694f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561aff694f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561aff694f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561aff694f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561aff694f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561aff694f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b01929f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561afe656b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561afe661be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561afe40dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561afe40dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561afe40e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561afe40d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561afe40d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561afe40d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b02d17abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b02d20928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b02d08699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b02d33112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e3ae8e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561afc62db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0xf4,0x84,0x9f,0xbf,0x27, Step #5: '\364\204\237\277' Step #5: artifact_prefix='./'; Test unit written to ./oom-15e30fba0cced1184a1713de616c75f583562164 Step #5: Base64: J/SEn78n Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 843 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2159854336 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dba1070810, 0x55dba125a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dba125a020,0x55dba30f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/15e30fba0cced1184a1713de616c75f583562164' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 938 processed earlier; will process 10091 files now Step #5: #1 pulse cov: 3650 ft: 3651 exec/s: 0 rss: 159Mb Step #5: #2 pulse cov: 3889 ft: 4123 exec/s: 0 rss: 160Mb Step #5: ==30382== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55db97b659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db9e1ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db9e1ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db9e1ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db97b6bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db97accb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db97ac7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db97b5dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db9ab2cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db9ab2cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db9ab2cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db9ab2cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db9ab2cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db9ab2cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db9ab2cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db9ab2cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db9ab2cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db9ab2cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db9cdc1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db99aeeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db99af9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db998a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db998a5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db998a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db998a5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db998a5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db998a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db9e1afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db9e1b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db9e1a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db9e1cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6c66a94082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db97ac5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xef,0xb8,0xab, Step #5: ws:\357\270\253 Step #5: artifact_prefix='./'; Test unit written to ./oom-58dfde0c1d08d85fcab1466af66358849ae3e1d8 Step #5: Base64: d3M677ir Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 844 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2160364649 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f66642e810, 0x55f66661801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f666618020,0x55f6684b00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58dfde0c1d08d85fcab1466af66358849ae3e1d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 941 processed earlier; will process 10088 files now Step #5: ==30418== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f65cf239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f663588898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f66356b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f66356b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f65cf29d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f65ce8ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f65ce85355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f65cf1bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f65feeaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f65feeaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f65feeaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f65feeaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f65feeaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f65feeaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f65feeaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f65feeaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f65feeaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f65feeaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f66217ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f65eeacb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f65eeb7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f65ec63c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f65ec63c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f65ec64738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f65ec63874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f65ec63874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f65ec63874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f66356dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f663576928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f66355e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f663589112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f950d2d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f65ce83b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x49,0x4c,0x45,0x20,0x4c, Step #5: FILE L Step #5: artifact_prefix='./'; Test unit written to ./oom-e6df15100d07020fe3bfa1328ae3f97d033dd672 Step #5: Base64: RklMRSBM Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 845 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2160800449 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652b6aa4810, 0x5652b6c8e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652b6c8e020,0x5652b8b260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e6df15100d07020fe3bfa1328ae3f97d033dd672' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 942 processed earlier; will process 10087 files now Step #5: ==30454== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5652ad5999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652b3bfe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652b3be15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652b3be14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5652ad59fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5652ad500b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5652ad4fb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5652ad591c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5652b0560f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5652b0560f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5652b0560f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5652b0560f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5652b0560f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5652b0560f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5652b0560f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5652b0560f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5652b0560f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5652b0560f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652b27f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5652af522b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5652af52dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652af2d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652af2d9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652af2da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652af2d9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652af2d9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652af2d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652b3be3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652b3bec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652b3bd4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652b3bff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f86e9aea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5652ad4f9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x50,0x7b,0xef,0x96,0xa0, Step #5: \\P{\357\226\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-a21b3d55714462ef6456cb8c3e3ef4e170205474 Step #5: Base64: XFB775ag Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 846 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2161233361 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a75c863810, 0x55a75ca4d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a75ca4d020,0x55a75e8e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a21b3d55714462ef6456cb8c3e3ef4e170205474' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 943 processed earlier; will process 10086 files now Step #5: #1 pulse cov: 3741 ft: 3742 exec/s: 0 rss: 160Mb Step #5: ==30490== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a7533589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a7599bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a7599a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a7599a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a75335ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a7532bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a7532ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a753350c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a75631ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a75631ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a75631ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a75631ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a75631ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a75631ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a75631ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a75631ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a75631ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a75631ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a7585b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a7552e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a7552ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a755098c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a755098c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a755099738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a755098874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a755098874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a755098874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a7599a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a7599ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a759993699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a7599be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f757b8d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a7532b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2c,0x27,0x27,0x27,0x27,0x27, Step #5: ,''''' Step #5: artifact_prefix='./'; Test unit written to ./oom-96955d57135dbb8488ee700b3f4b3d4e540bf30d Step #5: Base64: LCcnJycn Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 847 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2161705558 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5556a1a06810, 0x5556a1bf001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5556a1bf0020,0x5556a3a880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/96955d57135dbb8488ee700b3f4b3d4e540bf30d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 945 processed earlier; will process 10084 files now Step #5: #1 pulse cov: 10303 ft: 10304 exec/s: 0 rss: 179Mb Step #5: ==30526== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5556984fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55569eb60898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55569eb435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55569eb434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555698501d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555698462b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55569845d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5556984f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55569b4c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55569b4c2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55569b4c2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55569b4c2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55569b4c2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55569b4c2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55569b4c2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55569b4c2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55569b4c2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55569b4c2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55569d757f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55569a484b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55569a48fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55569a23bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55569a23bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55569a23c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55569a23b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55569a23b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55569a23b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55569eb45abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55569eb4e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55569eb36699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55569eb61112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f45b8a14082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55569845bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0xc7,0xb2,0xc7,0xb3,0x5d, Step #5: [\307\262\307\263] Step #5: artifact_prefix='./'; Test unit written to ./oom-67cf5d67bf8fbb849fe8fec5fdc53e501d18394a Step #5: Base64: W8eyx7Nd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 848 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2162198985 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55764ac86810, 0x55764ae7001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55764ae70020,0x55764cd080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/67cf5d67bf8fbb849fe8fec5fdc53e501d18394a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 947 processed earlier; will process 10082 files now Step #5: ==30562== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55764177b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557647de0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557647dc35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557647dc34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557641781d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5576416e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5576416dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557641773c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557644742f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557644742f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557644742f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557644742f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557644742f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557644742f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557644742f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557644742f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557644742f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557644742f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5576469d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557643704b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55764370fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5576434bbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5576434bbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5576434bc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5576434bb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5576434bb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5576434bb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557647dc5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557647dce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557647db6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557647de1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8da03f3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5576416dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x83,0xbd,0xe1,0x83,0xbd, Step #5: \341\203\275\341\203\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-b541e5deaafd1b68bf33691073bebba97274ead9 Step #5: Base64: 4YO94YO9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 849 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2162635857 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ebe6d0810, 0x555ebe8ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ebe8ba020,0x555ec07520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b541e5deaafd1b68bf33691073bebba97274ead9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 948 processed earlier; will process 10081 files now Step #5: ==30598== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555eb51c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ebb82a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ebb80d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ebb80d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555eb51cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555eb512cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555eb5127355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555eb51bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555eb818cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555eb818cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555eb818cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555eb818cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555eb818cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555eb818cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555eb818cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555eb818cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555eb818cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555eb818cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555eba421f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555eb714eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555eb7159be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555eb6f05c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555eb6f05c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555eb6f06738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555eb6f05874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555eb6f05874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555eb6f05874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ebb80fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ebb818928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ebb800699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ebb82b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f560b1e0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555eb5125b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0x2e,0x7c,0x2e,0x2e,0x1f, Step #5: ..|..\037 Step #5: artifact_prefix='./'; Test unit written to ./oom-c50b208b8ff04b0e83a06dd4ee2655d90d867d81 Step #5: Base64: Li58Li4f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 850 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2163066065 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f0ed53f810, 0x55f0ed72901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f0ed729020,0x55f0ef5c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c50b208b8ff04b0e83a06dd4ee2655d90d867d81' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 949 processed earlier; will process 10080 files now Step #5: ==30634== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f0e40349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f0ea699898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f0ea67c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f0ea67c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f0e403ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f0e3f9bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f0e3f96355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f0e402cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f0e6ffbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f0e6ffbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f0e6ffbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f0e6ffbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f0e6ffbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f0e6ffbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f0e6ffbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f0e6ffbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f0e6ffbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f0e6ffbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f0e9290f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f0e5fbdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f0e5fc8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f0e5d74c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f0e5d74c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f0e5d75738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f0e5d74874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f0e5d74874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f0e5d74874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f0ea67eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f0ea687928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f0ea66f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f0ea69a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c45427082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f0e3f94b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x52,0x45,0x47,0x49,0x4f,0x8d, Step #5: REGIO\215 Step #5: artifact_prefix='./'; Test unit written to ./oom-66b1553de718f2952fece3cc8b7065784b1e7d56 Step #5: Base64: UkVHSU+N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 851 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2163499363 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5607c445a810, 0x5607c464401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5607c4644020,0x5607c64dc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/66b1553de718f2952fece3cc8b7065784b1e7d56' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 950 processed earlier; will process 10079 files now Step #5: ==30670== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5607baf4f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5607c15b4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5607c15975dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5607c15974fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5607baf55d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5607baeb6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5607baeb1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5607baf47c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5607bdf16f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5607bdf16f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5607bdf16f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5607bdf16f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5607bdf16f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5607bdf16f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5607bdf16f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5607bdf16f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5607bdf16f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5607bdf16f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5607c01abf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5607bced8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5607bcee3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5607bcc8fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5607bcc8fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5607bcc90738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5607bcc8f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5607bcc8f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5607bcc8f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5607c1599abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5607c15a2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5607c158a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5607c15b5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f35c6ddf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5607baeafb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x5a,0x5b,0xdf,0xbf,0x5d, Step #5: -Z[\337\277] Step #5: artifact_prefix='./'; Test unit written to ./oom-919517906c6ee9e5bf27d3533fd17048f7e8a82c Step #5: Base64: LVpb379d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 852 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2163936783 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5600059e6810, 0x560005bd001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560005bd0020,0x560007a680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/919517906c6ee9e5bf27d3533fd17048f7e8a82c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 951 processed earlier; will process 10078 files now Step #5: ==30706== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fffc4db9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560002b40898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560002b235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560002b234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fffc4e1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fffc442b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fffc43d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fffc4d3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ffff4a2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ffff4a2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ffff4a2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ffff4a2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ffff4a2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ffff4a2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ffff4a2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ffff4a2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ffff4a2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ffff4a2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560001737f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fffe464b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fffe46fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fffe21bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fffe21bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fffe21c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fffe21b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fffe21b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fffe21b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560002b25abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560002b2e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560002b16699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560002b41112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6fd37b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fffc43bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7f,0x68,0x24,0x0,0x8,0x24, Step #5: \177h$\000\010$ Step #5: artifact_prefix='./'; Test unit written to ./oom-ac9d1e5c94596574f3643de6e43b53afcbbc3b47 Step #5: Base64: f2gkAAgk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 853 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2164375751 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db45ad4810, 0x55db45cbe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db45cbe020,0x55db47b560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ac9d1e5c94596574f3643de6e43b53afcbbc3b47' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 952 processed earlier; will process 10077 files now Step #5: ==30742== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55db3c5c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db42c2e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db42c115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db42c114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db3c5cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db3c530b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db3c52b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db3c5c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db3f590f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db3f590f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db3f590f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db3f590f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db3f590f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db3f590f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db3f590f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db3f590f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db3f590f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db3f590f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db41825f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db3e552b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db3e55dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db3e309c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db3e309c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db3e30a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db3e309874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db3e309874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db3e309874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db42c13abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db42c1c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db42c04699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db42c2f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa6f5887082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db3c529b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0xea,0xa2,0xa9,0xff,0x8a, Step #5: \003\352\242\251\377\212 Step #5: artifact_prefix='./'; Test unit written to ./oom-12acf9ca82f54c8df9fe39ce9dbd4e9527a3e0de Step #5: Base64: A+qiqf+K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 854 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2164807978 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e968c8810, 0x562e96ab201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e96ab2020,0x562e9894a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/12acf9ca82f54c8df9fe39ce9dbd4e9527a3e0de' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 953 processed earlier; will process 10076 files now Step #5: ==30778== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562e8d3bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e93a22898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e93a055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e93a054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e8d3c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e8d324b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e8d31f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e8d3b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e90384f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e90384f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e90384f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e90384f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e90384f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e90384f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e90384f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e90384f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e90384f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e90384f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e92619f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e8f346b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e8f351be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e8f0fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e8f0fdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e8f0fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e8f0fd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e8f0fd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e8f0fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e93a07abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e93a10928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e939f8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e93a23112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f392d07f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e8d31db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc5,0xb6,0xc4,0xb6,0xc4,0xa3, Step #5: \305\266\304\266\304\243 Step #5: artifact_prefix='./'; Test unit written to ./oom-ab945a53bb5f6bc201af2b028aba7a9792ee61d1 Step #5: Base64: xbbEtsSj Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 855 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2165245310 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555875eb0810, 0x55587609a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55587609a020,0x555877f320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ab945a53bb5f6bc201af2b028aba7a9792ee61d1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 954 processed earlier; will process 10075 files now Step #5: ==30814== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55586c9a59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55587300a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555872fed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555872fed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55586c9abd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55586c90cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55586c907355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55586c99dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55586f96cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55586f96cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55586f96cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55586f96cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55586f96cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55586f96cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55586f96cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55586f96cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55586f96cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55586f96cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555871c01f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55586e92eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55586e939be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55586e6e5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55586e6e5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55586e6e6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55586e6e5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55586e6e5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55586e6e5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555872fefabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555872ff8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555872fe0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55587300b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5091fc2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55586c905b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x46,0xa,0xa,0xa,0x2e,0x30, Step #5: PF\012\012\012.0 Step #5: artifact_prefix='./'; Test unit written to ./oom-842f0eb0a5bc0b31f0f69125c2bf97e80661b238 Step #5: Base64: UEYKCgouMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 856 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2165681010 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5638d2079810, 0x5638d226301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5638d2263020,0x5638d40fb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/842f0eb0a5bc0b31f0f69125c2bf97e80661b238' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 955 processed earlier; will process 10074 files now Step #5: ==30850== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5638c8b6e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5638cf1d3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5638cf1b65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5638cf1b64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5638c8b74d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5638c8ad5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5638c8ad0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5638c8b66c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5638cbb35f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5638cbb35f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5638cbb35f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5638cbb35f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5638cbb35f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5638cbb35f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5638cbb35f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5638cbb35f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5638cbb35f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5638cbb35f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5638cddcaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5638caaf7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5638cab02be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5638ca8aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5638ca8aec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5638ca8af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5638ca8ae874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5638ca8ae874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5638ca8ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5638cf1b8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5638cf1c1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5638cf1a9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5638cf1d4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d07ca0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5638c8aceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xba,0xbd,0x7c,0xef,0xbf,0xa5, Step #5: \357\272\275|\357\277\245 Step #5: artifact_prefix='./'; Test unit written to ./oom-f2118727055f7cf3c22b20761932c67283c85b31 Step #5: Base64: 77q9fO+/pQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 857 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2166121971 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f546957810, 0x55f546b4101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f546b41020,0x55f5489d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f2118727055f7cf3c22b20761932c67283c85b31' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 956 processed earlier; will process 10073 files now Step #5: ==30886== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f53d44c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f543ab1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f543a945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f543a944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f53d452d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f53d3b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f53d3ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f53d444c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f540413f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f540413f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f540413f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f540413f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f540413f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f540413f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f540413f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f540413f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f540413f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f540413f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f5426a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f53f3d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f53f3e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f53f18cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f53f18cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f53f18d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f53f18c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f53f18c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f53f18c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f543a96abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f543a9f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f543a87699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f543ab2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7265df3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f53d3acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x35,0x2b,0x30,0x2c,0x36,0x2b,0x2b, Step #5: 5+0,6++ Step #5: artifact_prefix='./'; Test unit written to ./oom-32c1c2b01ac6de76d945a4a6d27086e4e763ae66 Step #5: Base64: NSswLDYrKw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 858 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2166558024 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc347aa810, 0x55fc3499401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc34994020,0x55fc3682c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/32c1c2b01ac6de76d945a4a6d27086e4e763ae66' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 957 processed earlier; will process 10072 files now Step #5: #1 pulse cov: 3697 ft: 3698 exec/s: 0 rss: 162Mb Step #5: ==30922== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fc2b29f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc31904898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc318e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc318e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc2b2a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc2b206b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc2b201355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc2b297c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc2e266f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc2e266f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc2e266f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc2e266f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc2e266f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc2e266f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc2e266f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc2e266f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc2e266f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc2e266f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc304fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc2d228b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc2d233be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc2cfdfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc2cfdfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc2cfe0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc2cfdf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc2cfdf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc2cfdf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc318e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc318f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc318da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc31905112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff49bd6e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc2b1ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x21,0x0,0x21,0x6,0x0,0xd7, Step #5: \001!\000!\006\000\327 Step #5: artifact_prefix='./'; Test unit written to ./oom-de38d05d869c90e417bf0eb302e68cb8cbef63d3 Step #5: Base64: ASEAIQYA1w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 859 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2167046464 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e94533810, 0x563e9471d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e9471d020,0x563e965b50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de38d05d869c90e417bf0eb302e68cb8cbef63d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 959 processed earlier; will process 10070 files now Step #5: ==30958== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563e8b0289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e9168d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e916705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e916704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e8b02ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e8af8fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e8af8a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e8b020c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e8dfeff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e8dfeff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e8dfeff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e8dfeff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e8dfeff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e8dfeff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e8dfeff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e8dfeff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e8dfeff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e8dfeff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e90284f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e8cfb1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e8cfbcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e8cd68c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e8cd68c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e8cd69738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e8cd68874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e8cd68874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e8cd68874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e91672abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e9167b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e91663699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e9168e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f84d6dc3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e8af88b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x0,0x2d,0xef,0xb3,0xb3,0x5d, Step #5: [\000-\357\263\263] Step #5: artifact_prefix='./'; Test unit written to ./oom-a20c62d63fc9d3f82d33a0aea6e9a7375fb3e7a7 Step #5: Base64: WwAt77OzXQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 860 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2167477475 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c2aca9a810, 0x55c2acc8401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c2acc84020,0x55c2aeb1c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a20c62d63fc9d3f82d33a0aea6e9a7375fb3e7a7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 960 processed earlier; will process 10069 files now Step #5: ==30994== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c2a358f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c2a9bf4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c2a9bd75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c2a9bd74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c2a3595d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c2a34f6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c2a34f1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c2a3587c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c2a6556f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c2a6556f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c2a6556f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c2a6556f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c2a6556f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c2a6556f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c2a6556f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c2a6556f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c2a6556f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c2a6556f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c2a87ebf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c2a5518b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c2a5523be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c2a52cfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c2a52cfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c2a52d0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c2a52cf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c2a52cf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c2a52cf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c2a9bd9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c2a9be2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c2a9bca699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c2a9bf5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf42af4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c2a34efb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x5c,0x75,0x7b,0x37,0x32,0x7d, Step #5: \"\\u{72} Step #5: artifact_prefix='./'; Test unit written to ./oom-58d18d9e9b15027bb6b5204d2b083a0c20076876 Step #5: Base64: Ilx1ezcyfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 861 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2167909465 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd0752c810, 0x55dd0771601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd07716020,0x55dd095ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58d18d9e9b15027bb6b5204d2b083a0c20076876' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 961 processed earlier; will process 10068 files now Step #5: #1 pulse cov: 3455 ft: 3456 exec/s: 0 rss: 159Mb Step #5: ==31030== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dcfe0219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd04686898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd046695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd046694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dcfe027d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dcfdf88b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dcfdf83355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dcfe019c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd00fe8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd00fe8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd00fe8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd00fe8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd00fe8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd00fe8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd00fe8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd00fe8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd00fe8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd00fe8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd0327df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dcfffaab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dcfffb5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dcffd61c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dcffd61c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dcffd62738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dcffd61874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dcffd61874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dcffd61874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd0466babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd04674928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd0465c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd04687112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f69e5c42082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dcfdf81b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x38,0x58,0x25,0x58,0x5e,0x32,0x30, Step #5: 8X%X^20 Step #5: artifact_prefix='./'; Test unit written to ./oom-4484375688a2c04f281240d86738fb564c946235 Step #5: Base64: OFglWF4yMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 862 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2168381265 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ebe294810, 0x562ebe47e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ebe47e020,0x562ec03160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4484375688a2c04f281240d86738fb564c946235' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 963 processed earlier; will process 10066 files now Step #5: ==31066== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562eb4d899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ebb3ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ebb3d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ebb3d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562eb4d8fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562eb4cf0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562eb4ceb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562eb4d81c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562eb7d50f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562eb7d50f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562eb7d50f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562eb7d50f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562eb7d50f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562eb7d50f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562eb7d50f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562eb7d50f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562eb7d50f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562eb7d50f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562eb9fe5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562eb6d12b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562eb6d1dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562eb6ac9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562eb6ac9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562eb6aca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562eb6ac9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562eb6ac9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562eb6ac9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ebb3d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ebb3dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ebb3c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ebb3ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9d187b0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562eb4ce9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x88,0x49,0xa,0xcd,0x88,0x43, Step #5: \315\210I\012\315\210C Step #5: artifact_prefix='./'; Test unit written to ./oom-2b7e812cbb66eacd8534785d95152e9b60da0d6c Step #5: Base64: zYhJCs2IQw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 863 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2168813510 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0edacb810, 0x55b0edcb501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b0edcb5020,0x55b0efb4d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2b7e812cbb66eacd8534785d95152e9b60da0d6c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 964 processed earlier; will process 10065 files now Step #5: #1 pulse cov: 3512 ft: 3513 exec/s: 0 rss: 161Mb Step #5: ==31102== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b0e45c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b0eac25898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b0eac085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b0eac084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0e45c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0e4527b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0e4522355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0e45b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b0e7587f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b0e7587f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b0e7587f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b0e7587f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b0e7587f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b0e7587f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b0e7587f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b0e7587f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b0e7587f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b0e7587f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b0e981cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b0e6549b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b0e6554be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b0e6300c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b0e6300c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b0e6301738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b0e6300874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b0e6300874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b0e6300874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b0eac0aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b0eac13928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b0eabfb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b0eac26112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa745b78082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0e4520b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd6,0xac,0x51,0x37,0xd6,0xac,0x51, Step #5: \326\254Q7\326\254Q Step #5: artifact_prefix='./'; Test unit written to ./oom-276e7efab12337f0bfaaadfa4e1bba7412ab44aa Step #5: Base64: 1qxRN9asUQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 864 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2169293540 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c053b8d810, 0x55c053d7701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c053d77020,0x55c055c0f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/276e7efab12337f0bfaaadfa4e1bba7412ab44aa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 966 processed earlier; will process 10063 files now Step #5: ==31138== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c04a6829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c050ce7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c050cca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c050cca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c04a688d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c04a5e9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c04a5e4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c04a67ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c04d649f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c04d649f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c04d649f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c04d649f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c04d649f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c04d649f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c04d649f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c04d649f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c04d649f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c04d649f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c04f8def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c04c60bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c04c616be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c04c3c2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c04c3c2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c04c3c3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c04c3c2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c04c3c2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c04c3c2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c050cccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c050cd5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c050cbd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c050ce8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f0cb0d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c04a5e2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x27,0x5c,0xef,0xbb,0x8a,0x27, Step #5: e'\\\357\273\212' Step #5: artifact_prefix='./'; Test unit written to ./oom-80bea5b5372a79e5492623db195e0bc2a8851399 Step #5: Base64: ZSdc77uKJw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 865 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2169732437 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a97297d810, 0x55a972b6701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a972b67020,0x55a9749ff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/80bea5b5372a79e5492623db195e0bc2a8851399' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 967 processed earlier; will process 10062 files now Step #5: ==31174== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a9694729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a96fad7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a96faba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a96faba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a969478d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a9693d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a9693d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a96946ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a96c439f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a96c439f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a96c439f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a96c439f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a96c439f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a96c439f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a96c439f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a96c439f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a96c439f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a96c439f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a96e6cef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a96b3fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a96b406be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a96b1b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a96b1b2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a96b1b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a96b1b2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a96b1b2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a96b1b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a96fabcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a96fac5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a96faad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a96fad8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdbe6702082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a9693d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d, Step #5: - - - - Step #5: artifact_prefix='./'; Test unit written to ./oom-93233da6c2a34e4792b6ceadfca5b7ab0dd90bf1 Step #5: Base64: LSAtIC0gLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 866 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2170168178 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7fbbb3810, 0x55b7fbd9d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7fbd9d020,0x55b7fdc350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93233da6c2a34e4792b6ceadfca5b7ab0dd90bf1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 968 processed earlier; will process 10061 files now Step #5: ==31210== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b7f26a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b7f8d0d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b7f8cf05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b7f8cf04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b7f26aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b7f260fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b7f260a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b7f26a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b7f566ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b7f566ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b7f566ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b7f566ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b7f566ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b7f566ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b7f566ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b7f566ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b7f566ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b7f566ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b7f7904f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b7f4631b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b7f463cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b7f43e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b7f43e8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b7f43e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b7f43e8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b7f43e8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b7f43e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b7f8cf2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b7f8cfb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b7f8ce3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b7f8d0e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc9f4837082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b7f2608b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xea,0xab,0x81,0xcc,0x81,0xcc,0xb8, Step #5: \352\253\201\314\201\314\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-35e621411d51c555080b88552170d77c3d2857f3 Step #5: Base64: 6quBzIHMuA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 867 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2170595580 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d516002810, 0x55d5161ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d5161ec020,0x55d5180840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/35e621411d51c555080b88552170d77c3d2857f3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 969 processed earlier; will process 10060 files now Step #5: ==31246== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d50caf79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d51315c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d51313f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d51313f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d50cafdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d50ca5eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d50ca59355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d50caefc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d50fabef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d50fabef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d50fabef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d50fabef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d50fabef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d50fabef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d50fabef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d50fabef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d50fabef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d50fabef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d511d53f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d50ea80b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d50ea8bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d50e837c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d50e837c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d50e838738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d50e837874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d50e837874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d50e837874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d513141abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d51314a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d513132699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d51315d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9823ff9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d50ca57b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x3,0xef,0xbc,0x81, Step #5: \000\000\000\003\357\274\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-26767974cb5d6118798bd0c52620500af6dd14de Step #5: Base64: AAAAA++8gQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 868 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2171028950 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55888827b810, 0x55888846501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558888465020,0x55888a2fd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/26767974cb5d6118798bd0c52620500af6dd14de' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 970 processed earlier; will process 10059 files now Step #5: #1 pulse cov: 3489 ft: 3490 exec/s: 0 rss: 159Mb Step #5: ==31282== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55887ed709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5588853d5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588853b85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588853b84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55887ed76d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55887ecd7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55887ecd2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55887ed68c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558881d37f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558881d37f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558881d37f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558881d37f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558881d37f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558881d37f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558881d37f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558881d37f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558881d37f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558881d37f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558883fccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558880cf9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558880d04be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558880ab0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558880ab0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558880ab1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558880ab0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558880ab0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558880ab0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5588853baabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5588853c3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5588853ab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5588853d6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe9b50ac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55887ecd0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0x2e,0x2d,0x2e,0x2e,0xa,0x2b, Step #5: ..-..\012+ Step #5: artifact_prefix='./'; Test unit written to ./oom-1b0ff3c3ecaeace0c9a1d31b30863198567c0eca Step #5: Base64: Li4tLi4KKw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 869 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2171501656 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f738d9810, 0x556f73ac301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f73ac3020,0x556f7595b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b0ff3c3ecaeace0c9a1d31b30863198567c0eca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 972 processed earlier; will process 10057 files now Step #5: ==31318== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556f6a3ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f70a33898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f70a165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f70a164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f6a3d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f6a335b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f6a330355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f6a3c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f6d395f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f6d395f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f6d395f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f6d395f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f6d395f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f6d395f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f6d395f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f6d395f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f6d395f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f6d395f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f6f62af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f6c357b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f6c362be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f6c10ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f6c10ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f6c10f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f6c10e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f6c10e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f6c10e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f70a18abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f70a21928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f70a09699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f70a34112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1519cf2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f6a32eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x28,0x3f,0x69,0x29,0xce,0xbc, Step #5: ^(?i)\316\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-bba3789b23017637aaf75069b18cc430022cf21c Step #5: Base64: Xig/aSnOvA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 870 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2171935328 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560559374810, 0x56055955e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56055955e020,0x56055b3f60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bba3789b23017637aaf75069b18cc430022cf21c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 973 processed earlier; will process 10056 files now Step #5: ==31354== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56054fe699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605564ce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605564b15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605564b14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56054fe6fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56054fdd0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56054fdcb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56054fe61c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560552e30f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560552e30f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560552e30f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560552e30f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560552e30f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560552e30f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560552e30f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560552e30f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560552e30f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560552e30f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605550c5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560551df2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560551dfdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560551ba9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560551ba9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560551baa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560551ba9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560551ba9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560551ba9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605564b3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5605564bc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605564a4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605564cf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc262f4d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56054fdc9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3d,0xa,0x60,0xa,0x60,0x3d, Step #5: ==\012`\012`= Step #5: artifact_prefix='./'; Test unit written to ./oom-425a66ac08ce48ca266d441e2c8c51e7c3a21e60 Step #5: Base64: PT0KYApgPQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 871 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2172490316 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559d88213810, 0x559d883fd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559d883fd020,0x559d8a2950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/425a66ac08ce48ca266d441e2c8c51e7c3a21e60' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 974 processed earlier; will process 10055 files now Step #5: #1 pulse cov: 3509 ft: 3510 exec/s: 0 rss: 163Mb Step #5: ==31390== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559d7ed089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559d8536d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559d853505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559d853504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559d7ed0ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559d7ec6fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559d7ec6a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559d7ed00c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559d81ccff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559d81ccff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559d81ccff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559d81ccff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559d81ccff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559d81ccff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559d81ccff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559d81ccff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559d81ccff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559d81ccff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559d83f64f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559d80c91b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559d80c9cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559d80a48c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559d80a48c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559d80a49738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559d80a48874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559d80a48874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559d80a48874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559d85352abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559d8535b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559d85343699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559d8536e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9157c0c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559d7ec68b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0xb2,0xb2,0xe0,0xb2,0xb6, Step #5: \363\240\262\262\340\262\266 Step #5: artifact_prefix='./'; Test unit written to ./oom-20d6d20a922c5539c9c1a511196b01abc5ae1b57 Step #5: Base64: 86CysuCytg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 872 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2172959588 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559face81810, 0x559fad06b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559fad06b020,0x559faef030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/20d6d20a922c5539c9c1a511196b01abc5ae1b57' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 976 processed earlier; will process 10053 files now Step #5: ==31426== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559fa39769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559fa9fdb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559fa9fbe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559fa9fbe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559fa397cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559fa38ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559fa38d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559fa396ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559fa693df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559fa693df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559fa693df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559fa693df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559fa693df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559fa693df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559fa693df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559fa693df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559fa693df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559fa693df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559fa8bd2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559fa58ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559fa590abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559fa56b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559fa56b6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559fa56b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559fa56b6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559fa56b6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559fa56b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559fa9fc0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559fa9fc9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559fa9fb1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559fa9fdc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f03360ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559fa38d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x55,0x3a,0x3a,0x69,0x6f,0x6e,0x3a, Step #5: U::ion: Step #5: artifact_prefix='./'; Test unit written to ./oom-62b9b1f1dee41108d1ce13f859c61a925ac827e9 Step #5: Base64: VTo6aW9uOg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 873 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2173406703 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56183ede2810, 0x56183efcc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56183efcc020,0x561840e640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/62b9b1f1dee41108d1ce13f859c61a925ac827e9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 977 processed earlier; will process 10052 files now Step #5: ==31462== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5618358d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56183bf3c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56183bf1f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56183bf1f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5618358ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56183583eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561835839355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5618358cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56183889ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56183889ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56183889ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56183889ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56183889ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56183889ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56183889ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56183889ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56183889ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56183889ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56183ab33f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561837860b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56183786bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561837617c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561837617c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561837618738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561837617874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561837617874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561837617874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56183bf21abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56183bf2a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56183bf12699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56183bf3d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8cf3573082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561835837b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x6e,0x3a,0x6f,0x75,0x3d,0x73, Step #5: dn:ou=s Step #5: artifact_prefix='./'; Test unit written to ./oom-458af2b37fc1a1749d841e77c20ef1c3505531ca Step #5: Base64: ZG46b3U9cw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 874 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2173846805 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e2f84f810, 0x555e2fa3901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e2fa39020,0x555e318d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/458af2b37fc1a1749d841e77c20ef1c3505531ca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 978 processed earlier; will process 10051 files now Step #5: #1 pulse cov: 3434 ft: 3435 exec/s: 0 rss: 160Mb Step #5: ==31498== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555e263449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e2c9a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e2c98c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e2c98c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e2634ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e262abb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e262a6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e2633cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e2930bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e2930bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e2930bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e2930bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e2930bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e2930bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e2930bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e2930bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e2930bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e2930bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e2b5a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e282cdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e282d8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e28084c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e28084c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e28085738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e28084874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e28084874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e28084874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e2c98eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e2c997928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e2c97f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e2c9aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e79123082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e262a4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x53,0x3a,0xcd,0x8f,0xcd,0x8f, Step #5: wS:\315\217\315\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-032ed9e2dde4864f66a92a8e65fc7afb7840067e Step #5: Base64: d1M6zY/Njw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 875 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2174320740 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb3e964810, 0x55bb3eb4e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb3eb4e020,0x55bb409e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/032ed9e2dde4864f66a92a8e65fc7afb7840067e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 980 processed earlier; will process 10049 files now Step #5: ==31534== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bb354599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb3babe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb3baa15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb3baa14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb3545fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb353c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb353bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb35451c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb38420f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb38420f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb38420f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb38420f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb38420f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb38420f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb38420f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb38420f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb38420f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb38420f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb3a6b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb373e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb373edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb37199c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb37199c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb3719a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb37199874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb37199874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb37199874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb3baa3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb3baac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb3ba94699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb3babf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7cf1a1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb353b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0xef,0xbb,0xbf,0xef,0xbb,0xbf, Step #5: (\357\273\277\357\273\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-249caf1ab637a2cb45f51ac7d7d760f37a1e923b Step #5: Base64: KO+7v++7vw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 876 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2174753299 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557ce0151810, 0x557ce033b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557ce033b020,0x557ce21d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/249caf1ab637a2cb45f51ac7d7d760f37a1e923b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 981 processed earlier; will process 10048 files now Step #5: ==31570== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557cd6c469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557cdd2ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557cdd28e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557cdd28e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557cd6c4cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557cd6badb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557cd6ba8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557cd6c3ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557cd9c0df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557cd9c0df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557cd9c0df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557cd9c0df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557cd9c0df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557cd9c0df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557cd9c0df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557cd9c0df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557cd9c0df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557cd9c0df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557cdbea2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557cd8bcfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557cd8bdabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557cd8986c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557cd8986c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557cd8987738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557cd8986874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557cd8986874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557cd8986874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557cdd290abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557cdd299928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557cdd281699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557cdd2ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcd2d6b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557cd6ba6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xbf,0x25,0x54,0xdd,0xa6, Step #5: \357\273\277%T\335\246 Step #5: artifact_prefix='./'; Test unit written to ./oom-950e782de07a98c8465d610aabca74061c23116a Step #5: Base64: 77u/JVTdpg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 877 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2175189003 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563c38063810, 0x563c3824d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563c3824d020,0x563c3a0e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/950e782de07a98c8465d610aabca74061c23116a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 982 processed earlier; will process 10047 files now Step #5: ==31606== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563c2eb589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563c351bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563c351a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563c351a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563c2eb5ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563c2eabfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563c2eaba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563c2eb50c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563c31b1ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563c31b1ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563c31b1ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563c31b1ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563c31b1ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563c31b1ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563c31b1ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563c31b1ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563c31b1ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563c31b1ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563c33db4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563c30ae1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563c30aecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563c30898c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563c30898c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563c30899738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563c30898874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563c30898874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563c30898874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563c351a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563c351ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563c35193699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563c351be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5a80c06082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563c2eab8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x34,0x34,0x34,0x3a,0x31,0x3a,0x2d, Step #5: 444:1:- Step #5: artifact_prefix='./'; Test unit written to ./oom-c7287251eebf704873b242fe865581f97d72e972 Step #5: Base64: NDQ0OjE6LQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 878 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2175624550 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d65963e810, 0x55d65982801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d659828020,0x55d65b6c00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c7287251eebf704873b242fe865581f97d72e972' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 983 processed earlier; will process 10046 files now Step #5: ==31642== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d6501339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d656798898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d65677b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d65677b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d650139d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d65009ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d650095355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d65012bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d6530faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d6530faf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d6530faf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d6530faf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d6530faf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d6530faf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d6530faf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d6530faf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d6530faf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d6530faf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d65538ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d6520bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d6520c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d651e73c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d651e73c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d651e74738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d651e73874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d651e73874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d651e73874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d65677dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d656786928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d65676e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d656799112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f91e99dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d650093b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x3,0xe2,0x80,0x8a, Step #5: \000\000\000\003\342\200\212 Step #5: artifact_prefix='./'; Test unit written to ./oom-2004f7ac78041478a5f7b91bbe7aadb525ebbc0d Step #5: Base64: AAAAA+KAig== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 879 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2176057032 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564483b00810, 0x564483cea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564483cea020,0x564485b820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2004f7ac78041478a5f7b91bbe7aadb525ebbc0d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 984 processed earlier; will process 10045 files now Step #5: ==31678== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56447a5f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564480c5a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564480c3d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564480c3d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56447a5fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56447a55cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56447a557355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56447a5edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56447d5bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56447d5bcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56447d5bcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56447d5bcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56447d5bcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56447d5bcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56447d5bcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56447d5bcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56447d5bcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56447d5bcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56447f851f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56447c57eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56447c589be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56447c335c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56447c335c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56447c336738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56447c335874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56447c335874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56447c335874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564480c3fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564480c48928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564480c30699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564480c5b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd5a9a45082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56447a555b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5e,0x5b,0x5e,0xf4,0x8f,0x26, Step #5: [^[^\364\217& Step #5: artifact_prefix='./'; Test unit written to ./oom-02afe787dce6c8a138fac014df9f307d03871032 Step #5: Base64: W15bXvSPJg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 880 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2176492506 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565398551810, 0x56539873b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56539873b020,0x56539a5d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/02afe787dce6c8a138fac014df9f307d03871032' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 985 processed earlier; will process 10044 files now Step #5: #1 pulse cov: 3698 ft: 3699 exec/s: 0 rss: 162Mb Step #5: ==31714== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56538f0469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5653956ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56539568e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56539568e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56538f04cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56538efadb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56538efa8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56538f03ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56539200df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56539200df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56539200df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56539200df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56539200df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56539200df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56539200df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56539200df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56539200df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56539200df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5653942a2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565390fcfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565390fdabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565390d86c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565390d86c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565390d87738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565390d86874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565390d86874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565390d86874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565395690abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565395699928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565395681699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5653956ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc65575b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56538efa6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x38,0x31,0x39,0x30,0x2c,0x30, Step #5: -8190,0 Step #5: artifact_prefix='./'; Test unit written to ./oom-49afd0ce4231cb994d6af1aff1f849146b3d3179 Step #5: Base64: LTgxOTAsMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 881 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2176967096 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff6d7c3810, 0x55ff6d9ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff6d9ad020,0x55ff6f8450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/49afd0ce4231cb994d6af1aff1f849146b3d3179' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 987 processed earlier; will process 10042 files now Step #5: ==31750== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ff642b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff6a91d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff6a9005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff6a9004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff642bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff6421fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff6421a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff642b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff6727ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff6727ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff6727ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff6727ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff6727ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff6727ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff6727ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff6727ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff6727ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff6727ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff69514f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff66241b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff6624cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff65ff8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff65ff8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff65ff9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff65ff8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff65ff8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff65ff8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff6a902abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff6a90b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff6a8f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff6a91e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f65bfdfa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff64218b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x2f,0xda,0xb4,0x5f,0xda,0xb4, Step #5: ~/\332\264_\332\264 Step #5: artifact_prefix='./'; Test unit written to ./oom-63ecdce87adeda688c96f8899247091f1eaac189 Step #5: Base64: fi/atF/atA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 882 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2177403923 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610946c7810, 0x5610948b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610948b1020,0x5610967490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/63ecdce87adeda688c96f8899247091f1eaac189' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 988 processed earlier; will process 10041 files now Step #5: ==31786== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56108b1bc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561091821898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610918045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610918044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56108b1c2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56108b123b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56108b11e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56108b1b4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56108e183f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56108e183f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56108e183f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56108e183f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56108e183f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56108e183f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56108e183f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56108e183f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56108e183f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56108e183f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561090418f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56108d145b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56108d150be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56108cefcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56108cefcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56108cefd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56108cefc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56108cefc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56108cefc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561091806abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56109180f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610917f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561091822112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6fe591a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56108b11cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x2f,0xdb,0x81,0xe2,0x80,0xab, Step #5: +/\333\201\342\200\253 Step #5: artifact_prefix='./'; Test unit written to ./oom-7eff559d72ebb53c1664ee587142aafe2ab6dc5c Step #5: Base64: Ky/bgeKAqw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 883 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2177848549 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563db5c1e810, 0x563db5e0801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563db5e08020,0x563db7ca00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7eff559d72ebb53c1664ee587142aafe2ab6dc5c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 989 processed earlier; will process 10040 files now Step #5: ==31822== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563dac7139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563db2d78898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563db2d5b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563db2d5b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563dac719d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563dac67ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563dac675355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563dac70bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563daf6daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563daf6daf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563daf6daf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563daf6daf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563daf6daf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563daf6daf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563daf6daf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563daf6daf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563daf6daf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563daf6daf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563db196ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563dae69cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563dae6a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563dae453c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563dae453c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563dae454738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563dae453874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563dae453874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563dae453874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563db2d5dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563db2d66928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563db2d4e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563db2d79112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff79b6cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563dac673b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x52,0x55,0x4e,0x3d,0x22,0x1d,0x22, Step #5: RUN=\"\035\" Step #5: artifact_prefix='./'; Test unit written to ./oom-01647d26d0a450c49c8b8388488484da8de00a34 Step #5: Base64: UlVOPSIdIg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 884 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2178286935 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f0f6157810, 0x55f0f634101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f0f6341020,0x55f0f81d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01647d26d0a450c49c8b8388488484da8de00a34' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 990 processed earlier; will process 10039 files now Step #5: ==31858== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f0ecc4c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f0f32b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f0f32945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f0f32944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f0ecc52d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f0ecbb3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f0ecbae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f0ecc44c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f0efc13f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f0efc13f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f0efc13f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f0efc13f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f0efc13f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f0efc13f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f0efc13f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f0efc13f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f0efc13f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f0efc13f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f0f1ea8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f0eebd5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f0eebe0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f0ee98cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f0ee98cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f0ee98d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f0ee98c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f0ee98c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f0ee98c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f0f3296abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f0f329f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f0f3287699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f0f32b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa695f97082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f0ecbacb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xa,0x3d,0x3d,0xa,0x3d,0x3d, Step #5: =\012==\012== Step #5: artifact_prefix='./'; Test unit written to ./oom-dabcc1a373c0d9c3e48c84a514516ba4b9a967ab Step #5: Base64: PQo9PQo9PQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 885 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2178716218 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a948b36810, 0x55a948d2001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a948d20020,0x55a94abb80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dabcc1a373c0d9c3e48c84a514516ba4b9a967ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 991 processed earlier; will process 10038 files now Step #5: #1 pulse cov: 3574 ft: 3575 exec/s: 0 rss: 162Mb Step #5: #2 pulse cov: 6849 ft: 7248 exec/s: 0 rss: 176Mb Step #5: ==31894== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a93f62b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a945c90898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a945c735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a945c734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a93f631d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a93f592b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a93f58d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a93f623c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9425f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9425f2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9425f2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9425f2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9425f2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9425f2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9425f2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9425f2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9425f2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9425f2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a944887f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a9415b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a9415bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a94136bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a94136bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a94136c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a94136b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a94136b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a94136b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a945c75abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a945c7e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a945c66699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a945c91112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c08a18082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a93f58bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x5c,0x75,0xf0,0x9e,0xb8,0x9e, Step #5: \"\\u\360\236\270\236 Step #5: artifact_prefix='./'; Test unit written to ./oom-b8f2d9d355615a87fcd57f6c678a172f5872124d Step #5: Base64: Ilx18J64ng== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 886 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2179229918 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559092433810, 0x55909261d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55909261d020,0x5590944b50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b8f2d9d355615a87fcd57f6c678a172f5872124d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 994 processed earlier; will process 10035 files now Step #5: ==31930== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559088f289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55908f58d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55908f5705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55908f5704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559088f2ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559088e8fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559088e8a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559088f20c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55908beeff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55908beeff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55908beeff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55908beeff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55908beeff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55908beeff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55908beeff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55908beeff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55908beeff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55908beeff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55908e184f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55908aeb1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55908aebcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55908ac68c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55908ac68c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55908ac69738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55908ac68874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55908ac68874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55908ac68874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55908f572abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55908f57b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55908f563699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55908f58e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4aa4411082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559088e88b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x22,0x22,0xf0,0x90,0xae,0x90, Step #5: \000\"\"\360\220\256\220 Step #5: artifact_prefix='./'; Test unit written to ./oom-feb374d75fa4743b719a110a6605fc0752552dd2 Step #5: Base64: ACIi8JCukA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 887 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2179659885 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610a4bd8810, 0x5610a4dc201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610a4dc2020,0x5610a6c5a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/feb374d75fa4743b719a110a6605fc0752552dd2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 995 processed earlier; will process 10034 files now Step #5: #1 pulse cov: 3470 ft: 3471 exec/s: 0 rss: 160Mb Step #5: ==31966== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56109b6cd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610a1d32898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610a1d155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610a1d154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56109b6d3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56109b634b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56109b62f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56109b6c5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56109e694f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56109e694f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56109e694f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56109e694f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56109e694f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56109e694f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56109e694f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56109e694f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56109e694f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56109e694f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610a0929f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56109d656b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56109d661be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56109d40dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56109d40dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56109d40e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56109d40d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56109d40d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56109d40d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610a1d17abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610a1d20928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610a1d08699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610a1d33112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1e31aa9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56109b62db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33,0xa,0x33,0xa,0x32,0xa,0x32, Step #5: 3\0123\0122\0122 Step #5: artifact_prefix='./'; Test unit written to ./oom-297d758be4a699b848ea3b5abda9bdd348e68414 Step #5: Base64: MwozCjIKMg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 888 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2180137662 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c9aba1810, 0x559c9ad8b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c9ad8b020,0x559c9cc230e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/297d758be4a699b848ea3b5abda9bdd348e68414' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 997 processed earlier; will process 10032 files now Step #5: ==32002== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559c916969c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c97cfb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c97cde5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c97cde4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c9169cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c915fdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c915f8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c9168ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c9465df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c9465df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c9465df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c9465df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c9465df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c9465df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c9465df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c9465df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c9465df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c9465df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c968f2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c9361fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c9362abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c933d6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c933d6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c933d7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c933d6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c933d6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c933d6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c97ce0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c97ce9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c97cd1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c97cfc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1bd9f78082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c915f6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2,0x0,0x2,0x0,0x2,0x0, Step #5: \005\002\000\002\000\002\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3218152ff421d7451aa34a07d286aec983fe7cce Step #5: Base64: BQIAAgACAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 889 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2180571615 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5606000a2810, 0x56060028c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56060028c020,0x5606021240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3218152ff421d7451aa34a07d286aec983fe7cce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 998 processed earlier; will process 10031 files now Step #5: #1 pulse cov: 3596 ft: 3597 exec/s: 0 rss: 162Mb Step #5: ==32038== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5605f6b979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605fd1fc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605fd1df5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605fd1df4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5605f6b9dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605f6afeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5605f6af9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5605f6b8fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605f9b5ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605f9b5ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605f9b5ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605f9b5ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605f9b5ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605f9b5ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605f9b5ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605f9b5ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605f9b5ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605f9b5ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605fbdf3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5605f8b20b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5605f8b2bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5605f88d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5605f88d7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5605f88d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5605f88d7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5605f88d7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5605f88d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605fd1e1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5605fd1ea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605fd1d2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605fd1fd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f421cebf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5605f6af7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0x5c,0x31,0x30,0x27,0x33,0x40, Step #5: .\\10'3@ Step #5: artifact_prefix='./'; Test unit written to ./oom-5e5818067b7ee893c566e12778fa56a4ee42119a Step #5: Base64: LlwxMCczQA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 890 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2181038215 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557066dc4810, 0x557066fae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557066fae020,0x557068e460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e5818067b7ee893c566e12778fa56a4ee42119a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1000 processed earlier; will process 10029 files now Step #5: ==32074== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55705d8b99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557063f1e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557063f015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557063f014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55705d8bfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55705d820b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55705d81b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55705d8b1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557060880f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557060880f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557060880f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557060880f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557060880f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557060880f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557060880f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557060880f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557060880f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557060880f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557062b15f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55705f842b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55705f84dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55705f5f9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55705f5f9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55705f5fa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55705f5f9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55705f5f9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55705f5f9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557063f03abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557063f0c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557063ef4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557063f1f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff04a32c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55705d819b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x3b,0x86,0x60, Step #5: DanM;\206` Step #5: artifact_prefix='./'; Test unit written to ./oom-cc412bf784e78e5b767d61a14b0bac68b13c57dd Step #5: Base64: RGFuTTuGYA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 891 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2181467996 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ea78b4810, 0x562ea7a9e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ea7a9e020,0x562ea99360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cc412bf784e78e5b767d61a14b0bac68b13c57dd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1001 processed earlier; will process 10028 files now Step #5: ==32110== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562e9e3a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ea4a0e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ea49f15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ea49f14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e9e3afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e9e310b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e9e30b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e9e3a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ea1370f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ea1370f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ea1370f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ea1370f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ea1370f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ea1370f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ea1370f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ea1370f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ea1370f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ea1370f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ea3605f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ea0332b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ea033dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ea00e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ea00e9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ea00ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ea00e9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ea00e9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ea00e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ea49f3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ea49fc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ea49e4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ea4a0f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67080ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e9e309b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x63,0x65,0x6e,0x64,0x61,0x5b, Step #5: scenda[ Step #5: artifact_prefix='./'; Test unit written to ./oom-428706c8d42e0d520dc9356895cbbcab38baea3d Step #5: Base64: c2NlbmRhWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 892 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2181902714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8ad152810, 0x55c8ad33c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c8ad33c020,0x55c8af1d40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/428706c8d42e0d520dc9356895cbbcab38baea3d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1002 processed earlier; will process 10027 files now Step #5: ==32146== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c8a3c479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8aa2ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8aa28f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8aa28f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c8a3c4dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c8a3baeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c8a3ba9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c8a3c3fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c8a6c0ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c8a6c0ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c8a6c0ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c8a6c0ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c8a6c0ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c8a6c0ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c8a6c0ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c8a6c0ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c8a6c0ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c8a6c0ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c8a8ea3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c8a5bd0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c8a5bdbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c8a5987c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c8a5987c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c8a5988738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c8a5987874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c8a5987874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c8a5987874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8aa291abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8aa29a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8aa282699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8aa2ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f34d2bc2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c8a3ba7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x11,0xcc,0xb0,0xcc,0xb0, Step #5: \000\000\021\314\260\314\260 Step #5: artifact_prefix='./'; Test unit written to ./oom-f62421205df64b14984c2488af8c66672f80f381 Step #5: Base64: AAARzLDMsA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 893 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2182340670 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c01cfa7810, 0x55c01d19101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c01d191020,0x55c01f0290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f62421205df64b14984c2488af8c66672f80f381' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1003 processed earlier; will process 10026 files now Step #5: ==32182== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c013a9c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c01a101898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c01a0e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c01a0e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c013aa2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c013a03b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c0139fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c013a94c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c016a63f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c016a63f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c016a63f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c016a63f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c016a63f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c016a63f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c016a63f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c016a63f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c016a63f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c016a63f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c018cf8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c015a25b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c015a30be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c0157dcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c0157dcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c0157dd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c0157dc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c0157dc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c0157dc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c01a0e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c01a0ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c01a0d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c01a102112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8bb6624082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c0139fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd7,0xa9,0x1,0x0,0x2b,0x6,0x74, Step #5: \327\251\001\000+\006t Step #5: artifact_prefix='./'; Test unit written to ./oom-7e9e5c75288fd92ec43cbcb4c92865c22f2c941e Step #5: Base64: 16kBACsGdA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 894 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2182773567 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d7021dc810, 0x55d7023c601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d7023c6020,0x55d70425e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7e9e5c75288fd92ec43cbcb4c92865c22f2c941e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1004 processed earlier; will process 10025 files now Step #5: ==32218== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d6f8cd19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d6ff336898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d6ff3195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d6ff3194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d6f8cd7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d6f8c38b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d6f8c33355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d6f8cc9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d6fbc98f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d6fbc98f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d6fbc98f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d6fbc98f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d6fbc98f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d6fbc98f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d6fbc98f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d6fbc98f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d6fbc98f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d6fbc98f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d6fdf2df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d6fac5ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d6fac65be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d6faa11c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d6faa11c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d6faa12738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d6faa11874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d6faa11874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d6faa11874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d6ff31babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d6ff324928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d6ff30c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d6ff337112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7cf8204082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d6f8c31b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x2a,0x0,0x98,0x5b,0x5b,0x24, Step #5: **\000\230[[$ Step #5: artifact_prefix='./'; Test unit written to ./oom-183b7c71a12d2b4948f2edfc0d704b8a5f86aaa2 Step #5: Base64: KioAmFtbJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 895 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2183209147 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556980e53810, 0x55698103d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55698103d020,0x556982ed50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/183b7c71a12d2b4948f2edfc0d704b8a5f86aaa2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1005 processed earlier; will process 10024 files now Step #5: ==32254== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5569779489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55697dfad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55697df905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55697df904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55697794ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5569778afb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5569778aa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556977940c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55697a90ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55697a90ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55697a90ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55697a90ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55697a90ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55697a90ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55697a90ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55697a90ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55697a90ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55697a90ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55697cba4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5569798d1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5569798dcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556979688c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556979688c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556979689738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556979688874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556979688874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556979688874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55697df92abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55697df9b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55697df83699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55697dfae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb65ab32082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5569778a8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x20,0x68,0x20,0x61,0x38,0x6f, Step #5: 1 h a8o Step #5: artifact_prefix='./'; Test unit written to ./oom-f4f699c0053df0c75822a052a98d380bf6a09bb8 Step #5: Base64: MSBoIGE4bw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 896 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2183644838 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ad74646810, 0x55ad7483001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ad74830020,0x55ad766c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f4f699c0053df0c75822a052a98d380bf6a09bb8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1006 processed earlier; will process 10023 files now Step #5: ==32290== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ad6b13b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ad717a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ad717835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ad717834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ad6b141d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ad6b0a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ad6b09d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ad6b133c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ad6e102f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ad6e102f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ad6e102f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ad6e102f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ad6e102f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ad6e102f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ad6e102f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ad6e102f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ad6e102f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ad6e102f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ad70397f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ad6d0c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ad6d0cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ad6ce7bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ad6ce7bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ad6ce7c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ad6ce7b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ad6ce7b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ad6ce7b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ad71785abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ad7178e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ad71776699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ad717a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe88d65e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ad6b09bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0x20,0x3f,0x20,0x3f,0x20,0x3f, Step #5: ? ? ? ? Step #5: artifact_prefix='./'; Test unit written to ./oom-e51a3ed5d6bea0127ae5f743e988d029de33a163 Step #5: Base64: PyA/ID8gPw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 897 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2184073129 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe5f935810, 0x55fe5fb1f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe5fb1f020,0x55fe619b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e51a3ed5d6bea0127ae5f743e988d029de33a163' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1007 processed earlier; will process 10022 files now Step #5: ==32326== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fe5642a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe5ca8f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe5ca725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe5ca724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe56430d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe56391b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe5638c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe56422c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe593f1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe593f1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe593f1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe593f1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe593f1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe593f1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe593f1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe593f1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe593f1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe593f1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe5b686f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe583b3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe583bebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe5816ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe5816ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe5816b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe5816a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe5816a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe5816a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe5ca74abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe5ca7d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe5ca65699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe5ca90112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf46904082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe5638ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5e,0xa,0x2d,0xde,0xb3,0x5d, Step #5: [^\012-\336\263] Step #5: artifact_prefix='./'; Test unit written to ./oom-5cb17249e5fe645a4a309034005464317b6dafc2 Step #5: Base64: W14KLd6zXQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 898 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2184513265 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55952ce22810, 0x55952d00c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55952d00c020,0x55952eea40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5cb17249e5fe645a4a309034005464317b6dafc2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1008 processed earlier; will process 10021 files now Step #5: ==32362== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5595239179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559529f7c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559529f5f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559529f5f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55952391dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55952387eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559523879355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55952390fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5595268def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5595268def10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5595268def10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5595268def10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5595268def10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5595268def10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5595268def10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5595268def10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5595268def10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5595268def10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559528b73f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5595258a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5595258abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559525657c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559525657c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559525658738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559525657874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559525657874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559525657874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559529f61abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559529f6a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559529f52699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559529f7d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fec347fd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559523877b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x80,0x88,0xe1,0x80,0x88,0xd1, Step #5: \341\200\210\341\200\210\321 Step #5: artifact_prefix='./'; Test unit written to ./oom-9909479774080dc660ed1a3ece3be8dd0a85a521 Step #5: Base64: 4YCI4YCI0Q== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 899 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2184949514 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563505b46810, 0x563505d3001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563505d30020,0x563507bc80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9909479774080dc660ed1a3ece3be8dd0a85a521' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1009 processed earlier; will process 10020 files now Step #5: #1 pulse cov: 3448 ft: 3449 exec/s: 0 rss: 159Mb Step #5: ==32398== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5634fc63b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563502ca0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563502c835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563502c834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5634fc641d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5634fc5a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5634fc59d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5634fc633c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5634ff602f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5634ff602f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5634ff602f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5634ff602f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5634ff602f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5634ff602f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5634ff602f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5634ff602f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5634ff602f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5634ff602f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563501897f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5634fe5c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5634fe5cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5634fe37bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5634fe37bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5634fe37c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5634fe37b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5634fe37b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5634fe37b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563502c85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563502c8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563502c76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563502ca1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6107f0b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5634fc59bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4b,0x45,0x52,0x4c,0x3d,0x22,0x22, Step #5: KERL=\"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-dd84ebb701e0da81d289efa3d75dd85ed46c2aa0 Step #5: Base64: S0VSTD0iIg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 900 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2185422560 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d382c0810, 0x557d384aa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d384aa020,0x557d3a3420e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dd84ebb701e0da81d289efa3d75dd85ed46c2aa0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1011 processed earlier; will process 10018 files now Step #5: ==32434== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557d2edb59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557d3541a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557d353fd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557d353fd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557d2edbbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557d2ed1cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557d2ed17355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557d2edadc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557d31d7cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557d31d7cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557d31d7cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557d31d7cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557d31d7cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557d31d7cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557d31d7cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557d31d7cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557d31d7cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557d31d7cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557d34011f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557d30d3eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557d30d49be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557d30af5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557d30af5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557d30af6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557d30af5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557d30af5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557d30af5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557d353ffabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557d35408928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557d353f0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557d3541b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4656ea5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557d2ed15b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0xc2,0xad,0xc3,0x94,0x44,0x4b, Step #5: n\302\255\303\224DK Step #5: artifact_prefix='./'; Test unit written to ./oom-3698b9abe9a37e401a050c1f46625d6aa5089ce0 Step #5: Base64: bsKtw5RESw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 901 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2185857465 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd748f5810, 0x55dd74adf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd74adf020,0x55dd769770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3698b9abe9a37e401a050c1f46625d6aa5089ce0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1012 processed earlier; will process 10017 files now Step #5: ==32470== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dd6b3ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd71a4f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd71a325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd71a324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dd6b3f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dd6b351b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dd6b34c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dd6b3e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd6e3b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd6e3b1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd6e3b1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd6e3b1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd6e3b1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd6e3b1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd6e3b1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd6e3b1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd6e3b1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd6e3b1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd70646f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dd6d373b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dd6d37ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dd6d12ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dd6d12ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dd6d12b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dd6d12a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dd6d12a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dd6d12a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd71a34abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd71a3d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd71a25699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd71a50112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f29a476d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dd6b34ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x63,0x29,0x75,0xcd,0xa6,0x29, Step #5: \012c)u\315\246) Step #5: artifact_prefix='./'; Test unit written to ./oom-031e25c8c3b29153bccf4d5d5bb60cfbbadb1bc2 Step #5: Base64: CmMpdc2mKQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 902 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2186291876 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eec9358810, 0x55eec954201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eec9542020,0x55eecb3da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/031e25c8c3b29153bccf4d5d5bb60cfbbadb1bc2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1013 processed earlier; will process 10016 files now Step #5: ==32506== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eebfe4d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eec64b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eec64955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eec64954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eebfe53d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eebfdb4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eebfdaf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eebfe45c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eec2e14f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eec2e14f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eec2e14f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eec2e14f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eec2e14f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eec2e14f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eec2e14f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eec2e14f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eec2e14f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eec2e14f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eec50a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eec1dd6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eec1de1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eec1b8dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eec1b8dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eec1b8e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eec1b8d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eec1b8d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eec1b8d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eec6497abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eec64a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eec6488699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eec64b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c7b20e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eebfdadb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x61,0xc2,0xb7,0xc2,0xb7, Step #5: Step #5: Step #5: #0 0x5613d4adb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5613db140898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613db1235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613db1234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5613d4ae1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5613d4a42b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5613d4a3d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5613d4ad3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5613d7aa2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5613d7aa2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5613d7aa2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5613d7aa2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5613d7aa2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5613d7aa2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5613d7aa2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5613d7aa2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5613d7aa2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5613d7aa2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5613d9d37f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5613d6a64b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5613d6a6fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5613d681bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5613d681bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5613d681c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5613d681b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5613d681b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5613d681b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5613db125abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5613db12e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5613db116699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5613db141112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e01b99082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5613d4a3bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x90,0xa0,0xb5,0xd,0xd,0xd, Step #5: \360\220\240\265\015\015\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-f575adadd4a7910e12555912c6209ba3c02a77d2 Step #5: Base64: 8JCgtQ0NDQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 904 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2187199673 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55853eaa9810, 0x55853ec9301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55853ec93020,0x558540b2b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f575adadd4a7910e12555912c6209ba3c02a77d2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1016 processed earlier; will process 10013 files now Step #5: ==32578== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55853559e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55853bc03898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55853bbe65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55853bbe64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5585355a4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558535505b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558535500355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558535596c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558538565f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558538565f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558538565f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558538565f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558538565f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558538565f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558538565f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558538565f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558538565f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558538565f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55853a7faf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558537527b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558537532be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5585372dec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5585372dec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5585372df738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5585372de874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5585372de874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5585372de874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55853bbe8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55853bbf1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55853bbd9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55853bc04112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff04080b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5585354feb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xf0,0x90,0x8e,0x90, Step #5: ws:\360\220\216\220 Step #5: artifact_prefix='./'; Test unit written to ./oom-b5dba04e7977057fc3f63c96e396dde984218b4e Step #5: Base64: d3M68JCOkA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 905 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2187630712 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5629f7db3810, 0x5629f7f9d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5629f7f9d020,0x5629f9e350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b5dba04e7977057fc3f63c96e396dde984218b4e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1017 processed earlier; will process 10012 files now Step #5: ==32614== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5629ee8a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5629f4f0d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5629f4ef05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5629f4ef04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5629ee8aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629ee80fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629ee80a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5629ee8a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5629f186ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5629f186ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5629f186ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5629f186ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5629f186ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5629f186ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5629f186ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5629f186ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5629f186ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5629f186ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5629f3b04f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629f0831b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629f083cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629f05e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629f05e8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629f05e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629f05e8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629f05e8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629f05e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5629f4ef2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5629f4efb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5629f4ee3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5629f4f0e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5388bf3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629ee808b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x43,0x4f,0x49, Step #5: DanMCOI Step #5: artifact_prefix='./'; Test unit written to ./oom-46e0e9b266bc00364bd9dd83c0bd4a9c86d4ec03 Step #5: Base64: RGFuTUNPSQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 906 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2188062125 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d80a171810, 0x55d80a35b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d80a35b020,0x55d80c1f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/46e0e9b266bc00364bd9dd83c0bd4a9c86d4ec03' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1018 processed earlier; will process 10011 files now Step #5: ==32650== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d800c669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d8072cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d8072ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d8072ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d800c6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d800bcdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d800bc8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d800c5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d803c2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d803c2df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d803c2df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d803c2df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d803c2df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d803c2df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d803c2df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d803c2df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d803c2df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d803c2df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d805ec2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d802befb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d802bfabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d8029a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d8029a6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d8029a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d8029a6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d8029a6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d8029a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d8072b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d8072b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d8072a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d8072cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f90d9e64082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d800bc6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x4,0x22,0x7e,0x7e,0x7e, Step #5: HU\004\"~~~ Step #5: artifact_prefix='./'; Test unit written to ./oom-ec5be69588c481c1d69ca77e658c119662b88bfc Step #5: Base64: SFUEIn5+fg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 907 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2188499800 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c1305d810, 0x564c1324701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c13247020,0x564c150df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec5be69588c481c1d69ca77e658c119662b88bfc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1019 processed earlier; will process 10010 files now Step #5: ==32686== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564c09b529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c101b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c1019a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c1019a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c09b58d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c09ab9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c09ab4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c09b4ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c0cb19f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c0cb19f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c0cb19f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c0cb19f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c0cb19f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c0cb19f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c0cb19f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c0cb19f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c0cb19f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c0cb19f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c0edaef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c0badbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c0bae6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c0b892c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c0b892c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c0b893738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c0b892874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c0b892874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c0b892874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c1019cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c101a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c1018d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c101b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0489947082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c09ab2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0xf3,0xbf,0xba,0xbe,0x31,0x45, Step #5: 2\363\277\272\2761E Step #5: artifact_prefix='./'; Test unit written to ./oom-97f44d6948182bc878b2d7a1ee4153dfe662028a Step #5: Base64: MvO/ur4xRQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 908 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2188935726 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5653a5916810, 0x5653a5b0001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5653a5b00020,0x5653a79980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/97f44d6948182bc878b2d7a1ee4153dfe662028a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1020 processed earlier; will process 10009 files now Step #5: ==32722== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56539c40b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5653a2a70898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5653a2a535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5653a2a534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56539c411d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56539c372b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56539c36d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56539c403c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56539f3d2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56539f3d2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56539f3d2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56539f3d2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56539f3d2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56539f3d2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56539f3d2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56539f3d2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56539f3d2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56539f3d2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5653a1667f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56539e394b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56539e39fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56539e14bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56539e14bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56539e14c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56539e14b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56539e14b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56539e14b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5653a2a55abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5653a2a5e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5653a2a46699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5653a2a71112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feb5928b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56539c36bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5b,0x5b,0x32,0x5d,0x5d,0x5d, Step #5: [[[2]]] Step #5: artifact_prefix='./'; Test unit written to ./oom-cdaf9c7b6637f7e9a85ef2c80bfd797d65a94f83 Step #5: Base64: W1tbMl1dXQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 909 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2189370244 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dcfb8e8810, 0x55dcfbad201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dcfbad2020,0x55dcfd96a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cdaf9c7b6637f7e9a85ef2c80bfd797d65a94f83' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1021 processed earlier; will process 10008 files now Step #5: ==32758== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dcf23dd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dcf8a42898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dcf8a255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dcf8a254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dcf23e3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dcf2344b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dcf233f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dcf23d5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dcf53a4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dcf53a4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dcf53a4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dcf53a4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dcf53a4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dcf53a4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dcf53a4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dcf53a4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dcf53a4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dcf53a4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dcf7639f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dcf4366b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dcf4371be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dcf411dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dcf411dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dcf411e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dcf411d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dcf411d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dcf411d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dcf8a27abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dcf8a30928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dcf8a18699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dcf8a43112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f78f0e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dcf233db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x26,0x24,0x12,0x60,0x67,0x60, Step #5: $&$\022`g` Step #5: artifact_prefix='./'; Test unit written to ./oom-405e43b32f322cadfb48c0e9284c19ce0b8337eb Step #5: Base64: JCYkEmBnYA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 910 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2189934088 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562bd7a0c810, 0x562bd7bf601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562bd7bf6020,0x562bd9a8e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/405e43b32f322cadfb48c0e9284c19ce0b8337eb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1022 processed earlier; will process 10007 files now Step #5: ==32794== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562bce5019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562bd4b66898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562bd4b495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562bd4b494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562bce507d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562bce468b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562bce463355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562bce4f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562bd14c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562bd14c8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562bd14c8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562bd14c8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562bd14c8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562bd14c8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562bd14c8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562bd14c8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562bd14c8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562bd14c8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562bd375df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562bd048ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562bd0495be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562bd0241c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562bd0241c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562bd0242738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562bd0241874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562bd0241874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562bd0241874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562bd4b4babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562bd4b54928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562bd4b3c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562bd4b67112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8e86786082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562bce461b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0x43,0x30,0xef,0xbe,0x95,0x33, Step #5: CC0\357\276\2253 Step #5: artifact_prefix='./'; Test unit written to ./oom-84368d98e5f299aa08db0445317a94b43cd1d44c Step #5: Base64: Q0Mw776VMw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 911 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2190361615 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5622b4cf6810, 0x5622b4ee001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622b4ee0020,0x5622b6d780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/84368d98e5f299aa08db0445317a94b43cd1d44c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1023 processed earlier; will process 10006 files now Step #5: ==32830== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5622ab7eb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5622b1e50898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5622b1e335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5622b1e334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5622ab7f1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5622ab752b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5622ab74d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5622ab7e3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5622ae7b2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5622ae7b2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5622ae7b2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5622ae7b2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5622ae7b2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5622ae7b2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5622ae7b2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5622ae7b2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5622ae7b2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5622ae7b2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5622b0a47f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5622ad774b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5622ad77fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5622ad52bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5622ad52bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5622ad52c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5622ad52b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5622ad52b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5622ad52b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5622b1e35abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5622b1e3e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5622b1e26699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5622b1e51112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ebbec9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5622ab74bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0xa,0x7e,0xa,0x66,0xa,0x69, Step #5: f\012~\012f\012i Step #5: artifact_prefix='./'; Test unit written to ./oom-118f074eb273005fccf7e42721ecbbce7aa5d98a Step #5: Base64: Zgp+CmYKaQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 912 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2190798354 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aeb4d00810, 0x55aeb4eea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aeb4eea020,0x55aeb6d820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/118f074eb273005fccf7e42721ecbbce7aa5d98a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1024 processed earlier; will process 10005 files now Step #5: ==32866== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55aeab7f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aeb1e5a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aeb1e3d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aeb1e3d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aeab7fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aeab75cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aeab757355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aeab7edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aeae7bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aeae7bcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aeae7bcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aeae7bcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aeae7bcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aeae7bcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aeae7bcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aeae7bcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aeae7bcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aeae7bcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aeb0a51f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aead77eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aead789be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aead535c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aead535c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aead536738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aead535874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aead535874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aead535874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aeb1e3fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aeb1e48928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aeb1e30699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aeb1e5b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d6ad67082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aeab755b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x3,0xe1,0x9f,0xa0, Step #5: \000\000\000\003\341\237\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-948525da1de4f432f320050dbdb7d1125beffc74 Step #5: Base64: AAAAA+GfoA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 913 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2191226435 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55758da84810, 0x55758dc6e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55758dc6e020,0x55758fb060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/948525da1de4f432f320050dbdb7d1125beffc74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1025 processed earlier; will process 10004 files now Step #5: ==32902== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5575845799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55758abde898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55758abc15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55758abc14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55758457fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5575844e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5575844db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557584571c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557587540f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557587540f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557587540f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557587540f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557587540f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557587540f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557587540f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557587540f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557587540f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557587540f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5575897d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557586502b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55758650dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5575862b9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5575862b9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5575862ba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5575862b9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5575862b9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5575862b9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55758abc3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55758abcc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55758abb4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55758abdf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f89f26a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5575844d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x2d,0x2c,0x2d,0x41,0x2d,0x2d, Step #5: A-,-A-- Step #5: artifact_prefix='./'; Test unit written to ./oom-dc104c94f8ef5d9d15abcc9f09216ea1e2730808 Step #5: Base64: QS0sLUEtLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 914 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2191656488 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1cef07810, 0x55d1cf0f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1cf0f1020,0x55d1d0f890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dc104c94f8ef5d9d15abcc9f09216ea1e2730808' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1026 processed earlier; will process 10003 files now Step #5: ==32938== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d1c59fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1cc061898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1cc0445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1cc0444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1c5a02d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1c5963b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1c595e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1c59f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1c89c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1c89c3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1c89c3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1c89c3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1c89c3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1c89c3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1c89c3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1c89c3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1c89c3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1c89c3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1cac58f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1c7985b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1c7990be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1c773cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1c773cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1c773d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1c773c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1c773c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1c773c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1cc046abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1cc04f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1cc037699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1cc062112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe04ca4b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1c595cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x0,0x0,0x0,0x0,0x0,0x1, Step #5: 0\000\000\000\000\000\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-ca2d4523cce6d5ced097a8fb8dcbad085d2dff1d Step #5: Base64: MAAAAAAAAQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 915 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2192084673 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56354ac8f810, 0x56354ae7901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56354ae79020,0x56354cd110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca2d4523cce6d5ced097a8fb8dcbad085d2dff1d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1027 processed earlier; will process 10002 files now Step #5: ==32974== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5635417849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563547de9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563547dcc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563547dcc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56354178ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5635416ebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5635416e6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56354177cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56354474bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56354474bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56354474bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56354474bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56354474bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56354474bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56354474bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56354474bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56354474bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56354474bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5635469e0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56354370db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563543718be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5635434c4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5635434c4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5635434c5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5635434c4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5635434c4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5635434c4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563547dceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563547dd7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563547dbf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563547dea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb337946082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5635416e4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x24,0x24,0x24,0x5b,0x74,0x24, Step #5: \003$$$[t$ Step #5: artifact_prefix='./'; Test unit written to ./oom-6b423924c65ec84df3ad23d4c2c3b135b424ee38 Step #5: Base64: AyQkJFt0JA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 916 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2192520075 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c86c422810, 0x55c86c60c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c86c60c020,0x55c86e4a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b423924c65ec84df3ad23d4c2c3b135b424ee38' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1028 processed earlier; will process 10001 files now Step #5: ==33010== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c862f179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c86957c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c86955f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c86955f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c862f1dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c862e7eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c862e79355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c862f0fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c865edef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c865edef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c865edef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c865edef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c865edef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c865edef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c865edef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c865edef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c865edef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c865edef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c868173f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c864ea0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c864eabbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c864c57c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c864c57c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c864c58738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c864c57874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c864c57874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c864c57874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c869561abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c86956a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c869552699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c86957d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f06b61d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c862e77b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0xdc,0xbb,0x2d,0xdc,0xb5, Step #5: --\334\273-\334\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-f815631faa4e252eb809b000d5f38ea7abe3ee7b Step #5: Base64: LS3cuy3ctQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 917 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2192949288 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab30fdc810, 0x55ab311c601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab311c6020,0x55ab3305e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f815631faa4e252eb809b000d5f38ea7abe3ee7b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1029 processed earlier; will process 10000 files now Step #5: ==33046== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ab27ad19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab2e136898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab2e1195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab2e1194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab27ad7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab27a38b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab27a33355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab27ac9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab2aa98f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab2aa98f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab2aa98f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab2aa98f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab2aa98f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab2aa98f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab2aa98f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab2aa98f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab2aa98f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab2aa98f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab2cd2df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab29a5ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab29a65be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab29811c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab29811c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab29812738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab29811874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab29811874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab29811874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab2e11babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab2e124928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab2e10c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab2e137112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9e251f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab27a31b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x1,0x25,0x2d,0xdf,0xbf,0x5d, Step #5: [\001%-\337\277] Step #5: artifact_prefix='./'; Test unit written to ./oom-a62be1bd1ecd7a8c4c5d0b6a6809add14dc797a5 Step #5: Base64: WwElLd+/XQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 918 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2193380664 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c9470c5810, 0x55c9472af01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c9472af020,0x55c9491470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a62be1bd1ecd7a8c4c5d0b6a6809add14dc797a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1030 processed earlier; will process 9999 files now Step #5: ==33082== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c93dbba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c94421f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9442025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9442024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c93dbc0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c93db21b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c93db1c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c93dbb2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c940b81f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c940b81f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c940b81f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c940b81f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c940b81f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c940b81f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c940b81f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c940b81f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c940b81f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c940b81f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c942e16f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c93fb43b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c93fb4ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c93f8fac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c93f8fac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c93f8fb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c93f8fa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c93f8fa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c93f8fa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c944204abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c94420d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c9441f5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c944220112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f36363f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c93db1ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0xc4,0xad,0x8a,0x8a,0x55, Step #5: - \304\255\212\212U Step #5: artifact_prefix='./'; Test unit written to ./oom-0533b719386047c839aa7819a5e43debaf176f5b Step #5: Base64: LSDErYqKVQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 919 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2193817442 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cdfcfbd810, 0x55cdfd1a701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cdfd1a7020,0x55cdff03f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0533b719386047c839aa7819a5e43debaf176f5b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1031 processed earlier; will process 9998 files now Step #5: ==33118== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cdf3ab29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cdfa117898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cdfa0fa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cdfa0fa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cdf3ab8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cdf3a19b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cdf3a14355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cdf3aaac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cdf6a79f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cdf6a79f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cdf6a79f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cdf6a79f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cdf6a79f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cdf6a79f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cdf6a79f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cdf6a79f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cdf6a79f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cdf6a79f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cdf8d0ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cdf5a3bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cdf5a46be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cdf57f2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cdf57f2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cdf57f3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cdf57f2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cdf57f2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cdf57f2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cdfa0fcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cdfa105928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cdfa0ed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cdfa118112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc588c64082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cdf3a12b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x42,0xe1,0x80,0xb7, Step #5: ws:B\341\200\267 Step #5: artifact_prefix='./'; Test unit written to ./oom-d0b8251859911283dfa84bd9da3e4428740e9098 Step #5: Base64: d3M6QuGAtw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 920 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2194259157 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559845a58810, 0x559845c4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559845c42020,0x559847ada0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d0b8251859911283dfa84bd9da3e4428740e9098' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1032 processed earlier; will process 9997 files now Step #5: ==33154== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55983c54d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559842bb2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559842b955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559842b954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55983c553d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55983c4b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55983c4af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55983c545c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55983f514f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55983f514f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55983f514f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55983f514f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55983f514f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55983f514f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55983f514f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55983f514f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55983f514f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55983f514f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5598417a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55983e4d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55983e4e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55983e28dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55983e28dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55983e28e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55983e28d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55983e28d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55983e28d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559842b97abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559842ba0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559842b88699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559842bb3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b5e849082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55983c4adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x21,0xdc,0xbd,0x21,0xdc,0xbd, Step #5: 0!\334\275!\334\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-09cbfad4f8f322fe181efe479594f011265792c3 Step #5: Base64: MCHcvSHcvQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 921 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2194692664 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b39af53810, 0x55b39b13d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b39b13d020,0x55b39cfd50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/09cbfad4f8f322fe181efe479594f011265792c3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1033 processed earlier; will process 9996 files now Step #5: ==33190== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b391a489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b3980ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b3980905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b3980904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b391a4ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b3919afb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b3919aa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b391a40c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b394a0ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b394a0ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b394a0ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b394a0ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b394a0ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b394a0ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b394a0ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b394a0ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b394a0ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b394a0ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b396ca4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b3939d1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b3939dcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b393788c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b393788c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b393789738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b393788874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b393788874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b393788874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b398092abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b39809b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b398083699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b3980ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fef78b7b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b3919a8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc7,0xb2,0xc3,0x8c,0xc3,0x9b,0x1, Step #5: \307\262\303\214\303\233\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-3d35db91836b506a77e37dc89547594de0a6aa70 Step #5: Base64: x7LDjMObAQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 922 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2195129294 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56464e76e810, 0x56464e95801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56464e958020,0x5646507f00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3d35db91836b506a77e37dc89547594de0a6aa70' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1034 processed earlier; will process 9995 files now Step #5: #1 pulse cov: 3655 ft: 3656 exec/s: 0 rss: 162Mb Step #5: #2 pulse cov: 3957 ft: 4215 exec/s: 0 rss: 163Mb Step #5: ==33226== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5646452639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56464b8c8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56464b8ab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56464b8ab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564645269d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5646451cab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5646451c5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56464525bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56464822af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56464822af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56464822af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56464822af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56464822af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56464822af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56464822af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56464822af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56464822af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56464822af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56464a4bff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5646471ecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5646471f7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564646fa3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564646fa3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564646fa4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564646fa3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564646fa3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564646fa3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56464b8adabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56464b8b6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56464b89e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56464b8c9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f51c6b8b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5646451c3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x3,0xe2,0x81,0x84, Step #5: \000\000\000\003\342\201\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-4e579f061c40d27c4c66517975e821c7ec15095c Step #5: Base64: AAAAA+KBhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 923 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2195630071 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561548cff810, 0x561548ee901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561548ee9020,0x56154ad810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e579f061c40d27c4c66517975e821c7ec15095c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1037 processed earlier; will process 9992 files now Step #5: ==33262== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56153f7f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561545e59898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561545e3c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561545e3c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56153f7fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56153f75bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56153f756355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56153f7ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5615427bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5615427bbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5615427bbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5615427bbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5615427bbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5615427bbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5615427bbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5615427bbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5615427bbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5615427bbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561544a50f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56154177db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561541788be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561541534c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561541534c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561541535738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561541534874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561541534874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561541534874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561545e3eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561545e47928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561545e2f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561545e5a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc511ed9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56153f754b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xde,0xa4,0x7b,0x35,0x31,0x31,0x7d, Step #5: \336\244{511} Step #5: artifact_prefix='./'; Test unit written to ./oom-3f0b17942d8620e4e04182d6abd77785b309fb1c Step #5: Base64: 3qR7NTExfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 924 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2196062114 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e617bd4810, 0x55e617dbe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e617dbe020,0x55e619c560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3f0b17942d8620e4e04182d6abd77785b309fb1c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1038 processed earlier; will process 9991 files now Step #5: ==33298== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e60e6c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e614d2e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e614d115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e614d114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e60e6cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e60e630b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e60e62b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e60e6c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e611690f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e611690f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e611690f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e611690f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e611690f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e611690f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e611690f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e611690f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e611690f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e611690f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e613925f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e610652b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e61065dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e610409c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e610409c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e61040a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e610409874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e610409874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e610409874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e614d13abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e614d1c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e614d04699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e614d2f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f468808c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e60e629b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0xa4,0xad,0xbf,0x7c,0x40,0x2e, Step #5: \360\244\255\277|@. Step #5: artifact_prefix='./'; Test unit written to ./oom-7240b9db1029804f20e95b8108222078aaf872ce Step #5: Base64: 8KStv3xALg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 925 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2196491020 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557cfe292810, 0x557cfe47c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557cfe47c020,0x557d003140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7240b9db1029804f20e95b8108222078aaf872ce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1039 processed earlier; will process 9990 files now Step #5: ==33334== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557cf4d879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557cfb3ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557cfb3cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557cfb3cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557cf4d8dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557cf4ceeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557cf4ce9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557cf4d7fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557cf7d4ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557cf7d4ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557cf7d4ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557cf7d4ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557cf7d4ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557cf7d4ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557cf7d4ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557cf7d4ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557cf7d4ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557cf7d4ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557cf9fe3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557cf6d10b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557cf6d1bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557cf6ac7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557cf6ac7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557cf6ac8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557cf6ac7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557cf6ac7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557cf6ac7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557cfb3d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557cfb3da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557cfb3c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557cfb3ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7307cfd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557cf4ce7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xee,0xbb,0xb3,0x7c,0xee,0xbb,0xb2, Step #5: \356\273\263|\356\273\262 Step #5: artifact_prefix='./'; Test unit written to ./oom-991550f17c73ffa39f1026bc42e1ef7dff86510c Step #5: Base64: 7ruzfO67sg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 926 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2196917299 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55984f183810, 0x55984f36d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55984f36d020,0x5598512050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/991550f17c73ffa39f1026bc42e1ef7dff86510c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1040 processed earlier; will process 9989 files now Step #5: ==33370== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559845c789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55984c2dd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55984c2c05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55984c2c04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559845c7ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559845bdfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559845bda355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559845c70c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559848c3ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559848c3ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559848c3ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559848c3ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559848c3ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559848c3ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559848c3ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559848c3ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559848c3ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559848c3ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55984aed4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559847c01b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559847c0cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5598479b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5598479b8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5598479b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5598479b8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5598479b8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5598479b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55984c2c2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55984c2cb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55984c2b3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55984c2de112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa34379082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559845bd8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x6e,0x7b,0x39,0x38,0x31,0x7d, Step #5: ^n{981} Step #5: artifact_prefix='./'; Test unit written to ./oom-6f3223047cd0e5300ae2af12315eaabb1555041d Step #5: Base64: Xm57OTgxfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 927 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2197347715 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556add5e1810, 0x556add7cb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556add7cb020,0x556adf6630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6f3223047cd0e5300ae2af12315eaabb1555041d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1041 processed earlier; will process 9988 files now Step #5: ==33406== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556ad40d69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556ada73b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556ada71e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556ada71e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556ad40dcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556ad403db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556ad4038355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556ad40cec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556ad709df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556ad709df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556ad709df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556ad709df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556ad709df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556ad709df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556ad709df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556ad709df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556ad709df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556ad709df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556ad9332f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556ad605fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556ad606abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556ad5e16c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556ad5e16c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556ad5e17738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556ad5e16874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556ad5e16874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556ad5e16874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556ada720abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556ada729928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556ada711699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556ada73c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe110b17082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556ad4036b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x3,0xe1,0xac,0x80, Step #5: \000\000\000\003\341\254\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-612471f47a07437e85bd0f5fad29eadca7abc90c Step #5: Base64: AAAAA+GsgA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 928 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2197781334 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558f6e69a810, 0x558f6e88401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558f6e884020,0x558f7071c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/612471f47a07437e85bd0f5fad29eadca7abc90c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1042 processed earlier; will process 9987 files now Step #5: ==33442== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558f6518f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558f6b7f4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558f6b7d75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558f6b7d74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f65195d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f650f6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f650f1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f65187c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f68156f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f68156f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f68156f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f68156f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f68156f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f68156f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f68156f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f68156f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f68156f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f68156f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558f6a3ebf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f67118b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f67123be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f66ecfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f66ecfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f66ed0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f66ecf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f66ecf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f66ecf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558f6b7d9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558f6b7e2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558f6b7ca699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558f6b7f5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff5dc70d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f650efb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0xff,0xff,0xff,0xff,0x28,0xa5, Step #5: F\377\377\377\377(\245 Step #5: artifact_prefix='./'; Test unit written to ./oom-bc0d92604ebd6321d2431d2d6f0c12c1f0fa944b Step #5: Base64: Rv////8opQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 929 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2198207872 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5575f31db810, 0x5575f33c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5575f33c5020,0x5575f525d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bc0d92604ebd6321d2431d2d6f0c12c1f0fa944b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1043 processed earlier; will process 9986 files now Step #5: ==33478== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5575e9cd09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5575f0335898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5575f03185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5575f03184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5575e9cd6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5575e9c37b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5575e9c32355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5575e9cc8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5575ecc97f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5575ecc97f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5575ecc97f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5575ecc97f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5575ecc97f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5575ecc97f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5575ecc97f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5575ecc97f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5575ecc97f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5575ecc97f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5575eef2cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5575ebc59b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5575ebc64be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5575eba10c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5575eba10c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5575eba11738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5575eba10874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5575eba10874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5575eba10874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5575f031aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5575f0323928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5575f030b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5575f0336112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ed346f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5575e9c30b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0xc2,0xad,0xc2,0x94,0x44,0x4b, Step #5: n\302\255\302\224DK Step #5: artifact_prefix='./'; Test unit written to ./oom-36539ec7a6108c4dd588f0cfb87101cbc2230529 Step #5: Base64: bsKtwpRESw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 930 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2198639124 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55823fc1c810, 0x55823fe0601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55823fe06020,0x558241c9e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/36539ec7a6108c4dd588f0cfb87101cbc2230529' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1044 processed earlier; will process 9985 files now Step #5: ==33514== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5582367119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55823cd76898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55823cd595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55823cd594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558236717d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558236678b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558236673355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558236709c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5582396d8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5582396d8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5582396d8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5582396d8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5582396d8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5582396d8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5582396d8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5582396d8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5582396d8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5582396d8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55823b96df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55823869ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5582386a5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558238451c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558238451c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558238452738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558238451874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558238451874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558238451874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55823cd5babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55823cd64928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55823cd4c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55823cd77112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcee4187082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558236671b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x7e,0x2d,0x7e,0x2d,0x62,0x32, Step #5: -~-~-b2 Step #5: artifact_prefix='./'; Test unit written to ./oom-5dd7dd3764cf4ed1236ac3bdad2a73d3a38ffd80 Step #5: Base64: LX4tfi1iMg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 931 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2199068166 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5636acc2e810, 0x5636ace1801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5636ace18020,0x5636aecb00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5dd7dd3764cf4ed1236ac3bdad2a73d3a38ffd80' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1045 processed earlier; will process 9984 files now Step #5: ==33550== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5636a37239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5636a9d88898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636a9d6b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636a9d6b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5636a3729d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5636a368ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5636a3685355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5636a371bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5636a66eaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5636a66eaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5636a66eaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5636a66eaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5636a66eaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5636a66eaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5636a66eaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5636a66eaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5636a66eaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5636a66eaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5636a897ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5636a56acb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5636a56b7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5636a5463c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5636a5463c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5636a5464738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5636a5463874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5636a5463874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5636a5463874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5636a9d6dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5636a9d76928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5636a9d5e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5636a9d89112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f13fe98b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5636a3683b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x77,0x77,0x2e,0x48,0x6d,0x6d, Step #5: www.Hmm Step #5: artifact_prefix='./'; Test unit written to ./oom-0ae9146d7a00ec5e1d3459f014cd662d018f7c6b Step #5: Base64: d3d3LkhtbQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 932 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2199502611 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56503fd2d810, 0x56503ff1701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56503ff17020,0x565041daf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0ae9146d7a00ec5e1d3459f014cd662d018f7c6b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1046 processed earlier; will process 9983 files now Step #5: ==33586== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5650368229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56503ce87898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56503ce6a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56503ce6a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565036828d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565036789b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565036784355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56503681ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5650397e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5650397e9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5650397e9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5650397e9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5650397e9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5650397e9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5650397e9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5650397e9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5650397e9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5650397e9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56503ba7ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5650387abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5650387b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565038562c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565038562c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565038563738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565038562874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565038562874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565038562874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56503ce6cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56503ce75928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56503ce5d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56503ce88112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2788f1b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565036782b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0xf0,0x90,0xbd,0x93,0x7d,0x3a, Step #5: {\360\220\275\223}: Step #5: artifact_prefix='./'; Test unit written to ./oom-0a518cef2ee3c1345502ea68c6e4931fdce362d3 Step #5: Base64: e/CQvZN9Og== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 933 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2199932412 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d708882810, 0x55d708a6c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d708a6c020,0x55d70a9040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a518cef2ee3c1345502ea68c6e4931fdce362d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1047 processed earlier; will process 9982 files now Step #5: #1 pulse cov: 3565 ft: 3566 exec/s: 0 rss: 162Mb Step #5: ==33622== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d6ff3779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d7059dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7059bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7059bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d6ff37dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d6ff2deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d6ff2d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d6ff36fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d70233ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d70233ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d70233ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d70233ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d70233ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d70233ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d70233ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d70233ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d70233ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d70233ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d7045d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d701300b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d70130bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d7010b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d7010b7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d7010b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d7010b7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d7010b7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d7010b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d7059c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d7059ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d7059b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d7059dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe06b36d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d6ff2d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x43,0x4f,0x4d, Step #5: DanMCOM Step #5: artifact_prefix='./'; Test unit written to ./oom-59e6412483e8ef983216a20fb2087df4bc1ea045 Step #5: Base64: RGFuTUNPTQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 934 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2200405325 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5599ac2c3810, 0x5599ac4ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5599ac4ad020,0x5599ae3450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/59e6412483e8ef983216a20fb2087df4bc1ea045' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1049 processed earlier; will process 9980 files now Step #5: ==33658== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5599a2db89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5599a941d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5599a94005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5599a94004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5599a2dbed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5599a2d1fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5599a2d1a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5599a2db0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5599a5d7ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5599a5d7ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5599a5d7ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5599a5d7ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5599a5d7ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5599a5d7ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5599a5d7ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5599a5d7ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5599a5d7ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5599a5d7ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5599a8014f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5599a4d41b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5599a4d4cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5599a4af8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5599a4af8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5599a4af9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5599a4af8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5599a4af8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5599a4af8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5599a9402abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5599a940b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5599a93f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5599a941e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5a9f752082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5599a2d18b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x2d,0x2d,0x2d,0x2d,0x0,0x41, Step #5: \002----\000A Step #5: artifact_prefix='./'; Test unit written to ./oom-ba1772e49f93363f274e3af7e05a6f196e74bd72 Step #5: Base64: Ai0tLS0AQQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 935 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2200835268 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560cad2eb810, 0x560cad4d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560cad4d5020,0x560caf36d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba1772e49f93363f274e3af7e05a6f196e74bd72' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1050 processed earlier; will process 9979 files now Step #5: Step #5: thread '' (33694) panicked at crates/typst-layout/src/inline/shaping.rs:1353:9: Step #5: one or more glyphs in " " fell out of range Step #5: note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace Step #5: AddressSanitizer:DEADLYSIGNAL Step #5: ================================================================= Step #5: ==33694==ERROR: AddressSanitizer: ABRT on unknown address 0x00000000839e (pc 0x7fe1ccf9300b bp 0x7ffff93cf840 sp 0x7ffff93cf5f0 T0) Step #5: SCARINESS: 10 (signal) Step #5: #0 0x7fe1ccf9300b in raise (/lib/x86_64-linux-gnu/libc.so.6+0x4300b) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #1 0x7fe1ccf72858 in abort (/lib/x86_64-linux-gnu/libc.so.6+0x22858) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #2 0x560ca3c03389 in std::sys::pal::unix::abort_internal (.llvm.4199261174039724961) /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/sys/pal/unix/mod.rs:300:14 Step #5: #3 0x560ca3c031e8 in std::process::abort /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/process.rs:2638:5 Step #5: #4 0x560ca3b900ec in libfuzzer_sys::initialize::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:94:9 Step #5: #5 0x560ca6b7b0c1 in core::ops::function::Fn<(&'a std::panic::PanicHookInfo<'b>,), Output = ()> + core::marker::Sync + core::marker::Send> as core::ops::function::Fn<(&std::panic::PanicHookInfo,)>>::call /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/boxed.rs:2349:9 Step #5: #6 0x560ca6b7b0c1 in std::panicking::panic_with_hook /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:819:13 Step #5: #7 0x560ca6b67ef1 in std::panicking::panic_handler::{closure#0} /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:685:13 Step #5: #8 0x560ca6b61fe8 in std::sys::backtrace::__rust_end_short_backtrace:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/sys/backtrace.rs:182:18 Step #5: #9 0x560ca6b68b4c in __rustc::rust_begin_unwind /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:676:5 Step #5: #10 0x560ca3ae796b in core::panicking::panic_fmt /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/core/src/panicking.rs:80:14 Step #5: #11 0x560ca75cde61 in typst_layout::inline::shaping::assert_all_glyphs_in_range /src/typst/crates/typst-layout/src/inline/shaping.rs:1353:9 Step #5: #12 0x560ca75cde61 in ::reshape /src/typst/crates/typst-layout/src/inline/shaping.rs:550:13 Step #5: #13 0x560ca7554202 in typst_layout::inline::line::collect_range /src/typst/crates/typst-layout/src/inline/line.rs:320:35 Step #5: #14 0x560ca7554202 in typst_layout::inline::line::collect_items::{closure#0} /src/typst/crates/typst-layout/src/inline/line.rs:218:9 Step #5: #15 0x560ca77637e4 in typst_layout::inline::line::reorder:: /src/typst/crates/typst-layout/src/inline/line.rs:279:9 Step #5: #16 0x560ca77637e4 in typst_layout::inline::line::collect_items /src/typst/crates/typst-layout/src/inline/line.rs:216:5 Step #5: #17 0x560ca77637e4 in typst_layout::inline::line::line /src/typst/crates/typst-layout/src/inline/line.rs:159:5 Step #5: #18 0x560ca755c66c in typst_layout::inline::linebreak::linebreak_simple::{closure#0} /src/typst/crates/typst-layout/src/inline/linebreak.rs:178:27 Step #5: #19 0x560ca76d4f12 in typst_layout::inline::linebreak::breakpoints:: /src/typst/crates/typst-layout/src/inline/linebreak.rs:790:9 Step #5: #20 0x560ca76d4f12 in typst_layout::inline::linebreak::linebreak_simple /src/typst/crates/typst-layout/src/inline/linebreak.rs:176:5 Step #5: #21 0x560ca76d4f12 in typst_layout::inline::linebreak::linebreak /src/typst/crates/typst-layout/src/inline/linebreak.rs:158:31 Step #5: #22 0x560ca76d4f12 in typst_layout::inline::layout_inline_impl /src/typst/crates/typst-layout/src/inline/mod.rs:174:17 Step #5: #23 0x560ca766e0de in typst_layout::inline::layout_par_impl::{closure#0} /src/typst/crates/typst-layout/src/inline/mod.rs:108:5 Step #5: #24 0x560ca766e0de in comemo::memoize::memoize::, comemo::track::Tracked, &typst_utils::hash::LazyHash, comemo::track::Tracked, comemo::track::Tracked, comemo::track::TrackedMut, comemo::track::Tracked, comemo::track::Tracked, typst_library::foundations::styles::StyleChain, typst_library::layout::axes::Axes, bool, typst_layout::inline::ParSituation)>, core::result::Result>, typst_layout::inline::layout_par_impl::{closure#0}> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/comemo-0.5.1/src/memoize.rs:71:18 Step #5: #25 0x560ca766e0de in typst_layout::inline::layout_par_impl /src/typst/crates/typst-layout/src/inline/mod.rs:70:1 Step #5: #26 0x560ca766e0de in typst_layout::inline::layout_par /src/typst/crates/typst-layout/src/inline/mod.rs:53:5 Step #5: #27 0x560ca766e0de in ::par /src/typst/crates/typst-layout/src/flow/collect.rs:167:21 Step #5: #28 0x560ca766e0de in ::run_block /src/typst/crates/typst-layout/src/flow/collect.rs:101:22 Step #5: #29 0x560ca766e0de in ::run /src/typst/crates/typst-layout/src/flow/collect.rs:81:54 Step #5: #30 0x560ca766e0de in typst_layout::flow::collect::collect /src/typst/crates/typst-layout/src/flow/collect.rs:50:6 Step #5: #31 0x560ca766e0de in typst_layout::flow::layout_flow /src/typst/crates/typst-layout/src/flow/mod.rs:212:20 Step #5: #32 0x560ca754d396 in typst_layout::pages::run::layout_page_run_impl::{closure#0} /src/typst/crates/typst-layout/src/pages/run.rs:189:20 Step #5: #33 0x560ca77576f8 in comemo::memoize::memoize::, &typst_utils::hash::LazyHash, comemo::track::Tracked, comemo::track::Tracked, comemo::track::TrackedMut, comemo::track::Tracked, &[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], comemo::track::Tracked, typst_library::foundations::styles::StyleChain)>, core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::run::layout_page_run_impl::{closure#0}> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/comemo-0.5.1/src/memoize.rs:71:18 Step #5: #34 0x560ca77576f8 in typst_layout::pages::run::layout_page_run_impl /src/typst/crates/typst-layout/src/pages/run.rs:76:1 Step #5: #35 0x560ca77576f8 in typst_layout::pages::run::layout_page_run /src/typst/crates/typst-layout/src/pages/run.rs:62:5 Step #5: #36 0x560ca74e78d7 in typst_layout::pages::layout_pages::{closure#1} /src/typst/crates/typst-layout/src/pages/mod.rs:197:13 Step #5: #37 0x560ca74e78d7 in ::parallelize::, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0} /src/typst/crates/typst-library/src/engine.rs:86:18 Step #5: #38 0x560ca74e78d7 in <&::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0} as core::ops::function::FnMut<((&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator),)>>::call_mut /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/core/src/ops/function.rs:274:22 Step #5: #39 0x560ca74e78d7 in <&mut &::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0} as core::ops::function::FnOnce<((&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator),)>>::call_once /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/core/src/ops/function.rs:310:21 Step #5: #40 0x560ca74e78d7 in >::map::<(core::result::Result, ecow::vec::EcoVec>, typst_library::engine::Sink), &mut &::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/core/src/option.rs:1165:29 Step #5: #41 0x560ca74e78d7 in , &::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}> as core::iter::traits::iterator::Iterator>::next /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/core/src/iter/adapters/map.rs:107:26 Step #5: #42 0x560ca74e78d7 in , ecow::vec::EcoVec>, typst_library::engine::Sink)> as rayon::iter::plumbing::Folder<(core::result::Result, ecow::vec::EcoVec>, typst_library::engine::Sink)>>::consume_iter::, &::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}>> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/iter/plumbing/mod.rs:173:21 Step #5: #43 0x560ca74e78d7 in , ecow::vec::EcoVec>, typst_library::engine::Sink)>, ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}> as rayon::iter::plumbing::Folder<(&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator)>>::consume_iter::> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/iter/map.rs:244:31 Step #5: #44 0x560ca74e78d7 in as rayon::iter::plumbing::Producer>::fold_with::, ecow::vec::EcoVec>, typst_library::engine::Sink)>, ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}>> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/iter/plumbing/mod.rs:107:16 Step #5: #45 0x560ca74e78d7 in rayon::iter::plumbing::bridge_producer_consumer::helper::, rayon::iter::map::MapConsumer, ecow::vec::EcoVec>, typst_library::engine::Sink)>, ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}>> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/iter/plumbing/mod.rs:432:22 Step #5: #46 0x560ca76b385f in rayon::iter::plumbing::bridge_producer_consumer::, rayon::iter::map::MapConsumer, ecow::vec::EcoVec>, typst_library::engine::Sink)>, ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}>> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/iter/plumbing/mod.rs:391:12 Step #5: #47 0x560ca76b385f in , ecow::vec::EcoVec>, typst_library::engine::Sink)>, ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}>> as rayon::iter::plumbing::ProducerCallback<(&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator)>>::callback::> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/iter/plumbing/mod.rs:368:13 Step #5: #48 0x560ca76b385f in as rayon::iter::IndexedParallelIterator>::with_producer::, ecow::vec::EcoVec>, typst_library::engine::Sink)>, ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}>>> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/vec.rs:156:22 Step #5: #49 0x560ca76b385f in as rayon::iter::IndexedParallelIterator>::with_producer::, ecow::vec::EcoVec>, typst_library::engine::Sink)>, ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}>>> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/vec.rs:92:32 Step #5: #50 0x560ca76b385f in rayon::iter::plumbing::bridge::, rayon::iter::map::MapConsumer, ecow::vec::EcoVec>, typst_library::engine::Sink)>, ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}>> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/iter/plumbing/mod.rs:352:21 Step #5: #51 0x560ca76b385f in as rayon::iter::IndexedParallelIterator>::drive::, ecow::vec::EcoVec>, typst_library::engine::Sink)>, ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}>> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/vec.rs:80:9 Step #5: #52 0x560ca76b385f in , ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}> as rayon::iter::IndexedParallelIterator>::drive::, ecow::vec::EcoVec>, typst_library::engine::Sink)>> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/iter/map.rs:64:19 Step #5: #53 0x560ca76b385f in rayon::iter::collect::collect_into_vec::, ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}>, (core::result::Result, ecow::vec::EcoVec>, typst_library::engine::Sink)>::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/iter/collect/mod.rs:20:49 Step #5: #54 0x560ca76b385f in rayon::iter::collect::collect_with_consumer::<(core::result::Result, ecow::vec::EcoVec>, typst_library::engine::Sink), rayon::iter::collect::collect_into_vec, ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}>, (core::result::Result, ecow::vec::EcoVec>, typst_library::engine::Sink)>::{closure#0}> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/iter/collect/mod.rs:84:18 Step #5: #55 0x560ca76b385f in rayon::iter::collect::collect_into_vec::, ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}>, (core::result::Result, ecow::vec::EcoVec>, typst_library::engine::Sink)> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/iter/collect/mod.rs:20:5 Step #5: #56 0x560ca76b385f in , ::parallelize, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}>::{closure#0}> as rayon::iter::IndexedParallelIterator>::collect_into_vec /rust/registry/src/index.crates.io-1949cf8c6b5b557f/rayon-1.12.0/src/iter/mod.rs:2524:9 Step #5: #57 0x560ca76b385f in ::parallelize::, typst_layout::pages::layout_pages::{closure#0}>, core::iter::adapters::filter_map::FilterMap, typst_layout::pages::layout_pages::{closure#0}>, (&&[(&typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)], &typst_library::foundations::styles::StyleChain, typst_library::introspection::locator::Locator), core::result::Result, ecow::vec::EcoVec>, typst_layout::pages::layout_pages::{closure#1}> /src/typst/crates/typst-library/src/engine.rs:88:14 Step #5: #58 0x560ca76b385f in typst_layout::pages::layout_pages /src/typst/crates/typst-layout/src/pages/mod.rs:189:27 Step #5: #59 0x560ca76b385f in typst_layout::pages::layout_document_common /src/typst/crates/typst-layout/src/pages/mod.rs:173:17 Step #5: #60 0x560ca76ac1e7 in typst_layout::pages::layout_document_impl::{closure#0} /src/typst/crates/typst-layout/src/pages/mod.rs:65:5 Step #5: #61 0x560ca76ac1e7 in comemo::memoize::memoize::, &typst_utils::hash::LazyHash, comemo::track::Tracked, comemo::track::Tracked, comemo::track::TrackedMut, comemo::track::Tracked, &typst_library::foundations::content::Content, typst_library::foundations::styles::StyleChain)>, core::result::Result>, typst_layout::pages::layout_document_impl::{closure#0}> /rust/registry/src/index.crates.io-1949cf8c6b5b557f/comemo-0.5.1/src/memoize.rs:71:18 Step #5: #62 0x560ca76ac1e7 in typst_layout::pages::layout_document_impl /src/typst/crates/typst-layout/src/pages/mod.rs:53:1 Step #5: #63 0x560ca76ac1e7 in typst_layout::pages::layout_document /src/typst/crates/typst-layout/src/pages/mod.rs:40:5 Step #5: #64 0x560ca77a285c in ::create /src/typst/crates/typst-layout/src/document.rs:92:9 Step #5: #65 0x560ca5d1a121 in typst::compile_impl:: /src/typst/crates/typst/src/lib.rs:157:20 Step #5: #66 0x560ca5d6960d in typst::compile:: /src/typst/crates/typst/src/lib.rs:80:18 Step #5: #67 0x560ca5d6960d in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:13:27 Step #5: #68 0x560ca5d74be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #69 0x560ca5b20c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #70 0x560ca5b20c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #71 0x560ca5b21738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #72 0x560ca5b20874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #73 0x560ca5b20874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #74 0x560ca5b20874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #75 0x560caa42aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #76 0x560caa433928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #77 0x560caa41b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #78 0x560caa446112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #79 0x7fe1ccf74082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #80 0x560ca3d40b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: raise--abort--std::sys::pal::unix::abort_internal (.llvm.4199261174039724961) Step #5: ==33694==Register values: Step #5: rax = 0x0000000000000000 rbx = 0x00007fe1ccf4f580 rcx = 0x00007fe1ccf9300b rdx = 0x0000000000000000 Step #5: rdi = 0x0000000000000002 rsi = 0x00007ffff93cf5f0 rbp = 0x00007ffff93cf840 rsp = 0x00007ffff93cf5f0 Step #5: r8 = 0x0000000000000000 r9 = 0x00007ffff93cf5f0 r10 = 0x0000000000000008 r11 = 0x0000000000000246 Step #5: r12 = 0x0000000000000000 r13 = 0x0000560caf8a95a8 r14 = 0x0000560ca6b86240 r15 = 0x0000000000000001 Step #5: AddressSanitizer can not provide additional info. Step #5: SUMMARY: AddressSanitizer: ABRT (/lib/x86_64-linux-gnu/libc.so.6+0x4300b) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) in raise Step #5: ==33694==ABORTING Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd8,0x80,0x20,0xd8,0x94,0xda,0x80, Step #5: \330\200 \330\224\332\200 Step #5: artifact_prefix='./'; Test unit written to ./crash-0e57f6c94ed6999af28f3653f1bf06c8f1a327a5 Step #5: Base64: 2IAg2JTagA== Step #5: MERGE-OUTER: attempt 936 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2201417970 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a65eb32810, 0x55a65ed1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a65ed1c020,0x55a660bb40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/regressions/0e57f6c94ed6999af28f3653f1bf06c8f1a327a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1051 processed earlier; will process 9978 files now Step #5: ==33730== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a6556279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a65bc8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a65bc6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a65bc6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a65562dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a65558eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a655589355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a65561fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a6585eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a6585eef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a6585eef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a6585eef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a6585eef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a6585eef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a6585eef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a6585eef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a6585eef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a6585eef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a65a883f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a6575b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a6575bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a657367c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a657367c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a657368738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a657367874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a657367874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a657367874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a65bc71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a65bc7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a65bc62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a65bc8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f17abb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a655587b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x3a,0x2d,0x57,0x30,0x75,0x2b, Step #5: f:-W0u+ Step #5: artifact_prefix='./'; Test unit written to ./oom-178a88a5dab55175ecc0d4a7aff8234f2e81ff2f Step #5: Base64: ZjotVzB1Kw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 937 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2201859093 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55817fc3a810, 0x55817fe2401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55817fe24020,0x558181cbc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/178a88a5dab55175ecc0d4a7aff8234f2e81ff2f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1052 processed earlier; will process 9977 files now Step #5: ==33766== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55817672f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55817cd94898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55817cd775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55817cd774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558176735d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558176696b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558176691355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558176727c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5581796f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5581796f6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5581796f6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5581796f6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5581796f6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5581796f6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5581796f6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5581796f6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5581796f6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5581796f6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55817b98bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5581786b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5581786c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55817846fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55817846fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558178470738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55817846f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55817846f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55817846f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55817cd79abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55817cd82928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55817cd6a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55817cd95112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f60fb3cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55817668fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x68,0x6d,0x74,0x78,0x58,0x26,0x63, Step #5: hmtxX&c Step #5: artifact_prefix='./'; Test unit written to ./oom-aaead0fa757aeb9b6ae0b685c83d5d5d28eb7127 Step #5: Base64: aG10eFgmYw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 938 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2202293601 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e36963c810, 0x55e36982601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e369826020,0x55e36b6be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aaead0fa757aeb9b6ae0b685c83d5d5d28eb7127' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1053 processed earlier; will process 9976 files now Step #5: ==33802== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e3601319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e366796898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e3667795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e3667794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e360137d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e360098b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e360093355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e360129c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e3630f8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e3630f8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e3630f8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e3630f8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e3630f8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e3630f8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e3630f8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e3630f8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e3630f8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e3630f8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e36538df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e3620bab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e3620c5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e361e71c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e361e71c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e361e72738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e361e71874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e361e71874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e361e71874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e36677babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e366784928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e36676c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e366797112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fad5c237082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e360091b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x24,0x24, Step #5: \000\000\000\000\000$$ Step #5: artifact_prefix='./'; Test unit written to ./oom-3ffbb585d275aaab4a8db85a0b56d45c522d6283 Step #5: Base64: AAAAAAAkJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 939 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2202727941 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556dcac21810, 0x556dcae0b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556dcae0b020,0x556dccca30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3ffbb585d275aaab4a8db85a0b56d45c522d6283' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1054 processed earlier; will process 9975 files now Step #5: ==33838== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556dc17169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556dc7d7b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556dc7d5e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556dc7d5e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556dc171cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556dc167db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556dc1678355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556dc170ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556dc46ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556dc46ddf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556dc46ddf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556dc46ddf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556dc46ddf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556dc46ddf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556dc46ddf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556dc46ddf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556dc46ddf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556dc46ddf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556dc6972f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556dc369fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556dc36aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556dc3456c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556dc3456c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556dc3457738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556dc3456874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556dc3456874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556dc3456874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556dc7d60abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556dc7d69928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556dc7d51699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556dc7d7c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc575127082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556dc1676b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x52,0x2d,0x2d,0x2d,0x30,0x3e, Step #5: Step #5: artifact_prefix='./'; Test unit written to ./oom-f3a9dc244a526c89a50e92ea0396221ef3ad13e6 Step #5: Base64: PFItLS0wPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 940 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2203149336 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5648467cb810, 0x5648469b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5648469b5020,0x56484884d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f3a9dc244a526c89a50e92ea0396221ef3ad13e6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1055 processed earlier; will process 9974 files now Step #5: ==33874== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56483d2c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564843925898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5648439085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5648439084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56483d2c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56483d227b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56483d222355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56483d2b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564840287f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564840287f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564840287f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564840287f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564840287f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564840287f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564840287f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564840287f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564840287f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564840287f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56484251cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56483f249b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56483f254be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56483f000c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56483f000c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56483f001738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56483f000874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56483f000874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56483f000874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56484390aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564843913928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5648438fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564843926112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f041f394082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56483d220b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x1f,0x5f,0x5f,0x1,0x6,0x7, Step #5: \003\037__\001\006\007 Step #5: artifact_prefix='./'; Test unit written to ./oom-d4a54dfcfe18ecdf3a4ac7b47d3fd23b98b090e7 Step #5: Base64: Ax9fXwEGBw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 941 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2203583907 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ce27d16810, 0x55ce27f0001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ce27f00020,0x55ce29d980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d4a54dfcfe18ecdf3a4ac7b47d3fd23b98b090e7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1056 processed earlier; will process 9973 files now Step #5: ==33910== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ce1e80b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ce24e70898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ce24e535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ce24e534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ce1e811d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ce1e772b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ce1e76d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ce1e803c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ce217d2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ce217d2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ce217d2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ce217d2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ce217d2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ce217d2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ce217d2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ce217d2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ce217d2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ce217d2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ce23a67f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ce20794b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ce2079fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ce2054bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ce2054bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ce2054c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ce2054b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ce2054b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ce2054b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ce24e55abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ce24e5e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ce24e46699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ce24e71112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbecbf6e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ce1e76bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x22,0x24,0x68,0x6e,0x22,0x6d, Step #5: #\"$hn\"m Step #5: artifact_prefix='./'; Test unit written to ./oom-066f4ccad4d2926d649b341162f0cdcb9e4b9dce Step #5: Base64: IyIkaG4ibQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 942 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2204018873 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cad0b72810, 0x55cad0d5c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cad0d5c020,0x55cad2bf40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/066f4ccad4d2926d649b341162f0cdcb9e4b9dce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1057 processed earlier; will process 9972 files now Step #5: ==33946== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cac76679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cacdccc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cacdcaf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cacdcaf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cac766dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cac75ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cac75c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cac765fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55caca62ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55caca62ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55caca62ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55caca62ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55caca62ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55caca62ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55caca62ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55caca62ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55caca62ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55caca62ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cacc8c3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cac95f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cac95fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cac93a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cac93a7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cac93a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cac93a7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cac93a7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cac93a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cacdcb1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cacdcba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cacdca2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cacdccd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fce31f38082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cac75c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x52,0x22,0x22,0x22,0xe0,0xba,0xb5, Step #5: R\"\"\"\340\272\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-4bfafc062cf3a8d19678ef23a5c30b9d23f3c3c3 Step #5: Base64: UiIiIuC6tQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 943 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2204451124 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5602da670810, 0x5602da85a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5602da85a020,0x5602dc6f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4bfafc062cf3a8d19678ef23a5c30b9d23f3c3c3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1058 processed earlier; will process 9971 files now Step #5: ==33982== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5602d11659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5602d77ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602d77ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602d77ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5602d116bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5602d10ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5602d10c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5602d115dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5602d412cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5602d412cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5602d412cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5602d412cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5602d412cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5602d412cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5602d412cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5602d412cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5602d412cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5602d412cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5602d63c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5602d30eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5602d30f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5602d2ea5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5602d2ea5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5602d2ea6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5602d2ea5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5602d2ea5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5602d2ea5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5602d77afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5602d77b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5602d77a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5602d77cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc948ef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5602d10c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0xef,0xb7,0xbe, Step #5: (?i)\357\267\276 Step #5: artifact_prefix='./'; Test unit written to ./oom-ffd0a0e9df68d33c0c25e3bc001bde1be3fc5290 Step #5: Base64: KD9pKe+3vg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 944 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2204897669 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d07e37b810, 0x55d07e56501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d07e565020,0x55d0803fd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ffd0a0e9df68d33c0c25e3bc001bde1be3fc5290' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1059 processed earlier; will process 9970 files now Step #5: #1 pulse cov: 3533 ft: 3534 exec/s: 0 rss: 160Mb Step #5: ==34018== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d074e709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d07b4d5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d07b4b85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d07b4b84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d074e76d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d074dd7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d074dd2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d074e68c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d077e37f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d077e37f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d077e37f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d077e37f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d077e37f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d077e37f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d077e37f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d077e37f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d077e37f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d077e37f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d07a0ccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d076df9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d076e04be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d076bb0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d076bb0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d076bb1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d076bb0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d076bb0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d076bb0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d07b4baabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d07b4c3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d07b4ab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d07b4d6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbaf22a1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d074dd0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0xa,0xa,0x2b,0xa,0xa,0x2b, Step #5: c\012\012+\012\012+ Step #5: artifact_prefix='./'; Test unit written to ./oom-6dc694df433b0f5648ba9da08f926bf78f6d9b98 Step #5: Base64: YwoKKwoKKw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 945 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2205373544 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55efa6db8810, 0x55efa6fa201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55efa6fa2020,0x55efa8e3a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6dc694df433b0f5648ba9da08f926bf78f6d9b98' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1061 processed earlier; will process 9968 files now Step #5: ==34054== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ef9d8ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55efa3f12898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55efa3ef55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55efa3ef54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef9d8b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef9d814b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef9d80f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef9d8a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55efa0874f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55efa0874f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55efa0874f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55efa0874f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55efa0874f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55efa0874f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55efa0874f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55efa0874f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55efa0874f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55efa0874f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55efa2b09f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef9f836b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef9f841be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef9f5edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef9f5edc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef9f5ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef9f5ed874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef9f5ed874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef9f5ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55efa3ef7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55efa3f00928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55efa3ee8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55efa3f13112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ab2242082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef9d80db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xde,0x90,0xde,0x98,0xf,0xd6,0xb8, Step #5: \336\220\336\230\017\326\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-746b6260a8d998eda1d9fd628c11cad123e7b1be Step #5: Base64: 3pDemA/WuA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 946 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2205813661 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e69fb39810, 0x55e69fd2301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e69fd23020,0x55e6a1bbb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/746b6260a8d998eda1d9fd628c11cad123e7b1be' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1062 processed earlier; will process 9967 files now Step #5: ==34090== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e69662e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e69cc93898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e69cc765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e69cc764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e696634d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e696595b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e696590355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e696626c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e6995f5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e6995f5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e6995f5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e6995f5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e6995f5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e6995f5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e6995f5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e6995f5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e6995f5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e6995f5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e69b88af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e6985b7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e6985c2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e69836ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e69836ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e69836f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e69836e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e69836e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e69836e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e69cc78abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e69cc81928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e69cc69699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e69cc94112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f73f7028082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e69658eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0x8e,0x80,0xa1,0x7b,0x34,0x7d, Step #5: \363\216\200\241{4} Step #5: artifact_prefix='./'; Test unit written to ./oom-2e5a8224feee00c781bdb04757d69c65fc09d3af Step #5: Base64: 846AoXs0fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 947 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2206246753 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647ea71e810, 0x5647ea90801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5647ea908020,0x5647ec7a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2e5a8224feee00c781bdb04757d69c65fc09d3af' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1063 processed earlier; will process 9966 files now Step #5: ==34126== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5647e12139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647e7878898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647e785b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647e785b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647e1219d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647e117ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647e1175355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647e120bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647e41daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647e41daf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647e41daf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647e41daf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647e41daf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647e41daf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647e41daf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647e41daf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647e41daf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647e41daf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647e646ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647e319cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647e31a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647e2f53c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647e2f53c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647e2f54738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647e2f53874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647e2f53874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647e2f53874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647e785dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647e7866928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647e784e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647e7879112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a8d3e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647e1173b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xf3,0xa0,0x81,0x80,0x3e,0x3a, Step #5: <\363\240\201\200>: Step #5: artifact_prefix='./'; Test unit written to ./oom-321c09f8f9aa667820c2f5f14b4bbdc74bc9322d Step #5: Base64: PPOggYA+Og== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 948 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2206679497 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b21b63810, 0x556b21d4d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b21d4d020,0x556b23be50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/321c09f8f9aa667820c2f5f14b4bbdc74bc9322d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1064 processed earlier; will process 9965 files now Step #5: ==34162== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556b186589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b1ecbd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b1eca05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b1eca04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b1865ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b185bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b185ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b18650c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b1b61ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b1b61ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b1b61ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b1b61ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b1b61ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b1b61ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b1b61ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b1b61ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b1b61ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b1b61ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b1d8b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b1a5e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b1a5ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b1a398c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b1a398c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b1a399738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b1a398874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b1a398874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b1a398874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b1eca2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b1ecab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b1ec93699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b1ecbe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7d2d64082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b185b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4f,0x55,0x58,0x53,0x2e,0x2e,0x70, Step #5: OUXS..p Step #5: artifact_prefix='./'; Test unit written to ./oom-b0b4a66d9d0c378d06c81e681cf1eedc26b3a89d Step #5: Base64: T1VYUy4ucA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 949 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2207114449 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5653a6dcf810, 0x5653a6fb901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5653a6fb9020,0x5653a8e510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b0b4a66d9d0c378d06c81e681cf1eedc26b3a89d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1065 processed earlier; will process 9964 files now Step #5: ==34198== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56539d8c49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5653a3f29898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5653a3f0c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5653a3f0c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56539d8cad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56539d82bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56539d826355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56539d8bcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5653a088bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5653a088bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5653a088bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5653a088bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5653a088bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5653a088bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5653a088bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5653a088bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5653a088bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5653a088bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5653a2b20f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56539f84db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56539f858be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56539f604c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56539f604c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56539f605738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56539f604874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56539f604874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56539f604874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5653a3f0eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5653a3f17928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5653a3eff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5653a3f2a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f08a2e3f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56539d824b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xbf,0x3c,0x4b,0x3e,0x26, Step #5: \357\273\277& Step #5: artifact_prefix='./'; Test unit written to ./oom-03d533a39443f344efa6cb8e621cef49eb5199b0 Step #5: Base64: 77u/PEs+Jg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 950 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2207549923 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c0dc6a3810, 0x55c0dc88d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c0dc88d020,0x55c0de7250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03d533a39443f344efa6cb8e621cef49eb5199b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1066 processed earlier; will process 9963 files now Step #5: ==34234== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c0d31989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c0d97fd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c0d97e05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c0d97e04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c0d319ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c0d30ffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c0d30fa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c0d3190c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c0d615ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c0d615ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c0d615ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c0d615ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c0d615ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c0d615ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c0d615ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c0d615ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c0d615ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c0d615ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c0d83f4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c0d5121b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c0d512cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c0d4ed8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c0d4ed8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c0d4ed9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c0d4ed8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c0d4ed8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c0d4ed8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c0d97e2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c0d97eb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c0d97d3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c0d97fe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f447bd28082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c0d30f8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xf0,0x96,0xb9,0x9f, Step #5: ws:\360\226\271\237 Step #5: artifact_prefix='./'; Test unit written to ./oom-472eaada1f8ca2bc0d15bd49339c3c950e707e33 Step #5: Base64: d3M68Ja5nw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 951 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2207983645 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610bb062810, 0x5610bb24c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610bb24c020,0x5610bd0e40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/472eaada1f8ca2bc0d15bd49339c3c950e707e33' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1067 processed earlier; will process 9962 files now Step #5: ==34270== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5610b1b579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610b81bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610b819f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610b819f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610b1b5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610b1abeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610b1ab9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610b1b4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610b4b1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610b4b1ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610b4b1ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610b4b1ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610b4b1ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610b4b1ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610b4b1ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610b4b1ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610b4b1ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610b4b1ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610b6db3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610b3ae0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610b3aebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610b3897c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610b3897c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610b3898738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610b3897874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610b3897874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610b3897874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610b81a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610b81aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610b8192699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610b81bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8125681082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610b1ab7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x42,0x6e,0x4b, Step #5: DanMBnK Step #5: artifact_prefix='./'; Test unit written to ./oom-271708807af567afbae5087ee0d3db253c5ace88 Step #5: Base64: RGFuTUJuSw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 952 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2208414983 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640f48a8810, 0x5640f4a9201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640f4a92020,0x5640f692a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/271708807af567afbae5087ee0d3db253c5ace88' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1068 processed earlier; will process 9961 files now Step #5: #1 pulse cov: 3852 ft: 3853 exec/s: 0 rss: 164Mb Step #5: #2 pulse cov: 4333 ft: 4520 exec/s: 0 rss: 165Mb Step #5: ==34306== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5640eb39d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5640f1a02898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640f19e55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640f19e54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5640eb3a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5640eb304b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5640eb2ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5640eb395c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5640ee364f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5640ee364f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5640ee364f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5640ee364f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5640ee364f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5640ee364f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5640ee364f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5640ee364f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5640ee364f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5640ee364f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5640f05f9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5640ed326b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5640ed331be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5640ed0ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5640ed0ddc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5640ed0de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5640ed0dd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5640ed0dd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5640ed0dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5640f19e7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5640f19f0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5640f19d8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5640f1a03112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8bd5bde082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5640eb2fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x3a,0x33,0xd,0x35,0x2c,0x4c, Step #5: 0:3\0155,L Step #5: artifact_prefix='./'; Test unit written to ./oom-bf8b8a4c6d6ce48b629b05917b414ac283a3f080 Step #5: Base64: MDozDTUsTA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 953 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2208955157 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f074b17810, 0x55f074d0101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f074d01020,0x55f076b990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf8b8a4c6d6ce48b629b05917b414ac283a3f080' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1072 processed earlier; will process 9957 files now Step #5: ==34342== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f06b60c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f071c71898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f071c545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f071c544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f06b612d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f06b573b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f06b56e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f06b604c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f06e5d3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f06e5d3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f06e5d3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f06e5d3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f06e5d3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f06e5d3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f06e5d3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f06e5d3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f06e5d3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f06e5d3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f070868f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f06d595b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f06d5a0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f06d34cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f06d34cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f06d34d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f06d34c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f06d34c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f06d34c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f071c56abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f071c5f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f071c47699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f071c72112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8dd86f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f06b56cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0xe0,0xa3,0x9a, Step #5: \000\000\000\000\340\243\232 Step #5: artifact_prefix='./'; Test unit written to ./oom-b30c008199aef59a61588522bbc99fcc7af543a3 Step #5: Base64: AAAAAOCjmg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 954 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2209390706 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562bcec32810, 0x562bcee1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562bcee1c020,0x562bd0cb40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b30c008199aef59a61588522bbc99fcc7af543a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1073 processed earlier; will process 9956 files now Step #5: ==34378== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562bc57279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562bcbd8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562bcbd6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562bcbd6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562bc572dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562bc568eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562bc5689355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562bc571fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562bc86eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562bc86eef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562bc86eef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562bc86eef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562bc86eef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562bc86eef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562bc86eef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562bc86eef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562bc86eef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562bc86eef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562bca983f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562bc76b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562bc76bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562bc7467c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562bc7467c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562bc7468738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562bc7467874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562bc7467874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562bc7467874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562bcbd71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562bcbd7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562bcbd62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562bcbd8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f175f8d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562bc5687b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x66,0x66,0x6c,0x6f,0x78,0x70, Step #5: sffloxp Step #5: artifact_prefix='./'; Test unit written to ./oom-70a48f394174a1ac52e57b43e4ad4ea10f6d5e9a Step #5: Base64: c2ZmbG94cA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 955 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2209832457 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5558c1090810, 0x5558c127a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5558c127a020,0x5558c31120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70a48f394174a1ac52e57b43e4ad4ea10f6d5e9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1074 processed earlier; will process 9955 files now Step #5: ==34414== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5558b7b859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5558be1ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5558be1cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5558be1cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5558b7b8bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5558b7aecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5558b7ae7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5558b7b7dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5558bab4cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5558bab4cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5558bab4cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5558bab4cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5558bab4cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5558bab4cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5558bab4cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5558bab4cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5558bab4cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5558bab4cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5558bcde1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5558b9b0eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5558b9b19be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5558b98c5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5558b98c5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5558b98c6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5558b98c5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5558b98c5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5558b98c5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5558be1cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5558be1d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5558be1c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5558be1eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2bb637d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5558b7ae5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d, Step #5: ---\012--- Step #5: artifact_prefix='./'; Test unit written to ./oom-2abb1b9f1ba9375e7ecfce11de5fd95dcf59b291 Step #5: Base64: LS0tCi0tLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 956 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2210269963 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0cf82e810, 0x55b0cfa1801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b0cfa18020,0x55b0d18b00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2abb1b9f1ba9375e7ecfce11de5fd95dcf59b291' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1075 processed earlier; will process 9954 files now Step #5: #1 pulse cov: 3629 ft: 3630 exec/s: 0 rss: 164Mb Step #5: ==34450== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b0c63239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b0cc988898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b0cc96b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b0cc96b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0c6329d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0c628ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0c6285355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0c631bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b0c92eaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b0c92eaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b0c92eaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b0c92eaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b0c92eaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b0c92eaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b0c92eaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b0c92eaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b0c92eaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b0c92eaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b0cb57ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b0c82acb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b0c82b7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b0c8063c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b0c8063c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b0c8064738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b0c8063874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b0c8063874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b0c8063874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b0cc96dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b0cc976928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b0cc95e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b0cc989112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe0639ae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0c6283b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x5c,0xd7,0x96,0x26,0x96,0x26, Step #5: B\\\327\226&\226& Step #5: artifact_prefix='./'; Test unit written to ./oom-667eb38c9e48673f5c263be2e87cd99f357e0433 Step #5: Base64: QlzXliaWJg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 957 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2210736547 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d43b344810, 0x55d43b52e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d43b52e020,0x55d43d3c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/667eb38c9e48673f5c263be2e87cd99f357e0433' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1077 processed earlier; will process 9952 files now Step #5: ==34486== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d431e399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d43849e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d4384815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d4384814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d431e3fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d431da0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d431d9b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d431e31c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d434e00f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d434e00f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d434e00f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d434e00f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d434e00f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d434e00f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d434e00f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d434e00f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d434e00f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d434e00f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d437095f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d433dc2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d433dcdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d433b79c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d433b79c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d433b7a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d433b79874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d433b79874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d433b79874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d438483abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d43848c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d438474699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d43849f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd2fda0c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d431d99b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd7,0xa9,0x28,0x1,0x9,0x37,0x74, Step #5: \327\251(\001\0117t Step #5: artifact_prefix='./'; Test unit written to ./oom-4f7ce2f9121d22026654fdd2bc5b352d97c1669c Step #5: Base64: 16koAQk3dA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 958 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2211167710 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555cc68bc810, 0x555cc6aa601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555cc6aa6020,0x555cc893e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f7ce2f9121d22026654fdd2bc5b352d97c1669c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1078 processed earlier; will process 9951 files now Step #5: ==34522== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555cbd3b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555cc3a16898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555cc39f95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555cc39f94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555cbd3b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555cbd318b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555cbd313355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555cbd3a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555cc0378f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555cc0378f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555cc0378f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555cc0378f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555cc0378f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555cc0378f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555cc0378f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555cc0378f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555cc0378f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555cc0378f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555cc260df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555cbf33ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555cbf345be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555cbf0f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555cbf0f1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555cbf0f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555cbf0f1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555cbf0f1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555cbf0f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555cc39fbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555cc3a04928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555cc39ec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555cc3a17112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f50f75fb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555cbd311b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xf0,0x9e,0x92,0xa9,0x2f,0x3e, Step #5: <\360\236\222\251/> Step #5: artifact_prefix='./'; Test unit written to ./oom-1190661f2765bfa9b1521ddec017ea5d474691a1 Step #5: Base64: PPCekqkvPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 959 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2211598081 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d76100c810, 0x55d7611f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d7611f6020,0x55d76308e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1190661f2765bfa9b1521ddec017ea5d474691a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1079 processed earlier; will process 9950 files now Step #5: ==34558== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d757b019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d75e166898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d75e1495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d75e1494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d757b07d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d757a68b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d757a63355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d757af9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d75aac8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d75aac8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d75aac8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d75aac8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d75aac8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d75aac8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d75aac8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d75aac8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d75aac8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d75aac8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d75cd5df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d759a8ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d759a95be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d759841c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d759841c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d759842738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d759841874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d759841874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d759841874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d75e14babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d75e154928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d75e13c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d75e167112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f48c2520082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d757a61b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x66,0x66,0x66,0x66,0x66,0x3a, Step #5: ffffff: Step #5: artifact_prefix='./'; Test unit written to ./oom-5aada763ab7ca9cbbb96cec0c2e23f02debff81c Step #5: Base64: ZmZmZmZmOg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 960 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2212027421 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56348f45b810, 0x56348f64501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56348f645020,0x5634914dd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5aada763ab7ca9cbbb96cec0c2e23f02debff81c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1080 processed earlier; will process 9949 files now Step #5: ==34594== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563485f509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56348c5b5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56348c5985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56348c5984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563485f56d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563485eb7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563485eb2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563485f48c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563488f17f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563488f17f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563488f17f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563488f17f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563488f17f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563488f17f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563488f17f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563488f17f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563488f17f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563488f17f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56348b1acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563487ed9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563487ee4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563487c90c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563487c90c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563487c91738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563487c90874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563487c90874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563487c90874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56348c59aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56348c5a3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56348c58b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56348c5b6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f049a564082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563485eb0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x45,0x27,0x5c,0xe0,0xbe,0x86,0x27, Step #5: E'\\\340\276\206' Step #5: artifact_prefix='./'; Test unit written to ./oom-ee96bd80ad7e6ade8b691e3c6975d2aa2c03e0fc Step #5: Base64: RSdc4L6GJw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 961 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2212462035 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5581e3008810, 0x5581e31f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5581e31f2020,0x5581e508a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee96bd80ad7e6ade8b691e3c6975d2aa2c03e0fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1081 processed earlier; will process 9948 files now Step #5: ==34630== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5581d9afd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5581e0162898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5581e01455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5581e01454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5581d9b03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5581d9a64b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5581d9a5f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5581d9af5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5581dcac4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5581dcac4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5581dcac4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5581dcac4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5581dcac4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5581dcac4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5581dcac4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5581dcac4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5581dcac4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5581dcac4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5581ded59f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5581dba86b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5581dba91be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5581db83dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5581db83dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5581db83e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5581db83d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5581db83d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5581db83d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5581e0147abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5581e0150928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5581e0138699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5581e0163112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f169b2ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5581d9a5db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x54,0xe2,0x81,0xa7,0x41,0x47,0xa4, Step #5: T\342\201\247AG\244 Step #5: artifact_prefix='./'; Test unit written to ./oom-7960e399f01f50f407000e2623712064f390c243 Step #5: Base64: VOKBp0FHpA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 962 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2212897939 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d1ed8e810, 0x556d1ef7801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d1ef78020,0x556d20e100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7960e399f01f50f407000e2623712064f390c243' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1082 processed earlier; will process 9947 files now Step #5: ==34666== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556d158839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d1bee8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d1becb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d1becb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d15889d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d157eab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d157e5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d1587bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d1884af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d1884af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d1884af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d1884af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d1884af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d1884af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d1884af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d1884af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d1884af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d1884af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d1aadff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d1780cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d17817be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d175c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d175c3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d175c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d175c3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d175c3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d175c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d1becdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d1bed6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d1bebe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d1bee9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcef388e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d157e3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5e,0xa,0x2d,0xdf,0xb3,0x5d, Step #5: [^\012-\337\263] Step #5: artifact_prefix='./'; Test unit written to ./oom-7aceadd136bbde7446fd4b96ef252691fe343a3c Step #5: Base64: W14KLd+zXQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 963 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2213330148 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556da8ea3810, 0x556da908d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556da908d020,0x556daaf250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7aceadd136bbde7446fd4b96ef252691fe343a3c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1083 processed earlier; will process 9946 files now Step #5: ==34702== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556d9f9989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556da5ffd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556da5fe05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556da5fe04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d9f99ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d9f8ffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d9f8fa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d9f990c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556da295ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556da295ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556da295ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556da295ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556da295ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556da295ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556da295ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556da295ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556da295ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556da295ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556da4bf4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556da1921b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556da192cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556da16d8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556da16d8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556da16d9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556da16d8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556da16d8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556da16d8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556da5fe2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556da5feb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556da5fd3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556da5ffe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f23cc986082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d9f8f8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0xc9,0x9c,0xe2,0xa1,0x8a,0x5d, Step #5: [\311\234\342\241\212] Step #5: artifact_prefix='./'; Test unit written to ./oom-fb8d313f973ed072be9c5f4107eb38118b661799 Step #5: Base64: W8mc4qGKXQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 964 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2213765947 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f61831c810, 0x55f61850601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f618506020,0x55f61a39e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fb8d313f973ed072be9c5f4107eb38118b661799' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1084 processed earlier; will process 9945 files now Step #5: ==34738== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f60ee119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f615476898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f6154595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f6154594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f60ee17d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f60ed78b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f60ed73355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f60ee09c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f611dd8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f611dd8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f611dd8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f611dd8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f611dd8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f611dd8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f611dd8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f611dd8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f611dd8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f611dd8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f61406df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f610d9ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f610da5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f610b51c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f610b51c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f610b52738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f610b51874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f610b51874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f610b51874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f61545babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f615464928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f61544c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f615477112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f47bf58f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f60ed71b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24, Step #5: $|$|$|$ Step #5: artifact_prefix='./'; Test unit written to ./oom-0bbb0b660aeaeb18471e19687a43bda0e192165e Step #5: Base64: JHwkfCR8JA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 965 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2214200534 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe0a006810, 0x55fe0a1f001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe0a1f0020,0x55fe0c0880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0bbb0b660aeaeb18471e19687a43bda0e192165e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1085 processed earlier; will process 9944 files now Step #5: ==34774== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fe00afb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe07160898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe071435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe071434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe00b01d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe00a62b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe00a5d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe00af3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe03ac2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe03ac2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe03ac2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe03ac2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe03ac2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe03ac2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe03ac2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe03ac2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe03ac2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe03ac2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe05d57f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe02a84b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe02a8fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe0283bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe0283bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe0283c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe0283b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe0283b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe0283b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe07145abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe0714e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe07136699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe07161112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d42725082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe00a5bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0xb7,0xc2,0xb7,0xc2,0xb7,0xb7, Step #5: \302\267\302\267\302\267\267 Step #5: artifact_prefix='./'; Test unit written to ./oom-56e717961ad3652ec7498fd56c13b4ad9c5dbfd2 Step #5: Base64: wrfCt8K3tw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 966 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2214635966 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557c90b7a810, 0x557c90d6401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557c90d64020,0x557c92bfc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56e717961ad3652ec7498fd56c13b4ad9c5dbfd2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1086 processed earlier; will process 9943 files now Step #5: ==34810== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557c8766f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557c8dcd4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557c8dcb75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557c8dcb74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557c87675d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557c875d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557c875d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557c87667c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557c8a636f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557c8a636f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557c8a636f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557c8a636f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557c8a636f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557c8a636f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557c8a636f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557c8a636f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557c8a636f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557c8a636f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557c8c8cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557c895f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557c89603be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557c893afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557c893afc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557c893b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557c893af874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557c893af874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557c893af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557c8dcb9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557c8dcc2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557c8dcaa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557c8dcd5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd99ac0f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557c875cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3c,0xef,0xbe,0xa0,0x3e, Step #5: (?<\357\276\240> Step #5: artifact_prefix='./'; Test unit written to ./oom-4683056f448fa766f577f90425f79fb84b0b0cda Step #5: Base64: KD88776gPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 967 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2215074316 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55601c215810, 0x55601c3ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55601c3ff020,0x55601e2970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4683056f448fa766f577f90425f79fb84b0b0cda' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1087 processed earlier; will process 9942 files now Step #5: ==34846== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556012d0a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55601936f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5560193525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5560193524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556012d10d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556012c71b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556012c6c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556012d02c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556015cd1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556015cd1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556015cd1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556015cd1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556015cd1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556015cd1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556015cd1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556015cd1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556015cd1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556015cd1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556017f66f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556014c93b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556014c9ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556014a4ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556014a4ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556014a4b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556014a4a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556014a4a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556014a4a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556019354abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55601935d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556019345699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556019370112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f36453f5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556012c6ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x45,0x27,0x5c,0xed,0x88,0x8a,0x27, Step #5: E'\\\355\210\212' Step #5: artifact_prefix='./'; Test unit written to ./oom-d64c8015f216bdcb0b3a1a1a54ae5c590997b0f6 Step #5: Base64: RSdc7YiKJw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 968 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2215518944 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bbbb7b8810, 0x55bbbb9a201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bbbb9a2020,0x55bbbd83a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d64c8015f216bdcb0b3a1a1a54ae5c590997b0f6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1088 processed earlier; will process 9941 files now Step #5: ==34882== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bbb22ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bbb8912898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bbb88f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bbb88f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bbb22b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bbb2214b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bbb220f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bbb22a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bbb5274f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bbb5274f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bbb5274f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bbb5274f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bbb5274f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bbb5274f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bbb5274f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bbb5274f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bbb5274f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bbb5274f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bbb7509f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bbb4236b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bbb4241be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bbb3fedc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bbb3fedc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bbb3fee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bbb3fed874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bbb3fed874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bbb3fed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bbb88f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bbb8900928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bbb88e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bbb8913112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7da4075082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bbb220db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x5c,0x75,0xf0,0x96,0xa7,0xad, Step #5: \"\\u\360\226\247\255 Step #5: artifact_prefix='./'; Test unit written to ./oom-fd392af99803dd6f8d53b5c4cb0edd8d5a3dbce2 Step #5: Base64: Ilx18JanrQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 969 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2215954705 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e978215810, 0x55e9783ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9783ff020,0x55e97a2970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fd392af99803dd6f8d53b5c4cb0edd8d5a3dbce2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1089 processed earlier; will process 9940 files now Step #5: ==34918== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e96ed0a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e97536f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9753525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9753524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e96ed10d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e96ec71b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e96ec6c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e96ed02c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e971cd1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e971cd1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e971cd1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e971cd1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e971cd1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e971cd1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e971cd1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e971cd1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e971cd1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e971cd1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e973f66f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e970c93b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e970c9ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e970a4ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e970a4ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e970a4b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e970a4a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e970a4a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e970a4a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e975354abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e97535d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e975345699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e975370112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f71c84d6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e96ec6ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x3f,0x2d,0xf3,0xbf,0xbf,0x80, Step #5: [?-\363\277\277\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-4062d68441014655e1a2d312e35b18dd28b4f8e5 Step #5: Base64: Wz8t87+/gA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 970 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2216391686 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56193c365810, 0x56193c54f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56193c54f020,0x56193e3e70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4062d68441014655e1a2d312e35b18dd28b4f8e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1090 processed earlier; will process 9939 files now Step #5: ==34954== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561932e5a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5619394bf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5619394a25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5619394a24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561932e60d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561932dc1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561932dbc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561932e52c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561935e21f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561935e21f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561935e21f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561935e21f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561935e21f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561935e21f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561935e21f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561935e21f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561935e21f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561935e21f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5619380b6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561934de3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561934deebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561934b9ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561934b9ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561934b9b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561934b9a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561934b9a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561934b9a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5619394a4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5619394ad928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561939495699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5619394c0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f331e19d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561932dbab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x20,0x2d,0xf1,0xbb,0xbf,0xbf, Step #5: [ -\361\273\277\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-c03915f922b17c58554135c3c3c7d701bd5065b5 Step #5: Base64: WyAt8bu/vw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 971 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2216832862 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55703006c810, 0x55703025601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557030256020,0x5570320ee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c03915f922b17c58554135c3c3c7d701bd5065b5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1091 processed earlier; will process 9938 files now Step #5: ==34990== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557026b619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55702d1c6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55702d1a95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55702d1a94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557026b67d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557026ac8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557026ac3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557026b59c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557029b28f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557029b28f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557029b28f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557029b28f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557029b28f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557029b28f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557029b28f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557029b28f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557029b28f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557029b28f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55702bdbdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557028aeab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557028af5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5570288a1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5570288a1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5570288a2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5570288a1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5570288a1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5570288a1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55702d1ababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55702d1b4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55702d19c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55702d1c7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9152661082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557026ac1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x37,0x2d,0x7a,0x5e,0x33,0x2d,0x7a, Step #5: 7-z^3-z Step #5: artifact_prefix='./'; Test unit written to ./oom-99ef9fe7960f8d3d110ec6cddf88e7b7e7da3bec Step #5: Base64: Ny16XjMteg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 972 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2217272278 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b41bd73810, 0x55b41bf5d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b41bf5d020,0x55b41ddf50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/99ef9fe7960f8d3d110ec6cddf88e7b7e7da3bec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1092 processed earlier; will process 9937 files now Step #5: #1 pulse cov: 3771 ft: 3772 exec/s: 0 rss: 161Mb Step #5: ==35026== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b4128689c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b418ecd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b418eb05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b418eb04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b41286ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b4127cfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b4127ca355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b412860c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b41582ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b41582ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b41582ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b41582ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b41582ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b41582ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b41582ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b41582ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b41582ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b41582ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b417ac4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b4147f1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b4147fcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b4145a8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b4145a8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b4145a9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b4145a8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b4145a8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b4145a8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b418eb2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b418ebb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b418ea3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b418ece112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f03dfb20082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b4127c8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x20,0x20,0x20,0x20,0x0,0x80,0x25, Step #5: \000\200% Step #5: artifact_prefix='./'; Test unit written to ./oom-ba9ede4177a5379383b39f38e7a05f496e57c253 Step #5: Base64: ICAgICAAgCU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 973 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2217747308 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558d30ccd810, 0x558d30eb701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558d30eb7020,0x558d32d4f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba9ede4177a5379383b39f38e7a05f496e57c253' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1094 processed earlier; will process 9935 files now Step #5: ==35062== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558d277c29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558d2de27898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558d2de0a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558d2de0a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558d277c8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558d27729b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558d27724355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558d277bac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558d2a789f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558d2a789f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558d2a789f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558d2a789f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558d2a789f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558d2a789f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558d2a789f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558d2a789f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558d2a789f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558d2a789f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558d2ca1ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558d2974bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558d29756be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558d29502c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558d29502c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558d29503738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558d29502874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558d29502874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558d29502874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558d2de0cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558d2de15928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558d2ddfd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558d2de28112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f06765a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558d27722b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x80,0xb2,0x0,0x6d,0x61,0x4d, Step #5: \363\240\200\262\000maM Step #5: artifact_prefix='./'; Test unit written to ./oom-f4c2433e9f7c998c4d8276345c5133fb09e8fefc Step #5: Base64: 86CAsgBtYU0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 974 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2218177138 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bea6abb810, 0x55bea6ca501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bea6ca5020,0x55bea8b3d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f4c2433e9f7c998c4d8276345c5133fb09e8fefc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1095 processed earlier; will process 9934 files now Step #5: ==35098== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55be9d5b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bea3c15898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bea3bf85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bea3bf84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55be9d5b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55be9d517b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55be9d512355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55be9d5a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bea0577f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bea0577f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bea0577f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bea0577f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bea0577f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bea0577f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bea0577f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bea0577f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bea0577f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bea0577f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bea280cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55be9f539b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55be9f544be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55be9f2f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55be9f2f0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55be9f2f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55be9f2f0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55be9f2f0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55be9f2f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bea3bfaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bea3c03928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bea3beb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bea3c16112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd1d6a7e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55be9d510b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c, Step #5: ,,,,,,,, Step #5: artifact_prefix='./'; Test unit written to ./oom-12fe190b16c245bd5c971e574352e43e4e703edc Step #5: Base64: LCwsLCwsLCw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 975 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2218611444 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561104ae3810, 0x561104ccd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561104ccd020,0x561106b650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/12fe190b16c245bd5c971e574352e43e4e703edc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1096 processed earlier; will process 9933 files now Step #5: ==35134== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5610fb5d89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561101c3d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561101c205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561101c204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610fb5ded42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610fb53fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610fb53a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610fb5d0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610fe59ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610fe59ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610fe59ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610fe59ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610fe59ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610fe59ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610fe59ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610fe59ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610fe59ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610fe59ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561100834f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610fd561b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610fd56cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610fd318c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610fd318c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610fd319738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610fd318874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610fd318874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610fd318874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561101c22abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561101c2b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561101c13699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561101c3e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ad56f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610fb538b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x62,0xd1,0x8b,0x4f, Step #5: DanMb\321\213O Step #5: artifact_prefix='./'; Test unit written to ./oom-16a4c261be65bfc25d8e594fe43bd33d5fd4d602 Step #5: Base64: RGFuTWLRi08= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 976 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2219047356 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b9c02b7810, 0x55b9c04a101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b9c04a1020,0x55b9c23390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16a4c261be65bfc25d8e594fe43bd33d5fd4d602' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1097 processed earlier; will process 9932 files now Step #5: ==35170== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b9b6dac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b9bd411898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b9bd3f45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b9bd3f44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b9b6db2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b9b6d13b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b9b6d0e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b9b6da4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b9b9d73f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b9b9d73f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b9b9d73f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b9b9d73f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b9b9d73f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b9b9d73f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b9b9d73f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b9b9d73f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b9b9d73f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b9b9d73f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b9bc008f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b9b8d35b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b9b8d40be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b9b8aecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b9b8aecc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b9b8aed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b9b8aec874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b9b8aec874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b9b8aec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b9bd3f6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b9bd3ff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b9bd3e7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b9bd412112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff6677b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b9b6d0cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x0,0xd,0x0,0x10,0x0,0x0,0x0, Step #5: \001\000\015\000\020\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-070134a7b9826ff728ae4e6404f17dbcc123a8a6 Step #5: Base64: AQANABAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 977 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2219485502 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1b21bd810, 0x55d1b23a701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1b23a7020,0x55d1b423f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/070134a7b9826ff728ae4e6404f17dbcc123a8a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1098 processed earlier; will process 9931 files now Step #5: ==35206== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d1a8cb29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1af317898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1af2fa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1af2fa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1a8cb8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1a8c19b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1a8c14355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1a8caac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1abc79f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1abc79f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1abc79f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1abc79f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1abc79f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1abc79f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1abc79f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1abc79f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1abc79f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1abc79f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1adf0ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1aac3bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1aac46be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1aa9f2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1aa9f2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1aa9f3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1aa9f2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1aa9f2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1aa9f2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1af2fcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1af305928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1af2ed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1af318112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f29403e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1a8c12b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x27,0x27,0x27,0x27,0x29,0x29,0x27, Step #5: '''''))' Step #5: artifact_prefix='./'; Test unit written to ./oom-40980687cffef59d14c7eee1005feb203dc17db5 Step #5: Base64: JycnJycpKSc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 978 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2219924464 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555cf726d810, 0x555cf745701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555cf7457020,0x555cf92ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40980687cffef59d14c7eee1005feb203dc17db5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1099 processed earlier; will process 9930 files now Step #5: ==35242== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555cedd629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555cf43c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555cf43aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555cf43aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555cedd68d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555cedcc9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555cedcc4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555cedd5ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555cf0d29f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555cf0d29f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555cf0d29f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555cf0d29f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555cf0d29f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555cf0d29f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555cf0d29f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555cf0d29f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555cf0d29f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555cf0d29f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555cf2fbef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555cefcebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555cefcf6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555cefaa2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555cefaa2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555cefaa3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555cefaa2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555cefaa2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555cefaa2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555cf43acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555cf43b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555cf439d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555cf43c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f460f3c8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555cedcc2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x40,0x9,0x50,0x40, Step #5: DanM@\011P@ Step #5: artifact_prefix='./'; Test unit written to ./oom-9e5ce54c4dfe9a3eabe4b900773691598d7ca1e4 Step #5: Base64: RGFuTUAJUEA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 979 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2220358046 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56017f63d810, 0x56017f82701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56017f827020,0x5601816bf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9e5ce54c4dfe9a3eabe4b900773691598d7ca1e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1100 processed earlier; will process 9929 files now Step #5: #1 pulse cov: 3673 ft: 3674 exec/s: 0 rss: 162Mb Step #5: ==35278== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5601761329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56017c797898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56017c77a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56017c77a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560176138d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560176099b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560176094355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56017612ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601790f9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601790f9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601790f9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601790f9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601790f9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601790f9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601790f9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601790f9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601790f9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601790f9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56017b38ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601780bbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601780c6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560177e72c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560177e72c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560177e73738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560177e72874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560177e72874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560177e72874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56017c77cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56017c785928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56017c76d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56017c798112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f72a34c4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560176092b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x24,0x24,0x33,0x55, Step #5: DanM$$3U Step #5: artifact_prefix='./'; Test unit written to ./oom-b7b03a01aa0a080af5fbcbfb5488ee13d66d6574 Step #5: Base64: RGFuTSQkM1U= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 980 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2220833393 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fbeb576810, 0x55fbeb76001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fbeb760020,0x55fbed5f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7b03a01aa0a080af5fbcbfb5488ee13d66d6574' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1102 processed earlier; will process 9927 files now Step #5: ==35314== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fbe206b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fbe86d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fbe86b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fbe86b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fbe2071d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fbe1fd2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fbe1fcd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fbe2063c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fbe5032f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fbe5032f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fbe5032f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fbe5032f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fbe5032f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fbe5032f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fbe5032f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fbe5032f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fbe5032f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fbe5032f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fbe72c7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fbe3ff4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fbe3fffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fbe3dabc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fbe3dabc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fbe3dac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fbe3dab874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fbe3dab874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fbe3dab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fbe86b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fbe86be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fbe86a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fbe86d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f73e204c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fbe1fcbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x66,0xa,0xa,0xa,0x38,0x45,0x2b, Step #5: Pf\012\012\0128E+ Step #5: artifact_prefix='./'; Test unit written to ./oom-b3f16c4d30cfc9f4c271e5d7970e763157ae29c1 Step #5: Base64: UGYKCgo4RSs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 981 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2221272598 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55875c7a5810, 0x55875c98f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55875c98f020,0x55875e8270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3f16c4d30cfc9f4c271e5d7970e763157ae29c1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1103 processed earlier; will process 9926 files now Step #5: ==35350== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55875329a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5587598ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5587598e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5587598e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5587532a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558753201b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5587531fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558753292c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558756261f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558756261f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558756261f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558756261f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558756261f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558756261f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558756261f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558756261f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558756261f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558756261f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5587584f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558755223b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55875522ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558754fdac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558754fdac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558754fdb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558754fda874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558754fda874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558754fda874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5587598e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5587598ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5587598d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558759900112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f71980a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5587531fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x5c,0x75,0x7b,0x66,0x37,0x66,0x7d, Step #5: \"\\u{f7f} Step #5: artifact_prefix='./'; Test unit written to ./oom-46bb9995c8863a164b9dd7633172314f6e95fcdb Step #5: Base64: Ilx1e2Y3Zn0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 982 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2221713017 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5638aef25810, 0x5638af10f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5638af10f020,0x5638b0fa70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/46bb9995c8863a164b9dd7633172314f6e95fcdb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1104 processed earlier; will process 9925 files now Step #5: ==35386== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5638a5a1a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5638ac07f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5638ac0625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5638ac0624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5638a5a20d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5638a5981b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5638a597c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5638a5a12c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5638a89e1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5638a89e1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5638a89e1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5638a89e1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5638a89e1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5638a89e1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5638a89e1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5638a89e1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5638a89e1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5638a89e1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5638aac76f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5638a79a3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5638a79aebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5638a775ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5638a775ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5638a775b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5638a775a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5638a775a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5638a775a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5638ac064abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5638ac06d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5638ac055699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5638ac080112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc360771082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5638a597ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0x7a,0x61,0x0,0x68,0x6d,0x74,0x78, Step #5: iza\000hmtx Step #5: artifact_prefix='./'; Test unit written to ./oom-f0150c9657b72420a56c2893e8a059ea6159d63b Step #5: Base64: aXphAGhtdHg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 983 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2222152054 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5631a0577810, 0x5631a076101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5631a0761020,0x5631a25f90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f0150c9657b72420a56c2893e8a059ea6159d63b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1105 processed earlier; will process 9924 files now Step #5: ==35422== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56319706c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56319d6d1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56319d6b45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56319d6b44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563197072d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563196fd3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563196fce355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563197064c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56319a033f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56319a033f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56319a033f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56319a033f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56319a033f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56319a033f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56319a033f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56319a033f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56319a033f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56319a033f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56319c2c8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563198ff5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563199000be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563198dacc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563198dacc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563198dad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563198dac874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563198dac874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563198dac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56319d6b6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56319d6bf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56319d6a7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56319d6d2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe049ead082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563196fccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xa,0xa,0x60,0xa,0x60,0xa,0x60, Step #5: `\012\012`\012`\012` Step #5: artifact_prefix='./'; Test unit written to ./oom-3d147c11dfae6d5d2fa076035fb9bbf912f43187 Step #5: Base64: YAoKYApgCmA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 984 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2222708972 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55badd755810, 0x55badd93f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55badd93f020,0x55badf7d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3d147c11dfae6d5d2fa076035fb9bbf912f43187' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1106 processed earlier; will process 9923 files now Step #5: ==35458== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bad424a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bada8af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bada8925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bada8924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bad4250d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bad41b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bad41ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bad4242c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bad7211f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bad7211f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bad7211f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bad7211f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bad7211f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bad7211f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bad7211f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bad7211f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bad7211f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bad7211f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bad94a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bad61d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bad61debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bad5f8ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bad5f8ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bad5f8b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bad5f8a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bad5f8a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bad5f8a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bada894abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bada89d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bada885699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bada8b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f686d848082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bad41aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x74,0x70,0x1a,0x2f,0x2a,0x2f,0x7f, Step #5: ttp\032/*/\177 Step #5: artifact_prefix='./'; Test unit written to ./oom-7f1683856865c0538df8a69507009c25f7bc1381 Step #5: Base64: dHRwGi8qL38= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 985 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2223145836 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560678a83810, 0x560678c6d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560678c6d020,0x56067ab050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f1683856865c0538df8a69507009c25f7bc1381' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1107 processed earlier; will process 9922 files now Step #5: ==35494== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56066f5789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560675bdd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560675bc05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560675bc04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56066f57ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56066f4dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56066f4da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56066f570c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56067253ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56067253ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56067253ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56067253ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56067253ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56067253ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56067253ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56067253ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56067253ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56067253ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606747d4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560671501b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56067150cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5606712b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5606712b8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5606712b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5606712b8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5606712b8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5606712b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560675bc2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560675bcb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560675bb3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560675bde112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff736ce7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56066f4d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xbe,0x9c,0xd,0x69,0x6e,0xd,0xf3, Step #5: \341\276\234\015in\015\363 Step #5: artifact_prefix='./'; Test unit written to ./oom-c69e7ad5f788965f5f5fecfa5dc39abd8600b8bf Step #5: Base64: 4b6cDWluDfM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 986 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2223582004 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c61265d810, 0x55c61284701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c612847020,0x55c6146df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c69e7ad5f788965f5f5fecfa5dc39abd8600b8bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1108 processed earlier; will process 9921 files now Step #5: #1 pulse cov: 3655 ft: 3656 exec/s: 0 rss: 162Mb Step #5: ==35530== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c6091529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c60f7b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c60f79a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c60f79a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c609158d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6090b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6090b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c60914ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c60c119f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c60c119f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c60c119f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c60c119f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c60c119f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c60c119f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c60c119f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c60c119f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c60c119f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c60c119f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c60e3aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c60b0dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c60b0e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c60ae92c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c60ae92c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c60ae93738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c60ae92874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c60ae92874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c60ae92874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c60f79cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c60f7a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c60f78d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c60f7b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fad6c106082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6090b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33,0x32,0x30,0x36,0x30,0x36,0x36,0x31, Step #5: 32060661 Step #5: artifact_prefix='./'; Test unit written to ./oom-107f2a487b517203fd0e6c701e8946bd4e29497e Step #5: Base64: MzIwNjA2NjE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 987 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2224060709 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f8d2f50810, 0x55f8d313a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f8d313a020,0x55f8d4fd20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/107f2a487b517203fd0e6c701e8946bd4e29497e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1110 processed earlier; will process 9919 files now Step #5: ==35566== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f8c9a459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f8d00aa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8d008d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8d008d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8c9a4bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8c99acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8c99a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8c9a3dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8cca0cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8cca0cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8cca0cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8cca0cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8cca0cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8cca0cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8cca0cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8cca0cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8cca0cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8cca0cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f8ceca1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f8cb9ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f8cb9d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8cb785c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8cb785c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8cb786738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8cb785874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8cb785874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8cb785874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f8d008fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f8d0098928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f8d0080699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f8d00ab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f30e013d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8c99a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa, Step #5: \012\012\012\012\012\012\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-f080446304324098b74b9addc0a16960d33e1b84 Step #5: Base64: CgoKCgoKCgo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 988 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2224484456 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5633600dd810, 0x5633602c701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5633602c7020,0x56336215f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f080446304324098b74b9addc0a16960d33e1b84' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1111 processed earlier; will process 9918 files now Step #5: ==35602== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563356bd29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56335d237898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56335d21a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56335d21a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563356bd8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563356b39b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563356b34355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563356bcac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563359b99f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563359b99f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563359b99f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563359b99f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563359b99f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563359b99f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563359b99f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563359b99f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563359b99f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563359b99f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56335be2ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563358b5bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563358b66be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563358912c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563358912c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563358913738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563358912874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563358912874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563358912874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56335d21cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56335d225928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56335d20d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56335d238112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a4d903082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563356b32b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0x52,0x4d,0x42,0x5f,0x4d,0x42,0x5f, Step #5: _RMB_MB_ Step #5: artifact_prefix='./'; Test unit written to ./oom-364f80548cc797c0250469a9ed14b81ce6961943 Step #5: Base64: X1JNQl9NQl8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 989 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2224917837 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d5aeef810, 0x562d5b0d901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d5b0d9020,0x562d5cf710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/364f80548cc797c0250469a9ed14b81ce6961943' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1112 processed earlier; will process 9917 files now Step #5: ==35638== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562d519e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d58049898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d5802c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d5802c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d519ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d5194bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d51946355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d519dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d549abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d549abf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d549abf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d549abf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d549abf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d549abf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d549abf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d549abf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d549abf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d549abf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d56c40f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d5396db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d53978be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d53724c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d53724c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d53725738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d53724874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d53724874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d53724874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d5802eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d58037928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d5801f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d5804a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd5d0872082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d51944b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x7c,0x7c,0x25,0x7c,0x7c,0x25,0x7c, Step #5: %||%||%| Step #5: artifact_prefix='./'; Test unit written to ./oom-995823bffd3012f082dcb328acb277e05e905c95 Step #5: Base64: JXx8JXx8JXw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 990 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2225353640 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c9dbb38810, 0x55c9dbd2201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c9dbd22020,0x55c9ddbba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/995823bffd3012f082dcb328acb277e05e905c95' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1113 processed earlier; will process 9916 files now Step #5: ==35674== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c9d262d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c9d8c92898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9d8c755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9d8c754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9d2633d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9d2594b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c9d258f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9d2625c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c9d55f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c9d55f4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c9d55f4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c9d55f4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c9d55f4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c9d55f4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c9d55f4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c9d55f4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c9d55f4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c9d55f4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c9d7889f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9d45b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9d45c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c9d436dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c9d436dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c9d436e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c9d436d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c9d436d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c9d436d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c9d8c77abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c9d8c80928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c9d8c68699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c9d8c93112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5198d68082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c9d258db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x2c,0x30,0xa,0x2d,0x31,0x2c,0x33, Step #5: 0,0\012-1,3 Step #5: artifact_prefix='./'; Test unit written to ./oom-401f037b382f529ec108b70d844b22ee9bc6c74b Step #5: Base64: MCwwCi0xLDM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 991 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2225790218 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5628768ea810, 0x562876ad401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562876ad4020,0x56287896c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/401f037b382f529ec108b70d844b22ee9bc6c74b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1114 processed earlier; will process 9915 files now Step #5: ==35710== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56286d3df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562873a44898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562873a275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562873a274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56286d3e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56286d346b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56286d341355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56286d3d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5628703a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5628703a6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5628703a6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5628703a6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5628703a6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5628703a6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5628703a6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5628703a6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5628703a6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5628703a6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56287263bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56286f368b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56286f373be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56286f11fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56286f11fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56286f120738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56286f11f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56286f11f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56286f11f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562873a29abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562873a32928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562873a1a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562873a45112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf4831e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56286d33fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0xf0,0x9a,0xa1,0xa5, Step #5: (?i)\360\232\241\245 Step #5: artifact_prefix='./'; Test unit written to ./oom-ca6545145cdabc59ed985918f5dddbdf074a5fdf Step #5: Base64: KD9pKfCaoaU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 992 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2226230249 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b80ac84810, 0x55b80ae6e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b80ae6e020,0x55b80cd060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca6545145cdabc59ed985918f5dddbdf074a5fdf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1115 processed earlier; will process 9914 files now Step #5: #1 pulse cov: 3510 ft: 3511 exec/s: 0 rss: 164Mb Step #5: ==35746== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b8017799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b807dde898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b807dc15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b807dc14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b80177fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b8016e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b8016db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b801771c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b804740f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b804740f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b804740f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b804740f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b804740f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b804740f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b804740f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b804740f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b804740f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b804740f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b8069d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b803702b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b80370dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b8034b9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b8034b9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b8034ba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b8034b9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b8034b9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b8034b9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b807dc3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b807dcc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b807db4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b807ddf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0358fea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b8016d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x57,0x73,0x3a,0xe3,0x8d,0xbf,0xcd,0x84, Step #5: Ws:\343\215\277\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-2e08e3700619c4ee233aca2af4bd68cb60a9258e Step #5: Base64: V3M6442/zYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 993 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2226705055 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5635f22bb810, 0x5635f24a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5635f24a5020,0x5635f433d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2e08e3700619c4ee233aca2af4bd68cb60a9258e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1117 processed earlier; will process 9912 files now Step #5: ==35782== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5635e8db09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5635ef415898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5635ef3f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5635ef3f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5635e8db6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5635e8d17b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5635e8d12355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5635e8da8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5635ebd77f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5635ebd77f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5635ebd77f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5635ebd77f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5635ebd77f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5635ebd77f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5635ebd77f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5635ebd77f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5635ebd77f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5635ebd77f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5635ee00cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5635ead39b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5635ead44be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5635eaaf0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5635eaaf0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5635eaaf1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5635eaaf0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5635eaaf0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5635eaaf0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5635ef3faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5635ef403928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5635ef3eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5635ef416112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8e73698082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5635e8d10b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd8,0xad,0xd8,0x98,0x3f,0xff,0x8,0x30, Step #5: \330\255\330\230?\377\0100 Step #5: artifact_prefix='./'; Test unit written to ./oom-be929faeba7b756ad666c25208fbb716cac5b0ab Step #5: Base64: 2K3YmD//CDA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 994 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2227141547 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564fbb7e2810, 0x564fbb9cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564fbb9cc020,0x564fbd8640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/be929faeba7b756ad666c25208fbb716cac5b0ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1118 processed earlier; will process 9911 files now Step #5: ==35818== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564fb22d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564fb893c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564fb891f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564fb891f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564fb22ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564fb223eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564fb2239355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564fb22cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564fb529ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564fb529ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564fb529ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564fb529ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564fb529ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564fb529ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564fb529ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564fb529ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564fb529ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564fb529ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564fb7533f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564fb4260b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564fb426bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564fb4017c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564fb4017c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564fb4018738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564fb4017874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564fb4017874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564fb4017874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564fb8921abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564fb892a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564fb8912699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564fb893d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc7d1505082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564fb2237b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2d,0x2d,0x3d,0x2d,0x9,0x0,0x2, Step #5: \000--=-\011\000\002 Step #5: artifact_prefix='./'; Test unit written to ./oom-00d431ec18a7dfad265f174466472accd2c3e954 Step #5: Base64: AC0tPS0JAAI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 995 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2227579971 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565261717810, 0x56526190101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565261901020,0x5652637990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/00d431ec18a7dfad265f174466472accd2c3e954' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1119 processed earlier; will process 9910 files now Step #5: ==35854== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56525820c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56525e871898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56525e8545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56525e8544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565258212d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565258173b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56525816e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565258204c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56525b1d3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56525b1d3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56525b1d3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56525b1d3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56525b1d3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56525b1d3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56525b1d3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56525b1d3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56525b1d3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56525b1d3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56525d468f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56525a195b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56525a1a0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565259f4cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565259f4cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565259f4d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565259f4c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565259f4c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565259f4c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56525e856abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56525e85f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56525e847699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56525e872112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8715851082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56525816cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x61,0xc4,0xb2,0x35,0x0,0x44,0x92,0x35, Step #5: a\304\2625\000D\2225 Step #5: artifact_prefix='./'; Test unit written to ./oom-a3ef4cc889b5cded3aae108377a987c483fe2654 Step #5: Base64: YcSyNQBEkjU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 996 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2228017187 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561f11e48810, 0x561f1203201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561f12032020,0x561f13eca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a3ef4cc889b5cded3aae108377a987c483fe2654' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1120 processed earlier; will process 9909 files now Step #5: ==35890== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561f0893d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561f0efa2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561f0ef855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561f0ef854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561f08943d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561f088a4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561f0889f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561f08935c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561f0b904f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561f0b904f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561f0b904f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561f0b904f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561f0b904f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561f0b904f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561f0b904f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561f0b904f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561f0b904f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561f0b904f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561f0db99f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561f0a8c6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561f0a8d1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561f0a67dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561f0a67dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561f0a67e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561f0a67d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561f0a67d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561f0a67d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561f0ef87abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561f0ef90928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561f0ef78699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561f0efa3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f76f8142082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561f0889db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x23,0x22,0x6d,0x45,0x5c,0x4e,0x22, Step #5: [#\"mE\\N\" Step #5: artifact_prefix='./'; Test unit written to ./oom-f2b32b7f87f2b13e70dda885bccde73b2a4182ab Step #5: Base64: WyMibUVcTiI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 997 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2228454348 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559db3f3d810, 0x559db412701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559db4127020,0x559db5fbf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f2b32b7f87f2b13e70dda885bccde73b2a4182ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1121 processed earlier; will process 9908 files now Step #5: #1 pulse cov: 6444 ft: 6445 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 6739 ft: 7099 exec/s: 0 rss: 175Mb Step #5: ==35926== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559daaa329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559db1097898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559db107a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559db107a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559daaa38d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559daa999b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559daa994355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559daaa2ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559dad9f9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559dad9f9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559dad9f9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559dad9f9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559dad9f9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559dad9f9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559dad9f9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559dad9f9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559dad9f9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559dad9f9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559dafc8ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559dac9bbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559dac9c6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559dac772c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559dac772c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559dac773738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559dac772874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559dac772874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559dac772874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559db107cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559db1085928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559db106d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559db1098112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f70fe8d8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559daa992b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x5e,0x49,0xc4,0x35, Step #5: DanM^I\3045 Step #5: artifact_prefix='./'; Test unit written to ./oom-78a5427573c6ec3b6f57688d9582bc09e08cb018 Step #5: Base64: RGFuTV5JxDU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 998 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2228978816 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f5ad618810, 0x55f5ad80201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f5ad802020,0x55f5af69a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/78a5427573c6ec3b6f57688d9582bc09e08cb018' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1124 processed earlier; will process 9905 files now Step #5: #1 pulse cov: 3487 ft: 3488 exec/s: 0 rss: 164Mb Step #5: ==35962== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f5a410d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f5aa772898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f5aa7555dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f5aa7554fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f5a4113d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f5a4074b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f5a406f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f5a4105c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f5a70d4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f5a70d4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f5a70d4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f5a70d4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f5a70d4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f5a70d4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f5a70d4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f5a70d4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f5a70d4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f5a70d4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f5a9369f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f5a6096b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f5a60a1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f5a5e4dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f5a5e4dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f5a5e4e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f5a5e4d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f5a5e4d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f5a5e4d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f5aa757abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f5aa760928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f5aa748699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f5aa773112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac8898e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f5a406db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0xad,0x2d,0x2c,0xdf,0xad,0x2d,0x40, Step #5: \337\255-,\337\255-@ Step #5: artifact_prefix='./'; Test unit written to ./oom-9facdefbe23eda9ba73f43dea209c756f1e7f9dc Step #5: Base64: 360tLN+tLUA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 999 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2229452496 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5593a34bd810, 0x5593a36a701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5593a36a7020,0x5593a553f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9facdefbe23eda9ba73f43dea209c756f1e7f9dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1126 processed earlier; will process 9903 files now Step #5: ==35998== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559399fb29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5593a0617898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5593a05fa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5593a05fa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559399fb8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559399f19b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559399f14355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559399faac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55939cf79f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55939cf79f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55939cf79f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55939cf79f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55939cf79f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55939cf79f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55939cf79f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55939cf79f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55939cf79f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55939cf79f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55939f20ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55939bf3bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55939bf46be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55939bcf2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55939bcf2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55939bcf3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55939bcf2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55939bcf2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55939bcf2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5593a05fcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5593a0605928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5593a05ed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5593a0618112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c869eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559399f12b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x5c,0x75,0x7b,0x46,0x7d,0x5c,0x75, Step #5: \"\\u{F}\\u Step #5: artifact_prefix='./'; Test unit written to ./oom-643b48f1edab5bfd5be5d0c0d45d69a8e51a0b28 Step #5: Base64: Ilx1e0Z9XHU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1000 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2229887105 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5583a7655810, 0x5583a783f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5583a783f020,0x5583a96d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/643b48f1edab5bfd5be5d0c0d45d69a8e51a0b28' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1127 processed earlier; will process 9902 files now Step #5: ==36034== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55839e14a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5583a47af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583a47925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583a47924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55839e150d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55839e0b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55839e0ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55839e142c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5583a1111f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5583a1111f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5583a1111f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5583a1111f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5583a1111f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5583a1111f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5583a1111f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5583a1111f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5583a1111f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5583a1111f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5583a33a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5583a00d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5583a00debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55839fe8ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55839fe8ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55839fe8b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55839fe8a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55839fe8a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55839fe8a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5583a4794abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5583a479d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5583a4785699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5583a47b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f86c296d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55839e0aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x84,0xcc,0x90,0xf0,0x9d,0x85,0xad, Step #5: \315\204\314\220\360\235\205\255 Step #5: artifact_prefix='./'; Test unit written to ./oom-2d7dc02ffc3988e274d415760042ba530ed3b1c1 Step #5: Base64: zYTMkPCdha0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1001 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2230316912 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a6f4162810, 0x55a6f434c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a6f434c020,0x55a6f61e40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2d7dc02ffc3988e274d415760042ba530ed3b1c1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1128 processed earlier; will process 9901 files now Step #5: ==36070== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a6eac579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a6f12bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a6f129f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a6f129f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a6eac5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a6eabbeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a6eabb9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a6eac4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a6edc1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a6edc1ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a6edc1ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a6edc1ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a6edc1ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a6edc1ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a6edc1ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a6edc1ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a6edc1ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a6edc1ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a6efeb3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a6ecbe0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a6ecbebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a6ec997c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a6ec997c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a6ec998738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a6ec997874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a6ec997874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a6ec997874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a6f12a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a6f12aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a6f1292699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a6f12bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1848fe1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a6eabb7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x61,0x73,0x2a,0x6d,0x1,0xfd,0xd7, Step #5: \000as*m\001\375\327 Step #5: artifact_prefix='./'; Test unit written to ./oom-1743da04d23e57e8cfe95ece0a9e0336b2840be1 Step #5: Base64: AGFzKm0B/dc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1002 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2230745093 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561099e41810, 0x56109a02b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56109a02b020,0x56109bec30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1743da04d23e57e8cfe95ece0a9e0336b2840be1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1129 processed earlier; will process 9900 files now Step #5: ==36106== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5610909369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561096f9b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561096f7e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561096f7e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56109093cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56109089db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561090898355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56109092ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610938fdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610938fdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610938fdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610938fdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610938fdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610938fdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610938fdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610938fdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610938fdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610938fdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561095b92f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610928bfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610928cabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561092676c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561092676c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561092677738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561092676874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561092676874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561092676874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561096f80abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561096f89928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561096f71699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561096f9c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f594d76b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561090896b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4,0x65,0x22,0xf3,0xb5,0x9f,0x8f,0x22, Step #5: \004e\"\363\265\237\217\" Step #5: artifact_prefix='./'; Test unit written to ./oom-9b9ddfc3b689e3ac0dd2a59dea8367d9b694d707 Step #5: Base64: BGUi87WfjyI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1003 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2231180644 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56205ef75810, 0x56205f15f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56205f15f020,0x562060ff70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9b9ddfc3b689e3ac0dd2a59dea8367d9b694d707' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1130 processed earlier; will process 9899 files now Step #5: ==36142== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562055a6a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56205c0cf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56205c0b25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56205c0b24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562055a70d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5620559d1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5620559cc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562055a62c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562058a31f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562058a31f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562058a31f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562058a31f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562058a31f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562058a31f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562058a31f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562058a31f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562058a31f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562058a31f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56205acc6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5620579f3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5620579febe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5620577aac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5620577aac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5620577ab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5620577aa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5620577aa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5620577aa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56205c0b4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56205c0bd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56205c0a5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56205c0d0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f20d9006082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5620559cab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x58,0x3a,0x2f,0x0,0xcd,0x95,0xcd,0x95, Step #5: X:/\000\315\225\315\225 Step #5: artifact_prefix='./'; Test unit written to ./oom-25ef9d86a647f7565d18b29068dbc3c572b473fc Step #5: Base64: WDovAM2VzZU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1004 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2231613307 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562a13154810, 0x562a1333e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562a1333e020,0x562a151d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/25ef9d86a647f7565d18b29068dbc3c572b473fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1131 processed earlier; will process 9898 files now Step #5: ==36178== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562a09c499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562a102ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562a102915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562a102914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562a09c4fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562a09bb0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562a09bab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562a09c41c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562a0cc10f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562a0cc10f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562a0cc10f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562a0cc10f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562a0cc10f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562a0cc10f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562a0cc10f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562a0cc10f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562a0cc10f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562a0cc10f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562a0eea5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562a0bbd2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562a0bbddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562a0b989c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562a0b989c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562a0b98a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562a0b989874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562a0b989874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562a0b989874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562a10293abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562a1029c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562a10284699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562a102af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f01f6736082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562a09ba9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c,0x6f,0x6e,0x6d,0x9,0x0,0x0,0x0, Step #5: lonm\011\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4d4a713f2058c346b3122af985165f77bcf56b32 Step #5: Base64: bG9ubQkAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1005 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2232047032 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55634980e810, 0x5563499f801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5563499f8020,0x55634b8900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4d4a713f2058c346b3122af985165f77bcf56b32' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1132 processed earlier; will process 9897 files now Step #5: ==36214== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5563403039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556346968898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55634694b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55634694b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556340309d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55634026ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556340265355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5563402fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5563432caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5563432caf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5563432caf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5563432caf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5563432caf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5563432caf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5563432caf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5563432caf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5563432caf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5563432caf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55634555ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55634228cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556342297be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556342043c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556342043c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556342044738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556342043874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556342043874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556342043874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55634694dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556346956928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55634693e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556346969112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ae3294082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556340263b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xef,0xb8,0x8a,0xef,0xb8,0x8a,0x22, Step #5: \"\357\270\212\357\270\212\" Step #5: artifact_prefix='./'; Test unit written to ./oom-129690775a6a339af9e7ce5aa44c47a0754d5162 Step #5: Base64: Iu+4iu+4iiI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1006 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2232474138 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555aa7922810, 0x555aa7b0c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555aa7b0c020,0x555aa99a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/129690775a6a339af9e7ce5aa44c47a0754d5162' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1133 processed earlier; will process 9896 files now Step #5: #1 pulse cov: 3662 ft: 3663 exec/s: 0 rss: 161Mb Step #5: #2 pulse cov: 7014 ft: 7413 exec/s: 0 rss: 176Mb Step #5: ==36250== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555a9e4179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555aa4a7c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555aa4a5f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555aa4a5f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a9e41dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a9e37eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a9e379355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a9e40fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555aa13def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555aa13def10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555aa13def10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555aa13def10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555aa13def10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555aa13def10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555aa13def10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555aa13def10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555aa13def10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555aa13def10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555aa3673f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555aa03a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555aa03abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555aa0157c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555aa0157c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555aa0158738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555aa0157874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555aa0157874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555aa0157874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555aa4a61abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555aa4a6a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555aa4a52699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555aa4a7d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f60430d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a9e377b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x60,0x44,0x60,0xf3,0x4d,0xa2,0x4d, Step #5: D`D`\363M\242M Step #5: artifact_prefix='./'; Test unit written to ./oom-9c03df3320069eda85de88f640306bdbf7f22ada Step #5: Base64: RGBEYPNNok0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1007 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2233106155 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d7216a1810, 0x55d72188b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d72188b020,0x55d7237230e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c03df3320069eda85de88f640306bdbf7f22ada' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1136 processed earlier; will process 9893 files now Step #5: ==36286== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d7181969c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d71e7fb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d71e7de5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d71e7de4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d71819cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d7180fdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d7180f8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d71818ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d71b15df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d71b15df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d71b15df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d71b15df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d71b15df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d71b15df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d71b15df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d71b15df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d71b15df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d71b15df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d71d3f2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d71a11fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d71a12abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d719ed6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d719ed6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d719ed7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d719ed6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d719ed6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d719ed6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d71e7e0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d71e7e9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d71e7d1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d71e7fc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f47e7e7c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d7180f6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0x5f,0x2f,0x52,0x42,0x5f,0x2f,0x52, Step #5: C_/RB_/R Step #5: artifact_prefix='./'; Test unit written to ./oom-3eaed025165636b86ffea4710ffd9e81d5a42860 Step #5: Base64: Q18vUkJfL1I= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1008 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2233539672 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56360529a810, 0x56360548401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563605484020,0x56360731c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3eaed025165636b86ffea4710ffd9e81d5a42860' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1137 processed earlier; will process 9892 files now Step #5: #1 pulse cov: 3635 ft: 3636 exec/s: 0 rss: 161Mb Step #5: ==36322== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5635fbd8f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5636023f4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636023d75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636023d74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5635fbd95d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5635fbcf6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5635fbcf1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5635fbd87c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5635fed56f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5635fed56f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5635fed56f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5635fed56f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5635fed56f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5635fed56f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5635fed56f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5635fed56f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5635fed56f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5635fed56f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563600febf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5635fdd18b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5635fdd23be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5635fdacfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5635fdacfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5635fdad0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5635fdacf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5635fdacf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5635fdacf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5636023d9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5636023e2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5636023ca699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5636023f5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc82a66082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5635fbcefb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0x23,0x38,0x31,0x38,0x32,0x3b,0xfa, Step #5: ῶ\372 Step #5: artifact_prefix='./'; Test unit written to ./oom-631763bd6738c4aa1f5a477916c73b5a4113d0f1 Step #5: Base64: JiM4MTgyO/o= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1009 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2234012003 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f577ee0810, 0x55f5780ca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f5780ca020,0x55f579f620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/631763bd6738c4aa1f5a477916c73b5a4113d0f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1139 processed earlier; will process 9890 files now Step #5: ==36358== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f56e9d59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f57503a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f57501d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f57501d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f56e9dbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f56e93cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f56e937355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f56e9cdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f57199cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f57199cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f57199cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f57199cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f57199cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f57199cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f57199cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f57199cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f57199cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f57199cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f573c31f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f57095eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f570969be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f570715c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f570715c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f570716738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f570715874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f570715874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f570715874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f57501fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f575028928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f575010699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f57503b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f45d297f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f56e935b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0x5b,0xe1,0x9a,0xbc, Step #5: (?i)[\341\232\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-78f41703baf3aa5cf2dea5820d3e354eba4b7188 Step #5: Base64: KD9pKVvhmrw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1010 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2234447512 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559b49dbc810, 0x559b49fa601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559b49fa6020,0x559b4be3e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/78f41703baf3aa5cf2dea5820d3e354eba4b7188' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1140 processed earlier; will process 9889 files now Step #5: ==36394== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559b408b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559b46f16898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559b46ef95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559b46ef94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b408b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b40818b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b40813355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b408a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b43878f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b43878f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b43878f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b43878f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b43878f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b43878f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b43878f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b43878f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b43878f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b43878f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559b45b0df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b4283ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b42845be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b425f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b425f1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b425f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b425f1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b425f1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b425f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559b46efbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559b46f04928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559b46eec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559b46f17112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faec3345082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b40811b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x9,0x3f,0x2a,0x2a,0x27,0xff,0x0, Step #5: =\011?**'\377\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6c59fbac4e689b8f0c2c3a7d138984c5373036bb Step #5: Base64: PQk/Kion/wA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1011 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2234886720 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561e586e8810, 0x561e588d201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561e588d2020,0x561e5a76a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6c59fbac4e689b8f0c2c3a7d138984c5373036bb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1141 processed earlier; will process 9888 files now Step #5: ==36430== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561e4f1dd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561e55842898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561e558255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561e558254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561e4f1e3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561e4f144b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561e4f13f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561e4f1d5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561e521a4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561e521a4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561e521a4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561e521a4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561e521a4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561e521a4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561e521a4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561e521a4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561e521a4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561e521a4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561e54439f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561e51166b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561e51171be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561e50f1dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561e50f1dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561e50f1e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561e50f1d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561e50f1d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561e50f1d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561e55827abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561e55830928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561e55818699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561e55843112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb39f07c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561e4f13db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x0,0x20,0x0,0x20,0x0,0x20,0x0, Step #5: \000 \000 \000 \000 Step #5: artifact_prefix='./'; Test unit written to ./oom-28be9a569dccaecc3746aa7945f873f6cd56f68e Step #5: Base64: IAAgACAAIAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1012 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2235327188 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c16062a810, 0x55c16081401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c160814020,0x55c1626ac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/28be9a569dccaecc3746aa7945f873f6cd56f68e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1142 processed earlier; will process 9887 files now Step #5: ==36466== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c15711f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c15d784898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c15d7675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c15d7674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c157125d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c157086b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c157081355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c157117c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c15a0e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c15a0e6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c15a0e6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c15a0e6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c15a0e6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c15a0e6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c15a0e6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c15a0e6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c15a0e6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c15a0e6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c15c37bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c1590a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c1590b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c158e5fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c158e5fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c158e60738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c158e5f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c158e5f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c158e5f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c15d769abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c15d772928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c15d75a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c15d785112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6d36a8f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c15707fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0xa,0x3d,0xa,0x4f, Step #5: DanM\012=\012O Step #5: artifact_prefix='./'; Test unit written to ./oom-01dc65f55424d54fa4caab236fc5055b65578466 Step #5: Base64: RGFuTQo9Ck8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1013 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2235761648 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564ecf431810, 0x564ecf61b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564ecf61b020,0x564ed14b30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01dc65f55424d54fa4caab236fc5055b65578466' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1143 processed earlier; will process 9886 files now Step #5: ==36502== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564ec5f269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564ecc58b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564ecc56e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564ecc56e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ec5f2cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ec5e8db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ec5e88355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ec5f1ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564ec8eedf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564ec8eedf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564ec8eedf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564ec8eedf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564ec8eedf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564ec8eedf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564ec8eedf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564ec8eedf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564ec8eedf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564ec8eedf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564ecb182f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564ec7eafb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564ec7ebabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564ec7c66c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564ec7c66c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564ec7c67738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564ec7c66874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564ec7c66874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564ec7c66874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564ecc570abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564ecc579928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564ecc561699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564ecc58c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1ebdcbe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ec5e86b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x53,0x0,0x0,0x0,0x0,0xda,0xb4, Step #5: /S\000\000\000\000\332\264 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf0e131b80536467a003699064106c73080ea1ca Step #5: Base64: L1MAAAAA2rQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1014 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2236205237 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c7d5843810, 0x55c7d5a2d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c7d5a2d020,0x55c7d78c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf0e131b80536467a003699064106c73080ea1ca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1144 processed earlier; will process 9885 files now Step #5: ==36538== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c7cc3389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7d299d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7d29805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7d29804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c7cc33ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c7cc29fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c7cc29a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7cc330c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7cf2fff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7cf2fff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7cf2fff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7cf2fff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7cf2fff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7cf2fff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7cf2fff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7cf2fff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7cf2fff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7cf2fff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7d1594f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7ce2c1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7ce2ccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7ce078c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7ce078c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7ce079738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7ce078874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7ce078874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7ce078874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7d2982abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7d298b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c7d2973699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7d299e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fab50adc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c7cc298b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x5c,0x72,0x5c,0x7b,0x5c,0x32,0x2f, Step #5: /\\r\\{\\2/ Step #5: artifact_prefix='./'; Test unit written to ./oom-4dad1033f2706cebee2a79b5e921418cc70d6b7b Step #5: Base64: L1xyXHtcMi8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1015 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2236635903 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562917d7d810, 0x562917f6701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562917f67020,0x562919dff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4dad1033f2706cebee2a79b5e921418cc70d6b7b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1145 processed earlier; will process 9884 files now Step #5: ==36574== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56290e8729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562914ed7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562914eba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562914eba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56290e878d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56290e7d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56290e7d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56290e86ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562911839f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562911839f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562911839f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562911839f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562911839f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562911839f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562911839f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562911839f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562911839f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562911839f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562913acef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629107fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562910806be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629105b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629105b2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629105b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629105b2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629105b2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629105b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562914ebcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562914ec5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562914ead699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562914ed8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc4985ab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56290e7d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0x20,0x3f,0x20,0xf0,0x91,0x87,0x80, Step #5: ? ? \360\221\207\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-680d697912f0e3c87e57df004b14a395ea11b48d Step #5: Base64: PyA/IPCRh4A= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1016 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2237068714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55be695d0810, 0x55be697ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55be697ba020,0x55be6b6520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/680d697912f0e3c87e57df004b14a395ea11b48d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1146 processed earlier; will process 9883 files now Step #5: ==36610== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55be600c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55be6672a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55be6670d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55be6670d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55be600cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55be6002cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55be60027355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55be600bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55be6308cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55be6308cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55be6308cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55be6308cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55be6308cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55be6308cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55be6308cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55be6308cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55be6308cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55be6308cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55be65321f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55be6204eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55be62059be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55be61e05c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55be61e05c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55be61e06738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55be61e05874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55be61e05874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55be61e05874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55be6670fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55be66718928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55be66700699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55be6672b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f232b0cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55be60025b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x35,0x32,0x20,0x36,0x33,0x20,0x32, Step #5: P52 63 2 Step #5: artifact_prefix='./'; Test unit written to ./oom-d639eb969a5ffdf5b0a9ed9388f76098f4a39413 Step #5: Base64: UDUyIDYzIDI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1017 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2237501528 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647c5ab0810, 0x5647c5c9a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5647c5c9a020,0x5647c7b320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d639eb969a5ffdf5b0a9ed9388f76098f4a39413' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1147 processed earlier; will process 9882 files now Step #5: ==36646== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5647bc5a59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647c2c0a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647c2bed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647c2bed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647bc5abd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647bc50cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647bc507355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647bc59dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647bf56cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647bf56cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647bf56cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647bf56cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647bf56cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647bf56cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647bf56cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647bf56cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647bf56cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647bf56cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647c1801f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647be52eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647be539be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647be2e5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647be2e5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647be2e6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647be2e5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647be2e5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647be2e5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647c2befabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647c2bf8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647c2be0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647c2c0b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff5acfdd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647bc505b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x36,0x5a,0x29,0x5e,0x2d,0x32,0x34, Step #5: (6Z)^-24 Step #5: artifact_prefix='./'; Test unit written to ./oom-cc57418c218300e0c24a4554da2500d3725e6157 Step #5: Base64: KDZaKV4tMjQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1018 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2237942678 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556dd6811810, 0x556dd69fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556dd69fb020,0x556dd88930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cc57418c218300e0c24a4554da2500d3725e6157' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1148 processed earlier; will process 9881 files now Step #5: ==36682== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556dcd3069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556dd396b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556dd394e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556dd394e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556dcd30cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556dcd26db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556dcd268355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556dcd2fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556dd02cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556dd02cdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556dd02cdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556dd02cdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556dd02cdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556dd02cdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556dd02cdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556dd02cdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556dd02cdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556dd02cdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556dd2562f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556dcf28fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556dcf29abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556dcf046c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556dcf046c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556dcf047738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556dcf046874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556dcf046874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556dcf046874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556dd3950abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556dd3959928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556dd3941699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556dd396c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa9dfd8b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556dcd266b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x57,0x31,0xf0,0x90,0x92,0xa0,0xd7, Step #5: BW1\360\220\222\240\327 Step #5: artifact_prefix='./'; Test unit written to ./oom-a81930a5cd48441ebad103d6a0609d066edafa89 Step #5: Base64: Qlcx8JCSoNc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1019 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2238371654 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55991365f810, 0x55991384901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559913849020,0x5599156e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a81930a5cd48441ebad103d6a0609d066edafa89' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1149 processed earlier; will process 9880 files now Step #5: ==36718== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55990a1549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5599107b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55991079c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55991079c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55990a15ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55990a0bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55990a0b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55990a14cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55990d11bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55990d11bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55990d11bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55990d11bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55990d11bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55990d11bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55990d11bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55990d11bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55990d11bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55990d11bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55990f3b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55990c0ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55990c0e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55990be94c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55990be94c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55990be95738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55990be94874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55990be94874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55990be94874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55991079eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5599107a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55991078f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5599107ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5fb3e5f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55990a0b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x13,0x2b,0x7e,0x74,0x6e,0x65,0x6e,0x2c, Step #5: \023+~tnen, Step #5: artifact_prefix='./'; Test unit written to ./oom-fc6a9c523b046274546f3cc0b6f101b232e7b2c4 Step #5: Base64: Eyt+dG5lbiw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1020 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2238806527 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56481cea5810, 0x56481d08f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56481d08f020,0x56481ef270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc6a9c523b046274546f3cc0b6f101b232e7b2c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1150 processed earlier; will process 9879 files now Step #5: ==36754== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56481399a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564819fff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564819fe25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564819fe24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5648139a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564813901b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5648138fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564813992c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564816961f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564816961f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564816961f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564816961f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564816961f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564816961f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564816961f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564816961f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564816961f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564816961f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564818bf6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564815923b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56481592ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5648156dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5648156dac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5648156db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5648156da874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5648156da874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5648156da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564819fe4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564819fed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564819fd5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56481a000112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f08f7432082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5648138fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xb,0x60,0xf3,0xa0,0x80,0xb6,0xbf, Step #5: `\013`\363\240\200\266\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-4f03fdf36f0f32a59eeecdf8ce7276d025097405 Step #5: Base64: YAtg86CAtr8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1021 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2239357968 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a7c5a6810, 0x563a7c79001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a7c790020,0x563a7e6280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f03fdf36f0f32a59eeecdf8ce7276d025097405' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1151 processed earlier; will process 9878 files now Step #5: ==36790== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563a7309b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a79700898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a796e35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a796e34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a730a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a73002b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a72ffd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a73093c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a76062f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a76062f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a76062f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a76062f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a76062f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a76062f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a76062f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a76062f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a76062f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a76062f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a782f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a75024b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a7502fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a74ddbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a74ddbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a74ddc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a74ddb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a74ddb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a74ddb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a796e5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a796ee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a796d6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a79701112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd259409082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a72ffbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x3a,0xf0,0x9e,0xa3,0x87, Step #5: (?i:\360\236\243\207 Step #5: artifact_prefix='./'; Test unit written to ./oom-4209dc9b46d2cd74b1d97499c09264fe82e9fb98 Step #5: Base64: KD9pOvCeo4c= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1022 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2239793528 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a07378810, 0x555a0756201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a07562020,0x555a093fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4209dc9b46d2cd74b1d97499c09264fe82e9fb98' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1152 processed earlier; will process 9877 files now Step #5: ==36826== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5559fde6d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a044d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a044b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a044b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5559fde73d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5559fddd4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5559fddcf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5559fde65c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a00e34f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a00e34f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a00e34f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a00e34f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a00e34f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a00e34f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a00e34f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a00e34f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a00e34f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a00e34f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a030c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5559ffdf6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5559ffe01be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5559ffbadc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5559ffbadc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5559ffbae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5559ffbad874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5559ffbad874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5559ffbad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a044b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a044c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a044a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a044d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f82e518e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5559fddcdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x4,0xf0,0x91,0x83,0xb1, Step #5: \000\000\000\004\360\221\203\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-a362823c835509edc13f1e4c2bf08e4f6bc86221 Step #5: Base64: AAAABPCRg7E= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1023 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2240227154 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d637ac3810, 0x55d637cad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d637cad020,0x55d639b450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a362823c835509edc13f1e4c2bf08e4f6bc86221' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1153 processed earlier; will process 9876 files now Step #5: ==36862== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d62e5b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d634c1d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d634c005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d634c004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d62e5bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d62e51fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d62e51a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d62e5b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d63157ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d63157ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d63157ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d63157ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d63157ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d63157ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d63157ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d63157ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d63157ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d63157ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d633814f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d630541b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d63054cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d6302f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d6302f8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d6302f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d6302f8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d6302f8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d6302f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d634c02abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d634c0b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d634bf3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d634c1e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa81416c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d62e518b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x24,0x24,0x29,0x7b,0x38,0x36,0x7d, Step #5: ($$){86} Step #5: artifact_prefix='./'; Test unit written to ./oom-fd601bf6e903cd098505791a4bd20c94db015ce2 Step #5: Base64: KCQkKXs4Nn0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1024 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2240662353 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564635c99810, 0x564635e8301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564635e83020,0x564637d1b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fd601bf6e903cd098505791a4bd20c94db015ce2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1154 processed earlier; will process 9875 files now Step #5: #1 pulse cov: 3649 ft: 3650 exec/s: 0 rss: 164Mb Step #5: ==36898== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56462c78e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564632df3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564632dd65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564632dd64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56462c794d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56462c6f5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56462c6f0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56462c786c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56462f755f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56462f755f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56462f755f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56462f755f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56462f755f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56462f755f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56462f755f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56462f755f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56462f755f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56462f755f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5646319eaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56462e717b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56462e722be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56462e4cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56462e4cec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56462e4cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56462e4ce874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56462e4ce874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56462e4ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564632dd8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564632de1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564632dc9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564632df4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f28dfb69082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56462c6eeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xe6,0x9d,0x9d,0xe7,0x9d,0x9d,0x3e, Step #5: <\346\235\235\347\235\235> Step #5: artifact_prefix='./'; Test unit written to ./oom-7f6faefbbbe50225222ceef7a817b5c158a2f0e3 Step #5: Base64: POadneednT4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1025 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2241119982 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d490133810, 0x55d49031d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d49031d020,0x55d4921b50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f6faefbbbe50225222ceef7a817b5c158a2f0e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1156 processed earlier; will process 9873 files now Step #5: ==36934== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d486c289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d48d28d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d48d2705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d48d2704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d486c2ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d486b8fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d486b8a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d486c20c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d489beff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d489beff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d489beff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d489beff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d489beff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d489beff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d489beff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d489beff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d489beff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d489beff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d48be84f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d488bb1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d488bbcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d488968c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d488968c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d488969738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d488968874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d488968874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d488968874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d48d272abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d48d27b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d48d263699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d48d28e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ad7436082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d486b88b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0x7d,0x66,0x7d,0x73,0x7d,0x73,0x7b, Step #5: n}f}s}s{ Step #5: artifact_prefix='./'; Test unit written to ./oom-6f4ec37bdad99d9b1ac4a9d577b0595ba9fca186 Step #5: Base64: bn1mfXN9c3s= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1026 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2241550324 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561f315f2810, 0x561f317dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561f317dc020,0x561f336740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6f4ec37bdad99d9b1ac4a9d577b0595ba9fca186' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1157 processed earlier; will process 9872 files now Step #5: #1 pulse cov: 3608 ft: 3609 exec/s: 0 rss: 163Mb Step #5: ==36970== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561f280e79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561f2e74c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561f2e72f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561f2e72f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561f280edd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561f2804eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561f28049355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561f280dfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561f2b0aef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561f2b0aef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561f2b0aef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561f2b0aef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561f2b0aef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561f2b0aef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561f2b0aef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561f2b0aef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561f2b0aef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561f2b0aef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561f2d343f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561f2a070b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561f2a07bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561f29e27c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561f29e27c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561f29e28738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561f29e27874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561f29e27874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561f29e27874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561f2e731abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561f2e73a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561f2e722699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561f2e74d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8663368082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561f28047b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x60,0x3d,0x60,0x21,0x5b,0x21,0x5b, Step #5: =`=`![![ Step #5: artifact_prefix='./'; Test unit written to ./oom-ffd65313acc50a308f55683d2fb2866c43bf24cf Step #5: Base64: PWA9YCFbIVs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1027 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2242145911 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5564b9a48810, 0x5564b9c3201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564b9c32020,0x5564bbaca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ffd65313acc50a308f55683d2fb2866c43bf24cf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1159 processed earlier; will process 9870 files now Step #5: ==37006== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5564b053d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564b6ba2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564b6b855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564b6b854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564b0543d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5564b04a4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5564b049f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564b0535c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564b3504f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564b3504f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564b3504f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564b3504f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564b3504f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564b3504f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564b3504f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564b3504f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564b3504f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564b3504f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5564b5799f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5564b24c6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5564b24d1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5564b227dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5564b227dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5564b227e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5564b227d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5564b227d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5564b227d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564b6b87abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564b6b90928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564b6b78699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564b6ba3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f31c22fe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5564b049db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0xf0,0x9e,0x84,0x9e, Step #5: (?i)\360\236\204\236 Step #5: artifact_prefix='./'; Test unit written to ./oom-025781f21ad76926a4589994c9c7d04a30d21dfa Step #5: Base64: KD9pKfCehJ4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1028 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2242580333 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d8df277810, 0x55d8df46101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d8df461020,0x55d8e12f90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/025781f21ad76926a4589994c9c7d04a30d21dfa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1160 processed earlier; will process 9869 files now Step #5: ==37042== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d8d5d6c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d8dc3d1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d8dc3b45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d8dc3b44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d8d5d72d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d8d5cd3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d8d5cce355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d8d5d64c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d8d8d33f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d8d8d33f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d8d8d33f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d8d8d33f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d8d8d33f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d8d8d33f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d8d8d33f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d8d8d33f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d8d8d33f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d8d8d33f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d8dafc8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d8d7cf5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d8d7d00be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d8d7aacc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d8d7aacc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d8d7aad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d8d7aac874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d8d7aac874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d8d7aac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d8dc3b6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d8dc3bf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d8dc3a7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d8dc3d2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f72ea83f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d8d5cccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x60,0x7c,0xd,0x20,0x60,0xd,0x35, Step #5: |`|\015 `\0155 Step #5: artifact_prefix='./'; Test unit written to ./oom-9050b8b1250074676aa6b75848e0d74e3bc36d01 Step #5: Base64: fGB8DSBgDTU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1029 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2243134847 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c724eaa810, 0x55c72509401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c725094020,0x55c726f2c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9050b8b1250074676aa6b75848e0d74e3bc36d01' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1161 processed earlier; will process 9868 files now Step #5: ==37078== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c71b99f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c722004898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c721fe75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c721fe74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c71b9a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c71b906b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c71b901355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c71b997c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c71e966f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c71e966f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c71e966f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c71e966f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c71e966f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c71e966f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c71e966f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c71e966f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c71e966f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c71e966f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c720bfbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c71d928b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c71d933be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c71d6dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c71d6dfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c71d6e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c71d6df874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c71d6df874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c71d6df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c721fe9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c721ff2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c721fda699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c722005112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe134088082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c71b8ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x68,0x6d,0x74,0x78,0x69,0x3f,0x57,0x4f, Step #5: hmtxi?WO Step #5: artifact_prefix='./'; Test unit written to ./oom-597f18c7ba2c873939f07274ef57b5a8519cf10a Step #5: Base64: aG10eGk/V08= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1030 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2243563980 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562b972f5810, 0x562b974df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562b974df020,0x562b993770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/597f18c7ba2c873939f07274ef57b5a8519cf10a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1162 processed earlier; will process 9867 files now Step #5: ==37114== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562b8ddea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562b9444f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562b944325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562b944324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b8ddf0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b8dd51b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b8dd4c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b8dde2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b90db1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b90db1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b90db1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b90db1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b90db1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b90db1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b90db1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b90db1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b90db1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b90db1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562b93046f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b8fd73b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b8fd7ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b8fb2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b8fb2ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b8fb2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b8fb2a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b8fb2a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b8fb2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562b94434abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562b9443d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562b94425699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562b94450112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f52f60e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b8dd4ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xe3,0x80,0x80,0x80,0xc0,0xff,0x7f, Step #5: +\343\200\200\200\300\377\177 Step #5: artifact_prefix='./'; Test unit written to ./oom-8a4c30e36618dd3fc1ac30aeda058b6bf5e8772a Step #5: Base64: K+OAgIDA/38= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1031 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2243993066 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643eff04810, 0x5643f00ee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643f00ee020,0x5643f1f860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8a4c30e36618dd3fc1ac30aeda058b6bf5e8772a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1163 processed earlier; will process 9866 files now Step #5: ==37150== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5643e69f99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643ed05e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643ed0415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643ed0414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643e69ffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643e6960b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643e695b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643e69f1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643e99c0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643e99c0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643e99c0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643e99c0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643e99c0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643e99c0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643e99c0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643e99c0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643e99c0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643e99c0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643ebc55f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643e8982b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643e898dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643e8739c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643e8739c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643e873a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643e8739874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643e8739874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643e8739874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643ed043abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643ed04c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643ed034699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643ed05f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9d756c7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643e6959b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5e,0x0,0x2d,0xef,0xbf,0xa3,0x5d, Step #5: [^\000-\357\277\243] Step #5: artifact_prefix='./'; Test unit written to ./oom-3be1e8a4fea5c5d7c4cc03ecf59625f5649db196 Step #5: Base64: W14ALe+/o10= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1032 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2244426714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ba74cc810, 0x555ba76b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ba76b6020,0x555ba954e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3be1e8a4fea5c5d7c4cc03ecf59625f5649db196' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1164 processed earlier; will process 9865 files now Step #5: ==37186== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555b9dfc19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ba4626898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ba46095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ba46094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b9dfc7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b9df28b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b9df23355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b9dfb9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ba0f88f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ba0f88f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ba0f88f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ba0f88f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ba0f88f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ba0f88f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ba0f88f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ba0f88f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ba0f88f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ba0f88f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555ba321df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b9ff4ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b9ff55be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b9fd01c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b9fd01c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b9fd02738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b9fd01874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b9fd01874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b9fd01874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ba460babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ba4614928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ba45fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ba4627112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe2f1797082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b9df21b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3c,0xf2,0xbf,0xbe,0x9e,0x3e, Step #5: (?<\362\277\276\236> Step #5: artifact_prefix='./'; Test unit written to ./oom-f4262e3bd1041df384bcaabae59a1b570b90b198 Step #5: Base64: KD888r++nj4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1033 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2244856412 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5592c2087810, 0x5592c227101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5592c2271020,0x5592c41090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f4262e3bd1041df384bcaabae59a1b570b90b198' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1165 processed earlier; will process 9864 files now Step #5: ==37222== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5592b8b7c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5592bf1e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5592bf1c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5592bf1c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592b8b82d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592b8ae3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592b8ade355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592b8b74c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592bbb43f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592bbb43f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592bbb43f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592bbb43f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592bbb43f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592bbb43f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592bbb43f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592bbb43f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592bbb43f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592bbb43f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592bddd8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592bab05b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592bab10be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5592ba8bcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5592ba8bcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5592ba8bd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5592ba8bc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5592ba8bc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5592ba8bc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5592bf1c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5592bf1cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5592bf1b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5592bf1e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f269baa5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592b8adcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xef,0xa8,0xa7,0xcd,0x84, Step #5: ws:\357\250\247\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-66792ba65fbf5804649e04d9d47d2ffaef918ad6 Step #5: Base64: d3M676inzYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1034 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2245287651 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b32ff3810, 0x555b331dd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b331dd020,0x555b350750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/66792ba65fbf5804649e04d9d47d2ffaef918ad6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1166 processed earlier; will process 9863 files now Step #5: #1 pulse cov: 3581 ft: 3582 exec/s: 0 rss: 161Mb Step #5: ==37258== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555b29ae89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b3014d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b301305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b301304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b29aeed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b29a4fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b29a4a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b29ae0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b2caaff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b2caaff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b2caaff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b2caaff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b2caaff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b2caaff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b2caaff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b2caaff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b2caaff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b2caaff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b2ed44f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b2ba71b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b2ba7cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b2b828c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b2b828c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b2b829738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b2b828874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b2b828874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b2b828874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b30132abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b3013b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b30123699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b3014e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe941ee7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b29a48b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x3d,0xb,0x60,0xa,0x3d,0xa,0x60, Step #5: t=\013`\012=\012` Step #5: artifact_prefix='./'; Test unit written to ./oom-078b272e5820958eb805098fe13118a0e0b01d88 Step #5: Base64: dD0LYAo9CmA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1035 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2245880830 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563277a7a810, 0x563277c6401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563277c64020,0x563279afc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/078b272e5820958eb805098fe13118a0e0b01d88' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1168 processed earlier; will process 9861 files now Step #5: ==37294== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56326e56f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563274bd4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563274bb75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563274bb74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56326e575d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56326e4d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56326e4d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56326e567c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563271536f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563271536f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563271536f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563271536f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563271536f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563271536f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563271536f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563271536f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563271536f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563271536f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5632737cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5632704f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563270503be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5632702afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5632702afc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5632702b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5632702af874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5632702af874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5632702af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563274bb9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563274bc2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563274baa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563274bd5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8266735082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56326e4cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x6a, Step #5: 1******j Step #5: artifact_prefix='./'; Test unit written to ./oom-97005b37a72c6a43ef041e9b158c75fe04584b63 Step #5: Base64: MSoqKioqKmo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1036 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2246309895 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56299ab9f810, 0x56299ad8901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56299ad89020,0x56299cc210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/97005b37a72c6a43ef041e9b158c75fe04584b63' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1169 processed earlier; will process 9860 files now Step #5: ==37330== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5629916949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562997cf9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562997cdc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562997cdc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56299169ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629915fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629915f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56299168cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56299465bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56299465bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56299465bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56299465bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56299465bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56299465bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56299465bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56299465bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56299465bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56299465bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5629968f0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56299361db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562993628be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629933d4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629933d4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629933d5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629933d4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629933d4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629933d4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562997cdeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562997ce7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562997ccf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562997cfa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0fbf64b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629915f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xef,0xac,0xac,0xcd,0x83, Step #5: ws:\357\254\254\315\203 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ce62ddf6244ea9a7207e9d92c1811e8f86a0b90 Step #5: Base64: d3M676yszYM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1037 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2246746545 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c097eec810, 0x55c0980d601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c0980d6020,0x55c099f6e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ce62ddf6244ea9a7207e9d92c1811e8f86a0b90' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1170 processed earlier; will process 9859 files now Step #5: ==37366== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c08e9e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c095046898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c0950295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c0950294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c08e9e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c08e948b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c08e943355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c08e9d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c0919a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c0919a8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c0919a8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c0919a8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c0919a8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c0919a8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c0919a8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c0919a8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c0919a8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c0919a8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c093c3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c09096ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c090975be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c090721c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c090721c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c090722738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c090721874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c090721874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c090721874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c09502babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c095034928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c09501c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c095047112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc9e04a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c08e941b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0xf0,0x9e,0xa4,0xa6, Step #5: (?i)\360\236\244\246 Step #5: artifact_prefix='./'; Test unit written to ./oom-fb8fa21f7f7bef6f2a4778dc56569e543f1245b9 Step #5: Base64: KD9pKfCepKY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1038 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2247178034 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5641be1f0810, 0x5641be3da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5641be3da020,0x5641c02720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fb8fa21f7f7bef6f2a4778dc56569e543f1245b9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1171 processed earlier; will process 9858 files now Step #5: ==37402== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5641b4ce59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5641bb34a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5641bb32d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5641bb32d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5641b4cebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641b4c4cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641b4c47355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5641b4cddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5641b7cacf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5641b7cacf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5641b7cacf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5641b7cacf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5641b7cacf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5641b7cacf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5641b7cacf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5641b7cacf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5641b7cacf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5641b7cacf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5641b9f41f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5641b6c6eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5641b6c79be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5641b6a25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5641b6a25c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5641b6a26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5641b6a25874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5641b6a25874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5641b6a25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5641bb32fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5641bb338928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5641bb320699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5641bb34b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff50cbf2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641b4c45b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0xe3,0x80,0x8c,0xde,0xbf,0x5d,0x3a, Step #5: [\343\200\214\336\277]: Step #5: artifact_prefix='./'; Test unit written to ./oom-37b3b13705096bdece68996afb7dd03481863839 Step #5: Base64: W+OAjN6/XTo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1039 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2247611188 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55615dccb810, 0x55615deb501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55615deb5020,0x55615fd4d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/37b3b13705096bdece68996afb7dd03481863839' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1172 processed earlier; will process 9857 files now Step #5: ==37438== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5561547c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55615ae25898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55615ae085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55615ae084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5561547c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556154727b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556154722355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5561547b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556157787f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556157787f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556157787f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556157787f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556157787f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556157787f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556157787f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556157787f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556157787f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556157787f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556159a1cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556156749b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556156754be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556156500c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556156500c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556156501738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556156500874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556156500874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556156500874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55615ae0aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55615ae13928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55615adfb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55615ae26112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb26de61082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556154720b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x4,0x25,0xde,0x8d,0x30, Step #5: \000\000\000\004%\336\2150 Step #5: artifact_prefix='./'; Test unit written to ./oom-d3f9cc99669fcefaabd71480441fc0fd96993253 Step #5: Base64: AAAABCXejTA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1040 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2248043738 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56026dcf3810, 0x56026dedd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56026dedd020,0x56026fd750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d3f9cc99669fcefaabd71480441fc0fd96993253' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1173 processed earlier; will process 9856 files now Step #5: #1 pulse cov: 10562 ft: 10563 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 11051 ft: 11842 exec/s: 0 rss: 183Mb Step #5: ==37474== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5602647e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56026ae4d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56026ae305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56026ae304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5602647eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56026474fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56026474a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5602647e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5602677aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5602677aff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5602677aff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5602677aff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5602677aff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5602677aff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5602677aff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5602677aff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5602677aff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5602677aff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560269a44f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560266771b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56026677cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560266528c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560266528c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560266529738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560266528874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560266528874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560266528874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56026ae32abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56026ae3b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56026ae23699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56026ae4e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f879e53d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560264748b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0xa,0x22,0x22,0x3a,0xa,0xa,0x7d, Step #5: {\012\"\":\012\012} Step #5: artifact_prefix='./'; Test unit written to ./oom-9d834bdd52dfb92dab7a415755249483d390ee81 Step #5: Base64: ewoiIjoKCn0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1041 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2248608168 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc8f826810, 0x55cc8fa1001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc8fa10020,0x55cc918a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9d834bdd52dfb92dab7a415755249483d390ee81' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1177 processed earlier; will process 9852 files now Step #5: ==37510== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cc8631b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc8c980898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc8c9635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc8c9634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc86321d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc86282b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc8627d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc86313c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc892e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc892e2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc892e2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc892e2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc892e2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc892e2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc892e2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc892e2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc892e2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc892e2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc8b577f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc882a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc882afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc8805bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc8805bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc8805c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc8805b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc8805b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc8805b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc8c965abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc8c96e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc8c956699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc8c981112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6463629082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc8627bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x53,0x3a,0xe3,0x8c,0x96,0xcd,0x84, Step #5: wS:\343\214\226\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-1370d0240a5a594a7286a5739a44271fce42500c Step #5: Base64: d1M644yWzYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1042 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2249040082 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647e0536810, 0x5647e072001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5647e0720020,0x5647e25b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1370d0240a5a594a7286a5739a44271fce42500c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1178 processed earlier; will process 9851 files now Step #5: ==37546== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5647d702b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647dd690898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647dd6735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647dd6734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647d7031d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647d6f92b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647d6f8d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647d7023c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647d9ff2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647d9ff2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647d9ff2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647d9ff2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647d9ff2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647d9ff2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647d9ff2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647d9ff2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647d9ff2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647d9ff2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647dc287f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647d8fb4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647d8fbfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647d8d6bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647d8d6bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647d8d6c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647d8d6b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647d8d6b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647d8d6b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647dd675abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647dd67e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647dd666699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647dd691112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa847d24082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647d6f8bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0xa,0x64,0xa,0x60,0xe,0x60,0xe, Step #5: d\012d\012`\016`\016 Step #5: artifact_prefix='./'; Test unit written to ./oom-aea50aff24bb3845bc662690c42f87d5af1b64f0 Step #5: Base64: ZApkCmAOYA4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1043 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2249597015 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b05fe59810, 0x55b06004301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b060043020,0x55b061edb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aea50aff24bb3845bc662690c42f87d5af1b64f0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1179 processed earlier; will process 9850 files now Step #5: ==37582== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b05694e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b05cfb3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b05cf965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b05cf964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b056954d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0568b5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0568b0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b056946c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b059915f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b059915f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b059915f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b059915f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b059915f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b059915f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b059915f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b059915f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b059915f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b059915f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b05bbaaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b0588d7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b0588e2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b05868ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b05868ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b05868f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b05868e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b05868e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b05868e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b05cf98abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b05cfa1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b05cf89699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b05cfb4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1492f4d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0568aeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x49,0x32,0xf0,0x91,0xb5,0x99,0x53, Step #5: AI2\360\221\265\231S Step #5: artifact_prefix='./'; Test unit written to ./oom-d2106c95ef063ed2d0398444b748b371f78bf596 Step #5: Base64: QUky8JG1mVM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1044 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2250028447 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558f708ee810, 0x558f70ad801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558f70ad8020,0x558f729700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d2106c95ef063ed2d0398444b748b371f78bf596' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1180 processed earlier; will process 9849 files now Step #5: ==37618== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558f673e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558f6da48898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558f6da2b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558f6da2b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f673e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f6734ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f67345355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f673dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f6a3aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f6a3aaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f6a3aaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f6a3aaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f6a3aaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f6a3aaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f6a3aaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f6a3aaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f6a3aaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f6a3aaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558f6c63ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f6936cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f69377be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f69123c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f69123c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f69124738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f69123874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f69123874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f69123874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558f6da2dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558f6da36928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558f6da1e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558f6da49112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f93d89b2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f67343b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0x25,0x3f,0x25,0x3f,0x25,0x3f,0x25, Step #5: ?%?%?%?% Step #5: artifact_prefix='./'; Test unit written to ./oom-2fac8c4622c069afc3fd0332370c191b319b41fe Step #5: Base64: PyU/JT8lPyU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1045 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2250461004 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563c9c636810, 0x563c9c82001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563c9c820020,0x563c9e6b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2fac8c4622c069afc3fd0332370c191b319b41fe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1181 processed earlier; will process 9848 files now Step #5: #1 pulse cov: 3731 ft: 3732 exec/s: 0 rss: 164Mb Step #5: ==37654== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563c9312b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563c99790898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563c997735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563c997734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563c93131d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563c93092b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563c9308d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563c93123c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563c960f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563c960f2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563c960f2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563c960f2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563c960f2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563c960f2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563c960f2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563c960f2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563c960f2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563c960f2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563c98387f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563c950b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563c950bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563c94e6bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563c94e6bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563c94e6c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563c94e6b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563c94e6b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563c94e6b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563c99775abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563c9977e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563c99766699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563c99791112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9422dd5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563c9308bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x6d,0x9,0xb,0x9,0x9,0x9,0x9, Step #5: -m\011\013\011\011\011\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-6b43f502c7228bab7fb16702e32ba238359fe277 Step #5: Base64: LW0JCwkJCQk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1046 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2250936990 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee35a42810, 0x55ee35c2c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee35c2c020,0x55ee37ac40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b43f502c7228bab7fb16702e32ba238359fe277' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1183 processed earlier; will process 9846 files now Step #5: ==37690== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ee2c5379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee32b9c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee32b7f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee32b7f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee2c53dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee2c49eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee2c499355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee2c52fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee2f4fef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee2f4fef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee2f4fef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee2f4fef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee2f4fef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee2f4fef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee2f4fef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee2f4fef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee2f4fef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee2f4fef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee31793f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee2e4c0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee2e4cbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee2e277c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee2e277c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee2e278738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee2e277874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee2e277874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee2e277874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee32b81abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee32b8a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee32b72699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee32b9d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe9ae3b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee2c497b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x3c,0x0,0x0,0xd6,0xaa, Step #5: \000\000\000<\000\000\326\252 Step #5: artifact_prefix='./'; Test unit written to ./oom-3cd7e5452ed3ca3ed1bd23ed5fc1be277f19cf3d Step #5: Base64: AAAAPAAA1qo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1047 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2251367489 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f1846fe810, 0x55f1848e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f1848e8020,0x55f1867800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3cd7e5452ed3ca3ed1bd23ed5fc1be277f19cf3d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1184 processed earlier; will process 9845 files now Step #5: ==37726== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f17b1f39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f181858898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f18183b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f18183b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f17b1f9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f17b15ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f17b155355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f17b1ebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f17e1baf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f17e1baf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f17e1baf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f17e1baf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f17e1baf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f17e1baf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f17e1baf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f17e1baf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f17e1baf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f17e1baf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f18044ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f17d17cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f17d187be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f17cf33c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f17cf33c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f17cf34738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f17cf33874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f17cf33874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f17cf33874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f18183dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f181846928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f18182e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f181859112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd983959082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f17b153b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x3a,0xf0,0x9c,0x9e,0x9b, Step #5: (?i:\360\234\236\233 Step #5: artifact_prefix='./'; Test unit written to ./oom-6a25b93c06315a97c140d847e2792951b5c7e0bf Step #5: Base64: KD9pOvCcnps= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1048 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2251807727 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a405c85810, 0x55a405e6f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a405e6f020,0x55a407d070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a25b93c06315a97c140d847e2792951b5c7e0bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1185 processed earlier; will process 9844 files now Step #5: ==37762== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a3fc77a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a402ddf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a402dc25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a402dc24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3fc780d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a3fc6e1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a3fc6dc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3fc772c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a3ff741f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a3ff741f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a3ff741f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a3ff741f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a3ff741f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a3ff741f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a3ff741f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a3ff741f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a3ff741f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a3ff741f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a4019d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3fe703b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3fe70ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3fe4bac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3fe4bac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3fe4bb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3fe4ba874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3fe4ba874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3fe4ba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a402dc4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a402dcd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a402db5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a402de0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff974581082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a3fc6dab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x46,0x6f,0xcc,0x80,0x2f,0xb0,0xdb, Step #5: \012Fo\314\200/\260\333 Step #5: artifact_prefix='./'; Test unit written to ./oom-e6a6c4f545a11c341aec2788f6d571db95028278 Step #5: Base64: CkZvzIAvsNs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1049 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2252241099 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561377c6d810, 0x561377e5701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561377e57020,0x561379cef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e6a6c4f545a11c341aec2788f6d571db95028278' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1186 processed earlier; will process 9843 files now Step #5: ==37798== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56136e7629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561374dc7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561374daa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561374daa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56136e768d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56136e6c9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56136e6c4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56136e75ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561371729f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561371729f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561371729f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561371729f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561371729f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561371729f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561371729f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561371729f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561371729f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561371729f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5613739bef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5613706ebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5613706f6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5613704a2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5613704a2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5613704a3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5613704a2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5613704a2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5613704a2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561374dacabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561374db5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561374d9d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561374dc8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc7cf41d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56136e6c2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0x44,0xb,0xa,0xa,0x44,0xb,0xa, Step #5: \013D\013\012\012D\013\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-c3911998ffa3fd8d554ca87f181af175531e35c7 Step #5: Base64: C0QLCgpECwo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1050 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2252673185 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ff79f0810, 0x562ff7bda01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ff7bda020,0x562ff9a720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c3911998ffa3fd8d554ca87f181af175531e35c7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1187 processed earlier; will process 9842 files now Step #5: ==37834== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562fee4e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ff4b4a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ff4b2d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ff4b2d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562fee4ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562fee44cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562fee447355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562fee4ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ff14acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ff14acf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ff14acf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ff14acf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ff14acf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ff14acf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ff14acf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ff14acf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ff14acf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ff14acf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ff3741f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ff046eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ff0479be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ff0225c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ff0225c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ff0226738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ff0225874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ff0225874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ff0225874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ff4b2fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ff4b38928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ff4b20699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ff4b4b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0331e2b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562fee445b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x2a,0x27,0x2a,0x74,0x6d,0x78,0x58, Step #5: B*'*tmxX Step #5: artifact_prefix='./'; Test unit written to ./oom-b6de84f9b21a8f4d3fa44625ed523326c019cc3c Step #5: Base64: QionKnRteFg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1051 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2253108065 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564881088810, 0x56488127201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564881272020,0x56488310a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b6de84f9b21a8f4d3fa44625ed523326c019cc3c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1188 processed earlier; will process 9841 files now Step #5: #1 pulse cov: 10568 ft: 10569 exec/s: 0 rss: 180Mb Step #5: ==37870== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564877b7d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56487e1e2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56487e1c55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56487e1c54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564877b83d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564877ae4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564877adf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564877b75c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56487ab44f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56487ab44f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56487ab44f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56487ab44f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56487ab44f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56487ab44f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56487ab44f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56487ab44f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56487ab44f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56487ab44f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56487cdd9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564879b06b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564879b11be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5648798bdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5648798bdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5648798be738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5648798bd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5648798bd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5648798bd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56487e1c7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56487e1d0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56487e1b8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56487e1e3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4cda2fd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564877addb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xb,0x60,0xf3,0xa2,0x80,0xb6,0xbf, Step #5: `\013`\363\242\200\266\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-60b39f4d36bd9986348883f91a4de0314cda8493 Step #5: Base64: YAtg86KAtr8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1052 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2253734547 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8404ac810, 0x55c84069601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c840696020,0x55c84252e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/60b39f4d36bd9986348883f91a4de0314cda8493' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1190 processed earlier; will process 9839 files now Step #5: ==37906== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c836fa19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c83d606898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c83d5e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c83d5e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c836fa7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c836f08b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c836f03355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c836f99c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c839f68f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c839f68f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c839f68f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c839f68f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c839f68f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c839f68f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c839f68f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c839f68f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c839f68f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c839f68f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c83c1fdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c838f2ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c838f35be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c838ce1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c838ce1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c838ce2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c838ce1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c838ce1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c838ce1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c83d5ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c83d5f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c83d5dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c83d607112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe7cbe96082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c836f01b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60, Step #5: _`_`_`_` Step #5: artifact_prefix='./'; Test unit written to ./oom-5ef2c6a17c6de85e0e5856740525712975d5050f Step #5: Base64: X2BfYF9gX2A= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1053 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2254294378 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559308a85810, 0x559308c6f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559308c6f020,0x55930ab070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ef2c6a17c6de85e0e5856740525712975d5050f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1191 processed earlier; will process 9838 files now Step #5: #1 pulse cov: 3556 ft: 3557 exec/s: 0 rss: 164Mb Step #5: #2 pulse cov: 3699 ft: 3991 exec/s: 0 rss: 165Mb Step #5: ==37942== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5592ff57a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559305bdf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559305bc25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559305bc24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592ff580d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592ff4e1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592ff4dc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592ff572c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559302541f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559302541f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559302541f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559302541f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559302541f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559302541f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559302541f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559302541f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559302541f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559302541f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5593047d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559301503b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55930150ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5593012bac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5593012bac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5593012bb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5593012ba874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5593012ba874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5593012ba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559305bc4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559305bcd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559305bb5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559305be0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fecd2622082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592ff4dab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x3f,0x3f,0x3d,0x3f,0x3f,0x3f,0x3d, Step #5: '??=???= Step #5: artifact_prefix='./'; Test unit written to ./oom-880d93554bac85a758bafe2e413ae7937a2c07bf Step #5: Base64: Jz8/PT8/Pz0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1054 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2254841144 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5626090ea810, 0x5626092d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5626092d4020,0x56260b16c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/880d93554bac85a758bafe2e413ae7937a2c07bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1195 processed earlier; will process 9834 files now Step #5: ==37978== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5625ffbdf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562606244898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5626062275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5626062274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5625ffbe5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625ffb46b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625ffb41355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5625ffbd7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562602ba6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562602ba6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562602ba6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562602ba6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562602ba6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562602ba6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562602ba6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562602ba6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562602ba6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562602ba6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562604e3bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562601b68b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562601b73be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56260191fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56260191fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562601920738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56260191f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56260191f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56260191f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562606229abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562606232928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56260621a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562606245112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f03faf81082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625ffb3fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x27,0x27,0xd8,0x98,0x27,0x27,0x27, Step #5: '''\330\230''' Step #5: artifact_prefix='./'; Test unit written to ./oom-11390ae1d934f6c27044a4e1801302886ae6a897 Step #5: Base64: Jycn2JgnJyc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1055 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2255279511 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cd7e849810, 0x55cd7ea3301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cd7ea33020,0x55cd808cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/11390ae1d934f6c27044a4e1801302886ae6a897' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1196 processed earlier; will process 9833 files now Step #5: #1 pulse cov: 3535 ft: 3536 exec/s: 0 rss: 161Mb Step #5: ==38014== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cd7533e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cd7b9a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cd7b9865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cd7b9864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cd75344d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cd752a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cd752a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cd75336c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cd78305f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cd78305f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cd78305f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cd78305f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cd78305f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cd78305f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cd78305f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cd78305f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cd78305f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cd78305f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cd7a59af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cd772c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cd772d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cd7707ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cd7707ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cd7707f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cd7707e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cd7707e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cd7707e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cd7b988abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cd7b991928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cd7b979699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cd7b9a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb592caa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cd7529eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5b,0x3a,0x5b,0x3a,0x5b,0x3a,0x0, Step #5: [[:[:[:\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-94cb60a672c59a03ce710b16435d0ffeed327415 Step #5: Base64: W1s6WzpbOgA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1056 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2255760601 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c0b2ed810, 0x562c0b4d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c0b4d7020,0x562c0d36f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/94cb60a672c59a03ce710b16435d0ffeed327415' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1198 processed earlier; will process 9831 files now Step #5: ==38050== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562c01de29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c08447898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c0842a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c0842a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c01de8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c01d49b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c01d44355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c01ddac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c04da9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c04da9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c04da9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c04da9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c04da9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c04da9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c04da9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c04da9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c04da9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c04da9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c0703ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562c03d6bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562c03d76be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562c03b22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562c03b22c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562c03b23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562c03b22874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562c03b22874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562c03b22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c0842cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c08435928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c0841d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c08448112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcbc1bf5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c01d42b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd6,0xb6,0xb6,0xfe,0xf3,0xf3,0x81,0x4f, Step #5: \326\266\266\376\363\363\201O Step #5: artifact_prefix='./'; Test unit written to ./oom-14367d48aef8ddfb5497414a8f2d07a13ebffc9d Step #5: Base64: 1ra2/vPzgU8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1057 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2256204326 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556e1ebaa810, 0x556e1ed9401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556e1ed94020,0x556e20c2c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/14367d48aef8ddfb5497414a8f2d07a13ebffc9d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1199 processed earlier; will process 9830 files now Step #5: ==38086== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556e1569f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556e1bd04898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556e1bce75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556e1bce74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556e156a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556e15606b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556e15601355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556e15697c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556e18666f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556e18666f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556e18666f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556e18666f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556e18666f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556e18666f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556e18666f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556e18666f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556e18666f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556e18666f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556e1a8fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556e17628b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556e17633be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556e173dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556e173dfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556e173e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556e173df874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556e173df874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556e173df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556e1bce9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556e1bcf2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556e1bcda699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556e1bd05112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f46c8fa4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556e155ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0xd6,0x9a,0xa1,0xa5, Step #5: (?i)\326\232\241\245 Step #5: artifact_prefix='./'; Test unit written to ./oom-3069d4cdcb40bcf4b8ab691f56af444391d076c6 Step #5: Base64: KD9pKdaaoaU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1058 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2256648598 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5629f2882810, 0x5629f2a6c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5629f2a6c020,0x5629f49040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3069d4cdcb40bcf4b8ab691f56af444391d076c6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1200 processed earlier; will process 9829 files now Step #5: ==38122== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5629e93779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5629ef9dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5629ef9bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5629ef9bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5629e937dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629e92deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629e92d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5629e936fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5629ec33ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5629ec33ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5629ec33ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5629ec33ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5629ec33ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5629ec33ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5629ec33ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5629ec33ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5629ec33ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5629ec33ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5629ee5d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629eb300b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629eb30bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629eb0b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629eb0b7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629eb0b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629eb0b7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629eb0b7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629eb0b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5629ef9c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5629ef9ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5629ef9b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5629ef9dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb2d555a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629e92d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9e,0xb9,0x91,0xf0,0x9e,0xb9,0x81, Step #5: \360\236\271\221\360\236\271\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-3703a269c87400440d71e46417879a0d2560e070 Step #5: Base64: 8J65kfCeuYE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1059 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2257085464 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1ce225810, 0x55d1ce40f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1ce40f020,0x55d1d02a70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3703a269c87400440d71e46417879a0d2560e070' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1201 processed earlier; will process 9828 files now Step #5: ==38158== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d1c4d1a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1cb37f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1cb3625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1cb3624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1c4d20d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1c4c81b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1c4c7c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1c4d12c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1c7ce1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1c7ce1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1c7ce1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1c7ce1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1c7ce1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1c7ce1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1c7ce1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1c7ce1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1c7ce1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1c7ce1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1c9f76f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1c6ca3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1c6caebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1c6a5ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1c6a5ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1c6a5b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1c6a5a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1c6a5a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1c6a5a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1cb364abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1cb36d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1cb355699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1cb380112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa932cdb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1c4c7ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0x23,0x38,0x38,0x38,0x38,0x38,0x3b, Step #5: 𕬸 Step #5: artifact_prefix='./'; Test unit written to ./oom-c1d856f341c00ba2a34437f229af4fa4d6599762 Step #5: Base64: JiM4ODg4ODs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1060 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2257525550 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c78ccb5810, 0x55c78ce9f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c78ce9f020,0x55c78ed370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c1d856f341c00ba2a34437f229af4fa4d6599762' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1202 processed earlier; will process 9827 files now Step #5: ==38194== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c7837aa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c789e0f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c789df25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c789df24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c7837b0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c783711b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c78370c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7837a2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c786771f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c786771f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c786771f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c786771f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c786771f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c786771f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c786771f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c786771f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c786771f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c786771f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c788a06f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c785733b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c78573ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7854eac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7854eac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7854eb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7854ea874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7854ea874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7854ea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c789df4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c789dfd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c789de5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c789e10112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faecf6f3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c78370ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x2,0xa,0xa,0x1,0x0,0x2,0xf1, Step #5: \002\002\012\012\001\000\002\361 Step #5: artifact_prefix='./'; Test unit written to ./oom-4699546f02604485547dd6348f474b80cbb5546e Step #5: Base64: AgIKCgEAAvE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1061 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2257964228 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d795ecb810, 0x55d7960b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d7960b5020,0x55d797f4d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4699546f02604485547dd6348f474b80cbb5546e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1203 processed earlier; will process 9826 files now Step #5: ==38230== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d78c9c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d793025898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7930085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7930084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d78c9c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d78c927b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d78c922355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d78c9b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d78f987f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d78f987f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d78f987f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d78f987f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d78f987f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d78f987f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d78f987f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d78f987f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d78f987f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d78f987f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d791c1cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d78e949b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d78e954be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d78e700c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d78e700c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d78e701738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d78e700874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d78e700874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d78e700874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d79300aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d793013928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d792ffb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d793026112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc7f31d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d78c920b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53,0x43,0x46,0x46,0x20,0xc2,0xbd,0x27, Step #5: SCFF \302\275' Step #5: artifact_prefix='./'; Test unit written to ./oom-e3d54623d04c9f72c009ff23e0cf74ce07a6c483 Step #5: Base64: U0NGRiDCvSc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1062 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2258399097 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ef58a7e810, 0x55ef58c6801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ef58c68020,0x55ef5ab000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e3d54623d04c9f72c009ff23e0cf74ce07a6c483' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1204 processed earlier; will process 9825 files now Step #5: ==38266== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ef4f5739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ef55bd8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ef55bbb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ef55bbb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef4f579d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef4f4dab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef4f4d5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef4f56bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef5253af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef5253af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef5253af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef5253af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef5253af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef5253af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef5253af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef5253af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef5253af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef5253af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef547cff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef514fcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef51507be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef512b3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef512b3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef512b4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef512b3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef512b3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef512b3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ef55bbdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ef55bc6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ef55bae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ef55bd9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e08b70082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef4f4d3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0x5b,0xe1,0x9e,0xbc, Step #5: (?i)[\341\236\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-030d3cfc50f8275f740b44cc521b4d7ecf27787b Step #5: Base64: KD9pKVvhnrw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1063 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2258837611 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56096de6d810, 0x56096e05701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56096e057020,0x56096feef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/030d3cfc50f8275f740b44cc521b4d7ecf27787b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1205 processed earlier; will process 9824 files now Step #5: ==38302== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5609649629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56096afc7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56096afaa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56096afaa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560964968d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5609648c9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5609648c4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56096495ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560967929f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560967929f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560967929f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560967929f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560967929f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560967929f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560967929f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560967929f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560967929f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560967929f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560969bbef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5609668ebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5609668f6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5609666a2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5609666a2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5609666a3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5609666a2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5609666a2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5609666a2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56096afacabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56096afb5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56096af9d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56096afc8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0c004ac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5609648c2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x84,0xcd,0x84,0xf0,0x9d,0x85,0xad, Step #5: \315\204\315\204\360\235\205\255 Step #5: artifact_prefix='./'; Test unit written to ./oom-5c09656ddec5b7321f5768fdba3f3d9495ab5698 Step #5: Base64: zYTNhPCdha0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1064 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2259278885 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5650f8d74810, 0x5650f8f5e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5650f8f5e020,0x5650fadf60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c09656ddec5b7321f5768fdba3f3d9495ab5698' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1206 processed earlier; will process 9823 files now Step #5: ==38338== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5650ef8699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5650f5ece898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5650f5eb15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5650f5eb14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5650ef86fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5650ef7d0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5650ef7cb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5650ef861c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5650f2830f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5650f2830f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5650f2830f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5650f2830f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5650f2830f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5650f2830f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5650f2830f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5650f2830f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5650f2830f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5650f2830f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5650f4ac5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5650f17f2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5650f17fdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5650f15a9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5650f15a9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5650f15aa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5650f15a9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5650f15a9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5650f15a9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5650f5eb3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5650f5ebc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5650f5ea4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5650f5ecf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa43b86082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5650ef7c9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xa,0x60,0xf3,0xa0,0x80,0xb6,0x58, Step #5: `\012`\363\240\200\266X Step #5: artifact_prefix='./'; Test unit written to ./oom-1f24f45fcf6d394ba36fdf6bc86748c0f311be2d Step #5: Base64: YApg86CAtlg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1065 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2259842253 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5590764f5810, 0x5590766df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5590766df020,0x5590785770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f24f45fcf6d394ba36fdf6bc86748c0f311be2d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1207 processed earlier; will process 9822 files now Step #5: ==38374== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55906cfea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55907364f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5590736325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5590736324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55906cff0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55906cf51b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55906cf4c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55906cfe2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55906ffb1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55906ffb1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55906ffb1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55906ffb1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55906ffb1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55906ffb1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55906ffb1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55906ffb1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55906ffb1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55906ffb1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559072246f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55906ef73b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55906ef7ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55906ed2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55906ed2ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55906ed2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55906ed2a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55906ed2a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55906ed2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559073634abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55907363d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559073625699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559073650112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8c5a373082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55906cf4ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x5c,0x75,0x64,0x37,0x66,0x32,0x22, Step #5: \"\\ud7f2\" Step #5: artifact_prefix='./'; Test unit written to ./oom-b987923e68d85405080e2abc1e439bb8ac1bd8e9 Step #5: Base64: Ilx1ZDdmMiI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1066 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2260285983 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d3dbee5810, 0x55d3dc0cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d3dc0cf020,0x55d3ddf670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b987923e68d85405080e2abc1e439bb8ac1bd8e9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1208 processed earlier; will process 9821 files now Step #5: ==38410== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d3d29da9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d3d903f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d3d90225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d3d90224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d3d29e0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d3d2941b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d3d293c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d3d29d2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d3d59a1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d3d59a1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d3d59a1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d3d59a1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d3d59a1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d3d59a1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d3d59a1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d3d59a1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d3d59a1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d3d59a1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d3d7c36f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d3d4963b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d3d496ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d3d471ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d3d471ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d3d471b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d3d471a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d3d471a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d3d471a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d3d9024abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d3d902d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d3d9015699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d3d9040112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27a5ba7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d3d293ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x3a,0x2f,0x40,0x2f,0x46,0x2f,0x36, Step #5: F:/@/F/6 Step #5: artifact_prefix='./'; Test unit written to ./oom-aec1ea25071bc217928e4e1187988bfd044813d8 Step #5: Base64: RjovQC9GLzY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1067 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2260719626 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e7b04c3810, 0x55e7b06ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e7b06ad020,0x55e7b25450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aec1ea25071bc217928e4e1187988bfd044813d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1209 processed earlier; will process 9820 files now Step #5: ==38446== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e7a6fb89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e7ad61d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7ad6005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7ad6004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e7a6fbed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e7a6f1fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e7a6f1a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e7a6fb0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e7a9f7ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e7a9f7ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e7a9f7ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e7a9f7ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e7a9f7ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e7a9f7ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e7a9f7ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e7a9f7ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e7a9f7ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e7a9f7ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e7ac214f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e7a8f41b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e7a8f4cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e7a8cf8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e7a8cf8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e7a8cf9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e7a8cf8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e7a8cf8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e7a8cf8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e7ad602abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e7ad60b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e7ad5f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e7ad61e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7805745082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e7a6f18b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x4,0xea,0xa5,0xab,0x3a, Step #5: \000\000\000\004\352\245\253: Step #5: artifact_prefix='./'; Test unit written to ./oom-2dd9ca9aee655863726f07b7f4002e86b8f115b9 Step #5: Base64: AAAABOqlqzo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1068 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2261154384 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557727ac6810, 0x557727cb001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557727cb0020,0x557729b480e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2dd9ca9aee655863726f07b7f4002e86b8f115b9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1210 processed earlier; will process 9819 files now Step #5: ==38482== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55771e5bb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557724c20898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557724c035dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557724c034fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55771e5c1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55771e522b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55771e51d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55771e5b3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557721582f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557721582f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557721582f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557721582f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557721582f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557721582f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557721582f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557721582f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557721582f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557721582f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557723817f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557720544b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55772054fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5577202fbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5577202fbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5577202fc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5577202fb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5577202fb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5577202fb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557724c05abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557724c0e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557724bf6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557724c21112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f125f2c6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55771e51bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c, Step #5: ?\\\\\\\\\\\\\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-026707bf8b0a2dc0ccbb6ff3822c918ead30a03e Step #5: Base64: P1xcXFxcXFw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1069 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2261591206 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9ffcb5810, 0x55a9ffe9f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a9ffe9f020,0x55aa01d370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/026707bf8b0a2dc0ccbb6ff3822c918ead30a03e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1211 processed earlier; will process 9818 files now Step #5: ==38518== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a9f67aa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a9fce0f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9fcdf25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9fcdf24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a9f67b0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a9f6711b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a9f670c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a9f67a2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9f9771f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9f9771f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9f9771f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9f9771f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9f9771f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9f9771f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9f9771f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9f9771f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9f9771f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9f9771f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a9fba06f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a9f8733b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a9f873ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a9f84eac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a9f84eac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a9f84eb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a9f84ea874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a9f84ea874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a9f84ea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a9fcdf4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a9fcdfd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a9fcde5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a9fce10112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa31a65e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a9f670ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x8, Step #5: \001\000\000\000\000\000\000\010 Step #5: artifact_prefix='./'; Test unit written to ./oom-970c55f162cce5bdaf93b3990a98bac077cfbd75 Step #5: Base64: AQAAAAAAAAg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1070 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2262027037 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e84471810, 0x555e8465b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e8465b020,0x555e864f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/970c55f162cce5bdaf93b3990a98bac077cfbd75' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1212 processed earlier; will process 9817 files now Step #5: ==38554== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555e7af669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e815cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e815ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e815ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e7af6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e7aecdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e7aec8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e7af5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e7df2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e7df2df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e7df2df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e7df2df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e7df2df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e7df2df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e7df2df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e7df2df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e7df2df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e7df2df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e801c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e7ceefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e7cefabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e7cca6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e7cca6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e7cca7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e7cca6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e7cca6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e7cca6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e815b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e815b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e815a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e815cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8072aa7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e7aec6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0x23,0x34,0xf0,0xa4,0x86,0x8a,0x3c, Step #5: \360\244\206\212< Step #5: artifact_prefix='./'; Test unit written to ./oom-1a35fec3e4915afac4ecd4915c8820a92d22336d Step #5: Base64: JiM08KSGijw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1071 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2262463891 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5578a9f5c810, 0x5578aa14601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5578aa146020,0x5578abfde0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1a35fec3e4915afac4ecd4915c8820a92d22336d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1213 processed earlier; will process 9816 files now Step #5: ==38590== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5578a0a519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5578a70b6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5578a70995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5578a70994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5578a0a57d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5578a09b8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5578a09b3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5578a0a49c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5578a3a18f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5578a3a18f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5578a3a18f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5578a3a18f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5578a3a18f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5578a3a18f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5578a3a18f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5578a3a18f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5578a3a18f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5578a3a18f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5578a5cadf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5578a29dab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5578a29e5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5578a2791c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5578a2791c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5578a2792738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5578a2791874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5578a2791874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5578a2791874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5578a709babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5578a70a4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5578a708c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5578a70b7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f822fe86082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5578a09b1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x66,0xa,0xa,0xa,0x33,0x65,0xd2, Step #5: Pf\012\012\0123e\322 Step #5: artifact_prefix='./'; Test unit written to ./oom-4736414e666457953b7a85a1482aeae0a6c16c03 Step #5: Base64: UGYKCgozZdI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1072 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2262901367 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56070a31b810, 0x56070a50501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56070a505020,0x56070c39d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4736414e666457953b7a85a1482aeae0a6c16c03' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1214 processed earlier; will process 9815 files now Step #5: ==38626== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560700e109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560707475898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5607074585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5607074584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560700e16d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560700d77b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560700d72355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560700e08c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560703dd7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560703dd7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560703dd7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560703dd7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560703dd7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560703dd7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560703dd7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560703dd7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560703dd7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560703dd7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56070606cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560702d99b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560702da4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560702b50c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560702b50c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560702b51738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560702b50874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560702b50874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560702b50874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56070745aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560707463928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56070744b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560707476112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f81b26f0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560700d70b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x5b,0x5b,0x7e,0x74,0x6c,0x6c,0x5d, Step #5: %[[~tll] Step #5: artifact_prefix='./'; Test unit written to ./oom-afd127b4c2de280febf7d6e7e4e8d36186f57ac0 Step #5: Base64: JVtbfnRsbF0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1073 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2263336046 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee7c4d6810, 0x55ee7c6c001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee7c6c0020,0x55ee7e5580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/afd127b4c2de280febf7d6e7e4e8d36186f57ac0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1215 processed earlier; will process 9814 files now Step #5: ==38662== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ee72fcb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee79630898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee796135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee796134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee72fd1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee72f32b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee72f2d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee72fc3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee75f92f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee75f92f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee75f92f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee75f92f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee75f92f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee75f92f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee75f92f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee75f92f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee75f92f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee75f92f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee78227f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee74f54b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee74f5fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee74d0bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee74d0bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee74d0c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee74d0b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee74d0b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee74d0b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee79615abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee7961e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee79606699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee79631112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8add6f2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee72f2bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x4,0xf0,0x91,0xb1,0xb1, Step #5: \000\000\000\004\360\221\261\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-0371709d0fbe1747e7dafcb23de57792f4223f0e Step #5: Base64: AAAABPCRsbE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1074 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2263769849 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d3b54a810, 0x564d3b73401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d3b734020,0x564d3d5cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0371709d0fbe1747e7dafcb23de57792f4223f0e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1216 processed earlier; will process 9813 files now Step #5: ==38698== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564d3203f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d386a4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d386875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d386874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d32045d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d31fa6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d31fa1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d32037c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d35006f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d35006f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d35006f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d35006f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d35006f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d35006f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d35006f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d35006f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d35006f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d35006f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d3729bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d33fc8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d33fd3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d33d7fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d33d7fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d33d80738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d33d7f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d33d7f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d33d7f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d38689abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d38692928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d3867a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d386a5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f32705f4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d31f9fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x52,0x45,0x4d,0x47,0x65,0x6e,0x72,0x65, Step #5: REMGenre Step #5: artifact_prefix='./'; Test unit written to ./oom-4e6a10c3217395fd9848cb7868227fe0a33f2b15 Step #5: Base64: UkVNR2VucmU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1075 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2264203260 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b9e2a16810, 0x55b9e2c0001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b9e2c00020,0x55b9e4a980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e6a10c3217395fd9848cb7868227fe0a33f2b15' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1217 processed earlier; will process 9812 files now Step #5: #1 pulse cov: 3507 ft: 3508 exec/s: 0 rss: 163Mb Step #5: ==38734== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b9d950b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b9dfb70898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b9dfb535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b9dfb534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b9d9511d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b9d9472b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b9d946d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b9d9503c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b9dc4d2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b9dc4d2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b9dc4d2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b9dc4d2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b9dc4d2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b9dc4d2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b9dc4d2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b9dc4d2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b9dc4d2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b9dc4d2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b9de767f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b9db494b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b9db49fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b9db24bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b9db24bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b9db24c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b9db24b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b9db24b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b9db24b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b9dfb55abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b9dfb5e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b9dfb46699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b9dfb71112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa618055082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b9d946bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0x5c,0x75,0xc,0x0,0x0,0x0, Step #5: //\\u\014\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-343d0be8b9446b1eea45385f623a09ffee47f749 Step #5: Base64: Ly9cdQwAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1076 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2264682530 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fdbba91810, 0x55fdbbc7b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fdbbc7b020,0x55fdbdb130e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/343d0be8b9446b1eea45385f623a09ffee47f749' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1219 processed earlier; will process 9810 files now Step #5: ==38770== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fdb25869c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fdb8beb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fdb8bce5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fdb8bce4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fdb258cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fdb24edb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fdb24e8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fdb257ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fdb554df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fdb554df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fdb554df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fdb554df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fdb554df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fdb554df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fdb554df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fdb554df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fdb554df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fdb554df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fdb77e2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fdb450fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fdb451abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fdb42c6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fdb42c6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fdb42c7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fdb42c6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fdb42c6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fdb42c6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fdb8bd0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fdb8bd9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fdb8bc1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fdb8bec112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f32ff420082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fdb24e6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2,0x60,0x28,0x3,0x2,0x60,0x6b, Step #5: \000\002`(\003\002`k Step #5: artifact_prefix='./'; Test unit written to ./oom-4154d35afe04a7b49ba8f44fffe30e028fc028f8 Step #5: Base64: AAJgKAMCYGs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1077 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2265243017 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55676021e810, 0x55676040801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556760408020,0x5567622a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4154d35afe04a7b49ba8f44fffe30e028fc028f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1220 processed earlier; will process 9809 files now Step #5: #1 pulse cov: 3541 ft: 3542 exec/s: 0 rss: 165Mb Step #5: ==38806== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556756d139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55675d378898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55675d35b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55675d35b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556756d19d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556756c7ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556756c75355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556756d0bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556759cdaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556759cdaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556759cdaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556759cdaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556759cdaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556759cdaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556759cdaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556759cdaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556759cdaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556759cdaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55675bf6ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556758c9cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556758ca7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556758a53c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556758a53c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556758a54738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556758a53874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556758a53874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556758a53874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55675d35dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55675d366928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55675d34e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55675d379112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fafb7014082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556756c73b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x4,0xf0,0x91,0x97,0x9d, Step #5: \000\000\000\004\360\221\227\235 Step #5: artifact_prefix='./'; Test unit written to ./oom-6dc9946c25080b0d3c697d662686396bf157a0d7 Step #5: Base64: AAAABPCRl50= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1078 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2265717983 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564185e34810, 0x56418601e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56418601e020,0x564187eb60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6dc9946c25080b0d3c697d662686396bf157a0d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1222 processed earlier; will process 9807 files now Step #5: ==38842== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56417c9299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564182f8e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564182f715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564182f714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56417c92fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56417c890b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56417c88b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56417c921c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56417f8f0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56417f8f0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56417f8f0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56417f8f0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56417f8f0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56417f8f0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56417f8f0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56417f8f0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56417f8f0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56417f8f0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564181b85f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56417e8b2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56417e8bdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56417e669c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56417e669c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56417e66a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56417e669874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56417e669874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56417e669874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564182f73abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564182f7c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564182f64699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564182f8f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5038592082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56417c889b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x58,0x58,0x58,0x2e,0x2e,0x69,0x46,0x30, Step #5: XXX..iF0 Step #5: artifact_prefix='./'; Test unit written to ./oom-611f4213bca1005f3890a1c1baeae8ab5fd654b9 Step #5: Base64: WFhYLi5pRjA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1079 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2266153816 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9ef715810, 0x55e9ef8ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9ef8ff020,0x55e9f17970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/611f4213bca1005f3890a1c1baeae8ab5fd654b9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1223 processed earlier; will process 9806 files now Step #5: #1 pulse cov: 6540 ft: 6541 exec/s: 0 rss: 175Mb Step #5: ==38878== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e9e620a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9ec86f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9ec8525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9ec8524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9e6210d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e9e6171b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e9e616c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9e6202c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e9e91d1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e9e91d1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e9e91d1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e9e91d1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e9e91d1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e9e91d1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e9e91d1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e9e91d1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e9e91d1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e9e91d1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9eb466f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e9e8193b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e9e819ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9e7f4ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9e7f4ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9e7f4b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9e7f4a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9e7f4a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9e7f4a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e9ec854abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9ec85d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e9ec845699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e9ec870112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf8a334082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e9e616ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x20,0x0,0x0,0x0,0x20,0x30,0x24, Step #5: $ \000\000\000 0$ Step #5: artifact_prefix='./'; Test unit written to ./oom-5a037fc3943f2d77393c74c12d882ccd5938ef00 Step #5: Base64: JCAAAAAgMCQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1080 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2266641304 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56024e847810, 0x56024ea3101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56024ea31020,0x5602508c90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5a037fc3943f2d77393c74c12d882ccd5938ef00' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1225 processed earlier; will process 9804 files now Step #5: #1 pulse cov: 3420 ft: 3421 exec/s: 0 rss: 164Mb Step #5: ==38914== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56024533c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56024b9a1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56024b9845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56024b9844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560245342d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5602452a3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56024529e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560245334c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560248303f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560248303f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560248303f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560248303f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560248303f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560248303f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560248303f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560248303f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560248303f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560248303f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56024a598f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5602472c5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5602472d0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56024707cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56024707cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56024707d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56024707c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56024707c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56024707c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56024b986abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56024b98f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56024b977699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56024b9a2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5deff7a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56024529cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x20,0x30,0x5b,0x0,0x0,0x20,0x24, Step #5: $ 0[\000\000 $ Step #5: artifact_prefix='./'; Test unit written to ./oom-80e22252ace8ae9c611ff3f7e7ed101238f74254 Step #5: Base64: JCAwWwAAICQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1081 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2267119628 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5649c426e810, 0x5649c445801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5649c4458020,0x5649c62f00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/80e22252ace8ae9c611ff3f7e7ed101238f74254' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1227 processed earlier; will process 9802 files now Step #5: ==38950== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5649bad639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5649c13c8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5649c13ab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5649c13ab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5649bad69d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649baccab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649bacc5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5649bad5bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5649bdd2af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5649bdd2af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5649bdd2af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5649bdd2af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5649bdd2af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5649bdd2af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5649bdd2af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5649bdd2af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5649bdd2af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5649bdd2af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5649bffbff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649bccecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649bccf7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5649bcaa3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5649bcaa3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5649bcaa4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5649bcaa3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5649bcaa3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5649bcaa3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5649c13adabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5649c13b6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5649c139e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5649c13c9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9559304082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649bacc3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x57,0x73,0x3a,0xc8,0xb0,0xcc,0xb8, Step #5: \016Ws:\310\260\314\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-97c1662ac56ab15cb757b629dc10ba43621e5619 Step #5: Base64: DldzOsiwzLg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1082 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2267560570 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5595d4759810, 0x5595d494301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5595d4943020,0x5595d67db0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/97c1662ac56ab15cb757b629dc10ba43621e5619' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1228 processed earlier; will process 9801 files now Step #5: ==38986== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5595cb24e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5595d18b3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5595d18965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5595d18964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5595cb254d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5595cb1b5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5595cb1b0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5595cb246c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5595ce215f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5595ce215f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5595ce215f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5595ce215f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5595ce215f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5595ce215f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5595ce215f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5595ce215f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5595ce215f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5595ce215f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5595d04aaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5595cd1d7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5595cd1e2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5595ccf8ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5595ccf8ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5595ccf8f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5595ccf8e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5595ccf8e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5595ccf8e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5595d1898abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5595d18a1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5595d1889699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5595d18b4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc10cf1e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5595cb1aeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x59,0x7f,0x7f,0x0,0xe,0x27,0x24, Step #5: $Y\177\177\000\016'$ Step #5: artifact_prefix='./'; Test unit written to ./oom-098edb04d6739c062ecbb39e383872f90a28e61e Step #5: Base64: JFl/fwAOJyQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1083 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2268004101 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556db0ccb810, 0x556db0eb501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556db0eb5020,0x556db2d4d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/098edb04d6739c062ecbb39e383872f90a28e61e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1229 processed earlier; will process 9800 files now Step #5: ==39022== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556da77c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556dade25898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556dade085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556dade084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556da77c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556da7727b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556da7722355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556da77b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556daa787f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556daa787f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556daa787f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556daa787f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556daa787f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556daa787f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556daa787f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556daa787f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556daa787f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556daa787f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556daca1cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556da9749b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556da9754be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556da9500c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556da9500c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556da9501738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556da9500874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556da9500874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556da9500874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556dade0aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556dade13928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556daddfb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556dade26112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe7feee8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556da7720b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0x6c,0x63,0x4f,0x4d,0x4d,0x20,0x4c, Step #5: .lcOMM L Step #5: artifact_prefix='./'; Test unit written to ./oom-c05dc745672d33a0a2224a2dddb4e82b7420783f Step #5: Base64: LmxjT01NIEw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1084 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2268442470 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5632ce935810, 0x5632ceb1f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5632ceb1f020,0x5632d09b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c05dc745672d33a0a2224a2dddb4e82b7420783f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1230 processed earlier; will process 9799 files now Step #5: ==39058== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5632c542a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5632cba8f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5632cba725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5632cba724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5632c5430d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5632c5391b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5632c538c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5632c5422c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5632c83f1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5632c83f1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5632c83f1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5632c83f1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5632c83f1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5632c83f1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5632c83f1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5632c83f1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5632c83f1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5632c83f1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5632ca686f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5632c73b3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5632c73bebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5632c716ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5632c716ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5632c716b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5632c716a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5632c716a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5632c716a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5632cba74abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5632cba7d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5632cba65699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5632cba90112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f8318b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5632c538ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0xa,0x20,0x3,0xf3,0xff,0x1, Step #5: $$\012 \003\363\377\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-246b95f7ed04830c6d085453306f0cd11091f554 Step #5: Base64: JCQKIAPz/wE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1085 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2268888983 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fbf68c8810, 0x55fbf6ab201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fbf6ab2020,0x55fbf894a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/246b95f7ed04830c6d085453306f0cd11091f554' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1231 processed earlier; will process 9798 files now Step #5: ==39094== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fbed3bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fbf3a22898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fbf3a055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fbf3a054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fbed3c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fbed324b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fbed31f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fbed3b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fbf0384f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fbf0384f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fbf0384f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fbf0384f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fbf0384f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fbf0384f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fbf0384f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fbf0384f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fbf0384f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fbf0384f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fbf2619f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fbef346b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fbef351be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fbef0fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fbef0fdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fbef0fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fbef0fd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fbef0fd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fbef0fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fbf3a07abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fbf3a10928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fbf39f8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fbf3a23112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3db9906082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fbed31db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x59,0x7f,0x53,0x0,0xe,0x27,0x24, Step #5: $Y\177S\000\016'$ Step #5: artifact_prefix='./'; Test unit written to ./oom-14ff69121d72b125af3da4c83dcb54a84a0e1959 Step #5: Base64: JFl/UwAOJyQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1086 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2269331049 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5642733da810, 0x5642735c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5642735c4020,0x56427545c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/14ff69121d72b125af3da4c83dcb54a84a0e1959' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1232 processed earlier; will process 9797 files now Step #5: ==39130== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564269ecf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564270534898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5642705175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5642705174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564269ed5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564269e36b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564269e31355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564269ec7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56426ce96f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56426ce96f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56426ce96f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56426ce96f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56426ce96f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56426ce96f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56426ce96f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56426ce96f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56426ce96f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56426ce96f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56426f12bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56426be58b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56426be63be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56426bc0fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56426bc0fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56426bc10738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56426bc0f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56426bc0f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56426bc0f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564270519abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564270522928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56427050a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564270535112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe5ea437082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564269e2fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x3a,0x2f,0x2f,0xf4,0x88,0xa9,0xbe, Step #5: f://\364\210\251\276 Step #5: artifact_prefix='./'; Test unit written to ./oom-388ec629d162df8c264c005f48294542db621554 Step #5: Base64: ZjovL/SIqb4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1087 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2269771532 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d5fb4e810, 0x557d5fd3801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d5fd38020,0x557d61bd00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/388ec629d162df8c264c005f48294542db621554' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1233 processed earlier; will process 9796 files now Step #5: ==39166== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557d566439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557d5cca8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557d5cc8b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557d5cc8b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557d56649d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557d565aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557d565a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557d5663bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557d5960af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557d5960af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557d5960af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557d5960af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557d5960af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557d5960af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557d5960af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557d5960af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557d5960af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557d5960af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557d5b89ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557d585ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557d585d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557d58383c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557d58383c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557d58384738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557d58383874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557d58383874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557d58383874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557d5cc8dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557d5cc96928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557d5cc7e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557d5cca9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f69c5724082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557d565a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbb,0x3e, Step #5: <\315\274><\315\273> Step #5: artifact_prefix='./'; Test unit written to ./oom-8450fbd904d021a90d454729c00c31db19adb53d Step #5: Base64: PM28PjzNuz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1088 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2270201029 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5624698af810, 0x562469a9901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562469a99020,0x56246b9310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8450fbd904d021a90d454729c00c31db19adb53d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1234 processed earlier; will process 9795 files now Step #5: ==39202== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5624603a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562466a09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5624669ec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5624669ec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5624603aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56246030bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562460306355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56246039cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56246336bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56246336bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56246336bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56246336bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56246336bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56246336bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56246336bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56246336bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56246336bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56246336bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562465600f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56246232db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562462338be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5624620e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5624620e4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5624620e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5624620e4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5624620e4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5624620e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5624669eeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5624669f7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5624669df699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562466a0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1203356082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562460304b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x4f,0x46,0x46,0x0,0x1,0x0,0x0, Step #5: wOFF\000\001\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e233dcf39f11c147ebb8239c463c633b35acdc02 Step #5: Base64: d09GRgABAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1089 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2270643418 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555dacc58810, 0x555dace4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555dace42020,0x555daecda0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e233dcf39f11c147ebb8239c463c633b35acdc02' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1235 processed earlier; will process 9794 files now Step #5: ==39238== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555da374d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555da9db2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555da9d955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555da9d954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555da3753d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555da36b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555da36af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555da3745c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555da6714f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555da6714f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555da6714f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555da6714f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555da6714f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555da6714f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555da6714f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555da6714f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555da6714f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555da6714f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555da89a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555da56d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555da56e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555da548dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555da548dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555da548e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555da548d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555da548d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555da548d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555da9d97abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555da9da0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555da9d88699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555da9db3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f61e321b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555da36adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x5b,0x0,0xb1,0xff,0x1c,0xdb,0xff, Step #5: F[\000\261\377\034\333\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-781087f1cdc04c721b6e7063d097a4a5b7a7146a Step #5: Base64: RlsAsf8c2/8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1090 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2271082010 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c6a679810, 0x559c6a86301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c6a863020,0x559c6c6fb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/781087f1cdc04c721b6e7063d097a4a5b7a7146a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1236 processed earlier; will process 9793 files now Step #5: ==39274== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559c6116e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c677d3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c677b65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c677b64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c61174d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c610d5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c610d0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c61166c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c64135f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c64135f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c64135f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c64135f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c64135f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c64135f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c64135f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c64135f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c64135f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c64135f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c663caf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c630f7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c63102be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c62eaec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c62eaec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c62eaf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c62eae874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c62eae874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c62eae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c677b8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c677c1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c677a9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c677d4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8e01e4f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c610ceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x73,0x3a,0x27,0xe1,0x80,0xb9, Step #5: \016ws:'\341\200\271 Step #5: artifact_prefix='./'; Test unit written to ./oom-189f9b77775d272e01aee361f0310d399cf2fa4c Step #5: Base64: DndzOifhgLk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1091 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2271521420 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562a424e9810, 0x562a426d301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562a426d3020,0x562a4456b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/189f9b77775d272e01aee361f0310d399cf2fa4c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1237 processed earlier; will process 9792 files now Step #5: ==39310== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562a38fde9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562a3f643898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562a3f6265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562a3f6264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562a38fe4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562a38f45b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562a38f40355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562a38fd6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562a3bfa5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562a3bfa5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562a3bfa5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562a3bfa5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562a3bfa5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562a3bfa5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562a3bfa5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562a3bfa5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562a3bfa5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562a3bfa5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562a3e23af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562a3af67b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562a3af72be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562a3ad1ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562a3ad1ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562a3ad1f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562a3ad1e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562a3ad1e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562a3ad1e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562a3f628abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562a3f631928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562a3f619699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562a3f644112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efce371c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562a38f3eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9d,0x85,0xa0,0xf0,0x91,0x93,0x83, Step #5: \360\235\205\240\360\221\223\203 Step #5: artifact_prefix='./'; Test unit written to ./oom-2c1fd730e325996de4984940afe12c66624d33d7 Step #5: Base64: 8J2FoPCRk4M= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1092 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2271960488 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c137dd5810, 0x55c137fbf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c137fbf020,0x55c139e570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2c1fd730e325996de4984940afe12c66624d33d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1238 processed earlier; will process 9791 files now Step #5: ==39346== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c12e8ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c134f2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c134f125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c134f124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c12e8d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c12e831b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c12e82c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c12e8c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c131891f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c131891f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c131891f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c131891f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c131891f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c131891f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c131891f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c131891f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c131891f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c131891f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c133b26f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c130853b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c13085ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c13060ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c13060ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c13060b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c13060a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c13060a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c13060a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c134f14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c134f1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c134f05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c134f30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc0d231a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c12e82ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa8,0xba,0xd,0x69,0x6e,0xd,0xf3, Step #5: \341\250\272\015in\015\363 Step #5: artifact_prefix='./'; Test unit written to ./oom-aad4e0e72869494e21501281ca2b0e8f0a480bda Step #5: Base64: 4ai6DWluDfM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1093 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2272401962 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564048303810, 0x5640484ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640484ed020,0x56404a3850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aad4e0e72869494e21501281ca2b0e8f0a480bda' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1239 processed earlier; will process 9790 files now Step #5: #1 pulse cov: 3594 ft: 3595 exec/s: 0 rss: 165Mb Step #5: ==39382== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56403edf89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56404545d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640454405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640454404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56403edfed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56403ed5fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56403ed5a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56403edf0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564041dbff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564041dbff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564041dbff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564041dbff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564041dbff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564041dbff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564041dbff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564041dbff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564041dbff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564041dbff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564044054f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564040d81b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564040d8cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564040b38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564040b38c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564040b39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564040b38874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564040b38874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564040b38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564045442abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56404544b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564045433699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56404545e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b48219082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56403ed58b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcc,0x9a,0xcc,0x9f,0xd6,0xb7,0xcc,0xb8, Step #5: \314\232\314\237\326\267\314\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-6d1db84008fc39d374027e044a3a392bff6cc384 Step #5: Base64: zJrMn9a3zLg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1094 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2272881633 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f449502810, 0x55f4496ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f4496ec020,0x55f44b5840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6d1db84008fc39d374027e044a3a392bff6cc384' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1241 processed earlier; will process 9788 files now Step #5: ==39418== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f43fff79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f44665c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f44663f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f44663f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f43fffdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f43ff5eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f43ff59355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f43ffefc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f442fbef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f442fbef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f442fbef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f442fbef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f442fbef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f442fbef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f442fbef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f442fbef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f442fbef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f442fbef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f445253f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f441f80b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f441f8bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f441d37c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f441d37c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f441d38738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f441d37874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f441d37874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f441d37874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f446641abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f44664a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f446632699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f44665d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f280aca5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f43ff57b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0x5b,0xe1,0x92,0xbc, Step #5: (?i)[\341\222\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-08709b0e19cc0d1de9a34169f31c28b12ad08c9b Step #5: Base64: KD9pKVvhkrw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1095 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2273322995 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557e8d8af810, 0x557e8da9901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557e8da99020,0x557e8f9310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08709b0e19cc0d1de9a34169f31c28b12ad08c9b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1242 processed earlier; will process 9787 files now Step #5: #1 pulse cov: 3531 ft: 3532 exec/s: 0 rss: 164Mb Step #5: ==39454== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557e843a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557e8aa09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557e8a9ec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557e8a9ec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557e843aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557e8430bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557e84306355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557e8439cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557e8736bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557e8736bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557e8736bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557e8736bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557e8736bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557e8736bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557e8736bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557e8736bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557e8736bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557e8736bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557e89600f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557e8632db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557e86338be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557e860e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557e860e4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557e860e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557e860e4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557e860e4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557e860e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557e8a9eeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557e8a9f7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557e8a9df699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557e8aa0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb7f945082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557e84304b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf4,0x8f,0xbf,0xbd,0xf4,0x8f,0xb5,0xbd, Step #5: \364\217\277\275\364\217\265\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-9bc5fc5795cfe9dea5e6a81d36e3a146f16724ea Step #5: Base64: 9I+/vfSPtb0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1096 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2273803362 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563be66ed810, 0x563be68d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563be68d7020,0x563be876f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9bc5fc5795cfe9dea5e6a81d36e3a146f16724ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1244 processed earlier; will process 9785 files now Step #5: ==39490== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563bdd1e29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563be3847898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563be382a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563be382a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563bdd1e8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563bdd149b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563bdd144355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563bdd1dac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563be01a9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563be01a9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563be01a9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563be01a9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563be01a9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563be01a9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563be01a9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563be01a9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563be01a9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563be01a9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563be243ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563bdf16bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563bdf176be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563bdef22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563bdef22c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563bdef23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563bdef22874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563bdef22874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563bdef22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563be382cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563be3835928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563be381d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563be3848112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1f4ce0e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563bdd142b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7a,0x7b,0x22,0xb,0x2d,0x2e,0x30,0x2e, Step #5: z{\"\013-.0. Step #5: artifact_prefix='./'; Test unit written to ./oom-7714b59d11ecfdcb718e3e60290034d645297f02 Step #5: Base64: ensiCy0uMC4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1097 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2274240800 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3cb17f810, 0x55a3cb36901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3cb369020,0x55a3cd2010e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7714b59d11ecfdcb718e3e60290034d645297f02' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1245 processed earlier; will process 9784 files now Step #5: ==39526== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a3c1c749c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3c82d9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3c82bc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3c82bc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3c1c7ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a3c1bdbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a3c1bd6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3c1c6cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a3c4c3bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a3c4c3bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a3c4c3bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a3c4c3bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a3c4c3bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a3c4c3bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a3c4c3bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a3c4c3bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a3c4c3bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a3c4c3bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3c6ed0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3c3bfdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3c3c08be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3c39b4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3c39b4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3c39b5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3c39b4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3c39b4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3c39b4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a3c82beabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a3c82c7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3c82af699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3c82da112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a580ba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a3c1bd4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x64,0x41,0x42,0x69,0x68,0x67,0x77, Step #5: pdABihgw Step #5: artifact_prefix='./'; Test unit written to ./oom-5f228ab37850e111beed784e2577f42ae4090c4b Step #5: Base64: cGRBQmloZ3c= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1098 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2274680374 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e57d28810, 0x562e57f1201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e57f12020,0x562e59daa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f228ab37850e111beed784e2577f42ae4090c4b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1246 processed earlier; will process 9783 files now Step #5: ==39562== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562e4e81d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e54e82898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e54e655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e54e654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e4e823d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e4e784b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e4e77f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e4e815c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e517e4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e517e4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e517e4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e517e4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e517e4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e517e4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e517e4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e517e4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e517e4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e517e4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e53a79f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e507a6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e507b1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e5055dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e5055dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e5055e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e5055d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e5055d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e5055d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e54e67abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e54e70928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e54e58699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e54e83112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdd30e1c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e4e77db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x28,0x0,0x1d,0x79,0x0,0x0,0x0, Step #5: \005(\000\035y\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c4565630280169dbbee72fbc0b1582e258daa7d5 Step #5: Base64: BSgAHXkAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1099 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2275119411 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557692f63810, 0x55769314d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55769314d020,0x557694fe50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c4565630280169dbbee72fbc0b1582e258daa7d5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1247 processed earlier; will process 9782 files now Step #5: ==39598== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557689a589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5576900bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5576900a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5576900a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557689a5ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5576899bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5576899ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557689a50c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55768ca1ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55768ca1ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55768ca1ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55768ca1ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55768ca1ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55768ca1ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55768ca1ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55768ca1ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55768ca1ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55768ca1ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55768ecb4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55768b9e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55768b9ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55768b798c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55768b798c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55768b799738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55768b798874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55768b798874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55768b798874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5576900a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5576900ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557690093699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5576900be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0e9e99f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5576899b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x28,0x2d,0x2d,0x42,0x47, Step #5: s--(--BG Step #5: artifact_prefix='./'; Test unit written to ./oom-b69df6201a12f123648c3334eebae1dc7a6e1ca8 Step #5: Base64: cy0tKC0tQkc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1100 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2275554558 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55942ef0c810, 0x55942f0f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55942f0f6020,0x559430f8e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b69df6201a12f123648c3334eebae1dc7a6e1ca8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1248 processed earlier; will process 9781 files now Step #5: ==39634== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559425a019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55942c066898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55942c0495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55942c0494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559425a07d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559425968b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559425963355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5594259f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5594289c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5594289c8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5594289c8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5594289c8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5594289c8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5594289c8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5594289c8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5594289c8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5594289c8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5594289c8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55942ac5df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55942798ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559427995be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559427741c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559427741c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559427742738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559427741874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559427741874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559427741874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55942c04babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55942c054928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55942c03c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55942c067112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f622bd15082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559425961b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x74,0x63,0x66,0xff,0x0,0x0,0x0, Step #5: ttcf\377\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4079042cbc93b11b606ca0bde086f3ae276864b0 Step #5: Base64: dHRjZv8AAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1101 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2275993137 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5616d20a6810, 0x5616d229001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5616d2290020,0x5616d41280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4079042cbc93b11b606ca0bde086f3ae276864b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1249 processed earlier; will process 9780 files now Step #5: ==39670== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5616c8b9b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5616cf200898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5616cf1e35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5616cf1e34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5616c8ba1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5616c8b02b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5616c8afd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5616c8b93c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5616cbb62f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5616cbb62f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5616cbb62f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5616cbb62f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5616cbb62f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5616cbb62f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5616cbb62f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5616cbb62f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5616cbb62f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5616cbb62f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5616cddf7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5616cab24b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5616cab2fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5616ca8dbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5616ca8dbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5616ca8dc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5616ca8db874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5616ca8db874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5616ca8db874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5616cf1e5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5616cf1ee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5616cf1d6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5616cf201112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e49e4f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5616c8afbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x68,0xa,0x31,0x20,0x39,0xa,0x31, Step #5: Ph\0121 9\0121 Step #5: artifact_prefix='./'; Test unit written to ./oom-ff5ebcb59429a2e3fb270ee7b7ed45f60d6ea0c6 Step #5: Base64: UGgKMSA5CjE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1102 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2276430083 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b6c44fe810, 0x55b6c46e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b6c46e8020,0x55b6c65800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ff5ebcb59429a2e3fb270ee7b7ed45f60d6ea0c6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1250 processed earlier; will process 9779 files now Step #5: ==39706== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b6baff39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b6c1658898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b6c163b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b6c163b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6baff9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6baf5ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6baf55355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6bafebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b6bdfbaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b6bdfbaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b6bdfbaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b6bdfbaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b6bdfbaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b6bdfbaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b6bdfbaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b6bdfbaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b6bdfbaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b6bdfbaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b6c024ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6bcf7cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6bcf87be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6bcd33c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6bcd33c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6bcd34738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6bcd33874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6bcd33874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6bcd33874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b6c163dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b6c1646928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b6c162e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b6c1659112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc67d781082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6baf53b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x34,0x37,0x33,0x33,0x2e,0xc6,0x25, Step #5: 04733.\306% Step #5: artifact_prefix='./'; Test unit written to ./oom-5df52d30c58e1cf97811a65b8fef5a511806398c Step #5: Base64: MDQ3MzMuxiU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1103 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2276869211 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b73789810, 0x560b7397301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b73973020,0x560b7580b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5df52d30c58e1cf97811a65b8fef5a511806398c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1251 processed earlier; will process 9778 files now Step #5: ==39742== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560b6a27e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b708e3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b708c65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b708c64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b6a284d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b6a1e5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b6a1e0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b6a276c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b6d245f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b6d245f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b6d245f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b6d245f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b6d245f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b6d245f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b6d245f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b6d245f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b6d245f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b6d245f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b6f4daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b6c207b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b6c212be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b6bfbec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b6bfbec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b6bfbf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b6bfbe874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b6bfbe874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b6bfbe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b708c8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b708d1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b708b9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b708e4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f97dd8d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b6a1deb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0x65,0x3f,0x6e,0x3f,0x65,0x3f,0x6e, Step #5: ?e?n?e?n Step #5: artifact_prefix='./'; Test unit written to ./oom-24d668ac38e46b20a63074eaf823e79127bf9369 Step #5: Base64: P2U/bj9lP24= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1104 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2277307302 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b0ce9c810, 0x558b0d08601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b0d086020,0x558b0ef1e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/24d668ac38e46b20a63074eaf823e79127bf9369' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1252 processed earlier; will process 9777 files now Step #5: ==39778== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558b039919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b09ff6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b09fd95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b09fd94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b03997d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b038f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b038f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b03989c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b06958f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b06958f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b06958f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b06958f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b06958f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b06958f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b06958f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b06958f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b06958f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b06958f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b08bedf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b0591ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b05925be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b056d1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b056d1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b056d2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b056d1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b056d1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b056d1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b09fdbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b09fe4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b09fcc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b09ff7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcffeb9e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b038f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x3,0x2b,0x3,0x2b,0x44,0xfc,0x44, Step #5: \003\003+\003+D\374D Step #5: artifact_prefix='./'; Test unit written to ./oom-77fdd07c4016ed28936ca381bf639f3a5b1d2289 Step #5: Base64: AwMrAytE/EQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1105 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2277740316 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dadae8a810, 0x55dadb07401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dadb074020,0x55dadcf0c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/77fdd07c4016ed28936ca381bf639f3a5b1d2289' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1253 processed earlier; will process 9776 files now Step #5: ==39814== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dad197f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dad7fe4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dad7fc75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dad7fc74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dad1985d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dad18e6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dad18e1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dad1977c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dad4946f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dad4946f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dad4946f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dad4946f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dad4946f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dad4946f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dad4946f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dad4946f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dad4946f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dad4946f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dad6bdbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dad3908b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dad3913be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dad36bfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dad36bfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dad36c0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dad36bf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dad36bf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dad36bf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dad7fc9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dad7fd2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dad7fba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dad7fe5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf090b0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dad18dfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9d,0x85,0xa5,0xcc,0xa1,0xcc,0xb8, Step #5: \360\235\205\245\314\241\314\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-2e907d20a266dd523575f7bf52cf1a22d49b98e1 Step #5: Base64: 8J2FpcyhzLg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1106 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2278179762 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558fc9c6b810, 0x558fc9e5501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558fc9e55020,0x558fcbced0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2e907d20a266dd523575f7bf52cf1a22d49b98e1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1254 processed earlier; will process 9775 files now Step #5: ==39850== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558fc07609c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558fc6dc5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558fc6da85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558fc6da84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558fc0766d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558fc06c7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558fc06c2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558fc0758c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558fc3727f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558fc3727f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558fc3727f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558fc3727f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558fc3727f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558fc3727f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558fc3727f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558fc3727f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558fc3727f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558fc3727f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558fc59bcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558fc26e9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558fc26f4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558fc24a0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558fc24a0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558fc24a1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558fc24a0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558fc24a0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558fc24a0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558fc6daaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558fc6db3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558fc6d9b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558fc6dc6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f143b71f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558fc06c0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x0,0x9,0x0,0x9,0x3,0x9,0x80, Step #5: \002\000\011\000\011\003\011\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-aeea04c6c9129baf72315b8d4ecbac555caeb467 Step #5: Base64: AgAJAAkDCYA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1107 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2278616046 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f3f39c3810, 0x55f3f3bad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f3f3bad020,0x55f3f5a450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aeea04c6c9129baf72315b8d4ecbac555caeb467' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1255 processed earlier; will process 9774 files now Step #5: ==39886== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f3ea4b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f3f0b1d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f3f0b005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f3f0b004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f3ea4bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f3ea41fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f3ea41a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f3ea4b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f3ed47ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f3ed47ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f3ed47ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f3ed47ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f3ed47ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f3ed47ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f3ed47ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f3ed47ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f3ed47ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f3ed47ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f3ef714f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f3ec441b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f3ec44cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f3ec1f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f3ec1f8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f3ec1f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f3ec1f8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f3ec1f8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f3ec1f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f3f0b02abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f3f0b0b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f3f0af3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f3f0b1e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c538a7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f3ea418b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x74,0x72,0x65,0x61,0x6d,0x69,0x69, Step #5: streamii Step #5: artifact_prefix='./'; Test unit written to ./oom-e192c2e2ab838cdb1d5230c2485fe3158436fd66 Step #5: Base64: c3RyZWFtaWk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1108 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2279054694 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b7471d810, 0x556b7490701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b74907020,0x556b7679f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e192c2e2ab838cdb1d5230c2485fe3158436fd66' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1256 processed earlier; will process 9773 files now Step #5: ==39922== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556b6b2129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b71877898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b7185a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b7185a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b6b218d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b6b179b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b6b174355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b6b20ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b6e1d9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b6e1d9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b6e1d9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b6e1d9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b6e1d9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b6e1d9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b6e1d9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b6e1d9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b6e1d9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b6e1d9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b7046ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b6d19bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b6d1a6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b6cf52c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b6cf52c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b6cf53738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b6cf52874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b6cf52874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b6cf52874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b7185cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b71865928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b7184d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b71878112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e89581082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b6b172b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x2d,0x3d,0x3d,0x7e,0x2d,0x24, Step #5: ~$-==~-$ Step #5: artifact_prefix='./'; Test unit written to ./oom-ff53e6f5db39a86e6fa8ff650bf67a7e8351672b Step #5: Base64: fiQtPT1+LSQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1109 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2279495575 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56517a3bd810, 0x56517a5a701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56517a5a7020,0x56517c43f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ff53e6f5db39a86e6fa8ff650bf67a7e8351672b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1257 processed earlier; will process 9772 files now Step #5: ==39958== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x565170eb29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565177517898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651774fa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651774fa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565170eb8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565170e19b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565170e14355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565170eaac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565173e79f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565173e79f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565173e79f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565173e79f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565173e79f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565173e79f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565173e79f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565173e79f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565173e79f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565173e79f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56517610ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565172e3bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565172e46be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565172bf2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565172bf2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565172bf3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565172bf2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565172bf2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565172bf2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5651774fcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565177505928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5651774ed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565177518112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68387ed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565170e12b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24, Step #5: $$$$$$$$ Step #5: artifact_prefix='./'; Test unit written to ./oom-b8c435e13f9248ad695f0901d6dc3f46b71c9d9b Step #5: Base64: JCQkJCQkJCQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1110 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2279938162 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aaafcf4810, 0x55aaafede01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aaafede020,0x55aab1d760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b8c435e13f9248ad695f0901d6dc3f46b71c9d9b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1258 processed earlier; will process 9771 files now Step #5: ==39994== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55aaa67e99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aaace4e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aaace315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aaace314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aaa67efd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aaa6750b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aaa674b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aaa67e1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aaa97b0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aaa97b0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aaa97b0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aaa97b0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aaa97b0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aaa97b0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aaa97b0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aaa97b0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aaa97b0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aaa97b0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aaaba45f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aaa8772b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aaa877dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aaa8529c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aaa8529c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aaa852a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aaa8529874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aaa8529874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aaa8529874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aaace33abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aaace3c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aaace24699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aaace4f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcec9940082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aaa6749b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x29, Step #5: ^(?:$|$) Step #5: artifact_prefix='./'; Test unit written to ./oom-e92a0c092b41be291fd2e66eda8bfd6889716c3c Step #5: Base64: Xig/OiR8JCk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1111 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2280378473 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558ef20d1810, 0x558ef22bb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558ef22bb020,0x558ef41530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e92a0c092b41be291fd2e66eda8bfd6889716c3c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1259 processed earlier; will process 9770 files now Step #5: ==40030== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558ee8bc69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558eef22b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558eef20e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558eef20e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558ee8bccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558ee8b2db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558ee8b28355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558ee8bbec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558eebb8df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558eebb8df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558eebb8df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558eebb8df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558eebb8df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558eebb8df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558eebb8df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558eebb8df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558eebb8df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558eebb8df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558eede22f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558eeab4fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558eeab5abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558eea906c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558eea906c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558eea907738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558eea906874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558eea906874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558eea906874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558eef210abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558eef219928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558eef201699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558eef22c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f28db0b9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558ee8b26b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0x24,0x6e,0x0,0x24,0x6f,0x0,0x0, Step #5: :$n\000$o\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c61611c68cc5b3790a74ee9293428de87596a314 Step #5: Base64: OiRuACRvAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1112 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2280822507 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556e18da4810, 0x556e18f8e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556e18f8e020,0x556e1ae260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c61611c68cc5b3790a74ee9293428de87596a314' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1260 processed earlier; will process 9769 files now Step #5: ==40066== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556e0f8999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556e15efe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556e15ee15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556e15ee14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556e0f89fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556e0f800b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556e0f7fb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556e0f891c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556e12860f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556e12860f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556e12860f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556e12860f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556e12860f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556e12860f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556e12860f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556e12860f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556e12860f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556e12860f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556e14af5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556e11822b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556e1182dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556e115d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556e115d9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556e115da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556e115d9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556e115d9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556e115d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556e15ee3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556e15eec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556e15ed4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556e15eff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a77df9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556e0f7f9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x81,0x90,0xe3,0x81,0xa4,0x30,0x30, Step #5: \343\201\220\343\201\24400 Step #5: artifact_prefix='./'; Test unit written to ./oom-d740314b35ac9edf328b700eb8ffc90b6dc7182a Step #5: Base64: 44GQ44GkMDA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1113 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2281261202 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56463609c810, 0x56463628601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564636286020,0x56463811e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d740314b35ac9edf328b700eb8ffc90b6dc7182a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1261 processed earlier; will process 9768 files now Step #5: ==40102== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56462cb919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5646331f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5646331d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5646331d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56462cb97d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56462caf8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56462caf3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56462cb89c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56462fb58f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56462fb58f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56462fb58f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56462fb58f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56462fb58f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56462fb58f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56462fb58f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56462fb58f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56462fb58f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56462fb58f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564631dedf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56462eb1ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56462eb25be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56462e8d1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56462e8d1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56462e8d2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56462e8d1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56462e8d1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56462e8d1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5646331dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5646331e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5646331cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5646331f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53436fb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56462caf1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x1,0x0,0xd6,0x83,0xda,0x83, Step #5: \000\000\001\000\326\203\332\203 Step #5: artifact_prefix='./'; Test unit written to ./oom-29367275fa82bc92958d95c0176b98b4638c1589 Step #5: Base64: AAABANaD2oM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1114 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2281699502 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564792d07810, 0x564792ef101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564792ef1020,0x564794d890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/29367275fa82bc92958d95c0176b98b4638c1589' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1262 processed earlier; will process 9767 files now Step #5: ==40138== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5647897fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56478fe61898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56478fe445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56478fe444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564789802d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564789763b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56478975e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647897f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56478c7c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56478c7c3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56478c7c3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56478c7c3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56478c7c3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56478c7c3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56478c7c3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56478c7c3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56478c7c3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56478c7c3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56478ea58f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56478b785b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56478b790be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56478b53cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56478b53cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56478b53d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56478b53c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56478b53c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56478b53c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56478fe46abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56478fe4f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56478fe37699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56478fe62112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa81ce5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56478975cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x4,0xf0,0x9b,0xb2,0x9d, Step #5: \000\000\000\004\360\233\262\235 Step #5: artifact_prefix='./'; Test unit written to ./oom-447d929972cf5e367aed8ceccc4de1a0146b564e Step #5: Base64: AAAABPCbsp0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1115 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2282136554 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cd18736810, 0x55cd1892001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cd18920020,0x55cd1a7b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/447d929972cf5e367aed8ceccc4de1a0146b564e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1263 processed earlier; will process 9766 files now Step #5: ==40174== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cd0f22b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cd15890898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cd158735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cd158734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cd0f231d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cd0f192b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cd0f18d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cd0f223c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cd121f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cd121f2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cd121f2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cd121f2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cd121f2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cd121f2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cd121f2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cd121f2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cd121f2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cd121f2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cd14487f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cd111b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cd111bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cd10f6bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cd10f6bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cd10f6c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cd10f6b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cd10f6b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cd10f6b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cd15875abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cd1587e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cd15866699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cd15891112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3743b7d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cd0f18bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x30,0x30,0x30,0x42,0x3c,0xdb,0xbe, Step #5: 0000B<\333\276 Step #5: artifact_prefix='./'; Test unit written to ./oom-094953fbe3ec485ff89ff9b935023c61ba843ac4 Step #5: Base64: MDAwMEI8274= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1116 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2282576764 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c7131ac810, 0x55c71339601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c713396020,0x55c71522e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/094953fbe3ec485ff89ff9b935023c61ba843ac4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1264 processed earlier; will process 9765 files now Step #5: ==40210== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c709ca19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c710306898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7102e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7102e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c709ca7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c709c08b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c709c03355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c709c99c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c70cc68f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c70cc68f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c70cc68f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c70cc68f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c70cc68f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c70cc68f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c70cc68f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c70cc68f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c70cc68f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c70cc68f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c70eefdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c70bc2ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c70bc35be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c70b9e1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c70b9e1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c70b9e2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c70b9e1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c70b9e1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c70b9e1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7102ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7102f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c7102dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c710307112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0c74360082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c709c01b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xa,0x3d,0xbe,0x3d,0xa,0x3d,0x3d, Step #5: =\012=\276=\012== Step #5: artifact_prefix='./'; Test unit written to ./oom-96b29434805af9ca94e090bee0eb9d670268dfaf Step #5: Base64: PQo9vj0KPT0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1117 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2283008323 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565499052810, 0x56549923c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56549923c020,0x56549b0d40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/96b29434805af9ca94e090bee0eb9d670268dfaf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1265 processed earlier; will process 9764 files now Step #5: ==40246== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56548fb479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5654961ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56549618f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56549618f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56548fb4dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56548faaeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56548faa9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56548fb3fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565492b0ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565492b0ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565492b0ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565492b0ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565492b0ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565492b0ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565492b0ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565492b0ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565492b0ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565492b0ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565494da3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565491ad0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565491adbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565491887c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565491887c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565491888738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565491887874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565491887874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565491887874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565496191abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56549619a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565496182699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5654961ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67e96cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56548faa7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x3c,0xdb,0x9e,0x3,0x33,0xdb,0xb5,0x32, Step #5: B<\333\236\0033\333\2652 Step #5: artifact_prefix='./'; Test unit written to ./oom-4d1189afdc4545b03f2e6bc3ae60a2f43cdb1e5c Step #5: Base64: QjzbngMz27Uy Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1118 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2283444943 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556409cfd810, 0x556409ee701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556409ee7020,0x55640bd7f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4d1189afdc4545b03f2e6bc3ae60a2f43cdb1e5c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1266 processed earlier; will process 9763 files now Step #5: ==40282== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5564007f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556406e57898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556406e3a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556406e3a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564007f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556400759b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556400754355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564007eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564037b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564037b9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564037b9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564037b9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564037b9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564037b9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564037b9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564037b9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564037b9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564037b9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556405a4ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55640277bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556402786be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556402532c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556402532c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556402533738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556402532874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556402532874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556402532874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556406e3cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556406e45928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556406e2d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556406e58112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7b6043b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556400752b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xc2,0xa0,0xc2,0xa0,0xa9,0xc2,0xa0,0xa, Step #5: \012\302\240\302\240\251\302\240\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-68c39409464c8115255a8cd67f658a0406e63670 Step #5: Base64: CsKgwqCpwqAK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1119 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2283881243 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559f628c4810, 0x559f62aae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559f62aae020,0x559f649460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/68c39409464c8115255a8cd67f658a0406e63670' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1267 processed earlier; will process 9762 files now Step #5: ==40318== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559f593b99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559f5fa1e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559f5fa015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559f5fa014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559f593bfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559f59320b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559f5931b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559f593b1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559f5c380f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559f5c380f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559f5c380f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559f5c380f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559f5c380f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559f5c380f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559f5c380f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559f5c380f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559f5c380f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559f5c380f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559f5e615f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559f5b342b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559f5b34dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559f5b0f9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559f5b0f9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559f5b0fa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559f5b0f9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559f5b0f9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559f5b0f9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559f5fa03abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559f5fa0c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559f5f9f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559f5fa1f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa5dc710082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559f59319b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xd, Step #5: Step #5: Step #5: #0 0x562dcddb69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562dd441b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562dd43fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562dd43fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562dcddbcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562dcdd1db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562dcdd18355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562dcddaec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562dd0d7df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562dd0d7df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562dd0d7df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562dd0d7df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562dd0d7df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562dd0d7df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562dd0d7df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562dd0d7df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562dd0d7df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562dd0d7df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562dd3012f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562dcfd3fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562dcfd4abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562dcfaf6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562dcfaf6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562dcfaf7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562dcfaf6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562dcfaf6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562dcfaf6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562dd4400abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562dd4409928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562dd43f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562dd441c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efcb2019082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562dcdd16b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x63,0x6f,0x63,0x6f,0x6e,0x75,0x74, Step #5: = coconut Step #5: artifact_prefix='./'; Test unit written to ./oom-768b291a204f08964381a22242b1386f329a6959 Step #5: Base64: PSBjb2NvbnV0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1121 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2284796591 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c4a0f9810, 0x556c4a2e301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c4a2e3020,0x556c4c17b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/768b291a204f08964381a22242b1386f329a6959' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1270 processed earlier; will process 9759 files now Step #5: ==40390== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556c40bee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c47253898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c472365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c472364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556c40bf4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556c40b55b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556c40b50355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556c40be6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556c43bb5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556c43bb5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556c43bb5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556c43bb5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556c43bb5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556c43bb5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556c43bb5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556c43bb5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556c43bb5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556c43bb5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c45e4af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556c42b77b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556c42b82be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556c4292ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556c4292ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556c4292f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556c4292e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556c4292e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556c4292e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c47238abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c47241928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c47229699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c47254112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0f0e2e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556c40b4eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x5,0x0,0x0,0x0,0x1,0x79, Step #5: \000\000\000\005\000\000\000\001y Step #5: artifact_prefix='./'; Test unit written to ./oom-7665ed44ef1c6f3e79b422eda438f1b6c0fc440b Step #5: Base64: AAAABQAAAAF5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1122 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2285235971 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c65044810, 0x559c6522e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c6522e020,0x559c670c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7665ed44ef1c6f3e79b422eda438f1b6c0fc440b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1271 processed earlier; will process 9758 files now Step #5: ==40426== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559c5bb399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c6219e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c621815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c621814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c5bb3fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c5baa0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c5ba9b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c5bb31c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c5eb00f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c5eb00f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c5eb00f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c5eb00f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c5eb00f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c5eb00f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c5eb00f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c5eb00f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c5eb00f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c5eb00f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c60d95f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c5dac2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c5dacdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c5d879c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c5d879c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c5d87a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c5d879874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c5d879874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c5d879874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c62183abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c6218c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c62174699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c6219f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f00b375f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c5ba99b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x7b,0x6b,0x7b,0x66,0x7b,0x7d,0x7d,0x7d, Step #5: d{k{f{}}} Step #5: artifact_prefix='./'; Test unit written to ./oom-4ae983e4c9d39c9323376b12c5aaf1fde7b9e6a0 Step #5: Base64: ZHtre2Z7fX19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1123 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2285672410 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562afdcbf810, 0x562afdea901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562afdea9020,0x562affd410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4ae983e4c9d39c9323376b12c5aaf1fde7b9e6a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1272 processed earlier; will process 9757 files now Step #5: ==40462== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562af47b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562afae19898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562afadfc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562afadfc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562af47bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562af471bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562af4716355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562af47acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562af777bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562af777bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562af777bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562af777bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562af777bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562af777bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562af777bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562af777bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562af777bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562af777bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562af9a10f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562af673db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562af6748be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562af64f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562af64f4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562af64f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562af64f4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562af64f4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562af64f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562afadfeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562afae07928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562afadef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562afae1a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd1df69c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562af4714b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x2a,0x27,0x2a,0x68,0x6d,0x74,0x78,0x58, Step #5: B*'*hmtxX Step #5: artifact_prefix='./'; Test unit written to ./oom-da91abfb8c8199531eec379448c186e6128030bb Step #5: Base64: QionKmhtdHhY Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1124 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2286112993 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b97388810, 0x557b9757201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b97572020,0x557b9940a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/da91abfb8c8199531eec379448c186e6128030bb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1273 processed earlier; will process 9756 files now Step #5: #1 pulse cov: 10623 ft: 10624 exec/s: 0 rss: 181Mb Step #5: ==40498== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557b8de7d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b944e2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b944c55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b944c54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b8de83d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b8dde4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b8dddf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b8de75c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b90e44f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b90e44f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b90e44f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b90e44f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b90e44f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b90e44f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b90e44f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b90e44f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b90e44f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b90e44f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b930d9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b8fe06b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b8fe11be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b8fbbdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b8fbbdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b8fbbe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b8fbbd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b8fbbd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b8fbbd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b944c7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b944d0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b944b8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b944e3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c292e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b8ddddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe0,0xb7,0x99,0xe0,0xb7,0x8f, Step #5: ws:\340\267\231\340\267\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-5035e444e5e4878caa149c0745289fbde4d2e388 Step #5: Base64: d3M64LeZ4LeP Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1125 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2286620389 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa58a8c810, 0x55aa58c7601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa58c76020,0x55aa5ab0e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5035e444e5e4878caa149c0745289fbde4d2e388' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1275 processed earlier; will process 9754 files now Step #5: ==40534== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55aa4f5819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa55be6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa55bc95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa55bc94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa4f587d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa4f4e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa4f4e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa4f579c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa52548f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa52548f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa52548f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa52548f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa52548f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa52548f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa52548f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa52548f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa52548f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa52548f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa547ddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa5150ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa51515be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa512c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa512c1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa512c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa512c1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa512c1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa512c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa55bcbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa55bd4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa55bbc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa55be7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2cd7936082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa4f4e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xf0,0xaa,0x9f,0x91,0xc,0x0,0x0,0x12, Step #5: \012\360\252\237\221\014\000\000\022 Step #5: artifact_prefix='./'; Test unit written to ./oom-88cb0b34dd0dff7c6892f78d78060f98b3c36adb Step #5: Base64: CvCqn5EMAAAS Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1126 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2287059766 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ca844f810, 0x562ca863901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ca8639020,0x562caa4d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88cb0b34dd0dff7c6892f78d78060f98b3c36adb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1276 processed earlier; will process 9753 files now Step #5: ==40570== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562c9ef449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ca55a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ca558c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ca558c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c9ef4ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c9eeabb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c9eea6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c9ef3cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ca1f0bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ca1f0bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ca1f0bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ca1f0bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ca1f0bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ca1f0bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ca1f0bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ca1f0bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ca1f0bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ca1f0bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ca41a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ca0ecdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ca0ed8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ca0c84c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ca0c84c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ca0c85738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ca0c84874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ca0c84874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ca0c84874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ca558eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ca5597928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ca557f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ca55aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f883cc4a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c9eea4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x68,0xa,0x20,0xa,0x2d,0x20,0x20,0x55, Step #5: Ph\012 \012- U Step #5: artifact_prefix='./'; Test unit written to ./oom-5274d33891944b3a432d335284721f081e7c6b7d Step #5: Base64: UGgKIAotICBV Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1127 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2287502589 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f060590810, 0x55f06077a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f06077a020,0x55f0626120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5274d33891944b3a432d335284721f081e7c6b7d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1277 processed earlier; will process 9752 files now Step #5: #1 pulse cov: 3795 ft: 3796 exec/s: 0 rss: 163Mb Step #5: ==40606== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f0570859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f05d6ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f05d6cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f05d6cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f05708bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f056fecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f056fe7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f05707dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f05a04cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f05a04cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f05a04cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f05a04cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f05a04cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f05a04cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f05a04cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f05a04cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f05a04cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f05a04cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f05c2e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f05900eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f059019be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f058dc5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f058dc5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f058dc6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f058dc5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f058dc5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f058dc5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f05d6cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f05d6d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f05d6c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f05d6eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe3436ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f056fe5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x6e,0x22,0x3d,0x67,0x6c,0x79,0x66,0x59, Step #5: +n\"=glyfY Step #5: artifact_prefix='./'; Test unit written to ./oom-457228fe97bf1dd634e330f0e00a663d9a26b2b7 Step #5: Base64: K24iPWdseWZZ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1128 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2287984319 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d30d7d810, 0x564d30f6701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d30f67020,0x564d32dff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/457228fe97bf1dd634e330f0e00a663d9a26b2b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1279 processed earlier; will process 9750 files now Step #5: #1 pulse cov: 3745 ft: 3746 exec/s: 0 rss: 165Mb Step #5: ==40642== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564d278729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d2ded7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d2deba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d2deba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d27878d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d277d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d277d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d2786ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d2a839f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d2a839f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d2a839f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d2a839f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d2a839f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d2a839f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d2a839f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d2a839f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d2a839f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d2a839f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d2cacef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d297fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d29806be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d295b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d295b2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d295b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d295b2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d295b2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d295b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d2debcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d2dec5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d2dead699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d2ded8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb1bd1c6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d277d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x0,0x10,0xd2,0x88,0x0,0x10,0xd2,0x88, Step #5: =\000\020\322\210\000\020\322\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-1eb9d4bf55f847d8f36e798afe235f55e3bc5864 Step #5: Base64: PQAQ0ogAENKI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1129 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2288466193 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559303a11810, 0x559303bfb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559303bfb020,0x559305a930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1eb9d4bf55f847d8f36e798afe235f55e3bc5864' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1281 processed earlier; will process 9748 files now Step #5: ==40678== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5592fa5069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559300b6b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559300b4e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559300b4e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592fa50cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592fa46db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592fa468355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592fa4fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592fd4cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592fd4cdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592fd4cdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592fd4cdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592fd4cdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592fd4cdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592fd4cdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592fd4cdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592fd4cdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592fd4cdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592ff762f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592fc48fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592fc49abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5592fc246c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5592fc246c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5592fc247738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5592fc246874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5592fc246874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5592fc246874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559300b50abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559300b59928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559300b41699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559300b6c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd242b80082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592fa466b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe1,0xac,0xbc,0xe1,0xac,0xb5, Step #5: ws:\341\254\274\341\254\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-53ed7cdb58add6f3dd3f34a54fcc2c69251f1ce4 Step #5: Base64: d3M64ay84ay1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1130 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2288906265 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a7b2a2a810, 0x55a7b2c1401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a7b2c14020,0x55a7b4aac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/53ed7cdb58add6f3dd3f34a54fcc2c69251f1ce4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1282 processed earlier; will process 9747 files now Step #5: ==40714== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a7a951f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a7afb84898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a7afb675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a7afb674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a7a9525d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a7a9486b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a7a9481355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a7a9517c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a7ac4e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a7ac4e6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a7ac4e6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a7ac4e6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a7ac4e6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a7ac4e6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a7ac4e6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a7ac4e6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a7ac4e6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a7ac4e6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a7ae77bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a7ab4a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a7ab4b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a7ab25fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a7ab25fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a7ab260738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a7ab25f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a7ab25f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a7ab25f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a7afb69abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a7afb72928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a7afb5a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a7afb85112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f42a430c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a7a947fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x57,0x5a,0x2d,0x54,0x41,0x47,0x1f, Step #5: FUWZ-TAG\037 Step #5: artifact_prefix='./'; Test unit written to ./oom-5fce9f4144759e16c5f93cd60ecab5cab405f048 Step #5: Base64: RlVXWi1UQUcf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1131 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2289344486 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558f980dd810, 0x558f982c701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558f982c7020,0x558f9a15f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5fce9f4144759e16c5f93cd60ecab5cab405f048' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1283 processed earlier; will process 9746 files now Step #5: #1 pulse cov: 3723 ft: 3724 exec/s: 0 rss: 165Mb Step #5: ==40750== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558f8ebd29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558f95237898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558f9521a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558f9521a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f8ebd8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f8eb39b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f8eb34355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f8ebcac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f91b99f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f91b99f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f91b99f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f91b99f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f91b99f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f91b99f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f91b99f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f91b99f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f91b99f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f91b99f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558f93e2ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f90b5bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f90b66be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f90912c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f90912c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f90913738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f90912874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f90912874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f90912874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558f9521cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558f95225928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558f9520d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558f95238112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f01b1197082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f8eb32b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0xd,0xd,0xd,0x13,0xd,0xe,0xa,0xa, Step #5: [\015\015\015\023\015\016\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-219d75d8c62fc797876f7dd939210a9300a89f8a Step #5: Base64: Ww0NDRMNDgoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1132 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2289825763 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a53f099810, 0x55a53f28301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a53f283020,0x55a54111b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/219d75d8c62fc797876f7dd939210a9300a89f8a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1285 processed earlier; will process 9744 files now Step #5: ==40786== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a535b8e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a53c1f3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a53c1d65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a53c1d64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a535b94d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a535af5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a535af0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a535b86c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a538b55f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a538b55f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a538b55f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a538b55f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a538b55f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a538b55f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a538b55f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a538b55f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a538b55f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a538b55f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a53adeaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a537b17b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a537b22be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a5378cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a5378cec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a5378cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a5378ce874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a5378ce874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a5378ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a53c1d8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a53c1e1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a53c1c9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a53c1f4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f57075be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a535aeeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xec,0x86,0xa8,0xe1,0x86,0xa8, Step #5: ws:\354\206\250\341\206\250 Step #5: artifact_prefix='./'; Test unit written to ./oom-0b0c40b12b288c2cf602adb906c18485b50417f7 Step #5: Base64: d3M67Iao4Yao Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1133 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2290261471 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56120e250810, 0x56120e43a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56120e43a020,0x5612102d20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b0c40b12b288c2cf602adb906c18485b50417f7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1286 processed earlier; will process 9743 files now Step #5: ==40822== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561204d459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56120b3aa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56120b38d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56120b38d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561204d4bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561204cacb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561204ca7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561204d3dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561207d0cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561207d0cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561207d0cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561207d0cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561207d0cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561207d0cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561207d0cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561207d0cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561207d0cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561207d0cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561209fa1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561206cceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561206cd9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561206a85c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561206a85c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561206a86738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561206a85874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561206a85874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561206a85874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56120b38fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56120b398928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56120b380699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56120b3ab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f36eef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561204ca5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0xc6,0xc6,0xc6,0xb9,0x39, Step #5: \333\200\333\200\306\306\306\2719 Step #5: artifact_prefix='./'; Test unit written to ./oom-ca39a53088142c7d5f51c9b4af3cddd518be3f9c Step #5: Base64: 24DbgMbGxrk5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1134 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2290695640 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7de9b5810, 0x55f7deb9f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7deb9f020,0x55f7e0a370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca39a53088142c7d5f51c9b4af3cddd518be3f9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1287 processed earlier; will process 9742 files now Step #5: ==40858== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f7d54aa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7dbb0f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7dbaf25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7dbaf24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f7d54b0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f7d5411b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f7d540c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f7d54a2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7d8471f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7d8471f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7d8471f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7d8471f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7d8471f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7d8471f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7d8471f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7d8471f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7d8471f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7d8471f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7da706f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f7d7433b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f7d743ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f7d71eac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f7d71eac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f7d71eb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f7d71ea874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f7d71ea874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f7d71ea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7dbaf4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7dbafd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7dbae5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7dbb10112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4d82acf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f7d540ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc, Step #5: '\\\014\\\014\\\014\\\014 Step #5: artifact_prefix='./'; Test unit written to ./oom-2bcb240cbc09aeb6677c2a38ffc803b1b4023fb5 Step #5: Base64: J1wMXAxcDFwM Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1135 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2291130077 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555c35c9b810, 0x555c35e8501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555c35e85020,0x555c37d1d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2bcb240cbc09aeb6677c2a38ffc803b1b4023fb5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1288 processed earlier; will process 9741 files now Step #5: #1 pulse cov: 3828 ft: 3829 exec/s: 0 rss: 163Mb Step #5: ==40894== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555c2c7909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555c32df5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555c32dd85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555c32dd84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555c2c796d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555c2c6f7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555c2c6f2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555c2c788c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555c2f757f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555c2f757f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555c2f757f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555c2f757f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555c2f757f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555c2f757f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555c2f757f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555c2f757f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555c2f757f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555c2f757f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555c319ecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555c2e719b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555c2e724be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555c2e4d0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555c2e4d0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555c2e4d1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555c2e4d0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555c2e4d0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555c2e4d0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555c32ddaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555c32de3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555c32dcb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555c32df6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b6dc9f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555c2c6f0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0x2b,0x73,0x63,0xd,0x74,0x20,0xd2,0x84, Step #5: &+sc\015t \322\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-7c314524248efd4e3fdccd3a3425096363c0241a Step #5: Base64: JitzYw10INKE Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1136 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2291605805 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0001c5810, 0x55a0003af01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0003af020,0x55a0022470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7c314524248efd4e3fdccd3a3425096363c0241a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1290 processed earlier; will process 9739 files now Step #5: ==40930== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559ff6cba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ffd31f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ffd3025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ffd3024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ff6cc0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ff6c21b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ff6c1c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ff6cb2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ff9c81f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ff9c81f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ff9c81f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ff9c81f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ff9c81f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ff9c81f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ff9c81f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ff9c81f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ff9c81f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ff9c81f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ffbf16f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559ff8c43b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559ff8c4ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559ff89fac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559ff89fac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559ff89fb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559ff89fa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559ff89fa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559ff89fa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ffd304abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ffd30d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ffd2f5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ffd320112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f50af460082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ff6c1ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x31, Step #5: - - - - 1 Step #5: artifact_prefix='./'; Test unit written to ./oom-1c0fbaf0f122aab1952e1a671796bac499cd9ce1 Step #5: Base64: LSAtIC0gLSAx Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1137 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2292049446 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fcdc98d810, 0x55fcdcb7701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fcdcb77020,0x55fcdea0f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c0fbaf0f122aab1952e1a671796bac499cd9ce1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1291 processed earlier; will process 9738 files now Step #5: ==40966== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fcd34829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fcd9ae7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fcd9aca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fcd9aca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fcd3488d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fcd33e9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fcd33e4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fcd347ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fcd6449f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fcd6449f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fcd6449f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fcd6449f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fcd6449f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fcd6449f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fcd6449f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fcd6449f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fcd6449f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fcd6449f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fcd86def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fcd540bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fcd5416be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fcd51c2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fcd51c2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fcd51c3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fcd51c2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fcd51c2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fcd51c2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fcd9accabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fcd9ad5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fcd9abd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fcd9ae8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c5691a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fcd33e2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x23,0x7b,0x30,0x7d,0x29,0x7b,0x34,0x7d, Step #5: (#{0}){4} Step #5: artifact_prefix='./'; Test unit written to ./oom-db614deb2709ff4869a3a0e95007a08090887870 Step #5: Base64: KCN7MH0pezR9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1138 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2292491541 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d25004c810, 0x55d25023601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d250236020,0x55d2520ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/db614deb2709ff4869a3a0e95007a08090887870' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1292 processed earlier; will process 9737 files now Step #5: ==41002== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d246b419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d24d1a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d24d1895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d24d1894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d246b47d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d246aa8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d246aa3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d246b39c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d249b08f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d249b08f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d249b08f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d249b08f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d249b08f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d249b08f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d249b08f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d249b08f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d249b08f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d249b08f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d24bd9df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d248acab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d248ad5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d248881c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d248881c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d248882738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d248881874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d248881874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d248881874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d24d18babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d24d194928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d24d17c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d24d1a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe28aaa2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d246aa1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0xe2,0x81,0x9f,0xf0,0x91,0x80,0x80,0x3a, Step #5: 0\342\201\237\360\221\200\200: Step #5: artifact_prefix='./'; Test unit written to ./oom-bf42c20564417b2ba06f7cf961e0dbd32426401c Step #5: Base64: MOKBn/CRgIA6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1139 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2292924563 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cf94edd810, 0x55cf950c701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cf950c7020,0x55cf96f5f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf42c20564417b2ba06f7cf961e0dbd32426401c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1293 processed earlier; will process 9736 files now Step #5: ==41038== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cf8b9d29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cf92037898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cf9201a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cf9201a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cf8b9d8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cf8b939b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cf8b934355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cf8b9cac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cf8e999f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cf8e999f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cf8e999f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cf8e999f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cf8e999f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cf8e999f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cf8e999f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cf8e999f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cf8e999f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cf8e999f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cf90c2ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cf8d95bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cf8d966be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cf8d712c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cf8d712c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cf8d713738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cf8d712874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cf8d712874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cf8d712874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cf9201cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cf92025928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cf9200d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cf92038112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd319ec7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cf8b932b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x5b,0x5d,0x2d,0xf3,0xa0,0x81,0xbd,0x2d, Step #5: #[]-\363\240\201\275- Step #5: artifact_prefix='./'; Test unit written to ./oom-161bf912cdc7d782e170990f5a38dee1cc5ebc44 Step #5: Base64: I1tdLfOggb0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1140 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2293363069 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dba39db810, 0x55dba3bc501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dba3bc5020,0x55dba5a5d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/161bf912cdc7d782e170990f5a38dee1cc5ebc44' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1294 processed earlier; will process 9735 files now Step #5: ==41074== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55db9a4d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dba0b35898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dba0b185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dba0b184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db9a4d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db9a437b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db9a432355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db9a4c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db9d497f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db9d497f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db9d497f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db9d497f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db9d497f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db9d497f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db9d497f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db9d497f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db9d497f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db9d497f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db9f72cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db9c459b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db9c464be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db9c210c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db9c210c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db9c211738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db9c210874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db9c210874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db9c210874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dba0b1aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dba0b23928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dba0b0b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dba0b36112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67265cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db9a430b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0xf0,0x9e,0xa4,0xa6,0x2c, Step #5: (?i)\360\236\244\246, Step #5: artifact_prefix='./'; Test unit written to ./oom-d11a624256205c920f78a0d8da661e88e8f078fd Step #5: Base64: KD9pKfCepKYs Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1141 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2293807484 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558496617810, 0x55849680101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558496801020,0x5584986990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d11a624256205c920f78a0d8da661e88e8f078fd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1295 processed earlier; will process 9734 files now Step #5: ==41110== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55848d10c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558493771898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5584937545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5584937544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55848d112d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55848d073b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55848d06e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55848d104c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5584900d3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5584900d3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5584900d3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5584900d3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5584900d3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5584900d3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5584900d3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5584900d3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5584900d3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5584900d3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558492368f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55848f095b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55848f0a0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55848ee4cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55848ee4cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55848ee4d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55848ee4c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55848ee4c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55848ee4c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558493756abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55849375f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558493747699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558493772112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f91c590e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55848d06cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33,0xcd,0x85,0xcd,0x85,0xcd,0x85,0xcd,0x85, Step #5: 3\315\205\315\205\315\205\315\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-24742bc6b8e2616844c9c9d853bde1129e127a7c Step #5: Base64: M82FzYXNhc2F Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1142 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2294249462 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562b9f738810, 0x562b9f92201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562b9f922020,0x562ba17ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/24742bc6b8e2616844c9c9d853bde1129e127a7c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1296 processed earlier; will process 9733 files now Step #5: ==41146== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562b9622d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562b9c892898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562b9c8755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562b9c8754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b96233d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b96194b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b9618f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b96225c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b991f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b991f4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b991f4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b991f4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b991f4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b991f4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b991f4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b991f4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b991f4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b991f4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562b9b489f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b981b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b981c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b97f6dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b97f6dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b97f6e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b97f6d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b97f6d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b97f6d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562b9c877abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562b9c880928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562b9c868699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562b9c893112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6188e05082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b9618db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xcd,0x80,0xcd,0x80,0xcd,0x80, Step #5: ws:\315\200\315\200\315\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-45255fbb37ab37966b7a20e0540cff499dd44807 Step #5: Base64: d3M6zYDNgM2A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1143 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2294691792 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5599117ac810, 0x55991199601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559911996020,0x55991382e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/45255fbb37ab37966b7a20e0540cff499dd44807' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1297 processed earlier; will process 9732 files now Step #5: #1 pulse cov: 3461 ft: 3462 exec/s: 0 rss: 162Mb Step #5: ==41182== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5599082a19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55990e906898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55990e8e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55990e8e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5599082a7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559908208b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559908203355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559908299c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55990b268f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55990b268f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55990b268f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55990b268f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55990b268f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55990b268f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55990b268f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55990b268f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55990b268f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55990b268f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55990d4fdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55990a22ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55990a235be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559909fe1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559909fe1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559909fe2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559909fe1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559909fe1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559909fe1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55990e8ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55990e8f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55990e8dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55990e907112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fea54f23082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559908201b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x16,0x0,0xdc,0xb5,0x44, Step #5: ID3\002\026\000\334\265D Step #5: artifact_prefix='./'; Test unit written to ./oom-6bb989aa48cd9b3e9d3e32d7b86bbc0c809907bf Step #5: Base64: SUQzAhYA3LVE Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1144 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2295175530 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5570fe339810, 0x5570fe52301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5570fe523020,0x5571003bb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bb989aa48cd9b3e9d3e32d7b86bbc0c809907bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1299 processed earlier; will process 9730 files now Step #5: ==41218== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5570f4e2e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5570fb493898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5570fb4765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5570fb4764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5570f4e34d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5570f4d95b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5570f4d90355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5570f4e26c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5570f7df5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5570f7df5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5570f7df5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5570f7df5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5570f7df5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5570f7df5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5570f7df5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5570f7df5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5570f7df5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5570f7df5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5570fa08af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5570f6db7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5570f6dc2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5570f6b6ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5570f6b6ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5570f6b6f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5570f6b6e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5570f6b6e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5570f6b6e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5570fb478abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5570fb481928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5570fb469699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5570fb494112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f63ccf5c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5570f4d8eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0xa,0x5c,0xa,0x5c,0xa,0x5c,0xa,0x5c, Step #5: \\\012\\\012\\\012\\\012\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-e7ffc27180c57dc0e90e005dec57301b24d00580 Step #5: Base64: XApcClwKXApc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1145 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2295614890 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56387d5a9810, 0x56387d79301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56387d793020,0x56387f62b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e7ffc27180c57dc0e90e005dec57301b24d00580' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1300 processed earlier; will process 9729 files now Step #5: ==41254== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56387409e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56387a703898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56387a6e65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56387a6e64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5638740a4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563874005b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563874000355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563874096c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563877065f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563877065f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563877065f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563877065f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563877065f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563877065f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563877065f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563877065f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563877065f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563877065f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5638792faf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563876027b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563876032be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563875ddec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563875ddec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563875ddf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563875dde874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563875dde874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563875dde874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56387a6e8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56387a6f1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56387a6d9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56387a704112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f64c4c25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563873ffeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x8,0x5a,0x2d,0x54,0x41,0x47,0x46, Step #5: FU\010Z-TAGF Step #5: artifact_prefix='./'; Test unit written to ./oom-2bfbcc71006f310df3f45d6967ed0520befb9b32 Step #5: Base64: RlUIWi1UQUdG Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1146 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2296056230 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4d5b41810, 0x55e4d5d2b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4d5d2b020,0x55e4d7bc30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2bfbcc71006f310df3f45d6967ed0520befb9b32' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1301 processed earlier; will process 9728 files now Step #5: ==41290== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e4cc6369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4d2c9b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4d2c7e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4d2c7e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4cc63cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4cc59db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4cc598355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4cc62ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4cf5fdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4cf5fdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4cf5fdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4cf5fdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4cf5fdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4cf5fdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4cf5fdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4cf5fdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4cf5fdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4cf5fdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4d1892f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4ce5bfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4ce5cabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4ce376c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4ce376c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4ce377738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4ce376874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4ce376874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4ce376874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4d2c80abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4d2c89928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4d2c71699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4d2c9c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd7c3f51082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4cc596b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x26,0x23,0x39,0x39, Step #5: c Step #5: artifact_prefix='./'; Test unit written to ./oom-952b03d629b3bcbb5b40a3a1418fe78ff6fa46d0 Step #5: Base64: PHN2Zz4mIzk5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1147 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2296496901 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561facc97810, 0x561face8101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561face81020,0x561faed190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/952b03d629b3bcbb5b40a3a1418fe78ff6fa46d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1302 processed earlier; will process 9727 files now Step #5: ==41326== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561fa378c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561fa9df1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561fa9dd45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561fa9dd44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561fa3792d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561fa36f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561fa36ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561fa3784c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561fa6753f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561fa6753f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561fa6753f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561fa6753f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561fa6753f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561fa6753f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561fa6753f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561fa6753f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561fa6753f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561fa6753f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561fa89e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561fa5715b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561fa5720be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561fa54ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561fa54ccc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561fa54cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561fa54cc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561fa54cc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561fa54cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561fa9dd6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561fa9ddf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561fa9dc7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561fa9df2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb9b8386082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561fa36ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x3f,0x3f,0x3d,0x3f,0x3f,0x3f,0x3d,0x56, Step #5: '??=???=V Step #5: artifact_prefix='./'; Test unit written to ./oom-b21a8addee351a22bffd21b679bc4057cee5654a Step #5: Base64: Jz8/PT8/Pz1W Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1148 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2296934518 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560c62b10810, 0x560c62cfa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560c62cfa020,0x560c64b920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b21a8addee351a22bffd21b679bc4057cee5654a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1303 processed earlier; will process 9726 files now Step #5: ==41362== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560c596059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560c5fc6a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560c5fc4d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560c5fc4d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560c5960bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560c5956cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560c59567355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560c595fdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560c5c5ccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560c5c5ccf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560c5c5ccf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560c5c5ccf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560c5c5ccf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560c5c5ccf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560c5c5ccf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560c5c5ccf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560c5c5ccf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560c5c5ccf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560c5e861f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560c5b58eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560c5b599be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560c5b345c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560c5b345c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560c5b346738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560c5b345874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560c5b345874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560c5b345874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560c5fc4fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560c5fc58928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560c5fc40699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560c5fc6b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4518928082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560c59565b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x7,0x1a,0x5,0xa,0x3,0xe2,0xba,0xa9, Step #5: \012\007\032\005\012\003\342\272\251 Step #5: artifact_prefix='./'; Test unit written to ./oom-edfb3435519acd5b0622e6309954514b85e3c1bd Step #5: Base64: CgcaBQoD4rqp Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1149 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2297377521 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab540a2810, 0x55ab5428c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab5428c020,0x55ab561240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/edfb3435519acd5b0622e6309954514b85e3c1bd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1304 processed earlier; will process 9725 files now Step #5: ==41398== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ab4ab979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab511fc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab511df5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab511df4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab4ab9dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab4aafeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab4aaf9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab4ab8fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab4db5ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab4db5ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab4db5ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab4db5ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab4db5ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab4db5ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab4db5ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab4db5ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab4db5ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab4db5ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab4fdf3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab4cb20b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab4cb2bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab4c8d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab4c8d7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab4c8d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab4c8d7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab4c8d7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab4c8d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab511e1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab511ea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab511d2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab511fd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f52692b2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab4aaf7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x67,0x75,0x6c,0x32,0x12,0xaf,0x1,0x0,0x0, Step #5: gul2\022\257\001\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a875aca50703dd9aea28b5d8c03e01197bde35a0 Step #5: Base64: Z3VsMhKvAQAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1150 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2297820984 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652f21d1810, 0x5652f23bb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652f23bb020,0x5652f42530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a875aca50703dd9aea28b5d8c03e01197bde35a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1305 processed earlier; will process 9724 files now Step #5: ==41434== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5652e8cc69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652ef32b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652ef30e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652ef30e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5652e8cccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5652e8c2db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5652e8c28355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5652e8cbec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5652ebc8df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5652ebc8df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5652ebc8df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5652ebc8df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5652ebc8df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5652ebc8df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5652ebc8df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5652ebc8df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5652ebc8df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5652ebc8df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652edf22f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5652eac4fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5652eac5abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652eaa06c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652eaa06c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652eaa07738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652eaa06874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652eaa06874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652eaa06874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652ef310abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652ef319928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652ef301699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652ef32c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f981719a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5652e8c26b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e, Step #5: >>>>>>>>> Step #5: artifact_prefix='./'; Test unit written to ./oom-50dc15106ec10a13231cf1efd82698646897a628 Step #5: Base64: Pj4+Pj4+Pj4+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1151 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2298264957 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55613d45d810, 0x55613d64701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55613d647020,0x55613f4df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/50dc15106ec10a13231cf1efd82698646897a628' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1306 processed earlier; will process 9723 files now Step #5: ==41470== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556133f529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55613a5b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55613a59a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55613a59a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556133f58d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556133eb9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556133eb4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556133f4ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556136f19f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556136f19f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556136f19f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556136f19f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556136f19f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556136f19f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556136f19f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556136f19f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556136f19f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556136f19f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5561391aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556135edbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556135ee6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556135c92c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556135c92c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556135c93738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556135c92874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556135c92874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556135c92874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55613a59cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55613a5a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55613a58d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55613a5b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5c9b1d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556133eb2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbe,0x94,0xef,0xbe,0x94,0xef,0xbe,0x94, Step #5: \357\276\224\357\276\224\357\276\224 Step #5: artifact_prefix='./'; Test unit written to ./oom-5b0f2cf24422949fae62d41cfcb0979921b074f9 Step #5: Base64: 776U776U776U Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1152 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2298703745 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5588b577e810, 0x5588b596801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5588b5968020,0x5588b78000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5b0f2cf24422949fae62d41cfcb0979921b074f9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1307 processed earlier; will process 9722 files now Step #5: ==41506== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5588ac2739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5588b28d8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588b28bb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588b28bb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588ac279d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588ac1dab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588ac1d5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588ac26bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5588af23af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5588af23af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5588af23af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5588af23af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5588af23af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5588af23af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5588af23af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5588af23af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5588af23af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5588af23af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5588b14cff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588ae1fcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588ae207be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588adfb3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588adfb3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588adfb4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588adfb3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588adfb3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588adfb3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5588b28bdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5588b28c6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5588b28ae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5588b28d9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f96caab2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588ac1d3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x71,0x2d,0x2d,0x3e,0x3c,0x21,0x2d,0x2d, Step #5: 2 Step #5: artifact_prefix='./'; Test unit written to ./oom-27f6fdb62f23c07d7d811c9ece711aa4300942a3 Step #5: Base64: MDo2OjcuMC0tPjI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1419 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2422762978 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560308ecb810, 0x5603090b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5603090b5020,0x56030af4d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/27f6fdb62f23c07d7d811c9ece711aa4300942a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1628 processed earlier; will process 9401 files now Step #5: ==51118== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5602ff9c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560306025898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5603060085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5603060084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5602ff9c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5602ff927b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5602ff922355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5602ff9b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560302987f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560302987f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560302987f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560302987f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560302987f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560302987f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560302987f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560302987f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560302987f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560302987f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560304c1cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560301949b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560301954be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560301700c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560301700c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560301701738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560301700874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560301700874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560301700874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56030600aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560306013928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560305ffb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560306026112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efc2c048082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5602ff920b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80, Step #5: ws:\315\200\315\200\315\200\315\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a95bbda17315fdd1e071affeb805d8440195665 Step #5: Base64: d3M6zYDNgM2AzYA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1420 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2423199812 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f47cc68810, 0x55f47ce5201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f47ce52020,0x55f47ecea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a95bbda17315fdd1e071affeb805d8440195665' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1629 processed earlier; will process 9400 files now Step #5: #1 pulse cov: 3636 ft: 3637 exec/s: 0 rss: 166Mb Step #5: ==51154== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f47375d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f479dc2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f479da55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f479da54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f473763d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f4736c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f4736bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f473755c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f476724f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f476724f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f476724f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f476724f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f476724f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f476724f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f476724f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f476724f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f476724f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f476724f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4789b9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4756e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4756f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f47549dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f47549dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f47549e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f47549d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f47549d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f47549d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f479da7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f479db0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f479d98699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f479dc3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdd5a86d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f4736bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xb9,0x83,0x79,0x79,0x0,0xa,0x0,0xca,0xb8,0xa, Step #5: \340\271\203yy\000\012\000\312\270\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-012c5dcdfca4fa96ee45066d7ed8292764e5bef2 Step #5: Base64: 4LmDeXkACgDKuAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1421 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2423677233 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5614ad44e810, 0x5614ad63801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5614ad638020,0x5614af4d00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/012c5dcdfca4fa96ee45066d7ed8292764e5bef2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1631 processed earlier; will process 9398 files now Step #5: ==51190== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5614a3f439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5614aa5a8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5614aa58b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5614aa58b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5614a3f49d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5614a3eaab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5614a3ea5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5614a3f3bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5614a6f0af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5614a6f0af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5614a6f0af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5614a6f0af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5614a6f0af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5614a6f0af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5614a6f0af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5614a6f0af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5614a6f0af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5614a6f0af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5614a919ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5614a5eccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5614a5ed7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5614a5c83c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5614a5c83c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5614a5c84738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5614a5c83874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5614a5c83874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5614a5c83874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5614aa58dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5614aa596928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5614aa57e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5614aa5a9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f250e39a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5614a3ea3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x68,0x68,0x68,0x68,0x68,0x68,0x60,0x23,0x60, Step #5: +\012hhhhhh`#` Step #5: artifact_prefix='./'; Test unit written to ./oom-602d97cf6bbb2ddfa1cece468cad75279d5e48d5 Step #5: Base64: KwpoaGhoaGhgI2A= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1422 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2424262271 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e216976810, 0x55e216b6001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e216b60020,0x55e2189f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/602d97cf6bbb2ddfa1cece468cad75279d5e48d5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1632 processed earlier; will process 9397 files now Step #5: ==51226== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e20d46b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e213ad0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e213ab35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e213ab34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e20d471d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e20d3d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e20d3cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e20d463c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e210432f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e210432f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e210432f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e210432f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e210432f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e210432f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e210432f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e210432f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e210432f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e210432f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e2126c7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e20f3f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e20f3ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e20f1abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e20f1abc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e20f1ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e20f1ab874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e20f1ab874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e20f1ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e213ab5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e213abe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e213aa6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e213ad1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f952f1b8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e20d3cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x8f,0x2e,0xa,0xcd,0x8f,0x2e,0xa,0xcd,0x8f,0x2e, Step #5: \315\217.\012\315\217.\012\315\217. Step #5: artifact_prefix='./'; Test unit written to ./oom-418799e93874aa5a0e325b184a4aff71f4874f5c Step #5: Base64: zY8uCs2PLgrNjy4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1423 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2424715065 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a803cf810, 0x555a805b901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a805b9020,0x555a824510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/418799e93874aa5a0e325b184a4aff71f4874f5c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1633 processed earlier; will process 9396 files now Step #5: ==51262== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555a76ec49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a7d529898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a7d50c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a7d50c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a76ecad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a76e2bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a76e26355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a76ebcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a79e8bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a79e8bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a79e8bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a79e8bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a79e8bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a79e8bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a79e8bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a79e8bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a79e8bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a79e8bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a7c120f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a78e4db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a78e58be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a78c04c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a78c04c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a78c05738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a78c04874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a78c04874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a78c04874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a7d50eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a7d517928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a7d4ff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a7d52a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7effc1cbf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a76e24b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x1,0x5c,0x26,0x5c,0x22,0x22,0x22,0x22,0x22,0x22, Step #5: \"\001\\&\\\"\"\"\"\"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-ebef3705330d1285b9826a2ae693a382f61db7f3 Step #5: Base64: IgFcJlwiIiIiIiI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1424 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2425162058 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555d0b602810, 0x555d0b7ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555d0b7ec020,0x555d0d6840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ebef3705330d1285b9826a2ae693a382f61db7f3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1634 processed earlier; will process 9395 files now Step #5: ==51298== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555d020f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555d0875c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555d0873f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555d0873f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555d020fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555d0205eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555d02059355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555d020efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555d050bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555d050bef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555d050bef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555d050bef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555d050bef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555d050bef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555d050bef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555d050bef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555d050bef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555d050bef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555d07353f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555d04080b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555d0408bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555d03e37c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555d03e37c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555d03e38738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555d03e37874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555d03e37874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555d03e37874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555d08741abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555d0874a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555d08732699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555d0875d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f22e80b0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555d02057b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x8,0x22,0xcc,0xad,0xcc,0xad,0xcc,0x9d,0xcc, Step #5: HU\010\"\314\255\314\255\314\235\314 Step #5: artifact_prefix='./'; Test unit written to ./oom-a07fdc22427ee015bbc53f882fc3a5af206d123c Step #5: Base64: SFUIIsytzK3Mncw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1425 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2425605360 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e609344810, 0x55e60952e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e60952e020,0x55e60b3c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a07fdc22427ee015bbc53f882fc3a5af206d123c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1635 processed earlier; will process 9394 files now Step #5: ==51334== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e5ffe399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e60649e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e6064815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e6064814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e5ffe3fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e5ffda0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e5ffd9b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e5ffe31c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e602e00f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e602e00f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e602e00f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e602e00f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e602e00f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e602e00f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e602e00f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e602e00f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e602e00f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e602e00f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e605095f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e601dc2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e601dcdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e601b79c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e601b79c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e601b7a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e601b79874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e601b79874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e601b79874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e606483abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e60648c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e606474699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e60649f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe13d32f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e5ffd99b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x29,0x3a,0x20,0x7b,0x5b,0xf0,0x9e,0x80,0x81,0x5d,0x7d, Step #5: ): {[\360\236\200\201]} Step #5: artifact_prefix='./'; Test unit written to ./oom-137ec4f620d3af0c9bb7a4e7d45fcf8ed604844f Step #5: Base64: KToge1vwnoCBXX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1426 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2426058400 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560f5acbb810, 0x560f5aea501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560f5aea5020,0x560f5cd3d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/137ec4f620d3af0c9bb7a4e7d45fcf8ed604844f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1636 processed earlier; will process 9393 files now Step #5: ==51370== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560f517b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560f57e15898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560f57df85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560f57df84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560f517b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560f51717b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560f51712355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560f517a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560f54777f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560f54777f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560f54777f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560f54777f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560f54777f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560f54777f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560f54777f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560f54777f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560f54777f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560f54777f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560f56a0cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560f53739b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560f53744be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560f534f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560f534f0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560f534f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560f534f0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560f534f0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560f534f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560f57dfaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560f57e03928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560f57deb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560f57e16112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f04c0dc8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560f51710b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x6e,0x3a,0x6f,0x75,0x3d,0x53,0x55,0x44,0x4f,0x47, Step #5: dn:ou=SUDOG Step #5: artifact_prefix='./'; Test unit written to ./oom-645ee9c8268e4983279ba6bbb29aaca28eefeb0d Step #5: Base64: ZG46b3U9U1VET0c= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1427 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2426507593 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557f6e6bd810, 0x557f6e8a701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557f6e8a7020,0x557f7073f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/645ee9c8268e4983279ba6bbb29aaca28eefeb0d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1637 processed earlier; will process 9392 files now Step #5: ==51406== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557f651b29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f6b817898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f6b7fa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f6b7fa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f651b8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f65119b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f65114355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f651aac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f68179f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f68179f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f68179f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f68179f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f68179f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f68179f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f68179f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f68179f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f68179f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f68179f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f6a40ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f6713bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f67146be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f66ef2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f66ef2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f66ef3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f66ef2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f66ef2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f66ef2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f6b7fcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f6b805928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f6b7ed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f6b818112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f209cb28082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f65112b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x5f,0x73,0x74,0xcd,0x8e,0x72,0x65,0x61,0x6d,0x62, Step #5: A_st\315\216reamb Step #5: artifact_prefix='./'; Test unit written to ./oom-4342d697f0c4a03406ca6b875025b6d1a748b8ec Step #5: Base64: QV9zdM2OcmVhbWI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1428 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2426955356 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564abbcd3810, 0x564abbebd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564abbebd020,0x564abdd550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4342d697f0c4a03406ca6b875025b6d1a748b8ec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1638 processed earlier; will process 9391 files now Step #5: ==51442== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564ab27c89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564ab8e2d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564ab8e105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564ab8e104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ab27ced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ab272fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ab272a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ab27c0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564ab578ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564ab578ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564ab578ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564ab578ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564ab578ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564ab578ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564ab578ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564ab578ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564ab578ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564ab578ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564ab7a24f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564ab4751b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564ab475cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564ab4508c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564ab4508c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564ab4509738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564ab4508874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564ab4508874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564ab4508874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564ab8e12abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564ab8e1b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564ab8e03699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564ab8e2e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5560380082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ab2728b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x22,0x22,0xf0,0x90,0x80,0xa0,0xf0,0x90,0x80,0xb8, Step #5: \016\"\"\360\220\200\240\360\220\200\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-d36d0f9fd8c6382dad37be33f284386e2d7ee312 Step #5: Base64: DiIi8JCAoPCQgLg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1429 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2427401865 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ede7b28810, 0x55ede7d1201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ede7d12020,0x55ede9baa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d36d0f9fd8c6382dad37be33f284386e2d7ee312' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1639 processed earlier; will process 9390 files now Step #5: ==51478== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55edde61d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ede4c82898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ede4c655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ede4c654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55edde623d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55edde584b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55edde57f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55edde615c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ede15e4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ede15e4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ede15e4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ede15e4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ede15e4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ede15e4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ede15e4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ede15e4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ede15e4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ede15e4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ede3879f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ede05a6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ede05b1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ede035dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ede035dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ede035e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ede035d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ede035d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ede035d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ede4c67abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ede4c70928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ede4c58699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ede4c83112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e2542c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55edde57db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x5b,0x5e,0x5c,0x53,0x5c,0x73,0x5d,0x7b,0x38,0x7d, Step #5: ^[^\\S\\s]{8} Step #5: artifact_prefix='./'; Test unit written to ./oom-bbb9dde05e43f10e3a6d1f5d6a8dd15073d10eb5 Step #5: Base64: XlteXFNcc117OH0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1430 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2427848994 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558becd70810, 0x558becf5a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558becf5a020,0x558beedf20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bbb9dde05e43f10e3a6d1f5d6a8dd15073d10eb5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1640 processed earlier; will process 9389 files now Step #5: #1 pulse cov: 3662 ft: 3663 exec/s: 0 rss: 167Mb Step #5: ==51514== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558be38659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558be9eca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558be9ead5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558be9ead4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558be386bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558be37ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558be37c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558be385dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558be682cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558be682cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558be682cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558be682cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558be682cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558be682cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558be682cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558be682cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558be682cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558be682cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558be8ac1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558be57eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558be57f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558be55a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558be55a5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558be55a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558be55a5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558be55a5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558be55a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558be9eafabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558be9eb8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558be9ea0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558be9ecb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb7a3db7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558be37c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x7d,0x5d,0xa,0x2c,0x5b,0xf0,0x90,0xb2,0x81,0x3d, Step #5: [}]\012,[\360\220\262\201= Step #5: artifact_prefix='./'; Test unit written to ./oom-7fbb3779a1d6ee1c7b4dad91edf4a1ca7c46d7ea Step #5: Base64: W31dCixb8JCygT0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1431 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2428338491 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fbcb983810, 0x55fbcbb6d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fbcbb6d020,0x55fbcda050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7fbb3779a1d6ee1c7b4dad91edf4a1ca7c46d7ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1642 processed earlier; will process 9387 files now Step #5: ==51550== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fbc24789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fbc8add898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fbc8ac05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fbc8ac04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fbc247ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fbc23dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fbc23da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fbc2470c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fbc543ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fbc543ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fbc543ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fbc543ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fbc543ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fbc543ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fbc543ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fbc543ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fbc543ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fbc543ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fbc76d4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fbc4401b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fbc440cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fbc41b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fbc41b8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fbc41b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fbc41b8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fbc41b8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fbc41b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fbc8ac2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fbc8acb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fbc8ab3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fbc8ade112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f57dc8cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fbc23d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3a,0x3e,0x26,0xe2,0x85,0xa3,0x26,0xe2,0x85,0xa3, Step #5: <:>&\342\205\243&\342\205\243 Step #5: artifact_prefix='./'; Test unit written to ./oom-ca991388288d004e44f7711356cd81cead1dd20d Step #5: Base64: PDo+JuKFoybihaM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1432 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2428781633 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563c957dd810, 0x563c959c701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563c959c7020,0x563c9785f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca991388288d004e44f7711356cd81cead1dd20d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1643 processed earlier; will process 9386 files now Step #5: #1 pulse cov: 3709 ft: 3710 exec/s: 0 rss: 165Mb Step #5: ==51586== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563c8c2d29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563c92937898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563c9291a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563c9291a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563c8c2d8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563c8c239b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563c8c234355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563c8c2cac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563c8f299f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563c8f299f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563c8f299f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563c8f299f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563c8f299f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563c8f299f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563c8f299f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563c8f299f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563c8f299f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563c8f299f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563c9152ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563c8e25bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563c8e266be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563c8e012c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563c8e012c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563c8e013738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563c8e012874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563c8e012874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563c8e012874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563c9291cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563c92925928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563c9290d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563c92938112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2974efd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563c8c232b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f, Step #5: ws:\315\217\315\217\315\217\315\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-3aa741ead5430d9da34787539d707ddebfeea57e Step #5: Base64: d3M6zY/Nj82PzY8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1433 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2429269024 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56459a087810, 0x56459a27101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56459a271020,0x56459c1090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3aa741ead5430d9da34787539d707ddebfeea57e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1645 processed earlier; will process 9384 files now Step #5: ==51622== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564590b7c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5645971e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5645971c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5645971c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564590b82d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564590ae3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564590ade355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564590b74c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564593b43f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564593b43f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564593b43f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564593b43f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564593b43f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564593b43f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564593b43f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564593b43f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564593b43f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564593b43f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564595dd8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564592b05b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564592b10be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5645928bcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5645928bcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5645928bd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5645928bc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5645928bc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5645928bc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5645971c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5645971cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5645971b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5645971e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a9b760082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564590adcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7,0x5c,0x24,0x5c,0x24,0xb,0x7e,0xde,0xad,0xbe,0xef, Step #5: \007\\$\\$\013~\336\255\276\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-05b3a475186b6e33d215638db031167be0afcd8a Step #5: Base64: B1wkXCQLft6tvu8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1434 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2429717079 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56147e471810, 0x56147e65b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56147e65b020,0x5614804f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/05b3a475186b6e33d215638db031167be0afcd8a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1646 processed earlier; will process 9383 files now Step #5: ==51658== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561474f669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56147b5cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56147b5ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56147b5ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561474f6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561474ecdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561474ec8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561474f5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561477f2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561477f2df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561477f2df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561477f2df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561477f2df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561477f2df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561477f2df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561477f2df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561477f2df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561477f2df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56147a1c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561476eefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561476efabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561476ca6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561476ca6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561476ca7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561476ca6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561476ca6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561476ca6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56147b5b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56147b5b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56147b5a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56147b5cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7545463082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561474ec6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd6,0xbb,0x0,0x0,0x0,0x0,0x0,0x0,0xbb,0xcc,0x44, Step #5: \326\273\000\000\000\000\000\000\273\314D Step #5: artifact_prefix='./'; Test unit written to ./oom-6583cc83733d84ff5bd6e7933b8f5e51db9d7f8d Step #5: Base64: 1rsAAAAAAAC7zEQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1435 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2430164215 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5630322a3810, 0x56303248d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56303248d020,0x5630343250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6583cc83733d84ff5bd6e7933b8f5e51db9d7f8d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1647 processed earlier; will process 9382 files now Step #5: ==51694== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563028d989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56302f3fd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56302f3e05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56302f3e04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563028d9ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563028cffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563028cfa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563028d90c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56302bd5ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56302bd5ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56302bd5ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56302bd5ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56302bd5ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56302bd5ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56302bd5ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56302bd5ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56302bd5ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56302bd5ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56302dff4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56302ad21b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56302ad2cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56302aad8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56302aad8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56302aad9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56302aad8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56302aad8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56302aad8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56302f3e2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56302f3eb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56302f3d3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56302f3fe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcac39c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563028cf8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x3,0x0,0x40,0x40,0x7f,0x7f,0x7f,0xc6, Step #5: ID3\003\000@@\177\177\177\306 Step #5: artifact_prefix='./'; Test unit written to ./oom-b7325a21639597abe5846153bc9304ffbe2dce3b Step #5: Base64: SUQzAwBAQH9/f8Y= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1436 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2430610518 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560ed49a0810, 0x560ed4b8a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560ed4b8a020,0x560ed6a220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7325a21639597abe5846153bc9304ffbe2dce3b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1648 processed earlier; will process 9381 files now Step #5: ==51730== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560ecb4959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560ed1afa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560ed1add5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560ed1add4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560ecb49bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560ecb3fcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560ecb3f7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560ecb48dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560ece45cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560ece45cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560ece45cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560ece45cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560ece45cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560ece45cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560ece45cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560ece45cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560ece45cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560ece45cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560ed06f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560ecd41eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560ecd429be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560ecd1d5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560ecd1d5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560ecd1d6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560ecd1d5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560ecd1d5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560ecd1d5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560ed1adfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560ed1ae8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560ed1ad0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560ed1afb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b10d97082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560ecb3f5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x12,0x0,0x12,0x0,0x12,0x0,0x12,0x0,0x12,0x0,0x12, Step #5: \022\000\022\000\022\000\022\000\022\000\022 Step #5: artifact_prefix='./'; Test unit written to ./oom-c10e1c946f988a5d4f8d6a6b4ebab5667d4c351a Step #5: Base64: EgASABIAEgASABI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1437 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2431057532 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55934ae4f810, 0x55934b03901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55934b039020,0x55934ced10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c10e1c946f988a5d4f8d6a6b4ebab5667d4c351a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1649 processed earlier; will process 9380 files now Step #5: #1 pulse cov: 3641 ft: 3642 exec/s: 0 rss: 167Mb Step #5: #2 pulse cov: 4117 ft: 4307 exec/s: 0 rss: 168Mb Step #5: ==51766== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5593419449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559347fa9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559347f8c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559347f8c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55934194ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5593418abb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5593418a6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55934193cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55934490bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55934490bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55934490bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55934490bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55934490bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55934490bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55934490bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55934490bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55934490bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55934490bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559346ba0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5593438cdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5593438d8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559343684c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559343684c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559343685738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559343684874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559343684874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559343684874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559347f8eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559347f97928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559347f7f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559347faa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fefffdfa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5593418a4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4c,0xa,0xa,0x0,0x71,0x26,0x2a,0xc2,0xad,0x2a,0xdb, Step #5: L\012\012\000q&*\302\255*\333 Step #5: artifact_prefix='./'; Test unit written to ./oom-98cb28ea96b55683ff807d4faff0976140ba06b2 Step #5: Base64: TAoKAHEmKsKtKts= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1438 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2431621362 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e9665b810, 0x559e9684501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e96845020,0x559e986dd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/98cb28ea96b55683ff807d4faff0976140ba06b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1653 processed earlier; will process 9376 files now Step #5: ==51802== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559e8d1509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e937b5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e937985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e937984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e8d156d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e8d0b7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e8d0b2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e8d148c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e90117f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e90117f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e90117f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e90117f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e90117f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e90117f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e90117f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e90117f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e90117f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e90117f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e923acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e8f0d9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e8f0e4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e8ee90c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e8ee90c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e8ee91738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e8ee90874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e8ee90874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e8ee90874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e9379aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e937a3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e9378b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e937b6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f07d1f34082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e8d0b0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x22,0x22,0x22,0x40,0x27,0x26,0x40,0x26,0x40,0x40, Step #5: \"\"\"\"@'&@&@@ Step #5: artifact_prefix='./'; Test unit written to ./oom-1b9f4d250019492bf9dca66fc7d944220eeec563 Step #5: Base64: IiIiIkAnJkAmQEA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1439 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2432072950 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ae7e6ee810, 0x55ae7e8d801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ae7e8d8020,0x55ae807700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b9f4d250019492bf9dca66fc7d944220eeec563' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1654 processed earlier; will process 9375 files now Step #5: #1 pulse cov: 3426 ft: 3427 exec/s: 0 rss: 165Mb Step #5: ==51838== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ae751e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ae7b848898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ae7b82b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ae7b82b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ae751e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ae7514ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ae75145355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ae751dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ae781aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ae781aaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ae781aaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ae781aaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ae781aaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ae781aaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ae781aaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ae781aaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ae781aaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ae781aaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ae7a43ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ae7716cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ae77177be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ae76f23c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ae76f23c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ae76f24738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ae76f23874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ae76f23874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ae76f23874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ae7b82dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ae7b836928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ae7b81e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ae7b849112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb2fe8b9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ae75143b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x5c,0x75,0x7b,0x32,0x7d,0x5c,0x75,0x7b,0x37,0x7d, Step #5: '\\u{2}\\u{7} Step #5: artifact_prefix='./'; Test unit written to ./oom-5191f9dc767b7f153640834433b22fc9aefbd77b Step #5: Base64: J1x1ezJ9XHV7N30= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1440 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2432577261 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e7a351a810, 0x55e7a370401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e7a3704020,0x55e7a559c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5191f9dc767b7f153640834433b22fc9aefbd77b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1656 processed earlier; will process 9373 files now Step #5: ==51874== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e79a00f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e7a0674898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7a06575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7a06574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e79a015d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e799f76b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e799f71355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e79a007c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e79cfd6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e79cfd6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e79cfd6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e79cfd6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e79cfd6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e79cfd6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e79cfd6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e79cfd6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e79cfd6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e79cfd6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e79f26bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e79bf98b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e79bfa3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e79bd4fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e79bd4fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e79bd50738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e79bd4f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e79bd4f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e79bd4f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e7a0659abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e7a0662928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e7a064a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e7a0675112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd492f9e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e799f6fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x45,0x3e,0x26,0xe2,0xbc,0xbc,0x26,0xe2,0xbc,0xbc, Step #5: &\342\274\274&\342\274\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-e71da275b02e80d0140f18885efb7a1547526041 Step #5: Base64: PEU+JuK8vCbivLw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1441 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2433034755 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56507540f810, 0x5650755f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5650755f9020,0x5650774910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e71da275b02e80d0140f18885efb7a1547526041' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1657 processed earlier; will process 9372 files now Step #5: ==51910== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56506bf049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565072569898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56507254c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56507254c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56506bf0ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56506be6bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56506be66355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56506befcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56506eecbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56506eecbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56506eecbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56506eecbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56506eecbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56506eecbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56506eecbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56506eecbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56506eecbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56506eecbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565071160f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56506de8db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56506de98be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56506dc44c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56506dc44c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56506dc45738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56506dc44874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56506dc44874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56506dc44874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56507254eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565072557928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56507253f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56507256a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8de0773082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56506be64b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xcd,0x8f,0xa,0x2d,0xcd,0x8f,0xa,0x2d,0xcd,0x8f, Step #5: -\315\217\012-\315\217\012-\315\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-cd56834b9bed5e4e5626de830c41d7c227420e22 Step #5: Base64: Lc2PCi3NjwotzY8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1442 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2433502880 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55996ff07810, 0x5599700f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5599700f1020,0x559971f890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd56834b9bed5e4e5626de830c41d7c227420e22' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1658 processed earlier; will process 9371 files now Step #5: ==51946== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5599669fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55996d061898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55996d0445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55996d0444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559966a02d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559966963b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55996695e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5599669f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5599699c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5599699c3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5599699c3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5599699c3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5599699c3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5599699c3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5599699c3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5599699c3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5599699c3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5599699c3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55996bc58f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559968985b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559968990be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55996873cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55996873cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55996873d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55996873c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55996873c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55996873c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55996d046abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55996d04f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55996d037699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55996d062112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a17b48082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55996695cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x25,0x60,0x16,0x0,0x3b,0x0,0x23,0x60,0x31,0xdb, Step #5: \000%`\026\000;\000#`1\333 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e4d0caa89fdb39377bb7be456864632c628aba3 Step #5: Base64: ACVgFgA7ACNgMds= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1443 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2434089801 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff18151810, 0x55ff1833b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff1833b020,0x55ff1a1d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e4d0caa89fdb39377bb7be456864632c628aba3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1659 processed earlier; will process 9370 files now Step #5: ==51982== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ff0ec469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff152ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff1528e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff1528e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff0ec4cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff0ebadb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff0eba8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff0ec3ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff11c0df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff11c0df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff11c0df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff11c0df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff11c0df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff11c0df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff11c0df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff11c0df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff11c0df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff11c0df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff13ea2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff10bcfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff10bdabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff10986c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff10986c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff10987738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff10986874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff10986874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff10986874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff15290abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff15299928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff15281699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff152ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb08e68082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff0eba6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x73,0x3a,0x70,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: \016ws:p\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-039f0b924cff5e7da4b527f850cf589ffc88ef1c Step #5: Base64: DndzOnDNhM2EzYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1444 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2434557222 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652f2282810, 0x5652f246c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652f246c020,0x5652f43040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/039f0b924cff5e7da4b527f850cf589ffc88ef1c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1660 processed earlier; will process 9369 files now Step #5: ==52018== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5652e8d779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652ef3dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652ef3bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652ef3bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5652e8d7dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5652e8cdeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5652e8cd9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5652e8d6fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5652ebd3ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5652ebd3ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5652ebd3ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5652ebd3ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5652ebd3ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5652ebd3ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5652ebd3ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5652ebd3ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5652ebd3ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5652ebd3ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652edfd3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5652ead00b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5652ead0bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652eaab7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652eaab7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652eaab8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652eaab7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652eaab7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652eaab7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652ef3c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652ef3ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652ef3b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652ef3dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbed93bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5652e8cd7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0x4,0x21,0xc,0x6f,0x6c,0x4,0x18,0xc,0x18,0xc, Step #5: \013\004!\014ol\004\030\014\030\014 Step #5: artifact_prefix='./'; Test unit written to ./oom-759b615f569d9b921d61c898e1ed367ddddc2533 Step #5: Base64: CwQhDG9sBBgMGAw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1445 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2435031435 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555c37480810, 0x555c3766a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555c3766a020,0x555c395020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/759b615f569d9b921d61c898e1ed367ddddc2533' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1661 processed earlier; will process 9368 files now Step #5: ==52054== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555c2df759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555c345da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555c345bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555c345bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555c2df7bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555c2dedcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555c2ded7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555c2df6dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555c30f3cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555c30f3cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555c30f3cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555c30f3cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555c30f3cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555c30f3cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555c30f3cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555c30f3cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555c30f3cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555c30f3cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555c331d1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555c2fefeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555c2ff09be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555c2fcb5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555c2fcb5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555c2fcb6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555c2fcb5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555c2fcb5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555c2fcb5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555c345bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555c345c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555c345b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555c345db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b5ca83082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555c2ded5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0x25,0x31,0xe2,0x80,0x8d,0xf3,0xa0,0x80,0x81,0x32, Step #5: i%1\342\200\215\363\240\200\2012 Step #5: artifact_prefix='./'; Test unit written to ./oom-92f7b6cd13e36fa0ef9a9c75b18c8d39c30c0b60 Step #5: Base64: aSUx4oCN86CAgTI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1446 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2435500222 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a734d77810, 0x55a734f6101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a734f61020,0x55a736df90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92f7b6cd13e36fa0ef9a9c75b18c8d39c30c0b60' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1662 processed earlier; will process 9367 files now Step #5: ==52090== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a72b86c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a731ed1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a731eb45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a731eb44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a72b872d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a72b7d3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a72b7ce355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a72b864c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a72e833f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a72e833f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a72e833f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a72e833f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a72e833f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a72e833f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a72e833f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a72e833f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a72e833f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a72e833f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a730ac8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a72d7f5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a72d800be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a72d5acc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a72d5acc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a72d5ad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a72d5ac874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a72d5ac874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a72d5ac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a731eb6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a731ebf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a731ea7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a731ed2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e0a6db082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a72b7ccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x4f,0xa,0x45,0x27,0x27,0x45,0x27,0x27,0x45,0x27, Step #5: dO\012E''E''E' Step #5: artifact_prefix='./'; Test unit written to ./oom-c269e29dd0a39768b3e89e12882733a495d96f5a Step #5: Base64: ZE8KRScnRScnRSc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1447 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2435973681 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55607e61d810, 0x55607e80701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55607e807020,0x55608069f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c269e29dd0a39768b3e89e12882733a495d96f5a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1663 processed earlier; will process 9366 files now Step #5: ==52126== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5560751129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55607b777898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55607b75a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55607b75a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556075118d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556075079b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556075074355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55607510ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5560780d9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5560780d9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5560780d9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5560780d9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5560780d9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5560780d9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5560780d9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5560780d9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5560780d9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5560780d9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55607a36ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55607709bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5560770a6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556076e52c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556076e52c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556076e53738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556076e52874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556076e52874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556076e52874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55607b75cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55607b765928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55607b74d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55607b778112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f57de7be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556075072b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x6d,0x61,0x6b,0x7f,0x44,0x4,0x6c, Step #5: ID3\004mak\177D\004l Step #5: artifact_prefix='./'; Test unit written to ./oom-ce4555078413b7c9ee70858d8b923aa4696250f8 Step #5: Base64: SUQzBG1ha39EBGw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1448 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2436443051 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0dab6a810, 0x55a0dad5401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0dad54020,0x55a0dcbec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce4555078413b7c9ee70858d8b923aa4696250f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1664 processed earlier; will process 9365 files now Step #5: ==52162== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a0d165f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0d7cc4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0d7ca75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0d7ca74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0d1665d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0d15c6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0d15c1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0d1657c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0d4626f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0d4626f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0d4626f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0d4626f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0d4626f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0d4626f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0d4626f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0d4626f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0d4626f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0d4626f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0d68bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0d35e8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0d35f3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0d339fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0d339fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0d33a0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0d339f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0d339f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0d339f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0d7ca9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0d7cb2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0d7c9a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0d7cc5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fce91375082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0d15bfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x61,0xd6,0x9c,0xd6,0xbd,0xd6,0x9c,0xd6,0x9c, Step #5: Step #5: Step #5: #0 0x55e4d28a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4d8f09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4d8eec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4d8eec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4d28aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4d280bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4d2806355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4d289cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4d586bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4d586bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4d586bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4d586bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4d586bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4d586bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4d586bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4d586bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4d586bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4d586bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4d7b00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4d482db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4d4838be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4d45e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4d45e4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4d45e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4d45e4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4d45e4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4d45e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4d8eeeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4d8ef7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4d8edf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4d8f0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f57600d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4d2804b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x9,0x2b,0xa,0x9,0x6d,0x6d,0x6d,0x6d,0x7c, Step #5: +\012\011+\012\011mmmm| Step #5: artifact_prefix='./'; Test unit written to ./oom-32b9ca87b4e91be6bcaceb5cf9e521f91d6fa2fa Step #5: Base64: KwoJKwoJbW1tbXw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1450 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2437455130 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5580ca897810, 0x5580caa8101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5580caa81020,0x5580cc9190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/32b9ca87b4e91be6bcaceb5cf9e521f91d6fa2fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1667 processed earlier; will process 9362 files now Step #5: ==52234== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5580c138c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5580c79f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5580c79d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5580c79d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5580c1392d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5580c12f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5580c12ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5580c1384c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5580c4353f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5580c4353f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5580c4353f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5580c4353f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5580c4353f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5580c4353f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5580c4353f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5580c4353f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5580c4353f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5580c4353f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5580c65e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5580c3315b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5580c3320be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580c30ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580c30ccc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580c30cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580c30cc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580c30cc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580c30cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5580c79d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5580c79df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5580c79c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5580c79f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f095a04d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5580c12ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x53,0x45,0x4c,0x65,0x63,0x74,0x29,0x46,0x6f,0x72, Step #5: (SELect)For Step #5: artifact_prefix='./'; Test unit written to ./oom-d42e4aad641f1483036d9d9abf702c7602a2ec49 Step #5: Base64: KFNFTGVjdClGb3I= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1451 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2437918931 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557aa001c810, 0x557aa020601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557aa0206020,0x557aa209e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d42e4aad641f1483036d9d9abf702c7602a2ec49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1668 processed earlier; will process 9361 files now Step #5: ==52270== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557a96b119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557a9d176898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557a9d1595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557a9d1594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557a96b17d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557a96a78b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557a96a73355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557a96b09c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557a99ad8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557a99ad8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557a99ad8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557a99ad8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557a99ad8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557a99ad8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557a99ad8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557a99ad8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557a99ad8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557a99ad8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557a9bd6df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557a98a9ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557a98aa5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557a98851c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557a98851c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557a98852738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557a98851874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557a98851874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557a98851874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557a9d15babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557a9d164928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557a9d14c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557a9d177112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5901fd2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557a96a71b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xde,0xbb,0x0,0x0,0x0,0x0,0x0,0x0,0xbb,0xcc,0x44, Step #5: \336\273\000\000\000\000\000\000\273\314D Step #5: artifact_prefix='./'; Test unit written to ./oom-602b67798ef323c04e35d307fde674020564e223 Step #5: Base64: 3rsAAAAAAAC7zEQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1452 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2438386940 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558bb4531810, 0x558bb471b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558bb471b020,0x558bb65b30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/602b67798ef323c04e35d307fde674020564e223' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1669 processed earlier; will process 9360 files now Step #5: ==52306== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558bab0269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558bb168b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558bb166e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558bb166e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558bab02cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558baaf8db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558baaf88355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558bab01ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558badfedf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558badfedf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558badfedf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558badfedf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558badfedf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558badfedf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558badfedf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558badfedf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558badfedf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558badfedf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558bb0282f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558bacfafb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558bacfbabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558bacd66c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558bacd66c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558bacd67738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558bacd66874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558bacd66874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558bacd66874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558bb1670abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558bb1679928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558bb1661699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558bb168c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f87c39d8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558baaf86b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x27,0x27,0xd8,0x98,0x27,0xd8,0x98,0x27,0x27,0x27, Step #5: '''\330\230'\330\230''' Step #5: artifact_prefix='./'; Test unit written to ./oom-fa0e77e378c8027b32751ddce9355dfb7b7a39ed Step #5: Base64: Jycn2Jgn2JgnJyc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1453 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2438850186 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55edc6d75810, 0x55edc6f5f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55edc6f5f020,0x55edc8df70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fa0e77e378c8027b32751ddce9355dfb7b7a39ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1670 processed earlier; will process 9359 files now Step #5: #1 pulse cov: 10233 ft: 10234 exec/s: 0 rss: 184Mb Step #5: ==52342== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55edbd86a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55edc3ecf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55edc3eb25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55edc3eb24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55edbd870d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55edbd7d1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55edbd7cc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55edbd862c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55edc0831f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55edc0831f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55edc0831f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55edc0831f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55edc0831f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55edc0831f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55edc0831f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55edc0831f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55edc0831f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55edc0831f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55edc2ac6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55edbf7f3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55edbf7febe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55edbf5aac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55edbf5aac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55edbf5ab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55edbf5aa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55edbf5aa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55edbf5aa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55edc3eb4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55edc3ebd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55edc3ea5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55edc3ed0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1f3902b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55edbd7cab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x57,0x73,0x3a,0x58,0x4e,0x2d,0x2d,0x35,0x68,0x31,0x48, Step #5: Ws:XN--5h1H Step #5: artifact_prefix='./'; Test unit written to ./oom-5df05b9624be1d54a635a2111b2bd0fef5a7f464 Step #5: Base64: V3M6WE4tLTVoMUg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1454 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2439382746 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f6a9fd6810, 0x55f6aa1c001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f6aa1c0020,0x55f6ac0580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5df05b9624be1d54a635a2111b2bd0fef5a7f464' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1672 processed earlier; will process 9357 files now Step #5: #1 pulse cov: 15480 ft: 15481 exec/s: 0 rss: 195Mb Step #5: ==52378== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f6a0acb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f6a7130898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f6a71135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f6a71134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f6a0ad1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f6a0a32b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f6a0a2d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f6a0ac3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f6a3a92f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f6a3a92f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f6a3a92f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f6a3a92f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f6a3a92f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f6a3a92f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f6a3a92f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f6a3a92f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f6a3a92f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f6a3a92f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f6a5d27f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f6a2a54b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f6a2a5fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f6a280bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f6a280bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f6a280c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f6a280b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f6a280b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f6a280b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f6a7115abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f6a711e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f6a7106699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f6a7131112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f696f1e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f6a0a2bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x3a,0x2f,0x2f,0xa,0xcd,0x84,0xcd,0x8f,0xcd,0x84, Step #5: o://\012\315\204\315\217\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-0987517a79e66c8e7eaf922d9e1543de64fed0fc Step #5: Base64: bzovLwrNhM2PzYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1455 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2440047640 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c585d82810, 0x55c585f6c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c585f6c020,0x55c587e040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0987517a79e66c8e7eaf922d9e1543de64fed0fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1674 processed earlier; will process 9355 files now Step #5: ==52414== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c57c8779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c582edc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c582ebf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c582ebf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c57c87dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c57c7deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c57c7d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c57c86fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c57f83ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c57f83ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c57f83ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c57f83ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c57f83ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c57f83ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c57f83ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c57f83ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c57f83ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c57f83ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c581ad3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c57e800b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c57e80bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c57e5b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c57e5b7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c57e5b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c57e5b7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c57e5b7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c57e5b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c582ec1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c582eca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c582eb2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c582edd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f03ccdda082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c57c7d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0x27,0xa,0x2a,0x2a,0x42,0x42,0xa,0xa,0x4,0xa, Step #5: c'\012**BB\012\012\004\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-f111670bb4e65bf3a8d1dd83058ffa0a1b15d0fa Step #5: Base64: YycKKipCQgoKBAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1456 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2440522308 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556ed27d2810, 0x556ed29bc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556ed29bc020,0x556ed48540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f111670bb4e65bf3a8d1dd83058ffa0a1b15d0fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1675 processed earlier; will process 9354 files now Step #5: ==52450== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556ec92c79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556ecf92c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556ecf90f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556ecf90f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556ec92cdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556ec922eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556ec9229355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556ec92bfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556ecc28ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556ecc28ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556ecc28ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556ecc28ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556ecc28ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556ecc28ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556ecc28ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556ecc28ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556ecc28ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556ecc28ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556ece523f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556ecb250b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556ecb25bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556ecb007c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556ecb007c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556ecb008738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556ecb007874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556ecb007874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556ecb007874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556ecf911abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556ecf91a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556ecf902699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556ecf92d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff416bd6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556ec9227b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4f,0x57,0x4e,0x45,0x52,0x3d,0x22,0xef,0xb8,0xae,0x22, Step #5: OWNER=\"\357\270\256\" Step #5: artifact_prefix='./'; Test unit written to ./oom-1ff144b027595ae52197461dc1819d3668fc9398 Step #5: Base64: T1dORVI9Iu+4riI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1457 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2440988138 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5636f88d5810, 0x5636f8abf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5636f8abf020,0x5636fa9570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ff144b027595ae52197461dc1819d3668fc9398' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1676 processed earlier; will process 9353 files now Step #5: ==52486== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5636ef3ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5636f5a2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636f5a125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636f5a124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5636ef3d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5636ef331b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5636ef32c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5636ef3c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5636f2391f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5636f2391f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5636f2391f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5636f2391f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5636f2391f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5636f2391f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5636f2391f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5636f2391f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5636f2391f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5636f2391f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5636f4626f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5636f1353b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5636f135ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5636f110ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5636f110ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5636f110b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5636f110a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5636f110a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5636f110a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5636f5a14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5636f5a1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5636f5a05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5636f5a30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5aa31f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5636ef32ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x2d,0x20,0x2d,0x3a,0x20,0xf5,0x3a,0x20,0x3a, Step #5: - - -: \365: : Step #5: artifact_prefix='./'; Test unit written to ./oom-4a07f050bdc31ca9da786b72cd487fe19ff59e22 Step #5: Base64: LSAtIC06IPU6IDo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1458 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2441446118 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564038ec8810, 0x5640390b201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640390b2020,0x56403af4a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4a07f050bdc31ca9da786b72cd487fe19ff59e22' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1677 processed earlier; will process 9352 files now Step #5: ==52522== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56402f9bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564036022898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640360055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640360054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56402f9c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56402f924b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56402f91f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56402f9b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564032984f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564032984f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564032984f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564032984f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564032984f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564032984f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564032984f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564032984f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564032984f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564032984f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564034c19f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564031946b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564031951be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5640316fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5640316fdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5640316fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5640316fd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5640316fd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5640316fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564036007abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564036010928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564035ff8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564036023112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8781544082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56402f91db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x42,0x7e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1f, Step #5: \000B~\000\000\000\000\000\000\000\037 Step #5: artifact_prefix='./'; Test unit written to ./oom-b13f2ff1da9650ea8d15c2c8e9e8399c27d17810 Step #5: Base64: AEJ+AAAAAAAAAB8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1459 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2441890717 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611bd09d810, 0x5611bd28701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5611bd287020,0x5611bf11f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b13f2ff1da9650ea8d15c2c8e9e8399c27d17810' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1678 processed earlier; will process 9351 files now Step #5: ==52558== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5611b3b929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5611ba1f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611ba1da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611ba1da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5611b3b98d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5611b3af9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5611b3af4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5611b3b8ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5611b6b59f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5611b6b59f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5611b6b59f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5611b6b59f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5611b6b59f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5611b6b59f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5611b6b59f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5611b6b59f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5611b6b59f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5611b6b59f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5611b8deef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611b5b1bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5611b5b26be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611b58d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611b58d2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611b58d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611b58d2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611b58d2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611b58d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5611ba1dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5611ba1e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611ba1cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5611ba1f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7febffe58082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5611b3af2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0x0,0x0,0x49,0x0,0x49,0x0,0x0,0x0,0x0,0x80, Step #5: \013\000\000I\000I\000\000\000\000\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-553334a500fa740007cd2eabad615a368f7f0808 Step #5: Base64: CwAASQBJAAAAAIA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1460 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2442345441 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fdf5ecc810, 0x55fdf60b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fdf60b6020,0x55fdf7f4e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/553334a500fa740007cd2eabad615a368f7f0808' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1679 processed earlier; will process 9350 files now Step #5: ==52594== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fdec9c19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fdf3026898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fdf30095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fdf30094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fdec9c7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fdec928b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fdec923355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fdec9b9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fdef988f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fdef988f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fdef988f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fdef988f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fdef988f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fdef988f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fdef988f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fdef988f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fdef988f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fdef988f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fdf1c1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fdee94ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fdee955be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fdee701c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fdee701c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fdee702738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fdee701874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fdee701874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fdee701874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fdf300babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fdf3014928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fdf2ffc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fdf3027112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8185e21082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fdec921b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xde,0xa2,0xdd,0x81,0xdf,0x80,0xdd,0x83,0xe2,0x80,0x8c,0x3f, Step #5: \336\242\335\201\337\200\335\203\342\200\214? Step #5: artifact_prefix='./'; Test unit written to ./oom-c62c4a196cac10dfedb73bf15fa633e40f80683e Step #5: Base64: 3qLdgd+A3YPigIw/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1461 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2442796371 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c553cba810, 0x55c553ea401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c553ea4020,0x55c555d3c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c62c4a196cac10dfedb73bf15fa633e40f80683e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1680 processed earlier; will process 9349 files now Step #5: ==52630== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c54a7af9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c550e14898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c550df75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c550df74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c54a7b5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c54a716b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c54a711355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c54a7a7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c54d776f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c54d776f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c54d776f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c54d776f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c54d776f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c54d776f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c54d776f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c54d776f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c54d776f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c54d776f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c54fa0bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c54c738b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c54c743be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c54c4efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c54c4efc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c54c4f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c54c4ef874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c54c4ef874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c54c4ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c550df9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c550e02928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c550dea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c550e15112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f72a14c2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c54a70fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xb5,0x8e,0xe0,0xa7,0xe0, Step #5: \340\250\216\340\250\216\340\265\216\340\247\340 Step #5: artifact_prefix='./'; Test unit written to ./oom-e8b3ee034c2ee7ab4c45dec25b50593aec9d3099 Step #5: Base64: 4KiO4KiO4LWO4Kfg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1462 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2443244811 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f86bba8810, 0x55f86bd9201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f86bd92020,0x55f86dc2a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e8b3ee034c2ee7ab4c45dec25b50593aec9d3099' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1681 processed earlier; will process 9348 files now Step #5: ==52666== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f86269d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f868d02898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f868ce55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f868ce54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8626a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f862604b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8625ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f862695c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f865664f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f865664f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f865664f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f865664f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f865664f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f865664f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f865664f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f865664f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f865664f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f865664f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f8678f9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f864626b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f864631be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8643ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8643ddc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8643de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8643dd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8643dd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8643dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f868ce7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f868cf0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f868cd8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f868d03112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd388dfd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8625fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x50,0xa,0xd,0x48,0xa,0xd,0x4a,0xa,0xd,0x48,0x8b, Step #5: HP\012\015H\012\015J\012\015H\213 Step #5: artifact_prefix='./'; Test unit written to ./oom-557427dce607abd1effa4930f8b010470e3c2f41 Step #5: Base64: SFAKDUgKDUoKDUiL Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1463 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2443695836 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558fa088a810, 0x558fa0a7401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558fa0a74020,0x558fa290c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/557427dce607abd1effa4930f8b010470e3c2f41' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1682 processed earlier; will process 9347 files now Step #5: ==52702== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558f9737f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558f9d9e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558f9d9c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558f9d9c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f97385d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f972e6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f972e1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f97377c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f9a346f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f9a346f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f9a346f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f9a346f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f9a346f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f9a346f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f9a346f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f9a346f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f9a346f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f9a346f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558f9c5dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f99308b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f99313be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f990bfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f990bfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f990c0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f990bf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f990bf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f990bf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558f9d9c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558f9d9d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558f9d9ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558f9d9e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f672e6dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f972dfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x12,0x25,0x73, Step #5: ~~~<\333\276~~~\022%s Step #5: artifact_prefix='./'; Test unit written to ./oom-f26a0dd23a86e83bc88a0280fd2fabeec2f31b2e Step #5: Base64: fn5+PNu+fn5+EiVz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1464 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2444146789 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cd0498c810, 0x55cd04b7601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cd04b76020,0x55cd06a0e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f26a0dd23a86e83bc88a0280fd2fabeec2f31b2e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1683 processed earlier; will process 9346 files now Step #5: ==52738== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ccfb4819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cd01ae6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cd01ac95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cd01ac94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ccfb487d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ccfb3e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ccfb3e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ccfb479c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ccfe448f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ccfe448f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ccfe448f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ccfe448f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ccfe448f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ccfe448f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ccfe448f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ccfe448f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ccfe448f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ccfe448f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cd006ddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ccfd40ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ccfd415be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ccfd1c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ccfd1c1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ccfd1c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ccfd1c1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ccfd1c1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ccfd1c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cd01acbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cd01ad4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cd01abc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cd01ae7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12de1f8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ccfb3e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0xe2,0x80,0xa8,0x2a,0x2a,0x2a,0xe2,0x80,0xa8,0x2a,0x2a, Step #5: *\342\200\250***\342\200\250** Step #5: artifact_prefix='./'; Test unit written to ./oom-e4363e1052b7b06cd569919625c9bed07d890526 Step #5: Base64: KuKAqCoqKuKAqCoq Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1465 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2444595409 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b731a6810, 0x561b7339001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b73390020,0x561b752280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e4363e1052b7b06cd569919625c9bed07d890526' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1684 processed earlier; will process 9345 files now Step #5: ==52774== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561b69c9b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b70300898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b702e35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b702e34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b69ca1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b69c02b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b69bfd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b69c93c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b6cc62f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b6cc62f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b6cc62f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b6cc62f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b6cc62f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b6cc62f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b6cc62f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b6cc62f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b6cc62f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b6cc62f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b6eef7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b6bc24b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b6bc2fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b6b9dbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b6b9dbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b6b9dc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b6b9db874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b6b9db874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b6b9db874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b702e5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b702ee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b702d6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b70301112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc5c9739082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b69bfbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x80,0xaf,0xe2,0x80,0xaf,0xe2,0x80,0xaf,0xd4,0xaf,0xa, Step #5: \342\200\257\342\200\257\342\200\257\324\257\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-f2df2e73c5ab6c8f923c549d9fc7be07cfddc87b Step #5: Base64: 4oCv4oCv4oCv1K8K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1466 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2445043439 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565228cb1810, 0x565228e9b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565228e9b020,0x56522ad330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f2df2e73c5ab6c8f923c549d9fc7be07cfddc87b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1685 processed earlier; will process 9344 files now Step #5: ==52810== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56521f7a69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565225e0b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565225dee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565225dee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56521f7acd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56521f70db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56521f708355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56521f79ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56522276df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56522276df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56522276df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56522276df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56522276df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56522276df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56522276df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56522276df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56522276df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56522276df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565224a02f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56522172fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56522173abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652214e6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652214e6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652214e7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652214e6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652214e6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652214e6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565225df0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565225df9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565225de1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565225e0c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fce72e35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56521f706b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcc,0x9b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xcc,0x9b,0xc8, Step #5: \314\233\000\000\000\000\000\000\000\314\233\310 Step #5: artifact_prefix='./'; Test unit written to ./oom-6e7f54b666453f0bee5e0850876c93acaf823d4e Step #5: Base64: zJsAAAAAAAAAzJvI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1467 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2445489542 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55942d94f810, 0x55942db3901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55942db39020,0x55942f9d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6e7f54b666453f0bee5e0850876c93acaf823d4e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1686 processed earlier; will process 9343 files now Step #5: ==52846== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5594244449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55942aaa9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55942aa8c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55942aa8c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55942444ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5594243abb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5594243a6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55942443cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55942740bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55942740bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55942740bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55942740bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55942740bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55942740bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55942740bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55942740bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55942740bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55942740bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5594296a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5594263cdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5594263d8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559426184c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559426184c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559426185738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559426184874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559426184874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559426184874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55942aa8eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55942aa97928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55942aa7f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55942aaaa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f87478cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5594243a4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x27,0x27,0x27,0x27,0x29,0x1,0x0,0x0,0xa,0x76,0x6d, Step #5: ''''')\001\000\000\012vm Step #5: artifact_prefix='./'; Test unit written to ./oom-83fff8e14fa120f75bf04e2ac136fa18f0b6a383 Step #5: Base64: JycnJycpAQAACnZt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1468 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2445950429 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f900303810, 0x55f9004ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f9004ed020,0x55f9023850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/83fff8e14fa120f75bf04e2ac136fa18f0b6a383' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1687 processed earlier; will process 9342 files now Step #5: ==52882== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f8f6df89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f8fd45d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8fd4405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8fd4404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8f6dfed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8f6d5fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8f6d5a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8f6df0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8f9dbff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8f9dbff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8f9dbff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8f9dbff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8f9dbff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8f9dbff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8f9dbff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8f9dbff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8f9dbff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8f9dbff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f8fc054f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f8f8d81b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f8f8d8cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8f8b38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8f8b38c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8f8b39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8f8b38874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8f8b38874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8f8b38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f8fd442abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f8fd44b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f8fd433699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f8fd45e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f799f521082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8f6d58b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x45,0x32,0x2e,0x31,0x31,0xea,0xa7,0x99,0x37,0x5c,0xab,0x5f, Step #5: E2.11\352\247\2317\\\253_ Step #5: artifact_prefix='./'; Test unit written to ./oom-1204bb6c1e3ee1544d1991db68e8a790f4a3084d Step #5: Base64: RTIuMTHqp5k3XKtf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1469 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2446399038 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5622b97a9810, 0x5622b999301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622b9993020,0x5622bb82b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1204bb6c1e3ee1544d1991db68e8a790f4a3084d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1688 processed earlier; will process 9341 files now Step #5: #1 pulse cov: 3800 ft: 3801 exec/s: 0 rss: 165Mb Step #5: ==52918== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5622b029e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5622b6903898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5622b68e65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5622b68e64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5622b02a4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5622b0205b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5622b0200355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5622b0296c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5622b3265f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5622b3265f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5622b3265f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5622b3265f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5622b3265f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5622b3265f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5622b3265f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5622b3265f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5622b3265f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5622b3265f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5622b54faf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5622b2227b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5622b2232be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5622b1fdec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5622b1fdec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5622b1fdf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5622b1fde874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5622b1fde874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5622b1fde874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5622b68e8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5622b68f1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5622b68d9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5622b6904112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0c4c914082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5622b01feb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x64,0xf0,0x91,0xa4,0xbd,0xf0,0x90,0xa4,0xb0, Step #5: ws:d\360\221\244\275\360\220\244\260 Step #5: artifact_prefix='./'; Test unit written to ./oom-61297663c108f0c8f969b82eb85d9f83eed57d9a Step #5: Base64: d3M6ZPCRpL3wkKSw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1470 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2446895015 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56149c759810, 0x56149c94301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56149c943020,0x56149e7db0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/61297663c108f0c8f969b82eb85d9f83eed57d9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1690 processed earlier; will process 9339 files now Step #5: #1 pulse cov: 3659 ft: 3660 exec/s: 0 rss: 165Mb Step #5: ==52954== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56149324e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5614998b3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5614998965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5614998964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561493254d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5614931b5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5614931b0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561493246c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561496215f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561496215f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561496215f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561496215f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561496215f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561496215f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561496215f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561496215f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561496215f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561496215f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5614984aaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5614951d7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5614951e2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561494f8ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561494f8ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561494f8f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561494f8e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561494f8e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561494f8e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561499898abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5614998a1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561499889699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5614998b4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e094ea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5614931aeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6,0xa,0x2d,0x20,0x2d,0x20,0x20,0x2d,0x2d,0xa,0x20,0x2d, Step #5: \006\012- - --\012 - Step #5: artifact_prefix='./'; Test unit written to ./oom-1f4e617a715d641b8cb78b36b89f632557891e0f Step #5: Base64: BgotIC0gIC0tCiAt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1471 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2447399817 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ba6eeb810, 0x559ba70d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ba70d5020,0x559ba8f6d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f4e617a715d641b8cb78b36b89f632557891e0f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1692 processed earlier; will process 9337 files now Step #5: ==52990== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559b9d9e09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ba4045898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ba40285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ba40284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b9d9e6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b9d947b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b9d942355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b9d9d8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ba09a7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ba09a7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ba09a7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ba09a7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ba09a7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ba09a7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ba09a7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ba09a7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ba09a7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ba09a7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ba2c3cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b9f969b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b9f974be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b9f720c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b9f720c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b9f721738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b9f720874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b9f720874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b9f720874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ba402aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ba4033928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ba401b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ba4046112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3aa69cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b9d940b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x3c,0x3d,0x6d,0x3c,0x24,0x3c,0xff,0xff,0xff,0x1f,0x3c, Step #5: $<=m<$<\377\377\377\037< Step #5: artifact_prefix='./'; Test unit written to ./oom-f708fc9e4bda9ee9594fa03d6c0d3d70c9db2c9e Step #5: Base64: JDw9bTwkPP///x88 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1472 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2447869070 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558d9eaad810, 0x558d9ec9701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558d9ec97020,0x558da0b2f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f708fc9e4bda9ee9594fa03d6c0d3d70c9db2c9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1693 processed earlier; will process 9336 files now Step #5: ==53026== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558d955a29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558d9bc07898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558d9bbea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558d9bbea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558d955a8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558d95509b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558d95504355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558d9559ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558d98569f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558d98569f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558d98569f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558d98569f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558d98569f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558d98569f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558d98569f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558d98569f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558d98569f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558d98569f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558d9a7fef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558d9752bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558d97536be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558d972e2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558d972e2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558d972e3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558d972e2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558d972e2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558d972e2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558d9bbecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558d9bbf5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558d9bbdd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558d9bc08112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd8c4ef9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558d95502b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x62,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x30,0xa, Step #5: \012b\"\"\"\"\"\"\"\"0\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-afc07de146d07dddeec3ce17428992ad5600b86b Step #5: Base64: CmIiIiIiIiIiIjAK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1473 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2448320618 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eab9457810, 0x55eab964101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eab9641020,0x55eabb4d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/afc07de146d07dddeec3ce17428992ad5600b86b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1694 processed earlier; will process 9335 files now Step #5: ==53062== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eaaff4c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eab65b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eab65945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eab65944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eaaff52d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eaafeb3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eaafeae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eaaff44c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eab2f13f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eab2f13f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eab2f13f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eab2f13f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eab2f13f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eab2f13f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eab2f13f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eab2f13f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eab2f13f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eab2f13f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eab51a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eab1ed5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eab1ee0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eab1c8cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eab1c8cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eab1c8d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eab1c8c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eab1c8c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eab1c8c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eab6596abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eab659f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eab6587699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eab65b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f76a1847082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eaafeacb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x23,0x7b,0x30,0x7d,0x29,0x7b,0xe2,0x80,0xad,0x31,0x7d, Step #5: (#{0}){\342\200\2551} Step #5: artifact_prefix='./'; Test unit written to ./oom-8a473f7a6e876a5d7eaf3a74a0fb9ee2ca12f0b7 Step #5: Base64: KCN7MH0pe+KArTF9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1474 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2448768518 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55579823a810, 0x55579842401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555798424020,0x55579a2bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8a473f7a6e876a5d7eaf3a74a0fb9ee2ca12f0b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1695 processed earlier; will process 9334 files now Step #5: ==53098== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55578ed2f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555795394898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557953775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557953774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55578ed35d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55578ec96b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55578ec91355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55578ed27c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555791cf6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555791cf6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555791cf6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555791cf6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555791cf6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555791cf6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555791cf6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555791cf6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555791cf6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555791cf6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555793f8bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555790cb8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555790cc3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555790a6fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555790a6fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555790a70738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555790a6f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555790a6f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555790a6f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555795379abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555795382928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55579536a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555795395112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f988744a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55578ec8fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x83,0x83,0xe3,0x83,0x8b,0xe3,0x83,0x83,0xe3,0x83,0x83, Step #5: \343\203\203\343\203\213\343\203\203\343\203\203 Step #5: artifact_prefix='./'; Test unit written to ./oom-ac5797009421e913091a23b60577d3841017d5fd Step #5: Base64: 44OD44OL44OD44OD Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1475 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2449217686 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563245a57810, 0x563245c4101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563245c41020,0x563247ad90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ac5797009421e913091a23b60577d3841017d5fd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1696 processed earlier; will process 9333 files now Step #5: ==53134== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56323c54c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563242bb1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563242b945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563242b944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56323c552d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56323c4b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56323c4ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56323c544c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56323f513f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56323f513f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56323f513f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56323f513f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56323f513f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56323f513f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56323f513f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56323f513f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56323f513f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56323f513f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5632417a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56323e4d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56323e4e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56323e28cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56323e28cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56323e28d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56323e28c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56323e28c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56323e28c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563242b96abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563242b9f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563242b87699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563242bb2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faad935d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56323c4acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x43,0x46,0x46,0x63,0x6f,0x63,0x6f,0x6e,0x75,0x74, Step #5: = CFFcoconut Step #5: artifact_prefix='./'; Test unit written to ./oom-a60c74963c2cdfb5d52e151ed2f3c730b39b9f6d Step #5: Base64: PSBDRkZjb2NvbnV0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1476 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2449668917 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3341cc810, 0x55a3343b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3343b6020,0x55a33624e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a60c74963c2cdfb5d52e151ed2f3c730b39b9f6d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1697 processed earlier; will process 9332 files now Step #5: ==53170== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a32acc19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a331326898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3313095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3313094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a32acc7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a32ac28b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a32ac23355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a32acb9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a32dc88f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a32dc88f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a32dc88f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a32dc88f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a32dc88f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a32dc88f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a32dc88f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a32dc88f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a32dc88f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a32dc88f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a32ff1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a32cc4ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a32cc55be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a32ca01c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a32ca01c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a32ca02738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a32ca01874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a32ca01874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a32ca01874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a33130babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a331314928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3312fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a331327112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0aa722c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a32ac21b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x5c,0xa,0x24,0x5c,0xa,0x24,0x6e,0xa,0x24,0x6e,0xa, Step #5: $\\\012$\\\012$n\012$n\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-82c40ece00c6b531efe880c5bb7a4c327161d854 Step #5: Base64: JFwKJFwKJG4KJG4K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1477 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2450126714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563bb1a2b810, 0x563bb1c1501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563bb1c15020,0x563bb3aad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/82c40ece00c6b531efe880c5bb7a4c327161d854' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1698 processed earlier; will process 9331 files now Step #5: ==53206== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563ba85209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563baeb85898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563baeb685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563baeb684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563ba8526d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563ba8487b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563ba8482355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563ba8518c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563bab4e7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563bab4e7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563bab4e7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563bab4e7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563bab4e7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563bab4e7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563bab4e7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563bab4e7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563bab4e7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563bab4e7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563bad77cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563baa4a9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563baa4b4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563baa260c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563baa260c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563baa261738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563baa260874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563baa260874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563baa260874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563baeb6aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563baeb73928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563baeb5b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563baeb86112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f05715ec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563ba8480b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x24,0x0,0x0,0x0,0x0,0x0,0x24,0x0,0x0,0x0,0x0, Step #5: \000$\000\000\000\000\000$\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb25ac7bf7f00351c1e764f12b0a6c91e64ec52c Step #5: Base64: ACQAAAAAACQAAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1478 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2450579189 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563b0016d810, 0x563b0035701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563b00357020,0x563b021ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb25ac7bf7f00351c1e764f12b0a6c91e64ec52c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1699 processed earlier; will process 9330 files now Step #5: ==53242== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563af6c629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563afd2c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563afd2aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563afd2aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563af6c68d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563af6bc9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563af6bc4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563af6c5ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563af9c29f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563af9c29f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563af9c29f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563af9c29f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563af9c29f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563af9c29f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563af9c29f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563af9c29f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563af9c29f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563af9c29f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563afbebef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563af8bebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563af8bf6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563af89a2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563af89a2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563af89a3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563af89a2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563af89a2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563af89a2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563afd2acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563afd2b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563afd29d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563afd2c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5106ee3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563af6bc2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x8,0xf0,0x91,0xa5,0x81,0xf0,0x91,0x9b,0x82, Step #5: \000\000\000\010\360\221\245\201\360\221\233\202 Step #5: artifact_prefix='./'; Test unit written to ./oom-25f867ed24b4390d4cddc9a3986bd7dc3bb8e53d Step #5: Base64: AAAACPCRpYHwkZuC Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1479 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2451043704 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b513e14810, 0x55b513ffe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b513ffe020,0x55b515e960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/25f867ed24b4390d4cddc9a3986bd7dc3bb8e53d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1700 processed earlier; will process 9329 files now Step #5: ==53278== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b50a9099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b510f6e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b510f515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b510f514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b50a90fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b50a870b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b50a86b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b50a901c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b50d8d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b50d8d0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b50d8d0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b50d8d0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b50d8d0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b50d8d0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b50d8d0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b50d8d0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b50d8d0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b50d8d0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b50fb65f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b50c892b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b50c89dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b50c649c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b50c649c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b50c64a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b50c649874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b50c649874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b50c649874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b510f53abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b510f5c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b510f44699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b510f6f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fca3d0d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b50a869b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x3a,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d, Step #5: r:\015- - - - - Step #5: artifact_prefix='./'; Test unit written to ./oom-4a13d9be6ef0ae395c9ed9582742b051749050d2 Step #5: Base64: cjoNLSAtIC0gLSAt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1480 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2451507714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b2dc72810, 0x557b2de5c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b2de5c020,0x557b2fcf40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4a13d9be6ef0ae395c9ed9582742b051749050d2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1701 processed earlier; will process 9328 files now Step #5: ==53314== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557b247679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b2adcc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b2adaf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b2adaf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b2476dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b246ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b246c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b2475fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b2772ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b2772ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b2772ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b2772ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b2772ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b2772ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b2772ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b2772ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b2772ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b2772ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b299c3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b266f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b266fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b264a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b264a7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b264a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b264a7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b264a7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b264a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b2adb1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b2adba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b2ada2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b2adcd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd597441082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b246c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcc,0x9b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xae,0xd5,0xc8, Step #5: \314\233\000\000\000\000\000\000\000\256\325\310 Step #5: artifact_prefix='./'; Test unit written to ./oom-8b9263584704fef03b91abd51ea8a5fbbfb621b5 Step #5: Base64: zJsAAAAAAAAArtXI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1481 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2451956357 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563112535810, 0x56311271f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56311271f020,0x5631145b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8b9263584704fef03b91abd51ea8a5fbbfb621b5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1702 processed earlier; will process 9327 files now Step #5: ==53350== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56310902a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56310f68f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56310f6725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56310f6724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563109030d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563108f91b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563108f8c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563109022c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56310bff1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56310bff1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56310bff1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56310bff1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56310bff1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56310bff1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56310bff1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56310bff1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56310bff1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56310bff1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56310e286f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56310afb3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56310afbebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56310ad6ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56310ad6ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56310ad6b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56310ad6a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56310ad6a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56310ad6a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56310f674abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56310f67d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56310f665699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56310f690112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf166c6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563108f8ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xa4,0xbe,0xe0,0xa4,0xbe,0xe0,0xa4,0xbe,0xe0,0xa4,0xbe, Step #5: \340\244\276\340\244\276\340\244\276\340\244\276 Step #5: artifact_prefix='./'; Test unit written to ./oom-7f3ce3dff7a469c938fbb55c797aec37e9a8ef94 Step #5: Base64: 4KS+4KS+4KS+4KS+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1482 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2452408865 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561392bb4810, 0x561392d9e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561392d9e020,0x561394c360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f3ce3dff7a469c938fbb55c797aec37e9a8ef94' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1703 processed earlier; will process 9326 files now Step #5: ==53386== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5613896a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56138fd0e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56138fcf15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56138fcf14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5613896afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561389610b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56138960b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5613896a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56138c670f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56138c670f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56138c670f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56138c670f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56138c670f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56138c670f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56138c670f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56138c670f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56138c670f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56138c670f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56138e905f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56138b632b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56138b63dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56138b3e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56138b3e9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56138b3ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56138b3e9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56138b3e9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56138b3e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56138fcf3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56138fcfc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56138fce4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56138fd0f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feebf1df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561389609b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x1e,0x48,0x1e,0x1e,0x1e,0x1e,0xf6,0xc3, Step #5: ID3\004\036H\036\036\036\036\366\303 Step #5: artifact_prefix='./'; Test unit written to ./oom-64d732ec1054d4f9ede039f906e72aac771ad802 Step #5: Base64: SUQzBB5IHh4eHvbD Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1483 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2452868433 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fd5b39a810, 0x55fd5b58401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fd5b584020,0x55fd5d41c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/64d732ec1054d4f9ede039f906e72aac771ad802' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1704 processed earlier; will process 9325 files now Step #5: ==53422== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fd51e8f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fd584f4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fd584d75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fd584d74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fd51e95d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fd51df6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fd51df1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fd51e87c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fd54e56f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fd54e56f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fd54e56f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fd54e56f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fd54e56f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fd54e56f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fd54e56f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fd54e56f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fd54e56f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fd54e56f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fd570ebf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fd53e18b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fd53e23be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fd53bcfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fd53bcfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fd53bd0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fd53bcf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fd53bcf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fd53bcf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fd584d9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fd584e2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fd584ca699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fd584f5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a1b4f3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fd51defb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0x22,0x8,0xa,0x6,0x2f,0x2f,0xc,0xe3,0x80,0x88, Step #5: \012\012\"\010\012\006//\014\343\200\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-fe837cadc64819056e5a67010f2236d9d6cfa481 Step #5: Base64: CgoiCAoGLy8M44CI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1484 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2453326210 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563c69941810, 0x563c69b2b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563c69b2b020,0x563c6b9c30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fe837cadc64819056e5a67010f2236d9d6cfa481' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1705 processed earlier; will process 9324 files now Step #5: ==53458== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563c604369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563c66a9b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563c66a7e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563c66a7e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563c6043cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563c6039db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563c60398355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563c6042ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563c633fdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563c633fdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563c633fdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563c633fdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563c633fdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563c633fdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563c633fdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563c633fdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563c633fdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563c633fdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563c65692f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563c623bfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563c623cabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563c62176c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563c62176c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563c62177738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563c62176874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563c62176874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563c62176874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563c66a80abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563c66a89928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563c66a71699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563c66a9c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff114fcc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563c60396b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x11,0x23,0x22,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x22, Step #5: \021#\"\\P\\P\\P\\P\" Step #5: artifact_prefix='./'; Test unit written to ./oom-b1f979b4c279d165ce0b29521ee3373013ef1088 Step #5: Base64: ESMiXFBcUFxQXFAi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1485 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2453780467 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563c50108810, 0x563c502f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563c502f2020,0x563c5218a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b1f979b4c279d165ce0b29521ee3373013ef1088' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1706 processed earlier; will process 9323 files now Step #5: ==53494== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563c46bfd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563c4d262898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563c4d2455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563c4d2454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563c46c03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563c46b64b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563c46b5f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563c46bf5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563c49bc4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563c49bc4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563c49bc4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563c49bc4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563c49bc4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563c49bc4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563c49bc4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563c49bc4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563c49bc4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563c49bc4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563c4be59f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563c48b86b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563c48b91be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563c4893dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563c4893dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563c4893e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563c4893d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563c4893d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563c4893d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563c4d247abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563c4d250928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563c4d238699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563c4d263112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb668eb0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563c46b5db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x0,0x2,0x1,0x0,0x1,0x2,0x0,0x1,0x2,0x0,0x2, Step #5: \001\000\002\001\000\001\002\000\001\002\000\002 Step #5: artifact_prefix='./'; Test unit written to ./oom-b111540f75c51a429ac3b2040cc6c85d14d24c45 Step #5: Base64: AQACAQABAgABAgAC Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1486 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2454235697 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8467b6810, 0x55c8469a001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c8469a0020,0x55c8488380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b111540f75c51a429ac3b2040cc6c85d14d24c45' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1707 processed earlier; will process 9322 files now Step #5: #1 pulse cov: 3627 ft: 3628 exec/s: 0 rss: 167Mb Step #5: ==53530== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c83d2ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c843910898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8438f35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8438f34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c83d2b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c83d212b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c83d20d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c83d2a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c840272f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c840272f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c840272f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c840272f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c840272f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c840272f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c840272f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c840272f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c840272f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c840272f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c842507f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c83f234b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c83f23fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c83efebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c83efebc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c83efec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c83efeb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c83efeb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c83efeb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8438f5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8438fe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8438e6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c843911112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b89369082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c83d20bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x27,0x21,0x24,0x27,0x21,0x31,0x24,0x36,0x31,0x24,0x36, Step #5: $'!$'!1$61$6 Step #5: artifact_prefix='./'; Test unit written to ./oom-0f65d1be16f6d560846a04db2627ab8c9f5f71cd Step #5: Base64: JCchJCchMSQ2MSQ2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1487 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2454735993 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec59cf4810, 0x55ec59ede01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec59ede020,0x55ec5bd760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0f65d1be16f6d560846a04db2627ab8c9f5f71cd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1709 processed earlier; will process 9320 files now Step #5: ==53566== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ec507e99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec56e4e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec56e315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec56e314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec507efd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec50750b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec5074b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec507e1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec537b0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec537b0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec537b0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec537b0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec537b0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec537b0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec537b0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec537b0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec537b0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec537b0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec55a45f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec52772b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec5277dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec52529c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec52529c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec5252a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec52529874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec52529874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec52529874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec56e33abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec56e3c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec56e24699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec56e4f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd02ab1e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec50749b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0x2b,0x73,0x63,0xd,0x74,0x20,0xe2,0x80,0xae,0xd2,0x84, Step #5: &+sc\015t \342\200\256\322\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-c1624df2e259e8dc7d703ec7277e3940e0cae85f Step #5: Base64: JitzYw10IOKArtKE Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1488 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2455192179 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557e964e0810, 0x557e966ca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557e966ca020,0x557e985620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c1624df2e259e8dc7d703ec7277e3940e0cae85f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1710 processed earlier; will process 9319 files now Step #5: ==53602== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557e8cfd59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557e9363a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557e9361d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557e9361d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557e8cfdbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557e8cf3cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557e8cf37355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557e8cfcdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557e8ff9cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557e8ff9cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557e8ff9cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557e8ff9cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557e8ff9cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557e8ff9cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557e8ff9cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557e8ff9cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557e8ff9cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557e8ff9cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557e92231f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557e8ef5eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557e8ef69be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557e8ed15c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557e8ed15c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557e8ed16738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557e8ed15874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557e8ed15874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557e8ed15874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557e9361fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557e93628928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557e93610699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557e9363b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f24f5463082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557e8cf35b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6,0x2e,0x20,0x2f,0xa,0x2e,0x20,0x32,0xde,0xad,0xbe,0xef, Step #5: \006. /\012. 2\336\255\276\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-315922eed0a17fc882e55181c64874585e840eca Step #5: Base64: Bi4gLwouIDLerb7v Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1489 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2455646765 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564a7a604810, 0x564a7a7ee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564a7a7ee020,0x564a7c6860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/315922eed0a17fc882e55181c64874585e840eca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1711 processed earlier; will process 9318 files now Step #5: ==53638== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564a710f99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564a7775e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564a777415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564a777414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564a710ffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564a71060b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564a7105b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564a710f1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564a740c0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564a740c0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564a740c0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564a740c0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564a740c0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564a740c0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564a740c0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564a740c0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564a740c0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564a740c0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564a76355f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564a73082b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564a7308dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564a72e39c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564a72e39c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564a72e3a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564a72e39874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564a72e39874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564a72e39874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564a77743abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564a7774c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564a77734699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564a7775f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe6a865e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564a71059b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9e,0x80,0x82,0xf0,0x9e,0x80,0x82,0xf0,0x9e,0x80,0x82, Step #5: \360\236\200\202\360\236\200\202\360\236\200\202 Step #5: artifact_prefix='./'; Test unit written to ./oom-6d09f8481a19b1666f26176864e2ac16c1177ea2 Step #5: Base64: 8J6AgvCegILwnoCC Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1490 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2456101844 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5583037d7810, 0x5583039c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5583039c1020,0x5583058590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6d09f8481a19b1666f26176864e2ac16c1177ea2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1712 processed earlier; will process 9317 files now Step #5: ==53674== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5582fa2cc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558300931898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583009145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583009144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5582fa2d2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5582fa233b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5582fa22e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5582fa2c4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5582fd293f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5582fd293f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5582fd293f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5582fd293f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5582fd293f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5582fd293f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5582fd293f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5582fd293f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5582fd293f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5582fd293f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5582ff528f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5582fc255b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5582fc260be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5582fc00cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5582fc00cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5582fc00d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5582fc00c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5582fc00c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5582fc00c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558300916abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55830091f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558300907699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558300932112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f54af093082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5582fa22cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x24,0x60,0x5b,0xc,0x6a,0x5d,0xdf,0xff,0xdf,0x70,0x73, Step #5: `$`[\014j]\337\377\337ps Step #5: artifact_prefix='./'; Test unit written to ./oom-6ebbb0a3c098d6ae973bf1a76b04b2294ad0feb7 Step #5: Base64: YCRgWwxqXd//33Bz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1491 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2456680002 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5605aa797810, 0x5605aa98101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5605aa981020,0x5605ac8190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ebbb0a3c098d6ae973bf1a76b04b2294ad0feb7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1713 processed earlier; will process 9316 files now Step #5: ==53710== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5605a128c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605a78f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605a78d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605a78d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5605a1292d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605a11f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5605a11ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5605a1284c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605a4253f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605a4253f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605a4253f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605a4253f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605a4253f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605a4253f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605a4253f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605a4253f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605a4253f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605a4253f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605a64e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5605a3215b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5605a3220be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5605a2fccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5605a2fccc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5605a2fcd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5605a2fcc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5605a2fcc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5605a2fcc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605a78d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5605a78df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605a78c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605a78f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa2f052c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5605a11ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x9,0x22,0xd6,0xa6,0xd6,0xa6,0xd6,0xa6,0xd6,0x59, Step #5: HU\011\"\326\246\326\246\326\246\326Y Step #5: artifact_prefix='./'; Test unit written to ./oom-e361527dc9cc9aef912ac813e4940423df4c333c Step #5: Base64: SFUJItam1qbWptZZ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1492 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2457135096 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd95008810, 0x55dd951f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd951f2020,0x55dd9708a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e361527dc9cc9aef912ac813e4940423df4c333c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1714 processed earlier; will process 9315 files now Step #5: ==53746== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dd8bafd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd92162898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd921455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd921454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dd8bb03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dd8ba64b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dd8ba5f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dd8baf5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd8eac4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd8eac4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd8eac4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd8eac4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd8eac4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd8eac4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd8eac4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd8eac4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd8eac4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd8eac4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd90d59f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dd8da86b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dd8da91be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dd8d83dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dd8d83dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dd8d83e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dd8d83d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dd8d83d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dd8d83d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd92147abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd92150928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd92138699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd92163112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f87a900c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dd8ba5db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81, Step #5: ws:\340\276\201\340\276\201\340\276\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-68a8b23cfaee0179f2a77e412e748695f6611743 Step #5: Base64: d3M64L6B4L6B4L6B Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1493 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2457596384 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1d055b810, 0x55a1d074501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1d0745020,0x55a1d25dd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/68a8b23cfaee0179f2a77e412e748695f6611743' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1715 processed earlier; will process 9314 files now Step #5: ==53782== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a1c70509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1cd6b5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1cd6985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1cd6984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1c7056d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1c6fb7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1c6fb2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1c7048c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1ca017f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1ca017f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1ca017f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1ca017f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1ca017f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1ca017f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1ca017f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1ca017f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1ca017f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1ca017f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1cc2acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1c8fd9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1c8fe4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1c8d90c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1c8d90c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1c8d91738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1c8d90874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1c8d90874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1c8d90874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a1cd69aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a1cd6a3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1cd68b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1cd6b6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2949e78082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1c6fb0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x40,0x7b,0x22,0x22,0x3a,0x2d,0x30,0x38,0x45,0x30,0x31,0x2e, Step #5: @{\"\":-08E01. Step #5: artifact_prefix='./'; Test unit written to ./oom-545b48dd33e76decda24753e14fbb4ebb20663db Step #5: Base64: QHsiIjotMDhFMDEu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1494 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2458048518 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f16b24c810, 0x55f16b43601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f16b436020,0x55f16d2ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/545b48dd33e76decda24753e14fbb4ebb20663db' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1716 processed earlier; will process 9313 files now Step #5: ==53818== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f161d419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f1683a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1683895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1683894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f161d47d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f161ca8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f161ca3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f161d39c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f164d08f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f164d08f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f164d08f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f164d08f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f164d08f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f164d08f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f164d08f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f164d08f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f164d08f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f164d08f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f166f9df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f163ccab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f163cd5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f163a81c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f163a81c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f163a82738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f163a81874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f163a81874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f163a81874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f16838babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f168394928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f16837c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f1683a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8f236a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f161ca1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0xa,0x3c,0xa,0x3a,0x3d,0x3f,0x3f,0x7a,0x3f,0x3f,0x3d, Step #5: \016\012<\012:=??z??= Step #5: artifact_prefix='./'; Test unit written to ./oom-610e9ef1a1ad40b62f060f31efc8387cc9246c32 Step #5: Base64: Dgo8Cjo9Pz96Pz89 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1495 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2458504512 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55de4ce07810, 0x55de4cff101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55de4cff1020,0x55de4ee890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/610e9ef1a1ad40b62f060f31efc8387cc9246c32' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1717 processed earlier; will process 9312 files now Step #5: ==53854== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55de438fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55de49f61898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55de49f445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55de49f444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55de43902d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55de43863b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55de4385e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55de438f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55de468c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55de468c3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55de468c3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55de468c3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55de468c3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55de468c3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55de468c3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55de468c3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55de468c3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55de468c3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55de48b58f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55de45885b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55de45890be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55de4563cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55de4563cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55de4563d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55de4563c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55de4563c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55de4563c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55de49f46abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55de49f4f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55de49f37699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55de49f62112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcaef0dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55de4385cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x45,0x3a,0x45,0x3a,0x3e,0x3c,0x2f,0x45,0x3a,0x45,0x3a, Step #5: Step #5: Step #5: #0 0x5556b142c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5556b7a91898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556b7a745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556b7a744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5556b1432d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5556b1393b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5556b138e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5556b1424c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5556b43f3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5556b43f3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5556b43f3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5556b43f3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5556b43f3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5556b43f3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5556b43f3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5556b43f3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5556b43f3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5556b43f3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5556b6688f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5556b33b5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5556b33c0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5556b316cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5556b316cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5556b316d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5556b316c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5556b316c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5556b316c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5556b7a76abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5556b7a7f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5556b7a67699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5556b7a92112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f14e71de082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5556b138cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0x26,0xa,0x31,0x0,0x1e,0xd8,0xae,0x2d,0x0,0x0,0x25, Step #5: i&\0121\000\036\330\256-\000\000% Step #5: artifact_prefix='./'; Test unit written to ./oom-4002dc4e7a19df9ce4fe949cd4e56f8f9922e665 Step #5: Base64: aSYKMQAe2K4tAAAl Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1497 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2459415443 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b94e99810, 0x561b9508301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b95083020,0x561b96f1b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4002dc4e7a19df9ce4fe949cd4e56f8f9922e665' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1719 processed earlier; will process 9310 files now Step #5: ==53926== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561b8b98e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b91ff3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b91fd65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b91fd64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b8b994d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b8b8f5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b8b8f0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b8b986c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b8e955f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b8e955f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b8e955f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b8e955f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b8e955f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b8e955f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b8e955f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b8e955f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b8e955f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b8e955f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b90beaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b8d917b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b8d922be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b8d6cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b8d6cec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b8d6cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b8d6ce874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b8d6ce874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b8d6ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b91fd8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b91fe1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b91fc9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b91ff4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff130af9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b8b8eeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdc,0x8c,0xe,0x27,0x9,0x0,0xa,0xa,0xe,0x27,0x9,0x33, Step #5: \334\214\016'\011\000\012\012\016'\0113 Step #5: artifact_prefix='./'; Test unit written to ./oom-1b4ce532f291bfffa855988d80ab6afa405c5a16 Step #5: Base64: 3IwOJwkACgoOJwkz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1498 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2459870500 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647012b7810, 0x5647014a101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5647014a1020,0x5647033390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b4ce532f291bfffa855988d80ab6afa405c5a16' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1720 processed earlier; will process 9309 files now Step #5: ==53962== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5646f7dac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5646fe411898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5646fe3f45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5646fe3f44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5646f7db2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5646f7d13b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5646f7d0e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5646f7da4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5646fad73f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5646fad73f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5646fad73f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5646fad73f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5646fad73f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5646fad73f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5646fad73f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5646fad73f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5646fad73f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5646fad73f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5646fd008f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5646f9d35b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5646f9d40be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5646f9aecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5646f9aecc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5646f9aed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5646f9aec874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5646f9aec874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5646f9aec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5646fe3f6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5646fe3ff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5646fe3e7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5646fe412112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1fc4f64082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5646f7d0cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x81,0x88,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xaa, Step #5: \363\240\201\210\363\252\252\252\363\252\252\252 Step #5: artifact_prefix='./'; Test unit written to ./oom-6a86c4de2baed0a84206bec3ce553e29f04f2c49 Step #5: Base64: 86CBiPOqqqrzqqqq Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1499 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2460321792 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55559a138810, 0x55559a32201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55559a322020,0x55559c1ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a86c4de2baed0a84206bec3ce553e29f04f2c49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1721 processed earlier; will process 9308 files now Step #5: ==53998== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555590c2d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555597292898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5555972755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5555972754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555590c33d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555590b94b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555590b8f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555590c25c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555593bf4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555593bf4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555593bf4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555593bf4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555593bf4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555593bf4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555593bf4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555593bf4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555593bf4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555593bf4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555595e89f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555592bb6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555592bc1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55559296dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55559296dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55559296e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55559296d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55559296d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55559296d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555597277abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555597280928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555597268699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555597293112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1436c81082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555590b8db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4f,0x57,0x4e,0x45,0x52,0x3d,0x22,0x72,0x6f,0x6f,0x74,0x22, Step #5: OWNER=\"root\" Step #5: artifact_prefix='./'; Test unit written to ./oom-6110c655e3bef2eba5557e80243310a24eb57d70 Step #5: Base64: T1dORVI9InJvb3Qi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1500 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2460777123 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5626e191c810, 0x5626e1b0601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5626e1b06020,0x5626e399e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6110c655e3bef2eba5557e80243310a24eb57d70' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1722 processed earlier; will process 9307 files now Step #5: ==54034== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5626d84119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5626dea76898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5626dea595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5626dea594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5626d8417d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5626d8378b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5626d8373355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5626d8409c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5626db3d8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5626db3d8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5626db3d8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5626db3d8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5626db3d8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5626db3d8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5626db3d8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5626db3d8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5626db3d8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5626db3d8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5626dd66df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5626da39ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5626da3a5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5626da151c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5626da151c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5626da152738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5626da151874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5626da151874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5626da151874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5626dea5babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5626dea64928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5626dea4c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5626dea77112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6bc9b57082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5626d8371b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x36,0x2,0x0,0x0,0x29,0x1,0x0,0x0,0x29,0x55,0xdc,0x83, Step #5: 6\002\000\000)\001\000\000)U\334\203 Step #5: artifact_prefix='./'; Test unit written to ./oom-af35043e036250fc66016ad668d56ecaa387ecc8 Step #5: Base64: NgIAACkBAAApVdyD Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1501 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2461224921 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56215ed58810, 0x56215ef4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56215ef42020,0x562160dda0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af35043e036250fc66016ad668d56ecaa387ecc8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1723 processed earlier; will process 9306 files now Step #5: ==54070== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56215584d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56215beb2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56215be955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56215be954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562155853d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5621557b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5621557af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562155845c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562158814f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562158814f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562158814f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562158814f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562158814f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562158814f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562158814f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562158814f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562158814f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562158814f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56215aaa9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5621577d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5621577e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56215758dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56215758dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56215758e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56215758d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56215758d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56215758d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56215be97abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56215bea0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56215be88699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56215beb3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e1187e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5621557adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x84,0x91,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0, Step #5: \341\204\221\341\205\252\341\204\221\341\205\260 Step #5: artifact_prefix='./'; Test unit written to ./oom-3d2c569c4831d6674f484b6b93eaccbd7411a2b7 Step #5: Base64: 4YSR4YWq4YSR4YWw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1502 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2461677029 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5649752c5810, 0x5649754af01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5649754af020,0x5649773470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3d2c569c4831d6674f484b6b93eaccbd7411a2b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1724 processed earlier; will process 9305 files now Step #5: #1 pulse cov: 3671 ft: 3672 exec/s: 0 rss: 167Mb Step #5: ==54106== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56496bdba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56497241f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5649724025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5649724024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56496bdc0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56496bd21b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56496bd1c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56496bdb2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56496ed81f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56496ed81f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56496ed81f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56496ed81f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56496ed81f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56496ed81f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56496ed81f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56496ed81f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56496ed81f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56496ed81f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564971016f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56496dd43b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56496dd4ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56496dafac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56496dafac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56496dafb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56496dafa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56496dafa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56496dafa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564972404abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56497240d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5649723f5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564972420112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0439a7d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56496bd1ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x40,0x0,0x2f,0x0,0xf,0xf,0xd,0x42,0xf,0x24,0x5b, Step #5: $@\000/\000\017\017\015B\017$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-be4ab3eeae17bef96f2db141d7bfab7efad502a1 Step #5: Base64: JEAALwAPDw1CDyRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1503 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2462173598 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559910fec810, 0x5599111d601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5599111d6020,0x55991306e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/be4ab3eeae17bef96f2db141d7bfab7efad502a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1726 processed earlier; will process 9303 files now Step #5: ==54142== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559907ae19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55990e146898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55990e1295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55990e1294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559907ae7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559907a48b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559907a43355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559907ad9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55990aaa8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55990aaa8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55990aaa8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55990aaa8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55990aaa8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55990aaa8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55990aaa8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55990aaa8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55990aaa8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55990aaa8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55990cd3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559909a6ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559909a75be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559909821c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559909821c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559909822738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559909821874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559909821874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559909821874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55990e12babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55990e134928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55990e11c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55990e147112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f06acb02082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559907a41b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8, Step #5: \342\200\250\342\200\250\342\200\250\342\200\250 Step #5: artifact_prefix='./'; Test unit written to ./oom-df5e8eca92f7990b1590ff37fd09bf455a317d41 Step #5: Base64: 4oCo4oCo4oCo4oCo Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1504 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2462615637 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560d6ffe0810, 0x560d701ca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560d701ca020,0x560d720620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/df5e8eca92f7990b1590ff37fd09bf455a317d41' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1727 processed earlier; will process 9302 files now Step #5: #1 pulse cov: 3682 ft: 3683 exec/s: 0 rss: 165Mb Step #5: ==54178== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560d66ad59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560d6d13a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560d6d11d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560d6d11d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560d66adbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560d66a3cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560d66a37355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560d66acdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560d69a9cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560d69a9cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560d69a9cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560d69a9cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560d69a9cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560d69a9cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560d69a9cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560d69a9cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560d69a9cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560d69a9cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560d6bd31f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560d68a5eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560d68a69be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560d68815c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560d68815c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560d68816738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560d68815874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560d68815874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560d68815874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560d6d11fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560d6d128928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560d6d110699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560d6d13b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f19eccd2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560d66a35b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x22,0x22,0x22,0x40,0x27,0x26,0x11,0x22,0xbd,0x8e,0x28, Step #5: \"\"\"\"@'&\021\"\275\216( Step #5: artifact_prefix='./'; Test unit written to ./oom-36df83c384c53d74f0f69cf995d5d92dfefb7f19 Step #5: Base64: IiIiIkAnJhEivY4o Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1505 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2463113075 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557c75452810, 0x557c7563c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557c7563c020,0x557c774d40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/36df83c384c53d74f0f69cf995d5d92dfefb7f19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1729 processed earlier; will process 9300 files now Step #5: #1 pulse cov: 3789 ft: 3790 exec/s: 0 rss: 169Mb Step #5: ==54214== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557c6bf479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557c725ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557c7258f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557c7258f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557c6bf4dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557c6beaeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557c6bea9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557c6bf3fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557c6ef0ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557c6ef0ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557c6ef0ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557c6ef0ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557c6ef0ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557c6ef0ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557c6ef0ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557c6ef0ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557c6ef0ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557c6ef0ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557c711a3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557c6ded0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557c6dedbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557c6dc87c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557c6dc87c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557c6dc88738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557c6dc87874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557c6dc87874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557c6dc87874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557c72591abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557c7259a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557c72582699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557c725ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f82c31d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557c6bea7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x9,0x3f,0x2a,0x27,0x3f,0x25,0x25,0x2a,0x27,0xff,0x0, Step #5: =\011?*'?%%*'\377\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-04fb5feb75299f2c472be339e9eacd3ddab790c5 Step #5: Base64: PQk/Kic/JSUqJ/8A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1506 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2463606945 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563789f22810, 0x56378a10c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56378a10c020,0x56378bfa40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/04fb5feb75299f2c472be339e9eacd3ddab790c5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1731 processed earlier; will process 9298 files now Step #5: ==54250== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563780a179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56378707c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56378705f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56378705f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563780a1dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56378097eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563780979355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563780a0fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5637839def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5637839def10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5637839def10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5637839def10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5637839def10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5637839def10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5637839def10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5637839def10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5637839def10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5637839def10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563785c73f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5637829a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5637829abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563782757c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563782757c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563782758738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563782757874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563782757874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563782757874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563787061abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56378706a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563787052699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56378707d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d5c949082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563780977b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xef,0xb7,0xba,0xcc,0x94,0xcd,0x88,0xcd,0x98, Step #5: ws:\357\267\272\314\224\315\210\315\230 Step #5: artifact_prefix='./'; Test unit written to ./oom-108186efa3ad62cee8992174273fc2cffcd551ad Step #5: Base64: d3M677e6zJTNiM2Y Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1507 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2464059308 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cca5187810, 0x55cca537101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cca5371020,0x55cca72090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/108186efa3ad62cee8992174273fc2cffcd551ad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1732 processed earlier; will process 9297 files now Step #5: ==54286== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cc9bc7c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cca22e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cca22c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cca22c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc9bc82d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc9bbe3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc9bbde355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc9bc74c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc9ec43f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc9ec43f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc9ec43f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc9ec43f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc9ec43f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc9ec43f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc9ec43f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc9ec43f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc9ec43f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc9ec43f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cca0ed8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc9dc05b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc9dc10be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc9d9bcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc9d9bcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc9d9bd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc9d9bc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc9d9bc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc9d9bc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cca22c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cca22cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cca22b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cca22e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcd984c2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc9bbdcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0x0,0xc,0xdb,0x80,0x39,0x39,0x39,0x38,0x4d,0x39, Step #5: \333\200\000\014\333\2009998M9 Step #5: artifact_prefix='./'; Test unit written to ./oom-dce4e385d18ddc178224901d739a503987744287 Step #5: Base64: 24AADNuAOTk5OE05 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1508 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2464512821 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c7ecb0a810, 0x55c7eccf401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c7eccf4020,0x55c7eeb8c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dce4e385d18ddc178224901d739a503987744287' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1733 processed earlier; will process 9296 files now Step #5: ==54322== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c7e35ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7e9c64898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7e9c475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7e9c474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c7e3605d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c7e3566b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c7e3561355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7e35f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7e65c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7e65c6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7e65c6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7e65c6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7e65c6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7e65c6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7e65c6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7e65c6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7e65c6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7e65c6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7e885bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7e5588b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7e5593be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7e533fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7e533fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7e5340738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7e533f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7e533f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7e533f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7e9c49abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7e9c52928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c7e9c3a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7e9c65112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc81fa1b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c7e355fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x23,0x24,0x1,0x3f,0x65,0x3f,0x0,0x2d,0x10,0x43,0x24, Step #5: ~#$\001?e?\000-\020C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-e8928f2690f946de8e26528e92d4f74f6ad41dd7 Step #5: Base64: fiMkAT9lPwAtEEMk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1509 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2464968856 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563c244e8810, 0x563c246d201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563c246d2020,0x563c2656a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e8928f2690f946de8e26528e92d4f74f6ad41dd7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1734 processed earlier; will process 9295 files now Step #5: ==54358== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563c1afdd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563c21642898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563c216255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563c216254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563c1afe3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563c1af44b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563c1af3f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563c1afd5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563c1dfa4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563c1dfa4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563c1dfa4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563c1dfa4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563c1dfa4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563c1dfa4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563c1dfa4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563c1dfa4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563c1dfa4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563c1dfa4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563c20239f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563c1cf66b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563c1cf71be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563c1cd1dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563c1cd1dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563c1cd1e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563c1cd1d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563c1cd1d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563c1cd1d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563c21627abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563c21630928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563c21618699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563c21643112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f85e4f38082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563c1af3db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x3c,0x3f,0x3c,0x3f,0x3c,0x3f,0x3e,0x49,0x52,0x70, Step #5: IRp Step #5: artifact_prefix='./'; Test unit written to ./oom-76a3428fccd71174b0d2532df9e772b38b11b5b0 Step #5: Base64: PD88Pzw/PD8+SVJw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1510 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2465421997 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d674d9810, 0x561d676c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d676c3020,0x561d6955b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/76a3428fccd71174b0d2532df9e772b38b11b5b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1735 processed earlier; will process 9294 files now Step #5: ==54394== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561d5dfce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d64633898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d646165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d646164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d5dfd4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d5df35b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d5df30355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d5dfc6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d60f95f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d60f95f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d60f95f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d60f95f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d60f95f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d60f95f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d60f95f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d60f95f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d60f95f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d60f95f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d6322af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d5ff57b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d5ff62be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d5fd0ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d5fd0ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d5fd0f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d5fd0e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d5fd0e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d5fd0e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d64618abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d64621928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d64609699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d64634112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb93f802082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d5df2eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x3a,0x3f,0xe0,0xbd,0xb4,0xe0,0xbd,0xbb,0xe0,0xbc,0xb5, Step #5: A:?\340\275\264\340\275\273\340\274\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-3fd673d4715aca736824ce14161a160308098b49 Step #5: Base64: QTo/4L204L274Ly1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1511 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2465874966 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558f49775810, 0x558f4995f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558f4995f020,0x558f4b7f70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3fd673d4715aca736824ce14161a160308098b49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1736 processed earlier; will process 9293 files now Step #5: ==54430== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558f4026a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558f468cf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558f468b25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558f468b24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f40270d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f401d1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f401cc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f40262c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f43231f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f43231f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f43231f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f43231f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f43231f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f43231f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f43231f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f43231f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f43231f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f43231f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558f454c6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f421f3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f421febe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f41faac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f41faac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f41fab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f41faa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f41faa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f41faa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558f468b4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558f468bd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558f468a5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558f468d0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3ac04b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f401cab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x76,0xe0,0xb8,0xb8,0x3f,0x3e, Step #5: Step #5: artifact_prefix='./'; Test unit written to ./oom-0a528dbf6af7937acb4a546b2338820a90a2a22f Step #5: Base64: PD94bWwgduC4uD8+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1512 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2466334379 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56134a764810, 0x56134a94e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56134a94e020,0x56134c7e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a528dbf6af7937acb4a546b2338820a90a2a22f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1737 processed earlier; will process 9292 files now Step #5: ==54466== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5613412599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5613478be898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613478a15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613478a14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56134125fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5613411c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5613411bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561341251c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561344220f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561344220f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561344220f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561344220f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561344220f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561344220f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561344220f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561344220f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561344220f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561344220f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5613464b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5613431e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5613431edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561342f99c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561342f99c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561342f9a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561342f99874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561342f99874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561342f99874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5613478a3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5613478ac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561347894699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5613478bf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0423b32082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5613411b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x54,0x41,0x47,0x3d,0x22,0x24,0x24,0x24,0x24,0x24,0x24,0x22, Step #5: TAG=\"$$$$$$\" Step #5: artifact_prefix='./'; Test unit written to ./oom-3a045bf86f4f7ca063f31446cab1213ae69f03a9 Step #5: Base64: VEFHPSIkJCQkJCQi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1513 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2466788530 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5568f817d810, 0x5568f836701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5568f8367020,0x5568fa1ff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a045bf86f4f7ca063f31446cab1213ae69f03a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1738 processed earlier; will process 9291 files now Step #5: ==54502== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5568eec729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5568f52d7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5568f52ba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5568f52ba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5568eec78d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5568eebd9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5568eebd4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5568eec6ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5568f1c39f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5568f1c39f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5568f1c39f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5568f1c39f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5568f1c39f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5568f1c39f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5568f1c39f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5568f1c39f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5568f1c39f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5568f1c39f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5568f3ecef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5568f0bfbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5568f0c06be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5568f09b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5568f09b2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5568f09b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5568f09b2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5568f09b2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5568f09b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5568f52bcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5568f52c5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5568f52ad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5568f52d8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd9c85b2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5568eebd2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x2d,0x3f,0x73,0x74,0x72,0x65,0x61,0x3f,0x6d,0x27, Step #5: \000\000-?strea?m' Step #5: artifact_prefix='./'; Test unit written to ./oom-24d416e7ed982a98dc081d063577e05b2b930f10 Step #5: Base64: AAAtP3N0cmVhP20n Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1514 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2467247196 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5564f844b810, 0x5564f863501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564f8635020,0x5564fa4cd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/24d416e7ed982a98dc081d063577e05b2b930f10' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1739 processed earlier; will process 9290 files now Step #5: ==54538== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5564eef409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564f55a5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564f55885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564f55884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564eef46d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5564eeea7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5564eeea2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564eef38c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564f1f07f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564f1f07f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564f1f07f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564f1f07f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564f1f07f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564f1f07f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564f1f07f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564f1f07f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564f1f07f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564f1f07f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5564f419cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5564f0ec9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5564f0ed4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5564f0c80c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5564f0c80c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5564f0c81738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5564f0c80874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5564f0c80874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5564f0c80874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564f558aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564f5593928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564f557b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564f55a6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff82e676082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5564eeea0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x5c,0x75,0x7b,0x43,0x7d,0x5c,0x75,0x7b,0x42,0x7d,0x42, Step #5: '\\u{C}\\u{B}B Step #5: artifact_prefix='./'; Test unit written to ./oom-fa10b1bbf5d683a2a680811ff7dd06eec8bfc08f Step #5: Base64: J1x1e0N9XHV7Qn1C Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1515 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2467704812 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55888528c810, 0x55888547601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558885476020,0x55888730e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fa10b1bbf5d683a2a680811ff7dd06eec8bfc08f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1740 processed earlier; will process 9289 files now Step #5: ==54574== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55887bd819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5588823e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588823c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588823c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55887bd87d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55887bce8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55887bce3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55887bd79c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55887ed48f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55887ed48f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55887ed48f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55887ed48f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55887ed48f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55887ed48f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55887ed48f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55887ed48f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55887ed48f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55887ed48f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558880fddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55887dd0ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55887dd15be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55887dac1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55887dac1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55887dac2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55887dac1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55887dac1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55887dac1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5588823cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5588823d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5588823bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5588823e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fae3041a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55887bce1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x34,0x60,0x0,0x24,0xff,0x0,0x0,0x0,0xff,0xff,0x9c, Step #5: $4`\000$\377\000\000\000\377\377\234 Step #5: artifact_prefix='./'; Test unit written to ./oom-1a58d5fcbcdc01e05913f5f6d5e051de92cdba1e Step #5: Base64: JDRgACT/AAAA//+c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1516 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2468160277 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5588b85aa810, 0x5588b879401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5588b8794020,0x5588ba62c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1a58d5fcbcdc01e05913f5f6d5e051de92cdba1e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1741 processed earlier; will process 9288 files now Step #5: #1 pulse cov: 3824 ft: 3825 exec/s: 0 rss: 167Mb Step #5: ==54610== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5588af09f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5588b5704898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588b56e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588b56e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588af0a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588af006b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588af001355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588af097c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5588b2066f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5588b2066f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5588b2066f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5588b2066f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5588b2066f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5588b2066f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5588b2066f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5588b2066f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5588b2066f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5588b2066f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5588b42fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588b1028b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588b1033be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588b0ddfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588b0ddfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588b0de0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588b0ddf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588b0ddf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588b0ddf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5588b56e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5588b56f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5588b56da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5588b5705112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe28fb58082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588aefffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x40,0x3f,0xf3,0xa0,0x81,0x92,0x3d,0x3f,0x3f,0x3f,0x3d, Step #5: '@?\363\240\201\222=???= Step #5: artifact_prefix='./'; Test unit written to ./oom-817cd278d8f028c36f01a46aaf0c9dd81a4540f9 Step #5: Base64: J0A/86CBkj0/Pz89 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1517 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2468654395 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7c9ea3810, 0x55f7ca08d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7ca08d020,0x55f7cbf250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/817cd278d8f028c36f01a46aaf0c9dd81a4540f9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1743 processed earlier; will process 9286 files now Step #5: ==54646== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f7c09989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7c6ffd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7c6fe05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7c6fe04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f7c099ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f7c08ffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f7c08fa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f7c0990c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7c395ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7c395ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7c395ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7c395ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7c395ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7c395ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7c395ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7c395ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7c395ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7c395ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7c5bf4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f7c2921b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f7c292cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f7c26d8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f7c26d8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f7c26d9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f7c26d8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f7c26d8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f7c26d8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7c6fe2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7c6feb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7c6fd3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7c6ffe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e5b3e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f7c08f8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x88,0xf0,0x91,0x97,0x80,0xf0,0x91,0x97,0x80,0xcc,0x8f, Step #5: \315\210\360\221\227\200\360\221\227\200\314\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-f111c8fc1374dc7869c4fc5f719adea6c8433af2 Step #5: Base64: zYjwkZeA8JGXgMyP Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1518 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2469111802 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56482f17e810, 0x56482f36801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56482f368020,0x5648312000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f111c8fc1374dc7869c4fc5f719adea6c8433af2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1744 processed earlier; will process 9285 files now Step #5: #1 pulse cov: 3556 ft: 3557 exec/s: 0 rss: 166Mb Step #5: ==54682== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564825c739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56482c2d8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56482c2bb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56482c2bb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564825c79d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564825bdab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564825bd5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564825c6bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564828c3af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564828c3af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564828c3af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564828c3af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564828c3af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564828c3af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564828c3af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564828c3af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564828c3af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564828c3af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56482aecff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564827bfcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564827c07be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5648279b3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5648279b3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5648279b4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5648279b3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5648279b3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5648279b3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56482c2bdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56482c2c6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56482c2ae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56482c2d9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fadaca3f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564825bd3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0x24,0x74,0x24,0x74,0xc8,0x96,0x39,0xc8,0x96,0x39,0x0, Step #5: \013$t$t\310\2269\310\2269\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-70fbe15a9268d7d04a2dd601238f937136f13e91 Step #5: Base64: CyR0JHTIljnIljkA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1519 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2469606805 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5566648e9810, 0x556664ad301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556664ad3020,0x55666696b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70fbe15a9268d7d04a2dd601238f937136f13e91' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1746 processed earlier; will process 9283 files now Step #5: ==54718== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55665b3de9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556661a43898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556661a265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556661a264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55665b3e4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55665b345b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55665b340355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55665b3d6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55665e3a5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55665e3a5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55665e3a5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55665e3a5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55665e3a5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55665e3a5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55665e3a5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55665e3a5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55665e3a5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55665e3a5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55666063af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55665d367b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55665d372be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55665d11ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55665d11ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55665d11f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55665d11e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55665d11e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55665d11e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556661a28abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556661a31928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556661a19699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556661a44112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f02f68e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55665b33eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x21,0x49,0x49,0x24,0x49,0x2b,0x49,0x49,0x24,0x49,0x49, Step #5: \000!II$I+II$II Step #5: artifact_prefix='./'; Test unit written to ./oom-eddd2d73ab165aab142833005e52248a32adebdb Step #5: Base64: ACFJSSRJK0lJJElJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1520 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2470066929 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ab29df810, 0x561ab2bc901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ab2bc9020,0x561ab4a610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eddd2d73ab165aab142833005e52248a32adebdb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1747 processed earlier; will process 9282 files now Step #5: ==54754== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561aa94d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561aafb39898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561aafb1c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561aafb1c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561aa94dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561aa943bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561aa9436355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561aa94ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561aac49bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561aac49bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561aac49bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561aac49bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561aac49bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561aac49bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561aac49bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561aac49bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561aac49bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561aac49bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561aae730f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561aab45db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561aab468be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561aab214c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561aab214c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561aab215738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561aab214874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561aab214874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561aab214874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561aafb1eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561aafb27928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561aafb0f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561aafb3a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b78d8b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561aa9434b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x39,0x32,0x31,0x33,0x2c,0x31,0xa,0x2d,0x34,0x2c,0x38, Step #5: -9213,1\012-4,8 Step #5: artifact_prefix='./'; Test unit written to ./oom-5fd6c88ec45ba0c157fd491962e483ac25e2483a Step #5: Base64: LTkyMTMsMQotNCw4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1521 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2470520876 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555d3daad810, 0x555d3dc9701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555d3dc97020,0x555d3fb2f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5fd6c88ec45ba0c157fd491962e483ac25e2483a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1748 processed earlier; will process 9281 files now Step #5: #1 pulse cov: 3686 ft: 3687 exec/s: 0 rss: 168Mb Step #5: ==54790== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555d345a29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555d3ac07898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555d3abea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555d3abea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555d345a8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555d34509b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555d34504355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555d3459ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555d37569f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555d37569f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555d37569f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555d37569f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555d37569f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555d37569f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555d37569f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555d37569f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555d37569f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555d37569f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555d397fef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555d3652bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555d36536be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555d362e2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555d362e2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555d362e3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555d362e2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555d362e2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555d362e2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555d3abecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555d3abf5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555d3abdd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555d3ac08112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f051f1e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555d34502b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x69,0x65,0x69,0x64,0x3e,0x3c,0x61,0x65,0x69,0x64,0x3e, Step #5: Step #5: artifact_prefix='./'; Test unit written to ./oom-1160d9d0f3e84491937c4121f80cb888be276ae9 Step #5: Base64: PGllaWQ+PGFlaWQ+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1522 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2471005806 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5570e480c810, 0x5570e49f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5570e49f6020,0x5570e688e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1160d9d0f3e84491937c4121f80cb888be276ae9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1750 processed earlier; will process 9279 files now Step #5: ==54826== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5570db3019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5570e1966898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5570e19495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5570e19494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5570db307d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5570db268b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5570db263355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5570db2f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5570de2c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5570de2c8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5570de2c8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5570de2c8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5570de2c8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5570de2c8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5570de2c8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5570de2c8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5570de2c8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5570de2c8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5570e055df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5570dd28ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5570dd295be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5570dd041c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5570dd041c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5570dd042738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5570dd041874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5570dd041874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5570dd041874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5570e194babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5570e1954928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5570e193c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5570e1967112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7155239082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5570db261b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe1,0x80,0x88,0xe1,0xa4,0xb9,0xe2,0x80,0x8c, Step #5: ws:\341\200\210\341\244\271\342\200\214 Step #5: artifact_prefix='./'; Test unit written to ./oom-1862750965ebbdd406dbd26e3d67b999fac14107 Step #5: Base64: d3M64YCI4aS54oCM Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1523 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2471458633 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a6567e810, 0x559a6586801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a65868020,0x559a677000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1862750965ebbdd406dbd26e3d67b999fac14107' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1751 processed earlier; will process 9278 files now Step #5: #1 pulse cov: 3705 ft: 3706 exec/s: 0 rss: 166Mb Step #5: #2 pulse cov: 4206 ft: 4652 exec/s: 0 rss: 168Mb Step #5: ==54862== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559a5c1739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a627d8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a627bb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a627bb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a5c179d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a5c0dab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a5c0d5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a5c16bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a5f13af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a5f13af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a5f13af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a5f13af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a5f13af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a5f13af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a5f13af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a5f13af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a5f13af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a5f13af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a613cff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a5e0fcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a5e107be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a5deb3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a5deb3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a5deb4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a5deb3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a5deb3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a5deb3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a627bdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a627c6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a627ae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a627d9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9dd0cdc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a5c0d3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x73,0x65,0x70,0x61,0x72,0x61,0x74,0x69,0x6f,0x4e,0xff, Step #5: /separatioN\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-975d73d515f3b59ad892f9be468d4e13028626b5 Step #5: Base64: L3NlcGFyYXRpb07/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1524 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2471992872 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559b28c8b810, 0x559b28e7501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559b28e75020,0x559b2ad0d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/975d73d515f3b59ad892f9be468d4e13028626b5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1754 processed earlier; will process 9275 files now Step #5: ==54898== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559b1f7809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559b25de5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559b25dc85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559b25dc84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b1f786d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b1f6e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b1f6e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b1f778c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b22747f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b22747f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b22747f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b22747f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b22747f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b22747f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b22747f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b22747f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b22747f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b22747f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559b249dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b21709b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b21714be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b214c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b214c0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b214c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b214c0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b214c0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b214c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559b25dcaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559b25dd3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559b25dbb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559b25de6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0609623082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b1f6e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x31,0xf0,0x94,0x92,0xa0,0xf3,0xa0,0x81,0x8a,0xd7,0x3d, Step #5: B1\360\224\222\240\363\240\201\212\327= Step #5: artifact_prefix='./'; Test unit written to ./oom-238d9c9b68f7d7e511890d031d5309d90219175b Step #5: Base64: QjHwlJKg86CBitc9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1525 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2472448587 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555c85466810, 0x555c8565001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555c85650020,0x555c874e80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/238d9c9b68f7d7e511890d031d5309d90219175b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1755 processed earlier; will process 9274 files now Step #5: ==54934== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555c7bf5b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555c825c0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555c825a35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555c825a34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555c7bf61d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555c7bec2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555c7bebd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555c7bf53c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555c7ef22f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555c7ef22f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555c7ef22f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555c7ef22f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555c7ef22f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555c7ef22f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555c7ef22f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555c7ef22f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555c7ef22f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555c7ef22f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555c811b7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555c7dee4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555c7deefbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555c7dc9bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555c7dc9bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555c7dc9c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555c7dc9b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555c7dc9b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555c7dc9b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555c825a5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555c825ae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555c82596699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555c825c1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f752cfd2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555c7bebbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2f,0x0,0x5a,0x0,0x2f,0x3f,0x0,0x5c,0x0,0x62,0x0, Step #5: \000/\000Z\000/?\000\\\000b\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2af8fdcb695bb1dce536565b6dfa9e67b1d25065 Step #5: Base64: AC8AWgAvPwBcAGIA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1526 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2472905400 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55993b7fd810, 0x55993b9e701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55993b9e7020,0x55993d87f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2af8fdcb695bb1dce536565b6dfa9e67b1d25065' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1756 processed earlier; will process 9273 files now Step #5: ==54970== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5599322f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559938957898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55993893a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55993893a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5599322f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559932259b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559932254355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5599322eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5599352b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5599352b9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5599352b9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5599352b9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5599352b9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5599352b9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5599352b9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5599352b9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5599352b9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5599352b9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55993754ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55993427bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559934286be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559934032c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559934032c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559934033738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559934032874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559934032874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559934032874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55993893cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559938945928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55993892d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559938958112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f80fe8ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559932252b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0x34,0x45,0x37,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f, Step #5: .4E7________ Step #5: artifact_prefix='./'; Test unit written to ./oom-471645fa00a7ef0a301a4020b9a15e38cfaf28b1 Step #5: Base64: LjRFN19fX19fX19f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1527 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2473357802 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c69bca6810, 0x55c69be9001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c69be90020,0x55c69dd280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/471645fa00a7ef0a301a4020b9a15e38cfaf28b1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1757 processed earlier; will process 9272 files now Step #5: #1 pulse cov: 3690 ft: 3691 exec/s: 0 rss: 166Mb Step #5: ==55006== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c69279b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c698e00898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c698de35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c698de34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c6927a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c692702b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6926fd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c692793c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c695762f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c695762f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c695762f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c695762f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c695762f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c695762f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c695762f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c695762f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c695762f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c695762f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c6979f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c694724b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c69472fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6944dbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6944dbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6944dc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6944db874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6944db874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6944db874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c698de5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c698dee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c698dd6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c698e01112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd64a50d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6926fbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xba,0x9c,0xe0,0xba,0x9c,0xe0,0xba,0x9c,0xe0,0xba,0x9c, Step #5: \340\272\234\340\272\234\340\272\234\340\272\234 Step #5: artifact_prefix='./'; Test unit written to ./oom-68a112d69c13af2485e6bb27781a2d07f114782e Step #5: Base64: 4Lqc4Lqc4Lqc4Lqc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1528 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2473849395 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cbe1a86810, 0x55cbe1c7001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cbe1c70020,0x55cbe3b080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/68a112d69c13af2485e6bb27781a2d07f114782e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1759 processed earlier; will process 9270 files now Step #5: ==55042== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cbd857b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cbdebe0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cbdebc35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cbdebc34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cbd8581d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cbd84e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cbd84dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cbd8573c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cbdb542f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cbdb542f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cbdb542f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cbdb542f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cbdb542f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cbdb542f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cbdb542f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cbdb542f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cbdb542f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cbdb542f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cbdd7d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cbda504b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cbda50fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cbda2bbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cbda2bbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cbda2bc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cbda2bb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cbda2bb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cbda2bb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cbdebc5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cbdebce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cbdebb6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cbdebe1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f860f3e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cbd84dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x2d,0x39,0x39,0x36,0x37,0x32,0x33,0x32, Step #5: \333\200\333\200-9967232 Step #5: artifact_prefix='./'; Test unit written to ./oom-16a875238d0d60aecb59fb3a96d73f098f22795f Step #5: Base64: 24DbgC05OTY3MjMy Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1529 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2474303797 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560d70a29810, 0x560d70c1301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560d70c13020,0x560d72aab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16a875238d0d60aecb59fb3a96d73f098f22795f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1760 processed earlier; will process 9269 files now Step #5: #1 pulse cov: 3707 ft: 3708 exec/s: 0 rss: 166Mb Step #5: #2 pulse cov: 4224 ft: 4586 exec/s: 0 rss: 168Mb Step #5: ==55078== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560d6751e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560d6db83898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560d6db665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560d6db664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560d67524d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560d67485b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560d67480355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560d67516c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560d6a4e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560d6a4e5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560d6a4e5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560d6a4e5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560d6a4e5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560d6a4e5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560d6a4e5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560d6a4e5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560d6a4e5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560d6a4e5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560d6c77af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560d694a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560d694b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560d6925ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560d6925ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560d6925f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560d6925e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560d6925e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560d6925e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560d6db68abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560d6db71928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560d6db59699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560d6db84112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa31d91d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560d6747eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0x66,0x6c,0x6f,0x61,0x74,0x9,0x2e,0x34,0x39,0x39,0x0, Step #5: .float\011.499\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-09abfbf51b524a47aee4ef6c6a6338341e4fce89 Step #5: Base64: LmZsb2F0CS40OTkA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1530 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2474831995 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eee069f810, 0x55eee088901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eee0889020,0x55eee27210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/09abfbf51b524a47aee4ef6c6a6338341e4fce89' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1763 processed earlier; will process 9266 files now Step #5: ==55114== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eed71949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eedd7f9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eedd7dc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eedd7dc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eed719ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eed70fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eed70f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eed718cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eeda15bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eeda15bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eeda15bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eeda15bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eeda15bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eeda15bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eeda15bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eeda15bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eeda15bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eeda15bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eedc3f0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eed911db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eed9128be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eed8ed4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eed8ed4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eed8ed5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eed8ed4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eed8ed4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eed8ed4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eedd7deabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eedd7e7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eedd7cf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eedd7fa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1812ced082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eed70f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x53,0x3a,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xcd,0x85, Step #5: \016wS:\343\214\226\343\214\226\315\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-a954d77c5dd35cc2b3fbe224a5ca85fec9a71fe6 Step #5: Base64: DndTOuOMluOMls2F Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1531 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2475284728 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c961ae8810, 0x55c961cd201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c961cd2020,0x55c963b6a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a954d77c5dd35cc2b3fbe224a5ca85fec9a71fe6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1764 processed earlier; will process 9265 files now Step #5: ==55150== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c9585dd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c95ec42898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c95ec255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c95ec254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9585e3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c958544b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c95853f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9585d5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c95b5a4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c95b5a4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c95b5a4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c95b5a4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c95b5a4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c95b5a4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c95b5a4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c95b5a4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c95b5a4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c95b5a4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c95d839f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c95a566b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c95a571be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c95a31dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c95a31dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c95a31e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c95a31d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c95a31d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c95a31d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c95ec27abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c95ec30928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c95ec18699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c95ec43112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa981ee5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c95853db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9, Step #5: \342\200\251\342\200\251\342\200\251\342\200\251 Step #5: artifact_prefix='./'; Test unit written to ./oom-0615b427120cc3094b64a926ef12ecbf35587982 Step #5: Base64: 4oCp4oCp4oCp4oCp Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1532 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2475725830 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562303fdf810, 0x5623041c901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5623041c9020,0x5623060610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0615b427120cc3094b64a926ef12ecbf35587982' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1765 processed earlier; will process 9264 files now Step #5: ==55186== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5622faad49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562301139898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56230111c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56230111c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5622faadad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5622faa3bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5622faa36355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5622faaccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5622fda9bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5622fda9bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5622fda9bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5622fda9bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5622fda9bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5622fda9bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5622fda9bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5622fda9bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5622fda9bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5622fda9bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5622ffd30f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5622fca5db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5622fca68be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5622fc814c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5622fc814c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5622fc815738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5622fc814874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5622fc814874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5622fc814874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56230111eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562301127928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56230110f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56230113a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f11b12eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5622faa34b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x2b,0x2b,0xa,0x6b,0x3d,0x22,0x71,0xa,0x2b,0x2b,0x2b, Step #5: +++\012k=\"q\012+++ Step #5: artifact_prefix='./'; Test unit written to ./oom-92e67356eb2785c2e07e1fd740b26cd73542dc4b Step #5: Base64: KysrCms9InEKKysr Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1533 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2476174468 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e1c36ef810, 0x55e1c38d901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e1c38d9020,0x55e1c57710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92e67356eb2785c2e07e1fd740b26cd73542dc4b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1766 processed earlier; will process 9263 files now Step #5: ==55222== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e1ba1e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e1c0849898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e1c082c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e1c082c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e1ba1ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e1ba14bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e1ba146355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e1ba1dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e1bd1abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e1bd1abf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e1bd1abf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e1bd1abf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e1bd1abf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e1bd1abf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e1bd1abf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e1bd1abf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e1bd1abf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e1bd1abf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e1bf440f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e1bc16db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e1bc178be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e1bbf24c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e1bbf24c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e1bbf25738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e1bbf24874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e1bbf24874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e1bbf24874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e1c082eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e1c0837928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e1c081f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e1c084a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f251290f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e1ba144b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdc,0x8c,0xe,0x27,0x9,0x0,0xa,0xe,0x27,0x9,0x3b,0x32, Step #5: \334\214\016'\011\000\012\016'\011;2 Step #5: artifact_prefix='./'; Test unit written to ./oom-9bce58b83f003d5932c59de5f5a7e0f83550f413 Step #5: Base64: 3IwOJwkACg4nCTsy Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1534 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2476626128 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56374cfa7810, 0x56374d19101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56374d191020,0x56374f0290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9bce58b83f003d5932c59de5f5a7e0f83550f413' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1767 processed earlier; will process 9262 files now Step #5: ==55258== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563743a9c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56374a101898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56374a0e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56374a0e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563743aa2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563743a03b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5637439fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563743a94c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563746a63f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563746a63f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563746a63f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563746a63f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563746a63f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563746a63f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563746a63f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563746a63f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563746a63f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563746a63f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563748cf8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563745a25b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563745a30be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5637457dcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5637457dcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5637457dd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5637457dc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5637457dc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5637457dc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56374a0e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56374a0ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56374a0d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56374a102112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f80816b3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5637439fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x11,0x0,0x24,0x2a,0x11,0x0,0x24,0x2a,0x2a,0xe7,0x2a,0xe7, Step #5: \021\000$*\021\000$**\347*\347 Step #5: artifact_prefix='./'; Test unit written to ./oom-b72818753c12efc356406cb9afd7363867932fdf Step #5: Base64: EQAkKhEAJCoq5yrn Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1535 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2477082298 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff2f36f810, 0x55ff2f55901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff2f559020,0x55ff313f10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b72818753c12efc356406cb9afd7363867932fdf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1768 processed earlier; will process 9261 files now Step #5: ==55294== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ff25e649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff2c4c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff2c4ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff2c4ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff25e6ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff25dcbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff25dc6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff25e5cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff28e2bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff28e2bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff28e2bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff28e2bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff28e2bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff28e2bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff28e2bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff28e2bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff28e2bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff28e2bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff2b0c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff27dedb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff27df8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff27ba4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff27ba4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff27ba5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff27ba4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff27ba4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff27ba4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff2c4aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff2c4b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff2c49f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff2c4ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1607431082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff25dc4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x3d,0x2d,0x2f,0x2a,0x47,0x49,0x4e,0xd6, Step #5: x---=-/*GIN\326 Step #5: artifact_prefix='./'; Test unit written to ./oom-b6a4a3b6466af92e54183e6c8e93186ce2a66222 Step #5: Base64: eC0tLT0tLypHSU7W Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1536 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2477529265 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558578215810, 0x5585783ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5585783ff020,0x55857a2970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b6a4a3b6466af92e54183e6c8e93186ce2a66222' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1769 processed earlier; will process 9260 files now Step #5: ==55330== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55856ed0a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55857536f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5585753525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5585753524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55856ed10d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55856ec71b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55856ec6c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55856ed02c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558571cd1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558571cd1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558571cd1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558571cd1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558571cd1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558571cd1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558571cd1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558571cd1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558571cd1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558571cd1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558573f66f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558570c93b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558570c9ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558570a4ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558570a4ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558570a4b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558570a4a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558570a4a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558570a4a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558575354abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55857535d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558575345699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558575370112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0a44371082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55856ec6ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x24,0x0,0x24,0x0,0x24,0x0,0x24,0x0,0x24,0x0, Step #5: $\000$\000$\000$\000$\000$\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4dc5494c6362417127d109f3952025a37332fd5c Step #5: Base64: JAAkACQAJAAkACQA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1537 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2477981434 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e299e3810, 0x563e29bcd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e29bcd020,0x563e2ba650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4dc5494c6362417127d109f3952025a37332fd5c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1770 processed earlier; will process 9259 files now Step #5: ==55366== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563e204d89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e26b3d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e26b205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e26b204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e204ded42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e2043fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e2043a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e204d0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e2349ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e2349ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e2349ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e2349ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e2349ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e2349ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e2349ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e2349ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e2349ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e2349ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e25734f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e22461b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e2246cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e22218c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e22218c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e22219738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e22218874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e22218874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e22218874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e26b22abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e26b2b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e26b13699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e26b3e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5f82fe0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e20438b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e, Step #5: <\315\274><\315\274><\315\274> Step #5: artifact_prefix='./'; Test unit written to ./oom-a2eff445fc4d11f4018da96be8489d2185032dc7 Step #5: Base64: PM28PjzNvD48zbw+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1538 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2478418820 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd705c4810, 0x55dd707ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd707ae020,0x55dd726460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2eff445fc4d11f4018da96be8489d2185032dc7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1771 processed earlier; will process 9258 files now Step #5: ==55402== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dd670b99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd6d71e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd6d7015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd6d7014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dd670bfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dd67020b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dd6701b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dd670b1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd6a080f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd6a080f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd6a080f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd6a080f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd6a080f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd6a080f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd6a080f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd6a080f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd6a080f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd6a080f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd6c315f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dd69042b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dd6904dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dd68df9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dd68df9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dd68dfa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dd68df9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dd68df9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dd68df9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd6d703abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd6d70c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd6d6f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd6d71f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb03709c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dd67019b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x11,0xe4,0x88,0xb9,0xce,0x93,0x1,0x43,0x4f,0x1, Step #5: ID\021\344\210\271\316\223\001CO\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-b8ce22a121b125b5172a6f5739273e3efdd23715 Step #5: Base64: SUQR5Ii5zpMBQ08B Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1539 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2478877004 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55921881f810, 0x559218a0901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559218a09020,0x55921a8a10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b8ce22a121b125b5172a6f5739273e3efdd23715' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1772 processed earlier; will process 9257 files now Step #5: ==55438== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55920f3149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559215979898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55921595c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55921595c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55920f31ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55920f27bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55920f276355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55920f30cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592122dbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592122dbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592122dbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592122dbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592122dbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592122dbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592122dbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592122dbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592122dbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592122dbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559214570f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55921129db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592112a8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559211054c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559211054c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559211055738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559211054874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559211054874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559211054874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55921595eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559215967928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55921594f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55921597a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b8bd90082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55920f274b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x8,0x4e,0x3f,0x3f,0x23,0x32,0x23,0x32,0x23,0x31,0x25, Step #5: %\010N??#2#2#1% Step #5: artifact_prefix='./'; Test unit written to ./oom-8fc73610f1333788ba04a670fe7539d8eafa1d74 Step #5: Base64: JQhOPz8jMiMyIzEl Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1540 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2479335556 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557642443810, 0x55764262d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55764262d020,0x5576444c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8fc73610f1333788ba04a670fe7539d8eafa1d74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1773 processed earlier; will process 9256 files now Step #5: #1 pulse cov: 3568 ft: 3569 exec/s: 0 rss: 169Mb Step #5: ==55474== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557638f389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55763f59d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55763f5805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55763f5804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557638f3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557638e9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557638e9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557638f30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55763befff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55763befff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55763befff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55763befff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55763befff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55763befff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55763befff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55763befff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55763befff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55763befff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55763e194f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55763aec1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55763aeccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55763ac78c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55763ac78c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55763ac79738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55763ac78874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55763ac78874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55763ac78874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55763f582abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55763f58b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55763f573699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55763f59e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdda5dc4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557638e98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80, Step #5: \341\232\200\341\232\200\341\232\200\341\232\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-1067bb8e0d49d73ea066068228d35798cadd5d62 Step #5: Base64: 4ZqA4ZqA4ZqA4ZqA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1541 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2479836693 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5616611eb810, 0x5616613d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5616613d5020,0x56166326d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1067bb8e0d49d73ea066068228d35798cadd5d62' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1775 processed earlier; will process 9254 files now Step #5: ==55510== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561657ce09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56165e345898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56165e3285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56165e3284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561657ce6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561657c47b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561657c42355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561657cd8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56165aca7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56165aca7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56165aca7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56165aca7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56165aca7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56165aca7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56165aca7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56165aca7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56165aca7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56165aca7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56165cf3cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561659c69b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561659c74be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561659a20c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561659a20c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561659a21738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561659a20874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561659a20874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561659a20874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56165e32aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56165e333928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56165e31b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56165e346112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f351f835082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561657c40b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xef,0xbe,0x9f,0xef,0xbe,0x9f,0xef,0xbe,0x9f, Step #5: ws:\357\276\237\357\276\237\357\276\237 Step #5: artifact_prefix='./'; Test unit written to ./oom-c8423266b4ed325eedb3b1dde27ae751ae7c4af0 Step #5: Base64: d3M6776f776f776f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1542 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2480298418 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55580bcdc810, 0x55580bec601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55580bec6020,0x55580dd5e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c8423266b4ed325eedb3b1dde27ae751ae7c4af0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1776 processed earlier; will process 9253 files now Step #5: #1 pulse cov: 6446 ft: 6447 exec/s: 0 rss: 182Mb Step #5: ==55546== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5558027d19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555808e36898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555808e195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555808e194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5558027d7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555802738b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555802733355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5558027c9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555805798f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555805798f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555805798f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555805798f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555805798f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555805798f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555805798f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555805798f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555805798f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555805798f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555807a2df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55580475ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555804765be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555804511c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555804511c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555804512738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555804511874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555804511874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555804511874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555808e1babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555808e24928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555808e0c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555808e37112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f21245d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555802731b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0xd8,0x83,0x50,0x7b,0xa,0x29,0x7b,0x39,0x31,0x36,0x7d, Step #5: (\330\203P{\012){916} Step #5: artifact_prefix='./'; Test unit written to ./oom-547a8b7c9f046f1ea78406d87f33b26665ccee9a Step #5: Base64: KNiDUHsKKXs5MTZ9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1543 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2480810468 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557cb3e3e810, 0x557cb402801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557cb4028020,0x557cb5ec00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/547a8b7c9f046f1ea78406d87f33b26665ccee9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1778 processed earlier; will process 9251 files now Step #5: ==55582== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557caa9339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557cb0f98898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557cb0f7b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557cb0f7b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557caa939d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557caa89ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557caa895355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557caa92bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557cad8faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557cad8faf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557cad8faf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557cad8faf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557cad8faf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557cad8faf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557cad8faf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557cad8faf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557cad8faf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557cad8faf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557cafb8ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557cac8bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557cac8c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557cac673c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557cac673c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557cac674738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557cac673874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557cac673874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557cac673874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557cb0f7dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557cb0f86928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557cb0f6e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557cb0f99112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa1b14a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557caa893b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x73,0x3a,0xd8,0xa5,0xdc,0xb9,0xd8,0xa5,0xdc,0xb8, Step #5: \016ws:\330\245\334\271\330\245\334\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-e9d37154b75e9850afffb1520f9fa91f78453317 Step #5: Base64: DndzOtil3LnYpdy4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1544 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2481286224 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db2cfdb810, 0x55db2d1c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db2d1c5020,0x55db2f05d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e9d37154b75e9850afffb1520f9fa91f78453317' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1779 processed earlier; will process 9250 files now Step #5: ==55618== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55db23ad09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db2a135898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db2a1185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db2a1184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db23ad6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db23a37b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db23a32355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db23ac8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db26a97f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db26a97f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db26a97f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db26a97f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db26a97f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db26a97f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db26a97f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db26a97f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db26a97f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db26a97f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db28d2cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db25a59b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db25a64be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db25810c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db25810c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db25811738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db25810874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db25810874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db25810874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db2a11aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db2a123928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db2a10b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db2a136112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fceb6996082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db23a30b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x53,0x4d,0x2d,0x38,0x37,0xcd,0xbb,0x3e,0x3c,0x2f,0x3e, Step #5: Step #5: artifact_prefix='./'; Test unit written to ./oom-37b93191172568c9aa2f6994fc46affb3f15deb0 Step #5: Base64: PFNNLTg3zbs+PC8+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1545 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2481740885 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557334402810, 0x5573345ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5573345ec020,0x5573364840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/37b93191172568c9aa2f6994fc46affb3f15deb0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1780 processed earlier; will process 9249 files now Step #5: ==55654== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55732aef79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55733155c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55733153f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55733153f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55732aefdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55732ae5eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55732ae59355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55732aeefc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55732debef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55732debef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55732debef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55732debef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55732debef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55732debef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55732debef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55732debef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55732debef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55732debef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557330153f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55732ce80b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55732ce8bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55732cc37c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55732cc37c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55732cc38738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55732cc37874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55732cc37874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55732cc37874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557331541abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55733154a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557331532699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55733155d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f71a9b63082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55732ae57b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x38,0x39,0x34,0x37,0x3a,0x31,0x2e,0x32,0x2d,0x2d,0x3e, Step #5: -8947:1.2--> Step #5: artifact_prefix='./'; Test unit written to ./oom-f4539c8179bfe5ba97ce758b1a2056b3415ae354 Step #5: Base64: LTg5NDc6MS4yLS0+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1546 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2482208214 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55981ff28810, 0x55982011201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559820112020,0x559821faa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f4539c8179bfe5ba97ce758b1a2056b3415ae354' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1781 processed earlier; will process 9248 files now Step #5: ==55690== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559816a1d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55981d082898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55981d0655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55981d0654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559816a23d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559816984b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55981697f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559816a15c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5598199e4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5598199e4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5598199e4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5598199e4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5598199e4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5598199e4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5598199e4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5598199e4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5598199e4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5598199e4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55981bc79f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5598189a6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5598189b1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55981875dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55981875dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55981875e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55981875d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55981875d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55981875d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55981d067abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55981d070928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55981d058699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55981d083112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f03869d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55981697db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c, Step #5: (?:$|$|$|$)| Step #5: artifact_prefix='./'; Test unit written to ./oom-638d066504356e1d606769469d0646fc27a6a72f Step #5: Base64: KD86JHwkfCR8JCl8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1547 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2482673205 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ce943db810, 0x55ce945c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ce945c5020,0x55ce9645d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/638d066504356e1d606769469d0646fc27a6a72f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1782 processed earlier; will process 9247 files now Step #5: ==55726== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ce8aed09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ce91535898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ce915185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ce915184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ce8aed6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ce8ae37b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ce8ae32355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ce8aec8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ce8de97f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ce8de97f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ce8de97f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ce8de97f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ce8de97f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ce8de97f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ce8de97f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ce8de97f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ce8de97f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ce8de97f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ce9012cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ce8ce59b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ce8ce64be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ce8cc10c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ce8cc10c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ce8cc11738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ce8cc10874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ce8cc10874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ce8cc10874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ce9151aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ce91523928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ce9150b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ce91536112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f099cd3b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ce8ae30b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x0,0x20,0x0,0x0,0x1e,0x1e,0x28,0x23,0x24,0x24, Step #5: = \000 \000\000\036\036(#$$ Step #5: artifact_prefix='./'; Test unit written to ./oom-8b37551e94bd2e9c890504d843e17920387f30ca Step #5: Base64: PSAAIAAAHh4oIyQk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1548 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2483138556 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55809d0fa810, 0x55809d2e401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55809d2e4020,0x55809f17c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8b37551e94bd2e9c890504d843e17920387f30ca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1783 processed earlier; will process 9246 files now Step #5: ==55762== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558093bef9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55809a254898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55809a2375dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55809a2374fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558093bf5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558093b56b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558093b51355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558093be7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558096bb6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558096bb6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558096bb6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558096bb6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558096bb6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558096bb6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558096bb6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558096bb6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558096bb6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558096bb6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558098e4bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558095b78b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558095b83be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55809592fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55809592fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558095930738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55809592f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55809592f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55809592f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55809a239abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55809a242928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55809a22a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55809a255112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ad3ee1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558093b4fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x45,0x3e,0x3c,0x3f,0x72,0xcc,0xb6,0x3f,0x3e,0x3c,0x3e, Step #5: <> Step #5: artifact_prefix='./'; Test unit written to ./oom-738d2907abc9e879d9f65ecf1a4700fd842d07c4 Step #5: Base64: PEU+PD9yzLY/Pjw+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1549 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2483603014 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640b0213810, 0x5640b03fd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640b03fd020,0x5640b22950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/738d2907abc9e879d9f65ecf1a4700fd842d07c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1784 processed earlier; will process 9245 files now Step #5: #1 pulse cov: 3888 ft: 3889 exec/s: 0 rss: 169Mb Step #5: ==55798== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5640a6d089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5640ad36d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640ad3505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640ad3504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5640a6d0ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5640a6c6fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5640a6c6a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5640a6d00c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5640a9ccff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5640a9ccff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5640a9ccff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5640a9ccff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5640a9ccff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5640a9ccff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5640a9ccff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5640a9ccff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5640a9ccff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5640a9ccff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5640abf64f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5640a8c91b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5640a8c9cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5640a8a48c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5640a8a48c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5640a8a49738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5640a8a48874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5640a8a48874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5640a8a48874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5640ad352abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5640ad35b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5640ad343699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5640ad36e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa777601082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5640a6c68b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3, Step #5: ws:\340\275\263\340\275\263\340\275\263 Step #5: artifact_prefix='./'; Test unit written to ./oom-5a01f0915b5652af7744081c48fbab052c383048 Step #5: Base64: d3M64L2z4L2z4L2z Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1550 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2484113396 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558e989de810, 0x558e98bc801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558e98bc8020,0x558e9aa600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5a01f0915b5652af7744081c48fbab052c383048' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1786 processed earlier; will process 9243 files now Step #5: ==55834== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558e8f4d39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558e95b38898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558e95b1b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558e95b1b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558e8f4d9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558e8f43ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558e8f435355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558e8f4cbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558e9249af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558e9249af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558e9249af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558e9249af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558e9249af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558e9249af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558e9249af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558e9249af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558e9249af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558e9249af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558e9472ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558e9145cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558e91467be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558e91213c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558e91213c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558e91214738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558e91213874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558e91213874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558e91213874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558e95b1dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558e95b26928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558e95b0e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558e95b39112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdd8ca38082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558e8f433b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x55,0x55,0xdb,0x82,0x39,0x2d,0x2b,0xdb,0x80,0x39,0x2d,0x3e, Step #5: UU\333\2029-+\333\2009-> Step #5: artifact_prefix='./'; Test unit written to ./oom-70338f060623301489baa46354a024dab2f4ccf9 Step #5: Base64: VVXbgjktK9uAOS0+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1551 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2484575357 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5598e20ef810, 0x5598e22d901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5598e22d9020,0x5598e41710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70338f060623301489baa46354a024dab2f4ccf9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1787 processed earlier; will process 9242 files now Step #5: ==55870== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5598d8be49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5598df249898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5598df22c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5598df22c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5598d8bead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5598d8b4bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5598d8b46355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5598d8bdcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5598dbbabf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5598dbbabf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5598dbbabf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5598dbbabf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5598dbbabf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5598dbbabf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5598dbbabf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5598dbbabf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5598dbbabf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5598dbbabf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5598dde40f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5598dab6db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5598dab78be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5598da924c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5598da924c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5598da925738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5598da924874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5598da924874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5598da924874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5598df22eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5598df237928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5598df21f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5598df24a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbb09ba1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5598d8b44b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x3,0x1,0x67,0x67,0x67,0x67,0x67,0x67,0x6f, Step #5: ID3\003\001ggggggo Step #5: artifact_prefix='./'; Test unit written to ./oom-5e056f4be31aedc9191791811217140a55827c9a Step #5: Base64: SUQzAwFnZ2dnZ2dv Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1552 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2485037430 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560faac3b810, 0x560faae2501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560faae25020,0x560faccbd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e056f4be31aedc9191791811217140a55827c9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1788 processed earlier; will process 9241 files now Step #5: ==55906== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560fa17309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560fa7d95898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560fa7d785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560fa7d784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560fa1736d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560fa1697b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560fa1692355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560fa1728c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560fa46f7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560fa46f7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560fa46f7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560fa46f7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560fa46f7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560fa46f7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560fa46f7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560fa46f7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560fa46f7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560fa46f7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560fa698cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560fa36b9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560fa36c4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560fa3470c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560fa3470c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560fa3471738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560fa3470874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560fa3470874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560fa3470874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560fa7d7aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560fa7d83928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560fa7d6b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560fa7d96112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc018272082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560fa1690b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5c,0x70,0x4c,0xdb,0x9a,0x2d,0xf1,0x8e,0x9d,0xa3,0x5d, Step #5: [\\pL\333\232-\361\216\235\243] Step #5: artifact_prefix='./'; Test unit written to ./oom-cedeb8b4baddf2c49df33d437af417c233d4f206 Step #5: Base64: W1xwTNuaLfGOnaNd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1553 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2485490855 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b924f5810, 0x558b926df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b926df020,0x558b945770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cedeb8b4baddf2c49df33d437af417c233d4f206' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1789 processed earlier; will process 9240 files now Step #5: ==55942== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558b88fea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b8f64f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b8f6325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b8f6324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b88ff0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b88f51b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b88f4c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b88fe2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b8bfb1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b8bfb1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b8bfb1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b8bfb1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b8bfb1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b8bfb1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b8bfb1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b8bfb1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b8bfb1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b8bfb1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b8e246f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b8af73b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b8af7ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b8ad2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b8ad2ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b8ad2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b8ad2a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b8ad2a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b8ad2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b8f634abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b8f63d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b8f625699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b8f650112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f930615c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b88f4ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbf,0xbf,0xef,0xb7,0xbf,0xef,0xbd,0xbf,0xef,0xbf,0x95, Step #5: \357\277\277\357\267\277\357\275\277\357\277\225 Step #5: artifact_prefix='./'; Test unit written to ./oom-ff54cb2cf2074f654d56ae44ac69fcacf77c9ba1 Step #5: Base64: 77+/77e/772/77+V Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1554 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2485943156 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558abd5a4810, 0x558abd78e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558abd78e020,0x558abf6260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ff54cb2cf2074f654d56ae44ac69fcacf77c9ba1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1790 processed earlier; will process 9239 files now Step #5: #1 pulse cov: 11214 ft: 11215 exec/s: 0 rss: 186Mb Step #5: ==55978== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558ab40999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558aba6fe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558aba6e15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558aba6e14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558ab409fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558ab4000b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558ab3ffb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558ab4091c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558ab7060f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558ab7060f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558ab7060f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558ab7060f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558ab7060f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558ab7060f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558ab7060f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558ab7060f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558ab7060f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558ab7060f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558ab92f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ab6022b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ab602dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ab5dd9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ab5dd9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ab5dda738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ab5dd9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ab5dd9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ab5dd9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558aba6e3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558aba6ec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558aba6d4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558aba6ff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa6cbbe5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558ab3ff9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x40,0x24,0x28,0x72,0x29,0x40,0x24,0x14,0xa,0x0,0x0,0x0, Step #5: @$(r)@$\024\012\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0d2c37ad446227ad17055ceecc53707464d7b17a Step #5: Base64: QCQocilAJBQKAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1555 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2486463703 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a70388a810, 0x55a703a7401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a703a74020,0x55a70590c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0d2c37ad446227ad17055ceecc53707464d7b17a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1792 processed earlier; will process 9237 files now Step #5: #1 pulse cov: 3403 ft: 3404 exec/s: 0 rss: 167Mb Step #5: #2 pulse cov: 10900 ft: 11659 exec/s: 0 rss: 189Mb Step #5: ==56014== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a6fa37f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a7009e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a7009c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a7009c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a6fa385d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a6fa2e6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a6fa2e1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a6fa377c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a6fd346f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a6fd346f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a6fd346f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a6fd346f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a6fd346f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a6fd346f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a6fd346f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a6fd346f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a6fd346f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a6fd346f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a6ff5dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a6fc308b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a6fc313be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a6fc0bfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a6fc0bfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a6fc0c0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a6fc0bf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a6fc0bf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a6fc0bf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a7009c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a7009d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a7009ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a7009e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c77f4f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a6fa2dfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x29,0xc2,0x85,0x29,0xc2,0x85,0x29,0xc2,0x85,0x29,0xc2,0x85, Step #5: )\302\205)\302\205)\302\205)\302\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-32149f3bb1c1fb9d39e8a2942a6cdc43d41cb72f Step #5: Base64: KcKFKcKFKcKFKcKF Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1556 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2487013611 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55849fed0810, 0x5584a00ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5584a00ba020,0x5584a1f520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/32149f3bb1c1fb9d39e8a2942a6cdc43d41cb72f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1795 processed earlier; will process 9234 files now Step #5: ==56050== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5584969c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55849d02a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55849d00d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55849d00d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5584969cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55849692cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558496927355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5584969bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55849998cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55849998cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55849998cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55849998cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55849998cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55849998cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55849998cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55849998cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55849998cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55849998cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55849bc21f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55849894eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558498959be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558498705c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558498705c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558498706738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558498705874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558498705874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558498705874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55849d00fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55849d018928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55849d000699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55849d02b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f585b053082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558496925b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x6d,0x61,0x78,0x5f,0x37,0x3a,0x24,0x36, Step #5: $3::{max_7:$6 Step #5: artifact_prefix='./'; Test unit written to ./oom-58e9854d1c3da169466922ec3bb436cd0ad2b776 Step #5: Base64: JDM6OnttYXhfNzokNg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1557 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2487471540 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565156655810, 0x56515683f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56515683f020,0x5651586d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58e9854d1c3da169466922ec3bb436cd0ad2b776' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1796 processed earlier; will process 9233 files now Step #5: ==56086== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56514d14a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5651537af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651537925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651537924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56514d150d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56514d0b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56514d0ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56514d142c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565150111f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565150111f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565150111f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565150111f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565150111f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565150111f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565150111f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565150111f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565150111f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565150111f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5651523a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56514f0d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56514f0debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56514ee8ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56514ee8ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56514ee8b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56514ee8a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56514ee8a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56514ee8a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565153794abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56515379d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565153785699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5651537b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc0aabaa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56514d0aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x2a,0x24,0x2,0xd7,0x80,0x0,0x0,0x0,0x0,0x0,0x0,0x2, Step #5: $*$\002\327\200\000\000\000\000\000\000\002 Step #5: artifact_prefix='./'; Test unit written to ./oom-31151909ba10f86d0f8320b9804ae3c1366b9f9a Step #5: Base64: JCokAteAAAAAAAAAAg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1558 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2487929906 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b3c488810, 0x558b3c67201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b3c672020,0x558b3e50a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/31151909ba10f86d0f8320b9804ae3c1366b9f9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1797 processed earlier; will process 9232 files now Step #5: ==56122== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558b32f7d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b395e2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b395c55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b395c54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b32f83d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b32ee4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b32edf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b32f75c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b35f44f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b35f44f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b35f44f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b35f44f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b35f44f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b35f44f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b35f44f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b35f44f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b35f44f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b35f44f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b381d9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b34f06b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b34f11be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b34cbdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b34cbdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b34cbe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b34cbd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b34cbd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b34cbd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b395c7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b395d0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b395b8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b395e3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f572ae80082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b32eddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x5b,0x30,0x2e,0xb,0x30,0x2e, Step #5: trailer[0.\0130. Step #5: artifact_prefix='./'; Test unit written to ./oom-8bec9ce823c64988cb8fd58626d933e99293b42f Step #5: Base64: dHJhaWxlclswLgswLg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1559 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2488383301 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563b739c6810, 0x563b73bb001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563b73bb0020,0x563b75a480e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8bec9ce823c64988cb8fd58626d933e99293b42f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1798 processed earlier; will process 9231 files now Step #5: ==56158== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563b6a4bb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563b70b20898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563b70b035dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563b70b034fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563b6a4c1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563b6a422b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563b6a41d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563b6a4b3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563b6d482f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563b6d482f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563b6d482f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563b6d482f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563b6d482f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563b6d482f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563b6d482f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563b6d482f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563b6d482f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563b6d482f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563b6f717f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563b6c444b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563b6c44fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563b6c1fbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563b6c1fbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563b6c1fc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563b6c1fb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563b6c1fb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563b6c1fb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563b70b05abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563b70b0e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563b70af6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563b70b21112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f93b8c19082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563b6a41bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x58,0x2e,0x73,0x6c,0x69,0x63,0x65,0xa,0x74,0x6d,0x70,0x72, Step #5: \012X.slice\012tmpr Step #5: artifact_prefix='./'; Test unit written to ./oom-8df1df9dd4f8acfb014d00bd7aca73163cea3338 Step #5: Base64: Clguc2xpY2UKdG1wcg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1560 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2488839034 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560713d79810, 0x560713f6301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560713f63020,0x560715dfb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8df1df9dd4f8acfb014d00bd7aca73163cea3338' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1799 processed earlier; will process 9230 files now Step #5: ==56194== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56070a86e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560710ed3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560710eb65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560710eb64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56070a874d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56070a7d5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56070a7d0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56070a866c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56070d835f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56070d835f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56070d835f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56070d835f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56070d835f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56070d835f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56070d835f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56070d835f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56070d835f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56070d835f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56070facaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56070c7f7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56070c802be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56070c5aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56070c5aec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56070c5af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56070c5ae874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56070c5ae874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56070c5ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560710eb8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560710ec1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560710ea9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560710ed4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b824e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56070a7ceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x5b,0x63,0xe,0x68,0x43,0xdd,0xa2,0xda,0xae,0xa5,0x70, Step #5: \000\000[c\016hC\335\242\332\256\245p Step #5: artifact_prefix='./'; Test unit written to ./oom-b07e74ed9b294cb41ed1e07037a5cdbf881657b6 Step #5: Base64: AABbYw5oQ92i2q6lcA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1561 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2489296081 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562397b41810, 0x562397d2b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562397d2b020,0x562399bc30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b07e74ed9b294cb41ed1e07037a5cdbf881657b6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1800 processed earlier; will process 9229 files now Step #5: ==56230== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56238e6369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562394c9b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562394c7e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562394c7e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56238e63cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56238e59db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56238e598355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56238e62ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5623915fdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5623915fdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5623915fdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5623915fdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5623915fdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5623915fdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5623915fdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5623915fdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5623915fdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5623915fdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562393892f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5623905bfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5623905cabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562390376c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562390376c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562390377738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562390376874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562390376874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562390376874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562394c80abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562394c89928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562394c71699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562394c9c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe0e9216082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56238e596b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0xab,0x9f,0xbf, Step #5: \357\267\272\357\267\272\357\267\272\360\253\237\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-df82fce608e233afa96c028063371ec9cb8f6a0c Step #5: Base64: 77e677e677e68Kufvw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1562 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2489751656 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d698e9f810, 0x55d69908901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d699089020,0x55d69af210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/df82fce608e233afa96c028063371ec9cb8f6a0c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1801 processed earlier; will process 9228 files now Step #5: ==56266== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d68f9949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d695ff9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d695fdc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d695fdc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d68f99ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d68f8fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d68f8f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d68f98cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d69295bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d69295bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d69295bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d69295bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d69295bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d69295bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d69295bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d69295bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d69295bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d69295bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d694bf0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d69191db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d691928be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d6916d4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d6916d4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d6916d5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d6916d4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d6916d4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d6916d4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d695fdeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d695fe7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d695fcf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d695ffa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe463b3f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d68f8f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0x40, Step #5: ws:\340\275\261\340\275\265\340\275\265@ Step #5: artifact_prefix='./'; Test unit written to ./oom-4b32863943d2d166c05bb466247a996d8148e815 Step #5: Base64: d3M64L2x4L214L21QA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1563 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2490207320 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5612bbaa4810, 0x5612bbc8e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5612bbc8e020,0x5612bdb260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4b32863943d2d166c05bb466247a996d8148e815' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1802 processed earlier; will process 9227 files now Step #5: ==56302== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5612b25999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5612b8bfe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5612b8be15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5612b8be14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5612b259fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5612b2500b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5612b24fb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5612b2591c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5612b5560f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5612b5560f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5612b5560f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5612b5560f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5612b5560f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5612b5560f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5612b5560f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5612b5560f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5612b5560f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5612b5560f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5612b77f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5612b4522b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5612b452dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5612b42d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5612b42d9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5612b42da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5612b42d9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5612b42d9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5612b42d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5612b8be3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5612b8bec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5612b8bd4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5612b8bff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc5e3869082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5612b24f9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x55,0x54,0x20,0x2f,0xa,0x60,0x3a,0x22,0xa,0x60,0x3a,0x35, Step #5: PUT /\012`:\"\012`:5 Step #5: artifact_prefix='./'; Test unit written to ./oom-04fc7b53d75d1d26de433a5f01582fd6933d81a1 Step #5: Base64: UFVUIC8KYDoiCmA6NQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1564 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2490791141 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c898fba810, 0x55c8991a401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c8991a4020,0x55c89b03c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/04fc7b53d75d1d26de433a5f01582fd6933d81a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1803 processed earlier; will process 9226 files now Step #5: ==56338== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c88faaf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c896114898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8960f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8960f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c88fab5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c88fa16b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c88fa11355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c88faa7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c892a76f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c892a76f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c892a76f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c892a76f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c892a76f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c892a76f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c892a76f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c892a76f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c892a76f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c892a76f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c894d0bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c891a38b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c891a43be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c8917efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c8917efc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c8917f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c8917ef874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c8917ef874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c8917ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8960f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c896102928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8960ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c896115112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f127da31082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c88fa0fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x7b,0x7d,0x2b,0x23,0x7b,0x7d,0x2b,0x23,0x7b,0x7d,0x2b,0xb, Step #5: #{}+#{}+#{}+\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-35edc203f7d24a1092c713b7ba4ecbb34f11f040 Step #5: Base64: I3t9KyN7fSsje30rCw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1565 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2491248562 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5635cedf5810, 0x5635cefdf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5635cefdf020,0x5635d0e770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/35edc203f7d24a1092c713b7ba4ecbb34f11f040' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1804 processed earlier; will process 9225 files now Step #5: ==56374== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5635c58ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5635cbf4f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5635cbf325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5635cbf324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5635c58f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5635c5851b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5635c584c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5635c58e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5635c88b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5635c88b1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5635c88b1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5635c88b1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5635c88b1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5635c88b1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5635c88b1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5635c88b1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5635c88b1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5635c88b1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5635cab46f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5635c7873b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5635c787ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5635c762ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5635c762ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5635c762b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5635c762a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5635c762a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5635c762a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5635cbf34abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5635cbf3d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5635cbf25699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5635cbf50112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f01c14c5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5635c584ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e, Step #5: Step #5: artifact_prefix='./'; Test unit written to ./oom-51b38e27957d597794d171dcebe0a46f47ade80e Step #5: Base64: PGRlc2NyaXB0aW9uPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1566 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2491692341 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d7621b810, 0x556d7640501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d76405020,0x556d7829d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/51b38e27957d597794d171dcebe0a46f47ade80e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1805 processed earlier; will process 9224 files now Step #5: ==56410== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556d6cd109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d73375898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d733585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d733584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d6cd16d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d6cc77b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d6cc72355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d6cd08c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d6fcd7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d6fcd7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d6fcd7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d6fcd7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d6fcd7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d6fcd7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d6fcd7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d6fcd7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d6fcd7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d6fcd7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d71f6cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d6ec99b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d6eca4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d6ea50c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d6ea50c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d6ea51738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d6ea50874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d6ea50874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d6ea50874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d7335aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d73363928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d7334b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d73376112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2cd52c1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d6cc70b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x59,0x3a,0x2f,0x2f,0x2b,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: Y://+\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-215f75af069aa8da996040263dd74ff91039e5c8 Step #5: Base64: WTovLyvNhM2EzYTNhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1567 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2492153711 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56245180f810, 0x5624519f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5624519f9020,0x5624538910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/215f75af069aa8da996040263dd74ff91039e5c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1806 processed earlier; will process 9223 files now Step #5: ==56446== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5624483049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56244e969898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56244e94c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56244e94c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56244830ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56244826bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562448266355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5624482fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56244b2cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56244b2cbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56244b2cbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56244b2cbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56244b2cbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56244b2cbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56244b2cbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56244b2cbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56244b2cbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56244b2cbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56244d560f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56244a28db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56244a298be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56244a044c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56244a044c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56244a045738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56244a044874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56244a044874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56244a044874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56244e94eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56244e957928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56244e93f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56244e96a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f35dee30082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562448264b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x69,0xa,0x22,0xe0,0xa0,0xa3,0xe0,0xa1,0x90,0xe0,0xad,0xa7, Step #5: Hi\012\"\340\240\243\340\241\220\340\255\247 Step #5: artifact_prefix='./'; Test unit written to ./oom-5110dd32b4e1bdea53e76565c23f1805dcd91f3a Step #5: Base64: SGkKIuCgo+ChkOCtpw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1568 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2492612572 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf36c52810, 0x55bf36e3c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf36e3c020,0x55bf38cd40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5110dd32b4e1bdea53e76565c23f1805dcd91f3a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1807 processed earlier; will process 9222 files now Step #5: ==56482== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bf2d7479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf33dac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf33d8f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf33d8f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf2d74dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf2d6aeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf2d6a9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf2d73fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf3070ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf3070ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf3070ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf3070ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf3070ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf3070ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf3070ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf3070ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf3070ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf3070ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf329a3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf2f6d0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf2f6dbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf2f487c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf2f487c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf2f488738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf2f487874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf2f487874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf2f487874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf33d91abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf33d9a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf33d82699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf33dad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4094dce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf2d6a7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x2d,0x31,0x2d,0x31,0xd9,0x91,0xd9,0x91,0xd9,0x92,0xd9,0x91, Step #5: 1-1-1\331\221\331\221\331\222\331\221 Step #5: artifact_prefix='./'; Test unit written to ./oom-7edc1626c3acb9c9d3ee492ec251438be1bb7c02 Step #5: Base64: MS0xLTHZkdmR2ZLZkQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1569 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2493076991 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559564de7810, 0x559564fd101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559564fd1020,0x559566e690e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7edc1626c3acb9c9d3ee492ec251438be1bb7c02' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1808 processed earlier; will process 9221 files now Step #5: ==56518== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55955b8dc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559561f41898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559561f245dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559561f244fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55955b8e2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55955b843b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55955b83e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55955b8d4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55955e8a3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55955e8a3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55955e8a3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55955e8a3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55955e8a3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55955e8a3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55955e8a3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55955e8a3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55955e8a3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55955e8a3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559560b38f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55955d865b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55955d870be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55955d61cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55955d61cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55955d61d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55955d61c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55955d61c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55955d61c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559561f26abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559561f2f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559561f17699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559561f42112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa72f00a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55955b83cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33,0xa,0x67,0x22,0x1,0x3f,0xa,0x22,0x22,0x0,0x0,0x0,0x11, Step #5: 3\012g\"\001?\012\"\"\000\000\000\021 Step #5: artifact_prefix='./'; Test unit written to ./oom-b84f33b79e0ec27a7cafd169bd1dbbf5fafab59b Step #5: Base64: MwpnIgE/CiIiAAAAEQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1570 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2493539158 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5597b0528810, 0x5597b071201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5597b0712020,0x5597b25aa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b84f33b79e0ec27a7cafd169bd1dbbf5fafab59b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1809 processed earlier; will process 9220 files now Step #5: ==56554== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5597a701d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5597ad682898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5597ad6655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5597ad6654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5597a7023d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5597a6f84b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5597a6f7f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5597a7015c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5597a9fe4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5597a9fe4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5597a9fe4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5597a9fe4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5597a9fe4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5597a9fe4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5597a9fe4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5597a9fe4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5597a9fe4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5597a9fe4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5597ac279f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5597a8fa6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5597a8fb1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5597a8d5dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5597a8d5dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5597a8d5e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5597a8d5d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5597a8d5d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5597a8d5d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5597ad667abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5597ad670928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5597ad658699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5597ad683112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0fa9afb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5597a6f7db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x2d,0x3d,0x21,0x3d,0x2c,0x2c,0x7e,0x46,0x20,0x29,0x24, Step #5: ~$-=!=,,~F )$ Step #5: artifact_prefix='./'; Test unit written to ./oom-267c82cee97ec6ce872ab673aa27aac29c3c9215 Step #5: Base64: fiQtPSE9LCx+RiApJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1571 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2493999192 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dc1061a810, 0x55dc1080401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dc10804020,0x55dc1269c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/267c82cee97ec6ce872ab673aa27aac29c3c9215' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1810 processed earlier; will process 9219 files now Step #5: ==56590== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dc0710f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dc0d774898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dc0d7575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dc0d7574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dc07115d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dc07076b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dc07071355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dc07107c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dc0a0d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dc0a0d6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dc0a0d6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dc0a0d6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dc0a0d6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dc0a0d6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dc0a0d6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dc0a0d6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dc0a0d6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dc0a0d6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dc0c36bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dc09098b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dc090a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dc08e4fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dc08e4fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dc08e50738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dc08e4f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dc08e4f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dc08e4f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dc0d759abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dc0d762928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dc0d74a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dc0d775112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0a97dd4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dc0706fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x9,0xcd,0x9a,0xd1,0x97,0x9,0xcd,0x8a,0x2c,0x3a, Step #5: \000\000\000\011\315\232\321\227\011\315\212,: Step #5: artifact_prefix='./'; Test unit written to ./oom-72479844f12ea81c213b7738ba2fcbaf22ad773d Step #5: Base64: AAAACc2a0ZcJzYosOg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1572 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2494478970 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556eba32a810, 0x556eba51401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556eba514020,0x556ebc3ac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/72479844f12ea81c213b7738ba2fcbaf22ad773d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1811 processed earlier; will process 9218 files now Step #5: ==56626== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556eb0e1f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556eb7484898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556eb74675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556eb74674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556eb0e25d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556eb0d86b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556eb0d81355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556eb0e17c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556eb3de6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556eb3de6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556eb3de6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556eb3de6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556eb3de6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556eb3de6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556eb3de6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556eb3de6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556eb3de6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556eb3de6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556eb607bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556eb2da8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556eb2db3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556eb2b5fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556eb2b5fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556eb2b60738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556eb2b5f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556eb2b5f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556eb2b5f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556eb7469abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556eb7472928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556eb745a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556eb7485112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc7ad724082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556eb0d7fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x20,0x30,0xde,0xad,0xbe,0xef, Step #5: \007\\_\\_\\_ 0\336\255\276\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-d52c95ccc329c7eb635f5834fb7d8f5893b62214 Step #5: Base64: B1xfXF9cXyAw3q2+7w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1573 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2494935612 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d9170ac810, 0x55d91729601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d917296020,0x55d91912e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d52c95ccc329c7eb635f5834fb7d8f5893b62214' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1812 processed earlier; will process 9217 files now Step #5: #1 pulse cov: 3742 ft: 3743 exec/s: 0 rss: 167Mb Step #5: ==56662== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d90dba19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d914206898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d9141e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d9141e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d90dba7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d90db08b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d90db03355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d90db99c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d910b68f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d910b68f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d910b68f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d910b68f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d910b68f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d910b68f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d910b68f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d910b68f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d910b68f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d910b68f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d912dfdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d90fb2ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d90fb35be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d90f8e1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d90f8e1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d90f8e2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d90f8e1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d90f8e1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d90f8e1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d9141ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d9141f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d9141dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d914207112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fde37303082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d90db01b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x27,0x3c,0x7b,0x27,0x3c,0x7b,0x27,0x3c,0x7b,0x27,0xa,0xa, Step #5: {'<{'<{'<{'\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-b9c7b60e9d59707b20c8942132f35c8fa69014c3 Step #5: Base64: eyc8eyc8eyc8eycKCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1574 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2495426485 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652756bb810, 0x5652758a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652758a5020,0x56527773d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b9c7b60e9d59707b20c8942132f35c8fa69014c3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1814 processed earlier; will process 9215 files now Step #5: ==56698== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56526c1b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565272815898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652727f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652727f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56526c1b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56526c117b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56526c112355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56526c1a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56526f177f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56526f177f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56526f177f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56526f177f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56526f177f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56526f177f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56526f177f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56526f177f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56526f177f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56526f177f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56527140cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56526e139b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56526e144be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56526def0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56526def0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56526def1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56526def0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56526def0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56526def0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652727faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565272803928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652727eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565272816112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f09f6e37082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56526c110b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa,0xa,0x8,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0, Step #5: \012\012\012\012\010\012\000\012\000\012\000\012\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4ed3f9150b25dc1726c7aaa596fc92c378e04592 Step #5: Base64: CgoKCggKAAoACgAKAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1575 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2495884677 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5573913ed810, 0x5573915d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5573915d7020,0x55739346f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4ed3f9150b25dc1726c7aaa596fc92c378e04592' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1815 processed earlier; will process 9214 files now Step #5: ==56734== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557387ee29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55738e547898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55738e52a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55738e52a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557387ee8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557387e49b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557387e44355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557387edac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55738aea9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55738aea9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55738aea9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55738aea9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55738aea9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55738aea9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55738aea9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55738aea9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55738aea9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55738aea9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55738d13ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557389e6bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557389e76be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557389c22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557389c22c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557389c23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557389c22874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557389c22874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557389c22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55738e52cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55738e535928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55738e51d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55738e548112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2753f92082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557387e42b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x11,0x0,0x0,0x0,0x2,0x4e,0x6f,0xcc,0x9c,0x0,0xdb, Step #5: \000\000\021\000\000\000\002No\314\234\000\333 Step #5: artifact_prefix='./'; Test unit written to ./oom-92d5fa14614c91e8348d4b6ce8cc0d5c029abab9 Step #5: Base64: AAARAAAAAk5vzJwA2w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1576 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2496338738 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7002be810, 0x55b7004a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7004a8020,0x55b7023400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92d5fa14614c91e8348d4b6ce8cc0d5c029abab9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1816 processed earlier; will process 9213 files now Step #5: ==56770== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b6f6db39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b6fd418898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b6fd3fb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b6fd3fb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6f6db9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6f6d1ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6f6d15355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6f6dabc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b6f9d7af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b6f9d7af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b6f9d7af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b6f9d7af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b6f9d7af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b6f9d7af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b6f9d7af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b6f9d7af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b6f9d7af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b6f9d7af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b6fc00ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6f8d3cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6f8d47be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6f8af3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6f8af3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6f8af4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6f8af3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6f8af3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6f8af3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b6fd3fdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b6fd406928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b6fd3ee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b6fd419112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8cf5fe9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6f6d13b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0xf0,0x91,0x91,0x82,0xf0,0x91,0x91,0x82,0xcc,0x98,0xcc,0xb8, Step #5: .\360\221\221\202\360\221\221\202\314\230\314\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-d26e33dbffc6a53c85b1bb3fa7b9552d7b3e6dd1 Step #5: Base64: LvCRkYLwkZGCzJjMuA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1577 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2496793703 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c2a69c810, 0x559c2a88601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c2a886020,0x559c2c71e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d26e33dbffc6a53c85b1bb3fa7b9552d7b3e6dd1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1817 processed earlier; will process 9212 files now Step #5: ==56806== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559c211919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c277f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c277d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c277d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c21197d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c210f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c210f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c21189c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c24158f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c24158f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c24158f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c24158f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c24158f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c24158f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c24158f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c24158f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c24158f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c24158f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c263edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c2311ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c23125be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c22ed1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c22ed1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c22ed2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c22ed1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c22ed1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c22ed1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c277dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c277e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c277cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c277f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff686bed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c210f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x9,0xe3,0x80,0xad,0xe2,0xa0,0xa1,0xe2,0xa0,0xa9, Step #5: \000\000\000\011\343\200\255\342\240\241\342\240\251 Step #5: artifact_prefix='./'; Test unit written to ./oom-d0accb164cfaff48b849034d859e3bf077e4d801 Step #5: Base64: AAAACeOAreKgoeKgqQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1578 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2497245849 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610ec827810, 0x5610eca1101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610eca11020,0x5610ee8a90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d0accb164cfaff48b849034d859e3bf077e4d801' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1818 processed earlier; will process 9211 files now Step #5: #1 pulse cov: 3426 ft: 3427 exec/s: 0 rss: 166Mb Step #5: #2 pulse cov: 3790 ft: 4082 exec/s: 0 rss: 168Mb Step #5: ==56842== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5610e331c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610e9981898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610e99645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610e99644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610e3322d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610e3283b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610e327e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610e3314c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610e62e3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610e62e3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610e62e3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610e62e3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610e62e3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610e62e3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610e62e3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610e62e3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610e62e3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610e62e3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610e8578f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610e52a5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610e52b0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610e505cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610e505cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610e505d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610e505c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610e505c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610e505c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610e9966abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610e996f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610e9957699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610e9982112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb98e106082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610e327cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0xe1,0x88,0xaf,0x78,0xfb,0x75,0xa2,0xa2,0x75,0xa2,0xa2,0xbb, Step #5: F\341\210\257x\373u\242\242u\242\242\273 Step #5: artifact_prefix='./'; Test unit written to ./oom-3977c5fc77d511eb6aafa3e31e730f0b2ffa5458 Step #5: Base64: RuGIr3j7daKidaKiuw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1579 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2497784003 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5581f12a2810, 0x5581f148c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5581f148c020,0x5581f33240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3977c5fc77d511eb6aafa3e31e730f0b2ffa5458' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1821 processed earlier; will process 9208 files now Step #5: ==56878== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5581e7d979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5581ee3fc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5581ee3df5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5581ee3df4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5581e7d9dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5581e7cfeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5581e7cf9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5581e7d8fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5581ead5ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5581ead5ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5581ead5ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5581ead5ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5581ead5ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5581ead5ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5581ead5ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5581ead5ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5581ead5ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5581ead5ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5581ecff3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5581e9d20b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5581e9d2bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5581e9ad7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5581e9ad7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5581e9ad8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5581e9ad7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5581e9ad7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5581e9ad7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5581ee3e1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5581ee3ea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5581ee3d2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5581ee3fd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b72f04082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5581e7cf7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x84,0x81,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0x7e, Step #5: \341\204\201\341\205\260\341\204\221\341\205\260~ Step #5: artifact_prefix='./'; Test unit written to ./oom-e04e7643c1cabafef0a2de23558b86b953dd6506 Step #5: Base64: 4YSB4YWw4YSR4YWwfg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1580 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2498246674 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558265fd6810, 0x5582661c001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5582661c0020,0x5582680580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e04e7643c1cabafef0a2de23558b86b953dd6506' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1822 processed earlier; will process 9207 files now Step #5: ==56914== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55825cacb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558263130898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5582631135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5582631134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55825cad1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55825ca32b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55825ca2d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55825cac3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55825fa92f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55825fa92f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55825fa92f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55825fa92f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55825fa92f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55825fa92f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55825fa92f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55825fa92f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55825fa92f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55825fa92f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558261d27f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55825ea54b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55825ea5fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55825e80bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55825e80bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55825e80c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55825e80b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55825e80b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55825e80b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558263115abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55826311e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558263106699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558263131112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f84181de082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55825ca2bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7f,0x68,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x8,0x24, Step #5: \177h$\000\000\000\000\000\000\000\000\010$ Step #5: artifact_prefix='./'; Test unit written to ./oom-554815461390fdfbbfdb07c96d51a9667566612d Step #5: Base64: f2gkAAAAAAAAAAAIJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1581 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2498712337 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b2b544810, 0x555b2b72e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b2b72e020,0x555b2d5c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/554815461390fdfbbfdb07c96d51a9667566612d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1823 processed earlier; will process 9206 files now Step #5: ==56950== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555b220399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b2869e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b286815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b286814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b2203fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b21fa0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b21f9b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b22031c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b25000f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b25000f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b25000f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b25000f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b25000f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b25000f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b25000f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b25000f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b25000f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b25000f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b27295f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b23fc2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b23fcdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b23d79c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b23d79c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b23d7a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b23d79874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b23d79874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b23d79874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b28683abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b2868c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b28674699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b2869f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f80a1e2b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b21f99b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x0,0x0,0x20,0x0,0x1e,0x1e,0x28,0x23,0x24,0x24,0x2f, Step #5: = \000\000 \000\036\036(#$$/ Step #5: artifact_prefix='./'; Test unit written to ./oom-511a64f9ae8bb1567a9e28766319e70fb5e1fdd4 Step #5: Base64: PSAAACAAHh4oIyQkLw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1582 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2499168280 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56481f346810, 0x56481f53001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56481f530020,0x5648213c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/511a64f9ae8bb1567a9e28766319e70fb5e1fdd4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1824 processed earlier; will process 9205 files now Step #5: ==56986== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564815e3b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56481c4a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56481c4835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56481c4834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564815e41d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564815da2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564815d9d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564815e33c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564818e02f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564818e02f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564818e02f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564818e02f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564818e02f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564818e02f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564818e02f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564818e02f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564818e02f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564818e02f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56481b097f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564817dc4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564817dcfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564817b7bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564817b7bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564817b7c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564817b7b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564817b7b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564817b7b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56481c485abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56481c48e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56481c476699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56481c4a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f92dc82f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564815d9bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x30,0x39,0x2c,0x32, Step #5: -2147483609,2 Step #5: artifact_prefix='./'; Test unit written to ./oom-00072aef9b99355fb86bbfe4796700f3b71b1a6f Step #5: Base64: LTIxNDc0ODM2MDksMg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1583 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2499621963 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c0c98d8810, 0x55c0c9ac201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c0c9ac2020,0x55c0cb95a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/00072aef9b99355fb86bbfe4796700f3b71b1a6f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1825 processed earlier; will process 9204 files now Step #5: #1 pulse cov: 3774 ft: 3775 exec/s: 0 rss: 167Mb Step #5: ==57022== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c0c03cd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c0c6a32898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c0c6a155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c0c6a154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c0c03d3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c0c0334b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c0c032f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c0c03c5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c0c3394f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c0c3394f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c0c3394f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c0c3394f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c0c3394f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c0c3394f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c0c3394f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c0c3394f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c0c3394f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c0c3394f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c0c5629f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c0c2356b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c0c2361be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c0c210dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c0c210dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c0c210e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c0c210d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c0c210d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c0c210d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c0c6a17abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c0c6a20928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c0c6a08699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c0c6a33112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc2a4601082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c0c032db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3b,0xa,0x3d,0x24, Step #5: $=\012=\012=\012=\012;\012=$ Step #5: artifact_prefix='./'; Test unit written to ./oom-81edf5d4676f7168930065bee104d27d9f1df22f Step #5: Base64: JD0KPQo9Cj0KOwo9JA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1584 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2500113542 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4edec1810, 0x55e4ee0ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4ee0ab020,0x55e4eff430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/81edf5d4676f7168930065bee104d27d9f1df22f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1827 processed earlier; will process 9202 files now Step #5: ==57058== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e4e49b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4eb01b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4eaffe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4eaffe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4e49bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4e491db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4e4918355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4e49aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4e797df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4e797df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4e797df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4e797df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4e797df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4e797df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4e797df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4e797df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4e797df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4e797df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4e9c12f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4e693fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4e694abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4e66f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4e66f6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4e66f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4e66f6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4e66f6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4e66f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4eb000abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4eb009928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4eaff1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4eb01c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa83f286082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4e4916b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x61,0x5c,0x23,0x73,0x63,0x65,0x6e,0x74,0x20,0x5c,0x23,0x23,0x68, Step #5: a\\#scent \\##h Step #5: artifact_prefix='./'; Test unit written to ./oom-a9db4aff3df2250a0c52102b301c549c18be7682 Step #5: Base64: YVwjc2NlbnQgXCMjaA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1585 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2500566928 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640060ff810, 0x5640062e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640062e9020,0x5640081810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9db4aff3df2250a0c52102b301c549c18be7682' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1828 processed earlier; will process 9201 files now Step #5: ==57094== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563ffcbf49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564003259898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56400323c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56400323c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563ffcbfad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563ffcb5bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563ffcb56355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563ffcbecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563fffbbbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563fffbbbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563fffbbbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563fffbbbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563fffbbbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563fffbbbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563fffbbbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563fffbbbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563fffbbbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563fffbbbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564001e50f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563ffeb7db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563ffeb88be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563ffe934c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563ffe934c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563ffe935738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563ffe934874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563ffe934874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563ffe934874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56400323eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564003247928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56400322f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56400325a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f57a239c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563ffcb54b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x2a,0xa,0x1,0x0,0x2a,0x3d,0xa,0x3d,0xa,0x2a,0x0,0x34, Step #5: **\012\001\000*=\012=\012*\0004 Step #5: artifact_prefix='./'; Test unit written to ./oom-4a799c3b639419aacb4075491d65f68c07519f6f Step #5: Base64: KioKAQAqPQo9CioANA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1586 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2501018671 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db45d27810, 0x55db45f1101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db45f11020,0x55db47da90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4a799c3b639419aacb4075491d65f68c07519f6f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1829 processed earlier; will process 9200 files now Step #5: ==57130== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55db3c81c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db42e81898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db42e645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db42e644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db3c822d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db3c783b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db3c77e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db3c814c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db3f7e3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db3f7e3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db3f7e3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db3f7e3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db3f7e3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db3f7e3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db3f7e3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db3f7e3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db3f7e3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db3f7e3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db41a78f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db3e7a5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db3e7b0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db3e55cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db3e55cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db3e55d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db3e55c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db3e55c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db3e55c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db42e66abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db42e6f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db42e57699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db42e82112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa68de64082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db3c77cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7f,0x4,0x61,0x24,0x4,0x4,0x20,0xa,0x25,0x6e,0x24,0x30,0x3d, Step #5: \177\004a$\004\004 \012%n$0= Step #5: artifact_prefix='./'; Test unit written to ./oom-8ece2770bf083332f777e15d848559187ddd3495 Step #5: Base64: fwRhJAQEIAolbiQwPQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1587 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2501489350 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556804fbb810, 0x5568051a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5568051a5020,0x55680703d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ece2770bf083332f777e15d848559187ddd3495' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1830 processed earlier; will process 9199 files now Step #5: ==57166== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5567fbab09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556802115898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5568020f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5568020f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5567fbab6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5567fba17b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5567fba12355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5567fbaa8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5567fea77f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5567fea77f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5567fea77f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5567fea77f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5567fea77f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5567fea77f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5567fea77f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5567fea77f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5567fea77f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5567fea77f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556800d0cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5567fda39b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5567fda44be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5567fd7f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5567fd7f0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5567fd7f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5567fd7f0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5567fd7f0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5567fd7f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5568020faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556802103928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5568020eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556802116112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4cb5dff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5567fba10b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x5c,0x75,0x7b,0x62,0x44,0x7d,0x5c,0x75,0x7b,0x62,0x44,0x7d, Step #5: '\\u{bD}\\u{bD} Step #5: artifact_prefix='./'; Test unit written to ./oom-f30e979c7623d6ce3217a6aa750e2afe7735ed92 Step #5: Base64: J1x1e2JEfVx1e2JEfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1588 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2501945516 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d560aa810, 0x563d5629401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d56294020,0x563d5812c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f30e979c7623d6ce3217a6aa750e2afe7735ed92' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1831 processed earlier; will process 9198 files now Step #5: ==57202== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563d4cb9f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d53204898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d531e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d531e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d4cba5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d4cb06b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d4cb01355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d4cb97c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d4fb66f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d4fb66f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d4fb66f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d4fb66f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d4fb66f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d4fb66f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d4fb66f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d4fb66f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d4fb66f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d4fb66f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d51dfbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d4eb28b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d4eb33be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d4e8dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d4e8dfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d4e8e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d4e8df874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d4e8df874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d4e8df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d531e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d531f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d531da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d53205112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6cdcfeb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d4caffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x9,0x3d,0x3,0x54,0x54,0x54,0x54,0xe2,0x81,0xa7,0xa7,0x3d, Step #5: -\011=\003TTTT\342\201\247\247= Step #5: artifact_prefix='./'; Test unit written to ./oom-04c021e13fe2a140020a28d53efc99e8b8cf309a Step #5: Base64: LQk9A1RUVFTigaenPQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1589 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2502408189 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557a64deb810, 0x557a64fd501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557a64fd5020,0x557a66e6d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/04c021e13fe2a140020a28d53efc99e8b8cf309a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1832 processed earlier; will process 9197 files now Step #5: ==57238== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557a5b8e09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557a61f45898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557a61f285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557a61f284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557a5b8e6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557a5b847b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557a5b842355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557a5b8d8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557a5e8a7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557a5e8a7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557a5e8a7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557a5e8a7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557a5e8a7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557a5e8a7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557a5e8a7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557a5e8a7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557a5e8a7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557a5e8a7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557a60b3cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557a5d869b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557a5d874be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557a5d620c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557a5d620c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557a5d621738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557a5d620874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557a5d620874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557a5d620874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557a61f2aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557a61f33928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557a61f1b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557a61f46112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faabc59b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557a5b840b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0xc7,0xb2,0xc7,0xb3,0x5d,0x7c,0x5b,0xc7,0xb2,0xc7,0xb3,0x5d, Step #5: [\307\262\307\263]|[\307\262\307\263] Step #5: artifact_prefix='./'; Test unit written to ./oom-339dfe05634fce4647b8f0982f07fb288e1c5d56 Step #5: Base64: W8eyx7NdfFvHssezXQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1590 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2502882741 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5574b7a3e810, 0x5574b7c2801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5574b7c28020,0x5574b9ac00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/339dfe05634fce4647b8f0982f07fb288e1c5d56' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1833 processed earlier; will process 9196 files now Step #5: #1 pulse cov: 3526 ft: 3527 exec/s: 0 rss: 167Mb Step #5: ==57274== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5574ae5339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5574b4b98898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5574b4b7b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5574b4b7b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5574ae539d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5574ae49ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5574ae495355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5574ae52bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5574b14faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5574b14faf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5574b14faf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5574b14faf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5574b14faf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5574b14faf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5574b14faf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5574b14faf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5574b14faf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5574b14faf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5574b378ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5574b04bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5574b04c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5574b0273c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5574b0273c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5574b0274738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5574b0273874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5574b0273874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5574b0273874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5574b4b7dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5574b4b86928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5574b4b6e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5574b4b99112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f59db109082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5574ae493b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x47,0x52,0x4f,0x55,0x50,0x3d,0x22,0x62,0x61,0x63,0x6b,0x74,0x22, Step #5: GROUP=\"backt\" Step #5: artifact_prefix='./'; Test unit written to ./oom-bbf6b8a8197b64f2cac0e81c16a2f64f08c6599e Step #5: Base64: R1JPVVA9ImJhY2t0Ig== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1591 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2503385159 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c02d03a810, 0x55c02d22401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c02d224020,0x55c02f0bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bbf6b8a8197b64f2cac0e81c16a2f64f08c6599e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1835 processed earlier; will process 9194 files now Step #5: ==57310== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c023b2f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c02a194898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c02a1775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c02a1774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c023b35d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c023a96b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c023a91355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c023b27c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c026af6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c026af6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c026af6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c026af6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c026af6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c026af6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c026af6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c026af6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c026af6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c026af6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c028d8bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c025ab8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c025ac3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c02586fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c02586fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c025870738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c02586f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c02586f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c02586f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c02a179abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c02a182928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c02a16a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c02a195112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f50106082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c023a8fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x20,0x30,0x20,0x31,0x20,0x30,0x20,0x30,0x20,0x30,0xa,0x30, Step #5: 0 0 1 0 0 0\0120 Step #5: artifact_prefix='./'; Test unit written to ./oom-2b8e0beff686de06bd4daa3adb9bb6fa00afedbf Step #5: Base64: MCAwIDEgMCAwIDAKMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1592 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2503845437 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56530b60f810, 0x56530b7f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56530b7f9020,0x56530d6910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2b8e0beff686de06bd4daa3adb9bb6fa00afedbf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1836 processed earlier; will process 9193 files now Step #5: ==57346== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5653021049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565308769898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56530874c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56530874c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56530210ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56530206bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565302066355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5653020fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5653050cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5653050cbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5653050cbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5653050cbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5653050cbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5653050cbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5653050cbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5653050cbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5653050cbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5653050cbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565307360f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56530408db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565304098be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565303e44c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565303e44c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565303e45738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565303e44874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565303e44874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565303e44874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56530874eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565308757928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56530873f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56530876a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f43da721082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565302064b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x21,0x50,0x61,0x67,0x65,0x4d,0x65,0x64,0x69,0x61,0x3a,0x34, Step #5: %!PageMedia:4 Step #5: artifact_prefix='./'; Test unit written to ./oom-a16bbd0d904b0c89e6a61ae56c84a463a706d524 Step #5: Base64: JSFQYWdlTWVkaWE6NA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1593 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2504303995 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5646056f6810, 0x5646058e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5646058e0020,0x5646077780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a16bbd0d904b0c89e6a61ae56c84a463a706d524' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1837 processed earlier; will process 9192 files now Step #5: ==57382== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5645fc1eb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564602850898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5646028335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5646028334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5645fc1f1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5645fc152b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5645fc14d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5645fc1e3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5645ff1b2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5645ff1b2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5645ff1b2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5645ff1b2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5645ff1b2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5645ff1b2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5645ff1b2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5645ff1b2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5645ff1b2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5645ff1b2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564601447f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5645fe174b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5645fe17fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5645fdf2bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5645fdf2bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5645fdf2c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5645fdf2b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5645fdf2b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5645fdf2b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564602835abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56460283e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564602826699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564602851112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9c9554c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5645fc14bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x65,0x6e,0x74,0x72,0x69,0x61,0x22,0x3a,0x5b,0x5d,0x7d, Step #5: {\"entria\":[]} Step #5: artifact_prefix='./'; Test unit written to ./oom-17897d74682e7d2ad389a2322c3e6de2a8de159a Step #5: Base64: eyJlbnRyaWEiOltdfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1594 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2504772773 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d39a0f810, 0x556d39bf901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d39bf9020,0x556d3ba910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/17897d74682e7d2ad389a2322c3e6de2a8de159a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1838 processed earlier; will process 9191 files now Step #5: #1 pulse cov: 10766 ft: 10767 exec/s: 0 rss: 186Mb Step #5: ==57418== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556d305049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d36b69898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d36b4c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d36b4c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d3050ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d3046bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d30466355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d304fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d334cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d334cbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d334cbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d334cbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d334cbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d334cbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d334cbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d334cbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d334cbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d334cbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d35760f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d3248db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d32498be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d32244c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d32244c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d32245738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d32244874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d32244874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d32244874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d36b4eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d36b57928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d36b3f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d36b6a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd12e766082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d30464b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x5c,0x5e,0x5c,0x5e,0x5c,0x5e,0x20,0x3f,0xde,0xad,0xbe,0xef, Step #5: \003\\^\\^\\^ ?\336\255\276\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-128ebf6cf75a526bc29e77e1c8089941c95278e3 Step #5: Base64: A1xeXF5cXiA/3q2+7w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1595 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2505299808 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56380e00a810, 0x56380e1f401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56380e1f4020,0x56381008c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/128ebf6cf75a526bc29e77e1c8089941c95278e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1840 processed earlier; will process 9189 files now Step #5: ==57454== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563804aff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56380b164898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56380b1475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56380b1474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563804b05d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563804a66b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563804a61355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563804af7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563807ac6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563807ac6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563807ac6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563807ac6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563807ac6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563807ac6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563807ac6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563807ac6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563807ac6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563807ac6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563809d5bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563806a88b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563806a93be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56380683fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56380683fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563806840738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56380683f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56380683f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56380683f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56380b149abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56380b152928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56380b13a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56380b165112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fde46b79082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563804a5fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4,0x5c,0x24,0x5c,0x24,0x5c,0x24,0xb,0x5c,0xde,0xad,0xbe,0xef, Step #5: \004\\$\\$\\$\013\\\336\255\276\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-eb3f9ca306539250db23a1736cd1be23d587666d Step #5: Base64: BFwkXCRcJAtc3q2+7w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1596 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2505761992 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56508e6f5810, 0x56508e8df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56508e8df020,0x5650907770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eb3f9ca306539250db23a1736cd1be23d587666d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1841 processed earlier; will process 9188 files now Step #5: ==57490== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5650851ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56508b84f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56508b8325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56508b8324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5650851f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565085151b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56508514c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5650851e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5650881b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5650881b1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5650881b1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5650881b1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5650881b1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5650881b1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5650881b1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5650881b1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5650881b1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5650881b1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56508a446f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565087173b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56508717ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565086f2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565086f2ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565086f2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565086f2a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565086f2a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565086f2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56508b834abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56508b83d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56508b825699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56508b850112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f41cf402082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56508514ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0x6b,0x6b,0x68,0x6b,0x6b,0x6b,0x73,0x68,0x65,0x32,0xff,0x54, Step #5: 2kkhkkkshe2\377T Step #5: artifact_prefix='./'; Test unit written to ./oom-3659d4e4ac67044fd1404c6d73a3b543dff014ab Step #5: Base64: MmtraGtra3NoZTL/VA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1597 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2506223878 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560db9133810, 0x560db931d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560db931d020,0x560dbb1b50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3659d4e4ac67044fd1404c6d73a3b543dff014ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1842 processed earlier; will process 9187 files now Step #5: ==57526== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560dafc289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560db628d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560db62705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560db62704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560dafc2ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560dafb8fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560dafb8a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560dafc20c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560db2beff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560db2beff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560db2beff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560db2beff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560db2beff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560db2beff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560db2beff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560db2beff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560db2beff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560db2beff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560db4e84f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560db1bb1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560db1bbcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560db1968c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560db1968c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560db1969738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560db1968874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560db1968874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560db1968874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560db6272abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560db627b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560db6263699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560db628e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f512bd6e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560dafb88b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0xa,0x20,0xa,0x20,0xa,0x20,0xa,0x70,0xd,0xa,0xd,0xa, Step #5: :\012 \012 \012 \012p\015\012\015\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-9ff41854e5388b30ada42414a0d268110a956e9e Step #5: Base64: OgogCiAKIApwDQoNCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1598 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2506683622 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f034524810, 0x55f03470e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f03470e020,0x55f0365a60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9ff41854e5388b30ada42414a0d268110a956e9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1843 processed earlier; will process 9186 files now Step #5: ==57562== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f02b0199c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f03167e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f0316615dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f0316614fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f02b01fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f02af80b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f02af7b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f02b011c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f02dfe0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f02dfe0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f02dfe0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f02dfe0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f02dfe0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f02dfe0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f02dfe0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f02dfe0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f02dfe0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f02dfe0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f030275f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f02cfa2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f02cfadbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f02cd59c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f02cd59c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f02cd5a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f02cd59874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f02cd59874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f02cd59874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f031663abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f03166c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f031654699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f03167f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d4af0d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f02af79b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x4d,0x50,0x4f,0x52,0x54,0x7b,0x62,0x75,0x7d,0x3d,0x22,0x22, Step #5: IMPORT{bu}=\"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-bc56b0a4555830b6ec641e245d0f4e8244f3d9d2 Step #5: Base64: SU1QT1JUe2J1fT0iIg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1599 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2507141215 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55744c5ef810, 0x55744c7d901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55744c7d9020,0x55744e6710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bc56b0a4555830b6ec641e245d0f4e8244f3d9d2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1844 processed earlier; will process 9185 files now Step #5: #1 pulse cov: 3590 ft: 3591 exec/s: 0 rss: 168Mb Step #5: ==57598== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5574430e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557449749898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55744972c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55744972c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5574430ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55744304bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557443046355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5574430dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5574460abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5574460abf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5574460abf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5574460abf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5574460abf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5574460abf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5574460abf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5574460abf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5574460abf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5574460abf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557448340f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55744506db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557445078be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557444e24c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557444e24c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557444e25738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557444e24874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557444e24874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557444e24874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55744972eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557449737928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55744971f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55744974a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbc0ed7d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557443044b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x18,0xa,0x14,0xa,0x14,0x22,0x12,0x30,0x10,0x18,0x8,0x29, Step #5: \012\030\012\024\012\024\"\0220\020\030\010) Step #5: artifact_prefix='./'; Test unit written to ./oom-a3d7e4070d937efe30aba27bcc1dda8ccdd046b2 Step #5: Base64: ChgKFAoUIhIwEBgIKQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1600 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2507644920 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a457fa9810, 0x55a45819301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a458193020,0x55a45a02b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a3d7e4070d937efe30aba27bcc1dda8ccdd046b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1846 processed earlier; will process 9183 files now Step #5: #1 pulse cov: 3812 ft: 3813 exec/s: 0 rss: 167Mb Step #5: ==57634== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a44ea9e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a455103898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a4550e65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a4550e64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a44eaa4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a44ea05b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a44ea00355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a44ea96c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a451a65f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a451a65f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a451a65f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a451a65f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a451a65f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a451a65f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a451a65f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a451a65f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a451a65f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a451a65f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a453cfaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a450a27b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a450a32be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a4507dec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a4507dec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a4507df738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a4507de874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a4507de874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a4507de874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a4550e8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a4550f1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a4550d9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a455104112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e40004082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a44e9feb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x35,0x2c,0x31, Step #5: -2147483645,1 Step #5: artifact_prefix='./'; Test unit written to ./oom-072ed86f6c72d56b148da247235ac7141c5d63c1 Step #5: Base64: LTIxNDc0ODM2NDUsMQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1601 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2508140408 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558ce9360810, 0x558ce954a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558ce954a020,0x558ceb3e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/072ed86f6c72d56b148da247235ac7141c5d63c1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1848 processed earlier; will process 9181 files now Step #5: ==57670== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558cdfe559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558ce64ba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558ce649d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558ce649d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558cdfe5bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558cdfdbcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558cdfdb7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558cdfe4dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558ce2e1cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558ce2e1cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558ce2e1cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558ce2e1cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558ce2e1cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558ce2e1cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558ce2e1cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558ce2e1cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558ce2e1cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558ce2e1cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558ce50b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ce1ddeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ce1de9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ce1b95c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ce1b95c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ce1b96738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ce1b95874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ce1b95874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ce1b95874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558ce649fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558ce64a8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558ce6490699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558ce64bb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3689bf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558cdfdb5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x62,0x6a,0x65,0x63,0x74,0x43,0x6c,0x61,0x73,0x73,0x6e,0x3a, Step #5: objectClassn: Step #5: artifact_prefix='./'; Test unit written to ./oom-46dcce45133752306b81efe671a43761ed39438f Step #5: Base64: b2JqZWN0Q2xhc3NuOg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1602 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2508604342 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5654a3c9e810, 0x5654a3e8801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5654a3e88020,0x5654a5d200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/46dcce45133752306b81efe671a43761ed39438f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1849 processed earlier; will process 9180 files now Step #5: ==57706== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56549a7939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5654a0df8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5654a0ddb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5654a0ddb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56549a799d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56549a6fab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56549a6f5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56549a78bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56549d75af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56549d75af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56549d75af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56549d75af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56549d75af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56549d75af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56549d75af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56549d75af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56549d75af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56549d75af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56549f9eff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56549c71cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56549c727be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56549c4d3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56549c4d3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56549c4d4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56549c4d3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56549c4d3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56549c4d3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5654a0dddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5654a0de6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5654a0dce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5654a0df9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a5d96e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56549a6f3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0x52,0x58,0x73,0x62,0x5f,0x42,0x5f,0x46,0x47,0x5f,0x42,0x5f, Step #5: _RXsb_B_FG_B_ Step #5: artifact_prefix='./'; Test unit written to ./oom-0443d77811b8ae91458fad97d8bf0e5d44cd7633 Step #5: Base64: X1JYc2JfQl9GR19CXw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1603 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2509054467 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560985293810, 0x56098547d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56098547d020,0x5609873150e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0443d77811b8ae91458fad97d8bf0e5d44cd7633' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1850 processed earlier; will process 9179 files now Step #5: ==57742== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56097bd889c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5609823ed898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5609823d05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5609823d04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56097bd8ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56097bcefb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56097bcea355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56097bd80c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56097ed4ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56097ed4ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56097ed4ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56097ed4ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56097ed4ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56097ed4ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56097ed4ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56097ed4ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56097ed4ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56097ed4ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560980fe4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56097dd11b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56097dd1cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56097dac8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56097dac8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56097dac9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56097dac8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56097dac8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56097dac8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5609823d2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5609823db928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5609823c3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5609823ee112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e66f89082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56097bce8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0x3a,0x53,0x3a,0x3a,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b, Step #5: ::S::;;;;;;;; Step #5: artifact_prefix='./'; Test unit written to ./oom-28bd6b8b1e38415bd889cafb189b1eea947d5ef3 Step #5: Base64: OjpTOjo7Ozs7Ozs7Ow== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1604 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2509498994 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556a098c8810, 0x556a09ab201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556a09ab2020,0x556a0b94a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/28bd6b8b1e38415bd889cafb189b1eea947d5ef3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1851 processed earlier; will process 9178 files now Step #5: ==57778== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556a003bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556a06a22898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556a06a055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556a06a054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556a003c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556a00324b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556a0031f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556a003b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556a03384f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556a03384f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556a03384f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556a03384f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556a03384f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556a03384f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556a03384f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556a03384f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556a03384f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556a03384f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556a05619f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556a02346b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556a02351be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556a020fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556a020fdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556a020fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556a020fd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556a020fd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556a020fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556a06a07abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556a06a10928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556a069f8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556a06a23112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff151775082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556a0031db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x58,0xa,0x2b,0xa,0x68,0x6f,0x53,0x74,0x3a,0xf4,0xaa,0xbe,0x8f, Step #5: X\012+\012hoSt:\364\252\276\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-fcbfc5accf9c6f7382bb5b19ce9c0b41e0039234 Step #5: Base64: WAorCmhvU3Q69Kq+jw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1605 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2509949863 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee91386810, 0x55ee9157001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee91570020,0x55ee934080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fcbfc5accf9c6f7382bb5b19ce9c0b41e0039234' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1852 processed earlier; will process 9177 files now Step #5: ==57814== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ee87e7b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee8e4e0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee8e4c35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee8e4c34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee87e81d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee87de2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee87ddd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee87e73c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee8ae42f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee8ae42f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee8ae42f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee8ae42f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee8ae42f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee8ae42f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee8ae42f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee8ae42f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee8ae42f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee8ae42f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee8d0d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee89e04b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee89e0fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee89bbbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee89bbbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee89bbc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee89bbb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee89bbb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee89bbb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee8e4c5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee8e4ce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee8e4b6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee8e4e1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe92f02e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee87ddbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x9,0x3e,0xc2,0x85,0x3e,0xc2,0x85,0x3e,0xc2,0x85, Step #5: \000\000\000\011>\302\205>\302\205>\302\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-c174c4746ffe0ede998c37634b37b12333c20bc7 Step #5: Base64: AAAACT7ChT7ChT7ChQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1606 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2510400869 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a04a80f810, 0x55a04a9f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a04a9f9020,0x55a04c8910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c174c4746ffe0ede998c37634b37b12333c20bc7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1853 processed earlier; will process 9176 files now Step #5: ==57850== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a0413049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a047969898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a04794c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a04794c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a04130ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a04126bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a041266355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0412fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0442cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0442cbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0442cbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0442cbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0442cbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0442cbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0442cbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0442cbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0442cbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0442cbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a046560f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a04328db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a043298be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a043044c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a043044c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a043045738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a043044874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a043044874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a043044874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a04794eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a047957928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a04793f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a04796a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f47ea411082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a041264b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x24,0x5c,0x23,0x36,0x31,0x24,0x5c,0x23,0x36,0x31,0x1f,0x21, Step #5: 1$\\#61$\\#61\037! Step #5: artifact_prefix='./'; Test unit written to ./oom-87fd26fcee9b46fb377193de4b86b248c2daa5ce Step #5: Base64: MSRcIzYxJFwjNjEfIQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1607 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2510851575 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611189bd810, 0x561118ba701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561118ba7020,0x56111aa3f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87fd26fcee9b46fb377193de4b86b248c2daa5ce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1854 processed earlier; will process 9175 files now Step #5: ==57886== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56110f4b29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561115b17898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561115afa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561115afa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56110f4b8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56110f419b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56110f414355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56110f4aac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561112479f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561112479f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561112479f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561112479f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561112479f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561112479f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561112479f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561112479f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561112479f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561112479f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56111470ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56111143bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561111446be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611111f2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611111f2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611111f3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611111f2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611111f2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611111f2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561115afcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561115b05928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561115aed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561115b18112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faba27ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56110f412b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x3c,0x3c,0x7b,0x27,0x3c,0x7b,0x27,0x3c,0x7b,0x27,0xa,0xa, Step #5: {<<{'<{'<{'\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-24b8a4a380db68878b3b85e455f27421f65d5e33 Step #5: Base64: ezw8eyc8eyc8eycKCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1608 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2511298138 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ae10a19810, 0x55ae10c0301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ae10c03020,0x55ae12a9b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/24b8a4a380db68878b3b85e455f27421f65d5e33' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1855 processed earlier; will process 9174 files now Step #5: #1 pulse cov: 3756 ft: 3757 exec/s: 0 rss: 167Mb Step #5: ==57922== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ae0750e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ae0db73898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ae0db565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ae0db564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ae07514d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ae07475b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ae07470355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ae07506c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ae0a4d5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ae0a4d5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ae0a4d5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ae0a4d5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ae0a4d5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ae0a4d5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ae0a4d5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ae0a4d5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ae0a4d5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ae0a4d5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ae0c76af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ae09497b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ae094a2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ae0924ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ae0924ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ae0924f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ae0924e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ae0924e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ae0924e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ae0db58abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ae0db61928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ae0db49699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ae0db74112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c56a40082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ae0746eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x9,0x22,0x5c,0xe2,0x80,0xa9,0x5c,0xe2,0x80,0x9d, Step #5: \000\000\000\011\"\\\342\200\251\\\342\200\235 Step #5: artifact_prefix='./'; Test unit written to ./oom-065d95848098e0496e024804c01212aeffc08cc3 Step #5: Base64: AAAACSJc4oCpXOKAnQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1609 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2511789941 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558f0aa19810, 0x558f0ac0301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558f0ac03020,0x558f0ca9b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/065d95848098e0496e024804c01212aeffc08cc3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1857 processed earlier; will process 9172 files now Step #5: ==57958== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558f0150e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558f07b73898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558f07b565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558f07b564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f01514d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f01475b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f01470355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f01506c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f044d5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f044d5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f044d5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f044d5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f044d5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f044d5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f044d5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f044d5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f044d5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f044d5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558f0676af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f03497b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f034a2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f0324ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f0324ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f0324f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f0324e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f0324e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f0324e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558f07b58abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558f07b61928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558f07b49699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558f07b74112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4e775f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f0146eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xe2,0x85,0x8c,0x3e,0x3c,0xe2,0x85,0x80,0x3c,0xe2,0x85,0x8c, Step #5: <\342\205\214><\342\205\200<\342\205\214 Step #5: artifact_prefix='./'; Test unit written to ./oom-b40bece7a9ac34eb1ee5e71494151dd889d32e8c Step #5: Base64: POKFjD484oWAPOKFjA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1610 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2512236173 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f2ccf5d810, 0x55f2cd14701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f2cd147020,0x55f2cefdf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b40bece7a9ac34eb1ee5e71494151dd889d32e8c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1858 processed earlier; will process 9171 files now Step #5: ==57994== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f2c3a529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f2ca0b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f2ca09a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f2ca09a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f2c3a58d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f2c39b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f2c39b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f2c3a4ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f2c6a19f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f2c6a19f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f2c6a19f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f2c6a19f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f2c6a19f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f2c6a19f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f2c6a19f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f2c6a19f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f2c6a19f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f2c6a19f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f2c8caef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f2c59dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f2c59e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f2c5792c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f2c5792c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f2c5793738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f2c5792874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f2c5792874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f2c5792874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f2ca09cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f2ca0a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f2ca08d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f2ca0b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f44e8c8f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f2c39b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0xa,0x3d,0xcc,0xbb,0xa9,0x0,0xa,0x21,0x6a,0x2d,0x2d,0x2d, Step #5: 0\012=\314\273\251\000\012!j--- Step #5: artifact_prefix='./'; Test unit written to ./oom-1f0e58c4f52e01f0d756e2461f1f2f1432d889b5 Step #5: Base64: MAo9zLupAAohai0tLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1611 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2512687507 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561054857810, 0x561054a4101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561054a41020,0x5610568d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f0e58c4f52e01f0d756e2461f1f2f1432d889b5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1859 processed earlier; will process 9170 files now Step #5: ==58030== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56104b34c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610519b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610519945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610519944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56104b352d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56104b2b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56104b2ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56104b344c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56104e313f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56104e313f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56104e313f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56104e313f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56104e313f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56104e313f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56104e313f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56104e313f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56104e313f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56104e313f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610505a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56104d2d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56104d2e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56104d08cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56104d08cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56104d08d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56104d08c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56104d08c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56104d08c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561051996abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56105199f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561051987699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610519b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f0dce4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56104b2acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7a,0xdc,0xbc,0xdc,0xb9,0xf0,0x9d,0x85,0xa0,0x1e,0xf5,0xdf,0x0, Step #5: z\334\274\334\271\360\235\205\240\036\365\337\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-93deb15c34c8665ec1690c2571b539935efddadb Step #5: Base64: ety83LnwnYWgHvXfAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1612 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2513133711 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a121c2e810, 0x55a121e1801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a121e18020,0x55a123cb00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93deb15c34c8665ec1690c2571b539935efddadb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1860 processed earlier; will process 9169 files now Step #5: ==58066== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a1187239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a11ed88898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a11ed6b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a11ed6b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a118729d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a11868ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a118685355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a11871bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a11b6eaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a11b6eaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a11b6eaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a11b6eaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a11b6eaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a11b6eaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a11b6eaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a11b6eaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a11b6eaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a11b6eaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a11d97ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a11a6acb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a11a6b7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a11a463c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a11a463c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a11a464738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a11a463874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a11a463874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a11a463874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a11ed6dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a11ed76928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a11ed5e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a11ed89112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4015630082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a118683b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1e,0xdb,0xaa,0x0,0xd3,0xaf,0x2c,0xdb,0xaa,0x0,0xd3,0xab,0x71, Step #5: \036\333\252\000\323\257,\333\252\000\323\253q Step #5: artifact_prefix='./'; Test unit written to ./oom-a5073f1c5fbc5ca84ac19b0735114628299c8ed1 Step #5: Base64: HtuqANOvLNuqANOrcQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1613 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2513585026 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55888aed2810, 0x55888b0bc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55888b0bc020,0x55888cf540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a5073f1c5fbc5ca84ac19b0735114628299c8ed1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1861 processed earlier; will process 9168 files now Step #5: ==58102== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5588819c79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55888802c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55888800f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55888800f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588819cdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55888192eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558881929355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588819bfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55888498ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55888498ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55888498ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55888498ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55888498ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55888498ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55888498ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55888498ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55888498ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55888498ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558886c23f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558883950b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55888395bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558883707c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558883707c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558883708738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558883707874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558883707874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558883707874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558888011abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55888801a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558888002699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55888802d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd518d8d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558881927b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x9,0x79,0x2d,0xa,0xa,0xa,0x2d,0xa,0x2d,0xa,0x2f,0x8,0xa, Step #5: \011y-\012\012\012-\012-\012/\010\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-c8c44cb5ae77b025d08d3f0ddd5dfc557f713669 Step #5: Base64: CXktCgoKLQotCi8ICg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1614 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2514041547 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561672451810, 0x56167263b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56167263b020,0x5616744d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c8c44cb5ae77b025d08d3f0ddd5dfc557f713669' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1862 processed earlier; will process 9167 files now Step #5: ==58138== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561668f469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56166f5ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56166f58e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56166f58e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561668f4cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561668eadb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561668ea8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561668f3ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56166bf0df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56166bf0df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56166bf0df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56166bf0df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56166bf0df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56166bf0df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56166bf0df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56166bf0df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56166bf0df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56166bf0df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56166e1a2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56166aecfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56166aedabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56166ac86c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56166ac86c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56166ac87738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56166ac86874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56166ac86874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56166ac86874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56166f590abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56166f599928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56166f581699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56166f5ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f54e298b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561668ea6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x24,0x0,0x0,0x0,0x9,0x7c,0xa,0x0,0x24,0xa,0x7c,0x2f, Step #5: \000$\000\000\000\011|\012\000$\012|/ Step #5: artifact_prefix='./'; Test unit written to ./oom-bf02ecdf37eacde9b6e1a9c6555488ef583077bd Step #5: Base64: ACQAAAAJfAoAJAp8Lw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1615 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2514498413 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5572d019d810, 0x5572d038701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5572d0387020,0x5572d221f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf02ecdf37eacde9b6e1a9c6555488ef583077bd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1863 processed earlier; will process 9166 files now Step #5: ==58174== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5572c6c929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5572cd2f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5572cd2da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5572cd2da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5572c6c98d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5572c6bf9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5572c6bf4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5572c6c8ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5572c9c59f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5572c9c59f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5572c9c59f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5572c9c59f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5572c9c59f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5572c9c59f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5572c9c59f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5572c9c59f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5572c9c59f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5572c9c59f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5572cbeeef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5572c8c1bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5572c8c26be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5572c89d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5572c89d2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5572c89d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5572c89d2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5572c89d2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5572c89d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5572cd2dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5572cd2e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5572cd2cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5572cd2f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ad2d4f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5572c6bf2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x31,0x0,0x3f,0x73,0x6b,0x69,0x35,0x37,0xff, Step #5: ID3\0021\000?ski57\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-1476179aa4e1758482ac2d1b3574bfea5026f30f Step #5: Base64: SUQzAjEAP3NraTU3/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1616 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2514949304 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ce1dcb6810, 0x55ce1dea001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ce1dea0020,0x55ce1fd380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1476179aa4e1758482ac2d1b3574bfea5026f30f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1864 processed earlier; will process 9165 files now Step #5: ==58210== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ce147ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ce1ae10898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ce1adf35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ce1adf34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ce147b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ce14712b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ce1470d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ce147a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ce17772f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ce17772f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ce17772f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ce17772f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ce17772f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ce17772f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ce17772f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ce17772f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ce17772f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ce17772f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ce19a07f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ce16734b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ce1673fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ce164ebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ce164ebc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ce164ec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ce164eb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ce164eb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ce164eb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ce1adf5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ce1adfe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ce1ade6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ce1ae11112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d83634082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ce1470bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x59,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x58,0x2f,0x2f,0x0, Step #5: Y********X//\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4be0f15bd3cea4d1598ea6cdff11d105431d4da8 Step #5: Base64: WSoqKioqKioqWC8vAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1617 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2515401911 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dae75c7810, 0x55dae77b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dae77b1020,0x55dae96490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4be0f15bd3cea4d1598ea6cdff11d105431d4da8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1865 processed earlier; will process 9164 files now Step #5: ==58246== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dade0bc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dae4721898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dae47045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dae47044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dade0c2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dade023b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dade01e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dade0b4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dae1083f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dae1083f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dae1083f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dae1083f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dae1083f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dae1083f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dae1083f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dae1083f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dae1083f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dae1083f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dae3318f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dae0045b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dae0050be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dadfdfcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dadfdfcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dadfdfd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dadfdfc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dadfdfc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dadfdfc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dae4706abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dae470f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dae46f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dae4722112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9485f3c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dade01cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x0,0x0,0x24,0x0,0x0,0x24,0x40,0x0,0x0,0x0,0x0,0x25, Step #5: \002\000\000$\000\000$@\000\000\000\000% Step #5: artifact_prefix='./'; Test unit written to ./oom-8f892b024e9db8738ccce589d918cbfdf5a3d24d Step #5: Base64: AgAAJAAAJEAAAAAAJQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1618 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2515854654 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5559f2c66810, 0x5559f2e5001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5559f2e50020,0x5559f4ce80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8f892b024e9db8738ccce589d918cbfdf5a3d24d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1866 processed earlier; will process 9163 files now Step #5: #1 pulse cov: 3725 ft: 3726 exec/s: 0 rss: 165Mb Step #5: #2 pulse cov: 3790 ft: 3885 exec/s: 0 rss: 167Mb Step #5: ==58282== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5559e975b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5559efdc0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5559efda35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5559efda34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5559e9761d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5559e96c2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5559e96bd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5559e9753c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5559ec722f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5559ec722f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5559ec722f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5559ec722f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5559ec722f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5559ec722f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5559ec722f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5559ec722f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5559ec722f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5559ec722f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5559ee9b7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5559eb6e4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5559eb6efbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5559eb49bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5559eb49bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5559eb49c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5559eb49b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5559eb49b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5559eb49b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5559efda5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5559efdae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5559efd96699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5559efdc1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe649873082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5559e96bbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x84,0x82,0xe1,0x85,0xac,0xa,0xe1,0x84,0x82,0xe1,0x85,0xac, Step #5: \341\204\202\341\205\254\012\341\204\202\341\205\254 Step #5: artifact_prefix='./'; Test unit written to ./oom-9e1ff99a22cd92eb7b45f67e4b514824027b3baa Step #5: Base64: 4YSC4YWsCuGEguGFrA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1619 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2516417331 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55adaa972810, 0x55adaab5c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55adaab5c020,0x55adac9f40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9e1ff99a22cd92eb7b45f67e4b514824027b3baa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1870 processed earlier; will process 9159 files now Step #5: ==58318== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ada14679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ada7acc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ada7aaf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ada7aaf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ada146dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ada13ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ada13c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ada145fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ada442ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ada442ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ada442ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ada442ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ada442ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ada442ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ada442ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ada442ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ada442ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ada442ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ada66c3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ada33f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ada33fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ada31a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ada31a7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ada31a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ada31a7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ada31a7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ada31a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ada7ab1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ada7aba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ada7aa2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ada7acd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f37536a3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ada13c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x61,0x2e,0x2e,0x2e,0x3e,0x3c,0x2f,0x61,0x2e,0x2e,0xf3,0x3e, Step #5: Step #5: artifact_prefix='./'; Test unit written to ./oom-887d1454ac92c53d03ca66babd6247a11032c974 Step #5: Base64: PGEuLi4+PC9hLi7zPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1620 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2516867913 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56364894a810, 0x563648b3401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563648b34020,0x56364a9cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/887d1454ac92c53d03ca66babd6247a11032c974' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1871 processed earlier; will process 9158 files now Step #5: ==58354== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56363f43f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563645aa4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563645a875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563645a874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56363f445d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56363f3a6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56363f3a1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56363f437c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563642406f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563642406f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563642406f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563642406f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563642406f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563642406f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563642406f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563642406f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563642406f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563642406f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56364469bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5636413c8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5636413d3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56364117fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56364117fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563641180738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56364117f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56364117f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56364117f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563645a89abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563645a92928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563645a7a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563645aa5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9498c66082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56363f39fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xab,0x91,0xcd,0x84,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x89,0xbc, Step #5: \357\253\221\315\204\302\274\343\215\277\343\211\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-3c108694c1cfe08fc472497683f2a577d63aef84 Step #5: Base64: 76uRzYTCvOONv+OJvA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1621 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2517319181 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f8147d9810, 0x55f8149c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f8149c3020,0x55f81685b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3c108694c1cfe08fc472497683f2a577d63aef84' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1872 processed earlier; will process 9157 files now Step #5: #1 pulse cov: 10756 ft: 10757 exec/s: 0 rss: 184Mb Step #5: ==58390== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f80b2ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f811933898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8119165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8119164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f80b2d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f80b235b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f80b230355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f80b2c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f80e295f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f80e295f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f80e295f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f80e295f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f80e295f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f80e295f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f80e295f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f80e295f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f80e295f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f80e295f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f81052af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f80d257b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f80d262be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f80d00ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f80d00ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f80d00f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f80d00e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f80d00e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f80d00e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f811918abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f811921928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f811909699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f811934112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1696855082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f80b22eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x5b,0x63,0xe,0x68,0x43,0xdd,0x82,0xda,0xae,0xa5,0x70, Step #5: \000\000[c\016hC\335\202\332\256\245p Step #5: artifact_prefix='./'; Test unit written to ./oom-082ebc41245d32d150dea9384812996a81679956 Step #5: Base64: AABbYw5oQ92C2q6lcA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1622 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2517835150 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643cbfd2810, 0x5643cc1bc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643cc1bc020,0x5643ce0540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/082ebc41245d32d150dea9384812996a81679956' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1874 processed earlier; will process 9155 files now Step #5: #1 pulse cov: 3580 ft: 3581 exec/s: 0 rss: 168Mb Step #5: ==58426== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5643c2ac79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643c912c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643c910f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643c910f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643c2acdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643c2a2eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643c2a29355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643c2abfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643c5a8ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643c5a8ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643c5a8ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643c5a8ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643c5a8ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643c5a8ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643c5a8ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643c5a8ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643c5a8ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643c5a8ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643c7d23f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643c4a50b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643c4a5bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643c4807c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643c4807c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643c4808738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643c4807874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643c4807874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643c4807874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643c9111abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643c911a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643c9102699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643c912d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0f5ae00082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643c2a27b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x2d,0x20,0x45,0x42,0x4c,0x43,0x2d,0x3a,0x2d,0x2,0x0, Step #5: - - EBLC-:-\002\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8904cca76e628378f7f75fb3bf802846807babce Step #5: Base64: LSAtIEVCTEMtOi0CAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1623 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2518333247 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559468e3f810, 0x55946902901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559469029020,0x55946aec10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8904cca76e628378f7f75fb3bf802846807babce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1876 processed earlier; will process 9153 files now Step #5: ==58462== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55945f9349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559465f99898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559465f7c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559465f7c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55945f93ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55945f89bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55945f896355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55945f92cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5594628fbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5594628fbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5594628fbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5594628fbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5594628fbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5594628fbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5594628fbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5594628fbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5594628fbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5594628fbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559464b90f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5594618bdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5594618c8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559461674c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559461674c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559461675738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559461674874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559461674874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559461674874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559465f7eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559465f87928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559465f6f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559465f9a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb59c21082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55945f894b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x28,0x2e,0x24,0x7c,0x7b,0x7c,0x2e,0x39,0x38,0x39,0x7d,0x24, Step #5: ^(.$|{|.989}$ Step #5: artifact_prefix='./'; Test unit written to ./oom-6e1b130e354b9cc456e8ef16960c65ad6163cc95 Step #5: Base64: XiguJHx7fC45ODl9JA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1624 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2518780115 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca89cd7810, 0x55ca89ec101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca89ec1020,0x55ca8bd590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6e1b130e354b9cc456e8ef16960c65ad6163cc95' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1877 processed earlier; will process 9152 files now Step #5: ==58498== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ca807cc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca86e31898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca86e145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca86e144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca807d2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca80733b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca8072e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca807c4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca83793f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca83793f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca83793f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca83793f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca83793f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca83793f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca83793f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca83793f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca83793f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca83793f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca85a28f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca82755b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca82760be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca8250cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca8250cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca8250d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca8250c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca8250c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca8250c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca86e16abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca86e1f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca86e07699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca86e32112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b4d0ef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca8072cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0xd,0x7b,0x2f,0xd,0x7b,0x4e,0xd,0x7b,0x4e,0xd,0x7b,0x7d, Step #5: 1\015{/\015{N\015{N\015{} Step #5: artifact_prefix='./'; Test unit written to ./oom-9c6b1e0c9ee2885b1e1507088e411d126a1b7f5d Step #5: Base64: MQ17Lw17Tg17Tg17fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1625 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2519226911 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556581edf810, 0x5565820c901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5565820c9020,0x556583f610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c6b1e0c9ee2885b1e1507088e411d126a1b7f5d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1878 processed earlier; will process 9151 files now Step #5: ==58534== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5565789d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55657f039898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55657f01c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55657f01c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5565789dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55657893bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556578936355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5565789ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55657b99bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55657b99bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55657b99bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55657b99bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55657b99bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55657b99bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55657b99bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55657b99bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55657b99bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55657b99bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55657dc30f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55657a95db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55657a968be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55657a714c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55657a714c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55657a715738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55657a714874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55657a714874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55657a714874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55657f01eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55657f027928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55657f00f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55657f03a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f59d6814082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556578934b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x45,0x78,0x65,0x63,0x5d,0xa,0x55,0x73,0x65,0x72,0x3d,0x17, Step #5: [Exec]\012User=\027 Step #5: artifact_prefix='./'; Test unit written to ./oom-c9b4dbb35f5d9760739268e7ef4a4df2380a337c Step #5: Base64: W0V4ZWNdClVzZXI9Fw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1626 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2519679104 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c7b9cb9810, 0x55c7b9ea301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c7b9ea3020,0x55c7bbd3b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9b4dbb35f5d9760739268e7ef4a4df2380a337c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1879 processed earlier; will process 9150 files now Step #5: ==58570== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c7b07ae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7b6e13898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7b6df65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7b6df64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c7b07b4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c7b0715b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c7b0710355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7b07a6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7b3775f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7b3775f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7b3775f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7b3775f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7b3775f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7b3775f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7b3775f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7b3775f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7b3775f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7b3775f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7b5a0af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7b2737b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7b2742be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7b24eec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7b24eec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7b24ef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7b24ee874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7b24ee874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7b24ee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7b6df8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7b6e01928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c7b6de9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7b6e14112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f957130e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c7b070eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x24,0x30,0x0,0x0,0x7c,0x9,0xa,0x0,0x24,0xa,0x7c,0x2f, Step #5: \000$0\000\000|\011\012\000$\012|/ Step #5: artifact_prefix='./'; Test unit written to ./oom-667a5cacbdb00920e0dcaec78a5ffdda07147d8a Step #5: Base64: ACQwAAB8CQoAJAp8Lw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1627 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2520129979 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5600540f0810, 0x5600542da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5600542da020,0x5600561720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/667a5cacbdb00920e0dcaec78a5ffdda07147d8a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1880 processed earlier; will process 9149 files now Step #5: ==58606== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56004abe59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56005124a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56005122d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56005122d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56004abebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56004ab4cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56004ab47355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56004abddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56004dbacf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56004dbacf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56004dbacf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56004dbacf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56004dbacf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56004dbacf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56004dbacf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56004dbacf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56004dbacf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56004dbacf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56004fe41f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56004cb6eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56004cb79be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56004c925c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56004c925c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56004c926738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56004c925874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56004c925874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56004c925874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56005122fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560051238928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560051220699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56005124b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5ec179b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56004ab45b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4a,0x3a,0x2f,0x2f,0x2c,0x2c,0x2c,0x2c,0x2c,0xda,0xbe,0x33,0x32, Step #5: J://,,,,,\332\27632 Step #5: artifact_prefix='./'; Test unit written to ./oom-ed9d108afeb3e80180026f3767fe39a85e38513a Step #5: Base64: SjovLywsLCws2r4zMg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1628 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2520590436 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ba1b0ba810, 0x55ba1b2a401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ba1b2a4020,0x55ba1d13c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ed9d108afeb3e80180026f3767fe39a85e38513a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1881 processed earlier; will process 9148 files now Step #5: ==58642== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ba11baf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ba18214898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ba181f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ba181f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ba11bb5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ba11b16b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ba11b11355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ba11ba7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ba14b76f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ba14b76f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ba14b76f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ba14b76f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ba14b76f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ba14b76f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ba14b76f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ba14b76f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ba14b76f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ba14b76f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ba16e0bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ba13b38b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ba13b43be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ba138efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ba138efc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ba138f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ba138ef874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ba138ef874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ba138ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ba181f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ba18202928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ba181ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ba18215112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9cf0feb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ba11b0fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x86,0x12,0x25,0x73, Step #5: ~~~<\333\276~~~\206\022%s Step #5: artifact_prefix='./'; Test unit written to ./oom-ab794bdf65c4eb80756bffeea4f2987afc064d93 Step #5: Base64: fn5+PNu+fn5+hhIlcw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1629 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2521051603 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5615fa6d0810, 0x5615fa8ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5615fa8ba020,0x5615fc7520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ab794bdf65c4eb80756bffeea4f2987afc064d93' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1882 processed earlier; will process 9147 files now Step #5: #1 pulse cov: 3661 ft: 3662 exec/s: 0 rss: 168Mb Step #5: ==58678== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5615f11c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5615f782a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5615f780d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5615f780d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5615f11cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5615f112cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5615f1127355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5615f11bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5615f418cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5615f418cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5615f418cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5615f418cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5615f418cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5615f418cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5615f418cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5615f418cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5615f418cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5615f418cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5615f6421f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5615f314eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5615f3159be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5615f2f05c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5615f2f05c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5615f2f06738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5615f2f05874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5615f2f05874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5615f2f05874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5615f780fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5615f7818928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5615f7800699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5615f782b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f060439d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5615f1125b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x9,0x2e,0x2e,0xa,0x2e,0x2e,0x2e,0xa,0x2e,0x2e, Step #5: \000\000\000\011..\012...\012.. Step #5: artifact_prefix='./'; Test unit written to ./oom-40ba7bf0c5fc5a8ad8f5864c8c09983834bf7e3e Step #5: Base64: AAAACS4uCi4uLgouLg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1630 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2521548581 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ab0a11810, 0x562ab0bfb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ab0bfb020,0x562ab2a930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40ba7bf0c5fc5a8ad8f5864c8c09983834bf7e3e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1884 processed earlier; will process 9145 files now Step #5: ==58714== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562aa75069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562aadb6b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562aadb4e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562aadb4e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562aa750cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562aa746db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562aa7468355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562aa74fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562aaa4cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562aaa4cdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562aaa4cdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562aaa4cdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562aaa4cdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562aaa4cdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562aaa4cdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562aaa4cdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562aaa4cdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562aaa4cdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562aac762f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562aa948fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562aa949abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562aa9246c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562aa9246c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562aa9247738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562aa9246874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562aa9246874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562aa9246874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562aadb50abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562aadb59928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562aadb41699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562aadb6c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2496e61082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562aa7466b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0xd,0x2d,0x2d,0x24,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0x24, Step #5: --\015--$\015--\015--$ Step #5: artifact_prefix='./'; Test unit written to ./oom-0d06647a421e26a514826af25ec4b0cee103c12d Step #5: Base64: LS0NLS0kDS0tDS0tJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1631 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2522007729 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55766dafc810, 0x55766dce601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55766dce6020,0x55766fb7e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0d06647a421e26a514826af25ec4b0cee103c12d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1885 processed earlier; will process 9144 files now Step #5: ==58750== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5576645f19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55766ac56898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55766ac395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55766ac394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5576645f7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557664558b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557664553355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5576645e9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576675b8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576675b8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576675b8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576675b8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576675b8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576675b8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576675b8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576675b8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576675b8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576675b8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55766984df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55766657ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557666585be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557666331c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557666331c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557666332738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557666331874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557666331874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557666331874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55766ac3babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55766ac44928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55766ac2c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55766ac57112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f86fb4f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557664551b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x73,0x3a,0x7a,0xd7,0x85,0xd7,0x85,0xd7,0x85,0xd7,0x84, Step #5: \016ws:z\327\205\327\205\327\205\327\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-b35038c7caf470de6caf06def82c0190a461f981 Step #5: Base64: DndzOnrXhdeF14XXhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1632 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2522459188 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56438fb9e810, 0x56438fd8801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56438fd88020,0x564391c200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b35038c7caf470de6caf06def82c0190a461f981' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1886 processed earlier; will process 9143 files now Step #5: ==58786== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5643866939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56438ccf8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56438ccdb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56438ccdb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564386699d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643865fab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643865f5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56438668bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56438965af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56438965af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56438965af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56438965af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56438965af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56438965af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56438965af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56438965af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56438965af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56438965af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56438b8eff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56438861cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564388627be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643883d3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643883d3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643883d4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643883d3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643883d3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643883d3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56438ccddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56438cce6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56438ccce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56438ccf9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f14a9a93082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643865f3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xbb,0x88,0x77,0x84,0x5d,0xe0,0xbb,0x88,0xe4,0xbb,0xfd,0xf9, Step #5: \340\273\210w\204]\340\273\210\344\273\375\371 Step #5: artifact_prefix='./'; Test unit written to ./oom-6f8c366aeed6f6488dd38963badb2c73fcb31d0e Step #5: Base64: 4LuId4Rd4LuI5Lv9+Q== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1633 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2522909488 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559550d26810, 0x559550f1001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559550f10020,0x559552da80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6f8c366aeed6f6488dd38963badb2c73fcb31d0e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1887 processed earlier; will process 9142 files now Step #5: ==58822== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55954781b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55954de80898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55954de635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55954de634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559547821d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559547782b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55954777d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559547813c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55954a7e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55954a7e2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55954a7e2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55954a7e2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55954a7e2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55954a7e2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55954a7e2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55954a7e2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55954a7e2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55954a7e2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55954ca77f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5595497a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5595497afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55954955bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55954955bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55954955c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55954955b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55954955b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55954955b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55954de65abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55954de6e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55954de56699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55954de81112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6822f79082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55954777bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xb7,0xba,0xef,0xb7,0xba,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba, Step #5: \357\267\272\357\267\272\012\357\267\272\357\267\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-98a953c510c487ecaadfe5fb2668b6dee67794f5 Step #5: Base64: 77e677e6Cu+3uu+3ug== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1634 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2523358616 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5651cef0a810, 0x5651cf0f401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5651cf0f4020,0x5651d0f8c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/98a953c510c487ecaadfe5fb2668b6dee67794f5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1888 processed earlier; will process 9141 files now Step #5: ==58858== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5651c59ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5651cc064898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651cc0475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651cc0474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5651c5a05d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5651c5966b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5651c5961355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5651c59f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5651c89c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5651c89c6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5651c89c6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5651c89c6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5651c89c6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5651c89c6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5651c89c6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5651c89c6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5651c89c6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5651c89c6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5651cac5bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5651c7988b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5651c7993be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5651c773fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5651c773fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5651c7740738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5651c773f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5651c773f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5651c773f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5651cc049abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5651cc052928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5651cc03a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5651cc065112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb7dfe66082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5651c595fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0x28,0x59,0x3e,0x33,0x34,0x30,0x32,0x38,0x38,0x31,0x38,0x34, Step #5: \015(Y>340288184 Step #5: artifact_prefix='./'; Test unit written to ./oom-86aae23b6410f480690ef8e7530a023c51a0835c Step #5: Base64: DShZPjM0MDI4ODE4NA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1635 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2523809257 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555d9bf80810, 0x555d9c16a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555d9c16a020,0x555d9e0020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/86aae23b6410f480690ef8e7530a023c51a0835c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1889 processed earlier; will process 9140 files now Step #5: ==58894== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555d92a759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555d990da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555d990bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555d990bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555d92a7bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555d929dcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555d929d7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555d92a6dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555d95a3cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555d95a3cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555d95a3cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555d95a3cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555d95a3cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555d95a3cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555d95a3cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555d95a3cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555d95a3cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555d95a3cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555d97cd1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555d949feb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555d94a09be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555d947b5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555d947b5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555d947b6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555d947b5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555d947b5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555d947b5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555d990bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555d990c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555d990b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555d990db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f236a603082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555d929d5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x61,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5, Step #5: ws:a\341\254\265\341\254\265\341\254\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-774485356888df1ee8351add7e1b4a8dafed997b Step #5: Base64: d3M6YeGsteGsteGstQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1636 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2524257061 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e98d8d810, 0x562e98f7701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e98f77020,0x562e9ae0f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/774485356888df1ee8351add7e1b4a8dafed997b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1890 processed earlier; will process 9139 files now Step #5: ==58930== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562e8f8829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e95ee7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e95eca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e95eca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e8f888d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e8f7e9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e8f7e4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e8f87ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e92849f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e92849f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e92849f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e92849f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e92849f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e92849f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e92849f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e92849f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e92849f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e92849f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e94adef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e9180bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e91816be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e915c2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e915c2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e915c3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e915c2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e915c2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e915c2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e95eccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e95ed5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e95ebd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e95ee8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f81eebdd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e8f7e2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x60,0x60,0x6c,0x75,0x67,0x67,0x61,0x67,0x65,0x60,0x60,0x60, Step #5: ```luggage``` Step #5: artifact_prefix='./'; Test unit written to ./oom-b6887048138c895d21c8fa7ee766f780e511a243 Step #5: Base64: YGBgbHVnZ2FnZWBgYA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1637 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2524815388 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fcbb4e1810, 0x55fcbb6cb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fcbb6cb020,0x55fcbd5630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b6887048138c895d21c8fa7ee766f780e511a243' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1891 processed earlier; will process 9138 files now Step #5: ==58966== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fcb1fd69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fcb863b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fcb861e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fcb861e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fcb1fdcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fcb1f3db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fcb1f38355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fcb1fcec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fcb4f9df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fcb4f9df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fcb4f9df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fcb4f9df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fcb4f9df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fcb4f9df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fcb4f9df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fcb4f9df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fcb4f9df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fcb4f9df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fcb7232f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fcb3f5fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fcb3f6abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fcb3d16c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fcb3d16c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fcb3d17738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fcb3d16874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fcb3d16874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fcb3d16874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fcb8620abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fcb8629928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fcb8611699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fcb863c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f54276f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fcb1f36b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x69,0x67,0x72,0x41,0x70,0x68,0x7b,0x77,0x75,0x3d,0x62,0x7d, Step #5: digrAph{wu=b} Step #5: artifact_prefix='./'; Test unit written to ./oom-3b0af98f8e036ebdd533ab384f5f2f516d6fe2ba Step #5: Base64: ZGlnckFwaHt3dT1ifQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1638 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2525269851 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c0cd398810, 0x55c0cd58201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c0cd582020,0x55c0cf41a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3b0af98f8e036ebdd533ab384f5f2f516d6fe2ba' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1892 processed earlier; will process 9137 files now Step #5: ==59002== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c0c3e8d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c0ca4f2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c0ca4d55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c0ca4d54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c0c3e93d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c0c3df4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c0c3def355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c0c3e85c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c0c6e54f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c0c6e54f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c0c6e54f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c0c6e54f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c0c6e54f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c0c6e54f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c0c6e54f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c0c6e54f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c0c6e54f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c0c6e54f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c0c90e9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c0c5e16b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c0c5e21be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c0c5bcdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c0c5bcdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c0c5bce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c0c5bcd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c0c5bcd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c0c5bcd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c0ca4d7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c0ca4e0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c0ca4c8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c0ca4f3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4b4dd7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c0c3dedb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x25,0x2f,0x0,0x0,0x24,0xf3,0x80,0xa0,0xaa,0x24,0x0,0x0, Step #5: \000%/\000\000$\363\200\240\252$\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fedaf9149c645dd66667f3884ef136ca156c7cf3 Step #5: Base64: ACUvAAAk84CgqiQAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1639 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2525723635 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565492461810, 0x56549264b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56549264b020,0x5654944e30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fedaf9149c645dd66667f3884ef136ca156c7cf3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1893 processed earlier; will process 9136 files now Step #5: ==59038== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x565488f569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56548f5bb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56548f59e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56548f59e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565488f5cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565488ebdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565488eb8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565488f4ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56548bf1df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56548bf1df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56548bf1df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56548bf1df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56548bf1df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56548bf1df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56548bf1df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56548bf1df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56548bf1df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56548bf1df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56548e1b2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56548aedfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56548aeeabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56548ac96c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56548ac96c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56548ac97738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56548ac96874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56548ac96874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56548ac96874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56548f5a0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56548f5a9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56548f591699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56548f5bc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe16afc5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565488eb6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x2d,0x3d,0x3d,0x60,0x7e,0x2d,0x11,0x0,0x0,0x0,0x24, Step #5: ~$-==`~-\021\000\000\000$ Step #5: artifact_prefix='./'; Test unit written to ./oom-4c234afe3e1e01e31a7036728f6698d06698364b Step #5: Base64: fiQtPT1gfi0RAAAAJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1640 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2526179943 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff46bb7810, 0x55ff46da101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff46da1020,0x55ff48c390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4c234afe3e1e01e31a7036728f6698d06698364b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1894 processed earlier; will process 9135 files now Step #5: ==59074== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ff3d6ac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff43d11898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff43cf45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff43cf44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff3d6b2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff3d613b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff3d60e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff3d6a4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff40673f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff40673f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff40673f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff40673f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff40673f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff40673f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff40673f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff40673f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff40673f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff40673f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff42908f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff3f635b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff3f640be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff3f3ecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff3f3ecc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff3f3ed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff3f3ec874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff3f3ec874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff3f3ec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff43cf6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff43cff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff43ce7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff43d12112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6dcd4d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff3d60cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x80,0xa9,0xe3,0x80,0xa9,0xe3,0x82,0xaa,0xe3,0x80,0xa9,0xc2,0x0, Step #5: \343\200\251\343\200\251\343\202\252\343\200\251\302\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9a18f3826bf15c2c9a9dc08ee47d4a6ff54bcb59 Step #5: Base64: 44Cp44Cp44Kq44CpwgA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1641 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2526630232 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b581b06810, 0x55b581cf001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b581cf0020,0x55b583b880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9a18f3826bf15c2c9a9dc08ee47d4a6ff54bcb59' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1895 processed earlier; will process 9134 files now Step #5: ==59110== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b5785fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b57ec60898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b57ec435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b57ec434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b578601d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b578562b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b57855d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b5785f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b57b5c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b57b5c2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b57b5c2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b57b5c2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b57b5c2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b57b5c2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b57b5c2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b57b5c2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b57b5c2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b57b5c2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b57d857f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b57a584b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b57a58fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b57a33bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b57a33bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b57a33c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b57a33b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b57a33b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b57a33b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b57ec45abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b57ec4e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b57ec36699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b57ec61112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7445938082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b57855bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x0,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x82,0x87, Step #5: I\000\000=\012=\012=\012=\012=\202\207 Step #5: artifact_prefix='./'; Test unit written to ./oom-e62c5217999dd7a05eae9a9a95f1cc536e203974 Step #5: Base64: SQAAPQo9Cj0KPQo9goc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1642 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2527081436 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c63e645810, 0x55c63e82f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c63e82f020,0x55c6406c70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e62c5217999dd7a05eae9a9a95f1cc536e203974' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1896 processed earlier; will process 9133 files now Step #5: ==59146== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c63513a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c63b79f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c63b7825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c63b7824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c635140d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6350a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c63509c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c635132c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c638101f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c638101f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c638101f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c638101f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c638101f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c638101f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c638101f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c638101f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c638101f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c638101f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c63a396f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6370c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c6370cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c636e7ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c636e7ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c636e7b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c636e7a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c636e7a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c636e7a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c63b784abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c63b78d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c63b775699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c63b7a0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f442c510082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c63509ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0xa9,0xd4,0xa9,0xc9,0xa9,0xcd,0xa9,0xd0,0xa9,0xc9,0xa2,0xd4,0xa9, Step #5: \315\251\324\251\311\251\315\251\320\251\311\242\324\251 Step #5: artifact_prefix='./'; Test unit written to ./oom-abb7a1f6ed56e58d58ada0310e95923bad829b00 Step #5: Base64: zanUqcmpzanQqcmi1Kk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1643 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2527543191 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55577bbf1810, 0x55577bddb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55577bddb020,0x55577dc730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/abb7a1f6ed56e58d58ada0310e95923bad829b00' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1897 processed earlier; will process 9132 files now Step #5: #1 pulse cov: 6494 ft: 6496 exec/s: 0 rss: 183Mb Step #5: ==59182== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5557726e69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555778d4b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555778d2e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555778d2e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557726ecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55577264db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555772648355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557726dec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557756adf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557756adf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557756adf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557756adf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557756adf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557756adf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557756adf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557756adf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557756adf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557756adf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555777942f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55577466fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55577467abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555774426c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555774426c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555774427738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555774426874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555774426874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555774426874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555778d30abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555778d39928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555778d21699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555778d4c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa22afe2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555772646b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xa,0x73,0x75,0x61, Step #5: FUZZTESTv1\012sua Step #5: artifact_prefix='./'; Test unit written to ./oom-fde4d0bf1cc2dfda458d4b7f33c30a9987532f94 Step #5: Base64: RlVaWlRFU1R2MQpzdWE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1644 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2528054059 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ece7657810, 0x55ece784101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ece7841020,0x55ece96d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fde4d0bf1cc2dfda458d4b7f33c30a9987532f94' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1899 processed earlier; will process 9130 files now Step #5: ==59218== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ecde14c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ece47b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ece47945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ece47944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ecde152d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ecde0b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ecde0ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ecde144c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ece1113f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ece1113f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ece1113f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ece1113f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ece1113f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ece1113f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ece1113f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ece1113f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ece1113f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ece1113f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ece33a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ece00d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ece00e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ecdfe8cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ecdfe8cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ecdfe8d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ecdfe8c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ecdfe8c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ecdfe8c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ece4796abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ece479f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ece4787699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ece47b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f81603cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ecde0acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xc,0x3a,0xa,0xa,0x8,0x78,0x6e,0x2d,0x2d,0xf0,0x90,0xa7,0xbd, Step #5: \012\014:\012\012\010xn--\360\220\247\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-68d1a972eb279ecdbb57dc3b537632f3f62489f2 Step #5: Base64: Cgw6CgoIeG4tLfCQp70= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1645 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2528513324 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ef50726810, 0x55ef5091001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ef50910020,0x55ef527a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/68d1a972eb279ecdbb57dc3b537632f3f62489f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1900 processed earlier; will process 9129 files now Step #5: ==59254== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ef4721b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ef4d880898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ef4d8635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ef4d8634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef47221d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef47182b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef4717d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef47213c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef4a1e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef4a1e2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef4a1e2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef4a1e2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef4a1e2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef4a1e2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef4a1e2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef4a1e2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef4a1e2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef4a1e2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef4c477f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef491a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef491afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef48f5bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef48f5bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef48f5c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef48f5b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef48f5b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef48f5b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ef4d865abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ef4d86e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ef4d856699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ef4d881112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4edd9ba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef4717bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x54,0x54,0x2c,0x1,0x41,0x54,0xcd,0x8f,0xba,0x48,0x2,0x5b,0xbf,0xdf, Step #5: TT,\001AT\315\217\272H\002[\277\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-9368ece04f0dff5005b0bbbd042e20e2172db8fb Step #5: Base64: VFQsAUFUzY+6SAJbv98= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1646 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2528965748 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b98be16810, 0x55b98c00001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b98c000020,0x55b98de980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9368ece04f0dff5005b0bbbd042e20e2172db8fb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1901 processed earlier; will process 9128 files now Step #5: ==59290== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b98290b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b988f70898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b988f535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b988f534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b982911d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b982872b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b98286d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b982903c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b9858d2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b9858d2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b9858d2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b9858d2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b9858d2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b9858d2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b9858d2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b9858d2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b9858d2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b9858d2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b987b67f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b984894b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b98489fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b98464bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b98464bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b98464c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b98464b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b98464b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b98464b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b988f55abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b988f5e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b988f46699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b988f71112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b8aa34082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b98286bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0xbd,0x73,0x74,0x4e,0x3b,0x6d,0x62,0xdf,0xbd,0x73,0x74,0x4e,0x3b, Step #5: \337\275stN;mb\337\275stN; Step #5: artifact_prefix='./'; Test unit written to ./oom-248a60ae6dd4432a36478b025eeee3dded2fa9f8 Step #5: Base64: 371zdE47bWLfvXN0Tjs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1647 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2529413104 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56164cc52810, 0x56164ce3c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56164ce3c020,0x56164ecd40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/248a60ae6dd4432a36478b025eeee3dded2fa9f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1902 processed earlier; will process 9127 files now Step #5: ==59326== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5616437479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561649dac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561649d8f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561649d8f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56164374dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5616436aeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5616436a9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56164373fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56164670ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56164670ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56164670ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56164670ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56164670ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56164670ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56164670ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56164670ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56164670ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56164670ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5616489a3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5616456d0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5616456dbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561645487c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561645487c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561645488738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561645487874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561645487874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561645487874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561649d91abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561649d9a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561649d82699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561649dad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb529b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5616436a7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x54,0x54,0x2c,0x54,0x48,0xcd,0x8f,0x41,0xba,0x1,0x2,0x5b,0xbf,0xdf, Step #5: TT,TH\315\217A\272\001\002[\277\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-6f80992f0903f1f3708f828624b20d468dbc23d5 Step #5: Base64: VFQsVEjNj0G6AQJbv98= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1648 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2529864124 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5635c1b1e810, 0x5635c1d0801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5635c1d08020,0x5635c3ba00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6f80992f0903f1f3708f828624b20d468dbc23d5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1903 processed earlier; will process 9126 files now Step #5: ==59362== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5635b86139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5635bec78898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5635bec5b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5635bec5b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5635b8619d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5635b857ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5635b8575355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5635b860bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5635bb5daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5635bb5daf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5635bb5daf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5635bb5daf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5635bb5daf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5635bb5daf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5635bb5daf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5635bb5daf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5635bb5daf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5635bb5daf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5635bd86ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5635ba59cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5635ba5a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5635ba353c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5635ba353c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5635ba354738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5635ba353874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5635ba353874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5635ba353874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5635bec5dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5635bec66928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5635bec4e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5635bec79112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f211645c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5635b8573b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x67,0x72,0x65,0x79,0x73,0x63,0x61,0x6c,0x65,0x3e,0xa,0x3c,0xa, Step #5: \012<\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-4aa7c2c2f986dbbd938deae0ff8fd4373df3e765 Step #5: Base64: PGdyZXlzY2FsZT4KPAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1649 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2530316836 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55584a5b0810, 0x55584a79a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55584a79a020,0x55584c6320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4aa7c2c2f986dbbd938deae0ff8fd4373df3e765' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1904 processed earlier; will process 9125 files now Step #5: ==59398== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5558410a59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55584770a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5558476ed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5558476ed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5558410abd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55584100cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555841007355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55584109dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55584406cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55584406cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55584406cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55584406cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55584406cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55584406cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55584406cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55584406cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55584406cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55584406cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555846301f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55584302eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555843039be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555842de5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555842de5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555842de6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555842de5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555842de5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555842de5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5558476efabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5558476f8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5558476e0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55584770b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4b8ec7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555841005b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x0,0x0,0x42,0x67,0x62,0x4a,0x4f,0x61,0x74,0x61, Step #5: ID3\002\000\000BgbJOata Step #5: artifact_prefix='./'; Test unit written to ./oom-12fc10ac88dd7f2fd4a392db0f6d732f5c783d3e Step #5: Base64: SUQzAgAAQmdiSk9hdGE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1650 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2530769612 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560418d1a810, 0x560418f0401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560418f04020,0x56041ad9c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/12fc10ac88dd7f2fd4a392db0f6d732f5c783d3e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1905 processed earlier; will process 9124 files now Step #5: ==59434== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56040f80f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560415e74898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560415e575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560415e574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56040f815d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56040f776b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56040f771355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56040f807c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5604127d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5604127d6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5604127d6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5604127d6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5604127d6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5604127d6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5604127d6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5604127d6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5604127d6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5604127d6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560414a6bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560411798b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5604117a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56041154fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56041154fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560411550738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56041154f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56041154f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56041154f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560415e59abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560415e62928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560415e4a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560415e75112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb3a2f2e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56040f76fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc7,0xac,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xa9, Step #5: \307\254\360\235\205\251\360\235\205\251\360\235\205\251 Step #5: artifact_prefix='./'; Test unit written to ./oom-18376fb12ea2fe6fe46b2d3bcb694341b10e75e1 Step #5: Base64: x6zwnYWp8J2FqfCdhak= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1651 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2531217934 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563845390810, 0x56384557a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56384557a020,0x5638474120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/18376fb12ea2fe6fe46b2d3bcb694341b10e75e1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1906 processed earlier; will process 9123 files now Step #5: ==59470== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56383be859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5638424ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5638424cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5638424cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56383be8bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56383bdecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56383bde7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56383be7dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56383ee4cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56383ee4cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56383ee4cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56383ee4cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56383ee4cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56383ee4cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56383ee4cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56383ee4cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56383ee4cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56383ee4cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5638410e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56383de0eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56383de19be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56383dbc5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56383dbc5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56383dbc6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56383dbc5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56383dbc5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56383dbc5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5638424cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5638424d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5638424c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5638424eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a62e95082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56383bde5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x15,0x4,0x3b,0x2,0x3,0x65,0x50,0x0,0x50,0x47, Step #5: ID3\002\025\004;\002\003eP\000PG Step #5: artifact_prefix='./'; Test unit written to ./oom-d97114d0ce684aaf26b24b6c4b102c0755adab75 Step #5: Base64: SUQzAhUEOwIDZVAAUEc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1652 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2531672173 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557e464f7810, 0x557e466e101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557e466e1020,0x557e485790e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d97114d0ce684aaf26b24b6c4b102c0755adab75' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1907 processed earlier; will process 9122 files now Step #5: #1 pulse cov: 3802 ft: 3803 exec/s: 0 rss: 166Mb Step #5: ==59506== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557e3cfec9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557e43651898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557e436345dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557e436344fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557e3cff2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557e3cf53b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557e3cf4e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557e3cfe4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557e3ffb3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557e3ffb3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557e3ffb3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557e3ffb3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557e3ffb3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557e3ffb3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557e3ffb3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557e3ffb3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557e3ffb3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557e3ffb3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557e42248f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557e3ef75b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557e3ef80be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557e3ed2cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557e3ed2cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557e3ed2d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557e3ed2c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557e3ed2c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557e3ed2c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557e43636abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557e4363f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557e43627699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557e43652112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd7d5ca6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557e3cf4cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x24,0x7b,0x7c,0x7c,0x60,0x24,0x7b,0x7c,0x7c,0x60,0x24,0x7b,0x7d, Step #5: `${||`${||`${} Step #5: artifact_prefix='./'; Test unit written to ./oom-0f012a71e534c29692332442fe7211e2ccaf648a Step #5: Base64: YCR7fHxgJHt8fGAke30= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1653 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2532287670 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5593e9bc3810, 0x5593e9dad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5593e9dad020,0x5593ebc450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0f012a71e534c29692332442fe7211e2ccaf648a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1909 processed earlier; will process 9120 files now Step #5: ==59542== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5593e06b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5593e6d1d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5593e6d005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5593e6d004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5593e06bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5593e061fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5593e061a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5593e06b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5593e367ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5593e367ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5593e367ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5593e367ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5593e367ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5593e367ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5593e367ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5593e367ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5593e367ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5593e367ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5593e5914f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5593e2641b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5593e264cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5593e23f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5593e23f8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5593e23f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5593e23f8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5593e23f8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5593e23f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5593e6d02abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5593e6d0b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5593e6cf3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5593e6d1e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f514dc5c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5593e0618b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0xa,0x65,0x6e,0x76,0x3a,0xa,0x20,0xef,0xbc,0x89,0x3a, Step #5: \000\000\000\012env:\012 \357\274\211: Step #5: artifact_prefix='./'; Test unit written to ./oom-5cb6ced0b3ce74187a5270b53d8462e8a7b3ab57 Step #5: Base64: AAAACmVudjoKIO+8iTo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1654 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2532740210 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a1e03a810, 0x561a1e22401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a1e224020,0x561a200bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5cb6ced0b3ce74187a5270b53d8462e8a7b3ab57' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1910 processed earlier; will process 9119 files now Step #5: ==59578== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561a14b2f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561a1b194898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561a1b1775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561a1b1774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561a14b35d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561a14a96b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561a14a91355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561a14b27c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561a17af6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561a17af6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561a17af6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561a17af6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561a17af6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561a17af6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561a17af6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561a17af6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561a17af6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561a17af6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561a19d8bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561a16ab8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561a16ac3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561a1686fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561a1686fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561a16870738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561a1686f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561a1686f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561a1686f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561a1b179abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561a1b182928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561a1b16a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561a1b195112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8d20cb2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561a14a8fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5d,0xa,0x5c,0xa,0xb,0x3d,0xa,0x5c,0xa,0xb,0x3d,0xa,0x3d, Step #5: []\012\\\012\013=\012\\\012\013=\012= Step #5: artifact_prefix='./'; Test unit written to ./oom-ebde1da2b6bae3247b7df4f503ffa196155b6bd7 Step #5: Base64: W10KXAoLPQpcCgs9Cj0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1655 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2533185192 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557995afb810, 0x557995ce501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557995ce5020,0x557997b7d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ebde1da2b6bae3247b7df4f503ffa196155b6bd7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1911 processed earlier; will process 9118 files now Step #5: ==59614== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55798c5f09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557992c55898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557992c385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557992c384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55798c5f6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55798c557b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55798c552355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55798c5e8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55798f5b7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55798f5b7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55798f5b7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55798f5b7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55798f5b7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55798f5b7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55798f5b7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55798f5b7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55798f5b7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55798f5b7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55799184cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55798e579b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55798e584be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55798e330c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55798e330c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55798e331738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55798e330874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55798e330874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55798e330874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557992c3aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557992c43928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557992c2b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557992c56112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f59bd1bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55798c550b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x24,0xd,0x2d,0x20,0x24,0xa,0x2d,0x20,0x24,0xa,0x24,0xa, Step #5: - $\015- $\012- $\012$\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-a6deaf3647592f0a97cd09b9fed859175a94c4f2 Step #5: Base64: LSAkDS0gJAotICQKJAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1656 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2533637848 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9883ec810, 0x55a9885d601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a9885d6020,0x55a98a46e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a6deaf3647592f0a97cd09b9fed859175a94c4f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1912 processed earlier; will process 9117 files now Step #5: ==59650== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a97eee19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a985546898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9855295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9855294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a97eee7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a97ee48b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a97ee43355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a97eed9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a981ea8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a981ea8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a981ea8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a981ea8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a981ea8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a981ea8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a981ea8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a981ea8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a981ea8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a981ea8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a98413df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a980e6ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a980e75be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a980c21c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a980c21c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a980c22738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a980c21874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a980c21874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a980c21874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a98552babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a985534928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a98551c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a985547112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc40b8c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a97ee41b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x7f,0x2f,0x16,0x2b,0x17,0x2b,0x50,0x52,0x49,0x7e, Step #5: ID3\002\177/\026+\027+PRI~ Step #5: artifact_prefix='./'; Test unit written to ./oom-9f508dd0d282dac5121070cdfdd926c8a627d004 Step #5: Base64: SUQzAn8vFisXK1BSSX4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1657 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2534088087 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3bd3a6810, 0x55a3bd59001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3bd590020,0x55a3bf4280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f508dd0d282dac5121070cdfdd926c8a627d004' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1913 processed earlier; will process 9116 files now Step #5: #1 pulse cov: 3691 ft: 3692 exec/s: 0 rss: 166Mb Step #5: ==59686== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a3b3e9b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3ba500898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3ba4e35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3ba4e34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3b3ea1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a3b3e02b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a3b3dfd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3b3e93c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a3b6e62f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a3b6e62f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a3b6e62f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a3b6e62f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a3b6e62f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a3b6e62f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a3b6e62f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a3b6e62f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a3b6e62f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a3b6e62f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3b90f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3b5e24b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3b5e2fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3b5bdbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3b5bdbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3b5bdc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3b5bdb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3b5bdb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3b5bdb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a3ba4e5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a3ba4ee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3ba4d6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3ba501112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f247e32c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a3b3dfbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2e,0x0,0x0,0xdd,0x8a,0x2f,0x20,0x0,0xdd,0x8a,0x2f,0x5b,0xb, Step #5: \000.\000\000\335\212/ \000\335\212/[\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-4504c4e462d2906b245ec92a95e8a07bf3a82bce Step #5: Base64: AC4AAN2KLyAA3YovWws= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1658 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2534587417 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb66a7f810, 0x55eb66c6901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb66c69020,0x55eb68b010e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4504c4e462d2906b245ec92a95e8a07bf3a82bce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1915 processed earlier; will process 9114 files now Step #5: ==59722== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eb5d5749c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb63bd9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb63bbc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb63bbc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb5d57ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb5d4dbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb5d4d6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb5d56cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb6053bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb6053bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb6053bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb6053bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb6053bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb6053bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb6053bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb6053bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb6053bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb6053bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb627d0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb5f4fdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb5f508be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb5f2b4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb5f2b4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb5f2b5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb5f2b4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb5f2b4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb5f2b4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb63bbeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb63bc7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb63baf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb63bda112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2a1ce25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb5d4d4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0, Step #5: \012\000\012\000\012\000\012\000\012\000\012\000\012\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-401c0c46f054b34167069f10e2bd67a8ce33e70d Step #5: Base64: CgAKAAoACgAKAAoACgA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1659 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2535041120 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5556a50ba810, 0x5556a52a401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5556a52a4020,0x5556a713c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/401c0c46f054b34167069f10e2bd67a8ce33e70d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1916 processed earlier; will process 9113 files now Step #5: ==59758== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55569bbaf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5556a2214898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556a21f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556a21f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55569bbb5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55569bb16b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55569bb11355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55569bba7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55569eb76f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55569eb76f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55569eb76f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55569eb76f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55569eb76f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55569eb76f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55569eb76f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55569eb76f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55569eb76f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55569eb76f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5556a0e0bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55569db38b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55569db43be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55569d8efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55569d8efc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55569d8f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55569d8ef874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55569d8ef874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55569d8ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5556a21f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5556a2202928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5556a21ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5556a2215112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b9956f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55569bb0fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0xa,0x2d,0x2d,0x2d,0x2d,0x40,0x27,0x23,0x30,0x25,0x2d,0x2d,0xa, Step #5: c\012----@'#0%--\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-8e745030bebc7d2ae993d0b5085da32c75d3bb2e Step #5: Base64: YwotLS0tQCcjMCUtLQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1660 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2535485574 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7c345d810, 0x55f7c364701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7c3647020,0x55f7c54df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8e745030bebc7d2ae993d0b5085da32c75d3bb2e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1917 processed earlier; will process 9112 files now Step #5: ==59794== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f7b9f529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7c05b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7c059a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7c059a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f7b9f58d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f7b9eb9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f7b9eb4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f7b9f4ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7bcf19f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7bcf19f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7bcf19f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7bcf19f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7bcf19f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7bcf19f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7bcf19f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7bcf19f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7bcf19f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7bcf19f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7bf1aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f7bbedbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f7bbee6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f7bbc92c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f7bbc92c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f7bbc93738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f7bbc92874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f7bbc92874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f7bbc92874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7c059cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7c05a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7c058d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7c05b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f973f356082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f7b9eb2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x62,0x6a,0x65,0x63,0x74,0x43,0x6c,0x61,0x73,0x73,0x3a,0x73,0x38, Step #5: objectClass:s8 Step #5: artifact_prefix='./'; Test unit written to ./oom-ee943eb07743f149aa3f049b200dfee110860951 Step #5: Base64: b2JqZWN0Q2xhc3M6czg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1661 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2535932799 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557fff8b5810, 0x557fffa9f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557fffa9f020,0x5580019370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee943eb07743f149aa3f049b200dfee110860951' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1918 processed earlier; will process 9111 files now Step #5: #1 pulse cov: 3725 ft: 3726 exec/s: 0 rss: 166Mb Step #5: ==59830== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557ff63aa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557ffca0f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557ffc9f25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557ffc9f24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557ff63b0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557ff6311b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557ff630c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557ff63a2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557ff9371f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557ff9371f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557ff9371f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557ff9371f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557ff9371f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557ff9371f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557ff9371f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557ff9371f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557ff9371f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557ff9371f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557ffb606f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557ff8333b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557ff833ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557ff80eac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557ff80eac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557ff80eb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557ff80ea874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557ff80ea874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557ff80ea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557ffc9f4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557ffc9fd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557ffc9e5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557ffca10112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0a2f43d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557ff630ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x66,0x7c,0x7c,0x6f,0x77,0x30,0x2f,0x77,0x6c,0x65,0x66,0x2f,0x2f, Step #5: f||ow0/wlef// Step #5: artifact_prefix='./'; Test unit written to ./oom-a0729b84ed065cf3b2b082a02d7c0d14769d917c Step #5: Base64: IGZ8fG93MC93bGVmLy8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1662 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2536422817 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e7a5caf810, 0x55e7a5e9901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e7a5e99020,0x55e7a7d310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a0729b84ed065cf3b2b082a02d7c0d14769d917c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1920 processed earlier; will process 9109 files now Step #5: ==59866== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e79c7a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e7a2e09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7a2dec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7a2dec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e79c7aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e79c70bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e79c706355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e79c79cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e79f76bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e79f76bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e79f76bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e79f76bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e79f76bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e79f76bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e79f76bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e79f76bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e79f76bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e79f76bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e7a1a00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e79e72db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e79e738be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e79e4e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e79e4e4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e79e4e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e79e4e4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e79e4e4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e79e4e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e7a2deeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e7a2df7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e7a2ddf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e7a2e0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe5a172d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e79c704b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x0,0x5b,0x27,0x5d,0x5b,0x28,0x5d,0x5b,0x27,0x5d,0x5b,0x28,0x5d, Step #5: 0\000['][(]['][(] Step #5: artifact_prefix='./'; Test unit written to ./oom-9ee14f29514eb6e82a39d95c2809b41a5065a0c5 Step #5: Base64: MABbJ11bKF1bJ11bKF0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1663 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2536873754 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563bcb753810, 0x563bcb93d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563bcb93d020,0x563bcd7d50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9ee14f29514eb6e82a39d95c2809b41a5065a0c5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1921 processed earlier; will process 9108 files now Step #5: ==59902== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563bc22489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563bc88ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563bc88905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563bc88904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563bc224ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563bc21afb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563bc21aa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563bc2240c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563bc520ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563bc520ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563bc520ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563bc520ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563bc520ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563bc520ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563bc520ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563bc520ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563bc520ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563bc520ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563bc74a4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563bc41d1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563bc41dcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563bc3f88c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563bc3f88c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563bc3f89738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563bc3f88874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563bc3f88874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563bc3f88874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563bc8892abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563bc889b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563bc8883699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563bc88ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6df733e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563bc21a8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3b,0x60,0x60,0x60,0xd,0xe0,0xbf,0xad,0xd,0xd,0xd,0x60,0x60,0x60, Step #5: ;```\015\340\277\255\015\015\015``` Step #5: artifact_prefix='./'; Test unit written to ./oom-b708fba9fef58175055c4e4ce62796083cbecf71 Step #5: Base64: O2BgYA3gv60NDQ1gYGA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1664 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2537447194 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cf653d7810, 0x55cf655c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cf655c1020,0x55cf674590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b708fba9fef58175055c4e4ce62796083cbecf71' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1922 processed earlier; will process 9107 files now Step #5: ==59938== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cf5becc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cf62531898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cf625145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cf625144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cf5bed2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cf5be33b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cf5be2e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cf5bec4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cf5ee93f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cf5ee93f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cf5ee93f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cf5ee93f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cf5ee93f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cf5ee93f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cf5ee93f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cf5ee93f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cf5ee93f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cf5ee93f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cf61128f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cf5de55b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cf5de60be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cf5dc0cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cf5dc0cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cf5dc0d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cf5dc0c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cf5dc0c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cf5dc0c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cf62516abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cf6251f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cf62507699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cf62532112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8f3a54f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cf5be2cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x0,0x0,0x0,0x44,0x65,0x6e,0xe2,0x81,0x9f,0x4d,0xf6,0xff,0x7f, Step #5: I\000\000\000Den\342\201\237M\366\377\177 Step #5: artifact_prefix='./'; Test unit written to ./oom-1db8222b55d55732d1bd9e557bc455f7ef2633b2 Step #5: Base64: SQAAAERlbuKBn032/38= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1665 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2537899026 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cbf1de8810, 0x55cbf1fd201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cbf1fd2020,0x55cbf3e6a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1db8222b55d55732d1bd9e557bc455f7ef2633b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1923 processed earlier; will process 9106 files now Step #5: ==59974== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cbe88dd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cbeef42898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cbeef255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cbeef254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cbe88e3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cbe8844b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cbe883f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cbe88d5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cbeb8a4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cbeb8a4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cbeb8a4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cbeb8a4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cbeb8a4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cbeb8a4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cbeb8a4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cbeb8a4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cbeb8a4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cbeb8a4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cbedb39f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cbea866b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cbea871be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cbea61dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cbea61dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cbea61e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cbea61d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cbea61d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cbea61d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cbeef27abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cbeef30928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cbeef18699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cbeef43112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6185794082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cbe883db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x35,0x35,0xa,0x24,0xa,0x31,0x2f,0x25,0x24,0xe2,0x80,0xa8,0x3d, Step #5: 155\012$\0121/%$\342\200\250= Step #5: artifact_prefix='./'; Test unit written to ./oom-8b933b7f6f8b117b258d43ba4008804e55cc07b0 Step #5: Base64: MTU1CiQKMS8lJOKAqD0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1666 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2538351618 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dbb3043810, 0x55dbb322d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dbb322d020,0x55dbb50c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8b933b7f6f8b117b258d43ba4008804e55cc07b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1924 processed earlier; will process 9105 files now Step #5: ==60010== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dba9b389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dbb019d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dbb01805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dbb01804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dba9b3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dba9a9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dba9a9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dba9b30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dbacafff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dbacafff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dbacafff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dbacafff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dbacafff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dbacafff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dbacafff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dbacafff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dbacafff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dbacafff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dbaed94f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dbabac1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dbabaccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dbab878c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dbab878c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dbab879738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dbab878874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dbab878874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dbab878874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dbb0182abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dbb018b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dbb0173699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dbb019e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f10cd4db082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dba9a98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x81,0xdb,0x80,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0x37,0x37,0x39, Step #5: \333\201\333\2004294967779 Step #5: artifact_prefix='./'; Test unit written to ./oom-a210b85d74a0d2d87051066edc211c21e51735eb Step #5: Base64: 24HbgDQyOTQ5Njc3Nzk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1667 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2538796897 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d00b834810, 0x55d00ba1e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d00ba1e020,0x55d00d8b60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a210b85d74a0d2d87051066edc211c21e51735eb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1925 processed earlier; will process 9104 files now Step #5: #1 pulse cov: 3576 ft: 3577 exec/s: 0 rss: 167Mb Step #5: ==60046== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d0023299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d00898e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d0089715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d0089714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d00232fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d002290b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d00228b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d002321c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d0052f0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d0052f0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d0052f0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d0052f0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d0052f0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d0052f0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d0052f0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d0052f0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d0052f0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d0052f0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d007585f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d0042b2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d0042bdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d004069c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d004069c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d00406a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d004069874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d004069874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d004069874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d008973abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d00897c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d008964699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d00898f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb334e98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d002289b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xa,0x9,0xa,0x60,0x2d,0x0,0x60,0x20,0x20,0x20,0x60,0xa,0x9, Step #5: `\012\011\012`-\000` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-2fb36d44f302385d56455fcf5f536f13d83d0f69 Step #5: Base64: YAoJCmAtAGAgICBgCgk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1668 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2539409519 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555bece22810, 0x555bed00c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555bed00c020,0x555beeea40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2fb36d44f302385d56455fcf5f536f13d83d0f69' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1927 processed earlier; will process 9102 files now Step #5: ==60082== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555be39179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555be9f7c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555be9f5f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555be9f5f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555be391dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555be387eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555be3879355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555be390fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555be68def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555be68def10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555be68def10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555be68def10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555be68def10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555be68def10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555be68def10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555be68def10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555be68def10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555be68def10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555be8b73f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555be58a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555be58abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555be5657c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555be5657c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555be5658738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555be5657874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555be5657874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555be5657874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555be9f61abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555be9f6a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555be9f52699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555be9f7d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb9596c6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555be3877b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x28,0x2e,0x24,0x7c,0x2e,0x3f,0x29,0x7b,0x39,0x38,0x39,0x7d,0x24, Step #5: ^(.$|.?){989}$ Step #5: artifact_prefix='./'; Test unit written to ./oom-20d1584f91d83a5a01e225372234dff72fe6facd Step #5: Base64: XiguJHwuPyl7OTg5fSQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1669 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2539860818 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5608ff5c8810, 0x5608ff7b201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5608ff7b2020,0x56090164a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/20d1584f91d83a5a01e225372234dff72fe6facd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1928 processed earlier; will process 9101 files now Step #5: ==60118== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5608f60bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5608fc722898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608fc7055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608fc7054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5608f60c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5608f6024b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5608f601f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5608f60b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5608f9084f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5608f9084f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5608f9084f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5608f9084f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5608f9084f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5608f9084f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5608f9084f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5608f9084f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5608f9084f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5608f9084f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608fb319f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5608f8046b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5608f8051be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5608f7dfdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5608f7dfdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5608f7dfe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5608f7dfd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5608f7dfd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5608f7dfd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5608fc707abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5608fc710928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5608fc6f8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5608fc723112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6127e81082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5608f601db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9d,0x85,0xb1,0xd6,0xb1,0xd6,0xb6,0xcc,0xb6,0xcc,0xb6,0xcc,0xb8, Step #5: \360\235\205\261\326\261\326\266\314\266\314\266\314\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-1fb8f73e98d4bab9b7634e074d0ecd7dbb1ff18d Step #5: Base64: 8J2Fsdax1rbMtsy2zLg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1670 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2540307100 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5564b2930810, 0x5564b2b1a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564b2b1a020,0x5564b49b20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1fb8f73e98d4bab9b7634e074d0ecd7dbb1ff18d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1929 processed earlier; will process 9100 files now Step #5: ==60154== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5564a94259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564afa8a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564afa6d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564afa6d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564a942bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5564a938cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5564a9387355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564a941dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564ac3ecf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564ac3ecf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564ac3ecf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564ac3ecf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564ac3ecf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564ac3ecf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564ac3ecf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564ac3ecf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564ac3ecf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564ac3ecf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5564ae681f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5564ab3aeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5564ab3b9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5564ab165c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5564ab165c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5564ab166738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5564ab165874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5564ab165874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5564ab165874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564afa6fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564afa78928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564afa60699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564afa8b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8f57dea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5564a9385b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x0,0xe1,0x81,0x9f,0xe1,0x85,0x9f,0xe1,0x85,0x9f,0xed,0x9e,0xbd, Step #5: (\000\341\201\237\341\205\237\341\205\237\355\236\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-0fde04f98f1be88eb448edc2a5efd02fa1e86e86 Step #5: Base64: KADhgZ/hhZ/hhZ/tnr0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 1671 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2540752435 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557ab9f58810, 0x557aba14201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557aba142020,0x557abbfda0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0fde04f98f1be88eb448edc2a5efd02fa1e86e86' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 1930 processed earlier; will process 9099 files now Step #5: ==60190== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557ab0a4d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557ab70b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557ab70955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557ab70954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557ab0a53d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557ab09b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557ab09af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557ab0a45c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557ab3a14f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557ab3a14f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557ab3a14f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557ab3a14f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557ab3a14f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557ab3a14f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557ab3a14f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557ab3a14f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557ab3a14f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557ab3a14f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557ab5ca9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557ab29d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557ab29e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557ab278dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557ab278dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557ab278e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557ab278d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557ab278d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557ab278d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557ab7097abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557ab70a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557ab7088699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557ab70b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5169901082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557ab09adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x2d,0x2d,0x2d,0x2d,0xd,0xe2,0x80,0x8f,0xe1,0xa0,0x8e,0xc4, Step #5: 0:0:0.5\012\355 Step #5: artifact_prefix='./'; Test unit written to ./oom-c9687475e32f3affe45e9d159a97389dd5575bc8 Step #5: Base64: ODowOjMuMi0tPjA6MDowLjUK7Q== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2110 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2749729982 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558005fc8810, 0x5580061b201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5580061b2020,0x55800804a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9687475e32f3affe45e9d159a97389dd5575bc8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2490 processed earlier; will process 8539 files now Step #5: ==75994== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557ffcabd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558003122898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5580031055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5580031054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557ffcac3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557ffca24b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557ffca1f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557ffcab5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557fffa84f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557fffa84f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557fffa84f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557fffa84f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557fffa84f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557fffa84f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557fffa84f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557fffa84f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557fffa84f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557fffa84f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558001d19f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557ffea46b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557ffea51be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557ffe7fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557ffe7fdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557ffe7fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557ffe7fd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557ffe7fd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557ffe7fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558003107abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558003110928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5580030f8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558003123112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc38c184082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557ffca1db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e,0x7e,0x3c,0xdb,0xbe,0x0,0x16,0x7e,0x7e,0x7f,0x0,0x42,0x67,0x72,0x79,0x34,0x73, Step #5: ~~~~<\333\276\000\026~~\177\000Bgry4s Step #5: artifact_prefix='./'; Test unit written to ./oom-1d7a436f63e2d04e7cca54a20132042fff98dcef Step #5: Base64: fn5+fjzbvgAWfn5/AEJncnk0cw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2111 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2750195558 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562009217810, 0x56200940101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562009401020,0x56200b2990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1d7a436f63e2d04e7cca54a20132042fff98dcef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2491 processed earlier; will process 8538 files now Step #5: ==76030== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561fffd0c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562006371898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5620063545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5620063544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561fffd12d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561fffc73b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561fffc6e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561fffd04c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562002cd3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562002cd3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562002cd3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562002cd3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562002cd3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562002cd3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562002cd3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562002cd3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562002cd3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562002cd3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562004f68f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562001c95b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562001ca0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562001a4cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562001a4cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562001a4d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562001a4c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562001a4c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562001a4c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562006356abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56200635f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562006347699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562006372112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1e78e69082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561fffc6cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80, Step #5: ws:\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-697c51d8a9949d0b10bdd5960d80e2af081f7833 Step #5: Base64: d3M6zYDNgM2AzYDNgM2AzYDNgA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2112 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2750661159 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56039b623810, 0x56039b80d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56039b80d020,0x56039d6a50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/697c51d8a9949d0b10bdd5960d80e2af081f7833' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2492 processed earlier; will process 8537 files now Step #5: ==76066== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5603921189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56039877d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5603987605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5603987604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56039211ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56039207fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56039207a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560392110c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5603950dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5603950dff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5603950dff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5603950dff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5603950dff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5603950dff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5603950dff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5603950dff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5603950dff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5603950dff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560397374f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5603940a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5603940acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560393e58c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560393e58c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560393e59738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560393e58874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560393e58874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560393e58874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560398762abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56039876b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560398753699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56039877e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff3c7616082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560392078b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0xcc,0x8e,0xcd,0x9a,0xdf,0x9e,0xdf,0xbd,0xcd,0x9a,0xdf,0x9f,0xcd,0x9a,0xdf,0x9e,0x7d,0x3a, Step #5: {\314\216\315\232\337\236\337\275\315\232\337\237\315\232\337\236}: Step #5: artifact_prefix='./'; Test unit written to ./oom-0ba8059d9d310443e22ce430df1a1a7773f8d79b Step #5: Base64: e8yOzZrfnt+9zZrfn82a3559Og== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2113 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2751126247 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652f7878810, 0x5652f7a6201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652f7a62020,0x5652f98fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0ba8059d9d310443e22ce430df1a1a7773f8d79b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2493 processed earlier; will process 8536 files now Step #5: ==76102== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5652ee36d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652f49d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652f49b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652f49b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5652ee373d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5652ee2d4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5652ee2cf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5652ee365c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5652f1334f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5652f1334f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5652f1334f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5652f1334f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5652f1334f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5652f1334f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5652f1334f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5652f1334f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5652f1334f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5652f1334f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652f35c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5652f02f6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5652f0301be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652f00adc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652f00adc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652f00ae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652f00ad874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652f00ad874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652f00ad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652f49b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652f49c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652f49a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652f49d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb6ea19d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5652ee2cdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x69,0x66,0x31,0x30,0x29,0x29,0x29,0x29,0xd7,0xa9,0x28,0x30,0x9,0x37,0x21,0x29,0x0,0x0, Step #5: !if10))))\327\251(0\0117!)\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b58c5f39bf2c7a0de2581e8a50682ebab9f85301 Step #5: Base64: IWlmMTApKSkp16koMAk3ISkAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2114 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2751589992 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5605de762810, 0x5605de94c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5605de94c020,0x5605e07e40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b58c5f39bf2c7a0de2581e8a50682ebab9f85301' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2494 processed earlier; will process 8535 files now Step #5: ==76138== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5605d52579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605db8bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605db89f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605db89f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5605d525dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605d51beb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5605d51b9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5605d524fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605d821ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605d821ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605d821ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605d821ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605d821ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605d821ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605d821ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605d821ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605d821ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605d821ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605da4b3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5605d71e0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5605d71ebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5605d6f97c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5605d6f97c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5605d6f98738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5605d6f97874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5605d6f97874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5605d6f97874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605db8a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5605db8aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605db892699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605db8bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa20a9fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5605d51b7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x71,0x0,0x0,0x0,0x0,0x0,0x1b,0x0,0x0,0x0,0x0,0x1,0x1,0x1,0x1,0x1,0x1,0x1, Step #5: \000q\000\000\000\000\000\033\000\000\000\000\001\001\001\001\001\001\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-c62d7478325c73ec30e220f95cb6d0862c1fa06c Step #5: Base64: AHEAAAAAABsAAAAAAQEBAQEBAQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2115 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2752053420 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56550dffb810, 0x56550e1e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56550e1e5020,0x56551007d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c62d7478325c73ec30e220f95cb6d0862c1fa06c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2495 processed earlier; will process 8534 files now Step #5: #1 pulse cov: 3651 ft: 3652 exec/s: 0 rss: 167Mb Step #5: ==76174== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x565504af09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56550b155898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56550b1385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56550b1384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565504af6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565504a57b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565504a52355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565504ae8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565507ab7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565507ab7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565507ab7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565507ab7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565507ab7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565507ab7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565507ab7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565507ab7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565507ab7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565507ab7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565509d4cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565506a79b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565506a84be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565506830c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565506830c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565506831738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565506830874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565506830874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565506830874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56550b13aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56550b143928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56550b12b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56550b156112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6504508082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565504a50b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x77,0x2b,0x5c,0x73,0x2b,0x5c,0x77,0x2b,0x5c,0x73,0x2b,0x5c,0x77,0xb,0x5c,0x2b,0x5c,0x73, Step #5: \\w+\\s+\\w+\\s+\\w\013\\+\\s Step #5: artifact_prefix='./'; Test unit written to ./oom-13308daab8d2133a3b20ae61cf8b5e1991801222 Step #5: Base64: XHcrXHMrXHcrXHMrXHcLXCtccw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2116 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2752565582 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e188365810, 0x55e18854f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e18854f020,0x55e18a3e70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/13308daab8d2133a3b20ae61cf8b5e1991801222' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2497 processed earlier; will process 8532 files now Step #5: #1 pulse cov: 3643 ft: 3644 exec/s: 0 rss: 169Mb Step #5: ==76210== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e17ee5a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e1854bf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e1854a25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e1854a24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e17ee60d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e17edc1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e17edbc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e17ee52c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e181e21f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e181e21f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e181e21f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e181e21f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e181e21f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e181e21f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e181e21f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e181e21f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e181e21f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e181e21f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e1840b6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e180de3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e180deebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e180b9ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e180b9ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e180b9b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e180b9a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e180b9a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e180b9a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e1854a4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e1854ad928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e185495699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e1854c0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3bd4d4a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e17edbab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4,0x2,0x2,0x2,0x2,0x2,0x2,0x7e,0x2,0x2,0x2,0x2,0x2,0x2,0x2,0x6,0x2,0x1,0x1, Step #5: \004\002\002\002\002\002\002~\002\002\002\002\002\002\002\006\002\001\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-df461d1107ca82320db5ba97c54e68bdea671df5 Step #5: Base64: BAICAgICAn4CAgICAgICBgIBAQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2117 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2753075580 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571fc62c810, 0x5571fc81601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571fc816020,0x5571fe6ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/df461d1107ca82320db5ba97c54e68bdea671df5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2499 processed earlier; will process 8530 files now Step #5: ==76246== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5571f31219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571f9786898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571f97695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571f97694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571f3127d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571f3088b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571f3083355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571f3119c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571f60e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571f60e8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571f60e8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571f60e8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571f60e8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571f60e8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571f60e8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571f60e8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571f60e8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571f60e8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571f837df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571f50aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571f50b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571f4e61c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571f4e61c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571f4e62738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571f4e61874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571f4e61874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571f4e61874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571f976babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571f9774928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571f975c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571f9787112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1bf2396082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571f3081b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x38,0x2d,0x31,0x2d,0x32,0x39,0x31,0x3a,0x39,0x3a,0x30,0xcc,0xb1,0xcc,0xb1,0xcc,0xb1,0xcc,0xb1, Step #5: 8-1-291:9:0\314\261\314\261\314\261\314\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-3aa3d33398a4742668fc02430de05bd5230e229c Step #5: Base64: OC0xLTI5MTo5OjDMscyxzLHMsQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2118 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2753540840 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56138c2eb810, 0x56138c4d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56138c4d5020,0x56138e36d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3aa3d33398a4742668fc02430de05bd5230e229c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2500 processed earlier; will process 8529 files now Step #5: #1 pulse cov: 3678 ft: 3679 exec/s: 0 rss: 169Mb Step #5: #2 pulse cov: 11278 ft: 12100 exec/s: 0 rss: 188Mb Step #5: ==76282== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561382de09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561389445898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613894285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613894284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561382de6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561382d47b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561382d42355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561382dd8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561385da7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561385da7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561385da7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561385da7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561385da7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561385da7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561385da7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561385da7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561385da7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561385da7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56138803cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561384d69b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561384d74be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561384b20c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561384b20c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561384b21738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561384b20874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561384b20874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561384b20874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56138942aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561389433928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56138941b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561389446112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa54adcf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561382d40b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x2d,0x32,0x2d,0x47,0x10,0x2d,0x54,0x43,0x4f,0x0,0xb9,0xb,0x0,0x2d,0x35, Step #5: ID3\002-2-G\020-TCO\000\271\013\000-5 Step #5: artifact_prefix='./'; Test unit written to ./oom-0ef2563bfafc8ad66f08eeac732708ada26d0df6 Step #5: Base64: SUQzAi0yLUcQLVRDTwC5CwAtNQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2119 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2754134091 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557dcac4a810, 0x557dcae3401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557dcae34020,0x557dccccc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0ef2563bfafc8ad66f08eeac732708ada26d0df6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2503 processed earlier; will process 8526 files now Step #5: ==76318== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557dc173f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557dc7da4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557dc7d875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557dc7d874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557dc1745d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557dc16a6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557dc16a1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557dc1737c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557dc4706f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557dc4706f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557dc4706f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557dc4706f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557dc4706f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557dc4706f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557dc4706f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557dc4706f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557dc4706f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557dc4706f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557dc699bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557dc36c8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557dc36d3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557dc347fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557dc347fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557dc3480738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557dc347f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557dc347f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557dc347f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557dc7d89abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557dc7d92928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557dc7d7a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557dc7da5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0abdc76082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557dc169fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x45,0x78,0x65,0x63,0x5d,0x0,0x4c,0x69,0x6d,0x69,0x74,0x41,0x53,0x3d,0x32,0x3a,0x2d,0x31, Step #5: [Exec]\000LimitAS=2:-1 Step #5: artifact_prefix='./'; Test unit written to ./oom-50b457e0a74004c7c925c2908e4c3d8eecb11e63 Step #5: Base64: W0V4ZWNdAExpbWl0QVM9MjotMQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2120 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2754598011 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c1d70ae810, 0x55c1d729801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c1d7298020,0x55c1d91300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/50b457e0a74004c7c925c2908e4c3d8eecb11e63' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2504 processed earlier; will process 8525 files now Step #5: #1 pulse cov: 3662 ft: 3663 exec/s: 0 rss: 167Mb Step #5: ==76354== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c1cdba39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c1d4208898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c1d41eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c1d41eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c1cdba9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c1cdb0ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c1cdb05355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c1cdb9bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c1d0b6af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c1d0b6af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c1d0b6af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c1d0b6af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c1d0b6af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c1d0b6af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c1d0b6af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c1d0b6af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c1d0b6af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c1d0b6af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c1d2dfff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c1cfb2cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c1cfb37be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c1cf8e3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c1cf8e3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c1cf8e4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c1cf8e3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c1cf8e3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c1cf8e3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c1d41edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c1d41f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c1d41de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c1d4209112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdfb9c80082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c1cdb03b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x47,0xd6,0xbf,0x27,0x27,0x27,0x2f,0xd7,0x29,0x47,0xd6,0xbf,0x27,0x27,0x27,0x2f,0x29,0x27, Step #5: BG\326\277'''/\327)G\326\277'''/)' Step #5: artifact_prefix='./'; Test unit written to ./oom-1271ef0a9cde2e6cf3277c9058107c7d5adc8bcf Step #5: Base64: QkfWvycnJy/XKUfWvycnJy8pJw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2121 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2755106623 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a8ab9a4810, 0x55a8abb8e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a8abb8e020,0x55a8ada260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1271ef0a9cde2e6cf3277c9058107c7d5adc8bcf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2506 processed earlier; will process 8523 files now Step #5: ==76390== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a8a24999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a8a8afe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a8a8ae15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a8a8ae14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a8a249fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a8a2400b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a8a23fb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a8a2491c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a8a5460f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a8a5460f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a8a5460f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a8a5460f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a8a5460f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a8a5460f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a8a5460f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a8a5460f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a8a5460f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a8a5460f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a8a76f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a8a4422b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a8a442dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a8a41d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a8a41d9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a8a41da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a8a41d9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a8a41d9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a8a41d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a8a8ae3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a8a8aec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a8a8ad4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a8a8aff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3d1b6d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a8a23f9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0x20,0x64,0x3a,0x33,0x65,0x2d,0x33,0x34,0x33, Step #5: FUZZTESTv1 d:3e-343 Step #5: artifact_prefix='./'; Test unit written to ./oom-bb38fd93a7a1a7fe31a754520b62fd450387a8e8 Step #5: Base64: RlVaWlRFU1R2MSBkOjNlLTM0Mw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2122 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2755569844 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5619576f1810, 0x5619578db01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5619578db020,0x5619597730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bb38fd93a7a1a7fe31a754520b62fd450387a8e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2507 processed earlier; will process 8522 files now Step #5: ==76426== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56194e1e69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56195484b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56195482e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56195482e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56194e1ecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56194e14db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56194e148355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56194e1dec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5619511adf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5619511adf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5619511adf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5619511adf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5619511adf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5619511adf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5619511adf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5619511adf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5619511adf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5619511adf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561953442f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56195016fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56195017abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56194ff26c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56194ff26c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56194ff27738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56194ff26874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56194ff26874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56194ff26874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561954830abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561954839928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561954821699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56195484c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe30dc0d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56194e146b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xcd,0x8e,0xcd,0x8c,0xd7,0x82,0xcd,0x9f,0xd7,0x82,0xcd,0x9f,0xdd,0x84,0xcd,0x8c, Step #5: ws:\315\216\315\214\327\202\315\237\327\202\315\237\335\204\315\214 Step #5: artifact_prefix='./'; Test unit written to ./oom-d01190554df1f557cd20f5f8cee6b33c74dc5a1e Step #5: Base64: d3M6zY7NjNeCzZ/Xgs2f3YTNjA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2123 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2756038205 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bfd896d810, 0x55bfd8b5701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bfd8b57020,0x55bfda9ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d01190554df1f557cd20f5f8cee6b33c74dc5a1e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2508 processed earlier; will process 8521 files now Step #5: ==76462== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bfcf4629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bfd5ac7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bfd5aaa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bfd5aaa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bfcf468d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bfcf3c9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bfcf3c4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bfcf45ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bfd2429f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bfd2429f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bfd2429f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bfd2429f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bfd2429f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bfd2429f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bfd2429f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bfd2429f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bfd2429f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bfd2429f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bfd46bef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bfd13ebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bfd13f6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bfd11a2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bfd11a2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bfd11a3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bfd11a2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bfd11a2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bfd11a2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bfd5aacabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bfd5ab5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bfd5a9d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bfd5ac8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa51456d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bfcf3c2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x58,0x2e,0x30,0x30,0x30,0x30,0x34,0x66,0x66,0x30,0x30,0x34,0x30,0x34,0x34,0x36,0x37,0x30, Step #5: 0X.00004ff004044670 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ecebf6c6858516c8c62f2eae3dd0d0596090c3a Step #5: Base64: MFguMDAwMDRmZjAwNDA0NDY3MA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2124 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2756501258 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5649fba15810, 0x5649fbbff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5649fbbff020,0x5649fda970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ecebf6c6858516c8c62f2eae3dd0d0596090c3a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2509 processed earlier; will process 8520 files now Step #5: #1 pulse cov: 3809 ft: 3810 exec/s: 0 rss: 170Mb Step #5: ==76498== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5649f250a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5649f8b6f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5649f8b525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5649f8b524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5649f2510d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649f2471b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649f246c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5649f2502c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5649f54d1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5649f54d1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5649f54d1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5649f54d1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5649f54d1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5649f54d1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5649f54d1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5649f54d1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5649f54d1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5649f54d1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5649f7766f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649f4493b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649f449ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5649f424ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5649f424ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5649f424b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5649f424a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5649f424a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5649f424a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5649f8b54abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5649f8b5d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5649f8b45699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5649f8b70112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f91e2625082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649f246ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x29,0x0, Step #5: ($$$$$$$$$$$$$$$$)\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-58a318ad5abcd941face8fbabe8b6ad2e8aed77b Step #5: Base64: KCQkJCQkJCQkJCQkJCQkJCQpAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2125 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2757010237 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557847f54810, 0x55784813e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55784813e020,0x557849fd60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58a318ad5abcd941face8fbabe8b6ad2e8aed77b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2511 processed earlier; will process 8518 files now Step #5: #1 pulse cov: 3550 ft: 3551 exec/s: 0 rss: 169Mb Step #5: ==76534== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55783ea499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5578450ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5578450915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5578450914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55783ea4fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55783e9b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55783e9ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55783ea41c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557841a10f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557841a10f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557841a10f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557841a10f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557841a10f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557841a10f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557841a10f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557841a10f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557841a10f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557841a10f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557843ca5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5578409d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5578409ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557840789c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557840789c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55784078a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557840789874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557840789874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557840789874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557845093abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55784509c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557845084699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5578450af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd5fe604082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55783e9a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x2a,0x2a,0x2a,0xa,0x24,0x2a,0x2a,0x2a,0xa,0x27,0x5e,0x2a,0xa,0x27,0x5e,0xe,0x27,0x5e, Step #5: $***\012$***\012'^*\012'^\016'^ Step #5: artifact_prefix='./'; Test unit written to ./oom-0909e878fd95cc997025fd849c8f530243bffe9b Step #5: Base64: JCoqKgokKioqCideKgonXg4nXg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2126 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2757523092 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f0f8cee810, 0x55f0f8ed801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f0f8ed8020,0x55f0fad700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0909e878fd95cc997025fd849c8f530243bffe9b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2513 processed earlier; will process 8516 files now Step #5: ==76570== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f0ef7e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f0f5e48898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f0f5e2b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f0f5e2b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f0ef7e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f0ef74ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f0ef745355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f0ef7dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f0f27aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f0f27aaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f0f27aaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f0f27aaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f0f27aaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f0f27aaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f0f27aaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f0f27aaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f0f27aaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f0f27aaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f0f4a3ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f0f176cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f0f1777be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f0f1523c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f0f1523c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f0f1524738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f0f1523874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f0f1523874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f0f1523874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f0f5e2dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f0f5e36928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f0f5e1e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f0f5e49112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6efb192082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f0ef743b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x11,0xcc,0xb0,0x4e,0x6f,0x0,0x0,0xcc,0x9c,0x0,0xcc,0x9c,0x0,0xcc,0x9c,0x0,0xdb, Step #5: \000\000\021\314\260No\000\000\314\234\000\314\234\000\314\234\000\333 Step #5: artifact_prefix='./'; Test unit written to ./oom-d870e0aab37971cf0807a740b67216256309b907 Step #5: Base64: AAARzLBObwAAzJwAzJwAzJwA2w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2127 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2757983971 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5600a60ef810, 0x5600a62d901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5600a62d9020,0x5600a81710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d870e0aab37971cf0807a740b67216256309b907' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2514 processed earlier; will process 8515 files now Step #5: ==76606== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56009cbe49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5600a3249898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5600a322c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5600a322c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56009cbead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56009cb4bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56009cb46355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56009cbdcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56009fbabf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56009fbabf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56009fbabf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56009fbabf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56009fbabf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56009fbabf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56009fbabf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56009fbabf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56009fbabf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56009fbabf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5600a1e40f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56009eb6db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56009eb78be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56009e924c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56009e924c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56009e925738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56009e924874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56009e924874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56009e924874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5600a322eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5600a3237928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5600a321f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5600a324a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f54b6688082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56009cb44b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x10,0x43,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x2d,0x74,0x79,0x70,0x65,0x3a,0xe3,0x80,0x8d, Step #5: \000\000\000\020Content-type:\343\200\215 Step #5: artifact_prefix='./'; Test unit written to ./oom-d4610c54bd3afd5d1f79f7bb314fb4b6cb745036 Step #5: Base64: AAAAEENvbnRlbnQtdHlwZTrjgI0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2128 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2758446672 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d34a290810, 0x55d34a47a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d34a47a020,0x55d34c3120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d4610c54bd3afd5d1f79f7bb314fb4b6cb745036' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2515 processed earlier; will process 8514 files now Step #5: ==76642== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d340d859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d3473ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d3473cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d3473cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d340d8bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d340cecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d340ce7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d340d7dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d343d4cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d343d4cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d343d4cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d343d4cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d343d4cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d343d4cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d343d4cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d343d4cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d343d4cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d343d4cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d345fe1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d342d0eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d342d19be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d342ac5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d342ac5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d342ac6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d342ac5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d342ac5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d342ac5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d3473cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d3473d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d3473c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d3473eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7464da1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d340ce5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0x75,0x24,0x33,0x9,0x6e,0x75,0x24,0x33,0x9,0x6e,0x75,0x24,0x33,0x9,0x6e,0x75,0x24,0x33,0x9, Step #5: nu$3\011nu$3\011nu$3\011nu$3\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-51b72f3bfa9e757c6fc6057e432e7f553dee67f2 Step #5: Base64: bnUkMwludSQzCW51JDMJbnUkMwk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2129 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2758911761 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563fc27c3810, 0x563fc29ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563fc29ad020,0x563fc48450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/51b72f3bfa9e757c6fc6057e432e7f553dee67f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2516 processed earlier; will process 8513 files now Step #5: ==76678== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563fb92b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563fbf91d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563fbf9005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563fbf9004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563fb92bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563fb921fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563fb921a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563fb92b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563fbc27ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563fbc27ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563fbc27ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563fbc27ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563fbc27ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563fbc27ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563fbc27ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563fbc27ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563fbc27ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563fbc27ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563fbe514f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563fbb241b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563fbb24cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563fbaff8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563fbaff8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563fbaff9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563fbaff8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563fbaff8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563fbaff8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563fbf902abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563fbf90b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563fbf8f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563fbf91e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b0b1cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563fb9218b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x2d,0x33,0x2d,0x36,0x20,0x38,0x3a,0x30,0x3a,0x39,0x2b,0x31,0x31,0x34,0x37,0x31,0x34,0xd1,0xad, Step #5: 0-3-6 8:0:9+114714\321\255 Step #5: artifact_prefix='./'; Test unit written to ./oom-e4113a0de4f2bb08c782faf1f47ecf94e0ec0cbf Step #5: Base64: MC0zLTYgODowOjkrMTE0NzE00a0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2130 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2759370695 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd7f11d810, 0x55dd7f30701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd7f307020,0x55dd8119f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e4113a0de4f2bb08c782faf1f47ecf94e0ec0cbf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2517 processed earlier; will process 8512 files now Step #5: #1 pulse cov: 11155 ft: 11156 exec/s: 0 rss: 186Mb Step #5: #2 pulse cov: 11719 ft: 12583 exec/s: 0 rss: 188Mb Step #5: ==76714== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dd75c129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd7c277898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd7c25a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd7c25a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dd75c18d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dd75b79b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dd75b74355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dd75c0ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd78bd9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd78bd9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd78bd9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd78bd9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd78bd9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd78bd9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd78bd9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd78bd9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd78bd9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd78bd9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd7ae6ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dd77b9bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dd77ba6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dd77952c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dd77952c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dd77953738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dd77952874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dd77952874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dd77952874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd7c25cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd7c265928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd7c24d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd7c278112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f96d40e1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dd75b72b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x55,0x54,0x20,0x2f,0xa,0x54,0x72,0x61,0x6e,0x73,0x66,0x65,0x72,0x2d,0x65,0x67,0x3a,0xa,0xa, Step #5: PUT /\012Transfer-eg:\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-ebc0dd2cf51ad02718770cd9839239417cb53f49 Step #5: Base64: UFVUIC8KVHJhbnNmZXItZWc6Cgo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2131 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2759935829 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5579ae760810, 0x5579ae94a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5579ae94a020,0x5579b07e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ebc0dd2cf51ad02718770cd9839239417cb53f49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2520 processed earlier; will process 8509 files now Step #5: ==76750== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5579a52559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5579ab8ba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5579ab89d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5579ab89d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5579a525bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5579a51bcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5579a51b7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5579a524dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5579a821cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5579a821cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5579a821cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5579a821cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5579a821cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5579a821cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5579a821cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5579a821cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5579a821cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5579a821cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579aa4b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5579a71deb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5579a71e9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5579a6f95c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5579a6f95c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5579a6f96738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5579a6f95874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5579a6f95874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5579a6f95874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5579ab89fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5579ab8a8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5579ab890699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5579ab8bb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f64c6fb3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5579a51b5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x4f,0x27,0xd1,0xa1,0x27,0x45,0x27,0x5c,0xd1,0xa1,0x27,0x45,0x27,0x5c,0xca,0xb6,0xd1,0x81,0x27, Step #5: dO'\321\241'E'\\\321\241'E'\\\312\266\321\201' Step #5: artifact_prefix='./'; Test unit written to ./oom-645cae80dc0a915b10b13ae311d63529a5fbf58d Step #5: Base64: ZE8n0aEnRSdc0aEnRSdcyrbRgSc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2132 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2760394257 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ea8d02810, 0x562ea8eec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ea8eec020,0x562eaad840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/645cae80dc0a915b10b13ae311d63529a5fbf58d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2521 processed earlier; will process 8508 files now Step #5: ==76786== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562e9f7f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ea5e5c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ea5e3f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ea5e3f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e9f7fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e9f75eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e9f759355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e9f7efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ea27bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ea27bef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ea27bef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ea27bef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ea27bef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ea27bef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ea27bef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ea27bef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ea27bef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ea27bef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ea4a53f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ea1780b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ea178bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ea1537c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ea1537c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ea1538738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ea1537874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ea1537874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ea1537874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ea5e41abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ea5e4a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ea5e32699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ea5e5d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f445548c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e9f757b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x6d,0x2e,0x73,0x77,0x61,0x70,0xa,0x69,0x6e,0x61,0x63,0x74,0x69,0x76,0x65,0x2d,0x65,0x6e,0x1, Step #5: \000m.swap\012inactive-en\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-d66719d6706ecad78d3e26f3325b9e5339e9f08c Step #5: Base64: AG0uc3dhcAppbmFjdGl2ZS1lbgE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2133 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2760872009 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611968b9810, 0x561196aa301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561196aa3020,0x56119893b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d66719d6706ecad78d3e26f3325b9e5339e9f08c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2522 processed earlier; will process 8507 files now Step #5: #1 pulse cov: 3483 ft: 3484 exec/s: 0 rss: 169Mb Step #5: #2 pulse cov: 4296 ft: 4579 exec/s: 0 rss: 171Mb Step #5: ==76822== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56118d3ae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561193a13898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611939f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611939f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56118d3b4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56118d315b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56118d310355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56118d3a6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561190375f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561190375f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561190375f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561190375f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561190375f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561190375f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561190375f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561190375f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561190375f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561190375f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56119260af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56118f337b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56118f342be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56118f0eec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56118f0eec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56118f0ef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56118f0ee874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56118f0ee874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56118f0ee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5611939f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561193a01928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611939e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561193a14112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3f77d61082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56118d30eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x72,0x69,0x66,0x42,0x45,0x62,0x6b,0x47,0x49,0x4e,0x6d,0x45,0x4e,0x3d,0x20,0xab,0x39, Step #5: s--rifBEbkGINmEN= \2539 Step #5: artifact_prefix='./'; Test unit written to ./oom-d5903c0e9cf50633b46b84cc3b6714f4c6876cf0 Step #5: Base64: cy0tcmlmQkVia0dJTm1FTj0gqzk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2134 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2761409845 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55effa3a1810, 0x55effa58b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55effa58b020,0x55effc4230e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d5903c0e9cf50633b46b84cc3b6714f4c6876cf0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2525 processed earlier; will process 8504 files now Step #5: #1 pulse cov: 3476 ft: 3477 exec/s: 0 rss: 167Mb Step #5: ==76858== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eff0e969c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eff74fb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eff74de5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eff74de4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eff0e9cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eff0dfdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eff0df8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eff0e8ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eff3e5df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eff3e5df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eff3e5df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eff3e5df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eff3e5df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eff3e5df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eff3e5df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eff3e5df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eff3e5df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eff3e5df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eff60f2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eff2e1fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eff2e2abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eff2bd6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eff2bd6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eff2bd7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eff2bd6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eff2bd6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eff2bd6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eff74e0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eff74e9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eff74d1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eff74fc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b32720082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eff0df6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x30,0x3d,0x2d,0x49,0x69,0x49,0x36,0x4d,0x32,0x55,0x7a,0x49,0x48,0x30,0x2e,0x65,0x33,0x30,0x2e, Step #5: e0=-IiI6M2UzIH0.e30. Step #5: artifact_prefix='./'; Test unit written to ./oom-b53469b0dae2f2e7f3d1f3d915d500823d9ef982 Step #5: Base64: ZTA9LUlpSTZNMlV6SUgwLmUzMC4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2135 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2761911738 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564dcdc28810, 0x564dcde1201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564dcde12020,0x564dcfcaa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b53469b0dae2f2e7f3d1f3d915d500823d9ef982' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2527 processed earlier; will process 8502 files now Step #5: ==76894== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564dc471d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564dcad82898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564dcad655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564dcad654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564dc4723d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564dc4684b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564dc467f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564dc4715c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564dc76e4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564dc76e4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564dc76e4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564dc76e4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564dc76e4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564dc76e4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564dc76e4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564dc76e4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564dc76e4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564dc76e4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564dc9979f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564dc66a6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564dc66b1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564dc645dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564dc645dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564dc645e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564dc645d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564dc645d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564dc645d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564dcad67abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564dcad70928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564dcad58699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564dcad83112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff65c638082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564dc467db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33,0x3a,0x31,0x9,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f, Step #5: 3:1\011________________ Step #5: artifact_prefix='./'; Test unit written to ./oom-a0f26938647bb5f5fac41f5b196b7085a1b2c162 Step #5: Base64: MzoxCV9fX19fX19fX19fX19fX18= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2136 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2762372812 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5557efb3f810, 0x5557efd2901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5557efd29020,0x5557f1bc10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a0f26938647bb5f5fac41f5b196b7085a1b2c162' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2528 processed earlier; will process 8501 files now Step #5: ==76930== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5557e66349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5557ecc99898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557ecc7c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557ecc7c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557e663ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557e659bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5557e6596355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557e662cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557e95fbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557e95fbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557e95fbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557e95fbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557e95fbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557e95fbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557e95fbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557e95fbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557e95fbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557e95fbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5557eb890f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557e85bdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557e85c8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5557e8374c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5557e8374c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5557e8375738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5557e8374874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5557e8374874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5557e8374874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557ecc7eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557ecc87928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557ecc6f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5557ecc9a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c0617e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5557e6594b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x7,0xef,0xad,0xbf,0xef,0xbc,0xbb,0xff,0xf9,0xe1,0xff,0x79,0x7d,0xff,0x4b,0x9,0x3d, Step #5: \000\000\000\007\357\255\277\357\274\273\377\371\341\377y}\377K\011= Step #5: artifact_prefix='./'; Test unit written to ./oom-a148e4adb01d0deb4637a993b417c6af5db9403b Step #5: Base64: AAAAB++tv++8u//54f95ff9LCT0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2137 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2762836078 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d7636f5810, 0x55d7638df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d7638df020,0x55d7657770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a148e4adb01d0deb4637a993b417c6af5db9403b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2529 processed earlier; will process 8500 files now Step #5: ==76966== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d75a1ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d76084f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7608325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7608324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d75a1f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d75a151b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d75a14c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d75a1e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d75d1b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d75d1b1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d75d1b1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d75d1b1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d75d1b1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d75d1b1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d75d1b1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d75d1b1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d75d1b1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d75d1b1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d75f446f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d75c173b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d75c17ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d75bf2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d75bf2ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d75bf2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d75bf2a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d75bf2a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d75bf2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d760834abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d76083d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d760825699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d760850112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f588abd5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d75a14ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xce,0x85,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xd6,0xb7,0xcd,0x84,0xcd,0x84, Step #5: \316\205\315\204\315\204\315\204\315\204\315\204\315\204\326\267\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec01dcfedd13fa5e08984a4e221534353483b0a3 Step #5: Base64: zoXNhM2EzYTNhM2EzYTWt82EzYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2138 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2763301996 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55619b705810, 0x55619b8ef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55619b8ef020,0x55619d7870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec01dcfedd13fa5e08984a4e221534353483b0a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2530 processed earlier; will process 8499 files now Step #5: ==77002== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5561921fa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55619885f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5561988425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5561988424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556192200d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556192161b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55619215c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5561921f2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5561951c1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5561951c1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5561951c1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5561951c1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5561951c1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5561951c1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5561951c1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5561951c1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5561951c1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5561951c1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556197456f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556194183b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55619418ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556193f3ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556193f3ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556193f3b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556193f3a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556193f3a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556193f3a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556198844abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55619884d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556198835699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556198860112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7be028d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55619215ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x54,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x4f,0x3a,0x1a, Step #5: $T\000\000\000\000\000\000\000\000\000\000\000\000\000\000$O:\032 Step #5: artifact_prefix='./'; Test unit written to ./oom-1957ca57ae4bd36edfc0daf156d3804e9552dbf1 Step #5: Base64: JFQAAAAAAAAAAAAAAAAAACRPOho= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2139 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2763768675 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ec0f70810, 0x555ec115a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ec115a020,0x555ec2ff20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1957ca57ae4bd36edfc0daf156d3804e9552dbf1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2531 processed earlier; will process 8498 files now Step #5: ==77038== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555eb7a659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ebe0ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ebe0ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ebe0ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555eb7a6bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555eb79ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555eb79c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555eb7a5dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ebaa2cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ebaa2cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ebaa2cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ebaa2cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ebaa2cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ebaa2cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ebaa2cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ebaa2cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ebaa2cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ebaa2cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555ebccc1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555eb99eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555eb99f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555eb97a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555eb97a5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555eb97a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555eb97a5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555eb97a5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555eb97a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ebe0afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ebe0b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ebe0a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ebe0cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc249ed8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555eb79c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2b,0xc,0x20,0x2b,0x2d,0xa,0x2b,0xc,0x20,0x2b,0x2d,0x2d,0x0,0x63,0xa,0xa,0x2b,0xc,0x36, Step #5: \012+\014 +-\012+\014 +--\000c\012\012+\0146 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7600c50b48bd50465043bc58a80fd3437c5b607 Step #5: Base64: CisMICstCisMICstLQBjCgorDDY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2140 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2764234953 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563c26b03810, 0x563c26ced01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563c26ced020,0x563c28b850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7600c50b48bd50465043bc58a80fd3437c5b607' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2532 processed earlier; will process 8497 files now Step #5: ==77074== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563c1d5f89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563c23c5d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563c23c405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563c23c404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563c1d5fed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563c1d55fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563c1d55a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563c1d5f0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563c205bff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563c205bff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563c205bff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563c205bff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563c205bff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563c205bff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563c205bff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563c205bff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563c205bff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563c205bff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563c22854f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563c1f581b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563c1f58cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563c1f338c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563c1f338c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563c1f339738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563c1f338874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563c1f338874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563c1f338874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563c23c42abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563c23c4b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563c23c33699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563c23c5e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f624ce2b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563c1d558b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x0,0x0,0x1,0xe2,0x80,0xae,0xf3,0xa0,0x81,0x8b,0x1d,0xe2,0x80,0x81,0x0,0x58, Step #5: ID3\004\000\000\001\342\200\256\363\240\201\213\035\342\200\201\000X Step #5: artifact_prefix='./'; Test unit written to ./oom-618e52bc78cda352a263eb1d4995e1dd87ded28e Step #5: Base64: SUQzBAAAAeKArvOggYsd4oCBAFg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2141 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2764693875 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1a81f8810, 0x55d1a83e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1a83e2020,0x55d1aa27a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/618e52bc78cda352a263eb1d4995e1dd87ded28e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2533 processed earlier; will process 8496 files now Step #5: ==77110== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d19eced9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1a5352898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1a53355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1a53354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d19ecf3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d19ec54b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d19ec4f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d19ece5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1a1cb4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1a1cb4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1a1cb4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1a1cb4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1a1cb4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1a1cb4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1a1cb4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1a1cb4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1a1cb4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1a1cb4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1a3f49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1a0c76b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1a0c81be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1a0a2dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1a0a2dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1a0a2e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1a0a2d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1a0a2d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1a0a2d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1a5337abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1a5340928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1a5328699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1a5353112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ca2bf5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d19ec4db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xed,0x85,0x92,0x3e,0x3c,0xed,0x85,0x92,0x3e,0x3c,0xed,0x85,0x92,0x3e,0x3c,0xed,0x85,0x92,0x3e, Step #5: <\355\205\222><\355\205\222><\355\205\222><\355\205\222> Step #5: artifact_prefix='./'; Test unit written to ./oom-54abc6ab60f4dc17f8437f1a97aac950e703480e Step #5: Base64: PO2Fkj487YWSPjzthZI+PO2Fkj4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2142 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2765141388 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5564f7105810, 0x5564f72ef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564f72ef020,0x5564f91870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/54abc6ab60f4dc17f8437f1a97aac950e703480e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2534 processed earlier; will process 8495 files now Step #5: #1 pulse cov: 3605 ft: 3606 exec/s: 0 rss: 167Mb Step #5: ==77146== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5564edbfa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564f425f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564f42425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564f42424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564edc00d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5564edb61b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5564edb5c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564edbf2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564f0bc1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564f0bc1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564f0bc1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564f0bc1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564f0bc1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564f0bc1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564f0bc1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564f0bc1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564f0bc1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564f0bc1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5564f2e56f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5564efb83b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5564efb8ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5564ef93ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5564ef93ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5564ef93b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5564ef93a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5564ef93a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5564ef93a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564f4244abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564f424d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564f4235699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564f4260112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0979f35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5564edb5ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x6d,0x3a,0x69,0x2e,0x3e,0x3c,0x78,0x6d,0x75,0x3a,0x69,0x3e,0xff,0xff,0xff,0xff,0xff,0xff,0xff, Step #5: \377\377\377\377\377\377\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-197ad27000380a5cd110a36432abbb5d7b05a2b9 Step #5: Base64: PG06aS4+PHhtdTppPv////////8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2143 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2765630322 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5644b51e2810, 0x5644b53cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5644b53cc020,0x5644b72640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/197ad27000380a5cd110a36432abbb5d7b05a2b9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2536 processed earlier; will process 8493 files now Step #5: #1 pulse cov: 3869 ft: 3870 exec/s: 0 rss: 167Mb Step #5: ==77182== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5644abcd79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5644b233c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5644b231f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5644b231f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5644abcddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5644abc3eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5644abc39355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5644abccfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5644aec9ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5644aec9ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5644aec9ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5644aec9ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5644aec9ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5644aec9ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5644aec9ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5644aec9ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5644aec9ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5644aec9ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5644b0f33f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5644adc60b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5644adc6bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5644ada17c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5644ada17c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5644ada18738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5644ada17874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5644ada17874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5644ada17874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5644b2321abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5644b232a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5644b2312699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5644b233d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f80d446a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5644abc37b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x44,0x73,0x74,0x65,0x72,0x61,0x6d,0x60,0x6e,0x61,0x44,0x60,0x6e,0x69,0x66,0x4d,0x83,0x12, Step #5: DaDsteram`naD`nifM\203\022 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf4eaf7ea933c10d75cddf0d32c8d23be3ca3eeb Step #5: Base64: RGFEc3RlcmFtYG5hRGBuaWZNgxI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2144 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2766258074 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5570935a5810, 0x55709378f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55709378f020,0x5570956270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf4eaf7ea933c10d75cddf0d32c8d23be3ca3eeb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2538 processed earlier; will process 8491 files now Step #5: ==77218== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55708a09a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5570906ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5570906e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5570906e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55708a0a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55708a001b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557089ffc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55708a092c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55708d061f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55708d061f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55708d061f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55708d061f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55708d061f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55708d061f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55708d061f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55708d061f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55708d061f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55708d061f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55708f2f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55708c023b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55708c02ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55708bddac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55708bddac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55708bddb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55708bdda874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55708bdda874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55708bdda874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5570906e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5570906ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5570906d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557090700112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f995e386082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557089ffab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3a,0x20,0x78,0x6d,0x6c,0x3a,0x69,0x64,0x3d,0x22,0x78,0xe3,0x80,0x87,0xe3,0x80,0x87,0x22,0x3e, Step #5: <: xml:id=\"x\343\200\207\343\200\207\"> Step #5: artifact_prefix='./'; Test unit written to ./oom-aebe11cad1e394baaa406e9e889514e9865e2a13 Step #5: Base64: PDogeG1sOmlkPSJ444CH44CHIj4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2145 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2766720853 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56221294d810, 0x562212b3701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562212b37020,0x5622149cf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aebe11cad1e394baaa406e9e889514e9865e2a13' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2539 processed earlier; will process 8490 files now Step #5: #1 pulse cov: 3671 ft: 3672 exec/s: 0 rss: 169Mb Step #5: ==77254== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5622094429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56220faa7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56220fa8a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56220fa8a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562209448d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5622093a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5622093a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56220943ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56220c409f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56220c409f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56220c409f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56220c409f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56220c409f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56220c409f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56220c409f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56220c409f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56220c409f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56220c409f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56220e69ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56220b3cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56220b3d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56220b182c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56220b182c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56220b183738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56220b182874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56220b182874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56220b182874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56220fa8cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56220fa95928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56220fa7d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56220faa8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7405c1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5622093a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x45,0x78,0x65,0x63,0x5d,0xa,0x4c,0x69,0x6d,0x69,0x74,0x41,0x53,0x3d,0x35,0x32,0x4b,0x3a,0x31, Step #5: [Exec]\012LimitAS=52K:1 Step #5: artifact_prefix='./'; Test unit written to ./oom-0169a3da37061bea62cbee657c985dc362e3c832 Step #5: Base64: W0V4ZWNdCkxpbWl0QVM9NTJLOjE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2146 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2767224442 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560627520810, 0x56062770a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56062770a020,0x5606295a20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0169a3da37061bea62cbee657c985dc362e3c832' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2541 processed earlier; will process 8488 files now Step #5: #1 pulse cov: 3742 ft: 3743 exec/s: 0 rss: 169Mb Step #5: #2 pulse cov: 4157 ft: 4514 exec/s: 0 rss: 171Mb Step #5: ==77290== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56061e0159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56062467a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56062465d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56062465d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56061e01bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56061df7cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56061df77355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56061e00dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560620fdcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560620fdcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560620fdcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560620fdcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560620fdcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560620fdcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560620fdcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560620fdcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560620fdcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560620fdcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560623271f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56061ff9eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56061ffa9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56061fd55c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56061fd55c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56061fd56738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56061fd55874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56061fd55874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56061fd55874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56062465fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560624668928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560624650699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56062467b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8dae36a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56061df75b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7,0x40,0x26,0xa0,0x37,0x20,0x98,0x37,0x2e,0x15,0x48,0x17,0x9,0x80,0x27,0x0,0x0,0xda,0x67,0xdc, Step #5: \007@&\2407 \2307.\025H\027\011\200'\000\000\332g\334 Step #5: artifact_prefix='./'; Test unit written to ./oom-a16bc1dc1454d289a9e21858542cce092093be75 Step #5: Base64: B0AmoDcgmDcuFUgXCYAnAADaZ9w= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2147 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2767768803 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560c4ac72810, 0x560c4ae5c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560c4ae5c020,0x560c4ccf40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a16bc1dc1454d289a9e21858542cce092093be75' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2544 processed earlier; will process 8485 files now Step #5: ==77326== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560c417679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560c47dcc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560c47daf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560c47daf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560c4176dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560c416ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560c416c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560c4175fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560c4472ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560c4472ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560c4472ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560c4472ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560c4472ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560c4472ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560c4472ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560c4472ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560c4472ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560c4472ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560c469c3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560c436f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560c436fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560c434a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560c434a7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560c434a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560c434a7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560c434a7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560c434a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560c47db1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560c47dba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560c47da2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560c47dcd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5671ce6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560c416c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x1,0x4,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0xd8,0xbd,0x2a, Step #5: *\001\004\004\000\000\000\000\000\000\004\004\004\004\004\004\004\330\275* Step #5: artifact_prefix='./'; Test unit written to ./oom-99ff02219e7c301ab75913a21ce003a2a66b77a9 Step #5: Base64: KgEEBAAAAAAAAAQEBAQEBATYvSo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2148 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2768236311 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f66d2c9810, 0x55f66d4b301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f66d4b3020,0x55f66f34b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/99ff02219e7c301ab75913a21ce003a2a66b77a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2545 processed earlier; will process 8484 files now Step #5: ==77362== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f663dbe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f66a423898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f66a4065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f66a4064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f663dc4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f663d25b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f663d20355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f663db6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f666d85f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f666d85f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f666d85f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f666d85f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f666d85f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f666d85f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f666d85f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f666d85f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f666d85f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f666d85f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f66901af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f665d47b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f665d52be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f665afec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f665afec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f665aff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f665afe874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f665afe874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f665afe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f66a408abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f66a411928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f66a3f9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f66a424112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa40fa18082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f663d1eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0xbd,0x73,0x74,0x3b,0x6d,0x62,0xdf,0xbd,0x73,0x4e,0x3b,0x6d,0x62,0xdf,0xbd,0x73,0x74,0x4e,0x3b, Step #5: \337\275st;mb\337\275sN;mb\337\275stN; Step #5: artifact_prefix='./'; Test unit written to ./oom-c1a9bce9520dd004faf1dca21d63a90c84d50bad Step #5: Base64: 371zdDttYt+9c047bWLfvXN0Tjs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2149 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2768706566 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f5a574c810, 0x55f5a593601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f5a5936020,0x55f5a77ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c1a9bce9520dd004faf1dca21d63a90c84d50bad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2546 processed earlier; will process 8483 files now Step #5: #1 pulse cov: 3764 ft: 3765 exec/s: 0 rss: 169Mb Step #5: ==77398== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f59c2419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f5a28a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f5a28895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f5a28894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f59c247d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f59c1a8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f59c1a3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f59c239c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f59f208f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f59f208f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f59f208f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f59f208f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f59f208f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f59f208f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f59f208f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f59f208f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f59f208f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f59f208f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f5a149df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f59e1cab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f59e1d5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f59df81c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f59df81c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f59df82738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f59df81874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f59df81874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f59df81874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f5a288babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f5a2894928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f5a287c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f5a28a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f76fd7dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f59c1a1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27, Step #5: ''''''''''''''''''' Step #5: artifact_prefix='./'; Test unit written to ./oom-c720753720809b720c757e9b484d8d7995ec2d75 Step #5: Base64: ICcnJycnJycnJycnJycnJycnJyc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2150 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2769206566 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5558c2f90810, 0x5558c317a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5558c317a020,0x5558c50120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c720753720809b720c757e9b484d8d7995ec2d75' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2548 processed earlier; will process 8481 files now Step #5: ==77434== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5558b9a859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5558c00ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5558c00cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5558c00cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5558b9a8bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5558b99ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5558b99e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5558b9a7dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5558bca4cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5558bca4cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5558bca4cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5558bca4cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5558bca4cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5558bca4cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5558bca4cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5558bca4cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5558bca4cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5558bca4cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5558bece1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5558bba0eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5558bba19be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5558bb7c5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5558bb7c5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5558bb7c6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5558bb7c5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5558bb7c5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5558bb7c5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5558c00cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5558c00d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5558c00c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5558c00eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ab06e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5558b99e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x31,0x44,0x73,0x30,0x0,0x0,0x0,0x0,0x0,0x5,0x69,0x0,0xf3,0xa0,0x84,0x81, Step #5: ID3\0041Ds0\000\000\000\000\000\005i\000\363\240\204\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-be711afdf2cf49fbdbaf98397b3fd91d1248ef6c Step #5: Base64: SUQzBDFEczAAAAAAAAVpAPOghIE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2151 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2769677210 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ac85597810, 0x55ac8578101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ac85781020,0x55ac876190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/be711afdf2cf49fbdbaf98397b3fd91d1248ef6c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2549 processed earlier; will process 8480 files now Step #5: #1 pulse cov: 10885 ft: 10886 exec/s: 0 rss: 187Mb Step #5: ==77470== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ac7c08c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ac826f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ac826d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ac826d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ac7c092d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ac7bff3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ac7bfee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ac7c084c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ac7f053f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ac7f053f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ac7f053f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ac7f053f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ac7f053f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ac7f053f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ac7f053f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ac7f053f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ac7f053f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ac7f053f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ac812e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ac7e015b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ac7e020be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ac7ddccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ac7ddccc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ac7ddcd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ac7ddcc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ac7ddcc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ac7ddcc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ac826d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ac826df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ac826c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ac826f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f921c138082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ac7bfecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x60,0x0,0x0,0x0,0x60,0x49,0x4e,0x54,0x20,0x45,0x50,0x48,0x45,0x4d,0x45,0x52,0x41,0x4c,0xa, Step #5: \012`\000\000\000`INT EPHEMERAL\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-25c836d015c21846f398d84736d536767d24d2f0 Step #5: Base64: CmAAAABgSU5UIEVQSEVNRVJBTAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2152 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2770328362 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5583deba8810, 0x5583ded9201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5583ded92020,0x5583e0c2a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/25c836d015c21846f398d84736d536767d24d2f0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2551 processed earlier; will process 8478 files now Step #5: #1 pulse cov: 4052 ft: 4053 exec/s: 0 rss: 170Mb Step #5: ==77506== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5583d569d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5583dbd02898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583dbce55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583dbce54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5583d56a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5583d5604b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5583d55ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5583d5695c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5583d8664f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5583d8664f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5583d8664f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5583d8664f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5583d8664f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5583d8664f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5583d8664f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5583d8664f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5583d8664f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5583d8664f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5583da8f9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5583d7626b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5583d7631be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5583d73ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5583d73ddc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5583d73de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5583d73dd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5583d73dd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5583d73dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5583dbce7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5583dbcf0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5583dbcd8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5583dbd03112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f89f197d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5583d55fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3c,0x77,0x3e,0x28,0x3f,0x3c,0x57,0x3e,0x28,0x3f,0x3c,0x6d,0x3e,0x28,0x3f,0x3c,0x36,0x3e, Step #5: (?(?(?(?<6> Step #5: artifact_prefix='./'; Test unit written to ./oom-fe57c25bba47e0d947974d6ef658a9aa93a79083 Step #5: Base64: KD88dz4oPzxXPig/PG0+KD88Nj4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2153 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2770837338 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fd0acdd810, 0x55fd0aec701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fd0aec7020,0x55fd0cd5f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fe57c25bba47e0d947974d6ef658a9aa93a79083' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2553 processed earlier; will process 8476 files now Step #5: ==77542== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fd017d29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fd07e37898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fd07e1a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fd07e1a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fd017d8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fd01739b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fd01734355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fd017cac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fd04799f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fd04799f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fd04799f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fd04799f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fd04799f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fd04799f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fd04799f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fd04799f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fd04799f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fd04799f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fd06a2ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fd0375bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fd03766be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fd03512c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fd03512c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fd03513738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fd03512874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fd03512874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fd03512874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fd07e1cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fd07e25928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fd07e0d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fd07e38112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f97673c8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fd01732b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d, Step #5: \012-\012=\012=\012=\012=\012=\012=\012=\012=\012= Step #5: artifact_prefix='./'; Test unit written to ./oom-337b75236ef66284dc05d3d8011a81f7f8e01c98 Step #5: Base64: Ci0KPQo9Cj0KPQo9Cj0KPQo9Cj0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2154 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2771303112 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca90bee810, 0x55ca90dd801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca90dd8020,0x55ca92c700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/337b75236ef66284dc05d3d8011a81f7f8e01c98' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2554 processed earlier; will process 8475 files now Step #5: ==77578== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ca876e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca8dd48898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca8dd2b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca8dd2b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca876e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca8764ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca87645355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca876dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca8a6aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca8a6aaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca8a6aaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca8a6aaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca8a6aaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca8a6aaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca8a6aaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca8a6aaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca8a6aaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca8a6aaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca8c93ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca8966cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca89677be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca89423c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca89423c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca89424738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca89423874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca89423874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca89423874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca8dd2dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca8dd36928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca8dd1e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca8dd49112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ead00c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca87643b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29, Step #5: ^(?:$|$|$|$|$|$|$|$) Step #5: artifact_prefix='./'; Test unit written to ./oom-785b33ad9fcf0b949b8e2163d26ad370344444d6 Step #5: Base64: Xig/OiR8JHwkfCR8JHwkfCR8JCk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2155 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2771772987 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a583e6f810, 0x55a58405901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a584059020,0x55a585ef10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/785b33ad9fcf0b949b8e2163d26ad370344444d6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2555 processed earlier; will process 8474 files now Step #5: #1 pulse cov: 4271 ft: 4272 exec/s: 0 rss: 172Mb Step #5: ==77614== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a57a9649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a580fc9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a580fac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a580fac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a57a96ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a57a8cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a57a8c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a57a95cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a57d92bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a57d92bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a57d92bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a57d92bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a57d92bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a57d92bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a57d92bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a57d92bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a57d92bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a57d92bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a57fbc0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a57c8edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a57c8f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a57c6a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a57c6a4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a57c6a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a57c6a4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a57c6a4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a57c6a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a580faeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a580fb7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a580f9f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a580fca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ffc173082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a57a8c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x2a,0xa,0x3d,0xa,0x1,0xa,0x1,0xa,0x3d,0x2a,0xa,0x3d,0xa,0x1,0xa,0x1,0xa,0xa,0xa, Step #5: +*\012=\012\001\012\001\012=*\012=\012\001\012\001\012\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-212453b42605a326cf191e05eaa31065b7e9e5d9 Step #5: Base64: KyoKPQoBCgEKPSoKPQoBCgEKCgo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2156 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2772280664 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5557b0d52810, 0x5557b0f3c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5557b0f3c020,0x5557b2dd40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/212453b42605a326cf191e05eaa31065b7e9e5d9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2557 processed earlier; will process 8472 files now Step #5: ==77650== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5557a78479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5557adeac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557ade8f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557ade8f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557a784dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557a77aeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5557a77a9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557a783fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557aa80ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557aa80ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557aa80ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557aa80ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557aa80ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557aa80ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557aa80ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557aa80ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557aa80ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557aa80ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5557acaa3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557a97d0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557a97dbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5557a9587c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5557a9587c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5557a9588738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5557a9587874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5557a9587874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5557a9587874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557ade91abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557ade9a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557ade82699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5557adead112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f83ce218082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5557a77a7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x11,0x23,0x22,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x22, Step #5: \021#\"\\P\\P\\P\\P\\P\\P\\P\\P\" Step #5: artifact_prefix='./'; Test unit written to ./oom-2ac893c3f1a8262206d60b0b9de08e40c2c83944 Step #5: Base64: ESMiXFBcUFxQXFBcUFxQXFBcUCI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2157 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2772744272 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e90df54810, 0x55e90e13e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e90e13e020,0x55e90ffd60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2ac893c3f1a8262206d60b0b9de08e40c2c83944' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2558 processed earlier; will process 8471 files now Step #5: ==77686== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e904a499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e90b0ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e90b0915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e90b0914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e904a4fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e9049b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e9049ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e904a41c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e907a10f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e907a10f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e907a10f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e907a10f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e907a10f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e907a10f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e907a10f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e907a10f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e907a10f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e907a10f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e909ca5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e9069d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e9069ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e906789c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e906789c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e90678a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e906789874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e906789874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e906789874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e90b093abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e90b09c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e90b084699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e90b0af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd336e51082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e9049a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3c,0x75,0x6a,0x75,0x75,0x75,0x75,0x6a,0x75,0x6a,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x3e, Step #5: (? Step #5: artifact_prefix='./'; Test unit written to ./oom-d866e7b05e4d9bc36a3290fba7a3c6023e49e16a Step #5: Base64: KD88dWp1dXV1anVqdXV1dXV1dT4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2158 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2773207981 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640a51c4810, 0x5640a53ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640a53ae020,0x5640a72460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d866e7b05e4d9bc36a3290fba7a3c6023e49e16a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2559 processed earlier; will process 8470 files now Step #5: ==77722== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56409bcb99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5640a231e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640a23015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640a23014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56409bcbfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56409bc20b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56409bc1b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56409bcb1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56409ec80f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56409ec80f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56409ec80f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56409ec80f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56409ec80f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56409ec80f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56409ec80f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56409ec80f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56409ec80f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56409ec80f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5640a0f15f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56409dc42b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56409dc4dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56409d9f9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56409d9f9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56409d9fa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56409d9f9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56409d9f9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56409d9f9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5640a2303abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5640a230c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5640a22f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5640a231f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d9f7fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56409bc19b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdc,0x8c,0xe,0x27,0x9,0xdc,0x8c,0xe,0x27,0x9,0x0,0xa,0xe,0x27,0x0,0xa,0xe,0x27,0x9,0x30, Step #5: \334\214\016'\011\334\214\016'\011\000\012\016'\000\012\016'\0110 Step #5: artifact_prefix='./'; Test unit written to ./oom-2881e88f971b23acfa90febc1a0dd038a46de4c0 Step #5: Base64: 3IwOJwncjA4nCQAKDicACg4nCTA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2159 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2773670064 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5629dc03d810, 0x5629dc22701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5629dc227020,0x5629de0bf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2881e88f971b23acfa90febc1a0dd038a46de4c0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2560 processed earlier; will process 8469 files now Step #5: ==77758== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5629d2b329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5629d9197898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5629d917a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5629d917a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5629d2b38d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629d2a99b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629d2a94355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5629d2b2ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5629d5af9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5629d5af9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5629d5af9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5629d5af9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5629d5af9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5629d5af9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5629d5af9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5629d5af9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5629d5af9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5629d5af9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5629d7d8ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629d4abbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629d4ac6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629d4872c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629d4872c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629d4873738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629d4872874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629d4872874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629d4872874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5629d917cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5629d9185928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5629d916d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5629d9198112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc955c38082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629d2a92b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0xa8,0xf0,0x9d,0x85,0xa8,0xf0,0x9d,0x85,0xa8,0xf0,0x9d,0x85,0xa8,0xf0,0x9d,0x85,0xa8,0xcd,0x80, Step #5: \315\250\360\235\205\250\360\235\205\250\360\235\205\250\360\235\205\250\315\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-d4bd08cf0dfbdc0c5258b3157cb5eb80b4f7d6ad Step #5: Base64: zajwnYWo8J2FqPCdhajwnYWozYA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2160 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2774133718 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640670d4810, 0x5640672be01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640672be020,0x5640691560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d4bd08cf0dfbdc0c5258b3157cb5eb80b4f7d6ad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2561 processed earlier; will process 8468 files now Step #5: ==77794== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56405dbc99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56406422e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640642115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640642114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56405dbcfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56405db30b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56405db2b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56405dbc1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564060b90f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564060b90f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564060b90f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564060b90f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564060b90f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564060b90f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564060b90f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564060b90f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564060b90f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564060b90f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564062e25f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56405fb52b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56405fb5dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56405f909c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56405f909c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56405f90a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56405f909874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56405f909874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56405f909874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564064213abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56406421c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564064204699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56406422f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf1e5f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56405db29b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x3,0x0,0x20,0x1,0x11,0x47,0x0,0x54,0x49,0x54,0x31,0x0,0x68,0x68,0x43,0xda,0x0, Step #5: ID3\003\000 \001\021G\000TIT1\000hhC\332\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0e17f62b20819e86618e63a974bd0f8ca65aae11 Step #5: Base64: SUQzAwAgARFHAFRJVDEAaGhD2gA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2161 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2774601499 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56056e597810, 0x56056e78101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56056e781020,0x5605706190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0e17f62b20819e86618e63a974bd0f8ca65aae11' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2562 processed earlier; will process 8467 files now Step #5: #1 pulse cov: 3667 ft: 3668 exec/s: 0 rss: 169Mb Step #5: ==77830== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56056508c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56056b6f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56056b6d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56056b6d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560565092d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560564ff3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560564fee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560565084c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560568053f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560568053f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560568053f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560568053f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560568053f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560568053f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560568053f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560568053f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560568053f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560568053f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56056a2e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560567015b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560567020be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560566dccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560566dccc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560566dcd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560566dcc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560566dcc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560566dcc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56056b6d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56056b6df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56056b6c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56056b6f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0209df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560564fecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x68,0xa,0x68,0x6d,0x74,0x78,0x61,0x61,0x61,0x61,0xa7,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x6d, Step #5: \012h\012hmtxaaaa\247aaaaaaam Step #5: artifact_prefix='./'; Test unit written to ./oom-a7d10c2d5658639955a0ee635e8d55fa6a7d3693 Step #5: Base64: CmgKaG10eGFhYWGnYWFhYWFhYW0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2162 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2775109973 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5625f43c7810, 0x5625f45b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625f45b1020,0x5625f64490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a7d10c2d5658639955a0ee635e8d55fa6a7d3693' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2564 processed earlier; will process 8465 files now Step #5: ==77866== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5625eaebc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5625f1521898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625f15045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625f15044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5625eaec2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625eae23b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625eae1e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5625eaeb4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5625ede83f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5625ede83f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5625ede83f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5625ede83f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5625ede83f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5625ede83f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5625ede83f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5625ede83f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5625ede83f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5625ede83f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5625f0118f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625ece45b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5625ece50be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5625ecbfcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5625ecbfcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5625ecbfd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5625ecbfc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5625ecbfc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5625ecbfc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5625f1506abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5625f150f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5625f14f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5625f1522112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7dba8ad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625eae1cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x51,0x31,0x32,0x5c,0x31,0xe1,0x9f,0xa3,0xe1,0x9e,0xa3,0x2f,0x78,0x28,0x3f,0x30,0x91,0x31,0x5d, Step #5: MQ12\\1\341\237\243\341\236\243/x(?0\2211] Step #5: artifact_prefix='./'; Test unit written to ./oom-affbebda7d435d0786de16269843a834e2ad300e Step #5: Base64: TVExMlwx4Z+j4Z6jL3goPzCRMV0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2163 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2775574870 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557cf1831810, 0x557cf1a1b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557cf1a1b020,0x557cf38b30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/affbebda7d435d0786de16269843a834e2ad300e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2565 processed earlier; will process 8464 files now Step #5: ==77906== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557ce83269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557cee98b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557cee96e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557cee96e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557ce832cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557ce828db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557ce8288355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557ce831ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557ceb2edf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557ceb2edf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557ceb2edf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557ceb2edf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557ceb2edf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557ceb2edf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557ceb2edf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557ceb2edf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557ceb2edf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557ceb2edf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557ced582f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557cea2afb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557cea2babe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557cea066c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557cea066c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557cea067738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557cea066874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557cea066874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557cea066874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557cee970abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557cee979928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557cee961699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557cee98c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fee28598082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557ce8286b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0xcd,0x8f,0xa,0xf0,0x9d,0x9f,0x95,0xa,0x6e,0x2d,0x9d,0x95,0x2d,0x9f,0xa,0xcd,0x2d, Step #5: ---\315\217\012\360\235\237\225\012n-\235\225-\237\012\315- Step #5: artifact_prefix='./'; Test unit written to ./oom-183ffd0b3a603cf6fe41dd8be33bec3db877faf4 Step #5: Base64: LS0tzY8K8J2flQpuLZ2VLZ8KzS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2164 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2776034406 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a7cc97810, 0x558a7ce8101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a7ce81020,0x558a7ed190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/183ffd0b3a603cf6fe41dd8be33bec3db877faf4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2566 processed earlier; will process 8463 files now Step #5: ==77942== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558a7378c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a79df1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a79dd45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a79dd44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a73792d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a736f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a736ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a73784c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a76753f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a76753f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a76753f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a76753f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a76753f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a76753f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a76753f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a76753f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a76753f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a76753f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a789e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a75715b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a75720be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a754ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a754ccc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a754cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a754cc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a754cc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a754cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a79dd6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a79ddf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a79dc7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a79df2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e869a2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a736ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4e,0x7a,0x4d,0x35,0x4d,0x6a,0x41,0x30,0x4d,0x54,0x4d,0x33,0x4d,0x57,0x55,0x79,0x4d,0x31,0x2e,0x2e, Step #5: NzM5MjA0MTM3MWUyM1.. Step #5: artifact_prefix='./'; Test unit written to ./oom-c7a2bd38ac725a53422db900eb66d1858cf811d5 Step #5: Base64: TnpNNU1qQTBNVE0zTVdVeU0xLi4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2165 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2776491600 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55adca47b810, 0x55adca66501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55adca665020,0x55adcc4fd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c7a2bd38ac725a53422db900eb66d1858cf811d5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2567 processed earlier; will process 8462 files now Step #5: ==77978== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55adc0f709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55adc75d5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55adc75b85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55adc75b84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55adc0f76d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55adc0ed7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55adc0ed2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55adc0f68c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55adc3f37f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55adc3f37f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55adc3f37f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55adc3f37f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55adc3f37f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55adc3f37f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55adc3f37f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55adc3f37f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55adc3f37f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55adc3f37f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55adc61ccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55adc2ef9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55adc2f04be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55adc2cb0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55adc2cb0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55adc2cb1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55adc2cb0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55adc2cb0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55adc2cb0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55adc75baabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55adc75c3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55adc75ab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55adc75d6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4e27aea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55adc0ed0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xed,0x88,0x87,0xcd,0x8f,0xec,0x88,0x87,0xcd,0x8f,0xed,0x88,0x87,0xcd,0x8f,0xed,0x88,0x87,0xcd,0x8f, Step #5: \355\210\207\315\217\354\210\207\315\217\355\210\207\315\217\355\210\207\315\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-eec680296d07d2a1ec2bed3a077de19fa313f7a0 Step #5: Base64: 7YiHzY/siIfNj+2Ih82P7YiHzY8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2166 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2776953501 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56232e1f8810, 0x56232e3e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56232e3e2020,0x56233027a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eec680296d07d2a1ec2bed3a077de19fa313f7a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2568 processed earlier; will process 8461 files now Step #5: ==78014== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562324ced9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56232b352898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56232b3355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56232b3354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562324cf3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562324c54b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562324c4f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562324ce5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562327cb4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562327cb4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562327cb4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562327cb4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562327cb4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562327cb4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562327cb4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562327cb4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562327cb4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562327cb4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562329f49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562326c76b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562326c81be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562326a2dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562326a2dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562326a2e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562326a2d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562326a2d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562326a2d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56232b337abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56232b340928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56232b328699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56232b353112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f09056fd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562324c4db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4f,0x3a,0x53,0x2d,0x31,0x2d,0x30,0x78,0x46,0x46,0x46,0x46,0x46,0x46,0x46,0x46,0x46,0x42,0x42,0x45, Step #5: O:S-1-0xFFFFFFFFFBBE Step #5: artifact_prefix='./'; Test unit written to ./oom-6d0747f370b44449304155ccb388c62c0ee70b5d Step #5: Base64: TzpTLTEtMHhGRkZGRkZGRkZCQkU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2167 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2777418430 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556594537810, 0x55659472101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556594721020,0x5565965b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6d0747f370b44449304155ccb388c62c0ee70b5d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2569 processed earlier; will process 8460 files now Step #5: ==78050== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55658b02c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556591691898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5565916745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5565916744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55658b032d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55658af93b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55658af8e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55658b024c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55658dff3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55658dff3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55658dff3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55658dff3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55658dff3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55658dff3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55658dff3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55658dff3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55658dff3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55658dff3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556590288f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55658cfb5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55658cfc0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55658cd6cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55658cd6cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55658cd6d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55658cd6c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55658cd6c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55658cd6c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556591676abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55659167f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556591667699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556591692112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3bedc60082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55658af8cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcc,0xbf,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0x93, Step #5: \314\277\314\264\314\264\314\264\314\264\314\264\314\264\314\264\314\264\314\223 Step #5: artifact_prefix='./'; Test unit written to ./oom-b8cc7a2c804199cc221c327f2231fba344357eae Step #5: Base64: zL/MtMy0zLTMtMy0zLTMtMy0zJM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2168 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2777881583 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5642cd766810, 0x5642cd95001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5642cd950020,0x5642cf7e80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b8cc7a2c804199cc221c327f2231fba344357eae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2570 processed earlier; will process 8459 files now Step #5: ==78086== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5642c425b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5642ca8c0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5642ca8a35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5642ca8a34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642c4261d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5642c41c2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5642c41bd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5642c4253c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5642c7222f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5642c7222f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5642c7222f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5642c7222f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5642c7222f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5642c7222f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5642c7222f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5642c7222f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5642c7222f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5642c7222f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5642c94b7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5642c61e4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5642c61efbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5642c5f9bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5642c5f9bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5642c5f9c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5642c5f9b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5642c5f9b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5642c5f9b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5642ca8a5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5642ca8ae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5642ca896699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5642ca8c1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6a30760082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5642c41bbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x10,0xf0,0x92,0x85,0xb2,0xf0,0x91,0x84,0xb2,0xf0,0x93,0x83,0xa2,0xf0,0x93,0x83,0xa2, Step #5: \000\000\000\020\360\222\205\262\360\221\204\262\360\223\203\242\360\223\203\242 Step #5: artifact_prefix='./'; Test unit written to ./oom-861241947a6aed463b665e5797fd5ff68b876cf9 Step #5: Base64: AAAAEPCShbLwkYSy8JODovCTg6I= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2169 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2778344865 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb606d3810, 0x55cb608bd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb608bd020,0x55cb627550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/861241947a6aed463b665e5797fd5ff68b876cf9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2571 processed earlier; will process 8458 files now Step #5: ==78122== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cb571c89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb5d82d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb5d8105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb5d8104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb571ced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb5712fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb5712a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb571c0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb5a18ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb5a18ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb5a18ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb5a18ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb5a18ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb5a18ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb5a18ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb5a18ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb5a18ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb5a18ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb5c424f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb59151b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb5915cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb58f08c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb58f08c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb58f09738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb58f08874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb58f08874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb58f08874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb5d812abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb5d81b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb5d803699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb5d82e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f42d0d45082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb57128b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4b,0x44,0x45,0x4f,0x42,0xec,0xfe,0x0,0xfe,0xf8,0x0,0x65,0x7e,0xe4,0x61,0x72,0x69,0x3d,0x7e,0xe4, Step #5: KDEOB\354\376\000\376\370\000e~\344ari=~\344 Step #5: artifact_prefix='./'; Test unit written to ./oom-9d89daaebfeb96e318f2e83420f50746a3401780 Step #5: Base64: S0RFT0Ls/gD++ABlfuRhcmk9fuQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2170 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2778802736 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a36b1c2810, 0x55a36b3ac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a36b3ac020,0x55a36d2440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9d89daaebfeb96e318f2e83420f50746a3401780' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2572 processed earlier; will process 8457 files now Step #5: ==78158== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a361cb79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a36831c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3682ff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3682ff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a361cbdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a361c1eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a361c19355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a361cafc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a364c7ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a364c7ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a364c7ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a364c7ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a364c7ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a364c7ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a364c7ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a364c7ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a364c7ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a364c7ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a366f13f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a363c40b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a363c4bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3639f7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3639f7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3639f8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3639f7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3639f7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3639f7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a368301abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a36830a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3682f2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a36831d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6510d87082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a361c17b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x0,0x5b,0x5b,0x27,0x13,0x0,0x0,0x0,0x27,0x5d,0x5b,0x28,0x5d,0x5b,0x27,0x5d,0x5b,0x28,0x0, Step #5: 0\000[['\023\000\000\000'][(]['][(\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0180023cb5f11410c56dde5e038ce6ebb047f68e Step #5: Base64: MABbWycTAAAAJ11bKF1bJ11bKAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2171 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2779264699 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a01c13a810, 0x55a01c32401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a01c324020,0x55a01e1bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0180023cb5f11410c56dde5e038ce6ebb047f68e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2573 processed earlier; will process 8456 files now Step #5: ==78194== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a012c2f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a019294898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0192775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0192774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a012c35d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a012b96b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a012b91355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a012c27c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a015bf6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a015bf6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a015bf6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a015bf6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a015bf6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a015bf6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a015bf6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a015bf6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a015bf6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a015bf6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a017e8bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a014bb8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a014bc3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a01496fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a01496fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a014970738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a01496f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a01496f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a01496f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a019279abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a019282928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a01926a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a019295112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4cd823f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a012b8fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x31,0x5c,0x28,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0xf8,0x35, Step #5: ^1\\(______________\3705 Step #5: artifact_prefix='./'; Test unit written to ./oom-1dc7b1782df1227db7a69d51b1a372cb1b5bc8ba Step #5: Base64: XjFcKF9fX19fX19fX19fX19f+DU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2172 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2779727660 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bba967f810, 0x55bba986901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bba9869020,0x55bbab7010e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1dc7b1782df1227db7a69d51b1a372cb1b5bc8ba' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2574 processed earlier; will process 8455 files now Step #5: #1 pulse cov: 3771 ft: 3772 exec/s: 0 rss: 168Mb Step #5: ==78230== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bba01749c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bba67d9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bba67bc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bba67bc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bba017ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bba00dbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bba00d6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bba016cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bba313bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bba313bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bba313bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bba313bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bba313bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bba313bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bba313bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bba313bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bba313bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bba313bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bba53d0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bba20fdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bba2108be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bba1eb4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bba1eb4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bba1eb5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bba1eb4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bba1eb4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bba1eb4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bba67beabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bba67c7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bba67af699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bba67da112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f89d68cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bba00d4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xd5,0x8c,0x2d,0x41,0x3b,0x41,0x2d,0x4b,0x24,0x41,0x2d,0x41,0x3b,0x47,0x2c,0x4f,0x24, Step #5: ws:\325\214-A;A-K$A-A;G,O$ Step #5: artifact_prefix='./'; Test unit written to ./oom-b6bef490b1b41b0c4640667428d50e46bdc827ef Step #5: Base64: d3M61YwtQTtBLUskQS1BO0csTyQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2173 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2780229552 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561cf6e21810, 0x561cf700b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561cf700b020,0x561cf8ea30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b6bef490b1b41b0c4640667428d50e46bdc827ef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2576 processed earlier; will process 8453 files now Step #5: ==78266== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561ced9169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561cf3f7b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561cf3f5e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561cf3f5e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561ced91cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561ced87db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561ced878355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561ced90ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561cf08ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561cf08ddf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561cf08ddf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561cf08ddf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561cf08ddf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561cf08ddf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561cf08ddf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561cf08ddf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561cf08ddf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561cf08ddf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561cf2b72f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561cef89fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561cef8aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561cef656c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561cef656c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561cef657738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561cef656874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561cef656874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561cef656874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561cf3f60abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561cf3f69928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561cf3f51699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561cf3f7c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f19dca63082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561ced876b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x3,0x0,0x1,0x4,0x3,0x2,0x4,0x3,0x1,0x2,0x0,0x1,0x4,0x3,0x2,0x4,0x0,0x1,0x2, Step #5: \000\003\000\001\004\003\002\004\003\001\002\000\001\004\003\002\004\000\001\002 Step #5: artifact_prefix='./'; Test unit written to ./oom-b69a1f1c7e1e4318e12bf7f2793dbefa625f962e Step #5: Base64: AAMAAQQDAgQDAQIAAQQDAgQAAQI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2174 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2780689357 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd4addd810, 0x55dd4afc701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd4afc7020,0x55dd4ce5f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b69a1f1c7e1e4318e12bf7f2793dbefa625f962e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2577 processed earlier; will process 8452 files now Step #5: #1 pulse cov: 3744 ft: 3745 exec/s: 0 rss: 169Mb Step #5: ==78302== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dd418d29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd47f37898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd47f1a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd47f1a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dd418d8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dd41839b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dd41834355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dd418cac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd44899f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd44899f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd44899f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd44899f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd44899f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd44899f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd44899f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd44899f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd44899f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd44899f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd46b2ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dd4385bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dd43866be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dd43612c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dd43612c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dd43613738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dd43612874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dd43612874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dd43612874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd47f1cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd47f25928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd47f0d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd47f38112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc3e63fe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dd41832b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x73,0x0,0x73,0x63,0x65,0x6e,0x74,0x20,0x0,0x44,0x65,0x6e,0xe2,0x81,0x9f,0x4d,0xf6,0xff,0x7f, Step #5: ps\000scent \000Den\342\201\237M\366\377\177 Step #5: artifact_prefix='./'; Test unit written to ./oom-ea7d07d8067084573214d04c00cc16e98879ef38 Step #5: Base64: cHMAc2NlbnQgAERlbuKBn032/38= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2175 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2781195269 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5624778f8810, 0x562477ae201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562477ae2020,0x56247997a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ea7d07d8067084573214d04c00cc16e98879ef38' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2579 processed earlier; will process 8450 files now Step #5: ==78338== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56246e3ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562474a52898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562474a355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562474a354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56246e3f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56246e354b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56246e34f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56246e3e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5624713b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5624713b4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5624713b4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5624713b4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5624713b4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5624713b4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5624713b4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5624713b4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5624713b4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5624713b4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562473649f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562470376b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562470381be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56247012dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56247012dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56247012e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56247012d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56247012d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56247012d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562474a37abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562474a40928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562474a28699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562474a53112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f691c793082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56246e34db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xa,0xd8,0x80,0x4,0x0,0x0,0xa,0x2d,0x20,0x0,0x7e,0x3a,0xd8,0x80,0x0,0x1,0x0,0x0,0x20, Step #5: \000\012\330\200\004\000\000\012- \000~:\330\200\000\001\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aa514ef15822da56c3aa525b3ad64f550b805527 Step #5: Base64: AArYgAQAAAotIAB+OtiAAAEAACA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2176 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2781659333 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1f67f0810, 0x55d1f69da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1f69da020,0x55d1f88720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aa514ef15822da56c3aa525b3ad64f550b805527' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2580 processed earlier; will process 8449 files now Step #5: #1 pulse cov: 3720 ft: 3721 exec/s: 0 rss: 167Mb Step #5: ==78374== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d1ed2e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1f394a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1f392d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1f392d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1ed2ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1ed24cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1ed247355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1ed2ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1f02acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1f02acf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1f02acf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1f02acf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1f02acf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1f02acf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1f02acf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1f02acf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1f02acf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1f02acf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1f2541f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1ef26eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1ef279be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1ef025c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1ef025c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1ef026738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1ef025874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1ef025874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1ef025874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1f392fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1f3938928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1f3920699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1f394b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb05a88082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1ed245b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6d,0x20,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0x20,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0x20,0xc2,0xa0, Step #5: m \302\240\302\240\302\240\302\240 \302\240\302\240\302\240 \302\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-47668854d5e0dc966cd062dd073c2e4b31b132c2 Step #5: Base64: bSDCoMKgwqDCoCDCoMKgwqAgwqA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2177 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2782159129 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563f131cc810, 0x563f133b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563f133b6020,0x563f1524e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/47668854d5e0dc966cd062dd073c2e4b31b132c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2582 processed earlier; will process 8447 files now Step #5: ==78410== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563f09cc19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563f10326898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563f103095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563f103094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563f09cc7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563f09c28b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563f09c23355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563f09cb9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563f0cc88f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563f0cc88f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563f0cc88f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563f0cc88f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563f0cc88f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563f0cc88f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563f0cc88f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563f0cc88f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563f0cc88f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563f0cc88f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563f0ef1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563f0bc4ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563f0bc55be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563f0ba01c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563f0ba01c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563f0ba02738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563f0ba01874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563f0ba01874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563f0ba01874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563f1030babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563f10314928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563f102fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563f10327112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7eff68c9a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563f09c21b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x51,0x31,0x32,0x5c,0x31,0xe1,0x9f,0xa3,0xe1,0x9f,0xa3,0x2f,0x78,0x28,0x3f,0x30,0x91,0x31,0x5d, Step #5: MQ12\\1\341\237\243\341\237\243/x(?0\2211] Step #5: artifact_prefix='./'; Test unit written to ./oom-f44d4e06b990fedb814f1946c8e51ab680198c24 Step #5: Base64: TVExMlwx4Z+j4Z+jL3goPzCRMV0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2178 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2782621778 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d06eec6810, 0x55d06f0b001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d06f0b0020,0x55d070f480e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f44d4e06b990fedb814f1946c8e51ab680198c24' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2583 processed earlier; will process 8446 files now Step #5: ==78446== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d0659bb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d06c020898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d06c0035dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d06c0034fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d0659c1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d065922b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d06591d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d0659b3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d068982f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d068982f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d068982f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d068982f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d068982f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d068982f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d068982f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d068982f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d068982f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d068982f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d06ac17f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d067944b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d06794fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d0676fbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d0676fbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d0676fc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d0676fb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d0676fb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d0676fb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d06c005abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d06c00e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d06bff6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d06c021112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe010be7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d06591bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x7,0xef,0xad,0xbf,0xef,0xbc,0xbb,0x79,0x7d,0xe1,0xff,0xff,0xf9,0xff,0x4b,0x9,0x3d, Step #5: \000\000\000\007\357\255\277\357\274\273y}\341\377\377\371\377K\011= Step #5: artifact_prefix='./'; Test unit written to ./oom-72ca073d94a95ece92193e2bdf8e64947c38a521 Step #5: Base64: AAAAB++tv++8u3l94f//+f9LCT0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2179 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2783084470 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe80863810, 0x55fe80a4d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe80a4d020,0x55fe828e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/72ca073d94a95ece92193e2bdf8e64947c38a521' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2584 processed earlier; will process 8445 files now Step #5: #1 pulse cov: 3586 ft: 3587 exec/s: 0 rss: 170Mb Step #5: ==78482== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fe773589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe7d9bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe7d9a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe7d9a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe7735ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe772bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe772ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe77350c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe7a31ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe7a31ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe7a31ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe7a31ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe7a31ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe7a31ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe7a31ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe7a31ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe7a31ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe7a31ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe7c5b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe792e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe792ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe79098c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe79098c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe79099738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe79098874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe79098874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe79098874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe7d9a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe7d9ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe7d993699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe7d9be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ddc5d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe772b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x65,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3d,0x22,0x4a,0x50,0x22,0x50, Step #5: Step #5: Step #5: #0 0x557f483f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f4ea59898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f4ea3c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f4ea3c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f483fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f4835bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f48356355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f483ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f4b3bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f4b3bbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f4b3bbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f4b3bbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f4b3bbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f4b3bbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f4b3bbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f4b3bbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f4b3bbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f4b3bbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f4d650f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f4a37db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f4a388be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f4a134c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f4a134c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f4a135738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f4a134874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f4a134874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f4a134874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f4ea3eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f4ea47928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f4ea2f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f4ea5a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe6f57a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f48354b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x27,0x3c,0x3c,0x7b,0x27,0x3c,0x7b,0x7b,0x27,0x3c,0x3c,0x7b,0x27,0x3c,0x7b,0x27,0x3c,0x2c,0x7b, Step #5: {'<<{'<{{'<<{'<{'<,{ Step #5: artifact_prefix='./'; Test unit written to ./oom-1bcfb011a792215876f2876d7ef1a53bfd4472cc Step #5: Base64: eyc8PHsnPHt7Jzw8eyc8eyc8LHs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2181 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2784125948 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5566148b7810, 0x556614aa101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556614aa1020,0x5566169390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1bcfb011a792215876f2876d7ef1a53bfd4472cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2589 processed earlier; will process 8440 files now Step #5: ==78554== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55660b3ac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556611a11898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5566119f45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5566119f44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55660b3b2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55660b313b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55660b30e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55660b3a4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55660e373f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55660e373f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55660e373f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55660e373f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55660e373f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55660e373f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55660e373f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55660e373f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55660e373f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55660e373f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556610608f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55660d335b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55660d340be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55660d0ecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55660d0ecc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55660d0ed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55660d0ec874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55660d0ec874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55660d0ec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5566119f6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5566119ff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5566119e7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556611a12112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0255d85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55660b30cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xc,0x0,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0xff,0x0, Step #5: -\014\000oooooooo\000\000\000\000\000\000\002\377\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-70fabd6dc689c9890637ccd9187f77be23ec4cff Step #5: Base64: LQwAb29vb29vb28AAAAAAAAC/wA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2182 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2784587582 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dbbd287810, 0x55dbbd47101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dbbd471020,0x55dbbf3090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70fabd6dc689c9890637ccd9187f77be23ec4cff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2590 processed earlier; will process 8439 files now Step #5: #1 pulse cov: 3652 ft: 3653 exec/s: 0 rss: 169Mb Step #5: ==78590== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dbb3d7c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dbba3e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dbba3c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dbba3c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dbb3d82d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dbb3ce3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dbb3cde355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dbb3d74c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dbb6d43f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dbb6d43f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dbb6d43f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dbb6d43f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dbb6d43f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dbb6d43f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dbb6d43f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dbb6d43f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dbb6d43f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dbb6d43f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dbb8fd8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dbb5d05b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dbb5d10be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dbb5abcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dbb5abcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dbb5abd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dbb5abc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dbb5abc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dbb5abc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dbba3c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dbba3cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dbba3b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dbba3e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a641ab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dbb3cdcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x38,0x30,0x36,0x2e, Step #5: 9223372036854775806. Step #5: artifact_prefix='./'; Test unit written to ./oom-b1fd4ece36c7592038bb8163599c077c734b4a10 Step #5: Base64: OTIyMzM3MjAzNjg1NDc3NTgwNi4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2183 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2785097862 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56339e5be810, 0x56339e7a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56339e7a8020,0x5633a06400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b1fd4ece36c7592038bb8163599c077c734b4a10' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2592 processed earlier; will process 8437 files now Step #5: #1 pulse cov: 3565 ft: 3566 exec/s: 0 rss: 167Mb Step #5: ==78626== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5633950b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56339b718898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56339b6fb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56339b6fb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5633950b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56339501ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563395015355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5633950abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56339807af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56339807af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56339807af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56339807af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56339807af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56339807af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56339807af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56339807af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56339807af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56339807af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56339a30ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56339703cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563397047be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563396df3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563396df3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563396df4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563396df3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563396df3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563396df3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56339b6fdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56339b706928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56339b6ee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56339b719112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa771713082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563395013b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7a,0x3c,0xdb,0xbe,0x7e,0x34,0x7e,0x3c,0xdb,0xbe,0x7e,0x34,0x2c,0xbe,0xbe,0x3e,0x21,0x2c,0xbe,0x7e, Step #5: z<\333\276~4~<\333\276~4,\276\276>!,\276~ Step #5: artifact_prefix='./'; Test unit written to ./oom-4c5cf0388b2f5b5292557c19f2d9cef8dadf3a80 Step #5: Base64: ejzbvn40fjzbvn40LL6+PiEsvn4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2184 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2785600089 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557892fee810, 0x5578931d801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5578931d8020,0x5578950700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4c5cf0388b2f5b5292557c19f2d9cef8dadf3a80' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2594 processed earlier; will process 8435 files now Step #5: ==78662== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557889ae39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557890148898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55789012b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55789012b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557889ae9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557889a4ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557889a45355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557889adbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55788caaaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55788caaaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55788caaaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55788caaaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55788caaaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55788caaaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55788caaaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55788caaaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55788caaaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55788caaaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55788ed3ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55788ba6cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55788ba77be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55788b823c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55788b823c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55788b824738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55788b823874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55788b823874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55788b823874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55789012dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557890136928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55789011e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557890149112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f64cd28f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557889a43b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x2d,0x2d,0x2d,0x32,0x45,0x2d,0x47,0x42,0x49,0x4e,0x20,0x2d,0x2d,0x27,0x2d,0x2d,0xa,0x2d,0xd3, Step #5: ---2E-GBIN --'--\012-\323 Step #5: artifact_prefix='./'; Test unit written to ./oom-a93dc797480d69ce795cf1ab9e4d599deda4fe01 Step #5: Base64: IC0tLTJFLUdCSU4gLS0nLS0KLdM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2185 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2786067000 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b002818810, 0x55b002a0201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b002a02020,0x55b00489a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a93dc797480d69ce795cf1ab9e4d599deda4fe01' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2595 processed earlier; will process 8434 files now Step #5: #1 pulse cov: 3592 ft: 3593 exec/s: 0 rss: 168Mb Step #5: ==78698== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55aff930d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55afff972898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55afff9555dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55afff9554fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aff9313d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aff9274b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aff926f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aff9305c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55affc2d4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55affc2d4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55affc2d4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55affc2d4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55affc2d4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55affc2d4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55affc2d4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55affc2d4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55affc2d4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55affc2d4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55affe569f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55affb296b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55affb2a1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55affb04dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55affb04dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55affb04e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55affb04d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55affb04d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55affb04d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55afff957abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55afff960928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55afff948699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55afff973112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ac4ad9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aff926db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x45,0x78,0x65,0x63,0x5d,0xa,0x4c,0x69,0x6d,0x69,0x74,0x43,0x50,0x55,0x3d,0x2e,0x30,0x34,0x39, Step #5: [Exec]\012LimitCPU=.049 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8c56219edc93d5c468804e99ccc726459b24eb2 Step #5: Base64: W0V4ZWNdCkxpbWl0Q1BVPS4wNDk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2186 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2786571317 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563905ed0810, 0x5639060ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5639060ba020,0x563907f520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8c56219edc93d5c468804e99ccc726459b24eb2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2597 processed earlier; will process 8432 files now Step #5: ==78734== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5638fc9c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56390302a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56390300d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56390300d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5638fc9cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5638fc92cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5638fc927355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5638fc9bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5638ff98cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5638ff98cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5638ff98cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5638ff98cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5638ff98cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5638ff98cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5638ff98cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5638ff98cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5638ff98cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5638ff98cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563901c21f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5638fe94eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5638fe959be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5638fe705c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5638fe705c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5638fe706738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5638fe705874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5638fe705874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5638fe705874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56390300fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563903018928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563903000699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56390302b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f57692a9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5638fc925b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x7b,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57, Step #5: f{WWWWWWWWWWWWWWWWWW Step #5: artifact_prefix='./'; Test unit written to ./oom-88812db5f4425965a1ca9c99382114c2295a8590 Step #5: Base64: ZntXV1dXV1dXV1dXV1dXV1dXV1c= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2187 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2787033589 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5654419c4810, 0x565441bae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565441bae020,0x565443a460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88812db5f4425965a1ca9c99382114c2295a8590' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2598 processed earlier; will process 8431 files now Step #5: ==78770== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5654384b99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56543eb1e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56543eb015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56543eb014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5654384bfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565438420b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56543841b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5654384b1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56543b480f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56543b480f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56543b480f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56543b480f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56543b480f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56543b480f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56543b480f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56543b480f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56543b480f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56543b480f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56543d715f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56543a442b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56543a44dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56543a1f9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56543a1f9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56543a1fa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56543a1f9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56543a1f9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56543a1f9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56543eb03abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56543eb0c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56543eaf4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56543eb1f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2fa972b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565438419b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x53,0x3a,0xe3,0x8c,0x96,0xcd,0x84,0xcd,0x96,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: wS:\343\214\226\315\204\315\226\315\204\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-c6eac8c3b05cd46574c29fca8c04b5f4de15a9ae Step #5: Base64: d1M644yWzYTNls2EzYTNhM2EzYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2188 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2787497619 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562620bf4810, 0x562620dde01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562620dde020,0x562622c760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c6eac8c3b05cd46574c29fca8c04b5f4de15a9ae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2599 processed earlier; will process 8430 files now Step #5: ==78806== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5626176e99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56261dd4e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56261dd315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56261dd314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5626176efd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562617650b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56261764b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5626176e1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56261a6b0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56261a6b0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56261a6b0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56261a6b0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56261a6b0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56261a6b0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56261a6b0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56261a6b0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56261a6b0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56261a6b0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56261c945f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562619672b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56261967dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562619429c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562619429c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56261942a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562619429874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562619429874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562619429874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56261dd33abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56261dd3c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56261dd24699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56261dd4f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7effcaab4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562617649b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0xa,0xa,0x2d,0x20,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x24,0x24,0xa,0x2d,0x20, Step #5: x--\012\012- GIN ----$$\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-c85410282e108279cb8071b8ac14c2d456cfb0f3 Step #5: Base64: eC0tCgotIEdJTiAtLS0tJCQKLSA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2189 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2787961997 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558415ecf810, 0x5584160b901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5584160b9020,0x558417f510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c85410282e108279cb8071b8ac14c2d456cfb0f3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2600 processed earlier; will process 8429 files now Step #5: ==78842== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55840c9c49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558413029898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55841300c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55841300c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55840c9cad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55840c92bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55840c926355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55840c9bcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55840f98bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55840f98bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55840f98bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55840f98bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55840f98bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55840f98bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55840f98bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55840f98bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55840f98bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55840f98bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558411c20f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55840e94db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55840e958be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55840e704c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55840e704c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55840e705738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55840e704874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55840e704874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55840e704874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55841300eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558413017928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558412fff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55841302a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa8abcc7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55840c924b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0xa,0x24,0x7e,0x8,0x24,0x2d,0x2b,0x24,0x2d,0x2b,0x24,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x9c, Step #5: ~\012$~\010$-+$-+$\377\377\377\377\377\377\377\234 Step #5: artifact_prefix='./'; Test unit written to ./oom-d722996e1a87d094b062b53c4db28c21b6e18724 Step #5: Base64: fgokfggkLSskLSsk/////////5w= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2190 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2788428696 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ba238cd810, 0x55ba23ab701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ba23ab7020,0x55ba2594f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d722996e1a87d094b062b53c4db28c21b6e18724' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2601 processed earlier; will process 8428 files now Step #5: ==78878== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ba1a3c29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ba20a27898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ba20a0a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ba20a0a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ba1a3c8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ba1a329b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ba1a324355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ba1a3bac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ba1d389f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ba1d389f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ba1d389f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ba1d389f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ba1d389f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ba1d389f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ba1d389f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ba1d389f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ba1d389f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ba1d389f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ba1f61ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ba1c34bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ba1c356be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ba1c102c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ba1c102c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ba1c103738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ba1c102874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ba1c102874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ba1c102874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ba20a0cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ba20a15928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ba209fd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ba20a28112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc671058082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ba1a322b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x2b,0xa,0xa,0x2b,0xa,0x2b,0xdc, Step #5: +\012+\012+\012++\012\012+\012++\012\012+\012+\334 Step #5: artifact_prefix='./'; Test unit written to ./oom-7d6881a0fe5fd9b0c81de1e95e18426ee0a3b0ab Step #5: Base64: KworCisKKysKCisKKysKCisKK9w= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2191 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2788899946 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c4c578810, 0x561c4c76201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c4c762020,0x561c4e5fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d6881a0fe5fd9b0c81de1e95e18426ee0a3b0ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2602 processed earlier; will process 8427 files now Step #5: ==78914== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561c4306d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c496d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c496b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c496b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c43073d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c42fd4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c42fcf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c43065c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c46034f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c46034f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c46034f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c46034f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c46034f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c46034f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c46034f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c46034f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c46034f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c46034f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c482c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c44ff6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c45001be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c44dadc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c44dadc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c44dae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c44dad874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c44dad874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c44dad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c496b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c496c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c496a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c496d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c30425082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c42fcdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x3a,0x28,0x30,0x2e,0xd,0x31,0x2e,0xd,0x30,0x2e,0xd,0x36,0x2e,0x7b, Step #5: $3::{$:(0.\0151.\0150.\0156.{ Step #5: artifact_prefix='./'; Test unit written to ./oom-ab168f04e41e5262f79fdc4dca5b193ed3828502 Step #5: Base64: JDM6OnskOigwLg0xLg0wLg02Lns= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2192 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2789376576 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5563d84d0810, 0x5563d86ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5563d86ba020,0x5563da5520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ab168f04e41e5262f79fdc4dca5b193ed3828502' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2603 processed earlier; will process 8426 files now Step #5: ==78950== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5563cefc59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5563d562a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5563d560d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5563d560d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5563cefcbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5563cef2cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5563cef27355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5563cefbdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5563d1f8cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5563d1f8cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5563d1f8cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5563d1f8cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5563d1f8cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5563d1f8cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5563d1f8cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5563d1f8cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5563d1f8cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5563d1f8cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5563d4221f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5563d0f4eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5563d0f59be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5563d0d05c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5563d0d05c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5563d0d06738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5563d0d05874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5563d0d05874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5563d0d05874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5563d560fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5563d5618928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5563d5600699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5563d562b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcae7606082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5563cef25b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x10,0x65,0x6e,0x76,0x3a,0x20,0x24,0x7b,0x7b,0x20,0x73,0x20,0x24,0x7b,0x7b,0x7d,0x7d, Step #5: \000\000\000\020env: ${{ s ${{}} Step #5: artifact_prefix='./'; Test unit written to ./oom-3816de000a450f8b4591ed584d10a73a1bc19a18 Step #5: Base64: AAAAEGVudjogJHt7IHMgJHt7fX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2193 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2789845225 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5566930da810, 0x5566932c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5566932c4020,0x55669515c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3816de000a450f8b4591ed584d10a73a1bc19a18' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2604 processed earlier; will process 8425 files now Step #5: ==78986== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556689bcf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556690234898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5566902175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5566902174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556689bd5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556689b36b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556689b31355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556689bc7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55668cb96f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55668cb96f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55668cb96f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55668cb96f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55668cb96f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55668cb96f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55668cb96f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55668cb96f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55668cb96f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55668cb96f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55668ee2bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55668bb58b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55668bb63be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55668b90fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55668b90fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55668b910738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55668b90f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55668b90f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55668b90f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556690219abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556690222928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55669020a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556690235112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc4fc2c9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556689b2fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x80,0xa4,0xd7,0xa9,0x28,0x1,0x9,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x38,0x74, Step #5: \363\240\200\244\327\251(\001\0112147483648t Step #5: artifact_prefix='./'; Test unit written to ./oom-99a3e98c024165cd39af192f340207f83117d6cb Step #5: Base64: 86CApNepKAEJMjE0NzQ4MzY0OHQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2194 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2790312245 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5599d79c1810, 0x5599d7bab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5599d7bab020,0x5599d9a430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/99a3e98c024165cd39af192f340207f83117d6cb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2605 processed earlier; will process 8424 files now Step #5: ==79022== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5599ce4b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5599d4b1b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5599d4afe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5599d4afe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5599ce4bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5599ce41db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5599ce418355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5599ce4aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5599d147df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5599d147df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5599d147df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5599d147df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5599d147df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5599d147df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5599d147df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5599d147df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5599d147df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5599d147df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5599d3712f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5599d043fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5599d044abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5599d01f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5599d01f6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5599d01f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5599d01f6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5599d01f6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5599d01f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5599d4b00abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5599d4b09928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5599d4af1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5599d4b1c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f474aec2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5599ce416b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0x61,0x6c,0x69,0x67,0x6e,0x20,0x30,0x2c,0x2c,0x2d,0x32,0x38,0x33,0x35,0x79,0x30,0x37,0x39,0x36,0x3b, Step #5: .align 0,,-2835y0796; Step #5: artifact_prefix='./'; Test unit written to ./oom-400e94d8557d0288198062276a59043c7eda9908 Step #5: Base64: LmFsaWduIDAsLC0yODM1eTA3OTY7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2195 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2790779875 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a28338a810, 0x55a28357401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a283574020,0x55a28540c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/400e94d8557d0288198062276a59043c7eda9908' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2606 processed earlier; will process 8423 files now Step #5: ==79058== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a279e7f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a2804e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2804c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2804c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a279e85d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a279de6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a279de1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a279e77c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a27ce46f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a27ce46f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a27ce46f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a27ce46f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a27ce46f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a27ce46f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a27ce46f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a27ce46f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a27ce46f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a27ce46f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a27f0dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a27be08b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a27be13be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a27bbbfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a27bbbfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a27bbc0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a27bbbf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a27bbbf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a27bbbf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a2804c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a2804d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2804ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a2804e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc11b9fb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a279ddfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x74,0x61,0x72,0x74,0x78,0x72,0x65,0x66,0x20,0x35,0x20,0x34,0x36,0x30,0x37,0x30,0x35,0x30,0x32,0x30, Step #5: startxref 5 460705020 Step #5: artifact_prefix='./'; Test unit written to ./oom-49903469d4344a5ac98de821c912754016b16f05 Step #5: Base64: c3RhcnR4cmVmIDUgNDYwNzA1MDIw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2196 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2791248208 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e0b774810, 0x563e0b95e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e0b95e020,0x563e0d7f60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/49903469d4344a5ac98de821c912754016b16f05' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2607 processed earlier; will process 8422 files now Step #5: ==79094== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563e022699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e088ce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e088b15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e088b14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e0226fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e021d0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e021cb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e02261c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e05230f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e05230f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e05230f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e05230f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e05230f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e05230f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e05230f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e05230f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e05230f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e05230f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e074c5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e041f2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e041fdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e03fa9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e03fa9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e03faa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e03fa9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e03fa9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e03fa9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e088b3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e088bc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e088a4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e088cf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7effcd2fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e021c9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x38,0x34,0x34,0x36,0x37,0x34,0x34,0x30,0x37,0x33,0x37,0x30,0x39,0x35,0x35,0x31,0x36,0x31,0x35,0x2e, Step #5: 18446744073709551615. Step #5: artifact_prefix='./'; Test unit written to ./oom-9e6bc4f3f71db47053fbda5f0842ffa536cf179d Step #5: Base64: MTg0NDY3NDQwNzM3MDk1NTE2MTUu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2197 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2791717973 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d85178e810, 0x55d85197801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d851978020,0x55d8538100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9e6bc4f3f71db47053fbda5f0842ffa536cf179d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2608 processed earlier; will process 8421 files now Step #5: ==79130== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d8482839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d84e8e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d84e8cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d84e8cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d848289d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d8481eab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d8481e5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d84827bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d84b24af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d84b24af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d84b24af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d84b24af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d84b24af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d84b24af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d84b24af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d84b24af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d84b24af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d84b24af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d84d4dff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d84a20cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d84a217be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d849fc3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d849fc3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d849fc4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d849fc3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d849fc3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d849fc3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d84e8cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d84e8d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d84e8be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d84e8e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f57a509b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d8481e3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0xc0,0xa4,0x0, Step #5: $$$$$$$$$$$$$$$$$$\300\244\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8c3834fb95c7ac876143adaea19fc320050c4bfb Step #5: Base64: JCQkJCQkJCQkJCQkJCQkJCQkwKQA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2198 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2792190850 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56017faa0810, 0x56017fc8a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56017fc8a020,0x560181b220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c3834fb95c7ac876143adaea19fc320050c4bfb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2609 processed earlier; will process 8420 files now Step #5: #1 pulse cov: 3722 ft: 3723 exec/s: 0 rss: 170Mb Step #5: ==79166== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5601765959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56017cbfa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56017cbdd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56017cbdd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56017659bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601764fcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601764f7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56017658dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56017955cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56017955cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56017955cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56017955cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56017955cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56017955cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56017955cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56017955cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56017955cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56017955cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56017b7f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56017851eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560178529be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5601782d5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5601782d5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5601782d6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5601782d5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5601782d5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5601782d5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56017cbdfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56017cbe8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56017cbd0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56017cbfb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f378a5ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601764f5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0xa,0xa,0x0,0xa,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x33,0x4,0x4d,0x4d,0xa, Step #5: --\012\012\000\012\012\012\012--\012- -\0123\004MM\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-10d3d48327baded082019048757f1d845f61c2a1 Step #5: Base64: LS0KCgAKCgoKLS0KLSAtCjMETU0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2199 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2792701653 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55638c825810, 0x55638ca0f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55638ca0f020,0x55638e8a70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/10d3d48327baded082019048757f1d845f61c2a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2611 processed earlier; will process 8418 files now Step #5: #1 pulse cov: 3679 ft: 3680 exec/s: 0 rss: 168Mb Step #5: ==79202== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55638331a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55638997f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5563899625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5563899624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556383320d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556383281b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55638327c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556383312c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5563862e1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5563862e1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5563862e1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5563862e1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5563862e1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5563862e1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5563862e1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5563862e1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5563862e1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5563862e1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556388576f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5563852a3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5563852aebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55638505ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55638505ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55638505b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55638505a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55638505a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55638505a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556389964abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55638996d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556389955699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556389980112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff9336b5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55638327ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x65,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3d,0x22,0x43,0x39,0x39,0x22,0x5c, Step #5: Step #5: Step #5: #0 0x55b1a94389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b1afa9d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1afa805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1afa804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b1a943ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b1a939fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b1a939a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b1a9430c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b1ac3fff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b1ac3fff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b1ac3fff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b1ac3fff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b1ac3fff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b1ac3fff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b1ac3fff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b1ac3fff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b1ac3fff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b1ac3fff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b1ae694f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b1ab3c1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b1ab3ccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b1ab178c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b1ab178c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b1ab179738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b1ab178874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b1ab178874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b1ab178874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b1afa82abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b1afa8b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b1afa73699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b1afa9e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3776539082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b1a9398b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe0,0xad,0x87,0xe0,0xad,0x97,0xe0,0xad,0x87,0xe0,0xad,0x97,0xe0,0xad,0x87,0xe0,0xad,0x97, Step #5: ws:\340\255\207\340\255\227\340\255\207\340\255\227\340\255\207\340\255\227 Step #5: artifact_prefix='./'; Test unit written to ./oom-0ef85646cbecfb143ee07b4e6c75ad97d4b34bc3 Step #5: Base64: d3M64K2H4K2X4K2H4K2X4K2H4K2X Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2201 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2793777365 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560878485810, 0x56087866f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56087866f020,0x56087a5070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0ef85646cbecfb143ee07b4e6c75ad97d4b34bc3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2616 processed earlier; will process 8413 files now Step #5: ==79274== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56086ef7a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5608755df898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608755c25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608755c24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56086ef80d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56086eee1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56086eedc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56086ef72c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560871f41f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560871f41f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560871f41f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560871f41f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560871f41f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560871f41f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560871f41f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560871f41f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560871f41f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560871f41f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608741d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560870f03b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560870f0ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560870cbac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560870cbac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560870cbb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560870cba874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560870cba874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560870cba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5608755c4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5608755cd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5608755b5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5608755e0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f443b90d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56086eedab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x17,0x3e,0x7e,0x76,0x28,0x4d,0x54,0x58,0x22,0x49,0x44,0x30,0x2,0xdc,0x0,0xdb,0x2f, Step #5: ID3\002\027>~v(MTX\"ID0\002\334\000\333/ Step #5: artifact_prefix='./'; Test unit written to ./oom-1aca9380ad4289a32e8eada963b8cbafd058d1c1 Step #5: Base64: SUQzAhc+fnYoTVRYIklEMALcANsv Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2202 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2794248139 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c78687c810, 0x55c786a6601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c786a66020,0x55c7888fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1aca9380ad4289a32e8eada963b8cbafd058d1c1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2617 processed earlier; will process 8412 files now Step #5: ==79310== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c77d3719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7839d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7839b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7839b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c77d377d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c77d2d8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c77d2d3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c77d369c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c780338f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c780338f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c780338f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c780338f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c780338f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c780338f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c780338f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c780338f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c780338f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c780338f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7825cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c77f2fab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c77f305be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c77f0b1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c77f0b1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c77f0b2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c77f0b1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c77f0b1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c77f0b1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7839bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7839c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c7839ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7839d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f37f483a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c77d2d1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0x5b,0x5b,0x5b,0x68,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x0,0x3a,0x3a,0x3a,0x5d, Step #5: ?[[[h:::::::::::\000:::] Step #5: artifact_prefix='./'; Test unit written to ./oom-aa2e2549f2e6862e353fa95c7a6160ff8e675d95 Step #5: Base64: P1tbW2g6Ojo6Ojo6Ojo6OgA6Ojpd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2203 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2794708950 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5642cf2af810, 0x5642cf49901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5642cf499020,0x5642d13310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aa2e2549f2e6862e353fa95c7a6160ff8e675d95' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2618 processed earlier; will process 8411 files now Step #5: ==79346== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5642c5da49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5642cc409898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5642cc3ec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5642cc3ec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642c5daad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5642c5d0bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5642c5d06355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5642c5d9cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5642c8d6bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5642c8d6bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5642c8d6bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5642c8d6bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5642c8d6bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5642c8d6bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5642c8d6bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5642c8d6bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5642c8d6bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5642c8d6bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5642cb000f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5642c7d2db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5642c7d38be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5642c7ae4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5642c7ae4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5642c7ae5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5642c7ae4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5642c7ae4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5642c7ae4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5642cc3eeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5642cc3f7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5642cc3df699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5642cc40a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f77a3e30082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5642c5d04b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0xf,0x73,0x65,0x72,0x69,0x66,0xa,0x2d,0x3a,0x24,0x55,0x56,0x60,0x2d,0x3a,0x24,0x60, Step #5: $\000\000/\017serif\012-:$UV`-:$` Step #5: artifact_prefix='./'; Test unit written to ./oom-d9ff58c7c4262c6779c37df3b57e96aaa48841ad Step #5: Base64: JAAALw9zZXJpZgotOiRVVmAtOiRg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2204 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2795304310 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab725f4810, 0x55ab727de01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab727de020,0x55ab746760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d9ff58c7c4262c6779c37df3b57e96aaa48841ad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2619 processed earlier; will process 8410 files now Step #5: ==79382== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ab690e99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab6f74e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab6f7315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab6f7314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab690efd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab69050b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab6904b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab690e1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab6c0b0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab6c0b0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab6c0b0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab6c0b0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab6c0b0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab6c0b0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab6c0b0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab6c0b0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab6c0b0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab6c0b0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab6e345f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab6b072b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab6b07dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab6ae29c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab6ae29c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab6ae2a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab6ae29874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab6ae29874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab6ae29874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab6f733abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab6f73c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab6f724699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab6f74f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd59fbca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab69049b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x6f,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x73,0x74,0x21, Step #5: pouuuuuuuuuuuuuuuust! Step #5: artifact_prefix='./'; Test unit written to ./oom-2107250090e1f42628243aada7484a33b5e83aa5 Step #5: Base64: cG91dXV1dXV1dXV1dXV1dXV1c3Qh Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2205 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2795771396 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc93f55810, 0x55fc9413f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc9413f020,0x55fc95fd70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2107250090e1f42628243aada7484a33b5e83aa5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2620 processed earlier; will process 8409 files now Step #5: ==79418== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fc8aa4a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc910af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc910925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc910924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc8aa50d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc8a9b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc8a9ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc8aa42c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc8da11f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc8da11f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc8da11f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc8da11f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc8da11f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc8da11f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc8da11f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc8da11f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc8da11f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc8da11f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc8fca6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc8c9d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc8c9debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc8c78ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc8c78ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc8c78b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc8c78a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc8c78a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc8c78a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc91094abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc9109d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc91085699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc910b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff2ed0a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc8a9aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x0,0x0,0x20,0x0,0x23,0x24,0x28,0x1e,0x1e,0x24,0x2f,0x0,0x23,0x24,0x28,0x1e,0x1e,0x24,0x2f, Step #5: = \000\000 \000#$(\036\036$/\000#$(\036\036$/ Step #5: artifact_prefix='./'; Test unit written to ./oom-ad8bd83e027e6454a6d072b1e4acc38dffb592e1 Step #5: Base64: PSAAACAAIyQoHh4kLwAjJCgeHiQv Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2206 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2796240901 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56076cafe810, 0x56076cce801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56076cce8020,0x56076eb800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad8bd83e027e6454a6d072b1e4acc38dffb592e1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2621 processed earlier; will process 8408 files now Step #5: ==79454== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5607635f39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560769c58898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560769c3b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560769c3b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5607635f9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56076355ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560763555355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5607635ebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5607665baf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5607665baf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5607665baf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5607665baf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5607665baf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5607665baf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5607665baf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5607665baf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5607665baf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5607665baf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56076884ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56076557cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560765587be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560765333c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560765333c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560765334738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560765333874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560765333874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560765333874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560769c3dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560769c46928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560769c2e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560769c59112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f795113d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560763553b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x90,0xe1,0x9a,0x80,0x0,0x54,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x37,0x20,0x30,0x20,0x35,0x4d,0x39, Step #5: \333\220\341\232\200\000T\000\000\000\000\000\000\0007 0 5M9 Step #5: artifact_prefix='./'; Test unit written to ./oom-0606063a7c9357596dfd017fe0f51e908249752e Step #5: Base64: 25DhmoAAVAAAAAAAAAA3IDAgNU05 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2207 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2796709749 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c290e11810, 0x55c290ffb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c290ffb020,0x55c292e930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0606063a7c9357596dfd017fe0f51e908249752e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 2622 processed earlier; will process 8407 files now Step #5: ==79490== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c2879069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c28df6b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c28df4e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c28df4e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c28790cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c28786db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c287868355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c2878fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c28a8cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c28a8cdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c28a8cdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c28a8cdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c28a8cdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c28a8cdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c28a8cdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c28a8cdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c28a8cdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c28a8cdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c28cb62f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c28988fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c28989abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c289646c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c289646c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c289647738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c289646874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c289646874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c289646874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c28df50abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c28df59928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c28df41699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c28df6c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12b35b0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c287866b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x2d,0x2d,0x3c,0x21,0x2d,0x2d,0x3c,0x53,0x3e,0x3e,0x17,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e, Step #5: 0:0.8\0000:0.0-->0:0.3 Step #5: artifact_prefix='./'; Test unit written to ./oom-983f0829b9a524806be6d952246c649a1d2ceab2 Step #5: Base64: MDowLjMwLS0+MDowLjgAMDowLjAtLT4wOjAuMw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2549 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2963916774 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9a7dad810, 0x55a9a7f9701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a9a7f97020,0x55a9a9e2f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/983f0829b9a524806be6d952246c649a1d2ceab2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3066 processed earlier; will process 7963 files now Step #5: ==91802== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a99e8a29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a9a4f07898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9a4eea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9a4eea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a99e8a8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a99e809b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a99e804355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a99e89ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9a1869f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9a1869f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9a1869f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9a1869f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9a1869f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9a1869f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9a1869f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9a1869f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9a1869f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9a1869f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a9a3afef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a9a082bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a9a0836be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a9a05e2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a9a05e2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a9a05e3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a9a05e2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a9a05e2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a9a05e2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a9a4eecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a9a4ef5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a9a4edd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a9a4f08112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f029b0bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a99e802b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xaa, Step #5: \363\252\252\252\363\252\252\256\363\252\252\252\363\252\252\252\363\252\252\256\363\252\252\252\363\252\252\252 Step #5: artifact_prefix='./'; Test unit written to ./oom-18ca44a0c5def007723490372b5ed70e6f202e82 Step #5: Base64: 86qqqvOqqq7zqqqq86qqqvOqqq7zqqqq86qqqg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2550 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2964380849 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562eede1f810, 0x562eee00901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562eee009020,0x562eefea10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/18ca44a0c5def007723490372b5ed70e6f202e82' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3067 processed earlier; will process 7962 files now Step #5: ==91838== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562ee49149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562eeaf79898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562eeaf5c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562eeaf5c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562ee491ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562ee487bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562ee4876355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562ee490cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ee78dbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ee78dbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ee78dbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ee78dbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ee78dbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ee78dbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ee78dbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ee78dbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ee78dbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ee78dbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ee9b70f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ee689db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ee68a8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ee6654c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ee6654c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ee6655738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ee6654874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ee6654874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ee6654874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562eeaf5eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562eeaf67928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562eeaf4f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562eeaf7a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9150867082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562ee4874b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x11,0xdc,0xb0,0x8,0x6f,0xcc,0xb0,0x4e,0x6f,0x6f,0xdc,0xb0,0xcc,0xb0,0x4e,0x9,0x8,0x6f,0xcc,0xb0,0x4e,0x6f,0x6f,0xdc,0xb0,0xc4,0xb0,0x4e, Step #5: \021\334\260\010o\314\260Noo\334\260\314\260N\011\010o\314\260Noo\334\260\304\260N Step #5: artifact_prefix='./'; Test unit written to ./oom-610a3e0373267a7dac9a40c29542a0175ca7267e Step #5: Base64: EdywCG/MsE5vb9ywzLBOCQhvzLBOb2/csMSwTg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2551 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2964845615 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56058d1d1810, 0x56058d3bb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56058d3bb020,0x56058f2530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/610a3e0373267a7dac9a40c29542a0175ca7267e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3068 processed earlier; will process 7961 files now Step #5: ==91874== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560583cc69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56058a32b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56058a30e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56058a30e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560583cccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560583c2db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560583c28355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560583cbec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560586c8df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560586c8df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560586c8df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560586c8df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560586c8df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560586c8df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560586c8df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560586c8df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560586c8df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560586c8df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560588f22f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560585c4fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560585c5abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560585a06c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560585a06c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560585a07738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560585a06874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560585a06874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560585a06874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56058a310abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56058a319928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56058a301699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56058a32c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb69daed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560583c26b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe3,0x80,0x8e,0xf3,0xa0,0x80,0xa6,0xff,0x0,0x0,0x0,0x5d,0xf5,0x15,0xf3,0xa0,0x81,0x9a,0xa, Step #5: \000\000\000\000\000\000\000\000\000\343\200\216\363\240\200\246\377\000\000\000]\365\025\363\240\201\232\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-1408de2766407f5ffc16cd059f6cf28e8f703e80 Step #5: Base64: AAAAAAAAAAAA44CO86CApv8AAABd9RXzoIGaCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2552 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2965306228 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0759c5810, 0x55b075baf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b075baf020,0x55b077a470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1408de2766407f5ffc16cd059f6cf28e8f703e80' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3069 processed earlier; will process 7960 files now Step #5: ==91910== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b06c4ba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b072b1f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b072b025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b072b024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b06c4c0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b06c421b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b06c41c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b06c4b2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b06f481f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b06f481f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b06f481f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b06f481f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b06f481f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b06f481f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b06f481f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b06f481f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b06f481f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b06f481f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b071716f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b06e443b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b06e44ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b06e1fac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b06e1fac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b06e1fb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b06e1fa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b06e1fa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b06e1fa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b072b04abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b072b0d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b072af5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b072b20112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd6ed45a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b06c41ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x18,0x6a,0x6f,0x62,0x73,0x3a,0xa,0x20,0x7a,0x3a,0xa,0x20,0x20,0xce,0x90,0xd1,0x8c,0xca,0x88,0xcd,0x9b,0x21,0x6e,0x61,0x3a, Step #5: \000\000\000\030jobs:\012 z:\012 \316\220\321\214\312\210\315\233!na: Step #5: artifact_prefix='./'; Test unit written to ./oom-227a943a14bf2dd754352cf0cbf6589de8ac8c4c Step #5: Base64: AAAAGGpvYnM6CiB6OgogIM6Q0YzKiM2bIW5hOg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2553 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2965773076 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571ba45e810, 0x5571ba64801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571ba648020,0x5571bc4e00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/227a943a14bf2dd754352cf0cbf6589de8ac8c4c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3070 processed earlier; will process 7959 files now Step #5: ==91946== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5571b0f539c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571b75b8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571b759b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571b759b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571b0f59d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571b0ebab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571b0eb5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571b0f4bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571b3f1af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571b3f1af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571b3f1af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571b3f1af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571b3f1af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571b3f1af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571b3f1af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571b3f1af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571b3f1af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571b3f1af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571b61aff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571b2edcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571b2ee7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571b2c93c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571b2c93c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571b2c94738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571b2c93874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571b2c93874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571b2c93874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571b759dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571b75a6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571b758e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571b75b9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbac425f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571b0eb3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x49,0x44,0x28,0x2,0x49,0x44,0x34,0x2,0x7e,0x22,0x2,0x7e,0x22,0x0,0x0,0x5b,0x0,0x13,0x0,0x7e,0x22,0x2,0x7e,0x22,0x3b,0x0,0x0, Step #5: 1ID(\002ID4\002~\"\002~\"\000\000[\000\023\000~\"\002~\";\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bcd8c88d7106e9579519b0f6f344c64a40fb4004 Step #5: Base64: MUlEKAJJRDQCfiICfiIAAFsAEwB+IgJ+IjsAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2554 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2966233238 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d8fe04810, 0x563d8ffee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d8ffee020,0x563d91e860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bcd8c88d7106e9579519b0f6f344c64a40fb4004' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3071 processed earlier; will process 7958 files now Step #5: ==91982== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563d868f99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d8cf5e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d8cf415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d8cf414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d868ffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d86860b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d8685b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d868f1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d898c0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d898c0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d898c0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d898c0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d898c0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d898c0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d898c0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d898c0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d898c0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d898c0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d8bb55f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d88882b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d8888dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d88639c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d88639c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d8863a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d88639874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d88639874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d88639874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d8cf43abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d8cf4c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d8cf34699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d8cf5f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5c29348082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d86859b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x80,0x8a,0x2d,0x2d,0xbf,0x39,0x3f,0x5c,0x97,0x80,0xdf,0xdb,0x9c,0x5c,0x97,0x80,0xdf,0xdb,0x9c,0xa1,0x81,0xa4,0x1a,0x3a,0xdf,0xdb,0x73, Step #5: \343\200\212--\2779?\\\227\200\337\333\234\\\227\200\337\333\234\241\201\244\032:\337\333s Step #5: artifact_prefix='./'; Test unit written to ./oom-2fa892c74ac5d64b7db6ec1de1e2416340a604a3 Step #5: Base64: 44CKLS2/OT9cl4Df25xcl4Df25yhgaQaOt/bcw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2555 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2966696906 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564ceae5a810, 0x564ceb04401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564ceb044020,0x564cecedc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2fa892c74ac5d64b7db6ec1de1e2416340a604a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3072 processed earlier; will process 7957 files now Step #5: #1 pulse cov: 13735 ft: 13736 exec/s: 0 rss: 190Mb Step #5: #2 pulse cov: 13967 ft: 14850 exec/s: 0 rss: 192Mb Step #5: ==92018== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564ce194f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564ce7fb4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564ce7f975dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564ce7f974fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ce1955d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ce18b6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ce18b1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ce1947c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564ce4916f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564ce4916f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564ce4916f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564ce4916f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564ce4916f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564ce4916f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564ce4916f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564ce4916f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564ce4916f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564ce4916f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564ce6babf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564ce38d8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564ce38e3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564ce368fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564ce368fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564ce3690738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564ce368f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564ce368f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564ce368f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564ce7f99abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564ce7fa2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564ce7f8a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564ce7fb5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc079c93082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ce18afb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x29,0x38,0x7d,0x24,0x7b,0x19,0x32,0x7d,0x7b,0x32,0x7d,0x24,0x7b,0x38,0x24,0x7b,0xc6,0x87,0x24,0x7d,0x7d,0x3c,0x7d,0x24,0x7b,0x38,0x7d, Step #5: $)8}${\0312}{2}${8${\306\207$}}<}${8} Step #5: artifact_prefix='./'; Test unit written to ./oom-72f765a296bb8d3f213057bb005677994286bc2b Step #5: Base64: JCk4fSR7GTJ9ezJ9JHs4JHvGhyR9fTx9JHs4fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2556 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2967278054 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ae06f18810, 0x55ae0710201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ae07102020,0x55ae08f9a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/72f765a296bb8d3f213057bb005677994286bc2b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3075 processed earlier; will process 7954 files now Step #5: ==92054== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55adfda0d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ae04072898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ae040555dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ae040554fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55adfda13d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55adfd974b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55adfd96f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55adfda05c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ae009d4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ae009d4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ae009d4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ae009d4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ae009d4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ae009d4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ae009d4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ae009d4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ae009d4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ae009d4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ae02c69f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55adff996b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55adff9a1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55adff74dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55adff74dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55adff74e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55adff74d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55adff74d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55adff74d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ae04057abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ae04060928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ae04048699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ae04073112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fed5c6d8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55adfd96db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3e,0x32,0x2d,0x3d,0x3e,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x4c,0x43,0xb2,0xb2,0xb2,0xb2,0x24, Step #5: =>2-=>\336\256!\336\256-\\\\\\\\\\\\\\\\\\LC\262\262\262\262$ Step #5: artifact_prefix='./'; Test unit written to ./oom-1389d4a960711a4d2f8f8c9ea80b3a226f272761 Step #5: Base64: PT4yLT0+3q4h3q4tXFxcXFxcXFxcTEOysrKyJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2557 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2967739052 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5576df79a810, 0x5576df98401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5576df984020,0x5576e181c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1389d4a960711a4d2f8f8c9ea80b3a226f272761' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3076 processed earlier; will process 7953 files now Step #5: ==92090== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5576d628f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5576dc8f4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5576dc8d75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5576dc8d74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5576d6295d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5576d61f6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5576d61f1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5576d6287c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576d9256f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576d9256f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576d9256f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576d9256f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576d9256f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576d9256f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576d9256f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576d9256f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576d9256f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576d9256f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5576db4ebf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5576d8218b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5576d8223be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5576d7fcfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5576d7fcfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5576d7fd0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5576d7fcf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5576d7fcf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5576d7fcf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5576dc8d9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5576dc8e2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5576dc8ca699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5576dc8f5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6eb6028082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5576d61efb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x34,0x4,0x7b,0x0,0x76,0x4d,0x57,0x41,0x50,0x52,0x49,0x73,0x74,0x72,0x65,0x61,0x6d,0x56,0x42,0x8,0x43,0x46,0x21,0xc8,0x0,0x0, Step #5: ID4\004{\000vMWAPRIstreamVB\010CF!\310\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4eaaf827d8b8990130b2040541470825e2d95e38 Step #5: Base64: SUQ0BHsAdk1XQVBSSXN0cmVhbVZCCENGIcgAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2558 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2968202402 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d97e566810, 0x55d97e75001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d97e750020,0x55d9805e80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4eaaf827d8b8990130b2040541470825e2d95e38' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3077 processed earlier; will process 7952 files now Step #5: ==92126== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d97505b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d97b6c0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d97b6a35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d97b6a34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d975061d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d974fc2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d974fbd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d975053c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d978022f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d978022f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d978022f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d978022f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d978022f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d978022f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d978022f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d978022f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d978022f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d978022f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d97a2b7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d976fe4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d976fefbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d976d9bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d976d9bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d976d9c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d976d9b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d976d9b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d976d9b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d97b6a5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d97b6ae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d97b696699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d97b6c1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0b29859082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d974fbbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0xfa, Step #5: vvvvvvvvvvvvvvvvvvvvvvvvvvv\372 Step #5: artifact_prefix='./'; Test unit written to ./oom-d00dff1466d7f63dc58637dbc9bb6669c5a5a237 Step #5: Base64: dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2+g== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2559 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2968666878 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bda02f4810, 0x55bda04de01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bda04de020,0x55bda23760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d00dff1466d7f63dc58637dbc9bb6669c5a5a237' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3078 processed earlier; will process 7951 files now Step #5: #1 pulse cov: 11658 ft: 11659 exec/s: 0 rss: 191Mb Step #5: #2 pulse cov: 13895 ft: 17646 exec/s: 0 rss: 195Mb Step #5: ==92162== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bd96de99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bd9d44e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bd9d4315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bd9d4314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bd96defd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bd96d50b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bd96d4b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bd96de1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bd99db0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bd99db0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bd99db0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bd99db0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bd99db0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bd99db0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bd99db0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bd99db0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bd99db0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bd99db0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bd9c045f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bd98d72b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bd98d7dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bd98b29c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bd98b29c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bd98b2a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bd98b29874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bd98b29874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bd98b29874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bd9d433abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bd9d43c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bd9d424699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bd9d44f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fefef815082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bd96d49b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x4e,0x2d,0x44,0x45,0x2d,0x20,0x2d,0x2d, Step #5: x-----BEGIN -----\012--N-DE- -- Step #5: artifact_prefix='./'; Test unit written to ./oom-16ff348bdfa3abe884d26c6cd8efcc444ccaf725 Step #5: Base64: eC0tLS0tQkVHSU4gLS0tLS0KLS1OLURFLSAtLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2560 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2969253915 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562cffda3810, 0x562cfff8d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562cfff8d020,0x562d01e250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16ff348bdfa3abe884d26c6cd8efcc444ccaf725' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3081 processed earlier; will process 7948 files now Step #5: ==92198== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562cf68989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562cfcefd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562cfcee05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562cfcee04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562cf689ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562cf67ffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562cf67fa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562cf6890c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562cf985ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562cf985ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562cf985ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562cf985ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562cf985ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562cf985ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562cf985ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562cf985ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562cf985ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562cf985ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562cfbaf4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562cf8821b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562cf882cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562cf85d8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562cf85d8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562cf85d9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562cf85d8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562cf85d8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562cf85d8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562cfcee2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562cfceeb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562cfced3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562cfcefe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0f39857082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562cf67f8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xa,0x73,0x75,0x62,0x7b,0x64,0x3a,0x39,0x32,0x39,0x36,0x65,0x33,0x30,0x38,0x20,0x7d,0xa, Step #5: FUZZTESTv1\012sub{d:9296e308 }\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-a4f521e23135fee9d3853eb04c88950eef5f3cd6 Step #5: Base64: RlVaWlRFU1R2MQpzdWJ7ZDo5Mjk2ZTMwOCB9Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2561 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2969719158 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4974ff810, 0x55e4976e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4976e9020,0x55e4995810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a4f521e23135fee9d3853eb04c88950eef5f3cd6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3082 processed earlier; will process 7947 files now Step #5: ==92234== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e48dff49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e494659898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e49463c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e49463c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e48dffad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e48df5bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e48df56355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e48dfecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e490fbbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e490fbbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e490fbbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e490fbbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e490fbbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e490fbbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e490fbbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e490fbbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e490fbbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e490fbbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e493250f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e48ff7db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e48ff88be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e48fd34c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e48fd34c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e48fd35738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e48fd34874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e48fd34874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e48fd34874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e49463eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e494647928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e49462f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e49465a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f84d37ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e48df54b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x3a,0x2d,0xa,0x2d, Step #5: -\012\012\012--\012-\012-\012-\012-\012\012-\012-\012-\012-\012:-\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-9866d458d9e541f3f2b24df801f6f445ac26d997 Step #5: Base64: LQoKCi0tCi0KLQotCi0KCi0KLQotCi0KOi0KLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2562 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2970193600 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562dd9f9d810, 0x562dda18701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562dda187020,0x562ddc01f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9866d458d9e541f3f2b24df801f6f445ac26d997' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3083 processed earlier; will process 7946 files now Step #5: ==92270== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562dd0a929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562dd70f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562dd70da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562dd70da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562dd0a98d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562dd09f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562dd09f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562dd0a8ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562dd3a59f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562dd3a59f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562dd3a59f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562dd3a59f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562dd3a59f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562dd3a59f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562dd3a59f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562dd3a59f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562dd3a59f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562dd3a59f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562dd5ceef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562dd2a1bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562dd2a26be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562dd27d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562dd27d2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562dd27d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562dd27d2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562dd27d2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562dd27d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562dd70dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562dd70e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562dd70cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562dd70f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd63724c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562dd09f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x57,0x6b,0x73,0x42,0x57,0x6b,0x73,0x42,0x57,0x60,0x21,0x57,0x73,0x3a,0x57,0x60,0x21,0x57,0x60,0x21,0x57,0x6b,0x73,0x3a,0x57,0x60,0x21, Step #5: BWksBWksBW`!Ws:W`!W`!Wks:W`! Step #5: artifact_prefix='./'; Test unit written to ./oom-94a6105106f397c1d54e4211f616f65551218909 Step #5: Base64: Qldrc0JXa3NCV2AhV3M6V2AhV2AhV2tzOldgIQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2563 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2970779492 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cdaa953810, 0x55cdaab3d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cdaab3d020,0x55cdac9d50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/94a6105106f397c1d54e4211f616f65551218909' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3084 processed earlier; will process 7945 files now Step #5: #1 pulse cov: 15931 ft: 15932 exec/s: 0 rss: 201Mb Step #5: ==92306== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cda14489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cda7aad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cda7a905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cda7a904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cda144ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cda13afb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cda13aa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cda1440c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cda440ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cda440ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cda440ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cda440ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cda440ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cda440ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cda440ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cda440ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cda440ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cda440ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cda66a4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cda33d1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cda33dcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cda3188c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cda3188c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cda3189738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cda3188874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cda3188874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cda3188874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cda7a92abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cda7a9b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cda7a83699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cda7aae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2644798082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cda13a8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x27,0x5c,0xe0,0xbd,0x8d,0xe0,0xb7,0x8d,0xe0,0xbf,0x8d,0xe0,0xbf,0x8d,0xe0,0xb8,0x8d,0xe0,0xbf,0x8d,0xe0,0xb7,0x8d,0xe0,0xbf,0x8d,0x27, Step #5: e'\\\340\275\215\340\267\215\340\277\215\340\277\215\340\270\215\340\277\215\340\267\215\340\277\215' Step #5: artifact_prefix='./'; Test unit written to ./oom-dc2c3331b3fe07f59b33f1ba8d741cda62cfc659 Step #5: Base64: ZSdc4L2N4LeN4L+N4L+N4LiN4L+N4LeN4L+NJw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2564 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2971470962 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d3ca14810, 0x561d3cbfe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d3cbfe020,0x561d3ea960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dc2c3331b3fe07f59b33f1ba8d741cda62cfc659' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3086 processed earlier; will process 7943 files now Step #5: ==92342== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561d335099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d39b6e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d39b515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d39b514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d3350fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d33470b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d3346b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d33501c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d364d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d364d0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d364d0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d364d0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d364d0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d364d0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d364d0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d364d0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d364d0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d364d0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d38765f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d35492b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d3549dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d35249c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d35249c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d3524a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d35249874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d35249874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d35249874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d39b53abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d39b5c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d39b44699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d39b6f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f800d285082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d33469b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x63,0xa,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0x63,0xa,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b, Step #5: c\012+\012\012+\012+c\012+\012+V\012V\012+c\012+\012+V\012V\012+ Step #5: artifact_prefix='./'; Test unit written to ./oom-5e3315950651a2e6f698b711d11fb138bed442ab Step #5: Base64: YworCgorCitjCisKK1YKVgorYworCitWClYKKw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2565 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2971938612 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a4a0f4810, 0x555a4a2de01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a4a2de020,0x555a4c1760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e3315950651a2e6f698b711d11fb138bed442ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3087 processed earlier; will process 7942 files now Step #5: ==92378== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555a40be99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a4724e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a472315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a472314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a40befd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a40b50b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a40b4b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a40be1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a43bb0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a43bb0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a43bb0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a43bb0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a43bb0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a43bb0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a43bb0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a43bb0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a43bb0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a43bb0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a45e45f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a42b72b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a42b7dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a42929c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a42929c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a4292a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a42929874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a42929874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a42929874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a47233abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a4723c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a47224699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a4724f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1969e7b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a40b49b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x9,0x2b,0xa,0xa,0x9,0xa,0x9,0x2b,0x9,0x2b,0xa,0x73,0x74,0x72,0x65,0x61,0x6d,0x9,0xd5,0x81,0x81,0x8b,0x7e,0x7e,0x7e,0xeb,0x7e, Step #5: +\011+\012\012\011\012\011+\011+\012stream\011\325\201\201\213~~~\353~ Step #5: artifact_prefix='./'; Test unit written to ./oom-91df885d213e44ac92c73d3cce1e95595cb19150 Step #5: Base64: KwkrCgoJCgkrCSsKc3RyZWFtCdWBgYt+fn7rfg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2566 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2972418285 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d651700810, 0x55d6518ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d6518ea020,0x55d6537820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/91df885d213e44ac92c73d3cce1e95595cb19150' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3088 processed earlier; will process 7941 files now Step #5: ==92414== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d6481f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d64e85a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d64e83d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d64e83d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d6481fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d64815cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d648157355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d6481edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d64b1bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d64b1bcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d64b1bcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d64b1bcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d64b1bcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d64b1bcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d64b1bcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d64b1bcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d64b1bcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d64b1bcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d64d451f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d64a17eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d64a189be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d649f35c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d649f35c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d649f36738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d649f35874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d649f35874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d649f35874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d64e83fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d64e848928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d64e830699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d64e85b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f370e78d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d648155b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x5b,0x32,0x2e,0x9,0x32,0x2e,0x9,0xd,0x30,0x2e,0x9,0x39,0x2e,0x9,0xd,0x32,0x2e,0x9,0x34,0x2e,0x9, Step #5: trailer[2.\0112.\011\0150.\0119.\011\0152.\0114.\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ba1a753ef348da82fb1f369ffb4465ee3166495 Step #5: Base64: dHJhaWxlclsyLgkyLgkNMC4JOS4JDTIuCTQuCQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2567 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2972888663 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571c1d2d810, 0x5571c1f1701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571c1f17020,0x5571c3daf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ba1a753ef348da82fb1f369ffb4465ee3166495' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3089 processed earlier; will process 7940 files now Step #5: ==92450== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5571b88229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571bee87898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571bee6a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571bee6a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571b8828d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571b8789b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571b8784355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571b881ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571bb7e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571bb7e9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571bb7e9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571bb7e9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571bb7e9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571bb7e9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571bb7e9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571bb7e9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571bb7e9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571bb7e9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571bda7ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571ba7abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571ba7b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571ba562c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571ba562c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571ba563738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571ba562874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571ba562874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571ba562874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571bee6cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571bee75928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571bee5d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571bee88112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ca46e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571b8782b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0x2f,0x2a,0x6e,0x6e,0x2f,0x58,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1c,0x0,0x0,0x0,0x0,0x34,0x2f,0x34,0x2f,0x58,0x34,0x6e,0x5b, Step #5: \012\012/*nn/X\000\000\000\000\000\000\000\034\000\000\000\0004/4/X4n[ Step #5: artifact_prefix='./'; Test unit written to ./oom-66c8407d23f1b876403c164d14437dece22b4fbe Step #5: Base64: CgovKm5uL1gAAAAAAAAAHAAAAAA0LzQvWDRuWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2568 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2973340480 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c2d4cec810, 0x55c2d4ed601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c2d4ed6020,0x55c2d6d6e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/66c8407d23f1b876403c164d14437dece22b4fbe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3090 processed earlier; will process 7939 files now Step #5: ==92486== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c2cb7e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c2d1e46898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c2d1e295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c2d1e294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c2cb7e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c2cb748b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c2cb743355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c2cb7d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c2ce7a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c2ce7a8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c2ce7a8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c2ce7a8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c2ce7a8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c2ce7a8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c2ce7a8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c2ce7a8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c2ce7a8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c2ce7a8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c2d0a3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c2cd76ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c2cd775be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c2cd521c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c2cd521c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c2cd522738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c2cd521874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c2cd521874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c2cd521874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c2d1e2babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c2d1e34928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c2d1e1c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c2d1e47112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff5b669f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c2cb741b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x3e,0x3e,0x68,0x3e,0xe0,0xa3,0xb3,0x9,0xa,0x3c,0x73,0x79,0x6d,0x62,0x6f,0x6c,0x3e, Step #5: >>h>\340\243\263\011\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-c4783cd5697287cc8022e595a18a65864fdeb25a Step #5: Base64: PHN2Zz48dGV4dD4+Pmg+4KOzCQo8c3ltYm9sPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2569 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2973805555 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff33355810, 0x55ff3353f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff3353f020,0x55ff353d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c4783cd5697287cc8022e595a18a65864fdeb25a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3091 processed earlier; will process 7938 files now Step #5: #1 pulse cov: 10844 ft: 10845 exec/s: 0 rss: 187Mb Step #5: #2 pulse cov: 11241 ft: 11998 exec/s: 0 rss: 189Mb Step #5: ==92522== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ff29e4a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff304af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff304925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff304924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff29e50d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff29db1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff29dac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff29e42c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff2ce11f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff2ce11f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff2ce11f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff2ce11f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff2ce11f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff2ce11f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff2ce11f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff2ce11f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff2ce11f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff2ce11f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff2f0a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff2bdd3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff2bddebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff2bb8ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff2bb8ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff2bb8b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff2bb8a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff2bb8a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff2bb8a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff30494abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff3049d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff30485699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff304b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3d7b09c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff29daab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x49,0x4c,0x45,0x20,0x27,0x20,0x42,0x49,0x4e,0x41,0x52,0x59,0xa,0x46,0x49,0x4c,0x45,0x20,0x27,0x20,0x42,0x49,0x4e,0x41,0x52,0x59,0xa, Step #5: FILE ' BINARY\012FILE ' BINARY\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-238cb311269bcb8a2d8f9dab4c433c2b16316945 Step #5: Base64: RklMRSAnIEJJTkFSWQpGSUxFICcgQklOQVJZCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2570 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2974405758 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56368888a810, 0x563688a7401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563688a74020,0x56368a90c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/238cb311269bcb8a2d8f9dab4c433c2b16316945' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3095 processed earlier; will process 7934 files now Step #5: ==92558== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56367f37f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5636859e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636859c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636859c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56367f385d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56367f2e6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56367f2e1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56367f377c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563682346f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563682346f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563682346f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563682346f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563682346f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563682346f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563682346f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563682346f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563682346f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563682346f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5636845dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563681308b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563681313be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5636810bfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5636810bfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5636810c0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5636810bf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5636810bf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5636810bf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5636859c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5636859d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5636859ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5636859e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d1a184082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56367f2dfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x26,0x37,0x9,0x5b,0x26,0x38,0x9,0x2e,0x32,0x35,0xde,0xa4,0x2c,0x2a,0x38,0x2c,0x2a,0x38,0x5d,0x2c,0x2a,0x37,0x2c,0x2a,0x37,0x5d,0x2c, Step #5: [&7\011[&8\011.25\336\244,*8,*8],*7,*7], Step #5: artifact_prefix='./'; Test unit written to ./oom-a4e283d833bd01827a6499b60f76f97526b26aad Step #5: Base64: WyY3CVsmOAkuMjXepCwqOCwqOF0sKjcsKjddLA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2571 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2974875632 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d051b47810, 0x55d051d3101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d051d31020,0x55d053bc90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a4e283d833bd01827a6499b60f76f97526b26aad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3096 processed earlier; will process 7933 files now Step #5: ==92594== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d04863c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d04eca1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d04ec845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d04ec844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d048642d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d0485a3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d04859e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d048634c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d04b603f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d04b603f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d04b603f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d04b603f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d04b603f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d04b603f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d04b603f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d04b603f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d04b603f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d04b603f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d04d898f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d04a5c5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d04a5d0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d04a37cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d04a37cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d04a37d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d04a37c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d04a37c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d04a37c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d04ec86abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d04ec8f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d04ec77699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d04eca2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f059fbe1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d04859cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf2,0xb0,0x81,0x9f,0xe7,0xa4,0x80,0xef,0x9d,0x80,0xef,0xa4,0x9f,0xe7,0xa4,0x80,0xef,0xa4,0x9f,0xef,0xa4,0x8d,0xef,0x9e,0x80,0xef,0xa4,0xbf, Step #5: \362\260\201\237\347\244\200\357\235\200\357\244\237\347\244\200\357\244\237\357\244\215\357\236\200\357\244\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-83cbccb049fa351a0f240ff87e3b5cc4379c9bae Step #5: Base64: 8rCBn+ekgO+dgO+kn+ekgO+kn++kje+egO+kvw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2572 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2975341426 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b8a486810, 0x558b8a67001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b8a670020,0x558b8c5080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/83cbccb049fa351a0f240ff87e3b5cc4379c9bae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3097 processed earlier; will process 7932 files now Step #5: ==92630== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558b80f7b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b875e0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b875c35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b875c34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b80f81d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b80ee2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b80edd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b80f73c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b83f42f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b83f42f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b83f42f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b83f42f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b83f42f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b83f42f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b83f42f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b83f42f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b83f42f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b83f42f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b861d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b82f04b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b82f0fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b82cbbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b82cbbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b82cbc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b82cbb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b82cbb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b82cbb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b875c5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b875ce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b875b6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b875e1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88e1f4a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b80edbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x18,0xe2,0x83,0xb9,0xe2,0x81,0x84,0xe1,0xa7,0xb9,0xe2,0x81,0x84,0xe2,0xa6,0xb8,0xe2,0x80,0x85,0xe2,0xa7,0x84,0xe2,0xa6,0x8f, Step #5: \000\000\000\030\342\203\271\342\201\204\341\247\271\342\201\204\342\246\270\342\200\205\342\247\204\342\246\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-42fd447ecad002bda97af61d955cc761f4aac797 Step #5: Base64: AAAAGOKDueKBhOGnueKBhOKmuOKAheKnhOKmjw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2573 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2975807129 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eec27b9810, 0x55eec29a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eec29a3020,0x55eec483b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/42fd447ecad002bda97af61d955cc761f4aac797' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3098 processed earlier; will process 7931 files now Step #5: ==92666== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55eeb92ae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eebf913898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eebf8f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eebf8f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eeb92b4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eeb9215b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eeb9210355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eeb92a6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eebc275f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eebc275f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eebc275f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eebc275f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eebc275f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eebc275f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eebc275f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eebc275f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eebc275f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eebc275f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eebe50af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eebb237b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eebb242be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eebafeec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eebafeec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eebafef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eebafee874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eebafee874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eebafee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eebf8f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eebf901928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eebf8e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eebf914112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffad6450082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eeb920eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x58,0x2e,0x58,0x2e,0x6e,0x3c,0x3e,0x2e,0x58,0x2e,0x58,0x2e,0x6e,0x3c,0x3e,0x2e,0x6e,0x3c,0x3e,0x49,0x0,0x2e,0x61,0x3d,0xa,0x0,0x0,0x0, Step #5: X.X.n<>.X.X.n<>.n<>I\000.a=\012\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9f76181b86e35d1faa0134342c8928618072dfb5 Step #5: Base64: WC5YLm48Pi5YLlgubjw+Lm48PkkALmE9CgAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2574 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2976278286 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56367ce83810, 0x56367d06d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56367d06d020,0x56367ef050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f76181b86e35d1faa0134342c8928618072dfb5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3099 processed earlier; will process 7930 files now Step #5: #1 pulse cov: 3917 ft: 3918 exec/s: 0 rss: 172Mb Step #5: ==92702== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5636739789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563679fdd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563679fc05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563679fc04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56367397ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5636738dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5636738da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563673970c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56367693ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56367693ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56367693ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56367693ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56367693ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56367693ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56367693ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56367693ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56367693ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56367693ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563678bd4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563675901b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56367590cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5636756b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5636756b8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5636756b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5636756b8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5636756b8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5636756b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563679fc2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563679fcb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563679fb3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563679fde112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f568db91082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5636738d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x7f,0x7f,0x0,0x0,0x28,0x0,0x72,0x0,0x0,0x28,0x0,0x64,0x64,0x0,0x0,0x28,0x0,0x72,0x0,0x0,0x2c,0x0,0x64,0x64,0x64,0x64, Step #5: = \177\177\000\000(\000r\000\000(\000dd\000\000(\000r\000\000,\000dddd Step #5: artifact_prefix='./'; Test unit written to ./oom-d4dd9193a79073f922b55514a5bf8f0e997da8c8 Step #5: Base64: PSB/fwAAKAByAAAoAGRkAAAoAHIAACwAZGRkZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2575 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2976785484 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dfcadf5810, 0x55dfcafdf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dfcafdf020,0x55dfcce770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d4dd9193a79073f922b55514a5bf8f0e997da8c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3101 processed earlier; will process 7928 files now Step #5: ==92738== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55dfc18ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dfc7f4f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dfc7f325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dfc7f324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dfc18f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dfc1851b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dfc184c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dfc18e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dfc48b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dfc48b1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dfc48b1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dfc48b1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dfc48b1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dfc48b1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dfc48b1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dfc48b1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dfc48b1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dfc48b1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dfc6b46f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dfc3873b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dfc387ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dfc362ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dfc362ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dfc362b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dfc362a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dfc362a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dfc362a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dfc7f34abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dfc7f3d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dfc7f25699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dfc7f50112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4882f15082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dfc184ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xe3,0x80,0x80,0x2d,0x2d,0x31,0x3f,0x5c,0x6f,0xdd,0xe3,0xdd,0x5c,0x72,0x5c,0x6e,0xf3,0x3b,0x5c,0x6e,0x3b,0x5c,0x6f,0xdd,0xe3,0xdd,0x3b, Step #5: -\343\200\200--1?\\o\335\343\335\\r\\n\363;\\n;\\o\335\343\335; Step #5: artifact_prefix='./'; Test unit written to ./oom-3b25cc952762f14203f432d7cbad932e0981ea10 Step #5: Base64: LeOAgC0tMT9cb93j3VxyXG7zO1xuO1xv3ePdOw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2576 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2977260838 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56125404d810, 0x56125423701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561254237020,0x5612560cf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3b25cc952762f14203f432d7cbad932e0981ea10' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3102 processed earlier; will process 7927 files now Step #5: ==92774== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56124ab429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5612511a7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56125118a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56125118a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56124ab48d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56124aaa9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56124aaa4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56124ab3ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56124db09f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56124db09f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56124db09f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56124db09f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56124db09f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56124db09f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56124db09f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56124db09f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56124db09f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56124db09f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56124fd9ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56124cacbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56124cad6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56124c882c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56124c882c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56124c883738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56124c882874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56124c882874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56124c882874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56125118cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561251195928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56125117d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5612511a8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f24b41e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56124aaa2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x39,0x2,0x0,0x0,0x29,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x29,0x55,0xdc,0x83, Step #5: ID9\002\000\000)\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000)U\334\203 Step #5: artifact_prefix='./'; Test unit written to ./oom-11b4a9ea7cb8791c3aeb2652e00f9ee8f1cfd15b Step #5: Base64: SUQ5AgAAKQAAAAAAAAAAAAAAAAAAAQAAKVXcgw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2577 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2977729016 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558416aa1810, 0x558416c8b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558416c8b020,0x558418b230e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/11b4a9ea7cb8791c3aeb2652e00f9ee8f1cfd15b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3103 processed earlier; will process 7926 files now Step #5: #1 pulse cov: 11669 ft: 11670 exec/s: 0 rss: 191Mb Step #5: ==92810== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55840d5969c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558413bfb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558413bde5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558413bde4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55840d59cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55840d4fdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55840d4f8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55840d58ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55841055df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55841055df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55841055df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55841055df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55841055df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55841055df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55841055df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55841055df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55841055df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55841055df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5584127f2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55840f51fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55840f52abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55840f2d6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55840f2d6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55840f2d7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55840f2d6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55840f2d6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55840f2d6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558413be0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558413be9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558413bd1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558413bfc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f119bdcb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55840d4f6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x45,0x3e,0x26,0x23,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x37,0x33,0x38,0x3b, Step #5: ˢ Step #5: artifact_prefix='./'; Test unit written to ./oom-0c7c19d5b08b4e921788edeb7beb25763c9f8d00 Step #5: Base64: PEU+JiMwMDAwMDAwMDAwMDAwMDAwMDAwMDczODs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2578 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2978260124 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55781270d810, 0x5578128f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5578128f7020,0x55781478f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0c7c19d5b08b4e921788edeb7beb25763c9f8d00' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3105 processed earlier; will process 7924 files now Step #5: ==92846== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5578092029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55780f867898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55780f84a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55780f84a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557809208d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557809169b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557809164355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5578091fac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55780c1c9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55780c1c9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55780c1c9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55780c1c9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55780c1c9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55780c1c9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55780c1c9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55780c1c9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55780c1c9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55780c1c9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55780e45ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55780b18bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55780b196be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55780af42c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55780af42c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55780af43738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55780af42874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55780af42874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55780af42874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55780f84cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55780f855928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55780f83d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55780f868112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f66c42a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557809162b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x11,0x11,0x79,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x34, Step #5: ID3\002\021\021y\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0004 Step #5: artifact_prefix='./'; Test unit written to ./oom-965678a42406047aff7e1f9af2481c7b76c4ad53 Step #5: Base64: SUQzAhEReQAAAAAAAAAAAAAAAAAAAAAAAAAAADQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2579 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2978729077 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56318fde6810, 0x56318ffd001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56318ffd0020,0x563191e680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/965678a42406047aff7e1f9af2481c7b76c4ad53' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3106 processed earlier; will process 7923 files now Step #5: ==92882== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5631868db9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56318cf40898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56318cf235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56318cf234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5631868e1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563186842b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56318683d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5631868d3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5631898a2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5631898a2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5631898a2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5631898a2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5631898a2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5631898a2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5631898a2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5631898a2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5631898a2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5631898a2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56318bb37f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563188864b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56318886fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56318861bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56318861bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56318861c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56318861b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56318861b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56318861b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56318cf25abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56318cf2e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56318cf16699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56318cf41112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5ab0aaf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56318683bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xbe,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: \341\276\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-2d3777bb0cba1aa40b0292eecab0bdf52c0e88c5 Step #5: Base64: 4b6EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2580 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2979199650 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ccda307810, 0x55ccda4f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ccda4f1020,0x55ccdc3890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2d3777bb0cba1aa40b0292eecab0bdf52c0e88c5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3107 processed earlier; will process 7922 files now Step #5: ==92918== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ccd0dfc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ccd7461898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ccd74445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ccd74444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ccd0e02d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ccd0d63b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ccd0d5e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ccd0df4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ccd3dc3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ccd3dc3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ccd3dc3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ccd3dc3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ccd3dc3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ccd3dc3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ccd3dc3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ccd3dc3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ccd3dc3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ccd3dc3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ccd6058f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ccd2d85b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ccd2d90be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ccd2b3cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ccd2b3cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ccd2b3d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ccd2b3c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ccd2b3c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ccd2b3c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ccd7446abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ccd744f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ccd7437699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ccd7462112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efc3b751082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ccd0d5cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x31,0x2b,0x32,0x2b,0x39,0x2b,0x31,0x22,0x22,0x20,0x67,0x20,0x22,0x22,0x20,0x67,0x20,0x22,0x22,0x20,0x63,0x20,0x22,0x22,0x20,0x63,0x20,0x22, Step #5: \"1+2+9+1\"\" g \"\" g \"\" c \"\" c \" Step #5: artifact_prefix='./'; Test unit written to ./oom-1ff049f9368afc618abe19736cc351ce9e38ccab Step #5: Base64: IjErMis5KzEiIiBnICIiIGcgIiIgYyAiIiBjICI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2581 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2979676502 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c6bb11d810, 0x55c6bb30701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c6bb307020,0x55c6bd19f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ff049f9368afc618abe19736cc351ce9e38ccab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3108 processed earlier; will process 7921 files now Step #5: ==92954== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c6b1c129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c6b8277898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c6b825a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c6b825a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c6b1c18d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6b1b79b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6b1b74355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c6b1c0ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c6b4bd9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c6b4bd9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c6b4bd9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c6b4bd9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c6b4bd9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c6b4bd9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c6b4bd9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c6b4bd9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c6b4bd9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c6b4bd9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c6b6e6ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6b3b9bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c6b3ba6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6b3952c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6b3952c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6b3953738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6b3952874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6b3952874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6b3952874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c6b825cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c6b8265928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c6b824d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c6b8278112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f87cef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6b1b72b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0xcd,0x91,0xcd,0x81,0xcd,0xa1,0xcd,0x81,0xcd,0xae,0xcd,0x81,0xcd,0xa1,0xcd,0xa1,0xcd,0xae,0xcd,0x81,0xcd,0xa1,0xcd,0x81,0xcd,0xae,0xcd,0x81, Step #5: M\315\221\315\201\315\241\315\201\315\256\315\201\315\241\315\241\315\256\315\201\315\241\315\201\315\256\315\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-ebee327d3ebbcd5dac95717d879202eb6a9e7c2a Step #5: Base64: Tc2RzYHNoc2Bza7Ngc2hzaHNrs2BzaHNgc2uzYE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2582 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2980147291 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a15a02810, 0x559a15bec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a15bec020,0x559a17a840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ebee327d3ebbcd5dac95717d879202eb6a9e7c2a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3109 processed earlier; will process 7920 files now Step #5: ==92990== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559a0c4f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a12b5c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a12b3f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a12b3f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a0c4fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a0c45eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a0c459355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a0c4efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a0f4bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a0f4bef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a0f4bef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a0f4bef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a0f4bef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a0f4bef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a0f4bef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a0f4bef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a0f4bef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a0f4bef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a11753f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a0e480b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a0e48bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a0e237c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a0e237c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a0e238738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a0e237874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a0e237874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a0e237874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a12b41abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a12b4a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a12b32699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a12b5d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4739d2b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a0c457b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0xd6,0x93,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0xd6,0x93,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: x----BEGIN\326\223---BEGIN\326\223\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6a0014478a5020cf463f65b3860389af4463f050 Step #5: Base64: eC0tLS1CRUdJTtaTLS0tQkVHSU7WkwAAAAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2583 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2980614324 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e7d48e810, 0x555e7d67801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e7d678020,0x555e7f5100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a0014478a5020cf463f65b3860389af4463f050' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3110 processed earlier; will process 7919 files now Step #5: ==93026== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555e73f839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e7a5e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e7a5cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e7a5cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e73f89d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e73eeab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e73ee5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e73f7bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e76f4af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e76f4af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e76f4af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e76f4af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e76f4af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e76f4af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e76f4af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e76f4af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e76f4af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e76f4af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e791dff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e75f0cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e75f17be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e75cc3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e75cc3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e75cc4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e75cc3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e75cc3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e75cc3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e7a5cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e7a5d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e7a5be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e7a5e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4583f2e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e73ee3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x36,0x3a,0x5b,0x7b,0x24,0x34,0x3a,0x22,0x5c,0x55,0x64,0x46,0x46,0x64,0x64,0x46,0x37,0x44,0x22,0x7d,0x5d,0x7d,0x24, Step #5: $3::{$6:[{$4:\"\\UdFFddF7D\"}]}$ Step #5: artifact_prefix='./'; Test unit written to ./oom-589cdb1a06373c5d3da37555cde8809ccc97509d Step #5: Base64: JDM6OnskNjpbeyQ0OiJcVWRGRmRkRjdEIn1dfSQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2584 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2981088414 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7db012810, 0x55f7db1fc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7db1fc020,0x55f7dd0940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/589cdb1a06373c5d3da37555cde8809ccc97509d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3111 processed earlier; will process 7918 files now Step #5: ==93062== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f7d1b079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7d816c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7d814f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7d814f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f7d1b0dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f7d1a6eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f7d1a69355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f7d1affc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7d4acef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7d4acef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7d4acef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7d4acef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7d4acef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7d4acef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7d4acef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7d4acef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7d4acef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7d4acef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7d6d63f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f7d3a90b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f7d3a9bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f7d3847c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f7d3847c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f7d3848738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f7d3847874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f7d3847874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f7d3847874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7d8151abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7d815a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7d8142699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7d816d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fee773cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f7d1a67b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x11,0x0,0x7,0x0,0xce,0x93,0x1,0x60,0x54,0x43,0x4f,0x0,0x0,0x68,0x61,0x69,0x72,0x6c,0x69,0x6e,0x65,0x1,0x60,0x54,0x43,0x4f,0x1, Step #5: ID\021\000\007\000\316\223\001`TCO\000\000hairline\001`TCO\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-c7d4e86b289a9c4b3b2cced2305a459f62806f15 Step #5: Base64: SUQRAAcAzpMBYFRDTwAAaGFpcmxpbmUBYFRDTwE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2585 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2981679365 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e2af676810, 0x55e2af86001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e2af860020,0x55e2b16f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c7d4e86b289a9c4b3b2cced2305a459f62806f15' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3112 processed earlier; will process 7917 files now Step #5: ==93098== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e2a616b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e2ac7d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e2ac7b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e2ac7b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e2a6171d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e2a60d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e2a60cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e2a6163c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e2a9132f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e2a9132f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e2a9132f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e2a9132f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e2a9132f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e2a9132f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e2a9132f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e2a9132f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e2a9132f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e2a9132f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e2ab3c7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e2a80f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e2a80ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e2a7eabc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e2a7eabc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e2a7eac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e2a7eab874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e2a7eab874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e2a7eab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e2ac7b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e2ac7be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e2ac7a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e2ac7d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ef7a0b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e2a60cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x60,0x8,0x2,0x33,0x3f,0x0,0x0,0x0,0x0,0x0,0x73,0x6f,0x75,0x72,0x63,0x65,0x0,0x44,0x5d,0xc,0xa,0x1,0x4d,0x60,0x49,0xfb,0x9, Step #5: ID`\010\0023?\000\000\000\000\000source\000D]\014\012\001M`I\373\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-eeefb3def52d074d692908c8c8c20dc6dc5fab24 Step #5: Base64: SURgCAIzPwAAAAAAc291cmNlAERdDAoBTWBJ+wk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2586 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2982272353 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5566217cb810, 0x5566219b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5566219b5020,0x55662384d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eeefb3def52d074d692908c8c8c20dc6dc5fab24' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3113 processed earlier; will process 7916 files now Step #5: ==93134== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5566182c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55661e925898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55661e9085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55661e9084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5566182c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556618227b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556618222355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5566182b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55661b287f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55661b287f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55661b287f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55661b287f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55661b287f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55661b287f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55661b287f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55661b287f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55661b287f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55661b287f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55661d51cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55661a249b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55661a254be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55661a000c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55661a000c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55661a001738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55661a000874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55661a000874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55661a000874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55661e90aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55661e913928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55661e8fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55661e926112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f598e0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556618220b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x1,0x0,0x0,0x0,0x1,0x0,0x21,0x57,0x0,0x0,0x2,0x61,0x76,0x61,0x72,0x0,0x0,0x0,0x22,0x0,0x0,0x0,0xa,0xdc,0xb2,0xff,0xda,0xdc, Step #5: \000\001\000\000\000\001\000!W\000\000\002avar\000\000\000\"\000\000\000\012\334\262\377\332\334 Step #5: artifact_prefix='./'; Test unit written to ./oom-19f7b4d67ecf549b05ccdee378f567ee47c3c82a Step #5: Base64: AAEAAAABACFXAAACYXZhcgAAACIAAAAK3LL/2tw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2587 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2982743015 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5598ef4ee810, 0x5598ef6d801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5598ef6d8020,0x5598f15700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/19f7b4d67ecf549b05ccdee378f567ee47c3c82a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3114 processed earlier; will process 7915 files now Step #5: ==93170== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5598e5fe39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5598ec648898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5598ec62b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5598ec62b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5598e5fe9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5598e5f4ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5598e5f45355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5598e5fdbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5598e8faaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5598e8faaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5598e8faaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5598e8faaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5598e8faaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5598e8faaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5598e8faaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5598e8faaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5598e8faaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5598e8faaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5598eb23ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5598e7f6cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5598e7f77be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5598e7d23c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5598e7d23c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5598e7d24738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5598e7d23874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5598e7d23874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5598e7d23874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5598ec62dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5598ec636928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5598ec61e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5598ec649112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0dc580c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5598e5f43b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x67,0x6c,0x79,0x72,0x5c,0x6e,0x22,0x78,0x63,0x66,0x66,0x67,0x7f,0x6c,0x79,0x67,0x7f,0x6d,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x45,0x6e, Step #5: tglyr\\n\"xcffg\177lyg\177mglyf?g?gEn Step #5: artifact_prefix='./'; Test unit written to ./oom-79e96f8fab0ff9587d64ff329ad9489c601d3ba2 Step #5: Base64: dGdseXJcbiJ4Y2ZmZ39seWd/bWdseWY/Zz9nRW4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2588 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2983218363 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eaa660f810, 0x55eaa67f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eaa67f9020,0x55eaa86910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/79e96f8fab0ff9587d64ff329ad9489c601d3ba2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3115 processed earlier; will process 7914 files now Step #5: ==93206== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ea9d1049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eaa3769898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eaa374c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eaa374c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea9d10ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea9d06bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea9d066355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea9d0fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eaa00cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eaa00cbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eaa00cbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eaa00cbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eaa00cbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eaa00cbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eaa00cbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eaa00cbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eaa00cbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eaa00cbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eaa2360f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea9f08db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea9f098be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea9ee44c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea9ee44c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea9ee45738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea9ee44874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea9ee44874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea9ee44874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eaa374eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eaa3757928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eaa373f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eaa376a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fee5f24b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea9d064b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x3f,0x5b,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0xa0,0x85,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa9,0x5d,0x5d, Step #5: [?[\360\235\205\240\360\235\205\240\360\235\205\240\360\235\240\205\360\235\205\240\360\235\205\251]] Step #5: artifact_prefix='./'; Test unit written to ./oom-a414a10bb8a5c7a75d815a28311d01a85b739b8e Step #5: Base64: Wz9b8J2FoPCdhaDwnYWg8J2ghfCdhaDwnYWpXV0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2589 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2983681428 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee5d002810, 0x55ee5d1ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee5d1ec020,0x55ee5f0840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a414a10bb8a5c7a75d815a28311d01a85b739b8e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3116 processed earlier; will process 7913 files now Step #5: ==93242== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ee53af79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee5a15c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee5a13f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee5a13f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee53afdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee53a5eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee53a59355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee53aefc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee56abef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee56abef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee56abef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee56abef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee56abef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee56abef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee56abef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee56abef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee56abef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee56abef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee58d53f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee55a80b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee55a8bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee55837c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee55837c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee55838738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee55837874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee55837874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee55837874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee5a141abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee5a14a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee5a132699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee5a15d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d5aea9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee53a57b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x3,0x23,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0x32,0x39,0x35,0x1b,0x50,0x52,0x49,0x56,0x0,0x42,0x8,0x1,0x53,0x58,0x8d,0x9,0xfa, Step #5: ID3\003#4294967295\033PRIV\000B\010\001SX\215\011\372 Step #5: artifact_prefix='./'; Test unit written to ./oom-469d24ef1aebe646d5a436a6ecc10f636d1e8d79 Step #5: Base64: SUQzAyM0Mjk0OTY3Mjk1G1BSSVYAQggBU1iNCfo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2590 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2984153724 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7545cf810, 0x55b7547b901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7547b9020,0x55b7566510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/469d24ef1aebe646d5a436a6ecc10f636d1e8d79' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3117 processed earlier; will process 7912 files now Step #5: ==93278== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b74b0c49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b751729898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b75170c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b75170c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b74b0cad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b74b02bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b74b026355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b74b0bcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b74e08bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b74e08bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b74e08bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b74e08bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b74e08bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b74e08bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b74e08bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b74e08bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b74e08bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b74e08bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b750320f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b74d04db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b74d058be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b74ce04c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b74ce04c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b74ce05738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b74ce04874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b74ce04874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b74ce04874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b75170eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b751717928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b7516ff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b75172a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4d30c83082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b74b024b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x8,0x0,0x7,0x2e,0x2b,0x42,0xda,0xbe,0x7c,0xdb,0xbe,0xdb,0xbe,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x22, Step #5: \"\010\000\007.+B\332\276|\333\276\333\276++++++++++++++\" Step #5: artifact_prefix='./'; Test unit written to ./oom-2d1c8765678a9100d6f4ddea8f525eb6b6faa5ec Step #5: Base64: IggABy4rQtq+fNu+274rKysrKysrKysrKysrKyI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2591 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2984625540 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610eccb8810, 0x5610ecea201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610ecea2020,0x5610eed3a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2d1c8765678a9100d6f4ddea8f525eb6b6faa5ec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3118 processed earlier; will process 7911 files now Step #5: ==93314== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5610e37ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610e9e12898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610e9df55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610e9df54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610e37b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610e3714b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610e370f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610e37a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610e6774f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610e6774f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610e6774f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610e6774f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610e6774f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610e6774f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610e6774f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610e6774f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610e6774f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610e6774f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610e8a09f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610e5736b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610e5741be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610e54edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610e54edc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610e54ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610e54ed874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610e54ed874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610e54ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610e9df7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610e9e00928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610e9de8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610e9e13112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f21f94ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610e370db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xf3,0xa0,0x81,0xac,0xcd,0x8f,0x26,0x3f,0x5c,0xde,0xb9,0x93,0xdb,0xc2,0xc4,0x4f,0xf8,0x67,0xd9,0xa,0xe2,0x24,0x4a,0x25,0xa6,0x1b,0x1f,0xb9, Step #5: -\363\240\201\254\315\217&?\\\336\271\223\333\302\304O\370g\331\012\342$J%\246\033\037\271 Step #5: artifact_prefix='./'; Test unit written to ./oom-9205ff0d16e03bd2fccff23a9c683f1fa0ce298f Step #5: Base64: LfOggazNjyY/XN65k9vCxE/4Z9kK4iRKJaYbH7k= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2592 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2985092602 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fa19375810, 0x55fa1955f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fa1955f020,0x55fa1b3f70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9205ff0d16e03bd2fccff23a9c683f1fa0ce298f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3119 processed earlier; will process 7910 files now Step #5: ==93350== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55fa0fe6a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fa164cf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fa164b25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fa164b24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fa0fe70d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fa0fdd1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fa0fdcc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fa0fe62c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fa12e31f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fa12e31f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fa12e31f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fa12e31f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fa12e31f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fa12e31f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fa12e31f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fa12e31f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fa12e31f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fa12e31f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fa150c6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fa11df3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fa11dfebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fa11baac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fa11baac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fa11bab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fa11baa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fa11baa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fa11baa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fa164b4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fa164bd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fa164a5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fa164d0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0bc7282082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fa0fdcab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7c,0x7d,0x24,0x7c,0x7c,0x24,0x7c,0x7c,0x24,0xf3,0xa0,0x81,0xa9,0x7c,0x7c,0x7c,0x24,0xf3,0xa0,0x81,0xa9,0x7c,0x68,0x24,0x29,0x7c,0x29,0x7c, Step #5: $|}$||$||$\363\240\201\251|||$\363\240\201\251|h$)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-c15fe9f8bd4d10f3720ec1bdf1122505c82e0a30 Step #5: Base64: JHx9JHx8JHx8JPOggal8fHwk86CBqXxoJCl8KXw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2593 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2985564821 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55998f191810, 0x55998f37b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55998f37b020,0x5599912130e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c15fe9f8bd4d10f3720ec1bdf1122505c82e0a30' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3120 processed earlier; will process 7909 files now Step #5: #1 pulse cov: 4076 ft: 4077 exec/s: 0 rss: 170Mb Step #5: #2 pulse cov: 4369 ft: 4580 exec/s: 0 rss: 172Mb Step #5: ==93386== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559985c869c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55998c2eb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55998c2ce5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55998c2ce4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559985c8cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559985bedb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559985be8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559985c7ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559988c4df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559988c4df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559988c4df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559988c4df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559988c4df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559988c4df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559988c4df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559988c4df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559988c4df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559988c4df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55998aee2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559987c0fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559987c1abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5599879c6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5599879c6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5599879c7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5599879c6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5599879c6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5599879c6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55998c2d0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55998c2d9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55998c2c1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55998c2ec112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f70e08e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559985be6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xb,0x64,0x3a,0x30,0x78,0x37,0x65,0x38,0x37,0x32,0x39,0x36,0x34,0x50,0x2d,0x31,0x30,0x35,0x33, Step #5: FUZZTESTv1\013d:0x7e872964P-1053 Step #5: artifact_prefix='./'; Test unit written to ./oom-91b2d3db3f35f0aa0ee5acda9ce89538b5b1f1a9 Step #5: Base64: RlVaWlRFU1R2MQtkOjB4N2U4NzI5NjRQLTEwNTM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2594 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2986109805 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5581286a7810, 0x55812889101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558128891020,0x55812a7290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/91b2d3db3f35f0aa0ee5acda9ce89538b5b1f1a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3123 processed earlier; will process 7906 files now Step #5: #1 pulse cov: 11664 ft: 11665 exec/s: 0 rss: 190Mb Step #5: ==93422== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55811f19c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558125801898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5581257e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5581257e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55811f1a2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55811f103b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55811f0fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55811f194c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558122163f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558122163f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558122163f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558122163f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558122163f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558122163f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558122163f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558122163f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558122163f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558122163f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5581243f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558121125b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558121130be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558120edcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558120edcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558120edd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558120edc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558120edc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558120edc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5581257e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5581257ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5581257d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558125802112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe6da431082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55811f0fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x26,0x24,0x12,0x60,0x24,0x75,0x1,0x1,0x1,0x1,0x68,0xa,0x23,0x1,0x2d,0x68,0x68,0x68,0x24,0x75,0x1,0x1,0x1,0x1,0x1,0x1,0x67,0x60, Step #5: $&$\022`$u\001\001\001\001h\012#\001-hhh$u\001\001\001\001\001\001g` Step #5: artifact_prefix='./'; Test unit written to ./oom-379a6934ac3cd5df394061baeecd111a8e7f93eb Step #5: Base64: JCYkEmAkdQEBAQFoCiMBLWhoaCR1AQEBAQEBZ2A= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2595 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2986769974 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7ae336810, 0x55f7ae52001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7ae520020,0x55f7b03b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/379a6934ac3cd5df394061baeecd111a8e7f93eb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3125 processed earlier; will process 7904 files now Step #5: ==93458== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f7a4e2b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7ab490898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7ab4735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7ab4734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f7a4e31d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f7a4d92b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f7a4d8d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f7a4e23c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7a7df2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7a7df2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7a7df2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7a7df2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7a7df2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7a7df2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7a7df2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7a7df2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7a7df2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7a7df2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7aa087f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f7a6db4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f7a6dbfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f7a6b6bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f7a6b6bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f7a6b6c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f7a6b6b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f7a6b6b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f7a6b6b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7ab475abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7ab47e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7ab466699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7ab491112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c2894c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f7a4d8bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x77,0x77,0x77,0x77,0x77,0x68,0x65,0x61,0x64,0x77,0x77,0x77,0x77,0x77,0x77,0x77,0x77,0x77,0x77,0x77,0x77,0x77,0x77,0x77,0x77,0x67,0x73,0x74, Step #5: pwwwwwheadwwwwwwwwwwwwwwwwgst Step #5: artifact_prefix='./'; Test unit written to ./oom-342168b0bbd40306619f93330e87e68c382ec69e Step #5: Base64: cHd3d3d3aGVhZHd3d3d3d3d3d3d3d3d3d3dnc3Q= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2596 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2987235484 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d9d25ab810, 0x55d9d279501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d9d2795020,0x55d9d462d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/342168b0bbd40306619f93330e87e68c382ec69e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3126 processed earlier; will process 7903 files now Step #5: #1 pulse cov: 3716 ft: 3717 exec/s: 0 rss: 171Mb Step #5: ==93494== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d9c90a09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d9cf705898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d9cf6e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d9cf6e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d9c90a6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d9c9007b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d9c9002355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d9c9098c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d9cc067f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d9cc067f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d9cc067f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d9cc067f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d9cc067f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d9cc067f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d9cc067f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d9cc067f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d9cc067f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d9cc067f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d9ce2fcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d9cb029b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d9cb034be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d9cade0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d9cade0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d9cade1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d9cade0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d9cade0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d9cade0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d9cf6eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d9cf6f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d9cf6db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d9cf706112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa30c991082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d9c9000b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0x72,0x3e,0x5b,0xa,0xa,0xa,0xa,0xa,0x3c,0x21,0x45,0x4c,0x45,0x4d,0x45,0x5d,0x3e,0x3c,0x2f,0x2d, Step #5: [\012\012\012\012\012 Step #5: Step #5: #0 0x55edcb4499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55edd1aae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55edd1a915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55edd1a914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55edcb44fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55edcb3b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55edcb3ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55edcb441c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55edce410f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55edce410f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55edce410f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55edce410f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55edce410f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55edce410f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55edce410f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55edce410f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55edce410f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55edce410f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55edd06a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55edcd3d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55edcd3ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55edcd189c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55edcd189c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55edcd18a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55edcd189874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55edcd189874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55edcd189874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55edd1a93abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55edd1a9c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55edd1a84699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55edd1aaf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f051adba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55edcb3a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0xa,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x3f,0x41,0x73,0x63,0x65,0x7a,0x74,0x7a,0x74,0x20,0x6a,0x2d,0x2d,0x2d, Step #5: 0\012=\314\273A---Asce\012-?Asceztzt j--- Step #5: artifact_prefix='./'; Test unit written to ./oom-d2d3fddb12b5135dec5d35c9770e8f6a26f8e843 Step #5: Base64: MAo9zLtBLS0tQXNjZQotP0FzY2V6dHp0IGotLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2598 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2988261484 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559825352810, 0x55982553c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55982553c020,0x5598273d40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d2d3fddb12b5135dec5d35c9770e8f6a26f8e843' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3130 processed earlier; will process 7899 files now Step #5: ==93566== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55981be479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5598224ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55982248f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55982248f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55981be4dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55981bdaeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55981bda9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55981be3fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55981ee0ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55981ee0ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55981ee0ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55981ee0ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55981ee0ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55981ee0ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55981ee0ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55981ee0ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55981ee0ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55981ee0ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5598210a3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55981ddd0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55981dddbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55981db87c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55981db87c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55981db88738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55981db87874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55981db87874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55981db87874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559822491abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55982249a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559822482699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5598224ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f817e775082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55981bda7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x73,0x3a,0x6c,0xe1,0x80,0xb9,0xe2,0x80,0x8c,0xe1,0x80,0xb9,0xe2,0x80,0x8c,0xe1,0x80,0xb9,0xe2,0x80,0x8c,0xe1,0x80,0xb9,0xe2,0x80,0x8c, Step #5: \016ws:l\341\200\271\342\200\214\341\200\271\342\200\214\341\200\271\342\200\214\341\200\271\342\200\214 Step #5: artifact_prefix='./'; Test unit written to ./oom-07d0de7eef1185f72addbb1efa1f52322e4f7a0f Step #5: Base64: DndzOmzhgLnigIzhgLnigIzhgLnigIzhgLnigIw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2599 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2988735161 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1034cb810, 0x55a1036b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1036b5020,0x55a10554d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/07d0de7eef1185f72addbb1efa1f52322e4f7a0f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3131 processed earlier; will process 7898 files now Step #5: ==93602== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a0f9fc09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a100625898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1006085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1006084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0f9fc6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0f9f27b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0f9f22355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0f9fb8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0fcf87f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0fcf87f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0fcf87f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0fcf87f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0fcf87f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0fcf87f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0fcf87f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0fcf87f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0fcf87f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0fcf87f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0ff21cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0fbf49b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0fbf54be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0fbd00c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0fbd00c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0fbd01738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0fbd00874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0fbd00874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0fbd00874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a10060aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a100613928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1005fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a100626112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2f6c268082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0f9f20b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x3,0x7c,0x0,0x1b,0x2e,0x64,0x64,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x42,0x0,0x8,0x78,0xda,0x8d,0x0,0xf3,0xa0,0x81,0x97,0x44, Step #5: ID3\003|\000\033.ddUSLT\000\000\000B\000\010x\332\215\000\363\240\201\227D Step #5: artifact_prefix='./'; Test unit written to ./oom-2cde5ccd93b7c812f61ad52a761f02ae46b1fe16 Step #5: Base64: SUQzA3wAGy5kZFVTTFQAAABCAAh42o0A86CBl0Q= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2600 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2989202713 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56518cdc9810, 0x56518cfb301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56518cfb3020,0x56518ee4b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2cde5ccd93b7c812f61ad52a761f02ae46b1fe16' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3132 processed earlier; will process 7897 files now Step #5: #1 pulse cov: 3688 ft: 3689 exec/s: 0 rss: 169Mb Step #5: ==93638== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5651838be9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565189f23898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565189f065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565189f064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5651838c4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565183825b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565183820355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5651838b6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565186885f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565186885f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565186885f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565186885f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565186885f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565186885f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565186885f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565186885f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565186885f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565186885f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565188b1af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565185847b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565185852be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5651855fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5651855fec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5651855ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5651855fe874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5651855fe874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5651855fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565189f08abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565189f11928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565189ef9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565189f24112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f0bca2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56518381eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0x5b,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x81,0x92,0x96,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x86,0x93, Step #5: (?i)[\000-\362\205\205\223\000-\362\201\222\226\000-\362\205\205\223\000-\362\205\206\223 Step #5: artifact_prefix='./'; Test unit written to ./oom-1c53bf44d54790c33e22d8a30eb7bd9e0418fff9 Step #5: Base64: KD9pKVsALfKFhZMALfKBkpYALfKFhZMALfKFhpM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2601 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2989712989 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56244af7e810, 0x56244b16801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56244b168020,0x56244d0000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c53bf44d54790c33e22d8a30eb7bd9e0418fff9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3134 processed earlier; will process 7895 files now Step #5: #1 pulse cov: 3576 ft: 3577 exec/s: 0 rss: 169Mb Step #5: ==93674== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562441a739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5624480d8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5624480bb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5624480bb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562441a79d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5624419dab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5624419d5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562441a6bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562444a3af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562444a3af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562444a3af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562444a3af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562444a3af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562444a3af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562444a3af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562444a3af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562444a3af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562444a3af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562446ccff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5624439fcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562443a07be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5624437b3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5624437b3c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5624437b4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5624437b3874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5624437b3874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5624437b3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5624480bdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5624480c6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5624480ae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5624480d9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0added5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5624419d3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x20,0x1f,0x1f,0xf,0x1f,0x1f,0x24,0x1f,0x1f,0x1f,0x1f,0x24,0x1b,0x1f,0x1f,0x64,0x1,0x0,0x0,0x0,0x0,0x0, Step #5: \037\037\037\037\037\037\037 \037\037\017\037\037$\037\037\037\037$\033\037\037d\001\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-789f2fd619cf263bd04daba72a1e94300edd0389 Step #5: Base64: Hx8fHx8fHyAfHw8fHyQfHx8fJBsfH2QBAAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2602 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2990226627 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56390f9a9810, 0x56390fb9301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56390fb93020,0x563911a2b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/789f2fd619cf263bd04daba72a1e94300edd0389' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3136 processed earlier; will process 7893 files now Step #5: ==93710== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56390649e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56390cb03898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56390cae65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56390cae64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5639064a4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563906405b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563906400355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563906496c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563909465f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563909465f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563909465f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563909465f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563909465f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563909465f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563909465f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563909465f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563909465f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563909465f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56390b6faf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563908427b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563908432be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5639081dec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5639081dec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5639081df738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5639081de874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5639081de874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5639081de874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56390cae8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56390caf1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56390cad9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56390cb04112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ab25c0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5639063feb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x50,0x3e,0x3c,0x39,0x32,0x32,0x33,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x30,0x32,0x3e,0xca,0x5c,0x72,0x63,0x65,0x3e,0x3c,0x66, Step #5:

<9223203685477502>\312\\rce> Step #5: Step #5: #0 0x5606e24529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5606e8ab7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606e8a9a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606e8a9a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5606e2458d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5606e23b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5606e23b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5606e244ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5606e5419f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5606e5419f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5606e5419f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5606e5419f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5606e5419f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5606e5419f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5606e5419f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5606e5419f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5606e5419f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5606e5419f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606e76aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5606e43dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5606e43e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5606e4192c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5606e4192c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5606e4193738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5606e4192874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5606e4192874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5606e4192874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5606e8a9cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5606e8aa5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5606e8a8d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5606e8ab8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3df3407082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5606e23b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0x9,0x72,0x6f,0x2f,0x2d,0xa,0x2d,0xa,0x9,0x72,0x6f,0x2f,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0x3d,0x8,0x2e, Step #5: -\012\011ro/-\012-\012\011ro/-\012-\012\012-\012-\012\012-\012=\010. Step #5: artifact_prefix='./'; Test unit written to ./oom-bd13273ce0efde37c730c9d1286a5cca7fcad2f1 Step #5: Base64: LQoJcm8vLQotCglyby8tCi0KCi0KLQoKLQo9CC4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2604 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2991168142 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a3f3a5810, 0x560a3f58f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a3f58f020,0x560a414270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bd13273ce0efde37c730c9d1286a5cca7fcad2f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3138 processed earlier; will process 7891 files now Step #5: ==93782== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560a35e9a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a3c4ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a3c4e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a3c4e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a35ea0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a35e01b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a35dfc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a35e92c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a38e61f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a38e61f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a38e61f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a38e61f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a38e61f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a38e61f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a38e61f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a38e61f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a38e61f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a38e61f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a3b0f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a37e23b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a37e2ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a37bdac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a37bdac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a37bdb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a37bda874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a37bda874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a37bda874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a3c4e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a3c4ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a3c4d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a3c500112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1f0343c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a35dfab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x8,0x0,0x7,0x2e,0x2b,0x42,0xda,0xbe,0x7c,0xdb,0xbe,0xdb,0xbe,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0xc0,0xab,0x6e,0x24,0x3,0x3,0x52, Step #5: - \010\000\007.+B\332\276|\333\276\333\276+++++++\300\253n$\003\003R Step #5: artifact_prefix='./'; Test unit written to ./oom-884f458e71aa59b9ff62cce6dffc12b79153aa0d Step #5: Base64: LSAIAAcuK0Lavnzbvtu+KysrKysrK8CrbiQDA1I= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2605 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2991637765 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a13b14c810, 0x55a13b33601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a13b336020,0x55a13d1ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/884f458e71aa59b9ff62cce6dffc12b79153aa0d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3139 processed earlier; will process 7890 files now Step #5: ==93818== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a131c419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1382a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1382895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1382894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a131c47d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a131ba8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a131ba3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a131c39c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a134c08f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a134c08f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a134c08f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a134c08f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a134c08f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a134c08f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a134c08f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a134c08f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a134c08f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a134c08f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a136e9df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a133bcab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a133bd5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a133981c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a133981c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a133982738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a133981874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a133981874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a133981874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a13828babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a138294928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a13827c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1382a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a64bb8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a131ba1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x8,0x1,0x7,0x2e,0x2b,0x42,0xdb,0xbe,0xdb,0xbe,0x2b,0x2f,0x76,0x2f,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x24,0x6e,0x24,0x3,0x3,0x52, Step #5: - \010\001\007.+B\333\276\333\276+/v/+++++++$n$\003\003R Step #5: artifact_prefix='./'; Test unit written to ./oom-74002f8224f4d46bae359c14fe64562d6e956a21 Step #5: Base64: LSAIAQcuK0Lbvtu+Ky92LysrKysrKyskbiQDA1I= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2606 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2992104187 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56540eeca810, 0x56540f0b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56540f0b4020,0x565410f4c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/74002f8224f4d46bae359c14fe64562d6e956a21' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3140 processed earlier; will process 7889 files now Step #5: ==93854== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5654059bf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56540c024898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56540c0075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56540c0074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5654059c5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565405926b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565405921355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5654059b7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565408986f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565408986f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565408986f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565408986f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565408986f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565408986f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565408986f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565408986f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565408986f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565408986f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56540ac1bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565407948b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565407953be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5654076ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5654076ffc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565407700738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5654076ff874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5654076ff874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5654076ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56540c009abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56540c012928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56540bffa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56540c025112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f07bd1ea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56540591fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xe1,0xa6,0xa6,0xe1,0xa6,0x9d,0x2d,0x39,0x32,0x32,0x68,0x6f,0x73,0x74,0x49,0x3d,0x33,0xe1,0xa6,0xa6,0x70,0x72,0x6f,0x63,0x65,0x73,0x73,0x22, Step #5: \"\341\246\246\341\246\235-922hostI=3\341\246\246process\" Step #5: artifact_prefix='./'; Test unit written to ./oom-38c245c0be6ee4cb4dd6d1bcd9f6a75af60961f5 Step #5: Base64: IuGmpuGmnS05MjJob3N0ST0z4aamcHJvY2VzcyI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2607 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2992567443 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea8e80f810, 0x55ea8e9f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea8e9f9020,0x55ea908910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/38c245c0be6ee4cb4dd6d1bcd9f6a75af60961f5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3141 processed earlier; will process 7888 files now Step #5: #1 pulse cov: 3714 ft: 3715 exec/s: 0 rss: 171Mb Step #5: ==93890== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ea853049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea8b969898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea8b94c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea8b94c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea8530ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea8526bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea85266355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea852fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea882cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea882cbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea882cbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea882cbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea882cbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea882cbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea882cbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea882cbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea882cbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea882cbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea8a560f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea8728db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea87298be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea87044c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea87044c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea87045738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea87044874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea87044874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea87044874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea8b94eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea8b957928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea8b93f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea8b96a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d0329f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea85264b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf2,0xa0,0x8f,0x87,0xf4,0x82,0x80,0x93,0xf3,0xa0,0x87,0x87,0xf4,0x84,0x80,0x9f,0xf3,0xa2,0x81,0x99,0xf0,0xb5,0x99,0x80,0xfc,0x87,0x83,0x87,0x83, Step #5: \362\240\217\207\364\202\200\223\363\240\207\207\364\204\200\237\363\242\201\231\360\265\231\200\374\207\203\207\203 Step #5: artifact_prefix='./'; Test unit written to ./oom-5c30ed0fe4878eb3e1f61f93624e1d445fd8d9c4 Step #5: Base64: 8qCPh/SCgJPzoIeH9ISAn/OigZnwtZmA/IeDh4M= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2608 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2993072994 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562448ba5810, 0x562448d8f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562448d8f020,0x56244ac270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c30ed0fe4878eb3e1f61f93624e1d445fd8d9c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3143 processed earlier; will process 7886 files now Step #5: ==93926== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56243f69a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562445cff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562445ce25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562445ce24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56243f6a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56243f601b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56243f5fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56243f692c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562442661f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562442661f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562442661f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562442661f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562442661f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562442661f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562442661f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562442661f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562442661f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562442661f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5624448f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562441623b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56244162ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5624413dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5624413dac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5624413db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5624413da874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5624413da874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5624413da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562445ce4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562445ced928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562445cd5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562445d00112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8478c78082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56243f5fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x5,0x0,0x6f,0x70,0x74,0x69,0x6f,0x6e,0x73,0x7b,0x6f,0x75,0x74,0x70,0x75,0x74,0x0,0x41,0x53,0x54,0x3c,0x46,0x2d,0x3e,0x26,0x67,0x2b,0x54, Step #5: d\005\000options{output\000AST&g+T Step #5: artifact_prefix='./'; Test unit written to ./oom-c522208c549b8f334fdf856bf7adfc904e2ee4a2 Step #5: Base64: ZAUAb3B0aW9uc3tvdXRwdXQAQVNUPEYtPiZnK1Q= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2609 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2993541663 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c3feab3810, 0x55c3fec9d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c3fec9d020,0x55c400b350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c522208c549b8f334fdf856bf7adfc904e2ee4a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3144 processed earlier; will process 7885 files now Step #5: ==93962== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c3f55a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c3fbc0d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c3fbbf05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c3fbbf04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c3f55aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c3f550fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c3f550a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c3f55a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c3f856ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c3f856ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c3f856ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c3f856ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c3f856ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c3f856ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c3f856ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c3f856ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c3f856ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c3f856ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c3fa804f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c3f7531b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c3f753cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c3f72e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c3f72e8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c3f72e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c3f72e8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c3f72e8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c3f72e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c3fbbf2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c3fbbfb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c3fbbe3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c3fbc0e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f799a541082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c3f5508b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x2d,0x2d,0xf3,0xa0,0x84,0xb7,0x2d,0x2d,0x3e,0x3c,0x21,0x2d,0x2d,0xf3,0xa0,0x84,0xb7,0x2d,0x2d,0x3e,0x3c,0x21,0x2d,0x2d,0xf3,0xa0,0x83,0xb7, Step #5: 0:2:1.2\0120\0122\0120\0120\0126\0122\0121 Step #5: artifact_prefix='./'; Test unit written to ./oom-fd1d1f205d107bdc4e97b0e77c6d347a2266a2da Step #5: Base64: MDoxOjQuMy0tPjA6MjoxLjIKMAoyCjAKMAo2CjIKMQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2656 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3016978319 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5653e9d96810, 0x5653e9f8001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5653e9f80020,0x5653ebe180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fd1d1f205d107bdc4e97b0e77c6d347a2266a2da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3213 processed earlier; will process 7816 files now Step #5: #1 pulse cov: 3640 ft: 3641 exec/s: 0 rss: 169Mb Step #5: ==95654== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5653e088b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5653e6ef0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5653e6ed35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5653e6ed34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5653e0891d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5653e07f2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5653e07ed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5653e0883c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5653e3852f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5653e3852f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5653e3852f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5653e3852f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5653e3852f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5653e3852f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5653e3852f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5653e3852f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5653e3852f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5653e3852f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5653e5ae7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5653e2814b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5653e281fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5653e25cbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5653e25cbc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5653e25cc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5653e25cb874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5653e25cb874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5653e25cb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5653e6ed5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5653e6ede928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5653e6ec6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5653e6ef1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f460f6d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5653e07ebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x3d,0xc2,0x85,0x6b,0xc2,0x85,0x6b,0x3d,0xc2,0x85,0x3f,0xc2,0x85,0x6b,0x3d,0xc2,0x85,0x3d,0xc2,0x85,0x3f,0xc2,0x85,0x6b,0x3d,0xc2,0x85,0x3f,0x3d,0xa, Step #5: \012=\302\205k\302\205k=\302\205?\302\205k=\302\205=\302\205?\302\205k=\302\205?=\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-5db8f1641b7e84ddb305a414b3ec42ee0022ceb5 Step #5: Base64: Cj3ChWvChWs9woU/woVrPcKFPcKFP8KFaz3ChT89Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2657 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3017489613 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a7f019810, 0x555a7f20301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a7f203020,0x555a8109b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5db8f1641b7e84ddb305a414b3ec42ee0022ceb5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3215 processed earlier; will process 7814 files now Step #5: ==95690== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555a75b0e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a7c173898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a7c1565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a7c1564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a75b14d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a75a75b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a75a70355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a75b06c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a78ad5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a78ad5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a78ad5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a78ad5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a78ad5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a78ad5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a78ad5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a78ad5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a78ad5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a78ad5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a7ad6af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a77a97b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a77aa2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a7784ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a7784ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a7784f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a7784e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a7784e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a7784e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a7c158abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a7c161928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a7c149699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a7c174112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe0a0bd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a75a6eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x1c,0x22,0xe0,0xbe,0x9a,0xe0,0xbe,0x9a,0xe6,0x81,0x82,0xe0,0xbe,0x9a,0xe0,0xab,0xac,0xe0,0xbe,0x9a,0xe0,0xbe,0x9a,0xe0,0xbe,0x9b,0xe0,0xab,0xab, Step #5: HU\034\"\340\276\232\340\276\232\346\201\202\340\276\232\340\253\254\340\276\232\340\276\232\340\276\233\340\253\253 Step #5: artifact_prefix='./'; Test unit written to ./oom-f268eb9c204bce2349a2748803b3095392d3af8e Step #5: Base64: SFUcIuC+muC+muaBguC+muCrrOC+muC+muC+m+Crqw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2658 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3017957168 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563dbb28c810, 0x563dbb47601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563dbb476020,0x563dbd30e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f268eb9c204bce2349a2748803b3095392d3af8e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3216 processed earlier; will process 7813 files now Step #5: ==95726== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563db1d819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563db83e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563db83c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563db83c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563db1d87d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563db1ce8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563db1ce3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563db1d79c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563db4d48f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563db4d48f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563db4d48f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563db4d48f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563db4d48f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563db4d48f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563db4d48f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563db4d48f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563db4d48f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563db4d48f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563db6fddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563db3d0ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563db3d15be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563db3ac1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563db3ac1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563db3ac2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563db3ac1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563db3ac1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563db3ac1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563db83cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563db83d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563db83bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563db83e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f393c1a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563db1ce1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x12,0x27,0x27,0x66,0x27,0x27,0x27,0x27,0x34,0xe2,0x81,0xa5,0x2d,0x3d,0x27,0x38,0x27,0x27,0x27,0x27,0x27,0xdf,0xbd,0x35,0x27,0x24,0x27,0x2d, Step #5: $22\022''f''''4\342\201\245-='8'''''\337\2755'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-c81b9e6e87d6727af7d006e74d3c0a234bd0dd9a Step #5: Base64: JDIyEicnZicnJyc04oGlLT0nOCcnJycn3701JyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2659 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3018435615 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5623c333d810, 0x5623c352701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5623c3527020,0x5623c53bf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c81b9e6e87d6727af7d006e74d3c0a234bd0dd9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3217 processed earlier; will process 7812 files now Step #5: ==95762== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5623b9e329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5623c0497898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5623c047a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5623c047a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5623b9e38d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5623b9d99b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5623b9d94355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5623b9e2ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5623bcdf9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5623bcdf9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5623bcdf9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5623bcdf9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5623bcdf9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5623bcdf9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5623bcdf9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5623bcdf9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5623bcdf9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5623bcdf9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5623bf08ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5623bbdbbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5623bbdc6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5623bbb72c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5623bbb72c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5623bbb73738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5623bbb72874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5623bbb72874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5623bbb72874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5623c047cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5623c0485928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5623c046d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5623c0498112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe11f1ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5623b9d92b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x6d,0x74,0x41,0x68,0x73,0x73,0x20,0x30,0xa,0x20,0x20,0xa,0x78,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47, Step #5: (mtAhss 0\012 \012xGGGGGGGGGGGGGGGGG Step #5: artifact_prefix='./'; Test unit written to ./oom-869e145d8391d513790a0261581fbf9ad233da66 Step #5: Base64: KG10QWhzcyAwCiAgCnhHR0dHR0dHR0dHR0dHR0dHRw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2660 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3018906336 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560be611a810, 0x560be630401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560be6304020,0x560be819c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/869e145d8391d513790a0261581fbf9ad233da66' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3218 processed earlier; will process 7811 files now Step #5: ==95798== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560bdcc0f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560be3274898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560be32575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560be32574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560bdcc15d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560bdcb76b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560bdcb71355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560bdcc07c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560bdfbd6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560bdfbd6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560bdfbd6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560bdfbd6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560bdfbd6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560bdfbd6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560bdfbd6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560bdfbd6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560bdfbd6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560bdfbd6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560be1e6bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560bdeb98b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560bdeba3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560bde94fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560bde94fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560bde950738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560bde94f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560bde94f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560bde94f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560be3259abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560be3262928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560be324a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560be3275112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c70f4f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560bdcb6fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x10,0x0,0x0,0x5,0x0,0xcd,0x8f,0xe1,0xa0,0x8e,0xaa,0x18,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x3,0x3e,0x0,0x1,0x0,0x20,0xfd,0xaa,0x0,0x1e,0x92, Step #5: \020\000\000\005\000\315\217\341\240\216\252\030\000\001\000\000\000\000\000\000\003>\000\001\000 \375\252\000\036\222 Step #5: artifact_prefix='./'; Test unit written to ./oom-b2ec7d9309a58a2cca5863ca624fd3eed43a5a07 Step #5: Base64: EAAABQDNj+GgjqoYAAEAAAAAAAADPgABACD9qgAekg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2661 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3019373644 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555bc64d2810, 0x555bc66bc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555bc66bc020,0x555bc85540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b2ec7d9309a58a2cca5863ca624fd3eed43a5a07' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3219 processed earlier; will process 7810 files now Step #5: #1 pulse cov: 3789 ft: 3790 exec/s: 0 rss: 171Mb Step #5: #2 pulse cov: 10929 ft: 11754 exec/s: 0 rss: 193Mb Step #5: ==95834== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555bbcfc79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555bc362c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555bc360f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555bc360f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555bbcfcdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555bbcf2eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555bbcf29355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555bbcfbfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555bbff8ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555bbff8ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555bbff8ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555bbff8ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555bbff8ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555bbff8ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555bbff8ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555bbff8ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555bbff8ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555bbff8ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555bc2223f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555bbef50b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555bbef5bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555bbed07c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555bbed07c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555bbed08738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555bbed07874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555bbed07874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555bbed07874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555bc3611abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555bc361a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555bc3602699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555bc362d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f247b98f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555bbcf27b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20, Step #5: - - - - - - - - - - - - - - - Step #5: artifact_prefix='./'; Test unit written to ./oom-85099272b9c7859aa3c46c5cd68031ca4d54cc7f Step #5: Base64: IC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2662 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3019951199 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c99e61e810, 0x55c99e80801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c99e808020,0x55c9a06a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/85099272b9c7859aa3c46c5cd68031ca4d54cc7f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3222 processed earlier; will process 7807 files now Step #5: ==95870== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c9951139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c99b778898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c99b75b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c99b75b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c995119d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c99507ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c995075355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c99510bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c9980daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c9980daf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c9980daf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c9980daf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c9980daf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c9980daf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c9980daf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c9980daf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c9980daf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c9980daf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c99a36ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c99709cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9970a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c996e53c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c996e53c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c996e54738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c996e53874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c996e53874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c996e53874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c99b75dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c99b766928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c99b74e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c99b779112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f7923d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c995073b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x1b,0x1,0x1a,0x0,0x8,0x0,0x0,0x0,0x21,0x63,0x22,0x62,0x0,0x0,0x0,0x1b,0x1,0x24,0x0,0x31,0x6e,0x24,0x24,0x30,0x6e,0x24,0x2d,0x2d, Step #5: \000\000\000\033\001\032\000\010\000\000\000!c\"b\000\000\000\033\001$\0001n$$0n$-- Step #5: artifact_prefix='./'; Test unit written to ./oom-a6811b7b814e3bc5de4566934549a442298753be Step #5: Base64: AAAAGwEaAAgAAAAhYyJiAAAAGwEkADFuJCQwbiQtLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2663 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3020418008 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ca56ee810, 0x561ca58d801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ca58d8020,0x561ca77700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a6811b7b814e3bc5de4566934549a442298753be' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3223 processed earlier; will process 7806 files now Step #5: #1 pulse cov: 3608 ft: 3609 exec/s: 0 rss: 169Mb Step #5: ==95906== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561c9c1e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561ca2848898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561ca282b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561ca282b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c9c1e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c9c14ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c9c145355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c9c1dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c9f1aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c9f1aaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c9f1aaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c9f1aaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c9f1aaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c9f1aaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c9f1aaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c9f1aaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c9f1aaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c9f1aaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561ca143ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c9e16cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c9e177be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c9df23c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c9df23c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c9df24738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c9df23874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c9df23874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c9df23874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561ca282dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561ca2836928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561ca281e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561ca2849112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f86764a1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c9c143b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $2'/''''''2-='''''''''''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-d64aeb5483a13dde6b97681e30bda64688dcb505 Step #5: Base64: JDInLycnJycnJzItPScnJycnJycnJycnJycuJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2664 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3020935038 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c07f90810, 0x564c0817a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c0817a020,0x564c0a0120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d64aeb5483a13dde6b97681e30bda64688dcb505' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3225 processed earlier; will process 7804 files now Step #5: ==95942== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564bfea859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c050ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c050cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c050cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564bfea8bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564bfe9ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564bfe9e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564bfea7dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c01a4cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c01a4cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c01a4cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c01a4cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c01a4cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c01a4cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c01a4cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c01a4cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c01a4cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c01a4cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c03ce1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c00a0eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c00a19be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c007c5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c007c5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c007c6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c007c5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c007c5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c007c5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c050cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c050d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c050c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c050eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a103e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564bfe9e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x69,0x67,0x72,0x41,0x70,0x68,0x7b,0xa,0x7a,0x7a,0x2d,0x3e,0x7b,0x73,0x55,0x62,0x47,0x72,0x61,0x70,0x68,0x22,0x0,0x0,0x22,0x7d,0x2d,0x3e,0x64,0x7d, Step #5: digrAph{\012zz->{sUbGraph\"\000\000\"}->d} Step #5: artifact_prefix='./'; Test unit written to ./oom-42180eef43a4e2af409efd9e49e705ab79cb3e8e Step #5: Base64: ZGlnckFwaHsKenotPntzVWJHcmFwaCIAACJ9LT5kfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2665 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3021398720 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559294650810, 0x55929483a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55929483a020,0x5592966d20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/42180eef43a4e2af409efd9e49e705ab79cb3e8e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3226 processed earlier; will process 7803 files now Step #5: ==95978== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55928b1459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5592917aa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55929178d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55929178d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55928b14bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55928b0acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55928b0a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55928b13dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55928e10cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55928e10cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55928e10cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55928e10cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55928e10cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55928e10cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55928e10cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55928e10cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55928e10cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55928e10cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592903a1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55928d0ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55928d0d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55928ce85c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55928ce85c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55928ce86738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55928ce85874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55928ce85874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55928ce85874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55929178fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559291798928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559291780699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5592917ab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faee77da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55928b0a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x49,0x27,0x21,0x31,0x24,0x44,0x33,0x2,0x11,0x11,0x79,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x36,0x0,0x0,0x34, Step #5: $I'!1$D3\002\021\021y\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0006\000\0004 Step #5: artifact_prefix='./'; Test unit written to ./oom-6da9c08cbb91547ea4e6f5c5c86531220682c17d Step #5: Base64: JEknITEkRDMCERF5AAAAAAAAAAAAAAAAAAAANgAANA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2666 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3021867742 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea07613810, 0x55ea077fd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea077fd020,0x55ea096950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6da9c08cbb91547ea4e6f5c5c86531220682c17d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3227 processed earlier; will process 7802 files now Step #5: ==96014== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e9fe1089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea0476d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea047505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea047504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9fe10ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e9fe06fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e9fe06a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9fe100c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea010cff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea010cff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea010cff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea010cff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea010cff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea010cff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea010cff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea010cff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea010cff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea010cff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea03364f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea00091b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea0009cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9ffe48c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9ffe48c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9ffe49738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9ffe48874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9ffe48874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9ffe48874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea04752abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea0475b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea04743699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea0476e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0f1ab69082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e9fe068b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0xf0,0x9d,0x85,0xbb,0xf0,0x9d,0x85,0xbb,0xd6,0xb9,0xd6,0xb0,0xd6,0xb8,0xf0,0x9d,0x85,0xbb,0xd6,0xb0,0xd6,0xb8,0xd6,0xb1,0xcc,0xb8,0xd6,0xb1,0xcc,0xb8, Step #5: x\360\235\205\273\360\235\205\273\326\271\326\260\326\270\360\235\205\273\326\260\326\270\326\261\314\270\326\261\314\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-bbeafb4e4d976a589c02e042bcc89fbac4b70844 Step #5: Base64: ePCdhbvwnYW71rnWsNa48J2Fu9aw1rjWscy41rHMuA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2667 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3022335744 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e24f0c5810, 0x55e24f2af01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e24f2af020,0x55e2511470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bbeafb4e4d976a589c02e042bcc89fbac4b70844' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3228 processed earlier; will process 7801 files now Step #5: ==96050== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e245bba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e24c21f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e24c2025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e24c2024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e245bc0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e245b21b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e245b1c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e245bb2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e248b81f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e248b81f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e248b81f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e248b81f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e248b81f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e248b81f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e248b81f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e248b81f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e248b81f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e248b81f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e24ae16f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e247b43b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e247b4ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e2478fac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e2478fac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e2478fb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e2478fa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e2478fa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e2478fa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e24c204abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e24c20d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e24c1f5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e24c220112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6fbd738082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e245b1ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f, Step #5: .\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-ff818a95c031f6743768ef3311b3e72737608aa4 Step #5: Base64: Ls2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2PCi7Njw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2668 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3022799782 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9504af810, 0x55a95069901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a950699020,0x55a9525310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ff818a95c031f6743768ef3311b3e72737608aa4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3229 processed earlier; will process 7800 files now Step #5: ==96086== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a946fa49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a94d609898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a94d5ec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a94d5ec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a946faad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a946f0bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a946f06355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a946f9cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a949f6bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a949f6bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a949f6bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a949f6bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a949f6bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a949f6bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a949f6bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a949f6bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a949f6bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a949f6bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a94c200f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a948f2db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a948f38be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a948ce4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a948ce4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a948ce5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a948ce4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a948ce4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a948ce4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a94d5eeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a94d5f7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a94d5df699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a94d60a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff84364c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a946f04b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x88,0x49,0xa,0xcd,0x88,0x49,0xa,0xcd,0x88,0x43,0xa,0xcd,0x88,0x41,0xa,0xcd,0x88,0x49,0xa,0xcd,0x88,0x41,0xa,0xcd,0x88,0x43,0x28,0xcd,0x88,0x43, Step #5: \315\210I\012\315\210I\012\315\210C\012\315\210A\012\315\210I\012\315\210A\012\315\210C(\315\210C Step #5: artifact_prefix='./'; Test unit written to ./oom-5f6531242c02c6fcc73e69bf9a37d3dbcbfab617 Step #5: Base64: zYhJCs2ISQrNiEMKzYhBCs2ISQrNiEEKzYhDKM2IQw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2669 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3023269219 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55911996a810, 0x559119b5401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559119b54020,0x55911b9ec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f6531242c02c6fcc73e69bf9a37d3dbcbfab617' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3230 processed earlier; will process 7799 files now Step #5: ==96122== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55911045f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559116ac4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559116aa75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559116aa74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559110465d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5591103c6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5591103c1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559110457c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559113426f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559113426f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559113426f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559113426f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559113426f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559113426f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559113426f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559113426f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559113426f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559113426f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5591156bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5591123e8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5591123f3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55911219fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55911219fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5591121a0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55911219f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55911219f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55911219f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559116aa9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559116ab2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559116a9a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559116ac5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f90d505f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5591103bfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x3d,0x7e,0x2d,0x3d,0x3d,0x1,0x79,0x0,0x65,0x0,0x0,0x29,0x2b,0x24,0x7e,0x24,0x3d,0x7e,0x2d,0x3d,0x3d,0x1,0x79,0x0,0x0,0x0,0x0,0x29,0x24, Step #5: ~$=~-==\001y\000e\000\000)+$~$=~-==\001y\000\000\000\000)$ Step #5: artifact_prefix='./'; Test unit written to ./oom-33a9e544ad8f79e95d42824648618d8a95741044 Step #5: Base64: fiQ9fi09PQF5AGUAACkrJH4kPX4tPT0BeQAAAAApJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2670 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3023739162 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56093aca4810, 0x56093ae8e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56093ae8e020,0x56093cd260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/33a9e544ad8f79e95d42824648618d8a95741044' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3231 processed earlier; will process 7798 files now Step #5: ==96158== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5609317999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560937dfe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560937de15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560937de14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56093179fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560931700b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5609316fb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560931791c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560934760f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560934760f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560934760f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560934760f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560934760f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560934760f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560934760f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560934760f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560934760f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560934760f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5609369f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560933722b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56093372dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5609334d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5609334d9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5609334da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5609334d9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5609334d9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5609334d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560937de3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560937dec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560937dd4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560937dff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fabcede2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5609316f9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0xa,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x4b,0x3a,0x65,0xa,0x2d,0x41,0x3f,0x41,0x73,0x63,0x65,0x7a,0x74,0x7a,0x74,0x20,0x6a,0x4c,0x2d,0x2d,0x2d, Step #5: 0\012=\314\273A---AsK:e\012-A?Asceztzt jL--- Step #5: artifact_prefix='./'; Test unit written to ./oom-ea050422a47d35a830e7b2e7c9766b706c970590 Step #5: Base64: MAo9zLtBLS0tQXNLOmUKLUE/QXNjZXp0enQgakwtLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2671 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3024205233 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5556e06d7810, 0x5556e08c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5556e08c1020,0x5556e27590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ea050422a47d35a830e7b2e7c9766b706c970590' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3232 processed earlier; will process 7797 files now Step #5: ==96194== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5556d71cc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5556dd831898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556dd8145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556dd8144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5556d71d2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5556d7133b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5556d712e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5556d71c4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5556da193f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5556da193f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5556da193f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5556da193f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5556da193f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5556da193f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5556da193f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5556da193f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5556da193f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5556da193f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5556dc428f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5556d9155b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5556d9160be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5556d8f0cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5556d8f0cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5556d8f0d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5556d8f0c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5556d8f0c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5556d8f0c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5556dd816abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5556dd81f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5556dd807699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5556dd832112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fde5abef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5556d712cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0xa1,0xcd,0xa1,0xcd,0x80,0xcd,0xa1,0xcd,0xa1,0xcd,0xa1,0xcd,0xa1,0xcd,0x80,0xcd,0xa1,0xcd,0xa1,0xcd,0xa1,0xcd,0x80,0xcd,0xa1,0xcd,0x80,0xcd,0xa1,0xcd,0x80, Step #5: \315\241\315\241\315\200\315\241\315\241\315\241\315\241\315\200\315\241\315\241\315\241\315\200\315\241\315\200\315\241\315\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-95430593ed2f4d7f388cd05543b2a244ddf54f9f Step #5: Base64: zaHNoc2AzaHNoc2hzaHNgM2hzaHNoc2AzaHNgM2hzYA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2672 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3024675732 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56512c0e3810, 0x56512c2cd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56512c2cd020,0x56512e1650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/95430593ed2f4d7f388cd05543b2a244ddf54f9f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3233 processed earlier; will process 7796 files now Step #5: ==96230== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x565122bd89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56512923d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651292205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651292204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565122bded42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565122b3fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565122b3a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565122bd0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565125b9ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565125b9ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565125b9ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565125b9ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565125b9ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565125b9ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565125b9ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565125b9ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565125b9ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565125b9ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565127e34f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565124b61b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565124b6cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565124918c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565124918c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565124919738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565124918874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565124918874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565124918874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565129222abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56512922b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565129213699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56512923e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa67d05e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565122b38b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xef,0xb7,0xba,0xd6,0xbd,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb2,0xe0,0xbd,0xb3, Step #5: ws:\357\267\272\326\275\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263\340\275\262\340\275\263 Step #5: artifact_prefix='./'; Test unit written to ./oom-cd16becdbf22962c596b2444a0f99f8f3fc92d3e Step #5: Base64: d3M677e61r3gvbPgvbPgvbPgvbPgvbPgvbPgvbLgvbM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2673 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3025141348 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555da1321810, 0x555da150b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555da150b020,0x555da33a30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd16becdbf22962c596b2444a0f99f8f3fc92d3e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3234 processed earlier; will process 7795 files now Step #5: ==96266== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555d97e169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555d9e47b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555d9e45e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555d9e45e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555d97e1cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555d97d7db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555d97d78355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555d97e0ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555d9adddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555d9adddf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555d9adddf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555d9adddf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555d9adddf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555d9adddf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555d9adddf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555d9adddf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555d9adddf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555d9adddf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555d9d072f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555d99d9fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555d99daabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555d99b56c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555d99b56c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555d99b57738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555d99b56874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555d99b56874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555d99b56874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555d9e460abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555d9e469928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555d9e451699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555d9e47c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88514c1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555d97d76b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x2,0x8,0x42,0x42,0x2,0x42,0x0,0x42,0x2,0x3a,0x0,0x42,0x2,0x8,0x42,0x42,0x2,0x42,0x0,0x42,0x2,0x42,0x0,0x42,0x2,0x42,0x0,0x42,0x2,0x42,0x42, Step #5: B\002\010BB\002B\000B\002:\000B\002\010BB\002B\000B\002B\000B\002B\000B\002BB Step #5: artifact_prefix='./'; Test unit written to ./oom-ad5edb7e306521af482a3cb148ff46d593153e4f Step #5: Base64: QgIIQkICQgBCAjoAQgIIQkICQgBCAkIAQgJCAEICQkI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2674 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3025602738 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ae2381810, 0x562ae256b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ae256b020,0x562ae44030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad5edb7e306521af482a3cb148ff46d593153e4f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3235 processed earlier; will process 7794 files now Step #5: ==96302== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562ad8e769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562adf4db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562adf4be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562adf4be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562ad8e7cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562ad8dddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562ad8dd8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562ad8e6ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562adbe3df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562adbe3df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562adbe3df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562adbe3df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562adbe3df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562adbe3df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562adbe3df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562adbe3df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562adbe3df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562adbe3df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ade0d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562adadffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562adae0abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562adabb6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562adabb6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562adabb7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562adabb6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562adabb6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562adabb6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562adf4c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562adf4c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562adf4b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562adf4dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f82a0f35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562ad8dd6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd, Step #5: \015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-0560a3616b976584cd04aea10de22a1311f7c34a Step #5: Base64: DQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2675 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3026056280 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55862912d810, 0x55862931701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558629317020,0x55862b1af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0560a3616b976584cd04aea10de22a1311f7c34a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3236 processed earlier; will process 7793 files now Step #5: ==96338== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55861fc229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558626287898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55862626a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55862626a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55861fc28d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55861fb89b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55861fb84355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55861fc1ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558622be9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558622be9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558622be9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558622be9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558622be9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558622be9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558622be9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558622be9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558622be9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558622be9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558624e7ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558621babb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558621bb6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558621962c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558621962c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558621963738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558621962874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558621962874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558621962874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55862626cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558626275928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55862625d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558626288112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff7ac85e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55861fb82b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xe1,0x9e,0x90,0xe1,0x9f,0x84,0x9,0xa,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: \341\236\220\341\237\204\011\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-60a4a64f3a60079077287d87d861c573e36cc0c0 Step #5: Base64: PHN2Zz48dGV4dD7hnpDhn4QJCjwvdGV4dD48L3N2Zz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2676 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3026523165 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557cd1c92810, 0x557cd1e7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557cd1e7c020,0x557cd3d140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/60a4a64f3a60079077287d87d861c573e36cc0c0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3237 processed earlier; will process 7792 files now Step #5: ==96374== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557cc87879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557ccedec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557ccedcf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557ccedcf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557cc878dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557cc86eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557cc86e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557cc877fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557ccb74ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557ccb74ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557ccb74ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557ccb74ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557ccb74ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557ccb74ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557ccb74ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557ccb74ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557ccb74ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557ccb74ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557ccd9e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557cca710b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557cca71bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557cca4c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557cca4c7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557cca4c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557cca4c7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557cca4c7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557cca4c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557ccedd1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557ccedda928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557ccedc2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557cceded112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe880e18082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557cc86e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xce,0x8b,0xdb,0xbe,0xd7,0xa1,0xda,0xb5,0xc6,0xb0,0xd3,0x81,0xd3,0xb5,0xd2,0xab,0xd3,0x94,0xd3,0x81,0xd3,0xa5,0xd3,0xb9,0xd3,0x8b,0xd3,0xbe,0xd6,0xb0,0xd3,0x81, Step #5: \316\213\333\276\327\241\332\265\306\260\323\201\323\265\322\253\323\224\323\201\323\245\323\271\323\213\323\276\326\260\323\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-b57ca68746e87e5b086469173219b8811bb0dd8c Step #5: Base64: zovbvteh2rXGsNOB07XSq9OU04HTpdO504vTvtaw04E= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2677 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3026992400 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560206598810, 0x56020678201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560206782020,0x56020861a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b57ca68746e87e5b086469173219b8811bb0dd8c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3238 processed earlier; will process 7791 files now Step #5: ==96410== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5601fd08d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5602036f2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602036d55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602036d54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5601fd093d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601fcff4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601fcfef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5601fd085c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560200054f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560200054f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560200054f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560200054f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560200054f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560200054f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560200054f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560200054f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560200054f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560200054f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5602022e9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601ff016b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601ff021be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5601fedcdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5601fedcdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5601fedce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5601fedcd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5601fedcd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5601fedcd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5602036d7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5602036e0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5602036c8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5602036f3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa2c48af082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601fcfedb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe1,0xbc,0x91,0xe1,0xac,0x91,0xa,0xe0,0xac,0xb5,0xe1,0xbc,0x91,0xe1,0xac,0xb5,0xe1,0xbc,0x91,0xe1,0xac,0xb5,0xe1,0xbc,0x91,0xe1,0xac,0xb5,0x27, Step #5: ws:\341\274\221\341\254\221\012\340\254\265\341\274\221\341\254\265\341\274\221\341\254\265\341\274\221\341\254\265' Step #5: artifact_prefix='./'; Test unit written to ./oom-b0dba716a04215ab50a71cccd239832c56d6e245 Step #5: Base64: d3M64byR4ayRCuCsteG8keGsteG8keGsteG8keGstSc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2678 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3027457777 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5579eea88810, 0x5579eec7201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5579eec72020,0x5579f0b0a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b0dba716a04215ab50a71cccd239832c56d6e245' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3239 processed earlier; will process 7790 files now Step #5: ==96446== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5579e557d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5579ebbe2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5579ebbc55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5579ebbc54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5579e5583d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5579e54e4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5579e54df355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5579e5575c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5579e8544f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5579e8544f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5579e8544f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5579e8544f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5579e8544f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5579e8544f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5579e8544f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5579e8544f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5579e8544f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5579e8544f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579ea7d9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5579e7506b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5579e7511be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5579e72bdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5579e72bdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5579e72be738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5579e72bd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5579e72bd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5579e72bd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5579ebbc7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5579ebbd0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5579ebbb8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5579ebbe3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ea3e79082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5579e54ddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xc5,0xb3,0xdd,0x8c,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xde,0x8c,0xc5,0x84,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xde,0x8c,0xc5,0xa3,0xc5,0xa3,0x22, Step #5: \"\305\263\335\214\335\204\305\204\335\204\336\214\305\204\335\204\305\204\335\204\305\204\335\204\336\214\305\243\305\243\" Step #5: artifact_prefix='./'; Test unit written to ./oom-635e989469b75d5950527a6825af933323bd4992 Step #5: Base64: IsWz3YzdhMWE3YTejMWE3YTFhN2ExYTdhN6MxaPFoyI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2679 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3027925065 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56327a885810, 0x56327aa6f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56327aa6f020,0x56327c9070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/635e989469b75d5950527a6825af933323bd4992' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3240 processed earlier; will process 7789 files now Step #5: #1 pulse cov: 3430 ft: 3431 exec/s: 0 rss: 169Mb Step #5: ==96482== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56327137a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5632779df898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5632779c25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5632779c24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563271380d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5632712e1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5632712dc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563271372c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563274341f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563274341f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563274341f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563274341f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563274341f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563274341f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563274341f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563274341f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563274341f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563274341f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5632765d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563273303b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56327330ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5632730bac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5632730bac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5632730bb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5632730ba874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5632730ba874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5632730ba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5632779c4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5632779cd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5632779b5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5632779e0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0401721082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5632712dab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x30,0x5c,0x30,0x5c,0x30,0x5c,0x30,0x5c,0x30,0x5c,0x30,0x5c,0x30,0x5c,0x30,0x5c,0x30,0x5c,0x30,0x5c,0x30,0x5c,0x30,0x5c,0x30,0x5c,0x30,0x5c,0x30,0x5c,0x30, Step #5: \\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0 Step #5: artifact_prefix='./'; Test unit written to ./oom-062e65a8d0cd937d074357c6ec3275c04e1750b8 Step #5: Base64: XDBcMFwwXDBcMFwwXDBcMFwwXDBcMFwwXDBcMFwwXDA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2680 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3028431040 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56149952b810, 0x56149971501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561499715020,0x56149b5ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/062e65a8d0cd937d074357c6ec3275c04e1750b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3242 processed earlier; will process 7787 files now Step #5: #1 pulse cov: 3715 ft: 3716 exec/s: 0 rss: 169Mb Step #5: ==96518== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5614900209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561496685898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5614966685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5614966684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561490026d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56148ff87b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56148ff82355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561490018c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561492fe7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561492fe7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561492fe7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561492fe7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561492fe7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561492fe7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561492fe7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561492fe7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561492fe7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561492fe7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56149527cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561491fa9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561491fb4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561491d60c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561491d60c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561491d61738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561491d60874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561491d60874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561491d60874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56149666aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561496673928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56149665b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561496686112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53ebcd5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56148ff80b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x90,0xa,0xc5,0x90,0xa,0xcd,0x90,0xa,0xcd,0x90,0xa,0xcd,0x90,0xa,0xcd,0x8a,0xa,0xcd,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed, Step #5: \315\220\012\305\220\012\315\220\012\315\220\012\315\220\012\315\212\012\315\220\012\355\226\220\355\220\220\012\355\226\220\355 Step #5: artifact_prefix='./'; Test unit written to ./oom-9b807cbb09c1914f9e88155138c6e403d12a1265 Step #5: Base64: zZAKxZAKzZAKzZAKzZAKzYoKzZAK7ZaQ7ZCQCu2WkO0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2681 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3028938580 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4a6dce810, 0x55e4a6fb801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4a6fb8020,0x55e4a8e500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9b807cbb09c1914f9e88155138c6e403d12a1265' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3244 processed earlier; will process 7785 files now Step #5: ==96554== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e49d8c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4a3f28898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4a3f0b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4a3f0b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e49d8c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e49d82ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e49d825355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e49d8bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4a088af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4a088af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4a088af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4a088af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4a088af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4a088af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4a088af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4a088af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4a088af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4a088af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4a2b1ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e49f84cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e49f857be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e49f603c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e49f603c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e49f604738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e49f603874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e49f603874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e49f603874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4a3f0dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4a3f16928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4a3efe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4a3f29112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b977f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e49d823b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc3,0xbc,0xd6,0xbb,0xc3,0xbc,0xd6,0xbb,0xc3,0xbc,0xd6,0xbb,0xc3,0xbc,0xd6,0xbb,0xc3,0xbc,0xd6,0xbb,0xc3,0xbc,0xd6,0xbb,0xc3,0xbc,0xd6,0xbb,0xc3,0xbc,0xd6,0xbb, Step #5: \303\274\326\273\303\274\326\273\303\274\326\273\303\274\326\273\303\274\326\273\303\274\326\273\303\274\326\273\303\274\326\273 Step #5: artifact_prefix='./'; Test unit written to ./oom-6bd635893a2ab31f78df75e492c017f64ce2e7cd Step #5: Base64: w7zWu8O81rvDvNa7w7zWu8O81rvDvNa7w7zWu8O81rs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2682 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3029404576 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5641557e6810, 0x5641559d001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5641559d0020,0x5641578680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bd635893a2ab31f78df75e492c017f64ce2e7cd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3245 processed earlier; will process 7784 files now Step #5: ==96590== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56414c2db9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564152940898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5641529235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5641529234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56414c2e1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56414c242b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56414c23d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56414c2d3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56414f2a2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56414f2a2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56414f2a2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56414f2a2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56414f2a2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56414f2a2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56414f2a2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56414f2a2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56414f2a2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56414f2a2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564151537f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56414e264b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56414e26fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56414e01bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56414e01bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56414e01c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56414e01b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56414e01b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56414e01b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564152925abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56415292e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564152916699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564152941112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d7b69e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56414c23bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0xab,0xa,0x2b,0xdb,0x7f,0xff,0xff,0xff,0xff,0xff,0x73,0x65,0x46,0x6f,0x72, Step #5: +\012+\012+\012+\012+\012\012+\012+\012+\012\253\012+\333\177\377\377\377\377\377seFor Step #5: artifact_prefix='./'; Test unit written to ./oom-0b13d4ecd4c386a7b62b858469a1a4b4de6284ad Step #5: Base64: KworCisKKworCgorCisKKwqrCivbf///////c2VGb3I= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2683 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3029877912 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e8bfd27810, 0x55e8bff1101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e8bff11020,0x55e8c1da90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b13d4ecd4c386a7b62b858469a1a4b4de6284ad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3246 processed earlier; will process 7783 files now Step #5: ==96626== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e8b681c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e8bce81898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e8bce645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e8bce644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e8b6822d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e8b6783b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e8b677e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e8b6814c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e8b97e3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e8b97e3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e8b97e3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e8b97e3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e8b97e3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e8b97e3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e8b97e3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e8b97e3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e8b97e3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e8b97e3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e8bba78f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e8b87a5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e8b87b0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e8b855cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e8b855cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e8b855d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e8b855c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e8b855c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e8b855c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e8bce66abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e8bce6f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e8bce57699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e8bce82112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe7a3c0b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e8b677cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x2,0x0,0x2,0x6c,0x1e,0x2,0x0,0x3,0x2c,0x5e,0x2,0x0,0x2,0x6c,0x5e,0x2,0x0,0x2,0x6c,0x5e,0x2,0x0,0x6d,0x0,0x1,0x0,0x0,0x5,0x1,0x31,0x1a, Step #5: ^\002\000\002l\036\002\000\003,^\002\000\002l^\002\000\002l^\002\000m\000\001\000\000\005\0011\032 Step #5: artifact_prefix='./'; Test unit written to ./oom-4f278604d2469fefb86aaee8a76ae4d1b3c75314 Step #5: Base64: XgIAAmweAgADLF4CAAJsXgIAAmxeAgBtAAEAAAUBMRo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2684 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3030343049 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fff2d98810, 0x55fff2f8201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fff2f82020,0x55fff4e1a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f278604d2469fefb86aaee8a76ae4d1b3c75314' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3247 processed earlier; will process 7782 files now Step #5: ==96662== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ffe988d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ffefef2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ffefed55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ffefed54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ffe9893d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ffe97f4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ffe97ef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ffe9885c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ffec854f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ffec854f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ffec854f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ffec854f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ffec854f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ffec854f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ffec854f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ffec854f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ffec854f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ffec854f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ffeeae9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ffeb816b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ffeb821be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ffeb5cdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ffeb5cdc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ffeb5ce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ffeb5cd874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ffeb5cd874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ffeb5cd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ffefed7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ffefee0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ffefec8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ffefef3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1fe988b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ffe97edb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7b,0x38,0x7d,0x24,0x7b,0x32,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x32,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d, Step #5: ${8}${2}${8}${2}${8}${8}${8}${8} Step #5: artifact_prefix='./'; Test unit written to ./oom-1111a46571ddb13df1261ffb4d811103aaa30ddf Step #5: Base64: JHs4fSR7Mn0kezh9JHsyfSR7OH0kezh9JHs4fSR7OH0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2685 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3030816297 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56067800b810, 0x5606781f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5606781f5020,0x56067a08d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1111a46571ddb13df1261ffb4d811103aaa30ddf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3248 processed earlier; will process 7781 files now Step #5: ==96698== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56066eb009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560675165898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606751485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606751484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56066eb06d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56066ea67b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56066ea62355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56066eaf8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560671ac7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560671ac7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560671ac7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560671ac7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560671ac7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560671ac7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560671ac7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560671ac7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560671ac7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560671ac7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560673d5cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560670a89b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560670a94be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560670840c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560670840c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560670841738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560670840874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560670840874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560670840874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56067514aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560675153928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56067513b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560675166112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f92d072f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56066ea60b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x11,0x0,0x11,0x0,0x11,0x0,0x11,0x0,0x11,0x0,0x11,0x0,0x11,0x0,0x11,0x0,0x11,0x0,0x11,0x0,0x11,0x0,0x11,0x0,0x11,0x0,0x11,0x0,0x11,0x0,0x11, Step #5: \002\021\000\021\000\021\000\021\000\021\000\021\000\021\000\021\000\021\000\021\000\021\000\021\000\021\000\021\000\021\000\021 Step #5: artifact_prefix='./'; Test unit written to ./oom-89497d53eb0e6d4fea6a96ba223f7a493903d9e3 Step #5: Base64: AhEAEQARABEAEQARABEAEQARABEAEQARABEAEQARABE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2686 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3031283213 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f9e5552810, 0x55f9e573c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f9e573c020,0x55f9e75d40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/89497d53eb0e6d4fea6a96ba223f7a493903d9e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3249 processed earlier; will process 7780 files now Step #5: ==96734== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f9dc0479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f9e26ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f9e268f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f9e268f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f9dc04dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f9dbfaeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f9dbfa9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f9dc03fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f9df00ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f9df00ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f9df00ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f9df00ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f9df00ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f9df00ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f9df00ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f9df00ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f9df00ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f9df00ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f9e12a3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f9ddfd0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f9ddfdbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f9ddd87c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f9ddd87c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f9ddd88738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f9ddd87874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f9ddd87874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f9ddd87874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f9e2691abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f9e269a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f9e2682699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f9e26ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa32b099082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f9dbfa7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x24,0x3d,0x7e,0x2d,0x3d,0x3d,0x1,0x79,0x0,0x0,0x0,0x0,0x29,0x24, Step #5: tttttttttttttttttt$=~-==\001y\000\000\000\000)$ Step #5: artifact_prefix='./'; Test unit written to ./oom-106b16270044bfa302253fb8d0977e2144ecb346 Step #5: Base64: dHR0dHR0dHR0dHR0dHR0dHR0JD1+LT09AXkAAAAAKSQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2687 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3031752138 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5593266d0810, 0x5593268ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5593268ba020,0x5593287520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/106b16270044bfa302253fb8d0977e2144ecb346' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3250 processed earlier; will process 7779 files now Step #5: ==96770== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55931d1c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55932382a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55932380d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55932380d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55931d1cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55931d12cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55931d127355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55931d1bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55932018cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55932018cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55932018cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55932018cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55932018cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55932018cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55932018cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55932018cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55932018cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55932018cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559322421f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55931f14eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55931f159be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55931ef05c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55931ef05c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55931ef06738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55931ef05874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55931ef05874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55931ef05874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55932380fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559323818928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559323800699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55932382b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f62991e1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55931d125b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x24,0x39,0x2f,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x38,0x30,0x38,0x0,0x0,0x7c,0x9,0xa,0x0,0x24,0xa,0x7c,0x2f, Step #5: \000$9/223372036854775808\000\000|\011\012\000$\012|/ Step #5: artifact_prefix='./'; Test unit written to ./oom-1d61ae25fdfe566e4cb9a085f2ec880192f7ed3f Step #5: Base64: ACQ5LzIyMzM3MjAzNjg1NDc3NTgwOAAAfAkKACQKfC8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2688 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3032220322 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5619f605e810, 0x5619f624801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5619f6248020,0x5619f80e00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1d61ae25fdfe566e4cb9a085f2ec880192f7ed3f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3251 processed earlier; will process 7778 files now Step #5: ==96806== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5619ecb539c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5619f31b8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5619f319b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5619f319b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5619ecb59d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5619ecabab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5619ecab5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5619ecb4bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5619efb1af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5619efb1af10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5619efb1af10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5619efb1af10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5619efb1af10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5619efb1af10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5619efb1af10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5619efb1af10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5619efb1af10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5619efb1af10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5619f1daff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5619eeadcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5619eeae7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5619ee893c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5619ee893c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5619ee894738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5619ee893874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5619ee893874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5619ee893874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5619f319dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5619f31a6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5619f318e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5619f31b9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f122b2d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5619ecab3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x4f,0x27,0xd1,0xa1,0x27,0x45,0x27,0x5c,0xd1,0xa1,0x27,0x45,0x27,0x5c,0xca,0xb6,0xd1,0xa1,0x27,0x45,0x27,0x5c,0xd1,0xa1,0x27,0x5c,0x2f,0xab,0xad,0x27,0x5c, Step #5: dO'\321\241'E'\\\321\241'E'\\\312\266\321\241'E'\\\321\241'\\/\253\255'\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-cfd48b8fa312854eb08f47105a2b3e919dab0d96 Step #5: Base64: ZE8n0aEnRSdc0aEnRSdcyrbRoSdFJ1zRoSdcL6utJ1w= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2689 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3032683219 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561864b06810, 0x561864cf001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561864cf0020,0x561866b880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cfd48b8fa312854eb08f47105a2b3e919dab0d96' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3252 processed earlier; will process 7777 files now Step #5: #1 pulse cov: 3504 ft: 3505 exec/s: 0 rss: 171Mb Step #5: ==96842== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56185b5fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561861c60898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561861c435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561861c434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56185b601d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56185b562b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56185b55d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56185b5f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56185e5c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56185e5c2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56185e5c2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56185e5c2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56185e5c2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56185e5c2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56185e5c2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56185e5c2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56185e5c2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56185e5c2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561860857f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56185d584b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56185d58fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56185d33bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56185d33bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56185d33c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56185d33b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56185d33b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56185d33b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561861c45abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561861c4e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561861c36699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561861c61112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d7d015082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56185b55bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x7e,0x7e,0x7e,0x7e,0x7e,0x24,0x4,0x32,0x34,0x2d,0x3d,0x3e,0x34,0x2d,0x3d,0x3e,0xde,0xae,0xde,0xae,0x2d,0x3d,0x3e,0x2d,0x3d,0x24,0xb2,0xb2,0xb2,0xb2,0x24, Step #5: '~~~~~$\00424-=>4-=>\336\256\336\256-=>-=$\262\262\262\262$ Step #5: artifact_prefix='./'; Test unit written to ./oom-5d47d3dc4b3585090e4a4df2593659c9cb05ceeb Step #5: Base64: J35+fn5+JAQyNC09PjQtPT7ert6uLT0+LT0ksrKysiQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2690 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3033193989 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564de3403810, 0x564de35ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564de35ed020,0x564de54850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5d47d3dc4b3585090e4a4df2593659c9cb05ceeb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3254 processed earlier; will process 7775 files now Step #5: ==96878== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564dd9ef89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564de055d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564de05405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564de05404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564dd9efed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564dd9e5fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564dd9e5a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564dd9ef0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564ddcebff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564ddcebff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564ddcebff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564ddcebff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564ddcebff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564ddcebff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564ddcebff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564ddcebff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564ddcebff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564ddcebff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564ddf154f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564ddbe81b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564ddbe8cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564ddbc38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564ddbc38c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564ddbc39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564ddbc38874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564ddbc38874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564ddbc38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564de0542abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564de054b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564de0533699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564de055e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1507240082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564dd9e58b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85, Step #5: \302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-aade3f23bf0b0c813fcbd1b7a7fae85cc1a90ff0 Step #5: Base64: woXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2691 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3033645094 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f8182c0810, 0x55f8184aa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f8184aa020,0x55f81a3420e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aade3f23bf0b0c813fcbd1b7a7fae85cc1a90ff0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3255 processed earlier; will process 7774 files now Step #5: ==96914== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f80edb59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f81541a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8153fd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8153fd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f80edbbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f80ed1cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f80ed17355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f80edadc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f811d7cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f811d7cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f811d7cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f811d7cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f811d7cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f811d7cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f811d7cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f811d7cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f811d7cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f811d7cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f814011f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f810d3eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f810d49be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f810af5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f810af5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f810af6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f810af5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f810af5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f810af5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f8153ffabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f815408928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f8153f0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f81541b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0487549082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f80ed15b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x9,0x2c,0x20,0x2c,0x66,0x2c,0x32,0x2c,0x60,0x2c,0x30,0x2c,0x60,0x2c,0x3c,0x2c,0x66,0x2c,0x66,0x2c,0x30,0x3c,0x17,0x2c,0xf3,0xe1,0x81,0x6e,0x21,0x5f,0x28,0x30, Step #5: \011, ,f,2,`,0,`,<,f,f,0<\027,\363\341\201n!_(0 Step #5: artifact_prefix='./'; Test unit written to ./oom-115b261a60ff717faefe6537ecda3c00741f7e63 Step #5: Base64: CSwgLGYsMixgLDAsYCw8LGYsZiwwPBcs8+GBbiFfKDA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2692 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3034230698 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5641523dc810, 0x5641525c601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5641525c6020,0x56415445e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/115b261a60ff717faefe6537ecda3c00741f7e63' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3256 processed earlier; will process 7773 files now Step #5: ==96950== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564148ed19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56414f536898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56414f5195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56414f5194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564148ed7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564148e38b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564148e33355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564148ec9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56414be98f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56414be98f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56414be98f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56414be98f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56414be98f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56414be98f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56414be98f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56414be98f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56414be98f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56414be98f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56414e12df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56414ae5ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56414ae65be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56414ac11c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56414ac11c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56414ac12738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56414ac11874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56414ac11874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56414ac11874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56414f51babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56414f524928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56414f50c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56414f537112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe41cf2e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564148e31b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5b,0x5b,0x3f,0x26,0x3f,0x2c,0x3f,0x24,0x2c,0x3f,0x2c,0x26,0x3f,0x2c,0x3d,0x24,0x2c,0x26,0x3f,0x2c,0x3f,0x2c,0x3f,0x26,0x3f,0x2c,0x3d,0x2c,0x3f,0x5d,0x2c, Step #5: [[[?&?,?$,?,&?,=$,&?,?,?&?,=,?], Step #5: artifact_prefix='./'; Test unit written to ./oom-d1ec2787ae225845adf32b9ca433936940486c42 Step #5: Base64: W1tbPyY/LD8kLD8sJj8sPSQsJj8sPyw/Jj8sPSw/XSw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2693 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3034698820 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5602c6638810, 0x5602c682201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5602c6822020,0x5602c86ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d1ec2787ae225845adf32b9ca433936940486c42' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3257 processed earlier; will process 7772 files now Step #5: ==96986== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5602bd12d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5602c3792898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602c37755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602c37754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5602bd133d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5602bd094b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5602bd08f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5602bd125c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5602c00f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5602c00f4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5602c00f4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5602c00f4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5602c00f4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5602c00f4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5602c00f4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5602c00f4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5602c00f4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5602c00f4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5602c2389f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5602bf0b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5602bf0c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5602bee6dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5602bee6dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5602bee6e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5602bee6d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5602bee6d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5602bee6d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5602c3777abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5602c3780928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5602c3768699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5602c3793112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2eae67f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5602bd08db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x58, Step #5: - - - - - - - - - - - - - - - -X Step #5: artifact_prefix='./'; Test unit written to ./oom-486e2381b207d10f45fe85ff38b783946b30f91e Step #5: Base64: LSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLVg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2694 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3035186697 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564bef41b810, 0x564bef60501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564bef605020,0x564bf149d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/486e2381b207d10f45fe85ff38b783946b30f91e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3258 processed earlier; will process 7771 files now Step #5: ==97022== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564be5f109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564bec575898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564bec5585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564bec5584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564be5f16d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564be5e77b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564be5e72355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564be5f08c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564be8ed7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564be8ed7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564be8ed7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564be8ed7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564be8ed7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564be8ed7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564be8ed7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564be8ed7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564be8ed7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564be8ed7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564beb16cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564be7e99b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564be7ea4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564be7c50c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564be7c50c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564be7c51738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564be7c50874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564be7c50874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564be7c50874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564bec55aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564bec563928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564bec54b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564bec576112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efdcb26b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564be5e70b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x8,0x0,0x7,0x2e,0x2b,0x42,0xdb,0xbe,0x7c,0xdb,0xbe,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x24,0x6e,0x24,0x3,0x3,0x52, Step #5: - \010\000\007.+B\333\276|\333\276+++++++++++++$n$\003\003R Step #5: artifact_prefix='./'; Test unit written to ./oom-d38514d95b4c160e7692818e0b26fe368b734335 Step #5: Base64: LSAIAAcuK0LbvnzbvisrKysrKysrKysrKyskbiQDA1I= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2695 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3035659170 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a96b33b810, 0x55a96b52501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a96b525020,0x55a96d3bd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d38514d95b4c160e7692818e0b26fe368b734335' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3259 processed earlier; will process 7770 files now Step #5: ==97058== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a961e309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a968495898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9684785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9684784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a961e36d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a961d97b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a961d92355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a961e28c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a964df7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a964df7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a964df7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a964df7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a964df7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a964df7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a964df7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a964df7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a964df7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a964df7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a96708cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a963db9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a963dc4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a963b70c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a963b70c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a963b71738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a963b70874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a963b70874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a963b70874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a96847aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a968483928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a96846b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a968496112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f46b8e3d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a961d90b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x3f,0x5b,0x3f,0x5b,0x3f,0x5b,0x3f,0x5b,0x3f,0x5b,0x3f,0x5b,0x3f,0x5b,0x3f,0x5b,0x3f,0x5b,0x3f,0x5b,0x3f,0x5b,0x3f,0x5b,0x3f,0x5b,0x3f,0x5b,0x3f,0x5b,0x3f, Step #5: [?[?[?[?[?[?[?[?[?[?[?[?[?[?[?[? Step #5: artifact_prefix='./'; Test unit written to ./oom-ee7b75f73f88ab3961bdd310268765a7544e2aef Step #5: Base64: Wz9bP1s/Wz9bP1s/Wz9bP1s/Wz9bP1s/Wz9bP1s/Wz8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2696 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3036123547 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f211982810, 0x55f211b6c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f211b6c020,0x55f213a040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee7b75f73f88ab3961bdd310268765a7544e2aef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3260 processed earlier; will process 7769 files now Step #5: ==97094== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f2084779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f20eadc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f20eabf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f20eabf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f20847dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f2083deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f2083d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f20846fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f20b43ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f20b43ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f20b43ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f20b43ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f20b43ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f20b43ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f20b43ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f20b43ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f20b43ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f20b43ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f20d6d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f20a400b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f20a40bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f20a1b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f20a1b7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f20a1b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f20a1b7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f20a1b7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f20a1b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f20eac1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f20eaca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f20eab2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f20eadd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f878e9da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f2083d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x20,0x2f,0x67,0x2f,0x20,0x48,0x54,0x54,0x50,0x2f,0x31,0x2e,0x31,0xd,0xa,0x68,0x68,0x3a,0xd,0xa,0x68,0x30,0x68,0x68,0x68,0x3a,0xd,0xa,0xd,0xa,0x2d, Step #5: \002 /g/ HTTP/1.1\015\012hh:\015\012h0hhh:\015\012\015\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-4c820481ddf9aec061b843ea08ad15bf323a856e Step #5: Base64: AiAvZy8gSFRUUC8xLjENCmhoOg0KaDBoaGg6DQoNCi0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2697 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3036590276 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5558a8b46810, 0x5558a8d3001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5558a8d30020,0x5558aabc80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4c820481ddf9aec061b843ea08ad15bf323a856e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3261 processed earlier; will process 7768 files now Step #5: ==97130== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55589f63b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5558a5ca0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5558a5c835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5558a5c834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55589f641d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55589f5a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55589f59d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55589f633c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5558a2602f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5558a2602f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5558a2602f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5558a2602f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5558a2602f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5558a2602f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5558a2602f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5558a2602f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5558a2602f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5558a2602f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5558a4897f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5558a15c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5558a15cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5558a137bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5558a137bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5558a137c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5558a137b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5558a137b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5558a137b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5558a5c85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5558a5c8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5558a5c76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5558a5ca1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1f17f5c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55589f59bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xef,0xb7,0xba,0xd7,0x81,0xe0,0xbe,0x81,0xe0,0xbc,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81, Step #5: ws:\357\267\272\327\201\340\276\201\340\274\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-14e1caedef76b77ba0f8856ec35a6cfca1284ab4 Step #5: Base64: d3M677e614HgvoHgvIHgvoHgvoHgvoHgvoHgvoHgvoE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2698 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3037055312 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558ae159f810, 0x558ae178901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558ae1789020,0x558ae36210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/14e1caedef76b77ba0f8856ec35a6cfca1284ab4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3262 processed earlier; will process 7767 files now Step #5: #1 pulse cov: 4060 ft: 4061 exec/s: 0 rss: 170Mb Step #5: ==97166== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558ad80949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558ade6f9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558ade6dc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558ade6dc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558ad809ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558ad7ffbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558ad7ff6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558ad808cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558adb05bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558adb05bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558adb05bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558adb05bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558adb05bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558adb05bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558adb05bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558adb05bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558adb05bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558adb05bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558add2f0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ada01db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ada028be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ad9dd4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ad9dd4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ad9dd5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ad9dd4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ad9dd4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ad9dd4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558ade6deabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558ade6e7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558ade6cf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558ade6fa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb920930082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558ad7ff4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x45,0x78,0x65,0x63,0x5d,0x0,0x4f,0x4f,0x4d,0x53,0x63,0x6f,0x72,0x65,0x41,0x64,0x6a,0x75,0x73,0x74,0x3d,0x2d,0x31,0x34,0x34,0x30,0x35,0x34,0x39,0x30,0x30, Step #5: [Exec]\000OOMScoreAdjust=-144054900 Step #5: artifact_prefix='./'; Test unit written to ./oom-cc0ddec603de935544c63ecc61e353603fe7a5eb Step #5: Base64: W0V4ZWNdAE9PTVNjb3JlQWRqdXN0PS0xNDQwNTQ5MDA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2699 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3037559872 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb28a19810, 0x55bb28c0301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb28c03020,0x55bb2aa9b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cc0ddec603de935544c63ecc61e353603fe7a5eb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3264 processed earlier; will process 7765 files now Step #5: ==97202== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bb1f50e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb25b73898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb25b565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb25b564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb1f514d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb1f475b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb1f470355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb1f506c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb224d5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb224d5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb224d5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb224d5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb224d5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb224d5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb224d5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb224d5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb224d5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb224d5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb2476af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb21497b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb214a2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb2124ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb2124ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb2124f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb2124e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb2124e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb2124e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb25b58abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb25b61928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb25b49699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb25b74112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7641729082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb1f46eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x16,0x22,0x2a,0xd0,0xa4,0xd0,0xae,0x2a,0xd0,0xa4,0xd0,0xae,0x16,0x22,0x28,0xd0,0xa4,0xd0,0xae,0x2a,0xd0,0xa4,0xd0,0xae,0x2a,0x0,0x5b,0x5c,0x2a,0x5b, Step #5: HU\026\"*\320\244\320\256*\320\244\320\256\026\"(\320\244\320\256*\320\244\320\256*\000[\\*[ Step #5: artifact_prefix='./'; Test unit written to ./oom-38c8993901d1e29c8ddfb67be4d38e223aa17e26 Step #5: Base64: SFUWIirQpNCuKtCk0K4WIijQpNCuKtCk0K4qAFtcKls= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2700 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3038027628 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560157c10810, 0x560157dfa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560157dfa020,0x560159c920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/38c8993901d1e29c8ddfb67be4d38e223aa17e26' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3265 processed earlier; will process 7764 files now Step #5: ==97238== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56014e7059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560154d6a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560154d4d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560154d4d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56014e70bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56014e66cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56014e667355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56014e6fdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601516ccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601516ccf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601516ccf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601516ccf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601516ccf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601516ccf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601516ccf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601516ccf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601516ccf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601516ccf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560153961f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56015068eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560150699be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560150445c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560150445c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560150446738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560150445874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560150445874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560150445874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560154d4fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560154d58928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560154d40699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560154d6b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9fff821082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56014e665b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x80,0x80,0xed,0x98,0x80,0xed,0x90,0xa0,0xed,0x98,0x80,0xed,0x90,0x80,0xed,0xed,0x98,0x80,0xed,0x98,0x80,0xed,0x90,0x80,0xed,0x98,0x80,0xed,0x90,0xed, Step #5: \363\240\200\200\355\230\200\355\220\240\355\230\200\355\220\200\355\355\230\200\355\230\200\355\220\200\355\230\200\355\220\355 Step #5: artifact_prefix='./'; Test unit written to ./oom-0ae00f9dfcb2b7d27ad373d4d7189c3adb7e56d9 Step #5: Base64: 86CAgO2YgO2QoO2YgO2QgO3tmIDtmIDtkIDtmIDtkO0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2701 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3038490572 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5603ff046810, 0x5603ff23001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5603ff230020,0x5604010c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0ae00f9dfcb2b7d27ad373d4d7189c3adb7e56d9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3266 processed earlier; will process 7763 files now Step #5: ==97274== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5603f5b3b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5603fc1a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5603fc1835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5603fc1834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5603f5b41d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5603f5aa2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5603f5a9d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5603f5b33c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5603f8b02f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5603f8b02f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5603f8b02f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5603f8b02f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5603f8b02f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5603f8b02f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5603f8b02f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5603f8b02f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5603f8b02f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5603f8b02f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5603fad97f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5603f7ac4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5603f7acfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5603f787bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5603f787bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5603f787c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5603f787b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5603f787b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5603f787b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5603fc185abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5603fc18e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5603fc176699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5603fc1a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d7e775082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5603f5a9bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xda,0xa5,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0x80,0x8c, Step #5: ws:\332\245\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\200\214 Step #5: artifact_prefix='./'; Test unit written to ./oom-670bb5afc2af7a399e3b45862696c2a1d7e4e5e0 Step #5: Base64: d3M62qXit7/it7/it7/it7/it7/it7/it7/it7/igIw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2702 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3038954835 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5608736f7810, 0x5608738e101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5608738e1020,0x5608757790e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/670bb5afc2af7a399e3b45862696c2a1d7e4e5e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3267 processed earlier; will process 7762 files now Step #5: ==97310== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56086a1ec9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560870851898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608708345dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608708344fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56086a1f2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56086a153b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56086a14e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56086a1e4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56086d1b3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56086d1b3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56086d1b3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56086d1b3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56086d1b3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56086d1b3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56086d1b3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56086d1b3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56086d1b3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56086d1b3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56086f448f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56086c175b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56086c180be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56086bf2cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56086bf2cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56086bf2d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56086bf2c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56086bf2c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56086bf2c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560870836abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56087083f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560870827699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560870852112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe051364082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56086a14cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x63,0x6f,0x6e,0x72,0x65,0x6e,0x72,0x65,0x65,0x6e,0x67,0x3e,0x3c,0x63,0x6f,0x67,0x72,0x65,0x6e,0x67,0x63,0x6f,0x3e,0x22,0x63,0x6f,0x6e,0x72,0x67,0x72,0x65, Step #5: \"conrgre Step #5: artifact_prefix='./'; Test unit written to ./oom-a44ca94c654d14e2ee7dbc5efa652f1dd9fe1031 Step #5: Base64: PGNvbnJlbnJlZW5nPjxjb2dyZW5nY28+ImNvbnJncmU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2703 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3039412942 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca9262d810, 0x55ca9281701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca92817020,0x55ca946af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a44ca94c654d14e2ee7dbc5efa652f1dd9fe1031' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3268 processed earlier; will process 7761 files now Step #5: ==97346== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ca891229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca8f787898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca8f76a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca8f76a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca89128d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca89089b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca89084355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca8911ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca8c0e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca8c0e9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca8c0e9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca8c0e9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca8c0e9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca8c0e9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca8c0e9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca8c0e9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca8c0e9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca8c0e9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca8e37ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca8b0abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca8b0b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca8ae62c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca8ae62c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca8ae63738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca8ae62874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca8ae62874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca8ae62874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca8f76cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca8f775928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca8f75d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca8f788112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1b4f5cb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca89082b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xa,0xd8,0x80,0xe0,0xb9,0x82,0x4,0x0,0x0,0xa,0x2d,0x20,0x2b,0x2f,0x76,0x38,0x0,0x0,0x3a,0xd8,0x80,0x4,0x25,0x0,0x1,0x0,0x25,0x0,0x1,0x0,0xa0, Step #5: \000\012\330\200\340\271\202\004\000\000\012- +/v8\000\000:\330\200\004%\000\001\000%\000\001\000\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-249e4126f5fe66a91d169e955ba357b07035d4b2 Step #5: Base64: AArYgOC5ggQAAAotICsvdjgAADrYgAQlAAEAJQABAKA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2704 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3039879313 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5634b9d41810, 0x5634b9f2b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5634b9f2b020,0x5634bbdc30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/249e4126f5fe66a91d169e955ba357b07035d4b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3269 processed earlier; will process 7760 files now Step #5: ==97382== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5634b08369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5634b6e9b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634b6e7e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634b6e7e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5634b083cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5634b079db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5634b0798355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5634b082ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5634b37fdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5634b37fdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5634b37fdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5634b37fdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5634b37fdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5634b37fdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5634b37fdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5634b37fdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5634b37fdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5634b37fdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5634b5a92f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5634b27bfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5634b27cabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5634b2576c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5634b2576c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5634b2577738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5634b2576874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5634b2576874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5634b2576874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5634b6e80abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5634b6e89928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5634b6e71699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5634b6e9c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0fd78a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5634b0796b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x7e,0x7e,0x7e,0x7e,0x7e,0x24,0x4,0x32,0x34,0x2d,0x3d,0x3e,0x34,0x2d,0x7d,0x3e,0xde,0xae,0xde,0xae,0x2d,0x3d,0x3e,0x2d,0x3d,0x24,0xb2,0xb2,0xb2,0xb2,0x24, Step #5: '~~~~~$\00424-=>4-}>\336\256\336\256-=>-=$\262\262\262\262$ Step #5: artifact_prefix='./'; Test unit written to ./oom-2e7317eaaf410953cf1e5e9e9974a0717f24315c Step #5: Base64: J35+fn5+JAQyNC09PjQtfT7ert6uLT0+LT0ksrKysiQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2705 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3040350837 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a5e6d64810, 0x55a5e6f4e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a5e6f4e020,0x55a5e8de60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2e7317eaaf410953cf1e5e9e9974a0717f24315c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3270 processed earlier; will process 7759 files now Step #5: ==97418== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a5dd8599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a5e3ebe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a5e3ea15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a5e3ea14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a5dd85fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a5dd7c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a5dd7bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a5dd851c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a5e0820f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a5e0820f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a5e0820f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a5e0820f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a5e0820f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a5e0820f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a5e0820f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a5e0820f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a5e0820f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a5e0820f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a5e2ab5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a5df7e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a5df7edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a5df599c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a5df599c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a5df59a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a5df599874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a5df599874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a5df599874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a5e3ea3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a5e3eac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a5e3e94699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a5e3ebf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdba3149082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a5dd7b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc7,0x80,0xc8,0x80,0xc8,0x80,0xc8,0x9f,0xc8,0x80,0xc8,0x9f,0xca,0x9f,0xc8,0x80,0xc8,0x80,0xc7,0x9f,0xca,0x82,0xc8,0x9f,0xc8,0x80,0xc8,0x80,0xc8,0x9f,0xca,0x80, Step #5: \307\200\310\200\310\200\310\237\310\200\310\237\312\237\310\200\310\200\307\237\312\202\310\237\310\200\310\200\310\237\312\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-25252d525877884acd8fa6bfc2e1dfda676faa53 Step #5: Base64: x4DIgMiAyJ/IgMifyp/IgMiAx5/KgsifyIDIgMifyoA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2706 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3040815013 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b459e45810, 0x55b45a02f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b45a02f020,0x55b45bec70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/25252d525877884acd8fa6bfc2e1dfda676faa53' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3271 processed earlier; will process 7758 files now Step #5: ==97454== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b45093a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b456f9f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b456f825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b456f824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b450940d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b4508a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b45089c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b450932c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b453901f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b453901f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b453901f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b453901f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b453901f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b453901f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b453901f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b453901f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b453901f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b453901f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b455b96f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b4528c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b4528cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b45267ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b45267ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b45267b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b45267a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b45267a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b45267a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b456f84abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b456f8d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b456f75699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b456fa0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff42bef0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b45089ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0xc,0xd,0x60,0xd,0xc,0xd,0x60,0xd,0xc,0xd,0x60,0xd,0xc,0xd,0x60,0xd,0xc,0xd,0x60,0xd,0xc,0xd,0x60,0xd,0xc,0xd,0x60,0xd,0xc,0xd,0x60, Step #5: \015\014\015`\015\014\015`\015\014\015`\015\014\015`\015\014\015`\015\014\015`\015\014\015`\015\014\015` Step #5: artifact_prefix='./'; Test unit written to ./oom-6742f058d715f7c967f5685be740cd2de7de4c21 Step #5: Base64: DQwNYA0MDWANDA1gDQwNYA0MDWANDA1gDQwNYA0MDWA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2707 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3041399666 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c3fd058810, 0x55c3fd24201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c3fd242020,0x55c3ff0da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6742f058d715f7c967f5685be740cd2de7de4c21' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3272 processed earlier; will process 7757 files now Step #5: ==97490== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c3f3b4d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c3fa1b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c3fa1955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c3fa1954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c3f3b53d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c3f3ab4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c3f3aaf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c3f3b45c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c3f6b14f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c3f6b14f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c3f6b14f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c3f6b14f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c3f6b14f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c3f6b14f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c3f6b14f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c3f6b14f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c3f6b14f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c3f6b14f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c3f8da9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c3f5ad6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c3f5ae1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c3f588dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c3f588dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c3f588e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c3f588d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c3f588d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c3f588d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c3fa197abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c3fa1a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c3fa188699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c3fa1b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe930caf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c3f3aadb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xe1,0x9e,0x90,0xe1,0x9f,0x92,0x9,0xa,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: \341\236\220\341\237\222\011\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-5d63a0764dbf2f5670d32b88c940831eb76f2c42 Step #5: Base64: PHN2Zz48dGV4dD7hnpDhn5IJCjwvdGV4dD48L3N2Zz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2708 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3041867732 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b45625d810, 0x55b45644701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b456447020,0x55b4582df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5d63a0764dbf2f5670d32b88c940831eb76f2c42' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3273 processed earlier; will process 7756 files now Step #5: ==97526== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b44cd529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b4533b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b45339a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b45339a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b44cd58d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b44ccb9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b44ccb4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b44cd4ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b44fd19f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b44fd19f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b44fd19f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b44fd19f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b44fd19f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b44fd19f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b44fd19f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b44fd19f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b44fd19f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b44fd19f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b451faef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b44ecdbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b44ece6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b44ea92c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b44ea92c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b44ea93738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b44ea92874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b44ea92874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b44ea92874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b45339cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b4533a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b45338d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b4533b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a57589082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b44ccb2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x6f,0x62,0x6f,0x62,0x6a,0x65,0x63,0x74,0x3e,0x3c,0x6f,0x6f,0x62,0x6f,0x74,0x62,0x6a,0x65,0x63,0x74,0x63,0x76,0x3e,0x3c,0x6f,0x6a,0x65,0x63,0x74,0x3e,0x3c, Step #5: < Step #5: artifact_prefix='./'; Test unit written to ./oom-a2403acc7de2d0193625fea58cb89c66d00ae9b0 Step #5: Base64: PG9ib2JqZWN0Pjxvb2JvdGJqZWN0Y3Y+PG9qZWN0Pjw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2709 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3042328080 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558c2a535810, 0x558c2a71f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558c2a71f020,0x558c2c5b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2403acc7de2d0193625fea58cb89c66d00ae9b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3274 processed earlier; will process 7755 files now Step #5: ==97562== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558c2102a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558c2768f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558c276725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558c276724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558c21030d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558c20f91b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558c20f8c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558c21022c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558c23ff1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558c23ff1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558c23ff1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558c23ff1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558c23ff1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558c23ff1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558c23ff1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558c23ff1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558c23ff1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558c23ff1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558c26286f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558c22fb3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558c22fbebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558c22d6ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558c22d6ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558c22d6b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558c22d6a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558c22d6a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558c22d6a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558c27674abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558c2767d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558c27665699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558c27690112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8f95654082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558c20f8ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47, Step #5: FUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAG Step #5: artifact_prefix='./'; Test unit written to ./oom-fdae29abd86a5d80c9ff363cb8ee66d7dad95b1b Step #5: Base64: RlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2710 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3042798455 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555588687810, 0x55558887101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555588871020,0x55558a7090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fdae29abd86a5d80c9ff363cb8ee66d7dad95b1b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3275 processed earlier; will process 7754 files now Step #5: ==97598== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55557f17c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5555857e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5555857c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5555857c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55557f182d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55557f0e3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55557f0de355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55557f174c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555582143f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555582143f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555582143f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555582143f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555582143f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555582143f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555582143f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555582143f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555582143f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555582143f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5555843d8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555581105b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555581110be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555580ebcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555580ebcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555580ebd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555580ebc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555580ebc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555580ebc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5555857c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5555857cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5555857b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5555857e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe5a11be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55557f0dcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x0,0x6b,0x0,0x60,0x2b,0x2b,0x4a,0x9,0x29,0x4a,0x9,0x29,0xa,0x20,0x0,0x29,0xa,0x5c,0x9,0x60,0xa9,0x60,0x40,0x29,0xa,0x1,0x0,0x1d,0x9,0x2b,0x29, Step #5: \012\000k\000`++J\011)J\011)\012 \000)\012\\\011`\251`@)\012\001\000\035\011+) Step #5: artifact_prefix='./'; Test unit written to ./oom-3eca3885129e1b0702c271c2abc3bf84c4f2802a Step #5: Base64: CgBrAGArK0oJKUoJKQogACkKXAlgqWBAKQoBAB0JKyk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2711 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3043390503 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560060415810, 0x5600605ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5600605ff020,0x5600624970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3eca3885129e1b0702c271c2abc3bf84c4f2802a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3276 processed earlier; will process 7753 files now Step #5: ==97634== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560056f0a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56005d56f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56005d5525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56005d5524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560056f10d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560056e71b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560056e6c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560056f02c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560059ed1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560059ed1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560059ed1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560059ed1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560059ed1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560059ed1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560059ed1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560059ed1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560059ed1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560059ed1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56005c166f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560058e93b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560058e9ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560058c4ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560058c4ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560058c4b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560058c4a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560058c4a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560058c4a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56005d554abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56005d55d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56005d545699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56005d570112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc974ec9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560056e6ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0x6e,0x63,0x78, Step #5: \360\221\226\271\360\221\222\275.x\360\221\226\271\360\221\222\275\012\360\221\226\271\360\221\222\275.xncx Step #5: artifact_prefix='./'; Test unit written to ./oom-1c601bce2de741343df23cbfc8c4c6f2ca090fba Step #5: Base64: 8JGWufCRkr0uePCRlrnwkZK9CvCRlrnwkZK9LnhuY3g= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2712 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3043855198 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5653ca244810, 0x5653ca42e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5653ca42e020,0x5653cc2c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c601bce2de741343df23cbfc8c4c6f2ca090fba' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3277 processed earlier; will process 7752 files now Step #5: ==97670== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5653c0d399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5653c739e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5653c73815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5653c73814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5653c0d3fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5653c0ca0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5653c0c9b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5653c0d31c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5653c3d00f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5653c3d00f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5653c3d00f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5653c3d00f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5653c3d00f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5653c3d00f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5653c3d00f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5653c3d00f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5653c3d00f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5653c3d00f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5653c5f95f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5653c2cc2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5653c2ccdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5653c2a79c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5653c2a79c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5653c2a7a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5653c2a79874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5653c2a79874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5653c2a79874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5653c7383abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5653c738c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5653c7374699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5653c739f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f221d388082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5653c0c99b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x63,0x3e,0xdb,0xa5,0xd,0xdb,0xa5,0x21,0xd,0xdb,0xa5,0xd,0xdb,0xa5,0x3c,0x73,0x3e,0xdb,0xa5,0xd,0xdb,0xa5,0x3c,0x73,0x3e,0xdb,0xa5,0xd,0xdb,0xa5,0x72, Step #5: \333\245\015\333\245!\015\333\245\015\333\245\333\245\015\333\245\333\245\015\333\245r Step #5: artifact_prefix='./'; Test unit written to ./oom-a93bf956c0692ae3159e7e66dce7ce2e85bf7953 Step #5: Base64: PGM+26UN26UhDdulDdulPHM+26UN26U8cz7bpQ3bpXI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2713 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3044324757 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557da65b4810, 0x557da679e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557da679e020,0x557da86360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a93bf956c0692ae3159e7e66dce7ce2e85bf7953' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3278 processed earlier; will process 7751 files now Step #5: ==97706== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557d9d0a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557da370e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557da36f15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557da36f14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557d9d0afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557d9d010b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557d9d00b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557d9d0a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557da0070f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557da0070f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557da0070f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557da0070f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557da0070f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557da0070f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557da0070f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557da0070f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557da0070f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557da0070f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557da2305f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557d9f032b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557d9f03dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557d9ede9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557d9ede9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557d9edea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557d9ede9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557d9ede9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557d9ede9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557da36f3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557da36fc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557da36e4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557da370f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb547b8d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557d9d009b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x62,0x0,0x0,0x6,0x0,0x0,0x60,0x0,0x0,0x0,0x2,0x60,0x0,0x0,0x0,0x2,0x41,0x41,0x33,0xf3,0xa0,0x81,0xa0, Step #5: \007\001\000\000\000\000\000\000\000b\000\000\006\000\000`\000\000\000\002`\000\000\000\002AA3\363\240\201\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-01c14fab294a148ace63bfe8c2ccb48fd2295d7d Step #5: Base64: BwEAAAAAAAAAYgAABgAAYAAAAAJgAAAAAkFBM/OggaA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2714 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3044915400 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e612f56810, 0x55e61314001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e613140020,0x55e614fd80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01c14fab294a148ace63bfe8c2ccb48fd2295d7d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3279 processed earlier; will process 7750 files now Step #5: ==97742== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e609a4b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e6100b0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e6100935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e6100934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e609a51d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e6099b2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e6099ad355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e609a43c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e60ca12f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e60ca12f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e60ca12f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e60ca12f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e60ca12f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e60ca12f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e60ca12f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e60ca12f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e60ca12f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e60ca12f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e60eca7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e60b9d4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e60b9dfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e60b78bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e60b78bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e60b78c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e60b78b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e60b78b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e60b78b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e610095abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e61009e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e610086699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e6100b1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9c74683082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e6099abb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x29,0xc,0x29,0xc,0x24,0xc,0x25,0xc,0x29,0x20,0x24,0xc,0x2a,0x20,0x29,0xc,0x29,0xc,0x29,0xc,0x24,0xc,0x25,0xc,0x29,0x20,0x24,0xc,0x2a,0x20,0x29,0xc, Step #5: )\014)\014$\014%\014) $\014* )\014)\014)\014$\014%\014) $\014* )\014 Step #5: artifact_prefix='./'; Test unit written to ./oom-c439ac8f7789b3e74e2420f2c8ab4939faeb1ca1 Step #5: Base64: KQwpDCQMJQwpICQMKiApDCkMKQwkDCUMKSAkDCogKQw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2715 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3045389967 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5597d8ea9810, 0x5597d909301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5597d9093020,0x5597daf2b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c439ac8f7789b3e74e2420f2c8ab4939faeb1ca1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3280 processed earlier; will process 7749 files now Step #5: ==97778== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5597cf99e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5597d6003898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5597d5fe65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5597d5fe64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5597cf9a4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5597cf905b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5597cf900355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5597cf996c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5597d2965f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5597d2965f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5597d2965f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5597d2965f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5597d2965f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5597d2965f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5597d2965f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5597d2965f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5597d2965f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5597d2965f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5597d4bfaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5597d1927b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5597d1932be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5597d16dec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5597d16dec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5597d16df738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5597d16de874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5597d16de874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5597d16de874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5597d5fe8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5597d5ff1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5597d5fd9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5597d6004112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb9c43c9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5597cf8feb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x65,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3d,0x22,0x49,0x53,0x4f,0x2d,0x38,0x38,0x35,0x39,0x2d,0x31,0x22,0x3f,0x3e,0xd2,0x63,0xd2, Step #5: \322c\322 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb6ba4abfad876566c2def7726ff5e33a3dc9a2b Step #5: Base64: PD94bWwgZW5jb2Rpbmc9IklTTy04ODU5LTEiPz7SY9I= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2716 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3045856543 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55697ec23810, 0x55697ee0d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55697ee0d020,0x556980ca50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb6ba4abfad876566c2def7726ff5e33a3dc9a2b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3281 processed earlier; will process 7748 files now Step #5: ==97814== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5569757189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55697bd7d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55697bd605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55697bd604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55697571ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55697567fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55697567a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556975710c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5569786dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5569786dff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5569786dff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5569786dff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5569786dff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5569786dff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5569786dff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5569786dff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5569786dff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5569786dff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55697a974f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5569776a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5569776acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556977458c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556977458c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556977459738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556977458874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556977458874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556977458874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55697bd62abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55697bd6b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55697bd53699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55697bd7e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ac4182082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556975678b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x61,0x64,0x64,0x64,0x64, Step #5: t-----BEGIN -----\012dddddddddadddd Step #5: artifact_prefix='./'; Test unit written to ./oom-7c510e063e0b7d2512cac5b2278b94af0d27741a Step #5: Base64: dC0tLS0tQkVHSU4gLS0tLS0KZGRkZGRkZGRkYWRkZGQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2717 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3046322726 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5578cfbc5810, 0x5578cfdaf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5578cfdaf020,0x5578d1c470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7c510e063e0b7d2512cac5b2278b94af0d27741a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3282 processed earlier; will process 7747 files now Step #5: ==97850== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5578c66ba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5578ccd1f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5578ccd025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5578ccd024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5578c66c0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5578c6621b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5578c661c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5578c66b2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5578c9681f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5578c9681f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5578c9681f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5578c9681f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5578c9681f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5578c9681f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5578c9681f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5578c9681f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5578c9681f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5578c9681f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5578cb916f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5578c8643b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5578c864ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5578c83fac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5578c83fac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5578c83fb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5578c83fa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5578c83fa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5578c83fa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5578ccd04abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5578ccd0d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5578cccf5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5578ccd20112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6620141082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5578c661ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x78,0x6e,0x2d,0x2d,0x31,0x51,0xe2,0x85,0xa5,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x58,0x61,0x61,0x65,0x61,0x61,0x61,0x61,0x53,0x41,0x61, Step #5: ws:xn--1Q\342\205\245aaaaaaaaaXaaeaaaaSAa Step #5: artifact_prefix='./'; Test unit written to ./oom-bf434a3ee8d0f4b9032ab7ae10097c47c7edf82e Step #5: Base64: d3M6eG4tLTFR4oWlYWFhYWFhYWFhWGFhZWFhYWFTQWE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2718 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3046786938 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff193fb810, 0x55ff195e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff195e5020,0x55ff1b47d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf434a3ee8d0f4b9032ab7ae10097c47c7edf82e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3283 processed earlier; will process 7746 files now Step #5: ==97886== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ff0fef09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff16555898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff165385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff165384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff0fef6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff0fe57b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff0fe52355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff0fee8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff12eb7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff12eb7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff12eb7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff12eb7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff12eb7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff12eb7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff12eb7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff12eb7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff12eb7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff12eb7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff1514cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff11e79b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff11e84be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff11c30c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff11c30c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff11c31738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff11c30874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff11c30874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff11c30874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff1653aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff16543928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff1652b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff16556112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb6b1ed1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff0fe50b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0xa,0x22,0xa,0x5f,0x22,0x22,0x22,0x10,0x0,0x3f,0x28,0x0,0x75,0x5f,0xa,0x22,0xa,0x5f,0x22,0x22,0x22,0x10,0x0,0x3f,0x28,0x0,0x75,0x73,0x73,0x2e,0x63, Step #5: _\012\"\012_\"\"\"\020\000?(\000u_\012\"\012_\"\"\"\020\000?(\000uss.c Step #5: artifact_prefix='./'; Test unit written to ./oom-79daf5e9af7d8e59ccbfd833e26be75b8510e5f8 Step #5: Base64: XwoiCl8iIiIQAD8oAHVfCiIKXyIiIhAAPygAdXNzLmM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2719 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3047252656 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5598f742e810, 0x5598f761801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5598f7618020,0x5598f94b00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/79daf5e9af7d8e59ccbfd833e26be75b8510e5f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3284 processed earlier; will process 7745 files now Step #5: ==97922== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5598edf239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5598f4588898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5598f456b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5598f456b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5598edf29d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5598ede8ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5598ede85355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5598edf1bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5598f0eeaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5598f0eeaf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5598f0eeaf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5598f0eeaf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5598f0eeaf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5598f0eeaf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5598f0eeaf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5598f0eeaf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5598f0eeaf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5598f0eeaf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5598f317ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5598efeacb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5598efeb7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5598efc63c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5598efc63c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5598efc64738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5598efc63874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5598efc63874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5598efc63874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5598f456dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5598f4576928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5598f455e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5598f4589112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8611832082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5598ede83b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x61,0xa,0x64,0xa,0x48,0xa,0x49,0xa,0x68,0xa,0x68,0xa,0xa,0x0, Step #5: ------BEGIN\000-----\012a\012d\012H\012I\012h\012h\012\012\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2f3871d13da3a36b67ac69c1c9b25c41e901490a Step #5: Base64: LS0tLS0tQkVHSU4ALS0tLS0KYQpkCkgKSQpoCmgKCgA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2720 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3047715465 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a02988b810, 0x55a029a7501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a029a75020,0x55a02b90d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f3871d13da3a36b67ac69c1c9b25c41e901490a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3285 processed earlier; will process 7744 files now Step #5: ==97958== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a0203809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0269e5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0269c85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0269c84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a020386d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0202e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0202e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a020378c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a023347f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a023347f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a023347f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a023347f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a023347f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a023347f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a023347f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a023347f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a023347f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a023347f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0255dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a022309b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a022314be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0220c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0220c0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0220c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0220c0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0220c0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0220c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0269caabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0269d3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0269bb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0269e6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f09591ad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0202e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa, Step #5: \012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-973edf66520ca740c6f56e48ffa5bed0cd6df2a3 Step #5: Base64: CgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2721 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3048171747 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a9a4d0810, 0x555a9a6ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a9a6ba020,0x555a9c5520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/973edf66520ca740c6f56e48ffa5bed0cd6df2a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3286 processed earlier; will process 7743 files now Step #5: ==97994== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555a90fc59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a9762a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a9760d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a9760d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a90fcbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a90f2cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a90f27355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a90fbdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a93f8cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a93f8cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a93f8cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a93f8cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a93f8cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a93f8cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a93f8cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a93f8cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a93f8cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a93f8cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a96221f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a92f4eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a92f59be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a92d05c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a92d05c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a92d06738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a92d05874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a92d05874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a92d05874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a9760fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a97618928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a97600699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a9762b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac5c586082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a90f25b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x3,0x0,0x20,0x1,0x11,0x47,0x0,0x54,0x49,0x42,0x2b,0x0,0x0,0x0,0x67,0xe,0x68,0x68,0x43,0xda,0x82,0x1,0x70,0x70,0x70,0x70,0x70,0x70,0x70, Step #5: ID3\003\000 \001\021G\000TIB+\000\000\000g\016hhC\332\202\001ppppppp Step #5: artifact_prefix='./'; Test unit written to ./oom-43ccd41dcef7e73a99d19dfa0b52b42cab9b0ebe Step #5: Base64: SUQzAwAgARFHAFRJQisAAABnDmhoQ9qCAXBwcHBwcHA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2722 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3048636435 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec057e3810, 0x55ec059cd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec059cd020,0x55ec078650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/43ccd41dcef7e73a99d19dfa0b52b42cab9b0ebe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3287 processed earlier; will process 7742 files now Step #5: #1 pulse cov: 3494 ft: 3495 exec/s: 0 rss: 171Mb Step #5: ==98030== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ebfc2d89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec0293d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec029205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec029204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ebfc2ded42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ebfc23fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ebfc23a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ebfc2d0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ebff29ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ebff29ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ebff29ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ebff29ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ebff29ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ebff29ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ebff29ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ebff29ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ebff29ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ebff29ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec01534f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ebfe261b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ebfe26cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ebfe018c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ebfe018c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ebfe019738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ebfe018874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ebfe018874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ebfe018874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec02922abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec0292b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec02913699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec0293e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7bdafe1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ebfc238b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0xa,0xcd,0x8f,0x2e,0x2e,0xa,0xcd,0x9f,0x2e,0xa,0xcd,0x8e,0x2e,0xa,0xcd,0x8f,0x2e,0xa,0xcd,0x8f,0x2e,0xa,0x6d,0xa,0xcd,0x9f,0x2e,0xa,0xcd,0x8e,0x2e, Step #5: .\012\315\217..\012\315\237.\012\315\216.\012\315\217.\012\315\217.\012m\012\315\237.\012\315\216. Step #5: artifact_prefix='./'; Test unit written to ./oom-60a7a9e2beca729453f7d20539fd3de5d425140a Step #5: Base64: LgrNjy4uCs2fLgrNji4KzY8uCs2PLgptCs2fLgrNji4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2723 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3049142140 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56376a910810, 0x56376aafa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56376aafa020,0x56376c9920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/60a7a9e2beca729453f7d20539fd3de5d425140a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3289 processed earlier; will process 7740 files now Step #5: #1 pulse cov: 11064 ft: 11065 exec/s: 0 rss: 189Mb Step #5: ==98066== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5637614059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563767a6a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563767a4d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563767a4d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56376140bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56376136cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563761367355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5637613fdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5637643ccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5637643ccf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5637643ccf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5637643ccf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5637643ccf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5637643ccf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5637643ccf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5637643ccf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5637643ccf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5637643ccf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563766661f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56376338eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563763399be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563763145c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563763145c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563763146738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563763145874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563763145874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563763145874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563767a4fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563767a58928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563767a40699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563767a6b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b61b68082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563761365b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0x83,0xdf,0x83,0xdf,0x83,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x84, Step #5: \337\203\337\203\337\203\337\203\337\204\337\204\337\204\337\203\337\204\337\204\337\204\337\203\337\204\337\204\337\204\337\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-b614ec9fffdfc7faeee54ddb780d65087bcabb79 Step #5: Base64: 34Pfg9+D34PfhN+E34Tfg9+E34TfhN+D34TfhN+E34Q= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2724 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3049674015 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a423382810, 0x55a42356c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a42356c020,0x55a4254040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b614ec9fffdfc7faeee54ddb780d65087bcabb79' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3291 processed earlier; will process 7738 files now Step #5: ==98102== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a419e779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a4204dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a4204bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a4204bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a419e7dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a419ddeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a419dd9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a419e6fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a41ce3ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a41ce3ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a41ce3ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a41ce3ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a41ce3ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a41ce3ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a41ce3ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a41ce3ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a41ce3ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a41ce3ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a41f0d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a41be00b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a41be0bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a41bbb7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a41bbb7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a41bbb8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a41bbb7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a41bbb7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a41bbb7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a4204c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a4204ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a4204b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a4204dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f04730a9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a419dd7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x36,0x2d,0x31,0x2d,0x32,0x31,0x39,0x3a,0x34,0x3a,0x32,0xd1,0x91,0xd9,0x92,0xd9,0x8e,0xd8,0x91,0xd9,0x91,0xd9,0x8e,0xd8,0x91,0xd9,0x92,0xd9,0x8e,0xd9,0x91,0x7, Step #5: 6-1-219:4:2\321\221\331\222\331\216\330\221\331\221\331\216\330\221\331\222\331\216\331\221\007 Step #5: artifact_prefix='./'; Test unit written to ./oom-342494edb043dafa073a11d38e3f5140fee12362 Step #5: Base64: Ni0xLTIxOTo0OjLRkdmS2Y7YkdmR2Y7YkdmS2Y7ZkQc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2725 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3050143176 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557cbc458810, 0x557cbc64201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557cbc642020,0x557cbe4da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/342494edb043dafa073a11d38e3f5140fee12362' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3292 processed earlier; will process 7737 files now Step #5: ==98138== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557cb2f4d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557cb95b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557cb95955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557cb95954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557cb2f53d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557cb2eb4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557cb2eaf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557cb2f45c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557cb5f14f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557cb5f14f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557cb5f14f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557cb5f14f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557cb5f14f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557cb5f14f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557cb5f14f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557cb5f14f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557cb5f14f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557cb5f14f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557cb81a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557cb4ed6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557cb4ee1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557cb4c8dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557cb4c8dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557cb4c8e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557cb4c8d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557cb4c8d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557cb4c8d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557cb9597abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557cb95a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557cb9588699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557cb95b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efc080dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557cb2eadb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf4,0x8f,0xa3,0xaf,0xf4,0x80,0x84,0xbb,0xf4,0x8f,0xa3,0xaf,0xf4,0x80,0x84,0xbb,0xf4,0x8f,0xa3,0xaf,0xf4,0x8f,0xb7,0xb0,0xf4,0x8f,0xa3,0x90,0xf4,0x8f,0xa3,0xaf, Step #5: \364\217\243\257\364\200\204\273\364\217\243\257\364\200\204\273\364\217\243\257\364\217\267\260\364\217\243\220\364\217\243\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-fc5419708edf5ae6f7a32e081a15644c58f67848 Step #5: Base64: 9I+jr/SAhLv0j6Ov9ICEu/SPo6/0j7ew9I+jkPSPo68= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2726 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3050604123 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f5508f810, 0x556f5527901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f55279020,0x556f571110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc5419708edf5ae6f7a32e081a15644c58f67848' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3293 processed earlier; will process 7736 files now Step #5: ==98174== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556f4bb849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f521e9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f521cc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f521cc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f4bb8ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f4baebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f4bae6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f4bb7cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f4eb4bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f4eb4bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f4eb4bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f4eb4bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f4eb4bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f4eb4bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f4eb4bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f4eb4bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f4eb4bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f4eb4bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f50de0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f4db0db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f4db18be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f4d8c4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f4d8c4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f4d8c5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f4d8c4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f4d8c4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f4d8c4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f521ceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f521d7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f521bf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f521ea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5bb3f85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f4bae4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x0,0x6b,0x0,0x60,0x2b,0x2b,0x4a,0x9,0x29,0x4a,0x9,0x29,0xa,0x5c,0x9,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x1,0x0,0x1d,0x9,0x60,0x29, Step #5: \012\000k\000`++J\011)J\011)\012\\\011)\012\\\011`@`@)\012\001\000\035\011`) Step #5: artifact_prefix='./'; Test unit written to ./oom-cbd7dac4f3058a75c3f43c149dc1ca2dfd1e6778 Step #5: Base64: CgBrAGArK0oJKUoJKQpcCSkKXAlgQGBAKQoBAB0JYCk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2727 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3051193202 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cfc8cd2810, 0x55cfc8ebc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cfc8ebc020,0x55cfcad540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cbd7dac4f3058a75c3f43c149dc1ca2dfd1e6778' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3294 processed earlier; will process 7735 files now Step #5: ==98210== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cfbf7c79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cfc5e2c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cfc5e0f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cfc5e0f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cfbf7cdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cfbf72eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cfbf729355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cfbf7bfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cfc278ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cfc278ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cfc278ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cfc278ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cfc278ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cfc278ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cfc278ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cfc278ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cfc278ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cfc278ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cfc4a23f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cfc1750b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cfc175bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cfc1507c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cfc1507c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cfc1508738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cfc1507874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cfc1507874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cfc1507874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cfc5e11abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cfc5e1a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cfc5e02699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cfc5e2d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ed07d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cfbf727b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x2d,0x30,0x2,0x2,0x21,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x38,0x5e,0x4e,0x41,0x50,0x49,0x43,0x6,0x4f,0x49,0x78,0x50,0x6e,0xca,0xb8,0x47, Step #5: ID-0\002\002!2147483648^NAPIC\006OIxPn\312\270G Step #5: artifact_prefix='./'; Test unit written to ./oom-c7cbfd1fddb59c83c0aa30f495ff2b952361629f Step #5: Base64: SUQtMAICITIxNDc0ODM2NDheTkFQSUMGT0l4UG7KuEc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2728 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3051656205 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a674a0d810, 0x55a674bf701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a674bf7020,0x55a676a8f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c7cbfd1fddb59c83c0aa30f495ff2b952361629f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3295 processed earlier; will process 7734 files now Step #5: ==98246== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a66b5029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a671b67898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a671b4a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a671b4a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a66b508d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a66b469b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a66b464355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a66b4fac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a66e4c9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a66e4c9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a66e4c9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a66e4c9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a66e4c9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a66e4c9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a66e4c9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a66e4c9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a66e4c9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a66e4c9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a67075ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a66d48bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a66d496be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a66d242c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a66d242c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a66d243738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a66d242874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a66d242874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a66d242874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a671b4cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a671b55928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a671b3d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a671b68112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe233a48082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a66b462b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60, Step #5: _`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_` Step #5: artifact_prefix='./'; Test unit written to ./oom-de5d0c6809241afbfe6067efb22614c1acbfbb49 Step #5: Base64: X2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2A= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2729 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3052245992 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56383ca30810, 0x56383cc1a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56383cc1a020,0x56383eab20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de5d0c6809241afbfe6067efb22614c1acbfbb49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3296 processed earlier; will process 7733 files now Step #5: ==98282== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5638335259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563839b8a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563839b6d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563839b6d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56383352bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56383348cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563833487355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56383351dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5638364ecf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5638364ecf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5638364ecf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5638364ecf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5638364ecf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5638364ecf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5638364ecf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5638364ecf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5638364ecf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5638364ecf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563838781f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5638354aeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5638354b9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563835265c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563835265c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563835266738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563835265874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563835265874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563835265874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563839b6fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563839b78928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563839b60699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563839b8b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd516e59082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563833485b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9, Step #5: -\011-\011-\011-\011-\011-\011-\011-\011-\011-\011-\011-\011-\011-\011-\011-\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-b36b532f928f74cde630920d81f79228ceab453c Step #5: Base64: LQktCS0JLQktCS0JLQktCS0JLQktCS0JLQktCS0JLQk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2730 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3052734454 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a911f28810, 0x55a91211201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a912112020,0x55a913faa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b36b532f928f74cde630920d81f79228ceab453c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3297 processed earlier; will process 7732 files now Step #5: ==98318== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a908a1d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a90f082898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a90f0655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a90f0654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a908a23d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a908984b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a90897f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a908a15c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a90b9e4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a90b9e4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a90b9e4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a90b9e4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a90b9e4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a90b9e4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a90b9e4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a90b9e4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a90b9e4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a90b9e4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a90dc79f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a90a9a6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a90a9b1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a90a75dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a90a75dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a90a75e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a90a75d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a90a75d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a90a75d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a90f067abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a90f070928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a90f058699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a90f083112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc59f77f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a90897db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0xa,0xf0,0xa6,0xb9,0x86,0x0,0x29,0x74,0x0,0xf0,0xa6,0xb9,0x86,0x2,0x43,0xc3,0x80,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0xf0,0xa2,0xb9,0x86,0x0, Step #5: \000\000\012\360\246\271\206\000)t\000\360\246\271\206\002C\303\200\000\000\000\000\000\000\000\002\360\242\271\206\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6fcd8351264d5496d374808bc4aca02832eb0627 Step #5: Base64: AAAK8Ka5hgApdADwprmGAkPDgAAAAAAAAAAC8KK5hgA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2731 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3053201449 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558fbac20810, 0x558fbae0a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558fbae0a020,0x558fbcca20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6fcd8351264d5496d374808bc4aca02832eb0627' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3298 processed earlier; will process 7731 files now Step #5: ==98354== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558fb17159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558fb7d7a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558fb7d5d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558fb7d5d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558fb171bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558fb167cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558fb1677355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558fb170dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558fb46dcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558fb46dcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558fb46dcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558fb46dcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558fb46dcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558fb46dcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558fb46dcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558fb46dcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558fb46dcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558fb46dcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558fb6971f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558fb369eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558fb36a9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558fb3455c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558fb3455c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558fb3456738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558fb3455874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558fb3455874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558fb3455874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558fb7d5fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558fb7d68928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558fb7d50699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558fb7d7b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb597130082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558fb1675b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x32,0xe2,0x97,0x8c,0xe0,0xb7,0x80,0x35,0x3c,0x2f,0x74,0x65,0x78,0x74, Step #5: >>>>>>>2\342\227\214\340\267\2005 Step #5: Step #5: #0 0x55a7a1d289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a7a838d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a7a83705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a7a83704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a7a1d2ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a7a1c8fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a7a1c8a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a7a1d20c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a7a4ceff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a7a4ceff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a7a4ceff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a7a4ceff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a7a4ceff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a7a4ceff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a7a4ceff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a7a4ceff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a7a4ceff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a7a4ceff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a7a6f84f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a7a3cb1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a7a3cbcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a7a3a68c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a7a3a68c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a7a3a69738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a7a3a68874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a7a3a68874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a7a3a68874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a7a8372abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a7a837b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a7a8363699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a7a838e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c3f934082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a7a1c88b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x6c,0x20,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0x56, Step #5: Step #5: Step #5: #0 0x56295a3e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562960a46898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562960a295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562960a294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56295a3e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56295a348b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56295a343355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56295a3d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56295d3a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56295d3a8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56295d3a8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56295d3a8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56295d3a8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56295d3a8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56295d3a8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56295d3a8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56295d3a8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56295d3a8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56295f63df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56295c36ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56295c375be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56295c121c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56295c121c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56295c122738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56295c121874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56295c121874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56295c121874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562960a2babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562960a34928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562960a1c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562960a47112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ed14d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56295a341b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3c,0x77,0x3e,0x28,0x3f,0x3c,0x57,0x3e,0x28,0x3f,0x3c,0x6d,0x3e,0x3c,0x6d,0x3e,0x28,0x3f,0x3c,0x36,0x3e,0x3c,0x36,0x3e,0x3c,0x36,0x3e,0x3c,0x36,0x3e, Step #5: (?(?(?(?<6><6><6><6> Step #5: artifact_prefix='./'; Test unit written to ./oom-498d26d8f65672912a1a40f9cfbcd7e7107baf19 Step #5: Base64: KD88dz4oPzxXPig/PG0+PG0+KD88Nj48Nj48Nj48Nj4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2734 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3054594079 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56321f708810, 0x56321f8f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56321f8f2020,0x56322178a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/498d26d8f65672912a1a40f9cfbcd7e7107baf19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3301 processed earlier; will process 7728 files now Step #5: ==98462== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5632161fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56321c862898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56321c8455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56321c8454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563216203d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563216164b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56321615f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5632161f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5632191c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5632191c4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5632191c4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5632191c4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5632191c4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5632191c4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5632191c4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5632191c4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5632191c4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5632191c4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56321b459f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563218186b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563218191be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563217f3dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563217f3dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563217f3e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563217f3d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563217f3d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563217f3d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56321c847abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56321c850928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56321c838699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56321c863112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcd4e3ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56321615db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24, Step #5: $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ Step #5: artifact_prefix='./'; Test unit written to ./oom-f4d449b7372db62599b33728581d24dae6af31ab Step #5: Base64: JCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2735 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3055058453 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d3ef1c5810, 0x55d3ef3af01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d3ef3af020,0x55d3f12470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f4d449b7372db62599b33728581d24dae6af31ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3302 processed earlier; will process 7727 files now Step #5: ==98498== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d3e5cba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d3ec31f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d3ec3025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d3ec3024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d3e5cc0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d3e5c21b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d3e5c1c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d3e5cb2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d3e8c81f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d3e8c81f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d3e8c81f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d3e8c81f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d3e8c81f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d3e8c81f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d3e8c81f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d3e8c81f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d3e8c81f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d3e8c81f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d3eaf16f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d3e7c43b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d3e7c4ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d3e79fac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d3e79fac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d3e79fb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d3e79fa874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d3e79fa874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d3e79fa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d3ec304abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d3ec30d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d3ec2f5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d3ec320112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2437e39082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d3e5c1ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x29, Step #5: |(?:$|(?:$|$|$|$|$|$|$|$|$|$|$)) Step #5: artifact_prefix='./'; Test unit written to ./oom-7da9806dc4dc16064ed3d1a1feec6fe72e2b796f Step #5: Base64: fCg/OiR8KD86JHwkfCR8JHwkfCR8JHwkfCR8JHwkKSk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2736 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3055528629 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c66b17810, 0x556c66d0101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c66d01020,0x556c68b990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7da9806dc4dc16064ed3d1a1feec6fe72e2b796f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3303 processed earlier; will process 7726 files now Step #5: ==98534== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556c5d60c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c63c71898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c63c545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c63c544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556c5d612d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556c5d573b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556c5d56e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556c5d604c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556c605d3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556c605d3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556c605d3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556c605d3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556c605d3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556c605d3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556c605d3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556c605d3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556c605d3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556c605d3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c62868f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556c5f595b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556c5f5a0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556c5f34cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556c5f34cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556c5f34d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556c5f34c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556c5f34c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556c5f34c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c63c56abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c63c5f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c63c47699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c63c72112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f78883db082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556c5d56cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0xda,0xba,0x3b,0x25,0xda,0xba,0x3b,0x25,0xda,0xba,0x3b,0x25,0xda,0xba,0x3b,0x25,0xda,0xba,0x3b,0x25,0xda,0xba,0x3b,0x25,0xda,0xba,0x3b,0x25,0xda,0xba,0x3b, Step #5: %\332\272;%\332\272;%\332\272;%\332\272;%\332\272;%\332\272;%\332\272;%\332\272; Step #5: artifact_prefix='./'; Test unit written to ./oom-8d683b73d4e448a398dd30b7d370afa12187d8c2 Step #5: Base64: Jdq6OyXaujsl2ro7Jdq6OyXaujsl2ro7Jdq6OyXaujs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2737 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3055997340 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55988d0cf810, 0x55988d2b901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55988d2b9020,0x55988f1510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d683b73d4e448a398dd30b7d370afa12187d8c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3304 processed earlier; will process 7725 files now Step #5: ==98570== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x559883bc49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55988a229898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55988a20c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55988a20c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559883bcad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559883b2bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559883b26355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559883bbcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559886b8bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559886b8bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559886b8bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559886b8bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559886b8bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559886b8bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559886b8bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559886b8bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559886b8bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559886b8bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559888e20f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559885b4db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559885b58be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559885904c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559885904c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559885905738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559885904874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559885904874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559885904874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55988a20eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55988a217928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55988a1ff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55988a22a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efe9ac5b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559883b24b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0x2e,0x5f,0x2e,0x5f,0x2e,0x5f,0x2e,0x5f,0x2e,0x5f,0x2e,0x5f,0x2e,0x5f,0x2e,0x5f,0x2e,0x5f,0x2e,0x5f,0x2e,0x5f,0x2e,0x5f,0x2e,0x5f,0x2e,0x5f,0x2e,0x5f,0x2e, Step #5: _._._._._._._._._._._._._._._._. Step #5: artifact_prefix='./'; Test unit written to ./oom-048db99a250b03ee9dbedb598f263ae6679ba54f Step #5: Base64: Xy5fLl8uXy5fLl8uXy5fLl8uXy5fLl8uXy5fLl8uXy4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2738 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3056466546 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55834595c810, 0x558345b4601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558345b46020,0x5583479de0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/048db99a250b03ee9dbedb598f263ae6679ba54f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3305 processed earlier; will process 7724 files now Step #5: ==98606== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55833c4519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558342ab6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558342a995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558342a994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55833c457d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55833c3b8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55833c3b3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55833c449c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55833f418f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55833f418f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55833f418f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55833f418f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55833f418f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55833f418f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55833f418f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55833f418f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55833f418f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55833f418f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5583416adf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55833e3dab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55833e3e5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55833e191c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55833e191c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55833e192738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55833e191874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55833e191874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55833e191874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558342a9babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558342aa4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558342a8c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558342ab7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f564edf8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55833c3b1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x69,0x66,0x3d,0x42,0x42,0xa,0x3d,0x20,0x20,0xa,0x3d,0x20,0x20,0x2e,0x1d,0x20,0x2e,0x2d,0x13,0x1d,0x60,0x1,0x2,0x0,0x6,0x60,0x20,0x0,0x65,0x20,0xa, Step #5: rif=BB\012= \012= .\035 .-\023\035`\001\002\000\006` \000e \012 Step #5: artifact_prefix='./'; Test unit written to ./oom-6740c81d8e978c1272c57a9f7a666c4f87df60e9 Step #5: Base64: cmlmPUJCCj0gIAo9ICAuHSAuLRMdYAECAAZgIABlIAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2739 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3057055132 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56019492a810, 0x560194b1401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560194b14020,0x5601969ac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6740c81d8e978c1272c57a9f7a666c4f87df60e9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3306 processed earlier; will process 7723 files now Step #5: ==98642== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56018b41f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560191a84898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560191a675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560191a674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56018b425d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56018b386b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56018b381355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56018b417c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56018e3e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56018e3e6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56018e3e6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56018e3e6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56018e3e6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56018e3e6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56018e3e6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56018e3e6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56018e3e6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56018e3e6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56019067bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56018d3a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56018d3b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56018d15fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56018d15fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56018d160738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56018d15f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56018d15f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56018d15f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560191a69abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560191a72928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560191a5a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560191a85112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ca6e78082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56018b37fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x20,0x20,0x7,0xa,0x6d,0x3a,0x60,0x43,0x4,0x3b,0x3d,0x7,0xa,0x6d,0x3a,0x3a,0x6d,0x4,0x3b,0x3d,0x7,0xa,0x6d,0x3a,0x60,0x5b,0xe5,0x3b,0x3d,0x7,0xa, Step #5: % \007\012m:`C\004;=\007\012m::m\004;=\007\012m:`[\345;=\007\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-8bffa70e43d7b7e7825f33fa670ee904361556a9 Step #5: Base64: JSAgBwptOmBDBDs9BwptOjptBDs9BwptOmBb5Ts9Bwo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2740 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3057642058 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5568feeab810, 0x5568ff09501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5568ff095020,0x556900f2d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8bffa70e43d7b7e7825f33fa670ee904361556a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3307 processed earlier; will process 7722 files now Step #5: ==98678== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5568f59a09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5568fc005898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5568fbfe85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5568fbfe84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5568f59a6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5568f5907b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5568f5902355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5568f5998c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5568f8967f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5568f8967f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5568f8967f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5568f8967f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5568f8967f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5568f8967f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5568f8967f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5568f8967f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5568f8967f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5568f8967f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5568fabfcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5568f7929b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5568f7934be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5568f76e0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5568f76e0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5568f76e1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5568f76e0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5568f76e0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5568f76e0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5568fbfeaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5568fbff3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5568fbfdb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5568fc006112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9094f90082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5568f5900b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x8,0x30,0x10,0x2,0x0,0x30,0x15,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x2,0x30,0x0,0x31,0x2,0x30,0x0,0x31,0x0,0x31,0x0,0x31,0x2,0x30,0x0, Step #5: 0\0100\020\002\0000\0251\0001\0001\0001\0001\0020\0001\0020\0001\0001\0001\0020\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0b353495c984d2a90dd84bbba716e068bfd5d508 Step #5: Base64: MAgwEAIAMBUxADEAMQAxADECMAAxAjAAMQAxADECMAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2741 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3058106973 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56441bea5810, 0x56441c08f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56441c08f020,0x56441df270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b353495c984d2a90dd84bbba716e068bfd5d508' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3308 processed earlier; will process 7721 files now Step #5: #1 pulse cov: 11405 ft: 11406 exec/s: 0 rss: 188Mb Step #5: ==98714== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56441299a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564418fff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564418fe25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564418fe24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5644129a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564412901b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5644128fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564412992c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564415961f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564415961f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564415961f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564415961f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564415961f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564415961f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564415961f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564415961f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564415961f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564415961f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564417bf6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564414923b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56441492ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5644146dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5644146dac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5644146db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5644146da874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5644146da874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5644146da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564418fe4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564418fed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564418fd5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564419000112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5a29307082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5644128fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x73,0x74,0x61,0x72,0x74,0x78,0x72,0x65,0x66,0x31,0x23,0x74,0x72,0x75,0x65,0x0,0x34,0x38,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x75,0x75,0x75,0x75,0x0,0x0, Step #5: -startxref1#true\00048\021\000\000\000\000\000\000uuuu\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d1222f2410623e0d1b0daf996d2be9ce698cd405 Step #5: Base64: LXN0YXJ0eHJlZjEjdHJ1ZQA0OBEAAAAAAAB1dXV1AAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2742 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3058638730 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5626c74a7810, 0x5626c769101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5626c7691020,0x5626c95290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d1222f2410623e0d1b0daf996d2be9ce698cd405' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3310 processed earlier; will process 7719 files now Step #5: ==98750== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5626bdf9c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5626c4601898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5626c45e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5626c45e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5626bdfa2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5626bdf03b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5626bdefe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5626bdf94c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5626c0f63f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5626c0f63f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5626c0f63f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5626c0f63f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5626c0f63f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5626c0f63f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5626c0f63f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5626c0f63f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5626c0f63f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5626c0f63f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5626c31f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5626bff25b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5626bff30be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5626bfcdcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5626bfcdcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5626bfcdd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5626bfcdc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5626bfcdc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5626bfcdc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5626c45e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5626c45ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5626c45d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5626c4602112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f19a13eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5626bdefcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x31,0x22,0xa,0x2d,0x2d,0x2d,0xa,0x22,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x5b,0x31,0x22,0xa,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x20,0x2d,0x2d,0x2d,0xa,0x22,0xa, Step #5: [1\"\012---\012\"\012\012---\012[1\"\012-\012---\012 ---\012\"\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-0f750218019d0f1970d2f63d030e9b335d857835 Step #5: Base64: WzEiCi0tLQoiCgotLS0KWzEiCi0KLS0tCiAtLS0KIgo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2743 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3059110546 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bcd7099810, 0x55bcd728301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bcd7283020,0x55bcd911b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0f750218019d0f1970d2f63d030e9b335d857835' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3311 processed earlier; will process 7718 files now Step #5: ==98786== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bccdb8e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bcd41f3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bcd41d65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bcd41d64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bccdb94d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bccdaf5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bccdaf0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bccdb86c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bcd0b55f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bcd0b55f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bcd0b55f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bcd0b55f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bcd0b55f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bcd0b55f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bcd0b55f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bcd0b55f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bcd0b55f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bcd0b55f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bcd2deaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bccfb17b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bccfb22be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bccf8cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bccf8cec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bccf8cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bccf8ce874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bccf8ce874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bccf8ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bcd41d8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bcd41e1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bcd41c9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bcd41f4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f46f6383082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bccdaeeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xe1,0x9e,0x90,0xea,0x9f,0x92,0x9,0xa,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: \341\236\220\352\237\222\011\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-7fa61967ceda8e1aa63023b3337a6db635dd7acc Step #5: Base64: PHN2Zz48dGV4dD7hnpDqn5IJCjwvdGV4dD48L3N2Zz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2744 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3059581336 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d9b10c1810, 0x55d9b12ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d9b12ab020,0x55d9b31430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7fa61967ceda8e1aa63023b3337a6db635dd7acc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3312 processed earlier; will process 7717 files now Step #5: #1 pulse cov: 3506 ft: 3507 exec/s: 0 rss: 172Mb Step #5: ==98822== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d9a7bb69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d9ae21b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d9ae1fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d9ae1fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d9a7bbcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d9a7b1db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d9a7b18355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d9a7baec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d9aab7df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d9aab7df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d9aab7df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d9aab7df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d9aab7df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d9aab7df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d9aab7df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d9aab7df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d9aab7df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d9aab7df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d9ace12f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d9a9b3fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d9a9b4abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d9a98f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d9a98f6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d9a98f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d9a98f6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d9a98f6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d9a98f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d9ae200abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d9ae209928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d9ae1f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d9ae21c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fef6d429082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d9a7b16b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc,0x5c,0xc, Step #5: '\\\014\\\014\\\014\\\014\\\014\\\014\\\014\\\014\\\014\\\014\\\014\\\014\\\014\\\014\\\014\\\014 Step #5: artifact_prefix='./'; Test unit written to ./oom-643c593f7e56b3fcce281a2f57ce4a4ad5770eea Step #5: Base64: J1wMXAxcDFwMXAxcDFwMXAxcDFwMXAxcDFwMXAxcDFwM Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2745 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3060085418 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b10c83b810, 0x55b10ca2501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b10ca25020,0x55b10e8bd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/643c593f7e56b3fcce281a2f57ce4a4ad5770eea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3314 processed earlier; will process 7715 files now Step #5: #1 pulse cov: 3707 ft: 3708 exec/s: 0 rss: 172Mb Step #5: ==98858== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b1033309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b109995898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1099785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1099784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b103336d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b103297b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b103292355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b103328c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b1062f7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b1062f7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b1062f7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b1062f7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b1062f7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b1062f7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b1062f7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b1062f7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b1062f7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b1062f7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b10858cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b1052b9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b1052c4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b105070c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b105070c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b105071738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b105070874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b105070874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b105070874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b10997aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b109983928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b10996b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b109996112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa1875e7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b103290b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x63,0x38,0x38,0x35,0x36,0x66,0x68,0x66,0x27,0x65,0x65,0x0,0x0,0x0,0x63,0x38,0x38,0x35,0x36,0x66,0x68,0x66,0x27,0x65,0x65,0x0,0x0,0x0,0x13,0x4f,0x2,0x10, Step #5: oc8856fhf'ee\000\000\000c8856fhf'ee\000\000\000\023O\002\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-cea7cb528e67a0133f853167f16ddcc53bdfddc8 Step #5: Base64: b2M4ODU2ZmhmJ2VlAAAAYzg4NTZmaGYnZWUAAAATTwIQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2746 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3060595107 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e727eed810, 0x55e7280d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e7280d7020,0x55e729f6f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cea7cb528e67a0133f853167f16ddcc53bdfddc8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3316 processed earlier; will process 7713 files now Step #5: #1 pulse cov: 10785 ft: 10786 exec/s: 0 rss: 189Mb Step #5: ==98894== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e71e9e29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e725047898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e72502a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e72502a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e71e9e8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e71e949b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e71e944355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e71e9dac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e7219a9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e7219a9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e7219a9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e7219a9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e7219a9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e7219a9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e7219a9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e7219a9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e7219a9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e7219a9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e723c3ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e72096bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e720976be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e720722c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e720722c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e720723738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e720722874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e720722874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e720722874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e72502cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e725035928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e72501d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e725048112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f296e7c0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e71e942b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x68,0x63,0x20,0xa,0x78,0x60,0x1a,0xb,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x29,0x29,0x30,0x29,0xd7,0xa9,0x28,0x0,0x0,0x64,0x0,0x29,0x61,0x6e,0x29,0x74, Step #5: `hc \012x`\032\013\000\000\000\000\000\000\000\000))0)\327\251(\000\000d\000)an)t Step #5: artifact_prefix='./'; Test unit written to ./oom-f65001e62460cd12aa9517bc07e56fdd47fcd3f2 Step #5: Base64: YGhjIAp4YBoLAAAAAAAAAAApKTAp16koAABkAClhbil0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2747 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3061249865 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a13991a810, 0x55a139b0401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a139b04020,0x55a13b99c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f65001e62460cd12aa9517bc07e56fdd47fcd3f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3318 processed earlier; will process 7711 files now Step #5: ==98930== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a13040f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a136a74898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a136a575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a136a574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a130415d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a130376b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a130371355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a130407c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1333d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1333d6f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1333d6f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1333d6f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1333d6f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1333d6f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1333d6f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1333d6f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1333d6f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1333d6f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a13566bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a132398b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1323a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a13214fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a13214fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a132150738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a13214f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a13214f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a13214f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a136a59abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a136a62928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a136a4a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a136a75112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f5e227082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a13036fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x2d,0x2d,0xd7,0x81,0x50,0x43,0x44,0x41,0x54,0x41,0x49,0x45,0x54,0x31,0x25,0x2d,0xd7,0x81,0x6c,0x6c,0x73,0x22,0xd7,0x80,0x2d,0x78,0x22,0xd7,0x81,0x2d,0x78, Step #5: 4:2:0.1\012 \012-7:5:8.2-->4:2:0.1\0126 Step #5: artifact_prefix='./'; Test unit written to ./oom-57988928269f233a98d26eee9dbec08a1bb27327 Step #5: Base64: Nzo1OjguMi0tPjQ6MjowLjEKIAotNzo1OjguMi0tPjQ6MjowLjEKNg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3013 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3194954795 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bcef3e0810, 0x55bcef5ca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bcef5ca020,0x55bcf14620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/57988928269f233a98d26eee9dbec08a1bb27327' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3683 processed earlier; will process 7346 files now Step #5: ==108540== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bce5ed59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bcec53a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bcec51d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bcec51d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bce5edbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bce5e3cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bce5e37355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bce5ecdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bce8e9cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bce8e9cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bce8e9cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bce8e9cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bce8e9cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bce8e9cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bce8e9cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bce8e9cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bce8e9cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bce8e9cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bceb131f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bce7e5eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bce7e69be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bce7c15c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bce7c15c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bce7c16738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bce7c15874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bce7c15874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bce7c15874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bcec51fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bcec528928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bcec510699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bcec53b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f30b5bac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bce5e35b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdd,0x84,0xb,0x0,0x0,0x0,0x0,0x1,0x1f,0x0,0x0,0x0,0x0,0x0,0x1f,0x0,0x0,0x1,0x1,0x0,0x0,0x0,0x0,0x1f,0x0,0x0,0x1,0x1,0x0,0x0,0x0,0x0,0x1f,0x0,0x0,0x1,0x1,0x0,0xec,0x1, Step #5: \335\204\013\000\000\000\000\001\037\000\000\000\000\000\037\000\000\001\001\000\000\000\000\037\000\000\001\001\000\000\000\000\037\000\000\001\001\000\354\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-9ec59e1fbf72b3bdfc377be8a2a445aa2478e9eb Step #5: Base64: 3YQLAAAAAAEfAAAAAAAfAAABAQAAAAAfAAABAQAAAAAfAAABAQDsAQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3014 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3195432197 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56340b02d810, 0x56340b21701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56340b217020,0x56340d0af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9ec59e1fbf72b3bdfc377be8a2a445aa2478e9eb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3684 processed earlier; will process 7345 files now Step #5: ==108576== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563401b229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563408187898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56340816a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56340816a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563401b28d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563401a89b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563401a84355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563401b1ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563404ae9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563404ae9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563404ae9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563404ae9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563404ae9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563404ae9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563404ae9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563404ae9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563404ae9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563404ae9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563406d7ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563403aabb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563403ab6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563403862c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563403862c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563403863738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563403862874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563403862874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563403862874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56340816cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563408175928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56340815d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563408188112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0befa42082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563401a82b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x9,0x7e,0x7e,0x45,0x7e,0x7e,0x7e,0xa,0x9,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0xa,0x5c, Step #5: +\012\011~~E~~~\012\011~~~~~~~~~~~~~~~~~~~~~~~~~~~\012\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-4e2e68a4ed2d5b9b552f38df0832dfca0c04a743 Step #5: Base64: KwoJfn5Ffn5+Cgl+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn4KXA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3015 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3195915515 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d9d584810, 0x556d9d76e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d9d76e020,0x556d9f6060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e2e68a4ed2d5b9b552f38df0832dfca0c04a743' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3685 processed earlier; will process 7344 files now Step #5: ==108612== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556d940799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d9a6de898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d9a6c15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d9a6c14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d9407fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d93fe0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d93fdb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d94071c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d97040f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d97040f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d97040f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d97040f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d97040f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d97040f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d97040f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d97040f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d97040f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d97040f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d992d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d96002b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d9600dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d95db9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d95db9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d95dba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d95db9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d95db9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d95db9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d9a6c3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d9a6cc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d9a6b4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d9a6df112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb85802e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d93fd9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xef,0xb7,0xba,0xcc,0x94,0xcc,0x87,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x88,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x98,0xcc,0xba, Step #5: ws:\357\267\272\314\224\314\207\314\273\315\230\314\273\315\230\314\273\315\210\314\273\315\230\314\273\315\230\314\273\315\230\314\273\315\230\314\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-5f231f05e786b9706d600f12699bc18581cff7a6 Step #5: Base64: d3M677e6zJTMh8y7zZjMu82YzLvNiMy7zZjMu82YzLvNmMy7zZjMug== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3016 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3196393474 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562b72e1f810, 0x562b7300901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562b73009020,0x562b74ea10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f231f05e786b9706d600f12699bc18581cff7a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3686 processed earlier; will process 7343 files now Step #5: ==108648== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562b699149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562b6ff79898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562b6ff5c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562b6ff5c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b6991ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b6987bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b69876355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b6990cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b6c8dbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b6c8dbf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b6c8dbf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b6c8dbf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b6c8dbf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b6c8dbf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b6c8dbf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b6c8dbf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b6c8dbf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b6c8dbf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562b6eb70f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b6b89db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b6b8a8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b6b654c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b6b654c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b6b655738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b6b654874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b6b654874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b6b654874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562b6ff5eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562b6ff67928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562b6ff4f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562b6ff7a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb49acf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b69874b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5b,0x5b,0x5b,0x5b,0x0,0x5b,0x53,0x1f,0x3f,0x2d,0x32,0x32,0x5f,0x3f,0x30,0x3a,0xef,0xbd,0xbf,0x5f,0x3f,0x75,0x6c,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x38,0x37,0x34,0x35,0x36,0x32,0x2d,0x2d,0x31,0x2d, Step #5: [[[[[\000[S\037?-22_?0:\357\275\277_?ul:_?0:_874562--1- Step #5: artifact_prefix='./'; Test unit written to ./oom-03d4e57675d971a2dba4070e7049d55b643d87c2 Step #5: Base64: W1tbW1sAW1MfPy0yMl8/MDrvvb9fP3VsOl8/MDpfODc0NTYyLS0xLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3017 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3196878387 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56278f141810, 0x56278f32b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56278f32b020,0x5627911c30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03d4e57675d971a2dba4070e7049d55b643d87c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3687 processed earlier; will process 7342 files now Step #5: ==108684== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562785c369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56278c29b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56278c27e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56278c27e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562785c3cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562785b9db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562785b98355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562785c2ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562788bfdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562788bfdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562788bfdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562788bfdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562788bfdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562788bfdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562788bfdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562788bfdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562788bfdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562788bfdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56278ae92f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562787bbfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562787bcabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562787976c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562787976c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562787977738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562787976874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562787976874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562787976874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56278c280abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56278c289928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56278c271699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56278c29c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5785c6d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562785b96b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x69,0x6c,0x65,0x3a,0xf0,0x91,0x96,0xbd,0xf0,0x91,0x96,0xaf,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x96,0xaf,0x0,0x3a,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x96,0xaf,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x96,0xaf,0x30, Step #5: file:\360\221\226\275\360\221\226\257\360\221\226\271\360\221\226\257\000:\360\221\226\271\360\221\226\257\360\221\226\271\360\221\226\2570 Step #5: artifact_prefix='./'; Test unit written to ./oom-d8c6c42a128748bc798def4f3348b52f31ca8de7 Step #5: Base64: ZmlsZTrwkZa98JGWr/CRlrnwkZavADrwkZa58JGWr/CRlrnwkZavMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3018 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3197361806 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560769cc1810, 0x560769eab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560769eab020,0x56076bd430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d8c6c42a128748bc798def4f3348b52f31ca8de7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3688 processed earlier; will process 7341 files now Step #5: ==108720== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5607607b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560766e1b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560766dfe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560766dfe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5607607bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56076071db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560760718355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5607607aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56076377df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56076377df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56076377df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56076377df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56076377df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56076377df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56076377df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56076377df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56076377df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56076377df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560765a12f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56076273fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56076274abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5607624f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5607624f6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5607624f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5607624f6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5607624f6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5607624f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560766e00abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560766e09928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560766df1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560766e1c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1e6e32b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560760716b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x69,0x66,0x3d,0x42,0x42,0xa,0x3d,0x20,0x9,0x0,0x0,0x0,0x20,0xa,0x3d,0x20,0x20,0x2e,0x1d,0x21,0x2e,0x2d,0x13,0x1d,0x60,0x60,0x20,0x60,0x0,0x60,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x9c,0xa, Step #5: rif=BB\012= \011\000\000\000 \012= .\035!.-\023\035`` `\000`\377\377\377\377\377\377\377\234\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-ac4b71be8c63b92c456d0002bd377193e5bc29af Step #5: Base64: cmlmPUJCCj0gCQAAACAKPSAgLh0hLi0THWBgIGAAYP////////+cCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3019 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3197963923 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5570b5404810, 0x5570b55ee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5570b55ee020,0x5570b74860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ac4b71be8c63b92c456d0002bd377193e5bc29af' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3689 processed earlier; will process 7340 files now Step #5: ==108756== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5570abef99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5570b255e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5570b25415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5570b25414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5570abeffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5570abe60b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5570abe5b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5570abef1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5570aeec0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5570aeec0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5570aeec0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5570aeec0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5570aeec0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5570aeec0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5570aeec0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5570aeec0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5570aeec0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5570aeec0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5570b1155f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5570ade82b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5570ade8dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5570adc39c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5570adc39c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5570adc3a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5570adc39874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5570adc39874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5570adc39874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5570b2543abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5570b254c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5570b2534699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5570b255f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb5b0542082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5570abe59b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1a,0x1a,0x65,0x60,0xdb,0xa4,0x60,0x65,0x60,0xdb,0xa4,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x60,0x42,0x65,0x60,0xdb,0xa4,0x47,0x49,0x4e,0x0,0x2d,0x0,0x60,0x65,0x60,0xdb,0xa4,0x60,0x2d,0xfc,0x42, Step #5: \032\032e`\333\244`e`\333\244\000-----BE`Be`\333\244GIN\000-\000`e`\333\244`-\374B Step #5: artifact_prefix='./'; Test unit written to ./oom-c76571c9413cd7d504c3a234d7b7af497cba34c9 Step #5: Base64: GhplYNukYGVg26QALS0tLS1CRWBCZWDbpEdJTgAtAGBlYNukYC38Qg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3020 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3198563592 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555caeab7810, 0x555caeca101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555caeca1020,0x555cb0b390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c76571c9413cd7d504c3a234d7b7af497cba34c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3690 processed earlier; will process 7339 files now Step #5: #1 pulse cov: 3793 ft: 3794 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 11636 ft: 12499 exec/s: 0 rss: 192Mb Step #5: ==108792== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555ca55ac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555cabc11898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555cabbf45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555cabbf44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ca55b2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ca5513b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ca550e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ca55a4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ca8573f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ca8573f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ca8573f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ca8573f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ca8573f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ca8573f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ca8573f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ca8573f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ca8573f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ca8573f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555caa808f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ca7535b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ca7540be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ca72ecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ca72ecc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ca72ed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ca72ec874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ca72ec874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ca72ec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555cabbf6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555cabbff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555cabbe7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555cabc12112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f47ebb4e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ca550cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7d,0x7d, Step #5: \"\\u{b}\\u{b}\\u{b}\\u{b}\\u{b}\\u{b}\\u{b}\\u}} Step #5: artifact_prefix='./'; Test unit written to ./oom-de2bb946010b40abd0b85bcd6c1a1b66a032c62f Step #5: Base64: Ilx1e2J9XHV7Yn1cdXtifVx1e2J9XHV7Yn1cdXtifVx1e2J9XHV9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3021 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3199142757 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb4be2d810, 0x55cb4c01701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb4c017020,0x55cb4deaf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de2bb946010b40abd0b85bcd6c1a1b66a032c62f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3693 processed earlier; will process 7336 files now Step #5: ==108828== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cb429229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb48f87898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb48f6a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb48f6a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb42928d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb42889b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb42884355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb4291ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb458e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb458e9f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb458e9f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb458e9f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb458e9f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb458e9f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb458e9f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb458e9f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb458e9f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb458e9f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb47b7ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb448abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb448b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb44662c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb44662c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb44663738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb44662874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb44662874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb44662874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb48f6cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb48f75928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb48f5d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb48f88112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d1f7ae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb42882b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x9,0x2b,0xa,0xa,0x9,0x9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x9,0x2b,0x9,0x73,0xa,0x0,0x2b,0x0,0x0,0x0,0x74,0x72,0x65,0x61,0x6d,0x9,0xd5,0x75,0x7e,0x74,0x81,0x81,0x81,0x14,0x81, Step #5: +\011+\012\012\011\011\000\000\000\000\000\000\000\012\011+\011s\012\000+\000\000\000tream\011\325u~t\201\201\201\024\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-f9bafb8c324da01a428ab285b9440ecabf91e7b0 Step #5: Base64: KwkrCgoJCQAAAAAAAAAKCSsJcwoAKwAAAHRyZWFtCdV1fnSBgYEUgQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3022 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3199625452 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55601a2f9810, 0x55601a4e301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55601a4e3020,0x55601c37b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9bafb8c324da01a428ab285b9440ecabf91e7b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3694 processed earlier; will process 7335 files now Step #5: ==108864== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556010dee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556017453898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5560174365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5560174364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556010df4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556010d55b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556010d50355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556010de6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556013db5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556013db5f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556013db5f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556013db5f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556013db5f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556013db5f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556013db5f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556013db5f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556013db5f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556013db5f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55601604af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556012d77b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556012d82be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556012b2ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556012b2ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556012b2f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556012b2e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556012b2e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556012b2e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556017438abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556017441928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556017429699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556017454112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5639673082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556010d4eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xaa, Step #5: \363\252\252\252\363\252\252\256\363\252\252\252\363\252\252\252\363\252\252\256\363\252\252\252\363\252\252\252\363\252\252\256\363\252\252\252\363\252\252\252 Step #5: artifact_prefix='./'; Test unit written to ./oom-b98239d3fb1c3af5ff1a22ddce91c3458e0b7607 Step #5: Base64: 86qqqvOqqq7zqqqq86qqqvOqqq7zqqqq86qqqvOqqq7zqqqq86qqqg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3023 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3200110520 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56051a70c810, 0x56051a8f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56051a8f6020,0x56051c78e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b98239d3fb1c3af5ff1a22ddce91c3458e0b7607' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3695 processed earlier; will process 7334 files now Step #5: ==108900== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5605112019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560517866898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605178495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605178494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560511207d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560511168b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560511163355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5605111f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605141c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605141c8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605141c8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605141c8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605141c8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605141c8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605141c8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605141c8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605141c8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605141c8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56051645df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56051318ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560513195be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560512f41c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560512f41c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560512f42738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560512f41874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560512f41874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560512f41874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56051784babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560517854928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56051783c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560517867112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5fe17a8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560511161b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x0,0xe2,0x80,0xad,0x0,0x0,0x25,0x0,0x0,0x43,0x4f,0x1a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x43,0x4f,0x4d,0x0,0xad,0x0,0x0,0x25,0x0,0x0,0x0,0x24,0x1, Step #5: ID3\002\000\342\200\255\000\000%\000\000CO\032\000\000\000\000\000\000\000\000\000\001\000COM\000\255\000\000%\000\000\000$\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-038a033509247877db0bad451244a9127749ca82 Step #5: Base64: SUQzAgDigK0AACUAAENPGgAAAAAAAAAAAAEAQ09NAK0AACUAAAAkAQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3024 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3200596429 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56416266b810, 0x56416285501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564162855020,0x5641646ed0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/038a033509247877db0bad451244a9127749ca82' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3696 processed earlier; will process 7333 files now Step #5: ==108936== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5641591609c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56415f7c5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56415f7a85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56415f7a84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564159166d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641590c7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641590c2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564159158c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56415c127f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56415c127f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56415c127f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56415c127f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56415c127f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56415c127f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56415c127f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56415c127f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56415c127f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56415c127f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56415e3bcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56415b0e9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56415b0f4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56415aea0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56415aea0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56415aea1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56415aea0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56415aea0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56415aea0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56415f7aaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56415f7b3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56415f79b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56415f7c6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f65a4c3d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641590c0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x77,0x6c,0x3e,0x0,0x0,0x0,0x0,0x0,0x0,0x50,0x4b,0x47,0x5f,0x4e,0x41,0x4d,0x45,0x3d,0x4,0x0,0x0,0xff,0x9,0x0,0x2a,0x28,0x0,0x0,0x0,0x95,0x2,0xf8,0xff,0x0,0x0,0x20,0x0,0xff,0x0, Step #5: \000\000\000\000\000\000PKG_NAME=\004\000\000\377\011\000*(\000\000\000\225\002\370\377\000\000 \000\377\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6581a7a9498ab8c704b678cf4038fd90f943c6a6 Step #5: Base64: PHdsPgAAAAAAAFBLR19OQU1FPQQAAP8JACooAAAAlQL4/wAAIAD/AA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3025 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3201075744 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56115cc68810, 0x56115ce5201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56115ce52020,0x56115ecea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6581a7a9498ab8c704b678cf4038fd90f943c6a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3697 processed earlier; will process 7332 files now Step #5: ==108972== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56115375d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561159dc2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561159da55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561159da54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561153763d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5611536c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5611536bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561153755c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561156724f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561156724f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561156724f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561156724f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561156724f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561156724f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561156724f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561156724f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561156724f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561156724f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5611589b9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611556e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5611556f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56115549dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56115549dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56115549e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56115549d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56115549d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56115549d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561159da7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561159db0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561159d98699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561159dc3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f487c1c5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5611536bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3e,0x32,0x2d,0x28,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x4c,0x43,0xb2,0xb2,0xb2,0xb2,0x24, Step #5: =>2-(\000\000\000\000\000\000\000\\\\\\\\\336\256!\336\256-\\\\\\\\\\\\\\\\\\\\\\LC\262\262\262\262$ Step #5: artifact_prefix='./'; Test unit written to ./oom-8f12316fde8f05c565838f6f2766ef3878a859a0 Step #5: Base64: PT4yLSgAAAAAAAAAXFxcXN6uId6uLVxcXFxcXFxcXFxcTEOysrKyJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3026 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3201554336 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c7bd0e810, 0x564c7bef801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c7bef8020,0x564c7dd900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8f12316fde8f05c565838f6f2766ef3878a859a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3698 processed earlier; will process 7331 files now Step #5: ==109008== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564c728039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c78e68898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c78e4b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c78e4b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c72809d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c7276ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c72765355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c727fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c757caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c757caf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c757caf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c757caf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c757caf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c757caf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c757caf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c757caf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c757caf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c757caf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c77a5ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c7478cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c74797be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c74543c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c74543c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c74544738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c74543874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c74543874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c74543874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c78e4dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c78e56928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c78e3e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c78e69112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc81d39082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c72763b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xcd,0x9e,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x49,0xcd,0x9d,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: ws:\315\236\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204I\315\235\315\204\315\204\315\204\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec16eecbf724d61e25444cc23d81745e04a335f2 Step #5: Base64: d3M6zZ7NhM2EzYTNhM2EzYTNhM2EzYRJzZ3NhM2EzYTNhM2EzYTNhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3027 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3202036025 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b5f642810, 0x557b5f82c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b5f82c020,0x557b616c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec16eecbf724d61e25444cc23d81745e04a335f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3699 processed earlier; will process 7330 files now Step #5: ==109044== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557b561379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b5c79c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b5c77f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b5c77f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b5613dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b5609eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b56099355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b5612fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b590fef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b590fef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b590fef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b590fef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b590fef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b590fef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b590fef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b590fef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b590fef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b590fef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b5b393f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b580c0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b580cbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b57e77c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b57e77c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b57e78738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b57e77874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b57e77874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b57e77874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b5c781abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b5c78a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b5c772699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b5c79d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f9fadb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b56097b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3c,0x74,0x3e,0x28,0x3f,0x3c,0x64,0x3e,0x28,0x3f,0x3c,0x64,0x3e,0x28,0x3f,0x3c,0x64,0x3e,0x28,0x3f,0x3c,0x64,0x3e,0x28,0x3f,0x3c,0x64,0x3e,0x28,0x3f,0x3c,0x64,0x3e,0x28,0x3f,0x3c,0x64,0x3e, Step #5: (?(?(?(?(?(?(?(? Step #5: artifact_prefix='./'; Test unit written to ./oom-b0df1695545969589a9d9ac256f87d60a7997f55 Step #5: Base64: KD88dD4oPzxkPig/PGQ+KD88ZD4oPzxkPig/PGQ+KD88ZD4oPzxkPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3028 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3202510330 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec00f6a810, 0x55ec0115401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec01154020,0x55ec02fec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b0df1695545969589a9d9ac256f87d60a7997f55' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3700 processed earlier; will process 7329 files now Step #5: ==109080== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ebf7a5f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ebfe0c4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ebfe0a75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ebfe0a74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ebf7a65d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ebf79c6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ebf79c1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ebf7a57c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ebfaa26f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ebfaa26f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ebfaa26f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ebfaa26f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ebfaa26f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ebfaa26f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ebfaa26f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ebfaa26f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ebfaa26f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ebfaa26f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ebfccbbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ebf99e8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ebf99f3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ebf979fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ebf979fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ebf97a0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ebf979f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ebf979f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ebf979f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ebfe0a9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ebfe0b2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ebfe09a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ebfe0c5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1fe3a0d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ebf79bfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x54,0x18,0x1,0xa,0x1,0x9,0x79,0x20,0x0,0xc2,0xb7,0x8,0x46,0x55,0x5a,0xf3,0xa0,0x80,0xb5,0x5a,0x2d,0x54,0x18,0x1,0x1,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0xec,0x20,0x0,0x0,0x0,0x2b, Step #5: \000T\030\001\012\001\011y \000\302\267\010FUZ\363\240\200\265Z-T\030\001\001FUZZ-TAG\354 \000\000\000+ Step #5: artifact_prefix='./'; Test unit written to ./oom-a3c707b4eb3307f69c97588cac7469b888601356 Step #5: Base64: AFQYAQoBCXkgAMK3CEZVWvOggLVaLVQYAQFGVVpaLVRBR+wgAAAAKw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3029 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3202990470 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a1861c810, 0x558a1880601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a18806020,0x558a1a69e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a3c707b4eb3307f69c97588cac7469b888601356' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3701 processed earlier; will process 7328 files now Step #5: ==109116== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558a0f1119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a15776898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a157595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a157594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a0f117d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a0f078b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a0f073355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a0f109c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a120d8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a120d8f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a120d8f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a120d8f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a120d8f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a120d8f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a120d8f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a120d8f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a120d8f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a120d8f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a1436df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a1109ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a110a5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a10e51c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a10e51c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a10e52738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a10e51874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a10e51874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a10e51874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a1575babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a15764928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a1574c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a15777112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc561b37082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a0f071b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x0,0x0,0x3,0x8,0x0,0x5f,0x47,0x45,0x4f,0x0,0x0,0x3,0x8,0x0,0x5f,0x47,0x45,0x4f,0x0,0x0,0x3,0x8,0x0,0x5f,0x47,0x45,0x4f,0x0,0x0,0x3,0x8,0x0,0x5f,0x47,0x45,0x4f,0x45, Step #5: ID3\002\000\000\003\010\000_GEO\000\000\003\010\000_GEO\000\000\003\010\000_GEO\000\000\003\010\000_GEOE Step #5: artifact_prefix='./'; Test unit written to ./oom-664d8c98141c51e867a04c5e83352a684a5c15f4 Step #5: Base64: SUQzAgAAAwgAX0dFTwAAAwgAX0dFTwAAAwgAX0dFTwAAAwgAX0dFT0U= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3030 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3203468682 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55745b9a4810, 0x55745bb8e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55745bb8e020,0x55745da260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/664d8c98141c51e867a04c5e83352a684a5c15f4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3702 processed earlier; will process 7327 files now Step #5: ==109152== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5574524999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557458afe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557458ae15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557458ae14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55745249fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557452400b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5574523fb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557452491c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557455460f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557455460f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557455460f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557455460f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557455460f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557455460f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557455460f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557455460f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557455460f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557455460f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5574576f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557454422b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55745442dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5574541d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5574541d9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5574541da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5574541d9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5574541d9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5574541d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557458ae3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557458aec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557458ad4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557458aff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd0a80e8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5574523f9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x26,0x22,0xd6,0x8a,0xd6,0x8a,0xd6,0x8a,0xd6,0x8a,0xd6,0x8a,0xd6,0x8a,0xd6,0x8a,0xd6,0xaa,0xd6,0x8a,0xd6,0x8a,0xd6,0x8a,0xd6,0x8a,0xd6,0x8a,0xd6,0x8a,0xd6,0x8a,0xd6,0x27,0xff,0x1c,0xaa,0x61,0x21, Step #5: HU&\"\326\212\326\212\326\212\326\212\326\212\326\212\326\212\326\252\326\212\326\212\326\212\326\212\326\212\326\212\326\212\326'\377\034\252a! Step #5: artifact_prefix='./'; Test unit written to ./oom-b5dab88180c620c83375a4073b25d817696991a4 Step #5: Base64: SFUmItaK1orWitaK1orWitaK1qrWitaK1orWitaK1orWitYn/xyqYSE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3031 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3203949749 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5579e5e76810, 0x5579e606001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5579e6060020,0x5579e7ef80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b5dab88180c620c83375a4073b25d817696991a4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3703 processed earlier; will process 7326 files now Step #5: ==109188== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5579dc96b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5579e2fd0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5579e2fb35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5579e2fb34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5579dc971d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5579dc8d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5579dc8cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5579dc963c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5579df932f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5579df932f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5579df932f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5579df932f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5579df932f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5579df932f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5579df932f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5579df932f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5579df932f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5579df932f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579e1bc7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5579de8f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5579de8ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5579de6abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5579de6abc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5579de6ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5579de6ab874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5579de6ab874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5579de6ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5579e2fb5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5579e2fbe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5579e2fa6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5579e2fd1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8cf2342082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5579dc8cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x11,0xde,0xa6,0x0,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x2e,0x0,0x0,0x0,0x42,0x0,0x0,0x0,0x30,0x0, Step #5: \021\336\246\000999999999999999999999999999.\000\000\000B\000\000\0000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a9e142e2eec825ecec2b19d05de8f18f269469e4 Step #5: Base64: Ed6mADk5OTk5OTk5OTk5OTk5OTk5OTk5OTk5OTk5OS4AAABCAAAAMAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3032 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3204424592 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561df2aaa810, 0x561df2c9401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561df2c94020,0x561df4b2c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9e142e2eec825ecec2b19d05de8f18f269469e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3704 processed earlier; will process 7325 files now Step #5: ==109224== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561de959f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561defc04898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561defbe75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561defbe74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561de95a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561de9506b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561de9501355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561de9597c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561dec566f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561dec566f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561dec566f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561dec566f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561dec566f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561dec566f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561dec566f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561dec566f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561dec566f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561dec566f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561dee7fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561deb528b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561deb533be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561deb2dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561deb2dfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561deb2e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561deb2df874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561deb2df874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561deb2df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561defbe9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561defbf2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561defbda699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561defc05112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc55cd5b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561de94ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3e,0x32,0x2d,0x3d,0x3e,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x2d,0x5c,0x5c,0x4c,0x43,0xb2,0xb2,0xb2,0xb2,0x24, Step #5: =>2-=>\336\256!\336\256-\\\\\\\\\336\256!\336\256-\\\\\\\\\\\\\\\\\\-\\\\LC\262\262\262\262$ Step #5: artifact_prefix='./'; Test unit written to ./oom-91fb195b5795db29ce8a5b91f3707c08455d4474 Step #5: Base64: PT4yLT0+3q4h3q4tXFxcXN6uId6uLVxcXFxcXFxcXC1cXExDsrKysiQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3033 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3204904203 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557ef5aa5810, 0x557ef5c8f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557ef5c8f020,0x557ef7b270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/91fb195b5795db29ce8a5b91f3707c08455d4474' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3705 processed earlier; will process 7324 files now Step #5: ==109260== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557eec59a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557ef2bff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557ef2be25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557ef2be24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557eec5a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557eec501b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557eec4fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557eec592c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557eef561f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557eef561f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557eef561f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557eef561f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557eef561f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557eef561f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557eef561f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557eef561f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557eef561f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557eef561f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557ef17f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557eee523b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557eee52ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557eee2dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557eee2dac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557eee2db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557eee2da874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557eee2da874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557eee2da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557ef2be4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557ef2bed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557ef2bd5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557ef2c00112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6799aaf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557eec4fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0x32,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x0,0x11,0xf,0x31,0x11,0x2d,0x0,0x0,0x0,0x2f,0x0,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x2d,0x3a,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\0172\0171\021\0171\021-\000\021\0171\021-\000\000\000/\000\0171\021\0171\021-:-:$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-8cb4c2e99fbad3363da4f7e5c68f4db5e2e6ddc7 Step #5: Base64: JAAALwAAAC8ADzIPMREPMREtABEPMREtAAAALwAPMREPMREtOi06JFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3034 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3205388098 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea3475a810, 0x55ea3494401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea34944020,0x55ea367dc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8cb4c2e99fbad3363da4f7e5c68f4db5e2e6ddc7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3706 processed earlier; will process 7323 files now Step #5: ==109296== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ea2b24f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea318b4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea318975dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea318974fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea2b255d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea2b1b6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea2b1b1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea2b247c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea2e216f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea2e216f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea2e216f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea2e216f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea2e216f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea2e216f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea2e216f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea2e216f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea2e216f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea2e216f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea304abf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea2d1d8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea2d1e3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea2cf8fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea2cf8fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea2cf90738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea2cf8f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea2cf8f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea2cf8f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea31899abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea318a2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea3188a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea318b5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f395a660082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea2b1afb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3e,0x32,0x2d,0x3d,0x3e,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xce,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x2d,0x5c,0x5c,0x4c,0x43,0xb2,0xb2,0xb2,0xb2,0x24, Step #5: =>2-=>\336\256!\336\256-\\\\\\\\\336\256!\316\256-\\\\\\\\\\\\\\\\\\-\\\\LC\262\262\262\262$ Step #5: artifact_prefix='./'; Test unit written to ./oom-c62eccb8f133d72c0efed8b325ac5716f04f7158 Step #5: Base64: PT4yLT0+3q4h3q4tXFxcXN6uIc6uLVxcXFxcXFxcXC1cXExDsrKysiQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3035 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3205867266 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c59e78810, 0x564c5a06201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c5a062020,0x564c5befa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c62eccb8f133d72c0efed8b325ac5716f04f7158' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3707 processed earlier; will process 7322 files now Step #5: ==109332== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564c5096d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c56fd2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c56fb55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c56fb54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c50973d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c508d4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c508cf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c50965c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c53934f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c53934f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c53934f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c53934f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c53934f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c53934f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c53934f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c53934f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c53934f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c53934f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c55bc9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c528f6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c52901be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c526adc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c526adc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c526ae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c526ad874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c526ad874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c526ad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c56fb7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c56fc0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c56fa8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c56fd3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc26c823082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c508cdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x25,0xd,0x25,0x59,0x41,0x4d,0x4c,0x20,0x36,0x2e,0x30,0x31,0x23,0x35,0x7e,0xf0,0x90,0x90,0x8d,0x6f,0xd8,0x8c,0x7e,0xf0,0x90,0x90,0xa4,0x21,0x6d,0xd8,0x8c,0x7e,0xf0,0x90,0x90,0xa4,0x63,0x20, Step #5: \000\000\000%\015%YAML 6.01#5~\360\220\220\215o\330\214~\360\220\220\244!m\330\214~\360\220\220\244c Step #5: artifact_prefix='./'; Test unit written to ./oom-4b70c0ad3cdfc22e5fc7a67bac7deff933022d29 Step #5: Base64: AAAAJQ0lWUFNTCA2LjAxIzV+8JCQjW/YjH7wkJCkIW3YjH7wkJCkYyA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3036 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3206345509 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b517e84810, 0x55b51806e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b51806e020,0x55b519f060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4b70c0ad3cdfc22e5fc7a67bac7deff933022d29' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3708 processed earlier; will process 7321 files now Step #5: ==109368== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b50e9799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b514fde898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b514fc15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b514fc14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b50e97fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b50e8e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b50e8db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b50e971c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b511940f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b511940f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b511940f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b511940f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b511940f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b511940f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b511940f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b511940f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b511940f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b511940f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b513bd5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b510902b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b51090dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b5106b9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b5106b9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b5106ba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b5106b9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b5106b9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b5106b9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b514fc3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b514fcc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b514fb4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b514fdf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ca1a9b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b50e8d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x40,0x2a,0x2a,0x2a,0x2a,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x3b,0x2a,0x2a,0x2a,0x0,0x0,0x1e,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x3b,0x2a,0x2a,0x2a,0x2a,0x25,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x57, Step #5: @****\000******;***\000\000\036*********;****%******W Step #5: artifact_prefix='./'; Test unit written to ./oom-5dc07d26076a2e9e3700326df6ab725eb906e07f Step #5: Base64: QCoqKioAKioqKioqOyoqKgAAHioqKioqKioqKjsqKioqJSoqKioqKlc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3037 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3206829227 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d65332810, 0x561d6551c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d6551c020,0x561d673b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5dc07d26076a2e9e3700326df6ab725eb906e07f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3709 processed earlier; will process 7320 files now Step #5: ==109404== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561d5be279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d6248c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d6246f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d6246f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d5be2dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d5bd8eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d5bd89355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d5be1fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d5edeef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d5edeef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d5edeef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d5edeef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d5edeef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d5edeef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d5edeef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d5edeef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d5edeef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d5edeef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d61083f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d5ddb0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d5ddbbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d5db67c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d5db67c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d5db68738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d5db67874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d5db67874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d5db67874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d62471abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d6247a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d62462699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d6248d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff2e3e59082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d5bd87b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x69,0x66,0x31,0x30,0x29,0x29,0x29,0x29,0xd7,0xa9,0x28,0x0,0x0,0x0,0x51,0x51,0x0,0x30,0x29,0x74,0x0,0x10,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x30,0x9,0x0,0x0,0x0, Step #5: !if10))))\327\251(\000\000\000QQ\0000)t\000\020\000\000\000\000\000\000\000\000\000\000\000\000\0000\011\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8ec5e3054d051eb5859e68f092deb8d7d4bab23d Step #5: Base64: IWlmMTApKSkp16koAAAAUVEAMCl0ABAAAAAAAAAAAAAAAAAAMAkAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3038 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3207306622 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c853cc810, 0x561c855b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c855b6020,0x561c8744e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ec5e3054d051eb5859e68f092deb8d7d4bab23d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3710 processed earlier; will process 7319 files now Step #5: ==109440== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561c7bec19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c82526898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c825095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c825094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c7bec7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c7be28b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c7be23355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c7beb9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c7ee88f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c7ee88f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c7ee88f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c7ee88f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c7ee88f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c7ee88f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c7ee88f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c7ee88f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c7ee88f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c7ee88f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c8111df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c7de4ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c7de55be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c7dc01c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c7dc01c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c7dc02738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c7dc01874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c7dc01874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c7dc01874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c8250babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c82514928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c824fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c82527112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d29c3e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c7be21b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0x72,0x65,0x61,0x74,0x65,0x32,0x2d,0x66,0x6f,0x72,0x6d,0x61,0x74,0x73,0x9,0x32,0xa,0x66,0x6c,0x6f,0x77,0x2d,0x63,0x6f,0x6e,0x74,0x72,0x6f,0x6c,0x23,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x37, Step #5: create2-formats\0112\012flow-control#2147483647 Step #5: artifact_prefix='./'; Test unit written to ./oom-a8115483d4ab5bca3f4448e7c22397d7b5e4bc84 Step #5: Base64: Y3JlYXRlMi1mb3JtYXRzCTIKZmxvdy1jb250cm9sIzIxNDc0ODM2NDc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3039 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3207781550 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556e3148a810, 0x556e3167401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556e31674020,0x556e3350c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a8115483d4ab5bca3f4448e7c22397d7b5e4bc84' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3711 processed earlier; will process 7318 files now Step #5: ==109476== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556e27f7f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556e2e5e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556e2e5c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556e2e5c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556e27f85d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556e27ee6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556e27ee1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556e27f77c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556e2af46f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556e2af46f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556e2af46f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556e2af46f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556e2af46f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556e2af46f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556e2af46f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556e2af46f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556e2af46f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556e2af46f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556e2d1dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556e29f08b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556e29f13be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556e29cbfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556e29cbfc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556e29cc0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556e29cbf874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556e29cbf874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556e29cbf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556e2e5c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556e2e5d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556e2e5ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556e2e5e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7025d71082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556e27edfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x81,0xa5,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c, Step #5: \363\240\201\245\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-49c791bd0867c1c8b02268606223111835d0e281 Step #5: Base64: 86CBpVxcXFxcXFxcXFxcXFxcXFxcXFxcXFxcXFxcXFxcXFxcXFxcXFw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3040 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3208256249 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc981f6810, 0x55cc983e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc983e0020,0x55cc9a2780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/49c791bd0867c1c8b02268606223111835d0e281' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3712 processed earlier; will process 7317 files now Step #5: ==109512== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cc8eceb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc95350898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc953335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc953334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc8ecf1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc8ec52b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc8ec4d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc8ece3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc91cb2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc91cb2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc91cb2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc91cb2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc91cb2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc91cb2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc91cb2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc91cb2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc91cb2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc91cb2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc93f47f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc90c74b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc90c7fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc90a2bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc90a2bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc90a2c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc90a2b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc90a2b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc90a2b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc95335abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc9533e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc95326699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc95351112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7ebd09082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc8ec4bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d, Step #5: - - - - - - - - - - - - - - - - - - - - - Step #5: artifact_prefix='./'; Test unit written to ./oom-78991b10e6282cdcbfbca8cc8f5cd910d004bdde Step #5: Base64: LSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3041 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3208772976 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ad62248810, 0x55ad6243201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ad62432020,0x55ad642ca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/78991b10e6282cdcbfbca8cc8f5cd910d004bdde' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3713 processed earlier; will process 7316 files now Step #5: ==109548== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ad58d3d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ad5f3a2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ad5f3855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ad5f3854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ad58d43d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ad58ca4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ad58c9f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ad58d35c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ad5bd04f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ad5bd04f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ad5bd04f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ad5bd04f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ad5bd04f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ad5bd04f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ad5bd04f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ad5bd04f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ad5bd04f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ad5bd04f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ad5df99f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ad5acc6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ad5acd1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ad5aa7dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ad5aa7dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ad5aa7e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ad5aa7d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ad5aa7d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ad5aa7d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ad5f387abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ad5f390928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ad5f378699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ad5f3a3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa9bb3d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ad58c9db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x51,0x30,0x35,0x5c,0x53,0x5c,0x53,0x5c,0x52,0x5c,0x3b,0x5c,0x65,0x5c,0x30,0x79,0x5b,0x71,0x2d,0xf0,0x97,0xa7,0xa7,0x52,0x2d,0xf0,0x97,0xa7,0xa7,0x52,0x5c,0x5c,0x53,0x26,0x52,0x53,0xfe,0xff,0xff,0xff, Step #5: BQ05\\S\\S\\R\\;\\e\\0y[q-\360\227\247\247R-\360\227\247\247R\\\\S&RS\376\377\377\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-0844c9e60af7275e0241d76e3484059154d601d5 Step #5: Base64: QlEwNVxTXFNcUlw7XGVcMHlbcS3wl6enUi3wl6enUlxcUyZSU/7///8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3042 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3209256022 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56203f383810, 0x56203f56d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56203f56d020,0x5620414050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0844c9e60af7275e0241d76e3484059154d601d5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3714 processed earlier; will process 7315 files now Step #5: ==109584== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562035e789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56203c4dd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56203c4c05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56203c4c04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562035e7ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562035ddfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562035dda355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562035e70c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562038e3ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562038e3ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562038e3ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562038e3ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562038e3ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562038e3ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562038e3ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562038e3ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562038e3ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562038e3ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56203b0d4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562037e01b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562037e0cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562037bb8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562037bb8c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562037bb9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562037bb8874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562037bb8874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562037bb8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56203c4c2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56203c4cb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56203c4b3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56203c4de112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe5b0888082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562035dd8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd3,0x81,0xe6,0x8d,0x8b,0x5b,0x7e,0x39,0xf3,0xa0,0x80,0xa9,0xd3,0x81,0xe6,0x80,0xa9,0xd3,0x81,0xe6,0x8d,0x8b,0x5b,0x7e,0x39,0x80,0xf3,0xe6,0x81,0xa9,0xa0,0xd3,0x8d,0x8b,0x5b,0x7e,0xf3,0xa0,0x80,0x9b,0x73, Step #5: \323\201\346\215\213[~9\363\240\200\251\323\201\346\200\251\323\201\346\215\213[~9\200\363\346\201\251\240\323\215\213[~\363\240\200\233s Step #5: artifact_prefix='./'; Test unit written to ./oom-47f74b05d8963fa5abda2a8365412c5e781cddea Step #5: Base64: 04HmjYtbfjnzoICp04HmgKnTgeaNi1t+OYDz5oGpoNONi1t+86CAm3M= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3043 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3209739161 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af8ef53810, 0x55af8f13d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af8f13d020,0x55af90fd50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/47f74b05d8963fa5abda2a8365412c5e781cddea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3715 processed earlier; will process 7314 files now Step #5: ==109620== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55af85a489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af8c0ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af8c0905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af8c0904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55af85a4ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55af859afb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55af859aa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55af85a40c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55af88a0ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55af88a0ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55af88a0ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55af88a0ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55af88a0ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55af88a0ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55af88a0ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55af88a0ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55af88a0ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55af88a0ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af8aca4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af879d1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af879dcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af87788c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af87788c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af87789738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af87788874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af87788874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af87788874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af8c092abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af8c09b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af8c083699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af8c0ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f723a548082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55af859a8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x67,0x6c,0x79,0x66,0x66,0x67,0x7f,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x67,0x7f,0x79,0x3b,0x67,0x66,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x6e, Step #5: tglyffg\177fg\177f;g?tglg\177y;gff?f;g?tglyf?g?g?n Step #5: artifact_prefix='./'; Test unit written to ./oom-ed44fe8b0a9e682183debd580d732a0bc5639b12 Step #5: Base64: dGdseWZmZ39mZ39mO2c/dGdsZ395O2dmZj9mO2c/dGdseWY/Zz9nP24= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3044 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3210227117 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5636833d4810, 0x5636835be01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5636835be020,0x5636854560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ed44fe8b0a9e682183debd580d732a0bc5639b12' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3716 processed earlier; will process 7313 files now Step #5: #1 pulse cov: 3998 ft: 3999 exec/s: 0 rss: 173Mb Step #5: ==109656== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563679ec99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56368052e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636805115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636805114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563679ecfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563679e30b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563679e2b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563679ec1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56367ce90f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56367ce90f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56367ce90f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56367ce90f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56367ce90f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56367ce90f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56367ce90f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56367ce90f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56367ce90f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56367ce90f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56367f125f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56367be52b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56367be5dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56367bc09c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56367bc09c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56367bc0a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56367bc09874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56367bc09874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56367bc09874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563680513abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56368051c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563680504699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56368052f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f917296b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563679e29b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0xa,0x2d,0x20,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x24,0x24,0x3b,0xa,0x2d,0x20, Step #5: x-----BE----BEGIN -----\012\012- GIN ----$$;\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-75f3f4f922f0f1ae51953d07f02165d58babd02a Step #5: Base64: eC0tLS0tQkUtLS0tQkVHSU4gLS0tLS0KCi0gR0lOIC0tLS0kJDsKLSA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3045 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3210753630 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556082b92810, 0x556082d7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556082d7c020,0x556084c140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/75f3f4f922f0f1ae51953d07f02165d58babd02a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3718 processed earlier; will process 7311 files now Step #5: #1 pulse cov: 3584 ft: 3585 exec/s: 0 rss: 173Mb Step #5: ==109692== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5560796879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55607fcec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55607fccf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55607fccf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55607968dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5560795eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5560795e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55607967fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55607c64ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55607c64ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55607c64ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55607c64ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55607c64ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55607c64ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55607c64ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55607c64ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55607c64ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55607c64ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55607e8e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55607b610b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55607b61bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55607b3c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55607b3c7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55607b3c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55607b3c7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55607b3c7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55607b3c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55607fcd1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55607fcda928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55607fcc2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55607fced112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6d461be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5560795e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xac,0xac,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xe3,0x8f,0xaf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8c,0xb4,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xcd,0x84,0xe3,0x8d,0xbf, Step #5: \357\254\254\343\215\277\343\214\226\357\267\274\343\217\257\343\214\226\357\267\274\343\216\257\343\216\257\343\214\264\343\214\226\357\267\274\315\204\343\215\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-bfe252d06e0ac4bb44f5eaec9b5c0930153bb226 Step #5: Base64: 76ys442/44yW77e844+v44yW77e8446v446v44y044yW77e8zYTjjb8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3046 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3211273182 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561e7e1d5810, 0x561e7e3bf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561e7e3bf020,0x561e802570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bfe252d06e0ac4bb44f5eaec9b5c0930153bb226' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3720 processed earlier; will process 7309 files now Step #5: #1 pulse cov: 10916 ft: 10917 exec/s: 0 rss: 190Mb Step #5: #2 pulse cov: 11750 ft: 12588 exec/s: 0 rss: 192Mb Step #5: #4 pulse cov: 14454 ft: 20529 exec/s: 0 rss: 197Mb Step #5: ==109728== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x561e74cca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561e7b32f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561e7b3125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561e7b3124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561e74cd0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561e74c31b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561e74c2c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561e74cc2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561e77c91f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561e77c91f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561e77c91f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561e77c91f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561e77c91f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561e77c91f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561e77c91f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561e77c91f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561e77c91f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561e77c91f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561e79f26f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561e76c53b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561e76c5ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561e76a0ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561e76a0ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561e76a0b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561e76a0a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561e76a0a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561e76a0a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561e7b314abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561e7b31d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561e7b305699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561e7b330112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f11a5944082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561e74c2ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x52,0x53,0x41,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x4b,0x45,0x59,0x42,0x45,0x2d,0x2d,0x2d,0xa, Step #5: onion-key\012-----BEGIN RSA PUBLIC KEYBE---\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-c9b1d0313eedfb6a0e37cd8bfd45382c394fb46f Step #5: Base64: b25pb24ta2V5Ci0tLS0tQkVHSU4gUlNBIFBVQkxJQyBLRVlCRS0tLQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3047 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3211946607 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e66115d810, 0x55e66134701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e661347020,0x55e6631df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9b1d0313eedfb6a0e37cd8bfd45382c394fb46f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3725 processed earlier; will process 7304 files now Step #5: ==109764== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e657c529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e65e2b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e65e29a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e65e29a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e657c58d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e657bb9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e657bb4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e657c4ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e65ac19f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e65ac19f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e65ac19f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e65ac19f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e65ac19f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e65ac19f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e65ac19f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e65ac19f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e65ac19f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e65ac19f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e65ceaef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e659bdbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e659be6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e659992c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e659992c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e659993738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e659992874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e659992874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e659992874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e65e29cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e65e2a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e65e28d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e65e2b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff185b18082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e657bb2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x2f,0x26,0x2f,0x23,0x22,0x26,0x2f,0x73,0x25,0x36,0x36,0x34,0x37,0x37,0x26,0x2f,0x73,0x25,0x36,0x36,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0xe2,0x80,0xaa,0x32,0x37,0x30,0x26,0x2f,0x23,0x22,0x26,0x2f,0x26, Step #5: '/&/#\"&/s%66477&/s%664294967\342\200\252270&/#\"&/& Step #5: artifact_prefix='./'; Test unit written to ./oom-9f954bad34b89cd7f6eaf664c77512b20833b295 Step #5: Base64: Jy8mLyMiJi9zJTY2NDc3Ji9zJTY2NDI5NDk2N+KAqjI3MCYvIyImLyY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3048 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3212426649 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bc4f7d7810, 0x55bc4f9c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bc4f9c1020,0x55bc518590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f954bad34b89cd7f6eaf664c77512b20833b295' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3726 processed earlier; will process 7303 files now Step #5: #1 pulse cov: 4067 ft: 4068 exec/s: 0 rss: 172Mb Step #5: #2 pulse cov: 4441 ft: 4857 exec/s: 0 rss: 173Mb Step #5: ==109800== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bc462cc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bc4c931898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bc4c9145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bc4c9144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bc462d2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bc46233b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bc4622e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bc462c4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bc49293f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bc49293f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bc49293f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bc49293f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bc49293f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bc49293f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bc49293f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bc49293f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bc49293f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bc49293f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bc4b528f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bc48255b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bc48260be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bc4800cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bc4800cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bc4800d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bc4800c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bc4800c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bc4800c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bc4c916abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bc4c91f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bc4c907699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bc4c932112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a9024e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bc4622cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x0,0x5b,0x27,0x5b,0x13,0x0,0x18,0x0,0x5b,0x28,0x5d,0x5b,0x27,0x5b,0x13,0x0,0x18,0x0,0x5b,0x28,0x5d,0x5b,0x27,0x5d,0x5b,0x28,0x5d,0x5b,0x27,0x27,0x5d,0x5b,0x28,0x5d,0x5b,0x27,0x5d,0x5b,0x28,0x0, Step #5: 0\000['[\023\000\030\000[(]['[\023\000\030\000[(]['][(][''][(]['][(\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-be1182bac1e53ae49393b4c030fc52b18e2fd3ae Step #5: Base64: MABbJ1sTABgAWyhdWydbEwAYAFsoXVsnXVsoXVsnJ11bKF1bJ11bKAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3049 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3213017458 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e572b82810, 0x55e572d6c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e572d6c020,0x55e574c040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/be1182bac1e53ae49393b4c030fc52b18e2fd3ae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3730 processed earlier; will process 7299 files now Step #5: ==109836== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e5696779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e56fcdc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e56fcbf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e56fcbf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e56967dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e5695deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e5695d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e56966fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e56c63ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e56c63ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e56c63ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e56c63ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e56c63ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e56c63ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e56c63ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e56c63ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e56c63ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e56c63ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e56e8d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e56b600b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e56b60bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e56b3b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e56b3b7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e56b3b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e56b3b7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e56b3b7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e56b3b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e56fcc1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e56fcca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e56fcb2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e56fcdd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7b6e813082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e5695d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x61,0x5c,0x75,0x7b,0x44,0x7d,0x5c,0x75,0x7b,0x44,0x7d,0x5c,0x75,0x7b,0x44,0x7d,0x5c,0x75,0x7b,0x44,0x7d,0x5c,0x75,0x7b,0x44,0x7d,0x5c,0x75,0x7b,0x44,0x7d,0x5c,0x75,0x7b,0x44,0x7d,0x5c,0x75,0x7b,0x44,0x7d, Step #5: a\\u{D}\\u{D}\\u{D}\\u{D}\\u{D}\\u{D}\\u{D}\\u{D} Step #5: artifact_prefix='./'; Test unit written to ./oom-5a3933bced0b5869f14ff637d6d27f0c6ec9e1db Step #5: Base64: YVx1e0R9XHV7RH1cdXtEfVx1e0R9XHV7RH1cdXtEfVx1e0R9XHV7RH0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3050 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3213495647 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5564cf270810, 0x5564cf45a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564cf45a020,0x5564d12f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5a3933bced0b5869f14ff637d6d27f0c6ec9e1db' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3731 processed earlier; will process 7298 files now Step #5: #1 pulse cov: 4172 ft: 4173 exec/s: 0 rss: 175Mb Step #5: ==109872== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5564c5d659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564cc3ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564cc3ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564cc3ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564c5d6bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5564c5cccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5564c5cc7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564c5d5dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564c8d2cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564c8d2cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564c8d2cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564c8d2cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564c8d2cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564c8d2cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564c8d2cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564c8d2cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564c8d2cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564c8d2cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5564cafc1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5564c7ceeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5564c7cf9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5564c7aa5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5564c7aa5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5564c7aa6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5564c7aa5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5564c7aa5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5564c7aa5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564cc3afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564cc3b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564cc3a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564cc3cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6214965082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5564c5cc5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x30,0x2,0x77,0x9,0x63,0x62,0x63,0x63,0x54,0xd3,0xbf,0xe2,0x81,0xa8,0x3c,0xc7,0xff,0xe2,0x80,0x82,0x2,0xda,0xb9,0xdf,0x2b,0x2,0xdb,0x2,0xdf,0x2d,0x2d,0x31,0xdb,0xbf,0xdf,0xb,0xdb,0xbf,0xdf, Step #5: ID0\002w\011cbccT\323\277\342\201\250<\307\377\342\200\202\002\332\271\337+\002\333\002\337--1\333\277\337\013\333\277\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-fffa03d2ad4927c80d53a47063996975e8d73368 Step #5: Base64: SUQwAncJY2JjY1TTv+KBqDzH/+KAggLaud8rAtsC3y0tMdu/3wvbv98= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3051 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3214013956 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560ac5ff4810, 0x560ac61de01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560ac61de020,0x560ac80760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fffa03d2ad4927c80d53a47063996975e8d73368' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3733 processed earlier; will process 7296 files now Step #5: ==109908== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560abcae99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560ac314e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560ac31315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560ac31314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560abcaefd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560abca50b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560abca4b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560abcae1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560abfab0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560abfab0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560abfab0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560abfab0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560abfab0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560abfab0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560abfab0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560abfab0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560abfab0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560abfab0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560ac1d45f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560abea72b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560abea7dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560abe829c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560abe829c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560abe82a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560abe829874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560abe829874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560abe829874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560ac3133abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560ac313c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560ac3124699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560ac314f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6375747082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560abca49b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x12,0x27,0x32,0x3d,0x3c,0x37,0x27,0x2f,0x30,0x27,0x67,0x27,0x27,0x66,0x7d,0x27,0x27,0x27,0x27,0x34,0xe2,0x81,0xa5,0x2d,0x3d,0x27,0x34,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x35,0x27,0x24,0x27,0x2d, Step #5: $2\022'2=<7'/0'g''f}''''4\342\201\245-='4'''''''5'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-81011460da00ec1b38d88f79242afa8cd95558fa Step #5: Base64: JDISJzI9PDcnLzAnZycnZn0nJycnNOKBpS09JzQnJycnJycnNSckJy0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3052 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3214500527 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b5b9994810, 0x55b5b9b7e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b5b9b7e020,0x55b5bba160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/81011460da00ec1b38d88f79242afa8cd95558fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3734 processed earlier; will process 7295 files now Step #5: ==109944== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b5b04899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b5b6aee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b5b6ad15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b5b6ad14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b5b048fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b5b03f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b5b03eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b5b0481c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b5b3450f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b5b3450f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b5b3450f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b5b3450f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b5b3450f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b5b3450f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b5b3450f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b5b3450f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b5b3450f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b5b3450f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b5b56e5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b5b2412b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b5b241dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b5b21c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b5b21c9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b5b21ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b5b21c9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b5b21c9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b5b21c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b5b6ad3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b5b6adc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b5b6ac4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b5b6aef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2845fc3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b5b03e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x67,0x6c,0x79,0x66,0x66,0x67,0x7f,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x67,0x7f,0x66,0x3b,0x67,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x6e, Step #5: tglyffg\177fg\177f;g?tglyg\177f;gf?f;g?tglyf?g?g?n Step #5: artifact_prefix='./'; Test unit written to ./oom-614cb6dba1539c9d94f551516f9b82fd9a3b1bf6 Step #5: Base64: dGdseWZmZ39mZ39mO2c/dGdseWd/ZjtnZj9mO2c/dGdseWY/Zz9nP24= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3053 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3214986506 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b2c8db810, 0x556b2cac501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b2cac5020,0x556b2e95d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/614cb6dba1539c9d94f551516f9b82fd9a3b1bf6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3735 processed earlier; will process 7294 files now Step #5: ==109980== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556b233d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b29a35898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b29a185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b29a184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b233d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b23337b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b23332355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b233c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b26397f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b26397f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b26397f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b26397f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b26397f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b26397f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b26397f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b26397f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b26397f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b26397f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b2862cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b25359b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b25364be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b25110c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b25110c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b25111738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b25110874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b25110874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b25110874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b29a1aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b29a23928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b29a0b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b29a36112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f94155ba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b23330b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0x90,0xd9,0x90,0xd9,0x91,0xd9,0x90,0xd9,0x91,0x20,0xef,0xb8,0x8f,0xd9,0x90,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: \331\220\331\220\331\221\331\220\331\221 \357\270\217\331\220' Step #5: artifact_prefix='./'; Test unit written to ./oom-00675b840640898b30ae1ebf7e72ac4af6faf1a3 Step #5: Base64: PHN2Zz48dGV4dD7ZkNmQ2ZHZkNmRIO+4j9mQJzwvdGV4dD48L3N2Zz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3054 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3215471808 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5600f882b810, 0x5600f8a1501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5600f8a15020,0x5600fa8ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/00675b840640898b30ae1ebf7e72ac4af6faf1a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3736 processed earlier; will process 7293 files now Step #5: ==110016== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5600ef3209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5600f5985898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5600f59685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5600f59684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5600ef326d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5600ef287b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5600ef282355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5600ef318c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5600f22e7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5600f22e7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5600f22e7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5600f22e7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5600f22e7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5600f22e7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5600f22e7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5600f22e7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5600f22e7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5600f22e7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5600f457cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5600f12a9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5600f12b4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5600f1060c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5600f1060c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5600f1061738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5600f1060874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5600f1060874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5600f1060874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5600f596aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5600f5973928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5600f595b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5600f5986112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0e62934082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5600ef280b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x65,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3d,0x22,0x63,0x68,0x61,0x72,0x22,0x0,0x78,0xcd,0xab,0xcd,0xab,0xcd,0xab,0xcd,0xab,0xcd,0xab,0xcd,0xab,0xcd,0xab,0xcd,0xab,0x28,0x3f, Step #5: Step #5: Step #5: #0 0x55d29e8819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d2a4ee6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d2a4ec95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d2a4ec94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d29e887d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d29e7e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d29e7e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d29e879c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d2a1848f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d2a1848f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d2a1848f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d2a1848f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d2a1848f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d2a1848f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d2a1848f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d2a1848f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d2a1848f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d2a1848f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d2a3addf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d2a080ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d2a0815be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d2a05c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d2a05c1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d2a05c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d2a05c1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d2a05c1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d2a05c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d2a4ecbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d2a4ed4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d2a4ebc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d2a4ee7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a7ea49082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d29e7e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd8,0xad,0x29,0x7e,0x76,0x21,0x39,0xa,0x0,0xe2,0x81,0x9f,0x7d,0x7d,0x7d,0x7d,0xd7,0xaf,0x69,0x66,0x7d,0xd7,0xaf,0x6d,0x0,0x7e,0x73,0x74,0x39,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3f,0x30, Step #5: \330\255)~v!9\012\000\342\201\237}}}}\327\257if}\327\257m\000~st9>>>>>>>>>>>?0 Step #5: artifact_prefix='./'; Test unit written to ./oom-77d63332918d8214043ea13778554d33c438dc13 Step #5: Base64: 2K0pfnYhOQoA4oGffX19fdevaWZ9169tAH5zdDk+Pj4+Pj4+Pj4+Pj8w Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3056 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3216479806 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559204be2810, 0x559204dcc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559204dcc020,0x559206c640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/77d63332918d8214043ea13778554d33c438dc13' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3739 processed earlier; will process 7290 files now Step #5: ==110088== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5591fb6d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559201d3c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559201d1f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559201d1f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5591fb6ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5591fb63eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5591fb639355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5591fb6cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5591fe69ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5591fe69ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5591fe69ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5591fe69ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5591fe69ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5591fe69ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5591fe69ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5591fe69ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5591fe69ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5591fe69ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559200933f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5591fd660b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5591fd66bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5591fd417c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5591fd417c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5591fd418738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5591fd417874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5591fd417874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5591fd417874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559201d21abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559201d2a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559201d12699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559201d3d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f308c266082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5591fb637b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x9,0x3d,0xe2,0x81,0xa7,0x54,0x54,0xe2,0x81,0xa7,0x54,0x0,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xe8,0xcb,0xb3,0x0,0x71,0xe,0x27,0xcf,0xe2,0x80,0x3d, Step #5: -\011=\342\201\247TT\342\201\247T\000\350\350\350\350\350\350\350\350\350\350\350\350\350\350\350\350\350\350\350\313\263\000q\016'\317\342\200= Step #5: artifact_prefix='./'; Test unit written to ./oom-8b4d687f72f5e5af8cc6b07cffc4985f5a705ddc Step #5: Base64: LQk94oGnVFTigadUAOjo6Ojo6Ojo6Ojo6Ojo6Ojo6OjLswBxDifP4oA9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3057 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3216963969 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5605c1b5a810, 0x5605c1d4401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5605c1d44020,0x5605c3bdc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8b4d687f72f5e5af8cc6b07cffc4985f5a705ddc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3740 processed earlier; will process 7289 files now Step #5: ==110124== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5605b864f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605becb4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605bec975dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605bec974fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5605b8655d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605b85b6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5605b85b1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5605b8647c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605bb616f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605bb616f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605bb616f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605bb616f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605bb616f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605bb616f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605bb616f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605bb616f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605bb616f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605bb616f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605bd8abf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5605ba5d8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5605ba5e3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5605ba38fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5605ba38fc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5605ba390738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5605ba38f874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5605ba38f874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5605ba38f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605bec99abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5605beca2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605bec8a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605becb5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa25ea6d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5605b85afb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x2a,0x0,0x2f,0x0,0x7e,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x24,0x11,0x3a,0x11,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x24,0x5b,0x2d,0x3a,0x24,0x5b, Step #5: $*\000/\000~\000\000/\000\017\017\017\017\0171\017-1[$\021:\021\017\017\017\017\0171\021\0171\021-:$[-:$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-065de5841267dfd58980e7034423b2572909f5b0 Step #5: Base64: JCoALwB+AAAvAA8PDw8PMQ8tMVskEToRDw8PDw8xEQ8xES06JFstOiRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3058 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3217447835 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563ab2338810, 0x563ab252201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563ab2522020,0x563ab43ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/065de5841267dfd58980e7034423b2572909f5b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3741 processed earlier; will process 7288 files now Step #5: ==110160== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563aa8e2d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563aaf492898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563aaf4755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563aaf4754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563aa8e33d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563aa8d94b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563aa8d8f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563aa8e25c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563aabdf4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563aabdf4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563aabdf4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563aabdf4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563aabdf4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563aabdf4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563aabdf4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563aabdf4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563aabdf4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563aabdf4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563aae089f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563aaadb6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563aaadc1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563aaab6dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563aaab6dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563aaab6e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563aaab6d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563aaab6d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563aaab6d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563aaf477abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563aaf480928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563aaf468699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563aaf493112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e057fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563aa8d8db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x54,0x38,0x39,0x5c,0x52,0x5c,0x53,0x5c,0x52,0x5c,0x31,0x5c,0x65,0x5c,0x18,0x28,0x3f,0x69,0x29,0xf0,0x90,0x8f,0x93,0x2a,0xf0,0x90,0x90,0x8a,0x70,0xce,0xa0,0x53,0x64,0x5c,0xfe,0x1c,0x6d,0xa4,0xdb,0xc,0x5f, Step #5: IT89\\R\\S\\R\\1\\e\\\030(?i)\360\220\217\223*\360\220\220\212p\316\240Sd\\\376\034m\244\333\014_ Step #5: artifact_prefix='./'; Test unit written to ./oom-6fc9939de630cff0b7761e40689f825acb4f4692 Step #5: Base64: SVQ4OVxSXFNcUlwxXGVcGCg/aSnwkI+TKvCQkIpwzqBTZFz+HG2k2wxf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3059 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3217927177 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5634e83c7810, 0x5634e85b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5634e85b1020,0x5634ea4490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6fc9939de630cff0b7761e40689f825acb4f4692' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3742 processed earlier; will process 7287 files now Step #5: ==110196== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5634deebc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5634e5521898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634e55045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634e55044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5634deec2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5634dee23b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5634dee1e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5634deeb4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5634e1e83f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5634e1e83f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5634e1e83f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5634e1e83f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5634e1e83f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5634e1e83f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5634e1e83f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5634e1e83f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5634e1e83f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5634e1e83f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5634e4118f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5634e0e45b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5634e0e50be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5634e0bfcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5634e0bfcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5634e0bfd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5634e0bfc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5634e0bfc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5634e0bfc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5634e5506abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5634e550f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5634e54f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5634e5522112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ab93a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5634dee1cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x74,0x65,0x73,0x74,0x41,0x6c,0x6c,0x54,0x79,0x70,0x65,0x73,0x22,0x3a,0x7b,0x22,0x6f,0x6e,0x65,0x6f,0x66,0x55,0x69,0x6e,0x74,0x33,0x32,0x22,0x3a,0x22,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe2,0x88,0x80,0x22, Step #5: {\"testAllTypes\":{\"oneofUint32\":\"\343\200\200\343\200\200\342\210\200\" Step #5: artifact_prefix='./'; Test unit written to ./oom-6b5bc9fd7a50e847648952ff236d36554f382547 Step #5: Base64: eyJ0ZXN0QWxsVHlwZXMiOnsib25lb2ZVaW50MzIiOiLjgIDjgIDiiIAi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3060 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3218404662 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555feed49810, 0x555feef3301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555feef33020,0x555ff0dcb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b5bc9fd7a50e847648952ff236d36554f382547' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3743 processed earlier; will process 7286 files now Step #5: #1 pulse cov: 3754 ft: 3755 exec/s: 0 rss: 172Mb Step #5: ==110232== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555fe583e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555febea3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555febe865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555febe864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555fe5844d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555fe57a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555fe57a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555fe5836c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555fe8805f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555fe8805f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555fe8805f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555fe8805f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555fe8805f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555fe8805f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555fe8805f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555fe8805f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555fe8805f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555fe8805f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555feaa9af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555fe77c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555fe77d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555fe757ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555fe757ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555fe757f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555fe757e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555fe757e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555fe757e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555febe88abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555febe91928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555febe79699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555febea4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7381c0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555fe579eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0xa,0x32,0xb,0x78,0x2e,0xa,0x32,0xb,0x78,0x2e,0x66,0xa,0x4d,0x60,0x66,0x5b,0x0,0x0,0x5f,0x0,0x0,0x0,0x0,0xa,0x78,0x6e,0x2e,0x6e,0x62,0x60,0x66,0x2e,0x66,0x6e,0x62,0x60,0x66,0xa,0xd,0x60,0x66, Step #5: 2\0122\013x.\0122\013x.f\012M`f[\000\000_\000\000\000\000\012xn.nb`f.fnb`f\012\015`f Step #5: artifact_prefix='./'; Test unit written to ./oom-13b4bfbeff6db8f2e96be63a31b7a6f8c32324dd Step #5: Base64: MgoyC3guCjILeC5mCk1gZlsAAF8AAAAACnhuLm5iYGYuZm5iYGYKDWBm Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3061 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3219048500 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556a94c9f810, 0x556a94e8901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556a94e89020,0x556a96d210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/13b4bfbeff6db8f2e96be63a31b7a6f8c32324dd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3745 processed earlier; will process 7284 files now Step #5: #1 pulse cov: 3489 ft: 3490 exec/s: 0 rss: 174Mb Step #5: ==110268== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556a8b7949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556a91df9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556a91ddc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556a91ddc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556a8b79ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556a8b6fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556a8b6f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556a8b78cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556a8e75bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556a8e75bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556a8e75bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556a8e75bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556a8e75bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556a8e75bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556a8e75bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556a8e75bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556a8e75bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556a8e75bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556a909f0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556a8d71db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556a8d728be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556a8d4d4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556a8d4d4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556a8d4d5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556a8d4d4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556a8d4d4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556a8d4d4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556a91ddeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556a91de7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556a91dcf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556a91dfa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc0e5dd2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556a8b6f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0xf3,0xa0,0xa0,0x80,0x0,0x41,0x50,0x7f,0x5b,0x5b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x80,0xa0,0x80,0xa3,0x5b,0x5b,0xa,0x47,0x0,0x5b,0xf7,0x64,0x4c,0x63,0x6f,0x63,0x6f,0x6e,0x75,0x74,0x5b,0x5b,0x52, Step #5: C\363\240\240\200\000AP\177[[\000\000\000\000\000\000\000\000\200\240\200\243[[\012G\000[\367dLcoconut[[R Step #5: artifact_prefix='./'; Test unit written to ./oom-f6d956d163db4f618dc0c67636451125f74d8f7a Step #5: Base64: Q/OgoIAAQVB/W1sAAAAAAAAAAICggKNbWwpHAFv3ZExjb2NvbnV0W1tS Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3062 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3219561374 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b6329a4810, 0x55b632b8e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b632b8e020,0x55b634a260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f6d956d163db4f618dc0c67636451125f74d8f7a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3747 processed earlier; will process 7282 files now Step #5: ==110304== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b6294999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b62fafe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b62fae15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b62fae14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b62949fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b629400b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6293fb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b629491c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b62c460f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b62c460f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b62c460f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b62c460f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b62c460f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b62c460f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b62c460f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b62c460f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b62c460f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b62c460f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b62e6f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b62b422b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b62b42dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b62b1d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b62b1d9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b62b1da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b62b1d9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b62b1d9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b62b1d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b62fae3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b62faec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b62fad4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b62faff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f502482c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6293f9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xb8,0xb8,0xe0,0xb8,0xb8,0xe0,0xb8,0xb8,0xe0,0xb8,0xb8,0xe0,0xb8,0xb8,0xe0,0xb8,0xb8,0x44,0xe0,0xb8,0xb8,0x49,0xe0,0xb8,0xb8,0xe0,0xb8,0xb8,0xe0,0xb8,0xb8,0xe0,0xb8,0xb8,0x77,0xe0,0xb8,0xb8,0xe0,0xb8,0xb8, Step #5: \340\270\270\340\270\270\340\270\270\340\270\270\340\270\270\340\270\270D\340\270\270I\340\270\270\340\270\270\340\270\270\340\270\270w\340\270\270\340\270\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-4086037c708cf4dcff6f7b07f67f9cb81ece60d8 Step #5: Base64: 4Li44Li44Li44Li44Li44Li4ROC4uEnguLjguLjguLjguLh34Li44Li4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3063 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3220049568 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b9bb6f3810, 0x55b9bb8dd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b9bb8dd020,0x55b9bd7750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4086037c708cf4dcff6f7b07f67f9cb81ece60d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3748 processed earlier; will process 7281 files now Step #5: ==110340== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b9b21e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b9b884d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b9b88305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b9b88304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b9b21eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b9b214fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b9b214a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b9b21e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b9b51aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b9b51aff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b9b51aff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b9b51aff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b9b51aff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b9b51aff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b9b51aff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b9b51aff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b9b51aff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b9b51aff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b9b7444f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b9b4171b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b9b417cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b9b3f28c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b9b3f28c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b9b3f29738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b9b3f28874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b9b3f28874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b9b3f28874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b9b8832abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b9b883b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b9b8823699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b9b884e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f424e28b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b9b2148b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xbd,0xb1,0xe0,0xbf,0xb1,0xe0,0xa2,0xb2,0xe0,0xbc,0xaf,0xe0,0xbb,0x8a,0xe0,0xba,0xa3,0xe0,0xbb,0x80,0xe0,0xba,0xa3,0xf1,0x7c,0x0,0x30,0x95,0x0,0x7e,0x40,0xc3,0x9b,0xbf,0xa3,0xe1,0x63,0x7b,0x84,0x60,0xf9, Step #5: \340\275\261\340\277\261\340\242\262\340\274\257\340\273\212\340\272\243\340\273\200\340\272\243\361|\0000\225\000~@\303\233\277\243\341c{\204`\371 Step #5: artifact_prefix='./'; Test unit written to ./oom-edc851ea3452f58378ae999df86a973f8e9d0fe2 Step #5: Base64: 4L2x4L+x4KKy4Lyv4LuK4Lqj4LuA4Lqj8XwAMJUAfkDDm7+j4WN7hGD5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3064 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3220528772 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55816f0df810, 0x55816f2c901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55816f2c9020,0x5581711610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/edc851ea3452f58378ae999df86a973f8e9d0fe2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3749 processed earlier; will process 7280 files now Step #5: ==110376== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558165bd49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55816c239898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55816c21c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55816c21c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558165bdad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558165b3bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558165b36355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558165bccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558168b9bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558168b9bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558168b9bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558168b9bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558168b9bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558168b9bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558168b9bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558168b9bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558168b9bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558168b9bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55816ae30f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558167b5db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558167b68be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558167914c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558167914c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558167915738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558167914874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558167914874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558167914874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55816c21eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55816c227928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55816c20f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55816c23a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f58f1ce7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558165b34b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0x31,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x0,0x11,0xf,0x31,0x11,0x2d,0x0,0x0,0x0,0x29,0x2f,0x0,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x2d,0x3a,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\0171\0171\021\0171\021-\000\021\0171\021-\000\000\000)/\000\0171\021\0171\021-:-:$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-6b141151ceab130b00db09db5fda608db543890d Step #5: Base64: JAAALwAAAC8ADzEPMREPMREtABEPMREtAAAAKS8ADzERDzERLTotOiRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3065 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3221008968 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565286211810, 0x5652863fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652863fb020,0x5652882930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b141151ceab130b00db09db5fda608db543890d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3750 processed earlier; will process 7279 files now Step #5: ==110412== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56527cd069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56528336b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56528334e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56528334e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56527cd0cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56527cc6db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56527cc68355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56527ccfec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56527fccdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56527fccdf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56527fccdf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56527fccdf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56527fccdf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56527fccdf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56527fccdf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56527fccdf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56527fccdf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56527fccdf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565281f62f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56527ec8fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56527ec9abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56527ea46c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56527ea46c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56527ea47738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56527ea46874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56527ea46874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56527ea46874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565283350abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565283359928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565283341699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56528336c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f280616c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56527cc66b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $22-=<'''/''''/''''''2-='''''''''''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-336d30f1637e67cdba9327e1f010d52b0823c6da Step #5: Base64: JDIyLT08JycnLycnJycvJycnJycnMi09JycnJycnJycnJycnJy4nJCct Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3066 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3221490101 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563c9baa0810, 0x563c9bc8a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563c9bc8a020,0x563c9db220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/336d30f1637e67cdba9327e1f010d52b0823c6da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3751 processed earlier; will process 7278 files now Step #5: ==110448== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563c925959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563c98bfa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563c98bdd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563c98bdd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563c9259bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563c924fcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563c924f7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563c9258dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563c9555cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563c9555cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563c9555cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563c9555cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563c9555cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563c9555cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563c9555cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563c9555cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563c9555cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563c9555cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563c977f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563c9451eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563c94529be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563c942d5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563c942d5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563c942d6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563c942d5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563c942d5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563c942d5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563c98bdfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563c98be8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563c98bd0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563c98bfb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb089fda082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563c924f5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd8,0xad,0x29,0x7e,0x76,0x21,0x39,0xa,0x0,0xe2,0x81,0x9f,0x7d,0x7d,0x7c,0xfd,0xd7,0xaf,0x69,0x66,0x7d,0xd7,0xaf,0x6d,0x0,0x7e,0x73,0x74,0x39,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3f,0x30, Step #5: \330\255)~v!9\012\000\342\201\237}}|\375\327\257if}\327\257m\000~st9>>>>>>>>>>>?0 Step #5: artifact_prefix='./'; Test unit written to ./oom-321d4d556b2e318238ae78f3e0ea645bc0077eb0 Step #5: Base64: 2K0pfnYhOQoA4oGffX18/devaWZ9169tAH5zdDk+Pj4+Pj4+Pj4+Pj8w Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3067 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3221967158 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564de1215810, 0x564de13ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564de13ff020,0x564de32970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/321d4d556b2e318238ae78f3e0ea645bc0077eb0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3752 processed earlier; will process 7277 files now Step #5: ==110484== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x564dd7d0a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564dde36f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564dde3525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564dde3524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564dd7d10d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564dd7c71b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564dd7c6c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564dd7d02c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564ddacd1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564ddacd1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564ddacd1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564ddacd1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564ddacd1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564ddacd1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564ddacd1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564ddacd1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564ddacd1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564ddacd1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564ddcf66f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564dd9c93b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564dd9c9ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564dd9a4ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564dd9a4ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564dd9a4b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564dd9a4a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564dd9a4a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564dd9a4a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564dde354abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564dde35d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564dde345699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564dde370112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a6b29d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564dd7c6ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0x4f,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x2d,0x3a,0x24,0x5b,0x2d,0xf,0xf,0xf,0x31,0x11,0x60,0xf,0x31,0x11,0x2d,0x3a,0x24,0x2a,0x24,0x5b,0x2d,0x3a,0x24,0x60, Step #5: $\000\000/\000\000\000/\000O\017\017\017\0171\021\0171-:$[-\017\017\0171\021`\0171\021-:$*$[-:$` Step #5: artifact_prefix='./'; Test unit written to ./oom-e11bbd9703e3a54380dcf3ec23cf94cb17477b2d Step #5: Base64: JAAALwAAAC8ATw8PDw8xEQ8xLTokWy0PDw8xEWAPMREtOiQqJFstOiRg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3068 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3222568469 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e8f767810, 0x555e8f95101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e8f951020,0x555e917e90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e11bbd9703e3a54380dcf3ec23cf94cb17477b2d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3753 processed earlier; will process 7276 files now Step #5: ==110520== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555e8625c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e8c8c1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e8c8a45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e8c8a44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e86262d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e861c3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e861be355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e86254c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e89223f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e89223f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e89223f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e89223f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e89223f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e89223f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e89223f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e89223f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e89223f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e89223f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e8b4b8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e881e5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e881f0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e87f9cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e87f9cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e87f9d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e87f9c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e87f9c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e87f9c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e8c8a6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e8c8af928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e8c897699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e8c8c2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7519bdd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e861bcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x4e,0xc,0x44,0x45,0x46,0x41,0x55,0x4c,0x54,0x28,0x2d,0x28,0x28,0x28,0x28,0x28,0x28,0x57,0x69,0x74,0x68,0x28,0x28,0x28,0x33,0x33,0x35,0x2c,0x30,0x2c,0x2c,0x2c,0xe2,0x81,0x9f,0x33,0x36,0x36,0x31,0x29,0xa, Step #5: \012N\014DEFAULT(-((((((With(((335,0,,,\342\201\2373661)\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-61023084199bc071c98d04d881959e7ba8cfdd51 Step #5: Base64: Ck4MREVGQVVMVCgtKCgoKCgoV2l0aCgoKDMzNSwwLCws4oGfMzY2MSkK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3069 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3223049246 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e2742f6810, 0x55e2744e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e2744e0020,0x55e2763780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/61023084199bc071c98d04d881959e7ba8cfdd51' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3754 processed earlier; will process 7275 files now Step #5: ==110556== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e26adeb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e271450898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e2714335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e2714334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e26adf1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e26ad52b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e26ad4d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e26ade3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e26ddb2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e26ddb2f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e26ddb2f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e26ddb2f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e26ddb2f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e26ddb2f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e26ddb2f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e26ddb2f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e26ddb2f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e26ddb2f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e270047f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e26cd74b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e26cd7fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e26cb2bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e26cb2bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e26cb2c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e26cb2b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e26cb2b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e26cb2b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e271435abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e27143e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e271426699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e271451112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f552da33082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e26ad4bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x9,0x2b,0xa,0x9,0x9,0x2b,0xa,0x2b,0xa,0x9,0x2b,0xa,0x9,0x9,0x2b,0xa,0x9,0x26,0x76,0x7e,0x7e,0x21,0x7e,0x3,0x70,0x2b,0x7e,0x9,0x26,0x76,0x7e,0x7e,0x21,0x7e,0x3,0x70,0x2b,0x7e,0x8,0x0, Step #5: +\012\011+\012\011\011+\012+\012\011+\012\011\011+\012\011&v~~!~\003p+~\011&v~~!~\003p+~\010\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ccb57efb81a5c31a127ba446340f2887c27d79e2 Step #5: Base64: KwoJKwoJCSsKKwoJKwoJCSsKCSZ2fn4hfgNwK34JJnZ+fiF+A3ArfggA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3070 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3223544934 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b2b704810, 0x558b2b8ee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b2b8ee020,0x558b2d7860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ccb57efb81a5c31a127ba446340f2887c27d79e2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3755 processed earlier; will process 7274 files now Step #5: ==110592== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558b221f99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b2885e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b288415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b288414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b221ffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b22160b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b2215b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b221f1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b251c0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b251c0f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b251c0f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b251c0f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b251c0f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b251c0f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b251c0f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b251c0f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b251c0f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b251c0f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b27455f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b24182b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b2418dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b23f39c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b23f39c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b23f3a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b23f39874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b23f39874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b23f39874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b28843abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b2884c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b28834699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b2885f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f76a1a6f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b22159b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x13,0x3a,0x11,0xa,0xf,0x78,0xe6,0xa3,0x80,0xef,0xa3,0x84,0x2d,0xef,0xa7,0x80,0xe4,0xa2,0x80,0xc,0xa,0x13,0x3a,0x11,0xa,0xf,0x78,0x30,0xe6,0xa3,0x80,0xef,0xa3,0x84,0x2d,0xef,0xa7,0x80,0xe4,0xa2,0x80, Step #5: \012\023:\021\012\017x\346\243\200\357\243\204-\357\247\200\344\242\200\014\012\023:\021\012\017x0\346\243\200\357\243\204-\357\247\200\344\242\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-7bc820f894794fdb8eaf4ab1ea48e2295139bd43 Step #5: Base64: ChM6EQoPeOajgO+jhC3vp4DkooAMChM6EQoPeDDmo4Dvo4Qt76eA5KKA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3071 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3224026327 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bc36bd9810, 0x55bc36dc301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bc36dc3020,0x55bc38c5b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7bc820f894794fdb8eaf4ab1ea48e2295139bd43' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3756 processed earlier; will process 7273 files now Step #5: ==110628== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55bc2d6ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bc33d33898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bc33d165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bc33d164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bc2d6d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bc2d635b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bc2d630355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bc2d6c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bc30695f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bc30695f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bc30695f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bc30695f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bc30695f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bc30695f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bc30695f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bc30695f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bc30695f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bc30695f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bc3292af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bc2f657b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bc2f662be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bc2f40ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bc2f40ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bc2f40f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bc2f40e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bc2f40e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bc2f40e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bc33d18abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bc33d21928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bc33d09699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bc33d34112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7eff87948082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bc2d62eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6,0x1,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x6,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0x4, Step #5: \006\001\004\004\004\004\004\004\004\004\004\004\004\004\006\004\004\004\004\004\004\004\004\004\004\004\004\004\004\004\004\004\004\004\004\004\004\004\004\004\004\004 Step #5: artifact_prefix='./'; Test unit written to ./oom-59af84ebb56a7425d8d57a782e3f7ac6fde39303 Step #5: Base64: BgEEBAQEBAQEBAQEBAQGBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQE Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3072 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3224507685 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0ba169810, 0x55a0ba35301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0ba353020,0x55a0bc1eb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/59af84ebb56a7425d8d57a782e3f7ac6fde39303' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3757 processed earlier; will process 7272 files now Step #5: ==110664== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a0b0c5e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0b72c3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0b72a65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0b72a64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0b0c64d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0b0bc5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0b0bc0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0b0c56c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0b3c25f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0b3c25f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0b3c25f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0b3c25f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0b3c25f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0b3c25f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0b3c25f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0b3c25f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0b3c25f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0b3c25f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0b5ebaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0b2be7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0b2bf2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0b299ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0b299ec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0b299f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0b299e874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0b299e874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0b299e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0b72a8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0b72b1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0b7299699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0b72c4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd0e3db5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0b0bbeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x61,0x73,0x74,0x72,0x65,0x61,0x6d,0x41,0x5c,0x3a,0x23,0x68,0x0,0x43,0x43,0x43,0x43,0x7a,0x0,0x0,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43, Step #5: \000CCCCCCCCastreamA\\:#h\000CCCCz\000\000CCCCCCCCCCCCC Step #5: artifact_prefix='./'; Test unit written to ./oom-56fe2dc8cef45fb327f195208a7944243878a27f Step #5: Base64: AENDQ0NDQ0NDYXN0cmVhbUFcOiNoAENDQ0N6AABDQ0NDQ0NDQ0NDQ0ND Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3073 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3224985835 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5622314e3810, 0x5622316cd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622316cd020,0x5622335650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56fe2dc8cef45fb327f195208a7944243878a27f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3758 processed earlier; will process 7271 files now Step #5: ==110700== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562227fd89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56222e63d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56222e6205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56222e6204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562227fded42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562227f3fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562227f3a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562227fd0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56222af9ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56222af9ff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56222af9ff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56222af9ff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56222af9ff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56222af9ff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56222af9ff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56222af9ff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56222af9ff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56222af9ff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56222d234f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562229f61b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562229f6cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562229d18c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562229d18c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562229d19738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562229d18874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562229d18874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562229d18874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56222e622abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56222e62b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56222e613699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56222e63e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf5ee3a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562227f38b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x40,0x24,0x62,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0xe,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x24,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e, Step #5: @$b.............\016.............$........... Step #5: artifact_prefix='./'; Test unit written to ./oom-d915d5c88acd3aec6ee11cc0139f3af80e5ddeeb Step #5: Base64: QCRiLi4uLi4uLi4uLi4uLg4uLi4uLi4uLi4uLi4uJC4uLi4uLi4uLi4u Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3074 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3225468413 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56052d691810, 0x56052d87b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56052d87b020,0x56052f7130e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d915d5c88acd3aec6ee11cc0139f3af80e5ddeeb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3759 processed earlier; will process 7270 files now Step #5: ==110736== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5605241869c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56052a7eb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56052a7ce5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56052a7ce4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56052418cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605240edb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5605240e8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56052417ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56052714df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56052714df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56052714df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56052714df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56052714df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56052714df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56052714df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56052714df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56052714df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56052714df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605293e2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56052610fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56052611abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560525ec6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560525ec6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560525ec7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560525ec6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560525ec6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560525ec6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56052a7d0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56052a7d9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56052a7c1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56052a7ec112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68fe204082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5605240e6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0x2d,0xd,0x2b,0xd,0x2d,0xd,0x2b,0xd,0x2d,0xd,0x2b,0xd,0x2d,0xd,0x2a,0xd,0x2d,0xd,0x2b,0xd,0x2d,0xd,0x2b,0xd,0x2d,0xd,0x2a,0xd,0x2d,0xd,0x2b,0xd,0x2d,0xd,0x2b,0xd,0x2d,0xd,0x2b,0xd,0x2d, Step #5: \015-\015+\015-\015+\015-\015+\015-\015*\015-\015+\015-\015+\015-\015*\015-\015+\015-\015+\015-\015+\015- Step #5: artifact_prefix='./'; Test unit written to ./oom-bb31b71373acb20c789f4c753027f8920b7296c9 Step #5: Base64: DS0NKw0tDSsNLQ0rDS0NKg0tDSsNLQ0rDS0NKg0tDSsNLQ0rDS0NKw0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3075 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3225972680 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a5d8e66810, 0x55a5d905001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a5d9050020,0x55a5daee80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bb31b71373acb20c789f4c753027f8920b7296c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3760 processed earlier; will process 7269 files now Step #5: ==110772== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a5cf95b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a5d5fc0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a5d5fa35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a5d5fa34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a5cf961d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a5cf8c2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a5cf8bd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a5cf953c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a5d2922f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a5d2922f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a5d2922f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a5d2922f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a5d2922f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a5d2922f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a5d2922f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a5d2922f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a5d2922f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a5d2922f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a5d4bb7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a5d18e4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a5d18efbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a5d169bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a5d169bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a5d169c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a5d169b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a5d169b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a5d169b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a5d5fa5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a5d5fae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a5d5f96699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a5d5fc1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fea6c12d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a5cf8bbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x6e,0x75,0x6d,0x20,0x45,0x60,0x69,0x6d,0x70,0x6c,0x65,0x6d,0x65,0x6e,0x74,0x73,0x20,0x49,0x7b,0x7d,0x65,0x6e,0x75,0x6d,0x20,0x45,0x60,0x69,0x6d,0x70,0x6c,0x65,0x6d,0x65,0x6e,0x74,0x73,0x20,0x49,0x7b,0x7d, Step #5: enum E`implements I{}enum E`implements I{} Step #5: artifact_prefix='./'; Test unit written to ./oom-bffdbe22979c2f91826be81ff5296ff46d591544 Step #5: Base64: ZW51bSBFYGltcGxlbWVudHMgSXt9ZW51bSBFYGltcGxlbWVudHMgSXt9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3076 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3226579869 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ffdf5c1810, 0x55ffdf7ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ffdf7ab020,0x55ffe16430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bffdbe22979c2f91826be81ff5296ff46d591544' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3761 processed earlier; will process 7268 files now Step #5: ==110808== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ffd60b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ffdc71b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ffdc6fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ffdc6fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ffd60bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ffd601db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ffd6018355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ffd60aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ffd907df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ffd907df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ffd907df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ffd907df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ffd907df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ffd907df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ffd907df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ffd907df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ffd907df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ffd907df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ffdb312f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ffd803fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ffd804abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ffd7df6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ffd7df6c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ffd7df7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ffd7df6874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ffd7df6874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ffd7df6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ffdc700abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ffdc709928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ffdc6f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ffdc71c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4e13b90082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ffd6016b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x4,0x33,0x3,0x0,0x0,0x45,0x30,0x50,0x55,0x53,0x4c,0x54,0x0,0x0,0x20,0xb,0x0,0x0,0x71,0x70,0x78,0x60,0x74,0x6d,0x21,0x60,0x32,0x50,0x55,0x53,0x4c,0x32,0x50,0x55,0x53,0x4c,0x32,0x54,0x0,0xc7,0x50, Step #5: I\0043\003\000\000E0PUSLT\000\000 \013\000\000qpx`tm!`2PUSL2PUSL2T\000\307P Step #5: artifact_prefix='./'; Test unit written to ./oom-0d25c668a4c98d08f94273b7fbd24d8e7d9c6ebf Step #5: Base64: SQQzAwAARTBQVVNMVAAAIAsAAHFweGB0bSFgMlBVU0wyUFVTTDJUAMdQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3077 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3227180362 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e50324d810, 0x55e50343701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e503437020,0x55e5052cf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0d25c668a4c98d08f94273b7fbd24d8e7d9c6ebf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3762 processed earlier; will process 7267 files now Step #5: ==110844== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e4f9d429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e5003a7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e50038a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e50038a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4f9d48d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4f9ca9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4f9ca4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4f9d3ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4fcd09f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4fcd09f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4fcd09f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4fcd09f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4fcd09f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4fcd09f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4fcd09f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4fcd09f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4fcd09f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4fcd09f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4fef9ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4fbccbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4fbcd6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4fba82c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4fba82c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4fba83738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4fba82874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4fba82874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4fba82874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e50038cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e500395928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e50037d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e5003a8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f906316a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4f9ca2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x7d, Step #5: \"\\u{b}\\u{b}\\u{b}\\u{b}\\u{b}\\u{b}\\u{b}\\u{b}} Step #5: artifact_prefix='./'; Test unit written to ./oom-65cc88cf85569e2936d619ff77c771d6861fc9f6 Step #5: Base64: Ilx1e2J9XHV7Yn1cdXtifVx1e2J9XHV7Yn1cdXtifVx1e2J9XHV7Yn19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3078 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3227657787 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f4c2ab4810, 0x55f4c2c9e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f4c2c9e020,0x55f4c4b360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/65cc88cf85569e2936d619ff77c771d6861fc9f6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3763 processed earlier; will process 7266 files now Step #5: ==110880== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f4b95a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f4bfc0e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f4bfbf15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f4bfbf14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f4b95afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f4b9510b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f4b950b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f4b95a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f4bc570f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f4bc570f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f4bc570f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f4bc570f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f4bc570f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f4bc570f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f4bc570f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f4bc570f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f4bc570f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f4bc570f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4be805f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4bb532b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4bb53dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f4bb2e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f4bb2e9c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f4bb2ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f4bb2e9874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f4bb2e9874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f4bb2e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f4bfbf3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f4bfbfc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f4bfbe4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f4bfc0f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1287fa0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f4b9509b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1a,0x1a,0x65,0x60,0xdb,0xa4,0x64,0x65,0x60,0xdb,0xa4,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x60,0x42,0x65,0x60,0xdb,0xa4,0x47,0x49,0x4e,0xb9,0x0,0x2d,0x0,0x60,0x65,0x60,0xdb,0xa4,0x60,0x2d,0xfc,0x42,0xfc, Step #5: \032\032e`\333\244de`\333\244\000-----BE`Be`\333\244GIN\271\000-\000`e`\333\244`-\374B\374 Step #5: artifact_prefix='./'; Test unit written to ./oom-602082af1827b309674f9c3a4a1643d17181f47e Step #5: Base64: GhplYNukZGVg26QALS0tLS1CRWBCZWDbpEdJTrkALQBgZWDbpGAt/EL8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3079 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3228255604 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560ecfb77810, 0x560ecfd6101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560ecfd61020,0x560ed1bf90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/602082af1827b309674f9c3a4a1643d17181f47e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3764 processed earlier; will process 7265 files now Step #5: ==110916== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560ec666c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560ecccd1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560ecccb45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560ecccb44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560ec6672d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560ec65d3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560ec65ce355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560ec6664c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560ec9633f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560ec9633f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560ec9633f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560ec9633f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560ec9633f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560ec9633f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560ec9633f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560ec9633f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560ec9633f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560ec9633f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560ecb8c8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560ec85f5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560ec8600be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560ec83acc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560ec83acc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560ec83ad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560ec83ac874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560ec83ac874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560ec83ac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560ecccb6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560ecccbf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560eccca7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560ecccd2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc7991d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560ec65ccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x9,0x3f,0xb,0x61,0xa,0x41,0x55,0x74,0x68,0x6f,0x72,0x69,0x7a,0x61,0x74,0x69,0x4f,0x6e,0x3a,0x4f,0x41,0x75,0x74,0x68,0x20,0x6f,0x61,0x55,0x74,0x68,0x5f,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x3d,0x31,0xca,0xbb, Step #5: o\011?\013a\012AUthorizatiOn:OAuth oaUth_version=1\312\273 Step #5: artifact_prefix='./'; Test unit written to ./oom-bf7ec9ee1dfab445eb20fa27b2e5604849a1facc Step #5: Base64: bwk/C2EKQVV0aG9yaXphdGlPbjpPQXV0aCBvYVV0aF92ZXJzaW9uPTHKuw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3080 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3228734696 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a155638810, 0x55a15582201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a155822020,0x55a1576ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf7ec9ee1dfab445eb20fa27b2e5604849a1facc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3765 processed earlier; will process 7264 files now Step #5: ==110952== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55a14c12d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a152792898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1527755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1527754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a14c133d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a14c094b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a14c08f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a14c125c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a14f0f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a14f0f4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a14f0f4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a14f0f4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a14f0f4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a14f0f4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a14f0f4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a14f0f4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a14f0f4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a14f0f4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a151389f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a14e0b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a14e0c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a14de6dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a14de6dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a14de6e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a14de6d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a14de6d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a14de6d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a152777abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a152780928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a152768699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a152793112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efd97889082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a14c08db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7b,0x38,0x7d,0x24,0x7f,0x32,0x7d,0x24,0x7b,0x28,0x7d,0x24,0x7b,0x31,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7f,0x32,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x3b,0x7b,0x38,0x7d, Step #5: ${8}$\1772}${(}${1}${8}$\1772}${8}$8}${8}${8};{8} Step #5: artifact_prefix='./'; Test unit written to ./oom-8a23e20cee18c5e8e71ae7b99389926497bf8ebe Step #5: Base64: JHs4fSR/Mn0keyh9JHsxfSR7OH0kfzJ9JHs4fSQ4fSR7OH0kezh9O3s4fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3081 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3229214932 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5620a4321810, 0x5620a450b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5620a450b020,0x5620a63a30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8a23e20cee18c5e8e71ae7b99389926497bf8ebe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3766 processed earlier; will process 7263 files now Step #5: #1 pulse cov: 3728 ft: 3729 exec/s: 0 rss: 171Mb Step #5: ==110989== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56209ae169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5620a147b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5620a145e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5620a145e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56209ae1cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56209ad7db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56209ad78355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56209ae0ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56209ddddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56209ddddf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56209ddddf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56209ddddf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56209ddddf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56209ddddf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56209ddddf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56209ddddf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56209ddddf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56209ddddf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5620a0072f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56209cd9fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56209cdaabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56209cb56c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56209cb56c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56209cb57738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56209cb56874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56209cb56874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56209cb56874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5620a1460abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5620a1469928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5620a1451699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5620a147c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc972316082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56209ad76b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x0,0x0,0x0,0x67,0x0,0x0,0x0,0x7a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2f,0xa,0x60,0x60,0x20,0x20,0x20,0x60,0xa,0x9, Step #5: `\000\000\000g\000\000\000z\000\000\000\000\000\000\000$\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000/\012`` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-cafbaa44c12636b89337319f1e56e1307ca30d38 Step #5: Base64: YAAAAGcAAAB6AAAAAAAAACQAAAAAAAAAAAAAAAAAAAAALwpgYCAgIGAKCQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3082 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3229867397 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1ebb70810, 0x55d1ebd5a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1ebd5a020,0x55d1edbf20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cafbaa44c12636b89337319f1e56e1307ca30d38' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3768 processed earlier; will process 7261 files now Step #5: #1 pulse cov: 4153 ft: 4154 exec/s: 0 rss: 173Mb Step #5: ==111028== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55d1e26659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1e8cca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1e8cad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1e8cad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1e266bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1e25ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1e25c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1e265dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1e562cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1e562cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1e562cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1e562cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1e562cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1e562cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1e562cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1e562cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1e562cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1e562cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1e78c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1e45eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1e45f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1e43a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1e43a5c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1e43a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1e43a5874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1e43a5874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1e43a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1e8cafabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1e8cb8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1e8ca0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1e8ccb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fad635ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1e25c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x31,0x32,0x38,0x12,0x3d,0x3c,0x27,0x27,0x32,0x36,0x2f,0x30,0x27,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0x32,0x39,0x36,0xe2,0x81,0xa5,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x36,0x27,0x24,0x27,0x2d, Step #5: $128\022=<''26/0'4294967296\342\201\245-='''''''''6'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-612276203c45c41925fe31dd2874bc91aff8c0fd Step #5: Base64: JDEyOBI9PCcnMjYvMCc0Mjk0OTY3Mjk24oGlLT0nJycnJycnJyc2JyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3083 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3230396850 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5590940eb810, 0x5590942d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5590942d5020,0x55909616d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/612276203c45c41925fe31dd2874bc91aff8c0fd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3770 processed earlier; will process 7259 files now Step #5: ==111064== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55908abe09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559091245898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5590912285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5590912284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55908abe6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55908ab47b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55908ab42355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55908abd8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55908dba7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55908dba7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55908dba7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55908dba7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55908dba7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55908dba7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55908dba7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55908dba7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55908dba7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55908dba7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55908fe3cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55908cb69b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55908cb74be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55908c920c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55908c920c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55908c921738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55908c920874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55908c920874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55908c920874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55909122aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559091233928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55909121b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559091246112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9e6a185082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55908ab40b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xb2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x84,0xbd,0xcc,0xa2, Step #5: ws:\354\214\275\314\242\354\214\275\314\242\354\214\275\314\242\354\214\275\314\262\354\214\275\314\242\354\214\275\314\242\354\214\275\314\242\354\204\275\314\242 Step #5: artifact_prefix='./'; Test unit written to ./oom-497bb044a1ba13db344938ef16a5d1bb97899c80 Step #5: Base64: d3M67Iy9zKLsjL3MouyMvcyi7Iy9zLLsjL3MouyMvcyi7Iy9zKLshL3Mog== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3084 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3230878231 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ecf558c810, 0x55ecf577601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ecf5776020,0x55ecf760e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/497bb044a1ba13db344938ef16a5d1bb97899c80' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3771 processed earlier; will process 7258 files now Step #5: ==111100== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ecec0819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ecf26e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ecf26c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ecf26c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ecec087d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ecebfe8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ecebfe3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ecec079c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ecef048f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ecef048f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ecef048f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ecef048f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ecef048f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ecef048f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ecef048f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ecef048f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ecef048f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ecef048f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ecf12ddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ecee00ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ecee015be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eceddc1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eceddc1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eceddc2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eceddc1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eceddc1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eceddc1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ecf26cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ecf26d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ecf26bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ecf26e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac413fb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ecebfe1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0xa,0x74,0xa,0x74,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x29,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x50,0xa,0x2d,0xa,0x2d, Step #5: 0\012t\012t\012-\012-\012-\012-\012-\012-\012-\012-\012)\012-\012-\012-\012-\012-\012-\012-\012P\012-\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-c12781911b434730dba7328fc4096889194491cb Step #5: Base64: MAp0CnQKLQotCi0KLQotCi0KLQotCikKLQotCi0KLQotCi0KLQpQCi0KLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3085 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3231378942 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f4dba0e810, 0x55f4dbbf801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f4dbbf8020,0x55f4dda900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c12781911b434730dba7328fc4096889194491cb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3772 processed earlier; will process 7257 files now Step #5: ==111136== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f4d25039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f4d8b68898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f4d8b4b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f4d8b4b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f4d2509d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f4d246ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f4d2465355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f4d24fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f4d54caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f4d54caf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f4d54caf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f4d54caf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f4d54caf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f4d54caf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f4d54caf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f4d54caf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f4d54caf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f4d54caf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4d775ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4d448cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4d4497be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f4d4243c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f4d4243c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f4d4244738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f4d4243874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f4d4243874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f4d4243874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f4d8b4dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f4d8b56928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f4d8b3e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f4d8b69112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f58d55d6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f4d2463b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x80,0x82,0x69,0xd7,0xbf,0xd1,0xb6,0xd7,0xbd,0xd3,0xb6,0xd7,0xaf,0xdf,0xbf,0xd7,0xbf,0xd7,0xbf,0xd1,0xb6,0xd7,0xbd,0xd7,0xaf,0xdf,0xbf,0x0,0x0,0x0,0x30,0x77,0x69,0x34,0x30,0x36,0x31,0x37,0x9,0x6b,0x6c, Step #5: \363\240\200\202i\327\277\321\266\327\275\323\266\327\257\337\277\327\277\327\277\321\266\327\275\327\257\337\277\000\000\0000wi40617\011kl Step #5: artifact_prefix='./'; Test unit written to ./oom-c20aea19ceb6e5eb43ff3857999009c94c71f0ab Step #5: Base64: 86CAgmnXv9G2173Tttev37/Xv9e/0bbXvdev378AAAAwd2k0MDYxNwlrbA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3086 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3231857134 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562157ef8810, 0x5621580e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5621580e2020,0x562159f7a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c20aea19ceb6e5eb43ff3857999009c94c71f0ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3773 processed earlier; will process 7256 files now Step #5: ==111172== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56214e9ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562155052898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5621550355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5621550354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56214e9f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56214e954b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56214e94f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56214e9e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5621519b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5621519b4f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5621519b4f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5621519b4f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5621519b4f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5621519b4f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5621519b4f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5621519b4f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5621519b4f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5621519b4f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562153c49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562150976b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562150981be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56215072dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56215072dc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56215072e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56215072d874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56215072d874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56215072d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562155037abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562155040928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562155028699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562155053112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f012f608082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56214e94db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c,0x65,0x74,0x20,0x6d,0x4c,0x3d,0x20,0x23,0x7b,0x7d,0x3b,0xa,0x6c,0x65,0x74,0x20,0x6c,0x4c,0x3d,0x20,0x23,0x7b,0x7d,0x3b,0xa,0x6c,0x65,0x74,0x20,0x6c,0x4c,0x3d,0x20,0x23,0x7b,0x7d,0x3b,0xa,0x6c,0x65,0x3b,0x7b, Step #5: let mL= #{};\012let lL= #{};\012let lL= #{};\012le;{ Step #5: artifact_prefix='./'; Test unit written to ./oom-08f221f87b5bf76363e1a42b09aca67c975a30bc Step #5: Base64: bGV0IG1MPSAje307CmxldCBsTD0gI3t9OwpsZXQgbEw9ICN7fTsKbGU7ew== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3087 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3232335109 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56084f446810, 0x56084f63001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56084f630020,0x5608514c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08f221f87b5bf76363e1a42b09aca67c975a30bc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3774 processed earlier; will process 7255 files now Step #5: ==111208== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560845f3b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56084c5a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56084c5835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56084c5834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560845f41d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560845ea2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560845e9d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560845f33c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560848f02f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560848f02f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560848f02f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560848f02f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560848f02f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560848f02f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560848f02f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560848f02f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560848f02f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560848f02f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56084b197f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560847ec4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560847ecfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560847c7bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560847c7bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560847c7c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560847c7b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560847c7b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560847c7b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56084c585abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56084c58e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56084c576699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56084c5a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7dd074f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560845e9bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x29,0x44,0x33,0x2,0x23,0x33,0x38,0x33,0x1,0x1,0x54,0x58,0x58,0x0,0x0,0x1,0x33,0x43,0x48,0x41,0x0,0x0,0x12,0x49,0x29,0x44,0x33,0x2,0x23,0x33,0x38,0x33,0x1,0x1,0x54,0x58,0x58,0x0,0x0,0x1,0x33,0x43, Step #5: I)D3\002#383\001\001TXX\000\000\0013CHA\000\000\022I)D3\002#383\001\001TXX\000\000\0013C Step #5: artifact_prefix='./'; Test unit written to ./oom-515846fc449c994378eafdd1f279c9a8289fb879 Step #5: Base64: SSlEMwIjMzgzAQFUWFgAAAEzQ0hBAAASSSlEMwIjMzgzAQFUWFgAAAEzQw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3088 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3232811313 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb384f5810, 0x55cb386df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb386df020,0x55cb3a5770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/515846fc449c994378eafdd1f279c9a8289fb879' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3775 processed earlier; will process 7254 files now Step #5: ==111244== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cb2efea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb3564f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb356325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb356324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb2eff0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb2ef51b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb2ef4c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb2efe2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb31fb1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb31fb1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb31fb1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb31fb1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb31fb1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb31fb1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb31fb1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb31fb1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb31fb1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb31fb1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb34246f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb30f73b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb30f7ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb30d2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb30d2ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb30d2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb30d2a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb30d2a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb30d2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb35634abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb3563d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb35625699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb35650112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffad9ce4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb2ef4ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x45,0x78,0x65,0x63,0x5d,0xa,0x55,0x73,0x65,0x72,0x3d,0xe2,0x81,0xa8,0x73,0x25,0x72,0x3d,0xe2,0x81,0xa8,0x5b,0x45,0x0,0x55,0x73,0x65,0x72,0x3d,0xe2,0x81,0xa8,0x73,0x25,0x72,0x3d,0xe2,0x81,0xa8,0x5b,0x65,0x30, Step #5: [Exec]\012User=\342\201\250s%r=\342\201\250[E\000User=\342\201\250s%r=\342\201\250[e0 Step #5: artifact_prefix='./'; Test unit written to ./oom-4a769e9e4a93e996535ec97902b6a22e9a95cac6 Step #5: Base64: W0V4ZWNdClVzZXI94oGocyVyPeKBqFtFAFVzZXI94oGocyVyPeKBqFtlMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3089 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3233293190 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560f1ab25810, 0x560f1ad0f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560f1ad0f020,0x560f1cba70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4a769e9e4a93e996535ec97902b6a22e9a95cac6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3776 processed earlier; will process 7253 files now Step #5: ==111280== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x560f1161a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560f17c7f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560f17c625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560f17c624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560f11620d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560f11581b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560f1157c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560f11612c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560f145e1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560f145e1f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560f145e1f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560f145e1f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560f145e1f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560f145e1f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560f145e1f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560f145e1f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560f145e1f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560f145e1f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560f16876f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560f135a3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560f135aebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560f1335ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560f1335ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560f1335b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560f1335a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560f1335a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560f1335a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560f17c64abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560f17c6d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560f17c55699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560f17c80112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbc8e280082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560f1157ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xde,0xa6,0x3d,0xa,0x1,0x0,0x0,0x0,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x28,0x3f,0x69,0x3a,0xf0,0x9e,0xa,0x2a,0xa3,0x0,0x87,0x0,0x0,0x0, Step #5: \336\246=\012\001\000\000\000==\012=\012=\012=\012=\012=\012=\012\012=\012==\012(?i:\360\236\012*\243\000\207\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c527a7a15c34e67fb25f63086ad627edccaef3e4 Step #5: Base64: 3qY9CgEAAAA9PQo9Cj0KPQo9Cj0KPQoKPQo9PQooP2k68J4KKqMAhwAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3090 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3233775115 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558efe817810, 0x558efea0101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558efea01020,0x558f008990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c527a7a15c34e67fb25f63086ad627edccaef3e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3777 processed earlier; will process 7252 files now Step #5: ==111316== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x558ef530c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558efb971898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558efb9545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558efb9544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558ef5312d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558ef5273b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558ef526e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558ef5304c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558ef82d3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558ef82d3f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558ef82d3f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558ef82d3f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558ef82d3f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558ef82d3f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558ef82d3f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558ef82d3f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558ef82d3f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558ef82d3f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558efa568f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ef7295b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ef72a0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ef704cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ef704cc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ef704d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ef704c874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ef704c874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ef704c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558efb956abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558efb95f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558efb947699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558efb972112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f40cbf4b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558ef526cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x0,0x0,0x0,0x0,0x0,0x6c,0x7c,0x7c,0x0,0x3,0x3,0x3,0x3,0x0,0x0,0x33,0x0,0x0,0x0,0x0,0x6c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xd6,0xae,0x0,0x0,0x0,0x27,0xd6,0xae,0xd5,0x0,0x0, Step #5: M\000\000\000\000\000l||\000\003\003\003\003\000\0003\000\000\000\000l\000\000\000\000\000\000\000\000\000\000\326\256\000\000\000'\326\256\325\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b5c0a6831de1e6da3c4f4c28e339b7a794208720 Step #5: Base64: TQAAAAAAbHx8AAMDAwMAADMAAAAAbAAAAAAAAAAAAADWrgAAACfWrtUAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3091 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3234252935 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca48223810, 0x55ca4840d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca4840d020,0x55ca4a2a50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b5c0a6831de1e6da3c4f4c28e339b7a794208720' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3778 processed earlier; will process 7251 files now Step #5: ==111352== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ca3ed189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca4537d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca453605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca453604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca3ed1ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca3ec7fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca3ec7a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca3ed10c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca41cdff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca41cdff10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca41cdff10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca41cdff10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca41cdff10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca41cdff10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca41cdff10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca41cdff10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca41cdff10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca41cdff10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca43f74f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca40ca1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca40cacbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca40a58c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca40a58c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca40a59738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca40a58874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca40a58874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca40a58874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca45362abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca4536b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca45353699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca4537e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7ed4723082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca3ec78b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0xa,0x22,0x5f,0x7,0x22,0x72,0x69,0x66,0x3d,0x42,0x42,0xa,0x7d,0x20,0x20,0xa,0x3d,0x20,0x20,0x2e,0x1d,0x20,0x2e,0x2d,0x13,0x1d,0x60,0x1,0x22,0x2,0xa,0x2,0x0,0x6,0x60,0x20,0x0,0x65,0x20,0x60,0xa,0x60, Step #5: _\012\"_\007\"rif=BB\012} \012= .\035 .-\023\035`\001\"\002\012\002\000\006` \000e `\012` Step #5: artifact_prefix='./'; Test unit written to ./oom-b3018d3cfa0bed7758a78d7582ceabff9665748f Step #5: Base64: XwoiXwcicmlmPUJCCn0gIAo9ICAuHSAuLRMdYAEiAgoCAAZgIABlIGAKYA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3092 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3234854428 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56516b3c7810, 0x56516b5b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56516b5b1020,0x56516d4490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3018d3cfa0bed7758a78d7582ceabff9665748f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3779 processed earlier; will process 7250 files now Step #5: ==111388== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x565161ebc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565168521898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651685045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651685044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565161ec2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565161e23b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565161e1e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565161eb4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565164e83f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565164e83f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565164e83f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565164e83f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565164e83f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565164e83f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565164e83f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565164e83f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565164e83f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565164e83f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565167118f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565163e45b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565163e50be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565163bfcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565163bfcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565163bfd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565163bfc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565163bfc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565163bfc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565168506abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56516850f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5651684f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565168522112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe3598e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565161e1cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x7f,0x7f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6c,0x6f,0x63,0x61,0x6c,0x5f,0x73,0x69,0x7a,0x79,0x3d,0x34,0x32,0x39,0x34,0x39,0x35,0x33,0x36,0x39,0x36,0x39,0x36,0x29,0x3b, Step #5: = \177\177\000\000\000\000\000\000\000\000\000\000\000\000\000\000local_sizy=429495369696); Step #5: artifact_prefix='./'; Test unit written to ./oom-460ba4fec97836114a06a09e1b438df0ba7eeba2 Step #5: Base64: PSB/fwAAAAAAAAAAAAAAAAAAbG9jYWxfc2l6eT00Mjk0OTUzNjk2OTYpOw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3093 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3235336161 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5574fb67b810, 0x5574fb86501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5574fb865020,0x5574fd6fd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/460ba4fec97836114a06a09e1b438df0ba7eeba2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3780 processed earlier; will process 7249 files now Step #5: ==111424== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5574f21709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5574f87d5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5574f87b85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5574f87b84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5574f2176d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5574f20d7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5574f20d2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5574f2168c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5574f5137f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5574f5137f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5574f5137f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5574f5137f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5574f5137f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5574f5137f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5574f5137f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5574f5137f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5574f5137f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5574f5137f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5574f73ccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5574f40f9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5574f4104be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5574f3eb0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5574f3eb0c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5574f3eb1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5574f3eb0874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5574f3eb0874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5574f3eb0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5574f87baabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5574f87c3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5574f87ab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5574f87d6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa14c7e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5574f20d0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x7f,0x7f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x28,0x0,0x72,0x0,0x64,0x0,0x20,0x0,0x72,0x64,0x64,0xb7,0x64,0x64, Step #5: = \177\177\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000(\000r\000d\000 \000rdd\267dd Step #5: artifact_prefix='./'; Test unit written to ./oom-b9af0d18515166ba16df93508315daaf2c0bc695 Step #5: Base64: PSB/fwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAoAHIAZAAgAHJkZLdkZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3094 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3235814362 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b882c89810, 0x55b882e7301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b882e73020,0x55b884d0b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b9af0d18515166ba16df93508315daaf2c0bc695' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3781 processed earlier; will process 7248 files now Step #5: ==111460== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b87977e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b87fde3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b87fdc65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b87fdc64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b879784d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b8796e5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b8796e0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b879776c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b87c745f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b87c745f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b87c745f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b87c745f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b87c745f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b87c745f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b87c745f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b87c745f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b87c745f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b87c745f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b87e9daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b87b707b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b87b712be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b87b4bec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b87b4bec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b87b4bf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b87b4be874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b87b4be874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b87b4be874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b87fdc8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b87fdd1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b87fdb9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b87fde4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f162b84e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b8796deb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4c,0x59,0x31,0x32,0x5c,0x6a,0x5c,0x52,0x5c,0x31,0xcc,0xa3,0xc4,0xa3,0x65,0x5c,0x40,0x28,0x3f,0x78,0x29,0xdb,0xad,0xdb,0xad,0xc4,0xa3,0xc4,0x80,0x0,0xbb,0x0,0x6a,0x5c,0xa8,0x5c,0x52,0x5c,0x65,0xff,0x3b,0x5c,0x65, Step #5: LY12\\j\\R\\1\314\243\304\243e\\@(?x)\333\255\333\255\304\243\304\200\000\273\000j\\\250\\R\\e\377;\\e Step #5: artifact_prefix='./'; Test unit written to ./oom-b21ab2d3bc370a4da7757832799eab9198f00630 Step #5: Base64: TFkxMlxqXFJcMcyjxKNlXEAoP3gp263brcSjxIAAuwBqXKhcUlxl/ztcZQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3095 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3236293824 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc52cd4810, 0x55cc52ebe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc52ebe020,0x55cc54d560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b21ab2d3bc370a4da7757832799eab9198f00630' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3782 processed earlier; will process 7247 files now Step #5: ==111496== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cc497c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc4fe2e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc4fe115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc4fe114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc497cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc49730b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc4972b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc497c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc4c790f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc4c790f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc4c790f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc4c790f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc4c790f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc4c790f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc4c790f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc4c790f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc4c790f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc4c790f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc4ea25f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc4b752b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc4b75dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc4b509c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc4b509c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc4b50a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc4b509874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc4b509874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc4b509874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc4fe13abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc4fe1c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc4fe04699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc4fe2f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe2a21e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc49729b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0x90,0xd9,0x91,0x20,0xe2,0x86,0x8d,0x31,0xe1,0x82,0x8d,0xef,0xb8,0x8f,0x3b,0xd9,0x90,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: \331\220\331\221 \342\206\2151\341\202\215\357\270\217;\331\220' Step #5: artifact_prefix='./'; Test unit written to ./oom-40008abfce0405a8af8b94d6b7805d9c6117f033 Step #5: Base64: PHN2Zz48dGV4dD7ZkNmRIOKGjTHhgo3vuI872ZAnPC90ZXh0Pjwvc3ZnPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3096 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3236770358 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563760f5b810, 0x56376114501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563761145020,0x563762fdd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40008abfce0405a8af8b94d6b7805d9c6117f033' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3783 processed earlier; will process 7246 files now Step #5: ==111532== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x563757a509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56375e0b5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56375e0985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56375e0984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563757a56d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5637579b7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5637579b2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563757a48c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56375aa17f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56375aa17f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56375aa17f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56375aa17f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56375aa17f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56375aa17f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56375aa17f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56375aa17f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56375aa17f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56375aa17f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56375ccacf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5637599d9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5637599e4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563759790c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563759790c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563759791738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563759790874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563759790874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563759790874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56375e09aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56375e0a3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56375e08b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56375e0b6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd41de3e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5637579b0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x1,0x0,0x0,0x11,0x0,0x0,0x2f,0x39,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xf,0x31,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x0,0x0,0x0,0x2f,0x0,0xf,0x30,0x11,0xf,0x31,0x11,0x2d,0x3a,0x2d,0x3a,0x24,0x5b, Step #5: $\001\000\000\021\000\000/9\000\000\000\000\000\000\000\000\0171\0171\021\0171\021-\000\000\000/\000\0170\021\0171\021-:-:$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-40a176390dfb5694b471fe4e87b5a6932626b2ce Step #5: Base64: JAEAABEAAC85AAAAAAAAAAAPMQ8xEQ8xES0AAAAvAA8wEQ8xES06LTokWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3097 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3237249999 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c79d40b810, 0x55c79d5f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c79d5f5020,0x55c79f48d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40a176390dfb5694b471fe4e87b5a6932626b2ce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3784 processed earlier; will process 7245 files now Step #5: ==111568== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c793f009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c79a565898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c79a5485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c79a5484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c793f06d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c793e67b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c793e62355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c793ef8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c796ec7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c796ec7f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c796ec7f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c796ec7f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c796ec7f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c796ec7f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c796ec7f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c796ec7f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c796ec7f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c796ec7f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c79915cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c795e89b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c795e94be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c795c40c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c795c40c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c795c41738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c795c40874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c795c40874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c795c40874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c79a54aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c79a553928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c79a53b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c79a566112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5edef01082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c793e60b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x29,0x4,0x43,0x20,0x0,0x24,0x31, Step #5: $\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000)\004C \000$1 Step #5: artifact_prefix='./'; Test unit written to ./oom-a0b5af8e4d91766cf2b3f4f8a4d6e59f506f87a5 Step #5: Base64: JAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAKQRDIAAkMQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3098 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3237734780 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c99dbd6810, 0x55c99ddc001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c99ddc0020,0x55c99fc580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a0b5af8e4d91766cf2b3f4f8a4d6e59f506f87a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3785 processed earlier; will process 7244 files now Step #5: #1 pulse cov: 3714 ft: 3715 exec/s: 0 rss: 171Mb Step #5: ==111604== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c9946cb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c99ad30898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c99ad135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c99ad134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9946d1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c994632b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c99462d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9946c3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c997692f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c997692f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c997692f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c997692f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c997692f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c997692f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c997692f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c997692f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c997692f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c997692f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c999927f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c996654b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c99665fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c99640bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c99640bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c99640c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c99640b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c99640b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c99640b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c99ad15abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c99ad1e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c99ad06699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c99ad31112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc45a56082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c99462bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x6c,0x31,0x46,0x50,0x3c,0x1d,0x54,0x11,0x11,0x11,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x44,0x33,0x2,0x0,0x0,0x0,0x0, Step #5: ID3\002l1FP<\035T\021\021\021\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033D3\002\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8e25751351fd74057cc47ac7ab93929d5254d13 Step #5: Base64: SUQzAmwxRlA8HVQREREbGxsbGxsbGxsbGxsbGxsbGxsbGxsbRDMCAAAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3099 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3238262802 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d60c7a810, 0x557d60e6401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d60e64020,0x557d62cfc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8e25751351fd74057cc47ac7ab93929d5254d13' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3787 processed earlier; will process 7242 files now Step #5: ==111640== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x557d5776f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557d5ddd4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557d5ddb75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557d5ddb74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557d57775d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557d576d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557d576d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557d57767c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557d5a736f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557d5a736f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557d5a736f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557d5a736f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557d5a736f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557d5a736f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557d5a736f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557d5a736f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557d5a736f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557d5a736f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557d5c9cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557d596f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557d59703be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557d594afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557d594afc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557d594b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557d594af874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557d594af874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557d594af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557d5ddb9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557d5ddc2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557d5ddaa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557d5ddd5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f05a4765082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557d576cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0xa,0x22,0x5f,0x7,0x22,0x72,0x69,0x66,0x3d,0x42,0x42,0xa,0x7d,0x20,0x20,0xa,0x3d,0x20,0x20,0x2e,0x1d,0x20,0x2e,0x2d,0x13,0x1d,0x60,0x1,0x22,0x2,0x4a,0x2,0x0,0x6,0x60,0x20,0x0,0x65,0x20,0x60,0xa,0x60, Step #5: _\012\"_\007\"rif=BB\012} \012= .\035 .-\023\035`\001\"\002J\002\000\006` \000e `\012` Step #5: artifact_prefix='./'; Test unit written to ./oom-638fb9e6174ccae7efce6472a760ce602b5c6ccc Step #5: Base64: XwoiXwcicmlmPUJCCn0gIAo9ICAuHSAuLRMdYAEiAkoCAAZgIABlIGAKYA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3100 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3238865723 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559289a92810, 0x559289c7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559289c7c020,0x55928bb140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/638fb9e6174ccae7efce6472a760ce602b5c6ccc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3788 processed earlier; will process 7241 files now Step #5: ==111676== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5592805879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559286bec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559286bcf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559286bcf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55928058dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592804eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592804e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55928057fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55928354ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55928354ef10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55928354ef10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55928354ef10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55928354ef10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55928354ef10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55928354ef10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55928354ef10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55928354ef10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55928354ef10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592857e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559282510b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55928251bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5592822c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5592822c7c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5592822c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5592822c7874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5592822c7874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5592822c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559286bd1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559286bda928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559286bc2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559286bed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a4ea3e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592804e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c,0x6f,0x63,0x61,0x6c,0xd,0x66,0x75,0x6e,0x63,0x74,0x69,0x6f,0x6e,0xc,0x6e,0x28,0x29,0x65,0x6e,0x64,0xd,0x6c,0x6f,0x63,0x61,0x6c,0xd,0x66,0x75,0x6e,0x63,0x74,0x69,0x6f,0x6e,0xc,0x6e,0x28,0x29,0x65,0x6e,0x64, Step #5: local\015function\014n()end\015local\015function\014n()end Step #5: artifact_prefix='./'; Test unit written to ./oom-0856e08940884973e0520f27aa3bf121d642e94c Step #5: Base64: bG9jYWwNZnVuY3Rpb24MbigpZW5kDWxvY2FsDWZ1bmN0aW9uDG4oKWVuZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3101 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3239341207 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563701465810, 0x56370164f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56370164f020,0x5637034e70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0856e08940884973e0520f27aa3bf121d642e94c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3789 processed earlier; will process 7240 files now Step #5: ==111712== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5636f7f5a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5636fe5bf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636fe5a25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636fe5a24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5636f7f60d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5636f7ec1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5636f7ebc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5636f7f52c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5636faf21f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5636faf21f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5636faf21f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5636faf21f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5636faf21f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5636faf21f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5636faf21f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5636faf21f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5636faf21f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5636faf21f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5636fd1b6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5636f9ee3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5636f9eeebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5636f9c9ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5636f9c9ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5636f9c9b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5636f9c9a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5636f9c9a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5636f9c9a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5636fe5a4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5636fe5ad928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5636fe595699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5636fe5c0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff9f2cd1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5636f7ebab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x2d,0x33,0x2d,0x32,0x31,0x36,0x3a,0x38,0x3a,0x31,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0,0xc2,0xa0, Step #5: 0-3-216:8:1\302\240\302\240\302\240\302\240\302\240\302\240\302\240\302\240\302\240\302\240\302\240\302\240\302\240\302\240\302\240\302\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-f9a3c462d3d4e4752c910ddd5e7610c168d9ba97 Step #5: Base64: MC0zLTIxNjo4OjHCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3102 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3239818682 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e3ca98c810, 0x55e3cab7601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e3cab76020,0x55e3cca0e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9a3c462d3d4e4752c910ddd5e7610c168d9ba97' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3790 processed earlier; will process 7239 files now Step #5: ==111748== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55e3c14819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e3c7ae6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e3c7ac95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e3c7ac94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e3c1487d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e3c13e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e3c13e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e3c1479c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e3c4448f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e3c4448f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e3c4448f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e3c4448f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e3c4448f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e3c4448f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e3c4448f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e3c4448f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e3c4448f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e3c4448f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e3c66ddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e3c340ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e3c3415be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e3c31c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e3c31c1c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e3c31c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e3c31c1874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e3c31c1874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e3c31c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e3c7acbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e3c7ad4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e3c7abc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e3c7ae7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf40cfc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e3c13e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33,0x3a,0x3a,0x3d,0xa,0x31,0x3a,0x3a,0x40,0x3d,0xa,0x6b,0x3a,0x3a,0x3d,0xa,0x3a,0x3a,0x3d,0xa,0x3d,0xa,0x21,0x3a,0x3a,0x3d,0xa,0x67,0x3a,0x3a,0x3d,0xa,0x64,0x3a,0x3a,0x3d,0xa,0x2b,0x3a,0x3a,0x3d,0xa,0x3d, Step #5: 3::=\0121::@=\012k::=\012::=\012=\012!::=\012g::=\012d::=\012+::=\012= Step #5: artifact_prefix='./'; Test unit written to ./oom-b9cbbe72b9fce2e8620d1b01bd6420057558fc39 Step #5: Base64: Mzo6PQoxOjpAPQprOjo9Cjo6PQo9CiE6Oj0KZzo6PQpkOjo9Cis6Oj0KPQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3103 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3240301493 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cdd92ad810, 0x55cdd949701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cdd9497020,0x55cddb32f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b9cbbe72b9fce2e8620d1b01bd6420057558fc39' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3791 processed earlier; will process 7238 files now Step #5: ==111784== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cdcfda29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cdd6407898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cdd63ea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cdd63ea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cdcfda8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cdcfd09b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cdcfd04355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cdcfd9ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cdd2d69f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cdd2d69f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cdd2d69f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cdd2d69f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cdd2d69f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cdd2d69f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cdd2d69f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cdd2d69f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cdd2d69f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cdd2d69f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cdd4ffef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cdd1d2bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cdd1d36be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cdd1ae2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cdd1ae2c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cdd1ae3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cdd1ae2874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cdd1ae2874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cdd1ae2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cdd63ecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cdd63f5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cdd63dd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cdd6408112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f86d7681082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cdcfd02b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x40,0x5c,0x2b,0x5c,0x4d,0x5c,0x5,0x5,0x2,0x29,0x0,0x0,0x29,0x3d,0x0,0x0,0xd9,0xbe,0x19,0x0,0x0,0xef,0xbf,0xb4,0xef,0xbf,0xaf,0xef,0xbf,0xad,0x0,0x1,0x0,0x0,0x0,0x0,0x1b,0x0,0xf,0x25,0x0,0x0, Step #5: \\@\\+\\M\\\005\005\002)\000\000)=\000\000\331\276\031\000\000\357\277\264\357\277\257\357\277\255\000\001\000\000\000\000\033\000\017%\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-754b8ceb96231d7d5ec8b68a7c3b2e0b9b776a3c Step #5: Base64: XEBcK1xNXAUFAikAACk9AADZvhkAAO+/tO+/r++/rQABAAAAABsADyUAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3104 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3240778296 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb80140810, 0x55cb8032a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb8032a020,0x55cb821c20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/754b8ceb96231d7d5ec8b68a7c3b2e0b9b776a3c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3792 processed earlier; will process 7237 files now Step #5: #1 pulse cov: 3939 ft: 3940 exec/s: 0 rss: 171Mb Step #5: ==111820== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55cb76c359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb7d29a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb7d27d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb7d27d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb76c3bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb76b9cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb76b97355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb76c2dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb79bfcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb79bfcf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb79bfcf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb79bfcf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb79bfcf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb79bfcf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb79bfcf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb79bfcf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb79bfcf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb79bfcf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb7be91f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb78bbeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb78bc9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb78975c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb78975c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb78976738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb78975874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb78975874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb78975874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb7d27fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb7d288928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb7d270699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb7d29b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6019d09082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb76b95b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x53,0x3a,0xc5,0x99,0xcd,0x99,0xd6,0xbd,0xd6,0xbb,0xd6,0xb9,0xc5,0x99,0xcd,0x99,0xd6,0xbd,0xd6,0xbb,0xd6,0xb9,0xc5,0x99,0xcd,0x99,0xd6,0xbd,0xd6,0xbb,0xd6,0xb9,0xc5,0xb8,0xcd,0x9a,0xd6,0xbd,0xd6,0xbb,0xd6,0xb9, Step #5: wS:\305\231\315\231\326\275\326\273\326\271\305\231\315\231\326\275\326\273\326\271\305\231\315\231\326\275\326\273\326\271\305\270\315\232\326\275\326\273\326\271 Step #5: artifact_prefix='./'; Test unit written to ./oom-aba1e17a1b9c0e379f3264aeaa06ccd27176fa6b Step #5: Base64: d1M6xZnNmda91rvWucWZzZnWvda71rnFmc2Z1r3Wu9a5xbjNmta91rvWuQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3105 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3241295905 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b1f1250810, 0x55b1f143a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b1f143a020,0x55b1f32d20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aba1e17a1b9c0e379f3264aeaa06ccd27176fa6b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3794 processed earlier; will process 7235 files now Step #5: #1 pulse cov: 3917 ft: 3918 exec/s: 0 rss: 172Mb Step #5: ==111856== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55b1e7d459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b1ee3aa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1ee38d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1ee38d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b1e7d4bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b1e7cacb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b1e7ca7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b1e7d3dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b1ead0cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b1ead0cf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b1ead0cf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b1ead0cf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b1ead0cf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b1ead0cf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b1ead0cf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b1ead0cf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b1ead0cf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b1ead0cf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b1ecfa1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b1e9cceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b1e9cd9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b1e9a85c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b1e9a85c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b1e9a86738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b1e9a85874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b1e9a85874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b1e9a85874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b1ee38fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b1ee398928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b1ee380699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b1ee3ab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d15320082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b1e7ca5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x36,0x2d,0x31,0x2d,0x32,0x31,0x39,0x3a,0x34,0x3a,0x32,0xd9,0x91,0xd9,0x92,0xd9,0x8e,0xd8,0x91,0xd9,0x91,0xd9,0x8e,0xd8,0x91,0xd9,0x92,0xd9,0x92,0xd9,0x8e,0xd9,0x91,0xd9,0x98,0xd9,0x91,0xd9,0x8e,0xd8,0x91,0xd9,0x92, Step #5: 6-1-219:4:2\331\221\331\222\331\216\330\221\331\221\331\216\330\221\331\222\331\222\331\216\331\221\331\230\331\221\331\216\330\221\331\222 Step #5: artifact_prefix='./'; Test unit written to ./oom-d4990f13a49a766a723cfec5245f71543617f31d Step #5: Base64: Ni0xLTIxOTo0OjLZkdmS2Y7YkdmR2Y7YkdmS2ZLZjtmR2ZjZkdmO2JHZkg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3106 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3241813640 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7bd2e1810, 0x55f7bd4cb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7bd4cb020,0x55f7bf3630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d4990f13a49a766a723cfec5245f71543617f31d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3796 processed earlier; will process 7233 files now Step #5: ==111892== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f7b3dd69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7ba43b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7ba41e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7ba41e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f7b3ddcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f7b3d3db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f7b3d38355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f7b3dcec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7b6d9df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7b6d9df10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7b6d9df10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7b6d9df10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7b6d9df10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7b6d9df10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7b6d9df10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7b6d9df10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7b6d9df10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7b6d9df10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7b9032f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f7b5d5fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f7b5d6abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f7b5b16c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f7b5b16c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f7b5b17738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f7b5b16874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f7b5b16874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f7b5b16874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7ba420abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7ba429928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7ba411699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7ba43c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b9675a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f7b3d36b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x30,0xf,0x2d,0x31,0x5b,0x26,0x11,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x30,0xf,0x2d,0x24,0x5b,0x2d,0x3a,0xee,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\017\017\017\017\0170\017-1[&\021\000\000/\000\000\000/\000\017\017\017\017\0170\017-$[-:\356$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-45a84c67f832e08bb95a736cd249084493c9cf7c Step #5: Base64: JAAALwAAAC8ADw8PDw8wDy0xWyYRAAAvAAAALwAPDw8PDzAPLSRbLTruJFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3107 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3242293761 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556ee71c7810, 0x556ee73b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556ee73b1020,0x556ee92490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/45a84c67f832e08bb95a736cd249084493c9cf7c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3797 processed earlier; will process 7232 files now Step #5: #1 pulse cov: 3678 ft: 3679 exec/s: 0 rss: 171Mb Step #5: ==111928== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x556eddcbc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556ee4321898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556ee43045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556ee43044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556eddcc2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556eddc23b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556eddc1e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556eddcb4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556ee0c83f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556ee0c83f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556ee0c83f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556ee0c83f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556ee0c83f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556ee0c83f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556ee0c83f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556ee0c83f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556ee0c83f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556ee0c83f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556ee2f18f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556edfc45b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556edfc50be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556edf9fcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556edf9fcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556edf9fd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556edf9fc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556edf9fc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556edf9fc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556ee4306abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556ee430f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556ee42f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556ee4322112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ea4a78082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556eddc1cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x24,0x30,0x2,0x2,0x0,0x30,0x24,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x31,0x0,0x32,0x32,0x35,0x0, Step #5: 0$0\002\002\0000$1\0001\0001\0001\0001\0001\0001\0001\0001\0001\0001\0001\0001\0001\0001\0001\000225\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-94aabd27bd7d0b045f1c7669a5127dc71587101b Step #5: Base64: MCQwAgIAMCQxADEAMQAxADEAMQAxADEAMQAxADEAMQAxADEAMQAxADIyNQA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3108 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3242811986 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562db0bd5810, 0x562db0dbf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562db0dbf020,0x562db2c570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/94aabd27bd7d0b045f1c7669a5127dc71587101b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3799 processed earlier; will process 7230 files now Step #5: ==111964== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x562da76ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562dadd2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562dadd125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562dadd124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562da76d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562da7631b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562da762c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562da76c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562daa691f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562daa691f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562daa691f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562daa691f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562daa691f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562daa691f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562daa691f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562daa691f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562daa691f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562daa691f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562dac926f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562da9653b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562da965ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562da940ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562da940ac6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562da940b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562da940a874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562da940a874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562da940a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562dadd14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562dadd1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562dadd05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562dadd30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb538878082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562da762ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x88,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x0,0x0,0x60,0xa,0x9,0x60,0x20,0x60,0x60,0xa,0x9, Step #5: `\342\210\210-\000`\012\363\240\201\272/\012`\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000\000\000`\012\011` ``\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-dc025d11e90d39280433961a9ac43cbff9df24da Step #5: Base64: YOKIiC0AYArzoIG6Lwpg4oCILQBgCvOggbrzoIG6LwEAAABgCglgIGBgCgk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3109 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3243408660 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56167dd46810, 0x56167df3001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56167df30020,0x56167fdc80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dc025d11e90d39280433961a9ac43cbff9df24da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3800 processed earlier; will process 7229 files now Step #5: #1 pulse cov: 3976 ft: 3977 exec/s: 0 rss: 171Mb Step #5: #2 pulse cov: 13850 ft: 14734 exec/s: 0 rss: 193Mb Step #5: ==112000== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x56167483b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56167aea0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56167ae835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56167ae834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561674841d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5616747a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56167479d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561674833c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561677802f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561677802f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561677802f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561677802f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561677802f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561677802f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561677802f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561677802f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561677802f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561677802f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561679a97f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5616767c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5616767cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56167657bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56167657bc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56167657c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56167657b874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56167657b874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56167657b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56167ae85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56167ae8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56167ae76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56167aea1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f32a405f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56167479bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x2b,0x32,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x7a,0x0,0x0,0xfe,0x1,0x44,0x33,0x4,0x8c,0x0,0x4,0x3,0x32,0x7a,0x0,0x1, Step #5: ID3\004+2ffffffffffffffffffffffz\000\000\376\001D3\004\214\000\004\0032z\000\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-746155c2e959c52975d3a6def8644371bff57c7e Step #5: Base64: SUQzBCsyZmZmZmZmZmZmZmZmZmZmZmZmZmZmZnoAAP4BRDMEjAAEAzJ6AAE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3110 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3243994311 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f89bfdb810, 0x55f89c1c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f89c1c5020,0x55f89e05d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/746155c2e959c52975d3a6def8644371bff57c7e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3803 processed earlier; will process 7226 files now Step #5: #1 pulse cov: 3923 ft: 3924 exec/s: 0 rss: 173Mb Step #5: ==112036== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55f892ad09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f899135898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8991185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8991184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f892ad6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f892a37b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f892a32355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f892ac8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f895a97f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f895a97f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f895a97f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f895a97f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f895a97f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f895a97f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f895a97f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f895a97f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f895a97f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f895a97f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f897d2cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f894a59b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f894a64be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f894810c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f894810c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f894811738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f894810874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f894810874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f894810874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f89911aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f899123928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f89910b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f899136112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f45237d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f892a30b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x2d,0x2c,0xd5,0xa4,0x21,0xd5,0xa4,0x21,0xd5,0xa4,0x60,0x5b,0x2d,0x31,0x2d,0x33,0x38,0x37,0x35,0x34,0x38,0x33,0x30,0x30,0x5d,0xff,0x5f,0x5f,0x5f,0x1,0x85,0x85,0x0,0x57,0x11,0x5f,0x1,0x85,0x57,0x11,0x5f,0x0,0x2a, Step #5: `-,\325\244!\325\244!\325\244`[-1-387548300]\377___\001\205\205\000W\021_\001\205W\021_\000* Step #5: artifact_prefix='./'; Test unit written to ./oom-ae66a415e7d523e00062718e468f3f6ea1fbeb28 Step #5: Base64: YC0s1aQh1aQh1aRgWy0xLTM4NzU0ODMwMF3/X19fAYWFAFcRXwGFVxFfACo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3111 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3244643161 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c707021810, 0x55c70720b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c70720b020,0x55c7090a30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ae66a415e7d523e00062718e468f3f6ea1fbeb28' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3805 processed earlier; will process 7224 files now Step #5: #1 pulse cov: 11860 ft: 11861 exec/s: 0 rss: 190Mb Step #5: #2 pulse cov: 12584 ft: 13432 exec/s: 0 rss: 193Mb Step #5: ==112072== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55c6fdb169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c70417b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c70415e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c70415e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c6fdb1cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6fda7db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6fda78355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c6fdb0ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c700addf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c700addf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c700addf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c700addf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c700addf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c700addf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c700addf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c700addf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c700addf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c700addf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c702d72f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6ffa9fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c6ffaaabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6ff856c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6ff856c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6ff857738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6ff856874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6ff856874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6ff856874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c704160abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c704169928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c704151699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c70417c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f04aeaa5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6fda76b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x2,0x0,0x1,0x0,0x30,0x63,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x49,0x0,0x0,0x0,0x0,0x0,0x2c,0x0,0x0,0x60,0x2a,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x1e,0x0,0xe9,0x0,0x0, Step #5: DanM\002\000\001\0000c````````I\000\000\000\000\000,\000\000`*``````````\036\000\351\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-285e4be867dd6acfe8f2582ab6f014cbd9a8b1c5 Step #5: Base64: RGFuTQIAAQAwY2BgYGBgYGBgSQAAAAAALAAAYCpgYGBgYGBgYGBgHgDpAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3112 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3245383268 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a807a7810, 0x555a8099101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a80991020,0x555a828290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/285e4be867dd6acfe8f2582ab6f014cbd9a8b1c5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3809 processed earlier; will process 7220 files now Step #5: ==112108== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x555a7729c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a7d901898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a7d8e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a7d8e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a772a2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a77203b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a771fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a77294c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a7a263f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a7a263f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a7a263f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a7a263f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a7a263f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a7a263f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a7a263f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a7a263f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a7a263f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a7a263f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a7c4f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a79225b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a79230be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a78fdcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a78fdcc6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a78fdd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a78fdc874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a78fdc874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a78fdc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a7d8e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a7d8ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a7d8d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a7d902112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdd93f85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a771fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x55,0x0,0x6,0x0,0x0,0xef,0xbe,0xa0,0xe0,0xb9,0x84,0x0,0x0,0x0,0xe0,0xb9,0x84,0xf3,0xa0,0x80,0xa4,0x0,0x0,0x0,0xef,0xac,0xac,0x2,0x0,0x6,0x0,0x0,0x0,0x6,0x0,0x0,0xb,0x0,0xf6,0xf0,0x9f,0x92,0xa9,0x6, Step #5: U\000\006\000\000\357\276\240\340\271\204\000\000\000\340\271\204\363\240\200\244\000\000\000\357\254\254\002\000\006\000\000\000\006\000\000\013\000\366\360\237\222\251\006 Step #5: artifact_prefix='./'; Test unit written to ./oom-47d7e4ceff31d73f58f8f989707bc005997d5640 Step #5: Base64: VQAGAADvvqDguYQAAADguYTzoICkAAAA76ysAgAGAAAABgAACwD28J+SqQY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3113 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3245866308 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5649b6e8f810, 0x5649b707901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5649b7079020,0x5649b8f110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/47d7e4ceff31d73f58f8f989707bc005997d5640' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3810 processed earlier; will process 7219 files now Step #5: ==112144== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x5649ad9849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5649b3fe9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5649b3fcc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5649b3fcc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5649ad98ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649ad8ebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649ad8e6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5649ad97cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5649b094bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5649b094bf10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5649b094bf10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5649b094bf10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5649b094bf10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5649b094bf10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5649b094bf10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5649b094bf10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5649b094bf10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5649b094bf10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5649b2be0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649af90db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649af918be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5649af6c4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5649af6c4c6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5649af6c5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5649af6c4874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5649af6c4874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5649af6c4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5649b3fceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5649b3fd7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5649b3fbf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5649b3fea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e94180082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649ad8e4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x49,0x4c,0x45,0x20,0x40,0x20,0x4d,0x50,0x33,0xa,0x46,0x49,0x4c,0x45,0x20,0x60,0x20,0x4d,0x50,0x33,0xa,0x46,0x49,0x4c,0x45,0x20,0x60,0x20,0x4d,0x50,0x33,0xa,0x46,0x49,0x4c,0x45,0x20,0x40,0x20,0x4d,0x50,0x33,0xa, Step #5: FILE @ MP3\012FILE ` MP3\012FILE ` MP3\012FILE @ MP3\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-896b8225af95518db290c2b3740c84422956057d Step #5: Base64: RklMRSBAIE1QMwpGSUxFIGAgTVAzCkZJTEUgYCBNUDMKRklMRSBAIE1QMwo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3114 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3246469369 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ebb89b9810, 0x55ebb8ba301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ebb8ba3020,0x55ebbaa3b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/896b8225af95518db290c2b3740c84422956057d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3811 processed earlier; will process 7218 files now Step #5: ==112180== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: #0 0x55ebaf4ae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ebb5b13898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ebb5af65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ebb5af64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ebaf4b4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ebaf415b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ebaf410355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ebaf4a6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ebb2475f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ebb2475f10 in ::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ebb2475f10 in ::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ebb2475f10 in ::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ebb2475f10 in ::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ebb2475f10 in ::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ebb2475f10 in >::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ebb2475f10 in ::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ebb2475f10 in alloc::vec::from_elem:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ebb2475f10 in ::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ebb470af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ebb1437b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ebb1442be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ebb11eec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ebb11eec6c in std::panicking::catch_unwind::do_call:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ebb11ef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ebb11ee874 in std::panicking::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ebb11ee874 in std::panic::catch_unwind:: /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ebb11ee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ebb5af8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ebb5b01928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ebb5ae9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ebb5b14112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e92983082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ebaf40eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x68,0x3e,0x3c,0x21,0x5b,0x43,0x44,0x41,0x54,0x41,0x5b,0xd,0xe1,0x85,0x9f,0xd,0xe1,0x85,0x9f,0xd,0xe1,0x85,0x9f,0xd,0xe1,0x85,0x9f,0xd,0xe1,0x85,0x9f,0xd,0xe1,0x85,0x9f,0xd,0xe1,0x85,0x9f,0xd,0xe1,0x85,0x9f, Step #5: \015\341\205\237\015\341\205\237\015\341\205\237\015\341\205\237\015\341\205\237\015\341\205\237\015\341\205\237\015\341\205\237 Step #5: artifact_prefix='./'; Test unit written to ./oom-bef8a4185c202890e3f71e823e259a84973ccefd Step #5: Base64: PGg+PCFbQ0RBVEFbDeGFnw3hhZ8N4YWfDeGFnw3hhZ8N4YWfDeGFnw3hhZ8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3115 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3246947637 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55593dda8810, 0x55593df9201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55593df92020,0x55593fe2a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bef8a4185c202890e3f71e823e259a84973ccefd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3812 processed earlier; will process 7217 files now Step #5: ==112216== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55593489d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55593af02898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55593aee55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55593aee54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5559348a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555934804b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5559347ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555934895c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555937864f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555937864f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555937864f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555937864f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555937864f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555937864f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555937864f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555937864f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555937864f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555937864f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555939af9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555936826b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555936831be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5559365ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5559365ddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5559365de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5559365dd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5559365dd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5559365dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55593aee7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55593aef0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55593aed8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55593af03112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0744fc4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5559347fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0x52,0x49,0x43,0x33,0x34,0x52,0x52,0x41,0x59,0x61,0x61,0x69,0x46,0x78,0x43,0x75,0x32,0x61,0x69,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x51,0x69,0x6a,0x6a,0x68,0x79,0x79,0x46,0x47,0x44,0x5f,0x7a,0x7a,0x45,0x63,0x42,0x61,0x5f, Step #5: _RIC34RRAYaaiFxCu2aiooooooQijjhyyFGD_zzEcBa_ Step #5: artifact_prefix='./'; Test unit written to ./oom-5caf855915ee39229151e2121704a8e16725503b Step #5: Base64: X1JJQzM0UlJBWWFhaUZ4Q3UyYWlvb29vb29RaWpqaHl5RkdEX3p6RWNCYV8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3116 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3247431678 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a99c69810, 0x558a99e5301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a99e53020,0x558a9bceb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5caf855915ee39229151e2121704a8e16725503b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3813 processed earlier; will process 7216 files now Step #5: #1 pulse cov: 3516 ft: 3517 exec/s: 0 rss: 174Mb Step #5: ==112252== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558a9075e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a96dc3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a96da65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a96da64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a90764d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a906c5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a906c0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a90756c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a93725f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a93725f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a93725f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a93725f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a93725f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a93725f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a93725f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a93725f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a93725f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a93725f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a959baf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a926e7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a926f2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a9249ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a9249ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a9249f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a9249e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a9249e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a9249e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a96da8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a96db1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a96d99699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a96dc4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3d19b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a906beb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x62,0x28,0x17,0x29,0x28,0x29,0x4d,0x26,0xe1,0x83,0x83,0x46,0x70,0x6a,0x28,0x29,0x4d,0x26,0xe1,0x83,0x83,0x46,0x26,0xe1,0x83,0x83,0x46,0x70,0x26,0x74,0x4d,0x52,0x29,0x2e,0x6a,0x6a,0x29,0x2e,0x2e,0x1,0x0,0x0,0x28,0x29, Step #5: b(\027)()M&\341\203\203Fpj()M&\341\203\203F&\341\203\203Fp&tMR).jj)..\001\000\000() Step #5: artifact_prefix='./'; Test unit written to ./oom-b61679b0d18fffffdb6a83b751f9424c004c0fa6 Step #5: Base64: YigXKSgpTSbhg4NGcGooKU0m4YODRibhg4NGcCZ0TVIpLmpqKS4uAQAAKCk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3117 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3247952890 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af5a069810, 0x55af5a25301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af5a253020,0x55af5c0eb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b61679b0d18fffffdb6a83b751f9424c004c0fa6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3815 processed earlier; will process 7214 files now Step #5: ==112288== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55af50b5e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af571c3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af571a65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af571a64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55af50b64d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55af50ac5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55af50ac0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55af50b56c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55af53b25f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55af53b25f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55af53b25f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55af53b25f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55af53b25f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55af53b25f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55af53b25f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55af53b25f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55af53b25f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55af53b25f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af55dbaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af52ae7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af52af2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af5289ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af5289ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af5289f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af5289e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af5289e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af5289e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af571a8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af571b1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af57199699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af571c4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f84d3d5c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55af50abeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x76,0x73,0x34,0x72,0x65,0x61,0x6d,0x50,0x50,0x4f,0x50,0x76,0x73,0x34,0x72,0x65,0x61,0x6d,0x50,0x50,0x4f,0x50,0x76,0x73,0x34,0x72,0x65,0x61,0x6d,0x50,0x50,0x4f,0x50,0x76,0x73,0x34,0x72,0x65,0x61,0x6d,0x50,0x50,0x4f,0x50, Step #5: vs4reamPPOPvs4reamPPOPvs4reamPPOPvs4reamPPOP Step #5: artifact_prefix='./'; Test unit written to ./oom-5bd30e7c940639fa7b0483b897f0b539f05f2aa8 Step #5: Base64: dnM0cmVhbVBQT1B2czRyZWFtUFBPUHZzNHJlYW1QUE9QdnM0cmVhbVBQT1A= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3118 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3248431073 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56007edcc810, 0x56007efb601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56007efb6020,0x560080e4e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5bd30e7c940639fa7b0483b897f0b539f05f2aa8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3816 processed earlier; will process 7213 files now Step #5: ==112324== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5600758c19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56007bf26898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56007bf095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56007bf094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5600758c7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560075828b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560075823355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5600758b9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560078888f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560078888f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560078888f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560078888f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560078888f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560078888f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560078888f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560078888f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560078888f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560078888f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56007ab1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56007784ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560077855be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560077601c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560077601c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560077602738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560077601874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560077601874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560077601874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56007bf0babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56007bf14928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56007befc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56007bf27112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f33ae414082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560075821b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0x3a,0x20,0x7b,0x7b,0x6f,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0x67,0x7d,0x7d, Step #5: 2: {{o\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015g}} Step #5: artifact_prefix='./'; Test unit written to ./oom-f184289c9d4dbc324b2c7a6292d470d12d7d4a11 Step #5: Base64: Mjoge3tvDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ1nfX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3119 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3248907305 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e19fe7810, 0x555e1a1d101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e1a1d1020,0x555e1c0690e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f184289c9d4dbc324b2c7a6292d470d12d7d4a11' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3817 processed earlier; will process 7212 files now Step #5: ==112360== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555e10adc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e17141898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e171245dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e171244fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e10ae2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e10a43b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e10a3e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e10ad4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e13aa3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e13aa3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e13aa3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e13aa3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e13aa3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e13aa3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e13aa3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e13aa3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e13aa3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e13aa3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e15d38f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e12a65b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e12a70be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e1281cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e1281cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e1281d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e1281c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e1281c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e1281c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e17126abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e1712f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e17117699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e17142112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff62d0b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e10a3cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x28,0x0,0xcf,0x87,0xc6,0xb0,0xc6,0xbd,0xc6,0xbd,0xc6,0xb0,0xcf,0x87,0xc6,0xb0,0xc6,0xbd,0xc9,0xb2,0x5b,0xef,0xbf,0xbd,0xc6,0xbd,0xc6,0xbd,0xc6,0xbd,0xc6,0xbd,0xc7,0xbd,0xdd,0xb0,0xcf,0xb0,0xcf,0x87,0x2f, Step #5: \000\000\000(\000\317\207\306\260\306\275\306\275\306\260\317\207\306\260\306\275\311\262[\357\277\275\306\275\306\275\306\275\306\275\307\275\335\260\317\260\317\207/ Step #5: artifact_prefix='./'; Test unit written to ./oom-eb05285c790298b8769871cc96d7006823ede106 Step #5: Base64: AAAAKADPh8awxr3Gvcawz4fGsMa9ybJb77+9xr3Gvca9xr3Hvd2wz7DPhy8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3120 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3249388369 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55efe63f8810, 0x55efe65e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55efe65e2020,0x55efe847a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eb05285c790298b8769871cc96d7006823ede106' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3818 processed earlier; will process 7211 files now Step #5: ==112396== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55efdceed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55efe3552898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55efe35355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55efe35354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55efdcef3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55efdce54b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55efdce4f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55efdcee5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55efdfeb4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55efdfeb4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55efdfeb4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55efdfeb4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55efdfeb4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55efdfeb4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55efdfeb4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55efdfeb4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55efdfeb4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55efdfeb4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55efe2149f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55efdee76b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55efdee81be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55efdec2dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55efdec2dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55efdec2e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55efdec2d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55efdec2d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55efdec2d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55efe3537abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55efe3540928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55efe3528699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55efe3553112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f26e1187082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55efdce4db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xba,0xd6,0xba,0xd6,0xb7,0xd6,0xb1,0xcc,0xb7,0xef,0xbb,0xba,0xd6,0xba,0xd6,0xb7,0xd6,0xb1,0xcc,0xb7,0xef,0xbb,0xba,0xd6,0xba,0xd6,0xb7,0xd6,0xb1,0xcc,0xb7,0xef,0xbb,0xba,0xd6,0xba,0xd6,0xb7,0xd6,0xb1,0xcc,0xb7, Step #5: \357\273\272\326\272\326\267\326\261\314\267\357\273\272\326\272\326\267\326\261\314\267\357\273\272\326\272\326\267\326\261\314\267\357\273\272\326\272\326\267\326\261\314\267 Step #5: artifact_prefix='./'; Test unit written to ./oom-5783ec6cb9681e560759e1d70c82a4d037327624 Step #5: Base64: 77u61rrWt9axzLfvu7rWuta31rHMt++7uta61rfWscy377u61rrWt9axzLc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3121 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3249866884 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5625a0977810, 0x5625a0b6101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625a0b61020,0x5625a29f90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5783ec6cb9681e560759e1d70c82a4d037327624' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3819 processed earlier; will process 7210 files now Step #5: ==112432== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56259746c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56259dad1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56259dab45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56259dab44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562597472d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625973d3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625973ce355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562597464c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56259a433f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56259a433f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56259a433f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56259a433f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56259a433f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56259a433f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56259a433f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56259a433f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56259a433f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56259a433f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56259c6c8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625993f5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562599400be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5625991acc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5625991acc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5625991ad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5625991ac874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5625991ac874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5625991ac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56259dab6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56259dabf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56259daa7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56259dad2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb3c61f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625973ccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x54,0x32,0x32,0x36,0x5c,0x52,0x5c,0x53,0x5c,0x52,0x5c,0x52,0x5c,0x3,0x2e,0x2b,0x5c,0x2f,0x5c,0x5c,0x75,0x44,0x39,0x31,0x34,0x5c,0x5c,0xea,0xa1,0xa1,0x8d,0xff,0x31,0x37,0x30,0x36,0x36,0x30,0x34,0x34,0x36,0x2f,0x53, Step #5: IT226\\R\\S\\R\\R\\\003.+\\/\\\\uD914\\\\\352\241\241\215\377170660446/S Step #5: artifact_prefix='./'; Test unit written to ./oom-fa8605e81b106ca494a16ab7cf6e141335fcae0c Step #5: Base64: SVQyMjZcUlxTXFJcUlwDLitcL1xcdUQ5MTRcXOqhoY3/MTcwNjYwNDQ2L1M= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3122 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3250343426 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b4dc162810, 0x55b4dc34c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b4dc34c020,0x55b4de1e40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fa8605e81b106ca494a16ab7cf6e141335fcae0c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3820 processed earlier; will process 7209 files now Step #5: ==112468== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b4d2c579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b4d92bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b4d929f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b4d929f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b4d2c5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b4d2bbeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b4d2bb9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b4d2c4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b4d5c1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b4d5c1ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b4d5c1ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b4d5c1ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b4d5c1ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b4d5c1ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b4d5c1ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b4d5c1ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b4d5c1ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b4d5c1ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b4d7eb3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b4d4be0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b4d4bebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b4d4997c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b4d4997c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b4d4998738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b4d4997874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b4d4997874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b4d4997874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b4d92a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b4d92aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b4d9292699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b4d92bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6a26304082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b4d2bb7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2d,0x2d,0x2d,0x2e,0x2d,0x2d,0x2d,0xa,0x3a,0xa,0xf3,0xa0,0x81,0x97,0x21,0xa,0x2d,0xa,0x3a,0xa,0xf3,0xa0,0x81,0x97,0x21,0xa,0xf3,0xa0,0x81,0x97,0x21,0xa,0xf3,0xa0,0x81,0x97,0x21,0xa,0x2d,0xa,0x2d,0xa,0xa, Step #5: \012---.---\012:\012\363\240\201\227!\012-\012:\012\363\240\201\227!\012\363\240\201\227!\012\363\240\201\227!\012-\012-\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-95fd40b69ce678eb9f34449fbc593e8366475c1d Step #5: Base64: Ci0tLS4tLS0KOgrzoIGXIQotCjoK86CBlyEK86CBlyEK86CBlyEKLQotCgo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3123 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3250828238 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55addf16c810, 0x55addf35601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55addf356020,0x55ade11ee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/95fd40b69ce678eb9f34449fbc593e8366475c1d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3821 processed earlier; will process 7208 files now Step #5: ==112504== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55add5c619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55addc2c6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55addc2a95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55addc2a94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55add5c67d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55add5bc8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55add5bc3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55add5c59c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55add8c28f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55add8c28f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55add8c28f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55add8c28f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55add8c28f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55add8c28f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55add8c28f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55add8c28f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55add8c28f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55add8c28f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55addaebdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55add7beab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55add7bf5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55add79a1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55add79a1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55add79a2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55add79a1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55add79a1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55add79a1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55addc2ababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55addc2b4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55addc29c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55addc2c7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f19a1e88082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55add5bc1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0xa,0x25,0x54,0x41,0x47,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0xa,0x2d,0x2d,0x2d, Step #5: ---\012%TAG\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\012--- Step #5: artifact_prefix='./'; Test unit written to ./oom-8c45bb837ddeb53bf041d8d7bd1d821765a22ff3 Step #5: Base64: LS0tCiVUQUcJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQotLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3124 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3251310625 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564182c0d810, 0x564182df701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564182df7020,0x564184c8f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c45bb837ddeb53bf041d8d7bd1d821765a22ff3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3822 processed earlier; will process 7207 files now Step #5: ==112540== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5641797029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56417fd67898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56417fd4a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56417fd4a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564179708d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564179669b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564179664355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5641796fac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56417c6c9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56417c6c9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56417c6c9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56417c6c9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56417c6c9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56417c6c9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56417c6c9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56417c6c9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56417c6c9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56417c6c9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56417e95ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56417b68bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56417b696be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56417b442c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56417b442c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56417b443738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56417b442874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56417b442874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56417b442874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56417fd4cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56417fd55928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56417fd3d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56417fd68112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e76dc9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564179662b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5c,0x3d,0x24,0x5c,0x5c, Step #5: =$\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\\=$\\\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-98d7e058b36e6142fd3bfd64dfe9b3e8a917e9ef Step #5: Base64: PSQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAXD0kXFw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3125 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3251794465 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a95f23a810, 0x55a95f42401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a95f424020,0x55a9612bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/98d7e058b36e6142fd3bfd64dfe9b3e8a917e9ef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3823 processed earlier; will process 7206 files now Step #5: ==112576== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a955d2f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a95c394898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a95c3775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a95c3774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a955d35d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a955c96b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a955c91355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a955d27c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a958cf6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a958cf6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a958cf6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a958cf6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a958cf6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a958cf6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a958cf6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a958cf6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a958cf6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a958cf6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a95af8bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a957cb8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a957cc3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a957a6fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a957a6fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a957a70738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a957a6f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a957a6f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a957a6f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a95c379abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a95c382928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a95c36a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a95c395112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efcbafc0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a955c8fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x21,0x73,0x3b,0x77,0x29,0x29,0x29,0x30,0x29,0x29,0x2b,0x77,0x29,0xd6,0x92,0x29,0x22,0x3a,0x31,0x2c,0x22,0x21,0x73,0x3b,0x77,0x29,0x29,0x29,0x30,0x29,0x29,0x2b,0x77,0x29,0xd6,0x92,0xd6,0x92,0x22,0x3a,0x37,0x7d, Step #5: {\"!s;w)))0))+w)\326\222)\":1,\"!s;w)))0))+w)\326\222\326\222\":7} Step #5: artifact_prefix='./'; Test unit written to ./oom-23ee8f30a13fae583cf737f4af298e9a93908b52 Step #5: Base64: eyIhczt3KSkpMCkpK3cp1pIpIjoxLCIhczt3KSkpMCkpK3cp1pLWkiI6N30= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3126 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3252275867 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611ec3fb810, 0x5611ec5e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5611ec5e5020,0x5611ee47d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/23ee8f30a13fae583cf737f4af298e9a93908b52' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3824 processed earlier; will process 7205 files now Step #5: ==112612== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5611e2ef09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5611e9555898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611e95385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611e95384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5611e2ef6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5611e2e57b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5611e2e52355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5611e2ee8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5611e5eb7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5611e5eb7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5611e5eb7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5611e5eb7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5611e5eb7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5611e5eb7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5611e5eb7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5611e5eb7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5611e5eb7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5611e5eb7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5611e814cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611e4e79b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5611e4e84be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611e4c30c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611e4c30c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611e4c31738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611e4c30874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611e4c30874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611e4c30874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5611e953aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5611e9543928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611e952b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5611e9556112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f18bc50b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5611e2e50b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x3f,0x3a,0x24,0x7c,0x7a,0x7c,0x24,0x7c,0x0,0x7c,0x24,0x7c,0x11,0x7c,0x24,0x28,0x3f,0x3a,0x24,0x7c,0x7a,0x7c,0x24,0x7c,0x0,0x7c,0x24,0x7c,0x11,0x7c,0x24,0x7c,0x7a,0x29,0x7c,0x29,0x7c,0x29,0x7c, Step #5: (?:(?:?:$|z|$|\000|$|\021|$(?:$|z|$|\000|$|\021|$|z)|)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-efbb54b6e26a23e36927e49b9b56fc118094f02e Step #5: Base64: KD86KD86PzokfHp8JHwAfCR8EXwkKD86JHx6fCR8AHwkfBF8JHx6KXwpfCl8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3127 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3252763811 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5637e4d97810, 0x5637e4f8101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5637e4f81020,0x5637e6e190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/efbb54b6e26a23e36927e49b9b56fc118094f02e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3825 processed earlier; will process 7204 files now Step #5: ==112648== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5637db88c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5637e1ef1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5637e1ed45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5637e1ed44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5637db892d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5637db7f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5637db7ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5637db884c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5637de853f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5637de853f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5637de853f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5637de853f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5637de853f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5637de853f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5637de853f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5637de853f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5637de853f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5637de853f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5637e0ae8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5637dd815b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5637dd820be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5637dd5ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5637dd5ccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5637dd5cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5637dd5cc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5637dd5cc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5637dd5cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5637e1ed6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5637e1edf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5637e1ec7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5637e1ef2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf73646082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5637db7ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe4,0x8d,0xaa,0xef,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8c,0xaa,0xed,0x93,0xaa,0xed,0x8f,0xaa,0xed,0x89,0xaa,0xed,0x89,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa, Step #5: \344\215\252\357\215\252\355\215\252\355\215\252\355\214\252\355\223\252\355\217\252\355\211\252\355\211\252\355\215\252\355\215\252\355\215\252\355\215\252\355\215\252\355\215\252 Step #5: artifact_prefix='./'; Test unit written to ./oom-1d55827315b51cc7f659af4848c17f7ffa1e86cc Step #5: Base64: 5I2q742q7Y2q7Y2q7Yyq7ZOq7Y+q7Ymq7Ymq7Y2q7Y2q7Y2q7Y2q7Y2q7Y2q Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3128 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3253241044 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56296e12e810, 0x56296e31801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56296e318020,0x5629701b00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1d55827315b51cc7f659af4848c17f7ffa1e86cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3826 processed earlier; will process 7203 files now Step #5: ==112684== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562964c239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56296b288898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56296b26b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56296b26b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562964c29d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562964b8ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562964b85355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562964c1bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562967beaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562967beaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562967beaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562967beaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562967beaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562967beaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562967beaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562967beaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562967beaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562967beaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562969e7ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562966bacb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562966bb7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562966963c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562966963c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562966964738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562966963874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562966963874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562966963874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56296b26dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56296b276928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56296b25e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56296b289112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0a42fbc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562964b83b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7,0x2e,0x31,0xd,0x24,0xa,0x2e,0x7b,0xd,0x1,0xa,0x2e,0x7b,0xd,0x2d,0xa,0x2e,0x7b,0xd,0x3,0xa,0x2e,0x7b,0xd,0x2d,0xa,0x2e,0x63,0xd,0x2a,0xa,0x2e,0x42,0xd,0x24,0xa,0x2e,0x73,0x9,0x69,0xde,0xad,0xbe,0xef,0xef, Step #5: \007.1\015$\012.{\015\001\012.{\015-\012.{\015\003\012.{\015-\012.c\015*\012.B\015$\012.s\011i\336\255\276\357\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-0e7372d4a2fd5c8253bcfeafcb4c451c8ce5e021 Step #5: Base64: By4xDSQKLnsNAQouew0tCi57DQMKLnsNLQouYw0qCi5CDSQKLnMJad6tvu/v Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3129 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3253730899 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ac69917810, 0x55ac69b0101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ac69b01020,0x55ac6b9990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0e7372d4a2fd5c8253bcfeafcb4c451c8ce5e021' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3827 processed earlier; will process 7202 files now Step #5: ==112720== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ac6040c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ac66a71898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ac66a545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ac66a544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ac60412d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ac60373b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ac6036e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ac60404c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ac633d3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ac633d3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ac633d3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ac633d3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ac633d3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ac633d3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ac633d3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ac633d3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ac633d3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ac633d3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ac65668f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ac62395b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ac623a0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ac6214cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ac6214cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ac6214d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ac6214c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ac6214c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ac6214c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ac66a56abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ac66a5f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ac66a47699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ac66a72112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6cb8812082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ac6036cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x24,0x75,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0x82,0x0,0x0,0x0,0x0,0x0,0x0,0xf3,0xa0,0x81,0x98,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe1,0xa0,0x8e,0x0,0x0,0x44,0x11,0x27,0x0,0x44,0x11,0x24, Step #5: \000$u\000\000\000\000\000\342\200\202\000\000\000\000\000\000\363\240\201\230\000\000\000\000\000\000\000\000\000\000\000\000\341\240\216\000\000D\021'\000D\021$ Step #5: artifact_prefix='./'; Test unit written to ./oom-23b0774bf16442ac4d173ca42c706e757de51b7d Step #5: Base64: ACR1AAAAAADigIIAAAAAAADzoIGYAAAAAAAAAAAAAAAA4aCOAABEEScARBEk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3130 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3254211711 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c8d2f0810, 0x561c8d4da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c8d4da020,0x561c8f3720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/23b0774bf16442ac4d173ca42c706e757de51b7d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3828 processed earlier; will process 7201 files now Step #5: #1 pulse cov: 4418 ft: 4419 exec/s: 0 rss: 173Mb Step #5: ==112756== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561c83de59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c8a44a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c8a42d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c8a42d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c83debd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c83d4cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c83d47355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c83dddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c86dacf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c86dacf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c86dacf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c86dacf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c86dacf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c86dacf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c86dacf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c86dacf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c86dacf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c86dacf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c89041f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c85d6eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c85d79be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c85b25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c85b25c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c85b26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c85b25874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c85b25874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c85b25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c8a42fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c8a438928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c8a420699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c8a44b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa74f29c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c83d45b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0x90,0x2f,0xd9,0x8c,0xd9,0x98,0x20,0xd9,0x90,0x2f,0xd9,0x8c,0xd9,0x98,0x20,0xd9,0x90,0xd9,0x90,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text>\331\220/\331\214\331\230 \331\220/\331\214\331\230 \331\220\331\220'</text></svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-7fa7bb9ed2ad839704f083fb82b9a18e2d2842e4 Step #5: Base64: PHN2Zz48dGV4dD7ZkC/ZjNmYINmQL9mM2Zgg2ZDZkCc8L3RleHQ+PC9zdmc+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3131 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3254736432 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55986e272810, 0x55986e45c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55986e45c020,0x5598702f40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7fa7bb9ed2ad839704f083fb82b9a18e2d2842e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3830 processed earlier; will process 7199 files now Step #5: #1 pulse cov: 3686 ft: 3687 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 3991 ft: 4382 exec/s: 0 rss: 176Mb Step #5: ==112792== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559864d679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55986b3cc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55986b3af5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55986b3af4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559864d6dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559864cceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559864cc9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559864d5fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559867d2ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559867d2ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559867d2ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559867d2ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559867d2ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559867d2ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559867d2ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559867d2ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559867d2ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559867d2ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559869fc3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559866cf0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559866cfbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559866aa7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559866aa7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559866aa8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559866aa7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559866aa7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559866aa7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55986b3b1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55986b3ba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55986b3a2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55986b3cd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff85cdac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559864cc7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x76,0x21,0x39,0xa,0x0,0x7d,0x7d,0x7d,0x7d,0xd7,0xaf,0x69,0x66,0x7d,0xd7,0xaf,0x2d,0x0,0x7e,0x73,0x74,0x39,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0xd7,0xa3,0x1,0xd7,0xa3,0x2d,0x0, Step #5: #v!9\012\000}}}}\327\257if}\327\257-\000~st9>>>>>>>>>>>>>>>\327\243\001\327\243-\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c797fc8baea908074aef08d2d151923ad19bbaf2 Step #5: Base64: I3YhOQoAfX19fdevaWZ9168tAH5zdDk+Pj4+Pj4+Pj4+Pj4+Pj7XowHXoy0A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3132 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3255293702 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560995daf810, 0x560995f9901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560995f99020,0x560997e310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c797fc8baea908074aef08d2d151923ad19bbaf2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3833 processed earlier; will process 7196 files now Step #5: #1 pulse cov: 3448 ft: 3449 exec/s: 0 rss: 171Mb Step #5: ==112828== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56098c8a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560992f09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560992eec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560992eec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56098c8aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56098c80bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56098c806355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56098c89cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56098f86bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56098f86bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56098f86bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56098f86bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56098f86bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56098f86bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56098f86bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56098f86bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56098f86bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56098f86bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560991b00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56098e82db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56098e838be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56098e5e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56098e5e4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56098e5e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56098e5e4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56098e5e4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56098e5e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560992eeeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560992ef7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560992edf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560992f0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb29a6d8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56098c804b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x35,0x36,0x2d,0x24,0x32,0x35,0x24,0x36,0x2d,0x32,0x35,0x36,0x2d,0x24,0x32,0x35,0x36,0x2d,0x24,0x32,0x35,0x33,0x2d,0x24,0x36,0x2d,0x24,0x32,0x35,0x36,0x2d,0x24,0x32,0x24,0x32,0x35,0x37,0x2d,0x24,0x32,0x35,0x36,0x2d, Step #5: $256-$25$6-256-$256-$253-$6-$256-$2$257-$256- Step #5: artifact_prefix='./'; Test unit written to ./oom-f01375d754b84757cc349544bfe8809337d63dd7 Step #5: Base64: JDI1Ni0kMjUkNi0yNTYtJDI1Ni0kMjUzLSQ2LSQyNTYtJDIkMjU3LSQyNTYt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3133 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3255822590 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56397ab5d810, 0x56397ad4701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56397ad47020,0x56397cbdf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f01375d754b84757cc349544bfe8809337d63dd7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3835 processed earlier; will process 7194 files now Step #5: ==112864== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5639716529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563977cb7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563977c9a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563977c9a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563971658d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5639715b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5639715b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56397164ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563974619f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563974619f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563974619f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563974619f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563974619f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563974619f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563974619f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563974619f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563974619f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563974619f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5639768aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5639735dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5639735e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563973392c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563973392c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563973393738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563973392874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563973392874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563973392874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563977c9cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563977ca5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563977c8d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563977cb8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ccf2b7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5639715b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x6b, Step #5: \\k<3>\\k<3>\\k\\k<3>\\k<3>\\k<3>\\k<3>\\k<3>\\k<3>\\kk Step #5: artifact_prefix='./'; Test unit written to ./oom-890bb4812bdf2d38d88e1970dbf0f28b73b14d82 Step #5: Base64: XGs8Mz5cazwzPlxrXGs8Mz5cazwzPlxrPDM+XGs8Mz5cazwzPlxrPDM+XGtr Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3134 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3256305012 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5621e0d59810, 0x5621e0f4301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5621e0f43020,0x5621e2ddb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/890bb4812bdf2d38d88e1970dbf0f28b73b14d82' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3836 processed earlier; will process 7193 files now Step #5: ==112900== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5621d784e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5621ddeb3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5621dde965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5621dde964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5621d7854d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5621d77b5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5621d77b0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5621d7846c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5621da815f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5621da815f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5621da815f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5621da815f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5621da815f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5621da815f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5621da815f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5621da815f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5621da815f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5621da815f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5621dcaaaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5621d97d7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5621d97e2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5621d958ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5621d958ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5621d958f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5621d958e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5621d958e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5621d958e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5621dde98abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5621ddea1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5621dde89699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5621ddeb4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd2a5618082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5621d77aeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x65,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3d,0x22,0x49,0x53,0x4f,0x2d,0x38,0x38,0x35,0x39,0x2d,0x31,0x22,0x3f,0x3e,0x64,0x49,0x3d,0x22,0x67,0x53,0x4f,0x54,0x3e,0x3e,0x5b,0x53,0x56,0x3e,0x31,0x5d, Step #5: <?xml encoding=\"ISO-8859-1\"?>dI=\"gSOT>>[SV>1] Step #5: artifact_prefix='./'; Test unit written to ./oom-be33e7ec484fc5d77396c84237e528ad1521a8da Step #5: Base64: PD94bWwgZW5jb2Rpbmc9IklTTy04ODU5LTEiPz5kST0iZ1NPVD4+W1NWPjFd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3135 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3256782926 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb5f0fb810, 0x55eb5f2e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb5f2e5020,0x55eb6117d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/be33e7ec484fc5d77396c84237e528ad1521a8da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3837 processed earlier; will process 7192 files now Step #5: #1 pulse cov: 3714 ft: 3715 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 4074 ft: 4356 exec/s: 0 rss: 175Mb Step #5: ==112936== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eb55bf09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb5c255898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb5c2385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb5c2384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb55bf6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb55b57b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb55b52355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb55be8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb58bb7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb58bb7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb58bb7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb58bb7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb58bb7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb58bb7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb58bb7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb58bb7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb58bb7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb58bb7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb5ae4cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb57b79b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb57b84be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb57930c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb57930c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb57931738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb57930874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb57930874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb57930874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb5c23aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb5c243928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb5c22b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb5c256112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa56b630082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb55b50b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x54,0x68,0x69,0x73,0x20,0x66,0x69,0x6c,0x65,0x20,0x6d,0x75,0x48,0x69,0x72,0x61,0x67,0x69,0x6e,0x6f,0x20,0x4b,0x61,0x6b,0x75,0x67,0x6f,0x20,0x57,0x36,0x7a,0x74,0x68,0x20,0x42,0x69,0x6e,0x48,0x65,0x78,0x20,0xd0,0x34,0x2e, Step #5: (This file muHiragino Kakugo W6zth BinHex \3204. Step #5: artifact_prefix='./'; Test unit written to ./oom-90f7f0d948894eddd0b7c0c4c4ddbb03f70b754c Step #5: Base64: KFRoaXMgZmlsZSBtdUhpcmFnaW5vIEtha3VnbyBXNnp0aCBCaW5IZXgg0DQu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3136 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3257332127 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564de6eec810, 0x564de70d601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564de70d6020,0x564de8f6e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/90f7f0d948894eddd0b7c0c4c4ddbb03f70b754c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3840 processed earlier; will process 7189 files now Step #5: ==112972== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564ddd9e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564de4046898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564de40295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564de40294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ddd9e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ddd948b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ddd943355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ddd9d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564de09a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564de09a8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564de09a8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564de09a8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564de09a8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564de09a8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564de09a8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564de09a8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564de09a8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564de09a8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564de2c3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564ddf96ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564ddf975be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564ddf721c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564ddf721c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564ddf722738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564ddf721874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564ddf721874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564ddf721874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564de402babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564de4034928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564de401c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564de4047112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd20ed65082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ddd941b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x2d,0xcc,0xad,0x2e,0x2a,0xcc,0xb8,0x2e,0xc4,0xb0,0x2e,0x6a,0xcc,0xb8,0x2e,0x2a,0xcc,0xae,0x2e,0x33,0xcc,0xa6,0x2e,0x2b,0xcc,0xb8,0x2e,0x2a,0xcc,0x8e,0x2e,0x30,0xcc,0xb8,0x2e,0x2b,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8, Step #5: ws:-\314\255.*\314\270.\304\260.j\314\270.*\314\256.3\314\246.+\314\270.*\314\216.0\314\270.+\314\270.*\314\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-427957d6ae6c7af3e97a841a43b498b47e164133 Step #5: Base64: d3M6LcytLirMuC7EsC5qzLguKsyuLjPMpi4rzLguKsyOLjDMuC4rzLguKsy4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3137 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3257811172 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4f9c32810, 0x55e4f9e1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4f9e1c020,0x55e4fbcb40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/427957d6ae6c7af3e97a841a43b498b47e164133' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3841 processed earlier; will process 7188 files now Step #5: ==113008== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e4f07279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4f6d8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4f6d6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4f6d6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4f072dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4f068eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4f0689355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4f071fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4f36eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4f36eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4f36eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4f36eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4f36eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4f36eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4f36eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4f36eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4f36eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4f36eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4f5983f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4f26b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4f26bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4f2467c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4f2467c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4f2468738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4f2467874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4f2467874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4f2467874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4f6d71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4f6d7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4f6d62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4f6d8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd1cb28b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4f0687b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x29,0x6a,0x6f,0x62,0x73,0x3a,0xa,0x20,0x38,0x3a,0xa,0x20,0x20,0x73,0x74,0x65,0x70,0x73,0x3a,0xa,0x20,0x20,0x2d,0x20,0x77,0x6f,0x72,0x6b,0x69,0x6e,0x67,0x2d,0x64,0x69,0xcd,0x86,0x20,0x6f,0x32,0x74,0x36,0x3a, Step #5: \000\000\000)jobs:\012 8:\012 steps:\012 - working-di\315\206 o2t6: Step #5: artifact_prefix='./'; Test unit written to ./oom-62536ff287a91b6dec95b16753872b9bcb83c23c Step #5: Base64: AAAAKWpvYnM6CiA4OgogIHN0ZXBzOgogIC0gd29ya2luZy1kac2GIG8ydDY6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3138 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3258291001 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fefd100810, 0x55fefd2ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fefd2ea020,0x55feff1820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/62536ff287a91b6dec95b16753872b9bcb83c23c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3842 processed earlier; will process 7187 files now Step #5: ==113044== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fef3bf59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fefa25a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fefa23d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fefa23d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fef3bfbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fef3b5cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fef3b57355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fef3bedc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fef6bbcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fef6bbcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fef6bbcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fef6bbcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fef6bbcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fef6bbcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fef6bbcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fef6bbcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fef6bbcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fef6bbcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fef8e51f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fef5b7eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fef5b89be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fef5935c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fef5935c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fef5936738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fef5935874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fef5935874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fef5935874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fefa23fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fefa248928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fefa230699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fefa25b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c35815082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fef3b55b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x60,0xa,0xa,0x2f,0xa,0x2f,0xa,0x60,0x60,0x20,0x20,0x20,0x60,0xa,0x9, Step #5: `\342\200\210-\000`\012\363\240\201\272/\012`\342\200\210-\000`\012\363\240\201\272\363\240\201\272`\012\012/\012/\012`` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-d11d812dcfbdde17df890b6341a6166bf8b9fc9c Step #5: Base64: YOKAiC0AYArzoIG6Lwpg4oCILQBgCvOggbrzoIG6YAoKLwovCmBgICAgYAoJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3139 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3258888216 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56088cb72810, 0x56088cd5c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56088cd5c020,0x56088ebf40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d11d812dcfbdde17df890b6341a6166bf8b9fc9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3843 processed earlier; will process 7186 files now Step #5: ==113080== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5608836679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560889ccc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560889caf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560889caf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56088366dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5608835ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5608835c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56088365fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56088662ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56088662ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56088662ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56088662ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56088662ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56088662ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56088662ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56088662ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56088662ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56088662ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608888c3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5608855f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5608855fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5608853a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5608853a7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5608853a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5608853a7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5608853a7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5608853a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560889cb1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560889cba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560889ca2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560889ccd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5a646d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5608835c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x29,0x6a,0x6f,0x62,0x73,0x3a,0xa,0x20,0x58,0x3a,0xa,0x20,0x20,0x73,0x74,0x65,0x70,0x73,0x3a,0xa,0x20,0x20,0x2d,0x20,0x63,0x6f,0x6e,0x74,0x69,0x6e,0x75,0x65,0x2d,0xd8,0x99,0x2d,0x65,0x72,0x72,0x6f,0x72,0x3a, Step #5: \000\000\000)jobs:\012 X:\012 steps:\012 - continue-\330\231-error: Step #5: artifact_prefix='./'; Test unit written to ./oom-e95f683e5942699ac6a77f6e53b2f71010bda596 Step #5: Base64: AAAAKWpvYnM6CiBYOgogIHN0ZXBzOgogIC0gY29udGludWUt2JktZXJyb3I6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3140 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3259368059 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e003f5810, 0x562e005df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e005df020,0x562e024770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e95f683e5942699ac6a77f6e53b2f71010bda596' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3844 processed earlier; will process 7185 files now Step #5: ==113116== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562df6eea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562dfd54f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562dfd5325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562dfd5324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562df6ef0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562df6e51b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562df6e4c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562df6ee2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562df9eb1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562df9eb1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562df9eb1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562df9eb1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562df9eb1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562df9eb1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562df9eb1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562df9eb1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562df9eb1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562df9eb1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562dfc146f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562df8e73b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562df8e7ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562df8c2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562df8c2ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562df8c2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562df8c2a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562df8c2a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562df8c2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562dfd534abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562dfd53d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562dfd525699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562dfd550112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efe2234b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562df6e4ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x11,0xcc,0xb0,0x4e,0x6f,0x0,0x0,0xcc,0x9c,0x0,0x0,0x0,0x0,0xcc,0x9c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xcc,0x9c,0x0,0xcc,0x9c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xcc,0x9c,0x0,0xcc,0x9c,0x0,0xdb, Step #5: \000\000\021\314\260No\000\000\314\234\000\000\000\000\314\234\000\000\000\000\000\000\000\000\000\314\234\000\314\234\000\000\000\000\000\000\000\314\234\000\314\234\000\333 Step #5: artifact_prefix='./'; Test unit written to ./oom-291dd3baed467436619c04c8500954233592dfbb Step #5: Base64: AAARzLBObwAAzJwAAAAAzJwAAAAAAAAAAADMnADMnAAAAAAAAADMnADMnADb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3141 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3259842553 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562f6954a810, 0x562f6973401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562f69734020,0x562f6b5cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/291dd3baed467436619c04c8500954233592dfbb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3845 processed earlier; will process 7184 files now Step #5: ==113152== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562f6003f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562f666a4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562f666875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562f666874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562f60045d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562f5ffa6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562f5ffa1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562f60037c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562f63006f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562f63006f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562f63006f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562f63006f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562f63006f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562f63006f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562f63006f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562f63006f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562f63006f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562f63006f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562f6529bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562f61fc8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562f61fd3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562f61d7fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562f61d7fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562f61d80738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562f61d7f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562f61d7f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562f61d7f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562f66689abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562f66692928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562f6667a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562f666a5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5950faf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562f5ff9fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x43,0x46,0x46,0x20,0xa,0x3d,0x0,0x3b,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0, Step #5: ~=\012=\012=\012=\012=CFF \012=\000;\012=\012=\012=\012=\012=\012=\012=\012=\012\012==\012=\012=\012=\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aaaf6da81378d22a138dbdd99cfd802e61b2c7de Step #5: Base64: fj0KPQo9Cj0KPUNGRiAKPQA7Cj0KPQo9Cj0KPQo9Cj0KPQoKPT0KPQo9Cj0A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3142 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3260323846 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56245d3ac810, 0x56245d59601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56245d596020,0x56245f42e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aaaf6da81378d22a138dbdd99cfd802e61b2c7de' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3846 processed earlier; will process 7183 files now Step #5: #1 pulse cov: 3783 ft: 3784 exec/s: 0 rss: 171Mb Step #5: #2 pulse cov: 3961 ft: 4136 exec/s: 0 rss: 172Mb Step #5: ==113188== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562453ea19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56245a506898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56245a4e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56245a4e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562453ea7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562453e08b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562453e03355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562453e99c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562456e68f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562456e68f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562456e68f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562456e68f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562456e68f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562456e68f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562456e68f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562456e68f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562456e68f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562456e68f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5624590fdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562455e2ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562455e35be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562455be1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562455be1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562455be2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562455be1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562455be1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562455be1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56245a4ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56245a4f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56245a4dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56245a507112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8519f07082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562453e01b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0x61,0x0,0x70,0x43,0x6f,0x6e,0x74,0x45,0x6e,0x74,0x2d,0x54,0x79,0x70,0x65,0x3a,0x67,0x3b,0x63,0x2a,0x21,0x3d,0x71,0x3b,0x2a,0x66,0x3d,0x63,0x3b,0x6f,0x2a,0x21,0x3d,0x71,0x3b,0x64,0x2a,0x62,0x3d,0x63,0x31,0x79,0x2a,0x21, Step #5: ?a\000pContEnt-Type:g;c*!=q;*f=c;o*!=q;d*b=c1y*! Step #5: artifact_prefix='./'; Test unit written to ./oom-d611e039795f942da7d0f24436630b5f8b1a0d91 Step #5: Base64: P2EAcENvbnRFbnQtVHlwZTpnO2MqIT1xOypmPWM7byohPXE7ZCpiPWMxeSoh Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3143 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3260879004 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560253380810, 0x56025356a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56025356a020,0x5602554020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d611e039795f942da7d0f24436630b5f8b1a0d91' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3849 processed earlier; will process 7180 files now Step #5: ==113224== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560249e759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5602504da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602504bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602504bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560249e7bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560249ddcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560249dd7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560249e6dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56024ce3cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56024ce3cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56024ce3cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56024ce3cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56024ce3cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56024ce3cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56024ce3cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56024ce3cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56024ce3cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56024ce3cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56024f0d1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56024bdfeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56024be09be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56024bbb5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56024bbb5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56024bbb6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56024bbb5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56024bbb5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56024bbb5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5602504bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5602504c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5602504b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5602504db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4957c89082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560249dd5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2d,0xa,0x2d,0xa,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2d,0x9,0x0,0x0,0x0,0xa,0x2d,0xf3, Step #5: --\012-\012-\012-\012-\012-\012-\012 \000\000\000\000\000\000\000\012-\012-\012 \000\000\000\000\000\000\000\012-\011\000\000\000\012-\363 Step #5: artifact_prefix='./'; Test unit written to ./oom-bc9be194cd09cbc4a2a842e4f228d1b3b65f3b90 Step #5: Base64: LS0KLQotCi0KLQotCi0KIAAAAAAAAAAKLQotCiAAAAAAAAAACi0JAAAACi3z Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3144 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3261371173 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55668a6f2810, 0x55668a8dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55668a8dc020,0x55668c7740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bc9be194cd09cbc4a2a842e4f228d1b3b65f3b90' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3850 processed earlier; will process 7179 files now Step #5: ==113260== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5566811e79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55668784c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55668782f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55668782f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5566811edd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55668114eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556681149355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5566811dfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5566841aef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5566841aef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5566841aef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5566841aef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5566841aef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5566841aef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5566841aef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5566841aef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5566841aef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5566841aef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556686443f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556683170b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55668317bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556682f27c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556682f27c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556682f28738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556682f27874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556682f27874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556682f27874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556687831abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55668783a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556687822699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55668784d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d235c9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556681147b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x60,0x60,0x6d,0x2f,0x2a,0x60,0x60,0x60,0x3b,0x60,0x3b,0x60,0x3b,0x60,0x3b,0x60,0x3b,0x60,0x3b,0x60,0x3b,0x60,0x3b,0x60,0x3b,0x60,0x3b,0x60,0x3b,0x60,0x3b,0x60,0x3b,0x60,0x3b,0x60,0x3b,0x60,0x3a,0x60,0x3b,0x60,0x3b,0x60, Step #5: ```m/*```;`;`;`;`;`;`;`;`;`;`;`;`;`;`;`:`;`;` Step #5: artifact_prefix='./'; Test unit written to ./oom-c13dea03f5bd56cc6742d3fa4302466cab557346 Step #5: Base64: YGBgbS8qYGBgO2A7YDtgO2A7YDtgO2A7YDtgO2A7YDtgO2A7YDtgOmA7YDtg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3145 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3262262075 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ac1e922810, 0x55ac1eb0c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ac1eb0c020,0x55ac209a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c13dea03f5bd56cc6742d3fa4302466cab557346' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3851 processed earlier; will process 7178 files now Step #5: ==113296== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ac154179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ac1ba7c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ac1ba5f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ac1ba5f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ac1541dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ac1537eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ac15379355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ac1540fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ac183def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ac183def10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ac183def10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ac183def10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ac183def10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ac183def10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ac183def10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ac183def10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ac183def10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ac183def10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ac1a673f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ac173a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ac173abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ac17157c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ac17157c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ac17158738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ac17157874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ac17157874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ac17157874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ac1ba61abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ac1ba6a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ac1ba52699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ac1ba7d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4510865082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ac15377b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x52,0x41,0x51,0x51,0x66,0x69,0x64,0x3d,0x42,0x42,0xa,0x3d,0x20,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x24,0x0,0x0,0x0,0x20,0x0,0x0,0x60,0x60,0x2a,0x2a,0x5b,0x5b,0x5b,0x6f,0x40,0x43,0xa,0x5b,0x5b,0x24, Step #5: rRAQQfid=BB\012= **********$\000\000\000 \000\000``**[[[o@C\012[[$ Step #5: artifact_prefix='./'; Test unit written to ./oom-8c500a5fa08a7f6b42e03fcfc9ff20844e7005f8 Step #5: Base64: clJBUVFmaWQ9QkIKPSAqKioqKioqKioqJAAAACAAAGBgKipbW1tvQEMKW1sk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3146 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3262747776 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d938568810, 0x55d93875201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d938752020,0x55d93a5ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c500a5fa08a7f6b42e03fcfc9ff20844e7005f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3852 processed earlier; will process 7177 files now Step #5: ==113332== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d92f05d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d9356c2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d9356a55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d9356a54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d92f063d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d92efc4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d92efbf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d92f055c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d932024f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d932024f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d932024f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d932024f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d932024f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d932024f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d932024f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d932024f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d932024f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d932024f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d9342b9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d930fe6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d930ff1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d930d9dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d930d9dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d930d9e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d930d9d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d930d9d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d930d9d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d9356a7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d9356b0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d935698699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d9356c3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f38e9bdb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d92efbdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x29,0x73,0x3a,0x20,0x21,0xd,0x2d,0x20,0x34,0xa,0x2d,0x20,0x6f,0x21,0xa,0x2d,0x20,0x6f,0x20,0x6f,0xa,0x2d,0x20,0x6f,0xa,0x2d,0x20,0x6f,0xa,0x2d,0x20,0x6f,0xa,0x2d,0x20,0x6f,0xa,0x2d,0x20,0x20,0x2d,0x3f, Step #5: \000\000\000)s: !\015- 4\012- o!\012- o o\012- o\012- o\012- o\012- o\012- -? Step #5: artifact_prefix='./'; Test unit written to ./oom-2498c0a6f50f0818b799a1fbde34f4240cb28a4f Step #5: Base64: AAAAKXM6ICENLSA0Ci0gbyEKLSBvIG8KLSBvCi0gbwotIG8KLSBvCi0gIC0/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3147 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3263236872 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d257dc3810, 0x55d257fad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d257fad020,0x55d259e450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2498c0a6f50f0818b799a1fbde34f4240cb28a4f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3853 processed earlier; will process 7176 files now Step #5: ==113368== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d24e8b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d254f1d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d254f005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d254f004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d24e8bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d24e81fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d24e81a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d24e8b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d25187ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d25187ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d25187ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d25187ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d25187ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d25187ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d25187ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d25187ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d25187ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d25187ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d253b14f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d250841b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d25084cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d2505f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d2505f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d2505f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d2505f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d2505f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d2505f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d254f02abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d254f0b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d254ef3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d254f1e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa961804082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d24e818b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa0,0x8c,0x3d,0x0,0x0,0x0,0x2d,0x0,0x0,0x0,0x7f,0x20,0x7f,0x7f,0x0,0x0,0x3f,0xe2,0x80,0xac,0x0,0xe1,0x76,0x30,0x0,0xf3,0xa0,0x81,0xb8,0x0,0x28,0xd,0x0,0x72,0x64,0xe5,0x64,0xb5,0xf3,0xa0,0x81,0x87,0x64,0x64, Step #5: \341\240\214=\000\000\000-\000\000\000\177 \177\177\000\000?\342\200\254\000\341v0\000\363\240\201\270\000(\015\000rd\345d\265\363\240\201\207dd Step #5: artifact_prefix='./'; Test unit written to ./oom-7628ebb7a570478d96df67ef06f1461f1defcf18 Step #5: Base64: 4aCMPQAAAC0AAAB/IH9/AAA/4oCsAOF2MADzoIG4ACgNAHJk5WS186CBh2Rk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3148 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3263711568 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563466359810, 0x56346654301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563466543020,0x5634683db0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7628ebb7a570478d96df67ef06f1461f1defcf18' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3854 processed earlier; will process 7175 files now Step #5: ==113404== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56345ce4e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5634634b3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634634965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634634964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56345ce54d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56345cdb5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56345cdb0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56345ce46c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56345fe15f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56345fe15f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56345fe15f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56345fe15f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56345fe15f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56345fe15f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56345fe15f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56345fe15f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56345fe15f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56345fe15f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5634620aaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56345edd7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56345ede2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56345eb8ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56345eb8ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56345eb8f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56345eb8e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56345eb8e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56345eb8e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563463498abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5634634a1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563463489699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5634634b4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f66378d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56345cdaeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x28,0x28,0x28,0x3c,0x28,0x2e,0x0,0x5e,0x4,0x2e,0x4,0x2b,0x24,0x24,0x5e,0x0,0x2e,0x1,0x7d,0x2b,0x7c,0x29,0x7b,0x32,0x7d,0x5,0x29,0x7b,0x32,0x7d,0x5,0x7c,0x29,0x7b,0x34,0x7d,0x29,0x7b,0x35,0x7d,0x29,0x7b,0x33,0x7d, Step #5: ((((<(.\000^\004.\004+$$^\000.\001}+|){2}\005){2}\005|){4}){5}){3} Step #5: artifact_prefix='./'; Test unit written to ./oom-5702f226719dd6431cd5c572e0a098c9d02c2fdd Step #5: Base64: KCgoKDwoLgBeBC4EKyQkXgAuAX0rfCl7Mn0FKXsyfQV8KXs0fSl7NX0pezN9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3149 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3264192285 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0dd606810, 0x55a0dd7f001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0dd7f0020,0x55a0df6880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5702f226719dd6431cd5c572e0a098c9d02c2fdd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3855 processed earlier; will process 7174 files now Step #5: #1 pulse cov: 3743 ft: 3744 exec/s: 0 rss: 171Mb Step #5: ==113440== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0d40fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0da760898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0da7435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0da7434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0d4101d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0d4062b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0d405d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0d40f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0d70c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0d70c2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0d70c2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0d70c2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0d70c2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0d70c2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0d70c2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0d70c2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0d70c2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0d70c2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0d9357f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0d6084b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0d608fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0d5e3bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0d5e3bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0d5e3c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0d5e3b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0d5e3b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0d5e3b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0da745abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0da74e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0da736699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0da761112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fad0546d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0d405bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x9,0x9,0x0,0x0,0x0,0x9,0xa,0x9,0x3d,0xa,0x3d,0x49,0x2b,0xa,0x9,0x9,0x0,0x0,0x0,0x9,0xa,0x9,0x3d,0xa,0x3d,0x49,0x0,0x3b,0x27,0x2d,0x2d,0x2b,0x7e,0xeb,0x7e,0x0,0x3b,0x27,0x2d,0x2d,0x2b,0x7e,0xeb,0x7e, Step #5: +\012\011\011\000\000\000\011\012\011=\012=I+\012\011\011\000\000\000\011\012\011=\012=I\000;'--+~\353~\000;'--+~\353~ Step #5: artifact_prefix='./'; Test unit written to ./oom-f2a62ba7880a47828abd050a9827198aeb8b8092 Step #5: Base64: KwoJCQAAAAkKCT0KPUkrCgkJAAAACQoJPQo9SQA7Jy0tK37rfgA7Jy0tK37rfg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3150 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3264720558 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7a92f2810, 0x55f7a94dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7a94dc020,0x55f7ab3740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f2a62ba7880a47828abd050a9827198aeb8b8092' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3857 processed earlier; will process 7172 files now Step #5: ==113476== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f79fde79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7a644c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7a642f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7a642f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f79fdedd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f79fd4eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f79fd49355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f79fddfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7a2daef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7a2daef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7a2daef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7a2daef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7a2daef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7a2daef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7a2daef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7a2daef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7a2daef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7a2daef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7a5043f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f7a1d70b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f7a1d7bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f7a1b27c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f7a1b27c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f7a1b28738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f7a1b27874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f7a1b27874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f7a1b27874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7a6431abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7a643a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7a6422699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7a644d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa4ef1ab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f79fd47b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x69,0x66,0x31,0x21,0x69,0x66,0x31,0x29,0x30,0x29,0x29,0x29,0xd7,0xa9,0x28,0x30,0x9,0x37,0x29,0x29,0x30,0x9,0x37,0x29,0x29,0x74,0x29,0x30,0x29,0x29,0x29,0xd7,0xa9,0x28,0x30,0x9,0x37,0x29,0x29,0x30,0x9,0x37,0x29,0x29,0x74, Step #5: !if1!if1)0)))\327\251(0\0117))0\0117))t)0)))\327\251(0\0117))0\0117))t Step #5: artifact_prefix='./'; Test unit written to ./oom-e70dd44a1431e840eccd3a0ef4d2d03e379dcd0a Step #5: Base64: IWlmMSFpZjEpMCkpKdepKDAJNykpMAk3KSl0KTApKSnXqSgwCTcpKTAJNykpdA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3151 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3265205224 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fd5ebdb810, 0x55fd5edc501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fd5edc5020,0x55fd60c5d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e70dd44a1431e840eccd3a0ef4d2d03e379dcd0a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3858 processed earlier; will process 7171 files now Step #5: ==113512== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fd556d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fd5bd35898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fd5bd185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fd5bd184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fd556d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fd55637b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fd55632355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fd556c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fd58697f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fd58697f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fd58697f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fd58697f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fd58697f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fd58697f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fd58697f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fd58697f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fd58697f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fd58697f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fd5a92cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fd57659b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fd57664be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fd57410c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fd57410c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fd57411738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fd57410874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fd57410874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fd57410874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fd5bd1aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fd5bd23928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fd5bd0b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fd5bd36112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e704d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fd55630b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0x32,0x31,0x34,0x37,0x34,0x38,0x25,0x36,0x5b,0x35,0x30,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3f,0x0,0x8,0x0,0x0,0x0,0x2d,0x32, Step #5: \333\200214748%6[50\000\000\000\000\000\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000?\000\010\000\000\000-2 Step #5: artifact_prefix='./'; Test unit written to ./oom-bd8f3dbd6210a216c5c5c94007eeb2e6dce0069e Step #5: Base64: 24AyMTQ3NDglNls1MAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAA/AAgAAAAtMg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3152 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3265684247 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55671ca57810, 0x55671cc4101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55671cc41020,0x55671ead90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bd8f3dbd6210a216c5c5c94007eeb2e6dce0069e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3859 processed earlier; will process 7170 files now Step #5: #1 pulse cov: 3613 ft: 3614 exec/s: 0 rss: 174Mb Step #5: ==113548== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55671354c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556719bb1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556719b945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556719b944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556713552d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5567134b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5567134ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556713544c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556716513f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556716513f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556716513f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556716513f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556716513f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556716513f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556716513f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556716513f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556716513f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556716513f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5567187a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5567154d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5567154e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55671528cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55671528cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55671528d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55671528c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55671528c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55671528c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556719b96abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556719b9f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556719b87699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556719bb2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f920cbd6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5567134acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x21,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x73,0x6c,0x73,0x41,0x2e,0x24,0x65,0x76,0x2f,0x78,0x72,0x6f,0x76,0x65,0x6e,0x6b,0x6e,0x63,0x65,0x2f,0x76,0x30,0x2e,0x30,0xef,0xf3,0xbf,0xbf,0xa0,0x81,0x30,0x22,0x22,0x41, Step #5: \000\000\000!https://slsA.$ev/xrovenknce/v0.0\357\363\277\277\240\2010\"\"A Step #5: artifact_prefix='./'; Test unit written to ./oom-5f68cc2dc026efa0b5941dfd616d900a7bcca84c Step #5: Base64: AAAAIWh0dHBzOi8vc2xzQS4kZXYveHJvdmVua25jZS92MC4w7/O/v6CBMCIiQQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3153 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3266206278 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557df791e810, 0x557df7b0801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557df7b08020,0x557df99a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f68cc2dc026efa0b5941dfd616d900a7bcca84c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3861 processed earlier; will process 7168 files now Step #5: ==113584== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557dee4139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557df4a78898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557df4a5b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557df4a5b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557dee419d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557dee37ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557dee375355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557dee40bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557df13daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557df13daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557df13daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557df13daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557df13daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557df13daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557df13daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557df13daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557df13daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557df13daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557df366ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557df039cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557df03a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557df0153c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557df0153c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557df0154738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557df0153874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557df0153874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557df0153874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557df4a5dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557df4a66928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557df4a4e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557df4a79112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fab890f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557dee373b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x2d,0x3d,0x3c,0x27,0x27,0x6f,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0xf3,0xa0,0x81,0xa5,0x32,0x2d,0x27,0x27,0x21,0x27,0x27,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $22-=<''o/''''/''''''\363\240\201\2452-''!''=''''''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-11ef5f71d2a7062f0095011aad8eee69fac87130 Step #5: Base64: JDIyLT08JydvLycnJycvJycnJycn86CBpTItJychJyc9JycnJycnJycuJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3154 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3266695797 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f8c4237810, 0x55f8c442101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f8c4421020,0x55f8c62b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/11ef5f71d2a7062f0095011aad8eee69fac87130' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3862 processed earlier; will process 7167 files now Step #5: ==113620== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8bad2c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f8c1391898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8c13745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8c13744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8bad32d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8bac93b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8bac8e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8bad24c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8bdcf3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8bdcf3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8bdcf3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8bdcf3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8bdcf3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8bdcf3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8bdcf3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8bdcf3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8bdcf3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8bdcf3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f8bff88f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f8bccb5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f8bccc0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8bca6cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8bca6cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8bca6d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8bca6c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8bca6c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8bca6c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f8c1376abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f8c137f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f8c1367699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f8c1392112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb4fc59a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8bac8cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd6,0xae,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x0,0x4f,0x0,0x96,0xc8, Step #5: \326\256\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\000O\000\226\310 Step #5: artifact_prefix='./'; Test unit written to ./oom-d15c48420ff061f2f3deba31402f396eb7a1b6af Step #5: Base64: 1q4AAAAAAAAAAAAAAAAAAAAAACIiIiIiIiIiIiIiIiIiIiIiIiIiIiIATwCWyA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3155 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3267169725 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0958db810, 0x55b095ac501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b095ac5020,0x55b09795d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d15c48420ff061f2f3deba31402f396eb7a1b6af' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3863 processed earlier; will process 7166 files now Step #5: ==113656== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b08c3d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b092a35898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b092a185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b092a184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b08c3d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b08c337b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b08c332355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b08c3c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b08f397f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b08f397f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b08f397f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b08f397f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b08f397f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b08f397f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b08f397f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b08f397f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b08f397f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b08f397f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b09162cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b08e359b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b08e364be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b08e110c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b08e110c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b08e111738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b08e110874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b08e110874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b08e110874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b092a1aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b092a23928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b092a0b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b092a36112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a59367082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b08c330b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x46,0x46,0x46,0x30,0x30,0x30,0x30,0x2d,0x30,0x46,0x35,0x30,0x50,0x46,0x2d,0x30,0x46,0x32,0x46,0x30,0x32,0x43,0x2d,0x2d,0x31,0x2d,0x2d,0x30,0x30,0x31,0x34,0x36,0x33,0x35,0x2d,0x35,0x2d,0x2d,0x2d,0x30,0x31,0x34,0x36,0x32,0x2d, Step #5: FFFF0000-0F50PF-0F2F02C--1--0014635-5---01462- Step #5: artifact_prefix='./'; Test unit written to ./oom-833e787237acd60b5efa9ae5b5f4235ff98ebc16 Step #5: Base64: RkZGRjAwMDAtMEY1MFBGLTBGMkYwMkMtLTEtLTAwMTQ2MzUtNS0tLTAxNDYyLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3156 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3267644857 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cdb2701810, 0x55cdb28eb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cdb28eb020,0x55cdb47830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/833e787237acd60b5efa9ae5b5f4235ff98ebc16' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3864 processed earlier; will process 7165 files now Step #5: #1 pulse cov: 3788 ft: 3789 exec/s: 0 rss: 173Mb Step #5: ==113692== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cda91f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cdaf85b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cdaf83e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cdaf83e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cda91fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cda915db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cda9158355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cda91eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cdac1bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cdac1bdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cdac1bdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cdac1bdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cdac1bdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cdac1bdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cdac1bdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cdac1bdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cdac1bdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cdac1bdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cdae452f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cdab17fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cdab18abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cdaaf36c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cdaaf36c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cdaaf37738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cdaaf36874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cdaaf36874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cdaaf36874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cdaf840abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cdaf849928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cdaf831699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cdaf85c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53ca410082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cda9156b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0, Step #5: \000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4f479e533cc5ea705aa287a79fb1d84652738739 Step #5: Base64: AEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3157 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3268173212 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c645b6810, 0x562c647a001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c647a0020,0x562c666380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f479e533cc5ea705aa287a79fb1d84652738739' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3866 processed earlier; will process 7163 files now Step #5: ==113728== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562c5b0ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c61710898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c616f35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c616f34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c5b0b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c5b012b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c5b00d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c5b0a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c5e072f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c5e072f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c5e072f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c5e072f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c5e072f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c5e072f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c5e072f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c5e072f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c5e072f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c5e072f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c60307f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562c5d034b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562c5d03fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562c5cdebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562c5cdebc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562c5cdec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562c5cdeb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562c5cdeb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562c5cdeb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c616f5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c616fe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c616e6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c61711112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd5fa80b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c5b00bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27, Step #5: ''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[' Step #5: artifact_prefix='./'; Test unit written to ./oom-675b346cebada086f96e2b5186bc031b717d1bbd Step #5: Base64: JydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3158 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3268649540 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bcd59cd810, 0x55bcd5bb701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bcd5bb7020,0x55bcd7a4f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/675b346cebada086f96e2b5186bc031b717d1bbd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3867 processed earlier; will process 7162 files now Step #5: ==113764== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bccc4c29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bcd2b27898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bcd2b0a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bcd2b0a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bccc4c8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bccc429b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bccc424355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bccc4bac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bccf489f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bccf489f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bccf489f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bccf489f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bccf489f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bccf489f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bccf489f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bccf489f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bccf489f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bccf489f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bcd171ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bcce44bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bcce456be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bcce202c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bcce202c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bcce203738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bcce202874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bcce202874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bcce202874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bcd2b0cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bcd2b15928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bcd2afd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bcd2b28112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d9db0b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bccc422b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x0,0x6e,0x0,0x43,0x43,0x0,0x0,0x0,0x0,0x0,0x0,0xe0,0xb8,0x84,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xf3,0xa0,0x81,0x8f,0x0,0x7a,0x0,0x43,0x31, Step #5: D\000n\000CC\000\000\000\000\000\000\340\270\204\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\363\240\201\217\000z\000C1 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf27f17ff5f0afca08db8d435a44ee4d8ef7c666 Step #5: Base64: RABuAENDAAAAAAAA4LiEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPOggY8AegBDMQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3159 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3269129599 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d013a89810, 0x55d013c7301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d013c73020,0x55d015b0b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf27f17ff5f0afca08db8d435a44ee4d8ef7c666' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3868 processed earlier; will process 7161 files now Step #5: #1 pulse cov: 3908 ft: 3909 exec/s: 0 rss: 174Mb Step #5: ==113800== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d00a57e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d010be3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d010bc65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d010bc64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d00a584d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d00a4e5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d00a4e0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d00a576c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d00d545f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d00d545f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d00d545f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d00d545f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d00d545f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d00d545f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d00d545f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d00d545f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d00d545f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d00d545f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d00f7daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d00c507b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d00c512be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d00c2bec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d00c2bec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d00c2bf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d00c2be874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d00c2be874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d00c2be874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d010bc8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d010bd1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d010bb9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d010be4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f77785bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d00a4deb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x24,0x24,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x36,0x55, Step #5: DanM$$340282366920938463463374607431768211456U Step #5: artifact_prefix='./'; Test unit written to ./oom-67b67f051c78a3c5a22abf64ed0745a00f879020 Step #5: Base64: RGFuTSQkMzQwMjgyMzY2OTIwOTM4NDYzNDYzMzc0NjA3NDMxNzY4MjExNDU2VQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3160 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3269650132 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560c04efc810, 0x560c050e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560c050e6020,0x560c06f7e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/67b67f051c78a3c5a22abf64ed0745a00f879020' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3870 processed earlier; will process 7159 files now Step #5: ==113836== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560bfb9f19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560c02056898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560c020395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560c020394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560bfb9f7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560bfb958b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560bfb953355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560bfb9e9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560bfe9b8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560bfe9b8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560bfe9b8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560bfe9b8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560bfe9b8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560bfe9b8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560bfe9b8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560bfe9b8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560bfe9b8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560bfe9b8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560c00c4df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560bfd97ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560bfd985be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560bfd731c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560bfd731c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560bfd732738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560bfd731874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560bfd731874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560bfd731874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560c0203babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560c02044928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560c0202c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560c02057112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe9960ef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560bfb951b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x3f,0x1a,0xa,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56, Step #5: -?\032\012VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV Step #5: artifact_prefix='./'; Test unit written to ./oom-1537c861bc34f15fa3283cf101f0fc15da901f9c Step #5: Base64: LT8aClZWVlZWVlZWVlZWVlZWVlZWVlZWVlZWVlZWVlZWVlZWVlZWVlZWVlZWVg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3161 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3270128594 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d0c928810, 0x564d0cb1201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d0cb12020,0x564d0e9aa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1537c861bc34f15fa3283cf101f0fc15da901f9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3871 processed earlier; will process 7158 files now Step #5: ==113872== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d0341d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d09a82898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d09a655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d09a654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d03423d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d03384b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d0337f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d03415c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d063e4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d063e4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d063e4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d063e4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d063e4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d063e4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d063e4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d063e4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d063e4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d063e4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d08679f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d053a6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d053b1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d0515dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d0515dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d0515e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d0515d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d0515d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d0515d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d09a67abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d09a70928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d09a58699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d09a83112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8af5216082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d0337db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd3,0x81,0xe6,0x8d,0x8b,0x0,0x6b,0x1,0xd3,0x81,0xe6,0x8d,0x8b,0x0,0x6b,0x1,0x0,0xd3,0x81,0xe6,0x8d,0x8b,0x53,0x6b,0x0,0xe6,0x8d,0x8b,0x5b,0x7e,0x17,0x0,0xd3,0x81,0xe6,0x8d,0x8b,0x53,0x6b,0x0,0xe6,0x8d,0x8b,0x5b,0x7e,0x17, Step #5: \323\201\346\215\213\000k\001\323\201\346\215\213\000k\001\000\323\201\346\215\213Sk\000\346\215\213[~\027\000\323\201\346\215\213Sk\000\346\215\213[~\027 Step #5: artifact_prefix='./'; Test unit written to ./oom-268c1f63c91e5bf9eb504b5372e13fffc56d28db Step #5: Base64: 04HmjYsAawHTgeaNiwBrAQDTgeaNi1NrAOaNi1t+FwDTgeaNi1NrAOaNi1t+Fw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3162 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3270612903 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556ba30bb810, 0x556ba32a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556ba32a5020,0x556ba513d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/268c1f63c91e5bf9eb504b5372e13fffc56d28db' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3872 processed earlier; will process 7157 files now Step #5: ==113908== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556b99bb09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556ba0215898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556ba01f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556ba01f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b99bb6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b99b17b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b99b12355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b99ba8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b9cb77f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b9cb77f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b9cb77f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b9cb77f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b9cb77f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b9cb77f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b9cb77f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b9cb77f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b9cb77f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b9cb77f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b9ee0cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b9bb39b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b9bb44be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b9b8f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b9b8f0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b9b8f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b9b8f0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b9b8f0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b9b8f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556ba01faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556ba0203928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556ba01eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556ba0216112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcd0258a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b99b10b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x73,0x20,0x37,0x20,0x30,0x20,0x37,0x20,0x30,0x20,0x32,0x10,0x20,0x32,0x7f,0x7f,0x6f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x24, Step #5: $\177]2.23/\020./s 7 0 7 0 2\020 2\177\177o\177\177\177\177\177\177\177\177\177\177\177\177\177o\000\000C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-5b9fef0a634d020dc49dbcdbaa993f53315a784d Step #5: Base64: JH9dMi4yMy8QLi9zIDcgMCA3IDAgMhAgMn9/b39/f39/f39/f39/f39vAABDJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3163 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3271092789 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5608581e5810, 0x5608583cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5608583cf020,0x56085a2670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5b9fef0a634d020dc49dbcdbaa993f53315a784d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3873 processed earlier; will process 7156 files now Step #5: #1 pulse cov: 10949 ft: 10950 exec/s: 0 rss: 189Mb Step #5: ==113944== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56084ecda9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56085533f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608553225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608553224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56084ece0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56084ec41b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56084ec3c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56084ecd2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560851ca1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560851ca1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560851ca1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560851ca1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560851ca1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560851ca1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560851ca1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560851ca1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560851ca1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560851ca1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560853f36f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560850c63b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560850c6ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560850a1ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560850a1ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560850a1b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560850a1a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560850a1a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560850a1a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560855324abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56085532d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560855315699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560855340112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb782699082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56084ec3ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4a,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0xe9,0x85,0x9f,0x47,0x45,0xe1,0x85,0x9f,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x20,0x2d,0x2d,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x47,0x64,0xa,0x2d,0xa,0xf3,0xa0,0x81,0xb3,0x66, Step #5: J-----BE\351\205\237GE\341\205\237GIN -- --\005---------\012Gd\012-\012\363\240\201\263f Step #5: artifact_prefix='./'; Test unit written to ./oom-738a137f71c9b452586a50a6ad1ad31d5e3c7986 Step #5: Base64: Si0tLS0tQkXphZ9HReGFn0dJTiAtLSAtLQUtLS0tLS0tLS0KR2QKLQrzoIGzZg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3164 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3271637592 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563dcaf54810, 0x563dcb13e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563dcb13e020,0x563dccfd60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/738a137f71c9b452586a50a6ad1ad31d5e3c7986' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3875 processed earlier; will process 7154 files now Step #5: #1 pulse cov: 3976 ft: 3977 exec/s: 0 rss: 171Mb Step #5: ==113980== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563dc1a499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563dc80ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563dc80915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563dc80914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563dc1a4fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563dc19b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563dc19ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563dc1a41c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563dc4a10f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563dc4a10f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563dc4a10f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563dc4a10f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563dc4a10f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563dc4a10f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563dc4a10f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563dc4a10f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563dc4a10f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563dc4a10f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563dc6ca5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563dc39d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563dc39ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563dc3789c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563dc3789c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563dc378a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563dc3789874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563dc3789874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563dc3789874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563dc8093abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563dc809c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563dc8084699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563dc80af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4520c7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563dc19a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0xa,0x3a,0xb,0x3a,0xb,0x78,0x2e,0xa,0xe,0x6e,0x78,0xa,0x2e,0xa,0x22,0x74,0x78,0x6e,0x62,0x60,0x66,0x2e,0xd,0x60,0x66,0x78,0x2e,0xa,0xe,0x6e,0x78,0xa,0x2e,0xa,0x22,0x74,0x78,0x6e,0x62,0x60,0x66,0xa,0xd,0x60,0x66, Step #5: 2\012:\013:\013x.\012\016nx\012.\012\"txnb`f.\015`fx.\012\016nx\012.\012\"txnb`f\012\015`f Step #5: artifact_prefix='./'; Test unit written to ./oom-4bbfc1295b1cfd57bb13edbeb81295ab1407215c Step #5: Base64: Mgo6CzoLeC4KDm54Ci4KInR4bmJgZi4NYGZ4LgoObngKLgoidHhuYmBmCg1gZg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3165 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3272281829 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d53f23810, 0x557d5410d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d5410d020,0x557d55fa50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4bbfc1295b1cfd57bb13edbeb81295ab1407215c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3877 processed earlier; will process 7152 files now Step #5: #1 pulse cov: 3953 ft: 3954 exec/s: 0 rss: 172Mb Step #5: ==114016== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557d4aa189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557d5107d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557d510605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557d510604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557d4aa1ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557d4a97fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557d4a97a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557d4aa10c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557d4d9dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557d4d9dff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557d4d9dff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557d4d9dff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557d4d9dff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557d4d9dff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557d4d9dff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557d4d9dff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557d4d9dff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557d4d9dff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557d4fc74f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557d4c9a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557d4c9acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557d4c758c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557d4c758c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557d4c759738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557d4c758874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557d4c758874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557d4c758874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557d51062abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557d5106b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557d51053699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557d5107e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5234e5d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557d4a978b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x29,0x3d,0x7e,0xd3,0xbf,0x32,0x3d,0x1,0x79,0x0,0x3d,0x29,0x7e,0x24,0x3d,0x3d,0x1,0x79,0x0,0x3d,0x29,0x7e,0x0,0x0,0x24,0x0,0x7e,0x0,0x0,0x0,0x24,0x0,0x7e,0x2d,0x3d,0x5,0x0,0x3a,0x3d,0x1,0x79,0x0,0x0,0x29,0x24, Step #5: ~)=~\323\2772=\001y\000=)~$==\001y\000=)~\000\000$\000~\000\000\000$\000~-=\005\000:=\001y\000\000)$ Step #5: artifact_prefix='./'; Test unit written to ./oom-b235196e693fe34feccefaf9bbc0ee5489defc93 Step #5: Base64: fik9ftO/Mj0BeQA9KX4kPT0BeQA9KX4AACQAfgAAACQAfi09BQA6PQF5AAApJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3166 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3272807101 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56131b907810, 0x56131baf101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56131baf1020,0x56131d9890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b235196e693fe34feccefaf9bbc0ee5489defc93' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3879 processed earlier; will process 7150 files now Step #5: ==114052== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5613123fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561318a61898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561318a445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561318a444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561312402d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561312363b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56131235e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5613123f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5613153c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5613153c3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5613153c3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5613153c3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5613153c3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5613153c3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5613153c3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5613153c3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5613153c3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5613153c3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561317658f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561314385b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561314390be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56131413cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56131413cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56131413d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56131413c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56131413c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56131413c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561318a46abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561318a4f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561318a37699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561318a62112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbf19254082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56131235cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x32,0x2e,0x32,0x33,0x35,0x10,0x2e,0x2f,0x73,0x20,0x37,0x20,0x30,0x20,0x32,0x10,0x20,0x32,0x10,0x2e,0x2f,0x2d,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x58,0x7e,0x7f,0x7f,0x7f,0x7f,0x6e,0x0,0x0,0x43,0x24, Step #5: $\177]2.235\020./s 7 0 2\020 2\020./-\177\177\177\177\177\177\177\177\177\177X~\177\177\177\177n\000\000C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-62ee1de0e9a6d02a9dbe5b5763a700298de1efa9 Step #5: Base64: JH9dMi4yMzUQLi9zIDcgMCAyECAyEC4vLX9/f39/f39/f39Yfn9/f39uAABDJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3167 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3273294159 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb9a441810, 0x55cb9a62b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb9a62b020,0x55cb9c4c30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/62ee1de0e9a6d02a9dbe5b5763a700298de1efa9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3880 processed earlier; will process 7149 files now Step #5: ==114088== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cb90f369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb9759b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb9757e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb9757e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb90f3cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb90e9db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb90e98355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb90f2ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb93efdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb93efdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb93efdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb93efdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb93efdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb93efdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb93efdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb93efdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb93efdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb93efdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb96192f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb92ebfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb92ecabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb92c76c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb92c76c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb92c77738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb92c76874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb92c76874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb92c76874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb97580abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb97589928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb97571699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb9759c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2eb9333082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb90e96b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x73,0x3a,0xe1,0xa0,0xb9,0xe2,0x80,0x8c,0xe1,0xa0,0xb9,0xe2,0x80,0x8c,0xe1,0x80,0xb9,0xe1,0xa0,0xb9,0xe2,0x80,0x8c,0xe1,0x80,0xb9,0xe1,0xa0,0xb9,0xe2,0x80,0x8c,0xe1,0xa0,0xb9,0xe2,0x80,0x8c,0xe1,0x80,0xbd,0xe1,0xa0,0xb9, Step #5: \016ws:\341\240\271\342\200\214\341\240\271\342\200\214\341\200\271\341\240\271\342\200\214\341\200\271\341\240\271\342\200\214\341\240\271\342\200\214\341\200\275\341\240\271 Step #5: artifact_prefix='./'; Test unit written to ./oom-92d20f720c2a33820c0c227fdc32b9ecdd599270 Step #5: Base64: DndzOuGgueKAjOGgueKAjOGAueGgueKAjOGAueGgueKAjOGgueKAjOGAveGguQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3168 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3273783240 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa2915c810, 0x55aa2934601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa29346020,0x55aa2b1de0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92d20f720c2a33820c0c227fdc32b9ecdd599270' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3881 processed earlier; will process 7148 files now Step #5: ==114124== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aa1fc519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa262b6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa262995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa262994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa1fc57d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa1fbb8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa1fbb3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa1fc49c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa22c18f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa22c18f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa22c18f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa22c18f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa22c18f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa22c18f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa22c18f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa22c18f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa22c18f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa22c18f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa24eadf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa21bdab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa21be5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa21991c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa21991c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa21992738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa21991874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa21991874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa21991874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa2629babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa262a4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa2628c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa262b7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3202ba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa1fbb1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x3a,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d, Step #5: t:\015- - - - - - - - - - - - - - - - - - - - - - Step #5: artifact_prefix='./'; Test unit written to ./oom-ee4166adb52f911d7ad5a7110479afabb0f11409 Step #5: Base64: dDoNLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAgLSAtIC0gLSAtIC0gLSAtIC0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3169 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3274304633 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610b4bb3810, 0x5610b4d9d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610b4d9d020,0x5610b6c350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee4166adb52f911d7ad5a7110479afabb0f11409' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3882 processed earlier; will process 7147 files now Step #5: ==114160== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5610ab6a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610b1d0d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610b1cf05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610b1cf04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610ab6aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610ab60fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610ab60a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610ab6a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610ae66ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610ae66ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610ae66ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610ae66ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610ae66ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610ae66ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610ae66ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610ae66ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610ae66ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610ae66ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610b0904f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610ad631b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610ad63cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610ad3e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610ad3e8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610ad3e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610ad3e8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610ad3e8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610ad3e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610b1cf2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610b1cfb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610b1ce3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610b1d0e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa373aa0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610ab608b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x2c,0x19,0x22,0xc4,0xb3,0xdf,0x93,0xdf,0xb3,0xdf,0xb3,0xdf,0xb3,0xdf,0xb2,0xdf,0xb3,0xdf,0xb3,0xdf,0xb3,0xdf,0xb3,0xdf,0xb2,0xdf,0xb3,0x62,0xdf,0xb3,0xdf,0xb3,0x26,0x4c,0x20,0x4d,0x20,0x4c,0x9d,0xb3,0xc4,0x78,0x78,0x28,0xdf, Step #5: HU,\031\"\304\263\337\223\337\263\337\263\337\263\337\262\337\263\337\263\337\263\337\263\337\262\337\263b\337\263\337\263&L M L\235\263\304xx(\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-1fde1a491a8bd4e7c738077db611e603ca33446b Step #5: Base64: SFUsGSLEs9+T37Pfs9+z37Lfs9+z37Pfs9+y37Ni37PfsyZMIE0gTJ2zxHh4KN8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3170 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3274790949 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bfc2e08810, 0x55bfc2ff201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bfc2ff2020,0x55bfc4e8a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1fde1a491a8bd4e7c738077db611e603ca33446b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3883 processed earlier; will process 7146 files now Step #5: ==114196== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bfb98fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bfbff62898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bfbff455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bfbff454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bfb9903d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bfb9864b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bfb985f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bfb98f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bfbc8c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bfbc8c4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bfbc8c4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bfbc8c4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bfbc8c4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bfbc8c4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bfbc8c4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bfbc8c4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bfbc8c4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bfbc8c4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bfbeb59f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bfbb886b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bfbb891be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bfbb63dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bfbb63dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bfbb63e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bfbb63d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bfbb63d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bfbb63d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bfbff47abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bfbff50928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bfbff38699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bfbff63112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe3cb2a1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bfb985db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x61,0x68,0x40,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0xa,0x0,0x0,0x0,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x2d,0x2e,0x2e,0xb0,0x2e,0x2e,0x2e,0x2e,0x2e,0x2d,0x64,0x40,0x64,0x40,0x31,0x2d, Step #5: ah@````````````\012\000\000\000````````````-..\260.....-d@d@1- Step #5: artifact_prefix='./'; Test unit written to ./oom-13367dd84c383aaf96382bce929ec34313d5805b Step #5: Base64: YWhAYGBgYGBgYGBgYGBgCgAAAGBgYGBgYGBgYGBgYC0uLrAuLi4uLi1kQGRAMS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3171 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3275404909 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed83a64810, 0x55ed83c4e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed83c4e020,0x55ed85ae60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/13367dd84c383aaf96382bce929ec34313d5805b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3884 processed earlier; will process 7145 files now Step #5: ==114232== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed7a5599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed80bbe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed80ba15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed80ba14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed7a55fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed7a4c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed7a4bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed7a551c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed7d520f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed7d520f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed7d520f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed7d520f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed7d520f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed7d520f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed7d520f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed7d520f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed7d520f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed7d520f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed7f7b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed7c4e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed7c4edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed7c299c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed7c299c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed7c29a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed7c299874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed7c299874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed7c299874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed80ba3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed80bac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed80b94699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed80bbf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6880c20082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed7a4b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x76,0x21,0x39,0xa,0x6e,0x75,0x73,0x20,0x73,0x65,0x72,0x69,0x66,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x7d,0xd7,0x93,0x93,0xd7,0x7d,0x0,0x0, Step #5: #v!9\012nus serifGGGGGGGGGGGGGGGGGGGGGGGGG}\327\223\223\327}\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0f0b1f1f6e29f5ed0c9a6e24a5b756e05a3481a2 Step #5: Base64: I3YhOQpudXMgc2VyaWZHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHfdeTk9d9AAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3172 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3275891638 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640e06ea810, 0x5640e08d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640e08d4020,0x5640e276c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0f0b1f1f6e29f5ed0c9a6e24a5b756e05a3481a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3885 processed earlier; will process 7144 files now Step #5: ==114268== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5640d71df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5640dd844898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640dd8275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640dd8274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5640d71e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5640d7146b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5640d7141355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5640d71d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5640da1a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5640da1a6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5640da1a6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5640da1a6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5640da1a6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5640da1a6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5640da1a6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5640da1a6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5640da1a6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5640da1a6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5640dc43bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5640d9168b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5640d9173be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5640d8f1fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5640d8f1fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5640d8f20738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5640d8f1f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5640d8f1f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5640d8f1f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5640dd829abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5640dd832928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5640dd81a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5640dd845112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9fb28de082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5640d713fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x55,0x54,0xb,0x31,0x20,0x48,0x54,0x54,0x50,0x2f,0x31,0x2e,0x30,0xa,0x43,0x6f,0x6e,0x74,0x65,0x6e,0x54,0x2d,0x54,0x79,0x70,0x65,0x3a,0x6d,0x75,0x6c,0x74,0x69,0x70,0x61,0x72,0x74,0x2f,0x66,0x6f,0x72,0x6d,0x0,0x2f,0x61,0x62,0x63, Step #5: PUT\0131 HTTP/1.0\012ContenT-Type:multipart/form\000/abc Step #5: artifact_prefix='./'; Test unit written to ./oom-7c39088dce375f13e41c6eb4a86f1c9218c50ff8 Step #5: Base64: UFVUCzEgSFRUUC8xLjAKQ29udGVuVC1UeXBlOm11bHRpcGFydC9mb3JtAC9hYmM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3173 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3276377697 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562740932810, 0x562740b1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562740b1c020,0x5627429b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7c39088dce375f13e41c6eb4a86f1c9218c50ff8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3886 processed earlier; will process 7143 files now Step #5: ==114304== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5627374279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56273da8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56273da6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56273da6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56273742dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56273738eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562737389355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56273741fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56273a3eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56273a3eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56273a3eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56273a3eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56273a3eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56273a3eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56273a3eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56273a3eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56273a3eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56273a3eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56273c683f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5627393b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5627393bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562739167c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562739167c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562739168738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562739167874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562739167874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562739167874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56273da71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56273da7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56273da62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56273da8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd91a197082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562737387b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x40,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x0,0x0,0x0,0x5b,0x62,0x5d,0xa4, Step #5: \000\000\000\000\000\000\000@#[(b\000]\000\000#[(b\000]\000\000#[(b\000]\000\000#[(b\000]\000\000\000\000\000[b]\244 Step #5: artifact_prefix='./'; Test unit written to ./oom-30026f158274b709177181d05cbe7729bdaf2dcf Step #5: Base64: AAAAAAAAAEAjWyhiAF0AACNbKGIAXQAAI1soYgBdAAAjWyhiAF0AAAAAAFtiXaQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3174 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3276857587 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d246ea810, 0x563d248d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d248d4020,0x563d2676c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/30026f158274b709177181d05cbe7729bdaf2dcf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3887 processed earlier; will process 7142 files now Step #5: #1 pulse cov: 3727 ft: 3728 exec/s: 0 rss: 173Mb Step #5: ==114340== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563d1b1df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d21844898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d218275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d218274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d1b1e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d1b146b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d1b141355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d1b1d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d1e1a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d1e1a6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d1e1a6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d1e1a6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d1e1a6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d1e1a6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d1e1a6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d1e1a6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d1e1a6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d1e1a6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d2043bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d1d168b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d1d173be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d1cf1fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d1cf1fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d1cf20738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d1cf1f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d1cf1f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d1cf1f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d21829abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d21832928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d2181a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d21845112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3442801082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d1b13fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xe0,0xba,0xba,0xe0,0xba,0xb9,0xe0,0xba,0xba,0xe0,0xba,0xba,0xe0,0xba,0xb9,0xe0,0xba,0xba,0xe0,0xba,0xba,0xe0,0xba,0xb9,0xe0,0xba,0xba,0xe0,0xba,0xba,0xe0,0xba,0xba,0xe0,0xba,0xbb,0x3a,0xe0,0xba,0xba,0xe0,0xba,0xba,0xe0,0xba,0xba, Step #5: \"\340\272\272\340\272\271\340\272\272\340\272\272\340\272\271\340\272\272\340\272\272\340\272\271\340\272\272\340\272\272\340\272\272\340\272\273:\340\272\272\340\272\272\340\272\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-efd57633659bc71c0d56771d9a20ca751957c33d Step #5: Base64: IuC6uuC6ueC6uuC6uuC6ueC6uuC6uuC6ueC6uuC6uuC6uuC6uzrgurrgurrguro= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3175 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3277391471 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc04b1b810, 0x55fc04d0501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc04d05020,0x55fc06b9d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/efd57633659bc71c0d56771d9a20ca751957c33d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3889 processed earlier; will process 7140 files now Step #5: ==114376== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fbfb6109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc01c75898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc01c585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc01c584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fbfb616d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fbfb577b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fbfb572355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fbfb608c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fbfe5d7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fbfe5d7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fbfe5d7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fbfe5d7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fbfe5d7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fbfe5d7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fbfe5d7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fbfe5d7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fbfe5d7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fbfe5d7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc0086cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fbfd599b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fbfd5a4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fbfd350c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fbfd350c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fbfd351738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fbfd350874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fbfd350874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fbfd350874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc01c5aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc01c63928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc01c4b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc01c76112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd78e5cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fbfb570b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x16,0x3,0x4,0x0,0x2a,0x2,0x0,0x0,0x26,0x3,0x3,0x6d,0x0,0x0,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x2a,0x2,0x0,0x0,0x26,0x3,0x3,0x6d,0x0,0x0,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x0,0x20,0x1,0x0,0xff,0x12,0x0, Step #5: \026\003\004\000*\002\000\000&\003\003m\000\000\000\000\342\200\256\000\000\000*\002\000\000&\003\003m\000\000\000\000\342\200\256\000\000\000\000 \001\000\377\022\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9ea2d7e2b00f08d04c0a283b31242682e5f74b29 Step #5: Base64: FgMEACoCAAAmAwNtAAAAAOKArgAAACoCAAAmAwNtAAAAAOKArgAAAAAgAQD/EgA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3176 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3277872195 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f604d8a810, 0x55f604f7401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f604f74020,0x55f606e0c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9ea2d7e2b00f08d04c0a283b31242682e5f74b29' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3890 processed earlier; will process 7139 files now Step #5: ==114412== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f5fb87f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f601ee4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f601ec75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f601ec74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f5fb885d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f5fb7e6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f5fb7e1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f5fb877c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f5fe846f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f5fe846f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f5fe846f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f5fe846f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f5fe846f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f5fe846f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f5fe846f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f5fe846f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f5fe846f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f5fe846f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f600adbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f5fd808b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f5fd813be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f5fd5bfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f5fd5bfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f5fd5c0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f5fd5bf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f5fd5bf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f5fd5bf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f601ec9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f601ed2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f601eba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f601ee5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5303147082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f5fb7dfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0x2a,0xa,0x60,0xe2,0x80,0x88,0xd0,0x0,0x60,0x11,0xf3,0xa0,0x81,0xba,0x21,0xf3,0xa0,0x81,0xba,0x60,0xa,0xa,0x2f,0x60,0xa,0x60,0x2f,0xb,0x20,0x20,0x20,0x60,0xa,0x9, Step #5: `\342\200\210-\000`\012\363\240\201\272/*\012`\342\200\210\320\000`\021\363\240\201\272!\363\240\201\272`\012\012/`\012`/\013 `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-4b57e49d129d660535cf588deb55dacb767b7c25 Step #5: Base64: YOKAiC0AYArzoIG6LyoKYOKAiNAAYBHzoIG6IfOggbpgCgovYApgLwsgICBgCgk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3177 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3278472115 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56267c1f0810, 0x56267c3da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56267c3da020,0x56267e2720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4b57e49d129d660535cf588deb55dacb767b7c25' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3891 processed earlier; will process 7138 files now Step #5: ==114448== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562672ce59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56267934a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56267932d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56267932d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562672cebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562672c4cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562672c47355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562672cddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562675cacf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562675cacf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562675cacf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562675cacf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562675cacf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562675cacf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562675cacf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562675cacf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562675cacf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562675cacf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562677f41f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562674c6eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562674c79be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562674a25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562674a25c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562674a26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562674a25874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562674a25874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562674a25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56267932fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562679338928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562679320699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56267934b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4e6ec22082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562672c45b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x80,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x80,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x89,0xa,0xcd,0x89,0xa,0xcd,0x88,0xa,0xcc,0x88,0xa,0xcd,0x88, Step #5: \315\210\012\315\210\012\315\210\012\315\210\012\315\200\012\315\210\012\315\210\012\315\210\012\315\200\012\315\210\012\315\210\012\315\211\012\315\211\012\315\210\012\314\210\012\315\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-23e2c293ecc3adaba048bfbe818c309fde052c71 Step #5: Base64: zYgKzYgKzYgKzYgKzYAKzYgKzYgKzYgKzYAKzYgKzYgKzYkKzYkKzYgKzIgKzYg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3178 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3278963509 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5609346e3810, 0x5609348cd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5609348cd020,0x5609367650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/23e2c293ecc3adaba048bfbe818c309fde052c71' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3892 processed earlier; will process 7137 files now Step #5: ==114484== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56092b1d89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56093183d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5609318205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5609318204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56092b1ded42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56092b13fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56092b13a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56092b1d0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56092e19ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56092e19ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56092e19ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56092e19ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56092e19ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56092e19ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56092e19ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56092e19ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56092e19ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56092e19ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560930434f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56092d161b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56092d16cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56092cf18c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56092cf18c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56092cf19738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56092cf18874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56092cf18874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56092cf18874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560931822abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56093182b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560931813699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56093183e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f458a793082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56092b138b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x66,0x3e,0x3c,0xe0,0xa4,0xb6,0x3e,0x3c,0xe0,0xa4,0xb6,0x3e,0x3c,0xe0,0xa4,0xb6,0x3e,0x3c,0x2f,0xe0,0xa4,0xb6,0x3e,0x3c,0x2f,0xe0,0xa4,0xb6,0x3e,0x3c,0xe0,0xa4,0xb6,0x3e,0x3c,0x2f,0xe0,0xa4,0xb6,0x3e,0x3c,0x2f,0xe0,0xa4,0xb6,0x3e, Step #5: <f><\340\244\266><\340\244\266><\340\244\266></\340\244\266></\340\244\266><\340\244\266></\340\244\266></\340\244\266> Step #5: artifact_prefix='./'; Test unit written to ./oom-0f9c9e5bd669eb566ddd1f3fafe8868ba4556ec8 Step #5: Base64: PGY+POCktj484KS2PjzgpLY+PC/gpLY+PC/gpLY+POCktj48L+Cktj48L+Cktj4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3179 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3279440229 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564728592810, 0x56472877c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56472877c020,0x56472a6140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0f9c9e5bd669eb566ddd1f3fafe8868ba4556ec8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3893 processed earlier; will process 7136 files now Step #5: ==114520== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56471f0879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647256ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647256cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647256cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56471f08dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56471efeeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56471efe9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56471f07fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56472204ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56472204ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56472204ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56472204ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56472204ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56472204ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56472204ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56472204ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56472204ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56472204ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647242e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564721010b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56472101bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564720dc7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564720dc7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564720dc8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564720dc7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564720dc7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564720dc7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647256d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647256da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647256c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647256ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd085830082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56471efe7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x3d,0x7e,0x2d,0x3d,0x3d,0x25,0x3,0xd2,0x84,0xcb,0xb5,0x28,0xcb,0xb5,0x1,0x79,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x29,0x24,0xcb,0xb5, Step #5: ~$=~-==%\003\322\204\313\265(\313\265\001y\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000)$\313\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-51d2fb437d31e04e24d01772a323ff7164049aed Step #5: Base64: fiQ9fi09PSUD0oTLtSjLtQF5AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACkky7U= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3180 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3279925160 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ae1417810, 0x562ae160101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ae1601020,0x562ae34990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/51d2fb437d31e04e24d01772a323ff7164049aed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3894 processed earlier; will process 7135 files now Step #5: #1 pulse cov: 3895 ft: 3896 exec/s: 0 rss: 174Mb Step #5: ==114556== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562ad7f0c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ade571898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ade5545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ade5544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562ad7f12d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562ad7e73b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562ad7e6e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562ad7f04c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562adaed3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562adaed3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562adaed3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562adaed3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562adaed3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562adaed3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562adaed3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562adaed3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562adaed3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562adaed3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562add168f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ad9e95b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ad9ea0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ad9c4cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ad9c4cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ad9c4d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ad9c4c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ad9c4c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ad9c4c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ade556abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ade55f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ade547699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ade572112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7edd195082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562ad7e6cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f, Step #5: \315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-7d209f18f09258568758e46a6505ec4baf5a0b56 Step #5: Base64: zY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3181 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3280444092 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55908b72d810, 0x55908b91701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55908b917020,0x55908d7af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d209f18f09258568758e46a6505ec4baf5a0b56' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3896 processed earlier; will process 7133 files now Step #5: #1 pulse cov: 4244 ft: 4245 exec/s: 0 rss: 172Mb Step #5: ==114592== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5590822229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559088887898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55908886a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55908886a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559082228d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559082189b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559082184355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55908221ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5590851e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5590851e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5590851e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5590851e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5590851e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5590851e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5590851e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5590851e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5590851e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5590851e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55908747ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5590841abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5590841b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559083f62c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559083f62c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559083f63738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559083f62874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559083f62874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559083f62874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55908886cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559088875928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55908885d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559088888112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ea507e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559082182b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x58,0xc,0x44,0x45,0x46,0x41,0x55,0x4c,0x54,0x28,0x28,0x41,0x55,0x4c,0x54,0x28,0x28,0x54,0x28,0x43,0x4f,0x4c,0x55,0x4d,0x4e,0x53,0x28,0x27,0x7b,0x0,0x21,0x4e,0x7c,0x7b,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x2,0x27,0x29,0xa, Step #5: \012X\014DEFAULT((AULT((T(COLUMNS('{\000!N|{$$$$$$$$\002')\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-89a7d96488710aaeff453fbd09d9a794e1c2a26a Step #5: Base64: ClgMREVGQVVMVCgoQVVMVCgoVChDT0xVTU5TKCd7ACFOfHskJCQkJCQkJAInKQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3182 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3280971145 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d5993d810, 0x556d59b2701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d59b27020,0x556d5b9bf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/89a7d96488710aaeff453fbd09d9a794e1c2a26a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3898 processed earlier; will process 7131 files now Step #5: ==114628== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556d504329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d56a97898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d56a7a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d56a7a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d50438d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d50399b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d50394355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d5042ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d533f9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d533f9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d533f9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d533f9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d533f9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d533f9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d533f9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d533f9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d533f9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d533f9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d5568ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d523bbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d523c6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d52172c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d52172c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d52173738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d52172874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d52172874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d52172874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d56a7cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d56a85928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d56a6d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d56a98112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6055627082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d50392b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x65,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3d,0x22,0x63,0x68,0x61,0x72,0x22,0x0,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0x6f,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81, Step #5: <?xml encoding=\"char\"\000\340\271\201\340\271\201o\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-90c26f5783721db677473a6d503b9a6df486ad90 Step #5: Base64: PD94bWwgZW5jb2Rpbmc9ImNoYXIiAOC5geC5gW/guYHguYHguYHguYHguYHguYE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3183 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3281458895 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559d0955f810, 0x559d0974901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559d09749020,0x559d0b5e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/90c26f5783721db677473a6d503b9a6df486ad90' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3899 processed earlier; will process 7130 files now Step #5: ==114664== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559d000549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559d066b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559d0669c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559d0669c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559d0005ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559cfffbbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559cfffb6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559d0004cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559d0301bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559d0301bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559d0301bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559d0301bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559d0301bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559d0301bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559d0301bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559d0301bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559d0301bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559d0301bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559d052b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559d01fddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559d01fe8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559d01d94c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559d01d94c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559d01d95738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559d01d94874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559d01d94874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559d01d94874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559d0669eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559d066a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559d0668f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559d066ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9c9f97b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559cfffb4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x0,0x6b,0x0,0x60,0x2b,0x2b,0x4a,0x9,0x29,0x4a,0x9,0x29,0xa,0x5c,0x9,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0x5c,0x9,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x1,0x0,0x1d,0x9,0x60,0xf3,0xa0,0x80,0xa1,0x29, Step #5: \012\000k\000`++J\011)J\011)\012\\\011)\012\\\011`@`@)\\\011)\012\\\011`@`@)\012\001\000\035\011`\363\240\200\241) Step #5: artifact_prefix='./'; Test unit written to ./oom-8d8040990ebe3685ba96a4674b224135817096a4 Step #5: Base64: CgBrAGArK0oJKUoJKQpcCSkKXAlgQGBAKVwJKQpcCWBAYEApCgEAHQlg86CAoSk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3184 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3282071305 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5625333f6810, 0x5625335e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625335e0020,0x5625354780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d8040990ebe3685ba96a4674b224135817096a4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3900 processed earlier; will process 7129 files now Step #5: ==114700== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562529eeb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562530550898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625305335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625305334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562529ef1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562529e52b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562529e4d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562529ee3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56252ceb2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56252ceb2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56252ceb2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56252ceb2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56252ceb2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56252ceb2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56252ceb2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56252ceb2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56252ceb2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56252ceb2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56252f147f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56252be74b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56252be7fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56252bc2bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56252bc2bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56252bc2c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56252bc2b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56252bc2b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56252bc2b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562530535abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56253053e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562530526699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562530551112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5d1550d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562529e4bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x0,0x24,0x0,0x0,0x0, Step #5: $\177]\177\000\000\0002\000\000\0002.23/\020./( 7 =\177\000\000\0002\000\000\000\000\000\177\177\177\177o\000\000C\000$\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-24e541d3fa04103782871e57ade35b555230f218 Step #5: Base64: JH9dfwAAADIAAAAyLjIzLxAuLyggNyA9fwAAADIAAAAAAH9/f39vAABDACQAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3185 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3282561400 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561e0dc0c810, 0x561e0ddf601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561e0ddf6020,0x561e0fc8e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/24e541d3fa04103782871e57ade35b555230f218' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3901 processed earlier; will process 7128 files now Step #5: ==114736== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561e047019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561e0ad66898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561e0ad495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561e0ad494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561e04707d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561e04668b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561e04663355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561e046f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561e076c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561e076c8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561e076c8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561e076c8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561e076c8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561e076c8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561e076c8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561e076c8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561e076c8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561e076c8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561e0995df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561e0668ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561e06695be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561e06441c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561e06441c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561e06442738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561e06441874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561e06441874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561e06441874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561e0ad4babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561e0ad54928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561e0ad3c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561e0ad67112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc36a9b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561e04661b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0xa4, Step #5: \000\000\000\000\000\000\000\000#[(b\000]\000\000#[(b\000]\000\000#[(b\000]\000\000#[(b\000]\000\000#[(b\000]\244 Step #5: artifact_prefix='./'; Test unit written to ./oom-ee25b1d46f34ae5e554a344184df9254bd36b290 Step #5: Base64: AAAAAAAAAAAjWyhiAF0AACNbKGIAXQAAI1soYgBdAAAjWyhiAF0AACNbKGIAXaQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3186 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3283043092 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f28b422810, 0x55f28b60c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f28b60c020,0x55f28d4a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee25b1d46f34ae5e554a344184df9254bd36b290' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3902 processed earlier; will process 7127 files now Step #5: ==114772== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f281f179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f28857c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f28855f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f28855f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f281f1dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f281e7eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f281e79355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f281f0fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f284edef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f284edef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f284edef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f284edef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f284edef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f284edef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f284edef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f284edef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f284edef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f284edef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f287173f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f283ea0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f283eabbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f283c57c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f283c57c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f283c58738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f283c57874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f283c57874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f283c57874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f288561abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f28856a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f288552699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f28857d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f18620c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f281e77b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0x24,0x2c,0x27,0x2c,0x24,0x24,0x24,0x24,0x3f,0x24,0x2b,0x2f,0x76,0x2f,0x24,0x2c,0x24,0x2c,0x24,0x24,0x24,0x24,0x3f,0x5c,0xf3,0xa0,0x80,0xa5,0x5c,0x5c,0x5c,0xf3,0xa0,0x81,0x99,0x65,0x6e,0x3,0x5c,0x5c,0x5c,0x5c,0x65,0x6e,0x3, Step #5: $$$,',$$$$?$+/v/$,$,$$$$?\\\363\240\200\245\\\\\\\363\240\201\231en\003\\\\\\\\en\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-c693ba1210ea56e87ff7b7c5f89bebd3b1050b54 Step #5: Base64: JCQkLCcsJCQkJD8kKy92LyQsJCwkJCQkP1zzoIClXFxc86CBmWVuA1xcXFxlbgM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3187 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3283527140 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec428b8810, 0x55ec42aa201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec42aa2020,0x55ec4493a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c693ba1210ea56e87ff7b7c5f89bebd3b1050b54' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3903 processed earlier; will process 7126 files now Step #5: ==114808== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec393ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec3fa12898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec3f9f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec3f9f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec393b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec39314b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec3930f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec393a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec3c374f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec3c374f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec3c374f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec3c374f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec3c374f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec3c374f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec3c374f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec3c374f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec3c374f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec3c374f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec3e609f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec3b336b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec3b341be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec3b0edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec3b0edc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec3b0ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec3b0ed874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec3b0ed874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec3b0ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec3f9f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec3fa00928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec3f9e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec3fa13112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f924e60a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec3930db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0xb2,0xdb,0xb2,0xdb,0xb2,0xdb,0xb2,0xdb,0xb2,0xdb,0xb2,0xdb,0xb2,0xdb,0xb2,0xdb,0xb2,0xd9,0xb2,0xdb,0xb2,0xdb,0xb2,0xdb,0xb2,0xdb,0xb1,0xdb,0xb2,0xdb,0xb2,0xdb,0xb2,0xdb,0xb1,0xdb,0xb2,0xdb,0xb2,0xdb,0xb2,0x71,0xdb,0xb2,0xdb,0xb2, Step #5: \333\262\333\262\333\262\333\262\333\262\333\262\333\262\333\262\333\262\331\262\333\262\333\262\333\262\333\261\333\262\333\262\333\262\333\261\333\262\333\262\333\262q\333\262\333\262 Step #5: artifact_prefix='./'; Test unit written to ./oom-b7535c58d9877eadb2a23998d877a7be1cad1a24 Step #5: Base64: 27Lbstuy27Lbstuy27Lbstuy2bLbstuy27Lbsduy27Lbstux27Lbstuycduy27I= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3188 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3284010176 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5601dcb5e810, 0x5601dcd4801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5601dcd48020,0x5601debe00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7535c58d9877eadb2a23998d877a7be1cad1a24' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3904 processed earlier; will process 7125 files now Step #5: ==114844== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5601d36539c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601d9cb8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601d9c9b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601d9c9b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5601d3659d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601d35bab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601d35b5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5601d364bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601d661af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601d661af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601d661af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601d661af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601d661af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601d661af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601d661af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601d661af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601d661af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601d661af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5601d88aff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601d55dcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601d55e7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5601d5393c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5601d5393c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5601d5394738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5601d5393874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5601d5393874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5601d5393874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5601d9c9dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5601d9ca6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5601d9c8e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601d9cb9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ae232d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601d35b3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xd0,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0, Step #5: \360\236\213\221\015in\015\320\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360 Step #5: artifact_prefix='./'; Test unit written to ./oom-a567e7a5f98be93555f5e2760fa757adf6a5c8b1 Step #5: Base64: 8J6LkQ1pbg3QkQ1pbg3wnouRDWluDfCei5ENaW4N8J6LkQ1pbg3wnouRDWluDfA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3189 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3284488930 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eea9e4c810, 0x55eeaa03601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eeaa036020,0x55eeabece0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a567e7a5f98be93555f5e2760fa757adf6a5c8b1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3905 processed earlier; will process 7124 files now Step #5: ==114880== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eea09419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eea6fa6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eea6f895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eea6f894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eea0947d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eea08a8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eea08a3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eea0939c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eea3908f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eea3908f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eea3908f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eea3908f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eea3908f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eea3908f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eea3908f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eea3908f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eea3908f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eea3908f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eea5b9df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eea28cab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eea28d5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eea2681c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eea2681c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eea2682738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eea2681874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eea2681874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eea2681874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eea6f8babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eea6f94928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eea6f7c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eea6fa7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f41dc7f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eea08a1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x4,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x42,0x3c,0xdb,0x9e,0x0,0x0,0x0,0x0,0x64,0x64,0x64,0x64,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x42,0x3c,0xdb,0x9e,0x7e,0x7e,0x7e,0x7e,0x7e,0x2b,0x7e,0x2b,0x7e,0x7e,0x7e,0x7e,0xff,0x7e,0xff,0x67,0x67, Step #5: \002\004~~~~~~B<\333\236\000\000\000\000dddd~~~~~~B<\333\236~~~~~+~+~~~~\377~\377gg Step #5: artifact_prefix='./'; Test unit written to ./oom-ec23a85160dbd4aeaff68140b9931e7870784da4 Step #5: Base64: AgR+fn5+fn5CPNueAAAAAGRkZGR+fn5+fn5CPNuefn5+fn4rfit+fn5+/37/Z2c= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3190 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3284967381 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56516ea54810, 0x56516ec3e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56516ec3e020,0x565170ad60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec23a85160dbd4aeaff68140b9931e7870784da4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3906 processed earlier; will process 7123 files now Step #5: ==114916== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5651655499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56516bbae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56516bb915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56516bb914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56516554fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5651654b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5651654ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565165541c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565168510f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565168510f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565168510f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565168510f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565168510f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565168510f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565168510f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565168510f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565168510f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565168510f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56516a7a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5651674d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5651674ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565167289c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565167289c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56516728a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565167289874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565167289874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565167289874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56516bb93abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56516bb9c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56516bb84699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56516bbaf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa41bdf4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5651654a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x1a,0x0,0x3,0x10,0x1,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0x0,0x5,0x0,0x0,0x50,0x2,0x0,0x0,0x0,0x5,0x0,0x0,0x50,0x2,0x0,0x0,0x40,0x6,0x0,0x0,0x0,0x3,0x0,0x0,0x40,0x6,0x0,0x0,0x0,0xa,0x0,0x3e,0x6, Step #5: \000\000\032\000\003\020\001\000\000\000\000\002\000\000\000\005\000\000P\002\000\000\000\005\000\000P\002\000\000@\006\000\000\000\003\000\000@\006\000\000\000\012\000>\006 Step #5: artifact_prefix='./'; Test unit written to ./oom-0bfffd5ebfab2fa0e99ad5dbca608e5325c42b48 Step #5: Base64: AAAaAAMQAQAAAAACAAAABQAAUAIAAAAFAABQAgAAQAYAAAADAABABgAAAAoAPgY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3191 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3285449447 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558fac9c9810, 0x558facbb301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558facbb3020,0x558faea4b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0bfffd5ebfab2fa0e99ad5dbca608e5325c42b48' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3907 processed earlier; will process 7122 files now Step #5: ==114952== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558fa34be9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558fa9b23898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558fa9b065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558fa9b064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558fa34c4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558fa3425b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558fa3420355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558fa34b6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558fa6485f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558fa6485f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558fa6485f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558fa6485f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558fa6485f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558fa6485f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558fa6485f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558fa6485f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558fa6485f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558fa6485f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558fa871af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558fa5447b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558fa5452be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558fa51fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558fa51fec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558fa51ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558fa51fe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558fa51fe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558fa51fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558fa9b08abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558fa9b11928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558fa9af9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558fa9b24112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff899cc0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558fa341eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x27,0x28,0x0,0x60,0x54,0x58,0x59,0x45,0x15,0x0,0x27,0x17,0x54,0x0,0x9,0x0,0x0,0x0,0x0,0x0,0x0,0x59,0x45,0x33,0x4,0x3b,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x58,0x59,0x45,0x15,0x0,0x10,0x0,0x15,0x0,0x10, Step #5: ID3\004'(\000`TXYE\025\000'\027T\000\011\000\000\000\000\000\000YE3\004;'\000\000`'\027TXYE\025\000\020\000\025\000\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-9650a8752c432ae1e73a7f008384767e9a559651 Step #5: Base64: SUQzBCcoAGBUWFlFFQAnF1QACQAAAAAAAFlFMwQ7JwAAYCcXVFhZRRUAEAAVABA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3192 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3286053228 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560c05e7b810, 0x560c0606501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560c06065020,0x560c07efd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9650a8752c432ae1e73a7f008384767e9a559651' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3908 processed earlier; will process 7121 files now Step #5: ==114988== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560bfc9709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560c02fd5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560c02fb85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560c02fb84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560bfc976d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560bfc8d7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560bfc8d2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560bfc968c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560bff937f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560bff937f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560bff937f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560bff937f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560bff937f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560bff937f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560bff937f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560bff937f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560bff937f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560bff937f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560c01bccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560bfe8f9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560bfe904be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560bfe6b0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560bfe6b0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560bfe6b1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560bfe6b0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560bfe6b0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560bfe6b0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560c02fbaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560c02fc3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560c02fab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560c02fd6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f284f8dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560bfc8d0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x67,0x6c,0x79,0x66,0x66,0x67,0x7f,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x67,0x7f,0x66,0x3b,0x67,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x73,0x74,0x72,0x65,0x61,0x6d,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x6e, Step #5: tglyffg\177fg\177f;g?tglyg\177f;gf?f;g?tstreamglyf?g?g?n Step #5: artifact_prefix='./'; Test unit written to ./oom-b177db0b7b423aaca2aafd1178a798072f9d6b95 Step #5: Base64: dGdseWZmZ39mZ39mO2c/dGdseWd/ZjtnZj9mO2c/dHN0cmVhbWdseWY/Zz9nP24= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3193 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3286536467 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5590bcc14810, 0x5590bcdfe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5590bcdfe020,0x5590bec960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b177db0b7b423aaca2aafd1178a798072f9d6b95' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3909 processed earlier; will process 7120 files now Step #5: ==115024== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5590b37099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5590b9d6e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5590b9d515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5590b9d514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5590b370fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5590b3670b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5590b366b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5590b3701c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5590b66d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5590b66d0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5590b66d0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5590b66d0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5590b66d0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5590b66d0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5590b66d0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5590b66d0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5590b66d0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5590b66d0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5590b8965f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5590b5692b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5590b569dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5590b5449c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5590b5449c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5590b544a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5590b5449874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5590b5449874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5590b5449874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5590b9d53abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5590b9d5c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5590b9d44699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5590b9d6f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c66f6c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5590b3669b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d, Step #5: \015- - - - - - - - - - - - - - - - - - - - - - - Step #5: artifact_prefix='./'; Test unit written to ./oom-0ed6c7618730415b6ec01e66346cd07134e221a7 Step #5: Base64: IA0tIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3194 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3287058453 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e841fdb810, 0x55e8421c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e8421c5020,0x55e84405d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0ed6c7618730415b6ec01e66346cd07134e221a7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3910 processed earlier; will process 7119 files now Step #5: ==115060== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e838ad09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e83f135898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e83f1185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e83f1184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e838ad6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e838a37b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e838a32355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e838ac8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e83ba97f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e83ba97f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e83ba97f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e83ba97f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e83ba97f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e83ba97f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e83ba97f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e83ba97f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e83ba97f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e83ba97f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e83dd2cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e83aa59b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e83aa64be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e83a810c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e83a810c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e83a811738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e83a810874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e83a810874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e83a810874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e83f11aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e83f123928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e83f10b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e83f136112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2320148082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e838a30b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x88,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x7f,0x0,0x0,0x0,0x0,0xff,0x0,0x0,0xb,0x0,0x60,0xa,0xa,0x2f,0x60,0xa,0x60,0x20,0x60,0x20,0x60,0xa,0x9, Step #5: `\342\210\210-\000`\012\363\240\201\272\363\240\201\272/\001\000\000\000\000\000\000\177\000\000\000\000\377\000\000\013\000`\012\012/`\012` ` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-578bb5afb059e7cd8e37da96dd528d4425c95161 Step #5: Base64: YOKIiC0AYArzoIG686CBui8BAAAAAAAAfwAAAAD/AAALAGAKCi9gCmAgYCBgCgk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3195 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3287664006 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ece2b61810, 0x55ece2d4b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ece2d4b020,0x55ece4be30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/578bb5afb059e7cd8e37da96dd528d4425c95161' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3911 processed earlier; will process 7118 files now Step #5: ==115096== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ecd96569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ecdfcbb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ecdfc9e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ecdfc9e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ecd965cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ecd95bdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ecd95b8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ecd964ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ecdc61df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ecdc61df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ecdc61df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ecdc61df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ecdc61df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ecdc61df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ecdc61df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ecdc61df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ecdc61df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ecdc61df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ecde8b2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ecdb5dfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ecdb5eabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ecdb396c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ecdb396c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ecdb397738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ecdb396874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ecdb396874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ecdb396874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ecdfca0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ecdfca9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ecdfc91699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ecdfcbc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3331e7e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ecd95b6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x2c,0x19,0x22,0xc4,0xb3,0xdf,0x93,0xdf,0xb3,0xdf,0xb3,0xdf,0xb3,0xdf,0xb2,0xdf,0xb3,0xdf,0xb3,0xdf,0xb3,0xdf,0xb3,0xdf,0xb2,0xdf,0xb3,0x62,0xdf,0xb3,0xdf,0xb3,0xdf,0xb3,0xdf,0xb2,0xdf,0xb3,0x62,0x4c,0xc4,0x78,0x78,0x28,0xdf, Step #5: HU,\031\"\304\263\337\223\337\263\337\263\337\263\337\262\337\263\337\263\337\263\337\263\337\262\337\263b\337\263\337\263\337\263\337\262\337\263bL\304xx(\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-a9b63557dcde71c6ff255b8b5968f72ffa5e134a Step #5: Base64: SFUsGSLEs9+T37Pfs9+z37Lfs9+z37Pfs9+y37Ni37Pfs9+z37Lfs2JMxHh4KN8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3196 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3288147530 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ad441ee810, 0x55ad443d801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ad443d8020,0x55ad462700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9b63557dcde71c6ff255b8b5968f72ffa5e134a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3912 processed earlier; will process 7117 files now Step #5: ==115132== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ad3ace39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ad41348898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ad4132b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ad4132b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ad3ace9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ad3ac4ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ad3ac45355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ad3acdbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ad3dcaaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ad3dcaaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ad3dcaaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ad3dcaaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ad3dcaaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ad3dcaaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ad3dcaaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ad3dcaaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ad3dcaaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ad3dcaaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ad3ff3ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ad3cc6cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ad3cc77be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ad3ca23c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ad3ca23c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ad3ca24738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ad3ca23874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ad3ca23874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ad3ca23874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ad4132dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ad41336928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ad4131e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ad41349112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4c520d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ad3ac43b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x80,0x82,0xe3,0x80,0x86,0xe3,0x80,0x82,0xe3,0x80,0x81,0xe3,0x80,0x82,0xe3,0x80,0x86,0xe3,0x80,0x82,0xe3,0x80,0x81,0xe3,0x80,0x82,0xe3,0x80,0x86,0xe3,0x80,0x82,0xe3,0x80,0x81,0xe3,0x80,0x83,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0xe, Step #5: \343\200\202\343\200\206\343\200\202\343\200\201\343\200\202\343\200\206\343\200\202\343\200\201\343\200\202\343\200\206\343\200\202\343\200\201\343\200\203\343\200\202\343\200\202\343\016 Step #5: artifact_prefix='./'; Test unit written to ./oom-c2f678183fb323f6b252d497c0bd0526b3dbc493 Step #5: Base64: 44CC44CG44CC44CB44CC44CG44CC44CB44CC44CG44CC44CB44CD44CC44CC4w4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3197 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3288632407 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4decc5810, 0x55e4deeaf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4deeaf020,0x55e4e0d470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c2f678183fb323f6b252d497c0bd0526b3dbc493' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3913 processed earlier; will process 7116 files now Step #5: #1 pulse cov: 3813 ft: 3814 exec/s: 0 rss: 175Mb Step #5: ==115168== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e4d57ba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4dbe1f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4dbe025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4dbe024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4d57c0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4d5721b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4d571c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4d57b2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4d8781f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4d8781f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4d8781f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4d8781f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4d8781f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4d8781f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4d8781f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4d8781f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4d8781f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4d8781f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4daa16f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4d7743b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4d774ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4d74fac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4d74fac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4d74fb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4d74fa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4d74fa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4d74fa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4dbe04abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4dbe0d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4dbdf5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4dbe20112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f944b978082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4d571ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6f,0x6f,0x6f,0x6f,0x68,0x65,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x7f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0xa4,0xb6,0x43,0x4f,0x4c,0x52,0x3,0x0,0x0,0x0, Step #5: oooooheoooooooooo\177ooooooooooooooooooo\244\266COLR\003\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d12764c343070b0c5bd3f54dde590dc55d2c6cbd Step #5: Base64: b29vb29oZW9vb29vb29vb29/b29vb29vb29vb29vb29vb29vb6S2Q09MUgMAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3198 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3289149423 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f074955810, 0x55f074b3f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f074b3f020,0x55f0769d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d12764c343070b0c5bd3f54dde590dc55d2c6cbd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3915 processed earlier; will process 7114 files now Step #5: ==115204== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f06b44a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f071aaf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f071a925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f071a924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f06b450d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f06b3b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f06b3ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f06b442c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f06e411f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f06e411f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f06e411f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f06e411f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f06e411f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f06e411f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f06e411f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f06e411f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f06e411f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f06e411f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f0706a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f06d3d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f06d3debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f06d18ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f06d18ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f06d18b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f06d18a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f06d18a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f06d18a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f071a94abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f071a9d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f071a85699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f071ab0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0441dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f06b3aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x30,0x4,0x0,0x0,0x0,0x0,0x0,0x6e,0x4d,0x1,0x8,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6e,0x4d,0x1,0x8,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: ID0\004\000\000\000\000\000nM\001\010\000\000\000\000\000\000\000\000\000\000\000nM\001\010\000\000\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7eea1c81d0496d1b3955d53b2bce5bf5e6867056 Step #5: Base64: SUQwBAAAAAAAbk0BCAAAAAAAAAAAAAAAbk0BCAAAAAAAAQAAAAAAAAAAAAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3199 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3289628878 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9298de810, 0x55a929ac801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a929ac8020,0x55a92b9600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7eea1c81d0496d1b3955d53b2bce5bf5e6867056' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3916 processed earlier; will process 7113 files now Step #5: #1 pulse cov: 3727 ft: 3728 exec/s: 0 rss: 171Mb Step #5: ==115240== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a9203d39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a926a38898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a926a1b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a926a1b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a9203d9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a92033ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a920335355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a9203cbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a92339af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a92339af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a92339af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a92339af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a92339af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a92339af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a92339af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a92339af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a92339af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a92339af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a92562ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a92235cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a922367be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a922113c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a922113c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a922114738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a922113874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a922113874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a922113874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a926a1dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a926a26928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a926a0e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a926a39112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f076486c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a920333b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4a,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0xe1,0x85,0x9f,0x47,0x45,0xe1,0x85,0x9f,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x49,0x4e,0x20,0x1,0x0,0x0,0x20,0x2d,0x2d,0xad,0x2d,0x2d,0x2d,0x2d,0xa,0x47,0x64,0xa,0x2d,0xa, Step #5: J-----BE\341\205\237GE\341\205\237GIN -------IN \001\000\000 --\255----\012Gd\012-\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-f6bb1ac7502539aeebe8f51f43b3ae679caf0eed Step #5: Base64: Si0tLS0tQkXhhZ9HReGFn0dJTiAtLS0tLS0tSU4gAQAAIC0trS0tLS0KR2QKLQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3200 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3290152878 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc59343810, 0x55cc5952d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc5952d020,0x55cc5b3c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f6bb1ac7502539aeebe8f51f43b3ae679caf0eed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3918 processed earlier; will process 7111 files now Step #5: ==115276== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cc4fe389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc5649d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc564805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc564804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc4fe3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc4fd9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc4fd9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc4fe30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc52dfff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc52dfff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc52dfff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc52dfff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc52dfff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc52dfff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc52dfff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc52dfff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc52dfff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc52dfff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc55094f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc51dc1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc51dccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc51b78c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc51b78c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc51b79738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc51b78874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc51b78874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc51b78874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc56482abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc5648b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc56473699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc5649e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3cf7b72082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc4fd98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x0,0x0,0x7f,0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x0,0x0,0x0, Step #5: $\177]\177\000\000\0002\000\000\0002.23/\020./( 7 =\177\000\000\0002\000\000\000\000\000\177/\000\000\000\000\000\000\000$\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-405dfe83fb425dcc5562e993eee023d824b35a08 Step #5: Base64: JH9dfwAAADIAAAAyLjIzLxAuLyggNyA9fwAAADIAAAAAAH8vAAAAAAAAACQAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3201 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3290637243 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561bc0219810, 0x561bc040301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561bc0403020,0x561bc229b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/405dfe83fb425dcc5562e993eee023d824b35a08' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3919 processed earlier; will process 7110 files now Step #5: ==115312== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561bb6d0e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561bbd373898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561bbd3565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561bbd3564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561bb6d14d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561bb6c75b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561bb6c70355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561bb6d06c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561bb9cd5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561bb9cd5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561bb9cd5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561bb9cd5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561bb9cd5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561bb9cd5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561bb9cd5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561bb9cd5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561bb9cd5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561bb9cd5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561bbbf6af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561bb8c97b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561bb8ca2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561bb8a4ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561bb8a4ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561bb8a4f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561bb8a4e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561bb8a4e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561bb8a4e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561bbd358abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561bbd361928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561bbd349699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561bbd374112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf103bd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561bb6c6eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6f,0x6f,0x6f,0x6f,0x68,0x65,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0xef,0x7f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0xa4,0xb6,0x43,0x4f,0x4c,0x52,0xc8,0x0,0x0,0x0, Step #5: oooooheooooooooo\357\177ooooooooooooooooooo\244\266COLR\310\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-22ca1f0e68c9a1246b1a9b1685cc6f004c787d7e Step #5: Base64: b29vb29oZW9vb29vb29vb+9/b29vb29vb29vb29vb29vb29vb6S2Q09MUsgAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3202 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3291119409 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556ee78f7810, 0x556ee7ae101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556ee7ae1020,0x556ee99790e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/22ca1f0e68c9a1246b1a9b1685cc6f004c787d7e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3920 processed earlier; will process 7109 files now Step #5: #1 pulse cov: 3499 ft: 3500 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 4255 ft: 4536 exec/s: 0 rss: 175Mb Step #5: ==115348== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556ede3ec9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556ee4a51898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556ee4a345dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556ee4a344fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556ede3f2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556ede353b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556ede34e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556ede3e4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556ee13b3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556ee13b3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556ee13b3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556ee13b3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556ee13b3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556ee13b3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556ee13b3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556ee13b3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556ee13b3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556ee13b3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556ee3648f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556ee0375b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556ee0380be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556ee012cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556ee012cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556ee012d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556ee012c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556ee012c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556ee012c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556ee4a36abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556ee4a3f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556ee4a27699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556ee4a52112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc551d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556ede34cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x3e, Step #5: <t><t><t><t><t><t><t><t><t><t><t><t><t><t><t><t> Step #5: artifact_prefix='./'; Test unit written to ./oom-28c1bd809447973c2b4bbe63e74807951163d326 Step #5: Base64: PHQ+PHQ+PHQ+PHQ+PHQ+PHQ+PHQ+PHQ+PHQ+PHQ+PHQ+PHQ+PHQ+PHQ+PHQ+PHQ+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3203 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3291660031 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a5f2d7a810, 0x55a5f2f6401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a5f2f64020,0x55a5f4dfc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/28c1bd809447973c2b4bbe63e74807951163d326' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3923 processed earlier; will process 7106 files now Step #5: ==115384== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a5e986f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a5efed4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a5efeb75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a5efeb74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a5e9875d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a5e97d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a5e97d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a5e9867c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a5ec836f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a5ec836f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a5ec836f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a5ec836f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a5ec836f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a5ec836f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a5ec836f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a5ec836f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a5ec836f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a5ec836f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a5eeacbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a5eb7f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a5eb803be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a5eb5afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a5eb5afc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a5eb5b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a5eb5af874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a5eb5af874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a5eb5af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a5efeb9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a5efec2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a5efeaa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a5efed5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8bd693c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a5e97cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa, Step #5: =\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-0177e93d968ab83ec2938345d86000b2bd92a2ea Step #5: Base64: PQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3204 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3292137902 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565524bce810, 0x565524db801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565524db8020,0x565526c500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0177e93d968ab83ec2938345d86000b2bd92a2ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3924 processed earlier; will process 7105 files now Step #5: #1 pulse cov: 3978 ft: 3979 exec/s: 0 rss: 172Mb Step #5: ==115420== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56551b6c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565521d28898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565521d0b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565521d0b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56551b6c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56551b62ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56551b625355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56551b6bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56551e68af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56551e68af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56551e68af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56551e68af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56551e68af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56551e68af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56551e68af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56551e68af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56551e68af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56551e68af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56552091ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56551d64cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56551d657be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56551d403c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56551d403c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56551d404738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56551d403874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56551d403874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56551d403874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565521d0dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565521d16928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565521cfe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565521d29112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9e3c92d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56551b623b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0x32,0x0,0xa,0xd8,0x80,0x4,0x0,0x0,0xa,0x2d,0x20,0x0,0x0,0x4f,0x0,0x4f,0x59,0x3e,0x2d,0x31,0x2b,0x34,0x27,0x0,0x54,0x3a,0xd8,0x80,0x4,0x2e,0x2b,0x59,0x3e,0x2d,0x31,0x2b,0x34,0x27,0x0,0x54,0x3a,0xd8,0x80,0x4,0x2e,0x2b,0x0, Step #5: 22\000\012\330\200\004\000\000\012- \000\000O\000OY>-1+4'\000T:\330\200\004.+Y>-1+4'\000T:\330\200\004.+\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cca48ba539350df8dc61afc1d1c2f6e111d5dd35 Step #5: Base64: MjIACtiABAAACi0gAABPAE9ZPi0xKzQnAFQ62IAELitZPi0xKzQnAFQ62IAELisA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3205 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3292661207 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560154e21810, 0x56015500b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56015500b020,0x560156ea30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cca48ba539350df8dc61afc1d1c2f6e111d5dd35' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3926 processed earlier; will process 7103 files now Step #5: ==115456== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56014b9169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560151f7b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560151f5e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560151f5e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56014b91cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56014b87db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56014b878355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56014b90ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56014e8ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56014e8ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56014e8ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56014e8ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56014e8ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56014e8ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56014e8ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56014e8ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56014e8ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56014e8ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560150b72f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56014d89fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56014d8aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56014d656c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56014d656c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56014d657738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56014d656874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56014d656874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56014d656874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560151f60abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560151f69928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560151f51699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560151f7c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e0fc25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56014b876b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0x32,0x0,0xa,0xd8,0x80,0x4,0x0,0x0,0xa,0x2d,0x20,0x0,0x0,0x4f,0x0,0x4f,0x59,0x3e,0x2d,0x31,0x2b,0x34,0x28,0x0,0x54,0x3a,0xd8,0x80,0x4,0x2e,0x2b,0x59,0x3e,0x2d,0x31,0x2b,0x34,0x27,0x0,0x54,0x3a,0xd8,0x80,0x4,0x2e,0xd8,0x80, Step #5: 22\000\012\330\200\004\000\000\012- \000\000O\000OY>-1+4(\000T:\330\200\004.+Y>-1+4'\000T:\330\200\004.\330\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-d5be093be8670493377a0e4c8c04aa47e0e10f5c Step #5: Base64: MjIACtiABAAACi0gAABPAE9ZPi0xKzQoAFQ62IAELitZPi0xKzQnAFQ62IAELtiA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3206 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3293139746 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db3de68810, 0x55db3e05201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db3e052020,0x55db3feea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d5be093be8670493377a0e4c8c04aa47e0e10f5c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3927 processed earlier; will process 7102 files now Step #5: ==115492== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db3495d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db3afc2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db3afa55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db3afa54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db34963d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db348c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db348bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db34955c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db37924f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db37924f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db37924f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db37924f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db37924f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db37924f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db37924f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db37924f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db37924f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db37924f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db39bb9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db368e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db368f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db3669dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db3669dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db3669e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db3669d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db3669d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db3669d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db3afa7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db3afb0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db3af98699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db3afc3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbb9d828082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db348bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x44,0x33,0x4,0x27,0x0,0x0,0x61,0x27,0x17,0x54,0x59,0x33,0x45,0x4,0x27,0x0,0x0,0x60,0x27,0x0,0x0,0x61,0x27,0x17,0x54,0x59,0x33,0x45,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x15,0x10,0x0,0x45,0x15,0x0,0x10, Step #5: ID3\004D3\004'\000\000a'\027TY3E\004'\000\000`'\000\000a'\027TY3E\004'\000\000`'\027TY\025\020\000E\025\000\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-920fa985b71f9cdb8769d8ffe8ec71b723e9a082 Step #5: Base64: SUQzBEQzBCcAAGEnF1RZM0UEJwAAYCcAAGEnF1RZM0UEJwAAYCcXVFkVEABFFQAQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3207 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3293735365 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559b3f691810, 0x559b3f87b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559b3f87b020,0x559b417130e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/920fa985b71f9cdb8769d8ffe8ec71b723e9a082' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3928 processed earlier; will process 7101 files now Step #5: ==115528== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559b361869c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559b3c7eb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559b3c7ce5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559b3c7ce4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b3618cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b360edb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b360e8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b3617ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b3914df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b3914df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b3914df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b3914df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b3914df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b3914df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b3914df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b3914df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b3914df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b3914df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559b3b3e2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b3810fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b3811abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b37ec6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b37ec6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b37ec7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b37ec6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b37ec6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b37ec6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559b3c7d0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559b3c7d9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559b3c7c1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559b3c7ec112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9103df5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b360e6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbe,0x94,0xef,0xbe,0x94,0xef,0xbe,0x94,0xef,0xbc,0x94,0xef,0xae,0x94,0xef,0xbe,0x94,0xef,0xbe,0x94,0xef,0xbe,0x94,0xef,0xbe,0x94,0xef,0xbe,0x94,0x29,0xbc,0x94,0xe7,0xbe,0x94,0xec,0x9c,0xb8,0xef,0xbe,0x94,0xef,0xbe,0x94,0xef,0xbe,0x0, Step #5: \357\276\224\357\276\224\357\276\224\357\274\224\357\256\224\357\276\224\357\276\224\357\276\224\357\276\224\357\276\224)\274\224\347\276\224\354\234\270\357\276\224\357\276\224\357\276\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a14474632090ec9b43d445e3838d70738d887ce9 Step #5: Base64: 776U776U776U77yU766U776U776U776U776U776UKbyU576U7Jy4776U776U774A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3208 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3294211757 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555f96597810, 0x555f9678101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555f96781020,0x555f986190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a14474632090ec9b43d445e3838d70738d887ce9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3929 processed earlier; will process 7100 files now Step #5: #1 pulse cov: 11241 ft: 11242 exec/s: 0 rss: 191Mb Step #5: ==115564== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555f8d08c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555f936f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555f936d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555f936d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555f8d092d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555f8cff3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555f8cfee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555f8d084c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555f90053f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555f90053f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555f90053f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555f90053f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555f90053f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555f90053f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555f90053f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555f90053f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555f90053f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555f90053f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555f922e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555f8f015b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555f8f020be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555f8edccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555f8edccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555f8edcd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555f8edcc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555f8edcc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555f8edcc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555f936d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555f936df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555f936c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555f936f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f008d01d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555f8cfecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1e,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a, Step #5: \036**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012** Step #5: artifact_prefix='./'; Test unit written to ./oom-ca1ab34fa1229c8bc54cc38ad61931444c4483bf Step #5: Base64: HioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioq Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3209 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3294756776 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559172ea1810, 0x55917308b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55917308b020,0x559174f230e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca1ab34fa1229c8bc54cc38ad61931444c4483bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3931 processed earlier; will process 7098 files now Step #5: ==115600== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5591699969c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55916fffb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55916ffde5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55916ffde4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55916999cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5591698fdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5591698f8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55916998ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55916c95df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55916c95df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55916c95df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55916c95df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55916c95df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55916c95df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55916c95df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55916c95df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55916c95df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55916c95df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55916ebf2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55916b91fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55916b92abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55916b6d6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55916b6d6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55916b6d7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55916b6d6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55916b6d6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55916b6d6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55916ffe0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55916ffe9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55916ffd1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55916fffc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6c58968082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5591698f6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0x20,0x73,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0x20,0x25,0x20,0x78,0xa,0x53,0x59,0x53,0x54,0x45,0x4d,0xa,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x2e,0x27,0x3e,0x25,0x78,0x3b,0x25,0x44, Step #5: <!DOCTYPE s[<!ENTITY % x\012SYSTEM\012'http://.'>%x;%D Step #5: artifact_prefix='./'; Test unit written to ./oom-896a113eaed5f7186ecf90d58403ec43bf7ec379 Step #5: Base64: PCFET0NUWVBFIHNbPCFFTlRJVFkgJSB4ClNZU1RFTQonaHR0cDovLy4nPiV4OyVE Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3210 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3295234865 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e506917810, 0x55e506b0101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e506b01020,0x55e5089990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/896a113eaed5f7186ecf90d58403ec43bf7ec379' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3932 processed earlier; will process 7097 files now Step #5: #1 pulse cov: 3728 ft: 3729 exec/s: 0 rss: 171Mb Step #5: ==115636== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e4fd40c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e503a71898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e503a545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e503a544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4fd412d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4fd373b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4fd36e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4fd404c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e5003d3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e5003d3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e5003d3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e5003d3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e5003d3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e5003d3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e5003d3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e5003d3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e5003d3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e5003d3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e502668f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4ff395b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4ff3a0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4ff14cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4ff14cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4ff14d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4ff14c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4ff14c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4ff14c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e503a56abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e503a5f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e503a47699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e503a72112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f17632d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4fd36cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x32,0x5f,0x39,0x2a,0x2a,0x39,0x2a,0x2a,0x33,0x2e,0x30,0x38,0x33,0x30,0x37,0x34,0x34,0x5f,0x34,0x30,0x35,0x35,0x32,0x36,0x32,0x35,0x31,0x30,0x35,0x31,0x37,0x33,0x33,0x37,0x31,0x39,0x30,0x34,0x38,0x38,0x65,0x2d,0xff,0x0,0x0,0xf5,0x5f, Step #5: 02_9**9**3.0830744_4055262510517337190488e-\377\000\000\365_ Step #5: artifact_prefix='./'; Test unit written to ./oom-cdf418e850dbdf67e37e5ac859b61db5b6077002 Step #5: Base64: MDJfOSoqOSoqMy4wODMwNzQ0XzQwNTUyNjI1MTA1MTczMzcxOTA0ODhlLf8AAPVf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3211 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3295757311 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557a536b0810, 0x557a5389a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557a5389a020,0x557a557320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cdf418e850dbdf67e37e5ac859b61db5b6077002' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3934 processed earlier; will process 7095 files now Step #5: ==115672== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557a4a1a59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557a5080a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557a507ed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557a507ed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557a4a1abd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557a4a10cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557a4a107355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557a4a19dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557a4d16cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557a4d16cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557a4d16cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557a4d16cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557a4d16cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557a4d16cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557a4d16cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557a4d16cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557a4d16cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557a4d16cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557a4f401f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557a4c12eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557a4c139be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557a4bee5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557a4bee5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557a4bee6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557a4bee5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557a4bee5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557a4bee5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557a507efabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557a507f8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557a507e0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557a5080b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7825a2c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557a4a105b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf2,0xb0,0x81,0x9f,0xe7,0xa4,0x80,0xef,0x9d,0x80,0xef,0xa4,0x9f,0xe7,0xa4,0x80,0xef,0xa4,0x9f,0xef,0xa4,0x8d,0xef,0x9e,0x81,0x98,0x21,0xa,0x2d,0xa,0x2d,0xa,0x3a,0xa,0xf3,0xa0,0x81,0x97,0x21,0xa,0xf3,0xa0,0x81,0x97,0x80,0xef,0xa4,0xbf, Step #5: \362\260\201\237\347\244\200\357\235\200\357\244\237\347\244\200\357\244\237\357\244\215\357\236\201\230!\012-\012-\012:\012\363\240\201\227!\012\363\240\201\227\200\357\244\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-35440dd74236ebfa2a74f69a7be1624204dae1f5 Step #5: Base64: 8rCBn+ekgO+dgO+kn+ekgO+kn++kje+egZghCi0KLQo6CvOggZchCvOggZeA76S/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3212 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3296237303 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa1fe2a810, 0x55aa2001401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa20014020,0x55aa21eac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/35440dd74236ebfa2a74f69a7be1624204dae1f5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3935 processed earlier; will process 7094 files now Step #5: ==115708== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aa1691f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa1cf84898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa1cf675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa1cf674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa16925d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa16886b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa16881355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa16917c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa198e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa198e6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa198e6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa198e6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa198e6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa198e6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa198e6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa198e6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa198e6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa198e6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa1bb7bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa188a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa188b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa1865fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa1865fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa18660738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa1865f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa1865f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa1865f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa1cf69abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa1cf72928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa1cf5a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa1cf85112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdbb0b54082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa1687fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x2d,0x54,0x79,0x70,0x65,0x3a,0x6d,0x75,0x6c,0x74,0x69,0x50,0x61,0x72,0x74,0x2f,0x73,0x69,0x67,0x6e,0x65,0x64,0x3b,0x62,0x6f,0x75,0x6e,0x64,0x61,0x72,0x79,0x3d,0x22,0x22,0xa,0xa,0x2d,0x2d,0xa,0xd,0xd, Step #5: Content-Type:multiPart/signed;boundary=\"\"\012\012--\012\015\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-921a2656086d06b98eb66e8e90506e25b7ee7ec9 Step #5: Base64: Q29udGVudC1UeXBlOm11bHRpUGFydC9zaWduZWQ7Ym91bmRhcnk9IiIKCi0tCg0N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3213 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3296712570 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5577035af810, 0x55770379901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557703799020,0x5577056310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/921a2656086d06b98eb66e8e90506e25b7ee7ec9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3936 processed earlier; will process 7093 files now Step #5: #1 pulse cov: 3977 ft: 3978 exec/s: 0 rss: 172Mb Step #5: ==115744== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5576fa0a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557700709898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5577006ec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5577006ec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5576fa0aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5576fa00bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5576fa006355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5576fa09cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576fd06bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576fd06bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576fd06bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576fd06bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576fd06bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576fd06bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576fd06bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576fd06bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576fd06bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576fd06bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5576ff300f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5576fc02db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5576fc038be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5576fbde4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5576fbde4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5576fbde5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5576fbde4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5576fbde4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5576fbde4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5577006eeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5577006f7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5577006df699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55770070a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5f1788e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5576fa004b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x4c,0x36,0x35,0x5c,0x40,0x5c,0x31,0x5c,0x31,0x5c,0x8,0x5c,0x45,0x2f,0x2e,0x5c,0x5d,0x5b,0x3a,0x4e,0x7d,0x5b,0xf3,0x9f,0xbf,0xbf,0x7b,0xf3,0xa0,0x85,0x9e,0x3a,0x5d,0x5c,0x1c,0x5d,0x5c,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x0,0x2f, Step #5: AL65\\@\\1\\1\\\010\\E/.\\][:N}[\363\237\277\277{\363\240\205\236:]\\\034]\\\377\377\377\377\377\377\377\377\000/ Step #5: artifact_prefix='./'; Test unit written to ./oom-d238659b659322e7f96eb05fbe043b4622bff6e3 Step #5: Base64: QUw2NVxAXDFcMVwIXEUvLlxdWzpOfVvzn7+/e/OghZ46XVwcXVz//////////wAv Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3214 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3297234727 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c3aa7e4810, 0x55c3aa9ce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c3aa9ce020,0x55c3ac8660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d238659b659322e7f96eb05fbe043b4622bff6e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3938 processed earlier; will process 7091 files now Step #5: ==115780== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c3a12d99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c3a793e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c3a79215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c3a79214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c3a12dfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c3a1240b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c3a123b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c3a12d1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c3a42a0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c3a42a0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c3a42a0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c3a42a0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c3a42a0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c3a42a0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c3a42a0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c3a42a0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c3a42a0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c3a42a0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c3a6535f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c3a3262b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c3a326dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c3a3019c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c3a3019c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c3a301a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c3a3019874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c3a3019874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c3a3019874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c3a7923abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c3a792c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c3a7914699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c3a793f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f51de902082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c3a1239b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0x93,0xa0,0xef,0x93,0x97,0xef,0x93,0xa0,0xef,0x93,0xa0,0xef,0x93,0x97,0xef,0x93,0xa0,0xef,0x93,0x97,0xef,0x93,0xa0,0xef,0x93,0xa0,0xef,0x93,0x97,0xef,0x93,0xa0,0xef,0x93,0x97,0xef,0x93,0xa0,0xef,0x93,0x97,0xef,0x93,0xa0,0xef,0x93,0x97, Step #5: \357\223\240\357\223\227\357\223\240\357\223\240\357\223\227\357\223\240\357\223\227\357\223\240\357\223\240\357\223\227\357\223\240\357\223\227\357\223\240\357\223\227\357\223\240\357\223\227 Step #5: artifact_prefix='./'; Test unit written to ./oom-7e7df5c484a17f349823d45e0306cfb6abfde392 Step #5: Base64: 75Og75OX75Og75Og75OX75Og75OX75Og75Og75OX75Og75OX75Og75OX75Og75OX Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3215 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3297708825 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d201b2c810, 0x55d201d1601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d201d16020,0x55d203bae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7e7df5c484a17f349823d45e0306cfb6abfde392' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3939 processed earlier; will process 7090 files now Step #5: #1 pulse cov: 3552 ft: 3553 exec/s: 0 rss: 171Mb Step #5: ==115816== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d1f86219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1fec86898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1fec695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1fec694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1f8627d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1f8588b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1f8583355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1f8619c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1fb5e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1fb5e8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1fb5e8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1fb5e8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1fb5e8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1fb5e8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1fb5e8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1fb5e8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1fb5e8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1fb5e8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1fd87df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1fa5aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1fa5b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1fa361c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1fa361c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1fa362738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1fa361874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1fa361874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1fa361874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1fec6babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1fec74928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1fec5c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1fec87112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f561f690082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1f8581b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd3,0x81,0xe6,0x8d,0x8b,0x0,0x6b,0x1,0xd3,0x81,0xe6,0x8d,0x8b,0x53,0x0,0x6b,0x1,0x0,0xd3,0x81,0xe6,0x8d,0x8b,0x53,0x6b,0x0,0xe6,0x8d,0x8b,0x5b,0x7e,0x17,0x0,0xd3,0x81,0xe6,0x8d,0x8b,0x53,0x6b,0x2f,0x0,0xe6,0x8d,0x8b,0x5b,0x7e,0x17, Step #5: \323\201\346\215\213\000k\001\323\201\346\215\213S\000k\001\000\323\201\346\215\213Sk\000\346\215\213[~\027\000\323\201\346\215\213Sk/\000\346\215\213[~\027 Step #5: artifact_prefix='./'; Test unit written to ./oom-26f3c8b3a15710020e81769feab5d2f2dd4cdf84 Step #5: Base64: 04HmjYsAawHTgeaNi1MAawEA04HmjYtTawDmjYtbfhcA04HmjYtTay8A5o2LW34X Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3216 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3298230600 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56359fa5f810, 0x56359fc4901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56359fc49020,0x5635a1ae10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/26f3c8b3a15710020e81769feab5d2f2dd4cdf84' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3941 processed earlier; will process 7088 files now Step #5: ==115852== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5635965549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56359cbb9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56359cb9c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56359cb9c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56359655ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5635964bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5635964b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56359654cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56359951bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56359951bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56359951bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56359951bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56359951bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56359951bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56359951bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56359951bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56359951bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56359951bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56359b7b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5635984ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5635984e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563598294c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563598294c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563598295738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563598294874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563598294874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563598294874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56359cb9eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56359cba7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56359cb8f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56359cbba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5fe9322082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5635964b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xbf,0xae,0xe0,0xa7,0xaf,0xe0,0xaf,0xaf,0xe0,0xaf,0xa7,0xe0,0xaf,0xaf,0xe0,0xae,0xaf,0xe0,0xaf,0xaf,0xe0,0xaf,0xaf,0xe0,0xaf,0xa7,0xe0,0xaf,0xaf,0xe0,0xae,0xaf,0xe0,0xaf,0xaf,0xe0,0xae,0xaf,0xe0,0xaf,0xaf,0xe0,0xaf,0xaf,0xe0,0xa0,0xb3, Step #5: \340\277\256\340\247\257\340\257\257\340\257\247\340\257\257\340\256\257\340\257\257\340\257\257\340\257\247\340\257\257\340\256\257\340\257\257\340\256\257\340\257\257\340\257\257\340\240\263 Step #5: artifact_prefix='./'; Test unit written to ./oom-d811ab12d7e956af945dc8ab1324282685ae2e7b Step #5: Base64: 4L+u4Kev4K+v4K+n4K+v4K6v4K+v4K+v4K+n4K+v4K6v4K+v4K6v4K+v4K+v4KCz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3217 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3298707129 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e66fc32810, 0x55e66fe1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e66fe1c020,0x55e671cb40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d811ab12d7e956af945dc8ab1324282685ae2e7b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3942 processed earlier; will process 7087 files now Step #5: ==115888== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e6667279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e66cd8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e66cd6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e66cd6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e66672dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e66668eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e666689355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e66671fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e6696eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e6696eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e6696eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e6696eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e6696eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e6696eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e6696eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e6696eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e6696eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e6696eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e66b983f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e6686b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e6686bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e668467c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e668467c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e668468738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e668467874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e668467874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e668467874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e66cd71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e66cd7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e66cd62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e66cd8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe3ef13e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e666687b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xee,0x9b,0x8f,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x93,0x8f,0xe1,0x8b,0x8f,0xe1,0xb4,0x9b,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x93,0x8f,0xe1,0x8b,0x8f,0xe1,0xb4,0x9b, Step #5: \356\233\217\341\233\217\341\213\217\356\233\217\341\233\217\341\213\217\356\233\217\341\223\217\341\213\217\341\264\233\341\233\217\341\213\217\356\233\217\341\223\217\341\213\217\341\264\233 Step #5: artifact_prefix='./'; Test unit written to ./oom-eded9e7fd2c19b65605ca33bc270579fa3bc11cf Step #5: Base64: 7puP4ZuP4YuP7puP4ZuP4YuP7puP4ZOP4YuP4bSb4ZuP4YuP7puP4ZOP4YuP4bSb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3218 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3299187968 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5637209f0810, 0x563720bda01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563720bda020,0x563722a720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eded9e7fd2c19b65605ca33bc270579fa3bc11cf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3943 processed earlier; will process 7086 files now Step #5: ==115924== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5637174e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56371db4a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56371db2d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56371db2d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5637174ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56371744cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563717447355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5637174ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56371a4acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56371a4acf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56371a4acf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56371a4acf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56371a4acf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56371a4acf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56371a4acf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56371a4acf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56371a4acf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56371a4acf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56371c741f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56371946eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563719479be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563719225c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563719225c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563719226738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563719225874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563719225874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563719225874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56371db2fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56371db38928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56371db20699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56371db4b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f17a72f5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563717445b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0x81,0x85,0xef,0xa6,0x89,0xef,0x81,0x85,0xef,0xa6,0x81,0xef,0x81,0x85,0xef,0xa6,0x81,0xef,0x81,0x85,0xef,0xa6,0x81,0xef,0x81,0x85,0xef,0xa6,0x89,0xef,0x81,0x85,0xef,0xa6,0x81,0xef,0x81,0x85,0xef,0xa6,0x81,0xef,0x81,0x85,0xef,0xa6,0x81, Step #5: \357\201\205\357\246\211\357\201\205\357\246\201\357\201\205\357\246\201\357\201\205\357\246\201\357\201\205\357\246\211\357\201\205\357\246\201\357\201\205\357\246\201\357\201\205\357\246\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-8925966e3b3dcbac7ca95963ef978c85d895512d Step #5: Base64: 74GF76aJ74GF76aB74GF76aB74GF76aB74GF76aJ74GF76aB74GF76aB74GF76aB Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3219 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3299673991 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563960e5a810, 0x56396104401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563961044020,0x563962edc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8925966e3b3dcbac7ca95963ef978c85d895512d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3944 processed earlier; will process 7085 files now Step #5: #1 pulse cov: 3765 ft: 3766 exec/s: 0 rss: 173Mb Step #5: ==115960== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56395794f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56395dfb4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56395df975dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56395df974fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563957955d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5639578b6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5639578b1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563957947c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56395a916f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56395a916f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56395a916f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56395a916f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56395a916f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56395a916f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56395a916f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56395a916f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56395a916f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56395a916f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56395cbabf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5639598d8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5639598e3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56395968fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56395968fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563959690738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56395968f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56395968f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56395968f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56395df99abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56395dfa2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56395df8a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56395dfb5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa1825be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5639578afb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0xd,0xd,0x4e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd,0x24,0xd,0xd,0x4e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd,0x28,0xd,0xd,0x4e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd, Step #5: (\015\015N\015\015$\015\015n\015\015$\015\015N\015\015$\015\015n\015\015(\015\015N\015\015$\015\015n\015\015$\015\015n\015\015$\015\015n\015\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-b81bcaf92ed5694d26b7dc2400e1cf54fac3ec98 Step #5: Base64: KA0NTg0NJA0Nbg0NJA0NTg0NJA0Nbg0NKA0NTg0NJA0Nbg0NJA0Nbg0NJA0Nbg0N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3220 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3300200101 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55faaf094810, 0x55faaf27e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55faaf27e020,0x55fab11160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b81bcaf92ed5694d26b7dc2400e1cf54fac3ec98' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3946 processed earlier; will process 7083 files now Step #5: ==115996== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55faa5b899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55faac1ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55faac1d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55faac1d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55faa5b8fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55faa5af0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55faa5aeb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55faa5b81c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55faa8b50f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55faa8b50f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55faa8b50f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55faa8b50f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55faa8b50f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55faa8b50f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55faa8b50f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55faa8b50f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55faa8b50f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55faa8b50f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55faaade5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55faa7b12b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55faa7b1dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55faa78c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55faa78c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55faa78ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55faa78c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55faa78c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55faa78c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55faac1d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55faac1dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55faac1c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55faac1ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff49202a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55faa5ae9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8,0xe2,0x80,0xa8, Step #5: \342\200\250\342\200\250\342\200\250\342\200\250\342\200\250\342\200\250\342\200\250\342\200\250\342\200\250\342\200\250\342\200\250\342\200\250\342\200\250\342\200\250\342\200\250\342\200\250 Step #5: artifact_prefix='./'; Test unit written to ./oom-96c8378b4a42fc2d4ae1e25f414e9c4f58e6de36 Step #5: Base64: 4oCo4oCo4oCo4oCo4oCo4oCo4oCo4oCo4oCo4oCo4oCo4oCo4oCo4oCo4oCo4oCo Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3221 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3300664997 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c61a6f0810, 0x55c61a8da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c61a8da020,0x55c61c7720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/96c8378b4a42fc2d4ae1e25f414e9c4f58e6de36' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3947 processed earlier; will process 7082 files now Step #5: ==116032== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c6111e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c61784a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c61782d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c61782d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c6111ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c61114cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c611147355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c6111ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c6141acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c6141acf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c6141acf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c6141acf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c6141acf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c6141acf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c6141acf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c6141acf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c6141acf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c6141acf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c616441f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c61316eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c613179be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c612f25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c612f25c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c612f26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c612f25874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c612f25874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c612f25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c61782fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c617838928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c617820699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c61784b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd06a660082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c611145b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9, Step #5: \342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251 Step #5: artifact_prefix='./'; Test unit written to ./oom-96847397c98b4f8499e86f4e2926394fe7d849ac Step #5: Base64: 4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3222 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3301131226 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563ff3341810, 0x563ff352b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563ff352b020,0x563ff53c30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/96847397c98b4f8499e86f4e2926394fe7d849ac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3948 processed earlier; will process 7081 files now Step #5: ==116068== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563fe9e369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563ff049b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563ff047e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563ff047e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563fe9e3cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563fe9d9db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563fe9d98355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563fe9e2ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563fecdfdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563fecdfdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563fecdfdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563fecdfdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563fecdfdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563fecdfdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563fecdfdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563fecdfdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563fecdfdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563fecdfdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563fef092f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563febdbfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563febdcabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563febb76c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563febb76c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563febb77738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563febb76874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563febb76874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563febb76874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563ff0480abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563ff0489928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563ff0471699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563ff049c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f25cf84d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563fe9d96b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x9a,0x9d,0xe1,0x9a,0x98,0xe1,0x9a,0x9d,0xe1,0x9a,0x98,0xe1,0x9a,0x9d,0xe1,0x9a,0x98,0xe1,0x9a,0x98,0xe1,0x9a,0x9c,0xe1,0x9a,0x9d,0xe1,0x9a,0x9c,0xe1,0x9a,0x9d,0xe1,0x9a,0x98,0xe1,0x9a,0x98,0xe1,0x9a,0x9c,0xe1,0x9a,0x9d,0xe1,0x9a,0x9c, Step #5: \341\232\235\341\232\230\341\232\235\341\232\230\341\232\235\341\232\230\341\232\230\341\232\234\341\232\235\341\232\234\341\232\235\341\232\230\341\232\230\341\232\234\341\232\235\341\232\234 Step #5: artifact_prefix='./'; Test unit written to ./oom-983a48518ff586a686d9bd1ecec00c267e425b11 Step #5: Base64: 4Zqd4ZqY4Zqd4ZqY4Zqd4ZqY4ZqY4Zqc4Zqd4Zqc4Zqd4ZqY4ZqY4Zqc4Zqd4Zqc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3223 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3301612601 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56222a45f810, 0x56222a64901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56222a649020,0x56222c4e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/983a48518ff586a686d9bd1ecec00c267e425b11' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3949 processed earlier; will process 7080 files now Step #5: ==116104== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562220f549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5622275b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56222759c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56222759c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562220f5ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562220ebbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562220eb6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562220f4cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562223f1bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562223f1bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562223f1bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562223f1bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562223f1bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562223f1bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562223f1bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562223f1bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562223f1bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562223f1bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5622261b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562222eddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562222ee8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562222c94c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562222c94c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562222c95738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562222c94874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562222c94874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562222c94874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56222759eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5622275a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56222758f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5622275ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe232467082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562220eb4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x33,0x32,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x34,0x5c,0x37,0x37,0x5c,0x37,0x36,0x5c,0x37,0x36,0x5c,0x37,0x37,0x5c,0x35,0x33, Step #5: \\77\\77\\77\\77\\77\\77\\32\\77\\77\\77\\74\\77\\76\\76\\77\\53 Step #5: artifact_prefix='./'; Test unit written to ./oom-19e1c0b6d9111490f3565930728a0a60620e6f87 Step #5: Base64: XDc3XDc3XDc3XDc3XDc3XDc3XDMyXDc3XDc3XDc3XDc0XDc3XDc2XDc2XDc3XDUz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3224 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3302088003 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55646abf0810, 0x55646adda01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55646adda020,0x55646cc720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/19e1c0b6d9111490f3565930728a0a60620e6f87' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3950 processed earlier; will process 7079 files now Step #5: #1 pulse cov: 3916 ft: 3917 exec/s: 0 rss: 173Mb Step #5: ==116140== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5564616e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556467d4a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556467d2d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556467d2d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564616ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55646164cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556461647355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564616ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564646acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564646acf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564646acf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564646acf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564646acf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564646acf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564646acf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564646acf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564646acf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564646acf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556466941f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55646366eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556463679be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556463425c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556463425c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556463426738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556463425874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556463425874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556463425874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556467d2fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556467d38928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556467d20699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556467d4b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f083b37c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556461645b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1f,0x52,0x27,0x27,0x27,0x3a,0x0,0xa,0xa,0xa,0xa,0xe2,0x81,0x97,0xe2,0x90,0xa7,0xe2,0x81,0x97,0xe2,0x90,0xa7,0xe2,0x81,0x97,0xe2,0x90,0xae,0xe2,0x81,0x97,0xe2,0x90,0xa7,0xe2,0x89,0xae,0x27,0x27,0x27,0xe2,0x81,0x97,0x4b,0xe2,0x90,0xa7, Step #5: \037R''':\000\012\012\012\012\342\201\227\342\220\247\342\201\227\342\220\247\342\201\227\342\220\256\342\201\227\342\220\247\342\211\256'''\342\201\227K\342\220\247 Step #5: artifact_prefix='./'; Test unit written to ./oom-e5ce234c0c262434b8fe7052d37b82bd78b13573 Step #5: Base64: H1InJyc6AAoKCgrigZfikKfigZfikKfigZfikK7igZfikKfiia4nJyfigZdL4pCn Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3225 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3302611648 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5609a9fef810, 0x5609aa1d901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5609aa1d9020,0x5609ac0710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e5ce234c0c262434b8fe7052d37b82bd78b13573' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3952 processed earlier; will process 7077 files now Step #5: ==116176== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5609a0ae49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5609a7149898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5609a712c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5609a712c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5609a0aead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5609a0a4bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5609a0a46355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5609a0adcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5609a3aabf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5609a3aabf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5609a3aabf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5609a3aabf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5609a3aabf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5609a3aabf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5609a3aabf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5609a3aabf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5609a3aabf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5609a3aabf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5609a5d40f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5609a2a6db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5609a2a78be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5609a2824c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5609a2824c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5609a2825738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5609a2824874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5609a2824874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5609a2824874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5609a712eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5609a7137928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5609a711f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5609a714a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f358d0e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5609a0a44b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x58,0x23,0x33,0x33,0x5c,0x53,0x5c,0x5d,0x5c,0x55,0x5c,0x55,0x5c,0x3d,0x5c,0x53,0x28,0x3f,0x69,0x29,0x5b,0x4b,0x26,0x26,0x7b,0x5d,0x43,0x64,0x2b,0x65,0x52,0x2b,0x32,0x32,0x36,0x5b,0x33,0x5b,0x5e,0x5c,0x70,0x38,0x78,0x31,0x43,0x29,0x27, Step #5: MX#33\\S\\]\\U\\U\\=\\S(?i)[K&&{]Cd+eR+226[3[^\\p8x1C)' Step #5: artifact_prefix='./'; Test unit written to ./oom-b33d75cb2198ad76d8e0f9711912d6a041f0ef48 Step #5: Base64: TVgjMzNcU1xdXFVcVVw9XFMoP2kpW0smJntdQ2QrZVIrMjI2WzNbXlxwOHgxQykn Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3226 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3303094044 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e73a62b810, 0x55e73a81501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e73a815020,0x55e73c6ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b33d75cb2198ad76d8e0f9711912d6a041f0ef48' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3953 processed earlier; will process 7076 files now Step #5: ==116212== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e7311209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e737785898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7377685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7377684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e731126d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e731087b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e731082355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e731118c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e7340e7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e7340e7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e7340e7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e7340e7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e7340e7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e7340e7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e7340e7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e7340e7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e7340e7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e7340e7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e73637cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e7330a9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e7330b4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e732e60c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e732e60c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e732e61738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e732e60874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e732e60874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e732e60874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e73776aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e737773928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e73775b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e737786112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ee9579082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e731080b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x3a,0xdd,0xba,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x3a,0xdd,0xba,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x3a,0xdd,0xba,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x3a,0xdd,0xba,0x5d, Step #5: \012\012:\010\012\006[::\335\272]\012\012:\010\012\006[::\335\272]\012\012:\010\012\006[::\335\272]\012\012:\010\012\006[::\335\272] Step #5: artifact_prefix='./'; Test unit written to ./oom-11d4d87c34b18aee885bc3fa7d656421e453513c Step #5: Base64: Cgo6CAoGWzo63bpdCgo6CAoGWzo63bpdCgo6CAoGWzo63bpdCgo6CAoGWzo63bpd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3227 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3303577972 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55abaf829810, 0x55abafa1301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55abafa13020,0x55abb18ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/11d4d87c34b18aee885bc3fa7d656421e453513c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3954 processed earlier; will process 7075 files now Step #5: ==116248== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aba631e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55abac983898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55abac9665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55abac9664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aba6324d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aba6285b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aba6280355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aba6316c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aba92e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aba92e5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aba92e5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aba92e5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aba92e5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aba92e5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aba92e5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aba92e5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aba92e5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aba92e5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55abab57af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aba82a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aba82b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aba805ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aba805ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aba805f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aba805e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aba805e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aba805e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55abac968abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55abac971928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55abac959699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55abac984112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe3942be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aba627eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xd2,0xd2,0x81,0xf3,0xd2,0xa0,0xba,0xa0,0xf5,0xa,0x2f,0xa,0x2f,0xa,0x60,0x60,0x20,0x20,0x20,0x60,0xa,0x9, Step #5: `\342\200\210-\000`\012\363\240\201\272/\012`\342\200\210-\000`\012\363\240\201\272\322\322\201\363\322\240\272\240\365\012/\012/\012`` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-1831cc86c2103a981a78d73ee77174d73523a7a4 Step #5: Base64: YOKAiC0AYArzoIG6Lwpg4oCILQBgCvOggbrS0oHz0qC6oPUKLwovCmBgICAgYAoJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3228 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3304174600 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5613e8f3e810, 0x5613e912801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5613e9128020,0x5613eafc00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1831cc86c2103a981a78d73ee77174d73523a7a4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3955 processed earlier; will process 7074 files now Step #5: ==116284== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5613dfa339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5613e6098898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613e607b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613e607b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5613dfa39d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5613df99ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5613df995355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5613dfa2bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5613e29faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5613e29faf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5613e29faf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5613e29faf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5613e29faf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5613e29faf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5613e29faf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5613e29faf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5613e29faf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5613e29faf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5613e4c8ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5613e19bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5613e19c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5613e1773c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5613e1773c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5613e1774738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5613e1773874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5613e1773874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5613e1773874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5613e607dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5613e6086928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5613e606e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5613e6099112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3a4482082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5613df993b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0x5,0xb,0xb,0xb,0xb,0xb,0x5,0xb,0xb,0xb,0xa,0xb,0x5,0xb,0xb,0xb,0xb,0xb,0x5,0xb,0xb,0xb,0xb,0xb,0x5,0xb,0xb,0xb,0xb,0xb,0x5,0xb,0xb,0xb,0xb,0xb,0x5,0xb,0xb,0xb,0xb,0xb,0x5,0xb,0xb,0xb,0xb, Step #5: \013\005\013\013\013\013\013\005\013\013\013\012\013\005\013\013\013\013\013\005\013\013\013\013\013\005\013\013\013\013\013\005\013\013\013\013\013\005\013\013\013\013\013\005\013\013\013\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-d245e4c64c30e9a39809c264d905d7e06f9217c7 Step #5: Base64: CwULCwsLCwULCwsKCwULCwsLCwULCwsLCwULCwsLCwULCwsLCwULCwsLCwULCwsL Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3229 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3304651530 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f28d587810, 0x55f28d77101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f28d771020,0x55f28f6090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d245e4c64c30e9a39809c264d905d7e06f9217c7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3956 processed earlier; will process 7073 files now Step #5: ==116320== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f28407c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f28a6e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f28a6c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f28a6c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f284082d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f283fe3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f283fde355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f284074c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f287043f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f287043f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f287043f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f287043f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f287043f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f287043f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f287043f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f287043f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f287043f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f287043f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f2892d8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f286005b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f286010be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f285dbcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f285dbcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f285dbd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f285dbc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f285dbc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f285dbc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f28a6c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f28a6cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f28a6b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f28a6e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc3f61eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f283fdcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xeb,0xb6,0xb8,0xe1,0x86,0xab,0xeb,0xb6,0xb8,0xe1,0x86,0xab,0xeb,0xb6,0xb8,0xe1,0x86,0xab,0xeb,0xb6,0xb8,0xe1,0x86,0xab,0xeb,0xb6,0xb8,0xe1,0x86,0xab,0xeb,0xb6,0xb8,0xe1,0x86,0xab,0xeb,0xb6,0xb8,0xe1,0x86,0xa9,0xeb,0xb6,0xb8,0xe1,0x86,0xab, Step #5: \353\266\270\341\206\253\353\266\270\341\206\253\353\266\270\341\206\253\353\266\270\341\206\253\353\266\270\341\206\253\353\266\270\341\206\253\353\266\270\341\206\251\353\266\270\341\206\253 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ba4a29ee10879a37704b6b77bb583b757783b23 Step #5: Base64: 67a44Yar67a44Yar67a44Yar67a44Yar67a44Yar67a44Yar67a44Yap67a44Yar Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3230 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3305131092 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563ce827c810, 0x563ce846601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563ce8466020,0x563cea2fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ba4a29ee10879a37704b6b77bb583b757783b23' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3957 processed earlier; will process 7072 files now Step #5: ==116356== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563cded719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563ce53d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563ce53b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563ce53b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563cded77d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563cdecd8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563cdecd3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563cded69c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563ce1d38f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563ce1d38f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563ce1d38f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563ce1d38f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563ce1d38f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563ce1d38f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563ce1d38f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563ce1d38f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563ce1d38f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563ce1d38f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563ce3fcdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563ce0cfab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563ce0d05be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563ce0ab1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563ce0ab1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563ce0ab2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563ce0ab1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563ce0ab1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563ce0ab1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563ce53bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563ce53c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563ce53ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563ce53d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7e656d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563cdecd1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x2d,0x54,0x72,0x61,0x6e,0x73,0x66,0x65,0x72,0x2d,0x45,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3a,0x62,0x61,0x73,0x65,0x36,0x34,0xa,0xa,0x43,0x6f,0x6d,0x75,0xa,0x65,0x65,0x38,0x4b,0xa,0x43,0x6f,0x72,0x6e, Step #5: Content-Transfer-Encoding:base64\012\012Comu\012ee8K\012Corn Step #5: artifact_prefix='./'; Test unit written to ./oom-87ee20ddb21218b8bcfa19deac55f048c4681142 Step #5: Base64: Q29udGVudC1UcmFuc2Zlci1FbmNvZGluZzpiYXNlNjQKCkNvbXUKZWU4SwpDb3Ju Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3231 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3305609994 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a672c33810, 0x55a672e1d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a672e1d020,0x55a674cb50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87ee20ddb21218b8bcfa19deac55f048c4681142' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3958 processed earlier; will process 7071 files now Step #5: ==116392== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a6697289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a66fd8d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a66fd705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a66fd704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a66972ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a66968fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a66968a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a669720c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a66c6eff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a66c6eff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a66c6eff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a66c6eff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a66c6eff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a66c6eff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a66c6eff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a66c6eff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a66c6eff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a66c6eff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a66e984f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a66b6b1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a66b6bcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a66b468c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a66b468c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a66b469738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a66b468874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a66b468874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a66b468874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a66fd72abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a66fd7b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a66fd63699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a66fd8e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e1c9c9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a669688b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9, Step #5: 0.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-ddab00c12d6b9e480b1e50351e1b8bf5ff712fa3 Step #5: Base64: MC4JMC4JMC4JMC4JMC4JMC4JMC4JMC4JMC4JMC4JMC4JMC4JMC4JMC4JMC4JMC4J Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3232 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3306118210 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5622b3e8f810, 0x5622b407901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622b4079020,0x5622b5f110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ddab00c12d6b9e480b1e50351e1b8bf5ff712fa3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3959 processed earlier; will process 7070 files now Step #5: ==116428== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5622aa9849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5622b0fe9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5622b0fcc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5622b0fcc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5622aa98ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5622aa8ebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5622aa8e6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5622aa97cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5622ad94bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5622ad94bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5622ad94bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5622ad94bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5622ad94bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5622ad94bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5622ad94bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5622ad94bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5622ad94bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5622ad94bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5622afbe0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5622ac90db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5622ac918be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5622ac6c4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5622ac6c4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5622ac6c5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5622ac6c4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5622ac6c4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5622ac6c4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5622b0fceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5622b0fd7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5622b0fbf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5622b0fea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f73b177f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5622aa8e4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x2f,0x45,0x3c,0x2f,0x45,0x3c,0x2f,0x45,0x3c,0x2f,0x45,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x2f,0x45,0x3c,0x2f,0x45,0x3c,0x2f,0x45,0x3c,0x2f,0x45, Step #5: <E><E><E><E><E><E></E</E</E</E<E><E></E</E</E</E Step #5: artifact_prefix='./'; Test unit written to ./oom-2e7467e730eaecdc987fa3114aa7d58896ea7174 Step #5: Base64: PEU+PEU+PEU+PEU+PEU+PEU+PC9FPC9FPC9FPC9FPEU+PEU+PC9FPC9FPC9FPC9F Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3233 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3306598108 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5618df75f810, 0x5618df94901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5618df949020,0x5618e17e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2e7467e730eaecdc987fa3114aa7d58896ea7174' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3960 processed earlier; will process 7069 files now Step #5: ==116464== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5618d62549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5618dc8b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5618dc89c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5618dc89c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5618d625ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5618d61bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5618d61b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5618d624cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5618d921bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5618d921bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5618d921bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5618d921bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5618d921bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5618d921bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5618d921bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5618d921bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5618d921bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5618d921bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5618db4b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5618d81ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5618d81e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5618d7f94c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5618d7f94c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5618d7f95738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5618d7f94874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5618d7f94874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5618d7f94874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5618dc89eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5618dc8a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5618dc88f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5618dc8ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e397e2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5618d61b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x22,0x24,0x24,0x20,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x37, Step #5: ID$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$\"$$ \377\377\377\377\377\377\3777 Step #5: artifact_prefix='./'; Test unit written to ./oom-f655c27f4ab2cb2a38c67503a45021f31874de78 Step #5: Base64: SUQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkIiQkIP////////83 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3234 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3307087372 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564ceecdf810, 0x564ceeec901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564ceeec9020,0x564cf0d610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f655c27f4ab2cb2a38c67503a45021f31874de78' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3961 processed earlier; will process 7068 files now Step #5: ==116500== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564ce57d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564cebe39898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564cebe1c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564cebe1c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ce57dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ce573bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ce5736355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ce57ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564ce879bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564ce879bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564ce879bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564ce879bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564ce879bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564ce879bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564ce879bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564ce879bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564ce879bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564ce879bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564ceaa30f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564ce775db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564ce7768be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564ce7514c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564ce7514c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564ce7515738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564ce7514874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564ce7514874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564ce7514874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564cebe1eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564cebe27928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564cebe0f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564cebe3a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6929192082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ce5734b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa, Step #5: \\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-7068faa2b0970ee0f7f178d0c0e1418e374efa26 Step #5: Base64: XAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3235 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3307568430 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55da61a8f810, 0x55da61c7901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55da61c79020,0x55da63b110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7068faa2b0970ee0f7f178d0c0e1418e374efa26' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3962 processed earlier; will process 7067 files now Step #5: ==116536== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55da585849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55da5ebe9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55da5ebcc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55da5ebcc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55da5858ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55da584ebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55da584e6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55da5857cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55da5b54bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55da5b54bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55da5b54bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55da5b54bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55da5b54bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55da5b54bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55da5b54bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55da5b54bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55da5b54bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55da5b54bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55da5d7e0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55da5a50db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55da5a518be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55da5a2c4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55da5a2c4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55da5a2c5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55da5a2c4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55da5a2c4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55da5a2c4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55da5ebceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55da5ebd7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55da5ebbf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55da5ebea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f631a0d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55da584e4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x1,0x1,0x1,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40, Step #5: \001\001\001\001@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ Step #5: artifact_prefix='./'; Test unit written to ./oom-d9f9286eb6293c8f3604c6e1b99429c7cc39c045 Step #5: Base64: AQEBAUBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3236 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3308052990 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5577f1093810, 0x5577f127d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5577f127d020,0x5577f31150e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d9f9286eb6293c8f3604c6e1b99429c7cc39c045' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3963 processed earlier; will process 7066 files now Step #5: ==116572== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5577e7b889c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5577ee1ed898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5577ee1d05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5577ee1d04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5577e7b8ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5577e7aefb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5577e7aea355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5577e7b80c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5577eab4ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5577eab4ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5577eab4ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5577eab4ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5577eab4ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5577eab4ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5577eab4ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5577eab4ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5577eab4ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5577eab4ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5577ecde4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5577e9b11b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5577e9b1cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5577e98c8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5577e98c8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5577e98c9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5577e98c8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5577e98c8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5577e98c8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5577ee1d2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5577ee1db928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5577ee1c3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5577ee1ee112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1238806082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5577e7ae8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd,0x2d,0x2d,0xd, Step #5: --\015--\015--\015--\015--\015--\015--\015--\015--\015--\015--\015--\015--\015--\015--\015--\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-0aa0df1992c605ae16de1269eb26db246b53f287 Step #5: Base64: LS0NLS0NLS0NLS0NLS0NLS0NLS0NLS0NLS0NLS0NLS0NLS0NLS0NLS0NLS0NLS0N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3237 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3308538067 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe28fbe810, 0x55fe291a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe291a8020,0x55fe2b0400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0aa0df1992c605ae16de1269eb26db246b53f287' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3964 processed earlier; will process 7065 files now Step #5: ==116608== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fe1fab39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe26118898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe260fb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe260fb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe1fab9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe1fa1ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe1fa15355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe1faabc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe22a7af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe22a7af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe22a7af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe22a7af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe22a7af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe22a7af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe22a7af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe22a7af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe22a7af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe22a7af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe24d0ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe21a3cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe21a47be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe217f3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe217f3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe217f4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe217f3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe217f3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe217f3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe260fdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe26106928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe260ee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe26119112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa73c972082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe1fa13b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x83,0x8c,0xe3,0x81,0x8d,0xe3,0x83,0x8d,0xe3,0x83,0x8c,0xe3,0x83,0x8c,0xe3,0x81,0x8d,0xe3,0x83,0x8d,0xe3,0x83,0x8d,0xe3,0x83,0x8c,0xe3,0x81,0x8d,0xe3,0x83,0x8d,0xe3,0x83,0x8c,0xe3,0x83,0x8c,0xe3,0x81,0x8d,0xe3,0x83,0x8d,0xe3,0x83,0x8d, Step #5: \343\203\214\343\201\215\343\203\215\343\203\214\343\203\214\343\201\215\343\203\215\343\203\215\343\203\214\343\201\215\343\203\215\343\203\214\343\203\214\343\201\215\343\203\215\343\203\215 Step #5: artifact_prefix='./'; Test unit written to ./oom-9317838abff953cb6dd243a01643b4dbf4cb7543 Step #5: Base64: 44OM44GN44ON44OM44OM44GN44ON44ON44OM44GN44ON44OM44OM44GN44ON44ON Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3238 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3309027073 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55faafc06810, 0x55faafdf001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55faafdf0020,0x55fab1c880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9317838abff953cb6dd243a01643b4dbf4cb7543' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3965 processed earlier; will process 7064 files now Step #5: #1 pulse cov: 10958 ft: 10959 exec/s: 0 rss: 191Mb Step #5: ==116644== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55faa66fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55faacd60898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55faacd435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55faacd434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55faa6701d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55faa6662b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55faa665d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55faa66f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55faa96c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55faa96c2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55faa96c2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55faa96c2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55faa96c2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55faa96c2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55faa96c2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55faa96c2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55faa96c2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55faa96c2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55faab957f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55faa8684b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55faa868fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55faa843bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55faa843bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55faa843c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55faa843b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55faa843b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55faa843b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55faacd45abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55faacd4e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55faacd36699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55faacd61112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe5bea2d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55faa665bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x24,0x24,0xcb,0x91,0x23,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x23,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0xdd,0xdb,0xdb,0xcc,0x3,0x7e,0x47,0x46,0x44,0x7e,0x91,0x47, Step #5: ID$$\313\221#$$$$$$$#$$$$$$$$$$$$$$$$$$$$$\335\333\333\314\003~GFD~\221G Step #5: artifact_prefix='./'; Test unit written to ./oom-03b8f18491634387ebe48c508a412e1e075c3e73 Step #5: Base64: SUQkJMuRIyQkJCQkJCQjJCQkJCQkJCQkJCQkJCQkJCQkJCQk3dvbzAN+R0ZEfpFH Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3239 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3309574646 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643bc73f810, 0x5643bc92901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643bc929020,0x5643be7c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03b8f18491634387ebe48c508a412e1e075c3e73' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3967 processed earlier; will process 7062 files now Step #5: #1 pulse cov: 3715 ft: 3716 exec/s: 0 rss: 172Mb Step #5: ==116680== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643b32349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643b9899898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643b987c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643b987c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643b323ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643b319bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643b3196355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643b322cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643b61fbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643b61fbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643b61fbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643b61fbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643b61fbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643b61fbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643b61fbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643b61fbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643b61fbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643b61fbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643b8490f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643b51bdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643b51c8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643b4f74c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643b4f74c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643b4f75738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643b4f74874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643b4f74874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643b4f74874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643b987eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643b9887928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643b986f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643b989a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27766d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643b3194b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xa8,0x8e,0xe0,0xac,0x8e,0xe0,0xa7,0x8e,0xe0,0xa7,0x8d,0xe0,0xac,0x8e,0xe0,0xa7,0x8e,0xe0,0xa7,0x8e,0xe0,0xa8,0x8e,0xe0,0xac,0x8e,0xe0,0xa7,0x8e,0xe0,0xa7,0x8d,0xe0,0xac,0x8e,0xe0,0xa7,0x8e,0xe0,0xa7,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e, Step #5: \340\250\216\340\254\216\340\247\216\340\247\215\340\254\216\340\247\216\340\247\216\340\250\216\340\254\216\340\247\216\340\247\215\340\254\216\340\247\216\340\247\216\340\250\216\340\250\216 Step #5: artifact_prefix='./'; Test unit written to ./oom-01e8d96ac356db8770ae3dbdcc4b5a4675ade8aa Step #5: Base64: 4KiO4KyO4KeO4KeN4KyO4KeO4KeO4KiO4KyO4KeO4KeN4KyO4KeO4KeO4KiO4KiO Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3240 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3310099948 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dc50d4a810, 0x55dc50f3401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dc50f34020,0x55dc52dcc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01e8d96ac356db8770ae3dbdcc4b5a4675ade8aa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3969 processed earlier; will process 7060 files now Step #5: ==116716== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dc4783f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dc4dea4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dc4de875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dc4de874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dc47845d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dc477a6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dc477a1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dc47837c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dc4a806f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dc4a806f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dc4a806f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dc4a806f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dc4a806f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dc4a806f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dc4a806f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dc4a806f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dc4a806f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dc4a806f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dc4ca9bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dc497c8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dc497d3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dc4957fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dc4957fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dc49580738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dc4957f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dc4957f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dc4957f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dc4de89abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dc4de92928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dc4de7a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dc4dea5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f225c913082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dc4779fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x8,0x0,0x7,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x7,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2e,0x0,0x2e,0x2b,0x42,0xdb,0xbe,0x7c,0xdb,0xbe,0x2b,0x2b,0x2b, Step #5: - \010\000\007\000\000\000\000\000\000\000\000\000\000\000\000\000\010\000\007\000\000\000\000\000\000\000\000\000\000\000\000\000\000.\000.+B\333\276|\333\276+++ Step #5: artifact_prefix='./'; Test unit written to ./oom-45d6b93a9c013294c2e594c56cecb624399d9279 Step #5: Base64: LSAIAAcAAAAAAAAAAAAAAAAACAAHAAAAAAAAAAAAAAAAAAAuAC4rQtu+fNu+Kysr Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3241 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3310586264 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56238896a810, 0x562388b5401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562388b54020,0x56238a9ec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/45d6b93a9c013294c2e594c56cecb624399d9279' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3970 processed earlier; will process 7059 files now Step #5: #1 pulse cov: 3761 ft: 3762 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 4617 ft: 4843 exec/s: 0 rss: 176Mb Step #5: ==116752== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56237f45f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562385ac4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562385aa75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562385aa74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56237f465d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56237f3c6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56237f3c1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56237f457c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562382426f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562382426f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562382426f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562382426f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562382426f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562382426f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562382426f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562382426f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562382426f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562382426f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5623846bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5623813e8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5623813f3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56238119fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56238119fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5623811a0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56238119f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56238119f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56238119f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562385aa9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562385ab2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562385a9a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562385ac5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f73b622b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56237f3bfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf, Step #5: \"\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-4274d75db2b56ce4d5a000f378d76004bcd84ce1 Step #5: Base64: Iu+7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7vw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3242 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3311181447 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c93014e810, 0x55c93033801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c930338020,0x55c9321d00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4274d75db2b56ce4d5a000f378d76004bcd84ce1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3974 processed earlier; will process 7055 files now Step #5: ==116788== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c926c439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c92d2a8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c92d28b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c92d28b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c926c49d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c926baab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c926ba5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c926c3bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c929c0af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c929c0af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c929c0af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c929c0af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c929c0af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c929c0af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c929c0af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c929c0af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c929c0af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c929c0af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c92be9ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c928bccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c928bd7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c928983c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c928983c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c928984738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c928983874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c928983874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c928983874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c92d28dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c92d296928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c92d27e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c92d2a9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f649a1b9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c926ba3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0x95,0xd9,0x8b,0xda,0x98,0xd9,0x95,0xdd,0x95,0xd9,0x8b,0xd9,0x98,0x20,0xd9,0x8f,0xd9,0x95,0xd9,0x8b,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e,0x27,0x3c,0x2f, Step #5: <svg><text>\331\225\331\213\332\230\331\225\335\225\331\213\331\230 \331\217\331\225\331\213'</text></svg>'</ Step #5: artifact_prefix='./'; Test unit written to ./oom-d675954d8255b957cec51d991a8ee748891ecf89 Step #5: Base64: PHN2Zz48dGV4dD7ZldmL2pjZld2V2YvZmCDZj9mV2YsnPC90ZXh0Pjwvc3ZnPic8Lw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3243 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3311668769 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557c56cde810, 0x557c56ec801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557c56ec8020,0x557c58d600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d675954d8255b957cec51d991a8ee748891ecf89' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3975 processed earlier; will process 7054 files now Step #5: ==116824== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557c4d7d39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557c53e38898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557c53e1b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557c53e1b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557c4d7d9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557c4d73ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557c4d735355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557c4d7cbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557c5079af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557c5079af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557c5079af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557c5079af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557c5079af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557c5079af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557c5079af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557c5079af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557c5079af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557c5079af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557c52a2ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557c4f75cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557c4f767be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557c4f513c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557c4f513c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557c4f514738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557c4f513874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557c4f513874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557c4f513874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557c53e1dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557c53e26928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557c53e0e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557c53e39112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0daf959082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557c4d733b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x32,0x37,0x36,0x37,0x2d,0x3d,0x3c,0x30,0x27,0x27,0x2f,0x25,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x20,0x73,0x65,0x72,0x69,0x66,0x27,0x27,0x2f,0x27,0x2f,0x27,0x65,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $32767-=<0''/%'''/'''exp'N'2-\007 serif''/'/'e'.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-5641cae842387b98f552c0e6bdbe93a73cbce908 Step #5: Base64: JDMyNzY3LT08MCcnLyUnJycvJycnZXhwJ04nMi0HIHNlcmlmJycvJy8nZScuJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3244 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3312169094 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56007e8db810, 0x56007eac501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56007eac5020,0x56008095d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5641cae842387b98f552c0e6bdbe93a73cbce908' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3976 processed earlier; will process 7053 files now Step #5: ==116860== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5600753d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56007ba35898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56007ba185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56007ba184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5600753d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560075337b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560075332355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5600753c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560078397f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560078397f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560078397f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560078397f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560078397f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560078397f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560078397f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560078397f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560078397f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560078397f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56007a62cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560077359b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560077364be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560077110c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560077110c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560077111738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560077110874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560077110874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560077110874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56007ba1aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56007ba23928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56007ba0b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56007ba36112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8e3225a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560075330b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x32,0x37,0x36,0x37,0x2d,0x3d,0x3c,0x30,0x27,0x27,0x2f,0x25,0x20,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x20,0x73,0x65,0x72,0x69,0x66,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $32767-=<0''/% ''/'''exp'N'2-\007 serif''/'''e'.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-048763a86c173d940a3249720dfb2cad54c080f3 Step #5: Base64: JDMyNzY3LT08MCcnLyUgJycvJycnZXhwJ04nMi0HIHNlcmlmJycvJycnZScuJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3245 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3312663958 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560e4a1bb810, 0x560e4a3a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560e4a3a5020,0x560e4c23d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/048763a86c173d940a3249720dfb2cad54c080f3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3977 processed earlier; will process 7052 files now Step #5: ==116896== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560e40cb09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560e47315898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560e472f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560e472f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560e40cb6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560e40c17b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560e40c12355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560e40ca8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560e43c77f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560e43c77f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560e43c77f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560e43c77f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560e43c77f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560e43c77f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560e43c77f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560e43c77f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560e43c77f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560e43c77f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560e45f0cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560e42c39b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560e42c44be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560e429f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560e429f0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560e429f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560e429f0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560e429f0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560e429f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560e472faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560e47303928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560e472eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560e47316112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fab17b2b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560e40c10b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x81,0x84,0xe2,0x80,0x80,0xe2,0x80,0x84,0xe2,0x80,0x80,0xe2,0x80,0x84,0xe2,0x80,0x80,0xe2,0x80,0x84,0xe2,0x80,0x80,0xe2,0x80,0x84,0xe2,0x80,0x80,0xe2,0x80,0x84,0xe2,0x80,0x80,0xe2,0x80,0x84,0xe2,0x80,0x80,0xe2,0x80,0x84,0xe2,0x80,0x80,0xa, Step #5: \342\201\204\342\200\200\342\200\204\342\200\200\342\200\204\342\200\200\342\200\204\342\200\200\342\200\204\342\200\200\342\200\204\342\200\200\342\200\204\342\200\200\342\200\204\342\200\200\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-87872bccf24067751b0e2b79b16bed749e7c4598 Step #5: Base64: 4oGE4oCA4oCE4oCA4oCE4oCA4oCE4oCA4oCE4oCA4oCE4oCA4oCE4oCA4oCE4oCACg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3246 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3313144350 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e024c3f810, 0x55e024e2901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e024e29020,0x55e026cc10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87872bccf24067751b0e2b79b16bed749e7c4598' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3978 processed earlier; will process 7051 files now Step #5: ==116932== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e01b7349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e021d99898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e021d7c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e021d7c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e01b73ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e01b69bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e01b696355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e01b72cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e01e6fbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e01e6fbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e01e6fbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e01e6fbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e01e6fbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e01e6fbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e01e6fbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e01e6fbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e01e6fbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e01e6fbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e020990f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e01d6bdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e01d6c8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e01d474c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e01d474c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e01d475738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e01d474874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e01d474874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e01d474874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e021d7eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e021d87928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e021d6f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e021d9a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6748801082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e01b694b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x0,0x2,0x6e,0x69,0x0,0x0,0x0,0x65,0x69,0x0,0x0,0x0,0x65,0x0,0x1,0x0,0x0,0x0,0x3,0x24,0x22,0xe2,0x80,0xab,0x26,0x22,0x22,0x22,0x22,0x1,0x24,0x0,0x2,0x1,0x60,0x5b,0x30,0x36,0x33,0x2e,0x2e,0x3d,0x5d,0xf8,0xcf,0x32,0x72,0x2d, Step #5: `\000\002ni\000\000\000ei\000\000\000e\000\001\000\000\000\003$\"\342\200\253&\"\"\"\"\001$\000\002\001`[063..=]\370\3172r- Step #5: artifact_prefix='./'; Test unit written to ./oom-d03f79d4aaa6ab88960aa238d857388775575996 Step #5: Base64: YAACbmkAAABlaQAAAGUAAQAAAAMkIuKAqyYiIiIiASQAAgFgWzA2My4uPV34zzJyLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3247 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3313750327 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562959a82810, 0x562959c6c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562959c6c020,0x56295bb040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d03f79d4aaa6ab88960aa238d857388775575996' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3979 processed earlier; will process 7050 files now Step #5: ==116968== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5629505779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562956bdc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562956bbf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562956bbf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56295057dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629504deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629504d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56295056fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56295353ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56295353ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56295353ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56295353ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56295353ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56295353ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56295353ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56295353ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56295353ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56295353ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5629557d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562952500b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56295250bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629522b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629522b7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629522b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629522b7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629522b7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629522b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562956bc1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562956bca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562956bb2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562956bdd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff70469e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629504d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0x69,0x69,0x69,0x69,0x31,0x4e,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x6b,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x1,0x0,0x69,0x69,0x69,0x69,0x69,0x1,0x0,0x20, Step #5: iiiii1Niiiiiiiiiiiiiiiiiiiiiiikiiiiiiii\001\000iiiii\001\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f616e181de594c732383033b7abed33d0e8999d3 Step #5: Base64: aWlpaWkxTmlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpa2lpaWlpaWlpAQBpaWlpaQEAIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3248 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3314232632 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5648761f7810, 0x5648763e101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5648763e1020,0x5648782790e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f616e181de594c732383033b7abed33d0e8999d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3980 processed earlier; will process 7049 files now Step #5: ==117004== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56486ccec9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564873351898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5648733345dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5648733344fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56486ccf2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56486cc53b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56486cc4e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56486cce4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56486fcb3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56486fcb3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56486fcb3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56486fcb3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56486fcb3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56486fcb3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56486fcb3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56486fcb3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56486fcb3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56486fcb3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564871f48f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56486ec75b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56486ec80be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56486ea2cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56486ea2cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56486ea2d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56486ea2c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56486ea2c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56486ea2c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564873336abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56487333f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564873327699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564873352112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f613e548082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56486cc4cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x2e,0x22,0xc8,0xa2,0xca,0xb5,0xd0,0xa4,0xcf,0xb5,0xc8,0xa4,0xc8,0xb0,0xc8,0xa3,0xc8,0xb2,0xc8,0xa3,0xc8,0xa2,0xc8,0xa3,0xc8,0xa3,0xc8,0xa3,0xc8,0xb0,0xc8,0xa3,0xc8,0xb0,0xc8,0xa3,0x2f,0xc8,0xa3,0x41,0xc8,0xb1,0xcf,0x0,0x23,0xc7,0xa2, Step #5: HU.\"\310\242\312\265\320\244\317\265\310\244\310\260\310\243\310\262\310\243\310\242\310\243\310\243\310\243\310\260\310\243\310\260\310\243/\310\243A\310\261\317\000#\307\242 Step #5: artifact_prefix='./'; Test unit written to ./oom-820ee74ef6447607fb144744ffcddb88e2049da6 Step #5: Base64: SFUuIsiiyrXQpM+1yKTIsMijyLLIo8iiyKPIo8ijyLDIo8iwyKMvyKNByLHPACPHog== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3249 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3314712518 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a5dcc7a810, 0x55a5dce6401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a5dce64020,0x55a5decfc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/820ee74ef6447607fb144744ffcddb88e2049da6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3981 processed earlier; will process 7048 files now Step #5: ==117040== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a5d376f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a5d9dd4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a5d9db75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a5d9db74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a5d3775d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a5d36d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a5d36d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a5d3767c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a5d6736f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a5d6736f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a5d6736f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a5d6736f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a5d6736f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a5d6736f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a5d6736f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a5d6736f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a5d6736f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a5d6736f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a5d89cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a5d56f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a5d5703be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a5d54afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a5d54afc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a5d54b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a5d54af874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a5d54af874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a5d54af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a5d9db9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a5d9dc2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a5d9daa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a5d9dd5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ffed25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a5d36cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0x9d,0xe0,0xbd,0xb5,0xe0,0xbd,0xbd,0xe0,0xbd,0x9d,0xe0,0xbd,0xb5,0xe0,0xbd,0xbc,0x3d, Step #5: \340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\235\340\275\265\340\275\275\340\275\235\340\275\265\340\275\274= Step #5: artifact_prefix='./'; Test unit written to ./oom-602455c9fe57bdaa782cd9f3be358c3cf9478a07 Step #5: Base64: 4L294L294L294L294L294L294L294L294L294L294L2d4L214L294L2d4L214L28PQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3250 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3315192245 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a555071810, 0x55a55525b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a55525b020,0x55a5570f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/602455c9fe57bdaa782cd9f3be358c3cf9478a07' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3982 processed earlier; will process 7047 files now Step #5: ==117076== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a54bb669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a5521cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a5521ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a5521ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a54bb6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a54bacdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a54bac8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a54bb5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a54eb2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a54eb2df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a54eb2df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a54eb2df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a54eb2df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a54eb2df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a54eb2df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a54eb2df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a54eb2df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a54eb2df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a550dc2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a54daefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a54dafabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a54d8a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a54d8a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a54d8a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a54d8a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a54d8a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a54d8a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a5521b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a5521b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a5521a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a5521cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9aba651082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a54bac6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x84,0x91,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xa2,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x81,0xe1,0x85,0xaa,0x79, Step #5: \341\204\221\341\205\252\341\204\221\341\205\260\341\204\221\341\205\260\341\204\221\341\205\242\341\204\221\341\205\260\341\204\221\341\205\252\341\204\221\341\205\260\341\204\201\341\205\252y Step #5: artifact_prefix='./'; Test unit written to ./oom-8ba95c642b27aaf20a73d5de2f06668e33e54cdc Step #5: Base64: 4YSR4YWq4YSR4YWw4YSR4YWw4YSR4YWi4YSR4YWw4YSR4YWq4YSR4YWw4YSB4YWqeQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3251 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3315672858 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c7af093810, 0x55c7af27d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c7af27d020,0x55c7b11150e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ba95c642b27aaf20a73d5de2f06668e33e54cdc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3983 processed earlier; will process 7046 files now Step #5: ==117112== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c7a5b889c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7ac1ed898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7ac1d05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7ac1d04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c7a5b8ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c7a5aefb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c7a5aea355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7a5b80c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7a8b4ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7a8b4ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7a8b4ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7a8b4ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7a8b4ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7a8b4ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7a8b4ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7a8b4ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7a8b4ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7a8b4ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7aade4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7a7b11b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7a7b1cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7a78c8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7a78c8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7a78c9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7a78c8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7a78c8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7a78c8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7ac1d2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7ac1db928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c7ac1c3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7ac1ee112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd0c97dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c7a5ae8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x32,0x37,0x36,0x37,0x2d,0x3d,0x3c,0x30,0x27,0x27,0x2f,0x25,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x33,0x2d,0x7,0x27,0x2f,0x25,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $32767-=<0''/%'''''/'''exp'N'3-\007'/%'''/'''e'.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-ae257da8a2dca3b210776d011d4ec6dba4ed4fe5 Step #5: Base64: JDMyNzY3LT08MCcnLyUnJycnJy8nJydleHAnTiczLQcnLyUnJycvJycnZScuJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3252 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3316162767 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5621f615b810, 0x5621f634501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5621f6345020,0x5621f81dd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ae257da8a2dca3b210776d011d4ec6dba4ed4fe5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3984 processed earlier; will process 7045 files now Step #5: ==117148== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5621ecc509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5621f32b5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5621f32985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5621f32984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5621ecc56d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5621ecbb7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5621ecbb2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5621ecc48c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5621efc17f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5621efc17f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5621efc17f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5621efc17f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5621efc17f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5621efc17f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5621efc17f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5621efc17f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5621efc17f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5621efc17f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5621f1eacf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5621eebd9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5621eebe4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5621ee990c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5621ee990c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5621ee991738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5621ee990874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5621ee990874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5621ee990874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5621f329aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5621f32a3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5621f328b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5621f32b6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7dd1e11082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5621ecbb0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x7d,0x6c,0x6f,0x6f,0x70,0x7b,0x3b,0x60,0x2d,0x36,0xef,0xac,0xac,0xef,0xac,0xac,0x60,0x2b,0x27,0x1f,0x27,0x3e,0x60,0x30,0x60,0x3b,0x5b,0x5d,0x3b,0x31,0x7d,0xc8,0xc9,0x0,0x30,0x5f,0xff,0xe5,0x31,0x5c,0x2d,0x33,0x36,0x2,0x0,0x0,0x0,0x5c, Step #5: {}loop{;`-6\357\254\254\357\254\254`+'\037'>`0`;[];1}\310\311\0000_\377\3451\\-36\002\000\000\000\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-c22a926b31dc6e16477d576f75a3ff579a7a2f49 Step #5: Base64: e31sb29weztgLTbvrKzvrKxgKycfJz5gMGA7W107MX3IyQAwX//lMVwtMzYCAAAAXA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3253 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3316770864 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55946d053810, 0x55946d23d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55946d23d020,0x55946f0d50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c22a926b31dc6e16477d576f75a3ff579a7a2f49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3985 processed earlier; will process 7044 files now Step #5: ==117184== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559463b489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55946a1ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55946a1905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55946a1904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559463b4ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559463aafb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559463aaa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559463b40c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559466b0ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559466b0ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559466b0ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559466b0ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559466b0ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559466b0ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559466b0ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559466b0ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559466b0ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559466b0ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559468da4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559465ad1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559465adcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559465888c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559465888c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559465889738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559465888874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559465888874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559465888874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55946a192abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55946a19b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55946a183699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55946a1ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fca9fc4d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559463aa8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x78,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0xa,0x2f,0x2f, Step #5: //\012//\012//\012//\012x//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012\012// Step #5: artifact_prefix='./'; Test unit written to ./oom-f9b8c76838c01550e676ce2c0d4a7a0978b8c0c4 Step #5: Base64: Ly8KLy8KLy8KLy8KeC8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCgovLw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3254 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3317252459 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d708709810, 0x55d7088f301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d7088f3020,0x55d70a78b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9b8c76838c01550e676ce2c0d4a7a0978b8c0c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3986 processed earlier; will process 7043 files now Step #5: #1 pulse cov: 3845 ft: 3846 exec/s: 0 rss: 173Mb Step #5: ==117220== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d6ff1fe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d705863898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7058465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7058464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d6ff204d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d6ff165b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d6ff160355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d6ff1f6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d7021c5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d7021c5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d7021c5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d7021c5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d7021c5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d7021c5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d7021c5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d7021c5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d7021c5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d7021c5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d70445af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d701187b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d701192be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d700f3ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d700f3ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d700f3f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d700f3e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d700f3e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d700f3e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d705848abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d705851928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d705839699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d705864112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe11b97082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d6ff15eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x32,0x37,0x36,0x37,0x2d,0x3d,0x3c,0x30,0x27,0x27,0x2f,0x25,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x2f,0x25,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $32767-=<0''/%'''/'''exp'N'2-\007=''/%'''/'''e'.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-089f1b5d7403831b9f1a80addf00c1bd7284fdcf Step #5: Base64: JDMyNzY3LT08MCcnLyUnJycvJycnZXhwJ04nMi0HPScnLyUnJycvJycnZScuJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3255 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3317784654 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c316e45810, 0x55c31702f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c31702f020,0x55c318ec70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/089f1b5d7403831b9f1a80addf00c1bd7284fdcf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3988 processed earlier; will process 7041 files now Step #5: ==117256== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c30d93a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c313f9f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c313f825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c313f824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c30d940d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c30d8a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c30d89c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c30d932c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c310901f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c310901f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c310901f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c310901f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c310901f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c310901f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c310901f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c310901f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c310901f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c310901f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c312b96f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c30f8c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c30f8cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c30f67ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c30f67ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c30f67b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c30f67a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c30f67a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c30f67a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c313f84abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c313f8d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c313f75699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c313fa0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0191637082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c30d89ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x2d,0x6a,0x6f,0x62,0x73,0x3a,0xa,0x20,0x41,0x3a,0xca,0x8c,0xca,0x8d,0xcd,0x9a,0xca,0xa3,0xcd,0x9a,0xd5,0x95,0xcd,0x9a,0x9,0x65,0xdb,0x8c,0xca,0x90,0xdb,0x8c,0xca,0x9d,0xcb,0x9a,0xca,0x95,0xcd,0x9e,0xce,0x95,0xcd,0x9a,0x3a,0x20, Step #5: \000\000\000-jobs:\012 A:\312\214\312\215\315\232\312\243\315\232\325\225\315\232\011e\333\214\312\220\333\214\312\235\313\232\312\225\315\236\316\225\315\232: Step #5: artifact_prefix='./'; Test unit written to ./oom-894d73baa0dce0f59a2733112e8f41949e8d607c Step #5: Base64: AAAALWpvYnM6CiBBOsqMyo3NmsqjzZrVlc2aCWXbjMqQ24zKncuaypXNns6VzZo6IA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3256 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3318271055 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f34d162810, 0x55f34d34c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f34d34c020,0x55f34f1e40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/894d73baa0dce0f59a2733112e8f41949e8d607c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3989 processed earlier; will process 7040 files now Step #5: ==117292== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f343c579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f34a2bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f34a29f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f34a29f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f343c5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f343bbeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f343bb9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f343c4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f346c1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f346c1ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f346c1ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f346c1ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f346c1ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f346c1ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f346c1ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f346c1ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f346c1ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f346c1ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f348eb3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f345be0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f345bebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f345997c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f345997c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f345998738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f345997874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f345997874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f345997874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f34a2a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f34a2aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f34a292699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f34a2bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba3e35e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f343bb7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x74,0x49,0x72,0x65,0x61,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x44,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2b,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x6d,0x0,0x44,0x31,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2,0x26, Step #5: stIrea..........D............+......m\000D1.......\002& Step #5: artifact_prefix='./'; Test unit written to ./oom-1797d38e70cba5275ba890cdfdd3c8dfb9c8d426 Step #5: Base64: c3RJcmVhLi4uLi4uLi4uLkQuLi4uLi4uLi4uLi4rLi4uLi4ubQBEMS4uLi4uLi4CJg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3257 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3318753929 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5639408a4810, 0x563940a8e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563940a8e020,0x5639429260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1797d38e70cba5275ba890cdfdd3c8dfb9c8d426' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3990 processed earlier; will process 7039 files now Step #5: ==117328== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5639373999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56393d9fe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56393d9e15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56393d9e14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56393739fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563937300b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5639372fb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563937391c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56393a360f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56393a360f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56393a360f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56393a360f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56393a360f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56393a360f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56393a360f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56393a360f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56393a360f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56393a360f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56393c5f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563939322b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56393932dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5639390d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5639390d9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5639390da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5639390d9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5639390d9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5639390d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56393d9e3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56393d9ec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56393d9d4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56393d9ff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6995e55082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5639372f9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x0,0x1f,0x18,0x18,0x2d,0x5b,0xd3,0xa3,0x2d,0x2d,0x50,0xa,0x32,0x44,0xa,0x2d,0xa,0x15,0x0,0x0,0x0,0x42,0x49,0xa,0x32,0xa,0x2d,0xa,0x82,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x64,0xa,0x64,0xa,0x3f, Step #5: s-----BE\000\037\030\030-[\323\243--P\0122D\012-\012\025\000\000\000BI\0122\012-\012\202\000\000\000\000\000\000\000d\012d\012? Step #5: artifact_prefix='./'; Test unit written to ./oom-df3224ea00baf0502ec8ec064e0b0641d9569d3d Step #5: Base64: cy0tLS0tQkUAHxgYLVvToy0tUAoyRAotChUAAABCSQoyCi0KggAAAAAAAABkCmQKPw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3258 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3319239405 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5648d6788810, 0x5648d697201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5648d6972020,0x5648d880a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/df3224ea00baf0502ec8ec064e0b0641d9569d3d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3991 processed earlier; will process 7038 files now Step #5: ==117364== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5648cd27d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5648d38e2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5648d38c55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5648d38c54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5648cd283d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5648cd1e4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5648cd1df355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5648cd275c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5648d0244f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5648d0244f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5648d0244f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5648d0244f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5648d0244f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5648d0244f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5648d0244f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5648d0244f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5648d0244f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5648d0244f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5648d24d9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5648cf206b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5648cf211be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5648cefbdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5648cefbdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5648cefbe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5648cefbd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5648cefbd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5648cefbd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5648d38c7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5648d38d0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5648d38b8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5648d38e3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f22011ed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5648cd1ddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x36,0x35,0x34,0x30,0x38,0x2,0x0,0x4,0x1,0x0,0x0,0x0,0x43,0x4f,0x4d,0x16,0x0,0x4,0x1,0x0,0xf3,0xa0,0x80,0xbe,0x0,0x0,0x43,0x4f,0x4d,0x16,0x0,0xe2,0x81,0xa6,0x4,0x1,0x0,0x0,0x0,0x43,0x4f,0x4d,0x0,0x0,0x4,0x1,0x0, Step #5: ID65408\002\000\004\001\000\000\000COM\026\000\004\001\000\363\240\200\276\000\000COM\026\000\342\201\246\004\001\000\000\000COM\000\000\004\001\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bbc0c8bd3aeda1eafbb73d43251a027b44dd1d3a Step #5: Base64: SUQ2NTQwOAIABAEAAABDT00WAAQBAPOggL4AAENPTRYA4oGmBAEAAABDT00AAAQBAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3259 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3319723930 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563414cb5810, 0x563414e9f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563414e9f020,0x563416d370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bbc0c8bd3aeda1eafbb73d43251a027b44dd1d3a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3992 processed earlier; will process 7037 files now Step #5: ==117400== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56340b7aa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563411e0f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563411df25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563411df24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56340b7b0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56340b711b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56340b70c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56340b7a2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56340e771f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56340e771f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56340e771f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56340e771f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56340e771f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56340e771f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56340e771f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56340e771f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56340e771f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56340e771f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563410a06f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56340d733b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56340d73ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56340d4eac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56340d4eac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56340d4eb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56340d4ea874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56340d4ea874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56340d4ea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563411df4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563411dfd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563411de5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563411e10112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f243dd5d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56340b70ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x70,0x68,0x70,0xa,0xa,0x23,0x5b,0x41,0x74,0x74,0x72,0x69,0x62,0x75,0x74,0x65,0x5d,0xa,0x23,0x5b,0x41,0x74,0x74,0x72,0x69,0x62,0x75,0x74,0x65,0x5d,0xa,0x63,0x6c,0x61,0x73,0x73,0x20,0x41,0x31,0x20,0x7b,0x20,0x7d,0xa,0xa,0x3f,0x3e, Step #5: <?php\012\012#[Attribute]\012#[Attribute]\012class A1 { }\012\012?> Step #5: artifact_prefix='./'; Test unit written to ./oom-c53c70a6960a5927157840625d0fb57948edf37c Step #5: Base64: PD9waHAKCiNbQXR0cmlidXRlXQojW0F0dHJpYnV0ZV0KY2xhc3MgQTEgeyB9Cgo/Pg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3260 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3320207324 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dc817d1810, 0x55dc819bb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dc819bb020,0x55dc838530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c53c70a6960a5927157840625d0fb57948edf37c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3993 processed earlier; will process 7036 files now Step #5: ==117436== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dc782c69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dc7e92b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dc7e90e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dc7e90e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dc782ccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dc7822db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dc78228355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dc782bec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dc7b28df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dc7b28df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dc7b28df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dc7b28df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dc7b28df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dc7b28df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dc7b28df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dc7b28df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dc7b28df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dc7b28df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dc7d522f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dc7a24fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dc7a25abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dc7a006c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dc7a006c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dc7a007738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dc7a006874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dc7a006874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dc7a006874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dc7e910abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dc7e919928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dc7e901699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dc7e92c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feaa10b7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dc78226b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0x24,0x69,0x6e,0x24,0x24,0x1e,0x24,0x6c,0x3,0x3,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x6d,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x26,0xcc,0x3,0x7e,0x47,0x46,0x44,0x7e,0x91,0x47, Step #5: $$$in$$\036$l\003\003................m$$$$$$$$$$&\314\003~GFD~\221G Step #5: artifact_prefix='./'; Test unit written to ./oom-fbe45570ce35e9b31d2260e882d020f71a51ba2e Step #5: Base64: JCQkaW4kJB4kbAMDLi4uLi4uLi4uLi4uLi4uLm0kJCQkJCQkJCQkJswDfkdGRH6RRw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3261 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3320693481 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ba905d9810, 0x55ba907c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ba907c3020,0x55ba9265b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fbe45570ce35e9b31d2260e882d020f71a51ba2e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3994 processed earlier; will process 7035 files now Step #5: #1 pulse cov: 4248 ft: 4249 exec/s: 0 rss: 173Mb Step #5: ==117472== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ba870ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ba8d733898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ba8d7165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ba8d7164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ba870d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ba87035b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ba87030355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ba870c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ba8a095f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ba8a095f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ba8a095f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ba8a095f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ba8a095f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ba8a095f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ba8a095f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ba8a095f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ba8a095f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ba8a095f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ba8c32af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ba89057b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ba89062be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ba88e0ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ba88e0ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ba88e0f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ba88e0e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ba88e0e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ba88e0e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ba8d718abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ba8d721928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ba8d709699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ba8d734112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8d95c11082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ba8702eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x70,0x68,0x70,0xa,0xa,0x5b,0x2c,0x20,0x22,0x61,0x22,0x20,0x3d,0x3e,0x20,0x24,0x62,0x5d,0x20,0x3d,0x20,0x5b,0x31,0x2c,0x20,0x22,0x3d,0x22,0x20,0x3d,0x3e,0x20,0x24,0x62,0x5d,0x20,0x3d,0x20,0x5b,0x31,0x20,0x61,0x3e,0x3b,0x3f,0x3e,0x3b, Step #5: <?php\012\012[, \"a\" => $b] = [1, \"=\" => $b] = [1 a>;?>; Step #5: artifact_prefix='./'; Test unit written to ./oom-7ec6fff5b07c8f744b2a379b4973f055da8a0532 Step #5: Base64: PD9waHAKClssICJhIiA9PiAkYl0gPSBbMSwgIj0iID0+ICRiXSA9IFsxIGE+Oz8+Ow== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3262 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3321222273 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ce5d86c810, 0x55ce5da5601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ce5da56020,0x55ce5f8ee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ec6fff5b07c8f744b2a379b4973f055da8a0532' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3996 processed earlier; will process 7033 files now Step #5: ==117508== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ce543619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ce5a9c6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ce5a9a95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ce5a9a94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ce54367d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ce542c8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ce542c3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ce54359c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ce57328f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ce57328f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ce57328f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ce57328f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ce57328f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ce57328f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ce57328f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ce57328f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ce57328f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ce57328f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ce595bdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ce562eab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ce562f5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ce560a1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ce560a1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ce560a2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ce560a1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ce560a1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ce560a1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ce5a9ababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ce5a9b4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ce5a99c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ce5a9c7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88092bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ce542c1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x81,0xb0,0xe2,0x84,0x9b,0xe2,0x81,0xb0,0xe2,0x81,0xa8,0xe2,0x81,0xa8,0xe2,0xa3,0xa8,0xe2,0x81,0xa8,0xe2,0x84,0xa3,0xe2,0x81,0xa8,0xe2,0x83,0xa8,0xe2,0x81,0xa8,0xe2,0x84,0xa3,0xe2,0x81,0xa8,0xe2,0x84,0xa8,0xe2,0x84,0xa3,0xe2,0x81,0xa8,0x9a, Step #5: \342\201\260\342\204\233\342\201\260\342\201\250\342\201\250\342\243\250\342\201\250\342\204\243\342\201\250\342\203\250\342\201\250\342\204\243\342\201\250\342\204\250\342\204\243\342\201\250\232 Step #5: artifact_prefix='./'; Test unit written to ./oom-d3d734676dcaa916e76fb3edff1cbdd0884a43d2 Step #5: Base64: 4oGw4oSb4oGw4oGo4oGo4qOo4oGo4oSj4oGo4oOo4oGo4oSj4oGo4oSo4oSj4oGomg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3263 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3321703853 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56268ce06810, 0x56268cff001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56268cff0020,0x56268ee880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d3d734676dcaa916e76fb3edff1cbdd0884a43d2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3997 processed earlier; will process 7032 files now Step #5: ==117544== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5626838fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562689f60898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562689f435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562689f434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562683901d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562683862b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56268385d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5626838f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5626868c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5626868c2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5626868c2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5626868c2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5626868c2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5626868c2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5626868c2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5626868c2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5626868c2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5626868c2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562688b57f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562685884b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56268588fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56268563bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56268563bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56268563c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56268563b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56268563b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56268563b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562689f45abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562689f4e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562689f36699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562689f61112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2663c7f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56268385bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x61,0x61,0x66,0x3a,0x20,0xd3,0xa1,0xdd,0x86,0xd2,0x8d,0x8a,0xd3,0xa0,0x8d,0x86,0xd2,0x8d,0x8a,0x5d,0x61,0x66,0x3a,0x20,0xd3,0xa1,0xdd,0x86,0xd2,0x8d,0x8a,0x5d,0x61,0x66,0x3a,0x20,0x86,0xd1,0x8d,0x8a,0xb6,0x8b,0x3a,0x20,0xd4,0x89,0x1c,0x25, Step #5: \003aaf: \323\241\335\206\322\215\212\323\240\215\206\322\215\212]af: \323\241\335\206\322\215\212]af: \206\321\215\212\266\213: \324\211\034% Step #5: artifact_prefix='./'; Test unit written to ./oom-efc00b2009c5d556437a0b02723a36464754827b Step #5: Base64: A2FhZjog06HdhtKNitOgjYbSjYpdYWY6INOh3YbSjYpdYWY6IIbRjYq2izog1IkcJQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3264 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3322193322 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5589f9043810, 0x5589f922d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5589f922d020,0x5589fb0c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/efc00b2009c5d556437a0b02723a36464754827b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3998 processed earlier; will process 7031 files now Step #5: ==117580== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5589efb389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5589f619d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589f61805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589f61804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5589efb3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5589efa9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5589efa9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5589efb30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5589f2afff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5589f2afff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5589f2afff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5589f2afff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5589f2afff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5589f2afff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5589f2afff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5589f2afff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5589f2afff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5589f2afff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589f4d94f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5589f1ac1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5589f1accbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5589f1878c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5589f1878c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5589f1879738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5589f1878874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5589f1878874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5589f1878874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5589f6182abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5589f618b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5589f6173699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5589f619e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5cbb47b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5589efa98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x34,0xf3,0xa0,0x80,0xa0,0x33,0x32,0x37,0x36,0x38,0xf3,0xa0,0x81,0xa7,0xe2,0x80,0xaf,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0x32,0x39,0x35,0xef,0xbc,0x8f,0x33,0x30,0x32,0xd7,0x8c,0x0,0x0,0xc2,0xb7,0x0,0x0,0x0,0x0,0x0,0x1,0xa9,0x9,0x74, Step #5: (4\363\240\200\24032768\363\240\201\247\342\200\2574294967295\357\274\217302\327\214\000\000\302\267\000\000\000\000\000\001\251\011t Step #5: artifact_prefix='./'; Test unit written to ./oom-2f77ad2302a52b209b777156ba780c5ff5c9bf68 Step #5: Base64: KDTzoICgMzI3NjjzoIGn4oCvNDI5NDk2NzI5Ne+8jzMwMteMAADCtwAAAAAAAakJdA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3265 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3322678255 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563ab29d1810, 0x563ab2bbb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563ab2bbb020,0x563ab4a530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f77ad2302a52b209b777156ba780c5ff5c9bf68' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 3999 processed earlier; will process 7030 files now Step #5: ==117616== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563aa94c69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563aafb2b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563aafb0e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563aafb0e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563aa94ccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563aa942db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563aa9428355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563aa94bec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563aac48df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563aac48df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563aac48df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563aac48df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563aac48df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563aac48df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563aac48df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563aac48df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563aac48df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563aac48df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563aae722f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563aab44fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563aab45abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563aab206c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563aab206c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563aab207738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563aab206874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563aab206874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563aab206874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563aafb10abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563aafb19928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563aafb01699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563aafb2c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feb0abef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563aa9426b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x2d,0x2d,0x2d,0x42,0x45,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x47,0x49,0x4e,0x20,0x2d,0xa,0x64,0x64,0x60,0x64,0x60,0x64,0x64,0x64,0x64,0x66,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x2d,0x2d,0x2d,0x2d, Step #5: x-----B---BE\001\000\000\000\000\000\000\000GIN -\012dd`d`ddddfdddddddddd---- Step #5: artifact_prefix='./'; Test unit written to ./oom-2b41a75a0b0bfd97779616a9160ebff4a2e92057 Step #5: Base64: eC0tLS0tQi0tLUJFAQAAAAAAAABHSU4gLQpkZGBkYGRkZGRmZGRkZGRkZGRkZC0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3266 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3323282459 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db57519810, 0x55db5770301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db57703020,0x55db5959b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2b41a75a0b0bfd97779616a9160ebff4a2e92057' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4000 processed earlier; will process 7029 files now Step #5: ==117652== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db4e00e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db54673898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db546565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db546564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db4e014d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db4df75b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db4df70355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db4e006c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db50fd5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db50fd5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db50fd5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db50fd5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db50fd5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db50fd5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db50fd5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db50fd5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db50fd5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db50fd5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db5326af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db4ff97b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db4ffa2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db4fd4ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db4fd4ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db4fd4f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db4fd4e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db4fd4e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db4fd4e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db54658abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db54661928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db54649699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db54674112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67132f5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db4df6eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5d,0xa,0x24,0x3d,0xa,0x6c,0x3d,0xa,0x8,0x3d,0xa,0x43,0x3d,0xa,0x6c,0x3d,0xa,0x6c,0x3d,0xa,0x7,0x3d,0xa,0x24,0x3d,0xa,0x6c,0x3d,0xa,0x8,0x3d,0xa,0x43,0x3d,0xa,0x62,0x3d,0xa,0x43,0x3d,0xa,0x62,0x3d,0xa,0x43,0x3d,0xa,0x43,0x3d, Step #5: []\012$=\012l=\012\010=\012C=\012l=\012l=\012\007=\012$=\012l=\012\010=\012C=\012b=\012C=\012b=\012C=\012C= Step #5: artifact_prefix='./'; Test unit written to ./oom-508b6e46da37be296b85dea7142ee8aa7a0d719e Step #5: Base64: W10KJD0KbD0KCD0KQz0KbD0KbD0KBz0KJD0KbD0KCD0KQz0KYj0KQz0KYj0KQz0KQz0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3267 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3323768078 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ae6a114810, 0x55ae6a2fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ae6a2fe020,0x55ae6c1960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/508b6e46da37be296b85dea7142ee8aa7a0d719e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4001 processed earlier; will process 7028 files now Step #5: ==117688== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ae60c099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ae6726e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ae672515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ae672514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ae60c0fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ae60b70b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ae60b6b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ae60c01c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ae63bd0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ae63bd0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ae63bd0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ae63bd0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ae63bd0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ae63bd0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ae63bd0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ae63bd0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ae63bd0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ae63bd0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ae65e65f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ae62b92b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ae62b9dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ae62949c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ae62949c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ae6294a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ae62949874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ae62949874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ae62949874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ae67253abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ae6725c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ae67244699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ae6726f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbd27d33082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ae60b69b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x32,0x37,0x36,0x37,0x2d,0x3d,0x3c,0x30,0x27,0x27,0x2f,0x25,0x20,0x21,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x20,0x73,0x65,0x72,0x69,0x66,0x27,0x27,0x2f,0x27,0x37,0x27,0x65,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $32767-=<0''/% !''/'''exp'N'2-\007 serif''/'7'e'.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-0608601abdca733e2b15500555ef74c502c99ad1 Step #5: Base64: JDMyNzY3LT08MCcnLyUgIScnLycnJ2V4cCdOJzItByBzZXJpZicnLyc3J2UnLickJy0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3268 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3324265554 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55850ab3c810, 0x55850ad2601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55850ad26020,0x55850cbbe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0608601abdca733e2b15500555ef74c502c99ad1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4002 processed earlier; will process 7027 files now Step #5: ==117724== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5585016319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558507c96898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558507c795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558507c794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558501637d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558501598b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558501593355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558501629c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5585045f8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5585045f8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5585045f8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5585045f8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5585045f8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5585045f8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5585045f8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5585045f8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5585045f8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5585045f8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55850688df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5585035bab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5585035c5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558503371c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558503371c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558503372738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558503371874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558503371874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558503371874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558507c7babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558507c84928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558507c6c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558507c97112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa76b819082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558501591b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0x20,0x64,0x3a,0x33,0x30,0x35,0x39,0x38,0x34,0x35,0x38,0x31,0x32,0x2e,0x33,0x35,0x39,0x30,0x30,0x36,0x36,0x33,0x32,0x36,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30, Step #5: FUZZTESTv1 d:3059845812.35900663260000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-896cf0f3f6cad7c1097b5cac02764126978364ab Step #5: Base64: RlVaWlRFU1R2MSBkOjMwNTk4NDU4MTIuMzU5MDA2NjMyNjAwMDAwMDAwMDAwMDAwMDA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3269 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3324749317 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd7603f810, 0x55dd7622901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd76229020,0x55dd780c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/896cf0f3f6cad7c1097b5cac02764126978364ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4003 processed earlier; will process 7026 files now Step #5: #1 pulse cov: 3913 ft: 3914 exec/s: 0 rss: 173Mb Step #5: ==117760== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dd6cb349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd73199898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd7317c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd7317c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dd6cb3ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dd6ca9bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dd6ca96355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dd6cb2cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd6fafbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd6fafbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd6fafbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd6fafbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd6fafbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd6fafbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd6fafbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd6fafbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd6fafbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd6fafbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd71d90f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dd6eabdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dd6eac8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dd6e874c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dd6e874c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dd6e875738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dd6e874874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dd6e874874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dd6e874874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd7317eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd73187928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd7316f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd7319a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbf08ca3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dd6ca94b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xd2,0xbf,0x46,0x46,0x20,0x0,0x40,0xa,0xd8,0x80,0x1,0xf,0x4,0x0,0x0,0xa,0x2d,0x20,0x0,0x0,0x4f,0x59,0x3e,0x30,0x23,0x76,0x21,0x39,0x76,0x0,0xe2,0x81,0x9f,0x3e,0xd7,0xa3,0x1,0xd7,0x2b,0x34,0x27,0x0,0x3a,0xd8,0x80,0x4,0xbb,0x2b,0x0, Step #5: \000\322\277FF \000@\012\330\200\001\017\004\000\000\012- \000\000OY>0#v!9v\000\342\201\237>\327\243\001\327+4'\000:\330\200\004\273+\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8a954d076ecdbce62ba8a2b833aca716aad586f7 Step #5: Base64: ANK/RkYgAEAK2IABDwQAAAotIAAAT1k+MCN2ITl2AOKBnz7XowHXKzQnADrYgAS7KwA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3270 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3325280588 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5592dcb21810, 0x5592dcd0b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5592dcd0b020,0x5592deba30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8a954d076ecdbce62ba8a2b833aca716aad586f7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4005 processed earlier; will process 7024 files now Step #5: ==117796== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5592d36169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5592d9c7b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5592d9c5e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5592d9c5e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592d361cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592d357db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592d3578355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592d360ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592d65ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592d65ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592d65ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592d65ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592d65ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592d65ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592d65ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592d65ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592d65ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592d65ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592d8872f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592d559fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592d55aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5592d5356c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5592d5356c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5592d5357738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5592d5356874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5592d5356874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5592d5356874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5592d9c60abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5592d9c69928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5592d9c51699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5592d9c7c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fea156eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592d3576b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x17,0x17,0x17,0x17,0x17,0x17,0x44,0x65,0x6e,0xe2,0x81,0x9f,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa0,0x8e,0x3c,0x20,0x7f,0x7f,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x81,0xae,0x0,0x64,0x64,0x64,0xb5,0xf3,0xa0,0x81,0x87,0x64,0x64, Step #5: \341\240\216= \177\027\027\027\027\027\027Den\342\201\237(\342\200\254\000\341\240\216< \177\177\342\200\215\000\000(\342\201\256\000ddd\265\363\240\201\207dd Step #5: artifact_prefix='./'; Test unit written to ./oom-9e28927529dc5c3e0724582992294ca7665c2762 Step #5: Base64: 4aCOPSB/FxcXFxcXRGVu4oGfKOKArADhoI48IH9/4oCNAAAo4oGuAGRkZLXzoIGHZGQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3271 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3325761058 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b264869810, 0x55b264a5301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b264a53020,0x55b2668eb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9e28927529dc5c3e0724582992294ca7665c2762' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4006 processed earlier; will process 7023 files now Step #5: ==117832== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b25b35e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b2619c3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b2619a65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b2619a64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b25b364d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b25b2c5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b25b2c0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b25b356c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b25e325f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b25e325f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b25e325f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b25e325f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b25e325f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b25e325f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b25e325f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b25e325f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b25e325f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b25e325f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b2605baf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b25d2e7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b25d2f2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b25d09ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b25d09ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b25d09f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b25d09e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b25d09e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b25d09e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b2619a8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b2619b1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b261999699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b2619c4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f21d0cd8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b25b2beb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x21,0x7b,0x66,0x6c,0x65,0x78,0x3a,0x7b,0x4d,0x3a,0x35,0x2c,0x4d,0x3a,0x35,0x2c,0x4d,0x61,0x3a,0x31,0x2c,0x4d,0x4d,0x4d,0x4d,0x4d,0x4d,0x4d,0x4d,0x4d,0x4d,0x4d,0x3a,0x31,0x2c,0x4d,0x4d,0x4d,0x4d,0x4d,0x4d,0x4d,0x4d,0x4d,0x4d,0x32,0x3a,0x30,0x7d, Step #5: #!{flex:{M:5,M:5,Ma:1,MMMMMMMMMMM:1,MMMMMMMMMM2:0} Step #5: artifact_prefix='./'; Test unit written to ./oom-74b8423b71f18ddb6b62bca6ad72c66901b6d5b9 Step #5: Base64: IyF7ZmxleDp7TTo1LE06NSxNYToxLE1NTU1NTU1NTU1NOjEsTU1NTU1NTU1NTTI6MH0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3272 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3326226660 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc7b951810, 0x55fc7bb3b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc7bb3b020,0x55fc7d9d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/74b8423b71f18ddb6b62bca6ad72c66901b6d5b9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4007 processed earlier; will process 7022 files now Step #5: #1 pulse cov: 4040 ft: 4041 exec/s: 0 rss: 173Mb Step #5: ==117868== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fc724469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc78aab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc78a8e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc78a8e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc7244cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc723adb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc723a8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc7243ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc7540df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc7540df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc7540df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc7540df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc7540df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc7540df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc7540df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc7540df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc7540df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc7540df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc776a2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc743cfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc743dabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc74186c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc74186c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc74187738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc74186874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc74186874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc74186874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc78a90abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc78a99928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc78a81699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc78aac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fab9512b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc723a6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x6f,0x63,0x69,0x56,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x31,0x2e,0x30,0x2e,0x30,0x22,0x2c,0x22,0x70,0x72,0x6f,0x63,0x65,0x73,0x73,0x22,0x3a,0x7b,0x22,0x6f,0x6f,0x6d,0x53,0x63,0x6f,0x72,0x65,0x41,0xdb,0xb7,0x22,0x3a,0x31,0x7d,0x7d, Step #5: {\"ociVersion\":\"1.0.0\",\"process\":{\"oomScoreA\333\267\":1}} Step #5: artifact_prefix='./'; Test unit written to ./oom-6b0316fa591e43d502b89afce0de5904db0551fb Step #5: Base64: eyJvY2lWZXJzaW9uIjoiMS4wLjAiLCJwcm9jZXNzIjp7Im9vbVNjb3JlQdu3IjoxfX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3273 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3326757501 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fcdb7f8810, 0x55fcdb9e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fcdb9e2020,0x55fcdd87a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b0316fa591e43d502b89afce0de5904db0551fb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4009 processed earlier; will process 7020 files now Step #5: ==117904== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fcd22ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fcd8952898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fcd89355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fcd89354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fcd22f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fcd2254b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fcd224f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fcd22e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fcd52b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fcd52b4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fcd52b4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fcd52b4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fcd52b4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fcd52b4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fcd52b4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fcd52b4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fcd52b4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fcd52b4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fcd7549f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fcd4276b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fcd4281be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fcd402dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fcd402dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fcd402e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fcd402d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fcd402d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fcd402d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fcd8937abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fcd8940928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fcd8928699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fcd8953112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc59da42082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fcd224db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xd,0x45,0x5b,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0x20,0x43,0xa,0x4f,0x20,0x49,0x44,0x9,0x22,0x78,0x33,0x32,0x37,0x36,0x38,0x54,0x4f,0x4b,0x45,0x4e,0x2b,0x2d,0x30,0x21,0x3e,0x3b,0x22,0x9,0x22, Step #5: <!DOCTYPE\015E[<!ATTLIST C\012O ID\011\"x32768TOKEN+-0!>;\"\011\" Step #5: artifact_prefix='./'; Test unit written to ./oom-1d5eb88b871414541cc90dcb8c95a3be6fa6bd30 Step #5: Base64: PCFET0NUWVBFDUVbPCFBVFRMSVNUIEMKTyBJRAkieDMyNzY4VE9LRU4rLTAhPjsiCSI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3274 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3327250276 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56046ceca810, 0x56046d0b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56046d0b4020,0x56046ef4c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1d5eb88b871414541cc90dcb8c95a3be6fa6bd30' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4010 processed earlier; will process 7019 files now Step #5: ==117940== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5604639bf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56046a024898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56046a0075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56046a0074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5604639c5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560463926b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560463921355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5604639b7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560466986f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560466986f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560466986f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560466986f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560466986f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560466986f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560466986f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560466986f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560466986f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560466986f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560468c1bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560465948b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560465953be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5604656ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5604656ffc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560465700738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5604656ff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5604656ff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5604656ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56046a009abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56046a012928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560469ffa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56046a025112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd152e84082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56046391fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdd,0xa7,0xce,0x9b,0xd3,0x8c,0xdd,0x8d,0xde,0xa9,0xdc,0xb9,0xdf,0x8d,0xd6,0x8e,0xde,0xaa,0xdd,0xb9,0xdf,0x8c,0xde,0x8c,0xd5,0x8d,0xd4,0x89,0xdc,0xa1,0xdd,0x82,0x8a,0x20,0x0,0x2f,0x85,0x24,0x0,0x0,0xf3,0x8e,0x12,0x6b,0x25,0x44,0x8d,0x2f,0x89,0x26, Step #5: \335\247\316\233\323\214\335\215\336\251\334\271\337\215\326\216\336\252\335\271\337\214\336\214\325\215\324\211\334\241\335\202\212 \000/\205$\000\000\363\216\022k%D\215/\211& Step #5: artifact_prefix='./'; Test unit written to ./oom-293aa9c5dd7632c271ee200d313638e205167291 Step #5: Base64: 3afOm9OM3Y3eqdy5343Wjt6q3bnfjN6M1Y3Uidyh3YKKIAAvhSQAAPOOEmslRI0viSY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3275 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3327744647 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5597940ad810, 0x55979429701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559794297020,0x55979612f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/293aa9c5dd7632c271ee200d313638e205167291' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4011 processed earlier; will process 7018 files now Step #5: #1 pulse cov: 11656 ft: 11657 exec/s: 0 rss: 191Mb Step #5: ==117976== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55978aba29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559791207898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5597911ea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5597911ea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55978aba8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55978ab09b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55978ab04355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55978ab9ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55978db69f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55978db69f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55978db69f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55978db69f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55978db69f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55978db69f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55978db69f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55978db69f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55978db69f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55978db69f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55978fdfef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55978cb2bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55978cb36be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55978c8e2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55978c8e2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55978c8e3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55978c8e2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55978c8e2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55978c8e2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5597911ecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5597911f5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5597911dd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559791208112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f96ef300082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55978ab02b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0xd4,0xf5,0x7d,0xc4,0x0,0x0,0x0,0x21,0xff,0xff,0x31, Step #5: #{}+\012#{}+\012#{}+\012#{}+\012#{}+\012\012#{}+\012#{}+\012#{}\324\365}\304\000\000\000!\377\3771 Step #5: artifact_prefix='./'; Test unit written to ./oom-4f1d81312d6708e6e60cadf0695b79b89fc49f81 Step #5: Base64: I3t9Kwoje30rCiN7fSsKI3t9Kwoje30rCgoje30rCiN7fSsKI3t91PV9xAAAACH//zE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3276 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3328303054 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56066a290810, 0x56066a47a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56066a47a020,0x56066c3120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f1d81312d6708e6e60cadf0695b79b89fc49f81' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4013 processed earlier; will process 7016 files now Step #5: ==118012== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560660d859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5606673ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606673cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606673cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560660d8bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560660cecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560660ce7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560660d7dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560663d4cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560663d4cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560663d4cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560663d4cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560663d4cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560663d4cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560663d4cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560663d4cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560663d4cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560663d4cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560665fe1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560662d0eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560662d19be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560662ac5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560662ac5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560662ac6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560662ac5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560662ac5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560662ac5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5606673cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5606673d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5606673c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5606673eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efc021c7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560660ce5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x64,0x3d,0x4d,0x61,0x67,0x69,0x63,0x6b,0x43,0x61,0x63,0x68,0x65,0xb,0x50,0x61,0x67,0x65,0x3d,0x58,0x2d,0x31,0xb,0x50,0x61,0x67,0x65,0x3d,0x58,0x2d,0x32,0xb,0x50,0x61,0x67,0x65,0x3d,0x58,0x2d,0x31,0xb,0x50,0x61,0x67,0x65,0x3d,0x58,0x2d,0x38, Step #5: Id=MagickCache\013Page=X-1\013Page=X-2\013Page=X-1\013Page=X-8 Step #5: artifact_prefix='./'; Test unit written to ./oom-784f391212939e19ee5bce0d2a76361db962ae6c Step #5: Base64: SWQ9TWFnaWNrQ2FjaGULUGFnZT1YLTELUGFnZT1YLTILUGFnZT1YLTELUGFnZT1YLTg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3277 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3328798295 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bd2a30d810, 0x55bd2a4f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bd2a4f7020,0x55bd2c38f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/784f391212939e19ee5bce0d2a76361db962ae6c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4014 processed earlier; will process 7015 files now Step #5: #1 pulse cov: 11331 ft: 11332 exec/s: 0 rss: 191Mb Step #5: #2 pulse cov: 12027 ft: 12795 exec/s: 0 rss: 193Mb Step #5: ==118048== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bd20e029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bd27467898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bd2744a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bd2744a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bd20e08d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bd20d69b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bd20d64355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bd20dfac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bd23dc9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bd23dc9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bd23dc9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bd23dc9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bd23dc9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bd23dc9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bd23dc9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bd23dc9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bd23dc9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bd23dc9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bd2605ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bd22d8bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bd22d96be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bd22b42c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bd22b42c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bd22b43738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bd22b42874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bd22b42874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bd22b42874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bd2744cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bd27455928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bd2743d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bd27468112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda4a406082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bd20d62b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x27,0x5c,0xa,0x27,0x5c,0xa,0x27,0x27,0x5c,0xa,0x27,0x27,0x5c,0xd,0x27,0x27,0x5c,0xa,0x27,0x27,0x5c,0xa,0x27,0x27,0x27,0xa,0x5c,0x27,0x5c,0xa,0x27,0x27,0x27,0x5c,0xa,0x27,0x27,0x5c,0xa,0x27,0x27,0x5c,0xa,0x27,0x27,0x5c,0xa,0x27,0x27, Step #5: ''\\\012'\\\012''\\\012''\\\015''\\\012''\\\012'''\012\\'\\\012'''\\\012''\\\012''\\\012''\\\012'' Step #5: artifact_prefix='./'; Test unit written to ./oom-a3465e53274f9fb8674985ad58d5943da22d8f58 Step #5: Base64: JydcCidcCicnXAonJ1wNJydcCicnXAonJycKXCdcCicnJ1wKJydcCicnXAonJ1wKJyc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3278 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3329401811 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558bad8b8810, 0x558badaa201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558badaa2020,0x558baf93a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a3465e53274f9fb8674985ad58d5943da22d8f58' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4017 processed earlier; will process 7012 files now Step #5: ==118084== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558ba43ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558baaa12898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558baa9f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558baa9f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558ba43b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558ba4314b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558ba430f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558ba43a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558ba7374f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558ba7374f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558ba7374f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558ba7374f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558ba7374f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558ba7374f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558ba7374f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558ba7374f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558ba7374f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558ba7374f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558ba9609f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ba6336b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ba6341be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ba60edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ba60edc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ba60ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ba60ed874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ba60ed874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ba60ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558baa9f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558baaa00928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558baa9e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558baaa13112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc3ff27b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558ba430db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x29,0x0,0x0,0x2f,0x0,0xf,0x31,0xf,0x31,0x11,0xf,0x31,0x3,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x11,0x2d,0x0,0x11,0x3f,0xf,0x31,0x11,0x2d,0x0,0x0,0x0,0x2f,0x0,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x2d,0x3a,0x24,0x5b, Step #5: $\000\000/)\000\000/\000\0171\0171\021\0171\003\000\000\000\000\000\000\000\021-\000\021?\0171\021-\000\000\000/\000\0171\021\0171\021-:-:$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-7d592bc0d4fb0418f6f9e8b5e1e8434429066bff Step #5: Base64: JAAALykAAC8ADzEPMREPMQMAAAAAAAAAES0AET8PMREtAAAALwAPMREPMREtOi06JFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3279 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3329894099 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559be8ab5810, 0x559be8c9f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559be8c9f020,0x559beab370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d592bc0d4fb0418f6f9e8b5e1e8434429066bff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4018 processed earlier; will process 7011 files now Step #5: #1 pulse cov: 3818 ft: 3819 exec/s: 0 rss: 173Mb Step #5: ==118120== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559bdf5aa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559be5c0f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559be5bf25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559be5bf24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559bdf5b0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559bdf511b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559bdf50c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559bdf5a2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559be2571f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559be2571f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559be2571f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559be2571f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559be2571f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559be2571f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559be2571f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559be2571f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559be2571f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559be2571f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559be4806f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559be1533b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559be153ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559be12eac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559be12eac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559be12eb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559be12ea874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559be12ea874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559be12ea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559be5bf4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559be5bfd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559be5be5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559be5c10112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa50c1a7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559bdf50ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x75,0x7b,0x74,0x24,0x3b,0x6e,0x24,0x3b,0x74,0x24,0x3b,0x6e,0x24,0x3b,0x74,0x24,0x3b,0x74,0x24,0x3b,0x74,0x24,0x3b,0x74,0x24,0x3b,0x6e,0x24,0x3b,0x6e,0x24,0x3b,0x6e,0x24,0x3b,0x6e,0x24,0x3b,0x74,0x24,0x3b,0x6e,0x24,0x3b,0x6e,0x24,0x3b,0x6e,0x24,0x3b, Step #5: u{t$;n$;t$;n$;t$;t$;t$;t$;n$;n$;n$;n$;t$;n$;n$;n$; Step #5: artifact_prefix='./'; Test unit written to ./oom-90318999e50e9a1785a7fb71411b4c6161cc90f5 Step #5: Base64: dXt0JDtuJDt0JDtuJDt0JDt0JDt0JDt0JDtuJDtuJDtuJDtuJDt0JDtuJDtuJDtuJDs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3280 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3330436187 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aae9b71810, 0x55aae9d5b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aae9d5b020,0x55aaebbf30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/90318999e50e9a1785a7fb71411b4c6161cc90f5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4020 processed earlier; will process 7009 files now Step #5: ==118156== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aae06669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aae6ccb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aae6cae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aae6cae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aae066cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aae05cdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aae05c8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aae065ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aae362df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aae362df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aae362df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aae362df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aae362df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aae362df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aae362df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aae362df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aae362df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aae362df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aae58c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aae25efb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aae25fabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aae23a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aae23a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aae23a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aae23a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aae23a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aae23a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aae6cb0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aae6cb9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aae6ca1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aae6ccc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6d8664b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aae05c6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x0,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x10,0x4,0x0,0x18,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0, Step #5: \001\000\012\000\000\000\000\000\000\000\000\000\001\000\020\004\000\030\000\000\000\000\000\000\001\000\000\000\000\000\000\000\000\001\000\000\000\000\001\000\000\000\000\000\001\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e1189cec715dfc16c6d9e859498e3cf641f9dcb8 Step #5: Base64: AQAKAAAAAAAAAAAAAQAQBAAYAAAAAAAAAQAAAAAAAAAAAQAAAAABAAAAAAABAAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3281 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3330928717 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560ce26d8810, 0x560ce28c201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560ce28c2020,0x560ce475a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e1189cec715dfc16c6d9e859498e3cf641f9dcb8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4021 processed earlier; will process 7008 files now Step #5: #1 pulse cov: 3660 ft: 3661 exec/s: 0 rss: 174Mb Step #5: ==118192== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560cd91cd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560cdf832898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560cdf8155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560cdf8154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560cd91d3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560cd9134b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560cd912f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560cd91c5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560cdc194f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560cdc194f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560cdc194f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560cdc194f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560cdc194f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560cdc194f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560cdc194f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560cdc194f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560cdc194f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560cdc194f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560cde429f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560cdb156b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560cdb161be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560cdaf0dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560cdaf0dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560cdaf0e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560cdaf0d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560cdaf0d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560cdaf0d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560cdf817abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560cdf820928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560cdf808699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560cdf833112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f90109af082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560cd912db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xbf,0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xa,0x6e,0x5b,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0x9,0x75,0xa,0x4f,0xa,0x28,0xcd,0x83,0x7c,0xcd,0x80,0x7c,0xcd,0x83,0x7c,0xcd,0x83,0x7c,0xcd,0x83,0x7c,0xcd,0x83,0x7c,0xcd,0x83, Step #5: \357\273\277<!DOCTYPE\012n[<!ATTLIST\011u\012O\012(\315\203|\315\200|\315\203|\315\203|\315\203|\315\203|\315\203 Step #5: artifact_prefix='./'; Test unit written to ./oom-0f4eea4ed487d173ab9b037cac1901b48cb0300f Step #5: Base64: 77u/PCFET0NUWVBFCm5bPCFBVFRMSVNUCXUKTwoozYN8zYB8zYN8zYN8zYN8zYN8zYM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3282 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3331456680 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561086cc0810, 0x561086eaa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561086eaa020,0x561088d420e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0f4eea4ed487d173ab9b037cac1901b48cb0300f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4023 processed earlier; will process 7006 files now Step #5: #1 pulse cov: 3894 ft: 3895 exec/s: 0 rss: 174Mb Step #5: ==118228== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56107d7b59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561083e1a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561083dfd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561083dfd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56107d7bbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56107d71cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56107d717355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56107d7adc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56108077cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56108077cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56108077cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56108077cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56108077cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56108077cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56108077cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56108077cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56108077cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56108077cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561082a11f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56107f73eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56107f749be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56107f4f5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56107f4f5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56107f4f6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56107f4f5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56107f4f5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56107f4f5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561083dffabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561083e08928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561083df0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561083e1b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f684613e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56107d715b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x73,0x0,0x0,0x0,0x2c,0x53,0x65,0x74,0x2d,0x43,0x6f,0x6f,0x6b,0x49,0x65,0x3a,0x68,0x3d,0x3b,0x65,0x58,0x70,0x69,0x72,0x65,0x73,0x3d,0x46,0x65,0x42,0x31,0x2b,0x30,0x38,0x36,0x36,0x25,0x37,0x36,0x4,0x9e,0x0,0xf5,0xfe,0x0,0x4,0x7c,0x79,0x79, Step #5: \000s\000\000\000,Set-CookIe:h=;eXpires=FeB1+0866%76\004\236\000\365\376\000\004|yy Step #5: artifact_prefix='./'; Test unit written to ./oom-80025d93342dc82e9fde3b47d9701e795f6672da Step #5: Base64: AHMAAAAsU2V0LUNvb2tJZTpoPTtlWHBpcmVzPUZlQjErMDg2NiU3NgSeAPX+AAR8eXk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3283 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3331980998 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56187d06d810, 0x56187d25701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56187d257020,0x56187f0ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/80025d93342dc82e9fde3b47d9701e795f6672da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4025 processed earlier; will process 7004 files now Step #5: #1 pulse cov: 9262 ft: 9263 exec/s: 0 rss: 188Mb Step #5: ==118264== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561873b629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56187a1c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56187a1aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56187a1aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561873b68d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561873ac9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561873ac4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561873b5ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561876b29f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561876b29f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561876b29f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561876b29f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561876b29f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561876b29f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561876b29f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561876b29f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561876b29f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561876b29f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561878dbef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561875aebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561875af6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5618758a2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5618758a2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5618758a3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5618758a2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5618758a2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5618758a2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56187a1acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56187a1b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56187a19d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56187a1c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa98863a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561873ac2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xbf,0x3c,0xf3,0xa0,0x80,0xb4,0x6d,0x61,0x74,0x68,0x20,0x78,0x6d,0x6c,0x6e,0x73,0x3d,0x22,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x74,0x54,0x68,0x20,0x78,0x6d,0x6c,0x6d,0x73,0x70,0x2d,0x32,0x31,0x35,0x30,0x38,0x38,0x38,0x6c,0x22,0x20, Step #5: \357\273\277<\363\240\200\264math xmlns=\"http://wwtTh xmlmsp-2150888l\" Step #5: artifact_prefix='./'; Test unit written to ./oom-af3a2c5dedfd382884c86cefc1487229442b9f5c Step #5: Base64: 77u/PPOggLRtYXRoIHhtbG5zPSJodHRwOi8vd3d0VGggeG1sbXNwLTIxNTA4ODhsIiA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3284 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3332526905 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5624c0c24810, 0x5624c0e0e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5624c0e0e020,0x5624c2ca60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af3a2c5dedfd382884c86cefc1487229442b9f5c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4027 processed earlier; will process 7002 files now Step #5: ==118300== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5624b77199c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5624bdd7e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5624bdd615dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5624bdd614fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5624b771fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5624b7680b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5624b767b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5624b7711c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5624ba6e0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5624ba6e0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5624ba6e0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5624ba6e0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5624ba6e0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5624ba6e0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5624ba6e0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5624ba6e0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5624ba6e0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5624ba6e0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5624bc975f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5624b96a2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5624b96adbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5624b9459c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5624b9459c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5624b945a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5624b9459874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5624b9459874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5624b9459874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5624bdd63abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5624bdd6c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5624bdd54699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5624bdd7f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f95bd9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5624b7679b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xa,0x3d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b,0x7d,0x24,0x7b, Step #5: =\012=${}${}${}${}${}${}${}${}${}${}${}${}${}${}${}${ Step #5: artifact_prefix='./'; Test unit written to ./oom-3f4453cf5222a592e8360f72d554a4dbeb21390d Step #5: Base64: PQo9JHt9JHt9JHt9JHt9JHt9JHt9JHt9JHt9JHt9JHt9JHt9JHt9JHt9JHt9JHt9JHs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3285 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3333020939 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af5d1cc810, 0x55af5d3b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af5d3b6020,0x55af5f24e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3f4453cf5222a592e8360f72d554a4dbeb21390d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4028 processed earlier; will process 7001 files now Step #5: #1 pulse cov: 3767 ft: 3768 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 3936 ft: 4303 exec/s: 0 rss: 175Mb Step #5: ==118336== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55af53cc19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af5a326898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af5a3095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af5a3094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55af53cc7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55af53c28b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55af53c23355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55af53cb9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55af56c88f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55af56c88f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55af56c88f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55af56c88f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55af56c88f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55af56c88f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55af56c88f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55af56c88f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55af56c88f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55af56c88f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af58f1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af55c4ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af55c55be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af55a01c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af55a01c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af55a02738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af55a01874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af55a01874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af55a01874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af5a30babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af5a314928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af5a2fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af5a327112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac23146082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55af53c21b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x52,0x2f,0x8b,0xe,0x35,0x0,0xbb,0x0,0x6b,0x6b,0x6b,0x6b,0x6b,0x90,0x0,0x0,0x23,0x0,0x0,0x0,0x0,0x6d,0x5d,0x6d,0x6d,0x6d,0x40,0x2,0xff,0xa0,0x0,0x0,0xff,0xff,0x73,0xff,0xff,0xff,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: \000\000\000\000\000\000R/\213\0165\000\273\000kkkkk\220\000\000#\000\000\000\000m]mmm@\002\377\240\000\000\377\377s\377\377\377\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-412a9e0dbf184ba372da8cc8fb5de6c766d44aac Step #5: Base64: AAAAAAAAUi+LDjUAuwBra2tra5AAACMAAAAAbV1tbW1AAv+gAAD//3P///8AAAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3286 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3333618499 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564ed4790810, 0x564ed497a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564ed497a020,0x564ed68120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/412a9e0dbf184ba372da8cc8fb5de6c766d44aac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4032 processed earlier; will process 6997 files now Step #5: ==118372== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564ecb2859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564ed18ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564ed18cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564ed18cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ecb28bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ecb1ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ecb1e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ecb27dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564ece24cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564ece24cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564ece24cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564ece24cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564ece24cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564ece24cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564ece24cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564ece24cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564ece24cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564ece24cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564ed04e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564ecd20eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564ecd219be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564eccfc5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564eccfc5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564eccfc6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564eccfc5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564eccfc5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564eccfc5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564ed18cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564ed18d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564ed18c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564ed18eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c5c1dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ecb1e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x73,0x64,0x3,0x11,0x47,0x0,0x54,0x49,0x42,0x2b,0x0,0x0,0x5b,0x67,0xe,0x68,0x68,0x43,0xda,0x82,0x0,0x20,0x79,0x11,0x47,0x0,0x54,0x49,0x42,0x2b,0x0,0x0,0x5b,0x67,0xe,0x68,0x68,0x43,0xda,0x82,0x1,0x70,0x70,0x70,0x70,0x70,0x20, Step #5: ID3sd\003\021G\000TIB+\000\000[g\016hhC\332\202\000 y\021G\000TIB+\000\000[g\016hhC\332\202\001ppppp Step #5: artifact_prefix='./'; Test unit written to ./oom-e4a65f3b7a2fe60c8b2d950cd09beaffa7f02d33 Step #5: Base64: SUQzc2QDEUcAVElCKwAAW2cOaGhD2oIAIHkRRwBUSUIrAABbZw5oaEPaggFwcHBwcCA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3287 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3334106264 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a52a48810, 0x563a52c3201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a52c32020,0x563a54aca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e4a65f3b7a2fe60c8b2d950cd09beaffa7f02d33' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4033 processed earlier; will process 6996 files now Step #5: ==118408== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563a4953d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a4fba2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a4fb855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a4fb854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a49543d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a494a4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a4949f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a49535c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a4c504f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a4c504f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a4c504f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a4c504f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a4c504f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a4c504f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a4c504f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a4c504f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a4c504f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a4c504f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a4e799f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a4b4c6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a4b4d1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a4b27dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a4b27dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a4b27e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a4b27d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a4b27d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a4b27d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a4fb87abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a4fb90928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a4fb78699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a4fba3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc60503f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a4949db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d, Step #5: -\012\012\012--\012-\012-\012-\012\012\012--\012-\012-\012-\012-\012-\012-\012-\012\012\012--\012-\012-\012-\012-\012-\012-\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-1fb7a4e9a670703b5dabe379e3186f5f07357dc2 Step #5: Base64: LQoKCi0tCi0KLQotCgoKLS0KLQotCi0KLQotCi0KLQoKCi0tCi0KLQotCi0KLQotCi0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3288 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3334611432 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563ca18d3810, 0x563ca1abd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563ca1abd020,0x563ca39550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1fb7a4e9a670703b5dabe379e3186f5f07357dc2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4034 processed earlier; will process 6995 files now Step #5: #1 pulse cov: 3896 ft: 3897 exec/s: 0 rss: 175Mb Step #5: ==118444== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563c983c89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563c9ea2d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563c9ea105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563c9ea104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563c983ced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563c9832fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563c9832a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563c983c0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563c9b38ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563c9b38ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563c9b38ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563c9b38ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563c9b38ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563c9b38ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563c9b38ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563c9b38ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563c9b38ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563c9b38ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563c9d624f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563c9a351b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563c9a35cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563c9a108c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563c9a108c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563c9a109738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563c9a108874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563c9a108874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563c9a108874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563c9ea12abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563c9ea1b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563c9ea03699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563c9ea2e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f84311a9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563c98328b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x27,0xf3,0xad,0xad,0x94,0x22,0x27,0xf2,0xad,0xad,0x94,0x22,0x27,0xf2,0xad,0xad,0x94,0x22,0x27,0xf2,0xad,0xad,0x94,0x22,0x27,0xf2,0xad,0xad,0x94,0x22,0x27,0xf2,0xad,0xad,0x94,0x22,0x27,0xf2,0xad,0xad,0x94,0x22,0x27,0xf2,0xad,0xad,0x94,0x22,0x27, Step #5: \"'\363\255\255\224\"'\362\255\255\224\"'\362\255\255\224\"'\362\255\255\224\"'\362\255\255\224\"'\362\255\255\224\"'\362\255\255\224\"'\362\255\255\224\"' Step #5: artifact_prefix='./'; Test unit written to ./oom-3da7cc41c028b39127ec96130cc14c334ed4c2ee Step #5: Base64: Iifzra2UIifyra2UIifyra2UIifyra2UIifyra2UIifyra2UIifyra2UIifyra2UIic= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3289 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3335135413 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55794fc1a810, 0x55794fe0401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55794fe04020,0x557951c9c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3da7cc41c028b39127ec96130cc14c334ed4c2ee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4036 processed earlier; will process 6993 files now Step #5: ==118480== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55794670f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55794cd74898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55794cd575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55794cd574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557946715d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557946676b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557946671355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557946707c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5579496d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5579496d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5579496d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5579496d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5579496d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5579496d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5579496d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5579496d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5579496d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5579496d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55794b96bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557948698b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5579486a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55794844fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55794844fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557948450738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55794844f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55794844f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55794844f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55794cd59abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55794cd62928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55794cd4a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55794cd75112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6c95c0f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55794666fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x22,0x61,0x22,0x61,0x22,0x64,0x22,0x61,0x22,0x61,0x22,0x64,0x22,0x3e,0x22,0x3e,0x22,0x63,0x22,0x61,0x22,0x61,0x22,0x66,0x22,0x3e,0x22,0x2e,0x22,0x3e,0x22,0x61,0x22,0x64,0x22,0xcd,0x8f,0x22,0x61,0x22,0x66,0x22,0x3e,0x3e,0x3e,0x3e,0x3e,0x22,0xfd, Step #5: \"\"a\"a\"d\"a\"a\"d\">\">\"c\"a\"a\"f\">\".\">\"a\"d\"\315\217\"a\"f\">>>>>\"\375 Step #5: artifact_prefix='./'; Test unit written to ./oom-ac8c9bb6d50c836311248214191990f66e590e86 Step #5: Base64: IiJhImEiZCJhImEiZCI+Ij4iYyJhImEiZiI+Ii4iPiJhImQizY8iYSJmIj4+Pj4+Iv0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3290 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3335625522 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e7be726810, 0x55e7be91001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e7be910020,0x55e7c07a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ac8c9bb6d50c836311248214191990f66e590e86' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4037 processed earlier; will process 6992 files now Step #5: #1 pulse cov: 11231 ft: 11232 exec/s: 0 rss: 192Mb Step #5: ==118516== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e7b521b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e7bb880898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7bb8635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7bb8634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e7b5221d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e7b5182b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e7b517d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e7b5213c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e7b81e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e7b81e2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e7b81e2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e7b81e2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e7b81e2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e7b81e2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e7b81e2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e7b81e2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e7b81e2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e7b81e2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e7ba477f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e7b71a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e7b71afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e7b6f5bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e7b6f5bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e7b6f5c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e7b6f5b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e7b6f5b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e7b6f5b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e7bb865abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e7bb86e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e7bb856699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e7bb881112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f14d61ab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e7b517bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x73,0x20,0x30,0xa,0x20,0x20,0x3d,0x22,0x22,0x22,0x22,0x0,0x0,0x22,0x22,0x22,0x22,0x0,0x0,0x0,0x0,0x0,0x22,0x1,0x2d,0x0, Step #5: \"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"s 0\012 =\"\"\"\"\000\000\"\"\"\"\000\000\000\000\000\"\001-\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b301e7388fa0bfc8a0d72cfd8e306c2c30a06df0 Step #5: Base64: IiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiInMgMAogID0iIiIiAAAiIiIiAAAAAAAiAS0A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3291 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3336182288 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56445106b810, 0x56445125501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564451255020,0x5644530ed0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b301e7388fa0bfc8a0d72cfd8e306c2c30a06df0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4039 processed earlier; will process 6990 files now Step #5: ==118552== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564447b609c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56444e1c5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56444e1a85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56444e1a84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564447b66d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564447ac7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564447ac2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564447b58c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56444ab27f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56444ab27f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56444ab27f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56444ab27f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56444ab27f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56444ab27f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56444ab27f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56444ab27f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56444ab27f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56444ab27f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56444cdbcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564449ae9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564449af4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5644498a0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5644498a0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5644498a1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5644498a0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5644498a0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5644498a0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56444e1aaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56444e1b3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56444e19b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56444e1c6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efda82f2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564447ac0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x5b, Step #5: \015- - - - - - - - - - - - - - - - - - - - - - - - [ Step #5: artifact_prefix='./'; Test unit written to ./oom-c786dfa6dd619fbdf508f7252b474bf76215d7d7 Step #5: Base64: IA0tIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSBb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3292 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3336712393 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5606353eb810, 0x5606355d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5606355d5020,0x56063746d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c786dfa6dd619fbdf508f7252b474bf76215d7d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4040 processed earlier; will process 6989 files now Step #5: ==118588== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56062bee09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560632545898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606325285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606325284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56062bee6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56062be47b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56062be42355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56062bed8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56062eea7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56062eea7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56062eea7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56062eea7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56062eea7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56062eea7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56062eea7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56062eea7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56062eea7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56062eea7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56063113cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56062de69b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56062de74be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56062dc20c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56062dc20c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56062dc21738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56062dc20874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56062dc20874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56062dc20874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56063252aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560632533928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56063251b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560632546112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f19eda98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56062be40b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5, Step #5: ws:\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-98d8bdc4476b550ff10741aabc5be67c62c56548 Step #5: Base64: d3M64ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3293 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3337201838 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557f04ec8810, 0x557f050b201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557f050b2020,0x557f06f4a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/98d8bdc4476b550ff10741aabc5be67c62c56548' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4041 processed earlier; will process 6988 files now Step #5: ==118624== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557efb9bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f02022898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f020055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f020054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557efb9c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557efb924b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557efb91f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557efb9b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557efe984f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557efe984f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557efe984f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557efe984f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557efe984f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557efe984f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557efe984f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557efe984f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557efe984f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557efe984f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f00c19f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557efd946b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557efd951be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557efd6fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557efd6fdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557efd6fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557efd6fd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557efd6fd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557efd6fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f02007abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f02010928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f01ff8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f02023112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f54a17e2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557efb91db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x49,0x4d,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0x4,0xa2,0x80,0xae,0x61,0x30,0x64,0x61,0xf,0x0,0x0,0x0,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0xa6,0xcd,0x9e,0xef,0xfd,0xb9,0x32,0x22, Step #5: ID3IM3\004\342\200\256\004\342\200\256a\342\200\256\004\242\200\256a0da\017\000\000\0003\004\342\200\256\004\342\200\256a\342\200\256\246\315\236\357\375\2712\" Step #5: artifact_prefix='./'; Test unit written to ./oom-25ae4b659eeafabf24b35c5c16f21f7a3c42547b Step #5: Base64: SUQzSU0zBOKArgTigK5h4oCuBKKArmEwZGEPAAAAMwTigK4E4oCuYeKArqbNnu/9uTIi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3294 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3337687288 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564f6db3f810, 0x564f6dd2901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564f6dd29020,0x564f6fbc10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/25ae4b659eeafabf24b35c5c16f21f7a3c42547b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4042 processed earlier; will process 6987 files now Step #5: ==118660== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564f646349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f6ac99898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f6ac7c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f6ac7c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f6463ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f6459bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f64596355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f6462cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f675fbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f675fbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f675fbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f675fbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f675fbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f675fbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f675fbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f675fbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f675fbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f675fbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f69890f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f665bdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f665c8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f66374c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f66374c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f66375738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f66374874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f66374874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f66374874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f6ac7eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f6ac87928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f6ac6f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f6ac9a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f66da988082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f64594b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x49,0x4d,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0x30,0x64,0x61,0xf,0x0,0x0,0x0,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0xa6,0xcd,0x9e,0xef,0xfd,0xb9,0x32,0x22, Step #5: ID3IM3\004\342\200\256\004\342\200\256a\342\200\256\004\342\200\256a0da\017\000\000\0003\004\342\200\256\004\342\200\256a\342\200\256\246\315\236\357\375\2712\" Step #5: artifact_prefix='./'; Test unit written to ./oom-548bd26eec36f1c8058644ed4e0eff2459ff0273 Step #5: Base64: SUQzSU0zBOKArgTigK5h4oCuBOKArmEwZGEPAAAAMwTigK4E4oCuYeKArqbNnu/9uTIi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3295 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3338171270 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561024593810, 0x56102477d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56102477d020,0x5610266150e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/548bd26eec36f1c8058644ed4e0eff2459ff0273' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4043 processed earlier; will process 6986 files now Step #5: ==118696== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56101b0889c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610216ed898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610216d05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610216d04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56101b08ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56101afefb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56101afea355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56101b080c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56101e04ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56101e04ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56101e04ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56101e04ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56101e04ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56101e04ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56101e04ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56101e04ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56101e04ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56101e04ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610202e4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56101d011b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56101d01cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56101cdc8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56101cdc8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56101cdc9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56101cdc8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56101cdc8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56101cdc8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610216d2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610216db928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610216c3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610216ee112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5b74ed8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56101afe8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x49,0x4d,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0x30,0x64,0x61,0xf,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x38,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0xd0,0xa6,0xcd,0x9e,0xef,0xfd,0xb9,0x32,0x22, Step #5: ID3IM3\004\342\200\256\004\342\200\256a\342\200\256\004\342\200\256a0da\017\000\000\000\000\000\000\0008\001\000\000\000\000\000\000\320\246\315\236\357\375\2712\" Step #5: artifact_prefix='./'; Test unit written to ./oom-096ff1344d6a6707500785ad28fb87c441de5ffd Step #5: Base64: SUQzSU0zBOKArgTigK5h4oCuBOKArmEwZGEPAAAAAAAAADgBAAAAAAAA0KbNnu/9uTIi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3296 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3338656906 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d315b5f810, 0x55d315d4901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d315d49020,0x55d317be10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/096ff1344d6a6707500785ad28fb87c441de5ffd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4044 processed earlier; will process 6985 files now Step #5: ==118732== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d30c6549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d312cb9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d312c9c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d312c9c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d30c65ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d30c5bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d30c5b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d30c64cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d30f61bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d30f61bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d30f61bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d30f61bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d30f61bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d30f61bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d30f61bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d30f61bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d30f61bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d30f61bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d3118b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d30e5ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d30e5e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d30e394c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d30e394c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d30e395738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d30e394874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d30e394874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d30e394874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d312c9eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d312ca7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d312c8f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d312cba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f302555b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d30c5b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x3a,0x2f,0xe1,0xa4,0xb9,0xe1,0xa4,0xb9,0xe1,0x80,0xb9,0xeb,0xa4,0xb9,0xe1,0x80,0xb9,0xe1,0xa4,0xb9,0xe1,0xa4,0xa9,0xe1,0x80,0xb9,0xeb,0xa4,0xb9,0xe1,0x80,0xb9,0xe1,0xa4,0xb9,0xe1,0xa4,0xb9,0xe1,0x80,0xb9,0xe1,0x80,0xb9,0xe1,0xa4,0xb9,0xe1,0xa0,0xb9, Step #5: A:/\341\244\271\341\244\271\341\200\271\353\244\271\341\200\271\341\244\271\341\244\251\341\200\271\353\244\271\341\200\271\341\244\271\341\244\271\341\200\271\341\200\271\341\244\271\341\240\271 Step #5: artifact_prefix='./'; Test unit written to ./oom-9715a046217a509932aea77b4306a571e84febc3 Step #5: Base64: QTov4aS54aS54YC566S54YC54aS54aSp4YC566S54YC54aS54aS54YC54YC54aS54aC5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3297 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3339149020 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561e4c142810, 0x561e4c32c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561e4c32c020,0x561e4e1c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9715a046217a509932aea77b4306a571e84febc3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4045 processed earlier; will process 6984 files now Step #5: ==118768== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561e42c379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561e4929c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561e4927f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561e4927f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561e42c3dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561e42b9eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561e42b99355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561e42c2fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561e45bfef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561e45bfef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561e45bfef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561e45bfef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561e45bfef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561e45bfef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561e45bfef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561e45bfef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561e45bfef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561e45bfef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561e47e93f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561e44bc0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561e44bcbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561e44977c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561e44977c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561e44978738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561e44977874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561e44977874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561e44977874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561e49281abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561e4928a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561e49272699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561e4929d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffbb9082082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561e42b97b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x3d,0x22,0x22,0x20,0x73,0x74,0x61,0x6e,0x64,0x61,0x6c,0x6f,0x6e,0x65,0x3d,0x22,0x79,0x65,0x73,0x22,0x3f,0x3e,0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0x20,0x65,0x5b,0x25,0x55,0x61,0x3b, Step #5: <?xml version=\"\" standalone=\"yes\"?><!DOCTYPE e[%Ua; Step #5: artifact_prefix='./'; Test unit written to ./oom-75889522d1777d2650392f03ee3274df679c5f7e Step #5: Base64: PD94bWwgdmVyc2lvbj0iIiBzdGFuZGFsb25lPSJ5ZXMiPz48IURPQ1RZUEUgZVslVWE7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3298 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3339647244 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55677ee06810, 0x55677eff001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55677eff0020,0x556780e880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/75889522d1777d2650392f03ee3274df679c5f7e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4046 processed earlier; will process 6983 files now Step #5: ==118804== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5567758fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55677bf60898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55677bf435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55677bf434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556775901d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556775862b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55677585d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5567758f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5567788c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5567788c2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5567788c2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5567788c2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5567788c2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5567788c2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5567788c2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5567788c2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5567788c2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5567788c2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55677ab57f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556777884b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55677788fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55677763bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55677763bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55677763c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55677763b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55677763b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55677763b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55677bf45abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55677bf4e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55677bf36699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55677bf61112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0668f81082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55677585bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0xd,0x22,0x5c,0x75,0x7b,0x66,0x46,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x46,0x7d,0x5c,0x75,0x7b,0x62,0x66,0x7d, Step #5: \015\015\"\\u{fF}\\u{ff}\\u{ff}\\u{ff}\\u{ff}\\u{ff}\\u{fF}\\u{bf} Step #5: artifact_prefix='./'; Test unit written to ./oom-b406f424f5b8a6d10b1af4c7e03efa6a73b41f53 Step #5: Base64: DQ0iXHV7ZkZ9XHV7ZmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZkZ9XHV7YmZ9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3299 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3340136488 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c4965b4810, 0x55c49679e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c49679e020,0x55c4986360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b406f424f5b8a6d10b1af4c7e03efa6a73b41f53' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4047 processed earlier; will process 6982 files now Step #5: #1 pulse cov: 3467 ft: 3468 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 11737 ft: 12551 exec/s: 0 rss: 193Mb Step #5: ==118840== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c48d0a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c49370e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c4936f15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c4936f14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c48d0afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c48d010b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c48d00b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c48d0a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c490070f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c490070f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c490070f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c490070f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c490070f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c490070f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c490070f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c490070f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c490070f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c490070f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c492305f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c48f032b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c48f03dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c48ede9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c48ede9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c48edea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c48ede9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c48ede9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c48ede9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c4936f3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c4936fc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c4936e4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c49370f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8faab52082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c48d009b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x49,0x4d,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0x4,0xe6,0x80,0xae,0x61,0x30,0x64,0x61,0xf,0x0,0x0,0x0,0x33,0x80,0x4,0xae,0xe2,0x4,0xe2,0x80,0xae,0x61,0xe2,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0xb9,0x32,0x22, Step #5: ID3IM3\004\342\200\256\004\342\200\256a\342\200\256\004\346\200\256a0da\017\000\000\0003\200\004\256\342\004\342\200\256a\342 i\012\012r=s\2712\" Step #5: artifact_prefix='./'; Test unit written to ./oom-4bdf5354d5aa3bc0bbc123b05a5d4ba479c13191 Step #5: Base64: SUQzSU0zBOKArgTigK5h4oCuBOaArmEwZGEPAAAAM4AEruIE4oCuYeIgaQoKcj1zuTIi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3300 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3340724963 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562b2315f810, 0x562b2334901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562b23349020,0x562b251e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4bdf5354d5aa3bc0bbc123b05a5d4ba479c13191' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4050 processed earlier; will process 6979 files now Step #5: #1 pulse cov: 3984 ft: 3985 exec/s: 0 rss: 174Mb Step #5: ==118876== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562b19c549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562b202b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562b2029c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562b2029c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b19c5ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b19bbbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b19bb6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b19c4cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b1cc1bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b1cc1bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b1cc1bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b1cc1bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b1cc1bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b1cc1bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b1cc1bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b1cc1bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b1cc1bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b1cc1bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562b1eeb0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b1bbddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b1bbe8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b1b994c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b1b994c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b1b995738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b1b994874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b1b994874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b1b994874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562b2029eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562b202a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562b2028f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562b202ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc174bba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b19bb4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3, Step #5: ws:\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263\340\275\263 Step #5: artifact_prefix='./'; Test unit written to ./oom-d013a7d432128e2927c19411cad76c2e9d0cc708 Step #5: Base64: d3M64L2z4L2z4L2z4L2z4L2z4L2z4L2z4L2z4L2z4L2z4L2z4L2z4L2z4L2z4L2z4L2z Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3301 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3341250075 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5560c7858810, 0x5560c7a4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5560c7a42020,0x5560c98da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d013a7d432128e2927c19411cad76c2e9d0cc708' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4052 processed earlier; will process 6977 files now Step #5: #1 pulse cov: 3726 ft: 3727 exec/s: 0 rss: 172Mb Step #5: ==118912== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5560be34d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5560c49b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5560c49955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5560c49954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5560be353d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5560be2b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5560be2af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5560be345c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5560c1314f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5560c1314f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5560c1314f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5560c1314f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5560c1314f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5560c1314f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5560c1314f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5560c1314f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5560c1314f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5560c1314f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5560c35a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5560c02d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5560c02e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5560c008dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5560c008dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5560c008e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5560c008d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5560c008d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5560c008d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5560c4997abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5560c49a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5560c4988699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5560c49b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a4ce76082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5560be2adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc, Step #5: \357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-e0d2ca00ce3dab4485a33f127c4d4a34236fce90 Step #5: Base64: 77e677e677e6LsK8Cu+3uu+3uu+3ui7CvArvt7rvt7rvt7ouwrwK77e677e677e6LsK8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3302 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3341775570 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557746446810, 0x55774663001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557746630020,0x5577484c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e0d2ca00ce3dab4485a33f127c4d4a34236fce90' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4054 processed earlier; will process 6975 files now Step #5: ==118948== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55773cf3b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5577435a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5577435835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5577435834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55773cf41d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55773cea2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55773ce9d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55773cf33c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55773ff02f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55773ff02f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55773ff02f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55773ff02f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55773ff02f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55773ff02f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55773ff02f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55773ff02f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55773ff02f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55773ff02f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557742197f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55773eec4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55773eecfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55773ec7bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55773ec7bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55773ec7c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55773ec7b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55773ec7b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55773ec7b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557743585abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55774358e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557743576699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5577435a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f066fb5a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55773ce9bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x49,0x4d,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x64,0x61,0xf,0x0,0x0,0x0,0x33,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x9e,0xef,0xfd,0xb9,0x32,0x22, Step #5: ID3IM3\004\342\200\256\004\342\200\256a\342\377\377\377\377\377\377\377\377da\017\000\000\0003\200\256\004\342\200\256a\342\200\256\004\342\200\256\236\357\375\2712\" Step #5: artifact_prefix='./'; Test unit written to ./oom-0054929c1a4672652a806fcd22327684b154d3d1 Step #5: Base64: SUQzSU0zBOKArgTigK5h4v//////////ZGEPAAAAM4CuBOKArmHigK4E4oCunu/9uTIi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3303 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3342259642 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed9daa7810, 0x55ed9dc9101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed9dc91020,0x55ed9fb290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0054929c1a4672652a806fcd22327684b154d3d1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4055 processed earlier; will process 6974 files now Step #5: ==118984== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed9459c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed9ac01898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed9abe45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed9abe44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed945a2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed94503b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed944fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed94594c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed97563f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed97563f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed97563f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed97563f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed97563f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed97563f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed97563f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed97563f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed97563f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed97563f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed997f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed96525b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed96530be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed962dcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed962dcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed962dd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed962dc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed962dc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed962dc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed9abe6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed9abef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed9abd7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed9ac02112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f79ea301082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed944fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0x3a,0x3f,0xe3,0x8c,0x96,0xe3,0x81,0xbe,0xe3,0x81,0x9e,0xe3,0x81,0xbe,0xe3,0x81,0x9e,0xe3,0x84,0xbe,0xe3,0x81,0xbe,0xef,0xbc,0x8f,0xe3,0x81,0xb5,0xe3,0x81,0xbe,0xe3,0x81,0xbf,0xe3,0x81,0x9e,0xe3,0x81,0xbe,0xe3,0x81,0xbe,0xe3,0x81,0xbe,0xe4,0x8c,0x96, Step #5: i:?\343\214\226\343\201\276\343\201\236\343\201\276\343\201\236\343\204\276\343\201\276\357\274\217\343\201\265\343\201\276\343\201\277\343\201\236\343\201\276\343\201\276\343\201\276\344\214\226 Step #5: artifact_prefix='./'; Test unit written to ./oom-69c56fd34a8c2b905fbc0df27d04341ca653a2ee Step #5: Base64: aTo/44yW44G+44Ge44G+44Ge44S+44G+77yP44G144G+44G/44Ge44G+44G+44G+5IyW Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3304 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3342744879 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e25ee3810, 0x562e260cd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e260cd020,0x562e27f650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/69c56fd34a8c2b905fbc0df27d04341ca653a2ee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4056 processed earlier; will process 6973 files now Step #5: ==119020== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562e1c9d89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e2303d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e230205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e230204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e1c9ded42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e1c93fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e1c93a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e1c9d0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e1f99ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e1f99ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e1f99ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e1f99ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e1f99ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e1f99ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e1f99ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e1f99ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e1f99ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e1f99ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e21c34f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e1e961b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e1e96cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e1e718c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e1e718c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e1e719738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e1e718874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e1e718874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e1e718874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e23022abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e2302b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e23013699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e2303e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f417788a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e1c938b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x78,0xcd,0x84,0x70,0xcd,0x84,0x7d,0xcd,0x84,0x78,0xcd,0x84,0x78,0xcd,0x84,0x78,0xcd,0x84,0x78,0xcd,0x84,0x78,0xcd,0x84,0x78,0xcd,0x84,0x78,0xcd,0x84,0x78,0xcd,0x84,0x78,0xcd,0x84,0x78,0xcd,0x84,0x78,0xcd,0x84,0x78,0xcd,0x84,0x78,0xcd,0x84, Step #5: ws:x\315\204p\315\204}\315\204x\315\204x\315\204x\315\204x\315\204x\315\204x\315\204x\315\204x\315\204x\315\204x\315\204x\315\204x\315\204x\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-63464f71fdbba8447f4ff0171eeb397cdd0067d5 Step #5: Base64: d3M6eM2EcM2Efc2EeM2EeM2EeM2EeM2EeM2EeM2EeM2EeM2EeM2EeM2EeM2EeM2EeM2E Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3305 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3343230162 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56299ea72810, 0x56299ec5c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56299ec5c020,0x5629a0af40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/63464f71fdbba8447f4ff0171eeb397cdd0067d5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4057 processed earlier; will process 6972 files now Step #5: ==119056== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5629955679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56299bbcc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56299bbaf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56299bbaf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56299556dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629954ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629954c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56299555fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56299852ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56299852ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56299852ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56299852ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56299852ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56299852ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56299852ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56299852ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56299852ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56299852ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56299a7c3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629974f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629974fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629972a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629972a7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629972a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629972a7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629972a7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629972a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56299bbb1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56299bbba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56299bba2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56299bbcd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b5173c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629954c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x49,0x4d,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0x4,0xe3,0x80,0xae,0x61,0x30,0x64,0x61,0xf,0x0,0x0,0x0,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0xa6,0xcd,0x9e,0xef,0xfd,0xb9,0x32,0x22, Step #5: ID3IM3\004\342\200\256\004\342\200\256a\342\200\256\004\343\200\256a0da\017\000\000\0003\004\342\200\256\004\342\200\256a\342\200\256\246\315\236\357\375\2712\" Step #5: artifact_prefix='./'; Test unit written to ./oom-6fcb387aa69bd6430e40f282d6f1f105964bd0eb Step #5: Base64: SUQzSU0zBOKArgTigK5h4oCuBOOArmEwZGEPAAAAMwTigK4E4oCuYeKArqbNnu/9uTIi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3306 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3343711398 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56363b00f810, 0x56363b1f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56363b1f9020,0x56363d0910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6fcb387aa69bd6430e40f282d6f1f105964bd0eb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4058 processed earlier; will process 6971 files now Step #5: ==119092== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563631b049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563638169898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56363814c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56363814c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563631b0ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563631a6bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563631a66355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563631afcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563634acbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563634acbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563634acbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563634acbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563634acbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563634acbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563634acbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563634acbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563634acbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563634acbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563636d60f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563633a8db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563633a98be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563633844c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563633844c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563633845738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563633844874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563633844874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563633844874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56363814eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563638157928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56363813f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56363816a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f696e878082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563631a64b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x34,0x68,0x3d,0xa,0x21,0x42,0x3d,0xa,0x3d,0xa,0x3d,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24, Step #5: 4h=\012!B=\012=\012=$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ Step #5: artifact_prefix='./'; Test unit written to ./oom-6d49b8432b68552567a2a3a7dcefe8cc98b0ffce Step #5: Base64: NGg9CiFCPQo9Cj0kJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3307 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3344207797 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d09c7f0810, 0x55d09c9da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d09c9da020,0x55d09e8720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6d49b8432b68552567a2a3a7dcefe8cc98b0ffce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4059 processed earlier; will process 6970 files now Step #5: ==119128== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d0932e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d09994a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d09992d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d09992d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d0932ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d09324cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d093247355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d0932ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d0962acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d0962acf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d0962acf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d0962acf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d0962acf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d0962acf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d0962acf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d0962acf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d0962acf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d0962acf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d098541f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d09526eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d095279be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d095025c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d095025c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d095026738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d095025874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d095025874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d095025874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d09992fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d099938928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d099920699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d09994b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ae2870082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d093245b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x46,0x54,0x79,0x77,0x42,0x4b,0x52,0x48,0x25,0x72,0x74,0x61,0x76,0x45,0x64,0x6d,0x65,0x79,0x73,0x63,0x65,0x6e,0x74,0x20,0x4e,0x30,0x65,0x46,0x76,0x52,0x6c,0xa,0x61,0x20,0x2d,0x31,0x32,0x38,0x2e, Step #5: onion-key\012ntFTywBKRH%rtavEdmeyscent N0eFvRl\012a -128. Step #5: artifact_prefix='./'; Test unit written to ./oom-e94b995c32253e406e39b48c1e50546f039437b3 Step #5: Base64: b25pb24ta2V5Cm50RlR5d0JLUkglcnRhdkVkbWV5c2NlbnQgTjBlRnZSbAphIC0xMjgu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3308 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3344700283 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a3294b810, 0x563a32b3501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a32b35020,0x563a349cd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e94b995c32253e406e39b48c1e50546f039437b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4060 processed earlier; will process 6969 files now Step #5: ==119164== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563a294409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a2faa5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a2fa885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a2fa884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a29446d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a293a7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a293a2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a29438c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a2c407f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a2c407f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a2c407f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a2c407f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a2c407f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a2c407f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a2c407f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a2c407f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a2c407f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a2c407f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a2e69cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a2b3c9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a2b3d4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a2b180c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a2b180c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a2b181738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a2b180874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a2b180874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a2b180874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a2fa8aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a2fa93928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a2fa7b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a2faa6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa031f71082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a293a0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e, Step #5: ws:\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236 Step #5: artifact_prefix='./'; Test unit written to ./oom-b1ec0f0f1ce0a43ac6b93a7acdfd57d592b61d92 Step #5: Base64: d3M6776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3309 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3345189764 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c1bf989810, 0x55c1bfb7301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c1bfb73020,0x55c1c1a0b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b1ec0f0f1ce0a43ac6b93a7acdfd57d592b61d92' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4061 processed earlier; will process 6968 files now Step #5: ==119200== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c1b647e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c1bcae3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c1bcac65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c1bcac64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c1b6484d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c1b63e5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c1b63e0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c1b6476c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c1b9445f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c1b9445f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c1b9445f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c1b9445f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c1b9445f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c1b9445f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c1b9445f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c1b9445f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c1b9445f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c1b9445f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c1bb6daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c1b8407b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c1b8412be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c1b81bec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c1b81bec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c1b81bf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c1b81be874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c1b81be874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c1b81be874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c1bcac8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c1bcad1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c1bcab9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c1bcae4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f811a2a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c1b63deb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x28,0x2e,0x24,0x7c,0x2e,0x3f,0x29,0x29,0x7b,0x39,0x38,0x39,0x7b,0x7c,0x2e,0x3f,0x29,0x29,0x7b,0x39,0x38,0x39,0x7b,0x7c,0x2e,0x3f,0x28,0x0,0x29,0x2f,0x2e,0xa,0x28,0x0,0x29,0x2f,0x2e,0xa,0x2e,0x3f,0x29,0x7b,0x39,0x38,0x39,0x39,0x38,0x39,0x7d,0x24, Step #5: ^(.$|.?)){989{|.?)){989{|.?(\000)/.\012(\000)/.\012.?){989989}$ Step #5: artifact_prefix='./'; Test unit written to ./oom-c233f3bf32750c1c6db86650df6813f2cd2ad107 Step #5: Base64: XiguJHwuPykpezk4OXt8Lj8pKXs5ODl7fC4/KAApLy4KKAApLy4KLj8pezk4OTk4OX0k Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3310 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3345684919 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a952b6b810, 0x55a952d5501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a952d55020,0x55a954bed0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c233f3bf32750c1c6db86650df6813f2cd2ad107' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4062 processed earlier; will process 6967 files now Step #5: ==119236== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a9496609c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a94fcc5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a94fca85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a94fca84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a949666d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a9495c7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a9495c2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a949658c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a94c627f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a94c627f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a94c627f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a94c627f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a94c627f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a94c627f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a94c627f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a94c627f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a94c627f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a94c627f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a94e8bcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a94b5e9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a94b5f4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a94b3a0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a94b3a0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a94b3a1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a94b3a0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a94b3a0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a94b3a0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a94fcaaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a94fcb3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a94fc9b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a94fcc6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27bf0ef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a9495c0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x76,0x42,0xa,0x3d,0x20,0x20,0xa,0x3d,0x20,0x20,0x2e,0x1d,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x4,0x0,0x60,0x60,0xa,0x69,0x66,0x3d,0x42,0x42,0xa,0x3d,0x20,0x20,0xa,0x3d,0x20,0x20,0x2e,0x1d,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x4,0x0,0x60,0x60,0xa, Step #5: vB\012= \012= .\035\001\000\000\000\000\000\000\004\000``\012if=BB\012= \012= .\035\001\000\000\000\000\000\000\004\000``\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-5bb424710035b7415a8c091ad48ab77aa8bbd5a0 Step #5: Base64: dkIKPSAgCj0gIC4dAQAAAAAAAAQAYGAKaWY9QkIKPSAgCj0gIC4dAQAAAAAAAAQAYGAK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3311 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3346300583 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c38448a810, 0x55c38467401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c384674020,0x55c38650c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5bb424710035b7415a8c091ad48ab77aa8bbd5a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4063 processed earlier; will process 6966 files now Step #5: #1 pulse cov: 3654 ft: 3655 exec/s: 0 rss: 173Mb Step #5: ==119272== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c37af7f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c3815e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c3815c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c3815c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c37af85d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c37aee6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c37aee1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c37af77c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c37df46f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c37df46f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c37df46f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c37df46f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c37df46f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c37df46f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c37df46f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c37df46f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c37df46f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c37df46f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c3801dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c37cf08b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c37cf13be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c37ccbfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c37ccbfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c37ccc0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c37ccbf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c37ccbf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c37ccbf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c3815c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c3815d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c3815ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c3815e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd2d7222082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c37aedfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x54,0x68,0x69,0x73,0x20,0x66,0x69,0x6c,0x65,0x20,0x6d,0x75,0x73,0x74,0x20,0x62,0x65,0x20,0x63,0x6f,0x6e,0x76,0x65,0x72,0x74,0x65,0x64,0x20,0x77,0x69,0x74,0x68,0x20,0x42,0x69,0x6e,0x48,0x65,0x78,0x20,0x34,0x2e,0x30,0x29,0x1,0x0,0x33,0x4a,0x21,0x20, Step #5: (This file must be converted with BinHex 4.0)\001\0003J! Step #5: artifact_prefix='./'; Test unit written to ./oom-a762d33bfa359f4817259ba7c3e4e9fe6250d48c Step #5: Base64: KFRoaXMgZmlsZSBtdXN0IGJlIGNvbnZlcnRlZCB3aXRoIEJpbkhleCA0LjApAQAzSiEg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3312 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3346840516 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5569b333d810, 0x5569b352701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5569b3527020,0x5569b53bf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a762d33bfa359f4817259ba7c3e4e9fe6250d48c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4065 processed earlier; will process 6964 files now Step #5: ==119308== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5569a9e329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5569b0497898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5569b047a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5569b047a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5569a9e38d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5569a9d99b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5569a9d94355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5569a9e2ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5569acdf9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5569acdf9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5569acdf9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5569acdf9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5569acdf9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5569acdf9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5569acdf9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5569acdf9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5569acdf9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5569acdf9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5569af08ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5569abdbbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5569abdc6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5569abb72c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5569abb72c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5569abb73738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5569abb72874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5569abb72874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5569abb72874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5569b047cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5569b0485928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5569b046d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5569b0498112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f661a2a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5569a9d92b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x75,0x70,0x64,0x61,0x74,0x65,0x5d,0xa,0x63,0x6f,0x6d,0x70,0x61,0x74,0x69,0x62,0x6c,0x65,0x3d,0xf0,0x93,0x81,0xb6,0xf0,0x93,0x82,0x82,0xf0,0x92,0x82,0x82,0xf0,0x93,0x82,0xab,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0xa6,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0xae, Step #5: [update]\012compatible=\360\223\201\266\360\223\202\202\360\222\202\202\360\223\202\253\360\223\202\266\360\223\202\246\360\223\202\266\360\223\202\256 Step #5: artifact_prefix='./'; Test unit written to ./oom-c52eb83c971b5089b4f5d3ba5f1b2ad9d1a95a67 Step #5: Base64: W3VwZGF0ZV0KY29tcGF0aWJsZT3wk4G28JOCgvCSgoLwk4Kr8JOCtvCTgqbwk4K28JOCrg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3313 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3347333926 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556104f6f810, 0x55610515901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556105159020,0x556106ff10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c52eb83c971b5089b4f5d3ba5f1b2ad9d1a95a67' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4066 processed earlier; will process 6963 files now Step #5: ==119344== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5560fba649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5561020c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5561020ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5561020ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5560fba6ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5560fb9cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5560fb9c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5560fba5cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5560fea2bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5560fea2bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5560fea2bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5560fea2bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5560fea2bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5560fea2bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5560fea2bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5560fea2bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5560fea2bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5560fea2bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556100cc0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5560fd9edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5560fd9f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5560fd7a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5560fd7a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5560fd7a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5560fd7a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5560fd7a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5560fd7a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5561020aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5561020b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55610209f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5561020ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8e560b2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5560fb9c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x40,0x1,0x7f,0x77,0x1e,0x0,0x47,0x45,0x4f,0x42,0x7d,0x24,0x7f,0x5d,0x7f,0x7f,0x6f,0x7c,0x10,0x2f,0x5b,0x32,0x2e,0x2e,0x2d,0x73,0x20,0x37,0x20,0x30,0x20,0x32,0x10,0x20,0x33,0x10,0x2e,0x2f,0x2d,0x5f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x24, Step #5: ID3\004@\001\177w\036\000GEOB}$\177]\177\177o|\020/[2..-s 7 0 2\020 3\020./-_\177\177\177o\000\000C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-d07422fde16bcb0f716ef0deca3efcbc91fbb1b8 Step #5: Base64: SUQzBEABf3ceAEdFT0J9JH9df39vfBAvWzIuLi1zIDcgMCAyECAzEC4vLV9/f39vAABDJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3314 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3347828527 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5590f5c4f810, 0x5590f5e3901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5590f5e39020,0x5590f7cd10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d07422fde16bcb0f716ef0deca3efcbc91fbb1b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4067 processed earlier; will process 6962 files now Step #5: ==119380== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5590ec7449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5590f2da9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5590f2d8c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5590f2d8c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5590ec74ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5590ec6abb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5590ec6a6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5590ec73cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5590ef70bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5590ef70bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5590ef70bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5590ef70bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5590ef70bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5590ef70bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5590ef70bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5590ef70bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5590ef70bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5590ef70bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5590f19a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5590ee6cdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5590ee6d8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5590ee484c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5590ee484c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5590ee485738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5590ee484874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5590ee484874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5590ee484874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5590f2d8eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5590f2d97928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5590f2d7f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5590f2daa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5489623082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5590ec6a4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x90,0x80,0x81,0xef,0xbf,0xa9,0xef,0xb4,0xaf,0xef,0xbf,0xa9,0xef,0xbf,0xa3,0xef,0xbf,0xa3,0xef,0xbf,0xa8,0xef,0xbf,0xab,0xef,0xbf,0xa3,0xef,0xbf,0xa3,0xef,0xbf,0xa9,0xef,0xbf,0xab,0xef,0x9f,0xa3,0xef,0xbf,0xa3,0xef,0xbf,0xa9,0xef,0xbf,0xaf,0xef,0xa9,0xef, Step #5: \360\220\200\201\357\277\251\357\264\257\357\277\251\357\277\243\357\277\243\357\277\250\357\277\253\357\277\243\357\277\243\357\277\251\357\277\253\357\237\243\357\277\243\357\277\251\357\277\257\357\251\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-7b5449ba20fb57f84d263f7a1d7afb056fd0dc41 Step #5: Base64: 8JCAge+/qe+0r++/qe+/o++/o++/qO+/q++/o++/o++/qe+/q++fo++/o++/qe+/r++p7w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3315 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3348312428 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f1af515810, 0x55f1af6ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f1af6ff020,0x55f1b15970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7b5449ba20fb57f84d263f7a1d7afb056fd0dc41' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4068 processed earlier; will process 6961 files now Step #5: ==119416== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f1a600a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f1ac66f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1ac6525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1ac6524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f1a6010d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f1a5f71b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f1a5f6c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f1a6002c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f1a8fd1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f1a8fd1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f1a8fd1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f1a8fd1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f1a8fd1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f1a8fd1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f1a8fd1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f1a8fd1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f1a8fd1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f1a8fd1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f1ab266f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f1a7f93b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f1a7f9ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f1a7d4ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f1a7d4ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f1a7d4b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f1a7d4a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f1a7d4a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f1a7d4a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f1ac654abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f1ac65d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f1ac645699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f1ac670112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b9ce67082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f1a5f6ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x73,0x72,0x20,0x43,0x70,0x73,0x72,0x5f,0x2c,0x4c,0x52,0xd,0x4d,0x73,0x72,0x20,0x43,0x70,0x73,0x72,0x5f,0x2c,0x4c,0x52,0xd,0x4d,0x73,0x72,0x20,0x43,0x70,0x73,0x72,0x5f,0x2c,0x4c,0x52,0xd,0x4d,0x73,0x72,0x20,0x43,0x70,0x73,0x72,0x5f,0x2c,0x4c,0x3b,0x73, Step #5: Msr Cpsr_,LR\015Msr Cpsr_,LR\015Msr Cpsr_,LR\015Msr Cpsr_,L;s Step #5: artifact_prefix='./'; Test unit written to ./oom-8d75eec200eef5d20801e7eb95bd3613db85a31a Step #5: Base64: TXNyIENwc3JfLExSDU1zciBDcHNyXyxMUg1Nc3IgQ3Bzcl8sTFINTXNyIENwc3JfLEw7cw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3316 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3348790763 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5562dc5ce810, 0x5562dc7b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5562dc7b8020,0x5562de6500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d75eec200eef5d20801e7eb95bd3613db85a31a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4069 processed earlier; will process 6960 files now Step #5: ==119452== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5562d30c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5562d9728898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5562d970b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5562d970b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5562d30c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5562d302ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5562d3025355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5562d30bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5562d608af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5562d608af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5562d608af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5562d608af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5562d608af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5562d608af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5562d608af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5562d608af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5562d608af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5562d608af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5562d831ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5562d504cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5562d5057be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5562d4e03c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5562d4e03c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5562d4e04738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5562d4e03874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5562d4e03874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5562d4e03874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5562d970dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5562d9716928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5562d96fe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5562d9729112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2a934b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5562d3023b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4a,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0xe1,0x85,0x9f,0x0,0x34,0xe1,0x85,0x9f,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x47,0x64,0xa,0x2d,0xa,0xf3,0xa0,0x81,0xb3,0x66, Step #5: J-----BE\341\205\237\0004\341\205\237GIN -------IN -----------\012Gd\012-\012\363\240\201\263f Step #5: artifact_prefix='./'; Test unit written to ./oom-33ff3234553f6dbae159f6e98de93450308d5b33 Step #5: Base64: Si0tLS0tQkXhhZ8ANOGFn0dJTiAtLS0tLS0tSU4gLS0tLS0tLS0tLS0KR2QKLQrzoIGzZg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3317 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3349282206 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5603cebfe810, 0x5603cede801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5603cede8020,0x5603d0c800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/33ff3234553f6dbae159f6e98de93450308d5b33' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4070 processed earlier; will process 6959 files now Step #5: ==119488== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5603c56f39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5603cbd58898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5603cbd3b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5603cbd3b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5603c56f9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5603c565ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5603c5655355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5603c56ebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5603c86baf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5603c86baf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5603c86baf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5603c86baf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5603c86baf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5603c86baf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5603c86baf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5603c86baf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5603c86baf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5603c86baf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5603ca94ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5603c767cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5603c7687be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5603c7433c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5603c7433c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5603c7434738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5603c7433874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5603c7433874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5603c7433874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5603cbd3dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5603cbd46928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5603cbd2e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5603cbd59112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2175712082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5603c5653b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x45,0x58,0x50,0x20,0x20,0x31,0xa,0x43,0x6e,0x54,0x20,0x20,0x32,0xa,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x31,0x30,0x36,0x30,0x30,0x30,0x31,0x35,0x36,0x31,0x35,0x2e,0xf9,0x20, Step #5: EXP 1\012CnT 2\01200000000000000009223372010600015615.\371 Step #5: artifact_prefix='./'; Test unit written to ./oom-1f96463b53364de58ee84c57b9fcccfef7421b71 Step #5: Base64: RVhQICAxCkNuVCAgMgowMDAwMDAwMDAwMDAwMDAwOTIyMzM3MjAxMDYwMDAxNTYxNS75IA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3318 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3349771147 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f83101d810, 0x55f83120701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f831207020,0x55f83309f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f96463b53364de58ee84c57b9fcccfef7421b71' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4071 processed earlier; will process 6958 files now Step #5: ==119524== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f827b129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f82e177898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f82e15a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f82e15a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f827b18d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f827a79b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f827a74355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f827b0ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f82aad9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f82aad9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f82aad9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f82aad9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f82aad9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f82aad9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f82aad9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f82aad9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f82aad9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f82aad9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f82cd6ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f829a9bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f829aa6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f829852c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f829852c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f829853738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f829852874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f829852874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f829852874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f82e15cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f82e165928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f82e14d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f82e178112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8c078d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f827a72b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x30,0xe0,0xa7,0x9c,0xe1,0xb7,0x9a,0xe0,0xb7,0x9d,0xe1,0xa5,0x9d,0xe0,0xa5,0x9d,0xe1,0xa5,0x9d,0xe0,0xa5,0x9d,0x30,0x65,0x78,0x2d,0x36,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x5a,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text>0\340\247\234\341\267\232\340\267\235\341\245\235\340\245\235\341\245\235\340\245\2350ex-6</text>Z</svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-b39a1a64fb99e548df45498dd8284bbb95b60aeb Step #5: Base64: PHN2Zz48dGV4dD4w4Kec4bea4Led4aWd4KWd4aWd4KWdMGV4LTY8L3RleHQ+Wjwvc3ZnPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3319 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3350268878 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55da06741810, 0x55da0692b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55da0692b020,0x55da087c30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b39a1a64fb99e548df45498dd8284bbb95b60aeb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4072 processed earlier; will process 6957 files now Step #5: ==119560== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d9fd2369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55da0389b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55da0387e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55da0387e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d9fd23cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d9fd19db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d9fd198355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d9fd22ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55da001fdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55da001fdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55da001fdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55da001fdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55da001fdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55da001fdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55da001fdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55da001fdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55da001fdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55da001fdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55da02492f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d9ff1bfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d9ff1cabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d9fef76c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d9fef76c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d9fef77738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d9fef76874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d9fef76874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d9fef76874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55da03880abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55da03889928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55da03871699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55da0389c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba6b26d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d9fd196b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x40,0x1,0x7f,0x77,0x1e,0x0,0x47,0x45,0x4f,0x42,0x7d,0x24,0x7f,0x5d,0x7f,0x7f,0x6f,0x7c,0x10,0x2f,0x5b,0x32,0x2e,0x2e,0x2f,0x73,0x20,0x37,0x20,0x30,0x20,0x32,0x10,0x20,0x32,0x10,0x2e,0x2f,0x2d,0x5f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x24, Step #5: ID3\004@\001\177w\036\000GEOB}$\177]\177\177o|\020/[2../s 7 0 2\020 2\020./-_\177\177\177o\000\000C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-83b818d8353e35693ced8bcc4447f539946870a1 Step #5: Base64: SUQzBEABf3ceAEdFT0J9JH9df39vfBAvWzIuLi9zIDcgMCAyECAyEC4vLV9/f39vAABDJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3320 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3350786274 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564e744a2810, 0x564e7468c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564e7468c020,0x564e765240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/83b818d8353e35693ced8bcc4447f539946870a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4073 processed earlier; will process 6956 files now Step #5: ==119596== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564e6af979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564e715fc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564e715df5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564e715df4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564e6af9dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564e6aefeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564e6aef9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564e6af8fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564e6df5ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564e6df5ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564e6df5ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564e6df5ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564e6df5ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564e6df5ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564e6df5ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564e6df5ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564e6df5ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564e6df5ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564e701f3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564e6cf20b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564e6cf2bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564e6ccd7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564e6ccd7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564e6ccd8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564e6ccd7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564e6ccd7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564e6ccd7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564e715e1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564e715ea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564e715d2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564e715fd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b4204b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564e6aef7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x55,0x54,0x20,0x2f,0xa,0x54,0x72,0x61,0x6e,0x73,0x66,0x65,0x72,0x2d,0x45,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3a,0x63,0x68,0x75,0x6e,0x6b,0x65,0x64,0xa,0xa,0x66,0x66,0x66,0x66,0x46,0x66,0x66,0x66,0x46,0x66,0x66,0x66,0xc4,0x99,0x9a,0xc8,0xd,0xa,0x6b, Step #5: PUT /\012Transfer-Encoding:chunked\012\012ffffFfffFfff\304\231\232\310\015\012k Step #5: artifact_prefix='./'; Test unit written to ./oom-8cf49f5a4399dbd32fc53e349d680a845381648b Step #5: Base64: UFVUIC8KVHJhbnNmZXItRW5jb2Rpbmc6Y2h1bmtlZAoKZmZmZkZmZmZGZmZmxJmayA0Kaw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3321 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3351281274 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560e1e400810, 0x560e1e5ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560e1e5ea020,0x560e204820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8cf49f5a4399dbd32fc53e349d680a845381648b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4074 processed earlier; will process 6955 files now Step #5: ==119632== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560e14ef59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560e1b55a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560e1b53d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560e1b53d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560e14efbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560e14e5cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560e14e57355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560e14eedc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560e17ebcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560e17ebcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560e17ebcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560e17ebcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560e17ebcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560e17ebcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560e17ebcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560e17ebcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560e17ebcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560e17ebcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560e1a151f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560e16e7eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560e16e89be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560e16c35c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560e16c35c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560e16c36738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560e16c35874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560e16c35874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560e16c35874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560e1b53fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560e1b548928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560e1b530699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560e1b55b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd8a3d02082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560e14e55b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0x5b,0x5c,0x70,0x4c,0x2e,0x2d,0xc6,0xac,0x52,0x29,0x8,0x5d,0x5b,0x5c,0x70,0x4c,0x2e,0x2d,0xc6,0xac,0x52,0x29,0x8,0x5d,0x5b,0x5c,0x70,0x4c,0x2e,0x2d,0xc6,0xac,0x52,0x29,0x8,0x5d,0x5b,0x5c,0x70,0x4c,0x2e,0x2d,0xc6,0xac,0x52,0x2b,0x8,0x5d, Step #5: (?i)[\\pL.-\306\254R)\010][\\pL.-\306\254R)\010][\\pL.-\306\254R)\010][\\pL.-\306\254R+\010] Step #5: artifact_prefix='./'; Test unit written to ./oom-20f27da9a50ba541e8d906bcc7b51fd48fc4b3a6 Step #5: Base64: KD9pKVtccEwuLcasUikIXVtccEwuLcasUikIXVtccEwuLcasUikIXVtccEwuLcasUisIXQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3322 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3351777518 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560917a2c810, 0x560917c1601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560917c16020,0x560919aae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/20f27da9a50ba541e8d906bcc7b51fd48fc4b3a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4075 processed earlier; will process 6954 files now Step #5: ==119668== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56090e5219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560914b86898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560914b695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560914b694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56090e527d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56090e488b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56090e483355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56090e519c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5609114e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5609114e8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5609114e8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5609114e8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5609114e8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5609114e8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5609114e8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5609114e8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5609114e8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5609114e8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56091377df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5609104aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5609104b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560910261c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560910261c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560910262738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560910261874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560910261874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560910261874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560914b6babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560914b74928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560914b5c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560914b87112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b36d92082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56090e481b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x80,0xa4,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xba,0xe0,0xaa,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb9,0xe0,0xb2,0xba,0xe0,0xaa,0xb2,0xe0,0xb2,0xb2, Step #5: \363\240\200\244\340\262\262\340\262\262\340\262\262\340\262\262\340\262\262\340\262\262\340\262\262\340\262\262\340\262\262\340\262\272\340\252\262\340\262\262\340\262\271\340\262\272\340\252\262\340\262\262 Step #5: artifact_prefix='./'; Test unit written to ./oom-8c12088f7e09c11209a0e2444704e70027f958d5 Step #5: Base64: 86CApOCysuCysuCysuCysuCysuCysuCysuCysuCysuCyuuCqsuCysuCyueCyuuCqsuCysg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3323 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3352272826 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55782456a810, 0x55782475401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557824754020,0x5578265ec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c12088f7e09c11209a0e2444704e70027f958d5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4076 processed earlier; will process 6953 files now Step #5: ==119704== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55781b05f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5578216c4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5578216a75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5578216a74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55781b065d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55781afc6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55781afc1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55781b057c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55781e026f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55781e026f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55781e026f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55781e026f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55781e026f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55781e026f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55781e026f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55781e026f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55781e026f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55781e026f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5578202bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55781cfe8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55781cff3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55781cd9fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55781cd9fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55781cda0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55781cd9f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55781cd9f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55781cd9f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5578216a9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5578216b2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55782169a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5578216c5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa1ebf60082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55781afbfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x45,0x47,0xff, Step #5: x-----B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-BEG\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-fb3feb94820ebdacb5dfc40a3d97c37674fcdf9d Step #5: Base64: eC0tLS0tQi1CLUItQi1CLUItQi1CLUItQi1CLUItQi1CLUItQi1CLUItQi1CLUItQkVH/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3324 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3352759346 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc9224e810, 0x55fc9243801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc92438020,0x55fc942d00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fb3feb94820ebdacb5dfc40a3d97c37674fcdf9d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4077 processed earlier; will process 6952 files now Step #5: ==119740== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fc88d439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc8f3a8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc8f38b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc8f38b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc88d49d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc88caab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc88ca5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc88d3bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc8bd0af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc8bd0af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc8bd0af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc8bd0af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc8bd0af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc8bd0af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc8bd0af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc8bd0af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc8bd0af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc8bd0af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc8df9ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc8acccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc8acd7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc8aa83c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc8aa83c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc8aa84738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc8aa83874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc8aa83874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc8aa83874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc8f38dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc8f396928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc8f37e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc8f3a9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0eec9bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc88ca3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x4f,0x27,0xd1,0xa1,0x27,0x45,0x27,0x5c,0xd1,0xa1,0x27,0x45,0x27,0x5b,0xca,0xb6,0xd1,0xa1,0x27,0x45,0x27,0x5c,0xd1,0xa1,0x27,0x45,0x27,0x5b,0xca,0xb6,0xd1,0xa1,0x27,0x45,0x27,0x5c,0xd1,0xa1,0x27,0x45,0x27,0x5c,0xd1,0xa1,0x27,0x5c,0x2f,0xab,0xac,0x27,0x5c, Step #5: dO'\321\241'E'\\\321\241'E'[\312\266\321\241'E'\\\321\241'E'[\312\266\321\241'E'\\\321\241'E'\\\321\241'\\/\253\254'\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-7fe108005f0bebcfd06fdcd3ce99b6bc7c036376 Step #5: Base64: ZE8n0aEnRSdc0aEnRSdbyrbRoSdFJ1zRoSdFJ1vKttGhJ0UnXNGhJ0UnXNGhJ1wvq6wnXA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3325 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3353243917 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562a665e0810, 0x562a667ca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562a667ca020,0x562a686620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7fe108005f0bebcfd06fdcd3ce99b6bc7c036376' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4078 processed earlier; will process 6951 files now Step #5: ==119776== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562a5d0d59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562a6373a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562a6371d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562a6371d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562a5d0dbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562a5d03cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562a5d037355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562a5d0cdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562a6009cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562a6009cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562a6009cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562a6009cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562a6009cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562a6009cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562a6009cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562a6009cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562a6009cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562a6009cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562a62331f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562a5f05eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562a5f069be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562a5ee15c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562a5ee15c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562a5ee16738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562a5ee15874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562a5ee15874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562a5ee15874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562a6371fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562a63728928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562a63710699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562a6373b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a1e99a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562a5d035b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x76,0x21,0x39,0xa,0x0,0x70,0x69,0x7d,0x7d,0x7d,0x7d,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x72,0x65,0x61,0x6d,0xd7,0xaf,0x39,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0xd7,0xa3,0x1,0xd7,0xa3,0x2d,0x0, Step #5: #v!9\012\000pi}}}}dddddddream\327\2579>>>>>>>>>>>>>>>>>>>\327\243\001\327\243-\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0d996df07f4b4ccbf2b3ec5e20fc96ed1b6845c5 Step #5: Base64: I3YhOQoAcGl9fX19ZGRkZGRkZHJlYW3Xrzk+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+16MB16MtAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3326 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3353729545 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb42777810, 0x55eb4296101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb42961020,0x55eb447f90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0d996df07f4b4ccbf2b3ec5e20fc96ed1b6845c5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4079 processed earlier; will process 6950 files now Step #5: ==119812== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eb3926c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb3f8d1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb3f8b45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb3f8b44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb39272d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb391d3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb391ce355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb39264c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb3c233f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb3c233f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb3c233f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb3c233f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb3c233f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb3c233f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb3c233f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb3c233f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb3c233f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb3c233f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb3e4c8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb3b1f5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb3b200be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb3afacc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb3afacc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb3afad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb3afac874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb3afac874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb3afac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb3f8b6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb3f8bf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb3f8a7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb3f8d2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff34de85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb391ccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x3a,0x24,0x30,0x3a,0x3a,0x28,0x24,0x33,0x3a,0x3a,0x7b,0x24,0x3a,0x24,0x30,0x3a,0x3a,0x28,0x24,0x30,0x3a,0x3a,0x28,0x24,0x34,0x3a,0x3a,0x7b,0x24,0x3a,0x24,0x30,0x3a,0x3a,0x28,0x24,0x31,0x3a,0x3a,0x28,0x24,0x33,0x3a,0x3a,0x7b,0x30, Step #5: $3::{$:$0::($3::{$:$0::($0::($4::{$:$0::($1::($3::{0 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7eae870fed6de502f366c851309833972adeaa3 Step #5: Base64: JDM6OnskOiQwOjooJDM6OnskOiQwOjooJDA6OigkNDo6eyQ6JDA6OigkMTo6KCQzOjp7MA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3327 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3354215046 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b9730d810, 0x555b974f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b974f7020,0x555b9938f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7eae870fed6de502f366c851309833972adeaa3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4080 processed earlier; will process 6949 files now Step #5: ==119848== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555b8de029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b94467898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b9444a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b9444a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b8de08d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b8dd69b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b8dd64355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b8ddfac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b90dc9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b90dc9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b90dc9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b90dc9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b90dc9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b90dc9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b90dc9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b90dc9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b90dc9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b90dc9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b9305ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b8fd8bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b8fd96be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b8fb42c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b8fb42c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b8fb43738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b8fb42874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b8fb42874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b8fb42874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b9444cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b94455928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b9443d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b94468112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9227082082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b8dd62b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x27,0x3f,0x28,0xcc,0x9d,0x3f,0x28,0xcc,0x9d,0x0,0x26,0x28,0xcc,0x9d,0x29,0x0,0x7d,0xcc,0x9d,0x3f,0x28,0xcc,0x9d,0x0,0x26,0x28,0xcc,0x9d,0x29,0x0,0x7d,0x29,0x7b,0x36,0x39,0x34,0x29,0x7b,0x36,0x39,0x3f,0x76,0x7d,0x34,0x7d,0x29,0x7b,0x34,0x38,0x33,0x7d, Step #5: ('?(\314\235?(\314\235\000&(\314\235)\000}\314\235?(\314\235\000&(\314\235)\000}){694){69?v}4}){483} Step #5: artifact_prefix='./'; Test unit written to ./oom-b84c9087da0a0a53b6252da8a9a50fbb02618b63 Step #5: Base64: KCc/KMydPyjMnQAmKMydKQB9zJ0/KMydACYozJ0pAH0pezY5NCl7Njk/dn00fSl7NDgzfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3328 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3354697284 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e99b61b810, 0x55e99b80501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e99b805020,0x55e99d69d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b84c9087da0a0a53b6252da8a9a50fbb02618b63' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4081 processed earlier; will process 6948 files now Step #5: ==119884== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e9921109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e998775898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9987585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9987584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e992116d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e992077b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e992072355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e992108c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e9950d7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e9950d7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e9950d7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e9950d7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e9950d7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e9950d7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e9950d7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e9950d7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e9950d7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e9950d7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e99736cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e994099b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e9940a4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e993e50c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e993e50c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e993e51738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e993e50874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e993e50874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e993e50874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e99875aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e998763928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e99874b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e998776112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa386645082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e992070b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0xbd,0xb5,0xb5,0xe0,0xbe,0x98,0xe0,0xbe,0x98,0xe0,0xbe,0x98,0xe0,0xbe,0x98,0xe0,0xbe,0x98,0xe0,0xab,0x82,0xe0,0xbe,0x98,0xe0,0xbe,0x98,0xe0,0xbe,0x98,0xe0,0xbe,0x98,0xe0,0xbe,0x98,0xe0,0xbe,0x98,0xe0,0xbe,0x98,0xe0,0xbe,0x98,0xe0,0xbe,0x98,0xe0,0xbe,0xe8, Step #5: \360\275\265\265\340\276\230\340\276\230\340\276\230\340\276\230\340\276\230\340\253\202\340\276\230\340\276\230\340\276\230\340\276\230\340\276\230\340\276\230\340\276\230\340\276\230\340\276\230\340\276\350 Step #5: artifact_prefix='./'; Test unit written to ./oom-f1a8d5417f7b3477b681b27debfbd9d891ac3d2b Step #5: Base64: 8L21teC+mOC+mOC+mOC+mOC+mOCrguC+mOC+mOC+mOC+mOC+mOC+mOC+mOC+mOC+mOC+6A== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3329 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3355177659 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b055d7a810, 0x55b055f6401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b055f64020,0x55b057dfc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f1a8d5417f7b3477b681b27debfbd9d891ac3d2b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4082 processed earlier; will process 6947 files now Step #5: #1 pulse cov: 3601 ft: 3602 exec/s: 0 rss: 171Mb Step #5: ==119920== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b04c86f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b052ed4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b052eb75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b052eb74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b04c875d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b04c7d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b04c7d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b04c867c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b04f836f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b04f836f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b04f836f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b04f836f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b04f836f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b04f836f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b04f836f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b04f836f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b04f836f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b04f836f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b051acbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b04e7f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b04e803be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b04e5afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b04e5afc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b04e5b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b04e5af874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b04e5af874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b04e5af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b052eb9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b052ec2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b052eaa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b052ed5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a74905082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b04c7cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x94,0x8f,0x8b,0xe2,0x80,0x88,0xe2,0x80,0x88,0xe2,0x80,0x88,0xe2,0x80,0x8a,0xe2,0x80,0x8a,0xe2,0x80,0x82,0xe2,0x80,0x8a,0xe2,0x80,0x80,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x8a,0xe3,0x81,0x9f, Step #5: \360\224\217\213\342\200\210\342\200\210\342\200\210\342\200\212\342\200\212\342\200\202\342\200\212\342\200\200\342\201\237\342\201\237\342\201\237\342\201\237\342\201\237\342\201\237\342\201\212\343\201\237 Step #5: artifact_prefix='./'; Test unit written to ./oom-91cb41dc7ab01213fe061f1004193df93c31ef74 Step #5: Base64: 8JSPi+KAiOKAiOKAiOKAiuKAiuKAguKAiuKAgOKBn+KBn+KBn+KBn+KBn+KBn+KBiuOBnw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3330 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3355700558 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a357455810, 0x55a35763f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a35763f020,0x55a3594d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/91cb41dc7ab01213fe061f1004193df93c31ef74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4084 processed earlier; will process 6945 files now Step #5: #1 pulse cov: 3593 ft: 3594 exec/s: 0 rss: 172Mb Step #5: ==119956== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a34df4a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3545af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3545925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3545924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a34df50d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a34deb1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a34deac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a34df42c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a350f11f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a350f11f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a350f11f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a350f11f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a350f11f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a350f11f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a350f11f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a350f11f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a350f11f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a350f11f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3531a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a34fed3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a34fedebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a34fc8ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a34fc8ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a34fc8b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a34fc8a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a34fc8a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a34fc8a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a354594abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a35459d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a354585699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3545b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b92ee9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a34deaab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x30,0xe0,0xa7,0xa1,0xe0,0xb7,0x9a,0xe0,0xb7,0x9d,0xe1,0xa5,0x9d,0xe0,0xbc,0x9d,0xe0,0xb7,0x9d,0xe0,0xb7,0x9d,0xe0,0xb7,0x9d,0x2d,0x2b,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x5a,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text>0\340\247\241\340\267\232\340\267\235\341\245\235\340\274\235\340\267\235\340\267\235\340\267\235-+</text>Z</svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-03a0f89ecd6b6ce066e93c360e5657fb21dd4dcc Step #5: Base64: PHN2Zz48dGV4dD4w4Keh4Lea4Led4aWd4Lyd4Led4Led4LedLSs8L3RleHQ+Wjwvc3ZnPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3331 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3356226633 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1dee6a810, 0x55a1df05401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1df054020,0x55a1e0eec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03a0f89ecd6b6ce066e93c360e5657fb21dd4dcc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4086 processed earlier; will process 6943 files now Step #5: #1 pulse cov: 3735 ft: 3736 exec/s: 0 rss: 173Mb Step #5: ==119992== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1d595f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1dbfc4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1dbfa75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1dbfa74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1d5965d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1d58c6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1d58c1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1d5957c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1d8926f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1d8926f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1d8926f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1d8926f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1d8926f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1d8926f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1d8926f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1d8926f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1d8926f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1d8926f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1dabbbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1d78e8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1d78f3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1d769fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1d769fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1d76a0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1d769f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1d769f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1d769f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a1dbfa9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a1dbfb2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1dbf9a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1dbfc5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd1ee62d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1d58bfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x80,0x80,0xed,0x98,0x80,0xed,0x90,0xa0,0xed,0x98,0x80,0xed,0x90,0x80,0xed,0x98,0x80,0xed,0x90,0x80,0xed,0x98,0x80,0xed,0x90,0x80,0xed,0x98,0x80,0xed,0x90,0x80,0xed,0x80,0x90,0xed,0x98,0x80,0xed,0x98,0x80,0xed,0x90,0x80,0xed,0x98,0x80,0xed,0x90,0xed, Step #5: \363\240\200\200\355\230\200\355\220\240\355\230\200\355\220\200\355\230\200\355\220\200\355\230\200\355\220\200\355\230\200\355\220\200\355\200\220\355\230\200\355\230\200\355\220\200\355\230\200\355\220\355 Step #5: artifact_prefix='./'; Test unit written to ./oom-c2b8772225e62607a37f2489695632fac195c26e Step #5: Base64: 86CAgO2YgO2QoO2YgO2QgO2YgO2QgO2YgO2QgO2YgO2QgO2AkO2YgO2YgO2QgO2YgO2Q7Q== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3332 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3356754485 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5621c67a8810, 0x5621c699201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5621c6992020,0x5621c882a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c2b8772225e62607a37f2489695632fac195c26e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4088 processed earlier; will process 6941 files now Step #5: #1 pulse cov: 3504 ft: 3505 exec/s: 0 rss: 171Mb Step #5: #2 pulse cov: 3716 ft: 3941 exec/s: 0 rss: 172Mb Step #5: ==120028== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5621bd29d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5621c3902898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5621c38e55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5621c38e54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5621bd2a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5621bd204b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5621bd1ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5621bd295c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5621c0264f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5621c0264f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5621c0264f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5621c0264f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5621c0264f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5621c0264f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5621c0264f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5621c0264f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5621c0264f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5621c0264f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5621c24f9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5621bf226b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5621bf231be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5621befddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5621befddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5621befde738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5621befdd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5621befdd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5621befdd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5621c38e7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5621c38f0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5621c38d8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5621c3903112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f39952d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5621bd1fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x27,0x3f,0x28,0xcc,0x9d,0x3f,0x28,0xcc,0x9d,0x0,0x26,0x28,0xcc,0x9d,0x29,0x0,0x7d,0xcc,0x9d,0x3f,0x28,0xcc,0x9d,0x0,0x26,0x28,0xcc,0x9d,0x29,0x0,0x7d,0x29,0x7b,0x36,0x39,0x34,0x29,0x7b,0x36,0x39,0x34,0x7d,0x76,0x3f,0x7d,0x29,0x7b,0x34,0x38,0x33,0x7d, Step #5: ('?(\314\235?(\314\235\000&(\314\235)\000}\314\235?(\314\235\000&(\314\235)\000}){694){694}v?}){483} Step #5: artifact_prefix='./'; Test unit written to ./oom-555a7a644bd630f20cd6909512b34af4aebd63ec Step #5: Base64: KCc/KMydPyjMnQAmKMydKQB9zJ0/KMydACYozJ0pAH0pezY5NCl7Njk0fXY/fSl7NDgzfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3333 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3357359143 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5602842f3810, 0x5602844dd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5602844dd020,0x5602863750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/555a7a644bd630f20cd6909512b34af4aebd63ec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4092 processed earlier; will process 6937 files now Step #5: ==120064== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56027ade89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56028144d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602814305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602814304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56027adeed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56027ad4fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56027ad4a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56027ade0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56027ddaff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56027ddaff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56027ddaff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56027ddaff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56027ddaff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56027ddaff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56027ddaff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56027ddaff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56027ddaff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56027ddaff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560280044f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56027cd71b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56027cd7cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56027cb28c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56027cb28c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56027cb29738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56027cb28874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56027cb28874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56027cb28874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560281432abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56028143b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560281423699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56028144e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbf6a8cb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56027ad48b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xa,0x72,0x32,0x66,0x3d,0x42,0x42,0xa,0x3d,0x20,0x60,0xd8,0x80,0x4,0x0,0x0,0xa,0xd8,0x80,0x0,0x4,0x0,0xa,0x0,0x0,0x8,0xa,0x3d,0x20,0x20,0x2e,0x1a,0x20,0x2e,0x2d,0x13,0x1d,0x10,0x0,0xa,0xd8,0x80,0x4,0x1c,0x60,0x0,0x66,0x0,0x60,0x60,0xa, Step #5: \000\012r2f=BB\012= `\330\200\004\000\000\012\330\200\000\004\000\012\000\000\010\012= .\032 .-\023\035\020\000\012\330\200\004\034`\000f\000``\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-dbd778558ab2dd37e4b0b56865f511a0ade69eb6 Step #5: Base64: AApyMmY9QkIKPSBg2IAEAAAK2IAABAAKAAAICj0gIC4aIC4tEx0QAArYgAQcYABmAGBgCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3334 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3357968125 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e357632810, 0x55e35781c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e35781c020,0x55e3596b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dbd778558ab2dd37e4b0b56865f511a0ade69eb6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4093 processed earlier; will process 6936 files now Step #5: ==120100== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e34e1279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e35478c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e35476f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e35476f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e34e12dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e34e08eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e34e089355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e34e11fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e3510eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e3510eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e3510eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e3510eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e3510eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e3510eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e3510eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e3510eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e3510eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e3510eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e353383f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e3500b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e3500bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e34fe67c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e34fe67c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e34fe68738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e34fe67874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e34fe67874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e34fe67874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e354771abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e35477a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e354762699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e35478d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ee4a47082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e34e087b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x53,0x3a,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x99,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x97,0xe3,0x8c,0x96, Step #5: \016wS:\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\231\343\214\226\343\214\226\343\214\227\343\214\226 Step #5: artifact_prefix='./'; Test unit written to ./oom-61cc93fb7f5a473648db5e438f32807162e94f74 Step #5: Base64: DndTOuOMluOMluOMluOMluOMluOMluOMluOMluOMluOMluOMluOMmeOMluOMluOMl+OMlg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3335 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3358448635 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e83e663810, 0x55e83e84d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e83e84d020,0x55e8406e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/61cc93fb7f5a473648db5e438f32807162e94f74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4094 processed earlier; will process 6935 files now Step #5: ==120136== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e8351589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e83b7bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e83b7a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e83b7a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e83515ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e8350bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e8350ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e835150c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e83811ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e83811ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e83811ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e83811ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e83811ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e83811ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e83811ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e83811ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e83811ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e83811ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e83a3b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e8370e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e8370ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e836e98c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e836e98c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e836e99738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e836e98874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e836e98874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e836e98874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e83b7a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e83b7ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e83b793699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e83b7be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f718d464082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e8350b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x78,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5, Step #5: ws:x\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-8e93bc46b3b62fc46ec1bcc1e42bbba6e419f037 Step #5: Base64: d3M6eOGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGstQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3336 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3358932415 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560e5d1fb810, 0x560e5d3e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560e5d3e5020,0x560e5f27d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8e93bc46b3b62fc46ec1bcc1e42bbba6e419f037' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4095 processed earlier; will process 6934 files now Step #5: ==120172== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560e53cf09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560e5a355898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560e5a3385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560e5a3384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560e53cf6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560e53c57b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560e53c52355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560e53ce8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560e56cb7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560e56cb7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560e56cb7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560e56cb7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560e56cb7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560e56cb7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560e56cb7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560e56cb7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560e56cb7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560e56cb7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560e58f4cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560e55c79b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560e55c84be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560e55a30c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560e55a30c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560e55a31738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560e55a30874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560e55a30874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560e55a30874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560e5a33aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560e5a343928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560e5a32b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560e5a356112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3460f15082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560e53c50b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x66,0x31,0x3e,0x3c,0x66,0x66,0x66,0x66,0x70,0x66,0x70,0x65,0x3e,0x3c,0x66,0x66,0x66,0x66,0x70,0x66,0x70,0x65,0x3e,0x3f,0x78,0x6d,0x6c,0x3c,0x66,0x66,0x66,0x66,0x70,0x66,0x70,0x65,0x3e,0x38,0x30,0x32,0x66,0x0,0x3e,0x3f,0x67,0x62,0x32,0x33,0x31,0x32,0x78, Step #5: <f1><ffffpfpe><ffffpfpe>?xml<ffffpfpe>802f\000>?gb2312x Step #5: artifact_prefix='./'; Test unit written to ./oom-f31ddfdfb18efa8863b9289c7758edb4a5b334cc Step #5: Base64: PGYxPjxmZmZmcGZwZT48ZmZmZnBmcGU+P3htbDxmZmZmcGZwZT44MDJmAD4/Z2IyMzEyeA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3337 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3359418781 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b313894810, 0x55b313a7e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b313a7e020,0x55b3159160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f31ddfdfb18efa8863b9289c7758edb4a5b334cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4096 processed earlier; will process 6933 files now Step #5: ==120208== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b30a3899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b3109ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b3109d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b3109d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b30a38fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b30a2f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b30a2eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b30a381c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b30d350f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b30d350f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b30d350f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b30d350f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b30d350f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b30d350f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b30d350f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b30d350f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b30d350f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b30d350f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b30f5e5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b30c312b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b30c31dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b30c0c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b30c0c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b30c0ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b30c0c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b30c0c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b30c0c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b3109d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b3109dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b3109c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b3109ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0a7dd19082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b30a2e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x30,0x6a,0x6f,0x62,0x73,0x3a,0xa,0x20,0xd5,0x9a,0xc7,0x99,0xce,0xbd,0xdd,0xaa,0xd5,0x95,0xc7,0x9a,0x24,0xd7,0x85,0xd7,0x9a,0x9,0x2d,0x30,0x62,0x20,0xd5,0x9a,0xc7,0x99,0xcd,0x9c,0x9,0x3a,0xa,0x24,0xdc,0x90,0xc6,0xa5,0x32,0x6e,0x25,0x3a,0x20, Step #5: \000\000\0000jobs:\012 \325\232\307\231\316\275\335\252\325\225\307\232$\327\205\327\232\011-0b \325\232\307\231\315\234\011:\012$\334\220\306\2452n%: Step #5: artifact_prefix='./'; Test unit written to ./oom-29ad8ffe2e8160c134f9e35465dc025634546fc3 Step #5: Base64: AAAAMGpvYnM6CiDVmseZzr3dqtWVx5ok14XXmgktMGIg1ZrHmc2cCToKJNyQxqUybiU6IA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3338 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3359913152 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5634040e4810, 0x5634042ce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5634042ce020,0x5634061660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/29ad8ffe2e8160c134f9e35465dc025634546fc3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4097 processed earlier; will process 6932 files now Step #5: ==120244== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5633fabd99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56340123e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634012215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634012214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5633fabdfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5633fab40b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5633fab3b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5633fabd1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5633fdba0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5633fdba0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5633fdba0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5633fdba0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5633fdba0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5633fdba0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5633fdba0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5633fdba0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5633fdba0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5633fdba0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5633ffe35f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5633fcb62b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5633fcb6dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5633fc919c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5633fc919c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5633fc91a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5633fc919874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5633fc919874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5633fc919874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563401223abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56340122c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563401214699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56340123f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6edf9c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5633fab39b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x6a,0x2d,0x24,0x42,0x22,0x22,0x22,0xe2,0x80,0xad,0x22,0x3d,0x24,0x74,0x2d,0xf3,0xa0,0x81,0x8b,0x21,0x2d,0x2d,0x24,0x3d,0x24,0x42,0x6a,0x2d,0x24,0x42,0x22,0x22,0x22,0xe2,0x80,0xad,0x22,0x3d,0x24,0x74,0x2d,0xf3,0xa0,0x81,0x8b,0x21,0x2d,0x2d,0x24,0x3d,0x24, Step #5: Bj-$B\"\"\"\342\200\255\"=$t-\363\240\201\213!--$=$Bj-$B\"\"\"\342\200\255\"=$t-\363\240\201\213!--$=$ Step #5: artifact_prefix='./'; Test unit written to ./oom-3b660c95e4a3b1f297b92216aaa7f87170c6c8d0 Step #5: Base64: QmotJEIiIiLigK0iPSR0LfOggYshLS0kPSRCai0kQiIiIuKArSI9JHQt86CBiyEtLSQ9JA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3339 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3360405811 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fcf67aa810, 0x55fcf699401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fcf6994020,0x55fcf882c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3b660c95e4a3b1f297b92216aaa7f87170c6c8d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4098 processed earlier; will process 6931 files now Step #5: ==120280== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fced29f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fcf3904898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fcf38e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fcf38e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fced2a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fced206b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fced201355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fced297c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fcf0266f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fcf0266f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fcf0266f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fcf0266f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fcf0266f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fcf0266f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fcf0266f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fcf0266f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fcf0266f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fcf0266f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fcf24fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fcef228b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fcef233be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fceefdfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fceefdfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fceefe0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fceefdf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fceefdf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fceefdf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fcf38e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fcf38f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fcf38da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fcf3905112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba2d2b5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fced1ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x4f,0x27,0x27,0xc,0x27,0x27,0xc,0x27,0x27,0xc,0x27,0x27,0xc,0x27,0x27,0xc,0x27,0x27,0xc,0x27,0x27,0xc,0x27,0xef,0xbc,0x8f,0x27,0xc,0x27,0x27,0xc,0x27,0x27,0xc,0x27,0x27,0xc,0x27,0x27,0xc,0x27,0x27,0xc,0x27,0x27,0xc,0x27,0x27,0xc,0xc,0x27,0x27, Step #5: dO''\014''\014''\014''\014''\014''\014''\014'\357\274\217'\014''\014''\014''\014''\014''\014''\014''\014\014'' Step #5: artifact_prefix='./'; Test unit written to ./oom-b4e4955c0762fe459a2dce66b76722b1444f006e Step #5: Base64: ZE8nJwwnJwwnJwwnJwwnJwwnJwwnJwwn77yPJwwnJwwnJwwnJwwnJwwnJwwnJwwnJwwMJyc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3340 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3360892639 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f6f32b6810, 0x55f6f34a001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f6f34a0020,0x55f6f53380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b4e4955c0762fe459a2dce66b76722b1444f006e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4099 processed earlier; will process 6930 files now Step #5: ==120316== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f6e9dab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f6f0410898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f6f03f35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f6f03f34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f6e9db1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f6e9d12b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f6e9d0d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f6e9da3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f6ecd72f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f6ecd72f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f6ecd72f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f6ecd72f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f6ecd72f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f6ecd72f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f6ecd72f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f6ecd72f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f6ecd72f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f6ecd72f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f6ef007f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f6ebd34b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f6ebd3fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f6ebaebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f6ebaebc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f6ebaec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f6ebaeb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f6ebaeb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f6ebaeb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f6f03f5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f6f03fe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f6f03e6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f6f0411112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9d9d3df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f6e9d0bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2c,0x2d,0x2d,0x2d,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2,0xa,0x2d,0xa,0x2d,0xa,0xff, Step #5: \000-----BEGIN ,----\012,\012-\012d\012-\012d\012d\012-\012\002\012-\012\002\012-\012,\012-\012d\012\002\012-\012-\012\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-f41ebf8c144ef04338840eef6275d70ae25ef580 Step #5: Base64: AC0tLS0tQkVHSU4gLC0tLS0KLAotCmQKLQpkCmQKLQoCCi0KAgotCiwKLQpkCgIKLQotCv8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3341 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3361397642 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b9c9aab810, 0x55b9c9c9501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b9c9c95020,0x55b9cbb2d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f41ebf8c144ef04338840eef6275d70ae25ef580' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4100 processed earlier; will process 6929 files now Step #5: ==120352== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b9c05a09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b9c6c05898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b9c6be85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b9c6be84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b9c05a6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b9c0507b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b9c0502355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b9c0598c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b9c3567f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b9c3567f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b9c3567f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b9c3567f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b9c3567f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b9c3567f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b9c3567f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b9c3567f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b9c3567f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b9c3567f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b9c57fcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b9c2529b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b9c2534be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b9c22e0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b9c22e0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b9c22e1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b9c22e0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b9c22e0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b9c22e0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b9c6beaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b9c6bf3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b9c6bdb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b9c6c06112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0be6977082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b9c0500b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x61,0x73,0x6d,0x1,0x0,0x0,0x0,0x1,0x5,0xf3,0x9f,0x81,0xa2,0x1,0x60,0x0,0x0,0x7b,0x3,0x2,0x1,0x0,0x0,0x0,0x0,0x1,0x5,0x0,0x60,0x0,0x0,0x7b,0x3,0x2,0x1,0x0,0xa,0x1a,0x1,0x17,0xff,0x0,0x81,0x0,0xff,0xfd,0xfd,0x0,0xfd,0x0,0xb,0x43, Step #5: \000asm\001\000\000\000\001\005\363\237\201\242\001`\000\000{\003\002\001\000\000\000\000\001\005\000`\000\000{\003\002\001\000\012\032\001\027\377\000\201\000\377\375\375\000\375\000\013C Step #5: artifact_prefix='./'; Test unit written to ./oom-7afeceb89eaf56b098c204235e6d464719f7c231 Step #5: Base64: AGFzbQEAAAABBfOfgaIBYAAAewMCAQAAAAABBQBgAAB7AwIBAAoaARf/AIEA//39AP0AC0M= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3342 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3362008549 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560f3c9b5810, 0x560f3cb9f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560f3cb9f020,0x560f3ea370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7afeceb89eaf56b098c204235e6d464719f7c231' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4101 processed earlier; will process 6928 files now Step #5: ==120388== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560f334aa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560f39b0f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560f39af25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560f39af24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560f334b0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560f33411b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560f3340c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560f334a2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560f36471f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560f36471f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560f36471f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560f36471f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560f36471f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560f36471f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560f36471f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560f36471f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560f36471f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560f36471f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560f38706f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560f35433b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560f3543ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560f351eac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560f351eac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560f351eb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560f351ea874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560f351ea874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560f351ea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560f39af4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560f39afd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560f39ae5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560f39b10112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f07da82d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560f3340ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x3a,0xa,0x2d,0x29,0x3a,0x9,0x20,0x3e,0x20,0xa,0x20,0x3e,0x20,0xd,0x20,0xc2,0xa5,0xd,0x20,0xc2,0xa5,0xd,0x20,0xc2,0xad,0x3f,0x60,0xd,0x20,0xc2,0xa5,0x3f,0xd,0x20,0xc2,0xa5,0xd,0x20,0xc2,0xa5,0xd,0x20,0xc2,0xad,0x3f,0x60,0xd,0x20,0xc2,0xa5,0x3f,0x31, Step #5: t:\012-):\011 > \012 > \015 \302\245\015 \302\245\015 \302\255?`\015 \302\245?\015 \302\245\015 \302\245\015 \302\255?`\015 \302\245?1 Step #5: artifact_prefix='./'; Test unit written to ./oom-806e44f7cd03b7261017ce46c0a09bc9a87ba431 Step #5: Base64: dDoKLSk6CSA+IAogPiANIMKlDSDCpQ0gwq0/YA0gwqU/DSDCpQ0gwqUNIMKtP2ANIMKlPzE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3343 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3362624395 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f1cc50d810, 0x55f1cc6f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f1cc6f7020,0x55f1ce58f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/806e44f7cd03b7261017ce46c0a09bc9a87ba431' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4102 processed earlier; will process 6927 files now Step #5: ==120424== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f1c30029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f1c9667898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1c964a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1c964a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f1c3008d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f1c2f69b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f1c2f64355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f1c2ffac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f1c5fc9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f1c5fc9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f1c5fc9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f1c5fc9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f1c5fc9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f1c5fc9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f1c5fc9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f1c5fc9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f1c5fc9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f1c5fc9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f1c825ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f1c4f8bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f1c4f96be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f1c4d42c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f1c4d42c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f1c4d43738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f1c4d42874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f1c4d42874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f1c4d42874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f1c964cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f1c9655928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f1c963d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f1c9668112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efea477d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f1c2f62b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x88,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x39,0x20,0x60,0x20,0x60,0xa,0x9, Step #5: `\342\210\210-\000`\012\363\240\201\272/\012`\342\200\210-\000` i\012\012r=sef=\012=+=\012=\012=\012=\012D\012=\0129 ` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-3f988e383f2a46099289f11c4551b3f64a512e0a Step #5: Base64: YOKIiC0AYArzoIG6Lwpg4oCILQBgIGkKCnI9c2VmPQo9Kz0KPQo9Cj0KRAo9CjkgYCBgCgk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3344 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3363244970 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561e060fc810, 0x561e062e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561e062e6020,0x561e0817e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3f988e383f2a46099289f11c4551b3f64a512e0a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4103 processed earlier; will process 6926 files now Step #5: #1 pulse cov: 4055 ft: 4056 exec/s: 0 rss: 174Mb Step #5: ==120460== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561dfcbf19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561e03256898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561e032395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561e032394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561dfcbf7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561dfcb58b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561dfcb53355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561dfcbe9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561dffbb8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561dffbb8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561dffbb8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561dffbb8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561dffbb8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561dffbb8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561dffbb8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561dffbb8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561dffbb8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561dffbb8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561e01e4df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561dfeb7ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561dfeb85be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561dfe931c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561dfe931c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561dfe932738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561dfe931874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561dfe931874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561dfe931874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561e0323babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561e03244928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561e0322c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561e03257112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f72c1152082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561dfcb51b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x40,0x1,0x7f,0x77,0x1e,0x0,0x47,0x45,0x4f,0x42,0x7d,0x24,0x7f,0x5d,0x7f,0x7f,0x6f,0x7c,0x10,0x2f,0x5b,0x32,0x2e,0x2e,0x2d,0x73,0x20,0x37,0x20,0x30,0x20,0x32,0x10,0x20,0x33,0x10,0x2e,0x2f,0x4d,0x2d,0x5f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x24, Step #5: ID3\004@\001\177w\036\000GEOB}$\177]\177\177o|\020/[2..-s 7 0 2\020 3\020./M-_\177\177\177o\000\000C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-b5fd35f8a011ea20cd3637c37ddbac322bf4fa57 Step #5: Base64: SUQzBEABf3ceAEdFT0J9JH9df39vfBAvWzIuLi1zIDcgMCAyECAzEC4vTS1ff39/bwAAQyQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3345 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3363779499 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0edeb4810, 0x55a0ee09e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0ee09e020,0x55a0eff360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b5fd35f8a011ea20cd3637c37ddbac322bf4fa57' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4105 processed earlier; will process 6924 files now Step #5: ==120496== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0e49a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0eb00e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0eaff15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0eaff14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0e49afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0e4910b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0e490b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0e49a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0e7970f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0e7970f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0e7970f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0e7970f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0e7970f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0e7970f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0e7970f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0e7970f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0e7970f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0e7970f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0e9c05f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0e6932b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0e693dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0e66e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0e66e9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0e66ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0e66e9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0e66e9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0e66e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0eaff3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0eaffc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0eafe4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0eb00f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0726df0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0e4909b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x7f,0x0,0x0,0x0,0x32,0x0,0x24,0x0,0x0,0x0, Step #5: $\177]\177\000\000\0002\000\000\0002.23/\020./( 7 =\177\000\000\000\000\177\177\177o\000\00023/\020./( \177\000\000\0002\000$\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-58690483137cf13969294718e390ce0dc63e6700 Step #5: Base64: JH9dfwAAADIAAAAyLjIzLxAuLyggNyA9fwAAAAB/f39vAAAyMy8QLi8oIH8AAAAyACQAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3346 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3364274213 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556948aa3810, 0x556948c8d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556948c8d020,0x55694ab250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58690483137cf13969294718e390ce0dc63e6700' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4106 processed earlier; will process 6923 files now Step #5: ==120532== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55693f5989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556945bfd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556945be05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556945be04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55693f59ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55693f4ffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55693f4fa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55693f590c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55694255ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55694255ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55694255ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55694255ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55694255ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55694255ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55694255ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55694255ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55694255ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55694255ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5569447f4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556941521b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55694152cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5569412d8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5569412d8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5569412d9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5569412d8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5569412d8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5569412d8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556945be2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556945beb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556945bd3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556945bfe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f30282ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55693f4f8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xa,0xe1,0xac,0xa5,0xe1,0xbc,0x91,0xe1,0xae,0xb5,0xe1,0xbf,0x91,0xe1,0xac,0xb5,0xe1,0x8f,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0x27, Step #5: ws:\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\012\341\254\245\341\274\221\341\256\265\341\277\221\341\254\265\341\217\221\341\254\265\341\254\221\341\254\265' Step #5: artifact_prefix='./'; Test unit written to ./oom-6e190389ad05d63b3188f1f17d6ce0a234d22b06 Step #5: Base64: d3M64ayR4ay14ayR4ay14ayR4ay14ayRCuGspeG8keGuteG/keGsteGPkeGsteGskeGstSc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3347 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3364761337 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5589c69ff810, 0x5589c6be901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5589c6be9020,0x5589c8a810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6e190389ad05d63b3188f1f17d6ce0a234d22b06' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4107 processed earlier; will process 6922 files now Step #5: ==120568== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5589bd4f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5589c3b59898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589c3b3c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589c3b3c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5589bd4fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5589bd45bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5589bd456355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5589bd4ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5589c04bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5589c04bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5589c04bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5589c04bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5589c04bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5589c04bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5589c04bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5589c04bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5589c04bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5589c04bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589c2750f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5589bf47db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5589bf488be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5589bf234c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5589bf234c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5589bf235738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5589bf234874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5589bf234874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5589bf234874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5589c3b3eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5589c3b47928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5589c3b2f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5589c3b5a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f45cc8d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5589bd454b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x20,0x20,0x20,0x20,0x20,0x20,0xd9,0x8b,0xd9,0x98,0x20,0xd9,0x90,0xd9,0x95,0xd9,0x86,0xd9,0x98,0x20,0xd9,0x90,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e,0x27,0x3c,0x2f,0x74,0x65,0x78, Step #5: <svg><text> \331\213\331\230 \331\220\331\225\331\206\331\230 \331\220'</text></svg>'</tex Step #5: artifact_prefix='./'; Test unit written to ./oom-7948c94abfdfff2ed7c07d747905438bd79b5c0a Step #5: Base64: PHN2Zz48dGV4dD4gICAgICDZi9mYINmQ2ZXZhtmYINmQJzwvdGV4dD48L3N2Zz4nPC90ZXg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3348 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3365251865 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e2026c810, 0x562e2045601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e20456020,0x562e222ee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7948c94abfdfff2ed7c07d747905438bd79b5c0a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4108 processed earlier; will process 6921 files now Step #5: ==120604== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562e16d619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e1d3c6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e1d3a95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e1d3a94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e16d67d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e16cc8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e16cc3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e16d59c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e19d28f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e19d28f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e19d28f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e19d28f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e19d28f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e19d28f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e19d28f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e19d28f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e19d28f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e19d28f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e1bfbdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e18ceab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e18cf5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e18aa1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e18aa1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e18aa2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e18aa1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e18aa1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e18aa1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e1d3ababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e1d3b4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e1d39c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e1d3c7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff767cfa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e16cc1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x7c,0x24,0x7c,0x7c,0x24,0x7c,0x7c,0x7e,0x7c,0x7c,0x24,0x7c,0x7c,0x2f,0x7c,0x7c,0x24,0x7c,0x7c,0x25,0x7c,0x7c,0x5,0x7c,0x7c,0x24,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x29,0x7c, Step #5: (?:(?:(?:(?:(?:$||$||$||~||$||/||$||%||\005||$)|)|)|)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-fccc376147126f92cc23858982ff6092d3a97d3d Step #5: Base64: KD86KD86KD86KD86KD86JHx8JHx8JHx8fnx8JHx8L3x8JHx8JXx8BXx8JCl8KXwpfCl8KXw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3349 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3365749392 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eac3c2b810, 0x55eac3e1501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eac3e15020,0x55eac5cad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fccc376147126f92cc23858982ff6092d3a97d3d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4109 processed earlier; will process 6920 files now Step #5: ==120640== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eaba7209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eac0d85898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eac0d685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eac0d684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eaba726d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eaba687b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eaba682355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eaba718c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eabd6e7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eabd6e7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eabd6e7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eabd6e7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eabd6e7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eabd6e7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eabd6e7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eabd6e7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eabd6e7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eabd6e7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eabf97cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eabc6a9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eabc6b4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eabc460c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eabc460c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eabc461738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eabc460874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eabc460874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eabc460874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eac0d6aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eac0d73928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eac0d5b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eac0d86112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fef78c27082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eaba680b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0x5b,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x81,0x92,0x96,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x81,0x92,0x96,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x81,0x92,0x96,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93, Step #5: (?i)[\000-\362\205\205\223\000-\362\201\222\226\000-\362\205\205\223\000-\362\201\222\226\000-\362\205\205\223\000-\362\201\222\226\000-\362\205\205\223\000-\362\205\205\223 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8bbd1033441e713206d0a0b1491d08a003831d0 Step #5: Base64: KD9pKVsALfKFhZMALfKBkpYALfKFhZMALfKBkpYALfKFhZMALfKBkpYALfKFhZMALfKFhZM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3350 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3366241375 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56435c411810, 0x56435c5fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56435c5fb020,0x56435e4930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8bbd1033441e713206d0a0b1491d08a003831d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4110 processed earlier; will process 6919 files now Step #5: ==120676== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564352f069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56435956b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56435954e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56435954e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564352f0cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564352e6db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564352e68355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564352efec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564355ecdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564355ecdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564355ecdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564355ecdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564355ecdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564355ecdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564355ecdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564355ecdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564355ecdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564355ecdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564358162f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564354e8fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564354e9abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564354c46c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564354c46c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564354c47738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564354c46874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564354c46874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564354c46874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564359550abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564359559928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564359541699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56435956c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c0f4c7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564352e66b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x20,0x0,0x2d,0x20,0x20,0x0,0x0,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x3e,0x24,0x40,0x3e,0x0,0x0,0x26,0x26,0x26,0x26,0x24,0x30,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x24,0x30,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x3e,0x24,0x30, Step #5: - \000- \000\000&&&&&&&&>$@>\000\000&&&&$0&&&&&&&&&$0&&&&&&&&&&>$0 Step #5: artifact_prefix='./'; Test unit written to ./oom-41e71007395dbd4f271c8320ada1cd3794098a02 Step #5: Base64: LSAgAC0gIAAAJiYmJiYmJiY+JEA+AAAmJiYmJDAmJiYmJiYmJiYkMCYmJiYmJiYmJiY+JDA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3351 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3366730342 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55652b1af810, 0x55652b39901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55652b399020,0x55652d2310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/41e71007395dbd4f271c8320ada1cd3794098a02' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4111 processed earlier; will process 6918 files now Step #5: ==120712== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556521ca49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556528309898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5565282ec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5565282ec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556521caad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556521c0bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556521c06355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556521c9cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556524c6bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556524c6bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556524c6bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556524c6bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556524c6bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556524c6bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556524c6bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556524c6bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556524c6bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556524c6bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556526f00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556523c2db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556523c38be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5565239e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5565239e4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5565239e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5565239e4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5565239e4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5565239e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5565282eeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5565282f7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5565282df699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55652830a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa645c81082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556521c04b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1,0xa,0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1, Step #5: \013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261\012\013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-cc1cc42c7110db2926db2c1c5fa32d402318ac0e Step #5: Base64: C++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLEKC++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3352 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3367219740 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562add566810, 0x562add75001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562add750020,0x562adf5e80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cc1cc42c7110db2926db2c1c5fa32d402318ac0e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4112 processed earlier; will process 6917 files now Step #5: #1 pulse cov: 10850 ft: 10851 exec/s: 0 rss: 190Mb Step #5: #2 pulse cov: 12906 ft: 17224 exec/s: 0 rss: 193Mb Step #5: ==120748== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562ad405b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ada6c0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ada6a35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ada6a34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562ad4061d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562ad3fc2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562ad3fbd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562ad4053c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ad7022f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ad7022f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ad7022f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ad7022f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ad7022f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ad7022f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ad7022f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ad7022f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ad7022f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ad7022f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ad92b7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ad5fe4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ad5fefbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ad5d9bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ad5d9bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ad5d9c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ad5d9b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ad5d9b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ad5d9b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ada6a5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ada6ae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ada696699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ada6c1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8fcf6e7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562ad3fbbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d, Step #5: --\012\012\012--\012-\012-\012-\012-\012\012-\012,\012-\012-\012-\012\012\012\012--\012-\012-\012-\012-\012\012-\012,\012-\012-\012-\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-5386eb1f5e998984caf43bda073e6274082d4aad Step #5: Base64: LS0KCgotLQotCi0KLQotCgotCiwKLQotCi0KCgoKLS0KLQotCi0KLQoKLQosCi0KLQotCi0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3353 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3367846417 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ac1da6810, 0x561ac1f9001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ac1f90020,0x561ac3e280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5386eb1f5e998984caf43bda073e6274082d4aad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4115 processed earlier; will process 6914 files now Step #5: #1 pulse cov: 3693 ft: 3694 exec/s: 0 rss: 172Mb Step #5: ==120784== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561ab889b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561abef00898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561abeee35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561abeee34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561ab88a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561ab8802b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561ab87fd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561ab8893c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561abb862f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561abb862f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561abb862f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561abb862f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561abb862f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561abb862f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561abb862f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561abb862f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561abb862f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561abb862f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561abdaf7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561aba824b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561aba82fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561aba5dbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561aba5dbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561aba5dc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561aba5db874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561aba5db874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561aba5db874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561abeee5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561abeeee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561abeed6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561abef01112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f83f212c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561ab87fbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x31,0x6a,0x6f,0x62,0x73,0x3a,0xa,0x20,0xf0,0x94,0x95,0xbc,0x65,0xf0,0x97,0x94,0xbc,0xf0,0x90,0x91,0x8d,0x6a,0x3a,0x3a,0xa,0x20,0xf0,0x94,0x95,0xbc,0x65,0xf0,0x97,0x94,0xbc,0xf0,0x90,0x91,0x8d,0x6a,0xf0,0x97,0xbc,0x95,0xf0,0xb4,0x95,0x8d,0x6a,0x3a, Step #5: \000\000\0001jobs:\012 \360\224\225\274e\360\227\224\274\360\220\221\215j::\012 \360\224\225\274e\360\227\224\274\360\220\221\215j\360\227\274\225\360\264\225\215j: Step #5: artifact_prefix='./'; Test unit written to ./oom-6e1c7d0736aacd3008191ddde3a4ea96b964e255 Step #5: Base64: AAAAMWpvYnM6CiDwlJW8ZfCXlLzwkJGNajo6CiDwlJW8ZfCXlLzwkJGNavCXvJXwtJWNajo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3354 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3368383924 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db0890f810, 0x55db08af901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db08af9020,0x55db0a9910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6e1c7d0736aacd3008191ddde3a4ea96b964e255' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4117 processed earlier; will process 6912 files now Step #5: ==120820== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55daff4049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db05a69898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db05a4c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db05a4c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55daff40ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55daff36bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55daff366355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55daff3fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db023cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db023cbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db023cbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db023cbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db023cbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db023cbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db023cbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db023cbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db023cbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db023cbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db04660f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db0138db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db01398be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db01144c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db01144c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db01145738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db01144874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db01144874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db01144874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db05a4eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db05a57928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db05a3f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db05a6a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b043d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55daff364b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2b,0x2b,0x2d,0x2d,0xe0,0xb9,0x80,0x2d,0xf2,0xa0,0x81,0x8c,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2b,0x2b,0x2d,0x2d,0xe0,0xb9,0x80,0x2d,0xf2,0xa0,0x81,0x8c,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: x-----BEGIN ++--\340\271\200-\362\240\201\214---BEGIN ++--\340\271\200-\362\240\201\214--\012----- Step #5: artifact_prefix='./'; Test unit written to ./oom-02867cfbd39eb0244d78d983025ea5770c8d6908 Step #5: Base64: eC0tLS0tQkVHSU4gKystLeC5gC3yoIGMLS0tQkVHSU4gKystLeC5gC3yoIGMLS0KLS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3355 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3368873211 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c04727810, 0x556c0491101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c04911020,0x556c067a90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/02867cfbd39eb0244d78d983025ea5770c8d6908' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4118 processed earlier; will process 6911 files now Step #5: ==120856== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556bfb21c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c01881898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c018645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c018644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556bfb222d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556bfb183b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556bfb17e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556bfb214c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556bfe1e3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556bfe1e3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556bfe1e3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556bfe1e3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556bfe1e3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556bfe1e3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556bfe1e3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556bfe1e3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556bfe1e3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556bfe1e3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c00478f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556bfd1a5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556bfd1b0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556bfcf5cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556bfcf5cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556bfcf5d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556bfcf5c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556bfcf5c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556bfcf5c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c01866abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c0186f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c01857699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c01882112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f08160ed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556bfb17cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x58,0xc,0x44,0x45,0x46,0x41,0x55,0x4c,0x54,0x28,0x41,0x50,0x50,0x4c,0x59,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x57,0x49,0x54,0x48,0x28,0x57,0x49,0x54,0x48,0x28,0x43,0x4f,0x4c,0x55,0x4d,0x4e,0x53,0x28,0x27,0x7c,0x2d,0x31,0x27,0x27,0x7c,0x2d,0x31,0x27,0x29,0xa, Step #5: \012X\014DEFAULT(APPLY(((((((WITH(WITH(COLUMNS('|-1''|-1')\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-32f5a372bba4ceed38cada2c35f58748ea9100b2 Step #5: Base64: ClgMREVGQVVMVChBUFBMWSgoKCgoKChXSVRIKFdJVEgoQ09MVU1OUygnfC0xJyd8LTEnKQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3356 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3369363803 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca22e57810, 0x55ca2304101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca23041020,0x55ca24ed90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/32f5a372bba4ceed38cada2c35f58748ea9100b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4119 processed earlier; will process 6910 files now Step #5: ==120892== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ca1994c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca1ffb1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca1ff945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca1ff944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca19952d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca198b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca198ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca19944c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca1c913f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca1c913f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca1c913f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca1c913f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca1c913f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca1c913f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca1c913f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca1c913f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca1c913f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca1c913f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca1eba8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca1b8d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca1b8e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca1b68cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca1b68cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca1b68d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca1b68c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca1b68c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca1b68c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca1ff96abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca1ff9f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca1ff87699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca1ffb2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f61a2bbd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca198acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x76,0x21,0x39,0xa,0x0,0x70,0x69,0x7d,0x7d,0x7d,0x7d,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x72,0x65,0x61,0x6d,0xd7,0xaf,0x2d,0x0,0x73,0x7e,0x74,0x39,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0xd7,0xa3,0x1,0xd7,0xa3,0x2d,0x0, Step #5: #v!9\012\000pi}}}}dddddddream\327\257-\000s~t9>>>>>>>>>>>>>>>\327\243\001\327\243-\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-29c048afc8854f118a2a90febda65e347befbb77 Step #5: Base64: I3YhOQoAcGl9fX19ZGRkZGRkZHJlYW3Xry0Ac350OT4+Pj4+Pj4+Pj4+Pj4+PtejAdejLQA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3357 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3369854749 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b662392810, 0x55b66257c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b66257c020,0x55b6644140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/29c048afc8854f118a2a90febda65e347befbb77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4120 processed earlier; will process 6909 files now Step #5: ==120928== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b658e879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b65f4ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b65f4cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b65f4cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b658e8dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b658deeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b658de9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b658e7fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b65be4ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b65be4ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b65be4ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b65be4ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b65be4ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b65be4ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b65be4ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b65be4ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b65be4ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b65be4ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b65e0e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b65ae10b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b65ae1bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b65abc7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b65abc7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b65abc8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b65abc7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b65abc7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b65abc7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b65f4d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b65f4da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b65f4c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b65f4ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f85f9d2d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b658de7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xe1,0x9e,0x90,0xe1,0x9f,0x84,0x9,0xa,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0xe1,0x9e,0x90,0xe1,0x9f,0x84,0x9,0xa,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text><text>\341\236\220\341\237\204\011\012</text>\341\236\220\341\237\204\011\012</text></svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-1a7f464af2bda06969fd74b8a843c01a5aae311f Step #5: Base64: PHN2Zz48dGV4dD48dGV4dD7hnpDhn4QJCjwvdGV4dD7hnpDhn4QJCjwvdGV4dD48L3N2Zz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3358 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3370353295 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1e7896810, 0x55a1e7a8001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1e7a80020,0x55a1e99180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1a7f464af2bda06969fd74b8a843c01a5aae311f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4121 processed earlier; will process 6908 files now Step #5: #1 pulse cov: 3639 ft: 3640 exec/s: 0 rss: 175Mb Step #5: ==120964== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1de38b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1e49f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1e49d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1e49d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1de391d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1de2f2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1de2ed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1de383c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1e1352f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1e1352f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1e1352f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1e1352f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1e1352f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1e1352f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1e1352f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1e1352f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1e1352f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1e1352f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1e35e7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1e0314b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1e031fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1e00cbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1e00cbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1e00cc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1e00cb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1e00cb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1e00cb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a1e49d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a1e49de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1e49c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1e49f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb73d40082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1de2ebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0xa,0x3c,0x3c,0xa,0x2f,0x52,0x6f,0x6f,0x74,0x20,0x31,0x20,0x30,0x52,0xa,0x1,0x1,0xa,0x31,0x20,0x32,0x35,0x37,0x20,0x6f,0x62,0x6a,0x33,0x32,0x37,0x36,0x39,0x78,0x27,0xef,0xac,0xab,0xf3,0xa0,0x81,0xbb,0x2d,0x39,0x38,0x25,0xa, Step #5: trailer\012<<\012/Root 1 0R\012\001\001\0121 257 obj32769x'\357\254\253\363\240\201\273-98%\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-1fdef66f78725ed9eff81beef28a5265eb634324 Step #5: Base64: dHJhaWxlcgo8PAovUm9vdCAxIDBSCgEBCjEgMjU3IG9iajMyNzY5eCfvrKvzoIG7LTk4JQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3359 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3370886081 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55682e803810, 0x55682e9ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55682e9ed020,0x5568308850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1fdef66f78725ed9eff81beef28a5265eb634324' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4123 processed earlier; will process 6906 files now Step #5: #1 pulse cov: 3866 ft: 3867 exec/s: 0 rss: 172Mb Step #5: ==121000== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5568252f89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55682b95d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55682b9405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55682b9404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5568252fed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55682525fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55682525a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5568252f0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5568282bff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5568282bff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5568282bff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5568282bff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5568282bff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5568282bff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5568282bff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5568282bff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5568282bff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5568282bff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55682a554f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556827281b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55682728cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556827038c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556827038c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556827039738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556827038874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556827038874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556827038874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55682b942abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55682b94b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55682b933699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55682b95e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f352e05e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556825258b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x24,0x24,0xd,0x33,0x2d,0x0,0x0,0x1,0x0,0x0,0x2,0x0,0x6e,0x24,0x24,0xd,0x2,0x44,0x0,0x33,0x2d,0x0,0x0,0x1,0x0,0x0,0x2,0x0,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0xc2,0xb6, Step #5: x$$\0153-\000\000\001\000\000\002\000n$$\015\002D\0003-\000\000\001\000\000\002\000nnnnnnnnnnnnnnnnnnnnnn\302\266 Step #5: artifact_prefix='./'; Test unit written to ./oom-f16a96c89cba5f81a9ff5dcffcf8342408e26942 Step #5: Base64: eCQkDTMtAAABAAACAG4kJA0CRAAzLQAAAQAAAgBubm5ubm5ubm5ubm5ubm5ubm5ubm5uwrY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3360 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3371427146 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed330d6810, 0x55ed332c001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed332c0020,0x55ed351580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f16a96c89cba5f81a9ff5dcffcf8342408e26942' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4125 processed earlier; will process 6904 files now Step #5: ==121036== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed29bcb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed30230898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed302135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed302134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed29bd1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed29b32b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed29b2d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed29bc3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed2cb92f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed2cb92f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed2cb92f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed2cb92f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed2cb92f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed2cb92f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed2cb92f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed2cb92f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed2cb92f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed2cb92f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed2ee27f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed2bb54b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed2bb5fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed2b90bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed2b90bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed2b90c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed2b90b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed2b90b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed2b90b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed30215abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed3021e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed30206699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed30231112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4cec496082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed29b2bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x72,0x0,0x43,0x4b,0x2,0x48,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: ID3\002r\000CK\002H\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-11a6cd47d28085c6e690d0f44cd5957b1fb128ee Step #5: Base64: SUQzAnIAQ0sCSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3361 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3371922980 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564425408810, 0x5644255f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5644255f2020,0x56442748a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/11a6cd47d28085c6e690d0f44cd5957b1fb128ee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4126 processed earlier; will process 6903 files now Step #5: #1 pulse cov: 3719 ft: 3720 exec/s: 0 rss: 172Mb Step #5: ==121072== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56441befd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564422562898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5644225455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5644225454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56441bf03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56441be64b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56441be5f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56441bef5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56441eec4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56441eec4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56441eec4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56441eec4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56441eec4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56441eec4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56441eec4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56441eec4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56441eec4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56441eec4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564421159f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56441de86b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56441de91be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56441dc3dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56441dc3dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56441dc3e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56441dc3d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56441dc3d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56441dc3d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564422547abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564422550928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564422538699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564422563112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbc826ef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56441be5db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xa,0xc2,0xa5,0xd,0xc2,0xa1,0xa,0xc3,0xa6,0xd,0xc8,0xa4,0xa,0xc7,0xa5,0xa,0xc7,0xa4,0xa,0xc8,0xa3,0xa,0xc8,0xa3,0xa,0xc8,0xa3,0xa,0xc7,0xa5,0xa,0xc3,0xa6,0xd,0xc8,0xa4,0xa,0xc7,0xa5,0xa,0xc6,0xa4,0xa,0xc8,0xa3,0xa,0xc7,0xa5, Step #5: \357\273\277\357\273\277\012\302\245\015\302\241\012\303\246\015\310\244\012\307\245\012\307\244\012\310\243\012\310\243\012\310\243\012\307\245\012\303\246\015\310\244\012\307\245\012\306\244\012\310\243\012\307\245 Step #5: artifact_prefix='./'; Test unit written to ./oom-526dc4603a972531f38cecea8f7c69017a8018a9 Step #5: Base64: 77u/77u/CsKlDcKhCsOmDcikCselCsekCsijCsijCsijCselCsOmDcikCselCsakCsijCsel Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3362 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3372460024 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557efb829810, 0x557efba1301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557efba13020,0x557efd8ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/526dc4603a972531f38cecea8f7c69017a8018a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4128 processed earlier; will process 6901 files now Step #5: ==121108== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557ef231e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557ef8983898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557ef89665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557ef89664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557ef2324d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557ef2285b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557ef2280355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557ef2316c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557ef52e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557ef52e5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557ef52e5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557ef52e5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557ef52e5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557ef52e5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557ef52e5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557ef52e5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557ef52e5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557ef52e5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557ef757af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557ef42a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557ef42b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557ef405ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557ef405ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557ef405f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557ef405e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557ef405e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557ef405e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557ef8968abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557ef8971928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557ef8959699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557ef8984112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fed287bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557ef227eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x4e,0x50,0x55,0x54,0xa,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x30,0xa,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x31,0xa,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x33,0x20,0x23,0x34,0x20,0x23,0x30,0xa,0x23,0x30,0xa,0x23,0x30,0x20, Step #5: INPUT\012#0\012#0 #0\012#0 #0\012#0\012#0\012#0 #1\012#0 #0\012#3 #4 #0\012#0\012#0 Step #5: artifact_prefix='./'; Test unit written to ./oom-6247cd6c69f5fec22e8aa8fe7eaad04451afb72a Step #5: Base64: SU5QVVQKIzAKIzAgIzAKIzAgIzAKIzAKIzAKIzAgIzEKIzAgIzAKIzMgIzQgIzAKIzAKIzAg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3363 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3372958872 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d32ce3f810, 0x55d32d02901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d32d029020,0x55d32eec10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6247cd6c69f5fec22e8aa8fe7eaad04451afb72a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4129 processed earlier; will process 6900 files now Step #5: #1 pulse cov: 3520 ft: 3521 exec/s: 0 rss: 175Mb Step #5: ==121144== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d3239349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d329f99898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d329f7c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d329f7c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d32393ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d32389bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d323896355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d32392cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d3268fbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d3268fbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d3268fbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d3268fbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d3268fbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d3268fbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d3268fbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d3268fbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d3268fbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d3268fbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d328b90f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d3258bdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d3258c8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d325674c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d325674c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d325675738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d325674874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d325674874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d325674874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d329f7eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d329f87928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d329f6f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d329f9a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc0175a3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d323894b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x9, Step #5: `\342\200\210-\000`\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\005\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ba8056d50094c56a1279161230be1224382225c Step #5: Base64: YOKAiC0AYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAUAAAAAAAAAAAAAAAAAAAAAAAoJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3364 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3373615043 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5613c8251810, 0x5613c843b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5613c843b020,0x5613ca2d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ba8056d50094c56a1279161230be1224382225c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4131 processed earlier; will process 6898 files now Step #5: #1 pulse cov: 3886 ft: 3887 exec/s: 0 rss: 172Mb Step #5: ==121180== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5613bed469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5613c53ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613c538e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613c538e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5613bed4cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5613becadb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5613beca8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5613bed3ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5613c1d0df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5613c1d0df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5613c1d0df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5613c1d0df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5613c1d0df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5613c1d0df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5613c1d0df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5613c1d0df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5613c1d0df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5613c1d0df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5613c3fa2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5613c0ccfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5613c0cdabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5613c0a86c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5613c0a86c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5613c0a87738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5613c0a86874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5613c0a86874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5613c0a86874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5613c5390abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5613c5399928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5613c5381699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5613c53ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff3aa69d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5613beca6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x0,0x0,0x25,0x1,0x0,0x0,0x0,0x2,0x2f,0x5b,0x43,0x61,0x5d,0xa,0x5b,0x43,0x61,0x5d,0xa,0x73,0x3d,0x27,0xe2,0x8a,0x88,0x27,0xa,0x5b,0x43,0x61,0x5d,0xa,0x73,0x3d,0x27,0xe2,0x8a,0x80,0x27,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff, Step #5: \012\000\000%\001\000\000\000\002/[Ca]\012[Ca]\012s='\342\212\210'\012[Ca]\012s='\342\212\200'\377\377\377\377\377\377\377\377\377\377\377\377\377\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-ee5b1604c62ba2d90bed2e6a86417dfff8ac495d Step #5: Base64: CgAAJQEAAAACL1tDYV0KW0NhXQpzPSfiiognCltDYV0Kcz0n4oqAJ/////////////////// Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3365 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3374159059 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55567e2fc810, 0x55567e4e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55567e4e6020,0x55568037e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee5b1604c62ba2d90bed2e6a86417dfff8ac495d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4133 processed earlier; will process 6896 files now Step #5: ==121216== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555674df19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55567b456898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55567b4395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55567b4394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555674df7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555674d58b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555674d53355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555674de9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555677db8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555677db8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555677db8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555677db8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555677db8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555677db8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555677db8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555677db8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555677db8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555677db8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55567a04df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555676d7ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555676d85be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555676b31c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555676b31c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555676b32738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555676b31874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555676b31874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555676b31874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55567b43babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55567b444928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55567b42c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55567b457112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f305de2b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555674d51b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x20,0x0,0x3,0x2d,0x20,0x20,0x0,0x0,0x26,0x26,0x26,0x27,0x26,0x26,0x26,0x26,0x3e,0x24,0x40,0x3e,0x0,0x0,0x26,0x26,0x20,0x26,0x24,0x30,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x24,0x30,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x3e,0x24,0x30, Step #5: - \000\003- \000\000&&&'&&&&>$@>\000\000&& &$0&&&&&&&&&$0&&&&&&&&&&>$0 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8ce7c5e5d004d1e0bf2b81848016423031acbd6 Step #5: Base64: LSAgAAMtICAAACYmJicmJiYmPiRAPgAAJiYgJiQwJiYmJiYmJiYmJDAmJiYmJiYmJiYmPiQw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3366 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3374658674 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b9094e810, 0x558b90b3801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b90b38020,0x558b929d00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8ce7c5e5d004d1e0bf2b81848016423031acbd6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4134 processed earlier; will process 6895 files now Step #5: ==121252== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558b874439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b8daa8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b8da8b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b8da8b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b87449d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b873aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b873a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b8743bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b8a40af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b8a40af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b8a40af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b8a40af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b8a40af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b8a40af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b8a40af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b8a40af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b8a40af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b8a40af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b8c69ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b893ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b893d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b89183c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b89183c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b89184738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b89183874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b89183874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b89183874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b8da8dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b8da96928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b8da7e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b8daa9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f580e6be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b873a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x32,0x2e,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x32,0x35,0x2f,0x10,0x2e,0x2f,0x73,0x20,0x37,0x20,0x30,0x20,0x32,0x10,0x20,0x32,0x10,0x2e,0x2f,0x2d,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x3f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x24, Step #5: $\177]2.2147483625/\020./s 7 0 2\020 2\020./-\177\177\177\177\177\177\177\177\177\177\177\177\177?\177\177o\000\000C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-e79696a0892524f17db10d67d4970b41748e98ed Step #5: Base64: JH9dMi4yMTQ3NDgzNjI1LxAuL3MgNyAwIDIQIDIQLi8tf39/f39/f39/f39/fz9/f28AAEMk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3367 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3375163448 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565406ebc810, 0x5654070a601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5654070a6020,0x565408f3e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e79696a0892524f17db10d67d4970b41748e98ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4135 processed earlier; will process 6894 files now Step #5: ==121288== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5653fd9b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565404016898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565403ff95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565403ff94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5653fd9b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5653fd918b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5653fd913355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5653fd9a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565400978f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565400978f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565400978f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565400978f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565400978f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565400978f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565400978f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565400978f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565400978f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565400978f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565402c0df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5653ff93ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5653ff945be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5653ff6f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5653ff6f1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5653ff6f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5653ff6f1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5653ff6f1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5653ff6f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565403ffbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565404004928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565403fec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565404017112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5c61f92082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5653fd911b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x12,0x9,0x71,0x2d,0xa,0xa,0xa,0x2d,0x24,0x0,0xa,0x41,0x2d,0xa,0x2f,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0x31,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x0,0x0,0x0,0x2f,0x0,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x8,0xa,0x63,0x2d,0x3a,0x24,0x5b,0x0,0x15, Step #5: \001\022\011q-\012\012\012-$\000\012A-\012/\000/\000\000\000/\000\0171\0171\021\0171\021-\000\000\000/\000\0171\021\0171\021-:\010\012c-:$[\000\025 Step #5: artifact_prefix='./'; Test unit written to ./oom-f43e229b5e2e25fad7b85510d015a14aae11139b Step #5: Base64: ARIJcS0KCgotJAAKQS0KLwAvAAAALwAPMQ8xEQ8xES0AAAAvAA8xEQ8xES06CApjLTokWwAV Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3368 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3375667792 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fda5571810, 0x55fda575b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fda575b020,0x55fda75f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f43e229b5e2e25fad7b85510d015a14aae11139b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4136 processed earlier; will process 6893 files now Step #5: ==121324== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fd9c0669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fda26cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fda26ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fda26ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fd9c06cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fd9bfcdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fd9bfc8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fd9c05ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fd9f02df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fd9f02df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fd9f02df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fd9f02df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fd9f02df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fd9f02df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fd9f02df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fd9f02df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fd9f02df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fd9f02df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fda12c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fd9dfefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fd9dffabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fd9dda6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fd9dda6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fd9dda7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fd9dda6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fd9dda6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fd9dda6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fda26b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fda26b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fda26a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fda26cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f56825e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fd9bfc6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xa,0x2f,0xa,0x2f,0xa,0x60,0x60,0x20,0x20,0x20,0x60,0xa,0x9,0xb0,0xb0,0xb0,0xb0,0xb0,0xb0,0xb0,0xb0,0xb0,0xb0,0xb0,0xb0,0xb0, Step #5: `\342\200\210-\000`\012\363\240\201\272/\012`\342\200\210-\000`\342\200\210-\000`\012\012/\012/\012`` `\012\011\260\260\260\260\260\260\260\260\260\260\260\260\260 Step #5: artifact_prefix='./'; Test unit written to ./oom-fbdeaf50a584434e125ddc45e3cf87df97e4ed27 Step #5: Base64: YOKAiC0AYArzoIG6Lwpg4oCILQBg4oCILQBgCgovCi8KYGAgICBgCgmwsLCwsLCwsLCwsLCw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3369 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3376289231 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f564ff7810, 0x55f5651e101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f5651e1020,0x55f5670790e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fbdeaf50a584434e125ddc45e3cf87df97e4ed27' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4137 processed earlier; will process 6892 files now Step #5: ==121360== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f55baec9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f562151898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f5621345dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f5621344fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f55baf2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f55ba53b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f55ba4e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f55bae4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f55eab3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f55eab3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f55eab3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f55eab3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f55eab3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f55eab3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f55eab3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f55eab3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f55eab3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f55eab3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f560d48f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f55da75b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f55da80be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f55d82cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f55d82cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f55d82d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f55d82c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f55d82c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f55d82c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f562136abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f56213f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f562127699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f562152112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f593a7fb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f55ba4cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x68,0x74,0x74,0x70,0x3a,0x27,0xcd,0x81,0x27,0xcd,0x81,0x27,0xcd,0x81,0x27,0xcd,0x81,0x27,0xcd,0x81,0x27,0xcd,0x81,0x27,0xcd,0x81,0x27,0xcd,0x81,0x27,0xcd,0x81,0x27,0xcd,0x81,0x27,0xcd,0x81,0x27,0xcd,0x81,0x27,0xcd,0x81,0x27,0xcd,0x81,0x27,0xcd,0x81,0x28,0xcd,0x81, Step #5: \016http:'\315\201'\315\201'\315\201'\315\201'\315\201'\315\201'\315\201'\315\201'\315\201'\315\201'\315\201'\315\201'\315\201'\315\201'\315\201(\315\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-42273c89565aa30585da2d10665097fe50ec88f3 Step #5: Base64: Dmh0dHA6J82BJ82BJ82BJ82BJ82BJ82BJ82BJ82BJ82BJ82BJ82BJ82BJ82BJ82BJ82BKM2B Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3370 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3376783862 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55de655c6810, 0x55de657b001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55de657b0020,0x55de676480e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/42273c89565aa30585da2d10665097fe50ec88f3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4138 processed earlier; will process 6891 files now Step #5: ==121396== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55de5c0bb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55de62720898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55de627035dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55de627034fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55de5c0c1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55de5c022b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55de5c01d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55de5c0b3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55de5f082f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55de5f082f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55de5f082f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55de5f082f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55de5f082f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55de5f082f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55de5f082f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55de5f082f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55de5f082f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55de5f082f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55de61317f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55de5e044b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55de5e04fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55de5ddfbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55de5ddfbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55de5ddfc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55de5ddfb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55de5ddfb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55de5ddfb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55de62705abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55de6270e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55de626f6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55de62721112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa0e45ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55de5c01bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x32,0x35,0x31,0x20,0x54,0x54,0x54,0x54,0x48,0xcd,0x8f,0x41,0x43,0xdb,0xbf,0x54,0x54,0x48,0xcd,0x8f,0x49,0x44,0x32,0x35,0x31,0x20,0x54,0x54,0x54,0x54,0x48,0xcd,0x8f,0x41,0x43,0xdb,0xbf,0x54,0x54,0x48,0xcd,0x8f,0x41,0x41,0x43,0xdb,0xbf,0x5,0x2,0xdb,0xbf,0xdf, Step #5: ID251 TTTTH\315\217AC\333\277TTH\315\217ID251 TTTTH\315\217AC\333\277TTH\315\217AAC\333\277\005\002\333\277\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-d17a2af46e9882daf75eb5083e0f99f29385e3d2 Step #5: Base64: SUQyNTEgVFRUVEjNj0FD279UVEjNj0lEMjUxIFRUVFRIzY9BQ9u/VFRIzY9BQUPbvwUC27/f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3371 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3377283562 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560543fc9810, 0x5605441b301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5605441b3020,0x56054604b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d17a2af46e9882daf75eb5083e0f99f29385e3d2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4139 processed earlier; will process 6890 files now Step #5: ==121432== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56053aabe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560541123898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605411065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605411064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56053aac4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56053aa25b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56053aa20355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56053aab6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56053da85f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56053da85f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56053da85f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56053da85f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56053da85f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56053da85f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56053da85f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56053da85f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56053da85f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56053da85f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56053fd1af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56053ca47b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56053ca52be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56053c7fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56053c7fec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56053c7ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56053c7fe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56053c7fe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56053c7fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560541108abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560541111928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605410f9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560541124112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc80e798082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56053aa1eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x0,0x30,0x2e,0x3d,0x60,0x37,0x50,0x49,0x43,0x0,0x0,0x7,0x21,0x70,0x6e,0x47,0x3d,0x70,0x31,0x43,0x48,0x41,0x0,0x0,0x13,0x0,0x30,0x2e,0x3d,0x60,0x38,0x50,0x49,0x43,0x0,0x0,0x7,0x21,0x70,0x6e,0x47,0x0,0x26,0xeb,0x43,0x48,0x41,0x0,0x0,0x13, Step #5: ID3\002\0000.=`7PIC\000\000\007!pnG=p1CHA\000\000\023\0000.=`8PIC\000\000\007!pnG\000&\353CHA\000\000\023 Step #5: artifact_prefix='./'; Test unit written to ./oom-00151a36d428682fd138a0ba6b3be186c1651aa7 Step #5: Base64: SUQzAgAwLj1gN1BJQwAAByFwbkc9cDFDSEEAABMAMC49YDhQSUMAAAchcG5HACbrQ0hBAAAT Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3372 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3377898823 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ed6309810, 0x561ed64f301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ed64f3020,0x561ed838b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/00151a36d428682fd138a0ba6b3be186c1651aa7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4140 processed earlier; will process 6889 files now Step #5: ==121468== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561eccdfe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561ed3463898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561ed34465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561ed34464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561ecce04d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561eccd65b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561eccd60355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561eccdf6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561ecfdc5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561ecfdc5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561ecfdc5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561ecfdc5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561ecfdc5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561ecfdc5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561ecfdc5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561ecfdc5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561ecfdc5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561ecfdc5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561ed205af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561eced87b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561eced92be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561eceb3ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561eceb3ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561eceb3f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561eceb3e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561eceb3e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561eceb3e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561ed3448abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561ed3451928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561ed3439699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561ed3464112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8fdf99e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561eccd5eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0xe,0x6e,0x3d,0xf,0x6e,0x5e,0x28,0x6e,0xd9,0x9b,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x6e,0x3d,0xf,0x6e,0x5e,0x28,0x6e,0xd9,0x9b,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x2e, Step #5: n\016n=\017n^(n\331\233=.^(d=.^(d=.^(d=n=\017n^(n\331\233=.^(d=.^(d=.^(d=.. Step #5: artifact_prefix='./'; Test unit written to ./oom-162882d24a6ce4693c8dbae61ad766b888d68248 Step #5: Base64: bg5uPQ9uXihu2Zs9Ll4oZD0uXihkPS5eKGQ9bj0Pbl4obtmbPS5eKGQ9Ll4oZD0uXihkPS4u Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3373 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3378386265 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a01825810, 0x561a01a0f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a01a0f020,0x561a038a70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/162882d24a6ce4693c8dbae61ad766b888d68248' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4141 processed earlier; will process 6888 files now Step #5: ==121504== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5619f831a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5619fe97f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5619fe9625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5619fe9624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5619f8320d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5619f8281b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5619f827c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5619f8312c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5619fb2e1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5619fb2e1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5619fb2e1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5619fb2e1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5619fb2e1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5619fb2e1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5619fb2e1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5619fb2e1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5619fb2e1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5619fb2e1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5619fd576f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5619fa2a3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5619fa2aebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5619fa05ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5619fa05ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5619fa05b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5619fa05a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5619fa05a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5619fa05a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5619fe964abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5619fe96d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5619fe955699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5619fe980112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e6f2b3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5619f827ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xcc,0x9c,0x20,0xcc,0x96,0x31,0x0,0x0,0x0,0x0,0x0,0xcc,0x9c,0x20,0xcc,0x96,0x31,0x0,0x0,0x0,0x0,0x2c,0x0,0xcc,0x9c,0x0,0xcc,0x96,0x31,0x0,0x0,0x0,0x0,0x2c,0x0,0xcc,0x9c,0x0,0xcc,0x96,0x31,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: \000\000\000\000\000\000\000\314\234 \314\2261\000\000\000\000\000\314\234 \314\2261\000\000\000\000,\000\314\234\000\314\2261\000\000\000\000,\000\314\234\000\314\2261\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5aec5bc0d9cd5730a7c9e1d8ab47820077290741 Step #5: Base64: AAAAAAAAAMycIMyWMQAAAAAAzJwgzJYxAAAAACwAzJwAzJYxAAAAACwAzJwAzJYxAAAAAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3374 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3378872686 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e97c01810, 0x555e97deb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e97deb020,0x555e99c830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5aec5bc0d9cd5730a7c9e1d8ab47820077290741' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4142 processed earlier; will process 6887 files now Step #5: ==121540== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555e8e6f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e94d5b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e94d3e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e94d3e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e8e6fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e8e65db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e8e658355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e8e6eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e916bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e916bdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e916bdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e916bdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e916bdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e916bdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e916bdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e916bdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e916bdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e916bdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e93952f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e9067fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e9068abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e90436c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e90436c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e90437738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e90436874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e90436874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e90436874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e94d40abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e94d49928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e94d31699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e94d5c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4c7245d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e8e656b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x45,0x58,0x50,0x20,0x20,0x31,0xa,0x43,0x6e,0x54,0x20,0x20,0x32,0xa,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x36,0x30,0x33,0x32,0x31,0x34,0x37,0x34,0x31,0x39,0x33,0x32,0x36,0x31,0x36,0x36,0x33,0x31,0x34,0x2e,0x20, Step #5: EXP 1\012CnT 2\01200000000000000000006032147419326166314. Step #5: artifact_prefix='./'; Test unit written to ./oom-e6ed42d394fb43a03b656aaf483052507d3d4258 Step #5: Base64: RVhQICAxCkNuVCAgMgowMDAwMDAwMDAwMDAwMDAwMDAwNjAzMjE0NzQxOTMyNjE2NjMxNC4g Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3375 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3379369718 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5634b74cc810, 0x5634b76b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5634b76b6020,0x5634b954e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e6ed42d394fb43a03b656aaf483052507d3d4258' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4143 processed earlier; will process 6886 files now Step #5: ==121576== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5634adfc19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5634b4626898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634b46095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634b46094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5634adfc7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5634adf28b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5634adf23355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5634adfb9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5634b0f88f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5634b0f88f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5634b0f88f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5634b0f88f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5634b0f88f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5634b0f88f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5634b0f88f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5634b0f88f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5634b0f88f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5634b0f88f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5634b321df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5634aff4ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5634aff55be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5634afd01c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5634afd01c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5634afd02738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5634afd01874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5634afd01874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5634afd01874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5634b460babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5634b4614928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5634b45fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5634b4627112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ba818b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5634adf21b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x7c,0x24,0x7c,0x7c,0x24,0x7c,0x7c,0x24,0x7c,0x7c,0x24,0x7c,0x7c,0x24,0x7c,0x7c,0x24,0x7c,0x7c,0x24,0x7c,0x29,0x7c,0x51,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x29,0x7c, Step #5: (?:(?:(?:(?:(?:(?:$||$||$||$||$||$||$||$|)|Q)|)|)|)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-75ea2ce1e133b5fedd5a371fdbb6800ccae02e31 Step #5: Base64: KD86KD86KD86KD86KD86KD86JHx8JHx8JHx8JHx8JHx8JHx8JHx8JHwpfFEpfCl8KXwpfCl8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3376 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3379863858 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d68756810, 0x562d6894001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d68940020,0x562d6a7d80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/75ea2ce1e133b5fedd5a371fdbb6800ccae02e31' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4144 processed earlier; will process 6885 files now Step #5: #1 pulse cov: 3692 ft: 3693 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 12243 ft: 13085 exec/s: 0 rss: 196Mb Step #5: ==121612== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562d5f24b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d658b0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d658935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d658934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d5f251d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d5f1b2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d5f1ad355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d5f243c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d62212f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d62212f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d62212f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d62212f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d62212f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d62212f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d62212f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d62212f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d62212f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d62212f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d644a7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d611d4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d611dfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d60f8bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d60f8bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d60f8c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d60f8b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d60f8b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d60f8b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d65895abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d6589e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d65886699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d658b1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f61619ab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d5f1abb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x29,0x0,0xef,0xbd,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0x0,0xef,0xbc,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0x0,0xef,0xbd,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0x0,0xef,0xbd,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0xed, Step #5: )\000\357\275\207\357\271\274\357\274\210\357\271\210\000\357\274\207\357\271\274\357\274\210\357\271\210\000\357\275\207\357\271\274\357\274\210\357\271\210\000\357\275\207\357\271\274\357\274\210\357\271\210\355 Step #5: artifact_prefix='./'; Test unit written to ./oom-54793592cff09371ea57c9abdf2bae043bdcf067 Step #5: Base64: KQDvvYfvubzvvIjvuYgA77yH77m877yI77mIAO+9h++5vO+8iO+5iADvvYfvubzvvIjvuYjt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3377 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3380466002 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b4997f6810, 0x55b4999e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b4999e0020,0x55b49b8780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/54793592cff09371ea57c9abdf2bae043bdcf067' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4147 processed earlier; will process 6882 files now Step #5: ==121648== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b4902eb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b496950898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b4969335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b4969334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b4902f1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b490252b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b49024d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b4902e3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b4932b2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b4932b2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b4932b2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b4932b2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b4932b2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b4932b2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b4932b2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b4932b2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b4932b2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b4932b2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b495547f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b492274b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b49227fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b49202bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b49202bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b49202c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b49202b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b49202b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b49202b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b496935abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b49693e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b496926699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b496951112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9e4b9c6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b49024bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x7d,0x7d,0x3c,0x74,0x65,0x78,0x74,0x3e,0x5e,0xe0,0xad,0x8b,0x3b,0xd,0x35,0xe1,0x9e,0xb7,0x31,0xe2,0x84,0x8c,0xe1,0x82,0x8d,0x49,0x43,0x43,0x50,0x5b,0x5b,0x29,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3e,0x3e,0x2c,0x47,0x47,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg>}}<text>^\340\255\213;\0155\341\236\2671\342\204\214\341\202\215ICCP[[)</text>>>,GG</svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-0b275a8aba2f69e3beaeb10dbaab3ef74975f496 Step #5: Base64: PHN2Zz59fTx0ZXh0Pl7grYs7DTXhnrcx4oSM4YKNSUNDUFtbKTwvdGV4dD4+PixHRzwvc3ZnPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3378 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3380963684 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b3cfd9810, 0x557b3d1c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b3d1c3020,0x557b3f05b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b275a8aba2f69e3beaeb10dbaab3ef74975f496' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4148 processed earlier; will process 6881 files now Step #5: ==121684== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557b33ace9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b3a133898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b3a1165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b3a1164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b33ad4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b33a35b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b33a30355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b33ac6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b36a95f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b36a95f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b36a95f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b36a95f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b36a95f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b36a95f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b36a95f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b36a95f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b36a95f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b36a95f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b38d2af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b35a57b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b35a62be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b3580ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b3580ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b3580f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b3580e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b3580e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b3580e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b3a118abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b3a121928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b3a109699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b3a134112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d1d42d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b33a2eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x0,0x0,0x0,0x9c,0x30, Step #5: \000\000\000\000hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh\000\000\000\2340 Step #5: artifact_prefix='./'; Test unit written to ./oom-e2e63f084ae7a2578a2bcc2abc0fae66465dca41 Step #5: Base64: AAAAAGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGgAAACcMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3379 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3381457196 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559710b90810, 0x559710d7a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559710d7a020,0x559712c120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e2e63f084ae7a2578a2bcc2abc0fae66465dca41' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4149 processed earlier; will process 6880 files now Step #5: ==121720== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5597076859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55970dcea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55970dccd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55970dccd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55970768bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5597075ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5597075e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55970767dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55970a64cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55970a64cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55970a64cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55970a64cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55970a64cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55970a64cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55970a64cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55970a64cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55970a64cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55970a64cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55970c8e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55970960eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559709619be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5597093c5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5597093c5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5597093c6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5597093c5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5597093c5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5597093c5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55970dccfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55970dcd8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55970dcc0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55970dceb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6a0fc31082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5597075e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x1,0x0,0x0,0x0,0x10,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x32,0x35,0x34,0x2e,0x43,0x2e,0x0,0x11,0x31,0x0,0x98,0x0,0x0,0x0,0x11,0x66,0x69,0x6c,0x65,0x3a,0x69,0x7c,0x20,0x6e,0x74,0x6c,0x76,0x61,0x6f,0x20,0x57,0x23,0x0,0x28,0x0,0x0,0x0,0x4,0x0,0x0,0x0,0x5, Step #5: \000\001\000\000\000\020http://254.C.\000\0211\000\230\000\000\000\021file:i| ntlvao W#\000(\000\000\000\004\000\000\000\005 Step #5: artifact_prefix='./'; Test unit written to ./oom-873e94ab319839843ad3787783381f80d4e69aae Step #5: Base64: AAEAAAAQaHR0cDovLzI1NC5DLgARMQCYAAAAEWZpbGU6aXwgbnRsdmFvIFcjACgAAAAEAAAABQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3380 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3381950632 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cfaad98810, 0x55cfaaf8201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cfaaf82020,0x55cface1a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/873e94ab319839843ad3787783381f80d4e69aae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4150 processed earlier; will process 6879 files now Step #5: ==121756== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cfa188d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cfa7ef2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cfa7ed55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cfa7ed54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cfa1893d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cfa17f4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cfa17ef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cfa1885c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cfa4854f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cfa4854f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cfa4854f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cfa4854f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cfa4854f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cfa4854f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cfa4854f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cfa4854f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cfa4854f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cfa4854f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cfa6ae9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cfa3816b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cfa3821be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cfa35cdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cfa35cdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cfa35ce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cfa35cd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cfa35cd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cfa35cd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cfa7ed7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cfa7ee0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cfa7ec8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cfa7ef3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ffa837082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cfa17edb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x42,0x1,0x0,0x0,0x0,0x0,0x0,0x2d,0x1f,0x44,0x2d,0x0,0x2d,0x33,0x3,0x73,0x60,0x78,0x21,0x74,0x1,0x33,0x3,0x3c,0x6d,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x3,0x3c,0x6d,0x60,0xdb,0x9e,0x3,0x32,0xdb,0xa5,0x32, Step #5: IB\001\000\000\000\000\000-\037D-\000-3\003s`x!t\0013\003<m++++++++++++++++++\003<m`\333\236\0032\333\2452 Step #5: artifact_prefix='./'; Test unit written to ./oom-d6c546a321613d46d260d3dd312ce326da9b86d6 Step #5: Base64: SUIBAAAAAAAtH0QtAC0zA3NgeCF0ATMDPG0rKysrKysrKysrKysrKysrKysDPG1g254DMtulMg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3381 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3382568294 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a2d9b36810, 0x55a2d9d2001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a2d9d20020,0x55a2dbbb80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d6c546a321613d46d260d3dd312ce326da9b86d6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4151 processed earlier; will process 6878 files now Step #5: ==121792== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a2d062b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a2d6c90898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2d6c735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2d6c734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a2d0631d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a2d0592b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a2d058d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a2d0623c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a2d35f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a2d35f2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a2d35f2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a2d35f2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a2d35f2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a2d35f2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a2d35f2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a2d35f2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a2d35f2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a2d35f2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a2d5887f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a2d25b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a2d25bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a2d236bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a2d236bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a2d236c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a2d236b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a2d236b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a2d236b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a2d6c75abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a2d6c7e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2d6c66699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a2d6c91112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd88bab9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a2d058bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x40,0x1,0x7f,0x77,0x1e,0x0,0x47,0x45,0x4f,0x42,0x7d,0x24,0x60,0x60,0x60,0x7f,0x5d,0x7f,0x7f,0x6f,0x7c,0x10,0x2f,0x5b,0x32,0x2e,0x2e,0x2f,0x73,0x20,0x37,0x20,0x30,0x20,0x32,0x10,0x20,0x32,0x10,0x2e,0x2f,0x2d,0x5f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x24, Step #5: ID3\004@\001\177w\036\000GEOB}$```\177]\177\177o|\020/[2../s 7 0 2\020 2\020./-_\177\177\177o\000\000C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-44e79739ca3842ab595aea03cbc9f9de2976bbe3 Step #5: Base64: SUQzBEABf3ceAEdFT0J9JGBgYH9df39vfBAvWzIuLi9zIDcgMCAyECAyEC4vLV9/f39vAABDJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3382 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3383070766 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55748fcb3810, 0x55748fe9d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55748fe9d020,0x557491d350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/44e79739ca3842ab595aea03cbc9f9de2976bbe3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4152 processed earlier; will process 6877 files now Step #5: ==121828== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5574867a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55748ce0d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55748cdf05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55748cdf04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5574867aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55748670fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55748670a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5574867a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55748976ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55748976ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55748976ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55748976ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55748976ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55748976ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55748976ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55748976ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55748976ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55748976ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55748ba04f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557488731b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55748873cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5574884e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5574884e8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5574884e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5574884e8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5574884e8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5574884e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55748cdf2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55748cdfb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55748cde3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55748ce0e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8dab6ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557486708b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4e,0xd,0x60,0x4e,0xd,0xa,0x60,0xd,0x60,0xd,0xa,0x4e,0xd,0xa,0x60,0xd,0x60,0xf3,0xa0,0x81,0x8c,0xd,0xa,0x4e,0xd,0xf3,0xa0,0x80,0xab,0x60,0xd,0x60,0xd,0xa,0x4e,0xd,0xa,0x32,0xd,0x60,0xd,0xd,0xa,0x4e,0xd,0xa,0x0,0x3d,0xa,0x81,0xb3,0xf3,0x3d,0xbc,0xa, Step #5: N\015`N\015\012`\015`\015\012N\015\012`\015`\363\240\201\214\015\012N\015\363\240\200\253`\015`\015\012N\015\0122\015`\015\015\012N\015\012\000=\012\201\263\363=\274\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-4e97966dccc0ddcdac4e22a0f795ab1843d6076e Step #5: Base64: Tg1gTg0KYA1gDQpODQpgDWDzoIGMDQpODfOggKtgDWANCk4NCjINYA0NCk4NCgA9CoGz8z28Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3383 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3383690714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d78b0e810, 0x562d78cf801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d78cf8020,0x562d7ab900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e97966dccc0ddcdac4e22a0f795ab1843d6076e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4153 processed earlier; will process 6876 files now Step #5: ==121864== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562d6f6039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d75c68898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d75c4b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d75c4b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d6f609d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d6f56ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d6f565355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d6f5fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d725caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d725caf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d725caf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d725caf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d725caf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d725caf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d725caf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d725caf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d725caf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d725caf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d7485ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d7158cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d71597be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d71343c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d71343c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d71344738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d71343874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d71343874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d71343874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d75c4dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d75c56928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d75c3e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d75c69112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f54dea35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d6f563b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x45,0x78,0x65,0x63,0x5d,0xa,0x57,0x6f,0x72,0x6b,0x69,0x6e,0x67,0x44,0x69,0x72,0x65,0x63,0x74,0x6f,0x72,0x79,0x3d,0x2f,0x2e,0x22,0x2f,0x46,0x2f,0x2e,0x5f,0x2e,0x5f,0x2f,0x2e,0x46,0x2f,0x2e,0x41,0x2f,0x2e,0x45,0x2f,0x2e,0x3d,0x2f,0x2e,0x22,0x2f,0x2e,0x3f,0x2f,0x2e,0x2d, Step #5: [Exec]\012WorkingDirectory=/.\"/F/._._/.F/.A/.E/.=/.\"/.?/.- Step #5: artifact_prefix='./'; Test unit written to ./oom-9d94a066244e9f59a407b1896e2059ac3a85f920 Step #5: Base64: W0V4ZWNdCldvcmtpbmdEaXJlY3Rvcnk9Ly4iL0YvLl8uXy8uRi8uQS8uRS8uPS8uIi8uPy8uLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3384 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3384186508 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5628d773c810, 0x5628d792601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5628d7926020,0x5628d97be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9d94a066244e9f59a407b1896e2059ac3a85f920' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4154 processed earlier; will process 6875 files now Step #5: ==121900== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5628ce2319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5628d4896898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5628d48795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5628d48794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5628ce237d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5628ce198b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5628ce193355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5628ce229c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5628d11f8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5628d11f8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5628d11f8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5628d11f8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5628d11f8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5628d11f8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5628d11f8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5628d11f8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5628d11f8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5628d11f8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5628d348df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5628d01bab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5628d01c5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5628cff71c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5628cff71c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5628cff72738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5628cff71874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5628cff71874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5628cff71874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5628d487babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5628d4884928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5628d486c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5628d4897112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f447f9ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5628ce191b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x27,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x3f,0x42, Step #5: \177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177'\177\177\177\177\177\177\177\177\177\177\177\177\177\177?B Step #5: artifact_prefix='./'; Test unit written to ./oom-826bd470e17d0cb38033574be2d2b0ed2440fc7f Step #5: Base64: f39/f39/f39/f39/f39/f39/f39/f39/f39/f39/f39/f39/f38nf39/f39/f39/f39/f38/Qg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3385 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3384678445 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f1a9b9c810, 0x55f1a9d8601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f1a9d86020,0x55f1abc1e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/826bd470e17d0cb38033574be2d2b0ed2440fc7f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4155 processed earlier; will process 6874 files now Step #5: #1 pulse cov: 4045 ft: 4046 exec/s: 0 rss: 172Mb Step #5: ==121936== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f1a06919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f1a6cf6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1a6cd95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1a6cd94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f1a0697d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f1a05f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f1a05f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f1a0689c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f1a3658f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f1a3658f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f1a3658f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f1a3658f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f1a3658f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f1a3658f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f1a3658f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f1a3658f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f1a3658f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f1a3658f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f1a58edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f1a261ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f1a2625be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f1a23d1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f1a23d1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f1a23d2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f1a23d1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f1a23d1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f1a23d1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f1a6cdbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f1a6ce4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f1a6ccc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f1a6cf7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feb928ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f1a05f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x8,0x0,0x0,0x1,0x8,0x0,0x0,0x1,0x8,0x0,0x0,0x1,0x8, Step #5: \002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\010\000\000\001\010\000\000\001\010\000\000\001\010 Step #5: artifact_prefix='./'; Test unit written to ./oom-c81e7e7df7f3714e17c54708ccff796698e51ea5 Step #5: Base64: AgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABCAAAAQgAAAEIAAABCA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3386 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3385214415 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d9339a1810, 0x55d933b8b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d933b8b020,0x55d935a230e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c81e7e7df7f3714e17c54708ccff796698e51ea5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4157 processed earlier; will process 6872 files now Step #5: #1 pulse cov: 4048 ft: 4049 exec/s: 0 rss: 172Mb Step #5: ==121972== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d92a4969c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d930afb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d930ade5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d930ade4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d92a49cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d92a3fdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d92a3f8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d92a48ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d92d45df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d92d45df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d92d45df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d92d45df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d92d45df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d92d45df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d92d45df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d92d45df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d92d45df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d92d45df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d92f6f2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d92c41fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d92c42abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d92c1d6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d92c1d6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d92c1d7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d92c1d6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d92c1d6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d92c1d6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d930ae0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d930ae9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d930ad1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d930afc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5346896082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d92a3f6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0x7c,0x2e,0x5e,0x2f,0x2e,0x7c,0x7c,0x2e,0x2e,0x2e,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x2e,0x40,0x2e,0x2f,0x2e,0x7c,0x2f,0x2e,0x7c,0x7c,0x2e,0x2e,0x2e,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x2e,0x40,0x2e,0x2f,0x2e,0x7c,0x7c,0x2e,0x2d,0x2e,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x2e,0x2e,0x0, Step #5: .|.^/.||...|.||.|.@./.|/.||...|.||.|.@./.||.-.|.||.|..\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6bab4762b9b33451817b7878a7ad721a161225a3 Step #5: Base64: LnwuXi8ufHwuLi58Lnx8LnwuQC4vLnwvLnx8Li4ufC58fC58LkAuLy58fC4tLnwufHwufC4uAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3387 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3385747614 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7e3290810, 0x55f7e347a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7e347a020,0x55f7e53120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bab4762b9b33451817b7878a7ad721a161225a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4159 processed earlier; will process 6870 files now Step #5: ==122008== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f7d9d859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7e03ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7e03cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7e03cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f7d9d8bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f7d9cecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f7d9ce7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f7d9d7dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7dcd4cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7dcd4cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7dcd4cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7dcd4cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7dcd4cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7dcd4cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7dcd4cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7dcd4cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7dcd4cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7dcd4cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7defe1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f7dbd0eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f7dbd19be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f7dbac5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f7dbac5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f7dbac6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f7dbac5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f7dbac5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f7dbac5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7e03cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7e03d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7e03c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7e03eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f42605d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f7d9ce5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x37,0x0,0x0,0x0,0x31,0x53,0x50,0x53,0x1,0x80,0xa,0x4,0xdd,0x2e,0x10,0x0,0x8,0x1b,0xbf,0x3b,0x2b,0x30,0x0,0xd5,0x1f,0x0,0x0,0x0,0xff,0xff,0xff,0x1e,0xae,0x1f,0x10,0x0,0x0,0x3,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x53,0x50,0x53,0xd5,0x5, Step #5: 7\000\000\0001SPS\001\200\012\004\335.\020\000\010\033\277;+0\000\325\037\000\000\000\377\377\377\036\256\037\020\000\000\003\000\000\000\000\000\000\000\001\000\000\000\000SPS\325\005 Step #5: artifact_prefix='./'; Test unit written to ./oom-3f8f3820057672f44b01c39b225abcfe2ba9e54e Step #5: Base64: NwAAADFTUFMBgAoE3S4QAAgbvzsrMADVHwAAAP///x6uHxAAAAMAAAAAAAAAAQAAAABTUFPVBQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3388 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3386234433 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555c57895810, 0x555c57a7f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555c57a7f020,0x555c599170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3f8f3820057672f44b01c39b225abcfe2ba9e54e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4160 processed earlier; will process 6869 files now Step #5: ==122044== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555c4e38a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555c549ef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555c549d25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555c549d24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555c4e390d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555c4e2f1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555c4e2ec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555c4e382c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555c51351f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555c51351f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555c51351f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555c51351f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555c51351f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555c51351f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555c51351f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555c51351f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555c51351f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555c51351f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555c535e6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555c50313b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555c5031ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555c500cac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555c500cac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555c500cb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555c500ca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555c500ca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555c500ca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555c549d4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555c549dd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555c549c5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555c549f0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5d0664e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555c4e2eab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd6,0xae,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x0,0x31,0x0,0x5b,0x27,0x5d,0x5b,0x28,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x0,0xf3,0xa0,0xa0,0xa0,0xf0,0x81,0x80,0x0,0x9d,0xe2,0xe2,0x85,0xf3,0x0,0xae,0x22,0xbf,0x81,0x88,0xbb,0x22,0x81,0xef,0x22,0x22,0x0,0x80,0xab,0x22, Step #5: \326\256\000\000\000\000\000\000\000-\0001\000['][(\000\000\000\000\000\000 \000\363\240\240\240\360\201\200\000\235\342\342\205\363\000\256\"\277\201\210\273\"\201\357\"\"\000\200\253\" Step #5: artifact_prefix='./'; Test unit written to ./oom-512d92c4c0b4e94fdc88caad40a715c9db8f48e0 Step #5: Base64: 1q4AAAAAAAAALQAxAFsnXVsoAAAAAAAAIADzoKCg8IGAAJ3i4oXzAK4iv4GIuyKB7yIiAICrIg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3389 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3386716090 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c656f34810, 0x55c65711e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c65711e020,0x55c658fb60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/512d92c4c0b4e94fdc88caad40a715c9db8f48e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4161 processed earlier; will process 6868 files now Step #5: #1 pulse cov: 3569 ft: 3570 exec/s: 0 rss: 172Mb Step #5: ==122080== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c64da299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c65408e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c6540715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c6540714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c64da2fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c64d990b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c64d98b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c64da21c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c6509f0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c6509f0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c6509f0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c6509f0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c6509f0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c6509f0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c6509f0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c6509f0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c6509f0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c6509f0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c652c85f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c64f9b2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c64f9bdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c64f769c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c64f769c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c64f76a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c64f769874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c64f769874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c64f769874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c654073abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c65407c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c654064699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c65408f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c848e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c64d989b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0xa,0x64,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x45,0x31,0xa,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x3f,0x41,0x73,0xa,0x0,0xa,0x64,0xa,0x64,0xa,0x64,0x0,0x0,0x2d,0x2d, Step #5: x-----BEGIN \012d\000\000-------\012E1\012=\314\273A---Asce\012-?As\012\000\012d\012d\012d\000\000-- Step #5: artifact_prefix='./'; Test unit written to ./oom-ce3f3b5c21137ab236e80ccbd7a9cf35bd52c593 Step #5: Base64: eC0tLS0tQkVHSU4gCmQAAC0tLS0tLS0KRTEKPcy7QS0tLUFzY2UKLT9BcwoACmQKZApkAAAtLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3390 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3387246415 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bac3dbf810, 0x55bac3fa901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bac3fa9020,0x55bac5e410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce3f3b5c21137ab236e80ccbd7a9cf35bd52c593' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4163 processed earlier; will process 6866 files now Step #5: ==122116== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55baba8b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bac0f19898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bac0efc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bac0efc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55baba8bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55baba81bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55baba816355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55baba8acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55babd87bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55babd87bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55babd87bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55babd87bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55babd87bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55babd87bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55babd87bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55babd87bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55babd87bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55babd87bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55babfb10f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55babc83db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55babc848be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55babc5f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55babc5f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55babc5f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55babc5f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55babc5f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55babc5f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bac0efeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bac0f07928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bac0eef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bac0f1a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe991e12082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55baba814b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0, Step #5: \000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-db9f05a9a678cce868eedf4596910fa7105dced0 Step #5: Base64: AEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3391 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3387742689 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652ed627810, 0x5652ed81101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652ed811020,0x5652ef6a90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/db9f05a9a678cce868eedf4596910fa7105dced0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4164 processed earlier; will process 6865 files now Step #5: ==122152== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5652e411c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652ea781898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652ea7645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652ea7644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5652e4122d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5652e4083b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5652e407e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5652e4114c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5652e70e3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5652e70e3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5652e70e3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5652e70e3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5652e70e3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5652e70e3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5652e70e3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5652e70e3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5652e70e3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5652e70e3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652e9378f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5652e60a5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5652e60b0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652e5e5cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652e5e5cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652e5e5d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652e5e5c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652e5e5c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652e5e5c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652ea766abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652ea76f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652ea757699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652ea782112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda2e4f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5652e407cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0xdc,0xbf,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb2,0xcc,0xb2,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb2,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb3,0xcc,0xb4,0xcc,0xb4,0xcc,0xb2,0xcc,0xb4,0xcc,0xb4,0xcc,0xb2,0xcc,0xb2,0xcc,0xb4,0xcc,0xb2,0xcc,0xb4, Step #5: i\334\277\314\264\314\264\314\264\314\264\314\264\314\262\314\262\314\264\314\264\314\264\314\262\314\264\314\264\314\264\314\264\314\263\314\264\314\264\314\262\314\264\314\264\314\262\314\262\314\264\314\262\314\264 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7aabab812c8a466992fe5a3d81f8e79a1b875c2 Step #5: Base64: ady/zLTMtMy0zLTMtMyyzLLMtMy0zLTMssy0zLTMtMy0zLPMtMy0zLLMtMy0zLLMssy0zLLMtA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3392 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3388236049 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56494e7ed810, 0x56494e9d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56494e9d7020,0x56495086f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7aabab812c8a466992fe5a3d81f8e79a1b875c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4165 processed earlier; will process 6864 files now Step #5: #1 pulse cov: 3680 ft: 3681 exec/s: 0 rss: 174Mb Step #5: ==122188== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5649452e29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56494b947898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56494b92a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56494b92a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5649452e8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564945249b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564945244355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5649452dac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5649482a9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5649482a9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5649482a9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5649482a9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5649482a9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5649482a9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5649482a9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5649482a9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5649482a9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5649482a9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56494a53ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56494726bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564947276be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564947022c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564947022c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564947023738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564947022874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564947022874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564947022874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56494b92cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56494b935928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56494b91d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56494b948112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd47893b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564945242b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x1,0x0,0x0,0x0,0x10,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x31,0x32,0x37,0x2e,0x30,0x2e,0x0,0x11,0x31,0x0,0x98,0x0,0x0,0x0,0x11,0x2a,0x20,0x4f,0x4b,0xd,0xa,0x53,0x65,0x72,0x76,0x65,0x72,0x3a,0x20,0x74,0x65,0x73,0x0,0x28,0x0,0x0,0x0,0x4,0x0,0x0,0x0,0x5, Step #5: \000\001\000\000\000\020http://127.0.\000\0211\000\230\000\000\000\021* OK\015\012Server: tes\000(\000\000\000\004\000\000\000\005 Step #5: artifact_prefix='./'; Test unit written to ./oom-faf779ab55e387a0591879aefe153de291ebe498 Step #5: Base64: AAEAAAAQaHR0cDovLzEyNy4wLgARMQCYAAAAESogT0sNClNlcnZlcjogdGVzACgAAAAEAAAABQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3393 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3388773875 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5591855c2810, 0x5591857ac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5591857ac020,0x5591876440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/faf779ab55e387a0591879aefe153de291ebe498' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4167 processed earlier; will process 6862 files now Step #5: ==122224== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55917c0b79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55918271c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5591826ff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5591826ff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55917c0bdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55917c01eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55917c019355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55917c0afc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55917f07ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55917f07ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55917f07ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55917f07ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55917f07ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55917f07ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55917f07ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55917f07ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55917f07ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55917f07ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559181313f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55917e040b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55917e04bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55917ddf7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55917ddf7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55917ddf8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55917ddf7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55917ddf7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55917ddf7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559182701abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55918270a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5591826f2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55918271d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdd2646f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55917c017b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xa,0x45,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xd,0x25,0x20,0x78,0x78,0x20,0x53,0x59,0x53,0x54,0x45,0x4d,0xa,0x27,0x75,0x72,0x6e,0x3a,0x70,0x75,0x67,0x6c,0x69,0x63,0x69,0x64,0x3a,0x27,0x3e,0x25,0x78,0x78,0x3b,0x78,0x84, Step #5: <!DOCTYPE\012E[<!ENTITY\015% xx SYSTEM\012'urn:puglicid:'>%xx;x\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-784ffdd7f81057c38e474db95482c81b5f4ab7e2 Step #5: Base64: PCFET0NUWVBFCkVbPCFFTlRJVFkNJSB4eCBTWVNURU0KJ3VybjpwdWdsaWNpZDonPiV4eDt4hA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3394 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3389266557 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b1de403810, 0x55b1de5ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b1de5ed020,0x55b1e04850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/784ffdd7f81057c38e474db95482c81b5f4ab7e2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4168 processed earlier; will process 6861 files now Step #5: ==122260== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b1d4ef89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b1db55d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1db5405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1db5404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b1d4efed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b1d4e5fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b1d4e5a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b1d4ef0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b1d7ebff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b1d7ebff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b1d7ebff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b1d7ebff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b1d7ebff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b1d7ebff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b1d7ebff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b1d7ebff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b1d7ebff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b1d7ebff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b1da154f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b1d6e81b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b1d6e8cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b1d6c38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b1d6c38c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b1d6c39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b1d6c38874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b1d6c38874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b1d6c38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b1db542abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b1db54b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b1db533699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b1db55e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa6c820082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b1d4e58b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd6,0xae,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x9,0xf3,0xa0,0x81,0x88,0x0,0x0,0x0,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0xe0,0xb9,0x81,0x22,0x22,0x22,0xa,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x0,0x4f,0x0,0x96,0xc8, Step #5: \326\256\000\000\000\000\000\000\000\000\000\000\000\000\000\000\011\363\240\201\210\000\000\000\"\"\"\"\"\"\"\"\"\"\"\340\271\201\"\"\"\012\"\"\"\"\"\"\"\"\000O\000\226\310 Step #5: artifact_prefix='./'; Test unit written to ./oom-43cc1e8a459b94f6177737d7258f60d7a09c6aae Step #5: Base64: 1q4AAAAAAAAAAAAAAAAAAAnzoIGIAAAAIiIiIiIiIiIiIiLguYEiIiIKIiIiIiIiIiIATwCWyA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3395 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3389754425 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f625d83810, 0x55f625f6d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f625f6d020,0x55f627e050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/43cc1e8a459b94f6177737d7258f60d7a09c6aae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4169 processed earlier; will process 6860 files now Step #5: #1 pulse cov: 11138 ft: 11139 exec/s: 0 rss: 192Mb Step #5: ==122296== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f61c8789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f622edd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f622ec05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f622ec04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f61c87ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f61c7dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f61c7da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f61c870c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f61f83ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f61f83ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f61f83ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f61f83ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f61f83ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f61f83ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f61f83ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f61f83ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f61f83ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f61f83ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f621ad4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f61e801b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f61e80cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f61e5b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f61e5b8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f61e5b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f61e5b8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f61e5b8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f61e5b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f622ec2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f622ecb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f622eb3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f622ede112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa0b7796082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f61c7d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x6f,0x63,0x69,0x56,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x31,0x2e,0x30,0x2e,0x30,0x22,0x2c,0x22,0x6c,0x69,0x6e,0x75,0x78,0x22,0x3a,0x7b,0x22,0x6d,0x61,0x73,0x6b,0x65,0x64,0x50,0x61,0x74,0x68,0x73,0x22,0x3a,0x5b,0x22,0x2f,0x73,0x31,0x69,0x22,0x5d,0x7d,0x7d, Step #5: {\"ociVersion\":\"1.0.0\",\"linux\":{\"maskedPaths\":[\"/s1i\"]}} Step #5: artifact_prefix='./'; Test unit written to ./oom-807300e55e151b85625f63f36e58b0ce2dc5c878 Step #5: Base64: eyJvY2lWZXJzaW9uIjoiMS4wLjAiLCJsaW51eCI6eyJtYXNrZWRQYXRocyI6WyIvczFpIl19fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3396 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3390317086 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c7fe120810, 0x55c7fe30a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c7fe30a020,0x55c8001a20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/807300e55e151b85625f63f36e58b0ce2dc5c878' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4171 processed earlier; will process 6858 files now Step #5: ==122332== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c7f4c159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7fb27a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7fb25d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7fb25d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c7f4c1bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c7f4b7cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c7f4b77355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7f4c0dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7f7bdcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7f7bdcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7f7bdcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7f7bdcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7f7bdcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7f7bdcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7f7bdcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7f7bdcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7f7bdcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7f7bdcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7f9e71f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7f6b9eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7f6ba9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7f6955c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7f6955c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7f6956738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7f6955874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7f6955874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7f6955874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7fb25fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7fb268928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c7fb250699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7fb27b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f476c6c5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c7f4b75b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x42,0x1,0x0,0x0,0x0,0x0,0x0,0x2d,0x1f,0x44,0x2d,0x0,0x2d,0x33,0x3,0x6d,0x60,0x78,0x21,0x74,0x1,0x33,0x3,0x3c,0x6d,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x23,0x2b,0x2b,0x2b,0x2b,0x26,0x2b,0x60,0xdb,0x1,0x33,0x3,0x3c,0x6d,0x60,0xdb,0x9e,0x3,0x32,0xdb,0xa5,0x32, Step #5: IB\001\000\000\000\000\000-\037D-\000-3\003m`x!t\0013\003<m+++++++#++++&+`\333\0013\003<m`\333\236\0032\333\2452 Step #5: artifact_prefix='./'; Test unit written to ./oom-ca337430b90d88924431fd5ac2b67a35a197e5b1 Step #5: Base64: SUIBAAAAAAAtH0QtAC0zA21geCF0ATMDPG0rKysrKysrIysrKysmK2DbATMDPG1g254DMtulMg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3397 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3390934178 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5563a3b98810, 0x5563a3d8201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5563a3d82020,0x5563a5c1a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca337430b90d88924431fd5ac2b67a35a197e5b1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4172 processed earlier; will process 6857 files now Step #5: ==122368== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55639a68d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5563a0cf2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5563a0cd55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5563a0cd54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55639a693d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55639a5f4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55639a5ef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55639a685c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55639d654f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55639d654f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55639d654f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55639d654f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55639d654f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55639d654f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55639d654f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55639d654f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55639d654f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55639d654f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55639f8e9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55639c616b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55639c621be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55639c3cdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55639c3cdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55639c3ce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55639c3cd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55639c3cd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55639c3cd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5563a0cd7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5563a0ce0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5563a0cc8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5563a0cf3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f830c1cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55639a5edb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd7,0xa3,0x1,0xd7,0xa3,0x1,0x9,0x9,0x34,0x9,0x1b,0xd7,0xa3,0x1,0xd7,0xa3,0x1,0x9,0x34,0x9,0x1b,0x1b,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x22,0x9,0x1b,0xd7,0xa3,0x1,0xd7,0xa3,0x1,0x9,0x34,0x9,0x1b,0x1b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x92,0x1b,0x74,0x1b,0x1b,0x74, Step #5: \327\243\001\327\243\001\011\0114\011\033\327\243\001\327\243\001\0114\011\033\033\000\000\000\000\000\000 \"\011\033\327\243\001\327\243\001\0114\011\033\033\000\000\000\000\000\000\000\222\033t\033\033t Step #5: artifact_prefix='./'; Test unit written to ./oom-56ab2ae6d1b3d0d40bff060251dee745ad7b80d1 Step #5: Base64: 16MB16MBCQk0CRvXowHXowEJNAkbGwAAAAAAACAiCRvXowHXowEJNAkbGwAAAAAAAACSG3QbG3Q= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3398 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3391425905 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e01d5e4810, 0x55e01d7ce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e01d7ce020,0x55e01f6660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56ab2ae6d1b3d0d40bff060251dee745ad7b80d1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4173 processed earlier; will process 6856 files now Step #5: ==122404== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e0140d99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e01a73e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e01a7215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e01a7214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e0140dfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e014040b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e01403b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e0140d1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e0170a0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e0170a0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e0170a0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e0170a0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e0170a0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e0170a0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e0170a0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e0170a0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e0170a0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e0170a0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e019335f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e016062b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e01606dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e015e19c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e015e19c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e015e1a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e015e19874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e015e19874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e015e19874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e01a723abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e01a72c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e01a714699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e01a73f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5adfc9d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e014039b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf, Step #5: //\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ea7ef1149a04e42518af089ae0608df7d252760 Step #5: Base64: Ly/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3399 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3391901427 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562264a92810, 0x562264c7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562264c7c020,0x562266b140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ea7ef1149a04e42518af089ae0608df7d252760' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4174 processed earlier; will process 6855 files now Step #5: ==122440== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56225b5879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562261bec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562261bcf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562261bcf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56225b58dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56225b4eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56225b4e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56225b57fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56225e54ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56225e54ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56225e54ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56225e54ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56225e54ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56225e54ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56225e54ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56225e54ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56225e54ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56225e54ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5622607e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56225d510b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56225d51bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56225d2c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56225d2c7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56225d2c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56225d2c7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56225d2c7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56225d2c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562261bd1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562261bda928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562261bc2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562261bed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa20077b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56225b4e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0xa,0x27,0xc2,0x85,0x7c,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x60,0xc2,0x85,0x7b,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x60,0xc2,0x85,0x7b,0xc2,0x85,0x5c,0xc2,0x85,0x7a,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0xa,0x2d,0x2d,0x2d, Step #5: ---\012'\302\205|\302\205\\\302\205\\\302\205\\\302\205\\\302\205`\302\205{\302\205\\\302\205\\\302\205`\302\205{\302\205\\\302\205z\302\205\\\302\205\\\302\205\012--- Step #5: artifact_prefix='./'; Test unit written to ./oom-47a1459911549436a1eaa8d8a6297f4cc5011b53 Step #5: Base64: LS0tCifChXzChVzChVzChVzChVzChWDChXvChVzChVzChWDChXvChVzChXrChVzChVzChQotLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3400 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3392516315 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5644fe0a8810, 0x5644fe29201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5644fe292020,0x56450012a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/47a1459911549436a1eaa8d8a6297f4cc5011b53' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4175 processed earlier; will process 6854 files now Step #5: ==122476== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5644f4b9d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5644fb202898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5644fb1e55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5644fb1e54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5644f4ba3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5644f4b04b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5644f4aff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5644f4b95c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5644f7b64f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5644f7b64f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5644f7b64f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5644f7b64f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5644f7b64f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5644f7b64f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5644f7b64f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5644f7b64f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5644f7b64f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5644f7b64f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5644f9df9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5644f6b26b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5644f6b31be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5644f68ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5644f68ddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5644f68de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5644f68dd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5644f68dd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5644f68dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5644fb1e7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5644fb1f0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5644fb1d8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5644fb203112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7fd5425082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5644f4afdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0x0,0x0,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0x2f,0x76,0x30,0x0,0xf3,0xa0,0x81,0xb8,0x0,0x28,0xd,0x0,0x72,0x64,0x64,0x64,0xb5,0xf3,0xa0,0x81,0x87,0x64,0x64, Step #5: \341\240\216= \177\177\000\000(\342\200\254\000\341\240\216= \177\177\342\200\215\000\000(\342\200\256\000r+/v0\000\363\240\201\270\000(\015\000rddd\265\363\240\201\207dd Step #5: artifact_prefix='./'; Test unit written to ./oom-3a1f8e51c7de04bce749e536421b24751631a9ce Step #5: Base64: 4aCOPSB/fwAAKOKArADhoI49IH9/4oCNAAAo4oCuAHIrL3YwAPOggbgAKA0AcmRkZLXzoIGHZGQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3401 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3393008737 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55758273d810, 0x55758292701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557582927020,0x5575847bf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a1f8e51c7de04bce749e536421b24751631a9ce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4176 processed earlier; will process 6853 files now Step #5: #1 pulse cov: 3852 ft: 3853 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 3987 ft: 4336 exec/s: 0 rss: 175Mb Step #5: ==122512== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5575792329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55757f897898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55757f87a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55757f87a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557579238d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557579199b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557579194355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55757922ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55757c1f9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55757c1f9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55757c1f9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55757c1f9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55757c1f9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55757c1f9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55757c1f9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55757c1f9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55757c1f9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55757c1f9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55757e48ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55757b1bbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55757b1c6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55757af72c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55757af72c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55757af73738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55757af72874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55757af72874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55757af72874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55757f87cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55757f885928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55757f86d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55757f898112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f518813d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557579192b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4f,0x57,0x4e,0x45,0x52,0x3d,0x22,0xef,0xbe,0xbb,0xef,0xbc,0xbf,0xef,0xbe,0xad,0xef,0xbc,0xbf,0xef,0xbc,0xbf,0xef,0xbc,0xbf,0xef,0xbe,0xbb,0xef,0xbc,0xbf,0xef,0xbe,0xad,0xef,0xbc,0xbf,0xef,0xbe,0xad,0xef,0xbc,0xbf,0xef,0xbe,0xbb,0xef,0xbc,0xbf,0xef,0xbf,0xbb,0xef,0xb8,0xbf,0x22, Step #5: OWNER=\"\357\276\273\357\274\277\357\276\255\357\274\277\357\274\277\357\274\277\357\276\273\357\274\277\357\276\255\357\274\277\357\276\255\357\274\277\357\276\273\357\274\277\357\277\273\357\270\277\" Step #5: artifact_prefix='./'; Test unit written to ./oom-665b4d3684832dbf01384f78d95fadf015ea3a45 Step #5: Base64: T1dORVI9Iu++u++8v+++re+8v++8v++8v+++u++8v+++re+8v+++re+8v+++u++8v++/u++4vyI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3402 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3393578307 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640ea960810, 0x5640eab4a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640eab4a020,0x5640ec9e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/665b4d3684832dbf01384f78d95fadf015ea3a45' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4179 processed earlier; will process 6850 files now Step #5: ==122548== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5640e14559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5640e7aba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640e7a9d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640e7a9d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5640e145bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5640e13bcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5640e13b7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5640e144dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5640e441cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5640e441cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5640e441cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5640e441cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5640e441cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5640e441cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5640e441cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5640e441cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5640e441cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5640e441cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5640e66b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5640e33deb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5640e33e9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5640e3195c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5640e3195c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5640e3196738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5640e3195874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5640e3195874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5640e3195874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5640e7a9fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5640e7aa8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5640e7a90699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5640e7abb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe90ccb5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5640e13b5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x76,0x21,0x39,0xa,0x0,0xe2,0x81,0x9f,0x3e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xd7,0xa3,0x1,0xd7,0xa3,0x2d,0x0, Step #5: #v!9\012\000\342\201\237>\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\327\243\001\327\243-\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b123caf3d53a027af69c43583cefd72e45f2915d Step #5: Base64: I3YhOQoA4oGfPgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAANejAdejLQA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3403 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3394070646 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563075073810, 0x56307525d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56307525d020,0x5630770f50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b123caf3d53a027af69c43583cefd72e45f2915d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4180 processed earlier; will process 6849 files now Step #5: ==122584== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56306bb689c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5630721cd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5630721b05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5630721b04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56306bb6ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56306bacfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56306baca355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56306bb60c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56306eb2ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56306eb2ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56306eb2ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56306eb2ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56306eb2ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56306eb2ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56306eb2ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56306eb2ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56306eb2ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56306eb2ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563070dc4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56306daf1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56306dafcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56306d8a8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56306d8a8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56306d8a9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56306d8a8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56306d8a8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56306d8a8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5630721b2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5630721bb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5630721a3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5630721ce112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3f092dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56306bac8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0x0,0x0,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0xe2,0x80,0x89,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0x2f,0x76,0x30,0x0,0xf3,0xa0,0x81,0xb8,0x0,0x28,0xd,0x0,0x72,0x64,0x64,0x64,0xb5,0xf3,0xa0,0x81,0x87,0x64,0x64, Step #5: \341\240\216= \177\177\000\000(\342\200\254\000\341\240\216= \177\177\342\200\211\000\000(\342\200\256\000r+/v0\000\363\240\201\270\000(\015\000rddd\265\363\240\201\207dd Step #5: artifact_prefix='./'; Test unit written to ./oom-6ee59ffc14155b05d725d231e22023018a5dc3d2 Step #5: Base64: 4aCOPSB/fwAAKOKArADhoI49IH9/4oCJAAAo4oCuAHIrL3YwAPOggbgAKA0AcmRkZLXzoIGHZGQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3404 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3394560932 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a765fd810, 0x555a767e701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a767e7020,0x555a7867f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ee59ffc14155b05d725d231e22023018a5dc3d2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4181 processed earlier; will process 6848 files now Step #5: ==122620== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555a6d0f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a73757898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a7373a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a7373a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a6d0f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a6d059b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a6d054355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a6d0eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a700b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a700b9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a700b9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a700b9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a700b9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a700b9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a700b9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a700b9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a700b9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a700b9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a7234ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a6f07bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a6f086be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a6ee32c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a6ee32c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a6ee33738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a6ee32874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a6ee32874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a6ee32874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a7373cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a73745928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a7372d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a73758112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd6211eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a6d052b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x36,0xa,0x34,0xa,0x32,0x3a,0x30,0xa,0x2e,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50,0x50, Step #5: \0126\0124\0122:0\012.PPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPP Step #5: artifact_prefix='./'; Test unit written to ./oom-c1fafbf603d7fe7b89d591c9db936160f190ef4e Step #5: Base64: CjYKNAoyOjAKLlBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3405 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3395054087 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d8852d9810, 0x55d8854c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d8854c3020,0x55d88735b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c1fafbf603d7fe7b89d591c9db936160f190ef4e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4182 processed earlier; will process 6847 files now Step #5: ==122656== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d87bdce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d882433898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d8824165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d8824164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d87bdd4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d87bd35b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d87bd30355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d87bdc6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d87ed95f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d87ed95f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d87ed95f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d87ed95f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d87ed95f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d87ed95f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d87ed95f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d87ed95f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d87ed95f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d87ed95f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d88102af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d87dd57b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d87dd62be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d87db0ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d87db0ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d87db0f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d87db0e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d87db0e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d87db0e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d882418abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d882421928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d882409699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d882434112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e207a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d87bd2eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x20,0x0,0x2d,0x20,0x20,0x0,0x0,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x3e,0x24,0x40,0x3e,0x0,0x0,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x3e,0x24,0x40,0x3e,0x0,0x0,0x26,0x26,0x26,0x26,0x24,0x30,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x3e,0x24,0x30, Step #5: - \000- \000\000&&&&&&&&>$@>\000\000&&&&&&&&>$@>\000\000&&&&$0&&&&&&&&&&>$0 Step #5: artifact_prefix='./'; Test unit written to ./oom-c2078e62ec60d4aa954f600b2760936b758d84ba Step #5: Base64: LSAgAC0gIAAAJiYmJiYmJiY+JEA+AAAmJiYmJiYmJj4kQD4AACYmJiYkMCYmJiYmJiYmJiY+JDA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3406 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3395551356 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55563228d810, 0x55563247701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555632477020,0x55563430f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c2078e62ec60d4aa954f600b2760936b758d84ba' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4183 processed earlier; will process 6846 files now Step #5: ==122692== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555628d829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55562f3e7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55562f3ca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55562f3ca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555628d88d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555628ce9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555628ce4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555628d7ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55562bd49f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55562bd49f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55562bd49f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55562bd49f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55562bd49f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55562bd49f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55562bd49f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55562bd49f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55562bd49f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55562bd49f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55562dfdef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55562ad0bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55562ad16be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55562aac2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55562aac2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55562aac3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55562aac2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55562aac2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55562aac2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55562f3ccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55562f3d5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55562f3bd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55562f3e8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f75e57a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555628ce2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x69,0x6c,0x65,0x3a,0x2f,0xe3,0x82,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0xa0,0x82,0xe3,0x80,0x80,0xe3,0x80,0x82,0xe3,0x80,0x82,0x2c,0xe3,0x80,0x82,0x30,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82, Step #5: File:/\343\202\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\240\202\343\200\200\343\200\202\343\200\202,\343\200\2020\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202 Step #5: artifact_prefix='./'; Test unit written to ./oom-d68eb4f1429192aa643d6d34281e833701b3a4a8 Step #5: Base64: RmlsZTov44KC44CC44CC44CC44CC44CC46CC44CA44CC44CCLOOAgjDjgILjgILjgILjgILjgII= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3407 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3396042566 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5612b1f31810, 0x5612b211b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5612b211b020,0x5612b3fb30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d68eb4f1429192aa643d6d34281e833701b3a4a8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4184 processed earlier; will process 6845 files now Step #5: ==122728== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5612a8a269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5612af08b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5612af06e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5612af06e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5612a8a2cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5612a898db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5612a8988355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5612a8a1ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5612ab9edf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5612ab9edf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5612ab9edf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5612ab9edf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5612ab9edf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5612ab9edf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5612ab9edf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5612ab9edf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5612ab9edf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5612ab9edf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5612adc82f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5612aa9afb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5612aa9babe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5612aa766c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5612aa766c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5612aa767738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5612aa766874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5612aa766874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5612aa766874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5612af070abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5612af079928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5612af061699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5612af08c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd6b2753082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5612a8986b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x0,0x6b,0x0,0x60,0x2b,0x2b,0x4a,0x9,0x29,0x4a,0x9,0x29,0xa,0x20,0x0,0x29,0xa,0x5c,0x2b,0x2b,0x4a,0x9,0x29,0x4a,0x9,0x29,0xa,0x20,0x0,0x29,0xa,0x5c,0x9,0x60,0xa9,0x60,0x40,0x29,0xa,0x1,0x0,0x1d,0x9,0x60,0xa9,0x60,0x40,0x29,0xa,0x1,0x0,0x1d,0x9,0x2b,0x29, Step #5: \012\000k\000`++J\011)J\011)\012 \000)\012\\++J\011)J\011)\012 \000)\012\\\011`\251`@)\012\001\000\035\011`\251`@)\012\001\000\035\011+) Step #5: artifact_prefix='./'; Test unit written to ./oom-88295eb0175b6bf097d700c20d16ca2ae2d7e507 Step #5: Base64: CgBrAGArK0oJKUoJKQogACkKXCsrSgkpSgkpCiAAKQpcCWCpYEApCgEAHQlgqWBAKQoBAB0JKyk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3408 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3396652949 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c31d39c810, 0x55c31d58601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c31d586020,0x55c31f41e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88295eb0175b6bf097d700c20d16ca2ae2d7e507' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4185 processed earlier; will process 6844 files now Step #5: ==122764== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c313e919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c31a4f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c31a4d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c31a4d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c313e97d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c313df8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c313df3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c313e89c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c316e58f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c316e58f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c316e58f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c316e58f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c316e58f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c316e58f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c316e58f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c316e58f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c316e58f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c316e58f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c3190edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c315e1ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c315e25be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c315bd1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c315bd1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c315bd2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c315bd1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c315bd1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c315bd1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c31a4dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c31a4e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c31a4cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c31a4f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f41aeef2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c313df1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x45,0x47,0x49,0x73,0x2d,0x2d,0x2d,0x2d,0x45,0x47,0x49,0x4e,0x20,0xca,0xb7,0xd,0xd,0xd,0x29,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0xca,0xb7,0xd,0x4e,0x20,0xca,0xb7,0xd,0xd,0xd,0x29,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0xca,0xb7,0xd,0xd,0xd,0x29,0x48, Step #5: s----EGIs----EGIN \312\267\015\015\015)-BEGIN \312\267\015N \312\267\015\015\015)-BEGIN \312\267\015\015\015)H Step #5: artifact_prefix='./'; Test unit written to ./oom-71c064be157b50147ab647f6b2cdfe18680d3637 Step #5: Base64: cy0tLS1FR0lzLS0tLUVHSU4gyrcNDQ0pLUJFR0lOIMq3DU4gyrcNDQ0pLUJFR0lOIMq3DQ0NKUg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3409 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3397143115 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c59ef2d810, 0x55c59f11701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c59f117020,0x55c5a0faf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/71c064be157b50147ab647f6b2cdfe18680d3637' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4186 processed earlier; will process 6843 files now Step #5: ==122800== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c595a229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c59c087898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c59c06a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c59c06a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c595a28d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c595989b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c595984355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c595a1ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c5989e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c5989e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c5989e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c5989e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c5989e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c5989e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c5989e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c5989e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c5989e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c5989e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c59ac7ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c5979abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c5979b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c597762c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c597762c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c597763738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c597762874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c597762874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c597762874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c59c06cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c59c075928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c59c05d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c59c088112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc7688f2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c595982b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xc,0x62,0xa,0xa,0x8,0xcd,0x9e,0xc3,0xa5,0xc3,0xa5,0xcd,0xa5,0xa,0xc,0x62,0xa,0xa,0x8,0xcd,0x9e,0xc3,0xa5,0xc3,0xa5,0xcd,0xa5,0xa,0xc,0x62,0xa,0xa,0x8,0xcd,0x9e,0xc3,0xa5,0xc3,0xa5,0xcd,0xa5,0xa,0xc,0x62,0xa,0xa,0x8,0xcd,0x9e,0xc3,0xa5,0xcd,0x9e,0xc3,0xa5, Step #5: \012\014b\012\012\010\315\236\303\245\303\245\315\245\012\014b\012\012\010\315\236\303\245\303\245\315\245\012\014b\012\012\010\315\236\303\245\303\245\315\245\012\014b\012\012\010\315\236\303\245\315\236\303\245 Step #5: artifact_prefix='./'; Test unit written to ./oom-0e752f5f086ab1253928bb04f42997bfebdb737c Step #5: Base64: CgxiCgoIzZ7DpcOlzaUKDGIKCgjNnsOlw6XNpQoMYgoKCM2ew6XDpc2lCgxiCgoIzZ7Dpc2ew6U= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3410 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3397633038 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5608a8ad4810, 0x5608a8cbe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5608a8cbe020,0x5608aab560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0e752f5f086ab1253928bb04f42997bfebdb737c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4187 processed earlier; will process 6842 files now Step #5: #1 pulse cov: 3617 ft: 3618 exec/s: 0 rss: 174Mb Step #5: ==122836== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56089f5c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5608a5c2e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608a5c115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608a5c114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56089f5cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56089f530b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56089f52b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56089f5c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5608a2590f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5608a2590f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5608a2590f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5608a2590f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5608a2590f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5608a2590f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5608a2590f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5608a2590f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5608a2590f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5608a2590f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608a4825f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5608a1552b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5608a155dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5608a1309c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5608a1309c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5608a130a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5608a1309874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5608a1309874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5608a1309874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5608a5c13abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5608a5c1c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5608a5c04699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5608a5c2f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f997a96e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56089f529b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0x20,0x0,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa8,0x8e,0x3d,0x20,0x7f,0x7f,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0x38,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x28,0xd,0x0,0x72,0x64,0x38,0x0,0x0,0x0,0xa0,0xa,0x3d,0x64,0x64, Step #5: \341\240\216= \177\177 \000(\342\200\254\000\341\250\216= \177\177\342\200\215\000\000(\342\200\256\000r+8\000\000\000\000\000\000\000\000(\015\000rd8\000\000\000\240\012=dd Step #5: artifact_prefix='./'; Test unit written to ./oom-ce0a9a7e66011ee8cd5f5d93dc0a854e454c35c3 Step #5: Base64: 4aCOPSB/fyAAKOKArADhqI49IH9/4oCNAAAo4oCuAHIrOAAAAAAAAAAAKA0AcmQ4AAAAoAo9ZGQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3411 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3398163290 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561616e7b810, 0x56161706501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561617065020,0x561618efd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce0a9a7e66011ee8cd5f5d93dc0a854e454c35c3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4189 processed earlier; will process 6840 files now Step #5: #1 pulse cov: 11328 ft: 11329 exec/s: 0 rss: 190Mb Step #5: ==122872== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56160d9709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561613fd5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561613fb85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561613fb84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56160d976d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56160d8d7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56160d8d2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56160d968c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561610937f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561610937f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561610937f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561610937f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561610937f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561610937f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561610937f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561610937f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561610937f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561610937f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561612bccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56160f8f9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56160f904be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56160f6b0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56160f6b0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56160f6b1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56160f6b0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56160f6b0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56160f6b0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561613fbaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561613fc3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561613fab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561613fd6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f98f4728082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56160d8d0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xa,0xd8,0x80,0xe0,0xb9,0x82,0x4,0x0,0x0,0xa,0x2f,0x20,0x0,0x2b,0x38,0x76,0x2d,0x0,0x3a,0xd8,0x80,0x4,0x25,0x0,0x5,0x0,0x0,0x38,0xa,0xd8,0x7d,0x1f,0xb9,0x82,0x4,0x0,0x0,0xa,0x2d,0x20,0x2b,0x2f,0x76,0x38,0x0,0x0,0x3a,0xd8,0x80,0x4,0x25,0x0,0x1,0x0,0xa0, Step #5: \000\012\330\200\340\271\202\004\000\000\012/ \000+8v-\000:\330\200\004%\000\005\000\0008\012\330}\037\271\202\004\000\000\012- +/v8\000\000:\330\200\004%\000\001\000\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-be246efc62fc4d9a1c957afc51df77d42f242a00 Step #5: Base64: AArYgOC5ggQAAAovIAArOHYtADrYgAQlAAUAADgK2H0fuYIEAAAKLSArL3Y4AAA62IAEJQABAKA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3412 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3398729463 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5596b36c9810, 0x5596b38b301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596b38b3020,0x5596b574b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/be246efc62fc4d9a1c957afc51df77d42f242a00' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4191 processed earlier; will process 6838 files now Step #5: #1 pulse cov: 3514 ft: 3515 exec/s: 0 rss: 174Mb Step #5: ==122908== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5596aa1be9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5596b0823898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5596b08065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5596b08064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5596aa1c4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5596aa125b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5596aa120355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5596aa1b6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5596ad185f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5596ad185f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5596ad185f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5596ad185f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5596ad185f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5596ad185f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5596ad185f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5596ad185f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5596ad185f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5596ad185f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596af41af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5596ac147b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5596ac152be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5596abefec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5596abefec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5596abeff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5596abefe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5596abefe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5596abefe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5596b0808abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5596b0811928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5596b07f9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5596b0824112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fec4aff4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5596aa11eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0xf3,0xa0,0x80,0xa1,0x2d,0x36,0xf3,0xa0,0x81,0xb9,0x3,0x6,0x0,0x0,0x31,0x0,0x24,0x54,0x3d,0xa,0x3d,0xa,0x1,0x14,0x3d,0xa,0xe2,0x80,0xae,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x29,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0xe,0xe,0x24, Step #5: ID\363\240\200\241-6\363\240\201\271\003\006\000\0001\000$T=\012=\012\001\024=\012\342\200\256=\012=\012=\012=\012=\012=)=\012=\012=\012=\012\000\000\016\016$ Step #5: artifact_prefix='./'; Test unit written to ./oom-5723d36e0bcb7bad8b4b97046c1934495df83647 Step #5: Base64: SUTzoIChLTbzoIG5AwYAADEAJFQ9Cj0KARQ9CuKArj0KPQo9Cj0KPQo9KT0KPQo9Cj0KAAAODiQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3413 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3399277254 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ec3eb0810, 0x562ec409a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ec409a020,0x562ec5f320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5723d36e0bcb7bad8b4b97046c1934495df83647' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4193 processed earlier; will process 6836 files now Step #5: ==122944== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562eba9a59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ec100a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ec0fed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ec0fed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562eba9abd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562eba90cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562eba907355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562eba99dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ebd96cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ebd96cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ebd96cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ebd96cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ebd96cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ebd96cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ebd96cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ebd96cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ebd96cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ebd96cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ebfc01f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ebc92eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ebc939be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ebc6e5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ebc6e5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ebc6e6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ebc6e5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ebc6e5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ebc6e5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ec0fefabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ec0ff8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ec0fe0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ec100b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9fc39fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562eba905b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0xd,0xa,0x2a,0x32,0x33,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa,0x2a,0xd,0xa, Step #5: *\015\012*23\015\012*\015\012*\015\012*\015\012*\015\012*\015\012*\015\012*\015\012*\015\012*\015\012*\015\012*\015\012*\015\012*\015\012*\015\012*\015\012*\015\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-2effb0c36ec0a597beca2e893ad99a1762542e34 Step #5: Base64: Kg0KKjIzDQoqDQoqDQoqDQoqDQoqDQoqDQoqDQoqDQoqDQoqDQoqDQoqDQoqDQoqDQoqDQoqDQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3414 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3399766474 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560ee1359810, 0x560ee154301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560ee1543020,0x560ee33db0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2effb0c36ec0a597beca2e893ad99a1762542e34' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4194 processed earlier; will process 6835 files now Step #5: ==122980== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560ed7e4e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560ede4b3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560ede4965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560ede4964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560ed7e54d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560ed7db5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560ed7db0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560ed7e46c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560edae15f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560edae15f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560edae15f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560edae15f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560edae15f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560edae15f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560edae15f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560edae15f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560edae15f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560edae15f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560edd0aaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560ed9dd7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560ed9de2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560ed9b8ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560ed9b8ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560ed9b8f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560ed9b8e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560ed9b8e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560ed9b8e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560ede498abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560ede4a1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560ede489699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560ede4b4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1efbca1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560ed7daeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x83,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1, Step #5: \012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\203\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a8554bfff4004052ff6047011793d8b7780fb03 Step #5: Base64: CgxiCgoI87yBgPSAgKEKDGIKCgjzvIGA9ICAoQoMYgoKCPO8g4D0gIChCgxiCgoI87yBgPSAgKE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3415 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3400257272 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562765362810, 0x56276554c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56276554c020,0x5627673e40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a8554bfff4004052ff6047011793d8b7780fb03' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4195 processed earlier; will process 6834 files now Step #5: ==123016== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56275be579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5627624bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56276249f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56276249f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56275be5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56275bdbeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56275bdb9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56275be4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56275ee1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56275ee1ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56275ee1ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56275ee1ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56275ee1ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56275ee1ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56275ee1ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56275ee1ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56275ee1ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56275ee1ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5627610b3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56275dde0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56275ddebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56275db97c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56275db97c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56275db98738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56275db97874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56275db97874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56275db97874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5627624a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5627624aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562762492699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5627624bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a5d14f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56275bdb7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x53,0x3a,0xe3,0x8c,0x96,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x2e,0xe3,0x8c,0x96,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x2e,0xe3,0x8c,0x96,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: wS:\343\214\226\315\204\315\204\315\204\315\204\315\204\315\204\315\204.\343\214\226\315\204\315\204\315\204\315\204\315\204\315\204\315\204.\343\214\226\315\204\315\204\315\204\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-fc9528291b390b8a2ed5fd6bcb4ec75ad2203942 Step #5: Base64: d1M644yWzYTNhM2EzYTNhM2EzYQu44yWzYTNhM2EzYTNhM2EzYQu44yWzYTNhM2EzYTNhM2EzYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3416 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3400751394 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5584489f9810, 0x558448be301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558448be3020,0x55844aa7b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc9528291b390b8a2ed5fd6bcb4ec75ad2203942' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4196 processed earlier; will process 6833 files now Step #5: ==123052== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55843f4ee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558445b53898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558445b365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558445b364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55843f4f4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55843f455b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55843f450355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55843f4e6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5584424b5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5584424b5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5584424b5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5584424b5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5584424b5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5584424b5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5584424b5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5584424b5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5584424b5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5584424b5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55844474af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558441477b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558441482be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55844122ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55844122ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55844122f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55844122e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55844122e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55844122e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558445b38abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558445b41928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558445b29699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558445b54112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb70df29082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55843f44eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x2d,0xa,0x3d,0x3d,0x5,0xa,0x3d,0x3d,0xa,0x2d,0xa,0x5,0xa,0x3d,0x3d,0xa,0x2d,0xa,0x4e,0x2d,0x2d,0xa,0xd9,0x8e,0x1f,0xa,0xa,0xa,0x3d,0xa,0x3d,0xa,0x6c,0x6c,0x6c,0x6c,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0x13,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: =-\012==\005\012==\012-\012\005\012==\012-\012N--\012\331\216\037\012\012\012=\012=\012llll\012=\012=\012\012=\023=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-5c004c5278435a70faf2fed5b51abbaf7616ab2d Step #5: Base64: PS0KPT0FCj09Ci0KBQo9PQotCk4tLQrZjh8KCgo9Cj0KbGxsbAo9Cj0KCj0TPQo9Cj0KPQo9ChA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3417 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3401250526 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55850ee31810, 0x55850f01b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55850f01b020,0x558510eb30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c004c5278435a70faf2fed5b51abbaf7616ab2d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4197 processed earlier; will process 6832 files now Step #5: ==123088== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5585059269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55850bf8b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55850bf6e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55850bf6e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55850592cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55850588db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558505888355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55850591ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5585088edf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5585088edf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5585088edf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5585088edf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5585088edf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5585088edf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5585088edf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5585088edf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5585088edf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5585088edf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55850ab82f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5585078afb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5585078babe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558507666c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558507666c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558507667738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558507666874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558507666874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558507666874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55850bf70abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55850bf79928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55850bf61699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55850bf8c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f38559aa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558505886b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x47,0x65,0x74,0x20,0x2f,0x68,0x69,0x20,0x48,0x54,0x54,0x50,0x2f,0x31,0x2e,0x31,0xd,0xa,0x68,0x6f,0x73,0x74,0x3a,0xd,0xa,0x74,0x72,0x61,0x6e,0x73,0x66,0x45,0x72,0x2d,0x65,0x6e,0x63,0x4f,0x64,0x69,0x6e,0x67,0x3a,0x25,0xd,0xa,0xd,0xa,0x42,0x46,0x46,0x46,0x46,0x46,0x65, Step #5: eGet /hi HTTP/1.1\015\012host:\015\012transfEr-encOding:%\015\012\015\012BFFFFFe Step #5: artifact_prefix='./'; Test unit written to ./oom-5b3457a3f7eecafed3b06d9522506ab192e3408b Step #5: Base64: ZUdldCAvaGkgSFRUUC8xLjENCmhvc3Q6DQp0cmFuc2ZFci1lbmNPZGluZzolDQoNCkJGRkZGRmU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3418 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3401748538 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560dbcec8810, 0x560dbd0b201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560dbd0b2020,0x560dbef4a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5b3457a3f7eecafed3b06d9522506ab192e3408b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4198 processed earlier; will process 6831 files now Step #5: ==123124== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560db39bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560dba022898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560dba0055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560dba0054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560db39c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560db3924b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560db391f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560db39b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560db6984f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560db6984f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560db6984f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560db6984f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560db6984f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560db6984f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560db6984f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560db6984f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560db6984f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560db6984f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560db8c19f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560db5946b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560db5951be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560db56fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560db56fdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560db56fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560db56fd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560db56fd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560db56fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560dba007abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560dba010928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560db9ff8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560dba023112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f60a0f85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560db391db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c,0x6f,0x63,0x61,0x6c,0xd,0x5f,0x3c,0x63,0x6c,0x6f,0x73,0x65,0x3e,0x6c,0x6f,0x63,0x61,0x6c,0xd,0x5f,0x3c,0x63,0x6c,0x6f,0x73,0x65,0x3e,0x6c,0x6f,0x63,0x61,0x6c,0xd,0x5f,0x3c,0x63,0x6c,0x6f,0x73,0x65,0x3e,0x6c,0x6f,0x63,0x61,0x6c,0xd,0x5f,0x3c,0x63,0x6c,0x6f,0x73,0x65,0x3e, Step #5: local\015_<close>local\015_<close>local\015_<close>local\015_<close> Step #5: artifact_prefix='./'; Test unit written to ./oom-cf72a2186f5a8cd4af53d380af4718d7197b33a2 Step #5: Base64: bG9jYWwNXzxjbG9zZT5sb2NhbA1fPGNsb3NlPmxvY2FsDV88Y2xvc2U+bG9jYWwNXzxjbG9zZT4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3419 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3402242267 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c017576810, 0x55c01776001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c017760020,0x55c0195f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf72a2186f5a8cd4af53d380af4718d7197b33a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4199 processed earlier; will process 6830 files now Step #5: ==123160== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c00e06b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c0146d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c0146b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c0146b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c00e071d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c00dfd2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c00dfcd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c00e063c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c011032f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c011032f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c011032f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c011032f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c011032f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c011032f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c011032f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c011032f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c011032f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c011032f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c0132c7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c00fff4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c00ffffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c00fdabc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c00fdabc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c00fdac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c00fdab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c00fdab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c00fdab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c0146b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c0146be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c0146a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c0146d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a65ef7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c00dfcbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x7f,0x0,0x21,0x0,0x32,0x0,0x0,0x0,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x2c,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x32,0x0,0x24,0x0,0x0,0x0, Step #5: $\177]\177\000!\0002\000\000\0002.23/\020./, 7 =\177\000\000\000\000\177\177\177o\000\00023/\020./( 7 =\177\000\000\0002\000$\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-85ccaac16798fffa0eb2ac731d4e14e023a5c490 Step #5: Base64: JH9dfwAhADIAAAAyLjIzLxAuLywgNyA9fwAAAAB/f39vAAAyMy8QLi8oIDcgPX8AAAAyACQAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3420 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3402734956 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55677ea8d810, 0x55677ec7701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55677ec77020,0x556780b0f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/85ccaac16798fffa0eb2ac731d4e14e023a5c490' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4200 processed earlier; will process 6829 files now Step #5: ==123196== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5567755829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55677bbe7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55677bbca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55677bbca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556775588d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5567754e9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5567754e4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55677557ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556778549f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556778549f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556778549f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556778549f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556778549f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556778549f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556778549f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556778549f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556778549f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556778549f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55677a7def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55677750bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556777516be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5567772c2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5567772c2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5567772c3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5567772c2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5567772c2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5567772c2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55677bbccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55677bbd5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55677bbbd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55677bbe8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f85b5e0f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5567754e2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0x0,0x0,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0xe2,0x80,0x89,0x0,0x0,0x28,0x30,0x80,0xae,0x0,0x72,0x2b,0x2f,0x76,0x30,0x0,0xf3,0xa0,0x81,0xb8,0x0,0x28,0xd,0x0,0x72,0x64,0x64,0x64,0xb5,0xf3,0xa0,0x81,0x87,0x64,0x64, Step #5: \341\240\216= \177\177\000\000(\342\200\254\000\341\240\216= \177\177\342\200\211\000\000(0\200\256\000r+/v0\000\363\240\201\270\000(\015\000rddd\265\363\240\201\207dd Step #5: artifact_prefix='./'; Test unit written to ./oom-73ab77a262eb8fd6f68c82375f5bee10d82bd86a Step #5: Base64: 4aCOPSB/fwAAKOKArADhoI49IH9/4oCJAAAoMICuAHIrL3YwAPOggbgAKA0AcmRkZLXzoIGHZGQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3421 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3403226613 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560440778810, 0x56044096201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560440962020,0x5604427fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/73ab77a262eb8fd6f68c82375f5bee10d82bd86a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4201 processed earlier; will process 6828 files now Step #5: ==123232== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56043726d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56043d8d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56043d8b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56043d8b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560437273d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5604371d4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5604371cf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560437265c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56043a234f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56043a234f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56043a234f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56043a234f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56043a234f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56043a234f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56043a234f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56043a234f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56043a234f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56043a234f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56043c4c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5604391f6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560439201be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560438fadc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560438fadc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560438fae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560438fad874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560438fad874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560438fad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56043d8b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56043d8c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56043d8a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56043d8d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe53ea76082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5604371cdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x32,0x0,0x24,0x0,0x0,0x0, Step #5: $\177]\177\000\000\0002\000\000\0002.23/\020./( 7 =\177\000\000\000\000\177\177\177o\000\00023/\020./( 7 =\177\000\000\0002\000$\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-51b652f36d2ceb7b144f6b9a010d77a9258d9cc7 Step #5: Base64: JH9dfwAAADIAAAAyLjIzLxAuLyggNyA9fwAAAAB/f39vAAAyMy8QLi8oIDcgPX8AAAAyACQAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3422 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3403726913 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55681cf94810, 0x55681d17e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55681d17e020,0x55681f0160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/51b652f36d2ceb7b144f6b9a010d77a9258d9cc7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4202 processed earlier; will process 6827 files now Step #5: ==123268== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556813a899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55681a0ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55681a0d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55681a0d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556813a8fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5568139f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5568139eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556813a81c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556816a50f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556816a50f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556816a50f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556816a50f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556816a50f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556816a50f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556816a50f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556816a50f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556816a50f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556816a50f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556818ce5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556815a12b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556815a1dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5568157c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5568157c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5568157ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5568157c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5568157c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5568157c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55681a0d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55681a0dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55681a0c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55681a0ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f28fd424082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5568139e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x6d,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x7a,0x24,0x7c,0x2e,0x7c,0x24,0x7c,0x73,0x7c,0x24,0x7c,0x5c,0x7a,0x7c,0x25,0x7c,0x5c,0x7a,0x7c,0x0,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x29,0x7c, Step #5: (?:(?:(?:(?:(?:(?m:(?:$|z$|.|$|s|$|\\z|%|\\z|\000)|)|)|)|)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-a47e66649108d2cb2f4e8118408bf6e3a9c1b2ff Step #5: Base64: KD86KD86KD86KD86KD86KD9tOig/OiR8eiR8LnwkfHN8JHxcenwlfFx6fAApfCl8KXwpfCl8KXw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3423 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3404228997 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c7af9fe810, 0x55c7afbe801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c7afbe8020,0x55c7b1a800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a47e66649108d2cb2f4e8118408bf6e3a9c1b2ff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4203 processed earlier; will process 6826 files now Step #5: ==123304== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c7a64f39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7acb58898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7acb3b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7acb3b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c7a64f9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c7a645ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c7a6455355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7a64ebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7a94baf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7a94baf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7a94baf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7a94baf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7a94baf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7a94baf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7a94baf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7a94baf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7a94baf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7a94baf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7ab74ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7a847cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7a8487be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7a8233c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7a8233c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7a8234738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7a8233874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7a8233874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7a8233874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7acb3dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7acb46928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c7acb2e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7acb59112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc10ef34082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c7a6453b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x4e,0x2f,0xe,0x0,0x0,0x2,0x25,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x25,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xab,0x0,0x3a,0x1,0x0,0x0,0x0, Step #5: \000N/\016\000\000\002%\000\000\000\000\000\000\000\000\000\002%\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\342\200\253\000:\001\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0acff23461b12c333a793608a2c918a5b1ba00ca Step #5: Base64: AE4vDgAAAiUAAAAAAAAAAAACJQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADigKsAOgEAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3424 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3404719922 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c59ef9d810, 0x55c59f18701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c59f187020,0x55c5a101f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0acff23461b12c333a793608a2c918a5b1ba00ca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4204 processed earlier; will process 6825 files now Step #5: ==123340== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c595a929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c59c0f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c59c0da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c59c0da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c595a98d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c5959f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c5959f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c595a8ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c598a59f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c598a59f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c598a59f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c598a59f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c598a59f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c598a59f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c598a59f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c598a59f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c598a59f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c598a59f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c59aceef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c597a1bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c597a26be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c5977d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c5977d2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c5977d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c5977d2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c5977d2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c5977d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c59c0dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c59c0e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c59c0cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c59c0f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4be4134082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c5959f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0x7b,0x22,0x4d,0x34,0x22,0x3a,0x20,0x34,0x2c,0x22,0x34,0xd6,0x99,0x61,0x22,0x3a,0x2d,0x38,0x2c,0x22,0x35,0x32,0xd6,0x80,0x22,0x3a,0x20,0x34,0x2c,0x22,0x6c,0x3d,0x6d,0x30,0x22,0x3a,0x2d,0x38,0x2c,0x22,0x34,0xd6,0x99,0x61,0x27,0x2d,0x2c,0x2d,0x22,0x3a,0x34,0x35,0x39,0x7d,0xa, Step #5: \012\012{\"M4\": 4,\"4\326\231a\":-8,\"52\326\200\": 4,\"l=m0\":-8,\"4\326\231a'-,-\":459}\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-316f3ff2761c5b85b28dfc21cf25e84f5e3d050b Step #5: Base64: Cgp7Ik00IjogNCwiNNaZYSI6LTgsIjUy1oAiOiA0LCJsPW0wIjotOCwiNNaZYSctLC0iOjQ1OX0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3425 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3405210929 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56028da32810, 0x56028dc1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56028dc1c020,0x56028fab40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/316f3ff2761c5b85b28dfc21cf25e84f5e3d050b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4205 processed earlier; will process 6824 files now Step #5: #1 pulse cov: 3749 ft: 3750 exec/s: 0 rss: 175Mb Step #5: ==123376== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5602845279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56028ab8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56028ab6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56028ab6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56028452dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56028448eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560284489355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56028451fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5602874eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5602874eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5602874eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5602874eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5602874eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5602874eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5602874eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5602874eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5602874eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5602874eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560289783f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5602864b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5602864bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560286267c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560286267c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560286268738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560286267874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560286267874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560286267874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56028ab71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56028ab7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56028ab62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56028ab8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f07fb3a7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560284487b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x7e,0x21,0x7d,0x3c,0x74,0x65,0x78,0x74,0x3e,0x30,0x21,0xe0,0xb8,0xb1,0x55,0x2d,0x5b,0x21,0x30,0x65,0x7f,0x7f,0x7f,0x65,0x78,0x74,0x3e,0x30,0x21,0xe0,0xbd,0xb1,0x55,0x2d,0x7f,0x30,0x7f,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x42,0x4f,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg>~!}<text>0!\340\270\261U-[!0e\177\177\177ext>0!\340\275\261U-\1770\177</text>BO</svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-b61119a1cae14703aeff82bb5f13c1ac8ec76cca Step #5: Base64: PHN2Zz5+IX08dGV4dD4wIeC4sVUtWyEwZX9/f2V4dD4wIeC9sVUtfzB/PC90ZXh0PkJPPC9zdmc+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3426 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3405740543 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559fc9240810, 0x559fc942a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559fc942a020,0x559fcb2c20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b61119a1cae14703aeff82bb5f13c1ac8ec76cca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4207 processed earlier; will process 6822 files now Step #5: ==123412== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559fbfd359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559fc639a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559fc637d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559fc637d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559fbfd3bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559fbfc9cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559fbfc97355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559fbfd2dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559fc2cfcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559fc2cfcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559fc2cfcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559fc2cfcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559fc2cfcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559fc2cfcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559fc2cfcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559fc2cfcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559fc2cfcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559fc2cfcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559fc4f91f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559fc1cbeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559fc1cc9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559fc1a75c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559fc1a75c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559fc1a76738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559fc1a75874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559fc1a75874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559fc1a75874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559fc637fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559fc6388928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559fc6370699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559fc639b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f188cfc5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559fbfc95b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x49,0x4d,0x33,0x4,0xe2,0x80,0xae,0x4,0x44,0x33,0x49,0x4d,0x33,0x4,0xe2,0x80,0xae,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa6,0x5b,0xcd,0x9e,0xef,0xf7,0xb9,0x32,0x22, Step #5: ID3IM3\004\342\200\256\004D3IM3\004\342\200\256\004\000\000\000\000\000\000\000\177\000\000\000\000\000\000\000'\000\000\000\000\000\000\000\000\000\000\000\246[\315\236\357\367\2712\" Step #5: artifact_prefix='./'; Test unit written to ./oom-7dceb3e6f486922ffd30e0bc85ec06ec8994f8be Step #5: Base64: SUQzSU0zBOKArgREM0lNMwTigK4EAAAAAAAAAH8AAAAAAAAAJwAAAAAAAAAAAAAAplvNnu/3uTIi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3427 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3406225554 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5600b091e810, 0x5600b0b0801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5600b0b08020,0x5600b29a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7dceb3e6f486922ffd30e0bc85ec06ec8994f8be' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4208 processed earlier; will process 6821 files now Step #5: ==123448== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5600a74139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5600ada78898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5600ada5b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5600ada5b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5600a7419d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5600a737ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5600a7375355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5600a740bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5600aa3daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5600aa3daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5600aa3daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5600aa3daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5600aa3daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5600aa3daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5600aa3daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5600aa3daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5600aa3daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5600aa3daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5600ac66ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5600a939cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5600a93a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5600a9153c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5600a9153c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5600a9154738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5600a9153874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5600a9153874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5600a9153874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5600ada5dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5600ada66928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5600ada4e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5600ada79112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd8a62ec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5600a7373b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x20,0x7b,0xa,0x20,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x22,0xa,0x7d,0xa, Step #5: e {\012 name: \"llllllllllllllllllllllllllllllllllllllll\"\012}\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-a18b9732da8974ab28b0bb7877c4cf2c48c7bac2 Step #5: Base64: ZSB7CiAgbmFtZTogImxsbGxsbGxsbGxsbGxsbGxsbGxsbGxsbGxsbGxsbGxsbGxsbGxsbGwiCn0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3428 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3406714651 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b2f33f7810, 0x55b2f35e101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b2f35e1020,0x55b2f54790e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a18b9732da8974ab28b0bb7877c4cf2c48c7bac2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4209 processed earlier; will process 6820 files now Step #5: ==123484== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b2e9eec9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b2f0551898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b2f05345dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b2f05344fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b2e9ef2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b2e9e53b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b2e9e4e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b2e9ee4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b2eceb3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b2eceb3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b2eceb3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b2eceb3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b2eceb3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b2eceb3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b2eceb3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b2eceb3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b2eceb3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b2eceb3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b2ef148f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b2ebe75b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b2ebe80be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b2ebc2cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b2ebc2cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b2ebc2d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b2ebc2c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b2ebc2c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b2ebc2c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b2f0536abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b2f053f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b2f0527699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b2f0552112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f56ceb83082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b2e9e4cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0xaf,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0xaf,0xcd,0x8f,0xcd,0x8f,0xcd,0xaf,0xcd,0x8f,0xcd,0x8f,0xcc,0x9f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f, Step #5: 2\315\217\315\217\315\217\315\217\315\217\315\217\315\257\315\217\315\217\315\217\315\257\315\217\315\217\315\257\315\217\315\217\314\237\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-7d4e26faef324b42dc88d0432553487d2475d7bf Step #5: Base64: Ms2PzY/Nj82PzY/Nj82vzY/Nj82Pza/Nj82Pza/Nj82PzJ/Nj82PzY/Nj82PzY/Nj82PzY/Nj82P Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3429 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3407203043 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d015100810, 0x55d0152ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d0152ea020,0x55d0171820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d4e26faef324b42dc88d0432553487d2475d7bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4210 processed earlier; will process 6819 files now Step #5: #1 pulse cov: 3878 ft: 3879 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 4041 ft: 4396 exec/s: 0 rss: 175Mb Step #5: ==123520== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d00bbf59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d01225a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d01223d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d01223d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d00bbfbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d00bb5cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d00bb57355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d00bbedc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d00ebbcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d00ebbcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d00ebbcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d00ebbcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d00ebbcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d00ebbcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d00ebbcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d00ebbcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d00ebbcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d00ebbcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d010e51f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d00db7eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d00db89be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d00d935c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d00d935c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d00d936738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d00d935874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d00d935874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d00d935874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d01223fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d012248928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d012230699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d01225b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3bb1c15082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d00bb55b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x20,0x0,0x2d,0x20,0x20,0x0,0x0,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x3e,0x24,0x40,0x3e,0x0,0x0,0x26,0x26,0x26,0x26,0x24,0x30,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x62,0x6f,0x6c,0x64,0x26,0x3e,0x24,0x30,0x26,0x26,0x62,0x6f,0x6c,0x64,0x26,0x3e,0x24,0x30, Step #5: - \000- \000\000&&&&&&&&>$@>\000\000&&&&$0&&&&&&&&&&bold&>$0&&bold&>$0 Step #5: artifact_prefix='./'; Test unit written to ./oom-f0ece7f3dd344b2739524760ee104c6ec6cdf1be Step #5: Base64: LSAgAC0gIAAAJiYmJiYmJiY+JEA+AAAmJiYmJDAmJiYmJiYmJiYmYm9sZCY+JDAmJmJvbGQmPiQw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3430 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3407835300 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564582b7a810, 0x564582d6401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564582d64020,0x564584bfc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f0ece7f3dd344b2739524760ee104c6ec6cdf1be' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4214 processed earlier; will process 6815 files now Step #5: ==123556== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56457966f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56457fcd4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56457fcb75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56457fcb74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564579675d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5645795d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5645795d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564579667c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56457c636f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56457c636f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56457c636f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56457c636f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56457c636f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56457c636f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56457c636f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56457c636f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56457c636f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56457c636f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56457e8cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56457b5f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56457b603be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56457b3afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56457b3afc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56457b3b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56457b3af874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56457b3af874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56457b3af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56457fcb9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56457fcc2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56457fcaa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56457fcd5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9acbbcf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5645795cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x70,0x6e,0x72,0x79,0x73,0x6c,0x61,0x74,0x65,0x3e,0x3c,0x74,0x72,0x61,0x6e,0x73,0x6c,0x61,0x74,0x72,0x66,0x6e,0x73,0x6c,0x61,0x74,0x65,0x3e,0x3c,0x74,0x72,0x61,0x6e,0x73,0x6c,0x72,0x79,0x3e,0x3c,0x61,0x74,0x65,0x3e,0x3c,0x74,0x72,0x61,0x6e,0x73,0x6c,0x61,0x74,0x65,0x3e,0x4e,0x65, Step #5: <pnryslate><translatrfnslate><translry><ate><translate>Ne Step #5: artifact_prefix='./'; Test unit written to ./oom-fb6f6acbbff744ea2fc026ca094e6b7086626e08 Step #5: Base64: PHBucnlzbGF0ZT48dHJhbnNsYXRyZm5zbGF0ZT48dHJhbnNscnk+PGF0ZT48dHJhbnNsYXRlPk5l Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3431 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3408323044 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eca8c02810, 0x55eca8dec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eca8dec020,0x55ecaac840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fb6f6acbbff744ea2fc026ca094e6b7086626e08' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4215 processed earlier; will process 6814 files now Step #5: ==123592== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec9f6f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eca5d5c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eca5d3f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eca5d3f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec9f6fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec9f65eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec9f659355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec9f6efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eca26bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eca26bef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eca26bef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eca26bef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eca26bef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eca26bef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eca26bef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eca26bef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eca26bef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eca26bef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eca4953f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eca1680b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eca168bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eca1437c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eca1437c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eca1438738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eca1437874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eca1437874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eca1437874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eca5d41abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eca5d4a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eca5d32699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eca5d5d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1121c35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec9f657b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x1, Step #5: FUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAG\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-034fa94d0df1336e4591d0699d6a7a9b1974b503 Step #5: Base64: RlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUcB Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3432 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3408820572 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5608cd1bf810, 0x5608cd3a901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5608cd3a9020,0x5608cf2410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/034fa94d0df1336e4591d0699d6a7a9b1974b503' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4216 processed earlier; will process 6813 files now Step #5: #1 pulse cov: 13375 ft: 13376 exec/s: 0 rss: 194Mb Step #5: #2 pulse cov: 14048 ft: 14970 exec/s: 0 rss: 196Mb Step #5: ==123628== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5608c3cb49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5608ca319898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608ca2fc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608ca2fc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5608c3cbad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5608c3c1bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5608c3c16355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5608c3cacc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5608c6c7bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5608c6c7bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5608c6c7bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5608c6c7bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5608c6c7bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5608c6c7bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5608c6c7bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5608c6c7bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5608c6c7bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5608c6c7bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608c8f10f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5608c5c3db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5608c5c48be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5608c59f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5608c59f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5608c59f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5608c59f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5608c59f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5608c59f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5608ca2feabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5608ca307928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5608ca2ef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5608ca31a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4215b38082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5608c3c14b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x45,0x3e,0x3c,0x3f,0xcd,0xb6,0x3f,0x3e,0x3c,0x3f,0xcd,0xb6,0x3f,0x3e,0x45,0x3c,0x3f,0xcd,0xb6,0x3f,0x3e,0x3c,0x3f,0xcd,0xb6,0x3f,0x3e,0x3e,0x3c,0x3f,0xcd,0xb6,0x3f,0x3e,0x3c,0x3f,0xcd,0xb6,0x3f,0x3e,0x3c,0x3f,0xcd,0xb6,0x3f,0x3e,0x3c,0x3f,0xcd,0xb6,0x3f,0x3e,0x3c,0x2f,0x45,0x3e, Step #5: <E><?\315\266?><?\315\266?>E<?\315\266?><?\315\266?>><?\315\266?><?\315\266?><?\315\266?><?\315\266?></E> Step #5: artifact_prefix='./'; Test unit written to ./oom-36faf098a25c37cb646d67cf175fef87e8ef2424 Step #5: Base64: PEU+PD/Ntj8+PD/Ntj8+RTw/zbY/Pjw/zbY/Pj48P822Pz48P822Pz48P822Pz48P822Pz48L0U+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3433 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3409419851 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cad79b3810, 0x55cad7b9d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cad7b9d020,0x55cad9a350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/36faf098a25c37cb646d67cf175fef87e8ef2424' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4219 processed earlier; will process 6810 files now Step #5: ==123664== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cace4a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cad4b0d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cad4af05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cad4af04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cace4aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cace40fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cace40a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cace4a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cad146ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cad146ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cad146ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cad146ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cad146ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cad146ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cad146ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cad146ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cad146ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cad146ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cad3704f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cad0431b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cad043cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cad01e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cad01e8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cad01e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cad01e8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cad01e8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cad01e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cad4af2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cad4afb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cad4ae3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cad4b0e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9830d0c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cace408b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x69,0x66,0x31,0x30,0x29,0x69,0x66,0x31,0x30,0x29,0x29,0x29,0x29,0xd7,0xa9,0x1,0x0,0x0,0x15,0x28,0x30,0x29,0x29,0xd7,0xa9,0x28,0x30,0x9,0x37,0x21,0x29,0x29,0x29,0x29,0xd7,0xa9,0x28,0x30,0x9,0x36,0x21,0x29,0x29,0x29,0x29,0xd7,0xa9,0x28,0x30,0x9,0x37,0x21,0x29,0x0,0x8d,0x0, Step #5: !if10)if10))))\327\251\001\000\000\025(0))\327\251(0\0117!))))\327\251(0\0116!))))\327\251(0\0117!)\000\215\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fb9e62599543f60ae01ab9692eb3715c6f74a9c7 Step #5: Base64: IWlmMTApaWYxMCkpKSnXqQEAABUoMCkp16koMAk3ISkpKSnXqSgwCTYhKSkpKdepKDAJNyEpAI0A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3434 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3409910842 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a1cc88810, 0x558a1ce7201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a1ce72020,0x558a1ed0a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fb9e62599543f60ae01ab9692eb3715c6f74a9c7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4220 processed earlier; will process 6809 files now Step #5: #1 pulse cov: 3498 ft: 3499 exec/s: 0 rss: 171Mb Step #5: ==123700== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558a1377d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a19de2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a19dc55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a19dc54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a13783d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a136e4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a136df355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a13775c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a16744f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a16744f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a16744f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a16744f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a16744f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a16744f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a16744f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a16744f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a16744f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a16744f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a189d9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a15706b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a15711be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a154bdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a154bdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a154be738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a154bd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a154bd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a154bd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a19dc7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a19dd0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a19db8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a19de3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f151cec6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a136ddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x46,0x54,0x79,0x77,0x42,0x4b,0x2f,0x37,0x30,0x58,0x69,0x44,0x52,0x48,0x71,0x72,0x74,0x61,0x76,0x45,0x64,0x6d,0x65,0x79,0x73,0x63,0x65,0x6e,0x74,0x20,0x4e,0x30,0x65,0x46,0x76,0x52,0x6c,0xa,0x61,0x20,0x2d,0x31,0x32,0x38,0x2e, Step #5: onion-key\012ntFTywBK/70XiDRHqrtavEdmeyscent N0eFvRl\012a -128. Step #5: artifact_prefix='./'; Test unit written to ./oom-0419ecdbefbb86ffd2ec290e5b1e5f2c655b27b9 Step #5: Base64: b25pb24ta2V5Cm50RlR5d0JLLzcwWGlEUkhxcnRhdkVkbWV5c2NlbnQgTjBlRnZSbAphIC0xMjgu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3435 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3410439628 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557aed540810, 0x557aed72a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557aed72a020,0x557aef5c20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0419ecdbefbb86ffd2ec290e5b1e5f2c655b27b9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4222 processed earlier; will process 6807 files now Step #5: ==123736== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557ae40359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557aea69a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557aea67d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557aea67d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557ae403bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557ae3f9cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557ae3f97355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557ae402dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557ae6ffcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557ae6ffcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557ae6ffcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557ae6ffcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557ae6ffcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557ae6ffcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557ae6ffcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557ae6ffcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557ae6ffcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557ae6ffcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557ae9291f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557ae5fbeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557ae5fc9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557ae5d75c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557ae5d75c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557ae5d76738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557ae5d75874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557ae5d75874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557ae5d75874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557aea67fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557aea688928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557aea670699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557aea69b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc029488082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557ae3f95b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x48,0x3a,0x64,0x2c,0x6d,0x61,0x78,0x5f,0x69,0x64,0x3a,0x64,0x2c,0x48,0x3a,0x64,0x2c,0x64,0x24,0x69,0x6e,0x6e,0x5f,0x35,0x5f,0x31,0x3a,0x64,0x2c,0x48,0x3a,0x64,0x2c,0x68,0x6f,0x6e,0x5f,0x73,0x79,0x6d,0x62,0x6f,0x3a,0x64,0x2c,0x6c,0x5f,0x74,0x48,0x3a,0x64,0x2c, Step #5: $3::{H:d,max_id:d,H:d,d$inn_5_1:d,H:d,hon_symbo:d,l_tH:d, Step #5: artifact_prefix='./'; Test unit written to ./oom-96ad07863b59048f85eb36f8e830b318f4a8b7e4 Step #5: Base64: JDM6OntIOmQsbWF4X2lkOmQsSDpkLGQkaW5uXzVfMTpkLEg6ZCxob25fc3ltYm86ZCxsX3RIOmQs Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3436 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3410934515 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb004cb810, 0x55eb006b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb006b5020,0x55eb0254d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/96ad07863b59048f85eb36f8e830b318f4a8b7e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4223 processed earlier; will process 6806 files now Step #5: ==123772== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eaf6fc09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eafd625898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eafd6085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eafd6084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eaf6fc6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eaf6f27b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eaf6f22355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eaf6fb8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eaf9f87f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eaf9f87f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eaf9f87f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eaf9f87f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eaf9f87f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eaf9f87f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eaf9f87f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eaf9f87f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eaf9f87f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eaf9f87f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eafc21cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eaf8f49b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eaf8f54be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eaf8d00c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eaf8d00c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eaf8d01738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eaf8d00874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eaf8d00874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eaf8d00874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eafd60aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eafd613928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eafd5fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eafd626112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba45b5e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eaf6f20b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x0,0x2d,0x2d,0x32,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x4e,0x21,0x15,0x0,0x2d,0x2d,0x32,0x2d,0x42,0x45,0x47,0x49,0x4e,0x15,0x20,0x4e,0x15,0x1b,0x24,0x2d,0x44,0x2d,0x2b,0xa,0x5b,0x2d,0x2d,0xa,0x29,0xa,0x15,0x20,0x24,0x2d,0xa,0x2b,0x2d,0x2d,0x5b,0x44,0x2d,0xa,0x29,0xa,0x3f, Step #5: !\000--2-BEGIN N!\025\000--2-BEGIN\025 N\025\033$-D-+\012[--\012)\012\025 $-\012+--[D-\012)\012? Step #5: artifact_prefix='./'; Test unit written to ./oom-80148af1f92481580e159fbecb41e70f85722f41 Step #5: Base64: IQAtLTItQkVHSU4gTiEVAC0tMi1CRUdJThUgThUbJC1ELSsKWy0tCikKFSAkLQorLS1bRC0KKQo/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3437 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3411422631 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7a4b3c810, 0x55f7a4d2601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7a4d26020,0x55f7a6bbe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/80148af1f92481580e159fbecb41e70f85722f41' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4224 processed earlier; will process 6805 files now Step #5: ==123808== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f79b6319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7a1c96898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7a1c795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7a1c794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f79b637d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f79b598b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f79b593355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f79b629c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f79e5f8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f79e5f8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f79e5f8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f79e5f8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f79e5f8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f79e5f8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f79e5f8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f79e5f8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f79e5f8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f79e5f8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7a088df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f79d5bab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f79d5c5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f79d371c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f79d371c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f79d372738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f79d371874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f79d371874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f79d371874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7a1c7babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7a1c84928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7a1c6c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7a1c97112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5c04055082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f79b591b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x58,0xc,0x44,0x45,0x46,0x41,0x55,0x4c,0x54,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x57,0x49,0x54,0x48,0x28,0x28,0x28,0x28,0x28,0x28,0x57,0x49,0x54,0x48,0x28,0x57,0x49,0x2a,0x43,0x4f,0x4c,0x55,0x2e,0x43,0x4f,0x4c,0x55,0x2e,0x43,0x4f,0x4c,0x55,0x4d,0x28,0x29,0xcd,0x8f,0x0,0xa, Step #5: \012X\014DEFAULT((((((((WITH((((((WITH(WI*COLU.COLU.COLUM()\315\217\000\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-92fdd3bcd261fb606b888c95e4164b6e9fbf16d8 Step #5: Base64: ClgMREVGQVVMVCgoKCgoKCgoV0lUSCgoKCgoKFdJVEgoV0kqQ09MVS5DT0xVLkNPTFVNKCnNjwAK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3438 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3411911754 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565496bc5810, 0x565496daf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565496daf020,0x565498c470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92fdd3bcd261fb606b888c95e4164b6e9fbf16d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4225 processed earlier; will process 6804 files now Step #5: #1 pulse cov: 3527 ft: 3528 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 11745 ft: 12561 exec/s: 0 rss: 193Mb Step #5: #4 pulse cov: 12955 ft: 16505 exec/s: 0 rss: 196Mb Step #5: ==123844== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56548d6ba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565493d1f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565493d025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565493d024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56548d6c0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56548d621b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56548d61c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56548d6b2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565490681f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565490681f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565490681f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565490681f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565490681f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565490681f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565490681f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565490681f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565490681f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565490681f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565492916f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56548f643b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56548f64ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56548f3fac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56548f3fac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56548f3fb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56548f3fa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56548f3fa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56548f3fa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565493d04abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565493d0d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565493cf5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565493d20112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbcb716b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56548d61ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0xd,0xd,0xd,0x32,0x0,0xd6,0x91,0x91,0x45,0xff,0xff,0xff,0xa,0x22,0x6d,0x80,0xdf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0x1,0x0,0x0,0x30,0xcf,0xa9,0x2b,0x2f,0x76,0xf5,0xf4,0xf4,0xcd,0xc6,0xff,0xb2,0xc6,0x0,0x31,0x0,0x30, Step #5: \002\015\015\0152\000\326\221\221E\377\377\377\012\"m\200\337\317\317\317\317\317\317\317\317\317\317\317\317\317\317\317\317\317\317\317\001\000\0000\317\251+/v\365\364\364\315\306\377\262\306\0001\0000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3360ea0297cb0909665d5f903e3b2012dad66aa1 Step #5: Base64: Ag0NDTIA1pGRRf///woibYDfz8/Pz8/Pz8/Pz8/Pz8/Pz8/PzwEAADDPqSsvdvX09M3G/7LGADEAMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3439 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3412606720 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5607ee07a810, 0x5607ee26401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5607ee264020,0x5607f00fc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3360ea0297cb0909665d5f903e3b2012dad66aa1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4230 processed earlier; will process 6799 files now Step #5: ==123880== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5607e4b6f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5607eb1d4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5607eb1b75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5607eb1b74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5607e4b75d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5607e4ad6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5607e4ad1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5607e4b67c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5607e7b36f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5607e7b36f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5607e7b36f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5607e7b36f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5607e7b36f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5607e7b36f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5607e7b36f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5607e7b36f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5607e7b36f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5607e7b36f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5607e9dcbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5607e6af8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5607e6b03be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5607e68afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5607e68afc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5607e68b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5607e68af874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5607e68af874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5607e68af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5607eb1b9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5607eb1c2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5607eb1aa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5607eb1d5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f216a567082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5607e4acfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x80,0x82,0xe3,0x80,0x86,0xe3,0x80,0x82,0xe3,0x80,0x81,0xe3,0x3c,0x68,0x65,0x61,0x64,0x3e,0x80,0x82,0xe3,0x80,0x81,0x81,0xe3,0x80,0x82,0xe3,0x80,0x86,0xe3,0x80,0x82,0xe3,0x80,0x81,0xe3,0x80,0x83,0xe3,0x80,0xe3,0x80,0x82,0xe3,0x80,0x86,0xe3,0x83,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0xe, Step #5: \343\200\202\343\200\206\343\200\202\343\200\201\343<head>\200\202\343\200\201\201\343\200\202\343\200\206\343\200\202\343\200\201\343\200\203\343\200\343\200\202\343\200\206\343\203\343\200\202\343\200\202\343\016 Step #5: artifact_prefix='./'; Test unit written to ./oom-941f1791f443a93b6214a08b7978172c458c4258 Step #5: Base64: 44CC44CG44CC44CB4zxoZWFkPoCC44CBgeOAguOAhuOAguOAgeOAg+OA44CC44CG44PjgILjgILjDg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3440 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3413091412 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56542a356810, 0x56542a54001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56542a540020,0x56542c3d80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/941f1791f443a93b6214a08b7978172c458c4258' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4231 processed earlier; will process 6798 files now Step #5: #1 pulse cov: 3963 ft: 3964 exec/s: 0 rss: 172Mb Step #5: ==123916== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565420e4b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5654274b0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5654274935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5654274934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565420e51d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565420db2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565420dad355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565420e43c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565423e12f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565423e12f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565423e12f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565423e12f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565423e12f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565423e12f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565423e12f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565423e12f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565423e12f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565423e12f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5654260a7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565422dd4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565422ddfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565422b8bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565422b8bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565422b8c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565422b8b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565422b8b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565422b8b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565427495abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56542749e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565427486699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5654274b1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f381750e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565420dabb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x5c,0x4c,0x4c,0x5c,0x77,0xb1,0xb1,0xb1,0x2d,0x2d,0x31,0x1d,0x33,0x36,0x38,0x35,0x34,0x38,0x34,0x31,0x33,0x34,0x36,0x2a,0x42,0xbf,0xbf,0x65,0x6e,0xa,0xa,0xa,0x61,0x4a, Step #5: LLLLLLLLLLLLLLLLLLLLLLLL\\LL\\w\261\261\261--1\03536854841346*B\277\277en\012\012\012aJ Step #5: artifact_prefix='./'; Test unit written to ./oom-7f1847c231aa885b8adfe1365e76b12a2ba44892 Step #5: Base64: TExMTExMTExMTExMTExMTExMTExMTExMXExMXHexsbEtLTEdMzY4NTQ4NDEzNDYqQr+/ZW4KCgphSg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3441 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3413620761 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56230979d810, 0x56230998701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562309987020,0x56230b81f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f1847c231aa885b8adfe1365e76b12a2ba44892' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4233 processed earlier; will process 6796 files now Step #5: ==123952== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5623002929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5623068f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5623068da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5623068da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562300298d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5623001f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5623001f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56230028ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562303259f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562303259f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562303259f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562303259f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562303259f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562303259f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562303259f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562303259f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562303259f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562303259f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5623054eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56230221bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562302226be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562301fd2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562301fd2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562301fd3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562301fd2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562301fd2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562301fd2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5623068dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5623068e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5623068cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5623068f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb734509082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5623001f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x58,0xc,0x44,0x45,0x46,0x41,0x55,0x4c,0x54,0x28,0x28,0x55,0x4c,0x54,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x57,0x49,0x54,0x48,0x28,0x43,0x4f,0x4c,0x55,0x4d,0x4e,0x53,0x28,0x27,0x77,0x7d,0x45,0x2e,0x7b,0x27,0x29,0x3d,0xa,0x9e, Step #5: \012X\014DEFAULT((ULT(((((((((((((((((((WITH(COLUMNS('w}E.{')=\012\236 Step #5: artifact_prefix='./'; Test unit written to ./oom-3b08e5079107f25fd74bef845ca1434416b91c08 Step #5: Base64: ClgMREVGQVVMVCgoVUxUKCgoKCgoKCgoKCgoKCgoKCgoKFdJVEgoQ09MVU1OUygnd31FLnsnKT0Kng== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3442 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3414107729 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ddd88f810, 0x559ddda7901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ddda79020,0x559ddf9110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3b08e5079107f25fd74bef845ca1434416b91c08' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4234 processed earlier; will process 6795 files now Step #5: #1 pulse cov: 3920 ft: 3921 exec/s: 0 rss: 175Mb Step #5: ==123988== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559dd43849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559dda9e9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559dda9cc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559dda9cc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559dd438ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559dd42ebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559dd42e6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559dd437cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559dd734bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559dd734bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559dd734bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559dd734bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559dd734bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559dd734bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559dd734bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559dd734bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559dd734bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559dd734bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559dd95e0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559dd630db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559dd6318be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559dd60c4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559dd60c4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559dd60c5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559dd60c4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559dd60c4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559dd60c4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559dda9ceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559dda9d7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559dda9bf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559dda9ea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f68354082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559dd42e4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x24,0x2b,0x3d,0xd,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x4,0xc,0xc,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x24,0x3c,0x3c,0xc,0xe2,0xc,0xf3,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x24,0x66,0x3a,0x1a, Step #5: $+=\015,,,,,,,,,,,,,,,,,,\004\014\014<<<<<<<<<<<$<<\014\342\014\363,,,,,,,,,,$f:\032 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb45dab239a243c886009b9562c248bc80062430 Step #5: Base64: ICQrPQ0sLCwsLCwsLCwsLCwsLCwsLCwEDAw8PDw8PDw8PDw8PCQ8PAziDPMsLCwsLCwsLCwsJGY6Gg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3443 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3414642514 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dff8c39810, 0x55dff8e2301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dff8e23020,0x55dffacbb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb45dab239a243c886009b9562c248bc80062430' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4236 processed earlier; will process 6793 files now Step #5: #1 pulse cov: 3732 ft: 3733 exec/s: 0 rss: 175Mb Step #5: ==124024== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dfef72e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dff5d93898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dff5d765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dff5d764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dfef734d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dfef695b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dfef690355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dfef726c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dff26f5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dff26f5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dff26f5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dff26f5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dff26f5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dff26f5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dff26f5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dff26f5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dff26f5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dff26f5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dff498af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dff16b7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dff16c2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dff146ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dff146ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dff146f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dff146e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dff146e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dff146e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dff5d78abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dff5d81928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dff5d69699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dff5d94112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb04582d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dfef68eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x56,0x69,0x73,0x69,0x6f,0x44,0x6f,0x63,0x75,0x6d,0x65,0x6e,0x74,0x3e,0x3c,0x47,0x65,0x6f,0x6d,0x3e,0x3c,0x4e,0x55,0x52,0x42,0x53,0x54,0x6f,0x3e,0x69,0x60,0x3c,0x45,0x3e,0x4e,0x55,0x52,0x42,0x53,0x28,0x34,0x65,0x6f,0x6d,0x60,0x3c,0x45,0x3e,0x4e,0x55,0x52,0x42,0x53,0x36,0x36,0x2d,0x0, Step #5: <VisioDocument><Geom><NURBSTo>i`<E>NURBS(4eom`<E>NURBS66-\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-030cc29125a24d8ad9bc102599d55f48c910aa77 Step #5: Base64: PFZpc2lvRG9jdW1lbnQ+PEdlb20+PE5VUkJTVG8+aWA8RT5OVVJCUyg0ZW9tYDxFPk5VUkJTNjYtAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3444 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3415291937 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf0301d810, 0x55bf0320701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf03207020,0x55bf0509f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/030cc29125a24d8ad9bc102599d55f48c910aa77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4238 processed earlier; will process 6791 files now Step #5: ==124060== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bef9b129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf00177898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf0015a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf0015a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bef9b18d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bef9a79b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bef9a74355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bef9b0ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55befcad9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55befcad9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55befcad9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55befcad9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55befcad9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55befcad9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55befcad9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55befcad9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55befcad9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55befcad9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55befed6ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55befba9bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55befbaa6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55befb852c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55befb852c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55befb853738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55befb852874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55befb852874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55befb852874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf0015cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf00165928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf0014d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf00178112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff9238e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bef9a72b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0xa,0x32,0xb,0x78,0x2e,0xa,0xa,0x78,0x6e,0x2e,0xa,0xa,0x7e,0x78,0x6e,0x62,0x60,0x66,0xa,0xd,0x60,0x66,0x49,0x44,0x2d,0x2d,0x42,0x49,0x45,0x56,0x56,0x4b,0x4d,0x34,0x2c,0xb,0x78,0x2e,0xa,0xa,0x78,0x6e,0x2e,0xa,0xa,0x7e,0x78,0x6e,0x62,0x60,0x66,0xa,0xd,0x60,0x66,0x49,0x44, Step #5: 2\0122\013x.\012\012xn.\012\012~xnb`f\012\015`fID--BIEVVKM4,\013x.\012\012xn.\012\012~xnb`f\012\015`fID Step #5: artifact_prefix='./'; Test unit written to ./oom-7757700bdc0e023b1837bc435b62566b31ec46a4 Step #5: Base64: MgoyC3guCgp4bi4KCn54bmJgZgoNYGZJRC0tQklFVlZLTTQsC3guCgp4bi4KCn54bmJgZgoNYGZJRA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3445 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3415906823 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ddb14e810, 0x562ddb33801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ddb338020,0x562ddd1d00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7757700bdc0e023b1837bc435b62566b31ec46a4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4239 processed earlier; will process 6790 files now Step #5: ==124096== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562dd1c439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562dd82a8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562dd828b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562dd828b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562dd1c49d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562dd1baab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562dd1ba5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562dd1c3bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562dd4c0af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562dd4c0af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562dd4c0af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562dd4c0af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562dd4c0af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562dd4c0af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562dd4c0af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562dd4c0af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562dd4c0af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562dd4c0af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562dd6e9ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562dd3bccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562dd3bd7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562dd3983c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562dd3983c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562dd3984738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562dd3983874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562dd3983874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562dd3983874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562dd828dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562dd8296928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562dd827e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562dd82a9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbd10478082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562dd1ba3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xd,0x6d,0x5b,0x3c,0x21,0x45,0x4c,0x45,0x4d,0x45,0x4e,0x54,0xd,0x45,0xd,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x78,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29, Step #5: <!DOCTYPE\015m[<!ELEMENT\015E\015((((((((((((((((x))))))))))))))))) Step #5: artifact_prefix='./'; Test unit written to ./oom-cf408716ba4a35032b327fa5b408afe06d7f62c8 Step #5: Base64: PCFET0NUWVBFDW1bPCFFTEVNRU5UDUUNKCgoKCgoKCgoKCgoKCgoKHgpKSkpKSkpKSkpKSkpKSkpKQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3446 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3416399035 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ac8dab6810, 0x55ac8dca001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ac8dca0020,0x55ac8fb380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf408716ba4a35032b327fa5b408afe06d7f62c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4240 processed earlier; will process 6789 files now Step #5: ==124132== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ac845ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ac8ac10898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ac8abf35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ac8abf34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ac845b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ac84512b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ac8450d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ac845a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ac87572f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ac87572f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ac87572f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ac87572f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ac87572f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ac87572f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ac87572f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ac87572f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ac87572f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ac87572f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ac89807f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ac86534b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ac8653fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ac862ebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ac862ebc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ac862ec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ac862eb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ac862eb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ac862eb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ac8abf5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ac8abfe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ac8abe6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ac8ac11112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff4a89c7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ac8450bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x68,0x74,0x6d,0x6c,0x3e,0xd,0xa,0x3c,0x67,0x72,0x6f,0x75,0x70,0x3e,0x26,0x23,0x33,0x32,0x3b,0x26,0x23,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x35,0x36,0x30,0x39,0x31,0x39,0x3b,0xca,0xfe,0xba,0x0,0x0,0x0,0x0,0x0,0x31,0x36,0x3b,0x26,0x23,0x31,0xdf,0x30, Step #5: <html>\015\012<group>&#32;&#9223372036854560919;\312\376\272\000\000\000\000\00016;&#1\3370 Step #5: artifact_prefix='./'; Test unit written to ./oom-6304fa9dd31e576b76ff99e4a153e1cc7a68c262 Step #5: Base64: PGh0bWw+DQo8Z3JvdXA+JiMzMjsmIzkyMjMzNzIwMzY4NTQ1NjA5MTk7yv66AAAAAAAxNjsmIzHfMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3447 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3416885733 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e27b313810, 0x55e27b4fd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e27b4fd020,0x55e27d3950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6304fa9dd31e576b76ff99e4a153e1cc7a68c262' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4241 processed earlier; will process 6788 files now Step #5: ==124168== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e271e089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e27846d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e2784505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e2784504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e271e0ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e271d6fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e271d6a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e271e00c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e274dcff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e274dcff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e274dcff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e274dcff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e274dcff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e274dcff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e274dcff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e274dcff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e274dcff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e274dcff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e277064f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e273d91b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e273d9cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e273b48c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e273b48c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e273b49738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e273b48874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e273b48874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e273b48874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e278452abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e27845b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e278443699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e27846e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4451fa4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e271d68b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x0,0x21,0x0,0x44,0x0,0x4f,0x0,0x43,0x0,0x54,0x0,0x59,0x0,0x50,0x0,0x45,0x0,0x20,0x0,0x63,0x0,0x20,0x0,0x50,0x0,0x55,0x0,0x42,0x0,0x4c,0x0,0x49,0x0,0x43,0x0,0x20,0x0,0x27,0x0,0x20,0x0,0x50,0x0,0x55,0x0,0x4c,0x0,0x49,0x0,0x6d,0x0,0x6c,0x0,0x6e,0x0,0x73,0x0, Step #5: <\000!\000D\000O\000C\000T\000Y\000P\000E\000 \000c\000 \000P\000U\000B\000L\000I\000C\000 \000'\000 \000P\000U\000L\000I\000m\000l\000n\000s\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a96ff4edbd79dc6ce1633f835e90368b25dbbbbc Step #5: Base64: PAAhAEQATwBDAFQAWQBQAEUAIABjACAAUABVAEIATABJAEMAIAAnACAAUABVAEwASQBtAGwAbgBzAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3448 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3417371372 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55707abe2810, 0x55707adcc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55707adcc020,0x55707cc640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a96ff4edbd79dc6ce1633f835e90368b25dbbbbc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4242 processed earlier; will process 6787 files now Step #5: ==124204== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5570716d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557077d3c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557077d1f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557077d1f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5570716ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55707163eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557071639355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5570716cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55707469ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55707469ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55707469ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55707469ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55707469ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55707469ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55707469ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55707469ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55707469ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55707469ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557076933f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557073660b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55707366bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557073417c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557073417c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557073418738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557073417874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557073417874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557073417874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557077d21abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557077d2a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557077d12699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557077d3d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f91c9fc3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557071637b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x38,0x42,0x50,0x53,0x0,0x1,0x0,0x2,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x27,0x0,0x8,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x80,0x7d,0xff,0xff,0x20,0x0,0x0,0x0,0xff,0xff,0xff,0xff, Step #5: 8BPS\000\001\000\002\000\000\000\000\000\002\000\000\000\001\000\000\000'\000\010\000\001\000\000\000\000\000\000\000\000\000\000\000\000\000\001\377\377\377\377\377\377\377\200}\377\377 \000\000\000\377\377\377\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-54470346a2a32832783d8b9c50a3c249de54d0cf Step #5: Base64: OEJQUwABAAIAAAAAAAIAAAABAAAAJwAIAAEAAAAAAAAAAAAAAAAAAf////////+Aff//IAAAAP////8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3449 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3417857653 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3cb83e810, 0x55a3cba2801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3cba28020,0x55a3cd8c00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/54470346a2a32832783d8b9c50a3c249de54d0cf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4243 processed earlier; will process 6786 files now Step #5: #1 pulse cov: 3537 ft: 3538 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 3925 ft: 4317 exec/s: 0 rss: 174Mb Step #5: ==124240== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a3c23339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3c8998898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3c897b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3c897b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3c2339d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a3c229ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a3c2295355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3c232bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a3c52faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a3c52faf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a3c52faf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a3c52faf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a3c52faf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a3c52faf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a3c52faf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a3c52faf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a3c52faf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a3c52faf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3c758ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3c42bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3c42c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3c4073c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3c4073c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3c4074738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3c4073874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3c4073874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3c4073874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a3c897dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a3c8986928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3c896e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3c8999112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a944c8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a3c2293b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x21,0x24,0x2d,0x2d,0x30,0x2d,0x2d,0xa,0x3a,0x4e,0x2f,0x21,0x24,0x47,0x2d,0x2d,0x42,0x45,0x47,0x49,0x49,0x49,0x44,0x32,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x42,0x45,0x47,0x49,0x21,0x24,0x2d,0x2d,0x30,0x2d,0x2d,0xa,0x3a,0x4e,0x2f,0x21,0x24,0x3, Step #5: \012-----BEGI!$--0--\012:N/!$G--BEGIIID2\002U -E\012\012BEGI!$--0--\012:N/!$\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-dcd3ef01028e156eec9ba979df8099a66343eaa5 Step #5: Base64: Ci0tLS0tQkVHSSEkLS0wLS0KOk4vISRHLS1CRUdJSUlEMgJVIC1FCgpCRUdJISQtLTAtLQo6Ti8hJAM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3450 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3418428774 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555bc0f54810, 0x555bc113e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555bc113e020,0x555bc2fd60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dcd3ef01028e156eec9ba979df8099a66343eaa5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4246 processed earlier; will process 6783 files now Step #5: #1 pulse cov: 10987 ft: 10988 exec/s: 0 rss: 190Mb Step #5: ==124276== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555bb7a499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555bbe0ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555bbe0915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555bbe0914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555bb7a4fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555bb79b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555bb79ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555bb7a41c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555bbaa10f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555bbaa10f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555bbaa10f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555bbaa10f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555bbaa10f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555bbaa10f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555bbaa10f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555bbaa10f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555bbaa10f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555bbaa10f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555bbcca5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555bb99d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555bb99ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555bb9789c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555bb9789c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555bb978a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555bb9789874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555bb9789874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555bb9789874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555bbe093abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555bbe09c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555bbe084699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555bbe0af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f45af8bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555bb79a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x36,0x2c,0x39,0xa,0x37,0x2c,0x38,0xa,0x36,0x2c,0x37,0xa,0x36,0x2c,0x38,0xa,0x36,0x2c,0x37,0xa,0x36,0x2c,0x39,0xa,0x36,0x2c,0x38,0xa,0x36,0x2c,0x37,0xa,0x36,0x2c,0x39,0xa,0x36,0x2c,0x37,0xa,0x36,0x2c,0x39,0xa,0x36,0x2c,0x37,0xa,0x32,0x2c,0x39,0xa,0x36,0x2c,0x39,0xa,0x30,0x2c,0x33, Step #5: 6,9\0127,8\0126,7\0126,8\0126,7\0126,9\0126,8\0126,7\0126,9\0126,7\0126,9\0126,7\0122,9\0126,9\0120,3 Step #5: artifact_prefix='./'; Test unit written to ./oom-7f8e631aadc055b250a4d9a61adba9bd480f4050 Step #5: Base64: Niw5CjcsOAo2LDcKNiw4CjYsNwo2LDkKNiw4CjYsNwo2LDkKNiw3CjYsOQo2LDcKMiw5CjYsOQowLDM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3451 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3418985733 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55abd7067810, 0x55abd725101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55abd7251020,0x55abd90e90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f8e631aadc055b250a4d9a61adba9bd480f4050' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4248 processed earlier; will process 6781 files now Step #5: #1 pulse cov: 3748 ft: 3749 exec/s: 0 rss: 172Mb Step #5: ==124312== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55abcdb5c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55abd41c1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55abd41a45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55abd41a44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55abcdb62d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55abcdac3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55abcdabe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55abcdb54c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55abd0b23f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55abd0b23f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55abd0b23f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55abd0b23f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55abd0b23f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55abd0b23f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55abd0b23f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55abd0b23f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55abd0b23f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55abd0b23f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55abd2db8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55abcfae5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55abcfaf0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55abcf89cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55abcf89cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55abcf89d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55abcf89c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55abcf89c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55abcf89c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55abd41a6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55abd41af928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55abd4197699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55abd41c2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f34711082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55abcdabcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x33,0x33,0x35,0x22,0xcc,0xaa,0xcc,0xaa,0xcf,0xa0,0x79,0x34,0xcc,0xaa,0xcc,0xaa,0xcc,0xaa,0xcc,0xaa,0xcf,0xa0,0x79,0x37,0xc9,0x88,0xcc,0xaa,0xcc,0xaa,0xcc,0xaa,0xcc,0xaa,0xcc,0xaa,0xcf,0xa0,0x79,0x37,0xc9,0x88,0xcc,0xaa,0xcc,0xaa,0xcc,0xaa,0xcc,0xaa,0xcc,0x1,0x0,0x0,0x0,0x0,0x46, Step #5: HU335\"\314\252\314\252\317\240y4\314\252\314\252\314\252\314\252\317\240y7\311\210\314\252\314\252\314\252\314\252\314\252\317\240y7\311\210\314\252\314\252\314\252\314\252\314\001\000\000\000\000F Step #5: artifact_prefix='./'; Test unit written to ./oom-7be0d2413c4f560623d3da0a4f05ea7b58a2075c Step #5: Base64: SFUzMzUizKrMqs+geTTMqsyqzKrMqs+geTfJiMyqzKrMqsyqzKrPoHk3yYjMqsyqzKrMqswBAAAAAEY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3452 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3419515674 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b205f62810, 0x55b20614c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b20614c020,0x55b207fe40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7be0d2413c4f560623d3da0a4f05ea7b58a2075c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4250 processed earlier; will process 6779 files now Step #5: #1 pulse cov: 3949 ft: 3950 exec/s: 0 rss: 174Mb Step #5: ==124348== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b1fca579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b2030bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b20309f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b20309f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b1fca5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b1fc9beb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b1fc9b9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b1fca4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b1ffa1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b1ffa1ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b1ffa1ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b1ffa1ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b1ffa1ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b1ffa1ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b1ffa1ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b1ffa1ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b1ffa1ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b1ffa1ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b201cb3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b1fe9e0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b1fe9ebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b1fe797c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b1fe797c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b1fe798738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b1fe797874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b1fe797874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b1fe797874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b2030a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b2030aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b203092699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b2030bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd5ce612082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b1fc9b7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x49,0x4d,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1b,0x61,0x30,0x64,0x61,0x20,0x0,0x0,0x0,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0xa6,0xcd,0x9e,0xef,0xfd,0xb9,0x32,0x22, Step #5: ID3IM3\004\342\200\256\004\342\200\256a\342\200\256\004\342\200\256\000\000\000\000\000\000\000\033a0da \000\000\0003\004\342\200\256\004\342\200\256a\342\200\256\246\315\236\357\375\2712\" Step #5: artifact_prefix='./'; Test unit written to ./oom-5827f268fafd4cd4afe1db495a267d03d76e01fe Step #5: Base64: SUQzSU0zBOKArgTigK5h4oCuBOKArgAAAAAAAAAbYTBkYSAAAAAzBOKArgTigK5h4oCups2e7/25MiI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3453 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3420043865 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ded623a810, 0x55ded642401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ded6424020,0x55ded82bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5827f268fafd4cd4afe1db495a267d03d76e01fe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4252 processed earlier; will process 6777 files now Step #5: #1 pulse cov: 3438 ft: 3439 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 3587 ft: 3811 exec/s: 0 rss: 173Mb Step #5: ==124384== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55deccd2f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ded3394898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ded33775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ded33774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55deccd35d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55deccc96b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55deccc91355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55deccd27c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55decfcf6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55decfcf6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55decfcf6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55decfcf6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55decfcf6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55decfcf6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55decfcf6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55decfcf6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55decfcf6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55decfcf6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ded1f8bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dececb8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dececc3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55decea6fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55decea6fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55decea70738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55decea6f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55decea6f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55decea6f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ded3379abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ded3382928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ded336a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ded3395112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6d840f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55deccc8fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x2f,0x31,0x0,0x4,0x44,0x27,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x13,0x60,0x0,0x9,0x69,0x6d,0x61,0x47,0x65,0x2f,0x67,0x69,0x66,0x0,0x5,0x4,0x2f,0x49,0x44,0x30,0x44,0x27,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x18,0x60,0x0,0x9,0x49,0x6d,0x61,0x67,0x65,0x2f,0x67,0x69,0x46, Step #5: ID3\004/1\000\004D'APIC\000\000\000\023`\000\011imaGe/gif\000\005\004/ID0D'APIC\000\000\000\030`\000\011Image/giF Step #5: artifact_prefix='./'; Test unit written to ./oom-ba33586ff92dcf53a243223e59ea50919467422d Step #5: Base64: SUQzBC8xAAREJ0FQSUMAAAATYAAJaW1hR2UvZ2lmAAUEL0lEMEQnQVBJQwAAABhgAAlJbWFnZS9naUY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3454 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3420727151 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5613122ac810, 0x56131249601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561312496020,0x56131432e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba33586ff92dcf53a243223e59ea50919467422d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4255 processed earlier; will process 6774 files now Step #5: ==124420== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561308da19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56130f406898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56130f3e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56130f3e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561308da7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561308d08b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561308d03355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561308d99c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56130bd68f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56130bd68f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56130bd68f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56130bd68f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56130bd68f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56130bd68f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56130bd68f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56130bd68f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56130bd68f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56130bd68f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56130dffdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56130ad2ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56130ad35be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56130aae1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56130aae1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56130aae2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56130aae1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56130aae1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56130aae1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56130f3ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56130f3f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56130f3dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56130f407112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f05cd274082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561308d01b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x39,0x2d,0x31,0x2d,0x30,0x31,0x39,0x3a,0x34,0x3a,0x1,0x0,0x0,0x63,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80, Step #5: 9-1-019:4:\001\000\000c\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-5d4c4c8918640cf1a1403aafacad030247b97ad0 Step #5: Base64: OS0xLTAxOTo0OgEAAGPhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3455 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3421220878 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556a762bf810, 0x556a764a901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556a764a9020,0x556a783410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5d4c4c8918640cf1a1403aafacad030247b97ad0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4256 processed earlier; will process 6773 files now Step #5: ==124456== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556a6cdb49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556a73419898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556a733fc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556a733fc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556a6cdbad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556a6cd1bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556a6cd16355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556a6cdacc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556a6fd7bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556a6fd7bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556a6fd7bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556a6fd7bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556a6fd7bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556a6fd7bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556a6fd7bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556a6fd7bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556a6fd7bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556a6fd7bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556a72010f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556a6ed3db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556a6ed48be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556a6eaf4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556a6eaf4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556a6eaf5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556a6eaf4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556a6eaf4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556a6eaf4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556a733feabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556a73407928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556a733ef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556a7341a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe51594a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556a6cd14b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x39,0x2d,0x31,0x2d,0x30,0x31,0x39,0x3a,0x34,0x3a,0x33,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80, Step #5: 9-1-019:4:3\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-05e8c53373903d045e0d76d844727de695ca4c5c Step #5: Base64: OS0xLTAxOTo0OjPhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3456 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3421706798 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5603aa77d810, 0x5603aa96701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5603aa967020,0x5603ac7ff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/05e8c53373903d045e0d76d844727de695ca4c5c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4257 processed earlier; will process 6772 files now Step #5: #1 pulse cov: 4201 ft: 4202 exec/s: 0 rss: 176Mb Step #5: ==124492== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5603a12729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5603a78d7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5603a78ba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5603a78ba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5603a1278d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5603a11d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5603a11d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5603a126ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5603a4239f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5603a4239f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5603a4239f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5603a4239f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5603a4239f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5603a4239f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5603a4239f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5603a4239f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5603a4239f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5603a4239f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5603a64cef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5603a31fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5603a3206be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5603a2fb2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5603a2fb2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5603a2fb3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5603a2fb2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5603a2fb2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5603a2fb2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5603a78bcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5603a78c5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5603a78ad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5603a78d8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f39fa1a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5603a11d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc, Step #5: \343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-55bbbe53e54449355a1beee8c7010b2e9419a3b4 Step #5: Base64: 442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7w= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3457 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3422240387 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5573e2bca810, 0x5573e2db401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5573e2db4020,0x5573e4c4c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/55bbbe53e54449355a1beee8c7010b2e9419a3b4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4259 processed earlier; will process 6770 files now Step #5: ==124528== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5573d96bf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5573dfd24898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5573dfd075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5573dfd074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5573d96c5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5573d9626b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5573d9621355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5573d96b7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5573dc686f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5573dc686f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5573dc686f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5573dc686f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5573dc686f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5573dc686f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5573dc686f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5573dc686f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5573dc686f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5573dc686f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5573de91bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5573db648b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5573db653be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5573db3ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5573db3ffc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5573db400738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5573db3ff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5573db3ff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5573db3ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5573dfd09abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5573dfd12928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5573dfcfa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5573dfd25112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc8c6b76082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5573d961fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x63,0x78,0x3e,0x3c,0x63,0x78,0x3e,0x3c,0x63,0x78,0x3e,0x3c,0x63,0x78,0x3e,0x3c,0x63,0x78,0x3e,0x3c,0x63,0x78,0x3e,0x3c,0x63,0x78,0x3e,0x3c,0x63,0x65,0x78,0x74,0x3e,0x3c,0x63,0x65,0x78,0x74,0x3e,0x3c,0x63,0x78,0x3e,0x3c,0x63,0x78,0x3e,0x3c,0x63,0x78,0x3e,0x3c,0x63,0x65,0x78,0x74,0x3e,0x3a,0xbf, Step #5: <cx><cx><cx><cx><cx><cx><cx><cext><cext><cx><cx><cx><cext>:\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-56c3fd480f48591bc0f7ecff19bbc1237ff9d2f0 Step #5: Base64: PGN4PjxjeD48Y3g+PGN4PjxjeD48Y3g+PGN4PjxjZXh0PjxjZXh0PjxjeD48Y3g+PGN4PjxjZXh0Pjq/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3458 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3422725916 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b1e264b810, 0x55b1e283501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b1e2835020,0x55b1e46cd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56c3fd480f48591bc0f7ecff19bbc1237ff9d2f0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4260 processed earlier; will process 6769 files now Step #5: ==124564== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b1d91409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b1df7a5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1df7885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1df7884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b1d9146d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b1d90a7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b1d90a2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b1d9138c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b1dc107f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b1dc107f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b1dc107f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b1dc107f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b1dc107f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b1dc107f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b1dc107f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b1dc107f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b1dc107f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b1dc107f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b1de39cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b1db0c9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b1db0d4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b1dae80c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b1dae80c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b1dae81738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b1dae80874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b1dae80874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b1dae80874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b1df78aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b1df793928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b1df77b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b1df7a6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9535f7c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b1d90a0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $22-=<'''/''''/''''/''''''2-=''''''''''2-='''''''''''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-4fb7d1f80a90638e3c301e9625e2a9dca64b298a Step #5: Base64: JDIyLT08JycnLycnJycvJycnJy8nJycnJycyLT0nJycnJycnJycnMi09JycnJycnJycnJycnJy4nJCct Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3459 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3423222413 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563150ef7810, 0x5631510e101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5631510e1020,0x563152f790e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4fb7d1f80a90638e3c301e9625e2a9dca64b298a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4261 processed earlier; will process 6768 files now Step #5: #1 pulse cov: 3711 ft: 3712 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 4013 ft: 4434 exec/s: 0 rss: 175Mb Step #5: ==124600== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5631479ec9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56314e051898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56314e0345dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56314e0344fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5631479f2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563147953b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56314794e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5631479e4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56314a9b3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56314a9b3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56314a9b3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56314a9b3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56314a9b3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56314a9b3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56314a9b3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56314a9b3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56314a9b3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56314a9b3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56314cc48f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563149975b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563149980be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56314972cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56314972cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56314972d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56314972c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56314972c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56314972c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56314e036abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56314e03f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56314e027699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56314e052112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb4ea5d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56314794cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x39,0x3b,0x39,0x3d,0x39,0x0,0x0,0x60,0x2d,0x2d,0x2d,0x2d,0x39,0x3d,0x39,0x0,0x0,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x0,0x0,0x9,0x4e,0x20,0x0,0x2d,0x0,0x25,0x0,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x0,0x0,0x9,0x4e,0x20,0x0,0x2d,0x0,0x25,0x0,0x2d,0x2d,0x0, Step #5: \333\200\333\20099;9=9\000\000`----9=9\000\000`-----BEG\000\000\011N \000-\000%\000---BEG\000\000\011N \000-\000%\000--\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f251fda9124e0585c4dde70d9f93898c472a80e4 Step #5: Base64: 24DbgDk5Ozk9OQAAYC0tLS05PTkAAGAtLS0tLUJFRwAACU4gAC0AJQAtLS1CRUcAAAlOIAAtACUALS0A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3460 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3423947262 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dbd3cf8810, 0x55dbd3ee201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dbd3ee2020,0x55dbd5d7a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f251fda9124e0585c4dde70d9f93898c472a80e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4265 processed earlier; will process 6764 files now Step #5: #1 pulse cov: 3842 ft: 3843 exec/s: 0 rss: 174Mb Step #5: ==124636== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dbca7ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dbd0e52898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dbd0e355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dbd0e354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dbca7f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dbca754b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dbca74f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dbca7e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dbcd7b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dbcd7b4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dbcd7b4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dbcd7b4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dbcd7b4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dbcd7b4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dbcd7b4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dbcd7b4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dbcd7b4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dbcd7b4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dbcfa49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dbcc776b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dbcc781be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dbcc52dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dbcc52dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dbcc52e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dbcc52d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dbcc52d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dbcc52d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dbd0e37abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dbd0e40928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dbd0e28699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dbd0e53112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f91647f4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dbca74db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x60,0xa,0x9,0xa,0x60,0x2d,0x0,0x60,0x65,0x72,0x69,0x66,0x60,0x20,0x20,0x20,0x60,0xa,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0xf3,0xa0,0x80,0xa4,0x68,0x11,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x9, Step #5: ``\012\011\012`-\000`erif` `\012hhhhhhhhhhhhhhhhhhhhhhhh\363\240\200\244h\021hhhhhhhhhh\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-844513f66c883dd1e6958c70a5ef2c32150556b2 Step #5: Base64: YGAKCQpgLQBgZXJpZmAgICBgCmhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaPOggKRoEWhoaGhoaGhoaGgJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3461 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3424602360 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca76097810, 0x55ca7628101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca76281020,0x55ca781190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/844513f66c883dd1e6958c70a5ef2c32150556b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4267 processed earlier; will process 6762 files now Step #5: ==124672== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ca6cb8c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca731f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca731d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca731d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca6cb92d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca6caf3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca6caee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca6cb84c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca6fb53f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca6fb53f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca6fb53f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca6fb53f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca6fb53f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca6fb53f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca6fb53f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca6fb53f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca6fb53f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca6fb53f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca71de8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca6eb15b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca6eb20be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca6e8ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca6e8ccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca6e8cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca6e8cc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca6e8cc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca6e8cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca731d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca731df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca731c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca731f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3def856082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca6caecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xaa,0xa9,0xaa,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xa9,0xaa,0xaa,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xae,0xf2,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xba,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xa2,0xaa,0xf3,0xaa,0xa8,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0x88, Step #5: \363\252\251\252\363\252\252\256\363\252\252\252\363\251\252\252\363\252\252\256\363\252\252\252\363\252\252\256\362\252\252\252\363\252\252\272\363\252\252\256\363\252\252\256\363\252\242\252\363\252\250\256\363\252\252\252\363\252\252\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-a109eaefff1507f9a134774045b232796060eb19 Step #5: Base64: 86qpqvOqqq7zqqqq86mqqvOqqq7zqqqq86qqrvKqqqrzqqq686qqrvOqqq7zqqKq86qorvOqqqrzqqqI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3462 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3425089821 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c75da2810, 0x559c75f8c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c75f8c020,0x559c77e240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a109eaefff1507f9a134774045b232796060eb19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4268 processed earlier; will process 6761 files now Step #5: ==124708== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559c6c8979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c72efc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c72edf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c72edf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c6c89dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c6c7feb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c6c7f9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c6c88fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c6f85ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c6f85ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c6f85ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c6f85ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c6f85ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c6f85ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c6f85ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c6f85ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c6f85ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c6f85ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c71af3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c6e820b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c6e82bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c6e5d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c6e5d7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c6e5d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c6e5d7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c6e5d7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c6e5d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c72ee1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c72eea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c72ed2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c72efd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f219d116082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c6c7f7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0xa,0x34,0x20,0x30,0x20,0x6f,0x62,0x6a,0x5b,0x31,0x32,0x20,0x30,0x20,0x52,0x20,0x32,0x20,0x30,0x20,0x52,0x20,0x31,0x33,0x20,0x30,0x20,0x52,0x20,0x31,0x34,0x20,0x30,0x20,0x52,0x20,0x31,0x35,0x20,0x30,0x20,0x52,0x20,0x31,0x37,0x20,0x30,0x20,0x52,0x20,0x30,0x20,0x31,0x39,0x20,0x30,0x20,0x52,0x20, Step #5: %\0124 0 obj[12 0 R 2 0 R 13 0 R 14 0 R 15 0 R 17 0 R 0 19 0 R Step #5: artifact_prefix='./'; Test unit written to ./oom-713f4f4ac900fe3747c93c5315a0cacda86eeff0 Step #5: Base64: JQo0IDAgb2JqWzEyIDAgUiAyIDAgUiAxMyAwIFIgMTQgMCBSIDE1IDAgUiAxNyAwIFIgMCAxOSAwIFIg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3463 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3425578616 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563b97311810, 0x563b974fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563b974fb020,0x563b993930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/713f4f4ac900fe3747c93c5315a0cacda86eeff0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4269 processed earlier; will process 6760 files now Step #5: ==124744== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563b8de069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563b9446b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563b9444e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563b9444e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563b8de0cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563b8dd6db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563b8dd68355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563b8ddfec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563b90dcdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563b90dcdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563b90dcdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563b90dcdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563b90dcdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563b90dcdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563b90dcdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563b90dcdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563b90dcdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563b90dcdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563b93062f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563b8fd8fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563b8fd9abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563b8fb46c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563b8fb46c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563b8fb47738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563b8fb46874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563b8fb46874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563b8fb46874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563b94450abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563b94459928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563b94441699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563b9446c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb371322082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563b8dd66b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0xd,0x9,0x21,0x2d,0xa,0xd,0x2d,0xa,0xd,0x9,0x21,0x2d,0xa,0x9,0x21,0x2d,0xa,0xd,0x9,0x2d,0xa,0xd,0x9,0x21,0x2d,0xa,0xd,0x9,0x21,0x2d,0xa,0x9,0x21,0x2d,0xa,0xd,0x9,0x2d,0xa,0xd,0x9,0x21,0x2d,0xa,0xd,0x9,0x21,0x2d,0xa,0x9,0x21,0x2d,0xd,0x9,0x2d,0xa,0xd,0x9, Step #5: -\012\015\011!-\012\015-\012\015\011!-\012\011!-\012\015\011-\012\015\011!-\012\015\011!-\012\011!-\012\015\011-\012\015\011!-\012\015\011!-\012\011!-\015\011-\012\015\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-16ad68ebd3973ae63da9f48084ef223eb6b65fab Step #5: Base64: LQoNCSEtCg0tCg0JIS0KCSEtCg0JLQoNCSEtCg0JIS0KCSEtCg0JLQoNCSEtCg0JIS0KCSEtDQktCg0J Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3464 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3426074038 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5556036d6810, 0x5556038c001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5556038c0020,0x5556057580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16ad68ebd3973ae63da9f48084ef223eb6b65fab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4270 processed earlier; will process 6759 files now Step #5: ==124780== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5555fa1cb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555600830898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556008135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556008134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5555fa1d1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5555fa132b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5555fa12d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5555fa1c3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5555fd192f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5555fd192f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5555fd192f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5555fd192f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5555fd192f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5555fd192f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5555fd192f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5555fd192f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5555fd192f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5555fd192f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5555ff427f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5555fc154b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5555fc15fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5555fbf0bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5555fbf0bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5555fbf0c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5555fbf0b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5555fbf0b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5555fbf0b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555600815abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55560081e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555600806699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555600831112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f240fec7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5555fa12bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20, Step #5: !\015- - - - - - - - - - - - - - - - - - - - - - - - - - - - - Step #5: artifact_prefix='./'; Test unit written to ./oom-fc8c6a37ffeb2d9f8262b515c4010620a2c46640 Step #5: Base64: IQ0tIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0g Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3465 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3426631091 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a29ac9810, 0x560a29cb301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a29cb3020,0x560a2bb4b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc8c6a37ffeb2d9f8262b515c4010620a2c46640' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4271 processed earlier; will process 6758 files now Step #5: #1 pulse cov: 3912 ft: 3913 exec/s: 0 rss: 173Mb Step #5: ==124816== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560a205be9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a26c23898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a26c065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a26c064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a205c4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a20525b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a20520355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a205b6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a23585f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a23585f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a23585f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a23585f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a23585f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a23585f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a23585f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a23585f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a23585f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a23585f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a2581af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a22547b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a22552be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a222fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a222fec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a222ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a222fe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a222fe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a222fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a26c08abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a26c11928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a26bf9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a26c24112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa2c9094082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a2051eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf2,0xa0,0x8f,0x88,0xf4,0x83,0x80,0xa9,0xf4,0x89,0x80,0x93,0xf3,0xa0,0x87,0x87,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0xa9,0xf4,0x87,0xaa,0x93,0xf3,0xa0,0x88,0x99,0xf0,0xb5,0xa0,0x8e,0xf4,0x84,0x87,0x88,0xf3,0xa0,0x81,0xa1,0xf4,0x83,0x80,0x9f,0xf3,0xa1,0xa0,0x99,0xf0,0xb5,0x87,0x88,0xf4,0x87,0x88,0x83,0xf3, Step #5: \362\240\217\210\364\203\200\251\364\211\200\223\363\240\207\207\364\203\200\251\364\207\200\251\364\207\252\223\363\240\210\231\360\265\240\216\364\204\207\210\363\240\201\241\364\203\200\237\363\241\240\231\360\265\207\210\364\207\210\203\363 Step #5: artifact_prefix='./'; Test unit written to ./oom-64ffe5ee3a3b0fef98526c20e16e116b6aa7a410 Step #5: Base64: 8qCPiPSDgKn0iYCT86CHh/SDgKn0h4Cp9Ieqk/OgiJnwtaCO9ISHiPOggaH0g4Cf86GgmfC1h4j0h4iD8w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3466 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3427160460 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559331e4c810, 0x55933203601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559332036020,0x559333ece0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/64ffe5ee3a3b0fef98526c20e16e116b6aa7a410' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4273 processed earlier; will process 6756 files now Step #5: ==124852== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5593289419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55932efa6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55932ef895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55932ef894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559328947d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5593288a8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5593288a3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559328939c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55932b908f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55932b908f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55932b908f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55932b908f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55932b908f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55932b908f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55932b908f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55932b908f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55932b908f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55932b908f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55932db9df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55932a8cab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55932a8d5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55932a681c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55932a681c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55932a682738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55932a681874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55932a681874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55932a681874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55932ef8babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55932ef94928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55932ef7c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55932efa7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8064c14082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5593288a1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2a,0x0,0x2a,0x0,0x2a,0x2d,0x2a,0x0,0x2a,0x7e,0x2a,0x0,0x2a,0x2d,0x2a,0x0,0x2a,0x2d,0x2a,0x0,0x2a,0x2e,0x2a,0x0,0x2a,0x24,0x2a,0x0,0x2a,0x0,0x2a,0x24,0x2a,0x0,0x2a,0x0,0x2a,0x24,0x2a,0x0,0x2a,0x0,0x2a,0x24,0x2a,0x0,0x2a,0x0,0x2a,0x24,0x2a,0x0,0x2a,0x0,0x2a,0x24,0x2a,0x0,0x2a,0x2a, Step #5: -*\000*\000*-*\000*~*\000*-*\000*-*\000*.*\000*$*\000*\000*$*\000*\000*$*\000*\000*$*\000*\000*$*\000*\000*$*\000** Step #5: artifact_prefix='./'; Test unit written to ./oom-2b325e4eef6361ba7b480c5926d2d9dc12a754ca Step #5: Base64: LSoAKgAqLSoAKn4qACotKgAqLSoAKi4qACokKgAqACokKgAqACokKgAqACokKgAqACokKgAqACokKgAqKg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3467 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3427656355 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5566f26b9810, 0x5566f28a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5566f28a3020,0x5566f473b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2b325e4eef6361ba7b480c5926d2d9dc12a754ca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4274 processed earlier; will process 6755 files now Step #5: ==124888== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5566e91ae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5566ef813898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5566ef7f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5566ef7f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5566e91b4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5566e9115b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5566e9110355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5566e91a6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5566ec175f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5566ec175f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5566ec175f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5566ec175f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5566ec175f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5566ec175f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5566ec175f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5566ec175f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5566ec175f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5566ec175f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5566ee40af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5566eb137b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5566eb142be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5566eaeeec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5566eaeeec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5566eaeef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5566eaeee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5566eaeee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5566eaeee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5566ef7f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5566ef801928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5566ef7e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5566ef814112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2568192082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5566e910eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0xa0,0xf3,0xbf,0xbf,0xb6,0xed,0x9f,0xbd,0x0,0xa,0xa,0x30,0x31,0x30,0x0,0x27,0x0,0x5c,0xf3,0xa0,0x85,0x9f,0x26,0x27,0x30,0x30,0x30,0x30,0x30,0x30,0x0,0x10,0x30,0x30,0x30,0x69,0x73,0x6f,0x32,0x30,0x32,0xf3,0xbf,0xbf,0xb2,0xed,0x9f,0xbd,0x0,0xa,0xa,0x30,0x30,0x30,0x30,0x20,0x3b,0x30,0x30,0x30, Step #5: \302\240\363\277\277\266\355\237\275\000\012\012010\000'\000\\\363\240\205\237&'000000\000\020000iso202\363\277\277\262\355\237\275\000\012\0120000 ;000 Step #5: artifact_prefix='./'; Test unit written to ./oom-966053683af11ef5684cdd26a38c078e965e909c Step #5: Base64: wqDzv7+27Z+9AAoKMDEwACcAXPOghZ8mJzAwMDAwMAAQMDAwaXNvMjAy87+/su2fvQAKCjAwMDAgOzAwMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3468 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3428145894 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b89c55810, 0x556b89e3f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b89e3f020,0x556b8bcd70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/966053683af11ef5684cdd26a38c078e965e909c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4275 processed earlier; will process 6754 files now Step #5: #1 pulse cov: 3750 ft: 3751 exec/s: 0 rss: 173Mb Step #5: ==124924== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556b8074a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b86daf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b86d925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b86d924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b80750d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b806b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b806ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b80742c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b83711f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b83711f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b83711f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b83711f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b83711f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b83711f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b83711f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b83711f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b83711f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b83711f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b859a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b826d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b826debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b8248ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b8248ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b8248b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b8248a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b8248a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b8248a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b86d94abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b86d9d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b86d85699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b86db0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f825fea2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b806aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0x95,0xd9,0x8b,0xd9,0x98,0x20,0xd9,0x90,0xd9,0x95,0xd9,0x8b,0xd9,0x98,0x20,0xd9,0x90,0xd9,0x95,0xdd,0x95,0xd9,0x8b,0xd9,0x98,0x20,0xd9,0x90,0xd9,0x95,0xd9,0x8b,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e,0x27,0x3c,0x2f, Step #5: <svg><text>\331\225\331\213\331\230 \331\220\331\225\331\213\331\230 \331\220\331\225\335\225\331\213\331\230 \331\220\331\225\331\213'</text></svg>'</ Step #5: artifact_prefix='./'; Test unit written to ./oom-50f5bfcb638a76e7b9bd3cb58beaee8ee4288dd7 Step #5: Base64: PHN2Zz48dGV4dD7ZldmL2Zgg2ZDZldmL2Zgg2ZDZld2V2YvZmCDZkNmV2YsnPC90ZXh0Pjwvc3ZnPic8Lw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3469 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3428675117 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56335c271810, 0x56335c45b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56335c45b020,0x56335e2f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/50f5bfcb638a76e7b9bd3cb58beaee8ee4288dd7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4277 processed earlier; will process 6752 files now Step #5: ==124960== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563352d669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5633593cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5633593ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5633593ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563352d6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563352ccdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563352cc8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563352d5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563355d2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563355d2df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563355d2df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563355d2df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563355d2df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563355d2df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563355d2df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563355d2df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563355d2df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563355d2df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563357fc2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563354cefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563354cfabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563354aa6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563354aa6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563354aa7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563354aa6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563354aa6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563354aa6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5633593b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5633593b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5633593a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5633593cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f49d0ba9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563352cc6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x6f,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0xe2,0x81,0x9f,0x75,0x75,0x75,0x6f,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0xe3,0x81,0x9f,0x75,0x75,0x75,0x6f,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0xe2,0x81,0x9f,0x75,0x75,0x75,0xf3,0xa0,0x81,0xbf,0x75,0x75,0xe2,0x80,0x81,0x75,0x75,0x75,0x73,0x74,0x21, Step #5: pouuuuuuuu\342\201\237uuuouuuuuuuu\343\201\237uuuouuuuuuuu\342\201\237uuu\363\240\201\277uu\342\200\201uuust! Step #5: artifact_prefix='./'; Test unit written to ./oom-eff20cffcda9d57e0ee5ed8aafcf8efaab8a0a46 Step #5: Base64: cG91dXV1dXV1deKBn3V1dW91dXV1dXV1deOBn3V1dW91dXV1dXV1deKBn3V1dfOggb91deKAgXV1dXN0IQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3470 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3429164529 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558cff2ac810, 0x558cff49601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558cff496020,0x558d0132e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eff20cffcda9d57e0ee5ed8aafcf8efaab8a0a46' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4278 processed earlier; will process 6751 files now Step #5: #1 pulse cov: 3887 ft: 3888 exec/s: 0 rss: 175Mb Step #5: ==124996== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558cf5da19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558cfc406898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558cfc3e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558cfc3e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558cf5da7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558cf5d08b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558cf5d03355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558cf5d99c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558cf8d68f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558cf8d68f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558cf8d68f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558cf8d68f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558cf8d68f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558cf8d68f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558cf8d68f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558cf8d68f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558cf8d68f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558cf8d68f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558cfaffdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558cf7d2ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558cf7d35be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558cf7ae1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558cf7ae1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558cf7ae2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558cf7ae1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558cf7ae1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558cf7ae1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558cfc3ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558cfc3f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558cfc3dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558cfc407112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3a455b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558cf5d01b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0xcd,0x8f,0xcd,0x9f,0xcd,0x84,0xcd,0x84,0xcd,0x81,0xcd,0x9f,0xcd,0x9f,0xcd,0x9f,0xcd,0x9f,0xcd,0x9f,0xcd,0x9f,0xcd,0x9f,0xcd,0x9f,0xcd,0x9f,0xcd,0x84,0xcd,0x81,0xcd,0x9f,0xcd,0x9f,0xcd,0x9f,0xcd,0x9f,0xcd,0x9f,0xcd,0x9f,0xcd,0x9f,0xcd,0x9f,0xcd,0x84,0xcd,0x81,0xcd,0x9f,0xcd,0x8b,0xcd,0x9f,0xcd,0x84, Step #5: D\315\217\315\237\315\204\315\204\315\201\315\237\315\237\315\237\315\237\315\237\315\237\315\237\315\237\315\237\315\204\315\201\315\237\315\237\315\237\315\237\315\237\315\237\315\237\315\237\315\204\315\201\315\237\315\213\315\237\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-176398e80507a92524fc6b81249e3cfe14aafc96 Step #5: Base64: RM2PzZ/NhM2EzYHNn82fzZ/Nn82fzZ/Nn82fzZ/NhM2BzZ/Nn82fzZ/Nn82fzZ/Nn82EzYHNn82LzZ/NhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3471 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3429692407 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556ec28dd810, 0x556ec2ac701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556ec2ac7020,0x556ec495f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/176398e80507a92524fc6b81249e3cfe14aafc96' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4280 processed earlier; will process 6749 files now Step #5: #1 pulse cov: 10944 ft: 10945 exec/s: 0 rss: 192Mb Step #5: #2 pulse cov: 11651 ft: 12496 exec/s: 0 rss: 194Mb Step #5: ==125032== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556eb93d29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556ebfa37898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556ebfa1a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556ebfa1a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556eb93d8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556eb9339b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556eb9334355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556eb93cac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556ebc399f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556ebc399f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556ebc399f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556ebc399f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556ebc399f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556ebc399f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556ebc399f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556ebc399f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556ebc399f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556ebc399f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556ebe62ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556ebb35bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556ebb366be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556ebb112c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556ebb112c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556ebb113738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556ebb112874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556ebb112874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556ebb112874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556ebfa1cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556ebfa25928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556ebfa0d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556ebfa38112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1b1e591082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556eb9332b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x65,0x74,0x6e,0x61,0x3e,0x3c,0x65,0x74,0x61,0x6e,0x3e,0x3c,0x65,0x6e,0x74,0x72,0x79,0x3e,0x3c,0x65,0x6e,0x74,0x72,0x79,0x3e,0x3c,0x6e,0x70,0x72,0x72,0x6e,0x72,0x79,0x3e,0x3c,0x65,0x6e,0x74,0x72,0x79,0x3e,0x6e,0x72,0x79,0x3e,0x6a,0x3c,0x6f,0x72,0x79,0x3e,0x3c,0x65,0x6e,0x6a,0x72,0x79,0x72,0x79,0x3e, Step #5: <etna><etan><entry><entry><nprrnry><entry>nry>j<ory><enjryry> Step #5: artifact_prefix='./'; Test unit written to ./oom-8ab700b63aadb2ec3b8e56f601de77e8f21177fa Step #5: Base64: PGV0bmE+PGV0YW4+PGVudHJ5PjxlbnRyeT48bnBycm5yeT48ZW50cnk+bnJ5Pmo8b3J5PjxlbmpyeXJ5Pg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3472 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3430317066 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556253c26810, 0x556253e1001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556253e10020,0x556255ca80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ab700b63aadb2ec3b8e56f601de77e8f21177fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4283 processed earlier; will process 6746 files now Step #5: ==125068== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55624a71b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556250d80898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556250d635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556250d634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55624a721d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55624a682b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55624a67d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55624a713c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55624d6e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55624d6e2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55624d6e2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55624d6e2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55624d6e2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55624d6e2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55624d6e2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55624d6e2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55624d6e2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55624d6e2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55624f977f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55624c6a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55624c6afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55624c45bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55624c45bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55624c45c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55624c45b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55624c45b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55624c45b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556250d65abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556250d6e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556250d56699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556250d81112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f51e4cbc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55624a67bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x81,0x95,0x63,0xc2,0xb7,0xe2,0xa1,0xaa,0xd,0xf3,0xa0,0x81,0xa5,0x31,0x37,0x30,0x31,0xf3,0xa0,0x81,0x89,0x34,0x31,0x31,0x38,0x33,0x34,0x36,0x30,0x34,0x36,0x39,0x32,0x33,0x31,0x37,0x33,0x31,0x36,0x38,0xf9,0x33,0x30,0x33,0x37,0x31,0x35,0x38,0x38,0x34,0x31,0x30,0x35,0x37,0x33,0x33,0xcb,0x91,0x0, Step #5: \363\240\201\225c\302\267\342\241\252\015\363\240\201\2451701\363\240\201\2114118346046923173168\371303715884105733\313\221\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3a4feab92d4c733fd770aa2520a5ef9b69260e35 Step #5: Base64: 86CBlWPCt+Khqg3zoIGlMTcwMfOggYk0MTE4MzQ2MDQ2OTIzMTczMTY4+TMwMzcxNTg4NDEwNTczM8uRAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3473 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3430805522 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b7eabb810, 0x556b7eca501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b7eca5020,0x556b80b3d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a4feab92d4c733fd770aa2520a5ef9b69260e35' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4284 processed earlier; will process 6745 files now Step #5: #1 pulse cov: 3724 ft: 3725 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 3870 ft: 4078 exec/s: 0 rss: 174Mb Step #5: #4 pulse cov: 4406 ft: 5249 exec/s: 0 rss: 176Mb Step #5: ==125104== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556b755b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b7bc15898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b7bbf85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b7bbf84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b755b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b75517b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b75512355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b755a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b78577f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b78577f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b78577f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b78577f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b78577f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b78577f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b78577f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b78577f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b78577f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b78577f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b7a80cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b77539b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b77544be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b772f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b772f0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b772f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b772f0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b772f0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b772f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b7bbfaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b7bc03928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b7bbeb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b7bc16112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb87b26082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b75510b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0x37,0xfe,0x39, Step #5: \333\201\333\20042\333\201\333\20042\333\201\333\20042\333\201\333\20042\333\201\333\20042\333\201\333\20042\333\201\333\20042\333\201\333\20042\333\201\333\20042949677\3769 Step #5: artifact_prefix='./'; Test unit written to ./oom-b304df0248035ac27c3e2e395fb07ffc848a432f Step #5: Base64: 24HbgDQy24HbgDQy24HbgDQy24HbgDQy24HbgDQy24HbgDQy24HbgDQy24HbgDQy24HbgDQyOTQ5Njc3/jk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3474 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3431474337 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bd4e0ea810, 0x55bd4e2d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bd4e2d4020,0x55bd5016c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b304df0248035ac27c3e2e395fb07ffc848a432f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4290 processed earlier; will process 6739 files now Step #5: #1 pulse cov: 3773 ft: 3774 exec/s: 0 rss: 174Mb Step #5: ==125140== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bd44bdf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bd4b244898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bd4b2275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bd4b2274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bd44be5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bd44b46b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bd44b41355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bd44bd7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bd47ba6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bd47ba6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bd47ba6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bd47ba6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bd47ba6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bd47ba6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bd47ba6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bd47ba6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bd47ba6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bd47ba6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bd49e3bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bd46b68b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bd46b73be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bd4691fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bd4691fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bd46920738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bd4691f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bd4691f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bd4691f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bd4b229abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bd4b232928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bd4b21a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bd4b245112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f216f623082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bd44b3fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x50,0x2f,0x2f,0x2f,0x2f,0x9,0x64,0x50,0x50,0x50,0x50,0x50,0x0,0xc,0xc,0xc,0x15,0xc,0x14,0x43,0x46,0x46,0xb,0x0,0x20,0x13,0x60,0x1f,0x0,0x0,0x0,0x74,0x4e,0xf1,0xca,0x0,0x21,0x78,0x63,0x61,0x6c,0x63,0x5c,0x78,0x30,0x61,0x25,0x6e,0x26,0x23,0x38,0x35,0x38,0x39,0x39,0x33,0x34,0x35,0x39,0x34,0x3b, Step #5: `P////\011dPPPPP\000\014\014\014\025\014\024CFF\013\000 \023`\037\000\000\000tN\361\312\000!xcalc\\x0a%n&#8589934594; Step #5: artifact_prefix='./'; Test unit written to ./oom-369bdeda5cc1e5e612272352198426f0c527cc9c Step #5: Base64: YFAvLy8vCWRQUFBQUAAMDAwVDBRDRkYLACATYB8AAAB0TvHKACF4Y2FsY1x4MGElbiYjODU4OTkzNDU5NDs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3475 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3432132414 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56425945b810, 0x56425964501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564259645020,0x56425b4dd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/369bdeda5cc1e5e612272352198426f0c527cc9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4292 processed earlier; will process 6737 files now Step #5: #1 pulse cov: 3787 ft: 3788 exec/s: 0 rss: 173Mb Step #5: ==125176== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56424ff509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5642565b5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5642565985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5642565984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56424ff56d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56424feb7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56424feb2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56424ff48c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564252f17f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564252f17f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564252f17f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564252f17f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564252f17f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564252f17f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564252f17f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564252f17f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564252f17f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564252f17f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5642551acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564251ed9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564251ee4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564251c90c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564251c90c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564251c91738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564251c90874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564251c90874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564251c90874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56425659aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5642565a3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56425658b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5642565b6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc6fd48c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56424feb0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x30,0x2d,0x9,0x5,0x47,0x4b,0x60,0x20,0x21,0x21,0x0,0x73,0xa,0x20,0x20,0x2f,0x43,0x2d,0x2d,0x2d,0x2d,0x42,0x6f,0x6c,0x61,0x63,0x6b,0x45,0x47,0x49,0x40,0x1,0xc,0x20,0x2d,0x2d,0x7a,0x5b,0x2d,0x45,0x47,0x4b,0x60,0x20,0x2d,0x0,0x1f,0x18,0x18,0x21,0x0,0x0,0x2d,0x2d,0x42,0x45,0x47,0x49, Step #5: s---0-\011\005GK` !!\000s\012 /C----BolackEGI@\001\014 --z[-EGK` -\000\037\030\030!\000\000--BEGI Step #5: artifact_prefix='./'; Test unit written to ./oom-9f5022d8798ccc9d13ae4c531e905a49e40ff577 Step #5: Base64: cy0tLTAtCQVHS2AgISEAcwogIC9DLS0tLUJvbGFja0VHSUABDCAtLXpbLUVHS2AgLQAfGBghAAAtLUJFR0k= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3476 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3432785250 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5593d77f0810, 0x5593d79da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5593d79da020,0x5593d98720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f5022d8798ccc9d13ae4c531e905a49e40ff577' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4294 processed earlier; will process 6735 files now Step #5: ==125212== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5593ce2e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5593d494a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5593d492d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5593d492d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5593ce2ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5593ce24cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5593ce247355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5593ce2ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5593d12acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5593d12acf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5593d12acf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5593d12acf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5593d12acf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5593d12acf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5593d12acf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5593d12acf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5593d12acf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5593d12acf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5593d3541f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5593d026eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5593d0279be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5593d0025c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5593d0025c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5593d0026738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5593d0025874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5593d0025874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5593d0025874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5593d492fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5593d4938928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5593d4920699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5593d494b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f43b07fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5593ce245b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0x7b,0x22,0x34,0x34,0x22,0x3a,0x20,0x34,0x2c,0x22,0x6d,0x46,0x6d,0x30,0x22,0x3a,0x2d,0x38,0x2c,0x22,0x74,0x34,0x3a,0xd6,0x89,0x22,0x3a,0x20,0x34,0x2c,0x22,0x6c,0x3d,0x6d,0x30,0x22,0x3a,0x2d,0x38,0x2c,0x22,0xd6,0x89,0x22,0x3a,0x20,0x38,0x2c,0x22,0xd6,0x89,0x6d,0x32,0x22,0x3a,0x34,0x35,0x38,0x7d,0xa, Step #5: \012\012{\"44\": 4,\"mFm0\":-8,\"t4:\326\211\": 4,\"l=m0\":-8,\"\326\211\": 8,\"\326\211m2\":458}\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-2650cba16875e36255a5102fba2edf57bc326e02 Step #5: Base64: Cgp7IjQ0IjogNCwibUZtMCI6LTgsInQ0OtaJIjogNCwibD1tMCI6LTgsItaJIjogOCwi1oltMiI6NDU4fQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3477 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3433271940 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5560a7440810, 0x5560a762a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5560a762a020,0x5560a94c20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2650cba16875e36255a5102fba2edf57bc326e02' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4295 processed earlier; will process 6734 files now Step #5: ==125248== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55609df359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5560a459a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5560a457d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5560a457d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55609df3bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55609de9cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55609de97355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55609df2dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5560a0efcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5560a0efcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5560a0efcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5560a0efcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5560a0efcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5560a0efcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5560a0efcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5560a0efcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5560a0efcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5560a0efcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5560a3191f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55609febeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55609fec9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55609fc75c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55609fc75c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55609fc76738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55609fc75874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55609fc75874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55609fc75874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5560a457fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5560a4588928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5560a4570699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5560a459b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f080befc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55609de95b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x3b,0x22,0x42,0x42,0x42,0x42,0xdb,0x8d,0xdb,0xaa,0xdb,0x8d,0xdb,0xaa,0x72,0x32,0x34,0x31,0xdb,0x8d,0x31,0xdb,0x8d,0xdb,0xaa,0xd7,0x8d,0xdb,0xaa,0x4d,0x72,0x30,0xdb,0x8d,0xdb,0xaa,0xdf,0x8d,0xdb,0xaa,0x72,0x30,0xdb,0x8d,0x31,0xdb,0x92,0xdb,0xaa,0xdb,0x8d,0xdb,0x2b,0x2b,0xaa,0x72,0x2b,0x2b,0x2c,0x2b, Step #5: HU;\"BBBB\333\215\333\252\333\215\333\252r241\333\2151\333\215\333\252\327\215\333\252Mr0\333\215\333\252\337\215\333\252r0\333\2151\333\222\333\252\333\215\333++\252r++,+ Step #5: artifact_prefix='./'; Test unit written to ./oom-400f889deb45a622677f6fb4324aeb7f83959ea9 Step #5: Base64: SFU7IkJCQkLbjduq243bqnIyNDHbjTHbjduq143bqk1yMNuN26rfjduqcjDbjTHbktuq243bKyuqcisrLCs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3478 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3433758678 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b09f45810, 0x560b0a12f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b0a12f020,0x560b0bfc70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/400f889deb45a622677f6fb4324aeb7f83959ea9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4296 processed earlier; will process 6733 files now Step #5: ==125284== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560b00a3a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b0709f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b070825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b070824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b00a40d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b009a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b0099c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b00a32c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b03a01f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b03a01f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b03a01f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b03a01f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b03a01f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b03a01f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b03a01f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b03a01f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b03a01f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b03a01f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b05c96f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b029c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b029cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b0277ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b0277ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b0277b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b0277a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b0277a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b0277a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b07084abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b0708d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b07075699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b070a0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffae9a1f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b0099ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0x24,0x7e,0x5e,0xa,0xa,0x7e,0x24,0x6e,0x0,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x4d,0x43,0x43,0x43,0x43,0x43,0x56,0x21,0xa,0xa,0x56,0x56,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x7e, Step #5: c$~^\012\012~$n\000CCCCCCCCCCCCCCCCCCCCCCCMCCCCCV!\012\012VV----------------~ Step #5: artifact_prefix='./'; Test unit written to ./oom-98ae942032e8ea8a61979eaa894f707acc078e58 Step #5: Base64: YyR+XgoKfiRuAENDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDTUNDQ0NDViEKClZWLS0tLS0tLS0tLS0tLS0tLX4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3479 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3434248448 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5616790f7810, 0x5616792e101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5616792e1020,0x56167b1790e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/98ae942032e8ea8a61979eaa894f707acc078e58' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4297 processed earlier; will process 6732 files now Step #5: ==125320== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56166fbec9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561676251898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5616762345dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5616762344fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56166fbf2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56166fb53b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56166fb4e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56166fbe4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561672bb3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561672bb3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561672bb3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561672bb3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561672bb3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561672bb3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561672bb3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561672bb3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561672bb3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561672bb3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561674e48f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561671b75b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561671b80be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56167192cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56167192cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56167192d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56167192c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56167192c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56167192c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561676236abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56167623f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561676227699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561676252112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f375944c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56166fb4cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0xb0,0xd9,0x90,0xd9,0x98,0x20,0xda,0x90,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0xb0,0xd9,0x90,0xd9,0x98,0x20,0xda,0x90,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x4d,0x2f,0x73,0x76,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text>\331\260\331\220\331\230 \332\220'</text><text>\331\260\331\220\331\230 \332\220'</text>M/sv></svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-4cfb3ebc441277ccd1bfd286761137fabc41f356 Step #5: Base64: PHN2Zz48dGV4dD7ZsNmQ2Zgg2pAnPC90ZXh0Pjx0ZXh0Ptmw2ZDZmCDakCc8L3RleHQ+TS9zdj48L3N2Zz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3480 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3434748011 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56298b9a6810, 0x56298bb9001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56298bb90020,0x56298da280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4cfb3ebc441277ccd1bfd286761137fabc41f356' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4298 processed earlier; will process 6731 files now Step #5: ==125356== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56298249b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562988b00898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562988ae35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562988ae34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5629824a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562982402b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629823fd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562982493c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562985462f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562985462f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562985462f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562985462f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562985462f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562985462f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562985462f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562985462f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562985462f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562985462f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5629876f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562984424b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56298442fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629841dbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629841dbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629841dc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629841db874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629841db874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629841db874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562988ae5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562988aee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562988ad6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562988b01112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ffa47e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629823fbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x9,0x28,0x69,0x2d,0x2d,0x42,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x24,0xa,0x3a,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x24,0x9d,0x72, Step #5: s-\011(i--B\000\000\000\000\001\000\000\000\000$\012:\012\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000-\012=\012=\012\000\000\000\000\000\000\000\012$\235r Step #5: artifact_prefix='./'; Test unit written to ./oom-523e6471c9386c81b6c41097e52f4351cb4d2a9f Step #5: Base64: cy0JKGktLUIAAAAAAQAAAAAkCjoKAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALQo9Cj0KAAAAAAAAAAoknXI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3481 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3435245407 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a40f858810, 0x55a40fa4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a40fa42020,0x55a4118da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/523e6471c9386c81b6c41097e52f4351cb4d2a9f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4299 processed earlier; will process 6730 files now Step #5: #1 pulse cov: 3950 ft: 3951 exec/s: 0 rss: 173Mb Step #5: ==125392== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a40634d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a40c9b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a40c9955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a40c9954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a406353d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a4062b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a4062af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a406345c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a409314f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a409314f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a409314f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a409314f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a409314f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a409314f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a409314f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a409314f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a409314f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a409314f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a40b5a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a4082d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a4082e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a40808dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a40808dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a40808e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a40808d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a40808d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a40808d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a40c997abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a40c9a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a40c988699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a40c9b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f657da64082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a4062adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x65,0x6c,0x45,0x43,0x74,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0x30,0x2e,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0x30,0x2e,0x2d,0xc,0x6c,0x45,0x21,0x74,0x2d,0xc,0x2d,0x43,0x74,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0x30,0x2e,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0x38,0x2e,0x2d,0x39,0x2e, Step #5: selECt-\014-\014-\014-0.-\014-\014-\014-\014-0.-\014lE!t-\014-Ct-\014-\014-\014-\014-0.-\014-\014-\014-\014-8.-9. Step #5: artifact_prefix='./'; Test unit written to ./oom-d76a510fae25f0b79dedb04c8a0777cf84ded08a Step #5: Base64: c2VsRUN0LQwtDC0MLTAuLQwtDC0MLQwtMC4tDGxFIXQtDC1DdC0MLQwtDC0MLTAuLQwtDC0MLQwtOC4tOS4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3482 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3435787683 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560314017810, 0x56031420101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560314201020,0x5603160990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d76a510fae25f0b79dedb04c8a0777cf84ded08a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4301 processed earlier; will process 6728 files now Step #5: ==125428== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56030ab0c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560311171898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5603111545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5603111544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56030ab12d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56030aa73b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56030aa6e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56030ab04c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56030dad3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56030dad3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56030dad3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56030dad3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56030dad3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56030dad3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56030dad3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56030dad3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56030dad3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56030dad3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56030fd68f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56030ca95b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56030caa0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56030c84cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56030c84cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56030c84d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56030c84c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56030c84c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56030c84c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560311156abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56031115f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560311147699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560311172112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f913762a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56030aa6cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x6e,0x74,0x65,0x72,0x70,0x6c,0x61,0x79,0x20,0x4d,0x56,0x45,0x20,0x46,0x69,0x6c,0x65,0x1a,0x0,0x1a,0x0,0x0,0x10,0x0,0x0,0x0,0x2,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: Interplay MVE File\032\000\032\000\000\020\000\000\000\002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b9c919c88c1697bb0249447010b969f283f746ef Step #5: Base64: SW50ZXJwbGF5IE1WRSBGaWxlGgAaAAAQAAAAAgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3483 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3436274976 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561082c3c810, 0x561082e2601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561082e26020,0x561084cbe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b9c919c88c1697bb0249447010b969f283f746ef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4302 processed earlier; will process 6727 files now Step #5: ==125464== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5610797319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56107fd96898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56107fd795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56107fd794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561079737d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561079698b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561079693355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561079729c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56107c6f8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56107c6f8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56107c6f8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56107c6f8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56107c6f8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56107c6f8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56107c6f8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56107c6f8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56107c6f8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56107c6f8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56107e98df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56107b6bab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56107b6c5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56107b471c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56107b471c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56107b472738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56107b471874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56107b471874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56107b471874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56107fd7babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56107fd84928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56107fd6c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56107fd97112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e47939082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561079691b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x12,0x3d,0x27,0x66,0x27,0x27,0x27,0x27,0x34,0xe2,0x81,0xa5,0x2d,0x3d,0x27,0x34,0x27,0x27,0x27,0x27,0x27,0xdf,0xbd,0x35,0x3c,0x27,0x27,0x37,0x2f,0x30,0x27,0x67,0x27,0x27,0x66,0x27,0x27,0x27,0x27,0x34,0xe2,0x81,0xa5,0x2d,0x3d,0x27,0x34,0x27,0x27,0x27,0x27,0x27,0xdf,0xbd,0x35,0x27,0x24,0x27,0x2d, Step #5: $22\022='f''''4\342\201\245-='4'''''\337\2755<''7/0'g''f''''4\342\201\245-='4'''''\337\2755'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-3b1a7bf3bdc7d500e2c02d7ebba8f73d2863a6f1 Step #5: Base64: JDIyEj0nZicnJyc04oGlLT0nNCcnJycn3701PCcnNy8wJ2cnJ2YnJycnNOKBpS09JzQnJycnJ9+9NSckJy0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3484 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3436768885 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a7bfc1810, 0x563a7c1ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a7c1ab020,0x563a7e0430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3b1a7bf3bdc7d500e2c02d7ebba8f73d2863a6f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4303 processed earlier; will process 6726 files now Step #5: ==125500== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563a72ab69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a7911b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a790fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a790fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a72abcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a72a1db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a72a18355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a72aaec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a75a7df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a75a7df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a75a7df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a75a7df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a75a7df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a75a7df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a75a7df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a75a7df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a75a7df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a75a7df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a77d12f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a74a3fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a74a4abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a747f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a747f6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a747f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a747f6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a747f6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a747f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a79100abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a79109928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a790f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a7911c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe827db0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a72a16b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x30,0x76,0x33,0x60,0x3e,0x32,0x7f,0x7f,0x7f,0x7f,0x0,0x0,0x0,0x30,0x76,0x31,0x60,0x3e,0x32,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x73,0x7d,0x7f,0x7f,0x7f,0x47,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7d,0x7f,0x72,0x70,0x69,0x2f,0x7f,0x76,0x7f,0x7f,0xa0,0x81,0xad,0x3c,0x80,0xbb, Step #5: \000\000\0000v3`>2\177\177\177\177\000\000\0000v1`>2\177\177\177\177\177\177\177\177\177\177\177s}\177\177\177G\000\000\000\000\000\000\000}\177rpi/\177v\177\177\240\201\255<\200\273 Step #5: artifact_prefix='./'; Test unit written to ./oom-e14d7b4771b939de35b8f07f01de3ed9394064b6 Step #5: Base64: AAAAMHYzYD4yf39/fwAAADB2MWA+Mn9/f39/f39/f39/c31/f39HAAAAAAAAAH1/cnBpL392f3+gga08gLs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3485 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3437387688 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b06613810, 0x556b067fd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b067fd020,0x556b086950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e14d7b4771b939de35b8f07f01de3ed9394064b6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4304 processed earlier; will process 6725 files now Step #5: ==125536== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556afd1089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b0376d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b037505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b037504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556afd10ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556afd06fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556afd06a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556afd100c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b000cff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b000cff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b000cff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b000cff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b000cff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b000cff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b000cff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b000cff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b000cff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b000cff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b02364f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556aff091b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556aff09cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556afee48c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556afee48c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556afee49738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556afee48874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556afee48874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556afee48874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b03752abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b0375b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b03743699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b0376e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f632f7ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556afd068b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x8,0x1a,0x0,0x0,0x0,0x5b,0x7,0x66, Step #5: HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH\010\032\000\000\000[\007f Step #5: artifact_prefix='./'; Test unit written to ./oom-2bf99119cc566ec49f47c7ca097c27bd61d0e282 Step #5: Base64: SEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhICBoAAABbB2Y= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3486 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3437873686 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564769912810, 0x564769afc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564769afc020,0x56476b9940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2bf99119cc566ec49f47c7ca097c27bd61d0e282' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4305 processed earlier; will process 6724 files now Step #5: ==125572== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647604079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564766a6c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564766a4f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564766a4f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56476040dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56476036eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564760369355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647603ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647633cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647633cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647633cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647633cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647633cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647633cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647633cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647633cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647633cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647633cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564765663f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564762390b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56476239bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564762147c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564762147c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564762148738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564762147874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564762147874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564762147874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564766a51abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564766a5a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564766a42699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564766a6d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe5561f3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564760367b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x50,0x44,0x46,0x2d,0x73,0x74,0x61,0x72,0x74,0x78,0x72,0x65,0x66,0x31,0x6a,0xa,0xa,0x32,0x20,0x30,0x20,0x6f,0x62,0x6a,0x20,0x3c,0x3c,0xa,0x20,0x31,0x2e,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0xa,0x3c,0x3c,0x2e,0xa,0x2f,0x52,0x6f,0x6f,0x74,0x20,0x31,0x20,0x30,0x20,0x52,0x2f,0x4b,0x69,0x64,0x73,0x20, Step #5: %PDF-startxref1j\012\0122 0 obj <<\012 1.\012trailer\012<<.\012/Root 1 0 R/Kids Step #5: artifact_prefix='./'; Test unit written to ./oom-296abaca5e4d75891169e72e88f233a5dd6007b8 Step #5: Base64: JVBERi1zdGFydHhyZWYxagoKMiAwIG9iaiA8PAogMS4KdHJhaWxlcgo8PC4KL1Jvb3QgMSAwIFIvS2lkcyA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3487 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3438364390 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c94bbf9810, 0x55c94bde301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c94bde3020,0x55c94dc7b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/296abaca5e4d75891169e72e88f233a5dd6007b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4306 processed earlier; will process 6723 files now Step #5: #1 pulse cov: 3752 ft: 3753 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 4280 ft: 4676 exec/s: 0 rss: 175Mb Step #5: ==125608== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c9426ee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c948d53898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c948d365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c948d364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9426f4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c942655b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c942650355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9426e6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c9456b5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c9456b5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c9456b5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c9456b5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c9456b5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c9456b5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c9456b5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c9456b5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c9456b5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c9456b5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c94794af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c944677b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c944682be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c94442ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c94442ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c94442f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c94442e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c94442e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c94442e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c948d38abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c948d41928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c948d29699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c948d54112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f40c55e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c94264eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x9,0x28,0x69,0x2d,0x2d,0x42,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x24,0xa,0x3a,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1c,0x0,0x0,0x0,0x0,0x16,0x16,0x16,0x16,0xf,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x24,0x9d,0x72, Step #5: s-\011(i--B\000\000\000\000\001\000\000\000\000$\012:\012\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\034\000\000\000\000\026\026\026\026\017'\000\000\000\000\000\000\000\012$\235r Step #5: artifact_prefix='./'; Test unit written to ./oom-78b62393ee45f51cad53076d5952760c409e9b1a Step #5: Base64: cy0JKGktLUIAAAAAAQAAAAAkCjoKAAAAAAAAAAAAAAAAAAAAAAAAAAAcAAAAABYWFhYPJwAAAAAAAAAKJJ1y Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3488 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3438934344 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55891ff00810, 0x5589200ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5589200ea020,0x558921f820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/78b62393ee45f51cad53076d5952760c409e9b1a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4309 processed earlier; will process 6720 files now Step #5: ==125644== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5589169f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55891d05a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55891d03d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55891d03d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5589169fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55891695cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558916957355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5589169edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5589199bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5589199bcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5589199bcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5589199bcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5589199bcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5589199bcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5589199bcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5589199bcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5589199bcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5589199bcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55891bc51f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55891897eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558918989be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558918735c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558918735c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558918736738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558918735874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558918735874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558918735874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55891d03fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55891d048928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55891d030699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55891d05b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd1e402a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558916955b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60, Step #5: ```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012``` Step #5: artifact_prefix='./'; Test unit written to ./oom-f2be40a8383c6104d1628da698bfe29ecbbe4a54 Step #5: Base64: YGBgCmBgYApgYGAKYGBgCmBgYApgYGAKYGBgCmBgYApgYGAKYGBgCmBgYApgYGAKYGBgCmBgYApgYGAKYGBg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3489 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3439541378 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5595d1a6f810, 0x5595d1c5901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5595d1c59020,0x5595d3af10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f2be40a8383c6104d1628da698bfe29ecbbe4a54' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4310 processed earlier; will process 6719 files now Step #5: ==125680== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5595c85649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5595cebc9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5595cebac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5595cebac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5595c856ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5595c84cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5595c84c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5595c855cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5595cb52bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5595cb52bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5595cb52bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5595cb52bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5595cb52bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5595cb52bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5595cb52bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5595cb52bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5595cb52bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5595cb52bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5595cd7c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5595ca4edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5595ca4f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5595ca2a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5595ca2a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5595ca2a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5595ca2a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5595ca2a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5595ca2a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5595cebaeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5595cebb7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5595ceb9f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5595cebca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f853cfa0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5595c84c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0x74,0x62,0x6f,0x64,0x79,0x3e,0xa,0x6e,0x62,0x65,0x66,0x6f,0x70,0x79,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0x61,0x75,0x64,0x69,0x6f,0x3e,0xa,0x4f,0x43,0x54,0x59,0x50,0x3c,0x0,0x0,0x0,0x40,0x3c, Step #5: \012\012\012\012\012\012\012\012\012\012\012<tbody>\012nbefopy\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012<audio>\012OCTYP<\000\000\000@< Step #5: artifact_prefix='./'; Test unit written to ./oom-3e67b4ae2cec0d7a80a02b53b9d8b5d9197d5913 Step #5: Base64: CgoKCgoKCgoKCgo8dGJvZHk+Cm5iZWZvcHkKCgoKCgoKCgoKCgoKCgoKCgo8YXVkaW8+Ck9DVFlQPAAAAEA8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3490 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3440026857 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ce03c2810, 0x559ce05ac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ce05ac020,0x559ce24440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3e67b4ae2cec0d7a80a02b53b9d8b5d9197d5913' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4311 processed earlier; will process 6718 files now Step #5: ==125716== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559cd6eb79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559cdd51c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559cdd4ff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559cdd4ff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559cd6ebdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559cd6e1eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559cd6e19355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559cd6eafc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559cd9e7ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559cd9e7ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559cd9e7ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559cd9e7ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559cd9e7ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559cd9e7ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559cd9e7ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559cd9e7ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559cd9e7ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559cd9e7ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559cdc113f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559cd8e40b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559cd8e4bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559cd8bf7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559cd8bf7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559cd8bf8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559cd8bf7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559cd8bf7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559cd8bf7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559cdd501abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559cdd50a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559cdd4f2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559cdd51d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb569c8b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559cd6e17b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x7a,0x77,0xf0,0x91,0x9b,0x86,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x7a,0x77,0xf0,0x91,0x9b,0x86,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf2,0x98,0xa0,0x8a, Step #5: \012\023\022\021\012\017//+build\013zw\360\221\233\206\012\023\022\021\012\017//+build\013zw\360\221\233\206\012\023\022\021\012\017//+build\013 w\362\230\240\212 Step #5: artifact_prefix='./'; Test unit written to ./oom-9504c408477f0a3a5af52bb1f68a433ae23c3f43 Step #5: Base64: ChMSEQoPLy8rYnVpbGQLenfwkZuGChMSEQoPLy8rYnVpbGQLenfwkZuGChMSEQoPLy8rYnVpbGQLIHfymKCK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3491 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3440513394 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c700a65810, 0x55c700c4f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c700c4f020,0x55c702ae70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9504c408477f0a3a5af52bb1f68a433ae23c3f43' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4312 processed earlier; will process 6717 files now Step #5: ==125752== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c6f755a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c6fdbbf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c6fdba25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c6fdba24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c6f7560d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6f74c1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6f74bc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c6f7552c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c6fa521f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c6fa521f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c6fa521f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c6fa521f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c6fa521f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c6fa521f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c6fa521f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c6fa521f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c6fa521f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c6fa521f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c6fc7b6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6f94e3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c6f94eebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6f929ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6f929ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6f929b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6f929a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6f929a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6f929a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c6fdba4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c6fdbad928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c6fdb95699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c6fdbc0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b65d93082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6f74bab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x0,0x6e,0x0,0x43,0x43,0x0,0x0,0x0,0x0,0x0,0x0,0xe0,0xb9,0x84,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x81,0xa8,0x0,0x0,0x0,0x0,0x0,0xf3,0xa0,0x81,0x8f,0x0,0x0,0x0,0x0,0x0,0x61,0x7a,0x0,0x43, Step #5: D\000n\000CC\000\000\000\000\000\000\340\271\204\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\342\201\250\000\000\000\000\000\363\240\201\217\000\000\000\000\000az\000C Step #5: artifact_prefix='./'; Test unit written to ./oom-7e23e7dd2ee4322015ab91e3de413b5db2ea5a8a Step #5: Base64: RABuAENDAAAAAAAA4LmEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA4oGoAAAAAADzoIGPAAAAAABhegBD Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3492 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3441001596 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556150bb2810, 0x556150d9c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556150d9c020,0x556152c340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7e23e7dd2ee4322015ab91e3de413b5db2ea5a8a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4313 processed earlier; will process 6716 files now Step #5: ==125788== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5561476a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55614dd0c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55614dcef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55614dcef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5561476add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55614760eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556147609355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55614769fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55614a66ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55614a66ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55614a66ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55614a66ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55614a66ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55614a66ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55614a66ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55614a66ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55614a66ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55614a66ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55614c903f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556149630b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55614963bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5561493e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5561493e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5561493e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5561493e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5561493e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5561493e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55614dcf1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55614dcfa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55614dce2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55614dd0d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f203d4b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556147607b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x3c,0x3c,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x3c,0x3c,0x2f,0x20,0x2f,0x20,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x3c,0x3c,0x2f,0x20,0x2f,0x20,0x2f,0x20,0x2f,0x20,0xa,0x2f,0x20,0x3a,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x3c,0x3c,0x2f,0x20,0x2f,0x20,0x3c,0x3c,0x2f,0x20, Step #5: trailer<<\012trailer<</ / \012trailer<</ / / / \012/ :\012trailer<</ / <</ Step #5: artifact_prefix='./'; Test unit written to ./oom-de44b0816df8430e27c9e3c8e443f693b925cb74 Step #5: Base64: dHJhaWxlcjw8CnRyYWlsZXI8PC8gLyAKdHJhaWxlcjw8LyAvIC8gLyAKLyA6CnRyYWlsZXI8PC8gLyA8PC8g Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3493 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3441496509 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5603fc028810, 0x5603fc21201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5603fc212020,0x5603fe0aa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de44b0816df8430e27c9e3c8e443f693b925cb74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4314 processed earlier; will process 6715 files now Step #5: ==125824== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5603f2b1d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5603f9182898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5603f91655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5603f91654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5603f2b23d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5603f2a84b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5603f2a7f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5603f2b15c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5603f5ae4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5603f5ae4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5603f5ae4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5603f5ae4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5603f5ae4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5603f5ae4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5603f5ae4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5603f5ae4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5603f5ae4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5603f5ae4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5603f7d79f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5603f4aa6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5603f4ab1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5603f485dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5603f485dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5603f485e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5603f485d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5603f485d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5603f485d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5603f9167abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5603f9170928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5603f9158699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5603f9183112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f454fae3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5603f2a7db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x7e,0x7e,0x3c,0x7e,0x7e,0x7e,0x24,0x4,0x32,0x34,0x2d,0x3d,0x3e,0x34,0x2d,0x3d,0x3e,0xde,0xae,0xce,0xae,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0x24,0xb2,0xb2,0xb2,0xb2,0x24, Step #5: '~~<~~~$\00424-=>4-=>\336\256\316\256-\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000=$\262\262\262\262$ Step #5: artifact_prefix='./'; Test unit written to ./oom-8b27185256bc2dc97ba310329019be4e6f5a68a8 Step #5: Base64: J35+PH5+fiQEMjQtPT40LT0+3q7Ori0AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA9JLKysrIk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3494 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3441990549 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b1003c810, 0x558b1022601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b10226020,0x558b120be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8b27185256bc2dc97ba310329019be4e6f5a68a8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4315 processed earlier; will process 6714 files now Step #5: ==125860== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558b06b319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b0d196898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b0d1795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b0d1794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b06b37d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b06a98b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b06a93355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b06b29c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b09af8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b09af8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b09af8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b09af8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b09af8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b09af8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b09af8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b09af8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b09af8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b09af8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b0bd8df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b08abab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b08ac5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b08871c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b08871c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b08872738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b08871874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b08871874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b08871874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b0d17babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b0d184928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b0d16c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b0d197112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb48976082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b06a91b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x85, Step #5: .\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-69759fdde35a34672ddd680009d1d6d1502eca37 Step #5: Base64: Ls2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2F Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3495 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3442474352 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a8538f3810, 0x55a853add01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a853add020,0x55a8559750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/69759fdde35a34672ddd680009d1d6d1502eca37' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4316 processed earlier; will process 6713 files now Step #5: ==125896== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a84a3e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a850a4d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a850a305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a850a304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a84a3eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a84a34fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a84a34a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a84a3e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a84d3aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a84d3aff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a84d3aff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a84d3aff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a84d3aff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a84d3aff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a84d3aff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a84d3aff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a84d3aff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a84d3aff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a84f644f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a84c371b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a84c37cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a84c128c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a84c128c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a84c129738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a84c128874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a84c128874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a84c128874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a850a32abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a850a3b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a850a23699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a850a4e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e3cba1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a84a348b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x61,0x73,0x6d,0x1,0x0,0x0,0x0,0x1,0x22,0x8,0x60,0x2,0x6f,0x7b,0x1,0x7c,0x60,0x0,0x0,0x60,0x2,0x6f,0x7b,0x1,0x7c,0x60,0x0,0x0,0x60,0x2,0x6f,0x7b,0x1,0x7c,0x60,0x0,0x0,0x60,0x2,0x6f,0x7b,0x1,0x7c,0x0,0x2e,0x0,0x0,0x0,0xf3,0xa0,0x81,0xbc,0x0,0x2,0x6f,0x7b,0x1,0x7c,0x60,0x0,0x0,0x9, Step #5: \000asm\001\000\000\000\001\"\010`\002o{\001|`\000\000`\002o{\001|`\000\000`\002o{\001|`\000\000`\002o{\001|\000.\000\000\000\363\240\201\274\000\002o{\001|`\000\000\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-5758485fde21df7753656b6f2cbf01a4e5600934 Step #5: Base64: AGFzbQEAAAABIghgAm97AXxgAABgAm97AXxgAABgAm97AXxgAABgAm97AXwALgAAAPOggbwAAm97AXxgAAAJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3496 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3443088321 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55896bb93810, 0x55896bd7d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55896bd7d020,0x55896dc150e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5758485fde21df7753656b6f2cbf01a4e5600934' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4317 processed earlier; will process 6712 files now Step #5: ==125932== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5589626889c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558968ced898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558968cd05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558968cd04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55896268ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5589625efb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5589625ea355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558962680c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55896564ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55896564ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55896564ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55896564ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55896564ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55896564ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55896564ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55896564ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55896564ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55896564ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589678e4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558964611b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55896461cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5589643c8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5589643c8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5589643c9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5589643c8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5589643c8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5589643c8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558968cd2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558968cdb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558968cc3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558968cee112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff0b2374082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5589625e8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0xaf,0xcd,0x8f,0xcd,0x8f,0xcc,0x9f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8d,0xcd,0x8f,0xcd,0x8f, Step #5: 1\315\217\315\217\315\217\315\217\315\217\315\217\315\257\315\217\315\217\314\237\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\215\315\217\315\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-c603942c23efd1d7cf149e15a6b8c229130aed35 Step #5: Base64: Mc2PzY/Nj82PzY/Nj82vzY/Nj8yfzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzY3Nj82P Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3497 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3443569885 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564fa201e810, 0x564fa220801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564fa2208020,0x564fa40a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c603942c23efd1d7cf149e15a6b8c229130aed35' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4318 processed earlier; will process 6711 files now Step #5: ==125968== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564f98b139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f9f178898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f9f15b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f9f15b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f98b19d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f98a7ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f98a75355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f98b0bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f9badaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f9badaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f9badaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f9badaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f9badaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f9badaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f9badaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f9badaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f9badaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f9badaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f9dd6ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f9aa9cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f9aaa7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f9a853c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f9a853c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f9a854738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f9a853874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f9a853874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f9a853874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f9f15dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f9f166928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f9f14e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f9f179112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe80a015082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f98a73b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xb,0x2f,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x27,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0xa,0x2d,0xa,0x2f,0x2f,0x37,0x37,0x37,0x37,0x27,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0xa,0x2d,0xa,0x2f,0x2f,0xa,0xa,0xa,0x2f,0x2f,0xa,0xa, Step #5: -\013/777777777'77777777777777\012-\012//7777'77777777777777\012-\012//\012\012\012//\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-124f3eadac9a16c642fd118c4f9a04f14d6bef9b Step #5: Base64: LQsvNzc3Nzc3Nzc3Jzc3Nzc3Nzc3Nzc3Nzc3Ci0KLy83Nzc3Jzc3Nzc3Nzc3Nzc3Nzc3Ci0KLy8KCgovLwoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3498 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3444057300 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560566f38810, 0x56056712201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560567122020,0x560568fba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/124f3eadac9a16c642fd118c4f9a04f14d6bef9b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4319 processed earlier; will process 6710 files now Step #5: ==126004== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56055da2d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560564092898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605640755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605640754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56055da33d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56055d994b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56055d98f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56055da25c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605609f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605609f4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605609f4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605609f4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605609f4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605609f4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605609f4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605609f4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605609f4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605609f4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560562c89f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56055f9b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56055f9c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56055f76dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56055f76dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56055f76e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56055f76d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56055f76d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56055f76d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560564077abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560564080928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560564068699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560564093112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff5a3b43082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56055d98db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x42,0x2d,0x2d,0x2d,0x78,0x2d,0x45,0x47,0x8,0x0,0x31,0xf,0x73,0x74,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x20,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x24,0x24,0xa,0x2d,0x20,0x2b,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x20,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x24,0x24,0xa,0x2d,0x20, Step #5: -B---x-EG\010\0001\017st------\012- GIN ----$$\012- +IN ------\012- GIN ----$$\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-028702f8c71e28565f62d7dabae79ce87cf5c87d Step #5: Base64: LUItLS14LUVHCAAxD3N0LS0tLS0tCi0gR0lOIC0tLS0kJAotICtJTiAtLS0tLS0KLSBHSU4gLS0tLSQkCi0g Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3499 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3444549904 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564a394aa810, 0x564a3969401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564a39694020,0x564a3b52c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/028702f8c71e28565f62d7dabae79ce87cf5c87d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4320 processed earlier; will process 6709 files now Step #5: ==126040== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564a2ff9f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564a36604898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564a365e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564a365e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564a2ffa5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564a2ff06b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564a2ff01355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564a2ff97c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564a32f66f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564a32f66f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564a32f66f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564a32f66f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564a32f66f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564a32f66f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564a32f66f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564a32f66f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564a32f66f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564a32f66f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564a351fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564a31f28b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564a31f33be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564a31cdfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564a31cdfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564a31ce0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564a31cdf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564a31cdf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564a31cdf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564a365e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564a365f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564a365da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564a36605112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd624961082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564a2feffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x0,0x6e,0x0,0x0,0x0,0x0,0x0,0x0,0xe0,0xb9,0x84,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x81,0xa8,0x0,0x0,0xa8,0x0,0x0,0x0,0x0,0x0,0xf3,0xa0,0x81,0x8f,0x0,0x0,0x0,0x0,0x0,0x61,0x7a,0x0,0x43, Step #5: D\000n\000\000\000\000\000\000\340\271\204\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\342\201\250\000\000\250\000\000\000\000\000\363\240\201\217\000\000\000\000\000az\000C Step #5: artifact_prefix='./'; Test unit written to ./oom-73512af9484fe9241f4f971becf0b84e650ab5e4 Step #5: Base64: RABuAAAAAAAA4LmEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA4oGoAACoAAAAAADzoIGPAAAAAABhegBD Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3500 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3445041402 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564f8d4f0810, 0x564f8d6da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564f8d6da020,0x564f8f5720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/73512af9484fe9241f4f971becf0b84e650ab5e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4321 processed earlier; will process 6708 files now Step #5: #1 pulse cov: 3633 ft: 3634 exec/s: 0 rss: 172Mb Step #5: ==126076== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564f83fe59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f8a64a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f8a62d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f8a62d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f83febd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f83f4cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f83f47355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f83fddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f86facf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f86facf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f86facf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f86facf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f86facf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f86facf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f86facf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f86facf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f86facf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f86facf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f89241f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f85f6eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f85f79be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f85d25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f85d25c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f85d26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f85d25874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f85d25874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f85d25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f8a62fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f8a638928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f8a620699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f8a64b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9bc2abf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f83f45b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x4f,0x3a,0x31,0x32,0x3a,0x22,0x44,0x61,0x54,0x65,0x49,0x6e,0x74,0x65,0x72,0x76,0x61,0x6c,0x22,0x3a,0x31,0x3a,0x7b,0x73,0x3a,0x31,0x31,0x3a,0x22,0x64,0x61,0x74,0x65,0x5f,0x73,0x74,0x72,0x69,0x6e,0x67,0x22,0x3b,0x53,0x3a,0x31,0x32,0x3a,0x22,0x21,0x33,0x35,0x34,0x31,0x30,0x38,0x30,0x37,0x54,0x32,0x27,0x22,0x3b, Step #5: |O:12:\"DaTeInterval\":1:{s:11:\"date_string\";S:12:\"!35410807T2'\"; Step #5: artifact_prefix='./'; Test unit written to ./oom-40c98da9c8594d4bccdf3bbfa8c972283b172976 Step #5: Base64: fE86MTI6IkRhVGVJbnRlcnZhbCI6MTp7czoxMToiZGF0ZV9zdHJpbmciO1M6MTI6IiEzNTQxMDgwN1QyJyI7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3501 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3445563907 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b7be8d810, 0x555b7c07701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b7c077020,0x555b7df0f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40c98da9c8594d4bccdf3bbfa8c972283b172976' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4323 processed earlier; will process 6706 files now Step #5: ==126112== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555b729829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b78fe7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b78fca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b78fca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b72988d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b728e9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b728e4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b7297ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b75949f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b75949f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b75949f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b75949f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b75949f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b75949f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b75949f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b75949f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b75949f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b75949f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b77bdef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b7490bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b74916be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b746c2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b746c2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b746c3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b746c2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b746c2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b746c2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b78fccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b78fd5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b78fbd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b78fe8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8730af5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b728e2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x23,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x31,0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x32,0xdb,0x81,0xdb,0x80,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0x37,0xfe,0x39, Step #5: \333\201\333\20042\333\201\333\20042\333\201\333\20042\333\201\333\20042\333#\201\333\20042\333\201\333\20041\333\201\333\20042\333\201\333\20042\333\201\333\20042949677\3769 Step #5: artifact_prefix='./'; Test unit written to ./oom-af818184f1953a4536cc8954bb274b066ab12827 Step #5: Base64: 24HbgDQy24HbgDQy24HbgDQy24HbgDQy2yOB24A0MtuB24A0MduB24A0MtuB24A0MtuB24A0Mjk0OTY3N/45 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3502 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3446053655 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558518743810, 0x55851892d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55851892d020,0x55851a7c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af818184f1953a4536cc8954bb274b066ab12827' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4324 processed earlier; will process 6705 files now Step #5: ==126148== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55850f2389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55851589d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5585158805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5585158804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55850f23ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55850f19fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55850f19a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55850f230c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5585121fff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5585121fff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5585121fff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5585121fff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5585121fff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5585121fff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5585121fff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5585121fff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5585121fff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5585121fff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558514494f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5585111c1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5585111ccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558510f78c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558510f78c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558510f79738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558510f78874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558510f78874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558510f78874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558515882abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55851588b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558515873699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55851589e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f97f6a64082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55850f198b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xc4,0xa7,0x3e,0x6e,0x63,0x3c,0x21,0x5b,0x43,0x44,0x41,0x54,0x41,0x5b,0x78,0x6d,0x6c,0x6e,0x73,0x3a,0x78,0x68,0x74,0x6d,0x6c,0x3d,0x22,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x77,0x33,0x2e,0x6f,0x72,0x67,0x2f,0x31,0x39,0x39,0x39,0x2f,0x78,0x68,0x74,0x6d,0x6c,0x22,0x2d,0x39,0x4f,0x3c,0x21,0x3c, Step #5: <\304\247>nc<![CDATA[xmlns:xhtml=\"http://www.w3.org/1999/xhtml\"-9O<!< Step #5: artifact_prefix='./'; Test unit written to ./oom-071d6dce7b1ab8b0fbd9b6d2171d88271fcf724c Step #5: Base64: PMSnPm5jPCFbQ0RBVEFbeG1sbnM6eGh0bWw9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkveGh0bWwiLTlPPCE8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3503 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3446541763 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7119fb810, 0x55b711be501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b711be5020,0x55b713a7d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/071d6dce7b1ab8b0fbd9b6d2171d88271fcf724c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4325 processed earlier; will process 6704 files now Step #5: ==126184== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b7084f09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b70eb55898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b70eb385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b70eb384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b7084f6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b708457b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b708452355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b7084e8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b70b4b7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b70b4b7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b70b4b7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b70b4b7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b70b4b7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b70b4b7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b70b4b7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b70b4b7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b70b4b7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b70b4b7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b70d74cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b70a479b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b70a484be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b70a230c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b70a230c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b70a231738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b70a230874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b70a230874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b70a230874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b70eb3aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b70eb43928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b70eb2b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b70eb56112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb1869df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b708450b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x73,0x6f,0x75,0x72,0x65,0x61,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0xa,0x64,0xa,0x0,0xa,0x64,0xa,0x64,0xa,0x64,0xa,0x74,0xa,0x64,0xa,0x64,0xa,0x64,0xa,0x0,0xa,0x74,0xa,0x64,0xa,0x64,0xa,0x64,0xa,0x0,0xa,0x64,0xa,0x64,0xa,0x0,0xa,0x6d,0xa,0x64,0xa,0x64,0x2d, Step #5: -sourea\\\\\\\\\\\\\\\\\\\\\\\\\\\012d\012\000\012d\012d\012d\012t\012d\012d\012d\012\000\012t\012d\012d\012d\012\000\012d\012d\012\000\012m\012d\012d- Step #5: artifact_prefix='./'; Test unit written to ./oom-128ae6753a6a7ecbb1a20c7fe10e7adfe8363019 Step #5: Base64: LXNvdXJlYVxcXFxcXFxcXFxcXFwKZAoACmQKZApkCnQKZApkCmQKAAp0CmQKZApkCgAKZApkCgAKbQpkCmQt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3504 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3447031671 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5618a86b2810, 0x5618a889c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5618a889c020,0x5618aa7340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/128ae6753a6a7ecbb1a20c7fe10e7adfe8363019' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4326 processed earlier; will process 6703 files now Step #5: ==126220== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56189f1a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5618a580c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5618a57ef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5618a57ef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56189f1add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56189f10eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56189f109355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56189f19fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5618a216ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5618a216ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5618a216ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5618a216ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5618a216ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5618a216ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5618a216ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5618a216ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5618a216ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5618a216ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5618a4403f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5618a1130b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5618a113bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5618a0ee7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5618a0ee7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5618a0ee8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5618a0ee7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5618a0ee7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5618a0ee7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5618a57f1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5618a57fa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5618a57e2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5618a580d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa928ffc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56189f107b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xa,0x25,0xa,0x3a,0xa,0x27,0x27,0x3e,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xa,0x61,0xa,0x27,0x9,0x25,0x3a,0x3b,0x24,0x25,0x3a,0x3b,0x24,0x25,0x3a,0x3b,0x3a,0x25,0x3a,0x3b,0x24,0x25,0x3a,0x3b,0x3a,0x25,0x3a,0x3b,0x9,0x25,0x3a,0x3b,0x24,0x25,0x3a,0x3b,0x54,0x27,0x3e, Step #5: <!ENTITY\012%\012:\012''><!ENTITY\012a\012'\011%:;$%:;$%:;:%:;$%:;:%:;\011%:;$%:;T'> Step #5: artifact_prefix='./'; Test unit written to ./oom-ce8dd0044f219b36b8c6a510763eb7488d643559 Step #5: Base64: PCFFTlRJVFkKJQo6CicnPjwhRU5USVRZCmEKJwklOjskJTo7JCU6OzolOjskJTo7OiU6OwklOjskJTo7VCc+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3505 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3447521748 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc07595810, 0x55cc0777f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc0777f020,0x55cc096170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce8dd0044f219b36b8c6a510763eb7488d643559' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4327 processed earlier; will process 6702 files now Step #5: ==126256== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cbfe08a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc046ef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc046d25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc046d24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cbfe090d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cbfdff1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cbfdfec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cbfe082c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc01051f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc01051f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc01051f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc01051f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc01051f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc01051f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc01051f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc01051f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc01051f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc01051f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc032e6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc00013b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc0001ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cbffdcac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cbffdcac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cbffdcb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cbffdca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cbffdca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cbffdca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc046d4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc046dd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc046c5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc046f0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f72aef37082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cbfdfeab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x67,0x7b,0x2f,0x22,0x41,0x63,0x7d,0x60,0x60,0x40,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x62,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x40,0x60,0x60,0x60,0x60,0x60,0x5d,0x60,0x60,0x60,0x62,0x60,0x60,0x60,0x60,0x60,0x65,0x3e,0x67,0x7b,0x1,0x0,0x1,0x8, Step #5: <svg><style>g{/\"Ac}``@````````b````````@`````]```b`````e>g{\001\000\001\010 Step #5: artifact_prefix='./'; Test unit written to ./oom-e50b96dd0547c1466feb541d642944af543d9734 Step #5: Base64: PHN2Zz48c3R5bGU+Z3svIkFjfWBgQGBgYGBgYGBgYmBgYGBgYGBgQGBgYGBgXWBgYGJgYGBgYGU+Z3sBAAEI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3506 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3448134985 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ac36c1810, 0x559ac38ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ac38ab020,0x559ac57430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e50b96dd0547c1466feb541d642944af543d9734' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4328 processed earlier; will process 6701 files now Step #5: ==126292== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559aba1b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ac081b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ac07fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ac07fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559aba1bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559aba11db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559aba118355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559aba1aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559abd17df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559abd17df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559abd17df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559abd17df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559abd17df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559abd17df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559abd17df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559abd17df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559abd17df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559abd17df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559abf412f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559abc13fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559abc14abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559abbef6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559abbef6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559abbef7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559abbef6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559abbef6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559abbef6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ac0800abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ac0809928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ac07f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ac081c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f93949cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559aba116b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x20,0x7b,0xa,0x20,0x20,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0xa,0x6e,0xd,0x7b,0xa,0x70,0x75,0x62,0x3a,0x20,0x22,0x5c,0x27,0x41,0x27,0x3e,0x5c,0x30,0x3c,0x5f,0x4b,0x3e,0x26,0x23,0x30,0x20,0x28,0x28,0x28,0x28,0x28,0x28,0x22,0x20,0x7d,0xa,0x7d,0x7d,0xa,0x7d, Step #5: p {\012 doctype {\012mdecl {\012n\015{\012pub: \"\\'A'>\\0<_K>&#0 ((((((\" }\012}}\012} Step #5: artifact_prefix='./'; Test unit written to ./oom-0b96dba5ee74897a94f0580ac95f82647c7dad56 Step #5: Base64: cCB7CiAgZG9jdHlwZSB7Cm1kZWNsIHsKbg17CnB1YjogIlwnQSc+XDA8X0s+JiMwICgoKCgoKCIgfQp9fQp9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3507 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3448619411 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56444d51f810, 0x56444d70901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56444d709020,0x56444f5a10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b96dba5ee74897a94f0580ac95f82647c7dad56' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4329 processed earlier; will process 6700 files now Step #5: #1 pulse cov: 3478 ft: 3479 exec/s: 0 rss: 172Mb Step #5: ==126328== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5644440149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56444a679898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56444a65c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56444a65c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56444401ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564443f7bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564443f76355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56444400cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564446fdbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564446fdbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564446fdbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564446fdbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564446fdbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564446fdbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564446fdbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564446fdbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564446fdbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564446fdbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564449270f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564445f9db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564445fa8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564445d54c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564445d54c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564445d55738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564445d54874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564445d54874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564445d54874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56444a65eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56444a667928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56444a64f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56444a67a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c8fb18082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564443f74b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x3f, Step #5: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ? Step #5: artifact_prefix='./'; Test unit written to ./oom-4f10e5e56f91d2ee3378d0d194fc4cb13ea20fa0 Step #5: Base64: LSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSA/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3508 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3449211617 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555d5788b810, 0x555d57a7501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555d57a75020,0x555d5990d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f10e5e56f91d2ee3378d0d194fc4cb13ea20fa0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4331 processed earlier; will process 6698 files now Step #5: ==126364== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555d4e3809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555d549e5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555d549c85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555d549c84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555d4e386d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555d4e2e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555d4e2e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555d4e378c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555d51347f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555d51347f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555d51347f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555d51347f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555d51347f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555d51347f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555d51347f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555d51347f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555d51347f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555d51347f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555d535dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555d50309b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555d50314be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555d500c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555d500c0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555d500c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555d500c0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555d500c0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555d500c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555d549caabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555d549d3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555d549bb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555d549e6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0a5840a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555d4e2e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x39,0x39,0x39,0x39,0x39,0x39, Step #5: \333\200\333\2009\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000999999 Step #5: artifact_prefix='./'; Test unit written to ./oom-a46319c927336c8a90a0d1271d51436444e20221 Step #5: Base64: 24DbgDkAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOTk5OTk5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3509 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3449700506 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b829b02810, 0x55b829cec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b829cec020,0x55b82bb840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a46319c927336c8a90a0d1271d51436444e20221' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4332 processed earlier; will process 6697 files now Step #5: ==126400== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b8205f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b826c5c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b826c3f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b826c3f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b8205fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b82055eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b820559355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b8205efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b8235bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b8235bef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b8235bef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b8235bef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b8235bef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b8235bef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b8235bef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b8235bef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b8235bef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b8235bef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b825853f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b822580b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b82258bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b822337c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b822337c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b822338738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b822337874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b822337874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b822337874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b826c41abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b826c4a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b826c32699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b826c5d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc3390c5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b820557b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x30,0x2d,0x31,0x0,0x30,0x7e,0x67,0x6f,0x3b,0x3b,0x48,0x0,0x6e,0x6f,0x73,0x6e,0x6f,0x62,0x6c,0xd6,0xbb,0x41,0x53,0x0,0x30,0x7e,0x29,0x67,0x6f,0x67,0x6c,0x65,0x2d,0x1,0x0,0x0,0x20,0x75,0x6c,0x30,0xd6,0xbb,0x1,0x0,0x0,0x30,0x74,0x72,0x65,0x7e,0x67,0x6f,0x6f,0x66,0x20,0x2f,0x75,0x4c,0x6c,0x33,0xd6,0xbb, Step #5: \0000-1\0000~go;;H\000nosnobl\326\273AS\0000~)gogle-\001\000\000 ul0\326\273\001\000\0000tre~goof /uLl3\326\273 Step #5: artifact_prefix='./'; Test unit written to ./oom-cc0cea0f1f837985767e2365bb0ec0cefeb3831d Step #5: Base64: ADAtMQAwfmdvOztIAG5vc25vYmzWu0FTADB+KWdvZ2xlLQEAACB1bDDWuwEAADB0cmV+Z29vZiAvdUxsM9a7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3510 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3450191345 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e34bf6810, 0x559e34de001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e34de0020,0x559e36c780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cc0cea0f1f837985767e2365bb0ec0cefeb3831d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4333 processed earlier; will process 6696 files now Step #5: #1 pulse cov: 3758 ft: 3759 exec/s: 0 rss: 172Mb Step #5: ==126436== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559e2b6eb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e31d50898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e31d335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e31d334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e2b6f1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e2b652b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e2b64d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e2b6e3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e2e6b2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e2e6b2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e2e6b2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e2e6b2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e2e6b2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e2e6b2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e2e6b2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e2e6b2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e2e6b2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e2e6b2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e30947f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e2d674b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e2d67fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e2d42bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e2d42bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e2d42c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e2d42b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e2d42b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e2d42b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e31d35abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e31d3e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e31d26699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e31d51112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f38728c5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e2b64bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x56,0x5,0x3,0x55,0x42,0x0,0x1,0x5f,0x41,0x56,0x5,0x1,0x55,0x42,0x0,0x1,0x5f,0x41,0x56,0x5,0x1,0x55,0x42,0x0,0x1,0x5f,0x41,0x56,0x5,0x1,0x55,0x52,0x0,0x1,0x5f,0x41,0x56,0x5,0x1,0x55,0x42,0x0,0x1,0x5f,0x41,0x56,0x5,0x1,0x55,0x42,0x0,0x1,0x5f,0x41,0x56,0x5,0x1,0x55,0x42,0x0,0x4,0x3, Step #5: AV\005\003UB\000\001_AV\005\001UB\000\001_AV\005\001UB\000\001_AV\005\001UR\000\001_AV\005\001UB\000\001_AV\005\001UB\000\001_AV\005\001UB\000\004\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-f4e34bc2d915de391c4d863a7b6103636f000cd0 Step #5: Base64: QVYFA1VCAAFfQVYFAVVCAAFfQVYFAVVCAAFfQVYFAVVSAAFfQVYFAVVCAAFfQVYFAVVCAAFfQVYFAVVCAAQD Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3511 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3450725635 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5635f65f9810, 0x5635f67e301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5635f67e3020,0x5635f867b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f4e34bc2d915de391c4d863a7b6103636f000cd0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4335 processed earlier; will process 6694 files now Step #5: ==126472== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5635ed0ee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5635f3753898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5635f37365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5635f37364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5635ed0f4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5635ed055b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5635ed050355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5635ed0e6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5635f00b5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5635f00b5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5635f00b5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5635f00b5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5635f00b5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5635f00b5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5635f00b5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5635f00b5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5635f00b5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5635f00b5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5635f234af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5635ef077b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5635ef082be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5635eee2ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5635eee2ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5635eee2f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5635eee2e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5635eee2e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5635eee2e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5635f3738abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5635f3741928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5635f3729699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5635f3754112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6c772f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5635ed04eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x37,0x74,0xd7,0xa9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x1, Step #5: 7t\327\251\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-8f441d4586ffb6c9072f32e56892b5e58124b346 Step #5: Base64: N3TXqQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEB Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3512 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3451213029 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56086b794810, 0x56086b97e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56086b97e020,0x56086d8160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8f441d4586ffb6c9072f32e56892b5e58124b346' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4336 processed earlier; will process 6693 files now Step #5: #1 pulse cov: 3583 ft: 3584 exec/s: 0 rss: 174Mb Step #5: ==126508== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5608622899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5608688ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608688d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608688d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56086228fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5608621f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5608621eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560862281c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560865250f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560865250f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560865250f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560865250f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560865250f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560865250f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560865250f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560865250f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560865250f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560865250f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608674e5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560864212b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56086421dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560863fc9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560863fc9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560863fca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560863fc9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560863fc9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560863fc9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5608688d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5608688dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5608688c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5608688ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1ed51ed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5608621e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x3c,0xdb,0xbe,0xdb,0xbe,0x7e,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x32,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x7e,0xff,0xff,0xff,0x73,0x73,0xff,0xff,0xff,0x30,0x73,0x7e,0x7e,0x7e,0x31,0x73, Step #5: ~<\333\276\333\276~sssssssssss%%%%%%%%%%%%%2sssssssssssssss~\377\377\377ss\377\377\3770s~~~1s Step #5: artifact_prefix='./'; Test unit written to ./oom-8e928db11fc0731077a215792ad768ee3c5035d1 Step #5: Base64: fjzbvtu+fnNzc3Nzc3Nzc3NzJSUlJSUlJSUlJSUlJTJzc3Nzc3Nzc3Nzc3Nzc3N+////c3P///8wc35+fjFz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3513 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3451742910 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c5abb0e810, 0x55c5abcf801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c5abcf8020,0x55c5adb900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8e928db11fc0731077a215792ad768ee3c5035d1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4338 processed earlier; will process 6691 files now Step #5: ==126544== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c5a26039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c5a8c68898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c5a8c4b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c5a8c4b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c5a2609d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c5a256ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c5a2565355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c5a25fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c5a55caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c5a55caf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c5a55caf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c5a55caf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c5a55caf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c5a55caf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c5a55caf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c5a55caf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c5a55caf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c5a55caf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c5a785ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c5a458cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c5a4597be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c5a4343c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c5a4343c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c5a4344738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c5a4343874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c5a4343874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c5a4343874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c5a8c4dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c5a8c56928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c5a8c3e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c5a8c69112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf0ff99082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c5a2563b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0x31,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x0,0x0,0x0,0x2f,0x0,0xf,0x31,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x2d,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x11,0xf,0x31,0x11,0x2d,0x3a,0x2d,0x3a,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\0171\0171\021\0171\021-\000\000\000/\000\017177777777-7777777777777777777\021\0171\021-:-:$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-259f315c6d987873d79a7ce994d02cfbb67b63bb Step #5: Base64: JAAALwAAAC8ADzEPMREPMREtAAAALwAPMTc3Nzc3Nzc3LTc3Nzc3Nzc3Nzc3Nzc3Nzc3NzcRDzERLTotOiRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3514 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3452234520 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5617dcfb8810, 0x5617dd1a201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5617dd1a2020,0x5617df03a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/259f315c6d987873d79a7ce994d02cfbb67b63bb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4339 processed earlier; will process 6690 files now Step #5: ==126580== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5617d3aad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5617da112898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5617da0f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5617da0f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5617d3ab3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5617d3a14b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5617d3a0f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5617d3aa5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5617d6a74f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5617d6a74f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5617d6a74f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5617d6a74f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5617d6a74f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5617d6a74f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5617d6a74f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5617d6a74f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5617d6a74f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5617d6a74f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5617d8d09f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5617d5a36b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5617d5a41be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5617d57edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5617d57edc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5617d57ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5617d57ed874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5617d57ed874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5617d57ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5617da0f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5617da100928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5617da0e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5617da113112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4338a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5617d3a0db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd1,0xa1,0xf,0x30,0x5e,0xf,0x0,0x5e,0x25,0x54,0x79,0x5e,0x5e,0x99,0xdf,0xe8,0xed,0xb3,0xfb,0xb7,0x0,0xcc,0xcc,0xcc,0xcc,0xcc,0xcc,0x3,0x0,0xc,0x2,0x2,0x3,0x40,0x0,0x0,0x7,0x31,0x3d,0xff,0x1,0x2e,0x85,0x3d,0x3b,0xb,0x70,0x8,0x13,0x5,0x2d,0x31,0x5e,0xb,0x5e,0x8,0x5,0xd2,0x8c,0xb3,0xeb,0x33,0xb7, Step #5: \321\241\0170^\017\000^%Ty^^\231\337\350\355\263\373\267\000\314\314\314\314\314\314\003\000\014\002\002\003@\000\000\0071=\377\001.\205=;\013p\010\023\005-1^\013^\010\005\322\214\263\3533\267 Step #5: artifact_prefix='./'; Test unit written to ./oom-ccd525992ba4b682734ad221f240c4a30d256893 Step #5: Base64: 0aEPMF4PAF4lVHleXpnf6O2z+7cAzMzMzMzMAwAMAgIDQAAABzE9/wEuhT07C3AIEwUtMV4LXggF0oyz6zO3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3515 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3452714081 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b9aa83c810, 0x55b9aaa2601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b9aaa26020,0x55b9ac8be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ccd525992ba4b682734ad221f240c4a30d256893' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4340 processed earlier; will process 6689 files now Step #5: #1 pulse cov: 3877 ft: 3878 exec/s: 0 rss: 175Mb Step #5: ==126616== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b9a13319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b9a7996898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b9a79795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b9a79794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b9a1337d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b9a1298b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b9a1293355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b9a1329c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b9a42f8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b9a42f8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b9a42f8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b9a42f8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b9a42f8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b9a42f8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b9a42f8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b9a42f8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b9a42f8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b9a42f8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b9a658df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b9a32bab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b9a32c5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b9a3071c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b9a3071c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b9a3072738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b9a3071874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b9a3071874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b9a3071874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b9a797babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b9a7984928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b9a796c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b9a7997112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1639799082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b9a1291b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x47,0xff,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0xff,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a, Step #5: FUZZ-TAGTAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGG\377FUZZ-TAG\377FUZZ-TAGZ Step #5: artifact_prefix='./'; Test unit written to ./oom-bfbe526df9bfb5203a365a473f4164e12ccf3258 Step #5: Base64: RlVaWi1UQUdUQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0f/RlVaWi1UQUf/RlVaWi1UQUda Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3516 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3453240623 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5628953f6810, 0x5628955e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5628955e0020,0x5628974780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bfbe526df9bfb5203a365a473f4164e12ccf3258' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4342 processed earlier; will process 6687 files now Step #5: ==126652== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56288beeb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562892550898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5628925335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5628925334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56288bef1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56288be52b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56288be4d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56288bee3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56288eeb2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56288eeb2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56288eeb2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56288eeb2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56288eeb2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56288eeb2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56288eeb2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56288eeb2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56288eeb2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56288eeb2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562891147f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56288de74b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56288de7fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56288dc2bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56288dc2bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56288dc2c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56288dc2b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56288dc2b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56288dc2b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562892535abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56289253e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562892526699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562892551112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f55a7b57082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56288be4bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x37,0x3a,0x5b,0x22,0xc3,0xbf,0xef,0xb7,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0x26,0xbf,0xef,0xbf,0xbf,0x26,0xff,0xff,0xff,0xff,0x23,0x2c,0x4b,0x22,0x5d,0x7d,0x59,0x27,0xc3,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x69,0x73,0xbf,0x35,0x70,0x27,0x3a,0x3a,0x44,0x3a, Step #5: $3::{$7:[\"\303\277\357\267\277\357\277\277\357\277\277\357\277\277&\277\357\277\277&\377\377\377\377#,K\"]}Y'\303\377\377\377\377\377\377\377\377\377\377is\2775p'::D: Step #5: artifact_prefix='./'; Test unit written to ./oom-0f2abd98283c98552e6cf6ef6a5c190ada7f716c Step #5: Base64: JDM6OnskNzpbIsO/77e/77+/77+/77+/Jr/vv78m/////yMsSyJdfVknw/////////////9pc781cCc6OkQ6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3517 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3453727563 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b8960d5810, 0x55b8962bf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b8962bf020,0x55b8981570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0f2abd98283c98552e6cf6ef6a5c190ada7f716c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4343 processed earlier; will process 6686 files now Step #5: ==126688== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b88cbca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b89322f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b8932125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b8932124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b88cbd0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b88cb31b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b88cb2c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b88cbc2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b88fb91f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b88fb91f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b88fb91f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b88fb91f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b88fb91f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b88fb91f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b88fb91f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b88fb91f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b88fb91f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b88fb91f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b891e26f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b88eb53b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b88eb5ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b88e90ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b88e90ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b88e90b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b88e90a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b88e90a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b88e90a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b893214abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b89321d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b893205699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b893230112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb017508082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b88cb2ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x47,0x41,0x3e,0x2e,0x65,0x3c,0x4b,0x65,0x3e,0x3c,0x4e,0x4e,0x3e,0x3c,0x50,0x6c,0x3e,0x3c,0x70,0x74,0x3e,0x3a,0x3c,0x41,0x59,0x3e,0x3c,0x61,0x65,0x3e,0x3c,0x67,0x65,0x3e,0x3c,0x4e,0x68,0x3e,0x3c,0x65,0x76,0x3e,0x3c,0x4e,0x65,0x3e,0x3c,0x6d,0x65,0x3e,0x3c,0x41,0x65,0x3e,0x3c,0x7a,0x41,0x3e,0x3c,0x52,0x52,0x3e, Step #5: <GA>.e<Ke><NN><Pl><pt>:<AY><ae><ge><Nh><ev><Ne><me><Ae><zA><RR> Step #5: artifact_prefix='./'; Test unit written to ./oom-6e7249710ed6cda3f8385f56eb490dc9bc25ede2 Step #5: Base64: PEdBPi5lPEtlPjxOTj48UGw+PHB0Pjo8QVk+PGFlPjxnZT48Tmg+PGV2PjxOZT48bWU+PEFlPjx6QT48UlI+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3518 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3454220576 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555cd271e810, 0x555cd290801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555cd2908020,0x555cd47a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6e7249710ed6cda3f8385f56eb490dc9bc25ede2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4344 processed earlier; will process 6685 files now Step #5: #1 pulse cov: 3765 ft: 3766 exec/s: 0 rss: 174Mb Step #5: ==126724== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555cc92139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ccf878898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ccf85b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ccf85b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555cc9219d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555cc917ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555cc9175355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555cc920bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ccc1daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ccc1daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ccc1daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ccc1daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ccc1daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ccc1daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ccc1daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ccc1daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ccc1daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ccc1daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555cce46ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ccb19cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ccb1a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ccaf53c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ccaf53c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ccaf54738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ccaf53874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ccaf53874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ccaf53874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ccf85dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ccf866928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ccf84e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ccf879112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f1c5b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555cc9173b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x3d,0x77,0x22,0xe1,0x85,0x80,0xe7,0x86,0xa0,0xe1,0x85,0x9f,0xe3,0x84,0x9f,0xe1,0x85,0xaa,0xe1,0x85,0xa0,0xe1,0x85,0xa0,0xe1,0x86,0xa0,0xe1,0x85,0xa0,0xe7,0x85,0xa0,0xe1,0x85,0xa1,0xe1,0x85,0xa1,0xe1,0x85,0x9c,0xe1,0x85,0xa0,0xe1,0x85,0xa1,0xe1,0x86,0xa0,0xe1,0x85,0xa0,0xe1,0x85,0xa0,0xe1,0x86,0xa0,0x31,0x9f, Step #5: HU=w\"\341\205\200\347\206\240\341\205\237\343\204\237\341\205\252\341\205\240\341\205\240\341\206\240\341\205\240\347\205\240\341\205\241\341\205\241\341\205\234\341\205\240\341\205\241\341\206\240\341\205\240\341\205\240\341\206\2401\237 Step #5: artifact_prefix='./'; Test unit written to ./oom-2156b193279772c4331b9fd33576e776c7f93cc0 Step #5: Base64: SFU9dyLhhYDnhqDhhZ/jhJ/hharhhaDhhaDhhqDhhaDnhaDhhaHhhaHhhZzhhaDhhaHhhqDhhaDhhaDhhqAxnw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3519 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3454749519 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f50567a810, 0x55f50586401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f505864020,0x55f5076fc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2156b193279772c4331b9fd33576e776c7f93cc0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4346 processed earlier; will process 6683 files now Step #5: ==126760== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f4fc16f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f5027d4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f5027b75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f5027b74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f4fc175d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f4fc0d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f4fc0d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f4fc167c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f4ff136f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f4ff136f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f4ff136f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f4ff136f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f4ff136f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f4ff136f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f4ff136f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f4ff136f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f4ff136f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f4ff136f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f5013cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4fe0f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4fe103be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f4fdeafc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f4fdeafc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f4fdeb0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f4fdeaf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f4fdeaf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f4fdeaf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f5027b9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f5027c2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f5027aa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f5027d5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb82354d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f4fc0cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x83,0xdf,0x83,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84, Step #5: \337\203\337\204\337\204\337\204\337\203\337\204\337\203\337\203\337\204\337\203\337\204\337\203\337\203\337\204\337\203\337\204\337\203\337\203\337\204\337\203\337\204\337\203\337\203\337\203\337\203\337\204\337\204\337\204\337\203\337\204\337\203\337\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-fa5d7a27935a528e08c8b5ae125624f08bd3d599 Step #5: Base64: 34PfhN+E34Tfg9+E34Pfg9+E34PfhN+D34PfhN+D34Tfg9+D34Tfg9+E34Pfg9+D34PfhN+E34Tfg9+E34PfhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3520 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3455238885 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f8e8b03810, 0x55f8e8ced01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f8e8ced020,0x55f8eab850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fa5d7a27935a528e08c8b5ae125624f08bd3d599' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4347 processed earlier; will process 6682 files now Step #5: ==126796== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8df5f89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f8e5c5d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8e5c405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8e5c404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8df5fed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8df55fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8df55a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8df5f0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8e25bff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8e25bff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8e25bff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8e25bff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8e25bff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8e25bff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8e25bff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8e25bff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8e25bff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8e25bff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f8e4854f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f8e1581b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f8e158cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8e1338c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8e1338c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8e1339738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8e1338874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8e1338874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8e1338874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f8e5c42abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f8e5c4b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f8e5c33699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f8e5c5e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f303dedd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8df558b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x2d,0x31,0x38,0x34,0x34,0x36,0x37,0x34,0x34,0x30,0x37,0x33,0x37,0x30,0x39,0x35,0x35,0x31,0x33,0x36,0x31,0x3,0x3,0x0,0x0,0x0,0x3,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: ID-18446744073709551361\003\003\000\000\000\003\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-40e348af69f81012291acfef5a6b865d76d5f427 Step #5: Base64: SUQtMTg0NDY3NDQwNzM3MDk1NTEzNjEDAwAAAAMAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3521 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3455729431 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563aa5d75810, 0x563aa5f5f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563aa5f5f020,0x563aa7df70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40e348af69f81012291acfef5a6b865d76d5f427' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4348 processed earlier; will process 6681 files now Step #5: ==126832== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563a9c86a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563aa2ecf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563aa2eb25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563aa2eb24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a9c870d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a9c7d1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a9c7cc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a9c862c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a9f831f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a9f831f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a9f831f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a9f831f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a9f831f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a9f831f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a9f831f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a9f831f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a9f831f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a9f831f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563aa1ac6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a9e7f3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a9e7febe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a9e5aac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a9e5aac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a9e5ab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a9e5aa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a9e5aa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a9e5aa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563aa2eb4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563aa2ebd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563aa2ea5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563aa2ed0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f87a8660082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a9c7cab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6,0x0,0x7,0x0,0x0,0x0,0x0,0x24,0x24,0x24,0x24,0x24,0x31,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x29,0x24,0x24,0x23,0x24,0x24,0x24,0x24,0x24,0x64,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x53,0x24,0x24,0x20,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x4a,0x24, Step #5: \006\000\007\000\000\000\000$$$$$1$$$$$$$$)$$#$$$$$d$$$$$$$$$$$$$$S$$ $$$$$$$$$$$$$J$ Step #5: artifact_prefix='./'; Test unit written to ./oom-0cfbff8866ae1f163a13eccdedefdc858bb1c4e8 Step #5: Base64: BgAHAAAAACQkJCQkMSQkJCQkJCQkKSQkIyQkJCQkZCQkJCQkJCQkJCQkJCQkUyQkICQkJCQkJCQkJCQkJCRKJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3522 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3456237548 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e6fcc9810, 0x555e6feb301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e6feb3020,0x555e71d4b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0cfbff8866ae1f163a13eccdedefdc858bb1c4e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4349 processed earlier; will process 6680 files now Step #5: ==126868== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555e667be9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e6ce23898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e6ce065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e6ce064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e667c4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e66725b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e66720355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e667b6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e69785f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e69785f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e69785f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e69785f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e69785f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e69785f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e69785f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e69785f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e69785f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e69785f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e6ba1af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e68747b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e68752be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e684fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e684fec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e684ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e684fe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e684fe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e684fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e6ce08abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e6ce11928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e6cdf9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e6ce24112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f55b4570082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e6671eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xaf,0xbf,0xaf,0xef,0x93,0xa0,0xef,0x93,0x97,0xef,0x93,0xa0,0xef,0x93,0xa0,0xef,0x97,0x97,0xef,0x93,0xa0,0xef,0x93,0x97,0xef,0xac,0xa0,0xef,0x93,0x97,0xef,0x93,0xa0,0xef,0x93,0x97,0xef,0x93,0xa0,0xef,0x93,0xa0,0xef,0x93,0x97,0xef,0x93,0xa0,0xef,0x93,0x97,0xef,0x93,0xa0,0xef,0x93,0x97,0xef,0x93,0xa0,0xef,0xa0,0xe0, Step #5: \363\257\277\257\357\223\240\357\223\227\357\223\240\357\223\240\357\227\227\357\223\240\357\223\227\357\254\240\357\223\227\357\223\240\357\223\227\357\223\240\357\223\240\357\223\227\357\223\240\357\223\227\357\223\240\357\223\227\357\223\240\357\240\340 Step #5: artifact_prefix='./'; Test unit written to ./oom-4075838fb0a2829b0d2ef68eca9ac4fab2b1a3c2 Step #5: Base64: 86+/r++ToO+Tl++ToO+ToO+Xl++ToO+Tl++soO+Tl++ToO+Tl++ToO+ToO+Tl++ToO+Tl++ToO+Tl++ToO+g4A== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3523 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3456720185 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5572c7263810, 0x5572c744d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5572c744d020,0x5572c92e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4075838fb0a2829b0d2ef68eca9ac4fab2b1a3c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4350 processed earlier; will process 6679 files now Step #5: ==126904== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5572bdd589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5572c43bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5572c43a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5572c43a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5572bdd5ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5572bdcbfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5572bdcba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5572bdd50c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5572c0d1ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5572c0d1ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5572c0d1ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5572c0d1ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5572c0d1ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5572c0d1ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5572c0d1ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5572c0d1ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5572c0d1ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5572c0d1ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5572c2fb4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5572bfce1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5572bfcecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5572bfa98c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5572bfa98c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5572bfa99738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5572bfa98874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5572bfa98874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5572bfa98874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5572c43a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5572c43ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5572c4393699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5572c43be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa1b977082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5572bdcb8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x6b,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b, Step #5: }{0,} {0,} ks{0,} {0,}${0,} {0,} {0,}}{0,} {0,} {0,}${0,} {0,} { Step #5: artifact_prefix='./'; Test unit written to ./oom-5968eba11e65a560a7b2fc47c26a5a6d7fb183fe Step #5: Base64: fXswLH0gezAsfSBrc3swLH0gezAsfSR7MCx9IHswLH0gezAsfX17MCx9IHswLH0gezAsfSR7MCx9IHswLH0gew== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3524 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3457213040 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb30f98810, 0x55bb3118201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb31182020,0x55bb3301a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5968eba11e65a560a7b2fc47c26a5a6d7fb183fe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4351 processed earlier; will process 6678 files now Step #5: #1 pulse cov: 3955 ft: 3956 exec/s: 0 rss: 172Mb Step #5: ==126940== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bb27a8d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb2e0f2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb2e0d55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb2e0d54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb27a93d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb279f4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb279ef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb27a85c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb2aa54f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb2aa54f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb2aa54f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb2aa54f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb2aa54f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb2aa54f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb2aa54f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb2aa54f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb2aa54f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb2aa54f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb2cce9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb29a16b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb29a21be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb297cdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb297cdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb297ce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb297cd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb297cd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb297cd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb2e0d7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb2e0e0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb2e0c8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb2e0f3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1e750f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb279edb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x6c,0x20,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc, Step #5: <?l \341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-877371327532c19026ed6010911443645f97e39e Step #5: Base64: PD9sIOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3525 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3457741822 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e37eccc810, 0x55e37eeb601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e37eeb6020,0x55e380d4e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/877371327532c19026ed6010911443645f97e39e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4353 processed earlier; will process 6676 files now Step #5: ==126976== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e3757c19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e37be26898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e37be095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e37be094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e3757c7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e375728b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e375723355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e3757b9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e378788f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e378788f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e378788f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e378788f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e378788f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e378788f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e378788f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e378788f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e378788f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e378788f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e37aa1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e37774ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e377755be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e377501c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e377501c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e377502738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e377501874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e377501874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e377501874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e37be0babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e37be14928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e37bdfc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e37be27112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9fdeccd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e375721b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf2,0xa0,0x8f,0x88,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0x93,0xf3,0xa0,0x82,0x99,0xf3,0xa0,0x87,0x87,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0xa9,0xf4,0x87,0x80,0x93,0xf3,0xa0,0x80,0x99,0xf0,0xb5,0x88,0x92,0xf0,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf3,0xa0,0x81,0xa1,0xf4,0x83,0x80,0x9f,0xf3,0xa0,0xa0,0x99,0xf0,0xb5,0x87,0x88, Step #5: \362\240\217\210\364\203\200\251\364\207\200\223\363\240\202\231\363\240\207\207\364\203\200\251\364\207\200\251\364\207\200\223\363\240\200\231\360\265\210\222\360\265\207\210\364\203\207\210\363\240\201\241\364\203\200\237\363\240\240\231\360\265\207\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-3469233b85da0b7b5c963eefa3ad661f5a19bb3d Step #5: Base64: 8qCPiPSDgKn0h4CT86CCmfOgh4f0g4Cp9IeAqfSHgJPzoICZ8LWIkvC1h4j0g4eI86CBofSDgJ/zoKCZ8LWHiA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3526 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3458226777 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56493ee37810, 0x56493f02101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56493f021020,0x564940eb90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3469233b85da0b7b5c963eefa3ad661f5a19bb3d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4354 processed earlier; will process 6675 files now Step #5: ==127012== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56493592c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56493bf91898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56493bf745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56493bf744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564935932d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564935893b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56493588e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564935924c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5649388f3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5649388f3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5649388f3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5649388f3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5649388f3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5649388f3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5649388f3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5649388f3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5649388f3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5649388f3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56493ab88f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649378b5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649378c0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56493766cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56493766cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56493766d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56493766c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56493766c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56493766c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56493bf76abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56493bf7f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56493bf67699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56493bf92112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f79793fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56493588cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x30,0xe0,0xa6,0xa1,0xe0,0xb7,0x8a,0xe0,0xa7,0x9d,0xe1,0xa5,0xae,0xe2,0x80,0xaa,0xe2,0x80,0x8c,0x38,0xe0,0xa6,0xa1,0xe0,0xb7,0x8a,0xe0,0xa7,0x9d,0xe1,0xa5,0x9b,0xe2,0x80,0xaa,0xe2,0x80,0x8c,0x38,0x33,0x3c,0x73,0x79,0x6d,0x62,0x6f,0x6c,0x3e,0x19,0x73,0x76,0x3f,0x52, Step #5: <svg><text>0\340\246\241\340\267\212\340\247\235\341\245\256\342\200\252\342\200\2148\340\246\241\340\267\212\340\247\235\341\245\233\342\200\252\342\200\21483<symbol>\031sv?R Step #5: artifact_prefix='./'; Test unit written to ./oom-766cb7753a1d540d901d7d79e3844d14ef798bb4 Step #5: Base64: PHN2Zz48dGV4dD4w4Kah4LeK4Ked4aWu4oCq4oCMOOCmoeC3iuCnneGlm+KAquKAjDgzPHN5bWJvbD4Zc3Y/Ug== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3527 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3458711172 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d01736810, 0x557d0192001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d01920020,0x557d037b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/766cb7753a1d540d901d7d79e3844d14ef798bb4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4355 processed earlier; will process 6674 files now Step #5: ==127048== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557cf822b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557cfe890898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557cfe8735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557cfe8734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557cf8231d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557cf8192b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557cf818d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557cf8223c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557cfb1f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557cfb1f2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557cfb1f2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557cfb1f2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557cfb1f2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557cfb1f2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557cfb1f2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557cfb1f2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557cfb1f2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557cfb1f2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557cfd487f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557cfa1b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557cfa1bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557cf9f6bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557cf9f6bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557cf9f6c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557cf9f6b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557cf9f6b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557cf9f6b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557cfe875abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557cfe87e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557cfe866699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557cfe891112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f42eab67082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557cf818bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc6,0xb2,0xc6,0xa9,0xd8,0xbd,0xc6,0xb2,0xd6,0xb2,0xd0,0x9b,0xc3,0xb2,0xd4,0xa9,0xda,0xbd,0xc6,0x9b,0xc3,0x81,0xda,0xbd,0xc6,0xb2,0xd6,0xb2,0xd0,0x9b,0xc3,0xbd,0xcc,0xb2,0xc7,0xa9,0xc7,0xb2,0xd6,0xa9,0xc6,0xb2,0xd4,0xa9,0xc6,0xb2,0xd4,0xbd,0xcc,0xb2,0xc7,0xa9,0xc7,0xb2,0xd6,0xa9,0xc6,0xb2,0xd4,0xa9,0xc6,0xb2,0xd4,0xb2, Step #5: \306\262\306\251\330\275\306\262\326\262\320\233\303\262\324\251\332\275\306\233\303\201\332\275\306\262\326\262\320\233\303\275\314\262\307\251\307\262\326\251\306\262\324\251\306\262\324\275\314\262\307\251\307\262\326\251\306\262\324\251\306\262\324\262 Step #5: artifact_prefix='./'; Test unit written to ./oom-c8e6e04bf588adee24806b204ec21c2fbe58eab1 Step #5: Base64: xrLGqdi9xrLWstCbw7LUqdq9xpvDgdq9xrLWstCbw73Mssepx7LWqcay1KnGstS9zLLHqcey1qnGstSpxrLUsg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3528 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3459205151 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560ec9abf810, 0x560ec9ca901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560ec9ca9020,0x560ecbb410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c8e6e04bf588adee24806b204ec21c2fbe58eab1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4356 processed earlier; will process 6673 files now Step #5: ==127084== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560ec05b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560ec6c19898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560ec6bfc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560ec6bfc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560ec05bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560ec051bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560ec0516355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560ec05acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560ec357bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560ec357bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560ec357bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560ec357bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560ec357bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560ec357bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560ec357bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560ec357bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560ec357bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560ec357bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560ec5810f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560ec253db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560ec2548be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560ec22f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560ec22f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560ec22f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560ec22f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560ec22f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560ec22f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560ec6bfeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560ec6c07928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560ec6bef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560ec6c1a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6d8c18e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560ec0514b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85, Step #5: \302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-9c973ff1b10b2bbd6e8fa9cb2095cdbbf8684c5e Step #5: Base64: woXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3529 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3459677204 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dcac182810, 0x55dcac36c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dcac36c020,0x55dcae2040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c973ff1b10b2bbd6e8fa9cb2095cdbbf8684c5e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4357 processed earlier; will process 6672 files now Step #5: ==127120== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dca2c779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dca92dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dca92bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dca92bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dca2c7dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dca2bdeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dca2bd9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dca2c6fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dca5c3ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dca5c3ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dca5c3ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dca5c3ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dca5c3ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dca5c3ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dca5c3ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dca5c3ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dca5c3ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dca5c3ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dca7ed3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dca4c00b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dca4c0bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dca49b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dca49b7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dca49b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dca49b7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dca49b7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dca49b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dca92c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dca92ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dca92b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dca92dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f986bac7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dca2bd7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x7a,0x2,0x2a,0x3b,0x7a,0x79,0x2a,0x78,0x7a,0x2,0x2a,0x7a,0x78,0x7d,0x2a,0x78,0x7a,0x2,0x2a,0x3b,0x7a,0x79,0x2a,0x78,0x7a,0x2,0x2a,0x7a,0x78,0x7d,0x2a,0x78,0x7a,0x2,0x2a,0x3b,0x7a,0x79,0x2a,0x78,0x7a,0x2,0x2a,0x7a,0x78,0x7d,0x2a,0x78,0x7a,0x2,0x2a,0x3b,0x7a,0x79,0x2a,0x78,0x7a,0x2,0x2a,0x7a,0x78,0x7d,0x2a, Step #5: xz\002*;zy*xz\002*zx}*xz\002*;zy*xz\002*zx}*xz\002*;zy*xz\002*zx}*xz\002*;zy*xz\002*zx}* Step #5: artifact_prefix='./'; Test unit written to ./oom-b11e1c957d524e8abe9fa220aec808161ee38181 Step #5: Base64: eHoCKjt6eSp4egIqenh9Knh6Aio7enkqeHoCKnp4fSp4egIqO3p5Knh6Aip6eH0qeHoCKjt6eSp4egIqenh9Kg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3530 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3460163108 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a5d596d810, 0x55a5d5b5701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a5d5b57020,0x55a5d79ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b11e1c957d524e8abe9fa220aec808161ee38181' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4358 processed earlier; will process 6671 files now Step #5: ==127156== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a5cc4629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a5d2ac7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a5d2aaa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a5d2aaa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a5cc468d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a5cc3c9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a5cc3c4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a5cc45ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a5cf429f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a5cf429f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a5cf429f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a5cf429f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a5cf429f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a5cf429f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a5cf429f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a5cf429f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a5cf429f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a5cf429f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a5d16bef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a5ce3ebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a5ce3f6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a5ce1a2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a5ce1a2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a5ce1a3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a5ce1a2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a5ce1a2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a5ce1a2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a5d2aacabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a5d2ab5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a5d2a9d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a5d2ac8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9566c05082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a5cc3c2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcc,0xbf,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb2,0xcc,0xb2,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb2,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb4,0xcc,0xb3,0xcc,0xb4,0xcc,0xb4,0xcc,0xb2,0xcc,0xb4,0xcc,0xb4,0xcc,0xb2,0xcc,0xb4,0xcc,0xb4,0xcc,0xb2,0xcc,0xb2,0xcc,0xb4,0xcc,0xb2,0xcc,0xb4, Step #5: \314\277\314\264\314\264\314\264\314\264\314\264\314\264\314\264\314\262\314\262\314\264\314\264\314\264\314\262\314\264\314\264\314\264\314\264\314\263\314\264\314\264\314\262\314\264\314\264\314\262\314\264\314\264\314\262\314\262\314\264\314\262\314\264 Step #5: artifact_prefix='./'; Test unit written to ./oom-e2198a5b67a4d677b24721b9beec1fe77a7f0546 Step #5: Base64: zL/MtMy0zLTMtMy0zLTMtMyyzLLMtMy0zLTMssy0zLTMtMy0zLPMtMy0zLLMtMy0zLLMtMy0zLLMssy0zLLMtA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3531 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3460642217 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5609a62bc810, 0x5609a64a601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5609a64a6020,0x5609a833e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e2198a5b67a4d677b24721b9beec1fe77a7f0546' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4359 processed earlier; will process 6670 files now Step #5: #1 pulse cov: 3569 ft: 3570 exec/s: 0 rss: 173Mb Step #5: ==127192== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56099cdb19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5609a3416898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5609a33f95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5609a33f94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56099cdb7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56099cd18b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56099cd13355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56099cda9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56099fd78f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56099fd78f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56099fd78f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56099fd78f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56099fd78f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56099fd78f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56099fd78f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56099fd78f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56099fd78f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56099fd78f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5609a200df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56099ed3ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56099ed45be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56099eaf1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56099eaf1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56099eaf2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56099eaf1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56099eaf1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56099eaf1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5609a33fbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5609a3404928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5609a33ec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5609a3417112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f73b489d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56099cd11b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x37,0x2f,0x5d,0x27,0x27,0x27,0x2f,0x27,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $''''-=<''''''''''''-=<''7/]'''/'=''''''/'''''''''''''.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-6248db3c91465cb4dde6923b52c259eeff329a9c Step #5: Base64: JCcnJyctPTwnJycnJycnJycnJyctPTwnJzcvXScnJy8nPScnJycnJy8nJycnJycnJycnJycnLicnJycuJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3532 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3461169146 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55719a3ba810, 0x55719a5a401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55719a5a4020,0x55719c43c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6248db3c91465cb4dde6923b52c259eeff329a9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4361 processed earlier; will process 6668 files now Step #5: #1 pulse cov: 11267 ft: 11268 exec/s: 0 rss: 190Mb Step #5: ==127228== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557190eaf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557197514898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571974f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571974f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557190eb5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557190e16b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557190e11355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557190ea7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557193e76f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557193e76f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557193e76f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557193e76f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557193e76f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557193e76f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557193e76f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557193e76f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557193e76f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557193e76f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55719610bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557192e38b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557192e43be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557192befc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557192befc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557192bf0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557192bef874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557192bef874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557192bef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571974f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557197502928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571974ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557197515112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6908668082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557190e0fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x25,0x2f,0x3e,0x3c,0x1,0x2f,0x3e,0x3c,0x25,0x2f,0x3e,0x3c,0x1,0x2f,0x3e,0x3c,0x25,0x2f,0x3e,0x3c,0x1,0x2f,0x3e,0x3c,0x25,0x2f,0x3e,0x3c,0x1,0x2f,0x3e,0x3c,0x25,0x2f,0x3e,0x3c,0x1,0x2f,0x3e,0x3c,0x25,0x2f,0x3e,0x3c,0x1,0x2f,0x3e,0x3c,0x25,0x2f,0x3e,0x3c,0x1,0x2f,0x3e,0x3c,0x25,0x2f,0x3e,0x3c,0x1,0x2f,0x3e, Step #5: <%/><\001/><%/><\001/><%/><\001/><%/><\001/><%/><\001/><%/><\001/><%/><\001/><%/><\001/> Step #5: artifact_prefix='./'; Test unit written to ./oom-42a78468bf3c03691c214880040d71f9bc445a29 Step #5: Base64: PCUvPjwBLz48JS8+PAEvPjwlLz48AS8+PCUvPjwBLz48JS8+PAEvPjwlLz48AS8+PCUvPjwBLz48JS8+PAEvPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3533 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3461724037 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9ed49c810, 0x55e9ed68601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9ed686020,0x55e9ef51e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/42a78468bf3c03691c214880040d71f9bc445a29' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4363 processed earlier; will process 6666 files now Step #5: ==127264== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e9e3f919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9ea5f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9ea5d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9ea5d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9e3f97d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e9e3ef8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e9e3ef3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9e3f89c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e9e6f58f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e9e6f58f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e9e6f58f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e9e6f58f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e9e6f58f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e9e6f58f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e9e6f58f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e9e6f58f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e9e6f58f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e9e6f58f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9e91edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e9e5f1ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e9e5f25be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9e5cd1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9e5cd1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9e5cd2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9e5cd1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9e5cd1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9e5cd1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e9ea5dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9ea5e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e9ea5cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e9ea5f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5677a62082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e9e3ef1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x6,0xa,0x4,0xa,0x2,0xc7,0x88,0xa,0x6,0xa,0x4,0xa,0x2,0xc7,0x88,0xa,0x6,0xa,0x4,0xa,0x2,0xc7,0x88,0xa,0x6,0xa,0x4,0xa,0x2,0xc7,0x88,0xa,0x6,0xa,0x4,0xa,0x2,0xc7,0x88,0xa,0x6,0xa,0x4,0xa,0x2,0xc7,0x88,0xa,0x6,0xa,0x4,0xa,0x2,0xc7,0x88,0xa,0x6,0xa,0x4,0xa,0x2,0xc7,0x88, Step #5: \012\006\012\004\012\002\307\210\012\006\012\004\012\002\307\210\012\006\012\004\012\002\307\210\012\006\012\004\012\002\307\210\012\006\012\004\012\002\307\210\012\006\012\004\012\002\307\210\012\006\012\004\012\002\307\210\012\006\012\004\012\002\307\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-02324fedea049a4c6637a4c2e69a6c0ee6770709 Step #5: Base64: CgYKBAoCx4gKBgoECgLHiAoGCgQKAseICgYKBAoCx4gKBgoECgLHiAoGCgQKAseICgYKBAoCx4gKBgoECgLHiA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3534 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3462225304 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a11e1a810, 0x563a1200401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a12004020,0x563a13e9c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/02324fedea049a4c6637a4c2e69a6c0ee6770709' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4364 processed earlier; will process 6665 files now Step #5: #1 pulse cov: 10626 ft: 10627 exec/s: 0 rss: 191Mb Step #5: ==127300== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563a0890f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a0ef74898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a0ef575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a0ef574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a08915d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a08876b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a08871355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a08907c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a0b8d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a0b8d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a0b8d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a0b8d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a0b8d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a0b8d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a0b8d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a0b8d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a0b8d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a0b8d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a0db6bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a0a898b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a0a8a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a0a64fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a0a64fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a0a650738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a0a64f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a0a64f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a0a64f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a0ef59abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a0ef62928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a0ef4a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a0ef75112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f25bf8a7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a0886fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0,0xa,0x2,0x2a,0x0, Step #5: \012\002*\000\012\002*\000\012\002*\000\012\002*\000\012\002*\000\012\002*\000\012\002*\000\012\002*\000\012\002*\000\012\002*\000\012\002*\000\012\002*\000\012\002*\000\012\002*\000\012\002*\000\012\002*\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-af0f97833bafc7a5cccfc1b95fd02b1b681f0124 Step #5: Base64: CgIqAAoCKgAKAioACgIqAAoCKgAKAioACgIqAAoCKgAKAioACgIqAAoCKgAKAioACgIqAAoCKgAKAioACgIqAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3535 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3462784024 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5606abf58810, 0x5606ac14201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5606ac142020,0x5606adfda0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af0f97833bafc7a5cccfc1b95fd02b1b681f0124' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4366 processed earlier; will process 6663 files now Step #5: ==127336== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5606a2a4d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5606a90b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606a90955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606a90954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5606a2a53d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5606a29b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5606a29af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5606a2a45c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5606a5a14f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5606a5a14f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5606a5a14f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5606a5a14f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5606a5a14f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5606a5a14f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5606a5a14f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5606a5a14f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5606a5a14f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5606a5a14f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606a7ca9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5606a49d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5606a49e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5606a478dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5606a478dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5606a478e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5606a478d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5606a478d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5606a478d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5606a9097abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5606a90a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5606a9088699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5606a90b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f46f983f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5606a29adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0xa,0x2b,0xa,0x26,0xa,0x42,0xa,0x26,0xa,0x74,0xa,0x74,0xa,0x74,0xa,0x74,0xa,0x74,0xa,0x6b,0xa,0x46,0xa,0x74,0xa,0x74,0xa,0x74,0xa,0x74,0xa,0x49,0xa,0x74,0xa,0x74,0xa,0x74,0xa,0x74,0xa,0x74,0xa,0x6b,0xa,0x46,0xa,0x7a,0xa,0x74,0xa,0x74,0xa,0x49,0xa,0x74,0xa,0x74,0xa,0x75,0xa,0x74,0xa, Step #5: B\012+\012&\012B\012&\012t\012t\012t\012t\012t\012k\012F\012t\012t\012t\012t\012I\012t\012t\012t\012t\012t\012k\012F\012z\012t\012t\012I\012t\012t\012u\012t\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-5166ebcaf242b53c88eec45dcd351a4adc97a5a0 Step #5: Base64: QgorCiYKQgomCnQKdAp0CnQKdAprCkYKdAp0CnQKdApJCnQKdAp0CnQKdAprCkYKegp0CnQKSQp0CnQKdQp0Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3536 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3463285751 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56501564c810, 0x56501583601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565015836020,0x5650176ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5166ebcaf242b53c88eec45dcd351a4adc97a5a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4367 processed earlier; will process 6662 files now Step #5: ==127372== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56500c1419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5650127a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5650127895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5650127894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56500c147d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56500c0a8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56500c0a3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56500c139c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56500f108f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56500f108f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56500f108f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56500f108f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56500f108f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56500f108f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56500f108f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56500f108f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56500f108f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56500f108f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56501139df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56500e0cab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56500e0d5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56500de81c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56500de81c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56500de82738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56500de81874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56500de81874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56500de81874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56501278babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565012794928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56501277c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5650127a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd9c0357082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56500c0a1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4c,0x4c,0x4b,0x4b,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4b,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4b,0x4c,0x4c,0x4c,0x4c,0x4c,0x4b,0x4c,0x4c, Step #5: KKKKKKKKKKKKKLLKKLLLLLLLLLLKKKKKKKKKKKKKKKLLLLLLLLLLLLLKLLLLLKLL Step #5: artifact_prefix='./'; Test unit written to ./oom-219842b2e6fa40fc1bfb70cd4da4cf60daedfaec Step #5: Base64: S0tLS0tLS0tLS0tLS0xMS0tMTExMTExMTExMS0tLS0tLS0tLS0tLS0tLTExMTExMTExMTExMTEtMTExMTEtMTA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3537 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3463773840 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56538790f810, 0x565387af901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565387af9020,0x5653899910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/219842b2e6fa40fc1bfb70cd4da4cf60daedfaec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4368 processed earlier; will process 6661 files now Step #5: ==127408== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56537e4049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565384a69898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565384a4c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565384a4c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56537e40ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56537e36bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56537e366355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56537e3fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5653813cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5653813cbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5653813cbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5653813cbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5653813cbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5653813cbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5653813cbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5653813cbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5653813cbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5653813cbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565383660f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56538038db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565380398be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565380144c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565380144c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565380145738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565380144874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565380144874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565380144874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565384a4eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565384a57928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565384a3f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565384a6a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8827382082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56537e364b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2f,0x33,0x0,0x54,0x49,0x4c,0x0,0xea,0xa0,0x80,0xba,0x0,0x5,0x0,0x31,0x33,0x24,0x0,0x0,0xf3,0xa0,0x80,0xba,0x0,0x5,0x0,0x31,0x33,0x24,0x0,0x54,0x44,0x41,0x0,0x0,0x54,0x44,0x41,0x0,0x0,0x5,0x0,0x36,0x31,0x34,0x75,0x67,0x59,0x45,0x47,0xb0,0x0,0x0,0x30,0x31,0x34,0x39, Step #5: \000\000\000\000\000\000\000/3\000TIL\000\352\240\200\272\000\005\00013$\000\000\363\240\200\272\000\005\00013$\000TDA\000\000TDA\000\000\005\000614ugYEG\260\000\0000149 Step #5: artifact_prefix='./'; Test unit written to ./oom-5f1cd27285cd84a6f99f07c320f68b81292030cf Step #5: Base64: AAAAAAAAAC8zAFRJTADqoIC6AAUAMTMkAADzoIC6AAUAMTMkAFREQQAAVERBAAAFADYxNHVnWUVHsAAAMDE0OQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3538 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3464259571 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5654ecbf6810, 0x5654ecde001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5654ecde0020,0x5654eec780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f1cd27285cd84a6f99f07c320f68b81292030cf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4369 processed earlier; will process 6660 files now Step #5: #1 pulse cov: 3531 ft: 3532 exec/s: 0 rss: 174Mb Step #5: ==127444== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5654e36eb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5654e9d50898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5654e9d335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5654e9d334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5654e36f1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5654e3652b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5654e364d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5654e36e3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5654e66b2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5654e66b2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5654e66b2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5654e66b2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5654e66b2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5654e66b2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5654e66b2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5654e66b2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5654e66b2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5654e66b2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5654e8947f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5654e5674b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5654e567fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5654e542bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5654e542bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5654e542c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5654e542b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5654e542b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5654e542b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5654e9d35abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5654e9d3e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5654e9d26699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5654e9d51112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6587b8e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5654e364bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc3,0x9e,0xdf,0x9f,0xdf,0x89,0xdf,0x9f,0xdf,0xa9,0xc3,0x9f,0xc3,0x9e,0xdf,0x9f,0xdf,0x89,0xc3,0x9e,0xdf,0x9f,0xdf,0x89,0xc3,0x89,0xc3,0x9e,0xdf,0x9f,0xdf,0x89,0xdf,0x9f,0xdf,0x9f,0xdf,0x89,0xc3,0x9e,0xdf,0xa0,0xdf,0x89,0xc3,0x9e,0xdf,0x9f,0xdf,0x89,0xc3,0x9e,0xdf,0x9f,0xdf,0x89,0xc3,0x9e,0xdf,0x9f,0xdf,0x89,0xdf,0x0, Step #5: \303\236\337\237\337\211\337\237\337\251\303\237\303\236\337\237\337\211\303\236\337\237\337\211\303\211\303\236\337\237\337\211\337\237\337\237\337\211\303\236\337\240\337\211\303\236\337\237\337\211\303\236\337\237\337\211\303\236\337\237\337\211\337\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-579885943596a5e0d941d7a4bdd6bf6a3ec5c54c Step #5: Base64: w57fn9+J35/fqcOfw57fn9+Jw57fn9+Jw4nDnt+f34nfn9+f34nDnt+g34nDnt+f34nDnt+f34nDnt+f34nfAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3539 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3464788493 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f6471ff810, 0x55f6473e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f6473e9020,0x55f6492810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/579885943596a5e0d941d7a4bdd6bf6a3ec5c54c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4371 processed earlier; will process 6658 files now Step #5: #1 pulse cov: 10496 ft: 10497 exec/s: 0 rss: 195Mb Step #5: ==127480== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f63dcf49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f644359898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f64433c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f64433c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f63dcfad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f63dc5bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f63dc56355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f63dcecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f640cbbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f640cbbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f640cbbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f640cbbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f640cbbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f640cbbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f640cbbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f640cbbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f640cbbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f640cbbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f642f50f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f63fc7db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f63fc88be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f63fa34c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f63fa34c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f63fa35738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f63fa34874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f63fa34874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f63fa34874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f64433eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f644347928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f64432f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f64435a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6c6425d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f63dc54b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x53,0x63,0x72,0x69,0x70,0x74,0x20,0x49,0x6e,0x66,0x6f,0x5d,0xd,0xa,0x3b,0x20,0x53,0x63,0x72,0x69,0x70,0x74,0x20,0x67,0x65,0x6e,0x65,0x72,0x61,0x74,0x65,0x64,0x20,0x62,0x79,0x20,0x41,0x65,0x67,0x69,0x73,0x75,0x62,0x20,0x32,0x2e,0x31,0x2e,0x37,0xd,0xa,0x3b,0x20,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77, Step #5: [Script Info]\015\012; Script generated by Aegisub 2.1.7\015\012; http://www Step #5: artifact_prefix='./'; Test unit written to ./oom-cb9a7a53542f02d5e7698de0cb8e532faebcd872 Step #5: Base64: W1NjcmlwdCBJbmZvXQ0KOyBTY3JpcHQgZ2VuZXJhdGVkIGJ5IEFlZ2lzdWIgMi4xLjcNCjsgaHR0cDovL3d3dw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3540 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3465400081 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e509ad4810, 0x55e509cbe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e509cbe020,0x55e50bb560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb9a7a53542f02d5e7698de0cb8e532faebcd872' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4373 processed earlier; will process 6656 files now Step #5: ==127516== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e5005c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e506c2e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e506c115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e506c114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e5005cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e500530b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e50052b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e5005c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e503590f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e503590f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e503590f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e503590f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e503590f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e503590f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e503590f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e503590f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e503590f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e503590f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e505825f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e502552b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e50255dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e502309c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e502309c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e50230a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e502309874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e502309874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e502309874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e506c13abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e506c1c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e506c04699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e506c2f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf00224082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e500529b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x65,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x65, Step #5: \005-----BEGIN -----\012dddddddddddddddddeddddddddddddddddddddddddddde Step #5: artifact_prefix='./'; Test unit written to ./oom-73a87361216631e9ca2f3d7bef93ee66879ef20d Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KZGRkZGRkZGRkZGRkZGRkZGRlZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3541 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3465889750 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561722e5f810, 0x56172304901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561723049020,0x561724ee10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/73a87361216631e9ca2f3d7bef93ee66879ef20d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4374 processed earlier; will process 6655 files now Step #5: #1 pulse cov: 11094 ft: 11095 exec/s: 0 rss: 191Mb Step #5: ==127552== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5617199549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56171ffb9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56171ff9c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56171ff9c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56171995ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5617198bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5617198b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56171994cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56171c91bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56171c91bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56171c91bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56171c91bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56171c91bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56171c91bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56171c91bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56171c91bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56171c91bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56171c91bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56171ebb0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56171b8ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56171b8e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56171b694c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56171b694c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56171b695738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56171b694874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56171b694874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56171b694874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56171ff9eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56171ffa7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56171ff8f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56171ffba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b15d20082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5617198b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xb,0x2d,0x3d,0x9,0x22,0x22,0xa,0x2b,0x3d,0x9,0x22,0x22,0x9,0x21,0x3d,0xd,0x22,0x22,0xa,0x3d,0x9,0x22,0x22,0x2f,0x3c,0xb,0x30,0x3d,0x9,0x22,0x22,0x9,0x21,0x3d,0xd,0x9,0x22,0x22,0x2f,0x3c,0xb,0x30,0x3d,0x9,0x22,0x22,0xb,0x2b,0x3d,0x9,0x22,0x22,0x9,0x21,0x3d,0xd,0x22,0x22,0xa,0x3d,0x9,0x22,0x22, Step #5: <\013-=\011\"\"\012+=\011\"\"\011!=\015\"\"\012=\011\"\"/<\0130=\011\"\"\011!=\015\011\"\"/<\0130=\011\"\"\013+=\011\"\"\011!=\015\"\"\012=\011\"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-a90195f1327d763d1f8d91538cd4288018d7fc29 Step #5: Base64: PAstPQkiIgorPQkiIgkhPQ0iIgo9CSIiLzwLMD0JIiIJIT0NCSIiLzwLMD0JIiILKz0JIiIJIT0NIiIKPQkiIg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3542 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3466439067 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a156ec4810, 0x55a1570ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1570ae020,0x55a158f460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a90195f1327d763d1f8d91538cd4288018d7fc29' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4376 processed earlier; will process 6653 files now Step #5: ==127588== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a14d9b99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a15401e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1540015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1540014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a14d9bfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a14d920b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a14d91b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a14d9b1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a150980f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a150980f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a150980f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a150980f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a150980f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a150980f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a150980f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a150980f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a150980f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a150980f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a152c15f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a14f942b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a14f94dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a14f6f9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a14f6f9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a14f6fa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a14f6f9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a14f6f9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a14f6f9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a154003abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a15400c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a153ff4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a15401f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf85776082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a14d919b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x22,0x31,0x8,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xd,0x0,0x0,0x0,0x1f,0x2e,0x74,0xe6,0x0,0x9,0x78,0x5d, Step #5: ID3\004*************\000\"1\010*******************************\015\000\000\000\037.t\346\000\011x] Step #5: artifact_prefix='./'; Test unit written to ./oom-be496369c62802a0021fa201f959c8cd03efea84 Step #5: Base64: SUQzBCoqKioqKioqKioqKioAIjEIKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKg0AAAAfLnTmAAl4XQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3543 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3466930641 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e31fa00810, 0x55e31fbea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e31fbea020,0x55e321a820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/be496369c62802a0021fa201f959c8cd03efea84' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4377 processed earlier; will process 6652 files now Step #5: ==127624== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e3164f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e31cb5a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e31cb3d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e31cb3d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e3164fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e31645cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e316457355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e3164edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e3194bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e3194bcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e3194bcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e3194bcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e3194bcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e3194bcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e3194bcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e3194bcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e3194bcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e3194bcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e31b751f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e31847eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e318489be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e318235c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e318235c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e318236738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e318235874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e318235874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e318235874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e31cb3fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e31cb48928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e31cb30699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e31cb5b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f621d308082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e316455b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x6,0x6a,0x4,0xa,0x2,0xd6,0xb1,0xa,0x6,0x6a,0x4,0xa,0x2,0xd6,0xb1,0xa,0x6,0x6a,0x4,0xa,0x2,0xd6,0xb1,0xa,0x6,0x6a,0x4,0xa,0x2,0xd6,0xb1,0xa,0x6,0x6a,0x4,0xa,0x2,0xd6,0xb1,0xa,0x6,0x6a,0x4,0xa,0x2,0xd6,0xb1,0xa,0x6,0x6a,0x4,0xa,0x2,0xd6,0xb1,0xa,0x6,0x6a,0x4,0xa,0x2,0xd6,0xb1, Step #5: \012\006j\004\012\002\326\261\012\006j\004\012\002\326\261\012\006j\004\012\002\326\261\012\006j\004\012\002\326\261\012\006j\004\012\002\326\261\012\006j\004\012\002\326\261\012\006j\004\012\002\326\261\012\006j\004\012\002\326\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-fcf42c944859bc82d2afc3e1c008caa340ad1c95 Step #5: Base64: CgZqBAoC1rEKBmoECgLWsQoGagQKAtaxCgZqBAoC1rEKBmoECgLWsQoGagQKAtaxCgZqBAoC1rEKBmoECgLWsQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3544 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3467423790 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5646f4fd4810, 0x5646f51be01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5646f51be020,0x5646f70560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fcf42c944859bc82d2afc3e1c008caa340ad1c95' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4378 processed earlier; will process 6651 files now Step #5: ==127660== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5646ebac99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5646f212e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5646f21115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5646f21114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5646ebacfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5646eba30b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5646eba2b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5646ebac1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5646eea90f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5646eea90f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5646eea90f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5646eea90f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5646eea90f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5646eea90f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5646eea90f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5646eea90f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5646eea90f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5646eea90f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5646f0d25f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5646eda52b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5646eda5dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5646ed809c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5646ed809c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5646ed80a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5646ed809874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5646ed809874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5646ed809874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5646f2113abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5646f211c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5646f2104699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5646f212f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcccc9fd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5646eba29b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf4,0x8f,0xbe,0x87,0xf4,0x84,0x80,0x80,0xf4,0x84,0x80,0x80,0xf4,0x8f,0x90,0xbf,0xf4,0x80,0xbe,0x94,0xf4,0x8f,0xbe,0x87,0xf4,0x80,0x87,0x80,0xf4,0x8f,0xbf,0x90,0xf4,0x8f,0x90,0xbf,0xf4,0x80,0xbe,0x80,0xf4,0x8f,0x90,0xbf,0xf4,0x80,0xbe,0x94,0xf4,0x8f,0xbe,0x87,0xf4,0x80,0x87,0x80,0xf4,0x8f,0xbf,0x90,0xf4,0x8f,0x90,0x80, Step #5: \364\217\276\207\364\204\200\200\364\204\200\200\364\217\220\277\364\200\276\224\364\217\276\207\364\200\207\200\364\217\277\220\364\217\220\277\364\200\276\200\364\217\220\277\364\200\276\224\364\217\276\207\364\200\207\200\364\217\277\220\364\217\220\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-07201aaa87dd9a7f0ed55299ab0dc539e315d417 Step #5: Base64: 9I++h/SEgID0hICA9I+Qv/SAvpT0j76H9ICHgPSPv5D0j5C/9IC+gPSPkL/0gL6U9I++h/SAh4D0j7+Q9I+QgA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3545 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3467919867 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a4ce845810, 0x55a4cea2f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a4cea2f020,0x55a4d08c70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/07201aaa87dd9a7f0ed55299ab0dc539e315d417' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4379 processed earlier; will process 6650 files now Step #5: ==127696== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a4c533a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a4cb99f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a4cb9825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a4cb9824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a4c5340d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a4c52a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a4c529c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a4c5332c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a4c8301f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a4c8301f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a4c8301f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a4c8301f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a4c8301f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a4c8301f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a4c8301f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a4c8301f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a4c8301f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a4c8301f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a4ca596f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a4c72c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a4c72cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a4c707ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a4c707ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a4c707b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a4c707a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a4c707a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a4c707a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a4cb984abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a4cb98d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a4cb975699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a4cb9a0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12d0e79082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a4c529ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0xbd,0xcd,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0x8d,0xc8,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0xbd,0xc2,0x8d,0xc8,0xbd, Step #5: \315\275\315\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\215\310\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\275\302\215\310\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-5801985743c9778d39c09697ca999941d31c243d Step #5: Base64: zb3NvcK9wr3CvcK9wr3CvcK9wr3CvcK9wr3CvcK9wo3IvcK9wr3CvcK9wr3CvcK9wr3CvcK9wr3CvcK9wo3IvQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3546 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3468407253 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560d6a03c810, 0x560d6a22601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560d6a226020,0x560d6c0be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5801985743c9778d39c09697ca999941d31c243d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4380 processed earlier; will process 6649 files now Step #5: ==127732== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560d60b319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560d67196898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560d671795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560d671794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560d60b37d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560d60a98b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560d60a93355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560d60b29c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560d63af8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560d63af8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560d63af8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560d63af8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560d63af8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560d63af8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560d63af8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560d63af8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560d63af8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560d63af8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560d65d8df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560d62abab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560d62ac5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560d62871c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560d62871c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560d62872738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560d62871874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560d62871874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560d62871874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560d6717babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560d67184928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560d6716c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560d67197112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b9ec90082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560d60a91b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x11,0x60,0x11,0x60,0x11,0x60,0x12,0x60,0x11,0x60,0x11,0x60,0x11,0x60,0x12,0x60,0x11,0x60,0x11,0x60,0x11,0x60,0x12,0x60,0x11,0x60,0x11,0x60,0x11,0x60,0x12,0x60,0x11,0x60,0x11,0x60,0x11,0x60,0x12,0x60,0x11,0x60,0x11,0x60,0x11,0x60,0x12,0x60,0x11,0x60,0x11,0x60,0x11,0x60,0x12,0x60,0x11,0x60,0x11,0x60,0x11,0x60,0x12,0x60, Step #5: \021`\021`\021`\022`\021`\021`\021`\022`\021`\021`\021`\022`\021`\021`\021`\022`\021`\021`\021`\022`\021`\021`\021`\022`\021`\021`\021`\022`\021`\021`\021`\022` Step #5: artifact_prefix='./'; Test unit written to ./oom-4adde44c757bafc640822c4fe35d7bb2969b833f Step #5: Base64: EWARYBFgEmARYBFgEWASYBFgEWARYBJgEWARYBFgEmARYBFgEWASYBFgEWARYBJgEWARYBFgEmARYBFgEWASYA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3547 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3469028711 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf6282c810, 0x55bf62a1601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf62a16020,0x55bf648ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4adde44c757bafc640822c4fe35d7bb2969b833f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4381 processed earlier; will process 6648 files now Step #5: #1 pulse cov: 3476 ft: 3477 exec/s: 0 rss: 174Mb Step #5: ==127768== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bf593219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf5f986898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf5f9695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf5f9694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf59327d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf59288b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf59283355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf59319c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf5c2e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf5c2e8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf5c2e8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf5c2e8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf5c2e8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf5c2e8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf5c2e8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf5c2e8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf5c2e8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf5c2e8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf5e57df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf5b2aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf5b2b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf5b061c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf5b061c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf5b062738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf5b061874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf5b061874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf5b061874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf5f96babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf5f974928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf5f95c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf5f987112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f811a959082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf59281b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc8,0x84,0xd6,0x84,0xcc,0xa5,0xcc,0xa5,0xc8,0x84,0xdd,0x84,0xd9,0x84,0xd6,0x84,0xc4,0xa5,0xc8,0x84,0xc8,0x84,0xdd,0x84,0xd9,0x84,0xd6,0x84,0xcc,0xa5,0xc8,0x84,0xdd,0xa4,0xd9,0xa5,0xcc,0xa5,0xc8,0x84,0xd6,0x84,0xcc,0xa5,0xc8,0x84,0xc8,0x84,0xdd,0x84,0xd9,0x84,0xd6,0x84,0xcc,0xa5,0xc8,0x84,0xdd,0x84,0xd9,0x84,0xd6,0x84, Step #5: \310\204\326\204\314\245\314\245\310\204\335\204\331\204\326\204\304\245\310\204\310\204\335\204\331\204\326\204\314\245\310\204\335\244\331\245\314\245\310\204\326\204\314\245\310\204\310\204\335\204\331\204\326\204\314\245\310\204\335\204\331\204\326\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-fd88d4fdf69919ef3aa3b7e7c850763616bf1db2 Step #5: Base64: yITWhMylzKXIhN2E2YTWhMSlyITIhN2E2YTWhMylyITdpNmlzKXIhNaEzKXIhMiE3YTZhNaEzKXIhN2E2YTWhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3548 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3469559289 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ad6a61810, 0x561ad6c4b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ad6c4b020,0x561ad8ae30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fd88d4fdf69919ef3aa3b7e7c850763616bf1db2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4383 processed earlier; will process 6646 files now Step #5: ==127804== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561acd5569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561ad3bbb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561ad3b9e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561ad3b9e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561acd55cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561acd4bdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561acd4b8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561acd54ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561ad051df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561ad051df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561ad051df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561ad051df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561ad051df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561ad051df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561ad051df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561ad051df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561ad051df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561ad051df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561ad27b2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561acf4dfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561acf4eabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561acf296c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561acf296c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561acf297738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561acf296874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561acf296874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561acf296874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561ad3ba0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561ad3ba9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561ad3b91699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561ad3bbc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1492ede082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561acd4b6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x36,0x2d,0x31,0x2d,0x36,0x20,0x31,0x3a,0x34,0x3a,0x37,0x2d,0x30,0xe3,0x82,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x9a,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xeb,0x81,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0xa0,0x73,0x0,0x0, Step #5: 6-1-6 1:4:7-0\343\202\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\232\343\200\200\343\200\200\343\200\200\343\200\200\353\201\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\240s\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bc497076b703117b4a6536a29dae5fc5dfca6720 Step #5: Base64: Ni0xLTYgMTo0OjctMOOCgOOAgOOAgOOAgOOAgOOAmuOAgOOAgOOAgOOAgOuBgOOAgOOAgOOAgOOAgOOAoHMAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3549 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3470046627 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55566a806810, 0x55566a9f001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55566a9f0020,0x55566c8880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bc497076b703117b4a6536a29dae5fc5dfca6720' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4384 processed earlier; will process 6645 files now Step #5: ==127840== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5556612fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555667960898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556679435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556679434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555661301d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555661262b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55566125d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5556612f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5556642c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5556642c2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5556642c2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5556642c2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5556642c2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5556642c2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5556642c2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5556642c2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5556642c2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5556642c2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555666557f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555663284b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55566328fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55566303bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55566303bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55566303c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55566303b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55566303b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55566303b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555667945abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55566794e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555667936699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555667961112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f021e17d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55566125bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa, Step #5: =\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-d3a92532824464618c22c6ae23ec6da75f132bb7 Step #5: Base64: PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3550 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3470536028 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55694a4d0810, 0x55694a6ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55694a6ba020,0x55694c5520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d3a92532824464618c22c6ae23ec6da75f132bb7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4385 processed earlier; will process 6644 files now Step #5: ==127876== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556940fc59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55694762a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55694760d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55694760d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556940fcbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556940f2cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556940f27355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556940fbdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556943f8cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556943f8cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556943f8cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556943f8cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556943f8cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556943f8cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556943f8cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556943f8cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556943f8cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556943f8cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556946221f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556942f4eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556942f59be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556942d05c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556942d05c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556942d06738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556942d05874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556942d05874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556942d05874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55694760fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556947618928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556947600699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55694762b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa1093be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556940f25b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0x88,0x30,0x0,0xb,0x0,0x7e,0x0,0x60,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x35,0x0,0x1b,0x0,0x0,0x60,0x0,0x60,0x31,0x0,0x1b,0x0,0x0,0x60,0x0,0x1b,0xb, Step #5: \337\2100\000\013\000~\000`\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0005\000\033\000\000`\000`1\000\033\000\000`\000\033\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-8246f1aa31ab2564fdce1547f66ea5abbfa740e4 Step #5: Base64: 34gwAAsAfgBgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA1ABsAAGAAYDEAGwAAYAAbCw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3551 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3471146859 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5588fab85810, 0x5588fad6f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5588fad6f020,0x5588fcc070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8246f1aa31ab2564fdce1547f66ea5abbfa740e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4386 processed earlier; will process 6643 files now Step #5: ==127912== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5588f167a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5588f7cdf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588f7cc25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588f7cc24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588f1680d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588f15e1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588f15dc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588f1672c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5588f4641f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5588f4641f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5588f4641f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5588f4641f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5588f4641f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5588f4641f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5588f4641f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5588f4641f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5588f4641f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5588f4641f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5588f68d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588f3603b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588f360ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588f33bac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588f33bac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588f33bb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588f33ba874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588f33ba874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588f33ba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5588f7cc4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5588f7ccd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5588f7cb5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5588f7ce0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff17b968082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588f15dab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0, Step #5: \360\235\205\260\360\235\205\260\360\235\205\251\360\235\205\251\360\235\205\251\360\235\205\251\360\235\205\251\360\235\205\251\360\235\205\251\360\235\205\260\360\235\205\251\360\235\205\251\360\235\205\251\360\235\205\260\360\235\205\260\360\235\205\260 Step #5: artifact_prefix='./'; Test unit written to ./oom-e843dc10cf5f20095fd5acddc7ddc8793c5f76fc Step #5: Base64: 8J2FsPCdhbDwnYWp8J2FqfCdhanwnYWp8J2FqfCdhanwnYWp8J2FsPCdhanwnYWp8J2FqfCdhbDwnYWw8J2FsA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3552 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3471632875 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f96e857810, 0x55f96ea4101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f96ea41020,0x55f9708d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e843dc10cf5f20095fd5acddc7ddc8793c5f76fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4387 processed earlier; will process 6642 files now Step #5: ==127948== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f96534c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f96b9b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f96b9945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f96b9944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f965352d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f9652b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f9652ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f965344c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f968313f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f968313f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f968313f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f968313f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f968313f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f968313f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f968313f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f968313f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f968313f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f968313f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f96a5a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f9672d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f9672e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f96708cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f96708cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f96708d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f96708c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f96708c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f96708c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f96b996abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f96b99f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f96b987699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f96b9b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5f548cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f9652acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27,0x5c,0x27, Step #5: \\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\'\\' Step #5: artifact_prefix='./'; Test unit written to ./oom-f8f264d8e7f3f44a7687a92e27228bbe337aa60a Step #5: Base64: XCdcJ1wnXCdcJ1wnXCdcJ1wnXCdcJ1wnXCdcJ1wnXCdcJ1wnXCdcJ1wnXCdcJ1wnXCdcJ1wnXCdcJ1wnXCdcJw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3553 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3472121988 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564b15b01810, 0x564b15ceb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564b15ceb020,0x564b17b830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8f264d8e7f3f44a7687a92e27228bbe337aa60a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4388 processed earlier; will process 6641 files now Step #5: ==127984== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564b0c5f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564b12c5b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564b12c3e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564b12c3e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564b0c5fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564b0c55db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564b0c558355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564b0c5eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564b0f5bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564b0f5bdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564b0f5bdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564b0f5bdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564b0f5bdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564b0f5bdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564b0f5bdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564b0f5bdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564b0f5bdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564b0f5bdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564b11852f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564b0e57fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564b0e58abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564b0e336c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564b0e336c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564b0e337738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564b0e336874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564b0e336874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564b0e336874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564b12c40abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564b12c49928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564b12c31699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564b12c5c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffb8cba1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564b0c556b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x20,0x30,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x3a,0x24,0x2d,0x5b,0xee,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\000/\000\017\017\017\017\0171\017\0171\021\0171\017s [8 0\017\017\017\0171\017-1[&\021:\021-\017\017\017\017\0171\021\0171\021-::$-[\356$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-93c23face9a808aa8f92c4b6a8804b185b8fa0d7 Step #5: Base64: JAAALwAAAC8AAC8ADw8PDw8xDw8xEQ8xD3MgWzggMA8PDw8xDy0xWyYROhEtDw8PDw8xEQ8xES06OiQtW+4kWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3554 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3472618033 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e6402b810, 0x555e6421501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e64215020,0x555e660ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93c23face9a808aa8f92c4b6a8804b185b8fa0d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4389 processed earlier; will process 6640 files now Step #5: ==128020== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555e5ab209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e61185898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e611685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e611684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e5ab26d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e5aa87b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e5aa82355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e5ab18c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e5dae7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e5dae7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e5dae7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e5dae7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e5dae7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e5dae7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e5dae7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e5dae7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e5dae7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e5dae7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e5fd7cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e5caa9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e5cab4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e5c860c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e5c860c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e5c861738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e5c860874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e5c860874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e5c860874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e6116aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e61173928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e6115b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e61186112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb6b822082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e5aa80b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0xa7,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x87,0x4b,0x2d,0xdd,0x87,0x4b,0x6d,0xdd,0x86,0x4c,0x2d,0xdf,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x87,0x4b,0x2d,0xdd,0xff, Step #5: K-\335\210K-\335\210K-\335\210K-\335\247K-\335\210K-\335\207K-\335\207Km\335\206L-\337\210K-\335\210K-\335\210K-\335\210K-\335\210K-\335\210K-\335\207K-\335\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-837bd44d27c7f64c48a7fd067e32058687aa7868 Step #5: Base64: Sy3diEst3YhLLd2ISy3dp0st3YhLLd2HSy3dh0tt3YZMLd+ISy3diEst3YhLLd2ISy3diEst3YhLLd2HSy3d/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3555 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3473108778 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e691ab2810, 0x55e691c9c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e691c9c020,0x55e693b340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/837bd44d27c7f64c48a7fd067e32058687aa7868' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4390 processed earlier; will process 6639 files now Step #5: ==128056== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e6885a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e68ec0c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e68ebef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e68ebef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e6885add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e68850eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e688509355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e68859fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e68b56ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e68b56ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e68b56ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e68b56ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e68b56ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e68b56ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e68b56ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e68b56ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e68b56ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e68b56ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e68d803f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e68a530b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e68a53bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e68a2e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e68a2e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e68a2e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e68a2e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e68a2e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e68a2e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e68ebf1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e68ebfa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e68ebe2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e68ec0d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c21ead082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e688507b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xc5,0xb3,0xdd,0x8c,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xde,0x8c,0xc5,0x8c,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xde,0x8c,0xc5,0x84,0xdd,0x84,0xde,0x8c,0xc5,0x8c,0xdd,0x84,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xde,0x8c,0xc5,0x84,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xde,0x8c,0xc5,0xa3,0xc5,0xa3,0x22, Step #5: \"\305\263\335\214\335\204\305\204\335\204\336\214\305\214\335\204\305\204\335\204\305\204\335\204\336\214\305\204\335\204\336\214\305\214\335\204\335\204\305\204\335\204\336\214\305\204\335\204\305\204\335\204\305\204\335\204\336\214\305\243\305\243\" Step #5: artifact_prefix='./'; Test unit written to ./oom-87feb60697b47bf7588470dd7a2a4226ce7b94bf Step #5: Base64: IsWz3YzdhMWE3YTejMWM3YTFhN2ExYTdhN6MxYTdhN6MxYzdhN2ExYTdhN6MxYTdhMWE3YTFhN2E3ozFo8WjIg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3556 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3473595970 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f440445810, 0x55f44062f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f44062f020,0x55f4424c70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87feb60697b47bf7588470dd7a2a4226ce7b94bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4391 processed earlier; will process 6638 files now Step #5: ==128092== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f436f3a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f43d59f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f43d5825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f43d5824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f436f40d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f436ea1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f436e9c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f436f32c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f439f01f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f439f01f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f439f01f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f439f01f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f439f01f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f439f01f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f439f01f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f439f01f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f439f01f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f439f01f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f43c196f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f438ec3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f438ecebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f438c7ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f438c7ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f438c7b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f438c7a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f438c7a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f438c7a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f43d584abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f43d58d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f43d575699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f43d5a0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc31cfa8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f436e9ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0xe2,0x80,0x89,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0x2f,0x76,0x31,0x38,0x34,0x34,0x36,0x37,0x34,0x34,0x30,0x37,0x33,0x37,0x30,0x39,0x35,0xe2,0x80,0xae,0x35,0x31,0x36,0x31,0x34,0x0,0xf3,0xa0,0x81,0xb8,0x0,0x28,0xd,0x0,0x72,0x64,0x64,0x64,0xb5,0xf3,0xa0,0x81,0x87,0x64,0x64, Step #5: \341\240\216= \177\177\342\200\211\000\000(\342\200\256\000r+/v184467440737095\342\200\25651614\000\363\240\201\270\000(\015\000rddd\265\363\240\201\207dd Step #5: artifact_prefix='./'; Test unit written to ./oom-f1a58fb6a0356bb8bc62fd1f82b7888d79981ad9 Step #5: Base64: 4aCOPSB/f+KAiQAAKOKArgByKy92MTg0NDY3NDQwNzM3MDk14oCuNTE2MTQA86CBuAAoDQByZGRktfOggYdkZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3557 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3474084153 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5557c57f5810, 0x5557c59df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5557c59df020,0x5557c78770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f1a58fb6a0356bb8bc62fd1f82b7888d79981ad9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4392 processed earlier; will process 6637 files now Step #5: #1 pulse cov: 3739 ft: 3740 exec/s: 0 rss: 174Mb Step #5: ==128128== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5557bc2ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5557c294f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557c29325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557c29324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557bc2f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557bc251b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5557bc24c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557bc2e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557bf2b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557bf2b1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557bf2b1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557bf2b1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557bf2b1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557bf2b1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557bf2b1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557bf2b1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557bf2b1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557bf2b1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5557c1546f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557be273b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557be27ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5557be02ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5557be02ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5557be02b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5557be02a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5557be02a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5557be02a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557c2934abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557c293d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557c2925699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5557c2950112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f52ca96e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5557bc24ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xe1,0x9e,0x90,0xe1,0x9f,0x92,0x9,0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xe1,0x9e,0x90,0xe1,0x9f,0x92,0x9,0xa,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e,0xa,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text>\341\236\220\341\237\222\011<svg><text>\341\236\220\341\237\222\011\012</text></svg>\012</text></svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-90d39d3a5f3786df4fc1764f6c5879939ff438bf Step #5: Base64: PHN2Zz48dGV4dD7hnpDhn5IJPHN2Zz48dGV4dD7hnpDhn5IJCjwvdGV4dD48L3N2Zz4KPC90ZXh0Pjwvc3ZnPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3558 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3474617516 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fed944b810, 0x55fed963501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fed9635020,0x55fedb4cd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/90d39d3a5f3786df4fc1764f6c5879939ff438bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4394 processed earlier; will process 6635 files now Step #5: #1 pulse cov: 10943 ft: 10944 exec/s: 0 rss: 191Mb Step #5: #2 pulse cov: 11511 ft: 12336 exec/s: 0 rss: 193Mb Step #5: ==128164== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fecff409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fed65a5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fed65885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fed65884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fecff46d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fecfea7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fecfea2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fecff38c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fed2f07f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fed2f07f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fed2f07f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fed2f07f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fed2f07f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fed2f07f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fed2f07f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fed2f07f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fed2f07f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fed2f07f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fed519cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fed1ec9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fed1ed4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fed1c80c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fed1c80c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fed1c81738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fed1c80874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fed1c80874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fed1c80874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fed658aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fed6593928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fed657b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fed65a6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2613158082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fecfea0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xd9,0x82,0xdb,0x99,0xd3,0x8a,0xd9,0x84,0xd9,0x8a,0xd9,0x99,0xd3,0x8a,0xd9,0x9b,0xd3,0x84,0xdd,0x99,0xd3,0x82,0xdb,0x84,0xdd,0x9b,0xd2,0x82,0xd9,0x84,0xdd,0x99,0xd9,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x99,0xd3,0x8a,0xd9,0x84,0xd9,0x99,0xd3,0x8a,0xd9,0x84,0xdd,0x99,0xd3,0x82,0xd9,0x84,0xd9,0x9b, Step #5: \"\331\202\333\231\323\212\331\204\331\212\331\231\323\212\331\233\323\204\335\231\323\202\333\204\335\233\322\202\331\204\335\231\331\204\335\231\323\212\331\204\335\231\323\212\331\231\323\212\331\204\331\231\323\212\331\204\335\231\323\202\331\204\331\233 Step #5: artifact_prefix='./'; Test unit written to ./oom-ad67388f72e9919292dd6c9e0949566e58284202 Step #5: Base64: ItmC25nTitmE2YrZmdOK2ZvThN2Z04LbhN2b0oLZhN2Z2YTdmdOK2YTdmdOK2ZnTitmE2ZnTitmE3ZnTgtmE2Zs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3559 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3475216491 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b9d931c810, 0x55b9d950601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b9d9506020,0x55b9db39e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad67388f72e9919292dd6c9e0949566e58284202' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4397 processed earlier; will process 6632 files now Step #5: ==128200== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b9cfe119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b9d6476898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b9d64595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b9d64594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b9cfe17d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b9cfd78b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b9cfd73355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b9cfe09c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b9d2dd8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b9d2dd8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b9d2dd8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b9d2dd8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b9d2dd8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b9d2dd8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b9d2dd8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b9d2dd8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b9d2dd8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b9d2dd8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b9d506df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b9d1d9ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b9d1da5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b9d1b51c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b9d1b51c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b9d1b52738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b9d1b51874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b9d1b51874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b9d1b51874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b9d645babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b9d6464928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b9d644c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b9d6477112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f07cb3ed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b9cfd71b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0xe,0x1,0xa,0x14,0x0,0x14,0x0,0x14,0x0,0x14,0x0,0x14,0x0,0x3,0x1,0x13,0x14,0x0,0x14,0x0,0x3,0x1,0x13,0x14,0x0,0x3,0x1,0x13,0x3,0x1,0x13,0x14,0x0,0x14,0x0,0x3,0x1,0x13,0x14,0x0,0x14,0x0,0x14,0x0,0x14,0x0,0x3,0x1,0x13,0x14,0x0,0x14,0x0,0x3,0x1,0x13,0x14,0x0,0x3,0x1,0x13,0x2,0x1,0x13, Step #5: A\016\001\012\024\000\024\000\024\000\024\000\024\000\003\001\023\024\000\024\000\003\001\023\024\000\003\001\023\003\001\023\024\000\024\000\003\001\023\024\000\024\000\024\000\024\000\003\001\023\024\000\024\000\003\001\023\024\000\003\001\023\002\001\023 Step #5: artifact_prefix='./'; Test unit written to ./oom-0dce0456ef0ef587f4cc74c5a678c56b783d78c8 Step #5: Base64: QQ4BChQAFAAUABQAFAADARMUABQAAwETFAADARMDARMUABQAAwETFAAUABQAFAADARMUABQAAwETFAADARMCARM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3560 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3475700307 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c03166a810, 0x55c03185401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c031854020,0x55c0336ec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0dce0456ef0ef587f4cc74c5a678c56b783d78c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4398 processed earlier; will process 6631 files now Step #5: ==128236== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c02815f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c02e7c4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c02e7a75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c02e7a74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c028165d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c0280c6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c0280c1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c028157c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c02b126f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c02b126f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c02b126f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c02b126f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c02b126f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c02b126f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c02b126f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c02b126f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c02b126f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c02b126f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c02d3bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c02a0e8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c02a0f3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c029e9fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c029e9fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c029ea0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c029e9f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c029e9f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c029e9f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c02e7a9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c02e7b2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c02e79a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c02e7c5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7bd7c49082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c0280bfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x6c,0x20,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0x41,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc, Step #5: <?l \341\204\274\341\204\274\341\204\274\341\204\274\341\204\274A\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-36405357c54f230a10f0c3b7a203e5b269b3370c Step #5: Base64: PD9sIOGEvOGEvOGEvOGEvOGEvEHhhLzhhLzhhLzhhLzhhLzhhLzhhLzhhLzhhLzhhLzhhLzhhLzhhLzhhLzhhLw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3561 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3476191360 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5619705ae810, 0x56197079801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561970798020,0x5619726300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/36405357c54f230a10f0c3b7a203e5b269b3370c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4399 processed earlier; will process 6630 files now Step #5: ==128272== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5619670a39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56196d708898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56196d6eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56196d6eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5619670a9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56196700ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561967005355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56196709bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56196a06af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56196a06af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56196a06af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56196a06af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56196a06af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56196a06af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56196a06af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56196a06af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56196a06af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56196a06af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56196c2fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56196902cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561969037be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561968de3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561968de3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561968de4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561968de3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561968de3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561968de3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56196d6edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56196d6f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56196d6de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56196d709112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd1ffa02082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561967003b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x11,0xde,0xa6,0x0,0x21,0x0,0x0,0x2d,0x0,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x0,0x0,0x0,0x2e,0x3d,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x0,0x0,0x0,0x2e,0x3d,0x3d,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: \021\336\246\000!\000\000-\000.................\000\000\000.=..........\000\000\000.==...........\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6abbd438040b886bd4fcf97517f589c743980d99 Step #5: Base64: Ed6mACEAAC0ALi4uLi4uLi4uLi4uLi4uLi4AAAAuPS4uLi4uLi4uLi4AAAAuPT0uLi4uLi4uLi4uLgAAAAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3562 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3476678891 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555fe81aa810, 0x555fe839401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555fe8394020,0x555fea22c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6abbd438040b886bd4fcf97517f589c743980d99' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4400 processed earlier; will process 6629 files now Step #5: ==128308== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555fdec9f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555fe5304898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555fe52e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555fe52e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555fdeca5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555fdec06b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555fdec01355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555fdec97c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555fe1c66f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555fe1c66f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555fe1c66f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555fe1c66f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555fe1c66f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555fe1c66f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555fe1c66f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555fe1c66f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555fe1c66f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555fe1c66f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555fe3efbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555fe0c28b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555fe0c33be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555fe09dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555fe09dfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555fe09e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555fe09df874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555fe09df874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555fe09df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555fe52e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555fe52f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555fe52da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555fe5305112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f443f0ec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555fdebffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x2f,0x67,0xd2,0x86,0x51,0xd2,0x86,0x67,0xd2,0x86,0x51,0xd2,0x86,0x2e,0xd2,0x86,0x7a,0x67,0xd2,0x98,0xd2,0x86,0x67,0x67,0x67,0xd2,0x86,0xd2,0x86,0xd2,0x86,0x51,0x67,0xd2,0x86,0xd2,0x86,0xd2,0x86,0x2e,0xd2,0x86,0x67,0xd2,0x86,0xd2,0x86,0xd2,0x86,0xd2,0x86,0xd2,0x86,0xd2,0x86,0x67,0xd2,0x86,0x67,0xd2,0x86,0x51,0xd2,0x86, Step #5: </g\322\206Q\322\206g\322\206Q\322\206.\322\206zg\322\230\322\206ggg\322\206\322\206\322\206Qg\322\206\322\206\322\206.\322\206g\322\206\322\206\322\206\322\206\322\206\322\206g\322\206g\322\206Q\322\206 Step #5: artifact_prefix='./'; Test unit written to ./oom-e5bec5f01cb69e35b58bce9613f7478000e9a6aa Step #5: Base64: PC9n0oZR0oZn0oZR0oYu0oZ6Z9KY0oZnZ2fShtKG0oZRZ9KG0obShi7ShmfShtKG0obShtKG0oZn0oZn0oZR0oY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3563 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3477168457 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ae4ffd810, 0x559ae51e701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ae51e7020,0x559ae707f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e5bec5f01cb69e35b58bce9613f7478000e9a6aa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4401 processed earlier; will process 6628 files now Step #5: #1 pulse cov: 3910 ft: 3911 exec/s: 0 rss: 174Mb Step #5: ==128344== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559adbaf29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ae2157898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ae213a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ae213a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559adbaf8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559adba59b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559adba54355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559adbaeac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559adeab9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559adeab9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559adeab9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559adeab9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559adeab9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559adeab9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559adeab9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559adeab9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559adeab9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559adeab9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ae0d4ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559adda7bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559adda86be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559add832c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559add832c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559add833738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559add832874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559add832874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559add832874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ae213cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ae2145928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ae212d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ae2158112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0571966082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559adba52b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x8,0x0,0x7,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x7,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2e,0x0,0x2e,0x2b,0x42,0xdb,0xbe,0x7c,0xdb,0xbe,0x2b,0x2b,0x2b, Step #5: - \010\000\007\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\010\000\007\000\000\000\000\000\000\000\000\000\000\000\000\000\000.\000.+B\333\276|\333\276+++ Step #5: artifact_prefix='./'; Test unit written to ./oom-a9599901f5070c16abf2a60ee499f023ed4af7be Step #5: Base64: LSAIAAcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAAcAAAAAAAAAAAAAAAAAAC4ALitC2758274rKys= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3564 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3477703231 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f0008b0810, 0x55f000a9a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f000a9a020,0x55f0029320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9599901f5070c16abf2a60ee499f023ed4af7be' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4403 processed earlier; will process 6626 files now Step #5: ==128380== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eff73a59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55effda0a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55effd9ed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55effd9ed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eff73abd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eff730cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eff7307355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eff739dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55effa36cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55effa36cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55effa36cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55effa36cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55effa36cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55effa36cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55effa36cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55effa36cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55effa36cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55effa36cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55effc601f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eff932eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eff9339be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eff90e5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eff90e5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eff90e6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eff90e5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eff90e5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eff90e5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55effd9efabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55effd9f8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55effd9e0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55effda0b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5f78da4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eff7305b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd8,0x8a,0xd8,0x8b,0xd8,0x8b,0xd8,0x8a,0xd8,0x8c,0xd8,0x9f,0xd8,0x8b,0xd8,0x8b,0xd8,0x9b,0xd8,0x8b,0xd8,0x83,0xd5,0x92,0xd7,0x82,0xd8,0x8b,0xca,0x9b,0xd8,0x8b,0xd8,0x8b,0xd9,0x8b,0xd8,0x8b,0xdf,0x8c,0xd8,0x8b,0xd9,0x8b,0xd8,0x83,0xd8,0x8a,0xda,0x8b,0xd8,0x8b,0xd8,0x8b,0xd9,0x8b,0xd8,0x8b,0xd9,0x82,0xd8,0x9b,0x8b,0x2e,0x81, Step #5: \330\212\330\213\330\213\330\212\330\214\330\237\330\213\330\213\330\233\330\213\330\203\325\222\327\202\330\213\312\233\330\213\330\213\331\213\330\213\337\214\330\213\331\213\330\203\330\212\332\213\330\213\330\213\331\213\330\213\331\202\330\233\213.\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-1916bc320dd4d49ecacba81212f4673238acd056 Step #5: Base64: 2IrYi9iL2IrYjNif2IvYi9ib2IvYg9WS14LYi8qb2IvYi9mL2IvfjNiL2YvYg9iK2ovYi9iL2YvYi9mC2JuLLoE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3565 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3478194706 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5584ca018810, 0x5584ca20201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5584ca202020,0x5584cc09a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1916bc320dd4d49ecacba81212f4673238acd056' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4404 processed earlier; will process 6625 files now Step #5: ==128416== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5584c0b0d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5584c7172898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5584c71555dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5584c71554fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5584c0b13d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5584c0a74b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5584c0a6f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5584c0b05c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5584c3ad4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5584c3ad4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5584c3ad4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5584c3ad4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5584c3ad4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5584c3ad4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5584c3ad4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5584c3ad4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5584c3ad4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5584c3ad4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5584c5d69f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5584c2a96b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5584c2aa1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5584c284dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5584c284dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5584c284e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5584c284d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5584c284d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5584c284d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5584c7157abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5584c7160928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5584c7148699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5584c7173112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88eef00082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5584c0a6db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x51,0x0,0x0,0x0,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x6d,0x6d,0x74,0x53,0xd,0xd,0xf2,0xbf,0x9f,0x9f,0xe8,0xa1,0x80,0x7,0x7,0x7,0x7,0x7,0x7,0x6,0x6,0xe3,0x80,0x8c,0x6,0x7,0x7,0x7,0x7,0x7,0x7,0xee,0xa1,0x80,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xee,0xa1,0x80,0x0, Step #5: Q\000\000\000\007\007\007\007\007\007\007\007\007\007\007\007mmtS\015\015\362\277\237\237\350\241\200\007\007\007\007\007\007\006\006\343\200\214\006\007\007\007\007\007\007\356\241\200\000\000\000\000\000\000\000\000\000\000\000\356\241\200\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a3746216982927b4f9821210efe582be8ad3555b Step #5: Base64: UQAAAAcHBwcHBwcHBwcHB21tdFMNDfK/n5/ooYAHBwcHBwcGBuOAjAYHBwcHBwfuoYAAAAAAAAAAAAAAAO6hgAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3566 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3478684829 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c12a0e7810, 0x55c12a2d101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c12a2d1020,0x55c12c1690e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a3746216982927b4f9821210efe582be8ad3555b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4405 processed earlier; will process 6624 files now Step #5: ==128452== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c120bdc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c127241898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c1272245dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c1272244fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c120be2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c120b43b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c120b3e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c120bd4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c123ba3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c123ba3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c123ba3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c123ba3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c123ba3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c123ba3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c123ba3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c123ba3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c123ba3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c123ba3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c125e38f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c122b65b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c122b70be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c12291cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c12291cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c12291d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c12291c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c12291c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c12291c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c127226abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c12722f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c127217699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c127242112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f11fe06c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c120b3cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0xa7,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x87,0x4b,0x2d,0xdd,0x87,0x4b,0x6d,0xdd,0x86,0x4c,0x2d,0xdf,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x88,0x4b,0x2d,0xdd,0x87,0x4b,0x2d,0xdd,0x87,0x81, Step #5: K-\335\210K-\335\210K-\335\210K-\335\247K-\335\210K-\335\207K-\335\207Km\335\206L-\337\210K-\335\210K-\335\210K-\335\210K-\335\210K-\335\210K-\335\207K-\335\207\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-3ff263616a685cf2aa8e7f3b36a649851d0f190d Step #5: Base64: Sy3diEst3YhLLd2ISy3dp0st3YhLLd2HSy3dh0tt3YZMLd+ISy3diEst3YhLLd2ISy3diEst3YhLLd2HSy3dh4E= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3567 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3479178880 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611a78cd810, 0x5611a7ab701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5611a7ab7020,0x5611a994f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3ff263616a685cf2aa8e7f3b36a649851d0f190d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4406 processed earlier; will process 6623 files now Step #5: ==128488== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56119e3c29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5611a4a27898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611a4a0a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611a4a0a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56119e3c8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56119e329b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56119e324355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56119e3bac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5611a1389f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5611a1389f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5611a1389f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5611a1389f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5611a1389f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5611a1389f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5611a1389f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5611a1389f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5611a1389f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5611a1389f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5611a361ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611a034bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5611a0356be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611a0102c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611a0102c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611a0103738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611a0102874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611a0102874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611a0102874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5611a4a0cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5611a4a15928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611a49fd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5611a4a28112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f922f3ae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56119e322b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x28,0x2e,0x24,0x7c,0x2e,0x3f,0x29,0x29,0x7b,0x39,0x38,0x39,0x7b,0x7c,0x2e,0x3f,0x29,0x29,0x7b,0x39,0x38,0x39,0x7b,0x7c,0x2e,0x3f,0x28,0x0,0x29,0x2f,0x2e,0xa,0x28,0x0,0x29,0x2f,0x2e,0xa,0x2e,0x3f,0x29,0x7b,0x39,0x38,0x39,0x39,0x38,0x39,0x7d,0x2f,0x2e,0xa,0x2e,0x3f,0x29,0x7b,0x39,0x38,0x39,0x39,0x38,0x39,0x7d,0x24, Step #5: ^(.$|.?)){989{|.?)){989{|.?(\000)/.\012(\000)/.\012.?){989989}/.\012.?){989989}$ Step #5: artifact_prefix='./'; Test unit written to ./oom-8c19078035655755e73ccdbc8ef7cd8a9fd04bff Step #5: Base64: XiguJHwuPykpezk4OXt8Lj8pKXs5ODl7fC4/KAApLy4KKAApLy4KLj8pezk4OTk4OX0vLgouPyl7OTg5OTg5fSQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3568 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3479677129 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560f4b294810, 0x560f4b47e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560f4b47e020,0x560f4d3160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c19078035655755e73ccdbc8ef7cd8a9fd04bff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4407 processed earlier; will process 6622 files now Step #5: ==128524== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560f41d899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560f483ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560f483d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560f483d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560f41d8fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560f41cf0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560f41ceb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560f41d81c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560f44d50f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560f44d50f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560f44d50f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560f44d50f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560f44d50f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560f44d50f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560f44d50f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560f44d50f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560f44d50f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560f44d50f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560f46fe5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560f43d12b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560f43d1dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560f43ac9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560f43ac9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560f43aca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560f43ac9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560f43ac9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560f43ac9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560f483d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560f483dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560f483c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560f483ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f39b98ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560f41ce9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x54,0x52,0x41,0x43,0x4b,0x37,0x41,0x55,0x44,0x49,0x4f,0xa,0x49,0x53,0x52,0x43,0x65,0xa,0x49,0x53,0x52,0x43,0x65,0xa,0x49,0x53,0x52,0x43,0x65,0xa,0x49,0x53,0x52,0x43,0x34,0xa,0x49,0x53,0x52,0x43,0x60,0xa,0x49,0x53,0x52,0x43,0x65,0xa,0x49,0x53,0x52,0x43,0x4f,0xa,0x49,0x53,0x52,0x43,0x65,0xa,0x49,0x53,0x52,0x43,0x60, Step #5: TRACK7AUDIO\012ISRCe\012ISRCe\012ISRCe\012ISRC4\012ISRC`\012ISRCe\012ISRCO\012ISRCe\012ISRC` Step #5: artifact_prefix='./'; Test unit written to ./oom-c593346090b8d7bfb6b6dccadae7dc57574ac91a Step #5: Base64: VFJBQ0s3QVVESU8KSVNSQ2UKSVNSQ2UKSVNSQ2UKSVNSQzQKSVNSQ2AKSVNSQ2UKSVNSQ08KSVNSQ2UKSVNSQ2A= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3569 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3480290751 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5597ef213810, 0x5597ef3fd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5597ef3fd020,0x5597f12950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c593346090b8d7bfb6b6dccadae7dc57574ac91a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4408 processed earlier; will process 6621 files now Step #5: ==128560== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5597e5d089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5597ec36d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5597ec3505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5597ec3504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5597e5d0ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5597e5c6fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5597e5c6a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5597e5d00c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5597e8ccff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5597e8ccff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5597e8ccff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5597e8ccff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5597e8ccff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5597e8ccff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5597e8ccff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5597e8ccff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5597e8ccff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5597e8ccff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5597eaf64f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5597e7c91b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5597e7c9cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5597e7a48c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5597e7a48c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5597e7a49738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5597e7a48874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5597e7a48874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5597e7a48874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5597ec352abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5597ec35b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5597ec343699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5597ec36e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f258cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5597e5c68b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0x88,0xcb,0x8c,0xc2,0xb1,0xc2,0x88,0xcd,0x8c,0xcd,0xa2,0xcb,0x8c,0xc2,0xa2,0xcb,0x8c,0xc2,0xb1,0xc2,0x88,0xcd,0xa2,0xcb,0x8c,0xcd,0xa2,0xcb,0x8c,0xc2,0xb1,0xc2,0x88,0xcb,0x8c,0xc2,0xa2,0xcb,0x8c,0xc2,0xb1,0xc2,0x88,0xcd,0xa2,0xcd,0xa2,0xcb,0x8c,0xc2,0xb1,0xc2,0x88,0xcd,0xa2,0xcb,0x8c,0xcd,0x8c,0xc2,0xb1,0xc2,0x88,0x3d, Step #5: \302\210\313\214\302\261\302\210\315\214\315\242\313\214\302\242\313\214\302\261\302\210\315\242\313\214\315\242\313\214\302\261\302\210\313\214\302\242\313\214\302\261\302\210\315\242\315\242\313\214\302\261\302\210\315\242\313\214\315\214\302\261\302\210= Step #5: artifact_prefix='./'; Test unit written to ./oom-813dd4da12bd96f889a9878decf87722900752a7 Step #5: Base64: wojLjMKxwojNjM2iy4zCosuMwrHCiM2iy4zNosuMwrHCiMuMwqLLjMKxwojNos2iy4zCscKIzaLLjM2MwrHCiD0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3570 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3480778503 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c8f993810, 0x564c8fb7d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c8fb7d020,0x564c91a150e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/813dd4da12bd96f889a9878decf87722900752a7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4409 processed earlier; will process 6620 files now Step #5: ==128596== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564c864889c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c8caed898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c8cad05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c8cad04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c8648ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c863efb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c863ea355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c86480c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c8944ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c8944ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c8944ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c8944ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c8944ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c8944ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c8944ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c8944ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c8944ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c8944ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c8b6e4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c88411b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c8841cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c881c8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c881c8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c881c9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c881c8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c881c8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c881c8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c8cad2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c8cadb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c8cac3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c8caee112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe388a71082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c863e8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xbf,0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xa,0x52,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xd,0x71,0xa,0x27,0x26,0x75,0x6f,0x3b,0x27,0x3e,0x25,0x63,0x3b,0x5d,0x3e,0x3c,0x6c,0x3e,0x26,0x71,0x3b,0x26,0x71,0x3b,0x26,0x71,0x3b,0x26,0x71,0x3b,0x26,0x71,0x3b,0x26,0x71,0x3b,0x26,0x71,0x3b,0x26,0x71,0x3b, Step #5: \357\273\277<!DOCTYPE\012R[<!ENTITY\015q\012'&uo;'>%c;]><l>&q;&q;&q;&q;&q;&q;&q;&q; Step #5: artifact_prefix='./'; Test unit written to ./oom-6365810eefb18df0b0315e905cd44bbcdc028547 Step #5: Base64: 77u/PCFET0NUWVBFClJbPCFFTlRJVFkNcQonJnVvOyc+JWM7XT48bD4mcTsmcTsmcTsmcTsmcTsmcTsmcTsmcTs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3571 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3481270147 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ec285f810, 0x562ec2a4901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ec2a49020,0x562ec48e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6365810eefb18df0b0315e905cd44bbcdc028547' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4410 processed earlier; will process 6619 files now Step #5: ==128632== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562eb93549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ebf9b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ebf99c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ebf99c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562eb935ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562eb92bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562eb92b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562eb934cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ebc31bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ebc31bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ebc31bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ebc31bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ebc31bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ebc31bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ebc31bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ebc31bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ebc31bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ebc31bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ebe5b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ebb2ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ebb2e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ebb094c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ebb094c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ebb095738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ebb094874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ebb094874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ebb094874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ebf99eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ebf9a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ebf98f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ebf9ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd32f632082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562eb92b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x9,0x2b,0x9,0x2b,0x9,0xd,0x9,0x2a,0x9,0x2b,0x9,0x2a,0x9,0xd,0x9,0x2b,0x9,0xd,0x9,0x2b,0x9,0x2b,0x9,0x2b,0x9,0x2b,0x9,0x2b,0x9,0xd,0x9,0x2b,0x9,0xd,0x9,0x2b,0x9,0x2b,0x9,0x2a,0x9,0x2b,0x9,0x2b,0x9,0xd,0x9,0x2a,0x9,0xd,0x9,0x2b,0x9,0x2b,0x9,0xd,0x9,0x2a,0x9,0x2a,0x9,0x2b,0x9,0x2b,0x9, Step #5: \011+\011+\011\015\011*\011+\011*\011\015\011+\011\015\011+\011+\011+\011+\011+\011\015\011+\011\015\011+\011+\011*\011+\011+\011\015\011*\011\015\011+\011+\011\015\011*\011*\011+\011+\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-e7fea0ab8e897d1795267384de69fb47ab19114b Step #5: Base64: CSsJKwkNCSoJKwkqCQ0JKwkNCSsJKwkrCSsJKwkNCSsJDQkrCSsJKgkrCSsJDQkqCQ0JKwkrCQ0JKgkqCSsJKwk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3572 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3481772770 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c9750a5810, 0x55c97528f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c97528f020,0x55c9771270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e7fea0ab8e897d1795267384de69fb47ab19114b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4411 processed earlier; will process 6618 files now Step #5: ==128668== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c96bb9a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c9721ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9721e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9721e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c96bba0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c96bb01b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c96bafc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c96bb92c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c96eb61f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c96eb61f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c96eb61f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c96eb61f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c96eb61f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c96eb61f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c96eb61f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c96eb61f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c96eb61f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c96eb61f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c970df6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c96db23b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c96db2ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c96d8dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c96d8dac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c96d8db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c96d8da874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c96d8da874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c96d8da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c9721e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c9721ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c9721d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c972200112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2f70317082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c96bafab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x0,0x0,0x0,0xcd,0x85,0x65,0x62,0x6f,0x6c,0x64,0x67,0x68,0x74,0x77,0x68,0x69,0x74,0x65,0x7a,0x0,0x20,0xcd,0x85,0x66,0x61,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x72,0x6f,0x72,0x0,0x0,0x0,0xcd,0x85,0x65,0x66,0x61,0x1,0x0,0x62,0x70,0x69,0x62,0x1,0x0,0x0,0x0,0x0,0x7a,0x20,0xcd,0x85,0x65,0x66,0xc4,0x40, Step #5: 0\000\000\000\315\205eboldghtwhitez\000 \315\205fa\000\000\000\000\000\000\000\000\001ror\000\000\000\315\205efa\001\000bpib\001\000\000\000\000z \315\205ef\304@ Step #5: artifact_prefix='./'; Test unit written to ./oom-c9b16e7e87569e0a7534ef66bdb3f4f56b4422ac Step #5: Base64: MAAAAM2FZWJvbGRnaHR3aGl0ZXoAIM2FZmEAAAAAAAAAAAFyb3IAAADNhWVmYQEAYnBpYgEAAAAAeiDNhWVmxEA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3573 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3482266073 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab9fa82810, 0x55ab9fc6c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab9fc6c020,0x55aba1b040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9b16e7e87569e0a7534ef66bdb3f4f56b4422ac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4412 processed earlier; will process 6617 files now Step #5: #1 pulse cov: 3611 ft: 3612 exec/s: 0 rss: 173Mb Step #5: ==128704== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ab965779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab9cbdc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab9cbbf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab9cbbf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab9657dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab964deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab964d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab9656fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab9953ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab9953ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab9953ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab9953ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab9953ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab9953ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab9953ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab9953ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab9953ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab9953ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab9b7d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab98500b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab9850bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab982b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab982b7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab982b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab982b7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab982b7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab982b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab9cbc1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab9cbca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab9cbb2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab9cbdd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd2072a2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab964d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0x5b,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x81,0x92,0x96,0x0,0x2d,0xf2,0x85,0x85,0x93,0xf2,0x85,0x85,0x93,0xf2,0x85,0x85,0x93,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x81,0x92,0x96,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x81,0x92,0x96,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93, Step #5: (?i)[\000-\362\205\205\223\000-\362\201\222\226\000-\362\205\205\223\362\205\205\223\362\205\205\223\362\205\205\223\000-\362\201\222\226\000-\362\205\205\223\000-\362\201\222\226\000-\362\205\205\223\000-\362\205\205\223 Step #5: artifact_prefix='./'; Test unit written to ./oom-124efbdb826f1808db8ffa71091799c69ed1b501 Step #5: Base64: KD9pKVsALfKFhZMALfKBkpYALfKFhZPyhYWT8oWFk/KFhZMALfKBkpYALfKFhZMALfKBkpYALfKFhZMALfKFhZM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3574 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3482794549 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a4c17cc810, 0x55a4c19b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a4c19b6020,0x55a4c384e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/124efbdb826f1808db8ffa71091799c69ed1b501' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4414 processed earlier; will process 6615 files now Step #5: ==128740== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a4b82c19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a4be926898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a4be9095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a4be9094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a4b82c7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a4b8228b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a4b8223355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a4b82b9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a4bb288f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a4bb288f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a4bb288f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a4bb288f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a4bb288f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a4bb288f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a4bb288f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a4bb288f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a4bb288f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a4bb288f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a4bd51df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a4ba24ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a4ba255be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a4ba001c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a4ba001c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a4ba002738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a4ba001874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a4ba001874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a4ba001874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a4be90babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a4be914928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a4be8fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a4be927112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff8a14c6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a4b8221b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x3e,0x3c,0x21,0x3e,0x3c,0x21,0xe2,0x84,0xaa,0x3e,0x3c,0x21,0x3e,0x3c,0x21,0x3e,0x3c,0x21,0xe2,0x84,0xaa,0x3e,0x3c,0x21,0x3e,0x3c,0x21,0x3e,0x3c,0x21,0xe2,0x84,0xaa,0x3e,0x3c,0x21,0x3e,0x3c,0x21,0x3e,0x3c,0x21,0xe2,0x84,0xaa,0x3e,0x3c,0x21,0x3e,0x3c,0x21,0xe2,0x84,0xaa,0x3e,0x3c,0x21,0x3e,0x3c,0x21,0xe2,0x84,0xaa, Step #5: <!><!><!\342\204\252><!><!><!\342\204\252><!><!><!\342\204\252><!><!><!\342\204\252><!><!\342\204\252><!><!\342\204\252 Step #5: artifact_prefix='./'; Test unit written to ./oom-2b5e1c56bcf4ec7cbe7faa96fb4ae42fd5f461a7 Step #5: Base64: PCE+PCE+PCHihKo+PCE+PCE+PCHihKo+PCE+PCE+PCHihKo+PCE+PCE+PCHihKo+PCE+PCHihKo+PCE+PCHihKo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3575 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3483280336 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f736655810, 0x55f73683f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f73683f020,0x55f7386d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2b5e1c56bcf4ec7cbe7faa96fb4ae42fd5f461a7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4415 processed earlier; will process 6614 files now Step #5: #1 pulse cov: 3904 ft: 3905 exec/s: 0 rss: 172Mb Step #5: #2 pulse cov: 4554 ft: 4901 exec/s: 0 rss: 174Mb Step #5: ==128776== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f72d14a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7337af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7337925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7337924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f72d150d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f72d0b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f72d0ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f72d142c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f730111f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f730111f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f730111f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f730111f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f730111f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f730111f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f730111f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f730111f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f730111f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f730111f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7323a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f72f0d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f72f0debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f72ee8ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f72ee8ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f72ee8b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f72ee8a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f72ee8a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f72ee8a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f733794abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f73379d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f733785699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7337b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3b2272082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f72d0aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4f,0x50,0x54,0x49,0x4f,0x4e,0x53,0x3d,0x22,0x6c,0x6f,0x67,0x5f,0x6c,0x65,0x76,0x65,0x6c,0x3d,0x38,0x22,0xa,0x4f,0x50,0x54,0x49,0x4f,0x4e,0x53,0x3d,0x22,0x6c,0x6f,0x67,0x5f,0x6c,0x65,0x76,0x65,0x6c,0x3d,0x39,0x22,0xa,0x4f,0x50,0x54,0x49,0x4f,0x4e,0x53,0x3d,0x22,0x6c,0x6f,0x67,0x5f,0x6c,0x65,0x76,0x65,0x6c,0x3d,0x38,0x22, Step #5: OPTIONS=\"log_level=8\"\012OPTIONS=\"log_level=9\"\012OPTIONS=\"log_level=8\" Step #5: artifact_prefix='./'; Test unit written to ./oom-013d072326d5e90924e8c33a4670d559c23a03e6 Step #5: Base64: T1BUSU9OUz0ibG9nX2xldmVsPTgiCk9QVElPTlM9ImxvZ19sZXZlbD05IgpPUFRJT05TPSJsb2dfbGV2ZWw9OCI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3576 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3483846765 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b8e964a810, 0x55b8e983401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b8e9834020,0x55b8eb6cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/013d072326d5e90924e8c33a4670d559c23a03e6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4418 processed earlier; will process 6611 files now Step #5: ==128812== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b8e013f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b8e67a4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b8e67875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b8e67874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b8e0145d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b8e00a6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b8e00a1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b8e0137c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b8e3106f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b8e3106f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b8e3106f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b8e3106f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b8e3106f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b8e3106f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b8e3106f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b8e3106f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b8e3106f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b8e3106f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b8e539bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b8e20c8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b8e20d3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b8e1e7fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b8e1e7fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b8e1e80738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b8e1e7f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b8e1e7f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b8e1e7f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b8e6789abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b8e6792928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b8e677a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b8e67a5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f267abde082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b8e009fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x68,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e, Step #5: h#version#version#version#version#version#version#version#version Step #5: artifact_prefix='./'; Test unit written to ./oom-3446c9122972a2355ee5d0a17b0cd1fcdd43e4f6 Step #5: Base64: aCN2ZXJzaW9uI3ZlcnNpb24jdmVyc2lvbiN2ZXJzaW9uI3ZlcnNpb24jdmVyc2lvbiN2ZXJzaW9uI3ZlcnNpb24= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3577 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3484345322 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7257aa810, 0x55b72599401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b725994020,0x55b72782c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3446c9122972a2355ee5d0a17b0cd1fcdd43e4f6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4419 processed earlier; will process 6610 files now Step #5: #1 pulse cov: 10471 ft: 10472 exec/s: 0 rss: 195Mb Step #5: ==128848== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b71c29f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b722904898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b7228e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b7228e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b71c2a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b71c206b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b71c201355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b71c297c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b71f266f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b71f266f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b71f266f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b71f266f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b71f266f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b71f266f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b71f266f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b71f266f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b71f266f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b71f266f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b7214fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b71e228b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b71e233be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b71dfdfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b71dfdfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b71dfe0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b71dfdf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b71dfdf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b71dfdf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b7228e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b7228f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b7228da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b722905112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6af551d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b71c1ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0x14,0x2d,0xd,0x3e,0xa,0x2d,0xd,0x3e,0xd,0x2d,0xd,0x3e,0xd,0x2d,0xd,0x3e,0xa,0x2d,0xd,0x3e,0xa,0x2d,0xd,0x3e,0xa,0x2d,0xd,0x3e,0xa,0x2d,0xd,0x3e,0xd,0x2d,0xd,0x3e,0xa,0x2d,0xd,0x3e,0xd,0x2d,0xd,0x3e,0xd,0x2d,0xd,0x3e,0xa,0x2d,0xd,0x3e,0xd,0x2d,0xd,0x3e,0xd,0x2d,0xd,0x3e,0xa,0x2d,0xd,0x3e, Step #5: :\024-\015>\012-\015>\015-\015>\015-\015>\012-\015>\012-\015>\012-\015>\012-\015>\015-\015>\012-\015>\015-\015>\015-\015>\012-\015>\015-\015>\015-\015>\012-\015> Step #5: artifact_prefix='./'; Test unit written to ./oom-20cfd0a9a50512814db93ad2695779845128102d Step #5: Base64: OhQtDT4KLQ0+DS0NPg0tDT4KLQ0+Ci0NPgotDT4KLQ0+DS0NPgotDT4NLQ0+DS0NPgotDT4NLQ0+DS0NPgotDT4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3578 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3484979170 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556bc0eec810, 0x556bc10d601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556bc10d6020,0x556bc2f6e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/20cfd0a9a50512814db93ad2695779845128102d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4421 processed earlier; will process 6608 files now Step #5: ==128884== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556bb79e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556bbe046898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556bbe0295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556bbe0294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556bb79e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556bb7948b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556bb7943355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556bb79d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556bba9a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556bba9a8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556bba9a8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556bba9a8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556bba9a8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556bba9a8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556bba9a8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556bba9a8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556bba9a8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556bba9a8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556bbcc3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556bb996ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556bb9975be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556bb9721c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556bb9721c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556bb9722738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556bb9721874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556bb9721874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556bb9721874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556bbe02babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556bbe034928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556bbe01c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556bbe047112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc388670082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556bb7941b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x69,0x66,0x20,0x20,0x73,0x74,0x72,0x65,0x6d,0x20,0x2e,0x2d,0x33,0x1d,0x60,0x1,0x2,0x0,0x6,0x60,0x20,0x1,0x0,0x0,0x0,0x0,0x0,0x3d,0x42,0x42,0xa,0x3d,0x20,0x20,0xa,0x3d,0x20,0x20,0x2e,0x1d,0x20,0x2e,0x2d,0x13,0x1d,0x60,0x1,0x2,0x0,0x6,0x60,0x20,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x90,0x0,0x65,0x20,0xa, Step #5: rif strem .-3\035`\001\002\000\006` \001\000\000\000\000\000=BB\012= \012= .\035 .-\023\035`\001\002\000\006` \001\000\000\000\000\000\000\220\000e \012 Step #5: artifact_prefix='./'; Test unit written to ./oom-a3d0bfed80dbd726dc122b8248aecc92a985f0cd Step #5: Base64: cmlmICBzdHJlbSAuLTMdYAECAAZgIAEAAAAAAD1CQgo9ICAKPSAgLh0gLi0THWABAgAGYCABAAAAAAAAkABlIAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3579 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3485595009 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fa4d8fd810, 0x55fa4dae701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fa4dae7020,0x55fa4f97f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a3d0bfed80dbd726dc122b8248aecc92a985f0cd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4422 processed earlier; will process 6607 files now Step #5: #1 pulse cov: 3910 ft: 3911 exec/s: 0 rss: 174Mb Step #5: ==128920== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fa443f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fa4aa57898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fa4aa3a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fa4aa3a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fa443f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fa44359b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fa44354355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fa443eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fa473b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fa473b9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fa473b9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fa473b9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fa473b9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fa473b9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fa473b9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fa473b9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fa473b9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fa473b9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fa4964ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fa4637bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fa46386be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fa46132c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fa46132c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fa46133738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fa46132874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fa46132874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fa46132874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fa4aa3cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fa4aa45928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fa4aa2d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fa4aa58112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd13b41d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fa44352b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c,0x24,0x3c, Step #5: <$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$<$< Step #5: artifact_prefix='./'; Test unit written to ./oom-0fda0352ef6d21b19d200ee4d3ff5246c394212f Step #5: Base64: PCQ8JDwkPCQ8JDwkPCQ8JDwkPCQ8JDwkPCQ8JDwkPCQ8JDwkPCQ8JDwkPCQ8JDwkPCQ8JDwkPCQ8JDwkPCQ8JDw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3580 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3486128984 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb32fcd810, 0x55cb331b701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb331b7020,0x55cb3504f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0fda0352ef6d21b19d200ee4d3ff5246c394212f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4424 processed earlier; will process 6605 files now Step #5: ==128956== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cb29ac29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb30127898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb3010a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb3010a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb29ac8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb29a29b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb29a24355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb29abac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb2ca89f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb2ca89f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb2ca89f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb2ca89f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb2ca89f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb2ca89f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb2ca89f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb2ca89f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb2ca89f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb2ca89f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb2ed1ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb2ba4bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb2ba56be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb2b802c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb2b802c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb2b803738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb2b802874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb2b802874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb2b802874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb3010cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb30115928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb300fd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb30128112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f77c23ec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb29a22b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0, Step #5: \360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a45b7d67a7dad591b9f32d113eca9aa5948350c Step #5: Base64: 8J6LkQ1pbg3wnouRDWluDfCei5ENaW4N8J6LkQ1pbg3wnouRDWluDfCei5ENaW4N8J6LkQ1pbg3wnouRDWluDfA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3581 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3486622889 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558acbc26810, 0x558acbe1001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558acbe10020,0x558acdca80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a45b7d67a7dad591b9f32d113eca9aa5948350c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4425 processed earlier; will process 6604 files now Step #5: #1 pulse cov: 3752 ft: 3753 exec/s: 0 rss: 175Mb Step #5: ==128992== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558ac271b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558ac8d80898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558ac8d635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558ac8d634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558ac2721d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558ac2682b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558ac267d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558ac2713c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558ac56e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558ac56e2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558ac56e2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558ac56e2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558ac56e2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558ac56e2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558ac56e2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558ac56e2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558ac56e2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558ac56e2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558ac7977f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ac46a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ac46afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ac445bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ac445bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ac445c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ac445b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ac445b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ac445b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558ac8d65abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558ac8d6e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558ac8d56699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558ac8d81112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f18ea5d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558ac267bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x6e,0x3a,0x24,0x3a,0x3a,0x5f,0x3a,0x3a,0x75,0x3a,0x3a,0x65,0x3a,0x3a,0x6b,0x3a,0x3a,0x24,0x3a,0x3a,0x5f,0x3a,0x3a,0x66,0x3a,0x3a,0x6f,0x3a,0x3a,0x30,0x7d,0x6e,0x3a,0x3a,0x5f,0x3a,0x3a,0x75,0x3a,0x3a,0x6b,0x3a,0x3a,0x24,0x3a,0x3a,0x5f,0x3a,0x3a,0x66,0x3a,0x3a,0x75,0x3a,0x3a,0x65,0x3a,0x3a,0x6b,0x2d, Step #5: $3::{n:$::_::u::e::k::$::_::f::o::0}n::_::u::k::$::_::f::u::e::k- Step #5: artifact_prefix='./'; Test unit written to ./oom-27251839f0ae67511dcc5bea68ebcaacb2dc9a7b Step #5: Base64: JDM6OntuOiQ6Ol86OnU6OmU6Oms6OiQ6Ol86OmY6Om86OjB9bjo6Xzo6dTo6azo6JDo6Xzo6Zjo6dTo6ZTo6ay0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3582 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3487158026 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556bd94b1810, 0x556bd969b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556bd969b020,0x556bdb5330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/27251839f0ae67511dcc5bea68ebcaacb2dc9a7b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4427 processed earlier; will process 6602 files now Step #5: #1 pulse cov: 10530 ft: 10531 exec/s: 0 rss: 196Mb Step #5: ==129028== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556bcffa69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556bd660b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556bd65ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556bd65ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556bcffacd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556bcff0db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556bcff08355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556bcff9ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556bd2f6df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556bd2f6df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556bd2f6df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556bd2f6df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556bd2f6df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556bd2f6df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556bd2f6df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556bd2f6df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556bd2f6df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556bd2f6df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556bd5202f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556bd1f2fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556bd1f3abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556bd1ce6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556bd1ce6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556bd1ce7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556bd1ce6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556bd1ce6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556bd1ce6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556bd65f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556bd65f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556bd65e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556bd660c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa4d22d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556bcff06b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xcd,0xb8,0xcd,0xb9,0xcd,0xb8,0xcd,0xb9,0xcd,0xb7,0xcd,0xb9,0xcd,0xb8,0xcd,0xb9,0xcd,0xb7,0xcd,0xb9,0xcd,0xb9,0xcd,0xb7,0xcd,0xb9,0xcd,0xb8,0xcd,0xb9,0xcd,0xb8,0xcd,0xb9,0xcd,0xb7,0xcd,0xb9,0xcd,0xb8,0xcd,0xb8,0xcd,0xb9,0xcd,0xb8,0xcd,0xb9,0xcd,0xb7,0xcd,0xb9,0xcd,0xb8,0xcd,0xb9,0xcd,0xb7,0xcd,0xb9,0xcd,0xb7,0xcd,0xb8, Step #5: <\315\270\315\271\315\270\315\271\315\267\315\271\315\270\315\271\315\267\315\271\315\271\315\267\315\271\315\270\315\271\315\270\315\271\315\267\315\271\315\270\315\270\315\271\315\270\315\271\315\267\315\271\315\270\315\271\315\267\315\271\315\267\315\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-82084b292a39514b0714ff9935221ad703bdad53 Step #5: Base64: PM24zbnNuM25zbfNuc24zbnNt825zbnNt825zbjNuc24zbnNt825zbjNuM25zbjNuc23zbnNuM25zbfNuc23zbg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3583 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3487801566 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed854b4810, 0x55ed8569e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed8569e020,0x55ed875360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/82084b292a39514b0714ff9935221ad703bdad53' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4429 processed earlier; will process 6600 files now Step #5: ==129064== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed7bfa99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed8260e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed825f15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed825f14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed7bfafd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed7bf10b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed7bf0b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed7bfa1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed7ef70f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed7ef70f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed7ef70f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed7ef70f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed7ef70f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed7ef70f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed7ef70f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed7ef70f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed7ef70f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed7ef70f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed81205f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed7df32b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed7df3dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed7dce9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed7dce9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed7dcea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed7dce9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed7dce9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed7dce9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed825f3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed825fc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed825e4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed8260f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc08286a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed7bf09b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x0,0x0,0x0,0x0,0x0,0x6c,0x7c,0x7c,0x0,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x0,0x0,0x0,0x0,0x0,0x33,0x0,0x0,0x20,0x0,0x6c,0x0,0x0,0x0,0x0,0x0,0x0,0x33,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xd6,0xae,0x0,0x0,0x0,0x0,0x0,0x0,0xd6,0xae,0x0,0x0,0x0,0x27,0xd6,0xae,0xd5,0xff,0x0, Step #5: M\000\000\000\000\000l||\000\003\003\003\003\003\003\003\003\003\003\003\003\000\000\000\000\0003\000\000 \000l\000\000\000\000\000\0003\000\000\000\000\000\000\000\326\256\000\000\000\000\000\000\326\256\000\000\000'\326\256\325\377\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-36b6cbb662daff09f8e2f9fcc57f5ef1c293dbdf Step #5: Base64: TQAAAAAAbHx8AAMDAwMDAwMDAwMDAwAAAAAAMwAAIABsAAAAAAAAMwAAAAAAAADWrgAAAAAAANauAAAAJ9au1f8A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3584 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3488293481 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c48cec810, 0x564c48ed601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c48ed6020,0x564c4ad6e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/36b6cbb662daff09f8e2f9fcc57f5ef1c293dbdf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4430 processed earlier; will process 6599 files now Step #5: ==129100== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564c3f7e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c45e46898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c45e295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c45e294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c3f7e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c3f748b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c3f743355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c3f7d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c427a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c427a8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c427a8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c427a8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c427a8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c427a8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c427a8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c427a8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c427a8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c427a8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c44a3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c4176ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c41775be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c41521c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c41521c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c41522738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c41521874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c41521874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c41521874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c45e2babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c45e34928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c45e1c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c45e47112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3a3155082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c3f741b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x7b,0x9,0x7e,0xa,0x7b,0x9,0x7e,0xa,0x7b,0x9,0x7f,0xa,0x7b,0x9,0x7e,0xa,0x7b,0x9,0x7e,0xa,0x7b,0x9,0x7b,0xa,0x24,0x9,0x7c,0xa,0x7b,0x9,0x25,0xa,0x7b,0x9,0x71,0xa,0x7b,0x9,0x7e,0xa,0x7b,0x9,0x7b,0xa,0x24,0x9,0x7c,0xa,0x7b,0x9,0x25,0xa,0x7b,0x9,0x71,0xa,0x7b,0x9,0x7e,0xa,0x8,0xde,0xad,0xbe,0xef, Step #5: \000{\011~\012{\011~\012{\011\177\012{\011~\012{\011~\012{\011{\012$\011|\012{\011%\012{\011q\012{\011~\012{\011{\012$\011|\012{\011%\012{\011q\012{\011~\012\010\336\255\276\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-341e49d7616b4979162c19f0cbdf9f10965732d7 Step #5: Base64: AHsJfgp7CX4Kewl/CnsJfgp7CX4Kewl7CiQJfAp7CSUKewlxCnsJfgp7CXsKJAl8CnsJJQp7CXEKewl+Cgjerb7v Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3585 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3488787236 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561788a2b810, 0x561788c1501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561788c15020,0x56178aaad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/341e49d7616b4979162c19f0cbdf9f10965732d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4431 processed earlier; will process 6598 files now Step #5: ==129136== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56177f5209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561785b85898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561785b685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561785b684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56177f526d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56177f487b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56177f482355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56177f518c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5617824e7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5617824e7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5617824e7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5617824e7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5617824e7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5617824e7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5617824e7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5617824e7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5617824e7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5617824e7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56178477cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5617814a9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5617814b4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561781260c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561781260c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561781261738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561781260874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561781260874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561781260874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561785b6aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561785b73928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561785b5b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561785b86112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe40d4e2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56177f480b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x85,0x9f,0xf3,0xa0,0x80,0xb2,0x5c,0x5c,0x65,0x34,0x52,0x2c,0x4b,0xcd,0x22,0xf7,0x8a,0xbd,0x6a,0x78,0x10,0x31,0x2d,0x4b,0xcb,0x66,0x37,0xab,0x67,0x7,0xe7,0x1f,0xdb,0xed,0x83,0x84,0x92,0x6e,0xba,0x90,0x66,0xa7,0x10,0x18,0xd8,0x3,0xb1,0x63,0x36,0x0,0x93,0x15,0x2c,0x9b,0xf7,0x45,0x6a,0xb6,0xb2,0x44,0x46,0x1f,0x8,0xbb,0xfe, Step #5: \341\205\237\363\240\200\262\\\\e4R,K\315\"\367\212\275jx\0201-K\313f7\253g\007\347\037\333\355\203\204\222n\272\220f\247\020\030\330\003\261c6\000\223\025,\233\367Ej\266\262DF\037\010\273\376 Step #5: artifact_prefix='./'; Test unit written to ./oom-b0512536225351eb1aed89323214220a8f822213 Step #5: Base64: 4YWf86CAslxcZTRSLEvNIveKvWp4EDEtS8tmN6tnB+cf2+2DhJJuupBmpxAY2AOxYzYAkxUsm/dFarayREYfCLv+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3586 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3489274908 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564a4ec4a810, 0x564a4ee3401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564a4ee34020,0x564a50ccc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b0512536225351eb1aed89323214220a8f822213' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4432 processed earlier; will process 6597 files now Step #5: ==129172== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564a4573f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564a4bda4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564a4bd875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564a4bd874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564a45745d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564a456a6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564a456a1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564a45737c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564a48706f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564a48706f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564a48706f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564a48706f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564a48706f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564a48706f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564a48706f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564a48706f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564a48706f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564a48706f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564a4a99bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564a476c8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564a476d3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564a4747fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564a4747fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564a47480738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564a4747f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564a4747f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564a4747f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564a4bd89abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564a4bd92928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564a4bd7a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564a4bda5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa58f046082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564a4569fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3d,0x53,0x3d,0x60,0x60,0x67,0x3d,0x60,0x60,0x67,0x3d,0x60,0x60,0x67,0x3d,0x60,0x60,0x67,0x3d,0x60,0x60,0x53,0x3d,0x60,0x60,0x65,0x3d,0x60,0x60,0x67,0x3d,0x60,0x60,0x3d,0x3d,0x60,0x60,0x67,0x3d,0x60,0x60,0x67,0x3d,0x60,0x60,0x67,0x3d,0x60,0x60,0x67,0x3d,0x60,0x60,0x53,0x3d,0x60,0x60,0x65,0x3d,0x60,0x60,0x67,0x3d,0x60,0x60, Step #5: <=S=``g=``g=``g=``g=``S=``e=``g=``==``g=``g=``g=``g=``S=``e=``g=`` Step #5: artifact_prefix='./'; Test unit written to ./oom-bdc56da9cabd0a6d9332323835250a3948b07231 Step #5: Base64: PD1TPWBgZz1gYGc9YGBnPWBgZz1gYFM9YGBlPWBgZz1gYD09YGBnPWBgZz1gYGc9YGBnPWBgUz1gYGU9YGBnPWBg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3587 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3489885515 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d72080810, 0x557d7226a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d7226a020,0x557d741020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bdc56da9cabd0a6d9332323835250a3948b07231' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4433 processed earlier; will process 6596 files now Step #5: ==129208== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557d68b759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557d6f1da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557d6f1bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557d6f1bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557d68b7bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557d68adcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557d68ad7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557d68b6dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557d6bb3cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557d6bb3cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557d6bb3cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557d6bb3cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557d6bb3cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557d6bb3cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557d6bb3cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557d6bb3cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557d6bb3cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557d6bb3cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557d6ddd1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557d6aafeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557d6ab09be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557d6a8b5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557d6a8b5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557d6a8b6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557d6a8b5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557d6a8b5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557d6a8b5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557d6f1bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557d6f1c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557d6f1b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557d6f1db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2d1f59b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557d68ad5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53,0x45,0x54,0x22,0x2d,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22,0x2e,0x22, Step #5: SET\"-\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\".\" Step #5: artifact_prefix='./'; Test unit written to ./oom-78cca1972064c684dba4a502a7bd8cacb29baf86 Step #5: Base64: U0VUIi0iLiIuIi4iLiIuIi4iLiIuIi4iLiIuIi4iLiIuIi4iLiIuIi4iLiIuIi4iLiIuIi4iLiIuIi4iLiIuIi4i Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3588 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3490374413 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556dec62c810, 0x556dec81601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556dec816020,0x556dee6ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/78cca1972064c684dba4a502a7bd8cacb29baf86' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4434 processed earlier; will process 6595 files now Step #5: #1 pulse cov: 11405 ft: 11406 exec/s: 0 rss: 193Mb Step #5: ==129244== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556de31219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556de9786898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556de97695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556de97694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556de3127d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556de3088b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556de3083355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556de3119c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556de60e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556de60e8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556de60e8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556de60e8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556de60e8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556de60e8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556de60e8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556de60e8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556de60e8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556de60e8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556de837df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556de50aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556de50b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556de4e61c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556de4e61c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556de4e62738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556de4e61874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556de4e61874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556de4e61874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556de976babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556de9774928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556de975c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556de9787112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb9dd8b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556de3081b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x68,0x3a,0xdc,0x90,0xcc,0x95,0xcb,0x91,0xcc,0x91,0xcc,0x91,0xcb,0x81,0xcc,0x91,0xcc,0x91,0xcc,0xb1,0xcb,0x95,0xdc,0x91,0xcc,0x95,0xcc,0x91,0xcc,0x93,0xcc,0x95,0xcc,0x91,0xcc,0x93,0xcc,0x95,0xcb,0x91,0xcc,0x91,0xcc,0x91,0xcb,0x81,0xcc,0x91,0xcc,0x91,0xcc,0xb1,0xcb,0x95,0xdc,0x91,0xcc,0x95,0xcc,0x91,0xcc,0x93,0xcc,0x95,0xcc,0x97, Step #5: h:\334\220\314\225\313\221\314\221\314\221\313\201\314\221\314\221\314\261\313\225\334\221\314\225\314\221\314\223\314\225\314\221\314\223\314\225\313\221\314\221\314\221\313\201\314\221\314\221\314\261\313\225\334\221\314\225\314\221\314\223\314\225\314\227 Step #5: artifact_prefix='./'; Test unit written to ./oom-0275a4cb8c2071110c3e12bb5ab718b7cc33d44e Step #5: Base64: aDrckMyVy5HMkcyRy4HMkcyRzLHLldyRzJXMkcyTzJXMkcyTzJXLkcyRzJHLgcyRzJHMscuV3JHMlcyRzJPMlcyX Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3589 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3490934814 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5583b7078810, 0x5583b726201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5583b7262020,0x5583b90fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0275a4cb8c2071110c3e12bb5ab718b7cc33d44e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4436 processed earlier; will process 6593 files now Step #5: ==129280== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5583adb6d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5583b41d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583b41b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583b41b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5583adb73d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5583adad4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5583adacf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5583adb65c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5583b0b34f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5583b0b34f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5583b0b34f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5583b0b34f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5583b0b34f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5583b0b34f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5583b0b34f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5583b0b34f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5583b0b34f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5583b0b34f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5583b2dc9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5583afaf6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5583afb01be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5583af8adc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5583af8adc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5583af8ae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5583af8ad874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5583af8ad874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5583af8ad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5583b41b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5583b41c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5583b41a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5583b41d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f161c810082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5583adacdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x6d,0x73,0x6f,0x79,0x62,0x6c,0x3e,0x76,0x67,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0xe1,0x80,0xae,0xe5,0x80,0xae,0xea,0xa2,0xb8,0x5b,0x20,0x3c,0x6d,0x73,0x6f,0x79,0x62,0x6c,0x3e,0x3e, Step #5: <svg><msoybl>vg><tAxt><tAxt><tAxt><tAxt><tAxt>\341\200\256\345\200\256\352\242\270[ <msoybl>> Step #5: artifact_prefix='./'; Test unit written to ./oom-186246e8d6352e804958eaedff7527110abf28be Step #5: Base64: PHN2Zz48bXNveWJsPnZnPjx0QXh0Pjx0QXh0Pjx0QXh0Pjx0QXh0Pjx0QXh0PuGAruWAruqiuFsgPG1zb3libD4+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3590 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3491418151 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf0a83b810, 0x55bf0aa2501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf0aa25020,0x55bf0c8bd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/186246e8d6352e804958eaedff7527110abf28be' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4437 processed earlier; will process 6592 files now Step #5: #1 pulse cov: 3958 ft: 3959 exec/s: 0 rss: 175Mb Step #5: ==129316== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bf013309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf07995898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf079785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf079784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf01336d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf01297b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf01292355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf01328c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf042f7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf042f7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf042f7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf042f7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf042f7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf042f7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf042f7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf042f7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf042f7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf042f7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf0658cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf032b9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf032c4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf03070c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf03070c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf03071738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf03070874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf03070874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf03070874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf0797aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf07983928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf0796b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf07996112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe2d6578082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf01290b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2b,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x9,0x2d,0x31,0x8a,0x8a,0x8a,0x8a,0x8a,0x8a,0x8a,0x8a,0x8a,0xa,0x8a,0x8a,0x8a,0x8a,0x8a,0x8a,0x8a,0x8a,0x8a,0x8a,0xa,0x8a,0x8a,0xd,0x9,0x9,0x9,0x9,0x55,0x8a,0x8a,0xd,0x9,0x9,0x9,0x9,0x55,0x8a,0x8a,0xd,0x9,0x9,0x9,0x9,0x55,0x8a,0x8a,0xd,0x9,0x9,0x9,0x9,0x55, Step #5: -+\011-\011-\011-\011-\011-1\212\212\212\212\212\212\212\212\212\012\212\212\212\212\212\212\212\212\212\212\012\212\212\015\011\011\011\011U\212\212\015\011\011\011\011U\212\212\015\011\011\011\011U\212\212\015\011\011\011\011U Step #5: artifact_prefix='./'; Test unit written to ./oom-858a10ef4969d8de5ac2a7404bdbe9b8017a8bd4 Step #5: Base64: LSsJLQktCS0JLQktMYqKioqKioqKigqKioqKioqKioqKCoqKDQkJCQlViooNCQkJCVWKig0JCQkJVYqKDQkJCQlV Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3591 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3491941249 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f4d1433810, 0x55f4d161d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f4d161d020,0x55f4d34b50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/858a10ef4969d8de5ac2a7404bdbe9b8017a8bd4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4439 processed earlier; will process 6590 files now Step #5: ==129352== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f4c7f289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f4ce58d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f4ce5705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f4ce5704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f4c7f2ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f4c7e8fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f4c7e8a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f4c7f20c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f4caeeff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f4caeeff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f4caeeff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f4caeeff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f4caeeff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f4caeeff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f4caeeff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f4caeeff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f4caeeff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f4caeeff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4cd184f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4c9eb1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4c9ebcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f4c9c68c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f4c9c68c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f4c9c69738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f4c9c68874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f4c9c68874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f4c9c68874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f4ce572abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f4ce57b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f4ce563699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f4ce58e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f204d4f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f4c7e88b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0x2d,0x2e,0xc2,0xbc, Step #5: -.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.\302\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-faba71762b0e0267b6e6a10f29a654bee0e78275 Step #5: Base64: LS4tLi0uLS4tLi0uLS4tLi0uLS4tLi0uLS4tLi0uLS4tLi0uLS4tLi0uLS4tLi0uLS4tLi0uLS4tLi0uLS4tLsK8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3592 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3492426817 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a5eb8d4810, 0x55a5ebabe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a5ebabe020,0x55a5ed9560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/faba71762b0e0267b6e6a10f29a654bee0e78275' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4440 processed earlier; will process 6589 files now Step #5: ==129388== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a5e23c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a5e8a2e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a5e8a115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a5e8a114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a5e23cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a5e2330b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a5e232b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a5e23c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a5e5390f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a5e5390f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a5e5390f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a5e5390f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a5e5390f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a5e5390f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a5e5390f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a5e5390f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a5e5390f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a5e5390f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a5e7625f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a5e4352b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a5e435dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a5e4109c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a5e4109c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a5e410a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a5e4109874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a5e4109874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a5e4109874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a5e8a13abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a5e8a1c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a5e8a04699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a5e8a2f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7026855082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a5e2329b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x7d,0x21,0x7d,0x3c,0x74,0x65,0x78,0x74,0x3e,0x30,0x5b,0x29,0xe1,0xa0,0x8c,0x30,0x7f,0x7f,0x7f,0xe1,0xa0,0x8c,0x30,0x7f,0x7f,0x7f,0x7f,0x31,0x31,0x31,0x31,0x31,0x31,0x31,0x31,0x31,0x32,0x31,0x41,0x4e,0x4d,0x46,0x31,0x31,0x30,0x35,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x42,0x4f,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg>}!}<text>0[)\341\240\2140\177\177\177\341\240\2140\177\177\177\17711111111121ANMF1105</text>BO</svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-0b5909e2451747930fa6dff41f1747cd4bbeb228 Step #5: Base64: PHN2Zz59IX08dGV4dD4wWynhoIwwf39/4aCMMH9/f38xMTExMTExMTEyMUFOTUYxMTA1PC90ZXh0PkJPPC9zdmc+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3593 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3492916331 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7554d1810, 0x55f7556bb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7556bb020,0x55f7575530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b5909e2451747930fa6dff41f1747cd4bbeb228' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4441 processed earlier; will process 6588 files now Step #5: #1 pulse cov: 3626 ft: 3627 exec/s: 0 rss: 173Mb Step #5: ==129424== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f74bfc69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f75262b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f75260e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f75260e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f74bfccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f74bf2db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f74bf28355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f74bfbec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f74ef8df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f74ef8df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f74ef8df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f74ef8df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f74ef8df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f74ef8df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f74ef8df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f74ef8df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f74ef8df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f74ef8df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f751222f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f74df4fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f74df5abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f74dd06c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f74dd06c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f74dd07738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f74dd06874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f74dd06874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f74dd06874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f752610abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f752619928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f752601699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f75262c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8229eca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f74bf26b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x0,0x0,0x0,0x0,0x0,0x6c,0x7c,0x0,0x33,0x0,0x0,0x0,0x0,0x6c,0x0,0x0,0x0,0x0,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x33,0x0,0x0,0x0,0x0,0x6c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x73,0x65,0x74,0x0,0x0,0xd6,0xad,0xff,0xfc,0x0,0x27,0xd6,0xae,0xd5,0x0,0x0, Step #5: M\000\000\000\000\000l|\0003\000\000\000\000l\000\000\000\000\003\003\003\003\003\003\003\003\003\000\000\000\000\000\000\000\0003\000\000\000\000l\000\000\000\000\000\000\000\000set\000\000\326\255\377\374\000'\326\256\325\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4c93dfebb1c372dae22b28c33410dfdb9a578bf0 Step #5: Base64: TQAAAAAAbHwAMwAAAABsAAAAAAMDAwMDAwMDAwAAAAAAAAAAMwAAAABsAAAAAAAAAABzZXQAANat//wAJ9au1QAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3594 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3493450402 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a7a4f4a810, 0x55a7a513401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a7a5134020,0x55a7a6fcc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4c93dfebb1c372dae22b28c33410dfdb9a578bf0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4443 processed earlier; will process 6586 files now Step #5: ==129460== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a79ba3f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a7a20a4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a7a20875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a7a20874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a79ba45d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a79b9a6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a79b9a1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a79ba37c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a79ea06f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a79ea06f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a79ea06f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a79ea06f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a79ea06f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a79ea06f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a79ea06f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a79ea06f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a79ea06f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a79ea06f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a7a0c9bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a79d9c8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a79d9d3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a79d77fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a79d77fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a79d780738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a79d77f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a79d77f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a79d77f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a7a2089abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a7a2092928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a7a207a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a7a20a5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9190b80082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a79b99fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x40,0x12,0x3e,0xa,0x3c,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xc,0x64,0xf0,0x91,0x91,0x99,0x3c,0xd,0x62,0xf0,0x91,0x91,0x99,0x65,0x64,0xf0,0x91,0x99,0x99,0x7a,0x70,0x69,0x64,0xf0,0x91,0x99,0x99,0x65,0x63,0x69,0x64,0xf0,0x91,0x99,0x99,0x69,0x64,0xf0,0x91,0x91,0x99,0x65,0x64,0xf0,0x91,0x99,0x99,0x4c,0x5a,0x20,0x20,0x20, Step #5: \012@\022>\012<//+build\014d\360\221\221\231<\015b\360\221\221\231ed\360\221\231\231zpid\360\221\231\231ecid\360\221\231\231id\360\221\221\231ed\360\221\231\231LZ Step #5: artifact_prefix='./'; Test unit written to ./oom-5dfeac44f9a9ee2245d4746d503959e5300eaf74 Step #5: Base64: CkASPgo8Ly8rYnVpbGQMZPCRkZk8DWLwkZGZZWTwkZmZenBpZPCRmZllY2lk8JGZmWlk8JGRmWVk8JGZmUxaICAg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3595 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3493940275 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557a2952b810, 0x557a2971501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557a29715020,0x557a2b5ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5dfeac44f9a9ee2245d4746d503959e5300eaf74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4444 processed earlier; will process 6585 files now Step #5: #1 pulse cov: 3435 ft: 3436 exec/s: 0 rss: 174Mb Step #5: ==129496== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557a200209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557a26685898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557a266685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557a266684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557a20026d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557a1ff87b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557a1ff82355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557a20018c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557a22fe7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557a22fe7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557a22fe7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557a22fe7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557a22fe7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557a22fe7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557a22fe7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557a22fe7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557a22fe7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557a22fe7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557a2527cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557a21fa9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557a21fb4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557a21d60c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557a21d60c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557a21d61738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557a21d60874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557a21d60874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557a21d60874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557a2666aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557a26673928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557a2665b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557a26686112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53b4bbf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557a1ff80b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x0,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x25,0x7d,0x7b,0x34,0x31,0x2c,0x3a,0x7b,0x20,0x7b,0x7d,0x30,0x2c,0x7d,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x0,0xb,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x2c,0x7d, Step #5: }{0,} {0\000}${0,}%}{41,:{ {}0,}} {0,} {\000\0130,}s{0,} {0,}${0,} {0,} {,} Step #5: artifact_prefix='./'; Test unit written to ./oom-5876434e105e42792043c9e43a49d6881a41b0dd Step #5: Base64: fXswLH0gezAAfSR7MCx9JX17NDEsOnsge30wLH19IHswLH0gewALMCx9c3swLH0gezAsfSR7MCx9IHswLH0geyx9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3596 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3494472135 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a78270810, 0x559a7845a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a7845a020,0x559a7a2f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5876434e105e42792043c9e43a49d6881a41b0dd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4446 processed earlier; will process 6583 files now Step #5: #1 pulse cov: 3772 ft: 3773 exec/s: 0 rss: 173Mb Step #5: ==129532== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559a6ed659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a753ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a753ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a753ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a6ed6bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a6ecccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a6ecc7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a6ed5dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a71d2cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a71d2cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a71d2cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a71d2cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a71d2cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a71d2cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a71d2cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a71d2cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a71d2cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a71d2cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a73fc1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a70ceeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a70cf9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a70aa5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a70aa5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a70aa6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a70aa5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a70aa5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a70aa5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a753afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a753b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a753a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a753cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0288b14082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a6ecc5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x6f,0x63,0x69,0x56,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x31,0x2e,0x30,0x2e,0x30,0x22,0x2c,0x22,0x6c,0x69,0x6e,0x75,0x78,0x22,0x3a,0x7b,0x22,0x6d,0x61,0x73,0x6b,0x65,0x64,0x50,0x61,0x74,0x68,0x73,0x22,0x3a,0x5b,0x22,0x2f,0x70,0x72,0x6f,0x63,0x2f,0x73,0x79,0x73,0x72,0x71,0x2d,0x74,0x72,0x37,0x22,0x5d,0x7d,0x7d, Step #5: {\"ociVersion\":\"1.0.0\",\"linux\":{\"maskedPaths\":[\"/proc/sysrq-tr7\"]}} Step #5: artifact_prefix='./'; Test unit written to ./oom-5d88f0ea2259630873dda514325b2379bd525307 Step #5: Base64: eyJvY2lWZXJzaW9uIjoiMS4wLjAiLCJsaW51eCI6eyJtYXNrZWRQYXRocyI6WyIvcHJvYy9zeXNycS10cjciXX19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3597 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3494997974 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559371bb6810, 0x559371da001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559371da0020,0x559373c380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5d88f0ea2259630873dda514325b2379bd525307' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4448 processed earlier; will process 6581 files now Step #5: #1 pulse cov: 11250 ft: 11251 exec/s: 0 rss: 190Mb Step #5: ==129568== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5593686ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55936ed10898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55936ecf35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55936ecf34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5593686b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559368612b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55936860d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5593686a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55936b672f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55936b672f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55936b672f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55936b672f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55936b672f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55936b672f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55936b672f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55936b672f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55936b672f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55936b672f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55936d907f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55936a634b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55936a63fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55936a3ebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55936a3ebc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55936a3ec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55936a3eb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55936a3eb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55936a3eb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55936ecf5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55936ecfe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55936ece6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55936ed11112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7de7b00082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55936860bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x73,0x74,0x20,0x37,0x30,0x20,0x60,0xa,0x9,0xa,0x60,0x2d,0x0,0x60,0x65,0x72,0x69,0x66,0x60,0x20,0x20,0x20,0x60,0xa,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0xf3,0xa0,0x80,0xa4,0x68,0x11,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x9, Step #5: `st 70 `\012\011\012`-\000`erif` `\012hhhhhhhhhhhhhhhhhhhhhhhh\363\240\200\244h\021hhhhhhhhhh\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-32b5b0958b5a5c386cdfd5546f8c2df843019943 Step #5: Base64: YHN0IDcwIGAKCQpgLQBgZXJpZmAgICBgCmhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaPOggKRoEWhoaGhoaGhoaGgJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3598 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3495682825 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5593d6807810, 0x5593d69f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5593d69f1020,0x5593d88890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/32b5b0958b5a5c386cdfd5546f8c2df843019943' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4450 processed earlier; will process 6579 files now Step #5: ==129604== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5593cd2fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5593d3961898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5593d39445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5593d39444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5593cd302d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5593cd263b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5593cd25e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5593cd2f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5593d02c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5593d02c3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5593d02c3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5593d02c3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5593d02c3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5593d02c3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5593d02c3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5593d02c3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5593d02c3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5593d02c3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5593d2558f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5593cf285b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5593cf290be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5593cf03cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5593cf03cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5593cf03d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5593cf03c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5593cf03c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5593cf03c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5593d3946abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5593d394f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5593d3937699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5593d3962112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffb25b22082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5593cd25cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x40,0x12,0x3e,0xa,0x3c,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xd,0x62,0x3c,0xd,0x62,0xf0,0x91,0x93,0x99,0x65,0x64,0xf0,0x91,0x99,0x99,0xf0,0x91,0x93,0x99,0x64,0xd,0x62,0xf0,0x91,0x93,0x99,0x65,0x64,0xf0,0x91,0x99,0x99,0xf0,0x91,0x93,0x99,0x64,0xf0,0x91,0x99,0x99,0x7a,0xf0,0x91,0x99,0x99,0x0,0x0,0x64,0x20,0x1a,0x20, Step #5: \012@\022>\012<//+build\015b<\015b\360\221\223\231ed\360\221\231\231\360\221\223\231d\015b\360\221\223\231ed\360\221\231\231\360\221\223\231d\360\221\231\231z\360\221\231\231\000\000d \032 Step #5: artifact_prefix='./'; Test unit written to ./oom-163a9f6ab0fcd6855520aa027ef91534f90e6d46 Step #5: Base64: CkASPgo8Ly8rYnVpbGQNYjwNYvCRk5llZPCRmZnwkZOZZA1i8JGTmWVk8JGZmfCRk5lk8JGZmXrwkZmZAABkIBog Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3599 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3496176184 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5625b58c5810, 0x5625b5aaf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625b5aaf020,0x5625b79470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/163a9f6ab0fcd6855520aa027ef91534f90e6d46' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4451 processed earlier; will process 6578 files now Step #5: ==129640== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5625ac3ba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5625b2a1f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625b2a025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625b2a024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5625ac3c0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625ac321b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625ac31c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5625ac3b2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5625af381f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5625af381f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5625af381f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5625af381f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5625af381f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5625af381f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5625af381f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5625af381f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5625af381f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5625af381f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5625b1616f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625ae343b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5625ae34ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5625ae0fac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5625ae0fac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5625ae0fb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5625ae0fa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5625ae0fa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5625ae0fa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5625b2a04abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5625b2a0d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5625b29f5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5625b2a20112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1aa5f0f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625ac31ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x31,0x2a,0x33,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x33,0x2a,0x32,0x2a,0x32,0x2a,0x32,0x2a,0x32, Step #5: (2*2*2*2*2*2*1*3*2*2*2*2*2*2*2*2*2*2*2*2*2*2*2*2*2*2*2*2*3*2*2*2*2 Step #5: artifact_prefix='./'; Test unit written to ./oom-525ee0643f226d7a33547348af83aa2befd8b93a Step #5: Base64: KDIqMioyKjIqMioyKjEqMyoyKjIqMioyKjIqMioyKjIqMioyKjIqMioyKjIqMioyKjIqMioyKjIqMyoyKjIqMioy Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3600 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3496660704 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c746aac810, 0x55c746c9601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c746c96020,0x55c748b2e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/525ee0643f226d7a33547348af83aa2befd8b93a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4452 processed earlier; will process 6577 files now Step #5: ==129676== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c73d5a19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c743c06898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c743be95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c743be94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c73d5a7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c73d508b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c73d503355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c73d599c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c740568f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c740568f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c740568f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c740568f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c740568f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c740568f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c740568f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c740568f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c740568f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c740568f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7427fdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c73f52ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c73f535be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c73f2e1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c73f2e1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c73f2e2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c73f2e1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c73f2e1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c73f2e1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c743bebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c743bf4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c743bdc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c743c07112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7136780082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c73d501b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x3f,0x20,0x22,0xf2,0x89,0x87,0x88,0xea,0x82,0x89,0xea,0x90,0x88,0xea,0x8a,0x88,0xea,0x90,0xa1,0xea,0x8a,0x88,0xea,0xb0,0x88,0xea,0x90,0x88,0xea,0x8a,0x88,0xea,0x90,0xa1,0xea,0x8a,0x88,0xea,0xb0,0x88,0xeb,0x8a,0x88,0xea,0xbc,0xdf,0x22,0xf2,0x89,0x87,0x88,0xea,0x82,0x88,0xea,0x90,0x88,0xea,0x8a,0x88,0xea,0x8f,0xa1,0x7b, Step #5: HU? \"\362\211\207\210\352\202\211\352\220\210\352\212\210\352\220\241\352\212\210\352\260\210\352\220\210\352\212\210\352\220\241\352\212\210\352\260\210\353\212\210\352\274\337\"\362\211\207\210\352\202\210\352\220\210\352\212\210\352\217\241{ Step #5: artifact_prefix='./'; Test unit written to ./oom-4b7412c8f6dd7e8c494ae800df00b4b79fcd7cf9 Step #5: Base64: SFU/ICLyiYeI6oKJ6pCI6oqI6pCh6oqI6rCI6pCI6oqI6pCh6oqI6rCI64qI6rzfIvKJh4jqgojqkIjqiojqj6F7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3601 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3497150509 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5609a4895810, 0x5609a4a7f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5609a4a7f020,0x5609a69170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4b7412c8f6dd7e8c494ae800df00b4b79fcd7cf9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4453 processed earlier; will process 6576 files now Step #5: #1 pulse cov: 3525 ft: 3526 exec/s: 0 rss: 175Mb Step #5: ==129712== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56099b38a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5609a19ef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5609a19d25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5609a19d24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56099b390d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56099b2f1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56099b2ec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56099b382c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56099e351f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56099e351f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56099e351f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56099e351f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56099e351f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56099e351f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56099e351f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56099e351f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56099e351f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56099e351f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5609a05e6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56099d313b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56099d31ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56099d0cac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56099d0cac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56099d0cb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56099d0ca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56099d0ca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56099d0ca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5609a19d4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5609a19dd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5609a19c5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5609a19f0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f49ca374082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56099b2eab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x40,0x12,0x3e,0xa,0x3c,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xd,0x40,0xf2,0x90,0x91,0xbf,0x6c,0x0,0x0,0x0,0xd,0xf0,0x90,0xba,0xb1,0x6c,0x0,0x0,0x0,0x15,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6c,0x0,0xf3,0xa0,0x81,0xaa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1d,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: \012@\022>\012<//+build\015@\362\220\221\277l\000\000\000\015\360\220\272\261l\000\000\000\025\000\000\000\000\000\000\000l\000\363\240\201\252\000\000\000\000\000\000\000\000\000\000\000\035\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-331957733d2c2d4cc5f9deb3c3420a2c3aef996d Step #5: Base64: CkASPgo8Ly8rYnVpbGQNQPKQkb9sAAAADfCQurFsAAAAFQAAAAAAAABsAPOggaoAAAAAAAAAAAAAAB0AAAAAAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3602 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3497683897 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5576c8b25810, 0x5576c8d0f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5576c8d0f020,0x5576caba70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/331957733d2c2d4cc5f9deb3c3420a2c3aef996d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4455 processed earlier; will process 6574 files now Step #5: ==129748== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5576bf61a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5576c5c7f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5576c5c625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5576c5c624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5576bf620d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5576bf581b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5576bf57c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5576bf612c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576c25e1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576c25e1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576c25e1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576c25e1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576c25e1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576c25e1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576c25e1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576c25e1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576c25e1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576c25e1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5576c4876f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5576c15a3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5576c15aebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5576c135ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5576c135ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5576c135b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5576c135a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5576c135a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5576c135a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5576c5c64abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5576c5c6d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5576c5c55699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5576c5c80112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ea112d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5576bf57ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0x26,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2b,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2b,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a,0xd,0x2a, Step #5: \015&\015*\015*\015*\015*\015*\015*\015*\015*\015*\015*\015+\015*\015*\015*\015*\015*\015*\015*\015*\015*\015*\015*\015*\015*\015+\015*\015*\015*\015*\015*\015*\015* Step #5: artifact_prefix='./'; Test unit written to ./oom-b8308c2fa66386cee47ca60429b5e6684784a18c Step #5: Base64: DSYNKg0qDSoNKg0qDSoNKg0qDSoNKg0rDSoNKg0qDSoNKg0qDSoNKg0qDSoNKg0qDSoNKw0qDSoNKg0qDSoNKg0q Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3603 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3498179387 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d269a1810, 0x561d26b8b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d26b8b020,0x561d28a230e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b8308c2fa66386cee47ca60429b5e6684784a18c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4456 processed earlier; will process 6573 files now Step #5: #1 pulse cov: 4243 ft: 4244 exec/s: 0 rss: 173Mb Step #5: ==129784== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d1d4969c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d23afb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d23ade5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d23ade4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d1d49cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d1d3fdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d1d3f8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d1d48ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d2045df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d2045df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d2045df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d2045df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d2045df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d2045df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d2045df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d2045df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d2045df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d2045df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d226f2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d1f41fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d1f42abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d1f1d6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d1f1d6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d1f1d7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d1f1d6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d1f1d6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d1f1d6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d23ae0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d23ae9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d23ad1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d23afc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f684a4e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d1d3f6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x32,0x2e,0x32,0x33,0x2f,0x10,0x5d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x0,0x0,0x7f,0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x0,0x0,0x0, Step #5: $\177]\177\000\000\0002\000\000\0002.23/\020]\177\000\000\0002\000\000\0002.23/\020./( ./( 7 =\177\000\000\0002\000\000\000\000\000\177/\000\000\000\000\000\000\000$\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-56cbbfc8e7c4bd4bc238ae9b4bb191e9eaafbcf7 Step #5: Base64: JH9dfwAAADIAAAAyLjIzLxBdfwAAADIAAAAyLjIzLxAuLyggLi8oIDcgPX8AAAAyAAAAAAB/LwAAAAAAAAAkAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3604 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3498721325 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c3b27be810, 0x55c3b29a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c3b29a8020,0x55c3b48400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56cbbfc8e7c4bd4bc238ae9b4bb191e9eaafbcf7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4458 processed earlier; will process 6571 files now Step #5: ==129820== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c3a92b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c3af918898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c3af8fb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c3af8fb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c3a92b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c3a921ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c3a9215355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c3a92abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c3ac27af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c3ac27af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c3ac27af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c3ac27af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c3ac27af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c3ac27af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c3ac27af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c3ac27af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c3ac27af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c3ac27af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c3ae50ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c3ab23cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c3ab247be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c3aaff3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c3aaff3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c3aaff4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c3aaff3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c3aaff3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c3aaff3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c3af8fdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c3af906928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c3af8ee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c3af919112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95ead3b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c3a9213b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2c,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x3d,0x1d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x31,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x24,0x43,0x47,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1b, Step #5: x---,--BEGIN -----\012=\035\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0001\000\000\000\000\000\000\000$$CG\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\033 Step #5: artifact_prefix='./'; Test unit written to ./oom-0386f46af1bb9039aabe7b70defbdfb0cf1df945 Step #5: Base64: eC0tLSwtLUJFR0lOIC0tLS0tCj0dAAAAAAAAAAAAAAAAAAAAMQAAAAAAAAAkJENHAAAAAAAAAAAAAAAAAAAAAAAb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3605 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3499213546 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55adf9f20810, 0x55adfa10a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55adfa10a020,0x55adfbfa20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0386f46af1bb9039aabe7b70defbdfb0cf1df945' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4459 processed earlier; will process 6570 files now Step #5: #1 pulse cov: 3468 ft: 3469 exec/s: 0 rss: 172Mb Step #5: ==129856== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55adf0a159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55adf707a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55adf705d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55adf705d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55adf0a1bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55adf097cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55adf0977355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55adf0a0dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55adf39dcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55adf39dcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55adf39dcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55adf39dcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55adf39dcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55adf39dcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55adf39dcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55adf39dcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55adf39dcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55adf39dcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55adf5c71f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55adf299eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55adf29a9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55adf2755c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55adf2755c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55adf2756738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55adf2755874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55adf2755874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55adf2755874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55adf705fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55adf7068928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55adf7050699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55adf707b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbb02110082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55adf0975b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x76,0x6f,0x69,0x64,0x20,0x6f,0x28,0x29,0x7b,0x69,0x6e,0x74,0x5b,0x39,0x2e,0x2c,0x31,0x2e,0x6e,0x5b,0x39,0x2e,0x2c,0x31,0x2e,0x6e,0x5b,0x38,0x2e,0x2c,0x39,0x2e,0x6e,0x5b,0x39,0x2e,0x2c,0x37,0x2e,0x74,0x5b,0x39,0x2e,0x2c,0x37,0x2e,0x6e,0x5b,0x33,0x2e,0x2c,0x31,0x2e,0x6e,0x5b,0x39,0x2e,0x2c,0x37,0x2e,0x6e,0x5b,0x34,0x2e,0x2c,0x31,0x2e, Step #5: void o(){int[9.,1.n[9.,1.n[8.,9.n[9.,7.t[9.,7.n[3.,1.n[9.,7.n[4.,1. Step #5: artifact_prefix='./'; Test unit written to ./oom-73e73752e17fb4a5f9a7e00a794e9c2b08f5a00e Step #5: Base64: dm9pZCBvKCl7aW50WzkuLDEubls5LiwxLm5bOC4sOS5uWzkuLDcudFs5Liw3Lm5bMy4sMS5uWzkuLDcubls0LiwxLg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3606 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3499739037 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ae4a85f810, 0x55ae4aa4901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ae4aa49020,0x55ae4c8e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/73e73752e17fb4a5f9a7e00a794e9c2b08f5a00e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4461 processed earlier; will process 6568 files now Step #5: #1 pulse cov: 10719 ft: 10720 exec/s: 0 rss: 192Mb Step #5: #2 pulse cov: 11234 ft: 12005 exec/s: 0 rss: 194Mb Step #5: ==129892== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ae413549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ae479b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ae4799c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ae4799c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ae4135ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ae412bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ae412b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ae4134cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ae4431bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ae4431bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ae4431bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ae4431bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ae4431bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ae4431bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ae4431bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ae4431bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ae4431bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ae4431bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ae465b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ae432ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ae432e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ae43094c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ae43094c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ae43095738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ae43094874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ae43094874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ae43094874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ae4799eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ae479a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ae4798f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ae479ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f84912ef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ae412b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x29,0x29,0x7c,0x29,0x7c,0x29,0x7c, Step #5: (?:(?:(?:$|$|(?:(?:(?:$|$|$|$|$|$|$|$|$|$|$|$|$)|$|$|$|$|$)|))|)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-76aaa9b1b8fa151614e7b6cc37fba73e0ad68a6e Step #5: Base64: KD86KD86KD86JHwkfCg/Oig/Oig/OiR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkfCQpfCR8JHwkfCR8JCl8KSl8KXwpfA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3607 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3500373258 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56492d8dc810, 0x56492dac601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56492dac6020,0x56492f95e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/76aaa9b1b8fa151614e7b6cc37fba73e0ad68a6e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4464 processed earlier; will process 6565 files now Step #5: ==129928== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5649243d19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56492aa36898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56492aa195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56492aa194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5649243d7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564924338b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564924333355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5649243c9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564927398f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564927398f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564927398f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564927398f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564927398f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564927398f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564927398f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564927398f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564927398f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564927398f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56492962df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56492635ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564926365be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564926111c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564926111c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564926112738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564926111874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564926111874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564926111874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56492aa1babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56492aa24928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56492aa0c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56492aa37112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ed58db082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564924331b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80,0xcd,0x80, Step #5: ws:\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200\315\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-53c84b8bf688c90954765a9eac6bfd2174b8b5a0 Step #5: Base64: d3M6zYDNgM2AzYDNgM2AzYDNgM2AzYDNgM2AzYDNgM2AzYDNgM2AzYDNgM2AzYDNgM2AzYDNgM2AzYDNgM2AzYDNgA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3608 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3500863598 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56153eb73810, 0x56153ed5d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56153ed5d020,0x561540bf50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/53c84b8bf688c90954765a9eac6bfd2174b8b5a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4465 processed earlier; will process 6564 files now Step #5: #1 pulse cov: 3546 ft: 3547 exec/s: 0 rss: 172Mb Step #5: ==129964== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5615356689c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56153bccd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56153bcb05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56153bcb04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56153566ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5615355cfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5615355ca355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561535660c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56153862ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56153862ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56153862ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56153862ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56153862ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56153862ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56153862ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56153862ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56153862ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56153862ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56153a8c4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5615375f1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5615375fcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5615373a8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5615373a8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5615373a9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5615373a8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5615373a8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5615373a8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56153bcb2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56153bcbb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56153bca3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56153bcce112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f62f6e54082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5615355c8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x4c,0x30,0x46,0x77,0x48,0x65,0x57,0x53,0x63,0x6f,0x41,0x61,0x71,0x59,0x30,0x2b,0x6a,0x47,0x46,0x43,0x4c,0x63,0x77,0x41,0x6d,0x57,0x65,0x48,0x53,0x63,0x6f,0x41,0x61,0x71,0x6a,0x3d,0x2b,0x6d,0x66,0x37,0x35, Step #5: onion-key\012ntor-onion-key vL0FwHeWScoAaqY0+jGFCLcwAmWeHScoAaqj=+mf75 Step #5: artifact_prefix='./'; Test unit written to ./oom-1ec7e2811346676f7d207df25b194009551cff81 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHZMMEZ3SGVXU2NvQWFxWTArakdGQ0xjd0FtV2VIU2NvQWFxaj0rbWY3NQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3609 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3501393491 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55efc4082810, 0x55efc426c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55efc426c020,0x55efc61040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ec7e2811346676f7d207df25b194009551cff81' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4467 processed earlier; will process 6562 files now Step #5: #1 pulse cov: 3605 ft: 3606 exec/s: 0 rss: 174Mb Step #5: ==130000== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55efbab779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55efc11dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55efc11bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55efc11bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55efbab7dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55efbaadeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55efbaad9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55efbab6fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55efbdb3ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55efbdb3ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55efbdb3ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55efbdb3ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55efbdb3ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55efbdb3ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55efbdb3ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55efbdb3ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55efbdb3ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55efbdb3ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55efbfdd3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55efbcb00b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55efbcb0bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55efbc8b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55efbc8b7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55efbc8b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55efbc8b7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55efbc8b7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55efbc8b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55efc11c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55efc11ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55efc11b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55efc11dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f59497eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55efbaad7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x73,0x3a,0xd9,0xb7,0x36,0x2e,0xd9,0xb7,0x38,0x2e,0xd9,0xb7,0x39,0x2e,0xd9,0xb7,0x38,0x2e,0xd9,0xb7,0x38,0x2e,0xd9,0xb7,0x38,0x2e,0xd9,0xb7,0x38,0x2e,0xd9,0xb7,0x38,0x2e,0xd9,0xb7,0x33,0x2e,0xd9,0xb7,0x38,0x2e,0xd9,0xb7,0x39,0x2e,0xd9,0xb7,0x38,0x2e,0xd9,0xb7,0x33,0x2e,0xd9,0xb7,0x32,0x2e,0xd9,0xb7,0x39,0x2e,0xd9,0xb7,0x38, Step #5: \016ws:\331\2676.\331\2678.\331\2679.\331\2678.\331\2678.\331\2678.\331\2678.\331\2678.\331\2673.\331\2678.\331\2679.\331\2678.\331\2673.\331\2672.\331\2679.\331\2678 Step #5: artifact_prefix='./'; Test unit written to ./oom-4002c3d198ba0b4e4ca9e55114e6201be855e415 Step #5: Base64: DndzOtm3Ni7Ztzgu2bc5Ltm3OC7Ztzgu2bc4Ltm3OC7Ztzgu2bczLtm3OC7Ztzku2bc4Ltm3My7ZtzIu2bc5Ltm3OA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3610 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3501937166 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d9d240810, 0x561d9d42a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d9d42a020,0x561d9f2c20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4002c3d198ba0b4e4ca9e55114e6201be855e415' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4469 processed earlier; will process 6560 files now Step #5: ==130036== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d93d359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d9a39a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d9a37d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d9a37d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d93d3bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d93c9cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d93c97355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d93d2dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d96cfcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d96cfcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d96cfcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d96cfcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d96cfcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d96cfcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d96cfcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d96cfcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d96cfcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d96cfcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d98f91f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d95cbeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d95cc9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d95a75c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d95a75c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d95a76738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d95a75874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d95a75874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d95a75874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d9a37fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d9a388928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d9a370699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d9a39b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ceed23082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d93c95b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x68,0x3a,0x2f,0xcd,0x95,0xcd,0x9d,0xcd,0x9b,0xcd,0x9b,0xcd,0x89,0xcd,0x96,0xcd,0x9b,0xcd,0x9b,0xcd,0x95,0xcd,0x95,0xcd,0x95,0xcd,0x9b,0xcd,0x95,0xcd,0x9b,0xcd,0x95,0xcd,0x95,0xcd,0x95,0xcd,0x9b,0xcd,0x95,0xcf,0x9d,0xcd,0x95,0xcd,0x94,0xcd,0x82,0xcd,0x95,0xcd,0x95,0xcd,0x95,0xcd,0x95,0xcd,0x95,0xcd,0x95,0xcd,0x95,0xcd,0x95,0xcd,0x9d, Step #5: h:/\315\225\315\235\315\233\315\233\315\211\315\226\315\233\315\233\315\225\315\225\315\225\315\233\315\225\315\233\315\225\315\225\315\225\315\233\315\225\317\235\315\225\315\224\315\202\315\225\315\225\315\225\315\225\315\225\315\225\315\225\315\225\315\235 Step #5: artifact_prefix='./'; Test unit written to ./oom-09079516397b4ab94627cbc4ea10a029089f8332 Step #5: Base64: aDovzZXNnc2bzZvNic2WzZvNm82VzZXNlc2bzZXNm82VzZXNlc2bzZXPnc2VzZTNgs2VzZXNlc2VzZXNlc2VzZXNnQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3611 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3502437413 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557364846810, 0x557364a3001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557364a30020,0x5573668c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/09079516397b4ab94627cbc4ea10a029089f8332' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4470 processed earlier; will process 6559 files now Step #5: #1 pulse cov: 3795 ft: 3796 exec/s: 0 rss: 172Mb Step #5: ==130072== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55735b33b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5573619a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5573619835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5573619834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55735b341d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55735b2a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55735b29d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55735b333c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55735e302f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55735e302f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55735e302f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55735e302f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55735e302f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55735e302f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55735e302f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55735e302f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55735e302f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55735e302f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557360597f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55735d2c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55735d2cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55735d07bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55735d07bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55735d07c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55735d07b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55735d07b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55735d07b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557361985abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55736198e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557361976699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5573619a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb8334af082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55735b29bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xc8,0xac,0xcc,0xb8,0xc8,0xad,0xcc,0xac,0xc8,0xac,0xcc,0xb8,0xc8,0xad,0xcc,0xac,0xc8,0xad,0xcc,0xac,0xc8,0xad,0xcc,0xa9,0xc7,0xad,0xcc,0xb8,0xc8,0xad,0xcc,0xac,0xc8,0xad,0xcc,0xa9,0xc8,0xad,0xcc,0xb8,0xc8,0xad,0xcc,0xad,0xc8,0xad,0xcc,0xac,0xc8,0xad,0xcc,0xb8,0xc8,0xad,0xcc,0xac,0xc8,0xad,0xcc,0xb8,0xc8,0xad,0xcc,0xac, Step #5: ws:\310\254\314\270\310\255\314\254\310\254\314\270\310\255\314\254\310\255\314\254\310\255\314\251\307\255\314\270\310\255\314\254\310\255\314\251\310\255\314\270\310\255\314\255\310\255\314\254\310\255\314\270\310\255\314\254\310\255\314\270\310\255\314\254 Step #5: artifact_prefix='./'; Test unit written to ./oom-e7d348aacae1741614e934cd1f6ec8dc6c4e983d Step #5: Base64: d3M6yKzMuMitzKzIrMy4yK3MrMitzKzIrcypx63MuMitzKzIrcypyK3MuMitzK3IrcysyK3MuMitzKzIrcy4yK3MrA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3612 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3502985142 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557e9572d810, 0x557e9591701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557e95917020,0x557e977af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e7d348aacae1741614e934cd1f6ec8dc6c4e983d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4472 processed earlier; will process 6557 files now Step #5: ==130108== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557e8c2229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557e92887898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557e9286a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557e9286a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557e8c228d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557e8c189b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557e8c184355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557e8c21ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557e8f1e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557e8f1e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557e8f1e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557e8f1e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557e8f1e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557e8f1e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557e8f1e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557e8f1e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557e8f1e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557e8f1e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557e9147ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557e8e1abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557e8e1b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557e8df62c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557e8df62c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557e8df63738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557e8df62874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557e8df62874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557e8df62874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557e9286cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557e92875928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557e9285d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557e92888112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f73e7429082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557e8c182b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x3f,0x7e,0x3d,0x3a,0xa,0x65,0x3a,0xa,0x6f,0x6e,0x3a,0xa,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x3f,0x20,0x2d,0x20,0x20,0x6e,0x3a,0xa,0x20,0x2d,0x20,0x2d,0x20,0x20,0x6e,0x3a,0xa,0x20,0x2d,0x20,0x2d,0x20,0x3a,0xa,0x20, Step #5: \000\000\000?~=:\012e:\012on:\012 - - - - - - - - - - - - - ? - n:\012 - - n:\012 - - :\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-43125e3858c73848314c42f4f8e199f81972dcfa Step #5: Base64: AAAAP349OgplOgpvbjoKIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gPyAtICBuOgogLSAtICBuOgogLSAtIDoKIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3613 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3503504736 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea86d3d810, 0x55ea86f2701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea86f27020,0x55ea88dbf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/43125e3858c73848314c42f4f8e199f81972dcfa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4473 processed earlier; will process 6556 files now Step #5: ==130144== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ea7d8329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea83e97898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea83e7a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea83e7a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea7d838d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea7d799b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea7d794355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea7d82ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea807f9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea807f9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea807f9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea807f9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea807f9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea807f9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea807f9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea807f9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea807f9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea807f9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea82a8ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea7f7bbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea7f7c6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea7f572c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea7f572c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea7f573738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea7f572874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea7f572874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea7f572874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea83e7cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea83e85928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea83e6d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea83e98112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f040fa77082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea7d792b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x28,0x28,0x28,0x3c,0x28,0x2e,0x0,0x5e,0x4,0x2e,0x4,0x2b,0x24,0x24,0x5e,0x0,0x2e,0x1,0x7d,0x49,0x44,0x33,0x4,0x2d,0x0,0x7f,0x7f,0x7f,0x2b,0x7c,0x29,0x7b,0x32,0x7d,0x5,0x29,0x7b,0x7f,0x0,0x75,0x67,0x3,0xf,0x75,0x32,0x7d,0x5,0x7c,0x29,0x7b,0x34,0x7d,0x29,0x7b,0x35,0x7d,0x29,0x7b,0x33,0x67,0x3,0x7d,0xf,0xee,0xee,0xff, Step #5: ((((<(.\000^\004.\004+$$^\000.\001}ID3\004-\000\177\177\177+|){2}\005){\177\000ug\003\017u2}\005|){4}){5}){3g\003}\017\356\356\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-d945cd9ea2aa1045043e8d8cf5f3666501703b0a Step #5: Base64: KCgoKDwoLgBeBC4EKyQkXgAuAX1JRDMELQB/f38rfCl7Mn0FKXt/AHVnAw91Mn0FfCl7NH0pezV9KXszZwN9D+7u/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3614 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3504000875 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a06038810, 0x561a0622201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a06222020,0x561a080ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d945cd9ea2aa1045043e8d8cf5f3666501703b0a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4474 processed earlier; will process 6555 files now Step #5: #1 pulse cov: 3862 ft: 3863 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4057 ft: 4382 exec/s: 0 rss: 176Mb Step #5: ==130180== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5619fcb2d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561a03192898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561a031755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561a031754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5619fcb33d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5619fca94b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5619fca8f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5619fcb25c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5619ffaf4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5619ffaf4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5619ffaf4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5619ffaf4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5619ffaf4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5619ffaf4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5619ffaf4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5619ffaf4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5619ffaf4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5619ffaf4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561a01d89f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5619feab6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5619feac1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5619fe86dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5619fe86dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5619fe86e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5619fe86d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5619fe86d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5619fe86d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561a03177abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561a03180928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561a03168699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561a03193112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1157748082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5619fca8db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x45,0x78,0x65,0x63,0x5d,0xd,0xd,0x29,0xd,0x2c,0x0,0x9,0x55,0x73,0x65,0x72,0x20,0x3d,0x37,0x39,0x20,0x5f,0x20,0x5f,0x20,0x5f,0x20,0x5f,0x20,0x20,0x5f,0x20,0x5f,0x20,0x5f,0x55,0xd,0x2c,0x0,0x9,0x55,0x73,0x65,0x72,0x20,0x3d,0x37,0x39,0x20,0x5f,0x20,0x5f,0x20,0x5f,0x20,0x20,0x5f,0x5f,0x20,0x5f,0x20,0x5f,0x0,0x20,0x20,0x45, Step #5: [Exec]\015\015)\015,\000\011User =79 _ _ _ _ _ _ _U\015,\000\011User =79 _ _ _ __ _ _\000 E Step #5: artifact_prefix='./'; Test unit written to ./oom-7a0ab642fcaea2053f4d1691c1b42d479c19d258 Step #5: Base64: W0V4ZWNdDQ0pDSwACVVzZXIgPTc5IF8gXyBfIF8gIF8gXyBfVQ0sAAlVc2VyID03OSBfIF8gXyAgX18gXyBfACAgRQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3615 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3504567828 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5556dd030810, 0x5556dd21a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5556dd21a020,0x5556df0b20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7a0ab642fcaea2053f4d1691c1b42d479c19d258' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4477 processed earlier; will process 6552 files now Step #5: ==130216== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5556d3b259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5556da18a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556da16d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556da16d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5556d3b2bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5556d3a8cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5556d3a87355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5556d3b1dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5556d6aecf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5556d6aecf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5556d6aecf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5556d6aecf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5556d6aecf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5556d6aecf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5556d6aecf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5556d6aecf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5556d6aecf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5556d6aecf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5556d8d81f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5556d5aaeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5556d5ab9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5556d5865c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5556d5865c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5556d5866738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5556d5865874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5556d5865874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5556d5865874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5556da16fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5556da178928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5556da160699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5556da18b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f722c93c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5556d3a85b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: ws:\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-e6c93b695a232ecf2857c2729f900863df831610 Step #5: Base64: d3M6zYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3616 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3505061921 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559785a1e810, 0x559785c0801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559785c08020,0x559787aa00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e6c93b695a232ecf2857c2729f900863df831610' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4478 processed earlier; will process 6551 files now Step #5: #1 pulse cov: 3893 ft: 3894 exec/s: 0 rss: 175Mb Step #5: ==130252== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55977c5139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559782b78898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559782b5b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559782b5b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55977c519d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55977c47ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55977c475355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55977c50bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55977f4daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55977f4daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55977f4daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55977f4daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55977f4daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55977f4daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55977f4daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55977f4daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55977f4daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55977f4daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55978176ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55977e49cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55977e4a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55977e253c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55977e253c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55977e254738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55977e253874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55977e253874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55977e253874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559782b5dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559782b66928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559782b4e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559782b79112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f40e8007082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55977c473b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xf0,0x90,0x90,0x80,0xf0,0x90,0x90,0x82,0xf0,0x90,0x90,0x80,0xf0,0x90,0x90,0x80,0xf0,0x90,0x90,0x80,0xf0,0x90,0x90,0x80,0xf0,0x90,0xb2,0x80,0xf0,0x90,0x90,0x80,0xf0,0x90,0x90,0x80,0xf0,0x90,0x90,0x80,0xf0,0x90,0x90,0x80,0xf0,0x90,0xb2,0x80,0xf0,0x90,0x90,0x80,0xf0,0x90,0x90,0x80,0xf0,0x90,0x90,0x80,0xf0,0x90,0xb2,0x80, Step #5: ws:\360\220\220\200\360\220\220\202\360\220\220\200\360\220\220\200\360\220\220\200\360\220\220\200\360\220\262\200\360\220\220\200\360\220\220\200\360\220\220\200\360\220\220\200\360\220\262\200\360\220\220\200\360\220\220\200\360\220\220\200\360\220\262\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-3b9b02b192cdd9d3d7d3b2038d0a84f37d77fd34 Step #5: Base64: d3M68JCQgPCQkILwkJCA8JCQgPCQkIDwkJCA8JCygPCQkIDwkJCA8JCQgPCQkIDwkLKA8JCQgPCQkIDwkJCA8JCygA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3617 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3505599380 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c692790810, 0x55c69297a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c69297a020,0x55c6948120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3b9b02b192cdd9d3d7d3b2038d0a84f37d77fd34' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4480 processed earlier; will process 6549 files now Step #5: #1 pulse cov: 3508 ft: 3509 exec/s: 0 rss: 174Mb Step #5: ==130288== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c6892859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c68f8ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c68f8cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c68f8cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c68928bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6891ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6891e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c68927dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c68c24cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c68c24cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c68c24cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c68c24cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c68c24cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c68c24cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c68c24cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c68c24cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c68c24cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c68c24cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c68e4e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c68b20eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c68b219be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c68afc5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c68afc5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c68afc6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c68afc5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c68afc5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c68afc5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c68f8cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c68f8d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c68f8c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c68f8eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fde82224082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6891e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xcd,0x84,0xcd,0x80,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x80,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x80,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: ws:\315\204\315\200\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\200\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\200\315\204\315\204\315\204\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-983909b7fbaa9f33abd98b6cba615607009b8d1a Step #5: Base64: d3M6zYTNgM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYDNhM2EzYTNhM2EzYTNhM2EzYDNhM2EzYTNhM2EzYTNhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3618 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3506138163 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d31bd49810, 0x55d31bf3301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d31bf33020,0x55d31ddcb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/983909b7fbaa9f33abd98b6cba615607009b8d1a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4482 processed earlier; will process 6547 files now Step #5: ==130324== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d31283e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d318ea3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d318e865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d318e864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d312844d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d3127a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d3127a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d312836c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d315805f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d315805f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d315805f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d315805f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d315805f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d315805f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d315805f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d315805f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d315805f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d315805f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d317a9af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d3147c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d3147d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d31457ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d31457ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d31457f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d31457e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d31457e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d31457e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d318e88abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d318e91928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d318e79699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d318ea4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f161e193082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d31279eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x24,0x60,0x60,0x58,0x0,0x0,0x0,0x0,0x3b,0x2a,0x2c,0x0,0x68,0x60,0x40,0x5a,0x0,0x60,0x60,0x58,0x60,0x60,0x2a,0x0,0x0,0x0,0x0,0x2a,0x2c,0x0,0x68,0x60,0x60,0x60,0x2a,0x37,0xc3,0x37,0xc3,0x27,0x2d,0xc8, Step #5: $22-=<'''''2-='''2-='''''$``X\000\000\000\000;*,\000h`@Z\000``X``*\000\000\000\000*,\000h```*7\3037\303'-\310 Step #5: artifact_prefix='./'; Test unit written to ./oom-dff6a1394e99d355a8e8eba6d4f9ae09159efd4d Step #5: Base64: JDIyLT08JycnJycyLT0nJycyLT0nJycnJyRgYFgAAAAAOyosAGhgQFoAYGBYYGAqAAAAACosAGhgYGAqN8M3wyctyA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3619 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3506761202 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5632771c9810, 0x5632773b301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5632773b3020,0x56327924b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dff6a1394e99d355a8e8eba6d4f9ae09159efd4d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4483 processed earlier; will process 6546 files now Step #5: #1 pulse cov: 3881 ft: 3882 exec/s: 0 rss: 172Mb Step #5: ==130360== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56326dcbe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563274323898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5632743065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5632743064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56326dcc4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56326dc25b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56326dc20355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56326dcb6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563270c85f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563270c85f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563270c85f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563270c85f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563270c85f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563270c85f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563270c85f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563270c85f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563270c85f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563270c85f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563272f1af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56326fc47b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56326fc52be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56326f9fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56326f9fec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56326f9ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56326f9fe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56326f9fe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56326f9fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563274308abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563274311928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5632742f9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563274324112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f50b5ef0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56326dc1eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x2f,0x4c,0xce,0x9c,0xce,0x8c,0xce,0x8c,0xce,0x8c,0xce,0x8c,0xce,0x8c,0xce,0x8c,0xce,0x8c,0xc8,0x8c,0xce,0xb7,0xca,0x8c,0xce,0x8c,0xce,0x8c,0xce,0x8c,0xce,0x8c,0xc8,0x8c,0xce,0xb7,0xca,0x8c,0xce,0x8c,0xc5,0x9c,0xc8,0x8c,0xce,0x8c,0xce,0x8c,0xce,0x8c,0xcc,0x8c,0xce,0x8c,0xce,0x8c,0xc5,0x9c,0xce,0x8c,0xcc,0x8c,0xce,0x8e,0xce,0x8c, Step #5: </L\316\234\316\214\316\214\316\214\316\214\316\214\316\214\316\214\310\214\316\267\312\214\316\214\316\214\316\214\316\214\310\214\316\267\312\214\316\214\305\234\310\214\316\214\316\214\316\214\314\214\316\214\316\214\305\234\316\214\314\214\316\216\316\214 Step #5: artifact_prefix='./'; Test unit written to ./oom-2874daf81e4dfd289377cc503175d32448523ce6 Step #5: Base64: PC9MzpzOjM6MzozOjM6MzozOjMiMzrfKjM6MzozOjM6MyIzOt8qMzozFnMiMzozOjM6MzIzOjM6MxZzOjMyMzo7OjA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3620 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3507296997 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559d3a1b9810, 0x559d3a3a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559d3a3a3020,0x559d3c23b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2874daf81e4dfd289377cc503175d32448523ce6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4485 processed earlier; will process 6544 files now Step #5: ==130396== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559d30cae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559d37313898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559d372f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559d372f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559d30cb4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559d30c15b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559d30c10355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559d30ca6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559d33c75f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559d33c75f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559d33c75f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559d33c75f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559d33c75f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559d33c75f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559d33c75f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559d33c75f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559d33c75f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559d33c75f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559d35f0af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559d32c37b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559d32c42be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559d329eec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559d329eec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559d329ef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559d329ee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559d329ee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559d329ee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559d372f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559d37301928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559d372e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559d37314112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc2f5162082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559d30c0eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xd6,0x9e,0xd6,0x9e,0xcc,0x9e,0xcc,0x9e,0xd6,0x9e,0xcc,0x9e,0xcc,0x9e,0xd6,0x9e,0xcc,0x9e,0xcc,0x9e,0xd6,0x9d,0xcc,0x9e,0xcc,0x9e,0xd6,0x9e,0xcc,0x9e,0xd6,0x9e,0xd6,0x9e,0xd6,0x9e,0xd6,0x9e,0xcc,0x9e,0xd6,0x9e,0xcc,0x9e,0xd6,0x9e,0xcc,0x9e,0xd6,0x9e,0xd6,0x9e,0xd6,0x9e,0xd6,0x9e,0xd6,0x9e,0xcc,0x9e,0xd6,0x9e,0xcc,0x80, Step #5: ws:\326\236\326\236\314\236\314\236\326\236\314\236\314\236\326\236\314\236\314\236\326\235\314\236\314\236\326\236\314\236\326\236\326\236\326\236\326\236\314\236\326\236\314\236\326\236\314\236\326\236\326\236\326\236\326\236\326\236\314\236\326\236\314\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-40e1956ef945c72fdc67041ac832230f77e2260b Step #5: Base64: d3M61p7WnsyezJ7WnsyezJ7WnsyezJ7WncyezJ7Wnsye1p7Wntae1p7MntaezJ7Wnsye1p7Wntae1p7Wnsye1p7MgA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3621 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3507796019 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560144722810, 0x56014490c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56014490c020,0x5601467a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40e1956ef945c72fdc67041ac832230f77e2260b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4486 processed earlier; will process 6543 files now Step #5: ==130432== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56013b2179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56014187c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56014185f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56014185f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56013b21dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56013b17eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56013b179355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56013b20fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56013e1def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56013e1def10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56013e1def10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56013e1def10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56013e1def10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56013e1def10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56013e1def10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56013e1def10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56013e1def10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56013e1def10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560140473f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56013d1a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56013d1abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56013cf57c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56013cf57c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56013cf58738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56013cf57874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56013cf57874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56013cf57874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560141861abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56014186a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560141852699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56014187d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd738793082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56013b177b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0xa,0x3d,0xa,0x3d,0xa,0x3a,0x3a,0x3a,0x2e,0x2e,0x67,0x68,0x74,0x24,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x0,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x0,0x3a,0x60,0x3a,0x3d,0xa,0x3d,0x1,0x0,0xa,0x3d,0xb,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x1,0x24,0x5b, Step #5: I\012=\012=\012:::..ght$:::::::::\000:::::::::::::::::\000:`:=\012=\001\000\012=\013=\012=\012=\012=\012\000\000\001$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-440b0cd26e85d992305ef51dcfa1fece5ec0e1b0 Step #5: Base64: SQo9Cj0KOjo6Li5naHQkOjo6Ojo6Ojo6ADo6Ojo6Ojo6Ojo6Ojo6Ojo6ADpgOj0KPQEACj0LPQo9Cj0KPQoAAAEkWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3622 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3508305175 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c921776810, 0x55c92196001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c921960020,0x55c9237f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/440b0cd26e85d992305ef51dcfa1fece5ec0e1b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4487 processed earlier; will process 6542 files now Step #5: ==130468== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c91826b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c91e8d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c91e8b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c91e8b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c918271d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9181d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c9181cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c918263c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c91b232f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c91b232f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c91b232f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c91b232f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c91b232f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c91b232f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c91b232f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c91b232f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c91b232f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c91b232f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c91d4c7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c91a1f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c91a1ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c919fabc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c919fabc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c919fac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c919fab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c919fab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c919fab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c91e8b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c91e8be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c91e8a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c91e8d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8872b1c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c9181cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x42,0x3a,0x40,0xa,0x38,0x78,0x6e,0x2d,0x2d,0xd9,0x96,0x21,0xd9,0x96,0x21,0x2d,0x74,0x34,0x6f,0x72,0x70,0x7a,0x70,0x78,0x6f,0x62,0x75,0x66,0x65,0x65,0x78,0x30,0x53,0x7a,0x78,0x7a,0x30,0x78,0x30,0x2d,0x70,0x41,0x7a,0x69,0x44,0x7a,0x7a,0x44,0x53,0x7a,0x53,0x7a,0x53,0x74,0x72,0x69,0x6e,0x45,0x70,0x70,0x54,0x22,0x0,0x80,0x80,0x3,0x23, Step #5: \012B:@\0128xn--\331\226!\331\226!-t4orpzpxobufeex0Szxz0x0-pAziDzzDSzSzStrinEppT\"\000\200\200\003# Step #5: artifact_prefix='./'; Test unit written to ./oom-190033fc6b069d87d1cb3111b8ff7f5dec392750 Step #5: Base64: CkI6QAo4eG4tLdmWIdmWIS10NG9ycHpweG9idWZlZXgwU3p4ejB4MC1wQXppRHp6RFN6U3pTdHJpbkVwcFQiAICAAyM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3623 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3508802405 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561833ac2810, 0x561833cac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561833cac020,0x561835b440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/190033fc6b069d87d1cb3111b8ff7f5dec392750' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4488 processed earlier; will process 6541 files now Step #5: ==130504== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56182a5b79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561830c1c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561830bff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561830bff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56182a5bdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56182a51eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56182a519355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56182a5afc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56182d57ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56182d57ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56182d57ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56182d57ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56182d57ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56182d57ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56182d57ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56182d57ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56182d57ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56182d57ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56182f813f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56182c540b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56182c54bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56182c2f7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56182c2f7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56182c2f8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56182c2f7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56182c2f7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56182c2f7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561830c01abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561830c0a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561830bf2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561830c1d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f24a818c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56182a517b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29, Step #5: ^(?:$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$) Step #5: artifact_prefix='./'; Test unit written to ./oom-6ecbd2e1d6725518e700b6e9bccdb5d2e4aecfeb Step #5: Base64: Xig/OiR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkfCR8JCk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3624 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3509306440 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564a4a14a810, 0x564a4a33401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564a4a334020,0x564a4c1cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ecbd2e1d6725518e700b6e9bccdb5d2e4aecfeb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4489 processed earlier; will process 6540 files now Step #5: ==130540== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564a40c3f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564a472a4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564a472875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564a472874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564a40c45d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564a40ba6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564a40ba1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564a40c37c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564a43c06f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564a43c06f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564a43c06f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564a43c06f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564a43c06f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564a43c06f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564a43c06f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564a43c06f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564a43c06f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564a43c06f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564a45e9bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564a42bc8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564a42bd3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564a4297fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564a4297fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564a42980738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564a4297f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564a4297f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564a4297f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564a47289abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564a47292928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564a4727a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564a472a5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c61866082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564a40b9fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x5b,0x49,0x47,0x4e,0x4f,0x52,0x45,0x5b,0xda,0xa8,0x3a,0x5b,0xda,0xa8,0x3a,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5b,0x49,0x47,0x4e,0x4f,0x52,0x45,0x5b,0xda,0xa8,0x3a,0x5b,0x3a,0x5e,0x5e,0x5e,0x5e,0x5b,0xda,0xa8,0x3a,0x5b,0xda,0xa8,0x3a,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0xd,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x25, Step #5: <![IGNORE[\332\250:[\332\250:^^^^^^^^[IGNORE[\332\250:[:^^^^[\332\250:[\332\250:^^^^^^^^^\015^^^^^^^% Step #5: artifact_prefix='./'; Test unit written to ./oom-e9f7e181fc83ff6e307076b8d3076b3b69d1fc62 Step #5: Base64: PCFbSUdOT1JFW9qoOlvaqDpeXl5eXl5eXltJR05PUkVb2qg6WzpeXl5eW9qoOlvaqDpeXl5eXl5eXl4NXl5eXl5eXiU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3625 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3509802350 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d0ac07810, 0x563d0adf101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d0adf1020,0x563d0cc890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e9f7e181fc83ff6e307076b8d3076b3b69d1fc62' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4490 processed earlier; will process 6539 files now Step #5: ==130576== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563d016fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d07d61898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d07d445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d07d444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d01702d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d01663b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d0165e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d016f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d046c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d046c3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d046c3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d046c3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d046c3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d046c3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d046c3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d046c3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d046c3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d046c3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d06958f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d03685b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d03690be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d0343cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d0343cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d0343d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d0343c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d0343c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d0343c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d07d46abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d07d4f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d07d37699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d07d62112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe55fc7f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d0165cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x53,0x3a,0xcd,0x82,0xcd,0x8b,0xcd,0x86,0xcd,0x86,0xcd,0x94,0xcd,0x8b,0xcd,0x86,0xcd,0x9c,0xcd,0xaa,0xcd,0x8b,0xcd,0x94,0xcd,0x86,0xcd,0x8b,0xcd,0x86,0xcd,0x9c,0xcd,0x94,0xcd,0x86,0x63,0xcd,0x94,0xcd,0x9c,0xcd,0xaa,0xcd,0x8c,0xcd,0x94,0xcd,0x86,0xcd,0x8b,0xcd,0x86,0xcd,0x9c,0xcd,0x94,0xcd,0x86,0xcd,0x94,0xcd,0xaa,0xcd,0x9c,0xcd,0xaa, Step #5: wS:\315\202\315\213\315\206\315\206\315\224\315\213\315\206\315\234\315\252\315\213\315\224\315\206\315\213\315\206\315\234\315\224\315\206c\315\224\315\234\315\252\315\214\315\224\315\206\315\213\315\206\315\234\315\224\315\206\315\224\315\252\315\234\315\252 Step #5: artifact_prefix='./'; Test unit written to ./oom-347979ffd2824d68140c1d3f64d7a53eb17299a3 Step #5: Base64: d1M6zYLNi82GzYbNlM2LzYbNnM2qzYvNlM2GzYvNhs2czZTNhmPNlM2czarNjM2UzYbNi82GzZzNlM2GzZTNqs2czao= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3626 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3510299654 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5562ff32c810, 0x5562ff51601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5562ff516020,0x5563013ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/347979ffd2824d68140c1d3f64d7a53eb17299a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4491 processed earlier; will process 6538 files now Step #5: ==130612== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5562f5e219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5562fc486898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5562fc4695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5562fc4694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5562f5e27d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5562f5d88b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5562f5d83355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5562f5e19c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5562f8de8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5562f8de8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5562f8de8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5562f8de8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5562f8de8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5562f8de8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5562f8de8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5562f8de8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5562f8de8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5562f8de8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5562fb07df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5562f7daab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5562f7db5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5562f7b61c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5562f7b61c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5562f7b62738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5562f7b61874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5562f7b61874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5562f7b61874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5562fc46babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5562fc474928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5562fc45c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5562fc487112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd292510082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5562f5d81b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x5b,0x5e,0xdf,0xba,0x5d, Step #5: \023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023[^\337\272] Step #5: artifact_prefix='./'; Test unit written to ./oom-350e09756e31be48692f08e988675d4472a63a87 Step #5: Base64: ExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTW17ful0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3627 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3510792325 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cce7614810, 0x55cce77fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cce77fe020,0x55cce96960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/350e09756e31be48692f08e988675d4472a63a87' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4492 processed earlier; will process 6537 files now Step #5: ==130648== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ccde1099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cce476e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cce47515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cce47514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ccde10fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ccde070b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ccde06b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ccde101c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cce10d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cce10d0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cce10d0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cce10d0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cce10d0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cce10d0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cce10d0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cce10d0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cce10d0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cce10d0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cce3365f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cce0092b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cce009dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ccdfe49c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ccdfe49c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ccdfe4a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ccdfe49874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ccdfe49874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ccdfe49874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cce4753abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cce475c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cce4744699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cce476f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f48a4703082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ccde069b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x42,0x3a,0x40,0xa,0x3e,0x51,0x2e,0x78,0x6e,0x2d,0x2d,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x44,0x7,0x7a,0x7,0x7,0x4e,0x7,0x7,0x7,0x7,0x7,0xf3,0xa0,0x84,0xa3,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x44,0x7,0x7a,0x7,0x7,0x4e,0x7,0x7,0x7,0x7,0x7,0xf3,0xa0,0x84,0xa3,0x7,0x7,0xd,0xf3,0xa0,0x84,0xa3,0x7,0x7,0x3a, Step #5: \012B:@\012>Q.xn--\007\007\007\007\007\007\007\007\007D\007z\007\007N\007\007\007\007\007\363\240\204\243\007\007\007\007\007\007\007D\007z\007\007N\007\007\007\007\007\363\240\204\243\007\007\015\363\240\204\243\007\007: Step #5: artifact_prefix='./'; Test unit written to ./oom-ec2f9ea58b556ce0159eb1449d0f3a07f5d94563 Step #5: Base64: CkI6QAo+US54bi0tBwcHBwcHBwcHRAd6BwdOBwcHBwfzoISjBwcHBwcHB0QHegcHTgcHBwcH86CEowcHDfOghKMHBzo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3628 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3511283513 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d2b831e810, 0x55d2b850801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d2b8508020,0x55d2ba3a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec2f9ea58b556ce0159eb1449d0f3a07f5d94563' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4493 processed earlier; will process 6536 files now Step #5: #1 pulse cov: 13199 ft: 13200 exec/s: 0 rss: 197Mb Step #5: ==130684== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d2aee139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d2b5478898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d2b545b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d2b545b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d2aee19d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d2aed7ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d2aed75355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d2aee0bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d2b1ddaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d2b1ddaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d2b1ddaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d2b1ddaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d2b1ddaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d2b1ddaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d2b1ddaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d2b1ddaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d2b1ddaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d2b1ddaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d2b406ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d2b0d9cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d2b0da7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d2b0b53c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d2b0b53c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d2b0b54738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d2b0b53874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d2b0b53874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d2b0b53874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d2b545dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d2b5466928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d2b544e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d2b5479112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe15f5c1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d2aed73b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x28,0xff,0x50,0x4b,0x3,0x4,0xfe,0x7a,0x50,0x4b,0x1,0x2,0xcf,0x7e,0x50,0x4b,0x5,0x6,0x0,0x0,0x0,0x3b,0x2e,0x5,0x1,0x0,0x6,0x0,0x0,0x0,0x6,0x0,0x0,0x0,0x13,0x0,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x1,0x40,0x0,0x0,0x1,0x20,0x0,0x0,0x0,0x0,0x2e,0x5c,0x2c,0x2f,0x2e,0x2a,0x66,0x2f,0x26,0x2e,0x0,0x50, Step #5: \000\000(\377PK\003\004\376zPK\001\002\317~PK\005\006\000\000\000;.\005\001\000\006\000\000\000\006\000\000\000\023\000\012\000\000\000\000\000\000\001\001@\000\000\001 \000\000\000\000.\\,/.*f/&.\000P Step #5: artifact_prefix='./'; Test unit written to ./oom-a3a164d18d73606b196d15dd96afe522aa73c945 Step #5: Base64: AAAo/1BLAwT+elBLAQLPflBLBQYAAAA7LgUBAAYAAAAGAAAAEwAKAAAAAAAAAQFAAAABIAAAAAAuXCwvLipmLyYuAFA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3629 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3511855799 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560fcd108810, 0x560fcd2f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560fcd2f2020,0x560fcf18a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a3a164d18d73606b196d15dd96afe522aa73c945' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4495 processed earlier; will process 6534 files now Step #5: ==130720== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560fc3bfd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560fca262898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560fca2455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560fca2454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560fc3c03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560fc3b64b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560fc3b5f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560fc3bf5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560fc6bc4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560fc6bc4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560fc6bc4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560fc6bc4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560fc6bc4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560fc6bc4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560fc6bc4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560fc6bc4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560fc6bc4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560fc6bc4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560fc8e59f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560fc5b86b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560fc5b91be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560fc593dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560fc593dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560fc593e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560fc593d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560fc593d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560fc593d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560fca247abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560fca250928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560fca238699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560fca263112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb06f2fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560fc3b5db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x42,0x3a,0x40,0xa,0x38,0x78,0x6e,0x2d,0x2d,0xf3,0xa0,0x84,0x80,0xf0,0xa0,0x81,0x80,0xef,0xbf,0x90,0x46,0x2d,0xf3,0xa0,0x84,0x81,0x2a,0xf3,0xa0,0x84,0x87,0x2a,0x8,0xf3,0xa0,0x84,0x80,0xf0,0xa0,0x81,0x80,0xe7,0xbf,0xbf,0xe7,0x88,0x80,0x7f,0x46,0x2d,0xf3,0xa0,0x84,0x88,0x7f,0x46,0x2d,0xf3,0xa0,0x84,0x81,0x68,0x68,0x68,0x2,0x22,0x0, Step #5: \012B:@\0128xn--\363\240\204\200\360\240\201\200\357\277\220F-\363\240\204\201*\363\240\204\207*\010\363\240\204\200\360\240\201\200\347\277\277\347\210\200\177F-\363\240\204\210\177F-\363\240\204\201hhh\002\"\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-60404355b47a1fee913695ad0423bbbc756e2d24 Step #5: Base64: CkI6QAo4eG4tLfOghIDwoIGA77+QRi3zoISBKvOghIcqCPOghIDwoIGA57+/54iAf0Yt86CEiH9GLfOghIFoaGgCIgA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3630 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3512350484 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3c6b01810, 0x55a3c6ceb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3c6ceb020,0x55a3c8b830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/60404355b47a1fee913695ad0423bbbc756e2d24' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4496 processed earlier; will process 6533 files now Step #5: ==130756== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a3bd5f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3c3c5b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3c3c3e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3c3c3e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3bd5fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a3bd55db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a3bd558355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3bd5eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a3c05bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a3c05bdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a3c05bdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a3c05bdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a3c05bdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a3c05bdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a3c05bdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a3c05bdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a3c05bdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a3c05bdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3c2852f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3bf57fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3bf58abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3bf336c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3bf336c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3bf337738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3bf336874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3bf336874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3bf336874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a3c3c40abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a3c3c49928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3c3c31699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3c3c5c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf22493082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a3bd556b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x42,0x12,0x40,0xa,0x3c,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x67,0x6f,0x20,0xdb,0xb3,0xdb,0xb3,0xdb,0xb3,0x6c,0xdb,0xb3,0xdb,0xb3,0xb,0xdb,0xb3,0xdb,0xb3,0x6c,0xb,0xdb,0xb3,0xb,0xdb,0xb3,0x20,0xdb,0xb3,0xdb,0xb3,0xdb,0xb3,0x6c,0xdb,0xb3,0xdb,0xb3,0xb,0xdb,0xb3,0xdb,0xb3,0x6c,0xb,0xdb,0xb3,0x20,0x0,0x30,0x30,0x32,0x0, Step #5: \012B\022@\012<//+build\013go \333\263\333\263\333\263l\333\263\333\263\013\333\263\333\263l\013\333\263\013\333\263 \333\263\333\263\333\263l\333\263\333\263\013\333\263\333\263l\013\333\263 \000002\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4d9378a9ba9c878f22a42ac8bae71fc72e8049c9 Step #5: Base64: CkISQAo8Ly8rYnVpbGQLZ28g27Pbs9uzbNuz27ML27Pbs2wL27ML27Mg27Pbs9uzbNuz27ML27Pbs2wL27MgADAwMgA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3631 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3512849555 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ae6356810, 0x555ae654001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ae6540020,0x555ae83d80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4d9378a9ba9c878f22a42ac8bae71fc72e8049c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4497 processed earlier; will process 6532 files now Step #5: #1 pulse cov: 4046 ft: 4047 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4416 ft: 4693 exec/s: 0 rss: 176Mb Step #5: ==130792== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555adce4b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ae34b0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ae34935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ae34934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555adce51d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555adcdb2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555adcdad355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555adce43c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555adfe12f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555adfe12f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555adfe12f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555adfe12f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555adfe12f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555adfe12f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555adfe12f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555adfe12f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555adfe12f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555adfe12f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555ae20a7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555adedd4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555adeddfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555adeb8bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555adeb8bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555adeb8c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555adeb8b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555adeb8b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555adeb8b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ae3495abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ae349e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ae3486699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ae34b1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff21ae04082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555adcdabb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x2d,0x2d,0xf0,0x90,0x90,0xb0,0xf0,0x90,0x90,0xb0,0xf0,0x90,0x90,0xb0,0xf0,0x90,0x90,0xb0,0xf0,0x90,0x90,0xb0,0xf0,0x92,0x90,0xb0,0xf0,0x90,0xb0,0x90,0xf0,0x90,0x90,0xb0,0xf0,0x90,0x90,0xb0,0xf0,0x90,0x90,0xb0,0xf0,0x90,0x90,0xb0,0xf0,0x90,0x90,0xb0,0xf0,0x90,0x90,0xb0,0xf0,0x90,0x90,0xb0,0xf0,0x90,0x90,0xb0,0xf0,0x90,0x90,0xb0, Step #5: <!--\360\220\220\260\360\220\220\260\360\220\220\260\360\220\220\260\360\220\220\260\360\222\220\260\360\220\260\220\360\220\220\260\360\220\220\260\360\220\220\260\360\220\220\260\360\220\220\260\360\220\220\260\360\220\220\260\360\220\220\260\360\220\220\260 Step #5: artifact_prefix='./'; Test unit written to ./oom-57279d000d122d1a05803eb23a90abbde514551e Step #5: Base64: PCEtLfCQkLDwkJCw8JCQsPCQkLDwkJCw8JKQsPCQsJDwkJCw8JCQsPCQkLDwkJCw8JCQsPCQkLDwkJCw8JCQsPCQkLA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3632 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3513416506 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f356016810, 0x55f35620001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f356200020,0x55f3580980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/57279d000d122d1a05803eb23a90abbde514551e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4500 processed earlier; will process 6529 files now Step #5: ==130828== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f34cb0b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f353170898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f3531535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f3531534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f34cb11d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f34ca72b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f34ca6d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f34cb03c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f34fad2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f34fad2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f34fad2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f34fad2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f34fad2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f34fad2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f34fad2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f34fad2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f34fad2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f34fad2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f351d67f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f34ea94b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f34ea9fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f34e84bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f34e84bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f34e84c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f34e84b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f34e84b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f34e84b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f353155abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f35315e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f353146699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f353171112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f78e106a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f34ca6bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd8,0x85,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xf0,0x9f,0x80,0x89,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81,0xd8,0x81, Step #5: \330\205\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\360\237\200\211\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201\330\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-141b15dce1904017a0cde5c893a9a541a17d4cca Step #5: Base64: 2IXYgdiB2IHYgdiB2IHYgdiB2IHYgfCfgInYgdiB2IHYgdiB2IHYgdiB2IHYgdiB2IHYgdiB2IHYgdiB2IHYgdiB2IE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3633 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3513912681 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5637618b1810, 0x563761a9b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563761a9b020,0x5637639330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/141b15dce1904017a0cde5c893a9a541a17d4cca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4501 processed earlier; will process 6528 files now Step #5: ==130864== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5637583a69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56375ea0b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56375e9ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56375e9ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5637583acd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56375830db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563758308355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56375839ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56375b36df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56375b36df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56375b36df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56375b36df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56375b36df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56375b36df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56375b36df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56375b36df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56375b36df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56375b36df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56375d602f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56375a32fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56375a33abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56375a0e6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56375a0e6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56375a0e7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56375a0e6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56375a0e6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56375a0e6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56375e9f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56375e9f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56375e9e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56375ea0c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f51ec5b9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563758306b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x28,0x28,0x28,0x21,0x3c,0x28,0x2e,0x0,0x5e,0x4,0x2e,0x4,0x2b,0x24,0x24,0x5e,0x0,0x2e,0x1,0x7d,0x49,0x44,0x33,0x4,0x2d,0x0,0x7f,0x7f,0x7f,0x2b,0x7c,0x29,0x7b,0x32,0x7d,0x5,0x29,0x7b,0x7f,0x0,0x75,0x67,0x3,0xf,0x75,0x32,0x7d,0x5,0x7c,0x29,0x7b,0x34,0x7d,0x29,0x7b,0x35,0x7d,0x29,0x7b,0x33,0x67,0x3,0x7d,0xf,0xee,0xee,0xff, Step #5: ((((!<(.\000^\004.\004+$$^\000.\001}ID3\004-\000\177\177\177+|){2}\005){\177\000ug\003\017u2}\005|){4}){5}){3g\003}\017\356\356\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-68b094c7d490674528d2c18a5cc115e39a34e803 Step #5: Base64: KCgoKCE8KC4AXgQuBCskJF4ALgF9SUQzBC0Af39/K3wpezJ9BSl7fwB1ZwMPdTJ9BXwpezR9KXs1fSl7M2cDfQ/u7v8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3634 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3514405058 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55df5dfd8810, 0x55df5e1c201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55df5e1c2020,0x55df6005a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/68b094c7d490674528d2c18a5cc115e39a34e803' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4502 processed earlier; will process 6527 files now Step #5: ==130900== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55df54acd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55df5b132898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55df5b1155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55df5b1154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55df54ad3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55df54a34b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55df54a2f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55df54ac5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55df57a94f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55df57a94f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55df57a94f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55df57a94f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55df57a94f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55df57a94f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55df57a94f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55df57a94f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55df57a94f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55df57a94f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55df59d29f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55df56a56b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55df56a61be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55df5680dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55df5680dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55df5680e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55df5680d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55df5680d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55df5680d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55df5b117abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55df5b120928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55df5b108699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55df5b133112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2d880d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55df54a2db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x0,0x2d,0xe1,0xb7,0xbf,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e, Step #5: [\000-\341\267\277^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Step #5: artifact_prefix='./'; Test unit written to ./oom-857075f7a0ec462178747ecc566da45105db4e0d Step #5: Base64: WwAt4be/Xl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3635 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3514894380 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55797d863810, 0x55797da4d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55797da4d020,0x55797f8e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/857075f7a0ec462178747ecc566da45105db4e0d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4503 processed earlier; will process 6526 files now Step #5: ==130936== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5579743589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55797a9bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55797a9a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55797a9a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55797435ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5579742bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5579742ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557974350c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55797731ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55797731ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55797731ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55797731ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55797731ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55797731ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55797731ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55797731ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55797731ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55797731ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579795b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5579762e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5579762ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557976098c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557976098c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557976099738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557976098874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557976098874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557976098874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55797a9a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55797a9ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55797a993699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55797a9be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4c012d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5579742b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x41,0x22,0xd8,0xb3,0xdc,0xb3,0xdc,0xb3,0xdf,0xb3,0xde,0xb3,0xd8,0xb3,0xdc,0xb3,0xdf,0xb3,0xdf,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb1,0xd8,0xb3,0xdb,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb2,0xd6,0xb3,0xd8,0xb3,0xdc,0xb3,0xdf,0xb3,0xde,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb1,0xd8,0xb3,0xdb,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb1,0xd8,0xb3,0xdb,0xd8, Step #5: HUA\"\330\263\334\263\334\263\337\263\336\263\330\263\334\263\337\263\337\263\330\263\330\263\330\261\330\263\333\263\330\263\330\263\330\262\326\263\330\263\334\263\337\263\336\263\330\263\330\263\330\261\330\263\333\263\330\263\330\263\330\261\330\263\333\330 Step #5: artifact_prefix='./'; Test unit written to ./oom-17eeaa150f9cebeb995176eaf537febc17b710a0 Step #5: Base64: SFVBItiz3LPcs9+z3rPYs9yz37Pfs9iz2LPYsdiz27PYs9iz2LLWs9iz3LPfs96z2LPYs9ix2LPbs9iz2LPYsdiz29g= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3636 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3515390281 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb46451810, 0x55bb4663b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb4663b020,0x55bb484d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/17eeaa150f9cebeb995176eaf537febc17b710a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4504 processed earlier; will process 6525 files now Step #5: ==130972== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bb3cf469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb435ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb4358e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb4358e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb3cf4cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb3ceadb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb3cea8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb3cf3ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb3ff0df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb3ff0df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb3ff0df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb3ff0df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb3ff0df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb3ff0df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb3ff0df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb3ff0df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb3ff0df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb3ff0df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb421a2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb3eecfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb3eedabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb3ec86c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb3ec86c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb3ec87738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb3ec86874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb3ec86874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb3ec86874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb43590abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb43599928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb43581699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb435ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc2b208d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb3cea6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x42,0x12,0x40,0xa,0x3c,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x28,0x21,0x48,0x7a,0x62,0x20,0x62,0x0,0x0,0x20,0x60,0x20,0x17,0x20,0x20,0x20,0x20,0x21,0x20,0x20,0x21,0x17,0x1e,0x20,0x2a,0x20,0x7e,0x2f,0x20,0x1e,0x20,0x2a,0x20,0x7e,0x20,0x17,0x20,0x17,0x20,0x5f,0xdf,0xbc,0x20,0x21,0x60,0x17,0x20,0x20,0x2d,0x20,0x1e,0x30,0x0, Step #5: \012B\022@\012<//+build\013(!Hzb b\000\000 ` \027 ! !\027\036 * ~/ \036 * ~ \027 \027 _\337\274 !`\027 - \0360\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9eed3d6d51508e99c78c3a886e5f338fb569ba7a Step #5: Base64: CkISQAo8Ly8rYnVpbGQLKCFIemIgYgAAIGAgFyAgICAhICAhFx4gKiB+LyAeICogfiAXIBcgX9+8ICFgFyAgLSAeMAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3637 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3515999413 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5596a9fd9810, 0x5596aa1c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596aa1c3020,0x5596ac05b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9eed3d6d51508e99c78c3a886e5f338fb569ba7a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4505 processed earlier; will process 6524 files now Step #5: ==131008== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5596a0ace9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5596a7133898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5596a71165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5596a71164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5596a0ad4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5596a0a35b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5596a0a30355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5596a0ac6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5596a3a95f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5596a3a95f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5596a3a95f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5596a3a95f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5596a3a95f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5596a3a95f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5596a3a95f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5596a3a95f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5596a3a95f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5596a3a95f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596a5d2af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5596a2a57b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5596a2a62be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5596a280ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5596a280ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5596a280f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5596a280e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5596a280e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5596a280e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5596a7118abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5596a7121928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5596a7109699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5596a7134112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb5734d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5596a0a2eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x49,0x4d,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0x30,0x64,0x61,0xf,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x61,0x30,0x64,0x61,0xf,0x0,0x0,0x0,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0xa6,0xcd,0x9e, Step #5: ID3IM3\004\342\200\256\004\342\200\256a\342\200\256\004\342\200\256a0da\017sef=\012=+=\012=\012=\012=\012=\012a0da\017\000\000\0003\004\342\200\256\004\342\200\256a\342\200\256\246\315\236 Step #5: artifact_prefix='./'; Test unit written to ./oom-de135a2f1858e9ae037987cb532b2e342bc89815 Step #5: Base64: SUQzSU0zBOKArgTigK5h4oCuBOKArmEwZGEPc2VmPQo9Kz0KPQo9Cj0KPQphMGRhDwAAADME4oCuBOKArmHigK6mzZ4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3638 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3516498109 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5653a4ad3810, 0x5653a4cbd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5653a4cbd020,0x5653a6b550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de135a2f1858e9ae037987cb532b2e342bc89815' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4506 processed earlier; will process 6523 files now Step #5: #1 pulse cov: 3608 ft: 3609 exec/s: 0 rss: 173Mb Step #5: ==131044== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56539b5c89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5653a1c2d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5653a1c105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5653a1c104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56539b5ced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56539b52fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56539b52a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56539b5c0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56539e58ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56539e58ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56539e58ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56539e58ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56539e58ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56539e58ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56539e58ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56539e58ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56539e58ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56539e58ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5653a0824f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56539d551b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56539d55cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56539d308c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56539d308c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56539d309738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56539d308874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56539d308874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56539d308874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5653a1c12abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5653a1c1b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5653a1c03699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5653a1c2e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd97b0bf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56539b528b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x0,0x2d,0xe1,0xb7,0xbf,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0xa4,0xa1,0xa1,0xa1,0xa1,0xa1,0xa1,0xa1,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x60,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x3b,0x5e,0x5e,0x98,0x3f, Step #5: [\000-\341\267\277^^^^^^^^^\244\241\241\241\241\241\241\241^^^^^^^^^^^^^^^^^^^^^^^^^^^`^^^^^^^^^^^^;^^\230? Step #5: artifact_prefix='./'; Test unit written to ./oom-3067f32f92fc73313a48d352d2ac62d8889b5e9e Step #5: Base64: WwAt4be/Xl5eXl5eXl5epKGhoaGhoaFeXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5gXl5eXl5eXl5eXl5eO15emD8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3639 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3517029077 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559d1463a810, 0x559d1482401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559d14824020,0x559d166bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3067f32f92fc73313a48d352d2ac62d8889b5e9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4508 processed earlier; will process 6521 files now Step #5: ==131080== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559d0b12f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559d11794898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559d117775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559d117774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559d0b135d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559d0b096b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559d0b091355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559d0b127c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559d0e0f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559d0e0f6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559d0e0f6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559d0e0f6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559d0e0f6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559d0e0f6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559d0e0f6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559d0e0f6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559d0e0f6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559d0e0f6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559d1038bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559d0d0b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559d0d0c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559d0ce6fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559d0ce6fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559d0ce70738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559d0ce6f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559d0ce6f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559d0ce6f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559d11779abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559d11782928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559d1176a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559d11795112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc10feb2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559d0b08fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x0,0x0,0x43,0x0,0x24,0x0,0x0,0x0, Step #5: $\177]\177\000\000\0002\000\000\0002.23/\020./( 7 =\177\000\000\0002\000\000\000\000\000\177\177\177\177o\000\00023/\020./( 7 =\177\000\000\0002\000\000\000\000\000C\000$\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a6f00d7db706ff35459246686d8c9f24e89b5fda Step #5: Base64: JH9dfwAAADIAAAAyLjIzLxAuLyggNyA9fwAAADIAAAAAAH9/f39vAAAyMy8QLi8oIDcgPX8AAAAyAAAAAABDACQAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3640 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3517528623 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55de38e6c810, 0x55de3905601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55de39056020,0x55de3aeee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a6f00d7db706ff35459246686d8c9f24e89b5fda' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4509 processed earlier; will process 6520 files now Step #5: ==131116== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55de2f9619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55de35fc6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55de35fa95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55de35fa94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55de2f967d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55de2f8c8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55de2f8c3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55de2f959c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55de32928f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55de32928f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55de32928f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55de32928f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55de32928f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55de32928f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55de32928f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55de32928f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55de32928f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55de32928f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55de34bbdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55de318eab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55de318f5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55de316a1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55de316a1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55de316a2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55de316a1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55de316a1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55de316a1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55de35fababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55de35fb4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55de35f9c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55de35fc7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a9718f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55de2f8c1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x27,0x5c,0xd3,0xa3,0xcd,0x9c,0xdc,0x9c,0xd3,0xa3,0xd3,0xa3,0xcd,0x9c,0xdc,0x9c,0xd3,0xa3,0xd3,0xa3,0xcd,0x9c,0xdc,0x9c,0xd3,0xa3,0xd3,0xa3,0xd3,0xa3,0xd3,0xa3,0xcd,0x9c,0xcd,0x1,0x1,0x1,0x1,0x1,0x1,0x1,0x1,0x67,0x67,0x67,0x67,0x67,0x67,0xd3,0xa3,0x67,0x67,0x67,0x67,0x67,0x1,0x1,0x21,0x1,0x1,0x1,0x1,0x1,0x1,0xa3,0x27, Step #5: e'\\\323\243\315\234\334\234\323\243\323\243\315\234\334\234\323\243\323\243\315\234\334\234\323\243\323\243\323\243\323\243\315\234\315\001\001\001\001\001\001\001\001gggggg\323\243ggggg\001\001!\001\001\001\001\001\001\243' Step #5: artifact_prefix='./'; Test unit written to ./oom-0a16a1d48443a1ef667deda91f9e1fe8f661b03e Step #5: Base64: ZSdc06PNnNyc06PTo82c3JzTo9OjzZzcnNOj06PTo9OjzZzNAQEBAQEBAQFnZ2dnZ2fTo2dnZ2dnAQEhAQEBAQEBoyc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3641 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3518017085 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557a0f611810, 0x557a0f7fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557a0f7fb020,0x557a116930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a16a1d48443a1ef667deda91f9e1fe8f661b03e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4510 processed earlier; will process 6519 files now Step #5: ==131152== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557a061069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557a0c76b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557a0c74e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557a0c74e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557a0610cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557a0606db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557a06068355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557a060fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557a090cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557a090cdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557a090cdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557a090cdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557a090cdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557a090cdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557a090cdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557a090cdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557a090cdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557a090cdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557a0b362f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557a0808fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557a0809abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557a07e46c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557a07e46c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557a07e47738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557a07e46874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557a07e46874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557a07e46874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557a0c750abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557a0c759928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557a0c741699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557a0c76c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efcc42f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557a06066b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x2,0x0,0x1c,0x3f,0xf3,0xa0,0x80,0x81,0x58,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x40,0xe2,0x80,0xae,0x54,0x54,0x54,0x7e,0x43,0xb,0x4d,0x33,0x4d, Step #5: ID3\002\002\000\034?\363\240\200\201X\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000@\342\200\256TTT~C\013M3M Step #5: artifact_prefix='./'; Test unit written to ./oom-f9137dd4dbfa2b15ff4c6413f4aea6ccffa91317 Step #5: Base64: SUQzAgIAHD/zoICBWAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEDigK5UVFR+QwtNM00= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3642 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3518509212 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55964aa84810, 0x55964ac6e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55964ac6e020,0x55964cb060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9137dd4dbfa2b15ff4c6413f4aea6ccffa91317' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4511 processed earlier; will process 6518 files now Step #5: ==131188== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5596415799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559647bde898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559647bc15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559647bc14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55964157fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5596414e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5596414db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559641571c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559644540f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559644540f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559644540f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559644540f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559644540f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559644540f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559644540f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559644540f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559644540f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559644540f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596467d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559643502b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55964350dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5596432b9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5596432b9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5596432ba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5596432b9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5596432b9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5596432b9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559647bc3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559647bcc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559647bb4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559647bdf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff5947bd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5596414d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x45,0x2d,0xa,0x44,0xa,0x2d,0xa,0x49,0x74,0x68,0xa,0x2d,0xa,0x64,0x2d,0x2d,0x5b,0x2d,0x2d,0xa,0x44,0xa,0x2d,0xa,0x49,0x74,0x68,0xa,0x2d,0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x47,0x45,0x42,0x4b,0x4e,0x20,0x36,0x68,0x31,0xa,0x2d,0x3f,0xa,0x64,0xa,0x64,0xa,0x64,0xa,0x64,0xa,0x3f,0x42,0x4b,0x4e,0x20,0x36,0x68,0x31,0xa,0x2d,0x3f, Step #5: !E-\012D\012-\012Ith\012-\012d--[--\012D\012-\012Ith\012-s-----GEBKN 6h1\012-?\012d\012d\012d\012d\012?BKN 6h1\012-? Step #5: artifact_prefix='./'; Test unit written to ./oom-8f07fa74ac0fccbb7257043333e7060d3f8d56e1 Step #5: Base64: IUUtCkQKLQpJdGgKLQpkLS1bLS0KRAotCkl0aAotcy0tLS0tR0VCS04gNmgxCi0/CmQKZApkCmQKP0JLTiA2aDEKLT8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3643 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3519015040 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0b7225810, 0x55a0b740f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0b740f020,0x55a0b92a70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8f07fa74ac0fccbb7257043333e7060d3f8d56e1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4512 processed earlier; will process 6517 files now Step #5: ==131224== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0add1a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0b437f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0b43625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0b43624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0add20d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0adc81b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0adc7c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0add12c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0b0ce1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0b0ce1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0b0ce1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0b0ce1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0b0ce1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0b0ce1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0b0ce1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0b0ce1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0b0ce1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0b0ce1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0b2f76f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0afca3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0afcaebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0afa5ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0afa5ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0afa5b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0afa5a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0afa5a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0afa5a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0b4364abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0b436d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0b4355699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0b4380112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd9ad313082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0adc7ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x2d,0x20,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x20,0x2d,0x20,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x20,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x20,0x2d,0x20,0x2d,0x20,0x20,0x2d,0x20,0x3f, Step #5: - - - - - - - - - - - - - - - - - - - - - - - - - - - - ? Step #5: artifact_prefix='./'; Test unit written to ./oom-087560a076e464d0e3acb28ee534b590a914ff38 Step #5: Base64: IC0gIC0gLSAtIC0gLSAtICAtIC0gLSAgLSAtIC0gIC0gIC0gLSAtIC0gIC0gLSAtICAgLSAtIC0gLSAgLSAtICAtID8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3644 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3519573211 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5619a2259810, 0x5619a244301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5619a2443020,0x5619a42db0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/087560a076e464d0e3acb28ee534b590a914ff38' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4513 processed earlier; will process 6516 files now Step #5: #1 pulse cov: 3747 ft: 3748 exec/s: 0 rss: 175Mb Step #5: ==131260== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561998d4e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56199f3b3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56199f3965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56199f3964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561998d54d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561998cb5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561998cb0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561998d46c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56199bd15f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56199bd15f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56199bd15f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56199bd15f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56199bd15f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56199bd15f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56199bd15f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56199bd15f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56199bd15f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56199bd15f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56199dfaaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56199acd7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56199ace2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56199aa8ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56199aa8ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56199aa8f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56199aa8e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56199aa8e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56199aa8e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56199f398abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56199f3a1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56199f389699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56199f3b4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb8b5f41082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561998caeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x41,0x22,0xd8,0xb3,0xdc,0xb3,0xdc,0xb3,0xdf,0xb3,0xde,0xb3,0xd8,0xb3,0xdc,0xb3,0xdf,0xb3,0xdf,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb1,0xd8,0xb3,0xdb,0x54,0x54,0x54,0xd8,0xb3,0xd8,0xb2,0xd6,0xb3,0xd8,0xb3,0xdc,0xb3,0xdf,0xb3,0xde,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb1,0xd8,0xb3,0xdb,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb1,0xd8,0xb3,0xdb,0xd8, Step #5: HUA\"\330\263\334\263\334\263\337\263\336\263\330\263\334\263\337\263\337\263\330\263\330\263\330\261\330\263\333TTT\330\263\330\262\326\263\330\263\334\263\337\263\336\263\330\263\330\263\330\261\330\263\333\263\330\263\330\263\330\261\330\263\333\330 Step #5: artifact_prefix='./'; Test unit written to ./oom-97753c390ad468696451348a7b3657189595b0da Step #5: Base64: SFVBItiz3LPcs9+z3rPYs9yz37Pfs9iz2LPYsdiz21RUVNiz2LLWs9iz3LPfs96z2LPYs9ix2LPbs9iz2LPYsdiz29g= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3645 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3520119714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d2955c810, 0x562d2974601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d29746020,0x562d2b5de0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/97753c390ad468696451348a7b3657189595b0da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4515 processed earlier; will process 6514 files now Step #5: ==131296== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562d200519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d266b6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d266995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d266994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d20057d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d1ffb8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d1ffb3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d20049c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d23018f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d23018f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d23018f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d23018f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d23018f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d23018f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d23018f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d23018f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d23018f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d23018f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d252adf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d21fdab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d21fe5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d21d91c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d21d91c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d21d92738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d21d91874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d21d91874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d21d91874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d2669babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d266a4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d2668c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d266b7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f38ed900082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d1ffb1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x60,0x20,0x53,0x74,0x79,0x6c,0x65,0x3d,0x31,0x2d,0x5c,0x3c,0x60,0x20,0x53,0x74,0x79,0x6c,0x65,0x3d,0x31,0x2d,0x5c,0x3c,0x60,0x20,0x53,0x74,0x79,0x6c,0x65,0x3d,0x31,0x2d,0x5c,0x3c,0x60,0x20,0x53,0x74,0x79,0x6c,0x65,0x3c,0x60,0x20,0x53,0x74,0x79,0x6c,0x65,0x3d,0x31,0x2d,0x5c,0x3c,0x60,0x20,0x53,0x74,0x79,0x6c,0x65,0x3d,0x31,0x2d,0x5c,0x3c, Step #5: <` Style=1-\\<` Style=1-\\<` Style=1-\\<` Style<` Style=1-\\<` Style=1-\\< Step #5: artifact_prefix='./'; Test unit written to ./oom-c18bae4608633bbd662ca328eb1fd81e3eaea059 Step #5: Base64: PGAgU3R5bGU9MS1cPGAgU3R5bGU9MS1cPGAgU3R5bGU9MS1cPGAgU3R5bGU8YCBTdHlsZT0xLVw8YCBTdHlsZT0xLVw8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3646 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3520744167 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564fbb298810, 0x564fbb48201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564fbb482020,0x564fbd31a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c18bae4608633bbd662ca328eb1fd81e3eaea059' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4516 processed earlier; will process 6513 files now Step #5: #1 pulse cov: 6757 ft: 6758 exec/s: 0 rss: 190Mb Step #5: ==131332== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564fb1d8d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564fb83f2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564fb83d55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564fb83d54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564fb1d93d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564fb1cf4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564fb1cef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564fb1d85c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564fb4d54f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564fb4d54f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564fb4d54f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564fb4d54f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564fb4d54f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564fb4d54f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564fb4d54f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564fb4d54f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564fb4d54f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564fb4d54f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564fb6fe9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564fb3d16b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564fb3d21be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564fb3acdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564fb3acdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564fb3ace738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564fb3acd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564fb3acd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564fb3acd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564fb83d7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564fb83e0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564fb83c8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564fb83f3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f97cfda8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564fb1cedb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0xa,0x3d,0xa,0x3d,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa, Step #5: \005-----\012-\012-\012-\012-\012\012\012=\012=\006\006\006\006\006\006\006\006\006\006\012-\012-\012-\012-\012\012\012=\012=\012=\012=\012=\012=\012=\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf6fdd0590e2b66c508b27e5df584b28bc9920ec Step #5: Base64: BS0tLS0tCi0KLQotCi0KCgo9Cj0GBgYGBgYGBgYGCi0KLQotCi0KCgo9Cj0KPQo9Cj0KPQo9CgoKCgoKCgoKCgoKCgoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3647 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3521300912 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564e3365f810, 0x564e3384901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564e33849020,0x564e356e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf6fdd0590e2b66c508b27e5df584b28bc9920ec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4518 processed earlier; will process 6511 files now Step #5: #1 pulse cov: 3550 ft: 3551 exec/s: 0 rss: 175Mb Step #5: ==131368== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564e2a1549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564e307b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564e3079c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564e3079c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564e2a15ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564e2a0bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564e2a0b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564e2a14cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564e2d11bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564e2d11bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564e2d11bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564e2d11bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564e2d11bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564e2d11bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564e2d11bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564e2d11bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564e2d11bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564e2d11bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564e2f3b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564e2c0ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564e2c0e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564e2be94c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564e2be94c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564e2be95738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564e2be94874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564e2be94874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564e2be94874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564e3079eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564e307a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564e3078f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564e307ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf28a35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564e2a0b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x5b,0x30,0xa,0x30,0x2e,0xb,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x5b,0x30,0xa,0x30,0x2e,0xb,0xa,0x30,0x2e,0xb,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x5b,0xa,0x6c,0x0,0xa,0x30,0x30,0x2e,0xb,0xa,0x31,0x2e,0xb,0xa,0x30,0x2e,0xb,0xa,0x30,0x2e,0xb,0x2e,0xa,0x30,0x2e,0xb,0xa,0x30,0x2e,0xb, Step #5: trailer[0\0120.\013\012trailer[0\0120.\013\0120.\013\012trailer[\012l\000\01200.\013\0121.\013\0120.\013\0120.\013.\0120.\013\0120.\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-d12c2e74af0dfe53923624c15bac19bb34a7cf0e Step #5: Base64: dHJhaWxlclswCjAuCwp0cmFpbGVyWzAKMC4LCjAuCwp0cmFpbGVyWwpsAAowMC4LCjEuCwowLgsKMC4LLgowLgsKMC4L Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3648 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3521859544 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d3b224d810, 0x55d3b243701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d3b2437020,0x55d3b42cf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d12c2e74af0dfe53923624c15bac19bb34a7cf0e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4520 processed earlier; will process 6509 files now Step #5: ==131404== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d3a8d429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d3af3a7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d3af38a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d3af38a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d3a8d48d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d3a8ca9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d3a8ca4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d3a8d3ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d3abd09f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d3abd09f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d3abd09f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d3abd09f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d3abd09f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d3abd09f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d3abd09f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d3abd09f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d3abd09f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d3abd09f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d3adf9ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d3aaccbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d3aacd6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d3aaa82c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d3aaa82c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d3aaa83738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d3aaa82874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d3aaa82874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d3aaa82874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d3af38cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d3af395928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d3af37d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d3af3a8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd212df9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d3a8ca2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x1,0x0,0x0,0x0,0x3,0x3a,0x54,0x43,0x4f,0x0,0x0,0x2,0x3,0x31,0x54,0x0,0x32,0x3,0x4f,0x54,0x43,0x2,0x0,0x43,0x4f,0x0,0x0,0x2,0x10,0x2,0x3,0x31,0x54,0x3b,0xef,0xbb,0xae,0xd,0x39,0x39,0x0,0x32,0x3,0x4f,0x43,0x2,0x0,0x43,0x4f,0x0,0x0,0x2,0x3,0x31,0x3,0x31,0x54,0x43,0x4f,0x0,0x0,0x2,0x3,0x31,0x3a, Step #5: ID3\002\001\000\000\000\003:TCO\000\000\002\0031T\0002\003OTC\002\000CO\000\000\002\020\002\0031T;\357\273\256\01599\0002\003OC\002\000CO\000\000\002\0031\0031TCO\000\000\002\0031: Step #5: artifact_prefix='./'; Test unit written to ./oom-d9b78e8b20117bba93df93dda65bf46e59ecc38a Step #5: Base64: SUQzAgEAAAADOlRDTwAAAgMxVAAyA09UQwIAQ08AAAIQAgMxVDvvu64NOTkAMgNPQwIAQ08AAAIDMQMxVENPAAACAzE6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3649 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3522359827 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d8dc5f810, 0x564d8de4901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d8de49020,0x564d8fce10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d9b78e8b20117bba93df93dda65bf46e59ecc38a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4521 processed earlier; will process 6508 files now Step #5: ==131440== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d847549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d8adb9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d8ad9c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d8ad9c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d8475ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d846bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d846b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d8474cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d8771bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d8771bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d8771bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d8771bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d8771bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d8771bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d8771bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d8771bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d8771bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d8771bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d899b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d866ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d866e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d86494c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d86494c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d86495738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d86494874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d86494874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d86494874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d8ad9eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d8ada7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d8ad8f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d8adba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff30029b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d846b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x20,0x6d,0x20,0x74,0x33,0x35,0x46,0x65,0x34,0x30,0x61,0x73,0x74,0x57,0x30,0x56,0x44,0x31,0x72,0x79,0x31,0x36,0x72,0x31,0x32,0x37,0x7a,0x31,0x64,0x6f,0xd,0x37,0x38,0x36,0x32,0x2d,0x31,0x2d,0x32,0x20,0x31,0x3a,0x33,0x3a,0x32,0x20,0x32,0x2e,0x33,0x2e,0x30,0x2e,0x30,0xd,0x32,0x20,0x31,0xa,0x70,0x72,0xa,0x73,0x23,0x68,0x20,0x4c,0xd,0x34, Step #5: r m t35Fe40astW0VD1ry16r127z1do\0157862-1-2 1:3:2 2.3.0.0\0152 1\012pr\012s#h L\0154 Step #5: artifact_prefix='./'; Test unit written to ./oom-8f9797fb9bd9d6b128112a6951237ebce1a2da47 Step #5: Base64: ciBtIHQzNUZlNDBhc3RXMFZEMXJ5MTZyMTI3ejFkbw03ODYyLTEtMiAxOjM6MiAyLjMuMC4wDTIgMQpwcgpzI2ggTA00 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3650 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3522863472 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55614fb0c810, 0x55614fcf601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55614fcf6020,0x556151b8e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8f9797fb9bd9d6b128112a6951237ebce1a2da47' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4522 processed earlier; will process 6507 files now Step #5: ==131476== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5561466019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55614cc66898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55614cc495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55614cc494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556146607d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556146568b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556146563355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5561465f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5561495c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5561495c8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5561495c8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5561495c8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5561495c8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5561495c8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5561495c8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5561495c8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5561495c8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5561495c8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55614b85df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55614858ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556148595be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556148341c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556148341c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556148342738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556148341874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556148341874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556148341874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55614cc4babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55614cc54928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55614cc3c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55614cc67112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f983fc70082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556146561b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0x46,0x7e,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x20,0x22, Step #5: CF~<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< \" Step #5: artifact_prefix='./'; Test unit written to ./oom-5da08b3a094e1a36537d44781c63c763e537c397 Step #5: Base64: Q0Z+PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PCAi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3651 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3523370342 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c1f3773810, 0x55c1f395d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c1f395d020,0x55c1f57f50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5da08b3a094e1a36537d44781c63c763e537c397' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4523 processed earlier; will process 6506 files now Step #5: ==131512== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c1ea2689c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c1f08cd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c1f08b05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c1f08b04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c1ea26ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c1ea1cfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c1ea1ca355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c1ea260c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c1ed22ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c1ed22ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c1ed22ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c1ed22ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c1ed22ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c1ed22ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c1ed22ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c1ed22ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c1ed22ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c1ed22ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c1ef4c4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c1ec1f1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c1ec1fcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c1ebfa8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c1ebfa8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c1ebfa9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c1ebfa8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c1ebfa8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c1ebfa8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c1f08b2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c1f08bb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c1f08a3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c1f08ce112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f635cd8a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c1ea1c8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x67,0x6c,0x79,0x66,0x66,0xe0,0xb9,0x81,0x67,0x2c,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x67,0x7f,0x66,0x3b,0x67,0x66,0x66,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x67,0x7f,0x66,0x3b,0x67,0x66,0x66,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x73,0x74,0x72,0x65,0x61,0x6d,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x6e, Step #5: tglyff\340\271\201g,fg\177f;g?tglyg\177f;gfff?f;g?tglyg\177f;gfff?f;g?tstreamglyf?g?g?n Step #5: artifact_prefix='./'; Test unit written to ./oom-11ae23c4ad4f6a19c4852faec7be85dbb412567b Step #5: Base64: dGdseWZm4LmBZyxmZ39mO2c/dGdseWd/ZjtnZmZmP2Y7Zz90Z2x5Z39mO2dmZmY/ZjtnP3RzdHJlYW1nbHlmP2c/Zz9u Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3652 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3523875022 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55784be06810, 0x55784bff001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55784bff0020,0x55784de880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/11ae23c4ad4f6a19c4852faec7be85dbb412567b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4524 processed earlier; will process 6505 files now Step #5: #1 pulse cov: 11288 ft: 11289 exec/s: 0 rss: 191Mb Step #5: ==131548== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5578428fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557848f60898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557848f435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557848f434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557842901d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557842862b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55784285d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5578428f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5578458c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5578458c2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5578458c2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5578458c2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5578458c2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5578458c2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5578458c2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5578458c2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5578458c2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5578458c2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557847b57f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557844884b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55784488fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55784463bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55784463bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55784463c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55784463b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55784463b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55784463b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557848f45abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557848f4e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557848f36699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557848f61112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3575c74082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55784285bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x46,0x76,0x30,0x4d,0x77,0x48,0x65,0x57,0x53,0x63,0x30,0x41,0x61,0x71,0x59,0x31,0x2b,0x6a,0x6d,0x47,0x4c,0x6c,0x43,0x41,0x41,0x42,0x73,0x54,0x2b,0x4c,0x53,0x58,0x45,0x53,0x79,0x56,0x77,0x36,0x32,0x3d,0x35,0x35,0x30,0x36, Step #5: onion-key\012ntor-onion-key Fv0MwHeWSc0AaqY1+jmGLlCAABsT+LSXESyVw62=5506 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec7bc6e56183a307489345678a9214fdc39d4e80 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IEZ2ME13SGVXU2MwQWFxWTEram1HTGxDQUFCc1QrTFNYRVN5Vnc2Mj01NTA2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3653 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3524442997 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e410ca5810, 0x55e410e8f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e410e8f020,0x55e412d270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec7bc6e56183a307489345678a9214fdc39d4e80' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4526 processed earlier; will process 6503 files now Step #5: ==131584== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e40779a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e40ddff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e40dde25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e40dde24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4077a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e407701b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4076fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e407792c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e40a761f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e40a761f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e40a761f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e40a761f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e40a761f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e40a761f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e40a761f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e40a761f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e40a761f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e40a761f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e40c9f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e409723b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e40972ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4094dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4094dac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4094db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4094da874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4094da874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4094da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e40dde4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e40dded928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e40ddd5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e40de00112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f480efd3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4076fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x11,0x23,0x22,0x7d,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x22, Step #5: \021#\"}\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\" Step #5: artifact_prefix='./'; Test unit written to ./oom-8db232270e1ab06c195ad65506146ad9aec5c6cb Step #5: Base64: ESMifVxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFAi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3654 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3524942050 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f64303810, 0x556f644ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f644ed020,0x556f663850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8db232270e1ab06c195ad65506146ad9aec5c6cb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4527 processed earlier; will process 6502 files now Step #5: ==131620== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556f5adf89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f6145d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f614405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f614404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f5adfed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f5ad5fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f5ad5a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f5adf0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f5ddbff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f5ddbff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f5ddbff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f5ddbff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f5ddbff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f5ddbff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f5ddbff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f5ddbff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f5ddbff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f5ddbff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f60054f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f5cd81b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f5cd8cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f5cb38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f5cb38c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f5cb39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f5cb38874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f5cb38874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f5cb38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f61442abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f6144b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f61433699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f6145e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2acb5ac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f5ad58b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xcd,0x88,0xd6,0xb7,0xcd,0x88,0xd6,0xb7,0xd6,0xb7,0xcd,0x88,0xd6,0xb7,0xcd,0x88,0xd6,0xb7,0xcd,0x88,0xd6,0xb7,0xd6,0xb7,0xd6,0xb5,0xcd,0x88,0xd6,0xb7,0xd6,0xb5,0xd6,0xb5,0xcd,0x88,0xd6,0xb7,0xd6,0xb5,0xcd,0x88,0xd6,0xb7,0xcd,0x88,0xd6,0xb7,0xd6,0xb7,0xd6,0xb5,0xcd,0x88,0xd6,0xb7,0xd6,0xb5,0xd6,0xb5,0xcd,0x88,0xd6,0xb7,0xd6,0xb5, Step #5: ws:\315\210\326\267\315\210\326\267\326\267\315\210\326\267\315\210\326\267\315\210\326\267\326\267\326\265\315\210\326\267\326\265\326\265\315\210\326\267\326\265\315\210\326\267\315\210\326\267\326\267\326\265\315\210\326\267\326\265\326\265\315\210\326\267\326\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-d80fbbf7d0d3ca030247674c17d88003b6899701 Step #5: Base64: d3M6zYjWt82I1rfWt82I1rfNiNa3zYjWt9a31rXNiNa31rXWtc2I1rfWtc2I1rfNiNa31rfWtc2I1rfWtda1zYjWt9a1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3655 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3525446360 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee6b9a7810, 0x55ee6bb9101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee6bb91020,0x55ee6da290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d80fbbf7d0d3ca030247674c17d88003b6899701' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4528 processed earlier; will process 6501 files now Step #5: ==131656== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ee6249c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee68b01898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee68ae45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee68ae44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee624a2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee62403b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee623fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee62494c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee65463f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee65463f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee65463f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee65463f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee65463f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee65463f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee65463f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee65463f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee65463f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee65463f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee676f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee64425b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee64430be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee641dcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee641dcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee641dd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee641dc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee641dc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee641dc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee68ae6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee68aef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee68ad7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee68b02112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f58862a3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee623fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd7,0x89,0x0,0x0,0x0,0x0,0x0,0x0,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0xd9,0xda,0x73,0x2d,0x2d,0x2d,0x1,0x0,0x27,0xf,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x25,0x25,0x25,0x25,0x2d,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0xa5,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x2d,0x39, Step #5: \327\211\000\000\000\000\000\000%%%%%%%%%%%\331\332s---\001\000'\017--BEGIN ----%%%%-%%%%%%%\245%%%%%%%%%%%%%-9 Step #5: artifact_prefix='./'; Test unit written to ./oom-23990269bc5c497c870cdbe1542cd3c3a1a31272 Step #5: Base64: 14kAAAAAAAAlJSUlJSUlJSUlJdnacy0tLQEAJw8tLUJFR0lOIC0tLS0lJSUlLSUlJSUlJSWlJSUlJSUlJSUlJSUlJS05 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3656 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3525941464 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5636bb0cc810, 0x5636bb2b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5636bb2b6020,0x5636bd14e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/23990269bc5c497c870cdbe1542cd3c3a1a31272' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4529 processed earlier; will process 6500 files now Step #5: #1 pulse cov: 10541 ft: 10542 exec/s: 0 rss: 195Mb Step #5: ==131692== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5636b1bc19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5636b8226898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636b82095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636b82094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5636b1bc7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5636b1b28b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5636b1b23355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5636b1bb9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5636b4b88f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5636b4b88f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5636b4b88f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5636b4b88f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5636b4b88f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5636b4b88f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5636b4b88f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5636b4b88f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5636b4b88f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5636b4b88f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5636b6e1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5636b3b4ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5636b3b55be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5636b3901c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5636b3901c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5636b3902738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5636b3901874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5636b3901874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5636b3901874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5636b820babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5636b8214928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5636b81fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5636b8227112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f587670e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5636b1b21b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d, Step #5: -----\012---\012---\012---\012---\012---\012---\012---\012---\012---\012---\012---\012---\012---\012---\012---\012--- Step #5: artifact_prefix='./'; Test unit written to ./oom-4c809a02b96d01f216dd6d34a0e7610d023f7a90 Step #5: Base64: LS0tLS0KLS0tCi0tLQotLS0KLS0tCi0tLQotLS0KLS0tCi0tLQotLS0KLS0tCi0tLQotLS0KLS0tCi0tLQotLS0KLS0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3657 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3526567385 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5651abece810, 0x5651ac0b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5651ac0b8020,0x5651adf500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4c809a02b96d01f216dd6d34a0e7610d023f7a90' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4531 processed earlier; will process 6498 files now Step #5: ==131728== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5651a29c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5651a9028898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651a900b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651a900b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5651a29c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5651a292ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5651a2925355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5651a29bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5651a598af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5651a598af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5651a598af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5651a598af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5651a598af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5651a598af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5651a598af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5651a598af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5651a598af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5651a598af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5651a7c1ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5651a494cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5651a4957be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5651a4703c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5651a4703c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5651a4704738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5651a4703874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5651a4703874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5651a4703874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5651a900dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5651a9016928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5651a8ffe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5651a9029112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f647c77b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5651a2923b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0xcd,0x9c,0xcd,0x9c,0xcd,0x84,0xcd,0x81,0xcd,0x9c,0xcd,0x9c,0xcd,0x9c,0xcd,0x9d,0xcd,0x9d,0xcd,0x9c,0xcd,0x9c,0xcd,0x84,0xcd,0x9c,0xcd,0x9c,0xcd,0x9c,0xcd,0x9d,0xcd,0x9d,0xcd,0x9c,0xcd,0x9c,0xcd,0x84,0xcd,0x81,0xcd,0x9d,0xcd,0x9c,0xcd,0x9c,0xcd,0x84,0xcd,0x9c,0xcd,0x9c,0xcd,0x9c,0xcd,0x9d,0xcd,0x9d,0xcd,0x9c,0xcd,0x9c,0xcd,0x84,0xcd,0x81, Step #5: x\315\234\315\234\315\204\315\201\315\234\315\234\315\234\315\235\315\235\315\234\315\234\315\204\315\234\315\234\315\234\315\235\315\235\315\234\315\234\315\204\315\201\315\235\315\234\315\234\315\204\315\234\315\234\315\234\315\235\315\235\315\234\315\234\315\204\315\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-8d171d2bf2c5d38b8851816594ab4cdc24acbf49 Step #5: Base64: eM2czZzNhM2BzZzNnM2czZ3Nnc2czZzNhM2czZzNnM2dzZ3NnM2czYTNgc2dzZzNnM2EzZzNnM2czZ3Nnc2czZzNhM2B Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3658 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3527069230 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d60cb41810, 0x55d60cd2b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d60cd2b020,0x55d60ebc30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d171d2bf2c5d38b8851816594ab4cdc24acbf49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4532 processed earlier; will process 6497 files now Step #5: ==131764== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d6036369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d609c9b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d609c7e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d609c7e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d60363cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d60359db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d603598355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d60362ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d6065fdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d6065fdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d6065fdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d6065fdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d6065fdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d6065fdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d6065fdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d6065fdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d6065fdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d6065fdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d608892f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d6055bfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d6055cabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d605376c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d605376c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d605377738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d605376874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d605376874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d605376874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d609c80abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d609c89928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d609c71699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d609c9c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe4a999d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d603596b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x0,0x6e,0x0,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x44,0x0,0x6e,0x20,0x4d,0x12,0x8b,0x61,0x7a,0x0,0x43, Step #5: D\000n\000CCCCCCCCCCCCCCCCCC\000\000\000\000\000\000\000\000\000\000\000CCCCCCCCCCCCCCCCCCCCCCCCCD\000n M\022\213az\000C Step #5: artifact_prefix='./'; Test unit written to ./oom-16a80fdb28b7abd73126168094519e484d530cbe Step #5: Base64: RABuAENDQ0NDQ0NDQ0NDQ0NDQ0NDQwAAAAAAAAAAAAAAQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0QAbiBNEothegBD Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3659 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3527578988 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ebb31f0810, 0x55ebb33da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ebb33da020,0x55ebb52720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16a80fdb28b7abd73126168094519e484d530cbe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4533 processed earlier; will process 6496 files now Step #5: ==131800== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eba9ce59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ebb034a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ebb032d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ebb032d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eba9cebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eba9c4cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eba9c47355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eba9cddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ebaccacf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ebaccacf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ebaccacf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ebaccacf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ebaccacf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ebaccacf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ebaccacf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ebaccacf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ebaccacf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ebaccacf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ebaef41f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ebabc6eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ebabc79be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ebaba25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ebaba25c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ebaba26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ebaba25874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ebaba25874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ebaba25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ebb032fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ebb0338928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ebb0320699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ebb034b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4e0838a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eba9c45b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x72,0x65,0x65,0x13,0x6a,0x74,0x72,0x65,0x65,0x13,0x6a,0x60,0x65,0x27,0x72,0x65,0x65,0x27,0x27,0x41,0x27,0x51,0x27,0x72,0x4b,0x27,0xb,0x27,0x27,0x41,0x27,0x51,0x27,0x1d,0x49,0x27,0xb,0x27,0x3b,0x60,0x65,0x27,0x72,0x65,0x65,0x27,0x27,0x41,0x27,0x51,0x27,0x72,0x4b,0x27,0xb,0x27,0x27,0x41,0x27,0x51,0x27,0x1d,0x49,0x27,0xb,0x27,0x3b,0x7a, Step #5: tree\023jtree\023j`e'ree''A'Q'rK'\013''A'Q'\035I'\013';`e'ree''A'Q'rK'\013''A'Q'\035I'\013';z Step #5: artifact_prefix='./'; Test unit written to ./oom-39b08ebdad0fb1779a1d01e898b444b7d62a3f62 Step #5: Base64: dHJlZRNqdHJlZRNqYGUncmVlJydBJ1EncksnCycnQSdRJx1JJwsnO2BlJ3JlZScnQSdRJ3JLJwsnJ0EnUScdSScLJzt6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3660 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3528209208 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5629d648b810, 0x5629d667501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5629d6675020,0x5629d850d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/39b08ebdad0fb1779a1d01e898b444b7d62a3f62' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4534 processed earlier; will process 6495 files now Step #5: ==131836== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5629ccf809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5629d35e5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5629d35c85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5629d35c84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5629ccf86d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629ccee7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629ccee2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5629ccf78c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5629cff47f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5629cff47f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5629cff47f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5629cff47f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5629cff47f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5629cff47f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5629cff47f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5629cff47f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5629cff47f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5629cff47f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5629d21dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629cef09b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629cef14be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629cecc0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629cecc0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629cecc1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629cecc0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629cecc0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629cecc0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5629d35caabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5629d35d3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5629d35bb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5629d35e6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efff9a71082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629ccee0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x42,0x1,0x0,0x0,0x0,0x2,0x2f,0x3d,0xb,0x30,0x27,0x9,0x5b,0x43,0x61,0x5d,0xa,0xa,0x9,0x9,0x9,0x32,0x20,0x3d,0x38,0xa,0x9,0xa,0x64,0x3d,0x22,0x22,0x22,0x9,0x7d,0x5c,0xa,0x9,0x9,0x5c,0xa,0x22,0x22,0x7d,0x5c,0xa,0x9,0x9,0x5c,0xa,0x22,0x22,0xb2,0x9,0x0,0xff,0xf9,0x0,0x22,0x22,0x22,0x26,0x2e,0x2e,0x30,0x9,0x0, Step #5: \000\000\000B\001\000\000\000\002/=\0130'\011[Ca]\012\012\011\011\0112 =8\012\011\012d=\"\"\"\011}\\\012\011\011\\\012\"\"}\\\012\011\011\\\012\"\"\262\011\000\377\371\000\"\"\"&..0\011\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-68951f570faa097b31c65c2d8e2e69addf019c4e Step #5: Base64: AAAAQgEAAAACLz0LMCcJW0NhXQoKCQkJMiA9OAoJCmQ9IiIiCX1cCgkJXAoiIn1cCgkJXAoiIrIJAP/5ACIiIiYuLjAJAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3661 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3528714079 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5589052ac810, 0x55890549601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558905496020,0x55890732e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/68951f570faa097b31c65c2d8e2e69addf019c4e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4535 processed earlier; will process 6494 files now Step #5: ==131872== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5588fbda19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558902406898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589023e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589023e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588fbda7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588fbd08b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588fbd03355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588fbd99c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5588fed68f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5588fed68f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5588fed68f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5588fed68f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5588fed68f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5588fed68f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5588fed68f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5588fed68f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5588fed68f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5588fed68f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558900ffdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588fdd2ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588fdd35be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588fdae1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588fdae1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588fdae2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588fdae1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588fdae1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588fdae1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5589023ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5589023f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5589023dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558902407112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f60c6ef6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588fbd01b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x1,0x0,0x0,0x0,0x21,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x5b,0x3a,0x3a,0x66,0x66,0x66,0x66,0x3a,0x63,0x30,0x61,0x38,0x3a,0x31,0x30,0x31,0x5d,0x2f,0x66,0x69,0x6c,0x78,0x74,0x65,0x2e,0x74,0x0,0x6,0x0,0x0,0x0,0x19,0x41,0x63,0x63,0x65,0x70,0x74,0x2d,0x45,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3a,0x20,0x69,0x65,0x65,0x6e,0x74,0x69,0x74,0xe8, Step #5: \000\001\000\000\000!http://[::ffff:c0a8:101]/filxte.t\000\006\000\000\000\031Accept-Encoding: ieentit\350 Step #5: artifact_prefix='./'; Test unit written to ./oom-58259384444abc211b36f884dc3b09b0ebe2c569 Step #5: Base64: AAEAAAAhaHR0cDovL1s6OmZmZmY6YzBhODoxMDFdL2ZpbHh0ZS50AAYAAAAZQWNjZXB0LUVuY29kaW5nOiBpZWVudGl06A== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3662 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3529217015 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55850bab6810, 0x55850bca001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55850bca0020,0x55850db380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58259384444abc211b36f884dc3b09b0ebe2c569' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4536 processed earlier; will process 6493 files now Step #5: #1 pulse cov: 3769 ft: 3770 exec/s: 0 rss: 174Mb Step #5: ==131908== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5585025ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558508c10898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558508bf35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558508bf34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5585025b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558502512b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55850250d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5585025a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558505572f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558505572f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558505572f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558505572f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558505572f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558505572f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558505572f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558505572f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558505572f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558505572f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558507807f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558504534b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55850453fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5585042ebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5585042ebc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5585042ec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5585042eb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5585042eb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5585042eb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558508bf5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558508bfe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558508be6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558508c11112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1ec9b83082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55850250bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x70,0x72,0x65,0x73,0x65,0x6e,0x63,0x65,0x3e,0x3c,0x70,0x65,0x72,0x73,0x6f,0x6e,0x3e,0x3c,0x61,0x63,0x74,0x69,0x76,0x69,0x74,0x69,0x65,0x73,0x3e,0x3c,0xa1,0x60,0xa1,0xa1,0x2f,0x3e,0x3c,0x2f,0x61,0x63,0x74,0x69,0x76,0x69,0x74,0x69,0x65,0x73,0x3e,0x3c,0x2f,0x70,0x65,0x72,0x73,0x6f,0x6e,0x3e,0x3c,0x2f,0x70,0x72,0x65,0x73,0x65,0x6e,0x63,0x65,0x3e, Step #5: <presence><person><activities><\241`\241\241/></activities></person></presence> Step #5: artifact_prefix='./'; Test unit written to ./oom-b56445a12bd29f7fb1938dfbc519e91637f77c5c Step #5: Base64: PHByZXNlbmNlPjxwZXJzb24+PGFjdGl2aXRpZXM+PKFgoaEvPjwvYWN0aXZpdGllcz48L3BlcnNvbj48L3ByZXNlbmNlPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3663 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3529757483 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d392268810, 0x55d39245201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d392452020,0x55d3942ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b56445a12bd29f7fb1938dfbc519e91637f77c5c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4538 processed earlier; will process 6491 files now Step #5: #1 pulse cov: 10445 ft: 10446 exec/s: 0 rss: 190Mb Step #5: #2 pulse cov: 11477 ft: 12339 exec/s: 0 rss: 192Mb Step #5: ==131944== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d388d5d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d38f3c2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d38f3a55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d38f3a54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d388d63d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d388cc4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d388cbf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d388d55c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d38bd24f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d38bd24f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d38bd24f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d38bd24f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d38bd24f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d38bd24f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d38bd24f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d38bd24f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d38bd24f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d38bd24f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d38dfb9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d38ace6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d38acf1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d38aa9dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d38aa9dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d38aa9e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d38aa9d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d38aa9d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d38aa9d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d38f3a7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d38f3b0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d38f398699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d38f3c3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8d1fe4c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d388cbdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x8,0x1a,0x6,0xa,0x4,0xf0,0x9a,0xa9,0xbd,0xa,0x8,0x1a,0x6,0xa,0x4,0xf0,0x9a,0xa9,0xbd,0xa,0x8,0x1a,0x6,0xa,0x4,0xf0,0x9a,0xa9,0xbd,0xa,0x8,0x1a,0x6,0xa,0x4,0xf0,0x9a,0xa9,0xbd,0xa,0x8,0x1a,0x6,0xa,0x4,0xf0,0x9a,0xa9,0xbd,0xa,0x8,0x1a,0x6,0xa,0x4,0xf0,0x90,0xa9,0xbd,0xa,0x8,0x1a,0x6,0xa,0x4,0xf0,0x9a,0xa9,0xbd, Step #5: \012\010\032\006\012\004\360\232\251\275\012\010\032\006\012\004\360\232\251\275\012\010\032\006\012\004\360\232\251\275\012\010\032\006\012\004\360\232\251\275\012\010\032\006\012\004\360\232\251\275\012\010\032\006\012\004\360\220\251\275\012\010\032\006\012\004\360\232\251\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-0797c3de101f183927adeabff6d3f932ea376d19 Step #5: Base64: CggaBgoE8JqpvQoIGgYKBPCaqb0KCBoGCgTwmqm9CggaBgoE8JqpvQoIGgYKBPCaqb0KCBoGCgTwkKm9CggaBgoE8JqpvQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3664 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3530359031 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5622add94810, 0x5622adf7e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622adf7e020,0x5622afe160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0797c3de101f183927adeabff6d3f932ea376d19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4541 processed earlier; will process 6488 files now Step #5: ==131980== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5622a48899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5622aaeee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5622aaed15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5622aaed14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5622a488fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5622a47f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5622a47eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5622a4881c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5622a7850f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5622a7850f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5622a7850f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5622a7850f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5622a7850f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5622a7850f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5622a7850f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5622a7850f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5622a7850f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5622a7850f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5622a9ae5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5622a6812b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5622a681dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5622a65c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5622a65c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5622a65ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5622a65c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5622a65c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5622a65c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5622aaed3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5622aaedc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5622aaec4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5622aaeef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fde35a50082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5622a47e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x42,0x2d,0x2d,0x2d,0x78,0x2d,0x45,0x47,0x8,0x0,0x31,0xf,0x73,0x74,0x2d,0x2d,0x2d,0x2d,0x45,0x42,0x47,0x49,0x4e,0xf3,0xa0,0x81,0x94,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x20,0x47,0x49,0x4e,0x20,0x2d,0x29,0x2d,0x2d,0x24,0x24,0xa,0x2d,0x20, Step #5: -B---x-EG\010\0001\017st----EBGIN\363\240\201\224 \000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000------\012- GIN -)--$$\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-b4890dc72a83a66299f196f23ada611b1c310068 Step #5: Base64: LUItLS14LUVHCAAxD3N0LS0tLUVCR0lO86CBlCAAAAAAAAAAAAAAAAAAAAAAAAAALS0tLS0tCi0gR0lOIC0pLS0kJAotIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3665 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3530867419 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc16ea5810, 0x55fc1708f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc1708f020,0x55fc18f270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b4890dc72a83a66299f196f23ada611b1c310068' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4542 processed earlier; will process 6487 files now Step #5: #1 pulse cov: 3680 ft: 3681 exec/s: 0 rss: 174Mb Step #5: ==132016== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fc0d99a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc13fff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc13fe25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc13fe24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc0d9a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc0d901b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc0d8fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc0d992c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc10961f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc10961f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc10961f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc10961f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc10961f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc10961f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc10961f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc10961f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc10961f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc10961f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc12bf6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc0f923b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc0f92ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc0f6dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc0f6dac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc0f6db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc0f6da874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc0f6da874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc0f6da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc13fe4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc13fed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc13fd5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc14000112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbcde016082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc0d8fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x7f,0x7f,0x2d,0x42,0x4f,0x53,0x2f,0x32,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x28,0x0,0x72,0x64,0x64,0x64,0x64,0x64,0x64, Step #5: = \177\177-BOS/2\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000(\000rdddddd Step #5: artifact_prefix='./'; Test unit written to ./oom-d727af6c6074e086a13ea42f478e3f008bfcd5ab Step #5: Base64: PSB/fy1CT1MvMgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACgAcmRkZGRkZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3666 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3531415015 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563f7ef72810, 0x563f7f15c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563f7f15c020,0x563f80ff40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d727af6c6074e086a13ea42f478e3f008bfcd5ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4544 processed earlier; will process 6485 files now Step #5: ==132052== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563f75a679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563f7c0cc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563f7c0af5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563f7c0af4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563f75a6dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563f759ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563f759c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563f75a5fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563f78a2ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563f78a2ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563f78a2ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563f78a2ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563f78a2ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563f78a2ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563f78a2ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563f78a2ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563f78a2ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563f78a2ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563f7acc3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563f779f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563f779fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563f777a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563f777a7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563f777a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563f777a7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563f777a7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563f777a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563f7c0b1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563f7c0ba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563f7c0a2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563f7c0cd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe6b0973082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563f759c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x34,0x4,0x44,0x32,0x35,0x34,0x4,0x27,0x0,0x0,0x61,0x27,0x17,0x54,0x59,0x33,0x45,0x4,0x27,0x0,0x0,0x60,0x27,0x0,0x0,0x61,0x27,0x17,0x54,0x59,0x31,0x45,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x15,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x10,0x0,0x45,0x15,0x0,0x10, Step #5: ID4\004D254\004'\000\000a'\027TY3E\004'\000\000`'\000\000a'\027TY1E\004'\000\000`'\027TY\025UUUUUUUUUUUUUUUUUUUU\020\000E\025\000\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-eeb64d64e80bf33725cf28117de0b57323913425 Step #5: Base64: SUQ0BEQyNTQEJwAAYScXVFkzRQQnAABgJwAAYScXVFkxRQQnAABgJxdUWRVVVVVVVVVVVVVVVVVVVVVVVVVVVRAARRUAEA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3667 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3532039225 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc163e9810, 0x55cc165d301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc165d3020,0x55cc1846b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eeb64d64e80bf33725cf28117de0b57323913425' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4545 processed earlier; will process 6484 files now Step #5: ==132088== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cc0cede9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc13543898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc135265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc135264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc0cee4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc0ce45b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc0ce40355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc0ced6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc0fea5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc0fea5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc0fea5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc0fea5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc0fea5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc0fea5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc0fea5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc0fea5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc0fea5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc0fea5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc1213af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc0ee67b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc0ee72be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc0ec1ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc0ec1ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc0ec1f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc0ec1e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc0ec1e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc0ec1e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc13528abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc13531928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc13519699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc13544112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb8b509d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc0ce3eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x2c,0x24,0x2c,0x2b,0x2c,0xd,0x2c,0x3d,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x24,0x66,0x3a,0x1a, Step #5: ,$,+,\015,=,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,$f:\032 Step #5: artifact_prefix='./'; Test unit written to ./oom-bbfe583279d4c3b3b40c746f7e8933026dddbc02 Step #5: Base64: ICwkLCssDSw9LCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsJGY6Gg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3668 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3532542598 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d9169f810, 0x556d9188901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d91889020,0x556d937210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bbfe583279d4c3b3b40c746f7e8933026dddbc02' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4546 processed earlier; will process 6483 files now Step #5: ==132124== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556d881949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d8e7f9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d8e7dc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d8e7dc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d8819ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d880fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d880f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d8818cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d8b15bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d8b15bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d8b15bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d8b15bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d8b15bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d8b15bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d8b15bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d8b15bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d8b15bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d8b15bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d8d3f0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d8a11db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d8a128be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d89ed4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d89ed4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d89ed5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d89ed4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d89ed4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d89ed4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d8e7deabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d8e7e7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d8e7cf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d8e7fa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7968118082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d880f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x63,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x63,0x6e,0x3d,0x5c, Step #5: dn:Cn=\\\012\012dn:Cn=\\\012\012dn:Cn=\\\012\012dn:Cn=\\\012\012dn:cn=\\\012\012dn:Cn=\\\012\012dn:Cn=\\\012\012dn:cn=\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-1c9170e71014dc7b218d3eb2908d7920a006705b Step #5: Base64: ZG46Q249XAoKZG46Q249XAoKZG46Q249XAoKZG46Q249XAoKZG46Y249XAoKZG46Q249XAoKZG46Q249XAoKZG46Y249XA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3669 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3533045990 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56433bc06810, 0x56433bdf001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56433bdf0020,0x56433dc880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c9170e71014dc7b218d3eb2908d7920a006705b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4547 processed earlier; will process 6482 files now Step #5: ==132160== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643326fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564338d60898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564338d435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564338d434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564332701d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564332662b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56433265d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643326f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643356c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643356c2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643356c2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643356c2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643356c2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643356c2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643356c2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643356c2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643356c2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643356c2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564337957f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564334684b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56433468fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56433443bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56433443bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56433443c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56433443b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56433443b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56433443b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564338d45abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564338d4e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564338d36699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564338d61112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb64c1a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56433265bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x20,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x3a,0x3c,0x70,0x61,0x74,0x68,0x6c,0x65,0x3e,0x3a,0x20,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x3a,0x3c,0x70,0x61,0x74,0x68,0x6c,0x65,0x3e,0x3a,0x3c,0x72,0x61,0x64,0x69,0x61,0x6c,0x70,0x61,0x74,0x68,0x6c,0x65,0x3e,0x3a,0x5c,0x13,0x2,0x20,0x76,0x65,0x72,0x73,0x69,0x0,0x0,0x0, Step #5: <svg> ><style>:<pathle>: ><style>:<pathle>:<radialpathle>:\\\023\002 versi\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-60ab5d396c6d311b90ef0f9301f0e4a316054a11 Step #5: Base64: PHN2Zz4gPjxzdHlsZT46PHBhdGhsZT46ID48c3R5bGU+OjxwYXRobGU+OjxyYWRpYWxwYXRobGU+OlwTAiB2ZXJzaQAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3670 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3533548402 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c0e0f8b810, 0x55c0e117501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c0e1175020,0x55c0e300d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/60ab5d396c6d311b90ef0f9301f0e4a316054a11' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4548 processed earlier; will process 6481 files now Step #5: #1 pulse cov: 4115 ft: 4116 exec/s: 0 rss: 174Mb Step #5: ==132196== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c0d7a809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c0de0e5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c0de0c85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c0de0c84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c0d7a86d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c0d79e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c0d79e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c0d7a78c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c0daa47f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c0daa47f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c0daa47f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c0daa47f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c0daa47f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c0daa47f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c0daa47f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c0daa47f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c0daa47f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c0daa47f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c0dccdcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c0d9a09b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c0d9a14be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c0d97c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c0d97c0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c0d97c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c0d97c0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c0d97c0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c0d97c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c0de0caabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c0de0d3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c0de0bb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c0de0e6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb58e642082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c0d79e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0x7c,0x2e,0x2e,0x7c,0x2e,0x2e,0x7c,0x7c,0x2e,0x7c,0x2e,0x2e,0x7c,0x2e,0x2e,0x7c,0x7c,0x2e,0x7c,0x2e,0x2e,0x7c,0x2e,0x2e,0x7c,0x7c,0x2e,0x7c,0x2e,0x2e,0x7c,0x2e,0x2e,0x7c,0x7c,0x2e,0x7c,0x2e,0x2e,0x7c,0x2e,0x2e,0x7c,0x7c,0x2e,0x7c,0x2e,0x2e,0x7c,0x2e,0x2e,0x7c,0x7c,0x2e,0x7c,0x2e,0x2e,0x7c,0x2e,0x2e,0x7c,0x7c,0x2e,0x7c,0x2e,0x2e,0x7c,0x2e,0x2e, Step #5: .|..|..||.|..|..||.|..|..||.|..|..||.|..|..||.|..|..||.|..|..||.|..|.. Step #5: artifact_prefix='./'; Test unit written to ./oom-0740b2074bad32990babd40de77c8f1ad8414d12 Step #5: Base64: LnwuLnwuLnx8LnwuLnwuLnx8LnwuLnwuLnx8LnwuLnwuLnx8LnwuLnwuLnx8LnwuLnwuLnx8LnwuLnwuLnx8LnwuLnwuLg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3671 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3534100975 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c78a7f810, 0x556c78c6901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c78c69020,0x556c7ab010e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0740b2074bad32990babd40de77c8f1ad8414d12' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4550 processed earlier; will process 6479 files now Step #5: ==132232== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556c6f5749c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c75bd9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c75bbc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c75bbc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556c6f57ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556c6f4dbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556c6f4d6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556c6f56cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556c7253bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556c7253bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556c7253bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556c7253bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556c7253bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556c7253bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556c7253bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556c7253bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556c7253bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556c7253bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c747d0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556c714fdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556c71508be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556c712b4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556c712b4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556c712b5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556c712b4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556c712b4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556c712b4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c75bbeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c75bc7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c75baf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c75bda112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f614624a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556c6f4d4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2,0xa,0x2d,0x4d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0xd5,0xa,0x2,0xa,0x32,0xa,0xdc,0xa,0xd2,0xa,0x0,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xff, Step #5: \000-----BEGIN -----\012,\012-\012d\012-\012d\012d\012-\012\002\012-\012\002\012-M\012,\012-\012d\012-\012d\012\325\012\002\0122\012\334\012\322\012\000\012-\012-\012-\012\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-1ae03834cf6c0bef593c4d7803fb19df1f5d71a3 Step #5: Base64: AC0tLS0tQkVHSU4gLS0tLS0KLAotCmQKLQpkCmQKLQoCCi0KAgotTQosCi0KZAotCmQK1QoCCjIK3ArSCgAKLQotCi0K/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3672 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3534614020 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b31165c810, 0x55b31184601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b311846020,0x55b3136de0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ae03834cf6c0bef593c4d7803fb19df1f5d71a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4551 processed earlier; will process 6478 files now Step #5: ==132268== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b3081519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b30e7b6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b30e7995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b30e7994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b308157d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b3080b8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b3080b3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b308149c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b30b118f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b30b118f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b30b118f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b30b118f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b30b118f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b30b118f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b30b118f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b30b118f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b30b118f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b30b118f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b30d3adf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b30a0dab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b30a0e5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b309e91c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b309e91c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b309e92738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b309e91874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b309e91874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b309e91874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b30e79babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b30e7a4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b30e78c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b30e7b7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb0288b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b3080b1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x23,0x33,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x2e,0x34,0x34,0x34,0x34,0x34,0x0,0x0,0x0,0x0,0x0,0x73,0x2d,0x2d,0x23,0x33,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x2e,0x34,0x34,0x34,0x34,0x34,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x0,0x0,0x2d,0x2d,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x5a,0x34,0x34,0x34,0x34,0x0,0x0,0x39, Step #5: s--#344444444.44444\000\000\000\000\000s--#344444444.44444\000\000\000\000\000\000\000\020\000\000--\001\000\000\000\000\000\000Z4444\000\0009 Step #5: artifact_prefix='./'; Test unit written to ./oom-0beb40c7d86d29b1170705a39bf9ce5146731dd3 Step #5: Base64: cy0tIzM0NDQ0NDQ0NC40NDQ0NAAAAAAAcy0tIzM0NDQ0NDQ0NC40NDQ0NAAAAAAAAAAQAAAtLQEAAAAAAABaNDQ0NAAAOQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3673 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3535107672 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56200c781810, 0x56200c96b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56200c96b020,0x56200e8030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0beb40c7d86d29b1170705a39bf9ce5146731dd3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4552 processed earlier; will process 6477 files now Step #5: ==132304== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5620032769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5620098db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5620098be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5620098be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56200327cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5620031ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5620031d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56200326ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56200623df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56200623df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56200623df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56200623df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56200623df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56200623df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56200623df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56200623df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56200623df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56200623df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5620084d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5620051ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56200520abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562004fb6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562004fb6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562004fb7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562004fb6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562004fb6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562004fb6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5620098c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5620098c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5620098b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5620098dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6d88308082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5620031d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x41,0xa,0x2d,0x20,0xa,0x2d,0xa,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0xa,0x2d,0x20,0x2d,0x1, Step #5: \000\000\000A\012- \012-\012-\012- - -\012-\012-\012- -\012-\012-\012- -\012-\012-\012- -\012- -\012-\012-\012- - -\012-\012-\012- -\012-\012- -\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-a31fdbade419aef2a061ab24a24f246246e93fa6 Step #5: Base64: AAAAQQotIAotCi0KLSAtIC0KLQotCi0gLQotCi0KLSAtCi0KLQotIC0KLSAtCi0KLQotIC0gLQotCi0KLSAtCi0KLSAtAQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3674 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3535634054 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559324039810, 0x55932422301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559324223020,0x5593260bb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a31fdbade419aef2a061ab24a24f246246e93fa6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4553 processed earlier; will process 6476 files now Step #5: ==132340== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55931ab2e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559321193898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5593211765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5593211764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55931ab34d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55931aa95b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55931aa90355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55931ab26c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55931daf5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55931daf5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55931daf5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55931daf5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55931daf5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55931daf5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55931daf5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55931daf5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55931daf5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55931daf5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55931fd8af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55931cab7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55931cac2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55931c86ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55931c86ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55931c86f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55931c86e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55931c86e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55931c86e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559321178abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559321181928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559321169699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559321194112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7c424f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55931aa8eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d, Step #5: \015- - - - - - - - - - - - - - - - - \015- - - - - - - - - - - - - - - - - Step #5: artifact_prefix='./'; Test unit written to ./oom-15d39c5ec458e1d9d9a46afebfec816be063ed6e Step #5: Base64: IA0tIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gDS0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3675 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3536178229 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a826906810, 0x55a826af001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a826af0020,0x55a8289880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/15d39c5ec458e1d9d9a46afebfec816be063ed6e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4554 processed earlier; will process 6475 files now Step #5: ==132376== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a81d3fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a823a60898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a823a435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a823a434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a81d401d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a81d362b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a81d35d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a81d3f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a8203c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a8203c2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a8203c2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a8203c2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a8203c2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a8203c2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a8203c2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a8203c2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a8203c2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a8203c2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a822657f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a81f384b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a81f38fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a81f13bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a81f13bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a81f13c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a81f13b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a81f13b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a81f13b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a823a45abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a823a4e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a823a36699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a823a61112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e54457082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a81d35bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x24,0x2b,0x3d,0xd,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x24,0x66,0x3a,0x1a, Step #5: $+=\015,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,$f:\032 Step #5: artifact_prefix='./'; Test unit written to ./oom-56470fbe94889961b6fb07517f0e9ebf695576bd Step #5: Base64: ICQrPQ0sLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsJGY6Gg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3676 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3536681621 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e872adb810, 0x55e872cc501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e872cc5020,0x55e874b5d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56470fbe94889961b6fb07517f0e9ebf695576bd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4555 processed earlier; will process 6474 files now Step #5: ==132412== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e8695d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e86fc35898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e86fc185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e86fc184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e8695d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e869537b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e869532355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e8695c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e86c597f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e86c597f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e86c597f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e86c597f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e86c597f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e86c597f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e86c597f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e86c597f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e86c597f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e86c597f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e86e82cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e86b559b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e86b564be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e86b310c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e86b310c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e86b311738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e86b310874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e86b310874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e86b310874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e86fc1aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e86fc23928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e86fc0b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e86fc36112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f15df70f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e869530b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x0,0x3f,0x0,0x78,0x0,0x3f,0x0,0x78,0x0,0x4d,0x0,0x31,0x0,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x70,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x0,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0xc6,0x0,0xdb,0x0, Step #5: <\000?\000x\000?\000x\000M\0001\000```````p`````````````````````````\000``````````````````\306\000\333\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1a3b56252dc549e8d402dd87a2843137cc7b0685 Step #5: Base64: PAA/AHgAPwB4AE0AMQBgYGBgYGBgcGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGAAYGBgYGBgYGBgYGBgYGBgYGBgxgDbAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3677 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3537319349 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5624eb3de810, 0x5624eb5c801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5624eb5c8020,0x5624ed4600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1a3b56252dc549e8d402dd87a2843137cc7b0685' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4556 processed earlier; will process 6473 files now Step #5: ==132448== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5624e1ed39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5624e8538898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5624e851b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5624e851b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5624e1ed9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5624e1e3ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5624e1e35355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5624e1ecbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5624e4e9af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5624e4e9af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5624e4e9af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5624e4e9af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5624e4e9af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5624e4e9af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5624e4e9af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5624e4e9af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5624e4e9af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5624e4e9af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5624e712ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5624e3e5cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5624e3e67be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5624e3c13c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5624e3c13c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5624e3c14738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5624e3c13874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5624e3c13874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5624e3c13874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5624e851dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5624e8526928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5624e850e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5624e8539112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff0f5a60082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5624e1e33b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x0,0x2,0x49,0x41,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa5,0x15,0xac, Step #5: \001\000\002IA\004\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\245\025\254 Step #5: artifact_prefix='./'; Test unit written to ./oom-c0ce37d35b38430955b4b70ea4740b17b8417277 Step #5: Base64: AQACSUEEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAClFaw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3678 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3537819142 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5638b28f8810, 0x5638b2ae201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5638b2ae2020,0x5638b497a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c0ce37d35b38430955b4b70ea4740b17b8417277' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4557 processed earlier; will process 6472 files now Step #5: ==132484== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5638a93ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5638afa52898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5638afa355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5638afa354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5638a93f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5638a9354b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5638a934f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5638a93e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5638ac3b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5638ac3b4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5638ac3b4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5638ac3b4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5638ac3b4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5638ac3b4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5638ac3b4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5638ac3b4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5638ac3b4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5638ac3b4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5638ae649f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5638ab376b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5638ab381be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5638ab12dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5638ab12dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5638ab12e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5638ab12d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5638ab12d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5638ab12d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5638afa37abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5638afa40928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5638afa28699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5638afa53112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa8fe253082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5638a934db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x5c,0x5f,0x20,0x31,0xde,0xad,0xbe,0xef, Step #5: \000\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_\\_ 1\336\255\276\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-a36b876ea28ec7fe5ec6b860584a41f3d1303621 Step #5: Base64: AFxfXF9cX1xfXF9cX1xfXF9cX1xfXF9cX1xfXF9cX1xfXF9cX1xfXF9cX1xfXF9cX1xfXF9cX1xfXF9cX1xfXF8gMd6tvu8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3679 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3538318755 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5564f6cdf810, 0x5564f6ec901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564f6ec9020,0x5564f8d610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a36b876ea28ec7fe5ec6b860584a41f3d1303621' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4558 processed earlier; will process 6471 files now Step #5: ==132520== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5564ed7d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564f3e39898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564f3e1c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564f3e1c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564ed7dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5564ed73bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5564ed736355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564ed7ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564f079bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564f079bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564f079bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564f079bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564f079bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564f079bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564f079bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564f079bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564f079bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564f079bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5564f2a30f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5564ef75db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5564ef768be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5564ef514c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5564ef514c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5564ef515738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5564ef514874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5564ef514874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5564ef514874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564f3e1eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564f3e27928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564f3e0f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564f3e3a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc6201ad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5564ed734b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53,0x45,0x4c,0x45,0x43,0x54,0x2a,0x4f,0x52,0x44,0x45,0x52,0x20,0x42,0x59,0x3f,0x54,0x3b,0x53,0x45,0x4c,0x45,0x43,0x54,0x2a,0x4f,0x52,0x44,0x45,0x52,0x20,0x42,0x59,0x3f,0x54,0x3b,0x53,0x45,0x4c,0x45,0x43,0x54,0x2a,0x4f,0x52,0x44,0x45,0x52,0x20,0x42,0x59,0x3f,0x54,0x3b,0x53,0x45,0x4c,0x45,0x43,0x54,0x2a,0x4f,0x52,0x44,0x45,0x52,0x20,0x42,0x59,0x3f,0x54, Step #5: SELECT*ORDER BY?T;SELECT*ORDER BY?T;SELECT*ORDER BY?T;SELECT*ORDER BY?T Step #5: artifact_prefix='./'; Test unit written to ./oom-01d0efda0bd0397dfea866ff27225ee54c7e914f Step #5: Base64: U0VMRUNUKk9SREVSIEJZP1Q7U0VMRUNUKk9SREVSIEJZP1Q7U0VMRUNUKk9SREVSIEJZP1Q7U0VMRUNUKk9SREVSIEJZP1Q= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3680 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3538821051 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c163d3810, 0x561c165bd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c165bd020,0x561c184550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01d0efda0bd0397dfea866ff27225ee54c7e914f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4559 processed earlier; will process 6470 files now Step #5: #1 pulse cov: 11031 ft: 11032 exec/s: 0 rss: 197Mb Step #5: #2 pulse cov: 11388 ft: 12270 exec/s: 0 rss: 198Mb Step #5: ==132556== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561c0cec89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c1352d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c135105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c135104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c0ceced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c0ce2fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c0ce2a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c0cec0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c0fe8ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c0fe8ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c0fe8ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c0fe8ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c0fe8ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c0fe8ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c0fe8ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c0fe8ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c0fe8ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c0fe8ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c12124f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c0ee51b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c0ee5cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c0ec08c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c0ec08c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c0ec09738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c0ec08874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c0ec08874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c0ec08874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c13512abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c1351b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c13503699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c1352e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcfb05ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c0ce28b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x24,0x75,0xef,0xbc,0x8f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xdb,0x80,0x1,0x0,0x0,0x38,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x0,0x0,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x44,0x11,0xf3,0xa0,0x80,0xb3,0x27,0x0,0x44,0x1,0x24, Step #5: \000$u\357\274\217\000\000\000\000\000\000\000\000\333\200\001\000\000834028236692093846346\000\000\000\000\342\200\256\000\000\000\000\000\000\000\000\000\000\000\000\000D\021\363\240\200\263'\000D\001$ Step #5: artifact_prefix='./'; Test unit written to ./oom-df6a0b4570a025f1282021cc09c6148eb3e7d0f7 Step #5: Base64: ACR177yPAAAAAAAAAADbgAEAADgzNDAyODIzNjY5MjA5Mzg0NjM0NgAAAADigK4AAAAAAAAAAAAAAAAARBHzoICzJwBEASQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3681 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3539482236 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5615c1734810, 0x5615c191e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5615c191e020,0x5615c37b60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/df6a0b4570a025f1282021cc09c6148eb3e7d0f7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4562 processed earlier; will process 6467 files now Step #5: ==132592== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5615b82299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5615be88e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5615be8715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5615be8714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5615b822fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5615b8190b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5615b818b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5615b8221c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5615bb1f0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5615bb1f0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5615bb1f0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5615bb1f0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5615bb1f0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5615bb1f0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5615bb1f0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5615bb1f0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5615bb1f0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5615bb1f0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5615bd485f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5615ba1b2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5615ba1bdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5615b9f69c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5615b9f69c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5615b9f6a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5615b9f69874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5615b9f69874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5615b9f69874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5615be873abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5615be87c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5615be864699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5615be88f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f82749e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5615b8189b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x35,0xdb,0x80,0x44,0x61,0x6e,0x4d,0x24,0x24,0x24,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xff,0xff,0xff,0xff,0xff,0xff,0xdb,0xff,0xff,0xff,0xff,0xff,0x0,0x0,0x0,0xb,0x0,0x0,0x0,0x1,0x1d,0x0,0x0,0x0,0x0,0x0,0xb,0x0,0x0,0x0,0x0,0x3e,0x3f,0x3f,0x3f,0x3f,0x3f,0x50,0x59,0x45,0x6a,0x3f,0x3f,0x3f,0x3f,0x6b,0x0,0x0, Step #5: 5\333\200DanM$$$$\000\000\000\000\000\000\000\000\000\000\000\000\377\377\377\377\377\377\333\377\377\377\377\377\000\000\000\013\000\000\000\001\035\000\000\000\000\000\013\000\000\000\000>?????PYEj????k\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1516048d3dac87e81741793d6d7485450dd5a74c Step #5: Base64: NduARGFuTSQkJCQAAAAAAAAAAAAAAAD////////b//////8AAAALAAAAAR0AAAAAAAsAAAAAPj8/Pz8/UFlFaj8/Pz9rAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3682 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3539979957 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5557ef689810, 0x5557ef87301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5557ef873020,0x5557f170b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1516048d3dac87e81741793d6d7485450dd5a74c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4563 processed earlier; will process 6466 files now Step #5: ==132628== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5557e617e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5557ec7e3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557ec7c65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557ec7c64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557e6184d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557e60e5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5557e60e0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557e6176c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557e9145f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557e9145f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557e9145f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557e9145f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557e9145f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557e9145f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557e9145f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557e9145f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557e9145f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557e9145f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5557eb3daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557e8107b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557e8112be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5557e7ebec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5557e7ebec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5557e7ebf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5557e7ebe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5557e7ebe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5557e7ebe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557ec7c8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557ec7d1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557ec7b9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5557ec7e4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0b11632082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5557e60deb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3e,0x32,0x2d,0x3d,0x3e,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x3d,0x3e,0x32,0x2d,0x3d,0x3e,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x4c,0x43,0xb2,0xb2,0xb2,0xb2,0x24, Step #5: =>2-=>\336\256!\336\256-\\\\\\\\\336\256!\336\256-\\\\\\=>2-=>\336\256!\336\256-\\\\\\\\\336\256!\336\256-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\LC\262\262\262\262$ Step #5: artifact_prefix='./'; Test unit written to ./oom-bfcc7b9b798ceca9f05698d51204ef4d449c3aef Step #5: Base64: PT4yLT0+3q4h3q4tXFxcXN6uId6uLVxcXD0+Mi09Pt6uId6uLVxcXFzeriHeri1cXFxcXFxcXFxcXFxcXFxcXExDsrKysiQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3683 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3540484553 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d3c0666810, 0x55d3c085001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d3c0850020,0x55d3c26e80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bfcc7b9b798ceca9f05698d51204ef4d449c3aef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4564 processed earlier; will process 6465 files now Step #5: ==132664== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d3b715b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d3bd7c0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d3bd7a35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d3bd7a34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d3b7161d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d3b70c2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d3b70bd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d3b7153c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d3ba122f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d3ba122f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d3ba122f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d3ba122f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d3ba122f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d3ba122f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d3ba122f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d3ba122f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d3ba122f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d3ba122f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d3bc3b7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d3b90e4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d3b90efbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d3b8e9bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d3b8e9bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d3b8e9c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d3b8e9b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d3b8e9b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d3b8e9b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d3bd7a5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d3bd7ae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d3bd796699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d3bd7c1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb23a4f0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d3b70bbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xf3,0xa0,0x81,0x87,0xf3,0xa0,0x81,0x87,0xf3,0xa0,0x80,0xbf,0xf3,0xa0,0x81,0x87,0xf3,0xa0,0x81,0x87,0xf3,0xa0,0x84,0xa0,0xf3,0xa0,0x81,0x87,0xf3,0xa0,0x81,0x87,0xf3,0xa0,0x80,0xbf,0xf3,0xa0,0x81,0x87,0xf3,0xa0,0x81,0x87,0xf3,0xa0,0x80,0xa0,0xf3,0xa0,0x81,0x87,0xf3,0x9f,0x80,0xa0,0xf3,0xa0,0x81,0x87,0xf3,0x9f,0x80,0xa0,0xf3,0xa0,0x80,0xb2,0x2f,0x3e, Step #5: <\363\240\201\207\363\240\201\207\363\240\200\277\363\240\201\207\363\240\201\207\363\240\204\240\363\240\201\207\363\240\201\207\363\240\200\277\363\240\201\207\363\240\201\207\363\240\200\240\363\240\201\207\363\237\200\240\363\240\201\207\363\237\200\240\363\240\200\262/> Step #5: artifact_prefix='./'; Test unit written to ./oom-04cc4a9e1d03c031870a84b82d441d3a9635ca94 Step #5: Base64: PPOggYfzoIGH86CAv/OggYfzoIGH86CEoPOggYfzoIGH86CAv/OggYfzoIGH86CAoPOggYfzn4Cg86CBh/OfgKDzoICyLz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3684 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3540980254 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5592415e0810, 0x5592417ca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5592417ca020,0x5592436620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/04cc4a9e1d03c031870a84b82d441d3a9635ca94' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4565 processed earlier; will process 6464 files now Step #5: ==132700== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5592380d59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55923e73a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55923e71d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55923e71d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592380dbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55923803cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559238037355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592380cdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55923b09cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55923b09cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55923b09cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55923b09cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55923b09cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55923b09cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55923b09cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55923b09cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55923b09cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55923b09cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55923d331f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55923a05eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55923a069be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559239e15c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559239e15c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559239e16738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559239e15874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559239e15874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559239e15874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55923e71fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55923e728928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55923e710699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55923e73b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f399f832082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559238035b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x45,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0xa,0x0,0x8,0x0,0xa,0x0,0xa,0x0,0xa, Step #5: \012E\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\012\000\010\000\012\000\012\000\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-8d237bf64d0019929d1e0d1c658346f46b824295 Step #5: Base64: CkUKAAoACgAKAAoACgAKAAoACgAKAAoACgAKAAoACgAKAAoACgAKAAoACgAKAAoACgAKAAoACgAKAAoACgAKAAgACgAKAAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3685 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3541479362 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b03ddba810, 0x55b03dfa401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b03dfa4020,0x55b03fe3c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d237bf64d0019929d1e0d1c658346f46b824295' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4566 processed earlier; will process 6463 files now Step #5: ==132736== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b0348af9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b03af14898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b03aef75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b03aef74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0348b5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b034816b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b034811355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0348a7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b037876f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b037876f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b037876f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b037876f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b037876f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b037876f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b037876f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b037876f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b037876f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b037876f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b039b0bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b036838b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b036843be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b0365efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b0365efc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b0365f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b0365ef874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b0365ef874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b0365ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b03aef9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b03af02928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b03aeea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b03af15112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f36c0a25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b03480fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x42,0x22,0x74,0x6f,0x74,0x66,0x38,0xe4,0x8b,0x8f,0xe4,0x8b,0x8b,0xe4,0x8b,0x8b,0x31,0xe4,0x8b,0x8b,0xe4,0x8b,0x8b,0x5b,0x37,0xe4,0x8b,0x8f,0xe4,0x8b,0x8b,0xe4,0x8b,0x8b,0x74,0x6f,0x37,0xe4,0x8b,0x8b,0xe4,0x8b,0x8b,0xe4,0x8b,0x8b,0xe4,0x8b,0x8b,0x74,0x6f,0xe4,0x8b,0x8b,0xe4,0x8b,0x8b,0x30,0xe4,0x8b,0x8b,0xe4,0x8b,0x8b,0x5b,0x5b,0x4c,0x4c,0x5b, Step #5: HUB\"totf8\344\213\217\344\213\213\344\213\2131\344\213\213\344\213\213[7\344\213\217\344\213\213\344\213\213to7\344\213\213\344\213\213\344\213\213\344\213\213to\344\213\213\344\213\2130\344\213\213\344\213\213[[LL[ Step #5: artifact_prefix='./'; Test unit written to ./oom-365e487b2141aa49dd7e950a8dcddb0e0415066e Step #5: Base64: SFVCInRvdGY45IuP5IuL5IuLMeSLi+SLi1s35IuP5IuL5IuLdG835IuL5IuL5IuL5IuLdG/ki4vki4sw5IuL5IuLW1tMTFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3686 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3541979897 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5590df767810, 0x5590df95101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5590df951020,0x5590e17e90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/365e487b2141aa49dd7e950a8dcddb0e0415066e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4567 processed earlier; will process 6462 files now Step #5: ==132772== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5590d625c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5590dc8c1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5590dc8a45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5590dc8a44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5590d6262d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5590d61c3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5590d61be355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5590d6254c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5590d9223f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5590d9223f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5590d9223f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5590d9223f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5590d9223f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5590d9223f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5590d9223f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5590d9223f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5590d9223f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5590d9223f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5590db4b8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5590d81e5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5590d81f0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5590d7f9cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5590d7f9cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5590d7f9d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5590d7f9c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5590d7f9c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5590d7f9c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5590dc8a6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5590dc8af928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5590dc897699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5590dc8c2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3dc7a60082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5590d61bcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0x0,0x0,0x3a,0x24,0x5b,0x2d,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0x0,0x0,0x3a,0x24,0x5b,0x2d,0xf,0xf,0xf,0x31,0x11,0x60,0xf,0x39,0x2d,0xa,0x3a,0x24,0x55,0x55,0x5b,0xf,0xf,0xf,0x31,0x11,0x60,0xf,0x39,0x2d,0xa,0x3a,0x24,0x55,0x55,0x5b,0x2d,0x3a,0x24,0x60, Step #5: $\000\000/\000\000/\000\017\017\017\017\0171\021\000\000:$[-\000/\000\017\017\017\017\0171\021\000\000:$[-\017\017\0171\021`\0179-\012:$UU[\017\017\0171\021`\0179-\012:$UU[-:$` Step #5: artifact_prefix='./'; Test unit written to ./oom-a1bcc12bc423f293ba28835ced3652bc2090f25a Step #5: Base64: JAAALwAALwAPDw8PDzERAAA6JFstAC8ADw8PDw8xEQAAOiRbLQ8PDzERYA85LQo6JFVVWw8PDzERYA85LQo6JFVVWy06JGA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3687 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3542608493 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558087b6f810, 0x558087d5901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558087d59020,0x558089bf10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a1bcc12bc423f293ba28835ced3652bc2090f25a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4568 processed earlier; will process 6461 files now Step #5: ==132808== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55807e6649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558084cc9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558084cac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558084cac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55807e66ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55807e5cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55807e5c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55807e65cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55808162bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55808162bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55808162bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55808162bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55808162bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55808162bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55808162bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55808162bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55808162bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55808162bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5580838c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5580805edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5580805f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580803a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580803a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580803a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580803a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580803a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580803a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558084caeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558084cb7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558084c9f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558084cca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc8136b3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55807e5c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0x20,0x3f,0xe2,0x80,0x8d,0xf0,0x9f,0x84,0x8c,0xf0,0x9f,0x84,0x8c,0xf0,0x9f,0x84,0x8c,0xf0,0x9f,0x84,0x8c,0xf0,0x9f,0x84,0x8c,0xf0,0x9f,0x84,0x84,0x41,0xf0,0x9f,0x8c,0x8c,0xf0,0x9f,0x84,0x8c,0xf0,0x9f,0x84,0x86,0xf0,0x9f,0x84,0x8c,0xf0,0x9f,0x84,0x8b,0xf0,0x9f,0x84,0x8c,0xf0,0x9f,0x84,0x8c,0xf0,0x9f,0x84,0x8c,0xf0,0x9f,0x84,0x8c,0xf0,0x9f,0x85,0x8c, Step #5: ? ?\342\200\215\360\237\204\214\360\237\204\214\360\237\204\214\360\237\204\214\360\237\204\214\360\237\204\204A\360\237\214\214\360\237\204\214\360\237\204\206\360\237\204\214\360\237\204\213\360\237\204\214\360\237\204\214\360\237\204\214\360\237\204\214\360\237\205\214 Step #5: artifact_prefix='./'; Test unit written to ./oom-43a9684db5f1570e169fc5d14613fe4bfbe49c7f Step #5: Base64: PyA/4oCN8J+EjPCfhIzwn4SM8J+EjPCfhIzwn4SEQfCfjIzwn4SM8J+EhvCfhIzwn4SL8J+EjPCfhIzwn4SM8J+EjPCfhYw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3688 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3543106491 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d4a21ef810, 0x55d4a23d901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d4a23d9020,0x55d4a42710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/43a9684db5f1570e169fc5d14613fe4bfbe49c7f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4569 processed earlier; will process 6460 files now Step #5: ==132844== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d498ce49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d49f349898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d49f32c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d49f32c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d498cead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d498c4bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d498c46355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d498cdcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d49bcabf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d49bcabf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d49bcabf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d49bcabf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d49bcabf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d49bcabf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d49bcabf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d49bcabf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d49bcabf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d49bcabf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d49df40f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d49ac6db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d49ac78be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d49aa24c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d49aa24c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d49aa25738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d49aa24874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d49aa24874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d49aa24874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d49f32eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d49f337928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d49f31f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d49f34a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd43e670082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d498c44b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x20,0x7b,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0xa,0x6e,0x20,0x7b,0xa,0x70,0x75,0x62,0x3a,0x20,0x22,0x5c,0x27,0x4f,0x27,0x3e,0x5c,0x30,0x3c,0x3f,0x72,0x31,0x31,0x20,0x7f,0x43,0x3f,0x3e,0x3c,0x3f,0x78,0x6d,0x6c,0x6e,0x61,0x6e,0x78,0x39,0x19,0x28,0x3a,0x30,0x3c,0x22,0x7d,0x20,0x7d,0x20,0x7d,0xb,0x7d, Step #5: p {doctype {\012mdecl {\012n {\012pub: \"\\'O'>\\0<?r11 \177C?><?xmlnanx9\031(:0<\"} } }\013} Step #5: artifact_prefix='./'; Test unit written to ./oom-a2068671b87bb212c894ee713e6bba8a1789b3eb Step #5: Base64: cCB7ZG9jdHlwZSB7Cm1kZWNsIHsKbiB7CnB1YjogIlwnTyc+XDA8P3IxMSB/Qz8+PD94bWxuYW54ORkoOjA8In0gfSB9C30= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3689 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3543605770 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56490a971810, 0x56490ab5b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56490ab5b020,0x56490c9f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2068671b87bb212c894ee713e6bba8a1789b3eb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4570 processed earlier; will process 6459 files now Step #5: ==132880== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5649014669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564907acb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564907aae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564907aae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56490146cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649013cdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649013c8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56490145ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56490442df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56490442df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56490442df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56490442df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56490442df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56490442df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56490442df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56490442df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56490442df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56490442df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5649066c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649033efb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649033fabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5649031a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5649031a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5649031a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5649031a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5649031a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5649031a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564907ab0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564907ab9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564907aa1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564907acc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9abdf10082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649013c6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x3a,0x22,0xc4,0x82,0xe0,0xbd,0xbd,0xe0,0xbd,0x82,0xe0,0xbd,0x82,0xe0,0xbd,0x82,0xe0,0xbd,0x82,0xe0,0xbd,0x8e,0xe0,0xbd,0xbd,0x7c,0xe0,0xad,0x82,0xe0,0xbc,0x82,0x54,0x83,0xe0,0xbd,0xbd,0xe0,0xbd,0x82,0xe0,0xbd,0x82,0xe0,0xbd,0x86,0xe0,0xbd,0xbd,0x81,0xe0,0xad,0x82,0xe0,0xbc,0x82,0xc5,0x82,0xe0,0x82,0x5c,0x30,0x82,0xe0,0xbd,0x82,0xe0,0xbd, Step #5: \000\000\000:\"\304\202\340\275\275\340\275\202\340\275\202\340\275\202\340\275\202\340\275\216\340\275\275|\340\255\202\340\274\202T\203\340\275\275\340\275\202\340\275\202\340\275\206\340\275\275\201\340\255\202\340\274\202\305\202\340\202\\0\202\340\275\202\340\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-3c88c6828a81a995ce778cd3baf58fffdf4d616b Step #5: Base64: AAAAOiLEguC9veC9guC9guC9guC9guC9juC9vXzgrYLgvIJUg+C9veC9guC9guC9huC9vYHgrYLgvILFguCCXDCC4L2C4L0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3690 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3544101665 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560474d1f810, 0x560474f0901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560474f09020,0x560476da10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3c88c6828a81a995ce778cd3baf58fffdf4d616b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4571 processed earlier; will process 6458 files now Step #5: ==132916== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56046b8149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560471e79898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560471e5c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560471e5c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56046b81ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56046b77bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56046b776355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56046b80cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56046e7dbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56046e7dbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56046e7dbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56046e7dbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56046e7dbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56046e7dbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56046e7dbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56046e7dbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56046e7dbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56046e7dbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560470a70f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56046d79db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56046d7a8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56046d554c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56046d554c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56046d555738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56046d554874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56046d554874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56046d554874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560471e5eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560471e67928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560471e4f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560471e7a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a90e58082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56046b774b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x0,0x3a,0x64,0x18,0x42,0x4d,0x50,0x49,0x43,0x0,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x0,0x7,0x3a,0x64,0x0,0x1b,0x4d,0x50,0x49,0x43,0x0,0x0,0x5, Step #5: ID3\002\000:d\030BMPIC\000;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;\000\007:d\000\033MPIC\000\000\005 Step #5: artifact_prefix='./'; Test unit written to ./oom-d493bfd26fb7027f6988fcc107bc7ca3c22e07b5 Step #5: Base64: SUQzAgA6ZBhCTVBJQwA7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OwAHOmQAG01QSUMAAAU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3691 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3544597998 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5594400ba810, 0x5594402a401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5594402a4020,0x55944213c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d493bfd26fb7027f6988fcc107bc7ca3c22e07b5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4572 processed earlier; will process 6457 files now Step #5: ==132952== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559436baf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55943d214898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55943d1f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55943d1f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559436bb5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559436b16b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559436b11355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559436ba7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559439b76f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559439b76f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559439b76f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559439b76f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559439b76f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559439b76f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559439b76f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559439b76f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559439b76f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559439b76f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55943be0bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559438b38b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559438b43be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5594388efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5594388efc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5594388f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5594388ef874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5594388ef874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5594388ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55943d1f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55943d202928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55943d1ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55943d215112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0647f84082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559436b0fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x0,0x5d,0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x24,0x5b, Step #5: $::::::::::::::::::::::::::::::::::::::::::::::::::::::::\000]/\000\000\000\000\000\000\000\000\001$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-61262cab33eca4cfa9cbca25e3e51c51fe700f23 Step #5: Base64: JDo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6AF0vAAAAAAAAAAABJFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3692 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3545095928 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5560e7f92810, 0x5560e817c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5560e817c020,0x5560ea0140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/61262cab33eca4cfa9cbca25e3e51c51fe700f23' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4573 processed earlier; will process 6456 files now Step #5: ==132988== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5560dea879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5560e50ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5560e50cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5560e50cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5560dea8dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5560de9eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5560de9e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5560dea7fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5560e1a4ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5560e1a4ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5560e1a4ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5560e1a4ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5560e1a4ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5560e1a4ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5560e1a4ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5560e1a4ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5560e1a4ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5560e1a4ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5560e3ce3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5560e0a10b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5560e0a1bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5560e07c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5560e07c7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5560e07c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5560e07c7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5560e07c7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5560e07c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5560e50d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5560e50da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5560e50c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5560e50ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fced4df8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5560de9e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x58,0xd,0x44,0x45,0x46,0x41,0x55,0x4c,0x54,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x53,0x45,0x4c,0x45,0x43,0x54,0x28,0x49,0x4e,0x54,0x45,0x52,0x76,0x54,0x28,0x49,0x4e,0x54,0x45,0x52,0x76,0x41,0x4c,0x27,0x2d,0x31,0x59,0x2,0x0,0x0,0x0,0x0,0x1f,0x5e,0x0,0x0,0x5e,0x0,0x0,0xe2,0x81,0x9f,0x0,0x0,0x4e,0x54,0x45,0x52,0x41,0x2e,0x27,0x76,0x26,0xa, Step #5: \012X\015DEFAULT(((((((SELECT(INTERvT(INTERvAL'-1Y\002\000\000\000\000\037^\000\000^\000\000\342\201\237\000\000NTERA.'v&\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-fff91bc0e58bd476cd2b5f62c97a7c267d767364 Step #5: Base64: ClgNREVGQVVMVCgoKCgoKChTRUxFQ1QoSU5URVJ2VChJTlRFUnZBTCctMVkCAAAAAB9eAABeAADigZ8AAE5URVJBLid2Jgo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3693 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3545593465 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a060343810, 0x55a06052d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a06052d020,0x55a0623c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fff91bc0e58bd476cd2b5f62c97a7c267d767364' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4574 processed earlier; will process 6455 files now Step #5: #1 pulse cov: 3649 ft: 3650 exec/s: 0 rss: 174Mb Step #5: ==133024== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a056e389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a05d49d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a05d4805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a05d4804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a056e3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a056d9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a056d9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a056e30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a059dfff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a059dfff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a059dfff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a059dfff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a059dfff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a059dfff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a059dfff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a059dfff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a059dfff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a059dfff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a05c094f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a058dc1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a058dccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a058b78c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a058b78c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a058b79738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a058b78874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a058b78874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a058b78874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a05d482abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a05d48b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a05d473699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a05d49e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f70dfb6e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a056d98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x23,0x22,0x5d,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x5c,0x50,0x22, Step #5: [#\"]\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\\P\" Step #5: artifact_prefix='./'; Test unit written to ./oom-18dc000ca798f4d4fff401273ec13111f5f18e4e Step #5: Base64: WyMiXVxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUFxQXFBcUCI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3694 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3546137503 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555f5aff9810, 0x555f5b1e301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555f5b1e3020,0x555f5d07b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/18dc000ca798f4d4fff401273ec13111f5f18e4e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4576 processed earlier; will process 6453 files now Step #5: ==133060== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555f51aee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555f58153898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555f581365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555f581364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555f51af4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555f51a55b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555f51a50355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555f51ae6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555f54ab5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555f54ab5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555f54ab5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555f54ab5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555f54ab5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555f54ab5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555f54ab5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555f54ab5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555f54ab5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555f54ab5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555f56d4af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555f53a77b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555f53a82be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555f5382ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555f5382ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555f5382f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555f5382e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555f5382e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555f5382e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555f58138abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555f58141928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555f58129699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555f58154112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feb8bd9a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555f51a4eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0xbd,0x79,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x6e,0x0,0x0,0x0,0x0,0x1,0x6e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x29,0x0,0x0,0x0,0x65,0x0,0x4a,0x4a,0x4a,0x4a,0x4a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xcb,0xbb, Step #5: \302\275y\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001n\000\000\000\000\001n\000\000\000\000\000\000\000\001)\000\000\000e\000JJJJJ\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\313\273 Step #5: artifact_prefix='./'; Test unit written to ./oom-ed8cd0c92880f7dced962635fe86537b202e78b6 Step #5: Base64: wr15AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABbgAAAAABbgAAAAAAAAABKQAAAGUASkpKSkoAAAAAAAAAAAAAAAAAAAAAy7s= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3695 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3546642707 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5583ef195810, 0x5583ef37f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5583ef37f020,0x5583f12170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ed8cd0c92880f7dced962635fe86537b202e78b6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4577 processed earlier; will process 6452 files now Step #5: ==133096== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5583e5c8a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5583ec2ef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583ec2d25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583ec2d24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5583e5c90d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5583e5bf1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5583e5bec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5583e5c82c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5583e8c51f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5583e8c51f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5583e8c51f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5583e8c51f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5583e8c51f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5583e8c51f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5583e8c51f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5583e8c51f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5583e8c51f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5583e8c51f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5583eaee6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5583e7c13b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5583e7c1ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5583e79cac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5583e79cac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5583e79cb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5583e79ca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5583e79ca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5583e79ca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5583ec2d4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5583ec2dd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5583ec2c5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5583ec2f0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f439f63c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5583e5beab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x45,0x62,0x43,0xa,0x41,0x7e,0x8,0x62,0xa,0x8,0x1a,0x6,0xa,0x1,0x35,0x1,0x4,0x3,0x45,0x3e,0x1,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0x88,0x0,0x0,0xe,0x36,0x1,0x0,0x0,0x0,0x2a,0x0,0x0,0x29,0x0,0x1, Step #5: \012EbC\012A~\010b\012\010\032\006\012\0015\001\004\003E>\001\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\210\000\000\0166\001\000\000\000*\000\000)\000\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-112ee1d74ca429a2c933aea4e77fb19512f71bde Step #5: Base64: CkViQwpBfghiCggaBgoBNQEEA0U+AdawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rCIAAAONgEAAAAqAAApAAE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3696 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3547141023 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9a479d810, 0x55a9a498701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a9a4987020,0x55a9a681f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/112ee1d74ca429a2c933aea4e77fb19512f71bde' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4578 processed earlier; will process 6451 files now Step #5: ==133132== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a99b2929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a9a18f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9a18da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9a18da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a99b298d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a99b1f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a99b1f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a99b28ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a99e259f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a99e259f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a99e259f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a99e259f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a99e259f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a99e259f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a99e259f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a99e259f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a99e259f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a99e259f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a9a04eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a99d21bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a99d226be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a99cfd2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a99cfd2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a99cfd3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a99cfd2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a99cfd2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a99cfd2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a9a18dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a9a18e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a9a18cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a9a18f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f41d155f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a99b1f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x1a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x0,0x0,0x1,0x24,0x5b, Step #5: $:::::::::::\032::::::::::::::::::::::::::::::::::::::::::::::::::::::\000\000\001$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-3f4ba0e1a764c5ea8ed3d8149cb5f0c34eda0819 Step #5: Base64: JDo6Ojo6Ojo6Ojo6Gjo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6OgAAASRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3697 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3547636661 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556778b78810, 0x556778d6201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556778d62020,0x55677abfa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3f4ba0e1a764c5ea8ed3d8149cb5f0c34eda0819' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4579 processed earlier; will process 6450 files now Step #5: ==133168== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55676f66d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556775cd2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556775cb55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556775cb54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55676f673d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55676f5d4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55676f5cf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55676f665c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556772634f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556772634f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556772634f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556772634f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556772634f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556772634f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556772634f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556772634f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556772634f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556772634f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5567748c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5567715f6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556771601be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5567713adc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5567713adc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5567713ae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5567713ad874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5567713ad874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5567713ad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556775cb7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556775cc0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556775ca8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556775cd3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5bd08b7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55676f5cdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x5b,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x5b,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x3c,0x3c,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x5b,0xa,0x30,0x2e,0x20,0x5b,0x30,0x2e,0x20,0x2e,0x30,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0x5b,0xa,0x30,0x2e,0x20,0x5b,0x30,0x2e,0x29,0x2e,0x30,0x20,0x2e,0x31,0x20,0x30,0x2e,0x20, Step #5: trailer[\012trailer[\012trailer<<\012trailer[\0120. [0. .0\012trailer[\0120. [0.).0 .1 0. Step #5: artifact_prefix='./'; Test unit written to ./oom-57d87ee8f08d117b96836ebf3ec4bac017ad3943 Step #5: Base64: dHJhaWxlclsKdHJhaWxlclsKdHJhaWxlcjw8CnRyYWlsZXJbCjAuIFswLiAuMAp0cmFpbGVyWwowLiBbMC4pLjAgLjEgMC4g Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3698 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3548140303 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f9a1d8f810, 0x55f9a1f7901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f9a1f79020,0x55f9a3e110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/57d87ee8f08d117b96836ebf3ec4bac017ad3943' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4580 processed earlier; will process 6449 files now Step #5: ==133204== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f9988849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f99eee9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f99eecc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f99eecc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f99888ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f9987ebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f9987e6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f99887cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f99b84bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f99b84bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f99b84bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f99b84bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f99b84bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f99b84bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f99b84bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f99b84bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f99b84bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f99b84bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f99dae0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f99a80db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f99a818be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f99a5c4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f99a5c4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f99a5c5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f99a5c4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f99a5c4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f99a5c4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f99eeceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f99eed7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f99eebf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f99eeea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f76c8346082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f9987e4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xef,0xb7,0xba,0xcc,0x94,0xcc,0x87,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x88,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x98,0xdc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x9a,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x98,0xcc,0xbb,0xcd,0x98,0xcc,0xba, Step #5: ws:\357\267\272\314\224\314\207\314\273\315\230\314\273\315\230\314\273\315\210\314\273\315\230\314\273\315\230\314\273\315\230\314\273\315\230\334\273\315\230\314\273\315\230\314\273\315\232\314\273\315\230\314\273\315\230\314\273\315\230\314\273\315\230\314\273\315\230\314\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-a50e61c42da461f4669eee5d77545319bd766bcb Step #5: Base64: d3M677e6zJTMh8y7zZjMu82YzLvNiMy7zZjMu82YzLvNmMy7zZjcu82YzLvNmMy7zZrMu82YzLvNmMy7zZjMu82YzLvNmMy6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3699 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3548643171 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564304522810, 0x56430470c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56430470c020,0x5643065a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a50e61c42da461f4669eee5d77545319bd766bcb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4581 processed earlier; will process 6448 files now Step #5: ==133240== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5642fb0179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56430167c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56430165f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56430165f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642fb01dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5642faf7eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5642faf79355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5642fb00fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5642fdfdef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5642fdfdef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5642fdfdef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5642fdfdef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5642fdfdef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5642fdfdef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5642fdfdef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5642fdfdef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5642fdfdef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5642fdfdef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564300273f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5642fcfa0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5642fcfabbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5642fcd57c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5642fcd57c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5642fcd58738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5642fcd57874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5642fcd57874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5642fcd57874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564301661abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56430166a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564301652699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56430167d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb07ed96082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5642faf77b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x29,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x58,0x58, Step #5: $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$)$$$$$$$$$$$$$$$$$$$$$$$$$$$mmmmmmmmmmmXX Step #5: artifact_prefix='./'; Test unit written to ./oom-051297a751369893b3d636bcd19538425704547d Step #5: Base64: JCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCkkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCRtbW1tbW1tbW1tbVhY Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3700 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3549154452 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5556c02e9810, 0x5556c04d301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5556c04d3020,0x5556c236b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/051297a751369893b3d636bcd19538425704547d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4582 processed earlier; will process 6447 files now Step #5: ==133276== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5556b6dde9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5556bd443898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556bd4265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556bd4264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5556b6de4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5556b6d45b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5556b6d40355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5556b6dd6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5556b9da5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5556b9da5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5556b9da5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5556b9da5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5556b9da5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5556b9da5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5556b9da5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5556b9da5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5556b9da5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5556b9da5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5556bc03af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5556b8d67b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5556b8d72be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5556b8b1ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5556b8b1ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5556b8b1f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5556b8b1e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5556b8b1e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5556b8b1e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5556bd428abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5556bd431928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5556bd419699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5556bd444112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f82c2baa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5556b6d3eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x30,0x30,0x30,0xe0,0xa1,0x9c,0xe0,0xb7,0x9a,0xe0,0xad,0x9d,0xe1,0xa5,0x9d,0xe0,0xa5,0x9d,0xe0,0xb7,0x9d,0xe0,0xa7,0x9c,0xe0,0xb7,0x9a,0xe0,0xad,0x9d,0xe1,0xa5,0x9d,0xe0,0xa5,0x9d,0xe0,0xb7,0x9d,0xe0,0xb7,0xae,0xe0,0xb7,0x9d,0x2d,0x36,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x5a,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text>000\340\241\234\340\267\232\340\255\235\341\245\235\340\245\235\340\267\235\340\247\234\340\267\232\340\255\235\341\245\235\340\245\235\340\267\235\340\267\256\340\267\235-6</text>Z</svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-96b5174ec922e311bda6cf50a580da6afdda93bc Step #5: Base64: PHN2Zz48dGV4dD4wMDDgoZzgt5rgrZ3hpZ3gpZ3gt53gp5zgt5rgrZ3hpZ3gpZ3gt53gt67gt50tNjwvdGV4dD5aPC9zdmc+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3701 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3549651083 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c65bae810, 0x564c65d9801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c65d98020,0x564c67c300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/96b5174ec922e311bda6cf50a580da6afdda93bc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4583 processed earlier; will process 6446 files now Step #5: ==133312== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564c5c6a39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c62d08898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c62ceb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c62ceb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c5c6a9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c5c60ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c5c605355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c5c69bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c5f66af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c5f66af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c5f66af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c5f66af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c5f66af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c5f66af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c5f66af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c5f66af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c5f66af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c5f66af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c618fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c5e62cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c5e637be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c5e3e3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c5e3e3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c5e3e4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c5e3e3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c5e3e3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c5e3e3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c62cedabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c62cf6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c62cde699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c62d09112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa2a579d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c5c603b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x84,0x81,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x92,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb5,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x90,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x81, Step #5: \341\204\201\341\205\260\341\207\201\341\204\221\341\205\260\341\207\201\341\204\222\341\205\260\341\207\201\341\204\221\341\205\260\341\207\201\341\204\221\341\205\265\341\207\201\341\204\221\341\205\260\341\207\201\341\204\220\341\205\260\341\207\201\341\204\221\341\205\260\341\207\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-5b87aea913c9821ba39fb7d8519e3b8c03a370fa Step #5: Base64: 4YSB4YWw4YeB4YSR4YWw4YeB4YSS4YWw4YeB4YSR4YWw4YeB4YSR4YW14YeB4YSR4YWw4YeB4YSQ4YWw4YeB4YSR4YWw4YeB Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3702 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3550152957 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5562b9ed7810, 0x5562ba0c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5562ba0c1020,0x5562bbf590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5b87aea913c9821ba39fb7d8519e3b8c03a370fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4584 processed earlier; will process 6445 files now Step #5: #1 pulse cov: 14203 ft: 14204 exec/s: 0 rss: 194Mb Step #5: ==133348== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5562b09cc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5562b7031898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5562b70145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5562b70144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5562b09d2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5562b0933b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5562b092e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5562b09c4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5562b3993f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5562b3993f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5562b3993f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5562b3993f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5562b3993f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5562b3993f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5562b3993f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5562b3993f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5562b3993f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5562b3993f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5562b5c28f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5562b2955b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5562b2960be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5562b270cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5562b270cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5562b270d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5562b270c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5562b270c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5562b270c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5562b7016abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5562b701f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5562b7007699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5562b7032112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb70e913082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5562b092cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa, Step #5: ===================================\012===================================\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-8c65f1b6e65adaf814a9b7bedc8a44608a2caf28 Step #5: Base64: PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3703 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3550726784 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564ee24a1810, 0x564ee268b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564ee268b020,0x564ee45230e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c65f1b6e65adaf814a9b7bedc8a44608a2caf28' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4586 processed earlier; will process 6443 files now Step #5: ==133384== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564ed8f969c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564edf5fb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564edf5de5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564edf5de4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ed8f9cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ed8efdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ed8ef8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ed8f8ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564edbf5df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564edbf5df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564edbf5df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564edbf5df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564edbf5df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564edbf5df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564edbf5df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564edbf5df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564edbf5df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564edbf5df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564ede1f2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564edaf1fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564edaf2abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564edacd6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564edacd6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564edacd7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564edacd6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564edacd6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564edacd6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564edf5e0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564edf5e9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564edf5d1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564edf5fc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f66ccaae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ed8ef6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x24,0x30,0x3a,0x7b,0x24,0x30,0x3a,0x7b,0x24,0x30,0x3a,0x7b,0x24,0x3a,0x7b,0x24,0x30,0x3a,0x7b,0x24,0x30,0x30,0x3a,0x7b,0x24,0x30,0x30,0x3a,0x7b,0x24,0x30,0x3a,0x7b,0x24,0x30,0x3a,0x7b,0x24,0x30,0x3a,0x7b,0x24,0x30,0x3a,0x7b,0x24,0x30,0x3a,0x7b,0x24,0x30,0x30,0x3a,0x7b,0x24,0x30,0x3a,0x7b,0x24,0x30,0x3a,0x7b,0x24,0x30,0x3a,0x7b,0x24,0x30,0x3a,0x7b,0x24, Step #5: {$0:{$0:{$0:{$:{$0:{$00:{$00:{$0:{$0:{$0:{$0:{$0:{$00:{$0:{$0:{$0:{$0:{$ Step #5: artifact_prefix='./'; Test unit written to ./oom-f98513fd47dc43e3528075858773025b6eae6693 Step #5: Base64: eyQwOnskMDp7JDA6eyQ6eyQwOnskMDA6eyQwMDp7JDA6eyQwOnskMDp7JDA6eyQwOnskMDA6eyQwOnskMDp7JDA6eyQwOnsk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3704 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3551231272 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf79427810, 0x55bf7961101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf79611020,0x55bf7b4a90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f98513fd47dc43e3528075858773025b6eae6693' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4587 processed earlier; will process 6442 files now Step #5: #1 pulse cov: 3684 ft: 3685 exec/s: 0 rss: 175Mb Step #5: ==133420== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bf6ff1c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf76581898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf765645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf765644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf6ff22d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf6fe83b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf6fe7e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf6ff14c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf72ee3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf72ee3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf72ee3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf72ee3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf72ee3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf72ee3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf72ee3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf72ee3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf72ee3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf72ee3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf75178f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf71ea5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf71eb0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf71c5cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf71c5cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf71c5d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf71c5c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf71c5c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf71c5c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf76566abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf7656f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf76557699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf76582112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7b45825082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf6fe7cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xda,0xae,0xd6,0xa6,0xc4,0x86,0xd6,0x8a,0xc4,0x9a,0xd6,0xae,0xd6,0x87,0xc5,0x9b,0xd6,0x86,0xda,0xb6,0xd6,0xae,0xda,0xae,0xde,0xae,0xda,0xae,0xde,0xae,0xd6,0x86,0xc4,0x86,0xd6,0x82,0xc4,0x9a,0xd6,0x86,0xda,0xa6,0xcd,0xae,0xda,0xae,0xdf,0xae,0xde,0xae,0xd6,0x86,0xd6,0x84,0xd9,0xb5,0xd8,0xae,0xde,0xae,0xdd,0xae,0xd6,0x86,0xd6,0x84,0xda,0xb6,0xd6,0xae,0xda,0xbb, Step #5: \332\256\326\246\304\206\326\212\304\232\326\256\326\207\305\233\326\206\332\266\326\256\332\256\336\256\332\256\336\256\326\206\304\206\326\202\304\232\326\206\332\246\315\256\332\256\337\256\336\256\326\206\326\204\331\265\330\256\336\256\335\256\326\206\326\204\332\266\326\256\332\273 Step #5: artifact_prefix='./'; Test unit written to ./oom-6822418d7c63d13e4be1ea8301ff8d206c9eef5c Step #5: Base64: 2q7WpsSG1orEmtau1ofFm9aG2rbWrtqu3q7art6u1obEhtaCxJrWhtqmza7art+u3q7WhtaE2bXYrt6u3a7WhtaE2rbWrtq7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3705 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3551773606 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5612a387c810, 0x5612a3a6601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5612a3a66020,0x5612a58fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6822418d7c63d13e4be1ea8301ff8d206c9eef5c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4589 processed earlier; will process 6440 files now Step #5: ==133456== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56129a3719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5612a09d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5612a09b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5612a09b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56129a377d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56129a2d8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56129a2d3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56129a369c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56129d338f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56129d338f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56129d338f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56129d338f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56129d338f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56129d338f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56129d338f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56129d338f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56129d338f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56129d338f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56129f5cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56129c2fab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56129c305be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56129c0b1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56129c0b1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56129c0b2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56129c0b1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56129c0b1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56129c0b1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5612a09bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5612a09c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5612a09ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5612a09d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd8e2769082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56129a2d1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x8,0x0,0x7,0x2e,0x2b,0x42,0xdb,0xbe,0x75,0xdb,0xbe,0x2b,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x0,0x0,0x31,0x38,0x34,0x34,0x36,0x37,0x34,0x34,0x30,0x37,0x33,0x37,0x30,0x39,0x35,0x35,0x31,0x36,0x31,0x35,0x0,0x0,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x2b,0x2b,0x24,0x6e,0x24,0x3,0x3,0x52, Step #5: - \010\000\007.+B\333\276u\333\276+99999999999\000\00018446744073709551615\000\000999999999999999++$n$\003\003R Step #5: artifact_prefix='./'; Test unit written to ./oom-3479a2c13a3fdb0448bdeef5f7a0435f72ee8378 Step #5: Base64: LSAIAAcuK0LbvnXbvis5OTk5OTk5OTk5OQAAMTg0NDY3NDQwNzM3MDk1NTE2MTUAADk5OTk5OTk5OTk5OTk5OSsrJG4kAwNS Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3706 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3552275751 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e1c14cb810, 0x55e1c16b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e1c16b5020,0x55e1c354d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3479a2c13a3fdb0448bdeef5f7a0435f72ee8378' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4590 processed earlier; will process 6439 files now Step #5: #1 pulse cov: 3569 ft: 3570 exec/s: 0 rss: 174Mb Step #5: ==133492== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e1b7fc09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e1be625898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e1be6085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e1be6084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e1b7fc6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e1b7f27b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e1b7f22355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e1b7fb8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e1baf87f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e1baf87f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e1baf87f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e1baf87f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e1baf87f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e1baf87f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e1baf87f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e1baf87f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e1baf87f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e1baf87f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e1bd21cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e1b9f49b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e1b9f54be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e1b9d00c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e1b9d00c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e1b9d01738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e1b9d00874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e1b9d00874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e1b9d00874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e1be60aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e1be613928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e1be5fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e1be626112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5d0b97d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e1b7f20b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x7f,0x8,0x0,0x1,0x0,0x2e,0x2e,0x2e,0x2e,0x5b,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0xf3,0xa0,0x81,0xa9,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2d,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x22,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x85,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x0, Step #5: = \177\010\000\001\000....[......\363\240\201\251...............-......\"............\205\000\000\000\000\000\000\000......\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d7293e0c8635adba4e9f742dd676dcc30eff4376 Step #5: Base64: PSB/CAABAC4uLi5bLi4uLi4u86CBqS4uLi4uLi4uLi4uLi4uLi0uLi4uLi4iLi4uLi4uLi4uLi4uhQAAAAAAAAAuLi4uLi4A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3707 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3552817729 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571b2bc2810, 0x5571b2dac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571b2dac020,0x5571b4c440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d7293e0c8635adba4e9f742dd676dcc30eff4376' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4592 processed earlier; will process 6437 files now Step #5: #1 pulse cov: 3921 ft: 3922 exec/s: 0 rss: 175Mb Step #5: ==133528== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571a96b79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571afd1c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571afcff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571afcff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571a96bdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571a961eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571a9619355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571a96afc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571ac67ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571ac67ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571ac67ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571ac67ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571ac67ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571ac67ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571ac67ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571ac67ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571ac67ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571ac67ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571ae913f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571ab640b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571ab64bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571ab3f7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571ab3f7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571ab3f8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571ab3f7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571ab3f7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571ab3f7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571afd01abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571afd0a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571afcf2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571afd1d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f18fa1b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571a9617b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x69,0x67,0x72,0x41,0x50,0x68,0x7b,0x75,0x3b,0x75,0x3b,0x68,0x3b,0x68,0x3b,0x31,0x3b,0x68,0x3b,0x6a,0x3b,0x75,0x3b,0x75,0x3b,0x68,0x3b,0x68,0x3b,0x31,0x3b,0x68,0x3b,0x6a,0x3b,0x75,0x3b,0x30,0x3b,0x68,0x3b,0x6a,0x3b,0x68,0x3b,0x31,0x3b,0x68,0x3b,0x68,0x3b,0x31,0x3b,0x68,0x3b,0x31,0x3b,0x68,0x3b,0x6a,0x3b,0x75,0x3b,0x30,0x3b,0x68,0x3b,0x6a,0x3b,0x68,0x3b, Step #5: DigrAPh{u;u;h;h;1;h;j;u;u;h;h;1;h;j;u;0;h;j;h;1;h;h;1;h;1;h;j;u;0;h;j;h; Step #5: artifact_prefix='./'; Test unit written to ./oom-d10693030eabf60cecb1429344a109be35f9398a Step #5: Base64: RGlnckFQaHt1O3U7aDtoOzE7aDtqO3U7dTtoO2g7MTtoO2o7dTswO2g7ajtoOzE7aDtoOzE7aDsxO2g7ajt1OzA7aDtqO2g7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3708 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3553359310 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55da1d7ea810, 0x55da1d9d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55da1d9d4020,0x55da1f86c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d10693030eabf60cecb1429344a109be35f9398a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4594 processed earlier; will process 6435 files now Step #5: ==133564== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55da142df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55da1a944898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55da1a9275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55da1a9274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55da142e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55da14246b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55da14241355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55da142d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55da172a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55da172a6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55da172a6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55da172a6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55da172a6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55da172a6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55da172a6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55da172a6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55da172a6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55da172a6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55da1953bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55da16268b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55da16273be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55da1601fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55da1601fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55da16020738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55da1601f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55da1601f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55da1601f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55da1a929abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55da1a932928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55da1a91a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55da1a945112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0859a97082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55da1423fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x73,0x65,0x72,0x69,0x66,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012= serif\012=\012=\012=+=\012=\012=\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-3f8182dedbbfbf4c1cd4d764ed52586d7bf603bd Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0gc2VyaWYKPQo9Cj0rPQo9Cj0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3709 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3553864180 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b25df7a810, 0x55b25e16401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b25e164020,0x55b25fffc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3f8182dedbbfbf4c1cd4d764ed52586d7bf603bd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4595 processed earlier; will process 6434 files now Step #5: #1 pulse cov: 3563 ft: 3564 exec/s: 0 rss: 174Mb Step #5: ==133600== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b254a6f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b25b0d4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b25b0b75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b25b0b74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b254a75d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b2549d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b2549d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b254a67c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b257a36f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b257a36f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b257a36f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b257a36f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b257a36f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b257a36f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b257a36f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b257a36f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b257a36f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b257a36f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b259ccbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b2569f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b256a03be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b2567afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b2567afc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b2567b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b2567af874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b2567af874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b2567af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b25b0b9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b25b0c2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b25b0aa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b25b0d5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f694e346082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b2549cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x53,0x3a,0xdd,0xb8,0xd9,0xb8,0x29,0x2b,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x29,0xd9,0xb8, Step #5: \016wS:\335\270\331\270)+}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}})\331\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-bdb32225c3fc044ba35cf83ccfae85161816057d Step #5: Base64: DndTOt242bgpK319fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19Kdm4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3710 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3554405287 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e1a2621810, 0x55e1a280b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e1a280b020,0x55e1a46a30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bdb32225c3fc044ba35cf83ccfae85161816057d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4597 processed earlier; will process 6432 files now Step #5: #1 pulse cov: 3764 ft: 3765 exec/s: 0 rss: 175Mb Step #5: ==133636== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e1991169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e19f77b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e19f75e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e19f75e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e19911cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e19907db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e199078355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e19910ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e19c0ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e19c0ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e19c0ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e19c0ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e19c0ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e19c0ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e19c0ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e19c0ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e19c0ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e19c0ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e19e372f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e19b09fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e19b0aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e19ae56c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e19ae56c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e19ae57738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e19ae56874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e19ae56874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e19ae56874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e19f760abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e19f769928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e19f751699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e19f77c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff32d369082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e199076b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa, Step #5: =====================\012=================================================\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-df6ffe457649398f9ff633154b0924fa4c2a5630 Step #5: Base64: PT09PT09PT09PT09PT09PT09PT09Cj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3711 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3554933561 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e22eb48810, 0x55e22ed3201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e22ed32020,0x55e230bca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/df6ffe457649398f9ff633154b0924fa4c2a5630' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4599 processed earlier; will process 6430 files now Step #5: #1 pulse cov: 11300 ft: 11301 exec/s: 0 rss: 193Mb Step #5: #2 pulse cov: 11979 ft: 12761 exec/s: 0 rss: 195Mb Step #5: ==133672== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e22563d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e22bca2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e22bc855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e22bc854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e225643d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e2255a4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e22559f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e225635c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e228604f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e228604f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e228604f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e228604f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e228604f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e228604f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e228604f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e228604f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e228604f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e228604f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e22a899f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e2275c6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e2275d1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e22737dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e22737dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e22737e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e22737d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e22737d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e22737d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e22bc87abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e22bc90928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e22bc78699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e22bca3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffb20399082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e22559db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x3a,0x3f,0xf3,0xbe,0xb2,0xbc,0xf2,0xbd,0xb2,0xbc,0xf3,0xbe,0xb2,0xbc,0xf3,0xbd,0xb2,0xbc,0xf3,0xbe,0xb2,0xbc,0xf3,0xbe,0xb2,0xbc,0xcd,0x85,0xf3,0xbe,0xb2,0xbc,0xf3,0xbd,0xb2,0xbc,0xf3,0xbe,0xb2,0xbc,0xf3,0xbe,0xb2,0xbc,0xf3,0xa4,0x80,0xb6,0xf3,0xbe,0xb2,0xbc,0x29,0xf3,0xbe,0xb2,0xbc,0xf3,0xbe,0xb2,0xbc,0xf3,0xbe,0xb2,0xbc,0x3c,0xf3,0xa0,0x80,0xb9,0x26, Step #5: A:?\363\276\262\274\362\275\262\274\363\276\262\274\363\275\262\274\363\276\262\274\363\276\262\274\315\205\363\276\262\274\363\275\262\274\363\276\262\274\363\276\262\274\363\244\200\266\363\276\262\274)\363\276\262\274\363\276\262\274\363\276\262\274<\363\240\200\271& Step #5: artifact_prefix='./'; Test unit written to ./oom-a92298c4e77b19eba0a107ec638006ae9682d35e Step #5: Base64: QTo/876yvPK9srzzvrK8872yvPO+srzzvrK8zYXzvrK8872yvPO+srzzvrK886SAtvO+srwp876yvPO+srzzvrK8PPOggLkm Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3712 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3555564624 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ebe10d0810, 0x55ebe12ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ebe12ba020,0x55ebe31520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a92298c4e77b19eba0a107ec638006ae9682d35e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4602 processed earlier; will process 6427 files now Step #5: ==133708== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ebd7bc59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ebde22a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ebde20d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ebde20d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ebd7bcbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ebd7b2cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ebd7b27355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ebd7bbdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ebdab8cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ebdab8cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ebdab8cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ebdab8cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ebdab8cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ebdab8cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ebdab8cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ebdab8cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ebdab8cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ebdab8cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ebdce21f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ebd9b4eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ebd9b59be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ebd9905c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ebd9905c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ebd9906738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ebd9905874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ebd9905874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ebd9905874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ebde20fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ebde218928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ebde200699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ebde22b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f669e791082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ebd7b25b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x54,0x32,0x56,0x69,0x65,0x50,0x69,0x6d,0x55,0x61,0x50,0x49,0x73,0x54,0x4c,0x76,0x2f,0x49,0x6c,0x4c,0x64,0x67,0x4f,0x78,0x5a,0x69,0x45,0x32,0x49,0x35,0x58,0x52,0x56,0x55,0x56,0x65,0x6e,0x6c,0x38,0x36,0x6f,0x43,0x41,0xa,0x61,0x20,0x5c,0x5c, Step #5: onion-key\012ntor-onion-key T2ViePimUaPIsTLv/IlLdgOxZiE2I5XRVUVenl86oCA\012a \\\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-7d88118dfc732986d498f05a40616213ff2faa30 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IFQyVmllUGltVWFQSXNUTHYvSWxMZGdPeFppRTJJNVhSVlVWZW5sODZvQ0EKYSBcXA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3713 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3556063369 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c63cfe6810, 0x55c63d1d001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c63d1d0020,0x55c63f0680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d88118dfc732986d498f05a40616213ff2faa30' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4603 processed earlier; will process 6426 files now Step #5: #1 pulse cov: 4006 ft: 4007 exec/s: 0 rss: 172Mb Step #5: #2 pulse cov: 11390 ft: 12207 exec/s: 0 rss: 192Mb Step #5: ==133744== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c633adb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c63a140898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c63a1235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c63a1234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c633ae1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c633a42b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c633a3d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c633ad3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c636aa2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c636aa2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c636aa2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c636aa2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c636aa2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c636aa2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c636aa2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c636aa2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c636aa2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c636aa2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c638d37f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c635a64b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c635a6fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c63581bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c63581bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c63581c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c63581b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c63581b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c63581b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c63a125abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c63a12e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c63a116699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c63a141112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f45afd09082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c633a3bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0,0x41,0x60,0x60,0x0, Step #5: \014A``\000A``\000A``\000A``\000A``\000A``\000A``\000A``\000A``\000A``\000A``\000A``\000A``\000A``\000A``\000A``\000A``\000A``\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c5aa068b0c1f9e80984845a1e4baa8e155bc1be9 Step #5: Base64: DEFgYABBYGAAQWBgAEFgYABBYGAAQWBgAEFgYABBYGAAQWBgAEFgYABBYGAAQWBgAEFgYABBYGAAQWBgAEFgYABBYGAAQWBgAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3714 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3556834990 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555c8e30b810, 0x555c8e4f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555c8e4f5020,0x555c9038d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c5aa068b0c1f9e80984845a1e4baa8e155bc1be9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4607 processed earlier; will process 6422 files now Step #5: ==133780== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555c84e009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555c8b465898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555c8b4485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555c8b4484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555c84e06d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555c84d67b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555c84d62355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555c84df8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555c87dc7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555c87dc7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555c87dc7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555c87dc7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555c87dc7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555c87dc7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555c87dc7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555c87dc7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555c87dc7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555c87dc7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555c8a05cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555c86d89b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555c86d94be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555c86b40c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555c86b40c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555c86b41738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555c86b40874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555c86b40874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555c86b40874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555c8b44aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555c8b453928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555c8b43b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555c8b466112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f18aa813082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555c84d60b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x2e,0x7b,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x38,0xef,0xa3,0xbf,0x39,0x36,0x37,0x36,0x33,0x37,0x7d,0x29,0x7b,0x2d,0x2e,0x7b,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x39,0xef,0xa3,0xbf,0x39,0x36,0x37,0x36,0x33,0x37,0x7d,0x29,0x7b,0x2d,0x31,0x31,0x33,0x30,0x39,0x31,0x36,0x30,0x31,0xf3,0xa0,0x81,0xba,0x32,0x7d,0xe2,0x81,0xa8,0x7b,0x37,0x35,0x7d, Step #5: (.{2147483648\357\243\277967637}){-.{2147483649\357\243\277967637}){-113091601\363\240\201\2722}\342\201\250{75} Step #5: artifact_prefix='./'; Test unit written to ./oom-d96083d960350a6d3c5ff3aba19f1903db3cef0a Step #5: Base64: KC57MjE0NzQ4MzY0OO+jvzk2NzYzN30pey0uezIxNDc0ODM2NDnvo785Njc2Mzd9KXstMTEzMDkxNjAx86CBujJ94oGoezc1fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3715 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3557331128 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f421d29810, 0x55f421f1301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f421f13020,0x55f423dab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d96083d960350a6d3c5ff3aba19f1903db3cef0a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4608 processed earlier; will process 6421 files now Step #5: ==133816== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f41881e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f41ee83898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f41ee665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f41ee664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f418824d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f418785b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f418780355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f418816c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f41b7e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f41b7e5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f41b7e5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f41b7e5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f41b7e5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f41b7e5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f41b7e5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f41b7e5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f41b7e5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f41b7e5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f41da7af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f41a7a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f41a7b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f41a55ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f41a55ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f41a55f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f41a55e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f41a55e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f41a55e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f41ee68abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f41ee71928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f41ee59699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f41ee84112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3eac18c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f41877eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x27,0x3f,0x28,0xcc,0x9d,0x3f,0x28,0xcc,0x9d,0x3f,0x28,0xcc,0x9d,0x0,0x26,0x28,0xcc,0x9d,0x29,0x0,0x7d,0x29,0x7b,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x36,0x7d,0x76,0x3f,0x7d,0x29,0x7b,0x34,0x38,0x33,0x7d, Step #5: ('?(\314\235?(\314\235?(\314\235\000&(\314\235)\000}){340282366920938463463374607431768211456}v?}){483} Step #5: artifact_prefix='./'; Test unit written to ./oom-877a50f8fa460e3f73a074e9500b2402623e8f3e Step #5: Base64: KCc/KMydPyjMnT8ozJ0AJijMnSkAfSl7MzQwMjgyMzY2OTIwOTM4NDYzNDYzMzc0NjA3NDMxNzY4MjExNDU2fXY/fSl7NDgzfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3716 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3557830235 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55651e6ee810, 0x55651e8d801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55651e8d8020,0x5565207700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/877a50f8fa460e3f73a074e9500b2402623e8f3e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4609 processed earlier; will process 6420 files now Step #5: ==133852== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5565151e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55651b848898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55651b82b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55651b82b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5565151e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55651514ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556515145355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5565151dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5565181aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5565181aaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5565181aaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5565181aaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5565181aaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5565181aaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5565181aaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5565181aaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5565181aaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5565181aaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55651a43ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55651716cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556517177be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556516f23c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556516f23c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556516f24738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556516f23874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556516f23874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556516f23874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55651b82dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55651b836928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55651b81e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55651b849112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b01936082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556515143b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x65,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3d,0x22,0x63,0x68,0x61,0x72,0x22,0x0,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0x6f,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0x64,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0x2b,0xe0,0xb9,0x81, Step #5: <?xml encoding=\"char\"\000\340\271\201\340\271\201o\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201d\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201+\340\271\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-e3d37271dc74f5a6f5960f06742e91ade90001c4 Step #5: Base64: PD94bWwgZW5jb2Rpbmc9ImNoYXIiAOC5geC5gW/guYHguYHguYHguYHguYHguYHguYHguYFk4LmB4LmB4LmB4LmB4LmBK+C5gQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3717 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3558336944 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5604861f7810, 0x5604863e101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604863e1020,0x5604882790e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e3d37271dc74f5a6f5960f06742e91ade90001c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4610 processed earlier; will process 6419 files now Step #5: ==133888== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56047ccec9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560483351898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5604833345dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5604833344fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56047ccf2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56047cc53b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56047cc4e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56047cce4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56047fcb3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56047fcb3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56047fcb3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56047fcb3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56047fcb3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56047fcb3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56047fcb3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56047fcb3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56047fcb3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56047fcb3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560481f48f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56047ec75b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56047ec80be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56047ea2cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56047ea2cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56047ea2d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56047ea2c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56047ea2c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56047ea2c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560483336abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56048333f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560483327699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560483352112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3f9004082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56047cc4cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x46,0x76,0x30,0x4d,0x77,0x48,0x65,0x57,0x53,0x63,0x30,0x41,0x61,0x71,0x59,0x31,0x2b,0x6a,0x6d,0x47,0x4c,0x6c,0x43,0x41,0x41,0x42,0x73,0x54,0x2b,0x4c,0x53,0x58,0x45,0x53,0x79,0x56,0x77,0x36,0x32,0x3d,0xff,0xff,0xff,0x7f,0x35,0x35,0x30,0x36, Step #5: onion-key\012ntor-onion-key Fv0MwHeWSc0AaqY1+jmGLlCAABsT+LSXESyVw62=\377\377\377\1775506 Step #5: artifact_prefix='./'; Test unit written to ./oom-166877a81d9ef77c65493d0a9cc2c5b70c377ebc Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IEZ2ME13SGVXU2MwQWFxWTEram1HTGxDQUFCc1QrTFNYRVN5Vnc2Mj3///9/NTUwNg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3718 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3558838809 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f4ee932810, 0x55f4eeb1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f4eeb1c020,0x55f4f09b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/166877a81d9ef77c65493d0a9cc2c5b70c377ebc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4611 processed earlier; will process 6418 files now Step #5: ==133924== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f4e54279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f4eba8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f4eba6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f4eba6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f4e542dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f4e538eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f4e5389355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f4e541fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f4e83eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f4e83eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f4e83eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f4e83eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f4e83eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f4e83eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f4e83eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f4e83eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f4e83eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f4e83eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4ea683f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4e73b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4e73bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f4e7167c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f4e7167c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f4e7168738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f4e7167874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f4e7167874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f4e7167874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f4eba71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f4eba7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f4eba62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f4eba8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f71537082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f4e5387b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x30,0x77,0x48,0x65,0x46,0x4d,0x76,0x57,0x53,0x63,0x6f,0x41,0x61,0x71,0x59,0x30,0x2b,0x6f,0x68,0x47,0x44,0x6c,0x4b,0x41,0x41,0x42,0x73,0x54,0x2b,0x53,0x53,0x58,0x4c,0x49,0x7a,0x56,0x77,0x6a,0x78,0x6f,0x31,0x61,0x2f,0xa,0x61,0x20,0x3a,0x2f, Step #5: onion-key\012ntor-onion-key 0wHeFMvWScoAaqY0+ohGDlKAABsT+SSXLIzVwjxo1a/\012a :/ Step #5: artifact_prefix='./'; Test unit written to ./oom-2fdc5557a39d1a0d65e1521e1ba50db61238f183 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IDB3SGVGTXZXU2NvQWFxWTArb2hHRGxLQUFCc1QrU1NYTEl6VndqeG8xYS8KYSA6Lw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3719 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3559346343 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b535042810, 0x55b53522c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b53522c020,0x55b5370c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2fdc5557a39d1a0d65e1521e1ba50db61238f183' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4612 processed earlier; will process 6417 files now Step #5: ==133960== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b52bb379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b53219c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b53217f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b53217f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b52bb3dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b52ba9eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b52ba99355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b52bb2fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b52eafef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b52eafef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b52eafef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b52eafef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b52eafef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b52eafef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b52eafef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b52eafef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b52eafef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b52eafef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b530d93f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b52dac0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b52dacbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b52d877c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b52d877c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b52d878738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b52d877874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b52d877874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b52d877874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b532181abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b53218a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b532172699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b53219d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd188946082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b52ba97b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x6e,0x61,0x6d,0x65,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x7,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x44,0x33,0x2,0x20,0x0,0x0,0x0,0x1,0x1,0x41,0x1,0x0,0x30,0x54,0x58,0x58,0x0,0x0,0x42,0x3,0x3d,0x54,0x58,0x58,0x3, Step #5: Iname____________________________________\007______D3\002 \000\000\000\001\001A\001\0000TXX\000\000B\003=TXX\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-c14ce37e01e6a8068a026aac5b3b7deab786c496 Step #5: Base64: SW5hbWVfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18HX19fX19fRDMCIAAAAAEBQQEAMFRYWAAAQgM9VFhYAw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3720 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3559857562 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5573c2418810, 0x5573c260201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5573c2602020,0x5573c449a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c14ce37e01e6a8068a026aac5b3b7deab786c496' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4613 processed earlier; will process 6416 files now Step #5: ==133996== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5573b8f0d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5573bf572898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5573bf5555dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5573bf5554fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5573b8f13d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5573b8e74b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5573b8e6f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5573b8f05c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5573bbed4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5573bbed4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5573bbed4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5573bbed4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5573bbed4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5573bbed4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5573bbed4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5573bbed4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5573bbed4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5573bbed4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5573be169f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5573bae96b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5573baea1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5573bac4dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5573bac4dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5573bac4e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5573bac4d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5573bac4d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5573bac4d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5573bf557abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5573bf560928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5573bf548699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5573bf573112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f36caf4a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5573b8e6db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x24,0x75,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0x82,0x0,0x0,0xe2,0x80,0x82,0x0,0x0,0x0,0x0,0x0,0x0,0xf3,0xa0,0x81,0x98,0x0,0x73,0xa,0x20,0x20,0x2b,0x43,0x0,0x0,0x0,0x0,0xe2,0x80,0x82,0x0,0x0,0x0,0x0,0x0,0x0,0xf3,0xa0,0x81,0x98,0x0,0x73,0xa,0x20,0x2f,0x43,0x40,0x0,0x0,0x0,0x0,0xe1,0xa0,0x8e,0x0,0x0,0x44,0x11,0x27,0x0,0x44,0x11,0x24, Step #5: \000$u\000\000\000\000\000\342\200\202\000\000\342\200\202\000\000\000\000\000\000\363\240\201\230\000s\012 +C\000\000\000\000\342\200\202\000\000\000\000\000\000\363\240\201\230\000s\012 /C@\000\000\000\000\341\240\216\000\000D\021'\000D\021$ Step #5: artifact_prefix='./'; Test unit written to ./oom-b7c3abdac5b8d880f7b5b9f8c5779e05d6495bcf Step #5: Base64: ACR1AAAAAADigIIAAOKAggAAAAAAAPOggZgAcwogICtDAAAAAOKAggAAAAAAAPOggZgAcwogL0NAAAAAAOGgjgAARBEnAEQRJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3721 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3560367478 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b2757e810, 0x557b2776801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b27768020,0x557b296000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7c3abdac5b8d880f7b5b9f8c5779e05d6495bcf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4614 processed earlier; will process 6415 files now Step #5: ==134032== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557b1e0739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b246d8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b246bb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b246bb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b1e079d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b1dfdab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b1dfd5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b1e06bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b2103af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b2103af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b2103af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b2103af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b2103af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b2103af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b2103af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b2103af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b2103af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b2103af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b232cff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b1fffcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b20007be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b1fdb3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b1fdb3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b1fdb4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b1fdb3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b1fdb3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b1fdb3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b246bdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b246c6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b246ae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b246d9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f05ac24a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b1dfd3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x7c,0x27,0x28,0xd5,0x8c,0x0,0xca,0xb4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0x8b,0x10,0x29,0x7b,0x39,0x43,0x37,0xe2,0x80,0x84,0x7d, Step #5: ||'(\325\214\000\312\264\000\000\000\000\000\000\000\000\000-\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\342\200\213\020){9C7\342\200\204} Step #5: artifact_prefix='./'; Test unit written to ./oom-7b72a3adf6226ac132edb2fc6d1efc6ecd4e7795 Step #5: Base64: fHwnKNWMAMq0AAAAAAAAAAAALQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA4oCLECl7OUM34oCEfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3722 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3560879599 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55717b275810, 0x55717b45f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55717b45f020,0x55717d2f70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7b72a3adf6226ac132edb2fc6d1efc6ecd4e7795' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4615 processed earlier; will process 6414 files now Step #5: ==134068== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557171d6a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571783cf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571783b25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571783b24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557171d70d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557171cd1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557171ccc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557171d62c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557174d31f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557174d31f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557174d31f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557174d31f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557174d31f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557174d31f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557174d31f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557174d31f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557174d31f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557174d31f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557176fc6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557173cf3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557173cfebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557173aaac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557173aaac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557173aab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557173aaa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557173aaa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557173aaa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571783b4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571783bd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571783a5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571783d0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda3d18e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557171ccab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0xd7,0xa9,0x1,0x0,0x6,0x54,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x0,0x25,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x32,0x32,0x49,0x44,0x33,0x2,0x6b,0x86,0x50,0x52,0x49,0x0,0x0,0x2,0x0,0x86,0x50,0x52,0x49,0x0,0x0,0x2,0x0,0xbe,0x32, Step #5: \000\000\327\251\001\000\006T\000\000\000\000\000\000\000\000\000\000\000\000\000\010\000\000%\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\00022ID3\002k\206PRI\000\000\002\000\206PRI\000\000\002\000\2762 Step #5: artifact_prefix='./'; Test unit written to ./oom-5fe1d3a16a62e1c28ea10ef6bdb183f4eaf72163 Step #5: Base64: AADXqQEABlQAAAAAAAAAAAAAAAAACAAAJQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMjJJRDMCa4ZQUkkAAAIAhlBSSQAAAgC+Mg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3723 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3561386100 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a55184e810, 0x55a551a3801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a551a38020,0x55a5538d00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5fe1d3a16a62e1c28ea10ef6bdb183f4eaf72163' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4616 processed earlier; will process 6413 files now Step #5: ==134104== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a5483439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a54e9a8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a54e98b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a54e98b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a548349d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a5482aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a5482a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a54833bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a54b30af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a54b30af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a54b30af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a54b30af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a54b30af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a54b30af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a54b30af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a54b30af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a54b30af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a54b30af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a54d59ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a54a2ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a54a2d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a54a083c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a54a083c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a54a084738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a54a083874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a54a083874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a54a083874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a54e98dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a54e996928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a54e97e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a54e9a9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4504593082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a5482a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x0,0x0,0x0,0x47,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x25,0x7d,0x7b,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x0,0xb,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x27,0xf,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x31,0x2c,0x7d,0x20,0x7b,0x2c,0x7d, Step #5: }{0,} {\000\000\000G{0,}s{0,} {0,}${0,}%}{,} {0,} {\000\0130,}s{0,} {0,}'\017${0,} {1,} {,} Step #5: artifact_prefix='./'; Test unit written to ./oom-97607f6637dbbb2a583dccbd0c07f5eb4e65da7c Step #5: Base64: fXswLH0gewAAAEd7MCx9c3swLH0gezAsfSR7MCx9JX17LH0gezAsfSB7AAswLH1zezAsfSB7MCx9Jw8kezAsfSB7MSx9IHssfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3724 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3561898706 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d593137810, 0x55d59332101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d593321020,0x55d5951b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/97607f6637dbbb2a583dccbd0c07f5eb4e65da7c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4617 processed earlier; will process 6412 files now Step #5: ==134140== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d589c2c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d590291898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d5902745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d5902744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d589c32d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d589b93b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d589b8e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d589c24c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d58cbf3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d58cbf3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d58cbf3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d58cbf3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d58cbf3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d58cbf3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d58cbf3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d58cbf3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d58cbf3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d58cbf3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d58ee88f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d58bbb5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d58bbc0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d58b96cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d58b96cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d58b96d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d58b96c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d58b96c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d58b96c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d590276abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d59027f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d590267699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d590292112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8fcca4b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d589b8cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x31,0x4d,0x46,0x76,0x48,0x65,0x57,0x46,0x63,0x6f,0x41,0x61,0x71,0x59,0x31,0x2b,0x6d,0x6a,0x47,0x4d,0x6c,0x43,0x41,0x41,0x42,0x73,0x54,0x2b,0x4c,0x53,0x58,0x49,0x53,0x7a,0x4c,0x77,0x6a,0x78,0x6f,0x2f,0x54,0x2f,0xa,0x61,0x20,0xd5,0x34, Step #5: onion-key\012ntor-onion-key v1MFvHeWFcoAaqY1+mjGMlCAABsT+LSXISzLwjxo/T/\012a \3254 Step #5: artifact_prefix='./'; Test unit written to ./oom-76d48162292f10f0502fc971652a72dbf158f8ab Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHYxTUZ2SGVXRmNvQWFxWTErbWpHTWxDQUFCc1QrTFNYSVN6THdqeG8vVC8KYSDVNA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3725 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3562403447 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56098bce6810, 0x56098bed001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56098bed0020,0x56098dd680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/76d48162292f10f0502fc971652a72dbf158f8ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4618 processed earlier; will process 6411 files now Step #5: ==134176== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5609827db9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560988e40898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560988e235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560988e234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5609827e1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560982742b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56098273d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5609827d3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5609857a2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5609857a2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5609857a2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5609857a2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5609857a2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5609857a2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5609857a2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5609857a2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5609857a2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5609857a2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560987a37f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560984764b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56098476fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56098451bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56098451bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56098451c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56098451b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56098451b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56098451b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560988e25abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560988e2e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560988e16699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560988e41112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5cb8e5a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56098273bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x61,0x63,0x74,0x69,0x6f,0x6e,0x73,0x7b,0xa,0x20,0x20,0x61,0x64,0x64,0x5f,0x72,0x65,0x66,0x65,0x72,0x65,0x6e,0x63,0x65,0x20,0x7b,0xa,0x7d,0xa,0x7d,0x61,0x63,0x74,0x69,0x6f,0x6e,0x73,0x7b,0x72,0x65,0x6d,0x6f,0x76,0x65,0x3a,0x22,0xcd,0x85,0x22,0xa,0x7d,0x61,0x63,0x74,0x69,0x6f,0x6e,0x73,0x7b,0x72,0x65,0x6d,0x6f,0x76,0x65,0x3a,0x22,0xcd,0x85,0x22,0xa,0x7d,0xa, Step #5: actions{\012 add_reference {\012}\012}actions{remove:\"\315\205\"\012}actions{remove:\"\315\205\"\012}\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-55760c73fcad27de5847ea2075e125117e69a8f8 Step #5: Base64: YWN0aW9uc3sKICBhZGRfcmVmZXJlbmNlIHsKfQp9YWN0aW9uc3tyZW1vdmU6Is2FIgp9YWN0aW9uc3tyZW1vdmU6Is2FIgp9Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3726 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3562913574 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56045e063810, 0x56045e24d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56045e24d020,0x5604600e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/55760c73fcad27de5847ea2075e125117e69a8f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4619 processed earlier; will process 6410 files now Step #5: ==134212== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560454b589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56045b1bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56045b1a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56045b1a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560454b5ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560454abfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560454aba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560454b50c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560457b1ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560457b1ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560457b1ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560457b1ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560457b1ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560457b1ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560457b1ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560457b1ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560457b1ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560457b1ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560459db4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560456ae1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560456aecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560456898c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560456898c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560456899738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560456898874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560456898874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560456898874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56045b1a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56045b1ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56045b193699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56045b1be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f859ee09082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560454ab8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x4,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x42,0x3c,0xdb,0x9e,0x0,0x0,0x0,0x0,0x64,0x64,0x64,0x64,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x42,0x3c,0xdb,0x9e,0x7e,0x7e,0x7e,0x42,0x3c,0xdb,0x9e,0x0,0x0,0x0,0x0,0x64,0x64,0x64,0x64,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x42,0x3c,0xdb,0x9e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x2b,0x7e,0x2b,0x7e,0x7e,0x7e,0x7e,0xff,0x7e,0xff,0x67,0x67, Step #5: \002\004~~~~~~B<\333\236\000\000\000\000dddd~~~~~~B<\333\236~~~B<\333\236\000\000\000\000dddd~~~~~~B<\333\236~~~~~~~+~+~~~~\377~\377gg Step #5: artifact_prefix='./'; Test unit written to ./oom-a92a7ddd151f4436be8e992d46d200fafc20832b Step #5: Base64: AgR+fn5+fn5CPNueAAAAAGRkZGR+fn5+fn5CPNuefn5+QjzbngAAAABkZGRkfn5+fn5+Qjzbnn5+fn5+fn4rfit+fn5+/37/Z2c= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3727 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3563420244 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ef3dbf3810, 0x55ef3dddd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ef3dddd020,0x55ef3fc750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a92a7ddd151f4436be8e992d46d200fafc20832b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4620 processed earlier; will process 6409 files now Step #5: ==134248== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ef346e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ef3ad4d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ef3ad305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ef3ad304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef346eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef3464fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef3464a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef346e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef376aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef376aff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef376aff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef376aff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef376aff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef376aff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef376aff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef376aff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef376aff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef376aff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef39944f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef36671b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef3667cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef36428c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef36428c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef36429738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef36428874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef36428874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef36428874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ef3ad32abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ef3ad3b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ef3ad23699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ef3ad4e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0081a19082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef34648b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x8,0x0,0x7,0x2e,0x2b,0x42,0xdb,0xbe,0x75,0xdb,0xbe,0x2b,0x2b,0x2b,0x2b,0x2b,0x41,0x2b,0x2b,0x2b,0x2b,0x2b,0x3b,0xef,0xbb,0xae,0xd,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x0,0x0,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x2b,0x2b,0x24,0x6e,0x24,0x3,0x3,0x52, Step #5: - \010\000\007.+B\333\276u\333\276+++++A+++++;\357\273\256\01599999999999999999999\000\000999999999999999++$n$\003\003R Step #5: artifact_prefix='./'; Test unit written to ./oom-a5b1497c5746b165257f161e2a242302744143ff Step #5: Base64: LSAIAAcuK0LbvnXbvisrKysrQSsrKysrO++7rg05OTk5OTk5OTk5OTk5OTk5OTk5OQAAOTk5OTk5OTk5OTk5OTk5KyskbiQDA1I= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3728 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3563933825 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c6a8fcc810, 0x55c6a91b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c6a91b6020,0x55c6ab04e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a5b1497c5746b165257f161e2a242302744143ff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4621 processed earlier; will process 6408 files now Step #5: ==134284== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c69fac19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c6a6126898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c6a61095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c6a61094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c69fac7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c69fa28b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c69fa23355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c69fab9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c6a2a88f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c6a2a88f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c6a2a88f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c6a2a88f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c6a2a88f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c6a2a88f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c6a2a88f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c6a2a88f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c6a2a88f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c6a2a88f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c6a4d1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6a1a4ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c6a1a55be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6a1801c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6a1801c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6a1802738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6a1801874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6a1801874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6a1801874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c6a610babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c6a6114928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c6a60fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c6a6127112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f377cc56082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c69fa21b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x2d,0x2d,0xa,0x3d,0x44,0x31,0x4,0xcc,0x96,0xb,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xff, Step #5: \005-----BEGIN =\012= i\012\012r=sef=\012=+=\012=\012=\012= =\012= i\012\012r=sef=\012=+--\012=D1\004\314\226\013skip_cl\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-9423e56a4985113c2af66f5068b2ec41b03e9149 Step #5: Base64: BS0tLS0tQkVHSU4gPQo9IGkKCnI9c2VmPQo9Kz0KPQo9Cj0gPQo9IGkKCnI9c2VmPQo9Ky0tCj1EMQTMlgtza2lwX2NsCnwAEP8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3729 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3564446415 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56064ada3810, 0x56064af8d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56064af8d020,0x56064ce250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9423e56a4985113c2af66f5068b2ec41b03e9149' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4622 processed earlier; will process 6407 files now Step #5: ==134320== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5606418989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560647efd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560647ee05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560647ee04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56064189ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5606417ffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5606417fa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560641890c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56064485ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56064485ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56064485ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56064485ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56064485ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56064485ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56064485ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56064485ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56064485ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56064485ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560646af4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560643821b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56064382cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5606435d8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5606435d8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5606435d9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5606435d8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5606435d8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5606435d8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560647ee2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560647eeb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560647ed3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560647efe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe610126082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5606417f8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0x90,0xd9,0x90,0xd9,0x91,0x20,0x78,0x74,0x3e,0xce,0x90,0xd9,0x90,0xd9,0x91,0x20,0xe2,0x86,0x8d,0x5b,0x31,0xe2,0x80,0xbc,0xe1,0x82,0x8d,0x38,0x33,0x36,0x34,0x38,0xe2,0x80,0xbc,0xe1,0x82,0x8d,0xef,0xb8,0x8f,0xd9,0x90,0xef,0xb8,0x8f,0xd9,0x90,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text>\331\220\331\220\331\221 xt>\316\220\331\220\331\221 \342\206\215[1\342\200\274\341\202\21583648\342\200\274\341\202\215\357\270\217\331\220\357\270\217\331\220'</text></svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-edeb23e8d600e2c75e153b840be484671e15d3f8 Step #5: Base64: PHN2Zz48dGV4dD7ZkNmQ2ZEgeHQ+zpDZkNmRIOKGjVsx4oC84YKNODM2NDjigLzhgo3vuI/ZkO+4j9mQJzwvdGV4dD48L3N2Zz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3730 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3564955216 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c0ee6d4810, 0x55c0ee8be01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c0ee8be020,0x55c0f07560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/edeb23e8d600e2c75e153b840be484671e15d3f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4623 processed earlier; will process 6406 files now Step #5: #1 pulse cov: 3669 ft: 3670 exec/s: 0 rss: 174Mb Step #5: ==134356== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c0e51c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c0eb82e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c0eb8115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c0eb8114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c0e51cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c0e5130b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c0e512b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c0e51c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c0e8190f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c0e8190f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c0e8190f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c0e8190f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c0e8190f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c0e8190f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c0e8190f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c0e8190f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c0e8190f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c0e8190f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c0ea425f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c0e7152b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c0e715dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c0e6f09c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c0e6f09c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c0e6f0a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c0e6f09874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c0e6f09874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c0e6f09874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c0eb813abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c0eb81c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c0eb804699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c0eb82f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda16e6a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c0e5129b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x0,0x6,0x0,0x0,0x29,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x18,0x0,0x0,0x0,0x0,0x1b,0x3f,0x1b,0x1b,0x1b,0x0,0x0,0x0,0x43,0x4b,0x2,0x48,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: \001\000\006\000\000)\001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\030\000\000\000\000\033?\033\033\033\000\000\000CK\002H\000\000\000\000\000\002\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-12244cb1471837ce59cf623d42090529eeabb1f5 Step #5: Base64: AQAGAAApAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYAAAAABs/GxsbAAAAQ0sCSAAAAAAAAgAAAAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3731 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3565501085 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d991fa2810, 0x55d99218c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d99218c020,0x55d9940240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/12244cb1471837ce59cf623d42090529eeabb1f5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4625 processed earlier; will process 6404 files now Step #5: ==134392== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d988a979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d98f0fc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d98f0df5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d98f0df4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d988a9dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d9889feb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d9889f9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d988a8fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d98ba5ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d98ba5ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d98ba5ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d98ba5ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d98ba5ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d98ba5ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d98ba5ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d98ba5ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d98ba5ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d98ba5ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d98dcf3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d98aa20b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d98aa2bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d98a7d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d98a7d7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d98a7d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d98a7d7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d98a7d7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d98a7d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d98f0e1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d98f0ea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d98f0d2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d98f0fd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4750a98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d9889f7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x67,0x6d,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0, Step #5: gm \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-bcedd03d14026c2f1e870e8df648c87bb5d4f826 Step #5: Base64: Z20gwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3732 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3566007473 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558861e10810, 0x558861ffa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558861ffa020,0x558863e920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bcedd03d14026c2f1e870e8df648c87bb5d4f826' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4626 processed earlier; will process 6403 files now Step #5: ==134428== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5588589059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55885ef6a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55885ef4d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55885ef4d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55885890bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55885886cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558858867355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588588fdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55885b8ccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55885b8ccf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55885b8ccf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55885b8ccf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55885b8ccf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55885b8ccf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55885b8ccf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55885b8ccf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55885b8ccf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55885b8ccf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55885db61f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55885a88eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55885a899be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55885a645c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55885a645c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55885a646738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55885a645874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55885a645874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55885a645874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55885ef4fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55885ef58928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55885ef40699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55885ef6b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdfb5165082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558858865b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x73,0x3a,0xc8,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x2e,0x65,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94, Step #5: \016ws:\310\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204.e\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\224 Step #5: artifact_prefix='./'; Test unit written to ./oom-a1267781f93fa77ddc4fc72e5a827a533c03f239 Step #5: Base64: DndzOsiEzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYQuZc2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzZQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3733 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3566506769 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a65fbad810, 0x55a65fd9701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a65fd97020,0x55a661c2f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a1267781f93fa77ddc4fc72e5a827a533c03f239' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4627 processed earlier; will process 6402 files now Step #5: #1 pulse cov: 3568 ft: 3569 exec/s: 0 rss: 174Mb Step #5: ==134464== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a6566a29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a65cd07898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a65ccea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a65ccea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a6566a8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a656609b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a656604355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a65669ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a659669f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a659669f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a659669f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a659669f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a659669f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a659669f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a659669f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a659669f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a659669f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a659669f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a65b8fef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a65862bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a658636be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a6583e2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a6583e2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a6583e3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a6583e2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a6583e2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a6583e2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a65ccecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a65ccf5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a65ccdd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a65cd08112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7108e16082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a656602b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0xa,0xcd,0x8f,0x2e,0x2e,0xa,0xcd,0x8f,0x2e,0xa,0x2e,0xa,0xcd,0x8f,0x2e,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0x28,0xa,0x2e,0xb1,0xa,0x2e,0xcc,0x95,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0xa,0x2e,0xcc,0x8f,0xa,0xcd,0x8b,0x2e,0xa,0x8f,0x2e,0xa,0xcd,0x8e,0x2e,0xa,0xcd,0x8f,0x2e,0xa,0xcd,0x2e,0xa,0xc3,0xbc,0x2e,0x63,0x6f,0x6d,0xa,0xcd,0x9f,0x2e,0xa,0xcd,0x8e,0x2e, Step #5: .\012\315\217..\012\315\217.\012.\012\315\217.\012.\314\261\012.(\012.\261\012.\314\225\012.\314\261\012.\314\012.\314\217\012\315\213.\012\217.\012\315\216.\012\315\217.\012\315.\012\303\274.com\012\315\237.\012\315\216. Step #5: artifact_prefix='./'; Test unit written to ./oom-99d82114148516ab7d75c8db7e64cd771d7a2f21 Step #5: Base64: LgrNjy4uCs2PLgouCs2PLgouzLEKLigKLrEKLsyVCi7MsQouzAouzI8KzYsuCo8uCs2OLgrNjy4KzS4Kw7wuY29tCs2fLgrNji4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3734 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3567056058 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55747340f810, 0x5574735f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5574735f9020,0x5574754910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/99d82114148516ab7d75c8db7e64cd771d7a2f21' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4629 processed earlier; will process 6400 files now Step #5: ==134500== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557469f049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557470569898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55747054c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55747054c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557469f0ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557469e6bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557469e66355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557469efcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55746cecbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55746cecbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55746cecbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55746cecbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55746cecbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55746cecbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55746cecbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55746cecbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55746cecbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55746cecbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55746f160f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55746be8db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55746be98be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55746bc44c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55746bc44c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55746bc45738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55746bc44874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55746bc44874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55746bc44874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55747054eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557470557928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55747053f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55747056a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f75b28d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557469e64b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x0,0x21,0x0,0x44,0x0,0x4f,0x0,0x43,0x0,0x54,0x0,0x59,0x0,0x50,0x0,0x45,0x0,0x20,0x0,0x4c,0x0,0xa,0x0,0x50,0x0,0x55,0x0,0x42,0x0,0x4c,0x0,0x49,0x0,0x43,0x0,0x20,0x0,0x22,0x0,0x20,0x0,0x27,0x0,0x27,0x0,0x27,0x0,0x27,0x0,0x27,0x0,0x27,0x0,0x27,0x0,0x27,0x0,0x27,0x0,0x27,0x0,0x27,0x0,0x27,0x0,0x27,0x0,0x27,0x0,0x27,0x0,0x27,0x0, Step #5: <\000!\000D\000O\000C\000T\000Y\000P\000E\000 \000L\000\012\000P\000U\000B\000L\000I\000C\000 \000\"\000 \000'\000'\000'\000'\000'\000'\000'\000'\000'\000'\000'\000'\000'\000'\000'\000'\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a6c0c0e402053ad18f6970b095778709e0f4e6d1 Step #5: Base64: PAAhAEQATwBDAFQAWQBQAEUAIABMAAoAUABVAEIATABJAEMAIAAiACAAJwAnACcAJwAnACcAJwAnACcAJwAnACcAJwAnACcAJwA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3735 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3567557953 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56251c56f810, 0x56251c75901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56251c759020,0x56251e5f10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a6c0c0e402053ad18f6970b095778709e0f4e6d1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4630 processed earlier; will process 6399 files now Step #5: ==134536== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5625130649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5625196c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625196ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625196ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56251306ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562512fcbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562512fc6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56251305cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56251602bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56251602bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56251602bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56251602bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56251602bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56251602bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56251602bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56251602bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56251602bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56251602bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5625182c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562514fedb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562514ff8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562514da4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562514da4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562514da5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562514da4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562514da4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562514da4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5625196aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5625196b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56251969f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5625196ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd7806ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562512fc4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x58,0xc,0x44,0x45,0x46,0x41,0x55,0x4c,0x54,0x28,0x28,0x28,0x54,0x48,0x28,0x57,0x28,0x44,0x45,0x28,0x28,0x45,0x58,0x50,0x4c,0x41,0x49,0x4e,0xe3,0x80,0x80,0x20,0x70,0x61,0x72,0x61,0x6d,0x5f,0x65,0x75,0x6c,0x31,0x70,0x3d,0x27,0x31,0x46,0x41,0x55,0x4c,0x54,0x28,0x28,0x28,0x28,0x28,0x28,0x1,0x0,0x0,0x0,0xc2,0x0,0x0,0x0,0x49,0x29,0x27,0xd6,0xda,0x55,0x28,0xa, Step #5: \012X\014DEFAULT(((TH(W(DE((EXPLAIN\343\200\200 param_eul1p='1FAULT((((((\001\000\000\000\302\000\000\000I)'\326\332U(\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-0edad9d49403ee67699227404bd42ad48ec65b29 Step #5: Base64: ClgMREVGQVVMVCgoKFRIKFcoREUoKEVYUExBSU7jgIAgcGFyYW1fZXVsMXA9JzFGQVVMVCgoKCgoKAEAAADCAAAASSkn1tpVKAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3736 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3568063278 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c9fefd3810, 0x55c9ff1bd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c9ff1bd020,0x55ca010550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0edad9d49403ee67699227404bd42ad48ec65b29' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4631 processed earlier; will process 6398 files now Step #5: ==134572== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c9f5ac89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c9fc12d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9fc1105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9fc1104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9f5aced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9f5a2fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c9f5a2a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9f5ac0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c9f8a8ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c9f8a8ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c9f8a8ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c9f8a8ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c9f8a8ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c9f8a8ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c9f8a8ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c9f8a8ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c9f8a8ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c9f8a8ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c9fad24f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9f7a51b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9f7a5cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c9f7808c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c9f7808c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c9f7809738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c9f7808874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c9f7808874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c9f7808874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c9fc112abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c9fc11b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c9fc103699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c9fc12e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9b84dcc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c9f5a28b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xbf,0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xa,0x6e,0x5b,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0x9,0x75,0xa,0x4f,0xa,0x28,0xcd,0x83,0x7c,0xcd,0x83,0x7c,0xcd,0x83,0x7c,0xcd,0x83,0x7c,0xcd,0x83,0x7c,0xcc,0x83,0x7c,0xcd,0x83,0x7c,0xcd,0x83,0x7c,0xcc,0x83,0x7c,0xcd,0x83,0x7c,0xcd,0x84,0x7c,0xcd,0x83,0x7c,0xcd,0x83,0x7c,0xcd,0x83,0x7c,0xcd,0x83, Step #5: \357\273\277<!DOCTYPE\012n[<!ATTLIST\011u\012O\012(\315\203|\315\203|\315\203|\315\203|\315\203|\314\203|\315\203|\315\203|\314\203|\315\203|\315\204|\315\203|\315\203|\315\203|\315\203 Step #5: artifact_prefix='./'; Test unit written to ./oom-120a718cdd917a6fffe2347edb256d638c9e57a2 Step #5: Base64: 77u/PCFET0NUWVBFCm5bPCFBVFRMSVNUCXUKTwoozYN8zYN8zYN8zYN8zYN8zIN8zYN8zYN8zIN8zYN8zYR8zYN8zYN8zYN8zYM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3737 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3568569425 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5624371c6810, 0x5624373b001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5624373b0020,0x5624392480e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/120a718cdd917a6fffe2347edb256d638c9e57a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4632 processed earlier; will process 6397 files now Step #5: ==134608== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56242dcbb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562434320898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5624343035dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5624343034fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56242dcc1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56242dc22b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56242dc1d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56242dcb3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562430c82f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562430c82f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562430c82f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562430c82f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562430c82f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562430c82f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562430c82f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562430c82f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562430c82f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562430c82f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562432f17f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56242fc44b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56242fc4fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56242f9fbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56242f9fbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56242f9fc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56242f9fb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56242f9fb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56242f9fb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562434305abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56243430e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5624342f6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562434321112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1022a2e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56242dc1bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa0,0x8e,0x0,0x0,0x0,0x40,0x0,0x0,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0xe2,0x80,0x8d,0x0,0x0,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0x2f,0x82,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x76,0x30,0x0,0xf3,0xa0,0x81,0xb8,0x0,0x28,0xd,0x0,0x72,0x64,0x64,0x64,0xb5,0xf3,0xa0,0x81,0x87,0x64,0x64, Step #5: \341\240\216\000\000\000@\000\000(\342\200\254\000\341\240\216= \177\177\342\200\215\000\000$$$$$$$$$$(\342\200\256\000r+/\202\000\001\000\000\000\000\000v0\000\363\240\201\270\000(\015\000rddd\265\363\240\201\207dd Step #5: artifact_prefix='./'; Test unit written to ./oom-858c1fad78de744621899fd2a7321be73506939e Step #5: Base64: 4aCOAAAAQAAAKOKArADhoI49IH9/4oCNAAAkJCQkJCQkJCQkKOKArgByKy+CAAEAAAAAAHYwAPOggbgAKA0AcmRkZLXzoIGHZGQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3738 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3569082733 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b888ac810, 0x555b88a9601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b88a96020,0x555b8a92e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/858c1fad78de744621899fd2a7321be73506939e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4633 processed earlier; will process 6396 files now Step #5: ==134644== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555b7f3a19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b85a06898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b859e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b859e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b7f3a7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b7f308b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b7f303355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b7f399c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b82368f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b82368f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b82368f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b82368f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b82368f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b82368f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b82368f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b82368f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b82368f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b82368f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b845fdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b8132ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b81335be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b810e1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b810e1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b810e2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b810e1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b810e1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b810e1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b859ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b859f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b859dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b85a07112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8eb8fd9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b7f301b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x33,0x2e,0x73,0x65,0x72,0x76,0x69,0x63,0x65,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d, Step #5: \0123.service\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012= Step #5: artifact_prefix='./'; Test unit written to ./oom-3abac72c18dce0a79ec2909666ce05ef860e73bb Step #5: Base64: CjMuc2VydmljZQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3739 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3569589910 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a989dc6810, 0x55a989fb001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a989fb0020,0x55a98be480e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3abac72c18dce0a79ec2909666ce05ef860e73bb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4634 processed earlier; will process 6395 files now Step #5: ==134680== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a9808bb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a986f20898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a986f035dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a986f034fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a9808c1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a980822b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a98081d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a9808b3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a983882f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a983882f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a983882f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a983882f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a983882f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a983882f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a983882f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a983882f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a983882f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a983882f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a985b17f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a982844b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a98284fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a9825fbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a9825fbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a9825fc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a9825fb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a9825fb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a9825fb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a986f05abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a986f0e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a986ef6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a986f21112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd2ef718082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a98081bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x2b,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20, Step #5: onion-key ' + \037 ' + \037 ' + ' + \037 ' + ' + \037 + ' + \037 ' + \037 ' + ' + \037 ' + \037 ' Step #5: artifact_prefix='./'; Test unit written to ./oom-6ce8bf011eaae5c1401b8266629aee6d321e8331 Step #5: Base64: b25pb24ta2V5ICcgKyAfICcgKyAfICcgKyAnICsgHyAnICsgJyArIB8gKyAnICsgHyAnICsgHyAnICsgJyArIB8gJyArIB8gJyA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3740 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3570096073 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0a06e6810, 0x55a0a08d001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0a08d0020,0x55a0a27680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ce8bf011eaae5c1401b8266629aee6d321e8331' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4635 processed earlier; will process 6394 files now Step #5: #1 pulse cov: 4278 ft: 4279 exec/s: 0 rss: 173Mb Step #5: ==134716== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0971db9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a09d840898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a09d8235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a09d8234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0971e1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a097142b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a09713d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0971d3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a09a1a2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a09a1a2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a09a1a2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a09a1a2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a09a1a2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a09a1a2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a09a1a2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a09a1a2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a09a1a2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a09a1a2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a09c437f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a099164b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a09916fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a098f1bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a098f1bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a098f1c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a098f1b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a098f1b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a098f1b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a09d825abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a09d82e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a09d816699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a09d841112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f51d3058082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a09713bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x8,0x0,0x7,0x2e,0x2b,0x42,0xda,0xbe,0x7c,0xdb,0xbe,0xdb,0xbe,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x81,0x2b,0x2b,0x2b,0x2b,0x2b,0x24,0x6e,0x24,0x3,0x3,0x52, Step #5: - \010\000\007.+B\332\276|\333\276\333\276++++++++++\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201\201+++++$n$\003\003R Step #5: artifact_prefix='./'; Test unit written to ./oom-cf30952ca73fd50584940255ae20a2d8acd31a68 Step #5: Base64: LSAIAAcuK0Lavnzbvtu+KysrKysrKysrK4GBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgSsrKysrJG4kAwNS Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3741 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3570643487 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561917a82810, 0x561917c6c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561917c6c020,0x561919b040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf30952ca73fd50584940255ae20a2d8acd31a68' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4637 processed earlier; will process 6392 files now Step #5: ==134752== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56190e5779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561914bdc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561914bbf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561914bbf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56190e57dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56190e4deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56190e4d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56190e56fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56191153ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56191153ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56191153ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56191153ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56191153ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56191153ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56191153ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56191153ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56191153ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56191153ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5619137d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561910500b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56191050bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5619102b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5619102b7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5619102b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5619102b7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5619102b7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5619102b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561914bc1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561914bca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561914bb2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561914bdd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e62b3e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56190e4d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3b,0x2a,0x34,0x39,0x6f,0x28,0x76,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x30,0x30,0x30,0x38,0x32,0x32,0x38,0x32,0x33,0x37,0x39,0x33,0x36,0x30,0x33,0x28,0x76,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x30,0x30,0x30,0x30,0x32,0x32,0x38,0x32,0x35,0x39,0x34,0x36,0x30,0x35,0x37,0x2f,0x32,0x30,0x2a, Step #5: ;*49o(v4444444444444444000822823793603(v4444444444444444000022825946057/20* Step #5: artifact_prefix='./'; Test unit written to ./oom-d4a37d64b3b5ee1949a62336a811c97f899a7373 Step #5: Base64: Oyo0OW8odjQ0NDQ0NDQ0NDQ0NDQ0NDQwMDA4MjI4MjM3OTM2MDModjQ0NDQ0NDQ0NDQ0NDQ0NDQwMDAwMjI4MjU5NDYwNTcvMjAq Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3742 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3571142098 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55de22d94810, 0x55de22f7e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55de22f7e020,0x55de24e160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d4a37d64b3b5ee1949a62336a811c97f899a7373' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4638 processed earlier; will process 6391 files now Step #5: ==134788== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55de198899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55de1feee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55de1fed15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55de1fed14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55de1988fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55de197f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55de197eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55de19881c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55de1c850f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55de1c850f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55de1c850f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55de1c850f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55de1c850f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55de1c850f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55de1c850f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55de1c850f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55de1c850f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55de1c850f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55de1eae5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55de1b812b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55de1b81dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55de1b5c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55de1b5c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55de1b5ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55de1b5c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55de1b5c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55de1b5c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55de1fed3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55de1fedc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55de1fec4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55de1feef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c92648082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55de197e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x61,0x5c,0x23,0x73,0x63,0x65,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x74,0x20,0x5c,0x23,0x23,0x68,0xb,0xb,0xb,0xea,0xb,0x41,0xb,0xb,0xb,0xb,0xb,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x4f,0xb,0xb, Step #5: a\\#sce\001\000\000\000\000\000\000\000/\000\000\000\000\000\000\000\000\000\000\000\000j\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000t \\##h\013\013\013\352\013A\013\013\013\013\013\021\000\000\000\000\000\000O\013\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-7d764aa9b07611bc2c7888e23e6908f6821b259c Step #5: Base64: YVwjc2NlAQAAAAAAAAAvAAAAAAAAAAAAAAAAagAAAAAAAAAAAAAAAAAAAAAAAAAAdCBcIyNoCwsL6gtBCwsLCwsRAAAAAAAATwsL Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3743 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3571648608 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a97f37810, 0x563a9812101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a98121020,0x563a99fb90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d764aa9b07611bc2c7888e23e6908f6821b259c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4639 processed earlier; will process 6390 files now Step #5: ==134824== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563a8ea2c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a95091898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a950745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a950744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a8ea32d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a8e993b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a8e98e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a8ea24c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a919f3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a919f3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a919f3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a919f3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a919f3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a919f3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a919f3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a919f3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a919f3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a919f3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a93c88f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a909b5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a909c0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a9076cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a9076cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a9076d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a9076c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a9076c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a9076c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a95076abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a9507f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a95067699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a95092112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4c71fc4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a8e98cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2d,0x25,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x21,0x24,0x29,0x2d,0x2d,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x5f,0x7f,0x5f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x2d,0x2d,0xa,0x3a,0x4e,0x21,0x24,0x47,0x49,0x49,0x44,0x30,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x3, Step #5: \012-%---BEGI!$)--\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177_\177_\177\177\177\177\177\177\177\177--\012:N!$GIID0\002U -E\012\012\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-07bc03ad392b7dd9fd278c78f6f35f7cf335c246 Step #5: Base64: Ci0lLS0tQkVHSSEkKS0tf39/f39/f39/f39/f39/f39/f39/f39/f39/f39ff19/f39/f39/fy0tCjpOISRHSUlEMAJVIC1FCgoD Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3744 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3572163272 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5603bf2af810, 0x5603bf49901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5603bf499020,0x5603c13310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/07bc03ad392b7dd9fd278c78f6f35f7cf335c246' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4640 processed earlier; will process 6389 files now Step #5: #1 pulse cov: 11678 ft: 11679 exec/s: 0 rss: 193Mb Step #5: ==134860== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5603b5da49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5603bc409898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5603bc3ec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5603bc3ec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5603b5daad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5603b5d0bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5603b5d06355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5603b5d9cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5603b8d6bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5603b8d6bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5603b8d6bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5603b8d6bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5603b8d6bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5603b8d6bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5603b8d6bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5603b8d6bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5603b8d6bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5603b8d6bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5603bb000f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5603b7d2db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5603b7d38be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5603b7ae4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5603b7ae4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5603b7ae5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5603b7ae4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5603b7ae4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5603b7ae4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5603bc3eeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5603bc3f7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5603bc3df699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5603bc40a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe91a8a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5603b5d04b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x2f,0x2f,0x0,0x2,0x22,0x5b,0x7b,0x4e,0x65,0x5c,0x74,0xf3,0xa1,0x81,0x9d,0x5c,0x74,0xf3,0x9f,0x81,0x9d,0x72,0x5c,0x6e,0xf3,0xb0,0x83,0x9d,0x5c,0x74,0xf3,0xa1,0x81,0x9d,0x5c,0x74,0xf3,0xa0,0x80,0x9d,0x73,0x5c,0x72,0x5c,0x74,0xf3,0xa0,0x81,0x9d,0x5c,0x74,0xf2,0xa0,0x81,0x9d,0x73,0x5c,0x6e,0xf3,0xa0,0x81,0x9d,0x74,0x9d,0x5d,0x4d,0x69,0x2e,0x6d,0x73,0x4, Step #5: \000\000\000\000//\000\002\"[{Ne\\t\363\241\201\235\\t\363\237\201\235r\\n\363\260\203\235\\t\363\241\201\235\\t\363\240\200\235s\\r\\t\363\240\201\235\\t\362\240\201\235s\\n\363\240\201\235t\235]Mi.ms\004 Step #5: artifact_prefix='./'; Test unit written to ./oom-632e1a82cc11ca8bc0c78dc9d26611b938bd057a Step #5: Base64: AAAAAC8vAAIiW3tOZVx086GBnVx085+BnXJcbvOwg51cdPOhgZ1cdPOggJ1zXHJcdPOggZ1cdPKggZ1zXG7zoIGddJ1dTWkubXME Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3745 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3572729578 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f60c6a7810, 0x55f60c89101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f60c891020,0x55f60e7290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/632e1a82cc11ca8bc0c78dc9d26611b938bd057a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4642 processed earlier; will process 6387 files now Step #5: #1 pulse cov: 3645 ft: 3646 exec/s: 0 rss: 175Mb Step #5: ==134896== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f60319c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f609801898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f6097e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f6097e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f6031a2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f603103b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f6030fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f603194c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f606163f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f606163f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f606163f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f606163f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f606163f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f606163f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f606163f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f606163f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f606163f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f606163f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f6083f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f605125b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f605130be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f604edcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f604edcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f604edd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f604edc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f604edc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f604edc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f6097e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f6097ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f6097d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f609802112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f761cfae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f6030fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2d,0x25,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x21,0x24,0x29,0x2d,0x2d,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x5f,0x7f,0x5f,0x7f,0x7f,0x7f,0x7f,0x7f,0x5f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x21,0x24,0x47,0x49,0x49,0x44,0x30,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x3, Step #5: \012-%---BEGI!$)--\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177_\177_\177\177\177\177\177_\177\177\177\177\177\177\177!$GIID0\002U -E\012\012\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-7059b0d4a8d3bbe295f7d4e754ad3ae6d59ba8bf Step #5: Base64: Ci0lLS0tQkVHSSEkKS0tf39/f39/f39/f39/f39/f39/f39/f39/f39/f39ff19/f39/f19/f39/f39/ISRHSUlEMAJVIC1FCgoD Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3746 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3573272018 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d2d67a3810, 0x55d2d698d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d2d698d020,0x55d2d88250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7059b0d4a8d3bbe295f7d4e754ad3ae6d59ba8bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4644 processed earlier; will process 6385 files now Step #5: ==134932== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d2cd2989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d2d38fd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d2d38e05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d2d38e04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d2cd29ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d2cd1ffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d2cd1fa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d2cd290c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d2d025ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d2d025ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d2d025ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d2d025ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d2d025ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d2d025ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d2d025ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d2d025ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d2d025ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d2d025ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d2d24f4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d2cf221b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d2cf22cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d2cefd8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d2cefd8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d2cefd9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d2cefd8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d2cefd8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d2cefd8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d2d38e2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d2d38eb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d2d38d3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d2d38fe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f41983c7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d2cd1f8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x29,0x0,0xef,0xbd,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0x0,0xef,0xbc,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0x0,0xef,0xbc,0x88,0xef,0xb9,0x88,0x0,0xef,0xbc,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0x0,0xef,0xbd,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb8,0x88,0x0,0xef,0xbd,0x87,0x53,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0xed, Step #5: )\000\357\275\207\357\271\274\357\274\210\357\271\210\000\357\274\207\357\271\274\357\274\210\357\271\210\000\357\274\210\357\271\210\000\357\274\207\357\271\274\357\274\210\357\271\210\000\357\275\207\357\271\274\357\274\210\357\270\210\000\357\275\207S\357\271\274\357\274\210\357\271\210\355 Step #5: artifact_prefix='./'; Test unit written to ./oom-e15d5c7c8a984e031b0ce28dfb28b1e519a6563e Step #5: Base64: KQDvvYfvubzvvIjvuYgA77yH77m877yI77mIAO+8iO+5iADvvIfvubzvvIjvuYgA772H77m877yI77iIAO+9h1PvubzvvIjvuYjt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3747 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3573763986 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5618b9eb4810, 0x5618ba09e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5618ba09e020,0x5618bbf360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e15d5c7c8a984e031b0ce28dfb28b1e519a6563e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4645 processed earlier; will process 6384 files now Step #5: ==134968== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5618b09a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5618b700e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5618b6ff15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5618b6ff14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5618b09afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5618b0910b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5618b090b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5618b09a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5618b3970f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5618b3970f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5618b3970f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5618b3970f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5618b3970f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5618b3970f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5618b3970f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5618b3970f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5618b3970f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5618b3970f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5618b5c05f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5618b2932b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5618b293dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5618b26e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5618b26e9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5618b26ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5618b26e9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5618b26e9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5618b26e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5618b6ff3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5618b6ffc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5618b6fe4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5618b700f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f869367c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5618b0909b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x48,0x55,0x9,0x22,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0xcf,0x89,0xcf,0x99,0xcf,0x99,0xd9,0x99,0x66,0xcf,0x89,0xcf,0x99,0xcf,0x99,0xdb,0x99,0x66,0x2a,0xcf,0xba,0x26,0x66,0xcf,0x89,0xcf,0x99,0x2a,0xcf,0x99,0xcf,0x99,0xdb,0x99,0x66,0xcf,0x89,0xcf,0x99,0x2a,0xcf,0x99,0xcf,0x99,0xdb,0x99,0x66,0xcf,0x89,0xcf,0x99,0xe2,0x99,0xdb,0x99,0x66,0xcf,0x89,0xcf,0x98,0x2b,0xcf, Step #5: HUHU\011\"fffffff\317\211\317\231\317\231\331\231f\317\211\317\231\317\231\333\231f*\317\272&f\317\211\317\231*\317\231\317\231\333\231f\317\211\317\231*\317\231\317\231\333\231f\317\211\317\231\342\231\333\231f\317\211\317\230+\317 Step #5: artifact_prefix='./'; Test unit written to ./oom-059e420eae17745049a7349f4987cdbdd2e8e1e3 Step #5: Base64: SFVIVQkiZmZmZmZmZs+Jz5nPmdmZZs+Jz5nPmduZZirPuiZmz4nPmSrPmc+Z25lmz4nPmSrPmc+Z25lmz4nPmeKZ25lmz4nPmCvP Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3748 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3574263111 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562797cef810, 0x562797ed901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562797ed9020,0x562799d710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/059e420eae17745049a7349f4987cdbdd2e8e1e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4646 processed earlier; will process 6383 files now Step #5: ==135004== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56278e7e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562794e49898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562794e2c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562794e2c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56278e7ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56278e74bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56278e746355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56278e7dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5627917abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5627917abf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5627917abf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5627917abf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5627917abf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5627917abf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5627917abf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5627917abf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5627917abf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5627917abf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562793a40f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56279076db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562790778be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562790524c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562790524c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562790525738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562790524874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562790524874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562790524874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562794e2eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562794e37928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562794e1f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562794e4a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f542915c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56278e744b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0x20,0x75,0x5b,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0xa,0x6d,0xa,0x79,0xd,0x28,0x53,0x3a,0xd6,0xb7,0x3a,0x7c,0x53,0x3a,0xd6,0xb7,0x3a,0x3a,0x2e,0x7c,0x52,0x53,0x3a,0xd6,0xb7,0x43,0x44,0x41,0x54,0x41,0x3a,0x2e,0x7c,0x52,0x3a,0x3a,0xbf,0x53,0x3a,0x2b,0x52,0xe5,0x57,0x57,0x7c,0x3a,0x0,0x7c,0x3a,0xd6,0xb7,0x3a,0x0,0x3a, Step #5: <!DOCTYPE u[<!ATTLIST\012m\012y\015(S:\326\267:|S:\326\267::.|RS:\326\267CDATA:.|R::\277S:+R\345WW|:\000|:\326\267:\000: Step #5: artifact_prefix='./'; Test unit written to ./oom-4fcdde818bb6a70ae6beb261619f1d89192ac164 Step #5: Base64: PCFET0NUWVBFIHVbPCFBVFRMSVNUCm0KeQ0oUzrWtzp8UzrWtzo6LnxSUzrWt0NEQVRBOi58Ujo6v1M6K1LlV1d8OgB8Ota3OgA6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3749 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3574765288 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55577ec45810, 0x55577ee2f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55577ee2f020,0x555780cc70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4fcdde818bb6a70ae6beb261619f1d89192ac164' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4647 processed earlier; will process 6382 files now Step #5: ==135040== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55577573a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55577bd9f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55577bd825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55577bd824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555775740d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557756a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55577569c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555775732c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555778701f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555778701f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555778701f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555778701f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555778701f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555778701f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555778701f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555778701f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555778701f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555778701f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55577a996f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557776c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557776cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55577747ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55577747ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55577747b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55577747a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55577747a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55577747a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55577bd84abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55577bd8d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55577bd75699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55577bda0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9e74d8e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55577569ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3e,0x32,0x2d,0x3d,0x3e,0xde,0xae,0x21,0xde,0xae,0x57,0x0,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x3d,0x3e,0x32,0x2d,0x3d,0x3e,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x57,0x5c,0x5c,0x4c,0x43,0x3,0x0,0x0,0x0,0xb2,0xb2,0xb2,0xb2,0x24, Step #5: =>2-=>\336\256!\336\256W\000\\\\\\\336\256!\336\256-\\\\\\=>2-=>\336\256!\336\256-\\\\\\\\\336\256!\336\256-\\\\\\\\\\\\\\\\\\\\\\\\\\\\W\\\\LC\003\000\000\000\262\262\262\262$ Step #5: artifact_prefix='./'; Test unit written to ./oom-3df03e93e502520a5665b033430f1275b0c5d915 Step #5: Base64: PT4yLT0+3q4h3q5XAFxcXN6uId6uLVxcXD0+Mi09Pt6uId6uLVxcXFzeriHeri1cXFxcXFxcXFxcXFxcXFdcXExDAwAAALKysrIk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3750 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3575268308 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aed864b810, 0x55aed883501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aed8835020,0x55aeda6cd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3df03e93e502520a5665b033430f1275b0c5d915' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4648 processed earlier; will process 6381 files now Step #5: ==135076== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aecf1409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aed57a5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aed57885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aed57884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aecf146d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aecf0a7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aecf0a2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aecf138c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aed2107f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aed2107f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aed2107f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aed2107f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aed2107f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aed2107f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aed2107f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aed2107f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aed2107f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aed2107f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aed439cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aed10c9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aed10d4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aed0e80c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aed0e80c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aed0e81738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aed0e80874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aed0e80874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aed0e80874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aed578aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aed5793928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aed577b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aed57a6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa5227a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aecf0a0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xdb,0x80,0xdb,0x80,0x34,0x39,0x0,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0x4e,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0x0,0x25,0x0,0x0,0xa,0x0,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0x4e,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0x0,0x25,0x0, Step #5: =\333\200\333\20049\000\016\016\016\016\016\016\016\016\016\016\016\016\016N\016\016\016\016\016\016\016\016\016\016\016\016\016\016\016\016\016\000%\000\000\012\000\016\016\016\016\016\016\016\016\016\016N\016\016\016\016\016\016\016\016\016\016\016\016\016\016\016\016\016\000%\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cd1df8f9d868202c2890d64a51412066c538408f Step #5: Base64: PduA24A0OQAODg4ODg4ODg4ODg4OTg4ODg4ODg4ODg4ODg4ODg4OACUAAAoADg4ODg4ODg4ODk4ODg4ODg4ODg4ODg4ODg4ODgAlAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3751 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3575764388 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d2567c6810, 0x55d2569b001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d2569b0020,0x55d2588480e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd1df8f9d868202c2890d64a51412066c538408f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4649 processed earlier; will process 6380 files now Step #5: ==135112== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d24d2bb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d253920898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d2539035dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d2539034fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d24d2c1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d24d222b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d24d21d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d24d2b3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d250282f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d250282f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d250282f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d250282f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d250282f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d250282f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d250282f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d250282f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d250282f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d250282f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d252517f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d24f244b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d24f24fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d24effbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d24effbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d24effc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d24effb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d24effb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d24effb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d253905abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d25390e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d2538f6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d253921112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d88ad1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d24d21bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdc,0xbb,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xdc,0xb5, Step #5: \334\273\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\334\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-05f66ab5c70bf131db1ac27e3a2e5308dbd132e8 Step #5: Base64: 3LsAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADctQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3752 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3576264471 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562b12db4810, 0x562b12f9e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562b12f9e020,0x562b14e360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/05f66ab5c70bf131db1ac27e3a2e5308dbd132e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4650 processed earlier; will process 6379 files now Step #5: ==135148== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562b098a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562b0ff0e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562b0fef15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562b0fef14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b098afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b09810b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b0980b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b098a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b0c870f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b0c870f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b0c870f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b0c870f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b0c870f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b0c870f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b0c870f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b0c870f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b0c870f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b0c870f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562b0eb05f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b0b832b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b0b83dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b0b5e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b0b5e9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b0b5ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b0b5e9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b0b5e9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b0b5e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562b0fef3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562b0fefc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562b0fee4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562b0ff0f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efd48c9f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b09809b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x51,0x69,0x71,0x67,0x47,0x52,0x49,0x46,0x54,0x79,0x77,0x42,0x4b,0x37,0x30,0x58,0x69,0x44,0x52,0x48,0x71,0x72,0x74,0x61,0x76,0x45,0x64,0x6d,0x65,0x79,0x57,0x61,0x71,0x49,0x59,0x31,0x4e,0x30,0x65,0x46,0x76,0x52,0x6c,0xa,0x61,0x20,0x2d,0x31,0x32,0x38,0x2e, Step #5: onion-key\012ntor-onion-key QiqgGRIFTywBK70XiDRHqrtavEdmeyWaqIY1N0eFvRl\012a -128. Step #5: artifact_prefix='./'; Test unit written to ./oom-085c2199cc73f98d9137d49339b993e4d8103860 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IFFpcWdHUklGVHl3Qks3MFhpRFJIcXJ0YXZFZG1leVdhcUlZMU4wZUZ2UmwKYSAtMTI4Lg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3753 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3576774306 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556e4e058810, 0x556e4e24201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556e4e242020,0x556e500da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/085c2199cc73f98d9137d49339b993e4d8103860' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4651 processed earlier; will process 6378 files now Step #5: ==135184== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556e44b4d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556e4b1b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556e4b1955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556e4b1954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556e44b53d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556e44ab4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556e44aaf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556e44b45c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556e47b14f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556e47b14f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556e47b14f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556e47b14f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556e47b14f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556e47b14f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556e47b14f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556e47b14f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556e47b14f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556e47b14f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556e49da9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556e46ad6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556e46ae1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556e4688dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556e4688dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556e4688e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556e4688d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556e4688d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556e4688d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556e4b197abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556e4b1a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556e4b188699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556e4b1b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbfc91d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556e44aadb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0xa,0x22,0x5f,0x2d,0x47,0xa,0x2b,0x49,0x44,0x31,0x38,0x34,0x34,0x36,0x37,0x34,0x34,0x30,0x37,0x33,0x37,0x30,0x39,0x35,0x35,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x60,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x1,0x0,0x0,0x7e,0x0,0x49,0x44,0x42,0x45,0x2d,0x2d,0x2d,0x2d,0x4b,0x4e,0x4f,0x4f,0x20,0x2d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x60,0x3d,0x3d, Step #5: _\012\"_-G\012+ID1844674407370955\012\000\000\000\000\000\000\000\000\000\000\000`\000\000\000\000\000\000\000\000-\001\000\000~\000IDBE----KNOO -=\012=\012=\012`== Step #5: artifact_prefix='./'; Test unit written to ./oom-5b6dd573de4602dce0ecb3e5762c857ee51959e8 Step #5: Base64: XwoiXy1HCitJRDE4NDQ2NzQ0MDczNzA5NTUKAAAAAAAAAAAAAABgAAAAAAAAAAAtAQAAfgBJREJFLS0tLUtOT08gLT0KPQo9CmA9PQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3754 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3577398326 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5592c66ad810, 0x5592c689701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5592c6897020,0x5592c872f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5b6dd573de4602dce0ecb3e5762c857ee51959e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4652 processed earlier; will process 6377 files now Step #5: ==135220== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5592bd1a29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5592c3807898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5592c37ea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5592c37ea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592bd1a8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592bd109b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592bd104355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592bd19ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592c0169f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592c0169f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592c0169f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592c0169f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592c0169f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592c0169f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592c0169f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592c0169f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592c0169f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592c0169f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592c23fef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592bf12bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592bf136be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5592beee2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5592beee2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5592beee3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5592beee2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5592beee2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5592beee2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5592c37ecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5592c37f5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5592c37dd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5592c3808112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff4c2906082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592bd102b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x59,0x6a,0x3e,0x3c,0x65,0x3e,0x3d,0x3c,0x6b,0x3e,0x3c,0x46,0x65,0x3e,0x3c,0x6d,0x3e,0x3c,0x62,0x3e,0x3c,0x41,0x2d,0x30,0x3e,0x3c,0x77,0x3e,0x3c,0x4d,0x3e,0x3c,0x67,0x3e,0x3c,0x47,0x3e,0x3c,0x52,0x3e,0x3c,0x48,0x42,0x3e,0x3c,0x57,0x3e,0x3c,0x73,0x3e,0x3c,0x63,0x3e,0x3c,0x71,0x3e,0x3c,0x69,0x3e,0x3c,0x7a,0x3e,0x3c,0x74,0x3e,0x3c,0x64,0x3e,0x3c,0x51,0x36,0x3e,0x3c,0x45,0x3e, Step #5: <Yj><e>=<k><Fe><m><b><A-0><w><M><g><G><R><HB><W><s><c><q><i><z><t><d><Q6><E> Step #5: artifact_prefix='./'; Test unit written to ./oom-c7beba2970e21d2cb7d7f1a3e1c9efc30705cc3c Step #5: Base64: PFlqPjxlPj08az48RmU+PG0+PGI+PEEtMD48dz48TT48Zz48Rz48Uj48SEI+PFc+PHM+PGM+PHE+PGk+PHo+PHQ+PGQ+PFE2PjxFPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3755 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3577896477 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563ad5ada810, 0x563ad5cc401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563ad5cc4020,0x563ad7b5c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c7beba2970e21d2cb7d7f1a3e1c9efc30705cc3c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4653 processed earlier; will process 6376 files now Step #5: ==135256== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563acc5cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563ad2c34898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563ad2c175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563ad2c174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563acc5d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563acc536b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563acc531355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563acc5c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563acf596f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563acf596f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563acf596f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563acf596f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563acf596f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563acf596f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563acf596f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563acf596f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563acf596f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563acf596f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563ad182bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563ace558b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563ace563be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563ace30fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563ace30fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563ace310738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563ace30f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563ace30f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563ace30f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563ad2c19abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563ad2c22928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563ad2c0a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563ad2c35112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c8b67e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563acc52fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x44,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012D=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012>\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-3a19bef512f435041563ba9f8137e837cefb2886 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KRD0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo+Cj0KPQo9Cj0KPQo9Cj0KEA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3756 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3578405111 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5606a5241810, 0x5606a542b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5606a542b020,0x5606a72c30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a19bef512f435041563ba9f8137e837cefb2886' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4654 processed earlier; will process 6375 files now Step #5: #1 pulse cov: 3698 ft: 3699 exec/s: 0 rss: 174Mb Step #5: ==135292== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56069bd369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5606a239b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606a237e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606a237e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56069bd3cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56069bc9db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56069bc98355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56069bd2ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56069ecfdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56069ecfdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56069ecfdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56069ecfdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56069ecfdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56069ecfdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56069ecfdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56069ecfdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56069ecfdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56069ecfdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606a0f92f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56069dcbfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56069dccabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56069da76c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56069da76c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56069da77738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56069da76874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56069da76874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56069da76874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5606a2380abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5606a2389928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5606a2371699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5606a239c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7febb0ad1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56069bc96b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x49,0x22,0xd8,0xb3,0xd8,0xb3,0xd8,0xb3,0xdf,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb1,0xd8,0xb3,0xdb,0xb2,0xd8,0xb3,0xd8,0xb3,0xd8,0xb2,0xd8,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb1,0xd8,0xb3,0xd8,0xb1,0xd8,0xb3,0xd4,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb2,0xd8,0xb3,0xd8,0xb3,0xd8,0xb3,0x50,0xda,0xb3,0xd8,0xb3,0xd8,0xb3,0xd8,0xb2,0xd8,0xb3,0xd8, Step #5: HUI\"\330\263\330\263\330\263\337\263\330\263\330\263\330\263\330\261\330\263\333\262\330\263\330\263\330\262\330\263\330\263\330\263\330\263\330\263\330\263\330\261\330\263\330\261\330\263\324\263\330\263\330\263\330\262\330\263\330\263\330\263P\332\263\330\263\330\263\330\262\330\263\330 Step #5: artifact_prefix='./'; Test unit written to ./oom-c36ffd17a29492e6a3505638bf1900e0f108ea84 Step #5: Base64: SFVJItiz2LPYs9+z2LPYs9iz2LHYs9uy2LPYs9iy2LPYs9iz2LPYs9iz2LHYs9ix2LPUs9iz2LPYstiz2LPYs1Das9iz2LPYstiz2A== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3757 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3578941504 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c43a89810, 0x561c43c7301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c43c73020,0x561c45b0b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c36ffd17a29492e6a3505638bf1900e0f108ea84' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4656 processed earlier; will process 6373 files now Step #5: #1 pulse cov: 3861 ft: 3862 exec/s: 0 rss: 174Mb Step #5: ==135328== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561c3a57e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c40be3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c40bc65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c40bc64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c3a584d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c3a4e5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c3a4e0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c3a576c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c3d545f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c3d545f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c3d545f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c3d545f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c3d545f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c3d545f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c3d545f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c3d545f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c3d545f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c3d545f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c3f7daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c3c507b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c3c512be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c3c2bec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c3c2bec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c3c2bf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c3c2be874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c3c2be874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c3c2be874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c40bc8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c40bd1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c40bb9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c40be4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f98b0000082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c3a4deb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x2e,0xe2,0x80,0x95,0xe2,0x80,0x94,0xe2,0x80,0x94,0xe2,0x80,0x94,0xe2,0x80,0x94,0xe2,0x80,0x94,0xe2,0x80,0x94,0xe2,0x80,0x94,0xe2,0x80,0x94,0xe2,0x80,0x8b,0xe2,0x80,0x94,0xe2,0x80,0x94,0x2d,0x2d,0xe2,0x80,0x94,0xe2,0x80,0x94,0xe2,0x80,0x94,0xe2,0x80,0x94,0xe2,0x80,0x8b,0xe2,0x80,0x94,0xe2,0x80,0x94,0x2d,0x2d,0xe2,0x80,0x94,0xe2,0x80,0x94,0xe2,0x80,0x94,0xe2,0x80,0x94,0x7e, Step #5: \016.\342\200\225\342\200\224\342\200\224\342\200\224\342\200\224\342\200\224\342\200\224\342\200\224\342\200\224\342\200\213\342\200\224\342\200\224--\342\200\224\342\200\224\342\200\224\342\200\224\342\200\213\342\200\224\342\200\224--\342\200\224\342\200\224\342\200\224\342\200\224~ Step #5: artifact_prefix='./'; Test unit written to ./oom-900132095a7a039981d08716edd106f19f52bfa7 Step #5: Base64: Di7igJXigJTigJTigJTigJTigJTigJTigJTigJTigIvigJTigJQtLeKAlOKAlOKAlOKAlOKAi+KAlOKAlC0t4oCU4oCU4oCU4oCUfg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3758 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3579476183 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56007b709810, 0x56007b8f301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56007b8f3020,0x56007d78b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/900132095a7a039981d08716edd106f19f52bfa7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4658 processed earlier; will process 6371 files now Step #5: #1 pulse cov: 3658 ft: 3659 exec/s: 0 rss: 174Mb Step #5: ==135364== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5600721fe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560078863898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5600788465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5600788464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560072204d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560072165b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560072160355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5600721f6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5600751c5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5600751c5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5600751c5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5600751c5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5600751c5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5600751c5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5600751c5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5600751c5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5600751c5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5600751c5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56007745af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560074187b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560074192be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560073f3ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560073f3ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560073f3f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560073f3e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560073f3e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560073f3e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560078848abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560078851928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560078839699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560078864112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3176785082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56007215eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x37,0x37,0x37,0x37,0x37,0x7a,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x35,0x37,0x37,0x37,0x37,0x37,0x37,0xa,0x60,0x21,0x60, Step #5: -------------------------------------------------77777z77777777775777777\012`!` Step #5: artifact_prefix='./'; Test unit written to ./oom-663ead2072a275d6dda38644c2abd64f9d7b355a Step #5: Base64: LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLTc3Nzc3ejc3Nzc3Nzc3Nzc1Nzc3Nzc3CmAhYA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3759 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3580137348 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a2092ae810, 0x55a20949801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a209498020,0x55a20b3300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/663ead2072a275d6dda38644c2abd64f9d7b355a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4660 processed earlier; will process 6369 files now Step #5: ==135400== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1ffda39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a206408898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2063eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2063eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1ffda9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1ffd0ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1ffd05355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1ffd9bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a202d6af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a202d6af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a202d6af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a202d6af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a202d6af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a202d6af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a202d6af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a202d6af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a202d6af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a202d6af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a204ffff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a201d2cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a201d37be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a201ae3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a201ae3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a201ae4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a201ae3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a201ae3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a201ae3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a2063edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a2063f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2063de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a206409112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f33f0179082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1ffd03b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x14,0x0,0x0,0x0,0x4,0x43,0x0,0x0,0xc,0x0,0x35,0x0,0x0,0x0,0x16,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x6c,0x6f,0x63,0x61,0x6c,0x68,0x6f,0x73,0x74,0x0,0x4,0xff,0xff,0xff,0x6,0x0,0x36,0x0,0x0,0x0,0x4,0x0,0x0,0x0,0x2,0x0,0x1,0x0,0x0,0x0,0x16,0x32,0x37,0x2e,0x30,0x2e,0x31,0x2e,0x31,0x32,0x37,0x2f,0x0,0x0,0x4,0x1,0x0,0x0,0x1,0x0,0x83,0xe5,0x0, Step #5: \001\024\000\000\000\004C\000\000\014\0005\000\000\000\026http://localhost\000\004\377\377\377\006\0006\000\000\000\004\000\000\000\002\000\001\000\000\000\02627.0.1.127/\000\000\004\001\000\000\001\000\203\345\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e2cdcd3577add3361cafe84c2e36d6dac574612e Step #5: Base64: ARQAAAAEQwAADAA1AAAAFmh0dHA6Ly9sb2NhbGhvc3QABP///wYANgAAAAQAAAACAAEAAAAWMjcuMC4xLjEyNy8AAAQBAAABAIPlAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3760 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3580632074 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56479e976810, 0x56479eb6001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56479eb60020,0x5647a09f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e2cdcd3577add3361cafe84c2e36d6dac574612e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4661 processed earlier; will process 6368 files now Step #5: ==135436== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56479546b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56479bad0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56479bab35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56479bab34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564795471d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647953d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647953cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564795463c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564798432f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564798432f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564798432f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564798432f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564798432f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564798432f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564798432f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564798432f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564798432f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564798432f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56479a6c7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647973f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647973ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647971abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647971abc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647971ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647971ab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647971ab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647971ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56479bab5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56479babe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56479baa6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56479bad1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f867d503082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647953cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x33,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x5b,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5e,0xdf,0xba,0x5d, Step #5: \023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\0233\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023[\001\000\000\000\000\000\000\000^\337\272] Step #5: artifact_prefix='./'; Test unit written to ./oom-91769eaaf7207e39db44c7a35322b1f6f677c4bf Step #5: Base64: ExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMzExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTWwEAAAAAAAAAXt+6XQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3761 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3581130959 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d20cee810, 0x563d20ed801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d20ed8020,0x563d22d700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/91769eaaf7207e39db44c7a35322b1f6f677c4bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4662 processed earlier; will process 6367 files now Step #5: ==135472== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563d177e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d1de48898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d1de2b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d1de2b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d177e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d1774ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d17745355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d177dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d1a7aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d1a7aaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d1a7aaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d1a7aaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d1a7aaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d1a7aaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d1a7aaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d1a7aaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d1a7aaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d1a7aaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d1ca3ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d1976cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d19777be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d19523c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d19523c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d19524738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d19523874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d19523874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d19523874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d1de2dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d1de36928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d1de1e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d1de49112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feac50a9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d17743b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x30,0x4f,0x59,0x65,0x77,0x64,0x61,0x31,0x48,0x41,0x6f,0x61,0x63,0x71,0x53,0x2b,0x6b,0x6d,0x48,0x6c,0x4c,0x42,0x43,0x41,0x41,0x70,0x50,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x48,0x65,0x4f,0x4f,0x4f,0x4b,0x4f,0xa,0x61,0x9,0x37,0x30,0x33,0x30,0x32,0x2e, Step #5: onion-key\012ntor-onion-key v0OYewda1HAoacqS+kmHlLBCAApPOOOOOOOOHeOOOKO\012a\01170302. Step #5: artifact_prefix='./'; Test unit written to ./oom-87c76390fe474c6319e5da8b4ce1659f4347180d Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHYwT1lld2RhMUhBb2FjcVMra21IbExCQ0FBcFBPT09PT09PT0hlT09PS08KYQk3MDMwMi4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3762 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3581634324 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f209ebf810, 0x55f20a0a901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f20a0a9020,0x55f20bf410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87c76390fe474c6319e5da8b4ce1659f4347180d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4663 processed earlier; will process 6366 files now Step #5: #1 pulse cov: 3821 ft: 3822 exec/s: 0 rss: 173Mb Step #5: ==135508== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f2009b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f207019898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f206ffc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f206ffc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f2009bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f20091bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f200916355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f2009acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f20397bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f20397bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f20397bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f20397bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f20397bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f20397bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f20397bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f20397bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f20397bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f20397bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f205c10f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f20293db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f202948be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f2026f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f2026f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f2026f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f2026f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f2026f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f2026f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f206ffeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f207007928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f206fef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f20701a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6432e84082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f200914b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x61,0x74,0x68,0x2e,0x61,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x62,0x73,0x28,0x57,0x29, Step #5: Math.a$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$bs(W) Step #5: artifact_prefix='./'; Test unit written to ./oom-c8a38ca9fce3464f3d21935ca936f7d32225c958 Step #5: Base64: TWF0aC5hJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkYnMoVyk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3763 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3582188865 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb375de810, 0x55eb377c801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb377c8020,0x55eb396600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c8a38ca9fce3464f3d21935ca936f7d32225c958' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4665 processed earlier; will process 6364 files now Step #5: ==135544== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eb2e0d39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb34738898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb3471b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb3471b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb2e0d9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb2e03ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb2e035355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb2e0cbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb3109af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb3109af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb3109af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb3109af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb3109af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb3109af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb3109af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb3109af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb3109af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb3109af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb3332ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb3005cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb30067be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb2fe13c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb2fe13c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb2fe14738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb2fe13874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb2fe13874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb2fe13874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb3471dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb34726928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb3470e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb34739112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ab3436082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb2e033b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x37,0x3a,0x5b,0x22,0xc3,0xbf,0xef,0xb7,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xdf,0x41,0x70,0x97,0x97,0x97,0x97,0x97,0x97,0x97,0x97,0x97,0x97,0x97,0x97,0x97,0x97,0xd2,0xff,0xff,0xff,0xff,0x26,0xff,0xff,0x6e,0x75,0x23,0x2c,0x4b,0x22,0x5d,0x7d,0x59,0x27,0xc3,0xff,0xff,0xff,0xff,0xff,0xff,0xbf,0x35,0x70,0x27,0x3a,0x3a,0x44,0x3a, Step #5: $3::{$7:[\"\303\277\357\267\277\357\277\277\357\277\277\357\277\277\357\277\277\337Ap\227\227\227\227\227\227\227\227\227\227\227\227\227\227\322\377\377\377\377&\377\377nu#,K\"]}Y'\303\377\377\377\377\377\377\2775p'::D: Step #5: artifact_prefix='./'; Test unit written to ./oom-b7789d77934734598eb1f9ec624d48442af67aff Step #5: Base64: JDM6OnskNzpbIsO/77e/77+/77+/77+/77+/30Fwl5eXl5eXl5eXl5eXl5fS/////yb//251IyxLIl19WSfD////////vzVwJzo6RDo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3764 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3582696070 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c804299810, 0x55c80448301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c804483020,0x55c80631b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7789d77934734598eb1f9ec624d48442af67aff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4666 processed earlier; will process 6363 files now Step #5: ==135580== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c7fad8e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8013f3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8013d65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8013d64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c7fad94d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c7facf5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c7facf0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7fad86c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7fdd55f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7fdd55f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7fdd55f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7fdd55f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7fdd55f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7fdd55f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7fdd55f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7fdd55f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7fdd55f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7fdd55f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7fffeaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7fcd17b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7fcd22be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7fcacec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7fcacec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7fcacf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7fcace874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7fcace874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7fcace874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8013d8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8013e1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8013c9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8013f4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f11629d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c7faceeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x1,0x0,0x0,0x0,0xa,0x72,0x54,0x53,0x70,0x3a,0x2f,0x2d,0x34,0x7e,0x57,0x0,0x11,0x0,0x0,0x0,0x37,0x52,0x54,0x53,0x50,0x2f,0x31,0x2e,0x30,0x20,0x33,0x35,0x37,0xa,0x63,0x6f,0x6e,0x74,0x45,0x6e,0x74,0x2d,0x6c,0x45,0x6e,0x67,0x74,0x68,0x3a,0x38,0x31,0x31,0x39,0x37,0x37,0x30,0x29,0x38,0x39,0x4e,0x32,0x37,0xa,0xa,0x0,0x0,0x24,0x24,0x24,0x24,0x20,0x31,0x30,0x6f,0x0,0x4, Step #5: \000\001\000\000\000\012rTSp:/-4~W\000\021\000\000\0007RTSP/1.0 357\012contEnt-lEngth:8119770)89N27\012\012\000\000$$$$ 10o\000\004 Step #5: artifact_prefix='./'; Test unit written to ./oom-49c70501e3c37a8bfb181693199b3606e86f4693 Step #5: Base64: AAEAAAAKclRTcDovLTR+VwARAAAAN1JUU1AvMS4wIDM1Nwpjb250RW50LWxFbmd0aDo4MTE5NzcwKTg5TjI3CgoAACQkJCQgMTBvAAQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3765 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3583202032 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5628fe50a810, 0x5628fe6f401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5628fe6f4020,0x56290058c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/49c70501e3c37a8bfb181693199b3606e86f4693' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4667 processed earlier; will process 6362 files now Step #5: ==135616== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5628f4fff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5628fb664898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5628fb6475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5628fb6474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5628f5005d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5628f4f66b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5628f4f61355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5628f4ff7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5628f7fc6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5628f7fc6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5628f7fc6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5628f7fc6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5628f7fc6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5628f7fc6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5628f7fc6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5628f7fc6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5628f7fc6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5628f7fc6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5628fa25bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5628f6f88b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5628f6f93be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5628f6d3fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5628f6d3fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5628f6d40738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5628f6d3f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5628f6d3f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5628f6d3f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5628fb649abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5628fb652928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5628fb63a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5628fb665112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e3144f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5628f4f5fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x61,0x73,0x6d,0x1,0x0,0x0,0x0,0x4,0x4,0x1,0x6f,0x0,0x57,0x0,0x2a,0x7,0x6c,0x69,0x6e,0x6b,0x69,0x6e,0x67,0x2,0x8,0x1f,0x59,0x5,0x25,0x0,0x1,0x56,0x5,0x24,0x0,0x1,0x1b,0x5,0x24,0x0,0x1,0x10,0x5,0x0,0x0,0xb,0x2a,0xb,0x38,0x3f,0x59,0x5,0x25,0x52,0x0,0x7d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x5,0x0,0x59,0x0,0x0,0xb1,0xb1,0x31,0x3,0x26,0x7,0x6d, Step #5: \000asm\001\000\000\000\004\004\001o\000W\000*\007linking\002\010\037Y\005%\000\001V\005$\000\001\033\005$\000\001\020\005\000\000\013*\0138?Y\005%R\000}\000\000\000\000\000\000\000\001\005\000Y\000\000\261\2611\003&\007m Step #5: artifact_prefix='./'; Test unit written to ./oom-41abe821c878584ff2814f73c42cf515cc32cfdb Step #5: Base64: AGFzbQEAAAAEBAFvAFcAKgdsaW5raW5nAggfWQUlAAFWBSQAARsFJAABEAUAAAsqCzg/WQUlUgB9AAAAAAAAAAEFAFkAALGxMQMmB20= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3766 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3583705698 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b6eaf70810, 0x55b6eb15a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b6eb15a020,0x55b6ecff20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/41abe821c878584ff2814f73c42cf515cc32cfdb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4668 processed earlier; will process 6361 files now Step #5: ==135652== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b6e1a659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b6e80ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b6e80ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b6e80ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6e1a6bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6e19ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6e19c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6e1a5dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b6e4a2cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b6e4a2cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b6e4a2cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b6e4a2cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b6e4a2cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b6e4a2cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b6e4a2cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b6e4a2cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b6e4a2cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b6e4a2cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b6e6cc1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6e39eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6e39f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6e37a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6e37a5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6e37a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6e37a5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6e37a5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6e37a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b6e80afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b6e80b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b6e80a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b6e80cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fddf17f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6e19c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6d,0x30,0xd1,0xb3,0x6c,0x6e,0xd1,0xb3,0x0,0x54,0xd2,0xa8,0x3d,0x6e,0xd1,0xbb,0x6c,0x6c,0xcd,0x8f,0x70,0x6c,0xd0,0xa9,0x3d,0x6e,0xd1,0xb3,0x7e,0x50,0xcd,0x8f,0x6e,0x6c,0xcd,0x8e,0x6d,0x7c,0xcd,0x8f,0x6e,0x6c,0xcd,0x8e,0x6e,0x6c,0xcd,0x8f,0x6e,0x6c,0xcd,0x8e,0x6e,0x6c,0xcd,0x8f,0x6e,0x6c,0xcd,0x8d,0x6e,0x50,0x8f,0x6e,0x6c,0xcd,0x6e,0x6b,0x6d,0x8e,0xa5,0x0,0x0,0x6c,0x6c,0xcd,0x4c, Step #5: m0\321\263ln\321\263\000T\322\250=n\321\273ll\315\217pl\320\251=n\321\263~P\315\217nl\315\216m|\315\217nl\315\216nl\315\217nl\315\216nl\315\217nl\315\215nP\217nl\315nkm\216\245\000\000ll\315L Step #5: artifact_prefix='./'; Test unit written to ./oom-aee2581b1d2adbdd72b9417891d7fef182cf5816 Step #5: Base64: bTDRs2xu0bMAVNKoPW7Ru2xszY9wbNCpPW7Rs35QzY9ubM2ObXzNj25szY5ubM2PbmzNjm5szY9ubM2NblCPbmzNbmttjqUAAGxszUw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3767 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3584208184 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0c37ca810, 0x55a0c39b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0c39b4020,0x55a0c584c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aee2581b1d2adbdd72b9417891d7fef182cf5816' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4669 processed earlier; will process 6360 files now Step #5: #1 pulse cov: 4067 ft: 4068 exec/s: 0 rss: 176Mb Step #5: ==135688== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0ba2bf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0c0924898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0c09075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0c09074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0ba2c5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0ba226b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0ba221355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0ba2b7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0bd286f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0bd286f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0bd286f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0bd286f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0bd286f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0bd286f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0bd286f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0bd286f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0bd286f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0bd286f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0bf51bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0bc248b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0bc253be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0bbfffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0bbfffc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0bc000738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0bbfff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0bbfff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0bbfff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0c0909abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0c0912928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0c08fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0c0925112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0eda60e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0ba21fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x45,0x20,0x20,0x75,0xa,0x43,0x3a,0x6d,0x75,0x6c,0x74,0x69,0x70,0x61,0x72,0x74,0x2f,0x6d,0x69,0x78,0x65,0x64,0x3b,0x62,0x6f,0x75,0x6e,0x64,0x61,0x72,0x79,0x3d,0xa,0xa,0x2d,0x2d,0xa,0x43,0x3a,0x21,0x2f,0x25,0xa,0x43,0x3a,0x60,0x2f,0x21,0xa,0x43,0x3a,0x60,0x2f,0x21,0xa,0x43,0x3a,0x60,0x2f,0x21,0xa,0x43,0x3a,0x60,0x2f,0x21,0xa,0x43,0x3a,0x60,0x2f,0x21,0xa,0x43,0x3a,0x60,0xa, Step #5: E u\012C:multipart/mixed;boundary=\012\012--\012C:!/%\012C:`/!\012C:`/!\012C:`/!\012C:`/!\012C:`/!\012C:`\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-1603d73f9334bfffd976ea8cc0ee7d3b52bf73ad Step #5: Base64: RSAgdQpDOm11bHRpcGFydC9taXhlZDtib3VuZGFyeT0KCi0tCkM6IS8lCkM6YC8hCkM6YC8hCkM6YC8hCkM6YC8hCkM6YC8hCkM6YAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3768 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3584879646 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b2dcfc2810, 0x55b2dd1ac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b2dd1ac020,0x55b2df0440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1603d73f9334bfffd976ea8cc0ee7d3b52bf73ad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4671 processed earlier; will process 6358 files now Step #5: ==135724== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b2d3ab79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b2da11c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b2da0ff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b2da0ff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b2d3abdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b2d3a1eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b2d3a19355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b2d3aafc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b2d6a7ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b2d6a7ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b2d6a7ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b2d6a7ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b2d6a7ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b2d6a7ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b2d6a7ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b2d6a7ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b2d6a7ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b2d6a7ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b2d8d13f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b2d5a40b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b2d5a4bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b2d57f7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b2d57f7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b2d57f8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b2d57f7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b2d57f7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b2d57f7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b2da101abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b2da10a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b2da0f2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b2da11d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f69e5196082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b2d3a17b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4e,0xd,0x60,0x4e,0xd,0xa,0x60,0xd,0x60,0xd,0xa,0x4e,0xd,0xa,0x60,0xd,0x60,0xf3,0xa0,0x81,0x8c,0xd,0xa,0x4e,0xd,0xf3,0xa0,0x80,0xab,0x60,0xd,0x60,0xd,0xa,0x4e,0xa,0x60,0xd,0x60,0xf3,0xa0,0x81,0x8c,0xd,0xa,0x4e,0xd,0xf3,0xa0,0x80,0xab,0x60,0xd,0x60,0xd,0xa,0x4e,0xd,0xa,0x32,0xd,0x60,0xd,0xd,0xa,0x4e,0xd,0xa,0x0,0x3d,0xa,0x81,0xb3,0xf3,0x3d,0xbc,0xa, Step #5: N\015`N\015\012`\015`\015\012N\015\012`\015`\363\240\201\214\015\012N\015\363\240\200\253`\015`\015\012N\012`\015`\363\240\201\214\015\012N\015\363\240\200\253`\015`\015\012N\015\0122\015`\015\015\012N\015\012\000=\012\201\263\363=\274\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-c976c55533276ad3f177eb036425f2b1c4f62c18 Step #5: Base64: Tg1gTg0KYA1gDQpODQpgDWDzoIGMDQpODfOggKtgDWANCk4KYA1g86CBjA0KTg3zoICrYA1gDQpODQoyDWANDQpODQoAPQqBs/M9vAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3769 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3585506753 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e41a08810, 0x563e41bf201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e41bf2020,0x563e43a8a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c976c55533276ad3f177eb036425f2b1c4f62c18' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4672 processed earlier; will process 6357 files now Step #5: ==135760== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563e384fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e3eb62898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e3eb455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e3eb454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e38503d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e38464b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e3845f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e384f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e3b4c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e3b4c4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e3b4c4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e3b4c4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e3b4c4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e3b4c4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e3b4c4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e3b4c4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e3b4c4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e3b4c4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e3d759f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e3a486b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e3a491be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e3a23dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e3a23dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e3a23e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e3a23d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e3a23d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e3a23d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e3eb47abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e3eb50928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e3eb38699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e3eb63112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcfeb2b9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e3845db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x33,0x41,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x5b,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5e,0xdf,0xba,0x5d, Step #5: \023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\0233A\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023[\001\000\000\000\000\000\000\000^\337\272] Step #5: artifact_prefix='./'; Test unit written to ./oom-919c32ee33bb2a297569cd1fc037dc5cbc76973f Step #5: Base64: ExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMzQRMTExMTExMTExMTExMTExMTExMTExMTExMTExMTE1sBAAAAAAAAAF7ful0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3770 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3586011790 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a8f62d5810, 0x55a8f64bf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a8f64bf020,0x55a8f83570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/919c32ee33bb2a297569cd1fc037dc5cbc76973f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4673 processed earlier; will process 6356 files now Step #5: ==135796== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a8ecdca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a8f342f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a8f34125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a8f34124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a8ecdd0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a8ecd31b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a8ecd2c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a8ecdc2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a8efd91f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a8efd91f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a8efd91f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a8efd91f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a8efd91f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a8efd91f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a8efd91f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a8efd91f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a8efd91f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a8efd91f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a8f2026f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a8eed53b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a8eed5ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a8eeb0ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a8eeb0ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a8eeb0b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a8eeb0a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a8eeb0a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a8eeb0a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a8f3414abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a8f341d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a8f3405699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a8f3430112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc0ebe5d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a8ecd2ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x24,0x0,0x26,0xa,0x26,0x24,0x0,0x0,0x0,0x24,0x0,0xa,0x27,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x27,0x29,0x27,0x3f,0x26,0x26,0x0,0x0,0x0,0x24,0x0,0xa,0x1,0x0,0x0,0x0,0xa,0x0,0xa,0xa, Step #5: \000\000$\000&\012&$\000\000\000$\000\012'>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>')'?&&\000\000\000$\000\012\001\000\000\000\012\000\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-144fd565a03c88a6b02facf2916c0aa4e68738f1 Step #5: Base64: AAAkACYKJiQAAAAkAAonPj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+JyknPyYmAAAAJAAKAQAAAAoACgo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3771 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3586518198 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5644682c0810, 0x5644684aa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5644684aa020,0x56446a3420e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/144fd565a03c88a6b02facf2916c0aa4e68738f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4674 processed earlier; will process 6355 files now Step #5: #1 pulse cov: 3700 ft: 3701 exec/s: 0 rss: 174Mb Step #5: ==135832== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56445edb59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56446541a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5644653fd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5644653fd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56445edbbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56445ed1cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56445ed17355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56445edadc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564461d7cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564461d7cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564461d7cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564461d7cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564461d7cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564461d7cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564461d7cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564461d7cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564461d7cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564461d7cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564464011f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564460d3eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564460d49be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564460af5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564460af5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564460af6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564460af5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564460af5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564460af5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5644653ffabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564465408928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5644653f0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56446541b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5215e06082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56445ed15b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x3d,0x7e,0xb,0x2d,0x3d,0x33,0x1,0x29,0x0,0x0,0x0,0x79,0x24,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e, Step #5: ~$=~\013-=3\001)\000\000\000y$~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Step #5: artifact_prefix='./'; Test unit written to ./oom-514701743cef478a1404830da58654603ce1c754 Step #5: Base64: fiQ9fgstPTMBKQAAAHkkfn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3772 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3587062471 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562b18935810, 0x562b18b1f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562b18b1f020,0x562b1a9b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/514701743cef478a1404830da58654603ce1c754' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4676 processed earlier; will process 6353 files now Step #5: ==135868== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562b0f42a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562b15a8f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562b15a725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562b15a724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b0f430d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b0f391b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b0f38c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b0f422c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b123f1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b123f1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b123f1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b123f1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b123f1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b123f1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b123f1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b123f1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b123f1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b123f1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562b14686f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b113b3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b113bebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b1116ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b1116ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b1116b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b1116a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b1116a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b1116a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562b15a74abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562b15a7d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562b15a65699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562b15a90112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5a26449082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b0f38ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x20,0x30,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x24,0x3a,0x3a,0x2d,0x2d,0x5b,0xee,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\000/\000\017\017\017\017\0171-\017[\017\0171-\017[-\017\017\017\017\0171\021\0171\017s [8 0\017\017\017\0171\017-1[&\021:\021-\017\017\017\017\0171\021\0171\021$::--[\356$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-958aec5798b066a1621dd547be67a61c400c9815 Step #5: Base64: JAAALwAAAC8AAC8ADw8PDw8xLQ9bDw8xLQ9bLQ8PDw8PMREPMQ9zIFs4IDAPDw8PMQ8tMVsmEToRLQ8PDw8PMREPMREkOjotLVvuJFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3773 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3587568463 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560797464810, 0x56079764e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56079764e020,0x5607994e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/958aec5798b066a1621dd547be67a61c400c9815' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4677 processed earlier; will process 6352 files now Step #5: #1 pulse cov: 4073 ft: 4074 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4475 ft: 4850 exec/s: 0 rss: 177Mb Step #5: ==135904== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56078df599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5607945be898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5607945a15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5607945a14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56078df5fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56078dec0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56078debb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56078df51c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560790f20f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560790f20f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560790f20f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560790f20f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560790f20f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560790f20f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560790f20f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560790f20f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560790f20f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560790f20f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5607931b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56078fee2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56078feedbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56078fc99c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56078fc99c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56078fc9a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56078fc99874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56078fc99874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56078fc99874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5607945a3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5607945ac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560794594699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5607945bf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68bd125082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56078deb9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x70,0x68,0x70,0xa,0xa,0x23,0x5b,0x44,0x65,0x6c,0x61,0x79,0x65,0x64,0x54,0x61,0x72,0x67,0x65,0x74,0x56,0x61,0x6c,0x69,0x64,0x61,0x74,0x69,0x6f,0x6e,0x5d,0xa,0x23,0x5b,0x4e,0x6f,0x44,0x69,0x73,0x63,0x61,0x72,0x64,0x5d,0xa,0x23,0x5b,0x4e,0x6f,0x44,0x69,0x73,0x63,0x61,0x72,0x64,0x5d,0xa,0x63,0x6c,0x61,0x73,0x73,0x20,0x44,0x65,0x6d,0x6f,0x20,0x7b,0x7d,0xa,0xa,0x3f,0x3e, Step #5: <?php\012\012#[DelayedTargetValidation]\012#[NoDiscard]\012#[NoDiscard]\012class Demo {}\012\012?> Step #5: artifact_prefix='./'; Test unit written to ./oom-b69ece133e6548f761a91ce52c79992066ccae5b Step #5: Base64: PD9waHAKCiNbRGVsYXllZFRhcmdldFZhbGlkYXRpb25dCiNbTm9EaXNjYXJkXQojW05vRGlzY2FyZF0KY2xhc3MgRGVtbyB7fQoKPz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3774 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3588153065 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564f00c4e810, 0x564f00e3801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564f00e38020,0x564f02cd00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b69ece133e6548f761a91ce52c79992066ccae5b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4680 processed earlier; will process 6349 files now Step #5: ==135940== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564ef77439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564efdda8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564efdd8b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564efdd8b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ef7749d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ef76aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ef76a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ef773bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564efa70af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564efa70af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564efa70af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564efa70af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564efa70af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564efa70af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564efa70af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564efa70af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564efa70af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564efa70af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564efc99ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564ef96ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564ef96d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564ef9483c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564ef9483c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564ef9484738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564ef9483874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564ef9483874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564ef9483874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564efdd8dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564efdd96928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564efdd7e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564efdda9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f998459d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ef76a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x7e,0x3c,0xdb,0xbe,0xdb,0xbe,0x7e,0x73,0x73,0x1,0x2d,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x7a,0x25,0x25,0xb,0x0,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x25,0x25,0x25,0x25,0x25,0x25,0x73,0x73,0x7e,0x31,0x73, Step #5: -~<\333\276\333\276~ss\001-sssssss%%%%%%%%%%%%%%%%%%%%%%z%%\013\000%%%%%%%%%%%sssssssss%%%%%%ss~1s Step #5: artifact_prefix='./'; Test unit written to ./oom-e4a2c16fa4d777f13dadb5b4b62ea8a8fd30a626 Step #5: Base64: LX48277bvn5zcwEtc3Nzc3NzcyUlJSUlJSUlJSUlJSUlJSUlJSUlJSV6JSULACUlJSUlJSUlJSUlc3Nzc3Nzc3NzJSUlJSUlc3N+MXM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3775 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3588655156 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d9278db810, 0x55d927ac501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d927ac5020,0x55d92995d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e4a2c16fa4d777f13dadb5b4b62ea8a8fd30a626' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4681 processed earlier; will process 6348 files now Step #5: ==135976== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d91e3d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d924a35898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d924a185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d924a184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d91e3d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d91e337b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d91e332355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d91e3c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d921397f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d921397f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d921397f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d921397f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d921397f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d921397f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d921397f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d921397f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d921397f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d921397f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d92362cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d920359b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d920364be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d920110c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d920110c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d920111738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d920110874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d920110874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d920110874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d924a1aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d924a23928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d924a0b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d924a36112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1ced99c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d91e330b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x3b,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0x31,0x31,0xf,0x2d,0x5b,0x24,0x11,0xf,0x2a,0x0,0x0,0x0,0x0,0x0,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x74,0x70,0x3a,0x2f,0x2f,0x64,0xa,0x64,0x0,0x0,0x0,0x8,0x2a,0x0,0x0,0x0,0x0,0x0,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x74,0x70,0x3a,0x2f,0x2f,0xa,0xaf,0xd2,0xa,0x0,0xa,0x2d,0x4d,0x26,0x61,0x6e,0x5b, Step #5: $\000;\000/\000\000\000/\000\017\017\017\01711\017-[$\021\017*\000\000\000\000\000\012-\012d\012d\012tp://d\012d\000\000\000\010*\000\000\000\000\000\012-\012d\012d\012tp://\012\257\322\012\000\012-M&an[ Step #5: artifact_prefix='./'; Test unit written to ./oom-9dddee8a9b75b6bd7d1760f4bad7943a1e2af6fc Step #5: Base64: JAA7AC8AAAAvAA8PDw8xMQ8tWyQRDyoAAAAAAAotCmQKZAp0cDovL2QKZAAAAAgqAAAAAAAKLQpkCmQKdHA6Ly8Kr9IKAAotTSZhbls= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3776 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3589168044 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f29a015810, 0x55f29a1ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f29a1ff020,0x55f29c0970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9dddee8a9b75b6bd7d1760f4bad7943a1e2af6fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4682 processed earlier; will process 6347 files now Step #5: ==136012== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f290b0a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f29716f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f2971525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f2971524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f290b10d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f290a71b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f290a6c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f290b02c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f293ad1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f293ad1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f293ad1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f293ad1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f293ad1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f293ad1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f293ad1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f293ad1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f293ad1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f293ad1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f295d66f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f292a93b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f292a9ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f29284ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f29284ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f29284b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f29284a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f29284a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f29284a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f297154abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f29715d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f297145699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f297170112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc8f956f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f290a6ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c,0x75,0x67,0x61,0x67,0x0,0x0,0x0,0x0,0x0,0x10,0x0,0x0,0x0,0x0,0x30,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4f,0x1,0x0,0x0,0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x49,0x49,0x49,0x25,0x0,0x0,0x0,0x0,0x0,0x67,0x1e,0x1e,0x1e,0x1e,0x6e, Step #5: lugag\000\000\000\000\000\020\000\000\000\0000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000O\001\000\000/\000\000\000\000\000\000\000\000\000\000\000III%\000\000\000\000\000g\036\036\036\036n Step #5: artifact_prefix='./'; Test unit written to ./oom-e2e6b5fa00eb271b398582b86b853ba9e02feeb6 Step #5: Base64: bHVnYWcAAAAAABAAAAAAMAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAE8BAAAvAAAAAAAAAAAAAABJSUklAAAAAABnHh4eHm4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3777 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3589669506 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b3151ac810, 0x55b31539601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b315396020,0x55b31722e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e2e6b5fa00eb271b398582b86b853ba9e02feeb6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4683 processed earlier; will process 6346 files now Step #5: #1 pulse cov: 3955 ft: 3956 exec/s: 0 rss: 173Mb Step #5: ==136048== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b30bca19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b312306898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b3122e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b3122e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b30bca7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b30bc08b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b30bc03355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b30bc99c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b30ec68f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b30ec68f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b30ec68f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b30ec68f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b30ec68f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b30ec68f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b30ec68f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b30ec68f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b30ec68f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b30ec68f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b310efdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b30dc2ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b30dc35be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b30d9e1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b30d9e1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b30d9e2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b30d9e1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b30d9e1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b30d9e1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b3122ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b3122f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b3122dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b312307112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdfe76e8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b30bc01b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0xa,0x33,0x3,0x0,0x0,0x20,0x47,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x73,0x74,0x72,0x65,0x61,0x6d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x30,0x47,0x32,0x50, Step #5: \001\0123\003\000\000 G\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000stream\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0000G2P Step #5: artifact_prefix='./'; Test unit written to ./oom-ca99fe7db54ccc422bf07318b77bf815e27846f5 Step #5: Base64: AQozAwAAIEcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAc3RyZWFtAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwRzJQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3778 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3590218167 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559f93c7d810, 0x559f93e6701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559f93e67020,0x559f95cff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca99fe7db54ccc422bf07318b77bf815e27846f5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4685 processed earlier; will process 6344 files now Step #5: #1 pulse cov: 4253 ft: 4254 exec/s: 0 rss: 174Mb Step #5: ==136084== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559f8a7729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559f90dd7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559f90dba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559f90dba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559f8a778d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559f8a6d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559f8a6d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559f8a76ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559f8d739f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559f8d739f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559f8d739f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559f8d739f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559f8d739f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559f8d739f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559f8d739f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559f8d739f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559f8d739f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559f8d739f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559f8f9cef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559f8c6fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559f8c706be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559f8c4b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559f8c4b2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559f8c4b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559f8c4b2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559f8c4b2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559f8c4b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559f90dbcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559f90dc5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559f90dad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559f90dd8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb36085f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559f8a6d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x18,0x24,0xa,0xc2,0xbd,0x7f,0x27,0x28,0x28,0x28,0x28,0x24,0x7b,0x31,0x7d,0x0,0x7b,0x31,0x31,0x7d,0x78,0x7b,0x32,0x7d,0x29,0x3,0x0,0x0,0x0,0x7b,0x32,0x7d,0x29,0x7b,0x33,0x7d,0xd7,0x84,0xcd,0xff,0xff,0xff,0xff,0xff,0x29,0x7b,0x18,0x3,0x58,0x31,0x63,0x28,0xa,0x8,0x18,0x3,0x58,0x31,0x0,0x43,0x48,0x41,0xff,0xff,0xff,0xff,0xff,0x29,0x7b,0x73,0x11,0x32,0x7d,0xe0,0xa1,0xb0,0x47, Step #5: (\030$\012\302\275\177'((((${1}\000{11}x{2})\003\000\000\000{2}){3}\327\204\315\377\377\377\377\377){\030\003X1c(\012\010\030\003X1\000CHA\377\377\377\377\377){s\0212}\340\241\260G Step #5: artifact_prefix='./'; Test unit written to ./oom-0aac52b918bc8c08649b8a939a40d8f9dca0f520 Step #5: Base64: KBgkCsK9fycoKCgoJHsxfQB7MTF9eHsyfSkDAAAAezJ9KXszfdeEzf//////KXsYA1gxYygKCBgDWDEAQ0hB//////8pe3MRMn3gobBH Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3779 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3590764286 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e3a51fa810, 0x55e3a53e401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e3a53e4020,0x55e3a727c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0aac52b918bc8c08649b8a939a40d8f9dca0f520' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4687 processed earlier; will process 6342 files now Step #5: #1 pulse cov: 4053 ft: 4054 exec/s: 0 rss: 175Mb Step #5: ==136120== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e39bcef9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e3a2354898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e3a23375dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e3a23374fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e39bcf5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e39bc56b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e39bc51355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e39bce7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e39ecb6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e39ecb6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e39ecb6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e39ecb6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e39ecb6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e39ecb6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e39ecb6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e39ecb6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e39ecb6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e39ecb6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e3a0f4bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e39dc78b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e39dc83be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e39da2fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e39da2fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e39da30738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e39da2f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e39da2f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e39da2f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e3a2339abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e3a2342928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e3a232a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e3a2355112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a24167082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e39bc4fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $22-=<'''/''''/''''''2-=''''''''''-=<'''/''''/''''''2-='''''''''''''.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-638b13d43e5e054e3456567804d8a73fa00c7370 Step #5: Base64: JDIyLT08JycnLycnJycvJycnJycnMi09JycnJycnJycnJy09PCcnJy8nJycnLycnJycnJzItPScnJycnJycnJycnJycuJycnJy4nJCct Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3780 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3591314483 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5563a0b2a810, 0x5563a0d1401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5563a0d14020,0x5563a2bac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/638b13d43e5e054e3456567804d8a73fa00c7370' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4689 processed earlier; will process 6340 files now Step #5: ==136156== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55639761f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55639dc84898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55639dc675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55639dc674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556397625d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556397586b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556397581355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556397617c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55639a5e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55639a5e6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55639a5e6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55639a5e6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55639a5e6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55639a5e6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55639a5e6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55639a5e6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55639a5e6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55639a5e6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55639c87bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5563995a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5563995b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55639935fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55639935fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556399360738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55639935f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55639935f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55639935f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55639dc69abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55639dc72928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55639dc5a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55639dc85112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffaeea2d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55639757fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc,0x4d,0x7e,0x12,0x4d,0x7e,0x7e,0x7e,0x1f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x63,0x43,0x43,0x43,0x43,0x43,0x7e,0x7e,0x12, Step #5: \014M~\022M~~~\037\000\000\000\000\000\000\000\000\002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000CCCCCCCCCCCCCCCCCCCCCcCCCCC~~\022 Step #5: artifact_prefix='./'; Test unit written to ./oom-2d2472e19dec1b6b92375ba886b769d0f28b8d94 Step #5: Base64: DE1+Ek1+fn4fAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDY0NDQ0NDfn4S Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3781 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3591817209 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b37975f810, 0x55b37994901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b379949020,0x55b37b7e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2d2472e19dec1b6b92375ba886b769d0f28b8d94' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4690 processed earlier; will process 6339 files now Step #5: ==136192== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b3702549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b3768b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b37689c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b37689c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b37025ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b3701bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b3701b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b37024cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b37321bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b37321bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b37321bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b37321bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b37321bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b37321bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b37321bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b37321bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b37321bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b37321bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b3754b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b3721ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b3721e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b371f94c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b371f94c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b371f95738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b371f94874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b371f94874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b371f94874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b37689eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b3768a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b37688f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b3768ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7eff8cc81082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b3701b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x42,0x1,0x0,0x0,0x0,0x0,0x0,0x2d,0x1f,0x44,0x2d,0x0,0x2d,0x33,0x3,0x6d,0xc5,0x83,0xcf,0x83,0xc5,0x83,0xc5,0xa7,0xcf,0x83,0xc5,0x83,0xc5,0x83,0xcc,0x83,0xc5,0x83,0xc3,0x84,0xc5,0x8a,0x3b,0x9c,0x78,0x21,0x74,0x1,0x33,0x3,0x3c,0x6d,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x60,0xdb,0x1,0x33,0x3,0x3c,0x6d,0x60,0xdb,0x9e,0x3,0x32,0xdb,0xa5,0x32, Step #5: IB\001\000\000\000\000\000-\037D-\000-3\003m\305\203\317\203\305\203\305\247\317\203\305\203\305\203\314\203\305\203\303\204\305\212;\234x!t\0013\003<m++++++++++++++`\333\0013\003<m`\333\236\0032\333\2452 Step #5: artifact_prefix='./'; Test unit written to ./oom-6a368f5010bd5c2894733accbbf17c67cb3738b5 Step #5: Base64: SUIBAAAAAAAtH0QtAC0zA23Fg8+DxYPFp8+DxYPFg8yDxYPDhMWKO5x4IXQBMwM8bSsrKysrKysrKysrKysrYNsBMwM8bWDbngMy26Uy Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3782 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3592315614 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ecfd858810, 0x55ecfda4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ecfda42020,0x55ecff8da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a368f5010bd5c2894733accbbf17c67cb3738b5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4691 processed earlier; will process 6338 files now Step #5: ==136228== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ecf434d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ecfa9b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ecfa9955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ecfa9954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ecf4353d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ecf42b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ecf42af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ecf4345c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ecf7314f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ecf7314f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ecf7314f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ecf7314f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ecf7314f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ecf7314f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ecf7314f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ecf7314f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ecf7314f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ecf7314f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ecf95a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ecf62d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ecf62e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ecf608dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ecf608dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ecf608e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ecf608d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ecf608d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ecf608d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ecfa997abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ecfa9a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ecfa988699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ecfa9b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff91a07b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ecf42adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x67,0x74,0x46,0x2d,0x31,0x65,0x72,0xa,0x3c,0x3c,0x25,0x50,0x44,0x46,0x2d,0x31,0x2e,0x37,0xa,0xe3,0x80,0x80,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0xa,0x3c,0x3c,0x28,0x2f,0x52,0x37,0x0,0x0,0x0,0x0,0x0,0x0,0x7b,0x3c,0x25,0x50,0x44,0x46,0x2d,0x31,0x2e,0x37,0xa,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0xa,0x3c,0x3c,0x28,0x2f,0x52,0xa,0x5c,0xd,0x8,0x0,0x3,0x0,0x0,0x0, Step #5: %gtF-1er\012<<%PDF-1.7\012\343\200\200\012trailer\012<<(/R7\000\000\000\000\000\000{<%PDF-1.7\012\012trailer\012<<(/R\012\\\015\010\000\003\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-47803a02d1c55a4679f9b38730618adacd73062a Step #5: Base64: JWd0Ri0xZXIKPDwlUERGLTEuNwrjgIAKdHJhaWxlcgo8PCgvUjcAAAAAAAB7PCVQREYtMS43Cgp0cmFpbGVyCjw8KC9SClwNCAADAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3783 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3592818516 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b79ee81810, 0x55b79f06b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b79f06b020,0x55b7a0f030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/47803a02d1c55a4679f9b38730618adacd73062a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4692 processed earlier; will process 6337 files now Step #5: ==136264== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b7959769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b79bfdb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b79bfbe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b79bfbe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b79597cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b7958ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b7958d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b79596ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b79893df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b79893df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b79893df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b79893df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b79893df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b79893df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b79893df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b79893df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b79893df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b79893df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b79abd2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b7978ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b79790abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b7976b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b7976b6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b7976b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b7976b6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b7976b6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b7976b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b79bfc0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b79bfc9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b79bfb1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b79bfdc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0eb0db6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b7958d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0xcd,0x9a,0xcd,0x9a,0xcc,0x9e,0x2c,0x75,0xcd,0x9a,0x2c,0xcd,0x9a,0xcc,0x9e,0x32,0xcf,0x99,0x6e,0xcc,0x9e,0xcf,0x99,0x65,0xcc,0x9e,0x2c,0xcc,0x9a,0xcc,0x9e,0x2c,0x33,0xcd,0x9a,0xcc,0x9e,0x31,0xcd,0x99,0xcd,0x9a,0xdf,0x9e,0xcd,0x9a,0xcc,0x9e,0x2c,0x33,0xcd,0x9a,0x33,0xcd,0x9a,0xcc,0x9e,0x32,0xcf,0x99,0x6e,0xcc,0x9e,0xcf,0x99,0xcd,0x9a,0xdf,0x9e,0x38,0xcd,0x9a,0xdf,0x9e,0x2c,0x7d,0x3a, Step #5: {\315\232\315\232\314\236,u\315\232,\315\232\314\2362\317\231n\314\236\317\231e\314\236,\314\232\314\236,3\315\232\314\2361\315\231\315\232\337\236\315\232\314\236,3\315\2323\315\232\314\2362\317\231n\314\236\317\231\315\232\337\2368\315\232\337\236,}: Step #5: artifact_prefix='./'; Test unit written to ./oom-93d0cc8c6b1f4076b495448515d92bcdafa576d4 Step #5: Base64: e82azZrMnix1zZoszZrMnjLPmW7Mns+ZZcyeLMyazJ4sM82azJ4xzZnNmt+ezZrMniwzzZozzZrMnjLPmW7Mns+ZzZrfnjjNmt+eLH06 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3784 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3593319302 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e8e9da810, 0x563e8ebc401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e8ebc4020,0x563e90a5c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93d0cc8c6b1f4076b495448515d92bcdafa576d4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4693 processed earlier; will process 6336 files now Step #5: ==136300== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563e854cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e8bb34898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e8bb175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e8bb174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e854d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e85436b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e85431355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e854c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e88496f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e88496f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e88496f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e88496f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e88496f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e88496f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e88496f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e88496f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e88496f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e88496f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e8a72bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e87458b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e87463be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e8720fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e8720fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e87210738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e8720f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e8720f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e8720f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e8bb19abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e8bb22928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e8bb0a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e8bb35112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc03c2a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e8542fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x44,0x33,0x4,0x27,0x0,0x0,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x61,0x27,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x0,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x3a,0x42,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x17,0x54,0x59,0x36,0x45,0x4,0x27,0x0,0x1,0x60,0x27,0x4,0x0,0x61,0x27,0x17,0x54,0x59,0x33,0x45,0x27,0x4,0x21,0x54,0x0,0x0,0x60,0x17,0x59,0x15,0x10,0x0,0x45,0x15,0x0,0x10, Step #5: ID3\004D3\004'\000\000{{{{{{a'{{{{{{\000{{{{{{{{:B{{{{{{{\027TY6E\004'\000\001`'\004\000a'\027TY3E'\004!T\000\000`\027Y\025\020\000E\025\000\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-f16f5089a6363817101b925119b4ea74415bce9a Step #5: Base64: SUQzBEQzBCcAAHt7e3t7e2Ene3t7e3t7AHt7e3t7e3t7OkJ7e3t7e3t7F1RZNkUEJwABYCcEAGEnF1RZM0UnBCFUAABgF1kVEABFFQAQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3785 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3593944599 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562809e29810, 0x56280a01301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56280a013020,0x56280beab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f16f5089a6363817101b925119b4ea74415bce9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4694 processed earlier; will process 6335 files now Step #5: ==136336== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56280091e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562806f83898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562806f665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562806f664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562800924d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562800885b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562800880355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562800916c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5628038e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5628038e5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5628038e5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5628038e5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5628038e5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5628038e5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5628038e5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5628038e5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5628038e5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5628038e5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562805b7af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5628028a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5628028b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56280265ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56280265ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56280265f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56280265e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56280265e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56280265e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562806f68abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562806f71928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562806f59699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562806f84112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3fb720b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56280087eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x64,0x0,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $22-=<'''/'''d\000''''''2-=''''''''''-=<'''/''''/''''''2-='''''''''''''.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-abb14ada8bdb826127b3068f1e7bb2ac5f1502c3 Step #5: Base64: JDIyLT08JycnLycnJ2QAJycnJycnMi09JycnJycnJycnJy09PCcnJy8nJycnLycnJycnJzItPScnJycnJycnJycnJycuJycnJy4nJCct Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3786 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3594452097 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5603ca25e810, 0x5603ca44801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5603ca448020,0x5603cc2e00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/abb14ada8bdb826127b3068f1e7bb2ac5f1502c3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4695 processed earlier; will process 6334 files now Step #5: ==136372== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5603c0d539c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5603c73b8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5603c739b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5603c739b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5603c0d59d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5603c0cbab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5603c0cb5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5603c0d4bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5603c3d1af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5603c3d1af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5603c3d1af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5603c3d1af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5603c3d1af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5603c3d1af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5603c3d1af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5603c3d1af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5603c3d1af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5603c3d1af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5603c5faff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5603c2cdcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5603c2ce7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5603c2a93c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5603c2a93c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5603c2a94738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5603c2a93874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5603c2a93874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5603c2a93874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5603c739dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5603c73a6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5603c738e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5603c73b9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1f75187082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5603c0cb3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x30,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x67,0x7b,0x30,0x3e,0x2a,0x7b,0x6c,0x3c,0x67,0x3e,0x67,0x3e,0x2a,0x7b,0x6f,0x70,0x61,0x63,0x69,0x74,0x79,0x3a,0x2d,0x35,0x35,0x31,0x2d,0x39,0x37,0x2c,0x30,0x6e,0x6e,0x2c,0x38,0xd7,0x81,0x70,0x6f,0x36,0x45,0x37,0x7d,0x3c,0x7a,0x67,0x3e,0x3c,0x67,0x3e,0x37,0xd7,0x81,0x70,0x6f,0x7d,0x31,0x36,0x45,0x37,0x7d,0x3c,0x3d,0x3c, Step #5: <svg>0><style>g{0>*{l<g>g>*{opacity:-551-97,0nn,8\327\201po6E7}<zg><g>7\327\201po}16E7}<=< Step #5: artifact_prefix='./'; Test unit written to ./oom-dbc05e925a3d7c874f09f2382356d666aa116f90 Step #5: Base64: PHN2Zz4wPjxzdHlsZT5nezA+KntsPGc+Zz4qe29wYWNpdHk6LTU1MS05Nywwbm4sONeBcG82RTd9PHpnPjxnPjfXgXBvfTE2RTd9PD08 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3787 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3594955514 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d67a9aa810, 0x55d67ab9401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d67ab94020,0x55d67ca2c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dbc05e925a3d7c874f09f2382356d666aa116f90' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4696 processed earlier; will process 6333 files now Step #5: ==136408== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d67149f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d677b04898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d677ae75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d677ae74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d6714a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d671406b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d671401355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d671497c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d674466f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d674466f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d674466f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d674466f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d674466f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d674466f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d674466f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d674466f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d674466f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d674466f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d6766fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d673428b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d673433be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d6731dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d6731dfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d6731e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d6731df874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d6731df874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d6731df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d677ae9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d677af2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d677ada699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d677b05112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa20b879082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d6713ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0xa,0xa,0x3a,0xb,0x3a,0xb,0x78,0x2e,0xa,0xe,0x6e,0x78,0xa,0x2e,0xa,0x22,0x74,0x78,0x6e,0x62,0x60,0x66,0x2e,0xd,0x60,0x66,0x78,0x2e,0xa,0xe,0x6e,0x78,0xa,0x3a,0xb,0x3a,0xb,0x78,0x2e,0xa,0xe,0x6e,0x78,0xa,0x2e,0xa,0x22,0x74,0x78,0x6e,0x62,0x60,0x66,0x2e,0xd,0x60,0x66,0x78,0x2e,0xa,0xe,0x6e,0x78,0xa,0x2e,0xa,0x22,0x74,0x78,0x6e,0x62,0x60,0x66,0xa,0xd,0x60,0x66, Step #5: 2\012\012:\013:\013x.\012\016nx\012.\012\"txnb`f.\015`fx.\012\016nx\012:\013:\013x.\012\016nx\012.\012\"txnb`f.\015`fx.\012\016nx\012.\012\"txnb`f\012\015`f Step #5: artifact_prefix='./'; Test unit written to ./oom-7f80667ae7a0743bcf62e13874ac1222ea428476 Step #5: Base64: MgoKOgs6C3guCg5ueAouCiJ0eG5iYGYuDWBmeC4KDm54CjoLOgt4LgoObngKLgoidHhuYmBmLg1gZnguCg5ueAouCiJ0eG5iYGYKDWBm Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3788 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3595577069 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55803e3be810, 0x55803e5a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55803e5a8020,0x5580404400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f80667ae7a0743bcf62e13874ac1222ea428476' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4697 processed earlier; will process 6332 files now Step #5: ==136444== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558034eb39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55803b518898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55803b4fb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55803b4fb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558034eb9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558034e1ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558034e15355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558034eabc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558037e7af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558037e7af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558037e7af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558037e7af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558037e7af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558037e7af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558037e7af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558037e7af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558037e7af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558037e7af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55803a10ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558036e3cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558036e47be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558036bf3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558036bf3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558036bf4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558036bf3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558036bf3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558036bf3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55803b4fdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55803b506928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55803b4ee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55803b519112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff5b2edb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558034e13b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x0,0x25,0x6e,0x0,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x4d,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x44,0x0,0x98,0xdf,0x4d,0x12,0x8b,0x61,0x7a,0x0,0x0, Step #5: D\000%n\000CCCCCCCCCCCCCCCCCCCCCCCMCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCD\000\230\337M\022\213az\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5e8d10b9ca7c8e187da9c14e0b7a9e1b0a88be59 Step #5: Base64: RAAlbgBDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ01DQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0QAmN9NEothegAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3789 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3596074216 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b4e560810, 0x558b4e74a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b4e74a020,0x558b505e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e8d10b9ca7c8e187da9c14e0b7a9e1b0a88be59' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4698 processed earlier; will process 6331 files now Step #5: #1 pulse cov: 3936 ft: 3937 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4474 ft: 4906 exec/s: 0 rss: 176Mb Step #5: ==136480== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558b450559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b4b6ba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b4b69d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b4b69d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b4505bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b44fbcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b44fb7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b4504dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b4801cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b4801cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b4801cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b4801cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b4801cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b4801cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b4801cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b4801cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b4801cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b4801cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b4a2b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b46fdeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b46fe9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b46d95c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b46d95c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b46d96738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b46d95874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b46d95874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b46d95874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b4b69fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b4b6a8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b4b690699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b4b6bb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f04467ba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b44fb5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0xa,0x30,0x30,0x21,0x1,0x27,0x0,0x24,0x1,0x27,0x21,0xdc,0xbd,0x2f,0x73,0x20,0x31,0x38,0x32,0x34,0x31,0x33,0x39,0x31,0x38,0x20,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x31,0x33,0x39,0x31,0x38,0x20,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x2d,0x31,0x69,0x1,0x0,0x0,0x41,0x7e,0x24,0x3d, Step #5: \001\01200!\001'\000$\001'!\334\275/s 182413918 34028236692093813918 340282366920938463463-1i\001\000\000A~$= Step #5: artifact_prefix='./'; Test unit written to ./oom-a7f945812bb605641e503c792827f42f7383052f Step #5: Base64: AQowMCEBJwAkASch3L0vcyAxODI0MTM5MTggMzQwMjgyMzY2OTIwOTM4MTM5MTggMzQwMjgyMzY2OTIwOTM4NDYzNDYzLTFpAQAAQX4kPQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3790 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3596660699 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5563ff637810, 0x5563ff82101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5563ff821020,0x5564016b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a7f945812bb605641e503c792827f42f7383052f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4701 processed earlier; will process 6328 files now Step #5: ==136516== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5563f612c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5563fc791898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5563fc7745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5563fc7744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5563f6132d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5563f6093b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5563f608e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5563f6124c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5563f90f3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5563f90f3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5563f90f3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5563f90f3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5563f90f3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5563f90f3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5563f90f3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5563f90f3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5563f90f3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5563f90f3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5563fb388f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5563f80b5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5563f80c0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5563f7e6cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5563f7e6cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5563f7e6d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5563f7e6c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5563f7e6c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5563f7e6c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5563fc776abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5563fc77f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5563fc767699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5563fc792112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe5f3509082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5563f608cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x76,0x2f,0x31,0x1,0x2,0x2,0x0,0x0,0x74,0x69,0x6c,0x65,0x65,0x6c,0x73,0x0,0x72,0x61,0x74,0x69,0x6f,0x6e,0x61,0x6c,0x0,0x74,0x69,0x6c,0x65,0x65,0x6c,0x73,0x0,0x72,0x61,0x74,0x69,0x6f,0x6e,0x61,0x6c,0x0,0x74,0x69,0x6c,0x65,0x65,0x6c,0x73,0x0,0x72,0x61,0x74,0x29,0x6f,0x6e,0x61,0x6c,0x0,0x0,0x0,0xff,0x1,0x2,0x0,0x72,0x61,0x74,0x69,0x6f,0x6e,0x61,0x6c,0x0,0x0,0xff,0xff,0x57,0x69, Step #5: v/1\001\002\002\000\000tileels\000rational\000tileels\000rational\000tileels\000rat)onal\000\000\000\377\001\002\000rational\000\000\377\377Wi Step #5: artifact_prefix='./'; Test unit written to ./oom-eb539e9f725d53737c1214acf743d726aae4bda3 Step #5: Base64: di8xAQICAAB0aWxlZWxzAHJhdGlvbmFsAHRpbGVlbHMAcmF0aW9uYWwAdGlsZWVscwByYXQpb25hbAAAAP8BAgByYXRpb25hbAAA//9XaQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3791 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3597158798 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f5901e5810, 0x55f5903cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f5903cf020,0x55f5922670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eb539e9f725d53737c1214acf743d726aae4bda3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4702 processed earlier; will process 6327 files now Step #5: #1 pulse cov: 11129 ft: 11130 exec/s: 0 rss: 192Mb Step #5: ==136552== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f586cda9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f58d33f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f58d3225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f58d3224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f586ce0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f586c41b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f586c3c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f586cd2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f589ca1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f589ca1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f589ca1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f589ca1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f589ca1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f589ca1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f589ca1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f589ca1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f589ca1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f589ca1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f58bf36f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f588c63b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f588c6ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f588a1ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f588a1ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f588a1b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f588a1a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f588a1a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f588a1a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f58d324abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f58d32d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f58d315699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f58d340112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6fe7b25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f586c3ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0x0,0x0,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0x2f,0x76,0x30,0x0,0xf3,0xa0,0x81,0xb8,0x0,0x28,0xd,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x0,0x72,0x64,0x64,0x64,0xb5,0xf3,0xa0,0x81,0x87,0x64,0x64, Step #5: \341\240\216= \177\177\000\000(\342\200\254\000\341\240\216= \177\177\342\200\215\000\000(\342\200\256\000r+/v0\000\363\240\201\270\000(\015(\342\200\254\000\341\240\216= \177\177\342\200\215\000\000(\342\200\256\000r\000rddd\265\363\240\201\207dd Step #5: artifact_prefix='./'; Test unit written to ./oom-4f465daea9266503da283135f352ad42a269287f Step #5: Base64: 4aCOPSB/fwAAKOKArADhoI49IH9/4oCNAAAo4oCuAHIrL3YwAPOggbgAKA0o4oCsAOGgjj0gf3/igI0AACjigK4AcgByZGRktfOggYdkZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3792 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3597728839 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aab5678810, 0x55aab586201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aab5862020,0x55aab76fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f465daea9266503da283135f352ad42a269287f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4704 processed earlier; will process 6325 files now Step #5: ==136588== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aaac16d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aab27d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aab27b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aab27b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aaac173d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aaac0d4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aaac0cf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aaac165c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aaaf134f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aaaf134f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aaaf134f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aaaf134f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aaaf134f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aaaf134f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aaaf134f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aaaf134f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aaaf134f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aaaf134f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aab13c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aaae0f6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aaae101be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aaadeadc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aaadeadc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aaadeae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aaadead874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aaadead874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aaadead874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aab27b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aab27c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aab27a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aab27d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4bee770082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aaac0cdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xbe,0x83,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81, Step #5: \341\276\203\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-f5ce8850ca7eac47951bba2a4a0e3a20666b11c0 Step #5: Base64: 4b6DzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhOC+geC+geC+geC+geC+geC+geC+geC+geC+geC+geC+geC+geC+geC+geC+geC+gQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3793 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3598231979 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55940fa71810, 0x55940fc5b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55940fc5b020,0x559411af30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f5ce8850ca7eac47951bba2a4a0e3a20666b11c0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4705 processed earlier; will process 6324 files now Step #5: #1 pulse cov: 6657 ft: 6657 exec/s: 0 rss: 188Mb Step #5: ==136624== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5594065669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55940cbcb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55940cbae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55940cbae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55940656cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5594064cdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5594064c8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55940655ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55940952df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55940952df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55940952df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55940952df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55940952df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55940952df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55940952df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55940952df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55940952df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55940952df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55940b7c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5594084efb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5594084fabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5594082a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5594082a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5594082a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5594082a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5594082a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5594082a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55940cbb0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55940cbb9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55940cba1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55940cbcc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0811b20082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5594064c6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2,0xa,0x2d,0xa,0x2d,0xa,0x62,0xa,0xd0,0xa,0x2d,0xa,0x64,0xa,0xd5,0xa,0x2,0xa,0x32,0xa,0xdc,0xa,0xd2,0xa,0x0,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xff, Step #5: \000-----BEGIN -----\012,\012-\012d\012-\012d\012d\012-\012\002\012-\012\002\012-\012,\012-\012d\012\002\012-\012-\012b\012\320\012-\012d\012\325\012\002\0122\012\334\012\322\012\000\012-\012-\012-\012\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-b1843d5d85f3e999d5c47b16668f0245ee9a36d8 Step #5: Base64: AC0tLS0tQkVHSU4gLS0tLS0KLAotCmQKLQpkCmQKLQoCCi0KAgotCiwKLQpkCgIKLQotCmIK0AotCmQK1QoCCjIK3ArSCgAKLQotCi0K/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3794 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3598790060 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b4e6171810, 0x55b4e635b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b4e635b020,0x55b4e81f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b1843d5d85f3e999d5c47b16668f0245ee9a36d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4707 processed earlier; will process 6322 files now Step #5: ==136660== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b4dcc669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b4e32cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b4e32ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b4e32ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b4dcc6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b4dcbcdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b4dcbc8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b4dcc5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b4dfc2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b4dfc2df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b4dfc2df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b4dfc2df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b4dfc2df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b4dfc2df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b4dfc2df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b4dfc2df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b4dfc2df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b4dfc2df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b4e1ec2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b4debefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b4debfabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b4de9a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b4de9a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b4de9a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b4de9a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b4de9a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b4de9a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b4e32b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b4e32b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b4e32a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b4e32cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f295e5e8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b4dcbc6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x68,0x6f,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x4e,0x75,0x72,0x67,0x6c,0x61,0x73,0x73,0x2b,0xa,0x2b,0x40,0x2b,0xa,0x2b,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x2b,0xa,0xa,0x2b,0xa,0x43,0x46,0x46,0x32,0x2b,0xdc, Step #5: hoNNNNNNNNNNNNNNNNNNN\012\000\000\000\000\000\000\000NNNNNNNNNNNNNurglass+\012+@+\012++\012\012+\012++\012\012+\012++\012\012+\012CFF2+\334 Step #5: artifact_prefix='./'; Test unit written to ./oom-bc1269af761371b714e3b3e9dcbfcdb782c28196 Step #5: Base64: aG9OTk5OTk5OTk5OTk5OTk5OTk5OCgAAAAAAAABOTk5OTk5OTk5OTk5OdXJnbGFzcysKK0ArCisrCgorCisrCgorCisrCgorCkNGRjIr3A== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3795 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3599295554 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f907b9c810, 0x55f907d8601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f907d86020,0x55f909c1e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bc1269af761371b714e3b3e9dcbfcdb782c28196' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4708 processed earlier; will process 6321 files now Step #5: ==136696== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8fe6919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f904cf6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f904cd95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f904cd94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8fe697d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8fe5f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8fe5f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8fe689c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f901658f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f901658f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f901658f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f901658f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f901658f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f901658f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f901658f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f901658f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f901658f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f901658f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f9038edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f90061ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f900625be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f9003d1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f9003d1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f9003d2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f9003d1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f9003d1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f9003d1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f904cdbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f904ce4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f904ccc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f904cf7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff8427c8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8fe5f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x6f,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x6,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x33,0x1,0x3, Step #5: 1\000\000\000\000\000\001\000\000\000o\000\000\001\000\000\001\000\000\001\006\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\000\000\001\0003\001\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-8336ea23cd991ec57d935e42a7f10a0c7f0523d2 Step #5: Base64: MQAAAAAAAQAAAG8AAAEAAAEAAAEGAAABAAABAAABAAABAAABAAABAAABAAABAAABAAABAAABAAABAAABAAABAAABAAABAAABAAABADMBAw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3796 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3599795903 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e5d6b87810, 0x55e5d6d7101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e5d6d71020,0x55e5d8c090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8336ea23cd991ec57d935e42a7f10a0c7f0523d2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4709 processed earlier; will process 6320 files now Step #5: ==136732== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e5cd67c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e5d3ce1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e5d3cc45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e5d3cc44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e5cd682d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e5cd5e3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e5cd5de355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e5cd674c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e5d0643f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e5d0643f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e5d0643f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e5d0643f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e5d0643f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e5d0643f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e5d0643f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e5d0643f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e5d0643f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e5d0643f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e5d28d8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e5cf605b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e5cf610be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e5cf3bcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e5cf3bcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e5cf3bd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e5cf3bc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e5cf3bc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e5cf3bc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e5d3cc6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e5d3ccf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e5d3cb7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e5d3ce2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa8e0d8c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e5cd5dcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x9,0x45,0x47,0x4b,0x60,0x20,0x2d,0x45,0x47,0x4b,0x60,0x20,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x2d,0x0,0x0,0x0,0x87,0x28,0x0,0x0,0x0,0xa,0x2d,0x60,0x64,0xa,0x64,0xa,0x3f, Step #5: s-----\011EGK` -EGK` BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB-\000\000\000\207(\000\000\000\012-`d\012d\012? Step #5: artifact_prefix='./'; Test unit written to ./oom-a6f8c0c50b65a5c200fdc212ba7f0156aa152191 Step #5: Base64: cy0tLS0tCUVHS2AgLUVHS2AgQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkItAAAAhygAAAAKLWBkCmQKPw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3797 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3600427773 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5623dbc4e810, 0x5623dbe3801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5623dbe38020,0x5623ddcd00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a6f8c0c50b65a5c200fdc212ba7f0156aa152191' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4710 processed earlier; will process 6319 files now Step #5: ==136768== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5623d27439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5623d8da8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5623d8d8b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5623d8d8b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5623d2749d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5623d26aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5623d26a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5623d273bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5623d570af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5623d570af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5623d570af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5623d570af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5623d570af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5623d570af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5623d570af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5623d570af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5623d570af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5623d570af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5623d799ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5623d46ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5623d46d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5623d4483c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5623d4483c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5623d4484738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5623d4483874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5623d4483874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5623d4483874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5623d8d8dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5623d8d96928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5623d8d7e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5623d8da9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdadab8a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5623d26a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x11,0x0,0x7,0x0,0xce,0x93,0x1,0x60,0x54,0x43,0x4f,0x0,0x0,0x1,0x60,0x54,0x43,0x49,0x44,0x11,0x0,0x7,0x0,0xce,0x93,0x1,0x60,0x54,0x43,0x43,0x4f,0x0,0x0,0x60,0x54,0x43,0x49,0x44,0x11,0x0,0x7,0x0,0xce,0x93,0x1,0x60,0x54,0x43,0x4f,0x0,0x0,0x1,0x60,0x54,0x43,0x49,0x44,0x11,0x0,0x7,0x0,0xce,0x93,0x1,0x60,0x54,0x43,0x43,0x4f,0x0,0x0,0x60,0x54,0x43,0x4f,0x4f,0x1, Step #5: ID\021\000\007\000\316\223\001`TCO\000\000\001`TCID\021\000\007\000\316\223\001`TCCO\000\000`TCID\021\000\007\000\316\223\001`TCO\000\000\001`TCID\021\000\007\000\316\223\001`TCCO\000\000`TCOO\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-249b3d3925ce101a9af5d8fd902d0c01b6c704da Step #5: Base64: SUQRAAcAzpMBYFRDTwAAAWBUQ0lEEQAHAM6TAWBUQ0NPAABgVENJRBEABwDOkwFgVENPAAABYFRDSUQRAAcAzpMBYFRDQ08AAGBUQ09PAQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3798 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3601058967 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556650774810, 0x55665095e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55665095e020,0x5566527f60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/249b3d3925ce101a9af5d8fd902d0c01b6c704da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4711 processed earlier; will process 6318 files now Step #5: ==136804== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5566472699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55664d8ce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55664d8b15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55664d8b14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55664726fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5566471d0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5566471cb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556647261c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55664a230f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55664a230f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55664a230f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55664a230f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55664a230f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55664a230f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55664a230f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55664a230f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55664a230f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55664a230f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55664c4c5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5566491f2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5566491fdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556648fa9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556648fa9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556648faa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556648fa9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556648fa9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556648fa9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55664d8b3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55664d8bc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55664d8a4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55664d8cf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27aac9b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5566471c9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x8,0x4e,0x3f,0x3f,0x23,0x31,0x23,0x31,0x25,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26, Step #5: %\010N??#1#1%&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&& Step #5: artifact_prefix='./'; Test unit written to ./oom-802213b1758f1cbde2bb8152988fea5090c9ec8b Step #5: Base64: JQhOPz8jMSMxJSYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3799 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3601571822 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d8eb7c4810, 0x55d8eb9ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d8eb9ae020,0x55d8ed8460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/802213b1758f1cbde2bb8152988fea5090c9ec8b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4712 processed earlier; will process 6317 files now Step #5: ==136840== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d8e22b99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d8e891e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d8e89015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d8e89014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d8e22bfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d8e2220b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d8e221b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d8e22b1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d8e5280f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d8e5280f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d8e5280f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d8e5280f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d8e5280f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d8e5280f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d8e5280f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d8e5280f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d8e5280f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d8e5280f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d8e7515f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d8e4242b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d8e424dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d8e3ff9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d8e3ff9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d8e3ffa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d8e3ff9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d8e3ff9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d8e3ff9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d8e8903abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d8e890c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d8e88f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d8e891f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fca3d825082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d8e2219b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x30,0x4d,0x46,0x77,0x48,0x65,0x57,0x50,0x63,0x6f,0x41,0x62,0x44,0x4c,0x71,0x6c,0x2b,0x59,0x35,0x6d,0x54,0x53,0x73,0x61,0x2b,0x41,0x41,0x4e,0x47,0x42,0x58,0x49,0x51,0x7a,0x56,0x77,0x6a,0x67,0x6f,0x31,0x54,0x45,0xa,0x66,0x61,0x6d,0x69,0x6c,0x79,0x9,0x36,0x9,0x71, Step #5: onion-key\012ntor-onion-key v0MFwHeWPcoAbDLql+Y5mTSsa+AANGBXIQzVwjgo1TE\012family\0116\011q Step #5: artifact_prefix='./'; Test unit written to ./oom-6c9a40482412e31b82309835885c1a9a766a85b5 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHYwTUZ3SGVXUGNvQWJETHFsK1k1bVRTc2ErQUFOR0JYSVF6VndqZ28xVEUKZmFtaWx5CTYJcQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3800 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3602079592 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557bdfe9f810, 0x557be008901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557be0089020,0x557be1f210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6c9a40482412e31b82309835885c1a9a766a85b5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4713 processed earlier; will process 6316 files now Step #5: ==136876== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557bd69949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557bdcff9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557bdcfdc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557bdcfdc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557bd699ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557bd68fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557bd68f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557bd698cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557bd995bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557bd995bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557bd995bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557bd995bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557bd995bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557bd995bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557bd995bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557bd995bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557bd995bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557bd995bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557bdbbf0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557bd891db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557bd8928be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557bd86d4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557bd86d4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557bd86d5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557bd86d4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557bd86d4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557bd86d4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557bdcfdeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557bdcfe7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557bdcfcf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557bdcffa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e65958082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557bd68f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x36,0x2c,0x31,0x36,0xa,0x36,0x2c,0x34,0x36,0xa,0x36,0x2c,0x31,0x36,0xa,0x36,0x2c,0x34,0x36,0xa,0x36,0x2c,0x31,0x36,0xa,0x36,0x2c,0x34,0x36,0xa,0x36,0x2c,0x31,0x36,0xa,0x36,0x2c,0x34,0x36,0xa,0x36,0x2c,0x31,0x36,0xa,0x36,0x2c,0x34,0x36,0xa,0x36,0x2c,0x31,0x36,0xa,0x36,0x2c,0x34,0x36,0xa,0x36,0x2c,0x31,0x36,0xa,0x36,0x2c,0x34,0x36,0xa,0x36,0x2c,0x31,0x36,0xa,0x36,0x2c,0x34,0x36, Step #5: 6,16\0126,46\0126,16\0126,46\0126,16\0126,46\0126,16\0126,46\0126,16\0126,46\0126,16\0126,46\0126,16\0126,46\0126,16\0126,46 Step #5: artifact_prefix='./'; Test unit written to ./oom-9c00baf2dde559e0cbf3a9570cf09b6cffd2d269 Step #5: Base64: NiwxNgo2LDQ2CjYsMTYKNiw0Ngo2LDE2CjYsNDYKNiwxNgo2LDQ2CjYsMTYKNiw0Ngo2LDE2CjYsNDYKNiwxNgo2LDQ2CjYsMTYKNiw0Ng== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3801 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3602583346 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56143f81b810, 0x56143fa0501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56143fa05020,0x56144189d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c00baf2dde559e0cbf3a9570cf09b6cffd2d269' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4714 processed earlier; will process 6315 files now Step #5: #1 pulse cov: 3779 ft: 3780 exec/s: 0 rss: 174Mb Step #5: ==136912== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5614363109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56143c975898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56143c9585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56143c9584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561436316d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561436277b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561436272355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561436308c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5614392d7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5614392d7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5614392d7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5614392d7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5614392d7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5614392d7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5614392d7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5614392d7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5614392d7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5614392d7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56143b56cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561438299b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5614382a4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561438050c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561438050c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561438051738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561438050874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561438050874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561438050874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56143c95aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56143c963928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56143c94b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56143c976112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efc6371d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561436270b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x31,0x2d,0x20,0x31,0x20,0x2d,0x3a,0x20,0x2d,0x0,0x14,0x31,0x1,0x27,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x63,0x65,0x6e,0x74,0x64,0xa,0x29,0xa,0xa,0x2,0x2d,0x2,0xa,0xa,0x2d,0x3f,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2,0x2d,0x29,0xa,0x64,0xa,0x64,0x29,0x2d,0xa,0x2b,0x1,0x0,0x0,0x0,0x3a,0x20,0x42,0x20,0x3a, Step #5: - 1- 1 -: -\000\0241\001'EGIN -----\012,\012-\012d\012-\012d\012centd\012)\012\012\002-\002\012\012-?,\012-\012d\012\002-)\012d\012d)-\012+\001\000\000\000: B : Step #5: artifact_prefix='./'; Test unit written to ./oom-8d5c5f63842e66fc3744a0c3db9aaf1077515814 Step #5: Base64: LSAxLSAxIC06IC0AFDEBJ0VHSU4gLS0tLS0KLAotCmQKLQpkCmNlbnRkCikKCgItAgoKLT8sCi0KZAoCLSkKZApkKS0KKwEAAAA6IEIgOg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3802 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3603140259 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f3bb11810, 0x556f3bcfb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f3bcfb020,0x556f3db930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d5c5f63842e66fc3744a0c3db9aaf1077515814' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4716 processed earlier; will process 6313 files now Step #5: ==136948== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556f326069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f38c6b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f38c4e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f38c4e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f3260cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f3256db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f32568355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f325fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f355cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f355cdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f355cdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f355cdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f355cdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f355cdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f355cdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f355cdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f355cdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f355cdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f37862f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f3458fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f3459abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f34346c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f34346c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f34347738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f34346874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f34346874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f34346874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f38c50abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f38c59928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f38c41699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f38c6c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f44f629b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f32566b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x2a,0x2a,0x4e,0x45,0x57,0x46,0x49,0x4c,0x45,0x2a,0x2a,0x2a,0x3a,0x63,0x6d,0x64,0x2e,0x74,0x78,0x74,0xa,0x64,0x72,0x69,0x76,0x65,0x72,0xa,0x70,0x64,0x66,0x0,0x0,0x6e,0xa,0x6c,0x69,0x73,0x74,0x2d,0x6c,0x61,0x79,0x65,0x72,0x73,0xa,0x69,0x0,0x6c,0x62,0xa,0x2f,0x76,0x73,0x69,0x63,0x75,0x72,0x6c,0x2f,0x64,0x74,0x74,0x61,0x72,0x2e,0x67,0x7a,0x2e,0x31,0x2b,0x2b,0x2b,0x2b,0x2b,0x2c,0x30, Step #5: ***NEWFILE***:cmd.txt\012driver\012pdf\000\000n\012list-layers\012i\000lb\012/vsicurl/dttar.gz.1+++++,0 Step #5: artifact_prefix='./'; Test unit written to ./oom-fb898e29785a2bdbb58c46758d9bbbca3441e2f0 Step #5: Base64: KioqTkVXRklMRSoqKjpjbWQudHh0CmRyaXZlcgpwZGYAAG4KbGlzdC1sYXllcnMKaQBsYgovdnNpY3VybC9kdHRhci5nei4xKysrKyssMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3803 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3603653020 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561376fe0810, 0x5613771ca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5613771ca020,0x5613790620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fb898e29785a2bdbb58c46758d9bbbca3441e2f0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4717 processed earlier; will process 6312 files now Step #5: ==136984== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56136dad59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56137413a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56137411d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56137411d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56136dadbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56136da3cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56136da37355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56136dacdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561370a9cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561370a9cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561370a9cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561370a9cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561370a9cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561370a9cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561370a9cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561370a9cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561370a9cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561370a9cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561372d31f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56136fa5eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56136fa69be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56136f815c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56136f815c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56136f816738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56136f815874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56136f815874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56136f815874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56137411fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561374128928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561374110699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56137413b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8fd1e04082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56136da35b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x22,0x24,0x22,0xa,0x3d,0x22,0x24,0x22,0xa,0x3d,0x22,0x24,0x22,0xa,0x3d,0x22,0x24,0x22,0xa,0x3d,0x22,0x24,0x22,0xa,0x3d,0x22,0x24,0x22,0xa,0x3d,0x22,0x24,0x22,0xa,0x3d,0x22,0x24,0x22,0x0,0x3d,0x22,0x3b,0x22,0xa,0x3d,0x22,0x24,0x22,0xa,0x3d,0x22,0x24,0x22,0xa,0x3d,0x22,0x24,0x22,0xa,0x3d,0x22,0x3b,0x22,0xa,0x3d,0x22,0x24,0x22,0xa,0x3d,0x22,0x24,0x22,0xa,0x3d,0x22,0x24,0x22, Step #5: =\"$\"\012=\"$\"\012=\"$\"\012=\"$\"\012=\"$\"\012=\"$\"\012=\"$\"\012=\"$\"\000=\";\"\012=\"$\"\012=\"$\"\012=\"$\"\012=\";\"\012=\"$\"\012=\"$\"\012=\"$\" Step #5: artifact_prefix='./'; Test unit written to ./oom-cc2b779ff1b1288bc12ba1a44fa693402107d93f Step #5: Base64: PSIkIgo9IiQiCj0iJCIKPSIkIgo9IiQiCj0iJCIKPSIkIgo9IiQiAD0iOyIKPSIkIgo9IiQiCj0iJCIKPSI7Igo9IiQiCj0iJCIKPSIkIg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3804 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3604170339 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5587ff144810, 0x5587ff32e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5587ff32e020,0x5588011c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cc2b779ff1b1288bc12ba1a44fa693402107d93f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4718 processed earlier; will process 6311 files now Step #5: ==137020== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5587f5c399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5587fc29e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5587fc2815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5587fc2814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5587f5c3fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5587f5ba0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5587f5b9b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5587f5c31c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5587f8c00f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5587f8c00f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5587f8c00f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5587f8c00f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5587f8c00f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5587f8c00f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5587f8c00f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5587f8c00f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5587f8c00f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5587f8c00f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5587fae95f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5587f7bc2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5587f7bcdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5587f7979c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5587f7979c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5587f797a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5587f7979874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5587f7979874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5587f7979874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5587fc283abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5587fc28c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5587fc274699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5587fc29f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3edc8a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5587f5b99b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x7b,0x27,0x27,0x27,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x27,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x24,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x27,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x27,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x5c,0xd,0x27,0x27,0x27,0x7d,0x7d,0x24, Step #5: {{'''\\\015\\\015\\\015\\\015\\\015\\\015\\\015'\\\015\\\015\\\015\\\015$\\\015\\\015\\\015\\\015'\\\015\\\015\\\015\\\015\\\015\\\015\\\015\\\015\\\015\\\015'\\\015\\\015\\\015\\\015\\\015\\\015\\\015'''}}$ Step #5: artifact_prefix='./'; Test unit written to ./oom-7cec1b84aa6f8fa58a9092cab3c7c374afc9ea8b Step #5: Base64: e3snJydcDVwNXA1cDVwNXA1cDSdcDVwNXA1cDSRcDVwNXA1cDSdcDVwNXA1cDVwNXA1cDVwNXA1cDSdcDVwNXA1cDVwNXA1cDScnJ319JA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3805 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3604676997 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b9ce558810, 0x55b9ce74201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b9ce742020,0x55b9d05da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7cec1b84aa6f8fa58a9092cab3c7c374afc9ea8b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4719 processed earlier; will process 6310 files now Step #5: ==137056== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b9c504d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b9cb6b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b9cb6955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b9cb6954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b9c5053d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b9c4fb4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b9c4faf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b9c5045c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b9c8014f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b9c8014f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b9c8014f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b9c8014f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b9c8014f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b9c8014f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b9c8014f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b9c8014f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b9c8014f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b9c8014f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b9ca2a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b9c6fd6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b9c6fe1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b9c6d8dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b9c6d8dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b9c6d8e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b9c6d8d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b9c6d8d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b9c6d8d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b9cb697abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b9cb6a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b9cb688699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b9cb6b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f737ae2b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b9c4fadb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x3a,0x30,0x3a,0x31,0x2e,0x36,0x2d,0x2d,0x3e,0x31,0x3a,0x30,0x3a,0x30,0x2e,0x38,0xd,0x60,0xd,0x31,0x3a,0x30,0x3a,0x31,0x2e,0x36,0x2d,0x2d,0x3e,0x31,0x3a,0x30,0x3a,0x30,0x2e,0x30,0xd,0x5d,0xd,0x31,0x3a,0x30,0x3a,0x31,0x2e,0x36,0x2d,0x2d,0x3e,0x31,0x3a,0x30,0x3a,0x30,0x2e,0x30,0xd,0x60,0xd,0x31,0x3a,0x30,0x3a,0x31,0x2e,0x36,0x2d,0x2d,0x3e,0x31,0x3a,0x30,0x3a,0x31,0x2e,0x36,0xd,0x40, Step #5: 1:0:1.6-->1:0:0.8\015`\0151:0:1.6-->1:0:0.0\015]\0151:0:1.6-->1:0:0.0\015`\0151:0:1.6-->1:0:1.6\015@ Step #5: artifact_prefix='./'; Test unit written to ./oom-3581d360fcd7f9961d981e4fb3c573ed157b3fc8 Step #5: Base64: MTowOjEuNi0tPjE6MDowLjgNYA0xOjA6MS42LS0+MTowOjAuMA1dDTE6MDoxLjYtLT4xOjA6MC4wDWANMTowOjEuNi0tPjE6MDoxLjYNQA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3806 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3605306443 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562f4fc23810, 0x562f4fe0d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562f4fe0d020,0x562f51ca50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3581d360fcd7f9961d981e4fb3c573ed157b3fc8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4720 processed earlier; will process 6309 files now Step #5: #1 pulse cov: 3673 ft: 3674 exec/s: 0 rss: 176Mb Step #5: ==137092== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562f467189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562f4cd7d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562f4cd605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562f4cd604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562f4671ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562f4667fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562f4667a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562f46710c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562f496dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562f496dff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562f496dff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562f496dff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562f496dff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562f496dff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562f496dff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562f496dff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562f496dff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562f496dff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562f4b974f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562f486a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562f486acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562f48458c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562f48458c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562f48459738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562f48458874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562f48458874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562f48458874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562f4cd62abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562f4cd6b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562f4cd53699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562f4cd7e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ee677d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562f46678b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x8,0xf,0xf,0xf,0x2f,0xf,0x31,0x11,0x0,0x0,0x0,0x7,0x2e,0x2b,0x42,0xdb,0xbe,0x75,0xdb,0xbe,0x2b,0x2b,0x2b,0x2b,0x2b,0x41,0x2b,0x2b,0x2b,0x2b,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x2b,0x2b,0x24,0x6e,0x24,0x3,0x3,0x52, Step #5: - \010\017\017\017/\0171\021\000\000\000\007.+B\333\276u\333\276+++++A++++99999999999\000\000\000\000\000\000\000\000\000\000\000\000\000\000999999999999999++$n$\003\003R Step #5: artifact_prefix='./'; Test unit written to ./oom-07e676a0b576cb23ef2b5f391dfaa177d4ae9a89 Step #5: Base64: LSAIDw8PLw8xEQAAAAcuK0LbvnXbvisrKysrQSsrKys5OTk5OTk5OTk5OQAAAAAAAAAAAAAAAAAAOTk5OTk5OTk5OTk5OTk5KyskbiQDA1I= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3807 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3605849659 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55604d8a7810, 0x55604da9101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55604da91020,0x55604f9290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/07e676a0b576cb23ef2b5f391dfaa177d4ae9a89' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4722 processed earlier; will process 6307 files now Step #5: ==137128== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55604439c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55604aa01898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55604a9e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55604a9e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5560443a2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556044303b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5560442fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556044394c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556047363f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556047363f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556047363f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556047363f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556047363f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556047363f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556047363f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556047363f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556047363f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556047363f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5560495f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556046325b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556046330be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5560460dcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5560460dcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5560460dd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5560460dc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5560460dc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5560460dc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55604a9e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55604a9ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55604a9d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55604aa02112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9abb9c1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5560442fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xd,0x48,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xd,0x25,0x20,0x78,0x78,0x20,0x27,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0x20,0x6a,0x9,0x64,0xd,0x49,0x44,0x52,0x45,0x46,0x53,0x9,0x22,0xe2,0x80,0x89,0x6c,0x9,0xe2,0x80,0x8d,0xcd,0xa2,0x22,0x3e,0x27,0x3e,0x25,0x78,0x78,0x3b,0x25,0x3b,0x3b,0x78,0x78,0xa0,0x81,0x83,0x25,0x78,0x78,0x3b,0xf3, Step #5: <!DOCTYPE\015H[<!ENTITY\015% xx '<!ATTLIST j\011d\015IDREFS\011\"\342\200\211l\011\342\200\215\315\242\">'>%xx;%;;xx\240\201\203%xx;\363 Step #5: artifact_prefix='./'; Test unit written to ./oom-bed435901f871e662ea1eff808893f7f006d466f Step #5: Base64: PCFET0NUWVBFDUhbPCFFTlRJVFkNJSB4eCAnPCFBVFRMSVNUIGoJZA1JRFJFRlMJIuKAiWwJ4oCNzaIiPic+JXh4OyU7O3h4oIGDJXh4O/M= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3808 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3606350424 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e916ba810, 0x563e918a401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e918a4020,0x563e9373c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bed435901f871e662ea1eff808893f7f006d466f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4723 processed earlier; will process 6306 files now Step #5: ==137164== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563e881af9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e8e814898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e8e7f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e8e7f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e881b5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e88116b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e88111355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e881a7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e8b176f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e8b176f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e8b176f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e8b176f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e8b176f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e8b176f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e8b176f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e8b176f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e8b176f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e8b176f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e8d40bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e8a138b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e8a143be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e89eefc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e89eefc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e89ef0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e89eef874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e89eef874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e89eef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e8e7f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e8e802928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e8e7ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e8e815112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5d4c66f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e8810fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9,0x2f,0x2f,0xe2,0x80,0xa9, Step #5: //\342\200\251//\342\200\251//\342\200\251//\342\200\251//\342\200\251//\342\200\251//\342\200\251//\342\200\251//\342\200\251//\342\200\251//\342\200\251//\342\200\251//\342\200\251//\342\200\251//\342\200\251//\342\200\251 Step #5: artifact_prefix='./'; Test unit written to ./oom-8601495f3e85e2bda622bffab5cfe1925398ae3c Step #5: Base64: Ly/igKkvL+KAqS8v4oCpLy/igKkvL+KAqS8v4oCpLy/igKkvL+KAqS8v4oCpLy/igKkvL+KAqS8v4oCpLy/igKkvL+KAqS8v4oCpLy/igKk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3809 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3606833936 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a2055a5810, 0x55a20578f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a20578f020,0x55a2076270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8601495f3e85e2bda622bffab5cfe1925398ae3c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4724 processed earlier; will process 6305 files now Step #5: ==137200== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1fc09a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a2026ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2026e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2026e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1fc0a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1fc001b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1fbffc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1fc092c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1ff061f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1ff061f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1ff061f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1ff061f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1ff061f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1ff061f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1ff061f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1ff061f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1ff061f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1ff061f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a2012f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1fe023b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1fe02ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1fdddac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1fdddac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1fdddb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1fddda874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1fddda874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1fddda874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a2026e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a2026ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2026d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a202700112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f21ec085082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1fbffab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0x20,0x73,0x76,0x67,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x22,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2c,0x27,0x27,0x27,0x27,0x32,0x27,0x27,0x27,0x25,0x7a,0x20,0x30,0x2d,0x25,0x24,0x25,0x27,0x27,0x27,0x32,0x27,0x27,0x27,0x27,0x7a,0x20,0x30,0x2d,0x25,0x24,0x25,0x20,0x22,0x20,0x22,0x22,0x20, Step #5: <!DOCTYPE svg PUBLIC \"''''''''''''2''''''',''''2'''%z 0-%$%'''2''''z 0-%$% \" \"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-95dcb4a12d15ad081aedbf86190b270d9a802e49 Step #5: Base64: PCFET0NUWVBFIHN2ZyBQVUJMSUMgIicnJycnJycnJycnJzInJycnJycnLCcnJycyJycnJXogMC0lJCUnJycyJycnJ3ogMC0lJCUgIiAiIiA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3810 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3607344490 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560c92a3f810, 0x560c92c2901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560c92c29020,0x560c94ac10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/95dcb4a12d15ad081aedbf86190b270d9a802e49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4725 processed earlier; will process 6304 files now Step #5: #1 pulse cov: 3961 ft: 3962 exec/s: 0 rss: 177Mb Step #5: ==137236== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560c895349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560c8fb99898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560c8fb7c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560c8fb7c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560c8953ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560c8949bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560c89496355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560c8952cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560c8c4fbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560c8c4fbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560c8c4fbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560c8c4fbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560c8c4fbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560c8c4fbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560c8c4fbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560c8c4fbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560c8c4fbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560c8c4fbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560c8e790f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560c8b4bdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560c8b4c8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560c8b274c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560c8b274c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560c8b275738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560c8b274874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560c8b274874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560c8b274874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560c8fb7eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560c8fb87928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560c8fb6f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560c8fb9a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7bdcfca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560c89494b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e, Step #5: (?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q> Step #5: artifact_prefix='./'; Test unit written to ./oom-91e1465096d359336f671dbae1c259c67eb1f195 Step #5: Base64: KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3811 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3607895426 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560ed9d8b810, 0x560ed9f7501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560ed9f75020,0x560edbe0d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/91e1465096d359336f671dbae1c259c67eb1f195' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4727 processed earlier; will process 6302 files now Step #5: ==137272== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560ed08809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560ed6ee5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560ed6ec85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560ed6ec84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560ed0886d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560ed07e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560ed07e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560ed0878c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560ed3847f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560ed3847f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560ed3847f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560ed3847f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560ed3847f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560ed3847f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560ed3847f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560ed3847f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560ed3847f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560ed3847f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560ed5adcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560ed2809b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560ed2814be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560ed25c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560ed25c0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560ed25c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560ed25c0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560ed25c0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560ed25c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560ed6ecaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560ed6ed3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560ed6ebb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560ed6ee6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff962b94082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560ed07e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x17,0x44,0x0,0x0,0x0,0x66,0x66,0x68,0x66,0x68,0x6d,0x74,0x78,0x1d,0x44,0x44,0x17,0x44,0x0,0x0,0x0,0x66,0x66,0x68,0x66,0x68,0x6d,0x74,0x78,0x1d,0x17,0x44,0x0,0x0,0x0,0x66,0x66,0x68,0x66,0x68,0x6d,0x74,0x78,0x1d,0x44,0x44,0x17,0x44,0x0,0x0,0x0,0x66,0x66,0x68,0x66,0x68,0x6d,0x74,0x78,0x1d,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44, Step #5: \027D\000\000\000ffhfhmtx\035DD\027D\000\000\000ffhfhmtx\035\027D\000\000\000ffhfhmtx\035DD\027D\000\000\000ffhfhmtx\035DDDDDDDDDDDDDDDDDDDD Step #5: artifact_prefix='./'; Test unit written to ./oom-d2df3b67761f7c07141010a09740cc425bf7ee3c Step #5: Base64: F0QAAABmZmhmaG10eB1ERBdEAAAAZmZoZmhtdHgdF0QAAABmZmhmaG10eB1ERBdEAAAAZmZoZmhtdHgdREREREREREREREREREREREREREQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3812 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3608404245 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea0c70d810, 0x55ea0c8f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea0c8f7020,0x55ea0e78f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d2df3b67761f7c07141010a09740cc425bf7ee3c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4728 processed earlier; will process 6301 files now Step #5: ==137308== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ea032029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea09867898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea0984a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea0984a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea03208d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea03169b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea03164355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea031fac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea061c9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea061c9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea061c9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea061c9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea061c9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea061c9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea061c9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea061c9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea061c9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea061c9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea0845ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea0518bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea05196be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea04f42c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea04f42c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea04f43738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea04f42874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea04f42874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea04f42874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea0984cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea09855928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea0983d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea09868112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f39160bf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea03162b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x48,0x55,0x4c,0x55,0x22,0x2f,0xe0,0xb9,0x83,0xe0,0xbb,0x84,0xe0,0xb9,0x83,0xe9,0xbb,0x83,0xe0,0xb9,0x84,0xe0,0xb9,0x83,0xe0,0xb8,0x83,0x43,0xe0,0xb9,0x83,0xe1,0xb9,0x83,0xea,0xb9,0x83,0xe0,0xba,0x83,0xe0,0xb9,0x84,0xe0,0xb9,0x84,0xe1,0xbd,0x83,0x43,0xe0,0xb9,0x83,0xe1,0xb9,0x83,0xe7,0xb9,0x83,0xe0,0xba,0x83,0xe0,0xb9,0x84,0xe0,0xb9,0x83,0xe0,0xbb,0x83,0xe0,0xb9,0x84,0xe0,0xca,0xb7,0x4,0x48, Step #5: [HULU\"/\340\271\203\340\273\204\340\271\203\351\273\203\340\271\204\340\271\203\340\270\203C\340\271\203\341\271\203\352\271\203\340\272\203\340\271\204\340\271\204\341\275\203C\340\271\203\341\271\203\347\271\203\340\272\203\340\271\204\340\271\203\340\273\203\340\271\204\340\312\267\004H Step #5: artifact_prefix='./'; Test unit written to ./oom-3361a4a40caeb585449774f37b4e241dd466d5cc Step #5: Base64: W0hVTFUiL+C5g+C7hOC5g+m7g+C5hOC5g+C4g0PguYPhuYPquYPguoPguYTguYThvYND4LmD4bmD57mD4LqD4LmE4LmD4LuD4LmE4Mq3BEg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3813 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3608919105 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571c5054810, 0x5571c523e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571c523e020,0x5571c70d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3361a4a40caeb585449774f37b4e241dd466d5cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4729 processed earlier; will process 6300 files now Step #5: ==137344== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571bbb499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571c21ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571c21915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571c21914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571bbb4fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571bbab0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571bbaab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571bbb41c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571beb10f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571beb10f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571beb10f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571beb10f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571beb10f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571beb10f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571beb10f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571beb10f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571beb10f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571beb10f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571c0da5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571bdad2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571bdaddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571bd889c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571bd889c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571bd88a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571bd889874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571bd889874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571bd889874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571c2193abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571c219c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571c2184699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571c21af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a127ad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571bbaa9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1,0xa,0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1,0xa,0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1, Step #5: \013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261\012\013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261\012\013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-ab5ca32970ede9e5d609cba7059dbb026f49d35b Step #5: Base64: C++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLEKC++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLEKC++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3814 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3609425936 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d1050d810, 0x564d106f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d106f7020,0x564d1258f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ab5ca32970ede9e5d609cba7059dbb026f49d35b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4730 processed earlier; will process 6299 files now Step #5: #1 pulse cov: 12871 ft: 12872 exec/s: 0 rss: 195Mb Step #5: ==137380== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d070029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d0d667898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d0d64a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d0d64a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d07008d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d06f69b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d06f64355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d06ffac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d09fc9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d09fc9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d09fc9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d09fc9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d09fc9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d09fc9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d09fc9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d09fc9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d09fc9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d09fc9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d0c25ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d08f8bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d08f96be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d08d42c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d08d42c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d08d43738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d08d42874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d08d42874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d08d42874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d0d64cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d0d655928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d0d63d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d0d668112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9bc2777082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d06f62b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0x0,0xe2,0x80,0x8d,0x1,0xe2, Step #5: \342\200\215\001\000\342\200\215\001\000\342\200\215\001\000\342\200\215\001\000\342\200\215\001\000\342\200\215\001\000\342\200\215\001\000\342\200\215\001\000\342\200\215\001\000\342\200\215\001\000\342\200\215\001\000\342\200\215\001\000\342\200\215\001\000\342\200\215\001\000\342\200\215\001\000\342\200\215\001\342 Step #5: artifact_prefix='./'; Test unit written to ./oom-e81b9ef9ffa165afc854298df146a8da63bc1024 Step #5: Base64: 4oCNAQDigI0BAOKAjQEA4oCNAQDigI0BAOKAjQEA4oCNAQDigI0BAOKAjQEA4oCNAQDigI0BAOKAjQEA4oCNAQDigI0BAOKAjQEA4oCNAeI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3815 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3610006094 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56148558c810, 0x56148577601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561485776020,0x56148760e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e81b9ef9ffa165afc854298df146a8da63bc1024' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4732 processed earlier; will process 6297 files now Step #5: ==137416== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56147c0819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5614826e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5614826c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5614826c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56147c087d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56147bfe8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56147bfe3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56147c079c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56147f048f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56147f048f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56147f048f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56147f048f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56147f048f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56147f048f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56147f048f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56147f048f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56147f048f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56147f048f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5614812ddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56147e00ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56147e015be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56147ddc1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56147ddc1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56147ddc2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56147ddc1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56147ddc1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56147ddc1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5614826cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5614826d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5614826bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5614826e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9e15c1b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56147bfe1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdc,0xae,0x4f,0x4f,0x2d,0x3d,0x2d,0x2d,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3,0x0, Step #5: \334\256OO-=--\001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\003\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3921d62ffc24a9586fb6bcde3a22fe0a801469c2 Step #5: Base64: 3K5PTy09LS0BAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3816 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3610504750 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c6f2d84810, 0x55c6f2f6e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c6f2f6e020,0x55c6f4e060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3921d62ffc24a9586fb6bcde3a22fe0a801469c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4733 processed earlier; will process 6296 files now Step #5: ==137452== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c6e98799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c6efede898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c6efec15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c6efec14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c6e987fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6e97e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6e97db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c6e9871c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c6ec840f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c6ec840f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c6ec840f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c6ec840f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c6ec840f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c6ec840f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c6ec840f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c6ec840f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c6ec840f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c6ec840f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c6eead5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6eb802b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c6eb80dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6eb5b9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6eb5b9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6eb5ba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6eb5b9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6eb5b9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6eb5b9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c6efec3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c6efecc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c6efeb4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c6efedf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe30dd29082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6e97d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xd,0x48,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xd,0x25,0x20,0x78,0x78,0x20,0x27,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0x20,0x6a,0x9,0x64,0xd,0x49,0x44,0x52,0x45,0x46,0x53,0x9,0x22,0xe2,0x80,0x8d,0x6c,0x9,0xe2,0x80,0x8d,0xcd,0xb2,0x22,0x3e,0x27,0x3e,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0xf3, Step #5: <!DOCTYPE\015H[<!ENTITY\015% xx '<!ATTLIST j\011d\015IDREFS\011\"\342\200\215l\011\342\200\215\315\262\">'>%xx;%xx;%xx;%xx;\363 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb61e34d91f5f95a469d63cc0599a75d3c9a5407 Step #5: Base64: PCFET0NUWVBFDUhbPCFFTlRJVFkNJSB4eCAnPCFBVFRMSVNUIGoJZA1JRFJFRlMJIuKAjWwJ4oCNzbIiPic+JXh4OyV4eDsleHg7JXh4O/M= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3817 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3611008854 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e95226810, 0x562e9541001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e95410020,0x562e972a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb61e34d91f5f95a469d63cc0599a75d3c9a5407' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4734 processed earlier; will process 6295 files now Step #5: ==137488== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562e8bd1b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e92380898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e923635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e923634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e8bd21d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e8bc82b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e8bc7d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e8bd13c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e8ece2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e8ece2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e8ece2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e8ece2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e8ece2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e8ece2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e8ece2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e8ece2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e8ece2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e8ece2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e90f77f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e8dca4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e8dcafbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e8da5bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e8da5bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e8da5c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e8da5b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e8da5b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e8da5b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e92365abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e9236e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e92356699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e92381112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f685620c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e8bc7bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x64,0xa,0x44,0xa,0x68,0xa,0x68,0xa,0x64,0xa,0x44,0xa,0x68,0xa,0x68,0xa,0x78,0xa,0x45,0xa,0x67,0xa,0x78,0xa,0x67,0xa,0x68,0xa,0x78,0xa,0x45,0xa,0x67,0xa,0x78,0xa,0x68,0xa,0x44,0xa,0x68,0xa,0x68,0xa,0x64,0xa,0x44,0xa,0x68,0xa,0x68,0xa,0x78,0xa,0x45,0xa,0x67,0xa,0x78,0xa,0xa,0x5b, Step #5: \005-----BEGIN -----\012d\012D\012h\012h\012d\012D\012h\012h\012x\012E\012g\012x\012g\012h\012x\012E\012g\012x\012h\012D\012h\012h\012d\012D\012h\012h\012x\012E\012g\012x\012\012[ Step #5: artifact_prefix='./'; Test unit written to ./oom-51a879ea65156dd3dd8a2e50df9f38616f7ec932 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KZApECmgKaApkCkQKaApoCngKRQpnCngKZwpoCngKRQpnCngKaApECmgKaApkCkQKaApoCngKRQpnCngKCls= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3818 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3611510593 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55941f114810, 0x55941f2fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55941f2fe020,0x5594211960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/51a879ea65156dd3dd8a2e50df9f38616f7ec932' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4735 processed earlier; will process 6294 files now Step #5: ==137524== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559415c099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55941c26e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55941c2515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55941c2514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559415c0fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559415b70b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559415b6b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559415c01c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559418bd0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559418bd0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559418bd0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559418bd0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559418bd0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559418bd0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559418bd0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559418bd0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559418bd0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559418bd0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55941ae65f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559417b92b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559417b9dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559417949c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559417949c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55941794a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559417949874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559417949874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559417949874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55941c253abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55941c25c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55941c244699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55941c26f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efd4dfa3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559415b69b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x20,0x7b,0xa,0x20,0x20,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0xa,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0xa,0x22,0x44,0x20,0x20,0x20,0x5c,0x27,0x59,0x3e,0x3b,0x39,0x3b,0x26,0x23,0x38,0x39,0x3b,0x26,0x23,0x38,0x39,0x3b,0x26,0x23,0x38,0x39,0x20,0x22,0xa,0x20,0x20,0x7d,0xa,0x7d,0xa,0x20,0x20,0x7d,0xa,0x7d,0xa, Step #5: p {\012 doctype {\012mdecl {\012entity { name:\012\"D \\'Y>;9;&#89;&#89;&#89 \"\012 }\012}\012 }\012}\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-03ab2508cc2e92981e68aec4744d6f64adb3539f Step #5: Base64: cCB7CiAgZG9jdHlwZSB7Cm1kZWNsIHsKZW50aXR5IHsgbmFtZToKIkQgICBcJ1k+Ozk7JiM4OTsmIzg5OyYjODkgIgogIH0KfQogIH0KfQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3819 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3612007840 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56208df79810, 0x56208e16301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56208e163020,0x56208fffb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03ab2508cc2e92981e68aec4744d6f64adb3539f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4736 processed earlier; will process 6293 files now Step #5: #1 pulse cov: 15531 ft: 15532 exec/s: 0 rss: 197Mb Step #5: #2 pulse cov: 15904 ft: 16841 exec/s: 0 rss: 199Mb Step #5: ==137560== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562084a6e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56208b0d3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56208b0b65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56208b0b64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562084a74d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5620849d5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5620849d0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562084a66c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562087a35f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562087a35f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562087a35f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562087a35f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562087a35f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562087a35f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562087a35f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562087a35f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562087a35f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562087a35f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562089ccaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5620869f7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562086a02be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5620867aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5620867aec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5620867af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5620867ae874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5620867ae874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5620867ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56208b0b8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56208b0c1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56208b0a9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56208b0d4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5574946082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5620849ceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x25,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d, Step #5: }{0,} {0,} {0,}s{0,} {0,}${0,}%{0,} {0,}}{0,} {0,} {0,}s{0,} {0,}${0,} {0,} {0,} Step #5: artifact_prefix='./'; Test unit written to ./oom-d258d7f2c876a0517701d882d3a497ea3a861be0 Step #5: Base64: fXswLH0gezAsfSB7MCx9c3swLH0gezAsfSR7MCx9JXswLH0gezAsfX17MCx9IHswLH0gezAsfXN7MCx9IHswLH0kezAsfSB7MCx9IHswLH0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3820 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3612636152 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e13db07810, 0x55e13dcf101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e13dcf1020,0x55e13fb890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d258d7f2c876a0517701d882d3a497ea3a861be0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4739 processed earlier; will process 6290 files now Step #5: ==137596== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e1345fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e13ac61898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e13ac445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e13ac444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e134602d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e134563b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e13455e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e1345f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e1375c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e1375c3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e1375c3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e1375c3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e1375c3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e1375c3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e1375c3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e1375c3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e1375c3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e1375c3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e139858f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e136585b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e136590be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e13633cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e13633cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e13633d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e13633c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e13633c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e13633c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e13ac46abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e13ac4f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e13ac37699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e13ac62112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e0a36e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e13455cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x42,0x45,0x4f,0x4f,0x4f,0x4f,0x4f,0x47,0x74,0x4f,0x49,0x4f,0x4f,0x4f,0x4b,0x65,0x63,0x4d,0x4f,0x4f,0x4f,0x4f,0x55,0x4f,0x54,0x4f,0x4f,0x4d,0x4f,0x4b,0x4b,0x4f,0x4f,0x4f,0x4f,0x4f,0x47,0x4e,0x4f,0x4f,0x4f,0x4f,0xa,0x70,0x20,0x72,0x65,0x6a,0x65,0x63,0x74,0x20,0x38,0x36, Step #5: onion-key\012ntor-onion-key vBEOOOOOGtOIOOOKecMOOOOUOTOOMOKKOOOOOGNOOOO\012p reject 86 Step #5: artifact_prefix='./'; Test unit written to ./oom-3c91c11dbe6419ee3c42484e8f2cf5c31c8e632a Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHZCRU9PT09PR3RPSU9PT0tlY01PT09PVU9UT09NT0tLT09PT09HTk9PT08KcCByZWplY3QgODY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3821 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3613136805 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ba9ea9b810, 0x55ba9ec8501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ba9ec85020,0x55baa0b1d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3c91c11dbe6419ee3c42484e8f2cf5c31c8e632a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4740 processed earlier; will process 6289 files now Step #5: #1 pulse cov: 3494 ft: 3495 exec/s: 0 rss: 174Mb Step #5: ==137632== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ba955909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ba9bbf5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ba9bbd85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ba9bbd84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ba95596d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ba954f7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ba954f2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ba95588c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ba98557f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ba98557f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ba98557f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ba98557f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ba98557f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ba98557f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ba98557f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ba98557f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ba98557f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ba98557f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ba9a7ecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ba97519b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ba97524be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ba972d0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ba972d0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ba972d1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ba972d0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ba972d0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ba972d0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ba9bbdaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ba9bbe3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ba9bbcb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ba9bbf6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3f9acbf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ba954f0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x69,0x22,0x3c,0x7b,0x27,0xa,0x27,0x49,0x44,0x33,0x4,0x22,0x25,0x5d,0x7f,0x5f,0x26,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $22''2-=''''''/''2-=''''''''''''''-=<''''''''''''-=<'''/''i\"<{'\012'ID3\004\"%]\177_&'.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-1fd4a348c1ce41da7091ed511c1bedae2d9f7f78 Step #5: Base64: JDIyJycyLT0nJycnJycvJycyLT0nJycnJycnJycnJycnJy09PCcnJycnJycnJycnJy09PCcnJy8nJ2kiPHsnCidJRDMEIiVdf18mJy4nJCct Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3822 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3613676922 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a7502df810, 0x55a7504c901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a7504c9020,0x55a7523610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1fd4a348c1ce41da7091ed511c1bedae2d9f7f78' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4742 processed earlier; will process 6287 files now Step #5: ==137668== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a746dd49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a74d439898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a74d41c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a74d41c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a746ddad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a746d3bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a746d36355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a746dccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a749d9bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a749d9bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a749d9bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a749d9bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a749d9bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a749d9bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a749d9bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a749d9bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a749d9bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a749d9bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a74c030f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a748d5db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a748d68be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a748b14c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a748b14c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a748b15738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a748b14874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a748b14874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a748b14874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a74d41eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a74d427928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a74d40f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a74d43a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f15940d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a746d34b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2d,0x25,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x21,0x24,0x29,0x2d,0x2d,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x2b,0x7f,0x7f,0x7f,0x7f,0x7f,0x24,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x32,0xfb,0x0,0x0,0x7f,0x2d,0x2d,0xa,0x3a,0x4e,0x21,0x24,0x47,0x49,0x49,0x27,0x44,0x32,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x3, Step #5: \012-%---BEGI!$)--\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177+\177\177\177\177\177$\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\1772\373\000\000\177--\012:N!$GII'D2\002U -E\012\012\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-c1b0b37bfac53a4c2e79bc821cfccdca619b5d97 Step #5: Base64: Ci0lLS0tQkVHSSEkKS0tf39/f39/f39/f39/f39/fyt/f39/fyR/f39/f39/f39/f39/f39/fzL7AAB/LS0KOk4hJEdJSSdEMgJVIC1FCgoD Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3823 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3614176576 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c7c072810, 0x564c7c25c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c7c25c020,0x564c7e0f40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c1b0b37bfac53a4c2e79bc821cfccdca619b5d97' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4743 processed earlier; will process 6286 files now Step #5: ==137704== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564c72b679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c791cc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c791af5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c791af4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c72b6dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c72aceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c72ac9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c72b5fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c75b2ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c75b2ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c75b2ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c75b2ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c75b2ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c75b2ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c75b2ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c75b2ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c75b2ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c75b2ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c77dc3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c74af0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c74afbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c748a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c748a7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c748a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c748a7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c748a7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c748a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c791b1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c791ba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c791a2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c791cd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb32eb3e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c72ac7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xef,0xb7,0xba,0xe0,0xbe,0x81,0xe0,0xbe,0x82,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81, Step #5: ws:\357\267\272\340\276\201\340\276\202\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-3e42bef4064663fe38eb6ea1be266cba49f5a874 Step #5: Base64: d3M677e64L6B4L6C4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3824 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3614671357 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56544a3bd810, 0x56544a5a701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56544a5a7020,0x56544c43f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3e42bef4064663fe38eb6ea1be266cba49f5a874' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4744 processed earlier; will process 6285 files now Step #5: #1 pulse cov: 3833 ft: 3834 exec/s: 0 rss: 173Mb Step #5: ==137740== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565440eb29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565447517898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5654474fa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5654474fa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565440eb8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565440e19b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565440e14355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565440eaac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565443e79f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565443e79f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565443e79f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565443e79f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565443e79f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565443e79f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565443e79f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565443e79f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565443e79f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565443e79f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56544610ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565442e3bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565442e46be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565442bf2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565442bf2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565442bf3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565442bf2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565442bf2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565442bf2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5654474fcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565447505928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5654474ed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565447518112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f59546fd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565440e12b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1e,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a, Step #5: \036**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012** Step #5: artifact_prefix='./'; Test unit written to ./oom-bc5586680602730c90563bc3fc4093314e76ba44 Step #5: Base64: HioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioq Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3825 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3615214368 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cade635810, 0x55cade81f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cade81f020,0x55cae06b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bc5586680602730c90563bc3fc4093314e76ba44' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4746 processed earlier; will process 6283 files now Step #5: ==137776== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cad512a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cadb78f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cadb7725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cadb7724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cad5130d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cad5091b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cad508c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cad5122c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cad80f1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cad80f1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cad80f1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cad80f1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cad80f1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cad80f1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cad80f1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cad80f1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cad80f1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cad80f1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cada386f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cad70b3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cad70bebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cad6e6ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cad6e6ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cad6e6b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cad6e6a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cad6e6a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cad6e6a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cadb774abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cadb77d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cadb765699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cadb790112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbc9ffd7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cad508ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x48,0x55,0x4c,0x55,0x22,0x2f,0xe0,0xb9,0x83,0xe0,0xbb,0x84,0xe0,0xb9,0x83,0xe9,0xbb,0x83,0xe0,0xb9,0x84,0xe0,0xb9,0x83,0xe0,0xb8,0x83,0x43,0xe0,0xb9,0x83,0xe1,0xb9,0x83,0xea,0xb9,0x83,0xe0,0x72,0xba,0x83,0xe0,0xb9,0x84,0xe0,0xb9,0x84,0xe1,0xbd,0x83,0x43,0xe0,0xb9,0x83,0xe1,0xb9,0x83,0xe7,0xb9,0x83,0xe0,0xba,0x83,0xe0,0xb9,0x84,0xe0,0xb9,0x83,0xe0,0xbb,0x83,0xe0,0xb9,0x84,0xe0,0xca,0xb7,0x4,0x48, Step #5: [HULU\"/\340\271\203\340\273\204\340\271\203\351\273\203\340\271\204\340\271\203\340\270\203C\340\271\203\341\271\203\352\271\203\340r\272\203\340\271\204\340\271\204\341\275\203C\340\271\203\341\271\203\347\271\203\340\272\203\340\271\204\340\271\203\340\273\203\340\271\204\340\312\267\004H Step #5: artifact_prefix='./'; Test unit written to ./oom-552b7ee4c8537d2ee758b47f414055b5ea0e8fab Step #5: Base64: W0hVTFUiL+C5g+C7hOC5g+m7g+C5hOC5g+C4g0PguYPhuYPquYPgcrqD4LmE4LmE4b2DQ+C5g+G5g+e5g+C6g+C5hOC5g+C7g+C5hODKtwRI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3826 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3615715042 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564008af3810, 0x564008cdd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564008cdd020,0x56400ab750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/552b7ee4c8537d2ee758b47f414055b5ea0e8fab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4747 processed earlier; will process 6282 files now Step #5: ==137812== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563fff5e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564005c4d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564005c305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564005c304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563fff5eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563fff54fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563fff54a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563fff5e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5640025aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5640025aff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5640025aff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5640025aff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5640025aff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5640025aff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5640025aff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5640025aff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5640025aff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5640025aff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564004844f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564001571b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56400157cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564001328c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564001328c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564001329738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564001328874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564001328874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564001328874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564005c32abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564005c3b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564005c23699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564005c4e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8c7fd5f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563fff548b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x39,0x3,0x6,0x0,0x0,0x31,0x0,0x24,0x54,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x69,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x1,0x14,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xf3,0xa0,0x81,0x9e,0x3d,0x29,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0xe,0xe,0x24, Step #5: ID2147483649\003\006\000\0001\000$T=\012=\012=\012=\012=\012=\012=i\012=\012=\012=\012=\012=\012\001\024=\012=\012=\012=\012=\012=\012\363\240\201\236=)=\012=\012==\012=\012=\012\000\000\016\016$ Step #5: artifact_prefix='./'; Test unit written to ./oom-9530c252e9e909b5d40734ec2f5b6348e823b675 Step #5: Base64: SUQyMTQ3NDgzNjQ5AwYAADEAJFQ9Cj0KPQo9Cj0KPQo9aQo9Cj0KPQo9Cj0KARQ9Cj0KPQo9Cj0KPQrzoIGePSk9Cj0KPT0KPQo9CgAADg4k Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3827 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3616219676 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640affcf810, 0x5640b01b901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640b01b9020,0x5640b20510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9530c252e9e909b5d40734ec2f5b6348e823b675' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4748 processed earlier; will process 6281 files now Step #5: #1 pulse cov: 3884 ft: 3885 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 11670 ft: 12573 exec/s: 0 rss: 194Mb Step #5: ==137848== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5640a6ac49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5640ad129898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640ad10c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640ad10c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5640a6acad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5640a6a2bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5640a6a26355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5640a6abcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5640a9a8bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5640a9a8bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5640a9a8bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5640a9a8bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5640a9a8bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5640a9a8bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5640a9a8bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5640a9a8bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5640a9a8bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5640a9a8bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5640abd20f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5640a8a4db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5640a8a58be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5640a8804c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5640a8804c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5640a8805738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5640a8804874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5640a8804874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5640a8804874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5640ad10eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5640ad117928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5640ad0ff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5640ad12a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4d359c1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5640a6a24b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3b,0x0,0x20,0x22,0x3b,0x26,0x3b,0x3b,0x1,0x14,0x3b,0x3b,0x30,0x3b,0x25,0x0,0x1b,0x24,0x0,0x31,0x0,0x0,0x30,0x3b,0x8,0x0,0x1e,0x8,0x0,0x0,0xe,0x0,0x21,0x29,0x12,0x17,0x3b,0x1,0x0,0x0,0x2a,0xc,0x0,0x0,0x3a,0x0,0x2b,0x0,0x25,0x0,0x26,0x18,0x0,0x14,0x0,0x0,0x17,0x1e,0x3b,0x3b,0x20,0x3b,0x0,0x3b,0x12,0x29,0x3b,0x18,0x3b,0x2a,0x3b,0x3a,0x3b,0x3b,0x3,0x24,0x3b,0xe,0x3b,0x21,0x3b, Step #5: ;\000 \";&;;\001\024;;0;%\000\033$\0001\000\0000;\010\000\036\010\000\000\016\000!)\022\027;\001\000\000*\014\000\000:\000+\000%\000&\030\000\024\000\000\027\036;; ;\000;\022);\030;*;:;;\003$;\016;!; Step #5: artifact_prefix='./'; Test unit written to ./oom-6bfc9c7b0e01ab73f43eb91e602168c1ca16ad23 Step #5: Base64: OwAgIjsmOzsBFDs7MDslABskADEAADA7CAAeCAAADgAhKRIXOwEAACoMAAA6ACsAJQAmGAAUAAAXHjs7IDsAOxIpOxg7Kjs6OzsDJDsOOyE7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3828 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3616823332 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562181784810, 0x56218196e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56218196e020,0x5621838060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bfc9c7b0e01ab73f43eb91e602168c1ca16ad23' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4751 processed earlier; will process 6278 files now Step #5: #1 pulse cov: 3724 ft: 3725 exec/s: 0 rss: 173Mb Step #5: ==137884== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5621782799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56217e8de898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56217e8c15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56217e8c14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56217827fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5621781e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5621781db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562178271c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56217b240f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56217b240f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56217b240f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56217b240f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56217b240f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56217b240f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56217b240f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56217b240f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56217b240f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56217b240f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56217d4d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56217a202b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56217a20dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562179fb9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562179fb9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562179fba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562179fb9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562179fb9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562179fb9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56217e8c3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56217e8cc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56217e8b4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56217e8df112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5361118082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5621781d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xa,0x73,0x75,0x62,0x7b,0x69,0x3a,0x30,0x20,0x7d,0xa,0x73,0x75,0x62,0x7b,0x69,0x3a,0x39,0x20,0x7d,0xa,0x73,0x75,0x62,0x20,0x7b,0x20,0x64,0x3a,0x31,0x20,0x7d,0xa,0x73,0x75,0x62,0x20,0x7b,0x20,0x64,0x3a,0x30,0x7d,0xa,0x73,0x75,0x62,0x20,0x7b,0x73,0x3a,0x20,0x22,0xe1,0x9a,0x80,0x22,0x7d,0x73,0x75,0x62,0x7b,0x73,0x3a,0x20,0x22,0xe2,0x80,0x84,0x22,0x7d, Step #5: FUZZTESTv1\012sub{i:0 }\012sub{i:9 }\012sub { d:1 }\012sub { d:0}\012sub {s: \"\341\232\200\"}sub{s: \"\342\200\204\"} Step #5: artifact_prefix='./'; Test unit written to ./oom-119e627626b5175051d77fd1e47952a360b024fe Step #5: Base64: RlVaWlRFU1R2MQpzdWJ7aTowIH0Kc3Vie2k6OSB9CnN1YiB7IGQ6MSB9CnN1YiB7IGQ6MH0Kc3ViIHtzOiAi4ZqAIn1zdWJ7czogIuKAhCJ9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3829 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3617370779 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c1f05b1810, 0x55c1f079b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c1f079b020,0x55c1f26330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/119e627626b5175051d77fd1e47952a360b024fe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4753 processed earlier; will process 6276 files now Step #5: ==137920== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c1e70a69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c1ed70b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c1ed6ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c1ed6ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c1e70acd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c1e700db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c1e7008355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c1e709ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c1ea06df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c1ea06df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c1ea06df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c1ea06df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c1ea06df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c1ea06df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c1ea06df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c1ea06df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c1ea06df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c1ea06df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c1ec302f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c1e902fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c1e903abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c1e8de6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c1e8de6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c1e8de7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c1e8de6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c1e8de6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c1e8de6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c1ed6f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c1ed6f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c1ed6e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c1ed70c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3b92f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c1e7006b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0xe7,0xb0,0xa3,0x3b,0x25,0xe7,0xb0,0xa3,0x3b,0x25,0xe7,0xb0,0x9a,0x3b,0x25,0xe7,0xb0,0xa3,0x3b,0x25,0xe7,0xb0,0xa3,0x3b,0x25,0xe7,0xb0,0xa3,0x3b,0x25,0xe7,0xb0,0xa3,0x3b,0x25,0xe7,0xb0,0xa3,0x3b,0x25,0xe7,0xb0,0xa3,0x3b,0x25,0xe7,0xb0,0xa3,0x3b,0x25,0xe7,0xb0,0xa3,0x3b,0x25,0xe7,0xb0,0xa3,0x3b,0x25,0xe7,0xa0,0xa3,0x49,0x3b,0x25,0xe7,0xb0,0xa3,0x3b,0x25,0xe7,0xb0,0xa3,0x3b,0x25,0xe7,0xb0,0xa3,0x3b, Step #5: %\347\260\243;%\347\260\243;%\347\260\232;%\347\260\243;%\347\260\243;%\347\260\243;%\347\260\243;%\347\260\243;%\347\260\243;%\347\260\243;%\347\260\243;%\347\260\243;%\347\240\243I;%\347\260\243;%\347\260\243;%\347\260\243; Step #5: artifact_prefix='./'; Test unit written to ./oom-efbf62d4390f2cfad9e67ddb6c69224ae7fbddb1 Step #5: Base64: Jeewozsl57CjOyXnsJo7Jeewozsl57CjOyXnsKM7Jeewozsl57CjOyXnsKM7Jeewozsl57CjOyXnsKM7Jeego0k7Jeewozsl57CjOyXnsKM7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3830 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3617874550 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563282c47810, 0x563282e3101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563282e31020,0x563284cc90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/efbf62d4390f2cfad9e67ddb6c69224ae7fbddb1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4754 processed earlier; will process 6275 files now Step #5: #1 pulse cov: 3726 ft: 3727 exec/s: 0 rss: 176Mb Step #5: ==137956== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56327973c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56327fda1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56327fd845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56327fd844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563279742d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5632796a3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56327969e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563279734c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56327c703f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56327c703f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56327c703f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56327c703f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56327c703f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56327c703f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56327c703f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56327c703f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56327c703f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56327c703f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56327e998f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56327b6c5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56327b6d0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56327b47cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56327b47cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56327b47d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56327b47c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56327b47c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56327b47c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56327fd86abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56327fd8f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56327fd77699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56327fda2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd2b27ab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56327969cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xb,0x73,0x2f,0x2d,0x28,0x1,0x0,0x21,0x69,0x66,0x31,0x30,0x29,0x69,0x66,0x31,0x30,0x29,0x29,0x29,0x29,0xd7,0xa9,0x1,0x0,0x0,0x15,0x28,0x30,0x29,0x29,0xd7,0xa9,0x28,0x30,0x9,0x37,0x21,0x29,0x0,0x0,0x4,0x0,0x0,0x0,0x0,0x15,0x0,0x73,0x29,0x29,0x29,0xd7,0xa9,0x28,0x30,0x9,0x36,0x21,0x29,0xd7,0xa4,0x37,0x21,0x29,0x29,0x29,0xd7,0xa9,0x38,0x20,0x30,0x28,0x30,0x9,0x37,0x21,0x29,0x0,0x8d,0x0, Step #5: -\013s/-(\001\000!if10)if10))))\327\251\001\000\000\025(0))\327\251(0\0117!)\000\000\004\000\000\000\000\025\000s)))\327\251(0\0116!)\327\2447!)))\327\2518 0(0\0117!)\000\215\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7f866b582027377629207ac3db3b1c27271b46b1 Step #5: Base64: LQtzLy0oAQAhaWYxMClpZjEwKSkpKdepAQAAFSgwKSnXqSgwCTchKQAABAAAAAAVAHMpKSnXqSgwCTYhKdekNyEpKSnXqTggMCgwCTchKQCNAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3831 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3618425597 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b2ed9df810, 0x55b2edbc901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b2edbc9020,0x55b2efa610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f866b582027377629207ac3db3b1c27271b46b1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4756 processed earlier; will process 6273 files now Step #5: ==137992== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b2e44d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b2eab39898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b2eab1c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b2eab1c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b2e44dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b2e443bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b2e4436355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b2e44ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b2e749bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b2e749bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b2e749bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b2e749bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b2e749bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b2e749bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b2e749bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b2e749bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b2e749bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b2e749bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b2e9730f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b2e645db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b2e6468be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b2e6214c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b2e6214c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b2e6215738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b2e6214874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b2e6214874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b2e6214874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b2eab1eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b2eab27928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b2eab0f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b2eab3a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f28675d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b2e4434b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x3d,0x79,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x44,0x1,0x79,0x0,0x0,0x0,0x0,0x54,0x24, Step #5: ~$=y\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000D\001y\000\000\000\000T$ Step #5: artifact_prefix='./'; Test unit written to ./oom-96e0e48b21c0988d3939d4517f36bcec5383bf66 Step #5: Base64: fiQ9eQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEQBeQAAAABUJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3832 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3618926592 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5606f72b3810, 0x5606f749d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5606f749d020,0x5606f93350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/96e0e48b21c0988d3939d4517f36bcec5383bf66' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4757 processed earlier; will process 6272 files now Step #5: ==138028== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5606edda89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5606f440d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606f43f05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606f43f04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5606eddaed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5606edd0fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5606edd0a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5606edda0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5606f0d6ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5606f0d6ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5606f0d6ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5606f0d6ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5606f0d6ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5606f0d6ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5606f0d6ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5606f0d6ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5606f0d6ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5606f0d6ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606f3004f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5606efd31b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5606efd3cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5606efae8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5606efae8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5606efae9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5606efae8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5606efae8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5606efae8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5606f43f2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5606f43fb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5606f43e3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5606f440e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f432b94d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5606edd08b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xdb,0x80,0x39,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x8,0x0,0x0,0x0,0x39, Step #5: \333\200\333\2009\000*********************************************\333\2009\000*********************\000\010\000\000\0009 Step #5: artifact_prefix='./'; Test unit written to ./oom-441dc252c161fd297155257b57fe8b57ea5ae358 Step #5: Base64: 24DbgDkAKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioq24A5ACoqKioqKioqKioqKioqKioqKioqKgAIAAAAOQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3833 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3619433085 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5614a4b97810, 0x5614a4d8101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5614a4d81020,0x5614a6c190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/441dc252c161fd297155257b57fe8b57ea5ae358' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4758 processed earlier; will process 6271 files now Step #5: ==138064== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56149b68c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5614a1cf1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5614a1cd45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5614a1cd44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56149b692d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56149b5f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56149b5ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56149b684c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56149e653f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56149e653f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56149e653f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56149e653f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56149e653f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56149e653f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56149e653f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56149e653f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56149e653f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56149e653f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5614a08e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56149d615b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56149d620be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56149d3ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56149d3ccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56149d3cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56149d3cc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56149d3cc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56149d3cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5614a1cd6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5614a1cdf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5614a1cc7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5614a1cf2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f317eca8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56149b5ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x27,0xdd,0xa0,0xdd,0xa0,0xdd,0xa1,0xca,0xb6,0xdd,0xa0,0xdd,0xa0,0xdd,0xa1,0xdd,0xa1,0xdd,0xa0,0xdd,0xa0,0xdd,0xa1,0xdd,0xa1,0xdd,0x88,0xdd,0x9a,0xc9,0xb6,0xdd,0xa0,0xdd,0xa0,0xdd,0xa1,0x0,0x0,0x0,0x72,0x27,0xdd,0xa0,0xdd,0xa0,0xdd,0xa1,0xca,0xb6,0xdd,0xa0,0xdd,0xa0,0xdd,0xa1,0xdd,0xa1,0xdd,0xa0,0xdd,0xa0,0xdd,0xa1,0xdd,0xa1,0xdd,0x88,0xdd,0x9a,0xca,0xb6,0xdd,0xa0,0xdd,0xa0,0xdd,0xa1,0x0,0x3b,0x5, Step #5: r'\335\240\335\240\335\241\312\266\335\240\335\240\335\241\335\241\335\240\335\240\335\241\335\241\335\210\335\232\311\266\335\240\335\240\335\241\000\000\000r'\335\240\335\240\335\241\312\266\335\240\335\240\335\241\335\241\335\240\335\240\335\241\335\241\335\210\335\232\312\266\335\240\335\240\335\241\000;\005 Step #5: artifact_prefix='./'; Test unit written to ./oom-0b2a9d3f5d64469534987cb8050e16a0b7a0317e Step #5: Base64: cifdoN2g3aHKtt2g3aDdod2h3aDdoN2h3aHdiN2aybbdoN2g3aEAAAByJ92g3aDdocq23aDdoN2h3aHdoN2g3aHdod2I3ZrKtt2g3aDdoQA7BQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3834 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3619939111 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d743095810, 0x55d74327f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d74327f020,0x55d7451170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b2a9d3f5d64469534987cb8050e16a0b7a0317e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4759 processed earlier; will process 6270 files now Step #5: ==138100== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d739b8a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d7401ef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7401d25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7401d24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d739b90d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d739af1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d739aec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d739b82c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d73cb51f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d73cb51f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d73cb51f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d73cb51f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d73cb51f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d73cb51f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d73cb51f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d73cb51f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d73cb51f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d73cb51f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d73ede6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d73bb13b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d73bb1ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d73b8cac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d73b8cac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d73b8cb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d73b8ca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d73b8ca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d73b8ca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d7401d4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d7401dd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d7401c5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d7401f0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3336b0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d739aeab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x3a,0x3e,0xa,0x20,0xe2,0x80,0x83,0xa,0x20,0xe2,0x80,0x87,0xa,0x20,0xe2,0x80,0x8b,0xa,0x20,0xe2,0x80,0x87,0xa,0x20,0xe2,0x80,0x87,0xa,0x20,0xe2,0x80,0x87,0xa,0x20,0xe2,0x80,0x83,0xa,0x20,0xe2,0x80,0x8e,0xa,0x20,0xe2,0x80,0x83,0xa,0x20,0xe2,0x80,0x87,0xa,0x20,0xe2,0x80,0x83,0xa,0x20,0xe2,0x80,0x87,0xa,0x20,0xe2,0x80,0x83,0xa,0x20,0xe2,0x80,0x83,0xa,0x20,0xe2,0x80,0x83,0xa,0xe2,0x80,0x84, Step #5: /:>\012 \342\200\203\012 \342\200\207\012 \342\200\213\012 \342\200\207\012 \342\200\207\012 \342\200\207\012 \342\200\203\012 \342\200\216\012 \342\200\203\012 \342\200\207\012 \342\200\203\012 \342\200\207\012 \342\200\203\012 \342\200\203\012 \342\200\203\012\342\200\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-5aae3d86234fbb4d9b7792317ddec569b2339795 Step #5: Base64: Lzo+CiDigIMKIOKAhwog4oCLCiDigIcKIOKAhwog4oCHCiDigIMKIOKAjgog4oCDCiDigIcKIOKAgwog4oCHCiDigIMKIOKAgwog4oCDCuKAhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3835 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3620441628 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5612c6d7b810, 0x5612c6f6501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5612c6f65020,0x5612c8dfd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5aae3d86234fbb4d9b7792317ddec569b2339795' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4760 processed earlier; will process 6269 files now Step #5: #1 pulse cov: 4367 ft: 4368 exec/s: 0 rss: 176Mb Step #5: ==138136== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5612bd8709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5612c3ed5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5612c3eb85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5612c3eb84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5612bd876d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5612bd7d7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5612bd7d2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5612bd868c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5612c0837f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5612c0837f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5612c0837f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5612c0837f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5612c0837f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5612c0837f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5612c0837f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5612c0837f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5612c0837f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5612c0837f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5612c2accf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5612bf7f9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5612bf804be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5612bf5b0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5612bf5b0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5612bf5b1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5612bf5b0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5612bf5b0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5612bf5b0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5612c3ebaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5612c3ec3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5612c3eab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5612c3ed6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faec1d42082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5612bd7d0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x61,0x0,0x22,0x31,0x8,0x2a,0x2a,0xd7,0xa9,0x28,0x2e,0x2e,0x1,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x30,0x0,0x22,0x31,0x8,0x2a,0x2a,0xd7,0xa9,0x43,0x48,0x43,0x0,0x0,0x0,0x50,0x8,0x74,0x0,0x0,0x0,0x1f,0x2e,0xd,0xe6,0x0,0x9,0x78,0x5d, Step #5: ID3\004****************************a\000\"1\010**\327\251(..\001........0\000\"1\010**\327\251CHC\000\000\000P\010t\000\000\000\037.\015\346\000\011x] Step #5: artifact_prefix='./'; Test unit written to ./oom-f55e00785e10ae1c7678d133188d8df4f975ca2d Step #5: Base64: SUQzBCoqKioqKioqKioqKioqKioqKioqKioqKioqKiphACIxCCoq16koLi4BLi4uLi4uLi4wACIxCCoq16lDSEMAAABQCHQAAAAfLg3mAAl4XQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3836 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3620988305 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c681651810, 0x55c68183b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c68183b020,0x55c6836d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f55e00785e10ae1c7678d133188d8df4f975ca2d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4762 processed earlier; will process 6267 files now Step #5: ==138172== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c6781469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c67e7ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c67e78e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c67e78e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c67814cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6780adb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6780a8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c67813ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c67b10df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c67b10df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c67b10df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c67b10df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c67b10df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c67b10df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c67b10df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c67b10df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c67b10df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c67b10df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c67d3a2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c67a0cfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c67a0dabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c679e86c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c679e86c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c679e87738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c679e86874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c679e86874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c679e86874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c67e790abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c67e799928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c67e781699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c67e7ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1feb751082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6780a6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x76,0x21,0x39,0xa,0x0,0x70,0x69,0x7d,0x7d,0x7d,0x7d,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x72,0x65,0x61,0x6d,0xd7,0xaf,0x2d,0x0,0x73,0x7e,0x74,0x39,0xa,0x0,0x70,0x69,0x7d,0x7d,0x7d,0x7d,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x72,0x65,0x61,0x6d,0xd7,0xaf,0x2d,0x0,0x73,0x7e,0x74,0x39,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0xd7,0xa3,0x1,0xd7,0xa3,0x2d,0x0, Step #5: #v!9\012\000pi}}}}dddddddddream\327\257-\000s~t9\012\000pi}}}}dddddddream\327\257-\000s~t9>>>>>>>>>>>>>>>\327\243\001\327\243-\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a6b872d95062cc851853858cf576ef0860b3e0e7 Step #5: Base64: I3YhOQoAcGl9fX19ZGRkZGRkZGRkcmVhbdevLQBzfnQ5CgBwaX19fX1kZGRkZGRkcmVhbdevLQBzfnQ5Pj4+Pj4+Pj4+Pj4+Pj4+16MB16MtAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3837 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3621495559 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555598763810, 0x55559894d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55559894d020,0x55559a7e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a6b872d95062cc851853858cf576ef0860b3e0e7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4763 processed earlier; will process 6266 files now Step #5: ==138208== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55558f2589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5555958bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5555958a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5555958a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55558f25ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55558f1bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55558f1ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55558f250c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55559221ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55559221ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55559221ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55559221ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55559221ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55559221ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55559221ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55559221ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55559221ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55559221ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5555944b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5555911e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5555911ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555590f98c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555590f98c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555590f99738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555590f98874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555590f98874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555590f98874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5555958a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5555958ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555595893699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5555958be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff8c8194082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55558f1b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x20,0x7b,0xa,0x20,0x20,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x6d,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x63,0x6f,0x6d,0x6d,0x65,0x6e,0x74,0x3a,0x20,0x22,0x46,0x46,0x46,0x37,0x22,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x7d,0xa,0x7d,0xa, Step #5: p {\012 doctype {\012 mdecl {\012 m {\012 comment: \"FFF7\"\012 }\012 }\012 }\012}\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-452b7d4b98707af3e6ee773c4d70ede1eacebe38 Step #5: Base64: cCB7CiAgZG9jdHlwZSB7CiAgICBtZGVjbCB7CiAgICAgIG0gewogICAgICAgIGNvbW1lbnQ6ICJGRkY3IgogICAgICB9CiAgICB9CiAgfQp9Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3838 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3621995796 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e7c9fd4810, 0x55e7ca1be01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e7ca1be020,0x55e7cc0560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/452b7d4b98707af3e6ee773c4d70ede1eacebe38' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4764 processed earlier; will process 6265 files now Step #5: ==138244== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e7c0ac99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e7c712e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7c71115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7c71114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e7c0acfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e7c0a30b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e7c0a2b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e7c0ac1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e7c3a90f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e7c3a90f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e7c3a90f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e7c3a90f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e7c3a90f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e7c3a90f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e7c3a90f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e7c3a90f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e7c3a90f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e7c3a90f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e7c5d25f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e7c2a52b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e7c2a5dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e7c2809c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e7c2809c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e7c280a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e7c2809874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e7c2809874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e7c2809874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e7c7113abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e7c711c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e7c7104699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e7c712f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf9aeab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e7c0a29b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x37,0x3a,0x5b,0x22,0xc3,0xbf,0xef,0xb7,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xb7,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xdf,0x41,0x70,0x31,0xc6,0xc6,0xc6,0xbf,0xef,0xbf,0xbf,0x6e,0x75,0x23,0x2c,0x4b,0x22,0x5d,0x7d,0x59,0x27,0xc3,0xff,0xff,0x3a,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xbf,0x35,0x70,0x27,0x3a,0x3a,0x44,0x3a, Step #5: $3::{$7:[\"\303\277\357\267\277\357\277\277\357\277\277\357\277\277\357\277\277\357\267\277\357\277\277\357\277\277\357\277\277\357\277\277\337Ap1\306\306\306\277\357\277\277nu#,K\"]}Y'\303\377\377:\377\377\377\377\377\377\377\2775p'::D: Step #5: artifact_prefix='./'; Test unit written to ./oom-809bcf8ba7ab92cec13516c9856ba38406efeafc Step #5: Base64: JDM6OnskNzpbIsO/77e/77+/77+/77+/77+/77e/77+/77+/77+/77+/30FwMcbGxr/vv79udSMsSyJdfVknw///Ov////////+/NXAnOjpEOg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3839 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3622496091 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571c991a810, 0x5571c9b0401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571c9b04020,0x5571cb99c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/809bcf8ba7ab92cec13516c9856ba38406efeafc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4765 processed earlier; will process 6264 files now Step #5: #1 pulse cov: 4009 ft: 4010 exec/s: 0 rss: 173Mb Step #5: ==138280== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571c040f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571c6a74898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571c6a575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571c6a574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571c0415d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571c0376b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571c0371355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571c0407c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571c33d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571c33d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571c33d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571c33d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571c33d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571c33d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571c33d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571c33d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571c33d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571c33d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571c566bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571c2398b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571c23a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571c214fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571c214fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571c2150738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571c214f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571c214f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571c214f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571c6a59abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571c6a62928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571c6a4a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571c6a75112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3d806b0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571c036fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x42,0x3c,0xdb,0xbe,0x7e,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x21,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x31,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x7e, Step #5: ~~~~~~B<\333\276~\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031!\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\0311\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031~ Step #5: artifact_prefix='./'; Test unit written to ./oom-5702f1f6144d31de6c9ff89f52630e4bc24aacb6 Step #5: Base64: fn5+fn5+Qjzbvn4ZGRkZGRkZGRkZGRkZGRkZGRkhGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGTEZGRkZGRkZGRkZGRkZGRkZfg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3840 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3623040767 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a7a005810, 0x559a7a1ef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a7a1ef020,0x559a7c0870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5702f1f6144d31de6c9ff89f52630e4bc24aacb6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4767 processed earlier; will process 6262 files now Step #5: #1 pulse cov: 3855 ft: 3856 exec/s: 0 rss: 175Mb Step #5: ==138316== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559a70afa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a7715f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a771425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a771424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a70b00d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a70a61b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a70a5c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a70af2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a73ac1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a73ac1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a73ac1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a73ac1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a73ac1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a73ac1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a73ac1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a73ac1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a73ac1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a73ac1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a75d56f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a72a83b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a72a8ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a7283ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a7283ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a7283b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a7283a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a7283a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a7283a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a77144abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a7714d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a77135699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a77160112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5680c26082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a70a5ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2c,0x2b,0xb,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x1a,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0x73,0x73,0x73,0x73,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0xee,0x2b,0xa,0x2e,0x2b,0x2b,0x2b,0xa,0x2b,0xdf, Step #5: +\012+\012+\012,+\013\012+\012+\012+\012+\012+\032+\012+\012+\012+\012+\012+ssssss\012+\012+\012+\012+\012+s\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012\012+\012+\356+\012.+++\012+\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-01ac3f791411c50a288f5bd8266f7033703479d3 Step #5: Base64: KworCisKLCsLCisKKworCisKKxorCisKKworCisKK3Nzc3NzcworCisKKworCitzCisKKworCisKKworCisKKworCisKCisKK+4rCi4rKysKK98= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3841 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3623610988 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d77795810, 0x561d7797f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d7797f020,0x561d798170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01ac3f791411c50a288f5bd8266f7033703479d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4769 processed earlier; will process 6260 files now Step #5: ==138352== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d6e28a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d748ef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d748d25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d748d24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d6e290d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d6e1f1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d6e1ec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d6e282c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d71251f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d71251f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d71251f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d71251f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d71251f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d71251f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d71251f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d71251f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d71251f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d71251f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d734e6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d70213b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d7021ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d6ffcac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d6ffcac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d6ffcb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d6ffca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d6ffca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d6ffca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d748d4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d748dd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d748c5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d748f0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3e9425082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d6e1eab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x49,0x0,0x22,0x54,0x4b,0x4e,0x2,0x73,0x74,0x0,0x22,0x54,0x4b,0x4e,0x2d,0x2e,0x2e,0x2e,0xde,0x44,0x2a, Step #5: n.............................................................I\000\"TKN\002st\000\"TKN-...\336D* Step #5: artifact_prefix='./'; Test unit written to ./oom-feb7aad1f5b1d6206621ec3485c9c1f8b6ee55f9 Step #5: Base64: bi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi5JACJUS04Cc3QAIlRLTi0uLi7eRCo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3842 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3624111901 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561716b0c810, 0x561716cf601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561716cf6020,0x561718b8e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/feb7aad1f5b1d6206621ec3485c9c1f8b6ee55f9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4770 processed earlier; will process 6259 files now Step #5: ==138388== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56170d6019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561713c66898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561713c495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561713c494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56170d607d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56170d568b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56170d563355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56170d5f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5617105c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5617105c8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5617105c8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5617105c8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5617105c8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5617105c8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5617105c8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5617105c8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5617105c8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5617105c8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56171285df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56170f58ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56170f595be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56170f341c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56170f341c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56170f342738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56170f341874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56170f341874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56170f341874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561713c4babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561713c54928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561713c3c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561713c67112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f03577f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56170d561b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2c,0x2b,0xb,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x22,0xa,0x2b,0x1a,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0x73,0x73,0x73,0x73,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0xee,0x2b,0xa,0x2e,0x2b,0x2b,0x2b,0xa,0x2b,0xdf, Step #5: +\012+\012+\012,+\013\012+\012+\012+\012\"\012+\032+\012+\012+\012+\012+\012+ssssss\012+\012+\012+\012+\012+s\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012\012+\012+\356+\012.+++\012+\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-c582cc7455974134923367fd031b0cdf4ebda681 Step #5: Base64: KworCisKLCsLCisKKworCiIKKxorCisKKworCisKK3Nzc3NzcworCisKKworCitzCisKKworCisKKworCisKKworCisKCisKK+4rCi4rKysKK98= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3843 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3624654257 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55da08303810, 0x55da084ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55da084ed020,0x55da0a3850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c582cc7455974134923367fd031b0cdf4ebda681' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4771 processed earlier; will process 6258 files now Step #5: #1 pulse cov: 3547 ft: 3548 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4252 ft: 4471 exec/s: 0 rss: 176Mb Step #5: ==138424== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d9fedf89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55da0545d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55da054405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55da054404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d9fedfed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d9fed5fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d9fed5a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d9fedf0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55da01dbff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55da01dbff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55da01dbff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55da01dbff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55da01dbff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55da01dbff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55da01dbff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55da01dbff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55da01dbff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55da01dbff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55da04054f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55da00d81b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55da00d8cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55da00b38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55da00b38c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55da00b39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55da00b38874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55da00b38874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55da00b38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55da05442abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55da0544b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55da05433699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55da0545e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7de3009082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d9fed58b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2c,0x2b,0xb,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0x73,0x73,0x73,0x73,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0xee,0x2b,0xa,0x2e,0x2b,0x2b,0x2b,0xa,0x2b,0xdf, Step #5: +\012+\012+\012,+\013\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+ssssss\012+\012+\012+\012+\012+s\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012\012+\012+\356+\012.+++\012+\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-674499c478471aa45f3dfe135f67db2009cf8829 Step #5: Base64: KworCisKLCsLCisKKworCisKKworCisKKworCisKK3Nzc3NzcworCisKKworCitzCisKKworCisKKworCisKKworCisKCisKK+4rCi4rKysKK98= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3844 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3625261466 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e28875810, 0x559e28a5f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e28a5f020,0x559e2a8f70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/674499c478471aa45f3dfe135f67db2009cf8829' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4774 processed earlier; will process 6255 files now Step #5: ==138460== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559e1f36a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e259cf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e259b25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e259b24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e1f370d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e1f2d1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e1f2cc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e1f362c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e22331f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e22331f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e22331f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e22331f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e22331f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e22331f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e22331f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e22331f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e22331f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e22331f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e245c6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e212f3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e212febe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e210aac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e210aac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e210ab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e210aa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e210aa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e210aa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e259b4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e259bd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e259a5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e259d0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3513960082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e1f2cab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x6f,0xcc,0xb2,0x3e,0xcc,0xb2,0xcc,0x90,0xcf,0xb2,0x3c,0x21,0x5b,0x43,0x44,0x41,0x54,0x41,0x5b,0x3e,0xcc,0xb2,0xcc,0xb2,0xcc,0xb1,0xcc,0xb3,0xcc,0xb2,0xcc,0xb2,0xcc,0xb1,0xcc,0xb2,0xcc,0xb1,0xcc,0xb2,0xcc,0xb2,0xcc,0xb2,0xcc,0xb1,0xcc,0xb3,0x6f,0xcc,0xb2,0xcc,0xb2,0x3e,0xcc,0xb2,0xcc,0xb1,0xcc,0xb3,0xcc,0xb2,0xcc,0xb2,0xcc,0xb2,0xcc,0xb1,0xcc,0xb3,0xcc,0xb2,0xcc,0xb2,0xcc,0xb2,0xcc,0xb1,0xcc,0xb3,0xcc,0xb2, Step #5: <o\314\262>\314\262\314\220\317\262<![CDATA[>\314\262\314\262\314\261\314\263\314\262\314\262\314\261\314\262\314\261\314\262\314\262\314\262\314\261\314\263o\314\262\314\262>\314\262\314\261\314\263\314\262\314\262\314\262\314\261\314\263\314\262\314\262\314\262\314\261\314\263\314\262 Step #5: artifact_prefix='./'; Test unit written to ./oom-1da0242a25c0fb30f419d06be4e94738f1858669 Step #5: Base64: PG/Msj7MssyQz7I8IVtDREFUQVs+zLLMssyxzLPMssyyzLHMssyxzLLMssyyzLHMs2/MssyyPsyyzLHMs8yyzLLMssyxzLPMssyyzLLMscyzzLI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3845 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3625758166 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cbcb882810, 0x55cbcba6c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cbcba6c020,0x55cbcd9040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1da0242a25c0fb30f419d06be4e94738f1858669' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4775 processed earlier; will process 6254 files now Step #5: ==138496== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cbc23779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cbc89dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cbc89bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cbc89bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cbc237dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cbc22deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cbc22d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cbc236fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cbc533ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cbc533ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cbc533ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cbc533ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cbc533ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cbc533ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cbc533ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cbc533ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cbc533ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cbc533ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cbc75d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cbc4300b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cbc430bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cbc40b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cbc40b7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cbc40b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cbc40b7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cbc40b7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cbc40b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cbc89c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cbc89ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cbc89b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cbc89dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f98e4500082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cbc22d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x2,0x0,0x2,0x1e,0x3d,0x7,0xb,0x2c,0x9,0x7,0x11,0x5,0x29,0x2d,0xe,0x27,0x15,0x0,0x2,0x1c,0x1e,0x3d,0x7,0xb,0x2c,0x9,0x7,0x11,0x5,0x29,0x2d,0xe,0x20,0x11,0x38,0x1,0x0,0x3a,0x2d,0x9,0x3f,0x24,0x9,0x30,0x31,0x1f,0x2,0x3,0x34,0x3,0x4,0x13,0x10,0x33,0x31,0x0,0x27,0x20,0x11,0x39,0x1,0x0,0x3a,0x2d,0x9,0x3f,0x9,0x24,0x30,0x31,0x1f,0x2,0x3,0x3f,0x3b,0x10,0x37,0x35,0x33,0x24,0x0,0x3f, Step #5: $\002\000\002\036=\007\013,\011\007\021\005)-\016'\025\000\002\034\036=\007\013,\011\007\021\005)-\016 \0218\001\000:-\011?$\01101\037\002\0034\003\004\023\02031\000' \0219\001\000:-\011?\011$01\037\002\003?;\020753$\000? Step #5: artifact_prefix='./'; Test unit written to ./oom-2f9e2fb956979d0ace549e891a05a9ae38297212 Step #5: Base64: JAIAAh49BwssCQcRBSktDicVAAIcHj0HCywJBxEFKS0OIBE4AQA6LQk/JAkwMR8CAzQDBBMQMzEAJyAROQEAOi0JPwkkMDEfAgM/OxA3NTMkAD8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3846 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3626264332 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fa7401b810, 0x55fa7420501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fa74205020,0x55fa7609d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f9e2fb956979d0ace549e891a05a9ae38297212' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4776 processed earlier; will process 6253 files now Step #5: ==138532== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fa6ab109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fa71175898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fa711585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fa711584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fa6ab16d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fa6aa77b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fa6aa72355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fa6ab08c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fa6dad7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fa6dad7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fa6dad7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fa6dad7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fa6dad7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fa6dad7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fa6dad7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fa6dad7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fa6dad7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fa6dad7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fa6fd6cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fa6ca99b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fa6caa4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fa6c850c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fa6c850c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fa6c851738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fa6c850874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fa6c850874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fa6c850874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fa7115aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fa71163928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fa7114b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fa71176112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7098ff6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fa6aa70b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x17,0x44,0x0,0x0,0x0,0x66,0x66,0x68,0x66,0x68,0x6d,0x74,0x78,0x1d,0x44,0x44,0x17,0x44,0x0,0x0,0x0,0x66,0x66,0x68,0x66,0x68,0x6d,0x74,0x78,0x1d,0x44,0x44,0x44,0x44,0x74,0x78,0x1d,0x44,0x44,0x17,0x44,0x0,0x0,0x0,0x66,0x66,0x68,0x66,0x68,0x6d,0x74,0x78,0x1d,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44, Step #5: \027D\000\000\000ffhfhmtx\035DD\027D\000\000\000ffhfhmtx\035DDDDtx\035DD\027D\000\000\000ffhfhmtx\035DDDDDDDDDDDDDDDDDDDDDDDDDDDDDD Step #5: artifact_prefix='./'; Test unit written to ./oom-122a5678c106c222ebec5cc13fb475c7f6974a99 Step #5: Base64: F0QAAABmZmhmaG10eB1ERBdEAAAAZmZoZmhtdHgdRERERHR4HUREF0QAAABmZmhmaG10eB1EREREREREREREREREREREREREREREREREREREREQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3847 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3626765115 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56024714f810, 0x56024733901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560247339020,0x5602491d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/122a5678c106c222ebec5cc13fb475c7f6974a99' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4777 processed earlier; will process 6252 files now Step #5: ==138568== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56023dc449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5602442a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56024428c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56024428c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56023dc4ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56023dbabb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56023dba6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56023dc3cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560240c0bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560240c0bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560240c0bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560240c0bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560240c0bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560240c0bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560240c0bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560240c0bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560240c0bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560240c0bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560242ea0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56023fbcdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56023fbd8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56023f984c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56023f984c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56023f985738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56023f984874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56023f984874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56023f984874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56024428eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560244297928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56024427f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5602442aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f863a481082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56023dba4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0xa4, Step #5: \000\000\000\000\000\000\000\000\000\000#[(]\000\000#[(b\000]\000\000#[(b\000]\000\000#[(b\000]\000\000\000\000\000\000#[(b\000]\000\000#[(b\000]\000\000#[(b\000]\000\000#[(b\000]\000\000#[(b\000]\244 Step #5: artifact_prefix='./'; Test unit written to ./oom-e58b734db70b14a4d4d0604263f1539225237d37 Step #5: Base64: AAAAAAAAAAAAACNbKF0AACNbKGIAXQAAI1soYgBdAAAjWyhiAF0AAAAAAAAjWyhiAF0AACNbKGIAXQAAI1soYgBdAAAjWyhiAF0AACNbKGIAXaQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3848 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3627263951 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e43906f810, 0x55e43925901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e439259020,0x55e43b0f10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e58b734db70b14a4d4d0604263f1539225237d37' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4778 processed earlier; will process 6251 files now Step #5: ==138604== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e42fb649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4361c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4361ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4361ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e42fb6ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e42facbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e42fac6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e42fb5cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e432b2bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e432b2bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e432b2bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e432b2bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e432b2bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e432b2bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e432b2bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e432b2bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e432b2bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e432b2bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e434dc0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e431aedb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e431af8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4318a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4318a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4318a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4318a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4318a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4318a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4361aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4361b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e43619f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4361ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9c6c647082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e42fac4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x73,0x3a,0xdf,0xa9,0x36,0x35,0x2e,0xdf,0xa9,0x38,0x38,0x2e,0xdf,0xa9,0x38,0x38,0x2e,0xdf,0xa9,0x38,0x39,0x2e,0xdf,0xa9,0x36,0x35,0x2e,0xdf,0xa9,0x38,0x37,0x2e,0xdf,0xa9,0x38,0x38,0x2e,0xdf,0xa9,0x38,0x38,0x2e,0xdf,0xa9,0x38,0x38,0x2e,0xdf,0xa9,0x38,0x39,0x2e,0xdf,0xa9,0x36,0x35,0x2e,0xdf,0xa9,0x38,0x37,0x2e,0xdf,0xa9,0x38,0x38,0x2e,0xdf,0xa9,0x38,0x38,0x2e,0xdf,0xa9,0x36,0x38,0x2e,0xdf,0xa9,0x38,0x38, Step #5: \016ws:\337\25165.\337\25188.\337\25188.\337\25189.\337\25165.\337\25187.\337\25188.\337\25188.\337\25188.\337\25189.\337\25165.\337\25187.\337\25188.\337\25188.\337\25168.\337\25188 Step #5: artifact_prefix='./'; Test unit written to ./oom-347b92bda5bf443f76873ee49b122437e4c1919e Step #5: Base64: DndzOt+pNjUu36k4OC7fqTg4Lt+pODku36k2NS7fqTg3Lt+pODgu36k4OC7fqTg4Lt+pODku36k2NS7fqTg3Lt+pODgu36k4OC7fqTY4Lt+pODg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3849 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3627763706 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55efeb7a0810, 0x55efeb98a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55efeb98a020,0x55efed8220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/347b92bda5bf443f76873ee49b122437e4c1919e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4779 processed earlier; will process 6250 files now Step #5: ==138640== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55efe22959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55efe88fa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55efe88dd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55efe88dd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55efe229bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55efe21fcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55efe21f7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55efe228dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55efe525cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55efe525cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55efe525cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55efe525cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55efe525cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55efe525cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55efe525cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55efe525cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55efe525cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55efe525cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55efe74f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55efe421eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55efe4229be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55efe3fd5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55efe3fd5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55efe3fd6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55efe3fd5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55efe3fd5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55efe3fd5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55efe88dfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55efe88e8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55efe88d0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55efe88fb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8cbebc0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55efe21f5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xea,0xb7,0x98,0xcc,0x83,0xea,0xb7,0xb8,0xcc,0x83,0xea,0xb7,0xb8,0xcc,0x83,0xea,0xb7,0xb8,0xcc,0x83,0xeb,0xb7,0xb0,0xcc,0x83,0xea,0xb7,0xb8,0xcc,0x83,0xea,0xb7,0xb8,0xcd,0x83,0xea,0xb7,0xb8,0xcc,0x83,0xea,0xb7,0xb8,0xcc,0x83,0xea,0xb7,0xb8,0xcc,0x83,0xea,0xb7,0xb8,0xcc,0x83,0xea,0xb7,0xb8,0xcc,0x83,0xea,0xb7,0xb8,0xcc,0x91,0xea,0xb7,0xb8,0xcc,0x83,0xea,0xb7,0xb8,0xcc,0x91,0xea,0xb7,0xb8,0xcc,0x92, Step #5: ws:\352\267\230\314\203\352\267\270\314\203\352\267\270\314\203\352\267\270\314\203\353\267\260\314\203\352\267\270\314\203\352\267\270\315\203\352\267\270\314\203\352\267\270\314\203\352\267\270\314\203\352\267\270\314\203\352\267\270\314\203\352\267\270\314\221\352\267\270\314\203\352\267\270\314\221\352\267\270\314\222 Step #5: artifact_prefix='./'; Test unit written to ./oom-e9751cc21a5e12318a6a20c74168bee445258e70 Step #5: Base64: d3M66reYzIPqt7jMg+q3uMyD6re4zIPrt7DMg+q3uMyD6re4zYPqt7jMg+q3uMyD6re4zIPqt7jMg+q3uMyD6re4zJHqt7jMg+q3uMyR6re4zJI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3850 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3628269389 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eab623b810, 0x55eab642501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eab6425020,0x55eab82bd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e9751cc21a5e12318a6a20c74168bee445258e70' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4780 processed earlier; will process 6249 files now Step #5: ==138676== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eaacd309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eab3395898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eab33785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eab33784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eaacd36d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eaacc97b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eaacc92355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eaacd28c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eaafcf7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eaafcf7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eaafcf7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eaafcf7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eaafcf7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eaafcf7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eaafcf7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eaafcf7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eaafcf7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eaafcf7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eab1f8cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eaaecb9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eaaecc4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eaaea70c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eaaea70c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eaaea71738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eaaea70874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eaaea70874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eaaea70874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eab337aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eab3383928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eab336b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eab3396112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbc40af7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eaacc90b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7f,0x68,0x24,0x0,0x0,0x11,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2b,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x8,0x24, Step #5: \177h$\000\000\021\000\000\000--------\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000------------------+------------\000\000-----------\010$ Step #5: artifact_prefix='./'; Test unit written to ./oom-d2c73dd3033fe9d13523bdff9e533a4a901590d3 Step #5: Base64: f2gkAAARAAAALS0tLS0tLS0AAAAAAAAAAAAAAAAAAAAAAAAAAC0tLS0tLS0tLS0tLS0tLS0tLSstLS0tLS0tLS0tLS0AAC0tLS0tLS0tLS0tCCQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3851 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3628775170 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563584ac3810, 0x563584cad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563584cad020,0x563586b450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d2c73dd3033fe9d13523bdff9e533a4a901590d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4781 processed earlier; will process 6248 files now Step #5: ==138712== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56357b5b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563581c1d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563581c005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563581c004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56357b5bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56357b51fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56357b51a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56357b5b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56357e57ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56357e57ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56357e57ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56357e57ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56357e57ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56357e57ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56357e57ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56357e57ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56357e57ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56357e57ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563580814f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56357d541b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56357d54cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56357d2f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56357d2f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56357d2f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56357d2f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56357d2f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56357d2f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563581c02abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563581c0b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563581bf3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563581c1e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe11aa4f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56357b518b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x41,0x5c,0x3a,0x23,0x68,0x0,0x43,0x43,0x43,0x43,0x7a,0x0,0x0,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x23,0x68,0x0,0x43,0x43,0x43,0x43,0x7a,0x0,0x0,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43, Step #5: \000CCCCCCCC44444444444444444444444444A\\:#h\000CCCCz\000\000CCCCCCCCCCCC#h\000CCCCz\000\000CCCCCCCCCCCCC Step #5: artifact_prefix='./'; Test unit written to ./oom-9aeb35174b3e2c90d4decf540c1bd79e0ebdf9c4 Step #5: Base64: AENDQ0NDQ0NDNDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDRBXDojaABDQ0NDegAAQ0NDQ0NDQ0NDQ0NDI2gAQ0NDQ3oAAENDQ0NDQ0NDQ0NDQ0M= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3852 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3629279032 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55669be7b810, 0x55669c06501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55669c065020,0x55669defd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9aeb35174b3e2c90d4decf540c1bd79e0ebdf9c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4782 processed earlier; will process 6247 files now Step #5: ==138748== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5566929709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556698fd5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556698fb85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556698fb84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556692976d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5566928d7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5566928d2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556692968c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556695937f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556695937f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556695937f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556695937f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556695937f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556695937f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556695937f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556695937f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556695937f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556695937f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556697bccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5566948f9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556694904be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5566946b0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5566946b0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5566946b1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5566946b0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5566946b0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5566946b0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556698fbaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556698fc3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556698fab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556698fd6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f42774082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5566928d0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xb9,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa2,0xec,0x8c,0xbd,0xcc,0xa3,0xec,0x8c,0xbd,0xcc,0xa2, Step #5: ws:\354\214\275\314\242\354\214\275\314\242\354\214\275\314\242\354\214\275\314\242\354\214\271\314\242\354\214\275\314\242\354\214\275\314\242\354\214\275\314\242\354\214\275\314\242\354\214\275\314\242\354\214\275\314\242\354\214\275\314\242\354\214\275\314\242\354\214\275\314\242\354\214\275\314\243\354\214\275\314\242 Step #5: artifact_prefix='./'; Test unit written to ./oom-8e0ec1ae1b5e571ae0578cb188d29f9552d020f8 Step #5: Base64: d3M67Iy9zKLsjL3MouyMvcyi7Iy9zKLsjLnMouyMvcyi7Iy9zKLsjL3MouyMvcyi7Iy9zKLsjL3MouyMvcyi7Iy9zKLsjL3MouyMvcyj7Iy9zKI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3853 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3629776653 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f145792810, 0x55f14597c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f14597c020,0x55f1478140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8e0ec1ae1b5e571ae0578cb188d29f9552d020f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4783 processed earlier; will process 6246 files now Step #5: ==138784== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f13c2879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f1428ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1428cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1428cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f13c28dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f13c1eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f13c1e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f13c27fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f13f24ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f13f24ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f13f24ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f13f24ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f13f24ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f13f24ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f13f24ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f13f24ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f13f24ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f13f24ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f1414e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f13e210b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f13e21bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f13dfc7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f13dfc7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f13dfc8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f13dfc7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f13dfc7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f13dfc7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f1428d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f1428da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f1428c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f1428ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe4d06b6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f13c1e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x53,0x3a,0xc5,0x99,0xcd,0x99,0xd6,0xbd,0xd6,0xbb,0xd6,0xb9,0xc5,0x99,0xcd,0x99,0xd6,0xbd,0xd6,0xbb,0xd6,0xb9,0xc5,0x99,0xcd,0x99,0xd6,0xbd,0xd6,0xbb,0xd6,0xb9,0xc5,0x99,0xcd,0x99,0xd6,0xbd,0xd6,0xbb,0xd6,0xb9,0xc5,0xbc,0xcd,0x99,0xd6,0xbd,0xd6,0xbb,0xd6,0xb9,0xc5,0x99,0xcd,0x99,0xd6,0xbd,0xd6,0xbb,0xd6,0xb9,0xc5,0x99,0xcd,0x99,0xd6,0xbd,0xd6,0xbb,0xd6,0xb9,0xc5,0xb9,0xcd,0x9a,0xd6,0xbd,0xd6,0xbb,0xd6,0xb9, Step #5: wS:\305\231\315\231\326\275\326\273\326\271\305\231\315\231\326\275\326\273\326\271\305\231\315\231\326\275\326\273\326\271\305\231\315\231\326\275\326\273\326\271\305\274\315\231\326\275\326\273\326\271\305\231\315\231\326\275\326\273\326\271\305\231\315\231\326\275\326\273\326\271\305\271\315\232\326\275\326\273\326\271 Step #5: artifact_prefix='./'; Test unit written to ./oom-95ce2e693da7a042587a15bcbdbbd66957a26cea Step #5: Base64: d1M6xZnNmda91rvWucWZzZnWvda71rnFmc2Z1r3Wu9a5xZnNmda91rvWucW8zZnWvda71rnFmc2Z1r3Wu9a5xZnNmda91rvWucW5zZrWvda71rk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3854 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3630281147 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55958002b810, 0x55958021501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559580215020,0x5595820ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/95ce2e693da7a042587a15bcbdbbd66957a26cea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4784 processed earlier; will process 6245 files now Step #5: ==138820== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559576b209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55957d185898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55957d1685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55957d1684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559576b26d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559576a87b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559576a82355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559576b18c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559579ae7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559579ae7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559579ae7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559579ae7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559579ae7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559579ae7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559579ae7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559579ae7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559579ae7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559579ae7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55957bd7cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559578aa9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559578ab4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559578860c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559578860c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559578861738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559578860874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559578860874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559578860874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55957d16aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55957d173928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55957d15b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55957d186112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4c1212082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559576a80b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x7b,0x6e,0x21,0x7b,0x2d,0x65,0x55,0x2e,0x5f,0x3e,0x5f,0x3a,0x32,0x3a,0x66,0x61,0x25,0x73,0x3a,0x32,0x3a,0x66,0x61,0x5b,0x2d,0x33,0x25,0x5b,0x32,0x5b,0x31,0x2d,0x33,0x25,0x5b,0x2d,0x33,0x25,0x5b,0x2d,0x33,0x25,0x33,0x25,0x2e,0x4a,0x2e,0x49,0x2e,0x49,0x2e,0x49,0x2e,0x49,0x2e,0x55,0x55,0x55,0x55,0x55,0x56,0x55,0x55,0x7d,0x65,0x55,0x7b,0x2d,0x65,0x62,0x22,0x22,0x22,0x5c,0x78,0x43,0x55,0x2e,0x43,0x4a,0x2e, Step #5: - {n!{-eU._>_:2:fa%s:2:fa[-3%[2[1-3%[-3%[-3%3%.J.I.I.I.I.UUUUUVUU}eU{-eb\"\"\"\\xCU.CJ. Step #5: artifact_prefix='./'; Test unit written to ./oom-3ba59d1c976a66f2b11e289bdfa2d1a41cd5c784 Step #5: Base64: LSB7biF7LWVVLl8+XzoyOmZhJXM6MjpmYVstMyVbMlsxLTMlWy0zJVstMyUzJS5KLkkuSS5JLkkuVVVVVVVWVVV9ZVV7LWViIiIiXHhDVS5DSi4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3855 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3630788698 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558c0eda3810, 0x558c0ef8d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558c0ef8d020,0x558c10e250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3ba59d1c976a66f2b11e289bdfa2d1a41cd5c784' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4785 processed earlier; will process 6244 files now Step #5: ==138856== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558c058989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558c0befd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558c0bee05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558c0bee04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558c0589ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558c057ffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558c057fa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558c05890c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558c0885ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558c0885ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558c0885ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558c0885ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558c0885ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558c0885ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558c0885ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558c0885ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558c0885ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558c0885ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558c0aaf4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558c07821b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558c0782cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558c075d8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558c075d8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558c075d9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558c075d8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558c075d8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558c075d8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558c0bee2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558c0beeb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558c0bed3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558c0befe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa28eeab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558c057f8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x44,0x33,0x4,0xcc,0x96,0x73,0x6b,0x69,0x70,0x5f,0x45,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x4e,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x44,0x33,0x4,0xcc,0x96,0x73,0x6b,0x69,0x70,0x5f,0x63,0x2d,0x44,0x33,0x4,0xcc,0x96,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0x7c,0x0,0xff, Step #5: I\000-----\000\000\000\000\000\000\000\000\000\000\000\000\000----\012--D3\004\314\226skip_E-----\012---N\000----\012--D3\004\314\226skip_c-D3\004\314\226skip_cl|\000\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-391c9d666866352ce87dd07aa605f54ef28be30b Step #5: Base64: SQAtLS0tLQAAAAAAAAAAAAAAAAAtLS0tCi0tRDMEzJZza2lwX0UtLS0tLQotLS1OAC0tLS0KLS1EMwTMlnNraXBfYy1EMwTMlnNraXBfY2x8AP8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3856 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3631292772 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f557f50810, 0x55f55813a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f55813a020,0x55f559fd20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/391c9d666866352ce87dd07aa605f54ef28be30b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4786 processed earlier; will process 6243 files now Step #5: ==138892== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f54ea459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f5550aa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f55508d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f55508d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f54ea4bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f54e9acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f54e9a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f54ea3dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f551a0cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f551a0cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f551a0cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f551a0cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f551a0cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f551a0cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f551a0cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f551a0cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f551a0cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f551a0cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f553ca1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f5509ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f5509d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f550785c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f550785c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f550786738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f550785874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f550785874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f550785874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f55508fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f555098928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f555080699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f5550ab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1628752082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f54e9a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xaa,0xb2,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x78,0xf0,0x91,0xb4,0x88,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xaa,0xb2,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xb4,0x88, Step #5: \012\023\022\021\012\017//+build\013 w\360\221\252\262\012\023\022\021\012\017//+build\013 x\360\221\264\210\012\023\022\021\012\017//+build\013 w\360\221\252\262\012\023\022\021\012\017//+build\013 w\360\221\264\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-0017b1e92ce436d08e0e8bfe067d1e699befaf25 Step #5: Base64: ChMSEQoPLy8rYnVpbGQLIHfwkaqyChMSEQoPLy8rYnVpbGQLIHjwkbSIChMSEQoPLy8rYnVpbGQLIHfwkaqyChMSEQoPLy8rYnVpbGQLIHfwkbSI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3857 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3631803420 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5617f0cb7810, 0x5617f0ea101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5617f0ea1020,0x5617f2d390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0017b1e92ce436d08e0e8bfe067d1e699befaf25' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4787 processed earlier; will process 6242 files now Step #5: #1 pulse cov: 3827 ft: 3828 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 12118 ft: 12942 exec/s: 0 rss: 194Mb Step #5: ==138928== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5617e77ac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5617ede11898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5617eddf45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5617eddf44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5617e77b2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5617e7713b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5617e770e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5617e77a4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5617ea773f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5617ea773f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5617ea773f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5617ea773f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5617ea773f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5617ea773f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5617ea773f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5617ea773f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5617ea773f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5617ea773f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5617eca08f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5617e9735b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5617e9740be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5617e94ecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5617e94ecc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5617e94ed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5617e94ec874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5617e94ec874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5617e94ec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5617eddf6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5617eddff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5617edde7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5617ede12112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1e9b898082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5617e770cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x5a,0x5b,0xdf,0xbf,0x5d,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7,0x7, Step #5: -Z[\337\277]\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007\007 Step #5: artifact_prefix='./'; Test unit written to ./oom-6d0e7a7df3bf9687187c53e6102e48ff2f6df3c4 Step #5: Base64: LVpb379dBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcH Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3858 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3632419144 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5567acd9e810, 0x5567acf8801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5567acf88020,0x5567aee200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6d0e7a7df3bf9687187c53e6102e48ff2f6df3c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4790 processed earlier; will process 6239 files now Step #5: #1 pulse cov: 4038 ft: 4039 exec/s: 0 rss: 173Mb Step #5: ==138964== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5567a38939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5567a9ef8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5567a9edb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5567a9edb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5567a3899d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5567a37fab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5567a37f5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5567a388bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5567a685af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5567a685af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5567a685af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5567a685af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5567a685af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5567a685af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5567a685af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5567a685af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5567a685af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5567a685af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5567a8aeff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5567a581cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5567a5827be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5567a55d3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5567a55d3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5567a55d4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5567a55d3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5567a55d3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5567a55d3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5567a9eddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5567a9ee6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5567a9ece699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5567a9ef9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe217cab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5567a37f3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xdb,0x80,0x38,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x39, Step #5: \333\200\333\2009\000*********************************************\333\2008\000*********yyyyyyyyyyyyy----\000\0009 Step #5: artifact_prefix='./'; Test unit written to ./oom-65142b76ace791bea21ab08b77da9b5e9190adee Step #5: Base64: 24DbgDkAKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioq24A4ACoqKioqKioqKnl5eXl5eXl5eXl5eXktLS0tAAA5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3859 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3632963417 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5568d0ba7810, 0x5568d0d9101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5568d0d91020,0x5568d2c290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/65142b76ace791bea21ab08b77da9b5e9190adee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4792 processed earlier; will process 6237 files now Step #5: ==139000== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5568c769c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5568cdd01898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5568cdce45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5568cdce44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5568c76a2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5568c7603b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5568c75fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5568c7694c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5568ca663f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5568ca663f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5568ca663f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5568ca663f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5568ca663f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5568ca663f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5568ca663f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5568ca663f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5568ca663f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5568ca663f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5568cc8f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5568c9625b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5568c9630be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5568c93dcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5568c93dcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5568c93dd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5568c93dc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5568c93dc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5568c93dc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5568cdce6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5568cdcef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5568cdcd7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5568cdd02112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f03773e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5568c75fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x44,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012D=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=mmmmmmmmmmmmmmmmmmmmmm=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-bb204c469323a82fc458ad8153f0a91b9a50cb47 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KRD0KPQoKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPW1tbW1tbW1tbW1tbW1tbW1tbW1tbW09Cj0KPQoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3860 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3633473033 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c4a0d11810, 0x55c4a0efb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c4a0efb020,0x55c4a2d930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bb204c469323a82fc458ad8153f0a91b9a50cb47' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4793 processed earlier; will process 6236 files now Step #5: ==139036== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c4978069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c49de6b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c49de4e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c49de4e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c49780cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c49776db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c497768355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c4977fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c49a7cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c49a7cdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c49a7cdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c49a7cdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c49a7cdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c49a7cdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c49a7cdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c49a7cdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c49a7cdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c49a7cdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c49ca62f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c49978fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c49979abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c499546c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c499546c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c499547738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c499546874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c499546874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c499546874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c49de50abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c49de59928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c49de41699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c49de6c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba79ac3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c497766b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x7d, Step #5: '\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{b}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}c}\\u{c}} Step #5: artifact_prefix='./'; Test unit written to ./oom-b16488086740113e2a3e8721055982b7f84b34e1 Step #5: Base64: J1x1e2N9XHV7Y31cdXtjfVx1e2N9XHV7Y31cdXtjfVx1e2N9XHV7Y31cdXtjfVx1e2J9XHV7Y31cdXtjfVx1e2N9XHV7Y31cdXtjfWN9XHV7Y319 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3861 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3633971777 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5619f7738810, 0x5619f792201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5619f7922020,0x5619f97ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b16488086740113e2a3e8721055982b7f84b34e1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4794 processed earlier; will process 6235 files now Step #5: #1 pulse cov: 3728 ft: 3729 exec/s: 0 rss: 175Mb Step #5: ==139072== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5619ee22d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5619f4892898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5619f48755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5619f48754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5619ee233d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5619ee194b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5619ee18f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5619ee225c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5619f11f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5619f11f4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5619f11f4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5619f11f4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5619f11f4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5619f11f4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5619f11f4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5619f11f4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5619f11f4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5619f11f4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5619f3489f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5619f01b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5619f01c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5619eff6dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5619eff6dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5619eff6e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5619eff6d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5619eff6d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5619eff6d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5619f4877abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5619f4880928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5619f4868699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5619f4893112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fea691ad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5619ee18db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x30,0x4d,0x42,0x65,0x41,0x57,0x61,0x47,0x6f,0x53,0x6c,0x71,0x2b,0x48,0x6d,0x73,0x63,0x77,0x31,0x42,0x59,0x6a,0x4c,0x43,0x54,0x41,0x42,0x2b,0x4c,0x53,0x58,0x49,0x56,0x77,0x6a,0x7a,0x53,0x77,0x6f,0x33,0x44,0x44,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f, Step #5: onion-key\012a /\012a /\012ntor-onion-key v0MBeAWaGoSlq+Hmscw1BYjLCTAB+LSXIVwjzSwo3DD\012a /\012a / Step #5: artifact_prefix='./'; Test unit written to ./oom-7fb1931098faf60cdfccfdf4712bfe8e27cb35d1 Step #5: Base64: b25pb24ta2V5CmEgLwphIC8KbnRvci1vbmlvbi1rZXkgdjBNQmVBV2FHb1NscStIbXNjdzFCWWpMQ1RBQitMU1hJVndqelN3bzNERAphIC8KYSAv Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3862 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3634513290 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559770565810, 0x55977074f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55977074f020,0x5597725e70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7fb1931098faf60cdfccfdf4712bfe8e27cb35d1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4796 processed earlier; will process 6233 files now Step #5: ==139108== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55976705a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55976d6bf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55976d6a25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55976d6a24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559767060d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559766fc1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559766fbc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559767052c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55976a021f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55976a021f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55976a021f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55976a021f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55976a021f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55976a021f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55976a021f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55976a021f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55976a021f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55976a021f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55976c2b6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559768fe3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559768feebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559768d9ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559768d9ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559768d9b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559768d9a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559768d9a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559768d9a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55976d6a4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55976d6ad928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55976d695699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55976d6c0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f042b7d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559766fbab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x50,0x6a,0x62,0x73,0x3a,0x29,0xcf,0x8a,0xca,0x9d,0xcd,0x9a,0xc7,0x8d,0xcc,0x9a,0xd2,0x95,0xcd,0x8c,0xca,0x9d,0xcf,0x89,0xca,0x92,0xcf,0x9a,0x3a,0xcb,0x8c,0xca,0x9d,0xd2,0x95,0xcd,0x8a,0xd5,0x95,0xc9,0x8c,0xca,0xa1,0xcf,0x8c,0xca,0x8c,0xc8,0xaa,0x77,0xd5,0x95,0xc8,0x9a,0x76,0x3a,0xa,0x20,0x29,0xcf,0x8a,0xca,0x9d,0xcd,0x9a,0xcb,0x8c,0xca,0x8c,0xc8,0x9d,0xcf,0xaa,0x77,0xd5,0x95,0xc8,0x9a,0x76,0x3a,0xa, Step #5: \000\000\000Pjbs:)\317\212\312\235\315\232\307\215\314\232\322\225\315\214\312\235\317\211\312\222\317\232:\313\214\312\235\322\225\315\212\325\225\311\214\312\241\317\214\312\214\310\252w\325\225\310\232v:\012 )\317\212\312\235\315\232\313\214\312\214\310\235\317\252w\325\225\310\232v:\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-25ea4e8eca514af34ceb16a431f27cf7706d7a5a Step #5: Base64: AAAAUGpiczopz4rKnc2ax43MmtKVzYzKnc+JypLPmjrLjMqd0pXNitWVyYzKoc+MyozIqnfVlciadjoKICnPisqdzZrLjMqMyJ3PqnfVlciadjoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3863 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3635013040 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5589a89b8810, 0x5589a8ba201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5589a8ba2020,0x5589aaa3a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/25ea4e8eca514af34ceb16a431f27cf7706d7a5a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4797 processed earlier; will process 6232 files now Step #5: #1 pulse cov: 11040 ft: 11041 exec/s: 0 rss: 193Mb Step #5: ==139144== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55899f4ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5589a5b12898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589a5af55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589a5af54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55899f4b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55899f414b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55899f40f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55899f4a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5589a2474f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5589a2474f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5589a2474f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5589a2474f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5589a2474f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5589a2474f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5589a2474f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5589a2474f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5589a2474f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5589a2474f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589a4709f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5589a1436b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5589a1441be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5589a11edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5589a11edc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5589a11ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5589a11ed874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5589a11ed874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5589a11ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5589a5af7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5589a5b00928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5589a5ae8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5589a5b13112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f25e62082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55899f40db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x7f,0x8,0x0,0x1,0x0,0x0,0x0,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x0, Step #5: = \177\010\000\001\000\000\000..........................................................................\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-83cbb35346e863019966b4d7075e50048c33bf19 Step #5: Base64: PSB/CAABAAAALi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3864 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3635588000 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5602e9054810, 0x5602e923e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5602e923e020,0x5602eb0d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/83cbb35346e863019966b4d7075e50048c33bf19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4799 processed earlier; will process 6230 files now Step #5: ==139180== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5602dfb499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5602e61ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602e61915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602e61914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5602dfb4fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5602dfab0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5602dfaab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5602dfb41c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5602e2b10f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5602e2b10f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5602e2b10f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5602e2b10f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5602e2b10f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5602e2b10f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5602e2b10f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5602e2b10f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5602e2b10f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5602e2b10f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5602e4da5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5602e1ad2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5602e1addbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5602e1889c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5602e1889c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5602e188a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5602e1889874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5602e1889874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5602e1889874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5602e6193abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5602e619c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5602e6184699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5602e61af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f868add0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5602dfaa9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x9,0x2c,0xa,0x50,0x72,0x6f,0x78,0x79,0x2d,0x41,0x75,0x74,0x68,0x65,0x6e,0x74,0x69,0x63,0x61,0x74,0x65,0x3a,0xa,0x57,0x57,0x57,0x2d,0x41,0x75,0x54,0x68,0x65,0x6e,0x74,0x69,0x63,0x61,0x74,0x65,0x3a,0x4e,0x74,0x4c,0x4d,0x20,0x54,0x6c,0x52,0x4d,0x54,0x56,0x4e,0x54,0x55,0x41,0x41,0x43,0x41,0x41,0x41,0x41,0x41,0x77,0x41,0x41,0x51,0x42,0x41,0x41,0x41,0x41,0x41,0x30,0x37,0x7a,0x2b,0x62,0xa,0x48,0x6f,0x53,0x74,0x3a, Step #5: =\011,\012Proxy-Authenticate:\012WWW-AuThenticate:NtLM TlRMTVNTUAACAAAAAwAAQBAAAAA07z+b\012HoSt: Step #5: artifact_prefix='./'; Test unit written to ./oom-f500e5c94b8a151a057f0852db267c518f5f9b9c Step #5: Base64: PQksClByb3h5LUF1dGhlbnRpY2F0ZToKV1dXLUF1VGhlbnRpY2F0ZTpOdExNIFRsUk1UVk5UVUFBQ0FBQUFBd0FBUUJBQUFBQTA3eitiCkhvU3Q6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3865 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3636098469 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5582d67ce810, 0x5582d69b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5582d69b8020,0x5582d88500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f500e5c94b8a151a057f0852db267c518f5f9b9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4800 processed earlier; will process 6229 files now Step #5: ==139216== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5582cd2c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5582d3928898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5582d390b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5582d390b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5582cd2c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5582cd22ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5582cd225355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5582cd2bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5582d028af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5582d028af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5582d028af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5582d028af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5582d028af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5582d028af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5582d028af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5582d028af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5582d028af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5582d028af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5582d251ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5582cf24cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5582cf257be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5582cf003c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5582cf003c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5582cf004738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5582cf003874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5582cf003874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5582cf003874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5582d390dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5582d3916928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5582d38fe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5582d3929112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3bcfa7b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5582cd223b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x2f,0x7b,0x66,0x6c,0x65,0x78,0x3a,0x5b,0x5b,0x5d,0x2c,0x5b,0x5d,0x2c,0x5b,0x5d,0x2c,0x5b,0x5d,0x2c,0x5b,0x5d,0x2c,0x5b,0x5d,0x2c,0x5b,0x5d,0x2c,0x5b,0x2e,0x34,0x5d,0x2c,0x5b,0x2e,0x33,0x5d,0x2c,0x5b,0x2e,0x31,0x2c,0x5b,0x2e,0x33,0x5d,0x2c,0x5b,0x2e,0x31,0x5d,0x2c,0x5b,0x2e,0x31,0x5d,0x2c,0x5b,0x2e,0x36,0x5d,0x2c,0x5b,0x2e,0x39,0x5d,0x2c,0x5b,0x2e,0x37,0x5d,0x5d,0x5d,0x2c,0x6e,0x61,0x6d,0x65,0x3a,0x22,0x22,0x7d, Step #5: '/{flex:[[],[],[],[],[],[],[],[.4],[.3],[.1,[.3],[.1],[.1],[.6],[.9],[.7]]],name:\"\"} Step #5: artifact_prefix='./'; Test unit written to ./oom-ceab92447ec75e0cbae7f4660473b9e9b5e41c00 Step #5: Base64: Jy97ZmxleDpbW10sW10sW10sW10sW10sW10sW10sWy40XSxbLjNdLFsuMSxbLjNdLFsuMV0sWy4xXSxbLjZdLFsuOV0sWy43XV1dLG5hbWU6IiJ9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3866 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3636606408 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559f82402810, 0x559f825ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559f825ec020,0x559f844840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ceab92447ec75e0cbae7f4660473b9e9b5e41c00' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4801 processed earlier; will process 6228 files now Step #5: ==139252== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559f78ef79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559f7f55c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559f7f53f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559f7f53f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559f78efdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559f78e5eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559f78e59355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559f78eefc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559f7bebef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559f7bebef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559f7bebef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559f7bebef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559f7bebef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559f7bebef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559f7bebef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559f7bebef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559f7bebef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559f7bebef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559f7e153f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559f7ae80b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559f7ae8bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559f7ac37c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559f7ac37c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559f7ac38738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559f7ac37874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559f7ac37874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559f7ac37874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559f7f541abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559f7f54a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559f7f532699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559f7f55d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faabf8b7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559f78e57b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x7e,0x24,0x7e,0x3d,0x2d,0x3d,0x3d,0x1,0x79,0x0,0x0,0x0,0x0,0x29,0x24,0x34,0x7e,0x24,0x7e,0x3d,0x2d,0x3d,0x3d,0x1,0x79,0x0,0x0,0x0,0x0,0x29,0x24,0x34,0x7e,0x24,0x7e,0x2d,0x3d,0x3d,0x3d,0x2d,0x3d,0x3d,0x1,0x79,0x0,0x0,0x0,0x0,0x4d,0x0,0x0,0x0,0x0,0xfe,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7e,0x2d,0x3d,0x3d,0x11,0x79,0x0,0x0,0x0,0x0,0x1e,0x24, Step #5: ~$~$~=-==\001y\000\000\000\000)$4~$~=-==\001y\000\000\000\000)$4~$~-===-==\001y\000\000\000\000M\000\000\000\000\376\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000~-==\021y\000\000\000\000\036$ Step #5: artifact_prefix='./'; Test unit written to ./oom-36174c37abeeeda599ed8bb421eb63da343dda9d Step #5: Base64: fiR+JH49LT09AXkAAAAAKSQ0fiR+PS09PQF5AAAAACkkNH4kfi09PT0tPT0BeQAAAABNAAAAAP4AAAAAAAAAAAAAAAAAAAAAfi09PRF5AAAAAB4k Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3867 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3637109470 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55824589e810, 0x558245a8801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558245a88020,0x5582479200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/36174c37abeeeda599ed8bb421eb63da343dda9d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4802 processed earlier; will process 6227 files now Step #5: #1 pulse cov: 11524 ft: 11525 exec/s: 0 rss: 195Mb Step #5: ==139288== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55823c3939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5582429f8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5582429db5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5582429db4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55823c399d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55823c2fab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55823c2f5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55823c38bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55823f35af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55823f35af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55823f35af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55823f35af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55823f35af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55823f35af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55823f35af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55823f35af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55823f35af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55823f35af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5582415eff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55823e31cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55823e327be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55823e0d3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55823e0d3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55823e0d4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55823e0d3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55823e0d3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55823e0d3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5582429ddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5582429e6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5582429ce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5582429f9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f569e1e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55823c2f3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x69,0x66,0x31,0x6e,0x31,0x6e,0x65,0x65,0x77,0x73,0x70,0x61,0x70,0x65,0x72,0x30,0x29,0x29,0x29,0x29,0xd7,0xa9,0x2a,0x65,0x77,0x73,0x70,0x61,0x70,0x65,0x72,0x30,0x29,0x29,0x29,0x29,0xd7,0xa9,0x2a,0x30,0x9,0x37,0x21,0x29,0x0,0x0,0x77,0x73,0x70,0x61,0x70,0x65,0x72,0x30,0x29,0x29,0x29,0x29,0xd7,0xa9,0x2a,0x65,0x77,0x73,0x70,0x61,0x70,0x65,0x72,0x30,0x29,0x29,0x29,0x29,0xd7,0xa9,0x2a,0x30,0x9,0x37,0x21,0x29,0x0,0x0, Step #5: 1if1n1neewspaper0))))\327\251*ewspaper0))))\327\251*0\0117!)\000\000wspaper0))))\327\251*ewspaper0))))\327\251*0\0117!)\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-25be35c4990ca57284b07f343d434b76963a7f5e Step #5: Base64: MWlmMW4xbmVld3NwYXBlcjApKSkp16kqZXdzcGFwZXIwKSkpKdepKjAJNyEpAAB3c3BhcGVyMCkpKSnXqSpld3NwYXBlcjApKSkp16kqMAk3ISkAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3868 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3637679159 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5576bf015810, 0x5576bf1ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5576bf1ff020,0x5576c10970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/25be35c4990ca57284b07f343d434b76963a7f5e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4804 processed earlier; will process 6225 files now Step #5: ==139324== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5576b5b0a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5576bc16f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5576bc1525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5576bc1524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5576b5b10d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5576b5a71b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5576b5a6c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5576b5b02c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576b8ad1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576b8ad1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576b8ad1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576b8ad1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576b8ad1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576b8ad1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576b8ad1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576b8ad1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576b8ad1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576b8ad1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5576bad66f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5576b7a93b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5576b7a9ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5576b784ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5576b784ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5576b784b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5576b784a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5576b784a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5576b784a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5576bc154abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5576bc15d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5576bc145699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5576bc170112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc3fe0bd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5576b5a6ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x3a,0x0,0x5b,0x3a,0x3a,0x32,0x24,0x77,0x0,0x5e,0x28,0x0,0x3f,0x0,0x2a,0x0,0x28,0x0,0x2a,0x0,0x41,0x0,0x43,0x0,0x43,0x0,0x45,0x0,0x50,0x0,0x54,0x0,0x29,0x0,0x29,0x0,0x36,0x0,0x7c,0x0,0x5c,0x0,0x68,0x0,0x7b,0x0,0x2c,0x0,0x31,0x0,0x37,0x0,0x7d,0x0,0x26,0x2f,0x0,0x24,0x0,0x5c,0x62,0x62,0x0,0x1e,0x0,0x32,0x2b,0x0,0x5b,0x2,0x44,0xf3,0x50,0x0,0x2f,0x20,0x5,0x2a,0xff,0xff,0xff,0xff,0xff, Step #5: \000\000:\000[::2$w\000^(\000?\000*\000(\000*\000A\000C\000C\000E\000P\000T\000)\000)\0006\000|\000\\\000h\000{\000,\0001\0007\000}\000&/\000$\000\\bb\000\036\0002+\000[\002D\363P\000/ \005*\377\377\377\377\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-6017c1baf604ad040cfb68c151ff1d387537102e Step #5: Base64: AAA6AFs6OjIkdwBeKAA/ACoAKAAqAEEAQwBDAEUAUABUACkAKQA2AHwAXABoAHsALAAxADcAfQAmLwAkAFxiYgAeADIrAFsCRPNQAC8gBSr//////w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3869 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3638187878 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e8febdb810, 0x55e8fedc501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e8fedc5020,0x55e900c5d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6017c1baf604ad040cfb68c151ff1d387537102e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4805 processed earlier; will process 6224 files now Step #5: ==139360== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e8f56d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e8fbd35898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e8fbd185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e8fbd184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e8f56d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e8f5637b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e8f5632355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e8f56c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e8f8697f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e8f8697f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e8f8697f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e8f8697f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e8f8697f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e8f8697f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e8f8697f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e8f8697f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e8f8697f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e8f8697f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e8fa92cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e8f7659b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e8f7664be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e8f7410c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e8f7410c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e8f7411738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e8f7410874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e8f7410874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e8f7410874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e8fbd1aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e8fbd23928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e8fbd0b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e8fbd36112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f105d297082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e8f5630b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x88,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x0,0x0,0x55,0x0,0x0,0xb,0x0,0x60,0xa,0xa,0x31,0x2f,0x60,0xa,0x20,0x0,0x0,0x0,0xb,0x0,0x60,0xa,0xa,0x31,0x2f,0x60,0xa,0x20,0x20,0x60,0x20,0x60,0xa,0x9, Step #5: `\342\210\210-\000`\012\363\240\201\272/\012`\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001`\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000\000\000U\000\000\013\000`\012\0121/`\012 \000\000\000\013\000`\012\0121/`\012 ` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-934be603a702308269a95c32c061667b2e5d6e6d Step #5: Base64: YOKIiC0AYArzoIG6Lwpg4oCILQBgCvOggbrzoIG6LwFg4oCILQBgCvOggbrzoIG6LwEAAABVAAALAGAKCjEvYAogAAAACwBgCgoxL2AKICBgIGAKCQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3870 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3638811351 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560509832810, 0x560509a1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560509a1c020,0x56050b8b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/934be603a702308269a95c32c061667b2e5d6e6d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4806 processed earlier; will process 6223 files now Step #5: ==139396== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5605003279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56050698c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56050696f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56050696f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56050032dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56050028eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560500289355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56050031fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605032eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605032eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605032eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605032eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605032eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605032eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605032eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605032eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605032eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605032eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560505583f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5605022b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5605022bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560502067c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560502067c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560502068738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560502067874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560502067874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560502067874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560506971abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56050697a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560506962699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56050698d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2da005a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560500287b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x3c,0x44,0x3a,0x45,0x3e,0x2f,0x3c,0x2f,0x3c,0x2f, Step #5: <D:E><D:E><D:E><D:E><D:E><D:E><D:E><D:E><D:E><D:E><D:E><D:E><D:E><D:E><D:E><D:E>/</</ Step #5: artifact_prefix='./'; Test unit written to ./oom-2ee164a364e7052c049d87d35710f471eebf39bc Step #5: Base64: PEQ6RT48RDpFPjxEOkU+PEQ6RT48RDpFPjxEOkU+PEQ6RT48RDpFPjxEOkU+PEQ6RT48RDpFPjxEOkU+PEQ6RT48RDpFPjxEOkU+PEQ6RT4vPC88Lw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3871 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3639307085 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5624c54b8810, 0x5624c56a201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5624c56a2020,0x5624c753a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2ee164a364e7052c049d87d35710f471eebf39bc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4807 processed earlier; will process 6222 files now Step #5: ==139432== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5624bbfad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5624c2612898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5624c25f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5624c25f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5624bbfb3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5624bbf14b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5624bbf0f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5624bbfa5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5624bef74f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5624bef74f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5624bef74f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5624bef74f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5624bef74f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5624bef74f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5624bef74f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5624bef74f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5624bef74f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5624bef74f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5624c1209f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5624bdf36b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5624bdf41be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5624bdcedc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5624bdcedc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5624bdcee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5624bdced874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5624bdced874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5624bdced874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5624c25f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5624c2600928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5624c25e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5624c2613112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efe4508f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5624bbf0db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x67,0x79,0x71,0x51,0x47,0x4d,0x49,0x41,0x43,0x41,0x2f,0x4b,0x42,0x77,0x45,0x50,0x48,0x35,0x65,0x61,0x74,0x34,0x79,0x71,0x52,0x76,0x69,0x64,0x6d,0x44,0x57,0x61,0x71,0x49,0x59,0x30,0x6e,0x76,0x65,0x6d,0x4d,0x46,0x74,0xa,0x61,0x20,0x5b,0x30,0x3a,0x30,0x3a,0x30,0x3a,0x66,0x32,0x46,0x46,0x3a,0x3a,0x5d, Step #5: onion-key\012ntor-onion-key gyqQGMIACA/KBwEPH5eat4yqRvidmDWaqIY0nvemMFt\012a [0:0:0:f2FF::] Step #5: artifact_prefix='./'; Test unit written to ./oom-4c0d83182a12f3dd5e8fe2c5af2209e6a56b7155 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IGd5cVFHTUlBQ0EvS0J3RVBINWVhdDR5cVJ2aWRtRFdhcUlZMG52ZW1NRnQKYSBbMDowOjA6ZjJGRjo6XQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3872 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3639805149 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a61d44c810, 0x55a61d63601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a61d636020,0x55a61f4ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4c0d83182a12f3dd5e8fe2c5af2209e6a56b7155' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4808 processed earlier; will process 6221 files now Step #5: ==139468== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a613f419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a61a5a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a61a5895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a61a5894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a613f47d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a613ea8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a613ea3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a613f39c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a616f08f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a616f08f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a616f08f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a616f08f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a616f08f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a616f08f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a616f08f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a616f08f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a616f08f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a616f08f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a61919df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a615ecab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a615ed5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a615c81c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a615c81c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a615c82738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a615c81874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a615c81874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a615c81874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a61a58babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a61a594928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a61a57c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a61a5a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f554fc65082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a613ea1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x3f,0x45,0x47,0x49,0x4e,0x20,0x30,0x2d,0x2d,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x2d,0x2d,0x2d,0x2,0x2d, Step #5: x-----B?EGIN 0---\012=\012=\012=\012=\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\000\000\000\000\000\000\000\000\000\000\000\000\000\000 ---\002- Step #5: artifact_prefix='./'; Test unit written to ./oom-a396c4f177c21d74fd44630b931e3a621f1ae438 Step #5: Base64: eC0tLS0tQj9FR0lOIDAtLS0KPQo9Cj0KPQwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwAAAAAAAAAAAAAAAAAACAtLS0CLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3873 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3640305502 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d2e533810, 0x561d2e71d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d2e71d020,0x561d305b50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a396c4f177c21d74fd44630b931e3a621f1ae438' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4809 processed earlier; will process 6220 files now Step #5: ==139504== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d250289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d2b68d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d2b6705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d2b6704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d2502ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d24f8fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d24f8a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d25020c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d27feff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d27feff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d27feff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d27feff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d27feff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d27feff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d27feff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d27feff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d27feff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d27feff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d2a284f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d26fb1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d26fbcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d26d68c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d26d68c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d26d69738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d26d68874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d26d68874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d26d68874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d2b672abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d2b67b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d2b663699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d2b68e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4fe637082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d24f88b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x21,0x0,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x5b,0x2d,0x2d,0xa,0x44,0x0,0x2d,0x2d,0x31,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x5b,0x2d,0x2d,0xa,0x44,0xa,0x2d,0xa,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x5b,0x2d,0x2d,0xa,0x44,0x0,0x2d,0x2d,0x49,0x74,0x68,0xa,0x2d,0xa,0x64,0xa,0x64, Step #5: !!\000----BEGIN ---BEGIN --[--\012D\000--1-BEGIN --[--\012D\012-\012-BEGIN ---BEGIN --[--\012D\000--Ith\012-\012d\012d Step #5: artifact_prefix='./'; Test unit written to ./oom-842c0be27467d54494e5aefad98b361e37ffe6da Step #5: Base64: ISEALS0tLUJFR0lOIC0tLUJFR0lOIC0tWy0tCkQALS0xLUJFR0lOIC0tWy0tCkQKLQotQkVHSU4gLS0tQkVHSU4gLS1bLS0KRAAtLUl0aAotCmQKZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3874 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3640808347 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b5afcc810, 0x557b5b1b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b5b1b6020,0x557b5d04e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/842c0be27467d54494e5aefad98b361e37ffe6da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4810 processed earlier; will process 6219 files now Step #5: ==139540== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557b51ac19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b58126898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b581095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b581094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b51ac7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b51a28b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b51a23355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b51ab9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b54a88f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b54a88f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b54a88f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b54a88f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b54a88f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b54a88f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b54a88f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b54a88f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b54a88f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b54a88f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b56d1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b53a4ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b53a55be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b53801c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b53801c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b53802738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b53801874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b53801874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b53801874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b5810babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b58114928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b580fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b58127112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f07b5640082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b51a21b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x11,0xf,0x31,0x11,0x2d,0x3a,0x24,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x31,0x8,0x11,0x2d,0x3a,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x31,0x8,0x11,0x2d,0x3a,0x8,0x11,0x2d,0x3a,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0x24,0x0,0x5b,0x11,0x2d,0x2d,0x3a,0x3a,0x24,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x0,0x24,0x5b,0x2d,0x3a,0x24,0x24,0x5b,0x5b, Step #5: \021\0171\021-:$\017\017\0171\021\01711\010\021-:\000\000/\000\000\000/\000\017\017\017\017\0171\021\01711\010\021-:\010\021-:\000\000/\000\000\000/\000\017$\000[\021--::$-\017\017\017\017\0171\021\0171\021-:\000$[-:$$[[ Step #5: artifact_prefix='./'; Test unit written to ./oom-7c7d160add54ab668b4379fd559e07a215227a3a Step #5: Base64: EQ8xES06JA8PDzERDzExCBEtOgAALwAAAC8ADw8PDw8xEQ8xMQgRLToIES06AAAvAAAALwAPJABbES0tOjokLQ8PDw8PMREPMREtOgAkWy06JCRbWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3875 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3641317003 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c6e6d9810, 0x556c6e8c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c6e8c3020,0x556c7075b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7c7d160add54ab668b4379fd559e07a215227a3a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4811 processed earlier; will process 6218 files now Step #5: ==139576== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556c651ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c6b833898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c6b8165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c6b8164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556c651d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556c65135b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556c65130355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556c651c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556c68195f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556c68195f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556c68195f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556c68195f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556c68195f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556c68195f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556c68195f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556c68195f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556c68195f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556c68195f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c6a42af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556c67157b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556c67162be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556c66f0ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556c66f0ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556c66f0f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556c66f0e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556c66f0e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556c66f0e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c6b818abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c6b821928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c6b809699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c6b834112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5df38c7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556c6512eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x47,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x64,0x62,0x6a,0x65,0x63,0x74,0x22,0x2c,0x7b,0x2c,0x7b,0x7d,0x2c,0x7d,0x7b,0x2c,0x7b,0x7d,0x2c,0x79,0x7d,0x2c,0x23,0x7b,0x7d,0x7d,0x2c,0x7b,0x6c,0x7b,0x7d,0x2c,0x2c,0x7d,0x7b,0x0,0x1,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x5b,0x5d,0x1,0x7d,0x2a,0x7b,0x2a,0x6d,0x6f,0x64,0x65,0x6c,0x73,0x2e,0x49,0x0,0x0,0x0,0x7b,0x7d,0x2c,0x2c,0x7b,0x75,0x31,0x7b,0x7d,0x2c,0x7b,0x7d, Step #5: \000\000\000G\000\000\000\000\000\000\000dbject\",{,{},}{,{},y},#{}},{l{},,}{\000\001,{},{},[]\001}*{*models.I\000\000\000{},,{u1{},{} Step #5: artifact_prefix='./'; Test unit written to ./oom-4e05fd1d81379ce0920591df2755192b89effa89 Step #5: Base64: AAAARwAAAAAAAABkYmplY3QiLHsse30sfXsse30seX0sI3t9fSx7bHt9LCx9ewABLHt9LHt9LFtdAX0qeyptb2RlbHMuSQAAAHt9LCx7dTF7fSx7fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3876 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3641814625 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dce4c7b810, 0x55dce4e6501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dce4e65020,0x55dce6cfd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e05fd1d81379ce0920591df2755192b89effa89' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4812 processed earlier; will process 6217 files now Step #5: #1 pulse cov: 13960 ft: 13961 exec/s: 0 rss: 198Mb Step #5: ==139612== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dcdb7709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dce1dd5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dce1db85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dce1db84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dcdb776d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dcdb6d7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dcdb6d2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dcdb768c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dcde737f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dcde737f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dcde737f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dcde737f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dcde737f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dcde737f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dcde737f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dcde737f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dcde737f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dcde737f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dce09ccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dcdd6f9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dcdd704be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dcdd4b0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dcdd4b0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dcdd4b1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dcdd4b0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dcdd4b0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dcdd4b0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dce1dbaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dce1dc3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dce1dab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dce1dd6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff402708082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dcdb6d0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xa,0x73,0x75,0x62,0x7b,0x20,0x64,0x3a,0x31,0x37,0x32,0x35,0x31,0x36,0x33,0x31,0x37,0x34,0x31,0x34,0x33,0x32,0x32,0x30,0x33,0x35,0x34,0x34,0x32,0x37,0x36,0x37,0x30,0x30,0x2e,0x20,0x7d,0xa,0x73,0x75,0x62,0x7b,0x20,0x64,0x3a,0x31,0x37,0x32,0x35,0x31,0x36,0x33,0x31,0x37,0x34,0x31,0x34,0x33,0x32,0x32,0x30,0x33,0x35,0x34,0x34,0x32,0x37,0x36,0x37,0x30,0x30,0x2e,0x20,0x7d,0xa, Step #5: FUZZTESTv1\012sub{ d:17251631741432203544276700. }\012sub{ d:17251631741432203544276700. }\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-82c5e72694b86755ed479f2a1a8761e986552c1f Step #5: Base64: RlVaWlRFU1R2MQpzdWJ7IGQ6MTcyNTE2MzE3NDE0MzIyMDM1NDQyNzY3MDAuIH0Kc3VieyBkOjE3MjUxNjMxNzQxNDMyMjAzNTQ0Mjc2NzAwLiB9Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3877 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3642393580 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556fa139c810, 0x556fa158601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556fa1586020,0x556fa341e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/82c5e72694b86755ed479f2a1a8761e986552c1f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4814 processed earlier; will process 6215 files now Step #5: ==139648== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556f97e919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f9e4f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f9e4d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f9e4d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f97e97d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f97df8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f97df3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f97e89c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f9ae58f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f9ae58f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f9ae58f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f9ae58f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f9ae58f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f9ae58f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f9ae58f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f9ae58f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f9ae58f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f9ae58f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f9d0edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f99e1ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f99e25be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f99bd1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f99bd1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f99bd2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f99bd1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f99bd1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f99bd1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f9e4dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f9e4e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f9e4cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f9e4f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1853711082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f97df1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x30,0x73,0x38,0x20,0x5b,0x20,0x2d,0x2d,0x2d,0x2d,0x73,0x74,0x72,0x65,0x61,0x6d,0x47,0x4b,0x60,0x20,0x2d,0x45,0x47,0x4b,0x60,0x24,0x24,0x24,0x24,0x24,0x41,0x24,0x24,0x24,0x24,0x24,0x63,0x72,0x79,0x73,0x74,0x61,0x6c,0x24,0x2a,0x24,0x64,0x24,0x24,0x24,0x24,0x2e,0x2e,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x4,0x24,0x63,0x6f,0x70,0x70,0x70,0x70,0x24,0x24,0x64,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x1,0x69,0x24,0x3f, Step #5: s0s8 [ ----streamGK` -EGK`$$$$$A$$$$$crystal$*$d$$$$..$$$$$$$\004$copppp$$d$$$$$$$$$\001i$? Step #5: artifact_prefix='./'; Test unit written to ./oom-7a477ff4ada67122af4fb449525b33e939e94899 Step #5: Base64: czBzOCBbIC0tLS1zdHJlYW1HS2AgLUVHS2AkJCQkJEEkJCQkJGNyeXN0YWwkKiRkJCQkJC4uJCQkJCQkJAQkY29wcHBwJCRkJCQkJCQkJCQkAWkkPw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3878 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3643029436 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560f6b627810, 0x560f6b81101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560f6b811020,0x560f6d6a90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7a477ff4ada67122af4fb449525b33e939e94899' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4815 processed earlier; will process 6214 files now Step #5: ==139684== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560f6211c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560f68781898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560f687645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560f687644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560f62122d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560f62083b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560f6207e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560f62114c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560f650e3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560f650e3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560f650e3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560f650e3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560f650e3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560f650e3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560f650e3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560f650e3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560f650e3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560f650e3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560f67378f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560f640a5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560f640b0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560f63e5cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560f63e5cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560f63e5d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560f63e5c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560f63e5c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560f63e5c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560f68766abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560f6876f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560f68757699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560f68782112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faba2b64082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560f6207cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x27,0x0,0x44,0x33,0x4,0x27,0x4,0x27,0x0,0x44,0x33,0x4,0x27,0x59,0x27,0x45,0x0,0x60,0x0,0x54,0x17,0x33,0x5,0x24,0x24,0x0,0x0,0x1a,0x0,0x24,0x24,0x24,0x24,0x40,0x24,0x46,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x4,0x3b,0x27,0x8,0x0,0x60,0x27,0x17,0x54,0x58,0x59,0x45,0x15,0x0,0x60,0x27,0x17,0x54,0x59,0x60,0x27,0x17,0x54,0x58,0x59,0x45,0x15,0x0,0x10,0x15,0x0,0x10, Step #5: ID3\004'\000D3\004'\004'\000D3\004'Y'E\000`\000T\0273\005$$\000\000\032\000$$$$@$F$$$$$$$$$$$$$\004;'\010\000`'\027TXYE\025\000`'\027TY`'\027TXYE\025\000\020\025\000\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-a5a890bec299d6b63123f75626b0f76317f7537a Step #5: Base64: SUQzBCcARDMEJwQnAEQzBCdZJ0UAYABUFzMFJCQAABoAJCQkJEAkRiQkJCQkJCQkJCQkJCQEOycIAGAnF1RYWUUVAGAnF1RZYCcXVFhZRRUAEBUAEA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3879 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3643650860 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dc70bb4810, 0x55dc70d9e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dc70d9e020,0x55dc72c360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a5a890bec299d6b63123f75626b0f76317f7537a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4816 processed earlier; will process 6213 files now Step #5: ==139720== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dc676a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dc6dd0e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dc6dcf15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dc6dcf14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dc676afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dc67610b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dc6760b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dc676a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dc6a670f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dc6a670f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dc6a670f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dc6a670f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dc6a670f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dc6a670f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dc6a670f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dc6a670f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dc6a670f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dc6a670f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dc6c905f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dc69632b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dc6963dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dc693e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dc693e9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dc693ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dc693e9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dc693e9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dc693e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dc6dcf3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dc6dcfc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dc6dce4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dc6dd0f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2963775082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dc67609b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a, Step #5: ************************************************************************************** Step #5: artifact_prefix='./'; Test unit written to ./oom-70f9f93c6069cc7ce610075e685b94a0abe2b7bf Step #5: Base64: KioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKio= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3880 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3644151256 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55636f171810, 0x55636f35b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55636f35b020,0x5563711f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70f9f93c6069cc7ce610075e685b94a0abe2b7bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4817 processed earlier; will process 6212 files now Step #5: ==139756== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556365c669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55636c2cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55636c2ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55636c2ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556365c6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556365bcdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556365bc8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556365c5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556368c2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556368c2df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556368c2df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556368c2df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556368c2df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556368c2df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556368c2df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556368c2df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556368c2df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556368c2df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55636aec2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556367befb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556367bfabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5563679a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5563679a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5563679a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5563679a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5563679a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5563679a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55636c2b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55636c2b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55636c2a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55636c2cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f03cde23082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556365bc6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x44,0x33,0x4,0x27,0x0,0x0,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x61,0x27,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x3a,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x17,0x54,0x59,0x33,0x45,0x4,0x27,0x0,0x0,0x60,0x27,0x4,0x0,0x61,0x27,0x17,0x54,0x59,0x33,0x45,0x4,0x27,0x0,0x0,0x60,0x21,0x17,0x54,0x59,0x15,0x10,0x0,0x45,0x15,0x0,0x10, Step #5: ID3\004D3\004'\000\000{{{{{{a'{{{{{{{{{{{{{{{{{{{{{{{{:{{{{{{{\027TY3E\004'\000\000`'\004\000a'\027TY3E\004'\000\000`!\027TY\025\020\000E\025\000\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-d75980f2ad367fe0b8336c199907f82c521653ad Step #5: Base64: SUQzBEQzBCcAAHt7e3t7e2Ene3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7Ont7e3t7e3sXVFkzRQQnAABgJwQAYScXVFkzRQQnAABgIRdUWRUQAEUVABA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3881 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3644772546 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561e64f1e810, 0x561e6510801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561e65108020,0x561e66fa00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d75980f2ad367fe0b8336c199907f82c521653ad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4818 processed earlier; will process 6211 files now Step #5: ==139792== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561e5ba139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561e62078898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561e6205b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561e6205b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561e5ba19d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561e5b97ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561e5b975355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561e5ba0bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561e5e9daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561e5e9daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561e5e9daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561e5e9daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561e5e9daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561e5e9daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561e5e9daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561e5e9daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561e5e9daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561e5e9daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561e60c6ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561e5d99cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561e5d9a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561e5d753c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561e5d753c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561e5d754738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561e5d753874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561e5d753874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561e5d753874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561e6205dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561e62066928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561e6204e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561e62079112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e1723d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561e5b973b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x8,0x0,0x7,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x17,0x0,0x0,0x0,0x0,0x0,0x0,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0xe,0x28,0x29,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2e,0x0,0x2e,0x2b,0x42,0xdb,0xbe,0x7c,0xdb,0xbe,0x2b,0x2b,0x2b, Step #5: - \010\000\007\000\000\000\000\000\000\000\000\000\000\010\000\027\000\000\000\000\000\000)()()()()()()()()()()()()()\001\000\000\000\000\000\000\016()\000\000\000\000\000\000\000\000\000\000\000\000.\000.+B\333\276|\333\276+++ Step #5: artifact_prefix='./'; Test unit written to ./oom-690843cb27534b7839395db8cc8da3d187a47f5a Step #5: Base64: LSAIAAcAAAAAAAAAAAAACAAXAAAAAAAAKSgpKCkoKSgpKCkoKSgpKCkoKSgpKCkoKSgpAQAAAAAAAA4oKQAAAAAAAAAAAAAAAC4ALitC2758274rKys= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3882 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3645280590 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dc3c881810, 0x55dc3ca6b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dc3ca6b020,0x55dc3e9030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/690843cb27534b7839395db8cc8da3d187a47f5a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4819 processed earlier; will process 6210 files now Step #5: ==139828== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dc333769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dc399db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dc399be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dc399be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dc3337cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dc332ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dc332d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dc3336ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dc3633df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dc3633df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dc3633df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dc3633df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dc3633df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dc3633df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dc3633df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dc3633df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dc3633df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dc3633df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dc385d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dc352ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dc3530abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dc350b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dc350b6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dc350b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dc350b6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dc350b6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dc350b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dc399c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dc399c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dc399b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dc399dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f709a5fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dc332d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x3d,0x79,0x0,0x0,0x0,0x0,0x29,0x25,0x7e,0x24,0x3d,0x7e,0x2d,0x3d,0x3d,0x3b,0x54,0x54,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x9d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x79,0x0,0x0,0x0,0x0,0x54,0x24, Step #5: ~$=y\000\000\000\000)%~$=~-==;TT\000\000\000\000\000\000\000\000\000\020\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\235\000\000\000\000\000\000\000\000\010\000\000\000\000\000\000\000\000\001y\000\000\000\000T$ Step #5: artifact_prefix='./'; Test unit written to ./oom-cd909da81021c94ced16c1448c1e5b53ca835b54 Step #5: Base64: fiQ9eQAAAAApJX4kPX4tPT07VFQAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAnQAAAAAAAAAACAAAAAAAAAAAAXkAAAAAVCQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3883 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3645789960 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5639dcb83810, 0x5639dcd6d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5639dcd6d020,0x5639dec050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd909da81021c94ced16c1448c1e5b53ca835b54' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4820 processed earlier; will process 6209 files now Step #5: #1 pulse cov: 4117 ft: 4118 exec/s: 0 rss: 175Mb Step #5: ==139864== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5639d36789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5639d9cdd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5639d9cc05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5639d9cc04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5639d367ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5639d35dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5639d35da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5639d3670c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5639d663ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5639d663ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5639d663ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5639d663ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5639d663ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5639d663ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5639d663ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5639d663ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5639d663ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5639d663ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5639d88d4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5639d5601b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5639d560cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5639d53b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5639d53b8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5639d53b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5639d53b8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5639d53b8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5639d53b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5639d9cc2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5639d9ccb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5639d9cb3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5639d9cde112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0c8e027082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5639d35d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xf,0x31,0xf,0x31,0x11,0xf,0x32,0x11,0x2d,0x0,0x0,0x0,0x2f,0x0,0xf,0x30,0x11,0xf,0x31,0x11,0x2d,0x3a,0x2d,0x3a,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0171\0171\021\0172\021-\000\000\000/\000\0170\021\0171\021-:-:$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-c061d3250d29b740824aa1eb63d6e900a7ed786a Step #5: Base64: JAAALwAAAC8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADzEPMREPMhEtAAAALwAPMBEPMREtOi06JFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3884 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3646342777 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557558b32810, 0x557558d1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557558d1c020,0x55755abb40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c061d3250d29b740824aa1eb63d6e900a7ed786a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4822 processed earlier; will process 6207 files now Step #5: #1 pulse cov: 3511 ft: 3512 exec/s: 0 rss: 173Mb Step #5: ==139900== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55754f6279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557555c8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557555c6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557555c6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55754f62dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55754f58eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55754f589355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55754f61fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5575525eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5575525eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5575525eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5575525eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5575525eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5575525eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5575525eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5575525eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5575525eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5575525eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557554883f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5575515b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5575515bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557551367c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557551367c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557551368738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557551367874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557551367874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557551367874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557555c71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557555c7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557555c62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557555c8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67206e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55754f587b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3a,0x3e,0x26,0x23,0x35,0x34,0x3b,0x26,0x23,0x35,0x33,0x3b,0x26,0x23,0x35,0x33,0x3b,0x26,0x23,0x35,0x33,0x3b,0x26,0x23,0x35,0x33,0x3b,0x26,0x26,0x23,0x35,0x34,0x3b,0x26,0x23,0x35,0x33,0x3b,0x26,0x23,0x35,0x33,0x3b,0x26,0x23,0x35,0x33,0x3b,0x26,0x23,0x35,0x33,0x3b,0x26,0x23,0x35,0x34,0x3b,0x26,0x23,0x35,0x33,0x3b,0x26,0x23,0x35,0x33,0x3b,0x26,0x26,0x23,0x35,0x34,0x3b,0x3b,0x26,0x23,0x35,0x33,0x3b,0x26,0x23,0x35,0x33,0x3b, Step #5: <:>&#54;&#53;&#53;&#53;&#53;&&#54;&#53;&#53;&#53;&#53;&#54;&#53;&#53;&&#54;;&#53;&#53; Step #5: artifact_prefix='./'; Test unit written to ./oom-38e79884d9821d85db0a1a74bf4f231e5a7b9f9b Step #5: Base64: PDo+JiM1NDsmIzUzOyYjNTM7JiM1MzsmIzUzOyYmIzU0OyYjNTM7JiM1MzsmIzUzOyYjNTM7JiM1NDsmIzUzOyYjNTM7JiYjNTQ7OyYjNTM7JiM1Mzs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3885 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3646882164 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5567342fe810, 0x5567344e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5567344e8020,0x5567363800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/38e79884d9821d85db0a1a74bf4f231e5a7b9f9b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4824 processed earlier; will process 6205 files now Step #5: ==139936== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55672adf39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556731458898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55673143b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55673143b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55672adf9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55672ad5ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55672ad55355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55672adebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55672ddbaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55672ddbaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55672ddbaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55672ddbaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55672ddbaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55672ddbaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55672ddbaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55672ddbaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55672ddbaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55672ddbaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55673004ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55672cd7cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55672cd87be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55672cb33c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55672cb33c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55672cb34738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55672cb33874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55672cb33874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55672cb33874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55673143dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556731446928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55673142e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556731459112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa6d757082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55672ad53b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x0,0x2d,0x2d,0x32,0x2d,0x42,0x45,0x57,0x49,0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x9,0x55,0x47,0x4b,0x60,0x4e,0x15,0x20,0x4e,0x15,0x20,0x24,0x2d,0xa,0x2b,0x0,0x0,0x0,0x0,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0xa,0x32,0x20,0x2d,0x45,0x2d,0x2d,0x9,0x45,0x47,0x4b,0x60,0x20,0x2d,0x7a,0x47,0x4b,0x0,0x73,0x2d,0xd0,0xa,0x2d,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xec,0x2d,0x3f,0x2d,0x3f,0x2d,0xa,0x3f, Step #5: !\000--2-BEWIs-----\011UGK`N\025 N\025 $-\012+\000\000\000\000CCCCCCCCCCCCC\0122 -E--\011EGK` -zGK\000s-\320\012-********\354-?-?-\012? Step #5: artifact_prefix='./'; Test unit written to ./oom-3c6bfec3b61be935702ba0b684f307b20ffbaa4b Step #5: Base64: IQAtLTItQkVXSXMtLS0tLQlVR0tgThUgThUgJC0KKwAAAABDQ0NDQ0NDQ0NDQ0NDCjIgLUUtLQlFR0tgIC16R0sAcy3QCi0qKioqKioqKuwtPy0/LQo/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3886 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3647508299 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561884d20810, 0x561884f0a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561884f0a020,0x561886da20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3c6bfec3b61be935702ba0b684f307b20ffbaa4b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4825 processed earlier; will process 6204 files now Step #5: #1 pulse cov: 4320 ft: 4321 exec/s: 0 rss: 176Mb Step #5: ==139972== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56187b8159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561881e7a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561881e5d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561881e5d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56187b81bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56187b77cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56187b777355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56187b80dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56187e7dcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56187e7dcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56187e7dcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56187e7dcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56187e7dcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56187e7dcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56187e7dcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56187e7dcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56187e7dcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56187e7dcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561880a71f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56187d79eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56187d7a9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56187d555c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56187d555c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56187d556738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56187d555874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56187d555874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56187d555874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561881e5fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561881e68928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561881e50699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561881e7b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f834294e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56187b775b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x52,0x41,0x43,0x4f,0x2,0x2,0x1,0x1,0x7d,0x68,0x2,0xea,0xa9,0xbb,0x2,0xa2,0xd1,0xf7,0x0,0x0,0xff,0xc0,0xe1,0x0,0x59,0x0,0xfd,0x2,0x24,0x30,0xf9,0xe7,0x62,0x1,0x2,0x5,0x0,0x3,0x4,0x1,0x0,0xfe,0x3f,0x0,0x21,0x1,0x7e,0x0,0x1,0xf,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x0,0x79,0x79,0x79,0x87,0x88,0x10,0xf0,0x3a,0x3a,0xbf,0x7f,0x5b,0x3,0x0,0x10,0xff,0xbf,0x7f,0x5b,0x3,0x0,0x10,0xff,0x3a,0x5b,0x0,0x40,0x0, Step #5: DRACO\002\002\001\001}h\002\352\251\273\002\242\321\367\000\000\377\300\341\000Y\000\375\002$0\371\347b\001\002\005\000\003\004\001\000\376?\000!\001~\000\001\017yyyyyyy\000yyy\207\210\020\360::\277\177[\003\000\020\377\277\177[\003\000\020\377:[\000@\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-249e4f2e4adb1a1982d345c01dd565564369a96b Step #5: Base64: RFJBQ08CAgEBfWgC6qm7AqLR9wAA/8DhAFkA/QIkMPnnYgECBQADBAEA/j8AIQF+AAEPeXl5eXl5eQB5eXmHiBDwOjq/f1sDABD/v39bAwAQ/zpbAEAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3887 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3648049920 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5576dd3da810, 0x5576dd5c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5576dd5c4020,0x5576df45c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/249e4f2e4adb1a1982d345c01dd565564369a96b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4827 processed earlier; will process 6202 files now Step #5: ==140008== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5576d3ecf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5576da534898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5576da5175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5576da5174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5576d3ed5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5576d3e36b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5576d3e31355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5576d3ec7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576d6e96f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576d6e96f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576d6e96f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576d6e96f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576d6e96f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576d6e96f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576d6e96f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576d6e96f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576d6e96f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576d6e96f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5576d912bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5576d5e58b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5576d5e63be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5576d5c0fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5576d5c0fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5576d5c10738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5576d5c0f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5576d5c0f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5576d5c0f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5576da519abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5576da522928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5576da50a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5576da535112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa91b07c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5576d3e2fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0x46,0x46,0x20,0x49,0x44,0x33,0x67,0x62,0x49,0x54,0x32,0x58,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x43,0x4f,0x4d,0x2,0xdb,0xbf,0x9f,0xff, Step #5: CFF ID3gbIT2X\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000 \000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000COM\002\333\277\237\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-ca77fed07a66af135b893261773b82b7b167f263 Step #5: Base64: Q0ZGIElEM2diSVQyWAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAENPTQLbv5// Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3888 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3648551743 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555abc1ce810, 0x555abc3b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555abc3b8020,0x555abe2500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca77fed07a66af135b893261773b82b7b167f263' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4828 processed earlier; will process 6201 files now Step #5: #1 pulse cov: 3843 ft: 3844 exec/s: 0 rss: 173Mb Step #5: ==140044== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555ab2cc39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ab9328898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ab930b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ab930b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ab2cc9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ab2c2ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ab2c25355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ab2cbbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ab5c8af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ab5c8af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ab5c8af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ab5c8af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ab5c8af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ab5c8af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ab5c8af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ab5c8af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ab5c8af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ab5c8af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555ab7f1ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ab4c4cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ab4c57be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ab4a03c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ab4a03c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ab4a04738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ab4a03874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ab4a03874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ab4a03874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ab930dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ab9316928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ab92fe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ab9329112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8337e67082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ab2c23b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x51,0x79,0x71,0x67,0x47,0x52,0x59,0x46,0x54,0x79,0x42,0x72,0x4b,0x77,0x45,0x50,0x48,0x39,0x65,0x61,0x74,0x48,0x39,0x65,0x61,0x74,0x35,0x79,0x71,0x52,0x76,0x69,0x64,0x6d,0x44,0x31,0x6e,0x76,0x65,0x6d,0x4d,0x38,0x2f,0xa,0x61,0x9,0x3a,0x3a,0x38,0x3a,0x35,0x3a,0x35,0x3a,0x35,0x3a,0x32,0x3a,0x32,0x3a,0x38,0x2f, Step #5: onion-key\012ntor-onion-key QyqgGRYFTyBrKwEPH9eatH9eat5yqRvidmD1nvemM8/\012a\011::8:5:5:5:2:2:8/ Step #5: artifact_prefix='./'; Test unit written to ./oom-f6678622c563567cc2e8444b3d7469983a693c2a Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IFF5cWdHUllGVHlCckt3RVBIOWVhdEg5ZWF0NXlxUnZpZG1EMW52ZW1NOC8KYQk6Ojg6NTo1OjU6MjoyOjgv Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3889 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3649104601 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55da6423d810, 0x55da6442701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55da64427020,0x55da662bf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f6678622c563567cc2e8444b3d7469983a693c2a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4830 processed earlier; will process 6199 files now Step #5: ==140080== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55da5ad329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55da61397898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55da6137a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55da6137a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55da5ad38d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55da5ac99b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55da5ac94355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55da5ad2ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55da5dcf9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55da5dcf9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55da5dcf9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55da5dcf9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55da5dcf9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55da5dcf9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55da5dcf9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55da5dcf9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55da5dcf9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55da5dcf9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55da5ff8ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55da5ccbbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55da5ccc6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55da5ca72c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55da5ca72c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55da5ca73738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55da5ca72874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55da5ca72874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55da5ca72874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55da6137cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55da61385928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55da6136d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55da61398112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb5440a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55da5ac92b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x74,0x6f,0x63,0x75,0x6d,0x65,0x6e,0x74,0x3e,0x3c,0x74,0x6f,0x63,0x75,0x6d,0x65,0x6e,0x74,0x3e,0x3c,0x74,0x6f,0x63,0x75,0x6d,0x65,0x66,0x66,0x65,0x63,0x74,0x61,0x73,0x65,0x2d,0x73,0x65,0x6e,0x73,0x69,0x74,0x69,0x76,0x65,0x6f,0x63,0x6f,0x6e,0x66,0x69,0x67,0x3a,0x6e,0x61,0x6d,0x65,0x64,0x79,0x6d,0x65,0x64,0x79,0x3e,0x3c,0x74,0x6f,0x63,0x75,0x6d,0x65,0x6e,0x74,0x3e,0xa,0x3e,0x3c,0x74,0x6f,0x63,0x75,0x6d,0x65,0x6e,0x74,0x3e,0xa, Step #5: <tocument><tocument><tocumeffectase-sensitiveoconfig:namedymedy><tocument>\012><tocument>\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-aceaf866482ae6f486df4fb346624747e35de20a Step #5: Base64: PHRvY3VtZW50Pjx0b2N1bWVudD48dG9jdW1lZmZlY3Rhc2Utc2Vuc2l0aXZlb2NvbmZpZzpuYW1lZHltZWR5Pjx0b2N1bWVudD4KPjx0b2N1bWVudD4K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3890 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3649603100 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f56cee2810, 0x55f56d0cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f56d0cc020,0x55f56ef640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aceaf866482ae6f486df4fb346624747e35de20a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4831 processed earlier; will process 6198 files now Step #5: ==140116== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f5639d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f56a03c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f56a01f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f56a01f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f5639ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f56393eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f563939355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f5639cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f56699ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f56699ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f56699ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f56699ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f56699ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f56699ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f56699ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f56699ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f56699ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f56699ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f568c33f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f565960b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f56596bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f565717c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f565717c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f565718738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f565717874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f565717874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f565717874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f56a021abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f56a02a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f56a012699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f56a03d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ca938d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f563937b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x55,0x30,0xa,0x12,0x51,0xa,0x2,0x6a,0x0,0xa,0x3f,0x0,0x0,0x3,0xa,0x5,0xe2,0xa2,0xa2,0x2a,0x5b,0xe2,0xa2,0xa2,0x2a,0x5b,0x5d,0x73,0x74,0x72,0x20,0x20,0x3,0xa,0x5,0xe2,0xa2,0xa2,0x2a,0x5b,0xe2,0xa2,0xa2,0x2a,0x5b,0x5d,0x73,0x74,0x72,0x69,0x6e,0x33,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5,0xe2,0x8d,0x1,0x2,0xa,0x5,0x8,0x3,0x9f,0x1,0x32,0x2,0xc,0x3,0xa,0xa,0x3f,0x0,0x2,0x8,0x3,0xa,0x5, Step #5: \012U0\012\022Q\012\002j\000\012?\000\000\003\012\005\342\242\242*[\342\242\242*[]str \003\012\005\342\242\242*[\342\242\242*[]strin3\000\000\000\000\000\000\000\000\000\000\005\342\215\001\002\012\005\010\003\237\0012\002\014\003\012\012?\000\002\010\003\012\005 Step #5: artifact_prefix='./'; Test unit written to ./oom-91b164dac11c89fff82b87aef471391ff2dceb28 Step #5: Base64: ClUwChJRCgJqAAo/AAADCgXioqIqW+KioipbXXN0ciAgAwoF4qKiKlvioqIqW11zdHJpbjMAAAAAAAAAAAAABeKNAQIKBQgDnwEyAgwDCgo/AAIIAwoF Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3891 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3650105991 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5608f514a810, 0x5608f533401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5608f5334020,0x5608f71cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/91b164dac11c89fff82b87aef471391ff2dceb28' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4832 processed earlier; will process 6197 files now Step #5: ==140152== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5608ebc3f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5608f22a4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608f22875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608f22874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5608ebc45d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5608ebba6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5608ebba1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5608ebc37c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5608eec06f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5608eec06f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5608eec06f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5608eec06f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5608eec06f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5608eec06f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5608eec06f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5608eec06f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5608eec06f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5608eec06f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608f0e9bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5608edbc8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5608edbd3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5608ed97fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5608ed97fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5608ed980738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5608ed97f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5608ed97f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5608ed97f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5608f2289abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5608f2292928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5608f227a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5608f22a5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc08973082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5608ebb9fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x0,0x2d,0x2d,0x32,0x2d,0x42,0x45,0x47,0x49,0x4e,0x15,0x20,0x4e,0x21,0x0,0x43,0x46,0x46,0x2d,0x2d,0x32,0x2d,0x42,0x45,0x47,0x47,0x2b,0x49,0x4e,0x15,0x20,0x4e,0x15,0x20,0x24,0x2d,0xe,0x2b,0x2d,0x2d,0x5b,0x44,0x2d,0xa,0x29,0xa,0x15,0x20,0x24,0x2d,0xa,0x20,0x4e,0x15,0x20,0x24,0x2d,0xe,0x2b,0x2d,0x2d,0x5b,0x44,0x2d,0xa,0x29,0xa,0x15,0x20,0x24,0x2d,0xa,0x2b,0x2d,0x2d,0x5b,0x2b,0x2d,0x2d,0x5b,0x44,0x2d,0xa,0x29,0xa,0x3f, Step #5: !\000--2-BEGIN\025 N!\000CFF--2-BEGG+IN\025 N\025 $-\016+--[D-\012)\012\025 $-\012 N\025 $-\016+--[D-\012)\012\025 $-\012+--[+--[D-\012)\012? Step #5: artifact_prefix='./'; Test unit written to ./oom-6dca374dd382aa9816d3c1dc23b7c495f13410e0 Step #5: Base64: IQAtLTItQkVHSU4VIE4hAENGRi0tMi1CRUdHK0lOFSBOFSAkLQ4rLS1bRC0KKQoVICQtCiBOFSAkLQ4rLS1bRC0KKQoVICQtCistLVsrLS1bRC0KKQo/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3892 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3650609911 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555cc0409810, 0x555cc05f301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555cc05f3020,0x555cc248b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6dca374dd382aa9816d3c1dc23b7c495f13410e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4833 processed earlier; will process 6196 files now Step #5: ==140188== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555cb6efe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555cbd563898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555cbd5465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555cbd5464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555cb6f04d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555cb6e65b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555cb6e60355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555cb6ef6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555cb9ec5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555cb9ec5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555cb9ec5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555cb9ec5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555cb9ec5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555cb9ec5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555cb9ec5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555cb9ec5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555cb9ec5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555cb9ec5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555cbc15af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555cb8e87b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555cb8e92be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555cb8c3ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555cb8c3ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555cb8c3f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555cb8c3e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555cb8c3e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555cb8c3e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555cbd548abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555cbd551928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555cbd539699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555cbd564112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f92dc924082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555cb6e5eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x31,0x3e,0x5c,0x6b,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x3c,0x33,0x3e,0x5c,0x6b,0x6b, Step #5: \\k<3>\\k<3>\\k<3>\\k\\k<3>\\k<3>\\k<3>\\k<3>\\k<3>\\k<3>\\k<1>\\k\\k<3>\\k<3>\\k<3>\\k<3>\\k<3>\\k<3>\\kk Step #5: artifact_prefix='./'; Test unit written to ./oom-d613d1553a8e086f125833f7f8f19a451583d067 Step #5: Base64: XGs8Mz5cazwzPlxrPDM+XGtcazwzPlxrPDM+XGs8Mz5cazwzPlxrPDM+XGs8Mz5cazwxPlxrXGs8Mz5cazwzPlxrPDM+XGs8Mz5cazwzPlxrPDM+XGtr Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3893 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3651114584 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563bf5a08810, 0x563bf5bf201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563bf5bf2020,0x563bf7a8a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d613d1553a8e086f125833f7f8f19a451583d067' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4834 processed earlier; will process 6195 files now Step #5: ==140224== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563bec4fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563bf2b62898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563bf2b455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563bf2b454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563bec503d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563bec464b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563bec45f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563bec4f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563bef4c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563bef4c4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563bef4c4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563bef4c4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563bef4c4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563bef4c4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563bef4c4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563bef4c4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563bef4c4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563bef4c4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563bf1759f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563bee486b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563bee491be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563bee23dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563bee23dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563bee23e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563bee23d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563bee23d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563bee23d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563bf2b47abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563bf2b50928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563bf2b38699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563bf2b63112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4cf9875082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563bec45db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0x6c,0x61,0x73,0x73,0xa,0x62,0x28,0x6e,0x28,0x1a,0x7d,0x3,0x0,0x0,0x0,0x62,0x28,0x6e,0xe2,0x81,0x9f,0x28,0x1a,0x7d,0x0,0x3,0x0,0x3,0x0,0x0,0x0,0x62,0x28,0x6e,0x28,0x1a,0x7d,0x3,0x0,0x0,0x0,0x62,0x28,0x6e,0x28,0x1a,0x7d,0x3,0x6e,0x28,0x1a,0x7d,0x3,0x0,0x0,0x0,0x62,0x28,0x6e,0x28,0x1a,0x7d,0x64,0x0,0x28,0x6e,0x28,0x1a,0x7d,0x3,0x0,0x0,0x3,0x0,0x0,0x0,0x62,0x28,0x6e,0x28,0x1a,0x7d,0x3,0x0,0x0,0x0, Step #5: class\012b(n(\032}\003\000\000\000b(n\342\201\237(\032}\000\003\000\003\000\000\000b(n(\032}\003\000\000\000b(n(\032}\003n(\032}\003\000\000\000b(n(\032}d\000(n(\032}\003\000\000\003\000\000\000b(n(\032}\003\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bc108d89599d936667bfc3e8b7a430ae9c504a6d Step #5: Base64: Y2xhc3MKYihuKBp9AwAAAGIobuKBnygafQADAAMAAABiKG4oGn0DAAAAYihuKBp9A24oGn0DAAAAYihuKBp9ZAAobigafQMAAAMAAABiKG4oGn0DAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3894 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3651622799 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5565b53ed810, 0x5565b55d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5565b55d7020,0x5565b746f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bc108d89599d936667bfc3e8b7a430ae9c504a6d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4835 processed earlier; will process 6194 files now Step #5: ==140260== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5565abee29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5565b2547898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5565b252a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5565b252a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5565abee8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5565abe49b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5565abe44355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5565abedac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5565aeea9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5565aeea9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5565aeea9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5565aeea9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5565aeea9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5565aeea9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5565aeea9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5565aeea9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5565aeea9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5565aeea9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5565b113ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5565ade6bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5565ade76be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5565adc22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5565adc22c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5565adc23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5565adc22874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5565adc22874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5565adc22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5565b252cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5565b2535928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5565b251d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5565b2548112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f286240b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5565abe42b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x70,0x5b,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x66,0x65,0x65,0x64,0x69,0x6e,0x67,0xf3,0xa0,0x81,0xa1,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x2f,0x70,0xa,0x54,0x54,0x31,0xf3,0xa0,0x81,0x9c,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x50,0x3d,0xa,0x2d,0x2d,0x2d,0x2d,0xf3,0xa0,0x81,0x9f,0x2d,0x45,0x4e,0xf3,0xa0,0x80,0xb4,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: \012p[pppppppppfeeding\363\240\201\241ppppppppppppppp/p\012TT1\363\240\201\234fffffffGGGGGGGP=\012----\363\240\201\237-EN\363\240\200\264D ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-5b8cf6c4f8e6aa1a4bfb2d203184b84bce42ee32 Step #5: Base64: CnBbcHBwcHBwcHBwZmVlZGluZ/OggaFwcHBwcHBwcHBwcHBwcHAvcApUVDHzoIGcZmZmZmZmZkdHR0dHR0dQPQotLS0t86CBny1FTvOggLREIC0tLS0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3895 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3652131122 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571c088c810, 0x5571c0a7601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571c0a76020,0x5571c290e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5b8cf6c4f8e6aa1a4bfb2d203184b84bce42ee32' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4836 processed earlier; will process 6193 files now Step #5: ==140296== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571b73819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571bd9e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571bd9c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571bd9c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571b7387d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571b72e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571b72e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571b7379c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571ba348f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571ba348f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571ba348f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571ba348f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571ba348f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571ba348f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571ba348f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571ba348f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571ba348f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571ba348f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571bc5ddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571b930ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571b9315be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571b90c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571b90c1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571b90c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571b90c1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571b90c1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571b90c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571bd9cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571bd9d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571bd9bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571bd9e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc294f11082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571b72e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2c,0x2b,0xb,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x1a,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0x73,0x73,0x73,0x73,0x73,0xa,0x2b,0xa,0x2b,0x0,0xa,0x54,0xa,0x0,0x0,0x2b,0x2b,0xa,0x2b,0x73,0xa,0x2b,0xa,0x2b,0xa,0xa,0x2b,0x2b,0xa,0x2b,0x6,0x2b,0xa,0x2b,0xa,0xd5,0xf5,0xd4,0xf5,0xd4,0xf5,0xf5,0xd5,0xa,0x12,0x2b,0xee,0x2b,0xa,0x2e,0x2b,0x2b,0x2b,0xa,0x2b,0xdf, Step #5: +\012+\012+\012,+\013\012+\012\012+\012+\012+\032+\012+\012+\012+\012+\012+ssssss\012+\012+\000\012T\012\000\000++\012+s\012+\012+\012\012++\012+\006+\012+\012\325\365\324\365\324\365\365\325\012\022+\356+\012.+++\012+\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-340ca0f699ed7ebb58a0cf0090f38cbfabffee2c Step #5: Base64: KworCisKLCsLCisKCisKKworGisKKworCisKKworc3Nzc3NzCisKKwAKVAoAACsrCitzCisKKwoKKysKKwYrCisK1fXU9dT19dUKEivuKwouKysrCivf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3896 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3652652882 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5617cf960810, 0x5617cfb4a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5617cfb4a020,0x5617d19e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/340ca0f699ed7ebb58a0cf0090f38cbfabffee2c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4837 processed earlier; will process 6192 files now Step #5: #1 pulse cov: 4317 ft: 4318 exec/s: 0 rss: 173Mb Step #5: ==140332== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5617c64559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5617ccaba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5617cca9d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5617cca9d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5617c645bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5617c63bcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5617c63b7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5617c644dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5617c941cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5617c941cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5617c941cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5617c941cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5617c941cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5617c941cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5617c941cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5617c941cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5617c941cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5617c941cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5617cb6b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5617c83deb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5617c83e9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5617c8195c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5617c8195c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5617c8196738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5617c8195874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5617c8195874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5617c8195874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5617cca9fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5617ccaa8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5617cca90699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5617ccabb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa35e456082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5617c63b5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x55,0x30,0xa,0x12,0x51,0xa,0x2,0x6a,0x0,0xa,0x3e,0x0,0x2,0xa,0x20,0x3,0xa,0x5,0xe2,0xa2,0xa2,0x2a,0x5b,0x5d,0x0,0x73,0x3,0x0,0x0,0x10,0x0,0x0,0x0,0xb,0x13,0x0,0x0,0x0,0xe2,0xa2,0xa2,0x2a,0x5b,0x5d,0x73,0x74,0x72,0xa,0x3,0x0,0x0,0x0,0x0,0x0,0x0,0x57,0x0,0xe2,0xa2,0xa2,0x1,0x8,0x8,0xdb,0xff,0xff,0x10,0x0,0x26,0x67,0x2,0xa,0x12,0x51,0xa,0x40,0x0,0x2,0xc,0x0,0x0,0x0,0x8,0x3,0xa,0x5, Step #5: \012U0\012\022Q\012\002j\000\012>\000\002\012 \003\012\005\342\242\242*[]\000s\003\000\000\020\000\000\000\013\023\000\000\000\342\242\242*[]str\012\003\000\000\000\000\000\000W\000\342\242\242\001\010\010\333\377\377\020\000&g\002\012\022Q\012@\000\002\014\000\000\000\010\003\012\005 Step #5: artifact_prefix='./'; Test unit written to ./oom-e5cd6ba2debae7f69deb5320809f98687bfb9309 Step #5: Base64: ClUwChJRCgJqAAo+AAIKIAMKBeKioipbXQBzAwAAEAAAAAsTAAAA4qKiKltdc3RyCgMAAAAAAABXAOKiogEICNv//xAAJmcCChJRCkAAAgwAAAAIAwoF Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3897 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3653204398 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f78921810, 0x556f78b0b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f78b0b020,0x556f7a9a30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e5cd6ba2debae7f69deb5320809f98687bfb9309' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4839 processed earlier; will process 6190 files now Step #5: ==140368== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556f6f4169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f75a7b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f75a5e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f75a5e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f6f41cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f6f37db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f6f378355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f6f40ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f723ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f723ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f723ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f723ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f723ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f723ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f723ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f723ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f723ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f723ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f74672f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f7139fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f713aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f71156c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f71156c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f71157738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f71156874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f71156874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f71156874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f75a60abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f75a69928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f75a51699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f75a7c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7204c25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f6f376b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x55,0x22,0x47,0x21,0xdc,0xb7,0xdc,0xaa,0xdc,0x90,0x59,0xdc,0xb0,0xdc,0x97,0xdc,0xb7,0xdc,0xaa,0xdc,0x90,0x59,0xdc,0xb0,0xdc,0x97,0xdc,0xab,0xdc,0x90,0xdc,0xaa,0xdc,0xb7,0x52,0xdc,0xb0,0x4d,0xdc,0xb0,0xdc,0xaa,0x42,0xdc,0xb6,0xdc,0xaa,0xdc,0xb0,0xdc,0xaa,0xdc,0xb7,0x4b,0xdc,0xb0,0x79,0xdc,0x97,0xdc,0xab,0xdc,0x90,0xdc,0xaa,0xdc,0xb6,0xdc,0xaa,0xdc,0xb0,0x30,0xdc,0xaa,0xdc,0xb7,0x4b,0xdc,0xb0,0x59,0xdc,0x59,0x30,0x0,0x31,0xae, Step #5: HUU\"G!\334\267\334\252\334\220Y\334\260\334\227\334\267\334\252\334\220Y\334\260\334\227\334\253\334\220\334\252\334\267R\334\260M\334\260\334\252B\334\266\334\252\334\260\334\252\334\267K\334\260y\334\227\334\253\334\220\334\252\334\266\334\252\334\2600\334\252\334\267K\334\260Y\334Y0\0001\256 Step #5: artifact_prefix='./'; Test unit written to ./oom-ba49a0df543c6ce0cf1ad6359a36d4bf8fb8eb02 Step #5: Base64: SFVVIkch3LfcqtyQWdyw3Jfct9yq3JBZ3LDcl9yr3JDcqty3UtywTdyw3KpC3Lbcqtyw3Krct0vcsHncl9yr3JDcqty23KrcsDDcqty3S9ywWdxZMAAxrg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3898 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3653714496 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558144686810, 0x55814487001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558144870020,0x5581467080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba49a0df543c6ce0cf1ad6359a36d4bf8fb8eb02' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4840 processed earlier; will process 6189 files now Step #5: #1 pulse cov: 3524 ft: 3525 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 3949 ft: 4180 exec/s: 0 rss: 176Mb Step #5: ==140404== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55813b17b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5581417e0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5581417c35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5581417c34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55813b181d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55813b0e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55813b0dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55813b173c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55813e142f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55813e142f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55813e142f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55813e142f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55813e142f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55813e142f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55813e142f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55813e142f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55813e142f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55813e142f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5581403d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55813d104b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55813d10fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55813cebbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55813cebbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55813cebc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55813cebb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55813cebb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55813cebb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5581417c5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5581417ce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5581417b6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5581417e1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8347e0d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55813b0dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0xad,0x80,0x39,0x39,0x39,0x39,0x39,0x34,0x39, Step #5: \333\200\333\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\255\2009999949 Step #5: artifact_prefix='./'; Test unit written to ./oom-59920636f37b24d3e3b3aa9d9a47c58c5eab66f2 Step #5: Base64: 24Dbra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2tra2AOTk5OTk0OQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3899 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3654298758 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db2a7c6810, 0x55db2a9b001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db2a9b0020,0x55db2c8480e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/59920636f37b24d3e3b3aa9d9a47c58c5eab66f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4843 processed earlier; will process 6186 files now Step #5: ==140440== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db212bb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db27920898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db279035dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db279034fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db212c1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db21222b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db2121d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db212b3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db24282f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db24282f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db24282f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db24282f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db24282f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db24282f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db24282f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db24282f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db24282f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db24282f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db26517f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db23244b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db2324fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db22ffbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db22ffbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db22ffc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db22ffb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db22ffb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db22ffb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db27905abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db2790e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db278f6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db27921112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f8f9a8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db2121bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x20,0x79,0x76,0x33,0x4d,0x42,0x65,0x41,0x57,0x61,0x47,0x6f,0x53,0x6c,0x71,0x2b,0x48,0x6d,0x73,0x63,0x77,0x33,0x32,0x37,0x36,0x39,0x42,0x59,0x6a,0x4c,0x43,0x54,0x41,0x42,0x2b,0x4c,0x53,0x58,0x49,0x56,0x77,0x6a,0x7a,0x53,0x77,0x6f,0x33,0x44,0x44,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f, Step #5: onion-key\012a /\012a /\012ntor-onion-ke yv3MBeAWaGoSlq+Hmscw32769BYjLCTAB+LSXIVwjzSwo3DD\012a /\012a / Step #5: artifact_prefix='./'; Test unit written to ./oom-313187f29329b62e87c1ef58ad0a0393504140af Step #5: Base64: b25pb24ta2V5CmEgLwphIC8KbnRvci1vbmlvbi1rZSB5djNNQmVBV2FHb1NscStIbXNjdzMyNzY5QllqTENUQUIrTFNYSVZ3anpTd28zREQKYSAvCmEgLw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3900 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3654804918 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ad1bf8c810, 0x55ad1c17601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ad1c176020,0x55ad1e00e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/313187f29329b62e87c1ef58ad0a0393504140af' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4844 processed earlier; will process 6185 files now Step #5: ==140476== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ad12a819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ad190e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ad190c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ad190c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ad12a87d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ad129e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ad129e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ad12a79c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ad15a48f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ad15a48f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ad15a48f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ad15a48f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ad15a48f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ad15a48f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ad15a48f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ad15a48f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ad15a48f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ad15a48f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ad17cddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ad14a0ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ad14a15be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ad147c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ad147c1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ad147c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ad147c1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ad147c1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ad147c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ad190cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ad190d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ad190bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ad190e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5f71eab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ad129e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xcc,0xb1,0xa,0xce,0x95,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0xb2,0xa,0x2e,0xcc,0x96,0xa,0x2e,0xcc,0xb3,0xa,0x6e,0xcc,0x94,0xa,0x2e,0xcc,0xb2,0xa,0xcc,0xb1,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0x94,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0x8a,0xa,0x2e,0xcc,0x96,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0xb3,0xa,0x6e,0xcc,0x94,0xa,0x2e,0xcc,0xb2,0xa,0xcc,0xb1,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0x94,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0xb1, Step #5: -\314\261\012\316\225\012.\314\261\012.\314\262\012.\314\226\012.\314\263\012n\314\224\012.\314\262\012\314\261\012.\314\261\012.\314\224\012.\314\261\012.\314\212\012.\314\226\012.\314\261\012.\314\263\012n\314\224\012.\314\262\012\314\261\012.\314\261\012.\314\224\012.\314\261\012.\314\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-b9d75e7682fac5b7d579feed6c676cb13c20d5f1 Step #5: Base64: LcyxCs6VCi7MsQouzLIKLsyWCi7MswpuzJQKLsyyCsyxCi7MsQouzJQKLsyxCi7MigouzJYKLsyxCi7MswpuzJQKLsyyCsyxCi7MsQouzJQKLsyxCi7MsQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3901 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3655312000 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa143a9810, 0x55aa1459301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa14593020,0x55aa1642b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b9d75e7682fac5b7d579feed6c676cb13c20d5f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4845 processed earlier; will process 6184 files now Step #5: ==140512== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aa0ae9e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa11503898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa114e65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa114e64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa0aea4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa0ae05b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa0ae00355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa0ae96c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa0de65f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa0de65f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa0de65f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa0de65f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa0de65f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa0de65f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa0de65f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa0de65f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa0de65f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa0de65f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa100faf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa0ce27b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa0ce32be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa0cbdec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa0cbdec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa0cbdf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa0cbde874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa0cbde874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa0cbde874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa114e8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa114f1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa114d9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa11504112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0629bf7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa0adfeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x26,0xa,0x24,0xa,0x0,0xa,0x20,0x20,0x0,0x0,0x0,0x0,0x8,0x0,0x0,0xa,0x2,0x1a,0x0,0x1a,0x0,0xa,0x3,0x1a,0x0,0xa,0x2,0x1a,0x0,0xa,0x2,0x1a,0x2,0x1a,0x0,0xa,0x2,0x1a,0x0,0xa,0x26,0xa,0x24,0xa,0x0,0xa,0x20,0x1f,0xff,0xfe,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x14,0x0,0xee,0xee,0x0,0xee,0xfd,0xff,0xff,0xff,0xf,0xef,0x23,0x0,0x0,0x17,0x11,0x7,0xee,0xee,0x1b,0x0,0xa,0x6,0xa,0x4,0xa,0x2,0x1a,0x0, Step #5: \012&\012$\012\000\012 \000\000\000\000\010\000\000\012\002\032\000\032\000\012\003\032\000\012\002\032\000\012\002\032\002\032\000\012\002\032\000\012&\012$\012\000\012 \037\377\376\377\377\377\377\377\377\377\024\000\356\356\000\356\375\377\377\377\017\357#\000\000\027\021\007\356\356\033\000\012\006\012\004\012\002\032\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-408162d83f532650e73cacb4250fde7cc2b5e658 Step #5: Base64: CiYKJAoACiAgAAAAAAgAAAoCGgAaAAoDGgAKAhoACgIaAhoACgIaAAomCiQKAAogH//+/////////xQA7u4A7v3///8P7yMAABcRB+7uGwAKBgoECgIaAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3902 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3655818531 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5579a29b3810, 0x5579a2b9d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5579a2b9d020,0x5579a4a350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/408162d83f532650e73cacb4250fde7cc2b5e658' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4846 processed earlier; will process 6183 files now Step #5: ==140548== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5579994a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55799fb0d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55799faf05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55799faf04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5579994aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55799940fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55799940a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5579994a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55799c46ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55799c46ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55799c46ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55799c46ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55799c46ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55799c46ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55799c46ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55799c46ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55799c46ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55799c46ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55799e704f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55799b431b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55799b43cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55799b1e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55799b1e8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55799b1e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55799b1e8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55799b1e8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55799b1e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55799faf2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55799fafb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55799fae3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55799fb0e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb12b7dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557999408b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xdd,0x8c,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xde,0x8c,0xc5,0x84,0xdd,0x84,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xde,0x8c,0xc5,0x84,0xdd,0x84,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xde,0x8c,0xc5,0x84,0xdd,0x84,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xde,0x8c,0xde,0x8c,0xc5,0x84,0xdd,0x84,0xc5,0x86,0xc5,0x84,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xde,0x8c,0xc5,0x86,0xc5,0x84,0xdd,0x84,0xc5,0x84,0xdd,0x84,0xde,0x8c,0xc5,0xa3,0xc5,0xa3,0x22, Step #5: \"\335\214\335\204\305\204\335\204\336\214\305\204\335\204\335\204\305\204\335\204\335\204\305\204\335\204\336\214\305\204\335\204\335\204\305\204\335\204\336\214\305\204\335\204\335\204\305\204\335\204\336\214\336\214\305\204\335\204\305\206\305\204\335\204\305\204\335\204\336\214\305\206\305\204\335\204\305\204\335\204\336\214\305\243\305\243\" Step #5: artifact_prefix='./'; Test unit written to ./oom-dd5ece7da85ddd5eabcf6aa5c435c8394bb5d135 Step #5: Base64: It2M3YTFhN2E3ozFhN2E3YTFhN2E3YTFhN2E3ozFhN2E3YTFhN2E3ozFhN2E3YTFhN2E3ozejMWE3YTFhsWE3YTFhN2E3ozFhsWE3YTFhN2E3ozFo8WjIg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3903 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3656323087 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5645c72af810, 0x5645c749901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5645c7499020,0x5645c93310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dd5ece7da85ddd5eabcf6aa5c435c8394bb5d135' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4847 processed earlier; will process 6182 files now Step #5: #1 pulse cov: 3977 ft: 3978 exec/s: 0 rss: 175Mb Step #5: ==140584== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5645bdda49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5645c4409898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5645c43ec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5645c43ec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5645bddaad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5645bdd0bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5645bdd06355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5645bdd9cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5645c0d6bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5645c0d6bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5645c0d6bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5645c0d6bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5645c0d6bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5645c0d6bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5645c0d6bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5645c0d6bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5645c0d6bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5645c0d6bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5645c3000f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5645bfd2db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5645bfd38be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5645bfae4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5645bfae4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5645bfae5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5645bfae4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5645bfae4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5645bfae4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5645c43eeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5645c43f7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5645c43df699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5645c440a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f204475e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5645bdd04b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0xef,0xac,0xac,0xef,0xbe,0xa1,0xef,0xac,0x96,0xef,0xbe,0xa3,0xef,0xac,0x8e,0xef,0xac,0xac,0xef,0xbe,0x90,0xe7,0xac,0xb6,0xef,0xbe,0xa0,0xef,0xac,0xac,0xef,0xbe,0xa0,0xef,0xac,0x96,0xef,0xbe,0xa0,0xef,0xac,0xad,0xef,0xbd,0xa0,0xef,0xac,0xac,0xef,0xbd,0xa0,0xef,0xac,0x96,0xef,0xbe,0xa0,0xef,0xbe,0xa0,0xef,0xac,0xac,0xef,0xbe,0xac,0x96,0xef,0xbe,0xa0,0xef,0xac,0x33,0x36,0x34,0x39,0xac,0x96,0xef,0xbe,0xa0,0xef,0xbe,0x53, Step #5: \000\000\000\000\357\254\254\357\276\241\357\254\226\357\276\243\357\254\216\357\254\254\357\276\220\347\254\266\357\276\240\357\254\254\357\276\240\357\254\226\357\276\240\357\254\255\357\275\240\357\254\254\357\275\240\357\254\226\357\276\240\357\276\240\357\254\254\357\276\254\226\357\276\240\357\2543649\254\226\357\276\240\357\276S Step #5: artifact_prefix='./'; Test unit written to ./oom-0950e73798b36af4c3215412d388ce3740393a48 Step #5: Base64: AAAAAO+srO++oe+slu++o++sju+srO++kOestu++oO+srO++oO+slu++oO+sre+9oO+srO+9oO+slu++oO++oO+srO++rJbvvqDvrDM2NDmslu++oO++Uw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3904 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3656875281 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e5be14810, 0x562e5bffe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e5bffe020,0x562e5de960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0950e73798b36af4c3215412d388ce3740393a48' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4849 processed earlier; will process 6180 files now Step #5: #1 pulse cov: 3633 ft: 3634 exec/s: 0 rss: 176Mb Step #5: ==140620== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562e529099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e58f6e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e58f515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e58f514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e5290fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e52870b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e5286b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e52901c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e558d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e558d0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e558d0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e558d0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e558d0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e558d0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e558d0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e558d0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e558d0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e558d0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e57b65f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e54892b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e5489dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e54649c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e54649c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e5464a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e54649874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e54649874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e54649874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e58f53abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e58f5c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e58f44699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e58f6f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ddf387082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e52869b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x76,0x21,0x39,0xa,0x0,0x7d,0x7d,0x7d,0x7d,0xd7,0xaf,0x69,0x66,0x7d,0xd7,0xaf,0x2d,0x0,0x7e,0x73,0x74,0x39,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x76,0x21,0x39,0xa,0x0,0x7d,0x7d,0x7d,0x7d,0xd7,0xaf,0x69,0x66,0x7d,0xd7,0xaf,0x2d,0x0,0x7e,0x73,0x74,0x39,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0xd7,0xa3,0x1,0xd7,0xa3,0x2d,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0xd7,0xa3,0x1,0xd7,0xa3,0x2d,0x0, Step #5: #v!9\012\000}}}}\327\257if}\327\257-\000~st9>>>>>>>>v!9\012\000}}}}\327\257if}\327\257-\000~st9>>>>>>>>>>>>>>>\327\243\001\327\243->>>>>>>\327\243\001\327\243-\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6b2fc95cd828ff4042746ab15799d9121cc457fc Step #5: Base64: I3YhOQoAfX19fdevaWZ9168tAH5zdDk+Pj4+Pj4+PnYhOQoAfX19fdevaWZ9168tAH5zdDk+Pj4+Pj4+Pj4+Pj4+Pj7XowHXoy0+Pj4+Pj4+16MB16MtAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3905 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3657423469 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5634afdf1810, 0x5634affdb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5634affdb020,0x5634b1e730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b2fc95cd828ff4042746ab15799d9121cc457fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4851 processed earlier; will process 6178 files now Step #5: ==140656== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5634a68e69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5634acf4b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634acf2e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634acf2e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5634a68ecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5634a684db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5634a6848355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5634a68dec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5634a98adf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5634a98adf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5634a98adf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5634a98adf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5634a98adf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5634a98adf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5634a98adf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5634a98adf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5634a98adf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5634a98adf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5634abb42f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5634a886fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5634a887abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5634a8626c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5634a8626c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5634a8627738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5634a8626874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5634a8626874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5634a8626874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5634acf30abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5634acf39928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5634acf21699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5634acf4c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5b913f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5634a6846b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x1,0x0,0x0,0x0,0x3,0x31,0x54,0x43,0x0,0x0,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x67,0x6c,0x79,0x66,0x0,0x31,0x3,0x4f,0x54,0x0,0x43,0x43,0x4f,0x2,0x0,0x0,0x2,0x0,0x2,0x3,0x31,0x54,0x3b,0xef,0xbb,0xae,0xd,0x39,0x39,0x0,0x32,0x3,0x1f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x3,0x31,0x3,0x31,0x54,0x43,0x4f,0x0,0x0,0x2,0x3,0x30,0x3a, Step #5: ID3\002\001\000\000\000\0031TC\000\000=\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000glyf\0001\003OT\000CCO\002\000\000\002\000\002\0031T;\357\273\256\01599\0002\003\037\000\000\000\000\000\000\000\000\002\0031\0031TCO\000\000\002\0030: Step #5: artifact_prefix='./'; Test unit written to ./oom-3babed4b3fa79199484d1498157134241c553bb3 Step #5: Base64: SUQzAgEAAAADMVRDAAA9AAAAAAAAAAAAAAAAAAAAAAAAZ2x5ZgAxA09UAENDTwIAAAIAAgMxVDvvu64NOTkAMgMfAAAAAAAAAAACAzEDMVRDTwAAAgMwOg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3906 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3657932448 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dce8f4f810, 0x55dce913901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dce9139020,0x55dceafd10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3babed4b3fa79199484d1498157134241c553bb3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4852 processed earlier; will process 6177 files now Step #5: ==140692== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dcdfa449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dce60a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dce608c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dce608c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dcdfa4ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dcdf9abb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dcdf9a6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dcdfa3cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dce2a0bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dce2a0bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dce2a0bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dce2a0bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dce2a0bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dce2a0bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dce2a0bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dce2a0bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dce2a0bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dce2a0bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dce4ca0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dce19cdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dce19d8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dce1784c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dce1784c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dce1785738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dce1784874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dce1784874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dce1784874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dce608eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dce6097928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dce607f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dce60aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ea5399082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dcdf9a4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x55,0x4,0x22,0xc6,0x87,0xc6,0x87,0xc6,0x87,0xc6,0x87,0xc9,0x86,0xce,0x87,0xc6,0x87,0xc6,0x86,0xc6,0x87,0xc6,0x8f,0xc6,0x87,0xc6,0x87,0xc6,0x87,0xc6,0x87,0x28,0xc6,0x87,0x41,0xc6,0x87,0xc6,0x87,0xc6,0x87,0xc6,0x87,0xc6,0x87,0xc9,0x86,0x33,0x78,0x39,0x78,0x39,0x79,0x31,0x78,0xc6,0x87,0xc6,0x87,0xc6,0x87,0xc6,0x87,0xc3,0x87,0xc6,0x86,0xce,0x87,0xc6,0x87,0xc6,0x87,0xc6,0x87,0xc6,0x88,0xc6,0x87,0xc6,0x87,0xc6,0x87,0xc6,0x87,0xc6, Step #5: HUU\004\"\306\207\306\207\306\207\306\207\311\206\316\207\306\207\306\206\306\207\306\217\306\207\306\207\306\207\306\207(\306\207A\306\207\306\207\306\207\306\207\306\207\311\2063x9x9y1x\306\207\306\207\306\207\306\207\303\207\306\206\316\207\306\207\306\207\306\207\306\210\306\207\306\207\306\207\306\207\306 Step #5: artifact_prefix='./'; Test unit written to ./oom-0446b10ea2c62224bd79a5f795f8cf731f63f937 Step #5: Base64: SFVVBCLGh8aHxofGh8mGzofGh8aGxofGj8aHxofGh8aHKMaHQcaHxofGh8aHxofJhjN4OXg5eTF4xofGh8aHxofDh8aGzofGh8aHxofGiMaHxofGh8aHxg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3907 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3658441902 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ce0727810, 0x561ce091101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ce0911020,0x561ce27a90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0446b10ea2c62224bd79a5f795f8cf731f63f937' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4853 processed earlier; will process 6176 files now Step #5: ==140728== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561cd721c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561cdd881898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561cdd8645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561cdd8644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561cd7222d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561cd7183b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561cd717e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561cd7214c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561cda1e3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561cda1e3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561cda1e3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561cda1e3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561cda1e3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561cda1e3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561cda1e3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561cda1e3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561cda1e3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561cda1e3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561cdc478f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561cd91a5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561cd91b0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561cd8f5cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561cd8f5cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561cd8f5d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561cd8f5c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561cd8f5c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561cd8f5c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561cdd866abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561cdd86f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561cdd857699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561cdd882112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6c71480082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561cd717cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x2d,0x30,0x2d,0x2d,0x35,0x2d,0x30,0x2d,0x2d,0x35,0x2d,0x30,0x2d,0x2d,0x34,0x2d,0x30,0x2d,0x30,0x2d,0x2d,0x35,0x2d,0x30,0x2d,0x2d,0x35,0x2d,0x30,0x2d,0x2d,0x33,0x2d,0x30,0x2d,0x2d,0x35,0x2d,0x30,0x2d,0x2d,0x35,0x2d,0x30,0x2d,0x2d,0x34,0x2d,0x30,0x2d,0x2d,0x35,0x2d,0x30,0x2d,0x2d,0x34,0x2d,0x30,0x2d,0x2d,0x34,0x2d,0x30,0x2d,0x2d,0x35,0x2d,0x30,0x2d,0x2d,0x34,0x2d,0x30,0x2d,0x2d,0x33,0x2d,0x30,0x2d,0x2d,0x35,0x2d,0x30,0x40,0x7e,0x29, Step #5: 1-0--5-0--5-0--4-0-0--5-0--5-0--3-0--5-0--5-0--4-0--5-0--4-0--4-0--5-0--4-0--3-0--5-0@~) Step #5: artifact_prefix='./'; Test unit written to ./oom-394e0fb8a5a1e0b858fa44339087576befe8bcfc Step #5: Base64: MS0wLS01LTAtLTUtMC0tNC0wLTAtLTUtMC0tNS0wLS0zLTAtLTUtMC0tNS0wLS00LTAtLTUtMC0tNC0wLS00LTAtLTUtMC0tNC0wLS0zLTAtLTUtMEB+KQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3908 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3658947070 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eedff64810, 0x55eee014e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eee014e020,0x55eee1fe60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/394e0fb8a5a1e0b858fa44339087576befe8bcfc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4854 processed earlier; will process 6175 files now Step #5: ==140764== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eed6a599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eedd0be898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eedd0a15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eedd0a14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eed6a5fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eed69c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eed69bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eed6a51c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eed9a20f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eed9a20f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eed9a20f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eed9a20f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eed9a20f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eed9a20f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eed9a20f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eed9a20f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eed9a20f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eed9a20f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eedbcb5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eed89e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eed89edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eed8799c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eed8799c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eed879a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eed8799874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eed8799874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eed8799874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eedd0a3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eedd0ac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eedd094699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eedd0bf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb494d92082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eed69b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xd,0x60,0x2e,0x6d,0x2c,0x30,0x2c,0x30,0x2c,0x2f,0x2c,0x30,0x2c,0x0,0x0,0x0,0x28,0x0,0x32,0x5b,0x0,0x63,0x75,0xff,0x63,0x5c,0x35,0x2c,0x30,0x7c,0x7a,0x4d,0x65,0x6d,0x54,0x6f,0x74,0x61,0x6c,0x3a,0x2c,0x31,0x2c,0x30,0x5c,0x63,0x0,0x63,0x0,0x0,0x40,0x33,0x0,0x63,0x75,0x63,0x5c,0x35,0x2c,0x30,0x74,0x7a,0x2c,0x30,0x2c,0x30,0x9d,0xcc,0xcf,0xd8,0x30,0x2c,0x30,0x35,0x30,0x30,0x2c,0x30,0x31,0x5d,0x7e,0x31,0xa2,0x30,0x32,0x3f,0x31,0x2f, Step #5: `\015`.m,0,0,/,0,\000\000\000(\0002[\000cu\377c\\5,0|zMemTotal:,1,0\\c\000c\000\000@3\000cuc\\5,0tz,0,0\235\314\317\3300,0500,01]~1\24202?1/ Step #5: artifact_prefix='./'; Test unit written to ./oom-8f7c89f6eb4c18784f450e5a27eec48bf52d6898 Step #5: Base64: YA1gLm0sMCwwLC8sMCwAAAAoADJbAGN1/2NcNSwwfHpNZW1Ub3RhbDosMSwwXGMAYwAAQDMAY3VjXDUsMHR6LDAsMJ3Mz9gwLDA1MDAsMDFdfjGiMDI/MS8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3909 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3659572158 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5566b41aa810, 0x5566b439401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5566b4394020,0x5566b622c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8f7c89f6eb4c18784f450e5a27eec48bf52d6898' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4855 processed earlier; will process 6174 files now Step #5: ==140800== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5566aac9f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5566b1304898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5566b12e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5566b12e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5566aaca5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5566aac06b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5566aac01355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5566aac97c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5566adc66f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5566adc66f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5566adc66f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5566adc66f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5566adc66f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5566adc66f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5566adc66f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5566adc66f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5566adc66f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5566adc66f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5566afefbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5566acc28b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5566acc33be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5566ac9dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5566ac9dfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5566ac9e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5566ac9df874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5566ac9df874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5566ac9df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5566b12e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5566b12f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5566b12da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5566b1305112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe991d34082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5566aabffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3e,0x20,0x1d,0x20,0x1d,0xa,0x3a,0x3d,0x3f,0x3f,0x42,0x3f,0x7a,0x72,0x20,0x3f,0x3d,0x3d,0x3f,0x3f,0x42,0x3f,0x7a,0x72,0x20,0x3f,0x3d,0x3d,0x3f,0x3f,0x42,0x3f,0x7a,0x72,0x20,0x3f,0x3d,0x3d,0x3f,0x3f,0x42,0x3f,0x7a,0x72,0x20,0x3f,0x3d,0x3d,0x3f,0x3f,0x42,0x3f,0x7a,0x72,0x20,0x3f,0x3d,0x3d,0x3f,0x3f,0x42,0x3f,0x7a,0x72,0x20,0x20,0x3f,0x3d,0x3d,0x3f,0x3f,0x42,0x3f,0x7a,0x72,0x20,0x3f,0x3d,0x3d,0x3f,0x3f,0x42,0x3f,0x7a,0x72,0x20,0x3f,0x3d,0x88, Step #5: > \035 \035\012:=??B?zr ?==??B?zr ?==??B?zr ?==??B?zr ?==??B?zr ?==??B?zr ?==??B?zr ?==??B?zr ?=\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-12140e8e173555af36d3775d6d57834c9359a955 Step #5: Base64: PiAdIB0KOj0/P0I/enIgPz09Pz9CP3pyID89PT8/Qj96ciA/PT0/P0I/enIgPz09Pz9CP3pyID89PT8/Qj96ciAgPz09Pz9CP3pyID89PT8/Qj96ciA/PYg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3910 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3660092286 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e40027b810, 0x55e40046501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e400465020,0x55e4022fd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/12140e8e173555af36d3775d6d57834c9359a955' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4856 processed earlier; will process 6173 files now Step #5: ==140836== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e3f6d709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e3fd3d5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e3fd3b85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e3fd3b84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e3f6d76d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e3f6cd7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e3f6cd2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e3f6d68c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e3f9d37f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e3f9d37f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e3f9d37f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e3f9d37f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e3f9d37f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e3f9d37f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e3f9d37f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e3f9d37f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e3f9d37f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e3f9d37f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e3fbfccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e3f8cf9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e3f8d04be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e3f8ab0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e3f8ab0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e3f8ab1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e3f8ab0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e3f8ab0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e3f8ab0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e3fd3baabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e3fd3c3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e3fd3ab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e3fd3d6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f63a2edd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e3f6cd0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x4f,0x2,0x0,0x42,0x8,0x0,0x47,0x45,0x4f,0x0,0x0,0x4,0x0,0x0,0x0,0x0,0x47,0x45,0x4f,0x0,0x0,0x4,0x0,0x0,0x0,0x0,0x47,0x45,0x4f,0x0,0x0,0x4,0x0,0x0,0x0,0x0,0x47,0x45,0x4f,0x0,0x47,0x45,0x4f,0x0,0x0,0x4,0x0,0x0,0x29,0x0,0x0,0x47,0x45,0x4f,0x0,0x0,0x4,0x0,0x0,0x0,0x0,0x47,0x45,0x4f,0x0,0x0,0x4,0x0,0x0,0x0,0x8,0x47,0x45,0x4f,0x0,0x0,0x4,0x0,0x0,0x0,0x0,0x47,0x45,0x4f,0x4, Step #5: ID3\002O\002\000B\010\000GEO\000\000\004\000\000\000\000GEO\000\000\004\000\000\000\000GEO\000\000\004\000\000\000\000GEO\000GEO\000\000\004\000\000)\000\000GEO\000\000\004\000\000\000\000GEO\000\000\004\000\000\000\010GEO\000\000\004\000\000\000\000GEO\004 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7d89c941e927fb3c2eee0dae794a79ada67ed5b Step #5: Base64: SUQzAk8CAEIIAEdFTwAABAAAAABHRU8AAAQAAAAAR0VPAAAEAAAAAEdFTwBHRU8AAAQAACkAAEdFTwAABAAAAABHRU8AAAQAAAAIR0VPAAAEAAAAAEdFTwQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3911 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3660600602 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b20dff810, 0x557b20fe901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b20fe9020,0x557b22e810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7d89c941e927fb3c2eee0dae794a79ada67ed5b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4857 processed earlier; will process 6172 files now Step #5: ==140872== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557b178f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b1df59898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b1df3c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b1df3c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b178fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b1785bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b17856355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b178ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b1a8bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b1a8bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b1a8bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b1a8bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b1a8bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b1a8bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b1a8bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b1a8bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b1a8bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b1a8bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b1cb50f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b1987db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b19888be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b19634c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b19634c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b19635738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b19634874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b19634874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b19634874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b1df3eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b1df47928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b1df2f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b1df5a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9153404082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b17854b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x2,0x0,0x1,0x0,0x30,0x63,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x49,0x0,0x0,0x0,0x0,0x0,0x2c,0x0,0x0,0x60,0x60,0x60,0x60,0x60,0x49,0x0,0x0,0x0,0x0,0x0,0x2c,0x0,0x0,0x60,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x1e,0x0,0xe9,0x0,0x0, Step #5: DanM\002\000\001\0000c````````I\000\000\000\000\000,\000\000`````I\000\000\000\000\000,\000\000`\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\011\000\000\000\000\000\000\000\000\000\000\000\000\000\000````````\036\000\351\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-77629a1dda2665e880176c5c0fe4f6a089a66724 Step #5: Base64: RGFuTQIAAQAwY2BgYGBgYGBgSQAAAAAALAAAYGBgYGBJAAAAAAAsAABgAAAAAAAAAAAAAAAAAAAAAAAAAAkAAAAAAAAAAAAAAAAAAGBgYGBgYGBgHgDpAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3912 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3661225646 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5596ba288810, 0x5596ba47201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596ba472020,0x5596bc30a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/77629a1dda2665e880176c5c0fe4f6a089a66724' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4858 processed earlier; will process 6171 files now Step #5: ==140908== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5596b0d7d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5596b73e2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5596b73c55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5596b73c54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5596b0d83d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5596b0ce4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5596b0cdf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5596b0d75c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5596b3d44f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5596b3d44f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5596b3d44f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5596b3d44f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5596b3d44f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5596b3d44f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5596b3d44f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5596b3d44f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5596b3d44f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5596b3d44f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596b5fd9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5596b2d06b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5596b2d11be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5596b2abdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5596b2abdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5596b2abe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5596b2abd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5596b2abd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5596b2abd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5596b73c7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5596b73d0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5596b73b8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5596b73e3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8db73bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5596b0cddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x67,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0x2e,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5, Step #5: ws:g\340\275\263\340\275\265\340\275\261\340\275\265\340\275\265\340\275\265\340\275\263\340\275\265\340\275\265\340\275\265.\340\275\263\340\275\265\340\275\265\340\275\265\340\275\265\340\275\261\340\275\265\340\275\263\340\275\265\340\275\265\340\275\263\340\275\265\340\275\265\340\275\265\340\275\261\340\275\265\340\275\265\340\275\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-259ecfb5968e9d45ab675ab3a08bcdeee477f9cd Step #5: Base64: d3M6Z+C9s+C9teC9seC9teC9teC9teC9s+C9teC9teC9tS7gvbPgvbXgvbXgvbXgvbXgvbHgvbXgvbPgvbXgvbXgvbPgvbXgvbXgvbXgvbHgvbXgvbXgvbU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3913 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3661732110 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564121870810, 0x564121a5a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564121a5a020,0x5641238f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/259ecfb5968e9d45ab675ab3a08bcdeee477f9cd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4859 processed earlier; will process 6170 files now Step #5: ==140944== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5641183659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56411e9ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56411e9ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56411e9ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56411836bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641182ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641182c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56411835dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56411b32cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56411b32cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56411b32cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56411b32cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56411b32cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56411b32cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56411b32cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56411b32cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56411b32cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56411b32cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56411d5c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56411a2eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56411a2f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56411a0a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56411a0a5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56411a0a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56411a0a5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56411a0a5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56411a0a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56411e9afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56411e9b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56411e9a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56411e9cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8716071082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641182c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2b,0x42,0x47,0xdd,0xbf,0x27,0x27,0x27,0x2f,0xd7,0x99,0x99,0xa3,0x66,0x66,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x26,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x7f,0xff,0x7a,0xff,0x48,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x27,0x27,0x15,0x2f,0x29,0x99,0xa3,0x66,0x66,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x26,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x7f,0xff,0x7a,0xff,0x48,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x27,0x27,0x15,0x2f,0x29,0x81,0x0,0x27, Step #5: \000+BG\335\277'''/\327\231\231\243ff\377\377\377\377\377\377\377&\377\377\377\377\377\377\377\377\177\377z\377H\377\377\377\377\377\377\377''\025/)\231\243ff\377\377\377\377\377\377\377&\377\377\377\377\377\377\377\377\177\377z\377H\377\377\377\377\377\377\377''\025/)\201\000' Step #5: artifact_prefix='./'; Test unit written to ./oom-8874ab754c033b9df1e09fe9be2f4642c750be8d Step #5: Base64: ACtCR92/JycnL9eZmaNmZv////////8m//////////9//3r/SP////////8nJxUvKZmjZmb/////////Jv//////////f/96/0j/////////JycVLymBACc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3914 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3662228806 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f0f799d810, 0x55f0f7b8701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f0f7b87020,0x55f0f9a1f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8874ab754c033b9df1e09fe9be2f4642c750be8d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4860 processed earlier; will process 6169 files now Step #5: ==140980== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f0ee4929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f0f4af7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f0f4ada5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f0f4ada4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f0ee498d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f0ee3f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f0ee3f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f0ee48ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f0f1459f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f0f1459f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f0f1459f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f0f1459f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f0f1459f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f0f1459f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f0f1459f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f0f1459f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f0f1459f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f0f1459f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f0f36eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f0f041bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f0f0426be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f0f01d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f0f01d2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f0f01d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f0f01d2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f0f01d2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f0f01d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f0f4adcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f0f4ae5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f0f4acd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f0f4af8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc2a400a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f0ee3f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x1d,0x1d,0x1d,0x1d,0x2f,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x2f,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0xa,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: ---\012---\012\035\035\035\035/\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035/\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\035\012\035\035\035\035\035\035\035\035\035\012-------END ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-f4e9ff588349affab32d248b240a574c9550d118 Step #5: Base64: LS0tCi0tLQodHR0dLx0dHR0dHR0dHR0dHR0dHR0dHR0dHR0vHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0KHR0dHR0dHR0dCi0tLS0tLS1FTkQgLS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3915 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3662730895 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a6fbc3810, 0x558a6fdad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a6fdad020,0x558a71c450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f4e9ff588349affab32d248b240a574c9550d118' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4861 processed earlier; will process 6168 files now Step #5: ==141016== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558a666b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a6cd1d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a6cd005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a6cd004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a666bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a6661fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a6661a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a666b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a6967ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a6967ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a6967ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a6967ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a6967ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a6967ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a6967ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a6967ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a6967ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a6967ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a6b914f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a68641b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a6864cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a683f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a683f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a683f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a683f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a683f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a683f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a6cd02abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a6cd0b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a6ccf3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a6cd1e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa54a432082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a66618b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x49,0x4d,0x33,0x4,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x37,0x64,0x61,0xf,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x38,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0xd0,0xa6,0xcd,0x9e,0xef,0xfd,0xb9,0x32,0x22, Step #5: ID3IM3\004\342\200\256\004\342\200\256a\342\200\256\004\342\200\256a340282366920938463463374607431768211457da\017\000\000\000\000\000\000\0008\001\000\000\000\000\000\000\320\246\315\236\357\375\2712\" Step #5: artifact_prefix='./'; Test unit written to ./oom-81aed500bcdd3f711509ab99875c7b55688222a9 Step #5: Base64: SUQzSU0zBOKArgTigK5h4oCuBOKArmEzNDAyODIzNjY5MjA5Mzg0NjM0NjMzNzQ2MDc0MzE3NjgyMTE0NTdkYQ8AAAAAAAAAOAEAAAAAAADQps2e7/25MiI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3916 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3663235615 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa34c25810, 0x55aa34e0f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa34e0f020,0x55aa36ca70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/81aed500bcdd3f711509ab99875c7b55688222a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4862 processed earlier; will process 6167 files now Step #5: ==141052== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aa2b71a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa31d7f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa31d625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa31d624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa2b720d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa2b681b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa2b67c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa2b712c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa2e6e1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa2e6e1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa2e6e1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa2e6e1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa2e6e1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa2e6e1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa2e6e1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa2e6e1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa2e6e1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa2e6e1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa30976f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa2d6a3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa2d6aebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa2d45ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa2d45ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa2d45b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa2d45a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa2d45a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa2d45a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa31d64abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa31d6d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa31d55699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa31d80112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e3a8a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa2b67ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xc3,0xb4,0xc3,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb8,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb8,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0x87,0xca,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb8,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb8,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0x87,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0xc2,0xb3,0x22,0x22, Step #5: \"\303\264\303\263\302\263\302\263\302\270\302\263\302\263\302\263\302\263\302\263\302\270\302\263\302\263\302\263\302\263\302\263\302\263\302\263\302\207\312\263\302\263\302\263\302\263\302\270\302\263\302\263\302\263\302\263\302\263\302\270\302\263\302\263\302\263\302\263\302\263\302\263\302\263\302\207\302\263\302\263\302\263\302\263\302\263\"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-1ffdb2cdc868d159e7f8acb972d766f7de3613c3 Step #5: Base64: IsO0w7PCs8KzwrjCs8KzwrPCs8KzwrjCs8KzwrPCs8KzwrPCs8KHyrPCs8KzwrPCuMKzwrPCs8KzwrPCuMKzwrPCs8KzwrPCs8KzwofCs8KzwrPCs8KzIiI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3917 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3663734241 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562eb06b8810, 0x562eb08a201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562eb08a2020,0x562eb273a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ffdb2cdc868d159e7f8acb972d766f7de3613c3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4863 processed earlier; will process 6166 files now Step #5: ==141088== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562ea71ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ead812898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ead7f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ead7f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562ea71b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562ea7114b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562ea710f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562ea71a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562eaa174f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562eaa174f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562eaa174f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562eaa174f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562eaa174f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562eaa174f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562eaa174f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562eaa174f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562eaa174f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562eaa174f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562eac409f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ea9136b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ea9141be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ea8eedc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ea8eedc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ea8eee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ea8eed874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ea8eed874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ea8eed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ead7f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ead800928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ead7e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ead813112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9c3c156082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562ea710db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2d,0x2d,0x0,0x0,0x2d,0xa,0x4f,0x0,0x41,0x24,0x4,0x2d,0x29,0x2d,0x0,0x3a,0x4e,0x21,0x24,0x47,0x49,0x49,0x44,0x32,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x49,0x21,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0xa,0x4f,0x0,0x41,0x24,0x4,0x2d,0x29,0x2d,0x0,0x3a,0x4f,0x21,0x24,0x47,0x49,0x49,0x44,0x32,0x2,0x55,0x20,0x2d,0x41,0x24,0x4,0x2d,0x29,0x2d,0x0,0x3a,0x4f,0x21,0x24,0x47,0x49,0x49,0x44,0x32,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x3, Step #5: \012--\000\000-\012O\000A$\004-)-\000:N!$GIID2\002U -E\012\012I!\001\000\000\000\000\000\000-\012O\000A$\004-)-\000:O!$GIID2\002U -A$\004-)-\000:O!$GIID2\002U -E\012\012\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-d14d42c9efe8f1f871b3a88a94f1344aae083123 Step #5: Base64: Ci0tAAAtCk8AQSQELSktADpOISRHSUlEMgJVIC1FCgpJIQEAAAAAAAAtCk8AQSQELSktADpPISRHSUlEMgJVIC1BJAQtKS0AOk8hJEdJSUQyAlUgLUUKCgM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3918 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3664246342 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55689e23d810, 0x55689e42701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55689e427020,0x5568a02bf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d14d42c9efe8f1f871b3a88a94f1344aae083123' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4864 processed earlier; will process 6165 files now Step #5: #1 pulse cov: 4324 ft: 4325 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4782 ft: 5109 exec/s: 0 rss: 179Mb Step #5: ==141124== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556894d329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55689b397898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55689b37a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55689b37a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556894d38d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556894c99b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556894c94355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556894d2ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556897cf9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556897cf9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556897cf9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556897cf9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556897cf9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556897cf9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556897cf9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556897cf9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556897cf9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556897cf9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556899f8ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556896cbbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556896cc6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556896a72c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556896a72c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556896a73738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556896a72874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556896a72874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556896a72874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55689b37cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55689b385928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55689b36d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55689b398112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f591d16b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556894c92b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x57,0x7a,0x67,0x73,0x4d,0x54,0x51,0x30,0x4e,0x7a,0x51,0x32,0x4d,0x7a,0x51,0x31,0x4d,0x54,0x51,0x30,0x4d,0x54,0x51,0x30,0x4e,0x7a,0x51,0x33,0x4d,0x7a,0x67,0x73,0x4d,0x54,0x51,0x30,0x4e,0x7a,0x51,0x32,0x4d,0x7a,0x51,0x32,0x4d,0x54,0x51,0x30,0x4d,0x54,0x51,0x31,0x4e,0x7a,0x51,0x32,0x4d,0x54,0x51,0x73,0x4e,0x7a,0x51,0x32,0x4d,0x7a,0x51,0x31,0x4d,0x54,0x51,0x30,0x4d,0x54,0x51,0x32,0x4d,0x54,0x51,0x30,0x4d,0x54,0x51,0x31,0x4d,0x54,0x67,0x2e,0x2e, Step #5: WzgsMTQ0NzQ2MzQ1MTQ0MTQ0NzQ3MzgsMTQ0NzQ2MzQ2MTQ0MTQ1NzQ2MTQsNzQ2MzQ1MTQ0MTQ2MTQ0MTQ1MTg.. Step #5: artifact_prefix='./'; Test unit written to ./oom-4e7a000c70f47bfe7c46fedf1638355eb420d58b Step #5: Base64: V3pnc01UUTBOelEyTXpRMU1UUTBNVFEwTnpRM016Z3NNVFEwTnpRMk16UTJNVFEwTVRRMU56UTJNVFFzTnpRMk16UTFNVFEwTVRRMk1UUTBNVFExTVRnLi4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3919 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3664830762 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5580f4cbf810, 0x5580f4ea901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5580f4ea9020,0x5580f6d410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e7a000c70f47bfe7c46fedf1638355eb420d58b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4867 processed earlier; will process 6162 files now Step #5: ==141160== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5580eb7b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5580f1e19898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5580f1dfc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5580f1dfc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5580eb7bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5580eb71bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5580eb716355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5580eb7acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5580ee77bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5580ee77bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5580ee77bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5580ee77bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5580ee77bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5580ee77bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5580ee77bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5580ee77bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5580ee77bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5580ee77bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5580f0a10f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5580ed73db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5580ed748be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580ed4f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580ed4f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580ed4f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580ed4f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580ed4f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580ed4f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5580f1dfeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5580f1e07928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5580f1def699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5580f1e1a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0aac1d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5580eb714b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x20,0x7b,0xa,0x20,0x20,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x65,0x78,0x74,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x74,0x79,0x70,0x65,0x3a,0x20,0x38,0xa,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x7d,0xa,0x7d,0xa,0x65,0x20,0x7b,0xa,0x20,0x20,0x63,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x73,0x74,0x72,0x3a,0x20,0x22,0x3c,0x61,0x3e,0x22,0xa,0x20,0x20,0x7d,0xa,0x7d,0xa, Step #5: p {\012 doctype {\012 ext {\012 type: 8\012 }\012 }\012}\012e {\012 content {\012 str: \"<a>\"\012 }\012}\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-11ca994005924f0e61ddbf13a3c04271db6cf397 Step #5: Base64: cCB7CiAgZG9jdHlwZSB7CiAgICBleHQgewogICAgICB0eXBlOiA4CiAgICB9CiAgfQp9CmUgewogIGNvbnRlbnQgewogICAgc3RyOiAiPGE+IgogIH0KfQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3920 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3665339852 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56492de74810, 0x56492e05e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56492e05e020,0x56492fef60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/11ca994005924f0e61ddbf13a3c04271db6cf397' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4868 processed earlier; will process 6161 files now Step #5: ==141196== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5649249699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56492afce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56492afb15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56492afb14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56492496fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649248d0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649248cb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564924961c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564927930f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564927930f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564927930f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564927930f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564927930f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564927930f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564927930f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564927930f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564927930f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564927930f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564929bc5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649268f2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649268fdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5649266a9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5649266a9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5649266aa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5649266a9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5649266a9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5649266a9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56492afb3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56492afbc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56492afa4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56492afcf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f360413f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649248c9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x2e,0x2e,0x2e,0x2e,0x0,0x0,0x0,0x0,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x65,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x33,0x2,0x6b,0x6,0x65,0x0,0x0,0x6b,0x6,0x65,0xdf,0xb4,0xfb,0xff,0x44,0x6b,0xff, Step #5: I....\000\000\000\000mmmmmmmmmmmmmmmmmmmmmmmmmmmmemmmmmmmmmmmmmmmmmmmmm\000\000\000\000\000\000\000......3\002k\006e\000\000k\006e\337\264\373\377Dk\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-e31784bf54f0da90773b0375c08fb54c4e3d54e8 Step #5: Base64: SS4uLi4AAAAAbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbWVtbW1tbW1tbW1tbW1tbW1tbW1tbW0AAAAAAAAALi4uLi4uMwJrBmUAAGsGZd+0+/9Ea/8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3921 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3665844643 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5608c1b08810, 0x5608c1cf201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5608c1cf2020,0x5608c3b8a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e31784bf54f0da90773b0375c08fb54c4e3d54e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4869 processed earlier; will process 6160 files now Step #5: ==141232== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5608b85fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5608bec62898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608bec455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608bec454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5608b8603d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5608b8564b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5608b855f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5608b85f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5608bb5c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5608bb5c4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5608bb5c4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5608bb5c4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5608bb5c4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5608bb5c4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5608bb5c4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5608bb5c4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5608bb5c4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5608bb5c4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608bd859f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5608ba586b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5608ba591be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5608ba33dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5608ba33dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5608ba33e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5608ba33d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5608ba33d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5608ba33d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5608bec47abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5608bec50928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5608bec38699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5608bec63112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f62986bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5608b855db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x42,0xdb,0xbe,0x75,0xdb,0xbe,0x73,0x74,0x72,0x65,0x61,0x6d,0x2b,0x2b,0x2b,0x2b,0x2b,0x41,0x2b,0x2b,0x2b,0x2b,0x2b,0x3b,0xef,0xbb,0xae,0xd,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x2b,0x2b,0x24,0x6e,0x24,0x3,0x3,0x52, Step #5: - B\333\276u\333\276stream+++++A+++++;\357\273\256\0159999999999999999999999\000\000\000\000\000\000\000\000\000\000\000\000\000\000999999999999999++$n$\003\003R Step #5: artifact_prefix='./'; Test unit written to ./oom-069256875658254ee54e698ab23956981c744d9a Step #5: Base64: LSBC2751275zdHJlYW0rKysrK0ErKysrKzvvu64NOTk5OTk5OTk5OTk5OTk5OTk5OTk5OQAAAAAAAAAAAAAAAAAAOTk5OTk5OTk5OTk5OTk5KyskbiQDA1I= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3922 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3666353247 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56170e296810, 0x56170e48001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56170e480020,0x5617103180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/069256875658254ee54e698ab23956981c744d9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4870 processed earlier; will process 6159 files now Step #5: ==141268== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561704d8b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56170b3f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56170b3d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56170b3d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561704d91d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561704cf2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561704ced355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561704d83c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561707d52f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561707d52f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561707d52f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561707d52f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561707d52f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561707d52f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561707d52f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561707d52f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561707d52f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561707d52f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561709fe7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561706d14b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561706d1fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561706acbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561706acbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561706acc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561706acb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561706acb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561706acb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56170b3d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56170b3de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56170b3c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56170b3f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efef50da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561704cebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0xdb,0x80,0xdb,0x80,0x39,0x39,0x39,0x39,0x39,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0xf6,0x2e,0x2e,0x2e,0x2e,0x33,0x2,0x6b,0x6,0x65,0x6e,0x72,0x58,0x29,0x58,0x78,0x54,0x58,0x58,0x2a,0x4b,0x0,0x0,0x44,0x6b,0xff, Step #5: ID............................................\333\200\333\20099999........\366....3\002k\006enrX)XxTXX*K\000\000Dk\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-34340064b0386781fa01a4dda19e4e86a37045dc Step #5: Base64: SUQuLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLtuA24A5OTk5OS4uLi4uLi4u9i4uLi4zAmsGZW5yWClYeFRYWCpLAABEa/8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3923 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3666852815 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561f75699810, 0x561f7588301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561f75883020,0x561f7771b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/34340064b0386781fa01a4dda19e4e86a37045dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4871 processed earlier; will process 6158 files now Step #5: #1 pulse cov: 4140 ft: 4141 exec/s: 0 rss: 174Mb Step #5: ==141304== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561f6c18e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561f727f3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561f727d65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561f727d64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561f6c194d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561f6c0f5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561f6c0f0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561f6c186c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561f6f155f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561f6f155f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561f6f155f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561f6f155f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561f6f155f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561f6f155f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561f6f155f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561f6f155f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561f6f155f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561f6f155f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561f713eaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561f6e117b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561f6e122be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561f6decec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561f6decec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561f6decf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561f6dece874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561f6dece874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561f6dece874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561f727d8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561f727e1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561f727c9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561f727f4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fddb4649082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561f6c0eeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x25,0x0,0x3d,0x2,0x4,0x1,0x43,0x48,0x41,0x0,0x0,0x11,0x40,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xae,0x0,0x63,0x72,0x79,0x73,0x74,0x61,0x6c,0x11,0x0,0x0,0x0,0x0,0x0, Step #5: ID3\002%\000=\002\004\001CHA\000\000\021@\000\000\000\000\000\000\000\000\000\000\342\200\256\000\000\000CHA\000\000\021\000\000\000\000\000\000\000\000\002\000\000\342\200\256\000\000\000CHA\000\000\021\000\000\000\000\000\000\000\000\000\000\000\342\200\256\000crystal\021\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8ba08e574a97b41ffd61b6c396935f8239ca1958 Step #5: Base64: SUQzAiUAPQIEAUNIQQAAEUAAAAAAAAAAAAAA4oCuAAAAQ0hBAAARAAAAAAAAAAACAADigK4AAABDSEEAABEAAAAAAAAAAAAAAOKArgBjcnlzdGFsEQAAAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3924 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3667399866 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f498692810, 0x55f49887c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f49887c020,0x55f49a7140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ba08e574a97b41ffd61b6c396935f8239ca1958' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4873 processed earlier; will process 6156 files now Step #5: ==141340== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f48f1879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f4957ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f4957cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f4957cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f48f18dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f48f0eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f48f0e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f48f17fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f49214ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f49214ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f49214ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f49214ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f49214ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f49214ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f49214ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f49214ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f49214ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f49214ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4943e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f491110b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f49111bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f490ec7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f490ec7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f490ec8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f490ec7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f490ec7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f490ec7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f4957d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f4957da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f4957c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f4957ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f366fd25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f48f0e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x60,0x20,0xa,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x20,0x2d,0x60,0x60,0x20,0xa,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x60,0x20,0x41,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x20,0x2d,0x60,0x60,0x20,0xa,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x0,0x20,0x20,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x0,0x20,0x20,0x20,0x63,0x36,0x2e,0x2e, Step #5: \012`-``-`` \001\000\000 ` \012`-`` \001\000\000 -`` \012`-``-`` \001\000\000 ` A`-`` \001\000\000 -`` \012`-`` \001\000\000 \000 `-`` \001\000\000 \000 c6.. Step #5: artifact_prefix='./'; Test unit written to ./oom-33b9caf3f2571ee81fa29925e2601149b93c5ab2 Step #5: Base64: CmAtYGAtYGAgAQAAIGAgCmAtYGAgAQAAICAtYGAgCmAtYGAtYGAgAQAAIGAgQWAtYGAgAQAAICAtYGAgCmAtYGAgAQAAIAAgIGAtYGAgAQAAIAAgICBjNi4u Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3925 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3668034905 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559b64efb810, 0x559b650e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559b650e5020,0x559b66f7d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/33b9caf3f2571ee81fa29925e2601149b93c5ab2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4874 processed earlier; will process 6155 files now Step #5: ==141376== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559b5b9f09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559b62055898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559b620385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559b620384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b5b9f6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b5b957b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b5b952355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b5b9e8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b5e9b7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b5e9b7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b5e9b7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b5e9b7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b5e9b7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b5e9b7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b5e9b7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b5e9b7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b5e9b7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b5e9b7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559b60c4cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b5d979b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b5d984be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b5d730c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b5d730c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b5d731738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b5d730874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b5d730874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b5d730874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559b6203aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559b62043928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559b6202b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559b62056112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f11eaa74082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b5b950b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x30,0x2d,0xe4,0x88,0x88,0x23,0x30,0x2d,0x2d,0xe4,0x88,0x88,0x23,0x30,0x2d,0xe4,0x88,0x88,0x23,0x30,0x2d,0xe4,0x88,0x88,0x23,0x30,0x2d,0xe4,0x88,0x88,0x23,0x30,0x2d,0xe4,0x88,0x88,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xfa,0x0,0x0,0x0,0x23,0x30,0x30,0x88,0x23,0xe4,0x88,0x2d,0x2d,0xe4,0x88,0x88,0x23,0x30,0x2d,0xe4,0x88,0x88,0x23,0x0,0x88,0xc0,0xad,0xc0,0xad,0xc0,0xad,0xc0,0xad,0xc0,0xad,0xc0,0xad,0xc0,0xad, Step #5: #0-\344\210\210#0--\344\210\210#0-\344\210\210#0-\344\210\210#0-\344\210\210#0-\344\210\210\000\000\000\000\000\000\000\000\000\000\000\000\000\000\372\000\000\000#00\210#\344\210--\344\210\210#0-\344\210\210#\000\210\300\255\300\255\300\255\300\255\300\255\300\255\300\255 Step #5: artifact_prefix='./'; Test unit written to ./oom-05023bb8c96ea6eb6890d2ab1afdedf7e3765ac0 Step #5: Base64: IzAt5IiIIzAtLeSIiCMwLeSIiCMwLeSIiCMwLeSIiCMwLeSIiAAAAAAAAAAAAAAAAAAA+gAAACMwMIgj5IgtLeSIiCMwLeSIiCMAiMCtwK3ArcCtwK3ArcCt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3926 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3668537910 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b4183be810, 0x55b4185a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b4185a8020,0x55b41a4400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/05023bb8c96ea6eb6890d2ab1afdedf7e3765ac0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4875 processed earlier; will process 6154 files now Step #5: #1 pulse cov: 10896 ft: 10897 exec/s: 0 rss: 194Mb Step #5: ==141412== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b40eeb39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b415518898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b4154fb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b4154fb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b40eeb9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b40ee1ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b40ee15355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b40eeabc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b411e7af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b411e7af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b411e7af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b411e7af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b411e7af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b411e7af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b411e7af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b411e7af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b411e7af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b411e7af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b41410ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b410e3cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b410e47be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b410bf3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b410bf3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b410bf4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b410bf3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b410bf3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b410bf3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b4154fdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b415506928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b4154ee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b415519112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc467182082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b40ee13b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x30,0x27,0x27,0x32,0x31,0x34,0x37,0x34,0x37,0x2d,0x3d,0x27,0x27,0x27,0x37,0x27,0x27,0x2f,0x27,0x1d,0x32,0x2d,0x3d,0x27,0x60,0x27,0x27,0x27,0x27,0x27,0x27,0x5e,0x27,0x73,0x20,0x37,0x20,0x30,0x20,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x60,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $0''214747-='''7''/'\0352-='`''''''^'s 7 0 =<'''''''''''`'''/''''''2-='''''''''''''.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-d2b7ddb016f1872cf8386ad786632a6d64c925a1 Step #5: Base64: JDAnJzIxNDc0Ny09JycnNycnLycdMi09J2AnJycnJydeJ3MgNyAwID08JycnJycnJycnJydgJycnLycnJycnJzItPScnJycnJycnJycnJycuJycnJy4nJCct Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3927 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3669119088 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564cab964810, 0x564cabb4e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564cabb4e020,0x564cad9e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d2b7ddb016f1872cf8386ad786632a6d64c925a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4877 processed earlier; will process 6152 files now Step #5: ==141448== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564ca24599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564ca8abe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564ca8aa15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564ca8aa14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ca245fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ca23c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ca23bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ca2451c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564ca5420f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564ca5420f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564ca5420f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564ca5420f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564ca5420f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564ca5420f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564ca5420f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564ca5420f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564ca5420f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564ca5420f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564ca76b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564ca43e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564ca43edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564ca4199c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564ca4199c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564ca419a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564ca4199874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564ca4199874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564ca4199874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564ca8aa3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564ca8aac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564ca8a94699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564ca8abf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd9fdfa4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ca23b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x25,0x0,0x3d,0x2,0x4,0x1,0x43,0x48,0x41,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0, Step #5: ID3\002%\000=\002\004\001CHA\000\000\021\000\000\000\000\000\000\000\000\000\000\000\342\200\256\000\000\000CHA\000\000\021\000\000\000\000\000\000\000\000\002\000\000\342\200\256\000\000\000CHA\000\000\021\000\000\000\000\000\000\000\000\000\000\000\342\200\256\000\000\000CHA\000\000\021\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e80417cc4906b820732563ff8e47ea3e6d767003 Step #5: Base64: SUQzAiUAPQIEAUNIQQAAEQAAAAAAAAAAAAAA4oCuAAAAQ0hBAAARAAAAAAAAAAACAADigK4AAABDSEEAABEAAAAAAAAAAAAAAOKArgAAAENIQQAAEQAAAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3928 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3669624562 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b47eedc810, 0x55b47f0c601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b47f0c6020,0x55b480f5e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e80417cc4906b820732563ff8e47ea3e6d767003' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4878 processed earlier; will process 6151 files now Step #5: ==141484== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b4759d19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b47c036898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b47c0195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b47c0194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b4759d7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b475938b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b475933355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b4759c9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b478998f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b478998f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b478998f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b478998f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b478998f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b478998f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b478998f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b478998f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b478998f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b478998f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b47ac2df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b47795ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b477965be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b477711c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b477711c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b477712738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b477711874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b477711874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b477711874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b47c01babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b47c024928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b47c00c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b47c037112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1cc47db082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b475931b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x23,0x33,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x2e,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x2d,0x2d,0x23,0x33,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x2e,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x19,0x19,0x19,0x19,0x34,0x34,0x34,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x6c,0x61,0x73,0x73,0x4e,0x5b,0x5b,0x5b,0x39, Step #5: s--#344444444.4444444444444444444--#344444444.444444444444444\031\031\031\031444\000\000\000\000\000\000\000\000\000\000---lassN[[[9 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec183dca0f3fd6abe467c87ffd64243ba6d9385f Step #5: Base64: cy0tIzM0NDQ0NDQ0NC40NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0LS0jMzQ0NDQ0NDQ0LjQ0NDQ0NDQ0NDQ0NDQ0NBkZGRk0NDQAAAAAAAAAAAAALS0tbGFzc05bW1s5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3929 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3670129885 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1d37cd810, 0x55a1d39b701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1d39b7020,0x55a1d584f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec183dca0f3fd6abe467c87ffd64243ba6d9385f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4879 processed earlier; will process 6150 files now Step #5: #1 pulse cov: 4045 ft: 4046 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4134 ft: 4812 exec/s: 0 rss: 176Mb Step #5: ==141520== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1ca2c29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1d0927898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1d090a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1d090a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1ca2c8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1ca229b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1ca224355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1ca2bac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1cd289f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1cd289f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1cd289f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1cd289f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1cd289f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1cd289f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1cd289f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1cd289f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1cd289f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1cd289f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1cf51ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1cc24bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1cc256be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1cc002c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1cc002c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1cc003738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1cc002874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1cc002874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1cc002874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a1d090cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a1d0915928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1d08fd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1d0928112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f492577c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1ca222b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x30,0x27,0x27,0x32,0x31,0x34,0x37,0x34,0x37,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x1d,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x5e,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x60,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $0''214747-=''''''/'\0352-=''''''''^''''''-=<'''''''''''`'''/''''''2-='''''''''''''.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-1ec80f739464f404e14403ca917086e37324b31b Step #5: Base64: JDAnJzIxNDc0Ny09JycnJycnLycdMi09JycnJycnJydeJycnJycnLT08JycnJycnJycnJydgJycnLycnJycnJzItPScnJycnJycnJycnJycuJycnJy4nJCct Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3930 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3670777385 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558febf1e810, 0x558fec10801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558fec108020,0x558fedfa00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ec80f739464f404e14403ca917086e37324b31b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4883 processed earlier; will process 6146 files now Step #5: ==141556== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558fe2a139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558fe9078898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558fe905b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558fe905b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558fe2a19d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558fe297ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558fe2975355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558fe2a0bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558fe59daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558fe59daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558fe59daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558fe59daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558fe59daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558fe59daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558fe59daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558fe59daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558fe59daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558fe59daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558fe7c6ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558fe499cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558fe49a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558fe4753c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558fe4753c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558fe4754738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558fe4753874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558fe4753874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558fe4753874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558fe905dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558fe9066928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558fe904e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558fe9079112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc590e23082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558fe2973b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x20,0x3c,0x3c,0xa,0x20,0x17,0x17,0x17,0x17,0x17,0x17,0x44,0x65,0x6e,0xe2,0x81,0x9f,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa0,0x8e,0x3c,0x20,0x17,0x17,0x17,0x17,0x17,0x44,0x65,0x6e,0xe2,0x81,0x9f,0x28,0xe2,0x80,0xac,0x5b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x81,0xae,0x64,0x0,0x64,0x64,0xb5,0xf3,0xa0,0x81,0x87,0x7f,0x7f,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x81,0xae,0x0,0x64,0x64,0x64,0xb5,0xf3,0xa0,0x81,0x87,0x64,0x64, Step #5: s <<\012 \027\027\027\027\027\027Den\342\201\237(\342\200\254\000\341\240\216< \027\027\027\027\027Den\342\201\237(\342\200\254[\000\000\000\000\000\000\000\342\200\215\000\000(\342\201\256d\000dd\265\363\240\201\207\177\177\342\200\215\000\000(\342\201\256\000ddd\265\363\240\201\207dd Step #5: artifact_prefix='./'; Test unit written to ./oom-889244dbdd3145ef4f36d301f88db14970ad032e Step #5: Base64: cyA8PAogFxcXFxcXRGVu4oGfKOKArADhoI48IBcXFxcXRGVu4oGfKOKArFsAAAAAAAAA4oCNAAAo4oGuZABkZLXzoIGHf3/igI0AACjiga4AZGRktfOggYdkZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3931 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3671285983 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fbdeb13810, 0x55fbdecfd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fbdecfd020,0x55fbe0b950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/889244dbdd3145ef4f36d301f88db14970ad032e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4884 processed earlier; will process 6145 files now Step #5: #1 pulse cov: 3415 ft: 3416 exec/s: 0 rss: 174Mb Step #5: ==141592== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fbd56089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fbdbc6d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fbdbc505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fbdbc504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fbd560ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fbd556fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fbd556a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fbd5600c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fbd85cff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fbd85cff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fbd85cff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fbd85cff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fbd85cff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fbd85cff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fbd85cff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fbd85cff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fbd85cff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fbd85cff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fbda864f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fbd7591b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fbd759cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fbd7348c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fbd7348c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fbd7349738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fbd7348874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fbd7348874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fbd7348874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fbdbc52abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fbdbc5b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fbdbc43699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fbdbc6e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f85a2595082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fbd5568b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x58,0x44,0x22,0x3d,0x3f,0x35,0xe6,0xbe,0x8e,0xe6,0x8e,0x8f,0xe6,0x8c,0x8e,0x30,0x38,0xe6,0xbd,0x8f,0x31,0xe2,0xbe,0x8e,0x3f,0x33,0xe6,0xbe,0x8e,0xe6,0x8e,0x8f,0xe6,0xb9,0x8e,0x3f,0x38,0xe6,0x8c,0x8e,0x31,0x28,0x29,0xe6,0x8c,0x8e,0x31,0x28,0xe6,0xbe,0x8f,0x32,0xe2,0xbe,0x8e,0x3f,0x31,0xe6,0xb9,0x8e,0x3f,0x31,0xe6,0xbe,0x8e,0xe6,0x8e,0x8f,0xe6,0x8c,0x8e,0x30,0x2b,0xe6,0xbe,0x8f,0x30,0xe2,0xbe,0x8e,0x3f,0x31,0xe6,0xb9,0x8e,0x3f,0x31,0xe6,0xe6, Step #5: HUXD\"=?5\346\276\216\346\216\217\346\214\21608\346\275\2171\342\276\216?3\346\276\216\346\216\217\346\271\216?8\346\214\2161()\346\214\2161(\346\276\2172\342\276\216?1\346\271\216?1\346\276\216\346\216\217\346\214\2160+\346\276\2170\342\276\216?1\346\271\216?1\346\346 Step #5: artifact_prefix='./'; Test unit written to ./oom-b21c8a268f83a6f077c61bfb548981aff04df95b Step #5: Base64: SFVYRCI9PzXmvo7mjo/mjI4wOOa9jzHivo4/M+a+juaOj+a5jj845oyOMSgp5oyOMSjmvo8y4r6OPzHmuY4/Mea+juaOj+aMjjAr5r6PMOK+jj8x5rmOPzHm5g== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3932 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3671829695 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559deb69d810, 0x559deb88701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559deb887020,0x559ded71f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b21c8a268f83a6f077c61bfb548981aff04df95b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4886 processed earlier; will process 6143 files now Step #5: ==141628== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559de21929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559de87f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559de87da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559de87da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559de2198d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559de20f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559de20f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559de218ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559de5159f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559de5159f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559de5159f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559de5159f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559de5159f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559de5159f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559de5159f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559de5159f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559de5159f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559de5159f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559de73eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559de411bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559de4126be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559de3ed2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559de3ed2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559de3ed3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559de3ed2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559de3ed2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559de3ed2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559de87dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559de87e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559de87cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559de87f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff7e7ee5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559de20f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x7b,0x5b,0x5f,0x3f,0x2d,0x31,0x5f,0x3f,0x31,0x36,0x36,0x31,0x31,0x31,0x75,0x5f,0x5f,0x3f,0x3f,0x24,0x7e,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x5f,0x3f,0x30,0x5f,0x3f,0x30,0x3a,0x3a,0x5f,0x3f,0x30,0x5f,0x3f,0x24,0x31,0x3a,0x5f,0x3f,0x28,0x30,0x3a,0x5f,0x3f,0x30,0x5f,0x3f,0x3f,0x30,0x3a,0x5f,0x2d,0x34,0x33,0x36,0x30,0x3a,0x30,0x3a,0x5f,0x3f,0x30,0x5f,0x3f,0x30,0x5f,0x36,0x35,0x3f,0x30, Step #5: [{[_?-1_?166111u__??$~:_?0:_?0:_?0:_?0:_?0_?0_?0::_?0_?$1:_?(0:_?0_??0:_-4360:0:_?0_?0_65?0 Step #5: artifact_prefix='./'; Test unit written to ./oom-1c49cd8968196cec28a1965b1bec38363b68a6a0 Step #5: Base64: W3tbXz8tMV8/MTY2MTExdV9fPz8kfjpfPzA6Xz8wOl8/MDpfPzA6Xz8wXz8wXz8wOjpfPzBfPyQxOl8/KDA6Xz8wXz8/MDpfLTQzNjA6MDpfPzBfPzBfNjU/MA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3933 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3672339151 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a93f0a3810, 0x55a93f28d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a93f28d020,0x55a9411250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c49cd8968196cec28a1965b1bec38363b68a6a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4887 processed earlier; will process 6142 files now Step #5: #1 pulse cov: 4017 ft: 4018 exec/s: 0 rss: 175Mb Step #5: ==141664== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a935b989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a93c1fd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a93c1e05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a93c1e04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a935b9ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a935affb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a935afa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a935b90c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a938b5ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a938b5ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a938b5ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a938b5ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a938b5ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a938b5ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a938b5ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a938b5ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a938b5ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a938b5ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a93adf4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a937b21b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a937b2cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a9378d8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a9378d8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a9378d9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a9378d8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a9378d8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a9378d8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a93c1e2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a93c1eb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a93c1d3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a93c1fe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e42157082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a935af8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x30,0x27,0x27,0x32,0x31,0x34,0x37,0x34,0x27,0x3d,0x2d,0x37,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x1d,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x5b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $0''21474'=-7'''''/'\0352-=''''''''''''''-=<'''''''''''''''''/''''[\000\000\000\000\000\000\000''''''''''.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-b78988ea3743979d67c936fa5b986a98435a3706 Step #5: Base64: JDAnJzIxNDc0Jz0tNycnJycnLycdMi09JycnJycnJycnJycnJyctPTwnJycnJycnJycnJycnJycnJy8nJycnWwAAAAAAAAAnJycnJycnJycnLicnJycuJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3934 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3672888295 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561fbdd5f810, 0x561fbdf4901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561fbdf49020,0x561fbfde10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b78988ea3743979d67c936fa5b986a98435a3706' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4889 processed earlier; will process 6140 files now Step #5: ==141700== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561fb48549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561fbaeb9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561fbae9c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561fbae9c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561fb485ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561fb47bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561fb47b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561fb484cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561fb781bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561fb781bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561fb781bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561fb781bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561fb781bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561fb781bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561fb781bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561fb781bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561fb781bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561fb781bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561fb9ab0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561fb67ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561fb67e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561fb6594c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561fb6594c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561fb6595738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561fb6594874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561fb6594874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561fb6594874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561fbae9eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561fbaea7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561fbae8f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561fbaeba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9de74ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561fb47b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x30,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x3b,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x3b,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $0-=<'''/''/''''/;''''''2-='''''''''''''.''''.''''''/''''/;''''''2-='''''''''''''.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-b64c261e49532779c59bbc8f0e2487efaff066ca Step #5: Base64: JDAtPTwnJycvJycvJycnJy87JycnJycnMi09JycnJycnJycnJycnJy4nJycnLicnJycnJy8nJycnLzsnJycnJycyLT0nJycnJycnJycnJycnLicnJycuJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3935 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3673399903 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a037101810, 0x55a0372eb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0372eb020,0x55a0391830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b64c261e49532779c59bbc8f0e2487efaff066ca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4890 processed earlier; will process 6139 files now Step #5: ==141736== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a02dbf69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a03425b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a03423e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a03423e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a02dbfcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a02db5db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a02db58355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a02dbeec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a030bbdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a030bbdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a030bbdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a030bbdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a030bbdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a030bbdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a030bbdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a030bbdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a030bbdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a030bbdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a032e52f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a02fb7fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a02fb8abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a02f936c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a02f936c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a02f937738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a02f936874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a02f936874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a02f936874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a034240abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a034249928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a034231699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a03425c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb39ef05082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a02db56b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x12,0x0,0x0,0x0,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x12,0x0,0x0,0x0,0x67,0x72,0x79,0x25,0x73,0x67,0x72,0x79,0x25,0x73,0x7e,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x12,0x49,0x44,0x33,0x4,0x1,0x2e,0x7d,0x41,0xb,0x0,0x55,0x53,0x4c,0x50,0x2e,0x0,0x0,0x0,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x2e,0x7b,0x30,0x7d,0x30,0xff,0x12,0x0,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x72,0x79,0x25,0x29, Step #5: ~~~<\333\276~~~\022\000\000\000~~<\333\276~~~\022\000\000\000gry%sgry%s~~~<\333\276~~~\022ID3\004\001.}A\013\000USLP.\000\000\000~~<\333\276~~~.{0}0\377\022\000\377\377\377\377\377\377\377\377ry%) Step #5: artifact_prefix='./'; Test unit written to ./oom-5ae5dbe834de0fd29e88f8f06bbaed212db03169 Step #5: Base64: fn5+PNu+fn5+EgAAAH5+PNu+fn5+EgAAAGdyeSVzZ3J5JXN+fn48275+fn4SSUQzBAEufUELAFVTTFAuAAAAfn48275+fn4uezB9MP8SAP//////////cnklKQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3936 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3673905792 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a06d5d1810, 0x55a06d7bb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a06d7bb020,0x55a06f6530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ae5dbe834de0fd29e88f8f06bbaed212db03169' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4891 processed earlier; will process 6138 files now Step #5: ==141772== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0640c69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a06a72b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a06a70e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a06a70e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0640ccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a06402db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a064028355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0640bec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a06708df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a06708df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a06708df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a06708df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a06708df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a06708df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a06708df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a06708df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a06708df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a06708df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a069322f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a06604fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a06605abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a065e06c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a065e06c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a065e07738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a065e06874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a065e06874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a065e06874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a06a710abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a06a719928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a06a701699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a06a72c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0cb27d6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a064026b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x1,0x69,0x3a,0x3f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xef,0xbe,0x9f,0xef,0xbe,0x9f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xef,0xbe,0x9f,0xef,0xbe,0x9f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2e,0xf0,0x90,0x90,0x80,0xf0,0x90,0x8d,0x80, Step #5: \000\001i:?\000\000\000\000\000\000\000\000\000\000\000\000\000\004\000\000\000\000\000\000\000\000\000\000\000\000\004\000\000\000\000\000\000\000\000\000\000\357\276\237\357\276\237\000\000\000\000\000\000\000\000\000\000\357\276\237\357\276\237\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000.\360\220\220\200\360\220\215\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-03037687a6866d2daaff6d9922c6bf23bc998923 Step #5: Base64: AAFpOj8AAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAQAAAAAAAAAAAAA776f776fAAAAAAAAAAAAAO++n+++nwAAAAAAAAAAAAAAAAAAAAAAAC7wkJCA8JCNgA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3937 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3674410762 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56337da64810, 0x56337dc4e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56337dc4e020,0x56337fae60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03037687a6866d2daaff6d9922c6bf23bc998923' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4892 processed earlier; will process 6137 files now Step #5: ==141808== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5633745599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56337abbe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56337aba15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56337aba14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56337455fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5633744c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5633744bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563374551c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563377520f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563377520f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563377520f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563377520f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563377520f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563377520f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563377520f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563377520f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563377520f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563377520f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5633797b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5633764e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5633764edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563376299c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563376299c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56337629a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563376299874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563376299874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563376299874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56337aba3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56337abac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56337ab94699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56337abbf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdfbb33a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5633744b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xce,0x90,0xd9,0x8c,0xe0,0xb7,0xa1,0x30,0x4c,0x33,0x33,0xe2,0x90,0x92,0xe2,0x80,0x8c,0xe0,0xaa,0x85,0xe2,0x80,0x8c,0xe0,0xb7,0x95,0x31,0x54,0x58,0x44,0xe2,0x80,0x9f,0x5b,0x35,0x36,0xe2,0x80,0x8c,0xe1,0x82,0x8d,0xef,0xb8,0x8f,0x7b,0x7b,0x7b,0x7b,0xe2,0x80,0x9f,0x5b,0x35,0x36,0xe2,0x80,0x8c,0xe1,0x82,0x8d,0xef,0xb8,0x8f,0xd9,0x90,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text>\316\220\331\214\340\267\2410L33\342\220\222\342\200\214\340\252\205\342\200\214\340\267\2251TXD\342\200\237[56\342\200\214\341\202\215\357\270\217{{{{\342\200\237[56\342\200\214\341\202\215\357\270\217\331\220'</text></svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-261b99925bceccb30d382da24e38842836083501 Step #5: Base64: PHN2Zz48dGV4dD7OkNmM4LehMEwzM+KQkuKAjOCqheKAjOC3lTFUWETigJ9bNTbigIzhgo3vuI97e3t74oCfWzU24oCM4YKN77iP2ZAnPC90ZXh0Pjwvc3ZnPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3938 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3674917677 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557135878810, 0x557135a6201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557135a62020,0x5571378fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/261b99925bceccb30d382da24e38842836083501' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4893 processed earlier; will process 6136 files now Step #5: ==141844== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55712c36d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571329d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571329b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571329b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55712c373d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55712c2d4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55712c2cf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55712c365c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55712f334f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55712f334f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55712f334f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55712f334f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55712f334f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55712f334f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55712f334f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55712f334f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55712f334f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55712f334f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571315c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55712e2f6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55712e301be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55712e0adc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55712e0adc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55712e0ae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55712e0ad874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55712e0ad874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55712e0ad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571329b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571329c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571329a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571329d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f174665c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55712c2cdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x17,0x17,0x17,0x17,0x17,0x17,0x44,0x65,0x6e,0xe2,0x81,0x9f,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa0,0x8e,0x3c,0x20,0x17,0x17,0x17,0x17,0x17,0x44,0x65,0x6e,0xe2,0x81,0x9f,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa0,0x8e,0x3c,0x20,0x7f,0x7f,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x81,0xae,0x0,0x64,0x64,0x64,0xb5,0xf3,0xa0,0x81,0x87,0x7f,0x7f,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x81,0xae,0x0,0x64,0x64,0x64,0xb5,0xf3,0xa0,0x81,0x87,0x64,0x64, Step #5: \341\240\216= \177\027\027\027\027\027\027Den\342\201\237(\342\200\254\000\341\240\216< \027\027\027\027\027Den\342\201\237(\342\200\254\000\341\240\216< \177\177\342\200\215\000\000(\342\201\256\000ddd\265\363\240\201\207\177\177\342\200\215\000\000(\342\201\256\000ddd\265\363\240\201\207dd Step #5: artifact_prefix='./'; Test unit written to ./oom-62bd73a91f419e499219811b9210fe21bd91cdd6 Step #5: Base64: 4aCOPSB/FxcXFxcXRGVu4oGfKOKArADhoI48IBcXFxcXRGVu4oGfKOKArADhoI48IH9/4oCNAAAo4oGuAGRkZLXzoIGHf3/igI0AACjiga4AZGRktfOggYdkZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3939 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3675427714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5555d793c810, 0x5555d7b2601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5555d7b26020,0x5555d99be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/62bd73a91f419e499219811b9210fe21bd91cdd6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4894 processed earlier; will process 6135 files now Step #5: ==141880== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5555ce4319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5555d4a96898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5555d4a795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5555d4a794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5555ce437d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5555ce398b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5555ce393355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5555ce429c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5555d13f8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5555d13f8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5555d13f8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5555d13f8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5555d13f8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5555d13f8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5555d13f8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5555d13f8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5555d13f8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5555d13f8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5555d368df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5555d03bab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5555d03c5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5555d0171c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5555d0171c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5555d0172738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5555d0171874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5555d0171874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5555d0171874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5555d4a7babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5555d4a84928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5555d4a6c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5555d4a97112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb43137082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5555ce391b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x37,0x3a,0x5b,0x22,0xc3,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0x9f,0xbf,0xef,0xbf,0xbf,0x51,0xef,0xbf,0x83,0xd9,0xbf,0xef,0xbf,0xb7,0xef,0xbf,0xbf,0xef,0x98,0xbf,0xdf,0xaf,0xdf,0xbf,0xdf,0xaf,0xc2,0x8d,0xef,0xbf,0xae,0x3b,0xdf,0xbf,0xdf,0xaf,0xdf,0xbf,0xd0,0xaf,0xba,0xef,0x81,0xa3,0x3b,0xc5,0x36,0x34,0x30,0x22,0x5d,0x7d,0x27,0xc3,0xff,0xff,0xff,0xff,0xef,0xff,0xff,0xff,0xff,0xff,0xfe,0xff,0xff,0x27,0x3a,0x3a,0x44,0x45, Step #5: $3::{$7:[\"\303\277\357\277\277\357\277\277\357\237\277\357\277\277Q\357\277\203\331\277\357\277\267\357\277\277\357\230\277\337\257\337\277\337\257\302\215\357\277\256;\337\277\337\257\337\277\320\257\272\357\201\243;\305640\"]}'\303\377\377\377\377\357\377\377\377\377\377\376\377\377'::DE Step #5: artifact_prefix='./'; Test unit written to ./oom-72a0aebaad6a24419f91d11485d4bec236eb71c8 Step #5: Base64: JDM6OnskNzpbIsO/77+/77+/75+/77+/Ue+/g9m/77+377+/75i/36/fv9+vwo3vv64737/fr9+/0K+674GjO8U2NDAiXX0nw//////v///////+//8nOjpERQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3940 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3675941636 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563beea2a810, 0x563beec1401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563beec14020,0x563bf0aac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/72a0aebaad6a24419f91d11485d4bec236eb71c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4895 processed earlier; will process 6134 files now Step #5: ==141916== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563be551f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563bebb84898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563bebb675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563bebb674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563be5525d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563be5486b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563be5481355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563be5517c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563be84e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563be84e6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563be84e6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563be84e6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563be84e6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563be84e6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563be84e6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563be84e6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563be84e6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563be84e6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563bea77bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563be74a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563be74b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563be725fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563be725fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563be7260738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563be725f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563be725f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563be725f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563bebb69abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563bebb72928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563bebb5a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563bebb85112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff51b125082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563be547fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x2a,0x2a,0x4e,0x45,0x57,0x46,0x49,0x4c,0x45,0x2a,0x2a,0x2a,0x3a,0x63,0x6d,0x64,0x2e,0x74,0x78,0x74,0xa,0x64,0x72,0x69,0x76,0x65,0x72,0xa,0x70,0x64,0x66,0x0,0x6e,0x2d,0x0,0xa,0x6c,0x69,0x73,0x74,0x2d,0x6c,0x61,0x79,0x65,0x72,0x73,0xa,0x69,0x0,0x6c,0x62,0xa,0x2f,0x76,0x73,0x69,0x63,0x75,0x72,0x6c,0x5f,0x73,0x74,0x72,0x65,0x61,0x6d,0x6d,0x6d,0x6d,0x27,0x6e,0x67,0x2f,0x63,0x6d,0x64,0x2d,0x33,0x32,0x37,0x36,0x38,0xe9,0x63,0x46,0x63,0x2f,0x31, Step #5: ***NEWFILE***:cmd.txt\012driver\012pdf\000n-\000\012list-layers\012i\000lb\012/vsicurl_streammmm'ng/cmd-32768\351cFc/1 Step #5: artifact_prefix='./'; Test unit written to ./oom-558fdf36f8fdbe87dbc00078c7f9cd4a935c8806 Step #5: Base64: KioqTkVXRklMRSoqKjpjbWQudHh0CmRyaXZlcgpwZGYAbi0ACmxpc3QtbGF5ZXJzCmkAbGIKL3ZzaWN1cmxfc3RyZWFtbW1tJ25nL2NtZC0zMjc2OOljRmMvMQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3941 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3676449797 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560f9d0f2810, 0x560f9d2dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560f9d2dc020,0x560f9f1740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/558fdf36f8fdbe87dbc00078c7f9cd4a935c8806' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4896 processed earlier; will process 6133 files now Step #5: #1 pulse cov: 3670 ft: 3671 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4526 ft: 4912 exec/s: 0 rss: 177Mb Step #5: ==141952== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560f93be79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560f9a24c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560f9a22f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560f9a22f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560f93bedd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560f93b4eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560f93b49355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560f93bdfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560f96baef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560f96baef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560f96baef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560f96baef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560f96baef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560f96baef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560f96baef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560f96baef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560f96baef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560f96baef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560f98e43f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560f95b70b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560f95b7bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560f95927c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560f95927c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560f95928738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560f95927874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560f95927874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560f95927874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560f9a231abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560f9a23a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560f9a222699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560f9a24d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f98e2146082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560f93b47b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0x5e,0x0,0x0,0x0,0xa,0xa,0x66,0x3d,0x72,0x3d,0x73,0x65,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0xc,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x2d,0x2d,0x3d,0x32,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x6b,0x3,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xff, Step #5: \005-----BEGIN =^\000\000\000\012\012f=r=se\012=+=\012=\012=\012= =\012= i\012\012r=sef\014\012=+=\012=\012=\012=\012D\012=\012=\012=\012\012--=2\002U -E\012\012k\003ip_cl\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-8d4194e630f11cc04f3786874cd7482ef8ee9840 Step #5: Base64: BS0tLS0tQkVHSU4gPV4AAAAKCmY9cj1zZQo9Kz0KPQo9Cj0gPQo9IGkKCnI9c2VmDAo9Kz0KPQo9Cj0KRAo9Cj0KPQoKLS09MgJVIC1FCgprA2lwX2NsCnwAEP8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3942 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3677043315 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56310f457810, 0x56310f64101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56310f641020,0x5631114d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d4194e630f11cc04f3786874cd7482ef8ee9840' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4899 processed earlier; will process 6130 files now Step #5: ==141988== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563105f4c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56310c5b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56310c5945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56310c5944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563105f52d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563105eb3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563105eae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563105f44c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563108f13f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563108f13f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563108f13f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563108f13f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563108f13f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563108f13f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563108f13f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563108f13f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563108f13f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563108f13f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56310b1a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563107ed5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563107ee0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563107c8cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563107c8cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563107c8d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563107c8c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563107c8c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563107c8c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56310c596abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56310c59f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56310c587699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56310c5b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc2b2ba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563105eacb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xb,0x2f,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x27,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x35,0x2d,0xa,0x2f,0x2f,0x33,0x32,0x37,0x37,0x36,0x27,0x2d,0x37,0x30,0xf3,0xa0,0x80,0xa2,0x39,0x32,0x32,0x36,0x33,0x32,0x37,0x37,0x36,0x27,0x2d,0x37,0x30,0xf3,0xa0,0x80,0xa2,0x39,0x32,0x32,0x36,0x32,0x38,0x35,0x31,0x86,0x37,0x7c,0x0,0x0,0x0,0x35,0x37,0x35,0x36,0x36,0x37,0x36,0x38,0x31,0xf3,0xa0,0x80,0xa2,0x37,0xa,0x2d,0xa,0x2f,0x2f,0xa, Step #5: -\013/777777777'77777777775-\012//32776'-70\363\240\200\242922632776'-70\363\240\200\24292262851\2067|\000\000\000575667681\363\240\200\2427\012-\012//\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-f9f0419057bfcf1cef7ed27e0cc495cea9a2d8b3 Step #5: Base64: LQsvNzc3Nzc3Nzc3Jzc3Nzc3Nzc3Nzc1LQovLzMyNzc2Jy03MPOggKI5MjI2MzI3NzYnLTcw86CAojkyMjYyODUxhjd8AAAANTc1NjY3Njgx86CAojcKLQovLwo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3943 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3677551538 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562748385810, 0x56274856f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56274856f020,0x56274a4070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9f0419057bfcf1cef7ed27e0cc495cea9a2d8b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4900 processed earlier; will process 6129 files now Step #5: ==142024== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56273ee7a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5627454df898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5627454c25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5627454c24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56273ee80d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56273ede1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56273eddc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56273ee72c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562741e41f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562741e41f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562741e41f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562741e41f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562741e41f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562741e41f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562741e41f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562741e41f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562741e41f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562741e41f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5627440d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562740e03b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562740e0ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562740bbac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562740bbac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562740bbb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562740bba874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562740bba874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562740bba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5627454c4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5627454cd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5627454b5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5627454e0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc5c63fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56273eddab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x3,0x0,0x0,0x45,0x30,0x50,0x55,0x53,0x4c,0x54,0x0,0x0,0x20,0x0,0x71,0x70,0x78,0x60,0x74,0x6d,0x21,0x60,0x32,0x50,0x55,0x53,0x1,0x6,0x54,0x0,0x0,0x0,0x5,0x20,0x0,0x0,0x20,0x47,0x45,0x30,0x50,0x32,0x50,0x55,0x53,0x4c,0x32,0x54,0x0,0x0,0x0,0x5,0x20,0x0,0x0,0x20,0x47,0x45,0x30,0x50,0x53,0x4c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x0,0x26,0xa,0x26,0x24,0x0,0x14,0xa, Step #5: \000\003\000\000E0PUSLT\000\000 \000qpx`tm!`2PUS\001\006T\000\000\000\005 \000\000 GE0P2PUSL2T\000\000\000\005 \000\000 GE0PSL\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000$\000&\012&$\000\024\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-c7e9c8d15149d7eac3c4760d4ca7504ec5e8cf26 Step #5: Base64: AAMAAEUwUFVTTFQAACAAcXB4YHRtIWAyUFVTAQZUAAAABSAAACBHRTBQMlBVU0wyVAAAAAUgAAAgR0UwUFNMAAAAAAAAAAAAAAAAAAAAAAAAAAAkACYKJiQAFAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3944 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3678185980 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f330fb0810, 0x55f33119a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f33119a020,0x55f3330320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c7e9c8d15149d7eac3c4760d4ca7504ec5e8cf26' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4901 processed earlier; will process 6128 files now Step #5: #1 pulse cov: 4166 ft: 4167 exec/s: 0 rss: 174Mb Step #5: ==142060== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f327aa59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f32e10a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f32e0ed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f32e0ed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f327aabd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f327a0cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f327a07355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f327a9dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f32aa6cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f32aa6cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f32aa6cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f32aa6cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f32aa6cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f32aa6cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f32aa6cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f32aa6cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f32aa6cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f32aa6cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f32cd01f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f329a2eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f329a39be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f3297e5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f3297e5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f3297e6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f3297e5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f3297e5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f3297e5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f32e0efabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f32e0f8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f32e0e0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f32e10b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6eb147d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f327a05b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0x7e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x2d,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x7e,0x12,0x0,0x0,0x0,0x7e,0x7e,0x3f,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x12,0x0,0x0,0x0,0x67,0x72,0x78,0x68,0x74,0x68,0x72,0x79,0x25,0x73, Step #5: ~~~<\333\276~~\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036-\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036~\022\000\000\000~~?<\333\276~~~\022\000\000\000grxhthry%s Step #5: artifact_prefix='./'; Test unit written to ./oom-9c0fe330f1b021ef1738959200b3724c1d937677 Step #5: Base64: fn5+PNu+fn4eHh4eHh4eHh4eHh4eHh4eHi0eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHn4SAAAAfn4/PNu+fn5+EgAAAGdyeGh0aHJ5JXM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3945 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3678741267 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56248f7a7810, 0x56248f99101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56248f991020,0x5624918290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c0fe330f1b021ef1738959200b3724c1d937677' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4903 processed earlier; will process 6126 files now Step #5: ==142096== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56248629c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56248c901898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56248c8e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56248c8e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5624862a2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562486203b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5624861fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562486294c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562489263f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562489263f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562489263f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562489263f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562489263f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562489263f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562489263f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562489263f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562489263f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562489263f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56248b4f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562488225b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562488230be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562487fdcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562487fdcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562487fdd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562487fdc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562487fdc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562487fdc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56248c8e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56248c8ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56248c8d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56248c902112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3294c7b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5624861fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x8,0x22,0x1b,0x0,0x22,0x51,0x72,0xef,0xbf,0xbd,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x69,0x6e,0x61,0x74,0x65,0x6d,0x65,0x6e,0x74,0x2f,0x76,0x30,0x2e,0x31,0x61,0x61,0x2c,0x5b,0x5d,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x5c,0x22, Step #5: \000\000\000\000\010\"\033\000\"Qr\357\277\275https://inatement/v0.1aa,[]aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\\\" Step #5: artifact_prefix='./'; Test unit written to ./oom-106a6ec50da6fcc5b54e602c6ddb78ef9bcda252 Step #5: Base64: AAAAAAgiGwAiUXLvv71odHRwczovL2luYXRlbWVudC92MC4xYWEsW11hYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhXCI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3946 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3679246423 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559108cc2810, 0x559108eac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559108eac020,0x55910ad440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/106a6ec50da6fcc5b54e602c6ddb78ef9bcda252' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4904 processed earlier; will process 6125 files now Step #5: ==142132== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5590ff7b79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559105e1c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559105dff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559105dff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5590ff7bdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5590ff71eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5590ff719355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5590ff7afc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55910277ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55910277ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55910277ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55910277ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55910277ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55910277ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55910277ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55910277ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55910277ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55910277ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559104a13f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559101740b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55910174bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5591014f7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5591014f7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5591014f8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5591014f7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5591014f7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5591014f7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559105e01abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559105e0a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559105df2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559105e1d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7088821082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5590ff717b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xd,0x60,0x2e,0x6d,0x61,0x74,0x63,0x68,0x24,0x60,0xd,0x60,0x2e,0x6d,0x24,0x24,0x60,0xd,0x60,0x2e,0x6d,0x24,0x24,0x60,0xd,0x60,0x2e,0x6d,0x61,0x74,0x24,0x60,0x3b,0x60,0x2e,0x6d,0x24,0x24,0x60,0xd,0x60,0x2e,0x6d,0x61,0x74,0x24,0x24,0x24,0x61,0x24,0x24,0x60,0xd,0x60,0x2e,0x6d,0x61,0x74,0x24,0x24,0x24,0x61,0x24,0x24,0x60,0xd,0x60,0x2e,0x6d,0x61,0x74,0x24,0x60,0x3b,0x60,0x2e,0x6d,0x24,0x24,0x60,0xd,0x60,0x2e,0x6d,0x61,0x74,0x24,0x24,0x24,0x61,0x74, Step #5: `\015`.match$`\015`.m$$`\015`.m$$`\015`.mat$`;`.m$$`\015`.mat$$$a$$`\015`.mat$$$a$$`\015`.mat$`;`.m$$`\015`.mat$$$at Step #5: artifact_prefix='./'; Test unit written to ./oom-58214c89e969e213b3d0eadca4037ac2bb0454f1 Step #5: Base64: YA1gLm1hdGNoJGANYC5tJCRgDWAubSQkYA1gLm1hdCRgO2AubSQkYA1gLm1hdCQkJGEkJGANYC5tYXQkJCRhJCRgDWAubWF0JGA7YC5tJCRgDWAubWF0JCQkYXQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3947 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3679885941 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55abd7f44810, 0x55abd812e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55abd812e020,0x55abd9fc60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58214c89e969e213b3d0eadca4037ac2bb0454f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4905 processed earlier; will process 6124 files now Step #5: ==142168== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55abcea399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55abd509e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55abd50815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55abd50814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55abcea3fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55abce9a0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55abce99b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55abcea31c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55abd1a00f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55abd1a00f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55abd1a00f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55abd1a00f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55abd1a00f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55abd1a00f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55abd1a00f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55abd1a00f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55abd1a00f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55abd1a00f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55abd3c95f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55abd09c2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55abd09cdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55abd0779c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55abd0779c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55abd077a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55abd0779874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55abd0779874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55abd0779874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55abd5083abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55abd508c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55abd5074699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55abd509f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd91df88082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55abce999b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x71,0x42,0x76,0x50,0x31,0x57,0x70,0x33,0x66,0x50,0x44,0x62,0x6a,0x4d,0x5a,0x50,0x67,0x31,0x68,0x66,0x31,0x36,0x54,0x54,0x52,0x4f,0x4f,0x32,0x59,0x78,0x30,0x4a,0x76,0x31,0x74,0x2f,0x59,0x2b,0x46,0x53,0x77,0x37,0x32,0xa,0x61,0x20,0x3a,0x2e,0x2f,0xa,0x61,0x20,0x3a,0x2e,0x2f,0xa,0x61,0x20,0x3a,0x2e,0x2f,0xa,0x61,0x20,0x3a,0x2e,0x2f, Step #5: onion-key\012ntor-onion-key qBvP1Wp3fPDbjMZPg1hf16TTROO2Yx0Jv1t/Y+FSw72\012a :./\012a :./\012a :./\012a :./ Step #5: artifact_prefix='./'; Test unit written to ./oom-eeece91764ec95b561399e188d79fef5d4aec853 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHFCdlAxV3AzZlBEYmpNWlBnMWhmMTZUVFJPTzJZeDBKdjF0L1krRlN3NzIKYSA6Li8KYSA6Li8KYSA6Li8KYSA6Li8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3948 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3680398549 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e596212810, 0x55e5963fc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e5963fc020,0x55e5982940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eeece91764ec95b561399e188d79fef5d4aec853' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4906 processed earlier; will process 6123 files now Step #5: ==142204== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e58cd079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e59336c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e59334f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e59334f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e58cd0dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e58cc6eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e58cc69355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e58ccffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e58fccef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e58fccef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e58fccef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e58fccef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e58fccef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e58fccef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e58fccef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e58fccef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e58fccef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e58fccef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e591f63f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e58ec90b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e58ec9bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e58ea47c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e58ea47c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e58ea48738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e58ea47874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e58ea47874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e58ea47874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e593351abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e59335a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e593342699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e59336d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e6b5ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e58cc67b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x20,0x5,0x5,0x5,0x9,0xe,0xe,0xe,0xe,0xe,0xe,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0x30,0x37,0x72,0x24,0x7b,0x7d,0x20,0x7d,0x7c,0x67,0x60,0x2d,0x60,0x3b,0x5,0x28,0x29,0x2e,0x31,0x9,0x1e,0xe,0x72,0x0,0x0,0x0,0x0,0x0,0x14,0x0,0x0,0x0,0x0,0x9,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0x37,0x72,0x7e,0x24,0x7b,0x7d,0x20,0x7d,0x7c,0x67,0x60,0x0,0x5b, Step #5: ` \005\005\005\011\016\016\016\016\016\016\004\000\000\000\000\000\000\000\000\000\000\016\016\016\016\016\016\016\016\016\016\016\016\016\01607r${} }|g`-`;\005().1\011\036\016r\000\000\000\000\000\024\000\000\000\000\011\016\016\016\016\016\016\016\0167r~${} }|g`\000[ Step #5: artifact_prefix='./'; Test unit written to ./oom-3b2f1d2b79bb8e945f242e7ac61e681a0d8b59d4 Step #5: Base64: YCAFBQUJDg4ODg4OBAAAAAAAAAAAAAAODg4ODg4ODg4ODg4ODjA3ciR7fSB9fGdgLWA7BSgpLjEJHg5yAAAAAAAUAAAAAAkODg4ODg4ODjdyfiR7fSB9fGdgAFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3949 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3681023010 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c7ce1e2810, 0x55c7ce3cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c7ce3cc020,0x55c7d02640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3b2f1d2b79bb8e945f242e7ac61e681a0d8b59d4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4907 processed earlier; will process 6122 files now Step #5: ==142240== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c7c4cd79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7cb33c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7cb31f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7cb31f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c7c4cddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c7c4c3eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c7c4c39355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7c4ccfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7c7c9ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7c7c9ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7c7c9ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7c7c9ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7c7c9ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7c7c9ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7c7c9ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7c7c9ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7c7c9ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7c7c9ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7c9f33f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7c6c60b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7c6c6bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7c6a17c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7c6a17c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7c6a18738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7c6a17874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7c6a17874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7c6a17874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7cb321abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7cb32a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c7cb312699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7cb33d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8093815082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c7c4c37b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x4d,0x61,0x72,0x73,0x68,0x2d,0x4d,0x61,0x72,0x73,0x42,0x69,0x6e,0x61,0x31,0x2e,0x32,0x65,0x2b,0x33,0x74,0x79,0x44,0x70,0x65,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x69,0x6e,0x2d,0x74,0x6f,0x2f,0x76,0x74,0x0,0x0,0x0,0x0,0x0,0x0,0x3c,0x27,0x2b,0x22,0x63,0x6c,0x69,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x55,0x0,0x6e,0x69,0x2d,0x74,0x6f,0x2f,0x76,0x74,0x0,0x0,0x0,0x0,0x0,0x0,0x3c,0x27,0x2b,0x22,0x63,0x6c,0x69,0x69,0x69,0x74,0x1, Step #5: \000\000\000Marsh-MarsBina1.2e+3tyDpehttps://in-to/vt\000\000\000\000\000\000<'+\"clihttps://U\000ni-to/vt\000\000\000\000\000\000<'+\"cliiit\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-ea800cb6f2013c672aef58dafff7121182186717 Step #5: Base64: AAAATWFyc2gtTWFyc0JpbmExLjJlKzN0eURwZWh0dHBzOi8vaW4tdG8vdnQAAAAAAAA8JysiY2xpaHR0cHM6Ly9VAG5pLXRvL3Z0AAAAAAAAPCcrImNsaWlpdAE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3950 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3681528533 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9312c1810, 0x55e9314ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9314ab020,0x55e9333430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ea800cb6f2013c672aef58dafff7121182186717' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4908 processed earlier; will process 6121 files now Step #5: ==142276== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e927db69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e92e41b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e92e3fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e92e3fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e927dbcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e927d1db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e927d18355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e927daec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e92ad7df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e92ad7df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e92ad7df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e92ad7df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e92ad7df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e92ad7df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e92ad7df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e92ad7df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e92ad7df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e92ad7df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e92d012f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e929d3fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e929d4abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e929af6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e929af6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e929af7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e929af6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e929af6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e929af6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e92e400abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e92e409928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e92e3f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e92e41c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa27c8ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e927d16b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x4f,0x3a,0x31,0x32,0x3a,0x22,0x44,0x41,0x54,0x65,0x49,0x6e,0x74,0x65,0x72,0x76,0x41,0x6c,0x22,0x3a,0x31,0x3a,0x7b,0x73,0x3a,0x31,0x31,0x3a,0x22,0x64,0x61,0x74,0x65,0x5f,0x73,0x74,0x72,0x69,0x6e,0x67,0x22,0x3b,0x73,0x3a,0x34,0x31,0x3a,0x22,0x60,0x20,0x31,0x33,0x22,0x56,0x20,0x31,0x8,0x56,0x49,0x29,0x60,0x20,0x31,0x33,0x22,0x56,0x20,0x31,0x8,0x56,0x49,0x29,0x54,0x9,0x2e,0x56,0x39,0x39,0x38,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x3b,0x36,0x22,0x3b, Step #5: |O:12:\"DATeIntervAl\":1:{s:11:\"date_string\";s:41:\"` 13\"V 1\010VI)` 13\"V 1\010VI)T\011.V99899999999;6\"; Step #5: artifact_prefix='./'; Test unit written to ./oom-93415d0582d2feab2fe7e9631bf2b10c039c8c56 Step #5: Base64: fE86MTI6IkRBVGVJbnRlcnZBbCI6MTp7czoxMToiZGF0ZV9zdHJpbmciO3M6NDE6ImAgMTMiViAxCFZJKWAgMTMiViAxCFZJKVQJLlY5OTg5OTk5OTk5OTs2Ijs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3951 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3682155215 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e2fa03f810, 0x55e2fa22901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e2fa229020,0x55e2fc0c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93415d0582d2feab2fe7e9631bf2b10c039c8c56' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4909 processed earlier; will process 6120 files now Step #5: ==142312== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e2f0b349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e2f7199898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e2f717c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e2f717c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e2f0b3ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e2f0a9bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e2f0a96355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e2f0b2cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e2f3afbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e2f3afbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e2f3afbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e2f3afbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e2f3afbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e2f3afbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e2f3afbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e2f3afbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e2f3afbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e2f3afbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e2f5d90f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e2f2abdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e2f2ac8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e2f2874c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e2f2874c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e2f2875738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e2f2874874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e2f2874874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e2f2874874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e2f717eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e2f7187928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e2f716f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e2f719a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67374d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e2f0a94b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x1,0x21,0x0,0x2a,0x64,0x65,0x63,0x6c,0x61,0x72,0x65,0x20,0x65,0x72,0x72,0x6f,0x72,0x3a,0x41,0x74,0x4,0x65,0x74,0x3c,0x72,0x3e,0x2e,0x70,0x0,0x0,0x0,0x22,0x6c,0x61,0x72,0x65,0x20,0x65,0x72,0x72,0x6f,0x72,0x3a,0x41,0x74,0x4,0x65,0x74,0x20,0x65,0x72,0x72,0x6f,0x72,0x3a,0x41,0x74,0x4,0x65,0x74,0x3c,0x72,0x3e,0x2e,0x70,0x0,0x0,0x0,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x2a,0x3b,0x3e,0x0,0x20,0x0,0x1,0xc2,0xb,0x0,0x0,0x0, Step #5: p\001!\000*declare error:At\004et<r>.p\000\000\000\"lare error:At\004et error:At\004et<r>.p\000\000\000\"\"\"\"\"\"\"\"\"\"\"*;>\000 \000\001\302\013\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-34b2dc09bb5a9381e01dee8becc540ade2331b65 Step #5: Base64: cAEhACpkZWNsYXJlIGVycm9yOkF0BGV0PHI+LnAAAAAibGFyZSBlcnJvcjpBdARldCBlcnJvcjpBdARldDxyPi5wAAAAIiIiIiIiIiIiIiIqOz4AIAABwgsAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3952 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3682664771 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bca86d8810, 0x55bca88c201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bca88c2020,0x55bcaa75a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/34b2dc09bb5a9381e01dee8becc540ade2331b65' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4910 processed earlier; will process 6119 files now Step #5: ==142348== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bc9f1cd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bca5832898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bca58155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bca58154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bc9f1d3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bc9f134b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bc9f12f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bc9f1c5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bca2194f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bca2194f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bca2194f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bca2194f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bca2194f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bca2194f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bca2194f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bca2194f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bca2194f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bca2194f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bca4429f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bca1156b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bca1161be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bca0f0dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bca0f0dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bca0f0e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bca0f0d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bca0f0d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bca0f0d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bca5817abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bca5820928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bca5808699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bca5833112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f71419c0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bc9f12db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60, Step #5: `\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012``\012```\012`` Step #5: artifact_prefix='./'; Test unit written to ./oom-42fbe95fd9a940ee02651d5c82bde33b7d9bd91e Step #5: Base64: YApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYApgYGAKYGA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3953 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3683314118 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55742de33810, 0x55742e01d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55742e01d020,0x55742feb50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/42fbe95fd9a940ee02651d5c82bde33b7d9bd91e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4911 processed earlier; will process 6118 files now Step #5: ==142384== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5574249289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55742af8d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55742af705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55742af704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55742492ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55742488fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55742488a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557424920c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5574278eff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5574278eff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5574278eff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5574278eff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5574278eff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5574278eff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5574278eff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5574278eff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5574278eff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5574278eff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557429b84f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5574268b1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5574268bcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557426668c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557426668c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557426669738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557426668874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557426668874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557426668874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55742af72abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55742af7b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55742af63699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55742af8e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2718f77082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557424888b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x6c,0x69,0x6e,0x65,0x61,0x72,0x47,0x72,0x61,0x64,0x69,0x65,0x6e,0x74,0x3e,0x3c,0x73,0x74,0x6f,0x70,0x3e,0x3c,0x73,0x74,0x6f,0x61,0x64,0x69,0x65,0x6e,0x74,0x3e,0x3c,0x6c,0x69,0x6e,0x65,0x61,0x72,0x47,0x72,0x61,0x64,0x69,0x65,0x6e,0x74,0x3e,0x3c,0x6c,0x69,0x6e,0x65,0x61,0x72,0x47,0x72,0x61,0x64,0x69,0x65,0x6e,0x74,0x3e,0x46,0x7b,0x66,0x6f,0x6e,0x74,0x2d,0x66,0x62,0x6d,0x69,0x3c,0x73,0x74,0x6f,0x70,0x3e,0x3c,0x73,0x74,0x6f,0x70,0x3e, Step #5: <svg><linearGradient><stop><stoadient><linearGradient><linearGradient>F{font-fbmi<stop><stop> Step #5: artifact_prefix='./'; Test unit written to ./oom-ff47dd9f64f7550158197caf36aac219d2f58628 Step #5: Base64: PHN2Zz48bGluZWFyR3JhZGllbnQ+PHN0b3A+PHN0b2FkaWVudD48bGluZWFyR3JhZGllbnQ+PGxpbmVhckdyYWRpZW50PkZ7Zm9udC1mYm1pPHN0b3A+PHN0b3A+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3954 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3683816578 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e90887a810, 0x55e908a6401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e908a64020,0x55e90a8fc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ff47dd9f64f7550158197caf36aac219d2f58628' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4912 processed earlier; will process 6117 files now Step #5: ==142420== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e8ff36f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9059d4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9059b75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9059b74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e8ff375d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e8ff2d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e8ff2d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e8ff367c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e902336f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e902336f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e902336f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e902336f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e902336f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e902336f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e902336f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e902336f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e902336f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e902336f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9045cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e9012f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e901303be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9010afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9010afc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9010b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9010af874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9010af874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9010af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e9059b9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9059c2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e9059aa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e9059d5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f207fade082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e8ff2cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe7,0x9f,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x89,0x21,0xed,0x8d,0xaa,0xe9,0x8d,0xaa,0xed,0x99,0xaa,0xec,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xec,0x8d,0xaa,0xed,0x8d,0xaa,0xec,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x89,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x89,0xaa,0xec,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0x5b,0x2d,0x2d,0xa,0x44,0xa,0x2d,0xa,0x49,0x74,0x68,0x8d,0xaa, Step #5: \347\237\252\355\215\252\355\215\252\355\211!\355\215\252\351\215\252\355\231\252\354\215\252\355\215\252\355\215\252\355\215\252\355\215\252\354\215\252\355\215\252\354\215\252\355\215\252\355\215\252\355\215\252\355\211\252\355\215\252\355\215\252\355\211\252\354\215\252\355\215\252\355\215\252\355\215\252\355\215[--\012D\012-\012Ith\215\252 Step #5: artifact_prefix='./'; Test unit written to ./oom-1d72a77679afea782fc7be6cbee2d49969fb2d93 Step #5: Base64: 55+q7Y2q7Y2q7Ykh7Y2q6Y2q7Zmq7I2q7Y2q7Y2q7Y2q7Y2q7I2q7Y2q7I2q7Y2q7Y2q7Y2q7Ymq7Y2q7Y2q7Ymq7I2q7Y2q7Y2q7Y2q7Y1bLS0KRAotCkl0aI2q Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3955 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3684325748 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5578df071810, 0x5578df25b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5578df25b020,0x5578e10f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1d72a77679afea782fc7be6cbee2d49969fb2d93' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4913 processed earlier; will process 6116 files now Step #5: ==142456== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5578d5b669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5578dc1cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5578dc1ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5578dc1ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5578d5b6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5578d5acdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5578d5ac8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5578d5b5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5578d8b2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5578d8b2df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5578d8b2df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5578d8b2df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5578d8b2df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5578d8b2df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5578d8b2df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5578d8b2df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5578d8b2df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5578d8b2df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5578dadc2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5578d7aefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5578d7afabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5578d78a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5578d78a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5578d78a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5578d78a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5578d78a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5578d78a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5578dc1b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5578dc1b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5578dc1a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5578dc1cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe5d9bb0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5578d5ac6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x65,0x2d,0x6d,0x3d,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $22''2-=''''''/''2-=''''''''''''''-=<'''''''''''''e-m='/''''/''''''2-='''''''''''''.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-100d28139ea1699e999f05851fd70e4ea784558f Step #5: Base64: JDIyJycyLT0nJycnJycvJycyLT0nJycnJycnJycnJycnJy09PCcnJycnJycnJycnJydlLW09Jy8nJycnLycnJycnJzItPScnJycnJycnJycnJycuJycnJy4nJCct Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3956 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3684847001 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56065c895810, 0x56065ca7f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56065ca7f020,0x56065e9170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/100d28139ea1699e999f05851fd70e4ea784558f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4914 processed earlier; will process 6115 files now Step #5: ==142492== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56065338a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5606599ef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606599d25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606599d24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560653390d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5606532f1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5606532ec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560653382c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560656351f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560656351f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560656351f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560656351f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560656351f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560656351f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560656351f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560656351f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560656351f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560656351f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606585e6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560655313b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56065531ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5606550cac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5606550cac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5606550cb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5606550ca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5606550ca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5606550ca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5606599d4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5606599dd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5606599c5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5606599f0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a11448082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5606532eab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x59,0x41,0x52,0x47,0x20,0xe2,0x86,0x8d,0x5b,0x31,0x32,0x39,0xe2,0x80,0xbc,0xe1,0x82,0x8d,0xef,0xb8,0x8f,0xd9,0x90,0xd9,0x90,0xd9,0x90,0xd9,0x91,0x20,0xe2,0x86,0x8d,0x5b,0x31,0x32,0x39,0xe2,0x80,0xbc,0xe1,0x82,0x8d,0xef,0xb8,0x8f,0xd9,0x90,0xe2,0x86,0x8d,0x5b,0x31,0x35,0x31,0x36,0x34,0xe2,0x80,0xbc,0xe1,0x82,0x8d,0xef,0xb8,0x8f,0xd9,0x90,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text>YARG \342\206\215[129\342\200\274\341\202\215\357\270\217\331\220\331\220\331\220\331\221 \342\206\215[129\342\200\274\341\202\215\357\270\217\331\220\342\206\215[15164\342\200\274\341\202\215\357\270\217\331\220'</text></svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-e3eb6c2feee9db1fa00fcfe5bbb2b014078cbb35 Step #5: Base64: PHN2Zz48dGV4dD5ZQVJHIOKGjVsxMjnigLzhgo3vuI/ZkNmQ2ZDZkSDiho1bMTI54oC84YKN77iP2ZDiho1bMTUxNjTigLzhgo3vuI/ZkCc8L3RleHQ+PC9zdmc+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3957 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3685360863 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5555b3a15810, 0x5555b3bff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5555b3bff020,0x5555b5a970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e3eb6c2feee9db1fa00fcfe5bbb2b014078cbb35' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4915 processed earlier; will process 6114 files now Step #5: ==142528== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5555aa50a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5555b0b6f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5555b0b525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5555b0b524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5555aa510d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5555aa471b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5555aa46c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5555aa502c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5555ad4d1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5555ad4d1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5555ad4d1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5555ad4d1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5555ad4d1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5555ad4d1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5555ad4d1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5555ad4d1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5555ad4d1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5555ad4d1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5555af766f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5555ac493b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5555ac49ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5555ac24ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5555ac24ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5555ac24b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5555ac24a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5555ac24a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5555ac24a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5555b0b54abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5555b0b5d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5555b0b45699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5555b0b70112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3f57e79082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5555aa46ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe7,0x9f,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x89,0xaa,0xed,0x8d,0xaa,0xe9,0x8d,0xaa,0xed,0x99,0xaa,0xec,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xec,0x8d,0xaa,0xed,0x8d,0xaa,0xec,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x89,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x89,0xaa,0xec,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xed,0x8d,0xaa,0xec,0x8d,0xaa,0xed,0x8d,0xaa,0xe5,0x8d,0xa7,0xed,0x8d,0xaa, Step #5: \347\237\252\355\215\252\355\215\252\355\211\252\355\215\252\351\215\252\355\231\252\354\215\252\355\215\252\355\215\252\355\215\252\355\215\252\354\215\252\355\215\252\354\215\252\355\215\252\355\215\252\355\215\252\355\211\252\355\215\252\355\215\252\355\211\252\354\215\252\355\215\252\355\215\252\355\215\252\355\215\252\354\215\252\355\215\252\345\215\247\355\215\252 Step #5: artifact_prefix='./'; Test unit written to ./oom-86b3de1d3757420986fd9739378ad03c8ed58f74 Step #5: Base64: 55+q7Y2q7Y2q7Ymq7Y2q6Y2q7Zmq7I2q7Y2q7Y2q7Y2q7Y2q7I2q7Y2q7I2q7Y2q7Y2q7Y2q7Ymq7Y2q7Y2q7Ymq7I2q7Y2q7Y2q7Y2q7Y2q7I2q7Y2q5Y2n7Y2q Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3958 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3685869525 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0b623f810, 0x55a0b642901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0b6429020,0x55a0b82c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/86b3de1d3757420986fd9739378ad03c8ed58f74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4916 processed earlier; will process 6113 files now Step #5: ==142564== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0acd349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0b3399898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0b337c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0b337c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0acd3ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0acc9bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0acc96355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0acd2cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0afcfbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0afcfbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0afcfbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0afcfbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0afcfbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0afcfbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0afcfbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0afcfbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0afcfbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0afcfbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0b1f90f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0aecbdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0aecc8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0aea74c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0aea74c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0aea75738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0aea74874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0aea74874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0aea74874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0b337eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0b3387928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0b336f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0b339a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1bd7dc9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0acc94b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2f,0xa,0x60,0x60,0x20,0x20,0x20,0x60,0xa,0x9, Step #5: `\000\000\000\000\000\000\000z\000\000\000\000\000\000\000\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000z\000\000\000\000\000\000\000\000\007\000\001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000/\012`` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-c40eb5708649a84c13c780f90b522a57cef1cc19 Step #5: Base64: YAAAAAAAAAB6AAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAB6AAAAAAAAAAAHAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAvCmBgICAgYAoJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3959 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3686492322 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558c2dbbe810, 0x558c2dda801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558c2dda8020,0x558c2fc400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c40eb5708649a84c13c780f90b522a57cef1cc19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4917 processed earlier; will process 6112 files now Step #5: ==142600== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558c246b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558c2ad18898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558c2acfb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558c2acfb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558c246b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558c2461ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558c24615355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558c246abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558c2767af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558c2767af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558c2767af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558c2767af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558c2767af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558c2767af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558c2767af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558c2767af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558c2767af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558c2767af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558c2990ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558c2663cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558c26647be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558c263f3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558c263f3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558c263f4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558c263f3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558c263f3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558c263f3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558c2acfdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558c2ad06928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558c2acee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558c2ad19112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe9e8b90082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558c24613b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $22''2-=''''''/''2-=''''''''''''''-=<''''''''''''-=<'''/''''/''''''2-='''''''''''''.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-7941c3ebd409d7a85c05f01e22c5ae8f1dd0f83a Step #5: Base64: JDIyJycyLT0nJycnJycvJycyLT0nJycnJycnJycnJycnJy09PCcnJycnJycnJycnJy09PCcnJy8nJycnLycnJycnJzItPScnJycnJycnJycnJycuJycnJy4nJCct Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3960 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3687015901 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7ff839810, 0x55b7ffa2301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7ffa23020,0x55b8018bb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7941c3ebd409d7a85c05f01e22c5ae8f1dd0f83a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4918 processed earlier; will process 6111 files now Step #5: ==142636== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b7f632e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b7fc993898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b7fc9765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b7fc9764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b7f6334d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b7f6295b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b7f6290355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b7f6326c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b7f92f5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b7f92f5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b7f92f5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b7f92f5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b7f92f5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b7f92f5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b7f92f5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b7f92f5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b7f92f5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b7f92f5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b7fb58af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b7f82b7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b7f82c2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b7f806ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b7f806ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b7f806f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b7f806e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b7f806e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b7f806e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b7fc978abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b7fc981928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b7fc969699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b7fc994112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5abdfd1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b7f628eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0xa,0x3d,0xa,0x3d,0xa,0x3a,0x3a,0x3a,0x2e,0x2e,0x67,0x68,0x74,0x24,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x0,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x0,0x3a,0x3a,0x3a,0x3d,0xa,0x3d,0x1,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0xa,0x3d,0xa,0x3d,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x4,0x3a,0x3a,0x3a,0x0,0x5d,0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x24,0x5b, Step #5: I\012=\012=\012:::..ght$:::::::::\000:::::::::::::::::\000:::=\012=\001\000\012=\012=\012=\012=\012=\012=?\012=\012=\001\000\000\000\000\000\000\004:::\000]/\000\000\000\000\000\000\000\000\001$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-06be3dd687f2bd83067f74b69ffa02729627b215 Step #5: Base64: SQo9Cj0KOjo6Li5naHQkOjo6Ojo6Ojo6ADo6Ojo6Ojo6Ojo6Ojo6Ojo6ADo6Oj0KPQEACj0KPQo9Cj0KPQo9Pwo9Cj0BAAAAAAAABDo6OgBdLwAAAAAAAAAAASRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3961 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3687526169 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cdfbff6810, 0x55cdfc1e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cdfc1e0020,0x55cdfe0780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/06be3dd687f2bd83067f74b69ffa02729627b215' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4919 processed earlier; will process 6110 files now Step #5: ==142672== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cdf2aeb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cdf9150898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cdf91335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cdf91334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cdf2af1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cdf2a52b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cdf2a4d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cdf2ae3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cdf5ab2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cdf5ab2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cdf5ab2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cdf5ab2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cdf5ab2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cdf5ab2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cdf5ab2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cdf5ab2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cdf5ab2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cdf5ab2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cdf7d47f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cdf4a74b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cdf4a7fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cdf482bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cdf482bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cdf482c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cdf482b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cdf482b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cdf482b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cdf9135abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cdf913e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cdf9126699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cdf9151112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4af583b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cdf2a4bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x59,0x6a,0x6f,0x62,0x73,0x3a,0xa,0x20,0x29,0xcf,0x8a,0xca,0x9d,0xcd,0x9a,0xc7,0x89,0xd5,0x9a,0x6e,0x61,0x6d,0x65,0xdb,0x95,0xcb,0x8d,0xc5,0x9d,0xcf,0x9a,0xca,0x9e,0xcd,0x9a,0xc5,0x9e,0x3e,0x62,0x30,0x76,0x38,0x6d,0x30,0xd2,0x9a,0xc5,0x95,0xcd,0x9d,0xcf,0x9a,0xca,0x9e,0xcd,0x9a,0xc5,0x9e,0xcd,0x9a,0xc5,0x88,0x6f,0x6e,0xd2,0x9a,0xc5,0x95,0xcd,0x8a,0xc5,0x95,0xd2,0x8c,0xd4,0x9d,0xf3,0xa0,0x81,0xb6,0x6a,0x6f,0x62,0x26,0xe2,0x80,0xae,0x76,0x3a,0xa, Step #5: \000\000\000Yjobs:\012 )\317\212\312\235\315\232\307\211\325\232name\333\225\313\215\305\235\317\232\312\236\315\232\305\236>b0v8m0\322\232\305\225\315\235\317\232\312\236\315\232\305\236\315\232\305\210on\322\232\305\225\315\212\305\225\322\214\324\235\363\240\201\266job&\342\200\256v:\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-a669eb1b65e9a1042200e2d9b40fd50956ba0e7b Step #5: Base64: AAAAWWpvYnM6CiApz4rKnc2ax4nVmm5hbWXblcuNxZ3PmsqezZrFnj5iMHY4bTDSmsWVzZ3PmsqezZrFns2axYhvbtKaxZXNisWV0ozUnfOggbZqb2Im4oCudjoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3962 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3688037057 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56315d98f810, 0x56315db7901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56315db79020,0x56315fa110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a669eb1b65e9a1042200e2d9b40fd50956ba0e7b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4920 processed earlier; will process 6109 files now Step #5: ==142708== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5631544849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56315aae9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56315aacc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56315aacc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56315448ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5631543ebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5631543e6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56315447cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56315744bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56315744bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56315744bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56315744bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56315744bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56315744bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56315744bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56315744bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56315744bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56315744bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5631596e0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56315640db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563156418be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5631561c4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5631561c4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5631561c5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5631561c4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5631561c4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5631561c4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56315aaceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56315aad7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56315aabf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56315aaea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff39de58082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5631543e4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x3c,0x4,0x31,0x0,0xd,0x0,0x6c,0x6c,0x2d,0x0,0x2d,0x0,0x2e,0x0,0x43,0x60,0x44,0x0,0x2d,0x0,0x2d,0x0,0x44,0x0,0x2d,0x0,0x44,0x0,0x43,0x60,0x44,0x0,0x2d,0x60,0x1d,0x0,0x44,0x0,0x2d,0x6c,0x44,0x0,0x2d,0x0,0x44,0x0,0x2d,0x0,0x2d,0x0,0x44,0x60,0x44,0x0,0x2d,0x0,0x4f,0x0,0x43,0x60,0x44,0x0,0x2d,0x0,0x2e,0x60,0x44,0x0,0x2d,0x0,0x2d,0x0,0x44,0x0,0x2d,0x0,0x43,0x60,0x44,0x0,0x2d,0x60,0x44,0x0,0x2d,0x6c,0x7c,0x6c,0x6c,0x6c,0x6c,0x6c, Step #5: \000<\0041\000\015\000ll-\000-\000.\000C`D\000-\000-\000D\000-\000D\000C`D\000-`\035\000D\000-lD\000-\000D\000-\000-\000D`D\000-\000O\000C`D\000-\000.`D\000-\000-\000D\000-\000C`D\000-`D\000-l|lllll Step #5: artifact_prefix='./'; Test unit written to ./oom-b1883d9b60b663d732709b802f4ed700664bf252 Step #5: Base64: ADwEMQANAGxsLQAtAC4AQ2BEAC0ALQBEAC0ARABDYEQALWAdAEQALWxEAC0ARAAtAC0ARGBEAC0ATwBDYEQALQAuYEQALQAtAEQALQBDYEQALWBEAC1sfGxsbGxs Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3963 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3688668095 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9388a5810, 0x55e938a8f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e938a8f020,0x55e93a9270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b1883d9b60b663d732709b802f4ed700664bf252' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4921 processed earlier; will process 6108 files now Step #5: #1 pulse cov: 3793 ft: 3794 exec/s: 0 rss: 175Mb Step #5: ==142744== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e92f39a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9359ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9359e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9359e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e92f3a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e92f301b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e92f2fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e92f392c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e932361f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e932361f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e932361f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e932361f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e932361f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e932361f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e932361f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e932361f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e932361f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e932361f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9345f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e931323b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e93132ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9310dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9310dac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9310db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9310da874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9310da874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9310da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e9359e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9359ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e9359d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e935a00112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff21c475082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e92f2fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x26,0x24,0x24,0x22,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x2d,0x2d,0x2d,0x64,0x0,0x42,0x45,0x47,0x4b,0x4e,0x20,0x73,0x74,0x72,0x65,0x61,0x6d,0x2d,0x2d,0x5b,0x2d,0x65,0x61,0x6d,0x2d,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x22,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x3f,0x0,0x0,0x0,0x0,0x0,0x2e,0x33, Step #5: s$$$$$$$$$$$&$$\"$$$r$$$---d\000BEGKN stream--[-eam-$$$$$$$$$$$$$$$$$\"$$$r$$$$$$$r$$$$$$$?\000\000\000\000\000.3 Step #5: artifact_prefix='./'; Test unit written to ./oom-870059ffae4d003cd6e6cffc1ce3ad7713947061 Step #5: Base64: cyQkJCQkJCQkJCQkJiQkIiQkJHIkJCQtLS1kAEJFR0tOIHN0cmVhbS0tWy1lYW0tJCQkJCQkJCQkJCQkJCQkJCQiJCQkciQkJCQkJCRyJCQkJCQkJD8AAAAAAC4z Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3964 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3689224502 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56232348b810, 0x56232367501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562323675020,0x56232550d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/870059ffae4d003cd6e6cffc1ce3ad7713947061' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4923 processed earlier; will process 6106 files now Step #5: ==142780== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562319f809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5623205e5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5623205c85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5623205c84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562319f86d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562319ee7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562319ee2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562319f78c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56231cf47f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56231cf47f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56231cf47f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56231cf47f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56231cf47f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56231cf47f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56231cf47f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56231cf47f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56231cf47f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56231cf47f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56231f1dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56231bf09b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56231bf14be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56231bcc0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56231bcc0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56231bcc1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56231bcc0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56231bcc0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56231bcc0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5623205caabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5623205d3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5623205bb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5623205e6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd43de1e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562319ee0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0x90,0xd9,0xaa,0xd9,0x91,0x20,0xd9,0x90,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0x90,0xd9,0xaa,0xd9,0x91,0x20,0xd9,0x90,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e,0x3c,0xef,0xbb,0xbe,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0x90,0xd9,0xaa,0xd9,0x91,0x20,0xd9,0x90,0x27,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text>\331\220\331\252\331\221 \331\220'</text><text>\331\220\331\252\331\221 \331\220'</text></svg><\357\273\276svg><text>\331\220\331\252\331\221 \331\220'/text></svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-9c934ca39d7856438835c3d8518863f14220d902 Step #5: Base64: PHN2Zz48dGV4dD7ZkNmq2ZEg2ZAnPC90ZXh0Pjx0ZXh0PtmQ2arZkSDZkCc8L3RleHQ+PC9zdmc+PO+7vnN2Zz48dGV4dD7ZkNmq2ZEg2ZAnL3RleHQ+PC9zdmc+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3965 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3689741246 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d532f1f810, 0x55d53310901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d533109020,0x55d534fa10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c934ca39d7856438835c3d8518863f14220d902' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4924 processed earlier; will process 6105 files now Step #5: ==142816== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d529a149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d530079898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d53005c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d53005c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d529a1ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d52997bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d529976355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d529a0cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d52c9dbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d52c9dbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d52c9dbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d52c9dbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d52c9dbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d52c9dbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d52c9dbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d52c9dbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d52c9dbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d52c9dbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d52ec70f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d52b99db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d52b9a8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d52b754c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d52b754c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d52b755738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d52b754874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d52b754874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d52b754874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d53005eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d530067928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d53004f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d53007a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8c2aa5b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d529974b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x2d,0xa,0x3d,0x3d,0x5,0xa,0x3d,0x3d,0xa,0x2d,0xa,0x4e,0x2d,0x2d,0xa,0xa,0xa,0x3d,0xa,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x16,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x82,0x3d,0xa,0x3d,0xa,0x3d,0x13,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: =-\012==\005\012==\012-\012N--\012\012\012=\012\012\012=\012=\012=\012=\012=\012=\012=\012=\012\026\012=\012=\012=\012=\012=\012=\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\202=\012=\012=\023=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-a2b899f00203a80de07f3cb5ae91039591db3cf6 Step #5: Base64: PS0KPT0FCj09Ci0KTi0tCgoKPQoKCj0KPQo9Cj0KPQo9Cj0KPQoWCj0KPQo9Cj0KPQo9AAo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0Kgj0KPQo9Ez0KPQo9Cj0KPQoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3966 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3690267957 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5594f3c5b810, 0x5594f3e4501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5594f3e45020,0x5594f5cdd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2b899f00203a80de07f3cb5ae91039591db3cf6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4925 processed earlier; will process 6104 files now Step #5: ==142852== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5594ea7509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5594f0db5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5594f0d985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5594f0d984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5594ea756d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5594ea6b7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5594ea6b2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5594ea748c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5594ed717f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5594ed717f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5594ed717f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5594ed717f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5594ed717f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5594ed717f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5594ed717f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5594ed717f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5594ed717f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5594ed717f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5594ef9acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5594ec6d9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5594ec6e4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5594ec490c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5594ec490c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5594ec491738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5594ec490874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5594ec490874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5594ec490874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5594f0d9aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5594f0da3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5594f0d8b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5594f0db6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe3c60a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5594ea6b0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0x90,0xd9,0x91,0x20,0xe2,0x86,0x8d,0x5b,0x31,0x32,0x39,0xe2,0x80,0xbc,0xe1,0x82,0x8d,0xef,0xb8,0x8f,0xd9,0x90,0xd9,0x90,0xd9,0x90,0xd9,0x91,0x20,0xe2,0x86,0x8d,0x5b,0x31,0x32,0x39,0xe2,0x80,0xbc,0xe1,0x82,0x8d,0xef,0xb8,0x8f,0xd9,0x90,0xe2,0x86,0x8d,0x5b,0x31,0x35,0x31,0x36,0x34,0xe2,0x80,0xbc,0xe1,0x82,0x8d,0xef,0xb8,0x8f,0xd9,0x90,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text>\331\220\331\221 \342\206\215[129\342\200\274\341\202\215\357\270\217\331\220\331\220\331\220\331\221 \342\206\215[129\342\200\274\341\202\215\357\270\217\331\220\342\206\215[15164\342\200\274\341\202\215\357\270\217\331\220'</text></svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-354f1804e4c411276a6c5f67b42ad40349931f26 Step #5: Base64: PHN2Zz48dGV4dD7ZkNmRIOKGjVsxMjnigLzhgo3vuI/ZkNmQ2ZDZkSDiho1bMTI54oC84YKN77iP2ZDiho1bMTUxNjTigLzhgo3vuI/ZkCc8L3RleHQ+PC9zdmc+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3967 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3690767402 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55604c032810, 0x55604c21c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55604c21c020,0x55604e0b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/354f1804e4c411276a6c5f67b42ad40349931f26' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4926 processed earlier; will process 6103 files now Step #5: ==142888== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556042b279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55604918c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55604916f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55604916f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556042b2dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556042a8eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556042a89355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556042b1fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556045aeef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556045aeef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556045aeef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556045aeef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556045aeef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556045aeef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556045aeef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556045aeef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556045aeef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556045aeef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556047d83f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556044ab0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556044abbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556044867c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556044867c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556044868738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556044867874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556044867874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556044867874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556049171abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55604917a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556049162699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55604918d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc15f22082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556042a87b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x3,0x32,0x0,0x7,0x0,0x0,0x3e,0x54,0x49,0x54,0x32,0x0,0x0,0x0,0xa,0x4e,0x68,0x68,0x43,0x3,0x0,0x49,0x4c,0x3e,0x0,0x33,0x0,0x54,0x49,0x54,0x31,0x0,0x0,0x0,0xa,0x4e,0x68,0x68,0x43,0x0,0x33,0x3f,0x49,0x0,0x3,0x3,0x44,0x54,0x49,0x54,0x31,0x0,0x0,0x0,0xe,0x4e,0x68,0x68,0x43,0x3,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x7,0x0,0x0,0x3e,0x54,0x49,0x54,0x30,0x0,0x0,0x0,0xe,0x4e,0x68,0x39,0x68,0x43,0x3,0x0,0x49,0x0,0x1,0x0, Step #5: ID3\0032\000\007\000\000>TIT2\000\000\000\012NhhC\003\000IL>\0003\000TIT1\000\000\000\012NhhC\0003?I\000\003\003DTIT1\000\000\000\016NhhC\003\000\000\000\000\001\000\000\007\000\000>TIT0\000\000\000\016Nh9hC\003\000I\000\001\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-59cc27d2a71348e03288fb97f4238edc6674e98a Step #5: Base64: SUQzAzIABwAAPlRJVDIAAAAKTmhoQwMASUw+ADMAVElUMQAAAApOaGhDADM/SQADA0RUSVQxAAAADk5oaEMDAAAAAAEAAAcAAD5USVQwAAAADk5oOWhDAwBJAAEA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3968 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3691268516 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9d1178810, 0x55a9d136201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a9d1362020,0x55a9d31fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/59cc27d2a71348e03288fb97f4238edc6674e98a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4927 processed earlier; will process 6102 files now Step #5: ==142924== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a9c7c6d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a9ce2d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9ce2b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9ce2b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a9c7c73d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a9c7bd4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a9c7bcf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a9c7c65c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9cac34f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9cac34f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9cac34f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9cac34f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9cac34f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9cac34f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9cac34f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9cac34f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9cac34f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9cac34f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a9ccec9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a9c9bf6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a9c9c01be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a9c99adc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a9c99adc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a9c99ae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a9c99ad874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a9c99ad874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a9c99ad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a9ce2b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a9ce2c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a9ce2a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a9ce2d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc0ff7e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a9c7bcdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba, Step #5: \357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-e8d25a85ae5e6956569e5fc65b2570d27742d8f9 Step #5: Base64: 77e677e677e6LsK8Cu+3uu+3uu+3ui7CvArvt7rvt7rvt7ouwrwK77e677e677e6LsK8Cu+3uu+3uu+3ui7CvArvt7rvt7rvt7ouwrwK77e677e677e6LsK8Cu+3ug== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3969 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3691771539 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640788f0810, 0x564078ada01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564078ada020,0x56407a9720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e8d25a85ae5e6956569e5fc65b2570d27742d8f9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4928 processed earlier; will process 6101 files now Step #5: ==142960== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56406f3e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564075a4a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564075a2d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564075a2d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56406f3ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56406f34cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56406f347355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56406f3ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5640723acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5640723acf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5640723acf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5640723acf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5640723acf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5640723acf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5640723acf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5640723acf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5640723acf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5640723acf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564074641f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56407136eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564071379be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564071125c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564071125c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564071126738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564071125874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564071125874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564071125874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564075a2fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564075a38928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564075a20699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564075a4b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f976f7d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56406f345b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xef,0xbf,0xbd,0xee, Step #5: \357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\357\277\275\356 Step #5: artifact_prefix='./'; Test unit written to ./oom-b7cf6da67653e5994fdf29d26b353f990158c7b0 Step #5: Base64: 77+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+977+97g== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3970 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3692275030 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c6d863810, 0x564c6da4d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c6da4d020,0x564c6f8e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7cf6da67653e5994fdf29d26b353f990158c7b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4929 processed earlier; will process 6100 files now Step #5: ==142996== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564c643589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c6a9bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c6a9a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c6a9a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c6435ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c642bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c642ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c64350c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c6731ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c6731ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c6731ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c6731ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c6731ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c6731ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c6731ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c6731ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c6731ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c6731ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c695b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c662e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c662ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c66098c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c66098c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c66099738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c66098874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c66098874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c66098874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c6a9a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c6a9ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c6a993699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c6a9be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2d7d45e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c642b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x5a,0x6a,0x6f,0x62,0x73,0x3a,0xa,0x20,0x69,0x3a,0xa,0x20,0x20,0x73,0x74,0x72,0x61,0x74,0x65,0x67,0x79,0x3a,0xa,0x20,0x20,0x20,0x6d,0x61,0x74,0x72,0x69,0x78,0x3a,0xa,0x20,0x20,0x20,0x20,0x65,0x78,0x63,0x4c,0x75,0x64,0x65,0x3a,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x2d,0x20,0x24,0x7b,0x7b,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x2d,0x20,0x24,0x7b,0x7b,0x7d,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x2d,0x20,0x24,0x7b,0x7b,0x20,0x20,0x24,0x20,0xa,0x20, Step #5: \000\000\000Zjobs:\012 i:\012 strategy:\012 matrix:\012 excLude:\012 - ${{ }\012 - ${{}\012 - ${{ $ \012 Step #5: artifact_prefix='./'; Test unit written to ./oom-38feafbd8ec1a9ffdbc432fb0f6f4dd2ce32628a Step #5: Base64: AAAAWmpvYnM6CiBpOgogIHN0cmF0ZWd5OgogICBtYXRyaXg6CiAgICBleGNMdWRlOgogICAgICAtICR7eyB9CiAgICAgIC0gJHt7fQogICAgICAtICR7eyAgJCAKIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3971 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3692782887 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562b4a7ce810, 0x562b4a9b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562b4a9b8020,0x562b4c8500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/38feafbd8ec1a9ffdbc432fb0f6f4dd2ce32628a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4930 processed earlier; will process 6099 files now Step #5: #1 pulse cov: 4116 ft: 4117 exec/s: 0 rss: 173Mb Step #5: ==143032== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562b412c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562b47928898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562b4790b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562b4790b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b412c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b4122ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b41225355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b412bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b4428af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b4428af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b4428af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b4428af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b4428af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b4428af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b4428af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b4428af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b4428af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b4428af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562b4651ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b4324cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b43257be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b43003c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b43003c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b43004738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b43003874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b43003874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b43003874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562b4790dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562b47916928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562b478fe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562b47929112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0db7ac0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b41223b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc9,0x84,0xc8,0xbd,0xc8,0x80,0xc8,0x84,0xd8,0x94,0xc8,0x84,0xd6,0x84,0xcc,0xa5,0xc6,0x84,0xc8,0x84,0xd8,0x94,0xc8,0x84,0xd6,0x84,0xd6,0x84,0xd9,0x84,0xf3,0xa0,0x81,0x84,0xc8,0x81,0xc8,0x84,0xc8,0x94,0xc8,0x84,0xd9,0x84,0xd6,0x84,0xcc,0xa5,0xd8,0x94,0xc8,0x84,0x59,0x59,0x59,0x59,0x59,0x59,0x59,0x59,0xd6,0x84,0xcc,0xa5,0xc6,0x84,0xc8,0x84,0xd8,0x94,0xc8,0x84,0xd6,0x84,0xd9,0x84,0xf3,0xa0,0x81,0x84,0x0,0x0,0x0,0x0,0x0,0x41,0x0,0x0,0x0,0x0,0x0,0x3a,0x3a,0xb, Step #5: \311\204\310\275\310\200\310\204\330\224\310\204\326\204\314\245\306\204\310\204\330\224\310\204\326\204\326\204\331\204\363\240\201\204\310\201\310\204\310\224\310\204\331\204\326\204\314\245\330\224\310\204YYYYYYYY\326\204\314\245\306\204\310\204\330\224\310\204\326\204\331\204\363\240\201\204\000\000\000\000\000A\000\000\000\000\000::\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-30c416aff5b25ff3af4cac556890fde0aef6827b Step #5: Base64: yYTIvciAyITYlMiE1oTMpcaEyITYlMiE1oTWhNmE86CBhMiByITIlMiE2YTWhMyl2JTIhFlZWVlZWVlZ1oTMpcaEyITYlMiE1oTZhPOggYQAAAAAAEEAAAAAADo6Cw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3972 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3693332850 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b711b0810, 0x558b7139a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b7139a020,0x558b732320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/30c416aff5b25ff3af4cac556890fde0aef6827b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4932 processed earlier; will process 6097 files now Step #5: ==143068== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558b67ca59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b6e30a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b6e2ed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b6e2ed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b67cabd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b67c0cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b67c07355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b67c9dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b6ac6cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b6ac6cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b6ac6cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b6ac6cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b6ac6cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b6ac6cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b6ac6cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b6ac6cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b6ac6cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b6ac6cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b6cf01f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b69c2eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b69c39be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b699e5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b699e5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b699e6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b699e5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b699e5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b699e5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b6e2efabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b6e2f8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b6e2e0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b6e30b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f557bbe9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b67c05b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x70,0x68,0x70,0xa,0xa,0x24,0x61,0x5b,0xa,0xa,0x24,0x61,0x5b,0x30,0x5d,0x20,0x2d,0x24,0x61,0x5b,0x30,0x5d,0x5b,0x30,0x5d,0x20,0x26,0x3d,0x30,0x5d,0x20,0x2d,0x24,0x61,0x5b,0x30,0x5d,0x5b,0x30,0x5d,0x20,0x26,0x3d,0x20,0x6e,0x65,0x77,0x20,0x73,0x74,0x64,0x63,0x6c,0x61,0x73,0x73,0x3b,0xa,0xa,0x5b,0x30,0x5d,0x20,0x2d,0x24,0x61,0x5b,0x30,0x5d,0x5b,0x30,0x5d,0x20,0x26,0x3d,0x30,0x5d,0x20,0x2d,0x24,0x61,0x5b,0x30,0x5d,0x5b,0x30,0x5d,0x20,0x26,0x3d,0x3f,0x3e, Step #5: <?php\012\012$a[\012\012$a[0] -$a[0][0] &=0] -$a[0][0] &= new stdclass;\012\012[0] -$a[0][0] &=0] -$a[0][0] &=?> Step #5: artifact_prefix='./'; Test unit written to ./oom-787a785df31c5059b713dced97ce8ff584fc979f Step #5: Base64: PD9waHAKCiRhWwoKJGFbMF0gLSRhWzBdWzBdICY9MF0gLSRhWzBdWzBdICY9IG5ldyBzdGRjbGFzczsKClswXSAtJGFbMF1bMF0gJj0wXSAtJGFbMF1bMF0gJj0/Pg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3973 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3693850169 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b4e8af3810, 0x55b4e8cdd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b4e8cdd020,0x55b4eab750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/787a785df31c5059b713dced97ce8ff584fc979f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4933 processed earlier; will process 6096 files now Step #5: ==143104== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b4df5e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b4e5c4d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b4e5c305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b4e5c304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b4df5eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b4df54fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b4df54a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b4df5e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b4e25aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b4e25aff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b4e25aff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b4e25aff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b4e25aff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b4e25aff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b4e25aff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b4e25aff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b4e25aff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b4e25aff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b4e4844f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b4e1571b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b4e157cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b4e1328c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b4e1328c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b4e1329738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b4e1328874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b4e1328874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b4e1328874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b4e5c32abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b4e5c3b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b4e5c23699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b4e5c4e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb9ff0be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b4df548b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x27,0x21,0x24,0x27,0x21,0x31,0x24,0x36,0x31,0x24,0xa3,0x68,0x34, Step #5: $++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++'!$'!1$61$\243h4 Step #5: artifact_prefix='./'; Test unit written to ./oom-aad60c63781c4f010445f4804c6bb763f44feb8c Step #5: Base64: JCsrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrJyEkJyExJDYxJKNoNA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3974 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3694359938 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ac2db4810, 0x562ac2f9e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ac2f9e020,0x562ac4e360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aad60c63781c4f010445f4804c6bb763f44feb8c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4934 processed earlier; will process 6095 files now Step #5: #1 pulse cov: 4046 ft: 4047 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4117 ft: 4492 exec/s: 0 rss: 176Mb Step #5: ==143140== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562ab98a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562abff0e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562abfef15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562abfef14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562ab98afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562ab9810b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562ab980b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562ab98a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562abc870f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562abc870f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562abc870f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562abc870f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562abc870f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562abc870f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562abc870f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562abc870f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562abc870f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562abc870f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562abeb05f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562abb832b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562abb83dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562abb5e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562abb5e9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562abb5ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562abb5e9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562abb5e9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562abb5e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562abfef3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562abfefc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562abfee4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562abff0f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f86c45bf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562ab9809b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27, Step #5: ''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[' Step #5: artifact_prefix='./'; Test unit written to ./oom-a3823581ba075522365149366af77bfcf54d0ea0 Step #5: Base64: JydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3975 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3694942988 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5582b0343810, 0x5582b052d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5582b052d020,0x5582b23c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a3823581ba075522365149366af77bfcf54d0ea0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4937 processed earlier; will process 6092 files now Step #5: ==143176== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5582a6e389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5582ad49d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5582ad4805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5582ad4804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5582a6e3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5582a6d9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5582a6d9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5582a6e30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5582a9dfff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5582a9dfff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5582a9dfff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5582a9dfff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5582a9dfff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5582a9dfff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5582a9dfff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5582a9dfff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5582a9dfff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5582a9dfff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5582ac094f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5582a8dc1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5582a8dccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5582a8b78c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5582a8b78c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5582a8b79738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5582a8b78874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5582a8b78874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5582a8b78874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5582ad482abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5582ad48b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5582ad473699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5582ad49e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9df0df4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5582a6d98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0x24,0x24,0x24,0x1e,0x24,0x24,0x30,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0xdd,0xdb,0xcc,0x3,0x7e,0x47,0xdb,0xcc,0x3,0x7e,0x47,0x46,0x44,0x7e,0x91,0x47, Step #5: $$$$$\036$$0$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$\335\333\314\003~G\333\314\003~GFD~\221G Step #5: artifact_prefix='./'; Test unit written to ./oom-08b28417f6fdb1f2b33d29a4a3508529dc6d16ed Step #5: Base64: JCQkJCQeJCQwJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQk3dvMA35H28wDfkdGRH6RRw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3976 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3695467331 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d9e4ef810, 0x562d9e6d901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d9e6d9020,0x562da05710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08b28417f6fdb1f2b33d29a4a3508529dc6d16ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4938 processed earlier; will process 6091 files now Step #5: ==143212== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562d94fe49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d9b649898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d9b62c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d9b62c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d94fead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d94f4bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d94f46355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d94fdcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d97fabf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d97fabf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d97fabf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d97fabf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d97fabf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d97fabf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d97fabf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d97fabf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d97fabf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d97fabf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d9a240f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d96f6db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d96f78be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d96d24c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d96d24c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d96d25738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d96d24874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d96d24874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d96d24874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d9b62eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d9b637928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d9b61f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d9b64a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f72ba8df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d94f44b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0x24,0x24,0x24,0x1e,0x24,0x24,0x31,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x31,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0xa4,0x24,0x24,0x24,0xcc,0x3,0x7e,0x47,0x46,0x44,0x7e,0x91,0x47, Step #5: $$$$$\036$$1$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$1$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$\244$$$\314\003~GFD~\221G Step #5: artifact_prefix='./'; Test unit written to ./oom-572f442f1eeed32d9aafbc2d84fa821e2b7b474a Step #5: Base64: JCQkJCQeJCQxJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkMSQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkpCQkJMwDfkdGRH6RRw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3977 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3695995053 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56386f04d810, 0x56386f23701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56386f237020,0x5638710cf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/572f442f1eeed32d9aafbc2d84fa821e2b7b474a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4939 processed earlier; will process 6090 files now Step #5: #1 pulse cov: 3828 ft: 3829 exec/s: 0 rss: 174Mb Step #5: ==143248== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563865b429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56386c1a7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56386c18a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56386c18a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563865b48d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563865aa9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563865aa4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563865b3ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563868b09f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563868b09f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563868b09f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563868b09f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563868b09f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563868b09f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563868b09f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563868b09f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563868b09f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563868b09f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56386ad9ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563867acbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563867ad6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563867882c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563867882c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563867883738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563867882874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563867882874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563867882874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56386c18cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56386c195928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56386c17d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56386c1a8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efd948b2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563865aa2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x42,0x2d,0x2d,0x2d,0x78,0x2d,0x45,0x47,0x8,0x0,0x31,0xf,0x73,0x74,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x2d,0x42,0x2d,0x2d,0x2d,0x78,0x2d,0x45,0x47,0x8,0x0,0x31,0xf,0x73,0x74,0x2d,0x2d,0x2d,0x2d,0x42,0x2d,0x2d,0x24,0x24,0xa,0x2d,0x20,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x20,0x47,0x2d,0x2d,0x24,0x24,0xa,0x2d,0x20,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x20,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x24,0x24,0xa,0x2d,0x20, Step #5: -B---x-EG\010\0001\017st----BEG-B---x-EG\010\0001\017st----B--$$\012- IN ------\012- G--$$\012- IN ------\012- GIN ----$$\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-65be801f3780180e01ee1ca0b9ddc1ccd1901ccc Step #5: Base64: LUItLS14LUVHCAAxD3N0LS0tLUJFRy1CLS0teC1FRwgAMQ9zdC0tLS1CLS0kJAotIElOIC0tLS0tLQotIEctLSQkCi0gSU4gLS0tLS0tCi0gR0lOIC0tLS0kJAotIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3978 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3696556186 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563af99c5810, 0x563af9baf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563af9baf020,0x563afba470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/65be801f3780180e01ee1ca0b9ddc1ccd1901ccc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4941 processed earlier; will process 6088 files now Step #5: ==143284== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563af04ba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563af6b1f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563af6b025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563af6b024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563af04c0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563af0421b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563af041c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563af04b2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563af3481f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563af3481f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563af3481f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563af3481f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563af3481f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563af3481f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563af3481f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563af3481f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563af3481f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563af3481f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563af5716f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563af2443b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563af244ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563af21fac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563af21fac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563af21fb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563af21fa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563af21fa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563af21fa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563af6b04abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563af6b0d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563af6af5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563af6b20112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f129e393082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563af041ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x42,0x3c,0xdb,0xbe,0x7e,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x33,0x2,0x28,0x12,0x3f,0x43,0x0,0x0,0x0,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x0,0x56,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x7e, Step #5: ID~~~~~~B<\333\276~\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\0313\002(\022?C\000\000\000\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\000V\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031~ Step #5: artifact_prefix='./'; Test unit written to ./oom-a52eedd07e6809ebfbbade4f78ddbce2e4e66720 Step #5: Base64: SUR+fn5+fn5CPNu+fhkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkzAigSP0MAAAAZGRkZGRkZGRkZGRkZGRkZGRkAVhkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZfg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3979 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3697061608 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56151ddbf810, 0x56151dfa901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56151dfa9020,0x56151fe410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a52eedd07e6809ebfbbade4f78ddbce2e4e66720' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4942 processed earlier; will process 6087 files now Step #5: ==143320== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5615148b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56151af19898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56151aefc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56151aefc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5615148bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56151481bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561514816355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5615148acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56151787bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56151787bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56151787bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56151787bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56151787bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56151787bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56151787bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56151787bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56151787bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56151787bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561519b10f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56151683db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561516848be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5615165f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5615165f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5615165f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5615165f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5615165f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5615165f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56151aefeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56151af07928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56151aeef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56151af1a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3d4845c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561514814b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x60,0xa,0x9,0xa,0x60,0x2d,0x0,0x60,0x65,0x72,0x69,0x66,0x60,0x20,0x20,0x20,0x60,0xa,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x98,0x97,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x9, Step #5: ``\012\011\012`-\000`erif` `\012hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh\230\227hhhhhhhhhhhhhhhhhhhh\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-810e5a0e074456bf8fe67137876f213e99703d85 Step #5: Base64: YGAKCQpgLQBgZXJpZmAgICBgCmhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhomJdoaGhoaGhoaGhoaGhoaGhoaGhoaAk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3980 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3697690819 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd718c3810, 0x55dd71aad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd71aad020,0x55dd739450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/810e5a0e074456bf8fe67137876f213e99703d85' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4943 processed earlier; will process 6086 files now Step #5: ==143356== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dd683b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd6ea1d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd6ea005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd6ea004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dd683bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dd6831fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dd6831a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dd683b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd6b37ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd6b37ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd6b37ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd6b37ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd6b37ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd6b37ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd6b37ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd6b37ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd6b37ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd6b37ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd6d614f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dd6a341b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dd6a34cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dd6a0f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dd6a0f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dd6a0f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dd6a0f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dd6a0f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dd6a0f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd6ea02abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd6ea0b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd6e9f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd6ea1e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbb4db4d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dd68318b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x37,0x3,0x6,0x0,0x0,0x31,0x0,0x24,0x54,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x69,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x73,0x3d,0xa,0x3d,0xa,0x1,0x14,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xf3,0xa0,0x81,0x9e,0x3d,0x29,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0xe,0xe,0x24, Step #5: ID7\003\006\000\0001\000$T=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=i\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=s=\012=\012\001\024=\012=\012=\012=\012=\012=\012\363\240\201\236=)=\012=\012=\012=\012\000\000\016\016$ Step #5: artifact_prefix='./'; Test unit written to ./oom-a193a69c46e67e621cbcddfcfc5d11533cf5674c Step #5: Base64: SUQ3AwYAADEAJFQ9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPWkKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9cz0KPQoBFD0KPQo9Cj0KPQo9CvOggZ49KT0KPQo9Cj0KAAAODiQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3981 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3698195992 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565174e1e810, 0x56517500801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565175008020,0x565176ea00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a193a69c46e67e621cbcddfcfc5d11533cf5674c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4944 processed earlier; will process 6085 files now Step #5: ==143392== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56516b9139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565171f78898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565171f5b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565171f5b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56516b919d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56516b87ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56516b875355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56516b90bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56516e8daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56516e8daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56516e8daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56516e8daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56516e8daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56516e8daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56516e8daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56516e8daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56516e8daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56516e8daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565170b6ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56516d89cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56516d8a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56516d653c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56516d653c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56516d654738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56516d653874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56516d653874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56516d653874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565171f5dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565171f66928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565171f4e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565171f79112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9d2d618082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56516b873b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f,0xa,0xcd,0x8f, Step #5: \315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217\012\315\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-4605039c0e7581eadd57feb01e124fe2877020e0 Step #5: Base64: zY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8KzY8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3982 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3698717325 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5632db026810, 0x5632db21001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5632db210020,0x5632dd0a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4605039c0e7581eadd57feb01e124fe2877020e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4945 processed earlier; will process 6084 files now Step #5: ==143428== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5632d1b1b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5632d8180898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5632d81635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5632d81634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5632d1b21d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5632d1a82b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5632d1a7d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5632d1b13c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5632d4ae2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5632d4ae2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5632d4ae2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5632d4ae2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5632d4ae2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5632d4ae2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5632d4ae2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5632d4ae2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5632d4ae2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5632d4ae2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5632d6d77f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5632d3aa4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5632d3aafbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5632d385bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5632d385bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5632d385c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5632d385b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5632d385b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5632d385b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5632d8165abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5632d816e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5632d8156699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5632d8181112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1af17af082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5632d1a7bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x60,0xa,0x9,0xa,0x60,0x2d,0x0,0x60,0x65,0x72,0x69,0x66,0x60,0x20,0x20,0x20,0x60,0xa,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x9, Step #5: ``\012\011\012`-\000`erif` `\012hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-5499a4a9a159632c69a146adeaa81ab3bd396ea9 Step #5: Base64: YGAKCQpgLQBgZXJpZmAgICBgCmhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaAk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3983 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3699345556 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562631a69810, 0x562631c5301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562631c53020,0x562633aeb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5499a4a9a159632c69a146adeaa81ab3bd396ea9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4946 processed earlier; will process 6083 files now Step #5: ==143464== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56262855e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56262ebc3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56262eba65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56262eba64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562628564d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5626284c5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5626284c0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562628556c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56262b525f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56262b525f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56262b525f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56262b525f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56262b525f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56262b525f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56262b525f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56262b525f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56262b525f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56262b525f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56262d7baf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56262a4e7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56262a4f2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56262a29ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56262a29ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56262a29f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56262a29e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56262a29e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56262a29e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56262eba8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56262ebb1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56262eb99699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56262ebc4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f650b6f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5626284beb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x80,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x80,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x80,0xa,0xcd,0x88,0xa,0xcc,0x88,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x89,0xa,0xcd,0x88,0xa,0xcd,0x80,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x80,0xa,0xcd,0x88,0xa,0xcd,0x88,0xa,0xcd,0x89,0xa,0xcd,0x88,0xa,0xcd,0x88, Step #5: \315\210\012\315\210\012\315\210\012\315\210\012\315\200\012\315\210\012\315\210\012\315\210\012\315\210\012\315\200\012\315\210\012\315\210\012\315\210\012\315\200\012\315\210\012\314\210\012\315\210\012\315\210\012\315\211\012\315\210\012\315\200\012\315\210\012\315\210\012\315\210\012\315\210\012\315\210\012\315\200\012\315\210\012\315\210\012\315\211\012\315\210\012\315\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-dc5bccf2d8e4ac6f1d98510ed85b15b2d153901a Step #5: Base64: zYgKzYgKzYgKzYgKzYAKzYgKzYgKzYgKzYgKzYAKzYgKzYgKzYgKzYAKzYgKzIgKzYgKzYgKzYkKzYgKzYAKzYgKzYgKzYgKzYgKzYgKzYAKzYgKzYgKzYkKzYgKzYg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3984 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3699871678 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559327733810, 0x55932791d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55932791d020,0x5593297b50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dc5bccf2d8e4ac6f1d98510ed85b15b2d153901a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4947 processed earlier; will process 6082 files now Step #5: ==143500== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55931e2289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55932488d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5593248705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5593248704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55931e22ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55931e18fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55931e18a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55931e220c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5593211eff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5593211eff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5593211eff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5593211eff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5593211eff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5593211eff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5593211eff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5593211eff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5593211eff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5593211eff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559323484f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5593201b1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5593201bcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55931ff68c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55931ff68c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55931ff69738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55931ff68874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55931ff68874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55931ff68874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559324872abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55932487b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559324863699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55932488e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7ff5172082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55931e188b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x6f,0x63,0x69,0x56,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x31,0x2e,0x30,0x2e,0x30,0x22,0x2c,0x22,0x6c,0x69,0x6e,0x75,0x78,0x22,0x3a,0x7b,0x22,0x75,0x69,0x64,0x4d,0x61,0x70,0x70,0x69,0x6e,0x67,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x63,0x6f,0x6e,0x74,0x61,0x69,0x6e,0x65,0x72,0x49,0x44,0x22,0x3a,0x34,0x32,0x39,0x34,0x39,0x32,0x32,0x35,0x36,0x36,0x2c,0x22,0x68,0x6f,0x73,0x74,0x49,0x44,0x22,0x3a,0x34,0x2c,0x22,0x73,0x69,0x7a,0x65,0x22,0x3a,0x32,0x7d,0x5d,0x7d,0x7d, Step #5: {\"ociVersion\":\"1.0.0\",\"linux\":{\"uidMappings\":[{\"containerID\":4294922566,\"hostID\":4,\"size\":2}]}} Step #5: artifact_prefix='./'; Test unit written to ./oom-03e4666d306a6d52adc6d8126a349a724e30de24 Step #5: Base64: eyJvY2lWZXJzaW9uIjoiMS4wLjAiLCJsaW51eCI6eyJ1aWRNYXBwaW5ncyI6W3siY29udGFpbmVySUQiOjQyOTQ5MjI1NjYsImhvc3RJRCI6NCwic2l6ZSI6Mn1dfX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3985 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3700373880 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5615ad34f810, 0x5615ad53901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5615ad539020,0x5615af3d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03e4666d306a6d52adc6d8126a349a724e30de24' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4948 processed earlier; will process 6081 files now Step #5: ==143536== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5615a3e449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5615aa4a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5615aa48c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5615aa48c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5615a3e4ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5615a3dabb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5615a3da6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5615a3e3cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5615a6e0bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5615a6e0bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5615a6e0bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5615a6e0bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5615a6e0bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5615a6e0bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5615a6e0bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5615a6e0bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5615a6e0bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5615a6e0bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5615a90a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5615a5dcdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5615a5dd8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5615a5b84c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5615a5b84c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5615a5b85738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5615a5b84874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5615a5b84874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5615a5b84874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5615aa48eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5615aa497928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5615aa47f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5615aa4aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f08ad871082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5615a3da4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x5a,0xa,0x6a,0x6f,0x62,0x73,0x3a,0xa,0x20,0x69,0x3a,0xa,0x20,0x20,0x73,0x74,0x72,0x61,0x74,0x65,0x67,0x79,0x3a,0xa,0x20,0x20,0x20,0x6d,0x61,0x74,0x72,0x69,0x78,0x3a,0xa,0x20,0x20,0x20,0x20,0x65,0x78,0x63,0x4c,0x75,0x3b,0x65,0x3a,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x2d,0x20,0x30,0x62,0x7b,0x20,0x20,0x24,0x20,0x7d,0x7d,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x2d,0x20,0x24,0x7c,0x7b,0x7d,0x32,0x65,0x2d,0x38,0x2c,0x30,0x30,0x30,0x30,0x33,0x75,0x4b,0x20,0xbb, Step #5: \000\000\000Z\012jobs:\012 i:\012 strategy:\012 matrix:\012 excLu;e:\012 - 0b{ $ }}\012 - $|{}2e-8,00003uK \273 Step #5: artifact_prefix='./'; Test unit written to ./oom-8c8b5b2b2d7674e30ef2e7e592b7509eb11f86a8 Step #5: Base64: AAAAWgpqb2JzOgogaToKICBzdHJhdGVneToKICAgbWF0cml4OgogICAgZXhjTHU7ZToKICAgICAgLSAwYnsgICQgfX0KICAgICAgLSAkfHt9MmUtOCwwMDAwM3VLILs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3986 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3700881402 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557f51d12810, 0x557f51efc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557f51efc020,0x557f53d940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c8b5b2b2d7674e30ef2e7e592b7509eb11f86a8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4949 processed earlier; will process 6080 files now Step #5: #1 pulse cov: 3584 ft: 3585 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4218 ft: 4469 exec/s: 0 rss: 177Mb Step #5: ==143572== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557f488079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f4ee6c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f4ee4f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f4ee4f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f4880dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f4876eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f48769355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f487ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f4b7cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f4b7cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f4b7cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f4b7cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f4b7cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f4b7cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f4b7cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f4b7cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f4b7cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f4b7cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f4da63f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f4a790b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f4a79bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f4a547c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f4a547c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f4a548738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f4a547874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f4a547874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f4a547874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f4ee51abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f4ee5a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f4ee42699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f4ee6d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ad6223082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f48767b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x59,0x6a,0x6f,0x62,0x73,0x3a,0xa,0x20,0x29,0xcf,0x8a,0xd2,0x94,0xcd,0x9a,0xdb,0x95,0xcb,0x8c,0xca,0x9f,0xcf,0x89,0xca,0x95,0xcb,0x8c,0xca,0x9f,0xcf,0x89,0xca,0x92,0xcc,0x9a,0xd2,0x94,0xcd,0x9a,0xdb,0x95,0xcb,0x8c,0xca,0x9d,0xcf,0x89,0xca,0x92,0xdb,0x95,0xcb,0x8c,0xca,0x9f,0xcf,0x89,0xca,0x92,0xcc,0x9a,0xd2,0x94,0xcd,0x9a,0xdb,0x95,0xcb,0x8c,0xca,0x9d,0xcf,0x89,0xca,0x92,0xce,0xaa,0x3a,0xcb,0x8c,0x20,0x20,0x68,0x74,0x65,0x70,0x73,0x20,0x3a,0xa,0x32,0x30, Step #5: \000\000\000Yjobs:\012 )\317\212\322\224\315\232\333\225\313\214\312\237\317\211\312\225\313\214\312\237\317\211\312\222\314\232\322\224\315\232\333\225\313\214\312\235\317\211\312\222\333\225\313\214\312\237\317\211\312\222\314\232\322\224\315\232\333\225\313\214\312\235\317\211\312\222\316\252:\313\214 hteps :\01220 Step #5: artifact_prefix='./'; Test unit written to ./oom-7f25ce0731f39382db724db4f0b70adb7f01886f Step #5: Base64: AAAAWWpvYnM6CiApz4rSlM2a25XLjMqfz4nKlcuMyp/PicqSzJrSlM2a25XLjMqdz4nKktuVy4zKn8+JypLMmtKUzZrblcuMyp3PicqSzqo6y4wgIGh0ZXBzIDoKMjA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3987 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3701461083 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559430feb810, 0x5594311d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5594311d5020,0x55943306d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f25ce0731f39382db724db4f0b70adb7f01886f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4952 processed earlier; will process 6077 files now Step #5: #1 pulse cov: 3454 ft: 3455 exec/s: 0 rss: 174Mb Step #5: ==143608== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559427ae09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55942e145898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55942e1285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55942e1284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559427ae6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559427a47b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559427a42355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559427ad8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55942aaa7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55942aaa7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55942aaa7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55942aaa7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55942aaa7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55942aaa7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55942aaa7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55942aaa7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55942aaa7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55942aaa7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55942cd3cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559429a69b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559429a74be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559429820c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559429820c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559429821738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559429820874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559429820874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559429820874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55942e12aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55942e133928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55942e11b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55942e146112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2895db9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559427a40b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x6e,0x61,0x6d,0x65,0x0,0x0,0x0,0x0,0x0,0x6c,0x7c,0x7c,0x0,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x0,0x0,0x0,0x0,0x0,0x33,0x0,0x0,0x0,0x0,0x6c,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x11,0xdc,0xb0,0x8,0x29,0x3f,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x0,0x0,0x29,0x0,0x0,0x47,0x45,0x4f,0x0,0x0,0x4,0x0,0x0,0x0,0x0,0x24,0x24,0x24,0x24,0x24,0x24,0x0,0x0, Step #5: Mname\000\000\000\000\000l||\000\003\003\003\003\003\003\003\003\003\003\003\003\000\000\000\000\0003\000\000\000\000l^^^^^^^^^^^^^^^\021\334\260\010)?^^^^^^^^^^^^^^\000\000)\000\000GEO\000\000\004\000\000\000\000$$$$$$\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a6d8dff9af254bb9a59e39658079a23e176200a5 Step #5: Base64: TW5hbWUAAAAAAGx8fAADAwMDAwMDAwMDAwMAAAAAADMAAAAAbF5eXl5eXl5eXl5eXl5eXhHcsAgpP15eXl5eXl5eXl5eXl5eAAApAABHRU8AAAQAAAAAJCQkJCQkAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3988 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3702012451 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559d13664810, 0x559d1384e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559d1384e020,0x559d156e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a6d8dff9af254bb9a59e39658079a23e176200a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4954 processed earlier; will process 6075 files now Step #5: ==143644== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559d0a1599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559d107be898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559d107a15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559d107a14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559d0a15fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559d0a0c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559d0a0bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559d0a151c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559d0d120f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559d0d120f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559d0d120f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559d0d120f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559d0d120f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559d0d120f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559d0d120f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559d0d120f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559d0d120f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559d0d120f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559d0f3b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559d0c0e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559d0c0edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559d0be99c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559d0be99c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559d0be9a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559d0be99874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559d0be99874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559d0be99874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559d107a3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559d107ac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559d10794699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559d107bf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f588cc08082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559d0a0b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0x24,0x24,0x24,0x1e,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x7e,0x24,0x24,0x24,0x93,0x24,0x24,0x24,0xdb,0xdd,0x24,0xdb,0xcc,0x3,0x7e,0x47,0x46,0x44,0x7e,0x91,0x47, Step #5: $$$$$\036$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$~$$$\223$$$\333\335$\333\314\003~GFD~\221G Step #5: artifact_prefix='./'; Test unit written to ./oom-5b6d6908a7ad3a827d631963233fe99a620f7cbd Step #5: Base64: JCQkJCQeJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCR+JCQkkyQkJNvdJNvMA35HRkR+kUc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3989 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3702534227 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fbe745e810, 0x55fbe764801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fbe7648020,0x55fbe94e00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5b6d6908a7ad3a827d631963233fe99a620f7cbd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4955 processed earlier; will process 6074 files now Step #5: ==143680== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fbddf539c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fbe45b8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fbe459b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fbe459b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fbddf59d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fbddebab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fbddeb5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fbddf4bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fbe0f1af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fbe0f1af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fbe0f1af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fbe0f1af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fbe0f1af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fbe0f1af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fbe0f1af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fbe0f1af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fbe0f1af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fbe0f1af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fbe31aff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fbdfedcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fbdfee7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fbdfc93c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fbdfc93c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fbdfc94738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fbdfc93874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fbdfc93874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fbdfc93874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fbe459dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fbe45a6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fbe458e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fbe45b9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb26bc96082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fbddeb3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x82,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x82,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x82,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0xe, Step #5: \343\200\202\343\200\202\343\202\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\202\202\343\200\202\343\200\202\343\202\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\016 Step #5: artifact_prefix='./'; Test unit written to ./oom-018452f7ee77dd9aaa6bcbd13678311fc30ae303 Step #5: Base64: 44CC44CC44KC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44KC44CC44CC44KC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC4w4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3990 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3703038120 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556ef09ba810, 0x556ef0ba401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556ef0ba4020,0x556ef2a3c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/018452f7ee77dd9aaa6bcbd13678311fc30ae303' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4956 processed earlier; will process 6073 files now Step #5: ==143716== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556ee74af9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556eedb14898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556eedaf75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556eedaf74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556ee74b5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556ee7416b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556ee7411355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556ee74a7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556eea476f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556eea476f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556eea476f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556eea476f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556eea476f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556eea476f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556eea476f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556eea476f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556eea476f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556eea476f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556eec70bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556ee9438b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556ee9443be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556ee91efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556ee91efc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556ee91f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556ee91ef874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556ee91ef874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556ee91ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556eedaf9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556eedb02928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556eedaea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556eedb15112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c6659a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556ee740fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x3c,0x71,0x3e,0x3c,0x71,0x3e,0x3c,0x3c,0x71,0x3e,0x28,0x3e,0x28,0x3f,0x3c,0x71,0x3e, Step #5: (?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q><q>(?<q>(?<q>(?<q>(?<q>(?<q><q><q><<q>(>(?<q> Step #5: artifact_prefix='./'; Test unit written to ./oom-f98fb8f2a9bd816d75b6fb952c33c6dbca5bdaaa Step #5: Base64: KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT48cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+PHE+PHE+PDxxPig+KD88cT4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3991 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3703544729 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55afda5a6810, 0x55afda79001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55afda790020,0x55afdc6280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f98fb8f2a9bd816d75b6fb952c33c6dbca5bdaaa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4957 processed earlier; will process 6072 files now Step #5: ==143752== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55afd109b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55afd7700898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55afd76e35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55afd76e34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55afd10a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55afd1002b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55afd0ffd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55afd1093c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55afd4062f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55afd4062f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55afd4062f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55afd4062f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55afd4062f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55afd4062f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55afd4062f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55afd4062f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55afd4062f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55afd4062f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55afd62f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55afd3024b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55afd302fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55afd2ddbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55afd2ddbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55afd2ddc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55afd2ddb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55afd2ddb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55afd2ddb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55afd76e5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55afd76ee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55afd76d6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55afd7701112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd1a20b0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55afd0ffbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x70,0x5b,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x66,0x66,0x65,0x65,0x64,0x69,0x6e,0x67,0xf3,0xa0,0x81,0xa1,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x2f,0x70,0xa,0x54,0x54,0x33,0x34,0x33,0x38,0x30,0x36,0x39,0x37,0x34,0xf3,0xa0,0x81,0x9c,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x47,0x47,0x47,0x47,0x47,0x47,0x50,0x3d,0xa,0x2d,0x2d,0x2d,0x2d,0xf3,0xa0,0x81,0x9f,0x2d,0x45,0x4e,0xf3,0xa0,0x80,0xb4,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: \012p[pppppppppffeeding\363\240\201\241ppppppppppppppp/p\012TT343806974\363\240\201\234fffffffGGGGGGP=\012----\363\240\201\237-EN\363\240\200\264D ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-b50dd8e8a3cd23968b2eeaa1ebc1c83861bee6d0 Step #5: Base64: CnBbcHBwcHBwcHBwZmZlZWRpbmfzoIGhcHBwcHBwcHBwcHBwcHBwL3AKVFQzNDM4MDY5NzTzoIGcZmZmZmZmZkdHR0dHR1A9Ci0tLS3zoIGfLUVO86CAtEQgLS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3992 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3704052581 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563083b94810, 0x563083d7e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563083d7e020,0x563085c160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b50dd8e8a3cd23968b2eeaa1ebc1c83861bee6d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4958 processed earlier; will process 6071 files now Step #5: ==143788== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56307a6899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563080cee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563080cd15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563080cd14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56307a68fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56307a5f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56307a5eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56307a681c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56307d650f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56307d650f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56307d650f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56307d650f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56307d650f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56307d650f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56307d650f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56307d650f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56307d650f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56307d650f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56307f8e5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56307c612b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56307c61dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56307c3c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56307c3c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56307c3ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56307c3c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56307c3c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56307c3c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563080cd3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563080cdc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563080cc4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563080cef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbd11b95082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56307a5e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x3d,0x9,0x15,0x20,0xd,0x11,0x2d,0x0,0x1a,0x0,0x27,0xe,0x0,0x33,0x23,0x39,0x2d,0x27,0x1,0x0,0x7,0x21,0x10,0x25,0x38,0x37,0x11,0x3e,0x1,0x22,0x2b,0x3a,0x2f,0x32,0x4,0x17,0x0,0x1f,0x3f,0x18,0x8,0x3,0x16,0x14,0x24,0x20,0x9,0x15,0x20,0xd,0x11,0x2d,0x0,0x1a,0x0,0x27,0xe,0x0,0x32,0x23,0x39,0x2d,0x27,0x1,0x0,0x2f,0x32,0x4,0x17,0x0,0x1f,0x3f,0x18,0x8,0x3,0x16,0x33,0x3d,0x14,0x24,0x20,0x7,0x21,0x10,0x25,0x38,0x37,0x11,0x3e,0x1,0x22,0x2b,0x3a,0x2f, Step #5: \000=\011\025 \015\021-\000\032\000'\016\0003#9-'\001\000\007!\020%87\021>\001\"+:/2\004\027\000\037?\030\010\003\026\024$ \011\025 \015\021-\000\032\000'\016\0002#9-'\001\000/2\004\027\000\037?\030\010\003\0263=\024$ \007!\020%87\021>\001\"+:/ Step #5: artifact_prefix='./'; Test unit written to ./oom-f29277116460c8182c872cc7df7d4790eb07b6ba Step #5: Base64: AD0JFSANES0AGgAnDgAzIzktJwEAByEQJTg3ET4BIis6LzIEFwAfPxgIAxYUJCAJFSANES0AGgAnDgAyIzktJwEALzIEFwAfPxgIAxYzPRQkIAchECU4NxE+ASIrOi8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3993 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3704576288 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e2238e810, 0x563e2257801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e22578020,0x563e244100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f29277116460c8182c872cc7df7d4790eb07b6ba' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4959 processed earlier; will process 6070 files now Step #5: ==143824== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563e18e839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e1f4e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e1f4cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e1f4cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e18e89d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e18deab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e18de5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e18e7bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e1be4af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e1be4af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e1be4af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e1be4af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e1be4af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e1be4af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e1be4af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e1be4af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e1be4af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e1be4af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e1e0dff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e1ae0cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e1ae17be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e1abc3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e1abc3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e1abc4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e1abc3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e1abc3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e1abc3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e1f4cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e1f4d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e1f4be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e1f4e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f91ecc75082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e18de3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9d,0x85,0x9f,0xd6,0xb9,0xd6,0xb8,0xd6,0xb1,0xcc,0xb8,0xf0,0x9d,0x85,0x9f,0xd6,0xbf,0xd6,0xb8,0xd6,0xb1,0xcc,0xb4,0xf0,0x9d,0x85,0x9f,0xd6,0xb9,0xd6,0xb8,0xd6,0xb1,0xcc,0xb8,0xf0,0x9d,0x85,0x9f,0xd6,0xb9,0xd6,0xb8,0xd6,0xb1,0xcc,0xb8,0xf0,0x9d,0x85,0x9e,0xd6,0xb9,0xd6,0xb8,0xd6,0xb1,0xcc,0xb8,0xf0,0x9d,0x85,0x9f,0xd6,0xb9,0xd6,0xb8,0xd6,0xb1,0xcc,0xb8,0xf0,0x9d,0x85,0x9e,0xd6,0xb9,0xd6,0xb8,0xd6,0xb1,0xcc,0xb8,0xf0,0x9d,0x85,0x9f,0xd6,0xb9,0xd6,0xb8,0xd6,0xb1,0xcc,0xb8, Step #5: \360\235\205\237\326\271\326\270\326\261\314\270\360\235\205\237\326\277\326\270\326\261\314\264\360\235\205\237\326\271\326\270\326\261\314\270\360\235\205\237\326\271\326\270\326\261\314\270\360\235\205\236\326\271\326\270\326\261\314\270\360\235\205\237\326\271\326\270\326\261\314\270\360\235\205\236\326\271\326\270\326\261\314\270\360\235\205\237\326\271\326\270\326\261\314\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-ecacf2fc27df37a23b4abbd3edb61d8447c9d6e7 Step #5: Base64: 8J2Fn9a51rjWscy48J2Fn9a/1rjWscy08J2Fn9a51rjWscy48J2Fn9a51rjWscy48J2Fnta51rjWscy48J2Fn9a51rjWscy48J2Fnta51rjWscy48J2Fn9a51rjWscy4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3994 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3705089442 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56293b91c810, 0x56293bb0601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56293bb06020,0x56293d99e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ecacf2fc27df37a23b4abbd3edb61d8447c9d6e7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4960 processed earlier; will process 6069 files now Step #5: ==143860== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5629324119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562938a76898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562938a595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562938a594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562932417d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562932378b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562932373355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562932409c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5629353d8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5629353d8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5629353d8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5629353d8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5629353d8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5629353d8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5629353d8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5629353d8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5629353d8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5629353d8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56293766df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56293439ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629343a5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562934151c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562934151c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562934152738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562934151874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562934151874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562934151874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562938a5babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562938a64928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562938a4c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562938a77112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcca28ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562932371b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x88,0x90,0xe3,0x88,0x90,0xe6,0x8f,0x90,0xe3,0x88,0x90,0xe6,0x8f,0x90,0xe3,0x8f,0x90,0xe3,0x88,0x90,0xe6,0x8f,0x90,0xe3,0x8a,0x90,0xe6,0x8f,0x90,0xe3,0x88,0x90,0xe6,0x8f,0x90,0xe3,0x88,0x90,0xe7,0x8f,0x90,0xe3,0x88,0x90,0xe6,0x8f,0x90,0xe3,0x88,0x90,0xe3,0x88,0x90,0xe6,0x8f,0x90,0xe3,0x88,0x90,0xe6,0x8f,0x90,0xe3,0x88,0x90,0xe6,0x8f,0x90,0xe3,0x88,0x90,0xe6,0x8f,0x90,0xe3,0x88,0x90,0xe6,0x8f,0x90,0xe3,0x88,0x90,0xe6,0x8f,0x90,0xe6,0x8f,0x90,0xe3,0x88,0x8f,0xe3,0x88,0x90, Step #5: \343\210\220\343\210\220\346\217\220\343\210\220\346\217\220\343\217\220\343\210\220\346\217\220\343\212\220\346\217\220\343\210\220\346\217\220\343\210\220\347\217\220\343\210\220\346\217\220\343\210\220\343\210\220\346\217\220\343\210\220\346\217\220\343\210\220\346\217\220\343\210\220\346\217\220\343\210\220\346\217\220\343\210\220\346\217\220\346\217\220\343\210\217\343\210\220 Step #5: artifact_prefix='./'; Test unit written to ./oom-de2f905bf5b9d0f667acfbe3c0f9056fa2118c82 Step #5: Base64: 44iQ44iQ5o+Q44iQ5o+Q44+Q44iQ5o+Q44qQ5o+Q44iQ5o+Q44iQ54+Q44iQ5o+Q44iQ44iQ5o+Q44iQ5o+Q44iQ5o+Q44iQ5o+Q44iQ5o+Q44iQ5o+Q5o+Q44iP44iQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3995 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3705596531 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555f87607810, 0x555f877f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555f877f1020,0x555f896890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de2f905bf5b9d0f667acfbe3c0f9056fa2118c82' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4961 processed earlier; will process 6068 files now Step #5: ==143896== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555f7e0fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555f84761898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555f847445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555f847444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555f7e102d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555f7e063b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555f7e05e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555f7e0f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555f810c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555f810c3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555f810c3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555f810c3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555f810c3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555f810c3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555f810c3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555f810c3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555f810c3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555f810c3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555f83358f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555f80085b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555f80090be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555f7fe3cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555f7fe3cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555f7fe3d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555f7fe3c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555f7fe3c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555f7fe3c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555f84746abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555f8474f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555f84737699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555f84762112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a0ebec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555f7e05cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0x61,0x6b,0x63,0x61,0x6c,0x6b,0x63,0x61,0x6c,0x61,0x2d,0x65,0x79,0x37,0x6d,0x7a,0x33,0x37,0x61,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xf0,0x9e,0xa4,0x8b,0x41,0xf0,0x9e,0xa4,0x8d,0xf0,0x9e,0xa4,0x8f,0xe3,0x8e,0xaf,0xe3,0x8e,0xa9,0xe3,0x8e,0xaf, Step #5: \012\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257akcalkcala-ey7mz37a\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\360\236\244\213A\360\236\244\215\360\236\244\217\343\216\257\343\216\251\343\216\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-1362602f7df85581d3d38e145385d141302d3058 Step #5: Base64: CuOOr+OOr+OOr+OOr+OOr+OOr+OOr+OOr+OOr+OOr2FrY2Fsa2NhbGEtZXk3bXozN2Hjjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/wnqSLQfCepI3wnqSP446v446p446v Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3996 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3706115957 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e30aba810, 0x563e30ca401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e30ca4020,0x563e32b3c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1362602f7df85581d3d38e145385d141302d3058' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4962 processed earlier; will process 6067 files now Step #5: #1 pulse cov: 4335 ft: 4336 exec/s: 0 rss: 175Mb Step #5: ==143932== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563e275af9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e2dc14898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e2dbf75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e2dbf74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e275b5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e27516b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e27511355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e275a7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e2a576f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e2a576f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e2a576f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e2a576f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e2a576f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e2a576f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e2a576f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e2a576f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e2a576f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e2a576f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e2c80bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e29538b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e29543be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e292efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e292efc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e292f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e292ef874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e292ef874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e292ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e2dbf9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e2dc02928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e2dbea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e2dc15112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc85a15082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e2750fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0x5d,0xbf,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xaf,0xe0,0xa8,0x6d, Step #5: \340\264\277\340\260\267\340\260\267\340\260\267\340\264\277\340\264\277\340\260\267\340\264\277\340\264\277\340\260\277\340\264\277\340\260\267\340\260\267\340\260\267\340\264\277\340\264\277\340\260\267\340]\277\340\260\267\340\260\267\340\260\267\340\264\277\340\264\277\340\260\267\340\260\267\340\260\267\340\264\277\340\264\277\340\264\277\340\264\277\340\260\257\340\250m Step #5: artifact_prefix='./'; Test unit written to ./oom-ee49d5888eca59f2a120f1097cc39fdfd0237b11 Step #5: Base64: 4LS/4LC34LC34LC34LS/4LS/4LC34LS/4LS/4LC/4LS/4LC34LC34LC34LS/4LS/4LC34F2/4LC34LC34LC34LS/4LS/4LC34LC34LC34LS/4LS/4LS/4LS/4LCv4Kht Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3997 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3706667799 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556dccc84810, 0x556dcce6e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556dcce6e020,0x556dced060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee49d5888eca59f2a120f1097cc39fdfd0237b11' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4964 processed earlier; will process 6065 files now Step #5: ==143968== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556dc37799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556dc9dde898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556dc9dc15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556dc9dc14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556dc377fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556dc36e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556dc36db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556dc3771c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556dc6740f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556dc6740f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556dc6740f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556dc6740f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556dc6740f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556dc6740f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556dc6740f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556dc6740f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556dc6740f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556dc6740f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556dc89d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556dc5702b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556dc570dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556dc54b9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556dc54b9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556dc54ba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556dc54b9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556dc54b9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556dc54b9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556dc9dc3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556dc9dcc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556dc9db4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556dc9ddf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0413786082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556dc36d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x61,0x20,0x5b,0x32,0x36,0x3a,0x37,0x30,0x3a,0x32,0x36,0x3a,0x39,0x39,0x3a,0x30,0x61,0x3a,0x30,0x64,0x3a,0x39,0x39,0x3a,0x33,0x37,0x5d,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x73,0x65,0x69,0x30,0x77,0x57,0x6c,0x54,0x57,0x35,0x54,0x6f,0x30,0x39,0x42,0x77,0x66,0x6b,0x41,0x4f,0x59,0x76,0x73,0x33,0x36,0x56,0x4a,0x30,0x6a,0x43,0x32,0x30,0x64,0x68,0x77,0x44,0x4b,0x32,0x62,0x69,0x2b,0x76,0x61, Step #5: onion-key\012a [26:70:26:99:0a:0d:99:37]\012ntor-onion-key sei0wWlTW5To09BwfkAOYvs36VJ0jC20dhwDK2bi+va Step #5: artifact_prefix='./'; Test unit written to ./oom-c6ed0f739499f8590edc98adb7004fbdc3b9d776 Step #5: Base64: b25pb24ta2V5CmEgWzI2OjcwOjI2Ojk5OjBhOjBkOjk5OjM3XQpudG9yLW9uaW9uLWtleSBzZWkwd1dsVFc1VG8wOUJ3ZmtBT1l2czM2VkowakMyMGRod0RLMmJpK3Zh Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3998 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3707175448 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c54f46810, 0x561c5513001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c55130020,0x561c56fc80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c6ed0f739499f8590edc98adb7004fbdc3b9d776' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4965 processed earlier; will process 6064 files now Step #5: ==144004== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561c4ba3b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c520a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c520835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c520834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c4ba41d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c4b9a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c4b99d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c4ba33c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c4ea02f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c4ea02f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c4ea02f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c4ea02f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c4ea02f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c4ea02f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c4ea02f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c4ea02f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c4ea02f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c4ea02f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c50c97f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c4d9c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c4d9cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c4d77bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c4d77bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c4d77c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c4d77b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c4d77b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c4d77b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c52085abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c5208e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c52076699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c520a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd5217d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c4b99bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe9,0x80,0x88,0x2d,0x0,0x60,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x73,0x20,0x5b,0x20,0x38,0x30,0x68,0x68,0x68,0x68,0x68,0x71,0x68,0x9c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0xf3,0xa0,0x6c,0x69,0x67,0x68,0x74,0xe2,0x80,0x88,0x2d,0x0,0x60,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0x2f,0xa,0x60,0x2a,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xa,0x2f,0xa,0x2f,0xa,0x60,0x60,0x20,0x20,0x20,0x60,0xa,0x9, Step #5: `\351\200\210-\000`hhhhhhhhs [ 80hhhhhqh\234\000\000\000\000\000\000\000hhhhhhhhhhhhhhh\363\240light\342\200\210-\000``\342\200\210-\000`\012/\012`*\342\200\210-\000`\012\012/\012/\012`` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf9ef60c375cf1f326bd688858dfa51e523fb2f2 Step #5: Base64: YOmAiC0AYGhoaGhoaGhocyBbIDgwaGhoaGhxaJwAAAAAAAAAaGhoaGhoaGhoaGhoaGho86BsaWdodOKAiC0AYGDigIgtAGAKLwpgKuKAiC0AYAoKLwovCmBgICAgYAoJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3999 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3707803675 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56224ffed810, 0x5622501d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622501d7020,0x56225206f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf9ef60c375cf1f326bd688858dfa51e523fb2f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4966 processed earlier; will process 6063 files now Step #5: ==144040== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562246ae29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56224d147898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56224d12a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56224d12a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562246ae8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562246a49b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562246a44355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562246adac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562249aa9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562249aa9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562249aa9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562249aa9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562249aa9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562249aa9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562249aa9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562249aa9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562249aa9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562249aa9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56224bd3ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562248a6bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562248a76be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562248822c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562248822c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562248823738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562248822874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562248822874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562248822874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56224d12cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56224d135928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56224d11d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56224d148112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffb978fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562246a42b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x73,0x64,0x3,0x11,0x47,0x0,0x54,0x49,0x42,0x2b,0x0,0x0,0x5b,0xda,0x82,0x0,0x20,0x79,0x11,0x47,0x0,0x54,0x49,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0xe0,0xb9,0x84,0x26,0x82,0x1,0x70,0x70,0x70,0x70,0x70,0x20, Step #5: ID3sd\003\021G\000TIB+\000\000[\332\202\000 y\021G\000TI\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000[[[[[[[[[[[[[[[\340\271\204&\202\001ppppp Step #5: artifact_prefix='./'; Test unit written to ./oom-53cc5a609eabf9aa6d8c1cb328be5603bec34f0d Step #5: Base64: SUQzc2QDEUcAVElCKwAAW9qCACB5EUcAVEkAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAW1tbW1tbW1tbW1tbW1tb4LmEJoIBcHBwcHAg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4000 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3708310753 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd0f1b1810, 0x55dd0f39b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd0f39b020,0x55dd112330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/53cc5a609eabf9aa6d8c1cb328be5603bec34f0d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4967 processed earlier; will process 6062 files now Step #5: ==144076== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dd05ca69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd0c30b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd0c2ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd0c2ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dd05cacd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dd05c0db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dd05c08355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dd05c9ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd08c6df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd08c6df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd08c6df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd08c6df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd08c6df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd08c6df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd08c6df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd08c6df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd08c6df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd08c6df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd0af02f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dd07c2fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dd07c3abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dd079e6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dd079e6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dd079e7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dd079e6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dd079e6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dd079e6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd0c2f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd0c2f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd0c2e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd0c30c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1fba99f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dd05c06b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xeb,0xb6,0xb8,0xe1,0x86,0xad,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xad,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xab,0xeb,0xb6,0xb8,0xe1,0x86,0xad,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac, Step #5: \353\266\270\341\206\255\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\255\353\266\270\341\206\254\353\266\270\341\206\253\353\266\270\341\206\255\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254 Step #5: artifact_prefix='./'; Test unit written to ./oom-72c7bdcb3e1fd43a3870dc64ba82c7f08a507758 Step #5: Base64: 67a44Yat67a44Yas67a44Yas67a44Yas67a44Yat67a44Yas67a44Yar67a44Yat67a44Yas67a44Yas67a44Yas67a44Yas67a44Yas67a44Yas67a44Yas67a44Yas Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4001 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3708820305 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb4bc1e810, 0x55bb4be0801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb4be08020,0x55bb4dca00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/72c7bdcb3e1fd43a3870dc64ba82c7f08a507758' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4968 processed earlier; will process 6061 files now Step #5: ==144112== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bb427139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb48d78898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb48d5b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb48d5b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb42719d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb4267ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb42675355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb4270bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb456daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb456daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb456daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb456daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb456daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb456daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb456daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb456daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb456daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb456daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb4796ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb4469cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb446a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb44453c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb44453c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb44454738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb44453874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb44453874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb44453874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb48d5dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb48d66928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb48d4e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb48d79112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f597aac6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb42673b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0xb1,0xa4,0xe2,0xa4,0xa4,0xe2,0xa4,0xa4,0xe2,0xa3,0xa4,0xe2,0xa5,0xa4,0xe2,0xa4,0xa3,0xe2,0xb5,0xa4,0xe1,0xa4,0xa4,0xe2,0xa5,0xa3,0xe2,0xa4,0xa3,0xe2,0xb5,0xa4,0xe1,0xa4,0xa4,0xe3,0xa5,0xa3,0xe2,0xa4,0xa3,0xe2,0xb5,0xa4,0xe1,0xa4,0xa4,0xe2,0xa5,0xa3,0xe2,0xa4,0xa3,0xe2,0xa4,0xa3,0xe3,0xb5,0xa4,0xe1,0xa0,0xa5,0xe2,0xa4,0xb0,0xe2,0xb5,0xa4,0xe2,0xa3,0xa4,0xe2,0xa4,0xb0,0xe2,0xa4,0xa5,0xe2,0xa4,0xa4,0xe2,0xa4,0xa4,0xe2,0xa4,0xa4,0xe2,0xa5,0xa4,0xe2,0xa4,0xb0,0xe1,0xa4,0xa4, Step #5: \342\261\244\342\244\244\342\244\244\342\243\244\342\245\244\342\244\243\342\265\244\341\244\244\342\245\243\342\244\243\342\265\244\341\244\244\343\245\243\342\244\243\342\265\244\341\244\244\342\245\243\342\244\243\342\244\243\343\265\244\341\240\245\342\244\260\342\265\244\342\243\244\342\244\260\342\244\245\342\244\244\342\244\244\342\244\244\342\245\244\342\244\260\341\244\244 Step #5: artifact_prefix='./'; Test unit written to ./oom-a0664b7ac54a8b3d6fb3ca63964242e25aad2b83 Step #5: Base64: 4rGk4qSk4qSk4qOk4qWk4qSj4rWk4aSk4qWj4qSj4rWk4aSk46Wj4qSj4rWk4aSk4qWj4qSj4qSj47Wk4aCl4qSw4rWk4qOk4qSw4qSl4qSk4qSk4qSk4qWk4qSw4aSk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4002 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3709335895 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558bff9c1810, 0x558bffbab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558bffbab020,0x558c01a430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a0664b7ac54a8b3d6fb3ca63964242e25aad2b83' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4969 processed earlier; will process 6060 files now Step #5: ==144148== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558bf64b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558bfcb1b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558bfcafe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558bfcafe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558bf64bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558bf641db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558bf6418355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558bf64aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558bf947df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558bf947df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558bf947df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558bf947df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558bf947df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558bf947df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558bf947df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558bf947df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558bf947df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558bf947df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558bfb712f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558bf843fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558bf844abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558bf81f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558bf81f6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558bf81f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558bf81f6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558bf81f6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558bf81f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558bfcb00abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558bfcb09928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558bfcaf1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558bfcb1c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f10fdb95082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558bf6416b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x31,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x31,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x31,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x31,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x31,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa,0x30,0x2e,0xa, Step #5: 1.\0120.\0120.\0120.\0120.\0121.\0120.\0120.\0120.\0120.\0121.\0120.\0120.\0120.\0120.\0120.\0120.\0120.\0120.\0121.\0120.\0120.\0120.\0120.\0121.\0120.\0120.\0121.\0120.\0120.\0120.\0120.\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-c96613ebdf509675c81cd1042fbfd88fc94b4539 Step #5: Base64: MS4KMC4KMC4KMC4KMC4KMS4KMC4KMC4KMC4KMC4KMS4KMC4KMC4KMC4KMC4KMC4KMC4KMC4KMC4KMS4KMC4KMC4KMC4KMC4KMS4KMC4KMC4KMS4KMC4KMC4KMC4KMC4K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4003 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3709877573 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5574a5068810, 0x5574a525201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5574a5252020,0x5574a70ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c96613ebdf509675c81cd1042fbfd88fc94b4539' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4970 processed earlier; will process 6059 files now Step #5: ==144184== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55749bb5d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5574a21c2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5574a21a55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5574a21a54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55749bb63d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55749bac4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55749babf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55749bb55c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55749eb24f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55749eb24f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55749eb24f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55749eb24f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55749eb24f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55749eb24f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55749eb24f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55749eb24f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55749eb24f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55749eb24f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5574a0db9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55749dae6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55749daf1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55749d89dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55749d89dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55749d89e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55749d89d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55749d89d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55749d89d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5574a21a7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5574a21b0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5574a2198699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5574a21c3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4fca2ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55749babdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4f,0x6c,0x31,0x2b,0x34,0x27,0x0,0x3a,0xd8,0x80,0x0,0xa,0xd8,0x80,0x4,0x0,0x3b,0x0,0xa,0x0,0x1f,0x18,0x18,0x4f,0x59,0x3e,0x2d,0x31,0x2b,0x34,0x27,0x0,0x3a,0xd8,0x80,0x0,0x37,0x37,0x37,0x12,0x0,0x0,0x0,0x37,0x37,0x31,0x29,0x30,0x29,0x29,0x29,0xd7,0xa9,0x28,0x30,0x9,0x37,0x29,0x29,0x30,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x4,0x2b,0x37,0x31,0x37,0x37,0x37,0x2e, Step #5: /\000\000\000\000\000\000\000\000\000\000\000\000\000Ol1+4'\000:\330\200\000\012\330\200\004\000;\000\012\000\037\030\030OY>-1+4'\000:\330\200\000777\022\000\000\000771)0)))\327\251(0\0117))077777777777777\004+71777. Step #5: artifact_prefix='./'; Test unit written to ./oom-6146debf92939768ce92df21b11cfc54319d6cde Step #5: Base64: LwAAAAAAAAAAAAAAAABPbDErNCcAOtiAAArYgAQAOwAKAB8YGE9ZPi0xKzQnADrYgAA3NzcSAAAANzcxKTApKSnXqSgwCTcpKTA3Nzc3Nzc3Nzc3Nzc3NwQrNzE3Nzcu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4004 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3710387349 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5579c6c4d810, 0x5579c6e3701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5579c6e37020,0x5579c8ccf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6146debf92939768ce92df21b11cfc54319d6cde' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4971 processed earlier; will process 6058 files now Step #5: ==144220== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5579bd7429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5579c3da7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5579c3d8a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5579c3d8a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5579bd748d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5579bd6a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5579bd6a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5579bd73ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5579c0709f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5579c0709f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5579c0709f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5579c0709f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5579c0709f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5579c0709f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5579c0709f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5579c0709f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5579c0709f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5579c0709f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579c299ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5579bf6cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5579bf6d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5579bf482c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5579bf482c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5579bf483738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5579bf482874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5579bf482874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5579bf482874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5579c3d8cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5579c3d95928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5579c3d7d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5579c3da8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4d4e625082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5579bd6a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x67,0x6c,0x79,0x66,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x67,0x3f,0x74,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x66,0x67,0x7f,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x7f,0x66,0x2b,0x67,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x66,0x67,0x7f,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x67,0x7f,0x66,0x2b,0x67,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x6e, Step #5: tglyffg\177f;g?tglyg?tglyf?g?g?fg\177fg\177f;g?tg\177f+gf?f;g?tglyf?g?g?fg\177fg\177f;g?tglyg\177f+gf?f;g?tglyf?g?g?n Step #5: artifact_prefix='./'; Test unit written to ./oom-ba4f532eb384ee70df6fac467bc99cd490291c1f Step #5: Base64: dGdseWZmZ39mO2c/dGdseWc/dGdseWY/Zz9nP2Znf2Znf2Y7Zz90Z39mK2dmP2Y7Zz90Z2x5Zj9nP2c/Zmd/Zmd/ZjtnP3RnbHlnf2YrZ2Y/ZjtnP3RnbHlmP2c/Zz9u Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4005 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3710901298 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56193c4ae810, 0x56193c69801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56193c698020,0x56193e5300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba4f532eb384ee70df6fac467bc99cd490291c1f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4972 processed earlier; will process 6057 files now Step #5: #1 pulse cov: 3493 ft: 3494 exec/s: 0 rss: 174Mb Step #5: ==144256== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561932fa39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561939608898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5619395eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5619395eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561932fa9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561932f0ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561932f05355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561932f9bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561935f6af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561935f6af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561935f6af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561935f6af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561935f6af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561935f6af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561935f6af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561935f6af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561935f6af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561935f6af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5619381fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561934f2cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561934f37be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561934ce3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561934ce3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561934ce4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561934ce3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561934ce3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561934ce3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5619395edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5619395f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5619395de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561939609112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2bb5520082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561932f03b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa,0x3d,0xd,0xa, Step #5: =\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012=\015\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-99eff42159ca2041948815db841ad638be57d146 Step #5: Base64: PQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0KPQ0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4006 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3711451798 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562bfdd46810, 0x562bfdf3001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562bfdf30020,0x562bffdc80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/99eff42159ca2041948815db841ad638be57d146' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4974 processed earlier; will process 6055 files now Step #5: ==144292== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562bf483b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562bfaea0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562bfae835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562bfae834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562bf4841d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562bf47a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562bf479d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562bf4833c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562bf7802f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562bf7802f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562bf7802f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562bf7802f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562bf7802f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562bf7802f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562bf7802f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562bf7802f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562bf7802f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562bf7802f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562bf9a97f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562bf67c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562bf67cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562bf657bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562bf657bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562bf657c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562bf657b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562bf657b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562bf657b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562bfae85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562bfae8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562bfae76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562bfaea1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd9c6d0e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562bf479bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0xd,0xd,0x4e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd,0x24,0xd,0xd,0x4e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd,0x28,0xd,0xd,0x4e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd,0x28,0xd,0xd,0x4e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd,0x24,0xd,0xd,0x4e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd,0x28,0xd,0xd,0x4e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd,0x24,0xd,0xd,0x6e,0xd,0xd, Step #5: (\015\015N\015\015$\015\015n\015\015$\015\015N\015\015$\015\015n\015\015(\015\015N\015\015$\015\015n\015\015$\015\015n\015\015$\015\015n\015\015(\015\015N\015\015$\015\015n\015\015$\015\015N\015\015$\015\015n\015\015(\015\015N\015\015$\015\015n\015\015$\015\015n\015\015$\015\015n\015\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-a8f1083e2a07ac1a46ec60ecedfdcbd5a6e2dbbb Step #5: Base64: KA0NTg0NJA0Nbg0NJA0NTg0NJA0Nbg0NKA0NTg0NJA0Nbg0NJA0Nbg0NJA0Nbg0NKA0NTg0NJA0Nbg0NJA0NTg0NJA0Nbg0NKA0NTg0NJA0Nbg0NJA0Nbg0NJA0Nbg0N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4007 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3711962887 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea46d75810, 0x55ea46f5f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea46f5f020,0x55ea48df70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a8f1083e2a07ac1a46ec60ecedfdcbd5a6e2dbbb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4975 processed earlier; will process 6054 files now Step #5: #1 pulse cov: 3910 ft: 3911 exec/s: 0 rss: 173Mb Step #5: ==144328== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ea3d86a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea43ecf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea43eb25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea43eb24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea3d870d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea3d7d1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea3d7cc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea3d862c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea40831f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea40831f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea40831f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea40831f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea40831f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea40831f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea40831f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea40831f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea40831f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea40831f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea42ac6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea3f7f3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea3f7febe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea3f5aac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea3f5aac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea3f5ab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea3f5aa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea3f5aa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea3f5aa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea43eb4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea43ebd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea43ea5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea43ed0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd8b92cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea3d7cab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9,0xe2,0x80,0xa9, Step #5: \342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251\342\200\251 Step #5: artifact_prefix='./'; Test unit written to ./oom-677519a8cce509d54d068166909534242dbba7c6 Step #5: Base64: 4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp4oCp Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4008 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3712490289 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a226802810, 0x55a2269ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a2269ec020,0x55a2288840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/677519a8cce509d54d068166909534242dbba7c6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4977 processed earlier; will process 6052 files now Step #5: ==144364== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a21d2f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a22395c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a22393f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a22393f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a21d2fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a21d25eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a21d259355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a21d2efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a2202bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a2202bef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a2202bef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a2202bef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a2202bef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a2202bef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a2202bef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a2202bef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a2202bef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a2202bef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a222553f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a21f280b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a21f28bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a21f037c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a21f037c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a21f038738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a21f037874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a21f037874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a21f037874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a223941abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a22394a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a223932699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a22395d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc64c69b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a21d257b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x33,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x34,0x5c,0x37,0x37,0x5c,0x37,0x36,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x35,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x36,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x33, Step #5: \\77\\77\\77\\77\\77\\77\\77\\73\\77\\77\\74\\77\\76\\77\\77\\57\\77\\77\\77\\77\\77\\77\\77\\76\\77\\77\\77\\77\\77\\77\\77\\73 Step #5: artifact_prefix='./'; Test unit written to ./oom-92e9024f05ec71f7477741b3f40f0d279a9383cc Step #5: Base64: XDc3XDc3XDc3XDc3XDc3XDc3XDc3XDczXDc3XDc3XDc0XDc3XDc2XDc3XDc3XDU3XDc3XDc3XDc3XDc3XDc3XDc3XDc3XDc2XDc3XDc3XDc3XDc3XDc3XDc3XDc3XDcz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4009 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3712995180 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9bcdda810, 0x55e9bcfc401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9bcfc4020,0x55e9bee5c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92e9024f05ec71f7477741b3f40f0d279a9383cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4978 processed earlier; will process 6051 files now Step #5: ==144400== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e9b38cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9b9f34898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9b9f175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9b9f174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9b38d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e9b3836b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e9b3831355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9b38c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e9b6896f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e9b6896f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e9b6896f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e9b6896f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e9b6896f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e9b6896f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e9b6896f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e9b6896f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e9b6896f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e9b6896f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9b8b2bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e9b5858b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e9b5863be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9b560fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9b560fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9b5610738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9b560f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9b560f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9b560f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e9b9f19abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9b9f22928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e9b9f0a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e9b9f35112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3957f41082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e9b382fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x68,0x6f,0x4e,0x2f,0x0,0x0,0x0,0x4e,0x0,0x0,0x0,0x0,0x4b,0x2b,0xa,0x2b,0x2b,0x2,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4b,0x2b,0xa,0x2b,0x2b,0x2,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4b,0x2b,0xa,0x2b,0x2b,0x2,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x46,0x32,0x2b,0xdc, Step #5: hoN/\000\000\000N\000\000\000\000K+\012++\002\012\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000K+\012++\002\012\000\000\000\000\000\000\000\000\000\000\000\000\000K+\012++\002\012\000\000\000\000\000\000\000\000\000\000\000F2+\334 Step #5: artifact_prefix='./'; Test unit written to ./oom-75a9ebe8951910205f8c720f6259bbaa12d53e69 Step #5: Base64: aG9OLwAAAE4AAAAASysKKysCCgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAASysKKysCCgAAAAAAAAAAAAAAAABLKworKwIKAAAAAAAAAAAAAABGMivc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4010 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3713496675 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557766080810, 0x55776626a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55776626a020,0x5577681020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/75a9ebe8951910205f8c720f6259bbaa12d53e69' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4979 processed earlier; will process 6050 files now Step #5: ==144436== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55775cb759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5577631da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5577631bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5577631bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55775cb7bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55775cadcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55775cad7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55775cb6dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55775fb3cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55775fb3cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55775fb3cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55775fb3cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55775fb3cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55775fb3cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55775fb3cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55775fb3cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55775fb3cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55775fb3cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557761dd1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55775eafeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55775eb09be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55775e8b5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55775e8b5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55775e8b6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55775e8b5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55775e8b5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55775e8b5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5577631bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5577631c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5577631b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5577631db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7facb9dbd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55775cad5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xee,0x9b,0x8f,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x97,0x8e,0xee,0x9b,0x8f,0xe1,0x97,0x8e,0xe9,0x8c,0x8f,0xee,0x93,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x9b,0x8f,0xe1,0x9b,0x9d,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xe1,0x9b,0x9d,0xe1,0x9b,0x87,0xe1,0x8b,0x8f,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x9b,0x9d,0xe2,0x9b,0x8f,0xe1,0x8b,0x8f,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0xa1,0x8f,0xee,0x9b,0x8f,0xe1,0x8b,0x8f,0xe1,0x8b,0x8f,0xe1,0xb4,0x9b, Step #5: \356\233\217\341\233\217\341\213\217\356\233\217\341\227\216\356\233\217\341\227\216\351\214\217\356\223\217\341\213\217\356\233\217\341\233\217\341\233\235\341\233\217\341\213\217\341\233\235\341\233\207\341\213\217\341\233\217\341\213\217\356\233\217\341\233\235\342\233\217\341\213\217\341\233\217\341\213\217\356\233\217\341\241\217\356\233\217\341\213\217\341\213\217\341\264\233 Step #5: artifact_prefix='./'; Test unit written to ./oom-ba84b17d4041e22457c71586c2b8f2f31918414f Step #5: Base64: 7puP4ZuP4YuP7puP4ZeO7puP4ZeO6YyP7pOP4YuP7puP4ZuP4Zud4ZuP4YuP4Zud4ZuH4YuP4ZuP4YuP7puP4Zud4puP4YuP4ZuP4YuP7puP4aGP7puP4YuP4YuP4bSb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4011 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3714007767 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5648bf336810, 0x5648bf52001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5648bf520020,0x5648c13b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba84b17d4041e22457c71586c2b8f2f31918414f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4980 processed earlier; will process 6049 files now Step #5: ==144472== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5648b5e2b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5648bc490898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5648bc4735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5648bc4734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5648b5e31d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5648b5d92b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5648b5d8d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5648b5e23c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5648b8df2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5648b8df2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5648b8df2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5648b8df2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5648b8df2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5648b8df2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5648b8df2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5648b8df2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5648b8df2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5648b8df2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5648bb087f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5648b7db4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5648b7dbfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5648b7b6bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5648b7b6bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5648b7b6c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5648b7b6b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5648b7b6b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5648b7b6b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5648bc475abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5648bc47e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5648bc466699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5648bc491112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f190ccf8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5648b5d8bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0xc2,0x85,0x5c,0xc2,0x85,0x5b,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x41,0xc2,0x85,0x7c,0xc2,0x85,0x5c,0xc2,0x85,0x5b,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x24,0xc2,0x85,0x5c,0xc2,0x85,0x5b,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x41,0xc2,0x85,0x7c,0xc2,0x85,0x5c,0xc2,0x85,0x5b,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x41,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5d,0xc2,0x85,0x41,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5d,0xc2,0x85, Step #5: $\302\205\\\302\205[\302\205\\\302\205\\\302\205A\302\205|\302\205\\\302\205[\302\205\\\302\205\\\302\205$\302\205\\\302\205[\302\205\\\302\205\\\302\205A\302\205|\302\205\\\302\205[\302\205\\\302\205\\\302\205A\302\205\\\302\205\\\302\205\\\302\205]\302\205A\302\205\\\302\205\\\302\205\\\302\205]\302\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-56dad31da9c280008911cb07f2d57b60f6041507 Step #5: Base64: JMKFXMKFW8KFXMKFXMKFQcKFfMKFXMKFW8KFXMKFXMKFJMKFXMKFW8KFXMKFXMKFQcKFfMKFXMKFW8KFXMKFXMKFQcKFXMKFXMKFXMKFXcKFQcKFXMKFXMKFXMKFXcKF Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4012 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3714515818 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611af926810, 0x5611afb1001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5611afb10020,0x5611b19a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56dad31da9c280008911cb07f2d57b60f6041507' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4981 processed earlier; will process 6048 files now Step #5: #1 pulse cov: 4149 ft: 4150 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 4416 ft: 4802 exec/s: 0 rss: 174Mb Step #5: ==144508== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5611a641b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5611aca80898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611aca635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611aca634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5611a6421d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5611a6382b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5611a637d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5611a6413c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5611a93e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5611a93e2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5611a93e2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5611a93e2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5611a93e2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5611a93e2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5611a93e2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5611a93e2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5611a93e2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5611a93e2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5611ab677f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611a83a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5611a83afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611a815bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611a815bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611a815c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611a815b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611a815b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611a815b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5611aca65abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5611aca6e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611aca56699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5611aca81112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fccd0ac8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5611a637bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xeb,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80, Step #5: \341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\353\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-ff4fede5a36b6522a4d2c9c4140266bc60e90148 Step #5: Base64: 4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA65qA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4013 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3715099564 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bcb9053810, 0x55bcb923d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bcb923d020,0x55bcbb0d50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ff4fede5a36b6522a4d2c9c4140266bc60e90148' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4984 processed earlier; will process 6045 files now Step #5: ==144544== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bcafb489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bcb61ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bcb61905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bcb61904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bcafb4ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bcafaafb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bcafaaa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bcafb40c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bcb2b0ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bcb2b0ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bcb2b0ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bcb2b0ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bcb2b0ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bcb2b0ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bcb2b0ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bcb2b0ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bcb2b0ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bcb2b0ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bcb4da4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bcb1ad1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bcb1adcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bcb1888c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bcb1888c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bcb1889738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bcb1888874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bcb1888874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bcb1888874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bcb6192abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bcb619b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bcb6183699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bcb61ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb49cb6a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bcafaa8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa, Step #5: \\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012\\\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-8ea7360a76a17f87739f6f72d236a626b02a705b Step #5: Base64: XAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoKXAoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4014 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3715610381 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a167dc810, 0x561a169c601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a169c6020,0x561a1885e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ea7360a76a17f87739f6f72d236a626b02a705b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4985 processed earlier; will process 6044 files now Step #5: ==144580== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561a0d2d19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561a13936898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561a139195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561a139194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561a0d2d7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561a0d238b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561a0d233355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561a0d2c9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561a10298f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561a10298f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561a10298f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561a10298f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561a10298f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561a10298f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561a10298f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561a10298f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561a10298f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561a10298f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561a1252df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561a0f25ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561a0f265be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561a0f011c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561a0f011c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561a0f012738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561a0f011874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561a0f011874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561a0f011874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561a1391babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561a13924928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561a1390c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561a13937112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdadd35f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561a0d231b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x9,0x45,0x47,0x4b,0x60,0x20,0x2d,0x45,0x47,0x4b,0x60,0x20,0x42,0x42,0x42,0x45,0x47,0x4b,0x60,0x20,0x2d,0x45,0x47,0x4b,0x60,0x20,0x42,0x42,0x42,0x3d,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x41,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x64,0x41,0x41,0x41,0x54,0x74,0x2f,0x43,0x42,0x2d,0x0,0x0,0x0,0x87,0x28,0x0,0x0,0x0,0xa,0x2d,0x60,0x64,0xa,0x64,0xa,0x3f, Step #5: s-----\011EGK` -EGK` BBBEGK` -EGK` BBB=BBBBBBBBBATTTTTTTTppppppppppppppppdAAATt/CB-\000\000\000\207(\000\000\000\012-`d\012d\012? Step #5: artifact_prefix='./'; Test unit written to ./oom-3e7aa7c5cdb2ca13288271056598fc7b2018daea Step #5: Base64: cy0tLS0tCUVHS2AgLUVHS2AgQkJCRUdLYCAtRUdLYCBCQkI9QkJCQkJCQkJCQVRUVFRUVFRUcHBwcHBwcHBwcHBwcHBwcGRBQUFUdC9DQi0AAACHKAAAAAotYGQKZAo/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4015 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3716240709 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5582ba332810, 0x5582ba51c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5582ba51c020,0x5582bc3b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3e7aa7c5cdb2ca13288271056598fc7b2018daea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4986 processed earlier; will process 6043 files now Step #5: ==144616== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5582b0e279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5582b748c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5582b746f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5582b746f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5582b0e2dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5582b0d8eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5582b0d89355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5582b0e1fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5582b3deef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5582b3deef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5582b3deef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5582b3deef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5582b3deef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5582b3deef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5582b3deef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5582b3deef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5582b3deef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5582b3deef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5582b6083f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5582b2db0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5582b2dbbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5582b2b67c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5582b2b67c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5582b2b68738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5582b2b67874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5582b2b67874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5582b2b67874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5582b7471abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5582b747a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5582b7462699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5582b748d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f5d421082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5582b0d87b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba, Step #5: \012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-2b1797e8ee502b30a3bc084ea0b7284f2f3cad16 Step #5: Base64: Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4016 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3716750763 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c1788a7810, 0x55c178a9101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c178a91020,0x55c17a9290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2b1797e8ee502b30a3bc084ea0b7284f2f3cad16' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4987 processed earlier; will process 6042 files now Step #5: ==144652== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c16f39c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c175a01898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c1759e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c1759e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c16f3a2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c16f303b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c16f2fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c16f394c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c172363f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c172363f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c172363f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c172363f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c172363f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c172363f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c172363f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c172363f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c172363f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c172363f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c1745f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c171325b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c171330be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c1710dcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c1710dcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c1710dd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c1710dc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c1710dc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c1710dc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c1759e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c1759ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c1759d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c175a02112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a8bea5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c16f2fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xaf,0xe0,0xa8,0x6d, Step #5: \340\264\277\340\260\267\340\260\267\340\260\267\340\264\277\340\264\277\340\260\267\340\264\277\340\264\277\340\260\277\340\264\277\340\260\267\340\260\267\340\260\267\340\264\277\340\264\277\340\260\267\340\264\277\340\260\267\340\260\267\340\260\267\340\264\277\340\264\277\340\260\267\340\260\267\340\260\267\340\264\277\340\264\277\340\264\277\340\264\277\340\260\257\340\250m Step #5: artifact_prefix='./'; Test unit written to ./oom-e73b4fef7d653547431d2ec465e7010ac0bd847d Step #5: Base64: 4LS/4LC34LC34LC34LS/4LS/4LC34LS/4LS/4LC/4LS/4LC34LC34LC34LS/4LS/4LC34LS/4LC34LC34LC34LS/4LS/4LC34LC34LC34LS/4LS/4LS/4LS/4LCv4Kht Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4017 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3717252548 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9b5f3f810, 0x55a9b612901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a9b6129020,0x55a9b7fc10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e73b4fef7d653547431d2ec465e7010ac0bd847d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4988 processed earlier; will process 6041 files now Step #5: ==144688== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a9aca349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a9b3099898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9b307c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9b307c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a9aca3ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a9ac99bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a9ac996355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a9aca2cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9af9fbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9af9fbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9af9fbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9af9fbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9af9fbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9af9fbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9af9fbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9af9fbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9af9fbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9af9fbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a9b1c90f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a9ae9bdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a9ae9c8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a9ae774c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a9ae774c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a9ae775738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a9ae774874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a9ae774874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a9ae774874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a9b307eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a9b3087928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a9b306f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a9b309a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e23cd2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a9ac994b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6d,0x61,0x78,0x70,0xa,0x2d,0x2d,0x2d,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x5b,0x0,0x2d,0xe1,0xb7,0xbf,0x56,0x56,0x56,0x56,0x56,0x76,0x56,0x56,0x56,0x56,0x56,0xf,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x5b,0x0,0x2d,0xe1,0xb7,0xbf,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0xa,0x3, Step #5: maxp\012---VVVVVVVVVVVVV[\000-\341\267\277VVVVVvVVVVV\017--BEGIN ---[\000-\341\267\277\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\011\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012\012\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-40d2b996e92586f64bccb2bf93a32f18b58fb73e Step #5: Base64: bWF4cAotLS1WVlZWVlZWVlZWVlZWWwAt4be/VlZWVlZ2VlZWVlYPLS1CRUdJTiAtLS1bAC3ht78AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAkAAAAAAAAAAAAAAAAAAAoKAw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4018 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3717763126 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f194074810, 0x55f19425e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f19425e020,0x55f1960f60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40d2b996e92586f64bccb2bf93a32f18b58fb73e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4989 processed earlier; will process 6040 files now Step #5: ==144724== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f18ab699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f1911ce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1911b15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1911b14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f18ab6fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f18aad0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f18aacb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f18ab61c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f18db30f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f18db30f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f18db30f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f18db30f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f18db30f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f18db30f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f18db30f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f18db30f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f18db30f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f18db30f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f18fdc5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f18caf2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f18cafdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f18c8a9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f18c8a9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f18c8aa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f18c8a9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f18c8a9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f18c8a9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f1911b3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f1911bc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f1911a4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f1911cf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2d00bb5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f18aac9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x58,0x44,0x22,0x3d,0x3f,0x35,0xe6,0xbe,0x8e,0xe6,0x8e,0x8f,0xe6,0x8c,0x8e,0x30,0x38,0xe6,0xbd,0x8f,0x31,0xe2,0xbe,0x8e,0x3f,0x33,0xe6,0x73,0x74,0x4e,0x75,0x6d,0x62,0xbe,0x8e,0xe6,0x8e,0x8f,0xe6,0xb9,0x8e,0x3f,0x38,0xe6,0x8c,0x8e,0x31,0x28,0x29,0xe6,0x8c,0x8e,0x31,0x28,0xe6,0xbe,0x8f,0x32,0xe2,0xbe,0x8e,0x3f,0x31,0xe6,0xb9,0x8e,0x3f,0x31,0xe6,0xbe,0x8e,0xe6,0x8e,0x8f,0xe6,0x8c,0x8e,0x30,0x2b,0xe6,0xbe,0x8f,0x30,0xe2,0xbe,0x8e,0x3f,0x31,0xe6,0xb9,0x8e,0x3f,0x31,0xe6,0xe6, Step #5: HUXD\"=?5\346\276\216\346\216\217\346\214\21608\346\275\2171\342\276\216?3\346stNumb\276\216\346\216\217\346\271\216?8\346\214\2161()\346\214\2161(\346\276\2172\342\276\216?1\346\271\216?1\346\276\216\346\216\217\346\214\2160+\346\276\2170\342\276\216?1\346\271\216?1\346\346 Step #5: artifact_prefix='./'; Test unit written to ./oom-6b65336f18bff7525d8976a0653bbae991c8bab4 Step #5: Base64: SFVYRCI9PzXmvo7mjo/mjI4wOOa9jzHivo4/M+ZzdE51bWK+juaOj+a5jj845oyOMSgp5oyOMSjmvo8y4r6OPzHmuY4/Mea+juaOj+aMjjAr5r6PMOK+jj8x5rmOPzHm5g== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4019 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3718265071 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559696362810, 0x55969654c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55969654c020,0x5596983e40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b65336f18bff7525d8976a0653bbae991c8bab4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4990 processed earlier; will process 6039 files now Step #5: ==144760== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55968ce579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5596934bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55969349f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55969349f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55968ce5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55968cdbeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55968cdb9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55968ce4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55968fe1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55968fe1ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55968fe1ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55968fe1ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55968fe1ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55968fe1ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55968fe1ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55968fe1ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55968fe1ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55968fe1ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596920b3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55968ede0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55968edebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55968eb97c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55968eb97c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55968eb98738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55968eb97874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55968eb97874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55968eb97874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5596934a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5596934aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559693492699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5596934bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4bab4b3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55968cdb7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x52,0x52,0x52,0x52,0x52,0x52,0x52,0x52,0x52,0x52,0x52,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x3a,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x0,0x3b,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d, Step #5: }RRRRRRRRRRR} {0,}${0,} {0,} {0,}}{0,} {0,} {0,}}{0,} {0,} {0,}\007 {0,}s{0:,} {0,}${0,\000;} {0,} {0,} Step #5: artifact_prefix='./'; Test unit written to ./oom-2bbe8417abef169ed4dd22d72d9ee5c8956b8d2c Step #5: Base64: fVJSUlJSUlJSUlJSfSB7MCx9JHswLH0gezAsfSB7MCx9fXswLH0gezAsfSB7MCx9fXswLH0gezAsfSB7MCx9ByB7MCx9c3swOix9IHswLH0kezAsADt9IHswLH0gezAsfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4020 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3718774210 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5581276e8810, 0x5581278d201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5581278d2020,0x55812976a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2bbe8417abef169ed4dd22d72d9ee5c8956b8d2c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4991 processed earlier; will process 6038 files now Step #5: ==144796== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55811e1dd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558124842898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5581248255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5581248254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55811e1e3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55811e144b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55811e13f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55811e1d5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5581211a4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5581211a4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5581211a4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5581211a4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5581211a4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5581211a4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5581211a4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5581211a4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5581211a4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5581211a4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558123439f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558120166b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558120171be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55811ff1dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55811ff1dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55811ff1e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55811ff1d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55811ff1d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55811ff1d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558124827abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558124830928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558124818699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558124843112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd61dd41082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55811e13db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x6,0x31,0x4d,0x2d,0x2,0x1e,0x43,0x48,0x41,0x48,0x41,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4f,0xff,0xff,0xff,0xfa, Step #5: ID3\002\0061M-\002\036CHAHA\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000?\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000O\377\377\377\372 Step #5: artifact_prefix='./'; Test unit written to ./oom-803ccb6fbbbfb481a0195759e6de816e21ec9b63 Step #5: Base64: SUQzAgYxTS0CHkNIQUhBAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABP////+g== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4021 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3719279558 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d7267e5810, 0x55d7269cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d7269cf020,0x55d7288670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/803ccb6fbbbfb481a0195759e6de816e21ec9b63' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4992 processed earlier; will process 6037 files now Step #5: #1 pulse cov: 3741 ft: 3742 exec/s: 0 rss: 173Mb Step #5: ==144832== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d71d2da9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d72393f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7239225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7239224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d71d2e0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d71d241b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d71d23c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d71d2d2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d7202a1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d7202a1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d7202a1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d7202a1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d7202a1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d7202a1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d7202a1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d7202a1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d7202a1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d7202a1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d722536f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d71f263b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d71f26ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d71f01ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d71f01ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d71f01b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d71f01a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d71f01a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d71f01a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d723924abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d72392d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d723915699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d723940112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa8c8442082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d71d23ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0xd, Step #5: <B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B>\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-482c09ca641b5678188d1304b2e36b893602406a Step #5: Base64: PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+DQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4022 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3719812509 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556307a49810, 0x556307c3301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556307c33020,0x556309acb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/482c09ca641b5678188d1304b2e36b893602406a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4994 processed earlier; will process 6035 files now Step #5: ==144868== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5562fe53e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556304ba3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556304b865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556304b864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5562fe544d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5562fe4a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5562fe4a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5562fe536c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556301505f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556301505f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556301505f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556301505f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556301505f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556301505f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556301505f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556301505f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556301505f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556301505f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55630379af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5563004c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5563004d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55630027ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55630027ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55630027f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55630027e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55630027e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55630027e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556304b88abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556304b91928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556304b79699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556304ba4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f840a7d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5562fe49eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x45,0x44,0x44,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x73,0x74,0x72,0x65,0x61,0x6d,0x40,0x3e,0x3e,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x7e,0x48,0x41,0xa1,0xe1, Step #5: ID3DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDEDD>>>>>>stream@>>DDDDDDDD~HA\241\341 Step #5: artifact_prefix='./'; Test unit written to ./oom-a8a4759b9274b9ca2021c46fea69036453860789 Step #5: Base64: SUQzRERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERUREPj4+Pj4+c3RyZWFtQD4+RERERERERER+SEGh4Q== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4023 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3720320568 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564284def810, 0x564284fd901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564284fd9020,0x564286e710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a8a4759b9274b9ca2021c46fea69036453860789' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4995 processed earlier; will process 6034 files now Step #5: ==144904== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56427b8e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564281f49898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564281f2c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564281f2c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56427b8ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56427b84bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56427b846355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56427b8dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56427e8abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56427e8abf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56427e8abf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56427e8abf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56427e8abf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56427e8abf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56427e8abf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56427e8abf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56427e8abf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56427e8abf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564280b40f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56427d86db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56427d878be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56427d624c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56427d624c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56427d625738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56427d624874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56427d624874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56427d624874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564281f2eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564281f37928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564281f1f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564281f4a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7643983082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56427b844b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0xa,0x60,0x20,0x1e,0x60,0x41,0x4c,0x49,0x41,0x53,0x5b,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x35,0x38,0x2c,0x31,0x38,0x34,0x34,0x36,0x37,0x34,0x34,0x30,0x37,0x33,0x37,0x30,0x34,0x38,0x30,0x38,0x35,0x37,0x37,0x2c,0x30,0x2c,0x5b,0x32,0x2c,0x31,0x33,0x37,0x36,0x31,0x32,0x32,0x38,0x32,0x30,0x32,0x31,0x34,0x30,0x33,0x34,0x39,0x32,0x33,0x5d,0x2c,0x2d,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x35,0x38,0x34,0x36,0x38,0x33,0x36,0x34,0x37,0x39,0x36,0x37,0x32,0x39,0x35,0x5d,0xe2,0x80,0x8d,0xa, Step #5: :\012` \036`ALIAS[214748358,18446744073704808577,0,[2,1376122820214034923],-2147483584683647967295]\342\200\215\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-5f4c304aceabec6b17a144a7ccbc1ed6d8443f00 Step #5: Base64: OgpgIB5gQUxJQVNbMjE0NzQ4MzU4LDE4NDQ2NzQ0MDczNzA0ODA4NTc3LDAsWzIsMTM3NjEyMjgyMDIxNDAzNDkyM10sLTIxNDc0ODM1ODQ2ODM2NDc5NjcyOTVd4oCNCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4024 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3720954799 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a57b94810, 0x555a57d7e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a57d7e020,0x555a59c160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f4c304aceabec6b17a144a7ccbc1ed6d8443f00' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4996 processed earlier; will process 6033 files now Step #5: ==144940== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555a4e6899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a54cee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a54cd15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a54cd14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a4e68fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a4e5f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a4e5eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a4e681c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a51650f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a51650f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a51650f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a51650f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a51650f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a51650f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a51650f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a51650f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a51650f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a51650f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a538e5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a50612b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a5061dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a503c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a503c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a503ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a503c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a503c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a503c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a54cd3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a54cdc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a54cc4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a54cef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff442408082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a4e5e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x84,0x8f,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x81,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x85,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb1,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x81,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0x41, Step #5: \341\204\217\341\205\260\341\204\221\341\205\260\341\204\201\341\205\260\341\204\221\341\205\260\341\204\221\341\205\260\341\204\221\341\205\260\341\204\221\341\205\260\341\204\221\341\205\260\341\204\205\341\205\260\341\204\221\341\205\261\341\204\221\341\205\260\341\204\221\341\205\260\341\204\221\341\205\252\341\204\221\341\205\260\341\204\201\341\205\252\341\204\221\341\205\260A Step #5: artifact_prefix='./'; Test unit written to ./oom-ddbc196a37ae00123dd9460aa3f01bbf9386980b Step #5: Base64: 4YSP4YWw4YSR4YWw4YSB4YWw4YSR4YWw4YSR4YWw4YSR4YWw4YSR4YWw4YSR4YWw4YSF4YWw4YSR4YWx4YSR4YWw4YSR4YWw4YSR4YWq4YSR4YWw4YSB4YWq4YSR4YWwQQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4025 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3721463237 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee9566d810, 0x55ee9585701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee95857020,0x55ee976ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ddbc196a37ae00123dd9460aa3f01bbf9386980b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4997 processed earlier; will process 6032 files now Step #5: ==144976== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ee8c1629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee927c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee927aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee927aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee8c168d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee8c0c9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee8c0c4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee8c15ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee8f129f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee8f129f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee8f129f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee8f129f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee8f129f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee8f129f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee8f129f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee8f129f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee8f129f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee8f129f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee913bef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee8e0ebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee8e0f6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee8dea2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee8dea2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee8dea3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee8dea2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee8dea2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee8dea2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee927acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee927b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee9279d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee927c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95af426082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee8c0c2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b,0x5d,0x2a,0x5b, Step #5: []*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[]*[ Step #5: artifact_prefix='./'; Test unit written to ./oom-3f5b34708104285bd461e238f621919413a2860e Step #5: Base64: W10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qW10qWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4026 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3721981280 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e7c3f96810, 0x55e7c418001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e7c4180020,0x55e7c60180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3f5b34708104285bd461e238f621919413a2860e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 4998 processed earlier; will process 6031 files now Step #5: #1 pulse cov: 3637 ft: 3638 exec/s: 0 rss: 175Mb Step #5: ==145012== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e7baa8b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e7c10f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7c10d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7c10d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e7baa91d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e7ba9f2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e7ba9ed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e7baa83c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e7bda52f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e7bda52f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e7bda52f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e7bda52f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e7bda52f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e7bda52f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e7bda52f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e7bda52f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e7bda52f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e7bda52f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e7bfce7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e7bca14b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e7bca1fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e7bc7cbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e7bc7cbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e7bc7cc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e7bc7cb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e7bc7cb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e7bc7cb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e7c10d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e7c10de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e7c10c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e7c10f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e58419082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e7ba9ebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27,0x27,0x5b,0x27, Step #5: ''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[''[' Step #5: artifact_prefix='./'; Test unit written to ./oom-30261dd336fb7234dd5289f5ede77850740d7296 Step #5: Base64: JydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJydbJw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4027 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3722534627 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652a39d8810, 0x5652a3bc201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652a3bc2020,0x5652a5a5a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/30261dd336fb7234dd5289f5ede77850740d7296' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5000 processed earlier; will process 6029 files now Step #5: ==145048== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56529a4cd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652a0b32898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652a0b155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652a0b154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56529a4d3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56529a434b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56529a42f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56529a4c5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56529d494f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56529d494f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56529d494f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56529d494f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56529d494f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56529d494f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56529d494f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56529d494f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56529d494f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56529d494f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56529f729f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56529c456b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56529c461be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56529c20dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56529c20dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56529c20e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56529c20d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56529c20d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56529c20d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652a0b17abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652a0b20928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652a0b08699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652a0b33112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c501c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56529a42db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x57,0x33,0x7a,0x2d,0x34,0x32,0x20,0x26,0x0,0x54,0x2,0x1,0x2,0x0,0x0,0x2,0x2b, Step #5: IDWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWW3z-42 &\000T\002\001\002\000\000\002+ Step #5: artifact_prefix='./'; Test unit written to ./oom-fd53582ecbfeeafd1dba59e8ab015537ae87c7f4 Step #5: Base64: SURXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXM3otNDIgJgBUAgECAAACKw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4028 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3723039663 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559b8cff6810, 0x559b8d1e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559b8d1e0020,0x559b8f0780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fd53582ecbfeeafd1dba59e8ab015537ae87c7f4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5001 processed earlier; will process 6028 files now Step #5: ==145084== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559b83aeb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559b8a150898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559b8a1335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559b8a1334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b83af1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b83a52b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b83a4d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b83ae3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b86ab2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b86ab2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b86ab2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b86ab2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b86ab2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b86ab2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b86ab2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b86ab2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b86ab2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b86ab2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559b88d47f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b85a74b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b85a7fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b8582bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b8582bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b8582c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b8582b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b8582b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b8582b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559b8a135abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559b8a13e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559b8a126699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559b8a151112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f82e1f33082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b83a4bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x8,0x0,0x7,0x2e,0x2b,0x42,0xdb,0xbe,0x75,0xdb,0xbe,0x2b,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x0,0x0,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x2b,0x39,0x39,0x39,0x0,0x7,0x2e,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x39,0x39,0x0,0x0,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x2b,0x2b,0x24,0x6e,0x24,0x3,0x3,0x52,0x8,0x0,0xf7,0xff, Step #5: - \010\000\007.+B\333\276u\333\276+99999999999\000\000999999999999999+999\000\007..23/\020.\177\000\000\0002\000\000\00099\000\000999999999999999999++$n$\003\003R\010\000\367\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-dbaaf1c009cf05431f89c50ade781300059f81e0 Step #5: Base64: LSAIAAcuK0LbvnXbvis5OTk5OTk5OTk5OQAAOTk5OTk5OTk5OTk5OTk5Kzk5OQAHLi4yMy8QLn8AAAAyAAAAOTkAADk5OTk5OTk5OTk5OTk5OTk5OSsrJG4kAwNSCAD3/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4029 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3723549416 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b85ec97810, 0x55b85ee8101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b85ee81020,0x55b860d190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dbaaf1c009cf05431f89c50ade781300059f81e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5002 processed earlier; will process 6027 files now Step #5: ==145120== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b85578c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b85bdf1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b85bdd45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b85bdd44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b855792d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b8556f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b8556ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b855784c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b858753f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b858753f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b858753f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b858753f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b858753f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b858753f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b858753f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b858753f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b858753f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b858753f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b85a9e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b857715b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b857720be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b8574ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b8574ccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b8574cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b8574cc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b8574cc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b8574cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b85bdd6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b85bddf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b85bdc7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b85bdf2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe0ad72a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b8556ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbc,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf, Step #5: \"\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\274\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-c9a7495205e5f864d4a4fd5989996a5fada24d6c Step #5: Base64: Iu+7v++7v++7v++7v++7v++7v++7v++8v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7vw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4030 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3724053862 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f84742b810, 0x55f84761501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f847615020,0x55f8494ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9a7495205e5f864d4a4fd5989996a5fada24d6c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5003 processed earlier; will process 6026 files now Step #5: ==145156== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f83df209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f844585898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8445685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8445684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f83df26d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f83de87b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f83de82355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f83df18c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f840ee7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f840ee7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f840ee7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f840ee7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f840ee7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f840ee7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f840ee7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f840ee7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f840ee7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f840ee7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f84317cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f83fea9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f83feb4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f83fc60c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f83fc60c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f83fc61738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f83fc60874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f83fc60874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f83fc60874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f84456aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f844573928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f84455b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f844586112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f98eb50f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f83de80b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x30,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x31,0x5c,0x5c,0x5c,0x5c,0x5c,0x3e,0xe0,0xa3,0xb3,0x5c,0x5b,0x5c,0x5c,0x54,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x54,0x4f,0x61,0xcc,0x8c,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0xe0,0xa3,0xb3,0x9,0xa,0x3c,0x73,0x79,0x6d,0x62,0x6f,0x6c,0x3e,0x3c,0x73,0x79,0x6d,0x62,0x6f,0x6c,0x3e,0x3c,0x73,0x79,0x6d,0x62,0x6f,0x6c,0x3e, Step #5: <svg><text>\\\\\\\\\\\\\\\\\\\\0\\\\\\\\\\\\1\\\\\\\\\\>\340\243\263\\[\\\\T\\\\\\\\\\\\\\\\\\\\\\\\\\TOa\314\214</text>\340\243\263\011\012<symbol><symbol><symbol> Step #5: artifact_prefix='./'; Test unit written to ./oom-2f46b814841e02232d11c7cc5070972d98ecfebe Step #5: Base64: PHN2Zz48dGV4dD5cXFxcXFxcXFxcMFxcXFxcXDFcXFxcXD7go7NcW1xcVFxcXFxcXFxcXFxcXFxUT2HMjDwvdGV4dD7go7MJCjxzeW1ib2w+PHN5bWJvbD48c3ltYm9sPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4031 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3724561321 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a05c32810, 0x560a05e1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a05e1c020,0x560a07cb40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f46b814841e02232d11c7cc5070972d98ecfebe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5004 processed earlier; will process 6025 files now Step #5: #1 pulse cov: 12580 ft: 12581 exec/s: 0 rss: 194Mb Step #5: ==145192== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5609fc7279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a02d8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a02d6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a02d6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5609fc72dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5609fc68eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5609fc689355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5609fc71fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5609ff6eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5609ff6eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5609ff6eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5609ff6eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5609ff6eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5609ff6eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5609ff6eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5609ff6eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5609ff6eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5609ff6eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a01983f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5609fe6b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5609fe6bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5609fe467c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5609fe467c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5609fe468738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5609fe467874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5609fe467874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5609fe467874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a02d71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a02d7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a02d62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a02d8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6d3f70b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5609fc687b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x4f,0x53,0x4f,0x53,0x53,0x54,0x27,0x3a,0x29, Step #5: ****************************************************************************************OSOSST':) Step #5: artifact_prefix='./'; Test unit written to ./oom-ecddd957c42d1dc877cb72e5c962540c78cd80fa Step #5: Base64: KioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKk9TT1NTVCc6KQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4032 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3725139266 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1ab571810, 0x55d1ab75b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1ab75b020,0x55d1ad5f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ecddd957c42d1dc877cb72e5c962540c78cd80fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5006 processed earlier; will process 6023 files now Step #5: ==145228== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d1a20669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1a86cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1a86ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1a86ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1a206cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1a1fcdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1a1fc8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1a205ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1a502df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1a502df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1a502df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1a502df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1a502df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1a502df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1a502df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1a502df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1a502df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1a502df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1a72c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1a3fefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1a3ffabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1a3da6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1a3da6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1a3da7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1a3da6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1a3da6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1a3da6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1a86b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1a86b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1a86a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1a86cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f258e6f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1a1fc6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x28,0x28,0x3f,0x3a,0x24,0x7c,0x7c,0x24,0x7c,0x24,0x7c,0x7c,0x24,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x7c,0x24,0x7c,0x24,0x7c,0x7c,0x24,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x7c,0x24,0x7c,0x24,0x7c,0x7c,0x24,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x7c,0x24,0x7c,0x24,0x7c,0x7c,0x24,0x29,0x7c,0x29,0x7c,0x29,0x7c, Step #5: (?:((?:$||$|$||$)|)|)|(?:(?:|(?:$||$|$||$)|)|)|(?:(?:|(?:$||$|$||$)|)|)|(?:(?:|(?:$||$|$||$)|)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-cd11565f2b1e7481a1f146e0631a8a7d40a804b3 Step #5: Base64: KD86KCg/OiR8fCR8JHx8JCl8KXwpfCg/Oig/OnwoPzokfHwkfCR8fCQpfCl8KXwoPzooPzp8KD86JHx8JHwkfHwkKXwpfCl8KD86KD86fCg/OiR8fCR8JHx8JCl8KXwpfA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4033 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3725661582 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5614b7b87810, 0x5614b7d7101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5614b7d71020,0x5614b9c090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd11565f2b1e7481a1f146e0631a8a7d40a804b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5007 processed earlier; will process 6022 files now Step #5: ==145264== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5614ae67c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5614b4ce1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5614b4cc45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5614b4cc44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5614ae682d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5614ae5e3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5614ae5de355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5614ae674c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5614b1643f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5614b1643f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5614b1643f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5614b1643f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5614b1643f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5614b1643f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5614b1643f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5614b1643f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5614b1643f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5614b1643f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5614b38d8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5614b0605b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5614b0610be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5614b03bcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5614b03bcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5614b03bd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5614b03bc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5614b03bc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5614b03bc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5614b4cc6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5614b4ccf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5614b4cb7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5614b4ce2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b2a189082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5614ae5dcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0xa,0x20,0x20,0xa,0x20,0x20,0xa,0x20,0x3a,0xa,0x20,0x2d,0xa,0x20,0x3a,0xa,0x20,0x3a,0xa,0x20,0x2d,0xa,0x20,0x3a,0xa,0x20,0x2d,0xa,0x20,0x3a,0xa,0x20,0x2d,0xa,0x20,0x3a,0xa,0x20,0x3a,0xa,0x20,0x2d,0xa,0x20,0x3a,0xa,0x20,0x2d,0xa,0x20,0x20,0xa,0x20,0x3a,0xa,0x20,0x2d,0xa,0x20,0x3a,0xa,0x20,0x3a,0xa,0x20,0x2d,0xa,0x20,0x3a,0xa,0x20,0x2d,0xa,0x20,0x3a,0xa,0x20,0x2d,0xa,0x20,0x3a,0xa,0x20,0x3a,0xa,0x20,0x2d,0xa,0x20,0x3a,0xa,0x20,0x2d,0xa,0x20,0x5c, Step #5: \012 \012 \012 :\012 -\012 :\012 :\012 -\012 :\012 -\012 :\012 -\012 :\012 :\012 -\012 :\012 -\012 \012 :\012 -\012 :\012 :\012 -\012 :\012 -\012 :\012 -\012 :\012 :\012 -\012 :\012 -\012 \\ Step #5: artifact_prefix='./'; Test unit written to ./oom-1797cd9bd8f6a5a19df94c87ce9df3f533036315 Step #5: Base64: IAogIAogIAogOgogLQogOgogOgogLQogOgogLQogOgogLQogOgogOgogLQogOgogLQogIAogOgogLQogOgogOgogLQogOgogLQogOgogLQogOgogOgogLQogOgogLQogXA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4034 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3726186758 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f83f807810, 0x55f83f9f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f83f9f1020,0x55f8418890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1797cd9bd8f6a5a19df94c87ce9df3f533036315' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5008 processed earlier; will process 6021 files now Step #5: ==145300== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8362fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f83c961898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f83c9445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f83c9444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f836302d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f836263b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f83625e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8362f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8392c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8392c3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8392c3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8392c3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8392c3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8392c3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8392c3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8392c3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8392c3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8392c3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f83b558f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f838285b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f838290be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f83803cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f83803cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f83803d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f83803c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f83803c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f83803c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f83c946abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f83c94f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f83c937699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f83c962112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb06485c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f83625cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x7e,0x3d,0x2d,0x3d,0x3d,0x1,0x79,0x0,0x0,0x0,0x0,0x73,0x65,0x72,0x69,0x66,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0x2d,0x3d,0x3d,0x1,0x79,0x0,0x0,0x0,0x0,0x73,0x65,0x72,0x69,0x66,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0xf,0x0,0x0,0x1e,0x24, Step #5: ~$~=-==\001y\000\000\000\000serif\000\000\000\000\000\000\000\000=-==\001y\000\000\000\000serif\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000'\017\000\000\036$ Step #5: artifact_prefix='./'; Test unit written to ./oom-ad229a46e0c1ab4831ee30018d226a9d43159827 Step #5: Base64: fiR+PS09PQF5AAAAAHNlcmlmAAAAAAAAAAA9LT09AXkAAAAAc2VyaWYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACcPAAAeJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4035 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3726703709 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652d9eaf810, 0x5652da09901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652da099020,0x5652dbf310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad229a46e0c1ab4831ee30018d226a9d43159827' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5009 processed earlier; will process 6020 files now Step #5: ==145336== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5652d09a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652d7009898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652d6fec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652d6fec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5652d09aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5652d090bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5652d0906355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5652d099cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5652d396bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5652d396bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5652d396bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5652d396bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5652d396bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5652d396bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5652d396bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5652d396bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5652d396bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5652d396bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652d5c00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5652d292db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5652d2938be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652d26e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652d26e4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652d26e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652d26e4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652d26e4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652d26e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652d6feeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652d6ff7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652d6fdf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652d700a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb353829082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5652d0904b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x7e,0x3d,0x2d,0x3d,0x3d,0x1,0x79,0x0,0x0,0x0,0x0,0x73,0x65,0x72,0x69,0x66,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x0,0x0,0x0,0x0,0x0,0x7e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0xf,0x0,0x0,0x1e,0x24, Step #5: ~$~=-==\001y\000\000\000\000serif\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000~\000\000\000\000\000\000\000\000\000\000\000\000'\000\000\000\000\000~\000\000\000\000\000\000\000\000\000\000\000\000'\017\000\000\036$ Step #5: artifact_prefix='./'; Test unit written to ./oom-ef24beb0d3fb339eda8e7a170d286c79aac13b9a Step #5: Base64: fiR+PS09PQF5AAAAAHNlcmlmAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB+AAAAAAAAAAAAAAAAJwAAAAAAfgAAAAAAAAAAAAAAACcPAAAeJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4036 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3727225208 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555cffa0a810, 0x555cffbf401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555cffbf4020,0x555d01a8c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ef24beb0d3fb339eda8e7a170d286c79aac13b9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5010 processed earlier; will process 6019 files now Step #5: ==145372== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555cf64ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555cfcb64898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555cfcb475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555cfcb474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555cf6505d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555cf6466b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555cf6461355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555cf64f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555cf94c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555cf94c6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555cf94c6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555cf94c6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555cf94c6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555cf94c6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555cf94c6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555cf94c6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555cf94c6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555cf94c6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555cfb75bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555cf8488b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555cf8493be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555cf823fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555cf823fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555cf8240738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555cf823f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555cf823f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555cf823f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555cfcb49abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555cfcb52928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555cfcb3a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555cfcb65112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6398379082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555cf645fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4c,0x9,0xd,0x9,0xd,0x9,0x8,0x9,0x18,0x9,0x2c,0x9,0x2f,0x9,0x8,0x9,0x24,0x9,0x1,0x9,0x8,0x9,0x2c,0x9,0x2f,0x9,0x8,0x9,0x24,0x9,0x1,0x9,0x5a,0x9,0xd,0x9,0x62,0x9,0x5,0x9,0x2f,0x9,0xa4,0x9,0x62,0x9,0x1,0x9,0x8,0x9,0x4c,0x9,0x2c,0x9,0x2f,0x9,0x8,0x9,0x18,0x9,0x2c,0x9,0x2f,0x9,0x8,0x9,0x24,0x9,0x1,0x9,0x8,0x9,0x2c,0x9,0x2f,0x9,0x8,0x9,0x24,0x9,0x1,0x9,0x5a,0x9,0xd,0x9,0x62,0x9,0x5,0x9,0x2f,0x9,0xa4,0x9,0xd,0x9,0x62, Step #5: L\011\015\011\015\011\010\011\030\011,\011/\011\010\011$\011\001\011\010\011,\011/\011\010\011$\011\001\011Z\011\015\011b\011\005\011/\011\244\011b\011\001\011\010\011L\011,\011/\011\010\011\030\011,\011/\011\010\011$\011\001\011\010\011,\011/\011\010\011$\011\001\011Z\011\015\011b\011\005\011/\011\244\011\015\011b Step #5: artifact_prefix='./'; Test unit written to ./oom-4396a3099689542598bf3ef0ee54788a3d73dab4 Step #5: Base64: TAkNCQ0JCAkYCSwJLwkICSQJAQkICSwJLwkICSQJAQlaCQ0JYgkFCS8JpAliCQEJCAlMCSwJLwkICRgJLAkvCQgJJAkBCQgJLAkvCQgJJAkBCVoJDQliCQUJLwmkCQ0JYg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4037 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3727735516 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e1dfb2810, 0x563e1e19c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e1e19c020,0x563e200340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4396a3099689542598bf3ef0ee54788a3d73dab4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5011 processed earlier; will process 6018 files now Step #5: ==145408== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563e14aa79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e1b10c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e1b0ef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e1b0ef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e14aadd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e14a0eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e14a09355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e14a9fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e17a6ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e17a6ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e17a6ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e17a6ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e17a6ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e17a6ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e17a6ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e17a6ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e17a6ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e17a6ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e19d03f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e16a30b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e16a3bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e167e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e167e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e167e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e167e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e167e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e167e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e1b0f1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e1b0fa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e1b0e2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e1b10d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8243523082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e14a07b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x17,0x0,0x0,0x0,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $22''2-=''''''/''2-=''''''''''''''-=<\027\000\000\000''''''''''''-=<'''/''''/''''''/''2-='''''''''''''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-23d3ee7861507c1e01cfc3883bd96fece02b1486 Step #5: Base64: JDIyJycyLT0nJycnJycvJycyLT0nJycnJycnJycnJycnJy09PBcAAAAnJycnJycnJycnJyctPTwnJycvJycnJy8nJycnJycvJycyLT0nJycnJycnJycnJycnJycuJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4038 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3728259566 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a2f2046810, 0x55a2f223001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a2f2230020,0x55a2f40c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/23d3ee7861507c1e01cfc3883bd96fece02b1486' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5012 processed earlier; will process 6017 files now Step #5: #1 pulse cov: 3889 ft: 3890 exec/s: 0 rss: 174Mb Step #5: ==145444== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a2e8b3b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a2ef1a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2ef1835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2ef1834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a2e8b41d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a2e8aa2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a2e8a9d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a2e8b33c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a2ebb02f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a2ebb02f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a2ebb02f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a2ebb02f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a2ebb02f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a2ebb02f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a2ebb02f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a2ebb02f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a2ebb02f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a2ebb02f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a2edd97f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a2eaac4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a2eaacfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a2ea87bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a2ea87bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a2ea87c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a2ea87b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a2ea87b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a2ea87b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a2ef185abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a2ef18e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2ef176699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a2ef1a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f57306e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a2e8a9bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x67,0x62,0x49,0x54,0x32,0x58,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x54,0x32,0x58,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xa9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x64,0x61,0x0,0x0,0x0,0x0,0xe2,0x80,0xa9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xa9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x43,0x4f,0x4d,0x2,0xdb,0xbf,0x9f,0xff, Step #5: ID3gbIT2X\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000T2X\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\342\200\251\000\000\000\000\000\000\000\000\000\000\000\000\000da\000\000\000\000\342\200\251\000\000\000\000\000\000\000\342\200\251\000\000\000\000\000\000\000COM\002\333\277\237\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-457bb3cedab0118185f58efe5b8eef963862b3a4 Step #5: Base64: SUQzZ2JJVDJYAAAAAAAAAAAAAAAAAAAAAFQyWAAAAAAAAAAAAAAAAAAAAAAAAADigKkAAAAAAAAAAAAAAAAAZGEAAAAA4oCpAAAAAAAAAOKAqQAAAAAAAABDT00C27+f/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4039 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3728808613 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56352c26e810, 0x56352c45801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56352c458020,0x56352e2f00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/457bb3cedab0118185f58efe5b8eef963862b3a4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5014 processed earlier; will process 6015 files now Step #5: ==145480== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563522d639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5635293c8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5635293ab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5635293ab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563522d69d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563522ccab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563522cc5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563522d5bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563525d2af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563525d2af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563525d2af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563525d2af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563525d2af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563525d2af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563525d2af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563525d2af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563525d2af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563525d2af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563527fbff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563524cecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563524cf7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563524aa3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563524aa3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563524aa4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563524aa3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563524aa3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563524aa3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5635293adabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5635293b6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56352939e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5635293c9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa23fac1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563522cc3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0xdd,0xdb,0x44,0x46,0x7e,0x7e,0x3,0x5d,0xdb,0xcc,0x47,0x91,0x47,0x49,0x44,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x1a,0x24,0x24,0x24,0x24,0xdd,0xdb,0x44,0x46,0x7e,0x7e,0x3,0x5d,0xdb,0xcc,0x47,0x91,0x47,0x24,0x24,0x2a,0xdd,0xdb,0x44,0x46,0x7e,0x7e,0x3,0x5d,0xdb,0xcc,0x47,0x91,0x47, Step #5: ID$$$$$$$$$$$$$$$$$$$$$$$$$$\335\333DF~~\003]\333\314G\221GID$$$$$$$$$$$$$$$$$$$$\032$$$$\335\333DF~~\003]\333\314G\221G$$*\335\333DF~~\003]\333\314G\221G Step #5: artifact_prefix='./'; Test unit written to ./oom-701821804965be4cf06771f752edac0be4234837 Step #5: Base64: SUQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJN3bREZ+fgNd28xHkUdJRCQkJCQkJCQkJCQkJCQkJCQkJCQkGiQkJCTd20RGfn4DXdvMR5FHJCQq3dtERn5+A13bzEeRRw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4040 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3729324744 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b107be1810, 0x55b107dcb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b107dcb020,0x55b109c630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/701821804965be4cf06771f752edac0be4234837' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5015 processed earlier; will process 6014 files now Step #5: ==145516== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b0fe6d69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b104d3b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b104d1e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b104d1e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0fe6dcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0fe63db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0fe638355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0fe6cec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b10169df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b10169df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b10169df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b10169df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b10169df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b10169df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b10169df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b10169df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b10169df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b10169df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b103932f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b10065fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b10066abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b100416c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b100416c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b100417738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b100416874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b100416874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b100416874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b104d20abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b104d29928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b104d11699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b104d3c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6d65943082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0fe636b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x65,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x65,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x65,0x25,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x42,0x2d,0x43,0x2d,0x2b,0x2b,0x2b,0x2b,0x2b,0x2a,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2a, Step #5: e-B-B-B-B-B-B-B-B-B-B-e-B-B-B-B-B-B-B-B-B-B-e-B-B-B-B-B-e%B-B-B-B-C-+++++*++++++++++++++++++++++* Step #5: artifact_prefix='./'; Test unit written to ./oom-077224e7304e88e29b913d393dd61b7b5d7cb300 Step #5: Base64: ZS1CLUItQi1CLUItQi1CLUItQi1CLWUtQi1CLUItQi1CLUItQi1CLUItQi1lLUItQi1CLUItQi1lJUItQi1CLUItQy0rKysrKyorKysrKysrKysrKysrKysrKysrKysrKg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4041 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3729831508 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d4b5690810, 0x55d4b587a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d4b587a020,0x55d4b77120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/077224e7304e88e29b913d393dd61b7b5d7cb300' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5016 processed earlier; will process 6013 files now Step #5: ==145552== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d4ac1859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d4b27ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d4b27cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d4b27cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d4ac18bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d4ac0ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d4ac0e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d4ac17dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d4af14cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d4af14cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d4af14cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d4af14cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d4af14cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d4af14cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d4af14cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d4af14cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d4af14cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d4af14cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d4b13e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d4ae10eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d4ae119be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d4adec5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d4adec5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d4adec6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d4adec5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d4adec5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d4adec5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d4b27cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d4b27d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d4b27c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d4b27eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbb90cc2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d4ac0e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2c,0x2b,0xb,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0xa,0xa,0x2b,0xb,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2b,0x2b,0xa,0x2b,0xa,0x2b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2b,0xa,0x2b,0x73,0x73,0x73,0x73,0x73,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0xa,0x2b,0x2b,0x2b,0x2b,0xa,0x2b,0xdf, Step #5: +\012+\012+\012,+\013\012+\012+\012+\012+\012\012\012+\013\000\000\000\000\000\000\000++\012+\012+\000\000\000\000\000\000\000\000\000\000\000\000\012+\012+ssssss\012+\012+\012+\012+\012+s\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012\012++++\012+\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-8ca534db9796e89a66b0dbd42903abbcce2fcbb4 Step #5: Base64: KworCisKLCsLCisKKworCisKCgorCwAAAAAAAAArKworCisAAAAAAAAAAAAAAAAKKworc3Nzc3NzCisKKworCisKK3MKKworCisKKworCisKKworCisKKwoKKysrKwor3w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4042 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3730362718 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559deb87f810, 0x559deba6901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559deba69020,0x559ded9010e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ca534db9796e89a66b0dbd42903abbcce2fcbb4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5017 processed earlier; will process 6012 files now Step #5: ==145588== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559de23749c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559de89d9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559de89bc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559de89bc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559de237ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559de22dbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559de22d6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559de236cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559de533bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559de533bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559de533bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559de533bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559de533bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559de533bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559de533bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559de533bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559de533bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559de533bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559de75d0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559de42fdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559de4308be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559de40b4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559de40b4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559de40b5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559de40b4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559de40b4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559de40b4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559de89beabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559de89c7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559de89af699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559de89da112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f48d74a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559de22d4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x3c,0xdb,0xbe,0xdb,0xbe,0x7e,0x73,0x73,0x73,0x73,0x73,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x31,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x7e,0xff,0xff,0xff,0x73,0x73,0xff,0xff,0xff,0x30,0x73,0x7e,0x7e,0x7e,0x31,0x73, Step #5: ~<\333\276\333\276~sssss%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%1sssssssssssssssssssssssssssssssss~\377\377\377ss\377\377\3770s~~~1s Step #5: artifact_prefix='./'; Test unit written to ./oom-70cf49ab93ac52a59d7d7d62d20e691f1089083b Step #5: Base64: fjzbvtu+fnNzc3NzJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUxc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzfv///3Nz////MHN+fn4xcw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4043 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3730868513 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56511fd39810, 0x56511ff2301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56511ff23020,0x565121dbb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70cf49ab93ac52a59d7d7d62d20e691f1089083b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5018 processed earlier; will process 6011 files now Step #5: ==145624== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56511682e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56511ce93898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56511ce765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56511ce764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565116834d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565116795b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565116790355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565116826c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5651197f5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5651197f5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5651197f5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5651197f5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5651197f5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5651197f5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5651197f5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5651197f5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5651197f5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5651197f5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56511ba8af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5651187b7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5651187c2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56511856ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56511856ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56511856f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56511856e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56511856e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56511856e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56511ce78abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56511ce81928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56511ce69699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56511ce94112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf815ae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56511678eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0x9d,0xe0,0xbd,0xb5,0xe0,0xbd,0xbc,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbc,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0x9d,0xe0,0xbd,0xb5,0xe0,0xbd,0xbc,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0x3d, Step #5: \340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\235\340\275\265\340\275\274\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\274\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\235\340\275\265\340\275\274\340\275\275\340\275\275\340\275\275= Step #5: artifact_prefix='./'; Test unit written to ./oom-fc9a6f46141f1bb0c1749cdc850036e318e91cab Step #5: Base64: 4L294L294L294L294L294L294L294L294L2d4L214L284L294L294L294L294L294L294Ly94L294L294L294L294L294L294L294L294L2d4L214L284L294L294L29PQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4044 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3731370726 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f57a54b810, 0x55f57a73501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f57a735020,0x55f57c5cd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc9a6f46141f1bb0c1749cdc850036e318e91cab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5019 processed earlier; will process 6010 files now Step #5: ==145660== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f5710409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f5776a5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f5776885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f5776884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f571046d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f570fa7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f570fa2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f571038c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f574007f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f574007f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f574007f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f574007f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f574007f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f574007f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f574007f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f574007f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f574007f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f574007f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f57629cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f572fc9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f572fd4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f572d80c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f572d80c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f572d81738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f572d80874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f572d80874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f572d80874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f57768aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f577693928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f57767b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f5776a6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f45da590082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f570fa0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x74,0xcd,0x9a,0x2c,0x61,0xcd,0x9a,0xcc,0x9e,0x2c,0x36,0xcd,0x9a,0xcc,0x9e,0x32,0xcd,0x99,0x2b,0xcd,0x9a,0xd8,0x9e,0xcd,0x9a,0xdf,0x9e,0x2d,0xcf,0x99,0xcc,0x9e,0x2c,0xcc,0x9e,0x32,0x31,0xcd,0x9a,0xcc,0x9e,0x2c,0xcd,0x9a,0xdc,0x9e,0x32,0xcd,0x99,0x2b,0x36,0x38,0xcd,0x9a,0xdf,0x9e,0xcd,0x9a,0x33,0xcd,0x9a,0xdf,0x9e,0x2d,0x38,0xcf,0x99,0x65,0xcc,0x9e,0x2c,0xcc,0x9e,0x2c,0xcd,0x9a,0xcc,0x9e,0x2c,0xcd,0x9a,0xcc,0x9e,0x32,0xcd,0x99,0x2b,0x30,0x4c,0xcd,0x9a,0xdf,0x9e,0x2c,0x7d,0x3a, Step #5: {t\315\232,a\315\232\314\236,6\315\232\314\2362\315\231+\315\232\330\236\315\232\337\236-\317\231\314\236,\314\23621\315\232\314\236,\315\232\334\2362\315\231+68\315\232\337\236\315\2323\315\232\337\236-8\317\231e\314\236,\314\236,\315\232\314\236,\315\232\314\2362\315\231+0L\315\232\337\236,}: Step #5: artifact_prefix='./'; Test unit written to ./oom-070f1567289dd2afcc83cf351b1f08fc834db0f7 Step #5: Base64: e3TNmixhzZrMniw2zZrMnjLNmSvNmtiezZrfni3PmcyeLMyeMjHNmsyeLM2a3J4yzZkrNjjNmt+ezZozzZrfni04z5llzJ4szJ4szZrMnizNmsyeMs2ZKzBMzZrfnix9Og== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4045 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3731878422 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555948be6810, 0x555948dd001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555948dd0020,0x55594ac680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/070f1567289dd2afcc83cf351b1f08fc834db0f7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5020 processed earlier; will process 6009 files now Step #5: ==145696== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55593f6db9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555945d40898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555945d235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555945d234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55593f6e1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55593f642b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55593f63d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55593f6d3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5559426a2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5559426a2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5559426a2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5559426a2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5559426a2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5559426a2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5559426a2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5559426a2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5559426a2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5559426a2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555944937f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555941664b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55594166fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55594141bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55594141bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55594141c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55594141b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55594141b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55594141b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555945d25abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555945d2e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555945d16699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555945d41112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f64ccbcc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55593f63bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x28,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x28,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x0,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x0,0x0,0x9c,0x36,0x35,0x35,0x33,0x35, Step #5: \000\000\000\000hhhhhhhhhhhhhhhhhhhhhhhhhh(hhhhhhhhhhhhhhhh(hhhhhhhh\000\000hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh\000\000\23465535 Step #5: artifact_prefix='./'; Test unit written to ./oom-c53ae6243adac07d37a74fd1a257f4ea5f5614e2 Step #5: Base64: AAAAAGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoKGhoaGhoaGhoaGhoaGhoaGgoaGhoaGhoaGgAAGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGgAAJw2NTUzNQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4046 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3732381636 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5600aaadf810, 0x5600aacc901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5600aacc9020,0x5600acb610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c53ae6243adac07d37a74fd1a257f4ea5f5614e2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5021 processed earlier; will process 6008 files now Step #5: ==145732== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5600a15d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5600a7c39898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5600a7c1c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5600a7c1c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5600a15dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5600a153bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5600a1536355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5600a15ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5600a459bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5600a459bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5600a459bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5600a459bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5600a459bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5600a459bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5600a459bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5600a459bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5600a459bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5600a459bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5600a6830f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5600a355db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5600a3568be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5600a3314c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5600a3314c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5600a3315738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5600a3314874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5600a3314874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5600a3314874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5600a7c1eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5600a7c27928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5600a7c0f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5600a7c3a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7ef49f2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5600a1534b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x9,0x0,0x0,0x0,0x0,0x0,0x4,0x2b,0xa,0x9,0x0,0x0,0x0,0x0,0x0,0x4,0x0,0x0,0x3d,0x20,0x7f,0x7f,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x21,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x20,0x3d,0x1d,0x0,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe9,0xe9,0xe9,0xe9,0xe9,0xe9,0xe9,0xe9,0xe9,0xe9,0x0,0x0,0x0,0x0,0x0,0x0,0x7e,0x29,0xeb,0x7c, Step #5: +\012\011\000\000\000\000\000\004+\012\011\000\000\000\000\000\004\000\000= \177\177\342\200\215\000\000(\342\200\256\000r+\002-\001\000\000\000\000ID3\002-!-----\012 =\035\000\256\200\256\200\256\200\256\200\000\000\000\000\000\000\000\000\000\000\000\351\351\351\351\351\351\351\351\351\351\000\000\000\000\000\000~)\353| Step #5: artifact_prefix='./'; Test unit written to ./oom-ed039ddc0871000a8e90c16c7493ab9d6ea2b0ab Step #5: Base64: KwoJAAAAAAAEKwoJAAAAAAAEAAA9IH9/4oCNAAAo4oCuAHIrAi0BAAAAAElEMwItIS0tLS0tCiA9HQCugK6AroCugAAAAAAAAAAAAAAA6enp6enp6enp6QAAAAAAAH4p63w= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4047 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3732891314 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559224d4d810, 0x559224f3701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559224f37020,0x559226dcf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ed039ddc0871000a8e90c16c7493ab9d6ea2b0ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5022 processed earlier; will process 6007 files now Step #5: ==145768== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55921b8429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559221ea7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559221e8a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559221e8a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55921b848d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55921b7a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55921b7a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55921b83ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55921e809f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55921e809f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55921e809f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55921e809f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55921e809f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55921e809f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55921e809f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55921e809f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55921e809f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55921e809f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559220a9ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55921d7cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55921d7d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55921d582c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55921d582c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55921d583738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55921d582874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55921d582874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55921d582874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559221e8cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559221e95928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559221e7d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559221ea8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7716f73082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55921b7a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x73,0x64,0x3,0x11,0x47,0x0,0x54,0x49,0x42,0x2b,0x0,0xda,0x82,0x0,0x20,0x79,0x11,0x47,0x0,0x54,0x49,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x26,0x82,0x1,0x70,0x70,0x70,0x70,0x70,0x20, Step #5: ID3sd\003\021G\000TIB+\000\332\202\000 y\021G\000TI\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000[[[[[[[[[[[[[[[[[[[[[[&\202\001ppppp Step #5: artifact_prefix='./'; Test unit written to ./oom-d85269bf2224bcecf07de631c92beba5b4924261 Step #5: Base64: SUQzc2QDEUcAVElCKwDaggAgeRFHAFRJAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAFtbW1tbW1tbW1tbW1tbW1tbW1tbW1smggFwcHBwcCA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4048 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3733406329 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56209996f810, 0x562099b5901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562099b59020,0x56209b9f10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d85269bf2224bcecf07de631c92beba5b4924261' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5023 processed earlier; will process 6006 files now Step #5: ==145804== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5620904649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562096ac9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562096aac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562096aac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56209046ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5620903cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5620903c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56209045cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56209342bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56209342bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56209342bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56209342bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56209342bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56209342bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56209342bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56209342bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56209342bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56209342bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5620956c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5620923edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5620923f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5620921a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5620921a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5620921a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5620921a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5620921a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5620921a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562096aaeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562096ab7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562096a9f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562096aca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f929e98c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5620903c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53,0x45,0x4c,0x45,0x43,0x54,0x2b,0x2b,0x49,0x4e,0x73,0x45,0x52,0x53,0xe2,0x81,0x84,0x45,0x6c,0x49,0x4e,0x28,0x63,0x29,0x53,0x45,0x4c,0x45,0x63,0x54,0x3b,0x45,0x58,0x50,0x4c,0x41,0x49,0x4e,0x28,0x63,0x29,0x53,0x45,0x4c,0x45,0x63,0x54,0x3b,0x45,0x58,0x50,0x4c,0x41,0x49,0x4e,0x28,0x63,0x29,0x53,0x45,0x4c,0x45,0x63,0x54,0x3b,0x45,0x58,0x50,0x4c,0x41,0x49,0x4e,0x28,0xe8,0x29,0x53,0x45,0x4c,0x45,0x63,0x54,0x3b,0x45,0x58,0x50,0x4c,0x41,0x49,0x4e,0x28,0xe8,0x29,0x53,0x45,0x4c,0x45,0x63,0x54, Step #5: SELECT++INsERS\342\201\204ElIN(c)SELEcT;EXPLAIN(c)SELEcT;EXPLAIN(c)SELEcT;EXPLAIN(\350)SELEcT;EXPLAIN(\350)SELEcT Step #5: artifact_prefix='./'; Test unit written to ./oom-a64acfece72169d4e78d7b0937e7aeffff6cde39 Step #5: Base64: U0VMRUNUKytJTnNFUlPigYRFbElOKGMpU0VMRWNUO0VYUExBSU4oYylTRUxFY1Q7RVhQTEFJTihjKVNFTEVjVDtFWFBMQUlOKOgpU0VMRWNUO0VYUExBSU4o6ClTRUxFY1Q= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4049 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3733906600 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5627a3b6a810, 0x5627a3d5401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5627a3d54020,0x5627a5bec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a64acfece72169d4e78d7b0937e7aeffff6cde39' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5024 processed earlier; will process 6005 files now Step #5: ==145840== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56279a65f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5627a0cc4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5627a0ca75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5627a0ca74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56279a665d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56279a5c6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56279a5c1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56279a657c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56279d626f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56279d626f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56279d626f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56279d626f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56279d626f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56279d626f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56279d626f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56279d626f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56279d626f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56279d626f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56279f8bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56279c5e8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56279c5f3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56279c39fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56279c39fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56279c3a0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56279c39f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56279c39f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56279c39f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5627a0ca9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5627a0cb2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5627a0c9a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5627a0cc5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e1040a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56279a5bfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0,0xce,0xa3,0xf2,0x81,0x90,0xa0, Step #5: //\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240\316\243\362\201\220\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-5399755df9bb997119a0ad516ff9590b331f5412 Step #5: Base64: Ly/Oo/KBkKDOo/KBkKDOo/KBkKDOo/KBkKDOo/KBkKDOo/KBkKDOo/KBkKDOo/KBkKDOo/KBkKDOo/KBkKDOo/KBkKDOo/KBkKDOo/KBkKDOo/KBkKDOo/KBkKDOo/KBkKA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4050 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3734399993 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563636e73810, 0x56363705d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56363705d020,0x563638ef50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5399755df9bb997119a0ad516ff9590b331f5412' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5025 processed earlier; will process 6004 files now Step #5: #1 pulse cov: 3757 ft: 3758 exec/s: 0 rss: 177Mb Step #5: ==145876== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56362d9689c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563633fcd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563633fb05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563633fb04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56362d96ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56362d8cfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56362d8ca355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56362d960c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56363092ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56363092ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56363092ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56363092ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56363092ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56363092ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56363092ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56363092ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56363092ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56363092ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563632bc4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56362f8f1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56362f8fcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56362f6a8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56362f6a8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56362f6a9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56362f6a8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56362f6a8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56362f6a8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563633fb2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563633fbb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563633fa3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563633fce112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd0b5bae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56362d8c8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0xa,0x64,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x45,0x32,0xa,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x49,0x4e,0x20,0xa,0x64,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x45,0x32,0xa,0x3d,0xcc,0xbb,0x2d,0x41,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x22,0x3f,0xb5,0x8c,0xf5,0xd2,0x41,0x73,0x63,0x65,0xa,0x2d,0x3f,0x41,0x73,0xa,0x0,0x1,0x0,0x0,0x43,0x46,0x46,0x20,0x9d,0xa,0x64,0xa,0x64,0xa,0x64,0x0,0x8,0x2d,0x2d, Step #5: x-----BEGIN \012d\000\000-------\012E2\012=\314\273A--IN \012d\000\000-------\012E2\012=\314\273-A--Asce\012\"?\265\214\365\322Asce\012-?As\012\000\001\000\000CFF \235\012d\012d\012d\000\010-- Step #5: artifact_prefix='./'; Test unit written to ./oom-fc5ab0cfbc459a4339ede7318719f7813cbefc24 Step #5: Base64: eC0tLS0tQkVHSU4gCmQAAC0tLS0tLS0KRTIKPcy7QS0tSU4gCmQAAC0tLS0tLS0KRTIKPcy7LUEtLUFzY2UKIj+1jPXSQXNjZQotP0FzCgABAABDRkYgnQpkCmQKZAAILS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4051 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3734948001 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e8824c810, 0x555e8843601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e88436020,0x555e8a2ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc5ab0cfbc459a4339ede7318719f7813cbefc24' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5027 processed earlier; will process 6002 files now Step #5: ==145912== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555e7ed419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e853a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e853895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e853894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e7ed47d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e7eca8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e7eca3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e7ed39c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e81d08f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e81d08f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e81d08f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e81d08f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e81d08f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e81d08f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e81d08f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e81d08f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e81d08f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e81d08f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e83f9df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e80ccab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e80cd5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e80a81c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e80a81c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e80a82738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e80a81874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e80a81874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e80a81874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e8538babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e85394928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e8537c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e853a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5cdad44082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e7eca1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x2d,0x2d,0xa,0x62,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xfa,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: `-----BEG\011N -----\000\012=\012=\012=\012=\012=\012=?=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012\012`-----B--\012b-----BEG\011N -----\372N ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-8437bbf0617d26b55aa60993bd3910f9a2138f8b Step #5: Base64: YC0tLS0tQkVHCU4gLS0tLS0ACj0KPQo9Cj0KPQo9Pz0KPQo9Cj0KPQo9Cj0KCj0KPQo9Cj0KPQo9Cj0KPQoKYC0tLS0tQi0tCmItLS0tLUJFRwlOIC0tLS0t+k4gLS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4052 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3735585585 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a4ff997810, 0x55a4ffb8101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a4ffb81020,0x55a501a190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8437bbf0617d26b55aa60993bd3910f9a2138f8b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5028 processed earlier; will process 6001 files now Step #5: ==145948== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a4f648c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a4fcaf1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a4fcad45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a4fcad44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a4f6492d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a4f63f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a4f63ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a4f6484c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a4f9453f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a4f9453f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a4f9453f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a4f9453f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a4f9453f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a4f9453f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a4f9453f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a4f9453f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a4f9453f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a4f9453f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a4fb6e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a4f8415b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a4f8420be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a4f81ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a4f81ccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a4f81cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a4f81cc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a4f81cc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a4f81cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a4fcad6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a4fcadf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a4fcac7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a4fcaf2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5de8fd5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a4f63ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xef,0xbb,0xbd,0xef,0xbb,0xbc,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0x9f,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbc,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbf,0xef,0xbb,0xbd,0xef,0xbb,0xbd,0xef,0xbb,0xbd, Step #5: \012\012\357\273\275\357\273\274\357\273\275\357\273\275\357\273\275\357\273\275\357\273\237\357\273\275\357\273\275\357\273\275\357\273\275\357\273\274\357\273\275\357\273\275\357\273\275\357\273\275\357\273\275\357\273\275\357\273\275\357\273\275\357\273\275\357\273\275\357\273\275\357\273\275\357\273\275\357\273\275\357\273\275\357\273\275\357\273\277\357\273\275\357\273\275\357\273\275 Step #5: artifact_prefix='./'; Test unit written to ./oom-6b47153c5c051dcf109ad47b21f74a1b80416645 Step #5: Base64: Cgrvu73vu7zvu73vu73vu73vu73vu5/vu73vu73vu73vu73vu7zvu73vu73vu73vu73vu73vu73vu73vu73vu73vu73vu73vu73vu73vu73vu73vu73vu7/vu73vu73vu70= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4053 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3736094228 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d6b0b81810, 0x55d6b0d6b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d6b0d6b020,0x55d6b2c030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b47153c5c051dcf109ad47b21f74a1b80416645' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5029 processed earlier; will process 6000 files now Step #5: ==145984== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d6a76769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d6adcdb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d6adcbe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d6adcbe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d6a767cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d6a75ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d6a75d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d6a766ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d6aa63df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d6aa63df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d6aa63df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d6aa63df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d6aa63df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d6aa63df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d6aa63df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d6aa63df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d6aa63df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d6aa63df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d6ac8d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d6a95ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d6a960abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d6a93b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d6a93b6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d6a93b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d6a93b6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d6a93b6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d6a93b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d6adcc0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d6adcc9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d6adcb1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d6adcdc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe0970f8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d6a75d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x2d,0x2e,0x2f,0x2f,0x1d,0x9,0xa,0xa,0x2f,0x2d,0x2d,0x2f,0x2d,0xd,0xc,0x9,0x9,0xa,0x2e,0x2f,0x2f,0x2d,0xd,0xc,0x9,0x2,0x0,0x0,0x0,0x0,0x9,0x2d,0xd,0xc,0x9,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xc,0xc,0x9,0x2d,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x5f,0x25,0x5f,0x3a,0x33,0x3a,0xd,0xc,0x9,0x2d,0xd,0xc,0x9, Step #5: t-.//\035\011\012\012/--/-\015\014\011\011\012.//-\015\014\011\002\000\000\000\000\011-\015\014\011\014\011-\015\014\011-\015\014-\015\014\011-\015\014\011-\014\014\011--\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014_%_:3:\015\014\011-\015\014\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-7ed1e4ad97a5c48a0f57a3520b531c6a8b543e99 Step #5: Base64: dC0uLy8dCQoKLy0tLy0NDAkJCi4vLy0NDAkCAAAAAAktDQwJDAktDQwJLQ0MLQ0MCS0NDAktDAwJLS0NDAktDQwJLQ0MCS0NDAktDQwJLQ0MCS0NDF8lXzozOg0MCS0NDAk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4054 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3736616866 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557914216810, 0x55791440001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557914400020,0x5579162980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ed1e4ad97a5c48a0f57a3520b531c6a8b543e99' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5030 processed earlier; will process 5999 files now Step #5: ==146020== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55790ad0b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557911370898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5579113535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5579113534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55790ad11d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55790ac72b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55790ac6d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55790ad03c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55790dcd2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55790dcd2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55790dcd2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55790dcd2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55790dcd2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55790dcd2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55790dcd2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55790dcd2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55790dcd2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55790dcd2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55790ff67f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55790cc94b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55790cc9fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55790ca4bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55790ca4bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55790ca4c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55790ca4b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55790ca4b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55790ca4b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557911355abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55791135e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557911346699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557911371112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f772255a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55790ac6bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x67,0x6d,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0, Step #5: gm \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-c335eeecbcf5e4d7694b89937c0646fa19be157a Step #5: Base64: Z20gwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqAgwqA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4055 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3737127589 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d812bd2810, 0x55d812dbc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d812dbc020,0x55d814c540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c335eeecbcf5e4d7694b89937c0646fa19be157a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5031 processed earlier; will process 5998 files now Step #5: #1 pulse cov: 3648 ft: 3649 exec/s: 0 rss: 174Mb Step #5: ==146056== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d8096c79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d80fd2c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d80fd0f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d80fd0f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d8096cdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d80962eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d809629355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d8096bfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d80c68ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d80c68ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d80c68ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d80c68ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d80c68ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d80c68ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d80c68ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d80c68ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d80c68ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d80c68ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d80e923f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d80b650b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d80b65bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d80b407c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d80b407c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d80b408738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d80b407874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d80b407874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d80b407874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d80fd11abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d80fd1a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d80fd02699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d80fd2d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb212fd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d809627b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0x5e,0x0,0x0,0x0,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x45,0x47,0x49,0x21,0x24,0x24,0x47,0x0,0x2d,0x2d,0x3f,0x2d,0x2d,0x4f,0x53,0x2f,0x32,0xa,0x2d,0x2d,0xa,0x3d,0x44,0x49,0x49,0x44,0x39,0x4,0xcc,0x96,0xb,0x73,0x32,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x6b,0x3,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xff, Step #5: \005-----BEGIN =^\000\000\000\012\012r=sef=\012=+=\012=\012=\012= =\012= i\012\012r=sEGI!$$G\000--?--OS/2\012--\012=DIID9\004\314\226\013s2\002U -E\012\012k\003ip_cl\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-48b32cecbea0e387736b307ee38a9de4ac08e873 Step #5: Base64: BS0tLS0tQkVHSU4gPV4AAAAKCnI9c2VmPQo9Kz0KPQo9Cj0gPQo9IGkKCnI9c0VHSSEkJEcALS0/LS1PUy8yCi0tCj1ESUlEOQTMlgtzMgJVIC1FCgprA2lwX2NsCnwAEP8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4056 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3737679396 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560807b74810, 0x560807d5e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560807d5e020,0x560809bf60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/48b32cecbea0e387736b307ee38a9de4ac08e873' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5033 processed earlier; will process 5996 files now Step #5: ==146092== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5607fe6699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560804cce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560804cb15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560804cb14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5607fe66fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5607fe5d0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5607fe5cb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5607fe661c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560801630f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560801630f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560801630f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560801630f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560801630f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560801630f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560801630f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560801630f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560801630f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560801630f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608038c5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5608005f2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5608005fdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5608003a9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5608003a9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5608003aa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5608003a9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5608003a9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5608003a9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560804cb3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560804cbc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560804ca4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560804ccf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3df573b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5607fe5c9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0xd,0xa,0x2a,0x37,0x38,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa, Step #5: *\015\012*78\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-bf48664c9a6cd272346529ea24efcbea119f6b9a Step #5: Base64: Kg0KKjc4DQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4057 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3738209347 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d658f3e810, 0x55d65912801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d659128020,0x55d65afc00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf48664c9a6cd272346529ea24efcbea119f6b9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5034 processed earlier; will process 5995 files now Step #5: ==146128== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d64fa339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d656098898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d65607b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d65607b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d64fa39d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d64f99ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d64f995355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d64fa2bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d6529faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d6529faf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d6529faf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d6529faf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d6529faf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d6529faf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d6529faf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d6529faf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d6529faf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d6529faf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d654c8ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d6519bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d6519c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d651773c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d651773c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d651774738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d651773874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d651773874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d651773874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d65607dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d656086928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d65606e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d656099112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbeb0235082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d64f993b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c,0x3a,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xce,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84,0x2f,0xcd,0x84, Step #5: l:/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\316\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204/\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-b5f2ed3f548510799c1297cc733e267339905ae9 Step #5: Base64: bDovzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzoQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQvzYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4058 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3738711216 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5617b6ac4810, 0x5617b6cae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5617b6cae020,0x5617b8b460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b5f2ed3f548510799c1297cc733e267339905ae9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5035 processed earlier; will process 5994 files now Step #5: #1 pulse cov: 3822 ft: 3823 exec/s: 0 rss: 177Mb Step #5: ==146164== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5617ad5b99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5617b3c1e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5617b3c015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5617b3c014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5617ad5bfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5617ad520b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5617ad51b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5617ad5b1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5617b0580f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5617b0580f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5617b0580f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5617b0580f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5617b0580f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5617b0580f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5617b0580f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5617b0580f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5617b0580f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5617b0580f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5617b2815f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5617af542b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5617af54dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5617af2f9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5617af2f9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5617af2fa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5617af2f9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5617af2f9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5617af2f9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5617b3c03abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5617b3c0c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5617b3bf4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5617b3c1f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc82d77e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5617ad519b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x2e,0x9,0x30,0x2e,0x9,0x36,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9,0x30,0x2e,0x9, Step #5: 0.\0110.\0116\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\0110.\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-4c492d274e3bf47356cea485e22dfecb4d445f96 Step #5: Base64: MC4JMC4JNgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgkwLgk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4059 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3739254740 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557089f70810, 0x55708a15a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55708a15a020,0x55708bff20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4c492d274e3bf47356cea485e22dfecb4d445f96' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5037 processed earlier; will process 5992 files now Step #5: ==146200== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557080a659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5570870ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5570870ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5570870ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557080a6bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5570809ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5570809c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557080a5dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557083a2cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557083a2cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557083a2cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557083a2cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557083a2cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557083a2cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557083a2cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557083a2cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557083a2cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557083a2cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557085cc1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5570829eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5570829f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5570827a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5570827a5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5570827a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5570827a5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5570827a5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5570827a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5570870afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5570870b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5570870a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5570870cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc4d452d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5570809c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x7c,0x24,0x7c,0xc7,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29, Step #5: ^(?:$|$|$|$|$|$|$|$|$|$|$|$|$|$|$\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"|$|\307|$|$|$|$|$|$|$|$|$|$|$|$|$|$|$) Step #5: artifact_prefix='./'; Test unit written to ./oom-ec78227a9e7f25383cb603eb6376ba261ca28d12 Step #5: Base64: Xig/OiR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIifCR8x3wkfCR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkfCR8JCk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4060 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3739760036 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ab9936810, 0x555ab9b2001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ab9b20020,0x555abb9b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec78227a9e7f25383cb603eb6376ba261ca28d12' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5038 processed earlier; will process 5991 files now Step #5: ==146236== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555ab042b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ab6a90898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ab6a735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ab6a734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ab0431d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ab0392b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ab038d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ab0423c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ab33f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ab33f2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ab33f2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ab33f2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ab33f2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ab33f2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ab33f2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ab33f2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ab33f2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ab33f2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555ab5687f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ab23b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ab23bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ab216bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ab216bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ab216c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ab216b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ab216b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ab216b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ab6a75abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ab6a7e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ab6a66699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ab6a91112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa9c01b0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ab038bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3e,0x60,0x24,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3c,0x60,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3e,0x60,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3c,0x60,0x24,0x60,0x3b,0x3b,0x27,0x2f,0x27,0x3e,0x60,0xef,0xac,0xac,0xf3,0xa0,0x81,0xa9,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3e,0x60,0x60,0x3b,0x3b,0x27,0x2f,0x27,0x3e,0x60,0xef,0xac,0xac,0xf3,0xa0,0x81,0xa9,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3e,0x60,0xf3,0xa0,0x81,0xa9,0x24,0x60,0x3b,0x27,0x3d,0x27,0xff,0x5e,0x7c,0x7c,0x7c,0x3c,0x60, Step #5: `$`;'/'>`$$`;'/'<`$`;'/'>`$`;'/'<`$`;;'/'>`\357\254\254\363\240\201\251$`;'/'>``;;'/'>`\357\254\254\363\240\201\251$`;'/'>`\363\240\201\251$`;'='\377^|||<` Step #5: artifact_prefix='./'; Test unit written to ./oom-a11db6c7bc343a2453d13d2d598ed8b294cb32f5 Step #5: Base64: YCRgOycvJz5gJCRgOycvJzxgJGA7Jy8nPmAkYDsnLyc8YCRgOzsnLyc+YO+srPOggakkYDsnLyc+YGA7OycvJz5g76ys86CBqSRgOycvJz5g86CBqSRgOyc9J/9efHx8PGA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4061 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3740394645 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56255ba49810, 0x56255bc3301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56255bc33020,0x56255dacb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a11db6c7bc343a2453d13d2d598ed8b294cb32f5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5039 processed earlier; will process 5990 files now Step #5: ==146272== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56255253e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562558ba3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562558b865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562558b864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562552544d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625524a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625524a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562552536c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562555505f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562555505f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562555505f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562555505f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562555505f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562555505f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562555505f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562555505f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562555505f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562555505f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56255779af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625544c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5625544d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56255427ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56255427ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56255427f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56255427e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56255427e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56255427e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562558b88abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562558b91928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562558b79699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562558ba4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e02b17082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56255249eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0xa,0x0,0x71,0x0,0x73,0x74,0x72,0x65,0x61,0x6d,0x0,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27, Step #5: I\012\000q\000stream\000'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Step #5: artifact_prefix='./'; Test unit written to ./oom-e860697553a8b70ee4eee52a934e31dc5d9eaf35 Step #5: Base64: SQoAcQBzdHJlYW0AJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJyc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4062 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3740898125 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5625e0d12810, 0x5625e0efc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625e0efc020,0x5625e2d940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e860697553a8b70ee4eee52a934e31dc5d9eaf35' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5040 processed earlier; will process 5989 files now Step #5: ==146308== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5625d78079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5625dde6c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625dde4f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625dde4f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5625d780dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625d776eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625d7769355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5625d77ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5625da7cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5625da7cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5625da7cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5625da7cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5625da7cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5625da7cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5625da7cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5625da7cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5625da7cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5625da7cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5625dca63f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625d9790b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5625d979bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5625d9547c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5625d9547c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5625d9548738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5625d9547874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5625d9547874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5625d9547874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5625dde51abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5625dde5a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5625dde42699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5625dde6d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb286fac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625d7767b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x7b,0x30,0x2c,0x7d,0x20,0x57,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x30,0x2c,0x7d,0x25,0x7b,0x2c,0x7d,0x25,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x0,0x62,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x60,0x0,0x60,0xde,0xae,0xa,0x60,0x2c,0x7d,0x20,0x7a,0x30,0x2c,0x7c,0x2d,0x3d,0x66,0x24,0x7a,0x2d,0x24,0x7d,0x24,0x7b,0x30,0x2d,0x2c,0x7d,0x20,0x3d,0x60,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d, Step #5: ({0,} W0,} {0,}s{0,} {00,}%{,}%{0,} {0,}}{\000b} {0,} {0,}s{0`\000`\336\256\012`,} z0,|-=f$z-$}${0-,} =`{0,} {0,} Step #5: artifact_prefix='./'; Test unit written to ./oom-cfd543d54571b8a303474925f68051f55160885e Step #5: Base64: KHswLH0gVzAsfSB7MCx9c3swLH0gezAwLH0leyx9JXswLH0gezAsfX17AGJ9IHswLH0gezAsfXN7MGAAYN6uCmAsfSB6MCx8LT1mJHotJH0kezAtLH0gPWB7MCx9IHswLH0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4063 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3741527131 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c910c36810, 0x55c910e2001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c910e20020,0x55c912cb80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cfd543d54571b8a303474925f68051f55160885e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5041 processed earlier; will process 5988 files now Step #5: #1 pulse cov: 3857 ft: 3858 exec/s: 0 rss: 176Mb Step #5: ==146344== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c90772b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c90dd90898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c90dd735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c90dd734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c907731d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c907692b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c90768d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c907723c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c90a6f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c90a6f2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c90a6f2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c90a6f2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c90a6f2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c90a6f2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c90a6f2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c90a6f2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c90a6f2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c90a6f2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c90c987f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9096b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9096bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c90946bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c90946bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c90946c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c90946b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c90946b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c90946b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c90dd75abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c90dd7e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c90dd66699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c90dd91112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2693dfc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c90768bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0xa,0x64,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x45,0x32,0xa,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x49,0x4e,0x20,0xa,0x64,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x45,0x32,0xa,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x3f,0x41,0x73,0xa,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x3f,0x41,0x73,0xa,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x9d,0xa,0x64,0xa,0x64,0xa,0x64,0x0,0x0,0x2d,0x2d, Step #5: x-----BEGIN \012d\000\000-------\012E2\012=\314\273A--IN \012d\000\000-------\012E2\012=\314\273A---Asce\012-?As\012-Asce\012-?As\012\000\001\000\000\000\000\000\000\235\012d\012d\012d\000\000-- Step #5: artifact_prefix='./'; Test unit written to ./oom-fcfd37512b4112a43afcf839fa7ce5ce164da536 Step #5: Base64: eC0tLS0tQkVHSU4gCmQAAC0tLS0tLS0KRTIKPcy7QS0tSU4gCmQAAC0tLS0tLS0KRTIKPcy7QS0tLUFzY2UKLT9BcwotQXNjZQotP0FzCgABAAAAAAAAnQpkCmQKZAAALS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4064 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3742073356 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55958ab8d810, 0x55958ad7701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55958ad77020,0x55958cc0f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fcfd37512b4112a43afcf839fa7ce5ce164da536' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5043 processed earlier; will process 5986 files now Step #5: ==146380== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5595816829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559587ce7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559587cca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559587cca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559581688d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5595815e9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5595815e4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55958167ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559584649f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559584649f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559584649f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559584649f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559584649f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559584649f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559584649f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559584649f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559584649f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559584649f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5595868def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55958360bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559583616be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5595833c2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5595833c2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5595833c3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5595833c2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5595833c2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5595833c2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559587cccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559587cd5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559587cbd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559587ce8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4c7caa7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5595815e2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe2,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf,0xe3,0x8e,0xaf, Step #5: //\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\343\216\257\342\216\257\343\216\257\343\216\257\343\216\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-210924bde72f50b12d8c0f841d7ccb0fb660cf8e Step #5: Base64: Ly/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/jjq/ijq/jjq/jjq/jjq8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4065 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3742559645 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56490988b810, 0x564909a7501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564909a75020,0x56490b90d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/210924bde72f50b12d8c0f841d7ccb0fb660cf8e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5044 processed earlier; will process 5985 files now Step #5: #1 pulse cov: 3693 ft: 3694 exec/s: 0 rss: 175Mb Step #5: ==146416== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5649003809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5649069e5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5649069c85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5649069c84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564900386d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649002e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649002e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564900378c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564903347f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564903347f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564903347f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564903347f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564903347f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564903347f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564903347f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564903347f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564903347f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564903347f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5649055dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564902309b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564902314be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5649020c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5649020c0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5649020c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5649020c0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5649020c0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5649020c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5649069caabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5649069d3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5649069bb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5649069e6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f61ed3d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649002e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x53,0x3a,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96, Step #5: wS:\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226 Step #5: artifact_prefix='./'; Test unit written to ./oom-4f2fb47f7e350c57b98c57f28bc143ecc3cc0c1f Step #5: Base64: d1M644yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4066 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3743101440 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b9618d1810, 0x55b961abb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b961abb020,0x55b9639530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f2fb47f7e350c57b98c57f28bc143ecc3cc0c1f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5046 processed earlier; will process 5983 files now Step #5: #1 pulse cov: 3723 ft: 3724 exec/s: 0 rss: 177Mb Step #5: ==146452== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b9583c69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b95ea2b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b95ea0e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b95ea0e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b9583ccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b95832db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b958328355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b9583bec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b95b38df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b95b38df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b95b38df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b95b38df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b95b38df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b95b38df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b95b38df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b95b38df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b95b38df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b95b38df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b95d622f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b95a34fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b95a35abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b95a106c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b95a106c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b95a107738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b95a106874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b95a106874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b95a106874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b95ea10abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b95ea19928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b95ea01699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b95ea2c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a5e40d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b958326b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82,0xe3,0x80,0x82, Step #5: ws:\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202\343\200\202 Step #5: artifact_prefix='./'; Test unit written to ./oom-fff219d4e87ec05dc532df1d2a2d5ecc84cfceca Step #5: Base64: d3M644CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC44CC Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4067 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3743632645 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e31c585810, 0x55e31c76f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e31c76f020,0x55e31e6070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fff219d4e87ec05dc532df1d2a2d5ecc84cfceca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5048 processed earlier; will process 5981 files now Step #5: #1 pulse cov: 3977 ft: 3978 exec/s: 0 rss: 173Mb Step #5: ==146488== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e31307a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e3196df898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e3196c25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e3196c24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e313080d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e312fe1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e312fdc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e313072c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e316041f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e316041f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e316041f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e316041f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e316041f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e316041f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e316041f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e316041f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e316041f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e316041f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e3182d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e315003b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e31500ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e314dbac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e314dbac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e314dbb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e314dba874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e314dba874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e314dba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e3196c4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e3196cd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e3196b5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e3196e0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbd95ee7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e312fdab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd6,0xae,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x0,0x4f,0x0,0x0,0x9d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x74,0x72,0x65,0x61,0x6d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x80,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0xd5,0x96,0xc8, Step #5: \326\256\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\000O\000\000\235\000\000\000\000\000\000\000tream\000\000\000\000\000\000\000\000\001\000\200\012\000\000\000\000\000\000\325\226\310 Step #5: artifact_prefix='./'; Test unit written to ./oom-c09170ddb37e8ef06333de6e9e880ba700cc61ee Step #5: Base64: 1q4AAAAAAAAAAAAAAAAAAAAAACIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIgBPAACdAAAAAAAAAHRyZWFtAAAAAAAAAAABAIAKAAAAAAAA1ZbI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4068 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3744176592 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55df45516810, 0x55df4570001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55df45700020,0x55df475980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c09170ddb37e8ef06333de6e9e880ba700cc61ee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5050 processed earlier; will process 5979 files now Step #5: ==146524== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55df3c00b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55df42670898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55df426535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55df426534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55df3c011d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55df3bf72b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55df3bf6d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55df3c003c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55df3efd2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55df3efd2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55df3efd2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55df3efd2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55df3efd2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55df3efd2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55df3efd2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55df3efd2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55df3efd2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55df3efd2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55df41267f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55df3df94b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55df3df9fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55df3dd4bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55df3dd4bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55df3dd4c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55df3dd4b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55df3dd4b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55df3dd4b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55df42655abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55df4265e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55df42646699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55df42671112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa52fcb2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55df3bf6bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6b,0x24,0x24,0x24,0x24,0x24,0x1e,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x16,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x7e,0x24,0x24,0x24,0x93,0x24,0x24,0x24,0xdb,0xdd,0x24,0xdb,0xcc,0x3,0x7e,0x47,0x46,0x44,0xaf,0x7e,0x91,0x89,0x47, Step #5: k$$$$$\036$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$\026$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$~$$$\223$$$\333\335$\333\314\003~GFD\257~\221\211G Step #5: artifact_prefix='./'; Test unit written to ./oom-7cc66279b9466400d660cdbdff38ab91036b6d07 Step #5: Base64: ayQkJCQkHiQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJBYkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJH4kJCSTJCQk290k28wDfkdGRK9+kYlH Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4069 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3744690136 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d86f76810, 0x563d8716001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d87160020,0x563d88ff80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7cc66279b9466400d660cdbdff38ab91036b6d07' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5051 processed earlier; will process 5978 files now Step #5: #1 pulse cov: 3729 ft: 3730 exec/s: 0 rss: 175Mb Step #5: ==146560== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563d7da6b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d840d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d840b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d840b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d7da71d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d7d9d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d7d9cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d7da63c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d80a32f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d80a32f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d80a32f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d80a32f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d80a32f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d80a32f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d80a32f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d80a32f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d80a32f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d80a32f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d82cc7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d7f9f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d7f9ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d7f7abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d7f7abc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d7f7ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d7f7ab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d7f7ab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d7f7ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d840b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d840be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d840a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d840d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f190abba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d7d9cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x4,0x0,0x2,0x33,0x3,0x0,0x0,0x45,0x30,0x50,0x55,0x53,0x4c,0x54,0x0,0x0,0x20,0x0,0x71,0x70,0x78,0x60,0x74,0x6d,0x21,0x60,0x32,0x50,0x55,0x53,0x4c,0x32,0x54,0x0,0x0,0x0,0x5,0x20,0x0,0x0,0x20,0x47,0x45,0x30,0x50,0x32,0x50,0x55,0x53,0x4c,0x32,0x54,0x0,0x0,0x0,0x5,0x20,0x0,0x0,0x20,0x47,0x45,0x30,0x50,0x53,0x4c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x32,0x54,0x80,0xc7,0x50, Step #5: I\004\000\0023\003\000\000E0PUSLT\000\000 \000qpx`tm!`2PUSL2T\000\000\000\005 \000\000 GE0P2PUSL2T\000\000\000\005 \000\000 GE0PSL\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0002T\200\307P Step #5: artifact_prefix='./'; Test unit written to ./oom-185d0c1c3dd157fb264d1fa64cdb955ae498c8e0 Step #5: Base64: SQQAAjMDAABFMFBVU0xUAAAgAHFweGB0bSFgMlBVU0wyVAAAAAUgAAAgR0UwUDJQVVNMMlQAAAAFIAAAIEdFMFBTTAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADJUgMdQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4070 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3745357127 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5646b0989810, 0x5646b0b7301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5646b0b73020,0x5646b2a0b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/185d0c1c3dd157fb264d1fa64cdb955ae498c8e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5053 processed earlier; will process 5976 files now Step #5: ==146596== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5646a747e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5646adae3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5646adac65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5646adac64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5646a7484d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5646a73e5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5646a73e0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5646a7476c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5646aa445f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5646aa445f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5646aa445f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5646aa445f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5646aa445f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5646aa445f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5646aa445f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5646aa445f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5646aa445f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5646aa445f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5646ac6daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5646a9407b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5646a9412be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5646a91bec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5646a91bec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5646a91bf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5646a91be874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5646a91be874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5646a91be874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5646adac8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5646adad1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5646adab9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5646adae4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6d16130082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5646a73deb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x8b,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5, Step #5: ws:\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\213\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-068060c96192c021d8d1952ed70de56c35d8bfe3 Step #5: Base64: d3M64ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayL4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4071 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3745862666 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5558b5c46810, 0x5558b5e3001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5558b5e30020,0x5558b7cc80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/068060c96192c021d8d1952ed70de56c35d8bfe3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5054 processed earlier; will process 5975 files now Step #5: ==146632== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5558ac73b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5558b2da0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5558b2d835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5558b2d834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5558ac741d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5558ac6a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5558ac69d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5558ac733c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5558af702f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5558af702f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5558af702f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5558af702f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5558af702f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5558af702f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5558af702f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5558af702f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5558af702f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5558af702f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5558b1997f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5558ae6c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5558ae6cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5558ae47bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5558ae47bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5558ae47c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5558ae47b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5558ae47b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5558ae47b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5558b2d85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5558b2d8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5558b2d76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5558b2da1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff4a7c32082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5558ac69bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5, Step #5: ws:\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-2ba96cc931398331aef7acce4d6cc585cc09b6fa Step #5: Base64: d3M64L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L214L21 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4072 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3746366735 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561f8cea0810, 0x561f8d08a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561f8d08a020,0x561f8ef220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2ba96cc931398331aef7acce4d6cc585cc09b6fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5055 processed earlier; will process 5974 files now Step #5: ==146668== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561f839959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561f89ffa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561f89fdd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561f89fdd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561f8399bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561f838fcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561f838f7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561f8398dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561f8695cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561f8695cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561f8695cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561f8695cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561f8695cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561f8695cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561f8695cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561f8695cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561f8695cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561f8695cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561f88bf1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561f8591eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561f85929be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561f856d5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561f856d5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561f856d6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561f856d5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561f856d5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561f856d5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561f89fdfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561f89fe8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561f89fd0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561f89ffb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb5e50f5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561f838f5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x20,0x6c,0x20,0x63,0x65,0x36,0x35,0x35,0x33,0x35,0x72,0x30,0x6d,0x36,0x36,0x38,0x37,0x33,0x38,0x41,0x31,0x73,0x36,0x74,0x30,0x2b,0x31,0x34,0x68,0x6f,0xd,0x32,0x32,0x31,0x30,0x2d,0x32,0x2d,0x31,0x20,0x31,0x3a,0x30,0x3a,0x30,0x20,0x31,0x2e,0x30,0x2e,0x30,0x2e,0x31,0xd,0x1,0x20,0x2d,0xa,0x61,0x20,0x2a,0x3a,0x2d,0xa,0x61,0x20,0x2a,0x3a,0x2d,0xa,0x61,0x20,0x2a,0x3a,0x2d,0xa,0x61,0x20,0x2a,0x3a,0x2d,0xa,0x61,0x20,0x2a,0x3a,0x2d,0xa,0x61,0x20,0x2a,0x3a,0x2d,0xa,0x70,0x72,0xa,0x73, Step #5: r l ce65535r0m668738A1s6t0+14ho\0152210-2-1 1:0:0 1.0.0.1\015\001 -\012a *:-\012a *:-\012a *:-\012a *:-\012a *:-\012a *:-\012pr\012s Step #5: artifact_prefix='./'; Test unit written to ./oom-2b10228cb0e8b61389f96eeebd402c7399d9d7cc Step #5: Base64: ciBsIGNlNjU1MzVyMG02Njg3MzhBMXM2dDArMTRobw0yMjEwLTItMSAxOjA6MCAxLjAuMC4xDQEgLQphICo6LQphICo6LQphICo6LQphICo6LQphICo6LQphICo6LQpwcgpz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4073 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3746872477 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610d8a93810, 0x5610d8c7d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610d8c7d020,0x5610dab150e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2b10228cb0e8b61389f96eeebd402c7399d9d7cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5056 processed earlier; will process 5973 files now Step #5: ==146704== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5610cf5889c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610d5bed898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610d5bd05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610d5bd04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610cf58ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610cf4efb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610cf4ea355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610cf580c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610d254ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610d254ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610d254ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610d254ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610d254ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610d254ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610d254ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610d254ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610d254ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610d254ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610d47e4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610d1511b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610d151cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610d12c8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610d12c8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610d12c9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610d12c8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610d12c8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610d12c8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610d5bd2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610d5bdb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610d5bc3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610d5bee112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f44468c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610cf4e8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb4,0xb4,0xbf,0xe0,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0x5d,0xbf,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb0,0xb7,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb4,0xbf,0xe0,0xb0,0xaf,0xe0,0xa8,0x6d, Step #5: \340\264\277\340\260\267\340\260\267\340\260\267\340\264\277\340\264\277\340\260\267\340\264\264\277\340\277\340\264\277\340\260\277\340\264\277\340\260\267\340\260\267\340\260\267\340\264\277\340\264\277\340\260\267\340]\277\340\260\267\340\260\267\340\260\267\340\264\277\340\264\277\340\260\267\340\260\267\340\260\267\340\264\277\340\264\277\340\264\277\340\264\277\340\260\257\340\250m Step #5: artifact_prefix='./'; Test unit written to ./oom-6a5447136dc8a2c8946600e2b6a4a010849df5a0 Step #5: Base64: 4LS/4LC34LC34LC34LS/4LS/4LC34LS0v+C/4LS/4LC/4LS/4LC34LC34LC34LS/4LS/4LC34F2/4LC34LC34LC34LS/4LS/4LC34LC34LC34LS/4LS/4LS/4LS/4LCv4Kht Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4074 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3747370376 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556a74648810, 0x556a7483201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556a74832020,0x556a766ca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a5447136dc8a2c8946600e2b6a4a010849df5a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5057 processed earlier; will process 5972 files now Step #5: ==146740== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556a6b13d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556a717a2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556a717855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556a717854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556a6b143d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556a6b0a4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556a6b09f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556a6b135c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556a6e104f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556a6e104f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556a6e104f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556a6e104f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556a6e104f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556a6e104f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556a6e104f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556a6e104f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556a6e104f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556a6e104f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556a70399f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556a6d0c6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556a6d0d1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556a6ce7dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556a6ce7dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556a6ce7e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556a6ce7d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556a6ce7d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556a6ce7d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556a71787abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556a71790928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556a71778699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556a717a3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6a1dbb4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556a6b09db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x50,0x44,0x46,0x2d,0x30,0x2e,0x34,0xa,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0xa,0x3c,0x3c,0xa,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x59,0x40,0x2e,0x2f,0xa,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0xa,0x3c,0x3c,0xa,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x59,0x40,0x2f,0x2f, Step #5: %PDF-0.4\012\012trailer\012<<\012/////////////////////Y@./\012\012trailer\012<<\012////////////////////////////////////Y@// Step #5: artifact_prefix='./'; Test unit written to ./oom-12a0ec930354b16aad8c81bf094017102d4e3a89 Step #5: Base64: JVBERi0wLjQKCnRyYWlsZXIKPDwKLy8vLy8vLy8vLy8vLy8vLy8vLy8vWUAuLwoKdHJhaWxlcgo8PAovLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy9ZQC8v Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4075 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3747874233 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1c4fb6810, 0x55d1c51a001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1c51a0020,0x55d1c70380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/12a0ec930354b16aad8c81bf094017102d4e3a89' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5058 processed earlier; will process 5971 files now Step #5: ==146776== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d1bbaab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1c2110898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1c20f35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1c20f34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1bbab1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1bba12b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1bba0d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1bbaa3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1bea72f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1bea72f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1bea72f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1bea72f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1bea72f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1bea72f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1bea72f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1bea72f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1bea72f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1bea72f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1c0d07f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1bda34b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1bda3fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1bd7ebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1bd7ebc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1bd7ec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1bd7eb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1bd7eb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1bd7eb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1c20f5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1c20fe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1c20e6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1c2111112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e9b66e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1bba0bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e,0xef,0xbe,0x9e, Step #5: ws:\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236\357\276\236 Step #5: artifact_prefix='./'; Test unit written to ./oom-2bba156e77e200337899f2d21902afe7094693d4 Step #5: Base64: d3M6776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e776e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4076 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3748377206 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5578cfbf9810, 0x5578cfde301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5578cfde3020,0x5578d1c7b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2bba156e77e200337899f2d21902afe7094693d4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5059 processed earlier; will process 5970 files now Step #5: ==146812== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5578c66ee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5578ccd53898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5578ccd365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5578ccd364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5578c66f4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5578c6655b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5578c6650355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5578c66e6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5578c96b5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5578c96b5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5578c96b5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5578c96b5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5578c96b5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5578c96b5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5578c96b5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5578c96b5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5578c96b5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5578c96b5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5578cb94af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5578c8677b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5578c8682be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5578c842ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5578c842ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5578c842f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5578c842e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5578c842e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5578c842e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5578ccd38abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5578ccd41928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5578ccd29699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5578ccd54112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f635bce0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5578c664eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x49,0x44,0x33,0x2,0x1,0x4,0x61,0x4d,0x1,0x4,0x61,0x4d,0x1,0x4,0x61,0x4d,0x1,0x4,0x61,0x4d,0x1,0x4,0x61,0x4d,0x1,0x4,0x61,0x4d,0x1,0x4,0x61,0x4d,0x1,0x4,0x61,0x4d,0x1,0x4,0x61,0x4d,0x0,0x2,0x47,0x45,0x4f,0x43,0x4f,0x4d,0x0,0x3, Step #5: IIDIDIDIDIDIDIDIDIDIDIDIDIDIDIDIDIDIDIDIDIDIDIDIDID3\002\001\004aM\001\004aM\001\004aM\001\004aM\001\004aM\001\004aM\001\004aM\001\004aM\001\004aM\000\002GEOCOM\000\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-b0294bedcb4d139b0af8c024e148e082630d87e2 Step #5: Base64: SUlESURJRElESURJRElESURJRElESURJRElESURJRElESURJRElESURJRElESURJRElEMwIBBGFNAQRhTQEEYU0BBGFNAQRhTQEEYU0BBGFNAQRhTQEEYU0AAkdFT0NPTQAD Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4077 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3748879609 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e42ac2810, 0x562e42cac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e42cac020,0x562e44b440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b0294bedcb4d139b0af8c024e148e082630d87e2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5060 processed earlier; will process 5969 files now Step #5: #1 pulse cov: 3672 ft: 3673 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 13187 ft: 14006 exec/s: 0 rss: 196Mb Step #5: ==146848== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562e395b79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e3fc1c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e3fbff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e3fbff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e395bdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e3951eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e39519355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e395afc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e3c57ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e3c57ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e3c57ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e3c57ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e3c57ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e3c57ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e3c57ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e3c57ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e3c57ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e3c57ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e3e813f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e3b540b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e3b54bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e3b2f7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e3b2f7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e3b2f8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e3b2f7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e3b2f7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e3b2f7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e3fc01abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e3fc0a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e3fbf2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e3fc1d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f42863a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e39517b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x81,0x88,0xe0,0xb2,0xb2,0xe0,0xaa,0xb6,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xaa,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb6,0xe0,0xbd,0xbf,0xe0,0xaa,0xb2,0xe0,0xb2,0xb2,0xe0,0xaa,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb6,0xe0,0xbd,0xbf,0xe0,0xaa,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb6,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb6,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xb2,0xb2,0xe0,0xbf,0xbf, Step #5: \363\240\201\210\340\262\262\340\252\266\340\262\262\340\262\262\340\252\262\340\262\262\340\262\262\340\262\266\340\275\277\340\252\262\340\262\262\340\252\262\340\262\262\340\262\262\340\262\266\340\275\277\340\252\262\340\262\262\340\262\266\340\262\262\340\262\262\340\262\262\340\262\262\340\262\262\340\262\262\340\262\266\340\262\262\340\262\262\340\262\262\340\262\262\340\262\262\340\277\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-3b1fef1e7fa9fec827b2ea35bee0dbf8f5d91250 Step #5: Base64: 86CBiOCysuCqtuCysuCysuCqsuCysuCysuCytuC9v+CqsuCysuCqsuCysuCysuCytuC9v+CqsuCysuCytuCysuCysuCysuCysuCysuCysuCytuCysuCysuCysuCysuCysuC/vw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4078 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3749485760 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5570f84ac810, 0x5570f869601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5570f8696020,0x5570fa52e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3b1fef1e7fa9fec827b2ea35bee0dbf8f5d91250' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5063 processed earlier; will process 5966 files now Step #5: ==146884== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5570eefa19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5570f5606898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5570f55e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5570f55e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5570eefa7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5570eef08b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5570eef03355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5570eef99c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5570f1f68f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5570f1f68f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5570f1f68f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5570f1f68f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5570f1f68f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5570f1f68f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5570f1f68f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5570f1f68f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5570f1f68f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5570f1f68f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5570f41fdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5570f0f2ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5570f0f35be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5570f0ce1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5570f0ce1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5570f0ce2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5570f0ce1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5570f0ce1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5570f0ce1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5570f55ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5570f55f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5570f55dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5570f5607112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b17c86082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5570eef01b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x2e,0x3b,0x7f,0x7f,0x7e,0x5e,0x54,0x43,0x4f,0x54,0x10,0x49,0x44,0x33,0x4,0x2e,0x3b,0x7f,0x7f,0x7e,0x5e,0x54,0x43,0x4f,0x54,0x10,0x49,0x44,0x31,0x32,0x34,0x4,0x2e,0x3b,0x7f,0x7f,0x7e,0x5e,0x54,0x43,0x4f,0x54,0x10,0x49,0x44,0x31,0x38,0x34,0x34,0x36,0x37,0x34,0x34,0x30,0x37,0x33,0x37,0x30,0x39,0x35,0x35,0x31,0x36,0x31,0x34,0x4,0x2e,0x3b,0x7f,0x7f,0x7e,0x5e,0x54,0x43,0x4f,0x54,0x10,0x49,0x44,0x36,0x35,0x35,0x33,0x36,0x4,0x2e,0x3b,0x7f,0x7f,0x7e,0x5e,0x54,0x43,0x4f,0x54,0x10, Step #5: ID3\004.;\177\177~^TCOT\020ID3\004.;\177\177~^TCOT\020ID124\004.;\177\177~^TCOT\020ID18446744073709551614\004.;\177\177~^TCOT\020ID65536\004.;\177\177~^TCOT\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-e6b940791f0ff27cce7730601492de199969216b Step #5: Base64: SUQzBC47f39+XlRDT1QQSUQzBC47f39+XlRDT1QQSUQxMjQELjt/f35eVENPVBBJRDE4NDQ2NzQ0MDczNzA5NTUxNjE0BC47f39+XlRDT1QQSUQ2NTUzNgQuO39/fl5UQ09UEA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4079 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3749986314 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56191ef3e810, 0x56191f12801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56191f128020,0x561920fc00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e6b940791f0ff27cce7730601492de199969216b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5064 processed earlier; will process 5965 files now Step #5: ==146920== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561915a339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56191c098898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56191c07b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56191c07b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561915a39d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56191599ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561915995355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561915a2bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5619189faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5619189faf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5619189faf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5619189faf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5619189faf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5619189faf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5619189faf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5619189faf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5619189faf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5619189faf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56191ac8ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5619179bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5619179c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561917773c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561917773c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561917774738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561917773874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561917773874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561917773874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56191c07dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56191c086928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56191c06e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56191c099112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe6eae8a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561915993b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x7b,0x21,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x21,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x78,0xa,0x2d,0x20,0x2d,0x20, Step #5: {!\015- - - - - - - - - - - - - - - -\012- - - - - !\015- - - - - - - - - - - -\012- - - - - - - - - - - x\012- - Step #5: artifact_prefix='./'; Test unit written to ./oom-1caaa472faa9c43893a9c13cccaa057649da1629 Step #5: Base64: IHshDS0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0KLSAtIC0gLSAtICENLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0KLSAtIC0gLSAtIC0gLSAtIC0gLSAtIHgKLSAtIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4080 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3750548515 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557af3fb8810, 0x557af41a201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557af41a2020,0x557af603a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1caaa472faa9c43893a9c13cccaa057649da1629' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5065 processed earlier; will process 5964 files now Step #5: #1 pulse cov: 11146 ft: 11147 exec/s: 0 rss: 192Mb Step #5: ==146956== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557aeaaad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557af1112898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557af10f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557af10f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557aeaab3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557aeaa14b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557aeaa0f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557aeaaa5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557aeda74f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557aeda74f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557aeda74f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557aeda74f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557aeda74f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557aeda74f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557aeda74f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557aeda74f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557aeda74f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557aeda74f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557aefd09f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557aeca36b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557aeca41be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557aec7edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557aec7edc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557aec7ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557aec7ed874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557aec7ed874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557aec7ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557af10f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557af1100928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557af10e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557af1113112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe092688082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557aeaa0db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xf3,0xa0,0x80,0xaf,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xe2,0x80,0xa9,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xb, Step #5: \012\012\012\012\012\012\012\012\012\012\012\363\240\200\257\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\342\200\251\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-670f58ed727f0f5899c3fde766bf032dbd665b35 Step #5: Base64: CgoKCgoKCgoKCgrzoICvCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoK4oCpCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4081 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3751119654 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fb6a9b3810, 0x55fb6ab9d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fb6ab9d020,0x55fb6ca350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/670f58ed727f0f5899c3fde766bf032dbd665b35' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5067 processed earlier; will process 5962 files now Step #5: ==146992== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fb614a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fb67b0d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fb67af05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fb67af04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fb614aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fb6140fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fb6140a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fb614a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fb6446ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fb6446ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fb6446ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fb6446ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fb6446ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fb6446ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fb6446ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fb6446ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fb6446ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fb6446ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fb66704f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fb63431b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fb6343cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fb631e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fb631e8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fb631e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fb631e8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fb631e8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fb631e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fb67af2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fb67afb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fb67ae3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fb67b0e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67ceb52082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fb61408b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x76,0x65,0x6e,0x74,0x73,0x20,0x7b,0xa,0x20,0x20,0x66,0x69,0x6e,0x61,0x6c,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x74,0x6f,0x6b,0x65,0x6e,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x62,0x69,0x6e,0x61,0x72,0x79,0x5f,0x70,0x72,0x6f,0x70,0x65,0x72,0x74,0x69,0x65,0x73,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x63,0x68,0x61,0x32,0x67,0x31,0x22,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x7d,0xa,0x7d,0xa, Step #5: events {\012 final {\012 token {\012 binary_properties {\012 name: \"cha2g1\"\012 }\012 }\012 }\012}\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-85a9884fd5040c2554bd8fe27be3f379a11a30cb Step #5: Base64: ZXZlbnRzIHsKICBmaW5hbCB7CiAgICB0b2tlbiB7CiAgICAgIGJpbmFyeV9wcm9wZXJ0aWVzIHsKICAgICAgICBuYW1lOiAiY2hhMmcxIgogICAgICB9CiAgICB9CiAgfQp9Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4082 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3751623797 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5598be8b9810, 0x5598beaa301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5598beaa3020,0x5598c093b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/85a9884fd5040c2554bd8fe27be3f379a11a30cb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5068 processed earlier; will process 5961 files now Step #5: ==147028== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5598b53ae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5598bba13898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5598bb9f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5598bb9f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5598b53b4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5598b5315b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5598b5310355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5598b53a6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5598b8375f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5598b8375f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5598b8375f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5598b8375f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5598b8375f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5598b8375f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5598b8375f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5598b8375f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5598b8375f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5598b8375f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5598ba60af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5598b7337b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5598b7342be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5598b70eec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5598b70eec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5598b70ef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5598b70ee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5598b70ee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5598b70ee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5598bb9f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5598bba01928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5598bb9e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5598bba14112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f010580f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5598b530eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa5,0xbf,0xbc,0xe0,0xa7,0x91,0xe0,0xa7,0x91,0xe0,0xa7,0x91,0xe0,0xb7,0x91,0xe0,0xb5,0x80,0xe0,0xa7,0x91,0xe0,0xb7,0x91,0xe0,0xb5,0x80,0xe0,0xa7,0x91,0xe0,0xb7,0x91,0xe0,0xb5,0x80,0xe0,0xa7,0x91,0xe0,0xb7,0x91,0xe0,0xb5,0x80,0xe0,0xa7,0x91,0xe0,0xb7,0x91,0xe0,0xb5,0x80,0xe0,0xa7,0x91,0xe0,0xb5,0x80,0xe0,0xa7,0x91,0xe0,0xb7,0x91,0xe0,0xb5,0x80,0xe0,0xa7,0x91,0xe0,0xb7,0x91,0xe0,0xb5,0x80,0xe0,0xa7,0x91,0xe0,0xa7,0x91,0xe0,0xb7,0x91,0xe0,0xb5,0x80,0xe0,0xa7,0x91,0xe0,0xb7,0x91,0xe0,0xb5,0x81, Step #5: \363\245\277\274\340\247\221\340\247\221\340\247\221\340\267\221\340\265\200\340\247\221\340\267\221\340\265\200\340\247\221\340\267\221\340\265\200\340\247\221\340\267\221\340\265\200\340\247\221\340\267\221\340\265\200\340\247\221\340\265\200\340\247\221\340\267\221\340\265\200\340\247\221\340\267\221\340\265\200\340\247\221\340\247\221\340\267\221\340\265\200\340\247\221\340\267\221\340\265\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-bd8481cfab93bc9a065153e98a3d9cc1c85d3bcf Step #5: Base64: 86W/vOCnkeCnkeCnkeC3keC1gOCnkeC3keC1gOCnkeC3keC1gOCnkeC3keC1gOCnkeC3keC1gOCnkeC1gOCnkeC3keC1gOCnkeC3keC1gOCnkeCnkeC3keC1gOCnkeC3keC1gQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4083 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3752133642 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b1267c810, 0x561b1286601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b12866020,0x561b146fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bd8481cfab93bc9a065153e98a3d9cc1c85d3bcf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5069 processed earlier; will process 5960 files now Step #5: ==147064== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561b091719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b0f7d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b0f7b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b0f7b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b09177d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b090d8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b090d3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b09169c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b0c138f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b0c138f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b0c138f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b0c138f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b0c138f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b0c138f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b0c138f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b0c138f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b0c138f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b0c138f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b0e3cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b0b0fab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b0b105be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b0aeb1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b0aeb1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b0aeb2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b0aeb1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b0aeb1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b0aeb1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b0f7bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b0f7c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b0f7ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b0f7d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd928f05082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b090d1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6d,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x54,0x58,0x2,0x3e,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x78,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x3c,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x40,0x3e,0x3e,0x3e,0x31, Step #5: ID\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000m\000\000\000\000\000\010\000\000\000\000\000TX\002>zzzzzzzzzzzzzzzzzzzzzxzzzzzzzzzzzzzzzzzzzzzzzz<>>>>>>>>>@>>>1 Step #5: artifact_prefix='./'; Test unit written to ./oom-f24152c40c17934a8aeb075ff5efe10fbff4a1f7 Step #5: Base64: SUQAAAAAAAAAAAAAAAAAAAAAAAAAAABtAAAAAAAIAAAAAABUWAI+enp6enp6enp6enp6enp6enp6enp6eHp6enp6enp6enp6enp6enp6enp6enp6ejw+Pj4+Pj4+Pj5APj4+MQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4084 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3752634855 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c0776cb810, 0x55c0778b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c0778b5020,0x55c07974d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f24152c40c17934a8aeb075ff5efe10fbff4a1f7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5070 processed earlier; will process 5959 files now Step #5: #1 pulse cov: 14084 ft: 14085 exec/s: 0 rss: 196Mb Step #5: ==147100== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c06e1c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c074825898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c0748085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c0748084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c06e1c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c06e127b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c06e122355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c06e1b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c071187f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c071187f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c071187f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c071187f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c071187f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c071187f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c071187f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c071187f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c071187f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c071187f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c07341cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c070149b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c070154be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c06ff00c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c06ff00c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c06ff01738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c06ff00874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c06ff00874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c06ff00874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c07480aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c074813928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c0747fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c074826112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdd3bdab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c06e120b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x81,0xa5,0xe0,0xac,0x8e,0xe0,0xa7,0x8e,0xe0,0xa7,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa7,0x8e,0xe0,0xa8,0x8a,0xe0,0xa8,0x8e,0xe0,0xac,0x8e,0xe0,0xa7,0x94,0xe0,0xa7,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x84,0xe0,0xa8,0x8e,0xe0,0xa8,0x85,0xe0,0xa8,0x8e,0xe0,0xa8,0x85,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0xce, Step #5: \363\240\201\245\340\254\216\340\247\216\340\247\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\247\216\340\250\212\340\250\216\340\254\216\340\247\224\340\247\216\340\250\216\340\250\204\340\250\216\340\250\205\340\250\216\340\250\205\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\316 Step #5: artifact_prefix='./'; Test unit written to ./oom-bd11896b5ac76eb158fc7a0b58f6ed1c63c6d9a1 Step #5: Base64: 86CBpeCsjuCnjuCnjuCojuCojuCojuCojuCojuCojuCojuCojuCojuCnjuCoiuCojuCsjuCnlOCnjuCojuCohOCojuCoheCojuCoheCojuCojuCojuCojuCojuCojuCojuCozg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4085 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3753216282 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c11d51d810, 0x55c11d70701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c11d707020,0x55c11f59f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bd11896b5ac76eb158fc7a0b58f6ed1c63c6d9a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5072 processed earlier; will process 5957 files now Step #5: ==147136== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c1140129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c11a677898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c11a65a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c11a65a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c114018d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c113f79b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c113f74355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c11400ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c116fd9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c116fd9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c116fd9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c116fd9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c116fd9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c116fd9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c116fd9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c116fd9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c116fd9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c116fd9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c11926ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c115f9bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c115fa6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c115d52c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c115d52c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c115d53738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c115d52874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c115d52874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c115d52874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c11a65cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c11a665928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c11a64d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c11a678112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f828cdd0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c113f72b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x53,0x3a,0xe3,0x85,0x87,0x9,0xe3,0x85,0x96,0xe3,0x85,0x87,0xe3,0x85,0x96,0xe3,0x85,0x87,0xe3,0x96,0x85,0xe3,0x85,0x87,0xe3,0x85,0x97,0xe3,0x84,0x87,0xe3,0x84,0x96,0xe3,0x85,0x87,0xe3,0x96,0x85,0xe3,0x85,0x87,0xe3,0x85,0xbd,0xe3,0x84,0x87,0xe3,0x85,0x96,0xe3,0x85,0x87,0xe3,0x85,0x96,0xe3,0x85,0x8c,0xe3,0x85,0x96,0xe1,0x85,0x87,0xe3,0x96,0x85,0xe3,0x85,0x87,0xe2,0x85,0x97,0xe3,0x84,0x87,0xe3,0x85,0x96,0xe3,0x85,0x87,0xe3,0x82,0x96,0xe3,0x85,0x8c,0xe3,0x85,0x96,0xe1,0x85,0x87,0xe3,0x85,0x96, Step #5: wS:\343\205\207\011\343\205\226\343\205\207\343\205\226\343\205\207\343\226\205\343\205\207\343\205\227\343\204\207\343\204\226\343\205\207\343\226\205\343\205\207\343\205\275\343\204\207\343\205\226\343\205\207\343\205\226\343\205\214\343\205\226\341\205\207\343\226\205\343\205\207\342\205\227\343\204\207\343\205\226\343\205\207\343\202\226\343\205\214\343\205\226\341\205\207\343\205\226 Step #5: artifact_prefix='./'; Test unit written to ./oom-7ae0c994de24a7f8868180bbb5d7b71a71742136 Step #5: Base64: d1M644WHCeOFluOFh+OFluOFh+OWheOFh+OFl+OEh+OEluOFh+OWheOFh+OFveOEh+OFluOFh+OFluOFjOOFluGFh+OWheOFh+KFl+OEh+OFluOFh+OCluOFjOOFluGFh+OFlg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4086 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3753718677 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56305b9da810, 0x56305bbc401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56305bbc4020,0x56305da5c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ae0c994de24a7f8868180bbb5d7b71a71742136' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5073 processed earlier; will process 5956 files now Step #5: ==147172== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5630524cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563058b34898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563058b175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563058b174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5630524d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563052436b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563052431355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5630524c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563055496f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563055496f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563055496f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563055496f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563055496f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563055496f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563055496f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563055496f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563055496f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563055496f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56305772bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563054458b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563054463be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56305420fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56305420fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563054210738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56305420f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56305420f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56305420f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563058b19abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563058b22928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563058b0a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563058b35112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb5e859f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56305242fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x78,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5,0xe1,0xac,0xb5, Step #5: ws:x\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265\341\254\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-f280228e5a5c2567b12349fa74212d894edc28cc Step #5: Base64: d3M6eOGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGsteGstQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4087 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3754227157 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556faa80f810, 0x556faa9f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556faa9f9020,0x556fac8910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f280228e5a5c2567b12349fa74212d894edc28cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5074 processed earlier; will process 5955 files now Step #5: ==147208== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556fa13049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556fa7969898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556fa794c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556fa794c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556fa130ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556fa126bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556fa1266355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556fa12fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556fa42cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556fa42cbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556fa42cbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556fa42cbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556fa42cbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556fa42cbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556fa42cbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556fa42cbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556fa42cbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556fa42cbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556fa6560f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556fa328db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556fa3298be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556fa3044c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556fa3044c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556fa3045738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556fa3044874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556fa3044874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556fa3044874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556fa794eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556fa7957928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556fa793f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556fa796a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7efdf8a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556fa1264b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x55,0x54,0x20,0x2f,0x27,0x20,0x48,0x54,0x54,0x50,0x2f,0x34,0x2e,0x31,0xd,0xa,0x43,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x2d,0x54,0x79,0x70,0x65,0x3a,0xef,0xbd,0x9b,0x86,0x87,0x86,0xc4,0xb0,0x86,0xc4,0x9b,0x87,0x86,0xc4,0x9b,0x87,0x86,0xac,0xc4,0x9b,0x7a,0x20,0x20,0xb8,0xab,0xab,0xaf,0xd0,0xce,0xd1,0xce,0x9f,0xf3,0xa0,0x81,0xbe,0x86,0xf6,0x86,0xc4,0x9b,0x87,0x86,0xc4,0x9b,0x87,0x86,0xc4,0x9b,0x87,0xc4,0x87,0xc4,0x86,0x86,0x9b,0x9b,0x87,0x86,0x87,0x86,0xc4,0x87,0xc4,0x9b,0x3f,0x5b,0xff,0xa,0xa, Step #5: PUT /' HTTP/4.1\015\012Content-Type:\357\275\233\206\207\206\304\260\206\304\233\207\206\304\233\207\206\254\304\233z \270\253\253\257\320\316\321\316\237\363\240\201\276\206\366\206\304\233\207\206\304\233\207\206\304\233\207\304\207\304\206\206\233\233\207\206\207\206\304\207\304\233?[\377\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-bcc00deeef7f460bc2ed8b9ae9476035abb3b943 Step #5: Base64: UFVUIC8nIEhUVFAvNC4xDQpDb250ZW50LVR5cGU6772bhoeGxLCGxJuHhsSbh4asxJt6ICC4q6uv0M7Rzp/zoIG+hvaGxJuHhsSbh4bEm4fEh8SGhpubh4aHhsSHxJs/W/8KCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4088 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3754745624 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f90acfb810, 0x55f90aee501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f90aee5020,0x55f90cd7d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bcc00deeef7f460bc2ed8b9ae9476035abb3b943' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5075 processed earlier; will process 5954 files now Step #5: ==147244== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f9017f09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f907e55898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f907e385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f907e384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f9017f6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f901757b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f901752355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f9017e8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f9047b7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f9047b7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f9047b7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f9047b7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f9047b7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f9047b7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f9047b7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f9047b7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f9047b7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f9047b7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f906a4cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f903779b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f903784be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f903530c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f903530c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f903531738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f903530874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f903530874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f903530874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f907e3aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f907e43928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f907e2b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f907e56112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd128e84082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f901750b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x25,0x60,0x3b,0x27,0x2f,0x27,0x3e,0x60,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x60,0x3b,0x27,0x2f,0x27,0x3e,0x60,0x24,0x60,0x3b,0x27,0x2f,0x27,0x7c,0x60,0x24,0x60,0x3b,0x3b,0x27,0x2f,0x27,0x3e,0x60,0xef,0xac,0xac,0xf3,0xa4,0x81,0xa9,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3e,0x60,0x60,0x3b,0x3b,0x27,0x2f,0x27,0x3e,0x60,0xef,0xac,0xac,0xf3,0xa0,0x81,0xa9,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3e,0x60,0xef,0xac,0xac,0xf3,0xa0,0x81,0xa9,0x24,0x60,0x3b,0x27,0x3d,0x27,0xff,0x5e,0x7c,0x7c,0x7c,0x3c,0x60, Step #5: `%`;'/'>`$\000\000\000\000\000\000\000\000`;'/'>`$`;'/'|`$`;;'/'>`\357\254\254\363\244\201\251$`;'/'>``;;'/'>`\357\254\254\363\240\201\251$`;'/'>`\357\254\254\363\240\201\251$`;'='\377^|||<` Step #5: artifact_prefix='./'; Test unit written to ./oom-242ec469103bd9da815c454dab4f8447c12a8e98 Step #5: Base64: YCVgOycvJz5gJAAAAAAAAAAAYDsnLyc+YCRgOycvJ3xgJGA7OycvJz5g76ys86SBqSRgOycvJz5gYDs7Jy8nPmDvrKzzoIGpJGA7Jy8nPmDvrKzzoIGpJGA7Jz0n/158fHw8YA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4089 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3755383826 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d59ac3810, 0x562d59cad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d59cad020,0x562d5bb450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/242ec469103bd9da815c454dab4f8447c12a8e98' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5076 processed earlier; will process 5953 files now Step #5: #1 pulse cov: 3504 ft: 3505 exec/s: 0 rss: 175Mb Step #5: ==147280== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562d505b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d56c1d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d56c005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d56c004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d505bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d5051fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d5051a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d505b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d5357ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d5357ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d5357ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d5357ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d5357ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d5357ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d5357ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d5357ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d5357ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d5357ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d55814f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d52541b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d5254cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d522f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d522f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d522f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d522f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d522f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d522f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d56c02abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d56c0b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d56bf3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d56c1e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f102578e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d50518b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0xf,0x31,0xb,0x73,0x20,0x5b,0x38,0x20,0x30,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x31,0x27,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xb,0x73,0x20,0x5b,0x38,0x20,0x30,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xb,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x3a,0x24,0x2d,0x5b,0xee,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\000/\000\017\017\017\017\0171-\017[\017\0171-\017\0171\013s [8 0\017\017\017\0171\017-1[1'&\021:\021-\017\017\017\017\0171\021\0171\013s [8 0\017\017\017\0171\017-1[&\021:\021-\017\017\013\017\0171\021\0171\021-::$-[\356$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-87dcfd5129d20880748f25ee4f5de2dfc34254ac Step #5: Base64: JAAALwAAAC8AAC8ADw8PDw8xLQ9bDw8xLQ8PMQtzIFs4IDAPDw8PMQ8tMVsxJyYROhEtDw8PDw8xEQ8xC3MgWzggMA8PDw8xDy0xWyYROhEtDw8LDw8xEQ8xES06OiQtW+4kWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4090 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3755935032 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55636849b810, 0x55636868501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556368685020,0x55636a51d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87dcfd5129d20880748f25ee4f5de2dfc34254ac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5078 processed earlier; will process 5951 files now Step #5: ==147316== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55635ef909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5563655f5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5563655d85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5563655d84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55635ef96d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55635eef7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55635eef2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55635ef88c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556361f57f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556361f57f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556361f57f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556361f57f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556361f57f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556361f57f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556361f57f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556361f57f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556361f57f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556361f57f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5563641ecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556360f19b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556360f24be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556360cd0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556360cd0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556360cd1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556360cd0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556360cd0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556360cd0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5563655daabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5563655e3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5563655cb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5563655f6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdee59a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55635eef0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x0,0x52,0x31,0x37,0x32,0x2d,0x2d,0x8,0x5f,0x75,0x2d,0x31,0x6c,0x69,0x73,0x74,0x20,0x46,0x6e,0x50,0x74,0x72,0x7b,0xa,0x2a,0x20,0x7b,0x4c,0x65,0x67,0x24,0x7b,0xa,0x76,0x6d,0xa,0xa,0x7d,0x6c,0x41,0x69,0xa,0x1,0x0,0x0,0x1,0x65,0x77,0x24,0x7b,0xa,0x20,0x7b,0xa,0x20,0x7d,0x20,0x7d,0xa,0x60,0xa,0xff,0xa,0x0,0x6c,0x69,0x73,0x74,0x74,0x20,0x7b,0x20,0x7d,0x5b,0x6c,0xa,0xc6,0xc6,0xc6,0xc6,0xc6,0xc6,0x29,0x3e,0xc6,0x62,0xc6,0x6f,0xc6,0x2,0x5f,0xc6,0x28,0x6f,0xc6,0xc6,0xc6,0xc6,0xc6,0xc6, Step #5: `\000R172--\010_u-1list FnPtr{\012* {Leg${\012vm\012\012}lAi\012\001\000\000\001ew${\012 {\012 } }\012`\012\377\012\000listt { }[l\012\306\306\306\306\306\306)>\306b\306o\306\002_\306(o\306\306\306\306\306\306 Step #5: artifact_prefix='./'; Test unit written to ./oom-eb06ddb965b7746cb5f902a1bd9c0f35dd06bc0c Step #5: Base64: YABSMTcyLS0IX3UtMWxpc3QgRm5QdHJ7Cioge0xlZyR7CnZtCgp9bEFpCgEAAAFldyR7CiB7CiB9IH0KYAr/CgBsaXN0dCB7IH1bbArGxsbGxsYpPsZixm/GAl/GKG/GxsbGxsY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4091 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3756560687 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558afa001810, 0x558afa1eb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558afa1eb020,0x558afc0830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eb06ddb965b7746cb5f902a1bd9c0f35dd06bc0c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5079 processed earlier; will process 5950 files now Step #5: ==147352== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558af0af69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558af715b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558af713e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558af713e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558af0afcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558af0a5db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558af0a58355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558af0aeec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558af3abdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558af3abdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558af3abdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558af3abdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558af3abdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558af3abdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558af3abdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558af3abdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558af3abdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558af3abdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558af5d52f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558af2a7fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558af2a8abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558af2836c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558af2836c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558af2837738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558af2836874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558af2836874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558af2836874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558af7140abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558af7149928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558af7131699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558af715c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f25a7db3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558af0a56b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x23,0x33,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x65,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x89,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x5b,0x2d,0x29,0x0,0x0,0x0,0x0,0x2d,0x2d,0xa,0x42,0x45,0x27,0x39,0x20,0x39,0x69,0x23,0x69,0x0,0x0,0x0,0x2e,0x0,0x0,0x0,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x6c,0x61,0x73,0x73,0x4e,0x5b,0x5b,0x5b,0x39, Step #5: s--#344444444444444444444444444444e4444444\211\000\000\000\000\000\000\000 [-)\000\000\000\000--\012BE'9 9i#i\000\000\000.\000\000\000\012-----END -----lassN[[[9 Step #5: artifact_prefix='./'; Test unit written to ./oom-e6332c3966eb0adb8218d6080f7ef11a30834701 Step #5: Base64: cy0tIzM0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NGU0NDQ0NDQ0iQAAAAAAAAAgWy0pAAAAAC0tCkJFJzkgOWkjaQAAAC4AAAAKLS0tLS1FTkQgLS0tLS1sYXNzTltbWzk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4092 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3757062046 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5634a50ee810, 0x5634a52d801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5634a52d8020,0x5634a71700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e6332c3966eb0adb8218d6080f7ef11a30834701' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5080 processed earlier; will process 5949 files now Step #5: ==147388== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56349bbe39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5634a2248898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634a222b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634a222b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56349bbe9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56349bb4ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56349bb45355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56349bbdbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56349ebaaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56349ebaaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56349ebaaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56349ebaaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56349ebaaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56349ebaaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56349ebaaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56349ebaaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56349ebaaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56349ebaaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5634a0e3ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56349db6cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56349db77be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56349d923c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56349d923c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56349d924738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56349d923874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56349d923874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56349d923874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5634a222dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5634a2236928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5634a221e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5634a2249112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ae0bc8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56349bb43b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x5b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x15,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x24,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7b,0x7b,0x7d,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0xff, Step #5: [{},{},{},{},{},{},{},{},[},{},{},{},{},{},{},{\025,{},{},{},{},{},{}${},{},{},{},{},$\000\000\000\000\000\000\000{{}},{},{}\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-ac153893c9547e88dc6cedaba452adb48cc3be61 Step #5: Base64: W3t9LHt9LHt9LHt9LHt9LHt9LHt9LHt9LFt9LHt9LHt9LHt9LHt9LHt9LHt9LHsVLHt9LHt9LHt9LHt9LHt9LHt9JHt9LHt9LHt9LHt9LHt9LCQAAAAAAAAAe3t9fSx7fSx7ff8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4093 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3757572975 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b6be674810, 0x55b6be85e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b6be85e020,0x55b6c06f60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ac153893c9547e88dc6cedaba452adb48cc3be61' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5081 processed earlier; will process 5948 files now Step #5: ==147424== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b6b51699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b6bb7ce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b6bb7b15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b6bb7b14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6b516fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6b50d0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6b50cb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6b5161c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b6b8130f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b6b8130f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b6b8130f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b6b8130f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b6b8130f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b6b8130f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b6b8130f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b6b8130f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b6b8130f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b6b8130f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b6ba3c5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6b70f2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6b70fdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6b6ea9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6b6ea9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6b6eaa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6b6ea9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6b6ea9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6b6ea9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b6bb7b3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b6bb7bc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b6bb7a4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b6bb7cf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f44a79d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6b50c9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x70,0x2b,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x2e,0x55,0x57,0x30,0x2d,0x38,0x31,0x38,0x7,0x31,0x57,0x3d,0x39,0xd,0x27,0x7e,0x60,0x60,0x60,0x2d,0x60,0x21,0x60,0x60,0xf,0x60,0x2b,0x60,0xd,0x7,0x27,0x60,0x60,0x60,0x2d,0x60,0x60,0x60,0x5f,0x6f,0x70,0x74,0x69,0x6f,0x6e,0x7,0x5f,0x60,0x60,0x60,0x2b,0x60,0xd,0x5,0x27,0x60,0x60,0x7,0x53,0x53,0x53,0x9,0x9,0x9,0x21,0x3d,0x32,0x37,0x36,0x7c,0x9,0x60,0x60,0x5f,0x60,0xa6,0xd,0x7,0x60,0xd0,0x60,0x60,0x60, Step #5: \012```````p+````````.UW0-818\0071W=9\015'~```-`!``\017`+`\015\007'```-```_option\007_```+`\015\005'``\007SSS\011\011\011!=276|\011``_`\246\015\007`\320``` Step #5: artifact_prefix='./'; Test unit written to ./oom-326db6c14ce101c78d4bc0876bb096b91d6bca71 Step #5: Base64: CmBgYGBgYGBwK2BgYGBgYGBgLlVXMC04MTgHMVc9OQ0nfmBgYC1gIWBgD2ArYA0HJ2BgYC1gYGBfb3B0aW9uB19gYGArYA0FJ2BgB1NTUwkJCSE9Mjc2fAlgYF9gpg0HYNBgYGA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4094 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3758670368 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55948cd6e810, 0x55948cf5801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55948cf58020,0x55948edf00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/326db6c14ce101c78d4bc0876bb096b91d6bca71' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5082 processed earlier; will process 5947 files now Step #5: #1 pulse cov: 3703 ft: 3704 exec/s: 0 rss: 173Mb Step #5: ==147460== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5594838639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559489ec8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559489eab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559489eab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559483869d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5594837cab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5594837c5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55948385bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55948682af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55948682af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55948682af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55948682af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55948682af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55948682af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55948682af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55948682af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55948682af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55948682af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559488abff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5594857ecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5594857f7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5594855a3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5594855a3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5594855a4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5594855a3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5594855a3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5594855a3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559489eadabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559489eb6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559489e9e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559489ec9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f40006a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5594837c3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x24,0x30,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x30,0x28,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28,0x24,0x30,0x28, Step #5: ($00($0($0($0($0($0($0($0($0($0($0($0($0($0($0($0($0($0($0($0($00(($0($0($00($0($0($0($0($0($0($0($0( Step #5: artifact_prefix='./'; Test unit written to ./oom-b61e45d6279bf65a4d713926e544f3ab48948193 Step #5: Base64: KCQwMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMDAoKCQwKCQwKCQwMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCgkMCg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4095 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3759224890 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5646d408e810, 0x5646d427801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5646d4278020,0x5646d61100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b61e45d6279bf65a4d713926e544f3ab48948193' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5084 processed earlier; will process 5945 files now Step #5: #1 pulse cov: 4001 ft: 4002 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 12215 ft: 13049 exec/s: 0 rss: 193Mb Step #5: ==147496== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5646cab839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5646d11e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5646d11cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5646d11cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5646cab89d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5646caaeab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5646caae5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5646cab7bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5646cdb4af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5646cdb4af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5646cdb4af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5646cdb4af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5646cdb4af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5646cdb4af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5646cdb4af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5646cdb4af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5646cdb4af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5646cdb4af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5646cfddff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5646ccb0cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5646ccb17be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5646cc8c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5646cc8c3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5646cc8c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5646cc8c3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5646cc8c3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5646cc8c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5646d11cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5646d11d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5646d11be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5646d11e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7341ac1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5646caae3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x7d,0x7d,0x7d,0x3c,0x74,0x65,0x78,0x74,0x3e,0x4d,0x5b,0x74,0x5b,0x5b,0x74,0x7b,0x7b,0x7b,0x3e,0x63,0x3a,0x3a,0x3a,0x3a,0x5d,0x5d,0x44,0xe1,0x9e,0xb2,0xe2,0x80,0x8c,0x73,0x7b,0x3e,0x74,0x7b,0x7b,0x72,0x6f,0x75,0x6e,0x64,0x7b,0x7b,0x5b,0x7b,0x5b,0x5b,0x5b,0x7b,0x5b,0x5b,0x5b,0x7b,0x5b,0x5b,0x5b,0x5b,0x5b,0x53,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x7b,0x5b,0x5b,0x5b,0x74,0x7b,0x7b,0x7b,0x3e,0x63,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x42,0x4f,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg>}}}<text>M[t[[t{{{>c::::]]D\341\236\262\342\200\214s{>t{{round{{[{[[[{[[[{[[[[[S[[[[[[[[[{[[[t{{{>c</text>BO</svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-cf2a7192d8e97db37fc3a74c40a37cc5f026e3ca Step #5: Base64: PHN2Zz59fX08dGV4dD5NW3RbW3R7e3s+Yzo6OjpdXUThnrLigIxzez50e3tyb3VuZHt7W3tbW1t7W1tbe1tbW1tbU1tbW1tbW1tbW3tbW1t0e3t7PmM8L3RleHQ+Qk88L3N2Zz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4096 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3759836225 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558ff5c4c810, 0x558ff5e3601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558ff5e36020,0x558ff7cce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf2a7192d8e97db37fc3a74c40a37cc5f026e3ca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5087 processed earlier; will process 5942 files now Step #5: ==147532== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558fec7419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558ff2da6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558ff2d895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558ff2d894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558fec747d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558fec6a8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558fec6a3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558fec739c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558fef708f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558fef708f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558fef708f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558fef708f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558fef708f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558fef708f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558fef708f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558fef708f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558fef708f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558fef708f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558ff199df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558fee6cab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558fee6d5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558fee481c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558fee481c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558fee482738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558fee481874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558fee481874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558fee481874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558ff2d8babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558ff2d94928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558ff2d7c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558ff2da7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa0719d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558fec6a1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x22,0x5c,0x75,0x7b,0x66,0x46,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x46,0x7d,0x5c,0x75,0x7b,0x62,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x46,0x7d,0x5c,0x75,0x7b,0x62,0x66,0x7d,0xa4,0x8a, Step #5: \012\"\\u{fF}\\u{ff}\\u{ff}\\u{fff}\\u{ff}\\u{ff}\\u{ff}\\u{fF}\\u{bf}\\u{ff}\\u{ff}\\u{ff}\\u{ff}\\u{ff}\\u{fF}\\u{bf}\244\212 Step #5: artifact_prefix='./'; Test unit written to ./oom-680d8e685ade6914713046219c08e77ce8fc0c18 Step #5: Base64: CiJcdXtmRn1cdXtmZn1cdXtmZn1cdXtmZmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZkZ9XHV7YmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZkZ9XHV7YmZ9pIo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4097 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3760335850 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557278725810, 0x55727890f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55727890f020,0x55727a7a70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/680d8e685ade6914713046219c08e77ce8fc0c18' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5088 processed earlier; will process 5941 files now Step #5: ==147568== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55726f21a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55727587f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5572758625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5572758624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55726f220d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55726f181b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55726f17c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55726f212c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5572721e1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5572721e1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5572721e1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5572721e1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5572721e1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5572721e1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5572721e1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5572721e1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5572721e1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5572721e1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557274476f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5572711a3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5572711aebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557270f5ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557270f5ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557270f5b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557270f5a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557270f5a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557270f5a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557275864abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55727586d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557275855699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557275880112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f52829d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55726f17ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0x24,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0x24,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81, Step #5: ws:\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201$\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201$\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-e347181209116985284f0f4b327866d6938a935a Step #5: Base64: d3M64L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6BJOC+geC+geC+geC+geC+geC+geC+geC+geC+geC+geC+gSTgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvoE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4098 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3760840161 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559611385810, 0x55961156f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55961156f020,0x5596134070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e347181209116985284f0f4b327866d6938a935a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5089 processed earlier; will process 5940 files now Step #5: ==147604== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559607e7a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55960e4df898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55960e4c25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55960e4c24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559607e80d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559607de1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559607ddc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559607e72c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55960ae41f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55960ae41f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55960ae41f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55960ae41f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55960ae41f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55960ae41f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55960ae41f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55960ae41f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55960ae41f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55960ae41f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55960d0d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559609e03b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559609e0ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559609bbac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559609bbac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559609bbb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559609bba874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559609bba874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559609bba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55960e4c4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55960e4cd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55960e4b5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55960e4e0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb01f32f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559607ddab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x2b,0x33,0x35,0x2d,0x34,0x2d,0x60,0x6,0xc,0x7d,0x0,0x60,0x60,0x25,0xb,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x31,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5f,0x66,0x33,0x32,0x0,0x0,0x0,0x0,0x0,0x0,0xe3,0x80,0x81,0xa,0xe3,0x80,0x81,0xa,0xe3,0x80,0x81,0x6f,0x66,0x28,0x1a,0xe3,0x80,0x81,0xa,0xe3,0x80,0x81,0x65,0x74,0x79,0x70,0x7a,0x60,0x25,0x60,0x24,0x7b,0x20,0x67,0x7d,0x60,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x35,0x5b,0x57,0x57, Step #5: 0+35-4-`\006\014}\000``%\013\000\000\000\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000_f32\000\000\000\000\000\000\343\200\201\012\343\200\201\012\343\200\201of(\032\343\200\201\012\343\200\201etypz`%`${ g}`\377\377\377\377\377\377\377\377\377\3775[WW Step #5: artifact_prefix='./'; Test unit written to ./oom-40b015e954d97fdd70878fdcd639113ee52782a0 Step #5: Base64: MCszNS00LWAGDH0AYGAlCwAAAAAAAAAxAAAAAAAAAAAAAAAAAAAAAABfZjMyAAAAAAAA44CBCuOAgQrjgIFvZiga44CBCuOAgWV0eXB6YCVgJHsgZ31g/////////////zVbV1c= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4099 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3761467453 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f8468cb810, 0x55f846ab501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f846ab5020,0x55f84894d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40b015e954d97fdd70878fdcd639113ee52782a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5090 processed earlier; will process 5939 files now Step #5: ==147640== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f83d3c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f843a25898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f843a085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f843a084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f83d3c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f83d327b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f83d322355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f83d3b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f840387f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f840387f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f840387f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f840387f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f840387f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f840387f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f840387f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f840387f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f840387f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f840387f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f84261cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f83f349b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f83f354be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f83f100c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f83f100c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f83f101738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f83f100874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f83f100874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f83f100874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f843a0aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f843a13928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f8439fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f843a26112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9717280082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f83d320b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x7c,0x60,0xe2,0x81,0x9f,0x24,0x5,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x20,0x67,0x7d,0x60,0x25,0x60,0x24,0x7b,0x7d,0x60,0x25,0x60,0xe2,0x81,0x9f,0x24,0x24,0x20,0x9,0x5f,0x6f,0x70,0x74,0x5f,0x62,0x6f,0x6f,0x6c,0x5f,0x60,0x25,0x60,0x24,0x7b,0x7d,0x60,0x25,0x60,0x7d,0x2d,0x60,0x60,0x24,0x24,0x7b,0x7d,0x60,0xdb,0xe2,0x81,0x9f,0x24,0x5,0xff,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x20,0x0,0x0,0x7d,0x0,0x70,0x60,0x25,0x67,0x0,0x11,0x25,0x0,0x0,0x22,0x23,0x1,0x0,0x20,0x0,0x0,0x0,0x0,0x60, Step #5: ||`\342\201\237$\005\000\000\000\000\000\000\000\012 g}`%`${}`%`\342\201\237$$ \011_opt_bool_`%`${}`%`}-``$${}`\333\342\201\237$\005\377\000\000\000\000\000\000\012 \000\000}\000p`%g\000\021%\000\000\"#\001\000 \000\000\000\000` Step #5: artifact_prefix='./'; Test unit written to ./oom-a4c6b5c900937ba63da7b5185de696b14cd4e3e3 Step #5: Base64: fHxg4oGfJAUAAAAAAAAACiBnfWAlYCR7fWAlYOKBnyQkIAlfb3B0X2Jvb2xfYCVgJHt9YCVgfS1gYCQke31g2+KBnyQF/wAAAAAAAAogAAB9AHBgJWcAESUAACIjAQAgAAAAAGA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4100 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3762105525 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562a33aba810, 0x562a33ca401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562a33ca4020,0x562a35b3c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a4c6b5c900937ba63da7b5185de696b14cd4e3e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5091 processed earlier; will process 5938 files now Step #5: ==147676== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562a2a5af9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562a30c14898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562a30bf75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562a30bf74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562a2a5b5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562a2a516b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562a2a511355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562a2a5a7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562a2d576f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562a2d576f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562a2d576f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562a2d576f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562a2d576f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562a2d576f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562a2d576f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562a2d576f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562a2d576f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562a2d576f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562a2f80bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562a2c538b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562a2c543be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562a2c2efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562a2c2efc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562a2c2f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562a2c2ef874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562a2c2ef874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562a2c2ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562a30bf9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562a30c02928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562a30bea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562a30c15112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5272f1a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562a2a50fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2d,0x41,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x63,0x6f,0x66,0x62,0x65,0x65,0x2d,0x2d,0x42,0x2d,0xa,0xd3,0xce,0x2d,0x2d,0x2d,0x41, Step #5: \000-A-\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000cofbee--B-\012\323\316---A Step #5: artifact_prefix='./'; Test unit written to ./oom-f5b9663f23cce10e053caebab3c8fbd55e1a7696 Step #5: Base64: AC1BLQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAY29mYmVlLS1CLQrTzi0tLUE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4101 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3762625426 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55885f874810, 0x55885fa5e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55885fa5e020,0x5588618f60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f5b9663f23cce10e053caebab3c8fbd55e1a7696' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5092 processed earlier; will process 5937 files now Step #5: ==147712== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5588563699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55885c9ce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55885c9b15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55885c9b14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55885636fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588562d0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588562cb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558856361c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558859330f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558859330f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558859330f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558859330f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558859330f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558859330f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558859330f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558859330f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558859330f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558859330f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55885b5c5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588582f2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588582fdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588580a9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588580a9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588580aa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588580a9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588580a9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588580a9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55885c9b3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55885c9bc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55885c9a4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55885c9cf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f647d2bd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588562c9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x81,0x9f,0x24,0x24,0x20,0x9,0x67,0x7d,0x60,0x25,0x60,0x24,0x7b,0x7d,0x60,0x25,0x60,0x24,0x20,0x9,0x74,0xa,0xa,0xa,0xa,0x63,0x6f,0x6e,0x73,0x74,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x6e,0x6a,0x6e,0x6c,0x6e,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x60,0x25,0x60,0x24,0x7b,0x7d,0x60,0x25,0x60,0x24,0x7b,0x7d,0x60,0x25,0x60,0x24,0x60,0x25,0x60,0x24,0x7b,0x7d,0x60,0xff,0xff,0xff,0xff,0x41,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x2e,0x57,0x57, Step #5: `\342\201\237$$ \011g}`%`${}`%`$ \011t\012\012\012\012const\012\012\012\012\012\012\012\012njnlnccccccccccccccccc`%`${}`%`${}`%`$`%`${}`\377\377\377\377A\377\377\377\377\377\377\377\377.WW Step #5: artifact_prefix='./'; Test unit written to ./oom-acc25b3652c0f8962de7aef880e1d8b949356f10 Step #5: Base64: YOKBnyQkIAlnfWAlYCR7fWAlYCQgCXQKCgoKY29uc3QKCgoKCgoKCm5qbmxuY2NjY2NjY2NjY2NjY2NjY2NgJWAke31gJWAke31gJWAkYCVgJHt9YP////9B//////////8uV1c= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4102 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3763266860 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a1f13e810, 0x558a1f32801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a1f328020,0x558a211c00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/acc25b3652c0f8962de7aef880e1d8b949356f10' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5093 processed earlier; will process 5936 files now Step #5: ==147748== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558a15c339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a1c298898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a1c27b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a1c27b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a15c39d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a15b9ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a15b95355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a15c2bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a18bfaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a18bfaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a18bfaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a18bfaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a18bfaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a18bfaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a18bfaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a18bfaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a18bfaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a18bfaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a1ae8ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a17bbcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a17bc7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a17973c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a17973c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a17974738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a17973874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a17973874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a17973874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a1c27dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a1c286928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a1c26e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a1c299112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f998375d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a15b93b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x73,0x75,0x62,0x5f,0x73,0x76,0x76,0x28,0x28,0x29,0x2b,0x22,0x22,0x22,0x22,0x22,0x22,0x29,0xa,0x3b,0x69,0x6d,0x70,0x6f,0x72,0x74,0x22,0x22,0x61,0x73,0x20,0x69,0xa,0x3b,0x69,0x6d,0x70,0x6f,0x72,0x74,0x20,0x20,0x79,0x5f,0x62,0x28,0x20,0x7d,0x20,0x60,0x7b,0xa,0x5f,0x65,0x6e,0x75,0x20,0xf,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x60,0x7b,0xa,0x20,0x2f,0x2f,0x2f,0x43,0x71,0xff,0xff,0xff,0xff,0xff,0xca,0xb3,0x2,0x71,0x49,0x71,0x32, Step #5: ZZZZZZZZZZZZZZZZsub_svv(()+\"\"\"\"\"\")\012;import\"\"as i\012;import y_b( } `{\012_enu \017//////`{\012 ///Cq\377\377\377\377\377\312\263\002qIq2 Step #5: artifact_prefix='./'; Test unit written to ./oom-dee51fad94ff8d4506149e3bf2473513135785dd Step #5: Base64: WlpaWlpaWlpaWlpaWlpaWnN1Yl9zdnYoKCkrIiIiIiIiKQo7aW1wb3J0IiJhcyBpCjtpbXBvcnQgIHlfYiggfSBgewpfZW51IA8vLy8vLy9gewogLy8vQ3H//////8qzAnFJcTI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4103 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3763897391 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647e1a21810, 0x5647e1c0b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5647e1c0b020,0x5647e3aa30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dee51fad94ff8d4506149e3bf2473513135785dd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5094 processed earlier; will process 5935 files now Step #5: ==147784== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647d85169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647deb7b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647deb5e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647deb5e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647d851cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647d847db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647d8478355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647d850ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647db4ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647db4ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647db4ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647db4ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647db4ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647db4ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647db4ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647db4ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647db4ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647db4ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647dd772f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647da49fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647da4aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647da256c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647da256c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647da257738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647da256874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647da256874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647da256874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647deb60abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647deb69928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647deb51699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647deb7c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0959319082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647d8476b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x81,0x9f,0x24,0x24,0xf3,0xb0,0x81,0xac,0x20,0x9,0x67,0xe2,0x81,0x9f,0x24,0x24,0x20,0x9,0x67,0x7d,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x40,0x25,0x5,0x24,0x7b,0x7d,0x60,0x25,0x60,0x24,0x20,0x0,0x0,0x40,0x25,0x5,0x24,0x7b,0x7d,0x60,0x25,0x60,0x24,0x20,0x9,0x67,0x7d,0x60,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x24,0x7b,0x7d,0x2e,0x60,0x24,0x7b,0x7d,0x2e,0x60,0x24,0x7b,0x7d,0x70,0x3d,0x60,0x5e,0x25,0x2e,0xff,0x77,0x76,0x76,0x28,0x28,0x29,0x65,0x60,0x2e,0x29,0x29,0x29,0x57,0x29,0x57, Step #5: `\342\201\237$$\363\260\201\254 \011g\342\201\237$$ \011g}\001\000\000\000\000\000\000\000@%\005${}`%`$ \000\000@%\005${}`%`$ \011g}`\377\377\377\377\377\377\377\377${}.`${}.`${}p=`^%.\377wvv(()e`.)))W)W Step #5: artifact_prefix='./'; Test unit written to ./oom-a126043145d7f61d6cd7b9d3ccf195a7f9770af9 Step #5: Base64: YOKBnyQk87CBrCAJZ+KBnyQkIAlnfQEAAAAAAAAAQCUFJHt9YCVgJCAAAEAlBSR7fWAlYCQgCWd9YP//////////JHt9LmAke30uYCR7fXA9YF4lLv93dnYoKCllYC4pKSlXKVc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4104 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3764526876 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b932736810, 0x55b93292001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b932920020,0x55b9347b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a126043145d7f61d6cd7b9d3ccf195a7f9770af9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5095 processed earlier; will process 5934 files now Step #5: ==147820== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b92922b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b92f890898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b92f8735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b92f8734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b929231d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b929192b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b92918d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b929223c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b92c1f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b92c1f2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b92c1f2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b92c1f2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b92c1f2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b92c1f2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b92c1f2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b92c1f2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b92c1f2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b92c1f2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b92e487f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b92b1b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b92b1bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b92af6bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b92af6bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b92af6c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b92af6b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b92af6b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b92af6b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b92f875abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b92f87e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b92f866699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b92f891112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f23df4ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b92918bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x79,0x32,0x61,0x78,0x74,0x63,0x5f,0x62,0x79,0x74,0x65,0x73,0x5f,0x75,0x5f,0x26,0x26,0x74,0x63,0x75,0x65,0x5e,0x79,0x5f,0x75,0x6e,0x69,0x74,0x26,0x26,0x78,0x32,0x26,0x61,0x5f,0x36,0x32,0x4f,0x78,0x37,0x75,0x5f,0x26,0x26,0x78,0x32,0x35,0x35,0x30,0x38,0x61,0x5f,0x26,0x26,0x78,0xec,0x99,0x9c,0x79,0x74,0x65,0x75,0x5e,0x61,0x2e,0x5f,0x61,0x26,0x63,0x79,0x63,0x79,0x8e,0xd9,0xcc,0x9e,0x5f,0x3f,0x75,0x5f,0x26,0x26,0x78,0x37,0x32,0x35,0x35,0x66,0x5f,0x61,0x63,0x0,0x0,0x0,0x61,0x50,0x5f,0x65,0x5e,0x73,0x59, Step #5: y2axtc_bytes_u_&&tcue^y_unit&&x2&a_62Ox7u_&&x25508a_&&x\354\231\234yteu^a._a&cycy\216\331\314\236_?u_&&x7255f_ac\000\000\000aP_e^sY Step #5: artifact_prefix='./'; Test unit written to ./oom-3574246be994dec7651c718070d0b43dab2126e4 Step #5: Base64: eTJheHRjX2J5dGVzX3VfJiZ0Y3VlXnlfdW5pdCYmeDImYV82Mk94N3VfJiZ4MjU1MDhhXyYmeOyZnHl0ZXVeYS5fYSZjeWN5jtnMnl8/dV8mJng3MjU1Zl9hYwAAAGFQX2Vec1k= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4105 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3765034847 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557123b95810, 0x557123d7f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557123d7f020,0x557125c170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3574246be994dec7651c718070d0b43dab2126e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5096 processed earlier; will process 5933 files now Step #5: ==147856== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55711a68a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557120cef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557120cd25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557120cd24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55711a690d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55711a5f1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55711a5ec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55711a682c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55711d651f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55711d651f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55711d651f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55711d651f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55711d651f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55711d651f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55711d651f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55711d651f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55711d651f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55711d651f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55711f8e6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55711c613b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55711c61ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55711c3cac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55711c3cac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55711c3cb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55711c3ca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55711c3ca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55711c3ca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557120cd4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557120cdd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557120cc5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557120cf0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7effdfe6f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55711a5eab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x20,0x20,0x7d,0x78,0x41,0x58,0x0,0x0,0x0,0xcd,0x8f,0x5e,0x1,0x2,0x0,0x0,0x0,0x32,0x2f,0x3c,0x31,0x5b,0xf3,0xa0,0x81,0xbb,0x0,0x0,0x0,0x0,0x0,0x2,0xcf,0xaa,0xf3,0xb0,0x81,0xbb,0xf3,0xa0,0x81,0xb3,0x39,0xcf,0xaa,0xf3,0xa0,0x81,0xbb,0xf3,0xa0,0x81,0xb3,0x39,0x3b,0xcf,0xaa,0xf3,0xa0,0x81,0xbb,0xe2,0x80,0x8e,0xf3,0xa0,0x81,0xb3,0x33,0x32,0x37,0x38,0x32,0x26,0x60,0x5b,0x31,0x2e,0x2e,0x5d,0x5b,0x31,0x2d,0x30,0x2e,0x5d,0xd8,0xd8,0xef,0xbe,0xa1,0x0,0x10,0x0,0x0,0x0,0x0,0x2,0x3e,0x63, Step #5: ` }xAX\000\000\000\315\217^\001\002\000\000\0002/<1[\363\240\201\273\000\000\000\000\000\002\317\252\363\260\201\273\363\240\201\2639\317\252\363\240\201\273\363\240\201\2639;\317\252\363\240\201\273\342\200\216\363\240\201\26332782&`[1..][1-0.]\330\330\357\276\241\000\020\000\000\000\000\002>c Step #5: artifact_prefix='./'; Test unit written to ./oom-4acb68a458af86e75eaa20e99856cae5d461c627 Step #5: Base64: YCAgfXhBWAAAAM2PXgECAAAAMi88MVvzoIG7AAAAAAACz6rzsIG786CBsznPqvOggbvzoIGzOTvPqvOggbvigI7zoIGzMzI3ODImYFsxLi5dWzEtMC5d2NjvvqEAEAAAAAACPmM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4106 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3765661360 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56420343c810, 0x56420362601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564203626020,0x5642054be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4acb68a458af86e75eaa20e99856cae5d461c627' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5097 processed earlier; will process 5932 files now Step #5: ==147892== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5641f9f319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564200596898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5642005795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5642005794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5641f9f37d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641f9e98b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641f9e93355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5641f9f29c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5641fcef8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5641fcef8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5641fcef8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5641fcef8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5641fcef8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5641fcef8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5641fcef8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5641fcef8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5641fcef8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5641fcef8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5641ff18df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5641fbebab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5641fbec5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5641fbc71c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5641fbc71c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5641fbc72738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5641fbc71874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5641fbc71874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5641fbc71874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56420057babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564200584928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56420056c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564200597112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1af17df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641f9e91b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x7b,0x22,0x72,0x65,0x73,0x6f,0x75,0x72,0x63,0x65,0x4d,0x65,0x74,0x72,0x69,0x63,0x73,0x22,0x5b,0x5b,0x56,0x7b,0x22,0x22,0x73,0x63,0x6f,0x70,0x65,0x5f,0x6d,0x65,0x74,0x72,0x69,0x63,0x73,0x22,0x1b,0x5b,0x4e,0x7b,0x22,0x22,0x73,0x63,0x6f,0x70,0x65,0x22,0x65,0x7b,0x22,0x2c,0x5b,0x0,0x2c,0x22,0x64,0x72,0x6f,0x70,0x70,0x65,0x64,0x41,0x74,0xf0,0x90,0x9a,0x8c,0xf0,0x90,0x9a,0x90,0xf0,0x90,0x9a,0x8c,0xf0,0x90,0x90,0x8a,0x27,0xf0,0x90,0x9a,0x90,0x30,0xdf,0xf0,0x90,0x9a,0x93,0x8a,0xf0,0x90,0x9a,0x90,0x22, Step #5: F{\"resourceMetrics\"[[V{\"\"scope_metrics\"\033[N{\"\"scope\"e{\",[\000,\"droppedAt\360\220\232\214\360\220\232\220\360\220\232\214\360\220\220\212'\360\220\232\2200\337\360\220\232\223\212\360\220\232\220\" Step #5: artifact_prefix='./'; Test unit written to ./oom-2ae37f6d9b6fa281765ff7d4d30bf6c593f278cc Step #5: Base64: RnsicmVzb3VyY2VNZXRyaWNzIltbVnsiInNjb3BlX21ldHJpY3MiG1tOeyIic2NvcGUiZXsiLFsALCJkcm9wcGVkQXTwkJqM8JCakPCQmozwkJCKJ/CQmpAw3/CQmpOK8JCakCI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4107 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3766170803 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c6d047c810, 0x55c6d066601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c6d0666020,0x55c6d24fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2ae37f6d9b6fa281765ff7d4d30bf6c593f278cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5098 processed earlier; will process 5931 files now Step #5: #1 pulse cov: 3586 ft: 3587 exec/s: 0 rss: 174Mb Step #5: ==147928== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c6c6f719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c6cd5d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c6cd5b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c6cd5b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c6c6f77d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6c6ed8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6c6ed3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c6c6f69c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c6c9f38f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c6c9f38f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c6c9f38f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c6c9f38f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c6c9f38f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c6c9f38f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c6c9f38f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c6c9f38f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c6c9f38f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c6c9f38f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c6cc1cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6c8efab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c6c8f05be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6c8cb1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6c8cb1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6c8cb2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6c8cb1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6c8cb1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6c8cb1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c6cd5bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c6cd5c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c6cd5ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c6cd5d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff6f5cb7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6c6ed1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x47,0x47,0x47,0x57,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x6e,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: \012-----BEGIN -----\012GGGWGGGGGGGGGGGGGGGGGGffffffffffffffffffffffffffffnffffffffGGGGGGGGG\012-----END ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-1c3cd3b19439a0fcb4f5f5b8b7bec59823732c28 Step #5: Base64: Ci0tLS0tQkVHSU4gLS0tLS0KR0dHV0dHR0dHR0dHR0dHR0dHR0dHR2ZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZuZmZmZmZmZmZHR0dHR0dHR0cKLS0tLS1FTkQgLS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4108 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3766714334 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5605b9425810, 0x5605b960f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5605b960f020,0x5605bb4a70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c3cd3b19439a0fcb4f5f5b8b7bec59823732c28' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5100 processed earlier; will process 5929 files now Step #5: ==147964== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5605aff1a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605b657f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605b65625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605b65624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5605aff20d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605afe81b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5605afe7c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5605aff12c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605b2ee1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605b2ee1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605b2ee1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605b2ee1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605b2ee1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605b2ee1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605b2ee1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605b2ee1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605b2ee1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605b2ee1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605b5176f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5605b1ea3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5605b1eaebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5605b1c5ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5605b1c5ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5605b1c5b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5605b1c5a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5605b1c5a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5605b1c5a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605b6564abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5605b656d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605b6555699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605b6580112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6899a80082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5605afe7ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0x5b,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x84,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x2b,0x2d,0xf2,0x85,0x84,0x93,0x0,0x2d,0xf2,0x85,0x85,0x92,0x0,0x2d,0xf3,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x84,0x85,0x93,0x1,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x8c,0x85,0x93,0x0,0x2d,0xf2,0x85,0x95,0x92,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93, Step #5: (?i)[\000-\362\205\205\223\000-\362\205\205\223\000-\362\204\205\223\000-\362\205\205\223+-\362\205\204\223\000-\362\205\205\222\000-\363\205\205\223\000-\362\205\205\223\000-\362\205\205\223\000-\362\204\205\223\001-\362\205\205\223\000-\362\214\205\223\000-\362\205\225\222\000-\362\205\205\223\000-\362\205\205\223\000-\362\205\205\223 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a9a2023ae54376f6457f583bc1608e82d9acf8b Step #5: Base64: KD9pKVsALfKFhZMALfKFhZMALfKEhZMALfKFhZMrLfKFhJMALfKFhZIALfOFhZMALfKFhZMALfKFhZMALfKEhZMBLfKFhZMALfKMhZMALfKFlZIALfKFhZMALfKFhZMALfKFhZM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4109 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3767221529 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af92d01810, 0x55af92eeb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af92eeb020,0x55af94d830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a9a2023ae54376f6457f583bc1608e82d9acf8b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5101 processed earlier; will process 5928 files now Step #5: ==148000== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55af897f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af8fe5b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af8fe3e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af8fe3e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55af897fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55af8975db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55af89758355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55af897eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55af8c7bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55af8c7bdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55af8c7bdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55af8c7bdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55af8c7bdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55af8c7bdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55af8c7bdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55af8c7bdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55af8c7bdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55af8c7bdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af8ea52f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af8b77fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af8b78abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af8b536c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af8b536c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af8b537738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af8b536874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af8b536874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af8b536874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af8fe40abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af8fe49928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af8fe31699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af8fe5c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb48d6a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55af89756b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x7c,0x7c,0x7c,0x2d,0xd,0x30,0x62,0x30,0x30,0x30,0x2d,0xd,0xd,0x34,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0x2d,0xd,0x2b,0x30,0x42,0x30,0xd,0x2d,0xd,0x75,0x5f,0x2b,0x30,0x42,0x30,0xd,0x2d,0xd,0x35,0x5f,0x25,0xd,0x2b,0x30,0x42,0x30,0xd,0x2d,0xd,0x35,0x5f,0x25,0xd,0x2b,0x30,0x42,0x30,0xd,0x2d,0xd,0x5f,0x35,0x74,0x75,0x70,0xff,0x0,0x0,0x0,0x0,0xff,0x0,0x0,0x0,0xff,0xff,0x0,0x0,0xff,0xff,0xff,0xff,0x0,0x0,0xff,0xff,0xff,0x0,0x0,0xff,0x33,0x30,0x31,0xff,0x35,0x56, Step #5: ||||-\0150b000-\015\0154\015\015\015\015\015\015\015\015\015\015-\015+0B0\015-\015u_+0B0\015-\0155_%\015+0B0\015-\0155_%\015+0B0\015-\015_5tup\377\000\000\000\000\377\000\000\000\377\377\000\000\377\377\377\377\000\000\377\377\377\000\000\377301\3775V Step #5: artifact_prefix='./'; Test unit written to ./oom-2e235362d5e44103bc4de6d9fdef4873fbb44668 Step #5: Base64: fHx8fC0NMGIwMDAtDQ00DQ0NDQ0NDQ0NDS0NKzBCMA0tDXVfKzBCMA0tDTVfJQ0rMEIwDS0NNV8lDSswQjANLQ1fNXR1cP8AAAAA/wAAAP//AAD/////AAD///8AAP8zMDH/NVY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4110 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3767738410 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e3702b810, 0x563e3721501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e37215020,0x563e390ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2e235362d5e44103bc4de6d9fdef4873fbb44668' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5102 processed earlier; will process 5927 files now Step #5: ==148036== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563e2db209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e34185898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e341685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e341684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e2db26d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e2da87b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e2da82355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e2db18c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e30ae7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e30ae7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e30ae7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e30ae7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e30ae7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e30ae7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e30ae7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e30ae7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e30ae7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e30ae7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e32d7cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e2faa9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e2fab4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e2f860c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e2f860c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e2f861738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e2f860874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e2f860874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e2f860874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e3416aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e34173928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e3415b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e34186112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fca1ce90082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e2da80b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x0,0x2b,0x2d,0xa,0x2,0x2,0x7d,0xa,0x7d,0x24,0x7b,0xa,0x78,0x7d,0xa,0x7d,0x24,0x7b,0x78,0xa,0x7d,0x7d,0x7d,0xa,0x24,0x7b,0xa,0x78,0x7d,0xa,0x7d,0x25,0x24,0x7b,0x7d,0xa,0x7d,0x0,0x0,0x10,0x0,0x0,0x68,0x5f,0x75,0x30,0x7e,0x35,0x7d,0x2a,0x6c,0x74,0x20,0x60,0xf6,0x0,0x0,0x90,0xa,0x78,0x7d,0xa,0x7d,0x24,0x7b,0x78,0xa,0x7d,0x7d,0x7d,0xa,0x24,0x7b,0xa,0x78,0x7d,0xa,0x5f,0x69,0x31,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x87,0xf6,0xf9,0xaa,0x2d,0x5e,0x2d,0x2f,0x34,0x30,0x5e, Step #5: `\000+-\012\002\002}\012}${\012x}\012}${x\012}}}\012${\012x}\012}%${}\012}\000\000\020\000\000h_u0~5}*lt `\366\000\000\220\012x}\012}${x\012}}}\012${\012x}\012_i1\000\000\000\000\000\000\000\000\000\207\366\371\252-^-/40^ Step #5: artifact_prefix='./'; Test unit written to ./oom-0de810d63fbdfc31b491b558eae8e416d439d711 Step #5: Base64: YAArLQoCAn0KfSR7Cnh9Cn0ke3gKfX19CiR7Cnh9Cn0lJHt9Cn0AABAAAGhfdTB+NX0qbHQgYPYAAJAKeH0KfSR7eAp9fX0KJHsKeH0KX2kxAAAAAAAAAAAAh/b5qi1eLS80MF4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4111 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3768370937 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5654859ea810, 0x565485bd401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565485bd4020,0x565487a6c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0de810d63fbdfc31b491b558eae8e416d439d711' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5103 processed earlier; will process 5926 files now Step #5: ==148072== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56547c4df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565482b44898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565482b275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565482b274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56547c4e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56547c446b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56547c441355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56547c4d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56547f4a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56547f4a6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56547f4a6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56547f4a6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56547f4a6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56547f4a6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56547f4a6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56547f4a6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56547f4a6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56547f4a6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56548173bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56547e468b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56547e473be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56547e21fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56547e21fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56547e220738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56547e21f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56547e21f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56547e21f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565482b29abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565482b32928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565482b1a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565482b45112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fccd8a9b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56547c43fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x23,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x38,0x60,0x44,0x33,0x2,0x23,0x33,0x32,0x38,0x33,0x58,0x58,0x0,0x0,0x1,0x0,0x54,0x58,0x58,0x0,0x0,0x1,0x0,0x38,0x33,0x23,0x54,0x58,0x58,0x0,0x33,0x2,0x23,0x33,0x32,0x49,0x44,0x33,0x2,0x23,0x33,0x32,0x38,0x73,0x23,0x54,0x58,0x58,0x0,0x0,0x1,0x0,0x54,0x58,0x58,0x0,0x0,0x1,0x0,0x54,0x58,0x58,0x0,0x0,0x1,0x0,0x0,0x1,0x60,0x0,0x54,0x58,0x58,0x0,0x0,0x1,0x0,0x54,0x58,0x58,0x0,0x0,0x1,0x0,0x54,0x57,0x58,0x49, Step #5: ID3\002#2147483648`D3\002#3283XX\000\000\001\000TXX\000\000\001\00083#TXX\0003\002#32ID3\002#328s#TXX\000\000\001\000TXX\000\000\001\000TXX\000\000\001\000\000\001`\000TXX\000\000\001\000TXX\000\000\001\000TWXI Step #5: artifact_prefix='./'; Test unit written to ./oom-9ae5379df0f07c0e94f2012630e5722673067257 Step #5: Base64: SUQzAiMyMTQ3NDgzNjQ4YEQzAiMzMjgzWFgAAAEAVFhYAAABADgzI1RYWAAzAiMzMklEMwIjMzI4cyNUWFgAAAEAVFhYAAABAFRYWAAAAQAAAWAAVFhYAAABAFRYWAAAAQBUV1hJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4112 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3768997548 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5585f22db810, 0x5585f24c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5585f24c5020,0x5585f435d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9ae5379df0f07c0e94f2012630e5722673067257' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5104 processed earlier; will process 5925 files now Step #5: ==148108== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5585e8dd09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5585ef435898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5585ef4185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5585ef4184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5585e8dd6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5585e8d37b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5585e8d32355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5585e8dc8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5585ebd97f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5585ebd97f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5585ebd97f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5585ebd97f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5585ebd97f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5585ebd97f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5585ebd97f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5585ebd97f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5585ebd97f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5585ebd97f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5585ee02cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5585ead59b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5585ead64be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5585eab10c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5585eab10c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5585eab11738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5585eab10874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5585eab10874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5585eab10874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5585ef41aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5585ef423928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5585ef40b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5585ef436112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe8851c9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5585e8d30b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x4e,0x50,0x55,0x54,0xa,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x30,0xa,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x30,0xa,0x23,0x30,0x20,0x23,0x30,0xa,0x23,0x30,0xa,0x23,0x30,0x20, Step #5: INPUT\012#0\012#0 #0\012#0 #0\012#0\012#0\012#0 #0\012#0 #0\012#0 #0 #0\012#0 #0\012#0\012#0 #0\012#0\012#0 #0\012#0 #0\012#0 #0 #0\012#0\012#0 #0\012#0\012#0 Step #5: artifact_prefix='./'; Test unit written to ./oom-22c6f602937fbc1ed2971db1971ae648fd0757b9 Step #5: Base64: SU5QVVQKIzAKIzAgIzAKIzAgIzAKIzAKIzAKIzAgIzAKIzAgIzAKIzAgIzAgIzAKIzAgIzAKIzAKIzAgIzAKIzAKIzAgIzAKIzAgIzAKIzAgIzAgIzAKIzAKIzAgIzAKIzAKIzAg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4113 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3769502977 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c39f169810, 0x55c39f35301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c39f353020,0x55c3a11eb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/22c6f602937fbc1ed2971db1971ae648fd0757b9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5105 processed earlier; will process 5924 files now Step #5: ==148144== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c395c5e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c39c2c3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c39c2a65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c39c2a64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c395c64d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c395bc5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c395bc0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c395c56c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c398c25f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c398c25f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c398c25f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c398c25f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c398c25f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c398c25f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c398c25f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c398c25f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c398c25f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c398c25f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c39aebaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c397be7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c397bf2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c39799ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c39799ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c39799f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c39799e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c39799e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c39799e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c39c2a8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c39c2b1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c39c299699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c39c2c4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc9bac68082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c395bbeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x37,0x37,0x35,0x38,0x30,0x37,0x49,0x44,0x2d,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x23,0x68,0xa,0xa,0x48,0xa,0x40,0xa,0x2d,0xa,0x68,0xa,0x48,0x68,0x68,0xa,0x2d,0x42,0x4f,0x53,0x2f,0x30,0x53,0x4c,0x4,0x1,0x0,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x3a,0xa,0x1c,0x68,0xa,0xa,0x48,0xa,0x40,0xa,0x2d,0xa,0x68,0xa,0x48,0xa,0xa,0x42,0x2d,0x68,0x4f,0x53,0x2f,0x32,0x53,0x73,0x2d,0x25,0x25,0x42, Step #5: 775807ID-IN -----\012#h\012\012H\012@\012-\012h\012Hhh\012-BOS/0SL\004\001\000----BEGIN -----BEGIN -----\012:\012\034h\012\012H\012@\012-\012h\012H\012\012B-hOS/2Ss-%%B Step #5: artifact_prefix='./'; Test unit written to ./oom-78dea4320d7ef197e34e9b848d643e5c69ba0c1e Step #5: Base64: Nzc1ODA3SUQtSU4gLS0tLS0KI2gKCkgKQAotCmgKSGhoCi1CT1MvMFNMBAEALS0tLUJFR0lOIC0tLS0tQkVHSU4gLS0tLS0KOgocaAoKSApACi0KaApICgpCLWhPUy8yU3MtJSVC Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4114 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3770017120 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d55672810, 0x564d5585c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d5585c020,0x564d576f40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/78dea4320d7ef197e34e9b848d643e5c69ba0c1e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5106 processed earlier; will process 5923 files now Step #5: ==148180== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d4c1679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d527cc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d527af5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d527af4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d4c16dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d4c0ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d4c0c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d4c15fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d4f12ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d4f12ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d4f12ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d4f12ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d4f12ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d4f12ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d4f12ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d4f12ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d4f12ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d4f12ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d513c3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d4e0f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d4e0fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d4dea7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d4dea7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d4dea8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d4dea7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d4dea7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d4dea7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d527b1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d527ba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d527a2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d527cd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b79ef9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d4c0c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x47,0xd6,0xbf,0x27,0x27,0x27,0x2f,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x29,0x27,0x47,0xd6,0xbf,0x27,0x27,0xbf,0x27,0x27,0x27,0x2f,0x29,0x29,0x47,0xd6,0xbf,0x27,0x27,0x27,0x2f,0x29,0x27, Step #5: BG\326\277'''/88888888888888888888888888888888888888888888888888888888888888888888888)'G\326\277''\277'''/))G\326\277'''/)' Step #5: artifact_prefix='./'; Test unit written to ./oom-516bfad2fa6c399f3e787f1ee9af060b67eb067a Step #5: Base64: QkfWvycnJy84ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4OCknR9a/Jye/JycnLykpR9a/JycnLykn Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4115 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3770522417 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5566ad0b5810, 0x5566ad29f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5566ad29f020,0x5566af1370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/516bfad2fa6c399f3e787f1ee9af060b67eb067a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5107 processed earlier; will process 5922 files now Step #5: ==148216== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5566a3baa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5566aa20f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5566aa1f25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5566aa1f24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5566a3bb0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5566a3b11b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5566a3b0c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5566a3ba2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5566a6b71f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5566a6b71f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5566a6b71f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5566a6b71f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5566a6b71f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5566a6b71f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5566a6b71f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5566a6b71f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5566a6b71f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5566a6b71f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5566a8e06f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5566a5b33b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5566a5b3ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5566a58eac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5566a58eac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5566a58eb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5566a58ea874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5566a58ea874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5566a58ea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5566aa1f4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5566aa1fd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5566aa1e5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5566aa210112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7479c9c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5566a3b0ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x52,0x55,0x4e,0x3d,0x22,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x24,0x69,0x64,0x22, Step #5: RUN=\"$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id$id\" Step #5: artifact_prefix='./'; Test unit written to ./oom-a0051f0b07570d6915d561417cc8eadafea71ed1 Step #5: Base64: UlVOPSIkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQkaWQi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4116 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3771047383 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ef979dd810, 0x55ef97bc701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ef97bc7020,0x55ef99a5f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a0051f0b07570d6915d561417cc8eadafea71ed1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5108 processed earlier; will process 5921 files now Step #5: ==148252== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ef8e4d29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ef94b37898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ef94b1a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ef94b1a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef8e4d8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef8e439b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef8e434355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef8e4cac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef91499f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef91499f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef91499f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef91499f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef91499f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef91499f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef91499f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef91499f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef91499f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef91499f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef9372ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef9045bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef90466be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef90212c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef90212c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef90213738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef90212874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef90212874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef90212874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ef94b1cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ef94b25928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ef94b0d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ef94b38112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb1beff8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef8e432b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0xc,0x0,0x0,0x1e,0x1e,0x63,0x65,0x6e,0x74,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x25,0x1e,0x7e,0x12,0x0,0x0,0x0,0x7e,0x7e,0x3f,0x3c,0xdb,0xbe,0x7e,0x7e,0x1e,0x1e,0x1e,0x1e,0x25,0x1e,0x7e,0x12,0x0,0x0,0x0,0x7e,0x7e,0x3f,0x3c,0xdb,0xbe,0x7e,0x7e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x7e,0x12,0x0,0x0,0x0,0x7e,0x7e,0x3f,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x12,0x0,0x0,0x0,0x67,0x72,0x78,0x68,0x74,0x68,0x72,0x79,0x25,0x73, Step #5: ~~~<\333\276~\014\000\000\036\036cent\036\036\036\036\036\036\036\036\036\036%\036~\022\000\000\000~~?<\333\276~~\036\036\036\036%\036~\022\000\000\000~~?<\333\276~~\036\036\036\036\036\036\036\036\036\036\036\036\036\036~\022\000\000\000~~?<\333\276~~~\022\000\000\000grxhthry%s Step #5: artifact_prefix='./'; Test unit written to ./oom-3aa481949ec5240d8b64b0a9b9a49e9af047ec8e Step #5: Base64: fn5+PNu+fgwAAB4eY2VudB4eHh4eHh4eHh4lHn4SAAAAfn4/PNu+fn4eHh4eJR5+EgAAAH5+Pzzbvn5+Hh4eHh4eHh4eHh4eHh5+EgAAAH5+Pzzbvn5+fhIAAABncnhodGhyeSVz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4117 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3771553021 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7c0cb2810, 0x55b7c0e9c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7c0e9c020,0x55b7c2d340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3aa481949ec5240d8b64b0a9b9a49e9af047ec8e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5109 processed earlier; will process 5920 files now Step #5: ==148288== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b7b77a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b7bde0c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b7bddef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b7bddef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b7b77add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b7b770eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b7b7709355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b7b779fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b7ba76ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b7ba76ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b7ba76ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b7ba76ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b7ba76ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b7ba76ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b7ba76ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b7ba76ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b7ba76ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b7ba76ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b7bca03f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b7b9730b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b7b973bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b7b94e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b7b94e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b7b94e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b7b94e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b7b94e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b7b94e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b7bddf1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b7bddfa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b7bdde2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b7bde0d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa1a690d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b7b7707b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x37,0x3a,0x5b,0x22,0xc3,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0x81,0x80,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xd2,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0x84,0xba,0xda,0xaf,0xdf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xdf,0xaf,0x24,0x24,0x73,0xcd,0x8d,0xcd,0x8d,0xc8,0x8d,0xcd,0x8d,0x66,0x61,0xca,0xaa,0x38,0x37,0x38,0x31,0x36,0x39,0x33,0x34,0x36,0x22,0x5d,0x7d,0x27,0xc3,0xff,0xff,0xff,0x7f,0xff,0x0,0x3d,0x43,0x26,0x27,0x3a,0x3a,0x44,0xb8, Step #5: $3::{$7:[\"\303\277\357\277\277\357\277\277\357\201\200\357\277\277\357\277\277\322\277\357\277\277\357\277\277\357\277\277\357\277\277\357\204\272\332\257\337\277\357\277\277\357\277\277\357\277\277\337\257$$s\315\215\315\215\310\215\315\215fa\312\252878169346\"]}'\303\377\377\377\177\377\000=C&'::D\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-e4d859359f43218326f1d5d7e7a9a18fb8e4ef8d Step #5: Base64: JDM6OnskNzpbIsO/77+/77+/74GA77+/77+/0r/vv7/vv7/vv7/vv7/vhLrar9+/77+/77+/77+/368kJHPNjc2NyI3NjWZhyqo4NzgxNjkzNDYiXX0nw////3//AD1DJic6OkS4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4118 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3772066993 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56272e27f810, 0x56272e46901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56272e469020,0x5627303010e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e4d859359f43218326f1d5d7e7a9a18fb8e4ef8d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5110 processed earlier; will process 5919 files now Step #5: ==148324== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562724d749c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56272b3d9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56272b3bc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56272b3bc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562724d7ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562724cdbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562724cd6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562724d6cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562727d3bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562727d3bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562727d3bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562727d3bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562727d3bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562727d3bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562727d3bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562727d3bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562727d3bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562727d3bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562729fd0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562726cfdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562726d08be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562726ab4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562726ab4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562726ab5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562726ab4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562726ab4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562726ab4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56272b3beabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56272b3c7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56272b3af699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56272b3da112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f224bd3e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562724cd4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x73,0x3a,0x31,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0x78,0x6e,0x2d,0x2d,0x66,0x6a,0x6a,0x2d,0x2d,0x66,0x6a,0x6a,0x2e,0x78,0x6a,0x2e,0x2e,0x78,0x6e,0x2d,0x2d,0x66,0x6a,0x6a,0x2e,0x78,0x6e,0x2d,0x2d,0x66,0x6a,0x6a,0x2e,0x78,0x6e,0x2e,0x78,0x6e,0x2d,0x2d,0x66,0x6a,0x6a,0x2e,0x78,0x6e,0x2d,0x2d,0x66,0x6a,0x6a,0x2e,0x78,0x6e,0x2d,0x2d,0x66,0x6a,0x2d,0x2d,0x66,0x6a,0x6a,0x2e,0x78,0x6e,0x2d,0x2d,0x66,0x6a,0x6a,0x2e,0x78,0x6e,0x2d,0x2d,0x66,0x6a,0x6a,0x2e,0x2d,0x66,0x6a, Step #5: \016ws:1\343\214\226.\343\214\226.\343\214\226\343\214\226xn--fjj--fjj.xj..xn--fjj.xn--fjj.xn.xn--fjj.xn--fjj.xn--fj--fjj.xn--fjj.xn--fjj.-fj Step #5: artifact_prefix='./'; Test unit written to ./oom-2dc3ef9a01f116aa71f9c45732a2fb4270e2b1c1 Step #5: Base64: DndzOjHjjJYu44yWLuOMluOMlnhuLS1mamotLWZqai54ai4ueG4tLWZqai54bi0tZmpqLnhuLnhuLS1mamoueG4tLWZqai54bi0tZmotLWZqai54bi0tZmpqLnhuLS1mamouLWZq Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4119 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3772570292 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5644bd33c810, 0x5644bd52601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5644bd526020,0x5644bf3be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2dc3ef9a01f116aa71f9c45732a2fb4270e2b1c1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5111 processed earlier; will process 5918 files now Step #5: #1 pulse cov: 3671 ft: 3672 exec/s: 0 rss: 175Mb Step #5: ==148360== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5644b3e319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5644ba496898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5644ba4795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5644ba4794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5644b3e37d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5644b3d98b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5644b3d93355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5644b3e29c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5644b6df8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5644b6df8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5644b6df8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5644b6df8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5644b6df8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5644b6df8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5644b6df8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5644b6df8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5644b6df8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5644b6df8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5644b908df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5644b5dbab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5644b5dc5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5644b5b71c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5644b5b71c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5644b5b72738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5644b5b71874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5644b5b71874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5644b5b71874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5644ba47babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5644ba484928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5644ba46c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5644ba497112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f46469d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5644b3d91b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0x3,0x16,0x1,0x1,0x13,0x14,0x1,0xd,0x14,0x1,0x14,0x1,0xd,0x14,0x1,0xd,0x14,0x1,0x14,0x1,0xd,0x14,0x1,0xd,0xd,0xd,0x14,0x1,0x14,0x1,0xd,0x14,0x1,0xd,0x14,0x1,0x14,0x1,0xd,0x14,0x1,0x14,0x1,0xd,0x14,0x1,0xd,0xd,0xd,0x14,0x1,0x14,0x1,0xd,0x14,0x1,0xd,0x14,0x1,0x14,0x1,0xd,0x14,0x1,0xd,0xd,0xd,0x14,0x1,0x14,0x1,0xd,0x14,0x1,0xd,0x14,0x1,0x14,0x1,0xd,0x14,0x1,0xd,0xd,0x14,0x1,0xd,0x14,0x1,0xd,0x14,0x1,0xd,0xd,0x14,0x1,0xd,0x14,0x1,0xd,0xd, Step #5: \013\003\026\001\001\023\024\001\015\024\001\024\001\015\024\001\015\024\001\024\001\015\024\001\015\015\015\024\001\024\001\015\024\001\015\024\001\024\001\015\024\001\024\001\015\024\001\015\015\015\024\001\024\001\015\024\001\015\024\001\024\001\015\024\001\015\015\015\024\001\024\001\015\024\001\015\024\001\024\001\015\024\001\015\015\024\001\015\024\001\015\024\001\015\015\024\001\015\024\001\015\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-0e9e8bee6818d18a283a4109c55958b30d38f2fa Step #5: Base64: CwMWAQETFAENFAEUAQ0UAQ0UARQBDRQBDQ0NFAEUAQ0UAQ0UARQBDRQBFAENFAENDQ0UARQBDRQBDRQBFAENFAENDQ0UARQBDRQBDRQBFAENFAENDRQBDRQBDRQBDQ0UAQ0UAQ0N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4120 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3773111812 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c7bd45810, 0x556c7bf2f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c7bf2f020,0x556c7ddc70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0e9e8bee6818d18a283a4109c55958b30d38f2fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5113 processed earlier; will process 5916 files now Step #5: #1 pulse cov: 3607 ft: 3608 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 13319 ft: 14244 exec/s: 0 rss: 194Mb Step #5: ==148396== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556c7283a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c78e9f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c78e825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c78e824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556c72840d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556c727a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556c7279c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556c72832c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556c75801f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556c75801f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556c75801f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556c75801f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556c75801f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556c75801f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556c75801f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556c75801f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556c75801f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556c75801f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c77a96f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556c747c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556c747cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556c7457ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556c7457ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556c7457b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556c7457a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556c7457a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556c7457a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c78e84abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c78e8d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c78e75699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c78ea0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c262fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556c7279ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x37,0x3a,0x5b,0x22,0xc3,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xb0,0xaf,0xef,0xb2,0xbf,0xdf,0xaf,0x72,0xef,0xbf,0xb7,0xdf,0xbd,0xef,0x80,0xbf,0xdf,0xbe,0xef,0xae,0x84,0xdf,0xaf,0xf7,0xbf,0xc1,0xef,0xf3,0xa0,0x80,0xa8,0xff,0xff,0xff,0x24,0x24,0x74,0x28,0x6c,0x69,0x73,0xa3,0x24,0x73,0x65,0x72,0x74,0x73,0x73,0x70,0x7e,0x3f,0x28,0x22,0x5d,0x7d,0x27,0xc3,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xf7,0xfd,0xff,0x0,0xff,0x9b,0xff,0x27,0x3a,0x3a,0x64,0xb8, Step #5: $3::{$7:[\"\303\277\357\277\277\357\277\277\357\277\277\357\260\257\357\262\277\337\257r\357\277\267\337\275\357\200\277\337\276\357\256\204\337\257\367\277\301\357\363\240\200\250\377\377\377$$t(lis\243$sertssp~?(\"]}'\303\377\377\377\377\377\377\377\377\377\377\377\367\375\377\000\377\233\377'::d\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-a7af0dcb7de28e46fd32f1efa8a47eece19e4e56 Step #5: Base64: JDM6OnskNzpbIsO/77+/77+/77+/77Cv77K/369y77+3373vgL/fvu+uhN+v97/B7/OggKj///8kJHQobGlzoyRzZXJ0c3Nwfj8oIl19J8P///////////////f9/wD/m/8nOjpkuA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4121 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3773763334 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557ab814a810, 0x557ab833401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557ab8334020,0x557aba1cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a7af0dcb7de28e46fd32f1efa8a47eece19e4e56' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5117 processed earlier; will process 5912 files now Step #5: #1 pulse cov: 3599 ft: 3600 exec/s: 0 rss: 173Mb Step #5: ==148432== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557aaec3f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557ab52a4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557ab52875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557ab52874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557aaec45d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557aaeba6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557aaeba1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557aaec37c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557ab1c06f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557ab1c06f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557ab1c06f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557ab1c06f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557ab1c06f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557ab1c06f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557ab1c06f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557ab1c06f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557ab1c06f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557ab1c06f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557ab3e9bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557ab0bc8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557ab0bd3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557ab097fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557ab097fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557ab0980738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557ab097f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557ab097f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557ab097f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557ab5289abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557ab5292928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557ab527a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557ab52a5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f34e04c7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557aaeb9fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x36,0x35,0x35,0x74,0xa,0x49,0x30,0x9,0x44,0x45,0x46,0x41,0x55,0x4c,0x54,0x28,0x53,0x45,0x4c,0x45,0x43,0x54,0x20,0x2d,0x31,0x2e,0x32,0x2c,0x35,0x2c,0x66,0x70,0x6c,0x2c,0x6c,0x75,0x31,0x79,0x31,0x2c,0x34,0x35,0x35,0x34,0x36,0x2c,0x31,0x39,0x34,0x31,0x37,0x2c,0x33,0x32,0x36,0x2c,0x32,0x2d,0x32,0x30,0x31,0x2c,0x54,0x2d,0x3e,0x43,0x4f,0x4c,0x55,0x4d,0x4e,0x53,0x28,0x27,0x66,0x42,0x49,0x5e,0x5c,0x42,0x6,0x5e,0x0,0x49,0x5c,0xd,0xd,0x0,0x27,0x29,0x2c,0x32,0x30,0x38,0x34,0x33,0x29,0x2d,0x72,0x2d,0x72,0xa, Step #5: e655t\012I0\011DEFAULT(SELECT -1.2,5,fpl,lu1y1,45546,19417,326,2-201,T->COLUMNS('fBI^\\B\006^\000I\\\015\015\000'),20843)-r-r\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-6f2a3d90e5ae3708dd061a0e5ae6696b28ab1c8e Step #5: Base64: ZTY1NXQKSTAJREVGQVVMVChTRUxFQ1QgLTEuMiw1LGZwbCxsdTF5MSw0NTU0NiwxOTQxNywzMjYsMi0yMDEsVC0+Q09MVU1OUygnZkJJXlxCBl4ASVwNDQAnKSwyMDg0Myktci1yCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4122 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3774316508 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562517912810, 0x562517afc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562517afc020,0x5625199940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6f2a3d90e5ae3708dd061a0e5ae6696b28ab1c8e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5119 processed earlier; will process 5910 files now Step #5: ==148468== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56250e4079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562514a6c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562514a4f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562514a4f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56250e40dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56250e36eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56250e369355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56250e3ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5625113cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5625113cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5625113cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5625113cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5625113cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5625113cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5625113cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5625113cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5625113cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5625113cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562513663f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562510390b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56251039bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562510147c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562510147c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562510148738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562510147874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562510147874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562510147874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562514a51abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562514a5a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562514a42699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562514a6d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5925b0e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56250e367b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2c,0x1c,0x2d,0xa,0x2d,0xa,0x2d,0x1c,0x2d,0xa,0x63,0x6f,0x6e,0x64,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x36,0x30,0x35,0x1,0x53,0x37,0x34,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x30,0x30,0x30,0x32,0x37,0x32,0x39,0x37,0x34,0x31,0x31,0x31,0x2d,0x1c,0x2d,0xa, Step #5: -\012\012\012--\012,\034-\012-\012-\034-\012cond-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012605\001S74\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012000272974111-\034-\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-6bb8ef87a0f59bb9d004bbdf7044ef0c4f71acbd Step #5: Base64: LQoKCi0tCiwcLQotCi0cLQpjb25kLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQo2MDUBUzc0Ci0KLQotCi0KLQotCi0KLQotCi0KMDAwMjcyOTc0MTExLRwtCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4123 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3774851462 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5604dced2810, 0x5604dd0bc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604dd0bc020,0x5604def540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bb8ef87a0f59bb9d004bbdf7044ef0c4f71acbd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5120 processed earlier; will process 5909 files now Step #5: ==148504== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5604d39c79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5604da02c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5604da00f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5604da00f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5604d39cdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5604d392eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5604d3929355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5604d39bfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5604d698ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5604d698ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5604d698ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5604d698ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5604d698ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5604d698ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5604d698ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5604d698ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5604d698ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5604d698ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5604d8c23f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5604d5950b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5604d595bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5604d5707c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5604d5707c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5604d5708738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5604d5707874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5604d5707874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5604d5707874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5604da011abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5604da01a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5604da002699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5604da02d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff88e0a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5604d3927b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x65,0x2a,0x63,0x12,0x61,0xf3,0x8c,0x92,0x96,0xf0,0xb6,0x8b,0xa2,0xf1,0x90,0xb6,0x89,0xf1,0xa2,0x82,0xba,0xf1,0xbe,0xa8,0xb0,0xf2,0xa2,0xa3,0xac,0xf3,0x95,0x9f,0xae,0xf2,0xa0,0xa9,0x95,0xf1,0x93,0x93,0x8b,0xf4,0x8f,0xbe,0xaa,0xf0,0xb1,0xa3,0xb8,0xf1,0x87,0x80,0x89,0xf1,0x80,0xa1,0xbc,0xf3,0xad,0xbc,0xaf,0xf2,0x86,0xbb,0xa7,0xf2,0xa8,0xac,0xa6,0xf1,0xac,0x9c,0xbe,0xf3,0x9b,0xb5,0x95,0xf2,0xa7,0x8f,0xac,0xf2,0xb3,0x82,0x81,0xf0,0x99,0xac,0xaa,0xf2,0xbf,0x9f,0xb6,0xf2,0xb0,0x80,0xaa,0xf1,0xb3,0x8f,0x88,0x17, Step #5: \012e*c\022a\363\214\222\226\360\266\213\242\361\220\266\211\361\242\202\272\361\276\250\260\362\242\243\254\363\225\237\256\362\240\251\225\361\223\223\213\364\217\276\252\360\261\243\270\361\207\200\211\361\200\241\274\363\255\274\257\362\206\273\247\362\250\254\246\361\254\234\276\363\233\265\225\362\247\217\254\362\263\202\201\360\231\254\252\362\277\237\266\362\260\200\252\361\263\217\210\027 Step #5: artifact_prefix='./'; Test unit written to ./oom-7256d632db87af20d1f210ad943124652a6101f1 Step #5: Base64: CmUqYxJh84ySlvC2i6LxkLaJ8aKCuvG+qLDyoqOs85WfrvKgqZXxk5OL9I++qvCxo7jxh4CJ8YChvPOtvK/yhrun8qispvGsnL7zm7WV8qePrPKzgoHwmayq8r+ftvKwgKrxs4+IFw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4124 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3775348869 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55721eb39810, 0x55721ed2301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55721ed23020,0x557220bbb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7256d632db87af20d1f210ad943124652a6101f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5121 processed earlier; will process 5908 files now Step #5: ==148540== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55721562e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55721bc93898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55721bc765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55721bc764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557215634d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557215595b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557215590355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557215626c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5572185f5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5572185f5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5572185f5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5572185f5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5572185f5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5572185f5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5572185f5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5572185f5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5572185f5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5572185f5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55721a88af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5572175b7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5572175c2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55721736ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55721736ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55721736f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55721736e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55721736e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55721736e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55721bc78abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55721bc81928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55721bc69699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55721bc94112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f065f07d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55721558eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x0,0x0,0x42,0x62,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: ID3\002\000\000Bb\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bd1c067d9afce8956669b8d19e91b4a962090b07 Step #5: Base64: SUQzAgAAQmIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4125 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3775850646 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56139872d810, 0x56139891701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561398917020,0x56139a7af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bd1c067d9afce8956669b8d19e91b4a962090b07' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5122 processed earlier; will process 5907 files now Step #5: ==148576== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56138f2229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561395887898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56139586a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56139586a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56138f228d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56138f189b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56138f184355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56138f21ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5613921e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5613921e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5613921e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5613921e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5613921e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5613921e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5613921e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5613921e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5613921e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5613921e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56139447ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5613911abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5613911b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561390f62c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561390f62c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561390f63738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561390f62874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561390f62874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561390f62874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56139586cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561395875928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56139585d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561395888112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9262f68082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56138f182b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x66,0x6e,0xe3,0x80,0x81,0xa,0xe3,0x80,0x81,0x0,0x0,0x0,0xe3,0x80,0x81,0xa,0xe3,0x80,0x81,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3,0xa,0xe3,0x80,0x81,0xa,0xe3,0x80,0x81,0xa,0xe3,0x80,0x81,0xa,0xe3,0x80,0x81,0xa,0xe3,0x80,0x81,0xa,0xe3,0x80,0x81,0xa,0xe3,0x80,0x81,0xe3,0xff,0xff,0xff,0xfb,0x80,0x81,0xa,0xe3,0x80,0x81,0xa,0xe3,0x80,0x81,0x2e,0x77,0x76,0x77,0x72,0x76,0x76,0x28,0x28,0x29,0x29,0x3e,0x77,0x2e,0x57,0x57,0x66,0x6e,0x6e,0xa,0xa,0x66,0x6e,0xa,0x66, Step #5: \012\012\012\012\012\012\012\012fn\343\200\201\012\343\200\201\000\000\000\343\200\201\012\343\200\201\000\000\000\000\000\000\000\003\012\343\200\201\012\343\200\201\012\343\200\201\012\343\200\201\012\343\200\201\012\343\200\201\012\343\200\201\343\377\377\377\373\200\201\012\343\200\201\012\343\200\201.wvwrvv(())>w.WWfnn\012\012fn\012f Step #5: artifact_prefix='./'; Test unit written to ./oom-dbc71bfea32e1696f4abbc3d1322e019113f4065 Step #5: Base64: CgoKCgoKCgpmbuOAgQrjgIEAAADjgIEK44CBAAAAAAAAAAMK44CBCuOAgQrjgIEK44CBCuOAgQrjgIEK44CB4/////uAgQrjgIEK44CBLnd2d3J2digoKSk+dy5XV2ZubgoKZm4KZg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4126 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3776350456 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5641ba74f810, 0x5641ba93901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5641ba939020,0x5641bc7d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dbc71bfea32e1696f4abbc3d1322e019113f4065' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5123 processed earlier; will process 5906 files now Step #5: ==148612== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5641b12449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5641b78a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5641b788c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5641b788c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5641b124ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641b11abb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641b11a6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5641b123cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5641b420bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5641b420bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5641b420bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5641b420bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5641b420bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5641b420bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5641b420bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5641b420bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5641b420bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5641b420bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5641b64a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5641b31cdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5641b31d8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5641b2f84c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5641b2f84c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5641b2f85738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5641b2f84874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5641b2f84874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5641b2f84874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5641b788eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5641b7897928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5641b787f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5641b78aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe3c4e1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641b11a4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x67,0x6c,0x79,0xcd,0x8f,0x66,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x67,0x3f,0x74,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x66,0x67,0x7f,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x7f,0x66,0x2b,0x67,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x66,0x67,0x7f,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x67,0x7f,0x66,0x2b,0x67,0x66,0x3f,0x66,0x2b,0x67,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x6e, Step #5: tgly\315\217ffg\177f;g?tglyg?tglyf?g?g?fg\177fg\177f;g?tg\177f+gf?f;g?tglyf?g?g?fg\177fg\177f;g?tglyg\177f+gf?f+gf?f;g?tglyf?g?g?n Step #5: artifact_prefix='./'; Test unit written to ./oom-e4146e2f86053d743660a4505a990250f9ce26de Step #5: Base64: dGdsec2PZmZnf2Y7Zz90Z2x5Zz90Z2x5Zj9nP2c/Zmd/Zmd/ZjtnP3Rnf2YrZ2Y/ZjtnP3RnbHlmP2c/Zz9mZ39mZ39mO2c/dGdseWd/ZitnZj9mK2dmP2Y7Zz90Z2x5Zj9nP2c/bg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4127 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3776869386 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d4348c810, 0x557d4367601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d43676020,0x557d4550e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e4146e2f86053d743660a4505a990250f9ce26de' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5124 processed earlier; will process 5905 files now Step #5: ==148648== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557d39f819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557d405e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557d405c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557d405c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557d39f87d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557d39ee8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557d39ee3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557d39f79c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557d3cf48f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557d3cf48f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557d3cf48f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557d3cf48f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557d3cf48f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557d3cf48f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557d3cf48f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557d3cf48f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557d3cf48f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557d3cf48f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557d3f1ddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557d3bf0ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557d3bf15be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557d3bcc1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557d3bcc1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557d3bcc2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557d3bcc1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557d3bcc1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557d3bcc1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557d405cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557d405d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557d405bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557d405e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f05fb420082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557d39ee1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x67,0x6c,0x7d,0xcd,0x8f,0x66,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x67,0x3f,0x74,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x66,0x67,0x7f,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x7f,0x66,0x2b,0x67,0x66,0x3f,0xe8,0xff,0xff,0xff,0xff,0xff,0xff,0x7f,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x66,0x67,0x7f,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x67,0x7f,0x66,0x2b,0x67,0x66,0x3f,0x66,0x2b,0x67,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x6e, Step #5: tgl}\315\217ffg\177f;g?tglyg?tglyf?g?g?fg\177fg\177f;g?tg\177f+gf?\350\377\377\377\377\377\377\177f?g?g?fg\177fg\177f;g?tglyg\177f+gf?f+gf?f;g?tglyf?g?g?n Step #5: artifact_prefix='./'; Test unit written to ./oom-89fe0b6b76c86f4448f9d9910bb29288bd8e2dff Step #5: Base64: dGdsfc2PZmZnf2Y7Zz90Z2x5Zz90Z2x5Zj9nP2c/Zmd/Zmd/ZjtnP3Rnf2YrZ2Y/6P///////39mP2c/Zz9mZ39mZ39mO2c/dGdseWd/ZitnZj9mK2dmP2Y7Zz90Z2x5Zj9nP2c/bg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4128 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3777376609 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f2d2c4810, 0x556f2d4ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f2d4ae020,0x556f2f3460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/89fe0b6b76c86f4448f9d9910bb29288bd8e2dff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5125 processed earlier; will process 5904 files now Step #5: ==148684== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556f23db99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f2a41e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f2a4015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f2a4014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f23dbfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f23d20b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f23d1b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f23db1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f26d80f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f26d80f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f26d80f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f26d80f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f26d80f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f26d80f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f26d80f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f26d80f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f26d80f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f26d80f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f29015f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f25d42b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f25d4dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f25af9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f25af9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f25afa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f25af9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f25af9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f25af9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f2a403abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f2a40c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f2a3f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f2a41f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc0f97df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f23d19b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x33,0x2e,0x32,0x2e,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5b,0x30,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x32,0x30,0x30,0x31,0x36,0x32,0x31,0x33,0x31,0x31,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24, Step #5: $\177]3.2.\177\177\177\177\177\177\000\000\000\000\000\000\000\000\000\000[0\000\000\000\000\000\000\000\000\000\000\000\000\0002222222222222222222222200000002001621311\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000$ Step #5: artifact_prefix='./'; Test unit written to ./oom-cb7eb2e19b51330f4eb48b580e36206e26fc3067 Step #5: Base64: JH9dMy4yLn9/f39/fwAAAAAAAAAAAABbMAAAAAAAAAAAAAAAAAAyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjAwMDAwMDAyMDAxNjIxMzExAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4129 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3777877703 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555f28fbd810, 0x555f291a701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555f291a7020,0x555f2b03f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb7eb2e19b51330f4eb48b580e36206e26fc3067' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5126 processed earlier; will process 5903 files now Step #5: ==148720== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555f1fab29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555f26117898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555f260fa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555f260fa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555f1fab8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555f1fa19b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555f1fa14355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555f1faaac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555f22a79f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555f22a79f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555f22a79f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555f22a79f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555f22a79f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555f22a79f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555f22a79f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555f22a79f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555f22a79f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555f22a79f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555f24d0ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555f21a3bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555f21a46be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555f217f2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555f217f2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555f217f3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555f217f2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555f217f2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555f217f2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555f260fcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555f26105928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555f260ed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555f26118112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f549c90e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555f1fa12b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x73,0x64,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x73,0x74,0x72,0x65,0x61,0x6d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x67,0xe,0x5b,0x67,0xe,0x68,0x68,0x43,0xda,0x82,0x1,0x70,0x4e,0x20,0x2d,0x6d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x70,0x86,0x2d,0x20, Step #5: ID3sd\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000stream\000\000\000\000\000\000\000\000\000\000\000\000----BEGIg\016[g\016hhC\332\202\001pN -m--END ----p\206- Step #5: artifact_prefix='./'; Test unit written to ./oom-ba07205dfcfd5e651dad2b9b7b1ad03b76529d04 Step #5: Base64: SUQzc2QAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABzdHJlYW0AAAAAAAAAAAAAAAAtLS0tQkVHSWcOW2cOaGhD2oIBcE4gLW0tLUVORCAtLS0tcIYtIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4130 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3778377925 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56294579e810, 0x56294598801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562945988020,0x5629478200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba07205dfcfd5e651dad2b9b7b1ad03b76529d04' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5127 processed earlier; will process 5902 files now Step #5: #1 pulse cov: 3892 ft: 3893 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4204 ft: 4554 exec/s: 0 rss: 177Mb Step #5: ==148756== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56293c2939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5629428f8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5629428db5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5629428db4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56293c299d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56293c1fab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56293c1f5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56293c28bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56293f25af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56293f25af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56293f25af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56293f25af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56293f25af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56293f25af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56293f25af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56293f25af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56293f25af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56293f25af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5629414eff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56293e21cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56293e227be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56293dfd3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56293dfd3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56293dfd4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56293dfd3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56293dfd3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56293dfd3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5629428ddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5629428e6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5629428ce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5629428f9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd091c35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56293c1f3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x7c,0x21,0x7d,0x3c,0x74,0x65,0x78,0x74,0x3e,0x30,0x2d,0x32,0x36,0x38,0xe2,0x80,0x8c,0xe2,0x80,0x8c,0xe1,0x9f,0x8c,0x2b,0x33,0x71,0x30,0x30,0x22,0x20,0x3e,0x5b,0x21,0x2d,0x2c,0x2d,0x32,0x36,0x38,0xe2,0x80,0x8c,0xe2,0x80,0x8c,0xe1,0x9f,0x8c,0x2b,0x33,0x71,0x30,0x30,0x22,0x20,0x3e,0x5b,0x21,0x34,0xef,0xba,0xb2,0x2d,0x2d,0x5b,0xe1,0xa0,0x8e,0x2d,0x2c,0x31,0xe2,0x80,0x8c,0x6f,0x6b,0x64,0x6c,0x35,0x48,0x63,0xd,0x63,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x42,0x4f,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg>|!}<text>0-268\342\200\214\342\200\214\341\237\214+3q00\" >[!-,-268\342\200\214\342\200\214\341\237\214+3q00\" >[!4\357\272\262--[\341\240\216-,1\342\200\214okdl5Hc\015c</text>BO</svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-73f31038ddbdb4d42c06eef51b15d315712cdf66 Step #5: Base64: PHN2Zz58IX08dGV4dD4wLTI2OOKAjOKAjOGfjCszcTAwIiA+WyEtLC0yNjjigIzigIzhn4wrM3EwMCIgPlshNO+6si0tW+Ggji0sMeKAjG9rZGw1SGMNYzwvdGV4dD5CTzwvc3ZnPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4131 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3778998774 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5626668f2810, 0x562666adc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562666adc020,0x5626689740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/73f31038ddbdb4d42c06eef51b15d315712cdf66' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5131 processed earlier; will process 5898 files now Step #5: ==148792== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56265d3e79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562663a4c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562663a2f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562663a2f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56265d3edd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56265d34eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56265d349355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56265d3dfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5626603aef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5626603aef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5626603aef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5626603aef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5626603aef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5626603aef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5626603aef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5626603aef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5626603aef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5626603aef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562662643f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56265f370b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56265f37bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56265f127c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56265f127c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56265f128738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56265f127874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56265f127874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56265f127874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562663a31abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562663a3a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562663a22699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562663a4d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4c7a7a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56265d347b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x4b,0x60,0x20,0x2d,0x67,0x6c,0x79,0x66,0x45,0x47,0x4b,0x60,0x24,0x24,0x24,0x1b,0x24,0x24,0x24,0x24,0x24,0x27,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x31,0x37,0x30,0x31,0x34,0x31,0x31,0x38,0x33,0x34,0x36,0x30,0x32,0x34,0x30,0x35,0x35,0x39,0x36,0x34,0x31,0x32,0x37,0x35,0x35,0x34,0x7c,0x34,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x31,0x31,0x31,0x60,0x24, Step #5: \\77\\77\\s-----BEGK` -glyfEGK`$$$\033$$$$$'$$$$$$$$$17014118346024055964127554|4|||||||||||||||||||||||111`$ Step #5: artifact_prefix='./'; Test unit written to ./oom-cb688f1c26bc18a02a24c7cd56db18ea963a953e Step #5: Base64: XDc3XDc3XHMtLS0tLUJFR0tgIC1nbHlmRUdLYCQkJBskJCQkJCckJCQkJCQkJCQxNzAxNDExODM0NjAyNDA1NTk2NDEyNzU1NHw0fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHwxMTFgJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4132 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3779644897 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c4f760810, 0x556c4f94a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c4f94a020,0x556c517e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb688f1c26bc18a02a24c7cd56db18ea963a953e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5132 processed earlier; will process 5897 files now Step #5: ==148828== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556c462559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c4c8ba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c4c89d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c4c89d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556c4625bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556c461bcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556c461b7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556c4624dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556c4921cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556c4921cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556c4921cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556c4921cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556c4921cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556c4921cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556c4921cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556c4921cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556c4921cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556c4921cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c4b4b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556c481deb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556c481e9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556c47f95c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556c47f95c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556c47f96738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556c47f95874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556c47f95874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556c47f95874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c4c89fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c4c8a8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c4c890699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c4c8bb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fde20e9d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556c461b5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x69,0x67,0x72,0x41,0x70,0x68,0x7b,0x36,0x2e,0xa,0x32,0x2e,0xa,0x35,0x2e,0xa,0x35,0x2e,0xa,0x35,0x2e,0xa,0x36,0x2e,0xa,0x35,0x2e,0xa,0x35,0x2e,0xa,0x32,0x2e,0xa,0x35,0x2e,0xa,0x33,0x2e,0xa,0x35,0x2e,0xa,0x35,0x2e,0x7b,0x35,0x2e,0xa,0x32,0x2e,0xa,0x35,0x2e,0xa,0x32,0x2e,0xa,0x35,0x2e,0xa,0x35,0x2e,0xa,0x35,0x2e,0x7b,0x36,0x2e,0xa,0x32,0x2e,0xa,0x35,0x2e,0xa,0x35,0x2e,0xa,0x35,0x2e,0xa,0x35,0x2e,0xa,0x37,0x2e,0xa,0x35,0x2e,0xa,0x35,0x2e,0xa,0x35,0x2e,0xa,0x35,0x2e,0xa,0x30,0x2e, Step #5: digrAph{6.\0122.\0125.\0125.\0125.\0126.\0125.\0125.\0122.\0125.\0123.\0125.\0125.{5.\0122.\0125.\0122.\0125.\0125.\0125.{6.\0122.\0125.\0125.\0125.\0125.\0127.\0125.\0125.\0125.\0125.\0120. Step #5: artifact_prefix='./'; Test unit written to ./oom-7290bb14b648850624534cb5cd8a689253512621 Step #5: Base64: ZGlnckFwaHs2LgoyLgo1Lgo1Lgo1Lgo2Lgo1Lgo1LgoyLgo1LgozLgo1Lgo1Lns1LgoyLgo1LgoyLgo1Lgo1Lgo1Lns2LgoyLgo1Lgo1Lgo1Lgo1Lgo3Lgo1Lgo1Lgo1Lgo1LgowLg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4133 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3780173156 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564b84fd1810, 0x564b851bb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564b851bb020,0x564b870530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7290bb14b648850624534cb5cd8a689253512621' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5133 processed earlier; will process 5896 files now Step #5: ==148864== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564b7bac69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564b8212b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564b8210e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564b8210e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564b7baccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564b7ba2db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564b7ba28355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564b7babec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564b7ea8df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564b7ea8df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564b7ea8df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564b7ea8df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564b7ea8df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564b7ea8df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564b7ea8df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564b7ea8df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564b7ea8df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564b7ea8df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564b80d22f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564b7da4fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564b7da5abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564b7d806c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564b7d806c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564b7d807738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564b7d806874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564b7d806874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564b7d806874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564b82110abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564b82119928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564b82101699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564b8212c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f21afe27082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564b7ba26b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x81,0xb0,0xe2,0x84,0x9b,0xe2,0x81,0xb0,0xe2,0x81,0xa8,0xe2,0x81,0xa8,0xe2,0xa3,0xa8,0xe2,0x81,0xa8,0xe2,0x84,0xa3,0xe2,0x81,0xa8,0xe2,0xa3,0xa8,0xe2,0x81,0xa8,0xe2,0x84,0xa3,0xe2,0x81,0xb0,0xe2,0x84,0xa3,0xe2,0x81,0xb0,0xe2,0x81,0xa8,0xe2,0x81,0xa8,0xe2,0x84,0xa8,0xe2,0x84,0xa3,0xe2,0x81,0xb0,0x5c,0x28,0x5c,0xb0,0x5c,0x28,0x5c,0x3,0xe2,0x81,0xa8,0xe2,0x81,0xb0,0xe2,0x84,0xa3,0xe2,0x81,0xa8,0xe2,0x81,0xa8,0xe2,0xa3,0xa8,0xe2,0x81,0xa7,0xe2,0x84,0xa3,0xe2,0x81,0xb0,0xe2,0x81,0xa8,0xe2,0x81,0xa8,0xe2,0xa3,0x9a, Step #5: \342\201\260\342\204\233\342\201\260\342\201\250\342\201\250\342\243\250\342\201\250\342\204\243\342\201\250\342\243\250\342\201\250\342\204\243\342\201\260\342\204\243\342\201\260\342\201\250\342\201\250\342\204\250\342\204\243\342\201\260\\(\\\260\\(\\\003\342\201\250\342\201\260\342\204\243\342\201\250\342\201\250\342\243\250\342\201\247\342\204\243\342\201\260\342\201\250\342\201\250\342\243\232 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ca5e2a25972d774c9764ffd9a13d466f0347488 Step #5: Base64: 4oGw4oSb4oGw4oGo4oGo4qOo4oGo4oSj4oGo4qOo4oGo4oSj4oGw4oSj4oGw4oGo4oGo4oSo4oSj4oGwXChcsFwoXAPigajigbDihKPigajigajio6jigafihKPigbDigajigajio5o= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4134 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3780675849 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561871632810, 0x56187181c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56187181c020,0x5618736b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ca5e2a25972d774c9764ffd9a13d466f0347488' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5134 processed earlier; will process 5895 files now Step #5: ==148900== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5618681279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56186e78c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56186e76f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56186e76f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56186812dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56186808eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561868089355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56186811fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56186b0eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56186b0eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56186b0eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56186b0eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56186b0eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56186b0eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56186b0eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56186b0eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56186b0eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56186b0eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56186d383f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56186a0b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56186a0bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561869e67c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561869e67c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561869e68738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561869e67874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561869e67874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561869e67874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56186e771abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56186e77a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56186e762699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56186e78d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f423d981082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561868087b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4a,0x3a,0x2f,0x2f,0x50,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbd,0x81,0x24,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0x21,0x40, Step #5: J://P\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\275\201$\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201\340\276\201!@ Step #5: artifact_prefix='./'; Test unit written to ./oom-cca25acac94627eb53c62587afc2294ac511f7ac Step #5: Base64: SjovL1DgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvoHgvYEk4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6B4L6BIUA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4135 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3781173419 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c4f06fe810, 0x55c4f08e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c4f08e8020,0x55c4f27800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cca25acac94627eb53c62587afc2294ac511f7ac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5135 processed earlier; will process 5894 files now Step #5: ==148936== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c4e71f39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c4ed858898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c4ed83b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c4ed83b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c4e71f9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c4e715ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c4e7155355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c4e71ebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c4ea1baf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c4ea1baf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c4ea1baf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c4ea1baf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c4ea1baf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c4ea1baf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c4ea1baf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c4ea1baf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c4ea1baf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c4ea1baf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c4ec44ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c4e917cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c4e9187be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c4e8f33c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c4e8f33c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c4e8f34738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c4e8f33874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c4e8f33874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c4e8f33874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c4ed83dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c4ed846928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c4ed82e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c4ed859112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb5cff47082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c4e7153b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0x2f,0xd6,0xa0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0xa,0x2f,0xd6,0xa0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x6e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x6e, Step #5: \012\012/\326\240\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012\012/\326\240\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000'\000\000\000\000\000\000n\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000'\000\000\000\000\000\000n Step #5: artifact_prefix='./'; Test unit written to ./oom-50d6c55ddd446405224343a58c841791aee101b8 Step #5: Base64: Cgov1qAAAAAAAAAAAAAAAAAAAAAAAAAACgov1qAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAnAAAAAAAAbgAAAAAAAAAAAAAAAAAAAAAAAAAAJwAAAAAAAG4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4136 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3781670246 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5580bf8f3810, 0x5580bfadd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5580bfadd020,0x5580c19750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/50d6c55ddd446405224343a58c841791aee101b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5136 processed earlier; will process 5893 files now Step #5: ==148972== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5580b63e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5580bca4d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5580bca305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5580bca304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5580b63eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5580b634fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5580b634a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5580b63e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5580b93aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5580b93aff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5580b93aff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5580b93aff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5580b93aff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5580b93aff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5580b93aff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5580b93aff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5580b93aff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5580b93aff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5580bb644f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5580b8371b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5580b837cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580b8128c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580b8128c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580b8129738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580b8128874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580b8128874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580b8128874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5580bca32abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5580bca3b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5580bca23699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5580bca4e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbc9b10e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5580b6348b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x21,0x21,0x21,0x29,0xce,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x47,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xa0,0x4f,0xdd,0xc2,0x58, Step #5: !!!!)\316\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240O\335\240G\335\240O\335\240O\335\240O\335\240O\335\302X Step #5: artifact_prefix='./'; Test unit written to ./oom-98c26f87911d5e768ade0ae184d93d66f61853b3 Step #5: Base64: ISEhISnOoE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doE/doEfdoE/doE/doE/doE/dwlg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4137 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3782173813 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af330b5810, 0x55af3329f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af3329f020,0x55af351370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/98c26f87911d5e768ade0ae184d93d66f61853b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5137 processed earlier; will process 5892 files now Step #5: #1 pulse cov: 3850 ft: 3851 exec/s: 0 rss: 174Mb Step #5: ==149008== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55af29baa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af3020f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af301f25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af301f24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55af29bb0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55af29b11b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55af29b0c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55af29ba2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55af2cb71f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55af2cb71f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55af2cb71f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55af2cb71f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55af2cb71f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55af2cb71f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55af2cb71f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55af2cb71f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55af2cb71f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55af2cb71f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af2ee06f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af2bb33b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af2bb3ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af2b8eac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af2b8eac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af2b8eb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af2b8ea874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af2b8ea874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af2b8ea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af301f4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af301fd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af301e5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af30210112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdedb05e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55af29b0ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x51,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x3d,0x2d,0x2d,0x29,0x63,0x63,0xef,0xbb,0xba,0xe1,0xb9,0x82,0x63,0x63,0xf3,0xa0,0xb9,0x82,0x63,0x63,0xf3,0xa0,0x80,0xb0,0x64,0x63,0x63,0x63,0xef,0xbb,0xbe,0xe0,0xb9,0x86,0x73,0x63,0xf3,0xa0,0xbb,0xbe,0xe0,0xb9,0x86,0x73,0x63,0xf3,0xa0,0x80,0xb0,0x63,0x63,0xf3,0xbd,0xbf,0x82,0x63,0x63,0xf3,0x0,0x0,0x0,0x2f,0x0,0xa9,0xa5,0xa7,0x0,0x7f,0xa5,0x7d,0x73,0x63,0x61,0x27,0xc3,0x2d,0x2d,0x70,0xcc,0x3d,0xa0,0x27,0x2,0x31,0x37,0x0,0xf3,0xa0,0x0,0x0,0x0,0x80, Step #5: Q\000\000\000\000\000\000\000\001\000\000\000=--)cc\357\273\272\341\271\202cc\363\240\271\202cc\363\240\200\260dccc\357\273\276\340\271\206sc\363\240\273\276\340\271\206sc\363\240\200\260cc\363\275\277\202cc\363\000\000\000/\000\251\245\247\000\177\245}sca'\303--p\314=\240'\00217\000\363\240\000\000\000\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-7c2df9664b00742907a94b3cebf8ce99c15608bd Step #5: Base64: UQAAAAAAAAABAAAAPS0tKWNj77u64bmCY2PzoLmCY2PzoICwZGNjY++7vuC5hnNj86C7vuC5hnNj86CAsGNj872/gmNj8wAAAC8AqaWnAH+lfXNjYSfDLS1wzD2gJwIxNwDzoAAAAIA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4138 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3782716688 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5600206f6810, 0x5600208e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5600208e0020,0x5600227780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7c2df9664b00742907a94b3cebf8ce99c15608bd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5139 processed earlier; will process 5890 files now Step #5: ==149044== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5600171eb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56001d850898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56001d8335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56001d8334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5600171f1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560017152b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56001714d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5600171e3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56001a1b2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56001a1b2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56001a1b2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56001a1b2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56001a1b2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56001a1b2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56001a1b2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56001a1b2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56001a1b2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56001a1b2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56001c447f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560019174b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56001917fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560018f2bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560018f2bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560018f2c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560018f2b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560018f2b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560018f2b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56001d835abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56001d83e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56001d826699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56001d851112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f17d3ea1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56001714bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0xa,0x2d,0xcd,0x8f,0xa,0x2d,0xd9,0xb3,0x2d,0x2d,0xcd,0x8f,0xa,0x46,0xe5,0x4e,0x47,0xff,0xff,0xff,0xff,0x10,0x4f, Step #5: I\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000-\012-\315\217\012-\331\263--\315\217\012F\345NG\377\377\377\377\020O Step #5: artifact_prefix='./'; Test unit written to ./oom-813c606cbf0145d44986c6561b56bf4934f6982d Step #5: Base64: SQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAtCi3Njwot2bMtLc2PCkblTkf/////EE8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4139 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3783224645 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562096754810, 0x56209693e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56209693e020,0x5620987d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/813c606cbf0145d44986c6561b56bf4934f6982d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5140 processed earlier; will process 5889 files now Step #5: #1 pulse cov: 3666 ft: 3667 exec/s: 0 rss: 175Mb Step #5: ==149080== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56208d2499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5620938ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5620938915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5620938914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56208d24fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56208d1b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56208d1ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56208d241c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562090210f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562090210f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562090210f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562090210f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562090210f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562090210f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562090210f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562090210f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562090210f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562090210f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5620924a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56208f1d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56208f1ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56208ef89c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56208ef89c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56208ef8a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56208ef89874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56208ef89874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56208ef89874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562093893abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56209389c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562093884699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5620938af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff0d2419082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56208d1a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x32,0x2d,0x27,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $22-=<'''/''''/''2-=''''''/''2-'='''''''''''''-=<''''''''''''-=<'''/''''/''''''2-=''''''''''''.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-4b94b6da7a37e963dec03a2325bc343fd8242329 Step #5: Base64: JDIyLT08JycnLycnJycvJycyLT0nJycnJycvJycyLSc9JycnJycnJycnJycnJy09PCcnJycnJycnJycnJy09PCcnJy8nJycnLycnJycnJzItPScnJycnJycnJycnJy4nJycnLickJy0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4140 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3783771812 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55883acd0810, 0x55883aeba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55883aeba020,0x55883cd520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4b94b6da7a37e963dec03a2325bc343fd8242329' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5142 processed earlier; will process 5887 files now Step #5: #1 pulse cov: 3890 ft: 3891 exec/s: 0 rss: 175Mb Step #5: ==149116== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5588317c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558837e2a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558837e0d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558837e0d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588317cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55883172cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558831727355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588317bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55883478cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55883478cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55883478cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55883478cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55883478cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55883478cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55883478cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55883478cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55883478cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55883478cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558836a21f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55883374eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558833759be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558833505c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558833505c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558833506738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558833505874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558833505874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558833505874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558837e0fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558837e18928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558837e00699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558837e2b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7febb079a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558831725b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x69,0x66,0x31,0x30,0x29,0x69,0x66,0x31,0x30,0x29,0x29,0x21,0x29,0xd7,0xa9,0x1,0x0,0x0,0x15,0x28,0x30,0x29,0x29,0xd7,0xa9,0x28,0x30,0x30,0x29,0x29,0x21,0x29,0xd7,0xa9,0x1,0x0,0x0,0x15,0x28,0x30,0x29,0x29,0xd7,0xa9,0x28,0x30,0x9,0x37,0x21,0x29,0x29,0x21,0x29,0x29,0x29,0x29,0xd7,0xa9,0x28,0x70,0x29,0x29,0x29,0x29,0xd7,0xa9,0x28,0x30,0x9,0x37,0x21,0x29,0x0,0x8d,0x9,0x37,0x21,0x29,0x29,0x21,0x29,0x29,0x29,0x29,0xd7,0xa9,0x28,0x70,0x29,0x29,0x29,0x29,0xd7,0xa9,0x28,0x30,0x9,0x37,0x21,0x29,0x0,0x8d,0x0, Step #5: !if10)if10))!)\327\251\001\000\000\025(0))\327\251(00))!)\327\251\001\000\000\025(0))\327\251(0\0117!))!))))\327\251(p))))\327\251(0\0117!)\000\215\0117!))!))))\327\251(p))))\327\251(0\0117!)\000\215\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f1cd9bec8881c576cc734a059c9be26313682323 Step #5: Base64: IWlmMTApaWYxMCkpISnXqQEAABUoMCkp16koMDApKSEp16kBAAAVKDApKdepKDAJNyEpKSEpKSkp16kocCkpKSnXqSgwCTchKQCNCTchKSkhKSkpKdepKHApKSkp16koMAk3ISkAjQA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4141 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3784314439 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5566dc428810, 0x5566dc61201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5566dc612020,0x5566de4aa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f1cd9bec8881c576cc734a059c9be26313682323' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5144 processed earlier; will process 5885 files now Step #5: #1 pulse cov: 3698 ft: 3699 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 3844 ft: 4026 exec/s: 0 rss: 177Mb Step #5: ==149152== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5566d2f1d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5566d9582898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5566d95655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5566d95654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5566d2f23d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5566d2e84b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5566d2e7f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5566d2f15c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5566d5ee4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5566d5ee4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5566d5ee4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5566d5ee4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5566d5ee4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5566d5ee4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5566d5ee4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5566d5ee4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5566d5ee4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5566d5ee4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5566d8179f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5566d4ea6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5566d4eb1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5566d4c5dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5566d4c5dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5566d4c5e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5566d4c5d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5566d4c5d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5566d4c5d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5566d9567abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5566d9570928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5566d9558699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5566d9583112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5f54d73082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5566d2e7db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x62,0x6a,0x65,0x63,0x74,0x43,0x6c,0x61,0x73,0x73,0x3a,0x73,0x75,0x64,0x6f,0x52,0x6f,0x6c,0x65,0xa,0x73,0x75,0x64,0x6f,0x55,0x73,0x65,0x72,0x3a,0xa,0x73,0x75,0x64,0x6f,0x48,0x6f,0x73,0x74,0x3a,0xa,0x73,0x75,0x64,0x6f,0x43,0x6f,0x6d,0x6d,0x61,0x6e,0x64,0x3a,0xa,0x73,0x75,0x64,0x6f,0x4e,0x6f,0x74,0x41,0x66,0x74,0x65,0x72,0x3a,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x37,0x2e,0xa,0x73,0x75,0x64,0x6f,0x4e,0x6f,0x74,0x42,0x65,0x66,0x6f,0x72,0x65,0x3a,0x31,0x31,0x32,0x34,0x34,0x33,0x36,0x39,0x36,0x32,0x2e, Step #5: objectClass:sudoRole\012sudoUser:\012sudoHost:\012sudoCommand:\012sudoNotAfter:2147483647.\012sudoNotBefore:1124436962. Step #5: artifact_prefix='./'; Test unit written to ./oom-576a1ab2763f798d2fbb682d2fa86695324cce4c Step #5: Base64: b2JqZWN0Q2xhc3M6c3Vkb1JvbGUKc3Vkb1VzZXI6CnN1ZG9Ib3N0OgpzdWRvQ29tbWFuZDoKc3Vkb05vdEFmdGVyOjIxNDc0ODM2NDcuCnN1ZG9Ob3RCZWZvcmU6MTEyNDQzNjk2Mi4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4142 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3784885434 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5634e1a46810, 0x5634e1c3001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5634e1c30020,0x5634e3ac80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/576a1ab2763f798d2fbb682d2fa86695324cce4c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5147 processed earlier; will process 5882 files now Step #5: ==149188== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5634d853b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5634deba0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634deb835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634deb834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5634d8541d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5634d84a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5634d849d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5634d8533c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5634db502f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5634db502f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5634db502f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5634db502f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5634db502f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5634db502f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5634db502f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5634db502f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5634db502f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5634db502f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5634dd797f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5634da4c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5634da4cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5634da27bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5634da27bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5634da27c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5634da27b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5634da27b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5634da27b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5634deb85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5634deb8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5634deb76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5634deba1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f967192a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5634d849bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xda,0xb7,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0xb7,0xbf,0xe2,0x80,0x8c, Step #5: ws:\332\267\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\267\277\342\200\214 Step #5: artifact_prefix='./'; Test unit written to ./oom-8dc1cc6976ed28478b8fb991e7f78fe752de581e Step #5: Base64: d3M62rfit7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/it7/igIw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4143 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3785386621 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a38b3a810, 0x563a38d2401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a38d24020,0x563a3abbc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8dc1cc6976ed28478b8fb991e7f78fe752de581e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5148 processed earlier; will process 5881 files now Step #5: ==149224== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563a2f62f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a35c94898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a35c775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a35c774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a2f635d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a2f596b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a2f591355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a2f627c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a325f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a325f6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a325f6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a325f6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a325f6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a325f6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a325f6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a325f6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a325f6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a325f6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a3488bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a315b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a315c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a3136fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a3136fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a31370738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a3136f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a3136f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a3136f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a35c79abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a35c82928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a35c6a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a35c95112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f646d78e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a2f58fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x2,0x0,0x1c,0x3f,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0xf3,0xa0,0x80,0x81,0x58,0x0,0x40,0xe2,0x80,0xae,0x54,0x54,0x54,0x43,0x4b,0x33, Step #5: ID3\002\002\000\034?GGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG\363\240\200\201X\000@\342\200\256TTTCK3 Step #5: artifact_prefix='./'; Test unit written to ./oom-f35de6deed6ce35196b8864863754435be279e77 Step #5: Base64: SUQzAgIAHD9HR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR/OggIFYAEDigK5UVFRDSzM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4144 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3785889682 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b4d663810, 0x560b4d84d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b4d84d020,0x560b4f6e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f35de6deed6ce35196b8864863754435be279e77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5149 processed earlier; will process 5880 files now Step #5: #1 pulse cov: 3882 ft: 3883 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 12085 ft: 13070 exec/s: 0 rss: 194Mb Step #5: ==149260== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560b441589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b4a7bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b4a7a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b4a7a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b4415ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b440bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b440ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b44150c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b4711ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b4711ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b4711ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b4711ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b4711ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b4711ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b4711ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b4711ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b4711ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b4711ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b493b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b460e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b460ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b45e98c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b45e98c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b45e99738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b45e98874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b45e98874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b45e98874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b4a7a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b4a7ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b4a793699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b4a7be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5748b2e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b440b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x73,0x73,0x3a,0x32,0x34,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb1,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0x2e,0x31,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xbb,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5, Step #5: fss:24\340\275\265\340\275\265\340\275\265\340\275\261\340\275\261\340\275\263\340\275\265\340\275\265\340\275\265\340\275\263\340\275\265\340\275\265\340\275\261\340\275\263\340\275\265\340\275\263.1\340\275\263\340\275\265\340\275\265\340\275\263\340\275\265\340\275\265\340\275\265\340\275\273\340\275\265\340\275\265\340\275\265\340\275\261\340\275\265\340\275\263\340\275\265\340\275\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-3fdf9fb5f09fbe4791823f3f02cb54e89208916e Step #5: Base64: ZnNzOjI04L214L214L214L2x4L2x4L2z4L214L214L214L2z4L214L214L2x4L2z4L214L2zLjHgvbPgvbXgvbXgvbPgvbXgvbXgvbXgvbvgvbXgvbXgvbXgvbHgvbXgvbPgvbXgvbU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4145 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3786535606 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a3670e810, 0x558a368f801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a368f8020,0x558a387900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3fdf9fb5f09fbe4791823f3f02cb54e89208916e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5153 processed earlier; will process 5876 files now Step #5: ==149296== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558a2d2039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a33868898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a3384b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a3384b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a2d209d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a2d16ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a2d165355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a2d1fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a301caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a301caf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a301caf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a301caf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a301caf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a301caf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a301caf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a301caf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a301caf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a301caf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a3245ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a2f18cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a2f197be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a2ef43c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a2ef43c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a2ef44738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a2ef43874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a2ef43874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a2ef43874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a3384dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a33856928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a3383e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a33869112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3381761082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a2d163b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe3,0x80,0x88,0x2d,0x0,0x60,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x73,0x20,0x5b,0x38,0x20,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xb,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x68,0x74,0xe2,0x80,0x88,0x2d,0x0,0x60,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xa,0x2f,0xa,0x2f,0xa,0x60,0x68,0x20,0x20,0x20,0x68,0xa,0x9, Step #5: `\343\200\210-\000`hhhhhhhhs [8 \012=\012=\012=\012=\012=\013\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=ht\342\200\210-\000``\342\200\210-\000`\012/\012`\342\200\210-\000`\012\012/\012/\012`h h\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-a59b422ac47167061ff70a493aca580547da921d Step #5: Base64: YOOAiC0AYGhoaGhoaGhocyBbOCAKPQo9Cj0KPQo9Cwo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj1odOKAiC0AYGDigIgtAGAKLwpg4oCILQBgCgovCi8KYGggICBoCgk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4146 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3787172854 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556228de1810, 0x556228fcb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556228fcb020,0x55622ae630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a59b422ac47167061ff70a493aca580547da921d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5154 processed earlier; will process 5875 files now Step #5: ==149332== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55621f8d69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556225f3b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556225f1e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556225f1e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55621f8dcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55621f83db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55621f838355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55621f8cec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55622289df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55622289df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55622289df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55622289df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55622289df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55622289df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55622289df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55622289df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55622289df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55622289df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556224b32f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55622185fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55622186abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556221616c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556221616c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556221617738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556221616874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556221616874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556221616874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556225f20abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556225f29928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556225f11699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556225f3c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efcdef87082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55621f836b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x42,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x63,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x4c,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: x-----BEGIN -----\012ddddddddddddBddddddddddddddddddddddddddddcdddddddddddddddddddddddddddddL\012-----END ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-052f2abe341e0af4467df5523889232b6e9e2f20 Step #5: Base64: eC0tLS0tQkVHSU4gLS0tLS0KZGRkZGRkZGRkZGRkQmRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRjZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRMCi0tLS0tRU5EIC0tLS0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4147 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3787678505 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5595b03c5810, 0x5595b05af01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5595b05af020,0x5595b24470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/052f2abe341e0af4467df5523889232b6e9e2f20' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5155 processed earlier; will process 5874 files now Step #5: #1 pulse cov: 4037 ft: 4038 exec/s: 0 rss: 174Mb Step #5: ==149368== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5595a6eba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5595ad51f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5595ad5025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5595ad5024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5595a6ec0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5595a6e21b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5595a6e1c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5595a6eb2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5595a9e81f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5595a9e81f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5595a9e81f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5595a9e81f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5595a9e81f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5595a9e81f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5595a9e81f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5595a9e81f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5595a9e81f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5595a9e81f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5595ac116f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5595a8e43b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5595a8e4ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5595a8bfac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5595a8bfac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5595a8bfb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5595a8bfa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5595a8bfa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5595a8bfa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5595ad504abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5595ad50d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5595ad4f5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5595ad520112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4c1fc53082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5595a6e1ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x4f,0x3a,0x31,0x32,0x3a,0x22,0x44,0x61,0x54,0x65,0x49,0x4e,0x74,0x65,0x72,0x76,0x61,0x6c,0x22,0x3a,0x31,0x3a,0x7b,0x73,0x3a,0x31,0x31,0x3a,0x22,0x64,0x61,0x74,0x65,0x5f,0x73,0x74,0x72,0x69,0x6e,0x67,0x22,0x3b,0x53,0x3a,0x35,0x34,0x3a,0x22,0x32,0x3a,0xa,0x62,0x22,0x3b,0x2d,0x30,0x30,0x2b,0x2b,0x2b,0x2b,0x46,0x2b,0x2b,0x2b,0x34,0x39,0x36,0xc2,0xa0,0x66,0x74,0x77,0x65,0x6c,0x66,0x74,0x44,0x77,0x65,0x6c,0x66,0x74,0x79,0xff,0xcd,0xe1,0xfd,0xd3,0x39,0x2d,0x64,0x61,0x74,0x65,0x5f,0x73,0x7b,0x73,0x69,0x6e,0x62,0x22,0x3b, Step #5: |O:12:\"DaTeINterval\":1:{s:11:\"date_string\";S:54:\"2:\012b\";-00++++F+++496\302\240ftwelftDwelfty\377\315\341\375\3239-date_s{sinb\"; Step #5: artifact_prefix='./'; Test unit written to ./oom-87a87c7ba5eb70221212c0f43aff789fb8b4ad3e Step #5: Base64: fE86MTI6IkRhVGVJTnRlcnZhbCI6MTp7czoxMToiZGF0ZV9zdHJpbmciO1M6NTQ6IjI6CmIiOy0wMCsrKytGKysrNDk2wqBmdHdlbGZ0RHdlbGZ0ef/N4f3TOS1kYXRlX3N7c2luYiI7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4148 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3788230685 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555bb8ff8810, 0x555bb91e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555bb91e2020,0x555bbb07a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87a87c7ba5eb70221212c0f43aff789fb8b4ad3e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5157 processed earlier; will process 5872 files now Step #5: ==149404== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555bafaed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555bb6152898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555bb61355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555bb61354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555bafaf3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555bafa54b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555bafa4f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555bafae5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555bb2ab4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555bb2ab4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555bb2ab4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555bb2ab4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555bb2ab4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555bb2ab4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555bb2ab4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555bb2ab4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555bb2ab4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555bb2ab4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555bb4d49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555bb1a76b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555bb1a81be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555bb182dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555bb182dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555bb182e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555bb182d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555bb182d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555bb182d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555bb6137abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555bb6140928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555bb6128699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555bb6153112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5540806082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555bafa4db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0x20,0x73,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0x20,0x25,0x20,0x78,0x78,0x20,0x27,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0x20,0x72,0x4e,0x61,0xd,0x4f,0x9,0x28,0x49,0x29,0x9,0x22,0x4e,0x4e,0x26,0x23,0x33,0x38,0x3b,0x23,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x31,0x38,0x34,0x32,0x37,0x33,0x38,0x37,0x39,0x30,0x34,0x27,0x3e,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b, Step #5: <!DOCTYPE s[<!ENTITY % xx '<!ATTLIST rNa\015O\011(I)\011\"NN&#38;#9223372018427387904'>%xx;%xx;%xx;%xx;%xx;%xx;%xx; Step #5: artifact_prefix='./'; Test unit written to ./oom-a9d3d3e4f60eaa1478e752906a99e337bb55f929 Step #5: Base64: PCFET0NUWVBFIHNbPCFFTlRJVFkgJSB4eCAnPCFBVFRMSVNUIHJOYQ1PCShJKQkiTk4mIzM4OyM5MjIzMzcyMDE4NDI3Mzg3OTA0Jz4leHg7JXh4OyV4eDsleHg7JXh4OyV4eDsleHg7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4149 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3788735783 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563b386ea810, 0x563b388d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563b388d4020,0x563b3a76c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9d3d3e4f60eaa1478e752906a99e337bb55f929' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5158 processed earlier; will process 5871 files now Step #5: ==149440== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563b2f1df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563b35844898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563b358275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563b358274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563b2f1e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563b2f146b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563b2f141355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563b2f1d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563b321a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563b321a6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563b321a6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563b321a6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563b321a6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563b321a6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563b321a6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563b321a6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563b321a6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563b321a6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563b3443bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563b31168b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563b31173be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563b30f1fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563b30f1fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563b30f20738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563b30f1f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563b30f1f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563b30f1f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563b35829abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563b35832928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563b3581a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563b35845112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdbd8c1e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563b2f13fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x67,0x62,0x49,0x54,0x32,0x58,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x54,0x32,0x58,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xa9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x64,0x61,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x31,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xa9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x43,0x4f,0x4d,0x2,0xdb,0xbf,0x9f,0xff, Step #5: ID3gbIT2X\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000T2X\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\342\200\251\000\000\000\000\000\000\000\000\000\000\000\000\000da\000\000\000\000\000\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\342\200\251\000\000\000\000\000\000\000COM\002\333\277\237\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-9ca446992b14665b44b7072db3e44bb8bd5f72a2 Step #5: Base64: SUQzZ2JJVDJYAAAAAAAAAAAAAAAAAAAAAFQyWAAAAAAAAAAAAAAAAAAAAAAAAADigKkAAAAAAAAAAAAAAAAAZGEAAAAAAAAAAAAxAAAAAAAAAAAAAAAA4oCpAAAAAAAAAENPTQLbv5// Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4150 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3789239949 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564dc24ae810, 0x564dc269801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564dc2698020,0x564dc45300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9ca446992b14665b44b7072db3e44bb8bd5f72a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5159 processed earlier; will process 5870 files now Step #5: ==149476== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564db8fa39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564dbf608898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564dbf5eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564dbf5eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564db8fa9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564db8f0ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564db8f05355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564db8f9bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564dbbf6af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564dbbf6af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564dbbf6af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564dbbf6af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564dbbf6af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564dbbf6af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564dbbf6af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564dbbf6af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564dbbf6af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564dbbf6af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564dbe1fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564dbaf2cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564dbaf37be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564dbace3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564dbace3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564dbace4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564dbace3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564dbace3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564dbace3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564dbf5edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564dbf5f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564dbf5de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564dbf609112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a729dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564db8f03b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0xd,0xa,0x2a,0x34,0x37,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x2b,0xd,0xa,0x0, Step #5: *\015\012*47\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012+\015\012\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-885c3ba1a981c1fafb1a54b8be069b26ea44b06e Step #5: Base64: Kg0KKjQ3DQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQorDQoA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4151 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3789765946 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561326246810, 0x56132643001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561326430020,0x5613282c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/885c3ba1a981c1fafb1a54b8be069b26ea44b06e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5160 processed earlier; will process 5869 files now Step #5: ==149512== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56131cd3b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5613233a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613233835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613233834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56131cd41d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56131cca2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56131cc9d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56131cd33c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56131fd02f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56131fd02f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56131fd02f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56131fd02f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56131fd02f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56131fd02f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56131fd02f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56131fd02f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56131fd02f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56131fd02f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561321f97f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56131ecc4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56131eccfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56131ea7bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56131ea7bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56131ea7c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56131ea7b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56131ea7b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56131ea7b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561323385abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56132338e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561323376699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5613233a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb151479082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56131cc9bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0x1f,0x20,0xa, Step #5: \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \037 \012 Step #5: artifact_prefix='./'; Test unit written to ./oom-df2fdd1a85d3b0d181657af24d89f4bd770e7f60 Step #5: Base64: HyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAfIB8gHyAK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4152 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3790269033 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560788be9810, 0x560788dd301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560788dd3020,0x56078ac6b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/df2fdd1a85d3b0d181657af24d89f4bd770e7f60' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5161 processed earlier; will process 5868 files now Step #5: ==149548== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56077f6de9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560785d43898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560785d265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560785d264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56077f6e4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56077f645b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56077f640355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56077f6d6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5607826a5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5607826a5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5607826a5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5607826a5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5607826a5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5607826a5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5607826a5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5607826a5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5607826a5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5607826a5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56078493af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560781667b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560781672be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56078141ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56078141ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56078141f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56078141e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56078141e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56078141e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560785d28abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560785d31928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560785d19699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560785d44112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc918ce2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56077f63eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x68,0x29,0x68,0x68,0x68,0x68,0x3f,0x68,0x68,0x69,0x68,0x68,0x48,0x69,0x68,0x68,0x60,0x68,0x70,0xf3,0xa0,0x81,0xac,0x68,0x69,0x68,0x68,0x60,0x68,0x70,0xf3,0xa0,0x81,0xac,0x68,0x69,0x68,0x68,0x22,0x78,0x63,0x61,0x6c,0x63,0xf3,0xa0,0x80,0xa1,0x68,0xf2,0xa0,0x81,0xbb,0x68,0x68,0x69,0x68,0x69,0xf3,0x9e,0x80,0x80,0x28,0x69,0xf3,0xa0,0x81,0x87,0x6f,0x64,0x68,0x6d,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x69,0x2e,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x70,0x68,0x2e,0xf3,0x9e,0x80,0x80,0x68,0x67,0x6f,0x74,0x2f,0x68,0x68,0x67, Step #5: %h)hhhh?hhihhHihh`hp\363\240\201\254hihh`hp\363\240\201\254hihh\"xcalc\363\240\200\241h\362\240\201\273hhihi\363\236\200\200(i\363\240\201\207odhmhhhhhhhhi.hhhhhhhph.\363\236\200\200hgot/hhg Step #5: artifact_prefix='./'; Test unit written to ./oom-ee91d5687daaf97dee532a198755a6fc11a5f78b Step #5: Base64: JWgpaGhoaD9oaGloaEhpaGhgaHDzoIGsaGloaGBocPOggaxoaWhoInhjYWxj86CAoWjyoIG7aGhpaGnznoCAKGnzoIGHb2RobWhoaGhoaGhoaS5oaGhoaGhocGgu856AgGhnb3QvaGhn Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4153 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3790893748 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561f3fbd3810, 0x561f3fdbd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561f3fdbd020,0x561f41c550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee91d5687daaf97dee532a198755a6fc11a5f78b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5162 processed earlier; will process 5867 files now Step #5: ==149584== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561f366c89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561f3cd2d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561f3cd105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561f3cd104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561f366ced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561f3662fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561f3662a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561f366c0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561f3968ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561f3968ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561f3968ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561f3968ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561f3968ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561f3968ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561f3968ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561f3968ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561f3968ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561f3968ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561f3b924f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561f38651b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561f3865cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561f38408c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561f38408c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561f38409738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561f38408874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561f38408874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561f38408874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561f3cd12abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561f3cd1b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561f3cd03699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561f3cd2e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa60509082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561f36628b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0xe0,0xbf,0xad,0x2b,0x56,0xa,0x56,0xa,0x2b,0xe2,0x80,0xad,0x63,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0xe2,0x80,0xad,0x63,0xa,0x73,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0x56,0xa,0x56,0xa,0x1,0x0,0x2b,0xe2,0x80,0xad,0x63,0xa,0xa,0x2b, Step #5: c\012+\012\012+\012+c\012\363\240\201\264+\012+V\012V\012\340\277\255+V\012V\012+\342\200\255c\012+\012\012+\012+c\012\363\240\201\264+\012+V\012V\012+\012\012+\012+c\012\363\240\201\264+\012+V\012V\012+\342\200\255c\012s\240\201\264+\012+V\012V\012+V\012V\012\001\000+\342\200\255c\012\012+ Step #5: artifact_prefix='./'; Test unit written to ./oom-fa05abd4cc17e0aa00c2bd01eee68f432310985d Step #5: Base64: YworCgorCitjCvOggbQrCitWClYK4L+tK1YKVgor4oCtYworCgorCitjCvOggbQrCitWClYKKwoKKworYwrzoIG0KworVgpWCivigK1jCnOggbQrCitWClYKK1YKVgoBACvigK1jCgor Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4154 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3791407602 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561bd2abe810, 0x561bd2ca801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561bd2ca8020,0x561bd4b400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fa05abd4cc17e0aa00c2bd01eee68f432310985d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5163 processed earlier; will process 5866 files now Step #5: ==149620== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561bc95b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561bcfc18898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561bcfbfb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561bcfbfb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561bc95b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561bc951ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561bc9515355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561bc95abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561bcc57af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561bcc57af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561bcc57af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561bcc57af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561bcc57af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561bcc57af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561bcc57af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561bcc57af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561bcc57af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561bcc57af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561bce80ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561bcb53cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561bcb547be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561bcb2f3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561bcb2f3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561bcb2f4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561bcb2f3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561bcb2f3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561bcb2f3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561bcfbfdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561bcfc06928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561bcfbee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561bcfc19112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa0cdd54082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561bc9513b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x78,0x39,0x30,0x5c,0x78,0x39,0x32,0x5c,0x78,0x39,0x30,0x5c,0x78,0x2d,0x33,0x25,0x6e,0x5c,0x78,0x30,0x64,0x4e,0x61,0x4e,0x24,0x21,0x21,0x24,0x60,0x5c,0x78,0x30,0x61,0x2b,0x69,0x6e,0x66,0x27,0x78,0x63,0x61,0x6c,0x63,0x24,0x26,0x2b,0x69,0x6e,0x66,0x5c,0x78,0x30,0x30,0x24,0x26,0x5c,0x78,0x30,0x30,0x21,0x21,0x24,0x28,0x78,0x63,0x61,0x6c,0x63,0x29,0x5c,0x78,0x30,0x64,0x5c,0x72,0x5c,0x6e,0x2b,0x69,0x6e,0x66,0x24,0x60,0x38,0x35,0x36,0x33,0x31,0x30,0x37,0x30,0x36,0x35,0x37,0x36,0x30,0x30,0xb1,0x38,0x37,0x37,0x32,0x39,0x35, Step #5: \\x90\\x92\\x90\\x-3%n\\x0dNaN$!!$`\\x0a+inf'xcalc$&+inf\\x00$&\\x00!!$(xcalc)\\x0d\\r\\n+inf$`85631070657600\261877295 Step #5: artifact_prefix='./'; Test unit written to ./oom-9bee2ba9259c98b15ff9629c82ad9072ea3e1684 Step #5: Base64: XHg5MFx4OTJceDkwXHgtMyVuXHgwZE5hTiQhISRgXHgwYStpbmYneGNhbGMkJitpbmZceDAwJCZceDAwISEkKHhjYWxjKVx4MGRcclxuK2luZiRgODU2MzEwNzA2NTc2MDCxODc3Mjk1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4155 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3792036667 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56276f511810, 0x56276f6fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56276f6fb020,0x5627715930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9bee2ba9259c98b15ff9629c82ad9072ea3e1684' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5164 processed earlier; will process 5865 files now Step #5: ==149656== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5627660069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56276c66b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56276c64e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56276c64e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56276600cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562765f6db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562765f68355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562765ffec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562768fcdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562768fcdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562768fcdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562768fcdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562768fcdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562768fcdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562768fcdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562768fcdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562768fcdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562768fcdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56276b262f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562767f8fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562767f9abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562767d46c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562767d46c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562767d47738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562767d46874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562767d46874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562767d46874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56276c650abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56276c659928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56276c641699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56276c66c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcbcc5bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562765f66b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x2d,0x3d,0x2f,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x32,0x2d,0x27,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $22-=/'''/''''/''2-=''''''/''2-'='''''''''''''-=<''''''''''''-=<'''/'''''/'''''2-='\000\000\000\000\000\000\000\001''''.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-3dd5103b50c5f12da0d047d8509f455a0e68ed8c Step #5: Base64: JDIyLT0vJycnLycnJycvJycyLT0nJycnJycvJycyLSc9JycnJycnJycnJycnJy09PCcnJycnJycnJycnJy09PCcnJy8nJycnJy8nJycnJzItPScAAAAAAAAAAScnJycuJycnJy4nJCct Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4156 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3792552572 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56151857c810, 0x56151876601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561518766020,0x56151a5fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3dd5103b50c5f12da0d047d8509f455a0e68ed8c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5165 processed earlier; will process 5864 files now Step #5: ==149692== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56150f0719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5615156d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5615156b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5615156b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56150f077d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56150efd8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56150efd3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56150f069c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561512038f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561512038f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561512038f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561512038f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561512038f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561512038f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561512038f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561512038f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561512038f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561512038f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5615142cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561510ffab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561511005be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561510db1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561510db1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561510db2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561510db1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561510db1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561510db1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5615156bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5615156c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5615156ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5615156d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f225ebdf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56150efd1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0xe0,0xbf,0xad,0x2b,0x56,0xa,0x56,0xa,0x2b,0xe2,0x80,0xad,0x63,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0xe2,0x80,0xad,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0x56,0xa,0x56,0xa,0x1,0x0,0x2b,0xe2,0x80,0xad,0x63,0xa,0xa,0x2b, Step #5: c\012+\012\012+\012+c\012\363\240\201\264+\012+V\012V\012\340\277\255+V\012V\012+\342\200\255c\012+\012\012+\012+c\012\363\240\201\264+\012+V\012V\012+\012\012+\012+c\012\363\240\201\264+\012+V\012V\012+\342\200\255c\012\363\240\201\264+\012+V\012V\012+V\012V\012\001\000+\342\200\255c\012\012+ Step #5: artifact_prefix='./'; Test unit written to ./oom-b83d204dd4c0f483e54b211273eaf5b7f45c10eb Step #5: Base64: YworCgorCitjCvOggbQrCitWClYK4L+tK1YKVgor4oCtYworCgorCitjCvOggbQrCitWClYKKwoKKworYwrzoIG0KworVgpWCivigK1jCvOggbQrCitWClYKK1YKVgoBACvigK1jCgor Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4157 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3793079085 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560beb447810, 0x560beb63101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560beb631020,0x560bed4c90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b83d204dd4c0f483e54b211273eaf5b7f45c10eb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5166 processed earlier; will process 5863 files now Step #5: #1 pulse cov: 3903 ft: 3904 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 4258 ft: 4570 exec/s: 0 rss: 175Mb Step #5: #4 pulse cov: 12621 ft: 16946 exec/s: 0 rss: 196Mb Step #5: ==149728== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560be1f3c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560be85a1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560be85845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560be85844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560be1f42d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560be1ea3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560be1e9e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560be1f34c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560be4f03f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560be4f03f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560be4f03f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560be4f03f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560be4f03f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560be4f03f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560be4f03f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560be4f03f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560be4f03f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560be4f03f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560be7198f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560be3ec5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560be3ed0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560be3c7cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560be3c7cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560be3c7d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560be3c7c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560be3c7c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560be3c7c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560be8586abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560be858f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560be8577699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560be85a2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa467e86082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560be1e9cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x26,0x22,0x22,0x22,0x22,0x22,0x22,0x3e,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x26,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x26,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x3e,0x22,0x22,0x22,0x26,0x5c,0x22,0x61,0x61,0x21, Step #5: \"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"&\"\"\"\"\"\">\"\"\"\"\"\"\"\"\"\"&\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"&\"\"\"\"\"\"\">\"\"\"&\\\"aa! Step #5: artifact_prefix='./'; Test unit written to ./oom-df6cb3a63e18bc817ba524ef7ee24f3cfae768fb Step #5: Base64: IiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiImIiIiIiIiPiIiIiIiIiIiIiImIiIiIiIiIiIiIiIiIiIiIiIiIiYiIiIiIiIiPiIiIiZcImFhIQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4158 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3793779846 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a0b682810, 0x559a0b86c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a0b86c020,0x559a0d7040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/df6cb3a63e18bc817ba524ef7ee24f3cfae768fb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5171 processed earlier; will process 5858 files now Step #5: #1 pulse cov: 3977 ft: 3978 exec/s: 0 rss: 176Mb Step #5: ==149764== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559a021779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a087dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a087bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a087bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a0217dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a020deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a020d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a0216fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a0513ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a0513ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a0513ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a0513ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a0513ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a0513ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a0513ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a0513ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a0513ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a0513ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a073d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a04100b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a0410bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a03eb7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a03eb7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a03eb8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a03eb7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a03eb7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a03eb7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a087c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a087ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a087b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a087dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc99f5e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a020d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xa,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x20,0x42,0x45,0x47,0x49,0x4e,0x2d,0x2d,0x2d,0x2d,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0xf,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x30,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x9,0xa,0x60,0x47,0x60,0xa,0x5,0x2d,0x9,0xa,0x60,0x47,0x47,0x0,0x54,0x49,0x42,0xa,0x60,0x60,0x20,0x20,0x20,0x60,0x0,0x54,0x0,0x54,0x49,0x42,0xa,0x60,0x60,0x20,0x20,0x20,0x60,0x0,0x54,0x49,0x42,0xa,0x60,0x60,0x20,0x20,0x20,0x2d,0xa,0x9, Step #5: `\012\005------ BEGIN----\012\000\000\000\000\000\000\017'\000\000\000\000\000\000\000\000\000\000\000ddddddd0ddddddddd\011\012`G`\012\005-\011\012`GG\000TIB\012`` `\000T\000TIB\012`` `\000TIB\012`` -\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-824b3fa3778325899078b43f4602b35562eed07d Step #5: Base64: YAoFLS0tLS0tIEJFR0lOLS0tLQoAAAAAAAAPJwAAAAAAAAAAAAAAZGRkZGRkZDBkZGRkZGRkZGQJCmBHYAoFLQkKYEdHAFRJQgpgYCAgIGAAVABUSUIKYGAgICBgAFRJQgpgYCAgIC0KCQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4159 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3794467914 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5637ccd58810, 0x5637ccf4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5637ccf42020,0x5637cedda0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/824b3fa3778325899078b43f4602b35562eed07d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5173 processed earlier; will process 5856 files now Step #5: ==149800== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5637c384d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5637c9eb2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5637c9e955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5637c9e954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5637c3853d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5637c37b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5637c37af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5637c3845c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5637c6814f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5637c6814f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5637c6814f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5637c6814f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5637c6814f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5637c6814f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5637c6814f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5637c6814f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5637c6814f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5637c6814f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5637c8aa9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5637c57d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5637c57e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5637c558dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5637c558dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5637c558e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5637c558d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5637c558d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5637c558d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5637c9e97abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5637c9ea0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5637c9e88699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5637c9eb3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff99056b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5637c37adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x29,0x0,0xef,0xbd,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0x0,0xef,0xbd,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0x0,0xef,0xbd,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0x0,0xef,0xbd,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x87,0x0,0xef,0xbd,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0x0,0xef,0xbd,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0x0,0xef,0xbd,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0x0,0xef,0xbd,0x87,0xef,0xb9,0xbc,0xef,0xbc,0x88,0xef,0xb9,0x88,0xed, Step #5: )\000\357\275\207\357\271\274\357\274\210\357\271\210\000\357\275\207\357\271\274\357\274\210\357\271\210\000\357\275\207\357\271\274\357\274\210\357\271\210\000\357\275\207\357\271\274\357\274\210\357\271\207\000\357\275\207\357\271\274\357\274\210\357\271\210\000\357\275\207\357\271\274\357\274\210\357\271\210\000\357\275\207\357\271\274\357\274\210\357\271\210\000\357\275\207\357\271\274\357\274\210\357\271\210\355 Step #5: artifact_prefix='./'; Test unit written to ./oom-20cd89da64d4b25574727bc4b88fe6e719109511 Step #5: Base64: KQDvvYfvubzvvIjvuYgA772H77m877yI77mIAO+9h++5vO+8iO+5iADvvYfvubzvvIjvuYcA772H77m877yI77mIAO+9h++5vO+8iO+5iADvvYfvubzvvIjvuYgA772H77m877yI77mI7Q== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4160 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3794974743 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611fa7ea810, 0x5611fa9d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5611fa9d4020,0x5611fc86c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/20cd89da64d4b25574727bc4b88fe6e719109511' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5174 processed earlier; will process 5855 files now Step #5: #1 pulse cov: 4018 ft: 4019 exec/s: 0 rss: 176Mb Step #5: ==149836== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5611f12df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5611f7944898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611f79275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611f79274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5611f12e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5611f1246b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5611f1241355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5611f12d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5611f42a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5611f42a6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5611f42a6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5611f42a6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5611f42a6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5611f42a6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5611f42a6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5611f42a6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5611f42a6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5611f42a6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5611f653bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611f3268b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5611f3273be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611f301fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611f301fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611f3020738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611f301f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611f301f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611f301f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5611f7929abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5611f7932928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611f791a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5611f7945112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e58346082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5611f123fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x43,0x46,0x24,0x0,0x22,0x22,0x22,0x22,0x0,0x0,0x5c,0xf3,0xbf,0xbe,0x8d,0x24,0x0,0x22,0x22,0x22,0x22,0x0,0x0,0x0,0x0,0x0,0x62,0x0,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x29,0x18,0x2a,0x2a,0x2a,0x2a,0x43,0x46,0x24,0x0,0x22,0x22,0x22,0x22,0x0,0x0,0x0,0x0,0x0,0x62,0x0,0x24,0x0,0x22,0x22,0x22,0x22,0x0,0x0,0x0,0x0,0x0,0x62,0x0,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x29,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0xd7,0xd5,0xd5,0xd5,0xd5,0xd5,0xd5,0xd9,0x2a,0x2a,0xad,0x2a,0x2a,0xd, Step #5: x-CF$\000\"\"\"\"\000\000\\\363\277\276\215$\000\"\"\"\"\000\000\000\000\000b\000\000*****)\030****CF$\000\"\"\"\"\000\000\000\000\000b\000$\000\"\"\"\"\000\000\000\000\000b\000\000*****)*********\000*****\327\325\325\325\325\325\325\331**\255**\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-1c9100ccb34fdf50dd8c7a1552bf5f19f728f5c0 Step #5: Base64: eC1DRiQAIiIiIgAAXPO/vo0kACIiIiIAAAAAAGIAACoqKioqKRgqKioqQ0YkACIiIiIAAAAAAGIAJAAiIiIiAAAAAABiAAAqKioqKikqKioqKioqKioAKioqKirX1dXV1dXV2SoqrSoqDQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4161 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3795530034 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f86f8cd810, 0x55f86fab701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f86fab7020,0x55f87194f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c9100ccb34fdf50dd8c7a1552bf5f19f728f5c0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5176 processed earlier; will process 5853 files now Step #5: ==149872== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8663c29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f86ca27898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f86ca0a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f86ca0a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8663c8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f866329b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f866324355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8663bac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f869389f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f869389f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f869389f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f869389f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f869389f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f869389f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f869389f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f869389f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f869389f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f869389f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f86b61ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f86834bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f868356be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f868102c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f868102c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f868103738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f868102874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f868102874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f868102874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f86ca0cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f86ca15928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f86c9fd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f86ca28112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f801c620082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f866322b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x7f,0x5d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x32,0x32,0x0,0x24,0x0,0x0,0x0, Step #5: $\177]\177\000\000\0002\000\000\0002.23/\020./( 7 =\177\000\000\000\000\177\177\177o\000\00023/\020./( 7 =\177\000\000\000\177]\177\000\000\0002\000\000\0002.23/\020./( 7 =\177\000\000\000\000\177\177\177o\000\00023/\020./( 7 =\177\000\000\00022\000$\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8ae616f4ff36542af6dccd8a6b48c6183198e807 Step #5: Base64: JH9dfwAAADIAAAAyLjIzLxAuLyggNyA9fwAAAAB/f39vAAAyMy8QLi8oIDcgPX8AAAB/XX8AAAAyAAAAMi4yMy8QLi8oIDcgPX8AAAAAf39/bwAAMjMvEC4vKCA3ID1/AAAAMjIAJAAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4162 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3796052204 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db8880d810, 0x55db889f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db889f7020,0x55db8a88f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ae616f4ff36542af6dccd8a6b48c6183198e807' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5177 processed earlier; will process 5852 files now Step #5: #1 pulse cov: 3644 ft: 3645 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4586 ft: 5015 exec/s: 0 rss: 179Mb Step #5: #4 pulse cov: 5086 ft: 6248 exec/s: 0 rss: 180Mb Step #5: ==149908== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db7f3029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db85967898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db8594a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db8594a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db7f308d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db7f269b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db7f264355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db7f2fac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db822c9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db822c9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db822c9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db822c9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db822c9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db822c9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db822c9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db822c9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db822c9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db822c9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db8455ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db8128bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db81296be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db81042c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db81042c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db81043738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db81042874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db81042874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db81042874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db8594cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db85955928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db8593d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db85968112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe207160082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db7f262b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x65,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3d,0x22,0x43,0x6e,0x22,0x24,0x24,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0xc9, Step #5: <?xml encoding=\"Cn\"$$~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\311 Step #5: artifact_prefix='./'; Test unit written to ./oom-a13b1b34c478f8ddd122ef8cf7f437b9c008e89a Step #5: Base64: PD94bWwgZW5jb2Rpbmc9IkNuIiQkfn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fsk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4163 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3796751189 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556193070810, 0x55619325a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55619325a020,0x5561950f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a13b1b34c478f8ddd122ef8cf7f437b9c008e89a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5183 processed earlier; will process 5846 files now Step #5: ==149944== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556189b659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5561901ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5561901ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5561901ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556189b6bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556189accb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556189ac7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556189b5dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55618cb2cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55618cb2cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55618cb2cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55618cb2cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55618cb2cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55618cb2cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55618cb2cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55618cb2cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55618cb2cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55618cb2cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55618edc1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55618baeeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55618baf9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55618b8a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55618b8a5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55618b8a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55618b8a5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55618b8a5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55618b8a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5561901afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5561901b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5561901a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5561901cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efda986c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556189ac5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1,0xa,0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1,0xa,0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1,0xa,0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1, Step #5: \013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261\012\013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261\012\013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261\012\013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-b7375e505359cc8f6a603e9beda3cbfb600185a1 Step #5: Base64: C++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLEKC++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLEKC++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLEKC++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4164 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3797259093 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560139d17810, 0x560139f0101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560139f01020,0x56013bd990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7375e505359cc8f6a603e9beda3cbfb600185a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5184 processed earlier; will process 5845 files now Step #5: ==149980== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56013080c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560136e71898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560136e545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560136e544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560130812d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560130773b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56013076e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560130804c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601337d3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601337d3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601337d3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601337d3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601337d3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601337d3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601337d3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601337d3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601337d3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601337d3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560135a68f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560132795b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601327a0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56013254cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56013254cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56013254d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56013254c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56013254c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56013254c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560136e56abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560136e5f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560136e47699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560136e72112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f445be11082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56013076cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x2e,0x7c,0x2e,0x2e,0x0,0x7c,0x2e,0x7c,0x7c,0x2e,0x2e,0x30,0x2e,0x7c,0x2e,0x2e,0x2e,0x1,0x2e,0x2e,0x2e,0x7c,0x7c,0x2e,0x2e,0x32,0x7c,0x2e,0x7c,0x7c,0x2e,0x2e,0x31,0x2e,0x7c,0x2e,0x2e,0x2e,0x1,0x7c,0x7c,0x2e,0x7c,0x2e,0x2e,0x2e,0x2e,0x7c,0x7c,0x2e,0x2e,0x30,0x7c,0x7c,0x2e,0x7c,0x2e,0x2e,0x2e,0x7c,0x7c,0x2e,0x2e,0x30,0x7c,0x2e,0x7c,0x7c,0x2e,0x2e,0x31,0x2e,0x7c,0x2e,0x2e,0x2e,0x1,0x7c,0x7c,0x7c,0x2e,0x2e,0x31,0x7c,0x2e,0x7c,0x7c,0x2e,0x2e,0x2e,0x30,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x2e,0x2e,0x31,0x2e,0x7c,0xe,0x2e,0x2e,0x2e, Step #5: 1.|..\000|.||..0.|...\001...||..2|.||..1.|...\001||.|....||..0||.|...||..0|.||..1.|...\001|||..1|.||...0|.||.|..1.|\016... Step #5: artifact_prefix='./'; Test unit written to ./oom-b89f9518cf9a02fa9259a2a93a790a1b96fbb91a Step #5: Base64: MS58Li4AfC58fC4uMC58Li4uAS4uLnx8Li4yfC58fC4uMS58Li4uAXx8LnwuLi4ufHwuLjB8fC58Li4ufHwuLjB8Lnx8Li4xLnwuLi4BfHx8Li4xfC58fC4uLjB8Lnx8LnwuLjEufA4uLi4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4165 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3797773464 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558558a3d810, 0x558558c2701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558558c27020,0x55855aabf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b89f9518cf9a02fa9259a2a93a790a1b96fbb91a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5185 processed earlier; will process 5844 files now Step #5: ==150016== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55854f5329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558555b97898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558555b7a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558555b7a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55854f538d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55854f499b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55854f494355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55854f52ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5585524f9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5585524f9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5585524f9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5585524f9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5585524f9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5585524f9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5585524f9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5585524f9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5585524f9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5585524f9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55855478ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5585514bbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5585514c6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558551272c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558551272c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558551273738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558551272874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558551272874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558551272874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558555b7cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558555b85928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558555b6d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558555b98112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f70e4140082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55854f492b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x9,0x7e,0x7a,0x45,0x7e,0x7e,0x7e,0xa,0x9,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x69,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0xa,0x5c, Step #5: +\012\011~zE~~~\012\011~~~~~~OOOOOOOOOOOOOOOOOOOOOOOOOiOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO~~~~~~~~~~~\012\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-94f99f122bf9580434a08e48aaa6a170b21978bc Step #5: Base64: KwoJfnpFfn5+Cgl+fn5+fn5PT09PT09PT09PT09PT09PT09PT09PT09PaU9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT35+fn5+fn5+fn5+Clw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4166 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3798295458 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557f7cc1f810, 0x557f7ce0901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557f7ce09020,0x557f7eca10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/94f99f122bf9580434a08e48aaa6a170b21978bc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5186 processed earlier; will process 5843 files now Step #5: ==150052== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557f737149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f79d79898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f79d5c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f79d5c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f7371ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f7367bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f73676355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f7370cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f766dbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f766dbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f766dbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f766dbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f766dbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f766dbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f766dbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f766dbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f766dbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f766dbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f78970f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f7569db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f756a8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f75454c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f75454c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f75455738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f75454874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f75454874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f75454874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f79d5eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f79d67928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f79d4f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f79d7a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f84074c1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f73674b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x11,0xf,0x31,0x11,0x2d,0x3a,0x24,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x31,0x8,0x11,0x2d,0x3a,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x2d,0x20,0x2d,0x20,0x20,0x2d,0x20,0x2d,0x3a,0x7c,0x20,0x2d,0x2d,0x3a,0x7c,0x20,0x2d,0x31,0x8,0x11,0x2d,0x3a,0x3a,0x20,0x3a,0x20,0x2d,0x20,0x2d,0x3a,0x7c,0x20,0x2d,0x2d,0x24,0x0,0x5b,0x11,0x2d,0x2d,0x3a,0x3a,0x24,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x0,0x24,0x5b,0x2d,0x3a,0x24,0x24,0x5b,0x5b,0x3a,0x7c,0x20,0x2d,0x3a,0x20, Step #5: \021\0171\021-:$\017\017\0171\021\01711\010\021-:\000\000/\000\000\000/\000\017\017\017\017\0171\021\0171- - - -:| --:| -1\010\021-:: : - -:| --$\000[\021--::$-\017\017\017\017\0171\021\0171\021-:\000$[-:$$[[:| -: Step #5: artifact_prefix='./'; Test unit written to ./oom-4fea6ae3685a03e0bc3681fa9b07d70e2f83474f Step #5: Base64: EQ8xES06JA8PDzERDzExCBEtOgAALwAAAC8ADw8PDw8xEQ8xLSAtICAtIC06fCAtLTp8IC0xCBEtOjogOiAtIC06fCAtLSQAWxEtLTo6JC0PDw8PDzERDzERLToAJFstOiQkW1s6fCAtOiA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4167 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3798830881 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558db3cfd810, 0x558db3ee701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558db3ee7020,0x558db5d7f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4fea6ae3685a03e0bc3681fa9b07d70e2f83474f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5187 processed earlier; will process 5842 files now Step #5: ==150088== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558daa7f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558db0e57898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558db0e3a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558db0e3a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558daa7f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558daa759b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558daa754355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558daa7eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558dad7b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558dad7b9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558dad7b9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558dad7b9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558dad7b9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558dad7b9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558dad7b9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558dad7b9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558dad7b9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558dad7b9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558dafa4ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558dac77bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558dac786be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558dac532c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558dac532c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558dac533738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558dac532874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558dac532874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558dac532874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558db0e3cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558db0e45928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558db0e2d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558db0e58112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f637e0f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558daa752b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xa,0x73,0x75,0x62,0x7b,0x73,0x75,0x62,0x7b,0x73,0x3a,0x22,0x2d,0xf3,0xa0,0x80,0xb7,0x3d,0x31,0x37,0x30,0x31,0x34,0x31,0x31,0x38,0x33,0x34,0x36,0x30,0x34,0x36,0x39,0x32,0x33,0x31,0x37,0x33,0x31,0x36,0xf3,0xa0,0x81,0xbf,0x39,0x36,0x35,0x39,0x30,0x36,0x30,0x34,0x31,0x33,0x35,0x31,0x32,0x32,0x31,0x32,0x30,0xca,0xb3,0x32,0xf3,0xa0,0x9b,0x9d,0x31,0x18,0x33,0xe2,0x81,0xa7,0x32,0x35,0x37,0x22,0x7d,0x73,0x75,0x62,0x7b,0x73,0x3a,0x22,0x22,0x7d,0x7d,0x73,0x75,0x62,0x7b,0x69,0x3a,0x32,0x7d, Step #5: FUZZTESTv1\012sub{sub{s:\"-\363\240\200\267=1701411834604692317316\363\240\201\27796590604135122120\312\2632\363\240\233\2351\0303\342\201\247257\"}sub{s:\"\"}}sub{i:2} Step #5: artifact_prefix='./'; Test unit written to ./oom-75fdf7b617d2e5b77a87832ad7b10798f765aee9 Step #5: Base64: RlVaWlRFU1R2MQpzdWJ7c3Vie3M6Ii3zoIC3PTE3MDE0MTE4MzQ2MDQ2OTIzMTczMTbzoIG/OTY1OTA2MDQxMzUxMjIxMjDKszLzoJudMRgz4oGnMjU3In1zdWJ7czoiIn19c3Vie2k6Mn0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4168 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3799344237 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564562076810, 0x56456226001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564562260020,0x5645640f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/75fdf7b617d2e5b77a87832ad7b10798f765aee9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5188 processed earlier; will process 5841 files now Step #5: ==150124== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564558b6b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56455f1d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56455f1b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56455f1b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564558b71d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564558ad2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564558acd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564558b63c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56455bb32f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56455bb32f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56455bb32f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56455bb32f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56455bb32f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56455bb32f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56455bb32f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56455bb32f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56455bb32f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56455bb32f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56455ddc7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56455aaf4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56455aaffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56455a8abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56455a8abc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56455a8ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56455a8ab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56455a8ab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56455a8ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56455f1b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56455f1be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56455f1a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56455f1d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3093d31082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564558acbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f, Step #5: \012__________________________________________________________________________________________________________ Step #5: artifact_prefix='./'; Test unit written to ./oom-4d23db2da4b4b8e62b0fed85c5b47a319d051fea Step #5: Base64: Cl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4169 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3799861096 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bdaea6f810, 0x55bdaec5901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bdaec59020,0x55bdb0af10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4d23db2da4b4b8e62b0fed85c5b47a319d051fea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5189 processed earlier; will process 5840 files now Step #5: ==150160== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bda55649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bdabbc9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bdabbac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bdabbac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bda556ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bda54cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bda54c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bda555cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bda852bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bda852bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bda852bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bda852bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bda852bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bda852bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bda852bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bda852bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bda852bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bda852bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bdaa7c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bda74edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bda74f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bda72a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bda72a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bda72a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bda72a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bda72a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bda72a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bdabbaeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bdabbb7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bdabb9f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bdabbca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feae33a8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bda54c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x20,0x1,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x7a,0x40,0x3a,0x2b, Step #5: / \001\000\010\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\010\000z@:+ Step #5: artifact_prefix='./'; Test unit written to ./oom-5cadd78fdc79e306843f02037ad9e65b34de9a92 Step #5: Base64: LyABAAgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACAB6QDor Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4170 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3800389151 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eda0efc810, 0x55eda10e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eda10e6020,0x55eda2f7e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5cadd78fdc79e306843f02037ad9e65b34de9a92' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5190 processed earlier; will process 5839 files now Step #5: #1 pulse cov: 3651 ft: 3652 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 4080 ft: 4290 exec/s: 0 rss: 175Mb Step #5: ==150196== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed979f19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed9e056898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed9e0395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed9e0394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed979f7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed97958b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed97953355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed979e9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed9a9b8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed9a9b8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed9a9b8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed9a9b8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed9a9b8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed9a9b8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed9a9b8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed9a9b8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed9a9b8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed9a9b8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed9cc4df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed9997ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed99985be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed99731c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed99731c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed99732738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed99731874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed99731874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed99731874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed9e03babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed9e044928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed9e02c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed9e057112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdbb0ece082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed97951b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0x6c,0x61,0x73,0x73,0xa,0x73,0x0,0x7e,0x7b,0x3b,0x7d,0x7b,0x7b,0x7d,0x7d,0x63,0x6c,0x61,0x73,0x73,0xa,0x73,0x0,0x7e,0x7b,0x3b,0x7d,0x7b,0x7b,0x7d,0x7d,0x7b,0x7b,0x7d,0x7d,0x7b,0x7b,0x7d,0x7d,0x3,0x23,0x7b,0x7b,0x7d,0x7d,0x7b,0x7b,0x7d,0x7d,0x3,0x0,0x0,0x63,0x6c,0x61,0x73,0x73,0xa,0x73,0x0,0x7e,0x7b,0x3b,0x7d,0x7b,0x7b,0x7d,0x7d,0x63,0x6c,0x61,0x96,0x73,0xa,0x73,0x0,0x7e,0x7b,0x3b,0x7d,0x7b,0x7b,0x7d,0x7d,0x7b,0x7b,0x7d,0x7d,0x7b,0x7b,0x7d,0x7d,0x3,0x23,0x0,0x7b,0x7b,0x7d,0x7d,0x7b,0x7b,0x7d,0x7d,0x3,0x0,0x0,0x0, Step #5: class\012s\000~{;}{{}}class\012s\000~{;}{{}}{{}}{{}}\003#{{}}{{}}\003\000\000class\012s\000~{;}{{}}cla\226s\012s\000~{;}{{}}{{}}{{}}\003#\000{{}}{{}}\003\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3d8a281d8b88ee2906bf1dc79d5c4620d1f5bdce Step #5: Base64: Y2xhc3MKcwB+ezt9e3t9fWNsYXNzCnMAfns7fXt7fX17e319e3t9fQMje3t9fXt7fX0DAABjbGFzcwpzAH57O317e319Y2xhlnMKcwB+ezt9e3t9fXt7fX17e319AyMAe3t9fXt7fX0DAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4171 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3800983669 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5619641f4810, 0x5619643de01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5619643de020,0x5619662760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3d8a281d8b88ee2906bf1dc79d5c4620d1f5bdce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5193 processed earlier; will process 5836 files now Step #5: ==150232== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56195ace99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56196134e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5619613315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5619613314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56195acefd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56195ac50b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56195ac4b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56195ace1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56195dcb0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56195dcb0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56195dcb0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56195dcb0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56195dcb0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56195dcb0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56195dcb0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56195dcb0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56195dcb0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56195dcb0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56195ff45f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56195cc72b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56195cc7dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56195ca29c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56195ca29c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56195ca2a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56195ca29874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56195ca29874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56195ca29874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561961333abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56196133c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561961324699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56196134f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdfb18d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56195ac49b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x3,0x32,0x0,0x0,0x0,0xa,0x4e,0x68,0x68,0x43,0x3,0x0,0x49,0x4c,0x3e,0x0,0x33,0x0,0x54,0x49,0x54,0x31,0x49,0x44,0x33,0x3,0x14,0x1,0x2f,0x0,0x0,0x67,0x54,0x49,0x54,0x30,0x0,0x0,0xd,0x0,0x0,0x0,0xa,0x4e,0x68,0x68,0xe,0xe,0x69,0x43,0x0,0xe,0x4e,0x68,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x43,0x3,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x7,0x0,0x0,0x2d,0x20,0x2d,0x7,0x20,0x2d,0x3a,0x3e,0x54,0x49,0x54,0x20,0x75,0x3a,0x20,0x30,0x0,0x0,0x0,0xe,0x4e,0x68,0x39,0x68,0x43,0x3,0x0,0x49,0x0,0x3a,0x1,0x0, Step #5: ID3\0032\000\000\000\012NhhC\003\000IL>\0003\000TIT1ID3\003\024\001/\000\000gTIT0\000\000\015\000\000\000\012Nhh\016\016iC\000\016Nhhttp://C\003\000\000\000\000\001\000\000\007\000\000- -\007 -:>TIT u: 0\000\000\000\016Nh9hC\003\000I\000:\001\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-45b070813a0396cf6297c1d6e215e43e98381492 Step #5: Base64: SUQzAzIAAAAKTmhoQwMASUw+ADMAVElUMUlEMwMUAS8AAGdUSVQwAAANAAAACk5oaA4OaUMADk5oaHR0cDovL0MDAAAAAAEAAAcAAC0gLQcgLTo+VElUIHU6IDAAAAAOTmg5aEMDAEkAOgEA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4172 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3801498041 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f570655810, 0x55f57083f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f57083f020,0x55f5726d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/45b070813a0396cf6297c1d6e215e43e98381492' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5194 processed earlier; will process 5835 files now Step #5: ==150268== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f56714a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f56d7af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f56d7925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f56d7924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f567150d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f5670b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f5670ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f567142c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f56a111f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f56a111f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f56a111f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f56a111f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f56a111f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f56a111f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f56a111f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f56a111f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f56a111f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f56a111f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f56c3a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f5690d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f5690debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f568e8ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f568e8ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f568e8b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f568e8a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f568e8a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f568e8a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f56d794abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f56d79d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f56d785699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f56d7b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3487284082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f5670aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7a,0x7b,0x22,0x72,0x65,0x73,0x6f,0x75,0x72,0x63,0x65,0x4d,0x65,0x74,0x72,0x69,0x63,0x73,0x22,0x5b,0x5b,0x4e,0x7b,0x22,0x22,0x73,0x63,0x6f,0x70,0x65,0x5f,0x6d,0x65,0x74,0x72,0x69,0x63,0x73,0x22,0x5b,0x5b,0x4e,0x7b,0x22,0x22,0x6d,0x65,0x74,0x72,0x69,0x63,0x73,0x22,0x5b,0x5b,0x4e,0x7b,0x22,0x22,0x65,0x78,0x70,0x6f,0x6e,0x65,0x6e,0x74,0x69,0x61,0x6c,0x48,0x69,0x73,0x74,0x6f,0x67,0x72,0x61,0x6d,0x22,0x2c,0x7b,0x22,0x22,0x64,0x60,0x72,0x61,0x5f,0x70,0x6f,0x69,0x6e,0x60,0x72,0x22,0x2c,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x4d,0x5b,0x5b,0x6e, Step #5: z{\"resourceMetrics\"[[N{\"\"scope_metrics\"[[N{\"\"metrics\"[[N{\"\"exponentialHistogram\",{\"\"d`ra_poin`r\",[[[[[[[M[[n Step #5: artifact_prefix='./'; Test unit written to ./oom-cd62045225df1f2d558c9830e447d8fbb3408d27 Step #5: Base64: ensicmVzb3VyY2VNZXRyaWNzIltbTnsiInNjb3BlX21ldHJpY3MiW1tOeyIibWV0cmljcyJbW057IiJleHBvbmVudGlhbEhpc3RvZ3JhbSIseyIiZGByYV9wb2luYHIiLFtbW1tbW1tNW1tu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4173 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3802136149 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5564e0be3810, 0x5564e0dcd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564e0dcd020,0x5564e2c650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd62045225df1f2d558c9830e447d8fbb3408d27' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5195 processed earlier; will process 5834 files now Step #5: #1 pulse cov: 3767 ft: 3768 exec/s: 0 rss: 175Mb Step #5: ==150304== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5564d76d89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564ddd3d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564ddd205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564ddd204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564d76ded42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5564d763fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5564d763a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564d76d0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564da69ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564da69ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564da69ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564da69ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564da69ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564da69ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564da69ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564da69ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564da69ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564da69ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5564dc934f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5564d9661b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5564d966cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5564d9418c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5564d9418c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5564d9419738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5564d9418874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5564d9418874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5564d9418874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564ddd22abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564ddd2b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564ddd13699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564ddd3e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f52fc40f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5564d7638b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x6c,0x69,0x6e,0x65,0x61,0x72,0x47,0x72,0x61,0x64,0x69,0x65,0x6e,0x74,0x3e,0x3c,0x73,0x74,0x6f,0x70,0x3e,0x3c,0x73,0x74,0x6f,0x70,0x3e,0x3c,0x73,0x74,0x6f,0x70,0x3e,0x3c,0x73,0x74,0x6f,0x72,0x61,0x64,0x69,0x65,0x6e,0x74,0x3e,0x3c,0x6c,0x69,0x6e,0x65,0x61,0x72,0x47,0x72,0x61,0x64,0x69,0x65,0x6c,0x69,0x6e,0x65,0x61,0x72,0x47,0x72,0x61,0x64,0x69,0x65,0x6e,0x74,0x3e,0x3c,0x73,0x74,0x6f,0x70,0x3e,0x46,0x7b,0x66,0x6f,0x6e,0x74,0x2d,0x66,0x62,0x6d,0x69,0x3c,0x73,0x74,0x6f,0x70,0x3e,0x3c,0x73,0x74,0x6f,0x70,0x3e, Step #5: <svg><linearGradient><stop><stop><stop><storadient><linearGradielinearGradient><stop>F{font-fbmi<stop><stop> Step #5: artifact_prefix='./'; Test unit written to ./oom-6fa3919c284dc7dd989b8949b9bb0efa142b4010 Step #5: Base64: PHN2Zz48bGluZWFyR3JhZGllbnQ+PHN0b3A+PHN0b3A+PHN0b3A+PHN0b3JhZGllbnQ+PGxpbmVhckdyYWRpZWxpbmVhckdyYWRpZW50PjxzdG9wPkZ7Zm9udC1mYm1pPHN0b3A+PHN0b3A+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4174 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3802677924 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d3266d810, 0x556d3285701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d32857020,0x556d346ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6fa3919c284dc7dd989b8949b9bb0efa142b4010' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5197 processed earlier; will process 5832 files now Step #5: ==150340== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556d291629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d2f7c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d2f7aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d2f7aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d29168d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d290c9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d290c4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d2915ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d2c129f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d2c129f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d2c129f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d2c129f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d2c129f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d2c129f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d2c129f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d2c129f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d2c129f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d2c129f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d2e3bef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d2b0ebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d2b0f6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d2aea2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d2aea2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d2aea3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d2aea2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d2aea2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d2aea2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d2f7acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d2f7b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d2f79d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d2f7c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3895a7f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d290c2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x73,0x3a,0xef,0xb7,0xbc,0x33,0x32,0x35,0x39,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0x33,0x36,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x28,0xef,0xb7,0xb7,0xef,0xb7,0xb7,0xef,0xb7,0xb7, Step #5: \016ws:\357\267\2743259\357\267\267\357\267\26736\357\267\267\357\267\267\357\267\267\357\267\267\357\267\267\357\267\267\357\267\267\357\267\267\357\267\267\357\267\267\357\267\267((((((((\357\267\267\357\267\267\357\267\267\357\267\267\357\267\267\357\267\267(((((((((((((((((((((\357\267\267\357\267\267\357\267\267 Step #5: artifact_prefix='./'; Test unit written to ./oom-16e435adaddc5ccd569e7702b087d0a73b2d34de Step #5: Base64: DndzOu+3vDMyNTnvt7fvt7czNu+3t++3t++3t++3t++3t++3t++3t++3t++3t++3t++3tygoKCgoKCgo77e377e377e377e377e377e3KCgoKCgoKCgoKCgoKCgoKCgoKCgo77e377e377e3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4175 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3803184945 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b1c0d5b810, 0x55b1c0f4501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b1c0f45020,0x55b1c2ddd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16e435adaddc5ccd569e7702b087d0a73b2d34de' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5198 processed earlier; will process 5831 files now Step #5: ==150376== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b1b78509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b1bdeb5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1bde985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1bde984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b1b7856d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b1b77b7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b1b77b2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b1b7848c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b1ba817f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b1ba817f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b1ba817f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b1ba817f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b1ba817f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b1ba817f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b1ba817f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b1ba817f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b1ba817f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b1ba817f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b1bcaacf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b1b97d9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b1b97e4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b1b9590c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b1b9590c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b1b9591738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b1b9590874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b1b9590874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b1b9590874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b1bde9aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b1bdea3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b1bde8b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b1bdeb6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8f8bbe4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b1b77b0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x0,0x6,0x73,0x6b,0x69,0x70,0x47,0x45,0x4f,0x0,0x0,0x22,0x22,0x22,0x22,0x20,0x3,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0xf3,0xa0,0x81,0xa6,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22, Step #5: ID3\002\000\006skipGEO\000\000\"\"\"\" \003\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\363\240\201\246\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-6b1aa78292b58812a1779f7dad04c09ab20cbf7c Step #5: Base64: SUQzAgAGc2tpcEdFTwAAIiIiIiADIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIi86CBpiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4176 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3803693958 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a079907810, 0x55a079af101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a079af1020,0x55a07b9890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b1aa78292b58812a1779f7dad04c09ab20cbf7c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5199 processed earlier; will process 5830 files now Step #5: #1 pulse cov: 3437 ft: 3438 exec/s: 0 rss: 175Mb Step #5: ==150412== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0703fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a076a61898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a076a445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a076a444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a070402d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a070363b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a07035e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0703f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0733c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0733c3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0733c3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0733c3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0733c3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0733c3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0733c3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0733c3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0733c3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0733c3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a075658f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a072385b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a072390be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a07213cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a07213cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a07213d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a07213c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a07213c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a07213c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a076a46abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a076a4f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a076a37699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a076a62112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe316789082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a07035cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x45,0x27,0x28,0x32,0x5c,0xed,0x82,0xb9,0xed,0x82,0xb9,0xa,0xed,0x82,0xb9,0x20,0x2d,0xa,0x32,0xa,0xed,0x82,0xb9,0x20,0x2d,0xa,0x32,0x5c,0xed,0x82,0xb9,0xed,0x82,0xb9,0xa,0x54,0x5c,0x13,0xed,0x82,0xb9,0xed,0x82,0xb9,0xa,0xed,0x82,0xb9,0x6b,0x20,0xa,0x2d,0xa,0x2d,0x10,0x32,0x5c,0x20,0x31,0x5c,0xed,0x82,0xb9,0xed,0x82,0xb9,0x20,0x2d,0x32,0x5c,0xed,0x8a,0xb9,0xed,0x82,0xb9,0xa,0xed,0x82,0xb9,0x20,0x2d,0xa,0x32,0x5c,0xed,0x82,0xb9,0xed,0x82,0xb9,0xa,0xed,0xff,0xa,0x82,0xb9,0x20,0x2d,0xa,0xed,0x82,0xb9,0x20,0x2d,0x2,0x2d,0x27, Step #5: E'(2\\\355\202\271\355\202\271\012\355\202\271 -\0122\012\355\202\271 -\0122\\\355\202\271\355\202\271\012T\\\023\355\202\271\355\202\271\012\355\202\271k \012-\012-\0202\\ 1\\\355\202\271\355\202\271 -2\\\355\212\271\355\202\271\012\355\202\271 -\0122\\\355\202\271\355\202\271\012\355\377\012\202\271 -\012\355\202\271 -\002-' Step #5: artifact_prefix='./'; Test unit written to ./oom-28b40c81f74202bab8156c71a8e15fa43d91b7ae Step #5: Base64: RScoMlztgrntgrkK7YK5IC0KMgrtgrkgLQoyXO2Cue2CuQpUXBPtgrntgrkK7YK5ayAKLQotEDJcIDFc7YK57YK5IC0yXO2Kue2CuQrtgrkgLQoyXO2Cue2CuQrt/wqCuSAtCu2CuSAtAi0n Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4177 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3804244861 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1f1e7d810, 0x55a1f206701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1f2067020,0x55a1f3eff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/28b40c81f74202bab8156c71a8e15fa43d91b7ae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5201 processed earlier; will process 5828 files now Step #5: #1 pulse cov: 3755 ft: 3756 exec/s: 0 rss: 174Mb Step #5: ==150448== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1e89729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1eefd7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1eefba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1eefba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1e8978d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1e88d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1e88d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1e896ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1eb939f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1eb939f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1eb939f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1eb939f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1eb939f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1eb939f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1eb939f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1eb939f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1eb939f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1eb939f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1edbcef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1ea8fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1ea906be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1ea6b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1ea6b2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1ea6b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1ea6b2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1ea6b2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1ea6b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a1eefbcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a1eefc5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1eefad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1eefd8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f33152e2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1e88d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x47,0xd6,0xbf,0x27,0x27,0x27,0x2f,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0xd6,0xbf,0x27,0x27,0x27,0x2f,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x29,0x27,0x47,0xd6,0xbf,0x27,0x27,0xbf,0x27,0x27,0x27,0x2f,0x29,0x29,0x47,0xd6,0xbf,0x27,0x27,0x27,0x2f,0x29,0x27, Step #5: BG\326\277'''/888888888888888888888888888888888888\326\277'''/88888888888888888888888888888888888)'G\326\277''\277'''/))G\326\277'''/)' Step #5: artifact_prefix='./'; Test unit written to ./oom-b9f5b8bb75cae260fdf62126bca2f888a668296d Step #5: Base64: QkfWvycnJy84ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODjWvycnJy84ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4OCknR9a/Jye/JycnLykpR9a/JycnLykn Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4178 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3804794847 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560ea26e2810, 0x560ea28cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560ea28cc020,0x560ea47640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b9f5b8bb75cae260fdf62126bca2f888a668296d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5203 processed earlier; will process 5826 files now Step #5: ==150484== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560e991d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560e9f83c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560e9f81f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560e9f81f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560e991ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560e9913eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560e99139355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560e991cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560e9c19ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560e9c19ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560e9c19ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560e9c19ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560e9c19ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560e9c19ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560e9c19ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560e9c19ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560e9c19ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560e9c19ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560e9e433f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560e9b160b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560e9b16bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560e9af17c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560e9af17c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560e9af18738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560e9af17874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560e9af17874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560e9af17874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560e9f821abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560e9f82a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560e9f812699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560e9f83d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e293ec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560e99137b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x36,0x3a,0x5b,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x7b,0x7d,0x2c,0x5d,0x7d,0x28, Step #5: $3::{$6:[{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},]}( Step #5: artifact_prefix='./'; Test unit written to ./oom-275d9795f90c1d36ed688875863dcc72f671bae0 Step #5: Base64: JDM6OnskNjpbe30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30se30sXX0o Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4179 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3805304355 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e0fb36a810, 0x55e0fb55401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e0fb554020,0x55e0fd3ec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/275d9795f90c1d36ed688875863dcc72f671bae0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5204 processed earlier; will process 5825 files now Step #5: ==150520== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e0f1e5f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e0f84c4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e0f84a75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e0f84a74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e0f1e65d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e0f1dc6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e0f1dc1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e0f1e57c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e0f4e26f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e0f4e26f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e0f4e26f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e0f4e26f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e0f4e26f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e0f4e26f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e0f4e26f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e0f4e26f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e0f4e26f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e0f4e26f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e0f70bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e0f3de8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e0f3df3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e0f3b9fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e0f3b9fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e0f3ba0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e0f3b9f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e0f3b9f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e0f3b9f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e0f84a9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e0f84b2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e0f849a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e0f84c5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f86da65e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e0f1dbfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3d,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x0,0x5d,0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x24,0x5b,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x0,0x5d,0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0xa4,0x5b, Step #5: $:::::::::::::::::::::::::::::::::::::::::::::::::::::::::=:::::::::::\000]/\000\000\000\000\000\000\000\000\001$[::::::::::\000]/\000\000\000\000\000\000\000\000\001\244[ Step #5: artifact_prefix='./'; Test unit written to ./oom-e56911b345ae555bfae7f67aa73efe6391cf356f Step #5: Base64: JDo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Oj06Ojo6Ojo6Ojo6OgBdLwAAAAAAAAAAASRbOjo6Ojo6Ojo6OgBdLwAAAAAAAAAAAaRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4180 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3805820925 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55df2d07c810, 0x55df2d26601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55df2d266020,0x55df2f0fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e56911b345ae555bfae7f67aa73efe6391cf356f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5205 processed earlier; will process 5824 files now Step #5: ==150556== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55df23b719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55df2a1d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55df2a1b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55df2a1b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55df23b77d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55df23ad8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55df23ad3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55df23b69c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55df26b38f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55df26b38f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55df26b38f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55df26b38f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55df26b38f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55df26b38f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55df26b38f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55df26b38f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55df26b38f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55df26b38f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55df28dcdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55df25afab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55df25b05be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55df258b1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55df258b1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55df258b2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55df258b1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55df258b1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55df258b1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55df2a1bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55df2a1c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55df2a1ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55df2a1d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b39f22082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55df23ad1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x4b,0x60,0x20,0x2d,0x67,0x6c,0x79,0x66,0x45,0x47,0x4b,0x60,0x24,0x24,0x24,0x1b,0x24,0x24,0x24,0x24,0x24,0x27,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x34,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x20,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x73,0x20,0x3c,0x3c,0xa,0x20,0x24,0x24,0x24,0x24,0x20,0x2d,0x0,0x0,0x0,0x87,0x90,0x94,0x70,0x70,0x70,0x2d,0x2a,0x64,0x46,0xa,0x64,0xa,0x3f, Step #5: s-----BEGK` -glyfEGK`$$$\033$$$$$'$$$$$$$$$4$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$s <<\012 $$$$ -\000\000\000\207\220\224ppp-*dF\012d\012? Step #5: artifact_prefix='./'; Test unit written to ./oom-110ab5c20ccf230285d5fe773c1f232db9ac0035 Step #5: Base64: cy0tLS0tQkVHS2AgLWdseWZFR0tgJCQkGyQkJCQkJyQkJCQkJCQkJDQkJCQkJCQkJCQkJCQkJCQgJCQkJCQkJCQkJCQkJCQkJCQkJCQkJHMgPDwKICQkJCQgLQAAAIeQlHBwcC0qZEYKZAo/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4181 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3806468026 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55690b0fc810, 0x55690b2e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55690b2e6020,0x55690d17e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/110ab5c20ccf230285d5fe773c1f232db9ac0035' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5206 processed earlier; will process 5823 files now Step #5: ==150592== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556901bf19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556908256898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5569082395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5569082394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556901bf7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556901b58b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556901b53355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556901be9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556904bb8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556904bb8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556904bb8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556904bb8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556904bb8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556904bb8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556904bb8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556904bb8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556904bb8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556904bb8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556906e4df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556903b7ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556903b85be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556903931c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556903931c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556903932738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556903931874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556903931874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556903931874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55690823babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556908244928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55690822c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556908257112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0cef3d6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556901b51b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x74,0x65,0x73,0x74,0x41,0x6c,0x6c,0x54,0x79,0x70,0x65,0x73,0x22,0x3a,0x7b,0x22,0x6f,0x6e,0x65,0x6f,0x66,0x55,0x69,0x6e,0x74,0x36,0x34,0x22,0x3a,0x22,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe2,0x88,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0x22, Step #5: {\"testAllTypes\":{\"oneofUint64\":\"\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\342\210\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\" Step #5: artifact_prefix='./'; Test unit written to ./oom-9abecaebd8d46dd9b2e1e7e9770193592d35b0f1 Step #5: Base64: eyJ0ZXN0QWxsVHlwZXMiOnsib25lb2ZVaW50NjQiOiLjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDiiIDjgIDjgIDjgIDjgIDjgIDjgIAi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4182 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3806972120 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565178d62810, 0x565178f4c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565178f4c020,0x56517ade40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9abecaebd8d46dd9b2e1e7e9770193592d35b0f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5207 processed earlier; will process 5822 files now Step #5: #1 pulse cov: 16400 ft: 16401 exec/s: 0 rss: 205Mb Step #5: ==150628== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56516f8579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565175ebc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565175e9f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565175e9f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56516f85dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56516f7beb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56516f7b9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56516f84fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56517281ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56517281ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56517281ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56517281ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56517281ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56517281ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56517281ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56517281ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56517281ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56517281ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565174ab3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5651717e0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5651717ebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565171597c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565171597c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565171598738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565171597874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565171597874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565171597874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565175ea1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565175eaa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565175e92699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565175ebd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7931f63082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56516f7b7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x3,0x32,0x0,0x7,0x0,0x0,0x3e,0x54,0x49,0x54,0x33,0x0,0x0,0x0,0xa,0x4e,0x7a,0x68,0x43,0x3,0x0,0x49,0x4c,0x3e,0x0,0x33,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x20,0x47,0x49,0x4e,0x20,0x2d,0x33,0x3,0x0,0x3f,0x54,0x49,0x54,0x31,0x0,0x0,0x0,0xe,0x4e,0x68,0x68,0x43,0x3,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x7,0x0,0x0,0x3e,0x54,0x49,0x54,0x31,0x0,0x0,0x0,0xe,0x4e,0x68,0x39,0x68,0x43,0x3,0x0,0x49,0x0,0x1,0x0,0x43,0x3,0x0,0x2d,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x20,0x47, Step #5: ID3\0032\000\007\000\000>TIT3\000\000\000\012NzhC\003\000IL>\0003\000------\012- GIN -3\003\000?TIT1\000\000\000\016NhhC\003\000\000\000\000\001\000\000\007\000\000>TIT1\000\000\000\016Nh9hC\003\000I\000\001\000C\003\000-GIN ------\012- G Step #5: artifact_prefix='./'; Test unit written to ./oom-4042cd5373082905da39076f5f53f51bf7fef9b7 Step #5: Base64: SUQzAzIABwAAPlRJVDMAAAAKTnpoQwMASUw+ADMALS0tLS0tCi0gR0lOIC0zAwA/VElUMQAAAA5OaGhDAwAAAAABAAAHAAA+VElUMQAAAA5OaDloQwMASQABAEMDAC1HSU4gLS0tLS0tCi0gRw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4183 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3807717029 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560df5208810, 0x560df53f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560df53f2020,0x560df728a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4042cd5373082905da39076f5f53f51bf7fef9b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5209 processed earlier; will process 5820 files now Step #5: ==150664== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560debcfd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560df2362898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560df23455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560df23454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560debd03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560debc64b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560debc5f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560debcf5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560deecc4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560deecc4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560deecc4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560deecc4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560deecc4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560deecc4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560deecc4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560deecc4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560deecc4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560deecc4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560df0f59f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560dedc86b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560dedc91be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560deda3dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560deda3dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560deda3e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560deda3d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560deda3d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560deda3d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560df2347abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560df2350928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560df2338699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560df2363112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faec146a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560debc5db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x69,0x65,0x3a,0xa,0x6a,0x6f,0x62,0x73,0x3a,0xa,0x20,0x3a,0x7c,0x6f,0x3a,0xa,0x20,0x20,0x73,0x74,0x72,0x61,0x74,0x65,0x67,0x79,0x3a,0xa,0x20,0x20,0x20,0x6d,0x61,0x74,0x72,0x69,0x78,0x3a,0xa,0x20,0x20,0x20,0x20,0x69,0x6e,0x63,0x6c,0x75,0x64,0x65,0x3a,0x20,0xa,0x20,0x20,0x20,0xa,0x20,0x20,0x20,0x20,0x2d,0x20,0x20,0xe2,0x80,0xae,0x9,0xa,0x20,0x20,0x20,0x20,0x2d,0x20,0xe2,0x80,0xae,0x9,0xa,0x20,0x20,0x20,0x20,0x2d,0x20,0x20,0xe2,0xb4,0x80,0x9,0xa,0x20,0x20,0x20,0x20,0x2d,0x20,0x20,0xe2,0xb5,0xaf,0x9,0xa,0xa,0x20, Step #5: \000\000\000ie:\012jobs:\012 :|o:\012 strategy:\012 matrix:\012 include: \012 \012 - \342\200\256\011\012 - \342\200\256\011\012 - \342\264\200\011\012 - \342\265\257\011\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-1133171d50b7b5e5a5436f6d365884eb7a78b9dd Step #5: Base64: AAAAaWU6CmpvYnM6CiA6fG86CiAgc3RyYXRlZ3k6CiAgIG1hdHJpeDoKICAgIGluY2x1ZGU6IAogICAKICAgIC0gIOKArgkKICAgIC0g4oCuCQogICAgLSAg4rSACQogICAgLSAg4rWvCQoKIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4184 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3808241156 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5629df20b810, 0x5629df3f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5629df3f5020,0x5629e128d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1133171d50b7b5e5a5436f6d365884eb7a78b9dd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5210 processed earlier; will process 5819 files now Step #5: ==150700== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5629d5d009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5629dc365898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5629dc3485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5629dc3484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5629d5d06d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629d5c67b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629d5c62355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5629d5cf8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5629d8cc7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5629d8cc7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5629d8cc7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5629d8cc7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5629d8cc7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5629d8cc7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5629d8cc7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5629d8cc7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5629d8cc7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5629d8cc7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5629daf5cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629d7c89b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629d7c94be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629d7a40c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629d7a40c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629d7a41738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629d7a40874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629d7a40874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629d7a40874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5629dc34aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5629dc353928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5629dc33b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5629dc366112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f79a9073082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629d5c60b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0xf3,0xa0,0x81,0xad,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0xa,0x3f,0x20,0x69,0x2,0xa,0x72,0x3d,0x73,0x65,0x66,0x0,0x0,0x3d,0x3d,0xa,0x2b,0x3d,0xa,0x3d,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x5b,0x0,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2d,0x2d,0xa,0x44,0x41,0x6e,0x4d,0xcc,0x92,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xff, Step #5: \005----\363\240\201\255-BEGIN =\012? i\002\012r=sef\000\000==\012+=\012==\012D\012=\012=\012=\012=\012=\012=\012=\012==\012\012=\012=\012=\012=\012=[\000----\000\000\000\000\000\000\000\000\000\000\000\000\000\012--\012DAnM\314\222skip_cl\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-d05cc448c7358548787de4539f91aee3115f0b96 Step #5: Base64: BS0tLS3zoIGtLUJFR0lOID0KPyBpAgpyPXNlZgAAPT0KKz0KPT0KRAo9Cj0KPQo9Cj0KPQo9Cj09Cgo9Cj0KPQo9Cj1bAC0tLS0AAAAAAAAAAAAAAAAACi0tCkRBbk3MknNraXBfY2wKfAAQ/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4185 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3808757163 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55acbf800810, 0x55acbf9ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55acbf9ea020,0x55acc18820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d05cc448c7358548787de4539f91aee3115f0b96' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5211 processed earlier; will process 5818 files now Step #5: #1 pulse cov: 12003 ft: 12004 exec/s: 0 rss: 194Mb Step #5: #2 pulse cov: 12654 ft: 13520 exec/s: 0 rss: 196Mb Step #5: ==150736== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55acb62f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55acbc95a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55acbc93d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55acbc93d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55acb62fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55acb625cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55acb6257355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55acb62edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55acb92bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55acb92bcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55acb92bcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55acb92bcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55acb92bcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55acb92bcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55acb92bcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55acb92bcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55acb92bcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55acb92bcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55acbb551f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55acb827eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55acb8289be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55acb8035c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55acb8035c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55acb8036738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55acb8035874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55acb8035874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55acb8035874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55acbc93fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55acbc948928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55acbc930699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55acbc95b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fad62795082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55acb6255b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x97,0xa5,0xa9,0xd,0x69,0x6e,0xd,0xf0,0x97,0xa5,0xa9,0xd,0x69,0x6e,0xc,0xf0,0x97,0x97,0xb5,0xf0,0x97,0xa5,0xa9,0xd,0x69,0x6e,0xc,0xf0,0x97,0x97,0xb5,0xf0,0x97,0xa5,0xa9,0xd,0x69,0x6e,0xc,0xf0,0x97,0xb5,0xfe,0xd,0x69,0x6e,0xd,0xf0,0x97,0xa5,0xa9,0xd,0x69,0x6e,0xc,0xf0,0x97,0x97,0xb5,0xf0,0x97,0xa5,0xa9,0xd,0x69,0x6e,0xc,0xf0,0x97,0x97,0xb5,0xf0,0x97,0xa5,0xa9,0xd,0x69,0x6e,0xc,0xf0,0x97,0x67,0x2b,0xf0,0x97,0x6e,0xd,0xf0,0x97,0xb5,0x6e,0xf0,0x97,0x69,0x67,0x2b,0xf0,0x97,0x6e,0xd,0xf0,0x97,0xb5,0x6e,0xf0,0x97,0x69,0x6e, Step #5: \360\227\245\251\015in\015\360\227\245\251\015in\014\360\227\227\265\360\227\245\251\015in\014\360\227\227\265\360\227\245\251\015in\014\360\227\265\376\015in\015\360\227\245\251\015in\014\360\227\227\265\360\227\245\251\015in\014\360\227\227\265\360\227\245\251\015in\014\360\227g+\360\227n\015\360\227\265n\360\227ig+\360\227n\015\360\227\265n\360\227in Step #5: artifact_prefix='./'; Test unit written to ./oom-f35e15df3deeb7b3321ca7dc4cb3d7796fc073d9 Step #5: Base64: 8JelqQ1pbg3wl6WpDWluDPCXl7Xwl6WpDWluDPCXl7Xwl6WpDWluDPCXtf4NaW4N8JelqQ1pbgzwl5e18JelqQ1pbgzwl5e18JelqQ1pbgzwl2cr8JduDfCXtW7wl2lnK/CXbg3wl7Vu8Jdpbg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4186 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3809409382 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571c98b1810, 0x5571c9a9b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571c9a9b020,0x5571cb9330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f35e15df3deeb7b3321ca7dc4cb3d7796fc073d9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5215 processed earlier; will process 5814 files now Step #5: #1 pulse cov: 11209 ft: 11210 exec/s: 0 rss: 196Mb Step #5: #2 pulse cov: 11864 ft: 12682 exec/s: 0 rss: 198Mb Step #5: ==150772== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571c03a69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571c6a0b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571c69ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571c69ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571c03acd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571c030db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571c0308355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571c039ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571c336df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571c336df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571c336df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571c336df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571c336df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571c336df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571c336df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571c336df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571c336df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571c336df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571c5602f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571c232fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571c233abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571c20e6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571c20e6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571c20e7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571c20e6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571c20e6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571c20e6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571c69f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571c69f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571c69e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571c6a0c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa4f838a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571c0306b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x47,0x4e,0x20,0x42,0x49,0x45,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x41,0x64,0x41,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x41,0x54,0x54,0x54,0x54,0x41,0x41,0x41,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x4,0x0,0x54,0x70,0x2f,0x2a,0x2a,0x70,0x2a,0x70,0x2a,0x2a,0x70,0x2d,0x2d,0x2d,0x45,0x61,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x64,0x65,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0xa,0x3f,0x2d,0x2d,0x2d, Step #5: s-----GN BIE-----\012AdAppppppppppppppppppppppppppppATTTTAAATTTTTTT\004\000Tp/**p*p**p---Eapppppppppde\012-----END --\012?--- Step #5: artifact_prefix='./'; Test unit written to ./oom-c16bf2aeeb091cdccce916d520090ed211b80a81 Step #5: Base64: cy0tLS0tR04gQklFLS0tLS0KQWRBcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcEFUVFRUQUFBVFRUVFRUVAQAVHAvKipwKnAqKnAtLS1FYXBwcHBwcHBwcGRlCi0tLS0tRU5EIC0tCj8tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4187 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3810023328 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c02241810, 0x561c0242b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c0242b020,0x561c042c30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c16bf2aeeb091cdccce916d520090ed211b80a81' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5218 processed earlier; will process 5811 files now Step #5: #1 pulse cov: 3769 ft: 3770 exec/s: 0 rss: 175Mb Step #5: ==150808== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561bf8d369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561bff39b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561bff37e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561bff37e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561bf8d3cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561bf8c9db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561bf8c98355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561bf8d2ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561bfbcfdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561bfbcfdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561bfbcfdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561bfbcfdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561bfbcfdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561bfbcfdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561bfbcfdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561bfbcfdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561bfbcfdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561bfbcfdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561bfdf92f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561bfacbfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561bfaccabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561bfaa76c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561bfaa76c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561bfaa77738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561bfaa76874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561bfaa76874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561bfaa76874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561bff380abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561bff389928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561bff371699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561bff39c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2cc023c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561bf8c96b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x1,0x4,0x4,0x0,0x0,0x0,0x0,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x1,0x14,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x29,0x0,0x4,0x4,0x4,0x4,0x4,0x4,0x4,0xd8,0xbd,0x2a, Step #5: *\001\004\004\000\000\000\000\000=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\001\024=\012=\012=\012=\012=\012=\012=)\000\004\004\004\004\004\004\004\330\275* Step #5: artifact_prefix='./'; Test unit written to ./oom-639fe842b5e9525ae285d6ee1a2c6e9f82238be3 Step #5: Base64: KgEEBAAAAAAAPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoBFD0KPQo9Cj0KPQo9Cj0pAAQEBAQEBATYvSo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4188 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3810590297 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5635a4639810, 0x5635a482301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5635a4823020,0x5635a66bb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/639fe842b5e9525ae285d6ee1a2c6e9f82238be3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5220 processed earlier; will process 5809 files now Step #5: #1 pulse cov: 3710 ft: 3711 exec/s: 0 rss: 176Mb Step #5: ==150844== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56359b12e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5635a1793898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5635a17765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5635a17764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56359b134d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56359b095b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56359b090355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56359b126c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56359e0f5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56359e0f5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56359e0f5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56359e0f5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56359e0f5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56359e0f5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56359e0f5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56359e0f5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56359e0f5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56359e0f5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5635a038af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56359d0b7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56359d0c2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56359ce6ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56359ce6ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56359ce6f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56359ce6e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56359ce6e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56359ce6e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5635a1778abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5635a1781928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5635a1769699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5635a1794112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f412b558082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56359b08eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x2d,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x3d,0x3c,0x2d,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x24,0x27,0x2d,0x24,0x2d,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x3d,0x3c,0x2d,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x24,0x27,0x2d, Step #5: $-9223372036854775551-=<-1''/''''/'''exp'N'2-\007='''''$'-$-9223372036854775551-=<-1''/''''/'''exp'N'2-\007='''''$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-c31eab119824d191b97ea3f9d23c5c75e26cec47 Step #5: Base64: JC05MjIzMzcyMDM2ODU0Nzc1NTUxLT08LTEnJy8nJycnLycnJ2V4cCdOJzItBz0nJycnJyQnLSQtOTIyMzM3MjAzNjg1NDc3NTU1MS09PC0xJycvJycnJy8nJydleHAnTicyLQc9JycnJyckJy0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4189 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3811153172 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556748a4e810, 0x556748c3801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556748c38020,0x55674aad00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c31eab119824d191b97ea3f9d23c5c75e26cec47' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5222 processed earlier; will process 5807 files now Step #5: ==150880== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55673f5439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556745ba8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556745b8b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556745b8b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55673f549d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55673f4aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55673f4a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55673f53bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55674250af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55674250af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55674250af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55674250af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55674250af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55674250af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55674250af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55674250af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55674250af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55674250af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55674479ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5567414ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5567414d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556741283c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556741283c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556741284738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556741283874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556741283874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556741283874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556745b8dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556745b96928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556745b7e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556745ba9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f285f292082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55673f4a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x35,0x24,0x34,0x5c,0x37,0x37,0x5c,0x37,0x37,0x24,0x7b,0x38,0x7d,0x24,0x7f,0x32,0x7d,0x24,0x7b,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x1,0x0,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x25,0x4e,0x3f,0x3f,0x8,0x23,0x31,0x23,0x31,0x23,0x31,0x25,0x1,0x0,0x0,0x0,0x20,0x23,0x31,0x25,0x24,0x1,0x0,0x0,0x0,0x7b,0x37,0x36,0x5c,0x37,0x37,0x5c,0x37,0x0,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x0,0x86,0x37,0x37,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x7d,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x5c,0x33,0x38,0x5c,0x37,0x37,0x5c,0x37,0x33, Step #5: \\5$4\\77\\77${8}$\1772}${\001\000\000\000\000\000\000$\001\000${8}${8}%N??\010#1#1#1%\001\000\000\000 #1%$\001\000\000\000{76\\77\\7\0007\\77\\77\\\000\20677jjjjjj}jjjjjjjjjj\\38\\77\\73 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec89cdca04aaadf98283bfa895df4c50066dffad Step #5: Base64: XDUkNFw3N1w3NyR7OH0kfzJ9JHsBAAAAAAAAJAEAJHs4fSR7OH0lTj8/CCMxIzEjMSUBAAAAICMxJSQBAAAAezc2XDc3XDcAN1w3N1w3N1wAhjc3ampqampqfWpqampqampqampcMzhcNzdcNzM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4190 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3811672139 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555de0ab2810, 0x555de0c9c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555de0c9c020,0x555de2b340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec89cdca04aaadf98283bfa895df4c50066dffad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5223 processed earlier; will process 5806 files now Step #5: ==150916== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555dd75a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555dddc0c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555dddbef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555dddbef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555dd75add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555dd750eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555dd7509355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555dd759fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555dda56ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555dda56ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555dda56ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555dda56ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555dda56ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555dda56ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555dda56ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555dda56ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555dda56ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555dda56ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555ddc803f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555dd9530b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555dd953bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555dd92e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555dd92e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555dd92e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555dd92e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555dd92e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555dd92e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555dddbf1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555dddbfa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555dddbe2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555dddc0d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67a6ba3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555dd7507b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x72,0x7c,0x4f,0x3a,0x32,0x3a,0x22,0xdd,0x9e,0x22,0x3a,0x36,0x3a,0x7b,0x69,0x3a,0x30,0x3b,0x69,0x3a,0x31,0x3b,0x69,0x3a,0x34,0x3b,0x4f,0x3a,0x32,0x3a,0x22,0xdd,0x9e,0x22,0x3a,0x36,0x3a,0x7b,0x69,0x3a,0x34,0x3b,0x4f,0x3a,0x32,0x3a,0x22,0xdd,0x9e,0x22,0x3a,0x36,0x3a,0x7b,0x69,0x3a,0x30,0x3b,0x72,0x3a,0x34,0x3b,0x69,0x3a,0x34,0x30,0x3b,0x72,0x3a,0x34,0x3b,0x69,0x3a,0x30,0x3b,0x69,0x3a,0x31,0x3b,0x69,0x3a,0x31,0x3b,0x4f,0x3a,0x32,0x3a,0x22,0xd9,0x9e,0x22,0x3a,0x36,0x3a,0x7b,0x69,0x3a,0x34,0x3b,0x4f,0x3a,0x32,0x3a,0x22,0xdd,0x97,0x22,0x3a,0x36, Step #5: tr|O:2:\"\335\236\":6:{i:0;i:1;i:4;O:2:\"\335\236\":6:{i:4;O:2:\"\335\236\":6:{i:0;r:4;i:40;r:4;i:0;i:1;i:1;O:2:\"\331\236\":6:{i:4;O:2:\"\335\227\":6 Step #5: artifact_prefix='./'; Test unit written to ./oom-c5ac92a7816f280d57590cf9013f8870a9eed967 Step #5: Base64: dHJ8TzoyOiLdniI6Njp7aTowO2k6MTtpOjQ7TzoyOiLdniI6Njp7aTo0O086Mjoi3Z4iOjY6e2k6MDtyOjQ7aTo0MDtyOjQ7aTowO2k6MTtpOjE7TzoyOiLZniI6Njp7aTo0O086Mjoi3ZciOjY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4191 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3812178280 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652a7a94810, 0x5652a7c7e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652a7c7e020,0x5652a9b160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c5ac92a7816f280d57590cf9013f8870a9eed967' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5224 processed earlier; will process 5805 files now Step #5: #1 pulse cov: 11159 ft: 11160 exec/s: 0 rss: 198Mb Step #5: #2 pulse cov: 12191 ft: 13118 exec/s: 0 rss: 200Mb Step #5: ==150952== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56529e5899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652a4bee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652a4bd15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652a4bd14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56529e58fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56529e4f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56529e4eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56529e581c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5652a1550f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5652a1550f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5652a1550f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5652a1550f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5652a1550f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5652a1550f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5652a1550f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5652a1550f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5652a1550f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5652a1550f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652a37e5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5652a0512b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5652a051dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652a02c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652a02c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652a02ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652a02c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652a02c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652a02c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652a4bd3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652a4bdc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652a4bc4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652a4bef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe72b9c4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56529e4e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0xe1,0x82,0x87,0xe0,0xba,0x88,0xef,0x89,0xaa,0xe4,0x89,0xb1,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x88,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x99,0xaa,0xe4,0x89,0xaa,0xe4,0x89,0xaa,0xe4,0x8a,0xaa,0xe4,0xaa,0xb9,0x8f,0xdd, Step #5: \001\341\202\207\340\272\210\357\211\252\344\211\261\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\210\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\211\252\344\231\252\344\211\252\344\211\252\344\212\252\344\252\271\217\335 Step #5: artifact_prefix='./'; Test unit written to ./oom-4f73d12ac3f99db832dfd6d19fa954df45ac3765 Step #5: Base64: AeGCh+C6iO+JquSJseSJquSJquSJquSJquSJquSJquSJquSJquSIquSJquSJquSJquSJquSJquSJquSJquSJquSJquSJquSJquSJquSJquSJquSJquSJquSJquSJquSZquSJquSJquSKquSquY/d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4192 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3812848097 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5592f1bb9810, 0x5592f1da301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5592f1da3020,0x5592f3c3b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f73d12ac3f99db832dfd6d19fa954df45ac3765' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5228 processed earlier; will process 5801 files now Step #5: ==150988== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5592e86ae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5592eed13898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5592eecf65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5592eecf64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592e86b4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592e8615b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592e8610355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592e86a6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592eb675f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592eb675f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592eb675f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592eb675f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592eb675f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592eb675f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592eb675f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592eb675f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592eb675f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592eb675f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592ed90af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592ea637b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592ea642be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5592ea3eec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5592ea3eec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5592ea3ef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5592ea3ee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5592ea3ee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5592ea3ee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5592eecf8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5592eed01928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5592eece9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5592eed14112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b141db082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592e860eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x28,0x2d,0x2d,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x24,0x2d,0x28,0x2d,0x2d,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x24,0xa,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x26,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x2d,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x3a,0xa,0x2d,0x20,0x2d,0x2d,0x2d,0x2d,0x24,0x2d,0x28,0x2d,0x2d,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x24,0xa,0x3a,0xa,0x72, Step #5: s--(--N ----$-(--N ----$\012^^^^^^^^^&^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^-^^^^^^^^^^^^^^^^:\012- ----$-(--N ----$\012:\012r Step #5: artifact_prefix='./'; Test unit written to ./oom-abf384b905c346b0e07235537f3f0a47456f46e2 Step #5: Base64: cy0tKC0tTiAtLS0tJC0oLS1OIC0tLS0kCl5eXl5eXl5eXiZeXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXi1eXl5eXl5eXl5eXl5eXl5eOgotIC0tLS0kLSgtLU4gLS0tLSQKOgpy Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4193 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3813365819 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c4b181810, 0x559c4b36b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c4b36b020,0x559c4d2030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/abf384b905c346b0e07235537f3f0a47456f46e2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5229 processed earlier; will process 5800 files now Step #5: ==151024== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559c41c769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c482db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c482be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c482be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c41c7cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c41bddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c41bd8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c41c6ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c44c3df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c44c3df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c44c3df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c44c3df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c44c3df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c44c3df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c44c3df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c44c3df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c44c3df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c44c3df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c46ed2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c43bffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c43c0abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c439b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c439b6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c439b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c439b6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c439b6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c439b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c482c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c482c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c482b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c482dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12e6a97082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c41bd6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x61,0x61,0x60,0x2b,0x61,0x61,0x61,0x61,0x62,0x60,0x61,0x61,0x2a,0x61,0x60,0x60,0x61,0x61,0x33,0x61,0x61,0x62,0x61,0x61,0x66,0x61,0x60,0x6a,0x61,0x62,0x5f,0x61,0x22,0x61,0x61,0x5e,0x61,0x61,0x60,0x62,0x61,0xa3,0x66,0x61,0x60,0x21,0x61,0x62,0x61,0x61,0x71,0x61,0x61,0x62,0x61,0x61,0x60,0x61,0x61,0x60,0x61,0x61,0x20,0x61,0x61,0x61,0x61,0x61,0xb0,0x7,0x61,0xf6,0x62,0x61,0x21,0x61,0x61,0x54,0x60,0x61,0x61,0x41,0x61,0x61,0xb0,0x61,0x61,0x23,0x61,0x31,0x62,0x61,0x56,0x65,0x61,0x26,0x2b,0x1,0x61,0x26,0x61,0x3,0x61,0xc6,0x23,0x61,0x60,0xb0,0xbd,0xaf, Step #5: !aa`+aaaab`aa*a``aa3aabaafa`jab_a\"aa^aa`ba\243fa`!abaaqaabaa`aa`aa aaaaa\260\007a\366ba!aaT`aaAaa\260aa#a1baVea&+\001a&a\003a\306#a`\260\275\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-9eb27d91460e33f10950a43c8bacad03943d250a Step #5: Base64: IWFhYCthYWFhYmBhYSphYGBhYTNhYWJhYWZhYGphYl9hImFhXmFhYGJho2ZhYCFhYmFhcWFhYmFhYGFhYGFhIGFhYWFhsAdh9mJhIWFhVGBhYUFhYbBhYSNhMWJhVmVhJisBYSZhA2HGI2FgsL2v Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4194 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3813996174 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f3c4b2f810, 0x55f3c4d1901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f3c4d19020,0x55f3c6bb10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9eb27d91460e33f10950a43c8bacad03943d250a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5230 processed earlier; will process 5799 files now Step #5: ==151060== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f3bb6249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f3c1c89898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f3c1c6c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f3c1c6c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f3bb62ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f3bb58bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f3bb586355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f3bb61cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f3be5ebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f3be5ebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f3be5ebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f3be5ebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f3be5ebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f3be5ebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f3be5ebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f3be5ebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f3be5ebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f3be5ebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f3c0880f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f3bd5adb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f3bd5b8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f3bd364c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f3bd364c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f3bd365738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f3bd364874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f3bd364874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f3bd364874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f3c1c6eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f3c1c77928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f3c1c5f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f3c1c8a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f71fd886082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f3bb584b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3a,0x3e,0x26,0xcd,0xb1,0x26,0x26,0xcd,0xb1,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x3a,0x6d,0x61,0x78,0x26,0xcd,0xb1,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1,0x26,0xcd,0xb1, Step #5: <:>&\315\261&&\315\261\315\261&\315\261&\315\261&\315\261&\315\261&\315\261&\315\261&\315\261&\315\261&\315\261&\315\261&\315\261&&\315\261&\315\261:max&\315\261\261&\315\261&\315\261&\315\261&\315\261&\315\261\315\261&\315\261&\315\261&\315\261&\315\261&\315\261&\315\261&\315\261\261&\315\261&\315\261&\315\261&\315\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-60eabeccce30ecd30e5d08b0aee6094d8c3f5a6a Step #5: Base64: PDo+Js2xJibNsc2xJs2xJs2xJs2xJs2xJs2xJs2xJs2xJs2xJs2xJs2xJs2xJibNsSbNsTptYXgmzbGxJs2xJs2xJs2xJs2xJs2xzbEmzbEmzbEmzbEmzbEmzbEmzbEmzbGxJs2xJs2xJs2xJs2x Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4195 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3814504621 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e2a893a810, 0x55e2a8b2401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e2a8b24020,0x55e2aa9bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/60eabeccce30ecd30e5d08b0aee6094d8c3f5a6a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5231 processed earlier; will process 5798 files now Step #5: ==151096== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e29f42f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e2a5a94898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e2a5a775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e2a5a774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e29f435d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e29f396b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e29f391355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e29f427c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e2a23f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e2a23f6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e2a23f6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e2a23f6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e2a23f6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e2a23f6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e2a23f6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e2a23f6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e2a23f6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e2a23f6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e2a468bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e2a13b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e2a13c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e2a116fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e2a116fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e2a1170738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e2a116f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e2a116f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e2a116f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e2a5a79abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e2a5a82928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e2a5a6a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e2a5a95112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f49b7e89082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e29f38fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x90,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x87,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8e,0xcd,0x8f,0xcd,0x8e,0xcd,0x8f,0xcd,0x8f,0xa,0x6b,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcc,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8a,0xcd,0x8f, Step #5: 0\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\220\315\217\315\217\315\217\315\217\315\217\315\207\315\217\315\217\315\217\315\217\315\217\315\216\315\217\315\216\315\217\315\217\012k\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\314\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\212\315\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-ff3927bec02661f7303151908e1096ae34249633 Step #5: Base64: MM2PzY/Nj82PzY/Nj82PzY/Nj82PzZDNj82PzY/Nj82PzYfNj82PzY/Nj82PzY7Nj82OzY/NjwprzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzI/Nj82PzY/Nj82PzY/Nj82PzY/Nis2P Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4196 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3815013843 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b4f971a810, 0x55b4f990401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b4f9904020,0x55b4fb79c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ff3927bec02661f7303151908e1096ae34249633' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5232 processed earlier; will process 5797 files now Step #5: ==151132== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b4f020f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b4f6874898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b4f68575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b4f68574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b4f0215d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b4f0176b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b4f0171355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b4f0207c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b4f31d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b4f31d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b4f31d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b4f31d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b4f31d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b4f31d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b4f31d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b4f31d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b4f31d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b4f31d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b4f546bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b4f2198b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b4f21a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b4f1f4fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b4f1f4fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b4f1f50738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b4f1f4f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b4f1f4f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b4f1f4f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b4f6859abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b4f6862928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b4f684a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b4f6875112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b67819082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b4f016fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0x9,0x59,0x5b,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0x9,0x61,0x20,0x78,0x6d,0x6c,0x6e,0x73,0x3a,0x77,0x9,0x49,0x44,0x9,0x27,0xe7,0x95,0x8a,0x48,0x27,0x20,0x78,0x6d,0x6c,0x6e,0x73,0x3a,0x30,0x9,0x49,0x44,0x9,0x27,0xe7,0x95,0x8a,0x27,0x20,0x78,0x6d,0x6c,0x6e,0x73,0x9,0x49,0x44,0x9,0x27,0xe7,0x95,0x8a,0x27,0x3e,0x5d,0xa,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x33,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e, Step #5: <!DOCTYPE\011Y[<!ATTLIST\011a xmlns:w\011ID\011'\347\225\212H' xmlns:0\011ID\011'\347\225\212' xmlns\011ID\011'\347\225\212'>]\012><a><a><a><a>3<a><a><a><a><a><a><a> Step #5: artifact_prefix='./'; Test unit written to ./oom-20c7e9f3a81e5f9910566772b9be2b176b0513d3 Step #5: Base64: PCFET0NUWVBFCVlbPCFBVFRMSVNUCWEgeG1sbnM6dwlJRAkn55WKSCcgeG1sbnM6MAlJRAkn55WKJyB4bWxucwlJRAkn55WKJz5dCj48YT48YT48YT48YT4zPGE+PGE+PGE+PGE+PGE+PGE+PGE+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4197 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3815524408 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560013246810, 0x56001343001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560013430020,0x5600152c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/20c7e9f3a81e5f9910566772b9be2b176b0513d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5233 processed earlier; will process 5796 files now Step #5: #1 pulse cov: 13121 ft: 13122 exec/s: 0 rss: 195Mb Step #5: ==151168== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560009d3b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5600103a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5600103835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5600103834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560009d41d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560009ca2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560009c9d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560009d33c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56000cd02f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56000cd02f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56000cd02f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56000cd02f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56000cd02f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56000cd02f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56000cd02f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56000cd02f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56000cd02f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56000cd02f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56000ef97f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56000bcc4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56000bccfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56000ba7bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56000ba7bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56000ba7c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56000ba7b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56000ba7b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56000ba7b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560010385abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56001038e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560010376699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5600103a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7019ca9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560009c9bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x81,0x80, Step #5: \012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\201\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-df83f0f159daf3a55578e19551ae1df580a337ea Step #5: Base64: CgxiCgoI87yBgPSAgKEKDGIKCgjzvIGA9ICAoQoMYgoKCPO8gYD0gIChCgxiCgoI87yBgPSAgKEKDGIKCgjzvIGA9ICAoQoMYgoKCPO8gYD0gIChCgxiCgoI87yBgPSAgKEKDGIKCgjzvIGA9ICBgA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4198 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3816113006 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a03af2810, 0x558a03cdc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a03cdc020,0x558a05b740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/df83f0f159daf3a55578e19551ae1df580a337ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5235 processed earlier; will process 5794 files now Step #5: #1 pulse cov: 10881 ft: 10882 exec/s: 0 rss: 192Mb Step #5: ==151204== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5589fa5e79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a00c4c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a00c2f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a00c2f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5589fa5edd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5589fa54eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5589fa549355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5589fa5dfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5589fd5aef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5589fd5aef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5589fd5aef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5589fd5aef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5589fd5aef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5589fd5aef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5589fd5aef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5589fd5aef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5589fd5aef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5589fd5aef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589ff843f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5589fc570b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5589fc57bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5589fc327c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5589fc327c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5589fc328738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5589fc327874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5589fc327874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5589fc327874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a00c31abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a00c3a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a00c22699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a00c4d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1cfd72a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5589fa547b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x47,0x41,0xd6,0xaf,0x27,0x27,0x27,0x2f,0x0,0x0,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x47,0x41,0xd6,0xaf,0x27,0x27,0x27,0x2f,0x0,0x0,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x0,0x0,0x0,0x0,0x0,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x15,0x2f,0x29,0x81,0x0,0x27, Step #5: BGA\326\257'''/\000\000\022\022\022\022\022\022\022\022GA\326\257'''/\000\000\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\000\000\000\000\000\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\000\000\000\000\000\000\000'\025/)\201\000' Step #5: artifact_prefix='./'; Test unit written to ./oom-4b4f2b8f1e6e3e5bbfd1892b060d0b47c5aad1b6 Step #5: Base64: QkdB1q8nJycvAAASEhISEhISEkdB1q8nJycvAAASEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhIAAAAAABISEhISEhISEhISEhISEhISEhISEhISEhISEhIAAAAAAAAAJxUvKYEAJw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4199 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3816684774 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558d6663f810, 0x558d6682901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558d66829020,0x558d686c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4b4f2b8f1e6e3e5bbfd1892b060d0b47c5aad1b6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5237 processed earlier; will process 5792 files now Step #5: ==151240== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558d5d1349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558d63799898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558d6377c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558d6377c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558d5d13ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558d5d09bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558d5d096355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558d5d12cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558d600fbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558d600fbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558d600fbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558d600fbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558d600fbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558d600fbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558d600fbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558d600fbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558d600fbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558d600fbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558d62390f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558d5f0bdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558d5f0c8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558d5ee74c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558d5ee74c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558d5ee75738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558d5ee74874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558d5ee74874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558d5ee74874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558d6377eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558d63787928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558d6376f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558d6379a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa2964b2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558d5d094b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x27,0x28,0x0,0x60,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x54,0x58,0x59,0x45,0x15,0x0,0x27,0x17,0x54,0x0,0x9,0x0,0x0,0x0,0x0,0x0,0x0,0x59,0x45,0x33,0x4,0x3b,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x58,0x59,0x45,0x15,0x0,0x10,0x0,0x15,0x0,0x10, Step #5: ID3\004'(\000`\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000TXYE\025\000'\027T\000\011\000\000\000\000\000\000YE3\004;'\000\000`'\027TXYE\025\000\020\000\025\000\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-d3e105f64ff72dd42dd0f4323506e10da34fa14c Step #5: Base64: SUQzBCcoAGAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAFRYWUUVACcXVAAJAAAAAAAAWUUzBDsnAABgJxdUWFlFFQAQABUAEA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4200 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3817314304 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557dc75fe810, 0x557dc77e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557dc77e8020,0x557dc96800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d3e105f64ff72dd42dd0f4323506e10da34fa14c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5238 processed earlier; will process 5791 files now Step #5: #1 pulse cov: 11641 ft: 11642 exec/s: 0 rss: 192Mb Step #5: ==151276== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557dbe0f39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557dc4758898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557dc473b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557dc473b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557dbe0f9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557dbe05ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557dbe055355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557dbe0ebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557dc10baf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557dc10baf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557dc10baf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557dc10baf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557dc10baf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557dc10baf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557dc10baf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557dc10baf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557dc10baf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557dc10baf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557dc334ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557dc007cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557dc0087be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557dbfe33c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557dbfe33c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557dbfe34738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557dbfe33874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557dbfe33874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557dbfe33874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557dc473dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557dc4746928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557dc472e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557dc4759112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f770a4dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557dbe053b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x44,0x44,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x2d,0x24,0x2d,0x2d,0x2d,0x20,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x2d,0x4e,0x24,0xa,0x3d,0xff,0xff,0xf7,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x0,0xe7,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: xDD-----BEGI-$--- ]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]-N$\012=\377\377\367\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\000\347\000\000\000\000\000\000\000\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b329faa947bdc07e0539ed0666e6252178f785d3 Step #5: Base64: eERELS0tLS1CRUdJLSQtLS0gXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXS1OJAo9///3////////////////////AOcAAAAAAAAAAAAAAAAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4201 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3817897889 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aae861d810, 0x55aae880701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aae8807020,0x55aaea69f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b329faa947bdc07e0539ed0666e6252178f785d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5240 processed earlier; will process 5789 files now Step #5: #1 pulse cov: 4210 ft: 4211 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4496 ft: 5124 exec/s: 0 rss: 178Mb Step #5: ==151312== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aadf1129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aae5777898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aae575a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aae575a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aadf118d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aadf079b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aadf074355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aadf10ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aae20d9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aae20d9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aae20d9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aae20d9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aae20d9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aae20d9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aae20d9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aae20d9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aae20d9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aae20d9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aae436ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aae109bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aae10a6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aae0e52c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aae0e52c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aae0e53738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aae0e52874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aae0e52874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aae0e52874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aae575cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aae5765928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aae574d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aae5778112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f98471b2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aadf072b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x1,0x4,0x61,0x4d,0x0,0x2,0x47,0x45,0x4f,0x49,0x44,0x32,0x42,0x12,0x3f,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x32,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x30,0x11,0xf,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x38,0x30,0x37,0x11,0x2d,0x3a,0x24,0x5b,0x2d,0x3a,0xee,0xdc,0x73,0x74,0xcc,0x72,0x28,0x24,0x5b,0x53,0x0,0x0,0x0,0x40,0x56,0x43,0x4e,0x4d,0x0,0x3, Step #5: ID3\002\001\004aM\000\002GEOID2B\022?+\012+\012+\012+\012+\012+\012+\012+$\000\000/\000\000\000/\000\017\017\017\017\0171\017-2[&\021:\021-\017\017\017\017\0170\021\0179223372036854775807\021-:$[-:\356\334st\314r($[S\000\000\000@VCNM\000\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-41fef4f3605b9ee5e4470602717e900e0ab7b59d Step #5: Base64: SUQzAgEEYU0AAkdFT0lEMkISPysKKworCisKKworCisKKyQAAC8AAAAvAA8PDw8PMQ8tMlsmEToRLQ8PDw8PMBEPOTIyMzM3MjAzNjg1NDc3NTgwNxEtOiRbLTru3HN0zHIoJFtTAAAAQFZDTk0AAw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4202 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3818530571 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5648ea590810, 0x5648ea77a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5648ea77a020,0x5648ec6120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/41fef4f3605b9ee5e4470602717e900e0ab7b59d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5244 processed earlier; will process 5785 files now Step #5: ==151348== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5648e10859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5648e76ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5648e76cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5648e76cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5648e108bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5648e0fecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5648e0fe7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5648e107dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5648e404cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5648e404cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5648e404cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5648e404cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5648e404cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5648e404cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5648e404cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5648e404cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5648e404cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5648e404cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5648e62e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5648e300eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5648e3019be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5648e2dc5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5648e2dc5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5648e2dc6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5648e2dc5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5648e2dc5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5648e2dc5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5648e76cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5648e76d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5648e76c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5648e76eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ef973c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5648e0fe5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x4e,0x20,0xa,0x64,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x73,0x0,0xa,0x3f,0x41,0xa,0x64,0xa,0x64,0xa,0x64,0x0,0x0,0x2d,0x2d,0x47,0x49,0x4e,0x20,0xa,0x64,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x45,0x31,0xa,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x3f,0x41,0x73,0xa,0x0,0xa,0x64,0xa,0x64,0xa,0x64,0x0,0x0,0x2d,0x2d, Step #5: x-----BEN \012d\000\000------\000\000\000\000\000\000\000\000\000\000\000\000\000\000=\314\273A---Asce\012-s\000\012?A\012d\012d\012d\000\000--GIN \012d\000\000----------\012E1\012=\314\273A---Asce\012-?As\012\000\012d\012d\012d\000\000-- Step #5: artifact_prefix='./'; Test unit written to ./oom-b6fc8e50a4b61aa4cc67fee0159d8b2d68b06b1c Step #5: Base64: eC0tLS0tQkVOIApkAAAtLS0tLS0AAAAAAAAAAAAAAAAAAD3Mu0EtLS1Bc2NlCi1zAAo/QQpkCmQKZAAALS1HSU4gCmQAAC0tLS0tLS0tLS0KRTEKPcy7QS0tLUFzY2UKLT9BcwoACmQKZApkAAAtLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4203 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3819042314 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b550f40810, 0x55b55112a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b55112a020,0x55b552fc20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b6fc8e50a4b61aa4cc67fee0159d8b2d68b06b1c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5245 processed earlier; will process 5784 files now Step #5: ==151384== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b547a359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b54e09a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b54e07d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b54e07d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b547a3bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b54799cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b547997355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b547a2dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b54a9fcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b54a9fcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b54a9fcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b54a9fcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b54a9fcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b54a9fcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b54a9fcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b54a9fcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b54a9fcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b54a9fcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b54cc91f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b5499beb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b5499c9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b549775c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b549775c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b549776738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b549775874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b549775874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b549775874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b54e07fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b54e088928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b54e070699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b54e09b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6222a7b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b547995b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xc,0x62,0xa,0xa,0x8,0xcd,0x9e,0xc3,0xa5,0xc3,0xa5,0xcd,0xa5,0xa,0xc,0x62,0xa,0xa,0x8,0xcd,0x9e,0xc3,0xa5,0xc3,0xa4,0xcd,0xa5,0xa,0xc,0x62,0xa,0xa,0x8,0xcd,0x9e,0xc3,0xa5,0xc3,0xa5,0xcd,0xa5,0xa,0xc,0x62,0xa,0xa,0x8,0xcd,0x9e,0xc3,0xa5,0xc3,0xa5,0xcd,0xa5,0xa,0xc,0x62,0xa,0xa,0x8,0xcd,0x9e,0xc3,0xa5,0xc3,0xa5,0xcd,0xa5,0xa,0xc,0x62,0xa,0xa,0x8,0xcd,0x9e,0xc3,0xa5,0xc3,0xa5,0xcd,0xa5,0xa,0xc,0x62,0xa,0xa,0x8,0xcd,0x9e,0xc3,0xa5,0xc3,0xa5,0xcd,0xa5,0xa,0xc,0x62,0xa,0xa,0x8,0xcd,0x9e,0xc3,0xa5,0xcd,0x9e,0xc3,0xa5, Step #5: \012\014b\012\012\010\315\236\303\245\303\245\315\245\012\014b\012\012\010\315\236\303\245\303\244\315\245\012\014b\012\012\010\315\236\303\245\303\245\315\245\012\014b\012\012\010\315\236\303\245\303\245\315\245\012\014b\012\012\010\315\236\303\245\303\245\315\245\012\014b\012\012\010\315\236\303\245\303\245\315\245\012\014b\012\012\010\315\236\303\245\303\245\315\245\012\014b\012\012\010\315\236\303\245\315\236\303\245 Step #5: artifact_prefix='./'; Test unit written to ./oom-53c76d7754061dfb7cfe8e3bb988c036b8eb764e Step #5: Base64: CgxiCgoIzZ7DpcOlzaUKDGIKCgjNnsOlw6TNpQoMYgoKCM2ew6XDpc2lCgxiCgoIzZ7DpcOlzaUKDGIKCgjNnsOlw6XNpQoMYgoKCM2ew6XDpc2lCgxiCgoIzZ7DpcOlzaUKDGIKCgjNnsOlzZ7DpQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4204 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3819556446 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe70087810, 0x55fe7027101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe70271020,0x55fe721090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/53c76d7754061dfb7cfe8e3bb988c036b8eb764e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5246 processed earlier; will process 5783 files now Step #5: ==151420== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fe66b7c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe6d1e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe6d1c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe6d1c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe66b82d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe66ae3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe66ade355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe66b74c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe69b43f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe69b43f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe69b43f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe69b43f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe69b43f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe69b43f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe69b43f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe69b43f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe69b43f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe69b43f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe6bdd8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe68b05b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe68b10be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe688bcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe688bcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe688bd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe688bc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe688bc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe688bc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe6d1c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe6d1cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe6d1b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe6d1e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f372d731082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe66adcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x0,0x3d,0x0,0x4,0x0,0x31,0x1a,0x31,0x6c,0x69,0x67,0x68,0x74,0x24,0x3a,0x3a,0x3a,0x3a,0x3a,0x54,0x0,0x54,0x5b,0x31,0x31,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3a,0x3a,0x3a,0x0,0x0,0x0,0x4,0x0,0x31,0x1a,0x3a,0x0,0x5d,0x2f,0x0,0x0,0x0,0x33,0x34,0x0,0x54,0x5b,0x31,0x31,0x0,0x0,0x0,0x0,0x4,0x0,0x0,0x31,0x0,0x0,0x0,0x1,0x24,0x5b, Step #5: ID3\004\000=\000\004\0001\0321light$:::::T\000T[11::::::::::::::::::=\012=\012=\012=\012=\012=\012=\012=?\012=\012=\012=\012=\012=\012:::\000\000\000\004\0001\032:\000]/\000\000\00034\000T[11\000\000\000\000\004\000\0001\000\000\000\001$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-ed0725ad66ac5b9fb9c361f5882195cb0e4b2d08 Step #5: Base64: SUQzBAA9AAQAMRoxbGlnaHQkOjo6OjpUAFRbMTE6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo9Cj0KPQo9Cj0KPQo9Cj0/Cj0KPQo9Cj0KPQo6OjoAAAAEADEaOgBdLwAAADM0AFRbMTEAAAAABAAAMQAAAAEkWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4205 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3820077407 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c6440dc810, 0x55c6442c601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c6442c6020,0x55c64615e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ed0725ad66ac5b9fb9c361f5882195cb0e4b2d08' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5247 processed earlier; will process 5782 files now Step #5: ==151456== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c63abd19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c641236898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c6412195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c6412194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c63abd7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c63ab38b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c63ab33355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c63abc9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c63db98f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c63db98f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c63db98f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c63db98f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c63db98f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c63db98f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c63db98f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c63db98f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c63db98f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c63db98f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c63fe2df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c63cb5ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c63cb65be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c63c911c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c63c911c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c63c912738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c63c911874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c63c911874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c63c911874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c64121babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c641224928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c64120c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c641237112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f47b93ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c63ab31b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x28,0x42,0x3f,0x5f,0x28,0x29,0x3a,0x47,0x28,0x29,0x29,0x29,0x3f,0x28,0x28,0x28,0x28,0x6f,0x3f,0x5f,0x28,0x29,0x3a,0x24,0x28,0x29,0x29,0x29,0x3f,0x28,0x28,0x6f,0x29,0x3f,0x57,0x28,0x29,0x3a,0x6f,0x28,0x29,0x29,0x3a,0x6f,0x29,0x3f,0x57,0x28,0x29,0x3a,0x6f,0x28,0x29,0x29,0x3a,0x28,0x28,0x42,0x3f,0x5f,0x28,0x29,0x3a,0x47,0x28,0x29,0x29,0x29,0x3f,0x28,0x28,0x28,0x28,0x6f,0x3f,0x5f,0x28,0x29,0x3a,0x24,0x28,0x29,0x29,0x29,0x3f,0x28,0x28,0x6f,0x29,0x3f,0x57,0x28,0x29,0x3a,0x6f,0x28,0x29,0x29,0x3a,0x6f,0x29,0x3f,0x57,0x28,0x29,0x3a,0x6f,0x28,0x29,0x29,0x3a,0x6f, Step #5: ((B?_():G()))?((((o?_():$()))?((o)?W():o()):o)?W():o()):((B?_():G()))?((((o?_():$()))?((o)?W():o()):o)?W():o()):o Step #5: artifact_prefix='./'; Test unit written to ./oom-7f1688eba940bb1337bb0945ea3032c8c7b08b7d Step #5: Base64: KChCP18oKTpHKCkpKT8oKCgobz9fKCk6JCgpKSk/KChvKT9XKCk6bygpKTpvKT9XKCk6bygpKTooKEI/XygpOkcoKSkpPygoKChvP18oKTokKCkpKT8oKG8pP1coKTpvKCkpOm8pP1coKTpvKCkpOm8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4206 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3820592681 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b65656810, 0x558b6584001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b65840020,0x558b676d80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f1688eba940bb1337bb0945ea3032c8c7b08b7d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5248 processed earlier; will process 5781 files now Step #5: ==151492== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558b5c14b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b627b0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b627935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b627934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b5c151d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b5c0b2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b5c0ad355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b5c143c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b5f112f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b5f112f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b5f112f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b5f112f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b5f112f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b5f112f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b5f112f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b5f112f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b5f112f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b5f112f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b613a7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b5e0d4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b5e0dfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b5de8bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b5de8bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b5de8c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b5de8b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b5de8b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b5de8b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b62795abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b6279e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b62786699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b627b1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb15e7f3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b5c0abb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x20,0x24,0x24,0x24,0x24,0x24,0x24,0x26,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x25,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x0,0x0,0x24,0x24,0x62,0x6f,0x6c,0x64,0x0,0x24,0x24,0x24,0x0,0x0,0x24,0x24,0x24,0x69,0x74,0x61,0x6c,0x69,0x63,0x24,0x24,0x24,0x24,0x24,0x24,0x0,0x0,0x0,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0xff,0x7e,0x47,0x46,0x65,0x72,0x69,0x66, Step #5: ID$$$$$$$$$$$$ $$$$$$&$$$$$$$$$$$$$$$$$$$$$$%$$$$$$$$$\000\000$$bold\000$$$\000\000$$$italic$$$$$$\000\000\000$$$$$$$$$$$$$$$$$$$\377~GFerif Step #5: artifact_prefix='./'; Test unit written to ./oom-c695799aa7d0fc25f29a14a0f8939ce5b4d9d7f8 Step #5: Base64: SUQkJCQkJCQkJCQkJCQgJCQkJCQkJiQkJCQkJCQkJCQkJCQkJCQkJCQkJCQlJCQkJCQkJCQkAAAkJGJvbGQAJCQkAAAkJCRpdGFsaWMkJCQkJCQAAAAkJCQkJCQkJCQkJCQkJCQkJCQk/35HRmVyaWY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4207 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3821120148 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56094f0fe810, 0x56094f2e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56094f2e8020,0x5609511800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c695799aa7d0fc25f29a14a0f8939ce5b4d9d7f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5249 processed earlier; will process 5780 files now Step #5: ==151528== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560945bf39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56094c258898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56094c23b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56094c23b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560945bf9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560945b5ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560945b55355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560945bebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560948bbaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560948bbaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560948bbaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560948bbaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560948bbaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560948bbaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560948bbaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560948bbaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560948bbaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560948bbaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56094ae4ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560947b7cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560947b87be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560947933c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560947933c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560947934738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560947933874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560947933874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560947933874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56094c23dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56094c246928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56094c22e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56094c259112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8980d87082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560945b53b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x5b,0x49,0x47,0x4e,0x4f,0x52,0x45,0x5b,0x41,0xcd,0xb9,0xcc,0xb9,0xcc,0xb9,0x41,0xcd,0xb9,0xcc,0xb9,0xcc,0xb9,0xcd,0xb9,0x5b,0xcd,0xb9,0xcd,0xb9,0xcc,0xb9,0x2d,0xcc,0xb9,0xc3,0x9a,0xcd,0xb9,0xcc,0xb9,0x41,0xcd,0xb9,0xcc,0xb9,0xcc,0xb9,0xcd,0xb9,0xcd,0xb9,0x5b,0xcd,0xb9,0xcc,0xb9,0xcc,0xb9,0xc3,0x9a,0xcd,0xb9,0xcc,0xb9,0x41,0xc3,0x9a,0xcd,0xb9,0xcc,0xb9,0x41,0xcd,0xb9,0xcc,0xb9,0xcc,0xb9,0xcd,0xb9,0xcd,0xb9,0x5b,0xcd,0xb9,0xcc,0xb9,0xcc,0xb9,0xc3,0x9a,0xcd,0xb9,0xcc,0xb9,0x41,0x66,0xcc,0xb9,0x66,0x40,0xcd,0xb9,0xcc,0xb9,0xcd,0xb9,0xd,0xcc,0xb9,0x3c, Step #5: <![IGNORE[A\315\271\314\271\314\271A\315\271\314\271\314\271\315\271[\315\271\315\271\314\271-\314\271\303\232\315\271\314\271A\315\271\314\271\314\271\315\271\315\271[\315\271\314\271\314\271\303\232\315\271\314\271A\303\232\315\271\314\271A\315\271\314\271\314\271\315\271\315\271[\315\271\314\271\314\271\303\232\315\271\314\271Af\314\271f@\315\271\314\271\315\271\015\314\271< Step #5: artifact_prefix='./'; Test unit written to ./oom-2a06d9f5b30ea903e23f9f2397d69d23e697d360 Step #5: Base64: PCFbSUdOT1JFW0HNucy5zLlBzbnMucy5zblbzbnNucy5Lcy5w5rNucy5Qc25zLnMuc25zblbzbnMucy5w5rNucy5QcOazbnMuUHNucy5zLnNuc25W825zLnMucOazbnMuUFmzLlmQM25zLnNuQ3MuTw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4208 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3821647515 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e8c96ce810, 0x55e8c98b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e8c98b8020,0x55e8cb7500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2a06d9f5b30ea903e23f9f2397d69d23e697d360' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5250 processed earlier; will process 5779 files now Step #5: ==151564== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e8c01c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e8c6828898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e8c680b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e8c680b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e8c01c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e8c012ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e8c0125355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e8c01bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e8c318af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e8c318af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e8c318af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e8c318af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e8c318af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e8c318af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e8c318af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e8c318af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e8c318af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e8c318af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e8c541ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e8c214cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e8c2157be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e8c1f03c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e8c1f03c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e8c1f04738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e8c1f03874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e8c1f03874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e8c1f03874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e8c680dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e8c6816928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e8c67fe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e8c6829112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe7554f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e8c0123b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x3a,0x7b,0x7b,0x22,0x22,0x7d,0x7d,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x24,0x3a,0x7b,0x7b,0x22,0x22,0x7d,0x7d,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x64,0x3a,0x7b,0x7b,0x22,0x22,0x7d,0x7d,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x65,0x3a,0x7b,0x7b,0x22,0x22,0x7d,0x7d,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x24,0x3a,0x7b,0x7b,0x22,0x22,0x7d,0x7d,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x65,0x3a,0x7b,0x7b,0x22,0x22,0x7d,0x7d,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x24,0x3a,0x7b,0x7b,0x22,0x22,0x7d,0x7d,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x65,0x3a,0x7b,0x7b,0x22,0x22,0x7d,0x7d,0x7d,0x65, Step #5: $3::{$:{{\"\"}}}$3::{$:{{\"\"}}}$3::{d:{{\"\"}}}$3::{e:{{\"\"}}}$3::{$:{{\"\"}}}$3::{e:{{\"\"}}}$3::{$:{{\"\"}}}$3::{e:{{\"\"}}}e Step #5: artifact_prefix='./'; Test unit written to ./oom-33e62a99bc2b30756db59a7089e951693319d6df Step #5: Base64: JDM6OnskOnt7IiJ9fX0kMzo6eyQ6e3siIn19fSQzOjp7ZDp7eyIifX19JDM6OntlOnt7IiJ9fX0kMzo6eyQ6e3siIn19fSQzOjp7ZTp7eyIifX19JDM6OnskOnt7IiJ9fX0kMzo6e2U6e3siIn19fWU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4209 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3822169123 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56447a8ba810, 0x56447aaa401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56447aaa4020,0x56447c93c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/33e62a99bc2b30756db59a7089e951693319d6df' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5251 processed earlier; will process 5778 files now Step #5: ==151600== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5644713af9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564477a14898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5644779f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5644779f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5644713b5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564471316b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564471311355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5644713a7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564474376f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564474376f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564474376f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564474376f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564474376f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564474376f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564474376f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564474376f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564474376f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564474376f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56447660bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564473338b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564473343be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5644730efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5644730efc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5644730f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5644730ef874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5644730ef874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5644730ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5644779f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564477a02928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5644779ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564477a15112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f56a6396082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56447130fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0x24,0x24,0x24,0x1e,0x24,0x6c,0x6f,0x72,0x65,0x6d,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x24,0x24,0x24,0x24,0x24,0x24,0x93,0x24,0x24,0x24,0xdb,0xdd,0x24,0xdb,0xcc,0x3,0x7e,0x47,0x46,0x44,0x7e,0x91,0x47, Step #5: $$$$$\036$lorem$$$$$$$$$$$$$$$$$$$$$$$$$$$$$\003\003\003\003\003\003\003\003\003\003\003\003\003$$$$$$$$$$$$$$$$$$$$$=\012=\012=\012=\012=\012=\012=\012=$$$$$$\223$$$\333\335$\333\314\003~GFD~\221G Step #5: artifact_prefix='./'; Test unit written to ./oom-8dd134c975fc0cd45369f3933a045e366b3e5853 Step #5: Base64: JCQkJCQeJGxvcmVtJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQDAwMDAwMDAwMDAwMDJCQkJCQkJCQkJCQkJCQkJCQkJCQkPQo9Cj0KPQo9Cj0KPQo9JCQkJCQkkyQkJNvdJNvMA35HRkR+kUc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4210 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3822696319 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0fcad9810, 0x55b0fccc301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b0fccc3020,0x55b0feb5b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8dd134c975fc0cd45369f3933a045e366b3e5853' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5252 processed earlier; will process 5777 files now Step #5: ==151636== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b0f35ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b0f9c33898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b0f9c165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b0f9c164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0f35d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0f3535b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0f3530355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0f35c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b0f6595f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b0f6595f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b0f6595f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b0f6595f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b0f6595f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b0f6595f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b0f6595f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b0f6595f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b0f6595f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b0f6595f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b0f882af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b0f5557b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b0f5562be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b0f530ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b0f530ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b0f530f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b0f530e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b0f530e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b0f530e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b0f9c18abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b0f9c21928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b0f9c09699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b0f9c34112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcdfd9fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0f352eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x0,0x22,0x54,0x4b,0x4e,0x54,0x4b,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x4e,0x2,0x73,0x74,0x0,0x22,0x54,0x60,0x4e,0x60,0x2d,0x2d,0x2d,0x2d,0x2,0x73,0x74,0x0,0x22,0x54,0x60,0x4e,0x60,0x2d,0x0,0xd2,0xbf,0x46,0x46,0x20,0xbb,0x2d,0x2d,0x2d,0xde,0x44,0x2a, Step #5: I\000\"TKNTKyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyN\002st\000\"T`N`----\002st\000\"T`N`-\000\322\277FF \273---\336D* Step #5: artifact_prefix='./'; Test unit written to ./oom-b7e9ee03f64ab46b14a5edd7a02f7f452b5c3788 Step #5: Base64: SQAiVEtOVEt5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eU4Cc3QAIlRgTmAtLS0tAnN0ACJUYE5gLQDSv0ZGILstLS3eRCo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4211 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3823331204 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db1358b810, 0x55db1377501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db13775020,0x55db1560d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7e9ee03f64ab46b14a5edd7a02f7f452b5c3788' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5253 processed earlier; will process 5776 files now Step #5: ==151672== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db0a0809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db106e5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db106c85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db106c84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db0a086d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db09fe7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db09fe2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db0a078c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db0d047f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db0d047f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db0d047f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db0d047f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db0d047f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db0d047f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db0d047f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db0d047f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db0d047f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db0d047f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db0f2dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db0c009b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db0c014be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db0bdc0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db0bdc0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db0bdc1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db0bdc0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db0bdc0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db0bdc0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db106caabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db106d3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db106bb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db106e6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f29439cb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db09fe0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x7d,0x6c,0x6f,0x6f,0x70,0x7b,0x39,0x39,0x33,0x32,0x31,0x38,0x26,0x38,0x30,0x39,0x33,0x31,0x2f,0x38,0x30,0x3b,0x46,0x6e,0x28,0x60,0x68,0x4a,0x59,0x60,0x29,0x2b,0xd,0x60,0x75,0x49,0xe,0x0,0x6f,0x6f,0x5b,0x5d,0x5d,0xc5,0xa5,0x5b,0x5d,0x6c,0x63,0x0,0x4c,0x6f,0x0,0x0,0x0,0x40,0x0,0x0,0x0,0x11,0x10,0x0,0x64,0x65,0x14,0x0,0x74,0x0,0x0,0x3,0x0,0x0,0x0,0x6b,0x7a,0xe0,0xbe,0x82,0x0,0x0,0x0,0x0,0x60,0x5b,0x31,0x2d,0x2e,0x2e,0x2d,0x34,0x5d,0x5b,0x30,0x31,0x2e,0x2e,0x5d,0x2b,0x2d,0x31,0x32,0x37,0x7d,0x66,0xe2,0x81,0xa7,0x6a,0x31,0x72,0xe0,0x68, Step #5: {}loop{993218&80931/80;Fn(`hJY`)+\015`uI\016\000oo[]]\305\245[]lc\000Lo\000\000\000@\000\000\000\021\020\000de\024\000t\000\000\003\000\000\000kz\340\276\202\000\000\000\000`[1-..-4][01..]+-127}f\342\201\247j1r\340h Step #5: artifact_prefix='./'; Test unit written to ./oom-30372c99278f8f78e4241d9ea65b043c352762a3 Step #5: Base64: e31sb29wezk5MzIxOCY4MDkzMS84MDtGbihgaEpZYCkrDWB1SQ4Ab29bXV3FpVtdbGMATG8AAABAAAAAERAAZGUUAHQAAAMAAABreuC+ggAAAABgWzEtLi4tNF1bMDEuLl0rLTEyN31m4oGnajFy4Gg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4212 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3823965163 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fcdc38d810, 0x55fcdc57701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fcdc577020,0x55fcde40f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/30372c99278f8f78e4241d9ea65b043c352762a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5254 processed earlier; will process 5775 files now Step #5: #1 pulse cov: 3653 ft: 3654 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 12118 ft: 13008 exec/s: 0 rss: 194Mb Step #5: ==151708== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fcd2e829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fcd94e7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fcd94ca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fcd94ca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fcd2e88d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fcd2de9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fcd2de4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fcd2e7ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fcd5e49f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fcd5e49f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fcd5e49f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fcd5e49f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fcd5e49f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fcd5e49f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fcd5e49f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fcd5e49f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fcd5e49f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fcd5e49f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fcd80def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fcd4e0bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fcd4e16be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fcd4bc2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fcd4bc2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fcd4bc3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fcd4bc2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fcd4bc2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fcd4bc2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fcd94ccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fcd94d5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fcd94bd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fcd94e8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a41288082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fcd2de2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x0,0x25,0x2e,0xde,0xbb,0x46,0xba,0xf3,0xa0,0x81,0x99,0xba,0xa2,0x46,0x1,0x3,0x17,0x3,0xf5,0x0,0x0,0x0,0xe8,0x0,0x0,0x0,0x3,0x8,0x0,0x0,0x0,0xec,0x81,0x2,0x0,0x0,0x0,0x73,0xfd,0xff,0xff,0xff,0x40,0xef,0xf3,0xa0,0x80,0xb3,0x45,0x16,0x17,0xba,0xb5,0xb8,0x7,0xf8,0x0,0x0,0xed,0xaa,0xad,0xba,0x2a,0x1,0xaa,0xba,0xe1,0x0,0xf2,0xba,0xf5,0x6,0x45,0x3a,0x97,0xba,0x63,0xbe,0xba,0xe,0x0,0x0,0xba,0x28,0x0,0x3a,0x7a,0xba,0x0,0x0,0x12,0x0,0x0,0x0,0x0,0xbf,0xfd,0x3c,0x61,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa0,0x0,0x40,0x72,0x1,0xff, Step #5: \002\000%.\336\273F\272\363\240\201\231\272\242F\001\003\027\003\365\000\000\000\350\000\000\000\003\010\000\000\000\354\201\002\000\000\000s\375\377\377\377@\357\363\240\200\263E\026\027\272\265\270\007\370\000\000\355\252\255\272*\001\252\272\341\000\362\272\365\006E:\227\272c\276\272\016\000\000\272(\000:z\272\000\000\022\000\000\000\000\277\375<a\000\000\000\000\000\000\000\240\000@r\001\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-2495960a81b56f3dce82543f104a3a8d98087111 Step #5: Base64: AgAlLt67RrrzoIGZuqJGAQMXA/UAAADoAAAAAwgAAADsgQIAAABz/f///0Dv86CAs0UWF7q1uAf4AADtqq26KgGquuEA8rr1BkU6l7pjvroOAAC6KAA6eroAABIAAAAAv/08YQAAAAAAAACgAEByAf8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4213 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3824579415 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb9acd4810, 0x55bb9aebe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb9aebe020,0x55bb9cd560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2495960a81b56f3dce82543f104a3a8d98087111' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5257 processed earlier; will process 5772 files now Step #5: ==151744== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bb917c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb97e2e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb97e115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb97e114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb917cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb91730b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb9172b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb917c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb94790f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb94790f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb94790f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb94790f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb94790f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb94790f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb94790f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb94790f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb94790f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb94790f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb96a25f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb93752b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb9375dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb93509c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb93509c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb9350a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb93509874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb93509874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb93509874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb97e13abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb97e1c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb97e04699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb97e2f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1eef0e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb91729b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7f,0x68,0x24,0x0,0x0,0x11,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x8,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x8,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x76,0x2d,0x2d,0x2d,0x76,0x0,0x0,0x8,0x24, Step #5: \177h$\000\000\021\000\000\000----------------------------\010\000\000\000------------------------------------------\010\000\000\000-----------------v---v\000\000\010$ Step #5: artifact_prefix='./'; Test unit written to ./oom-f27421119ad9d28bd29b06dc73288a89af587c94 Step #5: Base64: f2gkAAARAAAALS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLQgAAAAtLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0IAAAALS0tLS0tLS0tLS0tLS0tLS12LS0tdgAACCQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4214 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3825092038 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564f2a4cb810, 0x564f2a6b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564f2a6b5020,0x564f2c54d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f27421119ad9d28bd29b06dc73288a89af587c94' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5258 processed earlier; will process 5771 files now Step #5: ==151780== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564f20fc09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f27625898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f276085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f276084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f20fc6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f20f27b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f20f22355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f20fb8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f23f87f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f23f87f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f23f87f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f23f87f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f23f87f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f23f87f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f23f87f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f23f87f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f23f87f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f23f87f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f2621cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f22f49b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f22f54be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f22d00c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f22d00c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f22d01738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f22d00874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f22d00874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f22d00874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f2760aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f27613928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f275fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f27626112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8464774082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f20f20b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x47,0x41,0xd6,0xaf,0x27,0x27,0x27,0x2f,0x0,0x0,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x47,0x41,0xd6,0xaf,0x27,0x27,0x27,0x2f,0x0,0x0,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x0,0x0,0x0,0x0,0x0,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x47,0x41,0xd6,0xaf,0x27,0x27,0x27,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x15,0x2f,0x29,0x81,0x0,0x27, Step #5: BGA\326\257'''/\000\000\022\022\022\022\022\022\022\022GA\326\257'''/\000\000\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\000\000\000\000\000\022\022\022\022\022\022\022\022\022\022\022\022\022\022GA\326\257'''\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\000\000\000\000\000\000\000'\025/)\201\000' Step #5: artifact_prefix='./'; Test unit written to ./oom-7e25e5d280ddb8dd3ca62cd84b1f4875a5923f94 Step #5: Base64: QkdB1q8nJycvAAASEhISEhISEkdB1q8nJycvAAASEhISEhISEhISEhISEhISEhISEhISAAAAAAASEhISEhISEhISEhISEkdB1q8nJycSEhISEhISEhISEhISEhISEhISEhISAAAAAAAAACcVLymBACc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4215 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3825599966 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c7ebfda810, 0x55c7ec1c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c7ec1c4020,0x55c7ee05c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7e25e5d280ddb8dd3ca62cd84b1f4875a5923f94' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5259 processed earlier; will process 5770 files now Step #5: #1 pulse cov: 4069 ft: 4070 exec/s: 0 rss: 176Mb Step #5: ==151816== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c7e2acf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7e9134898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7e91175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7e91174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c7e2ad5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c7e2a36b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c7e2a31355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7e2ac7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7e5a96f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7e5a96f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7e5a96f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7e5a96f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7e5a96f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7e5a96f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7e5a96f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7e5a96f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7e5a96f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7e5a96f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7e7d2bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7e4a58b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7e4a63be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7e480fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7e480fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7e4810738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7e480f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7e480f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7e480f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7e9119abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7e9122928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c7e910a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7e9135112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc7089d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c7e2a2fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0x9,0x73,0x75,0x62,0x7b,0x64,0x3a,0x2d,0x32,0x65,0x33,0x31,0x37,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x2d,0x31,0x65,0x33,0x31,0x30,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x2d,0x31,0x65,0x33,0x32,0x30,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x2d,0x31,0x65,0x33,0x32,0x30,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x2d,0x33,0x65,0x33,0x31,0x36,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x2d,0x31,0x65,0x33,0x31,0x31,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x2d,0x31,0x65,0x33,0x31,0x31,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x2d,0x38,0x65,0x34,0x39,0x31, Step #5: FUZZTESTv1\011sub{d:-2e317}sub{d:-1e310}sub{d:-1e320}sub{d:-1e320}sub{d:-3e316}sub{d:-1e311}sub{d:-1e311}sub{d:-8e491 Step #5: artifact_prefix='./'; Test unit written to ./oom-d926afa495114538a1a4a95595d6fcc36c5c5645 Step #5: Base64: RlVaWlRFU1R2MQlzdWJ7ZDotMmUzMTd9c3Vie2Q6LTFlMzEwfXN1YntkOi0xZTMyMH1zdWJ7ZDotMWUzMjB9c3Vie2Q6LTNlMzE2fXN1YntkOi0xZTMxMX1zdWJ7ZDotMWUzMTF9c3Vie2Q6LThlNDkx Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4216 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3826152371 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55df9c8ae810, 0x55df9ca9801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55df9ca98020,0x55df9e9300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d926afa495114538a1a4a95595d6fcc36c5c5645' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5261 processed earlier; will process 5768 files now Step #5: ==151852== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55df933a39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55df99a08898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55df999eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55df999eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55df933a9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55df9330ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55df93305355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55df9339bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55df9636af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55df9636af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55df9636af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55df9636af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55df9636af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55df9636af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55df9636af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55df9636af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55df9636af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55df9636af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55df985fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55df9532cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55df95337be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55df950e3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55df950e3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55df950e4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55df950e3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55df950e3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55df950e3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55df999edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55df999f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55df999de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55df99a09112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f99101af082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55df93303b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0x21,0x20,0x54,0x69,0x73,0x68,0x78,0x5b,0x0,0x63,0x72,0x69,0x70,0x74,0x20,0x64,0x65,0x6e,0x29,0x3b,0xa,0xa,0x6c,0x65,0x74,0x20,0x22,0xe6,0x9c,0x9d,0xe3,0x81,0xab,0xe3,0x81,0xaf,0xe7,0xb4,0x85,0xe9,0xa1,0x94,0xe3,0x81,0x82,0xe3,0x82,0x8a,0xe3,0x81,0xa6,0xe5,0xa4,0x95,0xe3,0x81,0xb9,0xe3,0x81,0xab,0xe3,0x81,0xaf,0xe7,0x99,0xbd,0xe9,0xaa,0x3b,0xa,0x65,0x76,0x20,0x39,0x30,0x35,0x34,0x37,0x32,0x33,0x30,0x32,0x31,0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x17,0x2f,0x21,0x20,0x54,0x68,0x69,0x73,0x78,0x5b,0x0,0x67,0x72,0x28,0x70,0x74,0x20,0x64,0x65,0x6e,0x6c, Step #5: //! Tishx[\000cript den);\012\012let \"\346\234\235\343\201\253\343\201\257\347\264\205\351\241\224\343\201\202\343\202\212\343\201\246\345\244\225\343\201\271\343\201\253\343\201\257\347\231\275\351\252;\012ev 9054723021/\000\000\000\000\000\000\000\027/! Thisx[\000gr(pt denl Step #5: artifact_prefix='./'; Test unit written to ./oom-a9498fe298deb5e2a3ddd45532bfe7346ab4d997 Step #5: Base64: Ly8hIFRpc2h4WwBjcmlwdCBkZW4pOwoKbGV0ICLmnJ3jgavjga/ntIXpoZTjgYLjgorjgablpJXjgbnjgavjga/nmb3pqjsKZXYgOTA1NDcyMzAyMS8AAAAAAAAAFy8hIFRoaXN4WwBncihwdCBkZW5s Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4217 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3826656104 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56536e1d7810, 0x56536e3c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56536e3c1020,0x5653702590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9498fe298deb5e2a3ddd45532bfe7346ab4d997' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5262 processed earlier; will process 5767 files now Step #5: #1 pulse cov: 11200 ft: 11201 exec/s: 0 rss: 194Mb Step #5: #2 pulse cov: 11753 ft: 12786 exec/s: 0 rss: 197Mb Step #5: ==151888== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565364ccc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56536b331898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56536b3145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56536b3144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565364cd2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565364c33b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565364c2e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565364cc4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565367c93f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565367c93f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565367c93f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565367c93f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565367c93f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565367c93f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565367c93f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565367c93f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565367c93f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565367c93f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565369f28f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565366c55b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565366c60be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565366a0cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565366a0cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565366a0d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565366a0c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565366a0c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565366a0c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56536b316abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56536b31f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56536b307699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56536b332112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7492edf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565364c2cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc6,0xb2,0xc6,0xa9,0xd8,0xbd,0xc6,0xb2,0xd6,0xb2,0xd0,0x9b,0xc3,0xb2,0xd4,0xa9,0xda,0xbd,0xc6,0x9b,0xc3,0x81,0xda,0xbd,0xc6,0xb2,0xd6,0xb2,0xd0,0x9b,0xc3,0xbd,0xcc,0xb2,0xc7,0xa9,0xc7,0xb2,0xd6,0xa9,0xc6,0xb2,0xd4,0xa9,0xc6,0xb2,0xd4,0xbd,0xcc,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xb2,0xc7,0xa9,0xc7,0xb2,0xd6,0xa9,0xc6,0xb2,0xd4,0xa9,0xc6,0xb2,0xd4,0xb2, Step #5: \306\262\306\251\330\275\306\262\326\262\320\233\303\262\324\251\332\275\306\233\303\201\332\275\306\262\326\262\320\233\303\275\314\262\307\251\307\262\326\251\306\262\324\251\306\262\324\275\314\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\262\307\251\307\262\326\251\306\262\324\251\306\262\324\262 Step #5: artifact_prefix='./'; Test unit written to ./oom-32ac19d96dc27b198f3c98bfcb9fd5fbb9d55b4e Step #5: Base64: xrLGqdi9xrLWstCbw7LUqdq9xpvDgdq9xrLWstCbw73Mssepx7LWqcay1KnGstS9zAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAssepx7LWqcay1KnGstSy Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4218 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3827275725 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561f25cf8810, 0x561f25ee201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561f25ee2020,0x561f27d7a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/32ac19d96dc27b198f3c98bfcb9fd5fbb9d55b4e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5265 processed earlier; will process 5764 files now Step #5: ==151924== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561f1c7ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561f22e52898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561f22e355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561f22e354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561f1c7f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561f1c754b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561f1c74f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561f1c7e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561f1f7b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561f1f7b4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561f1f7b4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561f1f7b4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561f1f7b4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561f1f7b4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561f1f7b4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561f1f7b4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561f1f7b4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561f1f7b4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561f21a49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561f1e776b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561f1e781be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561f1e52dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561f1e52dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561f1e52e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561f1e52d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561f1e52d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561f1e52d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561f22e37abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561f22e40928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561f22e28699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561f22e53112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f85a3288082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561f1c74db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x6e,0x5b,0x32,0x73,0x32,0x2c,0x36,0xf0,0x91,0x8d,0x90,0xf0,0x90,0xba,0x98,0x20,0xf2,0xb9,0xbe,0x8e,0xf0,0xb0,0x95,0xbc,0xf1,0x9a,0x95,0xbb,0xf2,0x97,0xbf,0x95,0x2d,0x31,0x2d,0xf0,0xa6,0x95,0x8d,0x30,0x3a,0x30,0x30,0x32,0x2c,0x30,0xf0,0x91,0x8d,0x90,0xf2,0xb9,0xbe,0x8e,0xf0,0xb0,0x95,0xbc,0xf1,0x9a,0x95,0xbb,0x30,0x2d,0x32,0xd,0xd,0xd,0xd,0x32,0x2d,0x31,0x2d,0x32,0x74,0x31,0x2c,0x32,0xf0,0x91,0x8d,0x90,0xf0,0x90,0xba,0x98,0x20,0xf2,0xb9,0xbe,0x8e,0xf0,0xb0,0x95,0xbc,0xf1,0x9a,0x95,0xbb,0xf2,0x97,0xbf,0x95,0xf0,0xa6,0x95,0x8d,0x30,0x6f,0xa,0x31, Step #5: \000\000\000n[2s2,6\360\221\215\220\360\220\272\230 \362\271\276\216\360\260\225\274\361\232\225\273\362\227\277\225-1-\360\246\225\2150:002,0\360\221\215\220\362\271\276\216\360\260\225\274\361\232\225\2730-2\015\015\015\0152-1-2t1,2\360\221\215\220\360\220\272\230 \362\271\276\216\360\260\225\274\361\232\225\273\362\227\277\225\360\246\225\2150o\0121 Step #5: artifact_prefix='./'; Test unit written to ./oom-8654ce61d19d857893a6490fc06d390e2126af2c Step #5: Base64: AAAAblsyczIsNvCRjZDwkLqYIPK5vo7wsJW88ZqVu/KXv5UtMS3wppWNMDowMDIsMPCRjZDyub6O8LCVvPGalbswLTINDQ0NMi0xLTJ0MSwy8JGNkPCQupgg8rm+jvCwlbzxmpW78pe/lfCmlY0wbwox Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4219 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3827787134 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf40f1a810, 0x55bf4110401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf41104020,0x55bf42f9c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8654ce61d19d857893a6490fc06d390e2126af2c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5266 processed earlier; will process 5763 files now Step #5: ==151960== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bf37a0f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf3e074898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf3e0575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf3e0574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf37a15d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf37976b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf37971355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf37a07c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf3a9d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf3a9d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf3a9d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf3a9d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf3a9d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf3a9d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf3a9d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf3a9d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf3a9d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf3a9d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf3cc6bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf39998b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf399a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf3974fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf3974fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf39750738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf3974f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf3974f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf3974f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf3e059abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf3e062928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf3e04a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf3e075112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c9a825082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf3796fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x30,0x73,0x38,0x20,0x5b,0x20,0x2d,0x2d,0x2d,0x2d,0x73,0x74,0x72,0x65,0x61,0x6d,0x47,0x4b,0x60,0x20,0x2d,0x45,0x47,0x4b,0x60,0x24,0x24,0x24,0x24,0x24,0x24,0x6c,0x69,0x67,0x31,0x74,0x24,0x24,0x24,0x24,0x24,0x24,0x63,0x6f,0x6e,0x64,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x64,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x24,0x24,0x4,0x63,0x6f,0x70,0x70,0x70,0x70,0x70,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x3f, Step #5: s0s8 [ ----streamGK` -EGK`$$$$$$lig1t$$$$$$cond$$$$$$$$d()()()()()()()()()()()()()()()()$$\004coppppp$$$$$$$$$$$$$$$$? Step #5: artifact_prefix='./'; Test unit written to ./oom-5395c5f6c1bb484abd246280ac0e44f9f57a3949 Step #5: Base64: czBzOCBbIC0tLS1zdHJlYW1HS2AgLUVHS2AkJCQkJCRsaWcxdCQkJCQkJGNvbmQkJCQkJCQkJGQoKSgpKCkoKSgpKCkoKSgpKCkoKSgpKCkoKSgpKCkoKSQkBGNvcHBwcHAkJCQkJCQkJCQkJCQkJCQkPw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4220 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3828435531 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556e2aeac810, 0x556e2b09601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556e2b096020,0x556e2cf2e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5395c5f6c1bb484abd246280ac0e44f9f57a3949' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5267 processed earlier; will process 5762 files now Step #5: ==151996== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556e219a19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556e28006898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556e27fe95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556e27fe94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556e219a7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556e21908b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556e21903355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556e21999c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556e24968f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556e24968f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556e24968f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556e24968f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556e24968f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556e24968f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556e24968f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556e24968f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556e24968f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556e24968f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556e26bfdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556e2392ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556e23935be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556e236e1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556e236e1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556e236e2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556e236e1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556e236e1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556e236e1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556e27febabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556e27ff4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556e27fdc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556e28007112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fab32931082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556e21901b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x74,0x72,0x75,0x65,0x7c,0x21,0x74,0x72,0x75,0x65,0x3c,0x21,0x7c,0x72,0x75,0x65,0x7c,0x21,0x74,0x72,0x75,0x65,0x7c,0x74,0x72,0x75,0x65,0x7c,0x21,0x20,0x2d,0x60,0xd,0xa,0x60,0x2d,0x20,0x2d,0x60,0xd,0xa,0x60,0x2d,0x20,0x2d,0x60,0xd,0x1a,0x60,0x60,0x60,0x2b,0x60,0x60,0x2b,0x60,0x60,0x2b,0x60,0x60,0x2b,0x60,0x60,0x2b,0x60,0x60,0x2b,0x60,0x60,0x2b,0x60,0x60,0x2b,0x60,0x37,0x34,0x60,0x2d,0x60,0x31,0x60,0x2f,0x35,0x60,0x2b,0x5f,0x37,0x34,0x60,0x2d,0x60,0x31,0x60,0x2f,0x31,0x2e,0x35,0x2a,0x35,0x35,0x2b,0x60,0x74,0x31,0x60,0x2d,0x35,0x3b,0xd3,0xdf,0x2d,0x60,0x24,0x60, Step #5: !true|!true<!|rue|!true|true|! -`\015\012`- -`\015\012`- -`\015\032```+``+``+``+``+``+``+``+`74`-`1`/5`+_74`-`1`/1.5*55+`t1`-5;\323\337-`$` Step #5: artifact_prefix='./'; Test unit written to ./oom-1c3ea7e6f443493daa0b4f4d41997a1f3d9d7a17 Step #5: Base64: IXRydWV8IXRydWU8IXxydWV8IXRydWV8dHJ1ZXwhIC1gDQpgLSAtYA0KYC0gLWANGmBgYCtgYCtgYCtgYCtgYCtgYCtgYCtgYCtgNzRgLWAxYC81YCtfNzRgLWAxYC8xLjUqNTUrYHQxYC01O9PfLWAkYA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4221 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3829077596 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d405ef5810, 0x55d4060df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d4060df020,0x55d407f770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c3ea7e6f443493daa0b4f4d41997a1f3d9d7a17' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5268 processed earlier; will process 5761 files now Step #5: ==152032== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d3fc9ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d40304f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d4030325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d4030324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d3fc9f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d3fc951b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d3fc94c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d3fc9e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d3ff9b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d3ff9b1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d3ff9b1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d3ff9b1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d3ff9b1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d3ff9b1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d3ff9b1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d3ff9b1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d3ff9b1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d3ff9b1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d401c46f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d3fe973b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d3fe97ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d3fe72ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d3fe72ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d3fe72b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d3fe72a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d3fe72a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d3fe72a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d403034abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d40303d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d403025699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d403050112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f557ba85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d3fc94ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7b,0x37,0x7d,0x24,0x7f,0x32,0x7d,0x24,0x7b,0x31,0x37,0x30,0x31,0x34,0x31,0x31,0x38,0x33,0x34,0x36,0x30,0x34,0x36,0x39,0x32,0x33,0x31,0x37,0x33,0x31,0x36,0x38,0x37,0x33,0x30,0x33,0x37,0x31,0x35,0x38,0x38,0x34,0x31,0x30,0x35,0x37,0x32,0x39,0x7d,0x24,0x7b,0x31,0x30,0x35,0x35,0x7d,0xf3,0xa0,0x80,0xa2,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x31,0x37,0x30,0x31,0x34,0x31,0x31,0x38,0x33,0x34,0x36,0x30,0x34,0x36,0x39,0x32,0x33,0x31,0x37,0x33,0x31,0x36,0x38,0x37,0x33,0x30,0x33,0x37,0x31,0x35,0x38,0x38,0x34,0x31,0x30,0x35,0x37,0x33,0x36,0x7d,0x24,0x7b,0x38,0x7d, Step #5: ${7}$\1772}${170141183460469231731687303715884105729}${1055}\363\240\200\242${8}${8}${170141183460469231731687303715884105736}${8} Step #5: artifact_prefix='./'; Test unit written to ./oom-f5c8ecd60108b00aea5718be75072f2514788773 Step #5: Base64: JHs3fSR/Mn0kezE3MDE0MTE4MzQ2MDQ2OTIzMTczMTY4NzMwMzcxNTg4NDEwNTcyOX0kezEwNTV986CAoiR7OH0kezh9JHsxNzAxNDExODM0NjA0NjkyMzE3MzE2ODczMDM3MTU4ODQxMDU3MzZ9JHs4fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4222 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3829594204 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d226feb810, 0x55d2271d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d2271d5020,0x55d22906d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f5c8ecd60108b00aea5718be75072f2514788773' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5269 processed earlier; will process 5760 files now Step #5: ==152068== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d21dae09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d224145898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d2241285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d2241284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d21dae6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d21da47b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d21da42355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d21dad8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d220aa7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d220aa7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d220aa7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d220aa7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d220aa7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d220aa7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d220aa7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d220aa7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d220aa7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d220aa7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d222d3cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d21fa69b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d21fa74be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d21f820c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d21f820c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d21f821738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d21f820874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d21f820874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d21f820874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d22412aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d224133928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d22411b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d224146112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3f5be76082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d21da40b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x3c,0xdb,0xbe,0xdb,0xbe,0x7e,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x22,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x73,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x42,0x42,0x67,0x72,0x79,0x31,0x73, Step #5: ~<\333\276\333\276~sssssssssss%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%\"%%%%%%%%%%%%%%%%%%%%%%%s~~~~~~\001\000\000\000\000\000\000BBgry1s Step #5: artifact_prefix='./'; Test unit written to ./oom-1890e96ad25ea366d93247ded15911eda8a45a71 Step #5: Base64: fjzbvtu+fnNzc3Nzc3Nzc3NzJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSIlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJXN+fn5+fn4BAAAAAAAAQkJncnkxcw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4223 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3830106722 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d5256ce810, 0x55d5258b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d5258b8020,0x55d5277500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1890e96ad25ea366d93247ded15911eda8a45a71' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5270 processed earlier; will process 5759 files now Step #5: #1 pulse cov: 3716 ft: 3717 exec/s: 0 rss: 174Mb Step #5: ==152104== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d51c1c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d522828898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d52280b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d52280b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d51c1c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d51c12ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d51c125355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d51c1bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d51f18af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d51f18af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d51f18af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d51f18af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d51f18af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d51f18af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d51f18af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d51f18af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d51f18af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d51f18af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d52141ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d51e14cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d51e157be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d51df03c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d51df03c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d51df04738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d51df03874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d51df03874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d51df03874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d52280dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d522816928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d5227fe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d522829112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9d6fcef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d51c123b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0xa,0x2d,0x2d,0x2d,0x42,0x2d,0x2d,0xa,0x62,0x2d,0x2d,0x2d,0x2d,0x2d,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x49,0x44,0x33,0x3,0x14,0x1,0x2f,0x0,0x0,0x67,0x54,0x49,0x54,0x49,0x44,0x45,0x42,0x4c,0x43,0x3d,0x6b,0x0,0x2b,0x50,0x63,0x2d,0x31,0x0,0x0,0xd,0xe,0xe,0x69,0x2d,0x20,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x2d,0x2d,0xa,0x62,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xfa,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: `-----BEG\011N -----\000\012---B--\012b-----(\342\200\256\000r+\342\200\215\000ID3\003\024\001/\000\000gTITIDEBLC=k\000+Pc-1\000\000\015\016\016i- -\012`-----B--\012b-----BEG\011N -----\372N ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-b592ee167c31b6e252bd0d445b0a01305ebaafbb Step #5: Base64: YC0tLS0tQkVHCU4gLS0tLS0ACi0tLUItLQpiLS0tLS0o4oCuAHIr4oCNAElEMwMUAS8AAGdUSVRJREVCTEM9awArUGMtMQAADQ4OaS0gLQpgLS0tLS1CLS0KYi0tLS0tQkVHCU4gLS0tLS36TiAtLS0tLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4224 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3830783094 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557301111810, 0x5573012fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5573012fb020,0x5573031930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b592ee167c31b6e252bd0d445b0a01305ebaafbb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5272 processed earlier; will process 5757 files now Step #5: ==152140== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5572f7c069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5572fe26b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5572fe24e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5572fe24e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5572f7c0cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5572f7b6db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5572f7b68355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5572f7bfec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5572fabcdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5572fabcdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5572fabcdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5572fabcdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5572fabcdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5572fabcdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5572fabcdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5572fabcdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5572fabcdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5572fabcdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5572fce62f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5572f9b8fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5572f9b9abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5572f9946c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5572f9946c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5572f9947738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5572f9946874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5572f9946874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5572f9946874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5572fe250abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5572fe259928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5572fe241699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5572fe26c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a834c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5572f7b66b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x3f,0x67,0x67,0x6c,0x2d,0x2d,0x2d,0xa,0x44,0xa,0x2d,0xa,0x49,0xa,0x31,0xa,0x2d,0x2e,0x64,0xa,0x64,0xa,0x3f, Step #5: s\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000-----BEGI?ggl---\012D\012-\012I\0121\012-.d\012d\012? Step #5: artifact_prefix='./'; Test unit written to ./oom-08cf8b3741e5969e57519e7503c970d758538a40 Step #5: Base64: cwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAtLS0tLUJFR0k/Z2dsLS0tCkQKLQpJCjEKLS5kCmQKPw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4225 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3831291502 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5612a0cd1810, 0x5612a0ebb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5612a0ebb020,0x5612a2d530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08cf8b3741e5969e57519e7503c970d758538a40' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5273 processed earlier; will process 5756 files now Step #5: ==152176== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5612977c69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56129de2b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56129de0e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56129de0e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5612977ccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56129772db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561297728355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5612977bec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56129a78df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56129a78df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56129a78df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56129a78df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56129a78df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56129a78df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56129a78df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56129a78df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56129a78df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56129a78df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56129ca22f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56129974fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56129975abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561299506c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561299506c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561299507738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561299506874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561299506874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561299506874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56129de10abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56129de19928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56129de01699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56129de2c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb336cdd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561297726b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e, Step #5: \012\012\012<E><E><E><E><E><E><E><E><E><E><E><E><E><E><E></E><E></E></E></E></E></E></E></E></E></E></E></E></E></E></E></E> Step #5: artifact_prefix='./'; Test unit written to ./oom-b6c95009380d1dd6346abad3e2511fc7983a9a3a Step #5: Base64: CgoKPEU+PEU+PEU+PEU+PEU+PEU+PEU+PEU+PEU+PEU+PEU+PEU+PEU+PEU+PEU+PC9FPjxFPjwvRT48L0U+PC9FPjwvRT48L0U+PC9FPjwvRT48L0U+PC9FPjwvRT48L0U+PC9FPjwvRT48L0U+PC9FPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4226 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3831793165 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eacf71b810, 0x55eacf90501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eacf905020,0x55ead179d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b6c95009380d1dd6346abad3e2511fc7983a9a3a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5274 processed earlier; will process 5755 files now Step #5: ==152212== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eac62109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eacc875898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eacc8585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eacc8584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eac6216d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eac6177b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eac6172355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eac6208c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eac91d7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eac91d7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eac91d7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eac91d7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eac91d7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eac91d7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eac91d7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eac91d7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eac91d7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eac91d7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eacb46cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eac8199b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eac81a4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eac7f50c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eac7f50c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eac7f51738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eac7f50874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eac7f50874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eac7f50874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eacc85aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eacc863928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eacc84b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eacc876112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b21084082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eac6170b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x39,0x3b,0x39,0x39,0x39,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x39, Step #5: \333\200\333\20099;999\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000 \000\000\000\000\000\000\000\000\000\002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000-\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0009 Step #5: artifact_prefix='./'; Test unit written to ./oom-dcb6e1b0dc98f8ea6d72551a9f27b960b5943022 Step #5: Base64: 24DbgDk5Ozk5OQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAAAAtAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4227 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3832291120 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e8b2348810, 0x55e8b253201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e8b2532020,0x55e8b43ca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dcb6e1b0dc98f8ea6d72551a9f27b960b5943022' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5275 processed earlier; will process 5754 files now Step #5: ==152248== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e8a8e3d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e8af4a2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e8af4855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e8af4854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e8a8e43d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e8a8da4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e8a8d9f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e8a8e35c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e8abe04f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e8abe04f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e8abe04f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e8abe04f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e8abe04f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e8abe04f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e8abe04f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e8abe04f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e8abe04f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e8abe04f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e8ae099f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e8aadc6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e8aadd1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e8aab7dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e8aab7dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e8aab7e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e8aab7d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e8aab7d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e8aab7d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e8af487abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e8af490928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e8af478699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e8af4a3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f05ca8ac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e8a8d9db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x4f,0xa,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24, Step #5: dO\012$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ Step #5: artifact_prefix='./'; Test unit written to ./oom-55a5940f3e11343a024f93647149aa7cb0e02b2f Step #5: Base64: ZE8KJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4228 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3832814979 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aaa957b810, 0x55aaa976501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aaa9765020,0x55aaab5fd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/55a5940f3e11343a024f93647149aa7cb0e02b2f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5276 processed earlier; will process 5753 files now Step #5: #1 pulse cov: 3764 ft: 3765 exec/s: 0 rss: 176Mb Step #5: ==152284== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aaa00709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aaa66d5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aaa66b85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aaa66b84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aaa0076d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa9ffd7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa9ffd2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aaa0068c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aaa3037f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aaa3037f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aaa3037f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aaa3037f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aaa3037f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aaa3037f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aaa3037f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aaa3037f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aaa3037f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aaa3037f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aaa52ccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aaa1ff9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aaa2004be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aaa1db0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aaa1db0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aaa1db1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aaa1db0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aaa1db0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aaa1db0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aaa66baabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aaa66c3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aaa66ab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aaa66d6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f518c1de082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa9ffd0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x28,0xa,0x0,0x1a,0x24,0xa,0x22,0x9,0x4,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x27,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x0,0xa,0x28,0xa,0x0,0x1a,0x24,0xa,0x22,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x5b,0x0,0x9,0x9,0x9,0x0,0x2,0x0,0xa,0x28,0xa,0x0,0x1a,0x24,0xa,0x22,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0xa,0x0,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9, Step #5: \012(\012\000\032$\012\"\011\004\011\011\011\011\011\011\011'\011\011\011\011\011\011\011\011\011\011\011\011\011\000\012(\012\000\032$\012\"\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011[\000\011\011\011\000\002\000\012(\012\000\032$\012\"\011\011\011\011\011\011\011\011\011\011\011\011\011\012\000\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-4b2e02f57df9348fc42f8d88ba13dd06dea345c9 Step #5: Base64: CigKABokCiIJBAkJCQkJCQknCQkJCQkJCQkJCQkJCQAKKAoAGiQKIgkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJWwAJCQkAAgAKKAoAGiQKIgkJCQkJCQkJCQkJCQkKAAkJCQkJCQkJCQkJCQkJCQkJCQk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4229 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3833363001 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557f110e7810, 0x557f112d101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557f112d1020,0x557f131690e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4b2e02f57df9348fc42f8d88ba13dd06dea345c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5278 processed earlier; will process 5751 files now Step #5: ==152320== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557f07bdc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f0e241898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f0e2245dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f0e2244fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f07be2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f07b43b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f07b3e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f07bd4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f0aba3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f0aba3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f0aba3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f0aba3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f0aba3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f0aba3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f0aba3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f0aba3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f0aba3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f0aba3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f0ce38f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f09b65b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f09b70be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f0991cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f0991cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f0991d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f0991c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f0991c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f0991c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f0e226abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f0e22f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f0e217699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f0e242112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0743fd8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f07b3cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x32,0x35,0x36,0x26,0x31,0x3b,0x78,0x9,0x9,0x9,0x2e,0x57,0x57,0x38,0x5f,0x69,0x31,0x3d,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x78,0x9,0x9,0x9,0x2e,0x57,0x3b,0x78,0x9,0x3b,0x78,0x9,0x9,0x9,0x2e,0x57,0x31,0x39,0x76,0x76,0x76,0x7a,0x31,0x39,0x32,0x3d,0x78,0x9,0x3b,0x78,0x9,0x3b,0x78,0x9,0x9,0x9,0x2e,0x5f,0x6f,0x65,0x76,0x7a,0x31,0x39,0x32,0x3d,0x78,0x9,0x3b,0x78,0x9,0x3b,0x78,0x9,0x9,0x9,0x2e,0x5f,0x6f,0x65,0x39,0x34,0x37,0x31,0x39,0x34,0x37,0x31,0x5f,0x75,0x31,0x36,0x3b,0x22,0x22,0x2b,0x78,0xa,0xff,0xff,0x11,0x0,0x0,0x30,0x35,0x37,0x32,0x37,0x73, Step #5: -256&1;x\011\011\011.WW8_i1=||||||||x\011\011\011.W;x\011;x\011\011\011.W19vvvz192=x\011;x\011;x\011\011\011._oevz192=x\011;x\011;x\011\011\011._oe94719471_u16;\"\"+x\012\377\377\021\000\00005727s Step #5: artifact_prefix='./'; Test unit written to ./oom-884d642cfd7756c6d80e92b5b8cd25f2103bd0fd Step #5: Base64: LTI1NiYxO3gJCQkuV1c4X2kxPXx8fHx8fHx8eAkJCS5XO3gJO3gJCQkuVzE5dnZ2ejE5Mj14CTt4CTt4CQkJLl9vZXZ6MTkyPXgJO3gJO3gJCQkuX29lOTQ3MTk0NzFfdTE2OyIiK3gK//8RAAAwNTcyN3M= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4230 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3833869656 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55669338f810, 0x55669357901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556693579020,0x5566954110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/884d642cfd7756c6d80e92b5b8cd25f2103bd0fd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5279 processed earlier; will process 5750 files now Step #5: ==152356== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556689e849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5566904e9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5566904cc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5566904cc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556689e8ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556689debb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556689de6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556689e7cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55668ce4bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55668ce4bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55668ce4bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55668ce4bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55668ce4bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55668ce4bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55668ce4bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55668ce4bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55668ce4bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55668ce4bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55668f0e0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55668be0db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55668be18be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55668bbc4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55668bbc4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55668bbc5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55668bbc4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55668bbc4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55668bbc4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5566904ceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5566904d7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5566904bf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5566904ea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa1a771d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556689de4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x66,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x39,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0x3b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x8,0x3a,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x38,0x30,0x39,0x3a,0x3a,0x39,0x6c,0x79,0x66,0x66,0x67,0x2b,0x2f,0x76,0x38,0x7f,0x65,0x0,0x7f,0x66,0xc3,0x9f,0x3b,0x67,0x3f,0x49,0x7f,0x7f,0x12,0x6d,0x0,0x0,0x0,0x0,0x74,0x67,0x6c,0x79,0x67,0x7f,0x66,0x3b,0x67,0x66,0x3f,0x3f,0x6e, Step #5: tf::::::9-BEGIN -----\012N\012=;=\012=\012=\012=\012=\012=\012=\000\000\000\000\000\001\000\000\000\000\000\000\010:9223372036854775809::9lyffg+/v8\177e\000\177f\303\237;g?I\177\177\022m\000\000\000\000tglyg\177f;gf??n Step #5: artifact_prefix='./'; Test unit written to ./oom-5eff39abeed9ad908217221fe8b789645362c3d8 Step #5: Base64: dGY6Ojo6Ojo5LUJFR0lOIC0tLS0tCk4KPTs9Cj0KPQo9Cj0KPQo9AAAAAAABAAAAAAAACDo5MjIzMzcyMDM2ODU0Nzc1ODA5Ojo5bHlmZmcrL3Y4f2UAf2bDnztnP0l/fxJtAAAAAHRnbHlnf2Y7Z2Y/P24= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4231 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3834382149 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557093cfb810, 0x557093ee501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557093ee5020,0x557095d7d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5eff39abeed9ad908217221fe8b789645362c3d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5280 processed earlier; will process 5749 files now Step #5: #1 pulse cov: 3697 ft: 3698 exec/s: 0 rss: 176Mb Step #5: ==152392== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55708a7f09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557090e55898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557090e385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557090e384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55708a7f6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55708a757b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55708a752355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55708a7e8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55708d7b7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55708d7b7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55708d7b7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55708d7b7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55708d7b7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55708d7b7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55708d7b7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55708d7b7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55708d7b7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55708d7b7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55708fa4cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55708c779b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55708c784be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55708c530c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55708c530c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55708c531738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55708c530874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55708c530874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55708c530874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557090e3aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557090e43928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557090e2b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557090e56112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5545dab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55708a750b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x70,0x70,0x70,0x70,0x70,0x70,0xa,0x47,0x47,0x47,0x57,0x47,0x47,0x47,0x47,0x66,0x66,0x66,0x66,0x66,0x66,0x6e,0x66,0x2b,0x2f,0x76,0x39,0x66,0x27,0x66,0x66,0x66,0x66,0x2d,0xa,0x47,0x2d,0x2d,0x49,0x20,0x2d,0x4e,0x2d,0x2d,0xe2,0x80,0xaa,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0xe2,0x80,0xaa,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0xe2,0x80,0xaa,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x66,0x66,0x66,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x0,0x91,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: \012pppppp\012GGGWGGGGffffffnf+/v9f'ffff-\012G--I -N--\342\200\252----BEG\011N -----\012`-\342\200\252----BEG\011N -----\012`-\342\200\252----BEG\011fffGGGGGGG\000\221 ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-576028a354d895671f81489c2128afb66a5aad4e Step #5: Base64: CnBwcHBwcApHR0dXR0dHR2ZmZmZmZm5mKy92OWYnZmZmZi0KRy0tSSAtTi0t4oCqLS0tLUJFRwlOIC0tLS0tCmAt4oCqLS0tLUJFRwlOIC0tLS0tCmAt4oCqLS0tLUJFRwlmZmZHR0dHR0dHAJEgLS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4232 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3835057241 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55afd7b7f810, 0x55afd7d6901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55afd7d69020,0x55afd9c010e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/576028a354d895671f81489c2128afb66a5aad4e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5282 processed earlier; will process 5747 files now Step #5: #1 pulse cov: 3924 ft: 3925 exec/s: 0 rss: 176Mb Step #5: ==152428== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55afce6749c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55afd4cd9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55afd4cbc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55afd4cbc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55afce67ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55afce5dbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55afce5d6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55afce66cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55afd163bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55afd163bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55afd163bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55afd163bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55afd163bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55afd163bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55afd163bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55afd163bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55afd163bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55afd163bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55afd38d0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55afd05fdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55afd0608be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55afd03b4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55afd03b4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55afd03b5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55afd03b4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55afd03b4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55afd03b4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55afd4cbeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55afd4cc7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55afd4caf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55afd4cda112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2f8a5df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55afce5d4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0xe1,0x9f,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xbe, Step #5: P\341\237\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\276 Step #5: artifact_prefix='./'; Test unit written to ./oom-2f9fd0cf50dad836ff96976623feb5ac936ed7be Step #5: Base64: UOGfpqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampr4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4233 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3835597951 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e2eeb8810, 0x563e2f0a201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e2f0a2020,0x563e30f3a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f9fd0cf50dad836ff96976623feb5ac936ed7be' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5284 processed earlier; will process 5745 files now Step #5: ==152464== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563e259ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e2c012898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e2bff55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e2bff54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e259b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e25914b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e2590f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e259a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e28974f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e28974f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e28974f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e28974f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e28974f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e28974f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e28974f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e28974f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e28974f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e28974f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e2ac09f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e27936b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e27941be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e276edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e276edc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e276ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e276ed874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e276ed874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e276ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e2bff7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e2c000928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e2bfe8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e2c013112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f978d73e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e2590db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x70,0x70,0x70,0x70,0x70,0x70,0xa,0x47,0x47,0x47,0x57,0x47,0x47,0x47,0x47,0x66,0x66,0x66,0x66,0x66,0x66,0x6e,0x66,0x2b,0x2f,0x76,0x39,0x66,0x27,0x66,0x66,0x66,0x66,0x2d,0xa,0x47,0x2d,0x2d,0x49,0x20,0x2d,0x4e,0x2d,0x2d,0xa,0x47,0x47,0x47,0x57,0x47,0x47,0x47,0x47,0x66,0x66,0x66,0x66,0x66,0x66,0x6e,0x66,0x2b,0x2f,0x76,0x39,0x66,0x27,0x66,0x66,0x66,0x66,0x2d,0xa,0x47,0x47,0x47,0x2e,0x47,0x47,0x47,0x47,0x66,0x66,0x66,0x66,0x66,0x66,0x6e,0x66,0x2b,0x2f,0x76,0x27,0x66,0x66,0x39,0x66,0x66,0x66,0x66,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x0,0x91,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: \012pppppp\012GGGWGGGGffffffnf+/v9f'ffff-\012G--I -N--\012GGGWGGGGffffffnf+/v9f'ffff-\012GGG.GGGGffffffnf+/v'ff9ffffGGGGGGG\000\221 ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-c1705f759e2413daeca6f49f327512f4d4517ece Step #5: Base64: CnBwcHBwcApHR0dXR0dHR2ZmZmZmZm5mKy92OWYnZmZmZi0KRy0tSSAtTi0tCkdHR1dHR0dHZmZmZmZmbmYrL3Y5ZidmZmZmLQpHR0cuR0dHR2ZmZmZmZm5mKy92J2ZmOWZmZmZHR0dHR0dHAJEgLS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4234 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3836098030 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562b20c43810, 0x562b20e2d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562b20e2d020,0x562b22cc50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c1705f759e2413daeca6f49f327512f4d4517ece' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5285 processed earlier; will process 5744 files now Step #5: ==152500== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562b177389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562b1dd9d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562b1dd805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562b1dd804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b1773ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b1769fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b1769a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b17730c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b1a6fff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b1a6fff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b1a6fff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b1a6fff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b1a6fff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b1a6fff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b1a6fff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b1a6fff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b1a6fff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b1a6fff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562b1c994f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b196c1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b196ccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b19478c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b19478c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b19479738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b19478874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b19478874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b19478874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562b1dd82abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562b1dd8b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562b1dd73699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562b1dd9e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f352d87f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b17698b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x30,0x4d,0x46,0x65,0x57,0x48,0x77,0x42,0x63,0x6f,0x61,0x61,0x71,0x59,0x70,0x2b,0x6a,0x6d,0x47,0x4c,0x6c,0x43,0x41,0x41,0x42,0x73,0x54,0x53,0x2b,0x58,0x4e,0x49,0x53,0x7a,0x56,0x75,0x6a,0x77,0x6f,0x30,0x54,0x45,0xa,0x66,0x61,0x6d,0x69,0x6c,0x79,0x20,0x39,0x30,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x31,0x34,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x33, Step #5: onion-key\012ntor-onion-key v0MFeWHwBcoaaqYp+jmGLlCAABsTS+XNISzVujwo0TE\012family 9022222222222222222222142222222222222223 Step #5: artifact_prefix='./'; Test unit written to ./oom-9e783b5962589f721467c47a3402563340a6b70c Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHYwTUZlV0h3QmNvYWFxWXAram1HTGxDQUFCc1RTK1hOSVN6VnVqd28wVEUKZmFtaWx5IDkwMjIyMjIyMjIyMjIyMjIyMjIyMjIxNDIyMjIyMjIyMjIyMjIyMjM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4235 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3836598249 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5632de37c810, 0x5632de56601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5632de566020,0x5632e03fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9e783b5962589f721467c47a3402563340a6b70c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5286 processed earlier; will process 5743 files now Step #5: ==152536== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5632d4e719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5632db4d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5632db4b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5632db4b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5632d4e77d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5632d4dd8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5632d4dd3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5632d4e69c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5632d7e38f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5632d7e38f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5632d7e38f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5632d7e38f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5632d7e38f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5632d7e38f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5632d7e38f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5632d7e38f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5632d7e38f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5632d7e38f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5632da0cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5632d6dfab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5632d6e05be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5632d6bb1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5632d6bb1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5632d6bb2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5632d6bb1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5632d6bb1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5632d6bb1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5632db4bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5632db4c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5632db4ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5632db4d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f497f4cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5632d4dd1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x70,0x70,0x70,0x70,0x70,0x70,0xa,0x47,0x47,0x47,0x57,0x47,0x47,0x47,0x47,0x66,0x66,0x66,0x66,0x66,0x66,0x6e,0x66,0x2b,0x2f,0x76,0x38,0x66,0x27,0x66,0x66,0x66,0x66,0x2d,0xa,0x47,0x2d,0x2d,0x49,0x20,0x2d,0x4e,0x2d,0x2d,0xe2,0x80,0xaa,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0xe2,0x80,0xaa,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0xe2,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x52,0x47,0x9,0x66,0x66,0x66,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x0,0x91,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: \012pppppp\012GGGWGGGGffffffnf+/v8f'ffff-\012G--I -N--\342\200\252----BEG\011N -----\012`-\342\200\252----BEG\011N -----\012`-\342\377\377\377\377\377\377\377RG\011fffGGGGGGG\000\221 ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-142ba223f4cc41f2319650815265a3ab7c6cbbdc Step #5: Base64: CnBwcHBwcApHR0dXR0dHR2ZmZmZmZm5mKy92OGYnZmZmZi0KRy0tSSAtTi0t4oCqLS0tLUJFRwlOIC0tLS0tCmAt4oCqLS0tLUJFRwlOIC0tLS0tCmAt4v////////9SRwlmZmZHR0dHR0dHAJEgLS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4236 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3837222981 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555876784810, 0x55587696e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55587696e020,0x5558788060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/142ba223f4cc41f2319650815265a3ab7c6cbbdc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5287 processed earlier; will process 5742 files now Step #5: ==152572== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55586d2799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5558738de898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5558738c15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5558738c14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55586d27fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55586d1e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55586d1db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55586d271c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555870240f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555870240f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555870240f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555870240f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555870240f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555870240f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555870240f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555870240f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555870240f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555870240f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5558724d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55586f202b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55586f20dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55586efb9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55586efb9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55586efba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55586efb9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55586efb9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55586efb9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5558738c3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5558738cc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5558738b4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5558738df112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda6bd3b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55586d1d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x39,0x3b,0x39,0x39,0x39,0x0,0x0,0x0,0x0,0x0,0x0,0x25,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3b,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x39, Step #5: \333\200\333\20099;999\000\000\000\000\000\000%\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000;\000\000\000\000\000\000 \000\000\000\000\000\0009 Step #5: artifact_prefix='./'; Test unit written to ./oom-018db0eccacabc42599cd965fd1c143b23184d75 Step #5: Base64: 24DbgDk5Ozk5OQAAAAAAACUAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA7AAAAAAAAIAAAAAAAADk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4237 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3837725637 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d6f380810, 0x556d6f56a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d6f56a020,0x556d714020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/018db0eccacabc42599cd965fd1c143b23184d75' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5288 processed earlier; will process 5741 files now Step #5: ==152608== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556d65e759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d6c4da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d6c4bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d6c4bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d65e7bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d65ddcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d65dd7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d65e6dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d68e3cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d68e3cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d68e3cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d68e3cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d68e3cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d68e3cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d68e3cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d68e3cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d68e3cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d68e3cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d6b0d1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d67dfeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d67e09be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d67bb5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d67bb5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d67bb6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d67bb5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d67bb5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d67bb5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d6c4bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d6c4c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d6c4b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d6c4db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff1cf959082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d65dd5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0x20,0x75,0x5b,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0xa,0x6d,0xa,0x79,0xd,0x28,0x53,0x3a,0xd6,0xb7,0x3a,0x7c,0x52,0x3a,0xd6,0xbf,0x7c,0x52,0x3a,0xd6,0xbf,0xd6,0xbf,0x7c,0x52,0x3a,0xd6,0xbf,0x3a,0x3a,0x7c,0x53,0x3a,0xd6,0xb7,0x7a,0x7c,0x71,0x3a,0xd6,0xbf,0x2e,0x7c,0x52,0x3a,0xd6,0xb7,0x2e,0x7c,0x52,0x3a,0xd6,0xbf,0x32,0x7c,0x53,0x3a,0xd6,0xb7,0x2e,0x7c,0x52,0x3a,0xd6,0xbf,0x7c,0x52,0x3a,0xd6,0xbf,0x3a,0x7c,0x73,0x3a,0xd6,0xbf,0x2e,0x7c,0x4d,0x3a,0xd6,0xbf,0x53,0x7c,0x52,0x3a,0xd6,0xbf,0x3a,0x7c,0x53,0x53,0x3a,0xd6,0xbf, Step #5: <!DOCTYPE u[<!ATTLIST\012m\012y\015(S:\326\267:|R:\326\277|R:\326\277\326\277|R:\326\277::|S:\326\267z|q:\326\277.|R:\326\267.|R:\326\2772|S:\326\267.|R:\326\277|R:\326\277:|s:\326\277.|M:\326\277S|R:\326\277:|SS:\326\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-4ce4c30b66d85ee8f91199f818ea0a26e4fa6bf3 Step #5: Base64: PCFET0NUWVBFIHVbPCFBVFRMSVNUCm0KeQ0oUzrWtzp8UjrWv3xSOta/1r98UjrWvzo6fFM61rd6fHE61r8ufFI61rcufFI61r8yfFM61rcufFI61r98UjrWvzp8czrWvy58TTrWv1N8UjrWvzp8U1M61r8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4238 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3838226581 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5560bc6f0810, 0x5560bc8da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5560bc8da020,0x5560be7720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4ce4c30b66d85ee8f91199f818ea0a26e4fa6bf3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5289 processed earlier; will process 5740 files now Step #5: #1 pulse cov: 4180 ft: 4181 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 11492 ft: 12375 exec/s: 0 rss: 197Mb Step #5: ==152644== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5560b31e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5560b984a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5560b982d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5560b982d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5560b31ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5560b314cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5560b3147355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5560b31ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5560b61acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5560b61acf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5560b61acf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5560b61acf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5560b61acf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5560b61acf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5560b61acf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5560b61acf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5560b61acf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5560b61acf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5560b8441f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5560b516eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5560b5179be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5560b4f25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5560b4f25c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5560b4f26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5560b4f25874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5560b4f25874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5560b4f25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5560b982fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5560b9838928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5560b9820699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5560b984b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f24fb7e7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5560b3145b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x34,0x3c,0x74,0x65,0x78,0x74,0x3e,0x3a,0x35,0x33,0x71,0x75,0x6f,0x2d,0x39,0x3b,0x2d,0xa,0x26,0x23,0x37,0x30,0x34,0x38,0x3b,0x25,0x33,0x33,0x32,0xc2,0xb3,0xa,0xc2,0xb3,0xa,0x2d,0x34,0x33,0x36,0x36,0x33,0x34,0xa,0xa,0xc2,0xb3,0xa,0xc2,0xb3,0xa,0xc2,0xb3,0xa,0xc2,0xb3,0xa,0xde,0xaf,0xa,0xc2,0xb3,0xa,0xc2,0xb3,0xc2,0xb3,0xa,0xc2,0xb3,0xa,0xc2,0xb3,0xa,0xc2,0xb3,0xa,0xc2,0xb3,0xc2,0xb3,0x25,0x2d,0x33,0x32,0x37,0x36,0x39,0x20,0x3b,0x26,0x23,0x33,0x34,0x30,0x36,0x3b,0x20,0x20,0x20,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg>4<text>:53quo-9;-\012&#7048;%332\302\263\012\302\263\012-436634\012\012\302\263\012\302\263\012\302\263\012\302\263\012\336\257\012\302\263\012\302\263\302\263\012\302\263\012\302\263\012\302\263\012\302\263\302\263%-32769 ;&#3406; </text></svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-3828ceccb3cf2822c8e5f87ced468fc8d7d65baf Step #5: Base64: PHN2Zz40PHRleHQ+OjUzcXVvLTk7LQomIzcwNDg7JTMzMsKzCsKzCi00MzY2MzQKCsKzCsKzCsKzCsKzCt6vCsKzCsKzwrMKwrMKwrMKwrMKwrPCsyUtMzI3NjkgOyYjMzQwNjsgICA8L3RleHQ+PC9zdmc+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4239 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3838825072 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556049d02810, 0x556049eec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556049eec020,0x55604bd840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3828ceccb3cf2822c8e5f87ced468fc8d7d65baf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5292 processed earlier; will process 5737 files now Step #5: #1 pulse cov: 11573 ft: 11574 exec/s: 0 rss: 196Mb Step #5: ==152680== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5560407f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556046e5c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556046e3f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556046e3f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5560407fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55604075eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556040759355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5560407efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5560437bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5560437bef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5560437bef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5560437bef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5560437bef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5560437bef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5560437bef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5560437bef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5560437bef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5560437bef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556045a53f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556042780b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55604278bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556042537c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556042537c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556042538738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556042537874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556042537874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556042537874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556046e41abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556046e4a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556046e32699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556046e5d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6786816082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556040757b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0xa,0x69,0x24,0x7f,0x5d,0x32,0x2e,0x32,0x33,0x2f,0x10,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x9,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x2e,0x2f,0x73,0x20,0x37,0x20,0x30,0x20,0x32,0x10,0x20,0x32,0x10,0x2e,0x2f,0x2d,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x32,0x10,0x20,0x2d,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x24, Step #5: .\012i$\177]2.23/\020================\011========================================./s 7 0 2\020 2\020./-\177\177\177\177\177\177\177\177\177\177\177\177\1772\020 -\177\177\177\177\177\177\177\177\177\177o\000\000C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-dda1e575155d958b40f8e893301a69f7c9b0b8c1 Step #5: Base64: LgppJH9dMi4yMy8QPT09PT09PT09PT09PT09PQk9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Li9zIDcgMCAyECAyEC4vLX9/f39/f39/f39/f38yECAtf39/f39/f39/f28AAEMk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4240 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3839400903 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cbbd11a810, 0x55cbbd30401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cbbd304020,0x55cbbf19c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dda1e575155d958b40f8e893301a69f7c9b0b8c1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5294 processed earlier; will process 5735 files now Step #5: ==152716== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cbb3c0f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cbba274898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cbba2575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cbba2574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cbb3c15d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cbb3b76b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cbb3b71355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cbb3c07c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cbb6bd6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cbb6bd6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cbb6bd6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cbb6bd6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cbb6bd6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cbb6bd6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cbb6bd6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cbb6bd6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cbb6bd6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cbb6bd6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cbb8e6bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cbb5b98b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cbb5ba3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cbb594fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cbb594fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cbb5950738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cbb594f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cbb594f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cbb594f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cbba259abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cbba262928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cbba24a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cbba275112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feac2cf7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cbb3b6fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x31,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x3a,0x11,0x2d,0xf,0x29,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x3a,0x24,0x2d,0x5b,0xee,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\000/\000\017\017\017\017\0171-\017[\017\0171-\017[1&1&\021:\021-\017\017\017\017\0171\021\0171\017s [8A\000\017\017\017\0171\017-1[&\021:\021:\021-\017)\017\017\017\0171\021\0171\017s [8A\000\017\017\017\0171\017-1[&\021:\021-\017\017\017\017\0171\021\0171\021-::$-[\356$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-046c3fe640f68e6dc0740bab30a5d267f8cdb329 Step #5: Base64: JAAALwAAAC8AAC8ADw8PDw8xLQ9bDw8xLQ9bMSYxJhE6ES0PDw8PDzERDzEPcyBbOEEADw8PDzEPLTFbJhE6EToRLQ8pDw8PDzERDzEPcyBbOEEADw8PDzEPLTFbJhE6ES0PDw8PDzERDzERLTo6JC1b7iRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4241 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3839917109 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557f083e9810, 0x557f085d301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557f085d3020,0x557f0a46b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/046c3fe640f68e6dc0740bab30a5d267f8cdb329' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5295 processed earlier; will process 5734 files now Step #5: #1 pulse cov: 11579 ft: 11580 exec/s: 0 rss: 192Mb Step #5: ==152752== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557efeede9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f05543898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f055265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f055264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557efeee4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557efee45b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557efee40355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557efeed6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f01ea5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f01ea5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f01ea5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f01ea5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f01ea5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f01ea5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f01ea5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f01ea5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f01ea5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f01ea5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f0413af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f00e67b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f00e72be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f00c1ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f00c1ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f00c1f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f00c1e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f00c1e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f00c1e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f05528abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f05531928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f05519699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f05544112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f762e085082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557efee3eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x1d,0x0,0x0,0x0,0x4,0x0,0x0,0x0,0x2,0x0,0x1,0x0,0x0,0x0,0x34,0x72,0x74,0x73,0x70,0x3a,0x2f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x57,0x5f,0x30,0x7c,0x7c,0x5f,0x5f,0x5f,0x32,0x2d,0x2d,0x2f,0x32,0x2d,0x2d,0x0,0x11,0x0,0x0,0x0,0x2b,0x2d,0x52,0x61,0x66,0x67,0x65,0x36,0x52,0x54,0x53,0x50,0x2f,0x31,0x2e,0x30,0x20,0x33,0x30,0x32,0x5b,0x36,0x30,0x32,0x5b,0x36,0x30,0x20,0xa,0x4c,0x6f,0x43,0x61,0x74,0x69,0x6f,0x6e,0x3a,0x31,0x5b,0x50,0x30,0x20,0xa, Step #5: \000\035\000\000\000\004\000\000\000\002\000\001\000\000\0004rtsp:/_______________________________W_0||___2--/2--\000\021\000\000\000+-Rafge6RTSP/1.0 302[602[60 \012LoCation:1[P0 \012 Step #5: artifact_prefix='./'; Test unit written to ./oom-67f7904659a21018e7baf821533138188f2bed68 Step #5: Base64: AB0AAAAEAAAAAgABAAAANHJ0c3A6L19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19XXzB8fF9fXzItLS8yLS0AEQAAACstUmFmZ2U2UlRTUC8xLjAgMzAyWzYwMls2MCAKTG9DYXRpb246MVtQMCAK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4242 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3840488109 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f447971810, 0x55f447b5b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f447b5b020,0x55f4499f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/67f7904659a21018e7baf821533138188f2bed68' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5297 processed earlier; will process 5732 files now Step #5: ==152788== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f43e4669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f444acb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f444aae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f444aae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f43e46cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f43e3cdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f43e3c8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f43e45ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f44142df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f44142df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f44142df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f44142df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f44142df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f44142df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f44142df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f44142df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f44142df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f44142df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4436c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4403efb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4403fabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f4401a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f4401a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f4401a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f4401a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f4401a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f4401a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f444ab0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f444ab9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f444aa1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f444acc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf4ea82082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f43e3c6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x68,0x74,0x74,0x70,0x3a,0xd7,0xa4,0xd9,0xa4,0xd9,0xa4,0x2e,0xdf,0xa4,0xd9,0xa4,0xdf,0xa4,0x2e,0xde,0xa4,0xd9,0xa4,0xdf,0xa9,0x2e,0xdd,0xa4,0xd9,0xa4,0xd9,0xa4,0x2e,0xdf,0xa4,0xd9,0xa4,0xdf,0xa9,0x2e,0xdd,0xa4,0xd9,0xa4,0xd9,0xa4,0x2e,0xdf,0xa4,0xd9,0xa4,0xdf,0xa4,0x2e,0xde,0xa4,0xd9,0xa4,0xdf,0xa9,0x2e,0xdd,0xa4,0xd9,0xa4,0xd9,0xa4,0x2e,0xdf,0xa4,0xd9,0xa4,0xdf,0xa9,0x2e,0xdd,0xa4,0xd9,0xa4,0xd9,0xa4,0x2e,0xdf,0xa4,0xd9,0xa4,0xdf,0xa4,0x2e,0xdd,0xa4,0xd9,0xa4,0xd8,0xa4,0x2e,0xdf,0xa4,0xd9,0xa4,0xd9,0xa4,0x2e,0xdf,0xa4,0xd9,0xa4,0xdf,0xa4,0x2e,0xdf,0xa4,0xd9,0xa4,0xdf,0xa4, Step #5: \016http:\327\244\331\244\331\244.\337\244\331\244\337\244.\336\244\331\244\337\251.\335\244\331\244\331\244.\337\244\331\244\337\251.\335\244\331\244\331\244.\337\244\331\244\337\244.\336\244\331\244\337\251.\335\244\331\244\331\244.\337\244\331\244\337\251.\335\244\331\244\331\244.\337\244\331\244\337\244.\335\244\331\244\330\244.\337\244\331\244\331\244.\337\244\331\244\337\244.\337\244\331\244\337\244 Step #5: artifact_prefix='./'; Test unit written to ./oom-3edce4b19da20902f6aa511ecb832dd9bc378cad Step #5: Base64: Dmh0dHA616TZpNmkLt+k2aTfpC7epNmk36ku3aTZpNmkLt+k2aTfqS7dpNmk2aQu36TZpN+kLt6k2aTfqS7dpNmk2aQu36TZpN+pLt2k2aTZpC7fpNmk36Qu3aTZpNikLt+k2aTZpC7fpNmk36Qu36TZpN+k Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4243 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3840996870 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563251af1810, 0x563251cdb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563251cdb020,0x563253b730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3edce4b19da20902f6aa511ecb832dd9bc378cad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5298 processed earlier; will process 5731 files now Step #5: ==152824== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5632485e69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56324ec4b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56324ec2e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56324ec2e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5632485ecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56324854db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563248548355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5632485dec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56324b5adf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56324b5adf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56324b5adf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56324b5adf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56324b5adf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56324b5adf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56324b5adf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56324b5adf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56324b5adf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56324b5adf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56324d842f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56324a56fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56324a57abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56324a326c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56324a326c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56324a327738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56324a326874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56324a326874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56324a326874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56324ec30abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56324ec39928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56324ec21699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56324ec4c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8de8a7d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563248546b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x33,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x34,0x5c,0x37,0x37,0x5c,0x37,0x36,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x35,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x36,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x35,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x36,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x37,0x33, Step #5: \\77\\77\\77\\77\\77\\77\\77\\73\\77\\77\\74\\77\\76\\77\\77\\57\\77\\77\\77\\76\\77\\77\\57\\77\\77\\77\\77\\77\\77\\77\\76\\77\\77\\77\\77\\77\\77\\77\\73 Step #5: artifact_prefix='./'; Test unit written to ./oom-e3b38d3d5246d80e40d4efeb59ef619332bebb16 Step #5: Base64: XDc3XDc3XDc3XDc3XDc3XDc3XDc3XDczXDc3XDc3XDc0XDc3XDc2XDc3XDc3XDU3XDc3XDc3XDc3XDc2XDc3XDc3XDU3XDc3XDc3XDc3XDc3XDc3XDc3XDc3XDc2XDc3XDc3XDc3XDc3XDc3XDc3XDc3XDcz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4244 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3841499971 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564cb5ed5810, 0x564cb60bf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564cb60bf020,0x564cb7f570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e3b38d3d5246d80e40d4efeb59ef619332bebb16' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5299 processed earlier; will process 5730 files now Step #5: ==152860== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564cac9ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564cb302f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564cb30125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564cb30124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564cac9d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564cac931b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564cac92c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564cac9c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564caf991f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564caf991f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564caf991f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564caf991f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564caf991f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564caf991f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564caf991f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564caf991f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564caf991f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564caf991f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564cb1c26f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564cae953b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564cae95ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564cae70ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564cae70ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564cae70b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564cae70a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564cae70a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564cae70a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564cb3014abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564cb301d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564cb3005699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564cb3030112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88c6c60082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564cac92ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x20,0x1,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x7a,0x40,0x3a,0x20,0x1,0x0,0x8,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x7a,0x40,0x3a,0x20,0x1,0x0,0x8,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x25,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x2b, Step #5: / \001\000\010\000\000\000\000\000\010\000\000\000\000\000\010\000z@: \001\000\010-BEGIN -\000-----BEGIN -\000-----BEGIN -\000-----B\000\010\000\000\000\000\000\010\000z@: \001\000\010-BEGIN -\000-----BEGIN -\000%----\012---\000\000\000\000+ Step #5: artifact_prefix='./'; Test unit written to ./oom-18300a8b9eefd442a7f500940abd82452883732c Step #5: Base64: LyABAAgAAAAAAAgAAAAAAAgAekA6IAEACC1CRUdJTiAtAC0tLS0tQkVHSU4gLQAtLS0tLUJFR0lOIC0ALS0tLS1CAAgAAAAAAAgAekA6IAEACC1CRUdJTiAtAC0tLS0tQkVHSU4gLQAlLS0tLQotLS0AAAAAKw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4245 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3842015012 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563598e97810, 0x56359908101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563599081020,0x56359af190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/18300a8b9eefd442a7f500940abd82452883732c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5300 processed earlier; will process 5729 files now Step #5: ==152896== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56358f98c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563595ff1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563595fd45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563595fd44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56358f992d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56358f8f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56358f8ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56358f984c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563592953f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563592953f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563592953f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563592953f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563592953f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563592953f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563592953f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563592953f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563592953f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563592953f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563594be8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563591915b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563591920be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5635916ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5635916ccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5635916cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5635916cc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5635916cc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5635916cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563595fd6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563595fdf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563595fc7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563595ff2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f83b28c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56358f8ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xa,0x7a,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xd,0x3a,0xa,0x27,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x2d,0x3c,0x3f,0x58,0x3f,0x3e,0x27,0x3e,0x5d,0x3e,0x3c,0x3a,0x3e,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0xe3,0x80,0x80,0x26,0x93,0x3a,0x3b,0x26,0x26, Step #5: <!DOCTYPE\012z[<!ENTITY\015:\012'\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011-<?X?>'>]><:>&:;&:;&:;&:;&:;&:;&:;&:;&:;&:;&:;&:;&:;&:;&:;&:;&:;\343\200\200&\223:;&& Step #5: artifact_prefix='./'; Test unit written to ./oom-ba60007c6d346df8a220d6eaa894bd6d57c60c21 Step #5: Base64: PCFET0NUWVBFCnpbPCFFTlRJVFkNOgonCQkJCQkJCQkJCQkJCQkJCQkJCQkJLTw/WD8+Jz5dPjw6PiY6OyY6OyY6OyY6OyY6OyY6OyY6OyY6OyY6OyY6OyY6OyY6OyY6OyY6OyY6OyY6OyY6O+OAgCaTOjsmJg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4246 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3842520379 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556153946810, 0x556153b3001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556153b30020,0x5561559c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba60007c6d346df8a220d6eaa894bd6d57c60c21' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5301 processed earlier; will process 5728 files now Step #5: ==152932== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55614a43b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556150aa0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556150a835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556150a834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55614a441d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55614a3a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55614a39d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55614a433c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55614d402f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55614d402f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55614d402f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55614d402f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55614d402f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55614d402f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55614d402f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55614d402f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55614d402f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55614d402f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55614f697f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55614c3c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55614c3cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55614c17bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55614c17bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55614c17c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55614c17b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55614c17b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55614c17b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556150a85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556150a8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556150a76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556150aa1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f24f3d11082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55614a39bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xa,0x7a,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xd,0x3a,0xa,0x27,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x17,0x17,0x17,0x17,0x17,0x17,0x17,0x17,0x17,0x17,0x17,0x17,0x17,0x17,0x17,0x17,0x17,0x17,0x17,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x29,0x28,0x28,0x28,0x29,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0x26,0x3a,0x3b,0xe3,0x80,0x80,0x26,0x93,0x3a,0x3b,0x26,0x26, Step #5: <!DOCTYPE\012z[<!ENTITY\015:\012'\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011()()()()()()()()()()()()\027\027\027\027\027\027\027\027\027\027\027\027\027\027\027\027\027\027\027()()()()()((();&:;&:;&:;&:;\343\200\200&\223:;&& Step #5: artifact_prefix='./'; Test unit written to ./oom-221192a2d7da373a789b647aba0042ddc7e8d59d Step #5: Base64: PCFET0NUWVBFCnpbPCFFTlRJVFkNOgonCQkJCQkJCQkJCQkJCQkJKCkoKSgpKCkoKSgpKCkoKSgpKCkoKSgpFxcXFxcXFxcXFxcXFxcXFxcXFygpKCkoKSgpKCkoKCgpOyY6OyY6OyY6OyY6O+OAgCaTOjsmJg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4247 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3843026158 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559b4fd1d810, 0x559b4ff0701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559b4ff07020,0x559b51d9f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/221192a2d7da373a789b647aba0042ddc7e8d59d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5302 processed earlier; will process 5727 files now Step #5: ==152968== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559b468129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559b4ce77898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559b4ce5a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559b4ce5a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b46818d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b46779b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b46774355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b4680ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b497d9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b497d9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b497d9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b497d9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b497d9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b497d9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b497d9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b497d9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b497d9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b497d9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559b4ba6ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b4879bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b487a6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b48552c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b48552c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b48553738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b48552874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b48552874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b48552874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559b4ce5cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559b4ce65928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559b4ce4d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559b4ce78112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f963406f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b46772b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2,0x2d,0x1,0x0,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000ID3\002-\001\000\000\000\000ID3\002-\001\000\000\000\000\000\000\000ID3\002-\001\000\000\000ID3\002-\001\000\000\000\000ID3\002\002-\001\000\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-1c5915e212a1c9b2027c0ec7e2d3b134239ea478 Step #5: Base64: BS0tLS0tPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoASUQzAi0BAAAAAElEMwItAQAAAAAAAABJRDMCLQEAAABJRDMCLQEAAAAASUQzAgItAQAACj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KEA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4248 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3843538410 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5625cde2e810, 0x5625ce01801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625ce018020,0x5625cfeb00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c5915e212a1c9b2027c0ec7e2d3b134239ea478' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5303 processed earlier; will process 5726 files now Step #5: ==153004== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5625c49239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5625caf88898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625caf6b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625caf6b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5625c4929d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625c488ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625c4885355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5625c491bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5625c78eaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5625c78eaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5625c78eaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5625c78eaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5625c78eaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5625c78eaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5625c78eaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5625c78eaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5625c78eaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5625c78eaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5625c9b7ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625c68acb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5625c68b7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5625c6663c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5625c6663c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5625c6664738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5625c6663874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5625c6663874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5625c6663874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5625caf6dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5625caf76928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5625caf5e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5625caf89112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb62ce76082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625c4883b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x2d,0x54,0x79,0x70,0x65,0x3a,0x61,0x70,0x70,0x6c,0x69,0x63,0x61,0x74,0x49,0x6f,0x6e,0x2f,0x50,0x6b,0x63,0x73,0x37,0x2d,0x6d,0x69,0x6d,0x65,0xa,0xa,0xa,0x4d,0x49,0x49,0x41,0x4e,0x67,0x59,0x4a,0x4b,0x6f,0x5a,0x49,0x68,0x76,0x63,0x4e,0x41,0x51,0x63,0x45,0x6f,0x43,0x67,0x77,0x67,0x41,0x49,0x42,0x67,0x6a,0x47,0x41,0x4d,0x49,0x41,0x43,0x41,0x67,0x4a,0x41,0x4d,0x49,0x41,0x77,0x46,0x7a,0x45,0x56,0x4d,0x42,0x4d,0x47,0x42,0x4d,0x4f,0x73,0x41,0x41,0x77,0x4d,0x43,0x2f,0x4f,0x7a,0x73,0x34,0x77,0x7a,0x4d,0x2b,0x43,0x58,0x6f,0x67,0x45,0x6e,0x6f,0x52,0x6e,0x74, Step #5: Content-Type:applicatIon/Pkcs7-mime\012\012\012MIIANgYJKoZIhvcNAQcEoCgwgAIBgjGAMIACAgJAMIAwFzEVMBMGBMOsAAwMC/Ozs4wzM+CXogEnoRnt Step #5: artifact_prefix='./'; Test unit written to ./oom-ff5d92545a0416a9c40a7ea67ad118f2558f6370 Step #5: Base64: Q29udGVudC1UeXBlOmFwcGxpY2F0SW9uL1BrY3M3LW1pbWUKCgpNSUlBTmdZSktvWklodmNOQVFjRW9DZ3dnQUlCZ2pHQU1JQUNBZ0pBTUlBd0Z6RVZNQk1HQk1Pc0FBd01DL096czR3ek0rQ1hvZ0Vub1JudA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4249 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3844045199 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5638b4a57810, 0x5638b4c4101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5638b4c41020,0x5638b6ad90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ff5d92545a0416a9c40a7ea67ad118f2558f6370' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5304 processed earlier; will process 5725 files now Step #5: #1 pulse cov: 3954 ft: 3955 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4285 ft: 4804 exec/s: 0 rss: 177Mb Step #5: ==153040== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5638ab54c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5638b1bb1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5638b1b945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5638b1b944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5638ab552d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5638ab4b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5638ab4ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5638ab544c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5638ae513f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5638ae513f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5638ae513f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5638ae513f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5638ae513f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5638ae513f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5638ae513f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5638ae513f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5638ae513f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5638ae513f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5638b07a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5638ad4d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5638ad4e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5638ad28cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5638ad28cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5638ad28d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5638ad28c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5638ad28c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5638ad28c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5638b1b96abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5638b1b9f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5638b1b87699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5638b1bb2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f19cbc9e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5638ab4acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x31,0x24,0x31,0x69,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x30,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7e,0x0,0x0,0xde, Step #5: $1$1i\012=\012=\012=\012=\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000\000\000\000\000\000\000\000\0000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000~\000\000\336 Step #5: artifact_prefix='./'; Test unit written to ./oom-401c47180fe905b9e9bc3e3b3c3f56e4b1e9223f Step #5: Base64: JDEkMWkKPQo9Cj0KPQo9PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0AAAAAAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAH4AAN4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4250 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3844652454 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bd25e72810, 0x55bd2605c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bd2605c020,0x55bd27ef40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/401c47180fe905b9e9bc3e3b3c3f56e4b1e9223f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5307 processed earlier; will process 5722 files now Step #5: ==153076== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bd1c9679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bd22fcc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bd22faf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bd22faf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bd1c96dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bd1c8ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bd1c8c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bd1c95fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bd1f92ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bd1f92ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bd1f92ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bd1f92ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bd1f92ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bd1f92ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bd1f92ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bd1f92ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bd1f92ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bd1f92ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bd21bc3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bd1e8f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bd1e8fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bd1e6a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bd1e6a7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bd1e6a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bd1e6a7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bd1e6a7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bd1e6a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bd22fb1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bd22fba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bd22fa2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bd22fcd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9982373082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bd1c8c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x36,0x2d,0x31,0x2d,0x32,0x31,0x39,0x3a,0x34,0x3a,0x32,0xd9,0x91,0xd9,0x92,0xd9,0x8e,0xd8,0x91,0xd9,0x91,0xd9,0x8e,0xd8,0x91,0xd9,0x92,0xd9,0x92,0xd9,0x8e,0xd9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x91,0xd9,0x98,0xd9,0x91,0xd9,0x8e,0xd8,0x91,0xd9,0x92, Step #5: 6-1-219:4:2\331\221\331\222\331\216\330\221\331\221\331\216\330\221\331\222\331\222\331\216\331\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\221\331\230\331\221\331\216\330\221\331\222 Step #5: artifact_prefix='./'; Test unit written to ./oom-ca2d2dcda7bfa2b81ac53f9c3fec019ecc6cf462 Step #5: Base64: Ni0xLTIxOTo0OjLZkdmS2Y7YkdmR2Y7YkdmS2ZLZjtkAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAkdmY2ZHZjtiR2ZI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4251 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3845162748 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5584ed019810, 0x5584ed20301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5584ed203020,0x5584ef09b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca2d2dcda7bfa2b81ac53f9c3fec019ecc6cf462' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5308 processed earlier; will process 5721 files now Step #5: #1 pulse cov: 3816 ft: 3817 exec/s: 0 rss: 175Mb Step #5: ==153112== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5584e3b0e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5584ea173898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5584ea1565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5584ea1564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5584e3b14d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5584e3a75b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5584e3a70355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5584e3b06c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5584e6ad5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5584e6ad5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5584e6ad5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5584e6ad5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5584e6ad5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5584e6ad5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5584e6ad5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5584e6ad5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5584e6ad5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5584e6ad5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5584e8d6af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5584e5a97b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5584e5aa2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5584e584ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5584e584ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5584e584f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5584e584e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5584e584e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5584e584e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5584ea158abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5584ea161928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5584ea149699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5584ea174112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5fa2a99082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5584e3a6eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x8,0x0,0x7,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x0,0xe2,0x80,0xad,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x0,0x0,0x0,0x0,0x0,0x10,0x0,0x0,0x0,0x0,0x0,0x2e,0x2b,0x42,0xdb,0xca,0xb3,0xbe,0xca,0xb2,0x7c,0xdb,0xf3,0xe0,0xb9,0x80,0xa0,0xf3,0xa0,0x80,0xa8,0xdb,0xbe,0x7c,0xdb,0x2b,0x2b,0xbe,0xf3,0xa0,0x80,0xa8,0xdb,0xf3,0xa0,0x81,0xbe,0xbe,0x7c,0xdb,0xe2,0x80,0xa9,0x2b,0x2b,0xbe,0xca,0xb7,0xf3,0xa0,0x80,0xf3,0xc2,0xa0,0xa0,0x81,0x90,0xe,0xef,0xac,0xac,0xfe,0xff,0xb5,0xab, Step #5: - \010\000\007\000\000\000\000\000\000\000\000\020\000\342\200\255\000\000\000\000\000\000\000\020\000\000\000\000\000\000\000\020\000\000\000\000\000\000\000\000\000\020\000\000\000\000\000\020\000\000\000\000\000.+B\333\312\263\276\312\262|\333\363\340\271\200\240\363\240\200\250\333\276|\333++\276\363\240\200\250\333\363\240\201\276\276|\333\342\200\251++\276\312\267\363\240\200\363\302\240\240\201\220\016\357\254\254\376\377\265\253 Step #5: artifact_prefix='./'; Test unit written to ./oom-a9cba3fc7a230b435325a724281b86fa4542a786 Step #5: Base64: LSAIAAcAAAAAAAAAABAA4oCtAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAAABAAAAAAABAAAAAAAC4rQtvKs77Ksnzb8+C5gKDzoICo27582ysrvvOggKjb86CBvr582+KAqSsrvsq386CA88KgoIGQDu+srP7/tas= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4252 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3845706843 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5633c32c4810, 0x5633c34ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5633c34ae020,0x5633c53460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9cba3fc7a230b435325a724281b86fa4542a786' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5310 processed earlier; will process 5719 files now Step #5: ==153148== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5633b9db99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5633c041e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5633c04015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5633c04014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5633b9dbfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5633b9d20b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5633b9d1b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5633b9db1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5633bcd80f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5633bcd80f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5633bcd80f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5633bcd80f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5633bcd80f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5633bcd80f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5633bcd80f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5633bcd80f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5633bcd80f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5633bcd80f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5633bf015f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5633bbd42b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5633bbd4dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5633bbaf9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5633bbaf9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5633bbafa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5633bbaf9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5633bbaf9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5633bbaf9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5633c0403abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5633c040c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5633c03f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5633c041f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa0d0235082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5633b9d19b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc, Step #5: \343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-9bd757bb2a63fd8acd8d04ed0b6fd74ddfb94c11 Step #5: Base64: 442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7w= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4253 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3846213569 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55654f043810, 0x55654f22d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55654f22d020,0x5565510c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9bd757bb2a63fd8acd8d04ed0b6fd74ddfb94c11' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5311 processed earlier; will process 5718 files now Step #5: ==153184== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556545b389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55654c19d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55654c1805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55654c1804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556545b3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556545a9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556545a9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556545b30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556548afff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556548afff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556548afff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556548afff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556548afff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556548afff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556548afff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556548afff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556548afff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556548afff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55654ad94f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556547ac1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556547accbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556547878c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556547878c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556547879738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556547878874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556547878874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556547878874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55654c182abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55654c18b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55654c173699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55654c19e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff87dba3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556545a98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x31,0x38,0x34,0x34,0x36,0x37,0x34,0x34,0x30,0x37,0x33,0x37,0x30,0x39,0x35,0x35,0x31,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0xf5,0x36,0x31,0x36,0x25,0x21,0xe2,0x31, Step #5: #18446744073709551\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365\365616%!\3421 Step #5: artifact_prefix='./'; Test unit written to ./oom-301165683f684c96015e065ceb36148885e8d2d3 Step #5: Base64: IzE4NDQ2NzQ0MDczNzA5NTUx9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19TYxNiUh4jE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4254 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3846709378 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4a1db4810, 0x55e4a1f9e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4a1f9e020,0x55e4a3e360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/301165683f684c96015e065ceb36148885e8d2d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5312 processed earlier; will process 5717 files now Step #5: ==153220== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e4988a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e49ef0e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e49eef15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e49eef14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4988afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e498810b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e49880b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4988a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e49b870f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e49b870f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e49b870f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e49b870f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e49b870f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e49b870f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e49b870f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e49b870f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e49b870f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e49b870f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e49db05f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e49a832b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e49a83dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e49a5e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e49a5e9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e49a5ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e49a5e9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e49a5e9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e49a5e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e49eef3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e49eefc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e49eee4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e49ef0f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb09f63d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e498809b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x3f,0x3a,0x28,0x3f,0x73,0x74,0x72,0x79,0x20,0x28,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x7c,0x7c,0x24,0x7c,0x24,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x5c,0xde,0x99,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x3b,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x29,0x29,0x7c,0x29,0x7c,0x29,0x7c, Step #5: (?:(?:?:(?stry (:$|$|(?:(?:(?:$|$|$|$|$|$|$||$|$|$|$|$|$|||$|$$|(?:(?:(?:\\\336\231|$|$|$|$|$|$|$;|$|$|$|$)|$|$|$|$|$)|))|)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-09ff5ae56235d4451fd03d86cfa4fcaf44618414 Step #5: Base64: KD86KD86PzooP3N0cnkgKDokfCR8KD86KD86KD86JHwkfCR8JHwkfCR8JHx8JHwkfCR8JHwkfCR8fHwkfCQkfCg/Oig/Oig/OlzemXwkfCR8JHwkfCR8JHwkO3wkfCR8JHwkKXwkfCR8JHwkfCQpfCkpfCl8KXw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4255 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3847226430 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5559d7793810, 0x5559d797d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5559d797d020,0x5559d98150e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/09ff5ae56235d4451fd03d86cfa4fcaf44618414' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5313 processed earlier; will process 5716 files now Step #5: ==153256== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5559ce2889c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5559d48ed898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5559d48d05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5559d48d04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5559ce28ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5559ce1efb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5559ce1ea355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5559ce280c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5559d124ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5559d124ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5559d124ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5559d124ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5559d124ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5559d124ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5559d124ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5559d124ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5559d124ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5559d124ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5559d34e4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5559d0211b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5559d021cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5559cffc8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5559cffc8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5559cffc9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5559cffc8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5559cffc8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5559cffc8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5559d48d2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5559d48db928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5559d48c3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5559d48ee112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf82588082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5559ce1e8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x67,0x6c,0x79,0x66,0x0,0x0,0x1,0x0,0x0,0xa,0x2d,0x42,0x2d,0x2d,0x2d,0x78,0x2d,0x0,0x0,0x0,0x74,0x67,0x6c,0x79,0x67,0x7f,0x66,0x3b,0x67,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x72,0x74,0x73,0x64,0x71,0x6d,0x4,0x43,0x4f,0x26,0x3f,0x67,0x2e,0x45,0x47,0x8,0x6,0x32,0xf,0x73,0x74,0x2d,0x2d,0x2d,0x2d,0x42,0x24,0x2d,0x2d,0x2d,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2d,0x42,0x24,0x47,0x49,0x4e,0x20,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x47,0x49,0x44,0x33,0x0,0x0,0x53,0x16,0x16,0x70,0x10,0x5,0x25,0x33,0x32,0x49,0x4e,0x20,0x2d,0xa,0x2d,0x20,0x33,0x37,0x38, Step #5: tglyf\000\000\001\000\000\012-B---x-\000\000\000tglyg\177f;gf?f;g?trtsdqm\004CO&?g.EG\010\0062\017st----B$---......-B$GIN ..............GID3\000\000S\026\026p\020\005%32IN -\012- 378 Step #5: artifact_prefix='./'; Test unit written to ./oom-0bbb629cf1e7a2d4631248348adcb6e3360cc55d Step #5: Base64: dGdseWYAAAEAAAotQi0tLXgtAAAAdGdseWd/ZjtnZj9mO2c/dHJ0c2RxbQRDTyY/Zy5FRwgGMg9zdC0tLS1CJC0tLS4uLi4uLi1CJEdJTiAuLi4uLi4uLi4uLi4uLkdJRDMAAFMWFnAQBSUzMklOIC0KLSAzNzg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4256 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3847737758 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eff4a49810, 0x55eff4c3301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eff4c33020,0x55eff6acb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0bbb629cf1e7a2d4631248348adcb6e3360cc55d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5314 processed earlier; will process 5715 files now Step #5: ==153292== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55efeb53e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eff1ba3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eff1b865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eff1b864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55efeb544d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55efeb4a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55efeb4a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55efeb536c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55efee505f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55efee505f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55efee505f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55efee505f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55efee505f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55efee505f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55efee505f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55efee505f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55efee505f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55efee505f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eff079af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55efed4c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55efed4d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55efed27ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55efed27ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55efed27f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55efed27e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55efed27e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55efed27e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eff1b88abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eff1b91928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eff1b79699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eff1ba4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fce899c9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55efeb49eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x20,0x26,0x76,0x48,0x48,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x0,0x0,0x1,0x60,0x43,0x4f,0x4d,0x1, Step #5: ID3\002 &vHH`COM\000\000\001`COM\000\000\001`COM\000\000\001`COM\000\000\001`COM\000\000\001`COM\000\000\001`COM\000\000\001`COM\000\000\001`COM\000\000\001`COM\000\000\001`COM\000\000\001`COM\000\000\001`COM\000\000\001`COM\000\000\001`COM\000\000\001`COM\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-e9ab992f9cbbcd13619b119ca41bc15dac19a921 Step #5: Base64: SUQzAiAmdkhIYENPTQAAAWBDT00AAAFgQ09NAAABYENPTQAAAWBDT00AAAFgQ09NAAABYENPTQAAAWBDT00AAAFgQ09NAAABYENPTQAAAWBDT00AAAFgQ09NAAABYENPTQAAAWBDT00AAAFgQ09NAAABYENPTQE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4257 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3848371418 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b36271810, 0x555b3645b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b3645b020,0x555b382f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e9ab992f9cbbcd13619b119ca41bc15dac19a921' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5315 processed earlier; will process 5714 files now Step #5: ==153328== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555b2cd669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b333cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b333ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b333ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b2cd6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b2cccdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b2ccc8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b2cd5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b2fd2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b2fd2df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b2fd2df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b2fd2df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b2fd2df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b2fd2df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b2fd2df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b2fd2df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b2fd2df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b2fd2df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b31fc2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b2ecefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b2ecfabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b2eaa6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b2eaa6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b2eaa7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b2eaa6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b2eaa6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b2eaa6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b333b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b333b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b333a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b333cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c03f84082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b2ccc6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x65,0x24,0x30,0x26,0x26,0x2d,0x65,0x2d,0x65,0x24,0x30,0x26,0x26,0x2d,0x65,0x2d,0x2e,0x32,0x26,0x26,0x2d,0x65,0x24,0x30,0x26,0x26,0x2d,0x65,0x2c,0x24,0x2c,0x66,0x2c,0x64,0x2c,0x31,0x26,0x26,0x2d,0x65,0x24,0x34,0x2d,0x2e,0x32,0x26,0x26,0x2d,0x65,0x24,0x30,0x26,0x26,0x2d,0x65,0x2c,0x24,0x2c,0x66,0x2c,0x2d,0x65,0x24,0x30,0x26,0x26,0x2d,0x65,0x2c,0x24,0x2c,0x66,0x2c,0x64,0x2c,0x31,0x26,0x26,0x2d,0x65,0x24,0x34,0x2d,0x2e,0x32,0x26,0x26,0x2d,0x65,0x24,0x30,0x26,0x26,0x2d,0x65,0x2c,0x24,0x2c,0x66,0x2c,0x64,0x2c,0x31,0x26,0x26,0x2d,0x65,0x24,0x34,0x64,0x2c,0x31,0x26,0x26,0x2d,0x65,0x24,0x34, Step #5: -e$0&&-e-e$0&&-e-.2&&-e$0&&-e,$,f,d,1&&-e$4-.2&&-e$0&&-e,$,f,-e$0&&-e,$,f,d,1&&-e$4-.2&&-e$0&&-e,$,f,d,1&&-e$4d,1&&-e$4 Step #5: artifact_prefix='./'; Test unit written to ./oom-a7bd1cbd172a378d606fd2ab70cf956dd182edc3 Step #5: Base64: LWUkMCYmLWUtZSQwJiYtZS0uMiYmLWUkMCYmLWUsJCxmLGQsMSYmLWUkNC0uMiYmLWUkMCYmLWUsJCxmLC1lJDAmJi1lLCQsZixkLDEmJi1lJDQtLjImJi1lJDAmJi1lLCQsZixkLDEmJi1lJDRkLDEmJi1lJDQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4258 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3848882845 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c9601f6810, 0x55c9603e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c9603e0020,0x55c9622780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a7bd1cbd172a378d606fd2ab70cf956dd182edc3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5316 processed earlier; will process 5713 files now Step #5: #1 pulse cov: 4134 ft: 4135 exec/s: 0 rss: 175Mb Step #5: ==153364== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c956ceb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c95d350898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c95d3335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c95d3334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c956cf1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c956c52b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c956c4d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c956ce3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c959cb2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c959cb2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c959cb2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c959cb2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c959cb2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c959cb2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c959cb2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c959cb2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c959cb2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c959cb2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c95bf47f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c958c74b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c958c7fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c958a2bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c958a2bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c958a2c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c958a2b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c958a2b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c958a2b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c95d335abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c95d33e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c95d326699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c95d351112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc4c2d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c956c4bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x74,0x22,0x32,0x31,0x34,0x37,0x34,0x38,0x37,0x36,0xc9,0xa8,0xc9,0xbe,0x31,0xc9,0xa8,0xc9,0xa8,0xc9,0x9b,0x6f,0xdb,0xa8,0xc9,0xa8,0xc9,0xa8,0xc9,0xa9,0x5b,0x31,0xc9,0xa8,0xc8,0xbe,0x30,0xc9,0xa8,0xc9,0xa8,0xc9,0x9b,0x6b,0xdb,0xa8,0xc9,0xa8,0xc9,0xa8,0xc9,0xa9,0x5b,0xc9,0x99,0x7a,0xc8,0xbe,0x30,0xc9,0xa8,0xc9,0xa8,0x38,0x37,0x36,0xc9,0xa8,0xc9,0xbe,0x31,0xc9,0xa8,0xc9,0xa8,0xc9,0x9b,0x6f,0xdb,0xa8,0xc9,0xa8,0xc9,0xa8,0xc9,0xa9,0x5b,0x31,0xc9,0xa8,0xc8,0xbe,0x30,0xc9,0xa8,0xc9,0xa8,0xc9,0x9b,0x6b,0xdb,0xa8,0xc9,0xa8,0xc9,0xa8,0xc9,0xa9,0x5b,0xc9,0x99,0x7a,0xc8,0xbe,0xd4,0xc9,0xa8, Step #5: HUt\"21474876\311\250\311\2761\311\250\311\250\311\233o\333\250\311\250\311\250\311\251[1\311\250\310\2760\311\250\311\250\311\233k\333\250\311\250\311\250\311\251[\311\231z\310\2760\311\250\311\250876\311\250\311\2761\311\250\311\250\311\233o\333\250\311\250\311\250\311\251[1\311\250\310\2760\311\250\311\250\311\233k\333\250\311\250\311\250\311\251[\311\231z\310\276\324\311\250 Step #5: artifact_prefix='./'; Test unit written to ./oom-30e83d626a841bafd209d97d53a09368830886b5 Step #5: Base64: SFV0IjIxNDc0ODc2yajJvjHJqMmoyZtv26jJqMmoyalbMcmoyL4wyajJqMmba9uoyajJqMmpW8mZesi+MMmoyag4NzbJqMm+McmoyajJm2/bqMmoyajJqVsxyajIvjDJqMmoyZtr26jJqMmoyalbyZl6yL7Uyag= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4259 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3849426946 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c4b1980810, 0x55c4b1b6a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c4b1b6a020,0x55c4b3a020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/30e83d626a841bafd209d97d53a09368830886b5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5318 processed earlier; will process 5711 files now Step #5: ==153400== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c4a84759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c4aeada898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c4aeabd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c4aeabd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c4a847bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c4a83dcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c4a83d7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c4a846dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c4ab43cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c4ab43cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c4ab43cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c4ab43cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c4ab43cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c4ab43cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c4ab43cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c4ab43cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c4ab43cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c4ab43cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c4ad6d1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c4aa3feb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c4aa409be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c4aa1b5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c4aa1b5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c4aa1b6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c4aa1b5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c4aa1b5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c4aa1b5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c4aeabfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c4aeac8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c4aeab0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c4aeadb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ccc037082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c4a83d5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x7b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x31,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x31,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x21,0x4d,0x30,0x57,0x41,0x50,0x52,0x49,0x43,0x56,0x42,0x8,0x46,0x21,0xc8,0x0,0x0, Step #5: ID3\004{\000\000\000\000\000\000\000\000\000\000\000\000\000O\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000z\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000O\000\000\000\000\000\000\000\000\000\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000!M0WAPRICVB\010F!\310\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e1a4a54e0c1e95431f68d6166a9eea05c3ba9cfa Step #5: Base64: SUQzBHsAAAAAAAAAAAAAAAAATwAAAAAAAAAAAAAAAAAAAAAxAAAAAAAAAAAAAAB6AAAAAAAAAAAAAAAAAAAAAAAATwAAAAAAAAAAAAAAAAAxAAAAAAAAAAAAAAAAAAAAAAAAAAAAIU0wV0FQUklDVkIIRiHIAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4260 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3849924868 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3a3dfd810, 0x55a3a3fe701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3a3fe7020,0x55a3a5e7f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e1a4a54e0c1e95431f68d6166a9eea05c3ba9cfa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5319 processed earlier; will process 5710 files now Step #5: ==153436== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a39a8f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3a0f57898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3a0f3a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3a0f3a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a39a8f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a39a859b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a39a854355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a39a8eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a39d8b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a39d8b9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a39d8b9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a39d8b9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a39d8b9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a39d8b9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a39d8b9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a39d8b9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a39d8b9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a39d8b9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a39fb4ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a39c87bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a39c886be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a39c632c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a39c632c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a39c633738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a39c632874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a39c632874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a39c632874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a3a0f3cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a3a0f45928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3a0f2d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3a0f58112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efea18a8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a39a852b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xa,0x45,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xd,0x25,0x20,0x78,0x78,0x20,0x53,0x59,0x53,0x54,0x45,0x4d,0xa,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x6e,0x25,0x30,0x43,0x30,0x78,0x27,0x3e,0x25,0x78,0x78,0x3b,0x25,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x25,0x78,0x78,0x3b,0x25, Step #5: <!DOCTYPE\012E[<!ENTITY\015% xx SYSTEM\012'http://n%0C0x'>%xx;%%xx;%xx;%xx;%%xx;%xx;%xx;%x%xx;%xx;%xx;%%xx;%xx;%xx;%xx;%xx;%%xx;% Step #5: artifact_prefix='./'; Test unit written to ./oom-9d2fd369b21b1c47cc59afd53b125780ef126637 Step #5: Base64: PCFET0NUWVBFCkVbPCFFTlRJVFkNJSB4eCBTWVNURU0KJ2h0dHA6Ly9uJTBDMHgnPiV4eDslJXh4OyV4eDsleHg7JSV4eDsleHg7JXh4OyV4JXh4OyV4eDsleHg7JSV4eDsleHg7JXh4OyV4eDsleHg7JSV4eDsl Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4261 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3850430355 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e7e4b11810, 0x55e7e4cfb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e7e4cfb020,0x55e7e6b930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9d2fd369b21b1c47cc59afd53b125780ef126637' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5320 processed earlier; will process 5709 files now Step #5: ==153472== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e7db6069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e7e1c6b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7e1c4e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7e1c4e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e7db60cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e7db56db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e7db568355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e7db5fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e7de5cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e7de5cdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e7de5cdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e7de5cdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e7de5cdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e7de5cdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e7de5cdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e7de5cdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e7de5cdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e7de5cdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e7e0862f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e7dd58fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e7dd59abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e7dd346c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e7dd346c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e7dd347738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e7dd346874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e7dd346874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e7dd346874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e7e1c50abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e7e1c59928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e7e1c41699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e7e1c6c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2329787082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e7db566b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x18,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x19,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x19,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x19,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x19,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x19,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0xd7,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0x60,0x40,0x40,0x40,0x40,0xa, Step #5: @@@@`@@@@`@@@@\030@@@@`@@@@`@@@@\031@@@@`@@@@`@@@@\031@@@@`@@@@`@@@@\031@@@@`@@@@`@@@@\031@@@@`@@@@`@@@@\031@@@@`@@@@`@@@@\327@@@@`@@@@`@@@@\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-db6e9a197d4cdf5d6ed82575225048ab85e27646 Step #5: Base64: QEBAQGBAQEBAYEBAQEAYQEBAQGBAQEBAYEBAQEAZQEBAQGBAQEBAYEBAQEAZQEBAQGBAQEBAYEBAQEAZQEBAQGBAQEBAYEBAQEAZQEBAQGBAQEBAYEBAQEAZQEBAQGBAQEBAYEBAQEDXQEBAQGBAQEBAYEBAQEAK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4262 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3851060460 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560f8bcd8810, 0x560f8bec201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560f8bec2020,0x560f8dd5a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/db6e9a197d4cdf5d6ed82575225048ab85e27646' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5321 processed earlier; will process 5708 files now Step #5: ==153508== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560f827cd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560f88e32898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560f88e155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560f88e154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560f827d3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560f82734b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560f8272f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560f827c5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560f85794f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560f85794f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560f85794f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560f85794f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560f85794f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560f85794f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560f85794f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560f85794f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560f85794f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560f85794f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560f87a29f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560f84756b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560f84761be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560f8450dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560f8450dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560f8450e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560f8450d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560f8450d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560f8450d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560f88e17abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560f88e20928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560f88e08699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560f88e33112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8e49eed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560f8272db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x3c,0x61,0x3e,0x45,0x3c,0x64,0x3e,0x3c,0x50,0x6b,0x3e,0x3c,0x54,0x67,0x3e,0x3c,0x44,0x3e,0x3c,0x41,0x3e,0x28,0x3c,0x47,0x3e,0x3c,0x53,0x2d,0x3e,0x3c,0x50,0x3e,0x3c,0x45,0x49,0x3e,0x3c,0x49,0x69,0x4d,0x3e,0x3c,0x68,0x4d,0x3e,0x3c,0x7a,0x3e,0x4f,0x3c,0x6f,0x41,0x3e,0x3c,0x53,0x3e,0x3c,0x4e,0x3e,0x3c,0x46,0x3e,0x3c,0x74,0x41,0x3e,0x3c,0x46,0x44,0x3e,0x41,0x3c,0x59,0x45,0x3e,0x3c,0x6c,0x3e,0x3c,0x5a,0x3e,0x3c,0x62,0x3e,0x3c,0x59,0x3e,0x3c,0x74,0x3e,0x2c,0x3c,0x75,0x3e,0x3c,0x52,0x3e,0x3c,0x55,0x45,0x3e,0x3c,0x4d,0x3e,0x3c,0x4f,0x3e,0x3c,0x55,0x3e,0x3c,0x59,0x33,0x3e,0x3c,0x65,0x3e,0x3,0x20, Step #5: /<a>E<d><Pk><Tg><D><A>(<G><S-><P><EI><IiM><hM><z>O<oA><S><N><F><tA><FD>A<YE><l><Z><b><Y><t>,<u><R><UE><M><O><U><Y3><e>\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-182057a782b76767f0e0aecf0eaf12996faea02a Step #5: Base64: LzxhPkU8ZD48UGs+PFRnPjxEPjxBPig8Rz48Uy0+PFA+PEVJPjxJaU0+PGhNPjx6Pk88b0E+PFM+PE4+PEY+PHRBPjxGRD5BPFlFPjxsPjxaPjxiPjxZPjx0Piw8dT48Uj48VUU+PE0+PE8+PFU+PFkzPjxlPgMg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4263 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3851563147 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5630963b4810, 0x56309659e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56309659e020,0x5630984360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/182057a782b76767f0e0aecf0eaf12996faea02a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5322 processed earlier; will process 5707 files now Step #5: ==153544== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56308cea99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56309350e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5630934f15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5630934f14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56308ceafd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56308ce10b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56308ce0b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56308cea1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56308fe70f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56308fe70f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56308fe70f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56308fe70f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56308fe70f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56308fe70f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56308fe70f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56308fe70f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56308fe70f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56308fe70f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563092105f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56308ee32b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56308ee3dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56308ebe9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56308ebe9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56308ebea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56308ebe9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56308ebe9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56308ebe9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5630934f3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5630934fc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5630934e4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56309350f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb3afecc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56308ce09b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x33,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x42,0x45,0x2b,0x49,0x4e,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2b,0x4c,0x54,0x0,0x0,0x0,0x1,0x0,0x3a,0x20,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x4,0x0,0x29,0x12,0x54,0x0,0x0,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x4,0x0,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x5b,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5e,0xdf,0xba,0x5d, Step #5: \023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\0233\023\023\023\023\023\023\023\023\023\023\023\023\023\023BE+IN \012----+LT\000\000\000\001\000: USLT\000\000\000\004\000)\022T\000\000USLT\000\000\000\004\000\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023[\001\000\000\000\000\000\000\000^\337\272] Step #5: artifact_prefix='./'; Test unit written to ./oom-c3b1ee3cb38f7606aa5fd4eed4253bfa1a90e16d Step #5: Base64: ExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMzExMTExMTExMTExMTExNCRStJTiAKLS0tLStMVAAAAAEAOiBVU0xUAAAABAApElQAAFVTTFQAAAAEABMTExMTExMTExMTExMTExNbAQAAAAAAAABe37pd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4264 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3852068498 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560e4be2e810, 0x560e4c01801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560e4c018020,0x560e4deb00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c3b1ee3cb38f7606aa5fd4eed4253bfa1a90e16d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5323 processed earlier; will process 5706 files now Step #5: ==153580== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560e429239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560e48f88898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560e48f6b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560e48f6b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560e42929d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560e4288ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560e42885355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560e4291bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560e458eaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560e458eaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560e458eaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560e458eaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560e458eaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560e458eaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560e458eaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560e458eaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560e458eaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560e458eaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560e47b7ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560e448acb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560e448b7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560e44663c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560e44663c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560e44664738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560e44663874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560e44663874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560e44663874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560e48f6dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560e48f76928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560e48f5e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560e48f89112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f525799c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560e42883b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd,0x27,0xd, Step #5: '\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015'\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-4d9b4b78801172724ecec5e41132f356c8ef49b7 Step #5: Base64: Jw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScNJw0nDScN Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4265 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3852572008 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c08a5c7810, 0x55c08a7b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c08a7b1020,0x55c08c6490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4d9b4b78801172724ecec5e41132f356c8ef49b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5324 processed earlier; will process 5705 files now Step #5: #1 pulse cov: 11089 ft: 11090 exec/s: 0 rss: 192Mb Step #5: ==153616== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c0810bc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c087721898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c0877045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c0877044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c0810c2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c081023b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c08101e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c0810b4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c084083f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c084083f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c084083f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c084083f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c084083f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c084083f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c084083f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c084083f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c084083f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c084083f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c086318f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c083045b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c083050be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c082dfcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c082dfcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c082dfd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c082dfc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c082dfc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c082dfc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c087706abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c08770f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c0876f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c087722112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff74ec8b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c08101cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0xf3,0xa0,0x81,0xba,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b, Step #5: #{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}\363\240\201\272+\012#{}+\012[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[ Step #5: artifact_prefix='./'; Test unit written to ./oom-ce7fbc3f1bd1295ec7aedd633bd00d60cb65dee5 Step #5: Base64: I3t9Kwoje30rCiN7fSsKI3t9Kwoje30rCiN7fSsKI3t9Kwoje30rCiN7fSsKI3t9Kwoje30rCiN7fSsKI3t9Kwoje30rCiN7fSsKI3t986CBuisKI3t9KwpbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4266 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3853137766 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5576071d8810, 0x5576073c201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5576073c2020,0x55760925a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce7fbc3f1bd1295ec7aedd633bd00d60cb65dee5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5326 processed earlier; will process 5703 files now Step #5: ==153652== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5575fdccd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557604332898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5576043155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5576043154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5575fdcd3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5575fdc34b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5575fdc2f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5575fdcc5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557600c94f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557600c94f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557600c94f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557600c94f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557600c94f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557600c94f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557600c94f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557600c94f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557600c94f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557600c94f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557602f29f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5575ffc56b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5575ffc61be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5575ffa0dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5575ffa0dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5575ffa0e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5575ffa0d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5575ffa0d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5575ffa0d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557604317abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557604320928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557604308699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557604333112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f4f71a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5575fdc2db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x76,0x21,0x39,0xa,0x0,0x7d,0x7d,0x7d,0x7d,0xd7,0xaf,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0xe2,0x80,0xad,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0xe2,0x80,0xad,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0x69,0x66,0x7d,0xd7,0xaf,0x2d,0x0,0x7e,0x73,0x74,0x39,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0xd7,0xa3,0x1,0xd7,0xa3,0x2d,0x0, Step #5: #v!9\012\000}}}}\327\257\012+V\012V\012+\342\200\255c\012\363\240\201\264+\012+V\012V\012++c\012\363\240\201\264+\012+V\012V\012+\012\012+\012+c\012\363\240\201\264+\012+V\012V\012+\342\200\255c\012\363\240\201\264+\012+V\012V\012+if}\327\257-\000~st9>>>>>>>>>>>>>>>\327\243\001\327\243-\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0980866fd6edf30559b38d7ae7de81c818a108d0 Step #5: Base64: I3YhOQoAfX19fdevCitWClYKK+KArWMK86CBtCsKK1YKVgorK2MK86CBtCsKK1YKVgorCgorCitjCvOggbQrCitWClYKK+KArWMK86CBtCsKK1YKVgoraWZ9168tAH5zdDk+Pj4+Pj4+Pj4+Pj4+Pj7XowHXoy0A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4267 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3853655162 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d8042ef810, 0x55d8044d901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d8044d9020,0x55d8063710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0980866fd6edf30559b38d7ae7de81c818a108d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5327 processed earlier; will process 5702 files now Step #5: #1 pulse cov: 3719 ft: 3720 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 4076 ft: 4390 exec/s: 0 rss: 175Mb Step #5: #4 pulse cov: 4301 ft: 5154 exec/s: 0 rss: 176Mb Step #5: ==153688== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d7fade49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d801449898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d80142c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d80142c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d7fadead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d7fad4bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d7fad46355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d7faddcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d7fddabf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d7fddabf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d7fddabf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d7fddabf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d7fddabf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d7fddabf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d7fddabf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d7fddabf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d7fddabf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d7fddabf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d800040f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d7fcd6db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d7fcd78be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d7fcb24c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d7fcb24c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d7fcb25738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d7fcb24874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d7fcb24874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d7fcb24874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d80142eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d801437928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d80141f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d80144a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac77cb3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d7fad44b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x30,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x67,0x7b,0x30,0x3e,0x2a,0x7b,0x6c,0x3c,0x67,0x3e,0x3c,0x67,0x3e,0x3c,0x67,0x3e,0x3c,0x67,0x3e,0x3c,0x67,0x3e,0x67,0x2b,0x2a,0x7b,0x6f,0x70,0x61,0x63,0x69,0x74,0x79,0x36,0x35,0x32,0x35,0x31,0x2d,0x39,0x37,0x2c,0x31,0x6e,0x6e,0x2c,0x38,0xd7,0x81,0x70,0x6f,0x36,0x45,0x37,0x7d,0x3c,0x7a,0x67,0x3e,0x3c,0x67,0x3e,0x37,0xd7,0x81,0x70,0x6f,0x37,0x2c,0x31,0x6e,0x6e,0x2c,0x38,0xd7,0x81,0x70,0x6f,0x36,0x45,0x37,0x7d,0x3c,0x7a,0x67,0x3e,0x3c,0x67,0x3e,0x37,0xd7,0x81,0x70,0x6f,0x69,0x6e,0x73,0x30,0x7d,0x31,0x36,0x45,0x37,0x67,0x3d,0x3c, Step #5: <svg>0><style>g{0>*{l<g><g><g><g><g>g+*{opacity65251-97,1nn,8\327\201po6E7}<zg><g>7\327\201po7,1nn,8\327\201po6E7}<zg><g>7\327\201poins0}16E7g=< Step #5: artifact_prefix='./'; Test unit written to ./oom-65581d8f2288ff72199c9e64878012604fa84b28 Step #5: Base64: PHN2Zz4wPjxzdHlsZT5nezA+KntsPGc+PGc+PGc+PGc+PGc+Zysqe29wYWNpdHk2NTI1MS05Nywxbm4sONeBcG82RTd9PHpnPjxnPjfXgXBvNywxbm4sONeBcG82RTd9PHpnPjxnPjfXgXBvaW5zMH0xNkU3Zz08 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4268 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3854305557 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652d1beb810, 0x5652d1dd501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652d1dd5020,0x5652d3c6d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/65581d8f2288ff72199c9e64878012604fa84b28' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5332 processed earlier; will process 5697 files now Step #5: ==153724== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5652c86e09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652ced45898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652ced285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652ced284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5652c86e6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5652c8647b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5652c8642355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5652c86d8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5652cb6a7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5652cb6a7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5652cb6a7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5652cb6a7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5652cb6a7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5652cb6a7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5652cb6a7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5652cb6a7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5652cb6a7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5652cb6a7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652cd93cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5652ca669b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5652ca674be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652ca420c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652ca420c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652ca421738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652ca420874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652ca420874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652ca420874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652ced2aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652ced33928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652ced1b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652ced46112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa0707cb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5652c8640b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x76,0x21,0x39,0xa,0x0,0x7d,0x7d,0x7d,0x7d,0xd7,0xaf,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0xe2,0x80,0xad,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0x2b,0x6b,0x6b,0x6b,0x6b,0x6b,0x6b,0x6b,0x6b,0x0,0x56,0xa,0x56,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0xe2,0x80,0xad,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0x69,0x66,0x7d,0xd7,0xaf,0x2d,0x0,0x7e,0x73,0x74,0x39,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0xd7,0xa3,0x1,0xd7,0xa3,0x2d,0x0, Step #5: #v!9\012\000}}}}\327\257\012+V\012V\012+\342\200\255c\012\363\240\201\264+\012+V\012V\012++kkkkkkkk\000V\012V\012+\012\012+\012+c\012\363\240\201\264+\012+V\012V\012+\342\200\255c\012\363\240\201\264+\012+V\012V\012+if}\327\257-\000~st9>>>>>>>>>>>>>>>\327\243\001\327\243-\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bea3035c077f90509771997cc43d0ad777147dd6 Step #5: Base64: I3YhOQoAfX19fdevCitWClYKK+KArWMK86CBtCsKK1YKVgorK2tra2tra2trAFYKVgorCgorCitjCvOggbQrCitWClYKK+KArWMK86CBtCsKK1YKVgoraWZ9168tAH5zdDk+Pj4+Pj4+Pj4+Pj4+Pj7XowHXoy0A Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4269 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3854816698 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55994463a810, 0x55994482401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559944824020,0x5599466bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bea3035c077f90509771997cc43d0ad777147dd6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5333 processed earlier; will process 5696 files now Step #5: ==153760== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55993b12f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559941794898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5599417775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5599417774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55993b135d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55993b096b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55993b091355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55993b127c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55993e0f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55993e0f6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55993e0f6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55993e0f6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55993e0f6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55993e0f6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55993e0f6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55993e0f6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55993e0f6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55993e0f6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55994038bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55993d0b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55993d0c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55993ce6fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55993ce6fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55993ce70738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55993ce6f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55993ce6f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55993ce6f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559941779abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559941782928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55994176a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559941795112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff9b49c5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55993b08fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x4c,0x74,0x65,0x78,0x74,0x2f,0x3e,0x3e,0x3e,0x35,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x67,0x7b,0x74,0x65,0x72,0x35,0x69,0x74,0x7a,0x2d,0xa,0x3a,0x30,0x2c,0x27,0x2c,0x22,0x2c,0x73,0x3a,0x5c,0x5c,0x22,0x2e,0x5c,0x5c,0x63,0x5c,0x5c,0x64,0x5c,0x61,0x5c,0x64,0x45,0x61,0x5e,0x50,0xc5,0xa4,0xc5,0xa4,0x65,0x47,0x63,0x49,0x43,0x65,0x2e,0x74,0x3d,0x50,0xc5,0xa4,0xc5,0xa4,0x65,0x3a,0x5c,0x5c,0x22,0x2e,0x5c,0x5c,0x63,0x5c,0x5c,0x64,0x5c,0x61,0x5c,0x64,0x45,0x61,0x66,0x6f,0x6e,0x74,0x2d,0x73,0x69,0x7a,0x65,0x5e,0x50,0xc5,0xa4,0x2d,0x6c,0x69,0x27,0x2b,0x35,0x36,0x29,0x3e,0xa,0x1, Step #5: <svg>Ltext/>>>5<style>g{ter5itz-\012:0,',\",s:\\\\\".\\\\c\\\\d\\a\\dEa^P\305\244\305\244eGcICe.t=P\305\244\305\244e:\\\\\".\\\\c\\\\d\\a\\dEafont-size^P\305\244-li'+56)>\012\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-24e953d1ceaf13a71c5eb3966ab6384670c47f45 Step #5: Base64: PHN2Zz5MdGV4dC8+Pj41PHN0eWxlPmd7dGVyNWl0ei0KOjAsJywiLHM6XFwiLlxcY1xcZFxhXGRFYV5QxaTFpGVHY0lDZS50PVDFpMWkZTpcXCIuXFxjXFxkXGFcZEVhZm9udC1zaXplXlDFpC1saScrNTYpPgoB Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4270 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3855317810 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557cdb29e810, 0x557cdb48801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557cdb488020,0x557cdd3200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/24e953d1ceaf13a71c5eb3966ab6384670c47f45' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5334 processed earlier; will process 5695 files now Step #5: #1 pulse cov: 3708 ft: 3709 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4144 ft: 4538 exec/s: 0 rss: 177Mb Step #5: ==153796== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557cd1d939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557cd83f8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557cd83db5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557cd83db4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557cd1d99d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557cd1cfab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557cd1cf5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557cd1d8bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557cd4d5af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557cd4d5af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557cd4d5af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557cd4d5af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557cd4d5af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557cd4d5af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557cd4d5af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557cd4d5af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557cd4d5af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557cd4d5af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557cd6feff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557cd3d1cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557cd3d27be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557cd3ad3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557cd3ad3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557cd3ad4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557cd3ad3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557cd3ad3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557cd3ad3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557cd83ddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557cd83e6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557cd83ce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557cd83f9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5f023f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557cd1cf3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x6f,0x63,0x69,0x56,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x31,0x2e,0x30,0x2e,0x30,0x22,0x2c,0x22,0x6c,0x69,0x6e,0x75,0x78,0x22,0x3a,0x7b,0x22,0x72,0x65,0x73,0x6f,0x75,0x72,0x63,0x65,0x73,0x22,0x3a,0x7b,0x22,0x62,0x6c,0x6f,0x63,0x6b,0x49,0x4f,0x22,0x3a,0x7b,0x22,0x74,0x68,0x72,0x6f,0x74,0x74,0x6c,0x65,0x57,0x72,0x69,0x74,0x65,0x49,0x4f,0x50,0x53,0x44,0x65,0x76,0x69,0x63,0x65,0x22,0x3a,0x5b,0x7b,0x22,0x6d,0x61,0x6a,0x6f,0x72,0x22,0x3a,0x31,0x2c,0x22,0x6d,0x69,0x6e,0x6f,0x72,0x22,0x3a,0x30,0x2c,0x22,0x72,0x61,0x74,0x65,0x22,0x3a,0x33,0x32,0x37,0x35,0x38,0x7d,0x5d,0x7d,0x7d,0x7d,0x7d, Step #5: {\"ociVersion\":\"1.0.0\",\"linux\":{\"resources\":{\"blockIO\":{\"throttleWriteIOPSDevice\":[{\"major\":1,\"minor\":0,\"rate\":32758}]}}}} Step #5: artifact_prefix='./'; Test unit written to ./oom-2f52182603fb42152480d095f2f3b3f95d3f44d8 Step #5: Base64: eyJvY2lWZXJzaW9uIjoiMS4wLjAiLCJsaW51eCI6eyJyZXNvdXJjZXMiOnsiYmxvY2tJTyI6eyJ0aHJvdHRsZVdyaXRlSU9QU0RldmljZSI6W3sibWFqb3IiOjEsIm1pbm9yIjowLCJyYXRlIjozMjc1OH1dfX19fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4271 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3855934195 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56125196b810, 0x561251b5501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561251b55020,0x5612539ed0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f52182603fb42152480d095f2f3b3f95d3f44d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5338 processed earlier; will process 5691 files now Step #5: ==153832== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5612484609c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56124eac5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56124eaa85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56124eaa84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561248466d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5612483c7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5612483c2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561248458c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56124b427f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56124b427f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56124b427f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56124b427f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56124b427f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56124b427f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56124b427f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56124b427f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56124b427f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56124b427f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56124d6bcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56124a3e9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56124a3f4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56124a1a0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56124a1a0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56124a1a1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56124a1a0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56124a1a0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56124a1a0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56124eaaaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56124eab3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56124ea9b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56124eac6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f75d1df1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5612483c0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0, Step #5: FUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAG\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a03f5cd0d675db161c5e3ad50173534b271c107 Step #5: Base64: RlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4272 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3856449221 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559dd1a40810, 0x559dd1c2a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559dd1c2a020,0x559dd3ac20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a03f5cd0d675db161c5e3ad50173534b271c107' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5339 processed earlier; will process 5690 files now Step #5: ==153868== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559dc85359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559dceb9a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559dceb7d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559dceb7d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559dc853bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559dc849cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559dc8497355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559dc852dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559dcb4fcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559dcb4fcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559dcb4fcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559dcb4fcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559dcb4fcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559dcb4fcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559dcb4fcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559dcb4fcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559dcb4fcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559dcb4fcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559dcd791f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559dca4beb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559dca4c9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559dca275c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559dca275c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559dca276738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559dca275874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559dca275874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559dca275874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559dceb7fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559dceb88928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559dceb70699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559dceb9b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f178e79a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559dc8495b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x3d,0x79,0x0,0x0,0x0,0x0,0x29,0x24,0x7e,0x24,0x3d,0x7e,0x2d,0x3d,0x3d,0x3b,0x54,0x0,0x54,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x44,0x1,0x79,0x0,0x0,0x0,0x0,0x54,0x24, Step #5: ~$=y\000\000\000\000)$~$=~-==;T\000T\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000D\001y\000\000\000\000T$ Step #5: artifact_prefix='./'; Test unit written to ./oom-06f7223aad0e2f979a2b5ec8003ca478845d127d Step #5: Base64: fiQ9eQAAAAApJH4kPX4tPT07VABUAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEQBeQAAAABUJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4273 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3856956186 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5605fe6cf810, 0x5605fe8b901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5605fe8b9020,0x5606007510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/06f7223aad0e2f979a2b5ec8003ca478845d127d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5340 processed earlier; will process 5689 files now Step #5: ==153904== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5605f51c49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605fb829898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605fb80c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605fb80c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5605f51cad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605f512bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5605f5126355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5605f51bcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605f818bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605f818bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605f818bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605f818bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605f818bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605f818bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605f818bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605f818bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605f818bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605f818bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605fa420f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5605f714db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5605f7158be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5605f6f04c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5605f6f04c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5605f6f05738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5605f6f04874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5605f6f04874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5605f6f04874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605fb80eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5605fb817928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605fb7ff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605fb82a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf01073082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5605f5124b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0x5e,0x0,0x0,0x0,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0x43,0x46,0x46,0x20,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x39,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x66,0x65,0x65,0x64,0x69,0x6e,0x67,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0xa,0x3d,0x44,0x33,0x4,0xcc,0x96,0x4b,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0x40,0xa,0x7c,0x0,0x10,0xff, Step #5: \005-----BEGIN =^\000\000\000\012\012r=sef=\012=+=CFF \012= =\012= i\012\012r=sef=\012=+=\012=\012=\012=\012D\012=\0129\012=\012=\012=\012=\012feeding\012=\012=\012=\012=\012=\012\000----\012--\012=D3\004\314\226Kskip_cl@\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-99ac8d226de6f6ef14fe95aa65d7a34e8b7e6152 Step #5: Base64: BS0tLS0tQkVHSU4gPV4AAAAKCnI9c2VmPQo9Kz1DRkYgCj0gPQo9IGkKCnI9c2VmPQo9Kz0KPQo9Cj0KRAo9CjkKPQo9Cj0KPQpmZWVkaW5nCj0KPQo9Cj0KPQoALS0tLQotLQo9RDMEzJZLc2tpcF9jbEAKfAAQ/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4274 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3857470377 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556eff315810, 0x556eff4ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556eff4ff020,0x556f013970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/99ac8d226de6f6ef14fe95aa65d7a34e8b7e6152' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5341 processed earlier; will process 5688 files now Step #5: #1 pulse cov: 3644 ft: 3645 exec/s: 0 rss: 174Mb Step #5: ==153940== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556ef5e0a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556efc46f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556efc4525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556efc4524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556ef5e10d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556ef5d71b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556ef5d6c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556ef5e02c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556ef8dd1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556ef8dd1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556ef8dd1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556ef8dd1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556ef8dd1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556ef8dd1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556ef8dd1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556ef8dd1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556ef8dd1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556ef8dd1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556efb066f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556ef7d93b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556ef7d9ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556ef7b4ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556ef7b4ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556ef7b4b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556ef7b4a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556ef7b4a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556ef7b4a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556efc454abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556efc45d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556efc445699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556efc470112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff27b652082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556ef5d6ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x3c,0xdb,0xbe,0xdb,0xbe,0x7e,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0xb,0x0,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x25,0x25,0x25,0x25,0x25,0x25,0x32,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x7e,0xff,0xff,0xff,0x73,0x73,0xff,0xff,0xff,0x30,0x73,0x7e,0x7e,0x7e,0x31,0x73, Step #5: ~<\333\276\333\276~sssssssssss%%%%%%%%%%%%%%%%%%%%%%%%%\013\000%%%%%%%%%%%sssssssss%%%%%%2sssssssssssssssssssssssssssssssss~\377\377\377ss\377\377\3770s~~~1s Step #5: artifact_prefix='./'; Test unit written to ./oom-de045c54d20f53bb1288d4a477775581c71316d8 Step #5: Base64: fjzbvtu+fnNzc3Nzc3Nzc3NzJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJQsAJSUlJSUlJSUlJSVzc3Nzc3Nzc3MlJSUlJSUyc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzfv///3Nz////MHN+fn4xcw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4275 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3858017333 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e464569810, 0x55e46475301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e464753020,0x55e4665eb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de045c54d20f53bb1288d4a477775581c71316d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5343 processed earlier; will process 5686 files now Step #5: #1 pulse cov: 3824 ft: 3825 exec/s: 0 rss: 173Mb Step #5: ==153976== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e45b05e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4616c3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4616a65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4616a64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e45b064d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e45afc5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e45afc0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e45b056c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e45e025f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e45e025f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e45e025f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e45e025f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e45e025f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e45e025f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e45e025f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e45e025f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e45e025f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e45e025f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4602baf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e45cfe7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e45cff2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e45cd9ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e45cd9ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e45cd9f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e45cd9e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e45cd9e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e45cd9e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4616a8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4616b1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e461699699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4616c4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd915e52082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e45afbeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x67,0x6c,0x79,0x66,0x0,0x0,0x1,0x0,0x0,0xa,0x2d,0x2d,0x2d,0x2d,0x78,0x2d,0x0,0x0,0x0,0x74,0x67,0x6c,0x79,0x67,0x7f,0x66,0x3b,0x67,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x73,0x74,0x72,0x64,0x71,0x6d,0x4,0x43,0x4f,0x26,0x3f,0x67,0x2e,0x45,0x47,0x8,0x6,0x32,0xf,0x73,0x74,0x2d,0x2d,0x2d,0x2d,0x42,0x24,0x2d,0x2d,0x2d,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2d,0x42,0x24,0x47,0x49,0x4e,0x20,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x47,0x49,0x44,0x32,0x0,0x0,0x53,0x16,0x16,0x70,0x10,0x5,0x25,0x36,0x35,0x35,0x33,0x34,0x49,0x4e,0x20,0x2d,0xa,0x2d,0x20,0x75,0x0,0x38, Step #5: tglyf\000\000\001\000\000\012----x-\000\000\000tglyg\177f;gf?f;g?tstrdqm\004CO&?g.EG\010\0062\017st----B$---......-B$GIN ..............GID2\000\000S\026\026p\020\005%65534IN -\012- u\0008 Step #5: artifact_prefix='./'; Test unit written to ./oom-d961d0f4906826b924e34df104171d4d13210160 Step #5: Base64: dGdseWYAAAEAAAotLS0teC0AAAB0Z2x5Z39mO2dmP2Y7Zz90c3RyZHFtBENPJj9nLkVHCAYyD3N0LS0tLUIkLS0tLi4uLi4uLUIkR0lOIC4uLi4uLi4uLi4uLi4uR0lEMgAAUxYWcBAFJTY1NTM0SU4gLQotIHUAOA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4276 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3858562021 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aab99b0810, 0x55aab9b9a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aab9b9a020,0x55aabba320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d961d0f4906826b924e34df104171d4d13210160' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5345 processed earlier; will process 5684 files now Step #5: ==154012== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aab04a59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aab6b0a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aab6aed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aab6aed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aab04abd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aab040cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aab0407355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aab049dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aab346cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aab346cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aab346cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aab346cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aab346cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aab346cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aab346cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aab346cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aab346cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aab346cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aab5701f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aab242eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aab2439be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aab21e5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aab21e5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aab21e6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aab21e5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aab21e5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aab21e5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aab6aefabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aab6af8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aab6ae0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aab6b0b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe30edb6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aab0405b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xa,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x20,0x42,0x45,0x47,0x49,0x4e,0x2d,0x2d,0x2d,0x2d,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x32,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x9,0xa,0x60,0x47,0x60,0xa,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x20,0x42,0x45,0x47,0x49,0x4e,0x54,0x49,0x42,0xa,0x60,0x60,0x20,0x20,0x20,0x60,0x0,0x54,0x49,0x42,0xa,0x60,0x60,0x20,0x20,0x20,0x2d,0xa,0x9,0xa,0x60,0x47,0x0,0x54,0x49,0x42,0xa,0x60,0x60,0x20,0x20,0x20,0x60,0x0,0x54,0x49,0x42,0xa,0x60,0x60,0x20,0x20,0x20,0x2d,0xa,0x9, Step #5: `\012\005------ BEGIN----\012\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000ddddddd2ddddddddd\011\012`G`\012\005------ BEGINTIB\012`` `\000TIB\012`` -\012\011\012`G\000TIB\012`` `\000TIB\012`` -\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-f1028cfbfe01632ea0021944231e6aedf0a350ef Step #5: Base64: YAoFLS0tLS0tIEJFR0lOLS0tLQoAAAAAAAAAAAAAAAAAAABkZGRkZGRkMmRkZGRkZGRkZAkKYEdgCgUtLS0tLS0gQkVHSU5USUIKYGAgICBgAFRJQgpgYCAgIC0KCQpgRwBUSUIKYGAgICBgAFRJQgpgYCAgIC0KCQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4277 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3859195884 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5564f8722810, 0x5564f890c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564f890c020,0x5564fa7a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f1028cfbfe01632ea0021944231e6aedf0a350ef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5346 processed earlier; will process 5683 files now Step #5: #1 pulse cov: 3608 ft: 3609 exec/s: 0 rss: 176Mb Step #5: ==154048== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5564ef2179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564f587c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564f585f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564f585f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564ef21dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5564ef17eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5564ef179355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564ef20fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564f21def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564f21def10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564f21def10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564f21def10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564f21def10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564f21def10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564f21def10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564f21def10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564f21def10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564f21def10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5564f4473f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5564f11a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5564f11abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5564f0f57c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5564f0f57c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5564f0f58738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5564f0f57874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5564f0f57874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5564f0f57874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564f5861abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564f586a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564f5852699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564f587d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9c7319e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5564ef177b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x3a,0xa,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d, Step #5: A:\012- - - - -\012- --\012- - - - - -\012- -- -\012- - -\012- - -\012- - -\012- - - - -\012- - -\012- - -\012- - -\012- - -\012- -\012- - -\012- - -\012- -\012- - - - - - Step #5: artifact_prefix='./'; Test unit written to ./oom-ea4e4ac099f3389f65c066fc07af753e9065af23 Step #5: Base64: QToKLSAtIC0gLSAtCi0gLS0KLSAtIC0gLSAtIC0KLSAtLSAtCi0gLSAtCi0gLSAtCi0gLSAtCi0gLSAtIC0gLQotIC0gLQotIC0gLQotIC0gLQotIC0gLQotIC0KLSAtIC0KLSAgLSAtCi0gLQotIC0gLSAtIC0gLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4278 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3859794586 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5642b2403810, 0x5642b25ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5642b25ed020,0x5642b44850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ea4e4ac099f3389f65c066fc07af753e9065af23' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5348 processed earlier; will process 5681 files now Step #5: #1 pulse cov: 3608 ft: 3609 exec/s: 0 rss: 174Mb Step #5: ==154084== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5642a8ef89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5642af55d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5642af5405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5642af5404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642a8efed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5642a8e5fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5642a8e5a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5642a8ef0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5642abebff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5642abebff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5642abebff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5642abebff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5642abebff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5642abebff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5642abebff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5642abebff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5642abebff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5642abebff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5642ae154f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5642aae81b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5642aae8cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5642aac38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5642aac38c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5642aac39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5642aac38874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5642aac38874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5642aac38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5642af542abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5642af54b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5642af533699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5642af55e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9666a3a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5642a8e58b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x49,0x44,0x33,0x2,0x0,0x0,0x3,0x0,0x0,0x0,0x47,0x45,0x4f,0x0,0x0,0x3,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x49,0x44,0x33,0x2,0x0,0x0,0x3,0x0,0x0,0x0,0x47,0x45,0x4f,0x0,0x0,0x3,0x1,0x0,0x68,0x65,0x61,0x64,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0xa4,0x68,0x65,0x61,0x64,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0xa4, Step #5: \000\000\000\000\000\000\000#[(b\000]\000\000\000\000\000\000\000\000\000\000\000#[(b\000]\000ID3\002\000\000\003\000\000\000GEO\000\000\003\001\000\000\000\000\000\000\000#[(b\000]\000\000\000\000\000\000\000\000\000\000\000#[(b\000]\000ID3\002\000\000\003\000\000\000GEO\000\000\003\001\000head\000#[(b\000]\244head\000#[(b\000]\244 Step #5: artifact_prefix='./'; Test unit written to ./oom-105fd1ea93749ffe044f86e22adc1e4332d63073 Step #5: Base64: AAAAAAAAACNbKGIAXQAAAAAAAAAAAAAAI1soYgBdAElEMwIAAAMAAABHRU8AAAMBAAAAAAAAACNbKGIAXQAAAAAAAAAAAAAAI1soYgBdAElEMwIAAAMAAABHRU8AAAMBAGhlYWQAI1soYgBdpGhlYWQAI1soYgBdpA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4279 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3860357305 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55810ffad810, 0x55811019701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558110197020,0x55811202f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/105fd1ea93749ffe044f86e22adc1e4332d63073' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5350 processed earlier; will process 5679 files now Step #5: ==154120== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558106aa29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55810d107898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55810d0ea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55810d0ea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558106aa8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558106a09b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558106a04355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558106a9ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558109a69f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558109a69f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558109a69f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558109a69f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558109a69f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558109a69f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558109a69f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558109a69f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558109a69f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558109a69f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55810bcfef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558108a2bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558108a36be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5581087e2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5581087e2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5581087e3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5581087e2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5581087e2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5581087e2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55810d0ecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55810d0f5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55810d0dd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55810d108112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feab5e5f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558106a02b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x3d,0x79,0x0,0x0,0x0,0x0,0x29,0x24,0x7e,0x24,0x3d,0x7e,0x2d,0x3d,0x3d,0x3b,0x54,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x5b,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x54,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3b,0x5c,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x44,0x1,0x79,0x0,0x0,0x0,0x0,0x54,0x24, Step #5: ~$=y\000\000\000\000)$~$=~-==;T\012=\012=\012=\012=\012=\012=\012=\012=\012=[\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=T\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000;\\\012=\012=\012=\012=\000\000\000\000\000\000\000\000D\001y\000\000\000\000T$ Step #5: artifact_prefix='./'; Test unit written to ./oom-c0d5522e95ae4ae96f3e47d204990fbb0a9aa2d0 Step #5: Base64: fiQ9eQAAAAApJH4kPX4tPT07VAo9Cj0KPQo9Cj0KPQo9Cj0KPVsKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj1UAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA7XAo9Cj0KPQo9AAAAAAAAAABEAXkAAAAAVCQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4280 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3860873773 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558e2dfae810, 0x558e2e19801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558e2e198020,0x558e300300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c0d5522e95ae4ae96f3e47d204990fbb0a9aa2d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5351 processed earlier; will process 5678 files now Step #5: ==154156== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558e24aa39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558e2b108898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558e2b0eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558e2b0eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558e24aa9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558e24a0ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558e24a05355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558e24a9bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558e27a6af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558e27a6af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558e27a6af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558e27a6af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558e27a6af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558e27a6af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558e27a6af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558e27a6af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558e27a6af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558e27a6af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558e29cfff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558e26a2cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558e26a37be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558e267e3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558e267e3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558e267e4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558e267e3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558e267e3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558e267e3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558e2b0edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558e2b0f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558e2b0de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558e2b109112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f895e9a7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558e24a03b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x49,0x44,0x33,0x2,0x0,0x0,0x3,0x0,0x0,0x0,0x47,0x45,0x4f,0x0,0x0,0x3,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x49,0x44,0x33,0x2,0x0,0x0,0x3,0x0,0x0,0x0,0x47,0x45,0x4f,0x0,0x0,0x3,0x1,0x0,0x68,0x65,0x61,0x64,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x31,0xa4,0x68,0x65,0x61,0x64,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0xa4, Step #5: \000\000\000\000\000\000\000#[(b\000]\000\000\000\000\000\000\000\000\000\000\000#[(b\000]\000ID3\002\000\000\003\000\000\000GEO\000\000\003\001\000\000\000\000\000\000\000#[(b\000]\000\000\000\000\000\000\000\000\000\000\000#[(b\000]\000ID3\002\000\000\003\000\000\000GEO\000\000\003\001\000head\000#[(b\000]1\244head\000#[(b\000]\244 Step #5: artifact_prefix='./'; Test unit written to ./oom-b3d3ffa5cbd36d2417c9b7c06387d4eaf361f405 Step #5: Base64: AAAAAAAAACNbKGIAXQAAAAAAAAAAAAAAI1soYgBdAElEMwIAAAMAAABHRU8AAAMBAAAAAAAAACNbKGIAXQAAAAAAAAAAAAAAI1soYgBdAElEMwIAAAMAAABHRU8AAAMBAGhlYWQAI1soYgBdMaRoZWFkACNbKGIAXaQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4281 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3861388949 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563ef1af2810, 0x563ef1cdc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563ef1cdc020,0x563ef3b740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3d3ffa5cbd36d2417c9b7c06387d4eaf361f405' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5352 processed earlier; will process 5677 files now Step #5: ==154192== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563ee85e79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563eeec4c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563eeec2f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563eeec2f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563ee85edd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563ee854eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563ee8549355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563ee85dfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563eeb5aef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563eeb5aef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563eeb5aef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563eeb5aef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563eeb5aef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563eeb5aef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563eeb5aef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563eeb5aef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563eeb5aef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563eeb5aef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563eed843f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563eea570b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563eea57bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563eea327c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563eea327c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563eea328738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563eea327874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563eea327874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563eea327874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563eeec31abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563eeec3a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563eeec22699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563eeec4d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f02f50ad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563ee8547b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x3,0x32,0x0,0x0,0x0,0xa,0x4e,0x68,0x68,0x43,0x3,0x0,0x49,0x4c,0x3e,0x0,0x33,0x0,0x54,0x49,0x54,0x31,0x49,0x44,0x33,0x3,0x14,0x1,0x2f,0x0,0x0,0x67,0x54,0x49,0x54,0x30,0x0,0x0,0xd,0x0,0x0,0x0,0xa,0x4e,0x68,0x68,0xe,0xe,0x69,0x43,0x3,0x0,0x49,0x0,0x33,0x54,0x44,0x54,0x3,0x49,0x3f,0x31,0x0,0x0,0x0,0xe,0x4e,0x68,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x43,0x3,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x7,0x0,0x0,0x2d,0x20,0x2d,0x7,0x20,0x2d,0x3a,0x3e,0x54,0x49,0x54,0x20,0x75,0x3a,0x20,0x30,0x0,0x0,0x0,0xe,0x4e,0x68,0x39,0x68,0x43,0x3,0x0,0x49,0x0,0x3a,0x1,0x0, Step #5: ID3\0032\000\000\000\012NhhC\003\000IL>\0003\000TIT1ID3\003\024\001/\000\000gTIT0\000\000\015\000\000\000\012Nhh\016\016iC\003\000I\0003TDT\003I?1\000\000\000\016Nhhttp://C\003\000\000\000\000\001\000\000\007\000\000- -\007 -:>TIT u: 0\000\000\000\016Nh9hC\003\000I\000:\001\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-abac2f0cfd299b89998ade246ff8a9c093ad3627 Step #5: Base64: SUQzAzIAAAAKTmhoQwMASUw+ADMAVElUMUlEMwMUAS8AAGdUSVQwAAANAAAACk5oaA4OaUMDAEkAM1REVANJPzEAAAAOTmhodHRwOi8vQwMAAAAAAQAABwAALSAtByAtOj5USVQgdTogMAAAAA5OaDloQwMASQA6AQA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4282 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3861894905 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f554176810, 0x55f55436001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f554360020,0x55f5561f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/abac2f0cfd299b89998ade246ff8a9c093ad3627' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5353 processed earlier; will process 5676 files now Step #5: ==154228== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f54ac6b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f5512d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f5512b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f5512b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f54ac71d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f54abd2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f54abcd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f54ac63c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f54dc32f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f54dc32f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f54dc32f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f54dc32f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f54dc32f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f54dc32f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f54dc32f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f54dc32f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f54dc32f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f54dc32f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f54fec7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f54cbf4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f54cbffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f54c9abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f54c9abc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f54c9ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f54c9ab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f54c9ab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f54c9ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f5512b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f5512be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f5512a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f5512d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f253a7d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f54abcbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x41,0x3d,0x5e,0x0,0x0,0x0,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x29,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x34,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x66,0x65,0x65,0x64,0x69,0x6e,0x67,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0xa,0x3d,0x44,0x33,0x4,0xcc,0x86,0x4b,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0x40,0xa,0x7c,0x0,0x10,0xff, Step #5: \005-----BEGIN A=^\000\000\000\012\012r=sef=\012=+=\012=\012=\012= =\012= )\012\012r=sef=\012=+=\012=\012=\012=\012D\012=\0124\012=\012=\012=\012=\012feeding\012=\012=\012=\012=\012=\012\000----\012--\012=D3\004\314\206Kskip_cl@\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-efe18c506d40b14570ac99c567d1bdca7a326562 Step #5: Base64: BS0tLS0tQkVHSU4gQT1eAAAACgpyPXNlZj0KPSs9Cj0KPQo9ID0KPSApCgpyPXNlZj0KPSs9Cj0KPQo9CkQKPQo0Cj0KPQo9Cj0KZmVlZGluZwo9Cj0KPQo9Cj0KAC0tLS0KLS0KPUQzBMyGS3NraXBfY2xACnwAEP8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4283 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3862405420 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55654e731810, 0x55654e91b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55654e91b020,0x5565507b30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/efe18c506d40b14570ac99c567d1bdca7a326562' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5354 processed earlier; will process 5675 files now Step #5: ==154264== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5565452269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55654b88b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55654b86e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55654b86e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55654522cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55654518db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556545188355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55654521ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5565481edf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5565481edf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5565481edf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5565481edf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5565481edf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5565481edf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5565481edf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5565481edf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5565481edf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5565481edf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55654a482f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5565471afb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5565471babe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556546f66c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556546f66c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556546f67738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556546f66874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556546f66874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556546f66874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55654b870abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55654b879928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55654b861699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55654b88c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f549efe4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556545186b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x77,0x22,0xca,0x94,0x5f,0xd9,0x82,0xd9,0x90,0x52,0xd9,0x82,0xd9,0x8a,0x26,0x64,0xd9,0x94,0x5f,0xd9,0x82,0xd9,0x90,0xd9,0xa1,0xd9,0x82,0xc9,0x82,0x57,0x5b,0x5d,0x52,0x5f,0xd9,0x82,0xd9,0x90,0xd9,0xa1,0xd9,0x82,0x26,0xd9,0x90,0x64,0xd9,0x90,0x52,0xd1,0x82,0xd9,0x90,0xd9,0xa1,0xd9,0x90,0x52,0xd9,0x82,0xf4,0x82,0x7,0x22,0xca,0x94,0x5f,0xd9,0x82,0xd9,0x90,0x52,0xd9,0x82,0xd9,0x90,0x52,0x2f,0x7d,0x26,0x66,0xd9,0xa1,0xd9,0x90,0x52,0xd9,0x82,0xf4,0x82,0xa5,0x82,0xd9,0x82,0xda,0x94,0x5f,0xd9,0x82,0xd9,0x90,0x52,0xd1,0x82,0xd9,0x90,0xd9,0xa1,0xd9,0x90,0x52,0xd9,0x82,0xcb,0xd9,0x82,0xf4,0x82,0x0,0x0, Step #5: HUw\"\312\224_\331\202\331\220R\331\202\331\212&d\331\224_\331\202\331\220\331\241\331\202\311\202W[]R_\331\202\331\220\331\241\331\202&\331\220d\331\220R\321\202\331\220\331\241\331\220R\331\202\364\202\007\"\312\224_\331\202\331\220R\331\202\331\220R/}&f\331\241\331\220R\331\202\364\202\245\202\331\202\332\224_\331\202\331\220R\321\202\331\220\331\241\331\220R\331\202\313\331\202\364\202\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fe2b9c9b14cb310a30338235ab7fb4361f13d1bd Step #5: Base64: SFV3IsqUX9mC2ZBS2YLZiiZk2ZRf2YLZkNmh2YLJgldbXVJf2YLZkNmh2YIm2ZBk2ZBS0YLZkNmh2ZBS2YL0ggciypRf2YLZkFLZgtmQUi99JmbZodmQUtmC9IKlgtmC2pRf2YLZkFLRgtmQ2aHZkFLZgsvZgvSCAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4284 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3862913301 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55deee961810, 0x55deeeb4b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55deeeb4b020,0x55def09e30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fe2b9c9b14cb310a30338235ab7fb4361f13d1bd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5355 processed earlier; will process 5674 files now Step #5: ==154300== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dee54569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55deebabb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55deeba9e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55deeba9e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dee545cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dee53bdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dee53b8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dee544ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dee841df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dee841df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dee841df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dee841df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dee841df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dee841df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dee841df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dee841df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dee841df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dee841df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55deea6b2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dee73dfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dee73eabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dee7196c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dee7196c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dee7197738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dee7196874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dee7196874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dee7196874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55deebaa0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55deebaa9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55deeba91699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55deebabc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8f107f2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dee53b6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xbf,0x3c,0x78,0x3e,0x3c,0x21,0x5b,0x43,0x44,0x41,0x54,0x41,0x5b,0xa,0xd4,0xbb,0x22,0xa,0x54,0x7e,0xa,0xd4,0xbf,0x22,0xa,0xd4,0xbf,0x22,0x22,0x9,0xa,0xd4,0xbb,0xa,0xd4,0xbf,0x22,0xa,0xd4,0xbf,0x22,0xa,0xd4,0xbf,0x22,0x21,0xa,0xd4,0xbb,0x22,0xa,0x54,0x7e,0xa,0xd4,0xbf,0x22,0xa,0xd4,0xbf,0x22,0x22,0x9,0x43,0xa,0xd4,0xbb,0x22,0xa,0x55,0x7e,0xa,0xd4,0xbf,0x7e,0xa,0xd4,0xbf,0x22,0xa,0xd4,0xbf,0x22,0x22,0x9,0xa,0xd4,0xbb,0x7e,0xa,0xd4,0xbf,0x22,0xa,0xd4,0xbf,0x22,0xa,0xd4,0xbf,0x5b,0x43,0xa,0xd4,0xbb,0x22,0x7e,0xa,0xd4,0xbf,0x22,0xa,0xd4,0xbf,0x22,0x22,0xa,0xd4,0xbf,0x9, Step #5: \357\273\277<x><![CDATA[\012\324\273\"\012T~\012\324\277\"\012\324\277\"\"\011\012\324\273\012\324\277\"\012\324\277\"\012\324\277\"!\012\324\273\"\012T~\012\324\277\"\012\324\277\"\"\011C\012\324\273\"\012U~\012\324\277~\012\324\277\"\012\324\277\"\"\011\012\324\273~\012\324\277\"\012\324\277\"\012\324\277[C\012\324\273\"~\012\324\277\"\012\324\277\"\"\012\324\277\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-cfb8c552a9257000958dd1b47fb6ba38f2e14565 Step #5: Base64: 77u/PHg+PCFbQ0RBVEFbCtS7IgpUfgrUvyIK1L8iIgkK1LsK1L8iCtS/IgrUvyIhCtS7IgpUfgrUvyIK1L8iIglDCtS7IgpVfgrUv34K1L8iCtS/IiIJCtS7fgrUvyIK1L8iCtS/W0MK1LsifgrUvyIK1L8iIgrUvwk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4285 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3863415630 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556743be5810, 0x556743dcf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556743dcf020,0x556745c670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cfb8c552a9257000958dd1b47fb6ba38f2e14565' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5356 processed earlier; will process 5673 files now Step #5: ==154336== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55673a6da9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556740d3f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556740d225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556740d224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55673a6e0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55673a641b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55673a63c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55673a6d2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55673d6a1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55673d6a1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55673d6a1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55673d6a1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55673d6a1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55673d6a1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55673d6a1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55673d6a1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55673d6a1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55673d6a1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55673f936f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55673c663b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55673c66ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55673c41ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55673c41ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55673c41b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55673c41a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55673c41a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55673c41a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556740d24abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556740d2d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556740d15699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556740d40112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5fcf2f0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55673a63ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x26,0x24,0x24,0x22,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x0,0x0,0x0,0xd,0x0,0x0,0x0,0x0,0x0,0x73,0x35,0x2d,0x2d,0x2d,0x2d,0x64,0x0,0x42,0x45,0x47,0x4b,0x4e,0x20,0x73,0x74,0x72,0x65,0x61,0x6d,0x2d,0x2d,0x5b,0x2d,0x65,0x61,0x6d,0x2d,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x22,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x3f,0x0,0x0,0x0,0x0,0x0,0x2e,0x33, Step #5: s$$$$$$$$$$$&$$\"$$$r$$$$$$$$$$$$$$$$$$$$\000\000\000\015\000\000\000\000\000s5----d\000BEGKN stream--[-eam-$$$$$$$$$$$$$$$$$\"$$$r$$$$$$$r$$$$$$$?\000\000\000\000\000.3 Step #5: artifact_prefix='./'; Test unit written to ./oom-02593a23064e68d4312ec4d1868b9c7cb7a65a51 Step #5: Base64: cyQkJCQkJCQkJCQkJiQkIiQkJHIkJCQkJCQkJCQkJCQkJCQkJCQkJAAAAA0AAAAAAHM1LS0tLWQAQkVHS04gc3RyZWFtLS1bLWVhbS0kJCQkJCQkJCQkJCQkJCQkJCIkJCRyJCQkJCQkJHIkJCQkJCQkPwAAAAAALjM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4286 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3863934983 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556837035810, 0x55683721f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55683721f020,0x5568390b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/02593a23064e68d4312ec4d1868b9c7cb7a65a51' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5357 processed earlier; will process 5672 files now Step #5: ==154372== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55682db2a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55683418f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5568341725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5568341724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55682db30d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55682da91b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55682da8c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55682db22c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556830af1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556830af1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556830af1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556830af1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556830af1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556830af1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556830af1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556830af1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556830af1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556830af1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556832d86f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55682fab3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55682fabebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55682f86ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55682f86ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55682f86b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55682f86a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55682f86a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55682f86a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556834174abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55683417d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556834165699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556834190112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9dd742c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55682da8ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xa,0x9,0xa,0x60,0x2d,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xcb,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x8c,0xc5,0x83,0xc5,0x8b,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xcf,0xaf, Step #5: `\012\011\012`-\305\203\305\203\305\203\305\203\305\203\305\203\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\203\305\203\305\203\305\203\305\203\313\203\305\203\305\203\305\203\305\203\305\214\305\203\305\213\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\317\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-d02b60d852d42c28eed19de84b991948c0e739da Step #5: Base64: YAoJCmAtxYPFg8WDxYPFg8WDg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg4PFg8WDxYPFg8uDxYPFg8WDxYPFjMWDxYvFg8WDxYPFg8WDxYPFg8WDxYPFg8WDz68= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4287 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3864554496 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e12daff810, 0x55e12dce901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e12dce9020,0x55e12fb810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d02b60d852d42c28eed19de84b991948c0e739da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5358 processed earlier; will process 5671 files now Step #5: #1 pulse cov: 4023 ft: 4024 exec/s: 0 rss: 174Mb Step #5: ==154408== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e1245f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e12ac59898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e12ac3c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e12ac3c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e1245fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e12455bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e124556355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e1245ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e1275bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e1275bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e1275bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e1275bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e1275bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e1275bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e1275bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e1275bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e1275bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e1275bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e129850f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e12657db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e126588be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e126334c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e126334c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e126335738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e126334874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e126334874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e126334874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e12ac3eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e12ac47928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e12ac2f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e12ac5a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95af4a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e124554b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc7,0xb1,0xa,0xc7,0x88,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc,0xa,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0x2e,0xc2,0xbc, Step #5: \307\261\012\307\210\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274\012\357\267\272\357\267\272\357\267\272.\302\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a6b95c2fd274bb8759e892eaf35979d2923ccd1 Step #5: Base64: x7EKx4gK77e677e677e6LsK8Cu+3uu+3uu+3ui7CvArvt7rvt7rvt7ouwrwK77e677e677e6LsK8Cu+3uu+3uu+3ui7CvArvt7rvt7rvt7ouwrwK77e677e677e6LsK8Cu+3uu+3uu+3ui7CvArvt7rvt7rvt7ouwrw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4288 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3865104159 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fbb6f48810, 0x55fbb713201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fbb7132020,0x55fbb8fca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a6b95c2fd274bb8759e892eaf35979d2923ccd1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5360 processed earlier; will process 5669 files now Step #5: ==154444== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fbada3d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fbb40a2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fbb40855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fbb40854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fbada43d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fbad9a4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fbad99f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fbada35c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fbb0a04f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fbb0a04f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fbb0a04f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fbb0a04f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fbb0a04f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fbb0a04f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fbb0a04f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fbb0a04f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fbb0a04f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fbb0a04f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fbb2c99f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fbaf9c6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fbaf9d1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fbaf77dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fbaf77dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fbaf77e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fbaf77d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fbaf77d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fbaf77d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fbb4087abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fbb4090928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fbb4078699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fbb40a3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fae72cee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fbad99db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7b,0x37,0x7d,0x24,0x7f,0x32,0x7d,0x24,0x24,0x7b,0x7d,0x38,0x7b,0x32,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x38,0x7d,0x24,0x7b,0x78,0x1,0x0,0x0,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x32,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x38,0x7d,0x24,0x7b,0x78,0x1,0x0,0x7f,0x32,0x7d,0x24,0x24,0x7b,0x7d,0x38,0x7b,0x32,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x38,0x7d,0x24,0x7b,0x78,0x1,0x0,0x0,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x32,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x38,0x7d,0x24,0x7b,0x78,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x7,0x7b,0x38,0x0,0x0,0x0,0x0,0x0,0x7,0x7b,0x38,0x7d, Step #5: ${7}$\1772}$${}8{28}${8}$8}${x\001\000\000}${8}${2}${8}${8}$8}${x\001\000\1772}$${}8{28}${8}$8}${x\001\000\000}${8}${2}${8}${8}$8}${x\001\000\000\000\000\000\000\007{8\000\000\000\000\000\007{8} Step #5: artifact_prefix='./'; Test unit written to ./oom-0836ca8666c4dff06ecee1883941f982f95cd160 Step #5: Base64: JHs3fSR/Mn0kJHt9OHsyOH0kezh9JDh9JHt4AQAAfSR7OH0kezJ9JHs4fSR7OH0kOH0ke3gBAH8yfSQke304ezI4fSR7OH0kOH0ke3gBAAB9JHs4fSR7Mn0kezh9JHs4fSQ4fSR7eAEAAAAAAAAHezgAAAAAAAd7OH0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4289 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3865613002 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a5cfbfd810, 0x55a5cfde701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a5cfde7020,0x55a5d1c7f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0836ca8666c4dff06ecee1883941f982f95cd160' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5361 processed earlier; will process 5668 files now Step #5: ==154480== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a5c66f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a5ccd57898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a5ccd3a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a5ccd3a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a5c66f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a5c6659b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a5c6654355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a5c66eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a5c96b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a5c96b9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a5c96b9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a5c96b9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a5c96b9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a5c96b9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a5c96b9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a5c96b9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a5c96b9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a5c96b9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a5cb94ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a5c867bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a5c8686be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a5c8432c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a5c8432c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a5c8433738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a5c8432874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a5c8432874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a5c8432874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a5ccd3cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a5ccd45928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a5ccd2d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a5ccd58112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f747c35c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a5c6652b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x7d,0x7d,0x3c,0x74,0x65,0x78,0x74,0x3e,0x65,0x78,0x74,0x3e,0x5e,0xe0,0xad,0x8b,0x3b,0xd,0x61,0x3e,0x3b,0x2d,0xe1,0xb0,0x8e,0x30,0x30,0x30,0x61,0xe1,0xbf,0x8d,0xcd,0x8f,0xe0,0xa6,0x8b,0x29,0x2f,0x34,0xdb,0xba,0x2d,0x3e,0x3e,0x61,0xe9,0xbf,0x8d,0xcd,0x8f,0xe0,0xa6,0x8b,0x6e,0x6e,0x61,0x3e,0x3b,0x2d,0xe1,0xb0,0x8e,0x30,0x29,0x30,0x30,0x61,0xe1,0xbf,0x8d,0xcd,0x8f,0xe0,0xa6,0x8b,0x6e,0x6e,0x61,0x3e,0x3b,0xcd,0x8f,0xe0,0xa6,0x8b,0x6e,0x6e,0x61,0x3e,0x3b,0x34,0xdb,0xba,0x2d,0x29,0x28,0x28,0x69,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3e,0x3e,0x2c,0x47,0x47,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg>}}<text>ext>^\340\255\213;\015a>;-\341\260\216000a\341\277\215\315\217\340\246\213)/4\333\272->>a\351\277\215\315\217\340\246\213nna>;-\341\260\2160)00a\341\277\215\315\217\340\246\213nna>;\315\217\340\246\213nna>;4\333\272-)((i</text>>>,GG</svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-a1f1486f7e15744a7e017a77492ed3dd352c7b02 Step #5: Base64: PHN2Zz59fTx0ZXh0PmV4dD5e4K2LOw1hPjst4bCOMDAwYeG/jc2P4KaLKS8027otPj5h6b+NzY/gpotubmE+Oy3hsI4wKTAwYeG/jc2P4KaLbm5hPjvNj+Cmi25uYT47NNu6LSkoKGk8L3RleHQ+Pj4sR0c8L3N2Zz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4290 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3866120419 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fa2736c810, 0x55fa2755601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fa27556020,0x55fa293ee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a1f1486f7e15744a7e017a77492ed3dd352c7b02' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5362 processed earlier; will process 5667 files now Step #5: #1 pulse cov: 4037 ft: 4038 exec/s: 0 rss: 174Mb Step #5: ==154516== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fa1de619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fa244c6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fa244a95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fa244a94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fa1de67d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fa1ddc8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fa1ddc3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fa1de59c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fa20e28f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fa20e28f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fa20e28f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fa20e28f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fa20e28f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fa20e28f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fa20e28f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fa20e28f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fa20e28f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fa20e28f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fa230bdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fa1fdeab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fa1fdf5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fa1fba1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fa1fba1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fa1fba2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fa1fba1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fa1fba1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fa1fba1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fa244ababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fa244b4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fa2449c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fa244c7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f54410f3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fa1ddc1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xa,0x73,0x75,0x62,0x7b,0x20,0x64,0x3a,0x31,0x37,0x32,0x35,0x31,0x36,0x33,0x31,0x37,0x34,0x31,0x34,0x33,0x32,0x32,0x30,0x33,0x35,0x34,0x34,0x32,0x37,0x36,0x37,0x30,0x30,0x2e,0x20,0x7d,0xa,0x73,0x75,0x62,0x7b,0x20,0x64,0x3a,0x31,0x37,0x32,0x35,0x31,0x36,0x33,0x31,0x37,0x34,0x31,0x34,0x33,0x32,0x32,0x30,0x33,0x35,0x34,0x34,0x32,0x37,0x36,0x37,0x30,0x30,0x2e,0x20,0x7d,0xa,0x73,0x75,0x62,0x7b,0x20,0x64,0x3a,0x31,0x37,0x32,0x35,0x31,0x36,0x33,0x31,0x37,0x34,0x31,0x34,0x33,0x32,0x32,0x30,0x33,0x35,0x34,0x34,0x32,0x37,0x36,0x37,0x30,0x30,0x2e,0x20,0x7d,0xa, Step #5: FUZZTESTv1\012sub{ d:17251631741432203544276700. }\012sub{ d:17251631741432203544276700. }\012sub{ d:17251631741432203544276700. }\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-ed3041522ea1a0ea339d2429da0e537d129bfd19 Step #5: Base64: RlVaWlRFU1R2MQpzdWJ7IGQ6MTcyNTE2MzE3NDE0MzIyMDM1NDQyNzY3MDAuIH0Kc3VieyBkOjE3MjUxNjMxNzQxNDMyMjAzNTQ0Mjc2NzAwLiB9CnN1YnsgZDoxNzI1MTYzMTc0MTQzMjIwMzU0NDI3NjcwMC4gfQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4291 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3866667455 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5618ce2f8810, 0x5618ce4e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5618ce4e2020,0x5618d037a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ed3041522ea1a0ea339d2429da0e537d129bfd19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5364 processed earlier; will process 5665 files now Step #5: #1 pulse cov: 3679 ft: 3680 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 4059 ft: 4388 exec/s: 0 rss: 174Mb Step #5: ==154552== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5618c4ded9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5618cb452898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5618cb4355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5618cb4354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5618c4df3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5618c4d54b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5618c4d4f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5618c4de5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5618c7db4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5618c7db4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5618c7db4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5618c7db4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5618c7db4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5618c7db4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5618c7db4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5618c7db4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5618c7db4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5618c7db4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5618ca049f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5618c6d76b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5618c6d81be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5618c6b2dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5618c6b2dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5618c6b2e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5618c6b2d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5618c6b2d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5618c6b2d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5618cb437abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5618cb440928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5618cb428699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5618cb453112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f301a877082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5618c4d4db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x63,0x6f,0x6c,0x6f,0x6e,0x4b,0x60,0x20,0x2d,0x45,0x47,0x4b,0x60,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x2b,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x20,0x2d,0x24,0x24,0x0,0x0,0x0,0x87,0x28,0x0,0x0,0x0,0xa,0x2d,0x2a,0x64,0xa,0x64,0xa,0x3f, Step #5: s-----BEGcolonK` -EGK`$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$+$$$$$$$$$$$$$$$$$$$$$$$$ -$$\000\000\000\207(\000\000\000\012-*d\012d\012? Step #5: artifact_prefix='./'; Test unit written to ./oom-64332e0286bd89225f2aa31db458e112285a48d3 Step #5: Base64: cy0tLS0tQkVHY29sb25LYCAtRUdLYCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkKyQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCAtJCQAAACHKAAAAAotKmQKZAo/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4292 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3867376231 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cbff196810, 0x55cbff38001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cbff380020,0x55cc012180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/64332e0286bd89225f2aa31db458e112285a48d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5367 processed earlier; will process 5662 files now Step #5: ==154588== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cbf5c8b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cbfc2f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cbfc2d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cbfc2d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cbf5c91d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cbf5bf2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cbf5bed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cbf5c83c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cbf8c52f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cbf8c52f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cbf8c52f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cbf8c52f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cbf8c52f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cbf8c52f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cbf8c52f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cbf8c52f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cbf8c52f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cbf8c52f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cbfaee7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cbf7c14b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cbf7c1fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cbf79cbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cbf79cbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cbf79cc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cbf79cb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cbf79cb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cbf79cb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cbfc2d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cbfc2de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cbfc2c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cbfc2f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f51282bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cbf5bebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xdb,0x80,0x38,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x0,0x0,0x39, Step #5: \333\200\333\2009\000*********************************************\333\2008\000*************************************\000\000\000\000\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\010\000\000\0009 Step #5: artifact_prefix='./'; Test unit written to ./oom-fbe3da5bf43d25ee4a3561eadc409db1c493db32 Step #5: Base64: 24DbgDkAKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioq24A4ACoqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAgAAAA5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4293 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3867882551 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559462dff810, 0x559462fe901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559462fe9020,0x559464e810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fbe3da5bf43d25ee4a3561eadc409db1c493db32' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5368 processed earlier; will process 5661 files now Step #5: ==154624== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5594598f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55945ff59898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55945ff3c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55945ff3c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5594598fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55945985bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559459856355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5594598ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55945c8bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55945c8bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55945c8bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55945c8bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55945c8bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55945c8bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55945c8bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55945c8bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55945c8bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55945c8bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55945eb50f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55945b87db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55945b888be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55945b634c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55945b634c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55945b635738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55945b634874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55945b634874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55945b634874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55945ff3eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55945ff47928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55945ff2f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55945ff5a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc3e6729082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559459854b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x29,0x46,0x73,0x63,0x72,0x68,0x70,0x73,0x3e,0x74,0x3e,0x3c,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x3c,0x21,0x2d,0x2d,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x72,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x21,0x2d,0x2d,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x72,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e,0x3c,0x73,0x3e, Step #5: )Fscrhps>t><script><!--<s><s><s><s><s><s><s><s><s><r><s><s><s><!--<s><s><s><s><s><s><s><s><s><r><s><s><s><s><s><s><s><s><s> Step #5: artifact_prefix='./'; Test unit written to ./oom-5f9da75e1bf83eb4bcb702b05413d4b238c54fde Step #5: Base64: KUZzY3JocHM+dD48c2NyaXB0PjwhLS08cz48cz48cz48cz48cz48cz48cz48cz48cz48cj48cz48cz48cz48IS0tPHM+PHM+PHM+PHM+PHM+PHM+PHM+PHM+PHM+PHI+PHM+PHM+PHM+PHM+PHM+PHM+PHM+PHM+PHM+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4294 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3868382642 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560acb6ff810, 0x560acb8e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560acb8e9020,0x560acd7810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f9da75e1bf83eb4bcb702b05413d4b238c54fde' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5369 processed earlier; will process 5660 files now Step #5: ==154660== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560ac21f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560ac8859898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560ac883c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560ac883c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560ac21fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560ac215bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560ac2156355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560ac21ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560ac51bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560ac51bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560ac51bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560ac51bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560ac51bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560ac51bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560ac51bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560ac51bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560ac51bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560ac51bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560ac7450f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560ac417db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560ac4188be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560ac3f34c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560ac3f34c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560ac3f35738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560ac3f34874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560ac3f34874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560ac3f34874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560ac883eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560ac8847928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560ac882f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560ac885a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f644d009082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560ac2154b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x55,0x77,0x22,0x48,0x55,0x54,0x9,0x22,0x48,0xcc,0x8d,0x6d,0xe3,0xaa,0x8d,0xe3,0xaa,0x97,0x3a,0x7d,0x65,0x6d,0xe2,0xaa,0x97,0xcc,0x8d,0xe3,0xa9,0x97,0x3a,0x6d,0x6d,0xe3,0xaa,0x8d,0xe3,0xaa,0x97,0x6d,0x6d,0x6d,0xe3,0xaa,0x97,0x6d,0x6d,0x6d,0xe3,0xaa,0x8d,0xe3,0xaa,0x97,0x3a,0x6d,0x6d,0x6d,0xe2,0xaa,0x97,0xcc,0x8d,0xe3,0xa9,0x97,0x3a,0x6d,0x6d,0xe3,0xaa,0x8d,0xe3,0xaa,0x97,0x65,0x6d,0x6d,0xe3,0xaa,0x97,0x6d,0x6d,0x6d,0xe3,0xaa,0x8d,0xe3,0xaa,0x97,0x3a,0x6d,0x65,0x6d,0xe2,0xaa,0x97,0xcc,0x8d,0xe3,0xa9,0x97,0x3a,0x6d,0x6d,0xe3,0xaa,0x8d,0xe3,0xaa,0x97,0x30,0x0,0x0,0x0,0xaa,0x97,0xcc,0x8d,0xe3,0xa9,0x97, Step #5: HUw\"HUT\011\"H\314\215m\343\252\215\343\252\227:}em\342\252\227\314\215\343\251\227:mm\343\252\215\343\252\227mmm\343\252\227mmm\343\252\215\343\252\227:mmm\342\252\227\314\215\343\251\227:mm\343\252\215\343\252\227emm\343\252\227mmm\343\252\215\343\252\227:mem\342\252\227\314\215\343\251\227:mm\343\252\215\343\252\2270\000\000\000\252\227\314\215\343\251\227 Step #5: artifact_prefix='./'; Test unit written to ./oom-f5543523efe7ac2483e29c9ffea82ea980387153 Step #5: Base64: SFV3IkhVVAkiSMyNbeOqjeOqlzp9ZW3iqpfMjeOplzptbeOqjeOql21tbeOql21tbeOqjeOqlzptbW3iqpfMjeOplzptbeOqjeOql2VtbeOql21tbeOqjeOqlzptZW3iqpfMjeOplzptbeOqjeOqlzAAAACql8yN46mX Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4295 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3868882247 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557eca7b1810, 0x557eca99b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557eca99b020,0x557ecc8330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f5543523efe7ac2483e29c9ffea82ea980387153' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5370 processed earlier; will process 5659 files now Step #5: ==154696== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557ec12a69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557ec790b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557ec78ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557ec78ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557ec12acd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557ec120db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557ec1208355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557ec129ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557ec426df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557ec426df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557ec426df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557ec426df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557ec426df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557ec426df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557ec426df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557ec426df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557ec426df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557ec426df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557ec6502f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557ec322fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557ec323abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557ec2fe6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557ec2fe6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557ec2fe7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557ec2fe6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557ec2fe6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557ec2fe6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557ec78f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557ec78f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557ec78e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557ec790c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbef46cb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557ec1206b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x61,0x73,0x6d,0x1,0x0,0x0,0x0,0x0,0x4,0x3,0xe0,0xa0,0x9b,0x0,0x4,0x3,0xe0,0xa0,0xbb,0x0,0x4,0x3,0xe0,0xa1,0x9b,0x0,0x4,0x3,0xe0,0xa0,0xab,0x0,0x4,0x3,0xe0,0xa0,0xa0,0x0,0x4,0x3,0xe0,0xa0,0x9b,0x0,0x4,0x3,0xe0,0xa0,0xbb,0x0,0x4,0x3,0xe0,0xa0,0x9b,0x0,0x4,0x3,0xe0,0xa0,0xbb,0x0,0x4,0x3,0xe0,0xa1,0x9b,0x0,0x4,0x3,0xe0,0xa0,0xbf,0x0,0x4,0x3,0xe0,0xa0,0x9b,0x0,0x4,0x3,0xe0,0xa0,0xbb,0x0,0x4,0x3,0xe0,0xa0,0xab,0x0,0x4,0x3,0xe0,0xa1,0x9b,0x0,0x4,0x3,0xe0,0xa0,0xbb,0x0,0x4,0x3,0x0,0x61,0x73,0x6d,0x1,0x0,0xff,0xc,0xc,0xc,0x6f,0xd0,0x0,0x41,0xab,0x0, Step #5: \000asm\001\000\000\000\000\004\003\340\240\233\000\004\003\340\240\273\000\004\003\340\241\233\000\004\003\340\240\253\000\004\003\340\240\240\000\004\003\340\240\233\000\004\003\340\240\273\000\004\003\340\240\233\000\004\003\340\240\273\000\004\003\340\241\233\000\004\003\340\240\277\000\004\003\340\240\233\000\004\003\340\240\273\000\004\003\340\240\253\000\004\003\340\241\233\000\004\003\340\240\273\000\004\003\000asm\001\000\377\014\014\014o\320\000A\253\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5e163b97d6d75be01df6b639d35b2c734c9dd306 Step #5: Base64: AGFzbQEAAAAABAPgoJsABAPgoLsABAPgoZsABAPgoKsABAPgoKAABAPgoJsABAPgoLsABAPgoJsABAPgoLsABAPgoZsABAPgoL8ABAPgoJsABAPgoLsABAPgoKsABAPgoZsABAPgoLsABAMAYXNtAQD/DAwMb9AAQasA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4296 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3869387810 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5649cdc12810, 0x5649cddfc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5649cddfc020,0x5649cfc940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e163b97d6d75be01df6b639d35b2c734c9dd306' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5371 processed earlier; will process 5658 files now Step #5: ==154732== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5649c47079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5649cad6c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5649cad4f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5649cad4f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5649c470dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649c466eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649c4669355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5649c46ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5649c76cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5649c76cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5649c76cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5649c76cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5649c76cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5649c76cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5649c76cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5649c76cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5649c76cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5649c76cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5649c9963f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649c6690b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649c669bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5649c6447c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5649c6447c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5649c6448738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5649c6447874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5649c6447874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5649c6447874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5649cad51abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5649cad5a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5649cad42699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5649cad6d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5c636d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649c4667b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xdb,0x80,0x39,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3f,0x0,0x8,0x0,0x0,0x0,0x39, Step #5: \333\200\333\2009\000*********************************************\333\2009\000*************************************\000\000\000\000\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000?\000\010\000\000\0009 Step #5: artifact_prefix='./'; Test unit written to ./oom-daecdfe0a3aa257e25158aa74fc0765deed9a03a Step #5: Base64: 24DbgDkAKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioq24A5ACoqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAA/AAgAAAA5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4297 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3869893584 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bebb5bb810, 0x55bebb7a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bebb7a5020,0x55bebd63d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/daecdfe0a3aa257e25158aa74fc0765deed9a03a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5372 processed earlier; will process 5657 files now Step #5: ==154768== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55beb20b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55beb8715898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55beb86f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55beb86f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55beb20b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55beb2017b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55beb2012355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55beb20a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55beb5077f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55beb5077f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55beb5077f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55beb5077f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55beb5077f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55beb5077f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55beb5077f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55beb5077f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55beb5077f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55beb5077f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55beb730cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55beb4039b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55beb4044be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55beb3df0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55beb3df0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55beb3df1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55beb3df0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55beb3df0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55beb3df0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55beb86faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55beb8703928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55beb86eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55beb8716112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fce0bec3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55beb2010b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x61,0x3e,0x3c,0x53,0x64,0x3e,0x3c,0x68,0x3e,0x3c,0x54,0x41,0x3e,0x28,0x3c,0x4d,0x45,0x3e,0x3c,0x53,0x2d,0x3e,0x3c,0x65,0x3e,0x3c,0x45,0x49,0x3e,0x3c,0x49,0x69,0x49,0x3e,0x3c,0x74,0x3e,0x3c,0x6e,0x3e,0x3c,0x59,0x57,0x3e,0x3c,0x59,0x3e,0x3c,0x52,0x3e,0x3c,0x57,0x45,0x3e,0x3c,0x63,0x59,0x3e,0x3c,0x55,0x3e,0x3c,0x59,0x31,0x3e,0x3c,0x41,0x2d,0x3e,0x3c,0x65,0x51,0x3e,0x3c,0x46,0x72,0x3e,0x3c,0x41,0x50,0x3e,0x3c,0x4d,0x3e,0x4b,0x46,0x3c,0x45,0x3e,0x3c,0x6c,0x3e,0x3c,0x57,0x3e,0x3c,0x4a,0x3e,0x3c,0x57,0x56,0x3e,0x3c,0x62,0x57,0x3e,0x3c,0x49,0x3e,0x3c,0x43,0x3e,0x3c,0x51,0x46,0x65,0x3e,0x3c,0x41,0x48,0x3e,0x3c, Step #5: <a><Sd><h><TA>(<ME><S-><e><EI><IiI><t><n><YW><Y><R><WE><cY><U><Y1><A-><eQ><Fr><AP><M>KF<E><l><W><J><WV><bW><I><C><QFe><AH>< Step #5: artifact_prefix='./'; Test unit written to ./oom-78dfee86b8ccda56a3ea289ad761ef1d564cb9dc Step #5: Base64: PGE+PFNkPjxoPjxUQT4oPE1FPjxTLT48ZT48RUk+PElpST48dD48bj48WVc+PFk+PFI+PFdFPjxjWT48VT48WTE+PEEtPjxlUT48RnI+PEFQPjxNPktGPEU+PGw+PFc+PEo+PFdWPjxiVz48ST48Qz48UUZlPjxBSD48 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4298 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3870393862 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe5b8b1810, 0x55fe5ba9b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe5ba9b020,0x55fe5d9330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/78dfee86b8ccda56a3ea289ad761ef1d564cb9dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5373 processed earlier; will process 5656 files now Step #5: ==154804== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fe523a69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe58a0b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe589ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe589ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe523acd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe5230db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe52308355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe5239ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe5536df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe5536df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe5536df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe5536df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe5536df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe5536df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe5536df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe5536df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe5536df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe5536df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe57602f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe5432fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe5433abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe540e6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe540e6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe540e7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe540e6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe540e6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe540e6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe589f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe589f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe589e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe58a0c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2af18a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe52306b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x7f,0x8,0x0,0x1,0x0,0x0,0x0,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x0, Step #5: = \177\010\000\001\000\000\000..................................................................................................................\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e4ce755db217d66239300f74042cbb99e381488f Step #5: Base64: PSB/CAABAAAALi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4299 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3870893992 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5625e9167810, 0x5625e935101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625e9351020,0x5625eb1e90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e4ce755db217d66239300f74042cbb99e381488f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5374 processed earlier; will process 5655 files now Step #5: #1 pulse cov: 3714 ft: 3715 exec/s: 0 rss: 174Mb Step #5: ==154840== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5625dfc5c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5625e62c1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625e62a45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625e62a44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5625dfc62d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625dfbc3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625dfbbe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5625dfc54c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5625e2c23f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5625e2c23f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5625e2c23f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5625e2c23f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5625e2c23f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5625e2c23f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5625e2c23f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5625e2c23f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5625e2c23f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5625e2c23f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5625e4eb8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625e1be5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5625e1bf0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5625e199cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5625e199cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5625e199d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5625e199c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5625e199c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5625e199c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5625e62a6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5625e62af928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5625e6297699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5625e62c2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa4db6f2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625dfbbcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x26,0x24,0x24,0x22,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x2d,0x2d,0x2d,0x64,0x0,0x42,0x45,0x47,0x4b,0x4e,0x20,0x73,0x74,0x21,0x0,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x5b,0x2d,0x2d,0xa,0x44,0xa,0x2d,0xa,0x49,0xa,0x35,0xa,0x2d,0x72,0x65,0xa,0x64,0x61,0x6d,0x2d,0x2d,0x5b,0x2d,0x65,0x61,0x6d,0x2d,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0xa,0x64,0x24,0x24,0x24,0x24,0x24,0x24,0x22,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x3f,0x0,0x0,0x0,0x0,0x0,0x2e,0x33, Step #5: s$$$$$$$$$$$&$$\"$$$r$$$---d\000BEGKN st!\000----BEGIN --[--\012D\012-\012I\0125\012-re\012dam--[-eam-$$$$$$$$$$$\012d$$$$$$\"$$$r$$$$$$$r$$$$$$$?\000\000\000\000\000.3 Step #5: artifact_prefix='./'; Test unit written to ./oom-d740f451e1ec80033a2b5b4f203f56263b8d5be2 Step #5: Base64: cyQkJCQkJCQkJCQkJiQkIiQkJHIkJCQtLS1kAEJFR0tOIHN0IQAtLS0tQkVHSU4gLS1bLS0KRAotCkkKNQotcmUKZGFtLS1bLWVhbS0kJCQkJCQkJCQkJApkJCQkJCQkIiQkJHIkJCQkJCQkciQkJCQkJCQ/AAAAAAAuMw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4300 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3871448438 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fd811ba810, 0x55fd813a401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fd813a4020,0x55fd8323c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d740f451e1ec80033a2b5b4f203f56263b8d5be2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5376 processed earlier; will process 5653 files now Step #5: ==154876== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fd77caf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fd7e314898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fd7e2f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fd7e2f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fd77cb5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fd77c16b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fd77c11355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fd77ca7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fd7ac76f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fd7ac76f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fd7ac76f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fd7ac76f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fd7ac76f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fd7ac76f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fd7ac76f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fd7ac76f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fd7ac76f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fd7ac76f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fd7cf0bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fd79c38b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fd79c43be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fd799efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fd799efc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fd799f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fd799ef874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fd799ef874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fd799ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fd7e2f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fd7e302928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fd7e2ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fd7e315112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcbfcd43082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fd77c0fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x3f,0xdb,0xa2,0xdb,0xa2,0x22,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0xdb,0xa2,0xdb,0xa2,0x22,0x22,0x0,0x3c, Step #5: \000?\333\242\333\242\"5555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555\333\242\333\242\"\"\000< Step #5: artifact_prefix='./'; Test unit written to ./oom-d1d9c53346fae7f02fd36d5cbffcb0f3849f69da Step #5: Base64: AD/botuiIjU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTXbotuiIiIAPA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4301 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3871954079 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af08b4b810, 0x55af08d3501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af08d35020,0x55af0abcd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d1d9c53346fae7f02fd36d5cbffcb0f3849f69da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5377 processed earlier; will process 5652 files now Step #5: ==154912== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aeff6409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af05ca5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af05c885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af05c884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aeff646d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aeff5a7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aeff5a2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aeff638c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55af02607f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55af02607f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55af02607f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55af02607f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55af02607f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55af02607f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55af02607f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55af02607f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55af02607f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55af02607f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af0489cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af015c9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af015d4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af01380c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af01380c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af01381738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af01380874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af01380874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af01380874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af05c8aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af05c93928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af05c7b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af05ca6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3950d45082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aeff5a0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x0,0x0,0x1,0x20,0x0,0x60,0x1,0x0,0x2,0x32,0x0,0x1,0x3,0x20,0x49,0x44,0x37,0x2,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x20,0x4e,0x2d,0x2d,0x3d,0xa,0x2d,0x4e,0x2d,0x2d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x13,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x20,0x0,0x4,0x13,0x43,0x4f,0x4d,0x60,0x1,0x20,0x0,0x60,0x1,0x43,0x4f,0x4d,0x31,0x0,0xa,0x3d,0xa,0x3d,0xa,0x5d,0x3d,0xa,0x3d,0xa,0x60,0x1,0x0,0x0,0x32,0x38,0x39,0x35, Step #5: ID3\004\000\000\001 \000`\001\000\0022\000\001\003 ID7\002\005-----BEGI N--=\012-N--\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\023\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000\000 \000\004\023COM`\001 \000`\001COM1\000\012=\012=\012]=\012=\012`\001\000\0002895 Step #5: artifact_prefix='./'; Test unit written to ./oom-97d80c28a32793a14b4e12b32ccb9f889b1bbbcf Step #5: Base64: SUQzBAAAASAAYAEAAjIAAQMgSUQ3AgUtLS0tLUJFR0kgTi0tPQotTi0tCgo9Cj0KPQo9Cj0KPQo9Cj0KPQoTCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoAACAABBNDT01gASAAYAFDT00xAAo9Cj0KXT0KPQpgAQAAMjg5NQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4302 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3872591459 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563b751d7810, 0x563b753c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563b753c1020,0x563b772590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/97d80c28a32793a14b4e12b32ccb9f889b1bbbcf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5378 processed earlier; will process 5651 files now Step #5: ==154948== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563b6bccc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563b72331898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563b723145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563b723144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563b6bcd2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563b6bc33b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563b6bc2e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563b6bcc4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563b6ec93f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563b6ec93f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563b6ec93f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563b6ec93f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563b6ec93f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563b6ec93f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563b6ec93f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563b6ec93f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563b6ec93f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563b6ec93f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563b70f28f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563b6dc55b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563b6dc60be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563b6da0cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563b6da0cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563b6da0d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563b6da0c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563b6da0c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563b6da0c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563b72316abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563b7231f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563b72307699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563b72332112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3176128082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563b6bc2cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x77,0xcd,0x95,0xcc,0x8b,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xcc,0x8b,0xcc,0x9b,0xcd,0x95,0xcd,0x95,0xcd,0x95,0xcd,0x9b,0xcd,0x95,0xcd,0x9b,0xcd,0x95,0xcd,0x95,0xcc,0x8b,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xcc,0x8b,0xcc,0x9b,0xcd,0x95,0xcd,0x95,0xcd,0x95,0xcd,0x9b,0xcd,0x95,0xcd,0x9b,0xcd,0x95,0xcd,0x95,0xcd,0x9b,0xe0,0xbe,0x81,0x2e,0xcc,0x83,0xcd,0x95,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x95,0xcd,0x9b,0xcd,0x95,0xcd,0x9b,0xcd,0x8b,0xcc,0x95,0xcd,0x9b,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xcd,0x95,0xcd,0x95,0xcd,0x8b,0xcc,0x95,0xcd,0x95,0xcd,0x95,0xcd,0x9b,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81,0xe0,0xbe,0x81, Step #5: ws:w\315\225\314\213\340\276\201\340\276\201\314\213\314\233\315\225\315\225\315\225\315\233\315\225\315\233\315\225\315\225\314\213\340\276\201\340\276\201\314\213\314\233\315\225\315\225\315\225\315\233\315\225\315\233\315\225\315\225\315\233\340\276\201.\314\203\315\225\315\204\315\204\315\204\315\225\315\233\315\225\315\233\315\213\314\225\315\233\340\276\201\340\276\201\315\225\315\225\315\213\314\225\315\225\315\225\315\233\340\276\201\340\276\201\340\276\201\340\276\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-854e7e26a4e0d77e385484bfcfcb1d9bd54dea1d Step #5: Base64: d3M6d82VzIvgvoHgvoHMi8ybzZXNlc2VzZvNlc2bzZXNlcyL4L6B4L6BzIvMm82VzZXNlc2bzZXNm82VzZXNm+C+gS7Mg82VzYTNhM2EzZXNm82VzZvNi8yVzZvgvoHgvoHNlc2VzYvMlc2VzZXNm+C+geC+geC+geC+gQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4303 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3873092955 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555edcb36810, 0x555edcd2001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555edcd20020,0x555edebb80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/854e7e26a4e0d77e385484bfcfcb1d9bd54dea1d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5379 processed earlier; will process 5650 files now Step #5: #1 pulse cov: 3672 ft: 3673 exec/s: 0 rss: 176Mb Step #5: ==154984== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555ed362b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ed9c90898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ed9c735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ed9c734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ed3631d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ed3592b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ed358d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ed3623c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ed65f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ed65f2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ed65f2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ed65f2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ed65f2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ed65f2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ed65f2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ed65f2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ed65f2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ed65f2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555ed8887f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ed55b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ed55bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ed536bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ed536bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ed536c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ed536b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ed536b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ed536b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ed9c75abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ed9c7e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ed9c66699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ed9c91112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fad46586082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ed358bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x71,0x42,0x74,0x50,0x30,0x57,0x70,0x35,0x66,0x50,0x44,0x62,0x6a,0x4d,0x5a,0x50,0x54,0x70,0x32,0x67,0x66,0x69,0x31,0x54,0x52,0x4f,0x4f,0x30,0x59,0x31,0x4b,0x31,0x74,0x59,0x76,0x46,0x2f,0x78,0x2b,0x53,0x77,0x31,0x30,0xa,0x69,0x64,0x20,0x65,0x64,0x32,0x35,0x35,0x31,0x39,0x20,0x5a,0x31,0x61,0x39,0x32,0x32,0x33,0x61,0x31,0x47,0x75,0x65,0x64,0x64,0x4e,0x42,0x69,0x4c,0x6b,0x79,0x79,0x6c,0x67,0x48,0x77,0x32,0x36,0x4f,0x55,0x30,0x4f,0x55,0x51,0x76,0x31,0x74,0x2f,0x58,0x2b,0x6a,0x52,0x6e,0x6b,0x65, Step #5: onion-key\012ntor-onion-key qBtP0Wp5fPDbjMZPTp2gfi1TROO0Y1K1tYvF/x+Sw10\012id ed25519 Z1a9223a1GueddNBiLkyylgHw26OU0OUQv1t/X+jRnke Step #5: artifact_prefix='./'; Test unit written to ./oom-57cb585f0a28b71ddfa9890f3bc63c63986be521 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHFCdFAwV3A1ZlBEYmpNWlBUcDJnZmkxVFJPTzBZMUsxdFl2Ri94K1N3MTAKaWQgZWQyNTUxOSBaMWE5MjIzYTFHdWVkZE5CaUxreXlsZ0h3MjZPVTBPVVF2MXQvWCtqUm5rZQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4304 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3873636494 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cbf00cb810, 0x55cbf02b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cbf02b5020,0x55cbf214d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/57cb585f0a28b71ddfa9890f3bc63c63986be521' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5381 processed earlier; will process 5648 files now Step #5: ==155020== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cbe6bc09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cbed225898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cbed2085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cbed2084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cbe6bc6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cbe6b27b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cbe6b22355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cbe6bb8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cbe9b87f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cbe9b87f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cbe9b87f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cbe9b87f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cbe9b87f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cbe9b87f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cbe9b87f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cbe9b87f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cbe9b87f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cbe9b87f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cbebe1cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cbe8b49b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cbe8b54be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cbe8900c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cbe8900c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cbe8901738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cbe8900874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cbe8900874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cbe8900874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cbed20aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cbed213928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cbed1fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cbed226112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa18c20082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cbe6b20b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0xd,0x7b,0x7d,0x7d,0x6c,0x6f,0x6f,0x70,0x7b,0x7b,0x7d,0x7b,0x7d,0x22,0x30,0x22,0x5b,0x2d,0x30,0x2d,0x31,0x2e,0x2e,0x33,0x2f,0x34,0x2d,0x35,0x5d,0x3c,0x3d,0x22,0x22,0x3b,0x78,0x9,0x9,0x9,0x2e,0x57,0x57,0x3d,0x78,0x9,0x3b,0x22,0x0,0x4,0x1,0x21,0x0,0x0,0x6d,0x22,0x5b,0x2d,0x30,0x25,0x31,0x2e,0x2e,0x32,0x2f,0x34,0x2d,0x35,0x5d,0x3c,0x3d,0x22,0x2,0xc3,0x9f,0x3b,0x78,0x9,0x22,0x2b,0x30,0x7d,0x80,0x63,0x21,0x21,0x0,0x0,0x21,0x0,0x0,0x0,0x0,0x0,0x5f,0x6f,0x70,0x74,0x69,0x6f,0x6e,0x28,0x2b,0x22,0x5b,0x2d,0x30,0x5d,0x3e,0x3d,0x22,0x22,0x22,0x22,0x3b,0x3b,0x3b,0x35,0x30,0x5f,0x69,0x38,0xdf,0x3e,0x7b, Step #5: {\015{}}loop{{}{}\"0\"[-0-1..3/4-5]<=\"\";x\011\011\011.WW=x\011;\"\000\004\001!\000\000m\"[-0%1..2/4-5]<=\"\002\303\237;x\011\"+0}\200c!!\000\000!\000\000\000\000\000_option(+\"[-0]>=\"\"\"\";;;50_i8\337>{ Step #5: artifact_prefix='./'; Test unit written to ./oom-f659c930f9f978d110ccc3f46fd42bcdb6467278 Step #5: Base64: ew17fX1sb29we3t9e30iMCJbLTAtMS4uMy80LTVdPD0iIjt4CQkJLldXPXgJOyIABAEhAABtIlstMCUxLi4yLzQtNV08PSICw587eAkiKzB9gGMhIQAAIQAAAAAAX29wdGlvbigrIlstMF0+PSIiIiI7Ozs1MF9pON8+ew== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4305 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3874139398 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5621b6b2c810, 0x5621b6d1601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5621b6d16020,0x5621b8bae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f659c930f9f978d110ccc3f46fd42bcdb6467278' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5382 processed earlier; will process 5647 files now Step #5: ==155056== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5621ad6219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5621b3c86898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5621b3c695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5621b3c694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5621ad627d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5621ad588b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5621ad583355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5621ad619c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5621b05e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5621b05e8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5621b05e8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5621b05e8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5621b05e8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5621b05e8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5621b05e8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5621b05e8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5621b05e8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5621b05e8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5621b287df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5621af5aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5621af5b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5621af361c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5621af361c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5621af362738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5621af361874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5621af361874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5621af361874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5621b3c6babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5621b3c74928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5621b3c5c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5621b3c87112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f24f9a65082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5621ad581b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xae,0xf3,0xab,0xaa,0xa8,0xf3,0xa5,0xaa,0xae,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xba,0xaa,0xf3,0xaa,0xaa,0xae,0xf3,0xab,0xa8,0xa8,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xa9,0xae,0xf3,0xab,0xaa,0xaa,0xf3,0xaa,0xaa,0xae,0xf0,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xaa,0xf3,0xaa,0xaa,0xae,0xf3,0xaa,0xaa,0xa3, Step #5: \363\252\252\252\363\252\252\256\363\252\252\252\363\252\252\252\363\252\252\256\363\253\252\250\363\245\252\256\363\252\252\256\363\252\252\256\363\252\252\252\363\252\252\256\363\252\252\256\363\252\252\252\363\252\272\252\363\252\252\256\363\253\250\250\363\252\252\256\363\252\252\256\363\252\252\256\363\252\252\252\363\252\252\256\363\252\252\252\363\252\252\252\363\252\251\256\363\253\252\252\363\252\252\256\360\252\252\256\363\252\252\256\363\252\252\252\363\252\252\256\363\252\252\243 Step #5: artifact_prefix='./'; Test unit written to ./oom-f1904c48d67921bf88a8a567dd9c0c79a7e9ff1a Step #5: Base64: 86qqqvOqqq7zqqqq86qqqvOqqq7zq6qo86WqrvOqqq7zqqqu86qqqvOqqq7zqqqu86qqqvOquqrzqqqu86uoqPOqqq7zqqqu86qqrvOqqqrzqqqu86qqqvOqqqrzqqmu86uqqvOqqq7wqqqu86qqrvOqqqrzqqqu86qqow== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4306 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3874638025 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cd746bb810, 0x55cd748a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cd748a5020,0x55cd7673d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f1904c48d67921bf88a8a567dd9c0c79a7e9ff1a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5383 processed earlier; will process 5646 files now Step #5: ==155092== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cd6b1b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cd71815898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cd717f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cd717f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cd6b1b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cd6b117b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cd6b112355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cd6b1a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cd6e177f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cd6e177f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cd6e177f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cd6e177f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cd6e177f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cd6e177f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cd6e177f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cd6e177f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cd6e177f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cd6e177f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cd7040cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cd6d139b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cd6d144be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cd6cef0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cd6cef0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cd6cef1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cd6cef0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cd6cef0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cd6cef0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cd717faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cd71803928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cd717eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cd71816112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f54c2159082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cd6b110b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2c,0x1c,0x2d,0xa,0x2d,0xa,0x2d,0xef,0xbb,0xbe,0x1c,0x2d,0xa,0x2d,0xf3,0xa0,0x80,0xb3,0xa,0x2d,0xa,0xf3,0xa0,0x80,0xbf,0x2d,0xa,0x2d,0xa,0x36,0x30,0x35,0x38,0x36,0x37,0x34,0x35,0x34,0xe2,0x81,0xa0,0x30,0x32,0x36,0x34,0x34,0x30,0x39,0x30,0x33,0x31,0x31,0x35,0x33,0x36,0x36,0x31,0x65,0x6e,0xa,0xa,0xa,0xa,0xa,0x2d,0x2d,0xa,0xa,0x2c,0x1c,0x2d,0xa,0x2d,0xa,0x2d,0xef,0xbb,0xbe,0x1c,0x2d,0xa,0x2d,0xf3,0xa0,0x80,0xb3,0xa,0x2d,0xa,0xf3,0xa0,0x80,0xbf,0x36,0x36,0x31,0x65,0x6e,0xa,0xa,0xa,0xa,0xa,0x2d,0x2d,0xa,0xa,0x2c,0x1c,0x2d,0xa,0x2d,0xa,0x2d,0x1c,0x2d,0xa, Step #5: -\012\012\012--\012,\034-\012-\012-\357\273\276\034-\012-\363\240\200\263\012-\012\363\240\200\277-\012-\012605867454\342\201\2400264409031153661en\012\012\012\012\012--\012\012,\034-\012-\012-\357\273\276\034-\012-\363\240\200\263\012-\012\363\240\200\277661en\012\012\012\012\012--\012\012,\034-\012-\012-\034-\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-b3d0ab124c0f59c506fb67f6daf3548af1c542bd Step #5: Base64: LQoKCi0tCiwcLQotCi3vu74cLQot86CAswotCvOggL8tCi0KNjA1ODY3NDU04oGgMDI2NDQwOTAzMTE1MzY2MWVuCgoKCgotLQoKLBwtCi0KLe+7vhwtCi3zoICzCi0K86CAvzY2MWVuCgoKCgotLQoKLBwtCi0KLRwtCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4307 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3875151287 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55696448a810, 0x55696467401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556964674020,0x55696650c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3d0ab124c0f59c506fb67f6daf3548af1c542bd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5384 processed earlier; will process 5645 files now Step #5: ==155128== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55695af7f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5569615e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5569615c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5569615c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55695af85d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55695aee6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55695aee1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55695af77c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55695df46f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55695df46f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55695df46f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55695df46f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55695df46f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55695df46f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55695df46f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55695df46f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55695df46f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55695df46f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5569601dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55695cf08b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55695cf13be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55695ccbfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55695ccbfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55695ccc0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55695ccbf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55695ccbf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55695ccbf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5569615c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5569615d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5569615ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5569615e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa4bb472082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55695aedfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x9,0xa,0xa,0xa,0xb,0x5b,0xa,0xa,0xa,0x22,0x27,0xa,0x2d,0xa,0xa,0xa,0xb,0x5b,0xa,0xa,0xa,0x22,0x27,0xa,0x2d,0xa,0xa,0xa,0xb,0x5b,0xa,0xa,0xa,0x22,0x27,0xa,0x2d,0xa,0xa,0xa,0xb,0x5b,0xa,0xa,0xa,0x22,0x27,0xa,0x2d,0xa,0xa,0xa,0xb,0x5b,0xa,0xa,0xa,0x22,0x27,0xa,0x2d,0xa,0xa,0xa,0xb,0x5b,0x22,0x27,0xa,0xa,0x2d,0xa,0xa,0xa,0xb,0x5b,0xa,0xa,0xa,0x22,0x27,0xa,0x2d,0xa,0xa,0xa,0xb,0x5b,0xa,0xa,0xa,0x22,0x27,0xa,0x2d,0xa,0xa,0xa,0xb,0x5b,0xa,0xa,0xa,0x22,0x27,0xa,0x2d,0xa,0xa,0xa,0xb,0x5b,0xa,0xa,0xa,0x22,0x27,0xa,0x2d,0xa,0xa,0xa,0xb,0x5b, Step #5: \011\012\012\012\013[\012\012\012\"'\012-\012\012\012\013[\012\012\012\"'\012-\012\012\012\013[\012\012\012\"'\012-\012\012\012\013[\012\012\012\"'\012-\012\012\012\013[\012\012\012\"'\012-\012\012\012\013[\"'\012\012-\012\012\012\013[\012\012\012\"'\012-\012\012\012\013[\012\012\012\"'\012-\012\012\012\013[\012\012\012\"'\012-\012\012\012\013[\012\012\012\"'\012-\012\012\012\013[ Step #5: artifact_prefix='./'; Test unit written to ./oom-2747435b00a3cf6bf785ec7edd4401c2c8262d67 Step #5: Base64: CQoKCgtbCgoKIicKLQoKCgtbCgoKIicKLQoKCgtbCgoKIicKLQoKCgtbCgoKIicKLQoKCgtbCgoKIicKLQoKCgtbIicKCi0KCgoLWwoKCiInCi0KCgoLWwoKCiInCi0KCgoLWwoKCiInCi0KCgoLWwoKCiInCi0KCgoLWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4308 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3875668062 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557978c98810, 0x557978e8201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557978e82020,0x55797ad1a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2747435b00a3cf6bf785ec7edd4401c2c8262d67' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5385 processed earlier; will process 5644 files now Step #5: ==155164== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55796f78d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557975df2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557975dd55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557975dd54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55796f793d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55796f6f4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55796f6ef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55796f785c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557972754f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557972754f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557972754f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557972754f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557972754f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557972754f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557972754f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557972754f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557972754f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557972754f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579749e9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557971716b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557971721be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5579714cdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5579714cdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5579714ce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5579714cd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5579714cd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5579714cd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557975dd7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557975de0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557975dc8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557975df3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd701782082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55796f6edb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x75,0x5f,0x74,0x5f,0x69,0x69,0x5f,0x31,0x39,0x39,0x36,0x2d,0x31,0x39,0x30,0x31,0x2d,0x72,0x5f,0x74,0x5f,0x69,0x78,0x5f,0x31,0x39,0x39,0x36,0x2d,0x31,0x39,0x30,0x31,0x5f,0x74,0x5f,0x69,0x78,0x5f,0x31,0x39,0x39,0x36,0x2d,0x31,0x39,0x30,0x31,0x2d,0x72,0x5f,0x74,0x5f,0x69,0x78,0x5f,0x31,0x39,0x39,0x36,0x2d,0x31,0x39,0x30,0x31,0x2d,0x72,0x5f,0x74,0x5f,0x69,0x78,0x5f,0x31,0x39,0x39,0x36,0x2d,0x31,0x39,0x30,0x31,0x5f,0x74,0x5f,0x69,0x78,0x5f,0x31,0x39,0x39,0x36,0x2d,0x31,0x39,0x30,0x31,0x2d,0x72,0x5f,0x74,0x5f,0x69,0x78,0x5f,0x31,0x39,0x39,0x36,0x2d,0x31,0x39,0x30,0x31,0x2d,0x72,0x2d,0x75,0x5f,0x67,0x7a,0x7a,0x7a, Step #5: fu_t_ii_1996-1901-r_t_ix_1996-1901_t_ix_1996-1901-r_t_ix_1996-1901-r_t_ix_1996-1901_t_ix_1996-1901-r_t_ix_1996-1901-r-u_gzzz Step #5: artifact_prefix='./'; Test unit written to ./oom-63b2f9fc1b7cbfbc038314506a30090beedd1550 Step #5: Base64: ZnVfdF9paV8xOTk2LTE5MDEtcl90X2l4XzE5OTYtMTkwMV90X2l4XzE5OTYtMTkwMS1yX3RfaXhfMTk5Ni0xOTAxLXJfdF9peF8xOTk2LTE5MDFfdF9peF8xOTk2LTE5MDEtcl90X2l4XzE5OTYtMTkwMS1yLXVfZ3p6eg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4309 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3876163311 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c9c879810, 0x559c9ca6301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c9ca63020,0x559c9e8fb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/63b2f9fc1b7cbfbc038314506a30090beedd1550' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5386 processed earlier; will process 5643 files now Step #5: #1 pulse cov: 3711 ft: 3712 exec/s: 0 rss: 175Mb Step #5: ==155200== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559c9336e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c999d3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c999b65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c999b64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c93374d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c932d5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c932d0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c93366c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c96335f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c96335f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c96335f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c96335f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c96335f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c96335f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c96335f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c96335f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c96335f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c96335f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c985caf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c952f7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c95302be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c950aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c950aec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c950af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c950ae874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c950ae874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c950ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c999b8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c999c1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c999a9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c999d4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd96abd8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c932ceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x24,0x24,0x35,0xa,0x2d,0x72,0x65,0xa,0x64,0x61,0x6d,0x2d,0x2d,0x5b,0x2d,0x65,0x61,0x6d,0x2d,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0xa,0x64,0x24,0x24,0x24,0x24,0x24,0x24,0x22,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x3f,0x0,0x0,0x0,0x0,0x0,0xa,0x64,0x61,0x6d,0x2d,0x2d,0x5b,0x2d,0x65,0x61,0x6d,0x2d,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0xa,0x64,0x24,0x24,0x24,0x24,0x24,0x24,0x22,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x3f,0x0,0x0,0x0,0x0,0x0,0x2e,0x33, Step #5: s$$5\012-re\012dam--[-eam-$$$$$$$$$$$\012d$$$$$$\"$$$r$$$$$$$r$$$$$$$?\000\000\000\000\000\012dam--[-eam-$$$$$$$$$$$\012d$$$$$$\"$$$r$$$$$$$r$$$$$$$?\000\000\000\000\000.3 Step #5: artifact_prefix='./'; Test unit written to ./oom-17734d3adcc6d2d85e8e1ac177aa6c1cb2520c02 Step #5: Base64: cyQkNQotcmUKZGFtLS1bLWVhbS0kJCQkJCQkJCQkJApkJCQkJCQkIiQkJHIkJCQkJCQkciQkJCQkJCQ/AAAAAAAKZGFtLS1bLWVhbS0kJCQkJCQkJCQkJApkJCQkJCQkIiQkJHIkJCQkJCQkciQkJCQkJCQ/AAAAAAAuMw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4310 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3876713922 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d4a141b810, 0x55d4a160501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d4a1605020,0x55d4a349d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/17734d3adcc6d2d85e8e1ac177aa6c1cb2520c02' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5388 processed earlier; will process 5641 files now Step #5: #1 pulse cov: 3608 ft: 3609 exec/s: 0 rss: 175Mb Step #5: ==155236== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d497f109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d49e575898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d49e5585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d49e5584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d497f16d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d497e77b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d497e72355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d497f08c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d49aed7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d49aed7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d49aed7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d49aed7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d49aed7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d49aed7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d49aed7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d49aed7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d49aed7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d49aed7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d49d16cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d499e99b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d499ea4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d499c50c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d499c50c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d499c51738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d499c50874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d499c50874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d499c50874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d49e55aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d49e563928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d49e54b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d49e576112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ccd30e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d497e70b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf2,0xa0,0x8f,0x88,0xf4,0x83,0x80,0xa9,0xf4,0x89,0x80,0x93,0xf3,0xa0,0x87,0x87,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0xa9,0xf4,0x87,0x80,0x93,0xf3,0xa0,0x80,0x99,0xf0,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf3,0xa0,0x81,0xa1,0xf4,0x83,0x80,0x9f,0xf3,0xa0,0xa0,0x99,0xf0,0xb5,0x86,0x88,0xf4,0x87,0x88,0x83,0xf4,0x83,0x81,0x99,0xf2,0xa0,0x8f,0x88,0xf4,0x83,0x80,0xa9,0xf4,0x89,0x80,0x93,0xf3,0xa0,0x87,0x87,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0xa9,0xf4,0x87,0x80,0x93,0xf3,0xa0,0x80,0x99,0xf0,0xb5,0xa0,0x8e,0xf4,0x83,0x87,0x88,0xf3,0xa0,0x81,0xa1,0xf4,0x83,0x80,0x9f,0xf3,0xa1,0xa0,0x98,0xf0,0xb5,0x87,0x88,0xf4,0x87,0x88,0x83,0xf4, Step #5: \362\240\217\210\364\203\200\251\364\211\200\223\363\240\207\207\364\203\200\251\364\207\200\251\364\207\200\223\363\240\200\231\360\265\207\210\364\203\207\210\363\240\201\241\364\203\200\237\363\240\240\231\360\265\206\210\364\207\210\203\364\203\201\231\362\240\217\210\364\203\200\251\364\211\200\223\363\240\207\207\364\203\200\251\364\207\200\251\364\207\200\223\363\240\200\231\360\265\240\216\364\203\207\210\363\240\201\241\364\203\200\237\363\241\240\230\360\265\207\210\364\207\210\203\364 Step #5: artifact_prefix='./'; Test unit written to ./oom-ebf91971a4d40aa43efb53c33e9edb29d025240a Step #5: Base64: 8qCPiPSDgKn0iYCT86CHh/SDgKn0h4Cp9IeAk/OggJnwtYeI9IOHiPOggaH0g4Cf86CgmfC1hoj0h4iD9IOBmfKgj4j0g4Cp9ImAk/Ogh4f0g4Cp9IeAqfSHgJPzoICZ8LWgjvSDh4jzoIGh9IOAn/OhoJjwtYeI9IeIg/Q= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4311 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3877255761 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556489928810, 0x556489b1201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556489b12020,0x55648b9aa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ebf91971a4d40aa43efb53c33e9edb29d025240a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5390 processed earlier; will process 5639 files now Step #5: ==155272== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55648041d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556486a82898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556486a655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556486a654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556480423d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556480384b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55648037f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556480415c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564833e4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564833e4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564833e4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564833e4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564833e4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564833e4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564833e4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564833e4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564833e4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564833e4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556485679f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5564823a6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5564823b1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55648215dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55648215dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55648215e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55648215d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55648215d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55648215d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556486a67abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556486a70928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556486a58699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556486a83112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9bb4fea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55648037db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4,0x33,0x3,0x73,0x65,0x64,0x20,0x35,0x20,0x71,0x70,0x78,0x60,0x74,0x6d,0x21,0x60,0x31,0x50,0x55,0x53,0x4c,0x32,0x54,0x0,0x0,0x0,0x5,0x20,0x0,0x0,0x20,0x47,0xff,0xff,0xff,0x32,0x54,0x0,0x0,0x0,0x5,0x20,0x0,0x0,0x20,0x47,0xff,0xff,0xff,0x62,0xc7,0x50, Step #5: ILLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLL\0043\003sed 5 qpx`tm!`1PUSL2T\000\000\000\005 \000\000 G\377\377\3772T\000\000\000\005 \000\000 G\377\377\377b\307P Step #5: artifact_prefix='./'; Test unit written to ./oom-6377b933f69f68a931d1a5ed10c8fb86f05d1835 Step #5: Base64: SUxMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMBDMDc2VkIDUgcXB4YHRtIWAxUFVTTDJUAAAABSAAACBH////MlQAAAAFIAAAIEf///9ix1A= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4312 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3877880938 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55741682b810, 0x557416a1501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557416a15020,0x5574188ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6377b933f69f68a931d1a5ed10c8fb86f05d1835' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5391 processed earlier; will process 5638 files now Step #5: #1 pulse cov: 4360 ft: 4361 exec/s: 0 rss: 177Mb Step #5: ==155308== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55740d3209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557413985898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5574139685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5574139684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55740d326d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55740d287b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55740d282355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55740d318c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5574102e7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5574102e7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5574102e7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5574102e7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5574102e7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5574102e7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5574102e7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5574102e7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5574102e7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5574102e7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55741257cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55740f2a9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55740f2b4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55740f060c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55740f060c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55740f061738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55740f060874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55740f060874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55740f060874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55741396aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557413973928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55741395b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557413986112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc6e0e00082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55740d280b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x42,0x3c,0xdb,0xbe,0x7e,0x19,0x0,0x0,0x0,0x2d,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2d,0x0,0x0,0x2a,0x0,0x0,0x0,0x0,0x0,0xa,0x2d,0xa,0x64,0xa,0x64,0x19,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2d,0x0,0x0,0x2a,0x0,0x0,0x1,0x3,0x0,0x0,0x0,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0xa,0xdc,0x7e,0xa,0xd2,0xa,0x0,0xa,0x2d,0x4d,0x44,0x61,0x6e, Step #5: ~~~~~~B<\333\276~\031\000\000\000--\012,\012-\012d\012-\012d\012d\012-\000\000*\000\000\000\000\000\012-\012d\012d\031=\012=\012=\012=\012=\012=\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000-\012d\012-\012d\012d\012-\000\000*\000\000\001\003\000\000\000\031\031\031\031\031\031\031\031\031\031\031\031\031\031\012\334~\012\322\012\000\012-MDan Step #5: artifact_prefix='./'; Test unit written to ./oom-64ae744abc1d26e113fbb5bdd29c338005809b27 Step #5: Base64: fn5+fn5+Qjzbvn4ZAAAALS0KLAotCmQKLQpkCmQKLQAAKgAAAAAACi0KZApkGT0KPQo9Cj0KPQo9AAAAAAAAAAAAAAAAAAAAAAAAAAAtCmQKLQpkCmQKLQAAKgAAAQMAAAAZGRkZGRkZGRkZGRkZGQrcfgrSCgAKLU1EYW4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4313 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3878432691 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff54d67810, 0x55ff54f5101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff54f51020,0x55ff56de90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/64ae744abc1d26e113fbb5bdd29c338005809b27' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5393 processed earlier; will process 5636 files now Step #5: ==155344== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ff4b85c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff51ec1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff51ea45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff51ea44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff4b862d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff4b7c3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff4b7be355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff4b854c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff4e823f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff4e823f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff4e823f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff4e823f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff4e823f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff4e823f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff4e823f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff4e823f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff4e823f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff4e823f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff50ab8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff4d7e5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff4d7f0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff4d59cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff4d59cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff4d59d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff4d59c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff4d59c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff4d59c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff51ea6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff51eaf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff51e97699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff51ec2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f92a1767082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff4b7bcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x40,0x2a,0x2a,0x2a,0x2a,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x3b,0x2a,0x2a,0x28,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x1e,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x3b,0x2a,0x2a,0x2a,0x4f,0x53,0x4f,0x53,0x53,0x2a,0x2a,0x2a, Step #5: *******************************************************************************@****\000******;**(******\000\000\036*********;***OSOSS*** Step #5: artifact_prefix='./'; Test unit written to ./oom-bcdbf3637d5febc3bcc75021aeacff070a79ac8a Step #5: Base64: KioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKkAqKioqACoqKioqKjsqKigqKioqKioAAB4qKioqKioqKio7KioqT1NPU1MqKio= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4314 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3878937116 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555f07ab9810, 0x555f07ca301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555f07ca3020,0x555f09b3b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bcdbf3637d5febc3bcc75021aeacff070a79ac8a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5394 processed earlier; will process 5635 files now Step #5: ==155380== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555efe5ae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555f04c13898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555f04bf65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555f04bf64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555efe5b4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555efe515b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555efe510355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555efe5a6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555f01575f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555f01575f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555f01575f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555f01575f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555f01575f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555f01575f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555f01575f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555f01575f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555f01575f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555f01575f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555f0380af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555f00537b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555f00542be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555f002eec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555f002eec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555f002ef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555f002ee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555f002ee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555f002ee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555f04bf8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555f04c01928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555f04be9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555f04c14112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e31088082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555efe50eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x23,0x76,0xa,0x72,0x45,0x45,0x45,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x67,0x6c,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x79,0x66,0x0,0x0,0x0,0x0,0x0,0x0,0x82,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x90, Step #5: t#v\012rEEE\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000glxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxyf\000\000\000\000\000\000\202\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\220 Step #5: artifact_prefix='./'; Test unit written to ./oom-de2ae7a3aa8c21b9fd6f2f3a3f1737eef08f548d Step #5: Base64: dCN2CnJFRUUAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAZ2x4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHlmAAAAAAAAggAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4315 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3879440995 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b82bf51810, 0x55b82c13b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b82c13b020,0x55b82dfd30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de2ae7a3aa8c21b9fd6f2f3a3f1737eef08f548d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5395 processed earlier; will process 5634 files now Step #5: #1 pulse cov: 4318 ft: 4319 exec/s: 0 rss: 175Mb Step #5: ==155416== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b822a469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b8290ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b82908e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b82908e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b822a4cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b8229adb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b8229a8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b822a3ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b825a0df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b825a0df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b825a0df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b825a0df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b825a0df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b825a0df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b825a0df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b825a0df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b825a0df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b825a0df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b827ca2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b8249cfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b8249dabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b824786c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b824786c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b824787738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b824786874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b824786874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b824786874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b829090abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b829099928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b829081699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b8290ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa4e1f1c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b8229a6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x24,0x24,0x24,0x24,0x24,0x1e,0x24,0x6c,0x6f,0x72,0x65,0x6d,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x12,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x3,0x3,0x3,0x3,0x3,0x25,0x73,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x26,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x93,0x24,0x24,0x24,0xdb,0xdd,0x24,0xdb,0xcc,0x3,0x7e,0x47,0x46,0x44,0x7e,0x91,0x47, Step #5: ~~~<\333\276~~~$$$$$\036$lorem$$$$$$$$$$$$$$$$$\022$$$$$$$$$$$$\003\003\003\003\003%s\003\003\003\003\003\003\003\003$$$$$$$$$$$$$$$$$$$$$$$$$&$$$$$$$$$$$$$$$$\223$$$\333\335$\333\314\003~GFD~\221G Step #5: artifact_prefix='./'; Test unit written to ./oom-c5b55ceaed7ac4c62035fb43ae3c7ea7674ce604 Step #5: Base64: fn5+PNu+fn5+JCQkJCQeJGxvcmVtJCQkJCQkJCQkJCQkJCQkJCQSJCQkJCQkJCQkJCQkAwMDAwMlcwMDAwMDAwMDJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCYkJCQkJCQkJCQkJCQkJCQkkyQkJNvdJNvMA35HRkR+kUc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4316 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3880000399 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe1cf16810, 0x55fe1d10001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe1d100020,0x55fe1ef980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c5b55ceaed7ac4c62035fb43ae3c7ea7674ce604' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5397 processed earlier; will process 5632 files now Step #5: ==155452== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fe13a0b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe1a070898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe1a0535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe1a0534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe13a11d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe13972b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe1396d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe13a03c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe169d2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe169d2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe169d2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe169d2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe169d2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe169d2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe169d2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe169d2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe169d2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe169d2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe18c67f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe15994b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe1599fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe1574bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe1574bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe1574c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe1574b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe1574b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe1574b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe1a055abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe1a05e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe1a046699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe1a071112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a9764a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe1396bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x61,0x5c,0x23,0x73,0x63,0x65,0x6e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x27,0x0,0x0,0x0,0x0,0x0,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x74,0x20,0x5c,0x23,0x23,0x68,0xb,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x21,0x24,0x27,0x21,0x31,0x24,0x36,0x31,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x74,0x20,0x5c,0x23,0x23,0x68,0xb,0xb,0xb,0xea,0x14,0xb,0xb,0xb,0xb,0x14,0xb,0xb,0xb,0xb,0x3,0xb,0x11,0x0,0x0,0x0,0x21,0x0,0xfd,0xff,0x4f,0xb,0xb, Step #5: a\\#scen\000\000\000\000\000\000\000\000$'\000\000\000\000\000\012\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000t \\##h\013\000\000\000\000\000\000\000\000\000\000\000!$'!1$61$\000\000\000\000\000\000\000\000\000\000\000\000\000t \\##h\013\013\013\352\024\013\013\013\013\024\013\013\013\013\003\013\021\000\000\000!\000\375\377O\013\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-e2b409b865fe0b3b05d6d5099281e0d90a19db5c Step #5: Base64: YVwjc2NlbgAAAAAAAAAAJCcAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB0IFwjI2gLAAAAAAAAAAAAAAAhJCchMSQ2MSQAAAAAAAAAAAAAAAAAdCBcIyNoCwsL6hQLCwsLFAsLCwsDCxEAAAAhAP3/TwsL Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4317 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3880509366 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee88e2d810, 0x55ee8901701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee89017020,0x55ee8aeaf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e2b409b865fe0b3b05d6d5099281e0d90a19db5c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5398 processed earlier; will process 5631 files now Step #5: ==155488== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ee7f9229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee85f87898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee85f6a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee85f6a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee7f928d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee7f889b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee7f884355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee7f91ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee828e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee828e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee828e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee828e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee828e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee828e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee828e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee828e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee828e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee828e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee84b7ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee818abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee818b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee81662c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee81662c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee81663738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee81662874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee81662874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee81662874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee85f6cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee85f75928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee85f5d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee85f88112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff040cf9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee7f882b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x65,0x72,0x69,0x66,0x6e,0x4d,0x11,0x6,0x64,0x44,0x61,0x32,0x33,0x38,0x33,0x31,0x39,0x31,0x36,0x32,0x31,0x35,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x32,0x38,0x36,0x30,0x6e,0x4d,0x11,0x6,0x27,0x64,0x44,0x61,0x6e,0x4d,0x11,0x6,0x27,0x64,0xca,0xb2,0x44,0x61,0x6e,0x4d,0x11,0x6,0x27,0xf3,0xa0,0xa0,0xbb,0x64,0x44,0x61,0x6e,0x4d,0x11,0x6,0x27,0x64,0x44,0x61,0x6e,0x4d,0x11,0x6,0x27,0x64,0xca,0xb2,0x44,0x61,0x6e,0x4d,0x11,0x6,0x27,0xf3,0xa0,0xa0,0xbb,0x64,0x44,0x61,0x6e,0x4d,0x11,0x6,0x27,0x64,0x64,0x44,0x61,0x65,0x72,0x69,0x66,0x6e,0x4d,0x11,0x6,0x27,0xf3,0xa0,0xa0,0xbb,0x64,0x44,0x61,0x6e,0x4d,0x11,0x6,0x27,0x64,0x64, Step #5: DaerifnM\021\006dDa23831916215ttp://2860nM\021\006'dDanM\021\006'd\312\262DanM\021\006'\363\240\240\273dDanM\021\006'dDanM\021\006'd\312\262DanM\021\006'\363\240\240\273dDanM\021\006'ddDaerifnM\021\006'\363\240\240\273dDanM\021\006'dd Step #5: artifact_prefix='./'; Test unit written to ./oom-0deab9688b1f63bdc05f334d34b62380a1e32630 Step #5: Base64: RGFlcmlmbk0RBmREYTIzODMxOTE2MjE1dHRwOi8vMjg2MG5NEQYnZERhbk0RBidkyrJEYW5NEQYn86Cgu2REYW5NEQYnZERhbk0RBidkyrJEYW5NEQYn86Cgu2REYW5NEQYnZGREYWVyaWZuTREGJ/OgoLtkRGFuTREGJ2Rk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4318 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3881008030 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555c141c9810, 0x555c143b301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555c143b3020,0x555c1624b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0deab9688b1f63bdc05f334d34b62380a1e32630' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5399 processed earlier; will process 5630 files now Step #5: ==155524== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555c0acbe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555c11323898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555c113065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555c113064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555c0acc4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555c0ac25b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555c0ac20355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555c0acb6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555c0dc85f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555c0dc85f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555c0dc85f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555c0dc85f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555c0dc85f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555c0dc85f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555c0dc85f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555c0dc85f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555c0dc85f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555c0dc85f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555c0ff1af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555c0cc47b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555c0cc52be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555c0c9fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555c0c9fec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555c0c9ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555c0c9fe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555c0c9fe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555c0c9fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555c11308abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555c11311928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555c112f9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555c11324112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d8901a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555c0ac1eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0xa,0x3d,0xa,0x3d,0x3d,0xa,0xa,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x8,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x8e,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x2,0x2d,0x1,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----B\012=\012==\012\012\012==\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\010=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000ID3\002-\001\000\000\000\000ID3\002-\001\000\000\000\000ID\216\002-\001\000\000\000\000\002-\001=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-4ef076b48de19d22b972304a596813de228c06df Step #5: Base64: BS0tLS0tQgo9Cj09CgoKPT0KPQo9Cj0KPQo9Cj0KCj0KPQo9Cj0IPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoASUQzAi0BAAAAAElEMwItAQAAAABJRI4CLQEAAAAAAi0BPQo9Cj0KPQoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4319 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3881522889 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5602c527e810, 0x5602c546801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5602c5468020,0x5602c73000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4ef076b48de19d22b972304a596813de228c06df' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5400 processed earlier; will process 5629 files now Step #5: ==155560== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5602bbd739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5602c23d8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602c23bb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602c23bb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5602bbd79d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5602bbcdab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5602bbcd5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5602bbd6bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5602bed3af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5602bed3af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5602bed3af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5602bed3af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5602bed3af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5602bed3af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5602bed3af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5602bed3af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5602bed3af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5602bed3af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5602c0fcff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5602bdcfcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5602bdd07be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5602bdab3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5602bdab3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5602bdab4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5602bdab3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5602bdab3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5602bdab3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5602c23bdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5602c23c6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5602c23ae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5602c23d9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b8717e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5602bbcd3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x52,0x2d,0x75,0x5f,0x77,0x6a,0x62,0x5f,0x41,0x78,0x48,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x75,0x5f,0x73,0x6b,0x7a,0x2d,0x41,0x7a,0x48,0x2d,0x62,0x61,0x63,0x5f,0x62,0x62,0x62,0x5f,0x62,0x4d,0x52,0x2d,0x75,0x5f,0x77,0x6a,0x62,0x5f,0x41,0x78,0x46,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x68,0x2d,0x41,0x7a,0x7a,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x48,0x2d,0x62,0x61,0x7a,0x2d,0x41,0x7a,0x58,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x48,0x2d,0x41,0x7a,0x48, Step #5: MR-u_wjb_AxH-AzH-AzH-AzH-AzH-AzH-AzH-AzH-Azu_skz-AzH-bac_bbb_bMR-u_wjb_AxF-AzH-Azh-Azz-AzH-AzH-AzH-AzH-AzH-baz-AzX-AzH-AzH-AzH Step #5: artifact_prefix='./'; Test unit written to ./oom-d01dfc07b19a60aa68ea8fed19994446ad40f977 Step #5: Base64: TVItdV93amJfQXhILUF6SC1BekgtQXpILUF6SC1BekgtQXpILUF6SC1BenVfc2t6LUF6SC1iYWNfYmJiX2JNUi11X3dqYl9BeEYtQXpILUF6aC1BenotQXpILUF6SC1BekgtQXpILUF6SC1iYXotQXpYLUF6SC1BekgtQXpI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4320 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3882045547 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bd54645810, 0x55bd5482f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bd5482f020,0x55bd566c70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d01dfc07b19a60aa68ea8fed19994446ad40f977' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5401 processed earlier; will process 5628 files now Step #5: #1 pulse cov: 14557 ft: 14558 exec/s: 0 rss: 198Mb Step #5: ==155596== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bd4b13a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bd5179f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bd517825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bd517824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bd4b140d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bd4b0a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bd4b09c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bd4b132c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bd4e101f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bd4e101f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bd4e101f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bd4e101f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bd4e101f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bd4e101f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bd4e101f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bd4e101f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bd4e101f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bd4e101f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bd50396f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bd4d0c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bd4d0cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bd4ce7ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bd4ce7ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bd4ce7b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bd4ce7a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bd4ce7a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bd4ce7a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bd51784abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bd5178d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bd51775699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bd517a0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f401929c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bd4b09ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xe2,0x80,0x88,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xdb,0x80,0x32,0x35,0x35,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0xf7,0x64,0x4c,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3f,0x0,0x8,0x0,0x0,0x0,0x31,0x30, Step #5: \333\200\333\2009\000*****************\342\200\210****************************\333\200255\000***************************\000\000\000\000\000\367dL\000\000\001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000?\000\010\000\000\00010 Step #5: artifact_prefix='./'; Test unit written to ./oom-29d90359a2fbd69bcd9bba1a0417bc57810f844e Step #5: Base64: 24DbgDkAKioqKioqKioqKioqKioqKirigIgqKioqKioqKioqKioqKioqKioqKioqKioqKioq24AyNTUAKioqKioqKioqKioqKioqKioqKioqKioqKioqAAAAAAD3ZEwAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAD8ACAAAADEw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4321 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3882641619 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56109cbfc810, 0x56109cde601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56109cde6020,0x56109ec7e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/29d90359a2fbd69bcd9bba1a0417bc57810f844e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5403 processed earlier; will process 5626 files now Step #5: ==155632== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5610936f19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561099d56898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561099d395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561099d394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610936f7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561093658b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561093653355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610936e9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610966b8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610966b8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610966b8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610966b8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610966b8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610966b8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610966b8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610966b8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610966b8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610966b8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56109894df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56109567ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561095685be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561095431c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561095431c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561095432738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561095431874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561095431874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561095431874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561099d3babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561099d44928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561099d2c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561099d57112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc7794a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561093651b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2d,0x2d,0x4f,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0x2c,0xa,0x63,0x65,0x6e,0x74,0x64,0xa,0x29,0xa,0xa,0x2,0x2d,0x2,0xa,0xa,0x38,0x2d,0x3f,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2,0x2d,0x29,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x29,0xa,0x2,0xa,0x2d,0xa,0x2,0x70,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2,0xa,0x2d,0xa,0x2d,0xa,0x62,0xa,0xd0,0xa,0x2d,0xa,0x64,0xa,0xd5,0xa,0x2,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xb5,0xa,0x0,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0xff, Step #5: \000--O--BEGIN -----\012,\012-\012d\012-\012d,\012centd\012)\012\012\002-\002\012\0128-?,\012-\012d\012\002-)\012d\012-\012d\012d\012)\012\002\012-\012\002p-\012,\012-\012d\012\002\012-\012-\012b\012\320\012-\012d\012\325\012\002\265\265\265\265\265\265\265\265\265\265\265\265\265\265\265\265\265\265\265\012\000-\012-\012\012-\012\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-21e6ffbbe327996725e67d9230527080526f16dc Step #5: Base64: AC0tTy0tQkVHSU4gLS0tLS0KLAotCmQKLQpkLApjZW50ZAopCgoCLQIKCjgtPywKLQpkCgItKQpkCi0KZApkCikKAgotCgJwLQosCi0KZAoCCi0KLQpiCtAKLQpkCtUKArW1tbW1tbW1tbW1tbW1tbW1tbUKAC0KLQoKLQr/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4322 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3883154054 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5629c862e810, 0x5629c881801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5629c8818020,0x5629ca6b00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/21e6ffbbe327996725e67d9230527080526f16dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5404 processed earlier; will process 5625 files now Step #5: ==155668== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5629bf1239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5629c5788898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5629c576b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5629c576b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5629bf129d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629bf08ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629bf085355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5629bf11bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5629c20eaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5629c20eaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5629c20eaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5629c20eaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5629c20eaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5629c20eaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5629c20eaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5629c20eaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5629c20eaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5629c20eaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5629c437ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629c10acb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629c10b7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5629c0e63c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5629c0e63c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5629c0e64738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5629c0e63874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5629c0e63874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5629c0e63874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5629c576dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5629c5776928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5629c575e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5629c5789112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4506f98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629bf083b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x3d,0x7e,0x2d,0x3d,0x3d,0x25,0x3,0x3,0xd2,0x84,0xcb,0xb5,0x28,0xcb,0xb5,0x1,0x79,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x29,0x24,0xcb,0xb5,0xdb,0x90,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe1,0x9a,0x80,0x0,0xc,0x29,0x0,0x34,0x66,0xa9,0x73,0x20,0x37,0x20,0x30,0x20,0x30,0x20,0x35, Step #5: ~$=~-==%\003\003\322\204\313\265(\313\265\001y\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000)$\313\265\333\220\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\341\232\200\000\014)\0004f\251s 7 0 0 5 Step #5: artifact_prefix='./'; Test unit written to ./oom-fd0b2b704cd257f60169ed1599e963a8ccf01b64 Step #5: Base64: fiQ9fi09PSUDA9KEy7Uoy7UBeQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAApJMu125AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADhmoAADCkANGapcyA3IDAgMCA1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4323 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3883662189 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5650c525e810, 0x5650c544801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5650c5448020,0x5650c72e00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fd0b2b704cd257f60169ed1599e963a8ccf01b64' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5405 processed earlier; will process 5624 files now Step #5: ==155704== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5650bbd539c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5650c23b8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5650c239b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5650c239b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5650bbd59d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5650bbcbab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5650bbcb5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5650bbd4bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5650bed1af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5650bed1af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5650bed1af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5650bed1af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5650bed1af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5650bed1af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5650bed1af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5650bed1af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5650bed1af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5650bed1af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5650c0faff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5650bdcdcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5650bdce7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5650bda93c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5650bda93c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5650bda94738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5650bda93874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5650bda93874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5650bda93874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5650c239dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5650c23a6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5650c238e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5650c23b9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa989342082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5650bbcb3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f, Step #5: ______________________________________________________________________________________________________________________________ Step #5: artifact_prefix='./'; Test unit written to ./oom-592135d7e1b7915ecd556abb5649032ef45574a5 Step #5: Base64: X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4324 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3884155722 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c2b2fa8810, 0x55c2b319201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c2b3192020,0x55c2b502a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/592135d7e1b7915ecd556abb5649032ef45574a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5406 processed earlier; will process 5623 files now Step #5: ==155740== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c2a9a9d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c2b0102898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c2b00e55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c2b00e54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c2a9aa3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c2a9a04b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c2a99ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c2a9a95c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c2aca64f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c2aca64f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c2aca64f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c2aca64f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c2aca64f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c2aca64f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c2aca64f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c2aca64f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c2aca64f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c2aca64f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c2aecf9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c2aba26b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c2aba31be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c2ab7ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c2ab7ddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c2ab7de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c2ab7dd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c2ab7dd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c2ab7dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c2b00e7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c2b00f0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c2b00d8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c2b0103112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa37e444082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c2a99fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x2d,0x31,0x3,0x36,0x35,0x35,0x33,0x4c,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe2,0x80,0xab,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe2,0x80,0xab,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4e,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c, Step #5: ID-1\0036553LT\000\343\200\200\000\000\000\001SLT\000\343\200\200\000\000\000\001SLT\000\343\200\200\000\000\000\001SLT\000\343\200\200\000\000\000\001SLT\000\342\200\253\343\200\200\000\000\000\001SLT\000\343\200\200\000\000\000\001SLT\000\342\200\253\343\200\200\000\000\000\001SLT\000\343\200\200\000\000\000\001SLT\000\343\200\200\000\000\000\001SNT\000\343\200\200\000\000\000\001SL Step #5: artifact_prefix='./'; Test unit written to ./oom-e7279d9e35cc3defacd74c70ecff3ce68b5bb528 Step #5: Base64: SUQtMQM2NTUzTFQA44CAAAAAAVNMVADjgIAAAAABU0xUAOOAgAAAAAFTTFQA44CAAAAAAVNMVADigKvjgIAAAAABU0xUAOOAgAAAAAFTTFQA4oCr44CAAAAAAVNMVADjgIAAAAABU0xUAOOAgAAAAAFTTlQA44CAAAAAAVNM Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4325 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3884655146 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a99f1c4810, 0x55a99f3ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a99f3ae020,0x55a9a12460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e7279d9e35cc3defacd74c70ecff3ce68b5bb528' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5407 processed earlier; will process 5622 files now Step #5: ==155776== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a995cb99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a99c31e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a99c3015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a99c3014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a995cbfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a995c20b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a995c1b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a995cb1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a998c80f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a998c80f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a998c80f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a998c80f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a998c80f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a998c80f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a998c80f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a998c80f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a998c80f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a998c80f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a99af15f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a997c42b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a997c4dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a9979f9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a9979f9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a9979fa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a9979f9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a9979f9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a9979f9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a99c303abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a99c30c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a99c2f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a99c31f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f98559a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a995c19b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x3c,0xdb,0xbe,0xdb,0xbe,0x7e,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x33,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x7e,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x30,0x73,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x42,0x42,0x67,0x72,0x79,0x8,0x0,0x0,0x0,0x31,0x73, Step #5: ~<\333\276\333\276~sssssssssss%%%%%%%%%%%%%%%%%%%%3%%%%%%%%%%%%%%%%%%ssssssssssssssssssssssssssssssssss~\377\377\377\377\377\377\377\3770s~~~~~~\001\000\000\000\000\000\000BBgry\010\000\000\0001s Step #5: artifact_prefix='./'; Test unit written to ./oom-f46a6fdc54b72758b9fae7e3bc13ea32107ce09e Step #5: Base64: fjzbvtu+fnNzc3Nzc3Nzc3NzJSUlJSUlJSUlJSUlJSUlJSUlJSUzJSUlJSUlJSUlJSUlJSUlJSUlc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc37//////////zBzfn5+fn5+AQAAAAAAAEJCZ3J5CAAAADFz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4326 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3885156008 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56473f821810, 0x56473fa0b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56473fa0b020,0x5647418a30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f46a6fdc54b72758b9fae7e3bc13ea32107ce09e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5408 processed earlier; will process 5621 files now Step #5: ==155812== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647363169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56473c97b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56473c95e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56473c95e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56473631cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56473627db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564736278355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56473630ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647392ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647392ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647392ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647392ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647392ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647392ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647392ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647392ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647392ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647392ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56473b572f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56473829fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647382aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564738056c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564738056c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564738057738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564738056874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564738056874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564738056874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56473c960abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56473c969928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56473c951699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56473c97c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6673384082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564736276b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2d,0x0,0x6b,0x0,0xd6,0xae,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x0,0x31,0xd6,0xae,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x0,0x31,0x0,0x5b,0x27,0x5d,0x0,0x5b,0x27,0x5d,0x5b,0x28,0x0,0x0,0x0,0x0,0x5b,0x28,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x0,0xf3,0xa0,0xa0,0xa0,0xf0,0x81,0x80,0x0,0x9d,0xe2,0xe2,0x85,0xf3,0x0,0xae,0x22,0xbf,0x81,0x88,0x0,0x0,0x20,0x0,0xf3,0xa0,0xa0,0xa0,0xf0,0x81,0x80,0x0,0x9d,0xe2,0xe2,0x85,0xf3,0x0,0xae,0xbb,0x22,0x81,0xef,0x22,0x22,0x0,0x80,0xab,0x22,0x22,0xbf,0x81,0x88,0xbb,0x22,0x81,0x10,0x68,0xef,0x22,0x22,0x0,0x65,0x61,0x80,0x64,0xab,0x22, Step #5: -\012\012\012--\012-\000k\000\326\256\000\000\000\000\000\000\000-\0001\326\256\000\000\000\000\000\000\000-\0001\000[']\000['][(\000\000\000\000[(\000\000\000\000\000\000 \000\363\240\240\240\360\201\200\000\235\342\342\205\363\000\256\"\277\201\210\000\000 \000\363\240\240\240\360\201\200\000\235\342\342\205\363\000\256\273\"\201\357\"\"\000\200\253\"\"\277\201\210\273\"\201\020h\357\"\"\000ea\200d\253\" Step #5: artifact_prefix='./'; Test unit written to ./oom-194a55df55e62e2c997c62730f23967f1b7f8ad9 Step #5: Base64: LQoKCi0tCi0AawDWrgAAAAAAAAAtADHWrgAAAAAAAAAtADEAWyddAFsnXVsoAAAAAFsoAAAAAAAAIADzoKCg8IGAAJ3i4oXzAK4iv4GIAAAgAPOgoKDwgYAAneLihfMArrsige8iIgCAqyIiv4GIuyKBEGjvIiIAZWGAZKsi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4327 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3885655579 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563326827810, 0x563326a1101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563326a11020,0x5633288a90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/194a55df55e62e2c997c62730f23967f1b7f8ad9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5409 processed earlier; will process 5620 files now Step #5: ==155848== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56331d31c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563323981898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5633239645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5633239644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56331d322d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56331d283b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56331d27e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56331d314c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5633202e3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5633202e3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5633202e3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5633202e3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5633202e3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5633202e3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5633202e3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5633202e3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5633202e3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5633202e3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563322578f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56331f2a5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56331f2b0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56331f05cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56331f05cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56331f05d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56331f05c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56331f05c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56331f05c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563323966abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56332396f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563323957699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563323982112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2eda73c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56331d27cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc9,0x8e,0xd2,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xae,0xd1,0xa5,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd0,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd0,0xa6,0xd1,0xa6,0xd1,0xa6,0xf3,0xa0,0x80,0xb9,0xd1,0xae,0xd1,0xa5,0xd1,0xa6,0xd0,0xa6,0xd1,0xa5,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd9,0xa6,0xd1,0xa5,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xa6,0xd9,0xd1,0xa5,0xd1,0xa6,0xd0,0xa6,0xd1,0xa6,0xd1,0xa2,0xd1,0xf3,0xa0,0x80,0xbc,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xd9,0xa6,0xd0,0xa5,0xd0,0xa6,0xd0,0xa6,0xd1,0xa6,0xd1,0xa6,0xd1,0xa6,0xdb,0xa6,0xd1,0xa6,0xd1,0xa6, Step #5: \311\216\322\246\321\246\321\246\321\246\321\246\321\246\321\256\321\245\321\246\321\246\321\246\320\246\321\246\321\246\321\246\320\246\321\246\321\246\363\240\200\271\321\256\321\245\321\246\320\246\321\245\321\246\321\246\321\246\321\246\331\246\321\245\321\246\321\246\321\246\321\246\321\246\321\246\321\246\246\331\321\245\321\246\320\246\321\246\321\242\321\363\240\200\274\246\321\246\321\246\321\246\321\246\321\246\331\246\320\245\320\246\320\246\321\246\321\246\321\246\333\246\321\246\321\246 Step #5: artifact_prefix='./'; Test unit written to ./oom-d70fca551c0434c678559aafd6e2ae5ef03a2f68 Step #5: Base64: yY7SptGm0abRptGm0abRrtGl0abRptGm0KbRptGm0abQptGm0abzoIC50a7RpdGm0KbRpdGm0abRptGm2abRpdGm0abRptGm0abRptGmptnRpdGm0KbRptGi0fOggLym0abRptGm0abRptmm0KXQptCm0abRptGm26bRptGm Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4328 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3886154141 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e55af6e810, 0x55e55b15801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e55b158020,0x55e55cff00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d70fca551c0434c678559aafd6e2ae5ef03a2f68' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5410 processed earlier; will process 5619 files now Step #5: ==155884== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e551a639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e5580c8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e5580ab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e5580ab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e551a69d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e5519cab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e5519c5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e551a5bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e554a2af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e554a2af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e554a2af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e554a2af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e554a2af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e554a2af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e554a2af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e554a2af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e554a2af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e554a2af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e556cbff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e5539ecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e5539f7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e5537a3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e5537a3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e5537a4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e5537a3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e5537a3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e5537a3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e5580adabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e5580b6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e55809e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e5580c9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0f62a80082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e5519c3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x37,0x3a,0x5b,0x28,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x6d,0x2b,0x2b,0x6d,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x6d,0x2b,0x24,0x33,0x3a,0x3a,0x6d,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x6d,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x6d,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x6d,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x6d,0x2b,0x6d,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x6d,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x6d,0x2b,0x24,0x33,0x3a,0x3a,0x6d,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x6d,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x6d,0x2b,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x6d,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x6d,0x2b,0x24,0x33,0x3a,0x3a,0x2b,0x6d,0x2b,0x2b,0x28, Step #5: $3::{$7:[(+$3::+m++m+$3::+m+$3::m+$3::+$3::+m+$3::+m+$3::+m+$3::+m+m+$3::+m+$3::+m+$3::m+$3::+m+$3::+m++$3::+m+$3::+m+$3::+m++( Step #5: artifact_prefix='./'; Test unit written to ./oom-563eb3b3c158f55b7e1894b3b27d9309cd4cae38 Step #5: Base64: JDM6OnskNzpbKCskMzo6K20rK20rJDM6OittKyQzOjptKyQzOjorJDM6OittKyQzOjorbSskMzo6K20rJDM6OittK20rJDM6OittKyQzOjorbSskMzo6bSskMzo6K20rJDM6OittKyskMzo6K20rJDM6OittKyQzOjorbSsrKA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4329 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3886665790 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a743a50810, 0x55a743c3a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a743c3a020,0x55a745ad20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/563eb3b3c158f55b7e1894b3b27d9309cd4cae38' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5411 processed earlier; will process 5618 files now Step #5: #1 pulse cov: 3980 ft: 3981 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4315 ft: 4606 exec/s: 0 rss: 176Mb Step #5: #4 pulse cov: 11615 ft: 13117 exec/s: 0 rss: 201Mb Step #5: ==155920== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a73a5459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a740baa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a740b8d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a740b8d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a73a54bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a73a4acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a73a4a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a73a53dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a73d50cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a73d50cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a73d50cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a73d50cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a73d50cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a73d50cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a73d50cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a73d50cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a73d50cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a73d50cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a73f7a1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a73c4ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a73c4d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a73c285c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a73c285c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a73c286738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a73c285874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a73c285874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a73c285874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a740b8fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a740b98928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a740b80699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a740bab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd1b843d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a73a4a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7f,0x68,0x24,0x0,0x0,0x11,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2c,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x3d,0x7f,0x68,0x24,0x0,0x0,0x11,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2c,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x31,0x20,0x54,0x1,0x0,0x2,0x2f,0xcd,0x8f,0x41,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x8,0x2c, Step #5: \177h$\000\000\021\000\000\000-------------------,--------=\177h$\000\000\021\000\000\000-------------------,---------------------------1 T\001\000\002/\315\217A-------------------\000\000\010, Step #5: artifact_prefix='./'; Test unit written to ./oom-123190febb93452c4769bdb70d10408079b7de21 Step #5: Base64: f2gkAAARAAAALS0tLS0tLS0tLS0tLS0tLS0tLSwtLS0tLS0tLT1/aCQAABEAAAAtLS0tLS0tLS0tLS0tLS0tLS0tLC0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLTEgVAEAAi/Nj0EtLS0tLS0tLS0tLS0tLS0tLS0tAAAILA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4330 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3887428111 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56498a959810, 0x56498ab4301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56498ab43020,0x56498c9db0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/123190febb93452c4769bdb70d10408079b7de21' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5416 processed earlier; will process 5613 files now Step #5: ==155956== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56498144e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564987ab3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564987a965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564987a964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564981454d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649813b5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649813b0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564981446c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564984415f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564984415f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564984415f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564984415f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564984415f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564984415f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564984415f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564984415f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564984415f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564984415f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5649866aaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649833d7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649833e2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56498318ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56498318ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56498318f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56498318e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56498318e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56498318e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564987a98abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564987aa1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564987a89699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564987ab4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3cbb7df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649813aeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0xa,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0x7,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0x7,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-\012---BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\007\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012==\012=\012=\012=\012=\012==\012=\012=\012=\012=\012=\012=\012\012=\012=\007\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-687ca6dc4680598426ebd9318daaec8eb99d4352 Step #5: Base64: BS0KLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KCj0KPQcKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9PQo9Cj0KPQo9Cj09Cj0KPQo9Cj0KPQo9Cgo9Cj0HCj0KPQo9Cj0KPQo9Cj0KEA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4331 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3887943969 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56353c19d810, 0x56353c38701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56353c387020,0x56353e21f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/687ca6dc4680598426ebd9318daaec8eb99d4352' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5417 processed earlier; will process 5612 files now Step #5: ==155992== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563532c929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5635392f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5635392da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5635392da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563532c98d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563532bf9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563532bf4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563532c8ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563535c59f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563535c59f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563535c59f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563535c59f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563535c59f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563535c59f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563535c59f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563535c59f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563535c59f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563535c59f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563537eeef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563534c1bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563534c26be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5635349d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5635349d2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5635349d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5635349d2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5635349d2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5635349d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5635392dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5635392e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5635392cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5635392f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6fc845c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563532bf2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x1,0x0,0x41,0x1,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x37,0x55,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58,0x0,0x0,0x1,0x54,0x54,0x58,0x58, Step #5: ID3\002\001\000A\0012147483647UTXX\000\000\001TTXX\000\000\001TTXX\000\000\001TTXX\000\000\001TTXX\000\000\001TTXX\000\000\001TTXX\000\000\001TTXX\000\000\001TTXX\000\000\001TTXX\000\000\001TTXX\000\000\001TTXX\000\000\001TTXX\000\000\001TTXX\000\000\001TTXX\000\000\001TTXX Step #5: artifact_prefix='./'; Test unit written to ./oom-c4124bca4f0439881e290c53459ba15e9551d723 Step #5: Base64: SUQzAgEAQQEyMTQ3NDgzNjQ3VVRYWAAAAVRUWFgAAAFUVFhYAAABVFRYWAAAAVRUWFgAAAFUVFhYAAABVFRYWAAAAVRUWFgAAAFUVFhYAAABVFRYWAAAAVRUWFgAAAFUVFhYAAABVFRYWAAAAVRUWFgAAAFUVFhYAAABVFRYWA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4332 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3888451643 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e8d56f3810, 0x55e8d58dd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e8d58dd020,0x55e8d77750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c4124bca4f0439881e290c53459ba15e9551d723' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5418 processed earlier; will process 5611 files now Step #5: ==156028== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e8cc1e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e8d284d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e8d28305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e8d28304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e8cc1eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e8cc14fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e8cc14a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e8cc1e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e8cf1aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e8cf1aff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e8cf1aff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e8cf1aff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e8cf1aff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e8cf1aff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e8cf1aff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e8cf1aff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e8cf1aff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e8cf1aff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e8d1444f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e8ce171b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e8ce17cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e8cdf28c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e8cdf28c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e8cdf29738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e8cdf28874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e8cdf28874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e8cdf28874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e8d2832abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e8d283b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e8d2823699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e8d284e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf75564082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e8cc148b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3, Step #5: \340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263 Step #5: artifact_prefix='./'; Test unit written to ./oom-1b2020433130edc457e90ab1f50744571071f445 Step #5: Base64: 4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9sw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4333 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3888962935 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564e170bb810, 0x564e172a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564e172a5020,0x564e1913d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b2020433130edc457e90ab1f50744571071f445' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5419 processed earlier; will process 5610 files now Step #5: ==156064== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564e0dbb09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564e14215898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564e141f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564e141f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564e0dbb6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564e0db17b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564e0db12355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564e0dba8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564e10b77f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564e10b77f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564e10b77f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564e10b77f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564e10b77f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564e10b77f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564e10b77f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564e10b77f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564e10b77f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564e10b77f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564e12e0cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564e0fb39b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564e0fb44be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564e0f8f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564e0f8f0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564e0f8f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564e0f8f0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564e0f8f0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564e0f8f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564e141faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564e14203928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564e141eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564e14216112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe442ea8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564e0db10b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f,0xa,0x2e,0xcd,0x8f, Step #5: .\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217\012.\315\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-86e47418f93f16d0472586d534e6abc86ac45ed3 Step #5: Base64: Ls2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2PCi7NjwouzY8KLs2PCi7Njw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4334 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3889465296 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e2614e7810, 0x55e2616d101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e2616d1020,0x55e2635690e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/86e47418f93f16d0472586d534e6abc86ac45ed3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5420 processed earlier; will process 5609 files now Step #5: #1 pulse cov: 3781 ft: 3782 exec/s: 0 rss: 175Mb Step #5: ==156100== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e257fdc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e25e641898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e25e6245dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e25e6244fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e257fe2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e257f43b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e257f3e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e257fd4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e25afa3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e25afa3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e25afa3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e25afa3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e25afa3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e25afa3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e25afa3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e25afa3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e25afa3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e25afa3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e25d238f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e259f65b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e259f70be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e259d1cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e259d1cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e259d1d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e259d1c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e259d1c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e259d1c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e25e626abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e25e62f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e25e617699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e25e642112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf63380082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e257f3cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x6d,0x73,0x6f,0x79,0x62,0x6c,0x3e,0x76,0x67,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0x3c,0x74,0x41,0x78,0x74,0x76,0x67,0x3e,0x3c,0x6d,0x73,0x6f,0x79,0x62,0x6c,0x3e,0x76,0x67,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0x3c,0x74,0x41,0x78,0x74,0x3e,0xe1,0x80,0xae,0xe5,0x80,0xae,0xea,0xa2,0xb8,0x5b,0x20,0x3c,0x6d,0x73,0x6f,0x79,0x62,0x3e,0xe1,0x80,0xae,0xe5,0x80,0xae,0xea,0xa2,0xb8,0x5b,0x20,0x3c,0x6d,0x73,0x6f,0x79,0x62,0x6c,0x3e,0x3e, Step #5: <svg><msoybl>vg><tAxt><tAxt><tAxt><tAxt><tAxtvg><msoybl>vg><tAxt><tAxt><tAxt><tAxt><tAxt>\341\200\256\345\200\256\352\242\270[ <msoyb>\341\200\256\345\200\256\352\242\270[ <msoybl>> Step #5: artifact_prefix='./'; Test unit written to ./oom-636e631e0a1675ae15c8988b60d8098a9cdc09ea Step #5: Base64: PHN2Zz48bXNveWJsPnZnPjx0QXh0Pjx0QXh0Pjx0QXh0Pjx0QXh0Pjx0QXh0dmc+PG1zb3libD52Zz48dEF4dD48dEF4dD48dEF4dD48dEF4dD48dEF4dD7hgK7lgK7qorhbIDxtc295Yj7hgK7lgK7qorhbIDxtc295Ymw+Pg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4335 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3890011281 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5623ef1f8810, 0x5623ef3e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5623ef3e2020,0x5623f127a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/636e631e0a1675ae15c8988b60d8098a9cdc09ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5422 processed earlier; will process 5607 files now Step #5: #1 pulse cov: 3506 ft: 3507 exec/s: 0 rss: 175Mb Step #5: ==156136== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5623e5ced9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5623ec352898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5623ec3355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5623ec3354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5623e5cf3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5623e5c54b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5623e5c4f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5623e5ce5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5623e8cb4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5623e8cb4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5623e8cb4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5623e8cb4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5623e8cb4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5623e8cb4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5623e8cb4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5623e8cb4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5623e8cb4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5623e8cb4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5623eaf49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5623e7c76b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5623e7c81be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5623e7a2dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5623e7a2dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5623e7a2e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5623e7a2d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5623e7a2d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5623e7a2d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5623ec337abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5623ec340928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5623ec328699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5623ec353112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f028757d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5623e5c4db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xe2,0x80,0x88,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xdb,0x80,0x32,0x35,0x35,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x3d,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0xf7,0x64,0x4c,0x0,0x0,0x1,0x0,0x0,0x39,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3f,0x0,0x8,0x0,0x0,0x0,0x31,0x30, Step #5: \333\200\333\2009\000*****************\342\200\210****************************\333\200255\000*******************=********\000\000\000\000\000\367dL\000\000\001\000\0009\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000?\000\010\000\000\00010 Step #5: artifact_prefix='./'; Test unit written to ./oom-9bcc49ec3ed6761dd3b88331c6ec35f6361c782e Step #5: Base64: 24DbgDkAKioqKioqKioqKioqKioqKirigIgqKioqKioqKioqKioqKioqKioqKioqKioqKioq24AyNTUAKioqKioqKioqKioqKioqKioqKj0qKioqKioqKgAAAAAA92RMAAABAAA5AAAAAAAAAAAAAAAAAAAAAAAAPwAIAAAAMTA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4336 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3890558698 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b14e4a810, 0x561b1503401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b15034020,0x561b16ecc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9bcc49ec3ed6761dd3b88331c6ec35f6361c782e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5424 processed earlier; will process 5605 files now Step #5: ==156172== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561b0b93f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b11fa4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b11f875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b11f874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b0b945d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b0b8a6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b0b8a1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b0b937c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b0e906f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b0e906f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b0e906f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b0e906f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b0e906f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b0e906f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b0e906f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b0e906f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b0e906f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b0e906f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b10b9bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b0d8c8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b0d8d3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b0d67fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b0d67fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b0d680738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b0d67f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b0d67f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b0d67f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b11f89abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b11f92928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b11f7a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b11fa5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c7e00f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b0b89fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x76,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x7b,0x7d,0x2a,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x3c,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d,0x2a,0x7b,0x7d, Step #5: }*{}*{}*{}*{}*{}*{}*{}*{}*{}*{}*{}*{}**{}*{}*{}*{}*{}*{}*{v*{}*{}*{}*{}*{}*{}*{}*{}{}*}*{}*{<<<<<<<<}*{}*{}*{}*{}*{}*{}*{}*{}*{} Step #5: artifact_prefix='./'; Test unit written to ./oom-9df4f2e61fea2f5df1985196d59c5475729e9dda Step #5: Base64: fSp7fSp7fSp7fSp7fSp7fSp7fSp7fSp7fSp7fSp7fSp7fSp7fSoqe30qe30qe30qe30qe30qe30qe3Yqe30qe30qe30qe30qe30qe30qe30qe317fSp9Knt9Kns8PDw8PDw8PH0qe30qe30qe30qe30qe30qe30qe30qe30qe30= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4337 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3891065340 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5635c4dee810, 0x5635c4fd801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5635c4fd8020,0x5635c6e700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9df4f2e61fea2f5df1985196d59c5475729e9dda' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5425 processed earlier; will process 5604 files now Step #5: ==156208== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5635bb8e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5635c1f48898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5635c1f2b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5635c1f2b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5635bb8e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5635bb84ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5635bb845355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5635bb8dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5635be8aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5635be8aaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5635be8aaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5635be8aaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5635be8aaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5635be8aaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5635be8aaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5635be8aaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5635be8aaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5635be8aaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5635c0b3ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5635bd86cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5635bd877be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5635bd623c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5635bd623c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5635bd624738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5635bd623874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5635bd623874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5635bd623874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5635c1f2dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5635c1f36928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5635c1f1e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5635c1f49112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f72e172d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5635bb843b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0, Step #5: \012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e04049b4685367dfaa62fe8f82b9f5e6859fd73 Step #5: Base64: CgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4338 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3891573830 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560d19397810, 0x560d1958101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560d19581020,0x560d1b4190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e04049b4685367dfaa62fe8f82b9f5e6859fd73' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5426 processed earlier; will process 5603 files now Step #5: ==156244== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560d0fe8c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560d164f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560d164d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560d164d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560d0fe92d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560d0fdf3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560d0fdee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560d0fe84c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560d12e53f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560d12e53f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560d12e53f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560d12e53f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560d12e53f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560d12e53f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560d12e53f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560d12e53f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560d12e53f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560d12e53f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560d150e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560d11e15b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560d11e20be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560d11bccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560d11bccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560d11bcd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560d11bcc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560d11bcc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560d11bcc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560d164d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560d164df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560d164c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560d164f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f236e7c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560d0fdecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x3a,0x7b,0x27,0x27,0x7b, Step #5: {'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{'':{''{ Step #5: artifact_prefix='./'; Test unit written to ./oom-203b2dd03743a13c21ba523320baa23b756b52b3 Step #5: Base64: eycnOnsnJzp7Jyc6eycnOnsnJzp7Jyc6eycnOnsnJzp7Jyc6eycnOnsnJzp7Jyc6eycnOnsnJzp7Jyc6eycnOnsnJzp7Jyc6eycnOnsnJzp7Jyc6eycnOnsnJzp7Jyc6eycnOnsnJzp7Jyc6eycnOnsnJzp7Jyc6eycnOnsnJ3s= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4339 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3892079871 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561aadcaa810, 0x561aade9401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561aade94020,0x561aafd2c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/203b2dd03743a13c21ba523320baa23b756b52b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5427 processed earlier; will process 5602 files now Step #5: ==156280== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561aa479f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561aaae04898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561aaade75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561aaade74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561aa47a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561aa4706b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561aa4701355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561aa4797c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561aa7766f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561aa7766f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561aa7766f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561aa7766f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561aa7766f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561aa7766f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561aa7766f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561aa7766f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561aa7766f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561aa7766f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561aa99fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561aa6728b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561aa6733be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561aa64dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561aa64dfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561aa64e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561aa64df874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561aa64df874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561aa64df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561aaade9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561aaadf2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561aaadda699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561aaae05112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7889bf1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561aa46ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x4,0x33,0x3,0x20,0x0,0x45,0x30,0x50,0x73,0xa,0x20,0x20,0x2f,0x46,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x35,0x20,0x71,0x70,0x78,0x60,0x74,0x6d,0x21,0x60,0x31,0x50,0x55,0x53,0x4c,0x32,0x54,0xa,0xa,0xa,0x3d,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3f,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x8a,0x3d,0xa,0x3d,0x0,0x0,0x20,0x0,0x0,0xff,0xff,0xff,0x11,0xc7,0x50, Step #5: I\0043\003 \000E0Ps\012 /F=\012=\012=\0125 qpx`tm!`1PUSL2T\012\012\012==\012==\012=\012=\012=\012?\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\212=\012=\000\000 \000\000\377\377\377\021\307P Step #5: artifact_prefix='./'; Test unit written to ./oom-9820d9bd8b42dbe9a5afece0bfbd00d603f1a47d Step #5: Base64: SQQzAyAARTBQcwogIC9GPQo9Cj0KNSBxcHhgdG0hYDFQVVNMMlQKCgo9PQo9PQo9Cj0KPQo/Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cgo9Cj0KPQo9Cj0KPQo9Cj2KPQo9AAAgAAD///8Rx1A= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4340 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3892711712 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a411028810, 0x55a41121201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a411212020,0x55a4130aa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9820d9bd8b42dbe9a5afece0bfbd00d603f1a47d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5428 processed earlier; will process 5601 files now Step #5: ==156316== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a407b1d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a40e182898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a40e1655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a40e1654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a407b23d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a407a84b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a407a7f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a407b15c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a40aae4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a40aae4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a40aae4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a40aae4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a40aae4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a40aae4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a40aae4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a40aae4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a40aae4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a40aae4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a40cd79f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a409aa6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a409ab1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a40985dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a40985dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a40985e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a40985d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a40985d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a40985d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a40e167abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a40e170928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a40e158699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a40e183112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd9b9ad4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a407a7db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24, Step #5: $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ Step #5: artifact_prefix='./'; Test unit written to ./oom-02c3e8fb42f471b41c8721ec2ab80692094f4aec Step #5: Base64: JCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4341 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3893229757 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db366a4810, 0x55db3688e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db3688e020,0x55db387260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/02c3e8fb42f471b41c8721ec2ab80692094f4aec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5429 processed earlier; will process 5600 files now Step #5: ==156352== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db2d1999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db337fe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db337e15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db337e14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db2d19fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db2d100b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db2d0fb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db2d191c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db30160f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db30160f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db30160f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db30160f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db30160f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db30160f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db30160f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db30160f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db30160f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db30160f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db323f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db2f122b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db2f12dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db2eed9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db2eed9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db2eeda738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db2eed9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db2eed9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db2eed9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db337e3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db337ec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db337d4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db337ff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f500bb6f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db2d0f9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c,0xd,0x7b,0x6b,0xd,0x7b,0x7a,0xd,0x7b,0x26,0xc,0x7b,0x26,0xd,0x7b,0x7d,0x7d,0x7d,0x7d,0x3,0xd,0x7b,0x6b,0xd,0x7b,0x26,0xd,0x7b,0x7d,0x7d,0x7d,0x6b,0xd,0x7b,0x26,0xd,0x7b,0x2d,0xd,0x7b,0x26,0xd,0x7b,0x24,0xd,0x7b,0x7d,0x7d,0x7d,0x7d,0x26,0xd,0x7b,0x6b,0xd,0x7b,0x26,0xd,0x7b,0x7d,0x7d,0x7d,0x7d,0x7d,0x6c,0xd,0x7b,0x6b,0xd,0x7b,0x7a,0xd,0x7b,0x26,0xc,0x7b,0x26,0xd,0x7b,0x7d,0x7d,0x7d,0x7d,0x3,0xd,0x7b,0x6b,0xd,0x7b,0x26,0xd,0x7b,0x7d,0x7d,0x7d,0x6b,0xd,0x7b,0x26,0xd,0x7b,0x2d,0xd,0x7b,0x26,0xd,0x7b,0x24,0xd,0x7b,0x7d,0x7d,0x7d,0x7d,0x26,0xd,0x7b,0x6b,0xd,0x7b,0x26,0xd,0x7b,0x7d,0x7d,0x7d,0x7d,0x7d, Step #5: l\015{k\015{z\015{&\014{&\015{}}}}\003\015{k\015{&\015{}}}k\015{&\015{-\015{&\015{$\015{}}}}&\015{k\015{&\015{}}}}}l\015{k\015{z\015{&\014{&\015{}}}}\003\015{k\015{&\015{}}}k\015{&\015{-\015{&\015{$\015{}}}}&\015{k\015{&\015{}}}}} Step #5: artifact_prefix='./'; Test unit written to ./oom-ef4b789e465f46bff17e487989d16b25d8e12e2b Step #5: Base64: bA17aw17eg17Jgx7Jg17fX19fQMNe2sNeyYNe319fWsNeyYNey0NeyYNeyQNe319fX0mDXtrDXsmDXt9fX19fWwNe2sNe3oNeyYMeyYNe319fX0DDXtrDXsmDXt9fX1rDXsmDXstDXsmDXskDXt9fX19Jg17aw17Jg17fX19fX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4342 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3893740574 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559877257810, 0x55987744101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559877441020,0x5598792d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ef4b789e465f46bff17e487989d16b25d8e12e2b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5430 processed earlier; will process 5599 files now Step #5: ==156388== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55986dd4c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5598743b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5598743945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5598743944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55986dd52d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55986dcb3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55986dcae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55986dd44c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559870d13f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559870d13f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559870d13f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559870d13f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559870d13f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559870d13f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559870d13f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559870d13f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559870d13f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559870d13f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559872fa8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55986fcd5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55986fce0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55986fa8cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55986fa8cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55986fa8d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55986fa8c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55986fa8c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55986fa8c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559874396abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55987439f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559874387699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5598743b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f013bb51082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55986dcacb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0xe,0x27,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3b,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x24,0x7c,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x3a,0x24,0xe,0x27,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3b,0x24,0x7c,0x24,0x7c,0xf3,0xa0,0x81,0x9a,0x24,0x7c,0x24,0x7c,0x24,0x24,0x7c,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x29,0x29,0x7c,0x29,0x7c,0x24,0x29,0x7c,0x29,0x29,0x7c,0x29,0x7c,0x29,0x7c, Step #5: (?:(?:(?:$\016'|(?:(?:(?;$|$|$|$|$$||$|$|$|$|$|$|$)|$|$|$|$|:$\016'|(?:(?:(?;$|$|\363\240\201\232$|$|$$||$|$|$|$|$|$|$)|$|$|$|$|$)|))|)|$)|))|)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-45b7834cdf00fca4a9b13d92b23ad399cd56c743 Step #5: Base64: KD86KD86KD86JA4nfCg/Oig/Oig/OyR8JHwkfCR8JCR8fCR8JHwkfCR8JHwkfCQpfCR8JHwkfCR8OiQOJ3woPzooPzooPzskfCR886CBmiR8JHwkJHx8JHwkfCR8JHwkfCR8JCl8JHwkfCR8JHwkKXwpKXwpfCQpfCkpfCl8KXw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4343 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3894258576 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f52c443810, 0x55f52c62d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f52c62d020,0x55f52e4c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/45b7834cdf00fca4a9b13d92b23ad399cd56c743' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5431 processed earlier; will process 5598 files now Step #5: ==156424== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f522f389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f52959d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f5295805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f5295804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f522f3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f522e9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f522e9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f522f30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f525efff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f525efff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f525efff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f525efff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f525efff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f525efff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f525efff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f525efff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f525efff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f525efff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f528194f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f524ec1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f524eccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f524c78c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f524c78c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f524c79738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f524c78874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f524c78874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f524c78874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f529582abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f52958b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f529573699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f52959e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd67a501082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f522e98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x58,0x56,0x41,0x47,0x49,0xdf,0xdf,0xdf,0xdf,0xdf,0xdf,0xdf,0xdf,0xdf,0xdf,0xdf,0xdf,0xdf,0xdf,0xdf,0xdf,0xdf,0x1,0x0,0x1,0x20,0x79,0x7,0xd,0x20,0x20,0x80,0x0,0x0,0xc0,0x17,0xf5,0x65,0x0,0x0,0xfe,0x22,0x81,0x0,0x20,0x1a,0x10,0x25,0x0,0x1a,0x22,0xa4,0x1,0x20,0x20,0x0,0x0,0x1,0x20,0x51,0xdf,0xff,0xd4,0x5,0x3a,0x20,0x20,0x0,0x0,0x1,0x20,0x79,0x7,0x9,0x20,0x20,0x80,0x0,0x0,0xc0,0x17,0xfc,0x65,0x0,0x0,0x1,0x20,0x81,0x0,0x20,0x1a,0x10,0x1a,0xfc,0xa4,0x1,0x20,0x20,0x0,0x0,0x0,0x1,0x20,0x51,0xd4,0x20,0x20,0x0,0x0,0x0,0x1,0x20,0x51,0x0,0xff,0xd4,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xcf,0xdf,0xdf,0xdf,0xdf, Step #5: XVAGI\337\337\337\337\337\337\337\337\337\337\337\337\337\337\337\337\337\001\000\001 y\007\015 \200\000\000\300\027\365e\000\000\376\"\201\000 \032\020%\000\032\"\244\001 \000\000\001 Q\337\377\324\005: \000\000\001 y\007\011 \200\000\000\300\027\374e\000\000\001 \201\000 \032\020\032\374\244\001 \000\000\000\001 Q\324 \000\000\000\001 Q\000\377\324\317\317\317\317\317\317\317\317\337\337\337\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-d1d4973c5320d52c4da5490810341954713a1ed2 Step #5: Base64: WFZBR0nf39/f39/f39/f39/f39/f3wEAASB5Bw0gIIAAAMAX9WUAAP4igQAgGhAlABoipAEgIAAAASBR3//UBTogIAAAASB5BwkgIIAAAMAX/GUAAAEggQAgGhAa/KQBICAAAAABIFHUICAAAAABIFEA/9TPz8/Pz8/Pz9/f398= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4344 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3894750882 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc8eff9810, 0x55fc8f1e301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc8f1e3020,0x55fc9107b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d1d4973c5320d52c4da5490810341954713a1ed2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5432 processed earlier; will process 5597 files now Step #5: ==156460== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fc85aee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc8c153898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc8c1365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc8c1364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc85af4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc85a55b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc85a50355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc85ae6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc88ab5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc88ab5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc88ab5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc88ab5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc88ab5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc88ab5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc88ab5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc88ab5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc88ab5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc88ab5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc8ad4af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc87a77b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc87a82be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc8782ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc8782ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc8782f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc8782e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc8782e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc8782e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc8c138abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc8c141928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc8c129699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc8c154112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f39fc762082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc85a4eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x2d,0x31,0x3,0x36,0x35,0x35,0x33,0x4c,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe3,0x81,0x80,0x0,0x0,0x0,0x1,0x53,0x54,0x4c,0x0,0xe2,0x80,0xab,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe2,0x80,0xab,0xe3,0xe3,0x80,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4e,0x54,0x0,0xe3,0x80,0x80,0x0,0x0,0x0,0x1,0x53,0x4c, Step #5: ID-1\0036553LT\000\343\200\200\000\000\000\001SLT\000\343\200\200\000\000\000\001SLT\000\343\200\200\000\000\000\001SLT\000\343\201\200\000\000\000\001STL\000\342\200\253\343\200\200\000\000\000\001SLT\000\343\200\200\000\000\000\001SLT\000\342\200\253\343\343\200\200\200\000\000\000\001SLT\000\343\200\200\000\000\000\001SLT\000\343\200\200\000\000\000\001SNT\000\343\200\200\000\000\000\001SL Step #5: artifact_prefix='./'; Test unit written to ./oom-9c1cfbd1c259a84bf5c9b93b2ca445bceed650b4 Step #5: Base64: SUQtMQM2NTUzTFQA44CAAAAAAVNMVADjgIAAAAABU0xUAOOAgAAAAAFTTFQA44GAAAAAAVNUTADigKvjgIAAAAABU0xUAOOAgAAAAAFTTFQA4oCr4+OAgIAAAAABU0xUAOOAgAAAAAFTTFQA44CAAAAAAVNOVADjgIAAAAABU0w= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4345 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3895248705 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5570404ca810, 0x5570406b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5570406b4020,0x55704254c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c1cfbd1c259a84bf5c9b93b2ca445bceed650b4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5433 processed earlier; will process 5596 files now Step #5: ==156496== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557036fbf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55703d624898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55703d6075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55703d6074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557036fc5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557036f26b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557036f21355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557036fb7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557039f86f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557039f86f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557039f86f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557039f86f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557039f86f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557039f86f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557039f86f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557039f86f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557039f86f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557039f86f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55703c21bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557038f48b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557038f53be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557038cffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557038cffc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557038d00738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557038cff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557038cff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557038cff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55703d609abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55703d612928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55703d5fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55703d625112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f05559fe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557036f1fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x70,0x68,0x70,0xa,0xa,0x63,0x6c,0x61,0x73,0x73,0x20,0x4f,0x62,0x6a,0xa,0x7b,0xa,0x20,0x20,0x20,0x20,0x63,0x6f,0x6e,0x73,0x74,0x20,0x45,0x4d,0x50,0x54,0x59,0x20,0x3d,0x20,0x27,0x65,0x6d,0x70,0x74,0x79,0x27,0x3b,0xa,0x20,0x20,0x20,0x20,0x63,0x6f,0x6e,0x73,0x74,0x20,0x43,0x41,0x4c,0x4c,0x41,0x42,0x4c,0x45,0x20,0x3d,0x20,0x27,0x63,0x61,0x6c,0x6c,0x61,0x62,0x6c,0x65,0x27,0x3b,0xa,0x20,0x20,0x20,0x20,0x63,0x6f,0x6e,0x73,0x74,0x20,0x54,0x52,0x41,0x49,0x54,0x20,0x3d,0x20,0x27,0x74,0x72,0x61,0x69,0x74,0x27,0x3b,0xa,0x20,0x20,0x20,0x20,0x63,0x6f,0x6e,0x73,0x74,0x20,0x45,0x58,0x54,0x45,0x4e,0x44,0x53,0x20,0x3d,0x20,0x27,0x65, Step #5: <?php\012\012class Obj\012{\012 const EMPTY = 'empty';\012 const CALLABLE = 'callable';\012 const TRAIT = 'trait';\012 const EXTENDS = 'e Step #5: artifact_prefix='./'; Test unit written to ./oom-670cb1df367334a4af030706980e7824a5e6fd87 Step #5: Base64: PD9waHAKCmNsYXNzIE9iagp7CiAgICBjb25zdCBFTVBUWSA9ICdlbXB0eSc7CiAgICBjb25zdCBDQUxMQUJMRSA9ICdjYWxsYWJsZSc7CiAgICBjb25zdCBUUkFJVCA9ICd0cmFpdCc7CiAgICBjb25zdCBFWFRFTkRTID0gJ2U= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4346 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3895749834 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563160fec810, 0x5631611d601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5631611d6020,0x56316306e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/670cb1df367334a4af030706980e7824a5e6fd87' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5434 processed earlier; will process 5595 files now Step #5: ==156532== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563157ae19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56315e146898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56315e1295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56315e1294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563157ae7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563157a48b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563157a43355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563157ad9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56315aaa8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56315aaa8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56315aaa8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56315aaa8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56315aaa8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56315aaa8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56315aaa8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56315aaa8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56315aaa8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56315aaa8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56315cd3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563159a6ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563159a75be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563159821c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563159821c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563159822738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563159821874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563159821874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563159821874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56315e12babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56315e134928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56315e11c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56315e147112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f90860bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563157a41b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0x10,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xf4,0x8f,0xbf,0xbf,0xf4,0xbf,0x62, Step #5: bb\012\012\364\217\277\277bb\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\020\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\364\217\277\277\364\277b Step #5: artifact_prefix='./'; Test unit written to ./oom-375f7198e524c2bd8dc0ae2b01c8ab7079f4d6e5 Step #5: Base64: YmIKCvSPv79iYgr0j7+/YmIKCvSPv79iYgoK9I+/v2JiCvSPv79iYgoK9I+/v2JiCgr0j7+/YmIKCvSPv79iYgoK9I+/v2JiCgr0j7+/YmIKCvSPv79iYgoK9I+/v2JiEAr0j7+/YmIKCvSPv79iYgoK9I+/v2JiCvSPv7/0v2I= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4347 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3896257215 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e564559810, 0x55e56474301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e564743020,0x55e5665db0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/375f7198e524c2bd8dc0ae2b01c8ab7079f4d6e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5435 processed earlier; will process 5594 files now Step #5: #1 pulse cov: 3604 ft: 3605 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 4260 ft: 4702 exec/s: 0 rss: 175Mb Step #5: ==156568== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e55b04e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e5616b3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e5616965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e5616964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e55b054d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e55afb5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e55afb0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e55b046c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e55e015f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e55e015f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e55e015f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e55e015f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e55e015f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e55e015f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e55e015f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e55e015f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e55e015f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e55e015f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e5602aaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e55cfd7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e55cfe2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e55cd8ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e55cd8ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e55cd8f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e55cd8e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e55cd8e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e55cd8e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e561698abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e5616a1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e561689699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e5616b4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa672ce0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e55afaeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85, Step #5: \302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-591b22a3b41cc20ac79c2b602b23634d927d8dc0 Step #5: Base64: woXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4348 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3896819755 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c4e3b3b810, 0x55c4e3d2501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c4e3d25020,0x55c4e5bbd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/591b22a3b41cc20ac79c2b602b23634d927d8dc0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5438 processed earlier; will process 5591 files now Step #5: ==156604== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c4da6309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c4e0c95898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c4e0c785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c4e0c784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c4da636d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c4da597b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c4da592355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c4da628c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c4dd5f7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c4dd5f7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c4dd5f7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c4dd5f7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c4dd5f7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c4dd5f7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c4dd5f7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c4dd5f7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c4dd5f7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c4dd5f7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c4df88cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c4dc5b9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c4dc5c4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c4dc370c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c4dc370c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c4dc371738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c4dc370874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c4dc370874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c4dc370874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c4e0c7aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c4e0c83928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c4e0c6b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c4e0c96112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe85d475082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c4da590b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x61,0x20,0x3a,0x7b,0x61,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x61,0x20,0x3a,0x7b,0x61,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x61,0x20,0x3a,0x7b,0x61,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x61,0x20,0x3a,0x7b,0x61,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a,0x7b,0x24,0x20,0x3a, Step #5: {$ :{$ :{a :{a :{$ :{$ :{$ :{$ :{$ :{$ :{a :{a :{$ :{$ :{$ :{$ :{$ :{$ :{a :{a :{$ :{$ :{$ :{$ :{$ :{$ :{a :{a :{$ :{$ :{$ :{$ : Step #5: artifact_prefix='./'; Test unit written to ./oom-d36084abc19c6b3866a6213078e5691f31b1233f Step #5: Base64: eyQgOnskIDp7YSA6e2EgOnskIDp7JCA6eyQgOnskIDp7JCA6eyQgOnthIDp7YSA6eyQgOnskIDp7JCA6eyQgOnskIDp7JCA6e2EgOnthIDp7JCA6eyQgOnskIDp7JCA6eyQgOnskIDp7YSA6e2EgOnskIDp7JCA6eyQgOnskIDo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4349 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3897330243 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5642828ae810, 0x564282a9801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564282a98020,0x5642849300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d36084abc19c6b3866a6213078e5691f31b1233f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5439 processed earlier; will process 5590 files now Step #5: ==156640== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5642793a39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56427fa08898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56427f9eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56427f9eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642793a9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56427930ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564279305355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56427939bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56427c36af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56427c36af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56427c36af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56427c36af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56427c36af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56427c36af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56427c36af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56427c36af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56427c36af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56427c36af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56427e5fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56427b32cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56427b337be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56427b0e3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56427b0e3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56427b0e4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56427b0e3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56427b0e3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56427b0e3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56427f9edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56427f9f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56427f9de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56427fa09112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d5a6cb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564279303b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x34,0xe2,0x97,0x8c,0xc2,0xb3,0x3e,0x20,0xea,0xa7,0x93,0xe2,0x81,0xa8,0xe2,0x81,0xa7,0x5b,0xe2,0x81,0xa7,0x5c,0x5e,0x34,0x3b,0x3d,0xde,0xb3,0xc2,0xad,0x24,0xc2,0xb3,0x3e,0x20,0xea,0xa7,0xb3,0xe2,0x81,0xb3,0x3e,0x20,0xea,0xa7,0x93,0xe2,0x81,0xa8,0xe2,0x81,0xa7,0x5b,0xe2,0x81,0xa7,0x5c,0x5e,0x34,0x3b,0x3d,0xde,0xb3,0xc2,0xad,0x24,0xc2,0xb3,0x3e,0x20,0xea,0xa7,0xb3,0xe2,0x81,0xa8,0xe2,0x81,0xa7,0x5b,0xe2,0x81,0xa7,0x5c,0x5e,0x34,0x47,0x49,0x46,0x38,0x39,0x61,0xcc,0x8c,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e,0x49,0x6e,0x69, Step #5: <svg><text>>>>>>>>4\342\227\214\302\263> \352\247\223\342\201\250\342\201\247[\342\201\247\\^4;=\336\263\302\255$\302\263> \352\247\263\342\201\263> \352\247\223\342\201\250\342\201\247[\342\201\247\\^4;=\336\263\302\255$\302\263> \352\247\263\342\201\250\342\201\247[\342\201\247\\^4GIF89a\314\214</text></svg>Ini Step #5: artifact_prefix='./'; Test unit written to ./oom-f7a06957ae197d3f6b30563a21e4d069d027f25c Step #5: Base64: PHN2Zz48dGV4dD4+Pj4+Pj4+NOKXjMKzPiDqp5Pigajigadb4oGnXF40Oz3es8KtJMKzPiDqp7PigbM+IOqnk+KBqOKBp1vigadcXjQ7Pd6zwq0kwrM+IOqns+KBqOKBp1vigadcXjRHSUY4OWHMjDwvdGV4dD48L3N2Zz5Jbmk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4350 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3897833689 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7bfa92810, 0x55b7bfc7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7bfc7c020,0x55b7c1b140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7a06957ae197d3f6b30563a21e4d069d027f25c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5440 processed earlier; will process 5589 files now Step #5: #1 pulse cov: 3580 ft: 3581 exec/s: 0 rss: 174Mb Step #5: ==156676== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b7b65879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b7bcbec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b7bcbcf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b7bcbcf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b7b658dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b7b64eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b7b64e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b7b657fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b7b954ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b7b954ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b7b954ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b7b954ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b7b954ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b7b954ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b7b954ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b7b954ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b7b954ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b7b954ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b7bb7e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b7b8510b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b7b851bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b7b82c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b7b82c7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b7b82c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b7b82c7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b7b82c7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b7b82c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b7bcbd1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b7bcbda928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b7bcbc2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b7bcbed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f40af0a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b7b64e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0x2b,0xb,0x57,0xb,0x2b,0xb,0x57,0xb,0x2b,0xb,0x57,0xb,0x30,0xb,0x2b,0xb,0x57,0xb,0x2b,0xb,0x2b,0xb,0x57,0xb,0x2b,0xb,0x57,0xb,0x2b,0xb,0x2b,0xb,0x57,0xb,0x2b,0xb,0x57,0xb,0x2b,0xb,0x57,0xb,0x57,0xb,0x2b,0xb,0x2b,0xb,0x57,0xb,0x2d,0xb,0x30,0xb,0x2b,0xb,0x57,0xb,0x2b,0xb,0x2b,0xb,0x57,0xb,0x2b,0xb,0x57,0xb,0x2b,0xb,0x57,0xb,0x57,0xb,0x2b,0xb,0x2b,0xb,0x57,0xb,0x2d,0xb,0x30,0xb,0x2b,0xb,0x57,0xb,0x2b,0xb,0x57,0xb,0x2b,0x57,0xb,0x30,0xb,0x2b,0xb,0x57,0xb,0x2b,0xb,0x34,0xb,0x57,0xb,0x2b,0xb,0x2e,0xb,0x2b,0xb,0x57,0xb,0x55,0xb,0x2b,0xb,0x57,0xb,0x2d,0xb,0x30,0xb,0x2b,0xb, Step #5: \013+\013W\013+\013W\013+\013W\0130\013+\013W\013+\013+\013W\013+\013W\013+\013+\013W\013+\013W\013+\013W\013W\013+\013+\013W\013-\0130\013+\013W\013+\013+\013W\013+\013W\013+\013W\013W\013+\013+\013W\013-\0130\013+\013W\013+\013W\013+W\0130\013+\013W\013+\0134\013W\013+\013.\013+\013W\013U\013+\013W\013-\0130\013+\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-a7cd6444fe756d673d6521c158847987d4776f9c Step #5: Base64: CysLVwsrC1cLKwtXCzALKwtXCysLKwtXCysLVwsrCysLVwsrC1cLKwtXC1cLKwsrC1cLLQswCysLVwsrCysLVwsrC1cLKwtXC1cLKwsrC1cLLQswCysLVwsrC1cLK1cLMAsrC1cLKws0C1cLKwsuCysLVwtVCysLVwstCzALKws= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4351 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3898409494 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a7c5cd5810, 0x55a7c5ebf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a7c5ebf020,0x55a7c7d570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a7cd6444fe756d673d6521c158847987d4776f9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5442 processed earlier; will process 5587 files now Step #5: #1 pulse cov: 3482 ft: 3483 exec/s: 0 rss: 175Mb Step #5: ==156712== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a7bc7ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a7c2e2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a7c2e125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a7c2e124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a7bc7d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a7bc731b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a7bc72c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a7bc7c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a7bf791f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a7bf791f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a7bf791f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a7bf791f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a7bf791f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a7bf791f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a7bf791f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a7bf791f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a7bf791f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a7bf791f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a7c1a26f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a7be753b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a7be75ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a7be50ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a7be50ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a7be50b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a7be50a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a7be50a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a7be50a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a7c2e14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a7c2e1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a7c2e05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a7c2e30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a21d45082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a7bc72ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x2d,0x20,0x4a,0xa,0x2d,0x20,0x4b,0xa,0x2d,0x20,0x2b,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x25,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x6d,0xa,0x2d,0x20,0x26,0xa,0x2d,0x20,0x70,0xde,0xad,0xbe,0xef, Step #5: \002- J\012- K\012- +\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- %\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- m\012- &\012- p\336\255\276\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-dc8c90bab8d3e5478a4101dbec20937e4eb913bc Step #5: Base64: Ai0gSgotIEsKLSArCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotICUKLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIG0KLSAmCi0gcN6tvu8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4352 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3899004138 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b511d46810, 0x55b511f3001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b511f30020,0x55b513dc80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dc8c90bab8d3e5478a4101dbec20937e4eb913bc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5444 processed earlier; will process 5585 files now Step #5: ==156748== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b50883b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b50eea0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b50ee835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b50ee834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b508841d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b5087a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b50879d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b508833c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b50b802f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b50b802f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b50b802f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b50b802f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b50b802f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b50b802f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b50b802f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b50b802f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b50b802f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b50b802f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b50da97f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b50a7c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b50a7cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b50a57bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b50a57bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b50a57c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b50a57b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b50a57b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b50a57b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b50ee85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b50ee8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b50ee76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b50eea1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff52b296082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b50879bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x20,0x7b,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x3a,0x7b,0xb,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0x61,0x20,0x7b,0x6e,0x61,0x6d,0x65,0x3a,0x9,0x22,0x41,0xd,0x22,0xd,0xd,0xd,0x7d,0x20,0x7d,0x6d,0x64,0x65,0x63,0x6c,0x7b,0x61,0x20,0x7b,0x6e,0x61,0x6d,0x65,0x3a,0x9,0x22,0x42,0xd,0x22,0xd,0xd,0xd,0x7d,0x20,0x7d,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0x61,0x20,0x7b,0x6e,0x61,0x6d,0x65,0x3a,0x9,0x22,0x42,0x42,0xd,0x22,0xd,0xd,0xd,0x7d,0x20,0x7d,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0x61,0x20,0x7b,0x6e,0x61,0x6d,0x65,0x3a,0x9,0x22,0x42,0x42,0x42,0xd,0x22,0xd,0xd,0xd,0x7d,0x20,0x7d,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0x61,0x20, Step #5: p {doctype:{\013mdecl {a {name:\011\"A\015\"\015\015\015} }mdecl{a {name:\011\"B\015\"\015\015\015} }mdecl {a {name:\011\"BB\015\"\015\015\015} }mdecl {a {name:\011\"BBB\015\"\015\015\015} }mdecl {a Step #5: artifact_prefix='./'; Test unit written to ./oom-072b2e335e341b9909190f1f0f9426e59f84e1c9 Step #5: Base64: cCB7ZG9jdHlwZTp7C21kZWNsIHthIHtuYW1lOgkiQQ0iDQ0NfSB9bWRlY2x7YSB7bmFtZToJIkINIg0NDX0gfW1kZWNsIHthIHtuYW1lOgkiQkINIg0NDX0gfW1kZWNsIHthIHtuYW1lOgkiQkJCDSINDQ19IH1tZGVjbCB7YSA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4353 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3899510389 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556fcdd47810, 0x556fcdf3101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556fcdf31020,0x556fcfdc90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/072b2e335e341b9909190f1f0f9426e59f84e1c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5445 processed earlier; will process 5584 files now Step #5: ==156784== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556fc483c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556fcaea1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556fcae845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556fcae844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556fc4842d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556fc47a3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556fc479e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556fc4834c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556fc7803f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556fc7803f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556fc7803f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556fc7803f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556fc7803f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556fc7803f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556fc7803f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556fc7803f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556fc7803f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556fc7803f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556fc9a98f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556fc67c5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556fc67d0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556fc657cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556fc657cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556fc657d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556fc657c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556fc657c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556fc657c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556fcae86abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556fcae8f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556fcae77699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556fcaea2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe9bedd2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556fc479cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x3a,0x30,0x2a,0xdf,0x88,0x30,0x0,0x26,0x0,0x30,0xdf,0x80,0x30,0x30,0x30,0x2f,0x30,0xdf,0x88,0x30,0x30,0x30,0x30,0x30,0xdf,0x88,0x30,0x0,0x0,0x30,0xdf,0x80,0x30,0x30,0x30,0x30,0x30,0x2f,0x5b,0x30,0xdf,0x88,0x30,0x30,0x30,0x2a,0xdf,0x88,0x30,0x0,0x26,0x30,0x30,0x77,0x30,0xdf,0x80,0x30,0x30,0x30,0x30,0x30,0x30,0x5b,0x30,0xdf,0x88,0x30,0x30,0x30,0x34,0x30,0x30,0xdf,0x88,0x30,0x0,0x0,0x30,0xdf,0x80,0x30,0x30,0x30,0x30,0x30,0x2f,0xd,0x5b,0x30,0xdf,0x88,0x30,0x30,0x0,0x3a,0x30,0x2a,0xdf,0x88,0x30,0x0,0x26,0x0,0x30,0xdf,0x80,0x30,0x30,0x30,0x30,0x30,0x30,0xd7,0x88,0x30,0x0,0x0,0x30,0xdf,0x30,0x2f,0x5b,0x30,0x70, Step #5: \000\000\000:0*\337\2100\000&\0000\337\200000/0\337\21000000\337\2100\000\0000\337\20000000/[0\337\210000*\337\2100\000&00w0\337\200000000[0\337\210000400\337\2100\000\0000\337\20000000/\015[0\337\21000\000:0*\337\2100\000&\0000\337\200000000\327\2100\000\0000\3370/[0p Step #5: artifact_prefix='./'; Test unit written to ./oom-e2f413ddf3a74b9a37d26969557328e5b4114bd3 Step #5: Base64: AAAAOjAq34gwACYAMN+AMDAwLzDfiDAwMDAw34gwAAAw34AwMDAwMC9bMN+IMDAwKt+IMAAmMDB3MN+AMDAwMDAwWzDfiDAwMDQwMN+IMAAAMN+AMDAwMDAvDVsw34gwMAA6MCrfiDAAJgAw34AwMDAwMDDXiDAAADDfMC9bMHA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4354 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3900019194 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cd06961810, 0x55cd06b4b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cd06b4b020,0x55cd089e30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e2f413ddf3a74b9a37d26969557328e5b4114bd3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5446 processed earlier; will process 5583 files now Step #5: ==156820== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ccfd4569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cd03abb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cd03a9e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cd03a9e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ccfd45cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ccfd3bdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ccfd3b8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ccfd44ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cd0041df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cd0041df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cd0041df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cd0041df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cd0041df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cd0041df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cd0041df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cd0041df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cd0041df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cd0041df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cd026b2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ccff3dfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ccff3eabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ccff196c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ccff196c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ccff197738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ccff196874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ccff196874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ccff196874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cd03aa0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cd03aa9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cd03a91699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cd03abc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f00162c5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ccfd3b6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x67,0x7b,0x2f,0x2a,0x65,0x3e,0x67,0x7b,0x6e,0x6f,0x74,0x69,0x6d,0x65,0x32,0x2f,0x2a,0x20,0x58,0x3c,0x56,0x50,0x34,0x4c,0x67,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x54,0x79,0x6c,0x65,0x3e,0x67,0x7b,0x2f,0x2a,0x65,0x3e,0x67,0x7b,0x2f,0x2a,0x20,0x58,0x3c,0x50,0x76,0x4d,0x73,0x67,0x3e,0x3c,0x73,0x74,0x3e,0x5b,0x42,0x49,0x3d,0x2f,0x2a,0x65,0x3e,0x67,0x7b,0x2f,0x2a,0x20,0x58,0x3c,0x50,0x76,0x4d,0x73,0x67,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x54,0x3e,0x2d,0x3d,0x22,0x5c,0x42,0x3c,0x54,0x54,0x4b,0x3e,0x5b,0x49,0x49,0x3d,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x22,0x5c,0x42, Step #5: <svg><style>g{/*e>g{notime2/* X<VP4Lg><style>Tyle>g{/*e>g{/* X<PvMsg><st>[BI=/*e>g{/* X<PvMsg><style>T>-=\"\\B<TTK>[II=><style>\"\\B Step #5: artifact_prefix='./'; Test unit written to ./oom-4efe018a6ba1e12b3904298336f2e9c79767cc0f Step #5: Base64: PHN2Zz48c3R5bGU+Z3svKmU+Z3tub3RpbWUyLyogWDxWUDRMZz48c3R5bGU+VHlsZT5ney8qZT5ney8qIFg8UHZNc2c+PHN0PltCST0vKmU+Z3svKiBYPFB2TXNnPjxzdHlsZT5UPi09IlxCPFRUSz5bSUk9PjxzdHlsZT4iXEI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4355 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3900520150 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e7275ff810, 0x55e7277e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e7277e9020,0x55e7296810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4efe018a6ba1e12b3904298336f2e9c79767cc0f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5447 processed earlier; will process 5582 files now Step #5: ==156856== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e71e0f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e724759898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e72473c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e72473c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e71e0fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e71e05bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e71e056355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e71e0ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e7210bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e7210bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e7210bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e7210bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e7210bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e7210bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e7210bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e7210bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e7210bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e7210bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e723350f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e72007db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e720088be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e71fe34c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e71fe34c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e71fe35738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e71fe34874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e71fe34874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e71fe34874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e72473eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e724747928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e72472f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e72475a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f14b9d17082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e71e054b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7f,0x68,0x24,0x0,0x0,0x11,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x56,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2c,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x3d,0x7f,0x68,0x24,0x0,0x0,0x11,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2c,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x31,0x20,0x54,0x1,0x0,0x2,0x2f,0xcd,0x8f,0x41,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xd,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x8,0x2c, Step #5: \177h$\000\000\021\000\000\000------------V-------,--------=\177h$\000\000\021\000\000\000-------------------,---------------------------1 T\001\000\002/\315\217A---------\015---------\000\000\010, Step #5: artifact_prefix='./'; Test unit written to ./oom-670587acb7b167289be4b64c7c78018ab7795d79 Step #5: Base64: f2gkAAARAAAALS0tLS0tLS0tLS0tVi0tLS0tLS0sLS0tLS0tLS09f2gkAAARAAAALS0tLS0tLS0tLS0tLS0tLS0tLSwtLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0xIFQBAAIvzY9BLS0tLS0tLS0tDS0tLS0tLS0tLQAACCw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4356 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3901027445 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ec67cb810, 0x559ec69b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ec69b5020,0x559ec884d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/670587acb7b167289be4b64c7c78018ab7795d79' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5448 processed earlier; will process 5581 files now Step #5: ==156892== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559ebd2c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ec3925898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ec39085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ec39084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ebd2c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ebd227b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ebd222355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ebd2b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ec0287f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ec0287f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ec0287f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ec0287f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ec0287f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ec0287f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ec0287f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ec0287f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ec0287f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ec0287f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ec251cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559ebf249b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559ebf254be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559ebf000c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559ebf000c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559ebf001738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559ebf000874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559ebf000874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559ebf000874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ec390aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ec3913928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ec38fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ec3926112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f763ca1d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ebd220b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x20,0x0,0x2d,0x20,0x20,0x0,0x0,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x3e,0x24,0x40,0x3e,0x0,0x0,0x26,0x26,0x26,0x26,0x24,0x30,0x26,0x26,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x62,0x6f,0x6c,0x64,0x26,0x3e,0x24,0x30,0x26,0x26,0x62,0x6f,0x6c,0x64,0x26,0x3e,0x24,0x30, Step #5: - \000- \000\000&&&&&&&&>$@>\000\000&&&&$0&&{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{&&&&&&&&bold&>$0&&bold&>$0 Step #5: artifact_prefix='./'; Test unit written to ./oom-fd99169fe1b08fa016b578df4e8e116df6ea5494 Step #5: Base64: LSAgAC0gIAAAJiYmJiYmJiY+JEA+AAAmJiYmJDAmJnt7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7JiYmJiYmJiZib2xkJj4kMCYmYm9sZCY+JDA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4357 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3901537403 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563c8fb7c810, 0x563c8fd6601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563c8fd66020,0x563c91bfe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fd99169fe1b08fa016b578df4e8e116df6ea5494' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5449 processed earlier; will process 5580 files now Step #5: ==156928== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563c866719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563c8ccd6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563c8ccb95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563c8ccb94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563c86677d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563c865d8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563c865d3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563c86669c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563c89638f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563c89638f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563c89638f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563c89638f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563c89638f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563c89638f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563c89638f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563c89638f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563c89638f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563c89638f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563c8b8cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563c885fab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563c88605be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563c883b1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563c883b1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563c883b2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563c883b1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563c883b1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563c883b1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563c8ccbbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563c8ccc4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563c8ccac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563c8ccd7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe149955082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563c865d1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x3d,0x22,0x31,0x2e,0x30,0x22,0x20,0x65,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3d,0x22,0x4c,0x61,0x74,0x69,0x6e,0x31,0x22,0x20,0x20,0x3f,0x3e,0x3c,0x73,0x76,0x67,0x3e,0x3c,0x73,0x74,0x79,0x2e,0x65,0x3e,0x20,0x6d,0x6d,0x6d,0x60,0x27,0x6d,0x78,0x74,0x3e,0x2e,0x44,0x44,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x24,0x3c,0x73,0x76,0x67,0x3e,0x7d,0x7d,0x7d,0x3c,0x74,0x65,0x78,0x74,0x3e,0x31,0x27,0x69,0x63,0x6e,0x3e,0x79,0x5c,0x5c,0x44,0xd,0x5c,0x44,0x66,0x2f,0x60,0x35,0x5c,0x5c,0x45,0x68,0x79,0x5c,0x5c,0x44,0xd,0x5c,0x62,0x3a,0x73,0x76,0x67,0x3e,0x73,0x3c,0x67,0x3e,0x67,0x7b,0x74, Step #5: <?xml version=\"1.0\" encoding=\"Latin1\" ?><svg><sty.e> mmm`'mxt>.DD<style>$<svg>}}}<text>1'icn>y\\\\D\015\\Df/`5\\\\Ehy\\\\D\015\\b:svg>s<g>g{t Step #5: artifact_prefix='./'; Test unit written to ./oom-9f91a04a32456b7f4a164af1bd85799393dd7e12 Step #5: Base64: PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iTGF0aW4xIiAgPz48c3ZnPjxzdHkuZT4gbW1tYCdteHQ+LkREPHN0eWxlPiQ8c3ZnPn19fTx0ZXh0PjEnaWNuPnlcXEQNXERmL2A1XFxFaHlcXEQNXGI6c3ZnPnM8Zz5ne3Q= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4358 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3902167263 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b641e50810, 0x55b64203a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b64203a020,0x55b643ed20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f91a04a32456b7f4a164af1bd85799393dd7e12' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5450 processed earlier; will process 5579 files now Step #5: ==156964== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b6389459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b63efaa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b63ef8d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b63ef8d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b63894bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6388acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6388a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b63893dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b63b90cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b63b90cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b63b90cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b63b90cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b63b90cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b63b90cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b63b90cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b63b90cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b63b90cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b63b90cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b63dba1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b63a8ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b63a8d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b63a685c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b63a685c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b63a686738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b63a685874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b63a685874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b63a685874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b63ef8fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b63ef98928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b63ef80699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b63efab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe6467b3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6388a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9, Step #5: \011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ba6615898fd63ad69c2e9ec989adb109512677f Step #5: Base64: CQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4359 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3902651184 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56203fa54810, 0x56203fc3e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56203fc3e020,0x562041ad60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ba6615898fd63ad69c2e9ec989adb109512677f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5451 processed earlier; will process 5578 files now Step #5: #1 pulse cov: 11414 ft: 11415 exec/s: 0 rss: 195Mb Step #5: ==157000== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5620365499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56203cbae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56203cb915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56203cb914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56203654fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5620364b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5620364ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562036541c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562039510f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562039510f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562039510f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562039510f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562039510f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562039510f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562039510f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562039510f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562039510f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562039510f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56203b7a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5620384d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5620384ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562038289c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562038289c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56203828a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562038289874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562038289874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562038289874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56203cb93abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56203cb9c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56203cb84699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56203cbaf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5d460d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5620364a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x7d,0x7d,0x7d,0x3c,0x74,0x65,0x78,0x74,0x3e,0x39,0x32,0x29,0x28,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x31,0x36,0x39,0x32,0x35,0x3a,0x39,0x37,0x37,0xe2,0x80,0x98,0x3b,0xe1,0x82,0x8d,0xe1,0x82,0x8d,0xef,0xb8,0x8f,0x2d,0x2d,0x37,0x32,0x35,0x3a,0x39,0x37,0x37,0xe2,0x80,0x98,0x3b,0xe1,0x82,0x8d,0xe1,0x82,0x8d,0xef,0xb8,0x8f,0x2d,0x2d,0x37,0x32,0x32,0x2f,0x73,0x76,0x67,0x3e,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x42,0x4f,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e, Step #5: <svg>}}}<text>92)()))))))))))))))16925:977\342\200\230;\341\202\215\341\202\215\357\270\217--725:977\342\200\230;\341\202\215\341\202\215\357\270\217--722/svg></text><text>BO</text></svg></text><text> Step #5: artifact_prefix='./'; Test unit written to ./oom-91aa9de98036ac6aa55bc3f9127f54e97d068876 Step #5: Base64: PHN2Zz59fX08dGV4dD45MikoKSkpKSkpKSkpKSkpKSkpMTY5MjU6OTc34oCYO+GCjeGCje+4jy0tNzI1Ojk3N+KAmDvhgo3hgo3vuI8tLTcyMi9zdmc+PC90ZXh0Pjx0ZXh0PkJPPC90ZXh0Pjwvc3ZnPjwvdGV4dD48dGV4dD4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4360 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3903221280 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d31d58810, 0x564d31f4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d31f42020,0x564d33dda0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/91aa9de98036ac6aa55bc3f9127f54e97d068876' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5453 processed earlier; will process 5576 files now Step #5: ==157036== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d2884d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d2eeb2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d2ee955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d2ee954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d28853d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d287b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d287af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d28845c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d2b814f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d2b814f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d2b814f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d2b814f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d2b814f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d2b814f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d2b814f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d2b814f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d2b814f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d2b814f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d2daa9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d2a7d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d2a7e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d2a58dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d2a58dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d2a58e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d2a58d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d2a58d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d2a58d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d2ee97abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d2eea0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d2ee88699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d2eeb3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5181f6b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d287adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x3d,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x3d,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22, Step #5: /=\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"=\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-8999fd5dc5d1009f27816e2c65503c5fd52ea78d Step #5: Base64: Lz0iIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIj0iIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4361 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3903728065 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5616810fb810, 0x5616812e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5616812e5020,0x56168317d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8999fd5dc5d1009f27816e2c65503c5fd52ea78d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5454 processed earlier; will process 5575 files now Step #5: #1 pulse cov: 3755 ft: 3756 exec/s: 0 rss: 176Mb Step #5: ==157072== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561677bf09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56167e255898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56167e2385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56167e2384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561677bf6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561677b57b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561677b52355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561677be8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56167abb7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56167abb7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56167abb7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56167abb7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56167abb7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56167abb7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56167abb7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56167abb7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56167abb7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56167abb7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56167ce4cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561679b79b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561679b84be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561679930c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561679930c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561679931738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561679930874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561679930874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561679930874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56167e23aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56167e243928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56167e22b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56167e256112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4856625082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561677b50b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xa0,0xf3,0xb9,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xa9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x80,0xb9,0xf3,0xa0,0x30,0x30, Step #5: \363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\240\363\271\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\271\363\240\200\251\363\240\200\271\363\240\200\271\363\24000 Step #5: artifact_prefix='./'; Test unit written to ./oom-801117e4f74061191533134dd8006eff2c95a9ab Step #5: Base64: 86CAufOggLnzoIC586CAufOggLnzoIC586CAufOggLnzoIC586CAufOggLnzoIC586CAufOggLnzoIC586CAufOggLnzoICg87mAufOggLnzoIC586CAufOggLnzoIC586CAufOggLnzoIC586CAufOggKnzoIC586CAufOgMDA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4362 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3904267518 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5568a4be8810, 0x5568a4dd201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5568a4dd2020,0x5568a6c6a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/801117e4f74061191533134dd8006eff2c95a9ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5456 processed earlier; will process 5573 files now Step #5: ==157108== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55689b6dd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5568a1d42898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5568a1d255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5568a1d254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55689b6e3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55689b644b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55689b63f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55689b6d5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55689e6a4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55689e6a4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55689e6a4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55689e6a4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55689e6a4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55689e6a4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55689e6a4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55689e6a4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55689e6a4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55689e6a4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5568a0939f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55689d666b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55689d671be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55689d41dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55689d41dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55689d41e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55689d41d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55689d41d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55689d41d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5568a1d27abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5568a1d30928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5568a1d18699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5568a1d43112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc6f4ed5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55689b63db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0,0xa,0x2,0x3a,0x0, Step #5: \012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000\012\002:\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7861f36b05a523cc3440c53810eb6c4346beb1d1 Step #5: Base64: CgI6AAoCOgAKAjoACgI6AAoCOgAKAjoACgI6AAoCOgAKAjoACgI6AAoCOgAKAjoACgI6AAoCOgAKAjoACgI6AAoCOgAKAjoACgI6AAoCOgAKAjoACgI6AAoCOgAKAjoACgI6AAoCOgAKAjoACgI6AAoCOgAKAjoACgI6AAoCOgA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4363 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3904772177 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55779af23810, 0x55779b10d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55779b10d020,0x55779cfa50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7861f36b05a523cc3440c53810eb6c4346beb1d1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5457 processed earlier; will process 5572 files now Step #5: ==157144== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557791a189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55779807d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5577980605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5577980604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557791a1ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55779197fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55779197a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557791a10c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5577949dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5577949dff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5577949dff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5577949dff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5577949dff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5577949dff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5577949dff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5577949dff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5577949dff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5577949dff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557796c74f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5577939a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5577939acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557793758c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557793758c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557793759738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557793758874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557793758874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557793758874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557798062abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55779806b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557798053699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55779807e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f76ceeec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557791978b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x81,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x84,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x81,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x81,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x84,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x81,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x81,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x84,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x81,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x81,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x81,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x81,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x84,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x81,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x81,0xa9,0x3a,0xd,0x2d,0x2d,0x2d,0xe2,0x81,0xa9, Step #5: :\015---\342\201\251:\015---\342\204\251:\015---\342\201\251:\015---\342\201\251:\015---\342\204\251:\015---\342\201\251:\015---\342\201\251:\015---\342\204\251:\015---\342\201\251:\015---\342\201\251:\015---\342\201\251:\015---\342\201\251:\015---\342\204\251:\015---\342\201\251:\015---\342\201\251:\015---\342\201\251 Step #5: artifact_prefix='./'; Test unit written to ./oom-c3976c586800ea42b2ca7e7430dfdccd6124c60a Step #5: Base64: Og0tLS3igak6DS0tLeKEqToNLS0t4oGpOg0tLS3igak6DS0tLeKEqToNLS0t4oGpOg0tLS3igak6DS0tLeKEqToNLS0t4oGpOg0tLS3igak6DS0tLeKBqToNLS0t4oGpOg0tLS3ihKk6DS0tLeKBqToNLS0t4oGpOg0tLS3igak= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4364 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3905277697 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a16af2d810, 0x55a16b11701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a16b117020,0x55a16cfaf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c3976c586800ea42b2ca7e7430dfdccd6124c60a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5458 processed earlier; will process 5571 files now Step #5: #1 pulse cov: 3755 ft: 3756 exec/s: 0 rss: 176Mb Step #5: ==157180== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a161a229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a168087898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a16806a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a16806a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a161a28d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a161989b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a161984355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a161a1ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1649e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1649e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1649e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1649e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1649e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1649e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1649e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1649e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1649e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1649e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a166c7ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1639abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1639b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a163762c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a163762c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a163763738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a163762874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a163762874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a163762874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a16806cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a168075928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a16805d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a168088112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f65fa62d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a161982b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x81,0xa5,0xe0,0xac,0x8e,0xe0,0xa7,0x8e,0xe0,0xa7,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xb5,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa7,0x8e,0xe0,0xa8,0x8a,0xe0,0xa8,0x8e,0xe0,0xac,0x8e,0xe0,0xa7,0x8e,0xe0,0xa7,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x84,0xe0,0xa8,0x8e,0xe0,0xa8,0x85,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xaa,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0,0xa8,0x8e,0xe0, Step #5: \363\240\201\245\340\254\216\340\247\216\340\247\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\265\216\340\250\216\340\250\216\340\250\216\340\250\216\340\247\216\340\250\212\340\250\216\340\254\216\340\247\216\340\247\216\340\250\216\340\250\216\340\250\216\340\250\204\340\250\216\340\250\205\340\250\216\340\250\216\340\252\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340\250\216\340 Step #5: artifact_prefix='./'; Test unit written to ./oom-bb1dc072f4fa1d32586966c43877560c45c46606 Step #5: Base64: 86CBpeCsjuCnjuCnjuCojuCojuCojuCojuCojuCojuCojuCojuCojuC1juCojuCojuCojuCojuCnjuCoiuCojuCsjuCnjuCnjuCojuCojuCojuCohOCojuCoheCojuCojuCqjuCojuCojuCojuCojuCojuCojuCojuCojuCojuA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4365 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3905820146 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d55eec810, 0x556d560d601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d560d6020,0x556d57f6e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bb1dc072f4fa1d32586966c43877560c45c46606' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5460 processed earlier; will process 5569 files now Step #5: ==157216== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556d4c9e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d53046898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d530295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d530294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d4c9e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d4c948b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d4c943355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d4c9d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d4f9a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d4f9a8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d4f9a8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d4f9a8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d4f9a8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d4f9a8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d4f9a8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d4f9a8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d4f9a8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d4f9a8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d51c3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d4e96ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d4e975be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d4e721c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d4e721c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d4e722738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d4e721874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d4e721874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d4e721874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d5302babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d53034928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d5301c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d53047112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc8d63e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d4c941b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa, Step #5: \000\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf5175b1c434957228559b6c9dc3200e69248b77 Step #5: Base64: AAoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4366 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3906320361 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c3c4ee0810, 0x55c3c50ca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c3c50ca020,0x55c3c6f620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf5175b1c434957228559b6c9dc3200e69248b77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5461 processed earlier; will process 5568 files now Step #5: ==157252== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c3bb9d59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c3c203a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c3c201d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c3c201d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c3bb9dbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c3bb93cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c3bb937355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c3bb9cdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c3be99cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c3be99cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c3be99cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c3be99cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c3be99cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c3be99cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c3be99cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c3be99cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c3be99cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c3be99cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c3c0c31f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c3bd95eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c3bd969be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c3bd715c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c3bd715c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c3bd716738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c3bd715874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c3bd715874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c3bd715874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c3c201fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c3c2028928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c3c2010699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c3c203b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f919347e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c3bb935b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x12,0x0,0x0,0x0,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x12,0x0,0x0,0x0,0x67,0x72,0x79,0x25,0x73,0x67,0x72,0x79,0x25,0x73,0x7e,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x12,0x49,0x44,0x33,0x4,0x1,0x2e,0x7d,0x41,0xb,0x0,0x55,0x53,0x4c,0x50,0x2e,0x0,0x0,0x0,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x2e,0x7b,0x30,0x7d,0x30,0xff,0x12,0x0,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x72,0x79,0x25,0x29, Step #5: ~~~<\333\276~~~\022\000\000\000~~<\333\276~~~sssssssssssssssssssssssssssssssssssss\022\000\000\000gry%sgry%s~~~<\333\276~~~\022ID3\004\001.}A\013\000USLP.\000\000\000~~<\333\276~~~.{0}0\377\022\000\377\377\377\377\377\377\377\377ry%) Step #5: artifact_prefix='./'; Test unit written to ./oom-2d3546b2bc2a0346e09cfee24477cc13bc4092b3 Step #5: Base64: fn5+PNu+fn5+EgAAAH5+PNu+fn5+c3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3NzcxIAAABncnklc2dyeSVzfn5+PNu+fn5+EklEMwQBLn1BCwBVU0xQLgAAAH5+PNu+fn5+LnswfTD/EgD//////////3J5JSk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4367 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3906820875 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56371a2dd810, 0x56371a4c701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56371a4c7020,0x56371c35f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2d3546b2bc2a0346e09cfee24477cc13bc4092b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5462 processed earlier; will process 5567 files now Step #5: ==157288== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563710dd29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563717437898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56371741a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56371741a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563710dd8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563710d39b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563710d34355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563710dcac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563713d99f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563713d99f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563713d99f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563713d99f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563713d99f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563713d99f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563713d99f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563713d99f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563713d99f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563713d99f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56371602ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563712d5bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563712d66be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563712b12c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563712b12c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563712b13738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563712b12874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563712b12874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563712b12874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56371741cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563717425928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56371740d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563717438112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f563559a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563710d32b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x21,0x3f,0x20,0x3f,0x20,0x3f,0x20,0x3f,0xd,0x3f,0xd,0x3f,0x20,0x3f,0xa,0x3a,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa,0x3f,0x20,0x3f,0xa, Step #5: !!? ? ? ?\015?\015? ?\012: ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012? ?\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-96954c6d16d701615d0ae346356186c8d8f02ae5 Step #5: Base64: ISE/ID8gPyA/DT8NPyA/CjogPwo/ID8KPyA/Cj8gPwo/ID8KPyA/Cj8gPwo/ID8KPyA/Cj8gPwo/ID8KPyA/Cj8gPwo/ID8KPyA/Cj8gPwo/ID8KPyA/Cj8gPwo/ID8KPyA/Cj8gPwo/ID8KPyA/Cj8gPwo/ID8KPyA/Cj8gPwo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4368 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3907321966 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5584b171a810, 0x5584b190401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5584b1904020,0x5584b379c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/96954c6d16d701615d0ae346356186c8d8f02ae5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5463 processed earlier; will process 5566 files now Step #5: ==157324== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5584a820f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5584ae874898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5584ae8575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5584ae8574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5584a8215d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5584a8176b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5584a8171355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5584a8207c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5584ab1d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5584ab1d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5584ab1d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5584ab1d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5584ab1d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5584ab1d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5584ab1d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5584ab1d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5584ab1d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5584ab1d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5584ad46bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5584aa198b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5584aa1a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5584a9f4fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5584a9f4fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5584a9f50738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5584a9f4f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5584a9f4f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5584a9f4f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5584ae859abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5584ae862928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5584ae84a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5584ae875112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7ca044082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5584a816fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0xa5,0x81,0x8e,0xf0,0xa5,0x81,0x8e,0xf0,0xb7,0xb9,0x86,0xf0,0xa7,0x81,0x8f,0xf0,0xa7,0x81,0x8e,0xf0,0xa7,0xbf,0x96,0xf0,0xa7,0xbf,0x86,0xf0,0xa7,0x80,0x8e,0xf0,0xa7,0x82,0x8e,0xf0,0xa5,0x81,0x8f,0xf0,0xa7,0x81,0x8e,0xf0,0xa7,0xb9,0x86,0xf0,0xa7,0x81,0x8e,0xf0,0xa7,0xb9,0x8e,0xf0,0xa7,0xb9,0x8f,0xf0,0xa7,0x82,0x8e,0xf0,0xbf,0xbf,0x86,0xf0,0xb7,0xb9,0x86,0xf0,0xa7,0x81,0x8f,0xf0,0xa7,0x81,0x8e,0xf0,0xa7,0xbf,0x96,0xf0,0xa7,0xbf,0x86,0xf0,0xa7,0x80,0x8e,0xf0,0xa7,0x82,0x8e,0xf0,0xa5,0x81,0x8f,0xf0,0xa7,0x81,0x8e,0xf0,0xa7,0xb9,0x86,0xf0,0xa7,0x81,0x8e,0xf0,0xa7,0xb9,0x8e,0xf0,0xa7,0xb9,0x8f,0xf0,0xa7,0x82,0x8e,0xf0,0xbf,0xbf,0x86, Step #5: \360\245\201\216\360\245\201\216\360\267\271\206\360\247\201\217\360\247\201\216\360\247\277\226\360\247\277\206\360\247\200\216\360\247\202\216\360\245\201\217\360\247\201\216\360\247\271\206\360\247\201\216\360\247\271\216\360\247\271\217\360\247\202\216\360\277\277\206\360\267\271\206\360\247\201\217\360\247\201\216\360\247\277\226\360\247\277\206\360\247\200\216\360\247\202\216\360\245\201\217\360\247\201\216\360\247\271\206\360\247\201\216\360\247\271\216\360\247\271\217\360\247\202\216\360\277\277\206 Step #5: artifact_prefix='./'; Test unit written to ./oom-dbe4f0c176657633e904856c3985298dc1b3f57d Step #5: Base64: 8KWBjvClgY7wt7mG8KeBj/CngY7wp7+W8Ke/hvCngI7wp4KO8KWBj/CngY7wp7mG8KeBjvCnuY7wp7mP8KeCjvC/v4bwt7mG8KeBj/CngY7wp7+W8Ke/hvCngI7wp4KO8KWBj/CngY7wp7mG8KeBjvCnuY7wp7mP8KeCjvC/v4Y= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4369 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3907819813 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560982781810, 0x56098296b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56098296b020,0x5609848030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dbe4f0c176657633e904856c3985298dc1b3f57d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5464 processed earlier; will process 5565 files now Step #5: #1 pulse cov: 3757 ft: 3758 exec/s: 0 rss: 174Mb Step #5: ==157360== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5609792769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56097f8db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56097f8be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56097f8be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56097927cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5609791ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5609791d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56097926ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56097c23df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56097c23df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56097c23df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56097c23df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56097c23df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56097c23df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56097c23df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56097c23df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56097c23df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56097c23df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56097e4d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56097b1ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56097b20abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56097afb6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56097afb6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56097afb7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56097afb6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56097afb6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56097afb6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56097f8c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56097f8c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56097f8b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56097f8dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f331a25d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5609791d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x98,0xc3,0x99,0xc3,0x86,0xc3,0x99,0xc3,0x86,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x98,0xc3,0x86,0xc3,0x99,0xc3,0x99,0xc3,0x86,0xc3,0x85,0xc3,0x99,0xc3,0xb8,0xc3,0x99,0xc3,0x9a,0xc3,0x99,0xc3,0x86,0xc3,0x85,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x86,0xc3,0x99,0xc3,0x99,0xc3,0x86,0xc3,0x85,0xc3,0x99,0xc3,0xb8,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x86,0xc3,0x85,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x99,0xc3,0x86,0xc3,0x99,0xc3,0x97, Step #5: \303\231\303\231\303\231\303\231\303\230\303\231\303\206\303\231\303\206\303\231\303\231\303\231\303\231\303\231\303\231\303\231\303\231\303\231\303\230\303\206\303\231\303\231\303\206\303\205\303\231\303\270\303\231\303\232\303\231\303\206\303\205\303\231\303\231\303\231\303\231\303\231\303\231\303\231\303\231\303\206\303\231\303\231\303\206\303\205\303\231\303\270\303\231\303\231\303\231\303\206\303\205\303\231\303\231\303\231\303\231\303\231\303\231\303\231\303\231\303\231\303\231\303\206\303\231\303\227 Step #5: artifact_prefix='./'; Test unit written to ./oom-ba14c1f6a602d3797ada4e34cf26ce19c56b5b14 Step #5: Base64: w5nDmcOZw5nDmMOZw4bDmcOGw5nDmcOZw5nDmcOZw5nDmcOZw5jDhsOZw5nDhsOFw5nDuMOZw5rDmcOGw4XDmcOZw5nDmcOZw5nDmcOZw4bDmcOZw4bDhcOZw7jDmcOZw5nDhsOFw5nDmcOZw5nDmcOZw5nDmcOZw5nDhsOZw5c= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4370 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3908358459 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5570ab36a810, 0x5570ab55401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5570ab554020,0x5570ad3ec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba14c1f6a602d3797ada4e34cf26ce19c56b5b14' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5466 processed earlier; will process 5563 files now Step #5: #1 pulse cov: 3753 ft: 3754 exec/s: 0 rss: 174Mb Step #5: ==157396== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5570a1e5f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5570a84c4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5570a84a75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5570a84a74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5570a1e65d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5570a1dc6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5570a1dc1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5570a1e57c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5570a4e26f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5570a4e26f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5570a4e26f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5570a4e26f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5570a4e26f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5570a4e26f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5570a4e26f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5570a4e26f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5570a4e26f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5570a4e26f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5570a70bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5570a3de8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5570a3df3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5570a3b9fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5570a3b9fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5570a3ba0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5570a3b9f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5570a3b9f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5570a3b9f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5570a84a9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5570a84b2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5570a849a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5570a84c5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f894449b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5570a1dbfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdd,0xbf,0x42,0x14,0x0,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x48,0x0,0x0,0x27,0x27, Step #5: \335\277B\024\000HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH\000\000'' Step #5: artifact_prefix='./'; Test unit written to ./oom-9f62e71032e6ba5b7a7321668cf88d5a8128ad3a Step #5: Base64: 3b9CFABISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEgAACcn Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4371 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3908908646 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560edee4c810, 0x560edf03601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560edf036020,0x560ee0ece0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f62e71032e6ba5b7a7321668cf88d5a8128ad3a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5468 processed earlier; will process 5561 files now Step #5: ==157432== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560ed59419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560edbfa6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560edbf895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560edbf894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560ed5947d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560ed58a8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560ed58a3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560ed5939c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560ed8908f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560ed8908f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560ed8908f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560ed8908f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560ed8908f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560ed8908f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560ed8908f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560ed8908f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560ed8908f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560ed8908f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560edab9df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560ed78cab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560ed78d5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560ed7681c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560ed7681c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560ed7682738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560ed7681874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560ed7681874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560ed7681874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560edbf8babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560edbf94928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560edbf7c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560edbfa7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd00d9ad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560ed58a1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xad,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xb0,0xa,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x86,0xad,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xad,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xad,0xf0,0x9d,0x85,0xa9,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x85,0xad, Step #5: \360\235\205\251\360\235\205\260\360\235\205\260\360\235\205\260\360\235\205\260\360\235\205\260\360\235\205\260\360\235\205\260\360\235\205\260\360\235\205\255\360\235\205\251\360\235\205\260\012\360\235\205\260\360\235\205\260\360\235\205\260\360\235\205\260\360\235\205\260\360\235\206\255\360\235\205\260\360\235\205\260\360\235\205\260\360\235\205\260\360\235\205\260\360\235\205\255\360\235\205\251\360\235\205\260\360\235\205\260\360\235\205\260\360\235\205\255\360\235\205\251\360\235\205\260\360\235\205\255 Step #5: artifact_prefix='./'; Test unit written to ./oom-fd4d3b34f726d3b096e13d47c5319e9ef1b285ff Step #5: Base64: 8J2FqfCdhbDwnYWw8J2FsPCdhbDwnYWw8J2FsPCdhbDwnYWw8J2FrfCdhanwnYWwCvCdhbDwnYWw8J2FsPCdhbDwnYWw8J2GrfCdhbDwnYWw8J2FsPCdhbDwnYWw8J2FrfCdhanwnYWw8J2FsPCdhbDwnYWt8J2FqfCdhbDwnYWt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4372 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3909404958 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f9030c8810, 0x55f9032b201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f9032b2020,0x55f90514a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fd4d3b34f726d3b096e13d47c5319e9ef1b285ff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5469 processed earlier; will process 5560 files now Step #5: ==157468== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8f9bbd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f900222898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f9002055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f9002054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8f9bc3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8f9b24b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8f9b1f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8f9bb5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8fcb84f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8fcb84f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8fcb84f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8fcb84f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8fcb84f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8fcb84f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8fcb84f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8fcb84f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8fcb84f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8fcb84f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f8fee19f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f8fbb46b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f8fbb51be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8fb8fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8fb8fdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8fb8fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8fb8fd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8fb8fd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8fb8fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f900207abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f900210928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f9001f8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f900223112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f64722ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8f9b1db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x7b,0x22,0x72,0x65,0x73,0x6f,0x75,0x72,0x63,0x65,0x4d,0x65,0x74,0x72,0x69,0x63,0x73,0x22,0x5b,0x5b,0x4e,0x7b,0x22,0x22,0x73,0x63,0x6f,0x70,0x65,0x5f,0x6d,0x65,0x74,0x72,0x69,0x63,0x73,0x22,0x5b,0x5b,0x4e,0x7b,0x22,0x22,0x73,0x63,0x6f,0x70,0x65,0x22,0x65,0x7b,0x22,0x22,0x64,0x70,0x72,0x22,0x3e,0x31,0x36,0x2c,0x22,0x61,0x74,0x74,0x72,0x69,0x62,0x75,0x74,0x65,0x73,0x22,0x2c,0x5b,0x4e,0x7b,0x22,0x3e,0x37,0x35,0x30,0x2c,0x22,0x76,0x61,0x6c,0x75,0x65,0x22,0x7a,0x7b,0x22,0x22,0x6b,0x76,0x28,0x69,0x73,0x74,0x5f,0x76,0x61,0x6c,0x75,0x65,0x22,0xcf,0x7b,0x22,0x22,0x6f,0x73,0x22,0x5b,0x1,0x2c,0x6c,0x61,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c, Step #5: F{\"resourceMetrics\"[[N{\"\"scope_metrics\"[[N{\"\"scope\"e{\"\"dpr\">16,\"attributes\",[N{\">750,\"value\"z{\"\"kv(ist_value\"\317{\"\"os\"[\001,la,,,,,,,, Step #5: artifact_prefix='./'; Test unit written to ./oom-36e19fe25477a8b0cf43a65257e103649f247c3e Step #5: Base64: RnsicmVzb3VyY2VNZXRyaWNzIltbTnsiInNjb3BlX21ldHJpY3MiW1tOeyIic2NvcGUiZXsiImRwciI+MTYsImF0dHJpYnV0ZXMiLFtOeyI+NzUwLCJ2YWx1ZSJ6eyIia3YoaXN0X3ZhbHVlIs97IiJvcyJbASxsYSwsLCwsLCws Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4373 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3909907067 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f9ed9c810, 0x556f9ef8601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f9ef86020,0x556fa0e1e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/36e19fe25477a8b0cf43a65257e103649f247c3e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5470 processed earlier; will process 5559 files now Step #5: ==157504== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556f958919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f9bef6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f9bed95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f9bed94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f95897d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f957f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f957f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f95889c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f98858f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f98858f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f98858f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f98858f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f98858f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f98858f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f98858f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f98858f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f98858f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f98858f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f9aaedf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f9781ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f97825be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f975d1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f975d1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f975d2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f975d1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f975d1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f975d1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f9bedbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f9bee4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f9becc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f9bef7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc0c6807082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f957f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa, Step #5: \012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-2ac64a09b5a3a7ed60d837aa07467f46a918bbf4 Step #5: Base64: CgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4374 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3910392315 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559f52de6810, 0x559f52fd001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559f52fd0020,0x559f54e680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2ac64a09b5a3a7ed60d837aa07467f46a918bbf4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5471 processed earlier; will process 5558 files now Step #5: ==157540== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559f498db9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559f4ff40898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559f4ff235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559f4ff234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559f498e1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559f49842b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559f4983d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559f498d3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559f4c8a2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559f4c8a2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559f4c8a2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559f4c8a2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559f4c8a2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559f4c8a2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559f4c8a2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559f4c8a2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559f4c8a2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559f4c8a2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559f4eb37f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559f4b864b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559f4b86fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559f4b61bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559f4b61bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559f4b61c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559f4b61b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559f4b61b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559f4b61b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559f4ff25abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559f4ff2e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559f4ff16699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559f4ff41112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe309a25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559f4983bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2b,0x2e,0x2f,0xe,0x2b,0x2e,0x3f,0x7d,0x2b,0x32,0x2b,0x7d,0x2b,0x2e,0x63,0x82,0x2b,0x2e,0x2b,0x7d,0x2b,0x7d,0x2e,0x2b,0xb0,0xb0,0xb0,0xb0,0xb0,0xb0,0xb0,0xb0,0x7d,0x2b,0xff,0xff,0xff,0xfc,0xff,0xff,0x26,0x2e,0x2b,0x7d,0x2b,0x2e,0x6b,0x7d,0x2e,0x2b,0x2b,0x2b,0xd9,0x0,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x2a,0xff,0xff,0xff,0xff,0xff,0xfe,0x2e,0x2b,0x7d,0x2b,0xb7,0xaa,0xba,0xef,0x1f,0x28,0x25,0x6f,0x6f,0x6f,0x6f,0x6f,0x1,0x0,0x0,0x0,0x2e,0x2b,0x2e,0xff,0xff,0x8,0xff,0x2b,0x7d,0x2b,0x2e,0x2b,0x7d,0xb7,0xba,0xb7,0xba,0x3c,0xef,0x2b,0x7d,0x0,0x7d,0x2d,0x2b,0x2e,0x2f,0xe,0x2b,0x2e,0x3f,0x0,0x2b,0x32,0x7d,0x2b,0x2b, Step #5: -+./\016+.?}+2+}+.c\202+.+}+}.+\260\260\260\260\260\260\260\260}+\377\377\377\374\377\377&.+}+.k}.+++\331\000\377\377\377\377\377\377\377\377\377\377*\377\377\377\377\377\376.+}+\267\252\272\357\037(%ooooo\001\000\000\000.+.\377\377\010\377+}+.+}\267\272\267\272<\357+}\000}-+./\016+.?\000+2}++ Step #5: artifact_prefix='./'; Test unit written to ./oom-b1efba10df474fa93d0eee3098be78d1a6fee163 Step #5: Base64: LSsuLw4rLj99KzIrfSsuY4IrLit9K30uK7CwsLCwsLCwfSv////8//8mLit9Ky5rfS4rKyvZAP////////////8q///////+Lit9K7equu8fKCVvb29vbwEAAAAuKy7//wj/K30rLit9t7q3ujzvK30AfS0rLi8OKy4/ACsyfSsr Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4375 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3910887002 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c9e1b1810, 0x559c9e39b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c9e39b020,0x559ca02330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b1efba10df474fa93d0eee3098be78d1a6fee163' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5472 processed earlier; will process 5557 files now Step #5: ==157576== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559c94ca69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c9b30b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c9b2ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c9b2ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c94cacd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c94c0db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c94c08355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c94c9ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c97c6df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c97c6df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c97c6df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c97c6df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c97c6df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c97c6df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c97c6df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c97c6df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c97c6df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c97c6df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c99f02f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c96c2fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c96c3abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c969e6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c969e6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c969e7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c969e6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c969e6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c969e6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c9b2f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c9b2f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c9b2e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c9b30c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fde5c755082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c94c06b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x21,0x0,0x0,0x0,0x9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x32,0x0,0x0,0x29,0xef,0x8b,0xbf,0x3f,0x0,0x60,0x5b,0x2d,0x33,0x5d,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x20,0x60,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x21,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x32,0x0,0x0,0x29,0xef,0x8b,0xbf,0x3f,0x0,0x60,0x5b,0x2d,0x33,0x5d,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x20,0x61,0x34,0x30,0x34,0x31,0x7c,0x61,0x34,0x30,0x34,0x31,0x7c,0x7c, Step #5: `\000\000\000\000\000\000\000\000\000\000\000\000\000!\000\000\000\011\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0002\000\000)\357\213\277?\000`[-3]|||||| `\000\000\000\000\000\000\000\000\000\000\000\000\000!\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0002\000\000)\357\213\277?\000`[-3]|||||| a4041|a4041|| Step #5: artifact_prefix='./'; Test unit written to ./oom-60cbcddcd1cd03062fda164ae173d5ddbeb1b858 Step #5: Base64: YAAAAAAAAAAAAAAAAAAhAAAACQAAAAAAAAAAAAAAAAAAAAAAADIAACnvi78/AGBbLTNdfHx8fHx8IGAAAAAAAAAAAAAAAAAAIQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAyAAAp74u/PwBgWy0zXXx8fHx8fCBhNDA0MXxhNDA0MXx8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4376 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3911512672 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559346f91810, 0x55934717b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55934717b020,0x5593490130e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/60cbcddcd1cd03062fda164ae173d5ddbeb1b858' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5473 processed earlier; will process 5556 files now Step #5: ==157612== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55933da869c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5593440eb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5593440ce5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5593440ce4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55933da8cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55933d9edb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55933d9e8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55933da7ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559340a4df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559340a4df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559340a4df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559340a4df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559340a4df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559340a4df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559340a4df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559340a4df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559340a4df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559340a4df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559342ce2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55933fa0fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55933fa1abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55933f7c6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55933f7c6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55933f7c7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55933f7c6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55933f7c6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55933f7c6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5593440d0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5593440d9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5593440c1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5593440ec112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb7593fd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55933d9e6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x0,0x0,0x0,0x7b,0x6f,0x6e,0x4b,0x60,0x20,0x2d,0x45,0x47,0x4b,0x60,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x2b,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0xff,0xff,0xff,0xff,0xff,0xff,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x20,0x2d,0x24,0x24,0x0,0x0,0x0,0x87,0x28,0x0,0x0,0x0,0xa,0x2d,0x2a,0x64,0xa,0x64,0xa,0x3f, Step #5: s-----BE\000\000\000{onK` -EGK`$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$+$$$$$$$$$$\377\377\377\377\377\377$$$$$$$$$$$$$$ -$$\000\000\000\207(\000\000\000\012-*d\012d\012? Step #5: artifact_prefix='./'; Test unit written to ./oom-3670cee47a3458932e4ba8af9e0b1ea8026da381 Step #5: Base64: cy0tLS0tQkUAAAB7b25LYCAtRUdLYCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkKyQkJCQkJCQkJCT///////8kJCQkJCQkJCQkJCQkJCAtJCQAAACHKAAAAAotKmQKZAo/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4377 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3912149376 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f71d7d1810, 0x55f71d9bb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f71d9bb020,0x55f71f8530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3670cee47a3458932e4ba8af9e0b1ea8026da381' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5474 processed earlier; will process 5555 files now Step #5: ==157648== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f7142c69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f71a92b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f71a90e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f71a90e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f7142ccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f71422db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f714228355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f7142bec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f71728df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f71728df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f71728df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f71728df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f71728df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f71728df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f71728df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f71728df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f71728df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f71728df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f719522f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f71624fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f71625abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f716006c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f716006c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f716007738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f716006874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f716006874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f716006874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f71a910abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f71a919928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f71a901699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f71a92c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88969f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f714226b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0x4b,0xc7,0x8b,0x2e,0x78,0x6e,0x2d,0x2d,0xc7,0x8b, Step #5: ws:xn--K\307\213.xn--K\307\213.xn--K\307\213.xn--K\307\213.xn--K\307\213.xn--K\307\213.xn--K\307\213.xn--K\307\213.xn--K\307\213.xn--K\307\213.xn--K\307\213.xn--K\307\213.xn--K\307\213.xn--K\307\213.xn--K\307\213.xn--\307\213 Step #5: artifact_prefix='./'; Test unit written to ./oom-c2f2214899ad0291a8bc1c5a022c1dd5bccf537c Step #5: Base64: d3M6eG4tLUvHiy54bi0tS8eLLnhuLS1Lx4sueG4tLUvHiy54bi0tS8eLLnhuLS1Lx4sueG4tLUvHiy54bi0tS8eLLnhuLS1Lx4sueG4tLUvHiy54bi0tS8eLLnhuLS1Lx4sueG4tLUvHiy54bi0tS8eLLnhuLS1Lx4sueG4tLceL Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4378 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3912651131 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559564d38810, 0x559564f2201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559564f22020,0x559566dba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c2f2214899ad0291a8bc1c5a022c1dd5bccf537c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5475 processed earlier; will process 5554 files now Step #5: ==157684== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55955b82d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559561e92898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559561e755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559561e754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55955b833d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55955b794b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55955b78f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55955b825c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55955e7f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55955e7f4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55955e7f4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55955e7f4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55955e7f4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55955e7f4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55955e7f4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55955e7f4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55955e7f4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55955e7f4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559560a89f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55955d7b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55955d7c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55955d56dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55955d56dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55955d56e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55955d56d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55955d56d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55955d56d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559561e77abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559561e80928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559561e68699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559561e93112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc7bf1f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55955b78db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x68,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x23,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e, Step #5: h#version#version#version#version#version#version#version#version#version#version#version#version#version#version#version#version Step #5: artifact_prefix='./'; Test unit written to ./oom-c8bed69747b0afe19922aa82bcae3b16c3975edd Step #5: Base64: aCN2ZXJzaW9uI3ZlcnNpb24jdmVyc2lvbiN2ZXJzaW9uI3ZlcnNpb24jdmVyc2lvbiN2ZXJzaW9uI3ZlcnNpb24jdmVyc2lvbiN2ZXJzaW9uI3ZlcnNpb24jdmVyc2lvbiN2ZXJzaW9uI3ZlcnNpb24jdmVyc2lvbiN2ZXJzaW9u Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4379 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3913154756 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d33b5c810, 0x562d33d4601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d33d46020,0x562d35bde0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c8bed69747b0afe19922aa82bcae3b16c3975edd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5476 processed earlier; will process 5553 files now Step #5: ==157720== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562d2a6519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d30cb6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d30c995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d30c994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d2a657d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d2a5b8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d2a5b3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d2a649c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d2d618f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d2d618f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d2d618f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d2d618f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d2d618f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d2d618f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d2d618f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d2d618f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d2d618f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d2d618f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d2f8adf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d2c5dab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d2c5e5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d2c391c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d2c391c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d2c392738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d2c391874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d2c391874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d2c391874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d30c9babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d30ca4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d30c8c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d30cb7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5ec6712082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d2a5b1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c,0x24,0x65,0x5b,0x3e,0x59,0x3f,0x7d,0x3f,0x2c,0x24,0x5b,0x22,0x5b,0x3f,0x59,0x5d,0x3f,0x2c,0x5b,0x5b,0x5b,0x3d,0x5d,0x2c,0x29,0x3f,0x55,0x55,0x55,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20, Step #5: l$e[>Y?}?,$[\"[?Y]?,[[[=],)?UUU Step #5: artifact_prefix='./'; Test unit written to ./oom-fd023744bb76dc489dae866c233749f1715c5aaf Step #5: Base64: bCRlWz5ZP30/LCRbIls/WV0/LFtbWz1dLCk/VVVVICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4380 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3913659170 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d36ec2810, 0x564d370ac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d370ac020,0x564d38f440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fd023744bb76dc489dae866c233749f1715c5aaf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5477 processed earlier; will process 5552 files now Step #5: ==157756== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d2d9b79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d3401c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d33fff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d33fff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d2d9bdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d2d91eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d2d919355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d2d9afc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d3097ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d3097ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d3097ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d3097ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d3097ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d3097ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d3097ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d3097ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d3097ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d3097ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d32c13f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d2f940b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d2f94bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d2f6f7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d2f6f7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d2f6f8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d2f6f7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d2f6f7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d2f6f7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d34001abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d3400a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d33ff2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d3401d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f77e7001082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d2d917b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xdb,0x80,0x38,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x73,0x20,0x5b,0x30,0x20,0x32,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3f,0x0,0x8,0x0,0x0,0x0,0x39, Step #5: \333\200\333\2009\000*********************************************\333\2008\000*************************************\000\000\000\000\000\000\000\001\000\000s [0 2\000\000\000\000\000\000\000\000\000\000\000\000\000\000?\000\010\000\000\0009 Step #5: artifact_prefix='./'; Test unit written to ./oom-bf1b689a11a002832a332e2e9d94a54220d0824e Step #5: Base64: 24DbgDkAKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioq24A4ACoqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioAAAAAAAAAAQAAcyBbMCAyAAAAAAAAAAAAAAAAAAA/AAgAAAA5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4381 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3914167326 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5596dc474810, 0x5596dc65e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596dc65e020,0x5596de4f60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf1b689a11a002832a332e2e9d94a54220d0824e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5478 processed earlier; will process 5551 files now Step #5: ==157792== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5596d2f699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5596d95ce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5596d95b15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5596d95b14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5596d2f6fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5596d2ed0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5596d2ecb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5596d2f61c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5596d5f30f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5596d5f30f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5596d5f30f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5596d5f30f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5596d5f30f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5596d5f30f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5596d5f30f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5596d5f30f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5596d5f30f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5596d5f30f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596d81c5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5596d4ef2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5596d4efdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5596d4ca9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5596d4ca9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5596d4caa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5596d4ca9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5596d4ca9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5596d4ca9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5596d95b3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5596d95bc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5596d95a4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5596d95cf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f32f5e44082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5596d2ec9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x0,0x0,0x50,0x4e,0x47,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x4,0x0,0x0,0x50,0x4e,0x47,0x8,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x4,0x0,0x0,0x50,0x4e,0x47,0x8,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x4,0x0,0x0,0x50,0x4e,0x47,0x8,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x4,0x0,0x0,0x50,0x4e,0x47,0x8,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x4,0x0,0x0,0x50,0x4e,0x47,0x8,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x4,0x0,0x0,0x50,0x4e,0x47,0x8,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x4,0x0,0x0,0x50,0x4e,0x47,0x8,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x0,0x0,0x50,0x50,0x4e,0x29, Step #5: ID3\004\000\000PNG\000APIC\000\000\000\005\004\000\000PNG\010APIC\000\000\000\005\004\000\000PNG\010APIC\000\000\000\005\004\000\000PNG\010APIC\000\000\000\005\004\000\000PNG\010APIC\000\000\000\005\004\000\000PNG\010APIC\000\000\000\005\004\000\000PNG\010APIC\000\000\000\005\004\000\000PNG\010APIC\000\000\000\005\000\000PPN) Step #5: artifact_prefix='./'; Test unit written to ./oom-815b96ed5b225d00bd0dfb0797c8309977f66543 Step #5: Base64: SUQzBAAAUE5HAEFQSUMAAAAFBAAAUE5HCEFQSUMAAAAFBAAAUE5HCEFQSUMAAAAFBAAAUE5HCEFQSUMAAAAFBAAAUE5HCEFQSUMAAAAFBAAAUE5HCEFQSUMAAAAFBAAAUE5HCEFQSUMAAAAFBAAAUE5HCEFQSUMAAAAFAABQUE4p Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4382 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3914669661 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5636110c9810, 0x5636112b301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5636112b3020,0x56361314b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/815b96ed5b225d00bd0dfb0797c8309977f66543' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5479 processed earlier; will process 5550 files now Step #5: ==157828== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563607bbe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56360e223898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56360e2065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56360e2064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563607bc4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563607b25b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563607b20355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563607bb6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56360ab85f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56360ab85f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56360ab85f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56360ab85f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56360ab85f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56360ab85f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56360ab85f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56360ab85f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56360ab85f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56360ab85f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56360ce1af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563609b47b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563609b52be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5636098fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5636098fec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5636098ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5636098fe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5636098fe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5636098fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56360e208abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56360e211928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56360e1f9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56360e224112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f73bd59e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563607b1eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x7d,0x7d,0x7d,0x3c,0x74,0x65,0x78,0x74,0x3e,0x2c,0x31,0x2d,0x30,0x3f,0x37,0xd,0x2d,0xd6,0xbf,0x5b,0x33,0x37,0x30,0x39,0x35,0x35,0x52,0x2e,0x29,0x5b,0x21,0xef,0xba,0xac,0x2d,0xd6,0xbf,0x5b,0x3f,0x2e,0x2e,0x2f,0x2e,0x2b,0x34,0x34,0x31,0x2d,0x30,0x3f,0x37,0xd,0x2d,0xd6,0xbf,0x5b,0x33,0x37,0x30,0x39,0x35,0x35,0x52,0x2e,0x29,0x5b,0x21,0xef,0xba,0xac,0x2d,0xd6,0xbf,0x5b,0x3f,0x2e,0x2e,0x2f,0x2e,0x2b,0x34,0x34,0xef,0xbb,0xbf,0xef,0xba,0xac,0x2d,0x2d,0x5b,0x21,0xef,0xba,0xac,0x2d,0xd6,0xbf,0x5b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x42,0x4f,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg>}}}<text>,1-0?7\015-\326\277[370955R.)[!\357\272\254-\326\277[?../.+441-0?7\015-\326\277[370955R.)[!\357\272\254-\326\277[?../.+44\357\273\277\357\272\254--[!\357\272\254-\326\277[;;;;;;;;;;</text>BO</svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-90f8b9ac66ed3673a9db7c7563fbd0f27a1b252d Step #5: Base64: PHN2Zz59fX08dGV4dD4sMS0wPzcNLda/WzM3MDk1NVIuKVsh77qsLda/Wz8uLi8uKzQ0MS0wPzcNLda/WzM3MDk1NVIuKVsh77qsLda/Wz8uLi8uKzQ077u/77qsLS1bIe+6rC3Wv1s7Ozs7Ozs7Ozs7PC90ZXh0PkJPPC9zdmc+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4383 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3915172537 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557c20850810, 0x557c20a3a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557c20a3a020,0x557c228d20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/90f8b9ac66ed3673a9db7c7563fbd0f27a1b252d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5480 processed earlier; will process 5549 files now Step #5: ==157864== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557c173459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557c1d9aa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557c1d98d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557c1d98d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557c1734bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557c172acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557c172a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557c1733dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557c1a30cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557c1a30cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557c1a30cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557c1a30cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557c1a30cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557c1a30cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557c1a30cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557c1a30cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557c1a30cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557c1a30cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557c1c5a1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557c192ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557c192d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557c19085c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557c19085c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557c19086738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557c19085874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557c19085874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557c19085874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557c1d98fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557c1d998928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557c1d980699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557c1d9ab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0bd3f4c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557c172a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0, Step #5: FUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAG\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7c5f106ee7eaced7cf0d615b991fec9508bdcd25 Step #5: Base64: RlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUcA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4384 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3915682856 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564941c0a810, 0x564941df401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564941df4020,0x564943c8c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7c5f106ee7eaced7cf0d615b991fec9508bdcd25' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5481 processed earlier; will process 5548 files now Step #5: #1 pulse cov: 3611 ft: 3612 exec/s: 0 rss: 177Mb Step #5: ==157900== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5649386ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56493ed64898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56493ed475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56493ed474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564938705d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564938666b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564938661355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5649386f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56493b6c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56493b6c6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56493b6c6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56493b6c6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56493b6c6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56493b6c6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56493b6c6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56493b6c6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56493b6c6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56493b6c6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56493d95bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56493a688b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56493a693be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56493a43fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56493a43fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56493a440738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56493a43f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56493a43f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56493a43f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56493ed49abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56493ed52928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56493ed3a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56493ed65112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc8a9020082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56493865fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x26,0xe7,0x91,0xa7,0x3c, Step #5: &\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247&\347\221\247< Step #5: artifact_prefix='./'; Test unit written to ./oom-4134ed29428ba9b4e8d4b6536e076e638aa5182a Step #5: Base64: JueRpybnkacm55GnJueRpybnkacm55GnJueRpybnkacm55GnJueRpybnkacm55GnJueRpybnkacm55GnJueRpybnkacm55GnJueRpybnkacm55GnJueRpybnkacm55GnJueRpybnkacm55GnJueRpybnkacm55GnJueRpybnkac8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4385 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3916222013 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56528b047810, 0x56528b23101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56528b231020,0x56528d0c90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4134ed29428ba9b4e8d4b6536e076e638aa5182a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5483 processed earlier; will process 5546 files now Step #5: ==157936== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565281b3c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652881a1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652881845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652881844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565281b42d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565281aa3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565281a9e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565281b34c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565284b03f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565284b03f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565284b03f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565284b03f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565284b03f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565284b03f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565284b03f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565284b03f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565284b03f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565284b03f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565286d98f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565283ac5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565283ad0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56528387cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56528387cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56528387d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56528387c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56528387c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56528387c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565288186abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56528818f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565288177699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652881a2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd29922f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565281a9cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0x8d,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x97,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x87,0x8d,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x97,0x85,0xb0,0xf0,0x9d,0x85,0x8d,0xf0,0x9d,0x85,0xa0,0x3d,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0x8d,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x97,0x85,0xb0,0xf0,0x9d,0x85,0xb0,0xf0,0x9d,0x87,0x8d,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x9d,0x85,0xa0,0xf0,0x97,0x85,0xb0,0xf0,0x9d,0x85,0xa0,0xf0,0xa9,0x85,0xa0, Step #5: \360\235\205\240\360\235\205\240\360\235\205\240\360\235\205\215\360\235\205\240\360\235\205\240\360\227\205\260\360\235\205\260\360\235\207\215\360\235\205\240\360\235\205\240\360\235\205\240\360\227\205\260\360\235\205\215\360\235\205\240=\360\235\205\240\360\235\205\240\360\235\205\215\360\235\205\240\360\235\205\240\360\227\205\260\360\235\205\260\360\235\207\215\360\235\205\240\360\235\205\240\360\235\205\240\360\235\205\240\360\235\205\240\360\235\205\240\360\227\205\260\360\235\205\240\360\251\205\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-7145fcd889f842d0c9475edf85b2a2478cffdf36 Step #5: Base64: 8J2FoPCdhaDwnYWg8J2FjfCdhaDwnYWg8JeFsPCdhbDwnYeN8J2FoPCdhaDwnYWg8JeFsPCdhY3wnYWgPfCdhaDwnYWg8J2FjfCdhaDwnYWg8JeFsPCdhbDwnYeN8J2FoPCdhaDwnYWg8J2FoPCdhaDwnYWg8JeFsPCdhaDwqYWg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4386 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3916720642 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec1af08810, 0x55ec1b0f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec1b0f2020,0x55ec1cf8a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7145fcd889f842d0c9475edf85b2a2478cffdf36' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5484 processed earlier; will process 5545 files now Step #5: ==157972== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec119fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec18062898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec180455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec180454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec11a03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec11964b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec1195f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec119f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec149c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec149c4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec149c4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec149c4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec149c4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec149c4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec149c4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec149c4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec149c4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec149c4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec16c59f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec13986b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec13991be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec1373dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec1373dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec1373e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec1373d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec1373d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec1373d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec18047abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec18050928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec18038699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec18063112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fab74046082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec1195db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x44,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x48,0x48,0x48,0x48,0xa,0x3d,0xa,0x3d,0xa,0x80,0x0,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012D=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=?=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012HHHH\012=\012=\012\200\000=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-8e937b36fffc3edba500681a49c6b1da7e77c7e4 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KRD0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPT89Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQpISEhICj0KPQqAAD0KPQoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4387 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3917232127 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558cc745f810, 0x558cc764901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558cc7649020,0x558cc94e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8e937b36fffc3edba500681a49c6b1da7e77c7e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5485 processed earlier; will process 5544 files now Step #5: #1 pulse cov: 3560 ft: 3561 exec/s: 0 rss: 174Mb Step #5: ==158008== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558cbdf549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558cc45b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558cc459c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558cc459c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558cbdf5ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558cbdebbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558cbdeb6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558cbdf4cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558cc0f1bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558cc0f1bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558cc0f1bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558cc0f1bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558cc0f1bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558cc0f1bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558cc0f1bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558cc0f1bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558cc0f1bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558cc0f1bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558cc31b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558cbfeddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558cbfee8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558cbfc94c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558cbfc94c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558cbfc95738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558cbfc94874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558cbfc94874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558cbfc94874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558cc459eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558cc45a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558cc458f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558cc45ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fea6851d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558cbdeb4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x42,0x60,0x0,0xc2,0x85,0x7f,0x60,0x0,0xc2,0x85,0x7f,0x0,0x0,0x0,0x2c,0x0,0x1,0x66,0x0,0x60,0x0,0xc2,0x85,0x0,0x7f,0x0,0x0,0xc2,0x85,0x7f,0x0,0x0,0x60,0x4,0x6a,0x0,0x0,0xc2,0x85,0x7f,0x0,0x60,0x0,0xc2,0x85,0x0,0x7f,0x0,0xc2,0x86,0x42,0x42,0x42,0x42,0x3a,0x0,0x42,0x60,0x0,0xc2,0x85,0x7f,0x0,0x0,0x2c,0x0,0x60,0xc2,0x85,0x7f,0x0,0x0,0x0,0x2c,0x0,0x60,0xc2,0x85,0x7f,0x0,0x0,0x60,0x0,0xc2,0x85,0x0,0x7f,0x0,0xc2,0x86,0x42,0x42,0x42,0x42,0x5,0x0,0xc3,0xa8,0x3a,0x3d,0x0,0x42,0x60,0x0,0xc2,0x85,0x0,0x60,0xc2,0x85,0x40,0x0,0x0,0x0,0xc2,0x85,0x7f,0x3f,0x0,0x6a,0x4,0x4,0x60,0xc2,0x85,0x7f,0x0,0x0, Step #5: \000B`\000\302\205\177`\000\302\205\177\000\000\000,\000\001f\000`\000\302\205\000\177\000\000\302\205\177\000\000`\004j\000\000\302\205\177\000`\000\302\205\000\177\000\302\206BBBB:\000B`\000\302\205\177\000\000,\000`\302\205\177\000\000\000,\000`\302\205\177\000\000`\000\302\205\000\177\000\302\206BBBB\005\000\303\250:=\000B`\000\302\205\000`\302\205@\000\000\000\302\205\177?\000j\004\004`\302\205\177\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-78105596a458d07fff5cddcdb86248217d7ce51d Step #5: Base64: AEJgAMKFf2AAwoV/AAAALAABZgBgAMKFAH8AAMKFfwAAYARqAADChX8AYADChQB/AMKGQkJCQjoAQmAAwoV/AAAsAGDChX8AAAAsAGDChX8AAGAAwoUAfwDChkJCQkIFAMOoOj0AQmAAwoUAYMKFQAAAAMKFfz8AagQEYMKFfwAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4388 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3917892813 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56346cfc6810, 0x56346d1b001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56346d1b0020,0x56346f0480e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/78105596a458d07fff5cddcdb86248217d7ce51d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5487 processed earlier; will process 5542 files now Step #5: ==158044== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563463abb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56346a120898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56346a1035dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56346a1034fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563463ac1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563463a22b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563463a1d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563463ab3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563466a82f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563466a82f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563466a82f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563466a82f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563466a82f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563466a82f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563466a82f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563466a82f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563466a82f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563466a82f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563468d17f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563465a44b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563465a4fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5634657fbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5634657fbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5634657fc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5634657fb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5634657fb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5634657fb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56346a105abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56346a10e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56346a0f6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56346a121112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8afdbba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563463a1bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6b,0x69,0x73,0x73,0x6d,0x61,0x72,0x6b,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x49,0x44,0x33,0x2,0x0,0x0,0x3,0x0,0x0,0x0,0x47,0x45,0x4f,0x0,0x0,0x3,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0x0,0x49,0x44,0x33,0x2,0x0,0x0,0x3,0x0,0x0,0x0,0x47,0x45,0x4f,0x0,0x0,0x3,0x1,0x0,0x68,0x65,0x61,0x64,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0xa4,0x68,0x65,0x61,0x64,0x0,0x23,0x5b,0x28,0x62,0x0,0x5d,0xa4, Step #5: \000\000\000\000\000\000\000#[(b\000]\000\000\000\000\000\000\000\000kissmark\000\000\000#[(b\000]\000ID3\002\000\000\003\000\000\000GEO\000\000\003\001\000\000\000\000\000\000\000#[(b\000]\000\000\000\000\000\000\000\000\000\000\000#[(b\000]\000ID3\002\000\000\003\000\000\000GEO\000\000\003\001\000head\000#[(b\000]\244head\000#[(b\000]\244 Step #5: artifact_prefix='./'; Test unit written to ./oom-3ac51bee646d4e7fdf9d5076b8c0427d5d02ec63 Step #5: Base64: AAAAAAAAACNbKGIAXQAAAAAAAAAAa2lzc21hcmsAAAAjWyhiAF0ASUQzAgAAAwAAAEdFTwAAAwEAAAAAAAAAI1soYgBdAAAAAAAAAAAAAAAjWyhiAF0ASUQzAgAAAwAAAEdFTwAAAwEAaGVhZAAjWyhiAF2kaGVhZAAjWyhiAF2k Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4389 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3918398282 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a69d94810, 0x559a69f7e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a69f7e020,0x559a6be160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3ac51bee646d4e7fdf9d5076b8c0427d5d02ec63' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5488 processed earlier; will process 5541 files now Step #5: ==158080== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559a608899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a66eee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a66ed15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a66ed14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a6088fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a607f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a607eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a60881c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a63850f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a63850f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a63850f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a63850f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a63850f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a63850f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a63850f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a63850f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a63850f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a63850f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a65ae5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a62812b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a6281dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a625c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a625c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a625ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a625c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a625c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a625c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a66ed3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a66edc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a66ec4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a66eef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0305afe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a607e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xdb,0x80,0x38,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x30,0x20,0x32,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3f,0x0,0x8,0x0,0x0,0x0,0x39, Step #5: \333\200\333\2009\000*********************************************\333\2008\000*************************************\000\000\000\000\000\000\000\001\000\000\000\000\0000 2\000\000\000\000\000\000\000\000\000\000\000\000\000\000?\000\010\000\000\0009 Step #5: artifact_prefix='./'; Test unit written to ./oom-a13cf9ed118e1d9316c2b1052c323a70b7942ef3 Step #5: Base64: 24DbgDkAKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioq24A4ACoqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioAAAAAAAAAAQAAAAAAMCAyAAAAAAAAAAAAAAAAAAA/AAgAAAA5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4390 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3918903752 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d7b23f810, 0x564d7b42901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d7b429020,0x564d7d2c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a13cf9ed118e1d9316c2b1052c323a70b7942ef3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5489 processed earlier; will process 5540 files now Step #5: ==158116== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d71d349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d78399898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d7837c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d7837c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d71d3ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d71c9bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d71c96355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d71d2cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d74cfbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d74cfbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d74cfbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d74cfbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d74cfbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d74cfbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d74cfbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d74cfbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d74cfbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d74cfbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d76f90f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d73cbdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d73cc8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d73a74c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d73a74c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d73a75738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d73a74874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d73a74874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d73a74874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d7837eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d78387928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d7836f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d7839a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f13bdd8a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d71c94b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x50,0x4b,0x3,0x4,0x6,0x50,0x4b,0x1,0x2,0x0,0x4,0x6,0x50,0x4b,0xe2,0x81,0xa7,0x1,0x2,0x70,0xff,0xff,0xf9,0xf7,0xff,0x15,0x0,0x0,0x0,0x0,0x0,0x1a,0xb1,0x0,0x50,0x4b,0x3,0x4,0x6,0x50,0x6,0x0,0x24,0x24,0x24,0x50,0x4b,0x5,0x6,0x6,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xff,0xff,0x1,0x28,0xff,0xff,0xff,0xff,0xff,0xff,0x0,0x0,0x0,0x1a,0xb1,0x0,0x50,0x4b,0x3,0x4,0xff,0x88,0x2f,0x70,0x79,0xfa,0x4,0x6,0x50,0x4b,0x0,0x0,0x0,0x0,0xb4,0xfa,0xf9,0xf7,0xff,0xff,0x1,0x28,0x0,0x0,0x0,0x0,0x42,0x69,0x6e,0x44,0x61,0x74,0x61,0x3c,0x73,0x63,0xfd,0xff,0x1,0x0,0xfe,0x0,0x0,0x30,0x23,0x40,0x7e,0x5e,0x63,0xf9,0x7d, Step #5: PK\003\004\006PK\001\002\000\004\006PK\342\201\247\001\002p\377\377\371\367\377\025\000\000\000\000\000\032\261\000PK\003\004\006P\006\000$$$PK\005\006\006\014\014\014\014\014\014\014\014\377\377\001(\377\377\377\377\377\377\000\000\000\032\261\000PK\003\004\377\210/py\372\004\006PK\000\000\000\000\264\372\371\367\377\377\001(\000\000\000\000BinData<sc\375\377\001\000\376\000\0000#@~^c\371} Step #5: artifact_prefix='./'; Test unit written to ./oom-1477fd2cdd16edf56e203d7283c0d530140797c8 Step #5: Base64: UEsDBAZQSwECAAQGUEvigacBAnD///n3/xUAAAAAABqxAFBLAwQGUAYAJCQkUEsFBgYMDAwMDAwMDP//ASj///////8AAAAasQBQSwME/4gvcHn6BAZQSwAAAAC0+vn3//8BKAAAAABCaW5EYXRhPHNj/f8BAP4AADAjQH5eY/l9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4391 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3919399953 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a8c4fe810, 0x555a8c6e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a8c6e8020,0x555a8e5800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1477fd2cdd16edf56e203d7283c0d530140797c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5490 processed earlier; will process 5539 files now Step #5: ==158152== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555a82ff39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a89658898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a8963b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a8963b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a82ff9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a82f5ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a82f55355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a82febc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a85fbaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a85fbaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a85fbaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a85fbaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a85fbaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a85fbaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a85fbaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a85fbaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a85fbaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a85fbaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a8824ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a84f7cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a84f87be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a84d33c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a84d33c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a84d34738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a84d33874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a84d33874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a84d33874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a8963dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a89646928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a8962e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a89659112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa57babc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a82f53b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9f,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9e,0x5c,0x72,0xd6,0x9e, Step #5: \"\\r\326\237\\r\326\237\\r\326\236\\r\326\237\\r\326\237\\r\326\236\\r\326\237\\r\326\237\\r\326\236\\r\326\237\\r\326\237\\r\326\236\\r\326\236\\r\326\237\\r\326\237\\r\326\236\\r\326\237\\r\326\237\\r\326\236\\r\326\237\\r\326\237\\r\326\236\\r\326\236\\r\326\237\\r\326\236\\r\326\236\\r\326\236\\r\326\236\\r\326\236\\r\326\236\\r\326\236\\r\326\236 Step #5: artifact_prefix='./'; Test unit written to ./oom-aa147ea31997faf4f16d13fbdfb3fa42e9dec432 Step #5: Base64: Ilxy1p9cctafXHLWnlxy1p9cctafXHLWnlxy1p9cctafXHLWnlxy1p9cctafXHLWnlxy1p5cctafXHLWn1xy1p5cctafXHLWn1xy1p5cctafXHLWn1xy1p5cctaeXHLWn1xy1p5cctaeXHLWnlxy1p5cctaeXHLWnlxy1p5cctae Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4392 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3919906192 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cfb1ce1810, 0x55cfb1ecb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cfb1ecb020,0x55cfb3d630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aa147ea31997faf4f16d13fbdfb3fa42e9dec432' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5491 processed earlier; will process 5538 files now Step #5: #1 pulse cov: 10990 ft: 10991 exec/s: 0 rss: 202Mb Step #5: ==158188== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cfa87d69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cfaee3b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cfaee1e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cfaee1e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cfa87dcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cfa873db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cfa8738355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cfa87cec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cfab79df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cfab79df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cfab79df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cfab79df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cfab79df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cfab79df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cfab79df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cfab79df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cfab79df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cfab79df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cfada32f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cfaa75fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cfaa76abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cfaa516c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cfaa516c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cfaa517738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cfaa516874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cfaa516874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cfaa516874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cfaee20abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cfaee29928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cfaee11699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cfaee3c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ee0c39082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cfa8736b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x3b,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34, Step #5: {;44444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444 Step #5: artifact_prefix='./'; Test unit written to ./oom-6c388ab68e132552ac75f43cdba5a248a00eb5c7 Step #5: Base64: ezs0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4393 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3920580278 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559b9d2c9810, 0x559b9d4b301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559b9d4b3020,0x559b9f34b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6c388ab68e132552ac75f43cdba5a248a00eb5c7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5493 processed earlier; will process 5536 files now Step #5: ==158224== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559b93dbe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559b9a423898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559b9a4065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559b9a4064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b93dc4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b93d25b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b93d20355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b93db6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b96d85f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b96d85f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b96d85f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b96d85f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b96d85f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b96d85f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b96d85f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b96d85f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b96d85f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b96d85f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559b9901af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b95d47b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b95d52be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b95afec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b95afec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b95aff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b95afe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b95afe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b95afe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559b9a408abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559b9a411928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559b9a3f9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559b9a424112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fec5527a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b93d1eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x3e,0x3c,0xcd,0xbc,0x77,0x3e,0xa8,0x3c,0xcd,0xbc,0x3e, Step #5: <\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274><\315\274w>\250<\315\274> Step #5: artifact_prefix='./'; Test unit written to ./oom-4c721a2292752f7c7de5ee6af15ad3502434ac80 Step #5: Base64: PM28PjzNvD48zbw+PM28PjzNvD48zbw+PM28PjzNvD48zbw+PM28PjzNvD48zbw+PM28PjzNvD48zbw+PM28PjzNvD48zbw+PM28PjzNvD48zbw+PM28PjzNvD48zbw+PM28PjzNvD48zbw+PM28PjzNvD48zbw+PM28dz6oPM28Pg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4394 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3921070839 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5638316a5810, 0x56383188f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56383188f020,0x5638337270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4c721a2292752f7c7de5ee6af15ad3502434ac80' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5494 processed earlier; will process 5535 files now Step #5: ==158260== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56382819a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56382e7ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56382e7e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56382e7e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5638281a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563828101b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5638280fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563828192c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56382b161f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56382b161f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56382b161f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56382b161f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56382b161f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56382b161f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56382b161f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56382b161f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56382b161f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56382b161f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56382d3f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56382a123b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56382a12ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563829edac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563829edac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563829edb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563829eda874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563829eda874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563829eda874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56382e7e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56382e7ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56382e7d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56382e800112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe2d6ae8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5638280fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa,0x3f,0xa, Step #5: <\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012?\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7bee7d7dd0b9520c3bd45518c54b79f1eaa5985 Step #5: Base64: PAo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cj8KPwo/Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4395 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3921568421 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5596c6f42810, 0x5596c712c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596c712c020,0x5596c8fc40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7bee7d7dd0b9520c3bd45518c54b79f1eaa5985' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5495 processed earlier; will process 5534 files now Step #5: ==158296== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5596bda379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5596c409c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5596c407f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5596c407f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5596bda3dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5596bd99eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5596bd999355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5596bda2fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5596c09fef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5596c09fef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5596c09fef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5596c09fef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5596c09fef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5596c09fef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5596c09fef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5596c09fef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5596c09fef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5596c09fef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596c2c93f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5596bf9c0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5596bf9cbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5596bf777c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5596bf777c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5596bf778738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5596bf777874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5596bf777874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5596bf777874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5596c4081abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5596c408a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5596c4072699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5596c409d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6193163082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5596bd997b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x2a,0xcc,0xae,0x2e,0x2b,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x21,0xcc,0xb8,0x2e,0x2b,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x2a,0xcc,0x90,0x2e,0x21,0xcc,0xb8,0x2e,0x2b,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x21,0xcc,0xb8,0x2e,0x68,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x2b,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x2b,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x2b,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x2b,0xcc,0xb8,0x2e,0x29,0xcc,0xb8,0x2e,0x2b,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x2a,0xcc,0xb8,0x2e,0x29,0xcc,0xb8,0x2e,0x2a,0xcc,0xae,0x2e,0x2a,0xcc,0xb8, Step #5: ws:*\314\256.+\314\270.*\314\270.*\314\270.!\314\270.+\314\270.*\314\270.*\314\220.!\314\270.+\314\270.*\314\270.*\314\270.!\314\270.h\314\270.*\314\270.+\314\270.*\314\270.+\314\270.*\314\270.*\314\270.*\314\270.+\314\270.*\314\270.+\314\270.)\314\270.+\314\270.*\314\270.*\314\270.*\314\270.)\314\270.*\314\256.*\314\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-d46a50c508c739260e30eaea9a12f9ce7ed17b74 Step #5: Base64: d3M6KsyuLivMuC4qzLguKsy4LiHMuC4rzLguKsy4LirMkC4hzLguK8y4LirMuC4qzLguIcy4LmjMuC4qzLguK8y4LirMuC4rzLguKsy4LirMuC4qzLguK8y4LirMuC4rzLguKcy4LivMuC4qzLguKsy4LirMuC4pzLguKsyuLirMuA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4396 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3922067540 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55974d311810, 0x55974d4fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55974d4fb020,0x55974f3930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d46a50c508c739260e30eaea9a12f9ce7ed17b74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5496 processed earlier; will process 5533 files now Step #5: #1 pulse cov: 3567 ft: 3568 exec/s: 0 rss: 176Mb Step #5: ==158332== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559743e069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55974a46b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55974a44e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55974a44e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559743e0cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559743d6db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559743d68355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559743dfec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559746dcdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559746dcdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559746dcdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559746dcdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559746dcdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559746dcdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559746dcdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559746dcdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559746dcdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559746dcdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559749062f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559745d8fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559745d9abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559745b46c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559745b46c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559745b47738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559745b46874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559745b46874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559745b46874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55974a450abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55974a459928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55974a441699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55974a46c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f85bebe9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559743d66b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x9,0x7e,0xa,0x9,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0xa,0x5c, Step #5: +\012\011~\012\011~~~~~~OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO~~~~~~~~~~~\012\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-9b4e5ebbf2a0cbb917ca0007618616e9ea407b09 Step #5: Base64: KwoJfgoJfn5+fn5+T09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Pfn5+fn5+fn5+fn4KXA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4397 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3922611288 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563dfd1a4810, 0x563dfd38e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563dfd38e020,0x563dff2260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9b4e5ebbf2a0cbb917ca0007618616e9ea407b09' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5498 processed earlier; will process 5531 files now Step #5: ==158368== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563df3c999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563dfa2fe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563dfa2e15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563dfa2e14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563df3c9fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563df3c00b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563df3bfb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563df3c91c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563df6c60f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563df6c60f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563df6c60f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563df6c60f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563df6c60f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563df6c60f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563df6c60f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563df6c60f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563df6c60f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563df6c60f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563df8ef5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563df5c22b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563df5c2dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563df59d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563df59d9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563df59da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563df59d9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563df59d9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563df59d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563dfa2e3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563dfa2ec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563dfa2d4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563dfa2ff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffb273be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563df3bf9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5b,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x7d,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x89,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x7d,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x89,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8,0x5b,0xe2,0x81,0xa8, Step #5: [[[\342\201\250[\342\201\250}\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\211\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250}\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\211\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250[\342\201\250 Step #5: artifact_prefix='./'; Test unit written to ./oom-98bcbfe021eba8340794c0e10d3c076e77a67200 Step #5: Base64: W1tb4oGoW+KBqH3igahb4oGoW+KBqFvigahb4oGoW+KJqFvigahb4oGoW+KBqFvigahb4oGoW+KBqH3igahb4oGoW+KBqFvigahb4oGoW+KJqFvigahb4oGoW+KBqFvigahb4oGoW+KBqFvigahb4oGoW+KBqFvigahb4oGoW+KBqA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4398 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3923112361 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5602c6ddb810, 0x5602c6fc501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5602c6fc5020,0x5602c8e5d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/98bcbfe021eba8340794c0e10d3c076e77a67200' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5499 processed earlier; will process 5530 files now Step #5: ==158404== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5602bd8d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5602c3f35898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602c3f185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602c3f184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5602bd8d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5602bd837b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5602bd832355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5602bd8c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5602c0897f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5602c0897f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5602c0897f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5602c0897f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5602c0897f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5602c0897f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5602c0897f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5602c0897f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5602c0897f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5602c0897f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5602c2b2cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5602bf859b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5602bf864be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5602bf610c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5602bf610c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5602bf611738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5602bf610874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5602bf610874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5602bf610874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5602c3f1aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5602c3f23928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5602c3f0b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5602c3f36112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f84d43ed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5602bd830b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd8,0x8a,0xd8,0x8b,0xd8,0x8b,0xca,0x9b,0xd8,0x8b,0xd8,0x8b,0xd8,0x8b,0xdf,0x8c,0xd8,0x8b,0xd9,0x8a,0xd8,0x83,0xd8,0x8a,0xd8,0x8b,0xd8,0x8b,0xd8,0x8a,0xef,0xa3,0xbf,0xd8,0x8b,0x25,0xd8,0x8b,0xd8,0x9b,0xd8,0x8b,0xd8,0x83,0xd5,0x92,0xd7,0x82,0xd8,0x8b,0xca,0x9b,0xd8,0x8b,0xd8,0x8b,0xd8,0x8b,0xdf,0x8c,0xd8,0x8b,0xd9,0x8a,0xd8,0x83,0xd8,0x8a,0xd8,0x8b,0xd8,0x8b,0xd8,0x8a,0xef,0xa3,0xbf,0xd8,0x8b,0x25,0xd8,0x8b,0xd8,0x8a,0xd8,0x8c,0xd8,0x9f,0xd8,0x8c,0xd8,0x8b,0xd8,0x9b,0xd8,0x8b,0xd8,0x83,0xd5,0x92,0xd7,0x82,0xd8,0x8b,0xca,0x9b,0xd8,0x8b,0xd8,0x8b,0xd8,0x8b,0xdf,0x8c,0xd8,0x8b,0xd9,0x8a,0xd8,0x83,0xd8,0x8a,0xda,0x8b,0x30,0xd8,0x8b,0xd9,0x8b,0x81, Step #5: \330\212\330\213\330\213\312\233\330\213\330\213\330\213\337\214\330\213\331\212\330\203\330\212\330\213\330\213\330\212\357\243\277\330\213%\330\213\330\233\330\213\330\203\325\222\327\202\330\213\312\233\330\213\330\213\330\213\337\214\330\213\331\212\330\203\330\212\330\213\330\213\330\212\357\243\277\330\213%\330\213\330\212\330\214\330\237\330\214\330\213\330\233\330\213\330\203\325\222\327\202\330\213\312\233\330\213\330\213\330\213\337\214\330\213\331\212\330\203\330\212\332\2130\330\213\331\213\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-9af0a38d7af3d5fb34451af385d8a12fc8c607fd Step #5: Base64: 2IrYi9iLypvYi9iL2IvfjNiL2YrYg9iK2IvYi9iK76O/2Isl2IvYm9iL2IPVkteC2IvKm9iL2IvYi9+M2IvZitiD2IrYi9iL2Irvo7/YiyXYi9iK2IzYn9iM2IvYm9iL2IPVkteC2IvKm9iL2IvYi9+M2IvZitiD2IraizDYi9mLgQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4399 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3923617535 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8c1cb7810, 0x55c8c1ea101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c8c1ea1020,0x55c8c3d390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9af0a38d7af3d5fb34451af385d8a12fc8c607fd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5500 processed earlier; will process 5529 files now Step #5: ==158440== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c8b87ac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8bee11898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8bedf45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8bedf44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c8b87b2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c8b8713b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c8b870e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c8b87a4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c8bb773f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c8bb773f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c8bb773f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c8bb773f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c8bb773f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c8bb773f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c8bb773f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c8bb773f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c8bb773f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c8bb773f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c8bda08f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c8ba735b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c8ba740be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c8ba4ecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c8ba4ecc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c8ba4ed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c8ba4ec874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c8ba4ec874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c8ba4ec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8bedf6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8bedff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8bede7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8bee12112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feae2720082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c8b870cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x40,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x81,0xa6,0x75,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x44,0x11,0x2f,0x0,0x44,0x11,0x24, Step #5: \000$\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000@\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\342\201\246u\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000D\021/\000D\021$ Step #5: artifact_prefix='./'; Test unit written to ./oom-4c354d893411454200d9bdc6dda14e1462ea5ec6 Step #5: Base64: ACQAAAAAAAAAAAAAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOKBpnUAAAAAAAAAAAAAAAAAAAAAAAAAAAAARBEvAEQRJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4400 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3924126568 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558dd38b9810, 0x558dd3aa301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558dd3aa3020,0x558dd593b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4c354d893411454200d9bdc6dda14e1462ea5ec6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5501 processed earlier; will process 5528 files now Step #5: ==158476== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558dca3ae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558dd0a13898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558dd09f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558dd09f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558dca3b4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558dca315b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558dca310355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558dca3a6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558dcd375f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558dcd375f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558dcd375f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558dcd375f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558dcd375f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558dcd375f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558dcd375f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558dcd375f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558dcd375f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558dcd375f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558dcf60af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558dcc337b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558dcc342be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558dcc0eec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558dcc0eec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558dcc0ef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558dcc0ee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558dcc0ee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558dcc0ee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558dd09f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558dd0a01928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558dd09e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558dd0a14112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f32913f5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558dca30eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbc,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbc,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0x88,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf,0xef,0xbb,0xbf, Step #5: \"\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\274\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\274\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\210\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277\357\273\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-d62f7277039b5d48a03d108ee4d12355e06d84e8 Step #5: Base64: Iu+7v++7v++7v++7v++7v++7v++8v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++8v++7v++7v++7v++7v++7v++7iO+7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7v++7vw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4401 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3924632835 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d65cc1f810, 0x55d65ce0901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d65ce09020,0x55d65eca10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d62f7277039b5d48a03d108ee4d12355e06d84e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5502 processed earlier; will process 5527 files now Step #5: ==158512== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d6537149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d659d79898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d659d5c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d659d5c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d65371ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d65367bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d653676355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d65370cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d6566dbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d6566dbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d6566dbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d6566dbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d6566dbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d6566dbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d6566dbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d6566dbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d6566dbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d6566dbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d658970f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d65569db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d6556a8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d655454c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d655454c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d655455738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d655454874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d655454874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d655454874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d659d5eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d659d67928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d659d4f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d659d7a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa271dc3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d653674b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7a,0x7b,0x22,0x72,0x65,0x73,0x6f,0x75,0x72,0x63,0x65,0x4d,0x65,0x74,0x72,0x69,0x63,0x73,0x22,0x5b,0x5b,0x4e,0x7b,0x22,0x22,0x73,0x63,0x6f,0x70,0x65,0x5f,0x6d,0x65,0x74,0x72,0x69,0x63,0x73,0x22,0x5b,0x5b,0x4e,0x7b,0x22,0x22,0x6d,0x65,0x74,0x72,0x69,0x63,0x73,0x22,0x5b,0x5b,0x4e,0x7b,0x22,0x22,0x68,0x69,0x73,0x74,0x6f,0x67,0x72,0x61,0x6d,0x22,0x2c,0x7b,0x22,0x22,0x64,0x61,0x74,0x61,0x50,0x6f,0x69,0x6e,0x74,0x73,0x22,0x30,0x5b,0x4e,0x7b,0x22,0x22,0x6e,0x74,0x22,0x3e,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0x32,0x39,0x35,0x2c,0x22,0x65,0x78,0x70,0x6c,0x69,0x63,0x97,0x8b,0xc8,0xb8,0x6f,0x6e,0x64,0x73,0x22,0x3e,0x33,0x37,0x30,0x30,0x30,0xd0,0xcf,0xcf, Step #5: z{\"resourceMetrics\"[[N{\"\"scope_metrics\"[[N{\"\"metrics\"[[N{\"\"histogram\",{\"\"dataPoints\"0[N{\"\"nt\">4294967295,\"explic\227\213\310\270onds\">37000\320\317\317 Step #5: artifact_prefix='./'; Test unit written to ./oom-9bc463ecea9eb29cb88a08645391ad539443a6dc Step #5: Base64: ensicmVzb3VyY2VNZXRyaWNzIltbTnsiInNjb3BlX21ldHJpY3MiW1tOeyIibWV0cmljcyJbW057IiJoaXN0b2dyYW0iLHsiImRhdGFQb2ludHMiMFtOeyIibnQiPjQyOTQ5NjcyOTUsImV4cGxpY5eLyLhvbmRzIj4zNzAwMNDPzw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4402 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3925142042 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563230bf0810, 0x563230dda01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563230dda020,0x563232c720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9bc463ecea9eb29cb88a08645391ad539443a6dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5503 processed earlier; will process 5526 files now Step #5: ==158548== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5632276e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56322dd4a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56322dd2d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56322dd2d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5632276ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56322764cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563227647355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5632276ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56322a6acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56322a6acf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56322a6acf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56322a6acf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56322a6acf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56322a6acf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56322a6acf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56322a6acf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56322a6acf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56322a6acf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56322c941f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56322966eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563229679be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563229425c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563229425c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563229426738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563229425874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563229425874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563229425874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56322dd2fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56322dd38928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56322dd20699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56322dd4b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe08b4bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563227645b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2e,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3b,0x0,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x2a,0x2a,0xd7,0xa9,0x28,0x2e,0x2e,0x1,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x30,0x2e,0x2e,0x2e,0x2e,0x30,0x0,0x0,0x43,0x43,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x22,0x31,0x8,0x2a,0x2a,0xd7,0xa9,0x28,0x2e,0x2e,0x1,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x30,0x2e,0x2e,0x2e,0x2e,0x30,0x0,0x0,0x43,0x43,0x9,0x1,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x4,0x2b,0x33,0x35,0x38,0x38,0x38,0x2e, Step #5: /.7777777777777\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000;\000\012\000\000\000\000\000\000**\327\251(..\001........0....0\000\000CC****************\000\"1\010**\327\251(..\001........0....0\000\000CC\011\001777777777\004+35888. Step #5: artifact_prefix='./'; Test unit written to ./oom-e50732f961db01c194c45f85678861d6667c348f Step #5: Base64: Ly43Nzc3Nzc3Nzc3Nzc3AAAAAAAAAAAAAAAAAAAAOwAKAAAAAAAAKirXqSguLgEuLi4uLi4uLjAuLi4uMAAAQ0MqKioqKioqKioqKioqKioqACIxCCoq16koLi4BLi4uLi4uLi4wLi4uLjAAAENDCQE3Nzc3Nzc3NzcEKzM1ODg4Lg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4403 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3925646385 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a693220810, 0x55a69340a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a69340a020,0x55a6952a20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e50732f961db01c194c45f85678861d6667c348f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5504 processed earlier; will process 5525 files now Step #5: ==158584== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a689d159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a69037a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a69035d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a69035d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a689d1bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a689c7cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a689c77355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a689d0dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a68ccdcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a68ccdcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a68ccdcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a68ccdcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a68ccdcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a68ccdcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a68ccdcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a68ccdcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a68ccdcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a68ccdcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a68ef71f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a68bc9eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a68bca9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a68ba55c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a68ba55c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a68ba56738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a68ba55874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a68ba55874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a68ba55874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a69035fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a690368928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a690350699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a69037b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b252eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a689c75b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x65,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3d,0x22,0x63,0x68,0x61,0x72,0x22,0x0,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0x6f,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0x6f,0x64,0xe0,0xb9,0x81,0x68,0x72,0x22,0x0,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0x6f,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0x6f,0x64,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0x2b,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0xe0,0xb9,0x81,0x2b,0xe0,0xb9,0x81, Step #5: <?xml encoding=\"char\"\000\340\271\201\340\271\201o\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201od\340\271\201hr\"\000\340\271\201\340\271\201o\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201od\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201+\340\271\201\340\271\201\340\271\201\340\271\201\340\271\201+\340\271\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-15a06809571db893f3285adf1302140fd0a2bb7d Step #5: Base64: PD94bWwgZW5jb2Rpbmc9ImNoYXIiAOC5geC5gW/guYHguYHguYHguYHguYHguYHguYHguYFvZOC5gWhyIgDguYHguYFv4LmB4LmB4LmB4LmB4LmB4LmB4LmB4LmBb2TguYHguYHguYHguYHguYEr4LmB4LmB4LmB4LmB4LmBK+C5gQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4404 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3926163141 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56535ee5b810, 0x56535f04501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56535f045020,0x565360edd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/15a06809571db893f3285adf1302140fd0a2bb7d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5505 processed earlier; will process 5524 files now Step #5: ==158620== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5653559509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56535bfb5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56535bf985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56535bf984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565355956d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5653558b7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5653558b2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565355948c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565358917f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565358917f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565358917f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565358917f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565358917f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565358917f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565358917f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565358917f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565358917f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565358917f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56535abacf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5653578d9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5653578e4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565357690c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565357690c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565357691738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565357690874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565357690874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565357690874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56535bf9aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56535bfa3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56535bf8b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56535bfb6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd380d8c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5653558b0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x40,0x0,0x0,0x0,0x71,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x81,0xa6,0x75,0x0,0x0,0x0,0x0,0x0,0x65,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x0,0x0,0x0,0x0,0x44,0x11,0x2f,0x0,0x44,0x11,0x24, Step #5: \000$\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000@\000\000\000q\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000*\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\342\201\246u\000\000\000\000\000e\000\000\000\000\000\000\000\000\000\000\000\020\000\000\000\000D\021/\000D\021$ Step #5: artifact_prefix='./'; Test unit written to ./oom-273e03e4c13df97920e5e5dd6ab34ee8acedb086 Step #5: Base64: ACQAAAAAAAAAAAAAAAAAAAAAAAAAAEAAAABxAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAqAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADigaZ1AAAAAABlAAAAAAAAAAAAAAAQAAAAAEQRLwBEESQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4405 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3926668137 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d334bb2810, 0x55d334d9c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d334d9c020,0x55d336c340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/273e03e4c13df97920e5e5dd6ab34ee8acedb086' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5506 processed earlier; will process 5523 files now Step #5: ==158656== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d32b6a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d331d0c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d331cef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d331cef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d32b6add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d32b60eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d32b609355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d32b69fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d32e66ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d32e66ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d32e66ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d32e66ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d32e66ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d32e66ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d32e66ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d32e66ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d32e66ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d32e66ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d330903f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d32d630b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d32d63bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d32d3e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d32d3e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d32d3e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d32d3e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d32d3e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d32d3e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d331cf1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d331cfa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d331ce2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d331d0d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f298d631082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d32b607b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0x2d,0x3d,0x0,0x24, Step #5: ~$-\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000=-=\000$ Step #5: artifact_prefix='./'; Test unit written to ./oom-86f9d353e217f489d9df6609e58d87ef513b7bf0 Step #5: Base64: fiQtAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPS09ACQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4406 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3927175111 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ccd2007810, 0x55ccd21f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ccd21f1020,0x55ccd40890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/86f9d353e217f489d9df6609e58d87ef513b7bf0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5507 processed earlier; will process 5522 files now Step #5: ==158692== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ccc8afc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cccf161898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cccf1445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cccf1444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ccc8b02d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ccc8a63b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ccc8a5e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ccc8af4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cccbac3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cccbac3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cccbac3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cccbac3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cccbac3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cccbac3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cccbac3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cccbac3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cccbac3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cccbac3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cccdd58f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cccaa85b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cccaa90be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ccca83cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ccca83cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ccca83d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ccca83c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ccca83c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ccca83c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cccf146abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cccf14f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cccf137699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cccf162112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0e1cc41082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ccc8a5cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0xa,0x2d,0x6d,0x2d,0x2d,0x2d,0x42,0x45,0x0,0x27,0x0,0x60,0x27,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x38,0x30,0x38,0x35,0x34,0x37,0x37,0x35,0x38,0x30,0x36,0x54,0x59,0x59,0x45,0x33,0x4,0x27,0x0,0x0,0x60,0x27,0x54,0x17,0x59,0x45,0x3f,0x42,0x0,0xf3,0xa0,0x81,0x99,0x63,0xf3,0xa0,0x81,0x99,0x63,0xf3,0xa0,0xa0,0x81,0x99,0x63,0xf3,0xa0,0x81,0x0,0x0,0x0,0x15,0x0,0x10,0x15,0x0,0x10,0x47,0x49,0x4e,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x0,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20, Step #5: -----BEGIN \012-m---BE\000'\000`'922337203685477580854775806TYYE3\004'\000\000`'T\027YE?B\000\363\240\201\231c\363\240\201\231c\363\240\240\201\231c\363\240\201\000\000\000\025\000\020\025\000\020GIN \012-----BEGIN\000\012----------BEGIN Step #5: artifact_prefix='./'; Test unit written to ./oom-962b6505a53638ca97e6104af0ba2091a6a46f50 Step #5: Base64: IC0tLS0tQkVHSU4gCi1tLS0tQkUAJwBgJzkyMjMzNzIwMzY4NTQ3NzU4MDg1NDc3NTgwNlRZWUUzBCcAAGAnVBdZRT9CAPOggZlj86CBmWPzoKCBmWPzoIEAAAAVABAVABBHSU4gCi0tLS0tQkVHSU4ACi0tLS0tLS0tLS1CRUdJTiA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4407 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3927800731 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d4ec386810, 0x55d4ec57001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d4ec570020,0x55d4ee4080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/962b6505a53638ca97e6104af0ba2091a6a46f50' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5508 processed earlier; will process 5521 files now Step #5: ==158728== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d4e2e7b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d4e94e0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d4e94c35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d4e94c34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d4e2e81d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d4e2de2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d4e2ddd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d4e2e73c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d4e5e42f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d4e5e42f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d4e5e42f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d4e5e42f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d4e5e42f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d4e5e42f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d4e5e42f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d4e5e42f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d4e5e42f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d4e5e42f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d4e80d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d4e4e04b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d4e4e0fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d4e4bbbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d4e4bbbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d4e4bbc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d4e4bbb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d4e4bbb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d4e4bbb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d4e94c5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d4e94ce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d4e94b6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d4e94e1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6cca699082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d4e2ddbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x29,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x22,0x8,0x2a,0x31,0x2a,0xd7,0xa9,0x28,0x2e,0x2e,0x1,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x30,0xfa,0x2e,0x2e,0x2e,0x30,0x9,0x37,0x1,0x43,0x48,0x43,0x0,0x0,0x0,0x50,0x8,0xd,0x0,0x0,0x0,0x1f,0x2e,0x74,0xe6,0x0,0x74,0xe6,0x0,0x9,0x78,0x5d, Step #5: ID3\004*******************\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037)\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037********\000\"\010*1*\327\251(..\001........0\372...0\0117\001CHC\000\000\000P\010\015\000\000\000\037.t\346\000t\346\000\011x] Step #5: artifact_prefix='./'; Test unit written to ./oom-44579175140e4adec79a079089ec9b399d747a3a Step #5: Base64: SUQzBCoqKioqKioqKioqKioqKioqKiofHx8fHx8fHx8fHx8fHx8fHx8pHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8qKioqKioqKgAiCCoxKtepKC4uAS4uLi4uLi4uMPouLi4wCTcBQ0hDAAAAUAgNAAAAHy505gB05gAJeF0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4408 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3928313689 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b5b6de9810, 0x55b5b6fd301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b5b6fd3020,0x55b5b8e6b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/44579175140e4adec79a079089ec9b399d747a3a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5509 processed earlier; will process 5520 files now Step #5: ==158764== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b5ad8de9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b5b3f43898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b5b3f265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b5b3f264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b5ad8e4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b5ad845b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b5ad840355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b5ad8d6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b5b08a5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b5b08a5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b5b08a5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b5b08a5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b5b08a5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b5b08a5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b5b08a5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b5b08a5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b5b08a5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b5b08a5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b5b2b3af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b5af867b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b5af872be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b5af61ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b5af61ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b5af61f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b5af61e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b5af61e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b5af61e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b5b3f28abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b5b3f31928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b5b3f19699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b5b3f44112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f69152ed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b5ad83eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0x32,0x32,0x32,0x32,0x21,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x7a,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x21,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x36,0x32,0x32,0x36,0x2a,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x23,0x32,0x32,0x32,0x32,0x32,0x32,0x30,0x30,0x32,0x30,0x32,0x30,0x30,0x32,0x30,0x30,0x30,0x30,0x3f,0x30,0x30,0x30,0x30,0x31,0x37,0x38,0x31,0x32,0x31,0x35,0x9,0x32, Step #5: 22222!222222222222222222222222222z222222222222222222!222222222226226*22222222222222222222222222222#222222002020020000?00001781215\0112 Step #5: artifact_prefix='./'; Test unit written to ./oom-6fed55faf0d91230966c9effa142fb091fb99ee1 Step #5: Base64: MjIyMjIhMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyejIyMjIyMjIyMjIyMjIyMjIyMiEyMjIyMjIyMjIyMjYyMjYqMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIjMjIyMjIyMDAyMDIwMDIwMDAwPzAwMDAxNzgxMjE1CTI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4409 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3928830009 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571e816c810, 0x5571e835601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571e8356020,0x5571ea1ee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6fed55faf0d91230966c9effa142fb091fb99ee1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5510 processed earlier; will process 5519 files now Step #5: ==158800== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571dec619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571e52c6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571e52a95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571e52a94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571dec67d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571debc8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571debc3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571dec59c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571e1c28f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571e1c28f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571e1c28f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571e1c28f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571e1c28f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571e1c28f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571e1c28f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571e1c28f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571e1c28f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571e1c28f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571e3ebdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571e0beab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571e0bf5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571e09a1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571e09a1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571e09a2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571e09a1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571e09a1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571e09a1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571e52ababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571e52b4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571e529c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571e52c7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fccbf8c1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571debc1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x2d,0x3a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x5b, Step #5: $-:\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\020'\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-12c927736e4ffbef1c2f9ec91ec6310d64cba953 Step #5: Base64: JC06AAAAAAAAAAAAAAAAAAAAAAAAAAAQJwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4410 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3929353184 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56355ed52810, 0x56355ef3c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56355ef3c020,0x563560dd40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/12c927736e4ffbef1c2f9ec91ec6310d64cba953' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5511 processed earlier; will process 5518 files now Step #5: ==158836== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5635558479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56355beac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56355be8f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56355be8f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56355584dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5635557aeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5635557a9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56355583fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56355880ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56355880ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56355880ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56355880ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56355880ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56355880ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56355880ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56355880ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56355880ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56355880ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56355aaa3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5635577d0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5635577dbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563557587c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563557587c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563557588738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563557587874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563557587874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563557587874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56355be91abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56355be9a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56355be82699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56355bead112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9809c6c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5635557a7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x2d,0x32,0x35,0x35,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x2d,0x36,0x35,0x35,0x33,0x36,0x45,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x45,0x15,0x0,0x10,0x15,0x0,0x10,0x49,0x44,0x2d,0x32,0x35,0x35,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x2d,0x30,0x45,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x45,0x15,0x0,0x10,0x15,0x0,0x10,0x49,0x44,0x2d,0x32,0x35,0x35,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x2d,0x39,0x32,0x32,0x36,0x39,0x36,0x38,0x33,0x38,0x38,0x39,0x31,0x37,0x34,0x36,0x37,0x33,0x38,0x39,0x35,0x33,0x31,0x37,0x31,0x30,0x33,0x45,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x45,0x15,0x0,0x10,0x15,0x0,0x10, Step #5: ID-255\004'\000\000`'\027TY-65536E\004'\000\000`'\027TYE\025\000\020\025\000\020ID-255\004'\000\000`'\027TY-0E\004'\000\000`'\027TYE\025\000\020\025\000\020ID-255\004'\000\000`'\027TY-92269683889174673895317103E\004'\000\000`'\027TYE\025\000\020\025\000\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-f908e322f1cafdaf7257c8050baddc1500401afd Step #5: Base64: SUQtMjU1BCcAAGAnF1RZLTY1NTM2RQQnAABgJxdUWUUVABAVABBJRC0yNTUEJwAAYCcXVFktMEUEJwAAYCcXVFlFFQAQFQAQSUQtMjU1BCcAAGAnF1RZLTkyMjY5NjgzODg5MTc0NjczODk1MzE3MTAzRQQnAABgJxdUWUUVABAVABA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4411 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3929981869 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56219ea11810, 0x56219ebfb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56219ebfb020,0x5621a0a930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f908e322f1cafdaf7257c8050baddc1500401afd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5512 processed earlier; will process 5517 files now Step #5: #1 pulse cov: 3995 ft: 3996 exec/s: 0 rss: 177Mb Step #5: ==158872== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5621955069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56219bb6b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56219bb4e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56219bb4e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56219550cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56219546db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562195468355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5621954fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5621984cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5621984cdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5621984cdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5621984cdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5621984cdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5621984cdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5621984cdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5621984cdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5621984cdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5621984cdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56219a762f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56219748fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56219749abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562197246c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562197246c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562197247738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562197246874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562197246874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562197246874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56219bb50abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56219bb59928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56219bb41699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56219bb6c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd05bda9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562195466b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x24,0x75,0xef,0xbc,0x8f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xdb,0x80,0x1,0x0,0x0,0x38,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x0,0x0,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x44,0x11,0xf3,0xa0,0x80,0xb3,0x27,0x0,0x44,0x1,0x24,0x0,0x0,0x0,0x0,0x0,0xdb,0x80,0x1,0x0,0x0,0x38,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x0,0x0,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x44,0x11,0xf3,0xa0,0x80,0xb3,0x27,0x0,0x44, Step #5: \000$u\357\274\217\000\000\000\000\000\000\000\000\333\200\001\000\000834028236692093846346\000\000\000\000\342\200\256\000\000\000\000\000\000\000\000\000\000\000\000\000D\021\363\240\200\263'\000D\001$\000\000\000\000\000\333\200\001\000\000834028236692093846346\000\000\000\000\342\200\256\000\000\000\000\000\000\000\000\000\000\000\000\000D\021\363\240\200\263'\000D Step #5: artifact_prefix='./'; Test unit written to ./oom-71579064f3d807870e86890610037ba9b559804e Step #5: Base64: ACR177yPAAAAAAAAAADbgAEAADgzNDAyODIzNjY5MjA5Mzg0NjM0NgAAAADigK4AAAAAAAAAAAAAAAAARBHzoICzJwBEASQAAAAAANuAAQAAODM0MDI4MjM2NjkyMDkzODQ2MzQ2AAAAAOKArgAAAAAAAAAAAAAAAABEEfOggLMnAEQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4412 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3930533728 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d2c68ae810, 0x55d2c6a9801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d2c6a98020,0x55d2c89300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/71579064f3d807870e86890610037ba9b559804e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5514 processed earlier; will process 5515 files now Step #5: ==158908== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d2bd3a39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d2c3a08898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d2c39eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d2c39eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d2bd3a9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d2bd30ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d2bd305355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d2bd39bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d2c036af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d2c036af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d2c036af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d2c036af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d2c036af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d2c036af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d2c036af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d2c036af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d2c036af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d2c036af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d2c25fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d2bf32cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d2bf337be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d2bf0e3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d2bf0e3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d2bf0e4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d2bf0e3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d2bf0e3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d2bf0e3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d2c39edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d2c39f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d2c39de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d2c3a09112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f64ef233082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d2bd303b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x40,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x98,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0x22, Step #5: \"\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270@\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\230\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\" Step #5: artifact_prefix='./'; Test unit written to ./oom-d692ada76bc0b9bc22f0623bf8a575d3bff07a8f Step #5: Base64: Iu+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4QO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4mO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iCI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4413 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3931033200 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56223e256810, 0x56223e44001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56223e440020,0x5622402d80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d692ada76bc0b9bc22f0623bf8a575d3bff07a8f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5515 processed earlier; will process 5514 files now Step #5: ==158944== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562234d4b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56223b3b0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56223b3935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56223b3934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562234d51d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562234cb2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562234cad355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562234d43c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562237d12f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562237d12f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562237d12f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562237d12f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562237d12f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562237d12f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562237d12f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562237d12f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562237d12f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562237d12f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562239fa7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562236cd4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562236cdfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562236a8bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562236a8bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562236a8c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562236a8b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562236a8b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562236a8b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56223b395abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56223b39e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56223b386699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56223b3b1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f91a26d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562234cabb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xf3,0xa0,0x80,0xaf,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xe2,0x80,0xa9,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xe2,0x80,0xa9,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xb, Step #5: \012\012\012\012\012\012\012\012\012\012\012\363\240\200\257\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\342\200\251\012\012\012\012\012\012\012\012\012\012\012\012\012\342\200\251\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-fde89cf21676c809f522cb3c3cc97e29f48d9426 Step #5: Base64: CgoKCgoKCgoKCgrzoICvCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoK4oCpCgoKCgoKCgoKCgoKCuKAqQoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4414 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3931532731 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf8a868810, 0x55bf8aa5201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf8aa52020,0x55bf8c8ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fde89cf21676c809f522cb3c3cc97e29f48d9426' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5516 processed earlier; will process 5513 files now Step #5: ==158980== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bf8135d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf879c2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf879a55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf879a54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf81363d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf812c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf812bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf81355c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf84324f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf84324f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf84324f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf84324f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf84324f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf84324f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf84324f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf84324f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf84324f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf84324f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf865b9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf832e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf832f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf8309dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf8309dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf8309e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf8309d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf8309d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf8309d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf879a7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf879b0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf87998699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf879c3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff42c6ab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf812bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x98,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0x8c,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0x22, Step #5: \"\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\230\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\214\210\357\270\210\357\270\210\" Step #5: artifact_prefix='./'; Test unit written to ./oom-c19c135717a180b5e01a2ba3a9968643d2e4a803 Step #5: Base64: Iu+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4mO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+MiO+4iO+4iCI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4415 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3932034412 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4611aa810, 0x55e46139401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e461394020,0x55e46322c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c19c135717a180b5e01a2ba3a9968643d2e4a803' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5517 processed earlier; will process 5512 files now Step #5: ==159016== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e457c9f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e45e304898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e45e2e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e45e2e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e457ca5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e457c06b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e457c01355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e457c97c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e45ac66f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e45ac66f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e45ac66f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e45ac66f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e45ac66f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e45ac66f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e45ac66f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e45ac66f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e45ac66f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e45ac66f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e45cefbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e459c28b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e459c33be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4599dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4599dfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4599e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4599df874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4599df874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4599df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e45e2e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e45e2f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e45e2da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e45e305112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff1e627c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e457bffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x1f,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x22,0x31,0x8,0x2a,0x2a,0xd7,0xa9,0x28,0x2e,0x2e,0x1,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x30,0x2e,0x2e,0x2e,0x2e,0x30,0x9,0x37,0x1,0x43,0x48,0x43,0x0,0x0,0x0,0x50,0x8,0xd,0x0,0x0,0x0,0x1f,0x2e,0x74,0xe6,0x0,0x9,0x78,0x5d, Step #5: ID3\004*******************\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037\037***********\000\"1\010**\327\251(..\001........0....0\0117\001CHC\000\000\000P\010\015\000\000\000\037.t\346\000\011x] Step #5: artifact_prefix='./'; Test unit written to ./oom-d830d3350c88dd63a88cbabcf22d58104492226a Step #5: Base64: SUQzBCoqKioqKioqKioqKioqKioqKiofHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8qKioqKioqKioqKgAiMQgqKtepKC4uAS4uLi4uLi4uMC4uLi4wCTcBQ0hDAAAAUAgNAAAAHy505gAJeF0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4416 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3932543968 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5622b180a810, 0x5622b19f401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622b19f4020,0x5622b388c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d830d3350c88dd63a88cbabcf22d58104492226a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5518 processed earlier; will process 5511 files now Step #5: ==159052== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5622a82ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5622ae964898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5622ae9475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5622ae9474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5622a8305d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5622a8266b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5622a8261355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5622a82f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5622ab2c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5622ab2c6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5622ab2c6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5622ab2c6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5622ab2c6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5622ab2c6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5622ab2c6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5622ab2c6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5622ab2c6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5622ab2c6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5622ad55bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5622aa288b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5622aa293be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5622aa03fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5622aa03fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5622aa040738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5622aa03f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5622aa03f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5622aa03f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5622ae949abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5622ae952928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5622ae93a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5622ae965112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f50a3b88082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5622a825fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xbb,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x98,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0x8c,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0x22, Step #5: \"\357\270\210\357\270\210\357\270\210\357\273\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\230\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\214\210\357\270\210\357\270\210\" Step #5: artifact_prefix='./'; Test unit written to ./oom-6a0c24754289f24b79414f70a6b108b4f2407233 Step #5: Base64: Iu+4iO+4iO+4iO+7iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4mO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+MiO+4iO+4iCI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4417 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3933047220 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564e408a7810, 0x564e40a9101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564e40a91020,0x564e429290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a0c24754289f24b79414f70a6b108b4f2407233' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5519 processed earlier; will process 5510 files now Step #5: ==159088== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564e3739c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564e3da01898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564e3d9e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564e3d9e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564e373a2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564e37303b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564e372fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564e37394c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564e3a363f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564e3a363f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564e3a363f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564e3a363f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564e3a363f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564e3a363f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564e3a363f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564e3a363f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564e3a363f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564e3a363f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564e3c5f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564e39325b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564e39330be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564e390dcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564e390dcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564e390dd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564e390dc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564e390dc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564e390dc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564e3d9e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564e3d9ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564e3d9d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564e3da02112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f620c241082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564e372fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x32,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x24,0x32,0x32,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x32,0x2d,0x3d,0x3c,0x27,0x27,0x73,0x74,0x72,0x65,0x61,0x6d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x7a,0x27,0x27,0x27,0x27,0x27,0x7a,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x7a,0x27,0x27,0x27,0x27,0x27,0x7a,0x27,0x27,0x27,0x27,0x27,0x2d, Step #5: $22-=<'''''''''''/''''''''22-=<'''''$22-=<'''''''''''/''''''''22-=<''stream'''''''''/''''''''z'''''z'''''''''/''''''''z'''''z'''''- Step #5: artifact_prefix='./'; Test unit written to ./oom-b915f62a2cd72dc1ad7008e8b1f4cbfcc7e55143 Step #5: Base64: JDIyLT08JycnJycnJycnJycvJycnJycnJycyMi09PCcnJycnJDIyLT08JycnJycnJycnJycvJycnJycnJycyMi09PCcnc3RyZWFtJycnJycnJycnLycnJycnJycneicnJycneicnJycnJycnJy8nJycnJycnJ3onJycnJ3onJycnJy0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4418 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3933559623 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d62f8e810, 0x557d6317801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d63178020,0x557d650100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b915f62a2cd72dc1ad7008e8b1f4cbfcc7e55143' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5520 processed earlier; will process 5509 files now Step #5: ==159124== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557d59a839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557d600e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557d600cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557d600cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557d59a89d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557d599eab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557d599e5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557d59a7bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557d5ca4af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557d5ca4af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557d5ca4af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557d5ca4af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557d5ca4af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557d5ca4af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557d5ca4af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557d5ca4af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557d5ca4af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557d5ca4af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557d5ecdff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557d5ba0cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557d5ba17be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557d5b7c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557d5b7c3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557d5b7c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557d5b7c3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557d5b7c3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557d5b7c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557d600cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557d600d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557d600be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557d600e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2f5a969082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557d599e3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4,0x11,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x13, Step #5: \004\021 \000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\004\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000~\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\023 Step #5: artifact_prefix='./'; Test unit written to ./oom-ebdac0b368b55c84128f0f0cf2d55070864666f7 Step #5: Base64: BBEgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAH4AAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4419 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3934069285 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5584426b2810, 0x55844289c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55844289c020,0x5584447340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ebdac0b368b55c84128f0f0cf2d55070864666f7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5521 processed earlier; will process 5508 files now Step #5: ==159160== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5584391a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55843f80c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55843f7ef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55843f7ef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5584391add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55843910eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558439109355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55843919fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55843c16ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55843c16ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55843c16ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55843c16ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55843c16ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55843c16ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55843c16ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55843c16ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55843c16ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55843c16ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55843e403f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55843b130b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55843b13bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55843aee7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55843aee7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55843aee8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55843aee7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55843aee7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55843aee7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55843f7f1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55843f7fa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55843f7e2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55843f80d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa4cfcdd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558439107b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0x48,0x7d,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x98,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0x8c,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0x22, Step #5: \"\357\270\210\357\270\210\357\270\210\357H}\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\230\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\214\210\357\270\210\357\270\210\" Step #5: artifact_prefix='./'; Test unit written to ./oom-d4111738caa30297c790d5b9bdfda3482fe43d57 Step #5: Base64: Iu+4iO+4iO+4iO9Ife+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4mO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+MiO+4iO+4iCI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4420 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3934564872 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aafbae8810, 0x55aafbcd201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aafbcd2020,0x55aafdb6a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d4111738caa30297c790d5b9bdfda3482fe43d57' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5522 processed earlier; will process 5507 files now Step #5: ==159196== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aaf25dd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aaf8c42898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aaf8c255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aaf8c254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aaf25e3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aaf2544b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aaf253f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aaf25d5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aaf55a4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aaf55a4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aaf55a4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aaf55a4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aaf55a4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aaf55a4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aaf55a4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aaf55a4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aaf55a4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aaf55a4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aaf7839f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aaf4566b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aaf4571be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aaf431dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aaf431dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aaf431e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aaf431d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aaf431d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aaf431d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aaf8c27abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aaf8c30928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aaf8c18699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aaf8c43112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9a10c5d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aaf253db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x98,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0x22, Step #5: \"\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\230\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\" Step #5: artifact_prefix='./'; Test unit written to ./oom-02b44260b2ec250f2598382ecc44336a18b3e00a Step #5: Base64: Iu+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4mO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iCI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4421 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3935070664 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564111b86810, 0x564111d7001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564111d70020,0x564113c080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/02b44260b2ec250f2598382ecc44336a18b3e00a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5523 processed earlier; will process 5506 files now Step #5: ==159232== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56410867b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56410ece0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56410ecc35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56410ecc34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564108681d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641085e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641085dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564108673c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56410b642f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56410b642f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56410b642f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56410b642f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56410b642f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56410b642f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56410b642f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56410b642f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56410b642f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56410b642f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56410d8d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56410a604b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56410a60fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56410a3bbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56410a3bbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56410a3bc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56410a3bb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56410a3bb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56410a3bb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56410ecc5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56410ecce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56410ecb6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56410ece1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe711b6c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641085dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x61,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x61,0x3e,0x3c,0xce,0x9e,0x3e,0x3d,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e,0x3c,0xce,0x9e,0x3e, Step #5: <\316\236><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236a><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236a><\316\236>=<\316\236><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236><\316\236> Step #5: artifact_prefix='./'; Test unit written to ./oom-6da695a0cadea6e1f355aed0878a17e8dbd6480a Step #5: Base64: PM6ePjzOnj48zp4+PM6ePjzOnj48zp4+PM6ePjzOnj48zp4+PM6ePjzOnj48zp4+PM6eYT48zp4+PM6ePjzOnj48zp4+PM6ePjzOnj48zp5hPjzOnj49PM6ePjzOnj48zp4+PM6ePjzOnj48zp4+PM6ePjzOnj48zp4+PM6ePjzOnj4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4422 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3935575251 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5616dd668810, 0x5616dd85201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5616dd852020,0x5616df6ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6da695a0cadea6e1f355aed0878a17e8dbd6480a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5524 processed earlier; will process 5505 files now Step #5: #1 pulse cov: 3727 ft: 3728 exec/s: 0 rss: 176Mb Step #5: ==159268== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5616d415d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5616da7c2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5616da7a55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5616da7a54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5616d4163d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5616d40c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5616d40bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5616d4155c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5616d7124f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5616d7124f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5616d7124f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5616d7124f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5616d7124f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5616d7124f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5616d7124f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5616d7124f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5616d7124f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5616d7124f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5616d93b9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5616d60e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5616d60f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5616d5e9dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5616d5e9dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5616d5e9e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5616d5e9d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5616d5e9d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5616d5e9d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5616da7a7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5616da7b0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5616da798699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5616da7c3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6c2a1a2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5616d40bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x34,0x41,0x10,0x2f,0x0,0x0,0x0,0x74,0x3c,0x3c,0x3a,0xa,0x2d,0x20,0x2f,0x3a,0x3a,0xa,0x2d,0x20,0x21,0x30,0xa,0x3a,0x3a,0xa,0x2d,0x20,0x21,0x30,0xa,0x2d,0x20,0x21,0x30,0xa,0x2d,0x24,0x20,0x20,0x21,0x34,0x3a,0xa,0x2d,0x20,0x21,0x30,0xa,0x3a,0x3a,0xa,0x2d,0x20,0x2d,0x20,0x21,0x31,0xa,0x3a,0x3a,0x64,0x2d,0x20,0x21,0x3c,0x3c,0x3a,0xa,0x2d,0x20,0x2f,0x3a,0x3a,0xa,0x2d,0x20,0x21,0x30,0xa,0x3a,0x3a,0xa,0x2d,0x20,0x21,0x31,0xa,0x24,0x20,0x20,0x21,0x34,0x3a,0xa,0x2d,0x20,0x21,0x30,0xa,0x3a,0x3a,0xa,0x2d,0x20,0x2d,0x20,0x21,0x30,0xa,0x3a,0x3a,0x64,0x2d,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x3a,0x3f, Step #5: 4A\020/\000\000\000t<<:\012- /::\012- !0\012::\012- !0\012- !0\012-$ !4:\012- !0\012::\012- - !1\012::d- !<<:\012- /::\012- !0\012::\012- !1\012$ !4:\012- !0\012::\012- - !0\012::d- :? Step #5: artifact_prefix='./'; Test unit written to ./oom-256cee3c1014166df7f70cffe66c8b50970fa47a Step #5: Base64: NEEQLwAAAHQ8PDoKLSAvOjoKLSAhMAo6OgotICEwCi0gITAKLSQgICE0OgotICEwCjo6Ci0gLSAhMQo6OmQtICE8PDoKLSAvOjoKLSAhMAo6OgotICExCiQgICE0OgotICEwCjo6Ci0gLSAhMAo6OmQtICAgICAgICAgICAgICAgOj8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4423 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3936135675 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c286fcb810, 0x55c2871b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c2871b5020,0x55c28904d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/256cee3c1014166df7f70cffe66c8b50970fa47a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5526 processed earlier; will process 5503 files now Step #5: ==159304== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c27dac09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c284125898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c2841085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c2841084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c27dac6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c27da27b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c27da22355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c27dab8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c280a87f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c280a87f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c280a87f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c280a87f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c280a87f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c280a87f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c280a87f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c280a87f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c280a87f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c280a87f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c282d1cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c27fa49b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c27fa54be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c27f800c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c27f800c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c27f801738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c27f800874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c27f800874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c27f800874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c28410aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c284113928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c2840fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c284126112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbff538c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c27da20b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0x2c,0x26,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f, Step #5: &,&________________________________________________________________________________________________________________________________ Step #5: artifact_prefix='./'; Test unit written to ./oom-5b750b92ea2d873c8f0cbbd29142182a20b7b2ff Step #5: Base64: JiwmX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4424 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3936646357 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5569cc9bd810, 0x5569ccba701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5569ccba7020,0x5569cea3f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5b750b92ea2d873c8f0cbbd29142182a20b7b2ff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5527 processed earlier; will process 5502 files now Step #5: ==159340== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5569c34b29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5569c9b17898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5569c9afa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5569c9afa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5569c34b8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5569c3419b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5569c3414355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5569c34aac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5569c6479f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5569c6479f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5569c6479f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5569c6479f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5569c6479f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5569c6479f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5569c6479f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5569c6479f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5569c6479f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5569c6479f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5569c870ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5569c543bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5569c5446be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5569c51f2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5569c51f2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5569c51f3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5569c51f2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5569c51f2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5569c51f2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5569c9afcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5569c9b05928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5569c9aed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5569c9b18112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f337a116082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5569c3412b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x80,0x88,0x0,0x0,0x0,0x0,0x0,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4c,0x44,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x3e,0x3e,0x4e,0x44,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x20,0x60,0xa,0x9, Step #5: `\342\200\210\000\000\000\000\000\000********* \012-----END \012-----END \012-----ELD \012-----END \012---->>ND \012-----END \012-----END \012-----END \012-----END \012-----END \012-----E `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-52c532f00588750dd8d4f732ad080e62c218f00f Step #5: Base64: YOKAiAAAAAAAACoqKioqKioqKiAKLS0tLS1FTkQgCi0tLS0tRU5EIAotLS0tLUVMRCAKLS0tLS1FTkQgCi0tLS0+Pk5EIAotLS0tLUVORCAKLS0tLS1FTkQgCi0tLS0tRU5EIAotLS0tLUVORCAKLS0tLS1FTkQgCi0tLS0tRSBgCgk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4425 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3937280121 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ceeba3a810, 0x55ceebc2401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ceebc24020,0x55ceedabc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/52c532f00588750dd8d4f732ad080e62c218f00f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5528 processed earlier; will process 5501 files now Step #5: ==159376== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cee252f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cee8b94898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cee8b775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cee8b774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cee2535d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cee2496b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cee2491355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cee2527c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cee54f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cee54f6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cee54f6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cee54f6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cee54f6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cee54f6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cee54f6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cee54f6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cee54f6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cee54f6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cee778bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cee44b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cee44c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cee426fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cee426fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cee4270738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cee426f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cee426f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cee426f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cee8b79abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cee8b82928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cee8b6a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cee8b95112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f30c0ff4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cee248fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x98,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0x7e,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0xef,0xb8,0x88,0x22, Step #5: \"\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\230\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357~\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\357\270\210\" Step #5: artifact_prefix='./'; Test unit written to ./oom-3095fcb039ccc77938814a785438ad7420bfa3d1 Step #5: Base64: Iu+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4mO+4iO+4iO+4iO+4iO+4iO+4iO9+iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iO+4iCI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4426 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3937782262 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5569bd0ef810, 0x5569bd2d901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5569bd2d9020,0x5569bf1710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3095fcb039ccc77938814a785438ad7420bfa3d1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5529 processed earlier; will process 5500 files now Step #5: ==159412== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5569b3be49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5569ba249898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5569ba22c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5569ba22c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5569b3bead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5569b3b4bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5569b3b46355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5569b3bdcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5569b6babf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5569b6babf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5569b6babf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5569b6babf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5569b6babf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5569b6babf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5569b6babf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5569b6babf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5569b6babf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5569b6babf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5569b8e40f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5569b5b6db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5569b5b78be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5569b5924c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5569b5924c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5569b5925738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5569b5924874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5569b5924874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5569b5924874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5569ba22eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5569ba237928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5569ba21f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5569ba24a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9bd0546082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5569b3b44b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6,0x24,0x20,0x6,0xa,0x24,0x20,0x27,0xa,0x24,0x20,0x6e,0xa,0x24,0x20,0x6,0xa,0x24,0x20,0x29,0xa,0x24,0x20,0x30,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x31,0xa,0x24,0x20,0x6,0xa,0x24,0x20,0x28,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x30,0xa,0x24,0x20,0x45,0xa,0x24,0x20,0x6,0xa,0x24,0x20,0x27,0xa,0x24,0x20,0x6e,0xa,0x24,0x20,0x6,0xa,0x24,0x20,0x29,0xa,0x24,0x20,0x30,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2a,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x28,0xa,0x24,0xc,0x7a,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x25,0xde,0xad,0xbe,0xef, Step #5: \006$ \006\012$ '\012$ n\012$ \006\012$ )\012$ 0\012$ +\012$ +\012$ +\012$ 1\012$ \006\012$ (\012$ +\012$ 0\012$ E\012$ \006\012$ '\012$ n\012$ \006\012$ )\012$ 0\012$ +\012$ *\012$ +\012$ (\012$\014z\012$ +\012$ +\012$ +\012$ +\012$ +\012$ %\336\255\276\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-9c17a568230484d64b5fdb2eb15ee929ccba7e4b Step #5: Base64: BiQgBgokICcKJCBuCiQgBgokICkKJCAwCiQgKwokICsKJCArCiQgMQokIAYKJCAoCiQgKwokIDAKJCBFCiQgBgokICcKJCBuCiQgBgokICkKJCAwCiQgKwokICoKJCArCiQgKAokDHoKJCArCiQgKwokICsKJCArCiQgKwokICXerb7v Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4427 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3938301431 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556726698810, 0x55672688201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556726882020,0x55672871a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c17a568230484d64b5fdb2eb15ee929ccba7e4b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5530 processed earlier; will process 5499 files now Step #5: ==159448== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55671d18d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5567237f2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5567237d55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5567237d54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55671d193d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55671d0f4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55671d0ef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55671d185c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556720154f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556720154f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556720154f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556720154f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556720154f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556720154f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556720154f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556720154f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556720154f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556720154f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5567223e9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55671f116b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55671f121be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55671eecdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55671eecdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55671eece738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55671eecd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55671eecd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55671eecd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5567237d7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5567237e0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5567237c8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5567237f3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f947f6dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55671d0edb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x7b,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: ws:{\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-a8bcec74c0c18b6728e3e2a9153664c7a4b136cc Step #5: Base64: d3M6e82EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2E Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4428 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3938801751 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb44c37810, 0x55eb44e2101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb44e21020,0x55eb46cb90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a8bcec74c0c18b6728e3e2a9153664c7a4b136cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5531 processed earlier; will process 5498 files now Step #5: ==159484== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eb3b72c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb41d91898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb41d745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb41d744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb3b732d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb3b693b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb3b68e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb3b724c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb3e6f3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb3e6f3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb3e6f3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb3e6f3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb3e6f3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb3e6f3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb3e6f3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb3e6f3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb3e6f3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb3e6f3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb40988f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb3d6b5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb3d6c0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb3d46cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb3d46cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb3d46d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb3d46c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb3d46c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb3d46c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb41d76abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb41d7f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb41d67699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb41d92112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba76385082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb3b68cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x66,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a, Step #5: fjjjjjjjjjjjjjjjjjjjjjjjjjjjfjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj Step #5: artifact_prefix='./'; Test unit written to ./oom-86ae94e83e1e38b6ebaea7f21df40b0032a862fc Step #5: Base64: ZmpqampqampqampqampqampqampqampqampqamZqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampq Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4429 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3939305154 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ac57e66810, 0x55ac5805001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ac58050020,0x55ac59ee80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/86ae94e83e1e38b6ebaea7f21df40b0032a862fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5532 processed earlier; will process 5497 files now Step #5: ==159520== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ac4e95b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ac54fc0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ac54fa35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ac54fa34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ac4e961d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ac4e8c2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ac4e8bd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ac4e953c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ac51922f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ac51922f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ac51922f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ac51922f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ac51922f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ac51922f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ac51922f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ac51922f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ac51922f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ac51922f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ac53bb7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ac508e4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ac508efbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ac5069bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ac5069bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ac5069c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ac5069b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ac5069b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ac5069b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ac54fa5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ac54fae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ac54f96699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ac54fc1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc32c753082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ac4e8bbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x31,0x4d,0x42,0x65,0x41,0x57,0x61,0x47,0x6f,0x53,0x6c,0x71,0x2b,0x48,0x6d,0x72,0x63,0x77,0x31,0x42,0x59,0x6a,0x4c,0x43,0x54,0x41,0x42,0x2b,0x4c,0x53,0x58,0x49,0x56,0x77,0x6a,0x7a,0x53,0x77,0x6f,0x31,0x44,0x44,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f, Step #5: onion-key\012a /\012a /\012a /\012a /\012a /\012ntor-onion-key v1MBeAWaGoSlq+Hmrcw1BYjLCTAB+LSXIVwjzSwo1DD\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a / Step #5: artifact_prefix='./'; Test unit written to ./oom-2f3f568a563ec1c034dd534bd7dd404a6e758cb8 Step #5: Base64: b25pb24ta2V5CmEgLwphIC8KYSAvCmEgLwphIC8KbnRvci1vbmlvbi1rZXkgdjFNQmVBV2FHb1NscStIbXJjdzFCWWpMQ1RBQitMU1hJVndqelN3bzFERAphIC8KYSAvCmEgLwphIC8KYSAvCmEgLwphIC8KYSAvCmEgLwphIC8KYSAv Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4430 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3939809632 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dfa1894810, 0x55dfa1a7e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dfa1a7e020,0x55dfa39160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f3f568a563ec1c034dd534bd7dd404a6e758cb8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5533 processed earlier; will process 5496 files now Step #5: ==159556== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55df983899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55df9e9ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55df9e9d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55df9e9d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55df9838fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55df982f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55df982eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55df98381c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55df9b350f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55df9b350f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55df9b350f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55df9b350f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55df9b350f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55df9b350f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55df9b350f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55df9b350f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55df9b350f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55df9b350f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55df9d5e5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55df9a312b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55df9a31dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55df9a0c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55df9a0c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55df9a0ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55df9a0c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55df9a0c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55df9a0c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55df9e9d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55df9e9dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55df9e9c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55df9e9ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f60230ab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55df982e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x28,0x20,0x37,0x20,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x0,0x24,0x0,0x0,0x0, Step #5: $\177]2.23/\020./0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000( 7 \177\000\000\0002\000\000\000\000\000\177\177\177\177o\000\000C\000$\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7a39f2afa1cb5811f6d2acc8aae305b797c31b3c Step #5: Base64: JH9dMi4yMy8QLi8wMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwKCA3IH8AAAAyAAAAAAB/f39/bwAAQwAkAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4431 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3940323666 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558180a6a810, 0x558180c5401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558180c54020,0x558182aec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7a39f2afa1cb5811f6d2acc8aae305b797c31b3c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5534 processed earlier; will process 5495 files now Step #5: ==159592== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55817755f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55817dbc4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55817dba75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55817dba74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558177565d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5581774c6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5581774c1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558177557c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55817a526f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55817a526f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55817a526f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55817a526f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55817a526f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55817a526f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55817a526f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55817a526f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55817a526f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55817a526f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55817c7bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5581794e8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5581794f3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55817929fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55817929fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5581792a0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55817929f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55817929f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55817929f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55817dba9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55817dbb2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55817db9a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55817dbc5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8846858082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5581774bfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xdb,0x80,0xdb,0x80,0x39,0x0,0x39,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6b, Step #5: =\333\200\333\2009\0009\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000k Step #5: artifact_prefix='./'; Test unit written to ./oom-0efe925e21e3d80525a118c1d8fb8418ddb14c57 Step #5: Base64: PduA24A5ADkAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABr Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4432 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3940823172 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561717fbf810, 0x5617181a901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5617181a9020,0x56171a0410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0efe925e21e3d80525a118c1d8fb8418ddb14c57' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5535 processed earlier; will process 5494 files now Step #5: ==159628== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56170eab49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561715119898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5617150fc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5617150fc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56170eabad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56170ea1bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56170ea16355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56170eaacc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561711a7bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561711a7bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561711a7bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561711a7bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561711a7bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561711a7bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561711a7bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561711a7bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561711a7bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561711a7bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561713d10f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561710a3db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561710a48be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5617107f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5617107f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5617107f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5617107f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5617107f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5617107f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5617150feabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561715107928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5617150ef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56171511a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcbc630c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56170ea14b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x46,0x3e,0x3e,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x6c,0x76,0x62,0x61,0x67,0x2f,0x65,0x78,0x74,0x72,0x61,0x63,0x74,0x2d,0x64,0x65,0x65,0x6c,0x62,0x65,0x73,0x74,0x61,0x6e,0x64,0x2d,0x6c,0x76,0x63,0x2f,0x76,0x32,0x30,0x32,0x30,0x30,0x36,0x30,0x31,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x73,0x74,0x61,0x6e,0x64,0x6c,0x65,0x76,0x65,0x72,0x69,0x6e,0x67,0x2d,0x67,0x65,0x6e,0x65,0x72,0x69,0x65,0x6b,0x2f,0x31,0x2e,0x30,0x20, Step #5: <F>>http://www.kadaster.nl/schemas/lvbag/extract-deelbestand-lvc/v20200601http://www.kadaster.nl/schemas/standlevering-generiek/1.0 Step #5: artifact_prefix='./'; Test unit written to ./oom-16e1ddcceef780ff7d0f6041b03ac29f1fb7602a Step #5: Base64: PEY+Pmh0dHA6Ly93d3cua2FkYXN0ZXIubmwvc2NoZW1hcy9sdmJhZy9leHRyYWN0LWRlZWxiZXN0YW5kLWx2Yy92MjAyMDA2MDFodHRwOi8vd3d3LmthZGFzdGVyLm5sL3NjaGVtYXMvc3RhbmRsZXZlcmluZy1nZW5lcmllay8xLjAg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4433 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3941324057 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563721f4c810, 0x56372213601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563722136020,0x563723fce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16e1ddcceef780ff7d0f6041b03ac29f1fb7602a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5536 processed earlier; will process 5493 files now Step #5: ==159664== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563718a419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56371f0a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56371f0895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56371f0894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563718a47d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5637189a8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5637189a3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563718a39c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56371ba08f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56371ba08f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56371ba08f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56371ba08f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56371ba08f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56371ba08f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56371ba08f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56371ba08f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56371ba08f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56371ba08f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56371dc9df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56371a9cab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56371a9d5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56371a781c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56371a781c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56371a782738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56371a781874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56371a781874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56371a781874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56371f08babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56371f094928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56371f07c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56371f0a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88d422a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5637189a1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3a,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0xf0,0x9d,0x9f,0x96,0x24,0xb,0x3c,0xb,0xf3,0xa0,0x81,0xaf,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3c,0xb,0xa,0x24,0xb,0x3d,0xb,0xde,0xad,0xbe,0xef, Step #5: \003$\013<\013\012$\013<\013\012$\013<\013\012$\013<\013\012$\013<\013\012$\013:\013\012$\013<\013\012$\013<\013\012$\013<\013\012$\013<\013\012$\013<\013\012$\013<\013\012$\013<\013\012$\013<\013\012$\013<\013\012$\013<\013\012$\013<\013\012$\013<\013\012$\013<\013\012\360\235\237\226$\013<\013\363\240\201\257\012$\013<\013\012$\013<\013\012$\013<\013\012$\013=\013\336\255\276\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-ded4bd9ed3baccdb288aa99670247a49a3563931 Step #5: Base64: AyQLPAsKJAs8CwokCzwLCiQLPAsKJAs8CwokCzoLCiQLPAsKJAs8CwokCzwLCiQLPAsKJAs8CwokCzwLCiQLPAsKJAs8CwokCzwLCiQLPAsKJAs8CwokCzwLCiQLPAsK8J2fliQLPAvzoIGvCiQLPAsKJAs8CwokCzwLCiQLPQverb7v Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4434 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3941835097 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558de6802810, 0x558de69ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558de69ec020,0x558de88840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ded4bd9ed3baccdb288aa99670247a49a3563931' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5537 processed earlier; will process 5492 files now Step #5: #1 pulse cov: 11329 ft: 11330 exec/s: 0 rss: 196Mb Step #5: ==159700== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558ddd2f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558de395c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558de393f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558de393f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558ddd2fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558ddd25eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558ddd259355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558ddd2efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558de02bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558de02bef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558de02bef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558de02bef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558de02bef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558de02bef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558de02bef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558de02bef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558de02bef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558de02bef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558de2553f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ddf280b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ddf28bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ddf037c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ddf037c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ddf038738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ddf037874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ddf037874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ddf037874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558de3941abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558de394a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558de3932699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558de395d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb3dcf5b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558ddd257b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x9,0x3f,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0xf3,0xa0,0x81,0xa8,0x78,0x6d, Step #5: \011?\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250\363\240\201\250xm Step #5: artifact_prefix='./'; Test unit written to ./oom-b4b619317525282a187dc68961cc510b66f9c1ba Step #5: Base64: CT/zoIGo86CBqPOggajzoIGo86CBqPOggajzoIGo86CBqPOggajzoIGo86CBqPOggajzoIGo86CBqPOggajzoIGo86CBqPOggajzoIGo86CBqPOggajzoIGo86CBqPOggajzoIGo86CBqPOggajzoIGo86CBqPOggajzoIGo86CBqHht Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4435 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3942405611 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ad0061810, 0x555ad024b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ad024b020,0x555ad20e30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b4b619317525282a187dc68961cc510b66f9c1ba' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5539 processed earlier; will process 5490 files now Step #5: ==159736== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555ac6b569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555acd1bb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555acd19e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555acd19e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ac6b5cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ac6abdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ac6ab8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ac6b4ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ac9b1df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ac9b1df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ac9b1df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ac9b1df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ac9b1df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ac9b1df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ac9b1df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ac9b1df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ac9b1df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ac9b1df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555acbdb2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ac8adfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ac8aeabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ac8896c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ac8896c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ac8897738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ac8896874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ac8896874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ac8896874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555acd1a0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555acd1a9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555acd191699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555acd1bc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f500b308082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ac6ab6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xf0,0x9e,0x8b,0x91, Step #5: \360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221\015in\015\360\236\213\221 Step #5: artifact_prefix='./'; Test unit written to ./oom-650e9b66f70329bae6fd9469568a796a295ed634 Step #5: Base64: 8J6LkQ1pbg3wnouRDWluDfCei5ENaW4N8J6LkQ1pbg3wnouRDWluDfCei5ENaW4N8J6LkQ1pbg3wnouRDWluDfCei5ENaW4N8J6LkQ1pbg3wnouRDWluDfCei5ENaW4N8J6LkQ1pbg3wnouRDWluDfCei5ENaW4N8J6LkQ1pbg3wnouR Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4436 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3942913104 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf99880810, 0x55bf99a6a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf99a6a020,0x55bf9b9020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/650e9b66f70329bae6fd9469568a796a295ed634' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5540 processed earlier; will process 5489 files now Step #5: ==159772== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bf903759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf969da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf969bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf969bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf9037bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf902dcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf902d7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf9036dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf9333cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf9333cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf9333cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf9333cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf9333cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf9333cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf9333cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf9333cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf9333cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf9333cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf955d1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf922feb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf92309be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf920b5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf920b5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf920b6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf920b5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf920b5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf920b5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf969bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf969c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf969b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf969db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fae91d3f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf902d5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3c,0x61,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x3e, Step #5: (?<accccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc> Step #5: artifact_prefix='./'; Test unit written to ./oom-21c6c77e754ad0f1174e36a3715b958c983151db Step #5: Base64: KD88YWNjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2M+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4437 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3943412917 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca7bbd2810, 0x55ca7bdbc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca7bdbc020,0x55ca7dc540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/21c6c77e754ad0f1174e36a3715b958c983151db' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5541 processed earlier; will process 5488 files now Step #5: ==159808== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ca726c79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca78d2c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca78d0f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca78d0f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca726cdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca7262eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca72629355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca726bfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca7568ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca7568ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca7568ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca7568ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca7568ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca7568ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca7568ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca7568ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca7568ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca7568ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca77923f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca74650b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca7465bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca74407c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca74407c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca74408738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca74407874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca74407874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca74407874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca78d11abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca78d1a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca78d02699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca78d2d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f05c6959082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca72627b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x1,0x0,0x0,0x0,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a, Step #5: fjjjjjjjjj\001\000\000\000jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj Step #5: artifact_prefix='./'; Test unit written to ./oom-b555bf96b09265850c006a963d2472ef5b98a94a Step #5: Base64: ZmpqampqampqagEAAABqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampqampq Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4438 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3943916516 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b5c560810, 0x561b5c74a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b5c74a020,0x561b5e5e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b555bf96b09265850c006a963d2472ef5b98a94a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5542 processed earlier; will process 5487 files now Step #5: #1 pulse cov: 10525 ft: 10526 exec/s: 0 rss: 197Mb Step #5: ==159844== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561b530559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b596ba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b5969d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b5969d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b5305bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b52fbcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b52fb7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b5304dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b5601cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b5601cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b5601cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b5601cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b5601cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b5601cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b5601cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b5601cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b5601cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b5601cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b582b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b54fdeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b54fe9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b54d95c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b54d95c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b54d96738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b54d95874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b54d95874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b54d95874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b5969fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b596a8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b59690699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b596bb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1ee883f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b52fb5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x3f,0x3a,0x28,0x3f,0x73,0x74,0x72,0x79,0x20,0x28,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x7c,0x7c,0x24,0x7c,0x24,0x24,0x24,0x7c,0x24,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x29,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x29,0x29,0x7c,0x29,0x7c,0x29,0x7c, Step #5: (?:(?:?:(?stry (:$|$|(?:(?:(?:$|$|$|$|$|$|$|$|||$|$$$|$$|$|$|$|$|$|)|$|(?:$|$|(?:(?:(?:$|$|$|$|$|$|$|$|$|$|$|$|$)|$|$|$|$|$)|))|)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-77e4cf075f1f65cf35ca689bac166c7868fc3bc5 Step #5: Base64: KD86KD86PzooP3N0cnkgKDokfCR8KD86KD86KD86JHwkfCR8JHwkfCR8JHwkfHx8JHwkJCR8JCR8JHwkfCR8JHwkfCl8JHwoPzokfCR8KD86KD86KD86JHwkfCR8JHwkfCR8JHwkfCR8JHwkfCR8JCl8JHwkfCR8JHwkKXwpKXwpfCl8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4439 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3944553464 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e8fbf2810, 0x559e8fddc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e8fddc020,0x559e91c740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/77e4cf075f1f65cf35ca689bac166c7868fc3bc5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5544 processed earlier; will process 5485 files now Step #5: #1 pulse cov: 3513 ft: 3514 exec/s: 0 rss: 174Mb Step #5: ==159880== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559e866e79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e8cd4c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e8cd2f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e8cd2f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e866edd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e8664eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e86649355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e866dfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e896aef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e896aef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e896aef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e896aef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e896aef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e896aef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e896aef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e896aef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e896aef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e896aef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e8b943f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e88670b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e8867bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e88427c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e88427c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e88428738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e88427874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e88427874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e88427874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e8cd31abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e8cd3a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e8cd22699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e8cd4d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb681e97082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e86647b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x6c,0x3e,0x6c,0x3e,0x3c,0x21,0x2d,0x2d,0x36,0x3e,0x7e,0x3c,0x6e,0x3e,0x6d,0x27,0x27,0x2e,0xd,0xd,0x67,0x53,0x53,0x2d,0x53,0x53,0x53,0x53,0x53,0x53,0x53,0x53,0x53,0xd,0xd,0xa,0x67,0x2f,0x32,0x31,0x50,0x55,0x34,0x3b,0x72,0xd,0x65,0x34,0x6c,0x6e,0x3d,0x63,0x22,0x68,0x74,0x47,0xd,0x65,0x2f,0x32,0x30,0x30,0x30,0x6d,0xd,0xd,0xd,0x6e,0x68,0x61,0x30,0x37,0xd,0xd,0xd,0xd,0xd,0x3a,0x45,0x49,0x74,0x61,0x53,0x2d,0x38,0x4f,0x61,0x31,0x39,0x69,0x36,0x7a,0x55,0x27,0xd,0xd,0xd,0xd,0xd,0x67,0x2f,0x32,0x30,0x20,0x3a,0x27,0x27,0x27,0x34,0x2e,0x34,0x70,0x34,0x55,0x43,0x53,0x2d,0x30,0x37,0xd,0xd,0xd,0x34,0x70,0x34,0x50,0x55,0x27,0xd,0xd,0xd, Step #5: <l>l><!--6>~<n>m''.\015\015gSS-SSSSSSSSS\015\015\012g/21PU4;r\015e4ln=c\"htG\015e/2000m\015\015\015nha07\015\015\015\015\015:EItaS-8Oa19i6zU'\015\015\015\015\015g/20 :'''4.4p4UCS-07\015\015\0154p4PU'\015\015\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-338cd1c382f133c96d431455992e801f821bb0ab Step #5: Base64: PGw+bD48IS0tNj5+PG4+bScnLg0NZ1NTLVNTU1NTU1NTUw0NCmcvMjFQVTQ7cg1lNGxuPWMiaHRHDWUvMjAwMG0NDQ1uaGEwNw0NDQ0NOkVJdGFTLThPYTE5aTZ6VScNDQ0NDWcvMjAgOicnJzQuNHA0VUNTLTA3DQ0NNHA0UFUnDQ0N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4440 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3945103014 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d82ffd810, 0x557d831e701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d831e7020,0x557d8507f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/338cd1c382f133c96d431455992e801f821bb0ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5546 processed earlier; will process 5483 files now Step #5: #1 pulse cov: 4140 ft: 4141 exec/s: 0 rss: 177Mb Step #5: ==159916== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557d79af29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557d80157898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557d8013a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557d8013a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557d79af8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557d79a59b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557d79a54355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557d79aeac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557d7cab9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557d7cab9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557d7cab9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557d7cab9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557d7cab9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557d7cab9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557d7cab9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557d7cab9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557d7cab9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557d7cab9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557d7ed4ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557d7ba7bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557d7ba86be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557d7b832c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557d7b832c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557d7b833738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557d7b832874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557d7b832874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557d7b832874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557d8013cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557d80145928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557d8012d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557d80158112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f13d461b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557d79a52b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6,0x24,0x20,0x6,0xa,0x24,0x20,0x27,0xa,0x24,0x20,0x6e,0xa,0x24,0x20,0x6,0xa,0x24,0x20,0x29,0xa,0x24,0x20,0x30,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x30,0xa,0x24,0x20,0x6,0xa,0x24,0x20,0x28,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x32,0xa,0x24,0x20,0x45,0xa,0x24,0x20,0x6,0xa,0x24,0x20,0x27,0xa,0x24,0x20,0x6e,0xa,0x24,0x20,0x6,0xa,0x24,0x20,0x29,0xa,0x24,0x20,0x30,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2a,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x28,0xa,0x24,0xc,0x7a,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x2b,0xa,0x24,0x20,0x25,0xde,0xad,0xbe,0xef,0x43, Step #5: \006$ \006\012$ '\012$ n\012$ \006\012$ )\012$ 0\012$ +\012$ +\012$ +\012$ 0\012$ \006\012$ (\012$ +\012$ 2\012$ E\012$ \006\012$ '\012$ n\012$ \006\012$ )\012$ 0\012$ +\012$ *\012$ +\012$ (\012$\014z\012$ +\012$ +\012$ +\012$ +\012$ +\012$ %\336\255\276\357C Step #5: artifact_prefix='./'; Test unit written to ./oom-ece347d1234a5bcace31438885d2628f38291b84 Step #5: Base64: BiQgBgokICcKJCBuCiQgBgokICkKJCAwCiQgKwokICsKJCArCiQgMAokIAYKJCAoCiQgKwokIDIKJCBFCiQgBgokICcKJCBuCiQgBgokICkKJCAwCiQgKwokICoKJCArCiQgKAokDHoKJCArCiQgKwokICsKJCArCiQgKwokICXerb7vQw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4441 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3945662322 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564590bad810, 0x564590d9701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564590d97020,0x564592c2f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ece347d1234a5bcace31438885d2628f38291b84' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5548 processed earlier; will process 5481 files now Step #5: #1 pulse cov: 4013 ft: 4014 exec/s: 0 rss: 174Mb Step #5: ==159952== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5645876a29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56458dd07898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56458dcea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56458dcea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5645876a8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564587609b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564587604355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56458769ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56458a669f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56458a669f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56458a669f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56458a669f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56458a669f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56458a669f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56458a669f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56458a669f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56458a669f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56458a669f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56458c8fef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56458962bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564589636be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5645893e2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5645893e2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5645893e3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5645893e2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5645893e2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5645893e2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56458dcecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56458dcf5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56458dcdd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56458dd08112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb7f04ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564587602b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x52,0x3a,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x33,0x33,0x37,0x34,0x36,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x30,0x37,0x34,0x33,0x31,0x37,0x33,0x38,0x32,0x31,0x31,0x33,0x37,0x32,0x3b, Step #5: |R:340282366920938463433746222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222207431738211372; Step #5: artifact_prefix='./'; Test unit written to ./oom-4b17bce844d8e53d7b7236e837fa5e1e7db9a61d Step #5: Base64: fFI6MzQwMjgyMzY2OTIwOTM4NDYzNDMzNzQ2MjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjA3NDMxNzM4MjExMzcyOw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4442 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3946206940 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ffc591d810, 0x55ffc5b0701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ffc5b07020,0x55ffc799f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4b17bce844d8e53d7b7236e837fa5e1e7db9a61d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5550 processed earlier; will process 5479 files now Step #5: ==159988== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ffbc4129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ffc2a77898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ffc2a5a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ffc2a5a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ffbc418d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ffbc379b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ffbc374355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ffbc40ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ffbf3d9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ffbf3d9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ffbf3d9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ffbf3d9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ffbf3d9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ffbf3d9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ffbf3d9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ffbf3d9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ffbf3d9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ffbf3d9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ffc166ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ffbe39bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ffbe3a6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ffbe152c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ffbe152c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ffbe153738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ffbe152874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ffbe152874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ffbe152874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ffc2a5cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ffc2a65928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ffc2a4d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ffc2a78112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f07111f5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ffbc372b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x3f,0x3a,0x28,0x3f,0x73,0x74,0x72,0x79,0x20,0x28,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x7c,0x7c,0x24,0x7c,0x24,0x24,0x24,0x7c,0x24,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x29,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x5c,0xde,0x99,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x3b,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x29,0x29,0x7c,0x29,0x7c,0x29,0x7c, Step #5: (?:(?:?:(?stry (:$|$|(?:(?:(?:$|$|$|$|$|$|$|$|||$|$$$|$$|$|$|$|$|$|)|$|(?:$|$|(?:(?:(?:\\\336\231|$|$|$|$|$|$|$;|$|$|$|$)|$|$|$|$|$)|))|)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-60c57f592e6ec1bbe6c59e66b794112b051f4c65 Step #5: Base64: KD86KD86PzooP3N0cnkgKDokfCR8KD86KD86KD86JHwkfCR8JHwkfCR8JHwkfHx8JHwkJCR8JCR8JHwkfCR8JHwkfCl8JHwoPzokfCR8KD86KD86KD86XN6ZfCR8JHwkfCR8JHwkfCQ7fCR8JHwkfCQpfCR8JHwkfCR8JCl8KSl8KXwpfA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4443 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3946720213 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557ca41c4810, 0x557ca43ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557ca43ae020,0x557ca62460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/60c57f592e6ec1bbe6c59e66b794112b051f4c65' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5551 processed earlier; will process 5478 files now Step #5: ==160024== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557c9acb99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557ca131e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557ca13015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557ca13014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557c9acbfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557c9ac20b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557c9ac1b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557c9acb1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557c9dc80f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557c9dc80f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557c9dc80f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557c9dc80f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557c9dc80f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557c9dc80f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557c9dc80f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557c9dc80f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557c9dc80f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557c9dc80f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557c9ff15f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557c9cc42b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557c9cc4dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557c9c9f9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557c9c9f9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557c9c9fa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557c9c9f9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557c9c9f9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557c9c9f9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557ca1303abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557ca130c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557ca12f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557ca131f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1cd78b3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557c9ac19b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x7b,0x3f,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x3f,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x3f,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0xa,0x2d,0x20,0x2d,0x3f, Step #5: -{?\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- ?\012- -\012- -\012- ?\012- -\012- -\012- -\012- -\012- -\012- -\012\012- -? Step #5: artifact_prefix='./'; Test unit written to ./oom-7dfbc3043048ac134f80f62f5f228aad18a5d328 Step #5: Base64: LXs/Ci0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gPwotIC0KLSAtCi0gPwotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQoKLSAtPw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4444 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3947281956 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56259ff14810, 0x5625a00fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625a00fe020,0x5625a1f960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7dfbc3043048ac134f80f62f5f228aad18a5d328' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5552 processed earlier; will process 5477 files now Step #5: ==160060== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562596a099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56259d06e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56259d0515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56259d0514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562596a0fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562596970b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56259696b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562596a01c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5625999d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5625999d0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5625999d0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5625999d0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5625999d0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5625999d0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5625999d0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5625999d0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5625999d0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5625999d0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56259bc65f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562598992b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56259899dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562598749c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562598749c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56259874a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562598749874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562598749874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562598749874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56259d053abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56259d05c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56259d044699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56259d06f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b483ea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562596969b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2d,0x49,0x4e,0x20,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2c,0xb,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2,0xa,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2,0xa,0x2d,0xa,0x2d,0xa,0x62,0xa,0xd0,0xa,0x2d,0xa,0x64,0xa,0xd5,0xa,0x2,0xa,0x33,0xa,0xdc,0xa,0xd2,0xa,0x0,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xff, Step #5: \000-IN \005-----\012,\013-\012d\012-\012d\012-\012d\012d\012-\012\002\012-\012\002\012-\012,\012-\012d\012-\012d\012d\012\002\012-\012,\012-\012d\012-\012d\012d\012-\012\002\012-\012,\012-\012d\012\002\012-\012d\012-\012\002\012-\012\002\012-\012,\012-\012d\012\002\012-\012-\012b\012\320\012-\012d\012\325\012\002\0123\012\334\012\322\012\000\012-\012-\012-\012\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-61e2610d1826d0694cbf97a1324444a9a66979cc Step #5: Base64: AC1JTiAFLS0tLS0KLAstCmQKLQpkCi0KZApkCi0KAgotCgIKLQosCi0KZAotCmQKZAoCCi0KLAotCmQKLQpkCmQKLQoCCi0KLAotCmQKAgotCmQKLQoCCi0KAgotCiwKLQpkCgIKLQotCmIK0AotCmQK1QoCCjMK3ArSCgAKLQotCi0K/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4445 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3947818107 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f34911a810, 0x55f34930401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f349304020,0x55f34b19c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/61e2610d1826d0694cbf97a1324444a9a66979cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5553 processed earlier; will process 5476 files now Step #5: ==160096== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f33fc0f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f346274898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f3462575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f3462574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f33fc15d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f33fb76b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f33fb71355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f33fc07c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f342bd6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f342bd6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f342bd6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f342bd6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f342bd6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f342bd6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f342bd6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f342bd6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f342bd6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f342bd6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f344e6bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f341b98b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f341ba3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f34194fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f34194fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f341950738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f34194f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f34194f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f34194f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f346259abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f346262928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f34624a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f346275112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f91aae1a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f33fb6fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x5,0xd,0x1,0xa,0x4,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x62,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x25,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x1,0xd,0x5c,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x5c,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xa,0x5,0xd,0x1,0xde,0xad,0xbe,0xef,0x23, Step #5: \003\005\015\001\012\004\015\001\012\005\015\001\012\005\015b\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\001\012%\015\001\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\001\012\001\015\\\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\\\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\001\012\005\015\001\336\255\276\357# Step #5: artifact_prefix='./'; Test unit written to ./oom-d08856174378f66b7f83102ef6089f6188dff5ae Step #5: Base64: AwUNAQoEDQEKBQ0BCgUNYgoFDQEKBQ0BCgUNAQoFDQEKJQ0BCgUNAQoFDQEKBQ0BCgUNAQoBDVwKBQ0BCgUNAQoFDQEKBQ0BCgUNAQoFDQEKBQ0BCgUNAQoFDVwKBQ0BCgUNAQoFDQEKBQ0BCgUNAQoFDQEKBQ0BCgUNAQoFDQHerb7vIw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4446 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3948322426 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56132d9e2810, 0x56132dbcc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56132dbcc020,0x56132fa640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d08856174378f66b7f83102ef6089f6188dff5ae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5554 processed earlier; will process 5475 files now Step #5: ==160132== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5613244d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56132ab3c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56132ab1f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56132ab1f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5613244ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56132443eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561324439355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5613244cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56132749ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56132749ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56132749ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56132749ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56132749ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56132749ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56132749ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56132749ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56132749ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56132749ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561329733f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561326460b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56132646bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561326217c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561326217c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561326218738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561326217874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561326217874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561326217874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56132ab21abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56132ab2a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56132ab12699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56132ab3d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1b7d348082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561324437b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x2d,0x3d,0x3e,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x3d,0x37,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x4c,0x3e,0x32,0x2d,0x3d,0x3e,0xde,0xae,0x21,0xde,0xae,0x2d,0x4c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x3d,0x37,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x4c,0x43,0xb2,0xb2,0xb2,0xb2,0x24, Step #5: =-=>\336\256!\336\256-\\\\\\\\\336\256!\336\256-\\\\\\=7\000\000\000\000\000\000\000\336\256-\\\\\\\\\336\256!\336\256-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\L>2-=>\336\256!\336\256-L\\\\\\\336\256!\336\256-\\\\\\=7\000\000\000\000\000\000\000\336\256-\\\\\\\\\336\256!\336\256-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\LC\262\262\262\262$ Step #5: artifact_prefix='./'; Test unit written to ./oom-72338b8d6778f11c74364a772418c31f7c236ec8 Step #5: Base64: PS09Pt6uId6uLVxcXFzeriHeri1cXFw9NwAAAAAAAADeri1cXFxc3q4h3q4tXFxcXFxcXFxcXFxcXFxcXFxMPjItPT7eriHeri1MXFxc3q4h3q4tXFxcPTcAAAAAAAAA3q4tXFxcXN6uId6uLVxcXFxcXFxcXFxcXFxcXFxcTEOysrKyJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4447 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3948826721 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56403e660810, 0x56403e84a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56403e84a020,0x5640406e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/72338b8d6778f11c74364a772418c31f7c236ec8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5555 processed earlier; will process 5474 files now Step #5: #1 pulse cov: 3657 ft: 3658 exec/s: 0 rss: 175Mb Step #5: ==160168== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5640351559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56403b7ba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56403b79d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56403b79d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56403515bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5640350bcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5640350b7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56403514dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56403811cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56403811cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56403811cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56403811cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56403811cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56403811cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56403811cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56403811cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56403811cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56403811cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56403a3b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5640370deb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5640370e9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564036e95c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564036e95c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564036e96738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564036e95874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564036e95874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564036e95874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56403b79fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56403b7a8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56403b790699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56403b7bb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d234b0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5640350b5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x57,0x73,0x3a,0xda,0xba,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x36,0x29,0x37,0x35,0x38,0x30,0x39,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x31,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x34,0x34,0x34,0x30,0x30,0x31,0x37,0x34,0x35,0x37,0x30,0x36,0x30,0x32,0x36,0x2b,0x2b,0x2b,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b, Step #5: Ws:\332\27292233720368546)75809+++++++++++++++++++++++1++++++++++444001745706026+++4444444444444444444444444444444444++++++++++++++++++++++ Step #5: artifact_prefix='./'; Test unit written to ./oom-10f1594131065c0449b7e223c69e06a7eabe64d9 Step #5: Base64: V3M62ro5MjIzMzcyMDM2ODU0Nik3NTgwOSsrKysrKysrKysrKysrKysrKysrKysrMSsrKysrKysrKys0NDQwMDE3NDU3MDYwMjYrKys0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0KysrKysrKysrKysrKysrKysrKysrKw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4448 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3949367886 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564faecf4810, 0x564faeede01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564faeede020,0x564fb0d760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/10f1594131065c0449b7e223c69e06a7eabe64d9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5557 processed earlier; will process 5472 files now Step #5: ==160204== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564fa57e99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564fabe4e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564fabe315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564fabe314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564fa57efd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564fa5750b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564fa574b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564fa57e1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564fa87b0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564fa87b0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564fa87b0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564fa87b0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564fa87b0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564fa87b0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564fa87b0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564fa87b0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564fa87b0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564fa87b0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564faaa45f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564fa7772b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564fa777dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564fa7529c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564fa7529c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564fa752a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564fa7529874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564fa7529874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564fa7529874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564fabe33abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564fabe3c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564fabe24699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564fabe4f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a97b63082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564fa5749b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x6c,0xc5,0x90,0x3e,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x6c,0x76,0x62,0x61,0x67,0x2f,0x65,0x78,0x74,0x72,0x61,0x63,0x74,0x2d,0x64,0x65,0x65,0x6c,0x62,0x65,0x73,0x74,0x61,0x6e,0x64,0x2d,0x6c,0x76,0x63,0x2f,0x76,0x32,0x30,0x32,0x30,0x30,0x36,0x30,0x31,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x73,0x74,0x61,0x6e,0x64,0x6c,0x65,0x76,0x65,0x72,0x69,0x6e,0x67,0x2d,0x67,0x65,0x6e,0x65,0x72,0x69,0x65,0x6b,0x2f,0x31,0x2e,0x30, Step #5: <sl\305\220>http://www.kadaster.nl/schemas/lvbag/extract-deelbestand-lvc/v20200601http://www.kadaster.nl/schemas/standlevering-generiek/1.0 Step #5: artifact_prefix='./'; Test unit written to ./oom-f3da57b5d8d8fa925020bee8a7b2f79ccc8eac2c Step #5: Base64: PHNsxZA+aHR0cDovL3d3dy5rYWRhc3Rlci5ubC9zY2hlbWFzL2x2YmFnL2V4dHJhY3QtZGVlbGJlc3RhbmQtbHZjL3YyMDIwMDYwMWh0dHA6Ly93d3cua2FkYXN0ZXIubmwvc2NoZW1hcy9zdGFuZGxldmVyaW5nLWdlbmVyaWVrLzEuMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4449 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3949880390 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5564a3c9b810, 0x5564a3e8501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564a3e85020,0x5564a5d1d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f3da57b5d8d8fa925020bee8a7b2f79ccc8eac2c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5558 processed earlier; will process 5471 files now Step #5: ==160240== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55649a7909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564a0df5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564a0dd85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564a0dd84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55649a796d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55649a6f7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55649a6f2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55649a788c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55649d757f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55649d757f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55649d757f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55649d757f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55649d757f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55649d757f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55649d757f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55649d757f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55649d757f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55649d757f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55649f9ecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55649c719b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55649c724be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55649c4d0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55649c4d0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55649c4d1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55649c4d0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55649c4d0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55649c4d0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564a0ddaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564a0de3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564a0dcb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564a0df6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ee1343082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55649a6f0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0xa4,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: ws:\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\244\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-160636d3c1e3dc184d613f5ae4df8d7cc04e7fc0 Step #5: Base64: d3M6zYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNpM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4450 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3950394041 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c594b5810, 0x561c5969f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c5969f020,0x561c5b5370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/160636d3c1e3dc184d613f5ae4df8d7cc04e7fc0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5559 processed earlier; will process 5470 files now Step #5: #1 pulse cov: 3459 ft: 3460 exec/s: 0 rss: 175Mb Step #5: ==160276== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561c4ffaa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c5660f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c565f25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c565f24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c4ffb0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c4ff11b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c4ff0c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c4ffa2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c52f71f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c52f71f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c52f71f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c52f71f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c52f71f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c52f71f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c52f71f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c52f71f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c52f71f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c52f71f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c55206f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c51f33b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c51f3ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c51ceac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c51ceac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c51ceb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c51cea874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c51cea874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c51cea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c565f4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c565fd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c565e5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c56610112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2122204082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c4ff0ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x6d,0x3e,0x26,0x23,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30, Step #5: <m>&#00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-62ee232eeee393f1d7c1f79cf9586982e197871e Step #5: Base64: PG0+JiMwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4451 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3950940390 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db606e6810, 0x55db608d001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db608d0020,0x55db627680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/62ee232eeee393f1d7c1f79cf9586982e197871e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5561 processed earlier; will process 5468 files now Step #5: #1 pulse cov: 4340 ft: 4341 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4847 ft: 5221 exec/s: 0 rss: 176Mb Step #5: ==160312== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db571db9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db5d840898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db5d8235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db5d8234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db571e1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db57142b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db5713d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db571d3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db5a1a2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db5a1a2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db5a1a2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db5a1a2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db5a1a2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db5a1a2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db5a1a2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db5a1a2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db5a1a2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db5a1a2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db5c437f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db59164b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db5916fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db58f1bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db58f1bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db58f1c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db58f1b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db58f1b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db58f1b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db5d825abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db5d82e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db5d816699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db5d841112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe720446082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db5713bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xa9,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xf3,0xa0,0x80,0x81,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0,0xc2,0xb0, Step #5: //\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\251\302\260\302\260\302\260\363\240\200\201\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260\302\260 Step #5: artifact_prefix='./'; Test unit written to ./oom-28b873007cce5c761dcb77660997e9c87f3b4863 Step #5: Base64: Ly/CsMKwwrDCsMKwwrDCsMKwwrDCsMKwwrDCsMKwwrDCsMKwwrDCsMKwwrDCsMKwwrDCsMKwwrDCsMKwwrDCsMKpwrDCsMKw86CAgcKwwrDCsMKwwrDCsMKwwrDCsMKwwrDCsMKwwrDCsMKwwrDCsMKwwrDCsMKwwrDCsMKwwrDCsMKwwrA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4452 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3951515259 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7900ca810, 0x55b7902b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7902b4020,0x55b79214c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/28b873007cce5c761dcb77660997e9c87f3b4863' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5564 processed earlier; will process 5465 files now Step #5: ==160348== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b786bbf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b78d224898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b78d2075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b78d2074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b786bc5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b786b26b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b786b21355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b786bb7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b789b86f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b789b86f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b789b86f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b789b86f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b789b86f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b789b86f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b789b86f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b789b86f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b789b86f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b789b86f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b78be1bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b788b48b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b788b53be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b7888ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b7888ffc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b788900738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b7888ff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b7888ff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b7888ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b78d209abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b78d212928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b78d1fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b78d225112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd6824a8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b786b1fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x35,0x69,0x6e,0xd,0x33,0x69,0x6e,0x2a,0x34,0x69,0x6e,0x2c,0x36,0x69,0x6e,0x24,0x36,0x69,0x6e,0x21,0x34,0x69,0x6e,0xd,0x34,0x69,0x6e,0x3e,0x35,0x69,0x6e,0xd,0x33,0x69,0x6e,0x2a,0x34,0x69,0x6e,0x2c,0x36,0x69,0x6e,0x24,0x36,0x69,0x6e,0x21,0x31,0x69,0x6e,0xd,0x34,0x69,0x6e,0x3e,0x35,0x69,0x6e,0xd,0x33,0x69,0x6e,0x2a,0x34,0x69,0x6e,0x2c,0x36,0x69,0x6e,0x24,0x36,0x69,0x6e,0x21,0x34,0x69,0x6e,0xd,0x34,0x69,0x6e,0x2a,0x34,0x69,0x6e,0x2a,0x34,0x69,0x6e,0x3e,0x36,0x69,0x6e,0xd,0x33,0x69,0x6e,0x2a,0x34,0x69,0x6e,0x2c,0x36,0x69,0x6e,0x24,0x36,0x69,0x6e,0x21,0x34,0x69,0x6e,0xd,0x32,0x69,0x6e,0x2a,0x34,0x69,0x6e,0x2a,0x34,0x69,0x6e, Step #5: <style>5in\0153in*4in,6in$6in!4in\0154in>5in\0153in*4in,6in$6in!1in\0154in>5in\0153in*4in,6in$6in!4in\0154in*4in*4in>6in\0153in*4in,6in$6in!4in\0152in*4in*4in Step #5: artifact_prefix='./'; Test unit written to ./oom-b536f81c04400b08350789a9a69eb4303985567f Step #5: Base64: PHN0eWxlPjVpbg0zaW4qNGluLDZpbiQ2aW4hNGluDTRpbj41aW4NM2luKjRpbiw2aW4kNmluITFpbg00aW4+NWluDTNpbio0aW4sNmluJDZpbiE0aW4NNGluKjRpbio0aW4+NmluDTNpbio0aW4sNmluJDZpbiE0aW4NMmluKjRpbio0aW4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4453 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3952029444 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a67a881810, 0x55a67aa6b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a67aa6b020,0x55a67c9030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b536f81c04400b08350789a9a69eb4303985567f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5565 processed earlier; will process 5464 files now Step #5: #1 pulse cov: 3723 ft: 3724 exec/s: 0 rss: 174Mb Step #5: ==160384== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a6713769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a6779db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a6779be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a6779be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a67137cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a6712ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a6712d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a67136ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a67433df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a67433df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a67433df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a67433df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a67433df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a67433df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a67433df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a67433df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a67433df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a67433df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a6765d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a6732ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a67330abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a6730b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a6730b6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a6730b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a6730b6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a6730b6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a6730b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a6779c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a6779c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a6779b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a6779dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0fcb8be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a6712d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x53,0x3a,0xe3,0x8c,0x96,0x31,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0x46,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0x2e,0x2e, Step #5: \016wS:\343\214\2261\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226F\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226.. Step #5: artifact_prefix='./'; Test unit written to ./oom-5d9c21d4b4b39ca9eda68f906edd7c228a9d7fa9 Step #5: Base64: DndTOuOMljHjjJbjjJbjjJbjjJbjjJbjjJbjjJbjjJbjjJbjjJbjjJbjjJbjjJbjjJbjjJbjjJbjjJbjjJZG44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yWLi4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4454 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3952577016 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565367188810, 0x56536737201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565367372020,0x56536920a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5d9c21d4b4b39ca9eda68f906edd7c228a9d7fa9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5567 processed earlier; will process 5462 files now Step #5: ==160420== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56535dc7d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5653642e2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5653642c55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5653642c54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56535dc83d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56535dbe4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56535dbdf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56535dc75c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565360c44f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565360c44f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565360c44f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565360c44f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565360c44f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565360c44f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565360c44f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565360c44f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565360c44f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565360c44f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565362ed9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56535fc06b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56535fc11be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56535f9bdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56535f9bdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56535f9be738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56535f9bd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56535f9bd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56535f9bd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5653642c7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5653642d0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5653642b8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5653642e3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f91ddda4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56535dbddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x7b,0x20,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0x9,0x20,0x20,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0xb,0x22,0x44,0x20,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x27,0x47,0x58,0x27,0x20,0x27,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x37,0x40,0x2f,0x36,0x38,0xca,0xcf,0x27,0x20,0x20,0xd,0x3e,0x20,0x20,0x5c,0x30,0x30,0x20,0x20,0x3c,0x49,0x20,0x3e,0x20,0x21,0x3e,0x22,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x76,0x61,0x6c,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x22,0x20,0x20,0x20,0x7d,0x20,0x7d,0x20,0x7d,0x20,0x7d,0xa,0x20,0x7d,0x7d, Step #5: p{ doctype {\012mdecl {\011 entity { name:\013\"D PUBLIC 'GX' ' http://7@/68\312\317' \015> \\00 <I > !>\"ent {\012 val { name: \"D\" } } } }\012 }} Step #5: artifact_prefix='./'; Test unit written to ./oom-5a8e2542aa496c7b2c0fa97c48a70a9fce7de28f Step #5: Base64: cHsgZG9jdHlwZSB7Cm1kZWNsIHsJICBlbnRpdHkgeyBuYW1lOgsiRCAgUFVCTElDICdHWCcgJyAgICAgICAgaHR0cDovLzdALzY4ys8nICANPiAgXDAwICA8SSA+ICE+ImVudCB7CiAgdmFsIHsgbmFtZTogIkQiICAgfSB9IH0gfQogfX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4455 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3953083492 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a86102810, 0x560a862ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a862ec020,0x560a881840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5a8e2542aa496c7b2c0fa97c48a70a9fce7de28f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5568 processed earlier; will process 5461 files now Step #5: ==160456== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560a7cbf79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a8325c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a8323f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a8323f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a7cbfdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a7cb5eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a7cb59355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a7cbefc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a7fbbef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a7fbbef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a7fbbef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a7fbbef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a7fbbef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a7fbbef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a7fbbef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a7fbbef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a7fbbef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a7fbbef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a81e53f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a7eb80b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a7eb8bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a7e937c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a7e937c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a7e938738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a7e937874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a7e937874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a7e937874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a83241abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a8324a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a83232699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a8325d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f746d009082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a7cb57b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x2d,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x3d,0x3c,0x2d,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x24,0x27,0x2d,0x24,0x2d,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x3d,0x3c,0x2d,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x24,0x27,0x2d, Step #5: $-9223372036854775551-=<-1''/''''/'''exp'N'2-\007='''''$'-$-9223372036854775551-54775551-=<-1''/''''/'''exp'N'2-\007='''''exp'N'2-\007='''''$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-cd558bff7855c8ff6814309eb5e0265e0cbbdcd7 Step #5: Base64: JC05MjIzMzcyMDM2ODU0Nzc1NTUxLT08LTEnJy8nJycnLycnJ2V4cCdOJzItBz0nJycnJyQnLSQtOTIyMzM3MjAzNjg1NDc3NTU1MS01NDc3NTU1MS09PC0xJycvJycnJy8nJydleHAnTicyLQc9JycnJydleHAnTicyLQc9JycnJyckJy0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4456 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3953599007 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55749c795810, 0x55749c97f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55749c97f020,0x55749e8170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd558bff7855c8ff6814309eb5e0265e0cbbdcd7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5569 processed earlier; will process 5460 files now Step #5: ==160492== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55749328a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5574998ef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5574998d25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5574998d24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557493290d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5574931f1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5574931ec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557493282c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557496251f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557496251f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557496251f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557496251f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557496251f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557496251f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557496251f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557496251f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557496251f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557496251f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5574984e6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557495213b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55749521ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557494fcac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557494fcac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557494fcb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557494fca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557494fca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557494fca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5574998d4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5574998dd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5574998c5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5574998f0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f93942e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5574931eab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x4a,0x3e,0x3c,0x4a,0x3e,0x3c,0x4a,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x7a,0x3e,0x3c,0x7a,0x3e,0x3c,0x7a,0x3e,0x3c,0x7a,0x3e,0x3c,0x7a,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x4a,0x3e,0x3c,0x4a,0x3e,0x3c,0x4a,0x3e,0x3c,0x4a,0x3e,0x3c,0x4a,0x3e,0x3c,0x4a,0x3e,0x3c,0x4a,0x3e,0x3c,0x4a,0x3e,0x3c,0x4a,0x3e,0x3c,0x7a,0x3e,0x3c,0x42,0x3e,0x3c,0x42,0x3e,0x3c,0x4a,0x3e,0x3c,0x4a,0x3e,0x3c,0x7a,0x3e,0x3c,0x3e, Step #5: <J><J><J><B><B><B><B><B><B><z><z><z><z><z><B><B><B><B><B><B><B><B><B><B><B><B><B><B><B><J><J><J><J><J><J><J><J><J><z><B><B><J><J><z><> Step #5: artifact_prefix='./'; Test unit written to ./oom-5c61045d475db4b99be3b38f9372c57f90e6eb85 Step #5: Base64: PEo+PEo+PEo+PEI+PEI+PEI+PEI+PEI+PEI+PHo+PHo+PHo+PHo+PHo+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEI+PEo+PEo+PEo+PEo+PEo+PEo+PEo+PEo+PEo+PHo+PEI+PEI+PEo+PEo+PHo+PD4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4457 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3954100336 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559fd1e6e810, 0x559fd205801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559fd2058020,0x559fd3ef00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c61045d475db4b99be3b38f9372c57f90e6eb85' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5570 processed earlier; will process 5459 files now Step #5: ==160528== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559fc89639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559fcefc8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559fcefab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559fcefab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559fc8969d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559fc88cab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559fc88c5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559fc895bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559fcb92af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559fcb92af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559fcb92af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559fcb92af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559fcb92af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559fcb92af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559fcb92af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559fcb92af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559fcb92af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559fcb92af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559fcdbbff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559fca8ecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559fca8f7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559fca6a3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559fca6a3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559fca6a4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559fca6a3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559fca6a3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559fca6a3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559fcefadabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559fcefb6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559fcef9e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559fcefc9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe896a25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559fc88c3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x50,0x3c,0x64,0x3e,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x64,0x3e,0x28,0x3f,0x50,0x3c,0x3e, Step #5: (?P<d><d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<d>(?P<> Step #5: artifact_prefix='./'; Test unit written to ./oom-3a4db3c18598109e0b97d322abc95d200d8a6577 Step #5: Base64: KD9QPGQ+PGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPGQ+KD9QPD4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4458 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3954606069 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640d7bf5810, 0x5640d7ddf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640d7ddf020,0x5640d9c770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a4db3c18598109e0b97d322abc95d200d8a6577' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5571 processed earlier; will process 5458 files now Step #5: ==160564== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5640ce6ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5640d4d4f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640d4d325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640d4d324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5640ce6f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5640ce651b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5640ce64c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5640ce6e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5640d16b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5640d16b1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5640d16b1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5640d16b1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5640d16b1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5640d16b1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5640d16b1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5640d16b1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5640d16b1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5640d16b1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5640d3946f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5640d0673b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5640d067ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5640d042ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5640d042ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5640d042b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5640d042a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5640d042a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5640d042a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5640d4d34abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5640d4d3d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5640d4d25699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5640d4d50112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcef4d18082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5640ce64ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x41,0x64,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x4,0x0,0x73,0x20,0x31,0x33,0x31,0x8d,0x0,0x52,0x0,0x0,0x34,0x39,0x39,0x39,0x39,0x39,0x0,0x0,0x41,0x50,0x49,0x0,0x0,0x63,0x65,0x6e,0x74,0x52,0x29,0x4,0x80,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x3d, Step #5: \333\200\333\2009\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000Ad\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000ID3\004\000s 131\215\000R\000\000499999\000\000API\000\000centR)\004\200APIC\000\000\000= Step #5: artifact_prefix='./'; Test unit written to ./oom-834d45d29c175a6591d89b62f133f49723166df5 Step #5: Base64: 24DbgDkAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABBZAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAElEMwQAcyAxMzGNAFIAADQ5OTk5OQAAQVBJAABjZW50UikEgEFQSUMAAAA9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4459 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3955117239 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555bd0375810, 0x555bd055f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555bd055f020,0x555bd23f70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/834d45d29c175a6591d89b62f133f49723166df5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5572 processed earlier; will process 5457 files now Step #5: ==160600== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555bc6e6a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555bcd4cf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555bcd4b25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555bcd4b24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555bc6e70d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555bc6dd1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555bc6dcc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555bc6e62c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555bc9e31f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555bc9e31f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555bc9e31f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555bc9e31f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555bc9e31f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555bc9e31f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555bc9e31f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555bc9e31f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555bc9e31f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555bc9e31f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555bcc0c6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555bc8df3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555bc8dfebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555bc8baac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555bc8baac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555bc8bab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555bc8baa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555bc8baa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555bc8baa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555bcd4b4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555bcd4bd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555bcd4a5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555bcd4d0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe6076b8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555bc6dcab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0x9,0x59,0x5b,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0x9,0x61,0x20,0x20,0x78,0x6d,0x6c,0x6e,0x73,0x3a,0x73,0x77,0x9,0x49,0x44,0x9,0x27,0xe7,0x95,0x8a,0x27,0x20,0x78,0x6d,0x6c,0x6e,0x73,0x3a,0x6d,0x9,0x49,0x44,0x9,0x27,0xe7,0x95,0x8a,0x27,0x20,0x78,0x6d,0x6c,0x6e,0x73,0x3a,0x77,0x9,0x49,0x44,0x9,0x27,0x20,0x33,0x27,0x3e,0x5d,0xa,0x3e,0x3c,0x61,0x3e,0x6f,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x3c,0x61,0x3e,0x61,0x3c,0x3e,0x3c,0x3e, Step #5: <!DOCTYPE\011Y[<!ATTLIST\011a xmlns:sw\011ID\011'\347\225\212' xmlns:m\011ID\011'\347\225\212' xmlns:w\011ID\011' 3'>]\012><a>o<a><a><a><a>a><a><a><a><a><a><a><a><a><a><a><a>a<><> Step #5: artifact_prefix='./'; Test unit written to ./oom-38b5599752b48215838ffb360ba7d353477e94f4 Step #5: Base64: PCFET0NUWVBFCVlbPCFBVFRMSVNUCWEgIHhtbG5zOnN3CUlECSfnlYonIHhtbG5zOm0JSUQJJ+eViicgeG1sbnM6dwlJRAknIDMnPl0KPjxhPm88YT48YT48YT48YT5hPjxhPjxhPjxhPjxhPjxhPjxhPjxhPjxhPjxhPjxhPjxhPmE8Pjw+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4460 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3955627894 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55863a73c810, 0x55863a92601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55863a926020,0x55863c7be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/38b5599752b48215838ffb360ba7d353477e94f4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5573 processed earlier; will process 5456 files now Step #5: ==160636== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5586312319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558637896898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5586378795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5586378794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558631237d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558631198b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558631193355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558631229c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5586341f8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5586341f8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5586341f8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5586341f8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5586341f8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5586341f8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5586341f8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5586341f8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5586341f8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5586341f8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55863648df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5586331bab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5586331c5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558632f71c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558632f71c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558632f72738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558632f71874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558632f71874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558632f71874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55863787babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558637884928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55863786c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558637897112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa283ec2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558631191b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2d,0x2d,0x4f,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x2d,0xa,0x2d,0xa,0xff, Step #5: \000--O--BEGIN -----\012,\012-\012d\012-\012d=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=-\012-\012\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-e4f4013f13c007c1ebcda0a3fc7ce9b72359cd0b Step #5: Base64: AC0tTy0tQkVHSU4gLS0tLS0KLAotCmQKLQpkPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPS0KLQr/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4461 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3956163182 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c94ec4f810, 0x55c94ee3901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c94ee39020,0x55c950cd10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e4f4013f13c007c1ebcda0a3fc7ce9b72359cd0b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5574 processed earlier; will process 5455 files now Step #5: ==160672== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c9457449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c94bda9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c94bd8c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c94bd8c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c94574ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9456abb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c9456a6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c94573cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c94870bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c94870bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c94870bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c94870bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c94870bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c94870bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c94870bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c94870bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c94870bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c94870bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c94a9a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9476cdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9476d8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c947484c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c947484c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c947485738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c947484874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c947484874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c947484874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c94bd8eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c94bd97928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c94bd7f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c94bdaa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ba89cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c9456a4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0x98,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa6,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xb0,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa4,0xf3,0xa0,0x81,0xa6,0xf3,0x81,0x98,0x81,0xa4,0xf3,0xa0,0xa4,0x81,0xff,0x5, Step #5: \363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\230\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\246\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\260\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\244\363\240\201\246\363\201\230\201\244\363\240\244\201\377\005 Step #5: artifact_prefix='./'; Test unit written to ./oom-f13faf67fab0ab7661d412d52c8e1b1c22d93362 Step #5: Base64: 86CBpPOggaTzoIGk86CBpPOggaTzoIGk86CBpPOggaTzmIGk86CBpPOggaTzoIGk86CBpPOggaTzoIGk86CBpvOggaTzoIGk86CBpPOggaTzoIGk86CBpPOggaTzoIGw86CBpPOggaTzoIGk86CBpPOggaTzoIGk86CBpvOBmIGk86Ckgf8F Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4462 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3956667570 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5576a67f3810, 0x5576a69dd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5576a69dd020,0x5576a88750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f13faf67fab0ab7661d412d52c8e1b1c22d93362' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5575 processed earlier; will process 5454 files now Step #5: ==160708== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55769d2e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5576a394d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5576a39305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5576a39304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55769d2eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55769d24fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55769d24a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55769d2e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576a02aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576a02aff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576a02aff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576a02aff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576a02aff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576a02aff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576a02aff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576a02aff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576a02aff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576a02aff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5576a2544f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55769f271b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55769f27cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55769f028c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55769f028c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55769f029738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55769f028874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55769f028874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55769f028874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5576a3932abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5576a393b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5576a3923699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5576a394e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f720b2ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55769d248b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0xf3,0xa0,0x81,0xb0,0x33,0x4,0x2,0x3f,0x54,0x2d,0x35,0x36,0x30,0x33,0x32,0x38,0x37,0x31,0x39,0x34,0x34,0x33,0x33,0x36,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x1d,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0xe2,0x81,0x9f,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x37,0xe2,0x80,0xab,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x3f,0x54,0x31,0x43,0x48,0x75,0x0,0x12, Step #5: ID\363\240\201\2603\004\002?T-56032871944336\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\035\035\035\035\035\035\035\035\035\035\035\035\035\035\03534028236692093846346337\342\201\2374607431768211457\342\200\25392233720368?T1CHu\000\022 Step #5: artifact_prefix='./'; Test unit written to ./oom-5e8fc204bab0eaf13c034058bd7199239b104114 Step #5: Base64: SUTzoIGwMwQCP1QtNTYwMzI4NzE5NDQzMzYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAdHR0dHR0dHR0dHR0dHR0zNDAyODIzNjY5MjA5Mzg0NjM0NjMzN+KBnzQ2MDc0MzE3NjgyMTE0NTfigKs5MjIzMzcyMDM2OD9UMUNIdQAS Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4463 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3957181648 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0bd888810, 0x55a0bda7201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0bda72020,0x55a0bf90a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e8fc204bab0eaf13c034058bd7199239b104114' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5576 processed earlier; will process 5453 files now Step #5: ==160744== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0b437d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0ba9e2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0ba9c55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0ba9c54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0b4383d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0b42e4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0b42df355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0b4375c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0b7344f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0b7344f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0b7344f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0b7344f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0b7344f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0b7344f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0b7344f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0b7344f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0b7344f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0b7344f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0b95d9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0b6306b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0b6311be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0b60bdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0b60bdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0b60be738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0b60bd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0b60bd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0b60bd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0ba9c7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0ba9d0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0ba9b8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0ba9e3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe6cda9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0b42ddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x45,0x3e,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0xa0,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0x81,0xa0,0xa0,0xa0,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0xa0,0x81,0x26,0xe3,0x81,0xa0, Step #5: <E>&\343\240\201&\343\240\201&\343\240\201&\343\240\240&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\201\240\240\240&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\240\201&\343\201\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-4e27f6add26b083d623fec4fcc8f7fb9539c255f Step #5: Base64: PEU+JuOggSbjoIEm46CBJuOgoCbjoIEm46CBJuOggSbjoIEm4ybjoIEm46CBJuOggSbjoIEm46CBJuOggSbjoIEm46CBJuOggSbjoIEm46CBJuOBoKCgJuOggSbjoIEm46CBJuOggSbjoIEm46CBJuOggSbjoIEm46CBJuOggSbjoIEm44Gg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4464 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3957679735 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8578c1810, 0x55c857aab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c857aab020,0x55c8599430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e27f6add26b083d623fec4fcc8f7fb9539c255f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5577 processed earlier; will process 5452 files now Step #5: ==160780== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c84e3b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c854a1b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8549fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8549fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c84e3bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c84e31db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c84e318355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c84e3aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c85137df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c85137df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c85137df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c85137df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c85137df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c85137df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c85137df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c85137df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c85137df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c85137df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c853612f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c85033fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c85034abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c8500f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c8500f6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c8500f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c8500f6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c8500f6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c8500f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c854a00abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c854a09928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8549f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c854a1c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f145dbd3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c84e316b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c,0x69,0x67,0x68,0x74,0x24,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3a,0x3a,0x3a,0x3a,0x0,0x5d,0x2f,0x0,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3a,0x3a,0x3a,0x3a,0x0,0x5d,0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x24,0x5b, Step #5: light$:::::::::::::::::::::::=\012=\012=\012=\012=\012=\012=\012=?\012=\012=\012=\012=\012=\012::::\000]/\000::::::::::::::::::::::=\012=\012=\012=\012=\012=\012=\012=?\012=\012=\012=\012=\012=\012::::\000]/\000\000\000\000\000\000\000\000\000\000\000\000\001$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-e3d2da91763d4cc6862dd1e7aeef964c4fa6ac48 Step #5: Base64: bGlnaHQkOjo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo9Cj0KPQo9Cj0KPQo9Cj0/Cj0KPQo9Cj0KPQo6Ojo6AF0vADo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo9Cj0KPQo9Cj0KPQo9Cj0/Cj0KPQo9Cj0KPQo6Ojo6AF0vAAAAAAAAAAAAAAAAASRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4465 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3958194913 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c2c545e810, 0x55c2c564801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c2c5648020,0x55c2c74e00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e3d2da91763d4cc6862dd1e7aeef964c4fa6ac48' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5578 processed earlier; will process 5451 files now Step #5: ==160816== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c2bbf539c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c2c25b8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c2c259b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c2c259b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c2bbf59d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c2bbebab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c2bbeb5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c2bbf4bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c2bef1af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c2bef1af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c2bef1af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c2bef1af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c2bef1af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c2bef1af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c2bef1af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c2bef1af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c2bef1af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c2bef1af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c2c11aff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c2bdedcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c2bdee7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c2bdc93c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c2bdc93c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c2bdc94738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c2bdc93874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c2bdc93874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c2bdc93874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c2c259dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c2c25a6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c2c258e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c2c25b9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf4de76082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c2bbeb3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c,0x69,0x67,0x68,0x74,0x24,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3a,0x3a,0x3a,0x3a,0x0,0x5d,0x2f,0x0,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3a,0x3a,0x3a,0x3a,0x0,0x5d,0x2f,0x0,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3d,0x24,0x5b, Step #5: light$:::::::::::::::::::::::=\012=\012=\012=\012=\012=\012=\012=?\012=\012=\012=\012=\012=\012::::\000]/\000::::::::::::::::::::::=\012=\012=\012=\012=\012=\012=\012=\012::::\000]/\000::::::::::::::::::::::=$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-ce6679080a5d848e38b76bf6c86b8fe5ce6bca5e Step #5: Base64: bGlnaHQkOjo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo9Cj0KPQo9Cj0KPQo9Cj0/Cj0KPQo9Cj0KPQo6Ojo6AF0vADo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo9Cj0KPQo9Cj0KPQo9Cj0KOjo6OgBdLwA6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6PSRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4466 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3958703569 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e389a5810, 0x555e38b8f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e38b8f020,0x555e3aa270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce6679080a5d848e38b76bf6c86b8fe5ce6bca5e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5579 processed earlier; will process 5450 files now Step #5: ==160852== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555e2f49a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e35aff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e35ae25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e35ae24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e2f4a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e2f401b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e2f3fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e2f492c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e32461f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e32461f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e32461f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e32461f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e32461f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e32461f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e32461f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e32461f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e32461f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e32461f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e346f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e31423b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e3142ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e311dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e311dac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e311db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e311da874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e311da874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e311da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e35ae4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e35aed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e35ad5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e35b00112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3cd14e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e2f3fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x54,0x5b,0x32,0x5b,0x5d,0x45,0x0,0x5c,0x66,0x0,0x0,0x0,0x0,0x0,0x0,0x3a,0x5c,0x78,0x7f,0x30,0x63,0x63,0x62,0x63,0x0,0x0,0x0,0x0,0x7c,0x0,0x2d,0x31,0x5f,0x74,0x79,0x70,0x65,0x41,0x62,0x6b,0x63,0x63,0x63,0x63,0x63,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x32,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x73,0x6c,0x5c,0x74,0x73,0x61,0x2e,0x64,0x65,0x76,0x2f,0x70,0x72,0x6f,0x76,0x65,0x6e,0x61,0x6e,0x63,0x65,0x2f,0x76,0x30,0x2e,0x32,0x2d,0x32,0x66,0x61,0x6c,0x73,0x65,0x6b,0x63,0x63,0x63,0x63,0x0,0x7c,0x22,0x22,0x3a,0x0,0x0,0x0,0x3a,0x64,0x6b,0x9e,0x9c,0x9c,0x9c,0x63,0x63,0x5c,0x78,0x30,0x30,0x0,0x0,0x0,0x54,0x5b,0x30,0x44,0x0,0x0,0x3a,0x0,0x0, Step #5: \000\000\000T[2[]E\000\\f\000\000\000\000\000\000:\\x\1770ccbc\000\000\000\000|\000-1_typeAbkccccc\000\000\000\000\000\000-2https://sl\\tsa.dev/provenance/v0.2-2falsekcccc\000|\"\":\000\000\000:dk\236\234\234\234cc\\x00\000\000\000T[0D\000\000:\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-07b92ad85078be576b59131bba64d052fd2e0b37 Step #5: Base64: AAAAVFsyW11FAFxmAAAAAAAAOlx4fzBjY2JjAAAAAHwALTFfdHlwZUFia2NjY2NjAAAAAAAALTJodHRwczovL3NsXHRzYS5kZXYvcHJvdmVuYW5jZS92MC4yLTJmYWxzZWtjY2NjAHwiIjoAAAA6ZGuenJycY2NceDAwAAAAVFswRAAAOgAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4467 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3959208939 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a288803810, 0x55a2889ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a2889ed020,0x55a28a8850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/07b92ad85078be576b59131bba64d052fd2e0b37' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5580 processed earlier; will process 5449 files now Step #5: ==160888== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a27f2f89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a28595d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2859405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2859404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a27f2fed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a27f25fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a27f25a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a27f2f0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a2822bff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a2822bff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a2822bff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a2822bff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a2822bff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a2822bff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a2822bff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a2822bff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a2822bff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a2822bff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a284554f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a281281b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a28128cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a281038c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a281038c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a281039738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a281038874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a281038874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a281038874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a285942abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a28594b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a285933699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a28595e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb821e65082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a27f258b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x7f,0x7f,0x28,0x0,0x0,0x72,0x0,0x0,0x55,0x55,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x28,0x0,0x72,0x64, Step #5: = \177\177(\000\000r\000\000UU\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000(\000rd Step #5: artifact_prefix='./'; Test unit written to ./oom-1801b50e8af5a4088ee210918d3318fd7f3392a4 Step #5: Base64: PSB/fygAAHIAAFVVAAAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAoAHJk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4468 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3959712031 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa12f23810, 0x55aa1310d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa1310d020,0x55aa14fa50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1801b50e8af5a4088ee210918d3318fd7f3392a4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5581 processed earlier; will process 5448 files now Step #5: ==160924== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aa09a189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa1007d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa100605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa100604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa09a1ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa0997fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa0997a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa09a10c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa0c9dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa0c9dff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa0c9dff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa0c9dff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa0c9dff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa0c9dff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa0c9dff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa0c9dff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa0c9dff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa0c9dff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa0ec74f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa0b9a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa0b9acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa0b758c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa0b758c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa0b759738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa0b758874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa0b758874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa0b758874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa10062abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa1006b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa10053699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa1007e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf85ccc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa09978b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x67,0x6c,0x79,0x66,0x66,0x67,0x7f,0x66,0x0,0x7f,0x66,0x3b,0x67,0x3f,0x49,0x7f,0x7f,0x12,0x6d,0x0,0x0,0x0,0x0,0x0,0x0,0x74,0x67,0x6c,0x79,0x67,0x7f,0x66,0x3b,0x67,0x66,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3f,0x67,0x3f,0x67,0x3f,0x6e, Step #5: tglyffg\177f\000\177f;g?I\177\177\022m\000\000\000\000\000\000tglyg\177f;gf\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000?g?g?n Step #5: artifact_prefix='./'; Test unit written to ./oom-533799722ea8ba1e50728fbe0c952f481703684e Step #5: Base64: dGdseWZmZ39mAH9mO2c/SX9/Em0AAAAAAAB0Z2x5Z39mO2dmAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAP2c/Zz9u Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4469 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3960229430 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7d8c2b810, 0x55f7d8e1501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7d8e15020,0x55f7dacad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/533799722ea8ba1e50728fbe0c952f481703684e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5582 processed earlier; will process 5447 files now Step #5: ==160960== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f7cf7209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7d5d85898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7d5d685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7d5d684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f7cf726d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f7cf687b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f7cf682355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f7cf718c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7d26e7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7d26e7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7d26e7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7d26e7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7d26e7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7d26e7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7d26e7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7d26e7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7d26e7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7d26e7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7d497cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f7d16a9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f7d16b4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f7d1460c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f7d1460c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f7d1461738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f7d1460874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f7d1460874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f7d1460874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7d5d6aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7d5d73928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7d5d5b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7d5d86112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f48a1195082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f7cf680b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd6,0xae,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x0,0x4f,0x0,0x0,0x9d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x74,0x72,0x65,0x61,0x6d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x80,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0xd5,0x96,0xc8, Step #5: \326\256\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\000O\000\000\235\000\000\000\000\000\000\000tream\000\000\000\000\000\000\000\000\001\000\200\012\000\000\000\000\000\000\325\226\310 Step #5: artifact_prefix='./'; Test unit written to ./oom-e3a33a941e17d70439e9925449e8a564ffe72a1b Step #5: Base64: 1q4AAAAAAAAAAAAAAAAAAAAAACIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIgBPAACdAAAAAAAAAHRyZWFtAAAAAAAAAAABAIAKAAAAAAAA1ZbI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4470 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3960727923 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559f07aaf810, 0x559f07c9901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559f07c99020,0x559f09b310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e3a33a941e17d70439e9925449e8a564ffe72a1b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5583 processed earlier; will process 5446 files now Step #5: ==160996== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559efe5a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559f04c09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559f04bec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559f04bec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559efe5aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559efe50bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559efe506355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559efe59cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559f0156bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559f0156bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559f0156bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559f0156bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559f0156bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559f0156bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559f0156bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559f0156bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559f0156bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559f0156bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559f03800f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559f0052db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559f00538be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559f002e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559f002e4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559f002e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559f002e4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559f002e4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559f002e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559f04beeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559f04bf7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559f04bdf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559f04c0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88410e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559efe504b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1e,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a, Step #5: \036**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012**\012**\012**\012**\012** Step #5: artifact_prefix='./'; Test unit written to ./oom-f320ef89c9e9aeecbaf3e8a5cf62a51f9e65d048 Step #5: Base64: HioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAoqKgoqKgoqKgoqKgoqKg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4471 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3961233509 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f88fdee810, 0x55f88ffd801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f88ffd8020,0x55f891e700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f320ef89c9e9aeecbaf3e8a5cf62a51f9e65d048' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5584 processed earlier; will process 5445 files now Step #5: ==161032== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8868e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f88cf48898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f88cf2b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f88cf2b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8868e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f88684ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f886845355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8868dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8898aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8898aaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8898aaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8898aaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8898aaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8898aaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8898aaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8898aaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8898aaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8898aaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f88bb3ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f88886cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f888877be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f888623c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f888623c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f888624738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f888623874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f888623874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f888623874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f88cf2dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f88cf36928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f88cf1e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f88cf49112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb06daf4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f886843b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x25,0x0,0x3d,0x2,0x4,0x1,0x43,0x48,0x41,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xae,0x0,0x63,0x72,0x79,0x73,0x74,0x61,0x6c,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0xe2,0x80,0xae,0x0,0x63,0x72,0x79,0x73,0x74,0x61,0x6c,0x11,0x0,0x0,0x0,0x0,0x0, Step #5: ID3\002%\000=\002\004\001CHA\000\000\021\000\000\000\000\000\000\000\000\002\000\000\342\200\256\000\000\000CHA\000\000\021\000\000\000\000\000\000\000\000\002\000\000\342\200\256\000\000\000CHA\000\000\021\000\000\000\000\000\000\000\000\000\000\000\342\200\256\000crystal\021\000\000\000\000\000\000\000\000\002\000\000\342\200\256\000\000\000CHA\000\000\021\000\000\000\000\000\000\000\000\002\000\000\342\200\256\000crystal\021\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1372b20b3a2d889e9c2731df8ae40d52829ae639 Step #5: Base64: SUQzAiUAPQIEAUNIQQAAEQAAAAAAAAAAAgAA4oCuAAAAQ0hBAAARAAAAAAAAAAACAADigK4AAABDSEEAABEAAAAAAAAAAAAAAOKArgBjcnlzdGFsEQAAAAAAAAAAAgAA4oCuAAAAQ0hBAAARAAAAAAAAAAACAADigK4AY3J5c3RhbBEAAAAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4472 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3961733554 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d7b1c74810, 0x55d7b1e5e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d7b1e5e020,0x55d7b3cf60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1372b20b3a2d889e9c2731df8ae40d52829ae639' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5585 processed earlier; will process 5444 files now Step #5: ==161068== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d7a87699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d7aedce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7aedb15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7aedb14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d7a876fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d7a86d0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d7a86cb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d7a8761c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d7ab730f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d7ab730f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d7ab730f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d7ab730f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d7ab730f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d7ab730f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d7ab730f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d7ab730f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d7ab730f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d7ab730f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d7ad9c5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d7aa6f2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d7aa6fdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d7aa4a9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d7aa4a9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d7aa4aa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d7aa4a9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d7aa4a9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d7aa4a9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d7aedb3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d7aedbc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d7aeda4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d7aedcf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3121ae0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d7a86c9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0x9,0x48,0x5c,0xa,0x48,0x5c,0x2,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0x9,0x48,0x5c,0xa,0x48,0x5c,0x9,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0x9,0x48,0x5c,0xa,0x48,0x5c,0x2,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xc0,0x48,0x5c,0xa,0x48,0x5c,0xca,0x48,0x5c,0xa,0x48,0x5c,0xa,0x48,0x5c,0xc0,0x48,0x5c,0xa,0x48,0x5c,0xca,0x48,0x5c,0xa,0x48,0x5c,0xa,0x8,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xcd,0xce,0xce,0x8a,0x8f,0x1,0x0, Step #5: H\\\012H\\\012H\\\012H\\\011H\\\012H\\\002H\\\012H\\\012H\\\012H\\\012H\\\012H\\\012H\\\011H\\\012H\\\011H\\\012H\\\012H\\\012H\\\012H\\\012H\\\012H\\\011H\\\012H\\\002H\\\012H\\\012H\\\012H\\\012H\\\012H\\\012H\\\300H\\\012H\\\312H\\\012H\\\012H\\\300H\\\012H\\\312H\\\012H\\\012\010\377\377\377\377\377\377\377\377\315\316\316\212\217\001\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8ccf4548c824e4accb15b07fcbad7ea373521263 Step #5: Base64: SFwKSFwKSFwKSFwJSFwKSFwCSFwKSFwKSFwKSFwKSFwKSFwKSFwJSFwKSFwJSFwKSFwKSFwKSFwKSFwKSFwKSFwJSFwKSFwCSFwKSFwKSFwKSFwKSFwKSFwKSFzASFwKSFzKSFwKSFwKSFzASFwKSFzKSFwKSFwKCP//////////zc7Oio8BAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4473 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3962239316 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564f94b1e810, 0x564f94d0801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564f94d08020,0x564f96ba00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ccf4548c824e4accb15b07fcbad7ea373521263' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5586 processed earlier; will process 5443 files now Step #5: ==161104== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564f8b6139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f91c78898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f91c5b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f91c5b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f8b619d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f8b57ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f8b575355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f8b60bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f8e5daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f8e5daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f8e5daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f8e5daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f8e5daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f8e5daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f8e5daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f8e5daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f8e5daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f8e5daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f9086ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f8d59cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f8d5a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f8d353c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f8d353c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f8d354738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f8d353874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f8d353874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f8d353874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f91c5dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f91c66928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f91c4e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f91c79112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27ccee4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f8b573b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x69,0x6c,0x65,0x3a,0x2f,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x9,0x69, Step #5: file:/\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011\011i Step #5: artifact_prefix='./'; Test unit written to ./oom-51376b07d21ae0e794aee9db57f143c0d1d09fe5 Step #5: Base64: ZmlsZTovCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJaQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4474 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3962740047 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56358fcec810, 0x56358fed601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56358fed6020,0x563591d6e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/51376b07d21ae0e794aee9db57f143c0d1d09fe5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5587 processed earlier; will process 5442 files now Step #5: #1 pulse cov: 3823 ft: 3824 exec/s: 0 rss: 174Mb Step #5: ==161140== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5635867e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56358ce46898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56358ce295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56358ce294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5635867e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563586748b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563586743355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5635867d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5635897a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5635897a8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5635897a8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5635897a8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5635897a8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5635897a8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5635897a8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5635897a8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5635897a8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5635897a8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56358ba3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56358876ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563588775be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563588521c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563588521c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563588522738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563588521874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563588521874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563588521874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56358ce2babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56358ce34928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56358ce1c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56358ce47112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b97abb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563586741b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x54,0x49,0x54,0x4c,0x45,0x20,0x22,0x22,0xa,0x46,0x49,0x4c,0x45,0x20,0x22,0x22,0x20,0x22,0x22, Step #5: TITLE \"\"\012TITLE \"\"\012TITLE \"\"\012TITLE \"\"\012TITLE \"\"\012TITLE \"\"\012TITLE \"\"\012TITLE \"\"\012TITLE \"\"\012TITLE \"\"\012TITLE \"\"\012TITLE \"\"\012TITLE \"\"\012TITLE \"\"\012FILE \"\" \"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-0975080c6cfcee3b5ad2871e0a1618f315a64548 Step #5: Base64: VElUTEUgIiIKVElUTEUgIiIKVElUTEUgIiIKVElUTEUgIiIKVElUTEUgIiIKVElUTEUgIiIKVElUTEUgIiIKVElUTEUgIiIKVElUTEUgIiIKVElUTEUgIiIKVElUTEUgIiIKVElUTEUgIiIKVElUTEUgIiIKVElUTEUgIiIKRklMRSAiIiAiIg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4475 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3963289155 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ce04715810, 0x55ce048ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ce048ff020,0x55ce067970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0975080c6cfcee3b5ad2871e0a1618f315a64548' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5589 processed earlier; will process 5440 files now Step #5: #1 pulse cov: 11641 ft: 11642 exec/s: 0 rss: 194Mb Step #5: ==161176== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cdfb20a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ce0186f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ce018525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ce018524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cdfb210d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cdfb171b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cdfb16c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cdfb202c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cdfe1d1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cdfe1d1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cdfe1d1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cdfe1d1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cdfe1d1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cdfe1d1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cdfe1d1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cdfe1d1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cdfe1d1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cdfe1d1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ce00466f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cdfd193b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cdfd19ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cdfcf4ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cdfcf4ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cdfcf4b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cdfcf4a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cdfcf4a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cdfcf4a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ce01854abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ce0185d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ce01845699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ce01870112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f40e45c7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cdfb16ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x39,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xe2,0x80,0x88,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xdb,0x80,0x32,0x35,0x35,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x3d,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x13,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0xf7,0x64,0x4c,0x0,0x0,0x1,0x0,0x0,0x39,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3f,0x0,0x8,0x0,0x0,0x0,0x31,0x30, Step #5: \333\200\333\2009\000*****************\342\200\210****************************\333\200255\000*******************=******\000\000\000\000\000\000\000\023**\000\000\000\000\000\367dL\000\000\001\000\0009\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000?\000\010\000\000\00010 Step #5: artifact_prefix='./'; Test unit written to ./oom-0e653c56966dfbc5485682eaa72ee2bab21a4b5d Step #5: Base64: 24DbgDkAKioqKioqKioqKioqKioqKirigIgqKioqKioqKioqKioqKioqKioqKioqKioqKioq24AyNTUAKioqKioqKioqKioqKioqKioqKj0qKioqKioAAAAAAAAAEyoqAAAAAAD3ZEwAAAEAADkAAAAAAAAAAAAAAAAAAAAAAAA/AAgAAAAxMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4476 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3963883745 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5572622ff810, 0x5572624e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5572624e9020,0x5572643810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0e653c56966dfbc5485682eaa72ee2bab21a4b5d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5591 processed earlier; will process 5438 files now Step #5: ==161212== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557258df49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55725f459898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55725f43c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55725f43c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557258dfad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557258d5bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557258d56355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557258decc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55725bdbbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55725bdbbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55725bdbbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55725bdbbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55725bdbbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55725bdbbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55725bdbbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55725bdbbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55725bdbbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55725bdbbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55725e050f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55725ad7db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55725ad88be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55725ab34c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55725ab34c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55725ab35738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55725ab34874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55725ab34874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55725ab34874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55725f43eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55725f447928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55725f42f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55725f45a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe8c5897082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557258d54b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x4b,0x60,0x20,0x2d,0x45,0x47,0x4b,0x60,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x63,0x6f,0x6e,0x64,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x4,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x76,0x24,0x24,0x24,0x24,0x24,0x24,0x34,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x20,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x20,0x2d,0x0,0x0,0x0,0x87,0x70,0x70,0x70,0x70,0x70,0x2d,0x2a,0x64,0x46,0xa,0x64,0xa,0x3f, Step #5: s-----BEGK` -EGK`$$$$$$$$$$$$cond$$$$$$$$$$$$\004$$$$$$$$$$$$$$$v$$$$$$4$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ -\000\000\000\207ppppp-*dF\012d\012? Step #5: artifact_prefix='./'; Test unit written to ./oom-fc334b8d196e0fef683163cb2923390edf61e1f9 Step #5: Base64: cy0tLS0tQkVHS2AgLUVHS2AkJCQkJCQkJCQkJCRjb25kJCQkJCQkJCQkJCQkBCQkJCQkJCQkJCQkJCQkJHYkJCQkJCQ0JCQkJCQkJCQkJCQkJCQkICQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkIC0AAACHcHBwcHAtKmRGCmQKPw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4477 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3964534786 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e546b43810, 0x55e546d2d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e546d2d020,0x55e548bc50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc334b8d196e0fef683163cb2923390edf61e1f9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5592 processed earlier; will process 5437 files now Step #5: ==161248== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e53d6389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e543c9d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e543c805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e543c804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e53d63ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e53d59fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e53d59a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e53d630c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e5405fff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e5405fff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e5405fff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e5405fff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e5405fff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e5405fff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e5405fff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e5405fff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e5405fff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e5405fff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e542894f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e53f5c1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e53f5ccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e53f378c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e53f378c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e53f379738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e53f378874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e53f378874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e53f378874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e543c82abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e543c8b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e543c73699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e543c9e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2a84949082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e53d598b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x67,0x62,0x49,0x54,0x32,0x58,0x0,0x0,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x64,0x61,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x43,0x4f,0x4d,0x2,0xdb,0xbf,0x9f,0xff, Step #5: ID3gbIT2X\000\000[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000da\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000COM\002\333\277\237\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-c111ecc003795cb4cef23174c5c0e00c6428351b Step #5: Base64: SUQzZ2JJVDJYAABbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1sAAAAAAAAAAAAAAAAAAAAAAABkYQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABDT00C27+f/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4478 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3965051011 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fa04b90810, 0x55fa04d7a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fa04d7a020,0x55fa06c120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c111ecc003795cb4cef23174c5c0e00c6428351b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5593 processed earlier; will process 5436 files now Step #5: ==161284== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f9fb6859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fa01cea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fa01ccd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fa01ccd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f9fb68bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f9fb5ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f9fb5e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f9fb67dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f9fe64cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f9fe64cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f9fe64cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f9fe64cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f9fe64cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f9fe64cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f9fe64cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f9fe64cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f9fe64cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f9fe64cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fa008e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f9fd60eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f9fd619be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f9fd3c5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f9fd3c5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f9fd3c6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f9fd3c5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f9fd3c5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f9fd3c5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fa01ccfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fa01cd8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fa01cc0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fa01ceb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0da0ceb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f9fb5e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x21,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0xa,0x4f,0x0,0x41,0x24,0x4,0x2d,0x29,0x2d,0x0,0x3a,0x4e,0x21,0x24,0x47,0x49,0x49,0x44,0x32,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x49,0x21,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0xa,0x4f,0x0,0x41,0x24,0x4,0x2d,0x29,0x2d,0x0,0x3a,0x4e,0x21,0x24,0x47,0x49,0x49,0x44,0x32,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x3,0x45,0x47,0x49,0x21,0x1,0x0,0x0,0x0,0x3,0x45,0x47,0x49,0x21,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x4,0x41,0x4f,0x24,0x2d,0x2d,0x29,0x2d,0x0,0x3a,0x4e,0x21,0x24,0x47,0x49,0x49,0x44,0x31,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x3, Step #5: \012-----B\012-----BEGI!\001\000\000\000\000\000\000-\012O\000A$\004-)-\000:N!$GIID2\002U -E\012\012I!\001\000\000\000\000\000\000-\012O\000A$\004-)-\000:N!$GIID2\002U -E\012\012\003EGI!\001\000\000\000\003EGI!\001\000\000\000\000\000\000\000\012\004AO$--)-\000:N!$GIID1\002U -E\012\012\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-8c2cb5702ba3357972ac35dc834cdcde27df8030 Step #5: Base64: Ci0tLS0tQgotLS0tLUJFR0khAQAAAAAAAC0KTwBBJAQtKS0AOk4hJEdJSUQyAlUgLUUKCkkhAQAAAAAAAC0KTwBBJAQtKS0AOk4hJEdJSUQyAlUgLUUKCgNFR0khAQAAAANFR0khAQAAAAAAAAAKBEFPJC0tKS0AOk4hJEdJSUQxAlUgLUUKCgM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4479 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3965583655 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56180e767810, 0x56180e95101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56180e951020,0x5618107e90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c2cb5702ba3357972ac35dc834cdcde27df8030' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5594 processed earlier; will process 5435 files now Step #5: #1 pulse cov: 3678 ft: 3679 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 3933 ft: 4290 exec/s: 0 rss: 176Mb Step #5: ==161320== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56180525c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56180b8c1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56180b8a45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56180b8a44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561805262d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5618051c3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5618051be355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561805254c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561808223f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561808223f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561808223f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561808223f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561808223f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561808223f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561808223f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561808223f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561808223f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561808223f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56180a4b8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5618071e5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5618071f0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561806f9cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561806f9cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561806f9d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561806f9c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561806f9c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561806f9c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56180b8a6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56180b8af928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56180b897699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56180b8c2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68cde28082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5618051bcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0x21,0x20,0x54,0x68,0x69,0x6e,0x73,0x2e,0xa,0xa,0x73,0x70,0x6c,0x69,0x74,0x28,0x22,0x68,0x0,0x0,0x0,0x0,0x65,0x0,0x40,0x0,0x65,0x0,0x40,0x0,0x65,0x0,0x40,0x0,0x0,0x0,0xcd,0x8f,0x0,0x65,0x0,0x40,0x0,0x0,0x0,0xcd,0x8f,0x0,0x0,0x0,0x1d,0x0,0x0,0x0,0x0,0x0,0x40,0x0,0x65,0x0,0x40,0x0,0x65,0x0,0x40,0x0,0x0,0x0,0xcd,0x8f,0x0,0x65,0x0,0x40,0x0,0x0,0x0,0xcd,0x8f,0x0,0x0,0x0,0x1d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6c,0x6c,0x6f,0x22,0x29,0x3b,0xa,0xff,0xff,0x72,0xf0,0x9f,0x92,0xa9,0x69,0x6e,0x74,0x28,0x22,0x74,0x78,0x80,0x8f,0x51,0x51,0x51,0x51,0x70,0x71,0x51,0x51,0x51,0x51,0x7a, Step #5: //! Thins.\012\012split(\"h\000\000\000\000e\000@\000e\000@\000e\000@\000\000\000\315\217\000e\000@\000\000\000\315\217\000\000\000\035\000\000\000\000\000@\000e\000@\000e\000@\000\000\000\315\217\000e\000@\000\000\000\315\217\000\000\000\035\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000llo\");\012\377\377r\360\237\222\251int(\"tx\200\217QQQQpqQQQQz Step #5: artifact_prefix='./'; Test unit written to ./oom-bdb0cadb6521259ab58b8064edbe8ea2b64bb181 Step #5: Base64: Ly8hIFRoaW5zLgoKc3BsaXQoImgAAAAAZQBAAGUAQABlAEAAAADNjwBlAEAAAADNjwAAAB0AAAAAAEAAZQBAAGUAQAAAAM2PAGUAQAAAAM2PAAAAHQAAAAAAAAAAAAAAAAAAAAAAAGxsbyIpOwr//3Lwn5KpaW50KCJ0eICPUVFRUXBxUVFRUXo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4480 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3966208658 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b017b19810, 0x55b017d0301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b017d03020,0x55b019b9b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bdb0cadb6521259ab58b8064edbe8ea2b64bb181' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5598 processed earlier; will process 5431 files now Step #5: ==161356== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b00e60e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b014c73898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b014c565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b014c564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b00e614d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b00e575b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b00e570355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b00e606c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b0115d5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b0115d5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b0115d5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b0115d5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b0115d5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b0115d5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b0115d5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b0115d5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b0115d5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b0115d5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b01386af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b010597b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b0105a2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b01034ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b01034ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b01034f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b01034e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b01034e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b01034e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b014c58abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b014c61928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b014c49699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b014c74112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7742909082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b00e56eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x3d,0x7e,0x2d,0x3d,0x3d,0x25,0x3,0xd2,0x84,0x28,0xcb,0xb5,0x1,0x79,0x0,0x79,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x29,0x24,0xcb,0xbc,0xbc,0xbc,0xbc,0xb5, Step #5: ~$=~-==%\003\322\204(\313\265\001y\000y\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000)$\313\274\274\274\274\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-061fb998b2308f299742f808fb5951021b5b7fdc Step #5: Base64: fiQ9fi09PSUD0oQoy7UBeQB5AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAKSTLvLy8vLU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4481 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3966727455 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558e86edc810, 0x558e870c601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558e870c6020,0x558e88f5e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/061fb998b2308f299742f808fb5951021b5b7fdc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5599 processed earlier; will process 5430 files now Step #5: ==161392== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558e7d9d19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558e84036898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558e840195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558e840194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558e7d9d7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558e7d938b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558e7d933355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558e7d9c9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558e80998f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558e80998f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558e80998f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558e80998f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558e80998f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558e80998f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558e80998f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558e80998f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558e80998f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558e80998f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558e82c2df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558e7f95ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558e7f965be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558e7f711c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558e7f711c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558e7f712738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558e7f711874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558e7f711874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558e7f711874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558e8401babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558e84024928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558e8400c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558e84037112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d995f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558e7d931b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0xa,0x24,0x3a,0xa,0xa,0x20,0x24,0x3a,0xa,0x2d,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x24,0x3a,0xa,0x2d,0x20,0x2d,0x3a,0x20,0x24,0xa,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x24,0x3a,0xa,0x20,0x52,0x3a,0xa,0x2d,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x24,0x3a,0xa,0x20,0x24,0x3a,0xa,0x2d,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x24,0x3a,0xa,0x20,0x24,0x3a,0xa,0x24,0x3a,0xa,0x2d,0xa,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x24,0x3a,0xa,0x20,0x24,0x3a,0xa,0x2d,0x2d,0x2d, Step #5: ---\012$:\012\012 $:\012-:\012- $:\012$:\012- -: $\012$:\012- $:\012$:\012 R:\012-:\012- $:\012$:\012- $:\012- $:\012$:\012 $:\012-:\012- $:\012- $:\012$:\012- $:\012$:\012 $:\012$:\012-\012$:\012- $:\012$:\012- $:\012- $:\012$:\012 $:\012--- Step #5: artifact_prefix='./'; Test unit written to ./oom-a7737f0e5b8aed70918d2edf7972cd10c87086e9 Step #5: Base64: LS0tCiQ6CgogJDoKLToKLSAkOgokOgotIC06ICQKJDoKLSAkOgokOgogUjoKLToKLSAkOgokOgotICQ6Ci0gJDoKJDoKICQ6Ci06Ci0gJDoKLSAkOgokOgotICQ6CiQ6CiAkOgokOgotCiQ6Ci0gJDoKJDoKLSAkOgotICQ6CiQ6CiAkOgotLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4482 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3967258231 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55971c7d5810, 0x55971c9bf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55971c9bf020,0x55971e8570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a7737f0e5b8aed70918d2edf7972cd10c87086e9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5600 processed earlier; will process 5429 files now Step #5: #1 pulse cov: 4166 ft: 4167 exec/s: 0 rss: 177Mb Step #5: ==161428== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5597132ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55971992f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5597199125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5597199124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5597132d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559713231b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55971322c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5597132c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559716291f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559716291f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559716291f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559716291f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559716291f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559716291f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559716291f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559716291f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559716291f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559716291f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559718526f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559715253b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55971525ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55971500ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55971500ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55971500b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55971500a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55971500a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55971500a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559719914abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55971991d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559719905699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559719930112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8cdbd75082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55971322ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x69,0x6f,0x6e,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x35,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37,0x3a,0x7b,0x24,0x37, Step #5: $3::{$7:{$7:{$7:{$7:{$7:{$7:{$7:{$7:{$ion:{$7:{$7:{$7:{$7:{$7:{$7:{$7:{$7:{$7:{$7:{$7:{$7:{$7:{$7:{$7:{$5:{$7:{$7:{$7:{$7:{$7:{$7:{$7:{$7 Step #5: artifact_prefix='./'; Test unit written to ./oom-269c12cadbc8e2edb07338c0edac41b5d9146f8c Step #5: Base64: JDM6OnskNzp7JDc6eyQ3OnskNzp7JDc6eyQ3OnskNzp7JDc6eyRpb246eyQ3OnskNzp7JDc6eyQ3OnskNzp7JDc6eyQ3OnskNzp7JDc6eyQ3OnskNzp7JDc6eyQ3OnskNzp7JDc6eyQ1OnskNzp7JDc6eyQ3OnskNzp7JDc6eyQ3OnskNzp7JDc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4483 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3967826044 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fea1697810, 0x55fea188101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fea1881020,0x55fea37190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/269c12cadbc8e2edb07338c0edac41b5d9146f8c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5602 processed earlier; will process 5427 files now Step #5: ==161464== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fe9818c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe9e7f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe9e7d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe9e7d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe98192d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe980f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe980ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe98184c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe9b153f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe9b153f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe9b153f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe9b153f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe9b153f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe9b153f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe9b153f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe9b153f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe9b153f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe9b153f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe9d3e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe9a115b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe9a120be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe99eccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe99eccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe99ecd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe99ecc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe99ecc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe99ecc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe9e7d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe9e7df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe9e7c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe9e7f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7618825082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe980ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x21,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0xa,0x4f,0x0,0x41,0x24,0x4,0x2d,0x29,0x2d,0x0,0x3a,0x4e,0x21,0x24,0x47,0x49,0x49,0x44,0x32,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x49,0x21,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0xa,0x4f,0x0,0x41,0x24,0x4,0x2d,0x29,0x2d,0x0,0x3a,0x4e,0x21,0x24,0x47,0x49,0x49,0x44,0x32,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x3,0x45,0x47,0x49,0x21,0x1,0x0,0x0,0x0,0x3,0x45,0x47,0x49,0x21,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x4,0x41,0x4f,0x24,0x2d,0x2d,0x29,0x2d,0x0,0x3a,0x4e,0x21,0x24,0x47,0x49,0x49,0x44,0x32,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x3, Step #5: \012-----B\012-----BEGI!\001\000\000\000\000\000\000-\012O\000A$\004-)-\000:N!$GIID2\002U -E\012\012I!\001\000\000\000\000\000\000-\012O\000A$\004-)-\000:N!$GIID2\002U -E\012\012\003EGI!\001\000\000\000\003EGI!\001\000\000\000\000\000\000\000\012\004AO$--)-\000:N!$GIID2\002U -E\012\012\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-658417f24d264d396f39712b0a2b0b8287018509 Step #5: Base64: Ci0tLS0tQgotLS0tLUJFR0khAQAAAAAAAC0KTwBBJAQtKS0AOk4hJEdJSUQyAlUgLUUKCkkhAQAAAAAAAC0KTwBBJAQtKS0AOk4hJEdJSUQyAlUgLUUKCgNFR0khAQAAAANFR0khAQAAAAAAAAAKBEFPJC0tKS0AOk4hJEdJSUQyAlUgLUUKCgM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4484 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3968346240 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b360f96810, 0x55b36118001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b361180020,0x55b3630180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/658417f24d264d396f39712b0a2b0b8287018509' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5603 processed earlier; will process 5426 files now Step #5: ==161500== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b357a8b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b35e0f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b35e0d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b35e0d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b357a91d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b3579f2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b3579ed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b357a83c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b35aa52f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b35aa52f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b35aa52f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b35aa52f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b35aa52f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b35aa52f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b35aa52f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b35aa52f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b35aa52f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b35aa52f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b35cce7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b359a14b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b359a1fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b3597cbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b3597cbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b3597cc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b3597cb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b3597cb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b3597cb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b35e0d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b35e0de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b35e0c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b35e0f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe7b7501082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b3579ebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x63,0x24,0x24,0x32,0x24,0x25, Step #5: \000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000$c$$2$% Step #5: artifact_prefix='./'; Test unit written to ./oom-d709d896742fbed0e713153eceb970f9d4c3d9a3 Step #5: Base64: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACRjJCQyJCU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4485 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3968860507 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f8fcc2810, 0x556f8feac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f8feac020,0x556f91d440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d709d896742fbed0e713153eceb970f9d4c3d9a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5604 processed earlier; will process 5425 files now Step #5: ==161536== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556f867b79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f8ce1c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f8cdff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f8cdff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f867bdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f8671eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f86719355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f867afc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f8977ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f8977ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f8977ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f8977ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f8977ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f8977ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f8977ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f8977ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f8977ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f8977ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f8ba13f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f88740b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f8874bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f884f7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f884f7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f884f8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f884f7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f884f7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f884f7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f8ce01abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f8ce0a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f8cdf2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f8ce1d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feac9a19082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f86717b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x7e,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x7e,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x36,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x73,0x2d,0x3b, Step #5: 4444444444444444444444444444444444444444444444~444444444444444444444444444444444444444444444~444444444444444444444444444644444444444444s-; Step #5: artifact_prefix='./'; Test unit written to ./oom-b7d4dacee24dc15d35bc91153289374ffc013468 Step #5: Base64: NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NH40NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDR+NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NjQ0NDQ0NDQ0NDQ0NDQ0cy07 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4486 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3969371447 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56391c211810, 0x56391c3fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56391c3fb020,0x56391e2930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7d4dacee24dc15d35bc91153289374ffc013468' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5605 processed earlier; will process 5424 files now Step #5: ==161572== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563912d069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56391936b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56391934e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56391934e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563912d0cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563912c6db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563912c68355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563912cfec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563915ccdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563915ccdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563915ccdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563915ccdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563915ccdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563915ccdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563915ccdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563915ccdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563915ccdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563915ccdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563917f62f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563914c8fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563914c9abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563914a46c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563914a46c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563914a47738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563914a46874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563914a46874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563914a46874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563919350abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563919359928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563919341699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56391936c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2dbbd50082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563912c66b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x3d,0xa,0x2d,0xa,0x3d,0xa,0x2d,0x3d,0xa,0x2d,0x2d,0x2d,0xa,0x64,0xe2,0x81,0xa9,0x40,0xe2,0x80,0x85,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x3d,0xa,0x2d,0x3d,0xa,0x2d,0x2d,0x2d,0xa,0x64,0xe2,0x81,0xa9,0x40,0xe2,0x80,0x85,0x2d,0xa,0xf3,0xa0,0xf2,0x80,0xb2,0x23,0xa,0x68,0xa,0x23,0xf6,0x8c,0x2d,0x2d,0x2d,0x2d,0xa,0xff,0xef,0xff,0x3a,0xff,0x2d,0xa,0x73,0xa,0x64,0xe2,0x81,0xa9,0x40,0xe2,0x80,0x85,0x2d,0xa,0xf3,0xa0,0x80,0xb2,0x23,0xa,0x69,0xa,0x23,0xf6,0x8c,0x2d,0x2d,0x2d,0x2d,0xa,0xff,0xef,0xff,0x3a,0xff,0x3a,0xff,0x2d,0xa,0x73,0xa,0x64,0xa,0x23,0xa,0xf3,0xa0,0x80,0xa9,0x68,0xa,0x8a,0x10,0x2d,0x8f,0x7a,0x8f,0x8f,0x8f,0x8f,0x2d,0xa,0x2d, Step #5: \012-----\012=\012-\012=\012-=\012---\012d\342\201\251@\342\200\205-----\012=\012-=\012---\012d\342\201\251@\342\200\205-\012\363\240\362\200\262#\012h\012#\366\214----\012\377\357\377:\377-\012s\012d\342\201\251@\342\200\205-\012\363\240\200\262#\012i\012#\366\214----\012\377\357\377:\377:\377-\012s\012d\012#\012\363\240\200\251h\012\212\020-\217z\217\217\217\217-\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-a8f0a09d0e48a91f26f46002911dd46b9a24abe3 Step #5: Base64: Ci0tLS0tCj0KLQo9Ci09Ci0tLQpk4oGpQOKAhS0tLS0tCj0KLT0KLS0tCmTigalA4oCFLQrzoPKAsiMKaAoj9owtLS0tCv/v/zr/LQpzCmTigalA4oCFLQrzoICyIwppCiP2jC0tLS0K/+//Ov86/y0KcwpkCiMK86CAqWgKihAtj3qPj4+PLQot Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4487 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3969878647 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5654ff3a6810, 0x5654ff59001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5654ff590020,0x5655014280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a8f0a09d0e48a91f26f46002911dd46b9a24abe3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5606 processed earlier; will process 5423 files now Step #5: ==161608== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5654f5e9b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5654fc500898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5654fc4e35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5654fc4e34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5654f5ea1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5654f5e02b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5654f5dfd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5654f5e93c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5654f8e62f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5654f8e62f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5654f8e62f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5654f8e62f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5654f8e62f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5654f8e62f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5654f8e62f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5654f8e62f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5654f8e62f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5654f8e62f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5654fb0f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5654f7e24b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5654f7e2fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5654f7bdbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5654f7bdbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5654f7bdc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5654f7bdb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5654f7bdb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5654f7bdb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5654fc4e5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5654fc4ee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5654fc4d6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5654fc501112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdd34c93082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5654f5dfbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x0,0x22,0x54,0x4b,0x4e,0x2,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x6f,0x76,0x76,0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x49,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x76,0x4e,0x54,0x2d,0x60,0x2d,0x60,0x0,0x22,0x54,0x4b,0x4e,0x2,0x73,0x74,0x0,0x22,0x4e,0x54,0x2d,0x2d,0x2d,0xde,0x64,0x2a, Step #5: I\000\"TKN\002vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvovvx-----BIvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvNT-`-`\000\"TKN\002st\000\"NT---\336d* Step #5: artifact_prefix='./'; Test unit written to ./oom-ce66492bf25e4c126c1d58eb204275cadc9ddc8a Step #5: Base64: SQAiVEtOAnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dm92dngtLS0tLUJJdnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2TlQtYC1gACJUS04Cc3QAIk5ULS0t3mQq Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4488 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3970505837 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563f590a2810, 0x563f5928c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563f5928c020,0x563f5b1240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce66492bf25e4c126c1d58eb204275cadc9ddc8a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5607 processed earlier; will process 5422 files now Step #5: #1 pulse cov: 4039 ft: 4040 exec/s: 0 rss: 174Mb Step #5: ==161644== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563f4fb979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563f561fc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563f561df5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563f561df4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563f4fb9dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563f4fafeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563f4faf9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563f4fb8fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563f52b5ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563f52b5ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563f52b5ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563f52b5ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563f52b5ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563f52b5ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563f52b5ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563f52b5ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563f52b5ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563f52b5ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563f54df3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563f51b20b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563f51b2bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563f518d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563f518d7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563f518d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563f518d7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563f518d7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563f518d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563f561e1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563f561ea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563f561d2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563f561fd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff4830c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563f4faf7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1e,0x0,0x24,0x7b,0x37,0x7d,0x24,0x7f,0x32,0x7d,0x24,0x7b,0x5,0x0,0x0,0x0,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0x0,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0xf,0x38,0x7d,0x24,0x7b,0x32,0x26,0x7b,0x78,0x7d,0x24,0x7b,0x38,0x7b,0x38,0x7d,0x24,0x0,0x0,0x0,0x0,0x0,0x7b,0x38,0x7d,0xf8,0x0,0x0,0x0,0x0,0x0,0x0,0xba, Step #5: \036\000${7}$\1772}${\005\000\000\000\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\000\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\017\0178}${2&{x}${8{8}$\000\000\000\000\000{8}\370\000\000\000\000\000\000\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-6d51dbbd7904a3ef2dcb4eace1faf19ad3a559c3 Step #5: Base64: HgAkezd9JH8yfSR7BQAAAA8PDw8PDw8PDw8PDw8PDw8PDwAPDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDw8PDzh9JHsyJnt4fSR7OHs4fSQAAAAAAHs4ffgAAAAAAAC6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4489 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3971067781 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556511dff810, 0x556511fe901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556511fe9020,0x556513e810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6d51dbbd7904a3ef2dcb4eace1faf19ad3a559c3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5609 processed earlier; will process 5420 files now Step #5: ==161680== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5565088f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55650ef59898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55650ef3c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55650ef3c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5565088fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55650885bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556508856355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5565088ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55650b8bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55650b8bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55650b8bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55650b8bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55650b8bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55650b8bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55650b8bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55650b8bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55650b8bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55650b8bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55650db50f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55650a87db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55650a888be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55650a634c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55650a634c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55650a635738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55650a634874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55650a634874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55650a634874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55650ef3eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55650ef47928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55650ef2f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55650ef5a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3dbdcf7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556508854b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x2e,0x2e,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x72,0x61,0x64,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0xe2,0x80,0x8f,0x28,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x31,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0xd,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7b,0xd7,0x83,0xd7,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x28,0x7c,0x9d,0x28,0x7c,0x28,0x7c,0x2e,0x2e,0x8,0x7c,0x2e,0x2e,0x2e,0x79,0x2e, Step #5: |..(|(|(|(rad|(|(|(|(|(|(|(|\342\200\217((|(|(|(|(|(|(|(|1|(|(|(|(|(|(|(|(|(|(|(|(|(|(|(|(\015(|(|(|(|(|({\327\203\327|(|(|(|(|(|(|(|(|(|(|(|(|(|\235(|(|..\010|...y. Step #5: artifact_prefix='./'; Test unit written to ./oom-ef329d6b8640365c15c31f8463357f256a77b525 Step #5: Base64: fC4uKHwofCh8KHJhZHwofCh8KHwofCh8KHwofOKAjygofCh8KHwofCh8KHwofCh8MXwofCh8KHwofCh8KHwofCh8KHwofCh8KHwofCh8KHwoDSh8KHwofCh8KHwoe9eD13wofCh8KHwofCh8KHwofCh8KHwofCh8KHwofJ0ofCh8Li4IfC4uLnku Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4490 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3971579344 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56130c892810, 0x56130ca7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56130ca7c020,0x56130e9140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ef329d6b8640365c15c31f8463357f256a77b525' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5610 processed earlier; will process 5419 files now Step #5: ==161716== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5613033879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5613099ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613099cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613099cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56130338dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5613032eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5613032e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56130337fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56130634ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56130634ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56130634ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56130634ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56130634ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56130634ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56130634ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56130634ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56130634ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56130634ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5613085e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561305310b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56130531bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5613050c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5613050c7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5613050c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5613050c7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5613050c7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5613050c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5613099d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5613099da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5613099c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5613099ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0645029082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5613032e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x27,0xa,0x61,0x20,0x30,0x2e,0x31,0x2e,0x35,0x2e,0x39,0xa,0x61,0x20,0x30,0x2e,0x30,0x2e,0x35,0x2e,0x39,0xa,0x61,0x20,0x30,0x2e,0x31,0x2e,0x35,0x2e,0x39,0xa,0x61,0x20,0x30,0x2e,0x31,0x2e,0x35,0x2e,0x30,0xa,0x61,0x20,0x31,0x2e,0x31,0x2e,0x35,0x2e,0x30,0xa,0x61,0x20,0x30,0x2e,0x31,0x2e,0x35,0x2e,0x38,0xa,0x61,0x20,0x30,0x2e,0x31,0x2e,0x31,0x2e,0x39,0xa,0x6e,0x74,0x6f,0x2e,0x30,0x2e,0x35,0x2e,0x39,0xa,0x61,0x20,0x30,0x2e,0x31,0x2e,0x35,0x2e,0x39,0xa,0x61,0x20,0x33,0x66,0x50,0x44,0x62,0x6a,0x4d,0x5a,0x50,0x54,0x34,0x38,0x67,0x66,0x69,0x52,0x54,0x32,0x4f,0x4f,0x35,0x58,0x78,0x31,0x4a,0x33,0x39,0x73,0x2f,0x59,0x2f,0x46,0x53,0x77,0x73,0x30, Step #5: onion-ke'\012a 0.1.5.9\012a 0.0.5.9\012a 0.1.5.9\012a 0.1.5.0\012a 1.1.5.0\012a 0.1.5.8\012a 0.1.1.9\012nto.0.5.9\012a 0.1.5.9\012a 3fPDbjMZPT48gfiRT2OO5Xx1J39s/Y/FSws0 Step #5: artifact_prefix='./'; Test unit written to ./oom-681c2282d8f86971b4d662669504a5f390144a80 Step #5: Base64: b25pb24ta2UnCmEgMC4xLjUuOQphIDAuMC41LjkKYSAwLjEuNS45CmEgMC4xLjUuMAphIDEuMS41LjAKYSAwLjEuNS44CmEgMC4xLjEuOQpudG8uMC41LjkKYSAwLjEuNS45CmEgM2ZQRGJqTVpQVDQ4Z2ZpUlQyT081WHgxSjM5cy9ZL0ZTd3Mw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4491 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3972091269 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563730ae7810, 0x563730cd101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563730cd1020,0x563732b690e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/681c2282d8f86971b4d662669504a5f390144a80' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5611 processed earlier; will process 5418 files now Step #5: ==161752== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5637275dc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56372dc41898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56372dc245dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56372dc244fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5637275e2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563727543b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56372753e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5637275d4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56372a5a3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56372a5a3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56372a5a3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56372a5a3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56372a5a3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56372a5a3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56372a5a3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56372a5a3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56372a5a3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56372a5a3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56372c838f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563729565b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563729570be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56372931cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56372931cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56372931d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56372931c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56372931c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56372931c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56372dc26abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56372dc2f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56372dc17699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56372dc42112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1ae57eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56372753cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x74,0x65,0x73,0x74,0x41,0x6c,0x6c,0x54,0x79,0x70,0x65,0x73,0x22,0x3a,0x7b,0x22,0x72,0x65,0x70,0x65,0x61,0x74,0x65,0x64,0x44,0x6f,0x75,0x62,0x6c,0x65,0x22,0x3a,0x5b,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x31,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x33,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x36,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x33,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x36,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x32,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x33,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x36,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x32,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x32,0xe2,0x80,0x8c,0x22,0x2c,0x22,0xe2,0x80,0x8c,0x22, Step #5: {\"testAllTypes\":{\"repeatedDouble\":[\"0\342\200\214\",\"1\342\200\214\",\"0\342\200\214\",\"3\342\200\214\",\"0\342\200\214\",\"6\342\200\214\",\"3\342\200\214\",\"6\342\200\214\",\"2\342\200\214\",\"3\342\200\214\",\"6\342\200\214\",\"2\342\200\214\",\"0\342\200\214\",\"2\342\200\214\",\"\342\200\214\" Step #5: artifact_prefix='./'; Test unit written to ./oom-1f88e9575ee3321738fc1eca8ffacde9cdaaff48 Step #5: Base64: eyJ0ZXN0QWxsVHlwZXMiOnsicmVwZWF0ZWREb3VibGUiOlsiMOKAjCIsIjHigIwiLCIw4oCMIiwiM+KAjCIsIjDigIwiLCI24oCMIiwiM+KAjCIsIjbigIwiLCIy4oCMIiwiM+KAjCIsIjbigIwiLCIy4oCMIiwiMOKAjCIsIjLigIwiLCLigIwi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4492 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3972594884 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b5bd91b810, 0x55b5bdb0501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b5bdb05020,0x55b5bf99d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f88e9575ee3321738fc1eca8ffacde9cdaaff48' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5612 processed earlier; will process 5417 files now Step #5: ==161788== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b5b44109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b5baa75898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b5baa585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b5baa584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b5b4416d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b5b4377b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b5b4372355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b5b4408c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b5b73d7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b5b73d7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b5b73d7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b5b73d7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b5b73d7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b5b73d7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b5b73d7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b5b73d7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b5b73d7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b5b73d7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b5b966cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b5b6399b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b5b63a4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b5b6150c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b5b6150c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b5b6151738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b5b6150874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b5b6150874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b5b6150874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b5baa5aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b5baa63928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b5baa4b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b5baa76112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9aaa340082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b5b4370b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xe2,0x80,0xa8,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xe2,0x80,0xa8,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x73,0x74,0x72,0x65,0x61,0x6d,0xa,0x1,0x14,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x29,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\342\200\250=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012\342\200\250=\012=\012=\012=stream\012\001\024=\012=\012=\012=\012=\012=\012=)=\012=\012==\012\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-5b25c515eb1c976793dea1ad57b6448b60ee6500 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj3igKg9Cgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoKPQo9Cj0KPQo9Cj0K4oCoPQo9Cj0KPXN0cmVhbQoBFD0KPQo9Cj0KPQo9Cj0pPQo9Cj09CgoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4493 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3973114142 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562674a03810, 0x562674bed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562674bed020,0x562676a850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5b25c515eb1c976793dea1ad57b6448b60ee6500' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5613 processed earlier; will process 5416 files now Step #5: ==161824== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56266b4f89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562671b5d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562671b405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562671b404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56266b4fed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56266b45fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56266b45a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56266b4f0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56266e4bff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56266e4bff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56266e4bff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56266e4bff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56266e4bff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56266e4bff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56266e4bff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56266e4bff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56266e4bff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56266e4bff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562670754f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56266d481b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56266d48cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56266d238c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56266d238c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56266d239738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56266d238874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56266d238874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56266d238874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562671b42abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562671b4b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562671b33699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562671b5e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efe350b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56266b458b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x29,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x1,0x0,0x27,0xf,0x55,0x20,0x6d,0x2e,0xf,0x2,0x55,0x20,0x6d,0x2e,0xf,0x31,0x54,0x30,0x0,0x61,0x65,0xdf,0x0,0x54,0x0,0x0,0x1f,0xa,0x3d,0xa,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0xa,0xa1,0x44,0x31,0x4,0xdf,0x0,0x65,0x61,0xcc,0x96,0x0,0x3,0xb,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xff, Step #5: \005--)--BEGIN =\012=\012=\012= =\012= i\012\012r=sef=\012=+=\012=\012=\012=\012D\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\001\000\000\000\000ID3\002\001\000'\017U m.\017\002U m.\0171T0\000ae\337\000T\000\000\037\012=\012\000----\012--\012\241D1\004\337\000ea\314\226\000\003\013skip_cl\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-91d45d6da966957a3636c8fdad92bf8de434b763 Step #5: Base64: BS0tKS0tQkVHSU4gPQo9Cj0KPSA9Cj0gaQoKcj1zZWY9Cj0rPQo9Cj0KPQpECj0KPQo9Cj0KPQo9Cj0KPQo9Cj0BAAAAAElEMwIBACcPVSBtLg8CVSBtLg8xVDAAYWXfAFQAAB8KPQoALS0tLQotLQqhRDEE3wBlYcyWAAMLc2tpcF9jbAp8ABD/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4494 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3973627380 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56372a674810, 0x56372a85e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56372a85e020,0x56372c6f60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/91d45d6da966957a3636c8fdad92bf8de434b763' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5614 processed earlier; will process 5415 files now Step #5: ==161860== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5637211699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5637277ce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5637277b15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5637277b14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56372116fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5637210d0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5637210cb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563721161c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563724130f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563724130f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563724130f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563724130f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563724130f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563724130f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563724130f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563724130f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563724130f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563724130f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5637263c5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5637230f2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5637230fdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563722ea9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563722ea9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563722eaa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563722ea9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563722ea9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563722ea9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5637277b3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5637277bc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5637277a4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5637277cf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3eeeeab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5637210c9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3, Step #5: \003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf65e7c31cf9be9f8ee524063977b5681e157e00 Step #5: Base64: AwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMD Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4495 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3974139279 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ffbaf8e810, 0x55ffbb17801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ffbb178020,0x55ffbd0100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf65e7c31cf9be9f8ee524063977b5681e157e00' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5615 processed earlier; will process 5414 files now Step #5: #1 pulse cov: 3906 ft: 3907 exec/s: 0 rss: 174Mb Step #5: ==161896== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ffb1a839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ffb80e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ffb80cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ffb80cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ffb1a89d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ffb19eab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ffb19e5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ffb1a7bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ffb4a4af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ffb4a4af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ffb4a4af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ffb4a4af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ffb4a4af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ffb4a4af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ffb4a4af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ffb4a4af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ffb4a4af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ffb4a4af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ffb6cdff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ffb3a0cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ffb3a17be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ffb37c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ffb37c3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ffb37c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ffb37c3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ffb37c3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ffb37c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ffb80cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ffb80d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ffb80be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ffb80e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f215e50b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ffb19e3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x75,0x63,0x5f,0x6b,0x72,0x5f,0xc7,0xa0,0x69,0x73,0x6f,0x38,0x38,0x5f,0xc7,0xa0,0x39,0x33,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x77,0x36,0x7f,0x72,0x5f,0xc7,0xa0,0x69,0x73,0x6f,0x38,0x38,0x36,0x30,0x5f,0x34,0x30,0x30,0x37,0x76,0x5f,0xc7,0xa0,0x31,0x35,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x77,0x37,0x7f,0x72,0x5f,0xc7,0xa0,0x69,0x73,0x6f,0x38,0x31,0x36,0x30,0x5f,0x38,0x30,0x31,0x34,0x76,0x5f,0xc7,0xa0,0x0,0x0,0x35,0x31,0x0,0x0,0x1,0x0,0x0,0x77,0x31,0x7f,0x72,0x5f,0xc7,0xa0,0x31,0x35,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x77,0x37,0x7f,0x72,0x5f,0xc7,0xa0,0x31,0x32,0x34,0x69,0x6f,0x38,0x73,0x5f,0x34,0x30,0x30,0x37,0x76,0x5f,0xc7,0xa0,0x31,0x35,0x0,0x31,0x7f,0x37,0x0,0x0,0x38, Step #5: euc_kr_\307\240iso88_\307\24093\000\000\000\000\001\000\000w6\177r_\307\240iso8860_4007v_\307\24015\000\000\000\000\001\000\000w7\177r_\307\240iso8160_8014v_\307\240\000\00051\000\000\001\000\000w1\177r_\307\24015\000\000\000\000\001\000\000w7\177r_\307\240124io8s_4007v_\307\24015\0001\1777\000\0008 Step #5: artifact_prefix='./'; Test unit written to ./oom-740b94bd3ad4d216aa17b57667b171f19a9263d7 Step #5: Base64: ZXVjX2tyX8egaXNvODhfx6A5MwAAAAABAAB3Nn9yX8egaXNvODg2MF80MDA3dl/HoDE1AAAAAAEAAHc3f3Jfx6Bpc284MTYwXzgwMTR2X8egAAA1MQAAAQAAdzF/cl/HoDE1AAAAAAEAAHc3f3Jfx6AxMjRpbzhzXzQwMDd2X8egMTUAMX83AAA4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4496 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3974698455 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559bd1d23810, 0x559bd1f0d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559bd1f0d020,0x559bd3da50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/740b94bd3ad4d216aa17b57667b171f19a9263d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5617 processed earlier; will process 5412 files now Step #5: ==161932== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559bc88189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559bcee7d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559bcee605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559bcee604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559bc881ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559bc877fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559bc877a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559bc8810c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559bcb7dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559bcb7dff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559bcb7dff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559bcb7dff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559bcb7dff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559bcb7dff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559bcb7dff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559bcb7dff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559bcb7dff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559bcb7dff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559bcda74f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559bca7a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559bca7acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559bca558c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559bca558c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559bca559738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559bca558874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559bca558874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559bca558874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559bcee62abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559bcee6b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559bcee53699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559bcee7e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8aba151082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559bc8778b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2c,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x44,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x48,0x48,0x46,0x48,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0x3d,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -,---\012N\012=\012=\012D=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012HHFH\012=\012=\012\012=\012=\012=\012=\012=\012\012===\012\012=\012=\012=\012\012mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-05bc1c44c1da435453dc39aae846d06d95a0fc3c Step #5: Base64: BS0tLS0tQkVHSU4gLSwtLS0KTgo9Cj0KRD0KPQoKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KSEhGSAo9Cj0KCj0KPQo9Cj0KPQoKPT09Cgo9Cj0KPQoKbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tPQo9Cj0KEA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4497 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3975226902 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56489d64c810, 0x56489d83601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56489d836020,0x56489f6ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/05bc1c44c1da435453dc39aae846d06d95a0fc3c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5618 processed earlier; will process 5411 files now Step #5: ==161968== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5648941419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56489a7a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56489a7895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56489a7894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564894147d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5648940a8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5648940a3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564894139c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564897108f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564897108f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564897108f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564897108f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564897108f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564897108f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564897108f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564897108f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564897108f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564897108f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56489939df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5648960cab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5648960d5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564895e81c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564895e81c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564895e82738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564895e81874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564895e81874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564895e81874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56489a78babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56489a794928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56489a77c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56489a7a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1349f44082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5648940a1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x18,0x24,0xa,0xc2,0xbd,0x7f,0x27,0x28,0x28,0x28,0x28,0x24,0x7b,0x31,0x7d,0x0,0x7b,0x31,0x31,0x7d,0x78,0x7b,0x32,0x7d,0x29,0x3,0x0,0x0,0x0,0x7b,0x32,0x7d,0x29,0x7b,0x33,0x7d,0xd7,0x84,0xcd,0x82,0xd6,0x84,0xcd,0x7c,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x8,0x7b,0x32,0x7d,0x29,0x7b,0x33,0x7d,0x29,0x7b,0x32,0x7d,0x29,0x7b,0x32,0x7d,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x8,0x18,0x3,0x58,0x31,0x63,0x28,0xa,0x8,0x18,0x3,0x58,0x31,0x0,0x43,0x48,0xf8,0x41,0xff,0xff,0xff,0xff,0xff,0x29,0x7b,0x18,0x3,0x58,0x31,0x63,0x28,0xa,0x8,0x18,0x3,0x58,0x31,0x0,0x43,0x48,0x41,0xff,0xff,0xff,0xff,0xff,0x29,0x7b,0x73,0x11,0x32,0x7d,0xe0,0xa1,0xb0,0x47, Step #5: (\030$\012\302\275\177'((((${1}\000{11}x{2})\003\000\000\000{2}){3}\327\204\315\202\326\204\315|\377\377\377\377\377\377\377\377\377\377\377\010{2}){3}){2}){2}\377\377\377\377\377\377\377\377\377\377\377\010\030\003X1c(\012\010\030\003X1\000CH\370A\377\377\377\377\377){\030\003X1c(\012\010\030\003X1\000CHA\377\377\377\377\377){s\0212}\340\241\260G Step #5: artifact_prefix='./'; Test unit written to ./oom-1541704e91546d991d586ee8779695e755b8e4a2 Step #5: Base64: KBgkCsK9fycoKCgoJHsxfQB7MTF9eHsyfSkDAAAAezJ9KXszfdeEzYLWhM18//////////////8IezJ9KXszfSl7Mn0pezJ9//////////////8IGANYMWMoCggYA1gxAENI+EH//////yl7GANYMWMoCggYA1gxAENIQf//////KXtzETJ94KGwRw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4498 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3975754188 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f68e156810, 0x55f68e34001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f68e340020,0x55f6901d80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1541704e91546d991d586ee8779695e755b8e4a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5619 processed earlier; will process 5410 files now Step #5: ==162004== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f684c4b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f68b2b0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f68b2935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f68b2934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f684c51d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f684bb2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f684bad355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f684c43c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f687c12f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f687c12f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f687c12f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f687c12f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f687c12f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f687c12f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f687c12f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f687c12f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f687c12f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f687c12f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f689ea7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f686bd4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f686bdfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f68698bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f68698bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f68698c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f68698b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f68698b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f68698b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f68b295abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f68b29e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f68b286699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f68b2b1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e94355082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f684babb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x45,0x58,0x50,0x20,0x20,0x30,0x7d,0x7d,0x7d,0x7d,0x7d,0x41,0x20,0x20,0x20,0xa,0x4c,0x41,0x42,0x20,0x20,0x32,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x30,0x34,0x2e,0x30,0x33,0x39,0x38,0x36,0x35,0x35,0x20,0x34,0x2e,0x33,0x36,0x31,0x23,0x37,0x36,0x32,0x45,0x2b,0x30,0x35,0x20,0x35,0x2e,0x38,0x33,0x39,0x38,0x36,0x36,0x32,0x34,0x33,0x33,0x45,0x2b,0x30,0x35,0xa,0x20,0x36,0x36,0x30,0x45,0x2b,0x30,0x36,0x20,0x41,0x2e,0x33,0x36,0x31,0x34,0x33,0x2e,0x50,0x41,0x54,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x6e,0x61,0x6e,0x20,0x20,0x20,0x35,0x20,0x3b,0x20,0x20,0x35,0x20,0x20,0x30,0x35,0xa,0x45,0x4f,0x49,0xa,0x45,0x4f,0x53,0xa, Step #5: EXP 0}}}}}A \012LAB 2\012 04.0398655 4.361#762E+05 5.8398662433E+05\012 660E+06 A.36143.PAT nan 5 ; 5 05\012EOI\012EOS\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-adc4a4c9c2edd4103acce65158d4ee04ecf52071 Step #5: Base64: RVhQICAwfX19fX1BICAgCkxBQiAgMgogICAgICAgMDQuMDM5ODY1NSA0LjM2MSM3NjJFKzA1IDUuODM5ODY2MjQzM0UrMDUKIDY2MEUrMDYgQS4zNjE0My5QQVQgICAgICAgICAgICAgICAgICAgICAgbmFuICAgNSA7ICA1ICAwNQpFT0kKRU9TCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4499 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3976274778 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d74ec10810, 0x55d74edfa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d74edfa020,0x55d750c920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/adc4a4c9c2edd4103acce65158d4ee04ecf52071' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5620 processed earlier; will process 5409 files now Step #5: ==162040== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d7457059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d74bd6a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d74bd4d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d74bd4d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d74570bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d74566cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d745667355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d7456fdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d7486ccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d7486ccf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d7486ccf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d7486ccf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d7486ccf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d7486ccf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d7486ccf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d7486ccf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d7486ccf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d7486ccf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d74a961f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d74768eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d747699be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d747445c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d747445c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d747446738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d747445874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d747445874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d747445874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d74bd4fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d74bd58928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d74bd40699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d74bd6b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1378bda082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d745665b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x1,0x1,0x1,0x1,0x0,0x1,0xd7,0xa3,0x2a,0x73,0x20,0x34,0x20,0x24,0x24,0x24,0x28,0x3f,0x6d,0x29,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x1,0x1,0x1,0x1,0x0,0x1,0xd7,0xa3,0x2a,0x73,0x20,0x34,0x20,0x24,0x24,0x24,0x28,0x3f,0x6d,0x29,0x24,0x2c,0x24,0x24,0x24,0x24,0x24,0x28,0x24,0x24, Step #5: \000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000z\000\000\000\000\000\000\000\000\000\000\000\000\001\001\001\001\001\000\001\327\243*s 4 $$$(?m)\000\000\000\000\000\000\000\000\000\000\000\000\000z\000\000\000\000\000\000\000\000\000\000\000\000\001\001\001\001\001\000\001\327\243*s 4 $$$(?m)$,$$$$$($$ Step #5: artifact_prefix='./'; Test unit written to ./oom-b3e982f17adb66094816d0e0094b2c09c3ddbecf Step #5: Base64: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAegAAAAAAAAAAAAAAAAEBAQEBAAHXoypzIDQgJCQkKD9tKQAAAAAAAAAAAAAAAAB6AAAAAAAAAAAAAAAAAQEBAQEAAdejKnMgNCAkJCQoP20pJCwkJCQkJCgkJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4500 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3976793633 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5559d3812810, 0x5559d39fc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5559d39fc020,0x5559d58940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3e982f17adb66094816d0e0094b2c09c3ddbecf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5621 processed earlier; will process 5408 files now Step #5: ==162076== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5559ca3079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5559d096c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5559d094f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5559d094f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5559ca30dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5559ca26eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5559ca269355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5559ca2ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5559cd2cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5559cd2cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5559cd2cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5559cd2cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5559cd2cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5559cd2cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5559cd2cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5559cd2cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5559cd2cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5559cd2cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5559cf563f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5559cc290b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5559cc29bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5559cc047c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5559cc047c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5559cc048738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5559cc047874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5559cc047874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5559cc047874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5559d0951abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5559d095a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5559d0942699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5559d096d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a365f3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5559ca267b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x0,0x0,0x1,0x20,0x0,0x60,0x1,0x0,0x2,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x20,0x0,0x4,0x13,0x43,0x4f,0x4d,0x60,0x1,0x20,0x0,0x60,0x1,0x2,0x0,0x0,0x32,0x1,0x3,0x20,0x63,0x6f,0x63,0x6f,0x6e,0x75,0x74,0x0,0x4,0x13,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x2e,0x0,0x3d,0xa,0x3d,0xa,0x0,0x0,0x20,0x0,0x4,0x13,0x43,0x4f,0x4d,0x60,0x1,0x0,0x0,0x20,0x0,0x60,0x1,0x43,0x4f,0x4d,0x33,0x0,0xa,0x3d,0xa,0x3d,0xa,0x5d,0x3d,0xa,0x3d,0xa,0x60,0x1,0x0,0x0,0x32,0x38,0x39,0x35, Step #5: ID3\004\000\000\001 \000`\001\000\002\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000\000 \000\004\023COM`\001 \000`\001\002\000\0002\001\003 coconut\000\004\023\012=\012==\012=\012\012=\012=\012=\012=\012.\000=\012=\012\000\000 \000\004\023COM`\001\000\000 \000`\001COM3\000\012=\012=\012]=\012=\012`\001\000\0002895 Step #5: artifact_prefix='./'; Test unit written to ./oom-cc70b06b3132716443ae3ab9d5f5703833a84a66 Step #5: Base64: SUQzBAAAASAAYAEAAgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoAACAABBNDT01gASAAYAECAAAyAQMgY29jb251dAAEEwo9Cj09Cj0KCj0KPQo9Cj0KLgA9Cj0KAAAgAAQTQ09NYAEAACAAYAFDT00zAAo9Cj0KXT0KPQpgAQAAMjg5NQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4501 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3977433209 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556be0603810, 0x556be07ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556be07ed020,0x556be26850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cc70b06b3132716443ae3ab9d5f5703833a84a66' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5622 processed earlier; will process 5407 files now Step #5: ==162112== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556bd70f89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556bdd75d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556bdd7405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556bdd7404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556bd70fed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556bd705fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556bd705a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556bd70f0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556bda0bff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556bda0bff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556bda0bff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556bda0bff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556bda0bff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556bda0bff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556bda0bff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556bda0bff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556bda0bff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556bda0bff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556bdc354f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556bd9081b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556bd908cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556bd8e38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556bd8e38c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556bd8e39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556bd8e38874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556bd8e38874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556bd8e38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556bdd742abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556bdd74b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556bdd733699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556bdd75e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f29c56a2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556bd7058b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x79,0x3c,0x74,0x54,0x52,0x3e,0x3c,0x73,0x54,0x52,0x3e,0x3c,0x74,0x61,0x62,0x6c,0x65,0x3e,0x3c,0x74,0x54,0x52,0x3e,0x3c,0x3c,0x73,0x65,0x6c,0x65,0x63,0x74,0x3e,0x3c,0x74,0x41,0x3e,0x3c,0x59,0x3e,0x3c,0x69,0x3e,0x3c,0x63,0x3e,0x3c,0x6c,0x3e,0x3c,0x58,0x3e,0x3c,0x65,0x3e,0x3c,0x41,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x41,0x3e,0x3c,0x59,0x3e,0x3c,0x69,0x3e,0x3c,0x63,0x3e,0x3c,0x6c,0x3e,0x3c,0x58,0x3e,0x3c,0x65,0x3e,0x3c,0x41,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x41,0x3e,0x3c,0x76,0x3e,0x3c,0x69,0x3e,0x3c,0x63,0x3e,0x3c,0x6c,0x3e,0x3c,0x58,0x3e,0x3c,0x65,0x3e,0x3c,0x41,0x3e,0x3c,0x74,0x3e,0x3c,0x74,0x42,0x3e,0x3c,0x76,0x3e,0x3c,0x69,0x3e,0x3c,0x63,0x3e,0x3c,0x6c,0x3e,0x3c,0x58,0x3e,0x3c,0x65,0x3e,0x3c, Step #5: y<tTR><sTR><table><tTR><<select><tA><Y><i><c><l><X><e><A><t><tA><Y><i><c><l><X><e><A><t><tA><v><i><c><l><X><e><A><t><tB><v><i><c><l><X><e>< Step #5: artifact_prefix='./'; Test unit written to ./oom-80e1b77ce3da9bc834b8f09aef7a3ce36217e3f0 Step #5: Base64: eTx0VFI+PHNUUj48dGFibGU+PHRUUj48PHNlbGVjdD48dEE+PFk+PGk+PGM+PGw+PFg+PGU+PEE+PHQ+PHRBPjxZPjxpPjxjPjxsPjxYPjxlPjxBPjx0Pjx0QT48dj48aT48Yz48bD48WD48ZT48QT48dD48dEI+PHY+PGk+PGM+PGw+PFg+PGU+PA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4502 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3977931586 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557df2b70810, 0x557df2d5a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557df2d5a020,0x557df4bf20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/80e1b77ce3da9bc834b8f09aef7a3ce36217e3f0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5623 processed earlier; will process 5406 files now Step #5: ==162148== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557de96659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557defcca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557defcad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557defcad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557de966bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557de95ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557de95c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557de965dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557dec62cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557dec62cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557dec62cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557dec62cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557dec62cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557dec62cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557dec62cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557dec62cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557dec62cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557dec62cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557dee8c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557deb5eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557deb5f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557deb3a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557deb3a5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557deb3a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557deb3a5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557deb3a5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557deb3a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557defcafabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557defcb8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557defca0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557defccb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7b0145a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557de95c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x20,0x0,0x2d,0x20,0x20,0x0,0x0,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x26,0x3e,0x24,0x40,0x3e,0x0,0x0,0x26,0x26,0x26,0x26,0x24,0x30,0x26,0x26,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x61,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x5b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x26,0x26,0x26,0x26,0x26,0xc3,0x9f,0x5b,0x5e,0xf4,0x88,0x8f,0xbf,0x5d,0x26,0x26,0x26,0x62,0x6f,0x6c,0x64,0x26,0x3e,0x24,0x30,0x26,0x26,0x62,0x6f,0x6c,0x64,0x26,0x70,0x69,0x3e,0x24,0x30, Step #5: - \000- \000\000&&&&&&&&>$@>\000\000&&&&$0&&{{{{{{{{{{{{{{{{{{{{{{{{{{a{{{{{{{{{[{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{&&&&&\303\237[^\364\210\217\277]&&&bold&>$0&&bold&pi>$0 Step #5: artifact_prefix='./'; Test unit written to ./oom-d7ab384c9e26772de6fe3e496b2555b7ef0d7b4c Step #5: Base64: LSAgAC0gIAAAJiYmJiYmJiY+JEA+AAAmJiYmJDAmJnt7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7YXt7e3t7e3t7e1t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7JiYmJibDn1te9IiPv10mJiZib2xkJj4kMCYmYm9sZCZwaT4kMA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4503 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3978443164 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee97171810, 0x55ee9735b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee9735b020,0x55ee991f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d7ab384c9e26772de6fe3e496b2555b7ef0d7b4c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5624 processed earlier; will process 5405 files now Step #5: ==162184== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ee8dc669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee942cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee942ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee942ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee8dc6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee8dbcdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee8dbc8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee8dc5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee90c2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee90c2df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee90c2df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee90c2df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee90c2df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee90c2df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee90c2df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee90c2df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee90c2df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee90c2df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee92ec2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee8fbefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee8fbfabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee8f9a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee8f9a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee8f9a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee8f9a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee8f9a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee8f9a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee942b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee942b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee942a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee942cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0bcab6e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee8dbc6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x44,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x48,0x48,0x48,0x48,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012D=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012HHHH\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-176239c5370e8856eceba5b6f621d8f685e4666a Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KRD0KPQoKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KSEhISAo9Cj0KCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoKbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tPQo9Cj0KEA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4504 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3978962562 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d93f5d810, 0x562d9414701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d94147020,0x562d95fdf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/176239c5370e8856eceba5b6f621d8f685e4666a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5625 processed earlier; will process 5404 files now Step #5: ==162220== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562d8aa529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d910b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d9109a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d9109a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d8aa58d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d8a9b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d8a9b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d8aa4ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d8da19f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d8da19f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d8da19f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d8da19f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d8da19f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d8da19f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d8da19f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d8da19f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d8da19f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d8da19f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d8fcaef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d8c9dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d8c9e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d8c792c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d8c792c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d8c793738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d8c792874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d8c792874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d8c792874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d9109cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d910a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d9108d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d910b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f412ad6f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d8a9b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0xb,0x4a,0x41,0x6e,0xc,0x31,0x39,0xa,0x31,0x32,0x3a,0x35,0x30,0x9,0xf0,0x9e,0xa1,0x98,0x35,0x44,0x65,0x43,0x9,0x38,0x34,0x39,0x31,0xb,0x49,0x41,0x6e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3,0xc,0x0,0x0,0x0,0xd,0x31,0x39,0xa,0x31,0x32,0x3a,0x35,0x30,0x9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x35,0x33,0x31,0x0,0x0,0x0,0x0,0x0,0x9,0x38,0x35,0x30,0x9,0xf0,0x9e,0xa1,0x98,0xcd,0xbb,0x65,0x43,0x9,0x38,0x0,0x29,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2e,0x30,0x37,0x33,0x34,0x2e,0x7a, Step #5: 2\013JAn\01419\01212:50\011\360\236\241\2305DeC\0118491\013IAn\000\000\000\000\000\000\000\003\014\000\000\000\01519\01212:50\011\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000531\000\000\000\000\000\011850\011\360\236\241\230\315\273eC\0118\000)\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000.0734.z Step #5: artifact_prefix='./'; Test unit written to ./oom-6d031d1abd7f125436134a57d49f2bf0e2be0e61 Step #5: Base64: MgtKQW4MMTkKMTI6NTAJ8J6hmDVEZUMJODQ5MQtJQW4AAAAAAAAAAwwAAAANMTkKMTI6NTAJAAAAAAAAAAAAAAAAAAAAAAA1MzEAAAAAAAk4NTAJ8J6hmM27ZUMJOAApAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALjA3MzQueg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4505 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3979476152 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5569935a6810, 0x55699379001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556993790020,0x5569956280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6d031d1abd7f125436134a57d49f2bf0e2be0e61' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5626 processed earlier; will process 5403 files now Step #5: ==162256== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55698a09b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556990700898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5569906e35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5569906e34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55698a0a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55698a002b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556989ffd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55698a093c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55698d062f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55698d062f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55698d062f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55698d062f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55698d062f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55698d062f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55698d062f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55698d062f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55698d062f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55698d062f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55698f2f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55698c024b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55698c02fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55698bddbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55698bddbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55698bddc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55698bddb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55698bddb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55698bddb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5569906e5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5569906ee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5569906d6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556990701112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fed17d70082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556989ffbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x9,0x3a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x3a,0x24,0x2d,0x5b,0xee,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\000/\000\017\017\017\017\0171-\017[\017\0171-\017[1&\011:\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\021-\017\017\017\017\0171\021\0171\017\017\017\017\0171\017-1[&\021:\021-\017\017\017\017\0171\021\0171\021-::$-[\356$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-7ba5440ccce1205f70f8b7055f4cdc25a164e992 Step #5: Base64: JAAALwAAAC8AAC8ADw8PDw8xLQ9bDw8xLQ9bMSYJOgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABEtDw8PDw8xEQ8xDw8PDw8xDy0xWyYROhEtDw8PDw8xEQ8xES06OiQtW+4kWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4506 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3979996162 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557f3b2ca810, 0x557f3b4b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557f3b4b4020,0x557f3d34c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ba5440ccce1205f70f8b7055f4cdc25a164e992' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5627 processed earlier; will process 5402 files now Step #5: ==162292== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557f31dbf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f38424898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f384075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f384074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f31dc5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f31d26b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f31d21355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f31db7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f34d86f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f34d86f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f34d86f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f34d86f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f34d86f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f34d86f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f34d86f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f34d86f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f34d86f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f34d86f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f3701bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f33d48b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f33d53be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f33affc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f33affc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f33b00738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f33aff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f33aff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f33aff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f38409abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f38412928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f383fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f38425112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ac3598082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f31d1fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x33,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x25,0x3a,0x3a,0x24,0x2d,0x5b,0xee,0xf3,0xa0,0x81,0xa0,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\000/\000\017\017\017\017\0171/\000\000\000/\000\000/\000\017\017\017\017\0171-\017[\017\0171-\017[1&\021:\021-\017\017\017\017\0171\021\0171\017s\000/\000\000/\000\017\017\017\017\0171-\017[\017\0171-\017[3&\021:\021-\017\017\017\017\0171\021\0171\017s [8A\000\017\017\017\0171\017-1[&\021:\021-\017\017\017\017\0171\021\0171\021%::$-[\356\363\240\201\240$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-9a6261724fe267c1695777a48648d3ace9e94c2f Step #5: Base64: JAAALwAAAC8AAC8ADw8PDw8xLwAAAC8AAC8ADw8PDw8xLQ9bDw8xLQ9bMSYROhEtDw8PDw8xEQ8xD3MALwAALwAPDw8PDzEtD1sPDzEtD1szJhE6ES0PDw8PDzERDzEPcyBbOEEADw8PDzEPLTFbJhE6ES0PDw8PDzERDzERJTo6JC1b7vOggaAkWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4507 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3980513046 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e7b81c1810, 0x55e7b83ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e7b83ab020,0x55e7ba2430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9a6261724fe267c1695777a48648d3ace9e94c2f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5628 processed earlier; will process 5401 files now Step #5: ==162328== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e7aecb69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e7b531b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7b52fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7b52fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e7aecbcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e7aec1db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e7aec18355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e7aecaec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e7b1c7df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e7b1c7df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e7b1c7df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e7b1c7df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e7b1c7df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e7b1c7df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e7b1c7df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e7b1c7df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e7b1c7df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e7b1c7df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e7b3f12f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e7b0c3fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e7b0c4abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e7b09f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e7b09f6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e7b09f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e7b09f6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e7b09f6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e7b09f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e7b5300abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e7b5309928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e7b52f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e7b531c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f46dfc0e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e7aec16b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0x2e,0xef,0xbc,0x8e,0xef,0xb4,0x8e,0xef,0xbc,0x8e, Step #5: ws:\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226.\357\274\216\357\264\216\357\274\216 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ea415fea3531531e9e463b16cf0a2a8c5ed1654 Step #5: Base64: d3M644yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yWLu+8ju+0ju+8jg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4508 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3981024419 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d15d72810, 0x561d15f5c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d15f5c020,0x561d17df40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ea415fea3531531e9e463b16cf0a2a8c5ed1654' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5629 processed earlier; will process 5400 files now Step #5: ==162364== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d0c8679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d12ecc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d12eaf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d12eaf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d0c86dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d0c7ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d0c7c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d0c85fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d0f82ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d0f82ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d0f82ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d0f82ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d0f82ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d0f82ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d0f82ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d0f82ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d0f82ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d0f82ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d11ac3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d0e7f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d0e7fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d0e5a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d0e5a7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d0e5a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d0e5a7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d0e5a7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d0e5a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d12eb1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d12eba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d12ea2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d12ecd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5767977082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d0c7c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x44,0x33,0x2,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x44,0x33,0x2,0x1,0x1,0x41,0x1,0x0,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x1,0x1,0x41,0x1,0x0,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5b,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x30,0x54,0x58,0x58,0x0,0x0,0x42,0x3,0x3d,0x54,0x58,0x58,0x3, Step #5: I__________________________D3\002____________D3\002\001\001A\001\000_______\001\001A\001\000________________[_______________________________________________0TXX\000\000B\003=TXX\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-7ad78faf4ad0205fed05af8cc9ff685a77bca83b Step #5: Base64: SV9fX19fX19fX19fX19fX19fX19fX19fX19fRDMCX19fX19fX19fX19fRDMCAQFBAQBfX19fX19fAQFBAQBfX19fX19fX19fX19fX19fW19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fMFRYWAAAQgM9VFhYAw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4509 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3981533152 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af3e770810, 0x55af3e95a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af3e95a020,0x55af407f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ad78faf4ad0205fed05af8cc9ff685a77bca83b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5630 processed earlier; will process 5399 files now Step #5: ==162400== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55af352659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af3b8ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af3b8ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af3b8ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55af3526bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55af351ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55af351c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55af3525dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55af3822cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55af3822cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55af3822cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55af3822cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55af3822cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55af3822cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55af3822cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55af3822cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55af3822cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55af3822cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af3a4c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af371eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af371f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af36fa5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af36fa5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af36fa6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af36fa5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af36fa5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af36fa5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af3b8afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af3b8b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af3b8a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af3b8cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0edb9d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55af351c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x31,0x20,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x36,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x20,0x30,0xf,0xf,0xf,0xf,0x31,0x37,0x30,0x31,0x34,0x31,0x31,0x38,0x33,0x34,0x36,0x30,0x34,0x36,0x39,0x32,0x33,0x31,0x37,0x33,0x31,0x36,0x38,0x37,0x33,0x30,0x33,0x37,0x31,0x35,0x38,0x38,0x34,0x31,0x30,0x35,0x37,0x32,0x37,0xf,0x2d,0x32,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x3a,0x24,0x2d,0x5b,0xee,0x24,0x5b, Step #5: $\000\000/\000\021\0171\017s [1 340282366920938463463374607431768211456\017\017\017\0171\021\0171\017s [8 0\017\017\017\017170141183460469231731687303715884105727\017-2[&\021:\021-\017\017\017\017\0171\021\0171\021-::$-[\356$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-056efc901917f24e8eca2deff3c2918a55ba48cb Step #5: Base64: JAAALwARDzEPcyBbMSAzNDAyODIzNjY5MjA5Mzg0NjM0NjMzNzQ2MDc0MzE3NjgyMTE0NTYPDw8PMREPMQ9zIFs4IDAPDw8PMTcwMTQxMTgzNDYwNDY5MjMxNzMxNjg3MzAzNzE1ODg0MTA1NzI3Dy0yWyYROhEtDw8PDw8xEQ8xES06OiQtW+4kWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4510 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3982047688 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647989f0810, 0x564798bda01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564798bda020,0x56479aa720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/056efc901917f24e8eca2deff3c2918a55ba48cb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5631 processed earlier; will process 5398 files now Step #5: ==162436== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56478f4e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564795b4a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564795b2d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564795b2d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56478f4ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56478f44cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56478f447355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56478f4ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647924acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647924acf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647924acf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647924acf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647924acf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647924acf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647924acf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647924acf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647924acf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647924acf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564794741f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56479146eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564791479be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564791225c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564791225c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564791226738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564791225874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564791225874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564791225874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564795b2fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564795b38928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564795b20699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564795b4b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe2578a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56478f445b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x2d,0x2d,0x2d,0x42,0x3e,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0x3b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3b,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x2d,0x2d,0x2d,0x42, Step #5: \005-----\012=\012==\012=\012=\012=\012=\012=\000---B>GIN -----\012N\012=;=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=;=\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000=\012=\012=\012=\012=\012=\012=\012=\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000---B Step #5: artifact_prefix='./'; Test unit written to ./oom-210cd469c48aab54f749df9e4aefb6e29e42029e Step #5: Base64: BS0tLS0tCj0KPT0KPQo9Cj0KPQo9AC0tLUI+R0lOIC0tLS0tCk4KPTs9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Oz0KPT0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9AD0KPQo9Cj0KPQo9Cj0KPQo9PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0ALS0tQg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4511 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3982570941 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe4e40b810, 0x55fe4e5f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe4e5f5020,0x55fe5048d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/210cd469c48aab54f749df9e4aefb6e29e42029e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5632 processed earlier; will process 5397 files now Step #5: ==162472== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fe44f009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe4b565898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe4b5485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe4b5484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe44f06d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe44e67b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe44e62355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe44ef8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe47ec7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe47ec7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe47ec7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe47ec7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe47ec7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe47ec7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe47ec7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe47ec7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe47ec7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe47ec7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe4a15cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe46e89b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe46e94be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe46c40c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe46c40c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe46c41738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe46c40874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe46c40874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe46c40874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe4b54aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe4b553928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe4b53b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe4b566112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f174ea10082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe44e60b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x1d,0x0,0x0,0x0,0x4,0x0,0x0,0x0,0x3,0x0,0x1,0x0,0x0,0x0,0x10,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x40,0x73,0x33,0x2e,0x30,0x2e,0x30,0x2e,0x31,0x0,0x9e,0x0,0x0,0x0,0x4,0x0,0x0,0x0,0x4,0x0,0x5,0x0,0x0,0x0,0x16,0x30,0x2e,0x0,0x64,0x0,0xd6,0x34,0xfe,0x27,0xbf,0x0,0x0,0x0,0x0,0xc8,0xd0,0x86,0x37,0x52,0xd0,0x77,0x27,0x0,0x2,0x0,0x0,0x0,0x3f,0x48,0x54,0x54,0x50,0x2f,0x31,0x2e,0x31,0x20,0x33,0x30,0x34,0x30,0xf1,0xff,0xad,0x8,0x75,0x34,0xa,0x4c,0x6f,0x63,0x61,0x74,0x69,0x6f,0x6e,0x3a,0x9d,0xd0,0x9a,0xd7,0x9f,0xee,0xd8,0x21,0xec,0xca,0xc5,0x8c,0xc2,0x55,0xd3,0x20,0x64,0x7b,0x65,0x6c,0x65,0xa,0xa,0x13,0x40,0x0,0x0,0x0,0x0,0x0,0x9a,0xf7,0xfd,0xbf, Step #5: \000\035\000\000\000\004\000\000\000\003\000\001\000\000\000\020http://@s3.0.0.1\000\236\000\000\000\004\000\000\000\004\000\005\000\000\000\0260.\000d\000\3264\376'\277\000\000\000\000\310\320\2067R\320w'\000\002\000\000\000?HTTP/1.1 3040\361\377\255\010u4\012Location:\235\320\232\327\237\356\330!\354\312\305\214\302U\323 d{ele\012\012\023@\000\000\000\000\000\232\367\375\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-db8a11d980ce22deb2b12cf8462bd30cc577fba4 Step #5: Base64: AB0AAAAEAAAAAwABAAAAEGh0dHA6Ly9AczMuMC4wLjEAngAAAAQAAAAEAAUAAAAWMC4AZADWNP4nvwAAAADI0IY3UtB3JwACAAAAP0hUVFAvMS4xIDMwNDDx/60IdTQKTG9jYXRpb246ndCa15/u2CHsysWMwlXTIGR7ZWxlCgoTQAAAAAAAmvf9vw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4512 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3983075903 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c4a308810, 0x562c4a4f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c4a4f2020,0x562c4c38a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/db8a11d980ce22deb2b12cf8462bd30cc577fba4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5633 processed earlier; will process 5396 files now Step #5: ==162508== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562c40dfd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c47462898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c474455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c474454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c40e03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c40d64b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c40d5f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c40df5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c43dc4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c43dc4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c43dc4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c43dc4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c43dc4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c43dc4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c43dc4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c43dc4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c43dc4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c43dc4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c46059f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562c42d86b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562c42d91be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562c42b3dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562c42b3dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562c42b3e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562c42b3d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562c42b3d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562c42b3d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c47447abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c47450928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c47438699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c47463112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbbd2a61082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c40d5db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x31,0x4d,0x46,0x50,0x48,0x65,0x57,0x53,0x63,0x6f,0x41,0x62,0x71,0x59,0x30,0x2b,0x6a,0x6d,0x47,0x4c,0x4c,0x43,0x41,0x41,0x42,0x73,0x54,0x4c,0x2b,0x53,0x58,0x4a,0x53,0x7a,0x56,0x77,0x6a,0x73,0x6e,0x33,0x44,0x45,0xa,0x66,0x61,0x6d,0x69,0x6c,0x79,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24, Step #5: onion-key\012ntor-onion-key v1MFPHeWScoAbqY0+jmGLLCAABsTL+SXJSzVwjsn3DE\012family $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ Step #5: artifact_prefix='./'; Test unit written to ./oom-d21456ab21ac199a0a7237a453dbbd293b9a0be8 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHYxTUZQSGVXU2NvQWJxWTAram1HTExDQUFCc1RMK1NYSlN6Vndqc24zREUKZmFtaWx5ICQgJCAkICQgJCAkICQgJCAkICQgJCAkICQgJCAkICQgJCAkICQgJCAkICQgJCAkICQgJCAkICQgJCAkICQgJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4513 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3983588271 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5597cbc69810, 0x5597cbe5301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5597cbe53020,0x5597cdceb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d21456ab21ac199a0a7237a453dbbd293b9a0be8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5634 processed earlier; will process 5395 files now Step #5: ==162544== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5597c275e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5597c8dc3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5597c8da65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5597c8da64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5597c2764d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5597c26c5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5597c26c0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5597c2756c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5597c5725f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5597c5725f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5597c5725f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5597c5725f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5597c5725f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5597c5725f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5597c5725f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5597c5725f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5597c5725f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5597c5725f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5597c79baf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5597c46e7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5597c46f2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5597c449ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5597c449ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5597c449f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5597c449e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5597c449e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5597c449e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5597c8da8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5597c8db1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5597c8d99699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5597c8dc4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0585651082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5597c26beb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x25,0x7d,0x7b,0x34,0x30,0x2c,0x3a,0x7b,0x20,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x0,0xb,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x25,0x7d,0x7b,0x34,0x30,0x2c,0x3a,0x7b,0x20,0x7d,0x7d,0x7b,0x30,0x20,0x30,0x2c,0x7b,0x7d,0x2c,0x7d,0x20,0x7b,0x0,0xb,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x2c,0x7d, Step #5: }{0,} {0,} {0,}s{0,} {0,}${0,}%}{40,:{ }}{0,} {0,} {\000\0130,}s{0,} {0,}${0,} ,} {0,}${0,}%}{40,:{ }}{0 0,{},} {\000\0130,}s{0,} {0,}${0,} {0,}{0,} {,} Step #5: artifact_prefix='./'; Test unit written to ./oom-5d15fb4a4671c8478c6202ae5447544305ede320 Step #5: Base64: fXswLH0gezAsfSB7MCx9c3swLH0gezAsfSR7MCx9JX17NDAsOnsgfX17MCx9IHswLH0gewALMCx9c3swLH0gezAsfSR7MCx9ICx9IHswLH0kezAsfSV9ezQwLDp7IH19ezAgMCx7fSx9IHsACzAsfXN7MCx9IHswLH0kezAsfSB7MCx9ezAsfSB7LH0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4514 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3984098309 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55947a0b0810, 0x55947a29a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55947a29a020,0x55947c1320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5d15fb4a4671c8478c6202ae5447544305ede320' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5635 processed earlier; will process 5394 files now Step #5: ==162580== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559470ba59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55947720a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5594771ed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5594771ed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559470babd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559470b0cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559470b07355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559470b9dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559473b6cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559473b6cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559473b6cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559473b6cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559473b6cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559473b6cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559473b6cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559473b6cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559473b6cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559473b6cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559475e01f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559472b2eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559472b39be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5594728e5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5594728e5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5594728e6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5594728e5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5594728e5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5594728e5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5594771efabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5594771f8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5594771e0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55947720b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3f8ce73082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559470b05b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xe,0xf,0xf,0x32,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x11,0x38,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x25,0x3a,0x3a,0x24,0x2d,0x5b,0xee,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\000/\000\017\017\016\017\0172/\000\000\000/\000\000/\000\017\017\017\017\0171-\017[\017\0171-\017[1&\021:\021-\017\017\017\017\0171\021\0171\017s [8A\000\017\017\017\0171\017-1[&\021:-\017[\017\0171-\017[1&\0218\021-\017\017\017\017\0171\021\0171\017s [8A\000\017\017\017\0171\017-1[&\021:\021-\017\017\017\017\0171\021\0171\021%::$-[\356$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-c1ca87695afb770ed67bbdd6f3339e800590e55f Step #5: Base64: JAAALwAAAC8AAC8ADw8ODw8yLwAAAC8AAC8ADw8PDw8xLQ9bDw8xLQ9bMSYROhEtDw8PDw8xEQ8xD3MgWzhBAA8PDw8xDy0xWyYROi0PWw8PMS0PWzEmETgRLQ8PDw8PMREPMQ9zIFs4QQAPDw8PMQ8tMVsmEToRLQ8PDw8PMREPMRElOjokLVvuJFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4515 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3984612415 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5588d4ba6810, 0x5588d4d9001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5588d4d90020,0x5588d6c280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c1ca87695afb770ed67bbdd6f3339e800590e55f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5636 processed earlier; will process 5393 files now Step #5: ==162616== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5588cb69b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5588d1d00898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588d1ce35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588d1ce34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588cb6a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588cb602b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588cb5fd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588cb693c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5588ce662f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5588ce662f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5588ce662f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5588ce662f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5588ce662f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5588ce662f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5588ce662f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5588ce662f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5588ce662f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5588ce662f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5588d08f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588cd624b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588cd62fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588cd3dbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588cd3dbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588cd3dc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588cd3db874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588cd3db874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588cd3db874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5588d1ce5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5588d1cee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5588d1cd6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5588d1d01112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f310b561082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588cb5fbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0xf,0x31,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\000/\000\017\017\017\017\0171/\000\000\000/\000\000/\000\017\017\017\017\0171-\017[\017\0171-\017[1&\021:\021-\017\017\017\017\0171\021\0171\017s [8A\000\017\017\017\0171\017-1[&\021:-\017[\017\0171-\017[1&\021:\021-\017\017\017\017\0171\021\0171\017s [8A\000\017\017\017\0171\017-1[&\021:\021-\017\017\017\017\017\0171/\000\000\000/\000\000/\000\017$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-796d5aff77d321bd4e45ce5fab38e7edfb0fe30f Step #5: Base64: JAAALwAAAC8AAC8ADw8PDw8xLwAAAC8AAC8ADw8PDw8xLQ9bDw8xLQ9bMSYROhEtDw8PDw8xEQ8xD3MgWzhBAA8PDw8xDy0xWyYROi0PWw8PMS0PWzEmEToRLQ8PDw8PMREPMQ9zIFs4QQAPDw8PMQ8tMVsmEToRLQ8PDw8PDzEvAAAALwAALwAPJFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4516 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3985127512 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55697bb1d810, 0x55697bd0701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55697bd07020,0x55697db9f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/796d5aff77d321bd4e45ce5fab38e7edfb0fe30f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5637 processed earlier; will process 5392 files now Step #5: #1 pulse cov: 3842 ft: 3843 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4748 ft: 5161 exec/s: 0 rss: 177Mb Step #5: ==162652== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5569726129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556978c77898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556978c5a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556978c5a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556972618d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556972579b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556972574355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55697260ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5569755d9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5569755d9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5569755d9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5569755d9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5569755d9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5569755d9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5569755d9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5569755d9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5569755d9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5569755d9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55697786ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55697459bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5569745a6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556974352c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556974352c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556974353738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556974352874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556974352874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556974352874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556978c5cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556978c65928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556978c4d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556978c78112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb646f16082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556972572b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x60,0xd1,0x9f,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x11,0x60,0x0,0x1,0x0,0x9,0x0,0x80,0xf,0xa,0x60,0x0, Step #5: \000\000\000\000\000`\321\237\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021\021`\000\001\000\011\000\200\017\012`\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4129eaa76170df9a65a205ee93712c4bceb6d524 Step #5: Base64: AAAAAABg0Z8RERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERERYAABAAkAgA8KYAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4517 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3985837257 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a60b02f810, 0x55a60b21901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a60b219020,0x55a60d0b10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4129eaa76170df9a65a205ee93712c4bceb6d524' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5640 processed earlier; will process 5389 files now Step #5: #1 pulse cov: 3781 ft: 3782 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 3869 ft: 4286 exec/s: 0 rss: 178Mb Step #5: ==162688== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a601b249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a608189898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a60816c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a60816c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a601b2ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a601a8bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a601a86355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a601b1cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a604aebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a604aebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a604aebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a604aebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a604aebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a604aebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a604aebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a604aebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a604aebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a604aebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a606d80f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a603aadb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a603ab8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a603864c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a603864c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a603865738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a603864874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a603864874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a603864874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a60816eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a608177928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a60815f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a60818a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f40efffb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a601a84b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x61,0x3e,0x3c,0x21,0x5b,0x43,0x44,0x41,0x54,0x41,0x5b,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x90,0x90,0xa,0xeb,0x91,0x90, Step #5: <a><![CDATA[\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\220\220\012\353\221\220 Step #5: artifact_prefix='./'; Test unit written to ./oom-8e0ab50956791374c12065d2f5cc72ad9d7310b3 Step #5: Base64: PGE+PCFbQ0RBVEFbCuuQkArrkJAK65CQCuuQkArrkJAK65CQCuuQkArrkJAK65CQCuuQkArrkJAK65CQCuuQkArrkJAK65CQCuuQkArrkJAK65CQCuuQkArrkJAK65CQCuuQkArrkJAK65CQCuuQkArrkJAK65CQCuuQkArrkJAK65CQCuuQkArrkZA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4518 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3986424362 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564f7bbe4810, 0x564f7bdce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564f7bdce020,0x564f7dc660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8e0ab50956791374c12065d2f5cc72ad9d7310b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5643 processed earlier; will process 5386 files now Step #5: ==162724== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564f726d99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f78d3e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f78d215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f78d214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f726dfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f72640b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f7263b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f726d1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f756a0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f756a0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f756a0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f756a0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f756a0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f756a0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f756a0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f756a0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f756a0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f756a0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f77935f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f74662b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f7466dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f74419c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f74419c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f7441a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f74419874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f74419874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f74419874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f78d23abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f78d2c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f78d14699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f78d3f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f64230e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f72639b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdc,0xbb,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xdc,0xb5, Step #5: \334\273\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\334\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-d1ec30fe8688c2ec2d8b07648fbfaec81cdb64bd Step #5: Base64: 3LsAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA3LU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4519 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3986939643 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe1c387810, 0x55fe1c57101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe1c571020,0x55fe1e4090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d1ec30fe8688c2ec2d8b07648fbfaec81cdb64bd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5644 processed earlier; will process 5385 files now Step #5: ==162760== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fe12e7c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe194e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe194c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe194c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe12e82d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe12de3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe12dde355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe12e74c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe15e43f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe15e43f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe15e43f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe15e43f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe15e43f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe15e43f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe15e43f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe15e43f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe15e43f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe15e43f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe180d8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe14e05b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe14e10be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe14bbcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe14bbcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe14bbd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe14bbc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe14bbc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe14bbc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe194c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe194cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe194b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe194e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ddc6d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe12ddcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0xe2,0x80,0x88,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xef,0xbd,0xb0,0xa,0x3d,0xa,0x3d,0xa,0xe2,0x81,0xa8,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0xa,0x3d,0xa,0x3d,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xe2,0x81,0xa8,0x3d,0xa,0x3d,0xa,0x3d,0x61,0x6d,0x54,0x9,0x54,0x68,0x3,0x3d,0x34,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0xa,0x3d,0x44,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x38,0x30,0x38,0x4,0xcc,0x96,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xff, Step #5: \005-----BEGIN -\342\200\210----\012N\012=\012=\012=\012=\357\275\260\012=\012=\012\342\201\250=\012=\012=\012=\012=\000\012=\012==\012\012=\012=\012=\012\342\201\250=\012=\012=amT\011Th\003=4\012=\012=\012=\012=\012=\012=\012=\000----\012--\012=D9223372036854775808\004\314\226skip_cl\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-d6e9ed5c2f1b3a7483edf29029794c877c6f9189 Step #5: Base64: BS0tLS0tQkVHSU4gLeKAiC0tLS0KTgo9Cj0KPQo9772wCj0KPQrigag9Cj0KPQo9Cj0ACj0KPT0KCj0KPQo9CuKBqD0KPQo9YW1UCVRoAz00Cj0KPQo9Cj0KPQo9Cj0ALS0tLQotLQo9RDkyMjMzNzIwMzY4NTQ3NzU4MDgEzJZza2lwX2NsCnwAEP8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4520 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3987466403 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bd3ab6f810, 0x55bd3ad5901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bd3ad59020,0x55bd3cbf10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d6e9ed5c2f1b3a7483edf29029794c877c6f9189' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5645 processed earlier; will process 5384 files now Step #5: ==162796== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bd316649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bd37cc9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bd37cac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bd37cac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bd3166ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bd315cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bd315c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bd3165cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bd3462bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bd3462bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bd3462bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bd3462bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bd3462bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bd3462bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bd3462bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bd3462bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bd3462bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bd3462bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bd368c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bd335edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bd335f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bd333a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bd333a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bd333a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bd333a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bd333a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bd333a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bd37caeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bd37cb7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bd37c9f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bd37cca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffae5bf0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bd315c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x65,0x74,0x6e,0x61,0x3e,0x3c,0x65,0x74,0x61,0x6e,0x3e,0x3c,0x65,0x6e,0x74,0x72,0x72,0x79,0x3e,0x3c,0x65,0x6e,0x6a,0x72,0x79,0x72,0x65,0x74,0x6e,0x61,0x3e,0x3c,0x65,0x74,0x61,0x6e,0x3e,0x3c,0x65,0x6e,0x74,0x72,0x72,0x79,0x3e,0x3c,0x65,0x6e,0x6a,0x72,0x79,0x72,0x79,0x3e,0x3c,0x6e,0x70,0x72,0x72,0x6e,0x72,0x79,0x3e,0x3c,0x65,0x6e,0x74,0x72,0x79,0x3e,0x3c,0x65,0x3e,0x3c,0x65,0x6e,0x74,0x72,0x72,0x79,0x3e,0x3c,0x65,0x6e,0x6a,0x72,0x79,0x72,0x79,0x3e,0x3c,0x6e,0x70,0x72,0x72,0x6e,0x72,0x79,0x6f,0x72,0x79,0x3e,0x65,0x6e,0x74,0x72,0x72,0x79,0x3e,0x3c,0x65,0x6e,0x6a,0x72,0x79,0x72,0x79,0x3e,0x3c,0x6e,0x70,0x72,0x72,0x6e,0x72,0x79,0x6f,0x72,0x79,0x3e,0x3c,0x65,0x6e,0x6a,0x72,0x79,0x72,0x79,0x3e, Step #5: <etna><etan><entrry><enjryretna><etan><entrry><enjryry><nprrnry><entry><e><entrry><enjryry><nprrnryory>entrry><enjryry><nprrnryory><enjryry> Step #5: artifact_prefix='./'; Test unit written to ./oom-bf1f13d83befcaece831530df698b95b2fe5e280 Step #5: Base64: PGV0bmE+PGV0YW4+PGVudHJyeT48ZW5qcnlyZXRuYT48ZXRhbj48ZW50cnJ5PjxlbmpyeXJ5PjxucHJybnJ5PjxlbnRyeT48ZT48ZW50cnJ5PjxlbmpyeXJ5PjxucHJybnJ5b3J5PmVudHJyeT48ZW5qcnlyeT48bnBycm5yeW9yeT48ZW5qcnlyeT4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4521 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3987974416 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b25db2810, 0x556b25f9c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b25f9c020,0x556b27e340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf1f13d83befcaece831530df698b95b2fe5e280' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5646 processed earlier; will process 5383 files now Step #5: ==162832== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556b1c8a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b22f0c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b22eef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b22eef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b1c8add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b1c80eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b1c809355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b1c89fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b1f86ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b1f86ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b1f86ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b1f86ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b1f86ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b1f86ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b1f86ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b1f86ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b1f86ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b1f86ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b21b03f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b1e830b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b1e83bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b1e5e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b1e5e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b1e5e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b1e5e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b1e5e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b1e5e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b22ef1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b22efa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b22ee2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b22f0d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb3277db082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b1c807b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x25,0x7d,0x7b,0x34,0x30,0x2c,0x3a,0x7b,0x20,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x0,0xb,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x25,0x7d,0x7b,0x34,0x30,0x2c,0x3a,0x7b,0x20,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x0,0xb,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x2c,0x7d, Step #5: }{0,} {0,} {0,}s{0,} {0,}${0,}%}{40,:{ }}{0,} {0,} {\000\0130,}s{0,} {0,}${0,} ,} {0,}${0,}%}{40,:{ }}{0,} {0,} {\000\0130,}s{0,} {0,}${0,} {0,}{0,} {,} Step #5: artifact_prefix='./'; Test unit written to ./oom-0996f396f2bf3ce59ed167386c6099284a1b76b4 Step #5: Base64: fXswLH0gezAsfSB7MCx9c3swLH0gezAsfSR7MCx9JX17NDAsOnsgfX17MCx9IHswLH0gewALMCx9c3swLH0gezAsfSR7MCx9ICx9IHswLH0kezAsfSV9ezQwLDp7IH19ezAsfSB7MCx9IHsACzAsfXN7MCx9IHswLH0kezAsfSB7MCx9ezAsfSB7LH0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4522 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3988498431 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9ffeb2810, 0x55ea0009c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea0009c020,0x55ea01f340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0996f396f2bf3ce59ed167386c6099284a1b76b4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5647 processed earlier; will process 5382 files now Step #5: ==162868== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e9f69a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9fd00c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9fcfef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9fcfef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9f69add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e9f690eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e9f6909355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9f699fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e9f996ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e9f996ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e9f996ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e9f996ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e9f996ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e9f996ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e9f996ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e9f996ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e9f996ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e9f996ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9fbc03f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e9f8930b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e9f893bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9f86e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9f86e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9f86e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9f86e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9f86e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9f86e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e9fcff1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9fcffa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e9fcfe2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e9fd00d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fab60f52082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e9f6907b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x44,0x33,0x2,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x44,0x33,0x2,0x1,0x1,0x41,0x1,0x0,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x1,0x1,0x41,0x1,0x0,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5b,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x57,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x3a,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x31,0x54,0xe3,0x58,0x58,0x0,0x0,0x42,0x3,0x3d,0x54,0x58,0x58,0x3, Step #5: I__________________________D3\002____________D3\002\001\001A\001\000_______\001\001A\001\000________________[_______________W___________________:___________1T\343XX\000\000B\003=TXX\003 Step #5: artifact_prefix='./'; Test unit written to ./oom-5abdcf8e36f01c3f48facb042dd6ac0ef3d46811 Step #5: Base64: SV9fX19fX19fX19fX19fX19fX19fX19fX19fRDMCX19fX19fX19fX19fRDMCAQFBAQBfX19fX19fAQFBAQBfX19fX19fX19fX19fX19fW19fX19fX19fX19fX19fX1dfX19fX19fX19fX19fX19fX19fOl9fX19fX19fX19fMVTjWFgAAEIDPVRYWAM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4523 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3989011672 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a80024810, 0x563a8020e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a8020e020,0x563a820a60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5abdcf8e36f01c3f48facb042dd6ac0ef3d46811' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5648 processed earlier; will process 5381 files now Step #5: ==162904== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563a76b199c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a7d17e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a7d1615dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a7d1614fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a76b1fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a76a80b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a76a7b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a76b11c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a79ae0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a79ae0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a79ae0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a79ae0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a79ae0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a79ae0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a79ae0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a79ae0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a79ae0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a79ae0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a7bd75f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a78aa2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a78aadbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a78859c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a78859c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a7885a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a78859874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a78859874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a78859874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a7d163abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a7d16c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a7d154699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a7d17f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8af9f08082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a76a79b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x57,0x73,0x3a,0xc5,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xc5,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: \016Ws:\305\204\315\224\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\305\204\315\224\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-3f81a6e99eab75fbad8eb2654609c27e1ef05e1a Step #5: Base64: DldzOsWEzZTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2ExYTNlM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4524 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3989525871 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b805c5810, 0x558b807af01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b807af020,0x558b826470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3f81a6e99eab75fbad8eb2654609c27e1ef05e1a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5649 processed earlier; will process 5380 files now Step #5: #1 pulse cov: 4182 ft: 4183 exec/s: 0 rss: 174Mb Step #5: ==162940== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558b770ba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b7d71f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b7d7025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b7d7024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b770c0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b77021b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b7701c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b770b2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b7a081f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b7a081f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b7a081f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b7a081f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b7a081f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b7a081f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b7a081f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b7a081f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b7a081f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b7a081f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b7c316f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b79043b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b7904ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b78dfac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b78dfac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b78dfb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b78dfa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b78dfa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b78dfa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b7d704abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b7d70d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b7d6f5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b7d720112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f747ce8b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b7701ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd3,0x81,0xe6,0x8d,0x8b,0x5b,0x7e,0x39,0xd3,0x81,0xe6,0x8d,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x8b,0x5b,0x7e,0x73, Step #5: \323\201\346\215\213[~9\323\201\346\215{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{\213[~s Step #5: artifact_prefix='./'; Test unit written to ./oom-c04081c5d591893215975517dc4fa07992bae938 Step #5: Base64: 04HmjYtbfjnTgeaNe3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e4tbfnM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4525 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3990074564 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5557f0348810, 0x5557f053201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5557f0532020,0x5557f23ca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c04081c5d591893215975517dc4fa07992bae938' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5651 processed earlier; will process 5378 files now Step #5: #1 pulse cov: 3988 ft: 3989 exec/s: 0 rss: 176Mb Step #5: ==162976== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5557e6e3d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5557ed4a2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557ed4855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557ed4854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557e6e43d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557e6da4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5557e6d9f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557e6e35c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557e9e04f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557e9e04f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557e9e04f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557e9e04f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557e9e04f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557e9e04f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557e9e04f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557e9e04f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557e9e04f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557e9e04f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5557ec099f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557e8dc6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557e8dd1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5557e8b7dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5557e8b7dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5557e8b7e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5557e8b7d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5557e8b7d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5557e8b7d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557ed487abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557ed490928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557ed478699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5557ed4a3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb88bdbe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5557e6d9db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0xa,0x22,0x32,0x32,0x32,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0x80,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x8a,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa0,0x98,0xf0,0x90,0xa0,0x88,0xf0,0x90,0xa2,0x88,0xf0,0x90,0xa0,0x88,0xf0,0x90,0x80,0x98,0xf0,0x90,0xa0,0x88,0xf0,0x90,0x9b,0x88,0x29,0xff,0x22,0x3a,0x30,0xa,0x7d, Step #5: {\012\"222\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\200\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\212\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\210\360\220\240\230\360\220\240\210\360\220\242\210\360\220\240\210\360\220\200\230\360\220\240\210\360\220\233\210)\377\":0\012} Step #5: artifact_prefix='./'; Test unit written to ./oom-99c6d6925b819528f802214c6d765b611139ed38 Step #5: Base64: ewoiMjIy8JCgiPCQoIjwkKCI8JCgiPCQoIjwkKCI8JCgiPCQgIjwkKCI8JCgiPCQoIjwkKCI8JCgiPCQoIrwkKCI8JCgiPCQoIjwkKCI8JCgiPCQoIjwkKCI8JCgiPCQoIjwkKCI8JCgiPCQoJjwkKCI8JCiiPCQoIjwkICY8JCgiPCQm4gp/yI6MAp9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4526 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3990630646 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a654a52810, 0x55a654c3c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a654c3c020,0x55a656ad40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/99c6d6925b819528f802214c6d765b611139ed38' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5653 processed earlier; will process 5376 files now Step #5: ==163012== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a64b5479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a651bac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a651b8f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a651b8f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a64b54dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a64b4aeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a64b4a9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a64b53fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a64e50ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a64e50ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a64e50ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a64e50ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a64e50ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a64e50ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a64e50ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a64e50ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a64e50ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a64e50ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a6507a3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a64d4d0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a64d4dbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a64d287c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a64d287c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a64d288738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a64d287874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a64d287874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a64d287874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a651b91abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a651b9a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a651b82699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a651bad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc06ed59082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a64b4a7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x7a,0x45,0x78,0x4f,0x54,0x4d,0x78,0x4d,0x6a,0x4d,0x31,0x4d,0x6a,0x4d,0x77,0x4f,0x54,0x49,0x79,0x4d,0x7a,0x4d,0x32,0x4c,0x6a,0x41,0x79,0x4d,0x7a,0x4d,0x31,0x4d,0x6a,0x41,0x7a,0x4e,0x6a,0x4d,0x30,0x4e,0x44,0x63,0x35,0x4f,0x54,0x49,0x79,0x4d,0x44,0x63,0x31,0x4f,0x54,0x49,0x79,0x4d,0x54,0x49,0x79,0x4d,0x6a,0x63,0x35,0x4e,0x44,0x63,0x31,0x4f,0x54,0x49,0x79,0x4d,0x7a,0x49,0x79,0x4d,0x7a,0x4d,0x31,0x4d,0x54,0x4d,0x30,0x4e,0x44,0x63,0x35,0x4e,0x44,0x63,0x35,0x4f,0x54,0x49,0x79,0x4d,0x44,0x63,0x31,0x4f,0x54,0x49,0x79,0x4d,0x54,0x49,0x79,0x4d,0x7a,0x41,0x7a,0x4e,0x6a,0x63,0x35,0x4e,0x44,0x63,0x31,0x4f,0x54,0x49,0x79,0x4d,0x54,0x49,0x79,0x4d,0x54,0x49,0x79,0x4d,0x7a,0x4d,0x31,0x4d,0x6a,0x65,0x2e,0x2e, Step #5: MzExOTMxMjM1MjMwOTIyMzM2LjAyMzM1MjAzNjM0NDc5OTIyMDc1OTIyMTIyMjc5NDc1OTIyMzIyMzM1MTM0NDc5NDc5OTIyMDc1OTIyMTIyMzAzNjc5NDc1OTIyMTIyMTIyMzM1Mje.. Step #5: artifact_prefix='./'; Test unit written to ./oom-5f921839cdbc614a00b09c83e5557d3594981c7c Step #5: Base64: TXpFeE9UTXhNak0xTWpNd09USXlNek0yTGpBeU16TTFNakF6TmpNME5EYzVPVEl5TURjMU9USXlNVEl5TWpjNU5EYzFPVEl5TXpJeU16TTFNVE0wTkRjNU5EYzVPVEl5TURjMU9USXlNVEl5TXpBek5qYzVORGMxT1RJeU1USXlNVEl5TXpNMU1qZS4u Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4527 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3991142360 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561129e6f810, 0x56112a05901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56112a059020,0x56112bef10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f921839cdbc614a00b09c83e5557d3594981c7c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5654 processed earlier; will process 5375 files now Step #5: #1 pulse cov: 3880 ft: 3881 exec/s: 0 rss: 175Mb Step #5: ==163048== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5611209649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561126fc9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561126fac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561126fac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56112096ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5611208cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5611208c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56112095cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56112392bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56112392bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56112392bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56112392bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56112392bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56112392bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56112392bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56112392bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56112392bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56112392bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561125bc0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611228edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5611228f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611226a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611226a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611226a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611226a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611226a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611226a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561126faeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561126fb7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561126f9f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561126fca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa98006a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5611208c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x88,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x60,0x33,0xb,0x0,0xa,0xa,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0x20,0x60,0xa,0x9, Step #5: `\342\210\210-\000`\012\363\240\201\272/\012`\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000\000\000\000\000\000`3\013\000\012\0124028236692093846346337460743176821\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015 `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-9d98e9b1fbb3dacde05ddc9b33eb8716f0ea4a44 Step #5: Base64: YOKIiC0AYArzoIG6Lwpg4oCILQBgCvOggbrzoIG6LwEAAAAAAABgMwsACgo0MDI4MjM2NjkyMDkzODQ2MzQ2MzM3NDYwNzQzMTc2ODIxDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0gYAoJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4528 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3991826421 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c7ab155810, 0x55c7ab33f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c7ab33f020,0x55c7ad1d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9d98e9b1fbb3dacde05ddc9b33eb8716f0ea4a44' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5656 processed earlier; will process 5373 files now Step #5: #1 pulse cov: 3810 ft: 3811 exec/s: 0 rss: 176Mb Step #5: ==163084== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c7a1c4a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7a82af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7a82925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7a82924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c7a1c50d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c7a1bb1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c7a1bac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7a1c42c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7a4c11f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7a4c11f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7a4c11f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7a4c11f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7a4c11f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7a4c11f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7a4c11f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7a4c11f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7a4c11f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7a4c11f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c7a6ea6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7a3bd3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7a3bdebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7a398ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7a398ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7a398b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7a398a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7a398a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7a398a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7a8294abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7a829d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c7a8285699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7a82b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f28e4bb8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c7a1baab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x11,0x3a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x3a,0x24,0x2d,0x5b,0xee,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\000/\000\017\017\017\017\0171-\017[\017\0171-\017[1&\021:\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\021-\017\017\017\017\0171\021\0171\017\017\017\017\0171\017-1[&\021:\021-\017\017\017\017\0171\021\0171\021-::$-[\356$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-8928d55fe3d5726cba90a09b0b04f6929afe90dc Step #5: Base64: JAAALwAAAC8AAC8ADw8PDw8xLQ9bDw8xLQ9bMSYROgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAES0PDw8PDzERDzEPDw8PDzEPLTFbJhE6ES0PDw8PDzERDzERLTo6JC1b7iRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4529 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3992388491 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56413f511810, 0x56413f6fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56413f6fb020,0x5641415930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8928d55fe3d5726cba90a09b0b04f6929afe90dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5658 processed earlier; will process 5371 files now Step #5: ==163120== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5641360069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56413c66b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56413c64e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56413c64e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56413600cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564135f6db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564135f68355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564135ffec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564138fcdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564138fcdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564138fcdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564138fcdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564138fcdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564138fcdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564138fcdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564138fcdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564138fcdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564138fcdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56413b262f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564137f8fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564137f9abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564137d46c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564137d46c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564137d47738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564137d46874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564137d46874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564137d46874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56413c650abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56413c659928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56413c641699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56413c66c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f993d28b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564135f66b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0x61,0x65,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x3a,0x0,0x2a,0x2a,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x75,0x75,0x75,0x75,0x65, Step #5: nae**************************************\000\000\000:\000**hhhhhhhhh\004\000\000\000\000\000\000\000hhhhhhhhhhhhhh\000hhhhhhh**********hhhhhhhhhttps://hhhhhhhhhhhhhhhhhhhhhhhuuuue Step #5: artifact_prefix='./'; Test unit written to ./oom-c9800b610981cc7ec4cc51cb9b12d8f834a97e19 Step #5: Base64: bmFlKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioAAAA6ACoqaGhoaGhoaGhoBAAAAAAAAABoaGhoaGhoaGhoaGhoaABoaGhoaGhoKioqKioqKioqKmhoaGhoaGhoaHR0cHM6Ly9oaGhoaGhoaGhoaGhoaGhoaGhoaGhoaHV1dXVl Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4530 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3992901786 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b30f60e810, 0x55b30f7f801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b30f7f8020,0x55b3116900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9800b610981cc7ec4cc51cb9b12d8f834a97e19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5659 processed earlier; will process 5370 files now Step #5: ==163156== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b3061039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b30c768898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b30c74b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b30c74b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b306109d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b30606ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b306065355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b3060fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b3090caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b3090caf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b3090caf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b3090caf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b3090caf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b3090caf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b3090caf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b3090caf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b3090caf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b3090caf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b30b35ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b30808cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b308097be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b307e43c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b307e43c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b307e44738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b307e43874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b307e43874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b307e43874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b30c74dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b30c756928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b30c73e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b30c769112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f06a54d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b306063b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x74,0x67,0x6c,0x79,0xcd,0x8f,0x66,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x67,0x3f,0x74,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x66,0x67,0x7f,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x7f,0x66,0x2b,0x67,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67,0x3f,0x66,0x67,0x7f,0x66,0x67,0x7f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x67,0x7f,0x66,0x2b,0x67,0x66,0x3f,0x66,0x2b,0x67,0x66,0x3f,0x66,0x3b,0x67,0x3f,0x74,0x67,0x6c,0x79,0x66,0x3f,0x67,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0xba,0x0,0x5d,0xa4, Step #5: \000\000\000\000\000\000tgly\315\217ffg\177f;g?tglyg?tglyf?g?g?fg\177fg\177f;g?tg\177f+gf?f;g?tglyf?g?g?fg\177fg\177f;g?tglyg\177f+gf?f+gf?f;g?tglyf?g\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\272\000]\244 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb48bdd41b58b5b32de587bd6ceaae72bb6ad856 Step #5: Base64: AAAAAAAAdGdsec2PZmZnf2Y7Zz90Z2x5Zz90Z2x5Zj9nP2c/Zmd/Zmd/ZjtnP3Rnf2YrZ2Y/ZjtnP3RnbHlmP2c/Zz9mZ39mZ39mO2c/dGdseWd/ZitnZj9mK2dmP2Y7Zz90Z2x5Zj9nurq6urq6urq6urq6urq6urq6urq6urq6urq6urq6urq6AF2k Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4531 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3993416668 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ee6e8e810, 0x562ee707801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ee7078020,0x562ee8f100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb48bdd41b58b5b32de587bd6ceaae72bb6ad856' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5660 processed earlier; will process 5369 files now Step #5: #1 pulse cov: 3603 ft: 3604 exec/s: 0 rss: 174Mb Step #5: ==163192== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562edd9839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ee3fe8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ee3fcb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ee3fcb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562edd989d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562edd8eab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562edd8e5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562edd97bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ee094af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ee094af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ee094af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ee094af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ee094af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ee094af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ee094af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ee094af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ee094af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ee094af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ee2bdff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562edf90cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562edf917be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562edf6c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562edf6c3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562edf6c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562edf6c3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562edf6c3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562edf6c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ee3fcdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ee3fd6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ee3fbe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ee3fe9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f030b4ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562edd8e3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x3c,0x76,0x67,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x3c,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x67,0x3e,0x3c,0x67,0x3e,0x3c,0x61,0x61,0x61,0x61,0x61,0x3e,0x2a,0x7b,0x66,0x69,0x6c,0x6c,0x3a,0x20,0x20,0x22,0x23,0x22,0x22,0x3e,0x22,0x22,0x22,0x42,0x22,0x3c,0x67,0x3e,0x3c,0x61,0x61,0x61,0x61,0x61,0x3e,0x2a,0x7b,0x66,0x69,0x6c,0x6c,0x3a,0x20,0x20,0x22,0x23,0x22,0x22,0x3e,0x22,0x22,0x20,0x46,0x22,0x22,0x66,0x22,0x73,0x7d,0x73,0x20,0x6c,0x61,0x61,0x61,0x61,0x67,0x3e,0x3c,0x67,0x3e,0x3c,0x61,0x54,0x61,0x61,0x61,0x6c,0x61,0x61,0x61,0x61,0x61,0x61,0x67,0x3e,0x3c,0x67,0x3e,0x3a,0x20,0x20,0x22,0x23,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x42,0x22, Step #5: <svg><style><vg><style><aaaaaaaag><g><aaaaa>*{fill: \"#\"\">\"\"\"B\"<g><aaaaa>*{fill: \"#\"\">\"\" F\"\"f\"s}s laaaag><g><aTaaalaaaaaag><g>: \"#\"\"\"\"\"\"\"B\" Step #5: artifact_prefix='./'; Test unit written to ./oom-9d328e26e48a35194100fcf6e5dc5c22fc69dc08 Step #5: Base64: PHN2Zz48c3R5bGU+PHZnPjxzdHlsZT48YWFhYWFhYWFnPjxnPjxhYWFhYT4qe2ZpbGw6ICAiIyIiPiIiIkIiPGc+PGFhYWFhPip7ZmlsbDogICIjIiI+IiIgRiIiZiJzfXMgbGFhYWFnPjxnPjxhVGFhYWxhYWFhYWFnPjxnPjogICIjIiIiIiIiIkIi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4532 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3993968484 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab1c6ff810, 0x55ab1c8e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab1c8e9020,0x55ab1e7810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9d328e26e48a35194100fcf6e5dc5c22fc69dc08' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5662 processed earlier; will process 5367 files now Step #5: ==163228== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ab131f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab19859898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab1983c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab1983c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab131fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab1315bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab13156355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab131ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab161bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab161bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab161bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab161bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab161bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab161bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab161bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab161bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab161bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab161bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab18450f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab1517db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab15188be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab14f34c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab14f34c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab14f35738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab14f34874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab14f34874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab14f34874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab1983eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab19847928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab1982f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab1985a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f144ec7b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab13154b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x30,0x5b,0x31,0x25,0x20,0x0,0x0,0x0,0x2d,0x6b,0x25,0x65,0x78,0x69,0xdd,0x85,0x72,0x74,0x73,0x3a,0x32,0x3a,0x74,0x0,0x12,0x2d,0x5b,0x2d,0x30,0x20,0x20,0x0,0x0,0x0,0x29,0x31,0x25,0x2d,0xe2,0x80,0x83,0x5b,0x2d,0x30,0x20,0x0,0x0,0x0,0x2d,0x31,0x25,0xf3,0xa0,0x80,0xb8,0x2d,0x2d,0x30,0x0,0x0,0xcb,0x90,0x12,0x2d,0x5b,0x2d,0x30,0x20,0x20,0x0,0x0,0x0,0x2d,0x31,0x25,0x2d,0xf3,0xa0,0x81,0xb2,0x5b,0x2d,0x30,0x20,0x0,0x0,0x0,0x2d,0x31,0x25,0x2d,0x2d,0x31,0x25,0x53,0x68,0x0,0x0,0x2d,0x5b,0x5f,0x2d,0x5f,0x3a,0x32,0x3a,0x66,0x61,0x6c,0x73,0x65,0x2d,0x30,0x20,0x0,0x0,0x0,0x2d,0x36,0x37,0x31,0x31,0x25,0x2d,0x5b,0x2d,0x30,0x20,0x0,0x0,0x0,0x2d,0x31,0x2d,0x5b,0x0,0x25,0x30,0x2d,0x20,0x7, Step #5: -0[1% \000\000\000-k%exi\335\205rts:2:t\000\022-[-0 \000\000\000)1%-\342\200\203[-0 \000\000\000-1%\363\240\200\270--0\000\000\313\220\022-[-0 \000\000\000-1%-\363\240\201\262[-0 \000\000\000-1%--1%Sh\000\000-[_-_:2:false-0 \000\000\000-6711%-[-0 \000\000\000-1-[\000%0- \007 Step #5: artifact_prefix='./'; Test unit written to ./oom-b255a5ee5a788e0aa89358598ac0e6f794270f06 Step #5: Base64: LTBbMSUgAAAALWslZXhp3YVydHM6Mjp0ABItWy0wICAAAAApMSUt4oCDWy0wIAAAAC0xJfOggLgtLTAAAMuQEi1bLTAgIAAAAC0xJS3zoIGyWy0wIAAAAC0xJS0tMSVTaAAALVtfLV86MjpmYWxzZS0wIAAAAC02NzExJS1bLTAgAAAALTEtWwAlMC0gBw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4533 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3994478591 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5642e1a33810, 0x5642e1c1d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5642e1c1d020,0x5642e3ab50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b255a5ee5a788e0aa89358598ac0e6f794270f06' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5663 processed earlier; will process 5366 files now Step #5: #1 pulse cov: 3673 ft: 3674 exec/s: 0 rss: 177Mb Step #5: ==163264== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5642d85289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5642deb8d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5642deb705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5642deb704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642d852ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5642d848fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5642d848a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5642d8520c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5642db4eff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5642db4eff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5642db4eff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5642db4eff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5642db4eff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5642db4eff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5642db4eff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5642db4eff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5642db4eff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5642db4eff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5642dd784f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5642da4b1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5642da4bcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5642da268c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5642da268c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5642da269738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5642da268874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5642da268874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5642da268874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5642deb72abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5642deb7b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5642deb63699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5642deb8e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f973a943082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5642d8488b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe2,0x80,0xaa,0x0,0x2d,0x2d,0x4f,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x63,0x65,0x6e,0x74,0x0,0x0,0x47,0x45,0x4f,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x63,0x65,0x6e,0x74,0x64,0xa,0x29,0xa,0x2,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2c,0xa,0x2d,0x10,0x64,0xa,0x2,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x29,0xa,0x2,0xa,0x2d,0xa,0xa,0x2d,0x2,0xa,0x2d,0xa,0xa,0x2c,0x64,0xa,0x2,0xa,0x2d,0xa,0x2d,0xa,0x62,0xa,0x30,0xf5,0xd2,0xf3,0x64,0xa,0xd5,0xa,0x2,0xa,0x33,0xa,0xdc,0xa,0xd2,0xa,0x2d,0xa,0x2d,0xa,0x62,0xa,0xd0,0xa,0x2d,0xa,0x64,0xa,0xd5,0xa,0x2,0xa,0x31,0xa,0xdc,0xa,0xd2,0xa,0x0,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xff, Step #5: \342\200\252\000--O--BEGIN ---cent\000\000GEO\012,\012-\012d\012-\012d\012centd\012)\012\002\012-\012\002\012-\012,\012-\020d\012\002-\012d\012-\012d\012d\012)\012\002\012-\012\012-\002\012-\012\012,d\012\002\012-\012-\012b\0120\365\322\363d\012\325\012\002\0123\012\334\012\322\012-\012-\012b\012\320\012-\012d\012\325\012\002\0121\012\334\012\322\012\000\012-\012-\012-\012\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-7745eab00e586b0b22cbfeeef24e573152f2e014 Step #5: Base64: 4oCqAC0tTy0tQkVHSU4gLS0tY2VudAAAR0VPCiwKLQpkCi0KZApjZW50ZAopCgIKLQoCCi0KLAotEGQKAi0KZAotCmQKZAopCgIKLQoKLQIKLQoKLGQKAgotCi0KYgow9dLzZArVCgIKMwrcCtIKLQotCmIK0AotCmQK1QoCCjEK3ArSCgAKLQotCi0K/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4534 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3995043031 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e1098bc810, 0x55e109aa601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e109aa6020,0x55e10b93e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7745eab00e586b0b22cbfeeef24e573152f2e014' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5665 processed earlier; will process 5364 files now Step #5: ==163300== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e1003b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e106a16898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e1069f95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e1069f94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e1003b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e100318b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e100313355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e1003a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e103378f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e103378f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e103378f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e103378f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e103378f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e103378f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e103378f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e103378f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e103378f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e103378f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e10560df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e10233ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e102345be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e1020f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e1020f1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e1020f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e1020f1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e1020f1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e1020f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e1069fbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e106a04928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e1069ec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e106a17112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7713266082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e100311b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x63,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x63,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x63,0x6e,0x3d,0x5c,0xa,0xa,0x64,0x6e,0x3a,0x43,0x6e,0x3d,0x5c, Step #5: dn:Cn=\\\012\012dn:Cn=\\\012\012dn:Cn=\\\012\012dn:cn=\\\012\012dn:Cn=\\\012\012dn:Cn=\\\012\012dn:Cn=\\\012\012dn:Cn=\\\012\012dn:Cn=\\\012\012dn:cn=\\\012\012dn:Cn=\\\012\012dn:Cn=\\\012\012dn:Cn=\\\012\012dn:Cn=\\\012\012dn:cn=\\\012\012dn:Cn=\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-0bd30583ab43d654348dfc7e13e6b3967e6790c9 Step #5: Base64: ZG46Q249XAoKZG46Q249XAoKZG46Q249XAoKZG46Y249XAoKZG46Q249XAoKZG46Q249XAoKZG46Q249XAoKZG46Q249XAoKZG46Q249XAoKZG46Y249XAoKZG46Q249XAoKZG46Q249XAoKZG46Q249XAoKZG46Q249XAoKZG46Y249XAoKZG46Q249XA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4535 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3995557034 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ad33ce810, 0x562ad35b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ad35b8020,0x562ad54500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0bd30583ab43d654348dfc7e13e6b3967e6790c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5666 processed earlier; will process 5363 files now Step #5: ==163336== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562ac9ec39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ad0528898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ad050b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ad050b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562ac9ec9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562ac9e2ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562ac9e25355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562ac9ebbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562acce8af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562acce8af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562acce8af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562acce8af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562acce8af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562acce8af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562acce8af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562acce8af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562acce8af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562acce8af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562acf11ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562acbe4cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562acbe57be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562acbc03c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562acbc03c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562acbc04738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562acbc03874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562acbc03874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562acbc03874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ad050dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ad0516928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ad04fe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ad0529112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fefff887082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562ac9e23b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0x2e,0xef,0xbc,0x8e,0xef,0xbc,0x8e,0xef,0xbc,0x8e,0xef,0xbc,0x8e, Step #5: ws:\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226.\357\274\216\357\274\216\357\274\216\357\274\216 Step #5: artifact_prefix='./'; Test unit written to ./oom-d6bb02cdd656e03718e8d178bd73b30043535b9e Step #5: Base64: d3M644yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yWLu+8ju+8ju+8ju+8jg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4536 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3996071323 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5601f9a2d810, 0x5601f9c1701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5601f9c17020,0x5601fbaaf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d6bb02cdd656e03718e8d178bd73b30043535b9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5667 processed earlier; will process 5362 files now Step #5: ==163372== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5601f05229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601f6b87898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601f6b6a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601f6b6a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5601f0528d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601f0489b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601f0484355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5601f051ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601f34e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601f34e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601f34e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601f34e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601f34e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601f34e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601f34e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601f34e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601f34e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601f34e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5601f577ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601f24abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601f24b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5601f2262c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5601f2262c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5601f2263738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5601f2262874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5601f2262874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5601f2262874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5601f6b6cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5601f6b75928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5601f6b5d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601f6b88112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc9ade0f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601f0482b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x7c,0x27,0x28,0xd5,0x8c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0x8f,0x10,0x29,0x7b,0x39,0x39,0x37,0x7d, Step #5: ||'(\325\214\000\000\000\000\000\000\000\000\000\000-\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000:\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\342\200\217\020){997} Step #5: artifact_prefix='./'; Test unit written to ./oom-5f9027d432612a43f4307921a3d27a67732dcdcf Step #5: Base64: fHwnKNWMAAAAAAAAAAAAAC0AAAAAAAAAAAAAAAAAAAAAAAA6AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA4oCPECl7OTk3fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4537 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3996584399 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558dc1ed6810, 0x558dc20c001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558dc20c0020,0x558dc3f580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f9027d432612a43f4307921a3d27a67732dcdcf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5668 processed earlier; will process 5361 files now Step #5: ==163408== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558db89cb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558dbf030898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558dbf0135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558dbf0134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558db89d1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558db8932b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558db892d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558db89c3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558dbb992f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558dbb992f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558dbb992f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558dbb992f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558dbb992f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558dbb992f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558dbb992f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558dbb992f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558dbb992f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558dbb992f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558dbdc27f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558dba954b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558dba95fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558dba70bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558dba70bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558dba70c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558dba70b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558dba70b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558dba70b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558dbf015abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558dbf01e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558dbf006699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558dbf031112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2f15071082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558db892bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x8,0x0,0x7,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x7,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2e,0x0,0x2e,0x2b,0x42,0xdb,0xbe,0x7c,0xdb,0xbe,0x2b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x64,0x41,0x41,0x41,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x70,0x70,0x70,0x70,0x70,0x30,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x2b,0x2b, Step #5: - \010\000\007\000\000\000\000\000\000\000\000\000\000\010\000\007\000\000\000\000\000\000\000\000\000\000\000\000\000\000.\000.+B\333\276|\333\276+\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000ppppppppppppppppppppdAAATTTTTTTTTTTTTTTTTTTTTTTTppppp0ppppppppppppp++ Step #5: artifact_prefix='./'; Test unit written to ./oom-ea54da3de36ad055a28110f076862a93c331e8cc Step #5: Base64: LSAIAAcAAAAAAAAAAAAACAAHAAAAAAAAAAAAAAAAAAAuAC4rQtu+fNu+KwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHBwcHBwcHBwcHBwcHBwcHBwcHBwZEFBQVRUVFRUVFRUVFRUVFRUVFRUVFRUVFRUVHBwcHBwMHBwcHBwcHBwcHBwcHArKw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4538 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3997101731 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560f495aa810, 0x560f4979401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560f49794020,0x560f4b62c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ea54da3de36ad055a28110f076862a93c331e8cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5669 processed earlier; will process 5360 files now Step #5: ==163444== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560f4009f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560f46704898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560f466e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560f466e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560f400a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560f40006b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560f40001355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560f40097c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560f43066f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560f43066f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560f43066f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560f43066f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560f43066f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560f43066f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560f43066f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560f43066f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560f43066f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560f43066f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560f452fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560f42028b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560f42033be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560f41ddfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560f41ddfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560f41de0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560f41ddf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560f41ddf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560f41ddf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560f466e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560f466f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560f466da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560f46705112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ba4774082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560f3ffffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x7b,0x9,0x20,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0x9,0x20,0x20,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0xa,0x20,0x6e,0x61,0x6d,0x65,0x3a,0xb,0x22,0x44,0x20,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x27,0x47,0x58,0x27,0x20,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x36,0x39,0x39,0x3a,0x37,0x40,0x2f,0xc8,0xc9,0xc8,0xc6,0x30,0x27,0x20,0x20,0x20,0x3e,0x20,0x20,0x5c,0x30,0x30,0x20,0x20,0x20,0x3c,0x49,0x20,0x3e,0x20,0x21,0x20,0x3e,0x20,0x21,0x2e,0x22,0x20,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x76,0x61,0x6c,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x22,0x20,0x20,0x20,0x7d,0x20,0x7d,0xa,0x20,0x20,0x7d,0x20,0x7d,0xa,0x20,0x20,0x7d,0x7d, Step #5: p{\011 doctype {\012mdecl {\011 entity {\012 name:\013\"D PUBLIC 'GX' 'http://699:7@/\310\311\310\3060' > \\00 <I > ! > !.\" ent {\012 val { name: \"D\" } }\012 } }\012 }} Step #5: artifact_prefix='./'; Test unit written to ./oom-b8a73bb5a2473a0815eb2d2daf03eb43540c0690 Step #5: Base64: cHsJIGRvY3R5cGUgewptZGVjbCB7CSAgZW50aXR5IHsKIG5hbWU6CyJEICBQVUJMSUMgJ0dYJyAnaHR0cDovLzY5OTo3QC/IycjGMCcgICA+ICBcMDAgICA8SSA+ICEgPiAhLiIgZW50IHsKICB2YWwgeyBuYW1lOiAiRCIgICB9IH0KICB9IH0KICB9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4539 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3997617364 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf1204f810, 0x55bf1223901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf12239020,0x55bf140d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b8a73bb5a2473a0815eb2d2daf03eb43540c0690' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5670 processed earlier; will process 5359 files now Step #5: ==163480== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bf08b449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf0f1a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf0f18c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf0f18c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf08b4ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf08aabb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf08aa6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf08b3cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf0bb0bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf0bb0bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf0bb0bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf0bb0bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf0bb0bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf0bb0bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf0bb0bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf0bb0bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf0bb0bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf0bb0bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf0dda0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf0aacdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf0aad8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf0a884c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf0a884c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf0a885738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf0a884874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf0a884874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf0a884874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf0f18eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf0f197928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf0f17f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf0f1aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe41bedf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf08aa4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x20,0x47,0x0,0x0,0xe,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x1,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x1,0x1,0x1,0x1,0x0,0x1,0xd7,0xa3,0x2a,0x73,0x20,0x34,0x20,0x28,0x1,0xd7,0xa3,0x2a,0x73,0x20,0x34,0x20,0x28,0x20,0x3a,0x2b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x1,0x1,0x1,0x81,0x0,0x1,0xd7,0xa3,0x2a,0x73,0x20,0x34,0x20,0x28,0x20,0x3a,0x2b, Step #5: / G\000\000\016\000\000\000\000\000\000\000\000\000\000\001\001\001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\001\001\001\001\000\001\327\243*s 4 (\001\327\243*s 4 ( :+\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\001\001\001\201\000\001\327\243*s 4 ( :+ Step #5: artifact_prefix='./'; Test unit written to ./oom-8e1c8bc89a7b6ede69c961dca0788eb1aa767227 Step #5: Base64: LyBHAAAOAAAAAAAAAAAAAAEBAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAEBAQEBAAHXoypzIDQgKAHXoypzIDQgKCA6KwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEBAQGBAAHXoypzIDQgKCA6Kw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4540 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3998147595 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab2ba6a810, 0x55ab2bc5401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab2bc54020,0x55ab2daec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8e1c8bc89a7b6ede69c961dca0788eb1aa767227' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5671 processed earlier; will process 5358 files now Step #5: ==163516== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ab2255f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab28bc4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab28ba75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab28ba74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab22565d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab224c6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab224c1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab22557c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab25526f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab25526f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab25526f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab25526f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab25526f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab25526f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab25526f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab25526f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab25526f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab25526f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab277bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab244e8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab244f3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab2429fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab2429fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab242a0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab2429f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab2429f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab2429f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab28ba9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab28bb2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab28b9a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab28bc5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1884176082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab224bfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xb9,0x84,0x20,0xa,0x2b,0x20,0x2f,0x43,0x32,0x33,0x0,0x2d,0x68,0xca,0xb7,0xf3,0xa0,0x81,0xbb,0x68,0x68,0x68,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x38,0x36,0x32,0x30,0x30,0x39,0xf3,0xa0,0x81,0x8f,0xbb,0x68,0x68,0x6c,0xf3,0xa0,0x81,0x1e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x95,0x2d,0x41, Step #5: \340\271\204 \012+ /C23\000-h\312\267\363\240\201\273hhh8888888888888888888888888888888888888888888888888800000000000000000000000000000000000000000862009\363\240\201\217\273hhl\363\240\201\036\000\000\000\000\000\000\000\225-A Step #5: artifact_prefix='./'; Test unit written to ./oom-855ed45626ddb66b7b05edb3dd67cfc5b5510780 Step #5: Base64: 4LmEIAorIC9DMjMALWjKt/OggbtoaGg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4ODAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwODYyMDA586CBj7toaGzzoIEeAAAAAAAAAJUtQQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4541 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3998660809 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9877e2810, 0x55e9879cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9879cc020,0x55e9898640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/855ed45626ddb66b7b05edb3dd67cfc5b5510780' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5672 processed earlier; will process 5357 files now Step #5: ==163552== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e97e2d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e98493c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e98491f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e98491f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e97e2ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e97e23eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e97e239355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e97e2cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e98129ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e98129ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e98129ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e98129ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e98129ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e98129ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e98129ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e98129ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e98129ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e98129ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e983533f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e980260b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e98026bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e980017c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e980017c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e980018738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e980017874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e980017874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e980017874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e984921abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e98492a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e984912699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e98493d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3428f4d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e97e237b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x20,0x2d,0x20,0x20,0x2d,0x20,0x2d,0x3a,0x7c,0x20,0x2d,0x2d,0xd6,0xae,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x3a,0x7c,0x20,0x2d,0x3a,0x20,0x3a,0x20,0x2d,0x20,0x2d,0x3a,0x7c,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x0,0x20,0x2d,0x2d,0x3a,0x7c,0x4f,0x0,0x0,0x9d,0x0,0x0,0x20,0x2d,0x3a,0x20,0x0,0x0,0x0,0x0,0x0,0x74,0x72,0x65,0x61,0x6d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x80,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0xd5,0x96,0xc8, Step #5: - - - -:| --\326\256\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\007\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\":| -: : - -:|\"\"\"\"\"\"\"\"\"\"\"\000 --:|O\000\000\235\000\000 -: \000\000\000\000\000tream\000\000\000\000\000\000\000\000\001\000\200\012\000\000\000\000\000\000\325\226\310 Step #5: artifact_prefix='./'; Test unit written to ./oom-347feb676f570a41f5fdef27acbc340f3744172c Step #5: Base64: LSAtICAtIC06fCAtLdauAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAByIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiI6fCAtOiA6IC0gLTp8IiIiIiIiIiIiIiIAIC0tOnxPAACdAAAgLTogAAAAAAB0cmVhbQAAAAAAAAAAAQCACgAAAAAAANWWyA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4542 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3999180152 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559709942810, 0x559709b2c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559709b2c020,0x55970b9c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/347feb676f570a41f5fdef27acbc340f3744172c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5673 processed earlier; will process 5356 files now Step #5: ==163588== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5597004379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559706a9c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559706a7f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559706a7f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55970043dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55970039eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559700399355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55970042fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5597033fef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5597033fef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5597033fef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5597033fef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5597033fef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5597033fef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5597033fef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5597033fef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5597033fef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5597033fef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559705693f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5597023c0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5597023cbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559702177c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559702177c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559702178738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559702177874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559702177874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559702177874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559706a81abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559706a8a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559706a72699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559706a9d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb78ec6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559700397b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xa,0xa,0xa,0x31,0xe1,0x9b,0x92,0xa,0xa,0xa,0x54,0xa,0xa,0xa,0xa,0xa,0xe1,0xb0,0x92,0xe1,0x9f,0x92,0xa,0xa,0xa,0xa,0x54,0xa,0xa,0xa,0xa,0xa,0xe1,0xb0,0x92,0xe1,0x9f,0x9a,0xa,0xa,0xa,0xa,0xa,0xa,0x9,0xa,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xa,0xa,0xa,0x31,0xe1,0x9b,0x92,0xa,0xa,0xa,0x54,0xa,0xa,0xa,0xa,0xa,0xe1,0xb0,0x92,0xe1,0x9f,0x92,0xa,0xa,0xa,0xa,0x54,0xa,0xa,0xa,0xa,0xa,0xe1,0xb0,0x92,0xe1,0x9f,0x9a,0xa,0xa,0xa,0xa,0xa,0xa,0x9,0xa,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text>\012\012\0121\341\233\222\012\012\012T\012\012\012\012\012\341\260\222\341\237\222\012\012\012\012T\012\012\012\012\012\341\260\222\341\237\232\012\012\012\012\012\012\011\012</text><text>\012\012\0121\341\233\222\012\012\012T\012\012\012\012\012\341\260\222\341\237\222\012\012\012\012T\012\012\012\012\012\341\260\222\341\237\232\012\012\012\012\012\012\011\012</text></svg></text></svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-566ec3e7d517f31e85e7e3503f3f3bbc3c9a1d1a Step #5: Base64: PHN2Zz48dGV4dD4KCgox4ZuSCgoKVAoKCgoK4bCS4Z+SCgoKClQKCgoKCuGwkuGfmgoKCgoKCgkKPC90ZXh0Pjx0ZXh0PgoKCjHhm5IKCgpUCgoKCgrhsJLhn5IKCgoKVAoKCgoK4bCS4Z+aCgoKCgoKCQo8L3RleHQ+PC9zdmc+PC90ZXh0Pjwvc3ZnPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4543 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3999706722 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ebd9c6e810, 0x55ebd9e5801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ebd9e58020,0x55ebdbcf00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/566ec3e7d517f31e85e7e3503f3f3bbc3c9a1d1a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5674 processed earlier; will process 5355 files now Step #5: ==163624== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ebd07639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ebd6dc8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ebd6dab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ebd6dab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ebd0769d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ebd06cab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ebd06c5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ebd075bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ebd372af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ebd372af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ebd372af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ebd372af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ebd372af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ebd372af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ebd372af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ebd372af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ebd372af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ebd372af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ebd59bff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ebd26ecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ebd26f7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ebd24a3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ebd24a3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ebd24a4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ebd24a3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ebd24a3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ebd24a3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ebd6dadabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ebd6db6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ebd6d9e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ebd6dc9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f413870b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ebd06c3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x20,0x7b,0xa,0x20,0x20,0x64,0x65,0x63,0x6c,0x20,0x7b,0x20,0x65,0x6e,0x63,0x20,0x7b,0xa,0x20,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x55,0x54,0x46,0x38,0xa,0x7d,0xa,0x20,0x20,0x7d,0xa,0x20,0x20,0x6d,0x69,0x73,0x63,0x20,0x7b,0xa,0x9,0x20,0x20,0x63,0x6f,0x6d,0x6d,0x65,0x6e,0x74,0x3a,0x20,0x22,0x20,0xed,0x9d,0x9d,0xed,0x9d,0x9d,0xdd,0x9d,0xc2,0x9d,0xe,0xed,0x9d,0x9d,0xdd,0x9d,0xc2,0x9d,0xe,0x29,0x3,0xe8,0x9d,0x9d,0xed,0x9d,0x9d,0x29,0x29,0xe8,0x9d,0x9d,0xed,0x9d,0x9d,0x29,0x20,0xed,0x9d,0x9d,0xed,0x9d,0x9d,0xdd,0x9d,0xc2,0x9d,0xe,0xed,0x9d,0x9d,0xdd,0x9d,0xc2,0x9d,0xe,0x29,0x3,0xe8,0x9d,0x9d,0xed,0x9d,0x9d,0x29,0x29,0xe8,0x22,0x20,0x7d,0x6d,0x69,0x73,0x63,0x20,0x7b,0xa,0x9,0x20,0x7d,0xa,0x7d, Step #5: p {\012 decl { enc {\012 name: UTF8\012}\012 }\012 misc {\012\011 comment: \" \355\235\235\355\235\235\335\235\302\235\016\355\235\235\335\235\302\235\016)\003\350\235\235\355\235\235))\350\235\235\355\235\235) \355\235\235\355\235\235\335\235\302\235\016\355\235\235\335\235\302\235\016)\003\350\235\235\355\235\235))\350\" }misc {\012\011 }\012} Step #5: artifact_prefix='./'; Test unit written to ./oom-0d52e2d9f2c8ac467f90efe5cabee0bc10b59c06 Step #5: Base64: cCB7CiAgZGVjbCB7IGVuYyB7CiAgbmFtZTogVVRGOAp9CiAgfQogIG1pc2MgewoJICBjb21tZW50OiAiIO2dne2dnd2dwp0O7Z2d3Z3CnQ4pA+idne2dnSkp6J2d7Z2dKSDtnZ3tnZ3dncKdDu2dnd2dwp0OKQPonZ3tnZ0pKegiIH1taXNjIHsKCSB9Cn0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4544 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4000227819 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56326af1c810, 0x56326b10601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56326b106020,0x56326cf9e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0d52e2d9f2c8ac467f90efe5cabee0bc10b59c06' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5675 processed earlier; will process 5354 files now Step #5: ==163660== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563261a119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563268076898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5632680595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5632680594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563261a17d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563261978b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563261973355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563261a09c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5632649d8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5632649d8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5632649d8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5632649d8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5632649d8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5632649d8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5632649d8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5632649d8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5632649d8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5632649d8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563266c6df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56326399ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5632639a5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563263751c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563263751c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563263752738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563263751874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563263751874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563263751874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56326805babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563268064928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56326804c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563268077112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f59e4218082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563261971b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x27,0x2,0x74,0x3,0x2,0x2,0x43,0x48,0x41,0x38,0x48,0x56,0x0,0x0,0x2,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x54,0x43,0x4f,0x4d,0x0,0x25,0xa7,0x5e,0x2b,0x56,0x28,0x0,0x0,0x2d,0x3,0x0,0xff,0xf4, Step #5: ID3\002'\002t\003\002\002CHA8HV\000\000\002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000TCOM\000%\247^+V(\000\000-\003\000\377\364 Step #5: artifact_prefix='./'; Test unit written to ./oom-16b93a4e155e085b903f4960c5c3f228e2b6b8e6 Step #5: Base64: SUQzAicCdAMCAkNIQThIVgAAAgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABUQ09NACWnXitWKAAALQMA//Q= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4545 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4000754599 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56526d341810, 0x56526d52b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56526d52b020,0x56526f3c30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16b93a4e155e085b903f4960c5c3f228e2b6b8e6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5676 processed earlier; will process 5353 files now Step #5: ==163696== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565263e369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56526a49b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56526a47e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56526a47e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565263e3cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565263d9db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565263d98355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565263e2ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565266dfdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565266dfdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565266dfdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565266dfdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565266dfdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565266dfdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565266dfdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565266dfdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565266dfdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565266dfdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565269092f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565265dbfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565265dcabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565265b76c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565265b76c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565265b77738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565265b76874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565265b76874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565265b76874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56526a480abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56526a489928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56526a471699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56526a49c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1565b98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565263d96b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x10,0x0,0x2f,0x0,0x0,0x0,0x0,0x4,0xb,0x2f,0x76,0x2f,0x0,0x0,0x4,0x2b,0x26,0x2f,0x76,0x2f,0x0,0x4,0x2b,0x2f,0x76,0x2f,0x0,0x0,0x4,0x2b,0x2f,0x76,0x2f,0xf3,0xa0,0x81,0xbc,0x0,0x0,0x0,0x0,0xf3,0xa0,0x81,0xbc,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x0,0x2f,0x0,0x0,0x0,0x0,0x4,0xb,0x2f,0x76,0x2f,0x0,0x0,0x4,0x2b,0x26,0x2f,0x76,0x2f,0x0,0x4,0x2b,0x2f,0x76,0x2f,0x0,0x0,0x4,0x2b,0x2f,0x76,0x2f,0xf3,0xa0,0x81,0xbc,0x0,0x0,0x0,0x0,0xf3,0xa0,0x81,0xbc,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x24,0xf3,0xca,0xb5,0xa0,0x81,0xa8,0x5b,0x0,0x0,0x0,0x0,0x0,0x1,0x24,0xf3,0xca,0xb5,0xa0,0x81,0xa8,0x5b, Step #5: $\020\000/\000\000\000\000\004\013/v/\000\000\004+&/v/\000\004+/v/\000\000\004+/v/\363\240\201\274\000\000\000\000\363\240\201\274\000\000\000\000\000\000\000\000\000\000\000\000\020\000/\000\000\000\000\004\013/v/\000\000\004+&/v/\000\004+/v/\000\000\004+/v/\363\240\201\274\000\000\000\000\363\240\201\274\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001$\363\312\265\240\201\250[\000\000\000\000\000\001$\363\312\265\240\201\250[ Step #5: artifact_prefix='./'; Test unit written to ./oom-eabf6d925ce64a5fba0034bd898815e987f5c941 Step #5: Base64: JBAALwAAAAAECy92LwAABCsmL3YvAAQrL3YvAAAEKy92L/OggbwAAAAA86CBvAAAAAAAAAAAAAAAABAALwAAAAAECy92LwAABCsmL3YvAAQrL3YvAAAEKy92L/OggbwAAAAA86CBvAAAAAAAAAAAAAAAAAAAAAAAASTzyrWggahbAAAAAAABJPPKtaCBqFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4546 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4001276925 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e05637810, 0x562e0582101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e05821020,0x562e076b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eabf6d925ce64a5fba0034bd898815e987f5c941' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5677 processed earlier; will process 5352 files now Step #5: ==163732== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562dfc12c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e02791898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e027745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e027744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562dfc132d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562dfc093b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562dfc08e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562dfc124c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562dff0f3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562dff0f3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562dff0f3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562dff0f3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562dff0f3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562dff0f3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562dff0f3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562dff0f3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562dff0f3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562dff0f3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e01388f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562dfe0b5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562dfe0c0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562dfde6cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562dfde6cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562dfde6d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562dfde6c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562dfde6c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562dfde6c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e02776abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e0277f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e02767699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e02792112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7eaa161082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562dfc08cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x90,0xa,0xc5,0x90,0xa,0xcd,0x90,0xa,0xcd,0x90,0xa,0xcd,0x90,0xa,0xcd,0x8a,0xa,0xcd,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0xae,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0xed,0x96,0x90,0xed,0x90,0x90,0xa,0x5b,0x5b,0x5b,0x5b,0x5b,0xed,0x96,0x90,0xed,0x90,0x90,0x5b,0x5b,0xa,0xed,0x5b,0x96, Step #5: \315\220\012\305\220\012\315\220\012\315\220\012\315\220\012\315\212\012\315\220\012\355\226\220\355\220\220\012\355\226\220\355\220\220\012\355\226\220\355\220\220\012\355\226\220\355\220\220\012\355\226\220\355\220\220\012\355\226\220\355\220\220\012\355\226\220\355\220\220\012\355\226\220\355\220\220\012\355\226\220\355\220\220\012\355\226\220\355\220\220\012\355\226\220\355\220\220\012\355\226\220\355\220\256\012\355\226\220\355\220\220\012\355\226\220\355\220\220\012\355\226\220\355\220\220\012[[[[[\355\226\220\355\220\220[[\012\355[\226 Step #5: artifact_prefix='./'; Test unit written to ./oom-1ea43d49b8dc1188cb3b4d3ee7406745b00f7a30 Step #5: Base64: zZAKxZAKzZAKzZAKzZAKzYoKzZAK7ZaQ7ZCQCu2WkO2QkArtlpDtkJAK7ZaQ7ZCQCu2WkO2QkArtlpDtkJAK7ZaQ7ZCQCu2WkO2QkArtlpDtkJAK7ZaQ7ZCQCu2WkO2QkArtlpDtkK4K7ZaQ7ZCQCu2WkO2QkArtlpDtkJAKW1tbW1vtlpDtkJBbWwrtW5Y= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4547 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4001782568 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561cfd670810, 0x561cfd85a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561cfd85a020,0x561cff6f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ea43d49b8dc1188cb3b4d3ee7406745b00f7a30' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5678 processed earlier; will process 5351 files now Step #5: #1 pulse cov: 11330 ft: 11331 exec/s: 0 rss: 194Mb Step #5: ==163768== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561cf41659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561cfa7ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561cfa7ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561cfa7ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561cf416bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561cf40ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561cf40c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561cf415dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561cf712cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561cf712cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561cf712cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561cf712cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561cf712cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561cf712cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561cf712cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561cf712cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561cf712cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561cf712cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561cf93c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561cf60eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561cf60f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561cf5ea5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561cf5ea5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561cf5ea6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561cf5ea5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561cf5ea5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561cf5ea5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561cfa7afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561cfa7b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561cfa7a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561cfa7cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb6930a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561cf40c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x53,0x45,0x4c,0x45,0x63,0x54,0x26,0x30,0x62,0x31,0x31,0x26,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x31,0x26,0x62,0x31,0x26,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x26,0x30,0x62,0x31,0x23,0x30,0x62,0x31,0x26,0x30,0x61,0x30, Step #5: SELEcT&0b11&0b1#0b1&0b1#0b1&0b1&0b1#0b1&0b1#0b1#0b11&b1&0b1#0b1&0b1#0b1&0b1#0b1&0b1#0b1&0b1&0b1&0b1#0b1&0b1#0b1&0b1#0b1&0b1&0b1#0b1&0b1#0b1&0a0 Step #5: artifact_prefix='./'; Test unit written to ./oom-c3dfc221406329bc9ccdde1868ffe2724b7392fd Step #5: Base64: U0VMRWNUJjBiMTEmMGIxIzBiMSYwYjEjMGIxJjBiMSYwYjEjMGIxJjBiMSMwYjEjMGIxMSZiMSYwYjEjMGIxJjBiMSMwYjEmMGIxIzBiMSYwYjEjMGIxJjBiMSYwYjEmMGIxIzBiMSYwYjEjMGIxJjBiMSMwYjEmMGIxJjBiMSMwYjEmMGIxIzBiMSYwYTA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4548 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4002357212 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d4791ed810, 0x55d4793d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d4793d7020,0x55d47b26f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c3dfc221406329bc9ccdde1868ffe2724b7392fd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5680 processed earlier; will process 5349 files now Step #5: ==163804== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d46fce29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d476347898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d47632a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d47632a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d46fce8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d46fc49b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d46fc44355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d46fcdac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d472ca9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d472ca9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d472ca9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d472ca9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d472ca9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d472ca9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d472ca9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d472ca9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d472ca9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d472ca9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d474f3ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d471c6bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d471c76be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d471a22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d471a22c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d471a23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d471a22874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d471a22874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d471a22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d47632cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d476335928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d47631d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d476348112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc21bf87082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d46fc42b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x52,0x41,0x51,0x51,0x66,0x69,0x64,0x3d,0x42,0x42,0xa,0x3d,0x20,0x2a,0x2a,0x2a,0x2a,0x2a,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x2a,0x2a,0x2a,0x2a,0x2a,0x24,0x0,0x0,0x0,0x20,0x0,0x0,0x60,0x60,0x2a,0x2a,0x5b,0x5b,0x5b,0x6f,0x40,0x43,0xa,0x5b,0x5b,0x24, Step #5: rRAQQfid=BB\012= *****IIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII*****$\000\000\000 \000\000``**[[[o@C\012[[$ Step #5: artifact_prefix='./'; Test unit written to ./oom-b94903aa384dfa78cb1e3b7d9e837f847be3a8d6 Step #5: Base64: clJBUVFmaWQ9QkIKPSAqKioqKklJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJKioqKiokAAAAIAAAYGAqKltbW29AQwpbWyQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4549 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4002878445 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fa294cf810, 0x55fa296b901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fa296b9020,0x55fa2b5510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b94903aa384dfa78cb1e3b7d9e837f847be3a8d6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5681 processed earlier; will process 5348 files now Step #5: ==163840== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fa1ffc49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fa26629898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fa2660c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fa2660c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fa1ffcad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fa1ff2bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fa1ff26355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fa1ffbcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fa22f8bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fa22f8bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fa22f8bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fa22f8bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fa22f8bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fa22f8bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fa22f8bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fa22f8bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fa22f8bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fa22f8bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fa25220f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fa21f4db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fa21f58be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fa21d04c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fa21d04c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fa21d05738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fa21d04874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fa21d04874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fa21d04874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fa2660eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fa26617928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fa265ff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fa2662a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe290d3f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fa1ff24b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa, Step #5: ===================================\012=========================================\012================================================================\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-d11f215b4a6b86f0e5165eda0dc108e52da2e6ab Step #5: Base64: PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4550 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4003380226 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d20bcbc810, 0x55d20bea601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d20bea6020,0x55d20dd3e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d11f215b4a6b86f0e5165eda0dc108e52da2e6ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5682 processed earlier; will process 5347 files now Step #5: #1 pulse cov: 3849 ft: 3850 exec/s: 0 rss: 176Mb Step #5: ==163876== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d2027b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d208e16898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d208df95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d208df94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d2027b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d202718b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d202713355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d2027a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d205778f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d205778f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d205778f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d205778f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d205778f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d205778f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d205778f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d205778f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d205778f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d205778f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d207a0df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d20473ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d204745be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d2044f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d2044f1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d2044f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d2044f1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d2044f1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d2044f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d208dfbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d208e04928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d208dec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d208e17112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f574c15a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d202711b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x20,0x7b,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0xa,0x20,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0xa,0x20,0x6e,0x61,0x6d,0x65,0x3a,0xa,0x22,0x44,0x20,0x20,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x5c,0x27,0x45,0x59,0x27,0x20,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x80,0xc5,0xd0,0x39,0x40,0x2f,0x3f,0x74,0x23,0xdc,0xd0,0x23,0x23,0x27,0x20,0x20,0x20,0x3e,0x20,0x20,0x5c,0x30,0x30,0x30,0x5c,0x72,0x20,0x20,0x20,0x20,0x3c,0x41,0x3e,0x20,0xba,0xb9,0xdf,0xde,0x44,0x20,0x20,0x20,0x57,0x22,0x20,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x76,0x61,0x6c,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x22,0x20,0x7d,0x20,0x7d,0xc,0x7d,0x20,0x7d,0x20,0x7d,0x7d, Step #5: p {doctype {\012mdecl {\012 entity {\012 name:\012\"D PUBLIC \\'EY' 'http://\200\305\3209@/?t#\334\320##' > \\000\\r <A> \272\271\337\336D W\" ent {\012 val { name: \"D\" } }\014} } }} Step #5: artifact_prefix='./'; Test unit written to ./oom-d71c5cead4d892e377a8878a0bcaade66184e436 Step #5: Base64: cCB7ZG9jdHlwZSB7Cm1kZWNsIHsKIGVudGl0eSB7CiBuYW1lOgoiRCAgIFBVQkxJQyBcJ0VZJyAnaHR0cDovL4DF0DlALz90I9zQIyMnICAgPiAgXDAwMFxyICAgIDxBPiC6ud/eRCAgIFciIGVudCB7CiAgdmFsIHsgbmFtZTogIkQiIH0gfQx9IH0gfX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4551 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4003943831 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a79adb5810, 0x55a79af9f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a79af9f020,0x55a79ce370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d71c5cead4d892e377a8878a0bcaade66184e436' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5684 processed earlier; will process 5345 files now Step #5: ==163912== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a7918aa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a797f0f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a797ef25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a797ef24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a7918b0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a791811b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a79180c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a7918a2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a794871f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a794871f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a794871f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a794871f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a794871f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a794871f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a794871f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a794871f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a794871f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a794871f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a796b06f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a793833b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a79383ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a7935eac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a7935eac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a7935eb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a7935ea874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a7935ea874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a7935ea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a797ef4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a797efd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a797ee5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a797f10112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f273b17c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a79180ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xbf,0x3c,0x6f,0x3e,0x6e,0x3c,0x6e,0x3e,0xef,0xbb,0xbf,0x3c,0x67,0x31,0x3e,0x3c,0x6d,0x3e,0x3c,0x59,0x34,0x43,0x3e,0x35,0x3c,0x49,0x3e,0x3c,0x69,0x4d,0x3e,0x3c,0x49,0x30,0x5a,0x3e,0x3c,0x48,0x3e,0x3c,0x66,0x3e,0x3c,0x54,0x35,0x3e,0x3c,0x68,0x30,0x3e,0x3c,0x47,0x30,0x3e,0x3c,0x50,0x3a,0x3e,0x3c,0x71,0x30,0x3e,0x3c,0x59,0x36,0x3e,0x3c,0x41,0x69,0x3e,0x3c,0x57,0x59,0x3e,0x3c,0x69,0x37,0x3e,0x3c,0x41,0x3e,0x3c,0x61,0x3e,0x3c,0x57,0x32,0x3e,0x3c,0x7a,0x3e,0x3e,0x3c,0x62,0x73,0x3e,0x3c,0x41,0x32,0x3e,0x3c,0x68,0x69,0x61,0x3e,0x3c,0x45,0x3e,0x69,0x3c,0x4d,0x3e,0x3e,0x50,0x3c,0x51,0x4a,0x37,0x3e,0x3c,0x59,0x39,0x3e,0x3c,0x46,0x30,0x3e,0x3c,0x59,0x3e,0x3c,0x64,0x3e,0x35,0x3c,0x41,0x6d,0x3e,0x3c,0x0,0xa1, Step #5: \357\273\277<o>n<n>\357\273\277<g1><m><Y4C>5<I><iM><I0Z><H><f><T5><h0><G0><P:><q0><Y6><Ai><WY><i7><A><a><W2><z>><bs><A2><hia><E>i<M>>P<QJ7><Y9><F0><Y><d>5<Am><\000\241 Step #5: artifact_prefix='./'; Test unit written to ./oom-d83bf7e2c7644b431da41aa8760b3696f4ae8d4b Step #5: Base64: 77u/PG8+bjxuPu+7vzxnMT48bT48WTRDPjU8ST48aU0+PEkwWj48SD48Zj48VDU+PGgwPjxHMD48UDo+PHEwPjxZNj48QWk+PFdZPjxpNz48QT48YT48VzI+PHo+Pjxicz48QTI+PGhpYT48RT5pPE0+PlA8UUo3PjxZOT48RjA+PFk+PGQ+NTxBbT48AKE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4552 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4004458876 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564fd87c5810, 0x564fd89af01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564fd89af020,0x564fda8470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d83bf7e2c7644b431da41aa8760b3696f4ae8d4b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5685 processed earlier; will process 5344 files now Step #5: ==163948== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564fcf2ba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564fd591f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564fd59025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564fd59024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564fcf2c0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564fcf221b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564fcf21c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564fcf2b2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564fd2281f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564fd2281f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564fd2281f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564fd2281f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564fd2281f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564fd2281f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564fd2281f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564fd2281f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564fd2281f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564fd2281f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564fd4516f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564fd1243b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564fd124ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564fd0ffac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564fd0ffac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564fd0ffb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564fd0ffa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564fd0ffa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564fd0ffa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564fd5904abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564fd590d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564fd58f5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564fd5920112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f46ab3eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564fcf21ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xa,0x73,0x3a,0x22,0x20,0x33,0x34,0x30,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x24,0x26,0x26,0x23,0x30,0x30,0x30,0x3b,0x24,0x50,0x41,0x54,0x48,0x36,0x34,0x30,0x39,0x37,0x34,0x34,0x35,0x36,0x32,0x33,0x2d,0x37,0x38,0x36,0x39,0x32,0x36,0xa,0xe,0x2d,0x2d,0x2d,0x33,0x37,0x7d,0xa,0x32,0x35,0x37,0x7d,0xe,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x39,0x30,0x33,0x78,0x31,0x38,0x34,0x34,0x36,0x36,0x24,0x27,0x24,0x27,0x33,0x37,0x2f,0x39,0x35,0x38,0x34,0x33,0x37,0x39,0x97,0x7d,0xa,0xe,0x2d,0x39,0x32,0x31,0x35,0x35,0x31,0x35,0x34,0x30,0x36,0x31,0x36,0x37,0x33,0x36,0x38,0x33,0x37,0xaf,0x36,0x34,0x38,0x7d,0xa,0xe,0x31,0x7d,0xa,0xe,0x30,0x2d,0x31,0x20,0x22, Step #5: FUZZTESTv1\012s:\" 3400282366920$&&#000;$PATH64097445623-786926\012\016---37}\012257}\0162147483903x184466$'$'37/9584379\227}\012\016-921551540616736837\257648}\012\0161}\012\0160-1 \" Step #5: artifact_prefix='./'; Test unit written to ./oom-949f4d6a75ce7e366ec555e8c1dca66aa1bf69c6 Step #5: Base64: RlVaWlRFU1R2MQpzOiIgMzQwMDI4MjM2NjkyMCQmJiMwMDA7JFBBVEg2NDA5NzQ0NTYyMy03ODY5MjYKDi0tLTM3fQoyNTd9DjIxNDc0ODM5MDN4MTg0NDY2JCckJzM3Lzk1ODQzNzmXfQoOLTkyMTU1MTU0MDYxNjczNjgzN682NDh9Cg4xfQoOMC0xICI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4553 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4004973949 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b6d4fd810, 0x557b6d6e701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b6d6e7020,0x557b6f57f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/949f4d6a75ce7e366ec555e8c1dca66aa1bf69c6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5686 processed earlier; will process 5343 files now Step #5: #1 pulse cov: 3842 ft: 3843 exec/s: 0 rss: 174Mb Step #5: ==163984== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557b63ff29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b6a657898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b6a63a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b6a63a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b63ff8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b63f59b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b63f54355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b63feac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b66fb9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b66fb9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b66fb9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b66fb9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b66fb9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b66fb9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b66fb9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b66fb9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b66fb9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b66fb9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b6924ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b65f7bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b65f86be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b65d32c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b65d32c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b65d33738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b65d32874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b65d32874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b65d32874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b6a63cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b6a645928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b6a62d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b6a658112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f497723d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b63f52b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xe3,0x8e,0xaf,0xe3,0x89,0xbc,0xe3,0x8c,0x87,0xcd,0x84,0xa,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xe3,0x8e,0xaf,0xe3,0x89,0xbc,0xe3,0x8c,0x87,0xcd,0x84,0xa,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xe3,0x8e,0xaf,0xe3,0x89,0xbc,0xe3,0x8c,0x87,0xcd,0x84,0xa,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xe3,0x8e,0xaf,0xe3,0x89,0xbc,0xe3,0x8c,0x87,0xcd,0x84,0xa,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xe3,0x8e,0xaf,0xe3,0x89,0xbc,0xe3,0x8c,0x87,0xcd,0x84,0xa,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xe3,0x8e,0xaf,0xe3,0x89,0xbc,0xe3,0x8c,0x87,0xcd,0x84,0xa,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xe3,0x8e,0xaf,0xe3,0x89,0xbc,0xe3,0x8c,0x87,0xcd,0x84,0xa,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xe3,0x8e,0xaf,0xe3,0x89,0xbc,0xe3,0x8c,0x87,0xcd,0x84, Step #5: \343\215\277\343\214\226\343\216\257\343\211\274\343\214\207\315\204\012\343\215\277\343\214\226\343\216\257\343\211\274\343\214\207\315\204\012\343\215\277\343\214\226\343\216\257\343\211\274\343\214\207\315\204\012\343\215\277\343\214\226\343\216\257\343\211\274\343\214\207\315\204\012\343\215\277\343\214\226\343\216\257\343\211\274\343\214\207\315\204\012\343\215\277\343\214\226\343\216\257\343\211\274\343\214\207\315\204\012\343\215\277\343\214\226\343\216\257\343\211\274\343\214\207\315\204\012\343\215\277\343\214\226\343\216\257\343\211\274\343\214\207\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-1329f53c718f8b69e0f6dae10880a94c9c3e225a Step #5: Base64: 442/44yW446v44m844yHzYQK442/44yW446v44m844yHzYQK442/44yW446v44m844yHzYQK442/44yW446v44m844yHzYQK442/44yW446v44m844yHzYQK442/44yW446v44m844yHzYQK442/44yW446v44m844yHzYQK442/44yW446v44m844yHzYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4554 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4005531912 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558be2c11810, 0x558be2dfb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558be2dfb020,0x558be4c930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1329f53c718f8b69e0f6dae10880a94c9c3e225a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5688 processed earlier; will process 5341 files now Step #5: ==164020== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558bd97069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558bdfd6b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558bdfd4e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558bdfd4e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558bd970cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558bd966db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558bd9668355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558bd96fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558bdc6cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558bdc6cdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558bdc6cdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558bdc6cdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558bdc6cdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558bdc6cdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558bdc6cdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558bdc6cdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558bdc6cdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558bdc6cdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558bde962f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558bdb68fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558bdb69abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558bdb446c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558bdb446c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558bdb447738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558bdb446874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558bdb446874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558bdb446874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558bdfd50abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558bdfd59928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558bdfd41699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558bdfd6c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feba6108082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558bd9666b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x10,0x0,0x2f,0x0,0x0,0x0,0x0,0x4,0xb,0x2f,0x76,0x2f,0x0,0x0,0x4,0x2b,0x26,0x2f,0x76,0x2f,0x0,0x4,0x2b,0x2f,0x76,0x2f,0x0,0x0,0x4,0x2b,0x2f,0x76,0x2f,0xf3,0xa0,0x81,0xbc,0x0,0x0,0x0,0x0,0xf3,0xa0,0x81,0xbc,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x0,0x2f,0x0,0x0,0x0,0x0,0x4,0xb,0x2f,0x76,0x2f,0x0,0x0,0x4,0x2b,0x26,0x2f,0x76,0x2f,0x0,0x4,0x2b,0x2f,0x76,0x2f,0x0,0x0,0x4,0x2b,0x2f,0x76,0x2f,0xf3,0xa0,0x81,0xbc,0x0,0x0,0x0,0x0,0xf3,0xa0,0x81,0xbc,0x0,0x0,0x0,0x2f,0x76,0x2f,0xf3,0xa0,0x81,0xbc,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x24,0xf3,0xca,0xb5,0xa0,0x81,0xa8,0x5b,0x0,0x0,0x0,0x0,0x0,0x1,0x24,0xf3,0xca,0xb5,0xa0,0x81,0xa8,0x5b, Step #5: $\020\000/\000\000\000\000\004\013/v/\000\000\004+&/v/\000\004+/v/\000\000\004+/v/\363\240\201\274\000\000\000\000\363\240\201\274\000\000\000\000\000\000\000\000\000\000\000\000\020\000/\000\000\000\000\004\013/v/\000\000\004+&/v/\000\004+/v/\000\000\004+/v/\363\240\201\274\000\000\000\000\363\240\201\274\000\000\000/v/\363\240\201\274\000\000\000\000\000\000\000\001$\363\312\265\240\201\250[\000\000\000\000\000\001$\363\312\265\240\201\250[ Step #5: artifact_prefix='./'; Test unit written to ./oom-c65fc0deaf76682aa40ab60b6aec804dbc21126c Step #5: Base64: JBAALwAAAAAECy92LwAABCsmL3YvAAQrL3YvAAAEKy92L/OggbwAAAAA86CBvAAAAAAAAAAAAAAAABAALwAAAAAECy92LwAABCsmL3YvAAQrL3YvAAAEKy92L/OggbwAAAAA86CBvAAAAC92L/OggbwAAAAAAAAAASTzyrWggahbAAAAAAABJPPKtaCBqFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4555 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4006045538 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c9bc0b2810, 0x55c9bc29c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c9bc29c020,0x55c9be1340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c65fc0deaf76682aa40ab60b6aec804dbc21126c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5689 processed earlier; will process 5340 files now Step #5: #1 pulse cov: 4004 ft: 4005 exec/s: 0 rss: 176Mb Step #5: ==164056== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c9b2ba79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c9b920c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9b91ef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9b91ef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9b2badd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9b2b0eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c9b2b09355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9b2b9fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c9b5b6ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c9b5b6ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c9b5b6ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c9b5b6ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c9b5b6ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c9b5b6ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c9b5b6ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c9b5b6ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c9b5b6ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c9b5b6ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c9b7e03f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9b4b30b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9b4b3bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c9b48e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c9b48e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c9b48e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c9b48e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c9b48e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c9b48e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c9b91f1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c9b91fa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c9b91e2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c9b920d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f11d8779082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c9b2b07b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xa,0x73,0x75,0x62,0x20,0x7b,0xa,0x20,0x73,0x75,0x62,0x20,0x7b,0xa,0x20,0x20,0x73,0x75,0x62,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x73,0x75,0x62,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x73,0x75,0x62,0x20,0x7b,0x20,0x73,0x3a,0x20,0x22,0x47,0x49,0x46,0x38,0x33,0x2b,0x2e,0x26,0x7e,0x60,0x5d,0x5e,0x20,0x2c,0x46,0x73,0x4e,0x32,0x35,0x67,0x52,0x63,0x4a,0x5c,0x30,0x31,0x30,0x5c,0x30,0x33,0x34,0x58,0x60,0x68,0x6b,0x37,0x45,0x49,0x42,0x28,0x78,0x2d,0x34,0x48,0x39,0x2a,0x59,0x71,0x6b,0x59,0x2d,0x31,0x28,0x58,0x31,0x30,0x2f,0x64,0x72,0x22,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x7d,0xa,0x7d,0xa, Step #5: FUZZTESTv1\012sub {\012 sub {\012 sub {\012 sub {\012 sub { s: \"GIF83+.&~`]^ ,FsN25gRcJ\\010\\034X`hk7EIB(x-4H9*YqkY-1(X10/dr\" }\012 }\012 }\012 }\012}\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-dbf571239f18050480b1cc6806a98ee94eeed97e Step #5: Base64: RlVaWlRFU1R2MQpzdWIgewogc3ViIHsKICBzdWIgewogICAgc3ViIHsKICAgICAgICBzdWIgeyBzOiAiR0lGODMrLiZ+YF1eICxGc04yNWdSY0pcMDEwXDAzNFhgaGs3RUlCKHgtNEg5Kllxa1ktMShYMTAvZHIiIH0KICAgICAgfQogICAgfQogIH0KfQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4556 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4006719036 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55efd8b6b810, 0x55efd8d5501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55efd8d55020,0x55efdabed0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dbf571239f18050480b1cc6806a98ee94eeed97e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5691 processed earlier; will process 5338 files now Step #5: ==164092== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55efcf6609c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55efd5cc5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55efd5ca85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55efd5ca84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55efcf666d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55efcf5c7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55efcf5c2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55efcf658c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55efd2627f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55efd2627f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55efd2627f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55efd2627f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55efd2627f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55efd2627f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55efd2627f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55efd2627f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55efd2627f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55efd2627f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55efd48bcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55efd15e9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55efd15f4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55efd13a0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55efd13a0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55efd13a1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55efd13a0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55efd13a0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55efd13a0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55efd5caaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55efd5cb3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55efd5c9b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55efd5cc6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8055cce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55efcf5c0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x63,0x6f,0x6e,0x72,0x65,0x6e,0x74,0x61,0x62,0x6c,0x65,0x3a,0x65,0x78,0x65,0x63,0x75,0x74,0x65,0x67,0x63,0x6f,0x3e,0x3c,0x73,0x6e,0x6f,0x72,0x6e,0x6e,0x72,0x65,0x66,0x67,0x6b,0x6e,0x3e,0x3c,0x63,0x72,0x6f,0x61,0x6e,0x6e,0x67,0x63,0x6f,0x3e,0x3c,0x63,0x6e,0x6f,0x72,0x6e,0x6e,0x72,0x65,0x66,0x67,0x63,0x6f,0x3e,0x3c,0x67,0x63,0x6f,0x3e,0x3c,0x63,0x2d,0x6e,0x72,0x65,0x6e,0x67,0x63,0x6d,0x3e,0x3c,0x63,0x6f,0x73,0x6b,0x69,0x70,0x2d,0x77,0x68,0x69,0x74,0x65,0x2d,0x73,0x65,0x6e,0x67,0x63,0x6f,0x3e,0x3c,0x63,0x6e,0x6f,0x72,0x6e,0x6e,0x72,0x65,0x66,0x67,0x63,0x6f,0x3e,0x3c,0x63,0x6f,0x6e,0x72,0x61,0x6e,0x65,0x63,0x6f,0x3e,0x3c,0x63,0x6e,0x6f,0x3e,0x3c,0x63,0x2d,0x6e,0x72,0x65,0x6e,0x67,0x63,0x6d,0x3e,0x6f,0x6e,0x3e, Step #5: <conrentable:executegco><snornnrefgkn><croanngco><cnornnrefgco><gco><c-nrengcm><coskip-white-sengco><cnornnrefgco><conraneco><cno><c-nrengcm>on> Step #5: artifact_prefix='./'; Test unit written to ./oom-ea9e6ba4f377fa46d1ec4879866c3be5c142a1c1 Step #5: Base64: PGNvbnJlbnRhYmxlOmV4ZWN1dGVnY28+PHNub3JubnJlZmdrbj48Y3JvYW5uZ2NvPjxjbm9ybm5yZWZnY28+PGdjbz48Yy1ucmVuZ2NtPjxjb3NraXAtd2hpdGUtc2VuZ2NvPjxjbm9ybm5yZWZnY28+PGNvbnJhbmVjbz48Y25vPjxjLW5yZW5nY20+b24+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4557 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4007222934 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f8865e4810, 0x55f8867ce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f8867ce020,0x55f8886660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ea9e6ba4f377fa46d1ec4879866c3be5c142a1c1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5692 processed earlier; will process 5337 files now Step #5: ==164128== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f87d0d99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f88373e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8837215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8837214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f87d0dfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f87d040b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f87d03b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f87d0d1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8800a0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8800a0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8800a0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8800a0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8800a0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8800a0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8800a0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8800a0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8800a0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8800a0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f882335f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f87f062b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f87f06dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f87ee19c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f87ee19c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f87ee1a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f87ee19874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f87ee19874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f87ee19874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f883723abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f88372c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f883714699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f88373f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa51224e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f87d039b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x39,0x2d,0x34,0x2d,0x31,0x54,0x30,0x3a,0x32,0x3a,0x33,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdc,0xbb,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xd8,0xbb,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xff,0xff,0xff,0x7f,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xd8,0xbb,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdc,0xb1,0xdf,0xae,0xb1, Step #5: 9-4-1T0:2:3\337\263\337\261\337\261\334\273\337\261\337\263\337\261\337\263\337\261\337\263\337\261\337\261\330\273\337\261\337\261\337\261\337\261\337\261\337\377\377\377\177\261\337\256\337\261\337\261\337\261\337\263\337\261\337\263\337\261\337\261\337\263\337\261\337\261\337\261\337\261\337\263\337\261\337\263\337\261\337\261\337\263\337\261\337\261\330\273\337\261\337\261\337\261\337\261\337\261\337\263\337\261\337\261\337\256\337\261\337\256\337\261\337\261\337\263\337\261\337\256\337\261\337\263\337\261\337\261\334\261\337\256\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-19714f0f9ea2d98750133b1d490b0146bdb09d7a Step #5: Base64: OS00LTFUMDoyOjPfs9+x37Hcu9+x37Pfsd+z37Hfs9+x37HYu9+x37Hfsd+x37Hf////f7Hfrt+x37Hfsd+z37Hfs9+x37Hfs9+x37Hfsd+x37Pfsd+z37Hfsd+z37Hfsdi737Hfsd+x37Hfsd+z37Hfsd+u37Hfrt+x37Hfs9+x367fsd+z37Hfsdyx366x Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4558 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4007736526 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f46d36c810, 0x55f46d55601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f46d556020,0x55f46f3ee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/19714f0f9ea2d98750133b1d490b0146bdb09d7a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5693 processed earlier; will process 5336 files now Step #5: ==164164== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f463e619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f46a4c6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f46a4a95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f46a4a94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f463e67d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f463dc8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f463dc3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f463e59c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f466e28f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f466e28f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f466e28f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f466e28f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f466e28f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f466e28f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f466e28f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f466e28f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f466e28f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f466e28f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4690bdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f465deab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f465df5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f465ba1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f465ba1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f465ba2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f465ba1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f465ba1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f465ba1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f46a4ababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f46a4b4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f46a49c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f46a4c7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f92adbfe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f463dc1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xcf,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa, Step #5: ===================================\012=========================================\012========================================\317========================\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-5a32814bd57f15e1d00a5139ecee9156c180bd16 Step #5: Base64: PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Pc89PT09PT09PT09PT09PT09PT09PT09PT0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4559 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4008234452 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eaa4429810, 0x55eaa461301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eaa4613020,0x55eaa64ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5a32814bd57f15e1d00a5139ecee9156c180bd16' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5694 processed earlier; will process 5335 files now Step #5: ==164200== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ea9af1e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eaa1583898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eaa15665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eaa15664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea9af24d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea9ae85b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea9ae80355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea9af16c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea9dee5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea9dee5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea9dee5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea9dee5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea9dee5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea9dee5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea9dee5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea9dee5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea9dee5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea9dee5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eaa017af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea9cea7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea9ceb2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea9cc5ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea9cc5ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea9cc5f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea9cc5e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea9cc5e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea9cc5e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eaa1568abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eaa1571928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eaa1559699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eaa1584112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4f23d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea9ae7eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x39,0x2d,0x34,0x2d,0x31,0x54,0x30,0x3a,0x32,0x3a,0x33,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdc,0xbb,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xd8,0xbb,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xff,0xff,0xff,0x7f,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xd8,0xbb,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdc,0xb1,0xdf,0xae,0xb1, Step #5: 9-4-1T0:2:3\337\263\337\261\337\261\337\256\337\261\337\261\337\263\337\261\337\256\337\261\337\263\337\261\337\261\334\273\337\261\337\263\337\261\337\263\337\261\337\263\337\261\337\261\330\273\337\261\337\261\337\261\337\261\337\261\337\377\377\377\177\261\337\256\337\261\337\261\337\261\337\263\337\261\337\263\337\261\337\261\337\263\337\261\337\261\330\273\337\261\337\261\337\261\337\261\337\261\337\263\337\261\337\261\337\256\337\261\337\256\337\261\337\261\337\263\337\261\337\256\337\261\337\263\337\261\337\261\334\261\337\256\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-4aabe35833cccb595f47f0a85b25446111800264 Step #5: Base64: OS00LTFUMDoyOjPfs9+x37Hfrt+x37Hfs9+x367fsd+z37Hfsdy737Hfs9+x37Pfsd+z37Hfsdi737Hfsd+x37Hfsd////9/sd+u37Hfsd+x37Pfsd+z37Hfsd+z37Hfsdi737Hfsd+x37Hfsd+z37Hfsd+u37Hfrt+x37Hfs9+x367fsd+z37Hfsdyx366x Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4560 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4008743214 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c0a8d7e810, 0x55c0a8f6801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c0a8f68020,0x55c0aae000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4aabe35833cccb595f47f0a85b25446111800264' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5695 processed earlier; will process 5334 files now Step #5: #1 pulse cov: 4060 ft: 4061 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 4383 ft: 4824 exec/s: 0 rss: 175Mb Step #5: ==164236== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c09f8739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c0a5ed8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c0a5ebb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c0a5ebb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c09f879d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c09f7dab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c09f7d5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c09f86bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c0a283af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c0a283af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c0a283af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c0a283af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c0a283af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c0a283af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c0a283af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c0a283af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c0a283af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c0a283af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c0a4acff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c0a17fcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c0a1807be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c0a15b3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c0a15b3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c0a15b4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c0a15b3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c0a15b3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c0a15b3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c0a5ebdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c0a5ec6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c0a5eae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c0a5ed9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f80e7691082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c09f7d3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2c,0x1c,0x2d,0xa,0x2d,0xa,0x2d,0x1c,0x2d,0xa,0x63,0x6f,0x6e,0x64,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x36,0x30,0x35,0x1,0x53,0x37,0x34,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x30,0x30,0x30,0x32,0x37,0x32,0x39,0x37,0x34,0x31,0x31,0x31,0x2d,0x1c,0x2d,0xa, Step #5: -\012\012\012--\012,\034-\012-\012-\034-\012cond-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012605\001S74\012-\012-\012-\012-\012-\012-\012\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242-\012-\012-\012-\012000272974111-\034-\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec3350b958937a79ab56f53a99d726805aeea998 Step #5: Base64: LQoKCi0tCiwcLQotCi0cLQpjb25kLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQo2MDUBUzc0Ci0KLQotCi0KLQotCqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKiLQotCi0KLQowMDAyNzI5NzQxMTEtHC0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4561 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4009352717 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5582e93dd810, 0x5582e95c701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5582e95c7020,0x5582eb45f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec3350b958937a79ab56f53a99d726805aeea998' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5698 processed earlier; will process 5331 files now Step #5: ==164272== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5582dfed29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5582e6537898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5582e651a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5582e651a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5582dfed8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5582dfe39b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5582dfe34355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5582dfecac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5582e2e99f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5582e2e99f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5582e2e99f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5582e2e99f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5582e2e99f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5582e2e99f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5582e2e99f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5582e2e99f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5582e2e99f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5582e2e99f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5582e512ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5582e1e5bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5582e1e66be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5582e1c12c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5582e1c12c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5582e1c13738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5582e1c12874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5582e1c12874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5582e1c12874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5582e651cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5582e6525928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5582e650d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5582e6538112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9627220082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5582dfe32b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0xe,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0x1e,0x24,0x7b,0x7d,0x63,0x6c,0x61,0x73,0x73,0xe,0x24,0x7b,0x7d, Step #5: class\036${}class\036${}class\036${}class\036${}class\036${}class\036${}class\036${}class\016${}class\036${}class\036${}class\036${}class\036${}class\036${}class\036${}class\036${}class\016${} Step #5: artifact_prefix='./'; Test unit written to ./oom-b603479c911e28060e737896e5cfc0cf0eb5e40f Step #5: Base64: Y2xhc3MeJHt9Y2xhc3MeJHt9Y2xhc3MeJHt9Y2xhc3MeJHt9Y2xhc3MeJHt9Y2xhc3MeJHt9Y2xhc3MeJHt9Y2xhc3MOJHt9Y2xhc3MeJHt9Y2xhc3MeJHt9Y2xhc3MeJHt9Y2xhc3MeJHt9Y2xhc3MeJHt9Y2xhc3MeJHt9Y2xhc3MeJHt9Y2xhc3MOJHt9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4562 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4009873553 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5601e7708810, 0x5601e78f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5601e78f2020,0x5601e978a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b603479c911e28060e737896e5cfc0cf0eb5e40f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5699 processed earlier; will process 5330 files now Step #5: ==164308== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5601de1fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601e4862898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601e48455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601e48454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5601de203d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601de164b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601de15f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5601de1f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601e11c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601e11c4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601e11c4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601e11c4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601e11c4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601e11c4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601e11c4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601e11c4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601e11c4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601e11c4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5601e3459f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601e0186b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601e0191be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5601dff3dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5601dff3dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5601dff3e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5601dff3d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5601dff3d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5601dff3d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5601e4847abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5601e4850928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5601e4838699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601e4863112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ef259d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601de15db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xa,0x64,0x3a,0x2e,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x35,0x37, Step #5: FUZZTESTv1\012d:.0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000057 Step #5: artifact_prefix='./'; Test unit written to ./oom-6b9e47aab7fd557499c67b12350552b9deda9f54 Step #5: Base64: RlVaWlRFU1R2MQpkOi4wMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDU3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4563 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4010378540 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556ebc921810, 0x556ebcb0b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556ebcb0b020,0x556ebe9a30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b9e47aab7fd557499c67b12350552b9deda9f54' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5700 processed earlier; will process 5329 files now Step #5: ==164344== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556eb34169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556eb9a7b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556eb9a5e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556eb9a5e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556eb341cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556eb337db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556eb3378355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556eb340ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556eb63ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556eb63ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556eb63ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556eb63ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556eb63ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556eb63ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556eb63ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556eb63ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556eb63ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556eb63ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556eb8672f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556eb539fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556eb53aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556eb5156c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556eb5156c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556eb5157738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556eb5156874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556eb5156874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556eb5156874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556eb9a60abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556eb9a69928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556eb9a51699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556eb9a7c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c81332082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556eb3376b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x39,0x2d,0x34,0x2d,0x31,0x54,0x30,0x3a,0x32,0x3a,0x33,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdc,0xbb,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xd8,0xbb,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xd8,0xbb,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xae,0xdf,0xb1,0xdf,0xb3,0xdf,0xb1,0xdf,0xb1,0xdc,0xb1,0xdf,0xae,0xb1, Step #5: 9-4-1T0:2:3\337\263\337\261\337\261\337\256\337\261\337\261\337\263\337\261\337\256\337\261\337\263\337\261\337\261\334\273\337\261\337\263\337\261\337\263\337\261\337\263\337\261\337\261\330\273\337\261\337\261\337\261\337\261\337\261\337\263\337\261\337\261\337\256\337\261\337\261\337\261\337\263\337\261\337\263\337\261\337\261\337\263\337\261\337\261\330\273\337\261\337\261\337\261\337\261\337\261\337\263\337\261\337\261\337\256\337\261\337\256\337\261\337\261\337\263\337\261\337\256\337\261\337\263\337\261\337\261\334\261\337\256\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-bdfffd3f85f6efe68a2bf3e6890364b3cf2901e7 Step #5: Base64: OS00LTFUMDoyOjPfs9+x37Hfrt+x37Hfs9+x367fsd+z37Hfsdy737Hfs9+x37Pfsd+z37Hfsdi737Hfsd+x37Hfsd+z37Hfsd+u37Hfsd+x37Pfsd+z37Hfsd+z37Hfsdi737Hfsd+x37Hfsd+z37Hfsd+u37Hfrt+x37Hfs9+x367fsd+z37Hfsdyx366x Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4564 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4010886715 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca19dbb810, 0x55ca19fa501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca19fa5020,0x55ca1be3d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bdfffd3f85f6efe68a2bf3e6890364b3cf2901e7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5701 processed earlier; will process 5328 files now Step #5: ==164380== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ca108b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca16f15898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca16ef85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca16ef84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca108b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca10817b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca10812355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca108a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca13877f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca13877f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca13877f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca13877f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca13877f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca13877f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca13877f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca13877f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca13877f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca13877f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca15b0cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca12839b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca12844be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca125f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca125f0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca125f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca125f0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca125f0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca125f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca16efaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca16f03928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca16eeb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca16f16112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4fa3622082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca10810b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2c,0x1c,0x2d,0xa,0x2d,0xa,0x2d,0x1c,0x2d,0xa,0x63,0x6f,0x6e,0x64,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x36,0x30,0x35,0x38,0x36,0x37,0x34,0x35,0x34,0x30,0x32,0x36,0x34,0x34,0x30,0x39,0x30,0x33,0x31,0x31,0x35,0x33,0x36,0x36,0x31,0x65,0x6e,0xa,0xa,0xa,0xa,0xa,0x2d,0x2d,0xa,0xa,0x2c,0x1c,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x36,0x30,0x35,0x38,0x36,0x37,0x34,0x35,0x34,0x30,0x32,0x36,0x2d,0x1c,0x2d,0xa, Step #5: -\012\012\012--\012,\034-\012-\012-\034-\012cond-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\0126058674540264409031153661en\012\012\012\012\012--\012\012,\034-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012605867454026-\034-\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-4fa6ac022e1de49f55c2253b8f4256716a7b4faf Step #5: Base64: LQoKCi0tCiwcLQotCi0cLQpjb25kLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQo2MDU4Njc0NTQwMjY0NDA5MDMxMTUzNjYxZW4KCgoKCi0tCgosHC0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KNjA1ODY3NDU0MDI2LRwtCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4565 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4011429722 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555d6493c810, 0x555d64b2601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555d64b26020,0x555d669be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4fa6ac022e1de49f55c2253b8f4256716a7b4faf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5702 processed earlier; will process 5327 files now Step #5: ==164416== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555d5b4319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555d61a96898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555d61a795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555d61a794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555d5b437d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555d5b398b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555d5b393355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555d5b429c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555d5e3f8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555d5e3f8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555d5e3f8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555d5e3f8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555d5e3f8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555d5e3f8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555d5e3f8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555d5e3f8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555d5e3f8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555d5e3f8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555d6068df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555d5d3bab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555d5d3c5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555d5d171c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555d5d171c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555d5d172738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555d5d171874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555d5d171874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555d5d171874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555d61a7babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555d61a84928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555d61a6c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555d61a97112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3d54f8d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555d5b391b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x0,0xa,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x30,0x30,0x30,0x74,0x23,0x76,0xa,0x72,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x43,0x46,0x2a,0x46,0x86,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0xa,0x20,0x98,0x98,0x98,0x98,0x98,0x98,0x98,0x20, Step #5: 99999999999999999999999999999999\000\012999999999999999999999999999999999000t#v\012rEEEEEEEECF*F\206\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\230\012 \230\230\230\230\230\230\230 Step #5: artifact_prefix='./'; Test unit written to ./oom-3e042f9d8bc905cf612809bd324540ae141f10e1 Step #5: Base64: OTk5OTk5OTk5OTk5OTk5OTk5OTk5OTk5OTk5OTk5OTkACjk5OTk5OTk5OTk5OTk5OTk5OTk5OTk5OTk5OTk5OTk5OTAwMHQjdgpyRUVFRUVFRUVDRipGhpiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYCiCYmJiYmJiYIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4566 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4011946566 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e1b376810, 0x559e1b56001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e1b560020,0x559e1d3f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3e042f9d8bc905cf612809bd324540ae141f10e1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5703 processed earlier; will process 5326 files now Step #5: ==164452== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559e11e6b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e184d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e184b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e184b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e11e71d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e11dd2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e11dcd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e11e63c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e14e32f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e14e32f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e14e32f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e14e32f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e14e32f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e14e32f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e14e32f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e14e32f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e14e32f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e14e32f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e170c7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e13df4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e13dffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e13babc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e13babc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e13bac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e13bab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e13bab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e13bab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e184b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e184be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e184a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e184d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67a1025082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e11dcbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x9,0x2b,0x9,0x2b,0x9,0x2b,0x9,0x2b,0x9,0x2b,0x9,0x2b,0x9,0x2b,0x9,0x2b,0x9,0x9,0xc,0x60,0xc,0x60,0x2b,0x9,0x2b,0x9,0x9,0x33,0x2d,0x34,0x36,0x36,0x38,0x36,0x30,0x2d,0x34,0x34,0x30,0x36,0x38,0x36,0x30,0x2d,0x34,0x34,0x30,0x37,0x33,0x37,0x30,0x39,0x35,0x35,0x31,0x36,0x31,0x39,0x2c,0x31,0x38,0x34,0x34,0x36,0x37,0x34,0x38,0x34,0x34,0x36,0x37,0x34,0x34,0x30,0x37,0x33,0x30,0x2d,0x34,0x34,0x30,0x37,0x33,0x37,0x30,0x39,0x35,0x35,0x31,0x36,0x31,0x39,0x2c,0x31,0x38,0x34,0x34,0x36,0x2e,0x34,0x38,0x34,0x34,0x36,0x37,0x34,0x34,0x30,0x37,0x33,0x37,0x30,0x39,0x35,0x35,0x39,0x34,0x33,0x36,0x36,0x32,0x2d,0x34,0x36,0x34,0xc,0x60,0xc,0x60,0x2b,0x9,0x2b,0x9,0x9,0x33,0x2d,0x34,0x36,0x36,0x38,0x36,0x30,0x2d,0x34, Step #5: +\011+\011+\011+\011+\011+\011+\011+\011+\011\011\014`\014`+\011+\011\0113-466860-4406860-44073709551619,184467484467440730-44073709551619,18446.4844674407370955943662-464\014`\014`+\011+\011\0113-466860-4 Step #5: artifact_prefix='./'; Test unit written to ./oom-7189457eb90c48ecc46fd39031f8428123a20c98 Step #5: Base64: KwkrCSsJKwkrCSsJKwkrCSsJCQxgDGArCSsJCTMtNDY2ODYwLTQ0MDY4NjAtNDQwNzM3MDk1NTE2MTksMTg0NDY3NDg0NDY3NDQwNzMwLTQ0MDczNzA5NTUxNjE5LDE4NDQ2LjQ4NDQ2NzQ0MDczNzA5NTU5NDM2NjItNDY0DGAMYCsJKwkJMy00NjY4NjAtNA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4567 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4012588774 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b9e526a810, 0x55b9e545401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b9e5454020,0x55b9e72ec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7189457eb90c48ecc46fd39031f8428123a20c98' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5704 processed earlier; will process 5325 files now Step #5: ==164488== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b9dbd5f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b9e23c4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b9e23a75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b9e23a74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b9dbd65d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b9dbcc6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b9dbcc1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b9dbd57c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b9ded26f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b9ded26f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b9ded26f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b9ded26f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b9ded26f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b9ded26f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b9ded26f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b9ded26f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b9ded26f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b9ded26f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b9e0fbbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b9ddce8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b9ddcf3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b9dda9fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b9dda9fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b9ddaa0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b9dda9f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b9dda9f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b9dda9f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b9e23a9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b9e23b2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b9e239a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b9e23c5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f247ff5c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b9dbcbfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x81,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x82,0xe1,0x84,0x90,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x90,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x82,0xe1,0x84,0x90,0xe1,0x85,0xb0,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xa6,0xe1,0x87,0x81,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x87,0x81, Step #5: \341\204\221\341\205\260\341\207\201\341\204\221\341\205\260\341\207\201\341\204\201\341\205\260\341\207\201\341\204\221\341\205\260\341\207\202\341\204\220\341\205\260\341\207\201\341\204\221\341\205\260\341\207\201\341\204\221\341\205\260\341\207\201\341\204\221\341\205\260\341\207\201\012\341\204\221\341\205\260\341\207\201\341\204\220\341\205\260\341\207\201\341\204\221\341\205\260\341\207\201\341\204\221\341\205\260\341\207\201\341\204\221\341\205\260\341\207\202\341\204\220\341\205\260\341\207\201\341\204\221\341\205\246\341\207\201\341\204\221\341\205\260\341\207\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-e60743022b1c2bf42ff365961c3722f138062ffd Step #5: Base64: 4YSR4YWw4YeB4YSR4YWw4YeB4YSB4YWw4YeB4YSR4YWw4YeC4YSQ4YWw4YeB4YSR4YWw4YeB4YSR4YWw4YeB4YSR4YWw4YeBCuGEkeGFsOGHgeGEkOGFsOGHgeGEkeGFsOGHgeGEkeGFsOGHgeGEkeGFsOGHguGEkOGFsOGHgeGEkeGFpuGHgeGEkeGFsOGHgQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4568 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4013092145 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611173c4810, 0x5611175ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5611175ae020,0x5611194460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e60743022b1c2bf42ff365961c3722f138062ffd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5705 processed earlier; will process 5324 files now Step #5: ==164524== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56110deb99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56111451e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611145015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611145014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56110debfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56110de20b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56110de1b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56110deb1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561110e80f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561110e80f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561110e80f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561110e80f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561110e80f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561110e80f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561110e80f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561110e80f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561110e80f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561110e80f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561113115f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56110fe42b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56110fe4dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56110fbf9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56110fbf9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56110fbfa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56110fbf9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56110fbf9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56110fbf9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561114503abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56111450c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611144f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56111451f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe62fcec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56110de19b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0x74,0x22,0x3a,0x22,0x22,0x2c,0x22,0x63,0x6f,0x6e,0x74,0x75,0x6e,0x74,0x22,0x3a,0x22,0x22,0x2c,0x22,0x63,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x22,0x3a,0x22,0x3a,0x22,0x22,0x2c,0x22,0x63,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x22,0x3a,0x22,0x22,0x2c,0x22,0x63,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x22,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x24,0x24,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x49,0x33,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x49,0x33,0x34,0x20,0x44,0x0,0x0,0x0,0x0,0x0,0x35,0x20,0x44,0x0,0x0,0x54,0x32,0x2,0xdd,0x81,0x54,0x32,0x2,0xdd,0x81,0x0,0x0,0x0,0xbf,0x0,0x0,0x2e,0x36,0xdf,0x35,0x35,0x33,0x0,0x0,0x0,0xbf,0xdf,0x37, Step #5: :t\":\"\",\"contunt\":\"\",\"content\":\":\"\",\"content\":\"\",\"content\"\000\000\000\000\000\000\000$$$$\000\000\000\000\000\000\000\000\000\000\000I3\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000I34 D\000\000\000\000\0005 D\000\000T2\002\335\201T2\002\335\201\000\000\000\277\000\000.6\337553\000\000\000\277\3377 Step #5: artifact_prefix='./'; Test unit written to ./oom-edf1d2b712c73e85670fcde9502af7ffcc498921 Step #5: Base64: OnQiOiIiLCJjb250dW50IjoiIiwiY29udGVudCI6IjoiIiwiY29udGVudCI6IiIsImNvbnRlbnQiAAAAAAAAACQkJCQAAAAAAAAAAAAAAEkzAAAAAAAAAAAAAAAAAAAAAAAAAAAASTM0IEQAAAAAADUgRAAAVDIC3YFUMgLdgQAAAL8AAC423zU1MwAAAL/fNw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4569 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4013602915 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55902d736810, 0x55902d92001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55902d920020,0x55902f7b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/edf1d2b712c73e85670fcde9502af7ffcc498921' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5706 processed earlier; will process 5323 files now Step #5: ==164560== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55902422b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55902a890898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55902a8735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55902a8734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559024231d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559024192b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55902418d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559024223c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5590271f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5590271f2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5590271f2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5590271f2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5590271f2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5590271f2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5590271f2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5590271f2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5590271f2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5590271f2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559029487f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5590261b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5590261bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559025f6bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559025f6bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559025f6c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559025f6b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559025f6b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559025f6b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55902a875abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55902a87e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55902a866699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55902a891112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd73d097082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55902418bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x13,0x0,0x0,0x0,0x54,0x61,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0xdf,0xb9,0x0,0x0,0x7e,0x1,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0xdf,0xb9,0x0,0x0,0x0,0x0,0x1,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0xdf,0xb9,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0xdf,0xb9,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0xdf,0xb9,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0xdf,0xb9,0x0,0x0,0x0,0x0,0x1,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0xdf,0xb9,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0xdf,0xb9,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0xdf,0xb9,0x0,0x0,0x0,0x0,0x6c, Step #5: ID3\004\023\000\000\000TaAPIC\000\000\000\005\337\271\000\000~\001\000APIC\000\000\000\005\337\271\000\000\000\000\001APIC\000\000\000\005\337\271\000\000\000\000\000APIC\000\000\000\005\337\271\000\000\000\000\000APIC\000\000\000\005\337\271\000\000\000\000\000APIC\000\000\000\005\337\271\000\000\000\000\001APIC\000\000\000\005\337\271\000\000\000\000\000APIC\000\000\000\005\337\271\000\000\000\000\000APIC\000\000\000\005\337\271\000\000\000\000l Step #5: artifact_prefix='./'; Test unit written to ./oom-de8a8de20736935163957bbf994d255f41b80203 Step #5: Base64: SUQzBBMAAABUYUFQSUMAAAAF37kAAH4BAEFQSUMAAAAF37kAAAAAAUFQSUMAAAAF37kAAAAAAEFQSUMAAAAF37kAAAAAAEFQSUMAAAAF37kAAAAAAEFQSUMAAAAF37kAAAAAAUFQSUMAAAAF37kAAAAAAEFQSUMAAAAF37kAAAAAAEFQSUMAAAAF37kAAAAAbA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4570 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4014112921 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e03c167810, 0x55e03c35101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e03c351020,0x55e03e1e90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de8a8de20736935163957bbf994d255f41b80203' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5707 processed earlier; will process 5322 files now Step #5: ==164596== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e032c5c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e0392c1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e0392a45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e0392a44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e032c62d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e032bc3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e032bbe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e032c54c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e035c23f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e035c23f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e035c23f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e035c23f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e035c23f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e035c23f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e035c23f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e035c23f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e035c23f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e035c23f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e037eb8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e034be5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e034bf0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e03499cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e03499cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e03499d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e03499c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e03499c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e03499c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e0392a6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e0392af928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e039297699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e0392c2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0dcc19082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e032bbcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x3c,0x73,0x74,0x79,0x75,0x65,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x34,0x29,0x9,0x3c,0x67,0x3e,0x2a,0x7b,0x6c,0x3c,0x67,0x3e,0x3c,0x67,0x3e,0x3c,0x67,0x3e,0x3c,0x67,0x3e,0x67,0x7b,0x3b,0x66,0x6f,0x6e,0x74,0x2d,0x76,0x61,0x72,0x69,0x61,0x6e,0x74,0x3a,0x32,0x77,0x69,0x2c,0x74,0x4a,0x50,0x45,0x68,0x7d,0x7c,0x37,0x3c,0x67,0x3e,0x3c,0x67,0x49,0x67,0x3e,0x34,0x29,0x9,0x3c,0x67,0x3e,0x2a,0x7b,0x6c,0x3c,0x67,0x3e,0x3c,0x67,0x3e,0x3c,0x67,0x3e,0x3c,0x67,0x3e,0x67,0x7b,0x67,0x3e,0x3c,0x67,0x3e,0x3c,0x67,0x3e,0x3c,0x67,0x3e,0x67,0x7b,0x0,0x0,0x10,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x3,0x0,0x1,0x0,0x0,0x0, Step #5: <svg><style><styue><style>4)\011<g>*{l<g><g><g><g>g{;font-variant:2wi,tJPEh}|7<g><gIg>4)\011<g>*{l<g><g><g><g>g{g><g><g><g>g{\000\000\020\000\000\000\000\000\000\000\004\000\000\000\000\000\000\000\000\001\003\000\001\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bcb9b54499b764b058b1beaacb78bdbcef9b8596 Step #5: Base64: PHN2Zz48c3R5bGU+PHN0eXVlPjxzdHlsZT40KQk8Zz4qe2w8Zz48Zz48Zz48Zz5neztmb250LXZhcmlhbnQ6MndpLHRKUEVofXw3PGc+PGdJZz40KQk8Zz4qe2w8Zz48Zz48Zz48Zz5ne2c+PGc+PGc+PGc+Z3sAABAAAAAAAAAABAAAAAAAAAAAAQMAAQAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4571 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4014626250 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560281749810, 0x56028193301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560281933020,0x5602837cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bcb9b54499b764b058b1beaacb78bdbcef9b8596' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5708 processed earlier; will process 5321 files now Step #5: ==164632== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56027823e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56027e8a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56027e8865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56027e8864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560278244d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5602781a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5602781a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560278236c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56027b205f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56027b205f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56027b205f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56027b205f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56027b205f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56027b205f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56027b205f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56027b205f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56027b205f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56027b205f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56027d49af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56027a1c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56027a1d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560279f7ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560279f7ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560279f7f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560279f7e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560279f7e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560279f7e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56027e888abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56027e891928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56027e879699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56027e8a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f34b1433082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56027819eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x5f,0x5f,0x5f,0x5f,0x5f,0x0,0x0,0x0,0x0,0x20,0x0,0x0,0x0,0x5f,0x5f,0x5f,0x44,0x33,0x2,0x26,0x1,0x41,0x1,0x0,0x30,0x54,0x58,0x58,0x0,0x0,0x42,0x42,0x3,0x3d,0x65,0x6e,0x54,0x58,0x58,0x3,0x49,0x0,0x22,0x54,0x4b,0x4e,0x54,0x4b,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x49,0x6f,0x74,0x61,0x79,0x79,0x4e,0x2,0x73,0x74,0x0,0x22,0x54,0x60,0x4e,0x60,0x2d,0x2d,0x2d,0x2d,0x2,0x73,0x74,0x73,0x20,0x31,0x33,0x31,0x30,0x2d,0x0,0xd2,0xbf,0x46,0x46,0x20,0xbb,0x2d,0x2d,0x2d,0xde,0x44,0x2a, Step #5: I_____\000\000\000\000 \000\000\000___D3\002&\001A\001\0000TXX\000\000BB\003=enTXX\003I\000\"TKNTKyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyIotayyN\002st\000\"T`N`----\002sts 1310-\000\322\277FF \273---\336D* Step #5: artifact_prefix='./'; Test unit written to ./oom-d78dafacb220cb00b02ead9604cac72cf7101c51 Step #5: Base64: SV9fX19fAAAAACAAAABfX19EMwImAUEBADBUWFgAAEJCAz1lblRYWANJACJUS05US3l5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eUlvdGF5eU4Cc3QAIlRgTmAtLS0tAnN0cyAxMzEwLQDSv0ZGILstLS3eRCo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4572 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4015256409 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556167ebe810, 0x5561680a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5561680a8020,0x556169f400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d78dafacb220cb00b02ead9604cac72cf7101c51' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5709 processed earlier; will process 5320 files now Step #5: #1 pulse cov: 3773 ft: 3774 exec/s: 0 rss: 175Mb Step #5: ==164668== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55615e9b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556165018898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556164ffb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556164ffb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55615e9b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55615e91ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55615e915355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55615e9abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55616197af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55616197af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55616197af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55616197af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55616197af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55616197af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55616197af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55616197af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55616197af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55616197af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556163c0ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55616093cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556160947be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5561606f3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5561606f3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5561606f4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5561606f3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5561606f3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5561606f3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556164ffdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556165006928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556164fee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556165019112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe0ee2ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55615e913b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2c,0x1c,0x2d,0xa,0x2d,0xa,0x2d,0x3d,0x3d,0x7e,0x24,0x3d,0x7e,0x2d,0xf3,0x81,0xa0,0x88,0x3d,0x3d,0x7e,0x24,0x7e,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x36,0x30,0x35,0x1,0x53,0x37,0x34,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0x62,0x6b,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0xa2,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x30,0x30,0x30,0x32,0x37,0x32,0x39,0x37,0x34,0x31,0x31,0x31,0x2d,0x1c,0x2d,0xa, Step #5: -\012\012\012--\012,\034-\012-\012-==~$=~-\363\201\240\210==~$~\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012605\001S74\012-\012-\012-\012-\012-\012-\012\242\242\242\242\242\242bk\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242\242-\012-\012-\012-\012000272974111-\034-\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ccb51a493a911a20984da27b26f546629b3af75 Step #5: Base64: LQoKCi0tCiwcLQotCi09PX4kPX4t84GgiD09fiR+Ci0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQo2MDUBUzc0Ci0KLQotCi0KLQotCqKioqKiomJroqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqItCi0KLQotCjAwMDI3Mjk3NDExMS0cLQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4573 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4015830254 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4de1e2810, 0x55e4de3cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4de3cc020,0x55e4e02640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ccb51a493a911a20984da27b26f546629b3af75' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5711 processed earlier; will process 5318 files now Step #5: ==164704== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e4d4cd79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4db33c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4db31f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4db31f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4d4cddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4d4c3eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4d4c39355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4d4ccfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4d7c9ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4d7c9ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4d7c9ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4d7c9ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4d7c9ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4d7c9ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4d7c9ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4d7c9ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4d7c9ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4d7c9ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4d9f33f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4d6c60b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4d6c6bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4d6a17c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4d6a17c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4d6a18738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4d6a17874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4d6a17874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4d6a17874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4db321abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4db32a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4db312699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4db33d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1ded813082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4d4c37b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x2d,0x32,0x35,0x35,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x2d,0x36,0x35,0x35,0x33,0x2d,0x2d,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x45,0x15,0x0,0x10,0x15,0x0,0x10,0x49,0x44,0x2d,0x32,0x35,0x35,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x2d,0x30,0x45,0x6,0x64,0x68,0x65,0x61,0x64,0x27,0xa,0xa,0xc,0xa,0x27,0xa,0xa,0xc,0xa,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x45,0x15,0x0,0x10,0x15,0x0,0x10,0x49,0x44,0x2d,0x32,0x35,0x35,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x2d,0x39,0x32,0x32,0x36,0x39,0x36,0x38,0x33,0x38,0x38,0x39,0x31,0x37,0x34,0x36,0x37,0x33,0x38,0x39,0x35,0x33,0x31,0x37,0x31,0x30,0x33,0x45,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x45,0x15,0x0,0x10,0x15,0x0,0x10, Step #5: ID-255\004'\000\000`'\027TY-6553--\004'\000\000`'\027TYE\025\000\020\025\000\020ID-255\004'\000\000`'\027TY-0E\006dhead'\012\012\014\012'\012\012\014\012'\000\000`'\027TYE\025\000\020\025\000\020ID-255\004'\000\000`'\027TY-92269683889174673895317103E\004'\000\000`'\027TYE\025\000\020\025\000\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-b50229d050757b840d18ef8ccf3c69a79162c8b7 Step #5: Base64: SUQtMjU1BCcAAGAnF1RZLTY1NTMtLQQnAABgJxdUWUUVABAVABBJRC0yNTUEJwAAYCcXVFktMEUGZGhlYWQnCgoMCicKCgwKJwAAYCcXVFlFFQAQFQAQSUQtMjU1BCcAAGAnF1RZLTkyMjY5NjgzODg5MTc0NjczODk1MzE3MTAzRQQnAABgJxdUWUUVABAVABA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4574 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4016468873 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55829b228810, 0x55829b41201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55829b412020,0x55829d2aa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b50229d050757b840d18ef8ccf3c69a79162c8b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5712 processed earlier; will process 5317 files now Step #5: #1 pulse cov: 3916 ft: 3917 exec/s: 0 rss: 177Mb Step #5: ==164740== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558291d1d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558298382898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5582983655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5582983654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558291d23d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558291c84b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558291c7f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558291d15c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558294ce4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558294ce4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558294ce4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558294ce4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558294ce4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558294ce4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558294ce4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558294ce4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558294ce4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558294ce4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558296f79f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558293ca6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558293cb1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558293a5dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558293a5dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558293a5e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558293a5d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558293a5d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558293a5d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558298367abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558298370928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558298358699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558298383112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f476f9f0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558291c7db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x7f,0x8,0x0,0x1,0x0,0x2e,0x2e,0x2e,0x2e,0x5b,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0xf3,0xa0,0x81,0xa9,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x78,0x2d,0x2d,0x31,0x32,0x39,0x2d,0x2d,0x27,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x7a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2d,0x65,0x6e,0x2d,0x63,0x2d,0x74,0x2d,0x2d,0xa,0x3d,0x1d,0x41,0x0,0x0,0x0,0x0,0x20,0x0,0x0,0x0,0x0,0x0,0x32,0x31,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x2e,0x2e,0x2e,0x2d,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x0, Step #5: = \177\010\000\001\000....[......\363\240\201\251........x--129--'-BEGIN *****************z*********-en-c-t--\012=\035A\000\000\000\000 \000\000\000\000\00021\005\005\005\005\005\005\005\005\005\005...-.................................\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2596736cf181bc677112e8ec4ebdc88a0da4eaa1 Step #5: Base64: PSB/CAABAC4uLi5bLi4uLi4u86CBqS4uLi4uLi4ueC0tMTI5LS0nLUJFR0lOICoqKioqKioqKioqKioqKioqeioqKioqKioqKi1lbi1jLXQtLQo9HUEAAAAAIAAAAAAAMjEFBQUFBQUFBQUFLi4uLS4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLgA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4575 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4017027351 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56041099c810, 0x560410b8601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560410b86020,0x560412a1e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2596736cf181bc677112e8ec4ebdc88a0da4eaa1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5714 processed earlier; will process 5315 files now Step #5: #1 pulse cov: 3840 ft: 3841 exec/s: 0 rss: 174Mb Step #5: ==164776== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5604074919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56040daf6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56040dad95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56040dad94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560407497d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5604073f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5604073f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560407489c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56040a458f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56040a458f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56040a458f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56040a458f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56040a458f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56040a458f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56040a458f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56040a458f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56040a458f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56040a458f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56040c6edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56040941ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560409425be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5604091d1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5604091d1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5604091d2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5604091d1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5604091d1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5604091d1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56040dadbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56040dae4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56040dacc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56040daf7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f29d5707082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5604073f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7f,0x68,0x24,0x0,0x0,0x11,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x8,0x24, Step #5: \177h$\000\000\021\000\000\000--------\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000---------\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000----------\010$ Step #5: artifact_prefix='./'; Test unit written to ./oom-d337ce2c12292795f6da920213b5ce4ebef38d8c Step #5: Base64: f2gkAAARAAAALS0tLS0tLS0AAAAAAAAAAAAAAAAAAAAAAAAAAC0tLS0tLS0tLQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAtLS0tLS0tLS0tCCQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4576 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4017583215 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55705f85d810, 0x55705fa4701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55705fa47020,0x5570618df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d337ce2c12292795f6da920213b5ce4ebef38d8c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5716 processed earlier; will process 5313 files now Step #5: ==164812== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5570563529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55705c9b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55705c99a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55705c99a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557056358d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5570562b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5570562b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55705634ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557059319f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557059319f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557059319f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557059319f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557059319f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557059319f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557059319f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557059319f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557059319f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557059319f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55705b5aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5570582dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5570582e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557058092c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557058092c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557058093738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557058092874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557058092874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557058092874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55705c99cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55705c9a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55705c98d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55705c9b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efdae2f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5570562b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf3,0xa0,0x80,0xa8,0xf3,0xa0,0x80,0xa5,0xf3,0xa0,0x81,0xa3,0xf3,0xa0,0x81,0xa3,0xf3,0xa0,0x81,0x83,0xf3,0xa0,0x81,0xa3,0xf3,0xa0,0xa0,0x82,0xf3,0xa0,0x80,0xa8,0xf3,0xa0,0x80,0xa5,0xf3,0xa0,0x81,0xa3,0xf3,0xa0,0x81,0xa3,0xf3,0xa0,0x81,0x83,0xf3,0xa0,0x81,0xa3,0xf3,0xa0,0xa0,0x82,0xf3,0xa0,0x80,0xa8,0xf3,0xb8,0xa0,0x80,0xa5,0xf3,0xa0,0x81,0xa3,0xf3,0xa0,0x81,0xa3,0xa0,0xf3,0x81,0x83,0xf3,0xa0,0x81,0xa3,0xf3,0xa0,0x81,0xa3,0xf3,0xa0,0x81,0x83,0xf3,0xa3,0xa0,0x81,0x0,0x0,0xff,0x5,0x0,0x1f,0x40,0xee,0x8,0xff,0xff,0x7e,0x80,0xff,0xff,0xff,0xff,0xff,0x31,0xff,0x0,0x36,0x37,0x32,0x39,0x36,0xa9,0xc9,0x5,0x11,0xa0,0x2e,0xf3,0xa0,0xf3,0xa0,0x81,0xa3,0xf3,0xa0,0x81,0xa3,0xf3,0xa0,0xa3,0x81,0xff,0x1,0x0,0x3d,0x0,0x3,0x81, Step #5: \363\240\200\250\363\240\200\245\363\240\201\243\363\240\201\243\363\240\201\203\363\240\201\243\363\240\240\202\363\240\200\250\363\240\200\245\363\240\201\243\363\240\201\243\363\240\201\203\363\240\201\243\363\240\240\202\363\240\200\250\363\270\240\200\245\363\240\201\243\363\240\201\243\240\363\201\203\363\240\201\243\363\240\201\243\363\240\201\203\363\243\240\201\000\000\377\005\000\037@\356\010\377\377~\200\377\377\377\377\3771\377\00067296\251\311\005\021\240.\363\240\363\240\201\243\363\240\201\243\363\240\243\201\377\001\000=\000\003\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-f32624ae7f01210209e085e1d4c172ca284feb83 Step #5: Base64: 86CAqPOggKXzoIGj86CBo/OggYPzoIGj86CggvOggKjzoICl86CBo/OggaPzoIGD86CBo/OgoILzoICo87iggKXzoIGj86CBo6DzgYPzoIGj86CBo/OggYPzo6CBAAD/BQAfQO4I//9+gP//////Mf8ANjcyOTapyQURoC7zoPOggaPzoIGj86Cjgf8BAD0AA4E= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4577 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4018088207 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ae16956810, 0x55ae16b4001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ae16b40020,0x55ae189d80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f32624ae7f01210209e085e1d4c172ca284feb83' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5717 processed earlier; will process 5312 files now Step #5: ==164848== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ae0d44b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ae13ab0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ae13a935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ae13a934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ae0d451d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ae0d3b2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ae0d3ad355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ae0d443c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ae10412f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ae10412f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ae10412f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ae10412f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ae10412f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ae10412f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ae10412f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ae10412f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ae10412f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ae10412f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ae126a7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ae0f3d4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ae0f3dfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ae0f18bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ae0f18bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ae0f18c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ae0f18b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ae0f18b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ae0f18b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ae13a95abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ae13a9e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ae13a86699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ae13ab1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f39e5682082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ae0d3abb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0x35,0x35,0x31,0x73,0x64,0x35,0x2d,0x2d,0x2d,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xf,0x0,0x0,0x3a,0xdc,0x81,0x0,0x0,0x0,0x0,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x73,0x6f,0x75,0x72,0x63,0x65,0x1,0x47,0xa, Step #5: C551sd5---\012\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\017\000\000:\334\201\000\000\000\000\000=\012=\012=\012source\001G\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-7b85460c040b78585535f63359004f13a54707b2 Step #5: Base64: QzU1MXNkNS0tLQoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwAAOtyBAAAAAAA9Cj0KPQpzb3VyY2UBRwo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4578 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4018597348 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a24b773810, 0x55a24b95d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a24b95d020,0x55a24d7f50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7b85460c040b78585535f63359004f13a54707b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5718 processed earlier; will process 5311 files now Step #5: ==164884== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a2422689c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a2488cd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2488b05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2488b04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a24226ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a2421cfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a2421ca355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a242260c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a24522ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a24522ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a24522ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a24522ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a24522ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a24522ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a24522ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a24522ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a24522ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a24522ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a2474c4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a2441f1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a2441fcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a243fa8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a243fa8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a243fa9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a243fa8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a243fa8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a243fa8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a2488b2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a2488bb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2488a3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a2488ce112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9788316082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a2421c8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x1a,0x0,0x2,0x10,0x4,0x45,0x7f,0x7b,0x7b,0x7b,0x6c,0x6c,0x6c,0x6c,0x7b,0x7b,0x7b,0x7b,0x7b,0x0,0x2,0x0,0x1,0x2,0x69,0x61,0x6c,0x0,0x1b,0x0,0x1f,0x0,0x46,0x23,0x22,0xf,0x0,0x0,0x0,0x3b,0x7b,0x7b,0x7b,0x7b,0x7b,0x6c,0x6c,0x6c,0x6c,0x7b,0x7b,0x7b,0x7b,0x7b,0x0,0x2,0x0,0x1,0x2,0x69,0x61,0x6c,0x0,0x1b,0x0,0x1f,0x0,0x46,0x23,0x22,0xf,0x0,0x0,0x0,0x3b,0x7b,0x7b,0x7b,0x7b,0x7b,0x6c,0x6c,0x7c,0x6c,0x7b,0x7b,0x7b,0x7b,0x7b,0x0,0x2,0x0,0x1,0x2,0x69,0x61,0x6c,0x0,0x1b,0x0,0x1f,0x0,0x46,0x23,0x22,0xf,0x0,0x0,0x0,0x3b,0x7b,0x7b,0x7b,0x7b,0x7b,0x6c,0x6c,0x6c,0x6c,0x7b,0x7b,0x7b,0x7b,0x7b,0x0,0x2,0x0,0x1,0x2,0x69,0x61,0x6c,0x0,0x1b,0x0,0x1f,0x0,0x46,0x23,0x22,0xf,0x0,0xe2,0x0, Step #5: \000\000\032\000\002\020\004E\177{{{llll{{{{{\000\002\000\001\002ial\000\033\000\037\000F#\"\017\000\000\000;{{{{{llll{{{{{\000\002\000\001\002ial\000\033\000\037\000F#\"\017\000\000\000;{{{{{ll|l{{{{{\000\002\000\001\002ial\000\033\000\037\000F#\"\017\000\000\000;{{{{{llll{{{{{\000\002\000\001\002ial\000\033\000\037\000F#\"\017\000\342\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bf8cf3cd96d99772c5ac90fd686166c0d8eff17b Step #5: Base64: AAAaAAIQBEV/e3t7bGxsbHt7e3t7AAIAAQJpYWwAGwAfAEYjIg8AAAA7e3t7e3tsbGxse3t7e3sAAgABAmlhbAAbAB8ARiMiDwAAADt7e3t7e2xsfGx7e3t7ewACAAECaWFsABsAHwBGIyIPAAAAO3t7e3t7bGxsbHt7e3t7AAIAAQJpYWwAGwAfAEYjIg8A4gA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4579 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4019104803 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b5ca97810, 0x560b5cc8101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b5cc81020,0x560b5eb190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf8cf3cd96d99772c5ac90fd686166c0d8eff17b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5719 processed earlier; will process 5310 files now Step #5: ==164920== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560b5358c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b59bf1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b59bd45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b59bd44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b53592d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b534f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b534ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b53584c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b56553f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b56553f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b56553f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b56553f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b56553f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b56553f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b56553f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b56553f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b56553f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b56553f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b587e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b55515b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b55520be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b552ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b552ccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b552cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b552cc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b552cc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b552cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b59bd6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b59bdf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b59bc7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b59bf2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5276009082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b534ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xd,0x48,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xd,0x25,0x20,0x78,0x78,0x20,0x27,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0x20,0x6a,0x9,0x64,0xd,0x49,0x44,0x52,0x45,0x46,0x53,0x9,0x22,0x42,0x68,0x9,0xe2,0x80,0x8d,0xe4,0xb4,0x80,0x64,0x20,0xc3,0xb2,0x62,0x9,0xe2,0x80,0x8d,0xe0,0xb4,0x80,0x20,0xcd,0xb2,0x64,0x20,0xc3,0xb2,0x68,0x9,0xe0,0xbc,0x80,0x20,0xcd,0xb2,0x64,0x9,0xe2,0x80,0x8d,0xe0,0xb4,0x80,0x64,0x64,0x20,0xc3,0xb2,0x62,0x22,0x3e,0x27,0x3e,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b, Step #5: <!DOCTYPE\015H[<!ENTITY\015% xx '<!ATTLIST j\011d\015IDREFS\011\"Bh\011\342\200\215\344\264\200d \303\262b\011\342\200\215\340\264\200 \315\262d \303\262h\011\340\274\200 \315\262d\011\342\200\215\340\264\200dd \303\262b\">'>%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx; Step #5: artifact_prefix='./'; Test unit written to ./oom-8b37bd1c67a6d73f621bca42545993da4afe2175 Step #5: Base64: PCFET0NUWVBFDUhbPCFFTlRJVFkNJSB4eCAnPCFBVFRMSVNUIGoJZA1JRFJFRlMJIkJoCeKAjeS0gGQgw7JiCeKAjeC0gCDNsmQgw7JoCeC8gCDNsmQJ4oCN4LSAZGQgw7JiIj4nPiV4eDsleHg7JXh4OyV4eDsleHg7JXh4OyV4eDsleHg7JXh4OyV4eDsleHg7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4580 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4019616595 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564f44be5810, 0x564f44dcf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564f44dcf020,0x564f46c670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8b37bd1c67a6d73f621bca42545993da4afe2175' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5720 processed earlier; will process 5309 files now Step #5: ==164956== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564f3b6da9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f41d3f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f41d225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f41d224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f3b6e0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f3b641b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f3b63c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f3b6d2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f3e6a1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f3e6a1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f3e6a1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f3e6a1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f3e6a1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f3e6a1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f3e6a1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f3e6a1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f3e6a1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f3e6a1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f40936f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f3d663b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f3d66ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f3d41ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f3d41ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f3d41b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f3d41a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f3d41a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f3d41a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f41d24abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f41d2d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f41d15699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f41d40112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4929553082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f3b63ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x42,0x3c,0xdb,0xbe,0x7e,0x19,0x0,0x0,0x0,0x2d,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2d,0x0,0x0,0x2a,0x0,0x0,0x0,0x0,0x0,0xa,0x2d,0xa,0x64,0xa,0x64,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2d,0x0,0x0,0x2a,0x0,0x0,0x1,0x3,0x0,0x0,0x0,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0xa,0xdc,0x7e,0xa,0xd2,0xa,0x0,0xa,0x2d,0x4d,0x44,0x61,0x6e, Step #5: ~~~~~~B<\333\276~\031\000\000\000--\012,\012-\012d\012-\012d\012d\012-\000\000*\000\000\000\000\000\012-\012d\012d\031\031\031\031\031\031\031=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000-\012d\012-\012d\012d\012-\000\000*\000\000\001\003\000\000\000\031\031\031\031\031\031\031\031\031\031\031\031\031\031\012\334~\012\322\012\000\012-MDan Step #5: artifact_prefix='./'; Test unit written to ./oom-42ddacd4431ff441cb25a9117fc2e8804e71a2e1 Step #5: Base64: fn5+fn5+Qjzbvn4ZAAAALS0KLAotCmQKLQpkCmQKLQAAKgAAAAAACi0KZApkGRkZGRkZGT0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQAAAAAAAAAAAAAAAAAAAAAAAAAALQpkCi0KZApkCi0AACoAAAEDAAAAGRkZGRkZGRkZGRkZGRkK3H4K0goACi1NRGFu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4581 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4020140814 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56516b9bf810, 0x56516bba901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56516bba9020,0x56516da410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/42ddacd4431ff441cb25a9117fc2e8804e71a2e1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5721 processed earlier; will process 5308 files now Step #5: ==164992== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5651624b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565168b19898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565168afc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565168afc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5651624bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56516241bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565162416355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5651624acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56516547bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56516547bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56516547bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56516547bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56516547bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56516547bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56516547bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56516547bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56516547bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56516547bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565167710f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56516443db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565164448be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5651641f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5651641f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5651641f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5651641f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5651641f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5651641f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565168afeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565168b07928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565168aef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565168b1a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ee0f1e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565162414b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x26,0x36,0x20,0x5b,0x26,0x37,0x9,0x5b,0x26,0x38,0x9,0x7b,0x32,0x2c,0x33,0x5f,0x37,0x2c,0x2e,0x5f,0x31,0x2c,0x2e,0xcc,0x9e,0x37,0x2c,0x2e,0x5f,0x31,0x2c,0x2e,0x5f,0x2b,0x61,0x31,0x69,0x2c,0x2e,0x31,0x5f,0x32,0x5f,0x5f,0x69,0x67,0x39,0x31,0x5f,0x2d,0x34,0x2c,0x2e,0x5f,0x30,0x2c,0x2e,0xcc,0x9a,0x31,0x5f,0x36,0x37,0x2c,0x2e,0x5f,0x34,0x2c,0x2e,0x2c,0x2e,0x5f,0x34,0x2c,0x2e,0xcc,0x9a,0x31,0x2c,0x2e,0x5f,0x34,0x2c,0x2e,0x30,0x5f,0x2c,0x2e,0x2c,0x2e,0x5f,0x30,0x2c,0x2e,0xcc,0x9a,0x31,0x2c,0x2e,0x5f,0x34,0x2c,0x2e,0x30,0x5f,0x32,0x5f,0x5f,0x31,0x2c,0x2e,0x36,0x32,0x33,0x37,0x38,0x37,0x2c,0x2e,0x5f,0x37,0x2c,0x2e,0x2e,0x30,0x34,0x7d,0x2c,0x2a,0x38,0x2c,0x2a,0x38,0x5d,0x2c,0x2a,0x37,0x2c,0x2a,0x36,0x5d,0x2c,0x26,0x37,0x5d,0x31, Step #5: [&6 [&7\011[&8\011{2,3_7,._1,.\314\2367,._1,._+a1i,.1_2__ig91_-4,._0,.\314\2321_67,._4,.,._4,.\314\2321,._4,.0_,.,._0,.\314\2321,._4,.0_2__1,.623787,._7,..04},*8,*8],*7,*6],&7]1 Step #5: artifact_prefix='./'; Test unit written to ./oom-f484bd4872b146629e220e197a24bbcb8db36ef5 Step #5: Base64: WyY2IFsmNwlbJjgJezIsM183LC5fMSwuzJ43LC5fMSwuXythMWksLjFfMl9faWc5MV8tNCwuXzAsLsyaMV82NywuXzQsLiwuXzQsLsyaMSwuXzQsLjBfLC4sLl8wLC7MmjEsLl80LC4wXzJfXzEsLjYyMzc4NywuXzcsLi4wNH0sKjgsKjhdLCo3LCo2XSwmN10x Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4582 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4020653479 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647dfc6d810, 0x5647dfe5701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5647dfe57020,0x5647e1cef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f484bd4872b146629e220e197a24bbcb8db36ef5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5722 processed earlier; will process 5307 files now Step #5: ==165028== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647d67629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647dcdc7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647dcdaa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647dcdaa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647d6768d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647d66c9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647d66c4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647d675ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647d9729f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647d9729f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647d9729f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647d9729f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647d9729f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647d9729f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647d9729f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647d9729f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647d9729f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647d9729f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647db9bef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647d86ebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647d86f6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647d84a2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647d84a2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647d84a3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647d84a2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647d84a2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647d84a2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647dcdacabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647dcdb5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647dcd9d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647dcdc8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc41afa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647d66c2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x32,0x2,0x0,0x6,0x73,0x6b,0x69,0x70,0x47,0x45,0x4f,0x78,0x2d,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x62,0xa,0x2d,0x20,0x5,0x2d,0x55,0x0,0x0,0x0,0x42,0x45,0x47,0x49,0x2a,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x44,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x22,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x3d,0x2a,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x2a,0x2a,0x2a,0x3d,0x62,0x2a, Step #5: ID2\002\000\006skipGEOx--\012=\012=\012=\012=\012=\012=\012=b\012- \005-U\000\000\000BEGI* -----\012N\012=\012=\012D=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=**********\"******************************=*\012\012=\012=\012=\012=\012=\012***=b* Step #5: artifact_prefix='./'; Test unit written to ./oom-92c5515546abc2b85a70423573b2dfca6a819d80 Step #5: Base64: SUQyAgAGc2tpcEdFT3gtLQo9Cj0KPQo9Cj0KPQo9YgotIAUtVQAAAEJFR0kqIC0tLS0tCk4KPQo9CkQ9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0qKioqKioqKioqIioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKj0qCgo9Cj0KPQo9Cj0KKioqPWIq Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4583 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4021171089 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f2267ee810, 0x55f2269d801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f2269d8020,0x55f2288700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92c5515546abc2b85a70423573b2dfca6a819d80' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5723 processed earlier; will process 5306 files now Step #5: ==165064== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f21d2e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f223948898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f22392b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f22392b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f21d2e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f21d24ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f21d245355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f21d2dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f2202aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f2202aaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f2202aaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f2202aaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f2202aaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f2202aaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f2202aaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f2202aaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f2202aaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f2202aaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f22253ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f21f26cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f21f277be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f21f023c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f21f023c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f21f024738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f21f023874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f21f023874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f21f023874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f22392dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f223936928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f22391e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f223949112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe92db2d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f21d243b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x49,0x49,0x49,0x49,0x49,0x49,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x49,0x49,0x63,0x49,0x49,0x49,0x2f,0x49,0x49,0x49,0x69,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x3d,0x3d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: s-----BEGIN -----\012IIIIIIfffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffIIcIII/IIIiIIIIIIIIIIIIII==\012-----END ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-419b30c063fe8430f6514a0aad644c0c837281bf Step #5: Base64: cy0tLS0tQkVHSU4gLS0tLS0KSUlJSUlJZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmZmSUljSUlJL0lJSWlJSUlJSUlJSUlJSUlJST09Ci0tLS0tRU5EIC0tLS0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4584 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4021676174 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e5c3828810, 0x55e5c3a1201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e5c3a12020,0x55e5c58aa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/419b30c063fe8430f6514a0aad644c0c837281bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5724 processed earlier; will process 5305 files now Step #5: ==165100== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e5ba31d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e5c0982898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e5c09655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e5c09654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e5ba323d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e5ba284b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e5ba27f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e5ba315c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e5bd2e4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e5bd2e4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e5bd2e4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e5bd2e4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e5bd2e4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e5bd2e4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e5bd2e4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e5bd2e4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e5bd2e4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e5bd2e4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e5bf579f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e5bc2a6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e5bc2b1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e5bc05dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e5bc05dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e5bc05e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e5bc05d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e5bc05d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e5bc05d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e5c0967abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e5c0970928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e5c0958699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e5c0983112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f78db86a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e5ba27db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0xbe,0x9e,0x80,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xaa,0xb2,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xaa,0xb2,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xaa,0xb2,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xb4,0x88,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xaa,0xb2,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xb4,0x88, Step #5: \012\023\022\021\012\017//+build\013 w\360\276\236\200\012\023\022\021\012\017//+build\013 w\360\221\252\262\012\023\022\021\012\017//+build\013 w\360\221\252\262\012\023\022\021\012\017//+build\013 w\360\221\252\262\012\023\022\021\012\017//+build\013 w\360\221\264\210\012\023\022\021\012\017//+build\013 w\360\221\252\262\012\023\022\021\012\017//+build\013 w\360\221\264\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-3c5d086e4b9e1d0921dfd17bd725a925750f059d Step #5: Base64: ChMSEQoPLy8rYnVpbGQLIHfwvp6AChMSEQoPLy8rYnVpbGQLIHfwkaqyChMSEQoPLy8rYnVpbGQLIHfwkaqyChMSEQoPLy8rYnVpbGQLIHfwkaqyChMSEQoPLy8rYnVpbGQLIHfwkbSIChMSEQoPLy8rYnVpbGQLIHfwkaqyChMSEQoPLy8rYnVpbGQLIHfwkbSI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4585 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4022187896 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562601841810, 0x562601a2b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562601a2b020,0x5626038c30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3c5d086e4b9e1d0921dfd17bd725a925750f059d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5725 processed earlier; will process 5304 files now Step #5: #1 pulse cov: 3839 ft: 3840 exec/s: 0 rss: 175Mb Step #5: ==165136== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5625f83369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5625fe99b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625fe97e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625fe97e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5625f833cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625f829db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625f8298355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5625f832ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5625fb2fdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5625fb2fdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5625fb2fdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5625fb2fdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5625fb2fdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5625fb2fdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5625fb2fdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5625fb2fdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5625fb2fdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5625fb2fdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5625fd592f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625fa2bfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5625fa2cabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5625fa076c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5625fa076c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5625fa077738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5625fa076874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5625fa076874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5625fa076874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5625fe980abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5625fe989928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5625fe971699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5625fe99c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f761c8dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625f8296b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x78,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x65,0x43,0x65,0x65,0x63,0x65,0x67,0x65,0x65,0x65,0x65,0x61,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x65,0x65,0x65,0x65,0x63,0x2d,0x65,0x65,0x65,0x65,0x65,0x65,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x73,0x61,0x65,0x65,0x65,0x65,0x65,0x65,0x65,0x65,0x65,0x65,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x65,0x65,0x47,0x65,0x65,0x63,0x65,0x65,0x65,0x65,0x65,0x65,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x65,0x47,0x65,0x65,0x63,0x65,0x65,0x65,0x65,0x65,0x65,0x61,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x73,0x61,0x65,0x65,0x65,0x65,0x65,0x65,0x65,0x65,0x65,0x61,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x65,0x65,0x65,0x65,0x65,0x65,0x65,0x65,0x65,0x65,0x65,0x61,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x73,0x61,0x65,0x65,0x65,0x65,0x4e,0x65,0x65,0x65,0x65,0x65,0x3e, Step #5: <x><xml:eCeecegeeeea><xml:eeeec-eeeeee><xml:saeeeeeeeeee><xml:eeGeeceeeeee><xml:eGeeceeeeeea><xml:saeeeeeeeeea><xml:eeeeeeeeeeea><xml:saeeeeNeeeee> Step #5: artifact_prefix='./'; Test unit written to ./oom-b56ec3b642c6551dd53656db2f3273b3fe84483d Step #5: Base64: PHg+PHhtbDplQ2VlY2VnZWVlZWE+PHhtbDplZWVlYy1lZWVlZWU+PHhtbDpzYWVlZWVlZWVlZWU+PHhtbDplZUdlZWNlZWVlZWU+PHhtbDplR2VlY2VlZWVlZWE+PHhtbDpzYWVlZWVlZWVlZWE+PHhtbDplZWVlZWVlZWVlZWE+PHhtbDpzYWVlZWVOZWVlZWU+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4586 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4022719575 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56391af52810, 0x56391b13c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56391b13c020,0x56391cfd40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b56ec3b642c6551dd53656db2f3273b3fe84483d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5727 processed earlier; will process 5302 files now Step #5: #1 pulse cov: 3847 ft: 3848 exec/s: 0 rss: 174Mb Step #5: ==165172== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563911a479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5639180ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56391808f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56391808f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563911a4dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5639119aeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5639119a9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563911a3fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563914a0ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563914a0ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563914a0ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563914a0ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563914a0ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563914a0ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563914a0ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563914a0ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563914a0ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563914a0ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563916ca3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5639139d0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5639139dbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563913787c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563913787c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563913788738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563913787874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563913787874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563913787874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563918091abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56391809a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563918082699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5639180ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f11808c8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5639119a7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x2,0x40,0x5,0x67,0x1,0x2,0x1,0x0,0x1c,0x42,0x1,0x2,0x9,0x7f,0x2,0x22,0x7f,0x7f,0x67,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7e,0x26,0x7f,0x70,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x2d,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7e,0x7f,0x7f,0x7f,0x7f,0x10,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x70,0x7f,0x7e,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x60,0x7f,0x7f,0x7e,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x60,0x7f,0x7f,0x7f,0x7f,0x70,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0xf2,0xa0,0x81,0xb7,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f, Step #5: \000\000\002@\005g\001\002\001\000\034B\001\002\011\177\002\"\177\177g\177\177\177\177\177\177\177\177~&\177p\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177-\177\177\177\177\177\177\177\177\177~\177\177\177\177\020\000\000\000\000\000\000\000\177\177\177\177\177\177\177\177\177\177\177\177\177p\177~\177\177\177\177\177\177`\177\177~\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177`\177\177\177\177p\177\177\177\177\177\177\362\240\201\267\177\177\177\177\177\177\177\177\177\177 Step #5: artifact_prefix='./'; Test unit written to ./oom-7b2465d6edd47106552d8ba6fd1b184cafa4bcbf Step #5: Base64: AAACQAVnAQIBABxCAQIJfwIif39nf39/f39/f39+Jn9wf39/f39/f39/f39/f39/f39/f38tf39/f39/f39/fn9/f38QAAAAAAAAAH9/f39/f39/f39/f39wf35/f39/f39gf39+f39/f39/f39/f39/f39/f39/f2B/f39/cH9/f39/f/Kggbd/f39/f39/f39/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4587 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4023388168 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560fc6710810, 0x560fc68fa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560fc68fa020,0x560fc87920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7b2465d6edd47106552d8ba6fd1b184cafa4bcbf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5729 processed earlier; will process 5300 files now Step #5: #1 pulse cov: 3919 ft: 3920 exec/s: 0 rss: 175Mb Step #5: ==165208== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560fbd2059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560fc386a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560fc384d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560fc384d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560fbd20bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560fbd16cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560fbd167355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560fbd1fdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560fc01ccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560fc01ccf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560fc01ccf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560fc01ccf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560fc01ccf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560fc01ccf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560fc01ccf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560fc01ccf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560fc01ccf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560fc01ccf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560fc2461f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560fbf18eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560fbf199be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560fbef45c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560fbef45c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560fbef46738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560fbef45874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560fbef45874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560fbef45874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560fc384fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560fc3858928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560fc3840699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560fc386b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa814c4c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560fbd165b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x27,0x21,0x24,0x27,0x21,0x30,0x24,0x36,0x31,0x24,0xa3,0x68,0x34, Step #5: $++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++'!$'!0$61$\243h4 Step #5: artifact_prefix='./'; Test unit written to ./oom-3ab0aedc6600f6029ab9975389d5b5f7ce0a1185 Step #5: Base64: JCsrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrJyEkJyEwJDYxJKNoNA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4588 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4023949012 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c4dc54c810, 0x55c4dc73601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c4dc736020,0x55c4de5ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3ab0aedc6600f6029ab9975389d5b5f7ce0a1185' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5731 processed earlier; will process 5298 files now Step #5: ==165244== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c4d30419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c4d96a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c4d96895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c4d96894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c4d3047d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c4d2fa8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c4d2fa3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c4d3039c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c4d6008f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c4d6008f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c4d6008f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c4d6008f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c4d6008f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c4d6008f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c4d6008f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c4d6008f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c4d6008f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c4d6008f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c4d829df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c4d4fcab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c4d4fd5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c4d4d81c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c4d4d81c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c4d4d82738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c4d4d81874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c4d4d81874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c4d4d81874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c4d968babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c4d9694928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c4d967c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c4d96a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3708838082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c4d2fa1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x25,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x32,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x11,0x3a,0x11,0x2d,0xf,0x3a,0xf,0xf,0x52,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x30,0x41,0x0,0xf,0xf,0xf,0xf,0x24,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x32,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x11,0x3a,0x11,0x2d,0xf,0x3a,0xf,0xf,0x52,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0x5,0x24,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x3a,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x3a,0x24,0x2d,0x5b,0xee,0x24,0x5b, Step #5: $\000\000%/\000\000\000/\000\000/\000\017\017\017\017\0172-\017[\017\0171-\017[1&\021:\021-\017:\017\017R\0171\021\0171\017s [0A\000\017\017\017\017$\017-1[&\021:\021-\017\017\017\017\0172-\017[\017\0171-\017[1&\021:\021-\017:\017\017R\0171\021\0171\017s [8A\000\017\017\017\005$\017-1[&\021:\021-\017\017\017\017\0171\021\0171\021-::\017\017\017\0171\021\0171\021-::$-[\356$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-c1241efbaec759d0a105b23d1c1bf532860e0836 Step #5: Base64: JAAAJS8AAAAvAAAvAA8PDw8PMi0PWw8PMS0PWzEmEToRLQ86Dw9SDzERDzEPcyBbMEEADw8PDyQPLTFbJhE6ES0PDw8PDzItD1sPDzEtD1sxJhE6ES0POg8PUg8xEQ8xD3MgWzhBAA8PDwUkDy0xWyYROhEtDw8PDw8xEQ8xES06Og8PDw8xEQ8xES06OiQtW+4kWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4589 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4024468108 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557006fda810, 0x5570071c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5570071c4020,0x55700905c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c1241efbaec759d0a105b23d1c1bf532860e0836' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5732 processed earlier; will process 5297 files now Step #5: ==165280== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556ffdacf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557004134898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5570041175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5570041174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556ffdad5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556ffda36b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556ffda31355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556ffdac7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557000a96f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557000a96f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557000a96f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557000a96f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557000a96f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557000a96f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557000a96f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557000a96f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557000a96f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557000a96f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557002d2bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556fffa58b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556fffa63be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556fff80fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556fff80fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556fff810738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556fff80f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556fff80f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556fff80f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557004119abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557004122928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55700410a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557004135112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5ddeaa4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556ffda2fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x42,0x38,0x4f,0x41,0x55,0x55,0x58,0x44,0x45,0x51,0x4d,0x6f,0x77,0x69,0x66,0x2b,0x68,0x52,0x2f,0x30,0x4a,0x6a,0x58,0x31,0x77,0x34,0x2f,0x70,0x4b,0x37,0x31,0x67,0x37,0x4a,0x2f,0x32,0x79,0x34,0x65,0x72,0x31,0x30,0x30,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36,0xa,0x61,0x9,0x2a,0x36, Step #5: onion-key\012ntor-onion-key B8OAUUXDEQMowif+hR/0JjX1w4/pK71g7J/2y4er100\012a\011*6\012a\011*6\012a\011*6\012a\011*6\012a\011*6\012a\011*6\012a\011*6\012a\011*6\012a\011*6\012a\011*6\012a\011*6\012a\011*6\012a\011*6\012a\011*6\012a\011*6\012a\011*6 Step #5: artifact_prefix='./'; Test unit written to ./oom-9f2f6e316c20965be8d7e75e527fb08aedd6aec4 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IEI4T0FVVVhERVFNb3dpZitoUi8wSmpYMXc0L3BLNzFnN0ovMnk0ZXIxMDAKYQkqNgphCSo2CmEJKjYKYQkqNgphCSo2CmEJKjYKYQkqNgphCSo2CmEJKjYKYQkqNgphCSo2CmEJKjYKYQkqNgphCSo2CmEJKjYKYQkqNg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4590 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4024981693 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5637cf0f6810, 0x5637cf2e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5637cf2e0020,0x5637d11780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f2f6e316c20965be8d7e75e527fb08aedd6aec4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5733 processed earlier; will process 5296 files now Step #5: ==165316== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5637c5beb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5637cc250898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5637cc2335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5637cc2334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5637c5bf1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5637c5b52b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5637c5b4d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5637c5be3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5637c8bb2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5637c8bb2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5637c8bb2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5637c8bb2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5637c8bb2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5637c8bb2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5637c8bb2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5637c8bb2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5637c8bb2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5637c8bb2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5637cae47f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5637c7b74b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5637c7b7fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5637c792bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5637c792bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5637c792c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5637c792b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5637c792b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5637c792b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5637cc235abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5637cc23e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5637cc226699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5637cc251112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f994ba57082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5637c5b4bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x7b,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0x20,0x20,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0xb,0x6e,0x61,0x6d,0x65,0x3a,0xd,0x22,0x44,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x27,0x47,0x66,0x27,0x20,0x20,0x20,0x20,0x5c,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x25,0xe0,0x70,0x3a,0x20,0x20,0x2d,0x20,0x20,0x2e,0x5c,0x3f,0x3f,0x2f,0x3f,0x2f,0x2f,0x2f,0x2f,0x3f,0x5c,0x33,0x36,0x37,0x5c,0x32,0x36,0x30,0x27,0x20,0x20,0x20,0x3e,0x20,0x5c,0x30,0x30,0x30,0x5c,0x72,0x20,0x20,0x3c,0x42,0x20,0x3e,0x22,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x76,0x61,0x6c,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x22,0x2c,0x20,0x20,0x7d,0x20,0x7d,0xa,0x20,0x20,0x7d,0x20,0x7d,0xa,0x7d,0x7d, Step #5: p{doctype {\012mdecl { entity {\013name:\015\"D PUBLIC 'Gf' \\'http://%\340p: - .\\??/?////?\\367\\260' > \\000\\r <B >\"ent {\012 val { name: \"D\", } }\012 } }\012}} Step #5: artifact_prefix='./'; Test unit written to ./oom-c5792591388c62588120d9c3dd2971b2c2ce5fb6 Step #5: Base64: cHtkb2N0eXBlIHsKbWRlY2wgeyAgZW50aXR5IHsLbmFtZToNIkQgUFVCTElDICdHZicgICAgXCdodHRwOi8vJeBwOiAgLSAgLlw/Py8/Ly8vLz9cMzY3XDI2MCcgICA+IFwwMDBcciAgPEIgPiJlbnQgewogIHZhbCB7IG5hbWU6ICJEIiwgIH0gfQogIH0gfQp9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4591 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4025490430 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5612a8fac810, 0x5612a919601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5612a9196020,0x5612ab02e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c5792591388c62588120d9c3dd2971b2c2ce5fb6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5734 processed earlier; will process 5295 files now Step #5: ==165352== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56129faa19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5612a6106898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5612a60e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5612a60e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56129faa7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56129fa08b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56129fa03355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56129fa99c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5612a2a68f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5612a2a68f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5612a2a68f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5612a2a68f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5612a2a68f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5612a2a68f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5612a2a68f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5612a2a68f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5612a2a68f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5612a2a68f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5612a4cfdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5612a1a2ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5612a1a35be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5612a17e1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5612a17e1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5612a17e2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5612a17e1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5612a17e1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5612a17e1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5612a60ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5612a60f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5612a60dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5612a6107112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f652f127082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56129fa01b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x31,0x2a,0x74,0xd,0x74,0x2b,0x74,0xd,0x74,0xf,0x24,0x32,0x2a,0x74,0xd,0x74,0x74,0xd,0x74,0xf, Step #5: $!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!1*t\015t+t\015t\017$2*t\015tt\015t\017 Step #5: artifact_prefix='./'; Test unit written to ./oom-51464f68e826e7d499a583e5dfe82563cf70b376 Step #5: Base64: JCEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISExKnQNdCt0DXQPJDIqdA10dA10Dw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4592 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4026007953 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562047f01810, 0x5620480eb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5620480eb020,0x562049f830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/51464f68e826e7d499a583e5dfe82563cf70b376' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5735 processed earlier; will process 5294 files now Step #5: ==165388== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56203e9f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56204505b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56204503e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56204503e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56203e9fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56203e95db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56203e958355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56203e9eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5620419bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5620419bdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5620419bdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5620419bdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5620419bdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5620419bdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5620419bdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5620419bdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5620419bdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5620419bdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562043c52f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56204097fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56204098abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562040736c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562040736c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562040737738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562040736874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562040736874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562040736874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562045040abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562045049928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562045031699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56204505c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe75275c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56203e956b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0x72,0x69,0x63,0x74,0x66,0x70,0x20,0x73,0x74,0xd7,0x1, Step #5: strictfp strictfp strictfp strictfp strictfp strictfp strictfp strictfp strictfp strictfp strictfp strictfp strictfp strictfp strictfp strictfp st\327\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-0fe0659fb34ad1f98ddcdb5dd54696df91cc7c56 Step #5: Base64: c3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3RyaWN0ZnAgc3TXAQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4593 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4026521377 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555c24e12810, 0x555c24ffc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555c24ffc020,0x555c26e940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0fe0659fb34ad1f98ddcdb5dd54696df91cc7c56' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5736 processed earlier; will process 5293 files now Step #5: ==165424== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555c1b9079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555c21f6c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555c21f4f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555c21f4f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555c1b90dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555c1b86eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555c1b869355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555c1b8ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555c1e8cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555c1e8cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555c1e8cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555c1e8cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555c1e8cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555c1e8cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555c1e8cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555c1e8cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555c1e8cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555c1e8cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555c20b63f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555c1d890b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555c1d89bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555c1d647c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555c1d647c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555c1d648738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555c1d647874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555c1d647874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555c1d647874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555c21f51abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555c21f5a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555c21f42699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555c21f6d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8381031082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555c1b867b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x32,0x77,0x48,0x65,0x46,0x4d,0x76,0x57,0x53,0x63,0x6f,0x41,0x61,0x71,0x59,0x31,0x2b,0x6f,0x68,0x47,0x44,0x6c,0x4b,0x41,0x41,0x42,0x73,0x54,0x2b,0x53,0x53,0x58,0x4c,0x49,0x7a,0x56,0x77,0x6a,0x77,0x6f,0x32,0x54,0x45,0xa,0x61,0x20,0x30,0x3a,0x3a,0x30,0x3a,0x61,0x3a,0x61,0x3a,0x32,0x3a,0x31,0x3a,0x31,0x3a,0x61,0x2f,0xa,0x61,0x20,0x30,0x3a,0x31,0x3a,0x30,0x3a,0x3a,0x61,0x3a,0x32,0x3a,0x30,0x3a,0x31,0x3a,0x61,0x2f,0xa,0x61,0x20,0x30,0x3a,0x31,0x3a,0x30,0x3a,0x61,0x3a,0x61,0x3a,0x3a,0x30,0x3a,0x31,0x3a,0x61,0x2f,0xa,0x61,0x20,0x30,0x3a,0x30,0x3a,0x3a,0x61,0x3a,0x61,0x3a,0x32,0x3a,0x30,0x3a,0x30,0x3a,0x61,0x2f, Step #5: onion-key\012ntor-onion-key 2wHeFMvWScoAaqY1+ohGDlKAABsT+SSXLIzVwjwo2TE\012a 0::0:a:a:2:1:1:a/\012a 0:1:0::a:2:0:1:a/\012a 0:1:0:a:a::0:1:a/\012a 0:0::a:a:2:0:0:a/ Step #5: artifact_prefix='./'; Test unit written to ./oom-ee9ca813dc88e7b908fde07c4653427801708e57 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IDJ3SGVGTXZXU2NvQWFxWTErb2hHRGxLQUFCc1QrU1NYTEl6Vndqd28yVEUKYSAwOjowOmE6YToyOjE6MTphLwphIDA6MTowOjphOjI6MDoxOmEvCmEgMDoxOjA6YTphOjowOjE6YS8KYSAwOjA6OmE6YToyOjA6MDphLw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4594 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4027028120 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56289b487810, 0x56289b67101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56289b671020,0x56289d5090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee9ca813dc88e7b908fde07c4653427801708e57' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5737 processed earlier; will process 5292 files now Step #5: ==165460== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562891f7c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5628985e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5628985c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5628985c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562891f82d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562891ee3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562891ede355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562891f74c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562894f43f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562894f43f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562894f43f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562894f43f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562894f43f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562894f43f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562894f43f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562894f43f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562894f43f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562894f43f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5628971d8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562893f05b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562893f10be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562893cbcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562893cbcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562893cbd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562893cbc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562893cbc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562893cbc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5628985c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5628985cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5628985b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5628985e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b67402082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562891edcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x5e,0x49,0xd,0xd,0xd,0x68,0x6d,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0x74,0x78,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0x4d,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xc4,0x35, Step #5: DanM^I\015\015\015hm\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015tx\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015M\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\3045 Step #5: artifact_prefix='./'; Test unit written to ./oom-a95e101383ff7c2af42116b6d6f5a7df4db5827f Step #5: Base64: RGFuTV5JDQ0NaG0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ10eA0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NTQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ3ENQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4595 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4027543873 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5629217f2810, 0x5629219dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5629219dc020,0x5629238740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a95e101383ff7c2af42116b6d6f5a7df4db5827f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5738 processed earlier; will process 5291 files now Step #5: #1 pulse cov: 4018 ft: 4019 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 4367 ft: 4882 exec/s: 0 rss: 175Mb Step #5: ==165496== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5629182e79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56291e94c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56291e92f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56291e92f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5629182edd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56291824eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562918249355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5629182dfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56291b2aef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56291b2aef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56291b2aef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56291b2aef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56291b2aef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56291b2aef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56291b2aef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56291b2aef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56291b2aef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56291b2aef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56291d543f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56291a270b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56291a27bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56291a027c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56291a027c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56291a028738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56291a027874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56291a027874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56291a027874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56291e931abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56291e93a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56291e922699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56291e94d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd223324082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562918247b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x61,0x73,0x6d,0x1,0x0,0x0,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8e,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8a,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8e,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8a,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8e,0x0,0x0,0x5,0x3,0xe0,0xa0,0x8e,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8e,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8a,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8e,0x0,0x0,0x5,0x3,0xe0,0xa0,0x8e,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8e,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8a,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8e,0x0,0x0,0x5,0x3,0xe0,0xa0,0x8e,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8a,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8e,0x0,0x0,0x5,0x3,0xe0,0xa0,0x8e,0x0,0x0,0x5,0x3,0xe0,0xb7,0x8e,0x61,0x0,0x5,0x3,0xe0,0xb7,0x8e,0x0,0x0,0x0,0x5,0x3,0xe0,0xa0,0x8e,0x0, Step #5: \000asm\001\000\000\000\000\005\003\340\267\216\000\000\005\003\340\267\212\000\000\005\003\340\267\216\000\000\005\003\340\267\212\000\000\005\003\340\267\216\000\000\005\003\340\240\216\000\000\005\003\340\267\216\000\000\005\003\340\267\212\000\000\005\003\340\267\216\000\000\005\003\340\240\216\000\000\005\003\340\267\216\000\000\005\003\340\267\212\000\000\005\003\340\267\216\000\000\005\003\340\240\216\000\000\005\003\340\267\212\000\000\005\003\340\267\216\000\000\005\003\340\240\216\000\000\005\003\340\267\216a\000\005\003\340\267\216\000\000\000\005\003\340\240\216\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-58f220149d99c29edc035be413b5c3fb91478f53 Step #5: Base64: AGFzbQEAAAAABQPgt44AAAUD4LeKAAAFA+C3jgAABQPgt4oAAAUD4LeOAAAFA+CgjgAABQPgt44AAAUD4LeKAAAFA+C3jgAABQPgoI4AAAUD4LeOAAAFA+C3igAABQPgt44AAAUD4KCOAAAFA+C3igAABQPgt44AAAUD4KCOAAAFA+C3jmEABQPgt44AAAAFA+CgjgA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4596 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4028137553 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d343984810, 0x55d343b6e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d343b6e020,0x55d345a060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58f220149d99c29edc035be413b5c3fb91478f53' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5741 processed earlier; will process 5288 files now Step #5: ==165532== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d33a4799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d340ade898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d340ac15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d340ac14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d33a47fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d33a3e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d33a3db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d33a471c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d33d440f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d33d440f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d33d440f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d33d440f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d33d440f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d33d440f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d33d440f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d33d440f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d33d440f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d33d440f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d33f6d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d33c402b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d33c40dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d33c1b9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d33c1b9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d33c1ba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d33c1b9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d33c1b9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d33c1b9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d340ac3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d340acc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d340ab4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d340adf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3571f58082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d33a3d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x8f,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0xd8,0xd2,0xd2,0xd2,0x2d,0x2d,0xfa,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x8f,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0xd8,0xd2,0xd2,0xd2,0x2d,0x2d,0xfa,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: `-----BEG\011N -----\012=\012\012=\012-----BEG\011N -----\012`-----BEG\011N -----\012`-----BEG\011N -----\012`-----\377\377\377\377\377\377\377\217--BEG\011N\330\322\322\322--\372N -------\012`-----\377\377\377\377\377\377\377\217--BEG\011N\330\322\322\322--\372N ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-718a3affcd574c475da279a1f7fa097848ebd637 Step #5: Base64: YC0tLS0tQkVHCU4gLS0tLS0KPQoKPQotLS0tLUJFRwlOIC0tLS0tCmAtLS0tLUJFRwlOIC0tLS0tCmAtLS0tLUJFRwlOIC0tLS0tCmAtLS0tLf////////+PLS1CRUcJTtjS0tItLfpOIC0tLS0tLS0KYC0tLS0t/////////48tLUJFRwlO2NLS0i0t+k4gLS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4597 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4028776763 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5628f1c22810, 0x5628f1e0c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5628f1e0c020,0x5628f3ca40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/718a3affcd574c475da279a1f7fa097848ebd637' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5742 processed earlier; will process 5287 files now Step #5: #1 pulse cov: 3846 ft: 3847 exec/s: 0 rss: 177Mb Step #5: ==165568== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5628e87179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5628eed7c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5628eed5f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5628eed5f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5628e871dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5628e867eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5628e8679355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5628e870fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5628eb6def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5628eb6def10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5628eb6def10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5628eb6def10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5628eb6def10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5628eb6def10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5628eb6def10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5628eb6def10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5628eb6def10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5628eb6def10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5628ed973f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5628ea6a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5628ea6abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5628ea457c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5628ea457c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5628ea458738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5628ea457874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5628ea457874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5628ea457874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5628eed61abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5628eed6a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5628eed52699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5628eed7d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf351a8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5628e8677b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x2a,0x2a,0x2c,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x22,0x31,0x8,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x28,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0xdb,0x80,0xdb,0x80,0x39,0x38,0x0,0x0,0x25,0x0,0x0,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x2a,0x2a,0x2a,0x2a,0x0,0x2a,0xd,0x0,0x0,0x0,0x2a,0x2e,0x74,0xe6,0x0,0x9,0x78,0x5d, Step #5: ID3\004**,**********\000\"1\010******(\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000=\333\200\333\20098\000\000%\000\000\012\000\000\000\000\000\000****\000*\015\000\000\000*.t\346\000\011x] Step #5: artifact_prefix='./'; Test unit written to ./oom-b4e363ff99d98dcec2a5246d8cc3aba7abc07b5a Step #5: Base64: SUQzBCoqLCoqKioqKioqKioAIjEIKioqKioqKAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD3bgNuAOTgAACUAAAoAAAAAAAAqKioqACoNAAAAKi505gAJeF0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4598 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4029332154 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ed7abe810, 0x559ed7ca801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ed7ca8020,0x559ed9b400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b4e363ff99d98dcec2a5246d8cc3aba7abc07b5a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5744 processed earlier; will process 5285 files now Step #5: ==165604== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559ece5b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ed4c18898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ed4bfb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ed4bfb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ece5b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ece51ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ece515355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ece5abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ed157af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ed157af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ed157af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ed157af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ed157af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ed157af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ed157af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ed157af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ed157af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ed157af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ed380ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559ed053cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559ed0547be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559ed02f3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559ed02f3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559ed02f4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559ed02f3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559ed02f3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559ed02f3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ed4bfdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ed4c06928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ed4bee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ed4c19112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4c3de16082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ece513b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x28,0x28,0x28,0x28,0x28,0x28,0x24,0x7b,0x31,0x7d,0x78,0x7b,0x32,0x7d,0x78,0x7b,0x32,0x7d,0x28,0x35,0x7b,0x32,0x7d,0x0,0x7b,0x31,0x7d,0x78,0x7b,0x31,0x7d,0x78,0x7b,0x32,0x7d,0x29,0x7b,0x32,0x7d,0x29,0x7b,0x24,0x7b,0x31,0x7d,0x78,0x7b,0x32,0x7d,0x78,0x7b,0x32,0x7d,0x28,0x35,0x7b,0x32,0x7d,0x0,0x7b,0x31,0x7d,0x78,0x7b,0x31,0x7d,0x78,0x7b,0x32,0x7d,0x29,0x7b,0x32,0x7d,0x29,0x7b,0x32,0x7d,0x7d,0x7b,0x38,0x7d,0x78,0x7b,0x32,0x7d,0x7d,0x7b,0x33,0x7d,0x7b,0x7b,0x32,0x7d,0x78,0x7b,0x32,0x7d,0x29,0x7b,0x32,0x7d,0x32,0x7d,0x7d,0x7b,0x38,0x7d,0x78,0x7b,0x32,0x7d,0x7d,0x7b,0x33,0x7d,0x7b,0x7b,0x32,0x7d,0x78,0x7b,0x32,0x7d,0x29,0x7b,0x32,0x7d,0x29,0x7b,0x32,0x7d,0x29,0x7b,0x33,0x7d,0x29,0x7b,0x32,0x7d,0x29,0x7b,0x32,0x7d,0x29,0x7b,0x32,0x7d, Step #5: (((((((${1}x{2}x{2}(5{2}\000{1}x{1}x{2}){2}){${1}x{2}x{2}(5{2}\000{1}x{1}x{2}){2}){2}}{8}x{2}}{3}{{2}x{2}){2}2}}{8}x{2}}{3}{{2}x{2}){2}){2}){3}){2}){2}){2} Step #5: artifact_prefix='./'; Test unit written to ./oom-9534f596c62112963e7d5a4cec8ea961e8c2a552 Step #5: Base64: KCgoKCgoKCR7MX14ezJ9eHsyfSg1ezJ9AHsxfXh7MX14ezJ9KXsyfSl7JHsxfXh7Mn14ezJ9KDV7Mn0AezF9eHsxfXh7Mn0pezJ9KXsyfX17OH14ezJ9fXszfXt7Mn14ezJ9KXsyfTJ9fXs4fXh7Mn19ezN9e3syfXh7Mn0pezJ9KXsyfSl7M30pezJ9KXsyfSl7Mn0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4599 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4029848099 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558d9a22f810, 0x558d9a41901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558d9a419020,0x558d9c2b10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9534f596c62112963e7d5a4cec8ea961e8c2a552' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5745 processed earlier; will process 5284 files now Step #5: #1 pulse cov: 3990 ft: 3991 exec/s: 0 rss: 175Mb Step #5: ==165640== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558d90d249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558d97389898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558d9736c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558d9736c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558d90d2ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558d90c8bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558d90c86355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558d90d1cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558d93cebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558d93cebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558d93cebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558d93cebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558d93cebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558d93cebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558d93cebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558d93cebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558d93cebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558d93cebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558d95f80f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558d92cadb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558d92cb8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558d92a64c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558d92a64c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558d92a65738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558d92a64874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558d92a64874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558d92a64874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558d9736eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558d97377928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558d9735f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558d9738a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fee37cf6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558d90c84b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0xdb,0x80,0xdb,0x80,0x39,0x39,0x39,0x39,0x39,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0xdb,0x80,0xdb,0x80,0x39,0x39,0x39,0x39,0x39,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0xf6,0x2e,0x2e,0x2e,0x2e,0x33,0x2,0x6b,0x6,0x65,0x6e,0x72,0x58,0x29,0x58,0x78,0x54,0x58,0x58,0x2a,0x4b,0x0,0x0,0x44,0x6b,0xff, Step #5: ID.....................................................\333\200\333\20099999..........................................\333\200\333\20099999........\366....3\002k\006enrX)XxTXX*K\000\000Dk\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-e11ac5763b079563e5ae9670a5271989bedb7709 Step #5: Base64: SUQuLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLtuA24A5OTk5OS4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLi4uLtuA24A5OTk5OS4uLi4uLi4u9i4uLi4zAmsGZW5yWClYeFRYWCpLAABEa/8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4600 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4030400559 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c969cd0810, 0x55c969eba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c969eba020,0x55c96bd520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e11ac5763b079563e5ae9670a5271989bedb7709' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5747 processed earlier; will process 5282 files now Step #5: #1 pulse cov: 3987 ft: 3988 exec/s: 0 rss: 176Mb Step #5: ==165676== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c9607c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c966e2a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c966e0d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c966e0d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9607cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c96072cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c960727355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9607bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c96378cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c96378cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c96378cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c96378cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c96378cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c96378cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c96378cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c96378cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c96378cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c96378cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c965a21f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c96274eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c962759be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c962505c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c962505c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c962506738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c962505874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c962505874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c962505874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c966e0fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c966e18928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c966e00699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c966e2b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff796b70082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c960725b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x88,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x5b,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x6c,0x0,0x0,0x0,0x0,0xb,0x0,0x60,0xa,0xa,0x31,0x2f,0x60,0xa,0x20,0x20,0x60,0xe2,0x88,0x88,0x2d,0x0,0xa,0x5b,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x6c,0x0,0x0,0x0,0x0,0xb,0x0,0x60,0xa,0xa,0x31,0x2f,0x60,0xa,0x20,0x20,0x60,0xe2,0x88,0x60,0xa,0x2b,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x3a,0x48,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0x11,0xf3,0xa0,0x81,0xba,0x21,0xf3,0xa0,0x81,0xba,0x70,0xa,0xa,0x2f,0x60,0xa,0x60,0x2f,0xb,0x20,0x0,0x6c,0x60,0xa, Step #5: `\342\210\210-\000`\012\363\240\201\272/\012[\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000l\000\000\000\000\013\000`\012\0121/`\012 `\342\210\210-\000\012[\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000l\000\000\000\000\013\000`\012\0121/`\012 `\342\210`\012+\363\240\201\272/\012`\342\200\210:H\000`\012\363\240\201\272/\012`\342\200\210-\000`\021\363\240\201\272!\363\240\201\272p\012\012/`\012`/\013 \000l`\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-e2b5f8f788a1930e6cd22481b938410443df8e66 Step #5: Base64: YOKIiC0AYArzoIG6Lwpb4oCILQBgCvOggbrzoIG6LwEAbAAAAAALAGAKCjEvYAogIGDiiIgtAApb4oCILQBgCvOggbrzoIG6LwEAbAAAAAALAGAKCjEvYAogIGDiiGAKK/OggbovCmDigIg6SABgCvOggbovCmDigIgtAGAR86CBuiHzoIG6cAoKL2AKYC8LIABsYAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4601 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4031075345 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b342de5810, 0x55b342fcf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b342fcf020,0x55b344e670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e2b5f8f788a1930e6cd22481b938410443df8e66' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5749 processed earlier; will process 5280 files now Step #5: #1 pulse cov: 3889 ft: 3890 exec/s: 0 rss: 174Mb Step #5: #2 pulse cov: 4356 ft: 4719 exec/s: 0 rss: 175Mb Step #5: ==165712== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b3398da9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b33ff3f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b33ff225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b33ff224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b3398e0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b339841b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b33983c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b3398d2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b33c8a1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b33c8a1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b33c8a1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b33c8a1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b33c8a1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b33c8a1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b33c8a1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b33c8a1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b33c8a1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b33c8a1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b33eb36f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b33b863b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b33b86ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b33b61ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b33b61ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b33b61b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b33b61a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b33b61a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b33b61a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b33ff24abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b33ff2d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b33ff15699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b33ff40112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1657637082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b33983ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x7,0xf,0x0,0x0,0x2f,0x7e,0xf,0xf,0xf,0x30,0x11,0xf,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x31,0x11,0x2d,0x5b,0x2d,0x3a,0x24,0x5b, Step #5: $\000\007\017\000\000/~\017\017\0170\021\017\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0001\021-[-:$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-055f6150826746bad1b7f079a040e2cf92ad0d25 Step #5: Base64: JAAHDwAAL34PDw8wEQ8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADERLVstOiRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4602 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4031700671 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c185aa3810, 0x55c185c8d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c185c8d020,0x55c187b250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/055f6150826746bad1b7f079a040e2cf92ad0d25' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5753 processed earlier; will process 5276 files now Step #5: #1 pulse cov: 3814 ft: 3815 exec/s: 0 rss: 176Mb Step #5: ==165748== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c17c5989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c182bfd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c182be05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c182be04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c17c59ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c17c4ffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c17c4fa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c17c590c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c17f55ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c17f55ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c17f55ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c17f55ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c17f55ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c17f55ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c17f55ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c17f55ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c17f55ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c17f55ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c1817f4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c17e521b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c17e52cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c17e2d8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c17e2d8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c17e2d9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c17e2d8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c17e2d8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c17e2d8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c182be2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c182beb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c182bd3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c182bfe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f061439a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c17c4f8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x7b,0x20,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0xa,0x20,0x20,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0xa,0x20,0x6e,0x61,0x6d,0x65,0x3a,0xb,0x22,0x44,0x20,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x27,0x27,0x20,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x3b,0x3a,0x33,0x35,0x33,0x39,0x33,0x33,0x35,0x31,0x33,0x35,0x2f,0x3e,0x34,0x34,0xc5,0x59,0x59,0x59,0x59,0x59,0x58,0x70,0x59,0x59,0x3e,0x3e,0x31,0x37,0x20,0x3e,0x27,0x20,0x20,0xd,0x3e,0x20,0x20,0x5c,0x30,0x30,0x20,0x3c,0x48,0x3e,0x20,0x23,0x45,0x22,0x20,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x76,0x61,0x6c,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x22,0x20,0x20,0x20,0x7d,0x7d,0xa,0xa,0x7d,0x20,0x7d,0xb,0x20,0x20,0x7d,0x7d, Step #5: p{ doctype {\012mdecl {\012 entity {\012 name:\013\"D PUBLIC '' 'http://;:3539335135/>44\305YYYYYXpYY>>17 >' \015> \\00 <H> #E\" ent {\012 val { name: \"D\" }}\012\012} }\013 }} Step #5: artifact_prefix='./'; Test unit written to ./oom-13bfd167d23484803b08be0448f5eeb04ff877a8 Step #5: Base64: cHsgZG9jdHlwZSB7Cm1kZWNsIHsKICBlbnRpdHkgewogbmFtZToLIkQgIFBVQkxJQyAnJyAnaHR0cDovLzs6MzUzOTMzNTEzNS8+NDTFWVlZWVlYcFlZPj4xNyA+JyAgDT4gIFwwMCA8SD4gI0UiIGVudCB7CiAgdmFsIHsgbmFtZTogIkQiICAgfX0KCn0gfQsgIH19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4603 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4032244556 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55de9346c810, 0x55de9365601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55de93656020,0x55de954ee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/13bfd167d23484803b08be0448f5eeb04ff877a8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5755 processed earlier; will process 5274 files now Step #5: #1 pulse cov: 4060 ft: 4061 exec/s: 0 rss: 178Mb Step #5: ==165784== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55de89f619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55de905c6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55de905a95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55de905a94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55de89f67d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55de89ec8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55de89ec3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55de89f59c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55de8cf28f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55de8cf28f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55de8cf28f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55de8cf28f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55de8cf28f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55de8cf28f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55de8cf28f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55de8cf28f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55de8cf28f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55de8cf28f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55de8f1bdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55de8beeab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55de8bef5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55de8bca1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55de8bca1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55de8bca2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55de8bca1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55de8bca1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55de8bca1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55de905ababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55de905b4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55de9059c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55de905c7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe097959082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55de89ec1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x49,0x0,0x2d,0x27,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x47,0x49,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0xa,0x3d,0x44,0x33,0x4,0xcc,0x96,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xa5,0xa,0x8d, Step #5: =\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=I\000-'---BEGIN\000------\012-----\000-----BE\012=\012=\012=GIN\012=\012=\012=\012=\000----\012--\012=D3\004\314\226skip_cl\012|\000\020\245\012\215 Step #5: artifact_prefix='./'; Test unit written to ./oom-8c065917180f906c639a6837e2609824abbd5c20 Step #5: Base64: PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj1JAC0nLS0tQkVHSU4ALS0tLS0tCi0tLS0tAC0tLS0tQkUKPQo9Cj1HSU4KPQo9Cj0KPQAtLS0tCi0tCj1EMwTMlnNraXBfY2wKfAAQpQqN Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4604 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4032798941 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562f8e5da810, 0x562f8e7c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562f8e7c4020,0x562f9065c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c065917180f906c639a6837e2609824abbd5c20' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5757 processed earlier; will process 5272 files now Step #5: ==165820== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562f850cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562f8b734898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562f8b7175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562f8b7174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562f850d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562f85036b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562f85031355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562f850c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562f88096f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562f88096f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562f88096f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562f88096f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562f88096f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562f88096f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562f88096f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562f88096f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562f88096f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562f88096f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562f8a32bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562f87058b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562f87063be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562f86e0fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562f86e0fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562f86e10738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562f86e0f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562f86e0f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562f86e0f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562f8b719abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562f8b722928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562f8b70a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562f8b735112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa636af8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562f8502fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xde,0xa6,0x0,0x1c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x3d,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x0,0x0,0x0,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0xb3,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x0,0x0,0x0,0x0, Step #5: \336\246\000\034\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000|||||||||||=||||||||||||||||||||||||||||||||||||||||||||||\000\000\000\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263\263hhhhhhhhhhh\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f3c74e2ba0935f7e31a59c05b0bd7d5d8b11a03e Step #5: Base64: 3qYAHAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHx8fHx8fHx8fHx8PXx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHwAAACzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OzaGhoaGhoaGhoaGgAAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4605 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4033303208 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b77e40810, 0x560b7802a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b7802a020,0x560b79ec20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f3c74e2ba0935f7e31a59c05b0bd7d5d8b11a03e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5758 processed earlier; will process 5271 files now Step #5: ==165856== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560b6e9359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b74f9a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b74f7d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b74f7d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b6e93bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b6e89cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b6e897355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b6e92dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b718fcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b718fcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b718fcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b718fcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b718fcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b718fcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b718fcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b718fcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b718fcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b718fcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b73b91f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b708beb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b708c9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b70675c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b70675c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b70676738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b70675874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b70675874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b70675874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b74f7fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b74f88928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b74f70699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b74f9b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f63fb4b7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b6e895b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x2b,0x42,0xdb,0xbe,0x7c,0xdb,0xbe,0x2b,0x2b,0x2b,0x2b,0x2b,0x41,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x24,0x6e,0x24,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x45,0x4e,0x2b,0x42,0xdb,0xbe,0x7c,0xdb,0xbe,0x2b,0x2b,0x2b,0x2b,0x2b,0x41,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x24,0x6e,0x24,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0xb4,0xdf,0x2d,0x2d,0x2d,0x2d,0x2d,0xa, Step #5: -----END ------END -----END -----\012-----EN+B\333\276|\333\276+++++A+++++++$n$D -----\012EN+B\333\276|\333\276+++++A+++++++$n$D -----\012-----END -----\012-----END -----\012-----EN\264\337-----\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-b89f2fa753693b193066a609f208fc92cc569ee9 Step #5: Base64: LS0tLS1FTkQgLS0tLS0tRU5EIC0tLS0tRU5EIC0tLS0tCi0tLS0tRU4rQtu+fNu+KysrKytBKysrKysrKyRuJEQgLS0tLS0KRU4rQtu+fNu+KysrKytBKysrKysrKyRuJEQgLS0tLS0KLS0tLS1FTkQgLS0tLS0KLS0tLS1FTkQgLS0tLS0KLS0tLS1FTrTfLS0tLS0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4606 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4033806509 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cf15952810, 0x55cf15b3c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cf15b3c020,0x55cf179d40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b89f2fa753693b193066a609f208fc92cc569ee9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5759 processed earlier; will process 5270 files now Step #5: ==165892== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cf0c4479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cf12aac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cf12a8f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cf12a8f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cf0c44dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cf0c3aeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cf0c3a9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cf0c43fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cf0f40ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cf0f40ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cf0f40ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cf0f40ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cf0f40ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cf0f40ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cf0f40ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cf0f40ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cf0f40ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cf0f40ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cf116a3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cf0e3d0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cf0e3dbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cf0e187c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cf0e187c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cf0e188738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cf0e187874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cf0e187874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cf0e187874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cf12a91abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cf12a9a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cf12a82699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cf12aad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb01c0a2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cf0c3a7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x75,0x70,0x64,0x61,0x74,0x65,0x5d,0xa,0x63,0x6f,0x6d,0x70,0x61,0x74,0x69,0x62,0x6c,0x65,0x3d,0xd2,0x83,0xd2,0xb4,0xd6,0x83,0xd2,0x85,0xc2,0x83,0xd2,0xb4,0xd2,0x85,0xc2,0x81,0xd2,0x83,0xd2,0xb4,0xda,0x83,0xdb,0x83,0xd2,0xb4,0xd2,0x85,0xc2,0x83,0xd2,0xb4,0xda,0x83,0xc2,0x83,0xd2,0xb4,0xd6,0x83,0xc2,0x83,0xd2,0xb4,0xd3,0x9a,0xc2,0xbf,0xd2,0xb4,0xd2,0xb4,0x3a,0xda,0x83,0xc2,0x81,0xd2,0x83,0xc2,0x81,0xd2,0x83,0xd2,0xb4,0xda,0x83,0xdb,0x83,0xd2,0xb4,0xd2,0x85,0xc2,0x83,0xd2,0xb4,0xda,0x83,0xc2,0x83,0xd2,0xb4,0xd6,0x83,0xc2,0x83,0xd2,0xb4,0xd3,0x9a,0xc2,0x83,0xd9,0xb4,0xd2,0xb4,0xda,0x83,0xc2,0x81,0xd2,0x83,0xc2,0x81,0xd2,0x83,0xd2,0xb4,0xda,0x83,0xc2,0x83,0xd2,0xb4,0xd6,0x83,0xc2,0x83,0xd2,0xb4,0xda,0x83,0xd2,0xb4,0xdb,0x83,0xd2,0xb4,0xe0, Step #5: [update]\012compatible=\322\203\322\264\326\203\322\205\302\203\322\264\322\205\302\201\322\203\322\264\332\203\333\203\322\264\322\205\302\203\322\264\332\203\302\203\322\264\326\203\302\203\322\264\323\232\302\277\322\264\322\264:\332\203\302\201\322\203\302\201\322\203\322\264\332\203\333\203\322\264\322\205\302\203\322\264\332\203\302\203\322\264\326\203\302\203\322\264\323\232\302\203\331\264\322\264\332\203\302\201\322\203\302\201\322\203\322\264\332\203\302\203\322\264\326\203\302\203\322\264\332\203\322\264\333\203\322\264\340 Step #5: artifact_prefix='./'; Test unit written to ./oom-92c334926aae6e55d0910a6ca852f31c6ce1c8f1 Step #5: Base64: W3VwZGF0ZV0KY29tcGF0aWJsZT3Sg9K01oPShcKD0rTShcKB0oPStNqD24PStNKFwoPStNqDwoPStNaDwoPStNOawr/StNK0OtqDwoHSg8KB0oPStNqD24PStNKFwoPStNqDwoPStNaDwoPStNOawoPZtNK02oPCgdKDwoHSg9K02oPCg9K01oPCg9K02oPStNuD0rTg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4607 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4034315008 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c2e27aa810, 0x55c2e299401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c2e2994020,0x55c2e482c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92c334926aae6e55d0910a6ca852f31c6ce1c8f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5760 processed earlier; will process 5269 files now Step #5: ==165928== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c2d929f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c2df904898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c2df8e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c2df8e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c2d92a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c2d9206b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c2d9201355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c2d9297c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c2dc266f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c2dc266f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c2dc266f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c2dc266f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c2dc266f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c2dc266f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c2dc266f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c2dc266f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c2dc266f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c2dc266f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c2de4fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c2db228b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c2db233be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c2dafdfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c2dafdfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c2dafe0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c2dafdf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c2dafdf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c2dafdf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c2df8e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c2df8f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c2df8da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c2df905112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fddc8ef8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c2d91ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x65,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3d,0x22,0x45,0x55,0x43,0x63,0x6e,0x22,0x6e,0x63,0x67,0x72,0x69,0x64,0x2d,0x67,0x61,0x70,0x6f,0x64,0x69,0x3c,0x78,0x3e,0x3c,0x22,0x31,0x6e,0x67,0x3d,0x1f,0x43,0x70,0x38,0x3e,0x32,0x3a,0x6f,0x6e,0x62,0x65,0x66,0x6f,0x72,0x65,0x75,0x70,0x64,0x61,0x74,0x65,0x6c,0x6e,0x73,0x3a,0x78,0x3d,0x22,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x77,0x31,0x26,0x2e,0x26,0x72,0x67,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x8,0x65,0x73,0x70,0x61,0x74,0x74,0x70,0x3a,0x2f, Step #5: <?xml encoding=\"EUCcn\"ncgrid-gapodi<x><\"1ng=\037Cp8>2:onbeforeupdatelns:x=\"http://www.w1&.&rg\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010\010espattp:/ Step #5: artifact_prefix='./'; Test unit written to ./oom-165c53715fa4354ed6260b019f9604a3b44a9aa1 Step #5: Base64: PD94bWwgZW5jb2Rpbmc9IkVVQ2NuIm5jZ3JpZC1nYXBvZGk8eD48IjFuZz0fQ3A4PjI6b25iZWZvcmV1cGRhdGVsbnM6eD0iaHR0cDovL3d3dy53MSYuJnJnCAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIZXNwYXR0cDov Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4608 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4034818555 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56052b814810, 0x56052b9fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56052b9fe020,0x56052d8960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/165c53715fa4354ed6260b019f9604a3b44a9aa1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5761 processed earlier; will process 5268 files now Step #5: #1 pulse cov: 4379 ft: 4380 exec/s: 0 rss: 176Mb Step #5: ==165964== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5605223099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56052896e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605289515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605289514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56052230fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560522270b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56052226b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560522301c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605252d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605252d0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605252d0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605252d0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605252d0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605252d0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605252d0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605252d0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605252d0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605252d0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560527565f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560524292b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56052429dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560524049c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560524049c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56052404a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560524049874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560524049874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560524049874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560528953abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56052895c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560528944699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56052896f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5a47e7f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560522269b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x6f,0x61,0x73,0x69,0x73,0x2d,0x78,0x6d,0x6c,0x2d,0x63,0x61,0x74,0x61,0x6c,0x6f,0x67,0xd,0xa,0x63,0x61,0x74,0x61,0x6c,0x7f,0x67,0xa,0xa,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0xa,0xa,0xa,0xa,0x2d,0x2d,0x30,0xa,0xa,0xa,0x2d,0x30,0x22,0x3f,0x3e,0xa,0x3c,0x3f,0x6f,0x61,0x73,0x69,0x73,0x2d,0x78,0x6d,0x6c,0x2d,0x63,0x61,0x74,0x61,0x6c,0x6f,0x67,0xd,0xa,0x63,0x61,0x74,0x61,0x6c,0x6f,0x67,0xa,0xa,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0xa,0xa,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x3d,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x22,0x20,0x20,0x20,0x20,0xa,0xa,0xa,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0xa,0x2d,0x22,0xa,0xa,0x30,0x3f,0x3e,0xa,0x3c,0x3f,0x6f,0x61,0x73,0x69, Step #5: <?oasis-xml-catalog\015\012catal\177g\012\012\012 \012\012\012\012--0\012\012\012-0\"?>\012<?oasis-xml-catalog\015\012catalog\012\012\012 \012\012\012 = \" \012\012\012\012 \012-\"\012\0120?>\012<?oasi Step #5: artifact_prefix='./'; Test unit written to ./oom-1ccbef5636556f904eee343c424828ac50df3815 Step #5: Base64: PD9vYXNpcy14bWwtY2F0YWxvZw0KY2F0YWx/ZwoKCiAgICAgICAKCgoKLS0wCgoKLTAiPz4KPD9vYXNpcy14bWwtY2F0YWxvZw0KY2F0YWxvZwoKCiAgICAgICAKCgogICAgICAgPSAgICAgICAgICAgICAgICAiICAgIAoKCgogICAgICAgCi0iCgowPz4KPD9vYXNp Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4609 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4035374569 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d807ab810, 0x562d8099501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d80995020,0x562d8282d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ccbef5636556f904eee343c424828ac50df3815' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5763 processed earlier; will process 5266 files now Step #5: #1 pulse cov: 3893 ft: 3894 exec/s: 0 rss: 175Mb Step #5: ==166000== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562d772a09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d7d905898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d7d8e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d7d8e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d772a6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d77207b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d77202355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d77298c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d7a267f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d7a267f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d7a267f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d7a267f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d7a267f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d7a267f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d7a267f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d7a267f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d7a267f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d7a267f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d7c4fcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d79229b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d79234be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d78fe0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d78fe0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d78fe1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d78fe0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d78fe0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d78fe0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d7d8eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d7d8f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d7d8db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d7d906112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa09bc1b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d77200b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x1,0x14,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x29,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012====\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\001\024=\012=\012=\012=\012=\012=\012=)=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-23af4a2be68a61cf3483f83fb966c42cf3718c22 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9PT09Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoBFD0KPQo9Cj0KPQo9Cj0pPQo9Cj0KPQoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4610 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4035974399 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5623e3fa6810, 0x5623e419001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5623e4190020,0x5623e60280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/23af4a2be68a61cf3483f83fb966c42cf3718c22' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5765 processed earlier; will process 5264 files now Step #5: ==166036== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5623daa9b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5623e1100898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5623e10e35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5623e10e34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5623daaa1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5623daa02b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5623da9fd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5623daa93c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5623dda62f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5623dda62f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5623dda62f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5623dda62f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5623dda62f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5623dda62f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5623dda62f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5623dda62f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5623dda62f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5623dda62f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5623dfcf7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5623dca24b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5623dca2fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5623dc7dbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5623dc7dbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5623dc7dc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5623dc7db874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5623dc7db874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5623dc7db874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5623e10e5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5623e10ee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5623e10d6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5623e1101112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a33cf7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5623da9fbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x69,0x6c,0x45,0x3a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x40,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x2,0x2f,0x48,0x7c,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f,0x2e,0x2e,0x2f, Step #5: filE:\000\000\000\000\000\000\000\000 \000\000\000\000\000\000\000\000\000\000\000@\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\002/H|/../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../ Step #5: artifact_prefix='./'; Test unit written to ./oom-6011596653066792ce46399d2a6a07a162705baf Step #5: Base64: ZmlsRToAAAAAAAAAACAAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAIvSHwvLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4v Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4611 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4036474703 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5604411ce810, 0x5604413b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604413b8020,0x5604432500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6011596653066792ce46399d2a6a07a162705baf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5766 processed earlier; will process 5263 files now Step #5: #1 pulse cov: 3499 ft: 3500 exec/s: 0 rss: 174Mb Step #5: ==166072== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560437cc39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56043e328898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56043e30b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56043e30b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560437cc9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560437c2ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560437c25355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560437cbbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56043ac8af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56043ac8af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56043ac8af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56043ac8af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56043ac8af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56043ac8af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56043ac8af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56043ac8af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56043ac8af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56043ac8af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56043cf1ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560439c4cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560439c57be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560439a03c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560439a03c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560439a04738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560439a03874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560439a03874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560439a03874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56043e30dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56043e316928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56043e2fe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56043e329112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe411135082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560437c23b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x74,0x75,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x55,0x74,0x74,0x55,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7d,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x2a,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x7c,0x24,0x27,0xe,0x70,0x29,0x65,0x2a,0x7c,0x29,0x2f,0x29,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x7c,0x7f, Step #5: ttu(?:(?:?:(?:$|$|(?:(?:(?:$|$|$|$|$|$UttU|$|$|$|$|$|$|$)|$}(?:$|$|(?:(?:*?:$|$|$|$|$|$|$|$|$|$|$|$|$(?:(?:?:(?:$|$|(?:(?:(?:$|$||$'\016p)e*|)/))|)|)|)||\177 Step #5: artifact_prefix='./'; Test unit written to ./oom-3e9d65a89093b57116bebbf08b4d21cc3605db2e Step #5: Base64: dHR1KD86KD86PzooPzokfCR8KD86KD86KD86JHwkfCR8JHwkfCRVdHRVfCR8JHwkfCR8JHwkfCQpfCR9KD86JHwkfCg/Oig/Oio/OiR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkfCQoPzooPzo/Oig/OiR8JHwoPzooPzooPzokfCR8fCQnDnApZSp8KS8pKXwpfCl8KXx8fw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4612 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4037039116 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed5394e810, 0x55ed53b3801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed53b38020,0x55ed559d00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3e9d65a89093b57116bebbf08b4d21cc3605db2e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5768 processed earlier; will process 5261 files now Step #5: ==166108== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed4a4439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed50aa8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed50a8b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed50a8b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed4a449d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed4a3aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed4a3a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed4a43bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed4d40af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed4d40af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed4d40af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed4d40af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed4d40af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed4d40af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed4d40af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed4d40af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed4d40af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed4d40af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed4f69ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed4c3ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed4c3d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed4c183c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed4c183c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed4c184738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed4c183874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed4c183874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed4c183874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed50a8dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed50a96928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed50a7e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed50aa9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f646cdbc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed4a3a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0xe2,0x80,0xa8,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x71,0x6d,0x6d,0x6d,0x6d,0x6d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x33,0x2,0x6b,0x6,0x65,0x0,0x0,0x6b,0x6,0x65,0xdf,0xb4,0xfb,0xff,0x44,0x6b,0xff, Step #5: I..................mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm\342\200\250mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmqmmmmm\000\000\000\000\000\000\000......3\002k\006e\000\000k\006e\337\264\373\377Dk\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-2c9a394a012c6071b5a7f39c6fc412713eb9bbca Step #5: Base64: SS4uLi4uLi4uLi4uLi4uLi4uLm1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW3igKhtbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbXFtbW1tbQAAAAAAAAAuLi4uLi4zAmsGZQAAawZl37T7/0Rr/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4613 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4037540517 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c353de7810, 0x55c353fd101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c353fd1020,0x55c355e690e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2c9a394a012c6071b5a7f39c6fc412713eb9bbca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5769 processed earlier; will process 5260 files now Step #5: ==166144== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c34a8dc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c350f41898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c350f245dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c350f244fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c34a8e2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c34a843b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c34a83e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c34a8d4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c34d8a3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c34d8a3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c34d8a3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c34d8a3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c34d8a3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c34d8a3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c34d8a3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c34d8a3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c34d8a3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c34d8a3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c34fb38f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c34c865b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c34c870be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c34c61cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c34c61cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c34c61d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c34c61c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c34c61c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c34c61c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c350f26abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c350f2f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c350f17699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c350f42112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f28a897f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c34a83cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x32,0x32,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x5d,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x32,0x27,0x27,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $222''2-=''''''/''2-=''''''''''''''-=<''''\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000''''''''-=<'''/]'''/''''2''-='''''\000\000\000\000\000\000\000'.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-279e440daf59b243aa456de779a45fee484acaab Step #5: Base64: JDIyMicnMi09JycnJycnLycnMi09JycnJycnJycnJycnJyctPTwnJycnAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJycnJycnJyctPTwnJycvXScnJy8nJycnMicnLT0nJycnJwAAAAAAAAAnLicnJycuJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4614 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4038066180 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647d514c810, 0x5647d533601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5647d5336020,0x5647d71ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/279e440daf59b243aa456de779a45fee484acaab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5770 processed earlier; will process 5259 files now Step #5: ==166180== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647cbc419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647d22a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647d22895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647d22894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647cbc47d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647cbba8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647cbba3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647cbc39c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647cec08f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647cec08f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647cec08f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647cec08f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647cec08f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647cec08f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647cec08f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647cec08f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647cec08f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647cec08f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647d0e9df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647cdbcab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647cdbd5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647cd981c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647cd981c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647cd982738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647cd981874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647cd981874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647cd981874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647d228babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647d2294928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647d227c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647d22a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8113cc1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647cbba1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x24,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x3a,0x4e,0x21,0x24,0x47,0x49,0x2d,0x45,0xa,0x40,0x21,0xa,0x2d,0xa,0xa,0x4e,0x24,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x3a,0x4e,0x21,0x24,0x47,0x49,0x2d,0x45,0xa,0x40,0x21,0xa,0x2d,0xa,0xa,0x45,0x47,0x49,0x4e,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x47,0x49,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x54,0xa,0x1,0x0,0x33,0x4,0xcc,0x96,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0x9a,0x7c,0x0,0x10,0xa5,0xa,0x8d, Step #5: =\012=\012=\012=\012=\012=\012=\012-----BEGI\012-----BEGIN$-----\012:N!$GI-E\012@!\012-\012\012N$-----\012:N!$GI-E\012@!\012-\012\012EGIN\000------\012-----\000-----BE\012=\012=\012=GIN\012=\012=\012=\012=\000----\012--T\012\001\0003\004\314\226skip_cl\232|\000\020\245\012\215 Step #5: artifact_prefix='./'; Test unit written to ./oom-cadd66c19950c317401800c97c06a209fd930524 Step #5: Base64: PQo9Cj0KPQo9Cj0KPQotLS0tLUJFR0kKLS0tLS1CRUdJTiQtLS0tLQo6TiEkR0ktRQpAIQotCgpOJC0tLS0tCjpOISRHSS1FCkAhCi0KCkVHSU4ALS0tLS0tCi0tLS0tAC0tLS0tQkUKPQo9Cj1HSU4KPQo9Cj0KPQAtLS0tCi0tVAoBADMEzJZza2lwX2NsmnwAEKUKjQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4615 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4038583860 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cd5ca8b810, 0x55cd5cc7501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cd5cc75020,0x55cd5eb0d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cadd66c19950c317401800c97c06a209fd930524' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5771 processed earlier; will process 5258 files now Step #5: #1 pulse cov: 6692 ft: 6693 exec/s: 0 rss: 186Mb Step #5: #2 pulse cov: 7441 ft: 7778 exec/s: 0 rss: 188Mb Step #5: ==166216== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cd535809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cd59be5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cd59bc85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cd59bc84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cd53586d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cd534e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cd534e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cd53578c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cd56547f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cd56547f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cd56547f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cd56547f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cd56547f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cd56547f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cd56547f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cd56547f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cd56547f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cd56547f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cd587dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cd55509b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cd55514be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cd552c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cd552c0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cd552c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cd552c0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cd552c0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cd552c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cd59bcaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cd59bd3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cd59bbb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cd59be6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f990c4db082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cd534e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0x2f,0xd6,0xa0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0xa,0x2f,0xd6,0xa0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x6e,0x0,0x0,0x0,0xd6,0xa0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x6e,0x0,0x0,0x0,0xd6,0xa0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x6e, Step #5: \012\012/\326\240\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012\012/\326\240\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000'\000\000\000\000\000\000n\000\000\000\326\240\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000'\000\000\000\000\000\000n\000\000\000\326\240\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000'\000\000\000\000\000\000n Step #5: artifact_prefix='./'; Test unit written to ./oom-88997966c10dd7b7ffec68ce57d3423b0a8e9625 Step #5: Base64: Cgov1qAAAAAAAAAAAAAAAAAAAAAAAAAACgov1qAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAnAAAAAAAAbgAAANagAAAAAAAAAAAAAAAAAAAAJwAAAAAAAG4AAADWoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAnAAAAAAAAbg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4616 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4039184773 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a41b6ef810, 0x55a41b8d901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a41b8d9020,0x55a41d7710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88997966c10dd7b7ffec68ce57d3423b0a8e9625' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5774 processed earlier; will process 5255 files now Step #5: #1 pulse cov: 3803 ft: 3804 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 3958 ft: 4335 exec/s: 0 rss: 177Mb Step #5: ==166252== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a4121e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a418849898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a41882c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a41882c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a4121ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a41214bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a412146355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a4121dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a4151abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a4151abf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a4151abf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a4151abf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a4151abf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a4151abf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a4151abf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a4151abf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a4151abf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a4151abf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a417440f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a41416db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a414178be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a413f24c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a413f24c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a413f25738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a413f24874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a413f24874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a413f24874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a41882eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a418837928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a41881f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a41884a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf88385082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a412144b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x45,0x78,0x65,0x63,0x5d,0xa,0x57,0x6f,0x72,0x6b,0x69,0x6e,0x67,0x44,0x69,0x72,0x65,0x63,0x74,0x6f,0x72,0x79,0x3d,0xd1,0xa5,0xca,0x91,0xd1,0x9c,0xd1,0x93,0xd1,0x9c,0xcd,0x85,0xd1,0x9c,0xd0,0x9c,0xd1,0xa5,0xd1,0x93,0xd1,0x9c,0xd4,0xa5,0xd1,0x93,0xd1,0x9c,0xd1,0x9c,0xd0,0x9c,0xd1,0x86,0xc9,0x93,0xc9,0x93,0xd1,0x9c,0xc9,0x92,0xd0,0x9c,0xd1,0xa5,0xd1,0x93,0xd1,0x9c,0xd1,0x9c,0xd0,0x9c,0xd1,0xa5,0xd1,0x93,0xd1,0x9c,0xcd,0x85,0xd1,0x9c,0xd0,0x9c,0xd1,0xa5,0xd1,0x93,0xd1,0x9c,0xd4,0xa5,0xd1,0x93,0xd1,0x9c,0xd1,0x9c,0xd0,0x9c,0xd1,0x86,0xc9,0x93,0xc9,0x93,0xd1,0x9c,0xc9,0x92,0xd0,0x9c,0xd1,0xa5,0xd1,0x93,0xd1,0x9c,0xd4,0x9c,0xd1,0x93,0xd1,0x9c,0xd1,0x9c,0xd0,0x9c,0xd1,0x86,0xc9,0x93,0xc9,0x93,0xd1,0x9c,0xc9,0x92,0xd0,0x9c,0xd1,0xa5,0xd1,0x93,0xd1,0x9c, Step #5: [Exec]\012WorkingDirectory=\321\245\312\221\321\234\321\223\321\234\315\205\321\234\320\234\321\245\321\223\321\234\324\245\321\223\321\234\321\234\320\234\321\206\311\223\311\223\321\234\311\222\320\234\321\245\321\223\321\234\321\234\320\234\321\245\321\223\321\234\315\205\321\234\320\234\321\245\321\223\321\234\324\245\321\223\321\234\321\234\320\234\321\206\311\223\311\223\321\234\311\222\320\234\321\245\321\223\321\234\324\234\321\223\321\234\321\234\320\234\321\206\311\223\311\223\321\234\311\222\320\234\321\245\321\223\321\234 Step #5: artifact_prefix='./'; Test unit written to ./oom-d5105a5662c5e2a1169267415d2d1778abfa4f3d Step #5: Base64: W0V4ZWNdCldvcmtpbmdEaXJlY3Rvcnk90aXKkdGc0ZPRnM2F0ZzQnNGl0ZPRnNSl0ZPRnNGc0JzRhsmTyZPRnMmS0JzRpdGT0ZzRnNCc0aXRk9GczYXRnNCc0aXRk9Gc1KXRk9Gc0ZzQnNGGyZPJk9GcyZLQnNGl0ZPRnNSc0ZPRnNGc0JzRhsmTyZPRnMmS0JzRpdGT0Zw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4617 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4039771553 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564a09f50810, 0x564a0a13a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564a0a13a020,0x564a0bfd20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d5105a5662c5e2a1169267415d2d1778abfa4f3d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5777 processed earlier; will process 5252 files now Step #5: ==166288== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564a00a459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564a070aa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564a0708d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564a0708d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564a00a4bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564a009acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564a009a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564a00a3dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564a03a0cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564a03a0cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564a03a0cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564a03a0cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564a03a0cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564a03a0cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564a03a0cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564a03a0cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564a03a0cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564a03a0cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564a05ca1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564a029ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564a029d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564a02785c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564a02785c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564a02786738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564a02785874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564a02785874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564a02785874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564a0708fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564a07098928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564a07080699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564a070ab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe2df3f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564a009a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0x74,0x22,0x3a,0x22,0x22,0x2c,0x22,0x63,0x6f,0x6e,0x74,0x75,0x6e,0x74,0x22,0x3a,0x22,0x22,0x2c,0x22,0x32,0x2,0xdd,0x81,0x54,0x32,0x2,0x63,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x22,0x3a,0x22,0x3a,0x22,0x22,0x2c,0x22,0x63,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x22,0x3a,0x22,0x22,0x2c,0x22,0x63,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x22,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x24,0x24,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x49,0x33,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x49,0x33,0x34,0x20,0x44,0x0,0x0,0x0,0x0,0x0,0x35,0x20,0x44,0x0,0x0,0x54,0x32,0x2,0xdd,0x81,0x54,0x32,0x2,0xdd,0x81,0x0,0x0,0x0,0xbf,0x0,0x0,0x2e,0x36,0xdf,0x35,0x35,0x33,0x0,0x0,0x0,0xbf,0xdf,0x37, Step #5: :t\":\"\",\"contunt\":\"\",\"2\002\335\201T2\002content\":\":\"\",\"content\":\"\",\"content\"\000\000\000\000\000\000\000$$$$\000\000\000\000\000\000\000\000\000\000\000I3\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000I34 D\000\000\000\000\0005 D\000\000T2\002\335\201T2\002\335\201\000\000\000\277\000\000.6\337553\000\000\000\277\3377 Step #5: artifact_prefix='./'; Test unit written to ./oom-c18c7e8e63693b422746b7d6ce968b399cc8de61 Step #5: Base64: OnQiOiIiLCJjb250dW50IjoiIiwiMgLdgVQyAmNvbnRlbnQiOiI6IiIsImNvbnRlbnQiOiIiLCJjb250ZW50IgAAAAAAAAAkJCQkAAAAAAAAAAAAAABJMwAAAAAAAAAAAAAAAAAAAAAAAAAAAEkzNCBEAAAAAAA1IEQAAFQyAt2BVDIC3YEAAAC/AAAuNt81NTMAAAC/3zc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4618 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4040280528 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e1f1138810, 0x55e1f132201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e1f1322020,0x55e1f31ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c18c7e8e63693b422746b7d6ce968b399cc8de61' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5778 processed earlier; will process 5251 files now Step #5: #1 pulse cov: 3935 ft: 3936 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 12037 ft: 12918 exec/s: 0 rss: 194Mb Step #5: ==166324== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e1e7c2d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e1ee292898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e1ee2755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e1ee2754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e1e7c33d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e1e7b94b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e1e7b8f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e1e7c25c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e1eabf4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e1eabf4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e1eabf4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e1eabf4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e1eabf4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e1eabf4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e1eabf4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e1eabf4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e1eabf4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e1eabf4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e1ece89f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e1e9bb6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e1e9bc1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e1e996dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e1e996dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e1e996e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e1e996d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e1e996d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e1e996d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e1ee277abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e1ee280928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e1ee268699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e1ee293112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f69c1b2f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e1e7b8db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x88,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x0,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x0,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x0,0x0,0x0,0x0,0xb,0x0,0x60,0xa,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0x0,0x60,0xa,0xa,0x31,0x2f,0x60,0xa,0x20,0x20,0x60,0x20,0x60,0xa,0x9, Step #5: `\342\210\210-\000`\012\363\240\201\272/\012`\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000\000\000`\012\363\240\201\272/\012`\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000\000\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\006\000\000\000\000\013\000`\012\272/\012`\342\200\210-\000`\000`\012\0121/`\012 ` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-b06ef506e185f12ba3bac610397d1a1286522fa9 Step #5: Base64: YOKIiC0AYArzoIG6Lwpg4oCILQBgCvOggbrzoIG6LwEAAABgCvOggbovCmDigIgtAGAK86CBuvOggbovAQAABgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGAAAAAAsAYAq6Lwpg4oCILQBgAGAKCjEvYAogIGAgYAoJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4619 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4041013683 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0b01a8810, 0x55a0b039201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0b0392020,0x55a0b222a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b06ef506e185f12ba3bac610397d1a1286522fa9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5781 processed earlier; will process 5248 files now Step #5: #1 pulse cov: 4510 ft: 4511 exec/s: 0 rss: 175Mb Step #5: ==166360== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0a6c9d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0ad302898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0ad2e55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0ad2e54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0a6ca3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0a6c04b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0a6bff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0a6c95c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0a9c64f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0a9c64f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0a9c64f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0a9c64f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0a9c64f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0a9c64f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0a9c64f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0a9c64f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0a9c64f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0a9c64f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0abef9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0a8c26b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0a8c31be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0a89ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0a89ddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0a89de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0a89dd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0a89dd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0a89dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0ad2e7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0ad2f0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0ad2d8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0ad303112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc305b30082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0a6bfdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x52,0x1e,0x52,0x7c,0x6e,0xe,0x4e,0x3d,0xf,0x6e,0x5e,0x28,0x6e,0xd8,0x9b,0x3d,0x2e,0x5e,0x28,0x6e,0xd8,0x9b,0x3d,0x2e,0x5e,0x28,0x6e,0xd8,0x9b,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x6e,0xe,0x6e,0x3d,0xf,0x6e,0x5e,0x28,0x6e,0xd9,0x9b,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x6e,0xe,0x6e,0x3d,0xf,0x6e,0x5e,0x28,0x6e,0xd9,0x9b,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x6e,0xe,0x6e,0x3d,0xf,0x6e,0x5e,0x28,0x6e,0xd9,0x9b,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x6e,0xe,0x6e,0x3d,0xf,0x6e,0x5e,0x28,0x6e,0xd9,0x9b,0x43,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x5e,0x28,0x64,0x3d,0x2e,0x6e,0xe,0x6e,0x3d,0xf,0x6d,0x5e,0x28,0x6e,0xd9,0x9b,0x3d,0x2e,0x5e, Step #5: R\036R|n\016N=\017n^(n\330\233=.^(n\330\233=.^(n\330\233=.^(d=.^(d=.^(d=.n\016n=\017n^(n\331\233=.^(d=.^(d=.n\016n=\017n^(n\331\233=.^(d=.^(d=.n\016n=\017n^(n\331\233=.^(d=.^(d=.n\016n=\017n^(n\331\233C=.^(d=.^(d=.n\016n=\017m^(n\331\233=.^ Step #5: artifact_prefix='./'; Test unit written to ./oom-5cbe20414f17d1dd50413a7fdc87054b5e47bdec Step #5: Base64: Uh5SfG4OTj0Pbl4obtibPS5eKG7Ymz0uXihu2Js9Ll4oZD0uXihkPS5eKGQ9Lm4Obj0Pbl4obtmbPS5eKGQ9Ll4oZD0ubg5uPQ9uXihu2Zs9Ll4oZD0uXihkPS5uDm49D25eKG7Zmz0uXihkPS5eKGQ9Lm4Obj0Pbl4obtmbQz0uXihkPS5eKGQ9Lm4Obj0PbV4obtmbPS5e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4620 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4041572379 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56366e378810, 0x56366e56201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56366e562020,0x5636703fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5cbe20414f17d1dd50413a7fdc87054b5e47bdec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5783 processed earlier; will process 5246 files now Step #5: ==166396== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563664e6d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56366b4d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56366b4b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56366b4b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563664e73d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563664dd4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563664dcf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563664e65c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563667e34f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563667e34f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563667e34f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563667e34f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563667e34f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563667e34f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563667e34f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563667e34f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563667e34f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563667e34f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56366a0c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563666df6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563666e01be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563666badc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563666badc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563666bae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563666bad874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563666bad874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563666bad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56366b4b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56366b4c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56366b4a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56366b4d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc05709c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563664dcdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1,0x24,0x0,0x0,0x0,0x0,0x0,0x1f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x1,0x0,0x0,0x0,0x24,0x4f,0x0,0x0,0x0,0x1,0x0,0x0,0x0, Step #5: \001$\000\000\000\000\000\037\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\005\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\001\000\000\000$O\000\000\000\001\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2f86e2b5acbf9bcc5f7c48abbfaae718fd91c9cd Step #5: Base64: ASQAAAAAAB8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAUAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAABAAAAJE8AAAABAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4621 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4042093786 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f221e9810, 0x556f223d301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f223d3020,0x556f2426b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f86e2b5acbf9bcc5f7c48abbfaae718fd91c9cd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5784 processed earlier; will process 5245 files now Step #5: ==166432== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556f18cde9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f1f343898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f1f3265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f1f3264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f18ce4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f18c45b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f18c40355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f18cd6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f1bca5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f1bca5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f1bca5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f1bca5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f1bca5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f1bca5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f1bca5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f1bca5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f1bca5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f1bca5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f1df3af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f1ac67b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f1ac72be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f1aa1ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f1aa1ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f1aa1f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f1aa1e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f1aa1e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f1aa1e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f1f328abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f1f331928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f1f319699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f1f344112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fadf294e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f18c3eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdd,0x8c,0xdd,0x8a,0xde,0x8b,0xd9,0x8b,0xc8,0x8a,0x71,0xdd,0x8c,0xd8,0x8b,0xdc,0x8a,0xdc,0x9a,0xd5,0x8b,0xdd,0x8b,0xdc,0x8a,0xde,0x8c,0xde,0x8a,0xdd,0x8c,0xc8,0x8b,0xdc,0x8b,0xdc,0x9a,0xdd,0x8b,0xdd,0x8c,0xc8,0x8b,0xdc,0x9a,0xdd,0x8b,0xdd,0x8b,0xdd,0x8a,0xdd,0x8c,0xde,0x8a,0xdd,0x8c,0xc8,0x8a,0xdc,0x8b,0xdc,0x9a,0xdd,0x8d,0xdd,0x8b,0xdd,0x8b,0xdd,0x8b,0xdd,0x8b,0xdd,0x8b,0xdc,0x8b,0xdd,0x9a,0xdd,0x8a,0xdd,0x8b,0xdd,0x8b,0xdd,0x8b,0xdd,0x8b,0xdd,0x8b,0xdd,0x8c,0xc8,0x8b,0xdc,0x8a,0xdd,0x83,0xdd,0x8b,0xdd,0x8c,0xca,0x8b,0xdc,0x8b,0xdd,0x8b,0xdd,0x8b,0xdd,0x8b,0xdc,0x8b,0xdd,0x9a,0xdd,0x8b,0xdd,0x8a,0xdd,0x8c,0xc8,0x8b,0xdc,0x8b,0xdc,0x9a,0xdd,0x8b,0xdd,0x8b,0xdd,0x8b,0xdd,0x7e,0x92,0x43,0x49,0x0,0x0,0x20,0x88,0xfa,0x3,0xd9,0x0,0x30,0x7f,0x0,0xbc,0x63, Step #5: \335\214\335\212\336\213\331\213\310\212q\335\214\330\213\334\212\334\232\325\213\335\213\334\212\336\214\336\212\335\214\310\213\334\213\334\232\335\213\335\214\310\213\334\232\335\213\335\213\335\212\335\214\336\212\335\214\310\212\334\213\334\232\335\215\335\213\335\213\335\213\335\213\335\213\334\213\335\232\335\212\335\213\335\213\335\213\335\213\335\213\335\214\310\213\334\212\335\203\335\213\335\214\312\213\334\213\335\213\335\213\335\213\334\213\335\232\335\213\335\212\335\214\310\213\334\213\334\232\335\213\335\213\335\213\335~\222CI\000\000 \210\372\003\331\0000\177\000\274c Step #5: artifact_prefix='./'; Test unit written to ./oom-6658ecdba868847fd54e428fa596c3295ffa7089 Step #5: Base64: 3Yzdit6L2YvIinHdjNiL3IrcmtWL3Yvcit6M3ordjMiL3Ivcmt2L3YzIi9ya3Yvdi92K3Yzeit2MyIrci9ya3Y3di92L3Yvdi92L3Ivdmt2K3Yvdi92L3Yvdi92MyIvcit2D3YvdjMqL3Ivdi92L3Yvci92a3Yvdit2MyIvci9ya3Yvdi92L3X6SQ0kAACCI+gPZADB/ALxj Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4622 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4042605787 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5615c0d38810, 0x5615c0f2201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5615c0f22020,0x5615c2dba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6658ecdba868847fd54e428fa596c3295ffa7089' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5785 processed earlier; will process 5244 files now Step #5: ==166468== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5615b782d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5615bde92898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5615bde755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5615bde754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5615b7833d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5615b7794b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5615b778f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5615b7825c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5615ba7f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5615ba7f4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5615ba7f4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5615ba7f4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5615ba7f4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5615ba7f4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5615ba7f4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5615ba7f4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5615ba7f4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5615ba7f4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5615bca89f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5615b97b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5615b97c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5615b956dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5615b956dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5615b956e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5615b956d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5615b956d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5615b956d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5615bde77abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5615bde80928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5615bde68699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5615bde93112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcd23380082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5615b778db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xa,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x30,0x2e,0x7d,0x73,0x75,0x62,0x7b,0x64,0x3a,0x2e, Step #5: FUZZTESTv1\012sub{d:0.}sub{d:0.}sub{d:0.}sub{d:0.}sub{d:0.}sub{d:0.}sub{d:0.}sub{d:0.}sub{d:0.}sub{d:0.}sub{d:0.}sub{d:0.}sub{d:0.}sub{d:0.}sub{d:0.}sub{d:. Step #5: artifact_prefix='./'; Test unit written to ./oom-5cc2e4a76d7855e54aa0f5cafeec79cb78cbf44b Step #5: Base64: RlVaWlRFU1R2MQpzdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDowLn1zdWJ7ZDou Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4623 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4043114827 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5582cf985810, 0x5582cfb6f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5582cfb6f020,0x5582d1a070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5cc2e4a76d7855e54aa0f5cafeec79cb78cbf44b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5786 processed earlier; will process 5243 files now Step #5: ==166504== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5582c647a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5582ccadf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5582ccac25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5582ccac24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5582c6480d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5582c63e1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5582c63dc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5582c6472c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5582c9441f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5582c9441f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5582c9441f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5582c9441f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5582c9441f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5582c9441f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5582c9441f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5582c9441f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5582c9441f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5582c9441f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5582cb6d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5582c8403b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5582c840ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5582c81bac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5582c81bac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5582c81bb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5582c81ba874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5582c81ba874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5582c81ba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5582ccac4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5582ccacd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5582ccab5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5582ccae0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe250ba4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5582c63dab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0xa,0x3d,0xcc,0xbb,0x2b,0x41,0x2d,0x2d,0x2d,0x42,0x73,0x63,0x65,0xa,0x2d,0x3f,0x41,0x73,0x63,0x65,0x7a,0x74,0x7a,0x74,0x20,0x6a,0x2d,0x2d,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x2d,0x2d,0x2f,0x2d,0x6d,0x2d,0x42,0x45,0x1,0x0,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xe,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x49,0x44,0x34,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x1, Step #5: 0\012=\314\273+A---Bsce\012-?Asceztzt j---\012=\012=\012=\012=\012\000--/-m-BE\001\000\000=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\016=\012=\012=\012=\012=\012=\012=\012=\012=\012\000ID4\002-\001\000\000\000\000ID3\002-\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-a2d5aa0998859585a65c4495dd4d76f620cac2b9 Step #5: Base64: MAo9zLsrQS0tLUJzY2UKLT9Bc2NlenR6dCBqLS0tCj0KPQo9Cj0KAC0tLy1tLUJFAQAAPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQ49Cj0KPQo9Cj0KPQo9Cj0KPQoASUQ0Ai0BAAAAAElEMwItAQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4624 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4043637126 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a2c9cdd810, 0x55a2c9ec701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a2c9ec7020,0x55a2cbd5f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2d5aa0998859585a65c4495dd4d76f620cac2b9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5787 processed earlier; will process 5242 files now Step #5: ==166540== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a2c07d29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a2c6e37898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2c6e1a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2c6e1a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a2c07d8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a2c0739b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a2c0734355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a2c07cac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a2c3799f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a2c3799f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a2c3799f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a2c3799f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a2c3799f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a2c3799f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a2c3799f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a2c3799f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a2c3799f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a2c3799f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a2c5a2ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a2c275bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a2c2766be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a2c2512c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a2c2512c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a2c2513738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a2c2512874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a2c2512874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a2c2512874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a2c6e1cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a2c6e25928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2c6e0d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a2c6e38112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa8c10ad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a2c0732b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa,0x56,0x33,0x30,0x30,0x30,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa,0x4d,0x20,0x45,0x4e,0x44,0x9,0x2d,0xa, Step #5: \012\012\012V3000-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012M END\011-\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-a1e7fcea08da2a788fe16467d2d6f1b274f4661c Step #5: Base64: CgoKVjMwMDAtCk0gRU5ECS0KTSBFTkQJLQpNIEVORAktCk0gRU5ECS0KTSBFTkQJLQpNIEVORAktCk0gRU5ECS0KTSBFTkQJLQpNIEVORAktCk0gRU5ECS0KTSBFTkQJLQpNIEVORAktCk0gRU5ECS0KTSBFTkQJLQpNIEVORAktCk0gRU5ECS0KTSBFTkQJLQpNIEVORAktCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4625 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4044158987 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562aa4a15810, 0x562aa4bff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562aa4bff020,0x562aa6a970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a1e7fcea08da2a788fe16467d2d6f1b274f4661c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5788 processed earlier; will process 5241 files now Step #5: ==166576== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562a9b50a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562aa1b6f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562aa1b525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562aa1b524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562a9b510d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562a9b471b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562a9b46c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562a9b502c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562a9e4d1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562a9e4d1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562a9e4d1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562a9e4d1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562a9e4d1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562a9e4d1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562a9e4d1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562a9e4d1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562a9e4d1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562a9e4d1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562aa0766f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562a9d493b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562a9d49ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562a9d24ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562a9d24ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562a9d24b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562a9d24a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562a9d24a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562a9d24a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562aa1b54abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562aa1b5d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562aa1b45699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562aa1b70112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb452c96082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562a9b46ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x54,0x68,0x69,0x73,0x20,0x66,0x69,0x6c,0x65,0x20,0x6d,0x75,0x73,0x74,0x20,0x62,0x65,0x20,0x63,0x6f,0x6e,0x76,0x65,0x72,0x74,0x65,0x64,0x20,0x77,0x69,0x74,0x68,0x20,0x42,0x69,0x6e,0x48,0x65,0x78,0x20,0x34,0x2e,0x30,0x29,0xa,0x3a,0x22,0x28,0x30,0x68,0x2c,0x4d,0x4e,0x21,0x36,0x26,0x2a,0x41,0x34,0x64,0x65,0x25,0x38,0x70,0x46,0x22,0x21,0x21,0x21,0x21,0x21,0x4d,0x42,0x21,0x4e,0x21,0x34,0x66,0x39,0x38,0x65,0x25,0x21,0x22,0x5b,0x2a,0x24,0x72,0x22,0x4a,0x2a,0x24,0x72,0x22,0x4a,0x21,0x22,0x24,0x2a,0x24,0x72,0x22,0x6a,0x23,0x22,0x22,0x2a,0x22,0x2a,0x21,0x21,0x21,0x24,0x2a,0x24,0x72,0x22,0x62,0x23,0x22,0x22,0x2a,0x21,0x21,0x2a,0x64,0x22,0x4a,0x21,0x48,0x65,0x69,0x24,0x72,0x22,0x4a,0x21,0x22,0x24,0x2a,0x24,0x72,0x22,0x6a,0x23,0x22,0x22,0x2a,0x24,0x30,0x68,0x2c,0x3a, Step #5: (This file must be converted with BinHex 4.0)\012:\"(0h,MN!6&*A4de%8pF\"!!!!!MB!N!4f98e%!\"[*$r\"J*$r\"J!\"$*$r\"j#\"\"*\"*!!!$*$r\"b#\"\"*!!*d\"J!Hei$r\"J!\"$*$r\"j#\"\"*$0h,: Step #5: artifact_prefix='./'; Test unit written to ./oom-0362638ff395479cd7710aeddaa95f86f6c74c08 Step #5: Base64: KFRoaXMgZmlsZSBtdXN0IGJlIGNvbnZlcnRlZCB3aXRoIEJpbkhleCA0LjApCjoiKDBoLE1OITYmKkE0ZGUlOHBGIiEhISEhTUIhTiE0Zjk4ZSUhIlsqJHIiSiokciJKISIkKiRyImojIiIqIiohISEkKiRyImIjIiIqISEqZCJKIUhlaSRyIkohIiQqJHIiaiMiIiokMGgsOg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4626 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4044675396 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561f14b19810, 0x561f14d0301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561f14d03020,0x561f16b9b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0362638ff395479cd7710aeddaa95f86f6c74c08' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5789 processed earlier; will process 5240 files now Step #5: ==166612== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561f0b60e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561f11c73898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561f11c565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561f11c564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561f0b614d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561f0b575b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561f0b570355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561f0b606c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561f0e5d5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561f0e5d5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561f0e5d5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561f0e5d5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561f0e5d5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561f0e5d5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561f0e5d5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561f0e5d5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561f0e5d5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561f0e5d5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561f1086af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561f0d597b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561f0d5a2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561f0d34ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561f0d34ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561f0d34f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561f0d34e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561f0d34e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561f0d34e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561f11c58abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561f11c61928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561f11c49699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561f11c74112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f50f9cb4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561f0b56eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x4,0x33,0x3,0x0,0x0,0x45,0x30,0x50,0x55,0x53,0x4c,0x54,0x0,0x0,0x20,0x0,0x71,0x70,0x78,0x60,0x74,0x6d,0x21,0x60,0x33,0x50,0x55,0x53,0x4c,0x32,0x54,0x0,0x0,0x0,0x5,0x20,0x0,0x6c,0x6f,0x63,0x61,0x73,0x74,0x72,0x79,0x20,0x28,0x71,0x0,0x0,0x1,0x48,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x46,0x3e,0x3a,0x27,0x54,0x0,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x0,0xff,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0xa,0x2d,0x2d,0x2d,0x2e,0x50,0xa,0x2d,0xa,0x2d,0xa,0xa,0x55,0xb2,0xff,0x20,0x58,0x0,0x0, Step #5: I\0043\003\000\000E0PUSLT\000\000 \000qpx`tm!`3PUSL2T\000\000\000\005 \000locastry (q\000\000\001H~~~~~~~~~~~~~~~~~~~~~~~\001HTXX\000\000\001HTXX\000\000\001HF>:'T\000TXX\000\000\001HTX\000\377XX\000\000\001HTXX\000\000\001HTXX\000\000\001~~~~~~~\012---.P\012-\012-\012\012U\262\377 X\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bbbec0a833cde033cc25988f261610dc0e25a0c2 Step #5: Base64: SQQzAwAARTBQVVNMVAAAIABxcHhgdG0hYDNQVVNMMlQAAAAFIABsb2Nhc3RyeSAocQAAAUh+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fgFIVFhYAAABSFRYWAAAAUhGPjonVABUWFgAAAFIVFgA/1hYAAABSFRYWAAAAUhUWFgAAAF+fn5+fn5+Ci0tLS5QCi0KLQoKVbL/IFgAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4627 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4045304637 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5584ed0a5810, 0x5584ed28f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5584ed28f020,0x5584ef1270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bbbec0a833cde033cc25988f261610dc0e25a0c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5790 processed earlier; will process 5239 files now Step #5: ==166648== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5584e3b9a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5584ea1ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5584ea1e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5584ea1e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5584e3ba0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5584e3b01b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5584e3afc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5584e3b92c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5584e6b61f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5584e6b61f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5584e6b61f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5584e6b61f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5584e6b61f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5584e6b61f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5584e6b61f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5584e6b61f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5584e6b61f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5584e6b61f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5584e8df6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5584e5b23b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5584e5b2ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5584e58dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5584e58dac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5584e58db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5584e58da874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5584e58da874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5584e58da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5584ea1e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5584ea1ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5584ea1d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5584ea200112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f410eabf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5584e3afab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x2d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x2d,0x2d,0xa,0x44,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x3f, Step #5: s-----BEG-'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''---\012D\012-\012d\012d\012? Step #5: artifact_prefix='./'; Test unit written to ./oom-b0e908aeffc3bbd1c8a07990757aad32c9e82124 Step #5: Base64: cy0tLS0tQkVHLScnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnLS0tCkQKLQpkCmQKPw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4628 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4045817267 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d8f9dc810, 0x561d8fbc601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d8fbc6020,0x561d91a5e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b0e908aeffc3bbd1c8a07990757aad32c9e82124' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5791 processed earlier; will process 5238 files now Step #5: #1 pulse cov: 4506 ft: 4507 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4981 ft: 5354 exec/s: 0 rss: 179Mb Step #5: ==166684== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d864d19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d8cb36898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d8cb195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d8cb194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d864d7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d86438b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d86433355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d864c9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d89498f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d89498f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d89498f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d89498f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d89498f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d89498f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d89498f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d89498f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d89498f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d89498f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d8b72df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d8845ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d88465be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d88211c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d88211c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d88212738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d88211874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d88211874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d88211874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d8cb1babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d8cb24928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d8cb0c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d8cb37112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc06598082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d86431b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x68,0x74,0x74,0x70,0x3a,0x7b,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0x2e,0x68,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0x2e,0x68,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x2e,0x68,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94, Step #5: \016http:{\315\204\315\204\315\224\315\204\315\204\315\204\315\224\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\224\315\204\315\204.h\315\204\315\204\315\204\315\204\315\204\315\224\315\204\315\204\315\204\315\224\315\204\315\204\315\204\315\204\315\204\315\224\315\204\315\204.h\315\204\315\204\315\204\315\204\315\204\315\224\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204.h\315\204\315\204\315\204\315\204\315\224\315\204\315\204\315\204\315\224\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\224 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb813c481fbf05da1e47e4aa33c15e2fec2b3a88 Step #5: Base64: Dmh0dHA6e82EzYTNlM2EzYTNhM2UzYTNhM2EzYTNhM2EzYTNhM2UzYTNhC5ozYTNhM2EzYTNhM2UzYTNhM2EzZTNhM2EzYTNhM2EzZTNhM2ELmjNhM2EzYTNhM2EzZTNhM2EzYTNhM2EzYTNhM2EzYTNhM2ELmjNhM2EzYTNhM2UzYTNhM2EzZTNhM2EzYTNhM2EzYTNhM2EzZQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4629 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4046403749 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56301f1a3810, 0x56301f38d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56301f38d020,0x5630212250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb813c481fbf05da1e47e4aa33c15e2fec2b3a88' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5794 processed earlier; will process 5235 files now Step #5: #1 pulse cov: 3693 ft: 3694 exec/s: 0 rss: 176Mb Step #5: ==166720== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563015c989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56301c2fd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56301c2e05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56301c2e04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563015c9ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563015bffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563015bfa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563015c90c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563018c5ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563018c5ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563018c5ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563018c5ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563018c5ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563018c5ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563018c5ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563018c5ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563018c5ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563018c5ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56301aef4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563017c21b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563017c2cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5630179d8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5630179d8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5630179d9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5630179d8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5630179d8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5630179d8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56301c2e2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56301c2eb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56301c2d3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56301c2fe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4404769082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563015bf8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x30,0x4f,0x46,0x77,0x48,0x65,0x57,0x53,0x63,0x6f,0x41,0x61,0x71,0x59,0x6d,0x2b,0x6a,0x35,0x47,0x4c,0x6c,0x43,0x41,0x41,0x42,0x73,0x54,0x2b,0x4c,0x51,0x58,0x49,0x53,0x7a,0x56,0x77,0x6a,0x77,0x6f,0x30,0x56,0x45,0xa,0x66,0x61,0x6d,0x69,0x6c,0x79,0x20,0x22,0x20,0x1f,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x1f,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x1f,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27, Step #5: onion-key v0OFwHeWScoAaqYm+j5GLlCAABsT+LQXISzVwjwo0VE\012family \" \037 + \037 ' + \037 ' + \037 ' \037 + \037 ' + \037 ' + \037 ' +' + \037 ' + \037 ' \037 + \037 ' + \037 ' + \037 ' + \037 ' + \037 ' + \037 ' Step #5: artifact_prefix='./'; Test unit written to ./oom-06a46528042244e8ac054a2023dd4abfcb0de06b Step #5: Base64: b25pb24ta2V5IHYwT0Z3SGVXU2NvQWFxWW0rajVHTGxDQUFCc1QrTFFYSVN6Vndqd28wVkUKZmFtaWx5ICIgHyArIB8gJyArIB8gJyArIB8gJyAfICsgHyAnICsgHyAnICsgHyAnICsnICsgHyAnICsgHyAnIB8gKyAfICcgKyAfICcgKyAfICcgKyAfICcgKyAfICcgKyAfICc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4630 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4046951242 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557a6fd6c810, 0x557a6ff5601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557a6ff56020,0x557a71dee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/06a46528042244e8ac054a2023dd4abfcb0de06b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5796 processed earlier; will process 5233 files now Step #5: ==166756== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557a668619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557a6cec6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557a6cea95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557a6cea94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557a66867d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557a667c8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557a667c3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557a66859c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557a69828f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557a69828f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557a69828f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557a69828f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557a69828f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557a69828f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557a69828f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557a69828f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557a69828f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557a69828f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557a6babdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557a687eab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557a687f5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557a685a1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557a685a1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557a685a2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557a685a1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557a685a1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557a685a1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557a6ceababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557a6ceb4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557a6ce9c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557a6cec7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8568332082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557a667c1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3,0x2f,0x47,0x47,0x47,0x2f,0x7f,0x2f,0x20,0x75,0xa,0x2e,0x47,0x47,0x47,0x2f,0x44,0x2f,0x20,0x6f,0xa,0x2e,0x47,0x47,0x47,0x2f,0x47,0x2f,0x20,0x6f,0xa,0x2e,0x47,0x47,0x47,0x2f,0x4f,0x2f,0x20,0x6f,0xa,0x2e,0x47,0x47,0x47,0x2f,0x60,0x47,0x2f,0x20,0x70,0xa,0x2f,0x47,0x47,0x47,0x2f,0x7a,0x2f,0x20,0x6f,0xa,0x2e,0x47,0x47,0x47,0x2f,0x23,0x2f,0x20,0x6f,0xa,0x2e,0x47,0x47,0x47,0x2f,0x3,0x2f,0x20,0x6f,0xa,0x2e,0x47,0x47,0x47,0x2f,0x39,0x2f,0x20,0x6f,0xa,0x2f,0x47,0x47,0x47,0x2f,0x38,0x2f,0x20,0x6f,0xa,0x2e,0x47,0x47,0x47,0x2f,0x30,0x2f,0x20,0x70,0xa,0x2f,0x47,0x47,0x47,0x2f,0x60,0x2f,0x20,0x2f,0xa,0x2e,0x47,0x47,0x47,0x2f,0x2d,0x2f,0x20,0x6f,0xa,0x2e,0x47,0x47,0x47,0x2f,0x3b,0x2f,0x20,0x6f,0xa,0x2f,0x47,0x47,0x47,0x2f,0x3d,0x2f,0x20,0x6f,0xde,0xad,0xbe,0xef, Step #5: \003/GGG/\177/ u\012.GGG/D/ o\012.GGG/G/ o\012.GGG/O/ o\012.GGG/`G/ p\012/GGG/z/ o\012.GGG/#/ o\012.GGG/\003/ o\012.GGG/9/ o\012/GGG/8/ o\012.GGG/0/ p\012/GGG/`/ /\012.GGG/-/ o\012.GGG/;/ o\012/GGG/=/ o\336\255\276\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-9f7b2e65d2dbc0d281dc2ac8008fb18fd50e7005 Step #5: Base64: Ay9HR0cvfy8gdQouR0dHL0QvIG8KLkdHRy9HLyBvCi5HR0cvTy8gbwouR0dHL2BHLyBwCi9HR0cvei8gbwouR0dHLyMvIG8KLkdHRy8DLyBvCi5HR0cvOS8gbwovR0dHLzgvIG8KLkdHRy8wLyBwCi9HR0cvYC8gLwouR0dHLy0vIG8KLkdHRy87LyBvCi9HR0cvPS8gb96tvu8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4631 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4047588591 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5642af228810, 0x5642af41201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5642af412020,0x5642b12aa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f7b2e65d2dbc0d281dc2ac8008fb18fd50e7005' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5797 processed earlier; will process 5232 files now Step #5: ==166792== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5642a5d1d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5642ac382898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5642ac3655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5642ac3654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642a5d23d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5642a5c84b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5642a5c7f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5642a5d15c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5642a8ce4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5642a8ce4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5642a8ce4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5642a8ce4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5642a8ce4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5642a8ce4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5642a8ce4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5642a8ce4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5642a8ce4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5642a8ce4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5642aaf79f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5642a7ca6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5642a7cb1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5642a7a5dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5642a7a5dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5642a7a5e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5642a7a5d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5642a7a5d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5642a7a5d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5642ac367abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5642ac370928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5642ac358699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5642ac383112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff3c2508082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5642a5c7db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x11,0x0,0x24,0x2e,0x0,0x5,0x5,0x5,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x20,0x22,0x22,0x22,0x22,0x22,0x22,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x22,0x5,0xd2,0x84,0x5,0x5,0x5,0x5,0x24,0x3d, Step #5: \021\000$.\000\005\005\005\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\" \"\"\"\"\"\";;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;\"\"\"\"\"\"\"\"\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000#\000\000\000\000\000\000\000\000\000\000\"\005\322\204\005\005\005\005$= Step #5: artifact_prefix='./'; Test unit written to ./oom-5e96dad171add5a63d768abee40e5cab991e5463 Step #5: Base64: EQAkLgAFBQUiIiIiIiIiIiIiIiIiIiIiIiIiICIiIiIiIjs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7IiIiIiIiIiIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAjAAAAAAAAAAAAACIF0oQFBQUFJD0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4632 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4048114537 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565324df8810, 0x565324fe201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565324fe2020,0x565326e7a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e96dad171add5a63d768abee40e5cab991e5463' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5798 processed earlier; will process 5231 files now Step #5: ==166828== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56531b8ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565321f52898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565321f355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565321f354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56531b8f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56531b854b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56531b84f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56531b8e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56531e8b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56531e8b4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56531e8b4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56531e8b4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56531e8b4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56531e8b4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56531e8b4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56531e8b4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56531e8b4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56531e8b4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565320b49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56531d876b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56531d881be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56531d62dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56531d62dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56531d62e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56531d62d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56531d62d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56531d62d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565321f37abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565321f40928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565321f28699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565321f53112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6eb497e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56531b84db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0x5e,0x0,0x0,0x0,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x13,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0x73,0x65,0x66,0x3d,0xa,0x63,0x6f,0x66,0x66,0x65,0x65,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x10,0xff, Step #5: \005----BEGIN =^\000\000\000\012\012r=sef=\012=+=\012=\012=\012= =\012= i\012\012r\023sef=\012=+=\012=\012=\012= =\012= i\012\012r=sef=\012=+=\012=\012=\012= =sef=\012coffee=\012= =\012=+=\012=\012=\012= =\012= i\012r=sef=\012=+=\012=\012=\012= =\012= i\012\012r=\012=\012D\012=\012=\012=\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-ece39f315043d09da15ca7ee7bf709b55910368b Step #5: Base64: BS0tLS1CRUdJTiA9XgAAAAoKcj1zZWY9Cj0rPQo9Cj0KPSA9Cj0gaQoKchNzZWY9Cj0rPQo9Cj0KPSA9Cj0gaQoKcj1zZWY9Cj0rPQo9Cj0KPSA9c2VmPQpjb2ZmZWU9Cj0gPQo9Kz0KPQo9Cj0gPQo9IGkKcj1zZWY9Cj0rPQo9Cj0KPSA9Cj0gaQoKcj0KPQpECj0KPQo9EP8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4633 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4048642381 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb12e96810, 0x55bb1308001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb13080020,0x55bb14f180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ece39f315043d09da15ca7ee7bf709b55910368b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5799 processed earlier; will process 5230 files now Step #5: ==166864== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bb0998b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb0fff0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb0ffd35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb0ffd34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb09991d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb098f2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb098ed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb09983c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb0c952f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb0c952f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb0c952f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb0c952f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb0c952f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb0c952f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb0c952f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb0c952f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb0c952f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb0c952f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb0ebe7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb0b914b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb0b91fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb0b6cbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb0b6cbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb0b6cc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb0b6cb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb0b6cb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb0b6cb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb0ffd5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb0ffde928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb0ffc6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb0fff1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9d0dffd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb098ebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0xa,0x3d,0xcc,0xbb,0x2b,0x41,0x2d,0x2d,0x2d,0x42,0x73,0x63,0x65,0xa,0x2d,0x3f,0x41,0x73,0x63,0x65,0x7a,0x74,0x7a,0x74,0x20,0x6a,0x2d,0x2d,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x2d,0x2d,0x2f,0x2d,0x6d,0x2d,0x42,0x45,0x1,0x0,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3a,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xe,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x49,0x44,0x34,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x1, Step #5: 0\012=\314\273+A---Bsce\012-?Asceztzt j---\012=\012=\012=\012=\012\000--/-m-BE\001\000\000=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=:\012=\012=\012=\012=\012=\012=\012=\016=\012=\012=\012=\012=\012=\012=\012=\012=\012\000ID4\002-\001\000\000\000\000ID3\002-\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-f890cd55a182dcb61be22eb9100990cebaf122c2 Step #5: Base64: MAo9zLsrQS0tLUJzY2UKLT9Bc2NlenR6dCBqLS0tCj0KPQo9Cj0KAC0tLy1tLUJFAQAAPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj06Cj0KPQo9Cj0KPQo9Cj0OPQo9Cj0KPQo9Cj0KPQo9Cj0KAElENAItAQAAAABJRDMCLQE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4634 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4049179599 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5592c5a16810, 0x5592c5c0001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5592c5c00020,0x5592c7a980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f890cd55a182dcb61be22eb9100990cebaf122c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5800 processed earlier; will process 5229 files now Step #5: ==166900== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5592bc50b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5592c2b70898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5592c2b535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5592c2b534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592bc511d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592bc472b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592bc46d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592bc503c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592bf4d2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592bf4d2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592bf4d2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592bf4d2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592bf4d2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592bf4d2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592bf4d2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592bf4d2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592bf4d2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592bf4d2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592c1767f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592be494b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592be49fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5592be24bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5592be24bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5592be24c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5592be24b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5592be24b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5592be24b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5592c2b55abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5592c2b5e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5592c2b46699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5592c2b71112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc19ff00082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592bc46bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x4a,0x9,0x12,0xa,0x5c,0x9,0x29,0xa,0x5c,0x9,0x29,0xa,0x5c,0x9,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x63,0x72,0x79,0x73,0x74,0x61,0x6c,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x60,0x40,0x60,0x40,0x5c,0x9,0x60,0x40,0x60,0x40, Step #5: +J\011\022\012\\\011)\012\\\011)\012\\\011DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD\001\000\000\000\000\000\000\000DDDDDDDDDDDDDDDDDDcrystalDDDDDDDDDDDDDDDD`@`@\\\011`@`@ Step #5: artifact_prefix='./'; Test unit written to ./oom-cc719162f401f9d203592d7ae393004141819041 Step #5: Base64: K0oJEgpcCSkKXAkpClwJREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREAQAAAAAAAABERERERERERERERERERERERERjcnlzdGFsRERERERERERERERERERERGBAYEBcCWBAYEA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4635 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4049806606 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d9872b9810, 0x55d9874a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d9874a3020,0x55d98933b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cc719162f401f9d203592d7ae393004141819041' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5801 processed earlier; will process 5228 files now Step #5: ==166936== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d97ddae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d984413898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d9843f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d9843f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d97ddb4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d97dd15b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d97dd10355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d97dda6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d980d75f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d980d75f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d980d75f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d980d75f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d980d75f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d980d75f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d980d75f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d980d75f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d980d75f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d980d75f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d98300af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d97fd37b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d97fd42be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d97faeec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d97faeec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d97faef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d97faee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d97faee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d97faee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d9843f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d984401928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d9843e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d984414112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2dd606d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d97dd0eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x21,0x0,0x2d,0x0,0x0,0x0,0x4c,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x5b,0x2d,0x2d,0xa,0x44,0x0,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x43,0x46,0x46,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x43,0x46,0x46,0x20,0x5b,0x2d,0x2d,0xa,0x44,0xa,0x2d,0xa,0x49,0x74,0x20,0x5b,0x2d,0x2d,0xa,0x44,0xa,0x2d,0xa,0x49,0x74,0x68,0xa,0x2d,0xa,0x64,0x2d,0x49,0x4e,0x20,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x43,0x46,0x46,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x43,0x46,0x46,0x20,0x5b,0x2d,0x2d,0xa,0x44,0xa,0x2d,0x32,0x49,0x74,0x20,0x5b,0x2d,0x2d,0xa,0x44,0xa,0x2d,0xa,0x49,0x74,0x68,0xa,0x2d,0xa,0x64,0x2d,0x2d,0x5b,0x2d,0x2d,0xa,0x44,0xa,0x2d,0xa,0x4b,0x74,0x68,0xa,0xa,0x44,0xa,0x2d,0xa,0x4b,0x74,0x68,0xa,0x2d,0xa,0x64,0xa,0x64, Step #5: !!\000-\000\000\000LEGIN --[--\012D\000----BEGIN EGIN --CFFGIN --CFF [--\012D\012-\012It [--\012D\012-\012Ith\012-\012d-IN EGIN --CFFGIN --CFF [--\012D\012-2It [--\012D\012-\012Ith\012-\012d--[--\012D\012-\012Kth\012\012D\012-\012Kth\012-\012d\012d Step #5: artifact_prefix='./'; Test unit written to ./oom-2f04bc587abab6eb0062f01bfc6db80eade009e6 Step #5: Base64: ISEALQAAAExFR0lOIC0tWy0tCkQALS0tLUJFR0lOIEVHSU4gLS1DRkZHSU4gLS1DRkYgWy0tCkQKLQpJdCBbLS0KRAotCkl0aAotCmQtSU4gRUdJTiAtLUNGRkdJTiAtLUNGRiBbLS0KRAotMkl0IFstLQpECi0KSXRoCi0KZC0tWy0tCkQKLQpLdGgKCkQKLQpLdGgKLQpkCmQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4636 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4050327712 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f342151810, 0x55f34233b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f34233b020,0x55f3441d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f04bc587abab6eb0062f01bfc6db80eade009e6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5802 processed earlier; will process 5227 files now Step #5: ==166972== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f338c469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f33f2ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f33f28e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f33f28e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f338c4cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f338badb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f338ba8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f338c3ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f33bc0df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f33bc0df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f33bc0df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f33bc0df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f33bc0df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f33bc0df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f33bc0df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f33bc0df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f33bc0df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f33bc0df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f33dea2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f33abcfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f33abdabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f33a986c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f33a986c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f33a987738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f33a986874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f33a986874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f33a986874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f33f290abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f33f299928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f33f281699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f33f2ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f02aa235082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f338ba6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x53,0x3e,0x3c,0x73,0x6c,0x3a,0x73,0x74,0x61,0x6e,0x64,0x42,0x65,0x73,0x74,0x61,0x4e,0x64,0x3e,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x73,0x74,0x61,0x6e,0x64,0x6c,0x65,0x76,0x65,0x72,0x69,0x6e,0x67,0x2d,0x67,0x65,0x6e,0x65,0x72,0x69,0x65,0x6b,0x2f,0x31,0x2e,0x30,0x3c,0x73,0x6c,0x2d,0x62,0x63,0x67,0x3e,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x6c,0x76,0x62,0x61,0x67,0x2f,0x65,0x78,0x74,0x72,0x61,0x63,0x74,0x2d,0x64,0x65,0x65,0x6c,0x62,0x65,0x73,0x74,0x61,0x6e,0x64,0x2d,0x6c,0x76,0x63,0x2f,0x76,0x32,0x30,0x32,0x30,0x30,0x36,0x30,0x31, Step #5: <S><sl:standBestaNd>http://www.kadaster.nl/schemas/standlevering-generiek/1.0<sl-bcg>http://www.kadaster.nl/schemas/lvbag/extract-deelbestand-lvc/v20200601 Step #5: artifact_prefix='./'; Test unit written to ./oom-008346dc918ab7e0b611ddc5a6d1a62684fd21c7 Step #5: Base64: PFM+PHNsOnN0YW5kQmVzdGFOZD5odHRwOi8vd3d3LmthZGFzdGVyLm5sL3NjaGVtYXMvc3RhbmRsZXZlcmluZy1nZW5lcmllay8xLjA8c2wtYmNnPmh0dHA6Ly93d3cua2FkYXN0ZXIubmwvc2NoZW1hcy9sdmJhZy9leHRyYWN0LWRlZWxiZXN0YW5kLWx2Yy92MjAyMDA2MDE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4637 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4050835245 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b8b171810, 0x560b8b35b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b8b35b020,0x560b8d1f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/008346dc918ab7e0b611ddc5a6d1a62684fd21c7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5803 processed earlier; will process 5226 files now Step #5: ==167008== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560b81c669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b882cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b882ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b882ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b81c6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b81bcdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b81bc8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b81c5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b84c2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b84c2df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b84c2df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b84c2df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b84c2df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b84c2df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b84c2df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b84c2df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b84c2df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b84c2df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b86ec2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b83befb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b83bfabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b839a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b839a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b839a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b839a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b839a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b839a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b882b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b882b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b882a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b882cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f02bbd31082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b81bc6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x4a,0x2e,0x9,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x36,0xa,0x7d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x5c,0xa,0x5c,0x9,0x29,0xa,0x5c,0x9,0xa4,0xa,0x5c,0x9,0x60,0x40,0x60,0xff,0x68,0x9,0x60,0x40,0x60,0x40, Step #5: +J.\011\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012-\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\0126\012}\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\\\012\\\011)\012\\\011\244\012\\\011`@`\377h\011`@`@ Step #5: artifact_prefix='./'; Test unit written to ./oom-4986356cffc9813a4470fec6d5c0d8b1b28d4143 Step #5: Base64: K0ouCQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQotCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KCj0KPQo9CjYKfQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQpcClwJKQpcCaQKXAlgQGD/aAlgQGBA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4638 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4051364673 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ace1d2a810, 0x55ace1f1401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ace1f14020,0x55ace3dac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4986356cffc9813a4470fec6d5c0d8b1b28d4143' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5804 processed earlier; will process 5225 files now Step #5: #1 pulse cov: 12906 ft: 12907 exec/s: 0 rss: 197Mb Step #5: ==167044== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55acd881f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55acdee84898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55acdee675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55acdee674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55acd8825d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55acd8786b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55acd8781355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55acd8817c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55acdb7e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55acdb7e6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55acdb7e6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55acdb7e6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55acdb7e6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55acdb7e6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55acdb7e6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55acdb7e6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55acdb7e6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55acdb7e6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55acdda7bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55acda7a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55acda7b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55acda55fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55acda55fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55acda560738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55acda55f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55acda55f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55acda55f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55acdee69abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55acdee72928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55acdee5a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55acdee85112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fca3f155082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55acd877fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x2d,0x20,0x4a,0xa,0x2d,0x20,0x4b,0xa,0x2d,0x20,0x2b,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x25,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2c,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x6d,0xa,0x2d,0x20,0x2c,0xa,0x2d,0x20,0x2d,0xde,0xad,0xbe,0xef, Step #5: \002- J\012- K\012- +\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- %\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- -\012- ,\012- -\012- -\012- m\012- ,\012- -\336\255\276\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-bea593480ea54ce05ceb74ad34bffcccaa8ab9b0 Step #5: Base64: Ai0gSgotIEsKLSArCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gJQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAtCi0gLQotIC0KLSAsCi0gLQotIC0KLSBtCi0gLAotIC3erb7v Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4639 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4052018807 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563398830810, 0x563398a1a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563398a1a020,0x56339a8b20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bea593480ea54ce05ceb74ad34bffcccaa8ab9b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5806 processed earlier; will process 5223 files now Step #5: #1 pulse cov: 3808 ft: 3809 exec/s: 0 rss: 177Mb Step #5: ==167080== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56338f3259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56339598a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56339596d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56339596d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56338f32bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56338f28cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56338f287355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56338f31dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5633922ecf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5633922ecf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5633922ecf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5633922ecf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5633922ecf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5633922ecf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5633922ecf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5633922ecf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5633922ecf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5633922ecf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563394581f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5633912aeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5633912b9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563391065c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563391065c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563391066738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563391065874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563391065874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563391065874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56339596fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563395978928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563395960699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56339598b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb077bf3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56338f285b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x8,0x0,0x0,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012-\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\010\000\000\000\012=\012=\012=\012=\012=\012\012=\012=\012=\012\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-92d1aaeffa4e1337b2aa0e89578b2fbf011f0427 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KLQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQgAAAAKPQo9Cj0KPQo9Cgo9Cj0KPQoKPT0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4640 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4052593598 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55985b4ac810, 0x55985b69601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55985b696020,0x55985d52e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92d1aaeffa4e1337b2aa0e89578b2fbf011f0427' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5808 processed earlier; will process 5221 files now Step #5: ==167116== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559851fa19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559858606898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5598585e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5598585e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559851fa7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559851f08b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559851f03355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559851f99c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559854f68f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559854f68f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559854f68f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559854f68f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559854f68f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559854f68f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559854f68f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559854f68f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559854f68f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559854f68f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5598571fdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559853f2ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559853f35be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559853ce1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559853ce1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559853ce2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559853ce1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559853ce1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559853ce1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5598585ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5598585f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5598585dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559858607112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f90cd0be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559851f01b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2c,0x2b,0xb,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0xa,0xa,0x2b,0xb,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2b,0x2b,0xa,0x2b,0xa,0x2b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2b,0xa,0x2b,0x73,0x73,0x73,0x73,0x73,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0xee,0x2b,0xa,0x2e,0x2b,0x2b,0x2b,0xa,0x2b,0xdf, Step #5: +\012+\012+\012,+\013\012+\012+\012+\012+\012\012\012+\013\000\000\000\000\000\000\000++\012+\012+\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012+\012+ssssss\012+\012+\012+\012+\012+s\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012\012+\012+\356+\012.+++\012+\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-fc3cad945dbec97ad02f0c0bc47f275fbfbd39de Step #5: Base64: KworCisKLCsLCisKKworCisKCgorCwAAAAAAAAArKworCisAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAorCitzc3Nzc3MKKworCisKKworcworCisKKworCisKKworCisKKworCgorCivuKwouKysrCivf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4641 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4053135567 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b6f8d5810, 0x560b6fabf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b6fabf020,0x560b719570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc3cad945dbec97ad02f0c0bc47f275fbfbd39de' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5809 processed earlier; will process 5220 files now Step #5: ==167152== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560b663ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b6ca2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b6ca125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b6ca124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b663d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b66331b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b6632c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b663c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b69391f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b69391f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b69391f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b69391f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b69391f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b69391f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b69391f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b69391f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b69391f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b69391f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b6b626f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b68353b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b6835ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b6810ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b6810ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b6810b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b6810a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b6810a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b6810a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b6ca14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b6ca1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b6ca05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b6ca30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b6e492082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b6632ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xb,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2e,0x2e,0x2e,0x2e,0x2e,0x33,0x2,0x6b,0x6,0x65,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x73,0x65,0x46,0x6f,0x6e,0x74,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x33,0x2,0x6b,0x6,0x65,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x33,0x20,0x20,0x20,0x2,0x6b,0x6,0x60,0x65,0xdf,0xb4,0xfb,0xff,0x44,0xa,0x9,0x6b,0xff, Step #5: `\000\000\000\000\000\000\000\013\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000.....3\002k\006e\000\000\000\000\000\000\000\000\000\000\000\000\000seFont\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000......3\002k\006e\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000................3 \002k\006`e\337\264\373\377D\012\011k\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-73b21451390f619642937650bf3d19b3860cfe83 Step #5: Base64: YAAAAAAAAAALAAAAAAAAAAAAAAAAAAAALi4uLi4zAmsGZQAAAAAAAAAAAAAAAABzZUZvbnQAAAAAAAAAAAAAAAAAAAAAAAAAAAAALi4uLi4uMwJrBmUAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAuLi4uLi4uLi4uLi4uLi4uMyAgIAJrBmBl37T7/0QKCWv/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4642 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4053768481 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e10c626810, 0x55e10c81001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e10c810020,0x55e10e6a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/73b21451390f619642937650bf3d19b3860cfe83' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5810 processed earlier; will process 5219 files now Step #5: #1 pulse cov: 3656 ft: 3657 exec/s: 0 rss: 176Mb Step #5: ==167188== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e10311b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e109780898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e1097635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e1097634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e103121d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e103082b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e10307d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e103113c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e1060e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e1060e2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e1060e2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e1060e2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e1060e2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e1060e2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e1060e2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e1060e2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e1060e2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e1060e2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e108377f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e1050a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e1050afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e104e5bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e104e5bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e104e5c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e104e5b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e104e5b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e104e5b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e109765abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e10976e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e109756699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e109781112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12a3559082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e10307bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x88,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x6c,0x0,0x0,0x0,0x0,0xb,0x0,0x60,0xa,0xa,0x31,0x2f,0x60,0xa,0x20,0x20,0x60,0xe2,0x88,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0xb,0x2d,0x0,0x2d,0xa,0x5,0x60,0x2d,0x2d,0x2d,0x42,0x45,0xa,0x31,0x2f,0x60,0xa,0x20,0x20,0x47,0x49,0x4e,0x20,0x3d,0x5e,0x0,0x0,0x0,0x8,0xa,0x66,0x3d,0x72,0x3d,0x73,0x65,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x60,0x20,0x60,0xa,0x9,0x3d,0x20,0x3d,0xa,0x83,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0xff,0x60,0x20,0x60,0xa,0x9, Step #5: `\342\210\210-\000`\012\363\240\201\272/\012`\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000l\000\000\000\000\013\000`\012\0121/`\012 `\342\210\210-\000`\012\363\240\201\272/\012`\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000\000\000\000\000\000\013-\000-\012\005`---BE\0121/`\012 GIN =^\000\000\000\010\012f=r=se\012=+=\012=\012=\012` `\012\011= =\012\203\000\000\000\000\000\000\000\020\377` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7464bd76a2b9b3160dab0e167e8d7b05aa1cb8c Step #5: Base64: YOKIiC0AYArzoIG6Lwpg4oCILQBgCvOggbrzoIG6LwEAbAAAAAALAGAKCjEvYAogIGDiiIgtAGAK86CBui8KYOKAiC0AYArzoIG686CBui8BAAAAAAAACy0ALQoFYC0tLUJFCjEvYAogIEdJTiA9XgAAAAgKZj1yPXNlCj0rPQo9Cj0KYCBgCgk9ID0KgwAAAAAAAAAQ/2AgYAoJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4643 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4054461839 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a23d27810, 0x558a23f1101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a23f11020,0x558a25da90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7464bd76a2b9b3160dab0e167e8d7b05aa1cb8c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5812 processed earlier; will process 5217 files now Step #5: ==167224== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558a1a81c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a20e81898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a20e645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a20e644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a1a822d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a1a783b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a1a77e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a1a814c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a1d7e3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a1d7e3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a1d7e3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a1d7e3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a1d7e3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a1d7e3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a1d7e3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a1d7e3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a1d7e3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a1d7e3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a1fa78f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a1c7a5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a1c7b0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a1c55cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a1c55cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a1c55d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a1c55c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a1c55c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a1c55c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a20e66abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a20e6f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a20e57699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a20e82112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a7227f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a1a77cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xd,0x48,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xd,0x25,0x20,0x78,0x78,0x20,0x27,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0x20,0x6a,0x9,0x64,0xd,0x49,0x44,0x52,0x45,0x46,0x53,0x9,0x22,0x9,0x68,0x55,0x3a,0x42,0x20,0xe8,0xb9,0x81,0x31,0x64,0xef,0xb7,0xba,0x64,0xc5,0xb2,0x3a,0x20,0xe8,0xb9,0x81,0x36,0x30,0x22,0x3e,0x27,0x3e,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x70,0x3b,0x25,0x78,0x78,0x3b,0x25,0x30,0x78, Step #5: <!DOCTYPE\015H[<!ENTITY\015% xx '<!ATTLIST j\011d\015IDREFS\011\"\011hU:B \350\271\2011d\357\267\272d\305\262: \350\271\20160\">'>%xx;%xx;%xx;%xx;%xx;%xx;%x;%xx;%xx;%xx;%xx;%x;%xx;%xx;%x;%xx;%xx;%xx;%p;%xx;%0x Step #5: artifact_prefix='./'; Test unit written to ./oom-93127f239db7c1f3d6d3ae644f6f941c1a43035e Step #5: Base64: PCFET0NUWVBFDUhbPCFFTlRJVFkNJSB4eCAnPCFBVFRMSVNUIGoJZA1JRFJFRlMJIgloVTpCIOi5gTFk77e6ZMWyOiDouYE2MCI+Jz4leHg7JXh4OyV4eDsleHg7JXh4OyV4eDsleDsleHg7JXh4OyV4eDsleHg7JXg7JXh4OyV4eDsleDsleHg7JXh4OyV4eDslcDsleHg7JTB4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4644 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4054978824 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611ace63810, 0x5611ad04d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5611ad04d020,0x5611aeee50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93127f239db7c1f3d6d3ae644f6f941c1a43035e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5813 processed earlier; will process 5216 files now Step #5: ==167260== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5611a39589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5611a9fbd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611a9fa05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611a9fa04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5611a395ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5611a38bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5611a38ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5611a3950c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5611a691ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5611a691ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5611a691ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5611a691ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5611a691ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5611a691ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5611a691ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5611a691ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5611a691ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5611a691ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5611a8bb4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611a58e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5611a58ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611a5698c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611a5698c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611a5699738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611a5698874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611a5698874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611a5698874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5611a9fa2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5611a9fab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611a9f93699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5611a9fbe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f55a03a9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5611a38b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x9f,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x95,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xe3,0x8c,0x96,0xef,0xbc,0x8e,0xef,0xbc,0x8e,0xef,0xbc,0x8e,0xef,0xbc,0x8e,0xef,0xbc,0x8e,0xef,0xbc,0x8e,0xef,0xbc,0x8e,0xef,0xbc,0x8e, Step #5: ws:\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\237\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\226\343\214\225\343\214\226\343\214\226\343\214\226\343\214\226\357\274\216\357\274\216\357\274\216\357\274\216\357\274\216\357\274\216\357\274\216\357\274\216 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec70cd9e4082be22f945a992f6d67f82bbde1f8b Step #5: Base64: d3M644yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yf44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yW44yV44yW44yW44yW44yW77yO77yO77yO77yO77yO77yO77yO77yO Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4645 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4055489566 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e8ec35b810, 0x55e8ec54501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e8ec545020,0x55e8ee3dd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec70cd9e4082be22f945a992f6d67f82bbde1f8b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5814 processed earlier; will process 5215 files now Step #5: ==167296== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e8e2e509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e8e94b5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e8e94985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e8e94984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e8e2e56d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e8e2db7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e8e2db2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e8e2e48c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e8e5e17f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e8e5e17f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e8e5e17f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e8e5e17f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e8e5e17f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e8e5e17f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e8e5e17f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e8e5e17f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e8e5e17f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e8e5e17f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e8e80acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e8e4dd9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e8e4de4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e8e4b90c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e8e4b90c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e8e4b91738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e8e4b90874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e8e4b90874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e8e4b90874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e8e949aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e8e94a3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e8e948b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e8e94b6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd671e1d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e8e2db0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x22,0x20,0x24,0x3d,0x22,0x3c,0x22,0x20,0x72,0x3d,0x22,0x3c,0x22,0x20,0x72,0x3d,0x22,0x3c,0x22,0x20,0x72,0x3d,0x22,0x3c,0x22,0x20,0x72,0x3d,0x22,0x3c,0x22,0x20,0x72,0x3d,0x22,0x3c,0x22,0x20,0x24,0x3d,0x22,0x3c,0x22,0x20,0x72,0x3d,0x22,0x3c,0x22,0x20,0x72,0x3d,0x22,0x3c,0x22,0x20,0x72,0x3d,0x22,0x3c,0x22,0x20,0x72,0x3d,0x22,0x3c,0x22,0x20,0x72,0x3d,0x22,0x3c,0x22,0x20,0x72,0x65,0x6c,0x3d,0x26,0x67,0x74,0x20,0x72,0x65,0x6c,0x3d,0x26,0x67,0x74,0x20,0x72,0x65,0x6c,0x3d,0x26,0x67,0x74,0x20,0x72,0x65,0x6c,0x3d,0x26,0x67,0x74,0x20,0x72,0x65,0x6c,0x3d,0x26,0x67,0x74,0x20,0x72,0x65,0x6c,0x3d,0x26,0x67,0x74,0x20,0x72,0x65,0x6c,0x3d,0x26,0x67,0x74,0x20,0x72,0x65,0x6c,0x3d,0x26,0x67,0x74,0x20,0x72,0x65,0x6c,0x3d,0x26,0x67,0x74,0x20,0x72,0x65,0x6c,0x3d,0x26,0x67,0x74,0xd,0x86, Step #5: <\" $=\"<\" r=\"<\" r=\"<\" r=\"<\" r=\"<\" r=\"<\" $=\"<\" r=\"<\" r=\"<\" r=\"<\" r=\"<\" r=\"<\" rel=&gt rel=&gt rel=&gt rel=&gt rel=&gt rel=&gt rel=&gt rel=&gt rel=&gt rel=&gt\015\206 Step #5: artifact_prefix='./'; Test unit written to ./oom-4afd695671d70894d78aa6e49488fa52ad6f5ed6 Step #5: Base64: PCIgJD0iPCIgcj0iPCIgcj0iPCIgcj0iPCIgcj0iPCIgcj0iPCIgJD0iPCIgcj0iPCIgcj0iPCIgcj0iPCIgcj0iPCIgcj0iPCIgcmVsPSZndCByZWw9Jmd0IHJlbD0mZ3QgcmVsPSZndCByZWw9Jmd0IHJlbD0mZ3QgcmVsPSZndCByZWw9Jmd0IHJlbD0mZ3QgcmVsPSZndA2G Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4646 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4056003389 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55759ca4b810, 0x55759cc3501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55759cc35020,0x55759eacd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4afd695671d70894d78aa6e49488fa52ad6f5ed6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5815 processed earlier; will process 5214 files now Step #5: #1 pulse cov: 4091 ft: 4092 exec/s: 0 rss: 178Mb Step #5: ==167332== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5575935409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557599ba5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557599b885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557599b884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557593546d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5575934a7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5575934a2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557593538c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557596507f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557596507f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557596507f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557596507f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557596507f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557596507f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557596507f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557596507f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557596507f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557596507f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55759879cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5575954c9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5575954d4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557595280c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557595280c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557595281738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557595280874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557595280874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557595280874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557599b8aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557599b93928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557599b7b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557599ba6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd36a37a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5575934a0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x31,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x31,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x3a,0x11,0x2d,0xf,0x29,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x3a,0x24,0x2d,0x5b,0xee,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\000/\000\017\017\017\017\0171-\017[\017\0171-\017[1&1&\021:\021-\017\017\017\017\0171\021\0171\017s [8A\000\017\017\017\017\0171-\017[\017\0171-\017[1&1&\021:\021-\017\017\017\017\0171\021\0171\017s [8A\000\017\017\017\0171\017-1[&\021:\021:\021-\017)\017\017\017\0171\021\0171\017s [8A\000\017\017\017\0171\017-1[&\021:\021-\017\017\017\017\0171\021\0171\021-::$-[\356$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-7fcbaef4d2fe4693d749642beb299c0f5ce15c9c Step #5: Base64: JAAALwAAAC8AAC8ADw8PDw8xLQ9bDw8xLQ9bMSYxJhE6ES0PDw8PDzERDzEPcyBbOEEADw8PDw8xLQ9bDw8xLQ9bMSYxJhE6ES0PDw8PDzERDzEPcyBbOEEADw8PDzEPLTFbJhE6EToRLQ8pDw8PDzERDzEPcyBbOEEADw8PDzEPLTFbJhE6ES0PDw8PDzERDzERLTo6JC1b7iRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4647 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4056561198 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5585570eb810, 0x5585572d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5585572d5020,0x55855916d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7fcbaef4d2fe4693d749642beb299c0f5ce15c9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5817 processed earlier; will process 5212 files now Step #5: ==167368== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55854dbe09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558554245898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5585542285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5585542284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55854dbe6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55854db47b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55854db42355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55854dbd8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558550ba7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558550ba7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558550ba7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558550ba7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558550ba7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558550ba7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558550ba7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558550ba7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558550ba7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558550ba7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558552e3cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55854fb69b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55854fb74be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55854f920c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55854f920c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55854f921738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55854f920874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55854f920874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55854f920874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55855422aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558554233928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55855421b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558554246112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9451732082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55854db40b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e,0x3c,0x2f,0x45,0x3e, Step #5: \012\012<E><E><E><E><E><E><E><E><E><E><E><E><E><E><E><E><E></E><E></E></E></E><E><E><E></E><E></E></E></E></E></E></E></E></E></E></E></E></E></E></E></E></E></E> Step #5: artifact_prefix='./'; Test unit written to ./oom-e5d5e45bdf4aac10417e1d52fe17b516f8bab812 Step #5: Base64: Cgo8RT48RT48RT48RT48RT48RT48RT48RT48RT48RT48RT48RT48RT48RT48RT48RT48RT48L0U+PEU+PC9FPjwvRT48L0U+PEU+PEU+PEU+PC9FPjxFPjwvRT48L0U+PC9FPjwvRT48L0U+PC9FPjwvRT48L0U+PC9FPjwvRT48L0U+PC9FPjwvRT48L0U+PC9FPjwvRT48L0U+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4648 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4057077130 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562de0dce810, 0x562de0fb801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562de0fb8020,0x562de2e500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e5d5e45bdf4aac10417e1d52fe17b516f8bab812' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5818 processed earlier; will process 5211 files now Step #5: ==167404== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562dd78c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562dddf28898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562dddf0b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562dddf0b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562dd78c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562dd782ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562dd7825355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562dd78bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562dda88af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562dda88af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562dda88af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562dda88af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562dda88af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562dda88af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562dda88af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562dda88af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562dda88af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562dda88af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ddcb1ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562dd984cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562dd9857be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562dd9603c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562dd9603c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562dd9604738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562dd9603874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562dd9603874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562dd9603874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562dddf0dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562dddf16928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562dddefe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562dddf29112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a36bb1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562dd7823b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x2e,0x2f,0x28,0x20,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x0,0x24,0x0,0x0,0x0, Step #5: $\177]\177\000\000\0002\000\000\0002.23/\020./( 7 =\177\000\000\0002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\020./( \000(\342\200\256\000r+\342\200\215\000\000(\342\200\256\000r+\342\200\215\000\000(\342\200\256\000r+\342\200\215\000\000(\342\200\256\000r+\000\000\000\000\000\000\000\000\177\177\177\177o\000\000C\000$\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e986f01554024741419596ec215ceaab4aa3e14e Step #5: Base64: JH9dfwAAADIAAAAyLjIzLxAuLyggNyA9fwAAADIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEC4vKCAAKOKArgByK+KAjQAAKOKArgByK+KAjQAAKOKArgByK+KAjQAAKOKArgByKwAAAAAAAAAAf39/f28AAEMAJAAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4649 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4057599839 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5649a96d8810, 0x5649a98c201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5649a98c2020,0x5649ab75a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e986f01554024741419596ec215ceaab4aa3e14e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5819 processed earlier; will process 5210 files now Step #5: ==167440== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5649a01cd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5649a6832898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5649a68155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5649a68154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5649a01d3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649a0134b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649a012f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5649a01c5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5649a3194f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5649a3194f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5649a3194f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5649a3194f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5649a3194f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5649a3194f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5649a3194f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5649a3194f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5649a3194f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5649a3194f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5649a5429f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649a2156b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649a2161be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5649a1f0dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5649a1f0dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5649a1f0e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5649a1f0d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5649a1f0d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5649a1f0d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5649a6817abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5649a6820928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5649a6808699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5649a6833112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f316d3bd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649a012db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x6e,0x75,0x3e,0x3c,0x73,0x6c,0x3a,0x73,0x74,0x61,0x6e,0x64,0x42,0x65,0x73,0x74,0x3e,0x6f,0x6d,0x72,0x6f,0x63,0x53,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x73,0x74,0x61,0x6e,0x64,0x6c,0x65,0x76,0x65,0x72,0x69,0x6e,0x67,0x2d,0x67,0x65,0x6e,0x65,0x72,0x69,0x65,0x6b,0x2f,0x31,0x2e,0x30,0x47,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x6c,0x76,0x62,0x61,0x67,0x2f,0x65,0x78,0x74,0x72,0x61,0x63,0x74,0x2d,0x64,0x65,0x65,0x6c,0x62,0x65,0x73,0x74,0x61,0x6e,0x64,0x2d,0x6c,0x76,0x63,0x2f,0x76,0x32,0x30,0x32,0x30,0x30,0x36,0x30,0x31,0x65,0x79,0x6f,0x3e,0x73, Step #5: <nu><sl:standBest>omrocShttp://www.kadaster.nl/schemas/standlevering-generiek/1.0Ghttp://www.kadaster.nl/schemas/lvbag/extract-deelbestand-lvc/v20200601eyo>s Step #5: artifact_prefix='./'; Test unit written to ./oom-9f530d16e5b410aae258dfde30838f8477c4e5e0 Step #5: Base64: PG51PjxzbDpzdGFuZEJlc3Q+b21yb2NTaHR0cDovL3d3dy5rYWRhc3Rlci5ubC9zY2hlbWFzL3N0YW5kbGV2ZXJpbmctZ2VuZXJpZWsvMS4wR2h0dHA6Ly93d3cua2FkYXN0ZXIubmwvc2NoZW1hcy9sdmJhZy9leHRyYWN0LWRlZWxiZXN0YW5kLWx2Yy92MjAyMDA2MDFleW8+cw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4650 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4058115089 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558ef9364810, 0x558ef954e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558ef954e020,0x558efb3e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f530d16e5b410aae258dfde30838f8477c4e5e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5820 processed earlier; will process 5209 files now Step #5: ==167476== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558eefe599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558ef64be898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558ef64a15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558ef64a14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558eefe5fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558eefdc0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558eefdbb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558eefe51c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558ef2e20f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558ef2e20f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558ef2e20f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558ef2e20f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558ef2e20f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558ef2e20f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558ef2e20f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558ef2e20f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558ef2e20f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558ef2e20f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558ef50b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ef1de2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ef1dedbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ef1b99c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ef1b99c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ef1b9a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ef1b99874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ef1b99874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ef1b99874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558ef64a3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558ef64ac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558ef6494699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558ef64bf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f63748082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558eefdb9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x0,0x24,0x0,0x0,0x0, Step #5: $\177]\177\000\000\0002\000\000\0002.23/\020./( 7 =\177\000\000\0002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\177\177\177\177o\000\000C\000$\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3002e46714f6520790355352c1b50d3bf9459cdb Step #5: Base64: JH9dfwAAADIAAAAyLjIzLxAuLyggNyA9fwAAADIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAf39/f28AAEMAJAAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4651 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4058635620 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556cfb059810, 0x556cfb24301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556cfb243020,0x556cfd0db0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3002e46714f6520790355352c1b50d3bf9459cdb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5821 processed earlier; will process 5208 files now Step #5: ==167512== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556cf1b4e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556cf81b3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556cf81965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556cf81964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556cf1b54d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556cf1ab5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556cf1ab0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556cf1b46c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556cf4b15f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556cf4b15f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556cf4b15f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556cf4b15f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556cf4b15f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556cf4b15f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556cf4b15f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556cf4b15f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556cf4b15f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556cf4b15f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556cf6daaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556cf3ad7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556cf3ae2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556cf388ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556cf388ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556cf388f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556cf388e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556cf388e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556cf388e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556cf8198abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556cf81a1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556cf8189699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556cf81b4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f479a044082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556cf1aaeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x2e,0x2f,0x28,0x20,0x37,0x20,0x3d,0x7f,0x0,0x0,0x0,0x32,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x0,0x24,0x0,0x0,0x0, Step #5: $\177]\177\000\000\0002\000\000\0002.23/\020./( 7 =\177\000\000\0002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\020./( 7 =\177\000\000\0002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\177\177\177\177o\000\000C\000$\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-49526dbe2d6bbcb25c047d02daa5f187cdc4e181 Step #5: Base64: JH9dfwAAADIAAAAyLjIzLxAuLyggNyA9fwAAADIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEC4vKCA3ID1/AAAAMgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAf39/f28AAEMAJAAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4652 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4059158251 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f2c285d810, 0x55f2c2a4701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f2c2a47020,0x55f2c48df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/49526dbe2d6bbcb25c047d02daa5f187cdc4e181' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5822 processed earlier; will process 5207 files now Step #5: ==167548== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f2b93529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f2bf9b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f2bf99a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f2bf99a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f2b9358d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f2b92b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f2b92b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f2b934ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f2bc319f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f2bc319f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f2bc319f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f2bc319f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f2bc319f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f2bc319f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f2bc319f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f2bc319f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f2bc319f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f2bc319f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f2be5aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f2bb2dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f2bb2e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f2bb092c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f2bb092c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f2bb093738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f2bb092874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f2bb092874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f2bb092874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f2bf99cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f2bf9a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f2bf98d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f2bf9b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95fe559082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f2b92b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0x5e,0x0,0x0,0x0,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x5f,0x69,0x5f,0x5f,0x69,0x5f,0x5f,0x5f,0x5f,0x5f,0xa,0xa,0xd3,0x0,0x0,0x0,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x1a,0x3d,0x30,0xa,0x3d,0xa,0x3f,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x6c,0xa,0x7c,0x0,0x10,0xff, Step #5: \005--BEGIN =^\000\000\000\012\012r=sef=\012=+=\012=\012=\012= =\012= i\012\012r=sef=\012=\012= =\012= i\012\012r=sef=\012=\012= _i__i_____\012\012\323\000\000\000r=sef=\012=+=\012=\012=\012=\012D\012=\012r=sef=\012=+=\012=\012=\012=\012D\012=\012=\012=\012\032=0\012=\012?\012=\012=\012=\012\000----\012l\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-c1fa34656e7564c53829eb5710e4e1a71e7b40de Step #5: Base64: BS0tQkVHSU4gPV4AAAAKCnI9c2VmPQo9Kz0KPQo9Cj0gPQo9IGkKCnI9c2VmPQo9Cj0gPQo9IGkKCnI9c2VmPQo9Cj0gX2lfX2lfX19fXwoK0wAAAHI9c2VmPQo9Kz0KPQo9Cj0KRAo9CnI9c2VmPQo9Kz0KPQo9Cj0KRAo9Cj0KPQoaPTAKPQo/Cj0KPQo9CgAtLS0tCmwKfAAQ/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4653 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4059677544 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a44ed8810, 0x561a450c201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a450c2020,0x561a46f5a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c1fa34656e7564c53829eb5710e4e1a71e7b40de' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5823 processed earlier; will process 5206 files now Step #5: ==167584== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561a3b9cd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561a42032898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561a420155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561a420154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561a3b9d3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561a3b934b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561a3b92f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561a3b9c5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561a3e994f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561a3e994f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561a3e994f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561a3e994f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561a3e994f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561a3e994f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561a3e994f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561a3e994f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561a3e994f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561a3e994f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561a40c29f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561a3d956b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561a3d961be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561a3d70dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561a3d70dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561a3d70e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561a3d70d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561a3d70d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561a3d70d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561a42017abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561a42020928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561a42008699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561a42033112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0e96d92082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561a3b92db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x56,0x69,0x73,0x69,0x6f,0x44,0x6f,0x63,0x75,0x6d,0x65,0x6e,0x74,0x3e,0x3c,0x47,0x65,0x6f,0x6d,0x3e,0x3c,0x65,0x6f,0x6d,0x3e,0x3e,0x63,0x56,0x69,0x73,0x69,0x47,0x65,0x6f,0x6d,0x3e,0x3c,0x4d,0x6f,0x76,0x65,0x54,0x6f,0x3e,0x3c,0x56,0x69,0x6d,0x3e,0x54,0x6f,0x3e,0x3e,0x3c,0x58,0x3e,0x3c,0x58,0x3e,0x3c,0x58,0x3e,0x3c,0x58,0x3e,0x3c,0x58,0x3e,0x3c,0x58,0x3e,0x3c,0x58,0x3e,0x3c,0x56,0x69,0x6d,0x3e,0x3c,0x4d,0x6f,0x76,0x54,0x65,0x6f,0x3e,0x3c,0x4d,0x6f,0x76,0x54,0x65,0x6f,0x3e,0x3c,0x4d,0x6f,0x76,0x54,0x65,0x6f,0x3e,0x3e,0x63,0x56,0x69,0x73,0x69,0x47,0x65,0x6f,0x6d,0x3e,0x3c,0x4d,0x6f,0x76,0x65,0x54,0x6f,0x3e,0x54,0x6f,0x3e,0x3e,0x3c,0x58,0x3e,0x3c,0x56,0x69,0x6d,0x3e,0x3c,0x4d,0x6f,0x76,0x65,0x54,0x6f,0x3e,0x4d,0x6f,0x76,0x65,0x54,0x6f,0x3c,0x58,0x3e,0x70,0x6d,0x3c,0x4d,0x3e, Step #5: <VisioDocument><Geom><eom>>cVisiGeom><MoveTo><Vim>To>><X><X><X><X><X><X><X><Vim><MovTeo><MovTeo><MovTeo>>cVisiGeom><MoveTo>To>><X><Vim><MoveTo>MoveTo<X>pm<M> Step #5: artifact_prefix='./'; Test unit written to ./oom-01193430610575a88f49a6ed3453db7f6d4be547 Step #5: Base64: PFZpc2lvRG9jdW1lbnQ+PEdlb20+PGVvbT4+Y1Zpc2lHZW9tPjxNb3ZlVG8+PFZpbT5Ubz4+PFg+PFg+PFg+PFg+PFg+PFg+PFg+PFZpbT48TW92VGVvPjxNb3ZUZW8+PE1vdlRlbz4+Y1Zpc2lHZW9tPjxNb3ZlVG8+VG8+PjxYPjxWaW0+PE1vdmVUbz5Nb3ZlVG88WD5wbTxNPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4654 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4060182102 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b6882e810, 0x558b68a1801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b68a18020,0x558b6a8b00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01193430610575a88f49a6ed3453db7f6d4be547' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5824 processed earlier; will process 5205 files now Step #5: #1 pulse cov: 3801 ft: 3802 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4224 ft: 4415 exec/s: 0 rss: 176Mb Step #5: ==167620== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558b5f3239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b65988898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b6596b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b6596b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b5f329d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b5f28ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b5f285355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b5f31bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b622eaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b622eaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b622eaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b622eaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b622eaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b622eaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b622eaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b622eaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b622eaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b622eaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b6457ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b612acb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b612b7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b61063c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b61063c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b61064738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b61063874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b61063874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b61063874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b6596dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b65976928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b6595e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b65989112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f800bee9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b5f283b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x2d,0x32,0x35,0x35,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x2d,0x36,0x35,0x35,0x33,0x2d,0x2d,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x45,0x15,0x0,0x10,0x15,0x0,0x10,0x49,0x44,0x2d,0x32,0x35,0x35,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x2d,0x30,0x45,0x6,0x64,0x68,0x65,0x61,0x64,0x27,0xa,0xa,0xc,0xa,0x27,0xa,0xa,0xc,0xa,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x45,0x15,0x0,0x10,0x15,0x0,0x10,0x49,0x44,0x2d,0x32,0x35,0x35,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x2d,0x39,0x32,0x32,0x36,0x39,0x36,0x38,0x33,0x38,0x38,0x39,0x31,0x37,0x34,0x36,0x37,0x33,0x38,0x39,0x35,0x33,0x31,0x37,0x31,0x30,0x33,0x45,0x4,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x59,0x45,0x15,0x0,0xdc,0x8c,0xe,0x27,0x10,0x15,0x9,0x0,0x0,0x10,0xa,0xe,0x0,0x0,0x0,0x0, Step #5: ID-255\004'\000\000`'\027TY-6553--\004'\000\000`'\027TYE\025\000\020\025\000\020ID-255\004'\000\000`'\027TY-0E\006dhead'\012\012\014\012'\012\012\014\012'\000\000`'\027TYE\025\000\020\025\000\020ID-255\004'\000\000`'\027TY-92269683889174673895317103E\004'\000\000`'\027TYE\025\000\334\214\016'\020\025\011\000\000\020\012\016\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-066c3a718fd3a2a61931ecb36311631a8eeb6422 Step #5: Base64: SUQtMjU1BCcAAGAnF1RZLTY1NTMtLQQnAABgJxdUWUUVABAVABBJRC0yNTUEJwAAYCcXVFktMEUGZGhlYWQnCgoMCicKCgwKJwAAYCcXVFlFFQAQFQAQSUQtMjU1BCcAAGAnF1RZLTkyMjY5NjgzODg5MTc0NjczODk1MzE3MTAzRQQnAABgJxdUWUUVANyMDicQFQkAABAKDgAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4655 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4060886393 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5645e922e810, 0x5645e941801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5645e9418020,0x5645eb2b00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/066c3a718fd3a2a61931ecb36311631a8eeb6422' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5827 processed earlier; will process 5202 files now Step #5: ==167656== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5645dfd239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5645e6388898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5645e636b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5645e636b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5645dfd29d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5645dfc8ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5645dfc85355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5645dfd1bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5645e2ceaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5645e2ceaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5645e2ceaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5645e2ceaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5645e2ceaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5645e2ceaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5645e2ceaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5645e2ceaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5645e2ceaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5645e2ceaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5645e4f7ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5645e1cacb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5645e1cb7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5645e1a63c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5645e1a63c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5645e1a64738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5645e1a63874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5645e1a63874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5645e1a63874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5645e636dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5645e6376928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5645e635e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5645e6389112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fca91860082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5645dfc83b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0x5e,0x0,0x0,0x0,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x5f,0x69,0x5f,0x5f,0x5f,0x48,0x5f,0x5f,0xa,0xa,0xd3,0x0,0x0,0x0,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x1a,0x3d,0x30,0xa,0x3d,0xa,0x3f,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x6c,0xa,0x7c,0x0,0x10,0xff, Step #5: \005-----BEGIN =^\000\000\000\012\012r=sef=\012=+=\012=\012=\012= =\012= i\012\012r=sef=\012=\012= =\012= i\012\012r=sef=\012=\012= _i___H__\012\012\323\000\000\000r=sef=\012=+=\012=\012=\012=\012D\012=\012r=sef=\012=+=\012=\012=\012=\012D\012=\012=\012=\012\032=0\012=\012?\012=\012=\012=\012\000----\012l\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-782784a73b6539f366ed160ef679e39e9e478d79 Step #5: Base64: BS0tLS0tQkVHSU4gPV4AAAAKCnI9c2VmPQo9Kz0KPQo9Cj0gPQo9IGkKCnI9c2VmPQo9Cj0gPQo9IGkKCnI9c2VmPQo9Cj0gX2lfX19IX18KCtMAAAByPXNlZj0KPSs9Cj0KPQo9CkQKPQpyPXNlZj0KPSs9Cj0KPQo9CkQKPQo9Cj0KGj0wCj0KPwo9Cj0KPQoALS0tLQpsCnwAEP8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4656 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4061399514 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cbeb929810, 0x55cbebb1301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cbebb13020,0x55cbed9ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/782784a73b6539f366ed160ef679e39e9e478d79' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5828 processed earlier; will process 5201 files now Step #5: #1 pulse cov: 3955 ft: 3956 exec/s: 0 rss: 173Mb Step #5: #2 pulse cov: 4017 ft: 4546 exec/s: 0 rss: 175Mb Step #5: ==167692== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cbe241e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cbe8a83898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cbe8a665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cbe8a664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cbe2424d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cbe2385b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cbe2380355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cbe2416c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cbe53e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cbe53e5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cbe53e5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cbe53e5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cbe53e5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cbe53e5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cbe53e5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cbe53e5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cbe53e5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cbe53e5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cbe767af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cbe43a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cbe43b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cbe415ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cbe415ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cbe415f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cbe415e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cbe415e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cbe415e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cbe8a68abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cbe8a71928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cbe8a59699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cbe8a84112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c1ea66082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cbe237eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x5b,0x31,0x26,0x11,0x3a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0xf,0xf,0xf,0xf,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x30,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x11,0x3a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x3a,0x24,0x2d,0x5b,0xee,0x24,0x5b, Step #5: $\000\000/\000\000\000/[1&\021:\000\000\000\000\000\000\000\000\000?\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\021-\017\017\017\017\0171\021\0171\017\017\017\017\017\000\000/\000\017\017\017\017\0170-\017[\017\0171-\017[1&\021:\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000-\017\017\017\017\0171\021\0171\021-::$-[\356$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-f8840edcc84ca77145c9d2ec377cb990707dc546 Step #5: Base64: JAAALwAAAC9bMSYROgAAAAAAAAAAAD8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABEtDw8PDw8xEQ8xDw8PDw8AAC8ADw8PDw8wLQ9bDw8xLQ9bMSYROgAAAAAAAAAAAAAAAAAAAAAAAAAALQ8PDw8PMREPMREtOjokLVvuJFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4657 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4061994805 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561f73a6b810, 0x561f73c5501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561f73c55020,0x561f75aed0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8840edcc84ca77145c9d2ec377cb990707dc546' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5831 processed earlier; will process 5198 files now Step #5: ==167728== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561f6a5609c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561f70bc5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561f70ba85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561f70ba84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561f6a566d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561f6a4c7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561f6a4c2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561f6a558c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561f6d527f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561f6d527f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561f6d527f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561f6d527f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561f6d527f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561f6d527f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561f6d527f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561f6d527f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561f6d527f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561f6d527f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561f6f7bcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561f6c4e9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561f6c4f4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561f6c2a0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561f6c2a0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561f6c2a1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561f6c2a0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561f6c2a0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561f6c2a0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561f70baaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561f70bb3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561f70b9b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561f70bc6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f008bc8d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561f6a4c0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2c,0x2b,0xb,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x1a,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0x73,0x73,0x73,0x73,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2c,0x2b,0xb,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x1a,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0x73,0x73,0x73,0x73,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0xee,0x2b,0x2b,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0xee,0x2b,0xa,0x2e,0x2b,0x2b,0x2b,0xa,0x2b,0xdf, Step #5: +\012+\012+\012,+\013\012+\012+\012+\012+\012+\032+\012+\012+\012+\012+\012+ssssss\012+\012+\012+\012+\012+s\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012,+\013\012+\012+\012+\012+\012+\032+\012+\012+\012+\012+\012+ssssss\012+\012+\012+\012+\012+s\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012\012+\012+\356++\012+\012\012+\012+\356+\012.+++\012+\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-40a543f5d20b5e8d6b020f07ad30b0d3dae44517 Step #5: Base64: KworCisKLCsLCisKKworCisKKxorCisKKworCisKK3Nzc3NzcworCisKKworCitzCisKKworCisKKworCisKKworCisKKwosKwsKKworCisKKworGisKKworCisKKworc3Nzc3NzCisKKworCisKK3MKKworCisKKworCisKKworCisKKwoKKwor7isrCisKCisKK+4rCi4rKysKK98= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4658 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4062570307 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c17b34810, 0x561c17d1e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c17d1e020,0x561c19bb60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40a543f5d20b5e8d6b020f07ad30b0d3dae44517' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5832 processed earlier; will process 5197 files now Step #5: #1 pulse cov: 3831 ft: 3832 exec/s: 0 rss: 174Mb Step #5: ==167764== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561c0e6299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c14c8e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c14c715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c14c714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c0e62fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c0e590b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c0e58b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c0e621c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c115f0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c115f0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c115f0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c115f0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c115f0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c115f0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c115f0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c115f0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c115f0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c115f0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c13885f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c105b2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c105bdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c10369c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c10369c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c1036a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c10369874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c10369874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c10369874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c14c73abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c14c7c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c14c64699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c14c8f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc39aa9f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c0e589b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x30,0x2d,0xe4,0x88,0x88,0x23,0x30,0x2d,0x2d,0xe4,0x88,0x88,0x49,0x44,0x33,0x2,0x6,0x32,0x4d,0x2d,0x24,0x24,0x0,0x0,0x60,0x0,0x0,0x0,0x0,0x60,0x0,0x0,0x0,0x0,0x0,0x6d,0x60,0x60,0x0,0x0,0x0,0x0,0x0,0x60,0x0,0x0,0x0,0x0,0x0,0x6d,0x60,0x60,0x0,0x0,0x0,0x0,0x60,0x0,0x0,0x23,0x30,0x2d,0xe4,0x88,0x88,0x23,0x30,0x2d,0xe4,0x88,0x88,0x23,0x30,0x2d,0xe4,0x88,0x88,0x23,0x30,0x0,0x0,0x96,0x2,0x1e,0x0,0x6d,0x60,0xa0,0x20,0xff,0xff,0x92,0x9f,0x9f,0x2d,0xe4,0x88,0x88,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xfa,0x0,0x0,0x0,0x23,0x30,0x30,0x88,0x23,0xe4,0x88,0x2d,0x2d,0xe4,0x88,0x88,0x23,0x30,0x2d,0xe4,0x88,0x88,0x23,0x0,0x88,0xc0,0xad,0xc0,0xad,0xc0,0xad,0xc0,0xad,0xc0,0xad,0xc0,0xad,0x23,0x41,0xc0,0x48,0x41,0xad,0x34,0x4d, Step #5: #0-\344\210\210#0--\344\210\210ID3\002\0062M-$$\000\000`\000\000\000\000`\000\000\000\000\000m``\000\000\000\000\000`\000\000\000\000\000m``\000\000\000\000`\000\000#0-\344\210\210#0-\344\210\210#0-\344\210\210#0\000\000\226\002\036\000m`\240 \377\377\222\237\237-\344\210\210\000\000\000\000\000\000\000\000\000\000\000\000\000\000\372\000\000\000#00\210#\344\210--\344\210\210#0-\344\210\210#\000\210\300\255\300\255\300\255\300\255\300\255\300\255#A\300HA\2554M Step #5: artifact_prefix='./'; Test unit written to ./oom-dde43866a47550453f9ab6e604cb9f8cab2239aa Step #5: Base64: IzAt5IiIIzAtLeSIiElEMwIGMk0tJCQAAGAAAAAAYAAAAAAAbWBgAAAAAABgAAAAAABtYGAAAAAAYAAAIzAt5IiIIzAt5IiIIzAt5IiIIzAAAJYCHgBtYKAg//+Sn58t5IiIAAAAAAAAAAAAAAAAAAD6AAAAIzAwiCPkiC0t5IiIIzAt5IiIIwCIwK3ArcCtwK3ArcCtI0HASEGtNE0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4659 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4063262052 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56395a654810, 0x56395a83e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56395a83e020,0x56395c6d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dde43866a47550453f9ab6e604cb9f8cab2239aa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5834 processed earlier; will process 5195 files now Step #5: #1 pulse cov: 4006 ft: 4007 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4306 ft: 4571 exec/s: 0 rss: 179Mb Step #5: ==167800== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5639511499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5639577ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5639577915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5639577914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56395114fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5639510b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5639510ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563951141c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563954110f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563954110f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563954110f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563954110f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563954110f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563954110f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563954110f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563954110f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563954110f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563954110f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5639563a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5639530d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5639530ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563952e89c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563952e89c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563952e8a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563952e89874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563952e89874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563952e89874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563957793abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56395779c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563957784699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5639577af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff1be548082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5639510a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xd,0x48,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xd,0x25,0x20,0x78,0x78,0x20,0x27,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0x20,0x6a,0x9,0x64,0xd,0x49,0x44,0x52,0x45,0x46,0x53,0x9,0x22,0x42,0x68,0x9,0xe2,0x80,0x8d,0xe4,0xb4,0x80,0x64,0x20,0xc3,0xb2,0x62,0x9,0xe2,0x80,0x8d,0xe0,0xb4,0x80,0x20,0xcd,0xb2,0x64,0x20,0xc3,0xb2,0x68,0x9,0xe0,0xbc,0x80,0x20,0xcd,0xb2,0x64,0x9,0xe2,0x80,0x8d,0xe0,0xb4,0x80,0x64,0x20,0xc3,0xb2,0x9,0xe0,0xbc,0x80,0x20,0xcd,0xb2,0x64,0x9,0xe2,0x80,0x8d,0xe0,0xb4,0x80,0x64,0x64,0x20,0xc3,0xb2,0x62,0x22,0x3e,0x27,0x3e,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x84,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b, Step #5: <!DOCTYPE\015H[<!ENTITY\015% xx '<!ATTLIST j\011d\015IDREFS\011\"Bh\011\342\200\215\344\264\200d \303\262b\011\342\200\215\340\264\200 \315\262d \303\262h\011\340\274\200 \315\262d\011\342\200\215\340\264\200d \303\262\011\340\274\200 \315\262d\011\342\200\215\340\264\200dd \303\262b\">'>%xx;%xx;%xx;%xx;%xx;%xx\204;%xx;%xx;%xx; Step #5: artifact_prefix='./'; Test unit written to ./oom-0891fbf0f2ba817c4ede1b668b387ec3e26e0527 Step #5: Base64: PCFET0NUWVBFDUhbPCFFTlRJVFkNJSB4eCAnPCFBVFRMSVNUIGoJZA1JRFJFRlMJIkJoCeKAjeS0gGQgw7JiCeKAjeC0gCDNsmQgw7JoCeC8gCDNsmQJ4oCN4LSAZCDDsgngvIAgzbJkCeKAjeC0gGRkIMOyYiI+Jz4leHg7JXh4OyV4eDsleHg7JXh4OyV4eIQ7JXh4OyV4eDsleHg7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4660 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4063857279 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5651c0bac810, 0x5651c0d9601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5651c0d96020,0x5651c2c2e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0891fbf0f2ba817c4ede1b668b387ec3e26e0527' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5837 processed earlier; will process 5192 files now Step #5: #1 pulse cov: 4318 ft: 4319 exec/s: 0 rss: 176Mb Step #5: ==167836== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5651b76a19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5651bdd06898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651bdce95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651bdce94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5651b76a7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5651b7608b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5651b7603355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5651b7699c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5651ba668f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5651ba668f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5651ba668f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5651ba668f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5651ba668f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5651ba668f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5651ba668f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5651ba668f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5651ba668f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5651ba668f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5651bc8fdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5651b962ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5651b9635be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5651b93e1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5651b93e1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5651b93e2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5651b93e1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5651b93e1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5651b93e1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5651bdcebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5651bdcf4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5651bdcdc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5651bdd07112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f37da408082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5651b7601b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xc7,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x33,0x0,0x39,0x39,0x39,0x39,0x39,0x39, Step #5: \333\200\333\200\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\307\000\000\000\000\000\000\000\000\000\000\000\000\000\0003\000999999 Step #5: artifact_prefix='./'; Test unit written to ./oom-c15834456d7457cea9732a3d1f292e63cb5efc65 Step #5: Base64: 24DbgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMcAAAAAAAAAAAAAAAAAADMAOTk5OTk5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4661 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4064405555 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a48231810, 0x559a4841b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a4841b020,0x559a4a2b30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c15834456d7457cea9732a3d1f292e63cb5efc65' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5839 processed earlier; will process 5190 files now Step #5: ==167872== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559a3ed269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a4538b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a4536e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a4536e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a3ed2cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a3ec8db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a3ec88355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a3ed1ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a41cedf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a41cedf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a41cedf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a41cedf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a41cedf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a41cedf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a41cedf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a41cedf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a41cedf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a41cedf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a43f82f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a40cafb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a40cbabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a40a66c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a40a66c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a40a67738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a40a66874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a40a66874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a40a66874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a45370abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a45379928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a45361699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a4538c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f90b40d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a3ec86b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xa,0x73,0x75,0x62,0x7b,0x20,0x64,0x3a,0x31,0x37,0x32,0x35,0x31,0x36,0x33,0x31,0x37,0x34,0x31,0x34,0x33,0x32,0x32,0x30,0x33,0x35,0x34,0x34,0x32,0x37,0x36,0x37,0x30,0x30,0x2e,0x20,0x7d,0xa,0x73,0x75,0x62,0x7b,0x20,0x64,0x3a,0x31,0x37,0x32,0x35,0x31,0x36,0x33,0x31,0x37,0x34,0x31,0x34,0x33,0x32,0x32,0x30,0x33,0x35,0x34,0x34,0x32,0x37,0x36,0x37,0x30,0x30,0x2e,0x20,0x7d,0xa,0x73,0x75,0x62,0x7b,0x20,0x64,0x3a,0x31,0x37,0x32,0x35,0x31,0x36,0x33,0x31,0x37,0x34,0x31,0x34,0x33,0x32,0x32,0x30,0x33,0x35,0x34,0x34,0x32,0x37,0x36,0x37,0x30,0x30,0x2e,0x20,0x7d,0xa,0x73,0x75,0x62,0x7b,0x20,0x64,0x3a,0x31,0x37,0x32,0x35,0x31,0x36,0x33,0x31,0x37,0x34,0x31,0x34,0x33,0x32,0x32,0x30,0x33,0x35,0x34,0x34,0x32,0x37,0x36,0x37,0x30,0x30,0x2e,0x20,0x7d,0xa, Step #5: FUZZTESTv1\012sub{ d:17251631741432203544276700. }\012sub{ d:17251631741432203544276700. }\012sub{ d:17251631741432203544276700. }\012sub{ d:17251631741432203544276700. }\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-914df62de5f728eb178cd5443eb46d55b1816fe0 Step #5: Base64: RlVaWlRFU1R2MQpzdWJ7IGQ6MTcyNTE2MzE3NDE0MzIyMDM1NDQyNzY3MDAuIH0Kc3VieyBkOjE3MjUxNjMxNzQxNDMyMjAzNTQ0Mjc2NzAwLiB9CnN1YnsgZDoxNzI1MTYzMTc0MTQzMjIwMzU0NDI3NjcwMC4gfQpzdWJ7IGQ6MTcyNTE2MzE3NDE0MzIyMDM1NDQyNzY3MDAuIH0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4662 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4064907419 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56412fe25810, 0x56413000f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56413000f020,0x564131ea70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/914df62de5f728eb178cd5443eb46d55b1816fe0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5840 processed earlier; will process 5189 files now Step #5: ==167908== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56412691a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56412cf7f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56412cf625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56412cf624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564126920d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564126881b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56412687c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564126912c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5641298e1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5641298e1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5641298e1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5641298e1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5641298e1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5641298e1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5641298e1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5641298e1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5641298e1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5641298e1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56412bb76f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5641288a3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5641288aebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56412865ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56412865ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56412865b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56412865a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56412865a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56412865a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56412cf64abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56412cf6d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56412cf55699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56412cf80112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd2e8cc2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56412687ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x3e,0x68,0xcc,0x9a,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0xe0,0xa3,0xb3,0x9,0xa,0x3c,0x73,0x79,0x6d,0x62,0x6f,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x3e,0x68,0xcc,0x9a,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0xe0,0xa3,0xb3,0x9,0xa,0x3c,0x73,0x79,0x6d,0x62,0x6f,0x6c,0x3e,0x3c,0x3e,0x3e,0x3e,0x68,0xcc,0x9a,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0xe0,0xa3,0xb3,0x9,0xa,0x3c,0x73,0x79,0x6d,0x62,0x6f,0x6c,0x3e,0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x3e,0x3e,0x68,0xcc,0x9a,0x3c,0x2f,0x3e,0x6c,0x3e,0x3c,0x3e,0x3e,0x3e,0x68,0xcc,0x9a,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0xe0,0xa3,0xb3,0x9,0xa,0x3c,0x73,0x79,0x6d,0x62,0x6f,0x6c,0x3e,0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x3e,0x3e,0x68,0xcc,0x9a,0x3c,0x2f,0x3e, Step #5: <svg><text>>h\314\232</text>\340\243\263\011\012<symbog><text>>h\314\232</text>\340\243\263\011\012<symbol><>>>h\314\232</text>\340\243\263\011\012<symbol><svg><text>>>h\314\232</>l><>>>h\314\232</text>\340\243\263\011\012<symbol><svg><text>>>h\314\232</> Step #5: artifact_prefix='./'; Test unit written to ./oom-2be697989093cc7760c53ddad0f1e6af8050d045 Step #5: Base64: PHN2Zz48dGV4dD4+aMyaPC90ZXh0PuCjswkKPHN5bWJvZz48dGV4dD4+aMyaPC90ZXh0PuCjswkKPHN5bWJvbD48Pj4+aMyaPC90ZXh0PuCjswkKPHN5bWJvbD48c3ZnPjx0ZXh0Pj4+aMyaPC8+bD48Pj4+aMyaPC90ZXh0PuCjswkKPHN5bWJvbD48c3ZnPjx0ZXh0Pj4+aMyaPC8+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4663 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4065410383 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611ad0c3810, 0x5611ad2ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5611ad2ad020,0x5611af1450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2be697989093cc7760c53ddad0f1e6af8050d045' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5841 processed earlier; will process 5188 files now Step #5: #1 pulse cov: 3893 ft: 3894 exec/s: 0 rss: 175Mb Step #5: ==167944== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5611a3bb89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5611aa21d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611aa2005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611aa2004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5611a3bbed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5611a3b1fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5611a3b1a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5611a3bb0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5611a6b7ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5611a6b7ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5611a6b7ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5611a6b7ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5611a6b7ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5611a6b7ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5611a6b7ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5611a6b7ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5611a6b7ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5611a6b7ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5611a8e14f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611a5b41b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5611a5b4cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611a58f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611a58f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611a58f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611a58f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611a58f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611a58f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5611aa202abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5611aa20b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611aa1f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5611aa21e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4d26cdf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5611a3b18b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x20,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x5c,0xa,0x9,0x3d,0xa,0x3d, Step #5: []\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012 =\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012\\\012\011=\012= Step #5: artifact_prefix='./'; Test unit written to ./oom-edb32a1fb6fb4d52612c3bc53f90fd45c5279326 Step #5: Base64: W10KXAoJPQpcCgk9ClwKCT0KXAoJPQpcCgk9ClwKCT0KXAoJPQpcCgk9ClwKCT0KXAoJPQpcCgk9ClwKCT0KXAoJPQpcCgk9ClwKCT0KXAogPQpcCgk9ClwKCT0KXAoJPQpcCgk9ClwKCT0KXAoJPQpcCgk9ClwKCT0KXAoJPQpcCgk9ClwKCT0KXAoJPQpcCgk9ClwKCT0KXAoJPQo9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4664 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4065979978 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571cf837810, 0x5571cfa2101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571cfa21020,0x5571d18b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/edb32a1fb6fb4d52612c3bc53f90fd45c5279326' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5843 processed earlier; will process 5186 files now Step #5: ==167980== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571c632c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571cc991898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571cc9745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571cc9744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571c6332d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571c6293b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571c628e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571c6324c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571c92f3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571c92f3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571c92f3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571c92f3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571c92f3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571c92f3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571c92f3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571c92f3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571c92f3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571c92f3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571cb588f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571c82b5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571c82c0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571c806cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571c806cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571c806d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571c806c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571c806c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571c806c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571cc976abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571cc97f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571cc967699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571cc992112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb3c18ac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571c628cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33,0x4e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x46,0x25,0x50,0x44,0x46,0x2d,0x31,0x2e,0xa,0x38,0x33,0x20,0x2d,0x20,0x6f,0x62,0x6a,0xd,0x3c,0x3c,0x2f,0x4c,0x69,0x6e,0x65,0x61,0x72,0x69,0x7a,0x65,0x64,0x20,0x32,0x2f,0x4c,0x20,0x30,0x49,0x7,0x0,0x32,0x15,0x1,0x3,0x0,0x1,0x0,0x0,0x0,0x4,0x0,0x3b,0xe3,0x0,0x16,0x10,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6e,0x20,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0xa,0x3c,0x3c,0x2f,0x52,0x6f,0x6f,0x74,0x20,0x31,0x20,0x30,0x20,0x52,0x2f,0x61,0x72,0x65,0x6e,0x74,0x20,0x32,0x20,0x30,0x20,0x52,0x2f,0x43,0x6f,0x6e,0x74,0x65,0x6e,0x74,0xff,0xff,0xff,0xff,0xff,0x3e,0xf6,0x16,0x30,0x3e,0x0,0x39,0x32,0xa,0xa,0xa, Step #5: 3N\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000F%PDF-1.\01283 - obj\015<</Linearized 2/L 0I\007\0002\025\001\003\000\001\000\000\000\004\000;\343\000\026\020\000\000\000\000\000\000\000\000n \012trailer\012<</Root 1 0 R/arent 2 0 R/Content\377\377\377\377\377>\366\0260>\00092\012\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-0226a105b85557067cf85ba91f5146b64eda4322 Step #5: Base64: M04AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABGJVBERi0xLgo4MyAtIG9iag08PC9MaW5lYXJpemVkIDIvTCAwSQcAMhUBAwABAAAABAA74wAWEAAAAAAAAAAAbiAKdHJhaWxlcgo8PC9Sb290IDEgMCBSL2FyZW50IDIgMCBSL0NvbnRlbnT//////z72FjA+ADkyCgoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4665 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4066482402 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c0c582b810, 0x55c0c5a1501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c0c5a15020,0x55c0c78ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0226a105b85557067cf85ba91f5146b64eda4322' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5844 processed earlier; will process 5185 files now Step #5: ==168016== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c0bc3209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c0c2985898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c0c29685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c0c29684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c0bc326d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c0bc287b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c0bc282355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c0bc318c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c0bf2e7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c0bf2e7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c0bf2e7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c0bf2e7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c0bf2e7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c0bf2e7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c0bf2e7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c0bf2e7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c0bf2e7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c0bf2e7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c0c157cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c0be2a9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c0be2b4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c0be060c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c0be060c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c0be061738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c0be060874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c0be060874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c0be060874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c0c296aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c0c2973928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c0c295b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c0c2986112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb1ecdce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c0bc280b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90,0xa,0x8,0x2a,0x6,0xa,0x4,0xf0,0x90,0x90,0x90, Step #5: \012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220\012\010*\006\012\004\360\220\220\220 Step #5: artifact_prefix='./'; Test unit written to ./oom-e5185e34df5241d84a5240b0cecf3d7e8d83679f Step #5: Base64: CggqBgoE8JCQkAoIKgYKBPCQkJAKCCoGCgTwkJCQCggqBgoE8JCQkAoIKgYKBPCQkJAKCCoGCgTwkJCQCggqBgoE8JCQkAoIKgYKBPCQkJAKCCoGCgTwkJCQCggqBgoE8JCQkAoIKgYKBPCQkJAKCCoGCgTwkJCQCggqBgoE8JCQkAoIKgYKBPCQkJAKCCoGCgTwkJCQCggqBgoE8JCQkA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4666 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4066996011 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563ed8902810, 0x563ed8aec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563ed8aec020,0x563eda9840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e5185e34df5241d84a5240b0cecf3d7e8d83679f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5845 processed earlier; will process 5184 files now Step #5: ==168052== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563ecf3f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563ed5a5c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563ed5a3f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563ed5a3f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563ecf3fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563ecf35eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563ecf359355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563ecf3efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563ed23bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563ed23bef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563ed23bef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563ed23bef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563ed23bef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563ed23bef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563ed23bef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563ed23bef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563ed23bef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563ed23bef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563ed4653f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563ed1380b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563ed138bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563ed1137c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563ed1137c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563ed1138738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563ed1137874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563ed1137874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563ed1137874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563ed5a41abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563ed5a4a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563ed5a32699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563ed5a5d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa699786082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563ecf357b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e,0x28,0x3f,0x3c,0x71,0x3e, Step #5: (?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q>(?<q> Step #5: artifact_prefix='./'; Test unit written to ./oom-0eda43be8f255b779bf9a23b288e1acc0e14f43d Step #5: Base64: KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPig/PHE+KD88cT4oPzxxPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4667 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4067508056 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a18e863810, 0x55a18ea4d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a18ea4d020,0x55a1908e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0eda43be8f255b779bf9a23b288e1acc0e14f43d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5846 processed earlier; will process 5183 files now Step #5: ==168088== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1853589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a18b9bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a18b9a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a18b9a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a18535ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1852bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1852ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a185350c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a18831ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a18831ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a18831ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a18831ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a18831ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a18831ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a18831ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a18831ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a18831ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a18831ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a18a5b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1872e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1872ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a187098c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a187098c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a187099738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a187098874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a187098874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a187098874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a18b9a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a18b9ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a18b993699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a18b9be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4242eaa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1852b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x25,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x25,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d, Step #5: }{0,} {0,} {0,}s{0,} {0,}${0,}%{0,} {0,}}{0,} {0,} {0,}s{0,} {0,}${0,} {0,} {0,}}{0,} {0,} {0,}s{0,} {0,}${0,}%{0,} {0,}}{0,} {0,} {0,}s{0,} {0,}${0,} {0,} {0,} Step #5: artifact_prefix='./'; Test unit written to ./oom-eb8d8a9f81ae27e9482be0a94b5beb11645f4555 Step #5: Base64: fXswLH0gezAsfSB7MCx9c3swLH0gezAsfSR7MCx9JXswLH0gezAsfX17MCx9IHswLH0gezAsfXN7MCx9IHswLH0kezAsfSB7MCx9IHswLH19ezAsfSB7MCx9IHswLH1zezAsfSB7MCx9JHswLH0lezAsfSB7MCx9fXswLH0gezAsfSB7MCx9c3swLH0gezAsfSR7MCx9IHswLH0gezAsfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4668 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4068018633 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55997eabf810, 0x55997eca901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55997eca9020,0x559980b410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eb8d8a9f81ae27e9482be0a94b5beb11645f4555' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5847 processed earlier; will process 5182 files now Step #5: ==168124== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5599755b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55997bc19898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55997bbfc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55997bbfc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5599755bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55997551bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559975516355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5599755acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55997857bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55997857bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55997857bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55997857bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55997857bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55997857bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55997857bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55997857bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55997857bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55997857bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55997a810f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55997753db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559977548be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5599772f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5599772f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5599772f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5599772f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5599772f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5599772f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55997bbfeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55997bc07928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55997bbef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55997bc1a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fefa2a66082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559975514b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x68,0x74,0x74,0x70,0x3a,0x30,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x7e,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x80,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x4c,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x80,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x77,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x7e,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x80,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x7e,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x80,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: \016http:0\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204~\315\204\315\204\315\204\315\204\315\204\315\204\315\224\315\204\315\204\315\200\315\204\315\204\315\204L\315\204\315\204\315\204\315\204\315\204\315\204\315\224\315\204\315\204\315\200\315\204\315\204\315\204w\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204~\315\204\315\204\315\204\315\204\315\204\315\204\315\224\315\204\315\204\315\200\315\204\315\204\315\204~\315\204\315\204\315\204\315\204\315\204\315\204\315\224\315\204\315\204\315\200\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-d1a97c6d76bbd6d3d95a2f18bc4950253cc6dba1 Step #5: Base64: Dmh0dHA6MM2EzYTNhM2EzYTNhM2EzYTNhM2EzYR+zYTNhM2EzYTNhM2EzZTNhM2EzYDNhM2EzYRMzYTNhM2EzYTNhM2EzZTNhM2EzYDNhM2EzYR3zYTNhM2EzYTNhM2EzYTNhM2EzYTNhH7NhM2EzYTNhM2EzYTNlM2EzYTNgM2EzYTNhH7NhM2EzYTNhM2EzYTNlM2EzYTNgM2EzYTNhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4669 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4068527948 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558568347810, 0x55856853101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558568531020,0x55856a3c90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d1a97c6d76bbd6d3d95a2f18bc4950253cc6dba1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5848 processed earlier; will process 5181 files now Step #5: ==168160== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55855ee3c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5585654a1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5585654845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5585654844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55855ee42d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55855eda3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55855ed9e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55855ee34c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558561e03f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558561e03f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558561e03f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558561e03f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558561e03f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558561e03f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558561e03f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558561e03f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558561e03f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558561e03f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558564098f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558560dc5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558560dd0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558560b7cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558560b7cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558560b7d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558560b7c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558560b7c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558560b7c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558565486abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55856548f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558565477699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5585654a2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3d5919b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55855ed9cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0x6c,0x61,0x73,0x73,0xa,0x74,0x61,0x28,0x62,0x6f,0x27,0xcd,0x8f,0x62,0x6f,0x6f,0x6c,0x65,0x61,0x13,0x5b,0x5d,0x61,0x61,0x28,0x5b,0x5d,0x61,0x28,0x62,0x6f,0x6f,0x6c,0x65,0x61,0x13,0x5b,0x5d,0x61,0x28,0x62,0x6f,0x6f,0x6c,0x65,0x61,0x6f,0x5b,0x5d,0x48,0x75,0x78,0x7d,0xce,0xa9,0x65,0x61,0x1b,0x5b,0x5d,0x61,0x28,0x62,0x6f,0x6f,0x6c,0x65,0x61,0x6f,0x5b,0x5d,0x61,0x13,0x61,0x73,0x73,0xa,0x74,0x61,0x28,0x62,0x6f,0x27,0xcd,0x8f,0x62,0x6f,0x6f,0x6c,0x65,0x61,0x13,0x5b,0x5d,0x61,0x61,0x28,0x5b,0x5d,0x61,0x28,0x62,0x6f,0x6f,0x6c,0x65,0x61,0x13,0x5b,0x5d,0x61,0x28,0x62,0x6f,0x6f,0x6c,0x65,0x61,0x6f,0x5b,0x5d,0x48,0x75,0x78,0x7d,0xce,0xa9,0x65,0x61,0x1b,0x5b,0x5d,0x61,0x28,0x62,0x6f,0x6f,0x6c,0x65,0x61,0x6f,0x5b,0x5d,0x61,0x13,0x5b,0x5d,0x61,0x28,0x62,0x2f,0x2a,0x7d,0x0,0x3a,0x3,0x0,0x0,0x0, Step #5: class\012ta(bo'\315\217boolea\023[]aa([]a(boolea\023[]a(booleao[]Hux}\316\251ea\033[]a(booleao[]a\023ass\012ta(bo'\315\217boolea\023[]aa([]a(boolea\023[]a(booleao[]Hux}\316\251ea\033[]a(booleao[]a\023[]a(b/*}\000:\003\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8a43d1473c4fd65ccde0864aae33bccfad86f3fc Step #5: Base64: Y2xhc3MKdGEoYm8nzY9ib29sZWETW11hYShbXWEoYm9vbGVhE1tdYShib29sZWFvW11IdXh9zqllYRtbXWEoYm9vbGVhb1tdYRNhc3MKdGEoYm8nzY9ib29sZWETW11hYShbXWEoYm9vbGVhE1tdYShib29sZWFvW11IdXh9zqllYRtbXWEoYm9vbGVhb1tdYRNbXWEoYi8qfQA6AwAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4670 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4069035679 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b334d5810, 0x556b336bf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b336bf020,0x556b355570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8a43d1473c4fd65ccde0864aae33bccfad86f3fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5849 processed earlier; will process 5180 files now Step #5: ==168196== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556b29fca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b3062f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b306125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b306124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b29fd0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b29f31b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b29f2c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b29fc2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b2cf91f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b2cf91f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b2cf91f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b2cf91f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b2cf91f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b2cf91f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b2cf91f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b2cf91f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b2cf91f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b2cf91f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b2f226f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b2bf53b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b2bf5ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b2bd0ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b2bd0ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b2bd0b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b2bd0a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b2bd0a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b2bd0a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b30614abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b3061d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b30605699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b30630112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b879e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b29f2ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x61,0x3e,0x3e,0x45,0x3c,0x53,0x64,0x3e,0x3c,0x68,0x4d,0x3e,0x3c,0x54,0x67,0x3e,0x3c,0x57,0x3e,0x3c,0x72,0x3e,0x28,0x3c,0x4d,0x3e,0x3c,0x57,0x53,0x2d,0x3e,0x3c,0x67,0x3e,0x3e,0x3c,0x49,0x69,0x49,0x3e,0x3c,0x51,0x3e,0x3c,0x6f,0x3e,0x3c,0x55,0x54,0x3e,0x30,0x55,0x3c,0x65,0x64,0x3e,0x3c,0x64,0x3e,0x74,0x3c,0x67,0x73,0x3e,0x74,0x3c,0x66,0x3e,0x73,0x3c,0x6e,0x3e,0x3c,0x49,0x3e,0x3c,0x61,0x44,0x3e,0x3c,0x69,0x3e,0x3c,0x41,0x7a,0x3e,0x3c,0x6f,0x41,0x3e,0x3c,0x53,0x3e,0xa,0x3c,0x5a,0x3e,0x3c,0x62,0x3e,0x3c,0x59,0x3e,0x3c,0x74,0x3e,0x3c,0x75,0x70,0x3e,0x3c,0x48,0x69,0x3e,0x57,0x3c,0x49,0x31,0x3e,0x3c,0x74,0x6e,0x3e,0x3c,0x67,0x41,0x51,0x3e,0x3c,0x61,0x65,0x49,0x3e,0x3c,0x48,0x3e,0x3c,0x4e,0x44,0x3e,0x3c,0x57,0x5f,0x57,0x3e,0x3c,0x42,0x3e,0x3c,0x59,0x50,0x3e,0x3c,0x5f,0x3e,0x3c,0x45,0x41,0x3e, Step #5: <a>>E<Sd><hM><Tg><W><r>(<M><WS-><g>><IiI><Q><o><UT>0U<ed><d>t<gs>t<f>s<n><I><aD><i><Az><oA><S>\012<Z><b><Y><t><up><Hi>W<I1><tn><gAQ><aeI><H><ND><W_W><B><YP><_><EA> Step #5: artifact_prefix='./'; Test unit written to ./oom-27ca9cc9c2ca6b8d508e75dfb7bbd49f58d02ff9 Step #5: Base64: PGE+PkU8U2Q+PGhNPjxUZz48Vz48cj4oPE0+PFdTLT48Zz4+PElpST48UT48bz48VVQ+MFU8ZWQ+PGQ+dDxncz50PGY+czxuPjxJPjxhRD48aT48QXo+PG9BPjxTPgo8Wj48Yj48WT48dD48dXA+PEhpPlc8STE+PHRuPjxnQVE+PGFlST48SD48TkQ+PFdfVz48Qj48WVA+PF8+PEVBPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4671 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4069551286 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bdcb4e4810, 0x55bdcb6ce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bdcb6ce020,0x55bdcd5660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/27ca9cc9c2ca6b8d508e75dfb7bbd49f58d02ff9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5850 processed earlier; will process 5179 files now Step #5: #1 pulse cov: 4187 ft: 4188 exec/s: 0 rss: 176Mb Step #5: ==168232== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bdc1fd99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bdc863e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bdc86215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bdc86214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bdc1fdfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bdc1f40b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bdc1f3b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bdc1fd1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bdc4fa0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bdc4fa0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bdc4fa0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bdc4fa0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bdc4fa0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bdc4fa0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bdc4fa0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bdc4fa0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bdc4fa0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bdc4fa0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bdc7235f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bdc3f62b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bdc3f6dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bdc3d19c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bdc3d19c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bdc3d1a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bdc3d19874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bdc3d19874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bdc3d19874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bdc8623abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bdc862c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bdc8614699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bdc863f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc65fd7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bdc1f39b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xd7,0xa4,0x60,0x5b,0x30,0x2d,0x31,0x5d,0x2b,0x60,0x2d,0x32,0xd7,0xa4,0x60,0x5b,0x30,0x2d,0x31,0x5d,0x2b,0x60,0x6d,0x3f,0x3f,0x60,0x5b,0x30,0x2d,0x31,0x5d,0x2b,0x60,0x2d,0x32,0xd7,0xa4,0x60,0x5b,0x30,0x2d,0x31,0x5d,0x2b,0x60,0x6d,0x3f,0x3f,0x6d,0x3f,0x3f,0x1,0x0,0x6d,0x6d,0x3f,0x3f,0x6d,0x3f,0x3f,0x6d,0x3f,0x3f,0x6d,0x3f,0x3f,0x0,0x0,0x0,0x3f,0x2d,0xd6,0xa2,0x2c,0x2d,0x5b,0x60,0x3b,0x82,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x30,0x30,0x30,0x30,0x30,0x70,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x1,0x63,0x31,0x37,0x35,0x32,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x14,0x34,0x34,0x36,0x33,0x35,0x32,0x36,0x54,0x54,0x54,0x4b,0x54,0x42,0x42,0x42,0x42,0x42,0x42,0x43,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x7c,0x61, Step #5: `\327\244`[0-1]+`-2\327\244`[0-1]+`m??`[0-1]+`-2\327\244`[0-1]+`m??m??\001\000mm??m??m??m??\000\000\000?-\326\242,-[`;\202TTTTTTTT00000p0000000000\001c1752\001\000\000\000\000\000\000\0244463526TTTKTBBBBBBCBBBBBBBBBBBBBBBBBBBBB|a Step #5: artifact_prefix='./'; Test unit written to ./oom-9891e8b0b3ac007e0698a580b1474ac91080bdbf Step #5: Base64: YNekYFswLTFdK2AtMtekYFswLTFdK2BtPz9gWzAtMV0rYC0y16RgWzAtMV0rYG0/P20/PwEAbW0/P20/P20/P20/PwAAAD8t1qIsLVtgO4JUVFRUVFRUVDAwMDAwcDAwMDAwMDAwMDABYzE3NTIBAAAAAAAAFDQ0NjM1MjZUVFRLVEJCQkJCQkNCQkJCQkJCQkJCQkJCQkJCQkJCQkJ8YQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4672 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4070228335 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56234a8bc810, 0x56234aaa601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56234aaa6020,0x56234c93e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9891e8b0b3ac007e0698a580b1474ac91080bdbf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5852 processed earlier; will process 5177 files now Step #5: ==168268== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5623413b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562347a16898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5623479f95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5623479f94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5623413b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562341318b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562341313355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5623413a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562344378f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562344378f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562344378f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562344378f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562344378f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562344378f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562344378f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562344378f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562344378f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562344378f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56234660df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56234333ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562343345be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5623430f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5623430f1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5623430f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5623430f1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5623430f1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5623430f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5623479fbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562347a04928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5623479ec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562347a17112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f818b0a1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562341311b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x56,0x69,0x73,0x69,0x6f,0x44,0x6f,0x63,0x75,0x6d,0x65,0x6e,0x74,0x3e,0x3c,0x47,0x65,0x6f,0x6d,0x3e,0x3c,0x47,0x65,0x6f,0x6d,0x3e,0x3c,0x47,0x65,0x6f,0x6d,0x3e,0x3c,0x45,0x6c,0x6c,0x69,0x32,0x74,0x69,0x63,0x61,0x6c,0x41,0x63,0x72,0x54,0x6f,0x3e,0x3c,0x45,0x6c,0x6c,0x69,0x70,0x74,0x69,0x63,0x61,0x6c,0x41,0x72,0x63,0x54,0x6f,0x6d,0x3e,0x3c,0x45,0x6c,0x6c,0x69,0x32,0x74,0x69,0x63,0x61,0x6c,0x41,0x63,0x72,0x54,0x6f,0x3e,0x3c,0x45,0x6c,0x6c,0x69,0x32,0x74,0x69,0x63,0x61,0x6c,0x41,0x63,0x72,0x54,0x6f,0x3e,0x3c,0x45,0x6c,0x6c,0x69,0x70,0x74,0x69,0x63,0x61,0x6c,0x41,0x72,0x63,0x54,0x6f,0x3e,0x3c,0x47,0x65,0x6f,0x6c,0x61,0x74,0x69,0x6e,0x6d,0x3e,0x3c,0x59,0x3e,0x3c,0x45,0x6c,0x6c,0x69,0x32,0x74,0x69,0x63,0x61,0x6c,0x41,0x63,0x72,0x54,0x6f,0x3e,0x6e,0x3e,0x3c,0x53,0x74,0x3e,0x3c,0x53,0x74,0x3e, Step #5: <VisioDocument><Geom><Geom><Geom><Elli2ticalAcrTo><EllipticalArcTom><Elli2ticalAcrTo><Elli2ticalAcrTo><EllipticalArcTo><Geolatinm><Y><Elli2ticalAcrTo>n><St><St> Step #5: artifact_prefix='./'; Test unit written to ./oom-f227b334fe3fdae829a9e5e008f9cc2fb1de5cab Step #5: Base64: PFZpc2lvRG9jdW1lbnQ+PEdlb20+PEdlb20+PEdlb20+PEVsbGkydGljYWxBY3JUbz48RWxsaXB0aWNhbEFyY1RvbT48RWxsaTJ0aWNhbEFjclRvPjxFbGxpMnRpY2FsQWNyVG8+PEVsbGlwdGljYWxBcmNUbz48R2VvbGF0aW5tPjxZPjxFbGxpMnRpY2FsQWNyVG8+bj48U3Q+PFN0Pg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4673 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4070747926 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e577612810, 0x55e5777fc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e5777fc020,0x55e5796940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f227b334fe3fdae829a9e5e008f9cc2fb1de5cab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5853 processed earlier; will process 5176 files now Step #5: #1 pulse cov: 3938 ft: 3939 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4367 ft: 4925 exec/s: 0 rss: 179Mb Step #5: ==168304== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e56e1079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e57476c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e57474f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e57474f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e56e10dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e56e06eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e56e069355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e56e0ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e5710cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e5710cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e5710cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e5710cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e5710cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e5710cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e5710cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e5710cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e5710cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e5710cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e573363f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e570090b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e57009bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e56fe47c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e56fe47c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e56fe48738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e56fe47874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e56fe47874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e56fe47874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e574751abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e57475a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e574742699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e57476d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc6d5bdb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e56e067b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x20,0x47,0x0,0x0,0xe,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0xd7,0xa3,0x2a,0x73,0x20,0x34,0x20,0x28,0x20,0x3a,0x2b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x1,0x1,0x1,0x1,0x0,0x1,0xd7,0xa3,0x2a,0x73,0x20,0x34,0x20,0x28,0x1,0xd7,0xa3,0x2a,0x73,0x20,0x34,0x20,0x28,0x20,0x3a,0x2b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x1,0x1,0x1,0x81,0x0,0x1,0xd7,0xa3,0x2a,0x73,0x20,0x34,0x20,0x28,0x20,0x3a,0x2b, Step #5: / G\000\000\016\000\000\000\000\000\000\001\327\243*s 4 ( :+\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\001\001\001\001\000\001\327\243*s 4 (\001\327\243*s 4 ( :+\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\001\001\001\201\000\001\327\243*s 4 ( :+ Step #5: artifact_prefix='./'; Test unit written to ./oom-f776f2e4528ba85272628da9236ccb9e0a294ade Step #5: Base64: LyBHAAAOAAAAAAAAAdejKnMgNCAoIDorAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAQEBAQAB16MqcyA0ICgB16MqcyA0ICggOisAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEBAQGBAAHXoypzIDQgKCA6Kw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4674 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4071344201 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5641f306d810, 0x5641f325701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5641f3257020,0x5641f50ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f776f2e4528ba85272628da9236ccb9e0a294ade' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5856 processed earlier; will process 5173 files now Step #5: ==168340== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5641e9b629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5641f01c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5641f01aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5641f01aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5641e9b68d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641e9ac9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641e9ac4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5641e9b5ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5641ecb29f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5641ecb29f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5641ecb29f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5641ecb29f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5641ecb29f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5641ecb29f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5641ecb29f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5641ecb29f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5641ecb29f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5641ecb29f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5641eedbef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5641ebaebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5641ebaf6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5641eb8a2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5641eb8a2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5641eb8a3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5641eb8a2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5641eb8a2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5641eb8a2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5641f01acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5641f01b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5641f019d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5641f01c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5426e34082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641e9ac2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa,0x64,0x3a,0x5c,0x20,0xa, Step #5: o:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012d:\\ \012 Step #5: artifact_prefix='./'; Test unit written to ./oom-7cbba19bc514424077a716279960b204f569673d Step #5: Base64: bzpcIApkOlwgCmQ6XCAKZDpcIApkOlwgCmQ6XCAKZDpcIApkOlwgCmQ6XCAKZDpcIApkOlwgCmQ6XCAKZDpcIApkOlwgCmQ6XCAKZDpcIApkOlwgCmQ6XCAKZDpcIApkOlwgCmQ6XCAKZDpcIApkOlwgCmQ6XCAKZDpcIApkOlwgCmQ6XCAKZDpcIApkOlwgCmQ6XCAKZDpcIApkOlwgCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4675 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4071851670 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f440fa7810, 0x55f44119101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f441191020,0x55f4430290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7cbba19bc514424077a716279960b204f569673d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5857 processed earlier; will process 5172 files now Step #5: ==168376== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f437a9c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f43e101898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f43e0e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f43e0e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f437aa2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f437a03b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f4379fe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f437a94c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f43aa63f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f43aa63f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f43aa63f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f43aa63f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f43aa63f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f43aa63f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f43aa63f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f43aa63f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f43aa63f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f43aa63f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f43ccf8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f439a25b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f439a30be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f4397dcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f4397dcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f4397dd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f4397dc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f4397dc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f4397dc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f43e0e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f43e0ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f43e0d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f43e102112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f60a8d2e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f4379fcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x70,0x69,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xcb,0x90,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012pi=\012\012=\012=\012=\012\313\220=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-beb2c351b63d88e2130aa7cba5b7ad890a120ea2 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQpwaT0KCj0KPQo9CsuQPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9AAo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9ChA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4676 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4072388300 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560642113810, 0x5606422fd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5606422fd020,0x5606441950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/beb2c351b63d88e2130aa7cba5b7ad890a120ea2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5858 processed earlier; will process 5171 files now Step #5: ==168412== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560638c089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56063f26d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56063f2505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56063f2504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560638c0ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560638b6fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560638b6a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560638c00c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56063bbcff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56063bbcff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56063bbcff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56063bbcff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56063bbcff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56063bbcff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56063bbcff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56063bbcff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56063bbcff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56063bbcff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56063de64f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56063ab91b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56063ab9cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56063a948c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56063a948c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56063a949738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56063a948874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56063a948874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56063a948874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56063f252abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56063f25b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56063f243699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56063f26e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f39ff6b5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560638b68b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x25,0x50,0x2f,0x9,0x64,0x50,0x50,0x50,0x50,0x50,0x50,0xc,0xc,0xc,0x15,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xd,0xc,0x43,0x46,0x46,0xb,0x0,0x20,0x13,0x60,0x1f,0x50,0x50,0xc,0xc,0x4e,0xb4,0xf1,0xcb,0x0,0x5b, Step #5: `%P/\011dPPPPPP\014\014\014\025\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\015\014CFF\013\000 \023`\037PP\014\014N\264\361\313\000[ Step #5: artifact_prefix='./'; Test unit written to ./oom-78cf0c1ea973e8d90f5bd41975f9d17fff90f41e Step #5: Base64: YCVQLwlkUFBQUFBQDAwMFQsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsNDENGRgsAIBNgH1BQDAxOtPHLAFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4677 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4073042398 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c51bbb810, 0x562c51da501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c51da5020,0x562c53c3d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/78cf0c1ea973e8d90f5bd41975f9d17fff90f41e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5859 processed earlier; will process 5170 files now Step #5: #1 pulse cov: 3948 ft: 3949 exec/s: 0 rss: 175Mb Step #5: ==168448== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562c486b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c4ed15898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c4ecf85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c4ecf84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c486b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c48617b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c48612355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c486a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c4b677f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c4b677f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c4b677f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c4b677f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c4b677f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c4b677f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c4b677f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c4b677f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c4b677f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c4b677f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c4d90cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562c4a639b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562c4a644be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562c4a3f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562c4a3f0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562c4a3f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562c4a3f0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562c4a3f0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562c4a3f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c4ecfaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c4ed03928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c4eceb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c4ed16112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f49bc63e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c48610b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x0,0x0,0x0,0x0,0x0,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xae,0x32, Step #5: \000\000\000\000\000\000$$$$$$$$$$$$$$\000\000\000\000\000$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$:::::::::::::::\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\2562 Step #5: artifact_prefix='./'; Test unit written to ./oom-8de6596fa33168651f910f168bcfc2ddbd2d40bc Step #5: Base64: AAAAAAAAJCQkJCQkJCQkJCQkJCQAAAAAACQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJDo6Ojo6Ojo6Ojo6Ojo6OgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAArjI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4678 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4073601685 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c2de4cb810, 0x55c2de6b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c2de6b5020,0x55c2e054d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8de6596fa33168651f910f168bcfc2ddbd2d40bc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5861 processed earlier; will process 5168 files now Step #5: ==168484== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c2d4fc09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c2db625898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c2db6085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c2db6084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c2d4fc6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c2d4f27b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c2d4f22355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c2d4fb8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c2d7f87f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c2d7f87f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c2d7f87f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c2d7f87f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c2d7f87f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c2d7f87f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c2d7f87f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c2d7f87f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c2d7f87f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c2d7f87f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c2da21cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c2d6f49b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c2d6f54be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c2d6d00c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c2d6d00c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c2d6d01738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c2d6d00874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c2d6d00874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c2d6d00874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c2db60aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c2db613928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c2db5fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c2db626112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa37d4df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c2d4f20b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x3a,0x3a,0x7b,0x24,0x37,0x3a,0x5b,0x22,0xc3,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xb9,0xbf,0xef,0xb7,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0x8d,0xd2,0xbf,0xd1,0x24,0x69,0x6f,0x6e,0x5f,0x31,0x5f,0x30,0xef,0x9c,0x9b,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xb9,0xef,0xbf,0xbf,0xef,0xbf,0xbf,0xef,0xbf,0x92,0x73,0xc8,0xbf,0x6e,0x61,0x6d,0x6d,0x62,0x6f,0x59,0x59,0x59,0x59,0x59,0x59,0x59,0xa2,0x59,0x59,0x59,0x59,0xd9,0x59,0x59,0x59,0x59,0x59,0x59,0x59,0x59,0x59,0xff,0xff,0xff,0xff,0xff,0xff,0x52,0x73,0x28,0xff,0x6e,0x61,0x6d,0x6d,0x62,0x6f,0x38,0x22,0x5d,0x7d,0x27,0xc3,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xa1,0xff,0x2d,0xff,0x2c,0xfd,0x4,0x0,0x27,0x3a,0x3a,0x27,0xc3,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x27,0x3a,0x3a,0x44,0x45, Step #5: $3::{$7:[\"\303\277\357\277\277\357\277\277\357\277\277\357\277\277\357\271\277\357\267\277\357\277\277\357\277\215\322\277\321$ion_1_0\357\234\233\357\277\277\357\277\277\271\357\277\277\357\277\277\357\277\222s\310\277nammboYYYYYYY\242YYYY\331YYYYYYYYY\377\377\377\377\377\377Rs(\377nammbo8\"]}'\303\377\377\377\377\377\377\377\377\377\377\377\377\377\377\241\377-\377,\375\004\000'::'\303\377\377\377\377\377\377\377\377\377\377'::DE Step #5: artifact_prefix='./'; Test unit written to ./oom-6d3c01ce6984d96e9a841c89c78fc319fc32919a Step #5: Base64: JDM6OnskNzpbIsO/77+/77+/77+/77+/77m/77e/77+/77+N0r/RJGlvbl8xXzDvnJvvv7/vv7+577+/77+/77+Sc8i/bmFtbWJvWVlZWVlZWaJZWVlZ2VlZWVlZWVlZWf///////1JzKP9uYW1tYm84Il19J8P//////////////////6H/Lf8s/QQAJzo6J8P/////////////Jzo6REU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4679 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4074109695 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557dbe3da810, 0x557dbe5c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557dbe5c4020,0x557dc045c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6d3c01ce6984d96e9a841c89c78fc319fc32919a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5862 processed earlier; will process 5167 files now Step #5: ==168520== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557db4ecf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557dbb534898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557dbb5175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557dbb5174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557db4ed5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557db4e36b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557db4e31355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557db4ec7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557db7e96f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557db7e96f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557db7e96f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557db7e96f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557db7e96f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557db7e96f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557db7e96f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557db7e96f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557db7e96f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557db7e96f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557dba12bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557db6e58b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557db6e63be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557db6c0fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557db6c0fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557db6c10738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557db6c0f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557db6c0f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557db6c0f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557dbb519abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557dbb522928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557dbb50a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557dbb535112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f973500e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557db4e2fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x25,0x50,0x2f,0x9,0x64,0x50,0x50,0x50,0x50,0x50,0x6c,0x6f,0x72,0x65,0x6d,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xd,0xc,0x43,0x46,0x46,0xb,0x0,0x20,0x13,0x60,0x1f,0x50,0x50,0xc,0xc,0x4e,0xb4,0xf1,0xcb,0x0,0x5b, Step #5: `%P/\011dPPPPPlorem\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\015\014CFF\013\000 \023`\037PP\014\014N\264\361\313\000[ Step #5: artifact_prefix='./'; Test unit written to ./oom-f84653595ef044d2dfaa20df34be934af2ffa030 Step #5: Base64: YCVQLwlkUFBQUFBsb3JlbQsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsNDENGRgsAIBNgH1BQDAxOtPHLAFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4680 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4074762804 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cbd887c810, 0x55cbd8a6601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cbd8a66020,0x55cbda8fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f84653595ef044d2dfaa20df34be934af2ffa030' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5863 processed earlier; will process 5166 files now Step #5: ==168556== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cbcf3719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cbd59d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cbd59b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cbd59b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cbcf377d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cbcf2d8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cbcf2d3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cbcf369c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cbd2338f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cbd2338f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cbd2338f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cbd2338f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cbd2338f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cbd2338f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cbd2338f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cbd2338f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cbd2338f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cbd2338f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cbd45cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cbd12fab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cbd1305be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cbd10b1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cbd10b1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cbd10b2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cbd10b1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cbd10b1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cbd10b1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cbd59bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cbd59c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cbd59ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cbd59d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f33bb732082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cbcf2d1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x34,0x3c,0x74,0x65,0x78,0x74,0x3e,0x3a,0x30,0x3b,0x26,0x23,0x33,0x34,0x30,0x32,0x3b,0x26,0x23,0x37,0x34,0x30,0x36,0x3b,0x2d,0x32,0x3b,0x26,0x23,0x33,0x34,0x30,0x32,0x3b,0x26,0x23,0x37,0x34,0x30,0x36,0x3b,0x2d,0x32,0xe2,0x80,0xbf,0x3a,0x3e,0x32,0x2d,0xc2,0xb3,0x2d,0xa,0xa,0xc2,0xb3,0xe2,0x80,0x8c,0x3a,0x3e,0x20,0x26,0x23,0x32,0x31,0x30,0x35,0x3b,0x3b,0xa,0xa,0xc2,0xb3,0xe2,0x80,0xbf,0x3a,0x3a,0xa,0x2f,0xc2,0xb3,0x25,0x2d,0x34,0x33,0x20,0x74,0x3e,0x3a,0x20,0x26,0x23,0x32,0x31,0x30,0x35,0x3b,0x3b,0xa,0xa,0xc2,0xb3,0xe2,0x80,0xbf,0x3a,0x3a,0xa,0x2f,0xc2,0xb3,0x25,0x2d,0x34,0x33,0x20,0x74,0x3e,0x3a,0x30,0x32,0x3b,0x26,0x23,0x33,0x34,0x30,0x32,0x3b,0x7a,0xa,0xc2,0xb3,0x25,0x35,0x30,0x20,0x20,0x20,0x20,0x20,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg>4<text>:0;&#3402;&#7406;-2;&#3402;&#7406;-2\342\200\277:>2-\302\263-\012\012\302\263\342\200\214:> &#2105;;\012\012\302\263\342\200\277::\012/\302\263%-43 t>: &#2105;;\012\012\302\263\342\200\277::\012/\302\263%-43 t>:02;&#3402;z\012\302\263%50 </text></svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-c3df78cfe33f9ce0673904784bc7316f4c757a4d Step #5: Base64: PHN2Zz40PHRleHQ+OjA7JiMzNDAyOyYjNzQwNjstMjsmIzM0MDI7JiM3NDA2Oy0y4oC/Oj4yLcKzLQoKwrPigIw6PiAmIzIxMDU7OwoKwrPigL86OgovwrMlLTQzIHQ+OiAmIzIxMDU7OwoKwrPigL86OgovwrMlLTQzIHQ+OjAyOyYjMzQwMjt6CsKzJTUwICAgICA8L3RleHQ+PC9zdmc+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4681 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4075273751 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5569768bc810, 0x556976aa601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556976aa6020,0x55697893e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c3df78cfe33f9ce0673904784bc7316f4c757a4d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5864 processed earlier; will process 5165 files now Step #5: ==168592== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55696d3b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556973a16898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5569739f95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5569739f94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55696d3b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55696d318b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55696d313355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55696d3a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556970378f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556970378f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556970378f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556970378f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556970378f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556970378f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556970378f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556970378f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556970378f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556970378f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55697260df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55696f33ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55696f345be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55696f0f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55696f0f1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55696f0f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55696f0f1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55696f0f1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55696f0f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5569739fbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556973a04928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5569739ec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556973a17112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7bef514082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55696d311b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x62,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x5c,0x75,0x7b,0x63,0x7d,0x7d, Step #5: '\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{b}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}\\u{b}\\u{c}\\u{c}\\u{c}\\u{c}\\u{c}} Step #5: artifact_prefix='./'; Test unit written to ./oom-1fc3d1f94ea06ee8a55fc2934e12351ce4a29836 Step #5: Base64: J1x1e2N9XHV7Y31cdXtjfVx1e2N9XHV7Y31cdXtjfVx1e2N9XHV7Y31cdXtjfVx1e2J9XHV7Y31cdXtjfVx1e2N9XHV7Y31cdXtjfVx1e2N9XHV7Y31cdXtjfVx1e2N9XHV7Y31cdXtjfVx1e2N9XHV7Y31cdXtjfVx1e2N9XHV7Y31cdXtifVx1e2N9XHV7Y31cdXtjfVx1e2N9XHV7Y319 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4682 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4075774407 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c71d2d8810, 0x55c71d4c201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c71d4c2020,0x55c71f35a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1fc3d1f94ea06ee8a55fc2934e12351ce4a29836' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5865 processed earlier; will process 5164 files now Step #5: ==168628== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c713dcd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c71a432898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c71a4155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c71a4154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c713dd3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c713d34b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c713d2f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c713dc5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c716d94f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c716d94f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c716d94f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c716d94f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c716d94f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c716d94f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c716d94f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c716d94f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c716d94f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c716d94f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c719029f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c715d56b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c715d61be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c715b0dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c715b0dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c715b0e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c715b0d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c715b0d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c715b0d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c71a417abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c71a420928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c71a408699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c71a433112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd7992af082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c713d2db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x25,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7,0x20,0x7b,0x31,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x26,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x25,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7,0x20,0x7b,0x31,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d, Step #5: }{0,} {0,} {0,%{0,} {0,}}{0,} {0,}\007 {1,}s{0,} {0,}${0,} {0,} {{0,}${0,} {0,} {0,}}{0,} {0&} {0,}s{0,} {0,}${0,}%{0,} {0,}}{0,} {0,}\007 {1,}s{0,} {0,}${0,} {0,} {0,} Step #5: artifact_prefix='./'; Test unit written to ./oom-5b732b63553b77fe1bc1a022ddea9c228383e1a5 Step #5: Base64: fXswLH0gezAsfSB7MCwlezAsfSB7MCx9fXswLH0gezAsfQcgezEsfXN7MCx9IHswLH0kezAsfSB7MCx9IHt7MCx9JHswLH0gezAsfSB7MCx9fXswLH0gezAmfSB7MCx9c3swLH0gezAsfSR7MCx9JXswLH0gezAsfX17MCx9IHswLH0HIHsxLH1zezAsfSB7MCx9JHswLH0gezAsfSB7MCx9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4683 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4076283576 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f6412ec810, 0x55f6414d601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f6414d6020,0x55f64336e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5b732b63553b77fe1bc1a022ddea9c228383e1a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5866 processed earlier; will process 5163 files now Step #5: #1 pulse cov: 3897 ft: 3898 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 12347 ft: 13210 exec/s: 0 rss: 196Mb Step #5: ==168664== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f637de19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f63e446898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f63e4295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f63e4294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f637de7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f637d48b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f637d43355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f637dd9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f63ada8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f63ada8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f63ada8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f63ada8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f63ada8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f63ada8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f63ada8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f63ada8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f63ada8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f63ada8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f63d03df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f639d6ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f639d75be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f639b21c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f639b21c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f639b22738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f639b21874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f639b21874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f639b21874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f63e42babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f63e434928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f63e41c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f63e447112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa4a5440082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f637d41b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x3a,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0xd,0x2d,0xd,0x2d,0xd,0xd,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0x20,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x30,0x2f,0x30,0xa,0xa,0x33,0x3a,0x20,0x34,0x2f,0x30,0xa,0x30,0x3a,0x32,0x20,0x31,0xa,0x32,0x3a,0x33,0x20,0x33, Step #5: 1:\015- - - -\015-\015-\015-\015-\015-\015-\015\015-\015-\015\015\015-\015-\015-\015-\015-\015-\015-\015-\015-\015-\015- \015-\015-\015-\015-\015-\015-\015-\015-\015- - - - - \015-\015-\015-\015-\015-\015-\015-\015-\015-\015\015-\015-\015-\015-\015-\015-\015-\015-\015-\015-\015- - - - - - - - - - 0/0\012\0123: 4/0\0120:2 1\0122:3 3 Step #5: artifact_prefix='./'; Test unit written to ./oom-7f99134a6baef57288b1888f77d920d7650c39a0 Step #5: Base64: MToNLSAtIC0gLQ0tDS0NLQ0tDS0NLQ0NLQ0tDQ0NLQ0tDS0NLQ0tDS0NLQ0tDS0NLQ0tIA0tDS0NLQ0tDS0NLQ0tDS0NLSAtIC0gLSAtIA0tDS0NLQ0tDS0NLQ0tDS0NLQ0NLQ0tDS0NLQ0tDS0NLQ0tDS0NLQ0tIC0gLSAtIC0gLSAtIC0gLSAtIDAvMAoKMzogNC8wCjA6MiAxCjI6MyAz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4684 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4076958673 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559505329810, 0x55950551301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559505513020,0x5595073ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f99134a6baef57288b1888f77d920d7650c39a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5869 processed earlier; will process 5160 files now Step #5: ==168700== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5594fbe1e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559502483898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5595024665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5595024664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5594fbe24d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5594fbd85b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5594fbd80355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5594fbe16c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5594fede5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5594fede5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5594fede5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5594fede5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5594fede5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5594fede5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5594fede5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5594fede5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5594fede5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5594fede5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55950107af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5594fdda7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5594fddb2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5594fdb5ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5594fdb5ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5594fdb5f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5594fdb5e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5594fdb5e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5594fdb5e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559502468abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559502471928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559502459699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559502484112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f155db7d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5594fbd7eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x74,0x65,0x73,0x74,0x41,0x6c,0x6c,0x54,0x79,0x70,0x65,0x73,0x22,0x3a,0x7b,0x22,0x6f,0x6e,0x65,0x6f,0x66,0x55,0x69,0x6e,0x74,0x36,0x34,0x22,0x3a,0x22,0xe3,0x80,0xa1,0xe3,0x80,0x80,0xe2,0x88,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0x65,0x31,0x38,0x2c,0x31,0x65,0x32,0x30,0x2c,0x39,0x65,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x32,0x30,0x2c,0x31,0x32,0x31,0x39,0x2c,0x31,0x65,0x32,0x30,0x2c,0xe3,0x80,0x80,0x22, Step #5: {\"testAllTypes\":{\"oneofUint64\":\"\343\200\241\343\200\200\342\210\200\343\200\200\343\200\200e18,1e20,9eaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa20,1219,1e20,\343\200\200\" Step #5: artifact_prefix='./'; Test unit written to ./oom-3ef946f2cccc480245b12d5640e8f292916a2b1a Step #5: Base64: eyJ0ZXN0QWxsVHlwZXMiOnsib25lb2ZVaW50NjQiOiLjgKHjgIDiiIDjgIDjgIBlMTgsMWUyMCw5ZWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYTIwLDEyMTksMWUyMCzjgIAi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4685 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4077467717 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a57d67810, 0x563a57f5101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a57f51020,0x563a59de90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3ef946f2cccc480245b12d5640e8f292916a2b1a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5870 processed earlier; will process 5159 files now Step #5: ==168736== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563a4e85c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a54ec1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a54ea45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a54ea44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a4e862d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a4e7c3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a4e7be355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a4e854c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a51823f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a51823f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a51823f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a51823f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a51823f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a51823f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a51823f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a51823f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a51823f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a51823f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a53ab8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a507e5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a507f0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a5059cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a5059cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a5059d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a5059c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a5059c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a5059c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a54ea6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a54eaf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a54e97699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a54ec2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f10b5340082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a4e7bcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x24,0x24,0x24,0x24,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4e,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x43,0x46,0x46,0x20,0x5b,0x2d,0x2d,0xa,0x44,0xa,0x2d,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0xa,0x2d,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x7b,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x16,0x16,0x16,0x16,0x16,0x16,0x16,0x16,0x16,0x16,0xa,0x2d,0xa,0x73,0x2d,0x2d,0xd,0x2d,0x2d,0x42,0x45,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x5,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xae,0x70, Step #5: \000\000\000\000\000\000$$$$$$\000\000\000\000\000\000\000N \000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000--CFF [--\012D\012-\012 \012-\012 { \026\026\026\026\026\026\026\026\026\026\012-\012s--\015--BE\000\000\000\000\000\000\000\000\000\001\000\000\005\000\000\000\000\000\000\000\000\256p Step #5: artifact_prefix='./'; Test unit written to ./oom-fec1d796aa3903b941534aed3f59316df262be8e Step #5: Base64: AAAAAAAAJCQkJCQkAAAAAAAAAE4gAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAC0tQ0ZGIFstLQpECi0KICAgICAgICAKLQogICAgICAgICB7ICAgICAgIBYWFhYWFhYWFhYKLQpzLS0NLS1CRQAAAAAAAAAAAAEAAAUAAAAAAAAAAK5w Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4686 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4077983895 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dc17964810, 0x55dc17b4e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dc17b4e020,0x55dc199e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fec1d796aa3903b941534aed3f59316df262be8e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5871 processed earlier; will process 5158 files now Step #5: #1 pulse cov: 3735 ft: 3736 exec/s: 0 rss: 176Mb Step #5: ==168772== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dc0e4599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dc14abe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dc14aa15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dc14aa14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dc0e45fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dc0e3c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dc0e3bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dc0e451c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dc11420f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dc11420f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dc11420f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dc11420f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dc11420f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dc11420f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dc11420f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dc11420f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dc11420f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dc11420f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dc136b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dc103e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dc103edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dc10199c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dc10199c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dc1019a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dc10199874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dc10199874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dc10199874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dc14aa3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dc14aac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dc14a94699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dc14abf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fae2d3bd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dc0e3b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x30,0x2d,0x2d,0x2d,0x2d,0xa,0x3d,0x1d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4d,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x44,0x0,0x6e,0x20,0x4d,0x12,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: x-----BEGIN 0----\012=\035\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000LLLLLLLLLLLLLMCCCCCCCCCCCCCCCCCCCD\000n M\022\000\000\000\000\000\000\000\000\000LLLLLLLLLLLLLLCCCCCCCCLLLLLLLLLLLLLLLLLLLLL\001\000\000\000\000\000\000\000\000\000\000\000 ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-34f1687755ef07ad1592a4993f586b7d79d858cc Step #5: Base64: eC0tLS0tQkVHSU4gMC0tLS0KPR0AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAATExMTExMTExMTExMTE1DQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDRABuIE0SAAAAAAAAAAAATExMTExMTExMTExMTExDQ0NDQ0NDQ0xMTExMTExMTExMTExMTExMTExMTAEAAAAAAAAAAAAAACAtLS0tLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4687 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4078526621 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb27aaf810, 0x55bb27c9901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb27c99020,0x55bb29b310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/34f1687755ef07ad1592a4993f586b7d79d858cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5873 processed earlier; will process 5156 files now Step #5: #1 pulse cov: 4070 ft: 4071 exec/s: 0 rss: 175Mb Step #5: ==168808== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bb1e5a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb24c09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb24bec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb24bec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb1e5aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb1e50bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb1e506355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb1e59cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb2156bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb2156bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb2156bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb2156bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb2156bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb2156bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb2156bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb2156bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb2156bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb2156bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb23800f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb2052db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb20538be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb202e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb202e4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb202e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb202e4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb202e4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb202e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb24beeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb24bf7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb24bdf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb24c0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f85b8a9c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb1e504b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x13,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2b,0x6,0x7e,0x74,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6e,0x65,0x43,0x46,0x46,0x32,0x6e,0x2c, Step #5: \023\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000+\006~t\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000neCFF2n, Step #5: artifact_prefix='./'; Test unit written to ./oom-be242dc7d66b8fa5c6840fcda3730dbda2fc129b Step #5: Base64: EwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAArBn50AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABuZUNGRjJuLA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4688 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4079079256 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af6e962810, 0x55af6eb4c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af6eb4c020,0x55af709e40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/be242dc7d66b8fa5c6840fcda3730dbda2fc129b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5875 processed earlier; will process 5154 files now Step #5: ==168844== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55af654579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af6babc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af6ba9f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af6ba9f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55af6545dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55af653beb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55af653b9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55af6544fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55af6841ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55af6841ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55af6841ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55af6841ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55af6841ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55af6841ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55af6841ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55af6841ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55af6841ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55af6841ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af6a6b3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af673e0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af673ebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af67197c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af67197c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af67198738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af67197874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af67197874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af67197874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af6baa1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af6baaa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af6ba92699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af6babd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f02d23ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55af653b7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x3f,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x29,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x5c,0xde,0x99,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x3b,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x24,0x7c,0x7c,0x7c,0x24,0x7c,0x24,0x24,0x24,0x7c,0x24,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x29,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x5c,0xde,0x99,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x3b,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x29,0x29,0x7c,0x29,0x7c,0x29,0x7c, Step #5: (?:(?:?|$|$|$|$|)|$|(?:$|$|(?:(?:(?:\\\336\231|$|$|$|$|$|$|$;|$|$|$|$)|$|$|$|$|$)$|||$|$$$|$$|$|$|$|$|$|)|$|(?:$|$|(?:(?:(?:\\\336\231|$|$|$|$|$|$|$;|$|$|$|$)|$|$|$|$|$)|))|)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-f8de874ed723784b55e368f9b22eb3f8a0586b7f Step #5: Base64: KD86KD86P3wkfCR8JHwkfCl8JHwoPzokfCR8KD86KD86KD86XN6ZfCR8JHwkfCR8JHwkfCQ7fCR8JHwkfCQpfCR8JHwkfCR8JCkkfHx8JHwkJCR8JCR8JHwkfCR8JHwkfCl8JHwoPzokfCR8KD86KD86KD86XN6ZfCR8JHwkfCR8JHwkfCQ7fCR8JHwkfCQpfCR8JHwkfCR8JCl8KSl8KXwpfA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4689 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4079604019 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563108486810, 0x56310867001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563108670020,0x56310a5080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8de874ed723784b55e368f9b22eb3f8a0586b7f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5876 processed earlier; will process 5153 files now Step #5: ==168880== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5630fef7b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5631055e0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5631055c35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5631055c34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5630fef81d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5630feee2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5630feedd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5630fef73c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563101f42f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563101f42f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563101f42f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563101f42f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563101f42f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563101f42f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563101f42f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563101f42f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563101f42f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563101f42f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5631041d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563100f04b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563100f0fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563100cbbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563100cbbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563100cbc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563100cbb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563100cbb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563100cbb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5631055c5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5631055ce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5631055b6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5631055e1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1ac56d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5630feedbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0xa,0x3f,0x20,0x69,0x2,0xa,0x72,0x3d,0x73,0x65,0x66,0x0,0x0,0x3d,0x3d,0xa,0x2b,0x3d,0xa,0x3d,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x5b,0x0,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2d,0x2d,0xa,0x44,0x41,0x6e,0x4d,0xcc,0x92,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xa,0x3d,0x4a,0x3d,0xa,0x3d,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x5b,0x0,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2d,0x2d,0xa,0x44,0x41,0x6e,0x4d,0xcc,0x92,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xff, Step #5: \005-----BEGIN =\012? i\002\012r=sef\000\000==\012+=\012==\012D\012=\012=\012=\012=\012=\012=\012=\012==\012\012=\012=\012=\012=\012=[\000----\000\000\000\000\000\000\000\000\000\000\000\000\000\012--\012DAnM\314\222skip_cl\012|\000\020\012=J=\012==\012\012=\012=\012=\012=\012=[\000----\000\000\000\000\000\000\000\000\000\000\000\000\000\012--\012DAnM\314\222skip_cl\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-724107a73e676c98db1ce10a7a080017da761ace Step #5: Base64: BS0tLS0tQkVHSU4gPQo/IGkCCnI9c2VmAAA9PQorPQo9PQpECj0KPQo9Cj0KPQo9Cj0KPT0KCj0KPQo9Cj0KPVsALS0tLQAAAAAAAAAAAAAAAAAKLS0KREFuTcySc2tpcF9jbAp8ABAKPUo9Cj09Cgo9Cj0KPQo9Cj1bAC0tLS0AAAAAAAAAAAAAAAAACi0tCkRBbk3MknNraXBfY2wKfAAQ/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4690 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4080122519 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a51de59810, 0x55a51e04301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a51e043020,0x55a51fedb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/724107a73e676c98db1ce10a7a080017da761ace' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5877 processed earlier; will process 5152 files now Step #5: #1 pulse cov: 4084 ft: 4085 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4722 ft: 5135 exec/s: 0 rss: 178Mb Step #5: ==168916== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a51494e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a51afb3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a51af965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a51af964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a514954d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a5148b5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a5148b0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a514946c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a517915f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a517915f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a517915f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a517915f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a517915f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a517915f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a517915f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a517915f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a517915f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a517915f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a519baaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a5168d7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a5168e2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a51668ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a51668ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a51668f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a51668e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a51668e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a51668e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a51af98abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a51afa1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a51af89699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a51afb4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8195cd0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a5148aeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0xa,0x32,0xb,0x78,0x2e,0xa,0xa,0x78,0x6e,0x2e,0x75,0x75,0x75,0x75,0x27,0xf,0x10,0x31,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x33,0x4,0x14,0x33,0x32,0x37,0x36,0x39,0x2c,0x44,0x33,0x4,0x10,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0xe2,0x81,0x9f,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x37,0xe2,0x80,0xab,0x39,0x32,0x4,0x10,0x75,0x75,0x75,0x75,0xe2,0x80,0xa8,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x75,0x75,0x75,0x75,0x4,0x10,0x31,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x33,0x4,0x10,0x33,0x32,0x65,0x37,0x36,0x39,0x2c,0x44,0x33,0x4,0x10,0x75,0x75,0x75,0x75,0xca,0xb0,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x33,0xa,0x2d,0xa,0x3a,0xa,0x2d,0x3f,0x54,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0x32,0x39,0x35,0x75,0x75,0x75,0x75,0xca,0xb0,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0xa, Step #5: 2\0122\013x.\012\012xn.uuuu'\017\0201uuuumID3\004\02432769,D3\004\02093846346337\342\201\2374607431768211457\342\200\25392\004\020uuuu\342\200\250uuuumIDuuuu\004\0201uuuumID3\004\02032e769,D3\004\020uuuu\312\260uuuumID3\012-\012:\012-?T4294967295uuuu\312\260uuuumID\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-ed33fef242d8be8d56f1d08f9cea19ed26fc4035 Step #5: Base64: MgoyC3guCgp4bi51dXV1Jw8QMXV1dXVtSUQzBBQzMjc2OSxEMwQQOTM4NDYzNDYzMzfigZ80NjA3NDMxNzY4MjExNDU34oCrOTIEEHV1dXXigKh1dXV1bUlEdXV1dQQQMXV1dXVtSUQzBBAzMmU3NjksRDMEEHV1dXXKsHV1dXVtSUQzCi0KOgotP1Q0Mjk0OTY3Mjk1dXV1dcqwdXV1dW1JRAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4691 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4080714222 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c9ce144810, 0x55c9ce32e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c9ce32e020,0x55c9d01c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ed33fef242d8be8d56f1d08f9cea19ed26fc4035' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5880 processed earlier; will process 5149 files now Step #5: ==168952== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c9c4c399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c9cb29e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9cb2815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9cb2814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9c4c3fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9c4ba0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c9c4b9b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9c4c31c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c9c7c00f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c9c7c00f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c9c7c00f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c9c7c00f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c9c7c00f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c9c7c00f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c9c7c00f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c9c7c00f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c9c7c00f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c9c7c00f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c9c9e95f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9c6bc2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9c6bcdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c9c6979c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c9c6979c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c9c697a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c9c6979874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c9c6979874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c9c6979874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c9cb283abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c9cb28c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c9cb274699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c9cb29f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f477b807082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c9c4b99b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x24,0x7b,0x31,0x2c,0x5e,0x7b,0x31,0x2c,0x7d,0x24,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x24,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x24,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x0,0xa4,0x5e,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x24,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x24,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x24,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x24,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d,0x24,0x7b,0x31,0x2c,0x7d,0x5e,0x7b,0x31,0x2c,0x7d, Step #5: ^{1,}^{1,}${1,^{1,}${1,}^{1,}^{1,}^{1,}${1,}^{1,}^{1,}${1,}^{1\000\244^{1,}^{1,}${1,}^{1,}^{1,}^{1,}${1,}^{1,}^{1,}^{1,}${1,}^{1,}^{1,}^{1,}${1,}^{1,}^{1,}^{1,}${1,}^{1,} Step #5: artifact_prefix='./'; Test unit written to ./oom-fd29b3a06a88af82f30b235cf40d71187f1bc190 Step #5: Base64: XnsxLH1eezEsfSR7MSxeezEsfSR7MSx9XnsxLH1eezEsfV57MSx9JHsxLH1eezEsfV57MSx9JHsxLH1eezEApF57MSx9XnsxLH0kezEsfV57MSx9XnsxLH1eezEsfSR7MSx9XnsxLH1eezEsfV57MSx9JHsxLH1eezEsfV57MSx9XnsxLH0kezEsfV57MSx9XnsxLH1eezEsfSR7MSx9XnsxLH0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4692 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4081233580 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c80baa8810, 0x55c80bc9201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c80bc92020,0x55c80db2a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fd29b3a06a88af82f30b235cf40d71187f1bc190' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5881 processed earlier; will process 5148 files now Step #5: ==168988== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c80259d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c808c02898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c808be55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c808be54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c8025a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c802504b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c8024ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c802595c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c805564f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c805564f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c805564f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c805564f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c805564f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c805564f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c805564f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c805564f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c805564f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c805564f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c8077f9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c804526b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c804531be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c8042ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c8042ddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c8042de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c8042dd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c8042dd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c8042dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c808be7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c808bf0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c808bd8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c808c03112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff485733082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c8024fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3e,0xa,0x20,0x29,0xe2,0x80,0xa9,0x20,0x32,0xe2,0x80,0xa9,0x20,0x32,0xe2,0x80,0xa9,0x20,0x31,0xe2,0x80,0xa9,0x20,0x35,0xe2,0x80,0xa9,0x20,0x31,0xe2,0x80,0xa9,0x20,0x34,0xe2,0x80,0xa9,0x20,0x30,0xe2,0x80,0xa9,0x20,0x9,0xe2,0x80,0xa9,0x20,0x38,0xe2,0x80,0xa9,0x20,0x34,0xe2,0x80,0xa9,0x20,0x32,0xe2,0x80,0xa9,0x20,0x35,0xe2,0x80,0xa9,0x20,0x30,0xe2,0x80,0xa9,0x20,0x29,0xe2,0x80,0xa9,0x20,0x33,0xe2,0x80,0xa9,0x20,0x33,0xe2,0x80,0xa9,0x20,0x31,0xe2,0x80,0xa9,0x20,0x35,0xe2,0x80,0xa9,0x20,0x31,0xe2,0x80,0xa9,0x20,0x34,0xe2,0x80,0xa9,0x20,0x30,0xe2,0x80,0xa9,0x20,0x29,0xe2,0x80,0xa9,0x20,0x38,0xe2,0x80,0xa9,0x20,0x34,0xe2,0x80,0xa9,0x20,0x31,0xe2,0x80,0xa9,0x20,0x35,0xe2,0x80,0xa9,0x20,0x30,0xe2,0x80,0xa9,0x20,0x35,0xe2,0x80,0xa9,0x20,0x30,0xe2,0x80,0xa9,0x20,0x35,0xe2,0x80,0xa9,0x20,0x30,0xe2,0x80,0xa9,0x20,0x3f, Step #5: >\012 )\342\200\251 2\342\200\251 2\342\200\251 1\342\200\251 5\342\200\251 1\342\200\251 4\342\200\251 0\342\200\251 \011\342\200\251 8\342\200\251 4\342\200\251 2\342\200\251 5\342\200\251 0\342\200\251 )\342\200\251 3\342\200\251 3\342\200\251 1\342\200\251 5\342\200\251 1\342\200\251 4\342\200\251 0\342\200\251 )\342\200\251 8\342\200\251 4\342\200\251 1\342\200\251 5\342\200\251 0\342\200\251 5\342\200\251 0\342\200\251 5\342\200\251 0\342\200\251 ? Step #5: artifact_prefix='./'; Test unit written to ./oom-d0c6eeac205a8a5c0f4c358961783486addee6bf Step #5: Base64: PgogKeKAqSAy4oCpIDLigKkgMeKAqSA14oCpIDHigKkgNOKAqSAw4oCpIAnigKkgOOKAqSA04oCpIDLigKkgNeKAqSAw4oCpICnigKkgM+KAqSAz4oCpIDHigKkgNeKAqSAx4oCpIDTigKkgMOKAqSAp4oCpIDjigKkgNOKAqSAx4oCpIDXigKkgMOKAqSA14oCpIDDigKkgNeKAqSAw4oCpID8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4693 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4081734167 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561bf4c68810, 0x561bf4e5201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561bf4e52020,0x561bf6cea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d0c6eeac205a8a5c0f4c358961783486addee6bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5882 processed earlier; will process 5147 files now Step #5: #1 pulse cov: 11986 ft: 11987 exec/s: 0 rss: 195Mb Step #5: ==169024== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561beb75d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561bf1dc2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561bf1da55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561bf1da54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561beb763d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561beb6c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561beb6bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561beb755c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561bee724f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561bee724f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561bee724f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561bee724f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561bee724f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561bee724f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561bee724f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561bee724f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561bee724f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561bee724f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561bf09b9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561bed6e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561bed6f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561bed49dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561bed49dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561bed49e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561bed49d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561bed49d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561bed49d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561bf1da7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561bf1db0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561bf1d98699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561bf1dc3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5aa34b6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561beb6bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0xa,0x7b,0x22,0xe0,0xb9,0x84,0x22,0x3a,0x7b,0x5b,0x26,0x5f,0x20,0x5b,0x38,0x2c,0x32,0x65,0x2d,0x33,0x33,0x31,0x2c,0x2d,0x30,0x65,0x65,0x30,0x2c,0x32,0x65,0x2d,0x33,0x33,0x30,0x2c,0x2d,0x32,0x31,0x2c,0x32,0x65,0x2d,0x33,0x33,0x30,0x2c,0x65,0x39,0x2c,0x31,0x65,0x2d,0x33,0x33,0x30,0x2c,0x39,0x2c,0x32,0x65,0x2d,0x33,0x33,0x30,0x2c,0x32,0x65,0x2d,0x33,0x33,0x30,0x2c,0x32,0x65,0x2d,0x33,0x33,0x30,0x2c,0x68,0x2c,0x32,0x65,0x2d,0x33,0x33,0x30,0x2c,0x2d,0x32,0x32,0x65,0x32,0x37,0x2c,0x32,0x65,0x39,0x5d,0x2c,0x2a,0x5f,0x20,0x2c,0x2a,0x5f,0x2c,0x2a,0x5f,0x2c,0x31,0x2c,0x2a,0x5f,0x2c,0x2a,0x5f,0x2c,0x2a,0x5f,0x2c,0x2a,0x5f,0x2c,0x30,0x5f,0x2c,0x2a,0x5f,0x2c,0x2a,0x5f,0x2c,0x2a,0x5f,0x2c,0x2a,0x5f,0x2c,0x2a,0x5f,0x2c,0x2a,0x5f,0x2c,0x32,0x5f,0x2c,0x2b,0x5f,0x2c,0x2a,0x5f,0x5d,0x7d,0x7d,0xa,0x2d,0x2d,0x2d, Step #5: ---\012{\"\340\271\204\":{[&_ [8,2e-331,-0ee0,2e-330,-21,2e-330,e9,1e-330,9,2e-330,2e-330,2e-330,h,2e-330,-22e27,2e9],*_ ,*_,*_,1,*_,*_,*_,*_,0_,*_,*_,*_,*_,*_,*_,2_,+_,*_]}}\012--- Step #5: artifact_prefix='./'; Test unit written to ./oom-306a7f75d2b5d24f049a0c6195744d349dd54120 Step #5: Base64: LS0tCnsi4LmEIjp7WyZfIFs4LDJlLTMzMSwtMGVlMCwyZS0zMzAsLTIxLDJlLTMzMCxlOSwxZS0zMzAsOSwyZS0zMzAsMmUtMzMwLDJlLTMzMCxoLDJlLTMzMCwtMjJlMjcsMmU5XSwqXyAsKl8sKl8sMSwqXywqXywqXywqXywwXywqXywqXywqXywqXywqXywqXywyXywrXywqX119fQotLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4694 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4082319182 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55911b69b810, 0x55911b88501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55911b885020,0x55911d71d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/306a7f75d2b5d24f049a0c6195744d349dd54120' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5884 processed earlier; will process 5145 files now Step #5: ==169060== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5591121909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5591187f5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5591187d85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5591187d84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559112196d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5591120f7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5591120f2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559112188c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559115157f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559115157f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559115157f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559115157f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559115157f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559115157f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559115157f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559115157f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559115157f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559115157f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5591173ecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559114119b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559114124be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559113ed0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559113ed0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559113ed1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559113ed0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559113ed0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559113ed0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5591187daabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5591187e3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5591187cb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5591187f6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1ab1e2c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5591120f0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x24,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x30,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x32,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x3a,0x7b,0x24,0x31,0x3a,0x7b,0x24,0x31,0x3a,0x5b,0x22,0x22,0x5d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x3a,0x3a,0x44,0xb8, Step #5: {$:{$1:{$0:{$1:{$1:{$1:{$1:{$1:{$1:{$1:{$1:{$1:{$1:{$1:{$1:{$1:{$1:{$2:{$1:{$:{$1:{$1:{$1:{$1:{$1:{$1:{$1:{$1:{$1:{$:{$1:{$1:[\"\"]}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}::D\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-e6b50e04181e96e2e82404d446ba1020f18348c7 Step #5: Base64: eyQ6eyQxOnskMDp7JDE6eyQxOnskMTp7JDE6eyQxOnskMTp7JDE6eyQxOnskMTp7JDE6eyQxOnskMTp7JDE6eyQxOnskMjp7JDE6eyQ6eyQxOnskMTp7JDE6eyQxOnskMTp7JDE6eyQxOnskMTp7JDE6eyQ6eyQxOnskMTpbIiJdfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fTo6RLg= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4695 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4082839101 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e0b0585810, 0x55e0b076f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e0b076f020,0x55e0b26070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e6b50e04181e96e2e82404d446ba1020f18348c7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5885 processed earlier; will process 5144 files now Step #5: ==169096== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e0a707a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e0ad6df898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e0ad6c25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e0ad6c24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e0a7080d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e0a6fe1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e0a6fdc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e0a7072c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e0aa041f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e0aa041f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e0aa041f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e0aa041f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e0aa041f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e0aa041f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e0aa041f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e0aa041f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e0aa041f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e0aa041f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e0ac2d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e0a9003b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e0a900ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e0a8dbac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e0a8dbac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e0a8dbb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e0a8dba874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e0a8dba874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e0a8dba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e0ad6c4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e0ad6cd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e0ad6b5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e0ad6e0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efda55f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e0a6fdab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3b,0x0,0xa,0x2d,0x63,0x72,0x79,0x73,0x74,0x61,0xa,0xd8,0x80,0x4,0x0,0x3b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2d,0x20,0x0,0x0,0x4f,0x6c,0x31,0x2b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2d,0x20,0x0,0x0,0x4f,0x6c,0x31,0x2b,0x34,0x27,0x0,0x3a,0xd8,0x80,0x0,0xa,0xd8,0x80,0x4,0x0,0x3b,0x0,0xa,0x2d,0x20,0x0,0x0,0x4f,0x59,0x3e,0x2d,0x31,0x2b,0x34,0x27,0x0,0x3a,0xd8,0x80,0x0,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x4,0x2b,0x37,0x31,0x37,0x37,0x37,0x2e, Step #5: /\000\000\000\000\000\000\000\000\000\000\000\000;\000\012-crysta\012\330\200\004\000;\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012- \000\000Ol1+\000\000\000\000\000\000\000\000\012- \000\000Ol1+4'\000:\330\200\000\012\330\200\004\000;\000\012- \000\000OY>-1+4'\000:\330\200\0007777777777777777777\004+71777. Step #5: artifact_prefix='./'; Test unit written to ./oom-e55320eb74f6ae6cbe96e9de6c2b282302395615 Step #5: Base64: LwAAAAAAAAAAAAAAADsACi1jcnlzdGEK2IAEADsAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAotIAAAT2wxKwAAAAAAAAAACi0gAABPbDErNCcAOtiAAArYgAQAOwAKLSAAAE9ZPi0xKzQnADrYgAA3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3BCs3MTc3Ny4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4696 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4083361090 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f959bb2810, 0x55f959d9c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f959d9c020,0x55f95bc340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e55320eb74f6ae6cbe96e9de6c2b282302395615' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5886 processed earlier; will process 5143 files now Step #5: ==169132== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f9506a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f956d0c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f956cef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f956cef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f9506add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f95060eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f950609355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f95069fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f95366ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f95366ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f95366ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f95366ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f95366ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f95366ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f95366ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f95366ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f95366ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f95366ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f955903f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f952630b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f95263bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f9523e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f9523e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f9523e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f9523e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f9523e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f9523e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f956cf1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f956cfa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f956ce2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f956d0d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ce377f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f950607b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2e,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3b,0x0,0xa,0x2d,0x63,0x72,0x79,0x73,0x74,0x61,0xa,0xd8,0x80,0x4,0x0,0x3b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2a,0x2a,0xd7,0xa9,0x28,0x2e,0x2e,0x1,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x30,0x2e,0x2e,0x2e,0x2e,0x30,0x0,0x0,0x43,0x43,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x22,0x31,0x8,0x2a,0x2a,0xd7,0xa9,0x28,0x2e,0x2e,0x1,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x30,0x2e,0x2e,0x2e,0x2e,0x30,0x0,0x0,0x43,0x43,0x9,0x1,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x4,0x2b,0x33,0x35,0x38,0x38,0x38,0x2e, Step #5: /.7777777777777\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000;\000\012-crysta\012\330\200\004\000;\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000**\327\251(..\001........0....0\000\000CC****************\000\"1\010**\327\251(..\001........0....0\000\000CC\011\001777777777\004+35888. Step #5: artifact_prefix='./'; Test unit written to ./oom-88b0839b704c527809c9629b6d861a39d0b2c56a Step #5: Base64: Ly43Nzc3Nzc3Nzc3Nzc3AAAAAAAAAAAAAAAAAAAAOwAKLWNyeXN0YQrYgAQAOwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACoq16koLi4BLi4uLi4uLi4wLi4uLjAAAENDKioqKioqKioqKioqKioqKgAiMQgqKtepKC4uAS4uLi4uLi4uMC4uLi4wAABDQwkBNzc3Nzc3Nzc3BCszNTg4OC4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4697 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4083878214 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b43add7810, 0x55b43afc101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b43afc1020,0x55b43ce590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88b0839b704c527809c9629b6d861a39d0b2c56a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5887 processed earlier; will process 5142 files now Step #5: ==169168== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b4318cc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b437f31898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b437f145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b437f144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b4318d2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b431833b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b43182e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b4318c4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b434893f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b434893f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b434893f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b434893f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b434893f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b434893f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b434893f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b434893f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b434893f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b434893f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b436b28f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b433855b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b433860be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b43360cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b43360cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b43360d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b43360c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b43360c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b43360c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b437f16abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b437f1f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b437f07699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b437f32112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc9d8c06082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b43182cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x32,0x2e,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x32,0x35,0x2f,0x10,0x2e,0x2f,0x73,0x20,0x37,0x20,0x30,0x20,0x32,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x10,0x20,0x32,0x10,0x2e,0x2f,0x2d,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x3f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x24, Step #5: $\177]2.2147483625/\020./s 7 0 2[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[\020 2\020./-\177\177\177\177\177\177\177\177\177\177\177\177\177?\177\177o\000\000C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-ca338c5ffa258fe7fa12b8491e6b18ba35eb2b08 Step #5: Base64: JH9dMi4yMTQ3NDgzNjI1LxAuL3MgNyAwIDJbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1sQIDIQLi8tf39/f39/f39/f39/fz9/f28AAEMk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4698 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4084397694 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5654ed908810, 0x5654edaf201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5654edaf2020,0x5654ef98a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca338c5ffa258fe7fa12b8491e6b18ba35eb2b08' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5888 processed earlier; will process 5141 files now Step #5: ==169204== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5654e43fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5654eaa62898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5654eaa455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5654eaa454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5654e4403d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5654e4364b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5654e435f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5654e43f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5654e73c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5654e73c4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5654e73c4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5654e73c4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5654e73c4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5654e73c4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5654e73c4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5654e73c4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5654e73c4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5654e73c4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5654e9659f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5654e6386b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5654e6391be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5654e613dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5654e613dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5654e613e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5654e613d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5654e613d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5654e613d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5654eaa47abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5654eaa50928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5654eaa38699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5654eaa63112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb9f0061082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5654e435db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x2d,0x54,0x79,0x70,0x65,0x3a,0x61,0x70,0x70,0x6c,0x69,0x63,0x61,0x74,0x69,0x6f,0x6e,0x2f,0x70,0x6b,0x63,0x73,0x37,0x2d,0x6d,0x69,0x6d,0x65,0xa,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa, Step #5: Content-Type:application/pkcs7-mime\012\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-a6e5b73ef875ea43ab6199ac600719f59164310c Step #5: Base64: Q29udGVudC1UeXBlOmFwcGxpY2F0aW9uL3BrY3M3LW1pbWUKCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4699 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4084952781 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5556063fa810, 0x5556065e401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5556065e4020,0x55560847c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a6e5b73ef875ea43ab6199ac600719f59164310c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5889 processed earlier; will process 5140 files now Step #5: ==169240== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5555fceef9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555603554898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556035375dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556035374fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5555fcef5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5555fce56b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5555fce51355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5555fcee7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5555ffeb6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5555ffeb6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5555ffeb6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5555ffeb6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5555ffeb6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5555ffeb6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5555ffeb6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5555ffeb6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5555ffeb6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5555ffeb6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55560214bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5555fee78b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5555fee83be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5555fec2fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5555fec2fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5555fec30738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5555fec2f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5555fec2f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5555fec2f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555603539abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555603542928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55560352a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555603555112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb08709f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5555fce4fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x69,0x66,0x31,0x30,0x29,0x29,0x29,0x29,0xd7,0xa9,0x28,0x30,0x9,0x37,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x0,0xa,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x21,0x29,0x74,0x0,0x10,0x0,0x0,0x0,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: !if10))))\327\251(0\0117^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\000\012^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^!)t\000\020\000\000\000\004\000\000\000\000\000\000\000\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-157e656c75e633bd8251168d40cc9edf7d0e0ec5 Step #5: Base64: IWlmMTApKSkp16koMAk3Xl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eAApeXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXiEpdAAQAAAABAAAAAAAAAAAAAAAAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4700 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4085472364 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56157615d810, 0x56157634701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561576347020,0x5615781df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/157e656c75e633bd8251168d40cc9edf7d0e0ec5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5890 processed earlier; will process 5139 files now Step #5: ==169276== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56156cc529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5615732b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56157329a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56157329a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56156cc58d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56156cbb9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56156cbb4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56156cc4ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56156fc19f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56156fc19f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56156fc19f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56156fc19f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56156fc19f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56156fc19f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56156fc19f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56156fc19f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56156fc19f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56156fc19f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561571eaef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56156ebdbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56156ebe6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56156e992c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56156e992c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56156e993738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56156e992874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56156e992874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56156e992874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56157329cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5615732a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56157328d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5615732b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8467900082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56156cbb2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x3d,0x79,0x0,0x0,0x0,0x0,0x29,0x24,0x7e,0x24,0x3d,0x7e,0x2d,0x3d,0x3d,0x3b,0x54,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x5b,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x54,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3b,0x54,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x5b,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x54,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x44,0x1,0x79,0x0,0x0,0x0,0x0,0x54,0x24, Step #5: ~$=y\000\000\000\000)$~$=~-==;T\012=\012=\012=\012=\012=\012=\012=\012=\012=[\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=T\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000;T\012=\012=\012=\012=\012=\012=\012=\012=\012=[\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=T\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000D\001y\000\000\000\000T$ Step #5: artifact_prefix='./'; Test unit written to ./oom-547f4fe1e707683dc87049deab76a3b2bdd5ae10 Step #5: Base64: fiQ9eQAAAAApJH4kPX4tPT07VAo9Cj0KPQo9Cj0KPQo9Cj0KPVsKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj1UAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA7VAo9Cj0KPQo9Cj0KPQo9Cj0KPVsKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj1UAAAAAAAAAAAAAAAAAAAARAF5AAAAAFQk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4701 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4085990024 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558414044810, 0x55841422e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55841422e020,0x5584160c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/547f4fe1e707683dc87049deab76a3b2bdd5ae10' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5891 processed earlier; will process 5138 files now Step #5: #1 pulse cov: 12011 ft: 12012 exec/s: 0 rss: 194Mb Step #5: #2 pulse cov: 12641 ft: 13533 exec/s: 0 rss: 197Mb Step #5: ==169312== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55840ab399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55841119e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5584111815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5584111814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55840ab3fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55840aaa0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55840aa9b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55840ab31c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55840db00f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55840db00f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55840db00f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55840db00f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55840db00f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55840db00f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55840db00f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55840db00f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55840db00f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55840db00f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55840fd95f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55840cac2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55840cacdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55840c879c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55840c879c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55840c87a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55840c879874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55840c879874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55840c879874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558411183abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55841118c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558411174699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55841119f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f69dee47082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55840aa99b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x68,0x54,0x74,0x70,0x3a,0xed,0x8d,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x9e,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x9d,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x82,0x95,0xcd,0x95,0xed,0x91,0x95,0xcd,0x94,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xec,0x95,0x95,0xcd,0x95,0xed,0x91,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x94,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x8b,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x96,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95,0xed,0x95,0x95,0xcd,0x95, Step #5: hTtp:\355\215\225\315\225\355\225\225\315\236\355\225\225\315\225\355\225\225\315\225\355\225\225\315\225\355\235\225\315\225\355\225\225\315\225\355\225\225\315\225\355\225\225\315\225\355\225\225\315\225\355\202\225\315\225\355\221\225\315\224\355\225\225\315\225\355\225\225\315\225\355\225\225\315\225\355\225\225\315\225\355\225\225\315\225\354\225\225\315\225\355\221\225\315\225\355\225\225\315\225\355\224\225\315\225\355\225\225\315\225\355\225\225\315\225\355\225\225\315\225\355\225\213\315\225\355\225\225\315\225\355\225\226\315\225\355\225\225\315\225\355\225\225\315\225\355\225\225\315\225\355\225\225\315\225\355\225\225\315\225 Step #5: artifact_prefix='./'; Test unit written to ./oom-d7a600523c55d0bec6267efc3adad328b2b53e6d Step #5: Base64: aFR0cDrtjZXNle2Vlc2e7ZWVzZXtlZXNle2Vlc2V7Z2VzZXtlZXNle2Vlc2V7ZWVzZXtlZXNle2Clc2V7ZGVzZTtlZXNle2Vlc2V7ZWVzZXtlZXNle2Vlc2V7JWVzZXtkZXNle2Vlc2V7ZSVzZXtlZXNle2Vlc2V7ZWVzZXtlYvNle2Vlc2V7ZWWzZXtlZXNle2Vlc2V7ZWVzZXtlZXNle2Vlc2V Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4702 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4086639137 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fd6817d810, 0x55fd6836701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fd68367020,0x55fd6a1ff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d7a600523c55d0bec6267efc3adad328b2b53e6d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5895 processed earlier; will process 5134 files now Step #5: ==169348== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fd5ec729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fd652d7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fd652ba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fd652ba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fd5ec78d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fd5ebd9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fd5ebd4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fd5ec6ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fd61c39f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fd61c39f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fd61c39f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fd61c39f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fd61c39f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fd61c39f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fd61c39f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fd61c39f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fd61c39f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fd61c39f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fd63ecef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fd60bfbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fd60c06be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fd609b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fd609b2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fd609b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fd609b2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fd609b2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fd609b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fd652bcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fd652c5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fd652ad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fd652d8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffaf7106082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fd5ebd2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x20,0x1,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x7a,0x40,0x3a,0x20,0x1,0x0,0x8,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xfd,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x7a,0x40,0x3a,0x20,0x1,0x0,0x8,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x25,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x2b, Step #5: / \001\000\010\000\000\000\000\000\010\000\000\000\000\000\010\000z@: \001\000\010-BEGIN -\000-----BEGIN -\000----\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\375\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000-BEGIN -\000-----B\000\010\000\000\000\000\000\010\000z@: \001\000\010-BEGIN -\000-----BEGIN -\000%----\012---\000\000\000\000+ Step #5: artifact_prefix='./'; Test unit written to ./oom-44d894c15c8fd7de6f89dd872f66afc693a78a7b Step #5: Base64: LyABAAgAAAAAAAgAAAAAAAgAekA6IAEACC1CRUdJTiAtAC0tLS0tQkVHSU4gLQAtLS0tAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD9AAAAAAAAAAAAAAAAAAAAAAAAAAAALUJFR0lOIC0ALS0tLS1CAAgAAAAAAAgAekA6IAEACC1CRUdJTiAtAC0tLS0tQkVHSU4gLQAlLS0tLQotLS0AAAAAKw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4703 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4087151044 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dffb5d9810, 0x55dffb7c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dffb7c3020,0x55dffd65b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/44d894c15c8fd7de6f89dd872f66afc693a78a7b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5896 processed earlier; will process 5133 files now Step #5: ==169384== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dff20ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dff8733898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dff87165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dff87164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dff20d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dff2035b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dff2030355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dff20c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dff5095f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dff5095f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dff5095f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dff5095f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dff5095f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dff5095f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dff5095f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dff5095f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dff5095f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dff5095f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dff732af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dff4057b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dff4062be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dff3e0ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dff3e0ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dff3e0f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dff3e0e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dff3e0e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dff3e0e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dff8718abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dff8721928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dff8709699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dff8734112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fabed8c8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dff202eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e,0x60,0x25,0x50,0x2f,0x9,0x64,0x50,0x50,0x50,0x50,0x50,0x50,0xc,0xc,0xc,0x15,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0x5f,0xb,0xb,0xb,0xb,0x77,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xd,0xc,0x43,0x46,0x46,0xb,0x0,0x20,0x13,0x60,0x1f,0x50,0x50,0xc,0xc,0x4e,0xb4,0xf1,0xcb,0x0,0x5b, Step #5: ~~~`%P/\011dPPPPPP\014\014\014\025\013\013\013\013\013\013\013\013\013_\013\013\013\013w\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\015\014CFF\013\000 \023`\037PP\014\014N\264\361\313\000[ Step #5: artifact_prefix='./'; Test unit written to ./oom-1e57f8842f6659cdeaef0ada9f487f7792b70dea Step #5: Base64: fn5+YCVQLwlkUFBQUFBQDAwMFQsLCwsLCwsLC18LCwsLdwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCw0MQ0ZGCwAgE2AfUFAMDE608csAWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4704 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4087808402 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3d450b810, 0x55a3d46f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3d46f5020,0x55a3d658d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e57f8842f6659cdeaef0ada9f487f7792b70dea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5897 processed earlier; will process 5132 files now Step #5: ==169420== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a3cb0009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3d1665898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3d16485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3d16484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3cb006d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a3caf67b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a3caf62355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3caff8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a3cdfc7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a3cdfc7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a3cdfc7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a3cdfc7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a3cdfc7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a3cdfc7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a3cdfc7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a3cdfc7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a3cdfc7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a3cdfc7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3d025cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3ccf89b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3ccf94be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3ccd40c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3ccd40c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3ccd41738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3ccd40874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3ccd40874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3ccd40874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a3d164aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a3d1653928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3d163b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3d1666112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4103dce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a3caf60b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x66,0x74,0x70,0x3a,0x2d,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0x7b,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0x7b,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0x7b,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x94,0xcd,0x84,0xcd,0x84,0x7b,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x95,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x7b,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x95,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x7b,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: \016ftp:-\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\224\315\204\315\204{\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\224\315\204\315\204{\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\224\315\204\315\204{\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\224\315\204\315\204{\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\225\315\204\315\204\315\204{\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\225\315\204\315\204\315\204{\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-a017d2e1398dc92a9ddace094c75627e0ffcedcd Step #5: Base64: DmZ0cDotzYTNhM2EzYTNhM2EzYTNhM2UzYTNhHvNhM2EzYTNhM2EzYTNhM2EzZTNhM2Ee82EzYTNhM2EzYTNhM2EzYTNlM2EzYR7zYTNhM2EzYTNhM2EzYTNhM2UzYTNhHvNhM2EzYTNhM2EzYTNhM2VzYTNhM2Ee82EzYTNhM2EzYTNhM2EzZXNhM2EzYR7zYTNhM2EzYTNhM2EzYTNhM2EzYTNhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4705 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4088321153 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643c4340810, 0x5643c452a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643c452a020,0x5643c63c20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a017d2e1398dc92a9ddace094c75627e0ffcedcd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5898 processed earlier; will process 5131 files now Step #5: #1 pulse cov: 4182 ft: 4183 exec/s: 0 rss: 176Mb Step #5: ==169456== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643bae359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643c149a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643c147d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643c147d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643bae3bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643bad9cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643bad97355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643bae2dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643bddfcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643bddfcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643bddfcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643bddfcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643bddfcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643bddfcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643bddfcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643bddfcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643bddfcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643bddfcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643c0091f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643bcdbeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643bcdc9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643bcb75c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643bcb75c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643bcb76738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643bcb75874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643bcb75874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643bcb75874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643c147fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643c1488928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643c1470699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643c149b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3206cb9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643bad95b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x20,0x1,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x7a,0x40,0x3a,0x20,0x1,0x0,0x8,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x7a,0x40,0x3a,0x20,0x1,0x0,0x8,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x0,0x25,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x2b, Step #5: / \001\000\010\000\000\000\000\000\010\000\000\000\000\000\010\000z@: \001\000\010-BEGIN -\000-----BEGIN -\000----\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000-BEGIN -\000-----B\000\010\000\000\000\000\000\010\000z@: \001\000\010-BEGIN -\000-----BEGIN -\000%----\012---\000\000\000\000+ Step #5: artifact_prefix='./'; Test unit written to ./oom-c0a7c94bed9b0f5f96325d8906486902e0de65c8 Step #5: Base64: LyABAAgAAAAAAAgAAAAAAAgAekA6IAEACC1CRUdJTiAtAC0tLS0tQkVHSU4gLQAtLS0tAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALUJFR0lOIC0ALS0tLS1CAAgAAAAAAAgAekA6IAEACC1CRUdJTiAtAC0tLS0tQkVHSU4gLQAlLS0tLQotLS0AAAAAKw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4706 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4088869404 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5582266ed810, 0x5582268d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5582268d7020,0x55822876f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c0a7c94bed9b0f5f96325d8906486902e0de65c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5900 processed earlier; will process 5129 files now Step #5: #1 pulse cov: 3564 ft: 3565 exec/s: 0 rss: 176Mb Step #5: ==169492== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55821d1e29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558223847898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55822382a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55822382a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55821d1e8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55821d149b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55821d144355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55821d1dac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5582201a9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5582201a9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5582201a9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5582201a9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5582201a9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5582201a9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5582201a9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5582201a9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5582201a9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5582201a9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55822243ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55821f16bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55821f176be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55821ef22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55821ef22c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55821ef23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55821ef22874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55821ef22874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55821ef22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55822382cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558223835928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55822381d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558223848112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3f3442f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55821d142b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x2d,0x3d,0x3e,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x32,0x2d,0x5c,0x5c,0x5c,0x3d,0x37,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x3d,0x37,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0x5c,0xae,0x1c,0xde,0xae,0x2d,0x4c,0x5f,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x3d,0x37,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x4c,0x43,0xb2,0xb2,0xb2,0xb2,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0xde,0xae,0x21,0xde,0xae,0x2d,0x5c,0x5c,0x5c,0x5c,0x5c,0xae,0x21,0xde,0xae,0x2d,0x4c,0x5c,0x5c,0x5c,0xde,0xae,0x21, Step #5: =-=>\336\256!\336\256-\\\\\\\\\336\256!\336\2562-\\\\\\=7\\\\\\\336\256!\336\256-\\\\\\=7\000\000\000\000\000\000\000\336\256-\\\\\\\\\336\256!\336\256-\\\\\\\\\\\256\034\336\256-L_\\\\\336\256!\336\256-\\\\\\=7\000\000\000\000\000\000\000\336\256-\\\\\\\\\336\256!\336\256-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\LC\262\262\262\262$\000\000\000\000\000\000\000\336\256-\\\\\\\\\336\256!\336\256-\\\\\\\\\\\256!\336\256-L\\\\\\\336\256! Step #5: artifact_prefix='./'; Test unit written to ./oom-de0e9e616d83dbb7396953b60a80c52d3d16256c Step #5: Base64: PS09Pt6uId6uLVxcXFzeriHerjItXFxcPTdcXFzeriHeri1cXFw9NwAAAAAAAADeri1cXFxc3q4h3q4tXFxcXFyuHN6uLUxfXFzeriHeri1cXFw9NwAAAAAAAADeri1cXFxc3q4h3q4tXFxcXFxcXFxcXFxcXFxcXFxMQ7KysrIkAAAAAAAAAN6uLVxcXFzeriHeri1cXFxcXK4h3q4tTFxcXN6uIQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4707 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4089419640 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a10d376810, 0x55a10d56001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a10d560020,0x55a10f3f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de0e9e616d83dbb7396953b60a80c52d3d16256c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5902 processed earlier; will process 5127 files now Step #5: ==169528== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a103e6b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a10a4d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a10a4b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a10a4b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a103e71d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a103dd2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a103dcd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a103e63c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a106e32f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a106e32f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a106e32f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a106e32f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a106e32f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a106e32f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a106e32f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a106e32f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a106e32f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a106e32f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1090c7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a105df4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a105dffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a105babc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a105babc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a105bac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a105bab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a105bab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a105bab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a10a4b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a10a4be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a10a4a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a10a4d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fecf0538082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a103dcbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x78,0x6d,0x6c,0x20,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x3d,0x22,0x22,0x20,0x65,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3d,0x22,0x57,0x49,0x4e,0x44,0x30,0x53,0x35,0x22,0x3f,0x3e,0x3e,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x6c,0x76,0x62,0x61,0x67,0x2f,0x65,0x78,0x74,0x72,0x61,0x63,0x74,0x2d,0x64,0x65,0x65,0x6c,0x62,0x65,0x73,0x74,0x61,0x6e,0x64,0x2d,0x6c,0x76,0x63,0x2f,0x76,0x32,0x30,0x32,0x30,0x30,0x36,0x30,0x31,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x73,0x74,0x61,0x6e,0x64,0x6c,0x65,0x76,0x65,0x72,0x69,0x6e,0x67,0x2d,0x67,0x65,0x6e,0x65,0x72,0x69,0x65,0x6b,0x2f,0x31,0x2e,0x30,0x64, Step #5: <?xml version=\"\" encoding=\"WIND0S5\"?>>http://www.kadaster.nl/schemas/lvbag/extract-deelbestand-lvc/v20200601http://www.kadaster.nl/schemas/standlevering-generiek/1.0d Step #5: artifact_prefix='./'; Test unit written to ./oom-303b624b99d07380b77c16b4dae951527175f1dd Step #5: Base64: PD94bWwgdmVyc2lvbj0iIiBlbmNvZGluZz0iV0lORDBTNSI/Pj5odHRwOi8vd3d3LmthZGFzdGVyLm5sL3NjaGVtYXMvbHZiYWcvZXh0cmFjdC1kZWVsYmVzdGFuZC1sdmMvdjIwMjAwNjAxaHR0cDovL3d3dy5rYWRhc3Rlci5ubC9zY2hlbWFzL3N0YW5kbGV2ZXJpbmctZ2VuZXJpZWsvMS4wZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4708 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4089935426 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561e74a7d810, 0x561e74c6701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561e74c67020,0x561e76aff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/303b624b99d07380b77c16b4dae951527175f1dd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5903 processed earlier; will process 5126 files now Step #5: ==169564== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561e6b5729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561e71bd7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561e71bba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561e71bba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561e6b578d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561e6b4d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561e6b4d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561e6b56ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561e6e539f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561e6e539f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561e6e539f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561e6e539f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561e6e539f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561e6e539f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561e6e539f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561e6e539f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561e6e539f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561e6e539f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561e707cef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561e6d4fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561e6d506be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561e6d2b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561e6d2b2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561e6d2b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561e6d2b2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561e6d2b2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561e6d2b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561e71bbcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561e71bc5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561e71bad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561e71bd8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ed6a23082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561e6b4d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0xd,0x7c,0x2b,0xa,0x2d,0xd,0x7c,0x2b,0xa,0x2d,0x2d,0x2d, Step #5: ---\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012-\015|+\012\015|+\012-\015|+\012--- Step #5: artifact_prefix='./'; Test unit written to ./oom-7df8dd6415967a63ab682b1388f024146ab94b73 Step #5: Base64: LS0tCi0NfCsKLQ18KwotDXwrCi0NfCsKLQ18KwotDXwrCi0NfCsKLQ18KwotDXwrCi0NfCsKLQ18KwotDXwrCi0NfCsKLQ18KwotDXwrCi0NfCsKLQ18KwotDXwrCi0NfCsKLQ18KwotDXwrCi0NfCsKLQ18KwotDXwrCi0NfCsKLQ18KwotDXwrCi0NfCsKLQ18KwotDXwrCg18KwotDXwrCi0tLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4709 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4090488689 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b83ae1810, 0x556b83ccb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b83ccb020,0x556b85b630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7df8dd6415967a63ab682b1388f024146ab94b73' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5904 processed earlier; will process 5125 files now Step #5: ==169600== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556b7a5d69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b80c3b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b80c1e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b80c1e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b7a5dcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b7a53db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b7a538355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b7a5cec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b7d59df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b7d59df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b7d59df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b7d59df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b7d59df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b7d59df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b7d59df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b7d59df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b7d59df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b7d59df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b7f832f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b7c55fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b7c56abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b7c316c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b7c316c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b7c317738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b7c316874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b7c316874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b7c316874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b80c20abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b80c29928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b80c11699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b80c3c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fabda299082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b7a536b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x32,0x2e,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x73,0x20,0x37,0x20,0x30,0x20,0x32,0x10,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x73,0x20,0x37,0x20,0x30,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x0,0x0,0x0,0x0,0x0,0x31,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x24, Step #5: $\177]2.2.23/\020./s 7 0 2\02023/\020./s 7 022222222222222222\000\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\177\177\177\177o\000\000C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-5aefbfea0254ef23db4538a2d6cead2d3bd272ca Step #5: Base64: JH9dMi4yLjIzLxAuL3MgNyAwIDIQMjMvEC4vcyA3IDAyMjIyMjIyMjIyMjIyMjIyMgAAAAAAMQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAH9/f39vAABDJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4710 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4091008281 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dbb0d83810, 0x55dbb0f6d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dbb0f6d020,0x55dbb2e050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5aefbfea0254ef23db4538a2d6cead2d3bd272ca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5905 processed earlier; will process 5124 files now Step #5: ==169636== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dba78789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dbadedd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dbadec05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dbadec04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dba787ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dba77dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dba77da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dba7870c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dbaa83ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dbaa83ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dbaa83ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dbaa83ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dbaa83ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dbaa83ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dbaa83ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dbaa83ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dbaa83ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dbaa83ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dbacad4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dba9801b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dba980cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dba95b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dba95b8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dba95b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dba95b8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dba95b8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dba95b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dbadec2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dbadecb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dbadeb3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dbadede112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f92b036d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dba77d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x0,0x0,0x1,0x20,0x0,0x60,0x1,0x0,0x2,0x32,0x0,0x1,0x3,0x20,0x49,0x44,0x37,0x2,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x20,0x4e,0x2d,0x2d,0x3d,0xa,0x2d,0x4e,0x2d,0x2d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x20,0x0,0x4,0x13,0x43,0x4f,0x4d,0x60,0x1,0x20,0x0,0x60,0x1,0x2,0x0,0x0,0x32,0x1,0x3,0x20,0x63,0x6f,0x63,0x6f,0x6e,0x75,0x74,0x0,0x4,0x13,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x20,0x0,0x4,0x13,0x43,0x4f,0x4d,0x60,0x1,0x20,0x0,0x60,0x1,0x43,0x4f,0x4d,0x33,0x0,0xa,0x3d,0xa,0x3d,0xa,0x5d,0x3d,0xa,0x3d,0xa,0x60,0x1,0x0,0x0,0x32,0x38,0x39,0x35, Step #5: ID3\004\000\000\001 \000`\001\000\0022\000\001\003 ID7\002\005-----BEGI N--=\012-N--\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000\000 \000\004\023COM`\001 \000`\001\002\000\0002\001\003 coconut\000\004\023\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000\000 \000\004\023COM`\001 \000`\001COM3\000\012=\012=\012]=\012=\012`\001\000\0002895 Step #5: artifact_prefix='./'; Test unit written to ./oom-a95b587086e1a207d7ae35504dcbf31f785e9ca4 Step #5: Base64: SUQzBAAAASAAYAEAAjIAAQMgSUQ3AgUtLS0tLUJFR0kgTi0tPQotTi0tCgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoAACAABBNDT01gASAAYAECAAAyAQMgY29jb251dAAEEwo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KAAAgAAQTQ09NYAEgAGABQ09NMwAKPQo9Cl09Cj0KYAEAADI4OTU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4711 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4091653678 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562a98b1a810, 0x562a98d0401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562a98d04020,0x562a9ab9c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a95b587086e1a207d7ae35504dcbf31f785e9ca4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5906 processed earlier; will process 5123 files now Step #5: #1 pulse cov: 3950 ft: 3951 exec/s: 0 rss: 174Mb Step #5: ==169672== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562a8f60f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562a95c74898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562a95c575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562a95c574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562a8f615d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562a8f576b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562a8f571355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562a8f607c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562a925d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562a925d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562a925d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562a925d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562a925d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562a925d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562a925d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562a925d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562a925d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562a925d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562a9486bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562a91598b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562a915a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562a9134fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562a9134fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562a91350738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562a9134f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562a9134f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562a9134f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562a95c59abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562a95c62928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562a95c4a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562a95c75112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b6e726082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562a8f56fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x7f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x47,0x49,0x4e,0x20,0xcc,0xa1,0x0,0x0,0x0,0xa,0xa,0x72,0x67,0x6c,0x79,0x66,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x54,0xa,0x7f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x47,0x49,0x4e,0x20,0xcc,0xa1,0x0,0x0,0x0,0xa,0xa,0x72,0x67,0x6c,0x79,0x66,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x54,0xa,0x3d,0xa,0x64,0x6f,0x6c,0x70,0x68,0x69,0x6e,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0xf6,0xc2,0x2b,0x3d,0x3d,0xf5,0xc2,0x3,0x0,0x0,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x7c,0x0,0x10,0xff,0x3d,0xa,0x64,0x6f,0x6c,0x70,0x68,0x69,0x6e,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0xf6,0xc2,0x2b,0x3d,0x3d,0xf5,0xc2,0x3,0x0,0x0,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x7c,0x0,0x10,0xff, Step #5: \005\177\000\000\000\000\000\000\000GIN \314\241\000\000\000\012\012rglyf=\000\000\000\000\000\000\000T\012\177\000\000\000\000\000\000\000GIN \314\241\000\000\000\012\012rglyf=\000\000\000\000\000\000\000T\012=\012dolphin i\012\012r=sef=\012\366\302+==\365\302\003\000\000\000\012=\012=\012=\012=\012=\012=\012\012|\000\020\377=\012dolphin i\012\012r=sef=\012\366\302+==\365\302\003\000\000\000\012=\012=\012=\012=\012=\012=\012\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-2a8ead0e30680b6e7ca32684423ea7fadfd982c8 Step #5: Base64: BX8AAAAAAAAAR0lOIMyhAAAACgpyZ2x5Zj0AAAAAAAAAVAp/AAAAAAAAAEdJTiDMoQAAAAoKcmdseWY9AAAAAAAAAFQKPQpkb2xwaGluIGkKCnI9c2VmPQr2wis9PfXCAwAAAAo9Cj0KPQo9Cj0KPQoKfAAQ/z0KZG9scGhpbiBpCgpyPXNlZj0K9sIrPT31wgMAAAAKPQo9Cj0KPQo9Cj0KCnwAEP8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4712 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4092214637 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a49996810, 0x560a49b8001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a49b80020,0x560a4ba180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2a8ead0e30680b6e7ca32684423ea7fadfd982c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5908 processed earlier; will process 5121 files now Step #5: ==169708== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560a4048b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a46af0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a46ad35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a46ad34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a40491d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a403f2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a403ed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a40483c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a43452f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a43452f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a43452f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a43452f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a43452f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a43452f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a43452f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a43452f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a43452f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a43452f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a456e7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a42414b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a4241fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a421cbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a421cbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a421cc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a421cb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a421cb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a421cb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a46ad5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a46ade928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a46ac6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a46af1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c1c2e8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a403ebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0xd5,0xf5,0xdc,0xdd,0x84,0x7d,0x2b,0xa,0x23,0x7b,0x7d,0x2b,0x7b,0x2b,0xa,0x23,0x7d,0xa,0x23,0x7b,0x7d,0x2b,0xa,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0xa5,0x9c,0x5e,0x5b,0x4b,0x5b,0x5b,0x5b,0x5b, Step #5: #{}+\012#{}+\012#{}+\012#{}+\012#{}+#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}+\012#{}\325\365\334\335\204}+\012#{}+{+\012#}\012#{}+\012[[[[[[[[[[[[[[[[[[[[[[[[\245\234^[K[[[[ Step #5: artifact_prefix='./'; Test unit written to ./oom-271b5c1b42503270024248169de3905ee8903dc2 Step #5: Base64: I3t9Kwoje30rCiN7fSsKI3t9Kwoje30rI3t9Kwoje30rCiN7fSsKI3t9Kwoje30rCiN7fSsKI3t9Kwoje30rCiN7fSsKI3t9KyN7fSsKI3t9Kwoje30rCiN7fSsKI3t9Kwoje30rCiN7fSsKI3t91fXc3YR9Kwoje30reysKI30KI3t9KwpbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1ulnF5bS1tbW1s= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4713 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4092729403 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557e33826810, 0x557e33a1001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557e33a10020,0x557e358a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/271b5c1b42503270024248169de3905ee8903dc2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5909 processed earlier; will process 5120 files now Step #5: ==169744== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557e2a31b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557e30980898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557e309635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557e309634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557e2a321d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557e2a282b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557e2a27d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557e2a313c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557e2d2e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557e2d2e2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557e2d2e2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557e2d2e2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557e2d2e2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557e2d2e2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557e2d2e2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557e2d2e2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557e2d2e2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557e2d2e2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557e2f577f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557e2c2a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557e2c2afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557e2c05bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557e2c05bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557e2c05c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557e2c05b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557e2c05b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557e2c05b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557e30965abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557e3096e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557e30956699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557e30981112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9a2f1cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557e2a27bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x3d,0x1d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x8a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2d,0x2d,0x45,0x4e,0x2d,0x2d,0x2d,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: x-----BEGIN -----\012=\035\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000ooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\212\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012--EN---D ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-27b7d2f19a7626ff093f31c6bceb1fb2ca2f9bea Step #5: Base64: eC0tLS0tQkVHSU4gLS0tLS0KPR0AAAAAAAAAAAAAAAAAAABvb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vbwAAAAAAAAAAAAAAAAAAAAAAAACKAAAAAAAAAAAAAAAAAAAKLS1FTi0tLUQgLS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4714 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4093240590 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56483acad810, 0x56483ae9701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56483ae97020,0x56483cd2f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/27b7d2f19a7626ff093f31c6bceb1fb2ca2f9bea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5910 processed earlier; will process 5119 files now Step #5: #1 pulse cov: 11544 ft: 11545 exec/s: 0 rss: 196Mb Step #5: ==169780== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5648317a29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564837e07898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564837dea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564837dea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5648317a8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564831709b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564831704355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56483179ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564834769f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564834769f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564834769f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564834769f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564834769f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564834769f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564834769f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564834769f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564834769f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564834769f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5648369fef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56483372bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564833736be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5648334e2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5648334e2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5648334e3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5648334e2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5648334e2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5648334e2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564837decabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564837df5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564837ddd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564837e08112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f92e2dfc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564831702b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x5b,0x49,0x47,0x4e,0x4f,0x52,0x45,0x5b,0xe2,0xbb,0xb0,0x5d,0xe2,0xbb,0xb0,0xe1,0xab,0xbc,0x3e,0xe1,0xab,0xbc,0xe1,0xab,0xbc,0x3e,0xe1,0xa9,0xbc,0x3f,0xe2,0xbb,0xb0,0xe1,0xab,0xbc,0xe1,0xa9,0xb0,0x3e,0x59,0xe2,0xbb,0xb0,0xe1,0xab,0xbc,0x3e,0xe1,0xab,0xbc,0x44,0xe2,0xbb,0xb0,0xe1,0xab,0xbc,0xe1,0xab,0xbc,0xe1,0xab,0xbc,0x42,0x3e,0x5b,0xe2,0xbb,0xb0,0xe1,0xab,0xbc,0x3e,0xe1,0xa9,0xbc,0xe2,0xbb,0xb0,0xe1,0xab,0xbc,0xe1,0xab,0xbc,0xe2,0xbb,0xb0,0xe1,0xab,0xbc,0xe1,0xa9,0xbc,0x3f,0x59,0xe2,0xbb,0xb0,0xe1,0xa7,0xbc,0x3e,0xe1,0xab,0xbc,0xe1,0xab,0xbc,0x59,0xe2,0xbb,0xb0,0xe1,0xab,0xbc,0xe1,0xab,0xbc,0x3e,0xe1,0xab,0xbc,0x42,0x42,0x3e,0x5b,0xe2,0xbb,0xb0,0xe1,0xab,0xbc,0x56,0xe2,0xbb,0xb0,0xe1,0xab,0xbc,0x3e,0xe1,0xab,0xbc,0xe2,0xbb,0xb0,0xe1,0xab,0xbc,0x3e,0xe1,0xa9,0xbc,0x3f,0x59,0xe2,0xbb,0xb0,0xe1,0xa7,0x89,0x27,0x3c, Step #5: <![IGNORE[\342\273\260]\342\273\260\341\253\274>\341\253\274\341\253\274>\341\251\274?\342\273\260\341\253\274\341\251\260>Y\342\273\260\341\253\274>\341\253\274D\342\273\260\341\253\274\341\253\274\341\253\274B>[\342\273\260\341\253\274>\341\251\274\342\273\260\341\253\274\341\253\274\342\273\260\341\253\274\341\251\274?Y\342\273\260\341\247\274>\341\253\274\341\253\274Y\342\273\260\341\253\274\341\253\274>\341\253\274BB>[\342\273\260\341\253\274V\342\273\260\341\253\274>\341\253\274\342\273\260\341\253\274>\341\251\274?Y\342\273\260\341\247\211'< Step #5: artifact_prefix='./'; Test unit written to ./oom-fef048ab61c42c9bff747b62e1a0dc93ab45d7d9 Step #5: Base64: PCFbSUdOT1JFW+K7sF3iu7Dhq7w+4au84au8PuGpvD/iu7Dhq7zhqbA+WeK7sOGrvD7hq7xE4ruw4au84au84au8Qj5b4ruw4au8PuGpvOK7sOGrvOGrvOK7sOGrvOGpvD9Z4ruw4ae8PuGrvOGrvFniu7Dhq7zhq7w+4au8QkI+W+K7sOGrvFbiu7Dhq7w+4au84ruw4au8PuGpvD9Z4ruw4aeJJzw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4715 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4093829383 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555741bf1810, 0x555741ddb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555741ddb020,0x555743c730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fef048ab61c42c9bff747b62e1a0dc93ab45d7d9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5912 processed earlier; will process 5117 files now Step #5: ==169816== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5557386e69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55573ed4b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55573ed2e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55573ed2e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557386ecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55573864db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555738648355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557386dec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55573b6adf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55573b6adf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55573b6adf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55573b6adf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55573b6adf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55573b6adf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55573b6adf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55573b6adf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55573b6adf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55573b6adf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55573d942f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55573a66fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55573a67abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55573a426c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55573a426c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55573a427738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55573a426874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55573a426874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55573a426874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55573ed30abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55573ed39928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55573ed21699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55573ed4c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbc8daf5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555738646b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x90,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x87,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8e,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xa,0x6b,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x90,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x87,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8e,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xa,0x6b,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcc,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8a,0xcd,0x8f, Step #5: 1\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\220\315\217\315\217\315\217\315\217\315\217\315\207\315\217\315\217\315\217\315\217\315\217\315\216\315\217\315\217\315\217\315\217\012k\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\220\315\217\315\217\315\217\315\217\315\217\315\207\315\217\315\217\315\217\315\217\315\217\315\216\315\217\315\217\315\217\315\217\012k\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\314\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\212\315\217 Step #5: artifact_prefix='./'; Test unit written to ./oom-262760f8eb7f7d4b32179421b1a67259b7e6aaf8 Step #5: Base64: Mc2PzY/Nj82PzY/Nj82PzY/Nj82PzZDNj82PzY/Nj82PzYfNj82PzY/Nj82PzY7Nj82PzY/NjwprzY/Nj82PzY/Nj82PzY/Nj82PzY/NkM2PzY/Nj82PzY/Nh82PzY/Nj82PzY/Njs2PzY/Nj82PCmvNj82PzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzY/Mj82PzY/Nj82PzY/Nj82PzY/Nj82KzY8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4716 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4094338859 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559396b00810, 0x559396cea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559396cea020,0x559398b820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/262760f8eb7f7d4b32179421b1a67259b7e6aaf8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5913 processed earlier; will process 5116 files now Step #5: #1 pulse cov: 3657 ft: 3658 exec/s: 0 rss: 174Mb Step #5: ==169852== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55938d5f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559393c5a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559393c3d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559393c3d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55938d5fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55938d55cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55938d557355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55938d5edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5593905bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5593905bcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5593905bcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5593905bcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5593905bcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5593905bcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5593905bcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5593905bcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5593905bcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5593905bcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559392851f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55938f57eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55938f589be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55938f335c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55938f335c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55938f336738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55938f335874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55938f335874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55938f335874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559393c3fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559393c48928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559393c30699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559393c5b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9da1cc9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55938d555b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2f,0x4b,0x60,0x20,0x2d,0x45,0x47,0x4b,0x60,0x30,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xef,0xa7,0xa7,0xa7,0xa7,0xa7,0xa7,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x7f,0xff,0xff,0xff,0x9c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xa7,0x0,0x0,0xef,0xef,0xef,0x87,0x28,0x37,0x0,0x0,0x0,0xa,0x2d, Step #5: s/K` -EGK`0\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\357\247\247\247\247\247\247\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\177\377\377\377\234\000\000\000\000\000\000\000\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\247\000\000\357\357\357\207(7\000\000\000\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-24c06b59efe38c6dc0df6a079737c02744bb8cb1 Step #5: Base64: cy9LYCAtRUdLYDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA76enp6enp///////////////////////////////////////////f////5wAAAAAAAAA////////////////////////////////////pwAA7+/vhyg3AAAACi0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4717 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4095014013 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5599a36f4810, 0x5599a38de01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5599a38de020,0x5599a57760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/24c06b59efe38c6dc0df6a079737c02744bb8cb1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5915 processed earlier; will process 5114 files now Step #5: #1 pulse cov: 12838 ft: 12839 exec/s: 0 rss: 195Mb Step #5: ==169888== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55999a1e99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5599a084e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5599a08315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5599a08314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55999a1efd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55999a150b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55999a14b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55999a1e1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55999d1b0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55999d1b0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55999d1b0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55999d1b0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55999d1b0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55999d1b0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55999d1b0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55999d1b0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55999d1b0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55999d1b0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55999f445f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55999c172b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55999c17dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55999bf29c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55999bf29c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55999bf2a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55999bf29874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55999bf29874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55999bf29874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5599a0833abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5599a083c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5599a0824699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5599a084f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9c0fabc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55999a149b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x47,0x20,0x4e,0x49,0x45,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2,0xa,0x2d,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2c,0xa,0xa,0x2,0xa,0x2d,0x64,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2,0xa,0x2d,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2,0xa,0x2d,0xa,0x2d,0xa,0x62,0xa,0xd0,0xa,0x2d,0xa,0x64,0xa,0x2,0xa,0xd5,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: Da\000-----BG NIE-\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012\002\012-\012\000\000\000\000\000\000\000\000\000\000\012\002\012-\012\002\012-\012,\012\012\002\012-d\012-----\012,\012-\012d\012-\012d\012d\012-\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012\002\012-\012\000\000\000\000\000\000\000\000\000\000\012\002\012-\012\002\012-\012,\012-\012d\012\002\012-\012-\012b\012\320\012-\012d\012\002\012\325\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2641615f3ba7b7a6a8b4cb079379b805c67ee7aa Step #5: Base64: RGEALS0tLS1CRyBOSUUtAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAoCCi0KAAAAAAAAAAAAAAoCCi0KAgotCiwKCgIKLWQKLS0tLS0KLAotCmQKLQpkCmQKLQAAAAAAAAAAAAAAAAAAAAAAAAAACgIKLQoAAAAAAAAAAAAACgIKLQoCCi0KLAotCmQKAgotCi0KYgrQCi0KZAoCCtUAAAAAAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4718 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4095636139 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555bb21f4810, 0x555bb23de01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555bb23de020,0x555bb42760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2641615f3ba7b7a6a8b4cb079379b805c67ee7aa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5917 processed earlier; will process 5112 files now Step #5: ==169924== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555ba8ce99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555baf34e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555baf3315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555baf3314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ba8cefd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ba8c50b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ba8c4b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ba8ce1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555babcb0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555babcb0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555babcb0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555babcb0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555babcb0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555babcb0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555babcb0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555babcb0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555babcb0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555babcb0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555badf45f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555baac72b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555baac7dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555baaa29c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555baaa29c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555baaa2a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555baaa29874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555baaa29874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555baaa29874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555baf333abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555baf33c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555baf324699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555baf34f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5175ddd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ba8c49b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0xe2,0x81,0x9f,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x37,0xe2,0x80,0xab,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x39,0x34,0x36,0x31,0x4,0x10,0x75,0x6d,0x65,0x74,0x61,0x64,0x7f,0x2,0x3f,0x54,0x31,0x43,0x48,0x0,0x43,0x6d,0x65,0x49,0x44,0x32,0x4,0x10,0x75,0x75,0x75,0x75,0xe2,0x80,0xa8,0x75,0x75,0x75,0x75,0x6d,0x49,0x55,0x75,0x75,0x75,0x75,0x4,0x10,0x31,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x33,0x4,0x10,0x33,0x32,0x37,0x36,0x39,0x2c,0x44,0x33,0x4,0x10,0x75,0x75,0x75,0x75,0xca,0xb0,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x33,0xa,0x2d,0xa,0x3a,0xa,0x2d,0x3f,0x54,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0x32,0x39,0x35,0x43,0x48,0x0,0x75,0x75,0x6d,0x49,0x44,0x33,0x7f,0x2,0x3f,0x54,0x31,0x43,0x48,0x75,0x0,0x12, Step #5: I3846346337\342\201\2374607431768211457\342\200\2539223372036854779461\004\020umetad\177\002?T1CH\000CmeID2\004\020uuuu\342\200\250uuuumIUuuuu\004\0201uuuumID3\004\02032769,D3\004\020uuuu\312\260uuuumID3\012-\012:\012-?T4294967295CH\000uumID3\177\002?T1CHu\000\022 Step #5: artifact_prefix='./'; Test unit written to ./oom-8041b4d9e3111330ce308b6970bf7c7c0d62f06b Step #5: Base64: STM4NDYzNDYzMzfigZ80NjA3NDMxNzY4MjExNDU34oCrOTIyMzM3MjAzNjg1NDc3OTQ2MQQQdW1ldGFkfwI/VDFDSABDbWVJRDIEEHV1dXXigKh1dXV1bUlVdXV1dQQQMXV1dXVtSUQzBBAzMjc2OSxEMwQQdXV1dcqwdXV1dW1JRDMKLQo6Ci0/VDQyOTQ5NjcyOTVDSAB1dW1JRDN/Aj9UMUNIdQAS Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4719 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4096161392 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56269ff28810, 0x5626a011201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5626a0112020,0x5626a1faa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8041b4d9e3111330ce308b6970bf7c7c0d62f06b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5918 processed earlier; will process 5111 files now Step #5: #1 pulse cov: 3987 ft: 3988 exec/s: 0 rss: 174Mb Step #5: ==169960== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562696a1d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56269d082898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56269d0655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56269d0654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562696a23d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562696984b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56269697f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562696a15c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5626999e4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5626999e4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5626999e4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5626999e4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5626999e4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5626999e4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5626999e4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5626999e4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5626999e4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5626999e4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56269bc79f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5626989a6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5626989b1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56269875dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56269875dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56269875e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56269875d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56269875d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56269875d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56269d067abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56269d070928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56269d058699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56269d083112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7b2a685082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56269697db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xaa,0xb2,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xb4,0x88,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xaa,0xb2,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xaa,0xb2,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xaa,0xb2,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xb4,0x88,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xaa,0xb2,0xa,0x13,0x12,0x11,0xa,0xf,0x2f,0x2f,0x2b,0x62,0x75,0x69,0x6c,0x64,0xb,0x20,0x77,0xf0,0x91,0xb4,0x88, Step #5: \012\023\022\021\012\017//+build\013 w\360\221\252\262\012\023\022\021\012\017//+build\013 w\360\221\264\210\012\023\022\021\012\017//+build\013 w\360\221\252\262\012\023\022\021\012\017//+build\013 w\360\221\252\262\012\023\022\021\012\017//+build\013 w\360\221\252\262\012\023\022\021\012\017//+build\013 w\360\221\264\210\012\023\022\021\012\017//+build\013 w\360\221\252\262\012\023\022\021\012\017//+build\013 w\360\221\264\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-9da6d504ab773a06fe455f55836157972b6c9a09 Step #5: Base64: ChMSEQoPLy8rYnVpbGQLIHfwkaqyChMSEQoPLy8rYnVpbGQLIHfwkbSIChMSEQoPLy8rYnVpbGQLIHfwkaqyChMSEQoPLy8rYnVpbGQLIHfwkaqyChMSEQoPLy8rYnVpbGQLIHfwkaqyChMSEQoPLy8rYnVpbGQLIHfwkbSIChMSEQoPLy8rYnVpbGQLIHfwkaqyChMSEQoPLy8rYnVpbGQLIHfwkbSI Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4720 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4096721693 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560cf8c2d810, 0x560cf8e1701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560cf8e17020,0x560cfacaf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9da6d504ab773a06fe455f55836157972b6c9a09' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5920 processed earlier; will process 5109 files now Step #5: #1 pulse cov: 3756 ft: 3757 exec/s: 0 rss: 177Mb Step #5: ==169996== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560cef7229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560cf5d87898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560cf5d6a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560cf5d6a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560cef728d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560cef689b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560cef684355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560cef71ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560cf26e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560cf26e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560cf26e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560cf26e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560cf26e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560cf26e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560cf26e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560cf26e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560cf26e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560cf26e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560cf497ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560cf16abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560cf16b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560cf1462c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560cf1462c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560cf1463738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560cf1462874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560cf1462874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560cf1462874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560cf5d6cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560cf5d75928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560cf5d5d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560cf5d88112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f659db85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560cef682b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0x95,0xd9,0x8b,0xd9,0x98,0x20,0xd9,0x90,0xd9,0x95,0xd9,0x8b,0xd9,0x98,0x20,0xd9,0x90,0xd9,0x95,0xcd,0x95,0xd9,0x8b,0xd9,0x98,0x20,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x79,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0xd9,0x96,0xd9,0x95,0xd9,0x8b,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e,0x27,0x3c,0x2f, Step #5: <svg><text>\331\225\331\213\331\230 \331\220\331\225\331\213\331\230 \331\220\331\225\315\225\331\213\331\230 }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}y}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}\331\226\331\225\331\213'</text></svg>'</ Step #5: artifact_prefix='./'; Test unit written to ./oom-f1248c157270ad61579205409fae40a69bea280c Step #5: Base64: PHN2Zz48dGV4dD7ZldmL2Zgg2ZDZldmL2Zgg2ZDZlc2V2YvZmCB9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX3ZltmV2YsnPC90ZXh0Pjwvc3ZnPic8Lw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4721 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4097286128 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5583cbdbf810, 0x5583cbfa901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5583cbfa9020,0x5583cde410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f1248c157270ad61579205409fae40a69bea280c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5922 processed earlier; will process 5107 files now Step #5: #1 pulse cov: 3555 ft: 3556 exec/s: 0 rss: 176Mb Step #5: ==170032== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5583c28b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5583c8f19898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583c8efc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583c8efc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5583c28bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5583c281bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5583c2816355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5583c28acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5583c587bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5583c587bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5583c587bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5583c587bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5583c587bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5583c587bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5583c587bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5583c587bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5583c587bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5583c587bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5583c7b10f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5583c483db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5583c4848be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5583c45f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5583c45f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5583c45f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5583c45f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5583c45f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5583c45f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5583c8efeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5583c8f07928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5583c8eef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5583c8f1a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1b3b60f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5583c2814b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x2d,0x39,0x32,0x32,0x33,0x33,0x32,0x35,0x36,0x30,0x38,0x37,0x33,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x3d,0x3c,0x2d,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x38,0x37,0x33,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x3d,0x3c,0x2d,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x24,0x27,0x2d,0x24,0x2d,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x3d,0x3c,0x2d,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x3d,0x3c,0x2d,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x24,0x27,0x2d, Step #5: $-9223325608734775551-=<-1''/''''/'''8734775551-=<-1''/''''/'''exp'N'2-\007='''''$'-$-9223372036854775551-=<-1''/''''/'6854775551-=<-1''/''''/'''exp'N'2-\007='''N'2-\007='''''$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-d402f97f9cf47f0f02ad3662d7124a94954128d3 Step #5: Base64: JC05MjIzMzI1NjA4NzM0Nzc1NTUxLT08LTEnJy8nJycnLycnJzg3MzQ3NzU1NTEtPTwtMScnLycnJycvJycnZXhwJ04nMi0HPScnJycnJCctJC05MjIzMzcyMDM2ODU0Nzc1NTUxLT08LTEnJy8nJycnLyc2ODU0Nzc1NTUxLT08LTEnJy8nJycnLycnJ2V4cCdOJzItBz0nJydOJzItBz0nJycnJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4722 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4097858167 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558327683810, 0x55832786d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55832786d020,0x5583297050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d402f97f9cf47f0f02ad3662d7124a94954128d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5924 processed earlier; will process 5105 files now Step #5: ==170068== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55831e1789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5583247dd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583247c05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583247c04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55831e17ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55831e0dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55831e0da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55831e170c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55832113ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55832113ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55832113ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55832113ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55832113ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55832113ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55832113ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55832113ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55832113ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55832113ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5583233d4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558320101b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55832010cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55831feb8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55831feb8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55831feb9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55831feb8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55831feb8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55831feb8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5583247c2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5583247cb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5583247b3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5583247de112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f79668e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55831e0d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x42,0x1d,0x54,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xe,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0xf,0x4,0x43,0x4f,0x4d,0x0,0x0,0x4,0x2,0x43,0x3c, Step #5: ID3\002B\035TC\017\004COM\000\000\004\002C\017\004COM\000\000\004\002C\017\004COM\000\000\004\002C\017\004COM\000\000\004\002C\017\004COM\000\000\004\002C\017\004COM\000\000\004\002C\017\004COM\000\000\004\002C\017\004COM\000\000\004\002C\017\004COM\000\000\004\002C\017\004COM\000\000\004\002C\017\004COM\000\000\004\002C\017\004COM\000\000\004\002C\017\004COM\000\000\004\002C\017\004COM\000\000\004\002C\016\004COM\000\000\004\002C\017\004COM\000\000\004\002C< Step #5: artifact_prefix='./'; Test unit written to ./oom-94c285f3c244f63bbfc0f0b718e0ed47a296fb41 Step #5: Base64: SUQzAkIdVEMPBENPTQAABAJDDwRDT00AAAQCQw8EQ09NAAAEAkMPBENPTQAABAJDDwRDT00AAAQCQw8EQ09NAAAEAkMPBENPTQAABAJDDwRDT00AAAQCQw8EQ09NAAAEAkMPBENPTQAABAJDDwRDT00AAAQCQw8EQ09NAAAEAkMPBENPTQAABAJDDwRDT00AAAQCQw4EQ09NAAAEAkMPBENPTQAABAJDPA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4723 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4098377855 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d350314810, 0x55d3504fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d3504fe020,0x55d3523960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/94c285f3c244f63bbfc0f0b718e0ed47a296fb41' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5925 processed earlier; will process 5104 files now Step #5: #1 pulse cov: 3801 ft: 3802 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4467 ft: 4974 exec/s: 0 rss: 176Mb Step #5: ==170104== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d346e099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d34d46e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d34d4515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d34d4514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d346e0fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d346d70b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d346d6b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d346e01c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d349dd0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d349dd0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d349dd0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d349dd0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d349dd0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d349dd0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d349dd0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d349dd0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d349dd0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d349dd0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d34c065f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d348d92b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d348d9dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d348b49c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d348b49c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d348b4a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d348b49874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d348b49874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d348b49874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d34d453abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d34d45c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d34d444699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d34d46f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdef6cef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d346d69b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7d,0x30,0x7b,0x73,0x7b,0x2c,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x25,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x2e,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x25,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x73,0x20,0x2f,0x5b,0x39,0x20,0x30,0x30,0x2c,0x7d,0x7,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d, Step #5: }{0,} {0,} }0{s{,0,} {0,}${0,}%{0,} {0,}}{0,.} {0,} {0,}s{0,} {0,}${0,} {0,} {0,}}{0,} {0,} {0,}s{0,} {0,}${0,}%{0,} {0,}}{0,} {s /[9 00,}\007 {0,}s{0,} {0,}${0,} {0,} {0,} Step #5: artifact_prefix='./'; Test unit written to ./oom-9c481357f870d8d72959d3d7b5444e03d955dc1c Step #5: Base64: fXswLH0gezAsfSB9MHtzeywwLH0gezAsfSR7MCx9JXswLH0gezAsfX17MCwufSB7MCx9IHswLH1zezAsfSB7MCx9JHswLH0gezAsfSB7MCx9fXswLH0gezAsfSB7MCx9c3swLH0gezAsfSR7MCx9JXswLH0gezAsfX17MCx9IHtzIC9bOSAwMCx9ByB7MCx9c3swLH0gezAsfSR7MCx9IHswLH0gezAsfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4724 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4098986476 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c086960810, 0x55c086b4a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c086b4a020,0x55c0889e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c481357f870d8d72959d3d7b5444e03d955dc1c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5928 processed earlier; will process 5101 files now Step #5: #1 pulse cov: 3777 ft: 3778 exec/s: 0 rss: 174Mb Step #5: ==170140== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c07d4559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c083aba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c083a9d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c083a9d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c07d45bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c07d3bcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c07d3b7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c07d44dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c08041cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c08041cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c08041cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c08041cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c08041cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c08041cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c08041cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c08041cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c08041cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c08041cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c0826b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c07f3deb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c07f3e9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c07f195c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c07f195c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c07f196738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c07f195874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c07f195874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c07f195874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c083a9fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c083aa8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c083a90699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c083abb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8c366aa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c07d3b5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x39,0x39,0x3b,0x39,0x39,0x39,0x0,0x0,0x0,0x0,0x0,0x0,0x25,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x39, Step #5: \333\200\333\200%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%\000\000\000\000\000\000\000\000\00099;999\000\000\000\000\000\000%\000\000\000\000\000\000\000\000\000\000%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000 \000\000\000\000\000\0009 Step #5: artifact_prefix='./'; Test unit written to ./oom-72a6838c91550f052e636bd83baa3cb58e66fb8a Step #5: Base64: 24DbgCUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJQAAAAAAAAAAADk5Ozk5OQAAAAAAACUAAAAAAAAAAAAAJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgAAAAAAAAOQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4725 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4099549860 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5644ae1a9810, 0x5644ae39301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5644ae393020,0x5644b022b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/72a6838c91550f052e636bd83baa3cb58e66fb8a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5930 processed earlier; will process 5099 files now Step #5: ==170176== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5644a4c9e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5644ab303898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5644ab2e65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5644ab2e64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5644a4ca4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5644a4c05b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5644a4c00355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5644a4c96c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5644a7c65f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5644a7c65f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5644a7c65f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5644a7c65f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5644a7c65f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5644a7c65f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5644a7c65f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5644a7c65f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5644a7c65f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5644a7c65f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5644a9efaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5644a6c27b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5644a6c32be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5644a69dec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5644a69dec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5644a69df738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5644a69de874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5644a69de874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5644a69de874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5644ab2e8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5644ab2f1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5644ab2d9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5644ab304112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff342655082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5644a4bfeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x70,0x6e,0x72,0x79,0x6c,0x61,0x74,0x65,0x3e,0x3c,0x74,0x72,0x70,0x6e,0x72,0x79,0x6c,0x61,0x74,0x65,0x3e,0x3c,0x74,0x72,0x61,0x6e,0x73,0x6c,0x61,0x74,0x65,0x3e,0x3c,0x74,0x72,0x61,0x6e,0x73,0x6c,0x61,0x74,0x65,0x74,0x3e,0x72,0x3c,0x66,0x6e,0x73,0x6c,0x61,0x74,0x73,0x76,0x67,0x3a,0x63,0x79,0x65,0x3e,0x3c,0x74,0x72,0x61,0x6e,0x73,0x6c,0x72,0x79,0x3e,0x3c,0x61,0x74,0x65,0x3e,0x3c,0x74,0x72,0x61,0x6e,0x73,0x61,0x6c,0x4e,0x3e,0x65,0x73,0x6c,0x61,0x74,0x65,0x3e,0x3c,0x74,0x72,0x61,0x6e,0x73,0x6c,0x61,0x74,0x74,0x3a,0x6f,0x62,0x6a,0x65,0x63,0x74,0x2d,0x69,0x6e,0x64,0x65,0x78,0x2d,0x73,0x6f,0x75,0x72,0x63,0x65,0x6a,0x3e,0x3c,0x54,0x4e,0x65,0x74,0x3e,0x72,0x3c,0x66,0x6e,0x73,0x6c,0x61,0x74,0x65,0x3e,0x3c,0x74,0x72,0x61,0x6e,0x73,0x6c,0x72,0x79,0x3e,0x3c,0x61,0x74,0x65,0x3e,0x3c,0x74,0x72,0x61,0x6e,0x73,0x61,0x6c,0x4e,0x3e,0x65,0x74,0x65, Step #5: <pnrylate><trpnrylate><translate><translatet>r<fnslatsvg:cye><translry><ate><transalN>eslate><translatt:object-index-sourcej><TNet>r<fnslate><translry><ate><transalN>ete Step #5: artifact_prefix='./'; Test unit written to ./oom-d98b09629b73f3434d40fc2c59847174a87a5b00 Step #5: Base64: PHBucnlsYXRlPjx0cnBucnlsYXRlPjx0cmFuc2xhdGU+PHRyYW5zbGF0ZXQ+cjxmbnNsYXRzdmc6Y3llPjx0cmFuc2xyeT48YXRlPjx0cmFuc2FsTj5lc2xhdGU+PHRyYW5zbGF0dDpvYmplY3QtaW5kZXgtc291cmNlaj48VE5ldD5yPGZuc2xhdGU+PHRyYW5zbHJ5PjxhdGU+PHRyYW5zYWxOPmV0ZQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4726 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4100071743 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ba384f3810, 0x55ba386dd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ba386dd020,0x55ba3a5750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d98b09629b73f3434d40fc2c59847174a87a5b00' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5931 processed earlier; will process 5098 files now Step #5: ==170212== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ba2efe89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ba3564d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ba356305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ba356304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ba2efeed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ba2ef4fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ba2ef4a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ba2efe0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ba31faff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ba31faff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ba31faff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ba31faff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ba31faff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ba31faff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ba31faff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ba31faff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ba31faff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ba31faff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ba34244f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ba30f71b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ba30f7cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ba30d28c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ba30d28c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ba30d29738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ba30d28874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ba30d28874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ba30d28874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ba35632abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ba3563b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ba35623699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ba3564e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1842190082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ba2ef48b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7e,0x24,0x3d,0x7e,0xb,0x2d,0x3d,0x33,0x1,0x29,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x79,0x24,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x0,0x0,0x44,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5,0x0,0x0,0x0,0x0,0x0,0x44,0x61,0x6e,0x4d,0xdc,0x8,0x7f,0x0,0xb7,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e, Step #5: \000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000~$=~\013-=3\001)\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000y$~~~~~~~~~~~~~\000\000D\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\020\000\000\000\000\000\000\000\000\000\000\000\000\005\000\000\000\000\000DanM\334\010\177\000\267~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Step #5: artifact_prefix='./'; Test unit written to ./oom-2544de008943e687e3145596ad38a9babb13d72e Step #5: Base64: AAAAAAAAAAAAAAAAAAAAAAB+JD1+Cy09MwEpAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHkkfn5+fn5+fn5+fn5+fgAARAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAABQAAAAAARGFuTdwIfwC3fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4727 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4100592455 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f55becb810, 0x55f55c0b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f55c0b5020,0x55f55df4d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2544de008943e687e3145596ad38a9babb13d72e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5932 processed earlier; will process 5097 files now Step #5: #1 pulse cov: 14175 ft: 14176 exec/s: 0 rss: 196Mb Step #5: ==170248== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f5529c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f559025898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f5590085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f5590084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f5529c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f552927b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f552922355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f5529b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f555987f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f555987f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f555987f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f555987f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f555987f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f555987f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f555987f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f555987f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f555987f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f555987f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f557c1cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f554949b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f554954be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f554700c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f554700c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f554701738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f554700874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f554700874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f554700874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f55900aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f559013928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f558ffb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f559026112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb3bcac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f552920b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0xa,0x60,0x20,0x1e,0x60,0x41,0x4c,0x49,0x41,0x53,0x5b,0x30,0x2c,0x31,0x38,0x34,0x30,0x37,0x33,0x37,0x30,0x34,0x36,0x37,0x35,0x38,0x30,0x38,0x2c,0x30,0x41,0x28,0x28,0x45,0x58,0x50,0x4c,0x41,0x49,0x4e,0x20,0x65,0x75,0x6c,0x33,0x32,0x54,0x54,0x54,0x61,0x6d,0x5f,0x54,0x54,0x54,0x54,0x54,0x39,0x70,0x3d,0x33,0x31,0x2c,0x70,0x2e,0x38,0x36,0x61,0x72,0x61,0x6d,0x5f,0x33,0x32,0x59,0x37,0x70,0x3d,0x31,0x2c,0x70,0x61,0x72,0x61,0x6d,0x5f,0x33,0x32,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x6d,0x5f,0x30,0x54,0x3d,0x5b,0x32,0x2c,0x34,0x32,0x39,0x35,0x30,0x30,0x30,0x33,0x31,0x39,0x5d,0x2c,0x34,0x39,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd3,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd6,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0x34,0x32,0x31,0x5d,0xa, Step #5: :\012` \036`ALIAS[0,184073704675808,0A((EXPLAIN eul32TTTam_TTTTT9p=31,p.86aram_32Y7p=1,param_32TTTTTTTm_0T=[2,4295000319],49\327\327\327\327\327\327\323\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\326\327\327\327\327\327\327421]\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-5da96f7effcffe27e893657e69b661c461d16ad0 Step #5: Base64: OgpgIB5gQUxJQVNbMCwxODQwNzM3MDQ2NzU4MDgsMEEoKEVYUExBSU4gZXVsMzJUVFRhbV9UVFRUVDlwPTMxLHAuODZhcmFtXzMyWTdwPTEscGFyYW1fMzJUVFRUVFRUbV8wVD1bMiw0Mjk1MDAwMzE5XSw0OdfX19fX19PX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19bX19fX19c0MjFdCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4728 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4101319094 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cf99246810, 0x55cf9943001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cf99430020,0x55cf9b2c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5da96f7effcffe27e893657e69b661c461d16ad0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5934 processed earlier; will process 5095 files now Step #5: #1 pulse cov: 3638 ft: 3639 exec/s: 0 rss: 177Mb Step #5: ==170284== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cf8fd3b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cf963a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cf963835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cf963834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cf8fd41d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cf8fca2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cf8fc9d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cf8fd33c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cf92d02f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cf92d02f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cf92d02f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cf92d02f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cf92d02f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cf92d02f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cf92d02f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cf92d02f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cf92d02f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cf92d02f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cf94f97f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cf91cc4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cf91ccfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cf91a7bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cf91a7bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cf91a7c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cf91a7b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cf91a7b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cf91a7b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cf96385abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cf9638e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cf96376699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cf963a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ba1f49082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cf8fc9bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x24,0x2d,0x2d,0x2d,0x2d,0x27,0xa,0x3a,0x4e,0x21,0x24,0x47,0x49,0x2d,0x45,0xa,0x40,0x21,0xa,0x2d,0xa,0xa,0x4e,0x24,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x3a,0x4e,0x21,0x24,0x47,0x49,0x2d,0x45,0xa,0x40,0x21,0xa,0x2d,0xa,0xa,0x45,0x47,0x49,0x4e,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x45,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x47,0x49,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0xa,0x1,0x0,0x33,0x4,0xcc,0x96,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0x9a,0x7c,0x0,0x10,0xa5,0xa,0x8d, Step #5: =\012=\012=\012=\012=\012=\012=\012-----BEGI\012-----BEGIN$----'\012:N!$GI-E\012@!\012-\012\012N$-----\012:N!$GI-E\012@!\012-\012\012EGIN\000------\012-----\000-----B$$$$$$$$$$$$$$$$$$$$E\012=\012=\012=GIN\012=\012=\012=\012=\000----\012--\012\001\0003\004\314\226skip_cl\232|\000\020\245\012\215 Step #5: artifact_prefix='./'; Test unit written to ./oom-071c2d984dc221373faca50bf83b76bdcaa290b8 Step #5: Base64: PQo9Cj0KPQo9Cj0KPQotLS0tLUJFR0kKLS0tLS1CRUdJTiQtLS0tJwo6TiEkR0ktRQpAIQotCgpOJC0tLS0tCjpOISRHSS1FCkAhCi0KCkVHSU4ALS0tLS0tCi0tLS0tAC0tLS0tQiQkJCQkJCQkJCQkJCQkJCQkJCQkRQo9Cj0KPUdJTgo9Cj0KPQo9AC0tLS0KLS0KAQAzBMyWc2tpcF9jbJp8ABClCo0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4729 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4101898605 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559837815810, 0x5598379ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5598379ff020,0x5598398970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/071c2d984dc221373faca50bf83b76bdcaa290b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5936 processed earlier; will process 5093 files now Step #5: ==170320== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55982e30a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55983496f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5598349525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5598349524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55982e310d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55982e271b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55982e26c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55982e302c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5598312d1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5598312d1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5598312d1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5598312d1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5598312d1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5598312d1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5598312d1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5598312d1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5598312d1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5598312d1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559833566f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559830293b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55983029ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55983004ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55983004ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55983004b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55983004a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55983004a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55983004a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559834954abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55983495d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559834945699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559834970112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac8e21f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55982e26ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2c,0x2b,0xb,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0xa,0xa,0x2b,0xb,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2b,0x2b,0xa,0x2b,0xa,0x2b,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0xa,0x2b,0xb,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2b,0x2b,0xa,0x2b,0xa,0x2b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2b,0xa,0x2b,0x73,0x73,0x73,0x73,0x73,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0xa,0x2b,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2b,0xa,0x2b,0x73,0x73,0x73,0x73,0x73,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0x73,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0xa,0x2b,0x2b,0x2b,0x2b,0xa,0x2b,0xdf, Step #5: +\012+\012+\012,+\013\012+\012+\012+\012+\012\012\012+\013\000\000\000\000\000\000\000++\012+\012+\000\000\000\000\000\000\012\012+\013\000\000\000\000\000\000\000++\012+\012+\000\000\000\000\000\000\000\000\000\000\000\000\012+\012+ssssss\012+\012+\012+\012+\012+s\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012\012+\000\000\000\000\000\000\012+\012+ssssss\012+\012+\012+\012+\012+s\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012\012++++\012+\337 Step #5: artifact_prefix='./'; Test unit written to ./oom-4f7c8cb5d766f37a2d7ef9404f0b46abab48a37d Step #5: Base64: KworCisKLCsLCisKKworCisKCgorCwAAAAAAAAArKworCisAAAAAAAAKCisLAAAAAAAAACsrCisKKwAAAAAAAAAAAAAAAAorCitzc3Nzc3MKKworCisKKworcworCisKKworCisKKworCisKKworCgorAAAAAAAACisKK3Nzc3NzcworCisKKworCitzCisKKworCisKKworCisKKworCisKCisrKysKK98= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4730 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4102459873 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564568c8e810, 0x564568e7801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564568e78020,0x56456ad100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f7c8cb5d766f37a2d7ef9404f0b46abab48a37d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5937 processed earlier; will process 5092 files now Step #5: ==170356== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56455f7839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564565de8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564565dcb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564565dcb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56455f789d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56455f6eab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56455f6e5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56455f77bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56456274af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56456274af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56456274af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56456274af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56456274af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56456274af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56456274af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56456274af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56456274af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56456274af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5645649dff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56456170cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564561717be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5645614c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5645614c3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5645614c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5645614c3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5645614c3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5645614c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564565dcdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564565dd6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564565dbe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564565de9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f556d2bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56455f6e3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbc,0x8e,0xaf,0xe2,0xc0,0xe2,0xe2,0xbc,0x8e,0x4d,0x3c,0x61,0x62,0x62,0x72,0x3e,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0xe2,0x87,0x92,0x6c,0x20,0x8a,0x9a,0x8d,0x90,0x69,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x3c,0x72,0x74,0x65,0x6e,0x63,0x6f,0xa,0x3e,0xd,0x64,0x65,0x72,0x62,0x3c,0x53,0x43,0x52,0x49,0x50,0x54,0x20,0x6c,0x61,0x21,0x3d,0x46,0x67,0xa,0x49,0x47,0x1,0x2f,0xa,0x47,0x49,0x46,0xff,0xff,0x7e,0x7e,0x6c,0x3c,0x25,0x40,0x20,0x6e,0x7e,0x52,0xba,0xaf,0x20,0x6c,0x61,0x6e,0x67,0x75,0x61,0x67,0x65,0x3d,0x76,0x62,0x73,0x70,0x74,0x6e,0x62,0x65,0x67,0x69,0x6e,0x20,0x39,0x39,0x39,0x20,0x39,0x39,0x54,0x39,0x39,0x5,0xff,0x5a,0x28,0x3e,0x50,0x3d,0x22,0x90,0x6c,0x20,0x8a,0x9a,0x8d,0x90,0x69,0x6f,0x6e,0x3d,0x22,0x31,0x2e,0x30,0x22,0xa,0x3c,0x3f,0x78,0x6c,0x3c,0x41,0x20, Step #5: \357\274\216\257\342\300\342\342\274\216M<abbr>\342\342\342\342\342\342\342\342\342\342\342\342\342\342\342\342\342\342\342\342\342\207\222l \212\232\215\220i\377\377\377\377\377\377\377\377\377<rtenco\012>\015derb<SCRIPT la!=Fg\012IG\001/\012GIF\377\377~~l<%@ n~R\272\257 language=vbsptnbegin 999 99T99\005\377Z(>P=\"\220l \212\232\215\220ion=\"1.0\"\012<?xl<A Step #5: artifact_prefix='./'; Test unit written to ./oom-9bb2b1d99c5de37c9a71d0c7add5359046169c8c Step #5: Base64: 77yOr+LA4uK8jk08YWJicj7i4uLi4uLi4uLi4uLi4uLi4uLi4uKHkmwgipqNkGn///////////88cnRlbmNvCj4NZGVyYjxTQ1JJUFQgbGEhPUZnCklHAS8KR0lG//9+fmw8JUAgbn5Suq8gbGFuZ3VhZ2U9dmJzcHRuYmVnaW4gOTk5IDk5VDk5Bf9aKD5QPSKQbCCKmo2QaW9uPSIxLjAiCjw/eGw8QSA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4731 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4102975208 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558e3fbb4810, 0x558e3fd9e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558e3fd9e020,0x558e41c360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9bb2b1d99c5de37c9a71d0c7add5359046169c8c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5938 processed earlier; will process 5091 files now Step #5: ==170392== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558e366a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558e3cd0e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558e3ccf15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558e3ccf14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558e366afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558e36610b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558e3660b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558e366a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558e39670f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558e39670f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558e39670f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558e39670f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558e39670f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558e39670f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558e39670f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558e39670f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558e39670f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558e39670f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558e3b905f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558e38632b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558e3863dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558e383e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558e383e9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558e383ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558e383e9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558e383e9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558e383e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558e3ccf3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558e3ccfc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558e3cce4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558e3cd0f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f9d222082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558e36609b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0x3b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0x3b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=;=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=---BEGIN -----\012N\012=;=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-c133b4669bf8ae48380909ef083851cdf63fcef1 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Oz0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0tLS1CRUdJTiAtLS0tLQpOCj07PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9AAo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9ChA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4732 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4103508330 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e3e429c810, 0x55e3e448601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e3e4486020,0x55e3e631e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c133b4669bf8ae48380909ef083851cdf63fcef1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5939 processed earlier; will process 5090 files now Step #5: ==170428== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e3dad919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e3e13f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e3e13d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e3e13d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e3dad97d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e3dacf8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e3dacf3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e3dad89c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e3ddd58f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e3ddd58f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e3ddd58f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e3ddd58f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e3ddd58f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e3ddd58f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e3ddd58f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e3ddd58f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e3ddd58f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e3ddd58f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e3dffedf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e3dcd1ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e3dcd25be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e3dcad1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e3dcad1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e3dcad2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e3dcad1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e3dcad1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e3dcad1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e3e13dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e3e13e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e3e13cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e3e13f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f925cea8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e3dacf1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x4e,0x4f,0x54,0x41,0x54,0x49,0x4f,0x4e,0xd,0x54,0x9,0x50,0x55,0x42,0x4c,0x49,0x43,0xd,0x25,0x55,0x3b,0x9,0x25,0x41,0x3b,0x9,0x9,0x25,0x41,0x3b,0x25,0x41,0x3b,0x9,0x25,0xe1,0x85,0x9f,0x41,0x3b,0x9,0x9,0x25,0xe1,0x85,0x9f,0x41,0x3b,0x9,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x25,0x41,0x41,0x41,0x3b,0x9,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x9,0x9,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x9,0x25,0xe1,0x85,0x9f,0x41,0x3b,0x9,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x25,0x41,0x3b,0x9,0x9,0x25,0x41,0x3b,0x25,0x55,0x3b,0x9,0x25,0x41,0x3b,0x9,0x25,0x41,0x3b,0x9,0x27,0x27,0x3e, Step #5: <!NOTATION\015T\011PUBLIC\015%U;\011%A;\011\011%A;%A;\011%\341\205\237A;\011\011%\341\205\237A;\011%A;\011%A;%A;\011%A;\011%A;%AAA;\011%A;\011%A;\011%A;\011\011%A;\011%A;\011%\341\205\237A;\011%A;\011%A;%A;\011%A;\011%A;%A;\011%A;%A;\011%A;\011%A;\011%A;\011%A;%A;\011\011%A;%U;\011%A;\011%A;\011''> Step #5: artifact_prefix='./'; Test unit written to ./oom-25e76a668f604b1aae30e9ee569fc5314f3f6bda Step #5: Base64: PCFOT1RBVElPTg1UCVBVQkxJQw0lVTsJJUE7CQklQTslQTsJJeGFn0E7CQkl4YWfQTsJJUE7CSVBOyVBOwklQTsJJUE7JUFBQTsJJUE7CSVBOwklQTsJCSVBOwklQTsJJeGFn0E7CSVBOwklQTslQTsJJUE7CSVBOyVBOwklQTslQTsJJUE7CSVBOwklQTsJJUE7JUE7CQklQTslVTsJJUE7CSVBOwknJz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4733 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4104025209 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5591a10f1810, 0x5591a12db01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5591a12db020,0x5591a31730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/25e76a668f604b1aae30e9ee569fc5314f3f6bda' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5940 processed earlier; will process 5089 files now Step #5: ==170464== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559197be69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55919e24b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55919e22e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55919e22e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559197becd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559197b4db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559197b48355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559197bdec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55919abadf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55919abadf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55919abadf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55919abadf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55919abadf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55919abadf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55919abadf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55919abadf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55919abadf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55919abadf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55919ce42f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559199b6fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559199b7abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559199926c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559199926c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559199927738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559199926874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559199926874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559199926874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55919e230abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55919e239928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55919e221699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55919e24c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9918a84082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559197b46b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x44,0x5f,0x6e,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x44,0x5f,0x6e,0x4d, Step #5: **************************************************************************************************************************************************************D_n******D_nM Step #5: artifact_prefix='./'; Test unit written to ./oom-34b45938ec44b2c724dbe9bbd1beb81e1c9f0950 Step #5: Base64: KioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKipEX24qKioqKipEX25N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4734 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4104560738 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563eda9f8810, 0x563edabe201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563edabe2020,0x563edca7a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/34b45938ec44b2c724dbe9bbd1beb81e1c9f0950' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5941 processed earlier; will process 5088 files now Step #5: ==170500== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563ed14ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563ed7b52898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563ed7b355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563ed7b354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563ed14f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563ed1454b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563ed144f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563ed14e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563ed44b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563ed44b4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563ed44b4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563ed44b4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563ed44b4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563ed44b4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563ed44b4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563ed44b4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563ed44b4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563ed44b4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563ed6749f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563ed3476b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563ed3481be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563ed322dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563ed322dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563ed322e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563ed322d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563ed322d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563ed322d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563ed7b37abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563ed7b40928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563ed7b28699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563ed7b53112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f65df5a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563ed144db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x2c,0x5b,0x2d,0x2c,0x2d,0xe2,0xb1,0xb1,0x2c,0x2d,0xe2,0xb1,0xb1,0x2c,0x2f,0xe2,0x81,0xa1,0x2c,0x2d,0xe2,0xb1,0xb1,0x2c,0x2d,0xe2,0xb1,0xaf,0x2c,0x2d,0xe2,0x89,0xa1,0x2c,0x2d,0xe2,0xb1,0xb0,0x2c,0x2d,0xe2,0x81,0x81,0x2c,0x2d,0xe2,0xbb,0xb7,0x2c,0x2d,0xe2,0x81,0xb1,0x2c,0x2d,0xe2,0xb1,0xb1,0x2c,0x2d,0xe2,0xb1,0xb1,0x2c,0x2d,0xe2,0x81,0xa1,0x2c,0x2d,0xe2,0xb1,0xb1,0x2b,0x2c,0x2d,0xe2,0xa1,0x81,0x2c,0x2d,0xe2,0xb1,0xb0,0x2c,0x2d,0xe2,0x81,0xa1,0x2c,0x2d,0xe2,0xb1,0xb5,0x2c,0x2d,0xe2,0x81,0xb1,0x2b,0x2c,0x2d,0xe2,0xa1,0x81,0x2c,0x2d,0xe2,0xb1,0xb0,0x2c,0x2d,0xe2,0x81,0xa1,0x2c,0x2d,0xe2,0xb1,0xb5,0x2c,0x2d,0xe2,0x81,0xb1,0x2c,0x2d,0xe2,0xb1,0xb1,0x2c,0x2d,0xe2,0xb1,0xb1,0x2c,0x2d,0xe2,0x81,0xa1,0x2c,0x2d,0xe2,0xb1,0xb1,0x2c,0x2d,0xe2,0x81,0xb1,0x2c,0x2d,0xe2,0xb3,0xb1,0x2c,0x2d,0xe2,0xb1,0xb1,0x2c,0x2d,0xe2,0xb1,0xb1,0x2c,0x2d,0xe2,0xb2,0xb1, Step #5: f,[-,-\342\261\261,-\342\261\261,/\342\201\241,-\342\261\261,-\342\261\257,-\342\211\241,-\342\261\260,-\342\201\201,-\342\273\267,-\342\201\261,-\342\261\261,-\342\261\261,-\342\201\241,-\342\261\261+,-\342\241\201,-\342\261\260,-\342\201\241,-\342\261\265,-\342\201\261+,-\342\241\201,-\342\261\260,-\342\201\241,-\342\261\265,-\342\201\261,-\342\261\261,-\342\261\261,-\342\201\241,-\342\261\261,-\342\201\261,-\342\263\261,-\342\261\261,-\342\261\261,-\342\262\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-35ee2c1c43a6d884a721d6209714937b94a6c7e5 Step #5: Base64: ZixbLSwt4rGxLC3isbEsL+KBoSwt4rGxLC3isa8sLeKJoSwt4rGwLC3igYEsLeK7tywt4oGxLC3isbEsLeKxsSwt4oGhLC3isbErLC3ioYEsLeKxsCwt4oGhLC3isbUsLeKBsSssLeKhgSwt4rGwLC3igaEsLeKxtSwt4oGxLC3isbEsLeKxsSwt4oGhLC3isbEsLeKBsSwt4rOxLC3isbEsLeKxsSwt4rKx Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4735 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4105080558 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55575b95a810, 0x55575bb4401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55575bb44020,0x55575d9dc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/35ee2c1c43a6d884a721d6209714937b94a6c7e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5942 processed earlier; will process 5087 files now Step #5: #1 pulse cov: 3710 ft: 3711 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 3786 ft: 4123 exec/s: 0 rss: 177Mb Step #5: ==170536== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55575244f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555758ab4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555758a975dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555758a974fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555752455d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557523b6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5557523b1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555752447c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555755416f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555755416f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555755416f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555755416f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555755416f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555755416f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555755416f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555755416f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555755416f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555755416f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5557576abf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557543d8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557543e3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55575418fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55575418fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555754190738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55575418f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55575418f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55575418f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555758a99abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555758aa2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555758a8a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555758ab5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb626b65082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5557523afb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xd5,0xbb,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xbc,0xb1,0x2e,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xe0,0xd5,0xd5,0xd5,0xd5,0xd5,0xd5,0xd5,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x6e,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x44,0x5f,0x6e,0x4d, Step #5: \000********************************\325\273******************************************************\274\261.**********\340\325\325\325\325\325\325\325************************************\377\377\377\377\377\377\377\377\377\377\377\377\377\377n******D_nM Step #5: artifact_prefix='./'; Test unit written to ./oom-49278971a07111c76683efe7242cc08ff4d12cc7 Step #5: Base64: ACoqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioq1bsqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKiq8sS4qKioqKioqKioq4NXV1dXV1dUqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKir//////////////////24qKioqKipEX25N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4736 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4105684786 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b4d5b1810, 0x561b4d79b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b4d79b020,0x561b4f6330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/49278971a07111c76683efe7242cc08ff4d12cc7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5945 processed earlier; will process 5084 files now Step #5: ==170572== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561b440a69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b4a70b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b4a6ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b4a6ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b440acd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b4400db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b44008355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b4409ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b4706df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b4706df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b4706df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b4706df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b4706df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b4706df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b4706df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b4706df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b4706df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b4706df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b49302f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b4602fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b4603abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b45de6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b45de6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b45de7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b45de6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b45de6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b45de6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b4a6f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b4a6f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b4a6e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b4a70c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ddfe21082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b44006b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4d,0x6e,0x61,0x6d,0x65,0x0,0x0,0x0,0x0,0x0,0x6c,0x7c,0x7c,0x0,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x3,0x0,0x0,0x0,0x0,0x0,0x33,0x0,0x0,0x0,0x0,0x6c,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x11,0xdc,0xb0,0x8,0x29,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x6f,0xcc,0x1,0x0,0x0,0x0,0xcc,0x0,0xcc,0xb0,0x4e,0x9,0x8,0x6f,0xcc,0xb0,0x4e,0x6f,0x6f,0x28,0xdc,0xb0,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xd6,0xae,0x0,0x0,0x0,0x27,0xc4,0xb0,0x4e,0xd6,0xae,0xd5,0x0,0x0, Step #5: Mname\000\000\000\000\000l||\000\003\003\003\003\003\003\003\003\003\003\003\003\000\000\000\000\0003\000\000\000\000l^^^^^^^^^^^^^^^\021\334\260\010)^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^o\314\001\000\000\000\314\000\314\260N\011\010o\314\260Noo(\334\260^^^^^^^^^^^\000\000\000\000\000\000\000\000\000\000\326\256\000\000\000'\304\260N\326\256\325\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a391aaff1bbc32fdd3febd1a2b3087865593cc30 Step #5: Base64: TW5hbWUAAAAAAGx8fAADAwMDAwMDAwMDAwMAAAAAADMAAAAAbF5eXl5eXl5eXl5eXl5eXhHcsAgpXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eb8wBAAAAzADMsE4JCG/MsE5vbyjcsF5eXl5eXl5eXl5eAAAAAAAAAAAAANauAAAAJ8SwTtau1QAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4737 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4106206055 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a0bdf2810, 0x561a0bfdc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a0bfdc020,0x561a0de740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a391aaff1bbc32fdd3febd1a2b3087865593cc30' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5946 processed earlier; will process 5083 files now Step #5: ==170608== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561a028e79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561a08f4c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561a08f2f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561a08f2f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561a028edd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561a0284eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561a02849355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561a028dfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561a058aef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561a058aef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561a058aef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561a058aef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561a058aef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561a058aef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561a058aef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561a058aef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561a058aef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561a058aef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561a07b43f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561a04870b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561a0487bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561a04627c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561a04627c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561a04628738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561a04627874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561a04627874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561a04627874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561a08f31abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561a08f3a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561a08f22699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561a08f4d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f61057ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561a02847b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf2,0xa0,0x8f,0x88,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0x93,0xf3,0xa0,0x82,0x87,0xf4,0x87,0x80,0x93,0xf3,0xa0,0x82,0x87,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0xa9,0xf3,0x87,0x80,0x93,0xf3,0xa0,0x80,0x99,0xf1,0xb5,0x87,0x88,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0xa9,0xf3,0x87,0x80,0x93,0xf3,0xa0,0x80,0x88,0xf3,0xa0,0x81,0xa1,0xf4,0x83,0x80,0x9f,0xf3,0xa0,0xa0,0x99,0xf0,0xb5,0x88,0x92,0xf0,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf3,0x9f,0x81,0xa1,0xf4,0x83,0x88,0x9f,0xf3,0xb5,0x80,0x99,0xf1,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf4,0x83,0x81,0x99,0xf3,0xa0,0x8f,0x89,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0x93,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0xa9,0xf3,0x87,0x80,0x9f,0xf3,0xa0,0xa0,0x99,0xf0,0xb5,0x88,0x92,0xf0,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf4,0x83,0x81,0x99,0xf3,0xa0,0x87,0x88,0xf4,0x83,0x80,0xa9,0xf3,0xa0,0x87,0x88,0xf4,0x84,0x81,0x99,0xf0,0xb5,0xb1, Step #5: \362\240\217\210\364\203\200\251\364\207\200\223\363\240\202\207\364\207\200\223\363\240\202\207\364\203\200\251\364\207\200\251\363\207\200\223\363\240\200\231\361\265\207\210\364\203\200\251\364\207\200\251\363\207\200\223\363\240\200\210\363\240\201\241\364\203\200\237\363\240\240\231\360\265\210\222\360\265\207\210\364\203\207\210\363\237\201\241\364\203\210\237\363\265\200\231\361\265\207\210\364\203\207\210\364\203\201\231\363\240\217\211\364\203\200\251\364\207\200\223\364\203\200\251\364\207\200\251\363\207\200\237\363\240\240\231\360\265\210\222\360\265\207\210\364\203\207\210\364\203\201\231\363\240\207\210\364\203\200\251\363\240\207\210\364\204\201\231\360\265\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-1c3a7c45be7f5ab85514647fe8f1b5d0e512492b Step #5: Base64: 8qCPiPSDgKn0h4CT86CCh/SHgJPzoIKH9IOAqfSHgKnzh4CT86CAmfG1h4j0g4Cp9IeAqfOHgJPzoICI86CBofSDgJ/zoKCZ8LWIkvC1h4j0g4eI85+BofSDiJ/ztYCZ8bWHiPSDh4j0g4GZ86CPifSDgKn0h4CT9IOAqfSHgKnzh4Cf86CgmfC1iJLwtYeI9IOHiPSDgZnzoIeI9IOAqfOgh4j0hIGZ8LWx Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4738 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4106722637 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e2d439810, 0x559e2d62301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e2d623020,0x559e2f4bb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c3a7c45be7f5ab85514647fe8f1b5d0e512492b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5947 processed earlier; will process 5082 files now Step #5: ==170644== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559e23f2e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e2a593898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e2a5765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e2a5764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e23f34d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e23e95b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e23e90355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e23f26c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e26ef5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e26ef5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e26ef5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e26ef5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e26ef5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e26ef5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e26ef5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e26ef5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e26ef5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e26ef5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e2918af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e25eb7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e25ec2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e25c6ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e25c6ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e25c6f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e25c6e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e25c6e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e25c6e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e2a578abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e2a581928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e2a569699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e2a594112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5803177082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e23e8eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x6f,0x63,0x69,0x56,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x31,0x2e,0x30,0x2e,0x30,0x22,0x2c,0x22,0x70,0x72,0x6f,0x63,0x65,0x73,0x73,0x22,0x3a,0x7b,0x22,0x63,0x77,0x64,0x22,0x3a,0x22,0x24,0x7a,0x28,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x24,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x45,0x45,0x3b,0x45,0x3b,0x3b,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x45,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x39,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x22,0x7d,0x7d, Step #5: {\"ociVersion\":\"1.0.0\",\"process\":{\"cwd\":\"$z(;;;;;;;;;;;;;;;;;;;;;;;$;;;;;;;;;;;;;;;;;;;;EE;E;;EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE;;;;;;;;;;;;;9;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-caefa31e187a28b4c2d172c0634554f5c9fcf003 Step #5: Base64: eyJvY2lWZXJzaW9uIjoiMS4wLjAiLCJwcm9jZXNzIjp7ImN3ZCI6IiR6KDs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7JDs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7RUU7RTs7RUVFRUVFRUVFRUVFRUVFRUVFRUVFRUVFRUVFRUVFRTs7Ozs7Ozs7Ozs7Ozs5Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7In19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4739 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4107243495 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556458f0b810, 0x5564590f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564590f5020,0x55645af8d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/caefa31e187a28b4c2d172c0634554f5c9fcf003' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5948 processed earlier; will process 5081 files now Step #5: ==170680== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55644fa009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556456065898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564560485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564560484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55644fa06d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55644f967b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55644f962355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55644f9f8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564529c7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564529c7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564529c7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564529c7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564529c7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564529c7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564529c7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564529c7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564529c7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564529c7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556454c5cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556451989b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556451994be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556451740c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556451740c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556451741738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556451740874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556451740874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556451740874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55645604aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556456053928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55645603b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556456066112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f54601f0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55644f960b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2d,0x49,0x4e,0x20,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2c,0xb,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2c,0xa,0x2d,0xa,0xa,0x64,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2c,0x1,0x0,0x0,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2,0xa,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2,0xa,0x2d,0xa,0x64,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x2c,0x1,0x0,0x0,0xf,0xa,0x2d,0xa,0x64,0xa,0x2,0xa,0x2d,0xa,0x2d,0xa,0x62,0xa,0xd0,0xa,0x2d,0xa,0x64,0xa,0xd5,0xa,0x2,0xa,0x33,0xa,0xdc,0xa,0xd2,0xa,0x0,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xff, Step #5: \000-IN \005-----\012,\013-\012d\012-\012d\012-\012d\012d\012-\012\002\012-\012\002\012-\012,\012-\012\012d\012-\012\002\012-\012,\012-\012d\012\002\012-\012d\012-\012\002\012-\012\002\012-\012,\001\000\000d\012-\012d\012d\012\002\012-\012,\012-\012d\012-\012d\012d\012-\012\002\012-\012,\012-\012d\012\002\012-\012d\012-\012\002\012-\012\002\012-\012,\001\000\000\017\012-\012d\012\002\012-\012-\012b\012\320\012-\012d\012\325\012\002\0123\012\334\012\322\012\000\012-\012-\012-\012\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-6d3cd6a393d1683a2c5c81d260a621ca558bd2b0 Step #5: Base64: AC1JTiAFLS0tLS0KLAstCmQKLQpkCi0KZApkCi0KAgotCgIKLQosCi0KCmQKLQoCCi0KLAotCmQKAgotCmQKLQoCCi0KAgotCiwBAABkCi0KZApkCgIKLQosCi0KZAotCmQKZAotCgIKLQosCi0KZAoCCi0KZAotCgIKLQoCCi0KLAEAAA8KLQpkCgIKLQotCmIK0AotCmQK1QoCCjMK3ArSCgAKLQotCi0K/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4740 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4107799467 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e762fd810, 0x555e764e701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e764e7020,0x555e7837f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6d3cd6a393d1683a2c5c81d260a621ca558bd2b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5949 processed earlier; will process 5080 files now Step #5: ==170716== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555e6cdf29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e73457898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e7343a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e7343a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e6cdf8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e6cd59b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e6cd54355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e6cdeac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e6fdb9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e6fdb9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e6fdb9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e6fdb9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e6fdb9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e6fdb9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e6fdb9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e6fdb9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e6fdb9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e6fdb9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e7204ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e6ed7bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e6ed86be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e6eb32c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e6eb32c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e6eb33738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e6eb32874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e6eb32874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e6eb32874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e7343cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e73445928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e7342d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e73458112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f869cd6f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e6cd52b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc,0x20,0xc,0x20,0xc,0x5b,0xc,0x20,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x2c,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x64,0x60,0x60,0x60,0x60,0x60,0x20,0xc,0x20,0xc,0x20,0xc,0x20,0xc,0x20,0xc,0x20,0xc,0x5d,0xc,0xc,0x20,0xc,0x20,0x20,0xc,0x20,0xc,0x20,0xc,0x20,0xc,0x20,0xc,0x20,0x2b,0x5b,0xc,0x20,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x2c,0x60,0x60,0x60,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x60,0x60,0x60,0xc,0x20,0xc,0x20,0xc,0x20,0xc,0x20,0xc,0x5d,0x20,0xc,0xb1,0x46,0x46,0x7c,0x7c,0x7c,0xd,0xbd,0x2d,0x2d,0x2d,0x31,0xff,0xd3,0x1,0x25,0x0,0x0,0x2f,0xd2,0x2b,0xab,0xab,0xab,0xab,0x25,0x0,0x0,0x2f,0xd2,0x2b,0xab,0xab,0x0,0x0,0x2f,0xd2,0x2b,0xab,0xab,0xab,0xf3,0xa0,0x81,0x8a,0xab,0xab,0xab,0xab, Step #5: \014 \014 \014[\014 ``````````````````,```````d````` \014 \014 \014 \014 \014 \014]\014\014 \014 \014 \014 \014 \014 \014 +[\014 ``````````````````,```jjjjjjjjjjjjj```\014 \014 \014 \014 \014] \014\261FF|||\015\275---1\377\323\001%\000\000/\322+\253\253\253\253%\000\000/\322+\253\253\000\000/\322+\253\253\253\363\240\201\212\253\253\253\253 Step #5: artifact_prefix='./'; Test unit written to ./oom-3f05d4ea59be269b9ef13f387b7596a77e7e7762 Step #5: Base64: DCAMIAxbDCBgYGBgYGBgYGBgYGBgYGBgYGAsYGBgYGBgYGRgYGBgYCAMIAwgDCAMIAwgDF0MDCAMICAMIAwgDCAMIAwgK1sMIGBgYGBgYGBgYGBgYGBgYGBgYCxgYGBqampqampqampqampqYGBgDCAMIAwgDCAMXSAMsUZGfHx8Db0tLS0x/9MBJQAAL9Irq6urqyUAAC/SK6urAAAv0iurq6vzoIGKq6urqw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4741 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4108462134 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56469ca13810, 0x56469cbfd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56469cbfd020,0x56469ea950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3f05d4ea59be269b9ef13f387b7596a77e7e7762' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5950 processed earlier; will process 5079 files now Step #5: ==170752== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5646935089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564699b6d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564699b505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564699b504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56469350ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56469346fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56469346a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564693500c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5646964cff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5646964cff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5646964cff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5646964cff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5646964cff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5646964cff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5646964cff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5646964cff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5646964cff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5646964cff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564698764f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564695491b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56469549cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564695248c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564695248c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564695249738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564695248874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564695248874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564695248874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564699b52abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564699b5b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564699b43699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564699b6e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b954eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564693468b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x7a,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x7a,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x4d,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x13,0x60,0x62,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6c,0x6e,0x3b,0x6c,0x6c,0x6c,0x7e,0x6c,0x6c,0x3b,0x6c,0x6c,0x0,0x80, Step #5: `UUUUUUUUUUUUUUzUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUzUUUUUUUUUUUUUUUUUUUUUUUUCCCCCCCCCCCCCMCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC\023`bllllllln;lll~ll;ll\000\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-410f8d80b4b02d9a44f79ca9ae384e3bc6b1c959 Step #5: Base64: YFVVVVVVVVVVVVVVVVVVelVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVelVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVUNDQ0NDQ0NDQ0NDQ0NNQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0MTYGJsbGxsbGxsbjtsbGx+bGw7bGwAgA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4742 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4109095071 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562a6a13c810, 0x562a6a32601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562a6a326020,0x562a6c1be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/410f8d80b4b02d9a44f79ca9ae384e3bc6b1c959' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5951 processed earlier; will process 5078 files now Step #5: #1 pulse cov: 3522 ft: 3523 exec/s: 0 rss: 176Mb Step #5: ==170788== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562a60c319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562a67296898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562a672795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562a672794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562a60c37d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562a60b98b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562a60b93355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562a60c29c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562a63bf8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562a63bf8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562a63bf8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562a63bf8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562a63bf8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562a63bf8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562a63bf8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562a63bf8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562a63bf8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562a63bf8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562a65e8df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562a62bbab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562a62bc5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562a62971c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562a62971c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562a62972738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562a62971874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562a62971874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562a62971874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562a6727babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562a67284928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562a6726c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562a67297112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f75af93c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562a60b91b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x69,0x63,0x31,0x32,0x65,0x3e,0x5c,0x41,0x22,0x5c,0x38,0x5c,0x30,0x42,0x22,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x5c,0x41,0x22,0x5c,0x32,0x5c,0x30,0x42,0x22,0x22,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x5c,0x41,0x22,0x5c,0x38,0x5c,0x30,0x42,0x22,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x5c,0x41,0x22,0x5c,0x33,0x5c,0x30,0x42,0x22,0x22,0x5c,0x30,0x42,0x32,0x66,0x42,0x22,0x22,0x5c,0x30,0x42,0x32,0x6c,0x65,0x3e,0x5c,0x41,0x22,0x5c,0x33,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x5c,0x41,0x22,0x5c,0x38,0x5c,0x30,0x42,0x22,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x5c,0x41,0x22,0x5c,0x32,0x5c,0x30,0x42,0x22,0x22,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x5c,0x41,0x22,0x5c,0x38,0x5c,0x30,0x42,0x22,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x5c,0x61,0x22,0x5c,0x33,0x5c,0x30,0x42,0x22,0x22,0x5c,0x30,0x42,0x32,0x66,0x42,0x32,0x37,0x36,0x5c,0x32,0x37,0x36,0x39,0x4, Step #5: <svg><ic12e>\\A\"\\8\\0B\"<style>\\A\"\\2\\0B\"\"<style>\\A\"\\8\\0B\"<style>\\A\"\\3\\0B\"\"\\0B2fB\"\"\\0B2le>\\A\"\\3<style>\\A\"\\8\\0B\"<style>\\A\"\\2\\0B\"\"<style>\\A\"\\8\\0B\"<style>\\a\"\\3\\0B\"\"\\0B2fB276\\2769\004 Step #5: artifact_prefix='./'; Test unit written to ./oom-64224d2309f0e8db147aba6bf3333598bcc1334f Step #5: Base64: PHN2Zz48aWMxMmU+XEEiXDhcMEIiPHN0eWxlPlxBIlwyXDBCIiI8c3R5bGU+XEEiXDhcMEIiPHN0eWxlPlxBIlwzXDBCIiJcMEIyZkIiIlwwQjJsZT5cQSJcMzxzdHlsZT5cQSJcOFwwQiI8c3R5bGU+XEEiXDJcMEIiIjxzdHlsZT5cQSJcOFwwQiI8c3R5bGU+XGEiXDNcMEIiIlwwQjJmQjI3NlwyNzY5BA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4743 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4109657140 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb1622c810, 0x55cb1641601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb16416020,0x55cb182ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/64224d2309f0e8db147aba6bf3333598bcc1334f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5953 processed earlier; will process 5076 files now Step #5: #1 pulse cov: 3975 ft: 3976 exec/s: 0 rss: 177Mb Step #5: ==170824== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cb0cd219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb13386898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb133695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb133694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb0cd27d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb0cc88b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb0cc83355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb0cd19c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb0fce8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb0fce8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb0fce8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb0fce8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb0fce8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb0fce8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb0fce8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb0fce8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb0fce8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb0fce8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb11f7df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb0ecaab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb0ecb5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb0ea61c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb0ea61c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb0ea62738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb0ea61874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb0ea61874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb0ea61874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb1336babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb13374928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb1335c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb13387112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe19f74082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb0cc81b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c,0x69,0x73,0x74,0x20,0x7b,0xa,0x20,0x20,0x4e,0x65,0x77,0x58,0x4f,0x46,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x73,0x69,0x7a,0x65,0x3a,0x20,0x32,0x37,0x36,0x34,0x38,0xa,0x20,0x20,0x20,0x20,0x6b,0x65,0x79,0x3a,0x20,0x22,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x67,0x6f,0x6f,0x67,0x6c,0x65,0x2e,0x70,0x72,0x6f,0x74,0x6f,0x62,0x75,0x66,0x2e,0x46,0x69,0x65,0x6c,0x64,0x4f,0x70,0x74,0x58,0x58,0x58,0x5f,0x4f,0x6e,0x65,0x6f,0x66,0x46,0x75,0x6e,0x6e,0x73,0x2e,0x53,0x54,0x52,0x49,0x4e,0x47,0x2c,0x2c,0x3a,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x3a,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x2c,0x22,0xa,0x20,0x20,0x7d,0xa,0x7d,0xa, Step #5: list {\012 NewXOF {\012 size: 27648\012 key: \",,,,,,,google.protobuf.FieldOptXXX_OneofFunns.STRING,,:,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,:,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,\"\012 }\012}\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-f9efc6be6217cf0099f4f4e77a8238cffce382f9 Step #5: Base64: bGlzdCB7CiAgTmV3WE9GIHsKICAgIHNpemU6IDI3NjQ4CiAgICBrZXk6ICIsLCwsLCwsZ29vZ2xlLnByb3RvYnVmLkZpZWxkT3B0WFhYX09uZW9mRnVubnMuU1RSSU5HLCw6LCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLDosLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwiCiAgfQp9Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4744 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4110209442 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fecef3a810, 0x55fecf12401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fecf124020,0x55fed0fbc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9efc6be6217cf0099f4f4e77a8238cffce382f9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5955 processed earlier; will process 5074 files now Step #5: #1 pulse cov: 3916 ft: 3917 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4716 ft: 5196 exec/s: 0 rss: 178Mb Step #5: ==170860== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fec5a2f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fecc094898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fecc0775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fecc0774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fec5a35d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fec5996b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fec5991355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fec5a27c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fec89f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fec89f6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fec89f6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fec89f6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fec89f6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fec89f6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fec89f6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fec89f6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fec89f6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fec89f6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fecac8bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fec79b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fec79c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fec776fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fec776fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fec7770738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fec776f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fec776f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fec776f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fecc079abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fecc082928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fecc06a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fecc095112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0a9714d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fec598fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x37,0x37,0x60,0x38,0xe,0x31,0x60,0x38,0x60,0x36,0xe,0x31,0x60,0x31,0x60,0x38,0x60,0x36,0x60,0x38,0x60,0x31,0x60,0x32,0x60,0x30,0x60,0x31,0x60,0x31,0xe,0x30,0x60,0x30,0x60,0x38,0x60,0x36,0xe,0x31,0x60,0x31,0x60,0x38,0x60,0x36,0x60,0x31,0x60,0x38,0x60,0x31,0x60,0x30,0x60,0x31,0x60,0x31,0x60,0x31,0x60,0x38,0x60,0x36,0xe,0x31,0x60,0x31,0x60,0x38,0x60,0x31,0xe,0x31,0x60,0x32,0x60,0x31,0x60,0x30,0x60,0x37,0xe,0x31,0x60,0x31,0x60,0x38,0x60,0x36,0xe,0x31,0x60,0x31,0x60,0x38,0x60,0x31,0x60,0x38,0xe,0x31,0x60,0x38,0x60,0x30,0xe,0x31,0x60,0x31,0x60,0x38,0x60,0x36,0x60,0x38,0x60,0x31,0x60,0x31,0x60,0x31,0x60,0x38,0x60,0x31,0xe,0x31,0x60,0x31,0x60,0x31,0x60,0x38,0x60,0x36,0xe,0x31,0x9,0x31,0x60,0x38,0x60,0x36,0xe,0x31,0x60,0x31,0x60,0x31,0x60,0x39,0x60,0x31,0xe,0x31,0x60,0x32,0x60,0x31,0x72,0x38,0x60,0x31,0x60,0x31,0x60,0x31,0x60,0x31,0x77,0x30, Step #5: 77`8\0161`8`6\0161`1`8`6`8`1`2`0`1`1\0160`0`8`6\0161`1`8`6`1`8`1`0`1`1`1`8`6\0161`1`8`1\0161`2`1`0`7\0161`1`8`6\0161`1`8`1`8\0161`8`0\0161`1`8`6`8`1`1`1`8`1\0161`1`1`8`6\0161\0111`8`6\0161`1`1`9`1\0161`2`1r8`1`1`1`1w0 Step #5: artifact_prefix='./'; Test unit written to ./oom-264649abe0268c1360f7d0152c8c1ecd013857f4 Step #5: Base64: NzdgOA4xYDhgNg4xYDFgOGA2YDhgMWAyYDBgMWAxDjBgMGA4YDYOMWAxYDhgNmAxYDhgMWAwYDFgMWAxYDhgNg4xYDFgOGAxDjFgMmAxYDBgNw4xYDFgOGA2DjFgMWA4YDFgOA4xYDhgMA4xYDFgOGA2YDhgMWAxYDFgOGAxDjFgMWAxYDhgNg4xCTFgOGA2DjFgMWAxYDlgMQ4xYDJgMXI4YDFgMWAxYDF3MA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4745 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4110958198 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ce6446810, 0x561ce663001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ce6630020,0x561ce84c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/264649abe0268c1360f7d0152c8c1ecd013857f4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5958 processed earlier; will process 5071 files now Step #5: ==170896== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561cdcf3b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561ce35a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561ce35835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561ce35834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561cdcf41d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561cdcea2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561cdce9d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561cdcf33c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561cdff02f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561cdff02f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561cdff02f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561cdff02f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561cdff02f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561cdff02f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561cdff02f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561cdff02f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561cdff02f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561cdff02f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561ce2197f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561cdeec4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561cdeecfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561cdec7bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561cdec7bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561cdec7c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561cdec7b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561cdec7b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561cdec7b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561ce3585abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561ce358e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561ce3576699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561ce35a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f69583ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561cdce9bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x7a,0x69,0x69,0x69,0x66,0x69, Step #5: i\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"ziiifi Step #5: artifact_prefix='./'; Test unit written to ./oom-9997a25b52bfb7967f070d3a37a0f2ace20e0cab Step #5: Base64: aSIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiInppaWlmaQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4746 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4111474608 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4f8caa810, 0x55e4f8e9401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4f8e94020,0x55e4fad2c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9997a25b52bfb7967f070d3a37a0f2ace20e0cab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5959 processed earlier; will process 5070 files now Step #5: ==170932== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e4ef79f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4f5e04898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4f5de75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4f5de74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4ef7a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4ef706b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4ef701355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4ef797c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4f2766f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4f2766f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4f2766f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4f2766f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4f2766f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4f2766f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4f2766f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4f2766f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4f2766f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4f2766f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4f49fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4f1728b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4f1733be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4f14dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4f14dfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4f14e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4f14df874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4f14df874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4f14df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4f5de9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4f5df2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4f5dda699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4f5e05112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4d2957f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4ef6ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0x6e,0x63,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x6e,0xe5,0x8f,0xb8,0x2e,0x2e,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x6e,0xe5,0x8f,0xb8,0x2e,0x2e,0x2e,0x78,0x6e,0x63,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xa,0x2e,0x78,0x6e,0x63,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xa, Step #5: \360\221\226\271\360\221\222\275.x\360\221\226\271\360\221\222\275\012\360\221\226\271\360\221\222\275.xncx\360\221\226\271\360\221\222\275\360\221\226\271\360\221\222\275.x\360\221\226\271\360\221\222\275\012\360\221\226\271\360\221\222\275n\345\217\270..\360\221\226\271\360\221\222\275.x\360\221\226\271\360\221\222\275\012\360\221\226\271\360\221\222\275.\360\221\226\271\360\221\222\275\360\221\226\271\360\221\222\275.x\360\221\226\271\360\221\222\275\012\360\221\226\271\360\221\222\275n\345\217\270...xncx\360\221\226\271\360\221\222\275\012\012.xncx\360\221\226\271\360\221\222\275\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-2c03e76e0767f746555ea53abb129d7237b30f77 Step #5: Base64: 8JGWufCRkr0uePCRlrnwkZK9CvCRlrnwkZK9LnhuY3jwkZa58JGSvfCRlrnwkZK9LnjwkZa58JGSvQrwkZa58JGSvW7lj7guLvCRlrnwkZK9LnjwkZa58JGSvQrwkZa58JGSvS7wkZa58JGSvfCRlrnwkZK9LnjwkZa58JGSvQrwkZa58JGSvW7lj7guLi54bmN48JGWufCRkr0KCi54bmN48JGWufCRkr0KCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4747 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4111997465 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b2332a5810, 0x55b23348f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b23348f020,0x55b2353270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2c03e76e0767f746555ea53abb129d7237b30f77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5960 processed earlier; will process 5069 files now Step #5: ==170968== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b229d9a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b2303ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b2303e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b2303e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b229da0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b229d01b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b229cfc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b229d92c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b22cd61f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b22cd61f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b22cd61f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b22cd61f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b22cd61f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b22cd61f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b22cd61f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b22cd61f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b22cd61f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b22cd61f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b22eff6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b22bd23b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b22bd2ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b22badac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b22badac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b22badb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b22bada874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b22bada874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b22bada874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b2303e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b2303ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b2303d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b230400112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa06c6fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b229cfab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x61,0x5c,0x23,0x73,0x63,0x65,0x6e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x46,0x20,0x0,0x61,0x5c,0x23,0x72,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x3f,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x6e,0x0,0x0,0x0,0x0,0x0,0x0,0x73,0x74,0x7b,0x65,0x61,0x6d,0x0,0x0,0x0,0x0,0x20,0x5c,0x23,0x23,0x68,0xb,0xb,0xb,0x28,0xe0,0xea,0x14,0x38,0xc6,0x6d,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xb,0xb,0xb,0xb,0xb,0xb,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x4f,0xa,0x3d,0xa,0x3d,0xa,0xb,0xb,0x3d,0xa,0x3d, Step #5: a\\#scen\000\000\000\000\000\000\000\000\000\000\000\000\000\012\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000F \000a\\#rnnnnnn?nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn\000\000\000\000\000\000st{eam\000\000\000\000 \\##h\013\013\013(\340\352\0248\306m-\012=\012=\012=\012=\013\013\013\013\013\013\021\000\000\000\000\000\000O\012=\012=\012\013\013=\012= Step #5: artifact_prefix='./'; Test unit written to ./oom-c755524760922451b21e583d1fc53e970371fa9c Step #5: Base64: YVwjc2NlbgAAAAAAAAAAAAAAAAAKAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAARiAAYVwjcm5ubm5ubj9ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubgAAAAAAAHN0e2VhbQAAAAAgXCMjaAsLCyjg6hQ4xm0tCj0KPQo9Cj0LCwsLCwsRAAAAAAAATwo9Cj0KCws9Cj0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4748 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4112521703 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556005626810, 0x55600581001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556005810020,0x5560076a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c755524760922451b21e583d1fc53e970371fa9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5961 processed earlier; will process 5068 files now Step #5: ==171004== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555ffc11b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556002780898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5560027635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5560027634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ffc121d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ffc082b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ffc07d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ffc113c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555fff0e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555fff0e2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555fff0e2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555fff0e2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555fff0e2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555fff0e2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555fff0e2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555fff0e2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555fff0e2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555fff0e2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556001377f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ffe0a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ffe0afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ffde5bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ffde5bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ffde5c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ffde5b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ffde5b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ffde5b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556002765abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55600276e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556002756699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556002781112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc6783a3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ffc07bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7c,0x4f,0x3a,0x31,0x32,0x3a,0x22,0x44,0x61,0x54,0x65,0x49,0x6e,0x74,0x65,0x72,0x76,0x61,0x6c,0x22,0x3a,0x31,0x3a,0x7b,0x73,0x3a,0x31,0x31,0x3a,0x22,0x64,0x61,0x74,0x65,0x5f,0x73,0x74,0x72,0x69,0x6e,0x67,0x22,0x3b,0x73,0x3a,0x31,0x32,0x31,0x3a,0x22,0x0,0x22,0x3a,0x31,0x3a,0x7b,0x73,0x3a,0x31,0x31,0x3a,0x22,0x64,0x61,0x74,0x65,0x5f,0x73,0x74,0x72,0x69,0x6e,0x67,0x22,0x3b,0x73,0x3a,0x31,0x32,0x31,0x3a,0x22,0x0,0x2d,0x31,0x47,0x4d,0x54,0x36,0x36,0xe3,0x80,0xaf,0x61,0x30,0x6f,0x6e,0x44,0x28,0x53,0x35,0xf,0x53,0x65,0x63,0x4f,0x7,0x53,0x65,0x63,0x6f,0x2d,0x32,0x74,0x65,0x5f,0x73,0x74,0x72,0x69,0x6e,0x67,0x22,0x3b,0x73,0x3a,0x31,0x32,0x31,0x3a,0x22,0x0,0x2d,0x31,0x47,0x4d,0x54,0x36,0x36,0xe3,0x80,0xaf,0x61,0x30,0x6f,0x6e,0x44,0x28,0x53,0x35,0xf,0x53,0x65,0x63,0x4f,0x7,0x53,0x65,0x63,0x6f,0x2d,0x32,0x32,0xb9,0x37,0x62,0xc4,0xff,0x33,0xad,0x2d,0x22,0x3b, Step #5: |O:12:\"DaTeInterval\":1:{s:11:\"date_string\";s:121:\"\000\":1:{s:11:\"date_string\";s:121:\"\000-1GMT66\343\200\257a0onD(S5\017SecO\007Seco-2te_string\";s:121:\"\000-1GMT66\343\200\257a0onD(S5\017SecO\007Seco-22\2717b\304\3773\255-\"; Step #5: artifact_prefix='./'; Test unit written to ./oom-15f03b1504ef4c374ac279d0550258b2feacbc99 Step #5: Base64: fE86MTI6IkRhVGVJbnRlcnZhbCI6MTp7czoxMToiZGF0ZV9zdHJpbmciO3M6MTIxOiIAIjoxOntzOjExOiJkYXRlX3N0cmluZyI7czoxMjE6IgAtMUdNVDY244CvYTBvbkQoUzUPU2VjTwdTZWNvLTJ0ZV9zdHJpbmciO3M6MTIxOiIALTFHTVQ2NuOAr2Ewb25EKFM1D1NlY08HU2Vjby0yMrk3YsT/M60tIjs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4749 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4113044352 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e494230810, 0x55e49441a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e49441a020,0x55e4962b20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/15f03b1504ef4c374ac279d0550258b2feacbc99' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5962 processed earlier; will process 5067 files now Step #5: ==171040== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e48ad259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e49138a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e49136d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e49136d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e48ad2bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e48ac8cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e48ac87355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e48ad1dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e48dcecf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e48dcecf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e48dcecf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e48dcecf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e48dcecf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e48dcecf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e48dcecf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e48dcecf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e48dcecf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e48dcecf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e48ff81f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e48ccaeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e48ccb9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e48ca65c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e48ca65c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e48ca66738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e48ca65874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e48ca65874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e48ca65874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e49136fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e491378928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e491360699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e49138b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe318156082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e48ac85b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x24,0x24,0x24,0x20,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x4a,0x0,0x0,0x0,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x73,0x74,0x20,0x34,0x34,0x20,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x2c,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x74,0x20,0x34,0x34,0x20,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x2c,0x21,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x44,0x5b,0x7c,0x27,0x27,0x3d,0xa,0x81,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x44,0xa,0x7d,0xa,0x24,0x24,0x24,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0xa,0x3d,0xa,0x0,0x0,0x3d,0xa,0x3d,0x0,0x0,0x0,0xa,0xff,0xff,0xff,0xba,0xff,0xff,0xff,0xff,0xff, Step #5: ID$$$ $$$$$$$$$$$$$$$$$$J\000\000\000$$$$$$$st 44 $$$$$$$$$$$$$$$,$$$$$$$$$$t 44 $$$$$$$$$$$$$$$,!$$$$$$$$$$$$$$$$$$D[|''=\012\201\000=\012=\012=\012=\012=\012=\012=````````D\012}\012$$$\000\000\000\000\000\000\000=\012=\012\000\000=\012=\000\000\000\012\377\377\377\272\377\377\377\377\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-8c16d94eb3a0db86325391f5d122d721e6ae12d6 Step #5: Base64: SUQkJCQgJCQkJCQkJCQkJCQkJCQkJCQkSgAAACQkJCQkJCRzdCA0NCAkJCQkJCQkJCQkJCQkJCQsJCQkJCQkJCQkJHQgNDQgJCQkJCQkJCQkJCQkJCQkLCEkJCQkJCQkJCQkJCQkJCQkJCREW3wnJz0KgQA9Cj0KPQo9Cj0KPQo9YGBgYGBgYGBECn0KJCQkAAAAAAAAAD0KPQoAAD0KPQAAAAr///+6//////8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4750 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4113576911 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5651119f4810, 0x565111bde01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565111bde020,0x565113a760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c16d94eb3a0db86325391f5d122d721e6ae12d6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5963 processed earlier; will process 5066 files now Step #5: ==171076== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5651084e99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56510eb4e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56510eb315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56510eb314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5651084efd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565108450b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56510844b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5651084e1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56510b4b0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56510b4b0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56510b4b0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56510b4b0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56510b4b0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56510b4b0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56510b4b0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56510b4b0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56510b4b0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56510b4b0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56510d745f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56510a472b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56510a47dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56510a229c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56510a229c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56510a22a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56510a229874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56510a229874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56510a229874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56510eb33abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56510eb3c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56510eb24699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56510eb4f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f579da6b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565108449b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x44,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x48,0x48,0x48,0x48,0x48,0xa,0x3d,0xa,0x3d,0xa,0x80,0x0,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=---\012N\012=\012=\012D=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=?=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=?=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012HHHHH\012=\012=\012\200\000=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-2b98038fd14de731cca1a03865d371aa5c156fa7 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0tLS0KTgo9Cj0KRD0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPT89Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0/PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KSEhISEgKPQo9CoAAPQo9ChA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4751 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4114118931 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559871d2e810, 0x559871f1801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559871f18020,0x559873db00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2b98038fd14de731cca1a03865d371aa5c156fa7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5964 processed earlier; will process 5065 files now Step #5: ==171112== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5598688239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55986ee88898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55986ee6b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55986ee6b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559868829d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55986878ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559868785355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55986881bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55986b7eaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55986b7eaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55986b7eaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55986b7eaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55986b7eaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55986b7eaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55986b7eaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55986b7eaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55986b7eaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55986b7eaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55986da7ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55986a7acb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55986a7b7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55986a563c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55986a563c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55986a564738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55986a563874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55986a563874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55986a563874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55986ee6dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55986ee76928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55986ee5e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55986ee89112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f0d7ab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559868783b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x3d,0xf0,0x90,0x8f,0x8f,0xd,0xa,0xf0,0x90,0x8f,0x8f,0xa,0xf0,0x90,0x8f,0x8f,0xd,0xa,0xf0,0x90,0x8f,0x8f,0x22,0x3d,0x53,0xf0,0x90,0x8f,0x8f,0xd,0xa,0xf0,0x90,0x8f,0x8f,0xa,0xf0,0x90,0x8f,0x8f,0xf0,0x90,0x8f,0x8f,0xa,0xf0,0x90,0x8f,0x8f,0xd,0xf0,0x90,0x9f,0x8f,0xf0,0x90,0x8f,0x8f,0xa,0xf0,0x90,0x8f,0x8f,0x73,0x3d,0x53,0xf0,0x90,0x8f,0x8f,0xa,0xf0,0x90,0x8f,0x8f,0xa,0xf0,0x90,0x8f,0x8f,0xf0,0x90,0x8f,0x8f,0xa,0xf0,0x90,0x8f,0x8f,0xd,0xf0,0x90,0x8f,0x8f,0xd,0xa,0xf0,0x90,0x8f,0x8f,0xd,0xf0,0x90,0x8f,0x8f,0xa,0xf0,0x90,0x8f,0x8f,0x22,0x3e,0xf0,0x90,0x8f,0x8f,0xd,0xa,0xf0,0x90,0x8f,0x8f,0xf0,0x90,0x8f,0x8f,0xf0,0x90,0x8f,0x8f,0xd,0xa,0xf0,0x90,0x8f,0x8f,0x73,0x22,0xf0,0x90,0x8f,0x8f,0xd,0xa,0xf0,0x90,0x8f,0x8f,0xa,0xf0,0x90,0x8f,0x8f,0x22,0xf0,0x90,0x8f,0x8f,0xd,0xa,0xf0,0x90,0x8f,0x8f,0xd,0xa,0xf0,0x90,0x8f,0x8f,0x22,0x3e, Step #5: '=\360\220\217\217\015\012\360\220\217\217\012\360\220\217\217\015\012\360\220\217\217\"=S\360\220\217\217\015\012\360\220\217\217\012\360\220\217\217\360\220\217\217\012\360\220\217\217\015\360\220\237\217\360\220\217\217\012\360\220\217\217s=S\360\220\217\217\012\360\220\217\217\012\360\220\217\217\360\220\217\217\012\360\220\217\217\015\360\220\217\217\015\012\360\220\217\217\015\360\220\217\217\012\360\220\217\217\">\360\220\217\217\015\012\360\220\217\217\360\220\217\217\360\220\217\217\015\012\360\220\217\217s\"\360\220\217\217\015\012\360\220\217\217\012\360\220\217\217\"\360\220\217\217\015\012\360\220\217\217\015\012\360\220\217\217\"> Step #5: artifact_prefix='./'; Test unit written to ./oom-56d9a01dc11c6c0b173ee2cee1612dc31cf7b82a Step #5: Base64: Jz3wkI+PDQrwkI+PCvCQj48NCvCQj48iPVPwkI+PDQrwkI+PCvCQj4/wkI+PCvCQj48N8JCfj/CQj48K8JCPj3M9U/CQj48K8JCPjwrwkI+P8JCPjwrwkI+PDfCQj48NCvCQj48N8JCPjwrwkI+PIj7wkI+PDQrwkI+P8JCPj/CQj48NCvCQj49zIvCQj48NCvCQj48K8JCPjyLwkI+PDQrwkI+PDQrwkI+PIj4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4752 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4114630359 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ae0b652810, 0x55ae0b83c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ae0b83c020,0x55ae0d6d40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56d9a01dc11c6c0b173ee2cee1612dc31cf7b82a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5965 processed earlier; will process 5064 files now Step #5: ==171148== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ae021479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ae087ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ae0878f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ae0878f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ae0214dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ae020aeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ae020a9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ae0213fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ae0510ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ae0510ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ae0510ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ae0510ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ae0510ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ae0510ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ae0510ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ae0510ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ae0510ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ae0510ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ae073a3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ae040d0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ae040dbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ae03e87c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ae03e87c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ae03e88738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ae03e87874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ae03e87874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ae03e87874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ae08791abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ae0879a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ae08782699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ae087ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe2b946082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ae020a7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x42,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x34,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x4c,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: x-----BEGIN -----\012ddddddddddddBdddddddddddddddddddddddddddddddddddddddddddddddddddddddddd4dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddL\012-----END ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-f44be00eb76cf0281f0efb8408c4aa8be2a57f68 Step #5: Base64: eC0tLS0tQkVHSU4gLS0tLS0KZGRkZGRkZGRkZGRkQmRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGQ0ZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZEwKLS0tLS1FTkQgLS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4753 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4115150991 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec0d1ea810, 0x55ec0d3d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec0d3d4020,0x55ec0f26c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f44be00eb76cf0281f0efb8408c4aa8be2a57f68' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5966 processed earlier; will process 5063 files now Step #5: ==171184== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec03cdf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec0a344898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec0a3275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec0a3274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec03ce5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec03c46b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec03c41355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec03cd7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec06ca6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec06ca6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec06ca6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec06ca6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec06ca6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec06ca6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec06ca6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec06ca6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec06ca6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec06ca6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec08f3bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec05c68b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec05c73be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec05a1fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec05a1fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec05a20738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec05a1f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec05a1f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec05a1f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec0a329abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec0a332928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec0a31a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec0a345112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c6a0a3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec03c3fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xcd,0x84,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9c,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x85,0xcd,0x84,0x7e,0xd9,0x90,0xcd,0x85,0xcd,0x9d,0xcd,0x84,0xd9,0x9c,0xd9,0x90,0xcd,0x9d,0xcd,0x84, Step #5: \315\204\315\205\315\235\315\204\331\234\331\220\315\205\315\235\315\204\331\234\331\220\315\205\315\235\315\204\331\234\331\220\315\205\315\234\315\204\331\234\331\220\315\205\315\235\315\204\331\234\331\220\315\205\315\235\315\204\331\234\331\220\315\205\315\235\315\204\331\234\331\220\315\205\315\235\315\204\331\234\331\220\315\205\315\235\315\204\331\234\331\220\315\205\315\235\315\204\331\234\331\220\315\205\315\235\315\204\331\234\331\220\315\205\315\235\315\204\331\234\331\220\315\205\315\235\315\204\331\234\331\220\315\205\315\235\315\204\331\234\331\220\315\205\315\235\315\204\331\234\331\220\315\205\315\204~\331\220\315\205\315\235\315\204\331\234\331\220\315\235\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-3a3d3717b1dc00f015387b0aaa8302bb09dfd9ad Step #5: Base64: zYTNhc2dzYTZnNmQzYXNnc2E2ZzZkM2FzZ3NhNmc2ZDNhc2czYTZnNmQzYXNnc2E2ZzZkM2FzZ3NhNmc2ZDNhc2dzYTZnNmQzYXNnc2E2ZzZkM2FzZ3NhNmc2ZDNhc2dzYTZnNmQzYXNnc2E2ZzZkM2FzZ3NhNmc2ZDNhc2dzYTZnNmQzYXNnc2E2ZzZkM2FzZ3NhNmc2ZDNhc2EftmQzYXNnc2E2ZzZkM2dzYQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4754 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4115667350 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560714400810, 0x5607145ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5607145ea020,0x5607164820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a3d3717b1dc00f015387b0aaa8302bb09dfd9ad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5967 processed earlier; will process 5062 files now Step #5: #1 pulse cov: 3731 ft: 3732 exec/s: 0 rss: 174Mb Step #5: ==171220== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56070aef59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56071155a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56071153d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56071153d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56070aefbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56070ae5cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56070ae57355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56070aeedc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56070debcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56070debcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56070debcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56070debcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56070debcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56070debcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56070debcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56070debcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56070debcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56070debcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560710151f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56070ce7eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56070ce89be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56070cc35c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56070cc35c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56070cc36738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56070cc35874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56070cc35874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56070cc35874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56071153fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560711548928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560711530699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56071155b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e7fc83082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56070ae55b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0x5e,0x0,0x0,0x0,0xa,0xa,0x72,0x3d,0x73,0x65,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0x12,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x2d,0x2d,0x3f,0x2d,0x2d,0xa,0x2d,0x2d,0xa,0x3d,0x44,0x33,0x4,0xcc,0x96,0xb,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xff, Step #5: \005-----BEGIN =^\000\000\000\012\012r=se0000000000000000000000000000000000000000000000000000f=\012=+=\012=\012=\022= =\012= i\012\012r=sef=\012=+=\012=\012=\012=\012D\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000--?--\012--\012=D3\004\314\226\013skip_cl\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-5c7610b5bd3fab6aa1f9ca6f1e29e20fa1d5a91d Step #5: Base64: BS0tLS0tQkVHSU4gPV4AAAAKCnI9c2UwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwZj0KPSs9Cj0KPRI9ID0KPSBpCgpyPXNlZj0KPSs9Cj0KPQo9CkQKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KAC0tPy0tCi0tCj1EMwTMlgtza2lwX2NsCnwAEP8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4755 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4116238152 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4b6bb4810, 0x55e4b6d9e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4b6d9e020,0x55e4b8c360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c7610b5bd3fab6aa1f9ca6f1e29e20fa1d5a91d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5969 processed earlier; will process 5060 files now Step #5: ==171256== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e4ad6a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4b3d0e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4b3cf15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4b3cf14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4ad6afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4ad610b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4ad60b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4ad6a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4b0670f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4b0670f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4b0670f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4b0670f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4b0670f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4b0670f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4b0670f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4b0670f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4b0670f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4b0670f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4b2905f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4af632b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4af63dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4af3e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4af3e9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4af3ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4af3e9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4af3e9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4af3e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4b3cf3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4b3cfc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4b3ce4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4b3d0f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95cfcd1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4ad609b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x57,0x73,0x3a,0xdf,0x89,0x38,0x2e,0xdf,0xa9,0x32,0x2e,0xdf,0x89,0x38,0x2e,0xdf,0xa9,0x32,0x2e,0xdf,0xa9,0x38,0x2e,0xdf,0xa9,0x34,0x2e,0xdf,0xa9,0x32,0x2e,0xdf,0xa9,0x32,0x2e,0xdf,0x89,0x38,0x2e,0xdf,0xa9,0x32,0x2e,0xdb,0xa9,0x38,0x2e,0xdf,0xa9,0x38,0x2e,0xdf,0xa9,0x32,0x2e,0xdf,0x89,0x38,0x2e,0xdf,0xa9,0x38,0x2e,0xdf,0xa9,0x38,0x2e,0xdf,0xa9,0x39,0x2e,0xdf,0xa9,0x39,0x2e,0xdf,0xa9,0x30,0x2e,0xdf,0xa9,0x38,0x2e,0xdf,0xa9,0x38,0x2e,0xdf,0xa8,0x37,0x2e,0xdf,0x9b,0x38,0x2e,0xdf,0x89,0x30,0x2e,0xdf,0xa9,0x31,0x2e,0xdf,0x89,0x38,0x2e,0xdf,0xa9,0x38,0x2e,0xdf,0xa9,0x38,0x2e,0xdf,0xa9,0x32,0x2e,0xdf,0x89,0x38,0x2e,0xdf,0xa9,0x38,0x2e,0xdf,0xa1,0x38,0x2e,0xdf,0xa9,0x38,0x2e,0xdf,0xa9,0x32,0x2e,0xdf,0x89,0x38,0x2e,0xdf,0xa9,0x38,0x2e,0xdf,0xa9,0x38,0x2e,0xdf,0x89,0x38,0x2e,0xdf,0xa9,0x38,0x2e,0xdf,0xa9,0x2e,0xdf,0xa9,0x39,0x2e,0xd7,0xa9,0x38,0x2e,0xdf,0xa9,0x30, Step #5: Ws:\337\2118.\337\2512.\337\2118.\337\2512.\337\2518.\337\2514.\337\2512.\337\2512.\337\2118.\337\2512.\333\2518.\337\2518.\337\2512.\337\2118.\337\2518.\337\2518.\337\2519.\337\2519.\337\2510.\337\2518.\337\2518.\337\2507.\337\2338.\337\2110.\337\2511.\337\2118.\337\2518.\337\2518.\337\2512.\337\2118.\337\2518.\337\2418.\337\2518.\337\2512.\337\2118.\337\2518.\337\2518.\337\2118.\337\2518.\337\251.\337\2519.\327\2518.\337\2510 Step #5: artifact_prefix='./'; Test unit written to ./oom-166f2f66f7a6dd5c9ce10621106872d91804605a Step #5: Base64: V3M634k4Lt+pMi7fiTgu36kyLt+pOC7fqTQu36kyLt+pMi7fiTgu36kyLtupOC7fqTgu36kyLt+JOC7fqTgu36k4Lt+pOS7fqTku36kwLt+pOC7fqTgu36g3Lt+bOC7fiTAu36kxLt+JOC7fqTgu36k4Lt+pMi7fiTgu36k4Lt+hOC7fqTgu36kyLt+JOC7fqTgu36k4Lt+JOC7fqTgu36ku36k5LtepOC7fqTA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4756 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4116767149 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a9bdf0810, 0x555a9bfda01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a9bfda020,0x555a9de720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/166f2f66f7a6dd5c9ce10621106872d91804605a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5970 processed earlier; will process 5059 files now Step #5: ==171292== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555a928e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a98f4a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a98f2d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a98f2d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a928ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a9284cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a92847355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a928ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a958acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a958acf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a958acf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a958acf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a958acf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a958acf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a958acf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a958acf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a958acf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a958acf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a97b41f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a9486eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a94879be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a94625c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a94625c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a94626738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a94625874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a94625874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a94625874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a98f2fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a98f38928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a98f20699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a98f4b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f47f01f0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a92845b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x22,0x54,0x3e,0x2d,0x42,0x4b,0x3d,0x54,0x5c,0x22,0x3c,0x54,0x3e,0x5b,0x4b,0x3d,0x42,0x5c,0x42,0x4b,0x3d,0x54,0x5c,0x22,0x3c,0x54,0x3e,0x5b,0x42,0x4b,0x3d,0x5c,0x63,0x6d,0x6c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x22,0x54,0x3e,0x2d,0x42,0x4b,0x3d,0x54,0x5c,0x22,0x3c,0x54,0x3e,0x5b,0x4b,0x3d,0x70,0x3c,0x4b,0x3e,0x5b,0x42,0x5c,0x63,0x3d,0x54,0x79,0x6c,0x65,0x25,0x3e,0x54,0x3e,0x2d,0x3c,0x4b,0x3e,0x5b,0x42,0x5c,0x63,0x79,0x6c,0x42,0x4b,0x3d,0x54,0x5c,0x22,0x3c,0x54,0x3e,0x5b,0x4b,0x3d,0x42,0x5c,0x42,0x4b,0x3d,0x54,0x5c,0x22,0x3c,0x54,0x3e,0x5b,0x42,0x4b,0x3d,0x5c,0x63,0x6d,0x6c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x3c,0x4b,0x3e,0x3c,0x54,0x3e,0x5b,0x4b,0x3d,0x70,0x3c,0x4b,0x3e,0x5b,0x42,0x5c,0x63,0x3d,0x54,0x79,0x6c,0x65,0x25,0x3e,0x54,0x3e,0x2d,0x3c,0x4b,0x3e,0x65,0x3e,0x54,0x3e,0x5c,0x63,0x6d,0x6c,0x20,0x76, Step #5: <svg><style>\"T>-BK=T\\\"<T>[K=B\\BK=T\\\"<T>[BK=\\cmlstyle>\"T>-BK=T\\\"<T>[K=p<K>[B\\c=Tyle%>T>-<K>[B\\cylBK=T\\\"<T>[K=B\\BK=T\\\"<T>[BK=\\cmlstyle><K><T>[K=p<K>[B\\c=Tyle%>T>-<K>e>T>\\cml v Step #5: artifact_prefix='./'; Test unit written to ./oom-39aeaa47cfa7794d51d60a677d1226f6e3fa007c Step #5: Base64: PHN2Zz48c3R5bGU+IlQ+LUJLPVRcIjxUPltLPUJcQks9VFwiPFQ+W0JLPVxjbWxzdHlsZT4iVD4tQks9VFwiPFQ+W0s9cDxLPltCXGM9VHlsZSU+VD4tPEs+W0JcY3lsQks9VFwiPFQ+W0s9QlxCSz1UXCI8VD5bQks9XGNtbHN0eWxlPjxLPjxUPltLPXA8Sz5bQlxjPVR5bGUlPlQ+LTxLPmU+VD5cY21sIHY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4757 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4117292747 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5626cb539810, 0x5626cb72301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5626cb723020,0x5626cd5bb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/39aeaa47cfa7794d51d60a677d1226f6e3fa007c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5971 processed earlier; will process 5058 files now Step #5: ==171328== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5626c202e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5626c8693898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5626c86765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5626c86764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5626c2034d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5626c1f95b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5626c1f90355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5626c2026c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5626c4ff5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5626c4ff5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5626c4ff5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5626c4ff5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5626c4ff5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5626c4ff5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5626c4ff5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5626c4ff5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5626c4ff5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5626c4ff5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5626c728af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5626c3fb7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5626c3fc2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5626c3d6ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5626c3d6ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5626c3d6f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5626c3d6e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5626c3d6e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5626c3d6e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5626c8678abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5626c8681928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5626c8669699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5626c8694112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb4f7af1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5626c1f8eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x75,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x74,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x24,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x63,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x69,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x63,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x69,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x26,0x24,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x75,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f,0x2f,0x74,0x3c,0x2f,0x73,0x63,0x72,0x69,0x70,0x74,0x3e,0x2f, Step #5: +u</script>/</script>/</script>/t</script>/</script>/$</script>/c</script>/i</script>/c</script>/</script>/i</script>/</script>/&$</script>/</script>/u</script>//t</script>/ Step #5: artifact_prefix='./'; Test unit written to ./oom-e12d902157550cd506d6110bdbefde21c024effb Step #5: Base64: K3U8L3NjcmlwdD4vPC9zY3JpcHQ+Lzwvc2NyaXB0Pi90PC9zY3JpcHQ+Lzwvc2NyaXB0Pi8kPC9zY3JpcHQ+L2M8L3NjcmlwdD4vaTwvc2NyaXB0Pi9jPC9zY3JpcHQ+Lzwvc2NyaXB0Pi9pPC9zY3JpcHQ+Lzwvc2NyaXB0Pi8mJDwvc2NyaXB0Pi88L3NjcmlwdD4vdTwvc2NyaXB0Pi8vdDwvc2NyaXB0Pi8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4758 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4117831524 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ae5dc69810, 0x55ae5de5301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ae5de53020,0x55ae5fceb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e12d902157550cd506d6110bdbefde21c024effb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5972 processed earlier; will process 5057 files now Step #5: ==171364== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ae5475e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ae5adc3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ae5ada65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ae5ada64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ae54764d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ae546c5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ae546c0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ae54756c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ae57725f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ae57725f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ae57725f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ae57725f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ae57725f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ae57725f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ae57725f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ae57725f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ae57725f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ae57725f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ae599baf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ae566e7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ae566f2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ae5649ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ae5649ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ae5649f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ae5649e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ae5649e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ae5649e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ae5ada8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ae5adb1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ae5ad99699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ae5adc4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcbdb098082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ae546beb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x35,0x35,0x27,0x27,0x32,0x31,0x37,0x34,0x34,0x37,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x1d,0x32,0x2d,0x3d,0x27,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x3d,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $255''217447-=''''''/'\0352-=''\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000''''''''''='-=<''''''''''''-=<'''/''''/''\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000''''''''''''-=<''''''''''''-=<'''''''2-='''''''''''''.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-1f44d708af6b452f7b44ac2ba438e76f5887181a Step #5: Base64: JDI1NScnMjE3NDQ3LT0nJycnJycvJx0yLT0nJwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAnJycnJycnJycnPSctPTwnJycnJycnJycnJyctPTwnJycvJycnJy8nJwAAAAAAAAAAAAAAAAAAAAAAAAAnJycnJycnJycnJyctPTwnJycnJycnJycnJyctPTwnJycnJycnMi09JycnJycnJycnJycnJy4nJycnLickJy0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4759 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4118371352 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564bf4bd5810, 0x564bf4dbf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564bf4dbf020,0x564bf6c570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f44d708af6b452f7b44ac2ba438e76f5887181a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5973 processed earlier; will process 5056 files now Step #5: ==171400== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564beb6ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564bf1d2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564bf1d125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564bf1d124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564beb6d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564beb631b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564beb62c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564beb6c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564bee691f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564bee691f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564bee691f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564bee691f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564bee691f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564bee691f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564bee691f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564bee691f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564bee691f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564bee691f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564bf0926f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564bed653b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564bed65ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564bed40ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564bed40ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564bed40b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564bed40a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564bed40a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564bed40a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564bf1d14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564bf1d1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564bf1d05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564bf1d30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0dfcbc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564beb62ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x45,0x47,0x49,0x4e,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0xa,0x3d,0x44,0x31,0x4,0xcc,0x96,0xb,0x73,0x6b,0x44,0x33,0x2,0x2,0x13,0x0,0x0,0x0,0x5b,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0xa,0x3d,0x44,0x31,0x4,0xcc,0x96,0xb,0x73,0x6b,0x44,0x33,0x2,0x2,0x13,0x0,0x0,0x0,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xff, Step #5: \005-----B\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000EGIN =\012= i\012\012r=s\000----\012--\012=D1\004\314\226\013skD3\002\002\023\000\000\000[---\012--\012=D1\004\314\226\013skD3\002\002\023\000\000\000[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[ip_cl\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-70a9683fda296e0089e2dd1a8288f0914f95acda Step #5: Base64: BS0tLS0tQgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEVHSU4gPQo9IGkKCnI9cwAtLS0tCi0tCj1EMQTMlgtza0QzAgITAAAAWy0tLQotLQo9RDEEzJYLc2tEMwICEwAAAFtbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tpcF9jbAp8ABD/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4760 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4118893664 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e05e0de810, 0x55e05e2c801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e05e2c8020,0x55e0601600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70a9683fda296e0089e2dd1a8288f0914f95acda' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5974 processed earlier; will process 5055 files now Step #5: #1 pulse cov: 14511 ft: 14512 exec/s: 0 rss: 198Mb Step #5: #2 pulse cov: 15281 ft: 17788 exec/s: 0 rss: 203Mb Step #5: #4 pulse cov: 16161 ft: 19774 exec/s: 0 rss: 205Mb Step #5: ==171436== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e054bd39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e05b238898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e05b21b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e05b21b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e054bd9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e054b3ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e054b35355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e054bcbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e057b9af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e057b9af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e057b9af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e057b9af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e057b9af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e057b9af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e057b9af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e057b9af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e057b9af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e057b9af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e059e2ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e056b5cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e056b67be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e056913c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e056913c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e056914738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e056913874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e056913874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e056913874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e05b21dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e05b226928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e05b20e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e05b239112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2959ceb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e054b33b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x54,0x20,0x21,0xf2,0x96,0xaa,0xa9,0xf0,0x96,0xa8,0xb1,0xf0,0x97,0x97,0xa9,0xf3,0x90,0x81,0xa0,0xf0,0x96,0xa8,0xa9,0xf0,0x97,0x97,0xa9,0xf3,0xb0,0x81,0xa0,0xf0,0x96,0xaa,0xa9,0xf3,0x96,0xa9,0xa9,0xf0,0xa9,0xb7,0xa9,0xf3,0x97,0x97,0xa9,0xf3,0xb0,0x81,0xa0,0xf0,0x96,0xaa,0xa9,0xf3,0x96,0xa9,0xa9,0xf0,0xa9,0xb7,0xa9,0xf3,0xa0,0x81,0x90,0xf0,0x95,0xa9,0xaa,0xf0,0x97,0xa9,0xa9,0xf0,0x96,0xa9,0xa9,0xf3,0x96,0xa9,0xa9,0xf0,0xa9,0x97,0xa9,0xf3,0xa0,0x81,0x90,0xf0,0x95,0xa9,0xaa,0xf0,0x97,0xaa,0xa9,0xf0,0x96,0xa9,0xa9,0xf0,0x94,0xa8,0xb1,0xf0,0x97,0x97,0xa9,0xf3,0x90,0x81,0xa0,0xf0,0x96,0xaa,0xa9,0xf0,0xa8,0x97,0xa9,0xf3,0xa0,0x81,0xaa,0xf0,0x97,0xa9,0xa8,0xf0,0x96,0xaa,0xa3,0xf0,0x96,0x97,0xa9,0xf0,0x97,0xa9,0xa9,0xf0,0x96,0xa9,0xa9,0xf0,0xa9,0x97,0xa9,0xf3,0xa8,0x81,0xaa,0xf0,0x97,0xa9,0xa9,0xf0,0x96,0xa8,0xa9,0xf0,0x96,0xaa,0xa9,0xf3,0x96,0x90,0xa9,0xeb,0xa9,0x4f, Step #5: T !\362\226\252\251\360\226\250\261\360\227\227\251\363\220\201\240\360\226\250\251\360\227\227\251\363\260\201\240\360\226\252\251\363\226\251\251\360\251\267\251\363\227\227\251\363\260\201\240\360\226\252\251\363\226\251\251\360\251\267\251\363\240\201\220\360\225\251\252\360\227\251\251\360\226\251\251\363\226\251\251\360\251\227\251\363\240\201\220\360\225\251\252\360\227\252\251\360\226\251\251\360\224\250\261\360\227\227\251\363\220\201\240\360\226\252\251\360\250\227\251\363\240\201\252\360\227\251\250\360\226\252\243\360\226\227\251\360\227\251\251\360\226\251\251\360\251\227\251\363\250\201\252\360\227\251\251\360\226\250\251\360\226\252\251\363\226\220\251\353\251O Step #5: artifact_prefix='./'; Test unit written to ./oom-b70752f1b2d9c7c0ef542fe5165780a34bee575b Step #5: Base64: VCAh8paqqfCWqLHwl5ep85CBoPCWqKnwl5ep87CBoPCWqqnzlqmp8Km3qfOXl6nzsIGg8JaqqfOWqanwqbep86CBkPCVqarwl6mp8JapqfOWqanwqZep86CBkPCVqarwl6qp8JapqfCUqLHwl5ep85CBoPCWqqnwqJep86CBqvCXqajwlqqj8JaXqfCXqanwlqmp8KmXqfOogarwl6mp8JaoqfCWqqnzlpCp66lP Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4761 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4119672157 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f885538810, 0x55f88572201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f885722020,0x55f8875ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b70752f1b2d9c7c0ef542fe5165780a34bee575b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5979 processed earlier; will process 5050 files now Step #5: #1 pulse cov: 4288 ft: 4289 exec/s: 0 rss: 177Mb Step #5: ==171472== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f87c02d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f882692898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8826755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8826754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f87c033d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f87bf94b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f87bf8f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f87c025c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f87eff4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f87eff4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f87eff4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f87eff4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f87eff4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f87eff4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f87eff4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f87eff4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f87eff4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f87eff4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f881289f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f87dfb6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f87dfc1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f87dd6dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f87dd6dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f87dd6e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f87dd6d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f87dd6d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f87dd6d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f882677abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f882680928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f882668699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f882693112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b703a8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f87bf8db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x6f,0x63,0x69,0x56,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x31,0x2e,0x30,0x2e,0x30,0x22,0x2c,0x22,0x6c,0x69,0x6e,0x75,0x78,0x22,0x3a,0x7b,0x22,0x6d,0x61,0x73,0x6b,0x65,0x64,0x50,0x61,0x74,0x68,0x73,0x22,0x3a,0x5b,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x2f,0x22,0x2c,0x22,0x22,0x5d,0x7d,0x7d, Step #5: {\"ociVersion\":\"1.0.0\",\"linux\":{\"maskedPaths\":[\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"/\",\"\"]}} Step #5: artifact_prefix='./'; Test unit written to ./oom-2a5f8356995c32cbccc3c2b4562bd5a6b10bf916 Step #5: Base64: eyJvY2lWZXJzaW9uIjoiMS4wLjAiLCJsaW51eCI6eyJtYXNrZWRQYXRocyI6WyIvIiwiLyIsIi8iLCIvIiwiLyIsIi8iLCIvIiwiLyIsIi8iLCIvIiwiLyIsIi8iLCIvIiwiLyIsIi8iLCIvIiwiLyIsIi8iLCIvIiwiLyIsIi8iLCIvIiwiLyIsIi8iLCIvIiwiLyIsIi8iLCIvIiwiLyIsIi8iLCIvIiwiIl19fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4762 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4120250586 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555f17224810, 0x555f1740e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555f1740e020,0x555f192a60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2a5f8356995c32cbccc3c2b4562bd5a6b10bf916' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5981 processed earlier; will process 5048 files now Step #5: ==171508== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555f0dd199c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555f1437e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555f143615dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555f143614fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555f0dd1fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555f0dc80b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555f0dc7b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555f0dd11c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555f10ce0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555f10ce0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555f10ce0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555f10ce0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555f10ce0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555f10ce0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555f10ce0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555f10ce0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555f10ce0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555f10ce0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555f12f75f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555f0fca2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555f0fcadbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555f0fa59c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555f0fa59c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555f0fa5a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555f0fa59874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555f0fa59874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555f0fa59874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555f14363abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555f1436c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555f14354699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555f1437f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95dc51b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555f0dc79b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x0,0x6b,0x0,0x60,0x2b,0x2b,0x4a,0x9,0x29,0x4a,0x9,0x29,0xa,0x5c,0x9,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x1,0x0,0x1d,0x9,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x73,0x74,0x72,0x79,0x20,0x28,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x20,0x2a,0x2a,0x2a,0x2a,0x60,0xf3,0xa0,0x80,0xa1,0x29, Step #5: \012\000k\000`++J\011)J\011)\012\\\011)\012\\\011`@`@)\012\001\000\035\011***********************************stry (********************\000\000*********************************************************************** ****`\363\240\200\241) Step #5: artifact_prefix='./'; Test unit written to ./oom-22830139d8210d8eccd93af27279aa8e4f4bfee0 Step #5: Base64: CgBrAGArK0oJKUoJKQpcCSkKXAlgQGBAKQoBAB0JKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKipzdHJ5ICgqKioqKioqKioqKioqKioqKioqKgAAKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKiogKioqKmDzoIChKQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4763 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4120895115 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a3bfa8810, 0x555a3c19201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a3c192020,0x555a3e02a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/22830139d8210d8eccd93af27279aa8e4f4bfee0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5982 processed earlier; will process 5047 files now Step #5: ==171544== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555a32a9d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a39102898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a390e55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a390e54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a32aa3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a32a04b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a329ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a32a95c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a35a64f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a35a64f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a35a64f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a35a64f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a35a64f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a35a64f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a35a64f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a35a64f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a35a64f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a35a64f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a37cf9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a34a26b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a34a31be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a347ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a347ddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a347de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a347dd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a347dd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a347dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a390e7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a390f0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a390d8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a39103112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f60d48a3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a329fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x3d,0x7b,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x7b,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x2e,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x31,0x32,0x38,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x24,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x7b,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x24,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21,0x2c,0x21, Step #5: !={!,!,!,!,!,!,!,!,!,{!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,.,!,!,!,!128,!,!,!,!,!,!,!,$,!,!,!,!,!,!,!,!,!,{!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,!,$,!,!,!,!,!,!,! Step #5: artifact_prefix='./'; Test unit written to ./oom-80f42ee520cdedd3c8d4bf87f60993ab8b2aa8aa Step #5: Base64: IT17ISwhLCEsISwhLCEsISwhLCEseyEsISwhLCEsISwhLCEsISwhLCEsISwhLCEsISwhLCEsISwuLCEsISwhLCExMjgsISwhLCEsISwhLCEsISwkLCEsISwhLCEsISwhLCEsISwhLHshLCEsISwhLCEsISwhLCEsISwhLCEsISwhLCEsISwhLCEsISwhLCEsISwhLCEsISwhLCEsISwhLCQsISwhLCEsISwhLCEsIQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4764 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4121422313 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8aacd9810, 0x55c8aaec301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c8aaec3020,0x55c8acd5b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/80f42ee520cdedd3c8d4bf87f60993ab8b2aa8aa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5983 processed earlier; will process 5046 files now Step #5: #1 pulse cov: 14422 ft: 14423 exec/s: 0 rss: 196Mb Step #5: ==171580== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c8a17ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8a7e33898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8a7e165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8a7e164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c8a17d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c8a1735b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c8a1730355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c8a17c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c8a4795f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c8a4795f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c8a4795f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c8a4795f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c8a4795f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c8a4795f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c8a4795f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c8a4795f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c8a4795f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c8a4795f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c8a6a2af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c8a3757b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c8a3762be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c8a350ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c8a350ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c8a350f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c8a350e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c8a350e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c8a350e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8a7e18abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8a7e21928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8a7e09699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8a7e34112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9b00c5a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c8a172eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0x20,0x0,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa8,0x8e,0x3d,0x20,0x7f,0x7f,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x12,0x0,0x0,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x49,0x44,0x33,0x3,0x14,0x1,0x2f,0x0,0x0,0x67,0x54,0x49,0x54,0x49,0x44,0x45,0x42,0xb9,0xbc,0x3d,0x6b,0x0,0x2b,0x50,0x63,0x2d,0x31,0x0,0x0,0xd,0xe,0xe,0x69,0x2d,0x20,0x2d,0x7,0x20,0x2d,0x3a,0x20,0x75,0x3a,0x2f,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x20,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x6e,0x61,0x6d,0x65,0x80,0x8d,0x0,0x0,0x28,0xe2,0xe2,0x3a,0x80, Step #5: \341\240\216= \177\177 \000(\342\200\254\000\341\250\216= \177\177\342\200\215\000\000(\342\200\256\000r+\342\200\215\000\022\000\000\000\000(\342\200\256\000r+\342\200\215\000\000(\342\200\256\000r+\342\200\215\000\000(\342\200\256\000r+\342\200\215\000\000(\342\200\256\000r+\342\200\215\000ID3\003\024\001/\000\000gTITIDEB\271\274=k\000+Pc-1\000\000\015\016\016i- -\007 -: u:/\000(\342\200\256\000r+\342\200\215 \000\000(\342\200\256\000r+\342\200\215\000\000(\342\200\256name\200\215\000\000(\342\342:\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-b046fa0109c4788a7bcd545c98de5fd7f5cb3d97 Step #5: Base64: 4aCOPSB/fyAAKOKArADhqI49IH9/4oCNAAAo4oCuAHIr4oCNABIAAAAAKOKArgByK+KAjQAAKOKArgByK+KAjQAAKOKArgByK+KAjQAAKOKArgByK+KAjQBJRDMDFAEvAABnVElUSURFQrm8PWsAK1BjLTEAAA0ODmktIC0HIC06IHU6LwAo4oCuAHIr4oCNIAAAKOKArgByK+KAjQAAKOKArm5hbWWAjQAAKOLiOoA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4765 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4122018781 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e8c4ab810, 0x559e8c69501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e8c695020,0x559e8e52d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b046fa0109c4788a7bcd545c98de5fd7f5cb3d97' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5985 processed earlier; will process 5044 files now Step #5: #1 pulse cov: 3853 ft: 3854 exec/s: 0 rss: 174Mb Step #5: ==171616== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559e82fa09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e89605898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e895e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e895e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e82fa6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e82f07b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e82f02355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e82f98c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e85f67f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e85f67f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e85f67f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e85f67f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e85f67f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e85f67f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e85f67f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e85f67f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e85f67f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e85f67f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e881fcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e84f29b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e84f34be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e84ce0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e84ce0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e84ce1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e84ce0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e84ce0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e84ce0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e895eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e895f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e895db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e89606112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f26038e7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e82f00b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0x20,0x0,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa8,0x8e,0x3d,0x20,0x7f,0x7f,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x12,0x0,0x0,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x49,0x44,0x33,0x3,0x14,0x1,0x2f,0x0,0x0,0x67,0x54,0x49,0x54,0x49,0x44,0x45,0x42,0x4c,0x43,0x3d,0x6b,0x0,0x2b,0x50,0x63,0x2d,0x31,0x0,0x0,0xd,0xe,0xe,0x69,0x2d,0x20,0x2d,0x7,0x20,0x2d,0x3a,0x20,0x75,0x3a,0x2f,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x20,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x49,0x44,0x33,0x3,0x3a,0x80, Step #5: \341\240\216= \177\177 \000(\342\200\254\000\341\250\216= \177\177\342\200\215\000\000(\342\200\256\000r+\342\200\215\000\022\000\000\000\000(\342\200\256\000r+\342\200\215\000\000(\342\200\256\000r+\342\200\215\000\000(\342\200\256\000r+\342\200\215\000\000(\342\200\256\000r+\342\200\215\000ID3\003\024\001/\000\000gTITIDEBLC=k\000+Pc-1\000\000\015\016\016i- -\007 -: u:/\000(\342\200\256\000r+\342\200\215 \000\000(\342\200\256\000r+\342\200\215\000\000(\342\200\256\000r+\342\200\215\000ID3\003:\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-7b960a57441a9db81d2261eef91369bdd0247abd Step #5: Base64: 4aCOPSB/fyAAKOKArADhqI49IH9/4oCNAAAo4oCuAHIr4oCNABIAAAAAKOKArgByK+KAjQAAKOKArgByK+KAjQAAKOKArgByK+KAjQAAKOKArgByK+KAjQBJRDMDFAEvAABnVElUSURFQkxDPWsAK1BjLTEAAA0ODmktIC0HIC06IHU6LwAo4oCuAHIr4oCNIAAAKOKArgByK+KAjQAAKOKArgByK+KAjQBJRDMDOoA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4766 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4122584938 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b9ca30b810, 0x55b9ca4f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b9ca4f5020,0x55b9cc38d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7b960a57441a9db81d2261eef91369bdd0247abd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5987 processed earlier; will process 5042 files now Step #5: #1 pulse cov: 4005 ft: 4006 exec/s: 0 rss: 177Mb Step #5: ==171652== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b9c0e009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b9c7465898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b9c74485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b9c74484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b9c0e06d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b9c0d67b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b9c0d62355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b9c0df8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b9c3dc7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b9c3dc7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b9c3dc7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b9c3dc7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b9c3dc7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b9c3dc7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b9c3dc7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b9c3dc7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b9c3dc7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b9c3dc7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b9c605cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b9c2d89b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b9c2d94be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b9c2b40c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b9c2b40c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b9c2b41738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b9c2b40874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b9c2b40874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b9c2b40874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b9c744aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b9c7453928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b9c743b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b9c7466112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdbb2810082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b9c0d60b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xe,0x6a,0xc,0xa,0xa,0xe1,0xbf,0x8a,0xe1,0xbf,0x8a,0xa,0xe1,0xbf,0xa4,0xa,0xe,0x6a,0xc,0xa,0xa,0xe1,0xbf,0x8a,0xe1,0xbf,0x8a,0xe1,0xa4,0xbf,0xa,0xa,0xe,0x6a,0xc,0xa,0xa,0xe1,0xbf,0x8a,0xe1,0xbf,0x8a,0xa,0xe1,0xbf,0xa4,0xa,0xe,0x6a,0xc,0xa,0xa,0xe1,0xbf,0x8a,0xe1,0xbf,0x8a,0xe1,0xa4,0xbb,0xa,0xa,0xe,0x6a,0xc,0xa,0xa,0xe1,0xbf,0x8a,0xe1,0xbf,0x8a,0xa,0xe1,0xbf,0xa4,0xa,0xe,0x6a,0xc,0xa,0xa,0xe1,0xbf,0x8a,0xe1,0xbf,0x8a,0xa,0xe1,0xbf,0xa4,0xa,0xe,0x6a,0xc,0xa,0xa,0xe1,0xbf,0x8a,0xe1,0xbf,0x8a,0xe1,0xa4,0xbf,0xa,0xa,0xe,0x6a,0xc,0xa,0xa,0xe1,0xbf,0x8a,0xe1,0xbf,0x8a,0xe1,0xa4,0xbf,0xa,0xa,0xe,0x6a,0xc,0xa,0xa,0xe1,0xbf,0x8a,0xe1,0xbf,0x8a,0xe1,0xa4,0xbf,0xa,0xa,0xe,0x6a,0xc,0xa,0xa,0xe1,0xbf,0x8a,0xe1,0xbf,0x8a,0xa,0xe1,0xbf,0xa4,0xa,0xe,0x6a,0xc,0xa,0xa,0xe1,0xbf,0x8a,0xe1,0xbf,0x8a,0xe1,0xbf,0xa4,0xa, Step #5: \012\016j\014\012\012\341\277\212\341\277\212\012\341\277\244\012\016j\014\012\012\341\277\212\341\277\212\341\244\277\012\012\016j\014\012\012\341\277\212\341\277\212\012\341\277\244\012\016j\014\012\012\341\277\212\341\277\212\341\244\273\012\012\016j\014\012\012\341\277\212\341\277\212\012\341\277\244\012\016j\014\012\012\341\277\212\341\277\212\012\341\277\244\012\016j\014\012\012\341\277\212\341\277\212\341\244\277\012\012\016j\014\012\012\341\277\212\341\277\212\341\244\277\012\012\016j\014\012\012\341\277\212\341\277\212\341\244\277\012\012\016j\014\012\012\341\277\212\341\277\212\012\341\277\244\012\016j\014\012\012\341\277\212\341\277\212\341\277\244\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-aae463bf68a19f79c19a4d3975c8d3333922a1a9 Step #5: Base64: Cg5qDAoK4b+K4b+KCuG/pAoOagwKCuG/iuG/iuGkvwoKDmoMCgrhv4rhv4oK4b+kCg5qDAoK4b+K4b+K4aS7CgoOagwKCuG/iuG/igrhv6QKDmoMCgrhv4rhv4oK4b+kCg5qDAoK4b+K4b+K4aS/CgoOagwKCuG/iuG/iuGkvwoKDmoMCgrhv4rhv4rhpL8KCg5qDAoK4b+K4b+KCuG/pAoOagwKCuG/iuG/iuG/pAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4767 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4123148662 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f3a9eb6810, 0x55f3aa0a001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f3aa0a0020,0x55f3abf380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aae463bf68a19f79c19a4d3975c8d3333922a1a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5989 processed earlier; will process 5040 files now Step #5: #1 pulse cov: 3994 ft: 3995 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4152 ft: 4606 exec/s: 0 rss: 179Mb Step #5: ==171688== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f3a09ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f3a7010898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f3a6ff35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f3a6ff34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f3a09b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f3a0912b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f3a090d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f3a09a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f3a3972f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f3a3972f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f3a3972f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f3a3972f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f3a3972f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f3a3972f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f3a3972f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f3a3972f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f3a3972f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f3a3972f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f3a5c07f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f3a2934b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f3a293fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f3a26ebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f3a26ebc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f3a26ec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f3a26eb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f3a26eb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f3a26eb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f3a6ff5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f3a6ffe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f3a6fe6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f3a7011112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f953ad94082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f3a090bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x30,0x2d,0x3d,0x2f,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x33,0x32,0x37,0x36,0x37,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x31,0x2d,0x27,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x32,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x33,0x32,0x37,0x36,0x37,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x31,0x2d,0x27,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x31,0x2d,0x3d,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $0-=/'''/''''/''32767-=''''''/''1-'='''''''''''''-2=<''''''''''''-=<'''/''''/'''/''''/''32767-=''''''/''1-'='''''''''''''-=<''''''''''''-=<'''''''''1-='\000\000\000\000\000\000\000\001''''.''''''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-13ad07316d41dd26fda965068ec61d5878fdca4f Step #5: Base64: JDAtPS8nJycvJycnJy8nJzMyNzY3LT0nJycnJycvJycxLSc9JycnJycnJycnJycnJy0yPTwnJycnJycnJycnJyctPTwnJycvJycnJy8nJycvJycnJy8nJzMyNzY3LT0nJycnJycvJycxLSc9JycnJycnJycnJycnJy09PCcnJycnJycnJycnJy09PCcnJycnJycnJzEtPScAAAAAAAAAAScnJycuJycnJycnJycuJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4768 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4123789664 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed3ae33810, 0x55ed3b01d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed3b01d020,0x55ed3ceb50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/13ad07316d41dd26fda965068ec61d5878fdca4f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5993 processed earlier; will process 5036 files now Step #5: #1 pulse cov: 3892 ft: 3893 exec/s: 0 rss: 177Mb Step #5: ==171724== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed319289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed37f8d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed37f705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed37f704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed3192ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed3188fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed3188a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed31920c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed348eff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed348eff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed348eff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed348eff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed348eff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed348eff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed348eff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed348eff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed348eff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed348eff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed36b84f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed338b1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed338bcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed33668c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed33668c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed33669738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed33668874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed33668874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed33668874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed37f72abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed37f7b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed37f63699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed37f8e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0800159082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed31888b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x3d,0x7e,0x2d,0x3d,0x3d,0x25,0x3,0xd2,0x84,0x28,0xcb,0xb5,0x1,0x79,0x0,0x79,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x29,0x24,0xcb,0xbc,0xbc,0xbc,0xbc,0xb5, Step #5: ~$=~-==%\003\322\204(\313\265\001y\000y\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000)$\313\274\274\274\274\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-9c7f18b5dba3d9f3c3516c22a0a3b68402cfb272 Step #5: Base64: fiQ9fi09PSUD0oQoy7UBeQB5AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAApJMu8vLy8tQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4769 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4124360499 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e22572d810, 0x55e22591701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e225917020,0x55e2277af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c7f18b5dba3d9f3c3516c22a0a3b68402cfb272' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5995 processed earlier; will process 5034 files now Step #5: ==171760== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e21c2229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e222887898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e22286a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e22286a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e21c228d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e21c189b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e21c184355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e21c21ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e21f1e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e21f1e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e21f1e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e21f1e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e21f1e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e21f1e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e21f1e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e21f1e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e21f1e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e21f1e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e22147ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e21e1abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e21e1b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e21df62c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e21df62c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e21df63738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e21df62874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e21df62874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e21df62874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e22286cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e222875928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e22285d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e222888112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc2af00e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e21c182b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x30,0xd,0xa,0x2a,0x33,0xd,0xa,0x24,0x2d,0x35,0xd,0xa,0x2a,0x31,0x32,0x37,0xd,0xa,0x2a,0x30,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x31,0xd,0xa,0x24,0x2d,0x31,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x32,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x37,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x37,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa,0x24,0x2d,0x36,0xd,0xa, Step #5: *0\015\012*3\015\012$-5\015\012*127\015\012*0\015\012$-6\015\012$-6\015\012$-1\015\012$-1\015\012$-6\015\012$-6\015\012$-6\015\012$-6\015\012$-2\015\012$-6\015\012$-6\015\012$-6\015\012$-6\015\012$-6\015\012$-6\015\012$-7\015\012$-6\015\012$-6\015\012$-6\015\012$-6\015\012$-6\015\012$-6\015\012$-6\015\012$-6\015\012$-7\015\012$-6\015\012$-6\015\012$-6\015\012$-6\015\012$-6\015\012$-6\015\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-2200cb060e21467bce7c52b4e2a8ce983ee309c7 Step #5: Base64: KjANCiozDQokLTUNCioxMjcNCiowDQokLTYNCiQtNg0KJC0xDQokLTENCiQtNg0KJC02DQokLTYNCiQtNg0KJC0yDQokLTYNCiQtNg0KJC02DQokLTYNCiQtNg0KJC02DQokLTcNCiQtNg0KJC02DQokLTYNCiQtNg0KJC02DQokLTYNCiQtNg0KJC02DQokLTcNCiQtNg0KJC02DQokLTYNCiQtNg0KJC02DQokLTYNCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4770 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4124887520 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ccca5ea810, 0x55ccca7d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ccca7d4020,0x55cccc66c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2200cb060e21467bce7c52b4e2a8ce983ee309c7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5996 processed earlier; will process 5033 files now Step #5: #1 pulse cov: 3741 ft: 3742 exec/s: 0 rss: 174Mb Step #5: ==171796== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ccc10df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ccc7744898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ccc77275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ccc77274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ccc10e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ccc1046b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ccc1041355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ccc10d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ccc40a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ccc40a6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ccc40a6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ccc40a6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ccc40a6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ccc40a6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ccc40a6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ccc40a6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ccc40a6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ccc40a6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ccc633bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ccc3068b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ccc3073be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ccc2e1fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ccc2e1fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ccc2e20738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ccc2e1f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ccc2e1f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ccc2e1f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ccc7729abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ccc7732928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ccc771a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ccc7745112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0828af0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ccc103fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0xa,0xcd,0x8f,0x2e,0xa,0xcd,0x8f,0xcd,0x8f,0x2e,0xa,0xcd,0x8b,0x2e,0xa,0x26,0x8f,0x2e,0xa,0x2f,0xa,0xcd,0x8f,0x2e,0xa,0x8b,0x2e,0xa,0xce,0x8f,0x2e,0xa,0xcd,0xcd,0x8f,0x2e,0xa,0x41,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0x93,0xcc,0xb1,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0x8f,0x2e,0xa,0xcd,0x8f,0x2e,0xa,0xcd,0x2e,0xa,0xc3,0xbc,0x2e,0x63,0x6f,0x6d,0xa,0x8f,0x2e,0xa,0xcd,0x8f,0x2e,0xa,0xcd,0x8b,0x2e,0xa,0x8f,0x2e,0xa,0x85,0x8e,0x2e,0xa,0xcd,0xb1,0x2f,0x3d,0xa,0x2e,0xb1,0xa,0x2e,0xcc,0x95,0xa,0x2e,0xcc,0xa,0x2e,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0xb1,0x2f,0x3d,0xa,0x2e,0xb1,0xa,0x2e,0xcc,0x95,0xa,0xcc,0x2e,0xa,0x6f,0xcc,0xb1,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0x8f,0x2e,0xa,0xcd,0x8f,0x2e,0xa,0xcd,0x2e,0xa,0xc3,0xbc,0x2e,0x63,0x6f,0x6d,0xa,0x8f,0x2e,0xa,0xcd,0x8f,0x2e,0xa,0xcd,0x8b,0x2e,0xa,0x8f,0x2e,0xa,0x85,0x8e,0x2e,0xa,0xcd,0x2e, Step #5: .\012\315\217.\012\315\217\315\217.\012\315\213.\012&\217.\012/\012\315\217.\012\213.\012\316\217.\012\315\315\217.\012A.\314\261\012.\314\223\314\261\012.\314\261\012.\217.\012\315\217.\012\315.\012\303\274.com\012\217.\012\315\217.\012\315\213.\012\217.\012\205\216.\012\315\261/=\012.\261\012.\314\225\012.\314\012..\314\261\012.\314\261\012.\314\261/=\012.\261\012.\314\225\012\314.\012o\314\261\012.\314\261\012.\314\261\012.\217.\012\315\217.\012\315.\012\303\274.com\012\217.\012\315\217.\012\315\213.\012\217.\012\205\216.\012\315. Step #5: artifact_prefix='./'; Test unit written to ./oom-941a1182b1ef752e4578761406e276a5f419bd9b Step #5: Base64: LgrNjy4KzY/Njy4KzYsuCiaPLgovCs2PLgqLLgrOjy4Kzc2PLgpBLsyxCi7Mk8yxCi7MsQoujy4KzY8uCs0uCsO8LmNvbQqPLgrNjy4KzYsuCo8uCoWOLgrNsS89Ci6xCi7MlQouzAouLsyxCi7MsQouzLEvPQousQouzJUKzC4Kb8yxCi7MsQouzLEKLo8uCs2PLgrNLgrDvC5jb20Kjy4KzY8uCs2LLgqPLgqFji4KzS4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4771 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4125443913 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f9c5cf6810, 0x55f9c5ee001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f9c5ee0020,0x55f9c7d780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/941a1182b1ef752e4578761406e276a5f419bd9b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 5998 processed earlier; will process 5031 files now Step #5: #1 pulse cov: 3941 ft: 3942 exec/s: 0 rss: 176Mb Step #5: ==171832== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f9bc7eb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f9c2e50898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f9c2e335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f9c2e334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f9bc7f1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f9bc752b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f9bc74d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f9bc7e3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f9bf7b2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f9bf7b2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f9bf7b2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f9bf7b2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f9bf7b2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f9bf7b2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f9bf7b2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f9bf7b2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f9bf7b2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f9bf7b2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f9c1a47f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f9be774b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f9be77fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f9be52bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f9be52bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f9be52c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f9be52b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f9be52b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f9be52b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f9c2e35abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f9c2e3e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f9c2e26699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f9c2e51112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a6a53e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f9bc74bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x50,0x44,0x46,0x2d,0x31,0x2e,0x37,0xa,0xa,0x74,0x72,0x61,0x69,0x6c,0x65,0x72,0xa,0x3c,0x3c,0xa,0x2f,0x52,0x6f,0x6f,0x74,0x20,0x31,0x20,0x30,0x20,0x52,0xa,0x3e,0x3e,0xa,0xa,0x31,0x20,0x30,0x20,0x6f,0x62,0x6a,0xa,0x3c,0x3c,0xa,0x2f,0x54,0x79,0x70,0x65,0x20,0x2d,0x43,0x61,0x74,0x61,0x6c,0x6f,0x67,0xa,0x2f,0x50,0x61,0x67,0x65,0x73,0x20,0x31,0x20,0x30,0x20,0x52,0xa,0x66,0x66,0x65,0x72,0x65,0x6e,0x6f,0x67,0xa,0x2f,0x5b,0x32,0x34,0x20,0x2f,0x74,0x73,0x69,0x73,0x2e,0x73,0x63,0x2f,0x41,0x2f,0x43,0x6f,0x6c,0x75,0x6d,0x6e,0x73,0x72,0x69,0x6e,0x67,0x2f,0x42,0x2f,0x43,0x2f,0x44,0x2f,0xe2,0xe3,0xcf,0xd3,0xa,0x32,0x31,0x20,0x30,0x20,0x6f,0x62,0x6a,0xa,0x3c,0x3c,0xa,0x2f,0x4c,0x65,0x6e,0x67,0x54,0x68,0x20,0x2f,0x33,0x34,0x38,0xa,0x46,0x69,0x6c,0x74,0x65,0x72,0xaf,0x46,0x6c,0x61,0x74,0x65,0x44,0x65,0x63,0x6f,0x64,0x65,0xe,0x3e,0x3e,0xa,0x73,0x74,0x72,0x65,0x61,0x6d,0xa,0x78, Step #5: %PDF-1.7\012\012trailer\012<<\012/Root 1 0 R\012>>\012\0121 0 obj\012<<\012/Type -Catalog\012/Pages 1 0 R\012fferenog\012/[24 /tsis.sc/A/Columnsring/B/C/D/\342\343\317\323\01221 0 obj\012<<\012/LengTh /348\012Filter\257FlateDecode\016>>\012stream\012x Step #5: artifact_prefix='./'; Test unit written to ./oom-0b9a0de0fc04ff2461d2c34f5734d383ccf48504 Step #5: Base64: JVBERi0xLjcKCnRyYWlsZXIKPDwKL1Jvb3QgMSAwIFIKPj4KCjEgMCBvYmoKPDwKL1R5cGUgLUNhdGFsb2cKL1BhZ2VzIDEgMCBSCmZmZXJlbm9nCi9bMjQgL3RzaXMuc2MvQS9Db2x1bW5zcmluZy9CL0MvRC/i48/TCjIxIDAgb2JqCjw8Ci9MZW5nVGggLzM0OApGaWx0ZXKvRmxhdGVEZWNvZGUOPj4Kc3RyZWFtCng= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4772 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4126006386 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f6f469c810, 0x55f6f488601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f6f4886020,0x55f6f671e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b9a0de0fc04ff2461d2c34f5734d383ccf48504' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6000 processed earlier; will process 5029 files now Step #5: #1 pulse cov: 3563 ft: 3564 exec/s: 0 rss: 174Mb Step #5: ==171868== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f6eb1919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f6f17f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f6f17d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f6f17d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f6eb197d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f6eb0f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f6eb0f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f6eb189c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f6ee158f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f6ee158f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f6ee158f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f6ee158f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f6ee158f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f6ee158f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f6ee158f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f6ee158f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f6ee158f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f6ee158f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f6f03edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f6ed11ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f6ed125be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f6eced1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f6eced1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f6eced2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f6eced1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f6eced1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f6eced1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f6f17dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f6f17e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f6f17cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f6f17f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3f5e0d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f6eb0f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x1,0x14,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x29,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\001\024=\012=\012=\012=\012=\012=\012=)=\012=\012==\012\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-6dcb8d3020330cb6dd5a5dee4ea9892cbdb427f5 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9CgEUPQo9Cj0KPQo9Cj0KPSk9Cj0KPT0KChA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4773 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4126580428 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a72d91f810, 0x55a72db0901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a72db09020,0x55a72f9a10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6dcb8d3020330cb6dd5a5dee4ea9892cbdb427f5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6002 processed earlier; will process 5027 files now Step #5: ==171904== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a7244149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a72aa79898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a72aa5c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a72aa5c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a72441ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a72437bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a724376355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a72440cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a7273dbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a7273dbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a7273dbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a7273dbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a7273dbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a7273dbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a7273dbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a7273dbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a7273dbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a7273dbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a729670f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a72639db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a7263a8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a726154c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a726154c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a726155738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a726154874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a726154874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a726154874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a72aa5eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a72aa67928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a72aa4f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a72aa7a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efe069b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a724374b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x2b,0x42,0xdb,0xbe,0x7c,0xdb,0xbe,0x2b,0x2b,0x2b,0x2b,0x2b,0x41,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x24,0x6e,0x24,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x45,0x4e,0x2b,0x42,0xdb,0xbe,0x7c,0xdb,0xbe,0x2b,0x2b,0x2b,0x21,0x2b,0x33,0x32,0x37,0x35,0x37,0x24,0x24,0x24,0x3b,0x58,0x24,0x24,0x24,0x7e,0x24,0x24,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0xb4,0xdf,0x2d,0x2d,0x2d,0x2d,0x2d,0xa, Step #5: -----END ------END -----END -----\012-----EN+B\333\276|\333\276+++++A+++++++$n$D -----\012EN+B\333\276|\333\276+++!+32757$$$;X$$$~$$D -----\012-----END -----\012-----END ----------END -----END ------\012-----EN\264\337-----\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-501869cc90a2d5ed616169fb372e18a7e40a8ef5 Step #5: Base64: LS0tLS1FTkQgLS0tLS0tRU5EIC0tLS0tRU5EIC0tLS0tCi0tLS0tRU4rQtu+fNu+KysrKytBKysrKysrKyRuJEQgLS0tLS0KRU4rQtu+fNu+KysrISszMjc1NyQkJDtYJCQkfiQkRCAtLS0tLQotLS0tLUVORCAtLS0tLQotLS0tLUVORCAtLS0tLS0tLS0tRU5EIC0tLS0tRU5EIC0tLS0tLQotLS0tLUVOtN8tLS0tLQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4774 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4127107741 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c77bd3c810, 0x55c77bf2601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c77bf26020,0x55c77ddbe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/501869cc90a2d5ed616169fb372e18a7e40a8ef5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6003 processed earlier; will process 5026 files now Step #5: #1 pulse cov: 4081 ft: 4082 exec/s: 0 rss: 177Mb Step #5: ==171940== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c7728319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c778e96898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c778e795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c778e794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c772837d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c772798b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c772793355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c772829c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7757f8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7757f8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7757f8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7757f8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7757f8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7757f8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7757f8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7757f8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7757f8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7757f8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c777a8df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7747bab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7747c5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c774571c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c774571c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c774572738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c774571874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c774571874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c774571874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c778e7babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c778e84928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c778e6c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c778e97112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ec842b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c772791b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x6e,0x61,0x6d,0x65,0x22,0x3a,0x22,0xf0,0x92,0x85,0x81,0xf0,0x91,0x91,0x93,0xf0,0x92,0x91,0x95,0xf0,0x91,0x92,0x81,0x21,0xf0,0x91,0x91,0x93,0xf0,0x92,0x91,0x95,0xf0,0x91,0x92,0x81,0xf0,0x91,0x91,0x93,0xf0,0x92,0x91,0x95,0xf0,0x91,0x92,0x81,0xf0,0x9f,0x91,0x97,0xf0,0x9f,0x91,0x91,0xf0,0x97,0x8f,0x9b,0xf0,0x93,0x90,0x81,0xf0,0x91,0xb1,0x91,0xf0,0x91,0x91,0x93,0xf0,0x92,0x91,0x95,0xf0,0x91,0x92,0x81,0xf0,0x9f,0x91,0x97,0xf0,0x9f,0x91,0x91,0xf0,0x97,0x8f,0x9b,0xf0,0x91,0x91,0x93,0xf0,0x92,0x91,0x95,0xf0,0x91,0x8d,0xa1,0xf0,0x9f,0x91,0x97,0xf0,0x9f,0x91,0x91,0xf0,0x97,0x8f,0x9b,0xf0,0x93,0x80,0x82,0xf0,0x91,0xb4,0x8a,0xf0,0x91,0x91,0x93,0xf0,0x92,0x91,0x95,0xf0,0x91,0x92,0x81,0xf0,0x9f,0x91,0x97,0xf0,0x9f,0x91,0x91,0xf0,0x97,0x8f,0x9b,0xf0,0x93,0x90,0x81,0xf0,0x91,0xb0,0x91,0x22,0x2c,0x22,0x61,0x73,0x73,0x66,0x74,0x5f,0x74,0x6f,0x72,0x73,0x97,0x3a,0x5b,0x22,0x30,0x22,0x5d,0x7d, Step #5: {\"name\":\"\360\222\205\201\360\221\221\223\360\222\221\225\360\221\222\201!\360\221\221\223\360\222\221\225\360\221\222\201\360\221\221\223\360\222\221\225\360\221\222\201\360\237\221\227\360\237\221\221\360\227\217\233\360\223\220\201\360\221\261\221\360\221\221\223\360\222\221\225\360\221\222\201\360\237\221\227\360\237\221\221\360\227\217\233\360\221\221\223\360\222\221\225\360\221\215\241\360\237\221\227\360\237\221\221\360\227\217\233\360\223\200\202\360\221\264\212\360\221\221\223\360\222\221\225\360\221\222\201\360\237\221\227\360\237\221\221\360\227\217\233\360\223\220\201\360\221\260\221\",\"assft_tors\227:[\"0\"]} Step #5: artifact_prefix='./'; Test unit written to ./oom-8d2e28fef007ec5900c7845a94ffedae74f19e05 Step #5: Base64: eyJuYW1lIjoi8JKFgfCRkZPwkpGV8JGSgSHwkZGT8JKRlfCRkoHwkZGT8JKRlfCRkoHwn5GX8J+RkfCXj5vwk5CB8JGxkfCRkZPwkpGV8JGSgfCfkZfwn5GR8JePm/CRkZPwkpGV8JGNofCfkZfwn5GR8JePm/CTgILwkbSK8JGRk/CSkZXwkZKB8J+Rl/CfkZHwl4+b8JOQgfCRsJEiLCJhc3NmdF90b3JzlzpbIjAiXX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4775 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4127666415 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5633b41ab810, 0x5633b439501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5633b4395020,0x5633b622d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d2e28fef007ec5900c7845a94ffedae74f19e05' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6005 processed earlier; will process 5024 files now Step #5: ==171976== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5633aaca09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5633b1305898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5633b12e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5633b12e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5633aaca6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5633aac07b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5633aac02355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5633aac98c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5633adc67f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5633adc67f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5633adc67f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5633adc67f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5633adc67f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5633adc67f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5633adc67f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5633adc67f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5633adc67f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5633adc67f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5633afefcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5633acc29b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5633acc34be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5633ac9e0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5633ac9e0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5633ac9e1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5633ac9e0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5633ac9e0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5633ac9e0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5633b12eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5633b12f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5633b12db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5633b1306112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f37150e2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5633aac00b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0xcc,0xb1,0xa,0xce,0x95,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0x96,0xa,0x2e,0x14,0xcc,0xb3,0xa,0x6e,0xcc,0x94,0xa,0x2e,0xcc,0xb2,0xa,0xcc,0xb1,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0x94,0xa,0x2e,0x7a,0xcc,0xb3,0xa,0x6e,0xcc,0x94,0xa,0x2e,0xcc,0xb2,0xa,0xcc,0xb1,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0x94,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0x8a,0xa,0x2e,0xcc,0x8a,0xa,0x2e,0xcc,0xb2,0xa,0x2e,0xcc,0x96,0xa,0x7a,0xcc,0xb3,0xa,0x6e,0xcc,0x94,0xa,0x2e,0xcc,0xb2,0xa,0xcc,0xb1,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0x94,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0x8a,0xa,0x2e,0xcc,0x96,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0xb3,0xa,0x6e,0xcc,0x94,0xa,0x2e,0xcc,0xb2,0xa,0xcc,0xb1,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0x94,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0xb3,0xa,0x6e,0xcc,0x94,0xa,0x2e,0xcc,0xb2,0xa,0xcc,0xb1,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0x94,0xa,0x2e,0xcc,0xb1,0xa,0x2e,0xcc,0xb1, Step #5: -\314\261\012\316\225\012.\314\261\012.\314\226\012.\024\314\263\012n\314\224\012.\314\262\012\314\261\012.\314\261\012.\314\224\012.z\314\263\012n\314\224\012.\314\262\012\314\261\012.\314\261\012.\314\224\012.\314\261\012.\314\212\012.\314\212\012.\314\262\012.\314\226\012z\314\263\012n\314\224\012.\314\262\012\314\261\012.\314\261\012.\314\224\012.\314\261\012.\314\212\012.\314\226\012.\314\261\012.\314\263\012n\314\224\012.\314\262\012\314\261\012.\314\261\012.\314\224\012.\314\261\012.\314\263\012n\314\224\012.\314\262\012\314\261\012.\314\261\012.\314\224\012.\314\261\012.\314\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-dbcf7793a46271501706ae0dffcf49ac2e53846a Step #5: Base64: LcyxCs6VCi7MsQouzJYKLhTMswpuzJQKLsyyCsyxCi7MsQouzJQKLnrMswpuzJQKLsyyCsyxCi7MsQouzJQKLsyxCi7MigouzIoKLsyyCi7Mlgp6zLMKbsyUCi7MsgrMsQouzLEKLsyUCi7MsQouzIoKLsyWCi7MsQouzLMKbsyUCi7MsgrMsQouzLEKLsyUCi7MsQouzLMKbsyUCi7MsgrMsQouzLEKLsyUCi7MsQouzLE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4776 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4128192571 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563972ea8810, 0x56397309201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563973092020,0x563974f2a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dbcf7793a46271501706ae0dffcf49ac2e53846a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6006 processed earlier; will process 5023 files now Step #5: ==172012== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56396999d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563970002898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56396ffe55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56396ffe54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5639699a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563969904b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5639698ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563969995c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56396c964f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56396c964f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56396c964f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56396c964f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56396c964f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56396c964f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56396c964f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56396c964f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56396c964f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56396c964f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56396ebf9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56396b926b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56396b931be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56396b6ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56396b6ddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56396b6de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56396b6dd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56396b6dd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56396b6dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56396ffe7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56396fff0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56396ffd8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563970003112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff53314e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5639698fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0xd7,0xa9,0x1,0x0,0x6,0x54,0x0,0x0,0x0,0x1,0x0,0x48,0x0,0x55,0x55,0x45,0x2d,0x2d,0x2d,0x42,0x2d,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2e,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2e,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0xa,0x2d,0x20,0x47,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2e,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0xa,0x2d,0x20,0x47,0x0,0x5c,0x6b,0x86,0x50,0x52,0x49,0x0,0x49,0x2d,0x2d,0x86,0x0,0x2,0x32,0x32,0x12,0x3d,0x3c,0x27,0x27,0x2,0x0,0x32, Step #5: \000\000\327\251\001\000\006T\000\000\000\001\000H\000UUE---B-N -----------.----------------------.---------------------------------------\012\012- G------.---------------------------------------\012\012- G\000\\k\206PRI\000I--\206\000\00222\022=<''\002\0002 Step #5: artifact_prefix='./'; Test unit written to ./oom-06f3e93828c8ff2e0746747bdc83485696f23255 Step #5: Base64: AADXqQEABlQAAAABAEgAVVVFLS0tQi1OIC0tLS0tLS0tLS0tLi0tLS0tLS0tLS0tLS0tLS0tLS0tLS0uLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tCgotIEctLS0tLS0uLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tCgotIEcAXGuGUFJJAEktLYYAAjIyEj08JycCADI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4777 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4128715092 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562335509810, 0x5623356f301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5623356f3020,0x56233758b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/06f3e93828c8ff2e0746747bdc83485696f23255' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6007 processed earlier; will process 5022 files now Step #5: ==172048== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56232bffe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562332663898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5623326465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5623326464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56232c004d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56232bf65b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56232bf60355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56232bff6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56232efc5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56232efc5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56232efc5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56232efc5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56232efc5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56232efc5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56232efc5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56232efc5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56232efc5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56232efc5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56233125af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56232df87b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56232df92be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56232dd3ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56232dd3ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56232dd3f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56232dd3e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56232dd3e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56232dd3e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562332648abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562332651928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562332639699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562332664112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9801f36082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56232bf5eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x38,0x30,0x4d,0x46,0x77,0x48,0x65,0x57,0x53,0x63,0x6f,0x41,0x61,0x71,0x59,0x32,0x2b,0x6a,0x6d,0x47,0x4c,0x6c,0x43,0x54,0x73,0x41,0x42,0x41,0x2b,0x4c,0x77,0x6a,0x7a,0x53,0x49,0x58,0x56,0x53,0x77,0x6f,0x31,0x54,0x2f,0xa,0x61,0x20,0x3a,0x30,0x2e,0x31,0x2e,0x39,0x31,0x34,0x2e,0x31,0x2f,0xa,0x61,0x20,0x3a,0x30,0x2e,0x31,0x2e,0x39,0x30,0x33,0x2e,0x30,0x2f,0xa,0x61,0x20,0x3a,0x30,0x2e,0x34,0x2e,0x39,0x31,0x34,0x2e,0x30,0x2f,0xa,0x61,0x20,0x3a,0x30,0x2e,0x34,0x2e,0x39,0x31,0x35,0x2e,0x31,0x2f,0xa,0x61,0x20,0x3a,0x31,0x2e,0x34,0x2e,0x39,0x31,0x33,0x2e,0x30,0x2f,0xa,0x61,0x20,0x3a,0x30,0x2e,0x30,0x2e,0x39,0x31,0x33,0x2e,0x33,0x2f,0xa,0x61,0x20,0x3a,0x31,0x2e,0x31,0x2e,0x39,0x31,0x34,0x2e,0x33,0x2f,0xa,0x61,0x20,0x3a,0x30,0x2e,0x35,0x2e,0x38,0x32,0x34,0x2e,0x30,0x2f, Step #5: onion-key\012ntor-onion-key 80MFwHeWScoAaqY2+jmGLlCTsABA+LwjzSIXVSwo1T/\012a :0.1.914.1/\012a :0.1.903.0/\012a :0.4.914.0/\012a :0.4.915.1/\012a :1.4.913.0/\012a :0.0.913.3/\012a :1.1.914.3/\012a :0.5.824.0/ Step #5: artifact_prefix='./'; Test unit written to ./oom-d03fede6930f7d39fc38285174b6bce5a83484cc Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IDgwTUZ3SGVXU2NvQWFxWTIram1HTGxDVHNBQkErTHdqelNJWFZTd28xVC8KYSA6MC4xLjkxNC4xLwphIDowLjEuOTAzLjAvCmEgOjAuNC45MTQuMC8KYSA6MC40LjkxNS4xLwphIDoxLjQuOTEzLjAvCmEgOjAuMC45MTMuMy8KYSA6MS4xLjkxNC4zLwphIDowLjUuODI0LjAv Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4778 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4129238606 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c35c88a810, 0x55c35ca7401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c35ca74020,0x55c35e90c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d03fede6930f7d39fc38285174b6bce5a83484cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6008 processed earlier; will process 5021 files now Step #5: ==172084== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c35337f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c3599e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c3599c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c3599c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c353385d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c3532e6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c3532e1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c353377c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c356346f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c356346f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c356346f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c356346f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c356346f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c356346f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c356346f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c356346f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c356346f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c356346f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c3585dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c355308b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c355313be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c3550bfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c3550bfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c3550c0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c3550bf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c3550bf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c3550bf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c3599c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c3599d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c3599ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c3599e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f942011a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c3532dfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x3c,0xdb,0xbe,0xdb,0xbe,0x7e,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x60,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x60,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x9d,0x25,0x25,0x25,0x25,0x25,0x31,0x73, Step #5: ~<\333\276\333\276~sssssssssss%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%`%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%`%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%\001\000\000\000\000\000\000\235%%%%%1s Step #5: artifact_prefix='./'; Test unit written to ./oom-5c1c5a228f342c887fc2257d19920f1756cc1aeb Step #5: Base64: fjzbvtu+fnNzc3Nzc3Nzc3NzJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJWAlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlYCUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlAQAAAAAAAJ0lJSUlJTFz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4779 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4129887014 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5592ba87e810, 0x5592baa6801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5592baa68020,0x5592bc9000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c1c5a228f342c887fc2257d19920f1756cc1aeb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6009 processed earlier; will process 5020 files now Step #5: ==172120== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5592b13739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5592b79d8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5592b79bb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5592b79bb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592b1379d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592b12dab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592b12d5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592b136bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592b433af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592b433af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592b433af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592b433af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592b433af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592b433af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592b433af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592b433af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592b433af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592b433af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592b65cff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592b32fcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592b3307be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5592b30b3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5592b30b3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5592b30b4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5592b30b3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5592b30b3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5592b30b3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5592b79bdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5592b79c6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5592b79ae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5592b79d9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95a380c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592b12d3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x24,0x24,0x24,0x24,0x24,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x24,0x24,0x24,0x24,0x24,0x24,0x26,0x24,0x24,0x22,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x2d,0x2d,0x2d,0x64,0x0,0x42,0x45,0x47,0x4b,0x4e,0x20,0x73,0x74,0x72,0x65,0x22,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x72,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x3f,0x0,0x0,0x0,0x0,0x0,0x2e,0x36, Step #5: s$$$$$\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012$$$$$$&$$\"$$$r$$$---d\000BEGKN stre\"$$$r$$$$$$$r$$$$$$$?\000\000\000\000\000.6 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ad89722f586045b031d0da13f8603bc9a3a120f Step #5: Base64: cyQkJCQkCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KJCQkJCQkJiQkIiQkJHIkJCQtLS1kAEJFR0tOIHN0cmUiJCQkciQkJCQkJCRyJCQkJCQkJD8AAAAAAC42 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4780 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4130415829 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56001d4db810, 0x56001d6c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56001d6c5020,0x56001f55d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ad89722f586045b031d0da13f8603bc9a3a120f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6010 processed earlier; will process 5019 files now Step #5: ==172156== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560013fd09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56001a635898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56001a6185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56001a6184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560013fd6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560013f37b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560013f32355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560013fc8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560016f97f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560016f97f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560016f97f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560016f97f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560016f97f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560016f97f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560016f97f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560016f97f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560016f97f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560016f97f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56001922cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560015f59b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560015f64be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560015d10c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560015d10c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560015d11738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560015d10874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560015d10874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560015d10874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56001a61aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56001a623928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56001a60b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56001a636112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1349b9c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560013f30b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x21,0x24,0x26,0x26,0x28,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x24,0x26,0x26,0x28,0x28,0x24,0x26,0x26,0x28,0x28,0x24,0x26,0x26,0x28,0x24,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29, Step #5: !($&&($&&($&&($&&($&&($&&($&&($&&($&&(!$&&(($&&($&&($&&($&&($&&($&&($&&($&&($&&(($&&($&&($&&($&&($&&($&&($&&($&&(($&&($&&($&&($&&(($&&(($&&($))))))))))))))))))))))))))))))))))))))) Step #5: artifact_prefix='./'; Test unit written to ./oom-0cf3739a5a98eb5a028bc6fd972377ef20301ef8 Step #5: Base64: ISgkJiYoJCYmKCQmJigkJiYoJCYmKCQmJigkJiYoJCYmKCQmJighJCYmKCgkJiYoJCYmKCQmJigkJiYoJCYmKCQmJigkJiYoJCYmKCQmJigoJCYmKCQmJigkJiYoJCYmKCQmJigkJiYoJCYmKCQmJigoJCYmKCQmJigkJiYoJCYmKCgkJiYoKCQmJigkKSkpKSkpKSkpKSkpKSkpKSkpKSkpKSkpKSkpKSkpKSkpKSkpKSkp Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4781 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4130946748 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b38113810, 0x560b382fd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b382fd020,0x560b3a1950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0cf3739a5a98eb5a028bc6fd972377ef20301ef8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6011 processed earlier; will process 5018 files now Step #5: ==172192== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560b2ec089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b3526d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b352505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b352504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b2ec0ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b2eb6fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b2eb6a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b2ec00c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b31bcff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b31bcff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b31bcff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b31bcff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b31bcff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b31bcff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b31bcff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b31bcff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b31bcff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b31bcff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b33e64f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b30b91b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b30b9cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b30948c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b30948c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b30949738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b30948874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b30948874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b30948874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b35252abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b3525b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b35243699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b3526e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda2a42c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b2eb68b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0xd9,0x95,0xd9,0x8b,0xd9,0x98,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x37,0x3b,0x3b,0x3b,0x3b,0x3b,0x21,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x20,0xd9,0x90,0xd9,0x95,0xd9,0x8b,0xd9,0x98,0x20,0xd9,0x90,0x27,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e,0x27,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg><text>\331\225\331\213\331\230;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;340282366920938463463374607431768211457;;;;;!;;;;;;;;;;;;; \331\220\331\225\331\213\331\230 \331\220'</text></svg>'ext></svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-462fd4826725a7fb6769e47a4e279feb425d83e2 Step #5: Base64: PHN2Zz48dGV4dD7ZldmL2Zg7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OzM0MDI4MjM2NjkyMDkzODQ2MzQ2MzM3NDYwNzQzMTc2ODIxMTQ1Nzs7Ozs7ITs7Ozs7Ozs7Ozs7Ozsg2ZDZldmL2Zgg2ZAnPC90ZXh0Pjwvc3ZnPidleHQ+PC9zdmc+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4782 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4131463210 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a8511f810, 0x559a8530901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a85309020,0x559a871a10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/462fd4826725a7fb6769e47a4e279feb425d83e2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6012 processed earlier; will process 5017 files now Step #5: #1 pulse cov: 3776 ft: 3777 exec/s: 0 rss: 177Mb Step #5: ==172228== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559a7bc149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a82279898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a8225c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a8225c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a7bc1ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a7bb7bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a7bb76355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a7bc0cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a7ebdbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a7ebdbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a7ebdbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a7ebdbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a7ebdbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a7ebdbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a7ebdbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a7ebdbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a7ebdbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a7ebdbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a80e70f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a7db9db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a7dba8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a7d954c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a7d954c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a7d955738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a7d954874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a7d954874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a7d954874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a8225eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a82267928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a8224f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a8227a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f834fdec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a7bb74b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xa,0x64,0x3a,0x20,0x2e,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x35,0x35,0x35,0x33,0x33,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x36,0x32, Step #5: FUZZTESTv1\012d: .0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000555337460743176821162 Step #5: artifact_prefix='./'; Test unit written to ./oom-5808789189934d1699b65c6d4c172574dff1b4d2 Step #5: Base64: RlVaWlRFU1R2MQpkOiAuMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDU1NTMzNzQ2MDc0MzE3NjgyMTE2Mg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4783 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4132021125 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56536d88b810, 0x56536da7501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56536da75020,0x56536f90d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5808789189934d1699b65c6d4c172574dff1b4d2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6014 processed earlier; will process 5015 files now Step #5: #1 pulse cov: 3752 ft: 3753 exec/s: 0 rss: 177Mb Step #5: ==172264== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5653643809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56536a9e5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56536a9c85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56536a9c84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565364386d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5653642e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5653642e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565364378c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565367347f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565367347f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565367347f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565367347f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565367347f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565367347f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565367347f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565367347f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565367347f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565367347f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5653695dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565366309b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565366314be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5653660c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5653660c0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5653660c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5653660c0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5653660c0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5653660c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56536a9caabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56536a9d3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56536a9bb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56536a9e6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f20b40082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5653642e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x4,0xfd,0xff,0x0,0x0,0x7c,0x40,0x0,0x1, Step #5: \000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000ID3\004\375\377\000\000|@\000\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-e2f08738411260aad9a2cb2fe60d314008442da3 Step #5: Base64: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABJRDME/f8AAHxAAAE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4784 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4132590120 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5632768e2810, 0x563276acc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563276acc020,0x5632789640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e2f08738411260aad9a2cb2fe60d314008442da3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6016 processed earlier; will process 5013 files now Step #5: ==172300== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56326d3d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563273a3c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563273a1f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563273a1f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56326d3ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56326d33eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56326d339355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56326d3cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56327039ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56327039ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56327039ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56327039ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56327039ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56327039ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56327039ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56327039ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56327039ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56327039ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563272633f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56326f360b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56326f36bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56326f117c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56326f117c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56326f118738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56326f117874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56326f117874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56326f117874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563273a21abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563273a2a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563273a12699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563273a3d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f51d1d9c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56326d337b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x6c,0x69,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e,0x3c,0x64,0x61,0x74,0x61,0x6c,0x69,0x73,0x74,0x3e, Step #5: <datalist><datalist><datalist><datalist><datalist><datalist><datalist><datalist><datalist><datalist><datalist><datalist><datalist><datalist><datalist><datalislit><datalist><datalist> Step #5: artifact_prefix='./'; Test unit written to ./oom-1e868712731255b884b68ac3e972dde0f25225f3 Step #5: Base64: PGRhdGFsaXN0PjxkYXRhbGlzdD48ZGF0YWxpc3Q+PGRhdGFsaXN0PjxkYXRhbGlzdD48ZGF0YWxpc3Q+PGRhdGFsaXN0PjxkYXRhbGlzdD48ZGF0YWxpc3Q+PGRhdGFsaXN0PjxkYXRhbGlzdD48ZGF0YWxpc3Q+PGRhdGFsaXN0PjxkYXRhbGlzdD48ZGF0YWxpc3Q+PGRhdGFsaXNsaXQ+PGRhdGFsaXN0PjxkYXRhbGlzdD4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4785 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4133091133 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5645611f2810, 0x5645613dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5645613dc020,0x5645632740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e868712731255b884b68ac3e972dde0f25225f3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6017 processed earlier; will process 5012 files now Step #5: #1 pulse cov: 3929 ft: 3930 exec/s: 0 rss: 175Mb Step #5: ==172336== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564557ce79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56455e34c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56455e32f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56455e32f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564557cedd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564557c4eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564557c49355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564557cdfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56455acaef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56455acaef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56455acaef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56455acaef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56455acaef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56455acaef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56455acaef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56455acaef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56455acaef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56455acaef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56455cf43f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564559c70b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564559c7bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564559a27c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564559a27c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564559a28738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564559a27874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564559a27874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564559a27874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56455e331abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56455e33a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56455e322699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56455e34d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f860f284082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564557c47b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0x13,0x0,0x0,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x21,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012==\012=\012=\023\000\000\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=!\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-2dd6df99af06ab379e345cd38fd9a10efcd388fc Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9PQo9Cj0TAAAACj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPSEKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9ChA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4786 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4133674222 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652022c7810, 0x5652024b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652024b1020,0x5652043490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2dd6df99af06ab379e345cd38fd9a10efcd388fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6019 processed earlier; will process 5010 files now Step #5: #1 pulse cov: 3721 ft: 3722 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 3955 ft: 4306 exec/s: 0 rss: 178Mb Step #5: #4 pulse cov: 4865 ft: 6191 exec/s: 0 rss: 180Mb Step #5: ==172372== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5651f8dbc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5651ff421898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651ff4045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651ff4044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5651f8dc2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5651f8d23b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5651f8d1e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5651f8db4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5651fbd83f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5651fbd83f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5651fbd83f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5651fbd83f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5651fbd83f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5651fbd83f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5651fbd83f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5651fbd83f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5651fbd83f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5651fbd83f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5651fe018f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5651fad45b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5651fad50be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5651faafcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5651faafcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5651faafd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5651faafc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5651faafc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5651faafc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5651ff406abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5651ff40f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5651ff3f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5651ff422112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8cc596e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5651f8d1cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x57,0x73,0x3a,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x45,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0xa4,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x30,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xc5,0xa4,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x30,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xc5,0xb4,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x34,0xcd,0x94,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xc5,0xa4,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: Ws:\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204E\315\204\315\204\315\204\315\204\315\204\315\204\315\244\315\204\315\204\315\204\315\2040\315\224\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\305\244\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\2040\315\224\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\305\264\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\2044\315\224\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\305\244\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-1d76b2b89179f87c89daa739e0a06f4d6c8833ef Step #5: Base64: V3M6zYTNhM2EzYTNhM2EzYTNhM2EzYTNhEXNhM2EzYTNhM2EzYTNpM2EzYTNhM2EMM2UzYTNhM2EzYTNhM2EzYTNhM2EzYTFpM2EzYTNhM2EzYTNhM2EzYTNhM2EMM2UzYTNhM2EzYTNhM2EzYTNhM2EzYTFtM2EzYTNhM2EzYTNhM2EzYTNhM2ENM2UzYTNhM2EzYTNhM2EzYTNhM2EzYTFpM2EzYTNhM2EzYTNhM2EzYTNhM2E Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4787 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4134346693 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5626086e9810, 0x5626088d301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5626088d3020,0x56260a76b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1d76b2b89179f87c89daa739e0a06f4d6c8833ef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6024 processed earlier; will process 5005 files now Step #5: ==172408== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5625ff1de9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562605843898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5626058265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5626058264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5625ff1e4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625ff145b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625ff140355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5625ff1d6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5626021a5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5626021a5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5626021a5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5626021a5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5626021a5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5626021a5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5626021a5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5626021a5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5626021a5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5626021a5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56260443af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562601167b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562601172be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562600f1ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562600f1ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562600f1f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562600f1e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562600f1e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562600f1e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562605828abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562605831928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562605819699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562605844112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe8fa19b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625ff13eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x21,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0x3d,0xa,0x3d,0xa,0x3d,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0xe2,0x80,0x8d,0x0,0x49,0x44,0x33,0x3,0x14,0x1,0x2f,0x0,0x0,0x67,0x54,0x49,0x54,0x49,0x44,0x45,0x42,0x4c,0x43,0x3d,0x6b,0x0,0x2b,0x50,0x63,0x2d,0x31,0x0,0x0,0xd,0xe,0xe,0x69,0x2d,0x20,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x2d,0x2d,0xa,0x62,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xfa,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: `-----BEG\011N -----\000\012=\012=\012=\012=\012=\012=?=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=!\012=\012=\012=\012=\012=\012=\012=?=\012=\012=(\342\200\256\000r+\342\200\215\000\000(\342\200\256\000r+\342\200\215\000ID3\003\024\001/\000\000gTITIDEBLC=k\000+Pc-1\000\000\015\016\016i- -\012`-----B--\012b-----BEG\011N -----\372N ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-0260dac9d31bdd496e336a653b06450dc945a37a Step #5: Base64: YC0tLS0tQkVHCU4gLS0tLS0ACj0KPQo9Cj0KPQo9Pz0KPQo9Cj0KPQo9Cj0KCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPSEKPQo9Cj0KPQo9Cj0KPT89Cj0KPSjigK4AcivigI0AACjigK4AcivigI0ASUQzAxQBLwAAZ1RJVElERUJMQz1rACtQYy0xAAANDg5pLSAtCmAtLS0tLUItLQpiLS0tLS1CRUcJTiAtLS0tLfpOIC0tLS0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4788 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4135001075 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55be3107f810, 0x55be3126901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55be31269020,0x55be331010e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0260dac9d31bdd496e336a653b06450dc945a37a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6025 processed earlier; will process 5004 files now Step #5: ==172444== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55be27b749c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55be2e1d9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55be2e1bc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55be2e1bc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55be27b7ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55be27adbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55be27ad6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55be27b6cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55be2ab3bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55be2ab3bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55be2ab3bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55be2ab3bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55be2ab3bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55be2ab3bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55be2ab3bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55be2ab3bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55be2ab3bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55be2ab3bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55be2cdd0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55be29afdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55be29b08be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55be298b4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55be298b4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55be298b5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55be298b4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55be298b4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55be298b4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55be2e1beabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55be2e1c7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55be2e1af699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55be2e1da112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5f67b98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55be27ad4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x27,0x28,0x11,0x27,0x29,0x7f,0x6e,0x3f,0x28,0x6e,0x28,0x29,0x3f,0x2e,0x28,0x3d,0x29,0x3f,0x2a,0x35,0x2e,0x28,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x28,0x6e,0x28,0x29,0x3f,0x2e,0x3d,0x28,0x29,0x3f,0x2a,0x35,0x2e,0x28,0x1,0x27,0x29,0x3f,0x24,0x45,0x45,0x28,0x29,0x2a,0x28,0x29,0x3f,0x28,0x29,0x2a,0x35,0x29,0x3f,0x28,0x29,0x2a,0x35,0x2b,0x6e,0x3f,0x28,0x6e,0x28,0x29,0x3f,0x2e,0x3d,0x28,0x29,0x2a,0x3f,0x35,0x2e,0x28,0x1,0x27,0x29,0x3f,0x24,0x45,0x45,0x28,0x29,0x2a,0x7b,0x2c,0x3f,0x28,0x29,0x3f,0x28,0x29,0x2a,0x29,0x3f,0x28,0x29,0x2a,0x36,0x2b,0x9,0x7e,0x29,0x3f,0x24,0x45,0x45,0x28,0x29,0x2a,0x28,0x29,0x3f,0x28,0x29,0x2a,0x35,0x29,0x3f,0x28,0x29,0x2a,0x35,0x2b,0x6e,0x3f,0x28,0x6e,0x28,0x29,0x3f,0x2e,0x3d,0x28,0x29,0x2a,0x3f,0x35,0x2e,0x28,0x1,0x27,0x29,0x3f,0x24,0x45,0x45,0x28,0x29,0x2a,0x7b,0x2c,0x3f,0x28,0x29,0x3f,0x28,0x29,0x2a,0x29,0x3f,0x28,0x29,0x2a,0x5,0x0,0x9,0x7e,0x9,0x9, Step #5: (?'(\021')\177n?(n()?.(=)?*5.(\001\000\000\000\000\000\000\000\000(n()?.=()?*5.(\001')?$EE()*()?()*5)?()*5+n?(n()?.=()*?5.(\001')?$EE()*{,?()?()*)?()*6+\011~)?$EE()*()?()*5)?()*5+n?(n()?.=()*?5.(\001')?$EE()*{,?()?()*)?()*\005\000\011~\011\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ebdb97b5f5d411b39ded828315bd20d2c48882b Step #5: Base64: KD8nKBEnKX9uPyhuKCk/Lig9KT8qNS4oAQAAAAAAAAAAKG4oKT8uPSgpPyo1LigBJyk/JEVFKCkqKCk/KCkqNSk/KCkqNStuPyhuKCk/Lj0oKSo/NS4oAScpPyRFRSgpKnssPygpPygpKik/KCkqNisJfik/JEVFKCkqKCk/KCkqNSk/KCkqNStuPyhuKCk/Lj0oKSo/NS4oAScpPyRFRSgpKnssPygpPygpKik/KCkqBQAJfgkJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4789 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4135537546 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca4f72d810, 0x55ca4f91701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca4f917020,0x55ca517af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ebdb97b5f5d411b39ded828315bd20d2c48882b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6026 processed earlier; will process 5003 files now Step #5: ==172480== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ca462229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca4c887898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca4c86a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca4c86a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca46228d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca46189b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca46184355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca4621ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca491e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca491e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca491e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca491e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca491e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca491e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca491e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca491e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca491e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca491e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca4b47ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca481abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca481b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca47f62c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca47f62c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca47f63738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca47f62874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca47f62874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca47f62874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca4c86cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca4c875928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca4c85d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca4c888112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efed0e95082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca46182b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3e,0x3e,0x3e,0x3e,0x3e,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0xa,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x2d,0x2d,0x2d,0x20,0x2d,0x21,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x2b,0x50,0x63,0x2d,0x31,0x0,0x0,0xd,0xe,0xe,0x69,0x2d,0x20,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x2d,0x2d,0xa,0x62,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xfa,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: `-----BEG\011N -----\000\012=\012=\012=\012=\012=\012=?=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000>>>>> \012-----END \012-----END \012-\012-----BEGIN--- -!\012-----E+Pc-1\000\000\015\016\016i- -\012`-----B--\012b-----BEG\011N -----\372N ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-430627a1f1884cfb88ce4e772a87efd7d021e4ea Step #5: Base64: YC0tLS0tQkVHCU4gLS0tLS0ACj0KPQo9Cj0KPQo9Pz0KPQo9Cj0KPQo9Cj0KCj0KPQo9Cj0KPQo9Cj0KPQo9CgAAAAAAAAAAAAAAAAAAAAAAPj4+Pj4gCi0tLS0tRU5EIAotLS0tLUVORCAKLQotLS0tLUJFR0lOLS0tIC0hCi0tLS0tRStQYy0xAAANDg5pLSAtCmAtLS0tLUItLQpiLS0tLS1CRUcJTiAtLS0tLfpOIC0tLS0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4790 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4136184033 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562bd6909810, 0x562bd6af301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562bd6af3020,0x562bd898b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/430627a1f1884cfb88ce4e772a87efd7d021e4ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6027 processed earlier; will process 5002 files now Step #5: ==172516== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562bcd3fe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562bd3a63898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562bd3a465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562bd3a464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562bcd404d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562bcd365b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562bcd360355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562bcd3f6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562bd03c5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562bd03c5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562bd03c5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562bd03c5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562bd03c5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562bd03c5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562bd03c5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562bd03c5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562bd03c5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562bd03c5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562bd265af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562bcf387b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562bcf392be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562bcf13ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562bcf13ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562bcf13f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562bcf13e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562bcf13e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562bcf13e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562bd3a48abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562bd3a51928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562bd3a39699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562bd3a64112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff2403d6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562bcd35eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012\001\000\000\000\000\000\000\000=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-24d09f9d9a2698794673e115a6724f6b4d3d94bc Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQoBAAAAAAAAAD0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4791 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4136719564 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561547ccc810, 0x561547eb601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561547eb6020,0x561549d4e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/24d09f9d9a2698794673e115a6724f6b4d3d94bc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6028 processed earlier; will process 5001 files now Step #5: ==172552== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56153e7c19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561544e26898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561544e095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561544e094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56153e7c7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56153e728b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56153e723355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56153e7b9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561541788f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561541788f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561541788f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561541788f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561541788f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561541788f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561541788f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561541788f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561541788f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561541788f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561543a1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56154074ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561540755be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561540501c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561540501c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561540502738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561540501874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561540501874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561540501874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561544e0babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561544e14928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561544dfc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561544e27112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f08120c4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56153e721b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x9,0x28,0x69,0x2d,0x2d,0x42,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0xa,0x3a,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x2c,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x33,0x0,0x0,0x0,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x24,0x9d,0x72, Step #5: s-\011(i--B\000\000\000\000\001\000\000\000\000\000\000\000$\012:\012\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000333333333333333333333333333333333333333333333333333333333333333333333333,333333333333333333333333333333333333333333333333\000\000\000-\012=\012=\012\000\000\000\000\000\000\000\012$\235r Step #5: artifact_prefix='./'; Test unit written to ./oom-3cbb6b05fb925986ea24295011392d7c4e45d232 Step #5: Base64: cy0JKGktLUIAAAAAAQAAAAAAAAAkCjoKAAAAAAAAAAAAAAAAAAAAAAAAMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzLDMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMzMwAAAC0KPQo9CgAAAAAAAAAKJJ1y Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4792 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4137239358 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d201b7810, 0x561d203a101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d203a1020,0x561d222390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3cbb6b05fb925986ea24295011392d7c4e45d232' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6029 processed earlier; will process 5000 files now Step #5: ==172588== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d16cac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d1d311898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d1d2f45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d1d2f44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d16cb2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d16c13b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d16c0e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d16ca4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d19c73f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d19c73f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d19c73f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d19c73f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d19c73f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d19c73f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d19c73f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d19c73f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d19c73f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d19c73f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d1bf08f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d18c35b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d18c40be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d189ecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d189ecc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d189ed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d189ec874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d189ec874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d189ec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d1d2f6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d1d2ff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d1d2e7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d1d312112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f81f11ad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d16c0cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x61,0x61,0x57,0x76,0xf3,0xa0,0x84,0x8f,0xf3,0xa0,0x84,0xac,0x70,0x76,0xf3,0xa0,0x84,0x8f,0xf3,0xa0,0x84,0xac,0x6a,0xf3,0xa0,0x84,0x8f,0x26,0x2c,0xf3,0xa0,0x84,0xac,0x6d,0xf3,0xa0,0x84,0x8f,0x76,0x76,0x76,0xf3,0xa0,0x84,0x8f,0xf3,0xa0,0x84,0xac,0x6e,0x70,0xf3,0xa0,0x84,0x8f,0x76,0xf3,0xa0,0x84,0xac,0x76,0x76,0xf3,0xa0,0x84,0x8f,0xf3,0xa0,0x84,0xac,0x6e,0x70,0xf3,0xa0,0x84,0x8f,0x76,0xf3,0xa0,0x84,0xac,0x6a,0xf3,0xa0,0x84,0x96,0x76,0x30,0x61,0x61,0x61,0x61,0x6a,0xf3,0xa0,0x84,0x8f,0x71,0xf3,0xa0,0x84,0xac,0x30,0x6a,0xf3,0xa0,0x85,0x8f,0x2d,0xf3,0xa0,0x84,0xa4,0x76,0xf3,0xa0,0x84,0x8f,0xf3,0xa0,0x84,0xac,0x70,0x76,0xf3,0xa0,0x84,0x8f,0x32,0xf3,0xa0,0x84,0xac,0x6a,0xf3,0xa0,0x84,0x8f,0x26,0x2c,0xf3,0xa0,0x84,0xac,0x6d,0xf3,0xa0,0x84,0x8f,0x76,0x76,0xf3,0xa0,0x84,0x8f,0xf3,0xa0,0x84,0xac,0x70,0xf3,0xa0,0x84,0x8f,0x76,0xf3,0xa0,0x84,0xac,0x6a,0xf3,0xa0,0x84,0x96,0x76,0x30,0x4d,0x4d,0x4d,0x4d, Step #5: ws:aaWv\363\240\204\217\363\240\204\254pv\363\240\204\217\363\240\204\254j\363\240\204\217&,\363\240\204\254m\363\240\204\217vvv\363\240\204\217\363\240\204\254np\363\240\204\217v\363\240\204\254vv\363\240\204\217\363\240\204\254np\363\240\204\217v\363\240\204\254j\363\240\204\226v0aaaaj\363\240\204\217q\363\240\204\2540j\363\240\205\217-\363\240\204\244v\363\240\204\217\363\240\204\254pv\363\240\204\2172\363\240\204\254j\363\240\204\217&,\363\240\204\254m\363\240\204\217vv\363\240\204\217\363\240\204\254p\363\240\204\217v\363\240\204\254j\363\240\204\226v0MMMM Step #5: artifact_prefix='./'; Test unit written to ./oom-70307054bdd7e19e94302ebd2683f76e754327ed Step #5: Base64: d3M6YWFXdvOghI/zoISscHbzoISP86CErGrzoISPJizzoISsbfOghI92dnbzoISP86CErG5w86CEj3bzoISsdnbzoISP86CErG5w86CEj3bzoISsavOghJZ2MGFhYWFq86CEj3HzoISsMGrzoIWPLfOghKR286CEj/OghKxwdvOghI8y86CErGrzoISPJizzoISsbfOghI92dvOghI/zoISscPOghI9286CErGrzoISWdjBNTU1N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4793 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4137752852 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562a207f5810, 0x562a209df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562a209df020,0x562a228770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70307054bdd7e19e94302ebd2683f76e754327ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6030 processed earlier; will process 4999 files now Step #5: ==172624== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562a172ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562a1d94f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562a1d9325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562a1d9324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562a172f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562a17251b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562a1724c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562a172e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562a1a2b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562a1a2b1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562a1a2b1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562a1a2b1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562a1a2b1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562a1a2b1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562a1a2b1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562a1a2b1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562a1a2b1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562a1a2b1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562a1c546f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562a19273b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562a1927ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562a1902ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562a1902ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562a1902b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562a1902a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562a1902a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562a1902a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562a1d934abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562a1d93d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562a1d925699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562a1d950112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f43e8c4d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562a1724ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2b,0xa,0x9,0x2b,0xa,0x9,0x2b,0x7e,0x7e,0x7e,0x7e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2b,0xa,0x9,0x2b,0xa,0x9,0x2b,0x7e,0x7e,0x2b,0xa,0x9,0x2b,0xa,0x8,0x2b,0x7e,0x7e,0xa,0x9,0x65,0x6e,0x2b,0x7e,0x7e,0x7e,0x7e,0x29,0x7f,0xfe,0x7e,0xeb,0x5d,0xeb,0x7c,0xb2, Step #5: +\012\011\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000+\012\011+\012\011+~~~~\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000+\012\011+\012\011+~~+\012\011+\012\010+~~\012\011en+~~~~)\177\376~\353]\353|\262 Step #5: artifact_prefix='./'; Test unit written to ./oom-8c5b11bd09c69bd07c9f952e80a390f557e969fb Step #5: Base64: KwoJAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACsKCSsKCSt+fn5+AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAKwoJKwoJK35+KwoJKwoIK35+Cgllbit+fn5+KX/+futd63yy Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4794 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4138286423 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a912663810, 0x55a91284d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a91284d020,0x55a9146e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c5b11bd09c69bd07c9f952e80a390f557e969fb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6031 processed earlier; will process 4998 files now Step #5: #1 pulse cov: 3739 ft: 3740 exec/s: 0 rss: 176Mb Step #5: ==172660== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a9091589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a90f7bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a90f7a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a90f7a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a90915ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a9090bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a9090ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a909150c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a90c11ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a90c11ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a90c11ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a90c11ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a90c11ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a90c11ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a90c11ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a90c11ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a90c11ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a90c11ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a90e3b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a90b0e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a90b0ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a90ae98c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a90ae98c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a90ae99738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a90ae98874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a90ae98874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a90ae98874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a90f7a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a90f7ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a90f793699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a90f7be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd739a88082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a9090b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xa,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x20,0x42,0x45,0x47,0x49,0x4e,0x2d,0x2d,0x2d,0x2d,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x32,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x9,0xa,0x60,0x47,0x60,0xa,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x20,0x42,0x45,0x47,0x49,0x4e,0x2d,0x2d,0x2d,0x2d,0xa,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x33,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x9,0xa,0x60,0x47,0x0,0x54,0x49,0x42,0x20,0x20,0x60,0x0,0x54,0x49,0x42,0xa,0x60,0x60,0x20,0x20,0x20,0x60,0xa,0x9, Step #5: `\012\005------ BEGIN----\012\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000ddddddd2ddddddddd\011\012`G`\012\005------ BEGIN----\012ddddddd3ddddddddd\011\012`G\000TIB `\000TIB\012`` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-b25ae0686bbac85b06552c283874a30735134abc Step #5: Base64: YAoFLS0tLS0tIEJFR0lOLS0tLQoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABkZGRkZGRkMmRkZGRkZGRkZAkKYEdgCgUtLS0tLS0gQkVHSU4tLS0tCmRkZGRkZGQzZGRkZGRkZGRkCQpgRwBUSUIgIGAAVElCCmBgICAgYAoJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4795 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4138971849 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560643b86810, 0x560643d7001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560643d70020,0x560645c080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b25ae0686bbac85b06552c283874a30735134abc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6033 processed earlier; will process 4996 files now Step #5: #1 pulse cov: 3936 ft: 3937 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4093 ft: 4419 exec/s: 0 rss: 177Mb Step #5: ==172696== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56063a67b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560640ce0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560640cc35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560640cc34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56063a681d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56063a5e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56063a5dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56063a673c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56063d642f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56063d642f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56063d642f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56063d642f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56063d642f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56063d642f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56063d642f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56063d642f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56063d642f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56063d642f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56063f8d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56063c604b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56063c60fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56063c3bbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56063c3bbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56063c3bc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56063c3bb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56063c3bb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56063c3bb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560640cc5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560640cce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560640cb6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560640ce1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f148f202082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56063a5dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x20,0x7b,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0xa,0x20,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0xa,0x20,0x6e,0x61,0x6d,0x65,0x3a,0xa,0x22,0x44,0x20,0x20,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x5c,0x27,0x45,0x59,0x27,0x20,0x20,0x20,0x5c,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0xc5,0xae,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x13,0x40,0x2f,0xdc,0xd0,0xd0,0xd9,0x3f,0x74,0x2c,0x33,0xdc,0xd0,0x23,0x23,0x27,0x20,0x20,0x20,0x3e,0x20,0x20,0x5c,0x30,0x30,0x30,0x5c,0x72,0x20,0x20,0x20,0x20,0x3c,0x41,0x3e,0x20,0xba,0xb9,0xdf,0xde,0x44,0x20,0x20,0x20,0x57,0x22,0x20,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x76,0x61,0x6c,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x22,0x20,0x7d,0x20,0x7d,0xc,0x20,0xa,0x20,0x20,0x7d,0x20,0x7d,0x20,0x7d,0x7d, Step #5: p {doctype {\012mdecl {\012 entity {\012 name:\012\"D PUBLIC \\'EY' \\'http://\305\256\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023\023@/\334\320\320\331?t,3\334\320##' > \\000\\r <A> \272\271\337\336D W\" ent {\012 val { name: \"D\" } }\014 \012 } } }} Step #5: artifact_prefix='./'; Test unit written to ./oom-cef7534fe29d4772a519739f84f6bc330a3c9b27 Step #5: Base64: cCB7ZG9jdHlwZSB7Cm1kZWNsIHsKIGVudGl0eSB7CiBuYW1lOgoiRCAgIFBVQkxJQyBcJ0VZJyAgIFwnaHR0cDovL8WuExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTE0Av3NDQ2T90LDPc0CMjJyAgID4gIFwwMDBcciAgICA8QT4gurnf3kQgICBXIiBlbnQgewogIHZhbCB7IG5hbWU6ICJEIiB9IH0MIAogIH0gfSB9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4796 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4139569234 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bbc1b07810, 0x55bbc1cf101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bbc1cf1020,0x55bbc3b890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cef7534fe29d4772a519739f84f6bc330a3c9b27' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6036 processed earlier; will process 4993 files now Step #5: #1 pulse cov: 11328 ft: 11329 exec/s: 0 rss: 195Mb Step #5: ==172732== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bbb85fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bbbec61898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bbbec445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bbbec444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bbb8602d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bbb8563b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bbb855e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bbb85f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bbbb5c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bbbb5c3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bbbb5c3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bbbb5c3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bbbb5c3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bbbb5c3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bbbb5c3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bbbb5c3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bbbb5c3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bbbb5c3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bbbd858f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bbba585b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bbba590be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bbba33cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bbba33cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bbba33d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bbba33c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bbba33c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bbba33c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bbbec46abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bbbec4f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bbbec37699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bbbec62112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f29838082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bbb855cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x73,0x74,0x79,0x76,0x67,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x3c,0x73,0x76,0x67,0x74,0x38,0x6d,0x6b,0x3e,0x67,0x7b,0x6f,0x3a,0x2e,0x31,0x2d,0x31,0x7d,0x3c,0x67,0x38,0x6d,0x6b,0x3e,0x67,0x7b,0x6f,0x3a,0x2e,0x31,0x6c,0x65,0x3e,0x3c,0x73,0x76,0x67,0x73,0x76,0x67,0x74,0x38,0x6d,0x6b,0x3e,0x67,0x7b,0x6f,0x3a,0x2e,0x31,0x2d,0x31,0x7d,0x3c,0x67,0x38,0x6d,0x6b,0x3e,0x67,0x7b,0x6f,0x3a,0x2e,0x31,0x2d,0x31,0x7b,0x6f,0x3a,0x2e,0x31,0x2d,0x31,0x7d,0x3c,0x67,0x3e,0x3c,0x67,0x73,0x76,0x67,0x73,0x76,0x67,0x74,0x38,0x6d,0x6b,0x3e,0x67,0x7b,0x6f,0x3a,0x2e,0x31,0x2d,0x31,0x7d,0x3c,0x67,0x38,0x6d,0x6b,0x3e,0x67,0x7b,0x6f,0x3a,0x2e,0x31,0x6c,0x65,0x3e,0x3c,0x73,0x76,0x67,0x73,0x76,0x67,0x74,0x38,0x6d,0x6b,0x3e,0x67,0x7b,0x6f,0x3a,0x2e,0x31,0x2d,0x31,0x7d,0x3c,0x67,0x38,0x6d,0x6b,0x3e,0x67,0x7b,0x6f,0x3a,0x2e,0x31,0x2d,0x31,0x7b,0x6f,0x3a,0x2e,0x31,0x2d,0x31,0x7d,0x3c,0x67,0x3e,0x3c,0x67,0x3e, Step #5: <svg><styvg><style><svgt8mk>g{o:.1-1}<g8mk>g{o:.1le><svgsvgt8mk>g{o:.1-1}<g8mk>g{o:.1-1{o:.1-1}<g><gsvgsvgt8mk>g{o:.1-1}<g8mk>g{o:.1le><svgsvgt8mk>g{o:.1-1}<g8mk>g{o:.1-1{o:.1-1}<g><g> Step #5: artifact_prefix='./'; Test unit written to ./oom-c69524a527331b72a9c68c728eb061f526234720 Step #5: Base64: PHN2Zz48c3R5dmc+PHN0eWxlPjxzdmd0OG1rPmd7bzouMS0xfTxnOG1rPmd7bzouMWxlPjxzdmdzdmd0OG1rPmd7bzouMS0xfTxnOG1rPmd7bzouMS0xe286LjEtMX08Zz48Z3N2Z3N2Z3Q4bWs+Z3tvOi4xLTF9PGc4bWs+Z3tvOi4xbGU+PHN2Z3N2Z3Q4bWs+Z3tvOi4xLTF9PGc4bWs+Z3tvOi4xLTF7bzouMS0xfTxnPjxnPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4797 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4140157070 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563564857810, 0x563564a4101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563564a41020,0x5635668d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c69524a527331b72a9c68c728eb061f526234720' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6038 processed earlier; will process 4991 files now Step #5: ==172768== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56355b34c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5635619b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5635619945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5635619944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56355b352d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56355b2b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56355b2ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56355b344c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56355e313f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56355e313f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56355e313f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56355e313f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56355e313f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56355e313f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56355e313f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56355e313f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56355e313f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56355e313f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5635605a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56355d2d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56355d2e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56355d08cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56355d08cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56355d08d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56355d08c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56355d08c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56355d08c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563561996abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56356199f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563561987699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5635619b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1b9ade7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56355b2acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x65,0x6c,0x45,0x43,0x74,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0x30,0x2e,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0x30,0x2e,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0x30,0x2e,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0x30,0x2e,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0x30,0x2e,0x2d,0xc,0xc,0x45,0x43,0x74,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0x30,0x2e,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0x30,0x2e,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0x2e,0x2d,0xc,0x2d,0xc,0x2d,0xc,0x2d,0x2d,0x30,0x2e,0x2d,0xc,0x2d,0x38,0x2e, Step #5: selECt-\014-\014-\014-\014-\014-0.-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-0.-\014-\014-\014-\014-0.-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-0.-\014-\014-\014-\014-0.-\014\014ECt-\014-\014-\014-\014-0.-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-\014-0.-\014-\014-\014-.-\014-\014-\014--0.-\014-8. Step #5: artifact_prefix='./'; Test unit written to ./oom-758f7ffa5b53bccfe2fe3015d07d80d91ee69d14 Step #5: Base64: c2VsRUN0LQwtDC0MLQwtDC0wLi0MLQwtDC0MLQwtDC0MLQwtDC0MLQwtDC0MLQwtMC4tDC0MLQwtDC0wLi0MLQwtDC0MLQwtDC0MLQwtDC0MLQwtDC0MLQwtDC0wLi0MLQwtDC0MLTAuLQwMRUN0LQwtDC0MLQwtMC4tDC0MLQwtDC0MLQwtDC0MLQwtDC0MLQwtDC0MLQwtDC0MLQwtMC4tDC0MLQwtLi0MLQwtDC0tMC4tDC04Lg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4798 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4140727573 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a38728d810, 0x55a38747701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a387477020,0x55a38930f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/758f7ffa5b53bccfe2fe3015d07d80d91ee69d14' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6039 processed earlier; will process 4990 files now Step #5: ==172804== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a37dd829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3843e7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3843ca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3843ca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a37dd88d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a37dce9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a37dce4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a37dd7ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a380d49f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a380d49f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a380d49f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a380d49f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a380d49f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a380d49f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a380d49f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a380d49f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a380d49f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a380d49f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a382fdef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a37fd0bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a37fd16be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a37fac2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a37fac2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a37fac3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a37fac2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a37fac2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a37fac2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a3843ccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a3843d5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3843bd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3843e8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa4f3f3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a37dce2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x35,0x24,0x34,0x5c,0x37,0x37,0x5c,0x37,0x37,0x24,0x7b,0x38,0x7d,0x24,0x7f,0x32,0x7d,0x24,0x7b,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x1,0x0,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x25,0x4e,0x3f,0x3f,0x8,0x23,0x31,0x23,0x31,0x23,0x31,0x25,0x1,0x0,0x0,0x0,0x20,0x23,0x31,0x25,0x24,0x1,0x0,0x0,0x0,0x7b,0x7b,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x1,0x0,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x25,0x4e,0x3f,0x3f,0x8,0x23,0x31,0x23,0x31,0x23,0x31,0x25,0x1,0x0,0x0,0x0,0x20,0x23,0x31,0x25,0x24,0x1,0x0,0x0,0x0,0x7b,0x37,0x36,0x5c,0x37,0x37,0x5c,0x37,0x0,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x0,0x86,0x37,0x37,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x7d,0x6a,0x6a,0x37,0x36,0x5c,0x37,0x37,0x5c,0x37,0x0,0x37,0x5c,0x37,0x37,0x5c,0x37,0x37,0x5c,0x0,0x86,0x37,0x37,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x7d,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x6a,0x5c,0x33,0x38,0x5c,0x37,0x37,0x5c,0x37,0x33, Step #5: \\5$4\\77\\77${8}$\1772}${\001\000\000\000\000\000\000$\001\000${8}${8}%N??\010#1#1#1%\001\000\000\000 #1%$\001\000\000\000{{\001\000\000\000\000\000\000$\001\000${8}${8}%N??\010#1#1#1%\001\000\000\000 #1%$\001\000\000\000{76\\77\\7\0007\\77\\77\\\000\20677jjjjjj}jj76\\77\\7\0007\\77\\77\\\000\20677jjjjjj}jjjjjjjjjj\\38\\77\\73 Step #5: artifact_prefix='./'; Test unit written to ./oom-9fa33a048e5095b2b5d5b7217818c65f97c3d5ed Step #5: Base64: XDUkNFw3N1w3NyR7OH0kfzJ9JHsBAAAAAAAAJAEAJHs4fSR7OH0lTj8/CCMxIzEjMSUBAAAAICMxJSQBAAAAe3sBAAAAAAAAJAEAJHs4fSR7OH0lTj8/CCMxIzEjMSUBAAAAICMxJSQBAAAAezc2XDc3XDcAN1w3N1w3N1wAhjc3ampqampqfWpqNzZcNzdcNwA3XDc3XDc3XACGNzdqampqamp9ampqampqampqalwzOFw3N1w3Mw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4799 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4141260742 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5649b3961810, 0x5649b3b4b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5649b3b4b020,0x5649b59e30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9fa33a048e5095b2b5d5b7217818c65f97c3d5ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6040 processed earlier; will process 4989 files now Step #5: ==172840== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5649aa4569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5649b0abb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5649b0a9e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5649b0a9e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5649aa45cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649aa3bdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649aa3b8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5649aa44ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5649ad41df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5649ad41df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5649ad41df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5649ad41df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5649ad41df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5649ad41df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5649ad41df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5649ad41df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5649ad41df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5649ad41df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5649af6b2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649ac3dfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649ac3eabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5649ac196c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5649ac196c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5649ac197738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5649ac196874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5649ac196874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5649ac196874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5649b0aa0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5649b0aa9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5649b0a91699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5649b0abc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c61d88082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649aa3b6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0x5e,0x0,0x0,0x0,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x3d,0xa,0x3d,0x20,0x69,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x2d,0x2d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x2d,0xa,0x24,0xa,0x3d,0xa,0x3d,0xa,0x66,0x3d,0xa,0x3d,0xa,0xa,0x2d,0x2d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x2d,0x2d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x2d,0xa,0x24,0xa,0x3d,0xa,0x3d,0xa,0x66,0x3d,0xa,0x3d,0xa,0xa,0x2d,0x2d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x7c,0x0,0x10,0xff, Step #5: \005-----BEGIN =^\000\000\000\012\012r=sef=\012=+=\012=\012=\012= =\012= i\012\012r=sef=\012=+=\012=\012=\012=+=\012=\012=\012= =\012= i\012\012r=sef=\012=+=\012=\012=\012=\012D\012=\012=\012=\012\012--=\012=\012=\012=\012=\012-\012$\012=\012=\012f=\012=\012\012--=\012=\012=\012=\012D\012=\012=\012=\012\012--=\012=\012=\012=\012=\012-\012$\012=\012=\012f=\012=\012\012--=\012=\012=\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-fd9e4ce4a3d13889a8013d68c87e5b01b6175667 Step #5: Base64: BS0tLS0tQkVHSU4gPV4AAAAKCnI9c2VmPQo9Kz0KPQo9Cj0gPQo9IGkKCnI9c2VmPQo9Kz0KPQo9Cj0rPQo9Cj0KPSA9Cj0gaQoKcj1zZWY9Cj0rPQo9Cj0KPQpECj0KPQo9CgotLT0KPQo9Cj0KPQotCiQKPQo9CmY9Cj0KCi0tPQo9Cj0KPQpECj0KPQo9CgotLT0KPQo9Cj0KPQotCiQKPQo9CmY9Cj0KCi0tPQo9Cj0KfAAQ/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4800 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4141795473 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564495990810, 0x564495b7a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564495b7a020,0x564497a120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fd9e4ce4a3d13889a8013d68c87e5b01b6175667' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6041 processed earlier; will process 4988 files now Step #5: ==172876== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56448c4859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564492aea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564492acd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564492acd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56448c48bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56448c3ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56448c3e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56448c47dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56448f44cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56448f44cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56448f44cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56448f44cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56448f44cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56448f44cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56448f44cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56448f44cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56448f44cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56448f44cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5644916e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56448e40eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56448e419be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56448e1c5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56448e1c5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56448e1c6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56448e1c5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56448e1c5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56448e1c5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564492acfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564492ad8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564492ac0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564492aeb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f501f029082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56448c3e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe3,0x80,0x88,0x2d,0x0,0x60,0x68,0x68,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xb,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x68,0x74,0xe2,0x80,0x88,0x2d,0x0,0x60,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xa,0x2f,0xa,0x2f,0xa,0x60,0x68,0x20,0x20,0x20,0x68,0xa,0x9, Step #5: `\343\200\210-\000`hh\012=\012=\012\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000=\012=\012=\013\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=ht\342\200\210-\000``\342\200\210-\000`\012/\012`\342\200\210-\000`\012\012/\012/\012`h h\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-72a477edb9b4d3952c652bf8b49a734ca5fba09c Step #5: Base64: YOOAiC0AYGhoCj0KPQoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPQo9Cj0LCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPWh04oCILQBgYOKAiC0AYAovCmDigIgtAGAKCi8KLwpgaCAgIGgKCQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4801 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4142449667 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559676315810, 0x5596764ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596764ff020,0x5596783970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/72a477edb9b4d3952c652bf8b49a734ca5fba09c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6042 processed earlier; will process 4987 files now Step #5: #1 pulse cov: 3676 ft: 3677 exec/s: 0 rss: 174Mb Step #5: ==172912== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55966ce0a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55967346f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5596734525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5596734524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55966ce10d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55966cd71b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55966cd6c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55966ce02c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55966fdd1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55966fdd1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55966fdd1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55966fdd1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55966fdd1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55966fdd1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55966fdd1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55966fdd1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55966fdd1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55966fdd1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559672066f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55966ed93b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55966ed9ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55966eb4ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55966eb4ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55966eb4b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55966eb4a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55966eb4a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55966eb4a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559673454abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55967345d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559673445699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559673470112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a0047a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55966cd6ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x70,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x20,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x4a,0x0,0x0,0x0,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x73,0x74,0x20,0x31,0x20,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x20,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x1a,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x73,0x74,0x20,0x34,0x38,0x20,0x3,0x7e,0x47,0x46,0x44,0x7e,0x91,0x47, Step #5: ID\012\000\000\000\000\000\000\012p$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$$$J\000\000\000$$$$$$$st 1 $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ $$$$$$$$$$$$$$$$\032$$$$$$$$$$$$$$$$$$$$$$$st 48 \003~GFD~\221G Step #5: artifact_prefix='./'; Test unit written to ./oom-9f26f8a4261dafefc0785dd551f6da441454b781 Step #5: Base64: SUQKAAAAAAAACnAkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCAkJCQkJCQkJCQkJCQkJCQkJCRKAAAAJCQkJCQkJHN0IDEgJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCAkJCQkJCQkJCQkJCQkJCQkGiQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkc3QgNDggA35HRkR+kUc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4802 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4143034857 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5598117f3810, 0x5598119dd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5598119dd020,0x5598138750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f26f8a4261dafefc0785dd551f6da441454b781' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6044 processed earlier; will process 4985 files now Step #5: ==172948== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5598082e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55980e94d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55980e9305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55980e9304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5598082eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55980824fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55980824a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5598082e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55980b2aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55980b2aff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55980b2aff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55980b2aff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55980b2aff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55980b2aff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55980b2aff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55980b2aff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55980b2aff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55980b2aff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55980d544f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55980a271b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55980a27cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55980a028c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55980a028c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55980a029738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55980a028874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55980a028874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55980a028874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55980e932abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55980e93b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55980e923699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55980e94e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feb5e853082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559808248b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x51,0x79,0x71,0x67,0x47,0x42,0x54,0x59,0x46,0x79,0x42,0x72,0x4b,0x77,0x45,0x4d,0x48,0x4b,0x65,0x61,0x74,0x36,0x79,0x71,0x52,0x76,0x31,0x64,0x6d,0x44,0x57,0x61,0x71,0x49,0x59,0x30,0x6a,0x76,0x65,0x6d,0x4d,0x46,0x34,0x3d,0xa,0x61,0x20,0x2a,0x3a,0x2d,0x39,0xa,0x61,0x20,0x2a,0x3a,0x2d,0x39,0xa,0x61,0x9,0x2a,0x3a,0x35,0x2d,0x30,0xa,0x61,0x20,0x2a,0x3a,0x2d,0x38,0xa,0x61,0x20,0x2a,0x3a,0x2d,0x37,0xa,0x61,0x20,0x2a,0x3a,0x2d,0x39,0xa,0x61,0x20,0x2a,0x3a,0x2d,0x39,0xa,0x61,0x9,0x2a,0x3a,0x35,0x2d,0x30,0xa,0x61,0x20,0x2a,0x3a,0x2d,0x39,0x2d,0xa,0x61,0x20,0x2a,0x3a,0x2d,0x38,0xa,0x61,0x20,0x2a,0x3a,0x2d,0x37,0xa,0x61,0x20,0x2a,0x3a,0x2d,0x39,0xa,0x61,0x20,0x2a,0x3a,0x2d,0x39,0xa,0x61,0x9,0x2a,0x3a,0x35,0x2d,0x30,0xa,0x61,0x20,0x2a,0x3a,0x2d,0x39,0xa,0x61,0x20,0x2a,0x3a,0x2d,0x39, Step #5: onion-key\012ntor-onion-key QyqgGBTYFyBrKwEMHKeat6yqRv1dmDWaqIY0jvemMF4=\012a *:-9\012a *:-9\012a\011*:5-0\012a *:-8\012a *:-7\012a *:-9\012a *:-9\012a\011*:5-0\012a *:-9-\012a *:-8\012a *:-7\012a *:-9\012a *:-9\012a\011*:5-0\012a *:-9\012a *:-9 Step #5: artifact_prefix='./'; Test unit written to ./oom-4a0b35d7022dd7518c5bd5174edc30c9fb0e44c6 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IFF5cWdHQlRZRnlCckt3RU1IS2VhdDZ5cVJ2MWRtRFdhcUlZMGp2ZW1NRjQ9CmEgKjotOQphICo6LTkKYQkqOjUtMAphICo6LTgKYSAqOi03CmEgKjotOQphICo6LTkKYQkqOjUtMAphICo6LTktCmEgKjotOAphICo6LTcKYSAqOi05CmEgKjotOQphCSo6NS0wCmEgKjotOQphICo6LTk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4803 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4143557749 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56378b90a810, 0x56378baf401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56378baf4020,0x56378d98c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4a0b35d7022dd7518c5bd5174edc30c9fb0e44c6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6045 processed earlier; will process 4984 files now Step #5: ==172984== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5637823ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563788a64898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563788a475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563788a474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563782405d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563782366b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563782361355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5637823f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5637853c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5637853c6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5637853c6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5637853c6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5637853c6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5637853c6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5637853c6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5637853c6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5637853c6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5637853c6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56378765bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563784388b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563784393be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56378413fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56378413fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563784140738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56378413f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56378413f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56378413f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563788a49abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563788a52928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563788a3a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563788a65112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff2971e0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56378235fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0x13,0x0,0x0,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x2b,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012==\012=\012=\023\000\000\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012+\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-326165a00c799f7956b864ff98b4261b82b0fd87 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9PQo9Cj0TAAAACj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cgo9Cj0KKworCisKKworCisKKworCisKKworCisKKworCisKKworCisKKworCisKKworCisKKworCisKKworCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9ChA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4804 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4144120020 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d66cdc1810, 0x55d66cfab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d66cfab020,0x55d66ee430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/326165a00c799f7956b864ff98b4261b82b0fd87' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6046 processed earlier; will process 4983 files now Step #5: #1 pulse cov: 14463 ft: 14464 exec/s: 0 rss: 197Mb Step #5: ==173020== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d6638b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d669f1b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d669efe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d669efe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d6638bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d66381db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d663818355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d6638aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d66687df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d66687df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d66687df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d66687df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d66687df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d66687df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d66687df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d66687df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d66687df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d66687df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d668b12f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d66583fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d66584abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d6655f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d6655f6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d6655f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d6655f6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d6655f6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d6655f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d669f00abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d669f09928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d669ef1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d669f1c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f810eb22082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d663816b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x61,0x6c,0x70,0x68,0x61,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe,0x4,0x1,0x0,0x0,0x67,0x54,0x49,0x6d,0x73,0x74,0x72,0x65,0x61,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6d,0x69,0x3,0xe, Step #5: I\000\000\000\000\000\000\000\000\000\000\000\000\000alpha\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\016\004\001\000\000gTImstrea\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\034\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000mi\003\016 Step #5: artifact_prefix='./'; Test unit written to ./oom-b7c3cbe01d26aeb063471b91d6cc8707b2a85e07 Step #5: Base64: SQAAAAAAAAAAAAAAAABhbHBoYQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOBAEAAGdUSW1zdHJlYQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAG1pAw4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4805 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4144718833 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb35e80810, 0x55cb3606a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb3606a020,0x55cb37f020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7c3cbe01d26aeb063471b91d6cc8707b2a85e07' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6048 processed earlier; will process 4981 files now Step #5: #1 pulse cov: 4187 ft: 4188 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4801 ft: 5391 exec/s: 0 rss: 177Mb Step #5: ==173056== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cb2c9759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb32fda898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb32fbd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb32fbd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb2c97bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb2c8dcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb2c8d7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb2c96dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb2f93cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb2f93cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb2f93cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb2f93cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb2f93cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb2f93cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb2f93cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb2f93cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb2f93cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb2f93cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb31bd1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb2e8feb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb2e909be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb2e6b5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb2e6b5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb2e6b6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb2e6b5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb2e6b5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb2e6b5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb32fbfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb32fc8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb32fb0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb32fdb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f39a5a5b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb2c8d5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x74,0x75,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x55,0x74,0x74,0x55,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7d,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x2a,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x24,0x29,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x21,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x29,0x29,0x24,0x7c,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x27,0xe,0x70,0x29,0x65,0x2a,0x7c,0x29,0x2f,0x29,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x7c,0x7f, Step #5: ttu(?:(?:?:(?:$|$|(?:(?:(?:$|$|$|$|$|$UttU|$|$|$|$|$|$|$)|$}(?:$|$|(?:(?:*?:$|$|$|$|$|$|$|$|$$)|$|(?:$|$|(?:(?:(?:$|$|$!$|$|$|$|$|$|$|$|$|$)|$|)|$|$|$|$)|))$||$|$|$|$'\016p)e*|)/))|)|)|)||\177 Step #5: artifact_prefix='./'; Test unit written to ./oom-1946db8aceb40b6cf76cf677133c3bc8cbf09d45 Step #5: Base64: dHR1KD86KD86PzooPzokfCR8KD86KD86KD86JHwkfCR8JHwkfCRVdHRVfCR8JHwkfCR8JHwkfCQpfCR9KD86JHwkfCg/Oig/Oio/OiR8JHwkfCR8JHwkfCR8JHwkJCl8JHwoPzokfCR8KD86KD86KD86JHwkfCQhJHwkfCR8JHwkfCR8JHwkfCR8JCl8JHwpfCR8JHwkfCQpfCkpJHx8JHwkfCR8JCcOcCllKnwpLykpfCl8KXwpfHx/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4806 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4145333935 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1aa48d810, 0x55d1aa67701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1aa677020,0x55d1ac50f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1946db8aceb40b6cf76cf677133c3bc8cbf09d45' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6051 processed earlier; will process 4978 files now Step #5: ==173092== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d1a0f829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1a75e7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1a75ca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1a75ca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1a0f88d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1a0ee9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1a0ee4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1a0f7ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1a3f49f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1a3f49f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1a3f49f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1a3f49f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1a3f49f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1a3f49f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1a3f49f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1a3f49f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1a3f49f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1a3f49f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1a61def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1a2f0bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1a2f16be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1a2cc2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1a2cc2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1a2cc3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1a2cc2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1a2cc2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1a2cc2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1a75ccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1a75d5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1a75bd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1a75e8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1198571082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1a0ee2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0xa,0x2b,0x2c,0xa,0x2b,0xa,0x2b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xf,0x31,0x11,0x2d,0x3a,0x24,0x5b,0x2d,0xf,0xf,0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x24,0x5b,0x2d,0xf,0xf,0xf,0x31,0x11,0x60,0xf,0x31,0x11,0x2d,0x3a,0x24,0x2a,0xf,0x0,0x31,0x0,0x0,0x0,0x0,0x0,0x0,0x11,0x60,0xf,0x31,0x24,0x5b,0x2d,0x3a,0x24,0x60,0x11,0x2d,0x3a,0x24,0x2a,0x24,0x0,0x0,0x5b,0x2d,0x3a,0x0,0x24,0x60, Step #5: +\012+,\012+\012+\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000$\000\000/\000\000\000/\000\017\017\017\017\0171\021\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0171\021-:$[-\017\017$\000\000/\000\000\000/\000\017\017\017\017\0171\021\0171\021-:$[-\017\017\0171\021`\0171\021-:$*\017\0001\000\000\000\000\000\000\021`\0171$[-:$`\021-:$*$\000\000[-:\000$` Step #5: artifact_prefix='./'; Test unit written to ./oom-231ed2a139385aac1b2448cf716d9dc4c05c1377 Step #5: Base64: KworLAorCisAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAkAAAvAAAALwAPDw8PDzERAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8xES06JFstDw8kAAAvAAAALwAPDw8PDzERDzERLTokWy0PDw8xEWAPMREtOiQqDwAxAAAAAAAAEWAPMSRbLTokYBEtOiQqJAAAWy06ACRg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4807 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4145983578 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564f9c400810, 0x564f9c5ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564f9c5ea020,0x564f9e4820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/231ed2a139385aac1b2448cf716d9dc4c05c1377' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6052 processed earlier; will process 4977 files now Step #5: #1 pulse cov: 3938 ft: 3939 exec/s: 0 rss: 177Mb Step #5: ==173128== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564f92ef59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f9955a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f9953d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f9953d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f92efbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f92e5cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f92e57355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f92eedc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f95ebcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f95ebcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f95ebcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f95ebcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f95ebcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f95ebcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f95ebcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f95ebcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f95ebcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f95ebcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f98151f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f94e7eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f94e89be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f94c35c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f94c35c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f94c36738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f94c35874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f94c35874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f94c35874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f9953fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f99548928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f99530699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f9955b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faee958e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f92e55b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x2d,0x2d,0x2d,0x45,0x47,0x49,0x4e,0x0,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x66,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0xd3,0xb8,0x45,0x47,0x49,0x4e,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0xa,0x2d,0x2d,0x2d,0x2d,0xd3,0xb8,0x45,0x47,0x49,0x4e,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x0,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0xd3,0xb8,0x45,0x47,0x49,0x4e,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0xa,0x2d,0x2d,0x2d,0x2d,0xd3,0xb8,0x45,0x47,0x49,0x4e,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x5,0x47,0x50,0x4e,0x4f,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20, Step #5: ---EGIN\000\012-----Bf----BEGI-BEGIN \012----\323\270EGIN \012-----BEGIN\012----\323\270EGIN \012-----BE---BEGIN --\012---BEGIN\000\012-----BEGI-BEGIN \012----\323\270EGIN \012-----BEGIN\012----\323\270EGIN \012-----BEGIN \012-----B\005GPNO\000-----BEGIN Step #5: artifact_prefix='./'; Test unit written to ./oom-219f84b046916c28d4562b1da594bfd04ea6f163 Step #5: Base64: IC0tLUVHSU4ACi0tLS0tQmYtLS0tQkVHSS1CRUdJTiAgCi0tLS3TuEVHSU4gCi0tLS0tQkVHSU4KLS0tLdO4RUdJTiAKLS0tLS1CRS0tLUJFR0lOIC0tCi0tLUJFR0lOAAotLS0tLUJFR0ktQkVHSU4gIAotLS0t07hFR0lOIAotLS0tLUJFR0lOCi0tLS3TuEVHSU4gCi0tLS0tQkVHSU4gCi0tLS0tQgVHUE5PAC0tLS0tQkVHSU4g Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4808 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4146547923 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec2d6c2810, 0x55ec2d8ac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec2d8ac020,0x55ec2f7440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/219f84b046916c28d4562b1da594bfd04ea6f163' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6054 processed earlier; will process 4975 files now Step #5: ==173164== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec241b79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec2a81c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec2a7ff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec2a7ff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec241bdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec2411eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec24119355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec241afc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec2717ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec2717ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec2717ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec2717ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec2717ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec2717ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec2717ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec2717ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec2717ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec2717ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec29413f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec26140b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec2614bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec25ef7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec25ef7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec25ef8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec25ef7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec25ef7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec25ef7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec2a801abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec2a80a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec2a7f2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec2a81d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f21c404d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec24117b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x3f,0x2a,0x20,0x20,0x28,0x7c,0x75,0x20,0xf3,0xa0,0x80,0xa5,0x41,0x20,0x3f,0x2a,0x20,0x20,0x28,0xca,0xb8,0x7c,0x75,0x20,0x41,0x7a,0x29,0x28,0x7c,0x75,0x20,0x41,0x7a,0x29,0x7a,0x29,0x28,0x7c,0x75,0x20,0x41,0x20,0x3f,0x2a,0x20,0x20,0x28,0x7c,0x75,0x20,0x41,0x7a,0x29,0x28,0x7c,0x75,0x20,0x41,0x7a,0x29,0x7a,0x29,0x28,0x7c,0x75,0x20,0x41,0x20,0x3f,0x2a,0x20,0x20,0x28,0x7c,0x75,0x20,0x41,0x7a,0x29,0x7a,0x29,0x7c,0x29,0x3e,0x3e,0x3e,0x29,0x29,0x29,0x20,0x3f,0x2a,0x20,0x20,0x28,0x7c,0x75,0x20,0xf3,0xa0,0x80,0xa5,0x41,0x20,0x3f,0x2a,0x75,0x20,0xf3,0xa0,0x80,0xa5,0x41,0x20,0x3f,0x2a,0x20,0x20,0x28,0x7c,0x75,0x20,0x41,0x7a,0x29,0x7a,0x29,0x7c,0x29,0x3e,0x3e,0x3e,0x29,0x29,0x29,0x20,0x3f,0x2a,0x20,0x20,0x28,0x7c,0x75,0x20,0xf3,0xa0,0x80,0xa5,0x41,0x20,0x3f,0x2a,0x75,0x20,0xf3,0xa0,0x80,0xa5,0x41,0x20,0x3f,0x2a,0x20,0x20,0x28,0xca,0xb8,0x7c,0x75,0x20,0x41,0x7a,0x29,0x28,0x7c,0x75,0x20,0x20,0x20,0x28,0x3e,0x3e,0x3e,0x29,0x28,0x29, Step #5: ?* (|u \363\240\200\245A ?* (\312\270|u Az)(|u Az)z)(|u A ?* (|u Az)(|u Az)z)(|u A ?* (|u Az)z)|)>>>))) ?* (|u \363\240\200\245A ?*u \363\240\200\245A ?* (|u Az)z)|)>>>))) ?* (|u \363\240\200\245A ?*u \363\240\200\245A ?* (\312\270|u Az)(|u (>>>)() Step #5: artifact_prefix='./'; Test unit written to ./oom-e5e2e5b0ed913124e16d15b47bac720c5b3be5db Step #5: Base64: ID8qICAofHUg86CApUEgPyogICjKuHx1IEF6KSh8dSBBeil6KSh8dSBBID8qICAofHUgQXopKHx1IEF6KXopKHx1IEEgPyogICh8dSBBeil6KXwpPj4+KSkpID8qICAofHUg86CApUEgPyp1IPOggKVBID8qICAofHUgQXopeil8KT4+PikpKSA/KiAgKHx1IPOggKVBID8qdSDzoIClQSA/KiAgKMq4fHUgQXopKHx1ICAgKD4+PikoKQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4809 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4147079714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb9603f810, 0x55eb9622901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb96229020,0x55eb980c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e5e2e5b0ed913124e16d15b47bac720c5b3be5db' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6055 processed earlier; will process 4974 files now Step #5: ==173200== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eb8cb349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb93199898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb9317c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb9317c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb8cb3ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb8ca9bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb8ca96355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb8cb2cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb8fafbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb8fafbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb8fafbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb8fafbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb8fafbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb8fafbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb8fafbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb8fafbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb8fafbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb8fafbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb91d90f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb8eabdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb8eac8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb8e874c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb8e874c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb8e875738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb8e874874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb8e874874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb8e874874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb9317eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb93187928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb9316f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb9319a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f52aef0a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb8ca94b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x3f,0xdb,0xa2,0xdb,0xa2,0x22,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0x35,0xdb,0xa2,0xdb,0xa2,0x22,0x22,0x0,0x3c, Step #5: \000?\333\242\333\242\"5555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555555\333\242\333\242\"\"\000< Step #5: artifact_prefix='./'; Test unit written to ./oom-b69d1798abd89432ab2a59c837cf314f7ca47d46 Step #5: Base64: AD/botuiIjU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTXbotuiIiIAPA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4810 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4147596835 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560affd7a810, 0x560afff6401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560afff64020,0x560b01dfc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b69d1798abd89432ab2a59c837cf314f7ca47d46' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6056 processed earlier; will process 4973 files now Step #5: ==173236== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560af686f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560afced4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560afceb75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560afceb74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560af6875d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560af67d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560af67d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560af6867c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560af9836f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560af9836f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560af9836f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560af9836f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560af9836f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560af9836f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560af9836f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560af9836f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560af9836f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560af9836f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560afbacbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560af87f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560af8803be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560af85afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560af85afc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560af85b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560af85af874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560af85af874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560af85af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560afceb9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560afcec2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560afceaa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560afced5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2dc7c6c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560af67cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2e,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3b,0x0,0xa,0x2d,0x63,0x72,0x79,0x73,0x74,0x61,0xa,0xd8,0x80,0x4,0x0,0x3b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x2d,0x20,0x0,0x0,0x4f,0x6c,0x31,0x2b,0x34,0x27,0x0,0x3a,0xd8,0x80,0x0,0xa,0xd8,0x80,0x4,0x0,0x3b,0x0,0xa,0x2d,0x20,0x0,0x0,0x4f,0x6c,0x31,0x2b,0x34,0x27,0x0,0x3a,0xd8,0x80,0x0,0xa,0xd8,0x80,0x4,0x0,0x3b,0x0,0xa,0x2d,0x20,0x0,0x0,0x4f,0x59,0x3e,0x2d,0x31,0x2b,0x34,0x27,0x0,0x3a,0xd8,0x80,0x0,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x37,0x4,0x2b,0x37,0x31,0x37,0x37,0x37,0x2e, Step #5: /.7777777777777\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000;\000\012-crysta\012\330\200\004\000;\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012- \000\000Ol1+4'\000:\330\200\000\012\330\200\004\000;\000\012- \000\000Ol1+4'\000:\330\200\000\012\330\200\004\000;\000\012- \000\000OY>-1+4'\000:\330\200\0007777777777777777777\004+71777. Step #5: artifact_prefix='./'; Test unit written to ./oom-f5018937fe219a0eea9b690334df359c7260c27d Step #5: Base64: Ly43Nzc3Nzc3Nzc3Nzc3AAAAAAAAAAAAAAAAAAAAOwAKLWNyeXN0YQrYgAQAOwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi0gAABPbDErNCcAOtiAAArYgAQAOwAKLSAAAE9sMSs0JwA62IAACtiABAA7AAotIAAAT1k+LTErNCcAOtiAADc3Nzc3Nzc3Nzc3Nzc3Nzc3NzcEKzcxNzc3Lg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4811 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4148127360 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af2edac810, 0x55af2ef9601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af2ef96020,0x55af30e2e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f5018937fe219a0eea9b690334df359c7260c27d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6057 processed earlier; will process 4972 files now Step #5: ==173272== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55af258a19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af2bf06898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af2bee95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af2bee94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55af258a7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55af25808b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55af25803355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55af25899c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55af28868f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55af28868f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55af28868f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55af28868f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55af28868f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55af28868f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55af28868f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55af28868f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55af28868f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55af28868f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af2aafdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af2782ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af27835be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af275e1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af275e1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af275e2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af275e1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af275e1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af275e1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af2beebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af2bef4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af2bedc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af2bf07112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f62c1c0d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55af25801b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x0,0x3d,0x0,0x4,0x0,0x31,0x1a,0x31,0x6c,0x69,0x67,0x68,0x74,0x24,0x3a,0x3a,0x3a,0x3a,0x3a,0x54,0x0,0x54,0x5b,0x31,0x31,0x54,0x5b,0x31,0x31,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3a,0x3a,0x3a,0x0,0x0,0x0,0x4,0x0,0x31,0x1a,0x3a,0x0,0x5d,0x2f,0x0,0x0,0x0,0x33,0x34,0x0,0x54,0x5b,0x31,0x31,0x0,0x0,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3a,0x3a,0x3a,0x0,0x0,0x0,0x4,0x0,0x31,0x1a,0x3a,0x0,0x5d,0x2f,0x0,0x0,0x0,0x33,0x34,0x0,0x54,0x5b,0x31,0x31,0x0,0x0,0x0,0x0,0x4,0x0,0x0,0x31,0x0,0x0,0x0,0x1,0x24,0x5b, Step #5: ID3\004\000=\000\004\0001\0321light$:::::T\000T[11T[11::::::::::::::::::=\012=\012=\012=\012=\012=\012=\012=?\012=\012=\012=\012=\012=\012:::\000\000\000\004\0001\032:\000]/\000\000\00034\000T[11\000\000::::::::::::::::::=\012=\012=\012=\012=\012=\012=\012=?\012=\012=\012=\012=\012=\012:::\000\000\000\004\0001\032:\000]/\000\000\00034\000T[11\000\000\000\000\004\000\0001\000\000\000\001$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-a638fca24716a29ba70a3d24e093ffa1997b2151 Step #5: Base64: SUQzBAA9AAQAMRoxbGlnaHQkOjo6OjpUAFRbMTFUWzExOjo6Ojo6Ojo6Ojo6Ojo6Ojo6PQo9Cj0KPQo9Cj0KPQo9Pwo9Cj0KPQo9Cj0KOjo6AAAABAAxGjoAXS8AAAAzNABUWzExAAA6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo9Cj0KPQo9Cj0KPQo9Cj0/Cj0KPQo9Cj0KPQo6OjoAAAAEADEaOgBdLwAAADM0AFRbMTEAAAAABAAAMQAAAAEkWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4812 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4148651539 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559eafd72810, 0x559eaff5c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559eaff5c020,0x559eb1df40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a638fca24716a29ba70a3d24e093ffa1997b2151' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6058 processed earlier; will process 4971 files now Step #5: ==173308== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559ea68679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559eacecc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559eaceaf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559eaceaf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ea686dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ea67ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ea67c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ea685fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ea982ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ea982ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ea982ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ea982ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ea982ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ea982ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ea982ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ea982ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ea982ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ea982ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559eabac3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559ea87f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559ea87fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559ea85a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559ea85a7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559ea85a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559ea85a7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559ea85a7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559ea85a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559eaceb1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559eaceba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559eacea2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559eacecd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc761f98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ea67c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0x3f,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x48,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x48,0x48,0x48,0x48,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=?=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012H\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012HHHH\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-db8f4808da865f88d4e9a7ff070e453ff49def46 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KCj0/PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KSAo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KSEhISAo9Cj0KPQo9Cj0KEA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4813 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4149192182 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560baab1b810, 0x560baad0501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560baad05020,0x560bacb9d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/db8f4808da865f88d4e9a7ff070e453ff49def46' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6059 processed earlier; will process 4970 files now Step #5: ==173344== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560ba16109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560ba7c75898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560ba7c585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560ba7c584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560ba1616d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560ba1577b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560ba1572355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560ba1608c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560ba45d7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560ba45d7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560ba45d7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560ba45d7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560ba45d7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560ba45d7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560ba45d7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560ba45d7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560ba45d7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560ba45d7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560ba686cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560ba3599b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560ba35a4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560ba3350c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560ba3350c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560ba3351738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560ba3350874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560ba3350874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560ba3350874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560ba7c5aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560ba7c63928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560ba7c4b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560ba7c76112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7effe978e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560ba1570b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x6c,0x20,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc,0xe1,0x84,0xbc, Step #5: <?l \341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274\341\204\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-ef553889140e527c1bd6979a79c9041fea0e8e03 Step #5: Base64: PD9sIOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOE/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz+EvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvOGEvA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4814 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4149708327 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e83d3f1810, 0x55e83d5db01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e83d5db020,0x55e83f4730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ef553889140e527c1bd6979a79c9041fea0e8e03' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6060 processed earlier; will process 4969 files now Step #5: ==173380== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e833ee69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e83a54b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e83a52e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e83a52e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e833eecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e833e4db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e833e48355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e833edec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e836eadf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e836eadf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e836eadf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e836eadf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e836eadf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e836eadf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e836eadf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e836eadf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e836eadf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e836eadf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e839142f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e835e6fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e835e7abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e835c26c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e835c26c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e835c27738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e835c26874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e835c26874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e835c26874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e83a530abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e83a539928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e83a521699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e83a54c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe9f3026082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e833e46b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x76,0x65,0x6e,0x74,0x73,0x20,0x7b,0xa,0x20,0x20,0x72,0x65,0x70,0x6c,0x79,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x74,0x6f,0x6b,0x65,0x6e,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x62,0x69,0x6e,0x61,0x72,0x79,0x5f,0x70,0x72,0x6f,0x70,0x65,0x72,0x74,0x69,0x65,0x73,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x5c,0x30,0x30,0x30,0x24,0x5c,0x30,0x30,0x30,0x5c,0x30,0x30,0x30,0x5c,0x30,0x30,0x30,0x5c,0x30,0x30,0x30,0x22,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x62,0x69,0x6e,0x61,0x72,0x79,0x5f,0x70,0x72,0x6f,0x70,0x65,0x72,0x74,0x69,0x65,0x73,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x5c,0x30,0x30,0x30,0x24,0x5c,0x30,0x30,0x30,0x5c,0x30,0x30,0x30,0x5c,0x30,0x30,0x30,0x5c,0x30,0x30,0x30,0x22,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x7d,0xa,0x7d,0xa, Step #5: events {\012 reply {\012 token {\012 binary_properties {\012 name: \"\\000$\\000\\000\\000\\000\"\012 }\012 binary_properties {\012 name: \"\\000$\\000\\000\\000\\000\"\012 }\012 }\012 }\012}\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-8be31301922693f25625c94edda2ea82fba2c754 Step #5: Base64: ZXZlbnRzIHsKICByZXBseSB7CiAgICB0b2tlbiB7CiAgICAgIGJpbmFyeV9wcm9wZXJ0aWVzIHsKICAgICAgICBuYW1lOiAiXDAwMCRcMDAwXDAwMFwwMDBcMDAwIgogICAgICB9CiAgICAgIGJpbmFyeV9wcm9wZXJ0aWVzIHsKICAgICAgICBuYW1lOiAiXDAwMCRcMDAwXDAwMFwwMDBcMDAwIgogICAgICB9CiAgICB9CiAgfQp9Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4815 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4150242706 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56344a8ab810, 0x56344aa9501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56344aa95020,0x56344c92d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8be31301922693f25625c94edda2ea82fba2c754' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6061 processed earlier; will process 4968 files now Step #5: ==173416== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5634413a09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563447a05898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634479e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634479e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5634413a6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563441307b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563441302355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563441398c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563444367f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563444367f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563444367f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563444367f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563444367f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563444367f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563444367f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563444367f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563444367f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563444367f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5634465fcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563443329b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563443334be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5634430e0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5634430e0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5634430e1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5634430e0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5634430e0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5634430e0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5634479eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5634479f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5634479db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563447a06112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3c41d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563441300b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0xa,0x9,0x72,0x6f,0x2f,0x2d,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0xa,0x9,0x72,0x6f,0x2f,0x2d,0xa,0x2d,0xa,0x9,0x72,0x6f,0x2f,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0x3d,0x8,0x2e,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0xa,0x9,0x72,0x6f,0x2f,0x2d,0xa,0x2d,0xa,0x9,0x72,0x6f,0x2f,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0x2d,0xa,0x9,0x72,0x6f,0x2f,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0x3d,0x8,0x2e,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0x5,0xa,0x9,0x72,0x6f,0x2f,0x2d,0xa,0x2d,0xa,0x9,0x72,0x6f,0x2f,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0x3d,0x8,0x2e, Step #5: -\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\005\012\011ro/-\005\005\005\005\005\005\005\005\005\005\012\011ro/-\012-\012\011ro/-\012-\012\012-\012-\012\012-\012=\010.\005\005\005\005\005\005\005\005\012\011ro/-\012-\012\011ro/-\012-\012\012-\012-\012\012-\012-\012\011ro/-\012-\012\012-\012-\012\012-\012=\010.\005\005\005\005\005\005\005\005\012\011ro/-\012-\012\011ro/-\012-\012\012-\012-\012\012-\012=\010. Step #5: artifact_prefix='./'; Test unit written to ./oom-5500fc11cd616679ad4c0ab3437274d19ed11055 Step #5: Base64: LQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUKCXJvLy0FBQUFBQUFBQUFCglyby8tCi0KCXJvLy0KLQoKLQotCgotCj0ILgUFBQUFBQUFCglyby8tCi0KCXJvLy0KLQoKLQotCgotCi0KCXJvLy0KLQoKLQotCgotCj0ILgUFBQUFBQUFCglyby8tCi0KCXJvLy0KLQoKLQotCgotCj0ILg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4816 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4150802092 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610bf296810, 0x5610bf48001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610bf480020,0x5610c13180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5500fc11cd616679ad4c0ab3437274d19ed11055' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6062 processed earlier; will process 4967 files now Step #5: ==173452== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5610b5d8b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610bc3f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610bc3d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610bc3d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610b5d91d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610b5cf2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610b5ced355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610b5d83c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610b8d52f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610b8d52f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610b8d52f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610b8d52f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610b8d52f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610b8d52f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610b8d52f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610b8d52f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610b8d52f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610b8d52f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610bafe7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610b7d14b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610b7d1fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610b7acbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610b7acbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610b7acc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610b7acb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610b7acb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610b7acb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610bc3d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610bc3de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610bc3c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610bc3f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5070c73082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610b5cebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x76,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x74,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x36,0x2,0x6b,0x6,0x65,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x33,0x2,0x6b,0x6,0x65,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: \005--\000\000\000\000\000\000\000\000\000\000\012=\012=\012\000\000\000\000\000\000\000\000\000\000\000\000\000=tttttttttttttttttttttttttttttvtttttttttttttttttttttttttttttttttttttttttttttttttttt........6\002k\006e\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0003\002k\006e\000\000\000\000\000\000\000\000\000\000\012=\012=\012\000\000\000\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ee4b3b9c6dbc2244ee108cc098469f51621bfe5b Step #5: Base64: BS0tAAAAAAAAAAAAAAo9Cj0KAAAAAAAAAAAAAAAAAD10dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHZ0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0Li4uLi4uLi42AmsGZQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADMCawZlAAAAAAAAAAAAAAo9Cj0KAAAAAAAAAAAAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4817 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4151328896 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eca832e810, 0x55eca851801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eca8518020,0x55ecaa3b00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee4b3b9c6dbc2244ee108cc098469f51621bfe5b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6063 processed earlier; will process 4966 files now Step #5: ==173488== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec9ee239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eca5488898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eca546b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eca546b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec9ee29d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec9ed8ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec9ed85355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec9ee1bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eca1deaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eca1deaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eca1deaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eca1deaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eca1deaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eca1deaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eca1deaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eca1deaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eca1deaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eca1deaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eca407ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eca0dacb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eca0db7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eca0b63c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eca0b63c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eca0b64738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eca0b63874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eca0b63874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eca0b63874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eca546dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eca5476928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eca545e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eca5489112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f847ac06082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec9ed83b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x7b,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0x20,0x20,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0xb,0x61,0x6d,0x65,0x3a,0x20,0x22,0x74,0x22,0x6e,0x61,0x6d,0x65,0x3a,0xd,0x22,0x44,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x27,0x27,0x20,0x20,0x20,0x20,0x5c,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x26,0x25,0xb8,0x70,0x3a,0x20,0x20,0x20,0x20,0x20,0xc,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x33,0x30,0x39,0x35,0x39,0x30,0x39,0x30,0x38,0x38,0x37,0x38,0x30,0x33,0x39,0x35,0x35,0x33,0x31,0x20,0x5c,0x27,0x20,0x20,0x20,0x3e,0x20,0x5c,0x30,0x30,0x30,0x5c,0x72,0x20,0x20,0x3c,0x42,0x20,0x3e,0x22,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x76,0x61,0x6c,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x22,0x20,0x9,0x20,0x7d,0x20,0x7d,0xa,0x20,0x20,0x7d,0x20,0x7d,0xa,0x7d,0x7d, Step #5: p{doctype {\012mdecl { entity {\013ame: \"t\"name:\015\"D PUBLIC '' \\'http://&%\270p: \014 3095909088780395531 \\' > \\000\\r <B >\"ent {\012 val { name: \"D\" \011 } }\012 } }\012}} Step #5: artifact_prefix='./'; Test unit written to ./oom-27bd492f3db768d5121bd2e60dcd7160438b3b66 Step #5: Base64: cHtkb2N0eXBlIHsKbWRlY2wgeyAgZW50aXR5IHsLYW1lOiAidCJuYW1lOg0iRCBQVUJMSUMgJycgICAgXCdodHRwOi8vJiW4cDogICAgIAwgICAgICAgICAgICAgICAgICAgICAgICAgICAgIDMwOTU5MDkwODg3ODAzOTU1MzEgXCcgICA+IFwwMDBcciAgPEIgPiJlbnQgewogIHZhbCB7IG5hbWU6ICJEIiAJIH0gfQogIH0gfQp9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4818 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4151846279 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b89f62810, 0x561b8a14c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b8a14c020,0x561b8bfe40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/27bd492f3db768d5121bd2e60dcd7160438b3b66' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6064 processed earlier; will process 4965 files now Step #5: ==173524== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561b80a579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b870bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b8709f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b8709f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b80a5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b809beb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b809b9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b80a4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b83a1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b83a1ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b83a1ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b83a1ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b83a1ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b83a1ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b83a1ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b83a1ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b83a1ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b83a1ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b85cb3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b829e0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b829ebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b82797c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b82797c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b82798738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b82797874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b82797874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b82797874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b870a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b870aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b87092699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b870bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb3ded19082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b809b7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x32,0x27,0x27,0x32,0xd,0x3d,0x27,0x27,0x31,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x28,0x3f,0x3a,0x28,0x3f,0x10,0x0,0x24,0x7c,0x7c,0x2f,0x75,0x75,0x75,0x49,0x44,0xf3,0xa0,0x81,0xb0,0x33,0x4,0x2,0x3f,0x54,0x2d,0x35,0x36,0x30,0x33,0x32,0x38,0x37,0x31,0x39,0x34,0x34,0x33,0x33,0x36,0x30,0x36,0x35,0x32,0x43,0x48,0x0,0x43,0x6d,0x65,0x49,0x44,0x33,0x4,0x10,0x75,0x75,0x75,0x75,0x75,0x75,0x77,0x75,0x6d,0x49,0x44,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x33,0x37,0xe2,0x81,0x9f,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x37,0xe2,0x80,0xab,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x7c, Step #5: $2''2\015=''1'''''''''(?:(?\020\000$||/uuuID\363\240\201\2603\004\002?T-560328719443360652CH\000CmeID3\004\020uuuuuuwumID340282366CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC37\342\201\2374607431768211457\342\200\253922337203685477| Step #5: artifact_prefix='./'; Test unit written to ./oom-c1d8ce9ebacd15cda8835667b5b6df410fead9d8 Step #5: Base64: JDInJzINPScnMScnJycnJycnJyg/Oig/EAAkfHwvdXV1SUTzoIGwMwQCP1QtNTYwMzI4NzE5NDQzMzYwNjUyQ0gAQ21lSUQzBBB1dXV1dXV3dW1JRDM0MDI4MjM2NkNDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDMzfigZ80NjA3NDMxNzY4MjExNDU34oCrOTIyMzM3MjAzNjg1NDc3fA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4819 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4152372944 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e928558810, 0x55e92874201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e928742020,0x55e92a5da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c1d8ce9ebacd15cda8835667b5b6df410fead9d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6065 processed earlier; will process 4964 files now Step #5: ==173560== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e91f04d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9256b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9256955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9256954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e91f053d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e91efb4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e91efaf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e91f045c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e922014f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e922014f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e922014f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e922014f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e922014f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e922014f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e922014f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e922014f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e922014f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e922014f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9242a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e920fd6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e920fe1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e920d8dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e920d8dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e920d8e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e920d8d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e920d8d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e920d8d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e925697abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9256a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e925688699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e9256b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3876c25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e91efadb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0xa0,0x8e,0x3d,0x20,0x7f,0x7f,0x20,0x0,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa8,0x8e,0x3d,0x20,0x7f,0x7f,0x7f,0x20,0x0,0x28,0xe2,0x80,0xac,0x0,0xe1,0xa8,0x8e,0x3d,0x20,0x7f,0x7f,0xe2,0x80,0x8d,0x0,0x0,0x28,0xe2,0x80,0xae,0x0,0x72,0x2b,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x21,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x73,0x20,0x5b,0x38,0x20,0x30,0x31,0x32,0x31,0x31,0x38,0x32,0x33,0x30,0x38,0x32,0x32,0x34,0x30,0x30,0x30,0x35,0x38,0x37,0x2,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x20,0x3d,0x1d,0x0,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0x23,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80,0xae,0x80, Step #5: \341\240\216= \177\177 \000(\342\200\254\000\341\250\216= \177\177\177 \000(\342\200\254\000\341\250\216= \177\177\342\200\215\000\000(\342\200\256\000r+\002-\001\000\000\000\000ID3\002-!\000\000\000\000ID3\002-\001s [8 0121182308224000587\002---BEGIN-----\012 =\035\000\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200\256\200#\256\200\256\200\256\200\256\200\256\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-858d6cf7b337b4aad0182ce2ab3a26b9fe3a068f Step #5: Base64: 4aCOPSB/fyAAKOKArADhqI49IH9/fyAAKOKArADhqI49IH9/4oCNAAAo4oCuAHIrAi0BAAAAAElEMwItIQAAAABJRDMCLQFzIFs4IDAxMjExODIzMDgyMjQwMDA1ODcCLS0tQkVHSU4tLS0tLQogPR0AroCugK6AroCugK6AroCugK6AroCugK6AroCugK6AroCugK6AroCugK6AroCugK6AroCugK6AroCugK6AroAjroCugK6AroCugA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4820 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4152895705 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb4080e810, 0x55bb409f801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb409f8020,0x55bb428900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/858d6cf7b337b4aad0182ce2ab3a26b9fe3a068f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6066 processed earlier; will process 4963 files now Step #5: ==173596== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bb373039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb3d968898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb3d94b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb3d94b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb37309d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb3726ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb37265355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb372fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb3a2caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb3a2caf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb3a2caf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb3a2caf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb3a2caf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb3a2caf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb3a2caf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb3a2caf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb3a2caf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb3a2caf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb3c55ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb3928cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb39297be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb39043c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb39043c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb39044738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb39043874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb39043874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb39043874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb3d94dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb3d956928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb3d93e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb3d969112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f426b7e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb37263b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0x21,0x20,0x54,0x68,0x69,0x6e,0x73,0x2e,0xa,0xa,0x73,0x70,0x6c,0x69,0x74,0x28,0x22,0x68,0x0,0x0,0x0,0x0,0x65,0x0,0x40,0x0,0x65,0x0,0x40,0x0,0x65,0x0,0x40,0x0,0x0,0x0,0xcd,0x8f,0x0,0x65,0x0,0x40,0x0,0x0,0x0,0xcd,0x8f,0x0,0x0,0x0,0x1d,0x0,0x0,0x0,0x0,0x0,0x40,0x0,0x0,0x40,0x0,0x0,0x0,0xcd,0x8f,0x0,0x0,0x0,0x1d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6c,0x6c,0x6f,0x22,0x29,0x3b,0xa,0xff,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x65,0x0,0x40,0x0,0x65,0x0,0x40,0x0,0x0,0x0,0xcd,0x8f,0x0,0x65,0x0,0x40,0x0,0x0,0x0,0xcd,0x8f,0x0,0x0,0x0,0x1d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6c,0x6c,0x6f,0x22,0x29,0x3b,0xa,0xff,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x51,0x51,0x70,0x71,0x51,0x51,0x51,0x51,0x7a, Step #5: //! Thins.\012\012split(\"h\000\000\000\000e\000@\000e\000@\000e\000@\000\000\000\315\217\000e\000@\000\000\000\315\217\000\000\000\035\000\000\000\000\000@\000\000@\000\000\000\315\217\000\000\000\035\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000llo\");\012\377\000\000\000\000\000\000\000\000\000\000\000\000\000e\000@\000e\000@\000\000\000\315\217\000e\000@\000\000\000\315\217\000\000\000\035\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000llo\");\012\377\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000QQpqQQQQz Step #5: artifact_prefix='./'; Test unit written to ./oom-d755ac86b9443c8c5d017fe92d6c7114a42cbdc8 Step #5: Base64: Ly8hIFRoaW5zLgoKc3BsaXQoImgAAAAAZQBAAGUAQABlAEAAAADNjwBlAEAAAADNjwAAAB0AAAAAAEAAAEAAAADNjwAAAB0AAAAAAAAAAAAAAAAAAAAAAABsbG8iKTsK/wAAAAAAAAAAAAAAAABlAEAAZQBAAAAAzY8AZQBAAAAAzY8AAAAdAAAAAAAAAAAAAAAAAAAAAAAAbGxvIik7Cv8AAAAAAAAAAAAAAAAAAAAAAFFRcHFRUVFReg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4821 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4153406533 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5561508ff810, 0x556150ae901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556150ae9020,0x5561529810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d755ac86b9443c8c5d017fe92d6c7114a42cbdc8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6067 processed earlier; will process 4962 files now Step #5: #1 pulse cov: 3821 ft: 3822 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4100 ft: 4657 exec/s: 0 rss: 176Mb Step #5: ==173632== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5561473f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55614da59898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55614da3c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55614da3c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5561473fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55614735bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556147356355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5561473ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55614a3bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55614a3bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55614a3bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55614a3bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55614a3bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55614a3bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55614a3bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55614a3bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55614a3bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55614a3bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55614c650f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55614937db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556149388be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556149134c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556149134c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556149135738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556149134874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556149134874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556149134874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55614da3eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55614da47928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55614da2f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55614da5a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e0589c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556147354b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x45,0x3a,0x5a,0x3e,0x65,0x6e,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x58,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x46,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x6e,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3a,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x4a,0x3e,0x3c,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3a,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x3c,0x44,0x3a,0x5a,0x3e,0x65,0x2d,0x77,0x65,0x6e,0x5a,0x3e, Step #5: <E:Z>enZ><D:Z><D:Z><D:Z><D:X><D:Z><F:Z><D:Z>nZ><D:Z>::Z><D:Z><D:Z><D:Z><D:Z><D:Z><D:J><:Z><D:Z><D:Z><D:Z><D:Z><D:Z><D:Z><D:Z><D:Z>Z><D:Z>::Z><D:Z><D:Z><D:Z><D:Z><D:Z><D:Z><D:Z><D:Z>e-wenZ> Step #5: artifact_prefix='./'; Test unit written to ./oom-b4dbb753bfa71f101d430cc4c3d0cb981619819b Step #5: Base64: PEU6Wj5lblo+PEQ6Wj48RDpaPjxEOlo+PEQ6WD48RDpaPjxGOlo+PEQ6Wj5uWj48RDpaPjo6Wj48RDpaPjxEOlo+PEQ6Wj48RDpaPjxEOlo+PEQ6Sj48Olo+PEQ6Wj48RDpaPjxEOlo+PEQ6Wj48RDpaPjxEOlo+PEQ6Wj48RDpaPlo+PEQ6Wj46Olo+PEQ6Wj48RDpaPjxEOlo+PEQ6Wj48RDpaPjxEOlo+PEQ6Wj48RDpaPmUtd2VuWj4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4822 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4153998930 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5601bf0f0810, 0x5601bf2da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5601bf2da020,0x5601c11720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b4dbb753bfa71f101d430cc4c3d0cb981619819b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6070 processed earlier; will process 4959 files now Step #5: #1 pulse cov: 11234 ft: 11235 exec/s: 0 rss: 195Mb Step #5: ==173668== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5601b5be59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601bc24a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601bc22d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601bc22d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5601b5bebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601b5b4cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601b5b47355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5601b5bddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601b8bacf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601b8bacf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601b8bacf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601b8bacf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601b8bacf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601b8bacf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601b8bacf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601b8bacf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601b8bacf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601b8bacf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5601bae41f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601b7b6eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601b7b79be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5601b7925c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5601b7925c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5601b7926738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5601b7925874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5601b7925874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5601b7925874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5601bc22fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5601bc238928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5601bc220699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601bc24b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2749bf4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601b5b45b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0xe0,0xbf,0xad,0x2b,0x56,0xa,0x56,0xa,0x2b,0xe2,0x80,0xad,0x63,0xa,0x2b,0xa,0xa,0x2b,0xa,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0xe0,0xbf,0xad,0x2b,0x56,0xa,0x56,0xa,0x2b,0xe2,0x80,0xad,0x63,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0xe2,0x80,0xad,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0xa,0xa,0x2b,0xa,0x2b,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0xe2,0x80,0xad,0x63,0xa,0xf3,0xa0,0x81,0xb4,0x2b,0xa,0x2b,0x56,0xa,0x56,0xa,0x2b,0x56,0xa,0x56,0xa,0x1,0x0,0x2b,0xe2,0x80,0xad,0x63,0xa,0xa,0x2b, Step #5: c\012+\012\012+\012+c\012\363\240\201\264+\012+V\012V\012\340\277\255+V\012V\012+\342\200\255c\012+\012\012+\012c\012\363\240\201\264+\012+V\012V\012\340\277\255+V\012V\012+\342\200\255c\012+\012\012+\012+c\012\363\240\201\264+\012+V\012V\012+\012\012+\012+c\012\363\240\201\264+\012+V\012V\012+\342\200\255c\012\363\240\201\264+\012+V\012V\012++c\012\363\240\201\264+\012+V\012V\012+\012\012+\012+c\012\363\240\201\264+\012+V\012V\012+\342\200\255c\012\363\240\201\264+\012+V\012V\012+V\012V\012\001\000+\342\200\255c\012\012+ Step #5: artifact_prefix='./'; Test unit written to ./oom-5e1b54e3bfbcea001bcb372b7be6c941c4407a5d Step #5: Base64: YworCgorCitjCvOggbQrCitWClYK4L+tK1YKVgor4oCtYworCgorCmMK86CBtCsKK1YKVgrgv60rVgpWCivigK1jCisKCisKK2MK86CBtCsKK1YKVgorCgorCitjCvOggbQrCitWClYKK+KArWMK86CBtCsKK1YKVgorK2MK86CBtCsKK1YKVgorCgorCitjCvOggbQrCitWClYKK+KArWMK86CBtCsKK1YKVgorVgpWCgEAK+KArWMKCis= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4823 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4154595842 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5653a0720810, 0x5653a090a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5653a090a020,0x5653a27a20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e1b54e3bfbcea001bcb372b7be6c941c4407a5d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6072 processed earlier; will process 4957 files now Step #5: ==173704== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5653972159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56539d87a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56539d85d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56539d85d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56539721bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56539717cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565397177355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56539720dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56539a1dcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56539a1dcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56539a1dcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56539a1dcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56539a1dcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56539a1dcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56539a1dcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56539a1dcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56539a1dcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56539a1dcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56539c471f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56539919eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5653991a9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565398f55c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565398f55c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565398f56738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565398f55874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565398f55874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565398f55874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56539d85fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56539d868928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56539d850699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56539d87b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3106f5d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565397175b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x49,0x49,0x55,0x49,0x49,0x49,0x49,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x37,0x30,0x37,0x32,0x36,0x33,0x32,0x32,0x38,0x32,0x33,0x35,0x33,0x36,0x30,0x37,0x37,0x33,0x66,0x66,0x2d,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x46,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x66,0x0,0x2d,0x66,0x66,0x66,0x66,0x49,0x49,0x49,0x49,0x49,0x2d,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x49,0x34,0x34,0x49,0x49,0x3d,0x3d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: s-----BEGIN -----\012IIUIIIIfffffffffffff444444444444444LLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLL707263228235360773ff-ffffffffffffffffFfffffffffffffffff\000-ffffIIIII-IIIIIIIIIII44II==\012-----END ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-e0f2eaf7beecf5fc55fa15ff1c9319224890cf9a Step #5: Base64: cy0tLS0tQkVHSU4gLS0tLS0KSUlVSUlJSWZmZmZmZmZmZmZmZmY0NDQ0NDQ0NDQ0NDQ0NDRMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTExMTEw3MDcyNjMyMjgyMzUzNjA3NzNmZi1mZmZmZmZmZmZmZmZmZmZmRmZmZmZmZmZmZmZmZmZmZmZmAC1mZmZmSUlJSUktSUlJSUlJSUlJSUk0NElJPT0KLS0tLS1FTkQgLS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4824 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4155118755 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559501c85810, 0x559501e6f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559501e6f020,0x559503d070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e0f2eaf7beecf5fc55fa15ff1c9319224890cf9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6073 processed earlier; will process 4956 files now Step #5: ==173740== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5594f877a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5594feddf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5594fedc25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5594fedc24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5594f8780d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5594f86e1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5594f86dc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5594f8772c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5594fb741f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5594fb741f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5594fb741f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5594fb741f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5594fb741f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5594fb741f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5594fb741f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5594fb741f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5594fb741f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5594fb741f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5594fd9d6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5594fa703b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5594fa70ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5594fa4bac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5594fa4bac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5594fa4bb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5594fa4ba874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5594fa4ba874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5594fa4ba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5594fedc4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5594fedcd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5594fedb5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5594fede0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f22dde1d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5594f86dab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x6f,0x75,0x75,0x1,0x0,0x73,0x74,0x72,0x65,0x61,0x6d,0x75,0x75,0x75,0x75,0x75,0x75,0xe2,0x81,0x9f,0x75,0x75,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x75,0x6f,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0xe2,0x81,0x9f,0x75,0x75,0x75,0x6f,0x75,0x75,0x75,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x3f,0x75,0x75,0xd4,0x75,0x75,0xe2,0x81,0x9f,0x75,0x75,0x75,0xf3,0xa0,0x81,0xbf,0x75,0x75,0xe2,0x80,0x81,0x75,0x75,0x75,0x73,0x74,0x21, Step #5: pouu\001\000streamuuuuuu\342\201\237uu\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000uouuuuuuuu\342\201\237uuuouuu??????????????????????????????????????????????????????????????????????????????????????????????????uu\324uu\342\201\237uuu\363\240\201\277uu\342\200\201uuust! Step #5: artifact_prefix='./'; Test unit written to ./oom-82a01b37e19e2816e35d3e0f15007c5bf12f2c05 Step #5: Base64: cG91dQEAc3RyZWFtdXV1dXV14oGfdXUAAAAAAAAAAAAAAAAAAAAAAAAAAAB1b3V1dXV1dXV14oGfdXV1b3V1dT8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/Pz8/dXXUdXXigZ91dXXzoIG/dXXigIF1dXVzdCE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4825 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4155641100 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e57a7a9810, 0x55e57a99301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e57a993020,0x55e57c82b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/82a01b37e19e2816e35d3e0f15007c5bf12f2c05' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6074 processed earlier; will process 4955 files now Step #5: ==173776== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e57129e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e577903898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e5778e65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e5778e64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e5712a4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e571205b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e571200355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e571296c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e574265f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e574265f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e574265f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e574265f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e574265f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e574265f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e574265f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e574265f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e574265f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e574265f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e5764faf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e573227b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e573232be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e572fdec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e572fdec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e572fdf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e572fde874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e572fde874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e572fde874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e5778e8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e5778f1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e5778d9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e577904112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12dd8ea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e5711feb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x44,0x33,0x4,0x27,0x0,0x0,0x61,0x27,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x61,0x27,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x3a,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x3a,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x17,0x54,0x59,0x33,0x45,0x4,0x27,0x0,0x0,0x60,0x27,0x4,0x0,0x61,0x27,0x17,0x54,0x59,0x33,0x45,0x4,0x27,0x0,0x0,0x60,0x21,0x17,0x54,0x59,0x15,0x10,0x0,0x45,0x15,0x0,0x10, Step #5: ID3\004D3\004'\000\000a'{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{a'{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{:{{{{{{{{{{{{{{{{{{{{{{:{{{{{{{\027TY3E\004'\000\000`'\004\000a'\027TY3E\004'\000\000`!\027TY\025\020\000E\025\000\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-0f1e97f433e8ab2d6290fc8bc5e06a0a99b0e407 Step #5: Base64: SUQzBEQzBCcAAGEne3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3thJ3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7ezp7e3t7e3t7e3t7e3t7e3t7e3t7e3t7Ont7e3t7e3sXVFkzRQQnAABgJwQAYScXVFkzRQQnAABgIRdUWRUQAEUVABA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4826 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4156285158 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b742ea810, 0x555b744d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b744d4020,0x555b7636c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0f1e97f433e8ab2d6290fc8bc5e06a0a99b0e407' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6075 processed earlier; will process 4954 files now Step #5: ==173812== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555b6addf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b71444898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b714275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b714274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b6ade5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b6ad46b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b6ad41355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b6add7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b6dda6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b6dda6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b6dda6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b6dda6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b6dda6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b6dda6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b6dda6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b6dda6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b6dda6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b6dda6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b7003bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b6cd68b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b6cd73be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b6cb1fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b6cb1fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b6cb20738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b6cb1f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b6cb1f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b6cb1f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b71429abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b71432928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b7141a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b71445112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf22d9e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b6ad3fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x48,0x48,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x48,0x48,0x48,0x48,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x65,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEG\012=\012=\012=\012=\012=\012=\012=\012=?=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=HH\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=?=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012HHHH\012=\012=\012=\012e=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-b52126e72aedd5c44d8709c1f1b4e3c97d586ef2 Step #5: Base64: BS0tLS0tQkVHCj0KPQo9Cj0KPQo9Cj0KPT89Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPUhICj0KPQo9Cj0KPQo9Cj0KPQo9Cj0/PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KSEhISAo9Cj0KPQplPQo9ChA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4827 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4156820405 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557e80f07810, 0x557e810f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557e810f1020,0x557e82f890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b52126e72aedd5c44d8709c1f1b4e3c97d586ef2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6076 processed earlier; will process 4953 files now Step #5: ==173848== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557e779fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557e7e061898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557e7e0445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557e7e0444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557e77a02d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557e77963b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557e7795e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557e779f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557e7a9c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557e7a9c3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557e7a9c3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557e7a9c3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557e7a9c3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557e7a9c3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557e7a9c3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557e7a9c3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557e7a9c3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557e7a9c3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557e7cc58f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557e79985b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557e79990be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557e7973cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557e7973cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557e7973d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557e7973c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557e7973c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557e7973c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557e7e046abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557e7e04f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557e7e037699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557e7e062112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f876be70082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557e7795cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x3e,0x0,0x41,0x38,0x60,0x5b,0x2e,0x2e,0x38,0x36,0x34,0x32,0x30,0x30,0x30,0x31,0x31,0x5d,0x2d,0x60,0x33,0xef,0xbf,0xbf,0x1,0x0,0x75,0x2,0x63,0x1e,0xd9,0x80,0xdd,0xa4,0x60,0x5b,0x21,0x30,0x2d,0x33,0x5d,0x2d,0x60,0xe0,0xbf,0xbf,0xd5,0xad,0x21,0x60,0x5b,0x30,0x26,0x33,0x5d,0x2d,0x60,0xe0,0xbf,0xbf,0xd5,0xad,0x21,0x60,0x5b,0x31,0x26,0x31,0x32,0x35,0x5d,0x2d,0x60,0x7a,0x2d,0xef,0xbf,0xbf,0x1,0x0,0x75,0x2,0x63,0x1e,0xd9,0x80,0xdd,0xa4,0x60,0x5b,0x21,0x30,0x2d,0x33,0x5d,0x2d,0x60,0xe0,0xbf,0xbf,0xd5,0xad,0x21,0x60,0x5b,0x30,0x26,0x31,0x32,0x35,0x5d,0x2d,0x60,0x7a,0x2d,0xef,0xbf,0xbf,0xd5,0xa4,0x21,0x2,0x0,0x0,0x0,0x60,0x5b,0x36,0x2d,0x33,0x5d,0xa4,0xef,0x26,0xfe,0x90,0x74,0x28,0x78,0x29,0x3b,0xa,0xa,0x28,0x70,0x74,0x69,0xa,0x6e,0x72,0x2d,0x32,0x31,0x29,0x3b,0x8a,0xa,0x70,0x72,0x69,0x6e,0x74,0x28,0x78,0x29,0x3b,0xa,0xa,0x6c,0x65,0x74,0x20,0x78,0x20,0x3d,0xa,0xa,0x6e,0xa,0x70,0x72,0x3c,0x92,0x0,0xc0,0x99,0xba, Step #5: `>\000A8`[..864200011]-`3\357\277\277\001\000u\002c\036\331\200\335\244`[!0-3]-`\340\277\277\325\255!`[0&3]-`\340\277\277\325\255!`[1&125]-`z-\357\277\277\001\000u\002c\036\331\200\335\244`[!0-3]-`\340\277\277\325\255!`[0&125]-`z-\357\277\277\325\244!\002\000\000\000`[6-3]\244\357&\376\220t(x);\012\012(pti\012nr-21);\212\012print(x);\012\012let x =\012\012n\012pr<\222\000\300\231\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-8196d064f837e909acd484712e29ad32539c2e14 Step #5: Base64: YD4AQThgWy4uODY0MjAwMDExXS1gM++/vwEAdQJjHtmA3aRgWyEwLTNdLWDgv7/VrSFgWzAmM10tYOC/v9WtIWBbMSYxMjVdLWB6Le+/vwEAdQJjHtmA3aRgWyEwLTNdLWDgv7/VrSFgWzAmMTI1XS1gei3vv7/VpCECAAAAYFs2LTNdpO8m/pB0KHgpOwoKKHB0aQpuci0yMSk7igpwcmludCh4KTsKCmxldCB4ID0KCm4KcHI8kgDAmbo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4828 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4157463219 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f75fefd810, 0x55f7600e701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7600e7020,0x55f761f7f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8196d064f837e909acd484712e29ad32539c2e14' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6077 processed earlier; will process 4952 files now Step #5: #1 pulse cov: 4250 ft: 4251 exec/s: 0 rss: 175Mb Step #5: ==173884== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f7569f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f75d057898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f75d03a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f75d03a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f7569f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f756959b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f756954355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f7569eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7599b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7599b9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7599b9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7599b9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7599b9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7599b9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7599b9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7599b9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7599b9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7599b9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f75bc4ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f75897bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f758986be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f758732c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f758732c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f758733738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f758732874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f758732874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f758732874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f75d03cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f75d045928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f75d02d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f75d058112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fede2c6f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f756952b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0xd,0x50,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0x9,0x27,0x27,0xa,0x67,0xd,0x28,0xe0,0xbe,0xb2,0x29,0xbe,0xb2,0x29,0x9,0x29, Step #5: <!ATTLIST\015P\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\011''\012g\015(\340\276\262)\276\262)\011) Step #5: artifact_prefix='./'; Test unit written to ./oom-bc3d22f6d82a96be21a23d46401588d8befee185 Step #5: Base64: PCFBVFRMSVNUDVAKZw0o4L6yKQknJwpnDSjgvrIpCScnCmcNKOC+sikJJycKZw0o4L6yKQknJwpnDSjgvrIpCScnCmcNKOC+sikJJycKZw0o4L6yKQknJwpnDSjgvrIpCScnCmcNKOC+sikJJycKZw0o4L6yKQknJwpnDSjgvrIpCScnCmcNKOC+sikJJycKZw0o4L6yKQknJwpnDSjgvrIpCScnCmcNKOC+sikJJycKZw0o4L6yKb6yKQkp Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4829 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4158032656 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d745258810, 0x55d74544201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d745442020,0x55d7472da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bc3d22f6d82a96be21a23d46401588d8befee185' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6079 processed earlier; will process 4950 files now Step #5: ==173920== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d73bd4d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d7423b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7423955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7423954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d73bd53d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d73bcb4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d73bcaf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d73bd45c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d73ed14f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d73ed14f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d73ed14f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d73ed14f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d73ed14f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d73ed14f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d73ed14f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d73ed14f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d73ed14f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d73ed14f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d740fa9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d73dcd6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d73dce1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d73da8dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d73da8dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d73da8e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d73da8d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d73da8d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d73da8d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d742397abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d7423a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d742388699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d7423b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffbd01cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d73bcadb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x88,0x88,0x2d,0x0,0x64,0x6f,0x6c,0x70,0x68,0x69,0x6e,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x73,0x65,0x46,0x6f,0x6e,0x74,0x2f,0x60,0xa,0x20,0x20,0x60,0xe2,0x88,0x88,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0xb,0x0,0x60,0xa,0xa,0x32,0x2f,0x60,0xa,0x20,0x20,0x67,0x20,0x60,0xa,0x9,0x60,0x20,0x60,0x60,0xa,0x9, Step #5: `\342\210\210-\000dolphin\012`\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000\000\000\000\000\000seFont/`\012 `\342\210\210\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000-\000`\012\363\240\201\272/\012`\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000\000\000\000\000\000\013\000`\012\0122/`\012 g `\012\011` ``\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-b49c0015472e5a5b6308fb98ffd066b36930406e Step #5: Base64: YOKIiC0AZG9scGhpbgpg4oCILQBgCvOggbrzoIG6LwEAAAAAAABzZUZvbnQvYAogIGDiiIgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAC0AYArzoIG6Lwpg4oCILQBgCvOggbrzoIG6LwEAAAAAAAALAGAKCjIvYAogIGcgYAoJYCBgYAoJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4830 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4158672746 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e5a8156810, 0x55e5a834001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e5a8340020,0x55e5aa1d80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b49c0015472e5a5b6308fb98ffd066b36930406e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6080 processed earlier; will process 4949 files now Step #5: ==173956== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e59ec4b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e5a52b0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e5a52935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e5a52934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e59ec51d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e59ebb2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e59ebad355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e59ec43c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e5a1c12f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e5a1c12f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e5a1c12f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e5a1c12f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e5a1c12f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e5a1c12f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e5a1c12f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e5a1c12f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e5a1c12f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e5a1c12f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e5a3ea7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e5a0bd4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e5a0bdfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e5a098bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e5a098bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e5a098c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e5a098b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e5a098b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e5a098b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e5a5295abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e5a529e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e5a5286699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e5a52b1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb3a3ca9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e59ebabb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1c,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x1b,0x0,0x3e,0x41,0x38,0x60,0x5b,0x2e,0x2e,0x30,0x39,0x38,0x2a,0x31,0x2d,0x33,0x5d,0x2d,0x60,0x33,0xef,0xbf,0xbf,0xe2,0x80,0xa8,0xdd,0xa4,0x21,0x60,0x5b,0x30,0x2d,0x32,0x5d,0x2d,0x60,0x33,0xef,0xbf,0xbf,0xdd,0xa4,0x21,0x60,0x5b,0x31,0x2d,0x32,0x5d,0x2d,0x60,0xe0,0xbf,0xbf,0xd5,0xa4,0x21,0x60,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xfa,0xff,0xa3,0xcf,0x26,0x31,0x32,0x37,0x5d,0x2d,0x60,0x7a,0xef,0xbf,0xbf,0xd5,0xa4,0x21,0x60,0x5b,0x31,0x2d,0x32,0x5d,0x2d,0x60,0xe0,0xbf,0xbf,0xd5,0xa4,0x21,0x60,0x5b,0x60,0x73,0x21,0x60,0x5b,0x32,0x38,0x0,0x2d,0x5b,0xa4,0x21,0x14,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x32,0x32,0xff,0xff,0xff,0xfc,0x2a,0x39,0x33,0x33,0x5d,0x65,0x92,0x0,0xc0,0x99,0xba, Step #5: `\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\034\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\033\000>A8`[..098*1-3]-`3\357\277\277\342\200\250\335\244!`[0-2]-`3\357\277\277\335\244!`[1-2]-`\340\277\277\325\244!`\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\372\377\243\317&127]-`z\357\277\277\325\244!`[1-2]-`\340\277\277\325\244!`[`s!`[28\000-[\244!\024\000\000\000\000\000\000\000\000\000-22\377\377\377\374*933]e\222\000\300\231\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-8a60036cf8fb62a79119bb48b2581a3ee750211a Step #5: Base64: YBsbGxsbGxsbGxsbGxsbGxsbHBsbGxsbGxsbGxsbGxsbGxsbGxsbGxsAPkE4YFsuLjA5OCoxLTNdLWAz77+/4oCo3aQhYFswLTJdLWAz77+/3aQhYFsxLTJdLWDgv7/VpCFg//////////////////////r/o88mMTI3XS1geu+/v9WkIWBbMS0yXS1g4L+/1aQhYFtgcyFgWzI4AC1bpCEUAAAAAAAAAAAALTIy/////Co5MzNdZZIAwJm6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4831 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4159317249 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f70cc2f810, 0x55f70ce1901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f70ce19020,0x55f70ecb10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8a60036cf8fb62a79119bb48b2581a3ee750211a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6081 processed earlier; will process 4948 files now Step #5: ==173992== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f7037249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f709d89898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f709d6c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f709d6c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f70372ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f70368bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f703686355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f70371cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7066ebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7066ebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7066ebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7066ebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7066ebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7066ebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7066ebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7066ebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7066ebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7066ebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f708980f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f7056adb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f7056b8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f705464c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f705464c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f705465738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f705464874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f705464874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f705464874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f709d6eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f709d77928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f709d5f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f709d8a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbdc328e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f703684b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x5b,0x7b,0x24,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x5b,0x7b,0x24,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x7b,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x29,0x29,0x29,0x29,0x29,0x29,0x3e,0xe,0x32,0x29,0x31,0x73,0x3e,0x3e,0x3e,0x3e,0x2a,0x3e,0x3e,0x3e,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x29,0x29,0x29,0x29,0x29,0x29,0x3e,0xe,0x32,0x29,0x31,0x73,0x3e,0x3e,0x3e,0x3e,0x2a,0x3e,0x3e,0x3e,0x2a,0x2a, Step #5: {{{{{{{{{{[{${{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{>>>>>>>[{${{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{>>>>>>>>>>)))))))>>>>>>>>>>>))))))>\0162)1s>>>>*>>>)))))))>>>>>>>>>>>))))))>\0162)1s>>>>*>>>** Step #5: artifact_prefix='./'; Test unit written to ./oom-160af88a1759f5e2d54002180623d6c31a37126b Step #5: Base64: e3t7e3t7e3t7e1t7JHt7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7ez4+Pj4+Pj5beyR7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3t7e3s+Pj4+Pj4+Pj4+KSkpKSkpKT4+Pj4+Pj4+Pj4+KSkpKSkpPg4yKTFzPj4+Pio+Pj4pKSkpKSkpPj4+Pj4+Pj4+Pj4pKSkpKSk+DjIpMXM+Pj4+Kj4+Pioq Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4832 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4159837035 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55731373a810, 0x55731392401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557313924020,0x5573157bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/160af88a1759f5e2d54002180623d6c31a37126b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6082 processed earlier; will process 4947 files now Step #5: ==174028== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55730a22f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557310894898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5573108775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5573108774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55730a235d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55730a196b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55730a191355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55730a227c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55730d1f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55730d1f6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55730d1f6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55730d1f6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55730d1f6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55730d1f6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55730d1f6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55730d1f6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55730d1f6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55730d1f6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55730f48bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55730c1b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55730c1c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55730bf6fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55730bf6fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55730bf70738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55730bf6f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55730bf6f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55730bf6f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557310879abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557310882928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55731086a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557310895112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa54b8bd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55730a18fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x31,0x32,0x39,0x34,0x37,0x38,0x38,0x38,0x33,0x37,0x30,0x33,0x0,0x0,0x0,0x0,0x4f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x31,0x0,0x0,0x0,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x5c,0x9,0x60,0x40,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x60,0x40,0x60,0x40,0x29,0xa,0x5c,0x9,0x40,0x60,0x40,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0xa,0x5c,0x9,0x60,0x40,0x60,0x40,0x29,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x21,0x4d,0x30,0x57,0x41,0x50,0x52,0x49,0x43,0x56,0x42,0x8,0x46,0x21,0xc8,0x0,0x0, Step #5: ID129478883703\000\000\000\000O\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0001\000\000\000\012\\\011`@`@)\012\\\011`@`@)\012\\\011`@`@)\012\\\011`@`@)\012\\\011`@`@)\012\\\011`@)\012\\\011`@`@)\012\\\011`@`@)\012\\\011`@`@`@`@)\012\\\011@`@)\012\\\011`@`@)\012\\\011`@`@)\012\\\011`@`@)\012\\\011`@`@)\012\\\011`@`@)\000\000\000\000\000\000\000\000\000\000\000\000\000!M0WAPRICVB\010F!\310\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-80ec16d6dcfe68e00f845c9e9754694cceab571e Step #5: Base64: SUQxMjk0Nzg4ODM3MDMAAAAATwAAAAAAAAAAAAAAAAAAAAAxAAAAClwJYEBgQCkKXAlgQGBAKQpcCWBAYEApClwJYEBgQCkKXAlgQGBAKQpcCWBAKQpcCWBAYEApClwJYEBgQCkKXAlgQGBAYEBgQCkKXAlAYEApClwJYEBgQCkKXAlgQGBAKQpcCWBAYEApClwJYEBgQCkKXAlgQGBAKQAAAAAAAAAAAAAAAAAhTTBXQVBSSUNWQghGIcgAAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4833 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4160489872 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560480f10810, 0x5604810fa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604810fa020,0x560482f920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/80ec16d6dcfe68e00f845c9e9754694cceab571e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6083 processed earlier; will process 4946 files now Step #5: #1 pulse cov: 3900 ft: 3901 exec/s: 0 rss: 177Mb Step #5: ==174064== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560477a059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56047e06a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56047e04d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56047e04d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560477a0bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56047796cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560477967355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5604779fdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56047a9ccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56047a9ccf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56047a9ccf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56047a9ccf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56047a9ccf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56047a9ccf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56047a9ccf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56047a9ccf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56047a9ccf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56047a9ccf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56047cc61f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56047998eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560479999be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560479745c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560479745c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560479746738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560479745874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560479745874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560479745874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56047e04fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56047e058928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56047e040699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56047e06b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0085e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560477965b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x28,0x2e,0x2d,0x24,0x7c,0x2e,0x3f,0x29,0x7b,0x39,0x38,0x39,0x7d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24, Step #5: ^(.-$|.?){989}\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000$ Step #5: artifact_prefix='./'; Test unit written to ./oom-6dc5219d418f12cdb50ecf877c466e3fb148260b Step #5: Base64: XiguLSR8Lj8pezk4OX0AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4834 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4161057634 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643cd35b810, 0x5643cd54501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643cd545020,0x5643cf3dd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6dc5219d418f12cdb50ecf877c466e3fb148260b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6085 processed earlier; will process 4944 files now Step #5: #1 pulse cov: 3641 ft: 3642 exec/s: 0 rss: 177Mb Step #5: ==174100== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643c3e509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643ca4b5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643ca4985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643ca4984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643c3e56d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643c3db7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643c3db2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643c3e48c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643c6e17f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643c6e17f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643c6e17f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643c6e17f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643c6e17f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643c6e17f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643c6e17f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643c6e17f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643c6e17f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643c6e17f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643c90acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643c5dd9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643c5de4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643c5b90c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643c5b90c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643c5b91738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643c5b90874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643c5b90874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643c5b90874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643ca49aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643ca4a3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643ca48b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643ca4b6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe9fc543082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643c3db0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x47,0x41,0xd6,0xaf,0x27,0x27,0x27,0x2f,0x0,0x0,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x47,0x41,0xd6,0xaf,0x27,0x27,0x27,0x2f,0x0,0x0,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x32,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0xd6,0xaf,0x27,0x27,0x27,0x2f,0x0,0x0,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x47,0x41,0xd6,0xaf,0x27,0x27,0x27,0x2f,0x0,0x0,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x32,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x0,0x12,0x12,0x12,0x12,0x12,0x0,0x0,0x0,0x0,0x0,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x47,0x41,0xd6,0xaf,0x27,0x27,0x27,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x15,0x2f,0x29,0x81,0x0,0x27, Step #5: BGA\326\257'''/\000\000\022\022\022\022\022\022\022\022GA\326\257'''/\000\000\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\0222\022\022\022\022\022\022\022\022\326\257'''/\000\000\022\022\022\022\022\022\022\022GA\326\257'''/\000\000\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\0222\022\022\022\022\022\022\022\022\022\022\022\022\022\000\022\022\022\022\022\000\000\000\000\000\022\022\022\022\022\022\022\022\022\022\022\022\022\022GA\326\257'''\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022\000\000\000\000\000\000\000'\025/)\201\000' Step #5: artifact_prefix='./'; Test unit written to ./oom-53228c63e6620f1416140b9254bf9f6b7a73dce8 Step #5: Base64: QkdB1q8nJycvAAASEhISEhISEkdB1q8nJycvAAASEhISEhISEhISEhISEhISEhISEhISMhISEhISEhIS1q8nJycvAAASEhISEhISEkdB1q8nJycvAAASEhISEhISEhISEhISEhISEhISEhISMhISEhISEhISEhISEhIAEhISEhIAAAAAABISEhISEhISEhISEhISR0HWrycnJxISEhISEhISEhISEhISEhISEhISEhIAAAAAAAAAJxUvKYEAJw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4835 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4161619125 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564df0992810, 0x564df0b7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564df0b7c020,0x564df2a140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/53228c63e6620f1416140b9254bf9f6b7a73dce8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6087 processed earlier; will process 4942 files now Step #5: #1 pulse cov: 4309 ft: 4310 exec/s: 0 rss: 175Mb Step #5: ==174136== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564de74879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564dedaec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564dedacf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564dedacf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564de748dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564de73eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564de73e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564de747fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564dea44ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564dea44ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564dea44ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564dea44ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564dea44ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564dea44ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564dea44ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564dea44ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564dea44ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564dea44ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564dec6e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564de9410b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564de941bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564de91c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564de91c7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564de91c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564de91c7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564de91c7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564de91c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564dedad1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564dedada928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564dedac2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564dedaed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5feeafe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564de73e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x53,0x24,0x53,0x24,0x61,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0x30,0x64,0x73,0x20,0x31,0x33,0x31,0x30,0x1,0x0,0xe,0x79,0x61,0xf,0x0,0x0,0x0,0x33,0x4,0xe2,0x80,0xae,0x5e,0x5e,0x5e,0x5e,0xae,0x61,0xe2,0x80,0xae,0x4,0xe2,0x80,0xae,0x61,0x30,0x64,0x73,0x20,0x31,0x33,0x31,0x30,0x1,0x0,0xe,0x79,0x61,0xf,0x0,0x0,0x0,0x33,0x4,0xe2,0x80,0xae,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x4,0xe2,0x80,0xae,0x61,0xe2,0x80,0xb0,0xa6,0xcd,0x9e,0xef,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0xfd,0xb9,0x32,0x22,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e,0x5e, Step #5: (?:S$S$a\342\200\256\004\342\200\256a0ds 1310\001\000\016ya\017\000\000\0003\004\342\200\256^^^^\256a\342\200\256\004\342\200\256a0ds 1310\001\000\016ya\017\000\000\0003\004\342\200\256^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\004\342\200\256a\342\200\260\246\315\236\357^^^^^^^\375\2712\"^^^^^^^^^^^^^^^^^^^^^^^^^ Step #5: artifact_prefix='./'; Test unit written to ./oom-541f37df61c150c4c1b3ca8e3456a030e0b98597 Step #5: Base64: KD86UyRTJGHigK4E4oCuYTBkcyAxMzEwAQAOeWEPAAAAMwTigK5eXl5ermHigK4E4oCuYTBkcyAxMzEwAQAOeWEPAAAAMwTigK5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXgTigK5h4oCwps2e715eXl5eXl79uTIiXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4836 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4162175717 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a48ffcb810, 0x55a4901b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a4901b5020,0x55a49204d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/541f37df61c150c4c1b3ca8e3456a030e0b98597' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6089 processed earlier; will process 4940 files now Step #5: ==174172== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a486ac09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a48d125898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a48d1085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a48d1084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a486ac6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a486a27b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a486a22355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a486ab8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a489a87f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a489a87f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a489a87f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a489a87f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a489a87f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a489a87f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a489a87f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a489a87f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a489a87f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a489a87f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a48bd1cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a488a49b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a488a54be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a488800c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a488800c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a488801738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a488800874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a488800874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a488800874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a48d10aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a48d113928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a48d0fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a48d126112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f93eb252082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a486a20b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x26,0x26,0x3f,0x26,0x26,0x7c,0x7c,0x26,0x26,0x3a,0x26,0x26,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x26,0x26,0x3f,0x26,0x26,0x7c,0x7c,0x26,0x26,0x3a,0x26,0x26,0x3f,0x26,0x26,0x7f,0x7c,0x26,0x2f, Step #5: \024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024&&?&&||&&:&&\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024&&?&&||&&:&&?&&\177|&/ Step #5: artifact_prefix='./'; Test unit written to ./oom-5515009117867e650146f9ee499a4cbd4cab0c88 Step #5: Base64: FBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQmJj8mJnx8JiY6JiYUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUJiY/JiZ8fCYmOiYmPyYmf3wmLw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4837 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4162692935 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55beb6be5810, 0x55beb6dcf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55beb6dcf020,0x55beb8c670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5515009117867e650146f9ee499a4cbd4cab0c88' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6090 processed earlier; will process 4939 files now Step #5: #1 pulse cov: 13293 ft: 13294 exec/s: 0 rss: 195Mb Step #5: #2 pulse cov: 14223 ft: 15242 exec/s: 0 rss: 197Mb Step #5: ==174208== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bead6da9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55beb3d3f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55beb3d225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55beb3d224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bead6e0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bead641b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bead63c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bead6d2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55beb06a1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55beb06a1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55beb06a1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55beb06a1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55beb06a1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55beb06a1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55beb06a1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55beb06a1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55beb06a1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55beb06a1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55beb2936f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55beaf663b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55beaf66ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55beaf41ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55beaf41ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55beaf41b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55beaf41a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55beaf41a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55beaf41a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55beb3d24abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55beb3d2d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55beb3d15699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55beb3d40112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c6b136082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bead63ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a,0xa,0x2e,0x3a, Step #5: .:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.:\012.: Step #5: artifact_prefix='./'; Test unit written to ./oom-6ecbde5e082ed26daa8ebe27099927ed9f698c23 Step #5: Base64: LjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjoKLjo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4838 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4163362458 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eaad039810, 0x55eaad22301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eaad223020,0x55eaaf0bb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ecbde5e082ed26daa8ebe27099927ed9f698c23' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6093 processed earlier; will process 4936 files now Step #5: ==174244== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eaa3b2e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eaaa193898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eaaa1765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eaaa1764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eaa3b34d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eaa3a95b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eaa3a90355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eaa3b26c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eaa6af5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eaa6af5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eaa6af5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eaa6af5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eaa6af5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eaa6af5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eaa6af5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eaa6af5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eaa6af5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eaa6af5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eaa8d8af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eaa5ab7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eaa5ac2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eaa586ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eaa586ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eaa586f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eaa586e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eaa586e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eaa586e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eaaa178abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eaaa181928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eaaa169699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eaaa194112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f05722bf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eaa3a8eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x6f,0x63,0x69,0x56,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x31,0x2e,0x30,0x2e,0x30,0x22,0x2c,0x22,0x70,0x72,0x6f,0x63,0x65,0x73,0x73,0x22,0x3a,0x7b,0x22,0x63,0x61,0x70,0x61,0x62,0x69,0x6c,0x69,0x74,0x69,0x65,0x73,0x22,0x3a,0x7b,0x22,0x61,0x6d,0x62,0x69,0x65,0x6e,0x74,0x22,0x3a,0x5b,0x22,0x36,0x22,0x2c,0x22,0x30,0x22,0x2c,0x22,0x34,0x22,0x2c,0x22,0x30,0x22,0x2c,0x22,0x30,0x22,0x2c,0x22,0x31,0x22,0x2c,0x22,0x35,0x22,0x2c,0x22,0x34,0x22,0x2c,0x22,0x31,0x22,0x2c,0x22,0x35,0x22,0x2c,0x22,0x34,0x22,0x2c,0x22,0x30,0x22,0x2c,0x22,0x35,0x22,0x2c,0x22,0x31,0x22,0x2c,0x22,0x30,0x22,0x2c,0x22,0x34,0x22,0x2c,0x22,0x30,0x22,0x2c,0x22,0x34,0x22,0x2c,0x22,0x31,0x22,0x2c,0x22,0x35,0x22,0x2c,0x22,0x34,0x22,0x2c,0x22,0x31,0x22,0x2c,0x22,0x35,0x22,0x2c,0x22,0x34,0x22,0x2c,0x22,0x30,0x22,0x2c,0x22,0x35,0x22,0x2c,0x22,0x31,0x22,0x2c,0x22,0x30,0x22,0x2c,0x22,0x34,0x22,0x2c,0x22,0x31,0x22,0x2c,0x22,0x30,0x22,0x2c,0x22,0x37,0x22,0x5d,0x7d,0x7d,0x7d, Step #5: {\"ociVersion\":\"1.0.0\",\"process\":{\"capabilities\":{\"ambient\":[\"6\",\"0\",\"4\",\"0\",\"0\",\"1\",\"5\",\"4\",\"1\",\"5\",\"4\",\"0\",\"5\",\"1\",\"0\",\"4\",\"0\",\"4\",\"1\",\"5\",\"4\",\"1\",\"5\",\"4\",\"0\",\"5\",\"1\",\"0\",\"4\",\"1\",\"0\",\"7\"]}}} Step #5: artifact_prefix='./'; Test unit written to ./oom-e66dfd953bf63a1dd79e98963ba05705ca0288be Step #5: Base64: eyJvY2lWZXJzaW9uIjoiMS4wLjAiLCJwcm9jZXNzIjp7ImNhcGFiaWxpdGllcyI6eyJhbWJpZW50IjpbIjYiLCIwIiwiNCIsIjAiLCIwIiwiMSIsIjUiLCI0IiwiMSIsIjUiLCI0IiwiMCIsIjUiLCIxIiwiMCIsIjQiLCIwIiwiNCIsIjEiLCI1IiwiNCIsIjEiLCI1IiwiNCIsIjAiLCI1IiwiMSIsIjAiLCI0IiwiMSIsIjAiLCI3Il19fX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4839 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4163882766 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55da231cd810, 0x55da233b701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55da233b7020,0x55da2524f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e66dfd953bf63a1dd79e98963ba05705ca0288be' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6094 processed earlier; will process 4935 files now Step #5: ==174280== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55da19cc29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55da20327898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55da2030a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55da2030a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55da19cc8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55da19c29b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55da19c24355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55da19cbac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55da1cc89f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55da1cc89f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55da1cc89f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55da1cc89f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55da1cc89f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55da1cc89f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55da1cc89f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55da1cc89f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55da1cc89f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55da1cc89f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55da1ef1ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55da1bc4bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55da1bc56be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55da1ba02c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55da1ba02c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55da1ba03738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55da1ba02874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55da1ba02874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55da1ba02874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55da2030cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55da20315928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55da202fd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55da20328112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc35be5c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55da19c22b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7b,0x38,0x24,0x7d,0x7b,0x32,0x7d,0x7d,0x7b,0x32,0x7d,0x7b,0x32,0x7d,0x24,0x7b,0x37,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7b,0x32,0x7d,0x24,0x7b,0x37,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x24,0x7b,0x38,0x7d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: ${8$}{2}}{2}{2}${7}${8}${8}${8}\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000{2}${7}${8}${8}${8}\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-09352a48c1f8ecae556b1c6ad66882f999472f57 Step #5: Base64: JHs4JH17Mn19ezJ9ezJ9JHs3fSR7OH0kezh9JHs4fQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB7Mn0kezd9JHs4fSR7OH0kezh9AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4840 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4164416327 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c4671fe810, 0x55c4673e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c4673e8020,0x55c4692800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/09352a48c1f8ecae556b1c6ad66882f999472f57' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6095 processed earlier; will process 4934 files now Step #5: #1 pulse cov: 3585 ft: 3586 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4290 ft: 4611 exec/s: 0 rss: 176Mb Step #5: ==174316== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c45dcf39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c464358898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c46433b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c46433b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c45dcf9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c45dc5ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c45dc55355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c45dcebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c460cbaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c460cbaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c460cbaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c460cbaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c460cbaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c460cbaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c460cbaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c460cbaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c460cbaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c460cbaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c462f4ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c45fc7cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c45fc87be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c45fa33c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c45fa33c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c45fa34738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c45fa33874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c45fa33874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c45fa33874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c46433dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c464346928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c46432e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c464359112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff1a5c8f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c45dc53b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x7d,0x7b,0x7d,0x30,0x30,0x30,0x32,0x31,0x2b,0x22,0x22,0x22,0x22,0x22,0x22,0x2b,0x7c,0x7c,0xc,0x60,0xc,0xc,0x78,0x9,0x9,0x7d,0xa,0x6c,0x69,0x2e,0x2e,0x39,0x2,0x7d,0x24,0x7b,0x39,0x3b,0x7c,0x7c,0x75,0x7c,0x7c,0x65,0x76,0x41,0x6c,0x33,0x7c,0x7c,0x73,0x32,0x7c,0x77,0x7a,0x79,0x3b,0x78,0x9,0x9,0x3b,0x3b,0x3b,0x3b,0x42,0x7c,0x7c,0x5f,0x65,0x6e,0x75,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x7b,0x7d,0x7b,0x7d,0x9,0x6c,0x6f,0x6f,0x70,0x7b,0x7d,0x7b,0x7d,0x9,0x6c,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x7d,0x2a,0x6c,0x74,0x20,0x60,0xa,0xff,0xff,0xff,0x5f,0x75,0x38,0xff,0xff,0xff,0xff,0xff,0xff,0x3b,0x3b,0x7d,0x2a,0x6c,0x74,0x20,0x60,0xff,0x5f,0x75,0x38,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x79,0x3b,0x78,0x9,0x9,0x7c,0x7c,0x7c,0x7c,0x7c,0x7c,0x77,0x7c,0x7c,0x7c,0x7c,0x77,0x7c,0x79,0x3b,0x78,0x9,0x7b,0x69,0x6d,0x70,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x7b,0x7d,0x7b,0x7d,0x7b,0x7d,0x74,0x7b,0x22,0x22,0x7d,0x61,0x9,0x6c,0x6f,0x73, Step #5: {}{}00021+\"\"\"\"\"\"+||\014`\014\014x\011\011}\012li..9\002}${9;||u||evAl3||s2|wzy;x\011\011;;;;B||_enu;;;;;;{}{}\011loop{}{}\011l;;;;;;;;;}*lt `\012\377\377\377_u8\377\377\377\377\377\377;;}*lt `\377_u8\377\377\377\377\377\377\377\377\377y;x\011\011||||||w||||w|y;x\011{impOOOOOOOO{}{}{}t{\"\"}a\011los Step #5: artifact_prefix='./'; Test unit written to ./oom-123ffd896bf84bbe1af17b7931ec08182fbb2601 Step #5: Base64: e317fTAwMDIxKyIiIiIiIit8fAxgDAx4CQl9CmxpLi45An0kezk7fHx1fHxldkFsM3x8czJ8d3p5O3gJCTs7OztCfHxfZW51Ozs7Ozs7e317fQlsb29we317fQlsOzs7Ozs7Ozs7fSpsdCBgCv///191OP///////zs7fSpsdCBg/191OP///////////3k7eAkJfHx8fHx8d3x8fHx3fHk7eAl7aW1wT09PT09PT097fXt9e310eyIifWEJbG9z Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4841 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4165138873 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558d77fc3810, 0x558d781ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558d781ad020,0x558d7a0450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/123ffd896bf84bbe1af17b7931ec08182fbb2601' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6098 processed earlier; will process 4931 files now Step #5: ==174352== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558d6eab89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558d7511d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558d751005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558d751004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558d6eabed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558d6ea1fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558d6ea1a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558d6eab0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558d71a7ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558d71a7ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558d71a7ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558d71a7ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558d71a7ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558d71a7ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558d71a7ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558d71a7ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558d71a7ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558d71a7ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558d73d14f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558d70a41b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558d70a4cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558d707f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558d707f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558d707f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558d707f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558d707f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558d707f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558d75102abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558d7510b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558d750f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558d7511e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f270aba3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558d6ea18b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0x61,0x65,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x3a,0x0,0x2a,0x2a,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x3a,0x0,0x2a,0x2a,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x2a,0x2a,0x68,0x68,0x68,0x68,0x68,0x68,0x75,0x75,0x75,0x75,0x65, Step #5: nae**************************************\000\000\000:\000**hhhhhhhhh\004\000\000\000\000\000\000\000hhhhhhhhhhhhhh\000hhhhhhh**********hhhhhhhhhttps://hhhhhhhhhhhhhhhhh***\000\000\000:\000**hhhhhhhhh\004\000\000\000\000\000\000\000hhhhhhhhhhhhhh\000hhhhhhh**hhhhhhuuuue Step #5: artifact_prefix='./'; Test unit written to ./oom-97e08c74add1dcfc001ef7f7e27087e962952188 Step #5: Base64: bmFlKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioAAAA6ACoqaGhoaGhoaGhoBAAAAAAAAABoaGhoaGhoaGhoaGhoaABoaGhoaGhoKioqKioqKioqKmhoaGhoaGhoaHR0cHM6Ly9oaGhoaGhoaGhoaGhoaGhoaCoqKgAAADoAKipoaGhoaGhoaGgEAAAAAAAAAGhoaGhoaGhoaGhoaGhoAGhoaGhoaGgqKmhoaGhoaHV1dXVl Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4842 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4165670508 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5587a14d0810, 0x5587a16ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5587a16ba020,0x5587a35520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/97e08c74add1dcfc001ef7f7e27087e962952188' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6099 processed earlier; will process 4930 files now Step #5: ==174388== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558797fc59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55879e62a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55879e60d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55879e60d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558797fcbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558797f2cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558797f27355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558797fbdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55879af8cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55879af8cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55879af8cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55879af8cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55879af8cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55879af8cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55879af8cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55879af8cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55879af8cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55879af8cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55879d221f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558799f4eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558799f59be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558799d05c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558799d05c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558799d06738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558799d05874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558799d05874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558799d05874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55879e60fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55879e618928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55879e600699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55879e62b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc72ed8d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558797f25b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0xc2,0x85,0x5c,0xc2,0x85,0x5b,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x41,0xc2,0x85,0x7c,0xc2,0x85,0x5c,0xc2,0x85,0x5b,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x24,0xc2,0x85,0x5c,0xc2,0x85,0x5b,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x41,0xc2,0x85,0x7c,0xc2,0x85,0x5c,0xc2,0x85,0x5b,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x41,0xc2,0x85,0x24,0xc2,0x85,0x5c,0xc2,0x85,0x5b,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x41,0xc2,0x85,0x7c,0xc2,0x85,0x5c,0xc2,0x85,0x5b,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x24,0xc2,0x85,0x5c,0xc2,0x85,0x5b,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x41,0xc2,0x85,0x7c,0xc2,0x85,0x5c,0xc2,0x85,0x5b,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x41,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5d,0xc2,0x85,0x41,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5d,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5d,0xc2,0x85,0x41,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5c,0xc2,0x85,0x5d,0xc2,0x85, Step #5: $\302\205\\\302\205[\302\205\\\302\205\\\302\205A\302\205|\302\205\\\302\205[\302\205\\\302\205\\\302\205$\302\205\\\302\205[\302\205\\\302\205\\\302\205A\302\205|\302\205\\\302\205[\302\205\\\302\205\\\302\205A\302\205$\302\205\\\302\205[\302\205\\\302\205\\\302\205A\302\205|\302\205\\\302\205[\302\205\\\302\205\\\302\205$\302\205\\\302\205[\302\205\\\302\205\\\302\205A\302\205|\302\205\\\302\205[\302\205\\\302\205\\\302\205A\302\205\\\302\205\\\302\205\\\302\205]\302\205A\302\205\\\302\205\\\302\205\\\302\205]\302\205\\\302\205\\\302\205\\\302\205]\302\205A\302\205\\\302\205\\\302\205\\\302\205]\302\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-0b4553aeb556f8baf25f84f3cf31cd18dda2383f Step #5: Base64: JMKFXMKFW8KFXMKFXMKFQcKFfMKFXMKFW8KFXMKFXMKFJMKFXMKFW8KFXMKFXMKFQcKFfMKFXMKFW8KFXMKFXMKFQcKFJMKFXMKFW8KFXMKFXMKFQcKFfMKFXMKFW8KFXMKFXMKFJMKFXMKFW8KFXMKFXMKFQcKFfMKFXMKFW8KFXMKFXMKFQcKFXMKFXMKFXMKFXcKFQcKFXMKFXMKFXMKFXcKFXMKFXMKFXMKFXcKFQcKFXMKFXMKFXMKFXcKF Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4843 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4166193193 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562cad405810, 0x562cad5ef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562cad5ef020,0x562caf4870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b4553aeb556f8baf25f84f3cf31cd18dda2383f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6100 processed earlier; will process 4929 files now Step #5: ==174424== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562ca3efa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562caa55f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562caa5425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562caa5424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562ca3f00d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562ca3e61b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562ca3e5c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562ca3ef2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ca6ec1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ca6ec1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ca6ec1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ca6ec1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ca6ec1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ca6ec1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ca6ec1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ca6ec1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ca6ec1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ca6ec1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ca9156f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ca5e83b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ca5e8ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ca5c3ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ca5c3ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ca5c3b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ca5c3a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ca5c3a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ca5c3a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562caa544abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562caa54d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562caa535699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562caa560112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff37fd26082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562ca3e5ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x2e,0xdf,0xba,0x3a,0x5d, Step #5: \012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:]\012\012:\010\012\006[.\337\272:] Step #5: artifact_prefix='./'; Test unit written to ./oom-4560b623ca1d0031ce0974fc5eb597582747e4f1 Step #5: Base64: Cgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpdCgo6CAoGWy7fujpd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4844 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4166728303 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c21d183810, 0x55c21d36d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c21d36d020,0x55c21f2050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4560b623ca1d0031ce0974fc5eb597582747e4f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6101 processed earlier; will process 4928 files now Step #5: ==174460== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c213c789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c21a2dd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c21a2c05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c21a2c04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c213c7ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c213bdfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c213bda355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c213c70c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c216c3ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c216c3ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c216c3ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c216c3ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c216c3ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c216c3ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c216c3ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c216c3ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c216c3ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c216c3ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c218ed4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c215c01b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c215c0cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c2159b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c2159b8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c2159b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c2159b8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c2159b8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c2159b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c21a2c2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c21a2cb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c21a2b3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c21a2de112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e3289b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c213bd8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80, Step #5: \341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-3aea71e3625e1e9c87f7c320003ed353443a3bd1 Step #5: Base64: 4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA4ZqA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4845 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4167246220 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bdc5bf8810, 0x55bdc5de201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bdc5de2020,0x55bdc7c7a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3aea71e3625e1e9c87f7c320003ed353443a3bd1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6102 processed earlier; will process 4927 files now Step #5: ==174496== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bdbc6ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bdc2d52898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bdc2d355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bdc2d354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bdbc6f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bdbc654b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bdbc64f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bdbc6e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bdbf6b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bdbf6b4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bdbf6b4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bdbf6b4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bdbf6b4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bdbf6b4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bdbf6b4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bdbf6b4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bdbf6b4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bdbf6b4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bdc1949f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bdbe676b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bdbe681be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bdbe42dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bdbe42dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bdbe42e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bdbe42d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bdbe42d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bdbe42d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bdc2d37abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bdc2d40928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bdc2d28699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bdc2d53112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f23e6682082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bdbc64db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e,0x3c,0x61,0x52,0x65,0x61,0x3e, Step #5: <aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea><aRea> Step #5: artifact_prefix='./'; Test unit written to ./oom-7d3c09c1c1258f405500fc91a3f0d8d760a3dccc Step #5: Base64: PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+PGFSZWE+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4846 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4167756780 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5575fde7d810, 0x5575fe06701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5575fe067020,0x5575ffeff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d3c09c1c1258f405500fc91a3f0d8d760a3dccc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6103 processed earlier; will process 4926 files now Step #5: #1 pulse cov: 4155 ft: 4156 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4429 ft: 4688 exec/s: 0 rss: 179Mb Step #5: ==174532== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5575f49729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5575fafd7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5575fafba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5575fafba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5575f4978d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5575f48d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5575f48d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5575f496ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5575f7939f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5575f7939f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5575f7939f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5575f7939f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5575f7939f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5575f7939f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5575f7939f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5575f7939f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5575f7939f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5575f7939f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5575f9bcef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5575f68fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5575f6906be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5575f66b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5575f66b2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5575f66b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5575f66b2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5575f66b2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5575f66b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5575fafbcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5575fafc5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5575fafad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5575fafd8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8176dfa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5575f48d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba,0xa,0xa,0x3a,0x8,0xa,0x6,0x5b,0x3a,0x5d,0x3a,0xdd,0xba, Step #5: \012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272\012\012:\010\012\006[:]:\335\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-3135c8742a691d9f97dc014080f96cd62b5104a2 Step #5: Base64: Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26Cgo6CAoGWzpdOt26 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4847 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4168412444 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555cf7906810, 0x555cf7af001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555cf7af0020,0x555cf99880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3135c8742a691d9f97dc014080f96cd62b5104a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6107 processed earlier; will process 4922 files now Step #5: ==174568== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555cee3fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555cf4a60898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555cf4a435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555cf4a434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555cee401d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555cee362b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555cee35d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555cee3f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555cf13c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555cf13c2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555cf13c2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555cf13c2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555cf13c2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555cf13c2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555cf13c2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555cf13c2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555cf13c2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555cf13c2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555cf3657f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555cf0384b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555cf038fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555cf013bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555cf013bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555cf013c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555cf013b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555cf013b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555cf013b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555cf4a45abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555cf4a4e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555cf4a36699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555cf4a61112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff0893ea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555cee35bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x81,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x81,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x81,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x90,0xe1,0x85,0xa2,0xe1,0x84,0x91,0xe1,0x85,0xb1,0xa,0xe1,0x84,0x91,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x92,0xe1,0x85,0xb0,0xe1,0x84,0x85,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb1,0xe1,0x84,0x91,0xe1,0x85,0xa2,0xe1,0x84,0x91,0xe1,0x85,0xb1,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x81,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0, Step #5: \341\204\221\341\205\260\341\204\221\341\205\260\341\204\201\341\205\260\341\204\221\341\205\260\341\204\221\341\205\260\341\204\221\341\205\252\341\204\221\341\205\260\341\204\221\341\205\260\341\204\201\341\205\260\341\204\221\341\205\260\341\204\221\341\205\252\341\204\221\341\205\260\341\204\221\341\205\260\341\204\201\341\205\260\341\204\221\341\205\260\341\204\221\341\205\260\341\204\220\341\205\242\341\204\221\341\205\261\012\341\204\221\341\205\252\341\204\221\341\205\260\341\204\222\341\205\260\341\204\205\341\205\260\341\204\221\341\205\260\341\204\221\341\205\261\341\204\221\341\205\242\341\204\221\341\205\261\341\204\221\341\205\260\341\204\221\341\205\260\341\204\221\341\205\252\341\204\221\341\205\260\341\204\201\341\205\252\341\204\221\341\205\260 Step #5: artifact_prefix='./'; Test unit written to ./oom-4314ce81942885b7ed1fc056db588e4b0351cb55 Step #5: Base64: 4YSR4YWw4YSR4YWw4YSB4YWw4YSR4YWw4YSR4YWw4YSR4YWq4YSR4YWw4YSR4YWw4YSB4YWw4YSR4YWw4YSR4YWq4YSR4YWw4YSR4YWw4YSB4YWw4YSR4YWw4YSR4YWw4YSQ4YWi4YSR4YWxCuGEkeGFquGEkeGFsOGEkuGFsOGEheGFsOGEkeGFsOGEkeGFseGEkeGFouGEkeGFseGEkeGFsOGEkeGFsOGEkeGFquGEkeGFsOGEgeGFquGEkeGFsA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4848 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4168948193 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560c33eff810, 0x560c340e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560c340e9020,0x560c35f810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4314ce81942885b7ed1fc056db588e4b0351cb55' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6108 processed earlier; will process 4921 files now Step #5: ==174604== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560c2a9f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560c31059898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560c3103c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560c3103c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560c2a9fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560c2a95bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560c2a956355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560c2a9ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560c2d9bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560c2d9bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560c2d9bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560c2d9bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560c2d9bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560c2d9bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560c2d9bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560c2d9bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560c2d9bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560c2d9bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560c2fc50f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560c2c97db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560c2c988be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560c2c734c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560c2c734c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560c2c735738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560c2c734874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560c2c734874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560c2c734874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560c3103eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560c31047928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560c3102f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560c3105a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f35fe96a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560c2a954b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x7f,0x7f,0x0,0x29,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x30,0x63,0x60,0x60,0x64,0x60,0x60,0x60,0x6,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x60,0x60,0x60,0x60,0x69,0x66,0x60,0x60,0x60,0x60,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0xc,0x64,0x60,0x60,0x60,0x6,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x35,0x35,0x35,0x35,0x35,0x0,0x2,0x78,0x0,0x1,0x3,0x5c,0x49,0xe,0x0,0xe9,0x44,0x33,0x2,0x1,0x0,0x74,0x2e,0x0,0x44,0x0,0xff,0xff,0xff,0xff,0x0,0x54,0x0,0x41,0x5b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0x28,0x0,0x72,0x0,0x0,0x28,0x0,0x72,0x64,0x64,0x64,0x64,0x64,0x64, Step #5: = \177\177\000)\000\000\000\000\000\000\0000c``d```\006\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000````if````\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014\014d```\006\000\000\000\000\000\000\000\000\000\000\000\000\000\000\00055555\000\002x\000\001\003\\I\016\000\351D3\002\001\000t.\000D\000\377\377\377\377\000T\000A[\000\000\000\000\000\000\000\000\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246(\000r\000\000(\000rdddddd Step #5: artifact_prefix='./'; Test unit written to ./oom-08d384b7d905daa4808ec4cd83cf2a7a44eafb4d Step #5: Base64: PSB/fwApAAAAAAAAADBjYGBkYGBgBgAAAAAAAAAAAAAAAAAAAAAAAAAAYGBgYGlmYGBgYAAAAAAAAAAAAAAAAAAAAAAAAAwMDAwMDAwMDAwMDAwMDAwMDAxkYGBgBgAAAAAAAAAAAAAAAAAAADU1NTU1AAJ4AAEDXEkOAOlEMwIBAHQuAEQA/////wBUAEFbAAAAAAAAAACmpqampqampqampqampqampqampqampqampqYoAHIAACgAcmRkZGRkZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4849 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4169599035 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c4cc4ff810, 0x55c4cc6e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c4cc6e9020,0x55c4ce5810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08d384b7d905daa4808ec4cd83cf2a7a44eafb4d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6109 processed earlier; will process 4920 files now Step #5: ==174640== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c4c2ff49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c4c9659898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c4c963c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c4c963c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c4c2ffad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c4c2f5bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c4c2f56355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c4c2fecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c4c5fbbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c4c5fbbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c4c5fbbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c4c5fbbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c4c5fbbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c4c5fbbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c4c5fbbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c4c5fbbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c4c5fbbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c4c5fbbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c4c8250f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c4c4f7db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c4c4f88be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c4c4d34c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c4c4d34c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c4c4d35738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c4c4d34874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c4c4d34874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c4c4d34874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c4c963eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c4c9647928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c4c962f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c4c965a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f914cce7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c4c2f54b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x63,0x6f,0x6e,0x72,0x65,0x6e,0x67,0x63,0x6f,0x3e,0x3c,0x63,0x6e,0x6f,0x72,0x6e,0x6e,0x72,0x65,0x66,0x67,0x63,0x6e,0x3e,0x3c,0x63,0x6f,0x61,0x72,0x6e,0x6e,0x67,0x63,0x6f,0x3e,0x3c,0x63,0x6e,0x6f,0x72,0x6e,0x6e,0x72,0x65,0x66,0x67,0x63,0x6f,0x3e,0x3c,0x67,0x63,0x6f,0x3e,0x3c,0x63,0x2d,0x6e,0x72,0x65,0x6e,0x67,0x63,0x6d,0x3e,0x3c,0x63,0x6f,0x6e,0x72,0x3e,0x3c,0x63,0x6f,0x6e,0x72,0x3e,0x6e,0x6e,0x72,0x65,0x6e,0x67,0x63,0x6f,0x3e,0x3c,0x63,0x6e,0x6f,0x72,0x6e,0x6e,0x72,0x65,0x66,0x67,0x63,0x6f,0x3e,0x3c,0x63,0x6f,0x6e,0x72,0x61,0x6e,0x65,0x63,0x6f,0x3e,0x3c,0x72,0x65,0x66,0x67,0x63,0x6f,0x3e,0x3c,0x63,0x2d,0x6e,0x72,0x65,0x6e,0x67,0x63,0x6d,0x3e,0x3c,0x63,0x6f,0x6e,0x72,0x3e,0x3e,0x3c,0x63,0x6f,0x6e,0x72,0x61,0x6e,0x65,0x63,0x6f,0x3e,0x3c,0x63,0x6e,0x6f,0x72,0x6e,0x6e,0x72,0x65,0x66,0x67,0x63,0x6f,0x3e,0x3c,0x63,0x2d,0x6e,0x72,0x65,0x6e,0x67,0x63,0x72,0x61,0x6e,0x65,0x63,0x6f,0x3e,0x3c,0x63,0x2d,0x6e,0x72,0x65,0x6e,0x67,0x63,0x6d,0x3e,0x6f,0x6e,0x3e, Step #5: <conrengco><cnornnrefgcn><coarnngco><cnornnrefgco><gco><c-nrengcm><conr><conr>nnrengco><cnornnrefgco><conraneco><refgco><c-nrengcm><conr>><conraneco><cnornnrefgco><c-nrengcraneco><c-nrengcm>on> Step #5: artifact_prefix='./'; Test unit written to ./oom-142d0e0fc19902337888212aa53d51e8f91cb2a5 Step #5: Base64: PGNvbnJlbmdjbz48Y25vcm5ucmVmZ2NuPjxjb2Fybm5nY28+PGNub3JubnJlZmdjbz48Z2NvPjxjLW5yZW5nY20+PGNvbnI+PGNvbnI+bm5yZW5nY28+PGNub3JubnJlZmdjbz48Y29ucmFuZWNvPjxyZWZnY28+PGMtbnJlbmdjbT48Y29ucj4+PGNvbnJhbmVjbz48Y25vcm5ucmVmZ2NvPjxjLW5yZW5nY3JhbmVjbz48Yy1ucmVuZ2NtPm9uPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4850 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4170120370 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55566a238810, 0x55566a42201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55566a422020,0x55566c2ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/142d0e0fc19902337888212aa53d51e8f91cb2a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6110 processed earlier; will process 4919 files now Step #5: #1 pulse cov: 3969 ft: 3970 exec/s: 0 rss: 177Mb Step #5: ==174676== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555660d2d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555667392898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556673755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556673754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555660d33d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555660c94b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555660c8f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555660d25c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555663cf4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555663cf4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555663cf4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555663cf4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555663cf4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555663cf4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555663cf4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555663cf4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555663cf4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555663cf4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555665f89f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555662cb6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555662cc1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555662a6dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555662a6dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555662a6e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555662a6d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555662a6d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555662a6d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555667377abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555667380928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555667368699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555667393112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f91490f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555660c8db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x75,0x70,0x64,0x61,0x74,0x65,0x5d,0xa,0x63,0x6f,0x6d,0x70,0x61,0x74,0x69,0x62,0x6c,0x65,0x3d,0xf0,0x93,0x81,0x82,0xf0,0x93,0x82,0x82,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x83,0x82,0xf0,0x93,0x82,0x82,0xf0,0x93,0x82,0xab,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x83,0x82,0xf0,0x93,0x82,0x82,0xf0,0x93,0x89,0x82,0xf0,0x93,0x82,0x82,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0x82,0xf0,0x93,0x82,0x82,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0xab,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0x82,0xf0,0x93,0x82,0xab,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0xab,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0xb7,0xf0,0x93,0x82,0x82,0xf0,0x92,0x82,0x82,0xf0,0x93,0x82,0xb7,0xf0,0x93,0x82,0x82,0xf0,0x92,0x82,0x82,0xf0,0x93,0x82,0xab,0xf0,0x93,0x82,0x93,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0xab,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0xab,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0xab,0xf0,0x93,0x82,0x93,0xf0,0x93,0x82,0xb6,0xf0,0x93,0x82,0x82,0xf0,0x93,0x82,0x83,0xf0, Step #5: [update]\012compatible=\360\223\201\202\360\223\202\202\360\223\202\266\360\223\203\202\360\223\202\202\360\223\202\253\360\223\202\266\360\223\203\202\360\223\202\202\360\223\211\202\360\223\202\202\360\223\202\266\360\223\202\202\360\223\202\202\360\223\202\266\360\223\202\266\360\223\202\253\360\223\202\266\360\223\202\266\360\223\202\202\360\223\202\253\360\223\202\266\360\223\202\266\360\223\202\253\360\223\202\266\360\223\202\267\360\223\202\202\360\222\202\202\360\223\202\267\360\223\202\202\360\222\202\202\360\223\202\253\360\223\202\223\360\223\202\266\360\223\202\253\360\223\202\266\360\223\202\253\360\223\202\266\360\223\202\253\360\223\202\223\360\223\202\266\360\223\202\202\360\223\202\203\360 Step #5: artifact_prefix='./'; Test unit written to ./oom-5bfb5f68a3388565a5251790a0a2482d475e259b Step #5: Base64: W3VwZGF0ZV0KY29tcGF0aWJsZT3wk4GC8JOCgvCTgrbwk4OC8JOCgvCTgqvwk4K28JODgvCTgoLwk4mC8JOCgvCTgrbwk4KC8JOCgvCTgrbwk4K28JOCq/CTgrbwk4K28JOCgvCTgqvwk4K28JOCtvCTgqvwk4K28JOCt/CTgoLwkoKC8JOCt/CTgoLwkoKC8JOCq/CTgpPwk4K28JOCq/CTgrbwk4Kr8JOCtvCTgqvwk4KT8JOCtvCTgoLwk4KD8A== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4851 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4170687182 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f53d4a5810, 0x55f53d68f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f53d68f020,0x55f53f5270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5bfb5f68a3388565a5251790a0a2482d475e259b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6112 processed earlier; will process 4917 files now Step #5: ==174712== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f533f9a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f53a5ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f53a5e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f53a5e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f533fa0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f533f01b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f533efc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f533f92c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f536f61f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f536f61f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f536f61f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f536f61f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f536f61f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f536f61f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f536f61f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f536f61f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f536f61f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f536f61f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f5391f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f535f23b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f535f2ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f535cdac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f535cdac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f535cdb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f535cda874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f535cda874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f535cda874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f53a5e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f53a5ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f53a5d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f53a600112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c1774d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f533efab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x32,0xa,0x32,0xb,0x78,0x2e,0xa,0xa,0x78,0x6e,0x2e,0x75,0x75,0x75,0x75,0x4,0x10,0x31,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0x32,0x39,0x36,0x4,0xf3,0xa0,0x80,0xb9,0x14,0x33,0x32,0x37,0x36,0x38,0x2c,0x44,0x32,0x4,0x10,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x38,0x30,0x39,0xe2,0x81,0x9f,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x37,0xe2,0x80,0xab,0x39,0x32,0x32,0x33,0x33,0x7a,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x39,0x34,0x36,0x31,0x4,0x10,0x75,0x6d,0x65,0x74,0x61,0x64,0x7f,0x2,0x3f,0x54,0x31,0x43,0x48,0x0,0x43,0x6d,0x65,0x49,0x44,0x32,0xe,0xfe,0xff,0x4,0x10,0x75,0x75,0x75,0x75,0xe2,0x80,0xa8,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x75,0x75,0x75,0x75,0x4,0x10,0x31,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x33,0x4,0x10,0x33,0x32,0x37,0x36,0x39,0x2c,0x44,0x4,0x33,0x10,0x75,0x75,0x75,0x75,0xca,0xb0,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0xa, Step #5: 2\0122\013x.\012\012xn.uuuu\004\0201uuuumID4294967296\004\363\240\200\271\02432768,D2\004\0209223372036854775809\342\201\2374607431768211457\342\200\25392233z2036854779461\004\020umetad\177\002?T1CH\000CmeID2\016\376\377\004\020uuuu\342\200\250uuuumIDuuuu\004\0201uuuumID3\004\02032769,D\0043\020uuuu\312\260uuuumID\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-7c256e3493e96f3292cd81c1293554b192bbec4f Step #5: Base64: MgoyC3guCgp4bi51dXV1BBAxdXV1dW1JRDQyOTQ5NjcyOTYE86CAuRQzMjc2OCxEMgQQOTIyMzM3MjAzNjg1NDc3NTgwOeKBnzQ2MDc0MzE3NjgyMTE0NTfigKs5MjIzM3oyMDM2ODU0Nzc5NDYxBBB1bWV0YWR/Aj9UMUNIAENtZUlEMg7+/wQQdXV1deKAqHV1dXVtSUR1dXV1BBAxdXV1dW1JRDMEEDMyNzY5LEQEMxB1dXV1yrB1dXV1bUlECg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4852 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4171217666 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564193a54810, 0x564193c3e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564193c3e020,0x564195ad60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7c256e3493e96f3292cd81c1293554b192bbec4f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6113 processed earlier; will process 4916 files now Step #5: ==174748== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56418a5499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564190bae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564190b915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564190b914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56418a54fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56418a4b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56418a4ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56418a541c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56418d510f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56418d510f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56418d510f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56418d510f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56418d510f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56418d510f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56418d510f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56418d510f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56418d510f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56418d510f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56418f7a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56418c4d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56418c4ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56418c289c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56418c289c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56418c28a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56418c289874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56418c289874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56418c289874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564190b93abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564190b9c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564190b84699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564190baf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a87ae0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56418a4a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x73,0x67,0x74,0x43,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x2d,0x54,0x79,0x70,0x65,0x3a,0x64,0x3b,0xd,0xe2,0x81,0x9f,0xc,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xf2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xc,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xc,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xc,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0xd,0xd,0x9f,0x81, Step #5: }sgtContent-Type:d;\015\342\201\237\014\015\342\201\237\342\201\237\342\201\237\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\342\201\237\342\201\237\015\362\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\014\342\201\237\015\342\201\237\014\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\014\015\342\201\237\342\201\237\342\201\237\342\201\237\342\201\237\015\342\201\237\342\201\237\342\201\237\342\201\237\342\201\237\015\342\201\237\342\201\237\342\201\015\015\237\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-bf1b722ae52e1558ae6a1d7e779c507fe75d8beb Step #5: Base64: fXNndENvbnRlbnQtVHlwZTpkOw3igZ8MDeKBn+KBn+KBn+KBn+KBnw3igZ/igZ8N4oGf4oGfDeKBn+KBnw3igZ/igZ/igZ/igZ8N8oGf4oGfDeKBn+KBnw3igZ/igZ8N4oGf4oGfDeKBnwzigZ8N4oGfDA3igZ/igZ8N4oGf4oGfDeKBn+KBnw3igZ/igZ8N4oGfDA3igZ/igZ/igZ/igZ/igZ8N4oGf4oGf4oGf4oGf4oGfDeKBn+KBn+KBDQ2fgQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4853 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4171746007 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f8a25ca810, 0x55f8a27b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f8a27b4020,0x55f8a464c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf1b722ae52e1558ae6a1d7e779c507fe75d8beb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6114 processed earlier; will process 4915 files now Step #5: ==174784== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8990bf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f89f724898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f89f7075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f89f7074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8990c5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f899026b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f899021355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8990b7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f89c086f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f89c086f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f89c086f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f89c086f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f89c086f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f89c086f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f89c086f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f89c086f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f89c086f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f89c086f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f89e31bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f89b048b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f89b053be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f89adffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f89adffc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f89ae00738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f89adff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f89adff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f89adff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f89f709abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f89f712928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f89f6fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f89f725112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf2a14c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f89901fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x73,0x67,0x74,0x43,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x2d,0x54,0x79,0x70,0x65,0x3a,0x64,0x3b,0xd,0xe2,0x81,0x9f,0xc,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xc,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xc,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xc,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0xd,0xd,0x9f,0x81, Step #5: }sgtContent-Type:d;\015\342\201\237\014\015\342\201\237\342\201\237\342\201\237\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\014\342\201\237\015\342\201\237\014\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\014\015\342\201\237\342\201\237\342\201\237\342\201\237\342\201\237\015\342\201\237\342\201\237\342\201\237\342\201\237\342\201\237\015\342\201\237\342\201\237\342\201\015\015\237\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-b37d988d7d72990322646208379a95d86f237fe7 Step #5: Base64: fXNndENvbnRlbnQtVHlwZTpkOw3igZ8MDeKBn+KBn+KBn+KBn+KBnw3igZ/igZ8N4oGf4oGfDeKBn+KBnw3igZ/igZ/igZ/igZ8N4oGf4oGfDeKBn+KBnw3igZ/igZ8N4oGf4oGfDeKBnwzigZ8N4oGfDA3igZ/igZ8N4oGf4oGfDeKBn+KBnw3igZ/igZ8N4oGfDA3igZ/igZ/igZ/igZ/igZ8N4oGf4oGf4oGf4oGf4oGfDeKBn+KBn+KBDQ2fgQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4854 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4172270218 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55683d6cb810, 0x55683d8b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55683d8b5020,0x55683f74d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b37d988d7d72990322646208379a95d86f237fe7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6115 processed earlier; will process 4914 files now Step #5: ==174820== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5568341c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55683a825898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55683a8085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55683a8084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5568341c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556834127b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556834122355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5568341b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556837187f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556837187f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556837187f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556837187f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556837187f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556837187f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556837187f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556837187f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556837187f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556837187f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55683941cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556836149b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556836154be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556835f00c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556835f00c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556835f01738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556835f00874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556835f00874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556835f00874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55683a80aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55683a813928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55683a7fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55683a826112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc9b6628082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556834120b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd0,0xb0,0xa,0xd0,0x9f,0xa,0xd2,0xa8,0xa,0xd0,0xb8,0xa,0xdd,0xb0,0xa,0xd0,0x9f,0xa,0xdb,0xb8,0xa,0xd4,0xb8,0xa,0xd0,0xa8,0xa,0xd0,0xb8,0xa,0xd0,0xaa,0xa,0xd2,0xb8,0xa,0xd3,0xb8,0xa,0xd0,0xba,0xa,0xd0,0xa8,0xa,0xd0,0xb8,0xa,0xd0,0xaa,0xa,0xdc,0xb8,0xa,0xd0,0xb8,0xa,0xd0,0xb0,0xa,0xd0,0x9f,0xa,0xdf,0xb8,0xa,0xd4,0xb8,0xa,0xd0,0xbc,0xa,0xd1,0xb9,0xa,0xcf,0xa8,0xa,0xd0,0xb8,0xa,0xd0,0x9f,0xa,0xd2,0xa8,0xa,0xd0,0xb8,0xa,0xd0,0xb0,0xa,0xd0,0x9f,0xa,0xdf,0xb8,0xa,0xd4,0xb8,0xa,0xd0,0xa8,0xa,0xd0,0xb8,0xa,0xd0,0xaa,0xa,0xd2,0xbc,0xa,0xd4,0xb9,0xa,0xd0,0xba,0xa,0xd0,0xa8,0xa,0xd0,0xb8,0xa,0xcf,0xaa,0xa,0xdc,0xb8,0xa,0xd0,0xb8,0xa,0xcf,0xb0,0xa,0xd0,0x9f,0xa,0xdf,0xb8,0xa,0xd0,0xaa,0xa,0xd2,0xb8,0xa,0xd4,0xb8,0xa,0xd0,0xba,0xa,0xd0,0xa9,0xa,0xd0,0xb8,0xa,0xd0,0xaa,0xa,0xd0,0xa8,0xa,0xd0,0xb8,0xa,0xdc,0xb8,0xa,0xd0,0xb8,0xa,0xd0,0xb0,0xa,0xd0,0x9f,0xa,0xdf,0x8f,0xa,0xcf,0xaf,0xa,0xc3,0x8f,0xa,0xc3,0xaf, Step #5: \320\260\012\320\237\012\322\250\012\320\270\012\335\260\012\320\237\012\333\270\012\324\270\012\320\250\012\320\270\012\320\252\012\322\270\012\323\270\012\320\272\012\320\250\012\320\270\012\320\252\012\334\270\012\320\270\012\320\260\012\320\237\012\337\270\012\324\270\012\320\274\012\321\271\012\317\250\012\320\270\012\320\237\012\322\250\012\320\270\012\320\260\012\320\237\012\337\270\012\324\270\012\320\250\012\320\270\012\320\252\012\322\274\012\324\271\012\320\272\012\320\250\012\320\270\012\317\252\012\334\270\012\320\270\012\317\260\012\320\237\012\337\270\012\320\252\012\322\270\012\324\270\012\320\272\012\320\251\012\320\270\012\320\252\012\320\250\012\320\270\012\334\270\012\320\270\012\320\260\012\320\237\012\337\217\012\317\257\012\303\217\012\303\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-6594e6e82bdbca7d509e431e3823554c09f94ded Step #5: Base64: 0LAK0J8K0qgK0LgK3bAK0J8K27gK1LgK0KgK0LgK0KoK0rgK07gK0LoK0KgK0LgK0KoK3LgK0LgK0LAK0J8K37gK1LgK0LwK0bkKz6gK0LgK0J8K0qgK0LgK0LAK0J8K37gK1LgK0KgK0LgK0KoK0rwK1LkK0LoK0KgK0LgKz6oK3LgK0LgKz7AK0J8K37gK0KoK0rgK1LgK0LoK0KkK0LgK0KoK0KgK0LgK3LgK0LgK0LAK0J8K348Kz68Kw48Kw68= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4855 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4172810772 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cbf4992810, 0x55cbf4b7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cbf4b7c020,0x55cbf6a140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6594e6e82bdbca7d509e431e3823554c09f94ded' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6116 processed earlier; will process 4913 files now Step #5: ==174856== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cbeb4879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cbf1aec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cbf1acf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cbf1acf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cbeb48dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cbeb3eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cbeb3e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cbeb47fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cbee44ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cbee44ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cbee44ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cbee44ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cbee44ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cbee44ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cbee44ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cbee44ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cbee44ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cbee44ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cbf06e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cbed410b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cbed41bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cbed1c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cbed1c7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cbed1c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cbed1c7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cbed1c7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cbed1c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cbf1ad1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cbf1ada928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cbf1ac2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cbf1aed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0fd5e12082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cbeb3e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe3,0x80,0x88,0x2d,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x0,0x60,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x73,0x20,0x5b,0x38,0x20,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xb,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x68,0x74,0xe2,0x80,0x88,0x2d,0x0,0x60,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xa,0x2f,0xa,0x2f,0xa,0x60,0x68,0x20,0x20,0x20,0x68,0xa,0x9, Step #5: `\343\200\210-dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd\000`hhhhhhhhs [8 \012=\012=\012=\012=\012=\013\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=ht\342\200\210-\000``\342\200\210-\000`\012/\012`\342\200\210-\000`\012\012/\012/\012`h h\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-212e907b922d28324c1895193506a64677fb0490 Step #5: Base64: YOOAiC1kZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGQAYGhoaGhoaGhocyBbOCAKPQo9Cj0KPQo9Cwo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj1odOKAiC0AYGDigIgtAGAKLwpg4oCILQBgCgovCi8KYGggICBoCgk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4856 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4173469447 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558acebcd810, 0x558acedb701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558acedb7020,0x558ad0c4f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/212e907b922d28324c1895193506a64677fb0490' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6117 processed earlier; will process 4912 files now Step #5: ==174892== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558ac56c29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558acbd27898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558acbd0a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558acbd0a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558ac56c8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558ac5629b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558ac5624355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558ac56bac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558ac8689f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558ac8689f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558ac8689f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558ac8689f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558ac8689f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558ac8689f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558ac8689f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558ac8689f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558ac8689f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558ac8689f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558aca91ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ac764bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ac7656be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ac7402c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ac7402c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ac7403738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ac7402874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ac7402874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ac7402874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558acbd0cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558acbd15928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558acbcfd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558acbd28112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efe4c6b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558ac5622b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x17,0x44,0x0,0x0,0x0,0x66,0x66,0x68,0x66,0x68,0x6d,0x74,0x78,0x1d,0x44,0x44,0x17,0x44,0x0,0x0,0x0,0x66,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x66,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x17,0x44,0x0,0x0,0x0,0x66,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x66,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x17,0x44,0x0,0x0,0x0,0x66,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x66,0x68,0x66,0x68,0x6d,0x74,0x78,0x1d,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44, Step #5: \027D\000\000\000ffhfhmtx\035DD\027D\000\000\000f\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000f\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\027D\000\000\000f\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000f\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\027D\000\000\000f\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000fhfhmtx\035DDDDDDDDDDDDDDDDDD Step #5: artifact_prefix='./'; Test unit written to ./oom-138a83c69b913b383fc2a3fbe67ee187b816c9a7 Step #5: Base64: F0QAAABmZmhmaG10eB1ERBdEAAAAZgAAAAAAAAAAAAAAAAAAAAAAAAAAAGYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAXRAAAAGYAAAAAAAAAAAAAAAAAAAAAAAAAAABmAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAF0QAAABmAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAZmhmaG10eB1EREREREREREREREREREREREQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4857 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4173998141 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f6064f1810, 0x55f6066db01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f6066db020,0x55f6085730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/138a83c69b913b383fc2a3fbe67ee187b816c9a7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6118 processed earlier; will process 4911 files now Step #5: ==174928== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f5fcfe69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f60364b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f60362e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f60362e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f5fcfecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f5fcf4db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f5fcf48355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f5fcfdec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f5fffadf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f5fffadf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f5fffadf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f5fffadf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f5fffadf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f5fffadf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f5fffadf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f5fffadf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f5fffadf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f5fffadf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f602242f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f5fef6fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f5fef7abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f5fed26c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f5fed26c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f5fed27738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f5fed26874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f5fed26874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f5fed26874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f603630abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f603639928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f603621699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f60364c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb24738b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f5fcf46b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x88,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x60,0x33,0xb,0x0,0xa,0xa,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0x31,0x34,0x35,0x35,0x2f,0x60,0xa,0x20,0x20,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x83,0xba,0x2f,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0xb,0x7e,0x60,0xa,0xa,0x31,0x2f,0x60,0xa,0x20,0x20,0x60,0x20,0x60,0xa,0x9,0x60,0x20,0x60,0xa,0x9, Step #5: `\342\210\210-\000`\012\363\240\201\272/\012`\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000\000\000\000\000\000`3\013\000\012\0124028236692093846346337460743176821\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\0151455/`\012 `\342\200\210-\000`\012\363\240\201\272\363\240\203\272/\001\000\000\000\000\000\000\013~`\012\0121/`\012 ` `\012\011` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-cd012e836a475fb21f117730f92e05c437dcb07e Step #5: Base64: YOKIiC0AYArzoIG6Lwpg4oCILQBgCvOggbrzoIG6LwEAAAAAAABgMwsACgo0MDI4MjM2NjkyMDkzODQ2MzQ2MzM3NDYwNzQzMTc2ODIxDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0xNDU1L2AKICBg4oCILQBgCvOggbrzoIO6LwEAAAAAAAALfmAKCjEvYAogIGAgYAoJYCBgCgk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4858 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4174657393 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563f5b808810, 0x563f5b9f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563f5b9f2020,0x563f5d88a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd012e836a475fb21f117730f92e05c437dcb07e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6119 processed earlier; will process 4910 files now Step #5: ==174964== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563f522fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563f58962898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563f589455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563f589454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563f52303d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563f52264b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563f5225f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563f522f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563f552c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563f552c4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563f552c4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563f552c4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563f552c4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563f552c4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563f552c4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563f552c4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563f552c4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563f552c4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563f57559f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563f54286b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563f54291be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563f5403dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563f5403dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563f5403e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563f5403d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563f5403d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563f5403d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563f58947abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563f58950928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563f58938699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563f58963112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f65f4498082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563f5225db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x76,0x61,0x72,0x20,0x74,0x72,0x69,0x6d,0x45,0x6e,0x64,0x20,0x3d,0x20,0x53,0x74,0x72,0x69,0x6e,0x67,0x2e,0x70,0x72,0x6f,0x74,0x6f,0x74,0x79,0x70,0x65,0x2e,0x74,0x72,0x69,0x6d,0x45,0x6e,0x64,0x3b,0xa,0x76,0x61,0x72,0x20,0x6c,0x74,0x20,0x3d,0x20,0x27,0x5c,0x75,0x30,0x30,0x30,0x41,0x5c,0x75,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x32,0x30,0x32,0x3a,0x27,0x3b,0xa,0x76,0x61,0x72,0x20,0x73,0x74,0x72,0x20,0x3d,0x20,0x6c,0x74,0x20,0x2b,0x20,0x27,0x61,0x27,0x20,0x2b,0x20,0x6c,0x74,0x20,0x2b,0x20,0x27,0x62,0x27,0x20,0x2b,0x20,0x6c,0x74,0x3b,0xa,0x76,0x61,0x72,0x20,0x65,0x78,0x70,0x65,0x63,0x74,0x65,0x64,0x20,0x3d,0x20,0x6c,0x74,0x20,0x2b,0x20,0x27,0x61,0x27,0x20,0x2b,0x20,0x6c,0x74,0x20,0x2b,0x20,0x27,0x62,0x27,0x3b,0xa,0x61,0x73,0x73,0x65,0x72,0x74,0x2e,0x73,0x61,0x6d,0x65,0x56,0x61,0x6c,0x75,0x65,0x28,0xa,0x20,0x20,0x74,0x72,0x69,0x6d,0x45,0x6e,0x64,0x2e,0x63,0x61,0x6c,0x6c,0x28,0x73,0x74,0x72,0x29,0x2c,0xa,0x20,0x20,0xa,0x29,0x3b,0xa, Step #5: var trimEnd = String.prototype.trimEnd;\012var lt = '\\u000A\\u000000000000202:';\012var str = lt + 'a' + lt + 'b' + lt;\012var expected = lt + 'a' + lt + 'b';\012assert.sameValue(\012 trimEnd.call(str),\012 \012);\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-b405fe1e38cf785eecef66d4b454224783bdeac2 Step #5: Base64: dmFyIHRyaW1FbmQgPSBTdHJpbmcucHJvdG90eXBlLnRyaW1FbmQ7CnZhciBsdCA9ICdcdTAwMEFcdTAwMDAwMDAwMDAwMDIwMjonOwp2YXIgc3RyID0gbHQgKyAnYScgKyBsdCArICdiJyArIGx0Owp2YXIgZXhwZWN0ZWQgPSBsdCArICdhJyArIGx0ICsgJ2InOwphc3NlcnQuc2FtZVZhbHVlKAogIHRyaW1FbmQuY2FsbChzdHIpLAogIAopOwo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4859 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4175185687 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5570ef083810, 0x5570ef26d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5570ef26d020,0x5570f11050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b405fe1e38cf785eecef66d4b454224783bdeac2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6120 processed earlier; will process 4909 files now Step #5: #1 pulse cov: 3995 ft: 3996 exec/s: 0 rss: 177Mb Step #5: ==175000== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5570e5b789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5570ec1dd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5570ec1c05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5570ec1c04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5570e5b7ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5570e5adfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5570e5ada355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5570e5b70c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5570e8b3ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5570e8b3ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5570e8b3ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5570e8b3ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5570e8b3ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5570e8b3ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5570e8b3ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5570e8b3ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5570e8b3ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5570e8b3ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5570eadd4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5570e7b01b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5570e7b0cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5570e78b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5570e78b8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5570e78b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5570e78b8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5570e78b8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5570e78b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5570ec1c2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5570ec1cb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5570ec1b3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5570ec1de112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f029d33d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5570e5ad8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x6f,0x63,0x69,0x56,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x31,0x2e,0x30,0x2e,0x30,0x22,0x2c,0x22,0x6c,0x69,0x6e,0x75,0x78,0x22,0x3a,0x7b,0x22,0x63,0x67,0x72,0x6f,0x75,0x70,0x73,0x50,0x61,0x74,0x68,0x22,0x3a,0x22,0x2e,0x2d,0x68,0x7a,0x75,0x2d,0x33,0x2d,0x31,0x32,0x36,0x2d,0x43,0x2d,0x74,0x2d,0x6d,0x2d,0x43,0x70,0x63,0x75,0x2d,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x32,0x32,0x30,0x36,0x32,0x68,0x2d,0x34,0x2d,0x43,0x2d,0x70,0x2d,0x6d,0x2d,0x6d,0x2d,0x66,0x2d,0x6d,0x2d,0x6d,0x2d,0x66,0x2d,0x43,0x70,0x63,0x75,0x2d,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x32,0x32,0x30,0x36,0x32,0x68,0x2d,0x34,0x2d,0x43,0x2d,0x70,0x2d,0x6d,0x2d,0x6d,0x2d,0x66,0x2d,0x6d,0x2d,0x6d,0x2d,0x66,0x2d,0x43,0x2d,0x68,0x2d,0x70,0x2d,0x43,0x2d,0x61,0x2d,0x43,0x2d,0x70,0x2d,0x43,0x2d,0x70,0x2d,0x6d,0x2d,0x6d,0x2d,0x66,0x2d,0x43,0x2d,0x68,0x2d,0x6d,0x2d,0x7a,0x2d,0x66,0x2e,0x73,0x6c,0x69,0x63,0x65,0x22,0x7d,0x7d, Step #5: {\"ociVersion\":\"1.0.0\",\"linux\":{\"cgroupsPath\":\".-hzu-3-126-C-t-m-Cpcu-9223372036854722062h-4-C-p-m-m-f-m-m-f-Cpcu-9223372036854722062h-4-C-p-m-m-f-m-m-f-C-h-p-C-a-C-p-C-p-m-m-f-C-h-m-z-f.slice\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-7e3d1cc51098fa8f1c8b677995d509180203cdf4 Step #5: Base64: eyJvY2lWZXJzaW9uIjoiMS4wLjAiLCJsaW51eCI6eyJjZ3JvdXBzUGF0aCI6Ii4taHp1LTMtMTI2LUMtdC1tLUNwY3UtOTIyMzM3MjAzNjg1NDcyMjA2MmgtNC1DLXAtbS1tLWYtbS1tLWYtQ3BjdS05MjIzMzcyMDM2ODU0NzIyMDYyaC00LUMtcC1tLW0tZi1tLW0tZi1DLWgtcC1DLWEtQy1wLUMtcC1tLW0tZi1DLWgtbS16LWYuc2xpY2UifX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4860 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4175754135 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e80bc35810, 0x55e80be1f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e80be1f020,0x55e80dcb70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7e3d1cc51098fa8f1c8b677995d509180203cdf4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6122 processed earlier; will process 4907 files now Step #5: ==175036== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e80272a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e808d8f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e808d725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e808d724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e802730d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e802691b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e80268c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e802722c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e8056f1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e8056f1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e8056f1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e8056f1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e8056f1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e8056f1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e8056f1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e8056f1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e8056f1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e8056f1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e807986f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e8046b3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e8046bebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e80446ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e80446ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e80446b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e80446a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e80446a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e80446a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e808d74abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e808d7d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e808d65699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e808d90112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a23275082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e80268ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x58,0x20,0x76,0x3f,0x3e,0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0x20,0x73,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0x20,0x25,0x20,0x78,0x78,0x20,0x53,0x59,0x53,0x54,0x45,0x4d,0xa,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x64,0x3a,0x2b,0x78,0x3b,0x25,0x7c,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x3b,0x30,0x3a,0x4d,0x5d,0x50,0x2d,0x3e,0x27,0x3e,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0x25,0x78,0x78,0x3b,0xdd, Step #5: <?X v?><!DOCTYPE s[<!ENTITY % xx SYSTEM\012'http://wp://wwd:+x;%|x;%xx;%xx;%;0:M]P->'>%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%xx;%x;%xx;%xx;%xx;%xx;%xx;%xx;\335 Step #5: artifact_prefix='./'; Test unit written to ./oom-f9ae78132aae2db9c3b60599ce95821e4dd83eb5 Step #5: Base64: PD9YIHY/PjwhRE9DVFlQRSBzWzwhRU5USVRZICUgeHggU1lTVEVNCidodHRwOi8vd3A6Ly93d2Q6K3g7JXx4OyV4eDsleHg7JTswOk1dUC0+Jz4leHg7JXh4OyV4eDsleHg7JXh4OyV4eDsleHg7JXh4OyV4eDsleHg7JXh4OyV4eDsleHg7JXh4OyV4eDsleHg7JXh4OyV4eDsleHg7JXh4OyV4eDsleDsleHg7JXh4OyV4eDsleHg7JXh4OyV4eDvd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4861 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4176279812 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cd00f3e810, 0x55cd0112801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cd01128020,0x55cd02fc00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9ae78132aae2db9c3b60599ce95821e4dd83eb5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6123 processed earlier; will process 4906 files now Step #5: ==175072== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ccf7a339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ccfe098898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ccfe07b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ccfe07b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ccf7a39d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ccf799ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ccf7995355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ccf7a2bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ccfa9faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ccfa9faf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ccfa9faf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ccfa9faf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ccfa9faf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ccfa9faf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ccfa9faf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ccfa9faf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ccfa9faf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ccfa9faf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ccfcc8ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ccf99bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ccf99c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ccf9773c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ccf9773c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ccf9774738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ccf9773874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ccf9773874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ccf9773874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ccfe07dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ccfe086928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ccfe06e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ccfe099112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff933ae8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ccf7993b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x0,0x3e,0x41,0x38,0x60,0x5b,0x2e,0x2e,0x30,0x33,0x30,0x2a,0x30,0x39,0x38,0x31,0x30,0x2d,0x33,0x5d,0x2d,0x60,0x33,0xef,0xbf,0xbf,0xdd,0xa4,0x21,0x60,0x5b,0x30,0x2d,0x32,0x5d,0x2d,0x60,0xef,0xbf,0xbf,0xd5,0xa4,0x21,0x60,0x5b,0x30,0x26,0x31,0x31,0x2d,0x33,0x39,0x2a,0x33,0x30,0x2f,0x31,0x30,0x2d,0x33,0x5d,0x2d,0x60,0x33,0xef,0xbf,0xbf,0xdd,0xa4,0x21,0x60,0x5b,0x30,0x2d,0x32,0x5d,0x2d,0x60,0xef,0xbf,0xbf,0xd5,0xa4,0x21,0x60,0x5b,0x30,0x26,0x30,0x2d,0x33,0x38,0x2a,0x33,0x30,0x30,0x31,0x30,0x2d,0x33,0x5d,0x2d,0x60,0x33,0xef,0xbf,0xbf,0xdd,0xa4,0x21,0x60,0x5b,0x30,0x2d,0x32,0x5d,0x2d,0x60,0xe0,0xbf,0xbf,0xd5,0xa4,0x21,0x60,0x5b,0x30,0x26,0x31,0x32,0x37,0x5d,0x2d,0x60,0x7a,0xef,0xbf,0xbf,0xd5,0xa4,0x21,0x60,0x5b,0x31,0x2d,0x33,0x5d,0xa4,0xef,0x26,0x90,0x2d,0x60,0x73,0x21,0x60,0x5b,0x32,0x35,0x37,0x2d,0x5b,0x60,0x73,0x21,0x60,0x5b,0x32,0x38,0x0,0x2d,0x5b,0xa4,0x21,0x0,0x0,0x2d,0x32,0x32,0xff,0x2d,0xff,0xfc,0x2a,0x39,0x33,0x33,0x5d,0x65,0x92,0x0,0xc0,0x99,0xba, Step #5: `\000>A8`[..030*09810-3]-`3\357\277\277\335\244!`[0-2]-`\357\277\277\325\244!`[0&11-39*30/10-3]-`3\357\277\277\335\244!`[0-2]-`\357\277\277\325\244!`[0&0-38*30010-3]-`3\357\277\277\335\244!`[0-2]-`\340\277\277\325\244!`[0&127]-`z\357\277\277\325\244!`[1-3]\244\357&\220-`s!`[257-[`s!`[28\000-[\244!\000\000-22\377-\377\374*933]e\222\000\300\231\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-0c56e862f3af9c41159789e9afa156c3831ba333 Step #5: Base64: YAA+QThgWy4uMDMwKjA5ODEwLTNdLWAz77+/3aQhYFswLTJdLWDvv7/VpCFgWzAmMTEtMzkqMzAvMTAtM10tYDPvv7/dpCFgWzAtMl0tYO+/v9WkIWBbMCYwLTM4KjMwMDEwLTNdLWAz77+/3aQhYFswLTJdLWDgv7/VpCFgWzAmMTI3XS1geu+/v9WkIWBbMS0zXaTvJpAtYHMhYFsyNTctW2BzIWBbMjgALVukIQAALTIy/y3//Co5MzNdZZIAwJm6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4862 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4176937660 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562586868810, 0x562586a5201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562586a52020,0x5625888ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0c56e862f3af9c41159789e9afa156c3831ba333' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6124 processed earlier; will process 4905 files now Step #5: ==175108== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56257d35d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5625839c2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625839a55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625839a54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56257d363d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56257d2c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56257d2bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56257d355c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562580324f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562580324f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562580324f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562580324f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562580324f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562580324f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562580324f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562580324f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562580324f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562580324f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5625825b9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56257f2e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56257f2f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56257f09dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56257f09dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56257f09e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56257f09d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56257f09d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56257f09d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5625839a7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5625839b0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562583998699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5625839c3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f765ab5a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56257d2bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x0,0x3e,0x41,0x38,0x60,0x5b,0x2e,0x2e,0x30,0x33,0x30,0x2a,0x30,0x39,0x38,0x31,0x30,0x2d,0x33,0x5d,0x2d,0x60,0x33,0xef,0xbf,0xbf,0xdd,0xa4,0x21,0x60,0x5b,0x35,0x2d,0x32,0x5d,0x2d,0x60,0xef,0xbf,0xbf,0xd5,0xa4,0x21,0x60,0x5b,0x2d,0x31,0x39,0x30,0x31,0x26,0x33,0x2a,0x33,0x30,0x2f,0x31,0x30,0x2d,0x33,0x5d,0x2d,0x60,0x33,0xef,0xbf,0xbf,0xdd,0xa4,0x21,0x60,0x5b,0x30,0x25,0x32,0x5d,0x2d,0x60,0xef,0xbf,0xbf,0xd5,0xa4,0x21,0x60,0x5b,0x30,0x26,0x30,0x2d,0x33,0x38,0x2a,0x33,0x30,0x30,0x31,0x30,0x2d,0x33,0x5d,0x2d,0x60,0x31,0xef,0xbf,0xbf,0xdd,0xa4,0x21,0x60,0x5b,0x30,0x2d,0x32,0x5d,0x2d,0x60,0xe0,0xbf,0xbf,0xd5,0xa4,0x21,0x60,0x5b,0x30,0x26,0x31,0x32,0x37,0x5d,0x2d,0x60,0x7a,0xef,0xbf,0xbf,0xd5,0xa4,0x21,0x60,0x5b,0x31,0x2d,0x30,0x26,0x31,0x31,0x2d,0x33,0x39,0x2a,0x33,0x30,0x2f,0x31,0x30,0x2d,0x33,0x5d,0x2d,0x60,0x33,0xef,0xbf,0xbf,0xdd,0xa4,0x21,0x60,0x5b,0x30,0x2d,0x32,0x5d,0x2d,0x60,0xef,0xbf,0xbf,0xd5,0xa4,0x21,0x60,0x5b,0x30,0x26,0x30,0x2d,0x0,0xc0,0x99,0xba, Step #5: `\000>A8`[..030*09810-3]-`3\357\277\277\335\244!`[5-2]-`\357\277\277\325\244!`[-1901&3*30/10-3]-`3\357\277\277\335\244!`[0%2]-`\357\277\277\325\244!`[0&0-38*30010-3]-`1\357\277\277\335\244!`[0-2]-`\340\277\277\325\244!`[0&127]-`z\357\277\277\325\244!`[1-0&11-39*30/10-3]-`3\357\277\277\335\244!`[0-2]-`\357\277\277\325\244!`[0&0-\000\300\231\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-21c7dadac9936a6aac38200fe27ef052e4420c6a Step #5: Base64: YAA+QThgWy4uMDMwKjA5ODEwLTNdLWAz77+/3aQhYFs1LTJdLWDvv7/VpCFgWy0xOTAxJjMqMzAvMTAtM10tYDPvv7/dpCFgWzAlMl0tYO+/v9WkIWBbMCYwLTM4KjMwMDEwLTNdLWAx77+/3aQhYFswLTJdLWDgv7/VpCFgWzAmMTI3XS1geu+/v9WkIWBbMS0wJjExLTM5KjMwLzEwLTNdLWAz77+/3aQhYFswLTJdLWDvv7/VpCFgWzAmMC0AwJm6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4863 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4177592748 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610cc8c3810, 0x5610ccaad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610ccaad020,0x5610ce9450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/21c7dadac9936a6aac38200fe27ef052e4420c6a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6125 processed earlier; will process 4904 files now Step #5: #1 pulse cov: 4540 ft: 4541 exec/s: 0 rss: 177Mb Step #5: ==175144== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5610c33b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610c9a1d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610c9a005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610c9a004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610c33bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610c331fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610c331a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610c33b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610c637ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610c637ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610c637ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610c637ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610c637ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610c637ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610c637ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610c637ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610c637ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610c637ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610c8614f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610c5341b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610c534cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610c50f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610c50f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610c50f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610c50f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610c50f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610c50f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610c9a02abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610c9a0b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610c99f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610c9a1e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f82261c4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610c3318b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x8b,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x8b,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x8b,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5,0xe1,0xac,0x91,0xe1,0xac,0xb5, Step #5: ws:\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\213\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\213\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\213\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265\341\254\221\341\254\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-d6186cbfe2262865b2f9de58f1515ef9e4aebeea Step #5: Base64: d3M64ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayL4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayL4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay14ayL4ay14ayR4ay14ayR4ay14ayR4ay14ayR4ay1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4864 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4178161646 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d3c2292810, 0x55d3c247c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d3c247c020,0x55d3c43140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d6186cbfe2262865b2f9de58f1515ef9e4aebeea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6127 processed earlier; will process 4902 files now Step #5: #1 pulse cov: 3925 ft: 3926 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4300 ft: 4764 exec/s: 0 rss: 178Mb Step #5: ==175180== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d3b8d879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d3bf3ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d3bf3cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d3bf3cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d3b8d8dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d3b8ceeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d3b8ce9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d3b8d7fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d3bbd4ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d3bbd4ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d3bbd4ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d3bbd4ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d3bbd4ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d3bbd4ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d3bbd4ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d3bbd4ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d3bbd4ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d3bbd4ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d3bdfe3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d3bad10b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d3bad1bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d3baac7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d3baac7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d3baac8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d3baac7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d3baac7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d3baac7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d3bf3d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d3bf3da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d3bf3c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d3bf3ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa003d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d3b8ce7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x23,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0xc0,0xa4,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x23,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0x24,0xf3,0xf3,0xa0,0x81,0x8f,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0x24,0x3d, Step #5: \014$$$$$$$$$$$$#$$$$\363\240\201\243$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$\300\244$$\363\240\201\243$$#$$\363\240\201\243$$$$$$\363\363\240\201\217\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$$= Step #5: artifact_prefix='./'; Test unit written to ./oom-e0a5ad07414c8713953ae22516af62cbcc7cc6a1 Step #5: Base64: DCQkJCQkJCQkJCQkJCMkJCQk86CBoyQkJCTzoIGjJCQkJCTzoIGjJCQkJCTzoIGjJCQkJCTzoIGjJCQkJCTzoIGjJCQkJCTzoIGjJCQkJCTzgaMkJCQkJPOggaMkJCQkJPOggaMkJCQkJPOggaMkJMCkJCTzoIGjJCQjJCTzoIGjJCQkJCQk8/OggY+ggaMkJCQkJPOggaMkJCQkJPOggaMkJCQkJPOggaMkJCQkJPOggaMkJCQkJPOggaMkJCQkJCQ9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4865 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4178767772 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563febd12810, 0x563febefc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563febefc020,0x563fedd940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e0a5ad07414c8713953ae22516af62cbcc7cc6a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6130 processed earlier; will process 4899 files now Step #5: ==175216== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563fe28079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563fe8e6c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563fe8e4f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563fe8e4f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563fe280dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563fe276eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563fe2769355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563fe27ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563fe57cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563fe57cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563fe57cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563fe57cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563fe57cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563fe57cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563fe57cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563fe57cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563fe57cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563fe57cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563fe7a63f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563fe4790b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563fe479bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563fe4547c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563fe4547c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563fe4548738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563fe4547874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563fe4547874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563fe4547874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563fe8e51abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563fe8e5a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563fe8e42699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563fe8e6d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb8c5611082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563fe2767b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x5b,0x7c,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x32,0xd,0x44,0x44,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x32,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x39,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xf3,0xa0,0x81,0xa7,0x61,0x5c,0x23,0x73,0x63,0xc,0x68,0x23,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3c,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x7d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa, Step #5: D[|''/''''''2\015DD````````2\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\0129\012=\012=\012=\012=\012=\012\012=\363\240\201\247a\\#sc\014h#\012=\012=\012=\012=\012=\012=\012=\012=\012=\012<\012=\012=\012=\012=\012=\012\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012}\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=````````D\012=\012=\012=\012=\012=\012=\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-5bf1433d2566549142ff3823484ed758dc696755 Step #5: Base64: RFt8JycvJycnJycnMg1ERGBgYGBgYGBgMgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9CjkKPQo9Cj0KPQo9Cgo986CBp2FcI3NjDGgjCj0KPQo9Cj0KPQo9Cj0KPQo9CjwKPQo9Cj0KPQo9Cgo9PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cn0KPQo9Cj0KPQo9Cj0KPQo9Cgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj1gYGBgYGBgYEQKPQo9Cj0KPQo9Cj0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4866 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4179437439 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55da9b70f810, 0x55da9b8f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55da9b8f9020,0x55da9d7910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5bf1433d2566549142ff3823484ed758dc696755' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6131 processed earlier; will process 4898 files now Step #5: ==175252== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55da922049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55da98869898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55da9884c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55da9884c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55da9220ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55da9216bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55da92166355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55da921fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55da951cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55da951cbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55da951cbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55da951cbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55da951cbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55da951cbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55da951cbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55da951cbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55da951cbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55da951cbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55da97460f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55da9418db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55da94198be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55da93f44c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55da93f44c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55da93f45738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55da93f44874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55da93f44874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55da93f44874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55da9884eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55da98857928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55da9883f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55da9886a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc562dcb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55da92164b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x23,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0xc0,0xa4,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x23,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xf3,0xa0,0x81,0x8f,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0xf3,0xa0,0x81,0xa3,0x24,0x24,0x24,0x24,0x24,0x24,0x3d, Step #5: \014$$$$$$$$$$$$#$$$$\363\240\201\243$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$\300\244$$\363\240\201\243$$#$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\363\240\201\217\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$\363\240\201\243$$$$$$= Step #5: artifact_prefix='./'; Test unit written to ./oom-54c97f03360fec0d48481fe833d8077434689d77 Step #5: Base64: DCQkJCQkJCQkJCQkJCMkJCQk86CBoyQkJCTzoIGjJCQkJCTzoIGjJCQkJCTzoIGjJCQkJCTzoIGjJCQkJCTzoIGjJCQkJCTzoIGjJCQkJCTzoIGjJCQkJCTzoIGjJCQkJCTzoIGjJCTApCQk86CBoyQkIyQk86CBoyQkJCQk86CBoyQkJCQk8/OggY+ggaMkJCQkJPOggaMkJCQkJPOggaMkJCQkJPOggaMkJCQkJPOggaMkJCQkJPOggaMkJCQkJCQ9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4867 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4179977141 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d68e81810, 0x564d6906b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d6906b020,0x564d6af030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/54c97f03360fec0d48481fe833d8077434689d77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6132 processed earlier; will process 4897 files now Step #5: ==175288== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d5f9769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d65fdb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d65fbe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d65fbe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d5f97cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d5f8ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d5f8d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d5f96ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d6293df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d6293df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d6293df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d6293df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d6293df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d6293df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d6293df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d6293df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d6293df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d6293df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d64bd2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d618ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d6190abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d616b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d616b6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d616b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d616b6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d616b6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d616b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d65fc0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d65fc9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d65fb1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d65fdc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff016108082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d5f8d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0xa,0x2f,0x2f,0x2f,0xa,0x2f,0x2f,0xa, Step #5: //\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012///\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012\012//\012//\012//\012//\012//\012//\012///\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012//\012///\012//\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-f479a47d7bdee6758e67871fdda7795d4d068375 Step #5: Base64: Ly8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCi8vCgovLwovLwovLwovLwovLwovLwovLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8KLy8vCi8vCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4868 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4180490781 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561bdfb14810, 0x561bdfcfe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561bdfcfe020,0x561be1b960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f479a47d7bdee6758e67871fdda7795d4d068375' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6133 processed earlier; will process 4896 files now Step #5: ==175324== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561bd66099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561bdcc6e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561bdcc515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561bdcc514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561bd660fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561bd6570b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561bd656b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561bd6601c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561bd95d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561bd95d0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561bd95d0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561bd95d0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561bd95d0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561bd95d0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561bd95d0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561bd95d0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561bd95d0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561bd95d0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561bdb865f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561bd8592b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561bd859dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561bd8349c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561bd8349c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561bd834a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561bd8349874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561bd8349874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561bd8349874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561bdcc53abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561bdcc5c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561bdcc44699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561bdcc6f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5a76783082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561bd6569b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xbf,0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xa,0x6e,0x5b,0x25,0xd5,0x8c,0x3b,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0x9,0x75,0xa,0x61,0xa,0xa,0x28,0x2d,0x7c,0x2d,0x7c,0x2d,0x7c,0x2d,0x7c,0x74,0x7c,0xcc,0x83,0xd2,0x83,0x2d,0x7c,0xcd,0x83,0x7c,0x6c,0x7c,0x2d,0x7c,0x74,0x7c,0x2d,0x7c,0xed,0x90,0x83,0x7c,0xed,0x90,0x83,0x7c,0x2d,0x7c,0xed,0x90,0x83,0x2d,0x7c,0x74,0x7c,0xcc,0x83,0xed,0x90,0x83,0x2d,0x7c,0x74,0x7c,0x2d,0x2d,0x7c,0xcd,0x83,0x7c,0x6c,0x7c,0x44,0x44,0x44,0x74,0x74,0x7c,0xd3,0x83,0x7c,0x6c,0x7c,0xed,0x90,0x83,0x2d,0x7c,0x2d,0x7c,0xcd,0x83,0x7c,0x6c,0x7c,0x2d,0x74,0x7c,0xcd,0x83,0x7c,0x2d,0x7c,0x44,0x2d,0x2d,0x7c,0x74,0x7c,0x2d,0x7c,0xcd,0x83,0x7c,0x6c,0x7c,0x2d,0x7c,0x74,0x74,0x7c,0xd3,0x83,0x7c,0x6c,0x7c,0xed,0x90,0x83,0x2d,0x7c,0x2d,0x7c,0xcd,0x83,0x7c,0x6c,0x7c,0x2d,0x7c,0x4c,0x7c,0xd1,0x83,0x7c,0x6c,0x7c,0x2d,0x7c,0xed,0x90,0x83,0xd1,0x7c,0x2d,0x7c,0x44,0x44,0x7c,0x6c,0x7c,0x2d,0x2d,0x7c,0x74,0x7c,0x2d,0x7c,0x74,0x7c,0x2d,0x7c, Step #5: \357\273\277<!DOCTYPE\012n[%\325\214;<!ATTLIST\011u\012a\012\012(-|-|-|-|t|\314\203\322\203-|\315\203|l|-|t|-|\355\220\203|\355\220\203|-|\355\220\203-|t|\314\203\355\220\203-|t|--|\315\203|l|DDDtt|\323\203|l|\355\220\203-|-|\315\203|l|-t|\315\203|-|D--|t|-|\315\203|l|-|tt|\323\203|l|\355\220\203-|-|\315\203|l|-|L|\321\203|l|-|\355\220\203\321|-|DD|l|--|t|-|t|-| Step #5: artifact_prefix='./'; Test unit written to ./oom-e191a119ee1ae793431360d8ccbb246c9c228b49 Step #5: Base64: 77u/PCFET0NUWVBFCm5bJdWMOzwhQVRUTElTVAl1CmEKCigtfC18LXwtfHR8zIPSgy18zYN8bHwtfHR8LXztkIN87ZCDfC187ZCDLXx0fMyD7ZCDLXx0fC0tfM2DfGx8REREdHR804N8bHztkIMtfC18zYN8bHwtdHzNg3wtfEQtLXx0fC18zYN8bHwtfHR0fNODfGx87ZCDLXwtfM2DfGx8LXxMfNGDfGx8LXztkIPRfC18RER8bHwtLXx0fC18dHwtfA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4869 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4181019403 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a0a5dd810, 0x558a0a7c701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a0a7c7020,0x558a0c65f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e191a119ee1ae793431360d8ccbb246c9c228b49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6134 processed earlier; will process 4895 files now Step #5: #1 pulse cov: 4064 ft: 4065 exec/s: 0 rss: 177Mb Step #5: ==175360== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558a010d29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a07737898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a0771a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a0771a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a010d8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a01039b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a01034355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a010cac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a04099f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a04099f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a04099f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a04099f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a04099f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a04099f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a04099f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a04099f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a04099f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a04099f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a0632ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a0305bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a03066be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a02e12c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a02e12c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a02e13738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a02e12874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a02e12874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a02e12874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a0771cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a07725928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a0770d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a07738112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff7e620e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a01032b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x31,0x4d,0x46,0x65,0x41,0x57,0x61,0x47,0x6f,0x53,0x6c,0x71,0x2b,0x48,0x6d,0x73,0x63,0x76,0x31,0x42,0x59,0x6a,0x4c,0x43,0x54,0x42,0x42,0x2b,0x4c,0x53,0x58,0x49,0x56,0x77,0x6a,0x7a,0x53,0x77,0x6f,0x31,0x44,0x44,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f,0xa,0x61,0x20,0x2f, Step #5: onion-key\012ntor-onion-key v1MFeAWaGoSlq+Hmscv1BYjLCTBB+LSXIVwjzSwo1DD\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a /\012a / Step #5: artifact_prefix='./'; Test unit written to ./oom-1253e55f11e93678e727d98b13a299803e8451b8 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHYxTUZlQVdhR29TbHErSG1zY3YxQllqTENUQkIrTFNYSVZ3anpTd28xREQKYSAvCmEgLwphIC8KYSAvCmEgLwphIC8KYSAvCmEgLwphIC8KYSAvCmEgLwphIC8KYSAvCmEgLwphIC8KYSAvCmEgLwphIC8KYSAvCmEgLwphIC8KYSAvCmEgLwphIC8KYSAvCmEgLwphIC8KYSAvCmEgLwphIC8KYSAvCmEgLw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4870 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4181587666 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561db71f3810, 0x561db73dd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561db73dd020,0x561db92750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1253e55f11e93678e727d98b13a299803e8451b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6136 processed earlier; will process 4893 files now Step #5: #1 pulse cov: 3962 ft: 3963 exec/s: 0 rss: 175Mb Step #5: ==175396== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561dadce89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561db434d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561db43305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561db43304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561dadceed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561dadc4fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561dadc4a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561dadce0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561db0caff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561db0caff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561db0caff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561db0caff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561db0caff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561db0caff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561db0caff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561db0caff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561db0caff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561db0caff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561db2f44f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561dafc71b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561dafc7cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561dafa28c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561dafa28c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561dafa29738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561dafa28874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561dafa28874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561dafa28874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561db4332abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561db433b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561db4323699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561db434e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe52aeee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561dadc48b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdb,0x80,0xdb,0x80,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0xa,0x0,0x0,0x0,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x39,0x39,0x3b,0x39,0x39,0x39,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x38, Step #5: \333\200\333\200%%%%%%%%%%%%%%%%%%%%%%%%%%%%\012\000\000\000%%%%%%%%%%%\000\000\000\000\000\000\000\000\00099;999\000\000\000\000\000\001\000\000\000\000\000\000\000\000\000\000\001\000\000\000\000\000\000\000\000%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000 \000\000\000\000\000\0008 Step #5: artifact_prefix='./'; Test unit written to ./oom-45d9c2f865f4ffb255a8947d5c50d03c025f9036 Step #5: Base64: 24DbgCUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUKAAAAJSUlJSUlJSUlJSUAAAAAAAAAAAA5OTs5OTkAAAAAAAEAAAAAAAAAAAAAAQAAAAAAAAAAJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgAAAAAAAAOA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4871 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4182153831 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56334fced810, 0x56334fed701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56334fed7020,0x563351d6f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/45d9c2f865f4ffb255a8947d5c50d03c025f9036' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6138 processed earlier; will process 4891 files now Step #5: ==175432== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5633467e29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56334ce47898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56334ce2a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56334ce2a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5633467e8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563346749b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563346744355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5633467dac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5633497a9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5633497a9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5633497a9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5633497a9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5633497a9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5633497a9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5633497a9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5633497a9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5633497a9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5633497a9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56334ba3ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56334876bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563348776be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563348522c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563348522c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563348523738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563348522874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563348522874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563348522874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56334ce2cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56334ce35928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56334ce1d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56334ce48112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb56e735082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563346742b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x67,0x62,0x49,0x54,0x32,0x58,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x54,0x32,0x58,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xa9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x64,0x61,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x44,0x33,0x67,0x62,0x49,0x54,0x32,0x58,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x54,0x32,0x58,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xa9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x64,0x61,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x31,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xa9,0x0,0x0,0x0,0x31,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xa9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x43,0x4f,0x4d,0x2,0xdb,0xbf,0x9f,0xff, Step #5: ID3gbIT2X\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000T2X\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\342\200\251\000\000\000\000\000\000\000\000\000\000\000\000\000da\000\000\000\000\000\000\000\000D3gbIT2X\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000T2X\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\342\200\251\000\000\000\000\000\000\000\000\000\000\000\000\000da\000\000\000\000\000\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\342\200\251\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\342\200\251\000\000\000\000\000\000\000COM\002\333\277\237\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-09a7a40c371b0402ada9f0e29d1999bfabc53d9e Step #5: Base64: SUQzZ2JJVDJYAAAAAAAAAAAAAAAAAAAAAFQyWAAAAAAAAAAAAAAAAAAAAAAAAADigKkAAAAAAAAAAAAAAAAAZGEAAAAAAAAAAEQzZ2JJVDJYAAAAAAAAAAAAAAAAAAAAAFQyWAAAAAAAAAAAAAAAAAAAAAAAAADigKkAAAAAAAAAAAAAAAAAZGEAAAAAAAAAAAAxAAAAAAAAAAAAAAAA4oCpAAAAMQAAAAAAAAAAAAAAAOKAqQAAAAAAAABDT00C27+f/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4872 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4182685277 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f3283b810, 0x556f32a2501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f32a25020,0x556f348bd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/09a7a40c371b0402ada9f0e29d1999bfabc53d9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6139 processed earlier; will process 4890 files now Step #5: ==175468== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556f293309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f2f995898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f2f9785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f2f9784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f29336d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f29297b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f29292355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f29328c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f2c2f7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f2c2f7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f2c2f7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f2c2f7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f2c2f7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f2c2f7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f2c2f7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f2c2f7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f2c2f7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f2c2f7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f2e58cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f2b2b9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f2b2c4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f2b070c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f2b070c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f2b071738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f2b070874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f2b070874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f2b070874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f2f97aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f2f983928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f2f96b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f2f996112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f33f5037082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f29290b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x88,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x6c,0x0,0x0,0x0,0x0,0xb,0x0,0x60,0xa,0xa,0x31,0x2f,0x60,0xa,0x20,0x20,0x60,0xe2,0x88,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0xf3,0xa0,0x81,0xba,0x2f,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0xb,0x0,0x60,0xa,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0xa,0x31,0x2f,0x60,0xa,0x20,0x20,0x47,0x49,0x4e,0x20,0x3d,0x5e,0x0,0x0,0x0,0x8,0xa,0x66,0x3d,0x72,0x3d,0x73,0x65,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x60,0x20,0x60,0xa,0x9,0x3d,0x20,0x3d,0x5e,0x0,0x0,0x0,0x8,0xa,0x66,0x3d,0x72,0x3d,0x73,0x65,0xa,0x3d,0x2b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x60,0x20,0x20,0x9,0x3d,0xa,0x3d,0x60,0xa,0x83,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0xff,0xa,0x83,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0xff,0x60,0x20,0x60,0xa,0x9, Step #5: `\342\210\210-\000`\012\363\240\201\272/\012`\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000l\000\000\000\000\013\000`\012\0121/`\012 `\342\210\210-\000`\012\363\240\201\272/\012`\342\200\210-\000`\012\363\240\201\272\363\240\201\272/\001\000\000\000\000\000\000\013\000`\012\005-----BE\0121/`\012 GIN =^\000\000\000\010\012f=r=se\012=+=\012=\012=\012` `\012\011= =^\000\000\000\010\012f=r=se\012=+=\012=\012=\012` \011=\012=`\012\203\000\000\000\000\000\000\000\020\377\012\203\000\000\000\000\000\000\000\020\377` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-a39deb4709fdf8cfdf802dafac4a24fd4c559c56 Step #5: Base64: YOKIiC0AYArzoIG6Lwpg4oCILQBgCvOggbrzoIG6LwEAbAAAAAALAGAKCjEvYAogIGDiiIgtAGAK86CBui8KYOKAiC0AYArzoIG686CBui8BAAAAAAAACwBgCgUtLS0tLUJFCjEvYAogIEdJTiA9XgAAAAgKZj1yPXNlCj0rPQo9Cj0KYCBgCgk9ID1eAAAACApmPXI9c2UKPSs9Cj0KPQpgICAJPQo9YAqDAAAAAAAAABD/CoMAAAAAAAAAEP9gIGAKCQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4873 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4183340382 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562cb6d95810, 0x562cb6f7f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562cb6f7f020,0x562cb8e170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a39deb4709fdf8cfdf802dafac4a24fd4c559c56' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6140 processed earlier; will process 4889 files now Step #5: ==175504== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562cad88a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562cb3eef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562cb3ed25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562cb3ed24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562cad890d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562cad7f1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562cad7ec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562cad882c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562cb0851f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562cb0851f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562cb0851f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562cb0851f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562cb0851f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562cb0851f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562cb0851f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562cb0851f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562cb0851f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562cb0851f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562cb2ae6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562caf813b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562caf81ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562caf5cac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562caf5cac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562caf5cb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562caf5ca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562caf5ca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562caf5ca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562cb3ed4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562cb3edd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562cb3ec5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562cb3ef0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f86c6609082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562cad7eab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x9e,0x8b,0x91,0xd,0x69,0x6e,0xd,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4,0x91,0xd,0x69,0x6e,0xd,0xc4, Step #5: \360\236\213\221\015in\015\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304\221\015in\015\304 Step #5: artifact_prefix='./'; Test unit written to ./oom-208c5cf8d84d088ff4653b5b0d7d19588bb9741d Step #5: Base64: 8J6LkQ1pbg0NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxJENaW4NxA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4874 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4183862943 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5568ab539810, 0x5568ab72301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5568ab723020,0x5568ad5bb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/208c5cf8d84d088ff4653b5b0d7d19588bb9741d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6141 processed earlier; will process 4888 files now Step #5: #1 pulse cov: 3513 ft: 3514 exec/s: 0 rss: 176Mb Step #5: ==175540== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5568a202e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5568a8693898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5568a86765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5568a86764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5568a2034d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5568a1f95b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5568a1f90355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5568a2026c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5568a4ff5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5568a4ff5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5568a4ff5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5568a4ff5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5568a4ff5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5568a4ff5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5568a4ff5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5568a4ff5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5568a4ff5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5568a4ff5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5568a728af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5568a3fb7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5568a3fc2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5568a3d6ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5568a3d6ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5568a3d6f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5568a3d6e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5568a3d6e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5568a3d6e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5568a8678abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5568a8681928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5568a8669699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5568a8694112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3871bff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5568a1f8eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x2f,0x20,0x49,0x20,0x6e,0x74,0x28,0x78,0x2e,0x67,0x65,0x74,0x5f,0x62,0x69,0x0,0x28,0x2d,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x38,0x29,0x29,0x3b,0xa,0xa,0x6c,0x65,0x74,0x20,0x78,0x20,0x3d,0x20,0x30,0x3b,0xa,0xa,0x70,0x72,0x69,0x6e,0x74,0x28,0x78,0x2e,0x67,0x65,0x74,0x5f,0x62,0x69,0x74,0x73,0x28,0x36,0x2e,0x2e,0x31,0x29,0x29,0x3b,0xa,0xa,0x6c,0x65,0x74,0x20,0x78,0x20,0x3d,0x20,0x31,0x32,0x33,0x34,0x35,0x36,0x3b,0xa,0xa,0x70,0x72,0x69,0x6e,0x74,0x28,0x78,0x2e,0x67,0x65,0x74,0x5f,0x62,0x69,0x74,0x73,0x28,0x36,0x2e,0x2e,0x31,0x29,0x29,0x3b,0xa,0xa,0x6c,0x65,0x74,0x20,0x78,0x20,0x3d,0x20,0x34,0x30,0x31,0x30,0x37,0x35,0x34,0x37,0x32,0x31,0x38,0x37,0x35,0x37,0x33,0x36,0x35,0x3b,0xa,0xa,0x70,0x72,0x69,0x6e,0x74,0x28,0x78,0x2e,0x67,0x65,0x74,0x5f,0x62,0x69,0x74,0x73,0x28,0x32,0x36,0x32,0x2e,0x2e,0x3d,0x39,0x29,0x29,0x3b,0xa,0x84,0x6c,0x65,0x31,0x2f,0x2f,0x5,0x4,0x54,0x68,0x69,0x73,0x20,0x73,0x63,0x7b,0x2c,0x20,0x35,0x5d,0x3b,0xa,0xa,0x6c,0x65,0x74, Step #5: // I nt(x.get_bi\000(-2147483648));\012\012let x = 0;\012\012print(x.get_bits(6..1));\012\012let x = 123456;\012\012print(x.get_bits(6..1));\012\012let x = 40107547218757365;\012\012print(x.get_bits(262..=9));\012\204le1//\005\004This sc{, 5];\012\012let Step #5: artifact_prefix='./'; Test unit written to ./oom-a72a1837feef76e8c56a50d4c35bfdc04db8115f Step #5: Base64: Ly8gSSBudCh4LmdldF9iaQAoLTIxNDc0ODM2NDgpKTsKCmxldCB4ID0gMDsKCnByaW50KHguZ2V0X2JpdHMoNi4uMSkpOwoKbGV0IHggPSAxMjM0NTY7CgpwcmludCh4LmdldF9iaXRzKDYuLjEpKTsKCmxldCB4ID0gNDAxMDc1NDcyMTg3NTczNjU7CgpwcmludCh4LmdldF9iaXRzKDI2Mi4uPTkpKTsKhGxlMS8vBQRUaGlzIHNjeywgNV07CgpsZXQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4875 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4184422590 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5570db4c2810, 0x5570db6ac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5570db6ac020,0x5570dd5440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a72a1837feef76e8c56a50d4c35bfdc04db8115f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6143 processed earlier; will process 4886 files now Step #5: ==175576== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5570d1fb79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5570d861c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5570d85ff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5570d85ff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5570d1fbdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5570d1f1eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5570d1f19355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5570d1fafc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5570d4f7ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5570d4f7ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5570d4f7ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5570d4f7ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5570d4f7ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5570d4f7ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5570d4f7ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5570d4f7ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5570d4f7ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5570d4f7ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5570d7213f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5570d3f40b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5570d3f4bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5570d3cf7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5570d3cf7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5570d3cf8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5570d3cf7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5570d3cf7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5570d3cf7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5570d8601abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5570d860a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5570d85f2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5570d861d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f58182d6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5570d1f17b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xa,0x9,0xa,0x60,0x2d,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x82,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc8,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0x0,0x60,0x20,0x20,0x20,0x60,0xa,0x9,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xcb,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x8c,0xc5,0x83,0xc5,0x8b,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xc5,0x83,0xcf,0xaf, Step #5: `\012\011\012`-\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\202\305\203\305\203\305\203\305\203\305\203\310\203\305\203\305\203\305\203\305\203\000` `\012\011\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\203\305\203\305\203\305\203\305\203\313\203\305\203\305\203\305\203\305\203\305\214\305\203\305\213\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\305\203\317\257 Step #5: artifact_prefix='./'; Test unit written to ./oom-b8c3c6a083411e6210d58228f27ccd70680c0ad7 Step #5: Base64: YAoJCmAtxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFgsWDxYPFg8WDxYPIg8WDxYPFg8WDAGAgICBgCgnFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg8WDxYPFg4PFg8WDxYPFg8uDxYPFg8WDxYPFjMWDxYvFg8WDxYPFg8WDxYPFg8WDxYPFg8WDz68= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4876 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4185054278 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b4435e4810, 0x55b4437ce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b4437ce020,0x55b4456660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b8c3c6a083411e6210d58228f27ccd70680c0ad7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6144 processed earlier; will process 4885 files now Step #5: #1 pulse cov: 3844 ft: 3845 exec/s: 0 rss: 177Mb Step #5: ==175612== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b43a0d99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b44073e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b4407215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b4407214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b43a0dfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b43a040b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b43a03b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b43a0d1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b43d0a0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b43d0a0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b43d0a0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b43d0a0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b43d0a0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b43d0a0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b43d0a0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b43d0a0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b43d0a0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b43d0a0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b43f335f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b43c062b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b43c06dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b43be19c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b43be19c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b43be1a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b43be19874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b43be19874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b43be19874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b440723abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b44072c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b440714699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b44073f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f540bbcb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b43a039b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x32,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x12,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x29,0x49,0x44,0x21,0x7a,0x2d,0x34,0x32,0x2,0x0,0x0,0xff,0xff,0x20,0x54,0x26,0xdc,0x2,0x2b, Step #5: ))))))))))))));;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;2;;;;;;;;;;;;;;;;;;;;;\022\022\022\022\022\022\022\022\022\022\022\022\022\022\022;;;;;;;;;;;;;;)))))))))ID!z-42\002\000\000\377\377 T&\334\002+ Step #5: artifact_prefix='./'; Test unit written to ./oom-2ab3f1d5af26306a1ebf23262b95ebb5a5eb0adc Step #5: Base64: KSkpKSkpKSkpKSkpKSk7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OzsyOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7EhISEhISEhISEhISEhISOzs7Ozs7Ozs7Ozs7OzspKSkpKSkpKSlJRCF6LTQyAgAA//8gVCbcAis= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4877 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4185611573 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ae960ca810, 0x55ae962b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ae962b4020,0x55ae9814c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2ab3f1d5af26306a1ebf23262b95ebb5a5eb0adc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6146 processed earlier; will process 4883 files now Step #5: #1 pulse cov: 3626 ft: 3627 exec/s: 0 rss: 178Mb Step #5: ==175648== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ae8cbbf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ae93224898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ae932075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ae932074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ae8cbc5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ae8cb26b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ae8cb21355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ae8cbb7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ae8fb86f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ae8fb86f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ae8fb86f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ae8fb86f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ae8fb86f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ae8fb86f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ae8fb86f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ae8fb86f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ae8fb86f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ae8fb86f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ae91e1bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ae8eb48b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ae8eb53be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ae8e8ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ae8e8ffc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ae8e900738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ae8e8ff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ae8e8ff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ae8e8ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ae93209abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ae93212928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ae931fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ae93225112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0625ba5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ae8cb1fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x69,0x29,0x5b,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x84,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x2b,0x2d,0xf2,0x85,0x84,0x93,0x0,0x2d,0xf2,0x85,0x85,0x92,0x0,0x2d,0xf3,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x84,0x85,0x93,0x1,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x92,0x0,0x2d,0xf3,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf3,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x1,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x92,0x0,0x2d,0xf3,0x85,0x8d,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x1,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x95,0x92,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93,0x0,0x2d,0xf2,0x85,0x85,0x93, Step #5: (?i)[\000-\362\205\205\223\000-\362\205\205\223\000-\362\204\205\223\000-\362\205\205\223+-\362\205\204\223\000-\362\205\205\222\000-\363\205\205\223\000-\362\205\205\223\000-\362\205\205\223\000-\362\204\205\223\001-\362\205\205\223\000-\362\205\205\223\000-\362\205\205\223\000-\362\205\205\222\000-\363\205\205\223\000-\362\205\205\223\000-\363\205\205\223\000-\362\205\205\223\001-\362\205\205\223\000-\362\205\205\223\000-\362\205\205\223\000-\362\205\205\222\000-\363\205\215\223\000-\362\205\205\223\000-\362\205\205\223\000-\362\205\205\223\001-\362\205\205\223\000-\362\205\205\223\000-\362\205\225\222\000-\362\205\205\223\000-\362\205\205\223\000-\362\205\205\223 Step #5: artifact_prefix='./'; Test unit written to ./oom-7ed07966f4a2c8333917ae9be70fc4eae204d632 Step #5: Base64: KD9pKVsALfKFhZMALfKFhZMALfKEhZMALfKFhZMrLfKFhJMALfKFhZIALfOFhZMALfKFhZMALfKFhZMALfKEhZMBLfKFhZMALfKFhZMALfKFhZMALfKFhZIALfOFhZMALfKFhZMALfOFhZMALfKFhZMBLfKFhZMALfKFhZMALfKFhZMALfKFhZIALfOFjZMALfKFhZMALfKFhZMALfKFhZMBLfKFhZMALfKFhZMALfKFlZIALfKFhZMALfKFhZMALfKFhZM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4878 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4186164742 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cf099ed810, 0x55cf09bd701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cf09bd7020,0x55cf0ba6f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ed07966f4a2c8333917ae9be70fc4eae204d632' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6148 processed earlier; will process 4881 files now Step #5: #1 pulse cov: 3626 ft: 3627 exec/s: 0 rss: 177Mb Step #5: ==175684== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cf004e29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cf06b47898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cf06b2a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cf06b2a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cf004e8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cf00449b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cf00444355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cf004dac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cf034a9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cf034a9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cf034a9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cf034a9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cf034a9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cf034a9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cf034a9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cf034a9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cf034a9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cf034a9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cf0573ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cf0246bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cf02476be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cf02222c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cf02222c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cf02223738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cf02222874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cf02222874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cf02222874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cf06b2cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cf06b35928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cf06b1d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cf06b48112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0c9155f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cf00442b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xeb,0xb6,0xb8,0xe1,0x86,0xad,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xad,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xab,0xeb,0xb6,0xb8,0xe1,0x86,0xad,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xa,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xad,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xab,0xeb,0xb6,0xb8,0xe1,0x86,0xad,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xe1,0x86,0xa6,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xa,0xeb,0xb6,0xb8,0xe1,0x86,0xac,0xeb,0xb6,0xb8,0xe1,0x86,0xb8, Step #5: \012\353\266\270\341\206\255\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\255\353\266\270\341\206\254\353\266\270\341\206\253\353\266\270\341\206\255\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\012\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\255\353\266\270\341\206\254\353\266\270\341\206\253\353\266\270\341\206\255\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\341\206\246\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\353\266\270\341\206\254\012\353\266\270\341\206\254\353\266\270\341\206\270 Step #5: artifact_prefix='./'; Test unit written to ./oom-00df668f7bc93699ca24a7f1814760ca35e1d13f Step #5: Base64: Cuu2uOGGreu2uOGGrOu2uOGGrOu2uOGGrOu2uOGGreu2uOGGrOu2uOGGq+u2uOGGreu2uOGGrOu2uOGGrOu2uOGGrOu2uOGGrOu2uOGGrOu2uOGGrOu2uOGGrOu2uOGGrArrtrjhhqzrtrjhhqzrtrjhhqzrtrjhhq3rtrjhhqzrtrjhhqvrtrjhhq3rtrjhhqzrtrjhhqzrtrjhhqzhhqbrtrjhhqzrtrjhhqzrtrjhhqzrtrjhhqwK67a44Yas67a44Ya4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4879 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4186726167 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55972e3aa810, 0x55972e59401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55972e594020,0x55973042c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/00df668f7bc93699ca24a7f1814760ca35e1d13f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6150 processed earlier; will process 4879 files now Step #5: ==175720== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559724e9f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55972b504898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55972b4e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55972b4e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559724ea5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559724e06b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559724e01355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559724e97c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559727e66f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559727e66f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559727e66f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559727e66f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559727e66f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559727e66f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559727e66f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559727e66f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559727e66f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559727e66f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55972a0fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559726e28b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559726e33be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559726bdfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559726bdfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559726be0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559726bdf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559726bdf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559726bdf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55972b4e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55972b4f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55972b4da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55972b505112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4e0d829082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559724dffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x4a,0x9,0x29,0xb,0xa,0x5c,0x2d,0x9,0x29,0x60,0x40,0x4c,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x9,0xa,0x60,0x40, Step #5: /J\011)\013\012\\-\011)`@L=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012D\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012D\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012ttp://=\012=\012=\012=\012=\012=\012=\012\011\012`@ Step #5: artifact_prefix='./'; Test unit written to ./oom-dfba58e9d341663f6cf42d8f19797a7850e7c2b6 Step #5: Base64: L0oJKQsKXC0JKWBATD0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9CkQKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KRAo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KdHRwOi8vPQo9Cj0KPQo9Cj0KPQoJCmBA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4880 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4187404864 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ced408f810, 0x55ced427901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ced4279020,0x55ced61110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dfba58e9d341663f6cf42d8f19797a7850e7c2b6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6151 processed earlier; will process 4878 files now Step #5: ==175756== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cecab849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ced11e9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ced11cc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ced11cc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cecab8ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cecaaebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cecaae6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cecab7cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cecdb4bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cecdb4bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cecdb4bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cecdb4bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cecdb4bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cecdb4bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cecdb4bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cecdb4bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cecdb4bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cecdb4bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cecfde0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ceccb0db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ceccb18be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cecc8c4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cecc8c4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cecc8c5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cecc8c4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cecc8c4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cecc8c4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ced11ceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ced11d7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ced11bf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ced11ea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb64105b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cecaae4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x74,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x41,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x1, Step #5: FFUZZ-TAGFUZZ-TAGtFUZZ-TAGFUZZ-TAGAFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAGFUZZ-TAG\001 Step #5: artifact_prefix='./'; Test unit written to ./oom-57a869baf430e2f8c84e693493bc605d263f26eb Step #5: Base64: RkZVWlotVEFHRlVaWi1UQUd0RlVaWi1UQUdGVVpaLVRBR0FGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0dGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0dGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUdGVVpaLVRBR0ZVWlotVEFHRlVaWi1UQUcB Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4881 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4187960120 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f992a99810, 0x55f992c8301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f992c83020,0x55f994b1b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/57a869baf430e2f8c84e693493bc605d263f26eb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6152 processed earlier; will process 4877 files now Step #5: ==175792== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f98958e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f98fbf3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f98fbd65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f98fbd64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f989594d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f9894f5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f9894f0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f989586c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f98c555f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f98c555f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f98c555f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f98c555f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f98c555f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f98c555f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f98c555f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f98c555f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f98c555f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f98c555f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f98e7eaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f98b517b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f98b522be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f98b2cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f98b2cec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f98b2cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f98b2ce874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f98b2ce874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f98b2ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f98fbd8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f98fbe1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f98fbc9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f98fbf4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd9cb70e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f9894eeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x67,0x75,0x3b,0x71,0x3d,0x38,0x45,0x2d,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x36,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x34,0x5f,0x34,0x5f,0x5f,0x33,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x34,0x5f,0x32,0x54, Step #5: gu;q=8E-4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_6_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_4_44_4__3_4_4_4_4_4_4_4_4_4_4_2T Step #5: artifact_prefix='./'; Test unit written to ./oom-6a881e66b1e731eaf60f00256e5fa211cd700f2f Step #5: Base64: Z3U7cT04RS00XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF82XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNF80XzRfNDRfNF9fM180XzRfNF80XzRfNF80XzRfNF80XzJU Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4882 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4188487529 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563c114f9810, 0x563c116e301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563c116e3020,0x563c1357b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a881e66b1e731eaf60f00256e5fa211cd700f2f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6153 processed earlier; will process 4876 files now Step #5: ==175828== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563c07fee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563c0e653898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563c0e6365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563c0e6364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563c07ff4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563c07f55b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563c07f50355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563c07fe6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563c0afb5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563c0afb5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563c0afb5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563c0afb5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563c0afb5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563c0afb5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563c0afb5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563c0afb5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563c0afb5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563c0afb5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563c0d24af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563c09f77b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563c09f82be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563c09d2ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563c09d2ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563c09d2f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563c09d2e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563c09d2e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563c09d2e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563c0e638abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563c0e641928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563c0e629699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563c0e654112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f32df845082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563c07f4eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x8,0x33,0x34,0xa,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd,0x2d,0x2d,0x2d,0xd,0x24,0xd, Step #5: \01034\012---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015\015$\015---\015$\015---\015$\015-\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015---\015$\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-29344da3cbe597b9f02d5782634c7bde04bc61b3 Step #5: Base64: CDM0Ci0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0NJA0tLS0NJA0tLS0NJA0tDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDS0tLQ0kDQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4883 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4189028315 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a6c0fe4810, 0x55a6c11ce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a6c11ce020,0x55a6c30660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/29344da3cbe597b9f02d5782634c7bde04bc61b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6154 processed earlier; will process 4875 files now Step #5: #1 pulse cov: 4056 ft: 4057 exec/s: 0 rss: 177Mb Step #5: ==175864== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a6b7ad99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a6be13e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a6be1215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a6be1214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a6b7adfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a6b7a40b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a6b7a3b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a6b7ad1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a6baaa0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a6baaa0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a6baaa0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a6baaa0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a6baaa0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a6baaa0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a6baaa0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a6baaa0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a6baaa0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a6baaa0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a6bcd35f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a6b9a62b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a6b9a6dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a6b9819c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a6b9819c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a6b981a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a6b9819874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a6b9819874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a6b9819874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a6be123abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a6be12c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a6be114699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a6be13f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0b891fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a6b7a39b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x30,0x4d,0x46,0x77,0x48,0x65,0x57,0x53,0x2f,0x6f,0x41,0x61,0x71,0x59,0x30,0x2b,0x6a,0x6d,0x47,0x6a,0x54,0x41,0x53,0x56,0x53,0x43,0x4c,0x41,0x6c,0x58,0x2b,0x4c,0x77,0x7a,0x49,0x41,0x75,0x73,0x6f,0x31,0x54,0x45,0xa,0x61,0x20,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27, Step #5: onion-key\012ntor-onion-key v0MFwHeWS/oAaqY0+jmGjTASVSCLAlX+LwzIAuso1TE\012a '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Step #5: artifact_prefix='./'; Test unit written to ./oom-5f005b30ef0b310217c4f7de5f3a05fa6afeb407 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHYwTUZ3SGVXUy9vQWFxWTAram1HalRBU1ZTQ0xBbFgrTHd6SUF1c28xVEUKYSAnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4884 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4189611434 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558696ca6810, 0x558696e9001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558696e90020,0x558698d280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f005b30ef0b310217c4f7de5f3a05fa6afeb407' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6156 processed earlier; will process 4873 files now Step #5: #1 pulse cov: 3619 ft: 3620 exec/s: 0 rss: 175Mb Step #5: ==175900== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55868d79b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558693e00898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558693de35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558693de34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55868d7a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55868d702b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55868d6fd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55868d793c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558690762f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558690762f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558690762f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558690762f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558690762f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558690762f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558690762f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558690762f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558690762f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558690762f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5586929f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55868f724b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55868f72fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55868f4dbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55868f4dbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55868f4dc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55868f4db874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55868f4db874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55868f4db874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558693de5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558693dee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558693dd6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558693e01112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8e7f6b9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55868d6fbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x57,0x30,0x4d,0x46,0x77,0x53,0x48,0x2b,0x63,0x57,0x41,0x41,0x6c,0x79,0x6f,0x4c,0x30,0x61,0x6a,0x65,0x43,0x59,0x61,0x57,0x6d,0x2b,0x73,0x54,0x2b,0x32,0x53,0x58,0x49,0x53,0x7a,0x56,0x77,0x6a,0x77,0x39,0x30,0x37,0x39,0xa,0x61,0x9,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22, Step #5: onion-key\012ntor-onion-key W0MFwSH+cWAAlyoL0ajeCYaWm+sT+2SXISzVwjw9079\012a\011\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\" Step #5: artifact_prefix='./'; Test unit written to ./oom-faa766fdda8abe3198efe697b3db12347a47771f Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IFcwTUZ3U0grY1dBQWx5b0wwYWplQ1lhV20rc1QrMlNYSVN6VndqdzkwNzkKYQkiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4885 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4190199959 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5592e3d0c810, 0x5592e3ef601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5592e3ef6020,0x5592e5d8e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/faa766fdda8abe3198efe697b3db12347a47771f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6158 processed earlier; will process 4871 files now Step #5: ==175936== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5592da8019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5592e0e66898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5592e0e495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5592e0e494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592da807d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592da768b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592da763355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592da7f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592dd7c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592dd7c8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592dd7c8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592dd7c8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592dd7c8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592dd7c8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592dd7c8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592dd7c8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592dd7c8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592dd7c8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592dfa5df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592dc78ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592dc795be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5592dc541c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5592dc541c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5592dc542738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5592dc541874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5592dc541874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5592dc541874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5592e0e4babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5592e0e54928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5592e0e3c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5592e0e67112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2772b04082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592da761b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xf3,0xa0,0x80,0xb2,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x3d,0xa,0x3d,0x2a,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x7,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x0,0x0,0xa,0x3d,0xa,0x3d,0x2a,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x7,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000\000\000\000\000\000\000\000\000\000\000\000\363\240\200\262\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012=\012=*=\012=\012=\012=\012=\012=\007\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000\000\000\012=\012=*=\012=\012=\012=\012=\012=\007\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-080327f28516990173a3da46b2b8294132314dd9 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQAAAAAAAAAAAAAAAPOggLIAAAAAAAAAAAAAAAAAAAAAAAo9Cj0qPQo9Cj0KPQo9Cj0HCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQAAAAo9Cj0qPQo9Cj0KPQo9Cj0HCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KEA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4886 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4190775918 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d7b0f0810, 0x562d7b2da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d7b2da020,0x562d7d1720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/080327f28516990173a3da46b2b8294132314dd9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6159 processed earlier; will process 4870 files now Step #5: ==175972== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562d71be59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d7824a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d7822d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d7822d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d71bebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d71b4cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d71b47355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d71bddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d74bacf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d74bacf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d74bacf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d74bacf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d74bacf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d74bacf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d74bacf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d74bacf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d74bacf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d74bacf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d76e41f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d73b6eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d73b79be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d73925c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d73925c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d73926738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d73925874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d73925874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d73925874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d7822fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d78238928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d78220699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d7824b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4f9fa1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d71b45b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6c,0x65,0x78,0x65,0x72,0x20,0x71,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x44,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x44,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x44,0x7c,0x3b,0x44,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x44,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x44,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x44,0x7c,0x3b,0x44,0x7c,0x3b,0x41,0x7c,0x3b,0x4a,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x44,0x7c,0x24,0x41,0x7c,0x3b,0x41,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x44,0x7c,0x44,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x44,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x2b,0x41,0x7c,0x3b,0x44,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x44,0x7c,0x3b,0x44,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x44,0x7c,0x24,0x41,0x7c,0x3b,0x41,0x7c,0x3b,0x41, Step #5: lexer q;A|;A|;D|;A|;A|;A|;D|;A|;A|;A|;A|;D|;D|;A|;A|;A|;A|;D|;A|;A|;A|;A|;D|;A|;A|;A|;A|;D|;D|;A|;J|;A|;A|;D|$A|;A;A|;A|;A|;D|D|;A|;A|;A|;A|;D|;A|;A|;A|+A|;D|;A|;A|;A|;A|;D|;D|;A|;A|;A|;A|;D|$A|;A|;A Step #5: artifact_prefix='./'; Test unit written to ./oom-29e471d5c6fa9332c101b2e034c4f7d2db11046d Step #5: Base64: bGV4ZXIgcTtBfDtBfDtEfDtBfDtBfDtBfDtEfDtBfDtBfDtBfDtBfDtEfDtEfDtBfDtBfDtBfDtBfDtEfDtBfDtBfDtBfDtBfDtEfDtBfDtBfDtBfDtBfDtEfDtEfDtBfDtKfDtBfDtBfDtEfCRBfDtBO0F8O0F8O0F8O0R8RHw7QXw7QXw7QXw7QXw7RHw7QXw7QXw7QXwrQXw7RHw7QXw7QXw7QXw7QXw7RHw7RHw7QXw7QXw7QXw7QXw7RHwkQXw7QXw7QQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4887 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4191319254 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec5861f810, 0x55ec5880901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec58809020,0x55ec5a6a10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/29e471d5c6fa9332c101b2e034c4f7d2db11046d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6160 processed earlier; will process 4869 files now Step #5: ==176008== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec4f1149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec55779898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec5575c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec5575c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec4f11ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec4f07bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec4f076355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec4f10cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec520dbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec520dbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec520dbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec520dbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec520dbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec520dbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec520dbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec520dbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec520dbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec520dbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec54370f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec5109db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec510a8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec50e54c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec50e54c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec50e55738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec50e54874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec50e54874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec50e54874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec5575eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec55767928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec5574f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec5577a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe574c39082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec4f074b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xa,0x59,0x5b,0x3c,0x21,0x41,0x54,0x54,0x4c,0x49,0x53,0x54,0xd,0x45,0x20,0x78,0x20,0x28,0xda,0xa2,0x2d,0x7c,0xda,0xa2,0x3a,0xda,0x82,0x74,0x59,0x45,0x45,0x2d,0x7c,0xda,0xa2,0x3a,0xda,0x82,0x7c,0x59,0x55,0x3a,0x2d,0x7c,0xda,0xa2,0x3a,0xda,0xa2,0x7c,0xd7,0xa2,0x7c,0xda,0xa2,0x3a,0x2d,0x7c,0xda,0xa2,0x3a,0xda,0xa2,0x7c,0xd7,0xa2,0x7c,0xda,0xa2,0x2d,0x7c,0xda,0xa2,0x3a,0xda,0xa3,0x7c,0xd7,0xa2,0x7c,0xda,0xa2,0x7c,0xda,0xa2,0x3a,0xda,0xa2,0x7c,0xd7,0xa2,0x7c,0xda,0xa2,0x3a,0xda,0x82,0x3a,0xd2,0xa2,0x2d,0x7c,0xda,0xa2,0x3a,0xda,0xa2,0x7c,0xd7,0xa2,0x7c,0xda,0xa2,0x3a,0xda,0xa2,0x2e,0xda,0x82,0x3a,0xd2,0xa2,0x2d,0x7c,0xda,0xa2,0x3a,0x7c,0xd7,0xa2,0x7c,0xda,0xa2,0x3a,0xd9,0xa2,0xd2,0xa2,0x2d,0x7c,0xda,0xa2,0x3a,0xda,0xa2,0x7c,0xd7,0xa2,0x7c,0xda,0xa2,0x2e,0xda,0x82,0x3a,0xd2,0xa2,0x2d,0x7c,0xda,0xa2,0x3a,0xda,0xa2,0x7c,0xd7,0xa2,0x7c,0xda,0xa2,0x3a,0x7c,0xd7,0xa2,0x7c,0xda,0xa2,0x3a,0xda,0xa2,0x7c,0xd7,0xa2,0x7c,0xda,0xa2,0x3a,0xda,0xa2,0x2e, Step #5: <!DOCTYPE\012Y[<!ATTLIST\015E x (\332\242-|\332\242:\332\202tYEE-|\332\242:\332\202|YU:-|\332\242:\332\242|\327\242|\332\242:-|\332\242:\332\242|\327\242|\332\242-|\332\242:\332\243|\327\242|\332\242|\332\242:\332\242|\327\242|\332\242:\332\202:\322\242-|\332\242:\332\242|\327\242|\332\242:\332\242.\332\202:\322\242-|\332\242:|\327\242|\332\242:\331\242\322\242-|\332\242:\332\242|\327\242|\332\242.\332\202:\322\242-|\332\242:\332\242|\327\242|\332\242:|\327\242|\332\242:\332\242|\327\242|\332\242:\332\242. Step #5: artifact_prefix='./'; Test unit written to ./oom-9efabbe2e0a79f99ac24fd81e58963f8e43da066 Step #5: Base64: PCFET0NUWVBFCllbPCFBVFRMSVNUDUUgeCAo2qItfNqiOtqCdFlFRS182qI62oJ8WVU6LXzaojraonzXonzaojotfNqiOtqifNeifNqiLXzaojrao3zXonzaonzaojraonzXonzaojragjrSoi182qI62qJ816J82qI62qIu2oI60qItfNqiOnzXonzaojrZotKiLXzaojraonzXonzaoi7agjrSoi182qI62qJ816J82qI6fNeifNqiOtqifNeifNqiOtqiLg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4888 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4191865390 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555713fb1810, 0x55571419b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55571419b020,0x5557160330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9efabbe2e0a79f99ac24fd81e58963f8e43da066' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6161 processed earlier; will process 4868 files now Step #5: ==176044== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55570aaa69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55571110b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557110ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557110ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55570aaacd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55570aa0db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55570aa08355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55570aa9ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55570da6df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55570da6df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55570da6df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55570da6df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55570da6df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55570da6df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55570da6df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55570da6df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55570da6df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55570da6df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55570fd02f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55570ca2fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55570ca3abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55570c7e6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55570c7e6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55570c7e7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55570c7e6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55570c7e6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55570c7e6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557110f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557110f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557110e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55571110c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe1c3622082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55570aa06b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x81,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x81,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x81,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x90,0xe1,0x85,0xa2,0xe1,0x85,0xb1,0xa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x85,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb1,0xe1,0x84,0x91,0xe1,0x85,0xa2,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x81,0xe1,0x85,0xaa,0xe1,0x84,0x91,0xe1,0x85,0xb0,0xe1,0x84,0x91, Step #5: \341\204\221\341\205\260\341\204\221\341\205\260\341\204\201\341\205\260\341\204\221\341\205\260\341\204\221\341\205\260\341\204\221\341\205\252\341\204\221\341\205\260\341\204\221\341\205\260\341\204\201\341\205\260\341\204\221\341\205\260\341\204\221\341\205\260\341\204\221\341\205\252\341\204\221\341\205\260\341\204\221\341\205\260\341\204\201\341\205\260\341\204\221\341\205\260\341\204\221\341\205\260\341\204\220\341\205\242\341\205\261\012\341\204\221\341\205\260\341\204\221\341\205\260\341\204\221\341\205\260\341\204\221\341\205\260\341\204\205\341\205\260\341\204\221\341\205\260\341\204\221\341\205\261\341\204\221\341\205\242\341\204\221\341\205\260\341\204\221\341\205\260\341\204\221\341\205\252\341\204\221\341\205\260\341\204\201\341\205\252\341\204\221\341\205\260\341\204\221 Step #5: artifact_prefix='./'; Test unit written to ./oom-bb0047fcf2552e105e74098e5ddfcbebabe1b403 Step #5: Base64: 4YSR4YWw4YSR4YWw4YSB4YWw4YSR4YWw4YSR4YWw4YSR4YWq4YSR4YWw4YSR4YWw4YSB4YWw4YSR4YWw4YSR4YWw4YSR4YWq4YSR4YWw4YSR4YWw4YSB4YWw4YSR4YWw4YSR4YWw4YSQ4YWi4YWxCuGEkeGFsOGEkeGFsOGEkeGFsOGEkeGFsOGEheGFsOGEkeGFsOGEkeGFseGEkeGFouGEkeGFsOGEkeGFsOGEkeGFquGEkeGFsOGEgeGFquGEkeGFsOGEkQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4889 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4192398064 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557125ddf810, 0x557125fc901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557125fc9020,0x557127e610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bb0047fcf2552e105e74098e5ddfcbebabe1b403' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6162 processed earlier; will process 4867 files now Step #5: ==176080== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55711c8d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557122f39898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557122f1c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557122f1c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55711c8dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55711c83bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55711c836355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55711c8ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55711f89bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55711f89bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55711f89bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55711f89bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55711f89bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55711f89bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55711f89bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55711f89bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55711f89bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55711f89bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557121b30f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55711e85db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55711e868be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55711e614c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55711e614c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55711e615738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55711e614874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55711e614874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55711e614874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557122f1eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557122f27928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557122f0f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557122f3a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd8470e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55711c834b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x25,0x50,0x2f,0x9,0x64,0x50,0x50,0x50,0x50,0x50,0x50,0xc,0xc,0xc,0x15,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xd,0xc,0x43,0x46,0x46,0xb,0x0,0x20,0x24,0x13,0x60,0x1f,0x50,0x50,0xc,0xc,0x4e,0xb4,0xf1,0xcb,0x0,0x5b, Step #5: `%P/\011dPPPPPP\014\014\014\025\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\015\014CFF\013\000 $\023`\037PP\014\014N\264\361\313\000[ Step #5: artifact_prefix='./'; Test unit written to ./oom-b7ed8f9f261904b1ca74d7a4c8dc17868382ffff Step #5: Base64: YCVQLwlkUFBQUFBQDAwMFQsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCw0MQ0ZGCwAgJBNgH1BQDAxOtPHLAFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4890 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4193090281 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56326cfb0810, 0x56326d19a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56326d19a020,0x56326f0320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7ed8f9f261904b1ca74d7a4c8dc17868382ffff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6163 processed earlier; will process 4866 files now Step #5: #1 pulse cov: 4014 ft: 4015 exec/s: 0 rss: 178Mb Step #5: ==176116== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563263aa59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56326a10a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56326a0ed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56326a0ed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563263aabd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563263a0cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563263a07355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563263a9dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563266a6cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563266a6cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563266a6cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563266a6cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563266a6cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563266a6cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563266a6cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563266a6cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563266a6cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563266a6cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563268d01f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563265a2eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563265a39be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5632657e5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5632657e5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5632657e6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5632657e5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5632657e5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5632657e5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56326a0efabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56326a0f8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56326a0e0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56326a10b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1e77db2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563263a05b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x25,0x50,0x2f,0x9,0x64,0x58,0x50,0x50,0x50,0x50,0x50,0xc,0xc,0xc,0x15,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0x5d,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xb,0xd,0xc,0x43,0x46,0x46,0xb,0x0,0x20,0x24,0x13,0x60,0x1f,0x50,0x50,0xc,0xc,0x4e,0xb4,0xf1,0xcb,0x0,0x5b, Step #5: `%P/\011dXPPPPP\014\014\014\025\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013]\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\013\015\014CFF\013\000 $\023`\037PP\014\014N\264\361\313\000[ Step #5: artifact_prefix='./'; Test unit written to ./oom-ab7b6dc75095fc2a5e01ac45593eabccd224ba49 Step #5: Base64: YCVQLwlkWFBQUFBQDAwMFQsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwtdCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCwsLCw0MQ0ZGCwAgJBNgH1BQDAxOtPHLAFs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4891 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4193823078 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564e4eecd810, 0x564e4f0b701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564e4f0b7020,0x564e50f4f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ab7b6dc75095fc2a5e01ac45593eabccd224ba49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6165 processed earlier; will process 4864 files now Step #5: #1 pulse cov: 11397 ft: 11398 exec/s: 0 rss: 195Mb Step #5: #2 pulse cov: 12113 ft: 12987 exec/s: 0 rss: 197Mb Step #5: ==176152== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564e459c29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564e4c027898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564e4c00a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564e4c00a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564e459c8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564e45929b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564e45924355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564e459bac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564e48989f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564e48989f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564e48989f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564e48989f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564e48989f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564e48989f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564e48989f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564e48989f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564e48989f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564e48989f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564e4ac1ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564e4794bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564e47956be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564e47702c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564e47702c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564e47703738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564e47702874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564e47702874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564e47702874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564e4c00cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564e4c015928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564e4bffd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564e4c028112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9c443c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564e45922b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x65,0x1,0x13,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x28,0x55, Step #5: ID3\002e\001\023\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000(U Step #5: artifact_prefix='./'; Test unit written to ./oom-2a4fbd986b529e75c4c735f62cac1cccc7ae6ba2 Step #5: Base64: SUQzAmUBEwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAKFU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4892 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4194472864 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b61a83810, 0x555b61c6d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b61c6d020,0x555b63b050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2a4fbd986b529e75c4c735f62cac1cccc7ae6ba2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6168 processed earlier; will process 4861 files now Step #5: #1 pulse cov: 4014 ft: 4015 exec/s: 0 rss: 176Mb Step #5: ==176188== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555b585789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b5ebdd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b5ebc05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b5ebc04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b5857ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b584dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b584da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b58570c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b5b53ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b5b53ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b5b53ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b5b53ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b5b53ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b5b53ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b5b53ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b5b53ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b5b53ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b5b53ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b5d7d4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b5a501b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b5a50cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b5a2b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b5a2b8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b5a2b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b5a2b8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b5a2b8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b5a2b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b5ebc2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b5ebcb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b5ebb3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b5ebde112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb5802a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b584d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe9,0x80,0x88,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x0,0x60,0xa,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x80,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x3c,0x68,0x68,0x68,0xf3,0xa0,0x6c,0x69,0x67,0x68,0x74,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xf3,0x33,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0x2f,0xa,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xa,0xa,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2f,0xa,0x2f,0xa,0x60,0x60,0x20,0x20,0x20,0x60,0xa,0x9, Step #5: `\351\200\210\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000-\000`\012hhhhhhhhhhhhhhhhhhhhhhhhhh\200hhhhhhhhh<hhh\363\240light\342\200\210-\000`\012\3633\004\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012`\342\200\210-\000``\342\200\210-\000`\012/\012`\342\200\210-\000`\012\012\012\000\000\000\000\000\000\000/\012/\012`` `\012\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-e3f1bb712b22d4dafc3dd88d9621ab8298935678 Step #5: Base64: YOmAiAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALQBgCmhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhogGhoaGhoaGhoaDxoaGjzoGxpZ2h04oCILQBgCvMzBAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACmDigIgtAGBg4oCILQBgCi8KYOKAiC0AYAoKCgAAAAAAAAAvCi8KYGAgICBgCgk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4893 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4195171404 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a7f176810, 0x560a7f36001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a7f360020,0x560a811f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e3f1bb712b22d4dafc3dd88d9621ab8298935678' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6170 processed earlier; will process 4859 files now Step #5: #1 pulse cov: 3497 ft: 3498 exec/s: 0 rss: 174Mb Step #5: ==176224== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560a75c6b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a7c2d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a7c2b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a7c2b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a75c71d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a75bd2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a75bcd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a75c63c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a78c32f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a78c32f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a78c32f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a78c32f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a78c32f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a78c32f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a78c32f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a78c32f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a78c32f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a78c32f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a7aec7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a77bf4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a77bffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a779abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a779abc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a779ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a779ab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a779ab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a779ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a7c2b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a7c2be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a7c2a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a7c2d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f51fde4b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a75bcbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x3a,0x3f,0x41,0x77,0x73,0x3a,0x67,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbc,0xb1,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xea,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbc,0xb1,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0x93,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbc,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3, Step #5: A:?Aws:g\340\275\263\340\275\265\340\275\265\340\274\261\340\275\263\340\275\265\340\275\263\340\275\265\340\275\265\340\275\263\352\275\265\340\275\265\340\275\265\340\275\261\340\275\265\340\275\263\340\275\265\340\275\261\340\275\265\340\275\265\340\275\265\340\275\265\340\274\261\340\275\263\340\275\265\340\275\265\340\275\263\340\275\265\340\275\265\340\275\265\340\275\261\340\275\265\340\275\263\340\275\265\340\275\265\340\275\265\340\275\265\340\275\223\340\275\265\340\275\265\340\275\263\340\275\265\340\275\263\340\275\265\340\274\261\340\275\265\340\275\265\340\275\265\340\275\265\340\275\265\340\275\261\340\275\265\340\275\265\340\275\263\340\275\265\340\275\263\340\275\265\340\275\265\340\275\265\340\275\261\340\275\265\340\275\265\340\275\263\340\275\263 Step #5: artifact_prefix='./'; Test unit written to ./oom-fc09629736c46be790cd7ada2d1dafeba7dbf406 Step #5: Base64: QTo/QXdzOmfgvbPgvbXgvbXgvLHgvbPgvbXgvbPgvbXgvbXgvbPqvbXgvbXgvbXgvbHgvbXgvbPgvbXgvbHgvbXgvbXgvbXgvbXgvLHgvbPgvbXgvbXgvbPgvbXgvbXgvbXgvbHgvbXgvbPgvbXgvbXgvbXgvbXgvZPgvbXgvbXgvbPgvbXgvbPgvbXgvLHgvbXgvbXgvbXgvbXgvbXgvbHgvbXgvbXgvbPgvbXgvbPgvbXgvbXgvbXgvbHgvbXgvbXgvbPgvbM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4894 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4195748060 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee28600810, 0x55ee287ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee287ea020,0x55ee2a6820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc09629736c46be790cd7ada2d1dafeba7dbf406' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6172 processed earlier; will process 4857 files now Step #5: #1 pulse cov: 16366 ft: 16367 exec/s: 0 rss: 208Mb Step #5: #2 pulse cov: 16898 ft: 17810 exec/s: 0 rss: 210Mb Step #5: ==176260== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ee1f0f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee2575a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee2573d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee2573d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee1f0fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee1f05cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee1f057355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee1f0edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee220bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee220bcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee220bcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee220bcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee220bcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee220bcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee220bcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee220bcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee220bcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee220bcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee24351f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee2107eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee21089be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee20e35c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee20e35c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee20e36738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee20e35874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee20e35874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee20e35874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee2573fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee25748928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee25730699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee2575b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faeda340082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee1f055b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xe2,0x80,0xa8,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xe2,0x80,0xa8,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x73,0x74,0x72,0x65,0x61,0x6d,0xa,0x1,0x14,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x29,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012\342\200\250=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012\342\200\250=\012=\012=\012=stream\012\001\024=\012=\012=\012=\012=\012=\012=)=\012=\012==\012\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-ddaf56254f8ffa14e57908b593d0d0da6e922206 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj09Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cgo9Cj0KPQo9Cj0KPQrigKg9Cgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoKPQo9Cj0KPQo9Cj0K4oCoPQo9Cj0KPXN0cmVhbQoBFD0KPQo9Cj0KPQo9Cj0pPQo9Cj09CgoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4895 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4196546748 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d45127810, 0x564d4531101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d45311020,0x564d471a90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ddaf56254f8ffa14e57908b593d0d0da6e922206' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6175 processed earlier; will process 4854 files now Step #5: ==176296== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d3bc1c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d42281898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d422645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d422644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d3bc22d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d3bb83b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d3bb7e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d3bc14c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d3ebe3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d3ebe3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d3ebe3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d3ebe3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d3ebe3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d3ebe3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d3ebe3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d3ebe3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d3ebe3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d3ebe3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d40e78f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d3dba5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d3dbb0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d3d95cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d3d95cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d3d95d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d3d95c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d3d95c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d3d95c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d42266abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d4226f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d42257699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d42282112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe19f417082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d3bb7cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xa,0x0,0x0,0x59,0x3e,0x30,0x2b,0x34,0x27,0x73,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x43,0x5f,0x4c,0x51,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x74,0x72,0x65,0x0,0x59,0x3e,0x35,0x2b,0x34,0x27,0x0,0x3a,0xd8,0x80,0x4,0x2b,0x0, Step #5: \000\012\000\000Y>0+4's\001t`\000\002____C_LQ__\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001_\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002_tre\000Y>5+4'\000:\330\200\004+\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1ef19fc05254e947860899419565b3420ed9f838 Step #5: Base64: AAoAAFk+MCs0J3MBdGAAAl9fX19DX0xRX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BXwF0YAACX19fX1VgYF9fXwF0YAACX19fX1VgYF9fXwF0YAACX19fX1VgYF9fXwF0YAACX19fX1VgYF9fXwF0YAACX3RyZQBZPjUrNCcAOtiABCsA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4896 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4197213158 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5596214f0810, 0x5596216da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596216da020,0x5596235720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ef19fc05254e947860899419565b3420ed9f838' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6176 processed earlier; will process 4853 files now Step #5: ==176332== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559617fe59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55961e64a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55961e62d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55961e62d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559617febd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559617f4cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559617f47355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559617fddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55961afacf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55961afacf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55961afacf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55961afacf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55961afacf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55961afacf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55961afacf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55961afacf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55961afacf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55961afacf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55961d241f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559619f6eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559619f79be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559619d25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559619d25c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559619d26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559619d25874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559619d25874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559619d25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55961e62fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55961e638928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55961e620699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55961e64b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa2f1a82082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559617f45b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x7b,0x20,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0xa,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0x9,0x20,0x20,0x20,0x20,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0xa,0x20,0x6e,0x61,0x6d,0x65,0x3a,0xb,0xb,0x22,0x44,0x20,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x27,0x47,0x53,0x3d,0x27,0x20,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x2b,0x3a,0x37,0x30,0x36,0x38,0x36,0x37,0x30,0x32,0x37,0x36,0x2f,0x79,0x78,0x33,0x2d,0x39,0x33,0x33,0x35,0x78,0x78,0x79,0x78,0x78,0x34,0x33,0x33,0x37,0x32,0x30,0x30,0x35,0x1d,0x1d,0x1d,0x1d,0x1d,0x30,0x20,0x3c,0x48,0x3e,0x2d,0x38,0x30,0x33,0x32,0x32,0x39,0x34,0x36,0x32,0x38,0x38,0x74,0x32,0x32,0x32,0x32,0x32,0x32,0x31,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x31,0x28,0x32,0x32,0x3e,0x27,0x20,0x20,0xd,0x3e,0x20,0x20,0x5c,0x30,0x30,0x20,0x3c,0x48,0x3e,0x21,0x46,0x22,0x20,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x76,0x61,0x6c,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x22,0x20,0x20,0x20,0x7d,0x7d,0xa,0x20,0x20,0x7d,0x20,0x7d,0xb,0x2c,0x7d,0x7d, Step #5: p{ doctype\012{\012mdecl {\011 entity {\012 name:\013\013\"D PUBLIC 'GS=' 'http://+:7068670276/yx3-9335xxyxx43372005\035\035\035\035\0350 <H>-80322946288t22222212222222221(22>' \015> \\00 <H>!F\" ent {\012 val { name: \"D\" }}\012 } }\013,}} Step #5: artifact_prefix='./'; Test unit written to ./oom-08bff60e4b2ce5d34dc708aaa2f81c06528bcb77 Step #5: Base64: cHsgZG9jdHlwZQp7Cm1kZWNsIHsJICAgIGVudGl0eSB7CiBuYW1lOgsLIkQgIFBVQkxJQyAnR1M9JyAnaHR0cDovLys6NzA2ODY3MDI3Ni95eDMtOTMzNXh4eXh4NDMzNzIwMDUdHR0dHTAgPEg+LTgwMzIyOTQ2Mjg4dDIyMjIyMjEyMjIyMjIyMjIxKDIyPicgIA0+ICBcMDAgPEg+IUYiIGVudCB7CiAgdmFsIHsgbmFtZTogIkQiICAgfX0KICB9IH0LLH19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4897 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4197750674 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb6b6da810, 0x55bb6b8c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb6b8c4020,0x55bb6d75c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08bff60e4b2ce5d34dc708aaa2f81c06528bcb77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6177 processed earlier; will process 4852 files now Step #5: ==176368== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bb621cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb68834898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb688175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb688174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb621d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb62136b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb62131355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb621c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb65196f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb65196f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb65196f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb65196f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb65196f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb65196f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb65196f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb65196f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb65196f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb65196f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb6742bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb64158b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb64163be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb63f0fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb63f0fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb63f10738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb63f0f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb63f0f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb63f0f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb68819abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb68822928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb6880a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb68835112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbefd84e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb6212fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x24,0xa,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x24,0x20,0x24,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x41,0x20,0x20,0x24,0x20,0x24,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x25,0x20,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x20,0x24,0x20,0x24,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x20,0x24,0x20,0x24,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x20,0x24,0x20,0x24,0x20,0x41,0x20,0x20,0x41,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x41,0x20,0x24,0x20,0x24,0x20,0x24,0x20,0x41,0x20,0x24, Step #5: $$\012 $ A $ A $ $ $A $ A $ $ $ $ A $ $A $ A $ $ $ A $ A $ $ $ A $ A $ A % $ A $ A $ $A $ A $ $ $ A $ A $ $ A $ A $ A $ A $ A $ A $ $ $ A $ A $ $A $ A $ $ $ A $ A $ $ $ A A$ A $ A $ A $ A $ $ $ A $ Step #5: artifact_prefix='./'; Test unit written to ./oom-b7019b1c7e6d886e01afb10b0a6f68afbd573290 Step #5: Base64: JCQKICQgQSAkIEEgJCAkICRBICQgQSAkICQgJCAkIEEgICQgJEEgJCBBICQgJCAkIEEgJCBBICQgJCAkIEEgJCBBICQgQSAlICAkIEEgJCBBICAkICRBICQgQSAkICQgJCBBICQgQSAkICAkIEEgJCBBICQgQSAkIEEgJCBBICQgQSAkICQgJCBBICQgQSAgJCAkQSAkIEEgJCAkICQgQSAkIEEgJCAgJCAkIEEgIEEkIEEgJCBBICQgQSAkIEEgJCAkICQgQSAk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4898 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4198305101 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557e76423810, 0x557e7660d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557e7660d020,0x557e784a50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7019b1c7e6d886e01afb10b0a6f68afbd573290' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6178 processed earlier; will process 4851 files now Step #5: ==176404== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557e6cf189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557e7357d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557e735605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557e735604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557e6cf1ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557e6ce7fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557e6ce7a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557e6cf10c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557e6fedff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557e6fedff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557e6fedff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557e6fedff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557e6fedff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557e6fedff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557e6fedff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557e6fedff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557e6fedff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557e6fedff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557e72174f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557e6eea1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557e6eeacbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557e6ec58c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557e6ec58c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557e6ec59738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557e6ec58874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557e6ec58874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557e6ec58874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557e73562abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557e7356b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557e73553699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557e7357e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f72e815f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557e6ce78b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x30,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x1d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x25,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3f,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=0=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\035\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=%\012=\012=\012=\012=\012\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012?\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-c2cea5f6a0f2fee052daf2ba575da43f5e961782 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9MD0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Ch0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KCj0KPQo9Cj0KPQo9Cj0lCj0KPQo9Cj0KAAo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj8KEA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4899 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4198854962 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55760cac3810, 0x55760ccad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55760ccad020,0x55760eb450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c2cea5f6a0f2fee052daf2ba575da43f5e961782' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6179 processed earlier; will process 4850 files now Step #5: ==176440== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5576035b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557609c1d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557609c005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557609c004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5576035bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55760351fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55760351a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5576035b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55760657ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55760657ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55760657ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55760657ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55760657ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55760657ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55760657ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55760657ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55760657ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55760657ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557608814f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557605541b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55760554cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5576052f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5576052f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5576052f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5576052f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5576052f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5576052f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557609c02abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557609c0b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557609bf3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557609c1e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5750c25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557603518b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x31,0x4,0x48,0x12,0x12,0x3,0x1f,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x0,0x48,0x12,0x12,0x3,0x1f,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x0,0x5b,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x0,0x5b,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x0,0x5b,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x0,0x5b,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x0,0x5b,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x6d,0x61,0x78,0x70,0x0,0x5,0x0,0x48,0x12,0x12,0x3,0x1f,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x0,0x5b,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x0,0x5b,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x0,0x5b,0x0,0x0,0x0,0x0,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x0,0x5b,0x0,0x0,0x0,0x0,0x5b, Step #5: ID1\004H\022\022\003\037\000APIC\000\000\000\005\000H\022\022\003\037\000APIC\000\000\000\005\000[\000\000\000\000\000APIC\000\000\000\005\000[\000\000\000\000\000APIC\000\000\000\005\000[\000\000\000\000\000APIC\000\000\000\005\000[\000\000\000\000\000APIC\000\000\000\005\000[\000\000\000\000\000APIC\000\000maxp\000\005\000H\022\022\003\037\000APIC\000\000\000\005\000[\000\000\000\000\000APIC\000\000\000\005\000[\000\000\000\000\000APIC\000\000\000\005\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000APIC\000\000\000\005\000[\000\000\000\000\000APIC\000\000\000\005\000[\000\000\000\000[ Step #5: artifact_prefix='./'; Test unit written to ./oom-8b9578358fe1b93972fd176b1272858430b974b7 Step #5: Base64: SUQxBEgSEgMfAEFQSUMAAAAFAEgSEgMfAEFQSUMAAAAFAFsAAAAAAEFQSUMAAAAFAFsAAAAAAEFQSUMAAAAFAFsAAAAAAEFQSUMAAAAFAFsAAAAAAEFQSUMAAAAFAFsAAAAAAEFQSUMAAG1heHAABQBIEhIDHwBBUElDAAAABQBbAAAAAABBUElDAAAABQBbAAAAAABBUElDAAAABQAAAAAAAAAAAAAAAAAAAEFQSUMAAAAFAFsAAAAAAEFQSUMAAAAFAFsAAAAAWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4900 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4199383693 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1f3be3810, 0x55d1f3dcd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1f3dcd020,0x55d1f5c650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8b9578358fe1b93972fd176b1272858430b974b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6180 processed earlier; will process 4849 files now Step #5: ==176476== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d1ea6d89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1f0d3d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1f0d205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1f0d204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1ea6ded42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1ea63fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1ea63a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1ea6d0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1ed69ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1ed69ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1ed69ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1ed69ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1ed69ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1ed69ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1ed69ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1ed69ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1ed69ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1ed69ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1ef934f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1ec661b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1ec66cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1ec418c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1ec418c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1ec419738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1ec418874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1ec418874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1ec418874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1f0d22abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1f0d2b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1f0d13699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1f0d3e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3fc705f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1ea638b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x77,0x0,0x0,0x22,0x72,0x3a,0x72,0x72,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0x83,0x72,0x3a,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0x80,0x72,0x3a,0x5c,0x5c,0xcf,0x83,0x72,0x3a,0x5c,0x66,0x5c,0x5c,0xcf,0xa4,0x5c,0x5c,0xcf,0x83,0x72,0x3a,0x5c,0x66,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0x83,0x72,0x72,0x72,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0x83,0x72,0x3a,0x5c,0x5c,0xcf,0x83,0x71,0x3a,0x5c,0x66,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0x83,0x66,0x3a,0x5c,0x66,0xcf,0x83,0x72,0x3a,0x5c,0x66,0x5c,0x66,0xcf,0xa3,0x5c,0x5c,0xcf,0x83,0x2e,0x72,0x72,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0x83,0x72,0x3a,0x5c,0x5c,0xcf,0x83,0x72,0x3a,0x5c,0x66,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0x83,0x72,0x3a,0x5c,0x66,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0x83,0x5c,0x5c,0xcf,0x83,0x72,0x72,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0x83,0x5c,0x3a,0x5c,0x5c,0x5c,0x72,0x3a,0x83,0xcf,0x5c,0x66,0x5c,0xcf,0xa3,0x5c,0x5c,0xcf,0x22,0x41, Step #5: \000\000\000\000\000w\000\000\"r:rr\\\\\317\243\\\\\317\243\\\\\317\203r:\\\\\317\243\\\\\317\243\\\\\317\200r:\\\\\317\203r:\\f\\\\\317\244\\\\\317\203r:\\f\\\\\317\243\\\\\317\203rrr\\\\\317\243\\\\\317\243\\\\\317\203r:\\\\\317\203q:\\f\\\\\317\243\\\\\317\203f:\\f\317\203r:\\f\\f\317\243\\\\\317\203.rr\\\\\317\243\\\\\317\243\\\\\317\203r:\\\\\317\203r:\\f\\\\\317\243\\\\\317\203r:\\f\\\\\317\243\\\\\317\203\\\\\317\203rr\\\\\317\243\\\\\317\243\\\\\317\203\\:\\\\\\r:\203\317\\f\\\317\243\\\\\317\"A Step #5: artifact_prefix='./'; Test unit written to ./oom-cd102ad5f8a397fbbab08234feff0f820a2fdb1d Step #5: Base64: AAAAAAB3AAAicjpyclxcz6NcXM+jXFzPg3I6XFzPo1xcz6NcXM+AcjpcXM+DcjpcZlxcz6RcXM+DcjpcZlxcz6NcXM+DcnJyXFzPo1xcz6NcXM+DcjpcXM+DcTpcZlxcz6NcXM+DZjpcZs+DcjpcZlxmz6NcXM+DLnJyXFzPo1xcz6NcXM+DcjpcXM+DcjpcZlxcz6NcXM+DcjpcZlxcz6NcXM+DXFzPg3JyXFzPo1xcz6NcXM+DXDpcXFxyOoPPXGZcz6NcXM8iQQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4901 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4199916474 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b4b1901810, 0x55b4b1aeb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b4b1aeb020,0x55b4b39830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd102ad5f8a397fbbab08234feff0f820a2fdb1d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6181 processed earlier; will process 4848 files now Step #5: ==176512== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b4a83f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b4aea5b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b4aea3e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b4aea3e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b4a83fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b4a835db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b4a8358355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b4a83eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b4ab3bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b4ab3bdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b4ab3bdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b4ab3bdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b4ab3bdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b4ab3bdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b4ab3bdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b4ab3bdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b4ab3bdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b4ab3bdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b4ad652f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b4aa37fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b4aa38abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b4aa136c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b4aa136c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b4aa137738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b4aa136874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b4aa136874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b4aa136874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b4aea40abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b4aea49928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b4aea31699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b4aea5c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fae6dd50082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b4a8356b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x73,0x64,0x3,0x67,0xe,0x68,0x68,0x43,0xda,0x82,0x0,0x20,0x79,0x11,0x47,0x0,0x54,0x49,0x42,0x2b,0x0,0x0,0x5b,0x67,0xe,0x68,0x68,0x43,0xda,0x82,0x1,0x70,0x11,0x47,0x0,0x54,0x49,0x42,0x2b,0x0,0x0,0x5b,0x67,0xe,0x68,0x68,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x44,0x33,0x73,0x64,0x3,0x67,0xe,0x68,0x68,0x43,0xda,0x82,0x0,0x20,0x79,0x11,0x47,0x0,0x54,0x49,0x42,0x2b,0x0,0x0,0x5b,0x67,0xe,0x68,0x68,0x43,0xda,0x82,0x1,0x70,0x11,0x47,0x0,0x54,0x49,0x42,0x2b,0x0,0x0,0x20,0x20,0x54,0x49,0x42,0x4f,0x0,0x0,0x5b,0x79,0x11,0x47,0x0,0x54,0x49,0x42,0x2b,0x0,0x0,0x5b,0x67,0xe,0x68,0x68,0x43,0xda,0x82,0x1,0x70,0x11,0x47,0x0,0x54,0x49,0x42,0x2b,0x0,0x0,0x5b,0x67,0xe,0x68,0x68,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x44,0x33,0x73,0x64,0x3,0x67,0xe,0x68,0x68,0x43,0xda,0x82,0x0,0x20,0x79,0x11,0x47,0x0,0x54,0x49,0x42,0x2b,0x0,0x0,0x5b,0x67,0xe,0x68,0x68,0x43,0xda,0x82,0x1,0x70,0x11,0x47,0x0,0x54,0x49,0x67,0xe,0x68,0x68,0x43,0xda,0x82,0x1,0x70,0x70,0x70,0x70,0x70,0x20, Step #5: ID3sd\003g\016hhC\332\202\000 y\021G\000TIB+\000\000[g\016hhC\332\202\001p\021G\000TIB+\000\000[g\016hh D3sd\003g\016hhC\332\202\000 y\021G\000TIB+\000\000[g\016hhC\332\202\001p\021G\000TIB+\000\000 TIBO\000\000[y\021G\000TIB+\000\000[g\016hhC\332\202\001p\021G\000TIB+\000\000[g\016hh D3sd\003g\016hhC\332\202\000 y\021G\000TIB+\000\000[g\016hhC\332\202\001p\021G\000TIg\016hhC\332\202\001ppppp Step #5: artifact_prefix='./'; Test unit written to ./oom-d7b6042a6fa8ddf554941998e1bd3279187982b8 Step #5: Base64: SUQzc2QDZw5oaEPaggAgeRFHAFRJQisAAFtnDmhoQ9qCAXARRwBUSUIrAABbZw5oaCAgICAgICBEM3NkA2cOaGhD2oIAIHkRRwBUSUIrAABbZw5oaEPaggFwEUcAVElCKwAAICBUSUJPAABbeRFHAFRJQisAAFtnDmhoQ9qCAXARRwBUSUIrAABbZw5oaCAgICAgICBEM3NkA2cOaGhD2oIAIHkRRwBUSUIrAABbZw5oaEPaggFwEUcAVElnDmhoQ9qCAXBwcHBwIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4902 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4200444527 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bea4389810, 0x55bea457301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bea4573020,0x55bea640b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d7b6042a6fa8ddf554941998e1bd3279187982b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6182 processed earlier; will process 4847 files now Step #5: ==176548== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55be9ae7e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bea14e3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bea14c65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bea14c64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55be9ae84d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55be9ade5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55be9ade0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55be9ae76c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55be9de45f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55be9de45f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55be9de45f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55be9de45f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55be9de45f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55be9de45f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55be9de45f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55be9de45f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55be9de45f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55be9de45f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bea00daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55be9ce07b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55be9ce12be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55be9cbbec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55be9cbbec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55be9cbbf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55be9cbbe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55be9cbbe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55be9cbbe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bea14c8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bea14d1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bea14b9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bea14e4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f87f73082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55be9addeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x28,0x6b,0x3f,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0x5c,0x6b,0x3c,0x46,0x3e,0xfa,0x5d, Step #5: (?<F>\\k<F>\\k<F>\\k<F>\\k<F>\\k<F>\\k<F>\\k<F>\\k<F>\\k<F>\\k<F>\\k<F>\\k>\\k<F>\\k<F>\\k>\\k<F>\\k<F>\\k<F>F>\\k<F><F>\\k<F>\\k<F>\\k<F>\\k<F>(k?<F>\\k<F>\\k<F>\\k<F>\\k<F>\\k<F>\\k<F>\\k<F>\\k>\\k<F>\\k<F>\\k<F>F>\\k<F><F>\\k<F>\\k<F>\372] Step #5: artifact_prefix='./'; Test unit written to ./oom-da0a0161fb6aee1ac3805a6edce1d89f9e3991ba Step #5: Base64: KD88Rj5cazxGPlxrPEY+XGs8Rj5cazxGPlxrPEY+XGs8Rj5cazxGPlxrPEY+XGs8Rj5cazxGPlxrPEY+XGs+XGs8Rj5cazxGPlxrPlxrPEY+XGs8Rj5cazxGPkY+XGs8Rj48Rj5cazxGPlxrPEY+XGs8Rj5cazxGPihrPzxGPlxrPEY+XGs8Rj5cazxGPlxrPEY+XGs8Rj5cazxGPlxrPEY+XGs+XGs8Rj5cazxGPlxrPEY+Rj5cazxGPjxGPlxrPEY+XGs8Rj76XQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4903 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4200973517 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e6edd97810, 0x55e6edf8101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e6edf81020,0x55e6efe190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/da0a0161fb6aee1ac3805a6edce1d89f9e3991ba' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6183 processed earlier; will process 4846 files now Step #5: ==176584== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e6e488c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e6eaef1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e6eaed45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e6eaed44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e6e4892d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e6e47f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e6e47ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e6e4884c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e6e7853f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e6e7853f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e6e7853f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e6e7853f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e6e7853f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e6e7853f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e6e7853f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e6e7853f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e6e7853f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e6e7853f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e6e9ae8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e6e6815b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e6e6820be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e6e65ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e6e65ccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e6e65cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e6e65cc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e6e65cc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e6e65cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e6eaed6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e6eaedf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e6eaec7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e6eaef2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f416e5e1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e6e47ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x20,0x7b,0x21,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x78,0xa,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x78,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x78,0xa,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x78,0xa,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0xa,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x78,0xa,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x78,0xa,0x2d,0x20,0x2d,0x20,0x2d,0x20,0x2d,0x20, Step #5: {!\015- - - - - - - - - - - - - - - -\012- - - - - x\012- - - - - - - - - - - x -\015- - - - - - - - - - - x\012- - - - - - - - - - - x\012- - - - - - - - - - - -\012- - - - - - - - - - - x\012- - - - - - - - - - - x\012- - - - Step #5: artifact_prefix='./'; Test unit written to ./oom-aa80fcd57469df5b6af10cf0dbf0d2fdd5b7a740 Step #5: Base64: IHshDS0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0gLSAtIC0KLSAtIC0gLSAtIHgKLSAtIC0gLSAtIC0gLSAtIC0gLSAtIHggLQ0tIC0gLSAtIC0gLSAtIC0gLSAtIC0geAotIC0gLSAtIC0gLSAtIC0gLSAtIC0geAotIC0gLSAtIC0gLSAtIC0gLSAtIC0gLQotIC0gLSAtIC0gLSAtIC0gLSAtIC0geAotIC0gLSAtIC0gLSAtIC0gLSAtIC0geAotIC0gLSAtIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4904 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4201624781 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563c05102810, 0x563c052ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563c052ec020,0x563c071840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aa80fcd57469df5b6af10cf0dbf0d2fdd5b7a740' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6184 processed earlier; will process 4845 files now Step #5: ==176620== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563bfbbf79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563c0225c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563c0223f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563c0223f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563bfbbfdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563bfbb5eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563bfbb59355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563bfbbefc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563bfebbef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563bfebbef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563bfebbef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563bfebbef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563bfebbef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563bfebbef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563bfebbef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563bfebbef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563bfebbef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563bfebbef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563c00e53f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563bfdb80b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563bfdb8bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563bfd937c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563bfd937c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563bfd938738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563bfd937874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563bfd937874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563bfd937874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563c02241abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563c0224a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563c02232699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563c0225d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f96432a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563bfbb57b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x21,0x6,0x76,0xe,0x20,0x14,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xcd,0x85,0x41,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0x18,0xe,0xe,0xe,0x18,0x20,0xe,0xe,0xe,0xf,0x21,0xe,0xe,0xe,0xe,0xe,0xe,0x20,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0x21,0xe,0x76,0xe,0x20,0x14,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0x25,0xcd,0x85,0x41,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0x18,0xe,0x1e,0xe,0x18,0x20,0xe,0xe,0xe,0xe,0x21,0xe,0xe,0xe,0xe,0xf,0xe,0x20,0xe,0xe,0xe,0xe,0xe,0x17,0xe,0xe,0xe,0x21,0x14,0x20,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xcd,0x85,0x41,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0x18,0xe,0xe,0xe,0x18,0x20,0xe,0xe,0xe,0xe,0x21,0xe,0xe,0xe,0xe,0xe,0xe,0x20,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0x21,0x14,0x20,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0xe,0x20,0xe,0xe,0xe,0xe,0xe,0xe,0x18,0xe,0xe,0xe,0x18,0x20,0xe,0xe,0xe,0xe,0x21,0xe,0xe,0xe,0xe,0xe,0xe,0x20,0xe,0xe,0xe,0xe,0xe,0xe,0x2d,0xe,0xe,0xe,0xe, Step #5: \016!\006v\016 \024\016\016\016\016\016\016\016\016\315\205A\016\016\016\016\016\016\016\030\016\016\016\030 \016\016\016\017!\016\016\016\016\016\016 \016\016\016\016\016\016\016\016\016!\016v\016 \024\016\016\016\016\016\016\016%\315\205A\016\016\016\016\016\016\016\030\016\036\016\030 \016\016\016\016!\016\016\016\016\017\016 \016\016\016\016\016\027\016\016\016!\024 \016\016\016\016\016\016\016\016\016\315\205A\016\016\016\016\016\016\016\030\016\016\016\030 \016\016\016\016!\016\016\016\016\016\016 \016\016\016\016\016\016\016\016\016!\024 \016\016\016\016\016\016\016\016\016\016\016 \016\016\016\016\016\016\030\016\016\016\030 \016\016\016\016!\016\016\016\016\016\016 \016\016\016\016\016\016-\016\016\016\016 Step #5: artifact_prefix='./'; Test unit written to ./oom-400852762d2df02e265c4800163717e5e50cda9f Step #5: Base64: DiEGdg4gFA4ODg4ODg4OzYVBDg4ODg4ODhgODg4YIA4ODg8hDg4ODg4OIA4ODg4ODg4ODiEOdg4gFA4ODg4ODg4lzYVBDg4ODg4ODhgOHg4YIA4ODg4hDg4ODg8OIA4ODg4OFw4ODiEUIA4ODg4ODg4ODs2FQQ4ODg4ODg4YDg4OGCAODg4OIQ4ODg4ODiAODg4ODg4ODg4hFCAODg4ODg4ODg4ODiAODg4ODg4YDg4OGCAODg4OIQ4ODg4ODiAODg4ODg4tDg4ODg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4905 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4202155446 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556037ba2810, 0x556037d8c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556037d8c020,0x556039c240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/400852762d2df02e265c4800163717e5e50cda9f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6185 processed earlier; will process 4844 files now Step #5: #1 pulse cov: 3725 ft: 3726 exec/s: 0 rss: 175Mb Step #5: ==176656== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55602e6979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556034cfc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556034cdf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556034cdf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55602e69dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55602e5feb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55602e5f9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55602e68fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55603165ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55603165ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55603165ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55603165ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55603165ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55603165ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55603165ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55603165ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55603165ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55603165ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5560338f3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556030620b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55603062bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5560303d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5560303d7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5560303d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5560303d7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5560303d7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5560303d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556034ce1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556034cea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556034cd2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556034cfd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f843208a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55602e5f7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x39,0x2d,0x31,0x2d,0x30,0x31,0x39,0x3a,0x34,0x3a,0x30,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x90,0xe1,0x9a,0x80,0xe1,0x9a,0x80,0xe1,0x9a,0x80, Step #5: 9-1-019:4:0\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\200\341\232\220\341\232\200\341\232\200\341\232\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-d93213b1e15369b15e8b7cfe2be48fa452b21385 Step #5: Base64: OS0xLTAxOTo0OjDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmoDhmpDhmoDhmoDhmoA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4906 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4202726590 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560d25614810, 0x560d257fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560d257fe020,0x560d276960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d93213b1e15369b15e8b7cfe2be48fa452b21385' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6187 processed earlier; will process 4842 files now Step #5: ==176692== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560d1c1099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560d2276e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560d227515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560d227514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560d1c10fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560d1c070b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560d1c06b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560d1c101c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560d1f0d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560d1f0d0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560d1f0d0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560d1f0d0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560d1f0d0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560d1f0d0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560d1f0d0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560d1f0d0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560d1f0d0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560d1f0d0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560d21365f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560d1e092b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560d1e09dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560d1de49c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560d1de49c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560d1de4a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560d1de49874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560d1de49874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560d1de49874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560d22753abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560d2275c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560d22744699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560d2276f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc432b27082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560d1c069b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x21,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x21,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0x3d,0xa,0x3d,0xa,0x3d,0x3b,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10,0xa, Step #5: \005-----BEGI=\012=\012=\012=\012=!\012=\012=\012=\012=\012=\012=\012=N -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=!\012=\012=\012=\012=\012=\012=\012=?=\012=\012=;=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\020\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-3deaeec32451565c42018246ede12f1060108608 Step #5: Base64: BS0tLS0tQkVHST0KPQo9Cj0KPSEKPQo9Cj0KPQo9Cj0KPU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9IQo9Cj0KPQo9Cj0KPQo9Pz0KPQo9Oz0KPQo9Cj0KPQo9Cj0KPQo9Cj0KCj0KPQo9Cj0KPQo9Cj0KPQo9Cj09Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9ChAK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4907 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4203280875 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557a24598810, 0x557a2478201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557a24782020,0x557a2661a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3deaeec32451565c42018246ede12f1060108608' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6188 processed earlier; will process 4841 files now Step #5: ==176728== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557a1b08d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557a216f2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557a216d55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557a216d54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557a1b093d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557a1aff4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557a1afef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557a1b085c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557a1e054f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557a1e054f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557a1e054f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557a1e054f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557a1e054f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557a1e054f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557a1e054f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557a1e054f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557a1e054f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557a1e054f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557a202e9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557a1d016b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557a1d021be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557a1cdcdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557a1cdcdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557a1cdce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557a1cdcd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557a1cdcd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557a1cdcd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557a216d7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557a216e0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557a216c8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557a216f3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbee2e8e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557a1afedb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0xef,0xac,0xac,0xef,0xbe,0xa0,0xef,0xac,0xac,0xef,0xbd,0xa0,0xef,0xac,0xac,0xef,0xbe,0xa0,0xef,0xac,0x96,0xef,0xbe,0xb0,0xef,0xac,0x96,0xef,0xbe,0xa0,0xef,0xbe,0xa0,0xef,0xac,0x96,0xef,0xbe,0xa0,0xef,0xac,0xac,0xef,0xbe,0xa0,0xef,0xac,0x96,0xef,0xbe,0xa0,0xef,0xbe,0xa0,0xef,0xac,0xb6,0xef,0x9e,0xa0,0xef,0xac,0xac,0xef,0xbe,0xa0,0xef,0xac,0x96,0xef,0xbe,0xb0,0xef,0xac,0x96,0xef,0xbe,0xa0,0xef,0xbe,0xa0,0xef,0xa8,0x92,0xef,0xbe,0xb0,0xef,0xac,0x96,0xef,0xbe,0xa0,0xef,0xbe,0xa0,0xef,0xac,0x96,0xef,0xbe,0xb0,0xef,0xac,0x96,0xef,0xbe,0xa0,0xef,0xbe,0xa0,0xef,0xa8,0x92,0xef,0xbe,0xb0,0xef,0xac,0x96,0xef,0xbe,0xa0,0xef,0xbe,0xa0,0xef,0xac,0x96,0xef,0xbe,0xa0,0xef,0xac,0xac,0xef,0xbe,0xa0,0xef,0xac,0x96,0xef,0xbe,0xa0,0xef,0xbe,0xa0,0xef,0xac,0xb6,0xef,0x9e,0xa0,0xef,0xac,0xac,0xef,0xbe,0xa0,0xef,0xac,0x96,0xef,0xbe,0xb0,0xef,0xac,0x96,0xef,0xbe,0xa0,0xef,0xbe,0xa0,0xef,0xa8,0x92,0xef,0xa8,0x92,0xef,0xbe,0xb0,0xef,0xac,0x96,0xef,0xbe,0xa0,0x3a,0xef,0xbe,0xa0,0x0,0x0,0x0,0x9e,0x27,0xef,0xbe, Step #5: \000\000\000\000\357\254\254\357\276\240\357\254\254\357\275\240\357\254\254\357\276\240\357\254\226\357\276\260\357\254\226\357\276\240\357\276\240\357\254\226\357\276\240\357\254\254\357\276\240\357\254\226\357\276\240\357\276\240\357\254\266\357\236\240\357\254\254\357\276\240\357\254\226\357\276\260\357\254\226\357\276\240\357\276\240\357\250\222\357\276\260\357\254\226\357\276\240\357\276\240\357\254\226\357\276\260\357\254\226\357\276\240\357\276\240\357\250\222\357\276\260\357\254\226\357\276\240\357\276\240\357\254\226\357\276\240\357\254\254\357\276\240\357\254\226\357\276\240\357\276\240\357\254\266\357\236\240\357\254\254\357\276\240\357\254\226\357\276\260\357\254\226\357\276\240\357\276\240\357\250\222\357\250\222\357\276\260\357\254\226\357\276\240:\357\276\240\000\000\000\236'\357\276 Step #5: artifact_prefix='./'; Test unit written to ./oom-22ed2b01abc282639fba822df378b6b16de184ba Step #5: Base64: AAAAAO+srO++oO+srO+9oO+srO++oO+slu++sO+slu++oO++oO+slu++oO+srO++oO+slu++oO++oO+stu+eoO+srO++oO+slu++sO+slu++oO++oO+oku++sO+slu++oO++oO+slu++sO+slu++oO++oO+oku++sO+slu++oO++oO+slu++oO+srO++oO+slu++oO++oO+stu+eoO+srO++oO+slu++sO+slu++oO++oO+oku+oku++sO+slu++oDrvvqAAAACeJ+++ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4908 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4203812310 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564edc181810, 0x564edc36b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564edc36b020,0x564ede2030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/22ed2b01abc282639fba822df378b6b16de184ba' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6189 processed earlier; will process 4840 files now Step #5: ==176764== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564ed2c769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564ed92db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564ed92be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564ed92be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ed2c7cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ed2bddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ed2bd8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ed2c6ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564ed5c3df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564ed5c3df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564ed5c3df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564ed5c3df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564ed5c3df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564ed5c3df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564ed5c3df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564ed5c3df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564ed5c3df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564ed5c3df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564ed7ed2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564ed4bffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564ed4c0abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564ed49b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564ed49b6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564ed49b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564ed49b6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564ed49b6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564ed49b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564ed92c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564ed92c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564ed92b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564ed92dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f46007fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ed2bd6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x0,0x0,0x0,0x11,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0x0,0x1,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x24,0x5b,0x2d,0xf,0xf,0xf,0x31,0x11,0x60,0xf,0x31,0x11,0x2d,0x3a,0x24,0x2a,0x24,0x5b,0x2d,0x3a,0x24,0x60, Step #5: $4444444444444444444444444444444444444444444\000\000\000\0214444444444444444444444444444444444444444444444444444444\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177444444444444444444444444444\000\000/\000\000\000/\000\017\017\017\017\000\001\0171\021\0171\021-:$[-\017\017\0171\021`\0171\021-:$*$[-:$` Step #5: artifact_prefix='./'; Test unit written to ./oom-330dc1f584f42c7f0749fbd99cec33c224911732 Step #5: Base64: JDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQAAAARNDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NH9/f39/f39/f39/f39/f39/f39/f39/f39/f39/fzQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NAAALwAAAC8ADw8PDwABDzERDzERLTokWy0PDw8xEWAPMREtOiQqJFstOiRg Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4909 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4204466769 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55590ed32810, 0x55590ef1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55590ef1c020,0x555910db40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/330dc1f584f42c7f0749fbd99cec33c224911732' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6190 processed earlier; will process 4839 files now Step #5: ==176800== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5559058279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55590be8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55590be6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55590be6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55590582dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55590578eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555905789355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55590581fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5559087eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5559087eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5559087eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5559087eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5559087eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5559087eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5559087eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5559087eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5559087eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5559087eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55590aa83f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5559077b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5559077bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555907567c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555907567c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555907568738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555907567874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555907567874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555907567874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55590be71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55590be7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55590be62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55590be8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc3d5475082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555905787b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x2d,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x3d,0x3c,0x2d,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x24,0x27,0x2d,0x24,0x2d,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x3d,0x3c,0x2d,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x3d,0x3c,0x2d,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x24,0x27,0x2d,0x24,0x2d,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x3d,0x3c,0x2d,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x24,0x27,0x2d, Step #5: $-9223372036854775551-=<-1''/''''/'''exp'N'2-\007='''''$'-$-9223372036854775551-=<-1''/''''/'6854775551-=<-1''/''''/'''exp'N'2-\007='''''$'-$-9223372036854775551-=<-1''/''''/'''exp'N'2-\007='''''exp'N'2-\007='''''$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-f6946b3aee09917c56af006ee194bdc9deb03e30 Step #5: Base64: JC05MjIzMzcyMDM2ODU0Nzc1NTUxLT08LTEnJy8nJycnLycnJ2V4cCdOJzItBz0nJycnJyQnLSQtOTIyMzM3MjAzNjg1NDc3NTU1MS09PC0xJycvJycnJy8nNjg1NDc3NTU1MS09PC0xJycvJycnJy8nJydleHAnTicyLQc9JycnJyckJy0kLTkyMjMzNzIwMzY4NTQ3NzU1NTEtPTwtMScnLycnJycvJycnZXhwJ04nMi0HPScnJycnZXhwJ04nMi0HPScnJycnJCct Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4910 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4205008841 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f58851f810, 0x55f58870901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f588709020,0x55f58a5a10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f6946b3aee09917c56af006ee194bdc9deb03e30' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6191 processed earlier; will process 4838 files now Step #5: ==176836== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f57f0149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f585679898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f58565c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f58565c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f57f01ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f57ef7bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f57ef76355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f57f00cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f581fdbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f581fdbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f581fdbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f581fdbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f581fdbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f581fdbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f581fdbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f581fdbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f581fdbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f581fdbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f584270f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f580f9db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f580fa8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f580d54c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f580d54c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f580d55738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f580d54874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f580d54874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f580d54874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f58565eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f585667928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f58564f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f58567a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa42022082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f57ef74b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x42,0x3a,0x40,0xa,0x3e,0x0,0xef,0x88,0x80,0x7f,0x46,0x2d,0xf3,0xa0,0x84,0x88,0x0,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x3b,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x3b,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0xd,0xa,0x42,0x3a,0x40,0xa,0x3e,0x0,0xef,0x88,0x80,0x7f,0x46,0x2d,0xf3,0xa0,0x84,0x88,0x0,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x3b,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x3b,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0xd,0xa,0x42,0x3a,0x40,0xa,0x3e,0x0,0xef,0x88,0x80,0x7f,0x46,0x2d,0xf3,0xa0,0x84,0x88,0x0,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x3b,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x3b,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0xd, Step #5: \012B:@\012>\000\357\210\200\177F-\363\240\204\210\000............;..............;.....................\015\012B:@\012>\000\357\210\200\177F-\363\240\204\210\000............;..............;.....................\015\012B:@\012>\000\357\210\200\177F-\363\240\204\210\000............;..............;.....................\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e7c03143ea76ed01c254eff063905c2f07bf3fb Step #5: Base64: CkI6QAo+AO+IgH9GLfOghIgALi4uLi4uLi4uLi4uOy4uLi4uLi4uLi4uLi4uOy4uLi4uLi4uLi4uLi4uLi4uLi4uLg0KQjpACj4A74iAf0Yt86CEiAAuLi4uLi4uLi4uLi47Li4uLi4uLi4uLi4uLi47Li4uLi4uLi4uLi4uLi4uLi4uLi4uDQpCOkAKPgDviIB/Ri3zoISIAC4uLi4uLi4uLi4uLjsuLi4uLi4uLi4uLi4uLjsuLi4uLi4uLi4uLi4uLi4uLi4uLi4N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4911 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4205527843 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b525d6f810, 0x55b525f5901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b525f59020,0x55b527df10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e7c03143ea76ed01c254eff063905c2f07bf3fb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6192 processed earlier; will process 4837 files now Step #5: ==176872== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b51c8649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b522ec9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b522eac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b522eac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b51c86ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b51c7cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b51c7c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b51c85cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b51f82bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b51f82bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b51f82bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b51f82bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b51f82bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b51f82bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b51f82bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b51f82bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b51f82bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b51f82bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b521ac0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b51e7edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b51e7f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b51e5a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b51e5a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b51e5a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b51e5a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b51e5a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b51e5a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b522eaeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b522eb7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b522e9f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b522eca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f329f64a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b51c7c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0x61,0x65,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x3a,0x0,0x2a,0x2a,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x75,0x75,0x75,0x75,0x75,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0xa,0x2d,0x2d,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x68,0x68,0x3f,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x75,0x75,0x75,0x75,0x65, Step #5: nae**************************************\000\000\000:\000**hhhhhhhhh\004\000\000\000\000\000\000\000hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhuuuuu---END \012--*******\000\000\000\000\000\000\000\000*************hhhhhhhhhttps://hh?hhhhhhhhhhhhhhhhhhhhhuuuue Step #5: artifact_prefix='./'; Test unit written to ./oom-68fdeecafa7fd2c8cda7920677ec21f183c33cb0 Step #5: Base64: bmFlKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioAAAA6ACoqaGhoaGhoaGhoBAAAAAAAAABoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGh1dXV1dS0tLUVORCAKLS0qKioqKioqAAAAAAAAAAAqKioqKioqKioqKioqaGhoaGhoaGhodHRwczovL2hoP2hoaGhoaGhoaGhoaGhoaGhoaGhoaHV1dXVl Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4912 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4206056053 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557c515f6810, 0x557c517e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557c517e0020,0x557c536780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/68fdeecafa7fd2c8cda7920677ec21f183c33cb0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6193 processed earlier; will process 4836 files now Step #5: #1 pulse cov: 3788 ft: 3789 exec/s: 0 rss: 175Mb Step #5: ==176908== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557c480eb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557c4e750898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557c4e7335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557c4e7334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557c480f1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557c48052b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557c4804d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557c480e3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557c4b0b2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557c4b0b2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557c4b0b2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557c4b0b2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557c4b0b2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557c4b0b2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557c4b0b2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557c4b0b2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557c4b0b2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557c4b0b2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557c4d347f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557c4a074b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557c4a07fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557c49e2bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557c49e2bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557c49e2c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557c49e2b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557c49e2b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557c49e2b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557c4e735abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557c4e73e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557c4e726699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557c4e751112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd344136082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557c4804bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x30,0x4d,0x46,0x77,0x48,0x65,0x57,0x53,0x63,0x6f,0x41,0x61,0x71,0x59,0x6d,0x2b,0x6a,0x35,0x47,0x4c,0x6c,0x43,0x41,0x41,0x42,0x73,0x54,0x2b,0x4c,0x51,0x58,0x49,0x53,0x7a,0x56,0x77,0x6a,0x77,0x6f,0x30,0x56,0x45,0xa,0x66,0x61,0x6d,0x69,0x6c,0x79,0x20,0x22,0x20,0x1f,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x2b,0x20,0x2b,0x20,0x20,0x2b,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x1f,0x20,0x27,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x1f,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x22,0x20,0x1f,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x25,0x20,0x1f,0x20,0x27,0x20,0x2b,0x20,0x1f,0x20,0x27,0x20,0x25,0x20,0x1f,0x20,0x27,0x20,0x1f,0x20,0x1f,0x20,0x27,0x20,0x1f,0x20,0x2b,0x20,0x1f,0x20,0x27, Step #5: onion-key\012ntor-onion-key v0MFwHeWScoAaqYm+j5GLlCAABsT+LQXISzVwjwo0VE\012family \" \037 + \037 ' + \037 ' + + + + + \037 ' \037 ' \037 ' + \037 ' + \037 ' + \037 ' \037 + \037 ' + \037 ' + \037 ' + \037 ' + \037 \" \037 + \037 ' % \037 ' + \037 ' % \037 ' \037 \037 ' \037 + \037 ' Step #5: artifact_prefix='./'; Test unit written to ./oom-9a731365be66d52a2f3fc2661ec7b3913787f5dc Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHYwTUZ3SGVXU2NvQWFxWW0rajVHTGxDQUFCc1QrTFFYSVN6Vndqd28wVkUKZmFtaWx5ICIgHyArIB8gJyArIB8gJyArICsgKyAgKyArIB8gJyAfICcgHyAnICsgHyAnICsgHyAnICsgHyAnIB8gKyAfICcgKyAfICcgKyAfICcgKyAfICcgKyAfICIgHyArIB8gJyAlIB8gJyArIB8gJyAlIB8gJyAfIB8gJyAfICsgHyAn Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4913 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4206645721 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f6beaa6810, 0x55f6bec9001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f6bec90020,0x55f6c0b280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9a731365be66d52a2f3fc2661ec7b3913787f5dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6195 processed earlier; will process 4834 files now Step #5: #1 pulse cov: 3838 ft: 3839 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4310 ft: 4764 exec/s: 0 rss: 179Mb Step #5: ==176944== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f6b559b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f6bbc00898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f6bbbe35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f6bbbe34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f6b55a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f6b5502b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f6b54fd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f6b5593c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f6b8562f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f6b8562f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f6b8562f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f6b8562f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f6b8562f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f6b8562f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f6b8562f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f6b8562f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f6b8562f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f6b8562f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f6ba7f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f6b7524b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f6b752fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f6b72dbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f6b72dbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f6b72dc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f6b72db874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f6b72db874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f6b72db874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f6bbbe5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f6bbbee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f6bbbd6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f6bbc01112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbd26184082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f6b54fbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x7b,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0x20,0x20,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0xc,0x6e,0x61,0x6d,0x65,0x3a,0xd,0x22,0x44,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x27,0x38,0x66,0x27,0x20,0x20,0x20,0x20,0x5c,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7d,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x32,0x34,0x7e,0x7e,0x7e,0x7e,0x42,0x7e,0x7e,0x7e,0x7e,0x7d,0x7e,0xc7,0x72,0x7e,0x76,0x7e,0x7e,0x7e,0x7e,0x7e,0x1b,0x2d,0x32,0x32,0x39,0x30,0x7e,0x76,0x3b,0x78,0x4b,0xae,0xae,0xae,0xad,0x9,0x4b,0x4b,0x78,0x78,0x78,0x78,0x78,0x68,0xd7,0xdd,0x31,0x47,0x6d,0x65,0x3a,0x20,0x20,0x20,0x20,0x20,0x40,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x33,0x30,0x20,0x20,0x5c,0x27,0x20,0x20,0x20,0x3e,0x20,0x5c,0x30,0x30,0x30,0x5c,0x72,0x20,0x20,0x3c,0x46,0x20,0x3e,0x22,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x76,0x61,0x6c,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x22,0x20,0x20,0x20,0x7d,0x20,0x7d,0xa,0xa,0x7d,0x20,0x7d,0xa,0x7d,0x7d, Step #5: p{doctype {\012mdecl { entity {\014name:\015\"D PUBLIC '8f' \\'http://~~~~~~}~~~~~~~24~~~~B~~~~}~\307r~v~~~~~\033-2290~v;xK\256\256\256\255\011KKxxxxxh\327\3351Gme: @ 30 \\' > \\000\\r <F >\"ent {\012 val { name: \"D\" } }\012\012} }\012}} Step #5: artifact_prefix='./'; Test unit written to ./oom-8fcb66e50702982534b6585c7f7e44f370d8853d Step #5: Base64: cHtkb2N0eXBlIHsKbWRlY2wgeyAgZW50aXR5IHsMbmFtZToNIkQgUFVCTElDICc4ZicgICAgXCdodHRwOi8vfn5+fn5+fX5+fn5+fn4yNH5+fn5Cfn5+fn1+x3J+dn5+fn5+Gy0yMjkwfnY7eEuurq6tCUtLeHh4eHho190xR21lOiAgICAgQCAgICAgICAgMzAgIFwnICAgPiBcMDAwXHIgIDxGID4iZW50IHsKICB2YWwgeyBuYW1lOiAiRCIgICB9IH0KCn0gfQp9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4914 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4207250023 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564a4f757810, 0x564a4f94101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564a4f941020,0x564a517d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8fcb66e50702982534b6585c7f7e44f370d8853d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6198 processed earlier; will process 4831 files now Step #5: ==176980== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564a4624c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564a4c8b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564a4c8945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564a4c8944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564a46252d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564a461b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564a461ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564a46244c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564a49213f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564a49213f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564a49213f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564a49213f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564a49213f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564a49213f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564a49213f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564a49213f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564a49213f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564a49213f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564a4b4a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564a481d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564a481e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564a47f8cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564a47f8cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564a47f8d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564a47f8c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564a47f8c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564a47f8c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564a4c896abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564a4c89f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564a4c887699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564a4c8b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9c7306a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564a461acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x72,0x6c,0x62,0x79,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x6e,0x61,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x24,0x33,0x3a,0x3a,0x7b,0x7d,0x3a, Step #5: rlby{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}na::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}$3::{}: Step #5: artifact_prefix='./'; Test unit written to ./oom-ee5cad89afcdf17e84800d696cb72858f8e22b47 Step #5: Base64: cmxieXt9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9bmE6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9JDM6Ont9Og== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4915 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4207784738 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56032850a810, 0x5603286f401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5603286f4020,0x56032a58c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee5cad89afcdf17e84800d696cb72858f8e22b47' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6199 processed earlier; will process 4830 files now Step #5: ==177016== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56031efff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560325664898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5603256475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5603256474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56031f005d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56031ef66b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56031ef61355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56031eff7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560321fc6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560321fc6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560321fc6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560321fc6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560321fc6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560321fc6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560321fc6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560321fc6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560321fc6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560321fc6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56032425bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560320f88b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560320f93be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560320d3fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560320d3fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560320d40738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560320d3f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560320d3f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560320d3f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560325649abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560325652928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56032563a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560325665112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f56c9565082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56031ef5fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe,0x77,0x73,0x3a,0x65,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xdd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x65,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xdd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0x65,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xdd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: \016ws:e\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\335\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204e\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\335\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204e\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\335\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-68d9dc6cecee5e2ef9fd7d90afef75f5141f60d6 Step #5: Base64: DndzOmXNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2E3YTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYRlzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTdhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EZc2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2E3YTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4916 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4208326622 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559923b44810, 0x559923d2e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559923d2e020,0x559925bc60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/68d9dc6cecee5e2ef9fd7d90afef75f5141f60d6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6200 processed earlier; will process 4829 files now Step #5: #1 pulse cov: 4204 ft: 4205 exec/s: 0 rss: 177Mb Step #5: ==177052== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55991a6399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559920c9e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559920c815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559920c814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55991a63fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55991a5a0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55991a59b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55991a631c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55991d600f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55991d600f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55991d600f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55991d600f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55991d600f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55991d600f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55991d600f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55991d600f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55991d600f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55991d600f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55991f895f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55991c5c2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55991c5cdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55991c379c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55991c379c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55991c37a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55991c379874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55991c379874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55991c379874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559920c83abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559920c8c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559920c74699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559920c9f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b8a585082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55991a599b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x33,0xd,0x66,0x45,0x42,0x9,0x34,0x34,0xa,0x31,0x31,0x3a,0x32,0x35,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0x80,0xe3,0x80,0xa9, Step #5: 3\015fEB\01144\01211:25\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\200\343\200\251 Step #5: artifact_prefix='./'; Test unit written to ./oom-4daf4b2d196ffb9bb60b75ef452453497c58aa66 Step #5: Base64: Mw1mRUIJNDQKMTE6MjXjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgIDjgKk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4917 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4208897806 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555c7ef90810, 0x555c7f17a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555c7f17a020,0x555c810120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4daf4b2d196ffb9bb60b75ef452453497c58aa66' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6202 processed earlier; will process 4827 files now Step #5: ==177088== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555c75a859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555c7c0ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555c7c0cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555c7c0cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555c75a8bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555c759ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555c759e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555c75a7dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555c78a4cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555c78a4cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555c78a4cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555c78a4cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555c78a4cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555c78a4cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555c78a4cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555c78a4cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555c78a4cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555c78a4cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555c7ace1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555c77a0eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555c77a19be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555c777c5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555c777c5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555c777c6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555c777c5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555c777c5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555c777c5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555c7c0cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555c7c0d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555c7c0c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555c7c0eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f39db45c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555c759e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x55,0x6b,0x18,0x0,0x0,0x0,0x2f,0x49,0x46,0x33,0x4,0x0,0x30,0x8,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x48,0x48,0x48,0x48,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0x3d,0xa,0xa,0xa,0x3d,0xa,0xa,0x6d,0x6d,0x6d,0x7d,0x6d,0x6d,0x6d,0x2d,0x2d,0x3e,0x2d,0x42,0x20,0x4e,0x49,0x45,0x47,0x2d,0x2d,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x48,0x48,0x48,0x48,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0x3d,0xa,0xa,0xa,0x3d,0xa,0xa,0x6d,0x6d,0x6d,0x7d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x71,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x3d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x6d,0x1,0x68,0x7a,0x99, Step #5: eUk\030\000\000\000/IF3\004\0000\010\012=\012=\012=\012=\012=\012=\012=\012HHHH\012=\012=\012\012=\012=\012=\012=\012=\012=\012==\012==\012\012\012=\012\012mmm}mmm-->-B NIEG---\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012HHHH\012=\012=\012\012=\012=\012=\012=\012=\012=\012==\012==\012\012\012=\012\012mmm}mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmqmmmmmm=mmmmmmmmmmm\001hz\231 Step #5: artifact_prefix='./'; Test unit written to ./oom-a72a43f34dc57995daf436714c0215e4ae55025e Step #5: Base64: ZVVrGAAAAC9JRjMEADAICj0KPQo9Cj0KPQo9Cj0KSEhISAo9Cj0KCj0KPQo9Cj0KPQo9Cj09Cj09CgoKPQoKbW1tfW1tbS0tPi1CIE5JRUctLS0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQpISEhICj0KPQoKPQo9Cj0KPQo9Cj0KPT0KPT0KCgo9CgptbW19bW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tbW1tcW1tbW1tbT1tbW1tbW1tbW1tbQFoepk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4918 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4209436648 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55711121b810, 0x55711140501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557111405020,0x55711329d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a72a43f34dc57995daf436714c0215e4ae55025e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6203 processed earlier; will process 4826 files now Step #5: ==177124== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557107d109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55710e375898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55710e3585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55710e3584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557107d16d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557107c77b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557107c72355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557107d08c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55710acd7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55710acd7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55710acd7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55710acd7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55710acd7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55710acd7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55710acd7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55710acd7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55710acd7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55710acd7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55710cf6cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557109c99b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557109ca4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557109a50c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557109a50c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557109a51738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557109a50874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557109a50874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557109a50874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55710e35aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55710e363928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55710e34b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55710e376112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f74468a3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557107c70b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x22,0x5c,0x75,0x7b,0x66,0x46,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x46,0x7d,0x5c,0x75,0x7b,0x62,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x46,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x46,0x7d,0x75,0x66,0x7b,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x46,0x7d,0x5c,0x75,0x7b,0x62,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x46,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x46,0x7d,0x5c,0x75,0x7b,0x62,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x66,0x7d,0x5c,0x75,0x7b,0x66,0x46,0x7d,0x5c,0x7b,0x62,0x66,0x8a, Step #5: \012\"\\u{fF}\\u{ff}\\u{ff}\\u{fff}\\u{ff}\\u{ff}\\u{ff}\\u{fF}\\u{bf}\\u{fF}\\u{ff}\\u{fF}uf{}\\u{ff}\\u{fff}\\u{ff}\\u{ff}\\u{ff}\\u{fF}\\u{bf}\\u{fF}\\u{ff}\\u{ff}\\u{fff}\\u{ff}\\u{ff}\\u{ff}\\u{fF}\\u{bf}\\u{ff}\\u{ff}\\u{ff}\\u{fF}\\{bf\212 Step #5: artifact_prefix='./'; Test unit written to ./oom-7eb948e0bfbe0d6c3cacb71274b7d7ed8f3dd31b Step #5: Base64: CiJcdXtmRn1cdXtmZn1cdXtmZn1cdXtmZmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZkZ9XHV7YmZ9XHV7ZkZ9XHV7ZmZ9XHV7ZkZ9dWZ7fVx1e2ZmfVx1e2ZmZn1cdXtmZn1cdXtmZn1cdXtmZn1cdXtmRn1cdXtiZn1cdXtmRn1cdXtmZn1cdXtmZn1cdXtmZmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZkZ9XHV7YmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZmZ9XHV7ZkZ9XHtiZoo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4919 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4209960522 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558dc5d5c810, 0x558dc5f4601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558dc5f46020,0x558dc7dde0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7eb948e0bfbe0d6c3cacb71274b7d7ed8f3dd31b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6204 processed earlier; will process 4825 files now Step #5: ==177160== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558dbc8519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558dc2eb6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558dc2e995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558dc2e994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558dbc857d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558dbc7b8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558dbc7b3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558dbc849c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558dbf818f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558dbf818f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558dbf818f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558dbf818f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558dbf818f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558dbf818f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558dbf818f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558dbf818f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558dbf818f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558dbf818f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558dc1aadf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558dbe7dab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558dbe7e5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558dbe591c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558dbe591c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558dbe592738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558dbe591874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558dbe591874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558dbe591874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558dc2e9babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558dc2ea4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558dc2e8c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558dc2eb7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f32f1b47082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558dbc7b1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x67,0x31,0x3,0x21,0x44,0x3a,0x50,0x49,0x43,0x0,0x0,0x5,0x31,0x3,0x21,0x44,0x3a,0x50,0x49,0x43,0x49,0x43,0x0,0x0,0x5,0x45,0x3,0x21,0x44,0x3a,0x50,0x49,0x43,0x0,0x0,0x5,0x34,0x3,0x21,0x44,0x3a,0x50,0x49,0x43,0x0,0x0,0x5,0x45,0x2,0x21,0x44,0x3a,0x50,0x49,0x43,0x0,0x0,0x5,0x33,0x3,0x21,0x44,0x3a,0x50,0x49,0x21,0x44,0x3a,0x50,0x49,0xe0,0xb9,0x83,0xc2,0xb7,0x49,0x44,0x33,0x3,0x0,0x20,0xf3,0xa0,0x80,0xad,0x1,0x0,0x0,0x43,0x0,0x0,0x5,0x30,0x3,0x21,0x44,0x3a,0x50,0x49,0x43,0x0,0x0,0x5,0x30,0x3,0x21,0x44,0x3a,0x50,0x49,0x43,0x0,0x0,0x5,0x45,0x3,0x21,0x44,0x3a,0x50,0x49,0x43,0x0,0x0,0x5,0x33,0x3,0x21,0x44,0x3a,0x50,0x49,0x43,0x0,0x0,0x5,0x45,0x2,0x21,0x44,0x3a,0x50,0x49,0x43,0x22,0xe2,0x80,0xae,0x54,0x49,0x71,0x4,0x0,0xf3,0x5,0x34,0x30,0x30,0x36,0x36,0x33,0x36,0x37,0x39,0x30,0x32,0x33,0x3,0x24,0x44,0x3a,0x50,0x49,0x43,0x0,0x0,0x5,0x45,0x2,0x21,0x44,0x3a,0x50,0x49,0x43,0x0,0x0,0x5,0x32,0x35,0x35,0x3,0x21,0x44,0x3a,0x50,0x2d,0xff,0x49,0x43,0x0,0x0,0x5, Step #5: ID3\002g1\003!D:PIC\000\000\0051\003!D:PICIC\000\000\005E\003!D:PIC\000\000\0054\003!D:PIC\000\000\005E\002!D:PIC\000\000\0053\003!D:PI!D:PI\340\271\203\302\267ID3\003\000 \363\240\200\255\001\000\000C\000\000\0050\003!D:PIC\000\000\0050\003!D:PIC\000\000\005E\003!D:PIC\000\000\0053\003!D:PIC\000\000\005E\002!D:PIC\"\342\200\256TIq\004\000\363\005400663679023\003$D:PIC\000\000\005E\002!D:PIC\000\000\005255\003!D:P-\377IC\000\000\005 Step #5: artifact_prefix='./'; Test unit written to ./oom-d0300cb477f14af3b36729795935ef42ec814173 Step #5: Base64: SUQzAmcxAyFEOlBJQwAABTEDIUQ6UElDSUMAAAVFAyFEOlBJQwAABTQDIUQ6UElDAAAFRQIhRDpQSUMAAAUzAyFEOlBJIUQ6UEnguYPCt0lEMwMAIPOggK0BAABDAAAFMAMhRDpQSUMAAAUwAyFEOlBJQwAABUUDIUQ6UElDAAAFMwMhRDpQSUMAAAVFAiFEOlBJQyLigK5USXEEAPMFNDAwNjYzNjc5MDIzAyREOlBJQwAABUUCIUQ6UElDAAAFMjU1AyFEOlAt/0lDAAAF Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4920 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4210491879 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a09203c810, 0x55a09222601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a092226020,0x55a0940be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d0300cb477f14af3b36729795935ef42ec814173' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6205 processed earlier; will process 4824 files now Step #5: ==177196== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a088b319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a08f196898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a08f1795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a08f1794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a088b37d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a088a98b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a088a93355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a088b29c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a08baf8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a08baf8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a08baf8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a08baf8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a08baf8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a08baf8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a08baf8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a08baf8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a08baf8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a08baf8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a08dd8df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a08aabab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a08aac5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a08a871c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a08a871c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a08a872738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a08a871874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a08a871874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a08a871874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a08f17babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a08f184928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a08f16c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a08f197112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f976dbf8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a088a91b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x28,0x28,0x28,0x28,0x28,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x78,0x2d,0x2d,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x2d,0xa,0xa,0x2d,0x20,0x2d,0x2d,0x2d,0x11,0xf,0x31,0x11,0x2d,0x3a,0x24,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x31,0x8,0x11,0x2d,0x3a,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x2d,0x20,0x2d,0x20,0x20,0x2d,0x20,0x2d,0x3a,0x7c,0x20,0x2d,0x2d,0x3a,0x7c,0x20,0x2d,0x31,0x8,0x11,0x2d,0x3a,0x3a,0x20,0x3a,0x20,0x2d,0x20,0x2d,0x3a,0x7c,0x20,0x2d,0x2d,0x24,0x0,0x5b,0x11,0x2d,0x2d,0x3a,0x3a,0x24,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x0,0x24,0x5b,0x2d,0x3a,0x24,0x24,0x5b,0x5b,0x3a,0x7c,0x20,0x2d,0x3a,0x20, Step #5: \012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012(((((\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012x--\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012-\012\012- ---\021\0171\021-:$\017\017\0171\021\01711\010\021-:\000\000/\000\000\000/\000\017\017\017\017\0171\021\0171- - - -:| --:| -1\010\021-:: : - -:| --$\000[\021--::$-\017\017\017\017\0171\021\0171\021-:\000$[-:$$[[:| -: Step #5: artifact_prefix='./'; Test unit written to ./oom-ea642e762b9bf2c935e274d98f1bdff80a1bafc2 Step #5: Base64: CgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgooKCgoKAoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCngtLQoKCgoKCgoKCgoKCgoKCgotCgotIC0tLREPMREtOiQPDw8xEQ8xMQgRLToAAC8AAAAvAA8PDw8PMREPMS0gLSAgLSAtOnwgLS06fCAtMQgRLTo6IDogLSAtOnwgLS0kAFsRLS06OiQtDw8PDw8xEQ8xES06ACRbLTokJFtbOnwgLTog Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4921 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4211036772 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5632e6c44810, 0x5632e6e2e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5632e6e2e020,0x5632e8cc60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ea642e762b9bf2c935e274d98f1bdff80a1bafc2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6206 processed earlier; will process 4823 files now Step #5: #1 pulse cov: 11195 ft: 11196 exec/s: 0 rss: 194Mb Step #5: ==177232== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5632dd7399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5632e3d9e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5632e3d815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5632e3d814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5632dd73fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5632dd6a0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5632dd69b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5632dd731c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5632e0700f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5632e0700f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5632e0700f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5632e0700f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5632e0700f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5632e0700f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5632e0700f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5632e0700f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5632e0700f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5632e0700f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5632e2995f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5632df6c2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5632df6cdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5632df479c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5632df479c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5632df47a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5632df479874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5632df479874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5632df479874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5632e3d83abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5632e3d8c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5632e3d74699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5632e3d9f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f99a36d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5632dd699b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x7d,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0xf3,0xa0,0x81,0x8a,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0xcb,0x91,0x2e,0x7c,0x7c,0x2e,0x7c,0x2d,0x2d,0x36,0x7c,0x7c,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c,0x7c,0x2e,0x7c, Step #5: ^}.||.||.||.||.||.||.||.||.||.||.||.||.||\363\240\201\212.||.||.||.||.||.||.||.||.||.||.||.||.||.||.||.||.||.||.||.|.||.||.||.||.||.||.||.||\313\221.||.|--6||||.||.||.||.||.||.||.||.||.||.||.||.||.||.||.||.||.||.||.||.||.||.| Step #5: artifact_prefix='./'; Test unit written to ./oom-e9ecae73e62cbf49bde9fe5e754581f85af59615 Step #5: Base64: Xn0ufHwufHwufHwufHwufHwufHwufHwufHwufHwufHwufHwufHwufHzzoIGKLnx8Lnx8Lnx8Lnx8Lnx8Lnx8Lnx8Lnx8Lnx8Lnx8Lnx8Lnx8Lnx8Lnx8Lnx8Lnx8Lnx8Lnx8Lnx8LnwufHwufHwufHwufHwufHwufHwufHwufHzLkS58fC58LS02fHx8fC58fC58fC58fC58fC58fC58fC58fC58fC58fC58fC58fC58fC58fC58fC58fC58fC58fC58fC58fC58fC58fC58 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4922 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4211646670 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c4e9eaf810, 0x55c4ea09901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c4ea099020,0x55c4ebf310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e9ecae73e62cbf49bde9fe5e754581f85af59615' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6208 processed earlier; will process 4821 files now Step #5: ==177268== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c4e09a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c4e7009898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c4e6fec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c4e6fec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c4e09aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c4e090bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c4e0906355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c4e099cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c4e396bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c4e396bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c4e396bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c4e396bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c4e396bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c4e396bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c4e396bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c4e396bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c4e396bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c4e396bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c4e5c00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c4e292db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c4e2938be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c4e26e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c4e26e4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c4e26e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c4e26e4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c4e26e4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c4e26e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c4e6feeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c4e6ff7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c4e6fdf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c4e700a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa5031f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c4e0904b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x2d,0x3f,0x45,0x42,0x4c,0x43,0x2d,0x4d,0x27,0x6e,0x2d,0x2d,0x2b,0x2d,0x3f,0x45,0x42,0x4c,0x43,0x61,0x2d,0x2d,0x31,0x37,0x30,0x31,0x34,0x31,0x31,0x38,0x33,0x34,0x36,0x30,0x34,0x36,0x39,0x32,0x33,0x31,0x37,0x33,0x31,0x36,0x38,0x37,0x33,0x30,0x33,0x37,0x31,0x35,0x38,0x38,0x34,0x30,0x39,0x33,0x31,0x33,0x32,0x2b,0x2d,0x3f,0x45,0x42,0x4c,0x43,0x2d,0x4d,0x27,0x6e,0x2d,0x2d,0x2b,0x2d,0x3f,0x45,0x42,0x4c,0x43,0x61,0x2d,0x2d,0x33,0x34,0x38,0x37,0x38,0x31,0x37,0x30,0x39,0x39,0x31,0x39,0x36,0x35,0x39,0x39,0x39,0x38,0x32,0x2b,0x2d,0x3f,0x45,0x42,0x4c,0x43,0x2d,0x4d,0x27,0x6e,0x2d,0x2d,0x2b,0x2d,0x3f,0x45,0x42,0x4c,0x43,0x61,0x2d,0x2d,0x31,0x37,0x30,0x31,0x34,0x31,0x31,0x38,0x33,0x34,0x36,0x30,0x34,0x36,0x39,0x32,0x33,0x31,0x37,0x33,0x31,0x36,0x38,0x37,0x33,0x30,0x33,0x37,0x31,0x35,0x38,0x38,0x34,0x31,0x30,0x35,0x37,0x32,0x39,0x2b,0x2d,0x3f,0x45,0x42,0x4c,0x43,0x2d,0x4d,0x27,0x6e,0x2d,0x2d,0x2b,0x2d,0x3f,0x45,0x42,0x4c,0x43,0x61,0x2d,0x2d,0x33,0x34,0x38,0x37,0x38,0x31,0x37,0x30,0x39,0x39,0x31,0x39,0x36,0x35,0x39,0x39,0x39,0x38,0x32, Step #5: +-?EBLC-M'n--+-?EBLCa--170141183460469231731687303715884093132+-?EBLC-M'n--+-?EBLCa--3487817099196599982+-?EBLC-M'n--+-?EBLCa--170141183460469231731687303715884105729+-?EBLC-M'n--+-?EBLCa--3487817099196599982 Step #5: artifact_prefix='./'; Test unit written to ./oom-ef1eef65d11268e2cb677331c4c947dd1ded1808 Step #5: Base64: Ky0/RUJMQy1NJ24tLSstP0VCTENhLS0xNzAxNDExODM0NjA0NjkyMzE3MzE2ODczMDM3MTU4ODQwOTMxMzIrLT9FQkxDLU0nbi0tKy0/RUJMQ2EtLTM0ODc4MTcwOTkxOTY1OTk5ODIrLT9FQkxDLU0nbi0tKy0/RUJMQ2EtLTE3MDE0MTE4MzQ2MDQ2OTIzMTczMTY4NzMwMzcxNTg4NDEwNTcyOSstP0VCTEMtTSduLS0rLT9FQkxDYS0tMzQ4NzgxNzA5OTE5NjU5OTk4Mg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4923 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4212178081 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555bcf2fa810, 0x555bcf4e401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555bcf4e4020,0x555bd137c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ef1eef65d11268e2cb677331c4c947dd1ded1808' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6209 processed earlier; will process 4820 files now Step #5: #1 pulse cov: 4194 ft: 4195 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4916 ft: 5281 exec/s: 0 rss: 177Mb Step #5: ==177304== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555bc5def9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555bcc454898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555bcc4375dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555bcc4374fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555bc5df5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555bc5d56b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555bc5d51355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555bc5de7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555bc8db6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555bc8db6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555bc8db6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555bc8db6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555bc8db6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555bc8db6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555bc8db6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555bc8db6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555bc8db6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555bc8db6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555bcb04bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555bc7d78b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555bc7d83be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555bc7b2fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555bc7b2fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555bc7b30738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555bc7b2f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555bc7b2f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555bc7b2f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555bcc439abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555bcc442928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555bcc42a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555bcc455112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f369dd22082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555bc5d4fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0xe1,0x85,0x9f,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3b,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0xf3,0xa0,0x80,0xa1,0x3e,0x3c,0x3e,0x3c,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0xe1,0x85,0x9f,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3b,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0x3e,0x3c,0xf3,0xa0,0x80,0xa1,0x3e,0x3c,0x3e,0x3c, Step #5: <><><><><><><><><><><><><><><><><><><><><><><><><><>\341\205\237<><><><><>;><><><><><><><><><><><><><><><\363\240\200\241><><<><><><><><><><><><><><><><><><><><><><><><><><><><>\341\205\237<><><><><>;><><><><><><><><><><><><><><><\363\240\200\241><>< Step #5: artifact_prefix='./'; Test unit written to ./oom-bf8bb41aa6975636a7a2d7444a7f5b9ae8eae2d7 Step #5: Base64: PD48Pjw+PD48Pjw+PD48Pjw+PD48Pjw+PD48Pjw+PD48Pjw+PD48Pjw+PD48Pjw+PD48PuGFnzw+PD48Pjw+PD47Pjw+PD48Pjw+PD48Pjw+PD48Pjw+PD48Pjw+PD4886CAoT48Pjw8Pjw+PD48Pjw+PD48Pjw+PD48Pjw+PD48Pjw+PD48Pjw+PD48Pjw+PD48Pjw+PD48Pjw+4YWfPD48Pjw+PD48Pjs+PD48Pjw+PD48Pjw+PD48Pjw+PD48Pjw+PD48PjzzoIChPjw+PA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4924 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4212804677 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5645d26ed810, 0x5645d28d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5645d28d7020,0x5645d476f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf8bb41aa6975636a7a2d7444a7f5b9ae8eae2d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6212 processed earlier; will process 4817 files now Step #5: ==177340== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5645c91e29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5645cf847898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5645cf82a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5645cf82a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5645c91e8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5645c9149b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5645c9144355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5645c91dac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5645cc1a9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5645cc1a9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5645cc1a9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5645cc1a9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5645cc1a9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5645cc1a9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5645cc1a9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5645cc1a9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5645cc1a9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5645cc1a9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5645ce43ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5645cb16bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5645cb176be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5645caf22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5645caf22c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5645caf23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5645caf22874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5645caf22874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5645caf22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5645cf82cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5645cf835928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5645cf81d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5645cf848112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f26978ed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5645c9142b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0x20,0x75,0x62,0x69,0x74,0x74,0xdb,0xac,0x35,0x20,0x74,0x61,0x67,0xd7,0xac,0x74,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x69,0x76,0x74,0xdb,0xac,0x35,0x20,0x74,0x61,0x67,0xd7,0xac,0x74,0x61,0x74,0x61,0x67,0x3a,0xd7,0xac,0x74,0x61,0x74,0x61,0x67,0x3a,0x79,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0x5c,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x79,0x5c,0x3a,0x5c,0x5c,0x5c,0x5c,0x5c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xff,0xff,0xff,0x61,0x67,0xd7,0xac,0x5c,0x5c,0x5c,0xff,0xff,0xff,0xff,0xff,0x65,0x69,0x5c,0x5c,0x38,0x39,0x39,0x33,0x34,0x35,0x39,0x1f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6f,0x64,0x7e,0xd0, Step #5: ? ubitt\333\2545 tag\327\254t\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\\\\\\\\\\\\\\\\ivt\333\2545 tag\327\254tatag:\327\254tatag:y\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\377\377\377\377\377\377\377\377\377\377\377\377\377\377\\\\\\\\\\\\\\\\\377\377\377\377\377\377\377\377\377\377\377\377\377y\\:\\\\\\\\\\\000\000\000\000\000\000\000\000\000\377\377\377ag\327\254\\\\\\\377\377\377\377\377ei\\\\8993459\037\000\000\000\000\000\000\000od~\320 Step #5: artifact_prefix='./'; Test unit written to ./oom-d8167cd4da14fa03f026970f7c85cf06abcfba1f Step #5: Base64: PyB1Yml0dNusNSB0YWfXrHQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABcXFxcXFxcXGl2dNusNSB0YWfXrHRhdGFnOtesdGF0YWc6eVxcXFxcXFxcXFxcXFxcXFxcXFxcXFxcXFxcXFxcXFxcXFxcXFxcXFz//////////////////1xcXFxcXFxc/////////////////3lcOlxcXFxcAAAAAAAAAAAA////YWfXrFxcXP//////ZWlcXDg5OTM0NTkfAAAAAAAAAG9kftA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4925 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4213342608 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558659c0a810, 0x558659df401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558659df4020,0x55865bc8c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d8167cd4da14fa03f026970f7c85cf06abcfba1f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6213 processed earlier; will process 4816 files now Step #5: ==177376== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5586506ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558656d64898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558656d475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558656d474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558650705d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558650666b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558650661355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5586506f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5586536c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5586536c6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5586536c6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5586536c6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5586536c6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5586536c6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5586536c6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5586536c6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5586536c6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5586536c6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55865595bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558652688b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558652693be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55865243fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55865243fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558652440738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55865243f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55865243f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55865243f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558656d49abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558656d52928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558656d3a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558656d65112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7ffcfbd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55865065fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x65,0x33,0x33,0x2e,0x65,0x31,0x3d,0x71,0x49,0x6d,0x46,0x31,0x5a,0x43,0x49,0x36,0x57,0x7a,0x49,0x79,0x4d,0x7a,0x55,0x33,0x4d,0x54,0x41,0x79,0x4d,0x7a,0x41,0x30,0x4d,0x54,0x4d,0x79,0x4d,0x57,0x55,0x79,0x4d,0x7a,0x4d,0x73,0x4d,0x7a,0x49,0x33,0x4d,0x54,0x4d,0x33,0x4d,0x54,0x49,0x79,0x4d,0x57,0x55,0x79,0x4d,0x54,0x4d,0x73,0x4d,0x7a,0x49,0x33,0x4d,0x54,0x4d,0x33,0x4d,0x54,0x49,0x79,0x4d,0x57,0x55,0x79,0x4d,0x54,0x4d,0x73,0x4d,0x31,0x30,0x73,0x49,0x43,0x4a,0x6b,0x4a,0x43,0x49,0x36,0x57,0x7a,0x41,0x73,0x4d,0x54,0x55,0x33,0x4d,0x54,0x41,0x79,0x4d,0x7a,0x41,0x30,0x4d,0x54,0x4d,0x79,0x4d,0x57,0x55,0x79,0x4d,0x7a,0x4d,0x73,0x4d,0x54,0x55,0x33,0x4d,0x54,0x41,0x79,0x4d,0x7a,0x41,0x30,0x4d,0x54,0x4d,0x79,0x4d,0x57,0x55,0x79,0x4d,0x7a,0x4d,0x73,0x4d,0x7a,0x49,0x33,0x4d,0x54,0x4d,0x33,0x4d,0x54,0x49,0x79,0x4d,0x57,0x55,0x79,0x4d,0x54,0x4d,0x73,0x4d,0x7a,0x49,0x33,0x4d,0x54,0x4d,0x33,0x4d,0x54,0x49,0x79,0x4d,0x57,0x55,0x79,0x4d,0x54,0x4d,0x73,0x4d,0x54,0x41,0x79,0x4d,0x31,0x30,0x73,0x49,0x43,0x49,0x6b,0x49,0x43,0x49,0x36,0x4e,0x48,0x33,0x2e,0x61, Step #5: e33.e1=qImF1ZCI6WzIyMzU3MTAyMzA0MTMyMWUyMzMsMzI3MTM3MTIyMWUyMTMsMzI3MTM3MTIyMWUyMTMsM10sICJkJCI6WzAsMTU3MTAyMzA0MTMyMWUyMzMsMTU3MTAyMzA0MTMyMWUyMzMsMzI3MTM3MTIyMWUyMTMsMzI3MTM3MTIyMWUyMTMsMTAyM10sICIkICI6NH3.a Step #5: artifact_prefix='./'; Test unit written to ./oom-fe79d53341a97d0f6058685f354a957bc302af7b Step #5: Base64: ZTMzLmUxPXFJbUYxWkNJNld6SXlNelUzTVRBeU16QTBNVE15TVdVeU16TXNNekkzTVRNM01USXlNV1V5TVRNc016STNNVE0zTVRJeU1XVXlNVE1zTTEwc0lDSmtKQ0k2V3pBc01UVTNNVEF5TXpBME1UTXlNV1V5TXpNc01UVTNNVEF5TXpBME1UTXlNV1V5TXpNc016STNNVE0zTVRJeU1XVXlNVE1zTXpJM01UTTNNVEl5TVdVeU1UTXNNVEF5TTEwc0lDSWtJQ0k2TkgzLmE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4926 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4213876935 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e8152f2810, 0x55e8154dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e8154dc020,0x55e8173740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fe79d53341a97d0f6058685f354a957bc302af7b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6214 processed earlier; will process 4815 files now Step #5: #1 pulse cov: 4270 ft: 4271 exec/s: 0 rss: 178Mb Step #5: ==177412== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e80bde79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e81244c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e81242f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e81242f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e80bdedd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e80bd4eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e80bd49355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e80bddfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e80edaef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e80edaef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e80edaef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e80edaef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e80edaef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e80edaef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e80edaef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e80edaef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e80edaef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e80edaef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e811043f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e80dd70b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e80dd7bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e80db27c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e80db27c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e80db28738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e80db27874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e80db27874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e80db27874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e812431abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e81243a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e812422699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e81244d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6d7281f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e80bd47b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x73,0x74,0x72,0x79,0x20,0x28,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x20,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x5b,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x31,0x3d,0x33,0x0,0x54,0x59,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x44,0x5f,0x6e,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x44,0x5f,0x6e,0x4d, Step #5: **********************************************stry (********************\000\000*********************************************************************** *********************[****************1=3\000TY******D_n******D_nM Step #5: artifact_prefix='./'; Test unit written to ./oom-9ec22846537d333b3f3d936c4d991508ccdd8b7d Step #5: Base64: KioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKnN0cnkgKCoqKioqKioqKioqKioqKioqKioqAAAqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKiAqKioqKioqKioqKioqKioqKioqKipbKioqKioqKioqKioqKioqKjE9MwBUWSoqKioqKkRfbioqKioqKkRfbk0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4927 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4214456070 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564f6d10c810, 0x564f6d2f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564f6d2f6020,0x564f6f18e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9ec22846537d333b3f3d936c4d991508ccdd8b7d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6216 processed earlier; will process 4813 files now Step #5: ==177448== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564f63c019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f6a266898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f6a2495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f6a2494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f63c07d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f63b68b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f63b63355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f63bf9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f66bc8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f66bc8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f66bc8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f66bc8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f66bc8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f66bc8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f66bc8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f66bc8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f66bc8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f66bc8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f68e5df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f65b8ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f65b95be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f65941c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f65941c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f65942738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f65941874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f65941874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f65941874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f6a24babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f6a254928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f6a23c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f6a267112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f63a89082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f63b61b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc3,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0,0x20,0xc2,0xa0, Step #5: \303\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 \302\240 Step #5: artifact_prefix='./'; Test unit written to ./oom-07035a1a861d1c1b90d56e312de5d92e22815f97 Step #5: Base64: w6AgwqAgwqAgwqAgwqAgIMKgIMKgIMKgIMKgICDCoCDCoCDCoCDCoCAgwqAgwqAgwqAgwqAgIMKgIMKgIMKgIMKgICDCoCDCoCDCoCDCoCAgwqAgwqAgwqAgwqAgIMKgIMKgIMKgIMKgICDCoCDCoCDCoCDCoCAgwqAgwqAgwqAgwqAgIMKgIMKgIMKgIMKgICDCoCDCoCDCoCDCoCAgwqAgwqAgwqAgwqAgIMKgIMKgIMKgIMKgICDCoCDCoCDCoCDCoCAgwqAgwqAgwqAgwqA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4928 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4214979734 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555f939f1810, 0x555f93bdb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555f93bdb020,0x555f95a730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/07035a1a861d1c1b90d56e312de5d92e22815f97' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6217 processed earlier; will process 4812 files now Step #5: ==177484== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555f8a4e69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555f90b4b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555f90b2e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555f90b2e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555f8a4ecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555f8a44db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555f8a448355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555f8a4dec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555f8d4adf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555f8d4adf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555f8d4adf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555f8d4adf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555f8d4adf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555f8d4adf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555f8d4adf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555f8d4adf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555f8d4adf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555f8d4adf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555f8f742f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555f8c46fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555f8c47abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555f8c226c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555f8c226c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555f8c227738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555f8c226874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555f8c226874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555f8c226874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555f90b30abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555f90b39928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555f90b21699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555f90b4c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d2d184082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555f8a446b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x65,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x65,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x4d,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x64,0x65, Step #5: \005-----BEGIN -----\012dddddddddddddddddedddddddddddddddddddddddddddddeddddddddMddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddde Step #5: artifact_prefix='./'; Test unit written to ./oom-8fdf9c776cbf98fb0e620397a7e78549678c5fb7 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KZGRkZGRkZGRkZGRkZGRkZGRlZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRlZGRkZGRkZGRNZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4929 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4215502090 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cf052d2810, 0x55cf054bc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cf054bc020,0x55cf073540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8fdf9c776cbf98fb0e620397a7e78549678c5fb7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6218 processed earlier; will process 4811 files now Step #5: #1 pulse cov: 3970 ft: 3971 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4044 ft: 4329 exec/s: 0 rss: 178Mb Step #5: ==177520== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cefbdc79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cf0242c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cf0240f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cf0240f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cefbdcdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cefbd2eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cefbd29355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cefbdbfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cefed8ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cefed8ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cefed8ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cefed8ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cefed8ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cefed8ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cefed8ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cefed8ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cefed8ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cefed8ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cf01023f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cefdd50b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cefdd5bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cefdb07c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cefdb07c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cefdb08738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cefdb07874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cefdb07874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cefdb07874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cf02411abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cf0241a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cf02402699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cf0242d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b7187c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cefbd27b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x11,0x0,0x24,0x2e,0x0,0x5,0x5,0x5,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x20,0x22,0x22,0x22,0x22,0x22,0x22,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x24,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x24,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x3b,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x22,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x23,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x22,0x5,0xd2,0x84,0x5,0x5,0x5,0x5,0x24,0x3d, Step #5: \021\000$.\000\005\005\005\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\" \"\"\"\"\"\";;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;$;;;;;;;;;;;;;;;;;$;;;;;;;;;;;;;;;;;;;;;;\"\"\"\"\"\"\"\"\000\000\000\000\000\000\000\000\000\000\000\000\000\000;;;;;;;;;;;;;;\"\"\"\"\"\"\"\"\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000#\000\000\000\000\000\000\000\000\000\000\"\005\322\204\005\005\005\005$= Step #5: artifact_prefix='./'; Test unit written to ./oom-c112e71092a1267ffcbc894a0a8f4d30d9db9aee Step #5: Base64: EQAkLgAFBQUiIiIiIiIiIiIiIiIiIiIiIiIiICIiIiIiIjs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OzskOzs7Ozs7Ozs7Ozs7Ozs7OzskOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OyIiIiIiIiIiAAAAAAAAAAAAAAAAAAA7Ozs7Ozs7Ozs7Ozs7OyIiIiIiIiIiAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIwAAAAAAAAAAAAAiBdKEBQUFBSQ9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4930 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4216119573 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559280e15810, 0x559280fff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559280fff020,0x559282e970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c112e71092a1267ffcbc894a0a8f4d30d9db9aee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6221 processed earlier; will process 4808 files now Step #5: ==177556== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55927790a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55927df6f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55927df525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55927df524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559277910d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559277871b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55927786c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559277902c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55927a8d1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55927a8d1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55927a8d1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55927a8d1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55927a8d1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55927a8d1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55927a8d1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55927a8d1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55927a8d1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55927a8d1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55927cb66f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559279893b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55927989ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55927964ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55927964ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55927964b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55927964a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55927964a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55927964a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55927df54abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55927df5d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55927df45699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55927df70112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcabdf70082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55927786ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x64,0x65,0x73,0x63,0x72,0x69,0x70,0x74,0x69,0x6f,0x6e,0x3e,0x3c,0x3f, Step #5: <description><description><description><description><description><description><description><description><description><description><description><description><description><description><description><description><? Step #5: artifact_prefix='./'; Test unit written to ./oom-29b375c6ebf2573f774c1c105ef5e1bec1258a1b Step #5: Base64: PGRlc2NyaXB0aW9uPjxkZXNjcmlwdGlvbj48ZGVzY3JpcHRpb24+PGRlc2NyaXB0aW9uPjxkZXNjcmlwdGlvbj48ZGVzY3JpcHRpb24+PGRlc2NyaXB0aW9uPjxkZXNjcmlwdGlvbj48ZGVzY3JpcHRpb24+PGRlc2NyaXB0aW9uPjxkZXNjcmlwdGlvbj48ZGVzY3JpcHRpb24+PGRlc2NyaXB0aW9uPjxkZXNjcmlwdGlvbj48ZGVzY3JpcHRpb24+PGRlc2NyaXB0aW9uPjw/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4931 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4216644365 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561cb7886810, 0x561cb7a7001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561cb7a70020,0x561cb99080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/29b375c6ebf2573f774c1c105ef5e1bec1258a1b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6222 processed earlier; will process 4807 files now Step #5: ==177592== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561cae37b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561cb49e0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561cb49c35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561cb49c34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561cae381d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561cae2e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561cae2dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561cae373c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561cb1342f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561cb1342f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561cb1342f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561cb1342f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561cb1342f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561cb1342f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561cb1342f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561cb1342f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561cb1342f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561cb1342f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561cb35d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561cb0304b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561cb030fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561cb00bbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561cb00bbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561cb00bc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561cb00bb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561cb00bb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561cb00bb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561cb49c5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561cb49ce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561cb49b6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561cb49e1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6617d2b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561cae2dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x62,0x6a,0x65,0x63,0x74,0x43,0x6c,0x61,0x73,0x73,0x3a,0x73,0x75,0x64,0x6f,0x52,0x6f,0x6c,0x65,0xa,0x73,0x75,0x64,0x6f,0x48,0x6f,0x73,0x74,0x3a,0xa,0x73,0x75,0x64,0x6f,0x55,0x73,0x65,0x72,0x3a,0xa,0x73,0x75,0x64,0x6f,0x43,0x6f,0x6d,0x6d,0x61,0x6e,0x64,0x3a,0xa,0x73,0x75,0x64,0x6f,0x4e,0x6f,0x74,0x42,0x65,0x66,0x6f,0x72,0x65,0x3a,0x32,0x30,0x34,0x39,0x37,0x39,0x35,0x38,0x35,0x33,0x2e,0xa,0x73,0x75,0x64,0x6f,0x4e,0x6f,0x74,0x41,0x66,0x74,0x65,0x72,0x3a,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x39,0x2e,0xa,0xa,0x6f,0x62,0x6a,0x65,0x63,0x74,0x43,0x6c,0x61,0x73,0x73,0x3a,0x73,0x75,0x64,0x6f,0x52,0x6f,0x6c,0x65,0xa,0x73,0x75,0x64,0x6f,0x48,0x6f,0x73,0x74,0x3a,0xa,0x73,0x75,0x64,0x6f,0x55,0x73,0x65,0x72,0x3a,0xa,0x73,0x75,0x64,0x6f,0x43,0x6f,0x6d,0x6d,0x61,0x6e,0x64,0x3a,0xa,0x73,0x75,0x64,0x6f,0x4e,0x6f,0x74,0x41,0x66,0x74,0x65,0x72,0x3a,0x31,0x34,0x37,0x37,0x34,0x30,0x37,0x33,0x36,0x32,0x2e,0xa,0x73,0x75,0x64,0x6f,0x4e,0x6f,0x74,0x42,0x65,0x66,0x6f,0x72,0x65,0x3a,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x38,0x2e, Step #5: objectClass:sudoRole\012sudoHost:\012sudoUser:\012sudoCommand:\012sudoNotBefore:2049795853.\012sudoNotAfter:2147483649.\012\012objectClass:sudoRole\012sudoHost:\012sudoUser:\012sudoCommand:\012sudoNotAfter:1477407362.\012sudoNotBefore:2147483648. Step #5: artifact_prefix='./'; Test unit written to ./oom-b8558129a5a91474470997584bdeaedef497494c Step #5: Base64: b2JqZWN0Q2xhc3M6c3Vkb1JvbGUKc3Vkb0hvc3Q6CnN1ZG9Vc2VyOgpzdWRvQ29tbWFuZDoKc3Vkb05vdEJlZm9yZToyMDQ5Nzk1ODUzLgpzdWRvTm90QWZ0ZXI6MjE0NzQ4MzY0OS4KCm9iamVjdENsYXNzOnN1ZG9Sb2xlCnN1ZG9Ib3N0OgpzdWRvVXNlcjoKc3Vkb0NvbW1hbmQ6CnN1ZG9Ob3RBZnRlcjoxNDc3NDA3MzYyLgpzdWRvTm90QmVmb3JlOjIxNDc0ODM2NDgu Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4932 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4217172550 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55597cb9e810, 0x55597cd8801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55597cd88020,0x55597ec200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b8558129a5a91474470997584bdeaedef497494c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6223 processed earlier; will process 4806 files now Step #5: #1 pulse cov: 4311 ft: 4312 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4501 ft: 5275 exec/s: 0 rss: 179Mb Step #5: ==177628== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5559736939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555979cf8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555979cdb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555979cdb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555973699d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5559735fab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5559735f5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55597368bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55597665af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55597665af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55597665af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55597665af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55597665af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55597665af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55597665af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55597665af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55597665af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55597665af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5559788eff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55597561cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555975627be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5559753d3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5559753d3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5559753d4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5559753d3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5559753d3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5559753d3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555979cddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555979ce6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555979cce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555979cf9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb661229082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5559735f3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x20,0x7f,0x7f,0x0,0x29,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x30,0x63,0x60,0x60,0x64,0x60,0x60,0x60,0x6,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x60,0x60,0x60,0x60,0x69,0x66,0x60,0x60,0x60,0x60,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x10,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x30,0x63,0x60,0x60,0x64,0x60,0x60,0x60,0x6,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x35,0x35,0x35,0x35,0x35,0x0,0x2,0x78,0x0,0x1,0x3,0x5c,0x49,0xe,0x0,0xe9,0x44,0x33,0x2,0x1,0x0,0x74,0x2e,0x0,0x44,0x0,0x0,0x54,0x0,0x41,0x5b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0x28,0x0,0x72,0x0,0x0,0x28,0x0,0x72,0x64,0x64,0x64,0x64,0x64,0x64, Step #5: = \177\177\000)\000\000\000\000\000\000\0000c``d```\006\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000````if````\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\020\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0000c``d```\006\000\000\000\000\000\000\000\000\000\000\000\000\000\000\00055555\000\002x\000\001\003\\I\016\000\351D3\002\001\000t.\000D\000\000T\000A[\000\000\000\000\000\000\000\000\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246(\000r\000\000(\000rdddddd Step #5: artifact_prefix='./'; Test unit written to ./oom-fed9ada1e6a617859e608fce2a9bdd12f65247ae Step #5: Base64: PSB/fwApAAAAAAAAADBjYGBkYGBgBgAAAAAAAAAAAAAAAAAAAAAAAAAAYGBgYGlmYGBgYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEQAAAAAAAAAAAAAAAAAAAAAAAAADBjYGBkYGBgBgAAAAAAAAAAAAAAAAAAADU1NTU1AAJ4AAEDXEkOAOlEMwIBAHQuAEQAAFQAQVsAAAAAAAAAAKampqampqampqampqampqampqampqampqampigAcgAAKAByZGRkZGRk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4933 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4217903714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563bed808810, 0x563bed9f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563bed9f2020,0x563bef88a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fed9ada1e6a617859e608fce2a9bdd12f65247ae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6226 processed earlier; will process 4803 files now Step #5: #1 pulse cov: 11346 ft: 11347 exec/s: 0 rss: 194Mb Step #5: ==177664== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563be42fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563bea962898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563bea9455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563bea9454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563be4303d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563be4264b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563be425f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563be42f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563be72c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563be72c4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563be72c4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563be72c4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563be72c4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563be72c4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563be72c4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563be72c4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563be72c4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563be72c4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563be9559f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563be6286b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563be6291be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563be603dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563be603dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563be603e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563be603d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563be603d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563be603d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563bea947abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563bea950928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563bea938699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563bea963112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f13ed07f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563be425db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x78,0x6e,0x2d,0x2d,0xe3,0x89,0x9e,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x2e,0x78,0x6e,0x2d,0x2d,0xe3,0x89,0x9c,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x2e,0x78,0x6e,0x2d,0x2d,0xe3,0x89,0x9c,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x2e,0x78,0x6e,0x2d,0x2d,0xe3,0x89,0x9c,0x41,0x45,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x2e,0x78,0x6e,0x2d,0x2d,0xe3,0x89,0x9c,0x45,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x2e,0x78,0x6e,0x2d,0x2d,0xe3,0x89,0x9c,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x2e,0x78,0x6e,0x2d,0x2d,0xe3,0x89,0x9c,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x2e,0x78,0x6e,0x2d,0x2d,0xe3,0x89,0x9c,0x41,0x45,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x2e,0x78,0x6e,0x2d,0x2d,0xe3,0x89,0x9c,0x45,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41, Step #5: ws:xn--\343\211\236AAAAAAAAAAAAAAAAAAAA.xn--\343\211\234AAAAAAAAAAAAAAAAAA.xn--\343\211\234AAAAAAAAA.xn--\343\211\234AEAAAAAAAAAAAAAAA.xn--\343\211\234EAAAAAAAAAAAAAAA.xn--\343\211\234AAAAAAAAAAAAAAA.xn--\343\211\234AAAAAAAAA.xn--\343\211\234AEAAAAAAAAAAAAA.xn--\343\211\234EAAAAAAAAAAAAAAAAA Step #5: artifact_prefix='./'; Test unit written to ./oom-1a5204c5cd495a79accf491c4e924edeea1c7a55 Step #5: Base64: d3M6eG4tLeOJnkFBQUFBQUFBQUFBQUFBQUFBQUFBLnhuLS3jiZxBQUFBQUFBQUFBQUFBQUFBQUEueG4tLeOJnEFBQUFBQUFBQS54bi0t44mcQUVBQUFBQUFBQUFBQUFBQUEueG4tLeOJnEVBQUFBQUFBQUFBQUFBQUEueG4tLeOJnEFBQUFBQUFBQUFBQUFBQS54bi0t44mcQUFBQUFBQUFBLnhuLS3jiZxBRUFBQUFBQUFBQUFBQUEueG4tLeOJnEVBQUFBQUFBQUFBQUFBQUFBQQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4934 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4218511568 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56266c4a9810, 0x56266c69301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56266c693020,0x56266e52b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1a5204c5cd495a79accf491c4e924edeea1c7a55' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6228 processed earlier; will process 4801 files now Step #5: #1 pulse cov: 3917 ft: 3918 exec/s: 0 rss: 175Mb Step #5: ==177700== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562662f9e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562669603898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5626695e65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5626695e64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562662fa4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562662f05b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562662f00355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562662f96c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562665f65f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562665f65f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562665f65f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562665f65f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562665f65f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562665f65f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562665f65f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562665f65f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562665f65f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562665f65f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5626681faf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562664f27b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562664f32be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562664cdec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562664cdec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562664cdf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562664cde874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562664cde874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562664cde874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5626695e8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5626695f1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5626695d9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562669604112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcbce4d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562662efeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x73,0x20,0x5b,0x38,0x20,0x30,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x0,0x0,0x0,0x11,0x2d,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x31,0x38,0x37,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x34,0x34,0x34,0x34,0x34,0x34,0x14,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0x0,0x1,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x24,0x5b,0x2d,0xf,0xf,0xf,0x31,0x11,0x60,0xf,0x31,0x11,0x2d,0x3a,0x24,0x2a,0x24,0x5b,0x2d,0x3a,0x24,0x60, Step #5: $4444444444444444444444s [8 0444444444444444444444\000\000\000\021-4444444444444444444444444444444444444444444444444444187\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177444444\02444444444444444444444\000\000/\000\000\000/\000\017\017\017\017\000\001\0171\021\0171\021-:$[-\017\017\0171\021`\0171\021-:$*$[-:$` Step #5: artifact_prefix='./'; Test unit written to ./oom-4f3d692cdcbdd27b2c60533c0ed25f791e79acb8 Step #5: Base64: JDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDRzIFs4IDA0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQAAAARLTQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQxODd/f39/f39/f39/f39/f39/f39/f39/f39/f39/f380NDQ0NDQUNDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQAAC8AAAAvAA8PDw8AAQ8xEQ8xES06JFstDw8PMRFgDzERLTokKiRbLTokYA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4935 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4219207002 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556ab9e5e810, 0x556aba04801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556aba048020,0x556abbee00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f3d692cdcbdd27b2c60533c0ed25f791e79acb8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6230 processed earlier; will process 4799 files now Step #5: ==177736== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556ab09539c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556ab6fb8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556ab6f9b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556ab6f9b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556ab0959d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556ab08bab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556ab08b5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556ab094bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556ab391af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556ab391af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556ab391af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556ab391af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556ab391af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556ab391af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556ab391af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556ab391af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556ab391af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556ab391af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556ab5baff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556ab28dcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556ab28e7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556ab2693c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556ab2693c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556ab2694738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556ab2693874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556ab2693874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556ab2693874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556ab6f9dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556ab6fa6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556ab6f8e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556ab6fb9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa6cfe7b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556ab08b3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xbd,0xb0,0xe0,0xbc,0xb0,0xe0,0xb8,0xbd,0xe0,0xbe,0xb0,0xe0,0xb8,0xbd,0xe0,0xbc,0xb0,0xe0,0xbd,0xb0,0xe0,0xbd,0xb0,0xe0,0xbd,0xb0,0xe0,0xbd,0xaf,0xe0,0xbd,0xb0,0xe0,0xbe,0xb0,0xe0,0xb8,0xbd,0xe0,0xbd,0xb0,0xe0,0xbe,0xad,0xe0,0xb9,0xbd,0xe0,0xbd,0xb0,0xe0,0xb8,0xad,0xe0,0xbc,0xb1,0xe0,0xbf,0xb1,0xe0,0xbd,0xb1,0xe0,0xbd,0xb0,0xe0,0xbd,0xb0,0xe0,0xbd,0xb0,0xe0,0xbc,0xb0,0xe0,0xbd,0xb0,0xe0,0xbd,0xb0,0xe0,0xbe,0xb4,0xe0,0xbd,0xaf,0xe0,0xbd,0xb0,0xe0,0xb9,0xbd,0xe0,0xbf,0xb0,0xe0,0xbb,0xb0,0xe0,0xbd,0xb0,0xe0,0xbd,0xb0,0xe0,0xbe,0xb1,0xe0,0xb7,0xae,0xe0,0xbd,0xb0,0xe0,0xbd,0xb0,0xe0,0xb8,0xbd,0xe0,0xbd,0xb0,0xe0,0xb8,0xb0,0xe0,0xb8,0xbd,0xe0,0xbc,0xb0,0xe0,0xbd,0xb0,0xe0,0xbd,0xb0,0xe0,0xbd,0xb0,0xe0,0xbd,0xaf,0xe0,0xbd,0xb0,0xe0,0xbe,0xb0,0xe0,0xb8,0xbd,0xe0,0xb8,0xaf,0xe0,0xb8,0xbd,0xe0,0xbc,0xb0,0xe0,0xbd,0xb0,0xe0,0xbd,0xb0,0xe0,0xbd,0xaf,0xe0,0xbd,0xb0,0xe0,0xbe,0xb0,0xe0,0xb8,0xbd,0xe0,0xbd,0xb0,0xe0,0xbe,0xac,0xe0,0xb9,0xbd,0xe0,0xbd,0xbf,0xbd,0xe0,0xbd,0xc1,0x0,0x18,0x1,0x0,0x0,0x40,0xc3,0xcc,0x4e,0x5b,0xef,0xef,0xe8,0x32,0xc,0x2c, Step #5: \340\275\260\340\274\260\340\270\275\340\276\260\340\270\275\340\274\260\340\275\260\340\275\260\340\275\260\340\275\257\340\275\260\340\276\260\340\270\275\340\275\260\340\276\255\340\271\275\340\275\260\340\270\255\340\274\261\340\277\261\340\275\261\340\275\260\340\275\260\340\275\260\340\274\260\340\275\260\340\275\260\340\276\264\340\275\257\340\275\260\340\271\275\340\277\260\340\273\260\340\275\260\340\275\260\340\276\261\340\267\256\340\275\260\340\275\260\340\270\275\340\275\260\340\270\260\340\270\275\340\274\260\340\275\260\340\275\260\340\275\260\340\275\257\340\275\260\340\276\260\340\270\275\340\270\257\340\270\275\340\274\260\340\275\260\340\275\260\340\275\257\340\275\260\340\276\260\340\270\275\340\275\260\340\276\254\340\271\275\340\275\277\275\340\275\301\000\030\001\000\000@\303\314N[\357\357\3502\014, Step #5: artifact_prefix='./'; Test unit written to ./oom-b9f5395bffc332a22acb72c91d607384864a437a Step #5: Base64: 4L2w4Lyw4Li94L6w4Li94Lyw4L2w4L2w4L2w4L2v4L2w4L6w4Li94L2w4L6t4Lm94L2w4Lit4Lyx4L+x4L2x4L2w4L2w4L2w4Lyw4L2w4L2w4L604L2v4L2w4Lm94L+w4Luw4L2w4L2w4L6x4Leu4L2w4L2w4Li94L2w4Liw4Li94Lyw4L2w4L2w4L2w4L2v4L2w4L6w4Li94Liv4Li94Lyw4L2w4L2w4L2v4L2w4L6w4Li94L2w4L6s4Lm94L2/veC9wQAYAQAAQMPMTlvv7+gyDCw= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4936 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4219731570 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558374e29810, 0x55837501301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558375013020,0x558376eab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b9f5395bffc332a22acb72c91d607384864a437a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6231 processed earlier; will process 4798 files now Step #5: ==177772== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55836b91e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558371f83898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558371f665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558371f664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55836b924d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55836b885b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55836b880355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55836b916c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55836e8e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55836e8e5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55836e8e5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55836e8e5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55836e8e5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55836e8e5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55836e8e5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55836e8e5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55836e8e5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55836e8e5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558370b7af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55836d8a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55836d8b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55836d65ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55836d65ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55836d65f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55836d65e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55836d65e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55836d65e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558371f68abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558371f71928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558371f59699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558371f84112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f48b50082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55836b87eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x31,0x32,0x39,0x2d,0x2d,0x27,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x65,0x6e,0x2d,0x63,0x2d,0x74,0x2d,0x2d,0xf3,0xa0,0x81,0x8c,0xd,0xa,0x4e,0xd,0xf3,0xa0,0x85,0xab,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x60,0xd,0x60,0xd,0xd,0xa,0x4e,0xd,0xa,0x0,0xa,0x3d,0x1d,0x0,0x41,0x0,0x0,0x0,0x20,0x0,0x0,0x0,0x0,0x0,0x32,0x31,0x2d,0x2d,0xf3,0xa0,0x81,0x8c,0xd,0xa,0x4e,0xd,0xf3,0xa0,0x80,0xab,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x60,0xd,0x60,0xd,0xd,0xa,0x4e,0xd,0xa,0x0,0xa,0x3d,0x1d,0x0,0x41,0x0,0x0,0x0,0x20,0x0,0x0,0x0,0x0,0x0,0x32,0x31,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x67,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x7a,0x27,0xff,0xff,0xff,0x1c,0x27,0x27,0xe6,0xb7,0xba,0x27,0x27,0x0,0x0,0x0,0x0,0x31,0x0,0x0,0x3f,0x0,0x0,0x0,0x0,0x24,0x24,0x43,0x47,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1b, Step #5: x--129--'-BEGIN -en-c-t--\363\240\201\214\015\012N\015\363\240\205\253BEGIN --`\015`\015\015\012N\015\012\000\012=\035\000A\000\000\000 \000\000\000\000\00021--\363\240\201\214\015\012N\015\363\240\200\253BEGIN --`\015`\015\015\012N\015\012\000\012=\035\000A\000\000\000 \000\000\000\000\00021-=<'''''=<''''''-=<'''''=<''''''''g''/''''''''z'\377\377\377\034''\346\267\272''\000\000\000\0001\000\000?\000\000\000\000$$CG\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\033 Step #5: artifact_prefix='./'; Test unit written to ./oom-155a6feb47f694d330002b4a67ac71cabd29b873 Step #5: Base64: eC0tMTI5LS0nLUJFR0lOIC1lbi1jLXQtLfOggYwNCk4N86CFq0JFR0lOIC0tYA1gDQ0KTg0KAAo9HQBBAAAAIAAAAAAAMjEtLfOggYwNCk4N86CAq0JFR0lOIC0tYA1gDQ0KTg0KAAo9HQBBAAAAIAAAAAAAMjEtPTwnJycnJz08JycnJycnLT08JycnJyc9PCcnJycnJycnZycnLycnJycnJycneif///8cJyfmt7onJwAAAAAxAAA/AAAAACQkQ0cAAAAAAAAAAAAAAAAAAAAAABs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4937 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4220385642 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56227ab42810, 0x56227ad2c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56227ad2c020,0x56227cbc40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/155a6feb47f694d330002b4a67ac71cabd29b873' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6232 processed earlier; will process 4797 files now Step #5: #1 pulse cov: 3844 ft: 3845 exec/s: 0 rss: 177Mb Step #5: ==177808== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5622716379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562277c9c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562277c7f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562277c7f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56227163dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56227159eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562271599355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56227162fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5622745fef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5622745fef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5622745fef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5622745fef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5622745fef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5622745fef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5622745fef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5622745fef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5622745fef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5622745fef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562276893f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5622735c0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5622735cbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562273377c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562273377c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562273378738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562273377874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562273377874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562273377874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562277c81abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562277c8a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562277c72699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562277c9d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2511d93082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562271597b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x47,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x47,0x2d,0x49,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0x3b,0x3d,0x6,0x6,0x49,0x6f,0x74,0x61,0x6,0x6,0x6,0x6,0xe,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0xa,0x2d,0xa,0x2d,0xa,0x4e,0xa,0x3d,0x3b,0x3d,0x6,0x6,0x49,0xe2,0x80,0xae,0x6f,0x74,0x61,0x6,0x6,0x6,0x6,0xe,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x49,0x6f,0x74,0x61,0x6,0x6,0x6,0x6,0xe,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x49,0x6f,0x74,0x61,0x6,0x6,0x6,0x6,0xe,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0xa,0x3d,0x41,0x3d,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0xa,0x3d,0x41,0x3d,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x85,0xa4,0x31,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa, Step #5: \005-----BGGIN --G-I--\012N\012=;=\006\006Iota\006\006\006\006\016\006\006\006\006\006\006\006\006\006\006\006\006\006\006\012-\012-\012N\012=;=\006\006I\342\200\256ota\006\006\006\006\016\006\006\006\006\006\006\006\006Iota\006\006\006\006\016\006\006\006\006\006\006\006\006\006\006\006\006\006\006Iota\006\006\006\006\016\006\006\006\006\006\006\006\006\006\006\006\006\006\006\012-\012-\012-\012-\012\012\012=A=\006\006\006\006\006\006\006\006\006\006\012-\012-\012-\012-\012\012\012=A=\006\006\006\006\006\006\006\006\006\006\012-\012-\012-\012-\012\012\012=\012=\012=\012=\205\2441\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-5996d15f1bafd3a012d94339c7ad8fa6cad6ee5b Step #5: Base64: BS0tLS0tQkdHSU4gLS1HLUktLQpOCj07PQYGSW90YQYGBgYOBgYGBgYGBgYGBgYGBgYKLQotCk4KPTs9BgZJ4oCub3RhBgYGBg4GBgYGBgYGBklvdGEGBgYGDgYGBgYGBgYGBgYGBgYGSW90YQYGBgYOBgYGBgYGBgYGBgYGBgYKLQotCi0KLQoKCj1BPQYGBgYGBgYGBgYKLQotCi0KLQoKCj1BPQYGBgYGBgYGBgYKLQotCi0KLQoKCj0KPQo9Cj2FpDEKCgoKCgoKCgoKCgoKCgo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4938 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4220968358 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fb679d3810, 0x55fb67bbd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fb67bbd020,0x55fb69a550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5996d15f1bafd3a012d94339c7ad8fa6cad6ee5b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6234 processed earlier; will process 4795 files now Step #5: ==177844== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fb5e4c89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fb64b2d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fb64b105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fb64b104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fb5e4ced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fb5e42fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fb5e42a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fb5e4c0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fb6148ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fb6148ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fb6148ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fb6148ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fb6148ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fb6148ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fb6148ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fb6148ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fb6148ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fb6148ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fb63724f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fb60451b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fb6045cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fb60208c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fb60208c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fb60209738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fb60208874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fb60208874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fb60208874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fb64b12abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fb64b1b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fb64b03699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fb64b2e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcaf4e66082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fb5e428b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x60,0x23,0x60,0x60,0x60,0x60,0x60,0x60,0x67,0x6c,0x79,0x66,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x2a,0x27,0x44,0x61,0x6e,0x4d,0x7a,0x31,0x0,0x20,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0xa0,0x9f,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x37,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x60,0x60,0x58,0x0,0x0,0x0,0x0,0x2a,0x2c,0x0,0x68,0x60,0x60,0x60,0x2a,0x27,0x2a,0x68,0x74,0x68,0x5b,0x78,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x6d,0x27, Step #5: B`#``````glyf``````````````````````````*'DanMz1\000 `````````````````````\240\237``````````````````````````````````7\000\000\000\000\000\000\000``X\000\000\000\000*,\000h```*'*hth[x``````````````\001\000\000\000\000\000\000\000````````````````````````````````````````````````````m' Step #5: artifact_prefix='./'; Test unit written to ./oom-d17849211fe06c622e4e684394c0d8c7196fde90 Step #5: Base64: QmAjYGBgYGBgZ2x5ZmBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgKidEYW5NejEAIGBgYGBgYGBgYGBgYGBgYGBgYGBgYKCfYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYDcAAAAAAAAAYGBYAAAAACosAGhgYGAqJypodGhbeGBgYGBgYGBgYGBgYGBgAQAAAAAAAABgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgbSc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4939 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4221619654 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557376968810, 0x557376b5201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557376b52020,0x5573789ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d17849211fe06c622e4e684394c0d8c7196fde90' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6235 processed earlier; will process 4794 files now Step #5: #1 pulse cov: 3998 ft: 3999 exec/s: 0 rss: 175Mb Step #5: ==177880== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55736d45d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557373ac2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557373aa55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557373aa54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55736d463d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55736d3c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55736d3bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55736d455c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557370424f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557370424f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557370424f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557370424f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557370424f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557370424f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557370424f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557370424f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557370424f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557370424f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5573726b9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55736f3e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55736f3f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55736f19dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55736f19dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55736f19e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55736f19d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55736f19d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55736f19d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557373aa7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557373ab0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557373a98699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557373ac3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0b4925e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55736d3bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x72,0x47,0x73,0x65,0x64,0x20,0x2d,0x33,0x32,0x37,0x36,0x37,0x20,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0x0,0x0,0x0,0x1,0x0,0x0,0x10,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xf3,0xa0,0x80,0xa6,0xa,0x3d,0xa,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x24,0x24,0x32,0x31,0x63,0x6f,0x66,0x65,0x2f,0x66,0x27,0x65,0x27,0x27,0x27,0x2f,0x27,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0x27,0x27,0x27,0x32,0x37,0x39,0x39,0x30,0x31,0x39,0x2d,0x3d,0x27,0x27,0x27,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xfe,0xc2,0xc2,0xf5,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x27,0x27,0x27,0x27,0x27,0x1,0x1,0xf1,0x2f,0x27,0x27,0xa,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d,0x3d,0xa,0x10, Step #5: \005-----BrGsed -32767 --\012N\012=\012=\000\000\000\001\000\000\020\012=\012=\012=\012=\363\240\200\246\012=\012\012\012=\012=\012=\012=\012=\012\012\012=\012=\012=\012=\012=\012=\012=====================================$$21cofe/f'e'''/'=\012=\012==\012==\012==\012==\012==\012==\012='''2799019-='''\012=\012=\012=\012=\012=\012=\376\302\302\365=\012=\012=\012='''''\001\001\361/''\012''.'$'-=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-b196e18ac460f51aac2ec1c3e7e3df482943e607 Step #5: Base64: BS0tLS0tQnJHc2VkIC0zMjc2NyAtLQpOCj0KPQAAAAEAABAKPQo9Cj0KPfOggKYKPQoKCj0KPQo9Cj0KPQoKCj0KPQo9Cj0KPQo9Cj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0kJDIxY29mZS9mJ2UnJycvJz0KPQo9PQo9PQo9PQo9PQo9PQo9PQo9JycnMjc5OTAxOS09JycnCj0KPQo9Cj0KPQo9/sLC9T0KPQo9Cj0nJycnJwEB8S8nJwonJy4nJCctPQoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4940 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4222200705 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f580bf5810, 0x55f580ddf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f580ddf020,0x55f582c770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b196e18ac460f51aac2ec1c3e7e3df482943e607' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6237 processed earlier; will process 4792 files now Step #5: ==177916== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f5776ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f57dd4f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f57dd325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f57dd324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f5776f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f577651b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f57764c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f5776e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f57a6b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f57a6b1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f57a6b1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f57a6b1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f57a6b1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f57a6b1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f57a6b1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f57a6b1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f57a6b1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f57a6b1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f57c946f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f579673b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f57967ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f57942ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f57942ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f57942b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f57942a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f57942a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f57942a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f57dd34abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f57dd3d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f57dd25699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f57dd50112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd16ad2c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f57764ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x76,0x6f,0x69,0x64,0x20,0x6a,0x28,0x29,0x7b,0x4e,0x3b,0x62,0x6f,0x6f,0x6c,0x34,0x20,0x73,0x20,0x3b,0x68,0x61,0x6c,0x66,0x5b,0x73,0x2e,0x77,0x77,0x77,0x77,0x2e,0x30,0x42,0x42,0x42,0x2e,0x31,0x77,0x77,0x77,0x2e,0x31,0x77,0x77,0x77,0x2e,0x30,0x42,0x42,0x42,0x66,0x5b,0x73,0x2e,0x77,0x77,0x77,0x77,0x2e,0x30,0x42,0x42,0x42,0x2e,0x31,0x77,0x77,0x77,0x2e,0x31,0x77,0x77,0x77,0x2e,0x30,0x42,0x42,0x42,0x2e,0x31,0x42,0x42,0x42,0x2e,0x2e,0x7a,0x77,0x77,0x77,0x2e,0x30,0x42,0x42,0x42,0x66,0x5b,0x73,0x2e,0x77,0x77,0x77,0x77,0x2e,0x30,0x42,0x42,0x42,0x2e,0x31,0x77,0x77,0x77,0x2e,0x31,0x77,0x77,0x77,0x2e,0x30,0x42,0x42,0x42,0x2e,0x31,0x42,0x42,0x42,0x2e,0x31,0x42,0x42,0x42,0x2e,0x7a,0x77,0x77,0x77,0x2e,0x42,0x42,0x2e,0x7c,0x77,0x77,0x77,0x2e,0x30,0x61,0x6c,0x66,0x5b,0x73,0x2e,0x77,0x77,0x77,0x77,0x2e,0x30,0x42,0x42,0x42,0x2e,0x31,0x77,0x77,0x77,0x2e,0x30,0x77,0x77,0x77,0x5b,0x73,0x2e,0x77,0x77,0x77,0x77,0x2e,0x30,0x2e,0x25,0x31,0x42,0x5b,0x73,0x2e,0x77,0x77,0x77,0x77,0x2e,0x30,0x42,0x42,0x42,0x2e,0x31,0x77,0x77,0x77,0x2e,0x31,0x77,0x77,0x77,0x2e,0x7a,0x77,0x77,0x77, Step #5: void j(){N;bool4 s ;half[s.wwww.0BBB.1www.1www.0BBBf[s.wwww.0BBB.1www.1www.0BBB.1BBB..zwww.0BBBf[s.wwww.0BBB.1www.1www.0BBB.1BBB.1BBB.zwww.BB.|www.0alf[s.wwww.0BBB.1www.0www[s.wwww.0.%1B[s.wwww.0BBB.1www.1www.zwww Step #5: artifact_prefix='./'; Test unit written to ./oom-186b9a58e5fdf3de481f156279440f2dac846929 Step #5: Base64: dm9pZCBqKCl7Tjtib29sNCBzIDtoYWxmW3Mud3d3dy4wQkJCLjF3d3cuMXd3dy4wQkJCZltzLnd3d3cuMEJCQi4xd3d3LjF3d3cuMEJCQi4xQkJCLi56d3d3LjBCQkJmW3Mud3d3dy4wQkJCLjF3d3cuMXd3dy4wQkJCLjFCQkIuMUJCQi56d3d3LkJCLnx3d3cuMGFsZltzLnd3d3cuMEJCQi4xd3d3LjB3d3dbcy53d3d3LjAuJTFCW3Mud3d3dy4wQkJCLjF3d3cuMXd3dy56d3d3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4941 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4222732766 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5651d12cd810, 0x5651d14b701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5651d14b7020,0x5651d334f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/186b9a58e5fdf3de481f156279440f2dac846929' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6238 processed earlier; will process 4791 files now Step #5: #1 pulse cov: 4175 ft: 4176 exec/s: 0 rss: 179Mb Step #5: ==177952== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5651c7dc29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5651ce427898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651ce40a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651ce40a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5651c7dc8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5651c7d29b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5651c7d24355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5651c7dbac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5651cad89f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5651cad89f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5651cad89f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5651cad89f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5651cad89f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5651cad89f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5651cad89f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5651cad89f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5651cad89f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5651cad89f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5651cd01ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5651c9d4bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5651c9d56be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5651c9b02c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5651c9b02c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5651c9b03738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5651c9b02874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5651c9b02874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5651c9b02874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5651ce40cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5651ce415928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5651ce3fd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5651ce428112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a269fd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5651c7d22b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0xe2,0x80,0x88,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x1c,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x7d,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x5f,0x1c,0x2d,0x0,0x60,0xa,0xf3,0xa0,0x81,0xba,0x2f,0x2f,0x60,0xe2,0x80,0x88,0x2d,0x0,0x60,0xfc,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x29,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: `\342\200\210\034\034\034\034\034\034\034\034\034\034\034\034\034\034\034\034\034\034\034\034________________________________________________________________________________}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}___________________________________\034-\000`\012\363\240\201\272//`\342\200\210-\000`\374\000\000\000\000\000\000\000\000\000\000\000\000)\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-97ed8f5b3b33fa348f75ffc591064eacd587461c Step #5: Base64: YOKAiBwcHBwcHBwcHBwcHBwcHBwcHBwcX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX199fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX1fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXxwtAGAK86CBui8vYOKAiC0AYPwAAAAAAAAAAAAAAAApAAAAAAAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4942 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4223424758 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb77d27810, 0x55eb77f1101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb77f11020,0x55eb79da90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/97ed8f5b3b33fa348f75ffc591064eacd587461c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6240 processed earlier; will process 4789 files now Step #5: #1 pulse cov: 3993 ft: 3994 exec/s: 0 rss: 177Mb Step #5: ==177988== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eb6e81c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb74e81898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb74e645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb74e644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb6e822d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb6e783b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb6e77e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb6e814c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb717e3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb717e3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb717e3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb717e3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb717e3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb717e3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb717e3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb717e3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb717e3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb717e3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb73a78f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb707a5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb707b0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb7055cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb7055cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb7055d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb7055c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb7055c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb7055c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb74e66abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb74e6f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb74e57699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb74e82112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbfa6bf6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb6e77cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xa,0x0,0x7c,0x0,0x72,0x69,0x66,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x75,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x74,0x72,0x65,0x0,0x59,0x3e,0x30,0x2b,0x34,0x27,0x0,0x3a,0xd8,0x80,0x4,0x2b,0x0, Step #5: \000\012\000|\000rif__U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t__U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002_u__U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002_tre\000Y>0+4'\000:\330\200\004+\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e1ae64db15ec5c2822802e922f0d96205c30b835 Step #5: Base64: AAoAfAByaWZfX1VgYF9fXwF0YAACX19fX1VgYF9fXwF0YAACX19fX1VgYF9fXwF0YAACX19fX1VgYF9fXwF0YAACX19fX1VgYF9fXwF0YAACX19fX1VgYF9fXwF0X19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl91X19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl90cmUAWT4wKzQnADrYgAQrAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4943 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4224146633 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56437a4f8810, 0x56437a6e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56437a6e2020,0x56437c57a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e1ae64db15ec5c2822802e922f0d96205c30b835' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6242 processed earlier; will process 4787 files now Step #5: ==178024== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564370fed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564377652898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643776355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643776354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564370ff3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564370f54b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564370f4f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564370fe5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564373fb4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564373fb4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564373fb4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564373fb4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564373fb4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564373fb4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564373fb4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564373fb4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564373fb4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564373fb4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564376249f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564372f76b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564372f81be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564372d2dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564372d2dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564372d2e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564372d2d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564372d2d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564372d2d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564377637abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564377640928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564377628699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564377653112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe750763082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564370f4db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x0,0x0,0x25,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x7d,0x7d,0x2c,0x2c,0x7d,0x30,0x7b,0x30,0x20,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x68,0x65,0x30,0x2c,0x7d,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x25,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7d,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x7,0x7b,0x30,0x2c,0x7d,0x7,0x20,0x7b,0x30,0x2c,0x7d,0x73,0x7b,0x30,0x2c,0x7d,0x20,0x7b,0x30,0x2c,0x7d,0x24,0x7b,0x30,0x2c,0x7d,0x20,0x7e,0xcf,0xd3,0x82,0x20,0x7b,0x30,0x2c,0x7d, Step #5: }{0,} {0,} {0,}s{0,} {0,}${0\000\000%{0,}}{0,} {0,} {0,}s{0,} {0,}${0,} {0,} {}},,}0{0 {0,} {he0,}\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012s{0,} {0,}${0,}%{0,} {0,}}{0,} {0,}\007{0,}\007 {0,}s{0,} {0,}${0,} ~\317\323\202 {0,} Step #5: artifact_prefix='./'; Test unit written to ./oom-78b9bd7d2b5f645957431d4b5b672b0e7f12300a Step #5: Base64: fXswLH0gezAsfSB7MCx9c3swLH0gezAsfSR7MAAAJXswLH19ezAsfSB7MCx9IHswLH1zezAsfSB7MCx9JHswLH0gezAsfSB7fX0sLH0wezAgezAsfSB7aGUwLH0KCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgpzezAsfSB7MCx9JHswLH0lezAsfSB7MCx9fXswLH0gezAsfQd7MCx9ByB7MCx9c3swLH0gezAsfSR7MCx9IH7P04IgezAsfQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4944 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4224681069 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fd65c70810, 0x55fd65e5a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fd65e5a020,0x55fd67cf20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/78b9bd7d2b5f645957431d4b5b672b0e7f12300a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6243 processed earlier; will process 4786 files now Step #5: ==178060== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fd5c7659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fd62dca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fd62dad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fd62dad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fd5c76bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fd5c6ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fd5c6c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fd5c75dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fd5f72cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fd5f72cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fd5f72cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fd5f72cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fd5f72cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fd5f72cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fd5f72cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fd5f72cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fd5f72cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fd5f72cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fd619c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fd5e6eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fd5e6f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fd5e4a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fd5e4a5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fd5e4a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fd5e4a5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fd5e4a5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fd5e4a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fd62dafabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fd62db8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fd62da0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fd62dcb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f78b3e8e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fd5c6c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x7b,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0x20,0x20,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0xc,0x6e,0x61,0x6d,0x65,0x3a,0xd,0x22,0x44,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x27,0x31,0x66,0x27,0x20,0x20,0x20,0x20,0x5c,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x42,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0xc7,0x6c,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x1b,0x2d,0x32,0x32,0x39,0x30,0x7e,0x76,0x3b,0x3a,0x38,0x30,0x37,0x38,0x36,0x37,0x31,0x31,0x31,0x30,0x2f,0x1a,0x66,0x34,0x78,0x4b,0xae,0xae,0xae,0xad,0x9,0x4b,0x4b,0x78,0x78,0x78,0x78,0x78,0x76,0xd7,0xdd,0x31,0x47,0x6d,0x65,0x3a,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x32,0x39,0x20,0x20,0x5c,0x27,0x20,0x20,0x20,0x3e,0x20,0x5c,0x30,0x30,0x30,0x5c,0x72,0x20,0x20,0x3c,0x42,0x20,0x3e,0x22,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x76,0x61,0x6c,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x22,0x20,0x20,0x20,0x7d,0x20,0x7d,0xa,0xa,0x7d,0x20,0x7d,0xa,0x7d,0x7d, Step #5: p{doctype {\012mdecl { entity {\014name:\015\"D PUBLIC '1f' \\'http://~~~~~~~~~~~~~~B~~~~~~\307l { name\033-2290~v;:8078671110/\032f4xK\256\256\256\255\011KKxxxxxv\327\3351Gme: 29 \\' > \\000\\r <B >\"ent {\012 val { name: \"D\" } }\012\012} }\012}} Step #5: artifact_prefix='./'; Test unit written to ./oom-2d78e4c398224825cac41515478d6d4b2fdd5e42 Step #5: Base64: cHtkb2N0eXBlIHsKbWRlY2wgeyAgZW50aXR5IHsMbmFtZToNIkQgUFVCTElDICcxZicgICAgXCdodHRwOi8vfn5+fn5+fn5+fn5+fn5Cfn5+fn5+x2wgeyBuYW1lGy0yMjkwfnY7OjgwNzg2NzExMTAvGmY0eEuurq6tCUtLeHh4eHh2190xR21lOiAgICAgICAgICAgICAgMjkgIFwnICAgPiBcMDAwXHIgIDxCID4iZW50IHsKICB2YWwgeyBuYW1lOiAiRCIgICB9IH0KCn0gfQp9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4945 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4225204813 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a27d330810, 0x55a27d51a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a27d51a020,0x55a27f3b20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2d78e4c398224825cac41515478d6d4b2fdd5e42' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6244 processed earlier; will process 4785 files now Step #5: ==178096== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a273e259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a27a48a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a27a46d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a27a46d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a273e2bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a273d8cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a273d87355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a273e1dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a276decf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a276decf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a276decf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a276decf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a276decf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a276decf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a276decf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a276decf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a276decf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a276decf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a279081f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a275daeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a275db9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a275b65c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a275b65c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a275b66738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a275b65874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a275b65874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a275b65874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a27a46fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a27a478928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a27a460699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a27a48b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbeed14d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a273d85b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x22,0x24,0x24,0x24,0x24,0x24,0x29,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x5b,0x3d,0x3d,0x3d,0x3d,0x3d,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x73,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x24,0xe0,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x22,0x24,0x24,0x24,0x24,0x24,0x29,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x73,0x74,0x72,0x65,0x61,0x6d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x5b,0x2d,0x2d,0x2d,0x9,0x45,0x47,0x4b,0x60,0x20,0x2d,0x2d,0xa,0x44,0xa,0x2d,0x20,0x0,0x0,0x0,0x2e,0x33,0x2e,0x33, Step #5: s--\000\000\000\000\000\000$$$$$$$$$$$$$$\"$$$$$)$$$$$$$$===========================================================[=====$$$$$$$s--\000\000\000\000\000\000$$\340$$$$$$$$$$$\"$$$$$)$$$$$$$$====================stream================[---\011EGK` --\012D\012- \000\000\000.3.3 Step #5: artifact_prefix='./'; Test unit written to ./oom-391c0d2a8b6f856ec415c8ba3f808fbd00819b58 Step #5: Base64: cy0tAAAAAAAAJCQkJCQkJCQkJCQkJCQiJCQkJCQpJCQkJCQkJCQ9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PVs9PT09PSQkJCQkJCRzLS0AAAAAAAAkJOAkJCQkJCQkJCQkJCIkJCQkJCkkJCQkJCQkJD09PT09PT09PT09PT09PT09PT09c3RyZWFtPT09PT09PT09PT09PT09PVstLS0JRUdLYCAtLQpECi0gAAAALjMuMw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4946 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4225738033 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560571d6e810, 0x560571f5801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560571f58020,0x560573df00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/391c0d2a8b6f856ec415c8ba3f808fbd00819b58' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6245 processed earlier; will process 4784 files now Step #5: ==178132== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5605688639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56056eec8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56056eeab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56056eeab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560568869d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605687cab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5605687c5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56056885bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56056b82af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56056b82af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56056b82af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56056b82af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56056b82af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56056b82af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56056b82af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56056b82af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56056b82af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56056b82af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56056dabff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56056a7ecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56056a7f7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56056a5a3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56056a5a3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56056a5a4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56056a5a3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56056a5a3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56056a5a3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56056eeadabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56056eeb6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56056ee9e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56056eec9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faadd60f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5605687c3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7f,0x6e,0x44,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3c,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0x3d,0x3d,0xa,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3c,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0x3d,0x3d,0xa,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x9d,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x5f,0x4f, Step #5: \177nD\012==\012=\012=\012=\012=\012=\012=\012=\012<\012=\012=\012=\012=\012=\012=\012=\012\012===\012\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012<\012=\012=\012=\012=\012=\012=\012=\012\012===\012\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000\000\000\000\000\000\235\000\012=\012=\012=\012=\012=\012=_O Step #5: artifact_prefix='./'; Test unit written to ./oom-b328e1265a8217ab0efddc21af784afc6408fc0e Step #5: Base64: f25ECj09Cj0KPQo9Cj0KPQo9Cj0KPAo9Cj0KPQo9Cj0KPQo9Cgo9PT0KCgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9CjwKPQo9Cj0KPQo9Cj0KPQoKPT09CgoKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KCj0KCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9AAAAAAAAnQAKPQo9Cj0KPQo9Cj1fTw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4947 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4226284517 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b6eaa55810, 0x55b6eac3f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b6eac3f020,0x55b6ecad70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b328e1265a8217ab0efddc21af784afc6408fc0e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6246 processed earlier; will process 4783 files now Step #5: ==178168== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b6e154a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b6e7baf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b6e7b925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b6e7b924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6e1550d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6e14b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6e14ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6e1542c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b6e4511f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b6e4511f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b6e4511f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b6e4511f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b6e4511f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b6e4511f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b6e4511f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b6e4511f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b6e4511f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b6e4511f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b6e67a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6e34d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6e34debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6e328ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6e328ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6e328b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6e328a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6e328a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6e328a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b6e7b94abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b6e7b9d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b6e7b85699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b6e7bb0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e4b9c4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6e14aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0xd,0xa,0x2a,0x36,0x38,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24,0xd,0xa,0xd,0xa,0x24, Step #5: *\015\012*68\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$\015\012\015\012$ Step #5: artifact_prefix='./'; Test unit written to ./oom-19cc627a3bc3b3f305a8448b6822755534b019e1 Step #5: Base64: Kg0KKjY4DQokDQoNCiQNCg0KJA0KDQokDQoNCiQNCg0KJA0KDQokDQoNCiQNCg0KJA0KDQokDQoNCiQNCg0KJA0KDQokDQoNCiQNCg0KJA0KDQokDQoNCiQNCg0KJA0KDQokDQoNCiQNCg0KJA0KDQokDQoNCiQNCg0KJA0KDQokDQoNCiQNCg0KJA0KDQokDQoNCiQNCg0KJA0KDQokDQoNCiQNCg0KJA0KDQokDQoNCiQNCg0KJA0KDQokDQoNCiQNCg0KJA0KDQokDQoNCiQNCg0KJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4948 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4226821682 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1708f8810, 0x55a170ae201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a170ae2020,0x55a17297a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/19cc627a3bc3b3f305a8448b6822755534b019e1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6247 processed earlier; will process 4782 files now Step #5: ==178204== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1673ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a16da52898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a16da355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a16da354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1673f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a167354b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a16734f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1673e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a16a3b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a16a3b4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a16a3b4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a16a3b4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a16a3b4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a16a3b4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a16a3b4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a16a3b4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a16a3b4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a16a3b4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a16c649f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a169376b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a169381be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a16912dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a16912dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a16912e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a16912d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a16912d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a16912d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a16da37abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a16da40928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a16da28699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a16da53112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f30cec2f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a16734db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x3e,0x0,0x41,0x38,0x60,0x5b,0x2e,0x2e,0x38,0x36,0x34,0x32,0x30,0x30,0x30,0x31,0x31,0x5d,0x2d,0x60,0x33,0xef,0xbf,0xbf,0x1,0x0,0x75,0x2,0x63,0x1e,0xd9,0x80,0xdd,0xa4,0x60,0x5b,0x21,0x30,0x2d,0x33,0x5d,0x2d,0x60,0xe0,0xbf,0xbf,0xd5,0xad,0x21,0x60,0x5b,0x31,0x26,0x31,0x32,0x35,0x5d,0x2d,0x60,0x7a,0x2d,0xef,0xbf,0xbf,0x1,0x0,0x75,0x2,0x63,0x1e,0xd9,0x80,0xdd,0xa4,0x60,0x5b,0x21,0x30,0x2d,0x33,0x5d,0x2d,0x60,0xe0,0xbf,0xbf,0xd5,0xad,0x21,0x60,0x5b,0x31,0x26,0x31,0x32,0x35,0x5d,0x2d,0x60,0x7a,0x2d,0xef,0xbf,0xbf,0x1,0x0,0x75,0x2,0x63,0x1e,0xd9,0x80,0xdd,0xa4,0x60,0x5b,0x21,0x30,0x2d,0x33,0x5d,0x2d,0x60,0xe0,0xbf,0xbf,0xd5,0xad,0x21,0x60,0x5b,0x31,0x26,0x31,0x32,0x35,0x5d,0x2d,0x60,0x7a,0x2d,0xef,0xbf,0xbf,0xd5,0xa4,0x21,0x2,0x0,0x0,0x0,0x60,0x5b,0x36,0x2d,0x33,0x5d,0xa4,0xef,0x26,0xfe,0x90,0x74,0x28,0x78,0x29,0x3b,0xa,0xa,0x28,0x70,0x74,0x69,0xa,0x6e,0x72,0x2d,0x32,0x31,0x29,0x3b,0x8a,0xa,0x70,0x72,0x69,0x6e,0x74,0x28,0x78,0x29,0x3b,0xa,0xa,0x6c,0x65,0x74,0x20,0x78,0x20,0x3d,0xa,0xa,0x6e,0xa,0x70,0x72,0x3c,0x92,0x0,0xc0,0x99,0xba, Step #5: `>\000A8`[..864200011]-`3\357\277\277\001\000u\002c\036\331\200\335\244`[!0-3]-`\340\277\277\325\255!`[1&125]-`z-\357\277\277\001\000u\002c\036\331\200\335\244`[!0-3]-`\340\277\277\325\255!`[1&125]-`z-\357\277\277\001\000u\002c\036\331\200\335\244`[!0-3]-`\340\277\277\325\255!`[1&125]-`z-\357\277\277\325\244!\002\000\000\000`[6-3]\244\357&\376\220t(x);\012\012(pti\012nr-21);\212\012print(x);\012\012let x =\012\012n\012pr<\222\000\300\231\272 Step #5: artifact_prefix='./'; Test unit written to ./oom-73725873481617e356ed47e319d688aa4b662deb Step #5: Base64: YD4AQThgWy4uODY0MjAwMDExXS1gM++/vwEAdQJjHtmA3aRgWyEwLTNdLWDgv7/VrSFgWzEmMTI1XS1gei3vv78BAHUCYx7ZgN2kYFshMC0zXS1g4L+/1a0hYFsxJjEyNV0tYHot77+/AQB1AmMe2YDdpGBbITAtM10tYOC/v9WtIWBbMSYxMjVdLWB6Le+/v9WkIQIAAABgWzYtM12k7yb+kHQoeCk7CgoocHRpCm5yLTIxKTuKCnByaW50KHgpOwoKbGV0IHggPQoKbgpwcjySAMCZug== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4949 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4227474763 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5605b3929810, 0x5605b3b1301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5605b3b13020,0x5605b59ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/73725873481617e356ed47e319d688aa4b662deb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6248 processed earlier; will process 4781 files now Step #5: ==178240== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5605aa41e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605b0a83898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605b0a665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605b0a664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5605aa424d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605aa385b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5605aa380355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5605aa416c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605ad3e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605ad3e5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605ad3e5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605ad3e5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605ad3e5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605ad3e5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605ad3e5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605ad3e5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605ad3e5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605ad3e5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605af67af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5605ac3a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5605ac3b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5605ac15ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5605ac15ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5605ac15f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5605ac15e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5605ac15e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5605ac15e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605b0a68abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5605b0a71928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605b0a59699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605b0a84112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95e6dec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5605aa37eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xef,0xbb,0xbf,0x3c,0x46,0x6e,0x4e,0x3e,0x3c,0xe8,0x87,0x8d,0x32,0x3e,0x3c,0xe8,0x87,0x8d,0x3e,0x3e,0x3c,0x5f,0x3e,0x3e,0x3c,0xe8,0x87,0xb9,0x74,0x3e,0x4e,0x3e,0x3c,0xe8,0x87,0x8d,0x32,0x3e,0x3c,0xe8,0x87,0x8d,0x3e,0x3c,0x6e,0x3e,0x3c,0x5f,0x3e,0x3e,0x3c,0xe8,0x87,0xb9,0x74,0x3e,0x50,0x3c,0x50,0x4e,0x50,0x3e,0x3c,0xe8,0x87,0x8d,0x31,0x3e,0x74,0x3c,0x50,0x4e,0x4e,0x3e,0x3c,0x50,0x50,0x4e,0x4e,0x3e,0x3c,0xe8,0x87,0x8d,0x32,0x3e,0x3c,0xe8,0x87,0x8d,0x3e,0x3c,0x6e,0x3e,0x3c,0x5f,0x3e,0x3e,0x3c,0xe8,0x87,0xb9,0x74,0x3e,0x50,0x3c,0x50,0x4e,0x50,0x3e,0x3c,0xe8,0x87,0x8d,0x30,0x3e,0x3c,0xe8,0x87,0x8d,0x32,0x3e,0x3c,0xe8,0x87,0x8d,0x3e,0x3c,0xe8,0x87,0x8d,0x32,0x3e,0x3c,0xe8,0x87,0x8d,0x3e,0x3c,0x6e,0x3e,0x3c,0x5f,0x3e,0x3e,0x3c,0xe8,0x87,0xb9,0x3e,0x3c,0xe8,0x87,0x8d,0x30,0x3e,0x74,0x3c,0x50,0x4e,0x4e,0x3e,0x3c,0x50,0x3e,0x3c,0xe8,0x87,0x8d,0x32,0x3e,0x3c,0xe8,0x87,0x8d,0x3e,0x3c,0x6e,0x3e,0x3c,0x5f,0x3e,0x3e,0x3c,0xe8,0x87,0xb9,0x74,0x3e,0x50,0x50,0x3e,0x3c,0xe8,0x87,0x8d,0x31,0x3e,0x74,0x3c,0x50,0x3e,0x3c,0xe8,0x87,0x8d,0x31,0x3e,0xe8,0x87,0xb9,0x74,0x3e,0x4e, Step #5: \357\273\277<FnN><\350\207\2152><\350\207\215>><_>><\350\207\271t>N><\350\207\2152><\350\207\215><n><_>><\350\207\271t>P<PNP><\350\207\2151>t<PNN><PPNN><\350\207\2152><\350\207\215><n><_>><\350\207\271t>P<PNP><\350\207\2150><\350\207\2152><\350\207\215><\350\207\2152><\350\207\215><n><_>><\350\207\271><\350\207\2150>t<PNN><P><\350\207\2152><\350\207\215><n><_>><\350\207\271t>PP><\350\207\2151>t<P><\350\207\2151>\350\207\271t>N Step #5: artifact_prefix='./'; Test unit written to ./oom-3c2206b850418125566e2d075a1357a8d698737c Step #5: Base64: 77u/PEZuTj486IeNMj486IeNPj48Xz4+POiHuXQ+Tj486IeNMj486IeNPjxuPjxfPj486Ie5dD5QPFBOUD486IeNMT50PFBOTj48UFBOTj486IeNMj486IeNPjxuPjxfPj486Ie5dD5QPFBOUD486IeNMD486IeNMj486IeNPjzoh40yPjzoh40+PG4+PF8+Pjzoh7k+POiHjTA+dDxQTk4+PFA+POiHjTI+POiHjT48bj48Xz4+POiHuXQ+UFA+POiHjTE+dDxQPjzoh40xPuiHuXQ+Tg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4950 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4228002876 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564b17864810, 0x564b17a4e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564b17a4e020,0x564b198e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3c2206b850418125566e2d075a1357a8d698737c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6249 processed earlier; will process 4780 files now Step #5: ==178276== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564b0e3599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564b149be898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564b149a15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564b149a14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564b0e35fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564b0e2c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564b0e2bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564b0e351c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564b11320f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564b11320f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564b11320f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564b11320f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564b11320f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564b11320f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564b11320f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564b11320f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564b11320f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564b11320f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564b135b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564b102e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564b102edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564b10099c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564b10099c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564b1009a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564b10099874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564b10099874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564b10099874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564b149a3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564b149ac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564b14994699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564b149bf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe93e84a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564b0e2b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xa,0x0,0x0,0x59,0x3e,0x30,0x2b,0x34,0x27,0x73,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0xa5,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x5f,0x2,0x74,0x72,0x65,0x0,0x59,0x3e,0x30,0x2b,0x34,0x27,0x0,0x3a,0xd8,0x80,0x4,0x2b,0x0, Step #5: \000\012\000\000Y>0+4's\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U\245`___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000_\002tre\000Y>0+4'\000:\330\200\004+\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-618528e5e8bafedae80a6f324847c6537ad72492 Step #5: Base64: AAoAAFk+MCs0J3MBdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VpWBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAAl9fX19VYGBfX18BdGAAXwJ0cmUAWT4wKzQnADrYgAQrAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4951 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4228650974 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c06981810, 0x562c06b6b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c06b6b020,0x562c08a030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/618528e5e8bafedae80a6f324847c6537ad72492' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6250 processed earlier; will process 4779 files now Step #5: #1 pulse cov: 11374 ft: 11375 exec/s: 0 rss: 194Mb Step #5: ==178312== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562bfd4769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c03adb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c03abe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c03abe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562bfd47cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562bfd3ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562bfd3d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562bfd46ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c0043df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c0043df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c0043df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c0043df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c0043df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c0043df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c0043df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c0043df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c0043df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c0043df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c026d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562bff3ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562bff40abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562bff1b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562bff1b6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562bff1b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562bff1b6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562bff1b6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562bff1b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c03ac0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c03ac9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c03ab1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c03adc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc43d255082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562bfd3d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x16,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xc3,0xc0,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa, Step #5: ====================\026==============\012=========================================\012=======================================\012========\303\300===============================\012======================================================\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-28378368d1b2a50bd21403facc0b34f3d1f1fbc3 Step #5: Base64: PT09PT09PT09PT09PT09PT09PT0WPT09PT09PT09PT09PT0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Cj09PT09PT09w8A9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Cj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4952 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4229249236 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab31552810, 0x55ab3173c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab3173c020,0x55ab335d40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/28378368d1b2a50bd21403facc0b34f3d1f1fbc3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6252 processed earlier; will process 4777 files now Step #5: ==178348== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ab280479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab2e6ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab2e68f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab2e68f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab2804dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab27faeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab27fa9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab2803fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab2b00ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab2b00ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab2b00ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab2b00ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab2b00ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab2b00ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab2b00ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab2b00ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab2b00ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab2b00ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab2d2a3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab29fd0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab29fdbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab29d87c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab29d87c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab29d88738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab29d87874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab29d87874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab29d87874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab2e691abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab2e69a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab2e682699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab2e6ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa9007d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab27fa7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0xa,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x3a,0x65,0xa,0x2d,0x3f,0x41,0x73,0x63,0x65,0x7a,0x74,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x7a,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x74,0x20,0x6a,0x2d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: 0\012=\314\273A---Asc:e\012-?Ascezt\005-----BEGIN -----\012N\012=\012=\012=\012=\012=z\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012t j-=\012=\012=\012\012=\012=\012=\012\012==\012=\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-63adfb311f59688b7793afe0492cc1a374202c6b Step #5: Base64: MAo9zLtBLS0tQXNjOmUKLT9Bc2NlenQFLS0tLS1CRUdJTiAtLS0tLQpOCj0KPQo9Cj0KPXoKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KdCBqLT0KPQo9Cgo9Cj0KPQoKPT0KPQo9PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9AAo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9ChA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4953 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4229805570 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b10744c810, 0x55b10763601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b107636020,0x55b1094ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/63adfb311f59688b7793afe0492cc1a374202c6b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6253 processed earlier; will process 4776 files now Step #5: ==178384== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b0fdf419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b1045a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1045895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1045894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0fdf47d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0fdea8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0fdea3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0fdf39c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b100f08f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b100f08f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b100f08f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b100f08f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b100f08f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b100f08f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b100f08f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b100f08f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b100f08f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b100f08f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b10319df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b0ffecab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b0ffed5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b0ffc81c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b0ffc81c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b0ffc82738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b0ffc81874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b0ffc81874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b0ffc81874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b10458babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b104594928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b10457c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b1045a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8c18801082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0fdea1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1,0xa,0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1,0xa,0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1,0xa,0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1,0xa,0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1,0xa,0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1,0xa,0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1,0xa,0xb,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xef,0xb7,0xba,0xf0,0x96,0xac,0xb1, Step #5: \013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261\012\013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261\012\013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261\012\013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261\012\013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261\012\013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261\012\013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261\012\013\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\357\267\272\360\226\254\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-a270da6c7340036e8fe1bb33ccc005df802ddcce Step #5: Base64: C++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLEKC++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLEKC++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLEKC++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLEKC++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLEKC++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLEKC++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLEKC++3uu+3uu+3uu+3uu+3uu+3uu+3uvCWrLE= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4954 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4230340333 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55841d46a810, 0x55841d65401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55841d654020,0x55841f4ec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a270da6c7340036e8fe1bb33ccc005df802ddcce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6254 processed earlier; will process 4775 files now Step #5: ==178420== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558413f5f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55841a5c4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55841a5a75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55841a5a74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558413f65d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558413ec6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558413ec1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558413f57c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558416f26f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558416f26f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558416f26f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558416f26f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558416f26f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558416f26f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558416f26f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558416f26f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558416f26f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558416f26f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5584191bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558415ee8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558415ef3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558415c9fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558415c9fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558415ca0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558415c9f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558415c9f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558415c9f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55841a5a9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55841a5b2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55841a59a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55841a5c5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5709087082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558413ebfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0x66,0x0,0x3a,0x78,0x2d,0x2d,0x2d,0x2d,0x47,0x42,0x0,0x5,0x0,0x45,0x2d,0x0,0x49,0x4e,0x20,0x31,0x38,0x34,0x34,0x36,0x37,0x34,0x34,0x30,0x37,0x33,0x37,0x30,0x39,0x35,0x35,0x31,0x36,0x31,0x35,0x2d,0x2d,0x2d,0x2d,0x47,0x42,0x0,0x5,0x0,0x45,0x2d,0x0,0x49,0x4e,0x20,0x31,0x38,0x34,0x34,0x36,0x37,0x34,0x34,0x30,0x37,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x2d,0x2d,0x31,0x2d,0x2d,0x67,0x6c,0x79,0x66,0x0,0x3a,0xdc,0x81,0x0,0x0,0x0,0x0,0x0,0x65,0x1,0x47,0xb, Step #5: Cf\000:x----GB\000\005\000E-\000IN 18446744073709551615----GB\000\005\000E-\000IN 1844674407aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa--1--glyf\000:\334\201\000\000\000\000\000e\001G\013 Step #5: artifact_prefix='./'; Test unit written to ./oom-d873bcfaf9fe3fef76bd17da26ede4c3871295d4 Step #5: Base64: Q2YAOngtLS0tR0IABQBFLQBJTiAxODQ0Njc0NDA3MzcwOTU1MTYxNS0tLS1HQgAFAEUtAElOIDE4NDQ2NzQ0MDdhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYS0tMS0tZ2x5ZgA63IEAAAAAAGUBRws= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4955 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4230873508 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b813192810, 0x55b81337c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b81337c020,0x55b8152140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d873bcfaf9fe3fef76bd17da26ede4c3871295d4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6255 processed earlier; will process 4774 files now Step #5: ==178456== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b809c879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b8102ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b8102cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b8102cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b809c8dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b809beeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b809be9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b809c7fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b80cc4ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b80cc4ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b80cc4ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b80cc4ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b80cc4ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b80cc4ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b80cc4ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b80cc4ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b80cc4ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b80cc4ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b80eee3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b80bc10b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b80bc1bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b80b9c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b80b9c7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b80b9c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b80b9c7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b80b9c7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b80b9c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b8102d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b8102da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b8102c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b8102ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f400413f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b809be7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x30,0x4d,0x46,0x65,0x57,0x48,0x77,0x42,0x63,0x6f,0x61,0x61,0x71,0x59,0x70,0x2b,0x6a,0x6d,0x47,0x4c,0x6c,0x43,0x41,0x41,0x42,0x73,0x54,0x53,0x2b,0x58,0x4e,0x49,0x6a,0x75,0x56,0x7a,0x53,0x77,0x6f,0x30,0x54,0x45,0xa,0x66,0x61,0x6d,0x69,0x6c,0x79,0x20,0x39,0x30,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x10,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x31,0x34,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x33, Step #5: onion-key\012ntor-onion-key v0MFeWHwBcoaaqYp+jmGLlCAABsTS+XNIjuVzSwo0TE\012family 902222222\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\020\0202222222222222142222222222222223 Step #5: artifact_prefix='./'; Test unit written to ./oom-7e2a169b439f923d4079c279455b2a56cc3b5c17 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHYwTUZlV0h3QmNvYWFxWXAram1HTGxDQUFCc1RTK1hOSWp1VnpTd28wVEUKZmFtaWx5IDkwMjIyMjIyMhAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEDIyMjIyMjIyMjIyMjIxNDIyMjIyMjIyMjIyMjIyMjM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4956 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4231403902 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55723f8ee810, 0x55723fad801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55723fad8020,0x5572419700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7e2a169b439f923d4079c279455b2a56cc3b5c17' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6256 processed earlier; will process 4773 files now Step #5: ==178492== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5572363e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55723ca48898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55723ca2b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55723ca2b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5572363e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55723634ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557236345355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5572363dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5572393aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5572393aaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5572393aaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5572393aaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5572393aaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5572393aaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5572393aaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5572393aaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5572393aaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5572393aaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55723b63ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55723836cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557238377be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557238123c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557238123c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557238124738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557238123874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557238123874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557238123874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55723ca2dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55723ca36928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55723ca1e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55723ca49112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe75de94082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557236343b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x25,0x0,0x3d,0x2,0x4,0x1,0x43,0x48,0x41,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0xe2,0x80,0xae,0x0,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0,0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4e,0x20,0x2d,0x2d,0x2d,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x6f,0x0,0xa,0x2d,0x2d,0x45,0x4e,0x2d,0x2d,0x2d,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: ID3\002%\000=\002\004\001CHA\000\000\021\000\000\000\000\000\000\000\000\000\000\000\342\200\256\000\000\000CHA\000\000\021\000\000\000\000\000\000\000\000\002\000\000\342\200\256\000\000\000CHA\000\000\021\000\000\000\000\000x-----BEGI\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000x-----BEGI\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000N ---oooooooooooooooooo\000\012--EN---D ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-ffc07047b43bcdf51090c83078d2adb3f50b6bf1 Step #5: Base64: SUQzAiUAPQIEAUNIQQAAEQAAAAAAAAAAAAAA4oCuAAAAQ0hBAAARAAAAAAAAAAACAADigK4AAABDSEEAABEAAAAAAHgtLS0tLUJFR0kAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHgtLS0tLUJFR0kAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABOIC0tLW9vb29vb29vb29vb29vb29vbwAKLS1FTi0tLUQgLS0tLS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4957 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4231950907 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5621ec253810, 0x5621ec43d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5621ec43d020,0x5621ee2d50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ffc07047b43bcdf51090c83078d2adb3f50b6bf1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6257 processed earlier; will process 4772 files now Step #5: ==178528== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5621e2d489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5621e93ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5621e93905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5621e93904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5621e2d4ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5621e2cafb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5621e2caa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5621e2d40c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5621e5d0ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5621e5d0ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5621e5d0ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5621e5d0ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5621e5d0ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5621e5d0ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5621e5d0ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5621e5d0ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5621e5d0ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5621e5d0ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5621e7fa4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5621e4cd1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5621e4cdcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5621e4a88c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5621e4a88c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5621e4a89738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5621e4a88874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5621e4a88874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5621e4a88874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5621e9392abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5621e939b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5621e9383699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5621e93ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8de5959082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5621e2ca8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0xa,0x60,0x20,0x1e,0x60,0x41,0x4c,0x49,0x41,0x53,0x5b,0x31,0x32,0x38,0x2c,0x31,0x38,0x34,0x30,0x37,0x33,0x37,0x30,0x34,0x36,0x37,0x35,0x38,0x30,0x38,0x2c,0x30,0x41,0x28,0x28,0x45,0x58,0x50,0x4c,0x41,0x49,0x4e,0x20,0x65,0x75,0x6c,0x33,0x32,0x54,0x54,0x54,0x61,0x6d,0x5f,0x54,0x54,0x54,0x54,0x54,0x39,0x70,0x3d,0x33,0x31,0x2c,0x70,0x2e,0x38,0x36,0x61,0x72,0x61,0x6d,0x5f,0x33,0x32,0x59,0x37,0x70,0x3d,0x31,0x2c,0x70,0x61,0x72,0x61,0x6d,0x5f,0x33,0x32,0x54,0x54,0x54,0x54,0x54,0x54,0x6d,0x5f,0x54,0x54,0x54,0x54,0x54,0x39,0x70,0x3d,0x33,0x31,0x2e,0x36,0x38,0x2c,0x70,0x61,0x72,0x61,0x6d,0x5f,0x33,0x32,0x59,0x37,0x70,0x3d,0x31,0x2c,0x70,0x61,0x72,0x61,0x6d,0x5f,0x33,0x32,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x6d,0x5f,0x30,0x54,0x3d,0x5b,0x32,0x2c,0x34,0x32,0x39,0x35,0x30,0x30,0x30,0x33,0x31,0x39,0x5d,0x2c,0x34,0x39,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd3,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0xd6,0xd7,0xd7,0xd7,0xd7,0xd7,0xd7,0x32,0x39,0x34,0x5d,0xa, Step #5: :\012` \036`ALIAS[128,184073704675808,0A((EXPLAIN eul32TTTam_TTTTT9p=31,p.86aram_32Y7p=1,param_32TTTTTTm_TTTTT9p=31.68,param_32Y7p=1,param_32TTTTTTTm_0T=[2,4295000319],49\327\327\327\327\327\327\323\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\327\326\327\327\327\327\327\327294]\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-4a25b7e6c9e2959393904b0c35f4c4f8d0a45f5b Step #5: Base64: OgpgIB5gQUxJQVNbMTI4LDE4NDA3MzcwNDY3NTgwOCwwQSgoRVhQTEFJTiBldWwzMlRUVGFtX1RUVFRUOXA9MzEscC44NmFyYW1fMzJZN3A9MSxwYXJhbV8zMlRUVFRUVG1fVFRUVFQ5cD0zMS42OCxwYXJhbV8zMlk3cD0xLHBhcmFtXzMyVFRUVFRUVG1fMFQ9WzIsNDI5NTAwMDMxOV0sNDnX19fX19fT19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fW19fX19fXMjk0XQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4958 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4232616140 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db9c349810, 0x55db9c53301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db9c533020,0x55db9e3cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4a25b7e6c9e2959393904b0c35f4c4f8d0a45f5b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6258 processed earlier; will process 4771 files now Step #5: ==178564== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db92e3e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db994a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db994865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db994864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db92e44d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db92da5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db92da0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db92e36c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db95e05f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db95e05f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db95e05f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db95e05f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db95e05f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db95e05f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db95e05f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db95e05f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db95e05f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db95e05f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db9809af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db94dc7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db94dd2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db94b7ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db94b7ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db94b7f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db94b7e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db94b7e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db94b7e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db99488abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db99491928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db99479699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db994a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f23b0c57082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db92d9eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x16,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa, Step #5: ====================\026==============\012=========================================\012=======================================\012=========================================\012======================================================\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ed67249b383b51d7ade0d0611d94642f4a0b533 Step #5: Base64: PT09PT09PT09PT09PT09PT09PT0WPT09PT09PT09PT09PT0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Cj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Cj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4959 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4233146808 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5574a182f810, 0x5574a1a1901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5574a1a19020,0x5574a38b10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ed67249b383b51d7ade0d0611d94642f4a0b533' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6259 processed earlier; will process 4770 files now Step #5: ==178600== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5574983249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55749e989898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55749e96c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55749e96c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55749832ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55749828bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557498286355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55749831cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55749b2ebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55749b2ebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55749b2ebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55749b2ebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55749b2ebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55749b2ebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55749b2ebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55749b2ebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55749b2ebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55749b2ebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55749d580f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55749a2adb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55749a2b8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55749a064c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55749a064c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55749a065738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55749a064874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55749a064874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55749a064874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55749e96eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55749e977928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55749e95f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55749e98a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f98b7b94082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557498284b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xa, Step #5: ===================================\012=========================================\012==============================================================\012=========================================\012================================\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-a927d74d06bd6cf6b781113d90009d663d2986f2 Step #5: Base64: PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4960 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4233667811 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56263c6bc810, 0x56263c8a601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56263c8a6020,0x56263e73e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a927d74d06bd6cf6b781113d90009d663d2986f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6260 processed earlier; will process 4769 files now Step #5: ==178636== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5626331b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562639816898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5626397f95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5626397f94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5626331b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562633118b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562633113355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5626331a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562636178f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562636178f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562636178f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562636178f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562636178f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562636178f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562636178f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562636178f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562636178f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562636178f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56263840df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56263513ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562635145be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562634ef1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562634ef1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562634ef2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562634ef1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562634ef1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562634ef1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5626397fbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562639804928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5626397ec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562639817112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3b5be7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562633111b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4e,0x41,0xa,0x49,0x32,0x9,0x44,0x45,0x46,0x41,0x55,0x4c,0x54,0x28,0x53,0x45,0x4c,0x45,0x43,0x54,0x20,0x20,0x2d,0x36,0x32,0x30,0x38,0x7a,0x37,0x65,0x2d,0x61,0x65,0x73,0x5f,0x65,0x6e,0x63,0x72,0x79,0x70,0x74,0x5f,0x6d,0x79,0x73,0x71,0x6c,0x28,0x34,0x39,0x35,0x38,0x39,0x35,0x37,0x33,0x37,0x36,0x2e,0x2d,0x39,0x39,0x39,0x31,0x32,0x45,0x43,0x54,0x20,0x20,0x2d,0x36,0x32,0x30,0x38,0x7a,0x37,0x65,0x2d,0x61,0x65,0x73,0x5f,0x65,0x6e,0x63,0x72,0x79,0x70,0x74,0x5f,0x6d,0x79,0x73,0x71,0x6c,0x28,0x34,0x39,0x35,0x38,0x39,0x35,0x37,0x33,0x37,0x36,0x2e,0x2d,0x39,0x39,0x39,0x31,0x32,0x36,0x67,0x61,0x74,0x75,0x31,0x2e,0x2a,0x41,0x50,0x50,0x4c,0x59,0x20,0x63,0x6f,0x75,0x6c,0x6d,0x35,0x30,0x7a,0x3e,0x6a,0x35,0x2d,0x34,0x36,0x34,0x38,0x29,0xb,0x2f,0x58,0x2d,0x72,0x2d,0x36,0x67,0x61,0x74,0x75,0x31,0x2e,0x2a,0x41,0x50,0x50,0x4c,0x59,0x20,0x63,0x6f,0x75,0x6c,0x6d,0x35,0x30,0x7a,0x3e,0x6a,0x35,0x2d,0x34,0x36,0x34,0x38,0x29,0xb,0x2f,0x58,0x2d,0x72,0x2d,0x6f,0x77,0x72,0x7a,0x72,0x32,0x30,0x35,0x35,0x34,0x2d,0x3e,0x6a,0x33,0x29,0xb,0x2f,0x58,0x77,0x72,0x7a,0x72,0x32,0x30,0x35,0x35,0xa, Step #5: NA\012I2\011DEFAULT(SELECT -6208z7e-aes_encrypt_mysql(4958957376.-99912ECT -6208z7e-aes_encrypt_mysql(4958957376.-999126gatu1.*APPLY coulm50z>j5-4648)\013/X-r-6gatu1.*APPLY coulm50z>j5-4648)\013/X-r-owrzr20554->j3)\013/Xwrzr2055\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-57ec6d67347cea71177d719de692e67389919f9c Step #5: Base64: TkEKSTIJREVGQVVMVChTRUxFQ1QgIC02MjA4ejdlLWFlc19lbmNyeXB0X215c3FsKDQ5NTg5NTczNzYuLTk5OTEyRUNUICAtNjIwOHo3ZS1hZXNfZW5jcnlwdF9teXNxbCg0OTU4OTU3Mzc2Li05OTkxMjZnYXR1MS4qQVBQTFkgY291bG01MHo+ajUtNDY0OCkLL1gtci02Z2F0dTEuKkFQUExZIGNvdWxtNTB6Pmo1LTQ2NDgpCy9YLXItb3dyenIyMDU1NC0+ajMpCy9Yd3J6cjIwNTUK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4961 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4234202204 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a99ab31810, 0x55a99ad1b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a99ad1b020,0x55a99cbb30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/57ec6d67347cea71177d719de692e67389919f9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6261 processed earlier; will process 4768 files now Step #5: #1 pulse cov: 3495 ft: 3496 exec/s: 0 rss: 175Mb Step #5: ==178672== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a9916269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a997c8b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a997c6e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a997c6e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a99162cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a99158db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a991588355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a99161ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9945edf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9945edf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9945edf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9945edf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9945edf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9945edf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9945edf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9945edf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9945edf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9945edf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a996882f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a9935afb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a9935babe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a993366c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a993366c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a993367738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a993366874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a993366874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a993366874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a997c70abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a997c79928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a997c61699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a997c8c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb1afadb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a991586b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x4a,0x2e,0x9,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x36,0xa,0x7d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x5c,0xa,0x5c,0x9,0x29,0xa,0x5c,0x9,0xa4,0xa,0x5c,0x9,0x60,0x40,0x60,0xff,0x68,0x9,0x60,0x40,0x60,0x40, Step #5: +J.\011\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012-\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012-\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\0126\012}\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\\\012\\\011)\012\\\011\244\012\\\011`@`\377h\011`@`@ Step #5: artifact_prefix='./'; Test unit written to ./oom-fcb9736edb5821465b1a8b39f9369045f8d5058c Step #5: Base64: K0ouCQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KLQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQotCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KCj0KPQo9CjYKfQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQpcClwJKQpcCaQKXAlgQGD/aAlgQGBA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4962 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4234802231 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca0c9cf810, 0x55ca0cbb901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca0cbb9020,0x55ca0ea510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fcb9736edb5821465b1a8b39f9369045f8d5058c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6263 processed earlier; will process 4766 files now Step #5: #1 pulse cov: 10938 ft: 10939 exec/s: 0 rss: 193Mb Step #5: ==178708== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ca034c49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca09b29898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca09b0c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca09b0c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca034cad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca0342bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca03426355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca034bcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca0648bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca0648bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca0648bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca0648bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca0648bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca0648bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca0648bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca0648bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca0648bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca0648bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca08720f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca0544db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca05458be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca05204c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca05204c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca05205738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca05204874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca05204874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca05204874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca09b0eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca09b17928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca09aff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca09b2a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff124082082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca03424b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x1d,0x0,0x17,0x0,0x2,0x1c,0x25,0x30,0x0,0x1f,0x32,0x0,0x0,0x30,0x1,0x3,0x18,0x8,0x34,0x3d,0x0,0x29,0x30,0x5,0x1d,0x2,0xc,0x1,0x6,0x29,0x29,0x20,0x5,0x15,0x9,0xa,0x11,0x1,0x1e,0x25,0x3d,0x32,0x30,0x20,0x21,0x1,0x26,0x32,0xc,0x32,0x24,0x1d,0x3b,0x8,0x26,0x4,0x0,0x27,0x3b,0x2c,0x8,0x0,0x2c,0x26,0x29,0x13,0x11,0x2e,0x2e,0x19,0xa,0x0,0x18,0x3,0x22,0x1d,0x1d,0x3,0x29,0x3,0x15,0x0,0xc,0x8,0xf,0x0,0x1c,0x5,0x1f,0x15,0x0,0x26,0x31,0x34,0x35,0x33,0x34,0x30,0x35,0x10,0x3,0x1,0xf,0x4,0x15,0x4,0x34,0x4,0x13,0x35,0x10,0x11,0xf,0x2c,0x5,0xf,0x11,0x10,0x19,0x27,0x26,0x2c,0x2e,0x16,0x34,0x1f,0x24,0xe,0x1c,0x34,0x15,0x1f,0x4,0x17,0x18,0x22,0x29,0xa,0x9,0xc,0x11,0x4,0x32,0x19,0x27,0x26,0x2c,0x2e,0x16,0x30,0x21,0x24,0xe,0x1c,0x31,0x3b,0x1f,0x4,0x17,0x18,0x22,0x29,0xa,0x1,0x29,0x3b,0x32,0x2f,0x20,0x21,0x34,0xb,0x34,0x24,0x1d,0x3b,0x8,0x2c,0x3,0x30,0x19,0x26,0x27,0x5,0x0,0x3b,0x2c,0x3,0x25,0x0,0x0,0x8,0x0,0x6,0x32,0x1e,0xa,0x7,0x13,0x34,0x3d,0x8,0x29,0x10,0x1c,0x6,0x5,0x1d,0x2,0xc,0x1,0x27,0x3b,0x9,0x24,0x3f, Step #5: \002\035\000\027\000\002\034%0\000\0372\000\0000\001\003\030\0104=\000)0\005\035\002\014\001\006)) \005\025\011\012\021\001\036%=20 !\001&2\0142$\035;\010&\004\000';,\010\000,&)\023\021..\031\012\000\030\003\"\035\035\003)\003\025\000\014\010\017\000\034\005\037\025\000&1453405\020\003\001\017\004\025\0044\004\0235\020\021\017,\005\017\021\020\031'&,.\0264\037$\016\0344\025\037\004\027\030\")\012\011\014\021\0042\031'&,.\0260!$\016\0341;\037\004\027\030\")\012\001);2/ !4\0134$\035;\010,\0030\031&'\005\000;,\003%\000\000\010\000\0062\036\012\007\0234=\010)\020\034\006\005\035\002\014\001';\011$? Step #5: artifact_prefix='./'; Test unit written to ./oom-8db6c111b2749e8c45636c4345f0bcdb8b93610a Step #5: Base64: Ah0AFwACHCUwAB8yAAAwAQMYCDQ9ACkwBR0CDAEGKSkgBRUJChEBHiU9MjAgIQEmMgwyJB07CCYEACc7LAgALCYpExEuLhkKABgDIh0dAykDFQAMCA8AHAUfFQAmMTQ1MzQwNRADAQ8EFQQ0BBM1EBEPLAUPERAZJyYsLhY0HyQOHDQVHwQXGCIpCgkMEQQyGScmLC4WMCEkDhwxOx8EFxgiKQoBKTsyLyAhNAs0JB07CCwDMBkmJwUAOywDJQAACAAGMh4KBxM0PQgpEBwGBR0CDAEnOwkkPw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4963 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4235408134 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561fdcf09810, 0x561fdd0f301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561fdd0f3020,0x561fdef8b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8db6c111b2749e8c45636c4345f0bcdb8b93610a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6265 processed earlier; will process 4764 files now Step #5: #1 pulse cov: 11433 ft: 11434 exec/s: 0 rss: 196Mb Step #5: ==178744== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561fd39fe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561fda063898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561fda0465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561fda0464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561fd3a04d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561fd3965b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561fd3960355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561fd39f6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561fd69c5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561fd69c5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561fd69c5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561fd69c5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561fd69c5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561fd69c5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561fd69c5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561fd69c5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561fd69c5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561fd69c5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561fd8c5af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561fd5987b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561fd5992be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561fd573ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561fd573ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561fd573f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561fd573e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561fd573e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561fd573e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561fda048abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561fda051928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561fda039699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561fda064112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0a50b48082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561fd395eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x0,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0xff, Step #5: \000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\000FUZZ-TAG\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-7da7175d4f6aa814c4b309fbc2305064f2d626ff Step #5: Base64: AEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFHAEZVWlotVEFH/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4964 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4236048767 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5642d3851810, 0x5642d3a3b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5642d3a3b020,0x5642d58d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7da7175d4f6aa814c4b309fbc2305064f2d626ff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6267 processed earlier; will process 4762 files now Step #5: #1 pulse cov: 3713 ft: 3714 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 3935 ft: 4259 exec/s: 0 rss: 177Mb Step #5: #4 pulse cov: 15989 ft: 17466 exec/s: 0 rss: 201Mb Step #5: ==178780== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5642ca3469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5642d09ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5642d098e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5642d098e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642ca34cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5642ca2adb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5642ca2a8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5642ca33ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5642cd30df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5642cd30df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5642cd30df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5642cd30df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5642cd30df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5642cd30df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5642cd30df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5642cd30df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5642cd30df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5642cd30df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5642cf5a2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5642cc2cfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5642cc2dabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5642cc086c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5642cc086c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5642cc087738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5642cc086874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5642cc086874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5642cc086874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5642d0990abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5642d0999928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5642d0981699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5642d09ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0aa98be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5642ca2a6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0x4f,0x27,0xd1,0xa3,0x27,0x27,0x27,0x45,0x27,0x5c,0xd1,0xa1,0x43,0x52,0x45,0x41,0x54,0x45,0x20,0x49,0x4e,0x44,0x45,0x58,0x20,0x4f,0x63,0x72,0x65,0x61,0x74,0x65,0x64,0x4c,0x4c,0x5c,0x62,0x79,0x70,0x34,0x61,0x61,0xd1,0xa1,0x27,0x27,0x27,0x45,0x27,0x5c,0xd1,0xa1,0x43,0x52,0x45,0x41,0x54,0x45,0x20,0x49,0x4e,0x44,0x45,0x58,0x20,0x4f,0x63,0x72,0x65,0xf,0x74,0x65,0x64,0x4c,0x4c,0x5c,0x62,0x79,0x70,0x35,0x61,0x61,0xda,0xa1,0x27,0x27,0x27,0x45,0x27,0x5c,0xd1,0xa1,0x43,0x52,0x45,0x41,0x54,0x45,0x20,0x49,0x4e,0x44,0x45,0x58,0x20,0x4f,0x63,0x72,0x65,0x61,0x74,0x65,0x64,0x4c,0x4c,0x5c,0x62,0x79,0x70,0x34,0x61,0x61,0xd1,0xa1,0x27,0x27,0x27,0x45,0x27,0x5c,0xd1,0xa1,0x43,0x52,0x45,0x41,0x54,0x45,0x20,0x49,0x4e,0xf3,0xa0,0x81,0x81,0x44,0x31,0x58,0x20,0x4f,0x63,0x72,0x65,0x61,0x74,0x65,0x64,0x4c,0x4c,0x5c,0x62,0x79,0x70,0x34,0x61,0x61,0xd1,0xa1,0x27,0x27,0x27,0x45,0x27,0x5c,0xd1,0xa1,0x43,0x52,0x45,0x41,0x54,0x45,0x20,0x49,0x4e,0x44,0x45,0x58,0x20,0x4f,0x63,0x72,0x65,0x61,0x74,0x65,0x64,0x4c,0x4c,0x5c,0x62,0x79,0x70,0x34,0x61,0x61,0xd1,0xa1,0x27,0x27,0x27,0x45,0x27,0x5c,0xa1,0x41,0x54, Step #5: dO'\321\243'''E'\\\321\241CREATE INDEX OcreatedLL\\byp4aa\321\241'''E'\\\321\241CREATE INDEX Ocre\017tedLL\\byp5aa\332\241'''E'\\\321\241CREATE INDEX OcreatedLL\\byp4aa\321\241'''E'\\\321\241CREATE IN\363\240\201\201D1X OcreatedLL\\byp4aa\321\241'''E'\\\321\241CREATE INDEX OcreatedLL\\byp4aa\321\241'''E'\\\241AT Step #5: artifact_prefix='./'; Test unit written to ./oom-6c1429d23ca4b2bb1201d794f75d92e3a025e26d Step #5: Base64: ZE8n0aMnJydFJ1zRoUNSRUFURSBJTkRFWCBPY3JlYXRlZExMXGJ5cDRhYdGhJycnRSdc0aFDUkVBVEUgSU5ERVggT2NyZQ90ZWRMTFxieXA1YWHaoScnJ0UnXNGhQ1JFQVRFIElOREVYIE9jcmVhdGVkTExcYnlwNGFh0aEnJydFJ1zRoUNSRUFURSBJTvOggYFEMVggT2NyZWF0ZWRMTFxieXA0YWHRoScnJ0UnXNGhQ1JFQVRFIElOREVYIE9jcmVhdGVkTExcYnlwNGFh0aEnJydFJ1yhQVQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4965 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4236770283 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560be9b16810, 0x560be9d0001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560be9d00020,0x560bebb980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6c1429d23ca4b2bb1201d794f75d92e3a025e26d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6272 processed earlier; will process 4757 files now Step #5: #1 pulse cov: 3906 ft: 3907 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4195 ft: 4844 exec/s: 0 rss: 178Mb Step #5: ==178816== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560be060b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560be6c70898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560be6c535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560be6c534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560be0611d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560be0572b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560be056d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560be0603c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560be35d2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560be35d2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560be35d2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560be35d2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560be35d2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560be35d2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560be35d2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560be35d2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560be35d2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560be35d2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560be5867f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560be2594b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560be259fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560be234bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560be234bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560be234c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560be234b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560be234b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560be234b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560be6c55abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560be6c5e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560be6c46699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560be6c71112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe398d78082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560be056bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x2d,0x2d,0x32,0x36,0x30,0x35,0x34,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x1d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x25,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xe,0x3d,0xa,0x3f,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=--26054=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\035\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=%\012=\012=\012=\012=\012\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\016=\012?\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-90d52ff841f652278b4a0aaeb8e94397ca7fd4b6 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPS0tMjYwNTQ9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQodCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cgo9Cj0KPQo9Cj0KPQo9JQo9Cj0KPQo9CgAKPQo9Cj0KPQo9Cj0KPQo9Cj0OPQo/ChA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4966 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4237457007 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a2a6979810, 0x55a2a6b6301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a2a6b63020,0x55a2a89fb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/90d52ff841f652278b4a0aaeb8e94397ca7fd4b6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6276 processed earlier; will process 4753 files now Step #5: #1 pulse cov: 11602 ft: 11603 exec/s: 0 rss: 194Mb Step #5: ==178852== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a29d46e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a2a3ad3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2a3ab65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2a3ab64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a29d474d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a29d3d5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a29d3d0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a29d466c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a2a0435f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a2a0435f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a2a0435f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a2a0435f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a2a0435f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a2a0435f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a2a0435f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a2a0435f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a2a0435f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a2a0435f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a2a26caf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a29f3f7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a29f402be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a29f1aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a29f1aec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a29f1af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a29f1ae874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a29f1ae874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a29f1ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a2a3ab8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a2a3ac1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2a3aa9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a2a3ad4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7b1ff14082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a29d3ceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0xa,0x2d,0x20,0x47,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0xa,0x2d,0x20,0x47,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x30,0xa,0x2d,0x5e,0x2,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5e,0x20,0x0,0x30,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x30,0xa,0x2d,0x5e,0x2,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5e,0x20,0x0,0x30,0x21,0xdc,0xbd,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x21,0xdc,0xbd,0xbd,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x80, Step #5: x-----BEGIN \000\000----BE----BEGIN -----\012\012- G\000\000\000\000\000\000\000-----BEGIN \000\000----BE----BEGIN -----\012\012- G\000\000\000\000\000\000\000\000\000\000\000\000\000 \000\000\000\000\000\000\0120\012-^\002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000^ \0000\000\000\000\000\000\000 \000\000\000\000\000\000\0120\012-^\002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000^ \0000!\334\275\000\000\000\000\000\000\000\000\000\000 \000\000\000\000\000\000\000\000\000\000\000!\334\275\275\000\000\000\000\000\000-----\012-\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-e3681905dedd805c97a0eb2907484ff302bd93e3 Step #5: Base64: eC0tLS0tQkVHSU4gAAAtLS0tQkUtLS0tQkVHSU4gLS0tLS0KCi0gRwAAAAAAAAAtLS0tLUJFR0lOIAAALS0tLUJFLS0tLUJFR0lOIC0tLS0tCgotIEcAAAAAAAAAAAAAAAAAIAAAAAAAAAowCi1eAgAAAAAAAAAAAAAAAAAAAAAAAF4gADAAAAAAAAAgAAAAAAAACjAKLV4CAAAAAAAAAAAAAAAAAAAAAAAAXiAAMCHcvQAAAAAAAAAAAAAgAAAAAAAAAAAAAAAh3L29AAAAAAAALS0tLS0KLYA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4967 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4238059369 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e3da4b9810, 0x55e3da6a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e3da6a3020,0x55e3dc53b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e3681905dedd805c97a0eb2907484ff302bd93e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6278 processed earlier; will process 4751 files now Step #5: ==178888== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e3d0fae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e3d7613898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e3d75f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e3d75f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e3d0fb4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e3d0f15b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e3d0f10355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e3d0fa6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e3d3f75f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e3d3f75f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e3d3f75f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e3d3f75f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e3d3f75f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e3d3f75f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e3d3f75f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e3d3f75f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e3d3f75f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e3d3f75f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e3d620af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e3d2f37b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e3d2f42be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e3d2ceec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e3d2ceec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e3d2cef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e3d2cee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e3d2cee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e3d2cee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e3d75f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e3d7601928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e3d75e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e3d7614112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f877c5aa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e3d0f0eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x50,0x44,0x46,0x2d,0x30,0x2e,0x3b,0x35,0xa,0x31,0x20,0x30,0x20,0x6f,0x62,0x6a,0xa,0x3c,0x3c,0xa,0x20,0x20,0x2f,0x4e,0x20,0x35,0xa,0x20,0x20,0x2f,0x46,0x69,0x72,0x73,0x74,0x20,0x36,0x2f,0x44,0x53,0x7a,0xa,0x3e,0x3e,0xa,0x73,0x74,0x72,0x65,0x61,0x6d,0xa,0x34,0x20,0x30,0xa,0x33,0x20,0x34,0x32,0xa,0x34,0x32,0x30,0x31,0x20,0x35,0x20,0xa,0x32,0x36,0x32,0xa,0x36,0xc,0x2d,0x34,0x35,0x38,0x37,0x36,0x39,0x35,0x20,0x32,0x5b,0x30,0x30,0xa,0x65,0x6e,0x64,0x6f,0x62,0x6a,0xa,0x39,0x20,0x30,0x20,0x6f,0x62,0x6a,0x3c,0x3c,0xa,0x2f,0x54,0x79,0x70,0x65,0x20,0x2f,0x58,0x52,0x65,0x66,0xa,0x2f,0x53,0x69,0x7a,0x65,0x20,0x39,0xa,0x20,0x20,0x20,0x2f,0x57,0x20,0x5b,0x31,0x20,0x32,0x20,0x31,0x5d,0x5b,0x31,0x20,0x32,0x20,0x30,0x5d,0x6f,0x6f,0x74,0x20,0x32,0x20,0x30,0x20,0x52,0xa,0x3e,0x3e,0xa,0x73,0x74,0x72,0x65,0x61,0x6d,0xa,0x30,0x30,0x0,0x0,0x30,0x1,0xf,0x0,0x2,0x0,0x1,0x30,0xa,0x0,0x3,0x31,0x2,0x0,0x30,0x1,0xa,0x0,0x1,0x30,0x2,0xe5,0x1,0x2b,0x1,0x2,0x9,0x2,0x1,0x69,0x0,0xa,0x65,0x6e,0x64,0x73,0x74,0x72,0x65,0x61,0x6d,0xa,0x65,0x6e,0x64,0x6f,0x5b, Step #5: %PDF-0.;5\0121 0 obj\012<<\012 /N 5\012 /First 6/DSz\012>>\012stream\0124 0\0123 42\0124201 5 \012262\0126\014-4587695 2[00\012endobj\0129 0 obj<<\012/Type /XRef\012/Size 9\012 /W [1 2 1][1 2 0]oot 2 0 R\012>>\012stream\01200\000\0000\001\017\000\002\000\0010\012\000\0031\002\0000\001\012\000\0010\002\345\001+\001\002\011\002\001i\000\012endstream\012endo[ Step #5: artifact_prefix='./'; Test unit written to ./oom-370a1196e991fd75b62abdfe4cf9701058468995 Step #5: Base64: JVBERi0wLjs1CjEgMCBvYmoKPDwKICAvTiA1CiAgL0ZpcnN0IDYvRFN6Cj4+CnN0cmVhbQo0IDAKMyA0Mgo0MjAxIDUgCjI2Mgo2DC00NTg3Njk1IDJbMDAKZW5kb2JqCjkgMCBvYmo8PAovVHlwZSAvWFJlZgovU2l6ZSA5CiAgIC9XIFsxIDIgMV1bMSAyIDBdb290IDIgMCBSCj4+CnN0cmVhbQowMAAAMAEPAAIAATAKAAMxAgAwAQoAATAC5QErAQIJAgFpAAplbmRzdHJlYW0KZW5kb1s= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4968 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4238586483 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b3d60e7810, 0x55b3d62d101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b3d62d1020,0x55b3d81690e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/370a1196e991fd75b62abdfe4cf9701058468995' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6279 processed earlier; will process 4750 files now Step #5: ==178924== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b3ccbdc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b3d3241898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b3d32245dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b3d32244fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b3ccbe2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b3ccb43b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b3ccb3e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b3ccbd4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b3cfba3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b3cfba3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b3cfba3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b3cfba3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b3cfba3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b3cfba3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b3cfba3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b3cfba3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b3cfba3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b3cfba3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b3d1e38f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b3ceb65b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b3ceb70be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b3ce91cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b3ce91cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b3ce91d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b3ce91c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b3ce91c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b3ce91c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b3d3226abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b3d322f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b3d3217699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b3d3242112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f10b5754082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b3ccb3cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x7b,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0x20,0x20,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0xc,0x6e,0x61,0x6d,0x65,0x3a,0xd,0x22,0x44,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x27,0x31,0x66,0x27,0x20,0x20,0x20,0x20,0x5c,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x42,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x76,0x7e,0x7e,0x7e,0x7e,0x7e,0x1b,0x2d,0x32,0x32,0x39,0x30,0x7e,0x76,0x3b,0x3a,0x38,0x30,0x37,0x38,0x36,0x37,0x31,0x32,0x34,0x31,0x2f,0x1a,0x78,0x4b,0xae,0xae,0xae,0xad,0x9,0x4b,0x4b,0x78,0x78,0x78,0x78,0x78,0x76,0xd7,0xdd,0x31,0x47,0x6d,0x65,0x3a,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x33,0x30,0x20,0x20,0x5c,0x27,0x20,0x20,0x20,0x3e,0x20,0x5c,0x30,0x30,0x30,0x5c,0x72,0x20,0x20,0x3c,0x42,0x20,0x3e,0x22,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x76,0x61,0x6c,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x22,0x20,0x20,0x20,0x7d,0x20,0x7d,0xa,0x20,0x7d,0x20,0x7d,0xa,0x7d,0x7d, Step #5: p{doctype {\012mdecl { entity {\014name:\015\"D PUBLIC '1f' \\'http://~~~~~~~~~~~~~~~~~~~~B~~~~~~~~~v~~~~~\033-2290~v;:8078671241/\032xK\256\256\256\255\011KKxxxxxv\327\3351Gme: 30 \\' > \\000\\r <B >\"ent {\012 val { name: \"D\" } }\012 } }\012}} Step #5: artifact_prefix='./'; Test unit written to ./oom-161742a0be466c9005b61b481d2e2c5a24e96a01 Step #5: Base64: cHtkb2N0eXBlIHsKbWRlY2wgeyAgZW50aXR5IHsMbmFtZToNIkQgUFVCTElDICcxZicgICAgXCdodHRwOi8vfn5+fn5+fn5+fn5+fn5+fn5+fn5Cfn5+fn5+fn5+dn5+fn5+Gy0yMjkwfnY7OjgwNzg2NzEyNDEvGnhLrq6urQlLS3h4eHh4dtfdMUdtZTogICAgICAgICAgICAgIDMwICBcJyAgID4gXDAwMFxyICA8QiA+ImVudCB7CiAgdmFsIHsgbmFtZTogIkQiICAgfSB9CiB9IH0KfX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4969 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4239120316 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561915efd810, 0x5619160e701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5619160e7020,0x561917f7f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/161742a0be466c9005b61b481d2e2c5a24e96a01' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6280 processed earlier; will process 4749 files now Step #5: ==178960== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56190c9f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561913057898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56191303a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56191303a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56190c9f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56190c959b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56190c954355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56190c9eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56190f9b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56190f9b9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56190f9b9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56190f9b9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56190f9b9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56190f9b9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56190f9b9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56190f9b9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56190f9b9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56190f9b9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561911c4ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56190e97bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56190e986be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56190e732c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56190e732c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56190e733738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56190e732874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56190e732874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56190e732874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56191303cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561913045928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56191302d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561913058112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f337658b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56190c952b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x12,0x31,0x0,0x44,0x0,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x1,0x25,0x44,0x0,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x1,0x44,0x0,0x2,0x55,0x53,0x0,0x21,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x4c,0x54,0x0,0x0,0x0,0x1,0x44,0x0,0x2,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x44,0x33,0x4,0x0,0x27,0x0,0x60,0x27,0x31,0x54,0x59,0x45,0x33,0x4,0x27,0x0,0x0,0x60,0x27,0x54,0x17,0x59,0x45,0x15,0x0,0x10,0x15,0x0,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x1,0x44,0x0,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x1,0x44,0x0,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x1,0x44,0x0,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x1,0x40,0x0,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0xe0,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0xa6,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x44,0x0,0x2,0x55,0x53,0x0,0x2d,0x2d,0x2d,0x2d,0x0,0x0, Step #5: ID3\004\0221\000D\000\002USLT\000\000\000\001%D\000\002USLT\000\000\000\001D\000\002US\000!-----BLT\000\000\000\001D\000\002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000USLT\000\000\000D3\004\000'\000`'1TYE3\004'\000\000`'T\027YE\025\000\020\025\000\002USLT\000\000\000\001D\000\002USLT\000\000\000\001D\000\002USLT\000\000\000\001D\000\002USLT\000\000\000\001@\000\002USLT\000\000\340\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\246\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001D\000\002US\000----\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-991c0cf9de13d4eb774a1daa7e92b46336fd8c23 Step #5: Base64: SUQzBBIxAEQAAlVTTFQAAAABJUQAAlVTTFQAAAABRAACVVMAIS0tLS0tQkxUAAAAAUQAAgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABVU0xUAAAARDMEACcAYCcxVFlFMwQnAABgJ1QXWUUVABAVAAJVU0xUAAAAAUQAAlVTTFQAAAABRAACVVNMVAAAAAFEAAJVU0xUAAAAAUAAAlVTTFQAAOCmpqampqampqampqampqampqampqYAAAAAAAAAAAAAAAAAAAAAAAAAAAABRAACVVMALS0tLQAA Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4970 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4239778180 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564a00f1f810, 0x564a0110901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564a01109020,0x564a02fa10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/991c0cf9de13d4eb774a1daa7e92b46336fd8c23' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6281 processed earlier; will process 4748 files now Step #5: #1 pulse cov: 3811 ft: 3812 exec/s: 0 rss: 175Mb Step #5: ==178996== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5649f7a149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5649fe079898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5649fe05c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5649fe05c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5649f7a1ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649f797bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649f7976355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5649f7a0cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5649fa9dbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5649fa9dbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5649fa9dbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5649fa9dbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5649fa9dbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5649fa9dbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5649fa9dbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5649fa9dbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5649fa9dbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5649fa9dbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5649fcc70f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649f999db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649f99a8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5649f9754c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5649f9754c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5649f9755738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5649f9754874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5649f9754874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5649f9754874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5649fe05eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5649fe067928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5649fe04f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5649fe07a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e1987e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649f7974b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x30,0x4d,0x46,0x77,0x48,0x65,0x57,0x53,0x63,0x6f,0x41,0x61,0x71,0x59,0x31,0x2b,0x6a,0x79,0x20,0x51,0x20,0xc2,0xa0,0x44,0x20,0x4e,0xa,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x30,0xef,0xbc,0x8f,0x4d,0x46,0x77,0x48,0x65,0x57,0x53,0x63,0x6f,0x41,0x61,0x71,0x59,0x30,0x2f,0x6a,0x6d,0x47,0x4c,0x6c,0x43,0x41,0x41,0x42,0x73,0x54,0x2b,0x4c,0x53,0x59,0x49,0x53,0x7a,0x56,0x77,0x6a,0x77,0x6f,0x31,0x54,0x45,0xa,0x66,0x61,0x6d,0x69,0x6c,0x79,0x20,0x51,0x20,0x44,0x20,0x41,0xa,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x50,0x79,0x76,0x48,0x50,0x46,0x47,0x71,0x54,0x61,0x45,0x31,0x67,0x52,0x72,0x42,0x59,0x79,0x65,0x4b,0x74,0x31,0x79,0x71,0x52,0x76,0x69,0x64,0x6d,0x44,0x58,0x61,0x71,0x49,0x59,0x30,0x6e,0x76,0x65,0x6d,0x49,0x46,0x30,0xa,0x66,0x61,0x6d,0x69,0x6c,0x79,0x20,0x4c,0x20,0x55,0x20,0x4a, Step #5: onion-key\012ntor-onion-key v0MFwHeWScoAaqY1+jy Q \302\240D N\012onion-key\012ntor-onion-key v0\357\274\217MFwHeWScoAaqY0/jmGLlCAABsT+LSYISzVwjwo1TE\012family Q D A\012onion-key\012ntor-onion-key PyvHPFGqTaE1gRrBYyeKt1yqRvidmDXaqIY0nvemIF0\012family L U J Step #5: artifact_prefix='./'; Test unit written to ./oom-4fcb343211d785e1dc864384d1c5694fceae55c8 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHYwTUZ3SGVXU2NvQWFxWTErankgUSDCoEQgTgpvbmlvbi1rZXkKbnRvci1vbmlvbi1rZXkgdjDvvI9NRndIZVdTY29BYXFZMC9qbUdMbENBQUJzVCtMU1lJU3pWd2p3bzFURQpmYW1pbHkgUSBEIEEKb25pb24ta2V5Cm50b3Itb25pb24ta2V5IFB5dkhQRkdxVGFFMWdSckJZeWVLdDF5cVJ2aWRtRFhhcUlZMG52ZW1JRjAKZmFtaWx5IEwgVSBK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4971 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4240354744 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e78d67810, 0x555e78f5101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e78f51020,0x555e7ade90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4fcb343211d785e1dc864384d1c5694fceae55c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6283 processed earlier; will process 4746 files now Step #5: ==179032== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555e6f85c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e75ec1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e75ea45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e75ea44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e6f862d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e6f7c3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e6f7be355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e6f854c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e72823f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e72823f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e72823f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e72823f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e72823f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e72823f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e72823f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e72823f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e72823f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e72823f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e74ab8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e717e5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e717f0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e7159cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e7159cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e7159d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e7159c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e7159c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e7159c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e75ea6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e75eaf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e75e97699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e75ec2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0eea036082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e6f7bcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x76,0x65,0x63,0x20,0x24,0x3b,0x24,0x76,0x65,0x63,0x24,0x63,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63,0xa,0x76,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63,0x24,0x3b,0x3b,0x24,0x76,0x65,0x63,0x24,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63,0x24,0x63,0x20,0x3b,0x24,0x76,0x65,0x63,0xa,0x76,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63,0x24,0x3b,0x24,0x76,0x65,0x63,0x24,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63,0xa,0x76,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63,0x24,0x3b,0x3b,0x24,0x76,0x65,0x63,0x24,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63,0x24,0x63,0x20,0x3b,0x24,0x76,0x65,0x63,0xa,0x76,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63,0x24,0x3b,0x24,0x76,0x65,0x63,0x24,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63,0x24,0x3b,0x63,0x24,0x3b,0x24,0x76,0x65,0x63,0x20,0x6e,0x3b,0x24,0x76,0x65,0x63, Step #5: $vec $;$vec$c;$vec n;$vec n;$vec\012v;$vec n;$vec$;;$vec$;$vec n;$vec$c ;$vec\012v;$vec n;$vec$;$vec$;$vec n;$vec n;$vec n;$vec\012v;$vec n;$vec$;;$vec$;$vec n;$vec$c ;$vec\012v;$vec n;$vec$;$vec$;$vec n;$vec n;$vec$;c$;$vec n;$vec Step #5: artifact_prefix='./'; Test unit written to ./oom-dd2d0da0ab6839ac4722e3788fa60e23fe402cd3 Step #5: Base64: JHZlYyAkOyR2ZWMkYzskdmVjIG47JHZlYyBuOyR2ZWMKdjskdmVjIG47JHZlYyQ7OyR2ZWMkOyR2ZWMgbjskdmVjJGMgOyR2ZWMKdjskdmVjIG47JHZlYyQ7JHZlYyQ7JHZlYyBuOyR2ZWMgbjskdmVjIG47JHZlYwp2OyR2ZWMgbjskdmVjJDs7JHZlYyQ7JHZlYyBuOyR2ZWMkYyA7JHZlYwp2OyR2ZWMgbjskdmVjJDskdmVjJDskdmVjIG47JHZlYyBuOyR2ZWMkO2MkOyR2ZWMgbjskdmVj Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4972 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4240914964 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5606ef142810, 0x5606ef32c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5606ef32c020,0x5606f11c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dd2d0da0ab6839ac4722e3788fa60e23fe402cd3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6284 processed earlier; will process 4745 files now Step #5: #1 pulse cov: 3777 ft: 3778 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4389 ft: 4973 exec/s: 0 rss: 177Mb Step #5: ==179068== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5606e5c379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5606ec29c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606ec27f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606ec27f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5606e5c3dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5606e5b9eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5606e5b99355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5606e5c2fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5606e8bfef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5606e8bfef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5606e8bfef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5606e8bfef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5606e8bfef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5606e8bfef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5606e8bfef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5606e8bfef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5606e8bfef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5606e8bfef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606eae93f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5606e7bc0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5606e7bcbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5606e7977c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5606e7977c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5606e7978738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5606e7977874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5606e7977874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5606e7977874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5606ec281abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5606ec28a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5606ec272699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5606ec29d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6528c74082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5606e5b97b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x52,0x41,0x51,0xa,0x3d,0x44,0x5b,0x7c,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x33,0xd,0x44,0x44,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x33,0x2d,0x3d,0xef,0xbb,0xbe,0x3c,0x27,0x27,0x26,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x7d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3f,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x13,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0x44,0xa,0x3d,0xa,0x3d,0x51,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: RAQ\012=D[|''/''''''3\015DD````````3-=\357\273\276<''&\012=\012=\012=\012=\012=\012\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012}\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012?\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=````````D\012=\012=\012=\012=\012=\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012\023=\012=\012=\012=\012=\012=\012==D\012=\012=Q\012=\012=\012==\012=\012=\012D=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8d4b431da9ce84bb3fd3774c75f1d4580d396ff Step #5: Base64: UkFRCj1EW3wnJy8nJycnJyczDUREYGBgYGBgYGAzLT3vu748JycmCj0KPQo9Cj0KPQoKPT0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQp9Cj0KPQo9Cj0KPQo9Cj0KPQoKPQo9Cj0KPwo9Cj0KPQo9Cj0KPQo9Cj0KPQo9YGBgYGBgYGBECj0KPQo9Cj0KPQo9PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cgo9Cj0KPQo9Cj0KPQoTPQo9Cj0KPQo9Cj0KPT1ECj0KPVEKPQo9Cj09Cj0KPQpEPQo9Cj0KPQoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4973 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4241676587 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e47064f810, 0x55e47083901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e470839020,0x55e4726d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8d4b431da9ce84bb3fd3774c75f1d4580d396ff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6287 processed earlier; will process 4742 files now Step #5: ==179104== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e4671449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e46d7a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e46d78c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e46d78c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e46714ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4670abb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4670a6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e46713cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e46a10bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e46a10bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e46a10bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e46a10bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e46a10bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e46a10bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e46a10bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e46a10bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e46a10bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e46a10bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e46c3a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4690cdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4690d8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e468e84c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e468e84c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e468e85738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e468e84874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e468e84874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e468e84874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e46d78eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e46d797928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e46d77f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e46d7aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c3d3bf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4670a4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x4e,0x20,0xa,0x64,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x73,0x0,0xa,0x3f,0x41,0xa,0x64,0xa,0x64,0xa,0x64,0x0,0x0,0x2d,0x2d,0x47,0x49,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x4e,0x20,0xa,0x64,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x73,0x0,0xa,0x3f,0x41,0xa,0x64,0xa,0x64,0xa,0x64,0x0,0x0,0x2d,0x2d,0x47,0x49,0x4e,0x20,0xa,0x10,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x17,0x18,0x1f,0x0,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x3f,0x41,0x73,0xa,0x0,0xa,0x64,0xa,0x64,0xa,0x64,0x0,0x4e,0x20,0xa,0x10,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x17,0x18,0x1f,0x0,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x3f,0x41,0x73,0xa,0x0,0xa,0x64,0xa,0x64,0xa,0x64,0x0,0x0,0x2d,0x2d, Step #5: x-----BEN \012d\000\000------\000\000\000\000\000\000\000\000\000\000\000\000\000\000=\314\273A---Asce\012-s\000\012?A\012d\012d\012d\000\000--GI-----BEN \012d\000\000------\000\000\000\000\000\000\000\000\000\000\000\000\000\000=\314\273A---Asce\012-s\000\012?A\012d\012d\012d\000\000--GIN \012\020\000\000----------\027\030\037\000=\314\273A---Asce\012-?As\012\000\012d\012d\012d\000N \012\020\000\000----------\027\030\037\000=\314\273A---Asce\012-?As\012\000\012d\012d\012d\000\000-- Step #5: artifact_prefix='./'; Test unit written to ./oom-ba5c9bcd2fab23489617a61367fa303ea1bd66e8 Step #5: Base64: eC0tLS0tQkVOIApkAAAtLS0tLS0AAAAAAAAAAAAAAAAAAD3Mu0EtLS1Bc2NlCi1zAAo/QQpkCmQKZAAALS1HSS0tLS0tQkVOIApkAAAtLS0tLS0AAAAAAAAAAAAAAAAAAD3Mu0EtLS1Bc2NlCi1zAAo/QQpkCmQKZAAALS1HSU4gChAAAC0tLS0tLS0tLS0XGB8APcy7QS0tLUFzY2UKLT9BcwoACmQKZApkAE4gChAAAC0tLS0tLS0tLS0XGB8APcy7QS0tLUFzY2UKLT9BcwoACmQKZApkAAAtLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4974 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4242242611 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557c5d72a810, 0x557c5d91401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557c5d914020,0x557c5f7ac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba5c9bcd2fab23489617a61367fa303ea1bd66e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6288 processed earlier; will process 4741 files now Step #5: ==179140== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557c5421f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557c5a884898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557c5a8675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557c5a8674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557c54225d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557c54186b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557c54181355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557c54217c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557c571e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557c571e6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557c571e6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557c571e6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557c571e6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557c571e6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557c571e6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557c571e6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557c571e6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557c571e6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557c5947bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557c561a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557c561b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557c55f5fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557c55f5fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557c55f60738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557c55f5f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557c55f5f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557c55f5f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557c5a869abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557c5a872928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557c5a85a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557c5a885112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e336cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557c5417fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x3c,0x3c,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x2d,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x3a,0xd,0x2d,0x20,0x5c,0x5c,0x3a, Step #5: -:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015\015- \\:\015<<\\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\\\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- -:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\:\015- \\\\: Step #5: artifact_prefix='./'; Test unit written to ./oom-6a8c8667b150444590e57bead4e0b52e78244f84 Step #5: Base64: LToNLSBcOg0tIFw6DS0gXDoNLSBcOg0tIFw6DS0gXDoNLSBcOg0tIFw6DS0gXDoNLSBcOg0tIFw6DS0gXDoNLSBcOg0tIFw6DS0gXDoNLSBcOg0tIFw6DQ0tIFw6DTw8XDoNLSBcOg0tIFw6DS0gXDoNLSBcOg0tIFw6DS0gXDoNLSBcOg0tIFw6DS0gXDoNLSBcXDoNLSBcOg0tIFw6DS0gXDoNLSBcOg0tIFw6DS0gXDoNLSBcOg0tIC06DS0gXDoNLSBcOg0tIFw6DS0gXDoNLSBcOg0tIFxcOg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4975 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4242815282 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55871439d810, 0x55871458701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558714587020,0x55871641f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a8c8667b150444590e57bead4e0b52e78244f84' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6289 processed earlier; will process 4740 files now Step #5: ==179176== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55870ae929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5587114f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5587114da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5587114da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55870ae98d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55870adf9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55870adf4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55870ae8ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55870de59f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55870de59f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55870de59f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55870de59f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55870de59f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55870de59f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55870de59f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55870de59f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55870de59f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55870de59f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5587100eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55870ce1bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55870ce26be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55870cbd2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55870cbd2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55870cbd3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55870cbd2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55870cbd2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55870cbd2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5587114dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5587114e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5587114cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5587114f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f36c7e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55870adf2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x2d,0x2d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x70,0x69,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012--=\012=\012=\012pi=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000\012=\012=\012=\003\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-34d8aa9ea5b38c1ddee7d5259b717992b6d3eb9e Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Ci0tPQo9Cj0KcGk9Cgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0ACj0KPQo9AwAKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KEA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4976 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4243372742 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d6ccb32810, 0x55d6ccd1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d6ccd1c020,0x55d6cebb40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/34d8aa9ea5b38c1ddee7d5259b717992b6d3eb9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6290 processed earlier; will process 4739 files now Step #5: #1 pulse cov: 4076 ft: 4077 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4117 ft: 4270 exec/s: 0 rss: 177Mb Step #5: ==179212== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d6c36279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d6c9c8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d6c9c6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d6c9c6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d6c362dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d6c358eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d6c3589355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d6c361fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d6c65eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d6c65eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d6c65eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d6c65eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d6c65eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d6c65eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d6c65eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d6c65eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d6c65eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d6c65eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d6c8883f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d6c55b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d6c55bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d6c5367c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d6c5367c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d6c5368738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d6c5367874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d6c5367874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d6c5367874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d6c9c71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d6c9c7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d6c9c62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d6c9c8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e4cc8c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d6c3587b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x22,0x2e,0x2e,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x7a,0x5c,0xa,0x68,0x5c,0xa,0x0,0x72,0x69,0x66,0x0,0x0,0x0,0xdc,0xb4,0x0,0xdc,0x44,0x61,0x6e,0x4d,0x5e,0x49,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0x8d,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xb4,0xd9,0xd,0xd,0xd,0xd,0xd,0xd,0x22,0xd9,0x22,0xd,0xc4,0x35, Step #5: \"\"..zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz\\\012h\\\012\000rif\000\000\000\334\264\000\334DanM^I\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\215\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\264\331\015\015\015\015\015\015\"\331\"\015\3045 Step #5: artifact_prefix='./'; Test unit written to ./oom-6a654c1770121b148d63975eedfbecf24bc72c36 Step #5: Base64: IiIuLnp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enp6enpcCmhcCgByaWYAAADctADcRGFuTV5JDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NjQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NtNkNDQ0NDQ0i2SINxDU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4977 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4243980136 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558de91db810, 0x558de93c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558de93c5020,0x558deb25d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a654c1770121b148d63975eedfbecf24bc72c36' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6293 processed earlier; will process 4736 files now Step #5: ==179248== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558ddfcd09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558de6335898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558de63185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558de63184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558ddfcd6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558ddfc37b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558ddfc32355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558ddfcc8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558de2c97f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558de2c97f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558de2c97f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558de2c97f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558de2c97f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558de2c97f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558de2c97f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558de2c97f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558de2c97f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558de2c97f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558de4f2cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558de1c59b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558de1c64be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558de1a10c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558de1a10c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558de1a11738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558de1a10874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558de1a10874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558de1a10874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558de631aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558de6323928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558de630b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558de6336112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa12aef3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558ddfc30b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x2,0x22,0x2c,0x20,0x6c,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x0,0x0,0x0,0xa,0x54,0x88,0x49,0x44,0x33,0x4,0x2,0x26,0x2c,0x20,0x6c,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55,0x53,0x4c,0x54,0x0,0x0,0x0,0x2,0x2,0x28,0x55,0x2,0x55, Step #5: ID3\004\002\", l\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002US\000\000\000\012T\210ID3\004\002&, l\002USLT\000\000\000\002\002(U\002USLT\000\000\000\002\002(U\002U Step #5: artifact_prefix='./'; Test unit written to ./oom-f6e1226f8630fbcc336bcbf7a00a03a59d6d389b Step #5: Base64: SUQzBAIiLCBsAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlVTAAAAClSISUQzBAImLCBsAlVTTFQAAAACAihVAlVTTFQAAAACAihVAlU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4978 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4244506432 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9bd98d810, 0x55e9bdb7701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9bdb77020,0x55e9bfa0f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f6e1226f8630fbcc336bcbf7a00a03a59d6d389b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6294 processed earlier; will process 4735 files now Step #5: #1 pulse cov: 3614 ft: 3615 exec/s: 0 rss: 177Mb Step #5: ==179284== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e9b44829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9baae7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9baaca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9baaca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9b4488d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e9b43e9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e9b43e4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9b447ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e9b7449f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e9b7449f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e9b7449f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e9b7449f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e9b7449f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e9b7449f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e9b7449f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e9b7449f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e9b7449f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e9b7449f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9b96def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e9b640bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e9b6416be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9b61c2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9b61c2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9b61c3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9b61c2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9b61c2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9b61c2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e9baaccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9baad5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e9baabd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e9baae8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba51822082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e9b43e2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x46,0x55,0x5a,0x5a,0x54,0x45,0x53,0x54,0x76,0x31,0xb,0x64,0x3a,0x33,0x36,0x38,0x39,0x33,0x34,0x38,0x38,0x31,0x34,0x37,0x34,0x31,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x31,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x38,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x32,0x39,0x32,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x39,0x31,0x39,0x31,0x31,0x30,0x39,0x30,0x31,0x39,0x30,0x35,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x30,0x35,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x31,0x31,0x31,0x32,0x30,0x39,0x31,0x39,0x30,0x30,0x30,0x39,0x30,0x30,0x39,0x31,0x39,0x32,0x35,0x35,0x33,0x32,0x37,0x37,0x30,0xe2,0x80,0xad,0x2d,0x38,0x34,0x35,0xf0,0x9d,0x9f,0x96,0x31,0x31,0x31,0x39,0x31,0x30,0x39,0x31,0xe0,0xb9,0x82,0x39,0x31,0x30,0x39,0x31,0x30,0x39,0x32,0xe0,0xb9,0x82,0x31,0xe2,0x80,0xad,0x39,0x34,0x39,0x35,0x37,0x31,0x38,0x31,0x36,0x35,0x37, Step #5: FUZZTESTv1\013d:3689348814741910910910910910911910910910910910810910910910910910912920910910910919191109019050910910910910905091091091091091091091091091112091900090091925532770\342\200\255-845\360\235\237\22611191091\340\271\20291091092\340\271\2021\342\200\25594957181657 Step #5: artifact_prefix='./'; Test unit written to ./oom-cfd1b4dd45c5ec60984a6811497fc7bd8e72814a Step #5: Base64: RlVaWlRFU1R2MQtkOjM2ODkzNDg4MTQ3NDE5MTA5MTA5MTA5MTA5MTA5MTE5MTA5MTA5MTA5MTA5MTA4MTA5MTA5MTA5MTA5MTA5MTA5MTI5MjA5MTA5MTA5MTA5MTkxOTExMDkwMTkwNTA5MTA5MTA5MTA5MTA5MDUwOTEwOTEwOTEwOTEwOTEwOTEwOTEwOTEwOTExMTIwOTE5MDAwOTAwOTE5MjU1MzI3NzDigK0tODQ18J2fljExMTkxMDkx4LmCOTEwOTEwOTLguYIx4oCtOTQ5NTcxODE2NTc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4979 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4245068714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561943ddc810, 0x561943fc601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561943fc6020,0x561945e5e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cfd1b4dd45c5ec60984a6811497fc7bd8e72814a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6296 processed earlier; will process 4733 files now Step #5: ==179320== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56193a8d19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561940f36898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561940f195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561940f194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56193a8d7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56193a838b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56193a833355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56193a8c9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56193d898f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56193d898f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56193d898f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56193d898f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56193d898f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56193d898f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56193d898f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56193d898f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56193d898f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56193d898f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56193fb2df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56193c85ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56193c865be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56193c611c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56193c611c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56193c612738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56193c611874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56193c611874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56193c611874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561940f1babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561940f24928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561940f0c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561940f37112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5bd73ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56193a831b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x63,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x2d,0x54,0x79,0x70,0x65,0x3a,0x3b,0x62,0x6f,0x75,0x6e,0x64,0x61,0x72,0x79,0x3d,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa,0xa,0x2d,0x2d,0xa,0x3a,0xa, Step #5: content-Type:;boundary=\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012\012--\012:\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-1379b24a992a396b5c22ebf71bc086b18279e3f4 Step #5: Base64: Y29udGVudC1UeXBlOjtib3VuZGFyeT0KCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoKCi0tCjoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4980 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4245605028 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7cf69d810, 0x55b7cf88701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7cf887020,0x55b7d171f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1379b24a992a396b5c22ebf71bc086b18279e3f4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6297 processed earlier; will process 4732 files now Step #5: ==179356== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b7c61929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b7cc7f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b7cc7da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b7cc7da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b7c6198d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b7c60f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b7c60f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b7c618ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b7c9159f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b7c9159f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b7c9159f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b7c9159f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b7c9159f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b7c9159f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b7c9159f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b7c9159f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b7c9159f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b7c9159f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b7cb3eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b7c811bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b7c8126be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b7c7ed2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b7c7ed2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b7c7ed3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b7c7ed2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b7c7ed2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b7c7ed2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b7cc7dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b7cc7e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b7cc7cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b7cc7f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6c3f97e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b7c60f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0xa,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x0,0x0,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x2a,0x2a,0xa,0x1,0x0,0x2a,0x3d,0xa,0x3d,0xa,0x2a,0x0,0x30,0x30,0x30,0x30,0x35,0x36,0x35,0x32,0x37,0x34,0x33,0x38,0x34,0x34,0x39,0x30,0x30,0x39,0x33,0x33,0x34,0x36,0x38,0xb0,0x38,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x33,0x34,0x37,0x37,0x35,0x38,0x30,0x37, Step #5: **\012**\012**\012**\012**\012**\012**\012**\012**\012*\012*\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012~~~~~~~~~~~**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012*\000\000*\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012**\012\001\000*=\012=\012*\00000005652743844900933468\2608372036834775807 Step #5: artifact_prefix='./'; Test unit written to ./oom-00e474588012a1a16959ec955e3375acfa5e90a5 Step #5: Base64: KioKKioKKioKKioKKioKKioKKioKKioKKioKKgoqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCioqCn5+fn5+fn5+fn5+KioKKioKKioKKioKKioKKioKKioKKioKKioKKioKKioKKioKKioKKioKKgAAKgoqKgoqKgoqKgoqKgoqKgoqKgoqKgoqKgoqKgoqKgoqKgoBACo9Cj0KKgAwMDAwNTY1Mjc0Mzg0NDkwMDkzMzQ2OLA4MzcyMDM2ODM0Nzc1ODA3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4981 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4246135836 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55774a2e1810, 0x55774a4cb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55774a4cb020,0x55774c3630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/00e474588012a1a16959ec955e3375acfa5e90a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6298 processed earlier; will process 4731 files now Step #5: ==179392== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557740dd69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55774743b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55774741e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55774741e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557740ddcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557740d3db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557740d38355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557740dcec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557743d9df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557743d9df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557743d9df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557743d9df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557743d9df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557743d9df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557743d9df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557743d9df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557743d9df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557743d9df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557746032f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557742d5fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557742d6abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557742b16c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557742b16c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557742b17738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557742b16874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557742b16874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557742b16874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557747420abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557747429928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557747411699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55774743c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fad563c2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557740d36b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x3c,0x73,0x68,0x3e,0x2e,0x67,0x2c,0x74,0x2d,0x47,0x20,0x73,0x47,0x7b,0x5c,0x69,0x6c,0x3a,0x5b,0x4d,0x4d,0x4d,0x4d,0x4d,0x4d,0x73,0x60,0x3a,0x5c,0x6c,0x69,0x63,0x2b,0x30,0x37,0x75,0x7d,0x3e,0x52,0x74,0x73,0x76,0x67,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x3c,0x73,0x68,0x3e,0x2e,0x67,0x2c,0x74,0x2d,0x47,0x20,0x73,0x47,0x7b,0x5c,0x69,0x6c,0x3a,0x5b,0x4d,0x4d,0x4d,0x4d,0x4d,0x4d,0x73,0x60,0x3a,0x5c,0x6c,0x69,0x63,0x2b,0x30,0x37,0x75,0x7d,0x3e,0x52,0x74,0x73,0x2d,0x72,0x6f,0x6b,0x65,0x2d,0x77,0x69,0x64,0x74,0x68,0x3e,0x3c,0x67,0x3e,0x20,0x3c,0x65,0x2d,0x3e,0x52,0x3e,0x3c,0x67,0x3e,0x20,0x47,0x7b,0x73,0x3c,0x67,0x3e,0x20,0x47,0x7b,0x73,0x3a,0x5c,0x75,0x72,0x6c,0x28,0x2d,0x29,0x2d,0x3c,0x67,0x3e,0x79,0x6c,0x3e,0x65,0x3c,0x73,0x3e,0x79,0x6c,0x3e,0x65,0x3c,0x74,0x2d,0x3e,0x52,0x3e,0x3c,0x67,0x3e,0x20,0x47,0x7b,0x73,0x3a,0x5c,0x75,0x72,0x6c,0x28,0x2f,0x29,0x40,0x3c,0x67,0x3e,0x79,0x6c,0x3e,0x65,0x74,0x68,0x3e,0x3c,0x67,0x3e,0x20,0x47,0x7b,0x73,0x3a,0x5c,0x75,0x72,0x6c,0x28,0x2f,0x29,0x2d,0x3c,0x67,0x3e,0x79,0x6c,0x76,0x2d,0x29,0x2d,0x3c,0x0,0x3e, Step #5: <svg><style><sh>.g,t-G sG{\\il:[MMMMMMs`:\\lic+07u}>Rtsvg><style><sh>.g,t-G sG{\\il:[MMMMMMs`:\\lic+07u}>Rts-roke-width><g> <e->R><g> G{s<g> G{s:\\url(-)-<g>yl>e<s>yl>e<t->R><g> G{s:\\url(/)@<g>yl>eth><g> G{s:\\url(/)-<g>ylv-)-<\000> Step #5: artifact_prefix='./'; Test unit written to ./oom-6bcc18a69ffdf8803593b7d1fc6336e96dec2ef3 Step #5: Base64: PHN2Zz48c3R5bGU+PHNoPi5nLHQtRyBzR3tcaWw6W01NTU1NTXNgOlxsaWMrMDd1fT5SdHN2Zz48c3R5bGU+PHNoPi5nLHQtRyBzR3tcaWw6W01NTU1NTXNgOlxsaWMrMDd1fT5SdHMtcm9rZS13aWR0aD48Zz4gPGUtPlI+PGc+IEd7czxnPiBHe3M6XHVybCgtKS08Zz55bD5lPHM+eWw+ZTx0LT5SPjxnPiBHe3M6XHVybCgvKUA8Zz55bD5ldGg+PGc+IEd7czpcdXJsKC8pLTxnPnlsdi0pLTwAPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4982 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4246787319 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55890c3a0810, 0x55890c58a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55890c58a020,0x55890e4220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bcc18a69ffdf8803593b7d1fc6336e96dec2ef3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6299 processed earlier; will process 4730 files now Step #5: ==179428== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558902e959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5589094fa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589094dd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589094dd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558902e9bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558902dfcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558902df7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558902e8dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558905e5cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558905e5cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558905e5cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558905e5cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558905e5cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558905e5cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558905e5cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558905e5cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558905e5cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558905e5cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589080f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558904e1eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558904e29be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558904bd5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558904bd5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558904bd6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558904bd5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558904bd5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558904bd5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5589094dfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5589094e8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5589094d0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5589094fb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7cdbba9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558902df5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x38,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x25,0x27,0x27,0x7b,0x27,0x27,0x7b,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x25,0x27,0x7b,0x27,0x27,0x7b,0x27,0x7b,0x27,0x27,0x25,0x27,0x27,0x7b,0x27,0x27,0x7b,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x25,0x27,0x27,0x7b,0x27,0x27,0x7b,0x7b,0x78,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x7b,0x7d,0x7b,0x7d,0x27,0x25,0x27,0x27,0x7b,0x27,0x27,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x25,0x27,0x27,0x7b,0x27,0x27,0x7a,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x7b,0x78,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x25,0x27,0x27,0x7b,0x27,0x27,0x7b,0x7b,0x3a,0x3d,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x25,0x27,0x27,0x7b,0x27,0x27,0x7a,0x7b,0x25,0x27,0x27,0x7b,0x27,0x27,0x7b,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x25,0x27,0x27,0x7b,0x27,0x27,0x7b,0x27,0x27,0x27,0x7b, Step #5: 8'{''{''{''{''%''{''{{''{''{''{''{''{''%'{''{'{''%''{''{{''{''{''{''{''{''%''{''{{x''{''{''{''{''{'{}{}'%''{''''{''{''%''{''z{''{''{''{{x''{''{''{''{''{''%''{''{{:={''{''{''{''{''%''{''z{%''{''{{''{''{''{''{''{''%''{''{'''{ Step #5: artifact_prefix='./'; Test unit written to ./oom-f9054ce82e94f147d8bf76611ddc436390ee1beb Step #5: Base64: OCd7Jyd7Jyd7Jyd7JyclJyd7Jyd7eycneycneycneycneycneycnJSd7Jyd7J3snJyUnJ3snJ3t7Jyd7Jyd7Jyd7Jyd7Jyd7JyclJyd7Jyd7e3gnJ3snJ3snJ3snJ3snJ3sne317fSclJyd7JycnJ3snJ3snJyUnJ3snJ3p7Jyd7Jyd7Jyd7e3gnJ3snJ3snJ3snJ3snJ3snJyUnJ3snJ3t7Oj17Jyd7Jyd7Jyd7Jyd7JyclJyd7Jyd6eyUnJ3snJ3t7Jyd7Jyd7Jyd7Jyd7Jyd7JyclJyd7Jyd7Jycnew== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4983 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4247318500 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d9a516810, 0x561d9a70001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d9a700020,0x561d9c5980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9054ce82e94f147d8bf76611ddc436390ee1beb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6300 processed earlier; will process 4729 files now Step #5: #1 pulse cov: 3954 ft: 3955 exec/s: 0 rss: 175Mb Step #5: ==179464== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d9100b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d97670898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d976535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d976534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d91011d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d90f72b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d90f6d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d91003c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d93fd2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d93fd2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d93fd2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d93fd2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d93fd2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d93fd2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d93fd2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d93fd2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d93fd2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d93fd2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d96267f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d92f94b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d92f9fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d92d4bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d92d4bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d92d4c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d92d4b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d92d4b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d92d4b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d97655abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d9765e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d97646699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d97671112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0056a42082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d90f6bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x4e,0x20,0xa,0x64,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x73,0x22,0x22,0x22,0x22,0x0,0xa,0x3f,0x41,0xa,0x64,0xa,0x64,0xa,0x64,0x0,0x0,0x2d,0x2d,0x47,0x49,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x4e,0x20,0xa,0x64,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x73,0x0,0xa,0x3f,0x41,0xa,0x64,0xa,0x64,0xa,0x64,0x0,0x0,0x2d,0x2d,0x47,0x49,0x4e,0x20,0xa,0x10,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x17,0x18,0x1f,0x0,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x3f,0x41,0x73,0xa,0x0,0xa,0x64,0xa,0x64,0xa,0x64,0x0,0x4e,0x20,0xa,0x10,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x17,0x58,0x1f,0x0,0x3d,0xcc,0xbb,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x3f,0x41,0x73,0xa,0x0,0xa,0x64,0xa,0x64,0xa,0x64,0x0,0x0,0x2d,0x2d, Step #5: x-----BEN \012d\000\000------\000\000\000\000\000\000\000\000\000\000\000\000\000\000=\314\273A---Asce\012-s\"\"\"\"\000\012?A\012d\012d\012d\000\000--GI-----BEN \012d\000\000------\000\000\000\000\000\000\000\000\000\000\000\000\000\000=\314\273A---Asce\012-s\000\012?A\012d\012d\012d\000\000--GIN \012\020\000\000----------\027\030\037\000=\314\273A---Asce\012-?As\012\000\012d\012d\012d\000N \012\020\000\000----------\027X\037\000=\314\273A---Asce\012-?As\012\000\012d\012d\012d\000\000-- Step #5: artifact_prefix='./'; Test unit written to ./oom-5d55203cb0bff208dfeb6b60deef600239699c9f Step #5: Base64: eC0tLS0tQkVOIApkAAAtLS0tLS0AAAAAAAAAAAAAAAAAAD3Mu0EtLS1Bc2NlCi1zIiIiIgAKP0EKZApkCmQAAC0tR0ktLS0tLUJFTiAKZAAALS0tLS0tAAAAAAAAAAAAAAAAAAA9zLtBLS0tQXNjZQotcwAKP0EKZApkCmQAAC0tR0lOIAoQAAAtLS0tLS0tLS0tFxgfAD3Mu0EtLS1Bc2NlCi0/QXMKAApkCmQKZABOIAoQAAAtLS0tLS0tLS0tF1gfAD3Mu0EtLS1Bc2NlCi0/QXMKAApkCmQKZAAALS0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4984 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4247898849 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c260b47810, 0x55c260d3101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c260d31020,0x55c262bc90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5d55203cb0bff208dfeb6b60deef600239699c9f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6302 processed earlier; will process 4727 files now Step #5: ==179500== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c25763c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c25dca1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c25dc845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c25dc844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c257642d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c2575a3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c25759e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c257634c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c25a603f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c25a603f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c25a603f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c25a603f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c25a603f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c25a603f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c25a603f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c25a603f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c25a603f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c25a603f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c25c898f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c2595c5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c2595d0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c25937cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c25937cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c25937d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c25937c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c25937c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c25937c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c25dc86abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c25dc8f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c25dc77699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c25dca2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3f9201082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c25759cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa7,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0xbc,0xc4,0xbc,0xa,0xc,0x62,0xa,0xa,0x8,0xec,0xa3,0xbc,0xec,0xa3,0x84,0xbc,0xa, Step #5: \012\014b\012\012\010\354\243\274\354\243\274\304\274\012\014b\012\012\010\354\243\274\354\243\274\304\274\012\014b\012\012\010\354\243\274\354\243\274\304\274\012\014b\012\012\010\354\243\274\354\243\274\304\274\012\014b\012\012\010\354\243\274\354\243\274\304\274\012\014b\012\012\010\354\243\274\354\243\274\304\274\012\014b\012\012\010\354\243\274\354\243\274\304\274\012\014b\012\012\010\012\010\354\243\274\354\243\274\012\014b\012\012\010\354\243\274\354\243\274\304\274\012\014b\012\012\010\354\243\274\354\243\274\304\274\012\014b\012\012\010\354\247\274\354\243\274\304\274\012\014b\012\012\010\354\243\274\354\243\274\304\274\012\014b\012\012\010\354\243\274\354\243\274\304\274\012\014b\012\012\010\354\243\274\354\243\274\304\274\012\014b\012\012\010\354\243\274\354\243\274\304\274\012\014b\012\012\010\354\243\274\354\243\204\274\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-71f0be4d8847f02ce8eda23363cece17ebfdc418 Step #5: Base64: CgxiCgoI7KO87KO8xLwKDGIKCgjso7zso7zEvAoMYgoKCOyjvOyjvMS8CgxiCgoI7KO87KO8xLwKDGIKCgjso7zso7zEvAoMYgoKCOyjvOyjvMS8CgxiCgoI7KO87KO8xLwKDGIKCggKCOyjvOyjvAoMYgoKCOyjvOyjvMS8CgxiCgoI7KO87KO8xLwKDGIKCgjsp7zso7zEvAoMYgoKCOyjvOyjvMS8CgxiCgoI7KO87KO8xLwKDGIKCgjso7zso7zEvAoMYgoKCOyjvOyjvMS8CgxiCgoI7KO87KOEvAo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4985 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4248435383 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b15fd94810, 0x55b15ff7e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b15ff7e020,0x55b161e160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/71f0be4d8847f02ce8eda23363cece17ebfdc418' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6303 processed earlier; will process 4726 files now Step #5: ==179536== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b1568899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b15ceee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b15ced15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b15ced14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b15688fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b1567f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b1567eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b156881c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b159850f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b159850f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b159850f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b159850f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b159850f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b159850f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b159850f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b159850f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b159850f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b159850f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b15bae5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b158812b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b15881dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b1585c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b1585c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b1585ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b1585c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b1585c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b1585c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b15ced3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b15cedc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b15cec4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b15ceef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda99f4b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b1567e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x48,0x54,0x54,0x50,0x2f,0x33,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x35,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x33,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x35,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x35,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x33,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x33,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x33,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x35,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x33,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x35,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x35,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x33,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x33,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x35,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa,0x48,0x54,0x54,0x50,0x2f,0x35,0x2e,0x34,0x20,0x32,0x30,0x34,0xa,0xa, Step #5: HTTP/3.4 204\012\012HTTP/5.4 204\012\012HTTP/3.4 204\012\012HTTP/5.4 204\012\012HTTP/5.4 204\012\012HTTP/3.4 204\012\012HTTP/3.4 204\012\012HTTP/3.4 204\012\012HTTP/5.4 204\012\012HTTP/3.4 204\012\012HTTP/5.4 204\012\012HTTP/5.4 204\012\012HTTP/3.4 204\012\012HTTP/3.4 204\012\012HTTP/5.4 204\012\012HTTP/5.4 204\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-7ade5622b86d34f43bc6e79a8505ba00fe4a6075 Step #5: Base64: SFRUUC8zLjQgMjA0CgpIVFRQLzUuNCAyMDQKCkhUVFAvMy40IDIwNAoKSFRUUC81LjQgMjA0CgpIVFRQLzUuNCAyMDQKCkhUVFAvMy40IDIwNAoKSFRUUC8zLjQgMjA0CgpIVFRQLzMuNCAyMDQKCkhUVFAvNS40IDIwNAoKSFRUUC8zLjQgMjA0CgpIVFRQLzUuNCAyMDQKCkhUVFAvNS40IDIwNAoKSFRUUC8zLjQgMjA0CgpIVFRQLzMuNCAyMDQKCkhUVFAvNS40IDIwNAoKSFRUUC81LjQgMjA0Cgo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4986 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4248970126 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5600831d4810, 0x5600833be01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5600833be020,0x5600852560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ade5622b86d34f43bc6e79a8505ba00fe4a6075' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6304 processed earlier; will process 4725 files now Step #5: ==179572== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560079cc99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56008032e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5600803115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5600803114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560079ccfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560079c30b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560079c2b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560079cc1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56007cc90f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56007cc90f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56007cc90f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56007cc90f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56007cc90f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56007cc90f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56007cc90f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56007cc90f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56007cc90f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56007cc90f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56007ef25f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56007bc52b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56007bc5dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56007ba09c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56007ba09c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56007ba0a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56007ba09874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56007ba09874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56007ba09874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560080313abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56008031c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560080304699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56008032f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f07a9db0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560079c29b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf4,0x80,0x80,0xa1,0xa,0xc,0x62,0xa,0xa,0x8,0xf3,0xbc,0x81,0x80,0xf3,0xbc,0x81,0x80, Step #5: \012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\364\200\200\241\012\014b\012\012\010\363\274\201\200\363\274\201\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-27400d12aba05b2d2af6c283080d9e0950a8529e Step #5: Base64: CgxiCgoI87yBgPSAgKEKDGIKCgjzvIGA9ICAoQoMYgoKCPO8gYD0gIChCgxiCgoI87yBgPSAgKEKDGIKCgjzvIGA9ICAoQoMYgoKCPO8gYD0gIChCgxiCgoI87yBgPSAgKEKDGIKCgjzvIGA9ICAoQoMYgoKCPO8gYD0gIChCgxiCgoI87yBgPSAgKEKDGIKCgjzvIGA9ICAoQoMYgoKCPO8gYD0gIChCgxiCgoI87yBgPSAgKEKDGIKCgjzvIGA9ICAoQoMYgoKCPO8gYD0gIChCgxiCgoI87yBgPO8gYA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4987 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4249505649 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55beaeb0c810, 0x55beaecf601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55beaecf6020,0x55beb0b8e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/27400d12aba05b2d2af6c283080d9e0950a8529e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6305 processed earlier; will process 4724 files now Step #5: ==179608== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bea56019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55beabc66898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55beabc495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55beabc494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bea5607d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bea5568b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bea5563355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bea55f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bea85c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bea85c8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bea85c8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bea85c8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bea85c8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bea85c8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bea85c8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bea85c8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bea85c8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bea85c8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55beaa85df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bea758ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bea7595be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bea7341c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bea7341c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bea7342738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bea7341874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bea7341874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bea7341874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55beabc4babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55beabc54928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55beabc3c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55beabc67112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0826a8b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bea5561b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x3f,0x3a,0x28,0x3f,0x73,0x74,0x72,0x79,0x20,0x28,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x7c,0x7c,0x24,0x7c,0x24,0x24,0x24,0x7c,0x24,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x29,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x5c,0xde,0x99,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x3b,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x24,0x7c,0x7c,0x7c,0x24,0x7c,0x24,0x24,0x24,0x7c,0x24,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x29,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x5c,0xde,0x99,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x3b,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x29,0x29,0x7c,0x29,0x7c,0x29,0x7c, Step #5: (?:(?:?:(?stry (:$|$|(?:(?:(?:$|$|$|$|$|$|$||$|$|$|$|$|$|||$|$$$|$$|$|$|$|$|$|)|$|(?:$|$|(?:(?:(?:\\\336\231|$|$|$|$|$|$|$;|$|$|$|$)|$|$|$|$|$)$|||$|$$$|$$|$|$|$|$|$|)|$|(?:$|$|(?:(?:(?:\\\336\231|$|$|$|$|$|$|$;|$|$|$|$)|$|$|$|$|$)|))|)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-0282359bc22db6b0ab8d16e78c9ec2ca2efa69f2 Step #5: Base64: KD86KD86PzooP3N0cnkgKDokfCR8KD86KD86KD86JHwkfCR8JHwkfCR8JHx8JHwkfCR8JHwkfCR8fHwkfCQkJHwkJHwkfCR8JHwkfCR8KXwkfCg/OiR8JHwoPzooPzooPzpc3pl8JHwkfCR8JHwkfCR8JDt8JHwkfCR8JCl8JHwkfCR8JHwkKSR8fHwkfCQkJHwkJHwkfCR8JHwkfCR8KXwkfCg/OiR8JHwoPzooPzooPzpc3pl8JHwkfCR8JHwkfCR8JDt8JHwkfCR8JCl8JHwkfCR8JHwkKXwpKXwpfCl8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4988 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4250058103 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56445221b810, 0x56445240501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564452405020,0x56445429d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0282359bc22db6b0ab8d16e78c9ec2ca2efa69f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6306 processed earlier; will process 4723 files now Step #5: #1 pulse cov: 12015 ft: 12016 exec/s: 0 rss: 198Mb Step #5: ==179644== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564448d109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56444f375898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56444f3585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56444f3584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564448d16d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564448c77b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564448c72355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564448d08c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56444bcd7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56444bcd7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56444bcd7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56444bcd7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56444bcd7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56444bcd7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56444bcd7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56444bcd7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56444bcd7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56444bcd7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56444df6cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56444ac99b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56444aca4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56444aa50c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56444aa50c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56444aa51738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56444aa50874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56444aa50874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56444aa50874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56444f35aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56444f363928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56444f34b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56444f376112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9fba7f3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564448c70b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0x78,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb3,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0x2e,0x6e,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0x2e,0x6e,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0x2e,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb3,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb5,0xe0,0xbd,0xb1,0xe0,0xbd,0xb5, Step #5: ws:x\340\275\263\340\275\265\340\275\265\340\275\265\340\275\263\340\275\265\340\275\265\340\275\265\340\275\261\340\275\265\340\275\265\340\275\265\340\275\261\340\275\263\340\275\263\340\275\265\340\275\265\340\275\265.n\340\275\263\340\275\265\340\275\265\340\275\263\340\275\265\340\275\265\340\275\265\340\275\261\340\275\265\340\275\265\340\275\265\340\275\265\340\275\263\340\275\265\340\275\265\340\275\265\340\275\261\340\275\265.n\340\275\263\340\275\265\340\275\265\340\275\263\340\275\265\340\275\265\340\275\265\340\275\261\340\275\265\340\275\265\340\275\265\340\275\263\340\275\265\340\275\265\340\275\265\340\275\261\340\275\265\340\275\265.\340\275\263\340\275\265\340\275\265\340\275\263\340\275\265\340\275\265\340\275\265\340\275\261\340\275\265\340\275\265\340\275\265\340\275\265\340\275\263\340\275\265\340\275\265\340\275\265\340\275\261\340\275\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-489e7279a0a42fa1d9de48d90e72349633f1ff81 Step #5: Base64: d3M6eOC9s+C9teC9teC9teC9s+C9teC9teC9teC9seC9teC9teC9teC9seC9s+C9s+C9teC9teC9tS5u4L2z4L214L214L2z4L214L214L214L2x4L214L214L214L214L2z4L214L214L214L2x4L21Lm7gvbPgvbXgvbXgvbPgvbXgvbXgvbXgvbHgvbXgvbXgvbXgvbPgvbXgvbXgvbXgvbHgvbXgvbUu4L2z4L214L214L2z4L214L214L214L2x4L214L214L214L214L2z4L214L214L214L2x4L21 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4989 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4250666264 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558054b23810, 0x558054d0d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558054d0d020,0x558056ba50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/489e7279a0a42fa1d9de48d90e72349633f1ff81' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6308 processed earlier; will process 4721 files now Step #5: ==179680== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55804b6189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558051c7d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558051c605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558051c604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55804b61ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55804b57fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55804b57a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55804b610c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55804e5dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55804e5dff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55804e5dff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55804e5dff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55804e5dff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55804e5dff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55804e5dff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55804e5dff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55804e5dff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55804e5dff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558050874f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55804d5a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55804d5acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55804d358c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55804d358c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55804d359738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55804d358874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55804d358874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55804d358874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558051c62abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558051c6b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558051c53699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558051c7e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efd8bf49082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55804b578b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x3f,0x3a,0x28,0x3f,0x73,0x74,0x72,0x79,0x20,0x28,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x7c,0x7c,0x24,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x29,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x5c,0xde,0x99,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x3b,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x24,0x7c,0x7c,0x7c,0x24,0x7c,0x24,0x24,0x24,0x7c,0x24,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x29,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x5c,0xde,0x99,0x28,0x3f,0x3a,0x5c,0xde,0x99,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x3b,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x29,0x29,0x7c,0x29,0x7c,0x29,0x7c, Step #5: (?:(?:?:(?stry (:$|$|(?:(?:(?:$|$|$|$|$|$|$||$|$|$|$|$|$|||$$|$|$|$|$|$|)|$|(?:$|$|(?:(?:(?:\\\336\231|$|$|$|$|$|$|$;|$|$|$|$)|$|$|$|$|$)$|||$|$$$|$$|$|$|$|$|$|)|$|(?:$|$|(?:(?:(?:\\\336\231(?:\\\336\231|$|$|$|$|$|$|$;|$|$|$|$)|$|$|$|$|$)|))|)|)| Step #5: artifact_prefix='./'; Test unit written to ./oom-71953466bb94b83551ff45c2fdbf58452a573986 Step #5: Base64: KD86KD86PzooP3N0cnkgKDokfCR8KD86KD86KD86JHwkfCR8JHwkfCR8JHx8JHwkfCR8JHwkfCR8fHwkJHwkfCR8JHwkfCR8KXwkfCg/OiR8JHwoPzooPzooPzpc3pl8JHwkfCR8JHwkfCR8JDt8JHwkfCR8JCl8JHwkfCR8JHwkKSR8fHwkfCQkJHwkJHwkfCR8JHwkfCR8KXwkfCg/OiR8JHwoPzooPzooPzpc3pkoPzpc3pl8JHwkfCR8JHwkfCR8JDt8JHwkfCR8JCl8JHwkfCR8JHwkKXwpKXwpfCl8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4990 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4251220388 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f649454810, 0x55f64963e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f64963e020,0x55f64b4d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/71953466bb94b83551ff45c2fdbf58452a573986' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6309 processed earlier; will process 4720 files now Step #5: #1 pulse cov: 4110 ft: 4111 exec/s: 0 rss: 179Mb Step #5: ==179716== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f63ff499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f6465ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f6465915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f6465914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f63ff4fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f63feb0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f63feab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f63ff41c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f642f10f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f642f10f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f642f10f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f642f10f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f642f10f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f642f10f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f642f10f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f642f10f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f642f10f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f642f10f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f6451a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f641ed2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f641eddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f641c89c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f641c89c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f641c8a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f641c89874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f641c89874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f641c89874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f646593abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f64659c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f646584699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f6465af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe7895f0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f63fea9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x0,0x3d,0x0,0x4,0x0,0x31,0x1a,0x31,0x6c,0x69,0x67,0x68,0x74,0x24,0x3a,0x3a,0x3a,0x3a,0x3a,0x54,0x0,0x54,0x5b,0x31,0x31,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3a,0x3a,0x3a,0x0,0x0,0x0,0x4,0x0,0x31,0x1a,0x3a,0x0,0x5d,0x2f,0x0,0x0,0x0,0x33,0x34,0x0,0x54,0x5b,0x31,0x31,0x0,0x0,0x0,0x0,0x4,0x0,0x0,0x31,0x0,0x0,0x0,0x1,0x24,0x5b, Step #5: ID3\004\000=\000\004\0001\0321light$:::::T\000T[11::::::::::::::::::=\012=\012=\012=\012=\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012=\012=\012=?\012=\012=\012=\012=\012=\012:::\000\000\000\004\0001\032:\000]/\000\000\00034\000T[11\000\000\000\000\004\000\0001\000\000\000\001$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-f2555dd3156b869b64ace6f77d36b66eaa6d051f Step #5: Base64: SUQzBAA9AAQAMRoxbGlnaHQkOjo6OjpUAFRbMTE6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo9Cj0KPQo9Cj0AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAo9Cj0KPT8KPQo9Cj0KPQo9Cjo6OgAAAAQAMRo6AF0vAAAAMzQAVFsxMQAAAAAEAAAxAAAAASRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4991 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4251794617 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b79cd8e810, 0x55b79cf7801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b79cf78020,0x55b79ee100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f2555dd3156b869b64ace6f77d36b66eaa6d051f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6311 processed earlier; will process 4718 files now Step #5: #1 pulse cov: 4045 ft: 4046 exec/s: 0 rss: 175Mb Step #5: ==179752== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b7938839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b799ee8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b799ecb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b799ecb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b793889d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b7937eab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b7937e5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b79387bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b79684af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b79684af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b79684af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b79684af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b79684af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b79684af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b79684af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b79684af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b79684af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b79684af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b798adff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b79580cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b795817be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b7955c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b7955c3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b7955c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b7955c3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b7955c3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b7955c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b799ecdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b799ed6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b799ebe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b799ee9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ab503b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b7937e3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0xad,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcc,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x90,0xcd,0x8f,0xcd,0x8f,0xcd,0x8e,0xcd,0x8f,0xa,0x6b,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x90,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x87,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xa,0x6b,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcc,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcc,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcc,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcc,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xa,0x6b,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xcd,0x8f,0xa,0x8e, Step #5: 0\315\217\315\217\315\217\315\217\315\255\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\314\217\315\217\315\217\315\217\315\217\315\217\315\220\315\217\315\217\315\216\315\217\012k\315\217\315\217\315\217\315\217\315\220\315\217\315\217\315\217\315\207\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\012k\315\217\315\217\315\217\315\217\314\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\314\217\315\217\315\217\315\217\314\217\315\217\315\217\315\217\314\217\315\217\315\217\315\217\315\217\315\217\315\217\012k\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\315\217\012\216 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8025d8976c3ec3ba824ed20b2f65dfa14e90e17 Step #5: Base64: MM2PzY/Nj82Pza3Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzI/Nj82PzY/Nj82PzZDNj82PzY7NjwprzY/Nj82PzY/NkM2PzY/Nj82HzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PCmvNj82PzY/Nj8yPzY/Nj82PzY/Nj82PzY/Mj82PzY/Nj8yPzY/Nj82PzI/Nj82PzY/Nj82PzY8Ka82PzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzY/Nj82PzY/NjwqO Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4992 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4252364681 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56320956e810, 0x56320975801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563209758020,0x56320b5f00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8025d8976c3ec3ba824ed20b2f65dfa14e90e17' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6313 processed earlier; will process 4716 files now Step #5: ==179788== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5632000639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5632066c8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5632066ab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5632066ab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563200069d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5631fffcab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5631fffc5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56320005bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56320302af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56320302af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56320302af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56320302af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56320302af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56320302af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56320302af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56320302af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56320302af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56320302af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5632052bff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563201fecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563201ff7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563201da3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563201da3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563201da4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563201da3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563201da3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563201da3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5632066adabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5632066b6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56320669e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5632066c9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fef62f2e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5631fffc3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x2d,0x2d,0xa,0x29,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x31,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x24,0x3a,0xa,0x2d,0x20,0x2d,0x3a,0xa,0x2d,0x2d,0x2d, Step #5: ---\012):\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\0121 $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- $:\012- -:\012--- Step #5: artifact_prefix='./'; Test unit written to ./oom-4c8c240fcea2769f23407349dae2867098bd464d Step #5: Base64: LS0tCik6Ci0gJDoKLSAkOgotICQ6Ci0gJDoKLSAkOgotICQ6Ci0gJDoKLSAkOgotICQ6Ci0gJDoKLSAkOgotICQ6Ci0gJDoKLSAkOgotICQ6Ci0gJDoKLSAkOgotICQ6Ci0gJDoKLSAkOgotICQ6Ci0gJDoKLSAkOgotICQ6Ci0gJDoKLSAkOgotICQ6Ci0gJDoKLSAkOgoxICQ6Ci0gJDoKLSAkOgotICQ6Ci0gJDoKLSAkOgotICQ6Ci0gJDoKLSAkOgotICQ6Ci0gJDoKLSAkOgotICQ6Ci0gLToKLS0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4993 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4252921336 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a6826ec810, 0x55a6828d601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a6828d6020,0x55a68476e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4c8c240fcea2769f23407349dae2867098bd464d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6314 processed earlier; will process 4715 files now Step #5: ==179824== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a6791e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a67f846898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a67f8295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a67f8294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a6791e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a679148b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a679143355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a6791d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a67c1a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a67c1a8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a67c1a8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a67c1a8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a67c1a8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a67c1a8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a67c1a8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a67c1a8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a67c1a8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a67c1a8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a67e43df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a67b16ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a67b175be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a67af21c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a67af21c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a67af22738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a67af21874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a67af21874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a67af21874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a67f82babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a67f834928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a67f81c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a67f847112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb7a08a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a679141b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x3d,0x7e,0x2d,0x3d,0x3d,0x25,0x3,0xd2,0x84,0x28,0xcb,0xb5,0x1,0x79,0x0,0x79,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x29,0x24,0xcb,0xbc,0xbc,0xbc,0xbc,0xb5, Step #5: ~$=~-==%\003\322\204(\313\265\001y\000y\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000)$\313\274\274\274\274\265 Step #5: artifact_prefix='./'; Test unit written to ./oom-7ba206d13742a1cd92b6e8d218c0e6dc2b472716 Step #5: Base64: fiQ9fi09PSUD0oQoy7UBeQB5AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACkky7y8vLy1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4994 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4253462229 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555aec19a810, 0x555aec38401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555aec384020,0x555aee21c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ba206d13742a1cd92b6e8d218c0e6dc2b472716' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6315 processed earlier; will process 4714 files now Step #5: ==179860== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555ae2c8f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ae92f4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ae92d75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ae92d74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ae2c95d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ae2bf6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ae2bf1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ae2c87c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ae5c56f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ae5c56f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ae5c56f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ae5c56f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ae5c56f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ae5c56f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ae5c56f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ae5c56f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ae5c56f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ae5c56f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555ae7eebf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ae4c18b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ae4c23be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ae49cfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ae49cfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ae49d0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ae49cf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ae49cf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ae49cf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ae92d9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ae92e2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ae92ca699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ae92f5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5ebcb58082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ae2befb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x44,0x5f,0x6e,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x44,0x5f,0x6e,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x44,0x5f,0x6e,0x4d, Step #5: ************************************************************************************************************************************************************************************************************D_n******D_n******D_nM Step #5: artifact_prefix='./'; Test unit written to ./oom-4489163b3ee04905c045c361b3eabd7ed3b87e9b Step #5: Base64: KioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqRF9uKioqKioqRF9uKioqKioqRF9uTQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4995 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4254000629 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556368b86810, 0x556368d7001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556368d70020,0x55636ac080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4489163b3ee04905c045c361b3eabd7ed3b87e9b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6316 processed earlier; will process 4713 files now Step #5: ==179896== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55635f67b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556365ce0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556365cc35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556365cc34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55635f681d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55635f5e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55635f5dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55635f673c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556362642f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556362642f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556362642f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556362642f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556362642f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556362642f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556362642f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556362642f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556362642f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556362642f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5563648d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556361604b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55636160fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5563613bbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5563613bbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5563613bc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5563613bb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5563613bb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5563613bb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556365cc5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556365cce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556365cb6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556365ce1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa8fb87082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55635f5dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x74,0x65,0x73,0x74,0x41,0x6c,0x6c,0x54,0x79,0x70,0x65,0x73,0x22,0x3a,0x7b,0x22,0x72,0x65,0x70,0x65,0x61,0x74,0x65,0x64,0x44,0x6f,0x75,0x62,0x6c,0x65,0x22,0x3a,0x5b,0x22,0x31,0xc5,0xbf,0x22,0x2c,0x22,0x32,0xc5,0xbf,0x22,0x2c,0x22,0x32,0xc5,0x91,0x22,0x2c,0x22,0x32,0xc5,0xb5,0x22,0x2c,0x22,0x32,0xc3,0xbf,0x22,0x2c,0x22,0x32,0xc5,0xbf,0x22,0x2c,0x22,0x32,0xc3,0xbf,0x22,0x2c,0x22,0x32,0xc5,0xbf,0x22,0x2c,0x22,0x31,0xc3,0xbf,0x22,0x2c,0x22,0x34,0xc5,0xb5,0x22,0x2c,0x22,0x30,0xc3,0xbf,0x22,0x2c,0x22,0x32,0xc5,0xbf,0x22,0x2c,0x22,0x32,0xc3,0xbf,0x22,0x2c,0x22,0x32,0xc5,0xbf,0x22,0x2c,0x22,0x31,0xc5,0xbf,0x22,0x2c,0x22,0x32,0xc3,0xbf,0x22,0x2c,0x22,0x32,0xc5,0xbf,0x22,0x2c,0x22,0x31,0xc5,0xbf,0x22,0x2c,0x22,0x32,0xdb,0x9f,0x22,0x2c,0x22,0x30,0xc5,0xbf,0x22,0x2c,0x22,0x32,0xc5,0xb5,0x22,0x2c,0x22,0x32,0xc3,0xbf,0x22,0x2c,0x22,0x32,0xc5,0xbf,0x22,0x2c,0x22,0x33,0xc5,0xaf,0x22,0x2c,0x22,0x31,0xc3,0xbf,0x22,0x2c,0x22,0x31,0xc3,0xbf,0x22,0x2c,0x22,0x32,0xc5,0xbf,0x22,0x2c,0x22,0x32,0xc3,0xbf,0x22,0x2c,0x22,0x32,0xc5,0xbf,0x22,0x2c,0x22,0x30,0xc5,0xbf,0x22,0x2c,0x22,0x33,0xdb,0x9f,0x22,0x2c,0x22,0x30,0xc5,0xbf,0x22, Step #5: {\"testAllTypes\":{\"repeatedDouble\":[\"1\305\277\",\"2\305\277\",\"2\305\221\",\"2\305\265\",\"2\303\277\",\"2\305\277\",\"2\303\277\",\"2\305\277\",\"1\303\277\",\"4\305\265\",\"0\303\277\",\"2\305\277\",\"2\303\277\",\"2\305\277\",\"1\305\277\",\"2\303\277\",\"2\305\277\",\"1\305\277\",\"2\333\237\",\"0\305\277\",\"2\305\265\",\"2\303\277\",\"2\305\277\",\"3\305\257\",\"1\303\277\",\"1\303\277\",\"2\305\277\",\"2\303\277\",\"2\305\277\",\"0\305\277\",\"3\333\237\",\"0\305\277\" Step #5: artifact_prefix='./'; Test unit written to ./oom-bba59e6ce81992e97ba24eab75bcdcf4d34d1adb Step #5: Base64: eyJ0ZXN0QWxsVHlwZXMiOnsicmVwZWF0ZWREb3VibGUiOlsiMcW/IiwiMsW/IiwiMsWRIiwiMsW1IiwiMsO/IiwiMsW/IiwiMsO/IiwiMsW/IiwiMcO/IiwiNMW1IiwiMMO/IiwiMsW/IiwiMsO/IiwiMsW/IiwiMcW/IiwiMsO/IiwiMsW/IiwiMcW/IiwiMtufIiwiMMW/IiwiMsW1IiwiMsO/IiwiMsW/IiwiM8WvIiwiMcO/IiwiMcO/IiwiMsW/IiwiMsO/IiwiMsW/IiwiMMW/IiwiM9ufIiwiMMW/Ig== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4996 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4254540504 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557146420810, 0x55714660a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55714660a020,0x5571484a20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bba59e6ce81992e97ba24eab75bcdcf4d34d1adb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6317 processed earlier; will process 4712 files now Step #5: ==179932== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55713cf159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55714357a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55714355d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55714355d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55713cf1bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55713ce7cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55713ce77355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55713cf0dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55713fedcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55713fedcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55713fedcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55713fedcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55713fedcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55713fedcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55713fedcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55713fedcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55713fedcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55713fedcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557142171f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55713ee9eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55713eea9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55713ec55c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55713ec55c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55713ec56738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55713ec55874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55713ec55874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55713ec55874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55714355fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557143568928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557143550699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55714357b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f184d9a1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55713ce75b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x7b,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0x20,0x20,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0xc,0x6e,0x61,0x6d,0x65,0x3a,0xd,0x22,0x44,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x27,0x38,0x66,0x27,0x20,0x20,0x20,0x20,0x5c,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x7e,0x7e,0xdf,0xbd,0x35,0x3c,0x27,0x27,0x37,0x2f,0x30,0x27,0x67,0x27,0x27,0x66,0x27,0x27,0x27,0x27,0x34,0xe2,0x81,0x7e,0x7e,0x7e,0x7e,0x7d,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x32,0x34,0x7e,0x7e,0x7e,0x7e,0x42,0x7e,0x7e,0x7e,0x7e,0x7d,0x7e,0xc7,0x72,0x7e,0x76,0x7e,0x7e,0x7e,0x7e,0x7e,0x1b,0x2d,0x32,0x32,0x39,0x30,0x7e,0x76,0x3b,0x78,0x4b,0xae,0xae,0xae,0xad,0x9,0x4b,0x4b,0x78,0x78,0x78,0x78,0x78,0x68,0xd7,0xdd,0x31,0x47,0x6d,0x65,0x3a,0x20,0x20,0x20,0x20,0x20,0x40,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x33,0x30,0x20,0x20,0x5c,0x27,0x20,0x20,0x20,0x3e,0x20,0x5c,0x30,0x30,0x30,0x5c,0x72,0x20,0x20,0x3c,0x46,0x20,0x3e,0x22,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x76,0x61,0x6c,0x20,0x7b,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x22,0x20,0x20,0x20,0x7d,0x20,0x7d,0xa,0xa,0x7d,0x20,0x7d,0xa,0x7d,0x7d, Step #5: p{doctype {\012mdecl { entity {\014name:\015\"D PUBLIC '8f' \\'http://~~\337\2755<''7/0'g''f''''4\342\201~~~~}~~~~~~~24~~~~B~~~~}~\307r~v~~~~~\033-2290~v;xK\256\256\256\255\011KKxxxxxh\327\3351Gme: @ 30 \\' > \\000\\r <F >\"ent {\012 val { name: \"D\" } }\012\012} }\012}} Step #5: artifact_prefix='./'; Test unit written to ./oom-cb438873764e281bb98f0d31cbc8e463e92ada13 Step #5: Base64: cHtkb2N0eXBlIHsKbWRlY2wgeyAgZW50aXR5IHsMbmFtZToNIkQgUFVCTElDICc4ZicgICAgXCdodHRwOi8vfn7fvTU8Jyc3LzAnZycnZicnJyc04oF+fn5+fX5+fn5+fn4yNH5+fn5Cfn5+fn1+x3J+dn5+fn5+Gy0yMjkwfnY7eEuurq6tCUtLeHh4eHho190xR21lOiAgICAgQCAgICAgICAgMzAgIFwnICAgPiBcMDAwXHIgIDxGID4iZW50IHsKICB2YWwgeyBuYW1lOiAiRCIgICB9IH0KCn0gfQp9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4997 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4255062042 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564964bb2810, 0x564964d9c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564964d9c020,0x564966c340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb438873764e281bb98f0d31cbc8e463e92ada13' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6318 processed earlier; will process 4711 files now Step #5: ==179968== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56495b6a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564961d0c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564961cef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564961cef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56495b6add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56495b60eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56495b609355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56495b69fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56495e66ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56495e66ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56495e66ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56495e66ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56495e66ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56495e66ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56495e66ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56495e66ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56495e66ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56495e66ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564960903f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56495d630b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56495d63bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56495d3e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56495d3e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56495d3e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56495d3e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56495d3e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56495d3e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564961cf1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564961cfa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564961ce2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564961d0d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f46959c0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56495b607b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x5b,0x5b,0x5f,0x3f,0x2d,0x31,0x5f,0x3f,0x33,0x33,0x32,0x32,0x32,0x32,0x75,0x5f,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x31,0x3a,0x5f,0x3f,0x24,0x31,0x3a,0x5f,0x3f,0x28,0x30,0x3a,0x5f,0x3f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x5f,0x3f,0x30,0x5f,0x3f,0x30,0x3a,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x5b,0x24,0x31,0x3a,0x5f,0x3f,0x30,0x38,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x5f,0x3f,0x30,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x6,0x30,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x5b,0x5b,0x5b,0x5f,0x3f,0x2d,0x31,0x5f,0x3f,0x33,0x33,0x32,0x32,0x32,0x32,0x75,0x5f,0x5f,0x3f,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x39,0x3a,0x5f,0x3f,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0x32,0x39,0x37,0x3a,0x5f,0x3f,0x24,0x31,0x3a,0x5f,0x3f,0x28,0x30,0x3a,0x5f,0x3f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x5f,0x3f,0x30,0x5f,0x3f,0x30,0x3a,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x5b,0x24,0x31,0x3a,0x5f,0x3f,0x30,0x38,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x30,0x5f,0x3f,0x30,0x5f,0x3f,0x30,0x3a,0x5f,0x3f,0x6,0x30,0x3a,0x5f,0x3f,0x30,0x3a,0x5f, Step #5: [[[_?-1_?332222u__?0:_?1:_?$1:_?(0:_??0:_?0:_?0_?0_?0::_?0:_?0:_[$1:_?08_?0:_?0:_?0:_?0_?0_?0:_?\0060:_?0:_[[[_?-1_?332222u__?2147483649:_?4294967297:_?$1:_?(0:_??0:_?0:_?0_?0_?0::_?0:_?0:_[$1:_?08_?0:_?0:_?0:_?0_?0_?0:_?\0060:_?0:_ Step #5: artifact_prefix='./'; Test unit written to ./oom-940730269712c19a43becd3ca7857ba552bbc62c Step #5: Base64: W1tbXz8tMV8/MzMyMjIydV9fPzA6Xz8xOl8/JDE6Xz8oMDpfPz8wOl8/MDpfPzBfPzBfPzA6Ol8/MDpfPzA6X1skMTpfPzA4Xz8wOl8/MDpfPzA6Xz8wXz8wXz8wOl8/BjA6Xz8wOl9bW1tfPy0xXz8zMzIyMjJ1X18/MjE0NzQ4MzY0OTpfPzQyOTQ5NjcyOTc6Xz8kMTpfPygwOl8/PzA6Xz8wOl8/MF8/MF8/MDo6Xz8wOl8/MDpfWyQxOl8/MDhfPzA6Xz8wOl8/MDpfPzBfPzBfPzA6Xz8GMDpfPzA6Xw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4998 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4255611445 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5621440bf810, 0x5621442a901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5621442a9020,0x5621461410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/940730269712c19a43becd3ca7857ba552bbc62c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6319 processed earlier; will process 4710 files now Step #5: #1 pulse cov: 4078 ft: 4079 exec/s: 0 rss: 176Mb Step #5: ==180004== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56213abb49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562141219898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5621411fc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5621411fc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56213abbad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56213ab1bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56213ab16355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56213abacc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56213db7bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56213db7bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56213db7bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56213db7bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56213db7bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56213db7bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56213db7bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56213db7bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56213db7bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56213db7bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56213fe10f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56213cb3db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56213cb48be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56213c8f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56213c8f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56213c8f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56213c8f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56213c8f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56213c8f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5621411feabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562141207928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5621411ef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56214121a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1f1628a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56213ab14b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x78,0x6d,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e,0x3c,0x78,0x6d,0x6c,0x3a,0x69,0x3e, Step #5: <xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:ixm><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i><xml:i> Step #5: artifact_prefix='./'; Test unit written to ./oom-8ec120c21b1b108af77269e1020ef108a6b3d918 Step #5: Base64: PHhtbDppPjx4bWw6aT48eG1sOmk+PHhtbDppPjx4bWw6aT48eG1sOmk+PHhtbDppPjx4bWw6aT48eG1sOmk+PHhtbDppPjx4bWw6aXhtPjx4bWw6aT48eG1sOmk+PHhtbDppPjx4bWw6aT48eG1sOmk+PHhtbDppPjx4bWw6aT48eG1sOmk+PHhtbDppPjx4bWw6aT48eG1sOmk+PHhtbDppPjx4bWw6aT48eG1sOmk+PHhtbDppPjx4bWw6aT48eG1sOmk+PHhtbDppPjx4bWw6aT48eG1sOmk+PHhtbDppPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4999 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4256171692 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f8c5c0d810, 0x55f8c5df701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f8c5df7020,0x55f8c7c8f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ec120c21b1b108af77269e1020ef108a6b3d918' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6321 processed earlier; will process 4708 files now Step #5: ==180040== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8bc7029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f8c2d67898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8c2d4a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8c2d4a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8bc708d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8bc669b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8bc664355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8bc6fac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8bf6c9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8bf6c9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8bf6c9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8bf6c9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8bf6c9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8bf6c9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8bf6c9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8bf6c9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8bf6c9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8bf6c9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f8c195ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f8be68bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f8be696be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8be442c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8be442c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8be443738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8be442874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8be442874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8be442874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f8c2d4cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f8c2d55928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f8c2d3d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f8c2d68112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb8c95a8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8bc662b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x64,0x3e,0xa,0xf4,0x8b,0x91,0x91,0x69,0x65,0xa,0xf4,0x8c,0x91,0x91,0xa,0xf4,0x8b,0x91,0x91,0xa,0xf4,0x8c,0x91,0x91,0x3e,0xa,0xf4,0x8b,0x91,0x91,0x69,0x65,0xa,0xf4,0x8c,0x91,0x91,0x73,0xa,0x3c,0x21,0x5b,0x43,0x44,0x41,0x54,0x41,0x5b,0x65,0xa,0xf4,0x8b,0x91,0x91,0x69,0x65,0xa,0xf4,0x8c,0x91,0x91,0x3e,0xa,0xf4,0x8b,0x91,0x91,0xa,0xf4,0x8b,0x91,0x91,0x65,0xa,0xf4,0x8c,0x91,0x91,0x73,0x3e,0xa,0xf4,0x8b,0x91,0x91,0x41,0x65,0xa,0xf4,0x8c,0x91,0x91,0x31,0xd,0xa,0xf4,0x8b,0x91,0x91,0xa,0xf4,0x8c,0x91,0x91,0x57,0xa,0xf4,0x8b,0x91,0x91,0x27,0x65,0xa,0xf4,0x8c,0x91,0x91,0xa,0xf4,0x8b,0x91,0x91,0x69,0x65,0x4e,0xa,0xf4,0x8c,0x91,0x91,0xa,0xf4,0x8b,0x91,0x91,0x69,0xa,0xf4,0x8c,0x91,0x89,0xa,0xf4,0x8b,0x91,0x91,0xa,0xf4,0x8b,0x91,0x91,0x73,0x3e,0xa,0xf4,0x8b,0x91,0x91,0x3b,0x3e,0xa,0xf4,0x8b,0x91,0x91,0x30,0x65,0xa,0xf4,0x8c,0x91,0x91,0xa,0xf4,0x8b,0x91,0x91,0x41,0x65,0xa,0xf4,0x8c,0x91,0x91,0x73,0x37,0xd,0xf4,0x8b,0x91,0x91,0xa,0xf4,0x8c,0x91,0x91,0x73,0x3e,0xa,0xf4,0x8b,0x91,0x91,0xa,0xf4,0x8c,0x91,0x91,0x3e,0xa,0xf4,0x8b,0x91,0x91,0x65,0xa,0xf4,0x8c,0x91,0x91,0xa,0xf4,0x8b,0x91,0x91,0xa, Step #5: <d>\012\364\213\221\221ie\012\364\214\221\221\012\364\213\221\221\012\364\214\221\221>\012\364\213\221\221ie\012\364\214\221\221s\012<![CDATA[e\012\364\213\221\221ie\012\364\214\221\221>\012\364\213\221\221\012\364\213\221\221e\012\364\214\221\221s>\012\364\213\221\221Ae\012\364\214\221\2211\015\012\364\213\221\221\012\364\214\221\221W\012\364\213\221\221'e\012\364\214\221\221\012\364\213\221\221ieN\012\364\214\221\221\012\364\213\221\221i\012\364\214\221\211\012\364\213\221\221\012\364\213\221\221s>\012\364\213\221\221;>\012\364\213\221\2210e\012\364\214\221\221\012\364\213\221\221Ae\012\364\214\221\221s7\015\364\213\221\221\012\364\214\221\221s>\012\364\213\221\221\012\364\214\221\221>\012\364\213\221\221e\012\364\214\221\221\012\364\213\221\221\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-c8d4ba32b9fd9728cabf03d5d0eb4fd510c3e927 Step #5: Base64: PGQ+CvSLkZFpZQr0jJGRCvSLkZEK9IyRkT4K9IuRkWllCvSMkZFzCjwhW0NEQVRBW2UK9IuRkWllCvSMkZE+CvSLkZEK9IuRkWUK9IyRkXM+CvSLkZFBZQr0jJGRMQ0K9IuRkQr0jJGRVwr0i5GRJ2UK9IyRkQr0i5GRaWVOCvSMkZEK9IuRkWkK9IyRiQr0i5GRCvSLkZFzPgr0i5GROz4K9IuRkTBlCvSMkZEK9IuRkUFlCvSMkZFzNw30i5GRCvSMkZFzPgr0i5GRCvSMkZE+CvSLkZFlCvSMkZEK9IuRkQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5000 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4256697699 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5561f317b810, 0x5561f336501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5561f3365020,0x5561f51fd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c8d4ba32b9fd9728cabf03d5d0eb4fd510c3e927' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6322 processed earlier; will process 4707 files now Step #5: ==180076== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5561e9c709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5561f02d5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5561f02b85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5561f02b84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5561e9c76d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5561e9bd7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5561e9bd2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5561e9c68c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5561ecc37f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5561ecc37f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5561ecc37f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5561ecc37f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5561ecc37f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5561ecc37f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5561ecc37f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5561ecc37f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5561ecc37f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5561ecc37f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5561eeeccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5561ebbf9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5561ebc04be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5561eb9b0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5561eb9b0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5561eb9b1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5561eb9b0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5561eb9b0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5561eb9b0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5561f02baabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5561f02c3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5561f02ab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5561f02d6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efde7df0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5561e9bd0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x28,0x42,0x3f,0x5f,0x28,0x29,0x3a,0x47,0x28,0x29,0x29,0x29,0x3f,0x28,0x28,0x28,0x28,0x6f,0x3f,0x5f,0x28,0x29,0x3a,0x24,0x28,0x29,0x29,0x29,0x3f,0x28,0x28,0x6f,0x29,0x3f,0x57,0x28,0x29,0x3a,0x6f,0x28,0x29,0x29,0x3a,0x6f,0x29,0x3f,0x57,0x28,0x29,0x3a,0x6f,0x28,0x29,0x29,0x3a,0x6f,0x28,0x28,0x42,0x3f,0x5f,0x28,0x29,0x3a,0x47,0x28,0x29,0x29,0x29,0x3f,0x28,0x28,0x28,0x28,0x6f,0x3f,0x5f,0x28,0x29,0x3a,0x24,0x28,0x29,0x29,0x29,0x3f,0x28,0x28,0x6f,0x29,0x3f,0x57,0x28,0x29,0x3a,0x6f,0x28,0x29,0x29,0x3a,0x6f,0x29,0x3f,0x57,0x28,0x29,0x3a,0x6f,0x28,0x29,0x29,0x3a,0x6f,0x28,0x28,0x42,0x3f,0x5f,0x28,0x29,0x3a,0x47,0x28,0x29,0x29,0x29,0x3f,0x28,0x28,0x28,0x28,0x6f,0x3f,0x5f,0x28,0x29,0x3a,0x24,0x28,0x29,0x29,0x29,0x3f,0x28,0x28,0x6f,0x29,0x3f,0x57,0x28,0x29,0x3a,0x6f,0x28,0x29,0x29,0x3a,0x6f,0x29,0x3f,0x57,0x28,0x29,0x3a,0x6f,0x28,0x29,0x29,0x3a,0x28,0x28,0x42,0x3f,0x5f,0x28,0x29,0x3a,0x47,0x28,0x29,0x29,0x29,0x3f,0x28,0x28,0x28,0x28,0x6f,0x3f,0x5f,0x28,0x29,0x3a,0x24,0x28,0x29,0x29,0x29,0x3f,0x28,0x28,0x6f,0x29,0x3f,0x57,0x28,0x29,0x3a,0x6f,0x28,0x29,0x29,0x3a,0x6f,0x29,0x3f,0x57,0x28,0x29,0x3a,0x6f,0x28,0x29,0x29,0x3a,0x6f, Step #5: ((B?_():G()))?((((o?_():$()))?((o)?W():o()):o)?W():o()):o((B?_():G()))?((((o?_():$()))?((o)?W():o()):o)?W():o()):o((B?_():G()))?((((o?_():$()))?((o)?W():o()):o)?W():o()):((B?_():G()))?((((o?_():$()))?((o)?W():o()):o)?W():o()):o Step #5: artifact_prefix='./'; Test unit written to ./oom-ca44f5ee255146cf6c29604aa2a300f870ccac80 Step #5: Base64: KChCP18oKTpHKCkpKT8oKCgobz9fKCk6JCgpKSk/KChvKT9XKCk6bygpKTpvKT9XKCk6bygpKTpvKChCP18oKTpHKCkpKT8oKCgobz9fKCk6JCgpKSk/KChvKT9XKCk6bygpKTpvKT9XKCk6bygpKTpvKChCP18oKTpHKCkpKT8oKCgobz9fKCk6JCgpKSk/KChvKT9XKCk6bygpKTpvKT9XKCk6bygpKTooKEI/XygpOkcoKSkpPygoKChvP18oKTokKCkpKT8oKG8pP1coKTpvKCkpOm8pP1coKTpvKCkpOm8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5001 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4257229584 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e0a30e810, 0x555e0a4f801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e0a4f8020,0x555e0c3900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca44f5ee255146cf6c29604aa2a300f870ccac80' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6323 processed earlier; will process 4706 files now Step #5: #1 pulse cov: 4008 ft: 4009 exec/s: 0 rss: 175Mb Step #5: ==180112== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555e00e039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e07468898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e0744b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e0744b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e00e09d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e00d6ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e00d65355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e00dfbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e03dcaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e03dcaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e03dcaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e03dcaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e03dcaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e03dcaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e03dcaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e03dcaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e03dcaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e03dcaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e0605ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e02d8cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e02d97be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e02b43c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e02b43c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e02b44738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e02b43874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e02b43874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e02b43874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e0744dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e07456928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e0743e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e07469112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f32f86d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e00d63b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x1,0x0,0x0,0x0,0x18,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x3a,0x30,0x33,0x2a,0xcb,0x2e,0x30,0x2e,0x31,0x3a,0x38,0x39,0x40,0x30,0x2f,0x36,0x34,0x0,0x2,0x0,0x0,0x0,0xb5,0x48,0x54,0x54,0x50,0x2f,0x31,0x2e,0x31,0x20,0x34,0x30,0x31,0x20,0x41,0x75,0x74,0x68,0x6f,0x7a,0x69,0xa,0x57,0x57,0x57,0x2d,0x41,0x75,0x74,0x68,0x65,0x6e,0x74,0x69,0x63,0x61,0x74,0x65,0x3a,0x20,0x44,0x69,0x67,0x65,0x73,0x74,0x20,0x72,0x65,0x5e,0x6c,0x6d,0x3d,0x22,0x74,0x61,0x73,0x74,0x72,0x65,0x61,0x2c,0x53,0x52,0x50,0x2d,0x44,0x53,0x53,0x2d,0x32,0x44,0x45,0x53,0x2d,0x45,0x44,0x45,0x2d,0x43,0x42,0x6d,0x2c,0x22,0x20,0x6e,0x6f,0x6e,0x63,0x65,0x3d,0x2c,0x31,0x33,0x30,0x26,0xf3,0x2b,0x4e,0x31,0x42,0x54,0x74,0x50,0x2f,0x20,0xa,0x54,0x72,0x61,0x6e,0x73,0x66,0x45,0x72,0x2d,0x65,0x6e,0x63,0x6f,0x64,0x69,0x6e,0x67,0x3a,0x63,0x68,0x75,0x6e,0x6b,0x65,0x64,0xce,0x90,0x20,0xa,0xa,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x40,0x2c,0x39,0x2c,0x49,0x32,0xa,0xa,0x0,0x23,0x0,0x0,0x0,0x5,0x6a,0x65,0x6d,0x65,0x73,0x0,0x4,0x0,0x0,0x0,0x4,0x62,0xd3,0x6e,0x64,0x0,0x10,0x0,0x0,0x0,0x4,0x0,0x50,0x2f,0xee, Step #5: \000\001\000\000\000\030http://:03*\313.0.1:89@0/64\000\002\000\000\000\265HTTP/1.1 401 Authozi\012WWW-Authenticate: Digest re^lm=\"tastrea,SRP-DSS-2DES-EDE-CBm,\" nonce=,130&\363+N1BTtP/ \012TransfEr-encoding:chunked\316\220 \012\0120000000000000000@,9,I2\012\012\000#\000\000\000\005jemes\000\004\000\000\000\004b\323nd\000\020\000\000\000\004\000P/\356 Step #5: artifact_prefix='./'; Test unit written to ./oom-75cd343ae8c01a9a414ef824570e841e5781bfa3 Step #5: Base64: AAEAAAAYaHR0cDovLzowMyrLLjAuMTo4OUAwLzY0AAIAAAC1SFRUUC8xLjEgNDAxIEF1dGhvemkKV1dXLUF1dGhlbnRpY2F0ZTogRGlnZXN0IHJlXmxtPSJ0YXN0cmVhLFNSUC1EU1MtMkRFUy1FREUtQ0JtLCIgbm9uY2U9LDEzMCbzK04xQlR0UC8gClRyYW5zZkVyLWVuY29kaW5nOmNodW5rZWTOkCAKCjAwMDAwMDAwMDAwMDAwMDBALDksSTIKCgAjAAAABWplbWVzAAQAAAAEYtNuZAAQAAAABABQL+4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5002 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4257784787 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560c2e6df810, 0x560c2e8c901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560c2e8c9020,0x560c307610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/75cd343ae8c01a9a414ef824570e841e5781bfa3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6325 processed earlier; will process 4704 files now Step #5: #1 pulse cov: 4277 ft: 4278 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4418 ft: 4877 exec/s: 0 rss: 177Mb Step #5: ==180148== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560c251d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560c2b839898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560c2b81c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560c2b81c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560c251dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560c2513bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560c25136355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560c251ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560c2819bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560c2819bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560c2819bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560c2819bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560c2819bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560c2819bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560c2819bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560c2819bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560c2819bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560c2819bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560c2a430f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560c2715db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560c27168be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560c26f14c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560c26f14c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560c26f15738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560c26f14874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560c26f14874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560c26f14874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560c2b81eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560c2b827928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560c2b80f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560c2b83a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ad92d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560c25134b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x45,0x27,0x28,0x32,0x5c,0xed,0x82,0xb9,0xed,0x82,0xb9,0xa,0xed,0x82,0xb9,0x20,0x2d,0x20,0x2d,0xa,0x32,0xa,0xed,0x82,0xb9,0x20,0x2d,0xa,0x32,0x5c,0xed,0x82,0xb9,0xed,0x82,0xb9,0xa,0x54,0x5c,0x13,0xed,0x82,0xb9,0xed,0x82,0xb9,0xa,0xed,0x82,0xb9,0x6b,0x20,0xa,0x2d,0xa,0x2d,0x10,0x32,0x5c,0x20,0x31,0x5c,0xed,0x82,0xb9,0xed,0x89,0xb9,0x20,0x2d,0x32,0x5c,0xed,0x8a,0xb9,0xed,0x82,0xb9,0xa,0xed,0x82,0xb9,0x20,0x2d,0xa,0x36,0x35,0x35,0x33,0x35,0x5c,0xed,0x92,0xb9,0xed,0x82,0xb9,0xa,0xed,0x82,0xb9,0xed,0x82,0xb9,0xa,0xed,0x82,0xb9,0x20,0x2d,0xed,0x82,0xb9,0xed,0x82,0xb9,0xa,0xed,0x82,0xb9,0x6b,0x2d,0xf3,0xa0,0x81,0x93,0xa,0x2d,0x10,0xce,0x99,0x20,0x31,0x5c,0xed,0x82,0xb9,0xed,0x89,0xb9,0x20,0xa,0x32,0xa,0xed,0x82,0xb9,0x20,0x2d,0xa,0x32,0x5c,0xed,0x92,0xb9,0xed,0x82,0xb9,0x5c,0xed,0x92,0xb9,0xed,0x82,0xb9,0xa,0xed,0x82,0xb9,0xed,0x82,0xb9,0xa,0xed,0x82,0xb9,0x20,0x2d,0xa,0x32,0xa,0xed,0x82,0xb9,0x20,0x2d,0xa,0x32,0x5c,0xed,0x63,0x6f,0xb9,0x41,0xa,0xa,0x32,0xb9,0x82,0xed,0x92,0xb9,0xed,0x82,0xb9,0xed,0x89,0xb9,0x20,0x2d,0x32,0x2d,0xa,0x2d,0x10,0xed,0x82,0x8a,0xb9,0xed,0x82,0xb9,0xa,0xed,0x2d,0x2,0x2d,0x27, Step #5: E'(2\\\355\202\271\355\202\271\012\355\202\271 - -\0122\012\355\202\271 -\0122\\\355\202\271\355\202\271\012T\\\023\355\202\271\355\202\271\012\355\202\271k \012-\012-\0202\\ 1\\\355\202\271\355\211\271 -2\\\355\212\271\355\202\271\012\355\202\271 -\01265535\\\355\222\271\355\202\271\012\355\202\271\355\202\271\012\355\202\271 -\355\202\271\355\202\271\012\355\202\271k-\363\240\201\223\012-\020\316\231 1\\\355\202\271\355\211\271 \0122\012\355\202\271 -\0122\\\355\222\271\355\202\271\\\355\222\271\355\202\271\012\355\202\271\355\202\271\012\355\202\271 -\0122\012\355\202\271 -\0122\\\355co\271A\012\0122\271\202\355\222\271\355\202\271\355\211\271 -2-\012-\020\355\202\212\271\355\202\271\012\355-\002-' Step #5: artifact_prefix='./'; Test unit written to ./oom-b2696f03baab307cb4d1592d618caf0f803a4969 Step #5: Base64: RScoMlztgrntgrkK7YK5IC0gLQoyCu2CuSAtCjJc7YK57YK5ClRcE+2Cue2CuQrtgrlrIAotCi0QMlwgMVztgrntibkgLTJc7Yq57YK5Cu2CuSAtCjY1NTM1XO2Sue2CuQrtgrntgrkK7YK5IC3tgrntgrkK7YK5ay3zoIGTCi0QzpkgMVztgrntibkgCjIK7YK5IC0KMlztkrntgrlc7ZK57YK5Cu2Cue2CuQrtgrkgLQoyCu2CuSAtCjJc7WNvuUEKCjK5gu2Sue2Cue2JuSAtMi0KLRDtgoq57YK5Cu0tAi0n Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5003 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4258386810 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558fd0579810, 0x558fd076301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558fd0763020,0x558fd25fb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b2696f03baab307cb4d1592d618caf0f803a4969' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6328 processed earlier; will process 4701 files now Step #5: #1 pulse cov: 3964 ft: 3965 exec/s: 0 rss: 175Mb Step #5: #2 pulse cov: 4264 ft: 4790 exec/s: 0 rss: 176Mb Step #5: ==180184== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558fc706e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558fcd6d3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558fcd6b65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558fcd6b64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558fc7074d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558fc6fd5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558fc6fd0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558fc7066c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558fca035f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558fca035f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558fca035f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558fca035f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558fca035f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558fca035f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558fca035f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558fca035f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558fca035f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558fca035f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558fcc2caf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558fc8ff7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558fc9002be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558fc8daec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558fc8daec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558fc8daf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558fc8dae874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558fc8dae874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558fc8dae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558fcd6b8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558fcd6c1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558fcd6a9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558fcd6d4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2449b21082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558fc6fceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x41,0x64,0x41,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x41,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x54,0x54,0x54,0x54,0x54,0x54,0x70,0x70,0x30,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x64,0x41,0x41,0x41,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x54,0x70,0x2f,0x70,0x30,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x78,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x64,0x65,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: s-----BEGIN -----\012AdApppppppppppppppppppppATTTTTTTTppppppppppppppppppppppppppTTTTTTpp0pppppppppppppppppppppppppppppppppppppdAAATTTTTTTTTTTTTTTTTTTTTp/p0ppppppppxpppppppppppppppppppppppppppppppppppppppppppppppppppde\012-----END ----- Step #5: artifact_prefix='./'; Test unit written to ./oom-08d3cf6a67825ecfa94465d160a0c6935ca52906 Step #5: Base64: cy0tLS0tQkVHSU4gLS0tLS0KQWRBcHBwcHBwcHBwcHBwcHBwcHBwcHBwQVRUVFRUVFRUcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBUVFRUVFRwcDBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwZEFBQVRUVFRUVFRUVFRUVFRUVFRUVFRUVHAvcDBwcHBwcHBwcHhwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBkZQotLS0tLUVORCAtLS0tLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5004 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4258991161 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56451e944810, 0x56451eb2e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56451eb2e020,0x5645209c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08d3cf6a67825ecfa94465d160a0c6935ca52906' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6331 processed earlier; will process 4698 files now Step #5: ==180220== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5645154399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56451ba9e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56451ba815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56451ba814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56451543fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5645153a0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56451539b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564515431c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564518400f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564518400f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564518400f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564518400f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564518400f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564518400f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564518400f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564518400f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564518400f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564518400f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56451a695f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5645173c2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5645173cdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564517179c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564517179c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56451717a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564517179874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564517179874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564517179874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56451ba83abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56451ba8c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56451ba74699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56451ba9f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe927a22082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564515399b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x38,0x37,0x30,0x6d,0x75,0x38,0x38,0x32,0x30,0x35,0x32,0x38,0x36,0x30,0x30,0x32,0x30,0x35,0x38,0x36,0x37,0x33,0x30,0x6b,0xa,0x62,0x6c,0x69,0x0,0x36,0x39,0x6e,0x6f,0x5,0x30,0x38,0x21,0x6f,0x21,0x21,0x29,0x21,0x21,0x21,0x21,0x21,0x21,0x62,0x72,0x69,0x67,0x41,0xd8,0x99,0x6e,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x6f,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0xd8,0x99,0x6e,0x6f,0x75,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x21,0x6e,0x6f,0x2d,0x0,0x0,0x0,0x0,0x3,0x0,0x0,0x0,0x0,0x21,0x21,0x0,0x0,0x21,0x21,0x0,0xc2,0x0,0xf6,0xff,0x0,0x0,0x0,0x3,0x0,0x0,0x0,0x0,0x0,0x0,0xe4,0xe4,0x76,0x75,0x0,0xe4,0xe4,0xe4,0xe4,0xe4,0xe4,0xe4,0xe4,0xe4,0xe4,0xe4,0xe4,0xe4,0xe4,0xe4,0x74,0x77,0x68,0x69,0x30,0x30,0x30,0x30,0x30,0x30,0x80,0x0,0x0,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x0,0x0,0x0,0x0,0x0,0x69,0x67,0x68,0x74,0x77,0x68,0x69,0x64,0x65,0x66,0x30,0x30,0x30,0x62,0x0,0x0,0xe4,0xe4, Step #5: 870mu882052860020586730k\012bli\00069no\00508!o!!)!!!!!!brigA\330\231n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!o!!!!!!!!!!!!!\330\231nou!!!!!!!!!!!!!!!!!!!!!no-\000\000\000\000\003\000\000\000\000!!\000\000!!\000\302\000\366\377\000\000\000\003\000\000\000\000\000\000\344\344vu\000\344\344\344\344\344\344\344\344\344\344\344\344\344\344\344twhi000000\200\000\0000000000000\000\000\000\000\000ightwhidef000b\000\000\344\344 Step #5: artifact_prefix='./'; Test unit written to ./oom-6eebba8e45c0e5094f6c1eadade213cb51b0f9f9 Step #5: Base64: ODcwbXU4ODIwNTI4NjAwMjA1ODY3MzBrCmJsaQA2OW5vBTA4IW8hISkhISEhISFicmlnQdiZbiEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhISEhbyEhISEhISEhISEhISHYmW5vdSEhISEhISEhISEhISEhISEhISEhIW5vLQAAAAADAAAAACEhAAAhIQDCAPb/AAAAAwAAAAAAAOTkdnUA5OTk5OTk5OTk5OTk5OTkdHdoaTAwMDAwMIAAADAwMDAwMDAwMDAAAAAAAGlnaHR3aGlkZWYwMDBiAADk5A== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5005 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4259508348 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bd28684810, 0x55bd2886e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bd2886e020,0x55bd2a7060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6eebba8e45c0e5094f6c1eadade213cb51b0f9f9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6332 processed earlier; will process 4697 files now Step #5: ==180256== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bd1f1799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bd257de898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bd257c15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bd257c14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bd1f17fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bd1f0e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bd1f0db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bd1f171c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bd22140f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bd22140f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bd22140f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bd22140f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bd22140f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bd22140f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bd22140f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bd22140f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bd22140f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bd22140f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bd243d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bd21102b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bd2110dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bd20eb9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bd20eb9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bd20eba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bd20eb9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bd20eb9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bd20eb9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bd257c3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bd257cc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bd257b4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bd257df112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7916fb9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bd1f0d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2b,0x4a,0x9,0x12,0xa,0xa,0x29,0x5c,0x9,0x5c,0x9,0x29,0xa,0x5c,0x9,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x9,0x12,0xa,0xa,0x29,0x5c,0x9,0x5c,0x9,0x29,0xa,0x5c,0x9,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x63,0x72,0x79,0x73,0x74,0x61,0x6c,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x44,0x60,0x40,0x60,0x40,0x5c,0x9,0x60,0x40,0x60,0x40, Step #5: +J\011\022\012\012)\\\011\\\011)\012\\\011DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD\011\022\012\012)\\\011\\\011)\012\\\011DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD\001\000\000\000\000\000\000\000DDDDDDDDDDDDDDDDDDcrystalDDDDDDDDDDDDDDDD`@`@\\\011`@`@ Step #5: artifact_prefix='./'; Test unit written to ./oom-fa35b01066d065d41e73d1c19b5b9ecc33daff9e Step #5: Base64: K0oJEgoKKVwJXAkpClwJRERERERERERERERERERERERERERERERERERERERERERERERERERERERERAkSCgopXAlcCSkKXAlEREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREREQBAAAAAAAAAERERERERERERERERERERERERGNyeXN0YWxEREREREREREREREREREREYEBgQFwJYEBgQA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5006 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4260163707 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563f53d9d810, 0x563f53f8701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563f53f87020,0x563f55e1f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fa35b01066d065d41e73d1c19b5b9ecc33daff9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6333 processed earlier; will process 4696 files now Step #5: ==180292== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563f4a8929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563f50ef7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563f50eda5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563f50eda4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563f4a898d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563f4a7f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563f4a7f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563f4a88ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563f4d859f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563f4d859f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563f4d859f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563f4d859f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563f4d859f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563f4d859f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563f4d859f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563f4d859f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563f4d859f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563f4d859f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563f4faeef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563f4c81bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563f4c826be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563f4c5d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563f4c5d2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563f4c5d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563f4c5d2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563f4c5d2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563f4c5d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563f50edcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563f50ee5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563f50ecd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563f50ef8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8dd0ad0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563f4a7f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2a,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x60,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x9,0x4e,0x20,0x2d, Step #5: `-----BEG\011N -----\012`-----BEG\011N -----\012`--\000\000\000\000\000\000\000\000---BEG\011N -----\012`-----BEG\011N -----\012`-----BEG\011N -----\012`-----BEG\011N -----\012`-----BEG\011N -----\012`-----BEG\011N -----\012`---*--BEG\011N -----\012`-----BEG\011N -----\012` \000\000\000\000\000\000\000-----BEG\011N ------\012`-----BEG\011N - Step #5: artifact_prefix='./'; Test unit written to ./oom-198448edecfd14be133b3473b8515ebbe8c4cacf Step #5: Base64: YC0tLS0tQkVHCU4gLS0tLS0KYC0tLS0tQkVHCU4gLS0tLS0KYC0tAAAAAAAAAAAtLS1CRUcJTiAtLS0tLQpgLS0tLS1CRUcJTiAtLS0tLQpgLS0tLS1CRUcJTiAtLS0tLQpgLS0tLS1CRUcJTiAtLS0tLQpgLS0tLS1CRUcJTiAtLS0tLQpgLS0tLS1CRUcJTiAtLS0tLQpgLS0tKi0tQkVHCU4gLS0tLS0KYC0tLS0tQkVHCU4gLS0tLS0KYCAAAAAAAAAALS0tLS1CRUcJTiAtLS0tLS0KYC0tLS0tQkVHCU4gLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5007 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4260814534 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c92ce46810, 0x55c92d03001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c92d030020,0x55c92eec80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/198448edecfd14be133b3473b8515ebbe8c4cacf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6334 processed earlier; will process 4695 files now Step #5: ==180328== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c92393b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c929fa0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c929f835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c929f834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c923941d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9238a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c92389d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c923933c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c926902f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c926902f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c926902f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c926902f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c926902f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c926902f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c926902f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c926902f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c926902f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c926902f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c928b97f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9258c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9258cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c92567bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c92567bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c92567c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c92567b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c92567b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c92567b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c929f85abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c929f8e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c929f76699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c929fa1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0072895082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c92389bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x25,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x25,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xc,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x25,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0xd,0x24,0xa,0x7b,0xd,0x2d,0x73,0x9,0x8,0xde,0xad,0xbe,0xef,0xef, Step #5: \007{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015%\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015%\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\014$\012{\015-s\015%\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\015$\012{\015-s\011\010\336\255\276\357\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-085487789f59cd047324c80196c080048502873d Step #5: Base64: B3sNLXMNJAp7DS1zDSQKew0tcw0kCnsNLXMNJAp7DS1zDSQKew0tcw0kCnsNLXMNJAp7DS1zDSQKew0tcw0kCnsNLXMNJAp7DS1zDSUKew0tcw0kCnsNLXMNJAp7DS1zDSQKew0tcw0kCnsNLXMNJAp7DS1zDSUKew0tcw0kCnsNLXMNJAp7DS1zDSQKew0tcwwkCnsNLXMNJQp7DS1zDSQKew0tcw0kCnsNLXMNJAp7DS1zDSQKew0tcw0kCnsNLXMNJAp7DS1zDSQKew0tcw0kCnsNLXMNJAp7DS1zCQjerb7v7w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5008 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4261351070 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5589c8b1e810, 0x5589c8d0801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5589c8d08020,0x5589caba00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/085487789f59cd047324c80196c080048502873d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6335 processed earlier; will process 4694 files now Step #5: ==180364== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5589bf6139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5589c5c78898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589c5c5b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589c5c5b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5589bf619d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5589bf57ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5589bf575355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5589bf60bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5589c25daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5589c25daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5589c25daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5589c25daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5589c25daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5589c25daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5589c25daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5589c25daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5589c25daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5589c25daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589c486ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5589c159cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5589c15a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5589c1353c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5589c1353c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5589c1354738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5589c1353874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5589c1353874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5589c1353874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5589c5c5dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5589c5c66928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5589c5c4e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5589c5c79112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f849824f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5589bf573b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0x7b,0x7d,0x29,0x3d,0x3e,0x71,0x3d,0x3e,0x28,0x7b,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x24,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x6c,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x6c,0x24,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x24,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x24,0x3d,0x71,0x3d,0x3e,0x28,0x7b,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x24,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x24,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x6c,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x6c,0x24,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x7d,0x29,0x3d,0x3e,0x79,0x3d,0x28,0x7b,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x24,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x24,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x6c,0x24,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x6c,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x24,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x7d,0x29,0x3d,0x3e,0x79,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x7d,0x29,0x3d,0x3e,0x71,0x3d,0x3e,0x28,0x7b,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x6c,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x6c,0x24,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x6c,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x24,0x7d,0x29,0x3d,0x3e,0x28,0x7b,0x24,0x7d,0x29,0x3d,0x3e,0x79, Step #5: ({})=>q=>({})=>({$})=>({l})=>({l$})=>({})=>({$})=>({$=q=>({})=>({$})=>({$})=>({l})=>({l$})=>({})=>({})=>({})=>y=({})=>({$})=>({$})=>({})=>({l$})=>({l})=>({$})=>({})=>y})=>({})=>q=>({})=>({})=>({l})=>({l$})=>({l})=>({$})=>({$})=>y Step #5: artifact_prefix='./'; Test unit written to ./oom-2cb72345dcaf6adf99eb6d12b4b0e38e100820c4 Step #5: Base64: KHt9KT0+cT0+KHt9KT0+KHskfSk9Pih7bH0pPT4oe2wkfSk9Pih7fSk9Pih7JH0pPT4oeyQ9cT0+KHt9KT0+KHskfSk9Pih7JH0pPT4oe2x9KT0+KHtsJH0pPT4oe30pPT4oe30pPT4oe30pPT55PSh7fSk9Pih7JH0pPT4oeyR9KT0+KHt9KT0+KHtsJH0pPT4oe2x9KT0+KHskfSk9Pih7fSk9Pnl9KT0+KHt9KT0+cT0+KHt9KT0+KHt9KT0+KHtsfSk9Pih7bCR9KT0+KHtsfSk9Pih7JH0pPT4oeyR9KT0+eQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5009 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4261886006 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559383002810, 0x5593831ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5593831ec020,0x5593850840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2cb72345dcaf6adf99eb6d12b4b0e38e100820c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6336 processed earlier; will process 4693 files now Step #5: ==180400== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559379af79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55938015c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55938013f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55938013f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559379afdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559379a5eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559379a59355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559379aefc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55937cabef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55937cabef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55937cabef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55937cabef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55937cabef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55937cabef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55937cabef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55937cabef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55937cabef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55937cabef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55937ed53f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55937ba80b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55937ba8bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55937b837c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55937b837c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55937b838738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55937b837874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55937b837874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55937b837874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559380141abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55938014a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559380132699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55938015d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f595460a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559379a57b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x49,0x33,0x4d,0x4,0xe2,0x80,0xae,0x4,0x4,0xe2,0x80,0xae,0x61,0x30,0x64,0x61,0xf,0x0,0x0,0x0,0x33,0x4,0xe2,0x80,0xae,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x41,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xf,0x0,0x0,0x0,0x33,0x4,0xe2,0x80,0xae,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xe2,0x80,0xae,0x61,0xe2,0x83,0xae,0xa6,0xcd,0x9e,0xef,0xfd,0xb9,0x32,0x22, Step #5: ID3I3M\004\342\200\256\004\004\342\200\256a0da\017\000\000\0003\004\342\200\256\004\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000;\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000A\000\000\000\000\000\000\000\000\000\000\000\000\017\000\000\0003\004\342\200\256\004\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\342\200\256a\342\203\256\246\315\236\357\375\2712\" Step #5: artifact_prefix='./'; Test unit written to ./oom-b1abb8c884a8d8de736d03e18325b5a22c497f6f Step #5: Base64: SUQzSTNNBOKArgQE4oCuYTBkYQ8AAAAzBOKArgQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA7AAAAAAAAAAAAAAAAAAAAAEEAAAAAAAAAAAAAAAAPAAAAMwTigK4EAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADigK5h4oOups2e7/25MiI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5010 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4262409471 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563469203810, 0x5634693ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5634693ed020,0x56346b2850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b1abb8c884a8d8de736d03e18325b5a22c497f6f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6337 processed earlier; will process 4692 files now Step #5: #1 pulse cov: 11671 ft: 11672 exec/s: 0 rss: 196Mb Step #5: ==180436== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56345fcf89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56346635d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634663405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634663404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56345fcfed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56345fc5fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56345fc5a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56345fcf0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563462cbff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563462cbff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563462cbff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563462cbff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563462cbff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563462cbff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563462cbff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563462cbff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563462cbff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563462cbff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563464f54f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563461c81b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563461c8cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563461a38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563461a38c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563461a39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563461a38874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563461a38874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563461a38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563466342abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56346634b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563466333699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56346635e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9216a23082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56345fc58b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x10,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x60,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x2f,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x5,0x0,0x2,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0xa,0x3d,0x3d,0x3d,0xa,0x3d,0xa,0x44,0x11,0x0,0x7,0x0,0xce,0x93,0x1,0x60,0x54,0x34,0x2,0x6d,0x1,0x0,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN \020----\012N\012=-\012----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012`=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=/\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\005\000\002\000=\012=\012=\012=\012=\012=\012=\012\012\012===\012=\012D\021\000\007\000\316\223\001`T4\002m\001\000\000\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-500dee71fe270dbe933cf6475d5e3e27bc4330e5 Step #5: Base64: BS0tLS0tQkVHSU4gEC0tLS0KTgo9LQotLS0tCk4KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9CmA9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Lwo9PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9CgUAAgA9Cj0KPQo9Cj0KPQo9CgoKPT09Cj0KRBEABwDOkwFgVDQCbQEAAAo9Cj0KPQo9Cj0KPQoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5011 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4263148977 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a4dd38d810, 0x55a4dd57701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a4dd577020,0x55a4df40f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/500dee71fe270dbe933cf6475d5e3e27bc4330e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6339 processed earlier; will process 4690 files now Step #5: ==180472== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a4d3e829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a4da4e7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a4da4ca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a4da4ca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a4d3e88d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a4d3de9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a4d3de4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a4d3e7ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a4d6e49f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a4d6e49f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a4d6e49f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a4d6e49f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a4d6e49f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a4d6e49f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a4d6e49f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a4d6e49f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a4d6e49f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a4d6e49f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a4d90def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a4d5e0bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a4d5e16be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a4d5bc2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a4d5bc2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a4d5bc3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a4d5bc2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a4d5bc2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a4d5bc2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a4da4ccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a4da4d5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a4da4bd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a4da4e8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe0c92a9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a4d3de2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3e,0x3f,0x2d,0xd,0x2d,0xd,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d,0xd,0x2d,0x20,0x2d,0xd,0x2d,0x20,0x2d,0x20,0x2d,0xd,0x2d,0x2d,0x2d, Step #5: >?-\015-\015-\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015---\015- -\015- - -\015--- Step #5: artifact_prefix='./'; Test unit written to ./oom-a00706e91b0cddb5e53ecb71004b4fa65c882d25 Step #5: Base64: Pj8tDS0NLQ0tIC0NLSAtIC0NLS0tDS0gLQ0tIC0gLQ0tLS0NLSAtDS0gLSAtDS0tLQ0tIC0NLSAtIC0NLS0tDS0gLQ0tIC0gLQ0tLS0NLSAtDS0gLSAtDS0tLQ0tIC0NLSAtIC0NLS0tDS0gLQ0tIC0gLQ0tLS0NLSAtDS0gLSAtDS0tLQ0tIC0NLSAtIC0NLS0tDS0gLQ0tIC0gLQ0tLS0NLSAtDS0gLSAtDS0tLQ0tIC0NLSAtIC0NLS0tDS0gLQ0tIC0gLQ0tLS0NLSAtDS0gLSAtDS0tLQ0tIC0NLSAtIC0NLS0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5012 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4263757063 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7636be810, 0x55b7638a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7638a8020,0x55b7657400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a00706e91b0cddb5e53ecb71004b4fa65c882d25' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6340 processed earlier; will process 4689 files now Step #5: ==180508== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b75a1b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b760818898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b7607fb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b7607fb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b75a1b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b75a11ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b75a115355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b75a1abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b75d17af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b75d17af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b75d17af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b75d17af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b75d17af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b75d17af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b75d17af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b75d17af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b75d17af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b75d17af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b75f40ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b75c13cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b75c147be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b75bef3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b75bef3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b75bef4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b75bef3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b75bef3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b75bef3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b7607fdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b760806928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b7607ee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b760819112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fadd4739082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b75a113b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x7e,0x7e,0x3c,0xdb,0xbe,0x7e,0x7e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x7e,0x12,0x0,0x0,0x0,0x7e,0x7e,0x3f,0x3c,0xdb,0xbe,0x7e,0x7e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x7e,0x12,0x0,0x0,0x0,0x7e,0x7e,0x3f,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x12,0x0,0x0,0x0,0x67,0x7e,0x7e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x7e,0x12,0x0,0x0,0x0,0x7e,0x7e,0x3f,0x3c,0xdb,0xbe,0x7e,0x7e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x1e,0x7e,0x12,0x0,0x0,0x0,0x7e,0x7e,0x3f,0x3c,0xdb,0xbe,0x7e,0x7e,0x7e,0x12,0x0,0x0,0x0,0x67,0x72,0x78,0x68,0x74,0x68,0x72,0x72,0x78,0x68,0x74,0x68,0x72,0x79,0x25,0x73, Step #5: ~~~<\333\276~~\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036~\022\000\000\000~~?<\333\276~~\036\036\036\036\036\036\036\036\036\036\036\036\036\036~\022\000\000\000~~?<\333\276~~~\022\000\000\000g~~\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036\036~\022\000\000\000~~?<\333\276~~\036\036\036\036\036\036\036\036\036\036\036\036\036\036~\022\000\000\000~~?<\333\276~~~\022\000\000\000grxhthrrxhthry%s Step #5: artifact_prefix='./'; Test unit written to ./oom-65062b0c49bb974038398124e0c05a1d49203340 Step #5: Base64: fn5+PNu+fn4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh5+EgAAAH5+Pzzbvn5+Hh4eHh4eHh4eHh4eHh5+EgAAAH5+Pzzbvn5+fhIAAABnfn4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh5+EgAAAH5+Pzzbvn5+Hh4eHh4eHh4eHh4eHh5+EgAAAH5+Pzzbvn5+fhIAAABncnhodGhycnhodGhyeSVz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5013 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4264293469 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b00892810, 0x561b00a7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b00a7c020,0x561b029140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/65062b0c49bb974038398124e0c05a1d49203340' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6341 processed earlier; will process 4688 files now Step #5: #1 pulse cov: 4171 ft: 4172 exec/s: 0 rss: 176Mb Step #5: ==180544== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561af73879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561afd9ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561afd9cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561afd9cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561af738dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561af72eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561af72e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561af737fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561afa34ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561afa34ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561afa34ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561afa34ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561afa34ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561afa34ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561afa34ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561afa34ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561afa34ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561afa34ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561afc5e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561af9310b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561af931bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561af90c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561af90c7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561af90c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561af90c7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561af90c7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561af90c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561afd9d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561afd9da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561afd9c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561afd9ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1728734082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561af72e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x67,0x6c,0x79,0x66,0x0,0x8,0x6,0x32,0xf,0x73,0x74,0x2d,0x2d,0x2d,0x2d,0x42,0x24,0x2d,0x2d,0x2d,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2d,0x42,0x24,0x47,0x49,0x4e,0x20,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x47,0x49,0x44,0x33,0x0,0x0,0x53,0x16,0x16,0x70,0x10,0x5,0x25,0x33,0x32,0x49,0x4e,0x20,0x2d,0xa,0x2d,0x20,0x33,0x71,0x6d,0x4,0x43,0x4f,0x26,0x3f,0x67,0x2e,0x45,0x47,0x8,0x6,0x32,0xf,0x73,0x74,0x2d,0x2d,0x2d,0x2d,0x42,0x24,0x2d,0x2d,0x2d,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2d,0x42,0x24,0x47,0x49,0x4e,0x20,0x2e,0x2e,0x47,0x49,0x4e,0x20,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x47,0x49,0x44,0x33,0x0,0x0,0x53,0x16,0x16,0x70,0x10,0x5,0x25,0x33,0x32,0x49,0x4e,0x20,0x2d,0xa,0x2d,0x20,0x33,0x71,0x6d,0x4,0x43,0x4f,0x26,0x3f,0x67,0x2e,0x45,0x47,0x8,0x6,0x32,0xf,0x73,0x74,0x2d,0x2d,0x2d,0x2d,0x42,0x24,0x2d,0x2d,0x2d,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2d,0x42,0x24,0x47,0x49,0x4e,0x20,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x2e,0x47,0x49,0x44,0x33,0x0,0x0,0x53,0x16,0x16,0x70,0x10,0x5,0x25,0x33,0x32,0x49,0x4e,0x20,0x2d,0xa,0x2d,0x20,0x33,0x37,0x38, Step #5: tglyf\000\010\0062\017st----B$---......-B$GIN ..............GID3\000\000S\026\026p\020\005%32IN -\012- 3qm\004CO&?g.EG\010\0062\017st----B$---......-B$GIN ..GIN ..............GID3\000\000S\026\026p\020\005%32IN -\012- 3qm\004CO&?g.EG\010\0062\017st----B$---......-B$GIN ..............GID3\000\000S\026\026p\020\005%32IN -\012- 378 Step #5: artifact_prefix='./'; Test unit written to ./oom-a3ae2147f60c4cfdac4a3a87d48fa7b378f37cf3 Step #5: Base64: dGdseWYACAYyD3N0LS0tLUIkLS0tLi4uLi4uLUIkR0lOIC4uLi4uLi4uLi4uLi4uR0lEMwAAUxYWcBAFJTMySU4gLQotIDNxbQRDTyY/Zy5FRwgGMg9zdC0tLS1CJC0tLS4uLi4uLi1CJEdJTiAuLkdJTiAuLi4uLi4uLi4uLi4uLkdJRDMAAFMWFnAQBSUzMklOIC0KLSAzcW0EQ08mP2cuRUcIBjIPc3QtLS0tQiQtLS0uLi4uLi4tQiRHSU4gLi4uLi4uLi4uLi4uLi5HSUQzAABTFhZwEAUlMzJJTiAtCi0gMzc4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5014 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4264872858 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4dc8aa810, 0x55e4dca9401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4dca94020,0x55e4de92c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a3ae2147f60c4cfdac4a3a87d48fa7b378f37cf3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6343 processed earlier; will process 4686 files now Step #5: #1 pulse cov: 4137 ft: 4138 exec/s: 0 rss: 176Mb Step #5: ==180580== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e4d339f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4d9a04898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4d99e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4d99e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4d33a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4d3306b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4d3301355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4d3397c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4d6366f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4d6366f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4d6366f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4d6366f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4d6366f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4d6366f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4d6366f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4d6366f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4d6366f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4d6366f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4d85fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4d5328b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4d5333be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4d50dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4d50dfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4d50e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4d50df874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4d50df874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4d50df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4d99e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4d99f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4d99da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4d9a05112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa71e685082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4d32ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x49,0x46,0x33,0x4,0x8,0x32,0x73,0x55,0x6b,0x58,0x0,0x0,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3e,0xa,0x3d,0xa,0x3d,0xe3,0x80,0x80,0xa,0x3e,0xa,0x3d,0xa,0xf3,0xa0,0x81,0xbe,0x3d,0xa,0x3d,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x69,0x66,0x14,0x14,0x14,0x14,0x33,0x34,0xa,0x3a,0xb,0x3a,0xb,0x78,0x2e,0xa,0xe,0x6e,0x78,0xa,0x2e,0xa,0x22,0x74,0x78,0x6e,0x62,0x60,0x66,0x2e,0xd,0xef,0xb7,0xba,0x60,0x66,0x78,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x2e,0xa,0xe,0x6e,0x78,0xa,0x1,0x0,0x0,0x0,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6d,0x61,0x78,0x47,0x70,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x49,0x45,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x4d,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x0,0x0,0x0,0x0,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0xff,0xff,0xff,0x56,0x56,0x56,0x56,0x56,0x56, Step #5: 1IF3\004\0102sUkX\000\000\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024=\012=\012=\012=\012>\012=\012=\343\200\200\012>\012=\012\363\240\201\276=\012=\024\024\024\024\024\024\024\024if\024\024\024\02434\012:\013:\013x.\012\016nx\012.\012\"txnb`f.\015\357\267\272`fx\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377.\012\016nx\012\001\000\000\000ef=\012=+=\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000maxGp\012-----BIEVVVVVVVVVVVVVMVVVVVVV\000\000\000\000VVVVVVVVVVV\377\377\377VVVVVV Step #5: artifact_prefix='./'; Test unit written to ./oom-96dee34f70b3fd33b3bd17f6d5855e6b2c6450b7 Step #5: Base64: MUlGMwQIMnNVa1gAABQUFBQUFBQUFBQUFBQUFBQUFD0KPQo9Cj0KPgo9Cj3jgIAKPgo9CvOggb49Cj0UFBQUFBQUFGlmFBQUFDM0CjoLOgt4LgoObngKLgoidHhuYmBmLg3vt7pgZnj//////////////////////////////y4KDm54CgEAAABlZj0KPSs9AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABtYXhHcAotLS0tLUJJRVZWVlZWVlZWVlZWVlZNVlZWVlZWVgAAAABWVlZWVlZWVlZWVv///1ZWVlZWVg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5015 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4265561449 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563699bd5810, 0x563699dbf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563699dbf020,0x56369bc570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/96dee34f70b3fd33b3bd17f6d5855e6b2c6450b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6345 processed earlier; will process 4684 files now Step #5: ==180616== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5636906ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563696d2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563696d125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563696d124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5636906d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563690631b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56369062c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5636906c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563693691f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563693691f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563693691f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563693691f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563693691f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563693691f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563693691f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563693691f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563693691f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563693691f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563695926f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563692653b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56369265ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56369240ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56369240ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56369240b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56369240a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56369240a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56369240a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563696d14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563696d1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563696d05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563696d30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9b37d71082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56369062ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0xf3,0xa0,0x81,0xb0,0x33,0x4,0x2,0x3f,0x54,0x2d,0x35,0x36,0x30,0x33,0x32,0x38,0x37,0x31,0x39,0x34,0x34,0x33,0x33,0x36,0x30,0x36,0x35,0x32,0x43,0x48,0x0,0x43,0x6d,0x65,0x49,0x44,0x33,0x4,0x10,0x75,0x75,0x75,0x75,0x75,0x75,0x77,0x75,0x6d,0x49,0x44,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0xe2,0x81,0x9f,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x37,0xe2,0x80,0xab,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x39,0x34,0x36,0x31,0x4,0x10,0x75,0x6d,0x65,0x74,0x61,0x64,0x7f,0x2,0x3f,0x54,0x31,0x43,0x48,0x0,0x43,0x6d,0x65,0x49,0x44,0x32,0x4,0x10,0x75,0x75,0x75,0x75,0xe2,0x80,0xa8,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x75,0x75,0x75,0x75,0x4,0x10,0x31,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x33,0x4,0x10,0x33,0x32,0x37,0x36,0x39,0x2c,0xc4,0x33,0x4,0x10,0x75,0x75,0x75,0x75,0xca,0xb0,0x75,0x75,0x75,0x2e,0x6d,0x49,0x44,0x33,0xa,0x2d,0xa,0x3a,0xa,0x2d,0x3f,0x54,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0x32,0x39,0x35,0x43,0x48,0x0,0x75,0x75,0x6d,0x49,0x44,0x33,0x7f,0x2,0x3f,0x54,0x31,0x43,0x48,0x75,0x0,0x12, Step #5: ID\363\240\201\2603\004\002?T-560328719443360652CH\000CmeID3\004\020uuuuuuwumID34028236692093846346337\342\201\2374607431768211457\342\200\2539223372036854779461\004\020umetad\177\002?T1CH\000CmeID2\004\020uuuu\342\200\250uuuumIDuuuu\004\0201uuuumID3\004\02032769,\3043\004\020uuuu\312\260uuu.mID3\012-\012:\012-?T4294967295CH\000uumID3\177\002?T1CHu\000\022 Step #5: artifact_prefix='./'; Test unit written to ./oom-31ad8aa4eaf33251fb68fb5a5d836c40380c9a13 Step #5: Base64: SUTzoIGwMwQCP1QtNTYwMzI4NzE5NDQzMzYwNjUyQ0gAQ21lSUQzBBB1dXV1dXV3dW1JRDM0MDI4MjM2NjkyMDkzODQ2MzQ2MzM34oGfNDYwNzQzMTc2ODIxMTQ1N+KAqzkyMjMzNzIwMzY4NTQ3Nzk0NjEEEHVtZXRhZH8CP1QxQ0gAQ21lSUQyBBB1dXV14oCodXV1dW1JRHV1dXUEEDF1dXV1bUlEMwQQMzI3NjksxDMEEHV1dXXKsHV1dS5tSUQzCi0KOgotP1Q0Mjk0OTY3Mjk1Q0gAdXVtSUQzfwI/VDFDSHUAEg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5016 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4266105270 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c0d085810, 0x564c0d26f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c0d26f020,0x564c0f1070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/31ad8aa4eaf33251fb68fb5a5d836c40380c9a13' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6346 processed earlier; will process 4683 files now Step #5: #1 pulse cov: 4058 ft: 4059 exec/s: 0 rss: 175Mb Step #5: ==180652== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564c03b7a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c0a1df898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c0a1c25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c0a1c24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c03b80d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c03ae1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c03adc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c03b72c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c06b41f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c06b41f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c06b41f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c06b41f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c06b41f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c06b41f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c06b41f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c06b41f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c06b41f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c06b41f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c08dd6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c05b03b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c05b0ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c058bac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c058bac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c058bb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c058ba874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c058ba874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c058ba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c0a1c4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c0a1cd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c0a1b5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c0a1e0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f958a0fe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c03adab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x31,0x32,0x39,0x2,0x16,0x0,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0xf3,0xa0,0x81,0x88,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x23,0x23,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0xc,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0xc,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0xc,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x2f,0x23,0x7b,0x0,0x49,0x23,0x54,0x44,0xee, Step #5: ID129\002\026\000///////////////////////////////////////////////////////\363\240\201\210//////////////////////////##////////////////////////////////////////////////////\014\000\000\000\000\000\000\000/////////////\014\000\000\000\000\000\000\000/////////////\014\000\000\000\000\000\000\000///////////////////////////#{\000I#TD\356 Step #5: artifact_prefix='./'; Test unit written to ./oom-192fe6fef389d6369ae5dedc6d50e83cf3249ca7 Step #5: Base64: SUQxMjkCFgAvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v86CBiC8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vIyMvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vDAAAAAAAAAAvLy8vLy8vLy8vLy8vDAAAAAAAAAAvLy8vLy8vLy8vLy8vDAAAAAAAAAAvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8jewBJI1RE7g== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5017 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4266676600 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558fd0864810, 0x558fd0a4e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558fd0a4e020,0x558fd28e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/192fe6fef389d6369ae5dedc6d50e83cf3249ca7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6348 processed earlier; will process 4681 files now Step #5: ==180688== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558fc73599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558fcd9be898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558fcd9a15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558fcd9a14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558fc735fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558fc72c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558fc72bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558fc7351c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558fca320f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558fca320f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558fca320f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558fca320f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558fca320f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558fca320f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558fca320f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558fca320f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558fca320f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558fca320f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558fcc5b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558fc92e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558fc92edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558fc9099c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558fc9099c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558fc909a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558fc9099874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558fc9099874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558fc9099874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558fcd9a3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558fcd9ac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558fcd994699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558fcd9bf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6081e1d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558fc72b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x2d,0x2d,0x4f,0x2d,0x2d,0x42,0x45,0x6,0x48,0x41,0x0,0x0,0x2,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x2,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x2,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x2,0x0,0x0,0xa,0xa,0x2d,0x3f,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2,0x2d,0x29,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x29,0xa,0x2,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x49,0x44,0x33,0x3,0x14,0x1,0x2f,0x6e,0x68,0x6d,0x78,0xa,0x68,0x74,0x58,0x0,0x2,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x2,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x2,0x0,0x1,0x6,0x48,0x41,0x0,0x0,0x2,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x2,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x2,0x0,0x0,0x43,0x48,0x41,0x0,0x0,0x2,0x0,0x0,0xa,0xa,0x2d,0x3f,0x2c,0xa,0x2d,0xa,0x64,0xa,0x2,0x2d,0x29,0xa,0x64,0xa,0x2d,0xa,0x64,0xa,0x64,0xa,0x29,0xa,0x2,0xa,0x2d,0xa,0x2,0xa,0x2d,0xa,0x49,0x44,0x33,0x3,0x14,0x1,0x2f,0x0,0x0,0x67,0x54,0x49,0x54,0x30,0x0,0x0,0xd,0xe,0xe,0x69,0x2d,0x20,0x2d,0x7,0x20,0x2d,0x3a,0x20,0x75,0x3a,0x20,0x3a,0x2d,0x2d,0xa,0xa,0x62,0xd0,0xa,0xa,0x64,0xa,0xd5,0xa,0x2,0xa,0x33,0xa,0xdc,0xa,0xd2,0xa,0x0,0x2d,0xa,0x2d,0xa,0xa,0x2d,0xa,0xff, Step #5: \000--O--BE\006HA\000\000\002\000\000CHA\000\000\002\000\000CHA\000\000\002\000\000CHA\000\000\002\000\000\012\012-?,\012-\012d\012\002-)\012d\012-\012d\012d\012)\012\002\012-\012\002\012-\012ID3\003\024\001/nhmx\012htX\000\002\000\000CHA\000\000\002\000\000CHA\000\000\002\000\001\006HA\000\000\002\000\000CHA\000\000\002\000\000CHA\000\000\002\000\000CHA\000\000\002\000\000\012\012-?,\012-\012d\012\002-)\012d\012-\012d\012d\012)\012\002\012-\012\002\012-\012ID3\003\024\001/\000\000gTIT0\000\000\015\016\016i- -\007 -: u: :--\012\012b\320\012\012d\012\325\012\002\0123\012\334\012\322\012\000-\012-\012\012-\012\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-ae66391c35d179412df2eed067a46e4bd13146eb Step #5: Base64: AC0tTy0tQkUGSEEAAAIAAENIQQAAAgAAQ0hBAAACAABDSEEAAAIAAAoKLT8sCi0KZAoCLSkKZAotCmQKZAopCgIKLQoCCi0KSUQzAxQBL25obXgKaHRYAAIAAENIQQAAAgAAQ0hBAAACAAEGSEEAAAIAAENIQQAAAgAAQ0hBAAACAABDSEEAAAIAAAoKLT8sCi0KZAoCLSkKZAotCmQKZAopCgIKLQoCCi0KSUQzAxQBLwAAZ1RJVDAAAA0ODmktIC0HIC06IHU6IDotLQoKYtAKCmQK1QoCCjMK3ArSCgAtCi0KCi0K/w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5018 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4267215488 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5622dfa6f810, 0x5622dfc5901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622dfc59020,0x5622e1af10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ae66391c35d179412df2eed067a46e4bd13146eb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6349 processed earlier; will process 4680 files now Step #5: #1 pulse cov: 3917 ft: 3918 exec/s: 0 rss: 178Mb Step #5: ==180724== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5622d65649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5622dcbc9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5622dcbac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5622dcbac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5622d656ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5622d64cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5622d64c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5622d655cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5622d952bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5622d952bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5622d952bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5622d952bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5622d952bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5622d952bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5622d952bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5622d952bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5622d952bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5622d952bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5622db7c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5622d84edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5622d84f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5622d82a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5622d82a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5622d82a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5622d82a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5622d82a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5622d82a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5622dcbaeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5622dcbb7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5622dcb9f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5622dcbca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7facf4182082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5622d64c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x0,0x0,0x0,0xa,0x43,0x68,0x61,0x72,0x74,0x2e,0x79,0x61,0x6d,0x6c,0x43,0x63,0x68,0x41,0x49,0x41,0x21,0x41,0x2d,0x75,0x2c,0x6c,0x3a,0x21,0x3a,0x27,0x3a,0xd,0x2d,0x20,0x20,0x30,0x32,0x36,0x30,0x34,0x39,0x33,0x32,0x34,0x2e,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x3a,0xd,0xd,0xd,0xa,0xa,0xa,0xa,0x20,0x20,0x20,0x20,0x20,0x28,0x20,0x20,0x20,0x49,0x41,0x21,0x41,0x2d,0x75,0x2c,0x6c,0x3a,0x3a,0x27,0x3a,0xd,0x2d,0x20,0x20,0x30,0x32,0x36,0x30,0x34,0x39,0x33,0x32,0x34,0x2e,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x3a,0xd,0xd,0xd,0xa,0xa,0xa,0xa,0x20,0x20,0x20,0x20,0x20,0x28,0x20,0x20,0x20,0x49,0x41,0x21,0x41,0x2d,0x75,0x2c,0x6c,0x3a,0x3a,0x27,0x3a,0xd,0x2d,0x20,0x20,0x30,0x32,0x36,0x30,0x34,0x39,0x33,0x32,0x34,0x2e,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x39,0x32,0x39,0x39,0x3a,0xd,0xd,0xd,0xa,0xa,0xa,0xa,0x20,0x20,0x20,0x20,0x20,0x28,0x20,0x20,0x20,0x68,0x61,0x74,0x2e,0x79,0x61,0x6d,0x6c,0x43,0x63,0x68,0x41,0x49,0x41,0x21,0x68,0x61,0x72,0x74,0x2e,0xd,0x2d,0x20,0x31,0x38,0x38,0x32,0xd2,0xcf,0xcd,0xc9,0x30,0x33,0x35, Step #5: A\000\000\000\012Chart.yamlCchAIA!A-u,l:!:':\015- 026049324.9999999999999999:\015\015\015\012\012\012\012 ( IA!A-u,l::':\015- 026049324.9999999999999999:\015\015\015\012\012\012\012 ( IA!A-u,l::':\015- 026049324.99999999999999299:\015\015\015\012\012\012\012 ( hat.yamlCchAIA!hart.\015- 1882\322\317\315\311035 Step #5: artifact_prefix='./'; Test unit written to ./oom-9056b41557837311b74f0fdd780a4f81d8f89e2b Step #5: Base64: QQAAAApDaGFydC55YW1sQ2NoQUlBIUEtdSxsOiE6JzoNLSAgMDI2MDQ5MzI0Ljk5OTk5OTk5OTk5OTk5OTk6DQ0NCgoKCiAgICAgKCAgIElBIUEtdSxsOjonOg0tICAwMjYwNDkzMjQuOTk5OTk5OTk5OTk5OTk5OToNDQ0KCgoKICAgICAoICAgSUEhQS11LGw6Oic6DS0gIDAyNjA0OTMyNC45OTk5OTk5OTk5OTk5OTI5OToNDQ0KCgoKICAgICAoICAgaGF0LnlhbWxDY2hBSUEhaGFydC4NLSAxODgy0s/NyTAzNQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5019 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4267786608 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f8f30a7810, 0x55f8f329101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f8f3291020,0x55f8f51290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9056b41557837311b74f0fdd780a4f81d8f89e2b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6351 processed earlier; will process 4678 files now Step #5: #1 pulse cov: 3660 ft: 3661 exec/s: 0 rss: 175Mb Step #5: ==180760== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8e9b9c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f8f0201898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8f01e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8f01e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8e9ba2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8e9b03b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8e9afe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8e9b94c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8ecb63f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8ecb63f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8ecb63f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8ecb63f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8ecb63f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8ecb63f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8ecb63f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8ecb63f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8ecb63f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8ecb63f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f8eedf8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f8ebb25b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f8ebb30be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8eb8dcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8eb8dcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8eb8dd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8eb8dc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8eb8dc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8eb8dc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f8f01e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f8f01ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f8f01d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f8f0202112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f992607b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8e9afcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x3c,0xdb,0xbe,0xdb,0xbe,0x7e,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x9d,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x25,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x7e,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x30,0x73,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x42,0x42,0x67,0x72,0x79,0x31,0x73, Step #5: ~<\333\276\333\276~sssssssssss%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%\001\000\000\000\000\000\000\235%%%%%%%%%%%%%%%%%%%%%%%%sssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssss~\377\377\377\377\377\377\377\3770s~~~~~~\001\000\000\000\000\000\000BBgry1s Step #5: artifact_prefix='./'; Test unit written to ./oom-69913d42eb18b0ab175a3c9a9b92ded01a10c8e2 Step #5: Base64: fjzbvtu+fnNzc3Nzc3Nzc3NzJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJQEAAAAAAACdJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzfv//////////MHN+fn5+fn4BAAAAAAAAQkJncnkxcw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5020 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4268355595 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559b3d4a2810, 0x559b3d68c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559b3d68c020,0x559b3f5240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/69913d42eb18b0ab175a3c9a9b92ded01a10c8e2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6353 processed earlier; will process 4676 files now Step #5: ==180796== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559b33f979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559b3a5fc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559b3a5df5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559b3a5df4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b33f9dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b33efeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b33ef9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b33f8fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b36f5ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b36f5ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b36f5ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b36f5ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b36f5ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b36f5ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b36f5ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b36f5ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b36f5ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b36f5ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559b391f3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b35f20b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b35f2bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b35cd7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b35cd7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b35cd8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b35cd7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b35cd7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b35cd7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559b3a5e1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559b3a5ea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559b3a5d2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559b3a5fd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff24401c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b33ef7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x70,0x20,0x7b,0xa,0x20,0x20,0x64,0x6f,0x63,0x74,0x79,0x70,0x65,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x6d,0x64,0x65,0x63,0x6c,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x65,0x6e,0x74,0x69,0x74,0x79,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x20,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x5c,0x27,0x47,0x53,0x3d,0x5c,0x27,0x20,0x5c,0x27,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x25,0x41,0x33,0x25,0x41,0x3b,0x25,0x41,0x3b,0x25,0x41,0x3b,0x25,0x41,0x3b,0x25,0x3a,0x3b,0x25,0x41,0x3b,0x25,0x41,0x3b,0x25,0x41,0x3b,0x25,0x41,0x3b,0x25,0x41,0x5c,0x27,0x20,0x20,0x5c,0x72,0x3e,0x20,0x20,0x5c,0x30,0x30,0x30,0x20,0x3c,0x48,0x3e,0x20,0x21,0x46,0x22,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x76,0x61,0x6c,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x6e,0x61,0x6d,0x65,0x3a,0x20,0x22,0x44,0x22,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x7d,0xa,0x7d,0xa, Step #5: p {\012 doctype {\012 mdecl {\012 entity {\012 name: \"D PUBLIC \\'GS=\\' \\'http://%A3%A;%A;%A;%A;%:;%A;%A;%A;%A;%A\\' \\r> \\000 <H> !F\"\012 ent {\012 val {\012 name: \"D\"\012 }\012 }\012 }\012 }\012 }\012}\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-be6c4533bbc020eab97c9a0731b8dead755ac878 Step #5: Base64: cCB7CiAgZG9jdHlwZSB7CiAgICBtZGVjbCB7CiAgICAgIGVudGl0eSB7CiAgICAgICAgbmFtZTogIkQgIFBVQkxJQyBcJ0dTPVwnIFwnaHR0cDovLyVBMyVBOyVBOyVBOyVBOyU6OyVBOyVBOyVBOyVBOyVBXCcgIFxyPiAgXDAwMCA8SD4gIUYiCiAgICAgICAgZW50IHsKICAgICAgICAgIHZhbCB7CiAgICAgICAgICAgIG5hbWU6ICJEIgogICAgICAgICAgfQogICAgICAgIH0KICAgICAgfQogICAgfQogIH0KfQo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5021 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4268876760 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5596b8096810, 0x5596b828001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596b8280020,0x5596ba1180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/be6c4533bbc020eab97c9a0731b8dead755ac878' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6354 processed earlier; will process 4675 files now Step #5: #1 pulse cov: 15725 ft: 15726 exec/s: 0 rss: 200Mb Step #5: ==180832== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5596aeb8b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5596b51f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5596b51d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5596b51d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5596aeb91d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5596aeaf2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5596aeaed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5596aeb83c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5596b1b52f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5596b1b52f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5596b1b52f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5596b1b52f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5596b1b52f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5596b1b52f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5596b1b52f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5596b1b52f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5596b1b52f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5596b1b52f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596b3de7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5596b0b14b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5596b0b1fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5596b08cbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5596b08cbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5596b08cc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5596b08cb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5596b08cb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5596b08cb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5596b51d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5596b51de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5596b51c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5596b51f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe47c16082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5596aeaebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x34,0x36,0x2b,0x2d,0x31,0x32,0x35,0x2d,0x31,0x2d,0x33,0x33,0x2d,0x36,0x2d,0x36,0x36,0x2b,0x2d,0x33,0x2d,0x31,0x2d,0x33,0x2d,0x32,0x3b,0xa,0xa,0x6c,0x65,0x74,0x20,0x74,0x65,0x78,0x74,0x20,0x3d,0x20,0x22,0x68,0x65,0x6c,0x75,0x44,0x44,0x49,0x44,0x44,0x49,0x33,0x36,0x35,0x35,0x33,0x31,0x36,0x30,0x39,0x30,0x34,0x36,0x38,0x6c,0x6f,0x2c,0x20,0x77,0x6f,0x72,0x6c,0x64,0x21,0x22,0x3b,0xa,0xa,0x74,0x65,0x78,0x74,0x2e,0x63,0x72,0x6f,0x70,0x9,0x28,0x31,0x29,0x3b,0xa,0xa,0x70,0x72,0x69,0x6e,0x74,0x28,0x74,0x65,0x78,0x74,0x29,0x3b,0xa,0xa,0x74,0x65,0x78,0x74,0x2e,0x63,0x72,0x6f,0x70,0x9,0x28,0x30,0x29,0x3b,0xa,0xa,0xa,0x70,0x72,0x69,0x6e,0x74,0x28,0x74,0x65,0x78,0x74,0x29,0x3b,0xa,0xa,0x74,0x65,0x78,0x74,0x2e,0x63,0x72,0x6f,0x70,0x28,0x2d,0x34,0x32,0x39,0x34,0x39,0x36,0x37,0x33,0x30,0x30,0x29,0x3b,0xa,0xa,0x90,0xad,0x96,0x3a,0x3a,0x69,0x54,0x62,0x3a,0x3a,0x62,0x45,0x61,0x69,0x54,0x54,0x54,0x54,0x54,0x54,0x6c,0x32,0x54,0x54,0x45,0x69,0x61,0x54,0x54,0x54,0x54,0x65,0x5f,0x6f,0x66,0x28,0x29,0x3b,0x3b,0x3b,0x3b,0x54,0x54,0x3a,0x3a,0x3a,0x62,0x45,0x61,0x69,0x54,0x54,0x54,0x54,0x54,0x54,0x6c,0x32,0x66,0x2d,0x69,0x66,0x2d,0x76,0x2e,0x20,0x2b,0xd,0x20,0xad, Step #5: 46+-125-1-33-6-66+-3-1-3-2;\012\012let text = \"heluDDIDDI3655316090468lo, world!\";\012\012text.crop\011(1);\012\012print(text);\012\012text.crop\011(0);\012\012\012print(text);\012\012text.crop(-4294967300);\012\012\220\255\226::iTb::bEaiTTTTTTl2TTEiaTTTTe_of();;;;TT:::bEaiTTTTTTl2f-if-v. +\015 \255 Step #5: artifact_prefix='./'; Test unit written to ./oom-dd7551b47f970390ef2d88dbf0c7e4a1e93e8137 Step #5: Base64: NDYrLTEyNS0xLTMzLTYtNjYrLTMtMS0zLTI7CgpsZXQgdGV4dCA9ICJoZWx1RERJRERJMzY1NTMxNjA5MDQ2OGxvLCB3b3JsZCEiOwoKdGV4dC5jcm9wCSgxKTsKCnByaW50KHRleHQpOwoKdGV4dC5jcm9wCSgwKTsKCgpwcmludCh0ZXh0KTsKCnRleHQuY3JvcCgtNDI5NDk2NzMwMCk7CgqQrZY6OmlUYjo6YkVhaVRUVFRUVGwyVFRFaWFUVFRUZV9vZigpOzs7O1RUOjo6YkVhaVRUVFRUVGwyZi1pZi12LiArDSCt Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5022 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4269493523 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b584ca810, 0x561b586b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b586b4020,0x561b5a54c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dd7551b47f970390ef2d88dbf0c7e4a1e93e8137' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6356 processed earlier; will process 4673 files now Step #5: ==180868== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561b4efbf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b55624898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b556075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b556074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b4efc5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b4ef26b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b4ef21355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b4efb7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b51f86f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b51f86f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b51f86f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b51f86f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b51f86f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b51f86f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b51f86f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b51f86f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b51f86f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b51f86f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b5421bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b50f48b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b50f53be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b50cffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b50cffc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b50d00738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b50cff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b50cff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b50cff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b55609abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b55612928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b555fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b55625112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa293844082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b4ef1fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x32,0x2,0x23,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x34,0x38,0x60,0x44,0x33,0x2,0x23,0x33,0x32,0x38,0x33,0x58,0x58,0x0,0x0,0x1,0x0,0x54,0x24,0x27,0x21,0x3e,0x3e,0x3e,0x58,0x58,0x0,0x0,0x1,0x0,0x38,0x33,0x23,0x54,0x58,0x58,0x0,0x33,0x2,0x23,0x33,0x32,0x49,0x44,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0xf3,0xa0,0x80,0x81,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x33,0x2,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x7e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x23,0x33,0x32,0x38,0x73,0x23,0x54,0x58,0x58,0x0,0x0,0x1,0x0,0x3e,0x3e,0xe3,0x80,0x80,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x54,0x58,0x58,0x0,0x0,0x1,0x0,0x54,0x58,0x58,0x0,0x0,0x1,0x0,0x0,0x1,0x60,0x0,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x30,0x54,0x58,0x58,0x0,0x0,0x11,0x0,0x54,0x58,0x58,0x0,0x0,0x1,0x0,0x54,0x57,0x58,0x49, Step #5: ID2\002#2147483648`D3\002#3283XX\000\000\001\000T$'!>>>XX\000\000\001\00083#TXX\0003\002#32ID>>>>>>>>>>>>>>>>>>>>>>>>\363\240\200\201>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>3\002>>>>>>>>>>>>>>>>>~>>>>>>>>>>>>>>>#328s#TXX\000\000\001\000>>\343\200\200>>>>>>>>TXX\000\000\001\000TXX\000\000\001\000\000\001`\000>>>>>>>0TXX\000\000\021\000TXX\000\000\001\000TWXI Step #5: artifact_prefix='./'; Test unit written to ./oom-be444f3a53b073d3207dd0150c146bdff5da7f3e Step #5: Base64: SUQyAiMyMTQ3NDgzNjQ4YEQzAiMzMjgzWFgAAAEAVCQnIT4+PlhYAAABADgzI1RYWAAzAiMzMklEPj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+86CAgT4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+MwI+Pj4+Pj4+Pj4+Pj4+Pj4+Pn4+Pj4+Pj4+Pj4+Pj4+Pj4jMzI4cyNUWFgAAAEAPj7jgIA+Pj4+Pj4+PlRYWAAAAQBUWFgAAAEAAAFgAD4+Pj4+Pj4wVFhYAAARAFRYWAAAAQBUV1hJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5023 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4270134803 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558015eea810, 0x5580160d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5580160d4020,0x558017f6c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/be444f3a53b073d3207dd0150c146bdff5da7f3e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6357 processed earlier; will process 4672 files now Step #5: ==180904== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55800c9df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558013044898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5580130275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5580130274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55800c9e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55800c946b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55800c941355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55800c9d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55800f9a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55800f9a6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55800f9a6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55800f9a6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55800f9a6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55800f9a6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55800f9a6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55800f9a6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55800f9a6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55800f9a6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558011c3bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55800e968b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55800e973be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55800e71fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55800e71fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55800e720738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55800e71f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55800e71f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55800e71f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558013029abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558013032928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55801301a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558013045112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f103f75d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55800c93fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x43,0x3e,0x3e,0x73,0x6c,0x78,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x6c,0x76,0x62,0x61,0x67,0x2f,0x65,0x78,0x74,0x72,0x61,0x63,0x74,0x2d,0x64,0x65,0x65,0x6c,0x62,0x65,0x73,0x74,0x61,0x6e,0x64,0x2d,0x6c,0x76,0x63,0x2f,0x76,0x32,0x30,0x32,0x30,0x30,0x36,0x30,0x31,0x3d,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x73,0x74,0x61,0x6e,0x64,0x6c,0x65,0x76,0x65,0x72,0x69,0x6e,0x67,0x2d,0x67,0x65,0x6e,0x65,0x72,0x69,0x65,0x6b,0x2f,0x31,0x2e,0x30,0x23,0x3c,0x73,0x6c,0x3a,0x73,0x74,0x61,0x6e,0x64,0x42,0x65,0x73,0x74,0x61,0x6e,0x64,0x3e,0x40,0x20,0x20,0x3c,0x73,0x6c,0x3a,0x6f,0x62,0x6a,0x65,0x63,0x74,0x54,0x79,0x70,0x65,0x3e,0x56,0x42,0x4f,0x3c,0x2f,0x73,0x6c,0x3a,0x6f,0x62,0x6a,0x3a,0x63,0x74,0x54,0x79,0x70,0x65,0x3e,0x74,0xa,0x3c,0x73,0x6c,0x2d,0x62,0x61,0x67,0x2d,0x65,0x78,0x74,0x72,0x61,0x63,0x74,0x3a,0x62,0x61,0x67,0x4f,0x62,0x6a,0x65,0x63,0x74,0x3e,0x65,0x3c,0x6f,0x62,0x68,0x65,0x63,0x74,0x65,0x6e,0x3a,0x52,0x68,0x61,0x3e,0x3c, Step #5: <C>>slxhttp://www.kadaster.nl/schemas/lvbag/extract-deelbestand-lvc/v20200601=http://www.kadaster.nl/schemas/standlevering-generiek/1.0#<sl:standBestand>@ <sl:objectType>VBO</sl:obj:ctType>t\012<sl-bag-extract:bagObject>e<obhecten:Rha>< Step #5: artifact_prefix='./'; Test unit written to ./oom-23c6fdaafa0a2ce95fee0e43b8beff5b9da5e0e8 Step #5: Base64: PEM+PnNseGh0dHA6Ly93d3cua2FkYXN0ZXIubmwvc2NoZW1hcy9sdmJhZy9leHRyYWN0LWRlZWxiZXN0YW5kLWx2Yy92MjAyMDA2MDE9aHR0cDovL3d3dy5rYWRhc3Rlci5ubC9zY2hlbWFzL3N0YW5kbGV2ZXJpbmctZ2VuZXJpZWsvMS4wIzxzbDpzdGFuZEJlc3RhbmQ+QCAgPHNsOm9iamVjdFR5cGU+VkJPPC9zbDpvYmo6Y3RUeXBlPnQKPHNsLWJhZy1leHRyYWN0OmJhZ09iamVjdD5lPG9iaGVjdGVuOlJoYT48 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5024 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4270656495 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dfa7b87810, 0x55dfa7d7101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dfa7d71020,0x55dfa9c090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/23c6fdaafa0a2ce95fee0e43b8beff5b9da5e0e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6358 processed earlier; will process 4671 files now Step #5: ==180940== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55df9e67c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dfa4ce1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dfa4cc45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dfa4cc44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55df9e682d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55df9e5e3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55df9e5de355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55df9e674c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dfa1643f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dfa1643f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dfa1643f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dfa1643f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dfa1643f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dfa1643f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dfa1643f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dfa1643f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dfa1643f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dfa1643f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dfa38d8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dfa0605b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dfa0610be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dfa03bcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dfa03bcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dfa03bd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dfa03bc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dfa03bc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dfa03bc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dfa4cc6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dfa4ccf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dfa4cb7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dfa4ce2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f75f745f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55df9e5dcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x30,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x67,0x7b,0x30,0x3e,0x2a,0x7b,0x6c,0x3c,0x67,0x3e,0x67,0x3e,0x2a,0x7b,0x63,0x70,0x69,0x6f,0x74,0x79,0x7a,0x3a,0x2d,0x43,0x2d,0x35,0x2c,0x37,0x4e,0x31,0x2c,0x37,0x31,0x35,0x30,0x6e,0x6e,0x2c,0x38,0xd7,0x81,0x70,0x6f,0x36,0x45,0x37,0x7d,0x3c,0x7a,0x67,0x3e,0x3c,0x67,0x3e,0x37,0xd7,0x81,0x70,0x6f,0x7d,0x31,0x36,0x45,0x37,0x7d,0x61,0x63,0x69,0x74,0x35,0x30,0x6e,0x6e,0x6f,0x70,0x38,0xd7,0x81,0x2c,0x36,0x45,0x37,0x7d,0x3c,0x7a,0x67,0x3e,0x3c,0x67,0x76,0x67,0x3e,0x30,0x3e,0x3c,0x73,0x74,0x79,0x6c,0x65,0x3e,0x67,0x7b,0x30,0x3e,0x2a,0x7b,0x6c,0x3c,0x67,0x3e,0x67,0x3e,0x2a,0x7b,0x63,0x70,0x69,0x6f,0x74,0x79,0x3a,0x2d,0x43,0x2d,0x35,0x2c,0x37,0x4e,0x31,0x2c,0x37,0x31,0x35,0x30,0x6e,0x6e,0x2c,0x38,0xd7,0x81,0x70,0x6f,0x36,0x45,0x37,0x7d,0x3c,0x7a,0x67,0x3e,0x3c,0x67,0x3e,0x37,0xd7,0x81,0x70,0x6f,0x7d,0x31,0x36,0x45,0x37,0x7d,0x61,0x63,0x69,0x74,0x35,0x30,0x6e,0x6e,0x2c,0x38,0xd7,0x81,0x70,0x6f,0x36,0x45,0x37,0x7d,0x3c,0x7a,0x67,0x3e,0x3c,0x67,0x3e,0x37,0xd7,0x81,0x6f,0x6c,0x64,0x6c,0x70,0x6f,0x7d,0x31,0x45,0x3e,0x37,0xd7,0x81,0x6f,0x6c,0x64,0x6c,0x70,0x6f,0x7d,0x31,0x45,0x37,0x7d,0x3c,0x3d,0x3c, Step #5: <svg>0><style>g{0>*{l<g>g>*{cpiotyz:-C-5,7N1,7150nn,8\327\201po6E7}<zg><g>7\327\201po}16E7}acit50nnop8\327\201,6E7}<zg><gvg>0><style>g{0>*{l<g>g>*{cpioty:-C-5,7N1,7150nn,8\327\201po6E7}<zg><g>7\327\201po}16E7}acit50nn,8\327\201po6E7}<zg><g>7\327\201oldlpo}1E>7\327\201oldlpo}1E7}<=< Step #5: artifact_prefix='./'; Test unit written to ./oom-e79336378e98e269ab4597812b43538d76364969 Step #5: Base64: PHN2Zz4wPjxzdHlsZT5nezA+KntsPGc+Zz4qe2NwaW90eXo6LUMtNSw3TjEsNzE1MG5uLDjXgXBvNkU3fTx6Zz48Zz4314Fwb30xNkU3fWFjaXQ1MG5ub3A414EsNkU3fTx6Zz48Z3ZnPjA+PHN0eWxlPmd7MD4qe2w8Zz5nPip7Y3Bpb3R5Oi1DLTUsN04xLDcxNTBubiw414FwbzZFN308emc+PGc+N9eBcG99MTZFN31hY2l0NTBubiw414FwbzZFN308emc+PGc+N9eBb2xkbHBvfTFFPjfXgW9sZGxwb30xRTd9PD08 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5025 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4271179748 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cff14bb810, 0x55cff16a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cff16a5020,0x55cff353d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e79336378e98e269ab4597812b43538d76364969' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6359 processed earlier; will process 4670 files now Step #5: #1 pulse cov: 3838 ft: 3839 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 3979 ft: 4327 exec/s: 0 rss: 176Mb Step #5: ==180976== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cfe7fb09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cfee615898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cfee5f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cfee5f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cfe7fb6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cfe7f17b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cfe7f12355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cfe7fa8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cfeaf77f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cfeaf77f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cfeaf77f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cfeaf77f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cfeaf77f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cfeaf77f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cfeaf77f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cfeaf77f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cfeaf77f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cfeaf77f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cfed20cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cfe9f39b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cfe9f44be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cfe9cf0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cfe9cf0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cfe9cf1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cfe9cf0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cfe9cf0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cfe9cf0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cfee5faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cfee603928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cfee5eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cfee616112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb4fd0d8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cfe7f10b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2f,0x0,0x0,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x0,0x2f,0x0,0x0,0x2f,0x0,0xf,0xf,0xf,0xf,0xf,0x31,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x11,0x38,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x2d,0xf,0x5b,0xf,0xf,0x31,0x2d,0xf,0x5b,0x31,0x26,0x11,0x38,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0xf,0x73,0x20,0x5b,0x38,0x41,0x0,0xf,0xf,0xf,0xf,0x31,0xf,0x2d,0x31,0x5b,0x26,0x11,0x3a,0x11,0x2d,0xf,0xf,0xf,0xf,0xf,0x31,0x11,0xf,0x31,0x11,0x25,0x3a,0x3a,0x24,0x2d,0x5b,0xee,0x24,0x5b, Step #5: $\000\000/\000\000\000/\000\000/\000\017\017\017\017\0171/\000\000\000/\000\000/\000\017\017\017\017\0171-\017[\017\0171-\017[1&\021:\021-\017\017\017\017\0171\021\0171\017s\000/\000\000/\000\017\017\017\017\0171-\017[\017\0171-\017[1&\021:\021-\017\017\017\017\0171\021\0171\017s [8A\000\017\017\017\0171\017-1[&\021:-\017[\017\0171-\017[1&\0218\021-\017\017\017\017\0171\021\0171\017s [8A\000\017\017\017\0171\017-1[ [8A\000\017\017\017\0171\017-1[&\021:-\017[\017\0171-\017[1&\0218\021-\017\017\017\017\0171\021\0171\017s [8A\000\017\017\017\0171\017-1[&\021:\021-\017\017\017\017\0171\021\0171\021%::$-[\356$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-d083c99b5834c55ccb2201fdb11be856e608b2a6 Step #5: Base64: JAAALwAAAC8AAC8ADw8PDw8xLwAAAC8AAC8ADw8PDw8xLQ9bDw8xLQ9bMSYROhEtDw8PDw8xEQ8xD3MALwAALwAPDw8PDzEtD1sPDzEtD1sxJhE6ES0PDw8PDzERDzEPcyBbOEEADw8PDzEPLTFbJhE6LQ9bDw8xLQ9bMSYROBEtDw8PDw8xEQ8xD3MgWzhBAA8PDw8xDy0xWyBbOEEADw8PDzEPLTFbJhE6LQ9bDw8xLQ9bMSYROBEtDw8PDw8xEQ8xD3MgWzhBAA8PDw8xDy0xWyYROhEtDw8PDw8xEQ8xESU6OiQtW+4kWw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5026 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4271791468 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f6f16be810, 0x55f6f18a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f6f18a8020,0x55f6f37400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d083c99b5834c55ccb2201fdb11be856e608b2a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6362 processed earlier; will process 4667 files now Step #5: ==181012== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f6e81b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f6ee818898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f6ee7fb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f6ee7fb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f6e81b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f6e811ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f6e8115355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f6e81abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f6eb17af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f6eb17af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f6eb17af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f6eb17af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f6eb17af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f6eb17af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f6eb17af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f6eb17af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f6eb17af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f6eb17af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f6ed40ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f6ea13cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f6ea147be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f6e9ef3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f6e9ef3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f6e9ef4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f6e9ef3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f6e9ef3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f6e9ef3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f6ee7fdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f6ee806928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f6ee7ee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f6ee819112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8d547d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f6e8113b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x5d,0x32,0x2e,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x32,0x36,0x34,0x39,0x39,0x34,0x35,0x35,0x33,0x20,0x32,0x10,0x20,0x32,0x10,0x2e,0x2,0x0,0x2f,0x2d,0x7f,0x7f,0x6f,0x7f,0x7f,0x7f,0x7f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x24, Step #5: $\177]2.22222222222222222222222222222222222222222222222222222222222222222222222222222222000000000000000000000264994553 2\020 2\020.\002\000/-\177\177o\177\177\177\177\000\000\000\000\000\000\000\000\000\000\000\000\000\000/\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\177\177\177\177o\000\000C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-013f05e4e90a8f1405297e94c181ec3a9189c294 Step #5: Base64: JH9dMi4yMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjAwMDAwMDAwMDAwMDAwMDAwMDAwMDI2NDk5NDU1MyAyECAyEC4CAC8tf39vf39/fwAAAAAAAAAAAAAAAAAALwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAH9/f39vAABDJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5027 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4272323666 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564549d25810, 0x564549f0f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564549f0f020,0x56454bda70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/013f05e4e90a8f1405297e94c181ec3a9189c294' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6363 processed earlier; will process 4666 files now Step #5: ==181048== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56454081a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564546e7f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564546e625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564546e624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564540820d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564540781b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56454077c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564540812c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5645437e1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5645437e1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5645437e1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5645437e1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5645437e1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5645437e1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5645437e1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5645437e1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5645437e1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5645437e1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564545a76f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5645427a3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5645427aebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56454255ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56454255ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56454255b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56454255a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56454255a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56454255a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564546e64abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564546e6d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564546e55699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564546e80112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b8548d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56454077ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x21,0x0,0x2d,0x0,0x0,0x0,0x4c,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x5b,0x2d,0x2d,0xa,0x44,0x0,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x38,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x31,0x37,0x39,0x38,0x32,0x37,0x31,0x32,0x30,0x38,0x38,0x35,0x36,0x32,0x34,0x37,0x30,0x34,0x35,0x37,0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x30,0x30,0x30,0x31,0x37,0x39,0x38,0x32,0x37,0x31,0x32,0x30,0x38,0x38,0x35,0x36,0x32,0x34,0x37,0x30,0x34,0x35,0x37,0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x41,0x64,0x41,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x41,0x54,0x54,0x54,0x54,0x54,0x54,0x70,0x70,0x54,0x63,0x6f,0x6e,0x74,0x65,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x22,0x3a,0x22,0x22,0x2c,0x22,0x22,0x66,0x6f,0x6e,0x74,0x49,0x4e,0x20,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x43,0x46,0x46,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x43,0x46,0x46,0x20,0x5b,0x2d,0x2d,0xa,0x44,0xa,0x2d,0xa,0x49,0x74,0x20,0x5b,0x2d,0x2d,0xa,0x44,0x4a,0x2d,0xa,0x49,0x74,0x68,0xa,0x2d,0xa,0x64,0x65, Step #5: !!\000-\000\000\000LEGIN --[--\012D\000----BEG88888888000000000000017982712088562470457s-----BEGIN00017982712088562470457s-----BEGIN -----\012AdApppppppppppppppppppppATTTTTTppTconte\000\000\000\000\000\000\000\000\000ontent\":\"\",\"\"fontIN EGIN --CFFGIN --CFF [--\012D\012-\012It [--\012DJ-\012Ith\012-\012de Step #5: artifact_prefix='./'; Test unit written to ./oom-436ac84d762b18e0b269718d55e7e5a614b0e8d6 Step #5: Base64: ISEALQAAAExFR0lOIC0tWy0tCkQALS0tLUJFRzg4ODg4ODg4MDAwMDAwMDAwMDAwMDE3OTgyNzEyMDg4NTYyNDcwNDU3cy0tLS0tQkVHSU4wMDAxNzk4MjcxMjA4ODU2MjQ3MDQ1N3MtLS0tLUJFR0lOIC0tLS0tCkFkQXBwcHBwcHBwcHBwcHBwcHBwcHBwcEFUVFRUVFRwcFRjb250ZQAAAAAAAAAAAG9udGVudCI6IiIsIiJmb250SU4gRUdJTiAtLUNGRkdJTiAtLUNGRiBbLS0KRAotCkl0IFstLQpESi0KSXRoCi0KZGU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5028 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4272856881 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560f558ee810, 0x560f55ad801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560f55ad8020,0x560f579700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/436ac84d762b18e0b269718d55e7e5a614b0e8d6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6364 processed earlier; will process 4665 files now Step #5: ==181084== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560f4c3e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560f52a48898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560f52a2b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560f52a2b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560f4c3e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560f4c34ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560f4c345355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560f4c3dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560f4f3aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560f4f3aaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560f4f3aaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560f4f3aaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560f4f3aaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560f4f3aaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560f4f3aaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560f4f3aaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560f4f3aaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560f4f3aaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560f5163ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560f4e36cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560f4e377be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560f4e123c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560f4e123c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560f4e124738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560f4e123874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560f4e123874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560f4e123874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560f52a2dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560f52a36928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560f52a1e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560f52a49112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c11714082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560f4c343b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x32,0x5d,0x32,0x2e,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x73,0x20,0x37,0x20,0x30,0x20,0x32,0x10,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x73,0x20,0x37,0x20,0x30,0x32,0x32,0x32,0x32,0x32,0x33,0x32,0x32,0x32,0x32,0x32,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x47,0x0,0x2d,0x7d,0x0,0x2d,0x47,0x1,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x1,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x1,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x2d,0x7c,0x0,0x2d,0x7c,0x0,0x2d,0x47,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x24, Step #5: $\1772]2.2.23/\020./s 7 0 2\02023/\020./s 7 022222322222-G\000-|\000-G\000-|\000-|\000-G\000-|\000-G\000-|\000-G\000-|\000-|\000-G\000-|\000-G\000-|\000-G\000-|\000-G\000-G\000-}\000-G\001-G\000-|\000-G\001-|\000-G\000-|\000-G\000-|\000-|\000-G\000-|\000-G\000-|\000-G\000-|\000-G\000-G\000-|\000-G\000-|\000-G\000-|\000-|\000-G\001-|\000-G\000-|\000-G\000-|\000-|\000-G\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\177\177\177\177o\000\000C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-63c6aec1c2387d7b6531b1fcfae78c405d491741 Step #5: Base64: JH8yXTIuMi4yMy8QLi9zIDcgMCAyEDIzLxAuL3MgNyAwMjIyMjIzMjIyMjItRwAtfAAtRwAtfAAtfAAtRwAtfAAtRwAtfAAtRwAtfAAtfAAtRwAtfAAtRwAtfAAtRwAtfAAtRwAtRwAtfQAtRwEtRwAtfAAtRwEtfAAtRwAtfAAtRwAtfAAtfAAtRwAtfAAtRwAtfAAtRwAtfAAtRwAtRwAtfAAtRwAtfAAtRwAtfAAtfAAtRwEtfAAtRwAtfAAtRwAtfAAtfAAtRwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB/f39/bwAAQyQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5029 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4273388305 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c0acb5810, 0x562c0ae9f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c0ae9f020,0x562c0cd370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/63c6aec1c2387d7b6531b1fcfae78c405d491741' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6365 processed earlier; will process 4664 files now Step #5: ==181120== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562c017aa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c07e0f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c07df25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c07df24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c017b0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c01711b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c0170c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c017a2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c04771f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c04771f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c04771f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c04771f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c04771f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c04771f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c04771f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c04771f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c04771f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c04771f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c06a06f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562c03733b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562c0373ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562c034eac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562c034eac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562c034eb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562c034ea874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562c034ea874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562c034ea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c07df4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c07dfd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c07de5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c07e10112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5b25c96082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c0170ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x23,0x76,0x21,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x35,0xcc,0x9c,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x35,0xa,0x23,0x76,0x21,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x35,0xcc,0x9c,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x37,0x36,0x38,0x32,0x31,0x31,0x34,0x35,0x35,0xa,0x6e,0x75,0x73,0x20,0x73,0x65,0x72,0x69,0x66,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x7d,0xd7,0x93,0x93,0xd7,0x7d,0x0,0x47,0x73,0x65,0x64,0x20,0x31,0x32,0x33,0x30,0x37,0x34,0x31,0x31,0x34,0x37,0x34,0x39,0x36,0x34,0x39,0x37,0x30,0x20,0x47,0x47,0x7d,0xd7,0x93,0x93,0xd7,0x7d,0x0,0x7,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x47,0x7d,0xd7,0x93,0x93,0xd7,0x7d,0x0,0x0, Step #5: #v!340282366920938463463374607431768211455\314\2340938463463374607431768211455\012#v!340282366920938463463374607431768211455\314\2340938463463374607431768211455\012nus serifGGGGGGGGGGGGGGGGGGGGGGGGG}\327\223\223\327}\000Gsed 12307411474964970 GG}\327\223\223\327}\000\007GGGGGGGG}\327\223\223\327}\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f991b4212cea9d23f82903db37b7d8b5bd00d967 Step #5: Base64: I3YhMzQwMjgyMzY2OTIwOTM4NDYzNDYzMzc0NjA3NDMxNzY4MjExNDU1zJwwOTM4NDYzNDYzMzc0NjA3NDMxNzY4MjExNDU1CiN2ITM0MDI4MjM2NjkyMDkzODQ2MzQ2MzM3NDYwNzQzMTc2ODIxMTQ1NcycMDkzODQ2MzQ2MzM3NDYwNzQzMTc2ODIxMTQ1NQpudXMgc2VyaWZHR0dHR0dHR0dHR0dHR0dHR0dHR0dHR0dHfdeTk9d9AEdzZWQgMTIzMDc0MTE0NzQ5NjQ5NzAgR0d915OT130AB0dHR0dHR0dHfdeTk9d9AAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5030 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4273920526 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640ccdad810, 0x5640ccf9701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640ccf97020,0x5640cee2f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f991b4212cea9d23f82903db37b7d8b5bd00d967' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6366 processed earlier; will process 4663 files now Step #5: #1 pulse cov: 4105 ft: 4106 exec/s: 0 rss: 178Mb Step #5: ==181156== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5640c38a29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5640c9f07898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640c9eea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640c9eea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5640c38a8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5640c3809b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5640c3804355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5640c389ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5640c6869f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5640c6869f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5640c6869f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5640c6869f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5640c6869f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5640c6869f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5640c6869f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5640c6869f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5640c6869f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5640c6869f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5640c8afef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5640c582bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5640c5836be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5640c55e2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5640c55e2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5640c55e3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5640c55e2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5640c55e2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5640c55e2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5640c9eecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5640c9ef5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5640c9edd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5640c9f08112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe5d2e31082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5640c3802b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x7f,0x32,0x5d,0x32,0x2e,0x32,0x2e,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x73,0x20,0x37,0x20,0x30,0x20,0x32,0x10,0x32,0x33,0x2f,0x10,0x2e,0x2f,0x73,0x20,0x37,0x20,0x30,0x32,0x32,0x32,0x32,0x32,0x33,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x20,0x32,0x10,0x20,0x32,0x10,0x2e,0x2,0x0,0x2f,0x2d,0x7f,0x7f,0x6f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x31,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x32,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7f,0x7f,0x7f,0x7f,0x6f,0x0,0x0,0x43,0x24, Step #5: $\1772]2.2.23/\020./s 7 0 2\02023/\020./s 7 02222232222222222222 2\020 2\020.\002\000/-\177\177o\177\177\177\177\177\177\177\177\000\000\000\000\000\000\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\0002222222222222222222222222222222222222222\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\020\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\177\177\177\177o\000\000C$ Step #5: artifact_prefix='./'; Test unit written to ./oom-6cd1e694e7a416e234b01ca811fbbc2ac2a08a2d Step #5: Base64: JH8yXTIuMi4yMy8QLi9zIDcgMCAyEDIzLxAuL3MgNyAwMjIyMjIzMjIyMjIyMjIyMjIyMiAyECAyEC4CAC8tf39vf39/f39/f38AAAAAAAAAAAAAMQAAAAAAAAAAAAAAAAAyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB/f39/bwAAQyQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5031 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4274504126 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5557bc797810, 0x5557bc98101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5557bc981020,0x5557be8190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6cd1e694e7a416e234b01ca811fbbc2ac2a08a2d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6368 processed earlier; will process 4661 files now Step #5: ==181192== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5557b328c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5557b98f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557b98d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557b98d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557b3292d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557b31f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5557b31ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557b3284c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557b6253f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557b6253f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557b6253f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557b6253f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557b6253f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557b6253f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557b6253f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557b6253f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557b6253f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557b6253f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5557b84e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557b5215b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557b5220be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5557b4fccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5557b4fccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5557b4fcd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5557b4fcc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5557b4fcc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5557b4fcc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557b98d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557b98df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557b98c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5557b98f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f51eee03082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5557b31ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x7d,0x7d,0x3c,0x74,0x65,0x78,0x74,0x3e,0x65,0x78,0x74,0x3e,0x5e,0xe0,0xad,0x8b,0x3b,0xd,0x61,0x3e,0x3b,0x2d,0xe0,0xb0,0x8e,0x30,0x30,0x30,0x61,0xe1,0xbf,0x8d,0xcd,0x8f,0xe0,0xa6,0x8b,0x6e,0x6e,0x61,0x3e,0x3b,0x3e,0x3e,0x3e,0x3e,0x69,0x63,0x73,0x38,0x3e,0x3e,0x3e,0x3e,0x53,0x3e,0x61,0xe1,0xbf,0x8d,0xcd,0x8f,0xe0,0xa6,0x8b,0x29,0x2f,0x34,0xdb,0xba,0x2d,0x3e,0x3e,0x61,0xe9,0xbf,0x8d,0x66,0x6f,0x6e,0x74,0x2d,0x77,0x65,0x69,0x67,0x68,0x74,0xe1,0xb0,0x8e,0x30,0x29,0x30,0x30,0x5e,0xe0,0xad,0x8b,0x3b,0xd,0x61,0x3e,0x3b,0x2d,0xe1,0xb0,0x8e,0x30,0x30,0x30,0x61,0xe1,0xbf,0x8d,0xcd,0x8f,0xe0,0xa6,0x8b,0x6e,0x6e,0x61,0x3e,0x3b,0x3e,0x3e,0x36,0x3e,0x3e,0x3e,0x3e,0x69,0x63,0x73,0x38,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x61,0xe1,0xbf,0x8d,0xcd,0x8f,0xe0,0xb6,0x8b,0x29,0x2f,0x34,0xdb,0xba,0x2d,0x3e,0x3e,0x61,0xe9,0xbf,0x8d,0xcd,0x8f,0xe0,0xa6,0x8b,0x6e,0x6e,0x61,0x3e,0x3b,0x2d,0xe1,0xb0,0x8e,0x30,0x29,0x30,0x30,0x61,0xe1,0xbf,0x8d,0xcd,0x8f,0xe0,0xa6,0x8b,0x6e,0x6e,0x61,0x3e,0x3b,0xcd,0x8f,0xe0,0xa6,0x8b,0x6e,0x6e,0x61,0x3e,0x3b,0x34,0xdb,0xba,0x2d,0x29,0x28,0x28,0x69,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3e,0x3e,0x2c,0x47,0x47,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg>}}<text>ext>^\340\255\213;\015a>;-\340\260\216000a\341\277\215\315\217\340\246\213nna>;>>>>ics8>>>>S>a\341\277\215\315\217\340\246\213)/4\333\272->>a\351\277\215font-weight\341\260\2160)00^\340\255\213;\015a>;-\341\260\216000a\341\277\215\315\217\340\246\213nna>;>>6>>>>ics8>>>>>>a\341\277\215\315\217\340\266\213)/4\333\272->>a\351\277\215\315\217\340\246\213nna>;-\341\260\2160)00a\341\277\215\315\217\340\246\213nna>;\315\217\340\246\213nna>;4\333\272-)((i</text>>>,GG</svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-b5e0cc655881980a8eab22bc5cb357528835d472 Step #5: Base64: PHN2Zz59fTx0ZXh0PmV4dD5e4K2LOw1hPjst4LCOMDAwYeG/jc2P4KaLbm5hPjs+Pj4+aWNzOD4+Pj5TPmHhv43Nj+CmiykvNNu6LT4+Yem/jWZvbnQtd2VpZ2h04bCOMCkwMF7grYs7DWE+Oy3hsI4wMDBh4b+NzY/gpotubmE+Oz4+Nj4+Pj5pY3M4Pj4+Pj4+YeG/jc2P4LaLKS8027otPj5h6b+NzY/gpotubmE+Oy3hsI4wKTAwYeG/jc2P4KaLbm5hPjvNj+Cmi25uYT47NNu6LSkoKGk8L3RleHQ+Pj4sR0c8L3N2Zz4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5032 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4275042679 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643bac9e810, 0x5643bae8801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643bae88020,0x5643bcd200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b5e0cc655881980a8eab22bc5cb357528835d472' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6369 processed earlier; will process 4660 files now Step #5: ==181228== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643b17939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643b7df8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643b7ddb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643b7ddb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643b1799d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643b16fab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643b16f5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643b178bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643b475af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643b475af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643b475af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643b475af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643b475af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643b475af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643b475af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643b475af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643b475af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643b475af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643b69eff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643b371cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643b3727be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643b34d3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643b34d3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643b34d4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643b34d3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643b34d3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643b34d3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643b7dddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643b7de6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643b7dce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643b7df9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa69e291082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643b16f3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x4c,0x54,0x45,0x52,0x20,0x49,0x4e,0x44,0x45,0x58,0x20,0x49,0x46,0x20,0x45,0x58,0x49,0x53,0x54,0x53,0x20,0x50,0x20,0x6f,0x46,0x20,0x74,0x3b,0x41,0x4c,0x54,0x45,0x52,0x20,0x49,0x4e,0x44,0x45,0x58,0x20,0x49,0x46,0x20,0x45,0x58,0x49,0x53,0x54,0x53,0x20,0x50,0x20,0x6f,0x46,0x20,0x74,0x3b,0x41,0x4c,0x54,0x45,0x52,0x20,0x49,0x4e,0x44,0x45,0x58,0x20,0x49,0x46,0x20,0x45,0x58,0x49,0x53,0x54,0x53,0x20,0x50,0x20,0x6f,0x46,0x20,0x74,0x3b,0x41,0x4c,0x54,0x45,0x52,0x20,0x49,0x4e,0x44,0x45,0x58,0x20,0x49,0x46,0x20,0x45,0x58,0x49,0x53,0x54,0x53,0x20,0x50,0x20,0x6f,0x46,0x20,0x74,0x3b,0x41,0x4c,0x54,0x45,0x52,0x20,0x49,0x4e,0x44,0x45,0x58,0x20,0x49,0x46,0x20,0x45,0x58,0x49,0x53,0x54,0x53,0x20,0x50,0x20,0x6f,0x46,0x20,0x74,0x3b,0x41,0x4c,0x54,0x45,0x52,0x20,0x49,0x4e,0x44,0x45,0x58,0x20,0x49,0x46,0x20,0x45,0x58,0x49,0x53,0x54,0x53,0x20,0x50,0x20,0x6f,0x46,0x20,0x74,0x3b,0x41,0x4c,0x54,0x45,0x52,0x20,0x49,0x4e,0x44,0x45,0x58,0x20,0x49,0x46,0x20,0x45,0x58,0x49,0x53,0x54,0x53,0x20,0x50,0x20,0x6f,0x46,0x20,0x74,0x3b,0x41,0x4c,0x54,0x45,0x52,0x20,0x49,0x4e,0x44,0x45,0x58,0x20,0x49,0x46,0x20,0x45,0x58,0x49,0x53,0x54,0x53,0x20,0x50,0x20,0x6f,0x46,0x20,0x74,0x3b,0x41,0x20,0x74,0x3b, Step #5: ALTER INDEX IF EXISTS P oF t;ALTER INDEX IF EXISTS P oF t;ALTER INDEX IF EXISTS P oF t;ALTER INDEX IF EXISTS P oF t;ALTER INDEX IF EXISTS P oF t;ALTER INDEX IF EXISTS P oF t;ALTER INDEX IF EXISTS P oF t;ALTER INDEX IF EXISTS P oF t;A t; Step #5: artifact_prefix='./'; Test unit written to ./oom-e7b46ab73ac58095c541b6bd7b758466ce55fcbb Step #5: Base64: QUxURVIgSU5ERVggSUYgRVhJU1RTIFAgb0YgdDtBTFRFUiBJTkRFWCBJRiBFWElTVFMgUCBvRiB0O0FMVEVSIElOREVYIElGIEVYSVNUUyBQIG9GIHQ7QUxURVIgSU5ERVggSUYgRVhJU1RTIFAgb0YgdDtBTFRFUiBJTkRFWCBJRiBFWElTVFMgUCBvRiB0O0FMVEVSIElOREVYIElGIEVYSVNUUyBQIG9GIHQ7QUxURVIgSU5ERVggSUYgRVhJU1RTIFAgb0YgdDtBTFRFUiBJTkRFWCBJRiBFWElTVFMgUCBvRiB0O0EgdDs= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5033 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4275566821 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c6c3ed810, 0x564c6c5d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c6c5d7020,0x564c6e46f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e7b46ab73ac58095c541b6bd7b758466ce55fcbb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6370 processed earlier; will process 4659 files now Step #5: ==181264== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564c62ee29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c69547898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c6952a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c6952a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c62ee8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c62e49b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c62e44355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c62edac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c65ea9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c65ea9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c65ea9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c65ea9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c65ea9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c65ea9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c65ea9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c65ea9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c65ea9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c65ea9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c6813ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c64e6bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c64e76be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c64c22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c64c22c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c64c23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c64c22874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c64c22874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c64c22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c6952cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c69535928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c6951d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c69548112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe3952e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c62e42b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x75,0x70,0x64,0x61,0x74,0x65,0x5d,0xa,0x63,0x6f,0x6d,0x70,0x61,0x74,0x69,0x62,0x6c,0x65,0x3d,0xd2,0x83,0xd2,0xb4,0xd6,0x83,0xd2,0x85,0xc2,0x83,0xd2,0xb4,0xd2,0x85,0xc2,0x81,0xd2,0x83,0xd2,0xb4,0xda,0x83,0xdb,0x83,0xd2,0xb4,0xd2,0x85,0xc2,0x83,0xd2,0xb4,0xda,0x83,0xc2,0x83,0xd2,0xb4,0xd6,0x83,0xc2,0x83,0xd2,0xb4,0xd3,0x9a,0xc2,0x84,0xd9,0xbf,0xd2,0xb4,0xd2,0xb4,0xda,0x83,0xc2,0x81,0xd2,0x83,0xd2,0xb4,0xda,0x83,0xdb,0x83,0xd2,0xb4,0xd2,0x85,0xc2,0x83,0xd2,0xb4,0xda,0x83,0xc2,0x83,0xd2,0xb4,0xd6,0x83,0xc2,0x83,0xd2,0xb4,0xd3,0x9a,0xc2,0x83,0xd9,0xb4,0x32,0xd2,0xb4,0xda,0x83,0xc2,0x81,0xd2,0x83,0xc2,0x81,0xd2,0x83,0xd2,0xb4,0xda,0x83,0xd2,0xb4,0xd2,0x85,0xc2,0x83,0xd2,0xb4,0xda,0x83,0xc2,0x83,0xd2,0xb4,0xd6,0x83,0xc2,0x83,0xd2,0xb4,0xd3,0x9a,0xc2,0x83,0xd9,0xb4,0xd2,0xb4,0xda,0x83,0xc2,0x81,0xd2,0x83,0xc2,0x81,0xd2,0x83,0xd2,0xb4,0xda,0x83,0xdb,0x83,0xd2,0xb4,0xd2,0x85,0xc2,0x83,0xd2,0xb4,0xda,0x83,0xc2,0x83,0xd2,0xb4,0xd6,0x83,0xc2,0x83,0xd2,0xb4,0xd3,0x9a,0xc2,0x83,0xd9,0xb4,0xd2,0xb4,0xda,0x83,0xc2,0x81,0xd2,0x83,0xc2,0x81,0xd2,0x83,0xd2,0xb4,0xda,0x83,0xc2,0x83,0xd2,0xb4,0xd6,0x83,0xc2,0x83,0xd2,0xb4,0xda,0x83,0xd2,0xb4,0xda,0x83,0xdb,0x83,0xd2,0xb4,0xe0, Step #5: [update]\012compatible=\322\203\322\264\326\203\322\205\302\203\322\264\322\205\302\201\322\203\322\264\332\203\333\203\322\264\322\205\302\203\322\264\332\203\302\203\322\264\326\203\302\203\322\264\323\232\302\204\331\277\322\264\322\264\332\203\302\201\322\203\322\264\332\203\333\203\322\264\322\205\302\203\322\264\332\203\302\203\322\264\326\203\302\203\322\264\323\232\302\203\331\2642\322\264\332\203\302\201\322\203\302\201\322\203\322\264\332\203\322\264\322\205\302\203\322\264\332\203\302\203\322\264\326\203\302\203\322\264\323\232\302\203\331\264\322\264\332\203\302\201\322\203\302\201\322\203\322\264\332\203\333\203\322\264\322\205\302\203\322\264\332\203\302\203\322\264\326\203\302\203\322\264\323\232\302\203\331\264\322\264\332\203\302\201\322\203\302\201\322\203\322\264\332\203\302\203\322\264\326\203\302\203\322\264\332\203\322\264\332\203\333\203\322\264\340 Step #5: artifact_prefix='./'; Test unit written to ./oom-42b13f0d8e95cb899ccab132aa7f317df8bfec81 Step #5: Base64: W3VwZGF0ZV0KY29tcGF0aWJsZT3Sg9K01oPShcKD0rTShcKB0oPStNqD24PStNKFwoPStNqDwoPStNaDwoPStNOawoTZv9K00rTag8KB0oPStNqD24PStNKFwoPStNqDwoPStNaDwoPStNOawoPZtDLStNqDwoHSg8KB0oPStNqD0rTShcKD0rTag8KD0rTWg8KD0rTTmsKD2bTStNqDwoHSg8KB0oPStNqD24PStNKFwoPStNqDwoPStNaDwoPStNOawoPZtNK02oPCgdKDwoHSg9K02oPCg9K01oPCg9K02oPStNqD24PStOA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5034 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4276094970 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ad1dbf0810, 0x55ad1ddda01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ad1ddda020,0x55ad1fc720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/42b13f0d8e95cb899ccab132aa7f317df8bfec81' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6371 processed earlier; will process 4658 files now Step #5: ==181300== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ad146e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ad1ad4a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ad1ad2d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ad1ad2d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ad146ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ad1464cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ad14647355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ad146ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ad176acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ad176acf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ad176acf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ad176acf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ad176acf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ad176acf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ad176acf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ad176acf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ad176acf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ad176acf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ad19941f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ad1666eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ad16679be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ad16425c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ad16425c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ad16426738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ad16425874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ad16425874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ad16425874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ad1ad2fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ad1ad38928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ad1ad20699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ad1ad4b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4d505c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ad14645b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0x5e,0x0,0x0,0x0,0xa,0xa,0x72,0x3d,0x73,0x65,0x66,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0xa,0x3d,0x2d,0x2d,0x3d,0x32,0x2,0x55,0x20,0x2d,0x45,0xa,0xa,0x6b,0x3,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xff,0x65,0x6e, Step #5: \005-----BEGIN =^\000\000\000\012\012r=sef=\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012=\012=\012= \000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012=\012=\012= \000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012\012=--=2\002U -E\012\012k\003ip_cl\012|\000\020\377en Step #5: artifact_prefix='./'; Test unit written to ./oom-585b72fa0ab0dfad4445807f25d5ca1493889ecc Step #5: Base64: BS0tLS0tQkVHSU4gPV4AAAAKCnI9c2VmPQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAKPQo9Cj0gAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAo9Cj0KPSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAoKPS0tPTICVSAtRQoKawNpcF9jbAp8ABD/ZW4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5035 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4276615973 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55822a01d810, 0x55822a20701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55822a207020,0x55822c09f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/585b72fa0ab0dfad4445807f25d5ca1493889ecc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6372 processed earlier; will process 4657 files now Step #5: ==181336== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558220b129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558227177898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55822715a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55822715a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558220b18d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558220a79b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558220a74355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558220b0ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558223ad9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558223ad9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558223ad9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558223ad9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558223ad9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558223ad9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558223ad9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558223ad9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558223ad9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558223ad9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558225d6ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558222a9bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558222aa6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558222852c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558222852c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558222853738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558222852874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558222852874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558222852874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55822715cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558227165928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55822714d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558227178112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb2688e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558220a72b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x24,0x24,0x24,0x24,0x24,0x7a,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x24,0x0,0x0,0x0,0x0,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x3a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xae,0x34, Step #5: \000\000\000\000\000\000$$$$$$z$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$\000\000\000\000::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\2564 Step #5: artifact_prefix='./'; Test unit written to ./oom-77e91ea78739d1121762049e681270fd32829dce Step #5: Base64: AAAAAAAAJCQkJCQkeiQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJAAAAAA6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6Ojo6OgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAArjQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5036 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4277153542 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558f64782810, 0x558f6496c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558f6496c020,0x558f668040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/77e91ea78739d1121762049e681270fd32829dce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6373 processed earlier; will process 4656 files now Step #5: #1 pulse cov: 3824 ft: 3825 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 7249 ft: 7718 exec/s: 0 rss: 192Mb Step #5: ==181372== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558f5b2779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558f618dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558f618bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558f618bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f5b27dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f5b1deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f5b1d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f5b26fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f5e23ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f5e23ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f5e23ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f5e23ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f5e23ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f5e23ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f5e23ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f5e23ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f5e23ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f5e23ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558f604d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f5d200b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f5d20bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f5cfb7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f5cfb7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f5cfb8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f5cfb7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f5cfb7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f5cfb7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558f618c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558f618ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558f618b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558f618dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7effccbc0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f5b1d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x21,0x44,0x4f,0x43,0x54,0x59,0x50,0x45,0xa,0x47,0x5b,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xd,0x61,0xa,0x27,0x71,0x3c,0x57,0x57,0x78,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x78,0x3e,0x3c,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x49,0x53,0x4f,0x2d,0x38,0x38,0x35,0x39,0x2d,0x31,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x78,0x3e,0x3c,0x57,0x57,0x78,0x41,0x41,0x41,0x41,0x41,0x43,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x3e,0x3b,0x26,0x71,0x3b,0x27,0x3e,0x3c,0x21,0x45,0x4e,0x54,0x49,0x54,0x59,0xd,0x71,0xa,0x27,0x34,0x27,0x3e,0x5d,0x3e,0x3c,0x76,0x3e,0x26,0x61,0x3b,0x26,0x61,0x3b,0x3e,0x26,0x61,0x3b,0x26,0x61,0x3b,0x26,0x61,0x3b,0x26,0x61,0x3b,0x26,0x61,0x3b,0x26,0x61,0x3b,0x3e,0x26,0x61,0x3b,0x26,0x61,0x3b,0x26,0x61,0x3b,0x26,0x61,0x3b,0x26,0x61,0x3b,0x26,0x61,0x3b,0x2f,0x3e,0x26,0x61,0x3b,0x26,0x61,0x3b, Step #5: <!DOCTYPE\012G[<!ENTITY\015a\012'q<WWxAAAAAAAAAAAAAAAAAAAAAAAAAAAAx><AAAAAAAAAAAAAAAAAAAAAAAAISO-8859-1AAAAAAAAAAAAAAAAAAAAAAAAAAAAAx><WWxAAAAACAAAAAAAAAAAAAAAAAAAAAAA>;&q;'><!ENTITY\015q\012'4'>]><v>&a;&a;>&a;&a;&a;&a;&a;&a;>&a;&a;&a;&a;&a;&a;/>&a;&a; Step #5: artifact_prefix='./'; Test unit written to ./oom-390c5f7ac6a8260561a6999abfe9010cb5d05919 Step #5: Base64: PCFET0NUWVBFCkdbPCFFTlRJVFkNYQoncTxXV3hBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBeD48QUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBSVNPLTg4NTktMUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBeD48V1d4QUFBQUFDQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUE+OyZxOyc+PCFFTlRJVFkNcQonNCc+XT48dj4mYTsmYTs+JmE7JmE7JmE7JmE7JmE7JmE7PiZhOyZhOyZhOyZhOyZhOyZhOy8+JmE7JmE7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5037 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4277808238 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a6e8a3810, 0x559a6ea8d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a6ea8d020,0x559a709250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/390c5f7ac6a8260561a6999abfe9010cb5d05919' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6377 processed earlier; will process 4652 files now Step #5: #1 pulse cov: 3793 ft: 3794 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4112 ft: 4486 exec/s: 0 rss: 177Mb Step #5: #4 pulse cov: 5107 ft: 6122 exec/s: 0 rss: 180Mb Step #5: ==181408== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559a653989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a6b9fd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a6b9e05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a6b9e04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a6539ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a652ffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a652fa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a65390c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a6835ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a6835ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a6835ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a6835ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a6835ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a6835ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a6835ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a6835ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a6835ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a6835ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a6a5f4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a67321b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a6732cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a670d8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a670d8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a670d9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a670d8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a670d8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a670d8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a6b9e2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a6b9eb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a6b9d3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a6b9fe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe2a0cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a652f8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x2d,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x3d,0x3c,0x2d,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x24,0x27,0x2d,0x24,0x2d,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x7,0x3d,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x24,0x27,0x2d,0x24,0x2d,0x39,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x33,0x36,0x38,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x2d,0x35,0x34,0x37,0x37,0x35,0x35,0x35,0x31,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x65,0x78,0x70,0x27,0x4e,0x27,0x32,0x2d,0x7,0x3d,0x27,0x27,0x27,0x7,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x24,0x27,0x2d, Step #5: $-9223372036854775551-=<-1''/''''/'''exp'N'2-\007='''''$'-$-9223372036854775551-54775551''/''''/'''exp'N'2-\007='''''exp'N'2-\007='''\007=''/''''/'''exp'N'2-\007='''''$'-$-9223372036854775551-54775551''/''''/'''exp'N'2-\007='''''exp'N'2-\007='''\007=''''''''$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-1f3a9c5cfcdcccc6638b19a809e96a1ea7486d35 Step #5: Base64: JC05MjIzMzcyMDM2ODU0Nzc1NTUxLT08LTEnJy8nJycnLycnJ2V4cCdOJzItBz0nJycnJyQnLSQtOTIyMzM3MjAzNjg1NDc3NTU1MS01NDc3NTU1MScnLycnJycvJycnZXhwJ04nMi0HPScnJycnZXhwJ04nMi0HPScnJwc9JycvJycnJy8nJydleHAnTicyLQc9JycnJyckJy0kLTkyMjMzNzIwMzY4NTQ3NzU1NTEtNTQ3NzU1NTEnJy8nJycnLycnJ2V4cCdOJzItBz0nJycnJ2V4cCdOJzItBz0nJycHPScnJycnJycnJCct Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5038 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4278500081 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a530f2d810, 0x55a53111701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a531117020,0x55a532faf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f3a9c5cfcdcccc6638b19a809e96a1ea7486d35' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6382 processed earlier; will process 4647 files now Step #5: #1 pulse cov: 3752 ft: 3753 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4489 ft: 5032 exec/s: 0 rss: 177Mb Step #5: ==181444== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a527a229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a52e087898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a52e06a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a52e06a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a527a28d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a527989b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a527984355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a527a1ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a52a9e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a52a9e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a52a9e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a52a9e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a52a9e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a52a9e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a52a9e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a52a9e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a52a9e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a52a9e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a52cc7ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a5299abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a5299b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a529762c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a529762c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a529763738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a529762874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a529762874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a529762874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a52e06cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a52e075928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a52e05d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a52e088112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f873172f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a527982b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x30,0x2d,0x3d,0x2f,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x33,0x32,0x37,0x36,0x37,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x31,0x2d,0x27,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x32,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x2f,0x27,0x27,0x33,0x32,0x37,0x36,0x37,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x31,0x2d,0x27,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x31,0x2d,0x3d,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $0-=/'''/''''/''32767-=''''''/''1-'='''''''''''''-2=<''''''''''''-=<'''/''''/'''/'''\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000'/''32767-=''''''/''1-'='''''''''''''-=<''''''''''''-=<'''''''''1-='\000\000\000\000\000\000\000\001''''.''''''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-ae566ae476e37c9c51814896b2a3838394cdb3c8 Step #5: Base64: JDAtPS8nJycvJycnJy8nJzMyNzY3LT0nJycnJycvJycxLSc9JycnJycnJycnJycnJy0yPTwnJycnJycnJycnJyctPTwnJycvJycnJy8nJycvJycnAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACcvJyczMjc2Ny09JycnJycnLycnMS0nPScnJycnJycnJycnJyctPTwnJycnJycnJycnJyctPTwnJycnJycnJycxLT0nAAAAAAAAAAEnJycnLicnJycnJycnLickJy0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5039 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4279112004 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562553000810, 0x5625531ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625531ea020,0x5625550820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ae566ae476e37c9c51814896b2a3838394cdb3c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6385 processed earlier; will process 4644 files now Step #5: #1 pulse cov: 3762 ft: 3763 exec/s: 0 rss: 177Mb Step #5: ==181480== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562549af59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56255015a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56255013d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56255013d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562549afbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562549a5cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562549a57355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562549aedc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56254cabcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56254cabcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56254cabcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56254cabcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56254cabcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56254cabcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56254cabcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56254cabcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56254cabcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56254cabcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56254ed51f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56254ba7eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56254ba89be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56254b835c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56254b835c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56254b836738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56254b835874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56254b835874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56254b835874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56255013fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562550148928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562550130699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56255015b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f14749e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562549a55b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x6e,0xe2,0x9e,0x8c,0xe0,0xa9,0x99,0x5b,0x5b,0x5b,0x5b,0xe0,0xa9,0x8f,0x3f,0x42,0x4c,0x38,0x62,0x5b,0x5b,0xa,0xa,0x5b,0x5b,0x5b,0x5b,0x5a,0xa,0xa,0x65,0x69,0x6c,0x6c,0xa,0x9,0x63,0x50,0xe1,0xb4,0x80,0xe2,0x80,0x9d,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0xe2,0x80,0x8c,0xe0,0xa6,0x8b,0x5b,0x5b,0x5b,0x5a,0x5b,0x5b,0xa,0xe2,0x9e,0x8d,0xe0,0xb4,0x99,0xe0,0xa9,0x8c,0xe0,0xa5,0x92,0xa,0x5b,0x5b,0x5b,0x5b,0xe2,0x80,0x8c,0xe0,0xa5,0x8e,0xa,0x5b,0x5b,0x5b,0x5a,0x5b,0x5b,0xa,0xe2,0x9e,0x8d,0xe0,0xb4,0x99,0xe0,0xa9,0x8c,0xe0,0xa5,0x92,0xa,0x5b,0x5b,0x5b,0x5b,0x5b,0x5b,0xa,0xe2,0x9e,0x8d,0xa,0xe2,0x9e,0x8d,0xe1,0xa9,0x99,0xe0,0xa9,0x8d,0xe2,0x80,0x8d,0xe2,0x80,0x8c,0xe0,0xa5,0x8e,0xa,0x58,0x3f,0x62,0x5b,0x5b,0x7f,0xa,0x5b,0x76,0x61,0x71,0xa,0xe2,0x9e,0x8d,0xe0,0xa9,0x99,0xe0,0xa9,0x8d,0xe2,0x80,0x93,0x5b,0x5b,0xa,0xe2,0x9e,0x8d,0xe0,0xb4,0x99,0xe0,0xa9,0x8c,0xe0,0xa9,0x8d,0xe2,0x80,0x8c,0xe0,0xa5,0x92,0xe0,0xa9,0x8d,0xe2,0x80,0x8d,0xe2,0x80,0x8c,0xe0,0xa5,0x8e,0xa,0x5b,0xe0,0xa9,0x8d,0xe2,0x80,0x8c,0xe0,0xa5,0x92,0xe0,0xa9,0x8d,0xe2,0x80,0x8d,0xe2,0x80,0x8c,0xe0,0xa5,0x8e,0xa,0x5b,0x5b,0x3c,0x73,0x79,0x6d,0x62,0x6f,0x6c,0x3e, Step #5: <svg><text>n\342\236\214\340\251\231[[[[\340\251\217?BL8b[[\012\012[[[[Z\012\012eill\012\011cP\341\264\200\342\200\235[[[[[[\342\200\214\340\246\213[[[Z[[\012\342\236\215\340\264\231\340\251\214\340\245\222\012[[[[\342\200\214\340\245\216\012[[[Z[[\012\342\236\215\340\264\231\340\251\214\340\245\222\012[[[[[[\012\342\236\215\012\342\236\215\341\251\231\340\251\215\342\200\215\342\200\214\340\245\216\012X?b[[\177\012[vaq\012\342\236\215\340\251\231\340\251\215\342\200\223[[\012\342\236\215\340\264\231\340\251\214\340\251\215\342\200\214\340\245\222\340\251\215\342\200\215\342\200\214\340\245\216\012[\340\251\215\342\200\214\340\245\222\340\251\215\342\200\215\342\200\214\340\245\216\012[[<symbol> Step #5: artifact_prefix='./'; Test unit written to ./oom-42f2defe93f6679baa228610944556a3dbe8f784 Step #5: Base64: PHN2Zz48dGV4dD5u4p6M4KmZW1tbW+Cpjz9CTDhiW1sKCltbW1taCgplaWxsCgljUOG0gOKAnVtbW1tbW+KAjOCmi1tbW1pbWwrino3gtJngqYzgpZIKW1tbW+KAjOCljgpbW1taW1sK4p6N4LSZ4KmM4KWSCltbW1tbWwrino0K4p6N4amZ4KmN4oCN4oCM4KWOClg/YltbfwpbdmFxCuKejeCpmeCpjeKAk1tbCuKejeC0meCpjOCpjeKAjOClkuCpjeKAjeKAjOCljgpb4KmN4oCM4KWS4KmN4oCN4oCM4KWOCltbPHN5bWJvbD4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5040 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4279682747 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563921115810, 0x5639212ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5639212ff020,0x5639231970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/42f2defe93f6679baa228610944556a3dbe8f784' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6387 processed earlier; will process 4642 files now Step #5: ==181516== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563917c0a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56391e26f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56391e2525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56391e2524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563917c10d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563917b71b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563917b6c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563917c02c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56391abd1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56391abd1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56391abd1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56391abd1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56391abd1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56391abd1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56391abd1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56391abd1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56391abd1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56391abd1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56391ce66f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563919b93b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563919b9ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56391994ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56391994ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56391994b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56391994a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56391994a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56391994a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56391e254abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56391e25d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56391e245699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56391e270112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd7393b5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563917b6ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x39,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xdb,0x80,0x38,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x73,0x20,0x5b,0x30,0x20,0x32,0x0,0x0,0x0,0x0,0x0,0x0,0xdb,0x80,0xdb,0x80,0x39,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xdb,0x80,0x38,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x73,0x20,0x5b,0x30,0x20,0x32,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3f,0x0,0x8,0x0,0x0,0x0,0x39, Step #5: 9\000*********************************************\333\2008\000*************************************\000\000\000\000\000\000\000\001\000\000s [0 2\000\000\000\000\000\000\333\200\333\2009\000*********************************************\333\2008\000*************************************\000\000\000\000\000\000\000\001\000\000s [0 2\000\000\000\000\000\000\000\000\000\000\000\000\000\000?\000\010\000\000\0009 Step #5: artifact_prefix='./'; Test unit written to ./oom-c0f41765d314dbc2758902d22f8b4b9b194d04c9 Step #5: Base64: OQAqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKirbgDgAKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKgAAAAAAAAABAABzIFswIDIAAAAAAADbgNuAOQAqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKirbgDgAKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKgAAAAAAAAABAABzIFswIDIAAAAAAAAAAAAAAAAAAD8ACAAAADk= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5041 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4280218858 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556e9c456810, 0x556e9c64001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556e9c640020,0x556e9e4d80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c0f41765d314dbc2758902d22f8b4b9b194d04c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6388 processed earlier; will process 4641 files now Step #5: ==181552== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556e92f4b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556e995b0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556e995935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556e995934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556e92f51d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556e92eb2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556e92ead355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556e92f43c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556e95f12f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556e95f12f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556e95f12f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556e95f12f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556e95f12f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556e95f12f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556e95f12f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556e95f12f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556e95f12f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556e95f12f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556e981a7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556e94ed4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556e94edfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556e94c8bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556e94c8bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556e94c8c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556e94c8b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556e94c8b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556e94c8b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556e99595abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556e9959e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556e99586699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556e995b1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc2a8038082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556e92eabb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc,0xa,0xe3,0x8d,0xbf,0xc2,0xbc,0xe3,0x8d,0xbf,0xe3,0x8c,0x96,0xef,0xb7,0xbc, Step #5: \343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274\012\343\215\277\302\274\343\215\277\343\214\226\357\267\274 Step #5: artifact_prefix='./'; Test unit written to ./oom-b309666b0b33730fad96418c901d659b48ddcaad Step #5: Base64: 442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7wK442/wrzjjb/jjJbvt7w= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5042 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4280742105 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9b86e8810, 0x55e9b88d201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9b88d2020,0x55e9ba76a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b309666b0b33730fad96418c901d659b48ddcaad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6389 processed earlier; will process 4640 files now Step #5: ==181588== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e9af1dd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9b5842898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9b58255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9b58254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9af1e3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e9af144b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e9af13f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9af1d5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e9b21a4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e9b21a4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e9b21a4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e9b21a4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e9b21a4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e9b21a4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e9b21a4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e9b21a4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e9b21a4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e9b21a4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9b4439f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e9b1166b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e9b1171be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9b0f1dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9b0f1dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9b0f1e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9b0f1d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9b0f1d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9b0f1d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e9b5827abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9b5830928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e9b5818699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e9b5843112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e21380082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e9af13db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x21,0x21,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x3f,0x2b,0x3f,0x2b,0x2b,0x3f,0x2b,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x2b,0x3f,0x3f,0x2b,0x2b,0x2b,0x2b,0x2b,0x3f,0x3f,0x2b,0x3f,0x3f,0x74,0x61,0x67,0x3a,0x79,0x61,0x6d,0x6c,0x2e,0x6f,0x72,0x67,0x2c,0x32,0x30,0x30,0x31,0x3a,0x2b,0x2b,0x2b,0x2b,0x3f,0x2b,0x2b,0x2b,0x3f,0x3f,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x2b,0x56,0x3f,0x2b,0x3f,0x2b,0x2b,0x2b,0x2b,0x3f,0x30,0x3a,0x2b,0x2b,0x3f,0x2b,0x3f,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x2b,0x3f,0x2b,0x3f,0x2b,0x2b,0x2b,0x2b,0x49,0x2b,0x3f,0x2b,0x3f,0x3f,0x2b,0x2b,0x2b,0x3f,0x3f,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x2b,0x3f,0x3f,0x2b,0x2b,0x3f,0x3f,0x2b,0x3f,0x6b,0x2b,0x2b,0x3f,0x2b,0x3f,0x2b,0x2b,0x3f,0x2b,0x3f,0x2b,0x2b,0x2b,0x2b,0x3f,0x2b,0x2b,0x31,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x2b,0x3f,0x3f,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x62,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x74,0x61,0x67,0x3a,0x79,0x61,0x6d,0x6c,0x2e,0x6f,0x72,0x67,0x2c,0x32,0x30,0x30,0x33,0x3a,0x6d,0x61,0x70,0x2b,0x2b,0x2b,0x2b, Step #5: !!++++++++++++++?+?++?++?+?+?++??+++++??+??tag:yaml.org,2001:++++?+++???+?+?++?+?+?++V?+?++++?0:++?+??+?+?++?+?++++I+?+??+++??++++++++??++??+?k++?+?++?+?++++?++1+?+?+?++??bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb+?+?+?tag:yaml.org,2003:map++++ Step #5: artifact_prefix='./'; Test unit written to ./oom-68f04f6f1e4aa6f8e727cec012c8e71fe23a7599 Step #5: Base64: ISErKysrKysrKysrKysrKz8rPysrPysrPys/Kz8rKz8/KysrKys/Pys/P3RhZzp5YW1sLm9yZywyMDAxOisrKys/KysrPz8/Kz8rPysrPys/Kz8rK1Y/Kz8rKysrPzA6Kys/Kz8/Kz8rPysrPys/KysrK0krPys/PysrKz8/KysrKysrKys/PysrPz8rP2srKz8rPysrPys/KysrKz8rKzErPys/Kz8rKz8/YmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmJiYmIrPys/Kz90YWc6eWFtbC5vcmcsMjAwMzptYXArKysr Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5043 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4281309284 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c3e394a810, 0x55c3e3b3401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c3e3b34020,0x55c3e59cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/68f04f6f1e4aa6f8e727cec012c8e71fe23a7599' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6390 processed earlier; will process 4639 files now Step #5: ==181624== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c3da43f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c3e0aa4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c3e0a875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c3e0a874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c3da445d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c3da3a6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c3da3a1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c3da437c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c3dd406f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c3dd406f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c3dd406f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c3dd406f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c3dd406f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c3dd406f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c3dd406f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c3dd406f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c3dd406f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c3dd406f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c3df69bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c3dc3c8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c3dc3d3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c3dc17fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c3dc17fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c3dc180738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c3dc17f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c3dc17f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c3dc17f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c3e0a89abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c3e0a92928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c3e0a7a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c3e0aa5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c726c1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c3da39fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x74,0x61,0x74,0x65,0x6d,0x65,0x6e,0x74,0x73,0x20,0x7b,0xa,0x20,0x20,0x73,0x74,0x61,0x74,0x65,0x6d,0x65,0x6e,0x74,0x73,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x61,0x73,0x73,0x69,0x67,0x6e,0x6d,0x65,0x6e,0x74,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x72,0x76,0x61,0x6c,0x75,0x65,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x62,0x69,0x6e,0x6f,0x70,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x6f,0x70,0x3a,0x20,0x4c,0x45,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x6c,0x65,0x66,0x74,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x63,0x6f,0x6e,0x73,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x69,0x6e,0x74,0x5f,0x6c,0x69,0x74,0x3a,0x20,0x39,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x72,0x69,0x67,0x68,0x74,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x7d,0xa,0x7d,0xa, Step #5: statements {\012 statements {\012 assignment {\012 rvalue {\012 binop {\012 op: LE\012 left {\012 cons {\012 int_lit: 9\012 }\012 }\012 right {\012 }\012 }\012 }\012 }\012 }\012}\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-6b2951afb2192c6802cb32f428b982db9c73c1be Step #5: Base64: c3RhdGVtZW50cyB7CiAgc3RhdGVtZW50cyB7CiAgICBhc3NpZ25tZW50IHsKICAgICAgcnZhbHVlIHsKICAgICAgICBiaW5vcCB7CiAgICAgICAgICBvcDogTEUKICAgICAgICAgIGxlZnQgewogICAgICAgICAgICBjb25zIHsKICAgICAgICAgICAgICBpbnRfbGl0OiA5CiAgICAgICAgICAgIH0KICAgICAgICAgIH0KICAgICAgICAgIHJpZ2h0IHsKICAgICAgICAgIH0KICAgICAgICB9CiAgICAgIH0KICAgIH0KICB9Cn0K Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5044 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4281837037 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558f25b05810, 0x558f25cef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558f25cef020,0x558f27b870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b2951afb2192c6802cb32f428b982db9c73c1be' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6391 processed earlier; will process 4638 files now Step #5: ==181660== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558f1c5fa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558f22c5f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558f22c425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558f22c424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f1c600d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f1c561b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f1c55c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f1c5f2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f1f5c1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f1f5c1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f1f5c1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f1f5c1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f1f5c1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f1f5c1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f1f5c1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f1f5c1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f1f5c1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f1f5c1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558f21856f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f1e583b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f1e58ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f1e33ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f1e33ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f1e33b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f1e33a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f1e33a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f1e33a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558f22c44abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558f22c4d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558f22c35699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558f22c60112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fefa772f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f1c55ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x41,0x0,0x0,0x0,0xa,0x43,0x68,0x61,0x72,0x74,0x2e,0x79,0x61,0x6d,0x6c,0x43,0x63,0x68,0x2f,0x41,0xd,0xd,0x20,0x4c,0xd8,0xb8,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x61,0x6c,0x75,0x30,0x65,0x73,0x4c,0xef,0xbb,0xbf,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4e,0x4c,0x21,0x4c,0x4c,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x70,0x4c,0x60,0x60,0xe2,0x84,0xaa,0x60,0x60,0x60,0x60,0x60,0x4c,0xd8,0xb8,0x4c,0x4c,0x4c,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x70,0x4c,0x60,0x60,0xe2,0x84,0xaa,0x60,0x60,0x60,0x60,0x60,0x4c,0xd8,0xb8,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x28,0x61,0x6c,0x75,0x65,0x73,0x4c,0xef,0xbb,0xbf,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x21,0x4c,0x4c,0x70,0x70,0x70,0x70,0x70,0x70,0x70,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x4c,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x70,0x20,0x70,0x4c,0x60,0x60,0xe2,0x80,0xaa,0x60,0x60,0x30,0x30,0x30,0x30,0x30,0x21,0x2d,0x2d,0x32,0x7e,0x3a,0xa,0x20,0x34,0x3a,0x42,0x3a,0x3a,0x3a,0x3a,0xa,0x20,0x3a,0x3a,0xa,0x32,0x20,0x31,0x31,0x31,0x31,0x31,0x36,0x39,0x39,0x33,0x34,0x34,0x36,0x33,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x6,0x38,0x2d,0x2d,0x2d,0x63, Step #5: A\000\000\000\012Chart.yamlCch/A\015\015 L\330\270LLLLLLLLalu0esL\357\273\277LLLLLLLLLLLNL!LLpppppppLLLLLLLL pL``\342\204\252`````L\330\270LLL pL``\342\204\252`````L\330\270LLLLLLLL(aluesL\357\273\277LLLLLLLLLLLL!LLpppppppLLLLLLLL p pL``\342\200\252``00000!--2~:\012 4:B::::\012 ::\0122 1111169934463----\000\000\0068---c Step #5: artifact_prefix='./'; Test unit written to ./oom-f91f76dd6a960a0da9f7919d003f8bed5f024ad8 Step #5: Base64: QQAAAApDaGFydC55YW1sQ2NoL0ENDSBM2LhMTExMTExMTGFsdTBlc0zvu79MTExMTExMTExMTE5MIUxMcHBwcHBwcExMTExMTExMICAgICAgIHBMYGDihKpgYGBgYEzYuExMTCAgICAgICBwTGBg4oSqYGBgYGBM2LhMTExMTExMTChhbHVlc0zvu79MTExMTExMTExMTEwhTExwcHBwcHBwTExMTExMTEwgICAgICAgcCBwTGBg4oCqYGAwMDAwMCEtLTJ+OgogNDpCOjo6OgogOjoKMiAxMTExMTY5OTM0NDYzLS0tLQAABjgtLS1j Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5045 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4282482487 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55842520f810, 0x5584253f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5584253f9020,0x5584272910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f91f76dd6a960a0da9f7919d003f8bed5f024ad8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6392 processed earlier; will process 4637 files now Step #5: ==181696== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55841bd049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558422369898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55842234c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55842234c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55841bd0ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55841bc6bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55841bc66355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55841bcfcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55841eccbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55841eccbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55841eccbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55841eccbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55841eccbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55841eccbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55841eccbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55841eccbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55841eccbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55841eccbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558420f60f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55841dc8db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55841dc98be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55841da44c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55841da44c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55841da45738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55841da44874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55841da44874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55841da44874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55842234eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558422357928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55842233f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55842236a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb591583082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55841bc64b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2d,0x74,0x2e,0x65,0x78,0x69,0x73,0x74,0x73,0x5f,0x31,0x38,0x34,0x34,0x36,0x37,0x2f,0x2d,0x2e,0x2f,0x2f,0x1d,0x9,0xa,0xa,0x2f,0x2d,0x2d,0x2f,0x2d,0xd,0xc,0x9,0x9,0xa,0x2e,0x2f,0x2f,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2e,0x2f,0x2f,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0x2d,0x9,0xc,0xd,0x9,0x2d,0xd,0xc,0x9,0x2d,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0x9,0x2d,0xd,0xc,0xd,0xc,0x9,0x2d,0x4e,0x0,0x0,0x0,0xd,0x3a,0x74,0x72,0x2f,0x2d,0x9,0x54,0x0,0x1f,0x2d,0x2d,0x2d,0x5b,0xa,0x2f,0x2d,0x2e,0x2f,0x2f,0x2d,0x9,0x1,0xa,0x1f,0x2d,0x2d,0x2f,0x2d,0x2d,0x9,0x9, Step #5: -t.exists_184467/-.//\035\011\012\012/--/-\015\014\011\011\012.//-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011\014\011-\015\014\011-\015\014\011-\015-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011.//-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011-\015\014\011--\015\014\011-\015\014\011--\011\014\015\011-\015\014\011--\015\014\011-\015\014\011-\015\014\015\014\011-N\000\000\000\015:tr/-\011T\000\037---[\012/-.//-\011\001\012\037--/--\011\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-54cc9571ab7715023c8f7083989df856268ebf21 Step #5: Base64: LXQuZXhpc3RzXzE4NDQ2Ny8tLi8vHQkKCi8tLS8tDQwJCQouLy8tDQwJLQ0MCS0NDAktDQwJLQ0MCS0NDAkMCS0NDAktDQwJLQ0tDQwJLQ0MCS0NDAktDQwJLQ0MCS4vLy0NDAktDQwJLQ0MCS0NDAktDQwJLQ0MCS0NDAktDQwJLQ0MCS0NDAktDQwJLQ0MCS0NDAktDQwJLQ0MCS0NDAktDQwJLQ0MCS0tDQwJLQ0MCS0tCQwNCS0NDAktLQ0MCS0NDAktDQwNDAktTgAAAA06dHIvLQlUAB8tLS1bCi8tLi8vLQkBCh8tLS8tLQkJ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5046 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4283037240 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c7dcd7810, 0x561c7dec101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c7dec1020,0x561c7fd590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/54cc9571ab7715023c8f7083989df856268ebf21' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6393 processed earlier; will process 4636 files now Step #5: ==181732== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561c747cc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c7ae31898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c7ae145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c7ae144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c747d2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c74733b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c7472e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c747c4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c77793f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c77793f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c77793f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c77793f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c77793f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c77793f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c77793f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c77793f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c77793f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c77793f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c79a28f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c76755b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c76760be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c7650cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c7650cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c7650d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c7650c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c7650c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c7650c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c7ae16abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c7ae1f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c7ae07699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c7ae32112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9609306082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c7472cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x2d,0x3a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x10,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2b,0x4a,0x9,0x29,0x9,0x29,0x9,0x29,0xa,0x5c,0x9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x29,0xa,0xa,0x5c,0x9,0x29,0xa,0xa,0x5c,0x9,0x29,0xa,0xa,0x5c,0x9,0x29,0x0,0x0,0x0,0x0,0xa,0x5c,0x9,0x60,0x40,0x0,0x0,0x0,0x0,0x0,0x60,0x40,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x5b, Step #5: $-:\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\020'\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\020'\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000+J\011)\011)\011)\012\\\011\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000)\012\012\\\011)\012\012\\\011)\012\012\\\011)\000\000\000\000\012\\\011`@\000\000\000\000\000`@\000\000\000\000\000\000$[ Step #5: artifact_prefix='./'; Test unit written to ./oom-55f546c3603c97b92cb98b44ae86f6047b87ef08 Step #5: Base64: JC06AAAAAAAAAAAAAAAAAAAAAAAAAAAQJwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAECcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK0oJKQkpCSkKXAkAAAAAAAAAAAAAAAAAAAAAAAApCgpcCSkKClwJKQoKXAkpAAAAAApcCWBAAAAAAABgQAAAAAAAACRb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5047 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4283568834 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5579aba1a810, 0x5579abc0401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5579abc04020,0x5579ada9c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/55f546c3603c97b92cb98b44ae86f6047b87ef08' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6394 processed earlier; will process 4635 files now Step #5: ==181768== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5579a250f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5579a8b74898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5579a8b575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5579a8b574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5579a2515d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5579a2476b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5579a2471355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5579a2507c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5579a54d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5579a54d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5579a54d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5579a54d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5579a54d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5579a54d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5579a54d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5579a54d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5579a54d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5579a54d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579a776bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5579a4498b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5579a44a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5579a424fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5579a424fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5579a4250738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5579a424f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5579a424f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5579a424f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5579a8b59abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5579a8b62928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5579a8b4a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5579a8b75112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f305459d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5579a246fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x47,0x52,0x4f,0x55,0x50,0x3d,0x22,0x34,0x39,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x30,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0x30,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x30,0xe3,0x80,0x89,0xef,0xbb,0xbe,0x30,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x30,0xe2,0x80,0x89,0xef,0xbb,0xb6,0x39,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x34,0x37,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x30,0xe2,0x89,0x80,0xef,0xbb,0xbe,0x39,0x34,0xe2,0x80,0x89,0xef,0xbb,0xbe,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0x36,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x38,0x39,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x34,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x35,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x34,0xe2,0x80,0xb1,0xef,0xab,0xbe,0x31,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x30,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0x35,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x35,0xe2,0x80,0x8b,0xef,0xbb,0xbe,0x39,0x35,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0x35,0xe2,0x80,0x89,0xef,0xbb,0xbe,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0x35,0xe2,0x80,0x89,0xef,0xbb,0xbe,0xe2,0x82,0x89,0xef,0xbb,0xbe,0x39,0x35,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x35,0xe2,0x80,0x89,0xef,0xbb,0xbe,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x31,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x22,0x2f, Step #5: GROUP=\"49\342\200\211\357\273\2760\342\200\211\357\273\27690\342\200\211\357\273\2760\343\200\211\357\273\2760\342\200\211\357\273\2760\342\200\211\357\273\2669\342\200\211\357\273\27647\342\200\211\357\273\2760\342\211\200\357\273\27694\342\200\211\357\273\276\342\200\211\357\273\27696\342\200\211\357\273\27689\342\200\211\357\273\2764\342\200\211\357\273\2765\342\200\211\357\273\2764\342\200\261\357\253\2761\342\200\211\357\273\2760\342\200\211\357\273\2769\342\200\211\357\273\27695\342\200\211\357\273\2769\342\200\211\357\273\2765\342\200\213\357\273\27695\342\200\211\357\273\27695\342\200\211\357\273\276\342\200\211\357\273\27695\342\200\211\357\273\276\342\202\211\357\273\27695\342\200\211\357\273\2769\342\200\211\357\273\2765\342\200\211\357\273\276\342\200\211\357\273\2761\342\200\211\357\273\276\"/ Step #5: artifact_prefix='./'; Test unit written to ./oom-a07df8e2af88192b15e734309a7ed4b971e016b7 Step #5: Base64: R1JPVVA9IjQ54oCJ77u+MOKAie+7vjkw4oCJ77u+MOOAie+7vjDigInvu74w4oCJ77u2OeKAie+7vjQ34oCJ77u+MOKJgO+7vjk04oCJ77u+4oCJ77u+OTbigInvu744OeKAie+7vjTigInvu7414oCJ77u+NOKAse+rvjHigInvu74w4oCJ77u+OeKAie+7vjk14oCJ77u+OeKAie+7vjXigIvvu745NeKAie+7vjk14oCJ77u+4oCJ77u+OTXigInvu77igonvu745NeKAie+7vjnigInvu7414oCJ77u+4oCJ77u+MeKAie+7viIv Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5048 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4284098233 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562048fdc810, 0x5620491c601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5620491c6020,0x56204b05e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a07df8e2af88192b15e734309a7ed4b971e016b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6395 processed earlier; will process 4634 files now Step #5: ==181804== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56203fad19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562046136898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5620461195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5620461194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56203fad7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56203fa38b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56203fa33355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56203fac9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562042a98f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562042a98f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562042a98f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562042a98f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562042a98f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562042a98f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562042a98f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562042a98f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562042a98f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562042a98f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562044d2df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562041a5ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562041a65be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562041811c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562041811c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562041812738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562041811874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562041811874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562041811874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56204611babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562046124928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56204610c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562046137112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3091253082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56203fa31b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x65,0x3e,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0x62,0x3e,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0x73,0x75,0x62,0x3e,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0x73,0x3e,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0x6c,0x65,0x3e,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0x73,0x3e,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0x73,0x75,0x62,0x3e,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0x73,0x75,0x62,0x3e,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0x73,0x3e,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0x6c,0x65,0x3e,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0x73,0x3e,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0x62,0x3e,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0x3c,0xa,0x3e, Step #5: <e>\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012<b>\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012<sub>\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012<s>\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012<le>\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012<s>\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012<sub>\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012<sub>\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012<s>\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012<le>\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012<s>\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012<b>\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012<\012> Step #5: artifact_prefix='./'; Test unit written to ./oom-a87ded7b196184882bbbe8b992ca34a9657d30d9 Step #5: Base64: PGU+CgoKCgoKCgoKCgoKCgoKCjxiPgoKCgoKCgoKCgoKCgoKCgo8c3ViPgoKCgoKCgoKCgoKCgoKCgo8cz4KCgoKCgoKCgoKCgoKCgoKPGxlPgoKCgoKCgoKCgoKCgoKCgo8cz4KCgoKCgoKCgoKCgoKCgoKPHN1Yj4KCgoKCgoKCgoKCgoKCgoKPHN1Yj4KCgoKCgoKCgoKCgoKCgoKPHM+CgoKCgoKCgoKCgoKCgoKCjxsZT4KCgoKCgoKCgoKCgoKCgoKPHM+CgoKCgoKCgoKCgoKCgoKCjxiPgoKCgoKCgoKCgoKCgoKCgoKPAo+ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5049 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4284615901 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a1e301810, 0x558a1e4eb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a1e4eb020,0x558a203830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a87ded7b196184882bbbe8b992ca34a9657d30d9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6396 processed earlier; will process 4633 files now Step #5: #1 pulse cov: 16615 ft: 16616 exec/s: 0 rss: 207Mb Step #5: ==181840== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558a14df69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a1b45b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a1b43e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a1b43e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a14dfcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a14d5db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a14d58355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a14deec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a17dbdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a17dbdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a17dbdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a17dbdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a17dbdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a17dbdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a17dbdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a17dbdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a17dbdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a17dbdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a1a052f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a16d7fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a16d8abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a16b36c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a16b36c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a16b37738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a16b36874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a16b36874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a16b36874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a1b440abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a1b449928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a1b431699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a1b45c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f104f5cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a14d56b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x60,0x20,0xa,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x20,0x2d,0x60,0x60,0x20,0xa,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x2b,0xa,0x9,0x2b,0xa,0x9,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x3e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x1,0x0,0x73,0x74,0x72,0x65,0x61,0x6d,0x20,0x1,0x0,0x0,0x20,0x60,0x20,0x2d,0x60,0xa,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x20,0x2d,0x60,0x60,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5,0xa,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x20,0x1,0x0,0x20,0x1,0x0,0x0,0x20,0x60,0x20,0xa,0x60,0x2d,0x60,0x60,0x20,0x1,0x73,0x64,0x20,0x20,0x2d,0x60,0x60,0x20,0xa,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x73,0x74,0x72,0x65,0x61,0x6d,0x20,0x1,0x0,0x0,0x20,0x60,0x20,0xa,0x60,0x2d,0x60,0x60,0x20,0x3,0x0,0x0,0x0,0x0,0x0,0x0,0x81,0x0,0x0,0x7e,0x7e,0x7e,0x7e,0x7e,0x0,0x20,0x20,0x2d,0x7e,0x60,0x60,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5,0xa,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x0,0x20,0x0,0x49,0x44,0x33,0x3,0x25,0x20,0x0,0x1,0x0,0x66,0x47,0x45,0x4f,0x42,0x0,0x0,0x0,0x20,0x20,0x20,0x63,0x37,0x2e,0x10,0x0,0x68,0x2e,0x68,0x43,0x2d,0x0,0x14,0x1,0x0,0x0,0x45,0x21, Step #5: \012`-``-`` \001\000\000 ` \012`-`` \001\000\000 -`` \012`-``-``+\012\011+\012\011~~~~~~~~>~~~~~~~\001\000stream \001\000\000 ` -`\012`` \001\000\000 -`` \000\000\000\000\000\000\000\005\012`-`` \001\000\000 \001\000 \001\000\000 ` \012`-`` \001sd -`` \012`-``-``stream \001\000\000 ` \012`-`` \003\000\000\000\000\000\000\201\000\000~~~~~\000 -~`` \000\000\000\000\000\000\000\005\012`-`` \001\000\000 \000 \000ID3\003% \000\001\000fGEOB\000\000\000 c7.\020\000h.hC-\000\024\001\000\000E! Step #5: artifact_prefix='./'; Test unit written to ./oom-7f65fa28cbd7674cfb971e35249195e9b95c1125 Step #5: Base64: CmAtYGAtYGAgAQAAIGAgCmAtYGAgAQAAICAtYGAgCmAtYGAtYGArCgkrCgl+fn5+fn5+fj5+fn5+fn5+AQBzdHJlYW0gAQAAIGAgLWAKYGAgAQAAICAtYGAgAAAAAAAAAAUKYC1gYCABAAAgIAEAIAEAACBgIApgLWBgIAFzZCAgLWBgIApgLWBgLWBgc3RyZWFtIAEAACBgIApgLWBgIAMAAAAAAACBAAB+fn5+fgAgIC1+YGAgAAAAAAAAAAUKYC1gYCABAAAgACAASUQzAyUgAAEAZkdFT0IAAAAgICBjNy4QAGguaEMtABQBAABFIQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5050 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4285371565 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec7201e810, 0x55ec7220801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec72208020,0x55ec740a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f65fa28cbd7674cfb971e35249195e9b95c1125' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6398 processed earlier; will process 4631 files now Step #5: ==181876== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec68b139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec6f178898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec6f15b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec6f15b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec68b19d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec68a7ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec68a75355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec68b0bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec6badaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec6badaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec6badaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec6badaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec6badaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec6badaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec6badaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec6badaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec6badaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec6badaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec6dd6ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec6aa9cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec6aaa7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec6a853c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec6a853c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec6a854738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec6a853874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec6a853874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec6a853874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec6f15dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec6f166928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec6f14e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec6f179112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d21307082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec68a73b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x57,0x73,0x3a,0xdf,0xb4,0x2e,0xe3,0x8c,0x96,0x2e,0x61,0x61,0x61,0x61,0x61,0x63,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x60,0x61,0x61,0x78,0x73,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x78,0x78,0x78,0x78,0x78,0x61,0x61,0x61,0x61,0x61,0x61,0x60,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x69,0x61,0x63,0x61,0x61,0x69,0x61,0x63,0x61,0x61,0x61,0x61,0x61,0x60,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x78,0x78,0x78,0x78,0x78,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x60,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x63,0x61,0x61,0x61,0x69,0x61,0x61,0x61,0x61,0x60,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x60,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x63,0x61,0x61,0x61,0x69,0x61,0x61,0x61,0x61,0x60,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x61,0x60,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x61,0x21,0x61,0x61,0x61,0x61,0x2e, Step #5: Ws:\337\264.\343\214\226.aaaaacaaaaaaaaaaaaaa`aaxsxxxxxxxaaaaaaaaaaaaaxxxxxaaaaaa`aaaaaaaaaaaaaiacaaiacaaaaa`aaaaaaaaaaaaaxxxxxaaaaaaaaaaaaa`aaaaaaaaaaaacaaaiaaaa`aaaaaaaaaaaaaaaaaa`xxxxxxxxxxxaaaaaaaaaaacaaaiaaaa`aaaaaaaaaaaaaaaaaa`xxxxxxxxxxxxxxxxa!aaaa. Step #5: artifact_prefix='./'; Test unit written to ./oom-477c2b5ca0c90852aa17a41d03346cfdbff6709a Step #5: Base64: V3M637Qu44yWLmFhYWFhY2FhYWFhYWFhYWFhYWFhYGFheHN4eHh4eHh4YWFhYWFhYWFhYWFhYXh4eHh4YWFhYWFhYGFhYWFhYWFhYWFhYWFpYWNhYWlhY2FhYWFhYGFhYWFhYWFhYWFhYWF4eHh4eGFhYWFhYWFhYWFhYWFgYWFhYWFhYWFhYWFhY2FhYWlhYWFhYGFhYWFhYWFhYWFhYWFhYWFhYWB4eHh4eHh4eHh4eGFhYWFhYWFhYWFhY2FhYWlhYWFhYGFhYWFhYWFhYWFhYWFhYWFhYWB4eHh4eHh4eHh4eHh4eHh4YSFhYWFhLg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5051 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4286025725 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a62d15810, 0x555a62eff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a62eff020,0x555a64d970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/477c2b5ca0c90852aa17a41d03346cfdbff6709a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6399 processed earlier; will process 4630 files now Step #5: ==181912== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555a5980a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a5fe6f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a5fe525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a5fe524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a59810d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a59771b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a5976c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a59802c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a5c7d1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a5c7d1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a5c7d1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a5c7d1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a5c7d1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a5c7d1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a5c7d1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a5c7d1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a5c7d1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a5c7d1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a5ea66f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a5b793b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a5b79ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a5b54ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a5b54ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a5b54b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a5b54a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a5b54a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a5b54a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a5fe54abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a5fe5d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a5fe45699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a5fe70112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4cd2e2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a5976ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x60,0x20,0xa,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x20,0x2d,0x60,0x60,0x20,0xa,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x2b,0xa,0x9,0x2b,0xa,0x9,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x3e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x7e,0x1,0x0,0x73,0x74,0x72,0x65,0x61,0x6d,0x20,0x1,0x0,0x0,0x20,0x60,0x20,0x2d,0x60,0xa,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x20,0x2d,0x60,0x60,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5,0xa,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x20,0x1,0x0,0x20,0x1,0x0,0x0,0x20,0x60,0x20,0xa,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x20,0x2d,0x60,0x60,0x20,0xa,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x73,0x74,0x72,0x65,0x61,0x6d,0x20,0x1,0x0,0x0,0x20,0x60,0x20,0xa,0x60,0x2d,0x60,0x60,0x20,0x3,0x0,0x0,0x0,0x0,0x0,0x0,0x81,0x0,0x0,0x7e,0x7e,0x7e,0x7e,0x7e,0x0,0x20,0x20,0x2d,0x7e,0x60,0x60,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5,0xa,0x60,0x2d,0x60,0x60,0x20,0x1,0x0,0x0,0x20,0x0,0x20,0x0,0x49,0x44,0x33,0x3,0x25,0x20,0x0,0x1,0x0,0x66,0x47,0x45,0x4f,0x42,0x0,0x0,0x0,0x20,0x20,0x20,0x63,0x37,0x2e,0x10,0x0,0x68,0x2e,0x68,0x43,0x2d,0x0,0x14,0x1,0x0,0x0,0x45,0x21, Step #5: \012`-``-`` \001\000\000 ` \012`-`` \001\000\000 -`` \012`-``-``+\012\011+\012\011~~~~~~~~>~~~~~~~\001\000stream \001\000\000 ` -`\012`` \001\000\000 -`` \000\000\000\000\000\000\000\005\012`-`` \001\000\000 \001\000 \001\000\000 ` \012`-`` \001\000\000 -`` \012`-``-``stream \001\000\000 ` \012`-`` \003\000\000\000\000\000\000\201\000\000~~~~~\000 -~`` \000\000\000\000\000\000\000\005\012`-`` \001\000\000 \000 \000ID3\003% \000\001\000fGEOB\000\000\000 c7.\020\000h.hC-\000\024\001\000\000E! Step #5: artifact_prefix='./'; Test unit written to ./oom-f95f04547a8bd7257c040fbbfab4afe27444c2e5 Step #5: Base64: CmAtYGAtYGAgAQAAIGAgCmAtYGAgAQAAICAtYGAgCmAtYGAtYGArCgkrCgl+fn5+fn5+fj5+fn5+fn5+AQBzdHJlYW0gAQAAIGAgLWAKYGAgAQAAICAtYGAgAAAAAAAAAAUKYC1gYCABAAAgIAEAIAEAACBgIApgLWBgIAEAACAgLWBgIApgLWBgLWBgc3RyZWFtIAEAACBgIApgLWBgIAMAAAAAAACBAAB+fn5+fgAgIC1+YGAgAAAAAAAAAAUKYC1gYCABAAAgACAASUQzAyUgAAEAZkdFT0IAAAAgICBjNy4QAGguaEMtABQBAABFIQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5052 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4286677579 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562a1b455810, 0x562a1b63f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562a1b63f020,0x562a1d4d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f95f04547a8bd7257c040fbbfab4afe27444c2e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6400 processed earlier; will process 4629 files now Step #5: ==181948== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562a11f4a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562a185af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562a185925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562a185924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562a11f50d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562a11eb1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562a11eac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562a11f42c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562a14f11f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562a14f11f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562a14f11f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562a14f11f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562a14f11f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562a14f11f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562a14f11f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562a14f11f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562a14f11f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562a14f11f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562a171a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562a13ed3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562a13edebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562a13c8ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562a13c8ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562a13c8b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562a13c8a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562a13c8a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562a13c8a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562a18594abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562a1859d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562a18585699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562a185b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7586e30082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562a11eaab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0x30,0xa,0x3d,0xcc,0xbb,0x2b,0x41,0x2d,0x2d,0x2d,0x41,0x73,0x63,0x65,0xa,0x2d,0x3f,0x41,0x73,0x63,0x65,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x2d,0x2d,0x2f,0x2d,0x6d,0x2d,0x42,0x45,0x1,0x0,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x2d,0x2d,0x2f,0x2d,0x6d,0x2d,0x42,0x45,0x1,0x0,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xe,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x49,0x44,0x34,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x2d,0x2d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x2d,0xbb,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N0\012=\314\273+A---Asce\012-?Asce\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000--/-m-BE\001\000\000=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000--/-m-BE\001\000\000=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\016=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000ID4\012=\012=\012=\012=\012--=\012=\012=\012=\012-\273\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-6372d77e6178ad6c3ff0c257bf4c4a28b0990e7b Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTjAKPcy7K0EtLS1Bc2NlCi0/QXNjZQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9CgAtLS8tbS1CRQEAAD0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KAC0tLy1tLUJFAQAAPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQ49Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KAElENAo9Cj0KPQo9Ci0tPQo9Cj0KPQotuwo9ChA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5053 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4287237779 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5563d2ec8810, 0x5563d30b201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5563d30b2020,0x5563d4f4a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6372d77e6178ad6c3ff0c257bf4c4a28b0990e7b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6401 processed earlier; will process 4628 files now Step #5: #1 pulse cov: 4232 ft: 4233 exec/s: 0 rss: 179Mb Step #5: ==181984== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5563c99bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5563d0022898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5563d00055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5563d00054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5563c99c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5563c9924b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5563c991f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5563c99b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5563cc984f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5563cc984f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5563cc984f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5563cc984f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5563cc984f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5563cc984f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5563cc984f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5563cc984f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5563cc984f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5563cc984f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5563cec19f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5563cb946b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5563cb951be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5563cb6fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5563cb6fdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5563cb6fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5563cb6fd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5563cb6fd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5563cb6fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5563d0007abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5563d0010928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5563cfff8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5563d0023112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f41d2a0e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5563c991db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x74,0x75,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x55,0x74,0x74,0x55,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7d,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x2a,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x28,0x3f,0x3a,0x24,0x7c,0x24,0x7c,0x24,0x21,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x24,0x7c,0x29,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x29,0x7c,0x29,0x29,0x24,0x7c,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x7c,0x24,0x27,0xe,0x70,0x29,0x65,0x2a,0x7c,0x29,0x2f,0x29,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x29,0x7c,0x7c,0x7f, Step #5: ttu(?:(?:?:(?:$|$|(?:(?:(?:$|$|$|$|$|$UttU|$|$|$|$|$|$|$)|$}(?:$|$|(?:(?:*?:$|$|$|$|$|$|$|$|$|$|$|$|$(?:(?:?:(?:$|$|(?:(?:(?:$|$|$|$|$|$|$|$|$|$|$|$|$)|$|(?:$|$|(?:(?:(?:$|$|$!$|$|$|$|$|$|$|$|$|$)|$|)|$|$|$|$)|))$||$|$|$|$'\016p)e*|)/))|)|)|)||\177 Step #5: artifact_prefix='./'; Test unit written to ./oom-90528e9b8559b0896e410f8e3e1ffa87981283ed Step #5: Base64: dHR1KD86KD86PzooPzokfCR8KD86KD86KD86JHwkfCR8JHwkfCRVdHRVfCR8JHwkfCR8JHwkfCQpfCR9KD86JHwkfCg/Oig/Oio/OiR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkfCQoPzooPzo/Oig/OiR8JHwoPzooPzooPzokfCR8JHwkfCR8JHwkfCR8JHwkfCR8JHwkKXwkfCg/OiR8JHwoPzooPzooPzokfCR8JCEkfCR8JHwkfCR8JHwkfCR8JHwkKXwkfCl8JHwkfCR8JCl8KSkkfHwkfCR8JHwkJw5wKWUqfCkvKSl8KXwpfCl8fH8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5054 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4287833485 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb3a709810, 0x55cb3a8f301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb3a8f3020,0x55cb3c78b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/90528e9b8559b0896e410f8e3e1ffa87981283ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6403 processed earlier; will process 4626 files now Step #5: ==182020== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cb311fe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb37863898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb378465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb378464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb31204d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb31165b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb31160355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb311f6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb341c5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb341c5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb341c5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb341c5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb341c5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb341c5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb341c5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb341c5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb341c5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb341c5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb3645af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb33187b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb33192be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb32f3ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb32f3ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb32f3f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb32f3e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb32f3e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb32f3e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb37848abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb37851928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb37839699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb37864112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb8e0b34082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb3115eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x60,0x23,0x60,0x60,0x60,0x60,0x60,0x60,0x67,0x6c,0x79,0x66,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x73,0x63,0x65,0x6e,0x74,0x20,0x7a,0x31,0x0,0x20,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0xa0,0x9f,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x66,0x60,0x60,0x60,0x60,0x60,0x37,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x60,0x60,0x58,0x0,0x0,0x0,0x0,0x2a,0x2c,0x0,0x68,0x60,0x60,0x60,0x2a,0x27,0x2a,0x68,0x74,0x68,0x5b,0x78,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x19,0x6c,0x6f,0x72,0x65,0x6d,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x6d,0x60,0x60,0x60,0x60,0x60,0x27, Step #5: B`#``````glyf``````````````````````````scent z1\000 `````````````````````\240\237````````````````````````````f`````7\000\000\000\000\000\000\000``X\000\000\000\000*,\000h```*'*hth[x``````````````\001\000\000\000\000\000\000\000\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031\031lorem```````````````````````````````````````````````m`````' Step #5: artifact_prefix='./'; Test unit written to ./oom-c47654fd8d46cc932f521697a06ed91b450cb109 Step #5: Base64: QmAjYGBgYGBgZ2x5ZmBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgc2NlbnQgejEAIGBgYGBgYGBgYGBgYGBgYGBgYGBgYKCfYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGZgYGBgYDcAAAAAAAAAYGBYAAAAACosAGhgYGAqJypodGhbeGBgYGBgYGBgYGBgYGBgAQAAAAAAAAAZGRkZGRkZGRkZGRkZGRkZGRkZGRkZGRkZbG9yZW1gYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYGBgYG1gYGBgYCc= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5055 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4288481722 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559fb3a58810, 0x559fb3c4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559fb3c42020,0x559fb5ada0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c47654fd8d46cc932f521697a06ed91b450cb109' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6404 processed earlier; will process 4625 files now Step #5: #1 pulse cov: 4001 ft: 4002 exec/s: 0 rss: 176Mb Step #5: ==182056== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559faa54d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559fb0bb2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559fb0b955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559fb0b954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559faa553d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559faa4b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559faa4af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559faa545c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559fad514f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559fad514f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559fad514f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559fad514f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559fad514f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559fad514f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559fad514f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559fad514f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559fad514f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559fad514f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559faf7a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559fac4d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559fac4e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559fac28dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559fac28dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559fac28e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559fac28d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559fac28d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559fac28d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559fb0b97abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559fb0ba0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559fb0b88699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559fb0bb3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f77aa9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559faa4adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3e,0x60,0x60,0x3b,0x27,0x2f,0x27,0x3e,0x60,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3c,0x60,0x2d,0x60,0x3b,0x3b,0x27,0x2f,0x27,0x3c,0x27,0x2f,0x27,0x3c,0x60,0x24,0x60,0x3b,0x3b,0x27,0x2f,0x27,0x3c,0x60,0xef,0xac,0xac,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3c,0x60,0x24,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3c,0x60,0x2f,0x2d,0x27,0x3b,0x27,0x72,0x60,0x60,0x77,0x3e,0x69,0x74,0x65,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x33,0x39,0x31,0x35,0x36,0x39,0x35,0x31,0x30,0x34,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3c,0x60,0x2d,0x60,0x3b,0x3b,0x27,0x2f,0x27,0x3c,0x27,0x2f,0x27,0x3c,0x60,0x24,0x60,0x3b,0x3b,0x27,0x2f,0x27,0x3c,0x60,0xef,0xac,0xac,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3c,0x60,0x24,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3c,0x60,0x65,0x60,0x3b,0x27,0x2f,0x27,0x3e,0x60,0x77,0x72,0x69,0x74,0x65,0x5f,0x75,0x74,0x66,0x31,0x24,0x60,0x3b,0x27,0x2f,0x27,0x3c,0x60,0x2d,0x60,0x3b,0x3b,0x27,0x2f,0x27,0x3c,0x27,0x2f,0x27,0x3c,0x60,0x63,0x24,0x61,0x6c,0x6c,0x60,0x3b,0x3b,0x3b,0x27,0x2f,0x27,0x60,0xef,0xac,0xac,0x27,0x72,0x60,0x3b,0x27,0x2f,0x27,0x3e,0x60,0x24,0x60,0xc5,0xd8,0xc3,0xd0,0xd8,0x9f,0xd2,0x9e,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x27,0x2f,0x27,0x3c,0x60,0x24,0x60,0x3b,0x3b,0x27,0x2f,0x27,0x3c,0x60,0xef, Step #5: `$`;'/'>``;'/'>`$`;'/'<`-`;;'/'<'/'<`$`;;'/'<`\357\254\254$`;'/'<`$$`;'/'<`/-';'r``w>ite74607433915695104$`;'/'<`-`;;'/'<'/'<`$`;;'/'<`\357\254\254$`;'/'<`$$`;'/'<`e`;'/'>`write_utf1$`;'/'<`-`;;'/'<'/'<`c$all`;;;'/'`\357\254\254'r`;'/'>`$`\305\330\303\320\330\237\322\236\000\000\000\000\000\000$'/'<`$`;;'/'<`\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-afb7156da6f69c4eaaea4d2ae7c7b1a95c280dd2 Step #5: Base64: YCRgOycvJz5gYDsnLyc+YCRgOycvJzxgLWA7OycvJzwnLyc8YCRgOzsnLyc8YO+srCRgOycvJzxgJCRgOycvJzxgLy0nOydyYGB3Pml0ZTc0NjA3NDMzOTE1Njk1MTA0JGA7Jy8nPGAtYDs7Jy8nPCcvJzxgJGA7OycvJzxg76ysJGA7Jy8nPGAkJGA7Jy8nPGBlYDsnLyc+YHdyaXRlX3V0ZjEkYDsnLyc8YC1gOzsnLyc8Jy8nPGBjJGFsbGA7OzsnLydg76ysJ3JgOycvJz5gJGDF2MPQ2J/SngAAAAAAACQnLyc8YCRgOzsnLyc8YO8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5056 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4289185369 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56162c731810, 0x56162c91b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56162c91b020,0x56162e7b30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/afb7156da6f69c4eaaea4d2ae7c7b1a95c280dd2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6406 processed earlier; will process 4623 files now Step #5: #1 pulse cov: 3743 ft: 3744 exec/s: 0 rss: 178Mb Step #5: ==182092== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5616232269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56162988b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56162986e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56162986e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56162322cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56162318db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561623188355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56162321ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5616261edf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5616261edf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5616261edf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5616261edf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5616261edf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5616261edf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5616261edf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5616261edf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5616261edf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5616261edf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561628482f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5616251afb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5616251babe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561624f66c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561624f66c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561624f67738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561624f66874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561624f66874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561624f66874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561629870abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561629879928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561629861699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56162988c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcd72993082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561623186b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0x6e,0x63,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x6e,0xe5,0x8f,0xb8,0x2e,0x2e,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xf0,0x91,0x96,0xb9,0x73,0x74,0x72,0x65,0x61,0x6d,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x6e,0xe5,0x8f,0xb8,0x2e,0x2e,0x2e,0x78,0x6e,0x63,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xa,0x2e,0x78,0x6e,0x63,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x92,0xbd,0xa,0xa, Step #5: \360\221\226\271\360\221\222\275.x\360\221\226\271\360\221\222\275\012\360\221\226\271\360\221\222\275.xncx\360\221\226\271\360\221\222\275\360\221\226\271\360\221\222\275.x\360\221\226\271\360\221\222\275\012\360\221\226\271\360\221\222\275n\345\217\270..\360\221\226\271\360\221\222\275.x\360\221\226\271\360\221\222\275\012\360\221\226\271stream\221\226\271\360\221\222\275\360\221\226\271\360\221\222\275.x\360\221\226\271\360\221\222\275\012\360\221\226\271\360\221\222\275n\345\217\270...xncx\360\221\226\271\360\221\222\275\012\012.xncx\360\221\226\271\360\221\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\222\275\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-9eaced1bccf3d182a0ca4d142bce93d049db1fd3 Step #5: Base64: 8JGWufCRkr0uePCRlrnwkZK9CvCRlrnwkZK9LnhuY3jwkZa58JGSvfCRlrnwkZK9LnjwkZa58JGSvQrwkZa58JGSvW7lj7guLvCRlrnwkZK9LnjwkZa58JGSvQrwkZa5c3RyZWFtkZa58JGSvfCRlrnwkZK9LnjwkZa58JGSvQrwkZa58JGSvW7lj7guLi54bmN48JGWufCRkr0KCi54bmN48JGWufCR//////////////////////////////////////////////////////////////////////////////////////////////+SvQoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5057 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4289753084 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55567bf25810, 0x55567c10f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55567c10f020,0x55567dfa70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9eaced1bccf3d182a0ca4d142bce93d049db1fd3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6408 processed earlier; will process 4621 files now Step #5: #1 pulse cov: 4134 ft: 4135 exec/s: 0 rss: 176Mb Step #5: ==182128== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555672a1a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55567907f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556790625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556790624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555672a20d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555672981b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55567297c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555672a12c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5556759e1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5556759e1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5556759e1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5556759e1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5556759e1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5556759e1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5556759e1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5556759e1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5556759e1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5556759e1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555677c76f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5556749a3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5556749aebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55567475ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55567475ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55567475b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55567475a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55567475a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55567475a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555679064abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55567906d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555679055699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555679080112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c6d8fe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55567297ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x5d,0x5d,0x30,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x5d,0x0,0x0,0x2f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2f,0x0,0xf,0x31,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x0,0x11,0xf,0x31,0x11,0x2d,0x0,0x0,0x0,0x2f,0x0,0xf,0x31,0x11,0xf,0x31,0x11,0x2d,0x3a,0x2d,0x3a,0x24,0x5a, Step #5: $]]0]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]\000\000/\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000/\000\0171\0171\021\0171\021-\000\021\0171\021-\000\000\000/\000\0171\021\0171\021-:-:$Z Step #5: artifact_prefix='./'; Test unit written to ./oom-92c2dc1198c78d35cd13506ebf95921656dad0d7 Step #5: Base64: JF1dMF1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXRQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFF1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dXV1dAAAvAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAvAA8xDzERDzERLQARDzERLQAAAC8ADzERDzERLTotOiRa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5058 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4290331971 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fa654f7810, 0x55fa656e101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fa656e1020,0x55fa675790e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92c2dc1198c78d35cd13506ebf95921656dad0d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6410 processed earlier; will process 4619 files now Step #5: ==182164== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fa5bfec9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fa62651898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fa626345dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fa626344fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fa5bff2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fa5bf53b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fa5bf4e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fa5bfe4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fa5efb3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fa5efb3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fa5efb3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fa5efb3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fa5efb3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fa5efb3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fa5efb3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fa5efb3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fa5efb3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fa5efb3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fa61248f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fa5df75b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fa5df80be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fa5dd2cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fa5dd2cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fa5dd2d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fa5dd2c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fa5dd2c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fa5dd2c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fa62636abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fa6263f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fa62627699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fa62652112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f607639d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fa5bf4cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x63,0x0,0x50,0x50,0x71,0x54,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x47,0x0,0x50,0x7,0x4e,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x0,0x50,0x4e,0x47,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x0,0x50,0x4e,0x47,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x0,0x50,0x4e,0x47,0x54,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x0,0x50,0x4e,0x47,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x0,0x50,0x4e,0x47,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x0,0x50,0x4e,0x47,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x0,0x50,0x4e,0x71,0x54,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x0,0x50,0x4e,0x47,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x0,0x50,0x4e,0x47,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x0,0x50,0x4e,0x47,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x2,0x50,0x4e,0x47,0x54,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x0,0x50,0x4e,0x47,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x0,0x50,0x4e,0x47,0x0,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5,0x27,0x0,0x0,0x50,0x4e,0x47,0x54,0x41,0x50,0x49,0x43,0x0,0x0,0x0,0x5, Step #5: ID3\004c\000PPqTAPIC\000\000\000\005'\000G\000P\007NAPIC\000\000\000\005'\000\000PNG\000APIC\000\000\000\005'\000\000PNG\000APIC\000\000\000\005'\000\000PNGTAPIC\000\000\000\005'\000\000PNG\000APIC\000\000\000\005'\000\000PNG\000APIC\000\000\000\005'\000\000PNG\000APIC\000\000\000\005'\000\000PNqTAPIC\000\000\000\005'\000\000PNG\000APIC\000\000\000\005'\000\000PNG\000APIC\000\000\000\005'\000\000PNG\000APIC\000\000\000\005'\000\002PNGTAPIC\000\000\000\005'\000\000PNG\000APIC\000\000\000\005'\000\000PNG\000APIC\000\000\000\005'\000\000PNGTAPIC\000\000\000\005 Step #5: artifact_prefix='./'; Test unit written to ./oom-9e9c8e910b33020a4ccceca0fa9824f82f6112d4 Step #5: Base64: SUQzBGMAUFBxVEFQSUMAAAAFJwBHAFAHTkFQSUMAAAAFJwAAUE5HAEFQSUMAAAAFJwAAUE5HAEFQSUMAAAAFJwAAUE5HVEFQSUMAAAAFJwAAUE5HAEFQSUMAAAAFJwAAUE5HAEFQSUMAAAAFJwAAUE5HAEFQSUMAAAAFJwAAUE5xVEFQSUMAAAAFJwAAUE5HAEFQSUMAAAAFJwAAUE5HAEFQSUMAAAAFJwAAUE5HAEFQSUMAAAAFJwACUE5HVEFQSUMAAAAFJwAAUE5HAEFQSUMAAAAFJwAAUE5HAEFQSUMAAAAFJwAAUE5HVEFQSUMAAAAF Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5059 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4290861582 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c87c765810, 0x55c87c94f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c87c94f020,0x55c87e7e70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9e9c8e910b33020a4ccceca0fa9824f82f6112d4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6411 processed earlier; will process 4618 files now Step #5: ==182200== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c87325a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8798bf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8798a25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8798a24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c873260d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c8731c1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c8731bc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c873252c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c876221f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c876221f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c876221f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c876221f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c876221f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c876221f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c876221f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c876221f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c876221f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c876221f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c8784b6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c8751e3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c8751eebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c874f9ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c874f9ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c874f9b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c874f9a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c874f9a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c874f9a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8798a4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8798ad928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c879895699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8798c0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe74112d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c8731bab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x1a,0x45,0xdf,0xa3,0x8,0x0,0x0,0x0,0x0,0x56,0xea,0xa3,0xae,0x6b,0x16,0x1,0xae,0xab,0x83,0x81,0x2e,0x2d,0xe3,0x83,0x81,0x1,0x86,0x8f,0x60,0x16,0x54,0xae,0x6b,0x1,0x5e,0x16,0x54,0xae,0x6b,0x7e,0x76,0xae,0xab,0x2e,0xe3,0x2d,0x81,0x83,0x83,0x81,0x1,0x86,0x8f,0x60,0x16,0x54,0xae,0x6b,0x1,0x0,0x16,0xb2,0x51,0x6b,0x7e,0xce,0x2d,0xfb,0x83,0x81,0x21,0x86,0x8d,0x53,0x16,0x54,0xae,0x6b,0x1,0x5e,0x16,0x54,0xae,0x6b,0x7e,0x76,0xae,0xab,0x2e,0xe3,0x2d,0x81,0x83,0x83,0x81,0x1,0x86,0x8f,0x60,0x16,0x54,0xae,0x6b,0x1,0x0,0x16,0xa2,0x51,0x6b,0x7e,0xce,0x2d,0xfb,0x83,0x81,0x21,0x86,0x8d,0x53,0x16,0x54,0xae,0x6b,0x1,0x5e,0x16,0x54,0xae,0x6b,0x7e,0x76,0xae,0xab,0x2e,0xe3,0x2d,0x81,0x83,0x83,0x81,0x1,0x86,0x8f,0x60,0x16,0x54,0xae,0x6b,0x1,0x0,0x16,0xa2,0x51,0x6b,0x7e,0xce,0x2d,0xfb,0x83,0x81,0x21,0x86,0x8d,0x53,0x16,0x54,0xae,0x6b,0x1,0x5e,0x16,0x54,0xae,0x6b,0x7e,0x76,0xae,0xab,0x2e,0xe3,0x2d,0x81,0x5e,0x16,0x5c,0xae,0x6b,0x7e,0x76,0xae,0xab,0x2d,0x81,0x83,0x83,0x81,0x21,0x86,0x8d,0x53,0x16,0x54,0xae,0x6b,0x1,0x6b,0xae,0x5e,0x16,0x7e,0x54,0x76,0xae,0xab,0x2e,0x16,0x54,0xae,0x6b,0x76,0x76,0xae,0xfa,0x83,0x81,0x1,0x86,0x8f,0x56,0x5f,0x4d,0x49,0xad,0x46,0xb8,0xc9,0x0,0xc0,0x1f,0x43,0xb6,0x75,0x2, Step #5: \032E\337\243\010\000\000\000\000V\352\243\256k\026\001\256\253\203\201.-\343\203\201\001\206\217`\026T\256k\001^\026T\256k~v\256\253.\343-\201\203\203\201\001\206\217`\026T\256k\001\000\026\262Qk~\316-\373\203\201!\206\215S\026T\256k\001^\026T\256k~v\256\253.\343-\201\203\203\201\001\206\217`\026T\256k\001\000\026\242Qk~\316-\373\203\201!\206\215S\026T\256k\001^\026T\256k~v\256\253.\343-\201\203\203\201\001\206\217`\026T\256k\001\000\026\242Qk~\316-\373\203\201!\206\215S\026T\256k\001^\026T\256k~v\256\253.\343-\201^\026\\\256k~v\256\253-\201\203\203\201!\206\215S\026T\256k\001k\256^\026~Tv\256\253.\026T\256kvv\256\372\203\201\001\206\217V_MI\255F\270\311\000\300\037C\266u\002 Step #5: artifact_prefix='./'; Test unit written to ./oom-d8081e4e882888b2f9c85e6c66584af1a344e9c6 Step #5: Base64: GkXfowgAAAAAVuqjrmsWAa6rg4EuLeODgQGGj2AWVK5rAV4WVK5rfnauqy7jLYGDg4EBho9gFlSuawEAFrJRa37OLfuDgSGGjVMWVK5rAV4WVK5rfnauqy7jLYGDg4EBho9gFlSuawEAFqJRa37OLfuDgSGGjVMWVK5rAV4WVK5rfnauqy7jLYGDg4EBho9gFlSuawEAFqJRa37OLfuDgSGGjVMWVK5rAV4WVK5rfnauqy7jLYFeFlyua352rqstgYODgSGGjVMWVK5rAWuuXhZ+VHauqy4WVK5rdnau+oOBAYaPVl9NSa1GuMkAwB9DtnUC Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5060 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4291374602 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c5a8bc9810, 0x55c5a8db301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c5a8db3020,0x55c5aac4b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d8081e4e882888b2f9c85e6c66584af1a344e9c6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6412 processed earlier; will process 4617 files now Step #5: ==182236== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c59f6be9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c5a5d23898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c5a5d065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c5a5d064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c59f6c4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c59f625b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c59f620355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c59f6b6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c5a2685f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c5a2685f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c5a2685f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c5a2685f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c5a2685f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c5a2685f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c5a2685f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c5a2685f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c5a2685f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c5a2685f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c5a491af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c5a1647b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c5a1652be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c5a13fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c5a13fec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c5a13ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c5a13fe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c5a13fe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c5a13fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c5a5d08abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c5a5d11928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c5a5cf9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c5a5d24112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ac9b47082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c59f61eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0x6e,0x63,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xf0,0x91,0x96,0xb9,0x92,0xf0,0x91,0xbd,0x2e,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x6e,0xe5,0x8f,0xb8,0x2e,0x2e,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x2e,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0x6e,0xe5,0x8f,0xb8,0x2e,0x2e,0x2e,0x78,0x6e,0x63,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0x92,0xbd,0xa,0xa,0x2e,0x78,0x6e,0x63,0x78,0xf0,0x91,0x96,0xb9,0xf0,0x91,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x92,0xbd,0xa,0xa, Step #5: \360\221\226\271\360\221\222\275.x\360\221\226\271\360\221\222\275\012\360\221\226\271\360\221\222\275.xncx\360\221\226\271\360\221\222\275\360\221\226\271\222\360\221\275.x\360\221\226\271\360\221\222\275\012\360\221\226\271\360\221\222\275n\345\217\270..\360\221\226\271\360\221\222\275.x\360\221\226\271\360\221\222\275\012\360\221\226\271\360\221\222\275.\360\221\226\271\360\221\222\275\360\221\226\271\360\221\222\275.x\360\221\226\271\360\221\222\275\012\360\221\226\271\360\221\222\275n\345\217\270...xncx\360\221\226\271\360\221\222\275\012\012.xncx\360\221\226\271\360\221\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\222\275\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-d2e762cb120c056d3a8c49a3c1f782805a55aafb Step #5: Base64: 8JGWufCRkr0uePCRlrnwkZK9CvCRlrnwkZK9LnhuY3jwkZa58JGSvfCRlrmS8JG9LnjwkZa58JGSvQrwkZa58JGSvW7lj7guLvCRlrnwkZK9LnjwkZa58JGSvQrwkZa58JGSvS7wkZa58JGSvfCRlrnwkZK9LnjwkZa58JGSvQrwkZa58JGSvW7lj7guLi54bmN48JGWufCRkr0KCi54bmN48JGWufCR//////////////////////////////////////////////////////////////////////////////////////////////+SvQoK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5061 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4291902246 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557576678810, 0x55757686201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557576862020,0x5575786fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d2e762cb120c056d3a8c49a3c1f782805a55aafb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6413 processed earlier; will process 4616 files now Step #5: ==182272== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55756d16d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5575737d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5575737b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5575737b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55756d173d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55756d0d4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55756d0cf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55756d165c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557570134f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557570134f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557570134f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557570134f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557570134f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557570134f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557570134f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557570134f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557570134f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557570134f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5575723c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55756f0f6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55756f101be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55756eeadc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55756eeadc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55756eeae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55756eead874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55756eead874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55756eead874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5575737b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5575737c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5575737a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5575737d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff7e1c7b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55756d0cdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x21,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x44,0x5f,0x6e,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x44,0x5f,0x6e,0x4d, Step #5: ****************************************************************************!************************************\000\000********************************************************************************************************************D_n******D_nM Step #5: artifact_prefix='./'; Test unit written to ./oom-6692988819680291d85b728733b868d83e1491c8 Step #5: Base64: KioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKiEqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioAACoqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqRF9uKioqKioqRF9uTQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5062 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4292441474 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d50bbcd810, 0x55d50bdb701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d50bdb7020,0x55d50dc4f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6692988819680291d85b728733b868d83e1491c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6414 processed earlier; will process 4615 files now Step #5: #1 pulse cov: 4112 ft: 4113 exec/s: 0 rss: 176Mb Step #5: ==182308== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d5026c29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d508d27898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d508d0a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d508d0a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d5026c8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d502629b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d502624355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d5026bac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d505689f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d505689f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d505689f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d505689f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d505689f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d505689f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d505689f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d505689f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d505689f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d505689f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d50791ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d50464bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d504656be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d504402c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d504402c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d504403738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d504402874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d504402874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d504402874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d508d0cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d508d15928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d508cfd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d508d28112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa1200a2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d502622b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x28,0xa,0x33,0x3,0x0,0x0,0x20,0x47,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6c,0x75,0x67,0x67,0x61,0x67,0x65,0x0,0x0,0x0,0x0,0x0,0x28,0xa,0x33,0x3,0x0,0x0,0x20,0x47,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6c,0x75,0x67,0x67,0x61,0x67,0x65,0x0,0x0,0x40,0x0,0x0,0x0,0x9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x30,0x50,0x55,0x53,0x4c,0x54,0x2d,0x5e,0x67,0x65,0x0,0x2d,0x45,0x47,0x49,0x4e,0x72,0x69,0x66,0x55,0x0,0x9,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x30,0x50,0x55,0x53,0x4c,0x54,0x2d,0x61,0x67,0x65,0x0,0x2d,0x2d,0x55,0x45,0x47,0x49,0x4e,0x72,0x69,0x66,0x55,0x53,0x27,0x4c,0x54,0x10,0x0,0x0,0x0,0x5,0x20,0x0,0x0,0x20,0x47,0x32,0x50, Step #5: (\0123\003\000\000 G\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000luggage\000\000\000\000\000(\0123\003\000\000 G\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000luggage\000\000@\000\000\000\011\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0000PUSLT-^ge\000-EGINrifU\000\011\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0000PUSLT-age\000--UEGINrifUS'LT\020\000\000\000\005 \000\000 G2P Step #5: artifact_prefix='./'; Test unit written to ./oom-58a74bddd37fa8ee073ec154b9fa31aa78158cda Step #5: Base64: KAozAwAAIEcAAAAAAAAAAAAAAAAAAAAAAABsdWdnYWdlAAAAAAAoCjMDAAAgRwAAAAAAAAAAAAAAAAAAAAAAAGx1Z2dhZ2UAAEAAAAAJAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwUFVTTFQtXmdlAC1FR0lOcmlmVQAJAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwUFVTTFQtYWdlAC0tVUVHSU5yaWZVUydMVBAAAAAFIAAAIEcyUA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5063 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4293012023 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a869afc810, 0x55a869ce601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a869ce6020,0x55a86bb7e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58a74bddd37fa8ee073ec154b9fa31aa78158cda' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6416 processed earlier; will process 4613 files now Step #5: ==182344== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a8605f19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a866c56898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a866c395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a866c394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a8605f7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a860558b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a860553355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a8605e9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a8635b8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a8635b8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a8635b8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a8635b8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a8635b8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a8635b8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a8635b8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a8635b8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a8635b8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a8635b8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a86584df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a86257ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a862585be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a862331c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a862331c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a862332738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a862331874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a862331874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a862331874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a866c3babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a866c44928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a866c2c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a866c57112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa33edbb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a860551b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x77,0x73,0x3a,0x31,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96,0x2e,0xe3,0x8c,0x96, Step #5: \012ws:1\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226.\343\214\226 Step #5: artifact_prefix='./'; Test unit written to ./oom-a42b86543dba630ce9f385cef01f80023dfcced3 Step #5: Base64: CndzOjHjjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMli7jjJYu44yWLuOMlg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5064 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4293530579 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560de78a1810, 0x560de7a8b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560de7a8b020,0x560de99230e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a42b86543dba630ce9f385cef01f80023dfcced3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6417 processed earlier; will process 4612 files now Step #5: ==182380== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560dde3969c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560de49fb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560de49de5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560de49de4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560dde39cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560dde2fdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560dde2f8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560dde38ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560de135df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560de135df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560de135df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560de135df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560de135df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560de135df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560de135df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560de135df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560de135df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560de135df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560de35f2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560de031fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560de032abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560de00d6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560de00d6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560de00d7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560de00d6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560de00d6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560de00d6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560de49e0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560de49e9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560de49d1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560de49fc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd027632082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560dde2f6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x74,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x60,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x60,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x60,0x46,0x55,0x5a,0x5a,0x47,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x74,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x60,0x46,0x2d,0x54,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x74,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x5a,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x60,0x46,0x55,0x5a,0x5a,0x2d,0x54,0x41,0x47,0x60,0x46,0x55,0x5a,0x63,0x61,0x6c,0x63, Step #5: tFUZZ-TAG`FUZZ-TAGZFUZZ-TAG`FUZZ-TAGZFUZZ-TAG`FUZZGFUZZ-TAGtFUZZ-TAGZFUZZ-TAG`F-TFUZZ-TAGZFUZZ-TAGZFUZZ-TAGZFUZZ-TAGZFUZZ-TAGZFUZZ-TAGZFUZZ-TAGZFUZZ-TAGZFUZZ-TAGZFUZZ-TAGZFUZZ-TAGZFUZZ-TAGZFUZZ-TAGZFUZZ-TAGZFUtFUZZ-TAGZFUZZ-TAG`FUZZ-TAG`FUZcalc Step #5: artifact_prefix='./'; Test unit written to ./oom-be8d8898446776b813bb96eaf29a1911b467ca33 Step #5: Base64: dEZVWlotVEFHYEZVWlotVEFHWkZVWlotVEFHYEZVWlotVEFHWkZVWlotVEFHYEZVWlpHRlVaWi1UQUd0RlVaWi1UQUdaRlVaWi1UQUdgRi1URlVaWi1UQUdaRlVaWi1UQUdaRlVaWi1UQUdaRlVaWi1UQUdaRlVaWi1UQUdaRlVaWi1UQUdaRlVaWi1UQUdaRlVaWi1UQUdaRlVaWi1UQUdaRlVaWi1UQUdaRlVaWi1UQUdaRlVaWi1UQUdaRlVaWi1UQUdaRlVaWi1UQUdaRlV0RlVaWi1UQUdaRlVaWi1UQUdgRlVaWi1UQUdgRlVaY2FsYw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5065 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4294196901 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f9a2d32810, 0x55f9a2f1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f9a2f1c020,0x55f9a4db40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/be8d8898446776b813bb96eaf29a1911b467ca33' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6418 processed earlier; will process 4611 files now Step #5: ==182416== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f9998279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f99fe8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f99fe6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f99fe6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f99982dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f99978eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f999789355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f99981fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f99c7eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f99c7eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f99c7eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f99c7eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f99c7eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f99c7eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f99c7eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f99c7eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f99c7eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f99c7eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f99ea83f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f99b7b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f99b7bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f99b567c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f99b567c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f99b568738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f99b567874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f99b567874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f99b567874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f99fe71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f99fe7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f99fe62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f99fe8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f86c6569082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f999787b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x21,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x2a,0x2a,0x2a,0x44,0x5f,0x6e,0x4d, Step #5: ****************************************************************************!************************************\000\000**************************************************************************************\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377***D_nM Step #5: artifact_prefix='./'; Test unit written to ./oom-990adb278e8df64cff47e0cb8c140e211475d42d Step #5: Base64: KioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKiEqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioAACoqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioq////////////////////////////////////////////////KioqRF9uTQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5066 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4294730586 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b881d55810, 0x55b881f3f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b881f3f020,0x55b883dd70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/990adb278e8df64cff47e0cb8c140e211475d42d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6419 processed earlier; will process 4610 files now Step #5: ==182452== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b87884a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b87eeaf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b87ee925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b87ee924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b878850d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b8787b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b8787ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b878842c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b87b811f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b87b811f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b87b811f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b87b811f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b87b811f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b87b811f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b87b811f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b87b811f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b87b811f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b87b811f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b87daa6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b87a7d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b87a7debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b87a58ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b87a58ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b87a58b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b87a58a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b87a58a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b87a58a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b87ee94abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b87ee9d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b87ee85699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b87eeb0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7ac9c3b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b8787aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x7d,0x7d,0x7d,0x3c,0x74,0x65,0x78,0x74,0x3e,0x35,0x30,0x30,0x32,0xe2,0x9c,0x8e,0xa,0xa,0xc2,0xb3,0xe2,0x80,0x8c,0x3a,0x3e,0x20,0x26,0x23,0x33,0x34,0x30,0x36,0x3b,0x3b,0xa,0x3b,0xc2,0xb3,0x2d,0xa,0xa,0xc2,0xb3,0xe2,0x84,0x8c,0x3a,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x40,0x3e,0x31,0x31,0xcd,0xa2,0x76,0x76,0x26,0x23,0x33,0x34,0x30,0x36,0x3b,0x2d,0xa,0xa,0xc2,0xb3,0xe2,0x80,0xbf,0x3a,0xe2,0x80,0x8c,0xe2,0x80,0x8c,0xe2,0x80,0x8d,0x60,0x39,0x7f,0x2e,0x20,0x2f,0x34,0x32,0x3b,0x26,0x23,0x33,0x30,0x34,0x3b,0x26,0x23,0x37,0x36,0x37,0x34,0x3b,0x2d,0xa,0xa,0xc2,0xb3,0xe2,0x80,0xbf,0x3a,0xe2,0x80,0x8c,0xe2,0x80,0x8c,0xe2,0x80,0x8d,0x60,0x39,0x7f,0x39,0x32,0x32,0x33,0x33,0xe2,0x80,0x8c,0x3a,0x32,0x36,0x38,0x32,0x37,0x32,0x36,0x35,0x30,0x30,0x32,0xe2,0x80,0x8c,0xe2,0x80,0x8d,0xd,0xd,0x4d,0xd,0xd,0xd,0xd,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x42,0x4f,0x3c,0x2f,0x73,0x76,0x67,0x3e, Step #5: <svg>}}}<text>5002\342\234\216\012\012\302\263\342\200\214:> &#3406;;\012;\302\263-\012\012\302\263\342\204\214:@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@>11\315\242vv&#3406;-\012\012\302\263\342\200\277:\342\200\214\342\200\214\342\200\215`9\177. /42;&#304;&#7674;-\012\012\302\263\342\200\277:\342\200\214\342\200\214\342\200\215`9\17792233\342\200\214:26827265002\342\200\214\342\200\215\015\015M\015\015\015\015</text>BO</svg> Step #5: artifact_prefix='./'; Test unit written to ./oom-0ebf91a311c710050cba145dab95d3842a1c3b1c Step #5: Base64: PHN2Zz59fX08dGV4dD41MDAy4pyOCgrCs+KAjDo+ICYjMzQwNjs7CjvCsy0KCsKz4oSMOkBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQD4xMc2idnYmIzM0MDY7LQoKwrPigL864oCM4oCM4oCNYDl/LiAvNDI7JiMzMDQ7JiM3Njc0Oy0KCsKz4oC/OuKAjOKAjOKAjWA5fzkyMjMz4oCMOjI2ODI3MjY1MDAy4oCM4oCNDQ1NDQ0NDTwvdGV4dD5CTzwvc3ZnPg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5067 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 414585 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565405b33810, 0x565405d1d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565405d1d020,0x565407bb50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0ebf91a311c710050cba145dab95d3842a1c3b1c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6420 processed earlier; will process 4609 files now Step #5: ==182488== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5653fc6289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565402c8d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565402c705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565402c704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5653fc62ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5653fc58fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5653fc58a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5653fc620c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5653ff5eff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5653ff5eff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5653ff5eff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5653ff5eff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5653ff5eff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5653ff5eff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5653ff5eff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5653ff5eff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5653ff5eff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5653ff5eff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565401884f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5653fe5b1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5653fe5bcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5653fe368c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5653fe368c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5653fe369738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5653fe368874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5653fe368874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5653fe368874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565402c72abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565402c7b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565402c63699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565402c8e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f19c2de6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5653fc588b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x30,0x33,0x41,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x68,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x68,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x6e,0x64,0x72,0x6f,0x69,0x64,0x20,0x52,0x75,0x6e,0x74,0x69,0x6d,0x65,0x31,0x33,0x3a,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x3e,0x6e,0x64,0x72,0x6f,0x69,0x64,0x20,0x52,0x75,0x6e,0x74,0x69,0x6d,0x65,0x31,0x33,0x3a,0x32, Step #5: 03A>>>>>>>>>>h>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>h>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>ndroid Runtime13:>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>ndroid Runtime13:2 Step #5: artifact_prefix='./'; Test unit written to ./oom-d09fb1ff6409de99f5c3a766b23359a57904e20b Step #5: Base64: MDNBPj4+Pj4+Pj4+Pmg+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pmg+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+bmRyb2lkIFJ1bnRpbWUxMzo+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj4+Pj5uZHJvaWQgUnVudGltZTEzOjI= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5068 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 947107 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c15d5f810, 0x556c15f4901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c15f49020,0x556c17de10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d09fb1ff6409de99f5c3a766b23359a57904e20b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6421 processed earlier; will process 4608 files now Step #5: #1 pulse cov: 4042 ft: 4043 exec/s: 0 rss: 176Mb Step #5: ==182524== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556c0c8549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c12eb9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c12e9c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c12e9c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556c0c85ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556c0c7bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556c0c7b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556c0c84cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556c0f81bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556c0f81bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556c0f81bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556c0f81bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556c0f81bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556c0f81bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556c0f81bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556c0f81bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556c0f81bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556c0f81bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c11ab0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556c0e7ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556c0e7e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556c0e594c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556c0e594c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556c0e595738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556c0e594874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556c0e594874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556c0e594874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c12e9eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c12ea7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c12e8f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c12eba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb28d512082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556c0c7b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x47,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x47,0x2d,0x49,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0x3b,0x3d,0x6,0x6,0x49,0x6f,0x74,0x61,0x6,0x6,0x6,0x6,0xe,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0xa,0x2d,0xa,0x2d,0xa,0x4e,0xa,0x3d,0x3b,0x3d,0x6,0x6,0x49,0xe2,0x80,0xae,0x6f,0x74,0x61,0x6,0x6,0x6,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x68,0x6,0xe,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x49,0x6f,0x74,0x61,0x6,0x6,0x6,0x6,0xe,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x49,0x6f,0x74,0x61,0x6,0x6,0x6,0x6,0xe,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0xa,0x3d,0x41,0x3d,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0xa,0x3d,0x41,0x3d,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0x6,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x85,0xa4,0x31,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa,0xa, Step #5: \005-----BGGIN --G-I--\012N\012=;=\006\006Iota\006\006\006\006\016\006\006\006\006\006\006\006\006\006\006\006\006\006\006\012-\012-\012N\012=;=\006\006I\342\200\256ota\006\006\006hhhhhhhhhhhhhhhhhhhhhhhhhttps://h\006\016\006\006\006\006\006\006\006\006Iota\006\006\006\006\016\006\006\006\006\006\006\006\006\006\006\006\006\006\006Iota\006\006\006\006\016\006\006\006\006\006\006\006\006\006\006\006\006\006\006\012-\012-\012-\012-\012\012\012=A=\006\006\006\006\006\006\006\006\006\006\012-\012-\012-\012-\012\012\012=A=\006\006\006\006\006\006\006\006\006\006\012-\012-\012-\012-\012\012\012=\012=\012=\012=\205\2441\012\012\012\012\012\012\012\012\012\012\012\012\012\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-2c44f916b56fd29985b5e6eb356f0fefb280d9d1 Step #5: Base64: BS0tLS0tQkdHSU4gLS1HLUktLQpOCj07PQYGSW90YQYGBgYOBgYGBgYGBgYGBgYGBgYKLQotCk4KPTs9BgZJ4oCub3RhBgYGaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaHR0cHM6Ly9oBg4GBgYGBgYGBklvdGEGBgYGDgYGBgYGBgYGBgYGBgYGSW90YQYGBgYOBgYGBgYGBgYGBgYGBgYKLQotCi0KLQoKCj1BPQYGBgYGBgYGBgYKLQotCi0KLQoKCj1BPQYGBgYGBgYGBgYKLQotCi0KLQoKCj0KPQo9Cj2FpDEKCgoKCgoKCgoKCgoKCgo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5069 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1524522 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55efda4c5810, 0x55efda6af01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55efda6af020,0x55efdc5470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2c44f916b56fd29985b5e6eb356f0fefb280d9d1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6423 processed earlier; will process 4606 files now Step #5: ==182560== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55efd0fba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55efd761f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55efd76025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55efd76024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55efd0fc0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55efd0f21b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55efd0f1c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55efd0fb2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55efd3f81f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55efd3f81f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55efd3f81f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55efd3f81f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55efd3f81f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55efd3f81f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55efd3f81f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55efd3f81f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55efd3f81f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55efd3f81f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55efd6216f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55efd2f43b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55efd2f4ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55efd2cfac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55efd2cfac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55efd2cfb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55efd2cfa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55efd2cfa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55efd2cfa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55efd7604abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55efd760d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55efd75f5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55efd7620112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff3f022a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55efd0f1ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x30,0x4d,0x46,0x77,0x48,0x65,0x57,0x53,0x63,0x6f,0x41,0x61,0x71,0x59,0x31,0x2b,0x6a,0x6d,0x47,0x4c,0x6c,0x43,0x41,0x41,0x42,0x73,0x54,0x2b,0x4c,0x53,0x59,0x49,0x53,0x7a,0x56,0x77,0x6a,0x77,0x6f,0x30,0x54,0x45,0xa,0x66,0x61,0x6d,0x69,0x6c,0x79,0x20,0x51,0x20,0x44,0x20,0x4e,0xa,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x76,0x30,0x4d,0x46,0x77,0x48,0x65,0x57,0x53,0x63,0x6f,0x41,0x61,0x71,0x59,0x30,0x2f,0x6a,0x6d,0x47,0x4c,0x6c,0x43,0x41,0x41,0x42,0x73,0x54,0x2b,0x4c,0x53,0x59,0x49,0x53,0x7a,0x56,0x77,0x6a,0x77,0x6f,0x31,0x54,0x45,0xa,0x66,0x61,0x6d,0x69,0x6c,0x79,0x20,0x51,0x20,0x44,0x20,0x41,0xa,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x50,0x79,0x76,0x48,0x50,0x46,0x47,0x71,0x54,0x61,0x45,0x31,0x67,0x52,0x72,0x42,0x59,0x79,0x65,0x4b,0x74,0x31,0x79,0x71,0x52,0x76,0x69,0x64,0x6d,0x44,0x58,0x61,0x71,0x49,0x59,0x30,0x6e,0x76,0x65,0x6d,0x49,0x46,0x30,0xa,0x66,0x61,0x6d,0x69,0x6c,0x79,0x20,0x4c,0x20,0x55,0x20,0x4a, Step #5: onion-key\012ntor-onion-key v0MFwHeWScoAaqY1+jmGLlCAABsT+LSYISzVwjwo0TE\012family Q D N\012onion-key\012ntor-onion-key v0MFwHeWScoAaqY0/jmGLlCAABsT+LSYISzVwjwo1TE\012family Q D A\012onion-key\012ntor-onion-key PyvHPFGqTaE1gRrBYyeKt1yqRvidmDXaqIY0nvemIF0\012family L U J Step #5: artifact_prefix='./'; Test unit written to ./oom-7a444246200bc1aef3738d016a9a1dcb4a943044 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHYwTUZ3SGVXU2NvQWFxWTEram1HTGxDQUFCc1QrTFNZSVN6Vndqd28wVEUKZmFtaWx5IFEgRCBOCm9uaW9uLWtleQpudG9yLW9uaW9uLWtleSB2ME1Gd0hlV1Njb0FhcVkwL2ptR0xsQ0FBQnNUK0xTWUlTelZ3andvMVRFCmZhbWlseSBRIEQgQQpvbmlvbi1rZXkKbnRvci1vbmlvbi1rZXkgUHl2SFBGR3FUYUUxZ1JyQll5ZUt0MXlxUnZpZG1EWGFxSVkwbnZlbUlGMApmYW1pbHkgTCBVIEo= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5070 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2049262 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56002f792810, 0x56002f97c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56002f97c020,0x5600318140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7a444246200bc1aef3738d016a9a1dcb4a943044' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6424 processed earlier; will process 4605 files now Step #5: ==182596== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5600262879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56002c8ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56002c8cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56002c8cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56002628dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5600261eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5600261e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56002627fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56002924ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56002924ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56002924ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56002924ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56002924ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56002924ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56002924ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56002924ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56002924ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56002924ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56002b4e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560028210b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56002821bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560027fc7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560027fc7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560027fc8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560027fc7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560027fc7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560027fc7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56002c8d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56002c8da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56002c8c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56002c8ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff283110082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5600261e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2,0x22,0x21,0x2f,0x7d,0xd,0x2,0xa,0x1a,0x3e,0x2f,0x7d,0xd,0x2,0xa,0xe,0x22,0x2,0x2f,0x7d,0xc,0x2,0xa,0x1,0x22,0x2f,0x7d,0xd,0x6,0xa,0x2f,0x2d,0x2f,0xd,0x42,0xa,0x1a,0x6e,0x2f,0x7d,0xd,0x2,0xa,0x7d,0x2,0x2f,0xd,0x24,0xa,0x22,0x1a,0x2f,0x7d,0xd,0x6,0xa,0x75,0x13,0x2f,0x7d,0xd,0x3c,0xa,0x31,0x52,0x2f,0x7d,0xd,0x6,0xa,0x7d,0x47,0x2f,0xd,0x28,0xa,0x7d,0x3c,0x2f,0xd,0x2f,0xa,0x7d,0x6,0x2f,0xd,0x6,0xa,0x5d,0x2c,0x2f,0x9,0x51,0xa,0x24,0x25,0x2f,0xb,0x34,0xa,0x7d,0x31,0x2f,0xb,0xf,0xa,0x7d,0x61,0x2f,0x9,0x2f,0xa,0x7d,0x32,0x2f,0xd,0x48,0xa,0x24,0x49,0x2f,0x9,0x41,0xa,0x2f,0x27,0x3d,0x2f,0xd,0x6,0xa,0x7d,0x2,0x6e,0x2f,0xd,0x2,0xa,0x24,0x30,0x2f,0xb,0xf,0xa,0x24,0x4c,0x2f,0xb,0x33,0xa,0x24,0x44,0x2f,0xb,0xf,0xa,0x7d,0x67,0x2f,0x9,0xf,0xa,0x24,0x6f,0x2f,0xb,0xf,0xa,0x7d,0x75,0x2f,0xd,0x6,0xa,0x2,0x22,0x3c,0x2f,0x7d,0xd,0x2,0xa,0x7d,0x2,0x2d,0x2f,0xd,0x2,0xa,0x24,0x41,0x2f,0xb,0xf,0xa,0x2f,0x3b,0x2f,0x7d,0xd,0x6,0xa,0x2e,0x19,0x2f,0xd,0x2,0xa,0x7d,0x27,0x2f,0xd,0x6,0xa,0x1a,0x2,0x3c,0x2f,0x7d,0xd,0x7d,0xa,0x22,0x3d,0x2f,0x7d,0xd,0x2,0xa,0x7d,0x2,0x3d,0x2f,0xd,0x6,0xa,0x7d,0x7a,0x2f,0xd,0x12,0xde,0xad,0xbe,0xef, Step #5: \002\"!/}\015\002\012\032>/}\015\002\012\016\"\002/}\014\002\012\001\"/}\015\006\012/-/\015B\012\032n/}\015\002\012}\002/\015$\012\"\032/}\015\006\012u\023/}\015<\0121R/}\015\006\012}G/\015(\012}</\015/\012}\006/\015\006\012],/\011Q\012$%/\0134\012}1/\013\017\012}a/\011/\012}2/\015H\012$I/\011A\012/'=/\015\006\012}\002n/\015\002\012$0/\013\017\012$L/\0133\012$D/\013\017\012}g/\011\017\012$o/\013\017\012}u/\015\006\012\002\"</}\015\002\012}\002-/\015\002\012$A/\013\017\012/;/}\015\006\012.\031/\015\002\012}'/\015\006\012\032\002</}\015}\012\"=/}\015\002\012}\002=/\015\006\012}z/\015\022\336\255\276\357 Step #5: artifact_prefix='./'; Test unit written to ./oom-3798441251bb8677f31d3dc02633d96566b9d732 Step #5: Base64: AiIhL30NAgoaPi99DQIKDiICL30MAgoBIi99DQYKLy0vDUIKGm4vfQ0CCn0CLw0kCiIaL30NBgp1Ey99DTwKMVIvfQ0GCn1HLw0oCn08Lw0vCn0GLw0GCl0sLwlRCiQlLws0Cn0xLwsPCn1hLwkvCn0yLw1ICiRJLwlBCi8nPS8NBgp9Am4vDQIKJDAvCw8KJEwvCzMKJEQvCw8KfWcvCQ8KJG8vCw8KfXUvDQYKAiI8L30NAgp9Ai0vDQIKJEEvCw8KLzsvfQ0GCi4ZLw0CCn0nLw0GChoCPC99DX0KIj0vfQ0CCn0CPS8NBgp9ei8NEt6tvu8= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5071 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 2585823 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56548c698810, 0x56548c88201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56548c882020,0x56548e71a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3798441251bb8677f31d3dc02633d96566b9d732' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6425 processed earlier; will process 4604 files now Step #5: ==182632== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56548318d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5654897f2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5654897d55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5654897d54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565483193d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5654830f4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5654830ef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565483185c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565486154f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565486154f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565486154f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565486154f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565486154f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565486154f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565486154f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565486154f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565486154f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565486154f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5654883e9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565485116b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565485121be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565484ecdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565484ecdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565484ece738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565484ecd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565484ecd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565484ecd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5654897d7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5654897e0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5654897c8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5654897f3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7945bfe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5654830edb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x2,0x0,0x0,0x31,0x33,0x31,0x36,0x32,0x32,0x32,0x37,0x36,0x30,0x31,0x34,0x35,0x30,0x35,0x32,0x31,0x31,0x31,0x35,0x37,0x32,0x30,0x37,0x39,0x36,0x39,0x38,0x37,0x37,0x31,0x38,0x38,0x39,0x33,0x31,0x38,0x33,0x31,0x0,0x0,0xe2,0x81,0xa6,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2a,0x7e,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xf0,0x9d,0x85,0xa0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x1f,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2a,0x7e,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0xf0,0x9d,0x85,0xa0,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: ID3\002\000\000131622276014505211157207969877188931831\000\000\342\201\246\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000*~************\360\235\205\240****************\037****************************\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000*~************\360\235\205\240**************\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a73946b83e8617cac35d380579a22446c9bcc72b Step #5: Base64: SUQzAgAAMTMxNjIyMjc2MDE0NTA1MjExMTU3MjA3OTY5ODc3MTg4OTMxODMxAADigaYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACp+KioqKioqKioqKioq8J2FoCoqKioqKioqKioqKioqKiofKioqKioqKioqKioqKioqKioqKioqKioqKioqKgAAAAAAAAAAAAAAAAAAAAAAACp+KioqKioqKioqKioq8J2FoCoqKioqKioqKioqKioqAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5072 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3124298 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559bb425a810, 0x559bb444401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559bb4444020,0x559bb62dc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a73946b83e8617cac35d380579a22446c9bcc72b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6426 processed earlier; will process 4603 files now Step #5: ==182668== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559baad4f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559bb13b4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559bb13975dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559bb13974fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559baad55d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559baacb6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559baacb1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559baad47c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559badd16f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559badd16f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559badd16f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559badd16f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559badd16f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559badd16f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559badd16f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559badd16f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559badd16f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559badd16f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559baffabf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559baccd8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559bacce3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559baca8fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559baca8fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559baca90738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559baca8f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559baca8f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559baca8f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559bb1399abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559bb13a2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559bb138a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559bb13b5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f32615f1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559baacafb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x0,0x0,0x5b,0x7c,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x7d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0xf3, Step #5: $\000\000[|''/''''''\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012}\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012==D\012=\012=\012=\012=\012==\012=\012=\012D=\012=\012=\012=\012\020\000\000\000\000\000\000$\363 Step #5: artifact_prefix='./'; Test unit written to ./oom-807bf6170b7993783747c696daa07656f3131c4f Step #5: Base64: JAAAW3wnJy8nJycnJycKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoKPT0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQp9Cj0KPQo9Cj0KPQo9Cj0KPQoKPQo9Cj0KPQo9Cj0KPQo9PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj09RAo9Cj0KPQo9Cj09Cj0KPQpEPQo9Cj0KPQoQAAAAAAAAJPM= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5073 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3667661 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c2cc5be810, 0x55c2cc7a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c2cc7a8020,0x55c2ce6400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/807bf6170b7993783747c696daa07656f3131c4f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6427 processed earlier; will process 4602 files now Step #5: #1 pulse cov: 3454 ft: 3455 exec/s: 0 rss: 177Mb Step #5: ==182704== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c2c30b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c2c9718898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c2c96fb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c2c96fb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c2c30b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c2c301ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c2c3015355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c2c30abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c2c607af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c2c607af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c2c607af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c2c607af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c2c607af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c2c607af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c2c607af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c2c607af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c2c607af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c2c607af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c2c830ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c2c503cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c2c5047be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c2c4df3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c2c4df3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c2c4df4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c2c4df3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c2c4df3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c2c4df3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c2c96fdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c2c9706928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c2c96ee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c2c9719112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f0f3d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c2c3013b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x27,0x28,0x0,0x60,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x73,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x20,0x24,0x5b,0x2f,0x11,0xe0,0xa1,0xb0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x54,0x58,0x59,0x45,0x15,0x0,0x27,0x17,0x54,0x0,0x9,0x0,0x0,0x0,0x0,0x0,0x0,0x59,0x45,0x33,0x4,0x3b,0x27,0x0,0x0,0x60,0x27,0x17,0x54,0x58,0x59,0x45,0x15,0x0,0x10,0x0,0x15,0x0,0x10, Step #5: ID3\004'(\000`\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000s\012\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000 $[/\021\340\241\260\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000TXYE\025\000'\027T\000\011\000\000\000\000\000\000YE3\004;'\000\000`'\027TXYE\025\000\020\000\025\000\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-8285e93596c6e9897b69e7b7571304303f4a993c Step #5: Base64: SUQzBCcoAGAAAAAAAAAAAAAAAAAAAABzCgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgJFsvEeChsAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAVFhZRRUAJxdUAAkAAAAAAABZRTMEOycAAGAnF1RYWUUVABAAFQAQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5074 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4361150 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e27c832810, 0x55e27ca1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e27ca1c020,0x55e27e8b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8285e93596c6e9897b69e7b7571304303f4a993c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6429 processed earlier; will process 4600 files now Step #5: ==182740== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e2733279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e27998c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e27996f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e27996f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e27332dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e27328eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e273289355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e27331fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e2762eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e2762eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e2762eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e2762eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e2762eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e2762eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e2762eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e2762eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e2762eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e2762eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e278583f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e2752b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e2752bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e275067c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e275067c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e275068738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e275067874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e275067874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e275067874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e279971abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e27997a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e279962699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e27998d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f61bf358082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e273287b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa,0x60,0x60,0x60,0xa, Step #5: ```\012```\012```\012```\012```\012```\012```\012```\012```\012``\012```\012```\012```\012```\012```\012`\012```\012```\012```\012```\012``\012```\012```\012```\012```\012```\012```\012`\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012```\012`````\012```\012```\012```\012```\012```\012```\012```\012`````\012```\012```\012```\012```\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-afbb8ce6c94b99d4b83d57509af201fba4ed146f Step #5: Base64: YGBgCmBgYApgYGAKYGBgCmBgYApgYGAKYGBgCmBgYApgYGAKYGAKYGBgCmBgYApgYGAKYGBgCmBgYApgCmBgYApgYGAKYGBgCmBgYApgYApgYGAKYGBgCmBgYApgYGAKYGBgCmBgYApgCmBgYApgYGAKYGBgCmBgYApgYGAKYGBgCmBgYApgYGAKYGBgCmBgYApgYGAKYGBgCmBgYApgYGAKYGBgCmBgYApgYGAKYGBgCmBgYApgYGAKYGBgCmBgYGBgCmBgYApgYGAKYGBgCmBgYApgYGAKYGBgCmBgYApgYGBgYApgYGAKYGBgCmBgYApgYGAK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5075 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 5034261 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bfcc43d810, 0x55bfcc62701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bfcc627020,0x55bfce4bf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/afbb8ce6c94b99d4b83d57509af201fba4ed146f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6430 processed earlier; will process 4599 files now Step #5: ==182776== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bfc2f329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bfc9597898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bfc957a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bfc957a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bfc2f38d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bfc2e99b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bfc2e94355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bfc2f2ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bfc5ef9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bfc5ef9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bfc5ef9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bfc5ef9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bfc5ef9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bfc5ef9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bfc5ef9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bfc5ef9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bfc5ef9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bfc5ef9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bfc818ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bfc4ebbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bfc4ec6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bfc4c72c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bfc4c72c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bfc4c73738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bfc4c72874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bfc4c72874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bfc4c72874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bfc957cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bfc9585928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bfc956d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bfc9598112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8e5f85a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bfc2e92b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x77,0x73,0x3a,0xef,0xb7,0xba,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84,0xcd,0x84, Step #5: ws:\357\267\272\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204\315\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-cbeaded20a4d5f6192b31fa39a6d272128944932 Step #5: Base64: d3M677e6zYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2EzYTNhM2E Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5076 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 5568341 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e71acb810, 0x559e71cb501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e71cb5020,0x559e73b4d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cbeaded20a4d5f6192b31fa39a6d272128944932' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6431 processed earlier; will process 4598 files now Step #5: #1 pulse cov: 4322 ft: 4323 exec/s: 0 rss: 177Mb Step #5: ==182812== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559e685c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e6ec25898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e6ec085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e6ec084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e685c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e68527b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e68522355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e685b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e6b587f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e6b587f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e6b587f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e6b587f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e6b587f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e6b587f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e6b587f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e6b587f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e6b587f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e6b587f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e6d81cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e6a549b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e6a554be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e6a300c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e6a300c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e6a301738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e6a300874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e6a300874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e6a300874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e6ec0aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e6ec13928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e6ebfb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e6ec26112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fafd1a74082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e68520b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x47,0x49,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0xa,0x3d,0x44,0x2d,0x30,0x4,0xcc,0x96,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xff, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012D\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=---\012-----\000-----BE\012=\012=\012=GIN\012=\012=\012=\012=\000----\012--\012=D-0\004\314\226skip_cl\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-c9e7e8c4b45a1f1da06cfb0365cfcffbf9933c7d Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9CkQKPQo9Cj0KCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPS0tLQotLS0tLQAtLS0tLUJFCj0KPQo9R0lOCj0KPQo9Cj0ALS0tLQotLQo9RC0wBMyWc2tpcF9jbAp8ABD/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5077 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 6161635 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563ec4735810, 0x563ec491f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563ec491f020,0x563ec67b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9e7e8c4b45a1f1da06cfb0365cfcffbf9933c7d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6433 processed earlier; will process 4596 files now Step #5: #1 pulse cov: 4163 ft: 4164 exec/s: 0 rss: 177Mb Step #5: ==182848== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563ebb22a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563ec188f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563ec18725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563ec18724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563ebb230d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563ebb191b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563ebb18c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563ebb222c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563ebe1f1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563ebe1f1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563ebe1f1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563ebe1f1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563ebe1f1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563ebe1f1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563ebe1f1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563ebe1f1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563ebe1f1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563ebe1f1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563ec0486f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563ebd1b3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563ebd1bebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563ebcf6ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563ebcf6ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563ebcf6b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563ebcf6a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563ebcf6a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563ebcf6a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563ec1874abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563ec187d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563ec1865699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563ec1890112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9dc8ee0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563ebb18ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x3d,0x0,0xc,0x2,0x1e,0x6,0xe,0x6,0x1d,0x6,0x13,0x6,0xf,0x6,0x30,0x0,0x21,0x0,0x28,0x6,0x33,0x6,0x3b,0x2d,0x0,0x29,0x3a,0x6,0x6,0x34,0x24,0x0,0x3d,0x0,0xc,0x2,0x1e,0x6,0xe,0x6,0x1d,0x6,0x13,0x6,0xf,0x6,0x30,0x0,0x21,0x0,0x28,0x6,0x33,0x6,0x3b,0x2d,0x3a,0x6,0x34,0x6,0x29,0x8,0x1b,0x0,0x16,0x0,0xb,0x0,0x1,0x0,0x7,0x0,0x14,0x0,0x36,0x5,0x25,0x0,0x2,0x2a,0x35,0x37,0x31,0x0,0x24,0x0,0x15,0x0,0x31,0x0,0x24,0x0,0x3d,0x0,0xc,0x2,0x1e,0x6,0xe,0x6,0x1d,0x6,0x13,0x6,0xf,0x6,0x30,0x0,0x21,0x0,0x28,0x6,0x33,0x6,0x3b,0x2d,0x3a,0x6,0x34,0x6,0x29,0x8,0x1b,0x0,0x16,0x0,0xb,0x0,0x1,0x0,0x7,0x0,0x14,0x0,0x2a,0x5,0x25,0x2,0x36,0x35,0x37,0x0,0x31,0x0,0x24,0x0,0x15,0x0,0x2b,0x0,0xa,0x0,0x9,0x0,0x15,0x0,0x2b,0x0,0xa,0x0,0x9,0x0,0x14,0x0,0x2a,0x5,0x25,0x2,0x36,0x35,0x38,0x0,0x31,0x8,0x1b,0x0,0x16,0x0,0xb,0x0,0x1,0x0,0x7,0x0,0x3d,0x0,0xc,0x2,0x1e,0x6,0xe,0x6,0x1d,0x6,0x13,0x6,0xf,0x6,0x30,0x0,0x21,0x0,0x28,0x6,0x33,0x6,0x3b,0x2d,0x3a,0x6,0x34,0x6,0x29,0x8,0x1b,0x0,0x16,0x0,0xb,0x0,0x1,0x0,0x7,0x0,0x14,0x0,0x2a,0x5,0x25,0x2,0x36,0x35,0x2b,0x0,0xa,0x0,0x9,0x0,0x15,0x0,0x2b,0x0,0xa,0x0,0x9,0x0, Step #5: \000=\000\014\002\036\006\016\006\035\006\023\006\017\0060\000!\000(\0063\006;-\000):\006\0064$\000=\000\014\002\036\006\016\006\035\006\023\006\017\0060\000!\000(\0063\006;-:\0064\006)\010\033\000\026\000\013\000\001\000\007\000\024\0006\005%\000\002*571\000$\000\025\0001\000$\000=\000\014\002\036\006\016\006\035\006\023\006\017\0060\000!\000(\0063\006;-:\0064\006)\010\033\000\026\000\013\000\001\000\007\000\024\000*\005%\002657\0001\000$\000\025\000+\000\012\000\011\000\025\000+\000\012\000\011\000\024\000*\005%\002658\0001\010\033\000\026\000\013\000\001\000\007\000=\000\014\002\036\006\016\006\035\006\023\006\017\0060\000!\000(\0063\006;-:\0064\006)\010\033\000\026\000\013\000\001\000\007\000\024\000*\005%\00265+\000\012\000\011\000\025\000+\000\012\000\011\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-220b062896a80322279937d875f94bb5d8b2d2bf Step #5: Base64: AD0ADAIeBg4GHQYTBg8GMAAhACgGMwY7LQApOgYGNCQAPQAMAh4GDgYdBhMGDwYwACEAKAYzBjstOgY0BikIGwAWAAsAAQAHABQANgUlAAIqNTcxACQAFQAxACQAPQAMAh4GDgYdBhMGDwYwACEAKAYzBjstOgY0BikIGwAWAAsAAQAHABQAKgUlAjY1NwAxACQAFQArAAoACQAVACsACgAJABQAKgUlAjY1OAAxCBsAFgALAAEABwA9AAwCHgYOBh0GEwYPBjAAIQAoBjMGOy06BjQGKQgbABYACwABAAcAFAAqBSUCNjUrAAoACQAVACsACgAJAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5078 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 6754663 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4b63fc810, 0x55e4b65e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4b65e6020,0x55e4b847e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/220b062896a80322279937d875f94bb5d8b2d2bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6435 processed earlier; will process 4594 files now Step #5: #1 pulse cov: 3665 ft: 3666 exec/s: 0 rss: 176Mb Step #5: ==182884== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e4acef19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4b3556898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4b35395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4b35394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4acef7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4ace58b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4ace53355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4acee9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4afeb8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4afeb8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4afeb8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4afeb8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4afeb8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4afeb8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4afeb8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4afeb8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4afeb8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4afeb8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4b214df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4aee7ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4aee85be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4aec31c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4aec31c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4aec32738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4aec31874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4aec31874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4aec31874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4b353babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4b3544928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4b352c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4b3557112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0fa0e2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4ace51b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x2d,0x2d,0x2d,0x2d,0xa,0x49,0x66,0x66,0x66,0xa,0xa,0x3d,0x3d,0xa,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0x3d,0xa,0xc,0x2,0x0,0x0,0x4a,0x4a,0x4a,0x4a,0x4a,0x4a,0x4a,0x4a,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x7e,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3f,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x9,0x7e,0x9,0x7e,0x7e,0xa,0x2b,0x7e,0x7e,0x7e,0x7e,0x0,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa, Step #5: s-----BEGIN----\012Ifff\012\012==\012\012==\012=\012=\012=\012=?=\012\014\002\000\000JJJJJJJJ\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\001\000\000\000\000\000\000~=\012=\012=\012=\012=\012=\012=?=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\012\011~\011~~\012+~~~~\000\000=\012=\012=\012=\012=\012=\012=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-4e315c33b4de254cb5cacd505e246ae110dae019 Step #5: Base64: cy0tLS0tQkVHSU4tLS0tCklmZmYKCj09Cgo9PQo9Cj0KPQo9Pz0KDAIAAEpKSkpKSkpKAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KAQAAAAAAAH49Cj0KPQo9Cj0KPQo9Pz0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9CgoJfgl+fgorfn5+fgAAPQo9Cj0KPQo9Cj0KPQoKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5079 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 7379674 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564ad0ef1810, 0x564ad10db01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564ad10db020,0x564ad2f730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e315c33b4de254cb5cacd505e246ae110dae019' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6437 processed earlier; will process 4592 files now Step #5: #1 pulse cov: 11617 ft: 11618 exec/s: 0 rss: 196Mb Step #5: #2 pulse cov: 12175 ft: 13120 exec/s: 0 rss: 198Mb Step #5: ==182920== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564ac79e69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564ace04b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564ace02e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564ace02e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ac79ecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ac794db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ac7948355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ac79dec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564aca9adf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564aca9adf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564aca9adf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564aca9adf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564aca9adf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564aca9adf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564aca9adf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564aca9adf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564aca9adf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564aca9adf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564accc42f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564ac996fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564ac997abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564ac9726c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564ac9726c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564ac9727738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564ac9726874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564ac9726874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564ac9726874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564ace030abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564ace039928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564ace021699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564ace04c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f92f62082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ac7946b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0x24,0xe2,0x81,0xa6,0x75,0x0,0x0,0x0,0x19,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x0,0x37,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x12,0x3d,0x2a,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x0,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2a,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3a,0x0,0x0,0x0,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x4,0x0,0x62,0x0,0x21,0x0,0x44,0x11,0x2f,0x0,0x44,0x11,0x24, Step #5: \000$\342\201\246u\000\000\000\031\000\000\000\000\000\000\000\000\000=\012=\012=\012=\012=\012=\012=\000\0007\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000--\012N\012=\012=\012=\012=\012=\022=*=\012=\012=\012=\012=\012=\012=\000\000'\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000*\000\010\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000:\000\000\000\012\000\000\000\000\000\000\010\000\000\000\000\000\000\000\000\000\000\000\000\000\000\004\000b\000!\000D\021/\000D\021$ Step #5: artifact_prefix='./'; Test unit written to ./oom-c4a706eb48920c928a711a7401535eb4707aec98 Step #5: Base64: ACTigaZ1AAAAGQAAAAAAAAAAAD0KPQo9Cj0KPQo9Cj0AADcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAtLQpOCj0KPQo9Cj0KPRI9Kj0KPQo9Cj0KPQo9Cj0AACcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAKgAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA6AAAACgAAAAAAAAgAAAAAAAAAAAAAAAAAAAQAYgAhAEQRLwBEESQ= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5080 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 8039504 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b7f9fc810, 0x556b7fbe601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b7fbe6020,0x556b81a7e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c4a706eb48920c928a711a7401535eb4707aec98' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6440 processed earlier; will process 4589 files now Step #5: #1 pulse cov: 4176 ft: 4177 exec/s: 0 rss: 176Mb Step #5: ==182956== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556b764f19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b7cb56898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b7cb395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b7cb394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b764f7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b76458b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b76453355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b764e9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b794b8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b794b8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b794b8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b794b8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b794b8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b794b8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b794b8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b794b8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b794b8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b794b8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b7b74df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b7847ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b78485be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b78231c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b78231c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b78232738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b78231874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b78231874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b78231874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b7cb3babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b7cb44928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b7cb2c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b7cb57112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9217aa8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b76451b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf4,0x8c,0xba,0xbb,0xf4,0x8f,0xbb,0x9b,0xf4,0x8f,0xbb,0xbb,0xf4,0x8e,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbf,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8d,0xba,0xbb,0xf4,0x8f,0xbb,0x9b,0xf4,0x8f,0xbb,0xbb,0xf4,0x8e,0xbb,0xb9,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0x9b,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8d,0xb9,0x9b,0xf4,0x8f,0xbb,0xbb,0xf4,0x8e,0xbb,0xb9,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xf4,0x8f,0xbb,0xbb,0xbb,0xbb,0x8f,0xa5, Step #5: \364\214\272\273\364\217\273\233\364\217\273\273\364\216\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\277\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\215\272\273\364\217\273\233\364\217\273\273\364\216\273\271\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\233\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\215\271\233\364\217\273\273\364\216\273\271\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\364\217\273\273\273\273\217\245 Step #5: artifact_prefix='./'; Test unit written to ./oom-1eb6ff6657afbc6b88073f2892f0a5f4b41586de Step #5: Base64: 9Iy6u/SPu5v0j7u79I67u/SPu7v0j7u79I+7u/SPu7v0j7u79I+7u/SPu7v0j7u79I+7u/SPu7v0j7u79I+7u/SPu7v0j7u79I+7u/SPu7v0j7u79I+/u/SPu7v0j7u79I+7u/SPu7v0jbq79I+7m/SPu7v0jru59I+7u/SPu7v0j7u79I+7u/SPu7v0j7u79I+7u/SPu5v0j7u79I+7u/SPu7v0j7u79I25m/SPu7v0jru59I+7u/SPu7v0j7u79I+7u/SPu7v0j7u79I+7u/SPu7v0j7u79I+7u/SPu7v0j7u79I+7u/SPu7v0j7u79I+7u7u7j6U= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5081 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 8624235 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55da710b3810, 0x55da7129d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55da7129d020,0x55da731350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1eb6ff6657afbc6b88073f2892f0a5f4b41586de' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6442 processed earlier; will process 4587 files now Step #5: ==182992== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55da67ba89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55da6e20d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55da6e1f05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55da6e1f04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55da67baed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55da67b0fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55da67b0a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55da67ba0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55da6ab6ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55da6ab6ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55da6ab6ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55da6ab6ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55da6ab6ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55da6ab6ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55da6ab6ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55da6ab6ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55da6ab6ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55da6ab6ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55da6ce04f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55da69b31b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55da69b3cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55da698e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55da698e8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55da698e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55da698e8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55da698e8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55da698e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55da6e1f2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55da6e1fb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55da6e1e3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55da6e20e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2a5ec98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55da67b08b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x33,0x75,0x75,0x75,0x6d,0x49,0x75,0x44,0x33,0x4,0x10,0x31,0x2c,0x44,0x33,0x4,0x10,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x6d,0x58,0x49,0x44,0x33,0x4,0x10,0x75,0x75,0x75,0x33,0x4,0x10,0x31,0x7b,0x7f,0x2,0x3f,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x33,0x4,0x10,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x33,0x4,0x10,0x31,0x2c,0x33,0x4,0x27,0x0,0x44,0x33,0x4,0x10,0x75,0x6d,0x65,0x74,0x61,0x64,0x7f,0x2,0x3f,0x54,0x31,0x43,0x48,0x0,0x60,0x27,0x54,0x17,0x59,0x45,0x0,0x43,0x6d,0x65,0x4,0x10,0x75,0x75,0x75,0x75,0x15,0x75,0x0,0x75,0x10,0x15,0x75,0x75,0x6d,0x49,0x44,0x33,0x4,0x10,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x6d,0x49,0x75,0x44,0x33,0x4,0x10,0x31,0x0,0x10,0x2c,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x44,0x33,0x4,0x10,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x6d,0x58,0x49,0x44,0x33,0x4,0x10,0x75,0x75,0x75,0x33,0x4,0x10,0x31,0x7b,0x7f,0x2,0x3f,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x33,0x4,0x10,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x75,0x6d,0x49,0x44,0x33,0x4,0x10,0x31,0x2c,0x33,0x4,0x44,0x5a,0x4,0x0,0x27,0x0,0x60,0x27,0x31,0x54,0x59,0x45,0x4,0x39,0x10,0x7f,0x7f,0x7f,0x7a,0x43,0x4f,0x4d,0x39,0x10,0x7f,0x7f,0x7f,0x7a,0x43,0x4f,0x4d,0x30,0x10, Step #5: ID3\0043uuumIuD3\004\0201,D3\004\020uuuuuuuumXID3\004\020uuu3\004\0201{\177\002?uuuuuuumID3\004\020uuuuuuuumID3\004\0201,3\004'\000D3\004\020umetad\177\002?T1CH\000`'T\027YE\000Cme\004\020uuuu\025u\000u\020\025uumID3\004\020uuuuuuumIuD3\004\0201\000\020,\001\000\000\000\000\000\000\000D3\004\020uuuuuuuumXID3\004\020uuu3\004\0201{\177\002?uuuuuuumID3\004\020uuuuuuuumID3\004\0201,3\004DZ\004\000'\000`'1TYE\0049\020\177\177\177zCOM9\020\177\177\177zCOM0\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-3da943f3a4f5069006317077009a7ecd14309d08 Step #5: Base64: SUQzBDN1dXVtSXVEMwQQMSxEMwQQdXV1dXV1dXVtWElEMwQQdXV1MwQQMXt/Aj91dXV1dXV1bUlEMwQQdXV1dXV1dXVtSUQzBBAxLDMEJwBEMwQQdW1ldGFkfwI/VDFDSABgJ1QXWUUAQ21lBBB1dXV1FXUAdRAVdXVtSUQzBBB1dXV1dXV1bUl1RDMEEDEAECwBAAAAAAAAAEQzBBB1dXV1dXV1dW1YSUQzBBB1dXUzBBAxe38CP3V1dXV1dXVtSUQzBBB1dXV1dXV1dW1JRDMEEDEsMwREWgQAJwBgJzFUWUUEORB/f396Q09NORB/f396Q09NMBA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5082 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 9284009 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fdd452c810, 0x55fdd471601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fdd4716020,0x55fdd65ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3da943f3a4f5069006317077009a7ecd14309d08' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6443 processed earlier; will process 4586 files now Step #5: ==183028== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fdcb0219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fdd1686898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fdd16695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fdd16694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fdcb027d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fdcaf88b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fdcaf83355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fdcb019c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fdcdfe8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fdcdfe8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fdcdfe8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fdcdfe8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fdcdfe8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fdcdfe8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fdcdfe8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fdcdfe8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fdcdfe8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fdcdfe8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fdd027df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fdccfaab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fdccfb5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fdccd61c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fdccd61c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fdccd62738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fdccd61874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fdccd61874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fdccd61874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fdd166babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fdd1674928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fdd165c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fdd1687112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f29d5d53082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fdcaf81b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x3,0x76,0x6f,0x72,0x6d,0x75,0x49,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x44,0x33,0x3,0x76,0x6f,0x72,0x6d,0x75,0x49,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: ID3\003vormuI\000\000\000\000\000\000''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''\000\000\000\000\000\000\000\000\000\000\000\000''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''\000\000\000\000\000\000\000\000\000\000\000D3\003vormuI\000\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-03d3fbf908e236077412707a2ce87c5f00551bea Step #5: Base64: SUQzA3Zvcm11SQAAAAAAACcnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJwAAAAAAAAAAAAAAACcnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJwAAAAAAAAAAAAAARDMDdm9ybXVJAAAAAAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5083 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 9819696 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f893fb7810, 0x55f8941a101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f8941a1020,0x55f8960390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03d3fbf908e236077412707a2ce87c5f00551bea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6444 processed earlier; will process 4585 files now Step #5: ==183064== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f88aaac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f891111898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8910f45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8910f44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f88aab2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f88aa13b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f88aa0e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f88aaa4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f88da73f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f88da73f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f88da73f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f88da73f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f88da73f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f88da73f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f88da73f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f88da73f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f88da73f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f88da73f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f88fd08f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f88ca35b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f88ca40be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f88c7ecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f88c7ecc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f88c7ed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f88c7ec874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f88c7ec874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f88c7ec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f8910f6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f8910ff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f8910e7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f891112112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4918335082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f88aa0cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7d,0x73,0x67,0x74,0x43,0x6f,0x6e,0x74,0x65,0x6e,0x74,0x2d,0x54,0x79,0x70,0x65,0x3a,0x64,0x3b,0xd,0xe2,0x81,0x9f,0xc,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xc,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xc,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xc,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xc,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xd,0xe2,0x81,0x9f,0xe2,0x81,0x9f,0xe2,0x81,0xd,0xd,0x9f,0x81, Step #5: }sgtContent-Type:d;\015\342\201\237\014\015\342\201\237\342\201\237\342\201\237\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\014\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\014\015\342\201\237\342\201\237\342\201\237\342\201\237\342\201\237\015\342\201\237\342\201\237\342\201\237\015\342\201\237\014\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\342\201\237\015\342\201\237\014\015\342\201\237\342\201\237\342\201\237\342\201\237\342\201\237\015\342\201\237\342\201\237\342\201\237\342\201\237\342\201\237\015\342\201\237\342\201\237\342\201\015\015\237\201 Step #5: artifact_prefix='./'; Test unit written to ./oom-a0c7d8910fd53cd74186876895323da8892f097a Step #5: Base64: fXNndENvbnRlbnQtVHlwZTpkOw3igZ8MDeKBn+KBn+KBn+KBn+KBnw3igZ/igZ8N4oGf4oGfDeKBn+KBnw3igZ/igZ/igZ/igZ8N4oGf4oGfDeKBn+KBnw3igZ/igZ8N4oGf4oGfDeKBnwwN4oGf4oGfDeKBn+KBnw3igZ/igZ8N4oGf4oGfDeKBnwwN4oGf4oGf4oGf4oGf4oGfDeKBn+KBn+KBnw3igZ8MDeKBn+KBnw3igZ/igZ8N4oGf4oGfDeKBn+KBnw3igZ8MDeKBn+KBn+KBn+KBn+KBnw3igZ/igZ/igZ/igZ/igZ8N4oGf4oGf4oENDZ+B Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5084 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 10351389 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a15f35f810, 0x55a15f54901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a15f549020,0x55a1613e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a0c7d8910fd53cd74186876895323da8892f097a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6445 processed earlier; will process 4584 files now Step #5: ==183100== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a155e549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a15c4b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a15c49c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a15c49c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a155e5ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a155dbbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a155db6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a155e4cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a158e1bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a158e1bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a158e1bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a158e1bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a158e1bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a158e1bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a158e1bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a158e1bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a158e1bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a158e1bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a15b0b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a157dddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a157de8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a157b94c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a157b94c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a157b95738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a157b94874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a157b94874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a157b94874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a15c49eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a15c4a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a15c48f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a15c4ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f061d297082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a155db4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x42,0x6a,0x2d,0x24,0xcd,0x8f,0xe2,0x80,0x8e,0x42,0x22,0x22,0x22,0x22,0x3d,0x24,0x74,0x2d,0x21,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xa9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x2d,0xcb,0x91,0x2d,0x24,0xe0,0xb9,0x81,0x3d,0x24, Step #5: Bj-$\315\217\342\200\216B\"\"\"\"=$t-!-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\251\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\377\377\377\377\377\377\377\377\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=-\313\221-$\340\271\201=$ Step #5: artifact_prefix='./'; Test unit written to ./oom-94854f7a8cc84198436e65aa451be2bec24ec277 Step #5: Base64: QmotJM2P4oCOQiIiIiI9JHQtIS3LkS0k4LmBPS3LkS0k4LmBPS3LkS0k4LmBPS3LkS0k4LmBPS3LkS09LcuRLSTguYE9LcuRLSTguYE9LcuRLSTguYE9LcuRLSTgqYE9LcuRLSTguYE9LcuRLSTguYE9LcuRLSTguYE9LcuRLSTguYE9LcuRLSTguYE9LcuRLSTguYE9LcuRLSTguYE9LcuRLSTguf//////////gT0ty5EtJOC5gT0ty5EtJOC5gT0ty5EtJOC5gT0ty5EtJOC5gT0ty5EtJOC5gT0ty5EtJOC5gT0ty5EtJOC5gT0ty5EtJOC5gT0k Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5085 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 10901584 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56539ee45810, 0x56539f02f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56539f02f020,0x5653a0ec70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/94854f7a8cc84198436e65aa451be2bec24ec277' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6446 processed earlier; will process 4583 files now Step #5: ==183136== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56539593a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56539bf9f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56539bf825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56539bf824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565395940d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5653958a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56539589c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565395932c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565398901f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565398901f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565398901f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565398901f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565398901f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565398901f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565398901f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565398901f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565398901f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565398901f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56539ab96f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5653978c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5653978cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56539767ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56539767ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56539767b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56539767a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56539767a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56539767a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56539bf84abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56539bf8d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56539bf75699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56539bfa0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb8b236f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56539589ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x47,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x7f,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012G\012=\012=\012=\012=\012=\012=\012=\012\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177\177=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000ID3\002-\001\000\000\000\000ID3\002-\001\000\000\000\000ID3\002-\001\000\000\000\000ID3\002-\001\000\000\000\000ID3\002-\001=\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-f3d2ac75a5216d7bd3b0ba7f024bc7e0b5dbfea8 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQpHCj0KPQo9Cj0KPQo9Cj0Kf39/f39/f39/f39/f39/f39/f39/f39/f39/f39/fz0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoASUQzAi0BAAAAAElEMwItAQAAAABJRDMCLQEAAAAASUQzAi0BAAAAAElEMwItAT0KPQo9Cj0KPQo9Cj0KPQoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5086 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 11466487 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b441e05810, 0x55b441fef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b441fef020,0x55b443e870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f3d2ac75a5216d7bd3b0ba7f024bc7e0b5dbfea8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6447 processed earlier; will process 4582 files now Step #5: #1 pulse cov: 3952 ft: 3953 exec/s: 0 rss: 176Mb Step #5: ==183172== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b4388fa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b43ef5f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b43ef425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b43ef424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b438900d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b438861b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b43885c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b4388f2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b43b8c1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b43b8c1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b43b8c1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b43b8c1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b43b8c1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b43b8c1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b43b8c1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b43b8c1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b43b8c1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b43b8c1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b43db56f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b43a883b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b43a88ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b43a63ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b43a63ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b43a63b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b43a63a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b43a63a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b43a63a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b43ef44abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b43ef4d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b43ef35699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b43ef60112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f774af0e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b43885ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x70,0x69,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012pi=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-510205d4e75d87e5f49d5f22b048e909e1ee56a9 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQpwaT0KCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQAKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5087 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 12066458 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c16b493810, 0x55c16b67d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c16b67d020,0x55c16d5150e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/510205d4e75d87e5f49d5f22b048e909e1ee56a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6449 processed earlier; will process 4580 files now Step #5: ==183208== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c161f889c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c1685ed898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c1685d05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c1685d04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c161f8ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c161eefb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c161eea355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c161f80c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c164f4ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c164f4ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c164f4ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c164f4ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c164f4ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c164f4ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c164f4ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c164f4ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c164f4ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c164f4ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c1671e4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c163f11b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c163f1cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c163cc8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c163cc8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c163cc9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c163cc8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c163cc8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c163cc8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c1685d2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c1685db928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c1685c3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c1685ee112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdbbe3d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c161ee8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x60,0x60,0x3a,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x66,0x0,0x0,0x60,0x60,0x3a,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x60,0x66,0x0,0x0,0x60,0x60,0x60,0x60,0x60,0x60,0x0,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x60,0x0,0x60,0x60,0x60,0x2d,0x60,0x60,0x60,0x60,0x60,0x60,0x2d,0x60,0x60,0x60,0x60,0x60,0x0,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x60,0x0,0x60,0x2d,0x7b,0x7d,0x2f,0x60,0x60,0x60,0x60,0x60,0x60,0x2d,0x60,0x60,0x60,0x0,0x60,0x60,0x60,0x2d,0x60,0x60,0x60,0x60,0x60,0x60,0x2d,0x60,0x60,0x60,0x60,0x60,0x0,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x60,0x0,0x60,0x2d,0x7b,0x7d,0x2f,0x60,0x60,0x60,0x60,0x60,0x60,0xff,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x60,0x0,0x60,0x60,0x60,0x2d,0x60,0x60,0x60,0x60,0x60,0x60,0x2d,0x60,0x60,0x60,0x60,0x60,0x0,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x60,0x0,0x60,0x2d,0x7b,0x7d,0x2f,0x60,0x60,0x60,0x60,0x60,0x60,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x2f,0x32,0x32,0x33,0x33,0x60,0x37,0x2d,0xff,0x32,0x60,0x60,0x2d,0x60,0x60,0x60,0x0,0x60,0x60,0x60,0x2d,0x60,0x60,0x60,0x60,0x60,0x60,0x2d,0x60,0x60,0x60,0x60,0x60,0x0,0x60,0x2d,0x60,0x60,0x2d,0x60,0x60,0x32,0x32,0x33,0x33,0x37,0x32,0x30,0x3e,0x30,0x36,0x3b,0x21,0x38,0x3b,0x3b,0x72,0xa5,0xa5,0x70,0x2d,0x31,0xa5,0xa5,0xa5, Step #5: ```:````````f\000\000``:````````f\000\000``````\000`-``-``-```\000```-``````-`````\000`-``-```\000`-{}/``````-```\000```-``````-`````\000`-``-```\000`-{}/``````\377`-``-```\000```-``````-`````\000`-``-```\000`-{}/``````\377\377\377\377\377\377\377\377\377\377/2233`7-\3772``-```\000```-``````-`````\000`-``-``2233720>06;!8;;r\245\245p-1\245\245\245 Step #5: artifact_prefix='./'; Test unit written to ./oom-081e72bbfdf190d9d3c4febed3316f79db0f1086 Step #5: Base64: YGBgOmBgYGBgYGBgZgAAYGA6YGBgYGBgYGBmAABgYGBgYGAAYC1gYC1gYC1gYGAAYGBgLWBgYGBgYC1gYGBgYABgLWBgLWBgYABgLXt9L2BgYGBgYC1gYGAAYGBgLWBgYGBgYC1gYGBgYABgLWBgLWBgYABgLXt9L2BgYGBgYP9gLWBgLWBgYABgYGAtYGBgYGBgLWBgYGBgAGAtYGAtYGBgAGAte30vYGBgYGBg/////////////y8yMjMzYDct/zJgYC1gYGAAYGBgLWBgYGBgYC1gYGBgYABgLWBgLWBgMjIzMzcyMD4wNjshODs7cqWlcC0xpaWl Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5088 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 14199890 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c99ef7c810, 0x55c99f16601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c99f166020,0x55c9a0ffe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/081e72bbfdf190d9d3c4febed3316f79db0f1086' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6450 processed earlier; will process 4579 files now Step #5: ==183244== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c995a719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c99c0d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c99c0b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c99c0b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c995a77d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9959d8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c9959d3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c995a69c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c998a38f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c998a38f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c998a38f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c998a38f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c998a38f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c998a38f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c998a38f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c998a38f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c998a38f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c998a38f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c99accdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9979fab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c997a05be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c9977b1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c9977b1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c9977b2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c9977b1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c9977b1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c9977b1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c99c0bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c99c0c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c99c0ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c99c0d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f50b507d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c9959d1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x78,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x3d,0x1d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x31,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x24,0x43,0x47,0x0,0x0,0x0,0x0,0x0,0x47,0x42,0x2d,0x0,0x45,0x49,0x4e,0x20,0x30,0x2d,0x2d,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x1d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24,0x24,0x43,0x47,0x0,0x0,0x0,0x0,0x0,0x47,0x42,0x2d,0x0,0x45,0x49,0x4e,0x20,0x30,0x2d,0x2d,0x2d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x49,0x44,0x33,0x2,0x2d,0x1,0x0,0x0,0x0,0x0,0x49,0x44,0x33,0x2,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2d,0x2d,0x2d,0x2d,0x61,0x6c,0x70,0x68,0x61,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: x------BEGIN -----\012=\035\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0001\000\000\000\000\000\000\000$$CG\000\000\000\000\000GB-\000EIN 0---\012=\012=\012\035\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000ID3\002-\001\000\000\000\000ID3\002---END\000\000\000\000\000\000\000\000\000\000\000\000\000\000$$CG\000\000\000\000\000GB-\000EIN 0---\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000ID3\002-\001\000\000\000\000ID3\002---END\000\000\000\000\000\000\000\000\000----alpha------------------- Step #5: artifact_prefix='./'; Test unit written to ./oom-497ecb8f77a8313a8955fd51621893964fde3074 Step #5: Base64: eC0tLS0tLUJFR0lOIC0tLS0tCj0dAAAAAAAAAAAAAAAAAAAAMQAAAAAAAAAkJENHAAAAAABHQi0ARUlOIDAtLS0KPQo9Ch0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9CgBJRDMCLQEAAAAASUQzAi0tLUVORAAAAAAAAAAAAAAAAAAAJCRDRwAAAAAAR0ItAEVJTiAwLS0tCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoASUQzAi0BAAAAAElEMwItLS1FTkQAAAAAAAAAAAAtLS0tYWxwaGEtLS0tLS0tLS0tLS0tLS0tLS0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5089 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 14745037 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb3391a810, 0x55eb33b0401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb33b04020,0x55eb3599c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/497ecb8f77a8313a8955fd51621893964fde3074' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6451 processed earlier; will process 4578 files now Step #5: ==183280== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eb2a40f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb30a74898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb30a575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb30a574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb2a415d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb2a376b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb2a371355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb2a407c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb2d3d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb2d3d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb2d3d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb2d3d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb2d3d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb2d3d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb2d3d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb2d3d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb2d3d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb2d3d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb2f66bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb2c398b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb2c3a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb2c14fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb2c14fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb2c150738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb2c14f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb2c14f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb2c14f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb30a59abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb30a62928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb30a4a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb30a75112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc4fde3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb2a36fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x71,0x42,0x77,0x50,0x34,0x57,0x70,0x50,0x34,0x66,0x44,0x62,0x6a,0x4d,0x5a,0x50,0x54,0x34,0x39,0x67,0x66,0x69,0x32,0x54,0x52,0x4f,0x4f,0x35,0x59,0x78,0x32,0x4a,0x76,0x38,0x74,0x2f,0x59,0x2b,0x46,0x53,0x77,0x33,0x34,0xa,0x69,0x64,0x20,0x65,0x64,0x32,0x35,0x35,0x31,0x39,0x20,0x5a,0x31,0x61,0x30,0x47,0x75,0x37,0x4c,0x64,0x77,0x79,0x79,0x6c,0x67,0x48,0x77,0x32,0x33,0x4f,0x55,0x50,0x76,0x38,0x74,0x2f,0x59,0x4f,0x4f,0x35,0x59,0x78,0x32,0x4a,0x76,0x38,0x74,0x2f,0x59,0x2b,0x46,0x4a,0x69,0x64,0x73,0xa,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x6e,0x74,0x6f,0x72,0x2d,0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0x20,0x71,0x42,0x77,0x50,0x38,0x57,0x70,0x34,0x66,0x50,0x44,0x62,0x6a,0x4d,0x5a,0x50,0x54,0x34,0x39,0x67,0x66,0x69,0x30,0x54,0x4d,0x4f,0x4f,0x35,0x59,0x78,0x32,0x4a,0x76,0x38,0x74,0x2f,0x59,0x2b,0x46,0x53,0x77,0x33,0x34,0xa,0x69,0x64,0x20,0x65,0x64,0x32,0x35,0x35,0x31,0x39,0x20,0x5a,0x31,0x61,0x30,0x47,0x75,0x37,0x4c,0x64,0x34,0x66,0x50,0x44,0x62,0x6a,0x4d,0x5a,0x50,0x54,0x34,0x39,0x69,0x67,0x66,0x32,0x54,0x52,0x4f,0x4f,0x35,0x59,0x53,0x32,0x4a,0x76,0x38,0x64,0x2f,0x59,0x2b,0x4e,0x62,0x7a,0x30, Step #5: onion-key\012ntor-onion-key qBwP4WpP4fDbjMZPT49gfi2TROO5Yx2Jv8t/Y+FSw34\012id ed25519 Z1a0Gu7LdwyylgHw23OUPv8t/YOO5Yx2Jv8t/Y+FJids\012onion-key\012ntor-onion-key qBwP8Wp4fPDbjMZPT49gfi0TMOO5Yx2Jv8t/Y+FSw34\012id ed25519 Z1a0Gu7Ld4fPDbjMZPT49igf2TROO5YS2Jv8d/Y+Nbz0 Step #5: artifact_prefix='./'; Test unit written to ./oom-6eac0b8aa99069269de6e1970f7098cfb252e322 Step #5: Base64: b25pb24ta2V5Cm50b3Itb25pb24ta2V5IHFCd1A0V3BQNGZEYmpNWlBUNDlnZmkyVFJPTzVZeDJKdjh0L1krRlN3MzQKaWQgZWQyNTUxOSBaMWEwR3U3TGR3eXlsZ0h3MjNPVVB2OHQvWU9PNVl4Mkp2OHQvWStGSmlkcwpvbmlvbi1rZXkKbnRvci1vbmlvbi1rZXkgcUJ3UDhXcDRmUERiak1aUFQ0OWdmaTBUTU9PNVl4Mkp2OHQvWStGU3czNAppZCBlZDI1NTE5IFoxYTBHdTdMZDRmUERiak1aUFQ0OWlnZjJUUk9PNVlTMkp2OGQvWStOYnow Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5090 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 15274396 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556529c3a810, 0x556529e2401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556529e24020,0x55652bcbc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6eac0b8aa99069269de6e1970f7098cfb252e322' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6452 processed earlier; will process 4577 files now Step #5: ==183316== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55652072f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556526d94898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556526d775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556526d774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556520735d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556520696b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556520691355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556520727c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5565236f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5565236f6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5565236f6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5565236f6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5565236f6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5565236f6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5565236f6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5565236f6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5565236f6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5565236f6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55652598bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5565226b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5565226c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55652246fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55652246fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556522470738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55652246f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55652246f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55652246f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556526d79abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556526d82928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556526d6a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556526d95112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faaff755082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55652068fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x2f,0x20,0x47,0x0,0x0,0x0,0x3d,0x3e,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x0,0x0,0x0,0x35,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x0,0x0,0x0,0x2d,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x0,0x1,0x1,0x1,0x0,0x0,0x47,0x53,0x55,0x42,0x0,0x20,0x0,0x0,0x1,0x1,0x1,0x1,0x1,0x0,0x1,0xd7,0xa3,0x0,0x73,0x20,0x34,0x20,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x0,0x0,0x0,0x20,0x0,0x0,0x1,0x1,0x1,0x1,0x1,0x0,0x1,0xd7,0xa3,0x0,0x73,0x20,0x34,0x20,0x28,0x20,0x3a,0x2b, Step #5: / G\000\000\000=>\000\000\000\000\000\000\000\000\000yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy\000\000\0005yyyyyyyyyyy\000\000\000-yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy\000\001\001\001\000\000GSUB\000 \000\000\001\001\001\001\001\000\001\327\243\000s 4 yyyyyyyyyyyyyyyyyyyyyyyyyyyyyy\000\000\000 \000\000\001\001\001\001\001\000\001\327\243\000s 4 ( :+ Step #5: artifact_prefix='./'; Test unit written to ./oom-f87255fd4bd2bb80afc0c524968c77a467cf82f2 Step #5: Base64: LyBHAAAAPT4AAAAAAAAAAAB5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5AAAANXl5eXl5eXl5eXl5AAAALXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXkAAQEBAABHU1VCACAAAAEBAQEBAAHXowBzIDQgeXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5AAAAIAAAAQEBAQEAAdejAHMgNCAoIDor Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5091 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 15807262 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa702a9810, 0x55aa7049301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa70493020,0x55aa7232b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f87255fd4bd2bb80afc0c524968c77a467cf82f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6453 processed earlier; will process 4576 files now Step #5: ==183352== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aa66d9e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa6d403898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa6d3e65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa6d3e64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa66da4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa66d05b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa66d00355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa66d96c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa69d65f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa69d65f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa69d65f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa69d65f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa69d65f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa69d65f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa69d65f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa69d65f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa69d65f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa69d65f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa6bffaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa68d27b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa68d32be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa68adec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa68adec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa68adf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa68ade874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa68ade874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa68ade874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa6d3e8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa6d3f1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa6d3d9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa6d404112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f8b20f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa66cfeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x4,0x32,0x31,0x34,0x37,0x34,0x38,0x33,0x36,0x35,0x30,0x3,0x0,0x0,0x45,0x30,0x50,0x73,0xa,0x20,0x20,0x2f,0x46,0x20,0x7f,0x73,0x65,0x64,0x20,0x35,0x20,0x71,0x70,0x78,0x60,0x74,0x7f,0x0,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x6c,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x0,0x0,0x0,0x0,0x7d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5b,0x0,0x0,0x0,0x0,0x0,0x0,0x7e,0x2d,0x0,0x7d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0xa,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5b,0x0,0x0,0x0,0x0,0x0,0x0,0x7e,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x5b,0x47,0x49,0x4e,0x20,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x63,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x2d,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x73,0x6d,0x21,0x60,0x31,0x50,0x55,0x53,0x4c,0x32,0x54,0x0,0x0,0x0,0x5,0x20,0x0,0x0,0x20,0x47,0xc7,0x50,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x1e, Step #5: I\0042147483650\003\000\000E0Ps\012 /F \177sed 5 qpx`t\177\000sssssssssssssssssslssssssss\000\000\000\000}\000\000\000\000\000\000\000\001\000\000\000\012\000\000\000\000\000\000\000[\000\000\000\000\000\000~-\000}\000\000\000\000\000\000\000\001\000\000\000\012\000\000\000\000\000\000\000[\000\000\000\000\000\000~-----B[GIN ssssssssssssssssssssssssssssssssscsssssssssss-sssssssssssssssssssssssssssssssssssm!`1PUSL2T\000\000\000\005 \000\000 G\307P\377\377\377\377\377\377\377\036 Step #5: artifact_prefix='./'; Test unit written to ./oom-357718bc7daeeaeab3bdfa94627a3a8e6624c6e0 Step #5: Base64: SQQyMTQ3NDgzNjUwAwAARTBQcwogIC9GIH9zZWQgNSBxcHhgdH8Ac3Nzc3Nzc3Nzc3Nzc3Nzc3NzbHNzc3Nzc3NzAAAAAH0AAAAAAAAAAQAAAAoAAAAAAAAAWwAAAAAAAH4tAH0AAAAAAAAAAQAAAAoAAAAAAAAAWwAAAAAAAH4tLS0tLUJbR0lOIHNzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc2Nzc3Nzc3Nzc3Nzcy1zc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc20hYDFQVVNMMlQAAAAFIAAAIEfHUP////////8e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5092 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 16463173 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561f84743810, 0x561f8492d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561f8492d020,0x561f867c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/357718bc7daeeaeab3bdfa94627a3a8e6624c6e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6454 processed earlier; will process 4575 files now Step #5: ==183388== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561f7b2389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561f8189d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561f818805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561f818804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561f7b23ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561f7b19fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561f7b19a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561f7b230c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561f7e1fff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561f7e1fff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561f7e1fff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561f7e1fff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561f7e1fff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561f7e1fff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561f7e1fff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561f7e1fff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561f7e1fff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561f7e1fff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561f80494f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561f7d1c1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561f7d1ccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561f7cf78c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561f7cf78c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561f7cf79738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561f7cf78874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561f7cf78874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561f7cf78874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561f81882abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561f8188b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561f81873699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561f8189e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7ffed15082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561f7b198b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x74,0x65,0x73,0x74,0x41,0x6c,0x6c,0x54,0x79,0x70,0x65,0x73,0x22,0x3a,0x7b,0x22,0x72,0x65,0x70,0x65,0x61,0x74,0x65,0x64,0x44,0x6f,0x75,0x62,0x6c,0x65,0x22,0x3a,0x5b,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x31,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x33,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x36,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x33,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x36,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x32,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x33,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x36,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x32,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x31,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x36,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x32,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x36,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x32,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x32,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x32,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x33,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x36,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x32,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0x30,0xe2,0x80,0x8c,0x22,0x2c,0x22,0xe2,0x80,0x8c,0x22, Step #5: {\"testAllTypes\":{\"repeatedDouble\":[\"0\342\200\214\",\"1\342\200\214\",\"0\342\200\214\",\"3\342\200\214\",\"0\342\200\214\",\"6\342\200\214\",\"3\342\200\214\",\"6\342\200\214\",\"2\342\200\214\",\"3\342\200\214\",\"6\342\200\214\",\"2\342\200\214\",\"0\342\200\214\",\"0\342\200\214\",\"0\342\200\214\",\"0\342\200\214\",\"0\342\200\214\",\"1\342\200\214\",\"6\342\200\214\",\"2\342\200\214\",\"6\342\200\214\",\"0\342\200\214\",\"2\342\200\214\",\"2\342\200\214\",\"2\342\200\214\",\"3\342\200\214\",\"6\342\200\214\",\"2\342\200\214\",\"0\342\200\214\",\"0\342\200\214\",\"\342\200\214\" Step #5: artifact_prefix='./'; Test unit written to ./oom-4845ae16fc2d8e70abbc9494a3fb510f55151236 Step #5: Base64: eyJ0ZXN0QWxsVHlwZXMiOnsicmVwZWF0ZWREb3VibGUiOlsiMOKAjCIsIjHigIwiLCIw4oCMIiwiM+KAjCIsIjDigIwiLCI24oCMIiwiM+KAjCIsIjbigIwiLCIy4oCMIiwiM+KAjCIsIjbigIwiLCIy4oCMIiwiMOKAjCIsIjDigIwiLCIw4oCMIiwiMOKAjCIsIjDigIwiLCIx4oCMIiwiNuKAjCIsIjLigIwiLCI24oCMIiwiMOKAjCIsIjLigIwiLCIy4oCMIiwiMuKAjCIsIjPigIwiLCI24oCMIiwiMuKAjCIsIjDigIwiLCIw4oCMIiwi4oCMIg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5093 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 17003742 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e43146b810, 0x55e43165501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e431655020,0x55e4334ed0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4845ae16fc2d8e70abbc9494a3fb510f55151236' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6455 processed earlier; will process 4574 files now Step #5: #1 pulse cov: 4002 ft: 4003 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4447 ft: 4993 exec/s: 0 rss: 180Mb Step #5: ==183424== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e427f609c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e42e5c5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e42e5a85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e42e5a84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e427f66d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e427ec7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e427ec2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e427f58c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e42af27f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e42af27f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e42af27f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e42af27f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e42af27f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e42af27f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e42af27f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e42af27f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e42af27f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e42af27f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e42d1bcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e429ee9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e429ef4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e429ca0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e429ca0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e429ca1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e429ca0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e429ca0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e429ca0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e42e5aaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e42e5b3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e42e59b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e42e5c6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f55535ef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e427ec0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x60,0x20,0x20,0x7d,0x78,0x58,0x67,0x58,0x58,0x0,0x6f,0x6c,0x77,0x5f,0x5f,0x5f,0x5f,0x5b,0x5f,0x5f,0x5f,0x5f,0x5f,0x31,0x34,0x78,0x67,0x60,0x2d,0x60,0x3b,0x72,0x65,0x65,0x65,0x7d,0x9,0x9,0x9,0x9,0x9,0x9,0x69,0x7b,0x7d,0x78,0x78,0x78,0x32,0x41,0x42,0x62,0x62,0x3b,0x77,0x3b,0x7b,0x5a,0x0,0x0,0x0,0x7e,0x0,0x11,0x77,0x3b,0xd,0x0,0x3f,0x5b,0x3a,0xf3,0xa0,0x81,0xb3,0x60,0x5b,0x31,0x2d,0x33,0x5d,0x2b,0x60,0x24,0x0,0x67,0x60,0x2d,0x60,0x3b,0x72,0x65,0x65,0x65,0x7d,0x9,0x9,0x9,0x9,0x9,0x9,0x69,0x7b,0x7d,0x78,0x78,0x78,0x32,0x41,0x42,0x62,0x62,0x3b,0x77,0x3b,0x7b,0x5a,0x0,0x0,0x0,0x7e,0x0,0x11,0x77,0x3b,0xd,0x0,0x3f,0x5b,0x3a,0xf3,0xa0,0x81,0xb3,0x60,0x5b,0x31,0x2d,0x33,0x5d,0xff,0xff,0xff,0x4f,0x2b,0x1,0x7,0x84,0xc9,0x60,0x24,0x0,0x0,0x0,0x1b,0x0,0x0,0x5a,0x63,0x5f,0x4f,0x5f,0x62,0x3b,0x77,0x3b,0x3b,0x5a,0x0,0x0,0x0,0x7e,0x0,0x11,0x77,0x3b,0xd,0x0,0x2,0x0,0x9c,0x6c,0x6f,0x79,0x0,0x5c,0x7e,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x79,0x0,0x0,0x0,0x0,0x0,0xfa,0xff,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x2e,0x3b,0x63,0x62,0x2e,0x3b,0x63,0x62,0x94,0x8e, Step #5: ` }xXgXX\000olw____[_____14xg`-`;reee}\011\011\011\011\011\011i{}xxx2ABbb;w;{Z\000\000\000~\000\021w;\015\000?[:\363\240\201\263`[1-3]+`$\000g`-`;reee}\011\011\011\011\011\011i{}xxx2ABbb;w;{Z\000\000\000~\000\021w;\015\000?[:\363\240\201\263`[1-3]\377\377\377O+\001\007\204\311`$\000\000\000\033\000\000Zc_O_b;w;;Z\000\000\000~\000\021w;\015\000\002\000\234loy\000\\~yyyyyyyyyyyyyyyyyyyyyyyyyyyyy\000\000\000\000\000\372\377\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000'.;cb.;cb\224\216 Step #5: artifact_prefix='./'; Test unit written to ./oom-13cf5dea475e6664e733777feada471a9ea624ab Step #5: Base64: YCAgfXhYZ1hYAG9sd19fX19bX19fX18xNHhnYC1gO3JlZWV9CQkJCQkJaXt9eHh4MkFCYmI7dzt7WgAAAH4AEXc7DQA/WzrzoIGzYFsxLTNdK2AkAGdgLWA7cmVlZX0JCQkJCQlpe314eHgyQUJiYjt3O3taAAAAfgARdzsNAD9bOvOggbNgWzEtM13///9PKwEHhMlgJAAAABsAAFpjX09fYjt3OztaAAAAfgARdzsNAAIAnGxveQBcfnl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5AAAAAAD6/wAAAAAAAAAAAAAAAAAAAAAnLjtjYi47Y2KUjg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5094 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 17777048 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f1517f4810, 0x55f1519de01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f1519de020,0x55f1538760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/13cf5dea475e6664e733777feada471a9ea624ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6459 processed earlier; will process 4570 files now Step #5: #1 pulse cov: 3824 ft: 3825 exec/s: 0 rss: 178Mb Step #5: ==183460== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f1482e99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f14e94e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f14e9315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f14e9314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f1482efd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f148250b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f14824b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f1482e1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f14b2b0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f14b2b0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f14b2b0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f14b2b0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f14b2b0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f14b2b0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f14b2b0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f14b2b0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f14b2b0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f14b2b0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f14d545f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f14a272b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f14a27dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f14a029c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f14a029c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f14a02a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f14a029874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f14a029874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f14a029874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f14e933abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f14e93c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f14e924699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f14e94f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f374a9aa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f148249b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x28,0x2e,0x2d,0x24,0x7c,0x2e,0x3f,0x29,0x7b,0x39,0x38,0x39,0x7d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x27,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x24, Step #5: ^(.-$|.?){989}\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000'\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000'\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000$ Step #5: artifact_prefix='./'; Test unit written to ./oom-fc6769f8e5941cd99eb7f777dae329aa317f1f2c Step #5: Base64: XiguLSR8Lj8pezk4OX0AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAnAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5095 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 18355140 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5584ca300810, 0x5584ca4ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5584ca4ea020,0x5584cc3820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc6769f8e5941cd99eb7f777dae329aa317f1f2c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6461 processed earlier; will process 4568 files now Step #5: ==183496== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5584c0df59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5584c745a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5584c743d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5584c743d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5584c0dfbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5584c0d5cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5584c0d57355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5584c0dedc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5584c3dbcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5584c3dbcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5584c3dbcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5584c3dbcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5584c3dbcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5584c3dbcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5584c3dbcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5584c3dbcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5584c3dbcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5584c3dbcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5584c6051f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5584c2d7eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5584c2d89be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5584c2b35c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5584c2b35c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5584c2b36738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5584c2b35874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5584c2b35874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5584c2b35874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5584c743fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5584c7448928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5584c7430699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5584c745b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f49abc0c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5584c0d55b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x64,0xc9,0xa1,0xcd,0x84,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x78,0x32,0x6c,0x62,0x6b,0x3e,0x3c,0xa,0x20,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0, Step #5: d\311\241\315\204xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx2lbk><\012 \000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0b3ed401a7fe90481a0fcdba377bce6c459e0682 Step #5: Base64: ZMmhzYR4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eDJsYms+PAogAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5096 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 18883870 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557db5d5f810, 0x557db5f4901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557db5f49020,0x557db7de10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b3ed401a7fe90481a0fcdba377bce6c459e0682' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6462 processed earlier; will process 4567 files now Step #5: #1 pulse cov: 11837 ft: 11838 exec/s: 0 rss: 196Mb Step #5: ==183532== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557dac8549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557db2eb9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557db2e9c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557db2e9c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557dac85ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557dac7bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557dac7b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557dac84cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557daf81bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557daf81bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557daf81bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557daf81bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557daf81bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557daf81bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557daf81bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557daf81bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557daf81bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557daf81bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557db1ab0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557dae7ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557dae7e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557dae594c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557dae594c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557dae595738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557dae594874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557dae594874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557dae594874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557db2e9eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557db2ea7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557db2e8f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557db2eba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1da200e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557dac7b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x61,0x3e,0x3c,0x52,0x64,0x3e,0x3c,0x44,0x68,0x64,0x3e,0x3c,0x55,0x67,0x3e,0x3c,0x61,0x44,0x3e,0x3c,0x45,0x41,0x3e,0x3c,0x52,0x3e,0x3c,0x65,0x57,0x66,0x3e,0x3c,0x72,0x3e,0x3c,0x65,0x57,0x3e,0x3c,0x46,0x3e,0x3c,0x49,0x41,0x3e,0x3c,0x49,0x46,0x6e,0x74,0x3e,0x3c,0x6f,0x3e,0x3c,0x62,0x43,0x3e,0x3c,0x42,0x67,0x3e,0x3c,0x7a,0x30,0x3e,0x3a,0x3c,0x4f,0x3e,0x3c,0x6d,0x3e,0x3c,0x52,0x55,0x54,0x3e,0x46,0x3c,0x65,0x64,0x3e,0x3c,0x64,0x3e,0x6f,0x3c,0x4b,0x3e,0x3c,0x71,0x3e,0x3c,0x65,0x73,0x6e,0x3e,0x3c,0x49,0x3e,0x3c,0x57,0x3e,0x3c,0x54,0x64,0x3e,0x3c,0x75,0x6b,0x3e,0x3c,0x7a,0x3e,0x3c,0x65,0x3e,0x3c,0x53,0x3e,0x3c,0x74,0x67,0x3e,0x3c,0x6e,0x64,0x3e,0x3c,0x50,0x2e,0x3e,0x3c,0x50,0x55,0x3e,0x3c,0x66,0x3e,0x3c,0x49,0x51,0x3e,0x3c,0x61,0x65,0x49,0x3e,0x3c,0x4e,0x44,0x3e,0x3c,0x5f,0x57,0x57,0x3e,0x3c,0x6c,0x3e,0x3c,0x54,0x3e,0x3c,0x4c,0x3e,0x3c,0x57,0x52,0x3e,0x3c,0x41,0x50,0x3e,0x3c,0x67,0x3e,0x3c,0x67,0x61,0x49,0x3e,0x3c,0x50,0x57,0x3e,0x3c,0x50,0x3e,0x3c,0x57,0x65,0x3e,0x3c,0x56,0x3e,0x3c,0x4e,0x50,0x3e,0x3c,0x53,0x59,0x53,0x3e,0x3c,0x50,0x50,0x3e,0x3c,0x5f,0x3e,0x3e,0x3c,0x6e,0x3e,0x3c,0x69,0x35,0x54,0x3e,0x3c,0x69,0x50,0x41,0x3e,0x3c,0x54,0x6c,0x65,0x3e,0x3c,0x46,0x44,0x61,0x3e,0x3c,0x41,0x41,0x31,0x3e,0x3c,0x41,0x3e,0x3c,0x44,0x3e,0x41,0x3e, Step #5: <a><Rd><Dhd><Ug><aD><EA><R><eWf><r><eW><F><IA><IFnt><o><bC><Bg><z0>:<O><m><RUT>F<ed><d>o<K><q><esn><I><W><Td><uk><z><e><S><tg><nd><P.><PU><f><IQ><aeI><ND><_WW><l><T><L><WR><AP><g><gaI><PW><P><We><V><NP><SYS><PP><_>><n><i5T><iPA><Tle><FDa><AA1><A><D>A> Step #5: artifact_prefix='./'; Test unit written to ./oom-13a422912b378e0d8ab18d9805cdbd750c9f8037 Step #5: Base64: PGE+PFJkPjxEaGQ+PFVnPjxhRD48RUE+PFI+PGVXZj48cj48ZVc+PEY+PElBPjxJRm50PjxvPjxiQz48Qmc+PHowPjo8Tz48bT48UlVUPkY8ZWQ+PGQ+bzxLPjxxPjxlc24+PEk+PFc+PFRkPjx1az48ej48ZT48Uz48dGc+PG5kPjxQLj48UFU+PGY+PElRPjxhZUk+PE5EPjxfV1c+PGw+PFQ+PEw+PFdSPjxBUD48Zz48Z2FJPjxQVz48UD48V2U+PFY+PE5QPjxTWVM+PFBQPjxfPj48bj48aTVUPjxpUEE+PFRsZT48RkRhPjxBQTE+PEE+PEQ+QT4= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5097 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 19479839 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564b33881810, 0x564b33a6b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564b33a6b020,0x564b359030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/13a422912b378e0d8ab18d9805cdbd750c9f8037' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6464 processed earlier; will process 4565 files now Step #5: ==183568== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564b2a3769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564b309db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564b309be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564b309be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564b2a37cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564b2a2ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564b2a2d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564b2a36ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564b2d33df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564b2d33df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564b2d33df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564b2d33df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564b2d33df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564b2d33df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564b2d33df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564b2d33df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564b2d33df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564b2d33df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564b2f5d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564b2c2ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564b2c30abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564b2c0b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564b2c0b6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564b2c0b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564b2c0b6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564b2c0b6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564b2c0b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564b309c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564b309c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564b309b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564b309dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f153e285082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564b2a2d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x26,0x2b,0x24,0x2b,0x5e,0x2b,0x5e,0x2b,0x20,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x24,0x2b,0x25,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x5e,0x2b,0x20,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x5e,0x2b,0x4,0x2b,0x24,0x2b,0x24,0x14,0x2b,0x5e,0x2b,0x25,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x5e,0x2b,0x2b,0x24,0x2b,0x5f,0x2b,0x5e,0x2b,0x24,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x21,0x2b,0x5e,0x2b,0x5e,0x2b,0x24,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x5e,0x2b,0x20,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x24,0x2b,0x24,0x2b,0x25,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x5e,0x2b,0x20,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x5e,0x1,0x0,0x0,0x21,0x2b,0x4,0x2b,0x24,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x5e,0x2b,0x24,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x21,0x2b,0x5e,0x2b,0x5e,0x2b,0x41,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x24,0x2b,0x5e,0x2b,0x24,0x2b,0x2b, Step #5: &+$+^+^+ +$+^+$$+%+^+$+^+^+$+^+^+ +$+^+$+$+^+$+$+^+$+^+^+\004+$+$\024+^+%+$+^+$+$+^+$+^+^++$+_+^+$+$+^+$+^+!+^+^+$+$+^+$+^+$+$+^+$+^+$+^+^+$+^+^+ +$+^+$+$+$+%+^+$+^+^+$+^+\377\377\377\377\377\377\377\377^+ +$+^+$+$+^+$+$+^+$+^+^\001\000\000!+\004+$+$+^+$+^+^+$+$+^+$+^+!+^+^+A+$+^+$+^+$+$+^+$++ Step #5: artifact_prefix='./'; Test unit written to ./oom-fbf803f756d53ca6c0a7c6219c88d91a9feafb9e Step #5: Base64: JiskK14rXisgKyQrXiskJCslK14rJCteK14rJCteK14rICskK14rJCskK14rJCskK14rJCteK14rBCskKyQUK14rJSskK14rJCskK14rJCteK14rKyQrXyteKyQrJCteKyQrXishK14rXiskKyQrXiskK14rJCskK14rJCteKyQrXiteKyQrXiteKyArJCteKyQrJCskKyUrXiskK14rXiskK14r//////////9eKyArJCteKyQrJCteKyQrJCteKyQrXiteAQAAISsEKyQrJCteKyQrXiteKyQrJCteKyQrXishK14rXitBKyQrXiskK14rJCskK14rJCsr Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5098 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 20019566 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cdbeb05810, 0x55cdbecef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cdbecef020,0x55cdc0b870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fbf803f756d53ca6c0a7c6219c88d91a9feafb9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6465 processed earlier; will process 4564 files now Step #5: ==183604== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cdb55fa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cdbbc5f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cdbbc425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cdbbc424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cdb5600d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cdb5561b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cdb555c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cdb55f2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cdb85c1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cdb85c1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cdb85c1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cdb85c1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cdb85c1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cdb85c1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cdb85c1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cdb85c1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cdb85c1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cdb85c1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cdba856f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cdb7583b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cdb758ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cdb733ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cdb733ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cdb733b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cdb733a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cdb733a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cdb733a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cdbbc44abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cdbbc4d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cdbbc35699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cdbbc60112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f17aa0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cdb555ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xed,0x8f,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa5,0xed,0x95,0xa5,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa2,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa2,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa5,0xed,0x95,0xa5,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa2,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa5,0xed,0x95,0xa5,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa2,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9f,0xa2,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa5,0xed,0x95,0xa5,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa2,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa2,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa5,0xed,0x95,0xa5,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9d,0xa2,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa5,0xed,0x95,0xa5,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa5,0xed,0x95,0xa5,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa2,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa2,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa5,0xed,0x95,0xa5,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa5,0xed,0x0,0x0,0x0,0xe0,0x8f,0xa5,0xed,0x9e,0xa5,0x9e,0xa2,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xa5,0xed,0x8f,0xa5,0xed,0x9e,0xf1,0xbf,0xbf,0x80,0xc2,0xbd,0xec,0xed,0x9e,0xa5,0xed,0x9e,0xa5, Step #5: \355\217\245\355\217\245\355\236\245\355\225\245\355\236\245\355\217\245\355\236\242\355\236\245\355\217\245\355\236\245\355\217\245\355\236\242\355\236\245\355\217\245\355\236\245\355\225\245\355\236\245\355\217\245\355\236\242\355\236\245\355\217\245\355\236\245\355\225\245\355\236\245\355\217\245\355\236\242\355\236\245\355\217\245\355\236\245\355\217\245\355\237\242\355\236\245\355\217\245\355\236\245\355\225\245\355\236\245\355\217\245\355\236\242\355\236\245\355\217\245\355\236\242\355\236\245\355\217\245\355\236\245\355\225\245\355\236\245\355\217\245\355\235\242\355\236\245\355\217\245\355\236\245\355\225\245\355\236\245\355\217\245\355\236\245\355\225\245\355\236\245\355\217\245\355\236\242\355\236\245\355\217\245\355\236\245\355\217\245\355\236\242\355\236\245\355\217\245\355\236\245\355\225\245\355\236\245\355\217\245\355\236\245\355\000\000\000\340\217\245\355\236\245\236\242\355\236\245\355\217\245\355\236\245\355\217\245\355\236\361\277\277\200\302\275\354\355\236\245\355\236\245 Step #5: artifact_prefix='./'; Test unit written to ./oom-c9d2508315ba01d1baf70e2fb09ecc7bd13b2cf3 Step #5: Base64: 7Y+l7Y+l7Z6l7ZWl7Z6l7Y+l7Z6i7Z6l7Y+l7Z6l7Y+l7Z6i7Z6l7Y+l7Z6l7ZWl7Z6l7Y+l7Z6i7Z6l7Y+l7Z6l7ZWl7Z6l7Y+l7Z6i7Z6l7Y+l7Z6l7Y+l7Z+i7Z6l7Y+l7Z6l7ZWl7Z6l7Y+l7Z6i7Z6l7Y+l7Z6i7Z6l7Y+l7Z6l7ZWl7Z6l7Y+l7Z2i7Z6l7Y+l7Z6l7ZWl7Z6l7Y+l7Z6l7ZWl7Z6l7Y+l7Z6i7Z6l7Y+l7Z6l7Y+l7Z6i7Z6l7Y+l7Z6l7ZWl7Z6l7Y+l7Z6l7QAAAOCPpe2epZ6i7Z6l7Y+l7Z6l7Y+l7Z7xv7+Awr3s7Z6l7Z6l Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5099 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 20540947 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c8dbf4810, 0x562c8ddde01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c8ddde020,0x562c8fc760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9d2508315ba01d1baf70e2fb09ecc7bd13b2cf3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6466 processed earlier; will process 4563 files now Step #5: ==183640== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562c846e99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c8ad4e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c8ad315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c8ad314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c846efd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c84650b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c8464b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c846e1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c876b0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c876b0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c876b0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c876b0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c876b0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c876b0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c876b0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c876b0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c876b0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c876b0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c89945f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562c86672b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562c8667dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562c86429c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562c86429c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562c8642a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562c86429874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562c86429874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562c86429874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c8ad33abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c8ad3c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c8ad24699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c8ad4f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f347726c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c84649b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0x61,0x65,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x3a,0x0,0x2a,0x2a,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x68,0x68,0x68,0x68,0x68,0x68,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2a,0x2a,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x75,0x75,0x75,0x75,0x65, Step #5: nae**************************************\000\000\000:\000**hhhhhhhhh\004\000\000\000\000\000\000\000hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhttps://hhhhhh\000\000\000\000\000\000\000\000\000**hhhhhhhhh\004\000\000\000\000\000\000\000hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhttps://hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhuuuue Step #5: artifact_prefix='./'; Test unit written to ./oom-01ab9db821e8616ccee42900082d9fe641b8ce9c Step #5: Base64: bmFlKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqKioAAAA6ACoqaGhoaGhoaGhoBAAAAAAAAABoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhodHRwczovL2hoaGhoaAAAAAAAAAAAACoqaGhoaGhoaGhoBAAAAAAAAABoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhodHRwczovL2hoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaHV1dXVl Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5100 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 21075844 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c65df98810, 0x55c65e18201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c65e182020,0x55c66001a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01ab9db821e8616ccee42900082d9fe641b8ce9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6467 processed earlier; will process 4562 files now Step #5: #1 pulse cov: 3727 ft: 3728 exec/s: 0 rss: 176Mb Step #5: ==183676== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c654a8d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c65b0f2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c65b0d55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c65b0d54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c654a93d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6549f4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6549ef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c654a85c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c657a54f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c657a54f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c657a54f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c657a54f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c657a54f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c657a54f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c657a54f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c657a54f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c657a54f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c657a54f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c659ce9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c656a16b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c656a21be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6567cdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6567cdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6567ce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6567cd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6567cd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6567cd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c65b0d7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c65b0e0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c65b0c8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c65b0f3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa6526e0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6549edb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x50,0x3e,0x3c,0x64,0x3e,0x3c,0x50,0x3e,0x3c,0x73,0x6c,0x3a,0x73,0x74,0x61,0x6e,0x64,0x42,0x65,0x73,0x74,0x61,0x4e,0x64,0x3e,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x30,0x3c,0x64,0x3e,0x3c,0x50,0x3e,0x3c,0x64,0x3e,0x3c,0x64,0x3e,0x3c,0x64,0x3e,0x3c,0x64,0x3e,0x3c,0x64,0x3e,0x3c,0x50,0x3e,0x3c,0x50,0x3e,0x3c,0x64,0x3e,0x2e,0x3c,0x50,0x3e,0x3c,0x64,0x3e,0x3c,0x50,0x3e,0x3c,0x73,0x6c,0x3a,0x73,0x74,0x61,0x6e,0x64,0x42,0x65,0x73,0x70,0x61,0x4e,0x64,0x3e,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x6c,0x76,0x62,0x61,0x67,0x2f,0x65,0x78,0x74,0x72,0x61,0x63,0x74,0x2d,0x64,0x65,0x65,0x6c,0x62,0x65,0x73,0x74,0x61,0x6e,0x64,0x2d,0x6c,0x76,0x63,0x2f,0x76,0x32,0x30,0x32,0x30,0x30,0x36,0x30,0x31,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x6b,0x61,0x64,0x61,0x73,0x74,0x65,0x72,0x2e,0x6e,0x6c,0x2f,0x73,0x63,0x68,0x65,0x6d,0x61,0x73,0x2f,0x73,0x74,0x61,0x6e,0x64,0x6c,0x65,0x76,0x65,0x72,0x69,0x6e,0x67,0x2d,0x67,0x65,0x6e,0x65,0x72,0x69,0x65,0x6b,0x2f,0x31,0x2e,0x30,0x3c,0x64,0x3e,0x3c,0x50,0x3e,0x3c,0x64,0x3e,0x3c,0x64,0x3e,0x3c,0x64,0x3e,0x3c,0x64,0x3e,0x3c,0x64,0x3e,0x3c,0x50,0x3e,0x3c,0x50,0x3e,0x3c,0x64,0x3e,0x2e, Step #5: <P><d><P><sl:standBestaNd>http://www.0<d><P><d><d><d><d><d><P><P><d>.<P><d><P><sl:standBespaNd>http://www.kadaster.nl/schemas/lvbag/extract-deelbestand-lvc/v20200601http://www.kadaster.nl/schemas/standlevering-generiek/1.0<d><P><d><d><d><d><d><P><P><d>. Step #5: artifact_prefix='./'; Test unit written to ./oom-1b1fd22ba2d0073202e0e682169e8d81fe7d98d8 Step #5: Base64: PFA+PGQ+PFA+PHNsOnN0YW5kQmVzdGFOZD5odHRwOi8vd3d3LjA8ZD48UD48ZD48ZD48ZD48ZD48ZD48UD48UD48ZD4uPFA+PGQ+PFA+PHNsOnN0YW5kQmVzcGFOZD5odHRwOi8vd3d3LmthZGFzdGVyLm5sL3NjaGVtYXMvbHZiYWcvZXh0cmFjdC1kZWVsYmVzdGFuZC1sdmMvdjIwMjAwNjAxaHR0cDovL3d3dy5rYWRhc3Rlci5ubC9zY2hlbWFzL3N0YW5kbGV2ZXJpbmctZ2VuZXJpZWsvMS4wPGQ+PFA+PGQ+PGQ+PGQ+PGQ+PGQ+PFA+PFA+PGQ+Lg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5101 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 21658088 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa400c2810, 0x55aa402ac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa402ac020,0x55aa421440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b1fd22ba2d0073202e0e682169e8d81fe7d98d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6469 processed earlier; will process 4560 files now Step #5: ==183712== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aa36bb79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa3d21c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa3d1ff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa3d1ff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa36bbdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa36b1eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa36b19355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa36bafc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa39b7ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa39b7ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa39b7ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa39b7ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa39b7ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa39b7ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa39b7ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa39b7ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa39b7ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa39b7ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa3be13f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa38b40b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa38b4bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa388f7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa388f7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa388f8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa388f7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa388f7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa388f7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa3d201abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa3d20a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa3d1f2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa3d21d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5f8c94f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa36b17b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x31,0x49,0x46,0x33,0x4,0x8,0x32,0x73,0x55,0x6b,0x58,0x0,0x0,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x1,0x49,0x46,0x33,0x4,0x0,0x30,0x8,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x14,0x33,0x34,0xa,0x3a,0xb,0x3a,0xb,0x78,0x2e,0xa,0xe,0x6e,0x78,0xa,0x2e,0xa,0x22,0x74,0x78,0x6e,0x62,0x60,0x66,0x2e,0xd,0xef,0xb7,0xba,0x60,0x66,0x78,0x2e,0xa,0xe,0x6e,0x78,0xa,0x1,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x0,0x0,0x65,0x66,0x3d,0xa,0x3d,0x2b,0x3d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6d,0x61,0x78,0x47,0x70,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x49,0x45,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x0,0x0,0x0,0x0,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56, Step #5: 1IF3\004\0102sUkX\000\000\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\001IF3\004\0000\010\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\024\02434\012:\013:\013x.\012\016nx\012.\012\"txnb`f.\015\357\267\272`fx.\012\016nx\012\001------------------\000\000\000ef=\012=+=\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000maxGp\012-----BIEVVVVVVVVVVVVVVVVVVVVV\000\000\000\000VVVVVVVVVVVVVVVVV Step #5: artifact_prefix='./'; Test unit written to ./oom-588bcb3cd2e2c9b2e2d077fcf9201ff72e7e3047 Step #5: Base64: MUlGMwQIMnNVa1gAABQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFAFJRjMEADAIFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUMzQKOgs6C3guCg5ueAouCiJ0eG5iYGYuDe+3umBmeC4KDm54CgEtLS0tLS0tLS0tLS0tLS0tLS0AAABlZj0KPSs9AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABtYXhHcAotLS0tLUJJRVZWVlZWVlZWVlZWVlZWVlZWVlZWVgAAAABWVlZWVlZWVlZWVlZWVlZWVg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5102 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 22337305 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ef2162810, 0x559ef234c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ef234c020,0x559ef41e40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/588bcb3cd2e2c9b2e2d077fcf9201ff72e7e3047' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6470 processed earlier; will process 4559 files now Step #5: ==183748== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559ee8c579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559eef2bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559eef29f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559eef29f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ee8c5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ee8bbeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ee8bb9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ee8c4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559eebc1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559eebc1ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559eebc1ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559eebc1ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559eebc1ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559eebc1ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559eebc1ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559eebc1ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559eebc1ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559eebc1ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559eedeb3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559eeabe0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559eeabebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559eea997c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559eea997c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559eea998738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559eea997874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559eea997874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559eea997874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559eef2a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559eef2aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559eef292699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559eef2bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f17fd7ea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ee8bb7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x75,0x3d,0x74,0x69,0x6f,0x28,0x48,0x29,0x5f,0x3d,0x63,0x2d,0x66,0x75,0x6e,0x63,0x74,0x69,0x6f,0x6e,0x28,0x48,0x29,0x63,0x6e,0x28,0x6f,0x48,0x29,0x45,0x75,0x2e,0x72,0x27,0x27,0x71,0x3d,0x4c,0x2c,0x6c,0x6d,0x2d,0x52,0x20,0x65,0x2c,0x70,0x2c,0x63,0x67,0x2c,0x67,0x3d,0x61,0x2c,0x6c,0x7e,0x41,0x41,0x28,0x29,0x5f,0x3d,0x66,0x75,0x6e,0x63,0x74,0x69,0x6f,0x6e,0x28,0x48,0x29,0x5f,0x74,0x3d,0x66,0x75,0x6e,0x63,0x74,0x69,0x6f,0x6e,0x28,0x48,0x29,0x5f,0x3d,0x66,0x75,0x6e,0x63,0x74,0x69,0x6f,0x6e,0x28,0x29,0x5f,0x3d,0x66,0x75,0x6e,0x63,0x74,0x69,0x6f,0x6e,0x28,0x48,0x29,0x5f,0x3d,0x74,0x54,0x4c,0x2c,0x56,0x64,0x2c,0x65,0x2c,0x6c,0x2c,0x61,0x2c,0x56,0x2c,0x4f,0xa,0x70,0x61,0x3d,0x45,0x2c,0x5f,0x30,0x20,0x55,0x3d,0x49,0x2c,0x66,0x72,0x63,0x2c,0x6c,0x7a,0xd,0x6f,0x3d,0x5f,0x5f,0x2c,0x68,0x66,0x27,0x27,0x41,0x3d,0x77,0x2a,0x43,0x6c,0x2c,0x75,0x6c,0x2c,0x56,0x6e,0x28,0x29,0x64,0x28,0x43,0x29,0x64,0x66,0x2e,0x74,0x3d,0x5f,0x61,0x2c,0x67,0x41,0x2c,0x47,0x37,0x6c,0x6f,0x27,0x30,0x27,0x2d,0x4c,0x4a,0x2c,0x6e,0x28,0x29,0x65,0x6e,0x64,0x2d,0x66,0x75,0x6e,0x63,0x74,0x69,0x6f,0x6e,0x28,0x48,0x29,0x5f,0x3d,0x66,0x75,0x6e,0x63,0x74,0x69,0x6f,0x6e,0x28,0x29,0x5f,0x28,0x29,0x65,0x6e,0x64,0x2c,0x6e,0x63,0x28,0x29,0x65,0x6e,0x64,0x2d,0x66,0x28,0x29,0x65,0x2c,0x64,0x2d,0x6e, Step #5: u=tio(H)_=c-function(H)cn(oH)Eu.r''q=L,lm-R e,p,cg,g=a,l~AA()_=function(H)_t=function(H)_=function()_=function(H)_=tTL,Vd,e,l,a,V,O\012pa=E,_0 U=I,frc,lz\015o=__,hf''A=w*Cl,ul,Vn()d(C)df.t=_a,gA,G7lo'0'-LJ,n()end-function(H)_=function()_()end,nc()end-f()e,d-n Step #5: artifact_prefix='./'; Test unit written to ./oom-5512c4f73ae2832625e6f6e842be4bc91d548df9 Step #5: Base64: dT10aW8oSClfPWMtZnVuY3Rpb24oSCljbihvSClFdS5yJydxPUwsbG0tUiBlLHAsY2csZz1hLGx+QUEoKV89ZnVuY3Rpb24oSClfdD1mdW5jdGlvbihIKV89ZnVuY3Rpb24oKV89ZnVuY3Rpb24oSClfPXRUTCxWZCxlLGwsYSxWLE8KcGE9RSxfMCBVPUksZnJjLGx6DW89X18saGYnJ0E9dypDbCx1bCxWbigpZChDKWRmLnQ9X2EsZ0EsRzdsbycwJy1MSixuKCllbmQtZnVuY3Rpb24oSClfPWZ1bmN0aW9uKClfKCllbmQsbmMoKWVuZC1mKCllLGQtbg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5103 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 22885576 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56334a513810, 0x56334a6fd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56334a6fd020,0x56334c5950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5512c4f73ae2832625e6f6e842be4bc91d548df9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6471 processed earlier; will process 4558 files now Step #5: #1 pulse cov: 3727 ft: 3728 exec/s: 0 rss: 176Mb Step #5: ==183784== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5633410089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56334766d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5633476505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5633476504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56334100ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563340f6fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563340f6a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563341000c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563343fcff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563343fcff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563343fcff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563343fcff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563343fcff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563343fcff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563343fcff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563343fcff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563343fcff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563343fcff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563346264f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563342f91b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563342f9cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563342d48c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563342d48c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563342d49738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563342d48874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563342d48874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563342d48874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563347652abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56334765b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563347643699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56334766e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7042a7b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563340f68b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xa,0x0,0x7c,0x0,0x72,0x69,0x66,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5e,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x5b,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x75,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x5f,0x5f,0x5f,0x55,0x60,0x60,0x5f,0x5f,0x5f,0x1,0x74,0x60,0x0,0x2,0x5f,0x74,0x72,0x65,0x0,0x59,0x3e,0x30,0x2b,0x31,0x37,0x30,0x31,0x34,0x31,0x31,0x38,0x33,0x34,0x36,0x30,0x34,0x36,0x39,0x32,0x33,0x31,0x37,0x33,0x31,0x36,0x38,0x37,0x33,0x30,0x33,0x37,0x31,0x35,0x38,0x38,0x34,0x31,0x31,0x34,0x39,0x38,0x31,0x27,0x0,0x3a,0xd8,0x80,0x4,0x2b,0x0, Step #5: \000\012\000|\000rif__U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002___^U``___\001t__U``___\001t`\000\002____U`[`___\001t`\000\002____U``___\001t`\000\002_u__U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002____U``___\001t`\000\002_tre\000Y>0+170141183460469231731687303715884114981'\000:\330\200\004+\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4458a731028aa74eec554d26d8d78c50ece36bc5 Step #5: Base64: AAoAfAByaWZfX1VgYF9fXwF0YAACX19fX1VgYF9fXwF0YAACX19fX1VgYF9fXwF0YAACX19fX1VgYF9fXwF0YAACX19fX1VgYF9fXwF0YAACX19fXlVgYF9fXwF0X19VYGBfX18BdGAAAl9fX19VYFtgX19fAXRgAAJfX19fVWBgX19fAXRgAAJfdV9fVWBgX19fAXRgAAJfX19fVWBgX19fAXRgAAJfX19fVWBgX19fAXRgAAJfX19fVWBgX19fAXRgAAJfdHJlAFk+MCsxNzAxNDExODM0NjA0NjkyMzE3MzE2ODczMDM3MTU4ODQxMTQ5ODEnADrYgAQrAA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5104 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 23600451 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bce3000810, 0x55bce31ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bce31ea020,0x55bce50820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4458a731028aa74eec554d26d8d78c50ece36bc5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6473 processed earlier; will process 4556 files now Step #5: #1 pulse cov: 3885 ft: 3886 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4105 ft: 4578 exec/s: 0 rss: 179Mb Step #5: ==183820== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bcd9af59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bce015a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bce013d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bce013d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bcd9afbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bcd9a5cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bcd9a57355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bcd9aedc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bcdcabcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bcdcabcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bcdcabcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bcdcabcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bcdcabcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bcdcabcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bcdcabcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bcdcabcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bcdcabcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bcdcabcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bcded51f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bcdba7eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bcdba89be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bcdb835c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bcdb835c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bcdb836738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bcdb835874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bcdb835874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bcdb835874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bce013fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bce0148928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bce0130699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bce015b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a6357c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bcd9a55b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x4,0x33,0x3,0x0,0x0,0x45,0x30,0x50,0x55,0x53,0x4c,0x54,0x0,0x0,0x20,0x0,0x71,0x70,0x78,0x60,0x74,0x6d,0x21,0x60,0x33,0x50,0x55,0x53,0x4c,0x32,0x54,0x0,0x0,0x0,0x5,0x20,0x0,0x73,0x74,0x72,0x79,0x20,0x28,0x71,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x49,0x44,0x33,0x2,0x2b,0x5,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x46,0x3e,0x3a,0x27,0x54,0x0,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x0,0x58,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x0,0x58,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x9c,0xff,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x0,0x0,0x1,0x48,0x54,0x58,0x58,0x70,0x78,0x60,0x74,0x6d,0x21,0x60,0x32,0x50,0x55,0xb2,0xff,0x20,0x58,0x0,0x0, Step #5: I\0043\003\000\000E0PUSLT\000\000 \000qpx`tm!`3PUSL2T\000\000\000\005 \000stry (q\000\000\001HTXX\000\000\001HTXX\000\000\001HTXX\000ID3\002+\005\000\001HTXX\000\000\001HTXX\000\000\001HF>:'T\000TXX\000\000\001HTX\000X\000\001HTXX\000\000\001HTXX\000\000\001HTXX\000\000\001HTXX\000\000\001HTXX\000\000\001HTXX\000\000\001HTXX\000\000\001HTXX\000\000\001HTXX\000\000\001HTXX\000\000\001HTX\000X\000\001HTXX\000\000\001HTXX\000\000\001HTXX\000\000\377\377\377\377\377\377\377\234\377XX\000\000\001HTXX\000\000\001HTXX\000\000\001HTXXpx`tm!`2PU\262\377 X\000\000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2342d12d88b3e1c83b54b2e805cd04ef0b13b09e Step #5: Base64: SQQzAwAARTBQVVNMVAAAIABxcHhgdG0hYDNQVVNMMlQAAAAFIABzdHJ5IChxAAABSFRYWAAAAUhUWFgAAAFIVFhYAElEMwIrBQABSFRYWAAAAUhUWFgAAAFIRj46J1QAVFhYAAABSFRYAFgAAUhUWFgAAAFIVFhYAAABSFRYWAAAAUhUWFgAAAFIVFhYAAABSFRYWAAAAUhUWFgAAAFIVFhYAAABSFRYWAAAAUhUWFgAAAFIVFgAWAABSFRYWAAAAUhUWFgAAAFIVFhYAAD/////////nP9YWAAAAUhUWFgAAAFIVFhYAAABSFRYWHB4YHRtIWAyUFWy/yBYAAA= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5105 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 24332036 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f1740f5810, 0x55f1742df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f1742df020,0x55f1761770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2342d12d88b3e1c83b54b2e805cd04ef0b13b09e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6476 processed earlier; will process 4553 files now Step #5: ==183856== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f16abea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f17124f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1712325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1712324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f16abf0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f16ab51b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f16ab4c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f16abe2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f16dbb1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f16dbb1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f16dbb1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f16dbb1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f16dbb1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f16dbb1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f16dbb1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f16dbb1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f16dbb1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f16dbb1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f16fe46f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f16cb73b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f16cb7ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f16c92ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f16c92ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f16c92b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f16c92a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f16c92a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f16c92a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f171234abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f17123d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f171225699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f171250112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fab6dc6d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f16ab4ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0x8f,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0x9d,0xe0,0xbd,0xb5,0xe0,0xbd,0xbc,0xe0,0xbd,0xbd,0xe9,0xad,0x58,0xcf,0x2d,0x2b,0x86,0xe5,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbe,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xbd,0xbd,0xbd,0xbd,0xbd,0xbd,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0x4a,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xb8,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0x9d,0xe0,0xbd,0xb5,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0x9d,0xe0,0xbd,0xb5,0xe0,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0xbd,0xe0,0xbd,0x9d,0xe0,0xbd,0xb5,0xe0,0xbd,0xbe,0xe0,0xbd,0xbd,0x3d, Step #5: \340\275\275\340\275\275\340\275\275\340\217\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\235\340\275\265\340\275\274\340\275\275\351\255X\317-+\206\345\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\276\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\275\275\275\275\275\275\275\275\340\275\275\340\275\275\340\275\275\340\275J\340\275\275\340\275\275\340\275\275\340\275\275\270\270\270\270\270\270\270\270\270\270\270\270\270\270\270\270\270\270\270\270\270\270\340\275\275\340\275\275\340\275\275\340\275\275\340\275\235\340\275\265\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\235\340\275\265\340\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\275\340\275\235\340\275\265\340\275\276\340\275\275= Step #5: artifact_prefix='./'; Test unit written to ./oom-f425908f8eca33766cb02c770c70bf01e5a2438f Step #5: Base64: 4L294L294L294I+94L294L294L294L294L294L294L294L2d4L214L284L296a1Yzy0rhuW9veC9veC9veC9veC9veC9veC9veC9veC+veC9veC9veC9veC9veC9veC9veC9veC9veC9veC94L294L294L294L294L29vb29vb29vb3gvb3gvb3gvb3gvUrgvb3gvb3gvb3gvb24uLi4uLi4uLi4uLi4uLi4uLi4uLi44L294L294L294L294L2d4L214L294L294L294L294L294L294L294L2d4L214OC9veC9veC9veC9veC9veC9veC9neC9teC9vuC9vT0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5106 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 24852835 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564e70704810, 0x564e708ee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564e708ee020,0x564e727860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f425908f8eca33766cb02c770c70bf01e5a2438f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6477 processed earlier; will process 4552 files now Step #5: ==183892== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564e671f99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564e6d85e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564e6d8415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564e6d8414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564e671ffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564e67160b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564e6715b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564e671f1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564e6a1c0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564e6a1c0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564e6a1c0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564e6a1c0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564e6a1c0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564e6a1c0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564e6a1c0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564e6a1c0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564e6a1c0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564e6a1c0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564e6c455f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564e69182b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564e6918dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564e68f39c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564e68f39c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564e68f3a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564e68f39874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564e68f39874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564e68f39874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564e6d843abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564e6d84c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564e6d834699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564e6d85f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda3fc8e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564e67159b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x44,0x61,0x6e,0x4d,0x0,0x0,0x1,0x0,0x30,0x63,0x60,0x60,0x64,0x60,0x60,0x60,0x60,0x60,0x49,0x0,0x0,0x0,0x0,0x0,0x43,0x4f,0x4c,0x52,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x57,0x0,0x0,0x0,0x60,0x60,0x0,0x60,0x69,0x60,0x60,0x0,0x60,0x0,0x0,0x60,0x66,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x30,0x63,0x60,0x60,0x64,0x60,0x60,0x60,0xc,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x8,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x3d,0x5e,0x0,0x0,0x0,0xa,0xa,0x0,0x0,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0x4a,0x3d,0xa,0xa,0x2d,0x2d,0x3d,0x32,0x0,0x0,0x31,0x73,0x74,0x72,0x65,0x61,0x6d,0x63,0x60,0x60,0x64,0x60,0x60,0x60,0x6,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x60,0x60,0x60,0x60,0x60,0x49,0x44,0x33,0x4,0x0,0x35,0x35,0x35,0x35,0x35,0x78,0x0,0xca,0xb8,0x1,0x3,0x5c,0x49,0xe,0x0,0xe9,0x44,0x33,0x2,0x1,0x0,0x74,0x2e,0x0,0x44,0x0,0x0,0x54,0x0,0xc6,0x5b,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x11,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x35,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x26, Step #5: DanM\000\000\001\0000c``d`````I\000\000\000\000\000COLR\000\000\000\000\000\000\000W\000\000\000``\000`i``\000`\000\000`f\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\0000c``d```\014\000\000\000\000\000\000\000\000\000\000\000\010\000\000\000\000\000\000\000\005-----BEGIN =^\000\000\000\012\012\000\000\012=\012D\012=\012=J=\012\012--=2\000\0001streamc``d```\006\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000`````ID3\004\00055555x\000\312\270\001\003\\I\016\000\351D3\002\001\000t.\000D\000\000T\000\306[\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\021\000\000\000\000\000\000\000\000\000\000\000\0005\000\000\000\000\000\000\000& Step #5: artifact_prefix='./'; Test unit written to ./oom-1d2ef6f67070634377bf8dac3a9bd42a167a2f5e Step #5: Base64: RGFuTQAAAQAwY2BgZGBgYGBgSQAAAAAAQ09MUgAAAAAAAABXAAAAYGAAYGlgYABgAABgZgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwY2BgZGBgYAwAAAAAAAAAAAAAAAgAAAAAAAAABS0tLS0tQkVHSU4gPV4AAAAKCgAACj0KRAo9Cj1KPQoKLS09MgAAMXN0cmVhbWNgYGRgYGAGAAAAAAAAAAAAAAAAAAAAAGBgYGBgSUQzBAA1NTU1NXgAyrgBA1xJDgDpRDMCAQB0LgBEAABUAMZbAAAAAAAAAAAAAAAAAAAAABEAAAAAAAAAAAAAAAA1AAAAAAAAACY= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5107 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 25508291 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559bc377f810, 0x559bc396901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559bc3969020,0x559bc58010e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1d2ef6f67070634377bf8dac3a9bd42a167a2f5e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6478 processed earlier; will process 4551 files now Step #5: #1 pulse cov: 3581 ft: 3582 exec/s: 0 rss: 176Mb Step #5: ==183928== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559bba2749c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559bc08d9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559bc08bc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559bc08bc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559bba27ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559bba1dbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559bba1d6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559bba26cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559bbd23bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559bbd23bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559bbd23bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559bbd23bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559bbd23bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559bbd23bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559bbd23bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559bbd23bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559bbd23bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559bbd23bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559bbf4d0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559bbc1fdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559bbc208be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559bbbfb4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559bbbfb4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559bbbfb5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559bbbfb4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559bbbfb4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559bbbfb4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559bc08beabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559bc08c7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559bc08af699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559bc08da112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa68eca6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559bba1d4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x49,0x44,0x33,0x4,0x0,0x0,0x1,0x20,0x0,0x60,0x1,0x0,0x2,0x32,0x10,0x1,0x3,0x20,0x49,0x44,0x37,0x2,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x20,0x4e,0x2d,0x2d,0x3d,0xa,0x2d,0x4e,0x2d,0x2d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x20,0x0,0x4,0x13,0x43,0x4f,0x4d,0x60,0x1,0x20,0x0,0x60,0x1,0x2,0x0,0x0,0x32,0x1,0x3,0x20,0x63,0x6f,0x63,0x6f,0x6e,0x75,0x74,0x0,0x4,0x13,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x20,0x0,0x4,0x13,0x43,0x4f,0x4d,0x60,0x1,0x20,0x0,0x60,0x1,0x43,0x4f,0x4d,0x31,0x0,0x4a,0x3d,0xa,0x3d,0xa,0x5d,0x3d,0xa,0x3d,0xa,0x60,0x1,0x0,0x20,0x49,0x44,0x37,0x2,0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x20,0x4e,0x2d,0x2d,0x3d,0xa,0x2d,0x4e,0x2d,0x6c,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x0,0x4,0x13,0x43,0x4f,0x4d,0x60,0x1,0x20,0x0,0x60,0x1,0x2,0x0,0x0,0x32,0x1,0x3,0x20,0x63,0x6f,0x63,0x6f,0x6e,0x75,0x74,0x0,0x4,0x13,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x0,0x0,0x0,0x32,0x38,0x39,0x35, Step #5: ID3\004\000\000\001 \000`\001\000\0022\020\001\003 ID7\002\005-----BEGI N--=\012-N--\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000\000 \000\004\023COM`\001 \000`\001\002\000\0002\001\003 coconut\000\004\023\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000\000 \000\004\023COM`\001 \000`\001COM1\000J=\012=\012]=\012=\012`\001\000 ID7\002\005-----BEGI N--=\012-N-l\012\012=\012=\012= \000\004\023COM`\001 \000`\001\002\000\0002\001\003 coconut\000\004\023\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\000\000\0002895 Step #5: artifact_prefix='./'; Test unit written to ./oom-b817697d8e6ca9b7c3475b033821fe133c34fedf Step #5: Base64: SUQzBAAAASAAYAEAAjIQAQMgSUQ3AgUtLS0tLUJFR0kgTi0tPQotTi0tCgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoAACAABBNDT01gASAAYAECAAAyAQMgY29jb251dAAEEwo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KAAAgAAQTQ09NYAEgAGABQ09NMQBKPQo9Cl09Cj0KYAEAIElENwIFLS0tLS1CRUdJIE4tLT0KLU4tbAoKPQo9Cj0gAAQTQ09NYAEgAGABAgAAMgEDIGNvY29udXQABBMKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9CgAAADI4OTU= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5108 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 26221122 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab4047a810, 0x55ab4066401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab40664020,0x55ab424fc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b817697d8e6ca9b7c3475b033821fe133c34fedf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6480 processed earlier; will process 4549 files now Step #5: #1 pulse cov: 4104 ft: 4105 exec/s: 0 rss: 177Mb Step #5: ==183964== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ab36f6f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab3d5d4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab3d5b75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab3d5b74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab36f75d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab36ed6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab36ed1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab36f67c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab39f36f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab39f36f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab39f36f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab39f36f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab39f36f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab39f36f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab39f36f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab39f36f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab39f36f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab39f36f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab3c1cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab38ef8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab38f03be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab38cafc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab38cafc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab38cb0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab38caf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab38caf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab38caf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab3d5b9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab3d5c2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab3d5aa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab3d5d5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12194ea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab36ecfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3f,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d,0xa,0x2d, Step #5: ?\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012-\012- Step #5: artifact_prefix='./'; Test unit written to ./oom-7dd42ac47c380ebf350290ac4dc9abfeb2b8aaa9 Step #5: Base64: PwotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQotCi0KLQot Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5109 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 26887878 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e0af49810, 0x559e0b13301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e0b133020,0x559e0cfcb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7dd42ac47c380ebf350290ac4dc9abfeb2b8aaa9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6482 processed earlier; will process 4547 files now Step #5: ==184000== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559e01a3e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e080a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e080865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e080864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e01a44d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e019a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e019a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e01a36c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e04a05f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e04a05f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e04a05f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e04a05f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e04a05f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e04a05f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e04a05f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e04a05f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e04a05f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e04a05f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e06c9af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e039c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e039d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e0377ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e0377ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e0377f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e0377e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e0377e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e0377e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e08088abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e08091928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e08079699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e080a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5b7a11b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e0199eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x9,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x5e,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x13,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c,0x28,0x5c,0x53,0x5c,0x53,0x5c,0x53,0x5c, Step #5: \\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\\011\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\^\\S\\S\\S\\S\\S\\\023\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\S\\(\\S\\S\\S\\ Step #5: artifact_prefix='./'; Test unit written to ./oom-d0cf7a73fceb7458ae4fc5ef9c3fdde819dc04fd Step #5: Base64: XFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1wJXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXF5cU1xTXFNcU1xTXBNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXFNcU1xTXChcU1xTXFNc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5110 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 27420960 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557338c6f810, 0x557338e5901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557338e59020,0x55733acf10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d0cf7a73fceb7458ae4fc5ef9c3fdde819dc04fd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6483 processed earlier; will process 4546 files now Step #5: ==184036== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55732f7649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557335dc9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557335dac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557335dac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55732f76ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55732f6cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55732f6c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55732f75cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55733272bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55733272bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55733272bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55733272bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55733272bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55733272bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55733272bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55733272bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55733272bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55733272bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5573349c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5573316edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5573316f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5573314a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5573314a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5573314a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5573314a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5573314a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5573314a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557335daeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557335db7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557335d9f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557335dca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2f8bcad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55732f6c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x61,0x56,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x4e,0x44,0x41,0x54,0x41,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x56,0x63,0x63,0x63,0x63,0x49,0x47,0x4e,0x4f,0x52,0x45,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x3e,0x3c,0x21,0x2d,0x2d,0x61,0x44,0x55,0x43,0x53,0x2d,0x32,0x2a,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x49,0x47,0x4e,0x4f,0x52,0x45,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x63,0x3e,0x3c,0x21,0x2d,0x2d, Step #5: <aVccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccNDATAccccccccccccVVVVVVVVVVVVVVVVVVVVVVVVVccccIGNOREccccccccccccccccccccccccccccccccccccccccccc><!--aDUCS-2*ccccccccccccccccIGNOREccccccccccccccccccccccccccccccccccccccccccc><!-- Step #5: artifact_prefix='./'; Test unit written to ./oom-28ab974d1c77fc8574cbd16bc49436e8b8149c2e Step #5: Base64: PGFWY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NOREFUQWNjY2NjY2NjY2NjY1ZWVlZWVlZWVlZWVlZWVlZWVlZWVlZWVlZjY2NjSUdOT1JFY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjYz48IS0tYURVQ1MtMipjY2NjY2NjY2NjY2NjY2NjSUdOT1JFY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjYz48IS0t Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5111 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 27945886 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558644b88810, 0x558644d7201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558644d72020,0x558646c0a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/28ab974d1c77fc8574cbd16bc49436e8b8149c2e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6484 processed earlier; will process 4545 files now Step #5: ==184072== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55863b67d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558641ce2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558641cc55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558641cc54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55863b683d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55863b5e4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55863b5df355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55863b675c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55863e644f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55863e644f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55863e644f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55863e644f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55863e644f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55863e644f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55863e644f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55863e644f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55863e644f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55863e644f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5586408d9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55863d606b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55863d611be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55863d3bdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55863d3bdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55863d3be738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55863d3bd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55863d3bd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55863d3bd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558641cc7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558641cd0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558641cb8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558641ce3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f14636db082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55863b5ddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf2,0xa0,0x8f,0x88,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0x93,0xf3,0xa0,0x82,0x87,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0x93,0xf3,0xa0,0x82,0x87,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0xa9,0xf3,0x87,0x80,0x93,0xf3,0xa0,0x80,0x88,0xf3,0xa0,0x81,0xa1,0xf4,0x83,0x80,0x9f,0xf3,0xa0,0xa0,0x99,0xf0,0xb5,0x88,0x92,0xf0,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf3,0x9f,0x81,0xa1,0xf4,0x83,0x88,0x9f,0xf3,0xb5,0x80,0x99,0xf1,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf4,0x83,0x81,0x99,0xf3,0xa0,0x8f,0x89,0xf4,0x83,0x80,0xa9,0xf2,0xa0,0x8f,0x88,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0x93,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0xa9,0xf3,0x87,0x80,0x88,0xf3,0xa0,0x81,0xa1,0xf4,0x83,0x80,0x9f,0xf3,0xa0,0xa0,0x99,0xf0,0xb5,0x88,0x92,0xf0,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf3,0x9f,0x81,0xa1,0xf4,0x83,0x88,0x9f,0xf3,0xb5,0x80,0x99,0xf1,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf4,0x83,0x81,0x99,0xf3,0xa0,0x8f,0x89,0xf4,0x83,0x80,0xa9,0xf2,0xa0,0x8f,0x88,0xf4,0x83,0x80,0xa9,0xf4,0x83,0xae,0xa9,0xf3,0xa0,0x80,0x99,0xf0,0xb5,0x88,0x92,0xf0,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf3,0xa0,0x81,0xa1,0xf4,0x83,0x80,0x9f,0xf3,0xa0,0xa0,0x99,0xf3,0xa0,0x81,0x8a,0xf0,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf4,0x83,0x81,0x99,0xf3,0xa0,0x87,0x88,0xf4,0x83,0x80,0xa9,0xf3,0xa0,0x87,0x88,0xf4,0x84,0x81,0x99,0xf0,0xb5,0xb1, Step #5: \362\240\217\210\364\203\200\251\364\207\200\223\363\240\202\207\364\203\200\251\364\207\200\223\363\240\202\207\364\203\200\251\364\207\200\251\363\207\200\223\363\240\200\210\363\240\201\241\364\203\200\237\363\240\240\231\360\265\210\222\360\265\207\210\364\203\207\210\363\237\201\241\364\203\210\237\363\265\200\231\361\265\207\210\364\203\207\210\364\203\201\231\363\240\217\211\364\203\200\251\362\240\217\210\364\203\200\251\364\207\200\223\364\203\200\251\364\207\200\251\363\207\200\210\363\240\201\241\364\203\200\237\363\240\240\231\360\265\210\222\360\265\207\210\364\203\207\210\363\237\201\241\364\203\210\237\363\265\200\231\361\265\207\210\364\203\207\210\364\203\201\231\363\240\217\211\364\203\200\251\362\240\217\210\364\203\200\251\364\203\256\251\363\240\200\231\360\265\210\222\360\265\207\210\364\203\207\210\363\240\201\241\364\203\200\237\363\240\240\231\363\240\201\212\360\265\207\210\364\203\207\210\364\203\201\231\363\240\207\210\364\203\200\251\363\240\207\210\364\204\201\231\360\265\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-7dd9f0cf27e79ed4b5bbbc7355ad0ba6be098878 Step #5: Base64: 8qCPiPSDgKn0h4CT86CCh/SDgKn0h4CT86CCh/SDgKn0h4Cp84eAk/OggIjzoIGh9IOAn/OgoJnwtYiS8LWHiPSDh4jzn4Gh9IOIn/O1gJnxtYeI9IOHiPSDgZnzoI+J9IOAqfKgj4j0g4Cp9IeAk/SDgKn0h4Cp84eAiPOggaH0g4Cf86CgmfC1iJLwtYeI9IOHiPOfgaH0g4if87WAmfG1h4j0g4eI9IOBmfOgj4n0g4Cp8qCPiPSDgKn0g66p86CAmfC1iJLwtYeI9IOHiPOggaH0g4Cf86CgmfOggYrwtYeI9IOHiPSDgZnzoIeI9IOAqfOgh4j0hIGZ8LWx Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5112 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 28472519 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e7cfba810, 0x562e7d1a401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e7d1a4020,0x562e7f03c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7dd9f0cf27e79ed4b5bbbc7355ad0ba6be098878' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6485 processed earlier; will process 4544 files now Step #5: ==184108== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562e73aaf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e7a114898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e7a0f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e7a0f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e73ab5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e73a16b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e73a11355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e73aa7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e76a76f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e76a76f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e76a76f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e76a76f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e76a76f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e76a76f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e76a76f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e76a76f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e76a76f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e76a76f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e78d0bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e75a38b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e75a43be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e757efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e757efc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e757f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e757ef874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e757ef874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e757ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e7a0f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e7a102928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e7a0ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e7a115112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb273754082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e73a0fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x0,0xa,0xa,0xa,0x5b,0xa,0x5b,0x0,0xa,0xa,0x7b,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xa,0x3a,0xd,0xd,0xf3,0xa0,0x81,0x8e,0x4,0x31,0x32,0x38,0xa,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xd,0xcb,0xb0,0xd,0xd,0xd, Step #5: \000\012\012\012[\012[\000\012\012{\015\015\363\240\201\216\004\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\012:\015\015\363\240\201\216\004128\012\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\015\313\260\015\015\015 Step #5: artifact_prefix='./'; Test unit written to ./oom-4ac12337c66b2db199bb49f4704ecec9afd80c17 Step #5: Base64: AAoKClsKWwAKCnsNDfOggY4EDfOggY4EMTI4Cgo6DQ3zoIGOBDEyOAoKOg0N86CBjgQxMjgKCjoNDfOggY4EMTI4Cgo6DQ3zoIGOBDEyOAoKOg0N86CBjgQxMjgKCjoNDfOggY4EMTI4Cgo6DQ3zoIGOBDEyOAoKOg0N86CBjgQxMjgKCjoNDfOggY4EMTI4Cgo6DQ3zoIGOBDEyOAoKOg0N86CBjgQxMjgKCjoNDfOggY4EMTI4Cgo6DQ3zoIGOBDEyOAoKOg0N86CBjgQxMjgKCjoNDfOggY4EMTI4Cg0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDQ0NDcuwDQ0N Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5113 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 29013674 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d55b71810, 0x561d55d5b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d55d5b020,0x561d57bf30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4ac12337c66b2db199bb49f4704ecec9afd80c17' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6486 processed earlier; will process 4543 files now Step #5: ==184144== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d4c6669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d52ccb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d52cae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d52cae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d4c66cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d4c5cdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d4c5c8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d4c65ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d4f62df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d4f62df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d4f62df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d4f62df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d4f62df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d4f62df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d4f62df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d4f62df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d4f62df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d4f62df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d518c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d4e5efb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d4e5fabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d4e3a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d4e3a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d4e3a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d4e3a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d4e3a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d4e3a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d52cb0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d52cb9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d52ca1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d52ccc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f123754f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d4c5c6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27, Step #5: ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Step #5: artifact_prefix='./'; Test unit written to ./oom-956abe17bae4fd708e01a8b697fb26fd742c285c Step #5: Base64: JycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycnJycn Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5114 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 29560675 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5648028a5810, 0x564802a8f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564802a8f020,0x5648049270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/956abe17bae4fd708e01a8b697fb26fd742c285c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6487 processed earlier; will process 4542 files now Step #5: #1 pulse cov: 3664 ft: 3665 exec/s: 0 rss: 179Mb Step #5: ==184180== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647f939a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647ff9ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647ff9e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647ff9e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647f93a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647f9301b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647f92fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647f9392c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647fc361f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647fc361f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647fc361f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647fc361f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647fc361f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647fc361f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647fc361f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647fc361f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647fc361f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647fc361f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647fe5f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647fb323b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647fb32ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647fb0dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647fb0dac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647fb0db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647fb0da874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647fb0da874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647fb0da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647ff9e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647ff9ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647ff9d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647ffa00112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88aa813082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647f92fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x20,0x73,0x65,0x72,0x69,0x66,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x44,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x49,0x0,0x2d,0x27,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x0,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x47,0x49,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0x2d,0x2d,0x2d,0x2d,0xa,0x2d,0x2d,0xa,0x3d,0x44,0x34,0x4,0xcc,0x96,0x73,0x6b,0x69,0x70,0x5f,0x63,0x6c,0xa,0x7c,0x0,0x10,0xff, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012==\012=\012=\012=\012=\012=\012=\012=\012=\012=\012= serif\012=\012=\012=\012=\012=\012=\012=\012D\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=I\000-'---BEGIN\000------\012-----\000-----BE\012=\012=\012=GIN\012=\012=\012=\012=\000----\012--\012=D4\004\314\226skip_cl\012|\000\020\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-de901e4826b0f6c85636937916d5683bcdc13cf3 Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPT0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPSBzZXJpZgo9Cj0KPQo9Cj0KPQo9CkQKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPUkALSctLS1CRUdJTgAtLS0tLS0KLS0tLS0ALS0tLS1CRQo9Cj0KPUdJTgo9Cj0KPQo9AC0tLS0KLS0KPUQ0BMyWc2tpcF9jbAp8ABD/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5115 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 30170210 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f6c2811810, 0x55f6c29fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f6c29fb020,0x55f6c48930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de901e4826b0f6c85636937916d5683bcdc13cf3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6489 processed earlier; will process 4540 files now Step #5: #1 pulse cov: 4082 ft: 4083 exec/s: 0 rss: 180Mb Step #5: ==184216== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f6b93069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f6bf96b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f6bf94e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f6bf94e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f6b930cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f6b926db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f6b9268355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f6b92fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f6bc2cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f6bc2cdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f6bc2cdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f6bc2cdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f6bc2cdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f6bc2cdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f6bc2cdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f6bc2cdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f6bc2cdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f6bc2cdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f6be562f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f6bb28fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f6bb29abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f6bb046c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f6bb046c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f6bb047738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f6bb046874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f6bb046874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f6bb046874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f6bf950abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f6bf959928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f6bf941699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f6bf96c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f59dcc07082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f6b9266b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5e,0x6e,0x7b,0x39,0x38,0x31,0x7d,0xd,0xa,0xd,0xa,0xd,0xa,0xf3,0xa0,0x81,0x8a,0xf3,0xa0,0x81,0xa0,0xd,0xa,0xd,0xa,0xf3,0xa0,0x81,0x98,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xf3,0xa0,0x81,0x8a,0xf3,0xa0,0x81,0xa0,0xd,0xa,0xd,0xa,0xf3,0xa0,0x81,0x98,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xf3,0xa0,0x81,0x90,0xc0,0x8d,0xa,0xc0,0xbf, Step #5: ^n{981}\015\012\015\012\015\012\363\240\201\212\363\240\201\240\015\012\015\012\363\240\201\230\015\012\015\012\015\012\015\012\015\012\363\240\201\212\363\240\201\240\015\012\015\012\363\240\201\230\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\363\240\201\220\300\215\012\300\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-59f4358d5b78a2eef52bc7e3531515e79a722a3b Step #5: Base64: Xm57OTgxfQ0KDQoNCvOggYrzoIGgDQoNCvOggZgNCg0KDQoNCg0K86CBivOggaANCg0K86CBmA0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoN86CBkMCNCsC/ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5116 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 30739637 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5637f375c810, 0x5637f394601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5637f3946020,0x5637f57de0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/59f4358d5b78a2eef52bc7e3531515e79a722a3b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6491 processed earlier; will process 4538 files now Step #5: ==184252== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5637ea2519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5637f08b6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5637f08995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5637f08994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5637ea257d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5637ea1b8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5637ea1b3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5637ea249c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5637ed218f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5637ed218f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5637ed218f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5637ed218f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5637ed218f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5637ed218f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5637ed218f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5637ed218f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5637ed218f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5637ed218f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5637ef4adf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5637ec1dab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5637ec1e5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5637ebf91c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5637ebf91c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5637ebf92738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5637ebf91874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5637ebf91874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5637ebf91874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5637f089babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5637f08a4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5637f088c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5637f08b7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa5099ed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5637ea1b1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7a,0x6f,0x6e,0x65,0x5f,0x61,0x77,0x61,0x72,0x65,0x5f,0x6c,0x6f,0x61,0x64,0x5f,0x62,0x61,0x6c,0x61,0x6e,0x63,0x65,0x72,0x5f,0x74,0x65,0x73,0x74,0x5f,0x63,0x61,0x73,0x65,0x20,0x7b,0xa,0x20,0x20,0x6c,0x6f,0x61,0x64,0x5f,0x62,0x61,0x6c,0x61,0x6e,0x63,0x65,0x72,0x5f,0x74,0x65,0x73,0x74,0x5f,0x63,0x61,0x73,0x65,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x63,0x6f,0x6d,0x6d,0x6f,0x6e,0x5f,0x6c,0x62,0x5f,0x63,0x6f,0x6e,0x66,0x69,0x67,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x73,0x65,0x74,0x75,0x70,0x5f,0x70,0x72,0x69,0x6f,0x72,0x69,0x74,0x79,0x5f,0x6c,0x65,0x76,0x65,0x6c,0x73,0x20,0x7b,0xa,0x20,0x20,0x20,0x20,0x20,0x20,0x72,0x61,0x6e,0x64,0x6f,0x6d,0x5f,0x62,0x79,0x74,0x65,0x73,0x74,0x72,0x69,0x6e,0x67,0x3a,0x20,0x32,0xa,0x20,0x20,0x20,0x20,0x7d,0xa,0x20,0x20,0x20,0x20,0x73,0x65,0x65,0x64,0x5f,0x66,0x6f,0x72,0x5f,0x70,0x72,0x6e,0x67,0x3a,0x20,0x38,0xa,0x20,0x20,0x7d,0xa,0x20,0x20,0x72,0x61,0x6e,0x64,0x6f,0x6d,0x5f,0x62,0x79,0x74,0x65,0x73,0x74,0x72,0x69,0x6e,0x67,0x5f,0x66,0x6f,0x72,0x5f,0x77,0x65,0x69,0x67,0x68,0x74,0x73,0x3a,0x20,0x22,0x24,0x22,0xa,0x7d,0xa,0x72,0x61,0x6e,0x64,0x6f,0x6d,0x5f,0x62,0x79,0x74,0x65,0x73,0x74,0x72,0x69,0x6e,0x67,0x5f,0x66,0x6f,0x72,0x5f,0x72,0x65,0x71,0x75,0x65,0x73,0x74,0x73,0x3a,0x20,0x22,0x24,0x22,0xa, Step #5: zone_aware_load_balancer_test_case {\012 load_balancer_test_case {\012 common_lb_config {\012 }\012 setup_priority_levels {\012 random_bytestring: 2\012 }\012 seed_for_prng: 8\012 }\012 random_bytestring_for_weights: \"$\"\012}\012random_bytestring_for_requests: \"$\"\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-95a05cf18f1a1c5bf9cb3112bf9e7a6b76a627d0 Step #5: Base64: em9uZV9hd2FyZV9sb2FkX2JhbGFuY2VyX3Rlc3RfY2FzZSB7CiAgbG9hZF9iYWxhbmNlcl90ZXN0X2Nhc2UgewogICAgY29tbW9uX2xiX2NvbmZpZyB7CiAgICB9CiAgICBzZXR1cF9wcmlvcml0eV9sZXZlbHMgewogICAgICByYW5kb21fYnl0ZXN0cmluZzogMgogICAgfQogICAgc2VlZF9mb3JfcHJuZzogOAogIH0KICByYW5kb21fYnl0ZXN0cmluZ19mb3Jfd2VpZ2h0czogIiQiCn0KcmFuZG9tX2J5dGVzdHJpbmdfZm9yX3JlcXVlc3RzOiAiJCIK Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5117 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 31273313 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa21145810, 0x55aa2132f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa2132f020,0x55aa231c70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/95a05cf18f1a1c5bf9cb3112bf9e7a6b76a627d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6492 processed earlier; will process 4537 files now Step #5: ==184288== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aa17c3a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa1e29f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa1e2825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa1e2824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa17c40d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa17ba1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa17b9c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa17c32c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa1ac01f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa1ac01f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa1ac01f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa1ac01f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa1ac01f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa1ac01f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa1ac01f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa1ac01f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa1ac01f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa1ac01f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa1ce96f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa19bc3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa19bcebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa1997ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa1997ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa1997b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa1997a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa1997a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa1997a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa1e284abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa1e28d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa1e275699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa1e2a0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff92ca71082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa17b9ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x71,0x69,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012qi=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-2e2ac03add99d608058c692ca54c7bf6fa523e0f Step #5: Base64: Tgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9CnFpPQoKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9AAo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5118 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 31833463 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55921c642810, 0x55921c82c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55921c82c020,0x55921e6c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2e2ac03add99d608058c692ca54c7bf6fa523e0f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6493 processed earlier; will process 4536 files now Step #5: ==184324== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5592131379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55921979c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55921977f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55921977f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55921313dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55921309eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559213099355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55921312fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592160fef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592160fef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592160fef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592160fef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592160fef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592160fef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592160fef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592160fef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592160fef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592160fef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559218393f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592150c0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592150cbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559214e77c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559214e77c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559214e78738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559214e77874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559214e77874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559214e77874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559219781abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55921978a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559219772699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55921979d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffb59444082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559213097b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d, Step #5: =\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012= Step #5: artifact_prefix='./'; Test unit written to ./oom-7e4511ca1b6c94d88f6087992ab9ac8a7f53fa4c Step #5: Base64: PQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5119 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 32384854 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b1cc7e5810, 0x55b1cc9cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b1cc9cf020,0x55b1ce8670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7e4511ca1b6c94d88f6087992ab9ac8a7f53fa4c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6494 processed earlier; will process 4535 files now Step #5: ==184360== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b1c32da9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b1c993f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1c99225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1c99224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b1c32e0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b1c3241b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b1c323c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b1c32d2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b1c62a1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b1c62a1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b1c62a1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b1c62a1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b1c62a1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b1c62a1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b1c62a1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b1c62a1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b1c62a1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b1c62a1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b1c8536f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b1c5263b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b1c526ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b1c501ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b1c501ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b1c501b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b1c501a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b1c501a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b1c501a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b1c9924abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b1c992d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b1c9915699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b1c9940112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7cbe0de082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b1c323ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x73,0x74,0x72,0x75,0x63,0x74,0x20,0x52,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x5a,0x5a,0x5a,0x5a,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x6d,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x6b,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x49,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x6d,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x6b,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x68,0x61,0x35,0x39,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x6b,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x54,0x54,0x54,0x44,0x54,0x54,0x52,0x52,0x7b,0x7d,0x61,0x2c,0x52,0x6c,0x3d,0x28,0x61,0x3d,0x21,0x61,0x3d,0x2b,0x21,0x61, Step #5: struct RiiiiiiiiiiZZZZiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiimiiiiiiiiiiikiiiiiiiiiiiiiiiiIiiiiiiiiiiiiiiiiiiiiiiiiiiiiimiiiiiiiiiiikiiiiiiiiiiiiiiiiiiha59iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiikiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiTTTDTTRR{}a,Rl=(a=!a=+!a Step #5: artifact_prefix='./'; Test unit written to ./oom-af40900138df472b40e7d7fdd84517b2cda760a7 Step #5: Base64: c3RydWN0IFJpaWlpaWlpaWlpWlpaWmlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWltaWlpaWlpaWlpaWlraWlpaWlpaWlpaWlpaWlpaUlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaW1paWlpaWlpaWlpaWtpaWlpaWlpaWlpaWlpaWlpaWloYTU5aWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWtpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpaWlpVFRURFRUUlJ7fWEsUmw9KGE9IWE9KyFh Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5120 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 32921609 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c01f9d0810, 0x55c01fbba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c01fbba020,0x55c021a520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af40900138df472b40e7d7fdd84517b2cda760a7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6495 processed earlier; will process 4534 files now Step #5: ==184396== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c0164c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c01cb2a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c01cb0d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c01cb0d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c0164cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c01642cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c016427355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c0164bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c01948cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c01948cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c01948cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c01948cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c01948cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c01948cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c01948cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c01948cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c01948cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c01948cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c01b721f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c01844eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c018459be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c018205c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c018205c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c018206738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c018205874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c018205874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c018205874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c01cb0fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c01cb18928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c01cb00699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c01cb2b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f196c552082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c016425b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x47,0x52,0x4f,0x55,0x50,0x3d,0x22,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x31,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x30,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x30,0xe3,0x80,0x89,0xef,0xbb,0xbe,0x30,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x30,0xe2,0x80,0x89,0xef,0xbb,0xb6,0x39,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x34,0x37,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x30,0xe2,0x89,0x80,0xef,0xbb,0xbe,0xe2,0x80,0x89,0xef,0xbb,0xbe,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0x36,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x38,0x39,0xe2,0x80,0x89,0xef,0xbb,0xbe,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x35,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x34,0xe2,0x80,0xb1,0xef,0xab,0xbe,0x31,0xe2,0x80,0x89,0xef,0xbe,0xbb,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0xe2,0x80,0x89,0xef,0x80,0x89,0xef,0xbb,0xbe,0x39,0x35,0xe2,0x80,0x89,0xef,0xbb,0xbe,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0x35,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x35,0xe2,0x85,0x8b,0xef,0xbb,0xbe,0x38,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0x36,0xe2,0x80,0x89,0xef,0xbb,0xbe,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x39,0xe2,0x80,0x89,0x29,0xef,0xbb,0xbe,0xe2,0x82,0x89,0xef,0xbb,0xbe,0x35,0xe2,0x80,0x89,0xef,0xbb,0xbf,0x39,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x35,0xe2,0x80,0x89,0xef,0xbb,0xbe,0xe2,0x80,0x89,0xef,0xbb,0xbe,0x31,0xe2,0x80,0x89,0xef,0xb3,0xbe,0x22,0x2f, Step #5: GROUP=\"\342\200\211\357\273\2761\342\200\211\357\273\2760\342\200\211\357\273\2760\343\200\211\357\273\2760\342\200\211\357\273\2760\342\200\211\357\273\2669\342\200\211\357\273\27647\342\200\211\357\273\2760\342\211\200\357\273\276\342\200\211\357\273\276\342\200\211\357\273\27696\342\200\211\357\273\27689\342\200\211\357\273\276\342\200\211\357\273\2765\342\200\211\357\273\2764\342\200\261\357\253\2761\342\200\211\357\276\273\342\200\211\357\273\2769\342\200\211\357\200\211\357\273\27695\342\200\211\357\273\276\342\200\211\357\273\2769\342\200\211\357\273\27695\342\200\211\357\273\2769\342\200\211\357\273\2765\342\205\213\357\273\2768\342\200\211\357\273\27696\342\200\211\357\273\276\342\200\211\357\273\2769\342\200\211)\357\273\276\342\202\211\357\273\2765\342\200\211\357\273\2779\342\200\211\357\273\2765\342\200\211\357\273\276\342\200\211\357\273\2761\342\200\211\357\263\276\"/ Step #5: artifact_prefix='./'; Test unit written to ./oom-43380374af71b6fe539d60d1cf16b8ada252a43d Step #5: Base64: R1JPVVA9IuKAie+7vjHigInvu74w4oCJ77u+MOOAie+7vjDigInvu74w4oCJ77u2OeKAie+7vjQ34oCJ77u+MOKJgO+7vuKAie+7vuKAie+7vjk24oCJ77u+ODnigInvu77igInvu7414oCJ77u+NOKAse+rvjHigInvvrvigInvu7454oCJ74CJ77u+OTXigInvu77igInvu7454oCJ77u+OTXigInvu7454oCJ77u+NeKFi++7vjjigInvu745NuKAie+7vuKAie+7vjnigIkp77u+4oKJ77u+NeKAie+7vznigInvu7414oCJ77u+4oCJ77u+MeKAie+zviIv Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5121 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 33459947 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ba62f2810, 0x562ba64dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ba64dc020,0x562ba83740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/43380374af71b6fe539d60d1cf16b8ada252a43d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6496 processed earlier; will process 4533 files now Step #5: ==184432== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562b9cde79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ba344c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ba342f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ba342f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b9cdedd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b9cd4eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b9cd49355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b9cddfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b9fdaef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b9fdaef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b9fdaef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b9fdaef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b9fdaef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b9fdaef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b9fdaef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b9fdaef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b9fdaef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b9fdaef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ba2043f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b9ed70b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b9ed7bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b9eb27c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b9eb27c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b9eb28738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b9eb27874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b9eb27874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b9eb27874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ba3431abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ba343a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ba3422699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ba344d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5a3e863082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b9cd47b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0x45,0x78,0x65,0x63,0x5d,0xa,0x43,0x50,0x55,0x41,0x66,0x66,0x69,0x6e,0x69,0x74,0x79,0x3d,0x32,0xa,0x43,0x50,0x55,0x41,0x66,0x66,0x69,0x6e,0x69,0x74,0x79,0x3d,0x32,0x2c,0x32,0x34,0x33,0x30,0xa,0x43,0x50,0x55,0x41,0x66,0x66,0x69,0x6e,0x69,0x74,0x79,0x3d,0x34,0x2c,0x32,0x34,0x33,0x30,0x2c,0x36,0x32,0x31,0x31,0xa,0x43,0x50,0x55,0x41,0x66,0x66,0x69,0x6e,0x69,0x74,0x79,0x3d,0x30,0x2c,0x32,0x34,0x32,0x39,0x2c,0x36,0x32,0x31,0x33,0xa,0x43,0x50,0x55,0x41,0x66,0x66,0x69,0x6e,0x69,0x74,0x79,0x3d,0x31,0x2c,0x32,0x34,0x32,0x30,0x2c,0x36,0x32,0x31,0x36,0xa,0x43,0x50,0x55,0x41,0x66,0x66,0x69,0x6e,0x69,0x74,0x79,0x3d,0x31,0x2c,0x32,0x34,0x33,0x31,0x2c,0x36,0x32,0x31,0x33,0xa,0x43,0x50,0x55,0x41,0x66,0x66,0x69,0x6e,0x69,0x74,0x79,0x3d,0x31,0x2c,0x32,0x34,0x33,0x30,0x2c,0x36,0x32,0x31,0x36,0xa,0x43,0x50,0x55,0x41,0x66,0x66,0x69,0x6e,0x69,0x74,0x79,0x3d,0x31,0x2c,0x32,0x34,0x33,0x30,0x2c,0x36,0x32,0x31,0x31,0xa,0x43,0x50,0x55,0x41,0x66,0x66,0x69,0x6e,0x69,0x74,0x79,0x3d,0x31,0x2c,0x32,0x34,0x33,0x30,0x2c,0x36,0x32,0x31,0x33,0xa,0x43,0x50,0x55,0x41,0x66,0x66,0x69,0x6e,0x69,0x74,0x79,0x3d,0x31,0x2c,0x32,0x34,0x33,0x30,0x2c,0x36,0x32,0x31,0x36,0xa,0x43,0x50,0x55,0x41,0x66,0x66,0x69,0x6e,0x69,0x74,0x79,0x3d,0x31,0x2c,0x32,0x34,0x33,0x30,0x2c,0x36,0x32,0x31,0x33, Step #5: [Exec]\012CPUAffinity=2\012CPUAffinity=2,2430\012CPUAffinity=4,2430,6211\012CPUAffinity=0,2429,6213\012CPUAffinity=1,2420,6216\012CPUAffinity=1,2431,6213\012CPUAffinity=1,2430,6216\012CPUAffinity=1,2430,6211\012CPUAffinity=1,2430,6213\012CPUAffinity=1,2430,6216\012CPUAffinity=1,2430,6213 Step #5: artifact_prefix='./'; Test unit written to ./oom-e504d71ad9dd5073be2e69546623047d8b22822d Step #5: Base64: W0V4ZWNdCkNQVUFmZmluaXR5PTIKQ1BVQWZmaW5pdHk9MiwyNDMwCkNQVUFmZmluaXR5PTQsMjQzMCw2MjExCkNQVUFmZmluaXR5PTAsMjQyOSw2MjEzCkNQVUFmZmluaXR5PTEsMjQyMCw2MjE2CkNQVUFmZmluaXR5PTEsMjQzMSw2MjEzCkNQVUFmZmluaXR5PTEsMjQzMCw2MjE2CkNQVUFmZmluaXR5PTEsMjQzMCw2MjExCkNQVUFmZmluaXR5PTEsMjQzMCw2MjEzCkNQVUFmZmluaXR5PTEsMjQzMCw2MjE2CkNQVUFmZmluaXR5PTEsMjQzMCw2MjEz Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5122 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 33989769 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d225bb3810, 0x55d225d9d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d225d9d020,0x55d227c350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e504d71ad9dd5073be2e69546623047d8b22822d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6497 processed earlier; will process 4532 files now Step #5: ==184468== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d21c6a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d222d0d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d222cf05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d222cf04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d21c6aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d21c60fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d21c60a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d21c6a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d21f66ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d21f66ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d21f66ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d21f66ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d21f66ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d21f66ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d21f66ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d21f66ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d21f66ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d21f66ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d221904f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d21e631b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d21e63cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d21e3e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d21e3e8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d21e3e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d21e3e8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d21e3e8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d21e3e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d222cf2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d222cfb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d222ce3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d222d0e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe3b7703082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d21c608b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4e,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x2,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x70,0x69,0x3d,0xa,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0x0,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x3d,0xa,0x10, Step #5: \005-----BEGIN -----\012N\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\002=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012pi=\012\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\000\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012=\012\020 Step #5: artifact_prefix='./'; Test unit written to ./oom-b33e65ab01079dde533736eda3152d6a05cb3d8c Step #5: Base64: BS0tLS0tQkVHSU4gLS0tLS0KTgo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Aj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQpwaT0KCj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQAKPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQo9Cj0KPQoQ Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5123 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 34557664 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b9ef2a4810, 0x55b9ef48e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b9ef48e020,0x55b9f13260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b33e65ab01079dde533736eda3152d6a05cb3d8c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6498 processed earlier; will process 4531 files now Step #5: ==184504== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b9e5d999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b9ec3fe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b9ec3e15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b9ec3e14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b9e5d9fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b9e5d00b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b9e5cfb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b9e5d91c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b9e8d60f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b9e8d60f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b9e8d60f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b9e8d60f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b9e8d60f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b9e8d60f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b9e8d60f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b9e8d60f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b9e8d60f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b9e8d60f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b9eaff5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b9e7d22b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b9e7d2dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b9e7ad9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b9e7ad9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b9e7ada738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b9e7ad9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b9e7ad9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b9e7ad9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b9ec3e3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b9ec3ec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b9ec3d4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b9ec3ff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3609706082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b9e5cf9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3,0xa,0xe0,0xbd,0xb3, Step #5: \340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263\012\340\275\263 Step #5: artifact_prefix='./'; Test unit written to ./oom-dd31d774b42509f7d66201ea7a40a0d07d1def62 Step #5: Base64: 4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2zCuC9swrgvbMK4L2z Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5124 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 35092238 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558d13bce810, 0x558d13db801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558d13db8020,0x558d15c500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dd31d774b42509f7d66201ea7a40a0d07d1def62' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6499 processed earlier; will process 4530 files now Step #5: ==184540== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558d0a6c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558d10d28898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558d10d0b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558d10d0b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558d0a6c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558d0a62ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558d0a625355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558d0a6bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558d0d68af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558d0d68af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558d0d68af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558d0d68af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558d0d68af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558d0d68af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558d0d68af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558d0d68af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558d0d68af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558d0d68af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558d0f91ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558d0c64cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558d0c657be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558d0c403c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558d0c403c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558d0c404738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558d0c403874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558d0c403874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558d0c403874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558d10d0dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558d10d16928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558d10cfe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558d10d29112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff8bc952082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558d0a623b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6e,0x61,0x65,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x3a,0x0,0x2a,0x2a,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x2a,0x0,0x0,0x0,0x3a,0x0,0x2a,0x2a,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x4,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x68,0x75,0x75,0x75,0x75,0x65, Step #5: nae******************************\000\000\000:\000**hhhhhhhhh\004\000\000\000\000\000\000\000hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhttps://hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh********\000\000\000:\000**hhhhhhhhh\004\000\000\000\000\000\000\000hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhttps://hhhhhhhhhhhhhhuuuue Step #5: artifact_prefix='./'; Test unit written to ./oom-1e14a904f44db9248213641d11f94eaa3a878a91 Step #5: Base64: bmFlKioqKioqKioqKioqKioqKioqKioqKioqKioqKioqAAAAOgAqKmhoaGhoaGhoaAQAAAAAAAAAaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaHR0cHM6Ly9oaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaCoqKioqKioqAAAAOgAqKmhoaGhoaGhoaAQAAAAAAAAAaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaGhoaHR0cHM6Ly9oaGhoaGhoaGhoaGhoaHV1dXVl Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5125 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 35631453 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564016fcc810, 0x5640171b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640171b6020,0x56401904e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e14a904f44db9248213641d11f94eaa3a878a91' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6500 processed earlier; will process 4529 files now Step #5: ==184576== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56400dac19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564014126898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640141095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640141094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56400dac7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56400da28b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56400da23355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56400dab9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564010a88f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564010a88f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564010a88f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564010a88f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564010a88f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564010a88f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564010a88f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564010a88f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564010a88f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564010a88f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564012d1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56400fa4ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56400fa55be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56400f801c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56400f801c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56400f802738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56400f801874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56400f801874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56400f801874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56401410babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564014114928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5640140fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564014127112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa9daf2e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56400da21b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x76,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0x2d,0x3d,0x0,0x24, Step #5: ~$-\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000v\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000=-=\000$ Step #5: artifact_prefix='./'; Test unit written to ./oom-9b33f950aa24d956deba4d6c9dd298c4046089dc Step #5: Base64: fiQtAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB2AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD0tPQAk Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5126 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 36176128 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55adabb4d810, 0x55adabd3701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55adabd37020,0x55adadbcf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9b33f950aa24d956deba4d6c9dd298c4046089dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6501 processed earlier; will process 4528 files now Step #5: ==184612== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ada26429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ada8ca7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ada8c8a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ada8c8a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ada2648d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ada25a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ada25a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ada263ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ada5609f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ada5609f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ada5609f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ada5609f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ada5609f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ada5609f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ada5609f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ada5609f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ada5609f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ada5609f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ada789ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ada45cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ada45d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ada4382c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ada4382c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ada4383738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ada4382874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ada4382874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ada4382874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ada8c8cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ada8c95928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ada8c7d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ada8ca8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb5bd594082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ada25a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22,0x0,0x22, Step #5: \"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\"\000\" Step #5: artifact_prefix='./'; Test unit written to ./oom-e9204f1aacab8af625c9775aebcab39e7cef979c Step #5: Base64: IgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAiACIAIgAi Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5127 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 36730340 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e5d64b8810, 0x55e5d66a201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e5d66a2020,0x55e5d853a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e9204f1aacab8af625c9775aebcab39e7cef979c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6502 processed earlier; will process 4527 files now Step #5: ==184648== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e5ccfad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e5d3612898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e5d35f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e5d35f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e5ccfb3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e5ccf14b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e5ccf0f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e5ccfa5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e5cff74f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e5cff74f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e5cff74f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e5cff74f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e5cff74f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e5cff74f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e5cff74f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e5cff74f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e5cff74f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e5cff74f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e5d2209f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e5cef36b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e5cef41be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e5cecedc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e5cecedc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e5cecee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e5ceced874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e5ceced874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e5ceced874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e5d35f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e5d3600928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e5d35e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e5d3613112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe968d08082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e5ccf0db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x66,0x69,0x6e,0x65,0x5f,0x66,0x69,0x6e,0x65,0x5f,0x66,0x69,0x6e,0x65,0x5f,0x66,0x69,0x6e,0x65,0x5f,0x66,0x69,0x6e,0x65,0x5f,0x66,0x69,0x6e,0x65,0x5f,0x66,0x69,0x6e,0x65,0x5f,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x23,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x69,0x64,0x74,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x74,0x68,0x2c,0x30,0x78,0x38,0x46,0x46,0x46,0x46,0x46,0x46,0x46,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x66,0x65,0x68,0x20,0x46,0x46,0x46,0x61,0x61,0x61,0x66,0x30,0x68,0x20,0x30,0x68,0x66,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x1f,0x30,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x30,0x20,0x36,0x31,0x68,0x20,0x30,0x68,0x20,0x30,0x68,0x20,0x30, Step #5: fine_fine_fine_fine_fine_fine_fine_h 0h 0h 0h 0#h 0h 0h 0h 0h 0h 0h 0h idth 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h th,0x8FFFFFFF0h 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h 0feh FFFaaaf0h 0hf 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h 0h\0370h 0h 0h0 61h 0h 0h 0 Step #5: artifact_prefix='./'; Test unit written to ./oom-78543be7dd196faa0ea6c54d306a911a0d6f9936 Step #5: Base64: ZmluZV9maW5lX2ZpbmVfZmluZV9maW5lX2ZpbmVfZmluZV9oIDBoIDBoIDBoIDAjaCAwaCAwaCAwaCAwaCAwaCAwaCAwaCBpZHRoIDBoIDBoIDBoIDBoIDBoIDBoIDBoIDBoIDBoIDBoIDBoIDBoIDBoIDBoIDBoIDBoIHRoLDB4OEZGRkZGRkYwaCAwaCAwaCAwaCAwaCAwaCAwaCAwaCAwaCAwaCAwaCAwaCAwZmVoIEZGRmFhYWYwaCAwaGYgMGggMGggMGggMGggMGggMGggMGggMGggMGggMGggMGggMGggMGggMGgfMGggMGggMGgwIDYxaCAwaCAwaCAw Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5128 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 37267977 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e1cf76a810, 0x55e1cf95401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e1cf954020,0x55e1d17ec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/78543be7dd196faa0ea6c54d306a911a0d6f9936' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6503 processed earlier; will process 4526 files now Step #5: ==184684== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e1c625f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e1cc8c4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e1cc8a75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e1cc8a74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e1c6265d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e1c61c6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e1c61c1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e1c6257c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e1c9226f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e1c9226f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e1c9226f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e1c9226f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e1c9226f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e1c9226f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e1c9226f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e1c9226f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e1c9226f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e1c9226f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e1cb4bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e1c81e8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e1c81f3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e1c7f9fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e1c7f9fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e1c7fa0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e1c7f9f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e1c7f9f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e1c7f9f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e1cc8a9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e1cc8b2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e1cc89a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e1cc8c5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff82d25d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e1c61bfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xf2,0xa0,0x8f,0x88,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0x93,0xf3,0xa0,0x82,0x99,0xf3,0xa0,0x87,0x87,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0xa9,0xf4,0x87,0x80,0x93,0xf3,0xa0,0x80,0x99,0xf0,0xb5,0x88,0x92,0xf0,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf3,0xa0,0x81,0xa1,0xf4,0x83,0x80,0x9f,0xf3,0xa0,0xa0,0x99,0xf0,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf4,0x83,0x81,0x99,0xf3,0xa0,0x87,0x88,0xf4,0x83,0x80,0xa9,0xf4,0x8c,0x80,0x93,0xf3,0xa0,0xb0,0x99,0xf0,0xb5,0x88,0xb1,0xf4,0x89,0x80,0x92,0xf0,0xb5,0x87,0x88,0xf4,0x83,0x81,0x99,0xf0,0xb5,0x88,0xb1,0xf4,0x89,0x80,0x92,0xf0,0xb5,0x88,0x88,0xf4,0x84,0x80,0x9f,0xf3,0xa0,0x81,0x99,0xf0,0xb5,0x88,0xb1,0xf4,0x89,0x80,0x92,0xf4,0x88,0xbf,0x93,0xf3,0x9f,0x82,0x99,0xf3,0xa0,0x87,0x88,0xf4,0x83,0x80,0xa9,0xf3,0x87,0x80,0xa9,0xf4,0x87,0x80,0x93,0xf2,0xa0,0x81,0x99,0xf0,0xb5,0x88,0x92,0xf0,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf3,0xa0,0x81,0xa1,0xf4,0x83,0x88,0x9f,0xf3,0xb5,0x81,0x99,0xf1,0xb5,0x87,0x88,0xf4,0x83,0x87,0x88,0xf4,0x83,0x81,0x99,0xf3,0xa0,0x8f,0x89,0xf4,0x83,0x80,0xa9,0xf4,0x87,0x80,0x91,0xf3,0xa0,0x81,0x99,0xf0,0xb5,0x88,0xb1,0xf4,0x8a,0x80,0x92,0xf0,0xb5,0x88,0x88,0xf4,0x83,0x81,0x99,0xf0,0xb5,0x87,0xb1,0xf4,0x89,0x80,0x92,0xf0,0xb5,0x87,0xb1,0xf4,0x89,0x81,0x92,0xf1,0xb5,0x87,0x88,0xf4,0x84,0x81,0x99,0xf0,0xb5,0x88,0xb1, Step #5: \362\240\217\210\364\203\200\251\364\207\200\223\363\240\202\231\363\240\207\207\364\203\200\251\364\207\200\251\364\207\200\223\363\240\200\231\360\265\210\222\360\265\207\210\364\203\207\210\363\240\201\241\364\203\200\237\363\240\240\231\360\265\207\210\364\203\207\210\364\203\201\231\363\240\207\210\364\203\200\251\364\214\200\223\363\240\260\231\360\265\210\261\364\211\200\222\360\265\207\210\364\203\201\231\360\265\210\261\364\211\200\222\360\265\210\210\364\204\200\237\363\240\201\231\360\265\210\261\364\211\200\222\364\210\277\223\363\237\202\231\363\240\207\210\364\203\200\251\363\207\200\251\364\207\200\223\362\240\201\231\360\265\210\222\360\265\207\210\364\203\207\210\363\240\201\241\364\203\210\237\363\265\201\231\361\265\207\210\364\203\207\210\364\203\201\231\363\240\217\211\364\203\200\251\364\207\200\221\363\240\201\231\360\265\210\261\364\212\200\222\360\265\210\210\364\203\201\231\360\265\207\261\364\211\200\222\360\265\207\261\364\211\201\222\361\265\207\210\364\204\201\231\360\265\210\261 Step #5: artifact_prefix='./'; Test unit written to ./oom-77411dce6a8efb81bc80af75a997fd67e2ad71d0 Step #5: Base64: 8qCPiPSDgKn0h4CT86CCmfOgh4f0g4Cp9IeAqfSHgJPzoICZ8LWIkvC1h4j0g4eI86CBofSDgJ/zoKCZ8LWHiPSDh4j0g4GZ86CHiPSDgKn0jICT86CwmfC1iLH0iYCS8LWHiPSDgZnwtYix9ImAkvC1iIj0hICf86CBmfC1iLH0iYCS9Ii/k/OfgpnzoIeI9IOAqfOHgKn0h4CT8qCBmfC1iJLwtYeI9IOHiPOggaH0g4if87WBmfG1h4j0g4eI9IOBmfOgj4n0g4Cp9IeAkfOggZnwtYix9IqAkvC1iIj0g4GZ8LWHsfSJgJLwtYex9ImBkvG1h4j0hIGZ8LWIsQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5129 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 37796544 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564a1a8d6810, 0x564a1aac001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564a1aac0020,0x564a1c9580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/77411dce6a8efb81bc80af75a997fd67e2ad71d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6504 processed earlier; will process 4525 files now Step #5: ==184720== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564a113cb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564a17a30898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564a17a135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564a17a134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564a113d1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564a11332b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564a1132d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564a113c3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564a14392f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564a14392f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564a14392f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564a14392f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564a14392f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564a14392f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564a14392f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564a14392f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564a14392f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564a14392f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564a16627f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564a13354b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564a1335fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564a1310bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564a1310bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564a1310c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564a1310b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564a1310b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564a1310b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564a17a15abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564a17a1e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564a17a06699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564a17a31112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda061c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564a1132bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xee,0x9b,0x8f,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x97,0x8e,0xee,0x9b,0x8f,0xe1,0x97,0x8e,0xe9,0x8c,0x8f,0xee,0x93,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x9b,0x8f,0xe1,0x9b,0x9d,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x97,0x8f,0xee,0x9b,0x8f,0xe1,0x93,0x8f,0xe1,0x8b,0x8f,0xe1,0x97,0x8e,0xee,0x9b,0x8f,0xe1,0x97,0x8e,0xe9,0x8c,0x8f,0xee,0x93,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x9b,0x8f,0xe1,0x9b,0x9d,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x97,0x8f,0xee,0x9b,0x8f,0xe1,0x93,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x9b,0x8f,0xee,0x9b,0x8f,0xe1,0x93,0x8f,0xe1,0x8b,0x8f,0xe1,0x93,0x8f,0xe1,0x8b,0x8f,0xe1,0x8b,0x8f,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x97,0x8f,0xee,0x9b,0x8f,0xe1,0x93,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x9b,0x8f,0xee,0x9b,0x8f,0xe1,0x93,0x8f,0xe1,0x8b,0x8f,0xe1,0x8b,0x8f,0xe1,0xb4,0x9b,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x97,0x8e,0xe9,0x8c,0x8f,0xee,0x9b,0x8f,0xe1,0x93,0x8e,0xe9,0x8c,0x8f,0xee,0x9b,0x8f,0xe1,0x93,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe9,0x93,0x8f,0xe1,0x8b,0x8f,0xe1,0xb4,0x9b,0xe1,0x9b,0x8f,0xe1,0x8b,0x8f,0xee,0x9b,0x8f,0xe1, Step #5: \356\233\217\341\233\217\341\213\217\356\233\217\341\227\216\356\233\217\341\227\216\351\214\217\356\223\217\341\213\217\356\233\217\341\233\217\341\233\235\341\233\217\341\213\217\341\233\217\341\213\217\356\233\217\341\227\217\356\233\217\341\223\217\341\213\217\341\227\216\356\233\217\341\227\216\351\214\217\356\223\217\341\213\217\356\233\217\341\233\217\341\233\235\341\233\217\341\213\217\341\233\217\341\213\217\356\233\217\341\227\217\356\233\217\341\223\217\341\213\217\356\233\217\341\233\217\356\233\217\341\223\217\341\213\217\341\223\217\341\213\217\341\213\217\341\233\217\341\213\217\356\233\217\341\227\217\356\233\217\341\223\217\341\213\217\356\233\217\341\233\217\356\233\217\341\223\217\341\213\217\341\213\217\341\264\233\341\233\217\341\213\217\341\233\217\341\213\217\356\233\217\341\227\216\351\214\217\356\233\217\341\223\216\351\214\217\356\233\217\341\223\217\341\213\217\356\233\217\341\233\217\341\213\217\356\233\217\351\223\217\341\213\217\341\264\233\341\233\217\341\213\217\356\233\217\341 Step #5: artifact_prefix='./'; Test unit written to ./oom-10b6d5d99b2b4aef339cdcdd19a446aa484907a6 Step #5: Base64: 7puP4ZuP4YuP7puP4ZeO7puP4ZeO6YyP7pOP4YuP7puP4ZuP4Zud4ZuP4YuP4ZuP4YuP7puP4ZeP7puP4ZOP4YuP4ZeO7puP4ZeO6YyP7pOP4YuP7puP4ZuP4Zud4ZuP4YuP4ZuP4YuP7puP4ZeP7puP4ZOP4YuP7puP4ZuP7puP4ZOP4YuP4ZOP4YuP4YuP4ZuP4YuP7puP4ZeP7puP4ZOP4YuP7puP4ZuP7puP4ZOP4YuP4YuP4bSb4ZuP4YuP4ZuP4YuP7puP4ZeO6YyP7puP4ZOO6YyP7puP4ZOP4YuP7puP4ZuP4YuP7puP6ZOP4YuP4bSb4ZuP4YuP7puP4Q== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5130 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 38323417 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa9466c810, 0x55aa9485601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa94856020,0x55aa966ee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/10b6d5d99b2b4aef339cdcdd19a446aa484907a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6505 processed earlier; will process 4524 files now Step #5: ==184756== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aa8b1619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa917c6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa917a95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa917a94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa8b167d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa8b0c8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa8b0c3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa8b159c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa8e128f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa8e128f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa8e128f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa8e128f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa8e128f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa8e128f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa8e128f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa8e128f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa8e128f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa8e128f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa903bdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa8d0eab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa8d0f5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa8cea1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa8cea1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa8cea2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa8cea1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa8cea1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa8cea1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa917ababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa917b4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa9179c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa917c7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f40ce267082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa8b0c1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5b,0xa,0xa,0x2d,0x2d,0xa,0xa,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x5b,0xa,0xa,0x2d,0x2d,0xa,0xa,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0x2d,0x2d,0xa,0x0,0x8,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0xa,0x2d,0x27,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0x2d,0x2d,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0x2d,0x2d,0xa,0x2d,0x2d,0x2d,0xa,0xa,0x2d,0x2d,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0x22,0xa,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa,0xa,0x2d,0x2d,0xa,0xa,0xa,0x2d,0x2d,0x2d,0xa,0x7b,0x22,0x22,0xa,0xa, Step #5: [\012\012--\012\012\012\012\012---\012{\"\"\012\012\012\012---\012{\"\"\012\012\012\012---\012{\012\012\012---\012{\"\"\012\012\012--\012---\012{\"[\012\012--\012\012\012\012\012---\012{\"\"\012\012\012\012---\012{\"\"\012\012\012\012---\012{\"\"\012\012\012{\"\"\012\012\012--\012\000\010---\012{\"\"\012\012\012\012---\012{\"\"\012\012\012\012-'---\012{\"\"\012\012--\012\012\012---\012{\"\"\012\012\012\012---\012{\"\"\012\012\012--\012---\012\012--\012\012\012---\012{\"\"\012\012\012\012---\012{\"\"\012\012\012\012---\012{\"\"\012\012\012\"\012\012\012\012---\012{\"\"\012\012\012\012---\012{\"\"\012\012\012--\012\012\012---\012{\"\"\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-06e9de5392b3358c4c01f1f22fab86babd9aaf11 Step #5: Base64: WwoKLS0KCgoKCi0tLQp7IiIKCgoKLS0tCnsiIgoKCgotLS0KewoKCi0tLQp7IiIKCgotLQotLS0KeyJbCgotLQoKCgoKLS0tCnsiIgoKCgotLS0KeyIiCgoKCi0tLQp7IiIKCgp7IiIKCgotLQoACC0tLQp7IiIKCgoKLS0tCnsiIgoKCgotJy0tLQp7IiIKCi0tCgoKLS0tCnsiIgoKCgotLS0KeyIiCgoKLS0KLS0tCgotLQoKCi0tLQp7IiIKCgoKLS0tCnsiIgoKCgotLS0KeyIiCgoKIgoKCgotLS0KeyIiCgoKCi0tLQp7IiIKCgotLQoKCi0tLQp7IiIKCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5131 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 38860170 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562951cef810, 0x562951ed901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562951ed9020,0x562953d710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/06e9de5392b3358c4c01f1f22fab86babd9aaf11' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6506 processed earlier; will process 4523 files now Step #5: ==184792== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5629487e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56294ee49898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56294ee2c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56294ee2c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5629487ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56294874bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562948746355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5629487dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56294b7abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56294b7abf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56294b7abf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56294b7abf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56294b7abf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56294b7abf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56294b7abf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56294b7abf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56294b7abf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56294b7abf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56294da40f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56294a76db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56294a778be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56294a524c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56294a524c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56294a525738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56294a524874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56294a524874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56294a524874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56294ee2eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56294ee37928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56294ee1f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56294ee4a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff82bc10082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562948744b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0x65,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x5f,0x65,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x5f,0x65,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x5f,0x65,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b,0x3f,0x2d,0x3f,0x2b,0x3f,0x2b,0x3f,0x2b, Step #5: _e?+?+?+?+?-?+?+?+?+?+?-?+?+?+?-?+?+?+?-?+?+?+?-?+?+?+?-?+?+?+?-?+?+?+?-?+?+_e?+?+?+?+?-?+?+?+?+?+?-?+?+?+?-?+?+?-?+?+?+?-?+?+?+_e?+?+?+?+?-?+?+?+?+?+?-?+?+?+?-?+?+?+?-?+?+?+?-?+?+?+?-?+?+?+?-?+?+?+?-?+?+_e?+?+?+?+?-?+?+?+?+?+?-?+?+?+?-?+?+?-?+?+?+?-?+?+?+ Step #5: artifact_prefix='./'; Test unit written to ./oom-738ba91259cc991cd521c69f426055c4d42698b0 Step #5: Base64: X2U/Kz8rPys/Kz8tPys/Kz8rPys/Kz8tPys/Kz8rPy0/Kz8rPys/LT8rPys/Kz8tPys/Kz8rPy0/Kz8rPys/LT8rPys/Kz8tPys/K19lPys/Kz8rPys/LT8rPys/Kz8rPys/LT8rPys/Kz8tPys/Kz8tPys/Kz8rPy0/Kz8rPytfZT8rPys/Kz8rPy0/Kz8rPys/Kz8rPy0/Kz8rPys/LT8rPys/Kz8tPys/Kz8rPy0/Kz8rPys/LT8rPys/Kz8tPys/Kz8rPy0/Kz8rX2U/Kz8rPys/Kz8tPys/Kz8rPys/Kz8tPys/Kz8rPy0/Kz8rPy0/Kz8rPys/LT8rPys/Kw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5132 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 39461672 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dbb711b810, 0x55dbb730501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dbb7305020,0x55dbb919d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/738ba91259cc991cd521c69f426055c4d42698b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6507 processed earlier; will process 4522 files now Step #5: #1 pulse cov: 4104 ft: 4105 exec/s: 0 rss: 176Mb Step #5: ==184828== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dbadc109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dbb4275898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dbb42585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dbb42584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dbadc16d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dbadb77b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dbadb72355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dbadc08c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dbb0bd7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dbb0bd7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dbb0bd7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dbb0bd7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dbb0bd7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dbb0bd7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dbb0bd7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dbb0bd7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dbb0bd7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dbb0bd7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dbb2e6cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dbafb99b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dbafba4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dbaf950c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dbaf950c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dbaf951738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dbaf950874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dbaf950874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dbaf950874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dbb425aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dbb4263928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dbb424b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dbb4276112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ea0c40082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dbadb70b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7e,0x24,0x2d,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x76,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x29,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x3d,0x2d,0x3d,0x0,0x24, Step #5: ~$-\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000v\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\002\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000)\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000=-=\000$ Step #5: artifact_prefix='./'; Test unit written to ./oom-d448264c3b23e6e4596378b40f4b27af88376d2c Step #5: Base64: fiQtAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB2AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACkAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA9LT0AJA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5133 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 40035883 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f14566e810, 0x55f14585801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f145858020,0x55f1476f00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d448264c3b23e6e4596378b40f4b27af88376d2c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6509 processed earlier; will process 4520 files now Step #5: ==184864== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f13c1639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f1427c8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1427ab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1427ab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f13c169d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f13c0cab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f13c0c5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f13c15bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f13f12af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f13f12af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f13f12af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f13f12af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f13f12af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f13f12af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f13f12af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f13f12af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f13f12af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f13f12af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f1413bff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f13e0ecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f13e0f7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f13dea3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f13dea3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f13dea4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f13dea3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f13dea3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f13dea3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f1427adabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f1427b6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f14279e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f1427c9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f737e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f13c0c3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9,0x5c,0x9, Step #5: \\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011\\\011 Step #5: artifact_prefix='./'; Test unit written to ./oom-2f71fd0db6df5fb433847b0fbe2845f68a4e31ad Step #5: Base64: XAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCVwJXAlcCQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5134 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 40564320 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558cbc002810, 0x558cbc1ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558cbc1ec020,0x558cbe0840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f71fd0db6df5fb433847b0fbe2845f68a4e31ad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6510 processed earlier; will process 4519 files now Step #5: #1 pulse cov: 3854 ft: 3855 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4561 ft: 4924 exec/s: 0 rss: 177Mb Step #5: ==184900== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558cb2af79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558cb915c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558cb913f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558cb913f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558cb2afdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558cb2a5eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558cb2a59355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558cb2aefc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558cb5abef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558cb5abef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558cb5abef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558cb5abef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558cb5abef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558cb5abef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558cb5abef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558cb5abef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558cb5abef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558cb5abef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558cb7d53f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558cb4a80b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558cb4a8bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558cb4837c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558cb4837c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558cb4838738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558cb4837874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558cb4837874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558cb4837874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558cb9141abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558cb914a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558cb9132699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558cb915d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3fdf6da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558cb2a57b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x73,0x41,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x35,0x55,0x55,0x55,0x55,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x30,0x32,0x32,0x31,0x37,0x32,0x33,0x34,0x39,0x30,0xe6,0xbb,0xbf,0x55,0x55,0x2d,0x31,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0xe6,0xbb,0xbf,0x55,0x55,0x2d,0x2d,0x34,0x34,0x34,0x34,0x34,0x34,0x32,0x35,0x39,0x39,0x37,0x37,0x30,0x30,0x33,0x37,0x30,0x37,0x33,0x34,0x38,0x39,0x32,0x38,0x32,0x37,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0xe6,0xbb,0xbf,0x69,0x55,0x45,0x4c,0x45,0x4d,0x45,0x4e,0x54,0x55,0x55,0x55,0x55,0x55,0x55,0xe6,0xbb,0xbf,0x55,0x55,0x2d,0x31,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0xe6,0xbb,0xbf,0x55,0x55,0x2d,0x2d,0x34,0x34,0x34,0x34,0x34,0x34,0x32,0x35,0x39,0x39,0x37,0x37,0x30,0x30,0x33,0x37,0x30,0x37,0x33,0x34,0x38,0x39,0x32,0x38,0x32,0x37,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0xe6,0xbb,0xbf,0x69,0xcc,0x9c,0x55,0x45,0x4c,0x45,0x4d,0x45,0x4e,0x54,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x34,0x34,0x34,0x34,0x7a,0x34,0x34,0x34,0x34,0x34,0x34,0x34,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x4f,0x34,0x34,0x34,0x34,0x33,0x37,0x38,0x39,0xe6,0xbb,0xbf,0x69,0xcc, Step #5: %sA444444444445UUUU000000000000000000221723490\346\273\277UU-1UUUUUUUUUUUUUUUUUUU\346\273\277UU--44444425997700370734892827UUUUUUUUU\346\273\277iUELEMENTUUUUUU\346\273\277UU-1UUUUUUUUUUUUUUUUUUU\346\273\277UU--44444425997700370734892827UUUUUUUUU\346\273\277i\314\234UELEMENTUUUUUUU4444z4444444OOOOOOOOOO44443789\346\273\277i\314 Step #5: artifact_prefix='./'; Test unit written to ./oom-1ead0a535b85241cfbee7e9f10872400c1451aa7 Step #5: Base64: JXNBNDQ0NDQ0NDQ0NDQ1VVVVVTAwMDAwMDAwMDAwMDAwMDAwMDIyMTcyMzQ5MOa7v1VVLTFVVVVVVVVVVVVVVVVVVVVVVVVV5ru/VVUtLTQ0NDQ0NDI1OTk3NzAwMzcwNzM0ODkyODI3VVVVVVVVVVVV5ru/aVVFTEVNRU5UVVVVVVVV5ru/VVUtMVVVVVVVVVVVVVVVVVVVVVVVVVXmu79VVS0tNDQ0NDQ0MjU5OTc3MDAzNzA3MzQ4OTI4MjdVVVVVVVVVVVXmu79pzJxVRUxFTUVOVFVVVVVVVVU0NDQ0ejQ0NDQ0NDRPT09PT09PT09PNDQ0NDM3ODnmu79pzA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5135 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 41183368 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55740c8d6810, 0x55740cac001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55740cac0020,0x55740e9580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ead0a535b85241cfbee7e9f10872400c1451aa7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6513 processed earlier; will process 4516 files now Step #5: ==184936== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5574033cb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557409a30898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557409a135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557409a134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5574033d1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557403332b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55740332d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5574033c3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557406392f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557406392f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557406392f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557406392f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557406392f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557406392f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557406392f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557406392f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557406392f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557406392f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557408627f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557405354b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55740535fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55740510bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55740510bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55740510c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55740510b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55740510b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55740510b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557409a15abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557409a1e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557409a06699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557409a31112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffba3321082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55740332bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65,0x2c,0x22,0x22,0x3a,0x74,0x72,0x75,0x65, Step #5: {\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true,\"\":true Step #5: artifact_prefix='./'; Test unit written to ./oom-e0ca3284c205e174d2ef8c48614f449f43cc7c35 Step #5: Base64: eyIiOnRydWUsIiI6dHJ1ZSwiIjp0cnVlLCIiOnRydWUsIiI6dHJ1ZSwiIjp0cnVlLCIiOnRydWUsIiI6dHJ1ZSwiIjp0cnVlLCIiOnRydWUsIiI6dHJ1ZSwiIjp0cnVlLCIiOnRydWUsIiI6dHJ1ZSwiIjp0cnVlLCIiOnRydWUsIiI6dHJ1ZSwiIjp0cnVlLCIiOnRydWUsIiI6dHJ1ZSwiIjp0cnVlLCIiOnRydWUsIiI6dHJ1ZSwiIjp0cnVlLCIiOnRydWUsIiI6dHJ1ZSwiIjp0cnVlLCIiOnRydWUsIiI6dHJ1ZSwiIjp0cnVlLCIiOnRydWUsIiI6dHJ1ZQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5136 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 41724780 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561da0302810, 0x561da04ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561da04ec020,0x561da23840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e0ca3284c205e174d2ef8c48614f449f43cc7c35' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6514 processed earlier; will process 4515 files now Step #5: ==184972== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d96df79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d9d45c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d9d43f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d9d43f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d96dfdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d96d5eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d96d59355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d96defc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d99dbef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d99dbef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d99dbef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d99dbef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d99dbef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d99dbef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d99dbef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d99dbef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d99dbef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d99dbef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d9c053f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d98d80b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d98d8bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d98b37c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d98b37c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d98b38738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d98b37874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d98b37874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d98b37874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d9d441abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d9d44a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d9d432699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d9d45d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe455993082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d96d57b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x80,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x80,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x83,0xdf,0x80,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x84,0xdf,0x83,0xdf,0x84,0xdf,0x83,0xdf,0x84, Step #5: \337\203\337\204\337\203\337\204\337\203\337\204\337\204\337\203\337\204\337\203\337\203\337\204\337\203\337\204\337\203\337\204\337\203\337\203\337\204\337\204\337\203\337\204\337\203\337\200\337\204\337\203\337\204\337\203\337\204\337\203\337\204\337\204\337\204\337\204\337\204\337\203\337\204\337\204\337\204\337\203\337\204\337\204\337\203\337\203\337\204\337\203\337\204\337\203\337\204\337\203\337\200\337\204\337\203\337\204\337\204\337\204\337\203\337\203\337\204\337\203\337\204\337\204\337\204\337\204\337\203\337\204\337\204\337\204\337\203\337\204\337\204\337\203\337\204\337\203\337\204\337\204\337\204\337\204\337\204\337\203\337\204\337\204\337\203\337\204\337\204\337\204\337\203\337\204\337\204\337\203\337\203\337\200\337\204\337\203\337\204\337\203\337\204\337\204\337\203\337\204\337\203\337\204\337\204\337\204\337\203\337\204\337\204\337\203\337\204\337\204\337\204\337\203\337\204\337\204\337\204\337\203\337\204\337\204\337\203\337\204\337\204\337\203\337\204\337\204\337\203\337\204\337\203\337\204 Step #5: artifact_prefix='./'; Test unit written to ./oom-91ce1c558cae2207ab1fc53520e61c6d206a8390 Step #5: Base64: 34PfhN+D34Tfg9+E34Tfg9+E34Pfg9+E34PfhN+D34Tfg9+D34TfhN+D34Tfg9+A34Tfg9+E34PfhN+D34TfhN+E34TfhN+D34TfhN+E34PfhN+E34Pfg9+E34PfhN+D34Tfg9+A34Tfg9+E34TfhN+D34PfhN+D34TfhN+E34Tfg9+E34TfhN+D34TfhN+D34Tfg9+E34TfhN+E34Tfg9+E34Tfg9+E34TfhN+D34TfhN+D34PfgN+E34PfhN+D34TfhN+D34Tfg9+E34TfhN+D34TfhN+D34TfhN+E34PfhN+E34Tfg9+E34Tfg9+E34Tfg9+E34Tfg9+E34PfhA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5137 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 42261895 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557bc1e9c810, 0x557bc208601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557bc2086020,0x557bc3f1e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/91ce1c558cae2207ab1fc53520e61c6d206a8390' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6515 processed earlier; will process 4514 files now Step #5: ==185008== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557bb89919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557bbeff6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557bbefd95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557bbefd94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557bb8997d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557bb88f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557bb88f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557bb8989c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557bbb958f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557bbb958f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557bbb958f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557bbb958f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557bbb958f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557bbb958f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557bbb958f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557bbb958f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557bbb958f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557bbb958f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557bbdbedf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557bba91ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557bba925be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557bba6d1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557bba6d1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557bba6d2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557bba6d1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557bba6d1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557bba6d1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557bbefdbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557bbefe4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557bbefcc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557bbeff7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8c40ed4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557bb88f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60,0x43,0x60, Step #5: C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C`C` Step #5: artifact_prefix='./'; Test unit written to ./oom-83d427fa5f7ce4a0a40e48a0e34914200957b9df Step #5: Base64: Q2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYENgQ2BDYA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5138 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 42957910 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d0298d810, 0x563d02b7701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d02b77020,0x563d04a0f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/83d427fa5f7ce4a0a40e48a0e34914200957b9df' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6516 processed earlier; will process 4513 files now Step #5: #1 pulse cov: 3881 ft: 3882 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4056 ft: 4256 exec/s: 0 rss: 179Mb Step #5: ==185044== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563cf94829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563cffae7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563cffaca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563cffaca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563cf9488d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563cf93e9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563cf93e4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563cf947ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563cfc449f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563cfc449f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563cfc449f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563cfc449f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563cfc449f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563cfc449f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563cfc449f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563cfc449f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563cfc449f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563cfc449f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563cfe6def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563cfb40bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563cfb416be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563cfb1c2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563cfb1c2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563cfb1c3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563cfb1c2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563cfb1c2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563cfb1c2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563cffaccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563cffad5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563cffabd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563cffae8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1f923ba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563cf93e2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x6f,0x6e,0x69,0x6f,0x6e,0x2d,0x6b,0x65,0x79,0xa,0x2d,0x2d,0x2d,0x2d,0x2d,0x42,0x45,0x47,0x49,0x4e,0x20,0x52,0x53,0x41,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x4b,0x45,0x59,0x2d,0x2d,0x2d,0x2d,0x2d,0xa,0x4d,0x49,0x47,0x4a,0x41,0x6f,0x47,0x42,0x41,0x4c,0x67,0x62,0x65,0x58,0x68,0x51,0x66,0x41,0x6d,0x68,0x71,0x41,0x54,0x4d,0x44,0x42,0x58,0x64,0x66,0x78,0x78,0x5a,0x4d,0x2b,0x45,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x56,0x55,0x55,0x55,0x55,0x55,0x65,0x55,0x55,0x55,0x55,0x56,0x57,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x56,0x55,0x55,0x55,0x54,0x56,0x55,0x55,0x77,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x45,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x54,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x54,0x61,0x78,0x78,0x43,0x31,0x54,0x6f,0x4a,0x73,0x6d,0x55,0x54,0x61,0x78,0x78,0x43,0x30,0x54,0x6f,0x4a,0x73,0x6d,0x72,0x4e,0x4f,0x76,0x78,0x51,0x58,0x30,0x6d,0x55,0x6c,0x69,0x2f,0x2b,0x53,0x52,0x48,0x48,0x67,0x78,0x58,0x78,0x77,0x55,0x50,0x2f,0x65,0x30,0x55,0x66,0x67,0x70,0x41,0x67,0x4d,0x42,0x61,0x41,0x45,0x2d,0x2d,0x2d,0x2d,0x2d,0x45,0x4e,0x44,0x20,0x52,0x53,0x41,0x20,0x50,0x55,0x42,0x4c,0x49,0x43,0x20,0x4b,0x45,0x59,0x2d,0x2d,0x2d,0x2d,0x2d, Step #5: onion-key\012-----BEGIN RSA PUBLIC KEY-----\012MIGJAoGBALgbeXhQfAmhqATMDBXdfxxZM+EUUUUUUUVUUUUUeUUUUVWUUUUUUUUUVUUUTVUUwUUUUUUUUUUUUUUEUUUUUUUUUUUUUUUUUUUUUUUTUUUUUUUUUUUUUTaxxC1ToJsmUTaxxC0ToJsmrNOvxQX0mUli/+SRHHgxXxwUP/e0UfgpAgMBaAE-----END RSA PUBLIC KEY----- Step #5: artifact_prefix='./'; Test unit written to ./oom-88ddc7c9a084a29939be118cab290d6917676932 Step #5: Base64: b25pb24ta2V5Ci0tLS0tQkVHSU4gUlNBIFBVQkxJQyBLRVktLS0tLQpNSUdKQW9HQkFMZ2JlWGhRZkFtaHFBVE1EQlhkZnh4Wk0rRVVVVVVVVVVWVVVVVVVlVVVVVVZXVVVVVVVVVVVVVlVVVVRWVVV3VVVVVVVVVVVVVVVVVVVFVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVUVVVVVVVVVVVVVVVVVVRheHhDMVRvSnNtVVRheHhDMFRvSnNtck5PdnhRWDBtVWxpLytTUkhIZ3hYeHdVUC9lMFVmZ3BBZ01CYUFFLS0tLS1FTkQgUlNBIFBVQkxJQyBLRVktLS0tLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5139 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 43574361 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55faee320810, 0x55faee50a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55faee50a020,0x55faf03a20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88ddc7c9a084a29939be118cab290d6917676932' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6519 processed earlier; will process 4510 files now Step #5: ==185080== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fae4e159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55faeb47a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55faeb45d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55faeb45d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fae4e1bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fae4d7cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fae4d77355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fae4e0dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fae7ddcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fae7ddcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fae7ddcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fae7ddcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fae7ddcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fae7ddcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fae7ddcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fae7ddcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fae7ddcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fae7ddcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55faea071f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fae6d9eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fae6da9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fae6b55c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fae6b55c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fae6b56738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fae6b55874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fae6b55874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fae6b55874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55faeb45fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55faeb468928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55faeb450699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55faeb47b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f022ad6a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fae4d75b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0xa,0x5c,0x5c,0x5c,0xa,0xa,0xa,0x5c,0x5c,0xa,0x5c,0x5c,0xa,0x5c,0x5c,0xa,0x5c,0xa,0x5c,0xa,0x5c,0xa,0x5c,0x5c,0xa,0x5c,0xa,0x5c,0xa,0xa,0xa,0x5c,0x5c,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0xa,0x5c,0xa,0x5c,0x5c,0xa,0x5c,0x5c,0x5c,0xa,0xa,0x5c,0x5c,0x5c,0xa,0xa,0xa,0x5c,0x5c,0xa,0x5c,0xa,0xa,0x5c,0x5c,0xa,0xa,0x5c,0xa,0x5c,0x5c,0x5c,0xa,0x5c,0x5c,0x5c,0xa,0x5c,0x5c,0xa,0xa,0xa,0xa,0xa,0x5c,0x5c,0xa,0x5c,0x5c,0xa,0xa,0x5c,0x5c,0x5c,0xa,0xa,0xa,0x5c,0xa,0x5c,0x5c,0xa,0x5c,0xa,0x5c,0x5c,0xa,0x5c,0xa,0xa,0x5c,0xa,0x5c,0xa,0x5c,0xa,0xa,0x5c,0x5c,0xa,0x5c,0xa,0xa,0xa,0x5c,0xa,0xa,0x5c,0x5c,0xa,0x5c,0xa,0xa,0x5c,0xa,0xa,0xa,0x5c,0xa,0x5c,0x5c,0xa,0x5c,0x5c,0x5c,0xa,0xa,0x5c,0x5c,0x5c,0xa,0xa,0xa,0x5c,0x5c,0xa,0x5c,0xa,0x5c,0x5c,0xa,0x5c,0xa,0xa,0xa,0x5c,0x5c,0x5c,0xa,0xa,0x5c,0x5c,0x5c,0xa,0x5c,0x5c,0xa,0xa,0xa,0xa,0xa,0x5c,0x5c,0xa,0x5c,0x5c,0xa,0xa,0x5c,0x5c,0x5c,0xa,0xa,0xa,0x5c,0xa,0x5c,0x5c,0xa,0x5c,0xa,0x5c,0x5c,0xa,0x5c,0xa,0xa,0x5c,0xa,0x5c,0xa,0x5c,0xa,0xa,0x5c,0x5c,0xa,0x5c,0xa,0xa,0xa,0x5c,0xa,0xa,0x5c,0x5c,0xa,0x5c,0xa,0xa,0xa,0x5c,0x5c,0xa,0x5c,0x5c,0x5c,0x5c,0xa,0x5c,0x5c,0xa,0x5c,0xa,0xa,0xa,0x5c,0x5c,0xa,0xa,0x5c,0xa,0xa,0xa,0xa, Step #5: \\\012\\\\\\\012\012\012\\\\\012\\\\\012\\\\\012\\\012\\\012\\\012\\\\\012\\\012\\\012\012\012\\\\\012\\\012\012\\\012\012\012\\\012\\\\\012\\\\\\\012\012\\\\\\\012\012\012\\\\\012\\\012\012\\\\\012\012\\\012\\\\\\\012\\\\\\\012\\\\\012\012\012\012\012\\\\\012\\\\\012\012\\\\\\\012\012\012\\\012\\\\\012\\\012\\\\\012\\\012\012\\\012\\\012\\\012\012\\\\\012\\\012\012\012\\\012\012\\\\\012\\\012\012\\\012\012\012\\\012\\\\\012\\\\\\\012\012\\\\\\\012\012\012\\\\\012\\\012\\\\\012\\\012\012\012\\\\\\\012\012\\\\\\\012\\\\\012\012\012\012\012\\\\\012\\\\\012\012\\\\\\\012\012\012\\\012\\\\\012\\\012\\\\\012\\\012\012\\\012\\\012\\\012\012\\\\\012\\\012\012\012\\\012\012\\\\\012\\\012\012\012\\\\\012\\\\\\\\\012\\\\\012\\\012\012\012\\\\\012\012\\\012\012\012\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-d97f7f7bc85d5e28e024f0bc04d78ee9b6711853 Step #5: Base64: XApcXFwKCgpcXApcXApcXApcClwKXApcXApcClwKCgpcXApcCgpcCgoKXApcXApcXFwKClxcXAoKClxcClwKClxcCgpcClxcXApcXFwKXFwKCgoKClxcClxcCgpcXFwKCgpcClxcClwKXFwKXAoKXApcClwKClxcClwKCgpcCgpcXApcCgpcCgoKXApcXApcXFwKClxcXAoKClxcClwKXFwKXAoKClxcXAoKXFxcClxcCgoKCgpcXApcXAoKXFxcCgoKXApcXApcClxcClwKClwKXApcCgpcXApcCgoKXAoKXFwKXAoKClxcClxcXFwKXFwKXAoKClxcCgpcCgoKCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5140 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 44114566 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cdaa9c0810, 0x55cdaabaa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cdaabaa020,0x55cdaca420e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d97f7f7bc85d5e28e024f0bc04d78ee9b6711853' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6520 processed earlier; will process 4509 files now Step #5: ==185116== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cda14b59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cda7b1a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cda7afd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cda7afd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cda14bbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cda141cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cda1417355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cda14adc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cda447cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cda447cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cda447cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cda447cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cda447cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cda447cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cda447cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cda447cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cda447cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cda447cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cda6711f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cda343eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cda3449be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cda31f5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cda31f5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cda31f6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cda31f5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cda31f5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cda31f5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cda7affabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cda7b08928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cda7af0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cda7b1b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f77262d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cda1415b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85,0xc2,0x85, Step #5: \302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205\302\205 Step #5: artifact_prefix='./'; Test unit written to ./oom-52bd98bac028b74904e80a9a19ece2a5bf0865a2 Step #5: Base64: woXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChcKFwoXChQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5141 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 44628547 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b4c8f4810, 0x561b4cade01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b4cade020,0x561b4e9760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/52bd98bac028b74904e80a9a19ece2a5bf0865a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6521 processed earlier; will process 4508 files now Step #5: ==185152== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561b433e99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b49a4e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b49a315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b49a314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b433efd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b43350b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b4334b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b433e1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b463b0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b463b0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b463b0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b463b0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b463b0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b463b0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b463b0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b463b0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b463b0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b463b0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b48645f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b45372b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b4537dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b45129c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b45129c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b4512a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b45129874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b45129874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b45129874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b49a33abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b49a3c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b49a24699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b49a4f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fae60dd7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b43349b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd2,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xca,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd2,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xca,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd2,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xca,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd2,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xca,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd2,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xca,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd2,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xca,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd2,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xca,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd2,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xca,0x88,0xa,0x6,0x62,0x4,0xa,0x2,0xd3,0x88, Step #5: \012\006b\004\012\002\323\210\012\006b\004\012\002\322\210\012\006b\004\012\002\312\210\012\006b\004\012\002\323\210\012\006b\004\012\002\323\210\012\006b\004\012\002\322\210\012\006b\004\012\002\312\210\012\006b\004\012\002\323\210\012\006b\004\012\002\323\210\012\006b\004\012\002\322\210\012\006b\004\012\002\312\210\012\006b\004\012\002\323\210\012\006b\004\012\002\323\210\012\006b\004\012\002\322\210\012\006b\004\012\002\312\210\012\006b\004\012\002\323\210\012\006b\004\012\002\323\210\012\006b\004\012\002\322\210\012\006b\004\012\002\312\210\012\006b\004\012\002\323\210\012\006b\004\012\002\323\210\012\006b\004\012\002\322\210\012\006b\004\012\002\312\210\012\006b\004\012\002\323\210\012\006b\004\012\002\323\210\012\006b\004\012\002\322\210\012\006b\004\012\002\312\210\012\006b\004\012\002\323\210\012\006b\004\012\002\323\210\012\006b\004\012\002\322\210\012\006b\004\012\002\312\210\012\006b\004\012\002\323\210 Step #5: artifact_prefix='./'; Test unit written to ./oom-6879b837202a6f72c4e9dcb13b4407b633e56d55 Step #5: Base64: CgZiBAoC04gKBmIECgLSiAoGYgQKAsqICgZiBAoC04gKBmIECgLTiAoGYgQKAtKICgZiBAoCyogKBmIECgLTiAoGYgQKAtOICgZiBAoC0ogKBmIECgLKiAoGYgQKAtOICgZiBAoC04gKBmIECgLSiAoGYgQKAsqICgZiBAoC04gKBmIECgLTiAoGYgQKAtKICgZiBAoCyogKBmIECgLTiAoGYgQKAtOICgZiBAoC0ogKBmIECgLKiAoGYgQKAtOICgZiBAoC04gKBmIECgLSiAoGYgQKAsqICgZiBAoC04gKBmIECgLTiAoGYgQKAtKICgZiBAoCyogKBmIECgLTiA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5142 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 45168740 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560e855c4810, 0x560e857ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560e857ae020,0x560e876460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6879b837202a6f72c4e9dcb13b4407b633e56d55' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6522 processed earlier; will process 4507 files now Step #5: ==185188== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560e7c0b99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560e8271e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560e827015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560e827014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560e7c0bfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560e7c020b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560e7c01b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560e7c0b1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560e7f080f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560e7f080f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560e7f080f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560e7f080f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560e7f080f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560e7f080f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560e7f080f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560e7f080f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560e7f080f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560e7f080f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560e81315f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560e7e042b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560e7e04dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560e7ddf9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560e7ddf9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560e7ddfa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560e7ddf9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560e7ddf9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560e7ddf9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560e82703abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560e8270c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560e826f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560e8271f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc077390082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560e7c019b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0,0xa,0x6,0x3a,0x4,0xa,0x2,0xd6,0xb0, Step #5: \012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260\012\006:\004\012\002\326\260 Step #5: artifact_prefix='./'; Test unit written to ./oom-fcee2bf4d59d8214f117e502b933c18a34ac6dcc Step #5: Base64: CgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsAoGOgQKAtawCgY6BAoC1rAKBjoECgLWsA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5143 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 45701016 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b36f1d810, 0x555b3710701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b37107020,0x555b38f9f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fcee2bf4d59d8214f117e502b933c18a34ac6dcc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6523 processed earlier; will process 4506 files now Step #5: ==185224== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555b2da129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b34077898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b3405a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b3405a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b2da18d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b2d979b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b2d974355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b2da0ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b309d9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b309d9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b309d9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b309d9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b309d9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b309d9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b309d9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b309d9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b309d9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b309d9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b32c6ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b2f99bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b2f9a6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b2f752c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b2f752c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b2f753738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b2f752874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b2f752874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b2f752874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b3405cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b34065928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b3404d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b34078112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa8e80eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b2d972b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x24,0x33,0x34,0x30,0x32,0x38,0x32,0x33,0x36,0x36,0x39,0x32,0x30,0x39,0x33,0x38,0x34,0x36,0x33,0x34,0x36,0x33,0x33,0x37,0x34,0x36,0x30,0x37,0x34,0x33,0x31,0x27,0x27,0x27,0x2d,0x32,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x33,0x32,0x37,0x36,0x37,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x31,0x2d,0x27,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x31,0x2d,0x38,0x34,0x31,0x30,0x36,0x39,0x30,0x36,0x2d,0x27,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0xef,0xbd,0xb0,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x3d,0x3c,0x27,0x27,0x27,0x2f,0xf3,0xa0,0x81,0xa1,0x27,0x27,0x27,0x27,0x2f,0x27,0x27,0x27,0x27,0x27,0x27,0x2d,0x30,0x2d,0x3d,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x27,0x2e,0x27,0x27,0x27,0x27,0x2e,0x27,0x24,0x27,0x2d, Step #5: $340282366920938463463374607431'''-2=<''''''''''''-=<'''/''''/'''/''''/''32767-=''''''/''1-'='''''''''''''-=<''''''''''''-=<'''''''''1-84106906-'=''''''''''''\357\275\260'-=<''''''''''''-=<''''''''''''-=<''''''''''''-=<'''/\363\240\201\241''''/''''''-0-='''''''''''''.''''.'$'- Step #5: artifact_prefix='./'; Test unit written to ./oom-8a3135f6d04b44523ac1e7911344a5f973494a97 Step #5: Base64: JDM0MDI4MjM2NjkyMDkzODQ2MzQ2MzM3NDYwNzQzMScnJy0yPTwnJycnJycnJycnJyctPTwnJycvJycnJy8nJycvJycnJy8nJzMyNzY3LT0nJycnJycvJycxLSc9JycnJycnJycnJycnJy09PCcnJycnJycnJycnJy09PCcnJycnJycnJzEtODQxMDY5MDYtJz0nJycnJycnJycnJyfvvbAnLT08JycnJycnJycnJycnLT08JycnJycnJycnJycnLT08JycnJycnJycnJycnLT08JycnL/OggaEnJycnLycnJycnJy0wLT0nJycnJycnJycnJycnLicnJycuJyQnLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5144 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 46236200 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55be20960810, 0x55be20b4a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55be20b4a020,0x55be229e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8a3135f6d04b44523ac1e7911344a5f973494a97' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6524 processed earlier; will process 4505 files now Step #5: ==185260== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55be174559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55be1daba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55be1da9d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55be1da9d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55be1745bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55be173bcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55be173b7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55be1744dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55be1a41cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55be1a41cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55be1a41cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55be1a41cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55be1a41cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55be1a41cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55be1a41cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55be1a41cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55be1a41cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55be1a41cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55be1c6b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55be193deb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55be193e9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55be19195c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55be19195c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55be19196738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55be19195874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55be19195874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55be19195874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55be1da9fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55be1daa8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55be1da90699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55be1dabb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff58eaae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55be173b5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x25,0x44,0x74,0x2d,0xe7,0xbb,0xbf,0x76,0x56,0x55,0x53,0x2d,0x41,0xce,0x8c,0xce,0x8c,0x56,0x74,0xe7,0xbb,0xbf,0x76,0x56,0x56,0x44,0x74,0x53,0x4f,0x4c,0x55,0x44,0x45,0x57,0xce,0x8c,0x4f,0x4f,0x2d,0x49,0x4e,0xe7,0xbb,0x8c,0xce,0x8c,0x56,0x74,0xe7,0xbb,0xbf,0x76,0x56,0x56,0x56,0x56,0x56,0xce,0x8c,0xce,0x8c,0x4f,0x4f,0x4f,0x4e,0x49,0x2d,0xe7,0xbb,0xbf,0x44,0x45,0x57,0xce,0x8c,0x4f,0x4f,0x2d,0x49,0x4e,0xe7,0xbb,0xbf,0x76,0x76,0x55,0x53,0x2d,0x41,0xce,0x8c,0xce,0x8c,0x56,0x74,0xe7,0xb1,0xbf,0x76,0x56,0x56,0x52,0x56,0xce,0x8c,0xce,0x8c,0x56,0x73,0xe7,0xbb,0xbf,0x76,0x56,0x56,0x44,0x55,0x53,0x2d,0x41,0xce,0x8c,0xce,0x8c,0x56,0x6b,0xe7,0xbb,0xbf,0x2d,0x2d,0x76,0x56,0x56,0x56,0x56,0x56,0xce,0x8c,0xce,0x8c,0x56,0x74,0xe7,0xbb,0xbf,0xe7,0xbb,0xbf,0xce,0x8c,0xce,0x8c,0x56,0x74,0xe7,0xbb,0xbf,0x76,0x56,0x56,0x56,0x56,0x56,0xce,0x8c,0xce,0x8c,0x4f,0x4f,0x4e,0x49,0x2d,0x41,0xce,0x8c,0xce,0x8c,0x56,0x74,0x53,0x4f,0x4c,0x55,0x44,0x45,0x57,0xce,0x8c,0x4f,0x4f,0x2d,0x49,0x4e,0xe7,0xbb,0xbf,0x76,0x76,0x55,0x53,0x2d,0x41,0xce,0x8c,0xce,0x8c,0x56,0x74,0xe7,0xb1,0xbf,0x76,0x56,0x56,0x52,0x56,0x56,0xce,0x8c,0xce,0x8c,0x56,0x74,0xe7,0xbb,0xbf,0xe7,0xbb,0xbf,0x76,0x56,0x2d,0xe7,0xbb,0xbf,0x76,0x56,0x58,0x2d,0x2d,0x76,0x56,0x56,0x56,0x56,0x56,0xce,0x8c,0xce,0x8c,0x56,0x74,0xe7,0xbb,0xbf, Step #5: %Dt-\347\273\277vVUS-A\316\214\316\214Vt\347\273\277vVVDtSOLUDEW\316\214OO-IN\347\273\214\316\214Vt\347\273\277vVVVVV\316\214\316\214OOONI-\347\273\277DEW\316\214OO-IN\347\273\277vvUS-A\316\214\316\214Vt\347\261\277vVVRV\316\214\316\214Vs\347\273\277vVVDUS-A\316\214\316\214Vk\347\273\277--vVVVVV\316\214\316\214Vt\347\273\277\347\273\277\316\214\316\214Vt\347\273\277vVVVVV\316\214\316\214OONI-A\316\214\316\214VtSOLUDEW\316\214OO-IN\347\273\277vvUS-A\316\214\316\214Vt\347\261\277vVVRVV\316\214\316\214Vt\347\273\277\347\273\277vV-\347\273\277vVX--vVVVVV\316\214\316\214Vt\347\273\277 Step #5: artifact_prefix='./'; Test unit written to ./oom-f2963493ba3bd4393cf836625785f1fa899e1f9c Step #5: Base64: JUR0Lee7v3ZWVVMtQc6MzoxWdOe7v3ZWVkR0U09MVURFV86MT08tSU7nu4zOjFZ057u/dlZWVlZWzozOjE9PT05JLee7v0RFV86MT08tSU7nu792dlVTLUHOjM6MVnTnsb92VlZSVs6MzoxWc+e7v3ZWVkRVUy1BzozOjFZr57u/LS12VlZWVlbOjM6MVnTnu7/nu7/OjM6MVnTnu792VlZWVlbOjM6MT09OSS1BzozOjFZ0U09MVURFV86MT08tSU7nu792dlVTLUHOjM6MVnTnsb92VlZSVlbOjM6MVnTnu7/nu792Vi3nu792VlgtLXZWVlZWVs6MzoxWdOe7vw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5145 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 46770698 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562bf5dd6810, 0x562bf5fc001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562bf5fc0020,0x562bf7e580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f2963493ba3bd4393cf836625785f1fa899e1f9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6525 processed earlier; will process 4504 files now Step #5: #1 pulse cov: 3950 ft: 3951 exec/s: 0 rss: 178Mb Step #5: ==185296== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562bec8cb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562bf2f30898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562bf2f135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562bf2f134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562bec8d1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562bec832b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562bec82d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562bec8c3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562bef892f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562bef892f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562bef892f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562bef892f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562bef892f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562bef892f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562bef892f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562bef892f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562bef892f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562bef892f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562bf1b27f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562bee854b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562bee85fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562bee60bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562bee60bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562bee60c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562bee60b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562bee60b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562bee60b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562bf2f15abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562bf2f1e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562bf2f06699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562bf2f31112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c56bdc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562bec82bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x73,0x76,0x67,0x3e,0x7d,0x7d,0x7d,0x3c,0x74,0x65,0x78,0x74,0x3e,0x36,0x35,0x36,0x36,0x33,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xe2,0x81,0xa7,0xe2,0x81,0xa7,0x5c,0x5e,0x34,0x3a,0x3a,0x2d,0x2d,0x46,0x46,0x46,0x46,0x46,0x46,0x45,0x45,0x65,0x78,0x74,0x3e,0x42,0x4f,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x36,0x35,0x35,0x33,0x36,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xe2,0x81,0xa7,0xe2,0x81,0xa7,0x5c,0x5e,0x34,0x3a,0x3a,0x2d,0x2d,0x46,0x46,0x46,0x46,0x46,0x46,0x45,0x45,0x65,0x78,0x74,0x3e,0x42,0x4f,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x36,0x35,0x35,0x33,0x36,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xe2,0x81,0xa7,0xe2,0x81,0xa7,0x5c,0x5e,0x34,0x3a,0x3a,0x2d,0x2d,0x46,0x46,0x46,0x46,0x46,0x46,0x45,0x45,0x65,0x78,0x74,0x3e,0x42,0x4f,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x74,0x65,0x78,0x74,0x3e,0x36,0x35,0x35,0x33,0x36,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xe2,0x81,0xa7,0xe2,0x81,0xa7,0x5c,0x5e,0x34,0x3a,0x3a,0x2d,0x2d,0x46,0x46,0x46,0x46,0x46,0x46,0x45,0x45,0x65,0x78,0x74,0x3e,0x42,0x4f,0x3c,0x2f,0x74,0x65,0x78,0x74,0x3e,0x3c,0x2f,0x73,0x76,0x67,0x3e,0x3c,0x73,0x76,0x67,0x3e,0x7d,0x7d,0x7d,0x3c,0x74,0x65,0x78,0x74,0x3e,0x36,0x35,0x35,0x33,0x36,0x3d,0x3d,0x3d,0x3d,0x3d,0x3d,0xe2,0x81,0xa7,0xe2,0x81,0xa7,0x5c,0x5e,0x34,0x3a,0x3a,0x2d,0x2d, Step #5: <svg>}}}<text>65663======\342\201\247\342\201\247\\^4::--FFFFFFEEext>BO</text><text>65536======\342\201\247\342\201\247\\^4::--FFFFFFEEext>BO</text><text>65536======\342\201\247\342\201\247\\^4::--FFFFFFEEext>BO</text><text>65536======\342\201\247\342\201\247\\^4::--FFFFFFEEext>BO</text></svg><svg>}}}<text>65536======\342\201\247\342\201\247\\^4::-- Step #5: artifact_prefix='./'; Test unit written to ./oom-1a0d9e382e1d0128cc2b537dc419e85632bac4ba Step #5: Base64: PHN2Zz59fX08dGV4dD42NTY2Mz09PT09PeKBp+KBp1xeNDo6LS1GRkZGRkZFRWV4dD5CTzwvdGV4dD48dGV4dD42NTUzNj09PT09PeKBp+KBp1xeNDo6LS1GRkZGRkZFRWV4dD5CTzwvdGV4dD48dGV4dD42NTUzNj09PT09PeKBp+KBp1xeNDo6LS1GRkZGRkZFRWV4dD5CTzwvdGV4dD48dGV4dD42NTUzNj09PT09PeKBp+KBp1xeNDo6LS1GRkZGRkZFRWV4dD5CTzwvdGV4dD48L3N2Zz48c3ZnPn19fTx0ZXh0PjY1NTM2PT09PT094oGn4oGnXF40OjotLQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5146 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 47351475 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d25158810, 0x564d2534201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d25342020,0x564d271da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1a0d9e382e1d0128cc2b537dc419e85632bac4ba' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6527 processed earlier; will process 4502 files now Step #5: ==185332== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d1bc4d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d222b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d222955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d222954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d1bc53d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d1bbb4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d1bbaf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d1bc45c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d1ec14f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d1ec14f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d1ec14f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d1ec14f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d1ec14f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d1ec14f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d1ec14f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d1ec14f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d1ec14f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d1ec14f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d20ea9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d1dbd6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d1dbe1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d1d98dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d1d98dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d1d98e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d1d98d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d1d98d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d1d98d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d22297abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d222a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d22288699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d222b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f62decde082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d1bbadb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3c,0x3f,0x70,0x68,0x70,0xa,0xa,0x76,0x61,0x72,0x5f,0x64,0x75,0x6d,0x70,0x28,0x61,0x72,0x72,0x61,0x79,0x5f,0x73,0x6c,0x69,0x63,0x65,0x28,0x61,0x72,0x72,0x61,0x79,0x3a,0x20,0x5b,0x31,0x2c,0x20,0x34,0x2c,0x20,0x35,0x5d,0x2c,0x20,0x6f,0x66,0x66,0x73,0x65,0x74,0x3a,0x20,0x32,0x2c,0x20,0x6c,0x65,0x6e,0x67,0x74,0x68,0x3a,0x20,0x32,0x29,0x29,0x3b,0xa,0x76,0x61,0x72,0x5f,0x64,0x75,0x6d,0x70,0x28,0x61,0x72,0x72,0x61,0x79,0x5f,0x73,0x6c,0x69,0x63,0x65,0x28,0x6c,0x65,0x6e,0x67,0x74,0x68,0x3a,0x20,0x32,0x2c,0x20,0x6f,0x66,0x66,0x73,0x65,0x74,0x3a,0x20,0x32,0x2c,0x20,0x61,0x72,0x72,0x61,0x79,0x3a,0x20,0x5b,0x31,0x2c,0x20,0x32,0x2c,0x20,0x33,0x2c,0x20,0x34,0x2c,0x20,0x35,0x5d,0x29,0x29,0x3b,0xa,0xa,0x76,0x61,0x72,0x5f,0x64,0x75,0x6d,0x70,0x28,0x61,0x72,0x72,0x61,0x79,0x5f,0x73,0x6c,0x69,0x63,0x65,0x28,0x61,0x72,0x72,0x61,0x79,0x3a,0x20,0x5b,0x27,0x61,0x27,0x20,0x3d,0x3e,0x20,0x30,0x2c,0x20,0x27,0x62,0x27,0x20,0x3d,0x3e,0x20,0x31,0x5d,0x2c,0x20,0x6f,0x66,0x66,0x73,0x65,0x74,0x3a,0x20,0x31,0x2c,0x20,0x70,0x72,0x65,0x73,0x65,0x72,0x76,0x65,0x5f,0x6b,0x65,0x79,0x73,0x3a,0x20,0x74,0x72,0x75,0x65,0x29,0x29,0x3b,0xa,0x76,0x61,0x72,0x5f,0x64,0x75,0x6d,0x70,0x28,0x61,0x72,0x72,0x61,0x79,0x5f,0x73,0x6c,0x69,0x63,0x65,0x28,0x5b,0x27,0x61,0x27,0x20,0x3d,0x3e,0x20,0x30,0x2c,0x20, Step #5: <?php\012\012var_dump(array_slice(array: [1, 4, 5], offset: 2, length: 2));\012var_dump(array_slice(length: 2, offset: 2, array: [1, 2, 3, 4, 5]));\012\012var_dump(array_slice(array: ['a' => 0, 'b' => 1], offset: 1, preserve_keys: true));\012var_dump(array_slice(['a' => 0, Step #5: artifact_prefix='./'; Test unit written to ./oom-edf72fa7931510e153bfb57b939fb3acebe2fccc Step #5: Base64: PD9waHAKCnZhcl9kdW1wKGFycmF5X3NsaWNlKGFycmF5OiBbMSwgNCwgNV0sIG9mZnNldDogMiwgbGVuZ3RoOiAyKSk7CnZhcl9kdW1wKGFycmF5X3NsaWNlKGxlbmd0aDogMiwgb2Zmc2V0OiAyLCBhcnJheTogWzEsIDIsIDMsIDQsIDVdKSk7Cgp2YXJfZHVtcChhcnJheV9zbGljZShhcnJheTogWydhJyA9PiAwLCAnYicgPT4gMV0sIG9mZnNldDogMSwgcHJlc2VydmVfa2V5czogdHJ1ZSkpOwp2YXJfZHVtcChhcnJheV9zbGljZShbJ2EnID0+IDAsIA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5147 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 47883018 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561998f44810, 0x56199912e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56199912e020,0x56199afc60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/edf72fa7931510e153bfb57b939fb3acebe2fccc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6528 processed earlier; will process 4501 files now Step #5: #1 pulse cov: 3506 ft: 3507 exec/s: 0 rss: 178Mb Step #5: ==185368== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56198fa399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56199609e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5619960815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5619960814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56198fa3fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56198f9a0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56198f99b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56198fa31c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561992a00f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561992a00f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561992a00f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561992a00f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561992a00f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561992a00f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561992a00f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561992a00f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561992a00f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561992a00f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561994c95f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5619919c2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5619919cdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561991779c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561991779c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56199177a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561991779874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561991779874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561991779874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561996083abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56199608c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561996074699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56199609f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb71be6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56198f999b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80,0xa,0x6,0x5a,0x4,0xa,0x2,0xdc,0x80, Step #5: \012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200\012\006Z\004\012\002\334\200 Step #5: artifact_prefix='./'; Test unit written to ./oom-795a6562189b532c9c9debcea461d47a43ddc98c Step #5: Base64: CgZaBAoC3IAKBloECgLcgAoGWgQKAtyACgZaBAoC3IAKBloECgLcgAoGWgQKAtyACgZaBAoC3IAKBloECgLcgAoGWgQKAtyACgZaBAoC3IAKBloECgLcgAoGWgQKAtyACgZaBAoC3IAKBloECgLcgAoGWgQKAtyACgZaBAoC3IAKBloECgLcgAoGWgQKAtyACgZaBAoC3IAKBloECgLcgAoGWgQKAtyACgZaBAoC3IAKBloECgLcgAoGWgQKAtyACgZaBAoC3IAKBloECgLcgAoGWgQKAtyACgZaBAoC3IAKBloECgLcgAoGWgQKAtyACgZaBAoC3IAKBloECgLcgA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5148 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 48469664 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5605ecd3e810, 0x5605ecf2801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5605ecf28020,0x5605eedc00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/795a6562189b532c9c9debcea461d47a43ddc98c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6530 processed earlier; will process 4499 files now Step #5: #1 pulse cov: 3988 ft: 3989 exec/s: 0 rss: 178Mb Step #5: ==185404== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5605e38339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605e9e98898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605e9e7b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605e9e7b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5605e3839d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605e379ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5605e3795355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5605e382bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605e67faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605e67faf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605e67faf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605e67faf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605e67faf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605e67faf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605e67faf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605e67faf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605e67faf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605e67faf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605e8a8ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5605e57bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5605e57c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5605e5573c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5605e5573c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5605e5574738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5605e5573874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5605e5573874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5605e5573874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605e9e7dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5605e9e86928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605e9e6e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605e9e99112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f49b9ff3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5605e3793b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x22,0xd9,0x82,0xdb,0x99,0xd3,0x8a,0xd9,0x82,0xdb,0x84,0xdd,0x9b,0xd3,0x82,0xdd,0x99,0xd3,0x8a,0xd9,0x84,0xd9,0x8a,0xd9,0x99,0xd3,0x8a,0xd9,0x9b,0xd3,0x84,0xdd,0x99,0xd3,0x8a,0xd8,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x82,0xdb,0x85,0xdd,0x9b,0xd3,0x82,0xd9,0x84,0xdd,0x99,0xd3,0x84,0xdd,0x9b,0xd3,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x82,0xdb,0x84,0xdd,0x9b,0xd3,0x82,0xd9,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x84,0xd9,0x8a,0xd9,0x99,0xd3,0x8a,0xd9,0x9b,0xd3,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x82,0xdb,0x84,0xdd,0x9b,0xd2,0x82,0xd9,0x84,0xdd,0x99,0xd9,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x99,0xd3,0x8a,0xd9,0x84,0xd9,0x99,0xd3,0x8a,0xd9,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x84,0xd9,0x8a,0xd9,0x99,0xd3,0x8a,0xd9,0x9b,0xd3,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x82,0xdb,0x99,0xd3,0x8a,0xd9,0x82,0xdb,0x84,0xdd,0x9b,0xd3,0x82,0xd9,0x84,0xdd,0x99,0xd3,0x84,0xdd,0x99,0xd3,0x99,0xd3,0x8a,0xd9,0x84,0xd9,0x84,0xd9,0x8a,0xd9,0x99,0xd3,0x8a,0xd9,0x8a,0xd9,0x84,0xd9,0x99,0xd3,0x8a,0xd9,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x84,0xd9,0x8a,0xd9,0x99,0xd3,0x8a,0xd9,0x9b,0xd3,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x84,0xdd,0x99,0xd3,0x8a,0xd9,0x82,0xdb,0x84,0xdd,0x9b,0xd3,0x8a,0xd9,0x84,0xd9,0xa4,0xd9,0x84,0xc3,0x84,0x9b, Step #5: \"\331\202\333\231\323\212\331\202\333\204\335\233\323\202\335\231\323\212\331\204\331\212\331\231\323\212\331\233\323\204\335\231\323\212\330\204\335\231\323\212\331\202\333\205\335\233\323\202\331\204\335\231\323\204\335\233\323\204\335\231\323\212\331\204\335\231\323\212\331\202\333\204\335\233\323\202\331\204\335\231\323\212\331\204\331\212\331\231\323\212\331\233\323\204\335\231\323\212\331\204\335\231\323\212\331\202\333\204\335\233\322\202\331\204\335\231\331\204\335\231\323\212\331\204\335\231\323\212\331\231\323\212\331\204\331\231\323\212\331\204\335\231\323\212\331\204\331\212\331\231\323\212\331\233\323\204\335\231\323\212\331\204\335\231\323\212\331\202\333\231\323\212\331\202\333\204\335\233\323\202\331\204\335\231\323\204\335\231\323\231\323\212\331\204\331\204\331\212\331\231\323\212\331\212\331\204\331\231\323\212\331\204\335\231\323\212\331\204\331\212\331\231\323\212\331\233\323\204\335\231\323\212\331\204\335\231\323\212\331\202\333\204\335\233\323\212\331\204\331\244\331\204\303\204\233 Step #5: artifact_prefix='./'; Test unit written to ./oom-a84e95b66c613c53b66e67ac0db4497a55169a4d Step #5: Base64: ItmC25nTitmC24Tdm9OC3ZnTitmE2YrZmdOK2ZvThN2Z04rYhN2Z04rZgtuF3ZvTgtmE3ZnThN2b04TdmdOK2YTdmdOK2YLbhN2b04LZhN2Z04rZhNmK2ZnTitmb04TdmdOK2YTdmdOK2YLbhN2b0oLZhN2Z2YTdmdOK2YTdmdOK2ZnTitmE2ZnTitmE3ZnTitmE2YrZmdOK2ZvThN2Z04rZhN2Z04rZgtuZ04rZgtuE3ZvTgtmE3ZnThN2Z05nTitmE2YTZitmZ04rZitmE2ZnTitmE3ZnTitmE2YrZmdOK2ZvThN2Z04rZhN2Z04rZgtuE3ZvTitmE2aTZhMOEmw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5149 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 49054580 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557abf559810, 0x557abf74301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557abf743020,0x557ac15db0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a84e95b66c613c53b66e67ac0db4497a55169a4d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6532 processed earlier; will process 4497 files now Step #5: #1 pulse cov: 10451 ft: 10452 exec/s: 0 rss: 199Mb Step #5: ==185440== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557ab604e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557abc6b3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557abc6965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557abc6964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557ab6054d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557ab5fb5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557ab5fb0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557ab6046c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557ab9015f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557ab9015f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557ab9015f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557ab9015f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557ab9015f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557ab9015f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557ab9015f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557ab9015f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557ab9015f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557ab9015f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557abb2aaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557ab7fd7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557ab7fe2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557ab7d8ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557ab7d8ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557ab7d8f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557ab7d8e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557ab7d8e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557ab7d8e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557abc698abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557abc6a1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557abc689699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557abc6b4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcd7ff00082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557ab5faeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa,0xd,0xa, Step #5: \015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012\015\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-3e4a04de958de30f2a92f444cb53f1fb99d629c1 Step #5: Base64: DQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5150 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 49707983 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561102edf810, 0x5611030c901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5611030c9020,0x561104f610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3e4a04de958de30f2a92f444cb53f1fb99d629c1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6534 processed earlier; will process 4495 files now Step #5: ==185476== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5610f99d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561100039898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56110001c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56110001c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610f99dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610f993bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610f9936355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610f99ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610fc99bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610fc99bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610fc99bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610fc99bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610fc99bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610fc99bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610fc99bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610fc99bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610fc99bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610fc99bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610fec30f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610fb95db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610fb968be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610fb714c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610fb714c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610fb715738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610fb714874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610fb714874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610fb714874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56110001eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561100027928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56110000f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56110003a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6af7568082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610f9934b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64,0x5c,0x64, Step #5: \\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d\\d Step #5: artifact_prefix='./'; Test unit written to ./oom-569bc1a23d52635a78c47fa44edfdcec4629a0a7 Step #5: Base64: XGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZFxkXGRcZA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5151 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 50233348 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562655d12810, 0x562655efc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562655efc020,0x562657d940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/569bc1a23d52635a78c47fa44edfdcec4629a0a7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6535 processed earlier; will process 4494 files now Step #5: ==185512== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56264c8079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562652e6c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562652e4f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562652e4f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56264c80dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56264c76eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56264c769355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56264c7ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56264f7cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56264f7cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56264f7cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56264f7cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56264f7cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56264f7cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56264f7cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56264f7cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56264f7cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56264f7cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562651a63f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56264e790b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56264e79bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56264e547c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56264e547c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56264e548738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56264e547874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56264e547874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56264e547874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562652e51abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562652e5a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562652e42699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562652e6d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f26aeda5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56264c767b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60,0x5f,0x60, Step #5: _`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_`_` Step #5: artifact_prefix='./'; Test unit written to ./oom-ea9dc5c2280961b2248e7b36d6f466fcaf90892f Step #5: Base64: X2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYF9gX2BfYA== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5152 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 50926320 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562eb7ae0810, 0x562eb7cca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562eb7cca020,0x562eb9b620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ea9dc5c2280961b2248e7b36d6f466fcaf90892f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6536 processed earlier; will process 4493 files now Step #5: ==185548== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562eae5d59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562eb4c3a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562eb4c1d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562eb4c1d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562eae5dbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562eae53cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562eae537355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562eae5cdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562eb159cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562eb159cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562eb159cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562eb159cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562eb159cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562eb159cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562eb159cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562eb159cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562eb159cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562eb159cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562eb3831f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562eb055eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562eb0569be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562eb0315c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562eb0315c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562eb0316738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562eb0315874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562eb0315874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562eb0315874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562eb4c1fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562eb4c28928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562eb4c10699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562eb4c3b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4d5b33a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562eae535b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xd3,0xb2,0xc7,0xa9,0xda,0xbd,0xd6,0xa9,0xda,0x8b,0xda,0x9a,0xd3,0xb2,0xc7,0xa9,0xda,0xbd,0xc6,0xb2,0xd6,0xbd,0xda,0xbd,0xd3,0xb2,0xcf,0xa9,0xde,0xbd,0xd3,0x8a,0xda,0xbd,0xda,0xb2,0xd6,0xa9,0xda,0xbd,0xd3,0xb2,0xc7,0xb2,0xd9,0xa9,0xd3,0xb2,0xcf,0xa9,0xde,0xbd,0xd3,0x8a,0xda,0xbd,0xda,0xb2,0xd6,0xa9,0xda,0xbd,0xd3,0xb2,0xc7,0xb2,0xd9,0xa9,0xda,0xbd,0xc7,0xb2,0xd6,0x99,0xd3,0xb2,0xc7,0x89,0xda,0xbd,0xd6,0xa9,0xda,0x8b,0xda,0x99,0xd3,0xb2,0xc7,0xa9,0xda,0xbd,0xc6,0xb2,0xd6,0xbd,0xda,0xbd,0xda,0xbd,0xc6,0xb2,0xd6,0xbd,0xda,0xbd,0xd3,0xb2,0xcf,0xa9,0xde,0xbd,0xd3,0x8a,0xda,0xbd,0xda,0xb2,0xd6,0xa9,0xda,0xbd,0xd3,0xb2,0xc7,0xb2,0xd9,0xa9,0xd3,0xb2,0xcf,0xa9,0xde,0xbd,0xd3,0x8a,0xda,0xbd,0xda,0xb2,0xd6,0xa9,0xda,0xbd,0xd3,0xb2,0xcf,0xa9,0xde,0xbd,0xd3,0x8a,0xda,0xbd,0xda,0xb2,0xd6,0x81,0xd3,0x81,0xd3,0x81,0xc3,0xb0,0xd3,0xb0,0xc3,0xb0,0xd3,0x81,0xc7,0xb2,0xd9,0xa9,0xda,0xbd,0xc6,0xb2,0xd6,0x99,0xd3,0xb2,0xc7,0xa9,0xda,0xbd,0xd6,0xa9,0xda,0x8b,0xda,0x99,0xd3,0xb2,0xc7,0xa9,0xda,0xbd,0xd3,0xb0,0xd3,0x81,0xd3,0x81,0xd3,0x81,0xc3,0xb0,0xd3,0xb0,0xd3,0x81,0xc7,0xb2,0xd9,0xa9,0xd3,0xb5,0xd3,0xa9,0xda,0xbd,0xd3,0xb2,0xc7,0xb2,0xd9,0xa9,0xd3,0xb2,0xcf,0xa9,0xde,0xbd,0xd3,0x8a,0xda,0xbd,0xda,0xb2,0xd6,0xa9,0xda,0xbd,0xd3,0xb2,0xc7,0xb2,0xd9,0xa9,0xda,0xbd,0xc7,0xb2,0xd6,0x9b, Step #5: \323\262\307\251\332\275\326\251\332\213\332\232\323\262\307\251\332\275\306\262\326\275\332\275\323\262\317\251\336\275\323\212\332\275\332\262\326\251\332\275\323\262\307\262\331\251\323\262\317\251\336\275\323\212\332\275\332\262\326\251\332\275\323\262\307\262\331\251\332\275\307\262\326\231\323\262\307\211\332\275\326\251\332\213\332\231\323\262\307\251\332\275\306\262\326\275\332\275\332\275\306\262\326\275\332\275\323\262\317\251\336\275\323\212\332\275\332\262\326\251\332\275\323\262\307\262\331\251\323\262\317\251\336\275\323\212\332\275\332\262\326\251\332\275\323\262\317\251\336\275\323\212\332\275\332\262\326\201\323\201\323\201\303\260\323\260\303\260\323\201\307\262\331\251\332\275\306\262\326\231\323\262\307\251\332\275\326\251\332\213\332\231\323\262\307\251\332\275\323\260\323\201\323\201\323\201\303\260\323\260\323\201\307\262\331\251\323\265\323\251\332\275\323\262\307\262\331\251\323\262\317\251\336\275\323\212\332\275\332\262\326\251\332\275\323\262\307\262\331\251\332\275\307\262\326\233 Step #5: artifact_prefix='./'; Test unit written to ./oom-f69994223bd4e8a5808c7753ee6c577403be4561 Step #5: Base64: 07LHqdq91qnai9qa07LHqdq9xrLWvdq907LPqd6904ravdqy1qnavdOyx7LZqdOyz6nevdOK2r3astap2r3Tssey2anavcey1pnTsseJ2r3WqdqL2pnTssep2r3Gsta92r3avcay1r3avdOyz6nevdOK2r3astap2r3Tssey2anTss+p3r3Titq92rLWqdq907LPqd6904ravdqy1oHTgdOBw7DTsMOw04HHstmp2r3GstaZ07LHqdq91qnai9qZ07LHqdq907DTgdOB04HDsNOw04HHstmp07XTqdq907LHstmp07LPqd6904ravdqy1qnavdOyx7LZqdq9x7LWmw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5153 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 51462925 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556bc7853810, 0x556bc7a3d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556bc7a3d020,0x556bc98d50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f69994223bd4e8a5808c7753ee6c577403be4561' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6537 processed earlier; will process 4492 files now Step #5: ==185584== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556bbe3489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556bc49ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556bc49905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556bc49904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556bbe34ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556bbe2afb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556bbe2aa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556bbe340c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556bc130ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556bc130ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556bc130ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556bc130ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556bc130ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556bc130ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556bc130ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556bc130ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556bc130ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556bc130ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556bc35a4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556bc02d1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556bc02dcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556bc0088c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556bc0088c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556bc0089738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556bc0088874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556bc0088874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556bc0088874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556bc4992abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556bc499b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556bc4983699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556bc49ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb6acafa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556bbe2a8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x1,0x0,0x0,0x0,0x0,0x5f,0x1b,0xe4,0xa6,0x97,0x2d,0xf4,0x8b,0xb7,0x97,0x28,0x2d,0x5f,0x1b,0xe4,0xa6,0x97,0x4e,0x60,0x0,0x0,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x69,0x1,0x0,0x0,0x0,0x0,0x5f,0x1b,0xe4,0xa6,0x97,0x72,0x65,0x73,0x65,0x74,0x2d,0xf4,0x8b,0xb7,0x97,0x28,0x36,0x0,0x1b,0xe4,0xa6,0x97,0x4e,0x60,0x0,0x0,0x65,0x6c,0x72,0x6d,0x61,0x67,0x65,0x6e,0x74,0x61,0x67,0x65,0x6e,0x74,0x61,0x73,0x65,0x31,0x31,0x31,0x31,0x31,0x31,0x31,0x31,0x6e,0x6f,0x2d,0x31,0x31,0x32,0x3a,0x67,0x65,0x6e,0x31,0x31,0x30,0x30,0x33,0x33,0x38,0x39,0x31,0x31,0x31,0x31,0x31,0x31,0x31,0x62,0x72,0x69,0x67,0x68,0x74,0x77,0x68,0x69,0x74,0x65,0x65,0x6c,0x0,0x72,0x6d,0x61,0x67,0x65,0x6e,0x74,0x62,0x6f,0x6c,0x64,0x76,0x65,0x72,0x73,0x65,0x30,0x35,0x35,0x35,0x35,0x35,0x35,0x62,0x6c,0x61,0x63,0xd6,0x2f,0xf1,0x93,0xa3,0x2,0x4,0xb0,0x81,0xf1,0x8d,0x94,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x92,0xf3,0x9e,0xae,0x0,0x0,0x0,0x0,0x3b,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x97,0x2d,0x5f,0x1b,0xe4,0xa6,0x97,0x4e,0x0,0x0,0x0,0x5f,0x1b,0xf4,0x8f,0xa7,0x97,0x2d,0x34,0xff,0xff, Step #5: iiiiiiiiiiiiiiiiii\001\000\000\000\000_\033\344\246\227-\364\213\267\227(-_\033\344\246\227N`\000\000iiiiiiiii\001\000\000\000\000_\033\344\246\227reset-\364\213\267\227(6\000\033\344\246\227N`\000\000elrmagentagentase11111111no-112:gen110033891111111brightwhiteel\000rmagentboldverse0555555blac\326/\361\223\243\002\004\260\201\361\215\224\000\000\000\000\000\000\000\000\000\000\001\222\363\236\256\000\000\000\000;\001\000\000\000\000\000\000\000\000\007\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\227-_\033\344\246\227N\000\000\000_\033\364\217\247\227-4\377\377 Step #5: artifact_prefix='./'; Test unit written to ./oom-79205973c1a630db44211056d39bfba5f65dea65 Step #5: Base64: aWlpaWlpaWlpaWlpaWlpaWlpAQAAAABfG+Smly30i7eXKC1fG+Sml05gAABpaWlpaWlpaWkBAAAAAF8b5KaXcmVzZXQt9Iu3lyg2ABvkppdOYAAAZWxybWFnZW50YWdlbnRhc2UxMTExMTExMW5vLTExMjpnZW4xMTAwMzM4OTExMTExMTFicmlnaHR3aGl0ZWVsAHJtYWdlbnRib2xkdmVyc2UwNTU1NTU1YmxhY9Yv8ZOjAgSwgfGNlAAAAAAAAAAAAAABkvOergAAAAA7AQAAAAAAAAAABwAAAAAAAAAAAAAAAAAAAAAAAJctXxvkppdOAAAAXxv0j6eXLTT//w== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5154 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 52114809 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561fbdb17810, 0x561fbdd0101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561fbdd01020,0x561fbfb990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/79205973c1a630db44211056d39bfba5f65dea65' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6538 processed earlier; will process 4491 files now Step #5: #1 pulse cov: 4272 ft: 4273 exec/s: 0 rss: 178Mb Step #5: ==185620== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561fb460c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561fbac71898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561fbac545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561fbac544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561fb4612d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561fb4573b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561fb456e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561fb4604c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561fb75d3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561fb75d3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561fb75d3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561fb75d3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561fb75d3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561fb75d3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561fb75d3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561fb75d3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561fb75d3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561fb75d3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561fb9868f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561fb6595b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561fb65a0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561fb634cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561fb634cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561fb634d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561fb634c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561fb634c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561fb634c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561fbac56abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561fbac5f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561fbac47699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561fbac72112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f28ea0fe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561fb456cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x67,0x6c,0x79,0x66,0x3f,0x67,0x67,0x67,0x6c,0x79,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0x6c,0x79,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0x6c,0x79,0x66,0x67,0x6c,0x79,0x66,0x3f,0x67,0x67,0x67,0x6c,0x79,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0xec,0x79,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0x6c,0x79,0x66,0x67,0x6c,0x79,0x66,0x3f,0x67,0x67,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0x6c,0x79,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0x6c,0x79,0x66,0x67,0x6c,0x79,0x66,0x3f,0x67,0x67,0x67,0x6c,0x79,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0x6c,0x79,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0x6c,0x79,0x66,0x67,0x6c,0x79,0x66,0x3f,0x67,0x67,0x67,0x6c,0x79,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0x6c,0x79,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0x6c,0x79,0x66,0x67,0x6c,0x79,0x66,0x3f,0x67,0x67,0x67,0x6c,0x79,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0x6c,0x79,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0x6c,0x79,0x66,0x67,0x6c,0x79,0x66,0x3f,0x67,0x67,0x67,0x6c,0x79,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0x6c,0x79,0x66,0xf3,0xa0,0x80,0xb0,0x11,0x0,0x0,0x0,0x3f,0x3f,0x67,0x67,0x6c,0xf1,0xf1,0xf1,0xf1,0xf1,0xf1,0xf1,0xf1,0x67,0x67,0x66,0xf3,0xa0,0x80,0xb0,0x3f,0x3f,0x67,0x67,0x6c,0x79,0x66,0x3f,0x67,0x3f,0x67, Step #5: glyf?ggglyf\363\240\200\260??gglyf\363\240\200\260??gglyfglyf?ggglyf\363\240\200\260??gg\354yf\363\240\200\260??gglyfglyf?ggf\363\240\200\260??gglyf\363\240\200\260??gglyfglyf?ggglyf\363\240\200\260??gglyf\363\240\200\260??gglyfglyf?ggglyf\363\240\200\260??gglyf\363\240\200\260??gglyfglyf?ggglyf\363\240\200\260??gglyf\363\240\200\260??gglyfglyf?ggglyf\363\240\200\260??gglyf\363\240\200\260\021\000\000\000??ggl\361\361\361\361\361\361\361\361ggf\363\240\200\260??gglyf?g?g Step #5: artifact_prefix='./'; Test unit written to ./oom-532b76816d87d22166027ee3de35cfdcf423edfc Step #5: Base64: Z2x5Zj9nZ2dseWbzoICwPz9nZ2x5ZvOggLA/P2dnbHlmZ2x5Zj9nZ2dseWbzoICwPz9nZ+x5ZvOggLA/P2dnbHlmZ2x5Zj9nZ2bzoICwPz9nZ2x5ZvOggLA/P2dnbHlmZ2x5Zj9nZ2dseWbzoICwPz9nZ2x5ZvOggLA/P2dnbHlmZ2x5Zj9nZ2dseWbzoICwPz9nZ2x5ZvOggLA/P2dnbHlmZ2x5Zj9nZ2dseWbzoICwPz9nZ2x5ZvOggLA/P2dnbHlmZ2x5Zj9nZ2dseWbzoICwPz9nZ2x5ZvOggLARAAAAPz9nZ2zx8fHx8fHx8WdnZvOggLA/P2dnbHlmP2c/Zw== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5155 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 52679951 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556bb6c49810, 0x556bb6e3301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556bb6e33020,0x556bb8ccb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/532b76816d87d22166027ee3de35cfdcf423edfc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6540 processed earlier; will process 4489 files now Step #5: ==185656== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556bad73e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556bb3da3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556bb3d865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556bb3d864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556bad744d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556bad6a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556bad6a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556bad736c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556bb0705f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556bb0705f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556bb0705f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556bb0705f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556bb0705f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556bb0705f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556bb0705f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556bb0705f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556bb0705f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556bb0705f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556bb299af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556baf6c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556baf6d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556baf47ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556baf47ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556baf47f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556baf47e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556baf47e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556baf47e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556bb3d88abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556bb3d91928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556bb3d79699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556bb3da4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7cc8a82082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556bad69eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0xca,0xb1,0xd5,0xa6,0xdf,0xa2,0xdf,0xa6,0xd5,0xa6,0xdf,0xa2,0xdf,0xa6,0xdf,0xa2,0xd8,0xa6,0xdf,0xa6,0xcf,0xa2,0xdf,0xa6,0xdf,0x80,0xdf,0xa5,0xdf,0xa2,0xdf,0xa6,0xdf,0xa2,0xd7,0x9f,0xcc,0x9f,0xdf,0xa2,0xdf,0xa6,0xdf,0xa2,0xd8,0xa6,0xdf,0xa2,0xdf,0xa2,0xdf,0x93,0xdf,0xa2,0xd8,0xa6,0xdf,0xa0,0xdf,0xa6,0xde,0xa6,0xd7,0xa2,0xdf,0xa6,0xdf,0xa6,0xdf,0xa2,0xd7,0x9f,0xcd,0x9f,0xdf,0xa2,0xde,0xa6,0xdf,0xa2,0xd8,0xa6,0xdf,0xa6,0xcf,0xa2,0xdf,0xa6,0xdf,0x80,0xdf,0xa5,0xdf,0xa2,0xdf,0xa6,0xdf,0xa2,0xd7,0x9f,0xcc,0x9f,0xdf,0xa2,0xdf,0xa6,0xdf,0xa2,0xd8,0xa6,0xdf,0xa2,0xdf,0xa2,0xdf,0x93,0xdf,0xa2,0xd8,0xa6,0xdf,0xa0,0xdf,0xa6,0xde,0xa6,0xd7,0xa2,0xdf,0xa6,0xdf,0xa6,0xdf,0xa2,0xd7,0x9f,0xcd,0x9f,0xdf,0xa2,0xde,0xa6,0xdf,0xa2,0xd8,0xa6,0xdf,0xa2,0xdf,0xa2,0xdf,0xa2,0xdf,0xa6,0xdf,0xa2,0xd9,0xa6,0xdf,0xa6,0xc7,0xa2,0xdf,0xa6,0xdf,0xa8,0xdf,0x9f,0xdf,0xa2,0xdf,0xa5,0xd8,0xa7,0xde,0xa6,0xcf,0xa2,0xdf,0xa6,0xdf,0xa0,0xdf,0xa6,0xdf,0xa0,0xdf,0xa6,0xdf,0xa2,0xd7,0x9f,0xcd,0x9f,0xdf,0xa2,0xde,0xa6,0xdf,0xa6,0xde,0xa6,0xd7,0xa2,0xdf,0xa6,0xdf,0xa6,0xdf,0xa2,0xd7,0x9f,0xcd,0x9f,0xdf,0xa2,0xde,0xa6,0xdf,0xa2,0xd8,0xa6,0xde,0xa2,0xd8,0xa6,0xdf,0xa2,0xdf,0xa2,0xdf,0xb6,0xdf,0xa2,0xd8,0xa6,0xdf,0xa2,0xda,0x82,0xdf,0xa6,0xde,0xa2,0xd8,0xa6,0xdf,0xa0,0xdf,0xa6,0xde,0xa6,0xdf,0x82,0xd8,0xa6, Step #5: \312\261\325\246\337\242\337\246\325\246\337\242\337\246\337\242\330\246\337\246\317\242\337\246\337\200\337\245\337\242\337\246\337\242\327\237\314\237\337\242\337\246\337\242\330\246\337\242\337\242\337\223\337\242\330\246\337\240\337\246\336\246\327\242\337\246\337\246\337\242\327\237\315\237\337\242\336\246\337\242\330\246\337\246\317\242\337\246\337\200\337\245\337\242\337\246\337\242\327\237\314\237\337\242\337\246\337\242\330\246\337\242\337\242\337\223\337\242\330\246\337\240\337\246\336\246\327\242\337\246\337\246\337\242\327\237\315\237\337\242\336\246\337\242\330\246\337\242\337\242\337\242\337\246\337\242\331\246\337\246\307\242\337\246\337\250\337\237\337\242\337\245\330\247\336\246\317\242\337\246\337\240\337\246\337\240\337\246\337\242\327\237\315\237\337\242\336\246\337\246\336\246\327\242\337\246\337\246\337\242\327\237\315\237\337\242\336\246\337\242\330\246\336\242\330\246\337\242\337\242\337\266\337\242\330\246\337\242\332\202\337\246\336\242\330\246\337\240\337\246\336\246\337\202\330\246 Step #5: artifact_prefix='./'; Test unit written to ./oom-f3569e04fef126a16d49b43f1e2917d12448444a Step #5: Base64: yrHVpt+i36bVpt+i36bfotim36bPot+m34Dfpd+i36bfotefzJ/fot+m36LYpt+i36Lfk9+i2KbfoN+m3qbXot+m36bfotefzZ/fot6m36LYpt+mz6Lfpt+A36Xfot+m36LXn8yf36Lfpt+i2Kbfot+i35Pfotim36Dfpt6m16Lfpt+m36LXn82f36Lept+i2Kbfot+i36Lfpt+i2abfpsei36bfqN+f36Lfpdin3qbPot+m36Dfpt+g36bfotefzZ/fot6m36beptei36bfpt+i15/Nn9+i3qbfotim3qLYpt+i36Lftt+i2KbfotqC36beotim36Dfpt6m34LYpg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5156 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 53211892 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a21b864810, 0x55a21ba4e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a21ba4e020,0x55a21d8e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f3569e04fef126a16d49b43f1e2917d12448444a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6541 processed earlier; will process 4488 files now Step #5: ==185692== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a2123599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a2189be898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2189a15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2189a14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a21235fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a2122c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a2122bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a212351c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a215320f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a215320f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a215320f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a215320f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a215320f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a215320f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a215320f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a215320f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a215320f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a215320f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a2175b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a2142e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a2142edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a214099c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a214099c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a21409a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a214099874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a214099874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a214099874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a2189a3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a2189ac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a218994699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a2189bf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f162413f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a2122b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa,0xa,0xf4,0x8f,0xbf,0xbf,0x62,0xf4,0x8f,0xbf,0xbf,0x62,0x62,0xa, Step #5: bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\364\217\277\277bb\012\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bbb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277bb\012\012\364\217\277\277b\364\217\277\277bb\012 Step #5: artifact_prefix='./'; Test unit written to ./oom-cedd51b64d550eb0bedf348ae4c6e5c9925b41fc Step #5: Base64: YmIKCvSPv79iYgoK9I+/v2JiCvSPv79iYgoK9I+/v2JiCgr0j7+/YmIKCvSPv79iYgoK9I+/v2JiCgr0j7+/YmIKCvSPv79iYgoK9I+/v2JiCgr0j7+/YmIKCvSPv79iYgoK9I+/v2JiCvSPv79iYgoKCvSPv79iYgoK9I+/v2JiCgr0j7+/YmIKCvSPv79iYgoK9I+/v2JiCgr0j7+/YmIKCvSPv79iYgoK9I+/v2JiYgoK9I+/v2JiCgr0j7+/YmIKCvSPv79iYgoK9I+/v2JiCgr0j7+/YmIKCvSPv79iYgoK9I+/v2JiCgr0j7+/YmIKCvSPv79i9I+/v2JiCg== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5157 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 53747299 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eff05b6810, 0x55eff07a001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eff07a0020,0x55eff26380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cedd51b64d550eb0bedf348ae4c6e5c9925b41fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6542 processed earlier; will process 4487 files now Step #5: ==185728== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55efe70ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55efed710898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55efed6f35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55efed6f34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55efe70b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55efe7012b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55efe700d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55efe70a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55efea072f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55efea072f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55efea072f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55efea072f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55efea072f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55efea072f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55efea072f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55efea072f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55efea072f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55efea072f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55efec307f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55efe9034b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55efe903fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55efe8debc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55efe8debc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55efe8dec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55efe8deb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55efe8deb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55efe8deb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55efed6f5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55efed6fe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55efed6e6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55efed711112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f79f7122082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55efe700bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-810f038e64e47c627869ab77f7f7931fafdf5b59 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5158 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 54288461 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5568de6fb810, 0x5568de8e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5568de8e5020,0x5568e077d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/810f038e64e47c627869ab77f7f7931fafdf5b59' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6543 processed earlier; will process 4486 files now Step #5: ==185764== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5568d51f09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5568db855898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5568db8385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5568db8384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5568d51f6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5568d5157b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5568d5152355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5568d51e8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5568d81b7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5568d81b7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5568d81b7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5568d81b7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5568d81b7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5568d81b7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5568d81b7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5568d81b7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5568d81b7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5568d81b7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5568da44cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5568d7179b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5568d7184be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5568d6f30c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5568d6f30c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5568d6f31738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5568d6f30874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5568d6f30874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5568d6f30874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5568db83aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5568db843928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5568db82b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5568db856112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f41d863b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5568d5150b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-dc89b61526d6aaf47c96dd59748b16271cd25c66 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5159 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 54837674 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a099880810, 0x55a099a6a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a099a6a020,0x55a09b9020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dc89b61526d6aaf47c96dd59748b16271cd25c66' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6544 processed earlier; will process 4485 files now Step #5: ==185800== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0903759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0969da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0969bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0969bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a09037bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0902dcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0902d7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a09036dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a09333cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a09333cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a09333cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a09333cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a09333cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a09333cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a09333cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a09333cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a09333cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a09333cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0955d1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0922feb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a092309be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0920b5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0920b5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0920b6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0920b5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0920b5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0920b5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0969bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0969c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0969b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0969db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f753c25f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0902d5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c56ee02633e57f9da856c4b8961be1b6d46bcdd4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5160 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 55383123 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5641f1549810, 0x5641f173301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5641f1733020,0x5641f35cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c56ee02633e57f9da856c4b8961be1b6d46bcdd4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6545 processed earlier; will process 4484 files now Step #5: ==185836== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5641e803e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5641ee6a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5641ee6865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5641ee6864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5641e8044d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641e7fa5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641e7fa0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5641e8036c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5641eb005f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5641eb005f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5641eb005f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5641eb005f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5641eb005f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5641eb005f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5641eb005f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5641eb005f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5641eb005f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5641eb005f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5641ed29af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5641e9fc7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5641e9fd2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5641e9d7ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5641e9d7ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5641e9d7f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5641e9d7e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5641e9d7e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5641e9d7e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5641ee688abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5641ee691928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5641ee679699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5641ee6a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feb22092082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641e7f9eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ac6fef743a5fbf02f9c53552ca534c9732a792bd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5161 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 55927851 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a75b21810, 0x561a75d0b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a75d0b020,0x561a77ba30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ac6fef743a5fbf02f9c53552ca534c9732a792bd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6546 processed earlier; will process 4483 files now Step #5: ==185872== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561a6c6169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561a72c7b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561a72c5e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561a72c5e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561a6c61cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561a6c57db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561a6c578355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561a6c60ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561a6f5ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561a6f5ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561a6f5ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561a6f5ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561a6f5ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561a6f5ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561a6f5ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561a6f5ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561a6f5ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561a6f5ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561a71872f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561a6e59fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561a6e5aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561a6e356c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561a6e356c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561a6e357738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561a6e356874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561a6e356874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561a6e356874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561a72c60abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561a72c69928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561a72c51699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561a72c7c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4cc232f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561a6c576b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1ec458491752c0d7630ea5bd4bf56c1de29bae52 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5162 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 56481243 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571762b2810, 0x55717649c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55717649c020,0x5571783340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ec458491752c0d7630ea5bd4bf56c1de29bae52' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6547 processed earlier; will process 4482 files now Step #5: ==185908== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55716cda79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55717340c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571733ef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571733ef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55716cdadd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55716cd0eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55716cd09355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55716cd9fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55716fd6ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55716fd6ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55716fd6ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55716fd6ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55716fd6ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55716fd6ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55716fd6ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55716fd6ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55716fd6ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55716fd6ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557172003f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55716ed30b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55716ed3bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55716eae7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55716eae7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55716eae8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55716eae7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55716eae7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55716eae7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571733f1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571733fa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571733e2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55717340d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8e58c58082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55716cd07b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6731756088a1c8b4bb3bfab81ea6ebdaba8d4d3e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5163 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 57195754 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56219fa03810, 0x56219fbed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56219fbed020,0x5621a1a850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6731756088a1c8b4bb3bfab81ea6ebdaba8d4d3e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6548 processed earlier; will process 4481 files now Step #5: #1 pulse cov: 3890 ft: 3891 exec/s: 0 rss: 178Mb Step #5: ==185944== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5621964f89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56219cb5d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56219cb405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56219cb404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5621964fed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56219645fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56219645a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5621964f0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5621994bff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5621994bff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5621994bff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5621994bff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5621994bff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5621994bff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5621994bff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5621994bff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5621994bff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5621994bff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56219b754f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562198481b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56219848cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562198238c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562198238c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562198239738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562198238874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562198238874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562198238874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56219cb42abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56219cb4b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56219cb33699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56219cb5e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe902371082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562196458b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1637926e60a3b9d0ba83bb5b6bf454ac0be9d978 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5164 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 57779423 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5572cd0a4810, 0x5572cd28e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5572cd28e020,0x5572cf1260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1637926e60a3b9d0ba83bb5b6bf454ac0be9d978' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6550 processed earlier; will process 4479 files now Step #5: ==185980== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5572c3b999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5572ca1fe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5572ca1e15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5572ca1e14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5572c3b9fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5572c3b00b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5572c3afb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5572c3b91c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5572c6b60f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5572c6b60f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5572c6b60f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5572c6b60f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5572c6b60f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5572c6b60f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5572c6b60f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5572c6b60f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5572c6b60f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5572c6b60f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5572c8df5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5572c5b22b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5572c5b2dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5572c58d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5572c58d9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5572c58da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5572c58d9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5572c58d9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5572c58d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5572ca1e3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5572ca1ec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5572ca1d4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5572ca1ff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b73c4b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5572c3af9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-afba47c574dcde67afbb8b1b1ff887149b30198d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5165 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 58325071 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a0b71a810, 0x558a0b90401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a0b904020,0x558a0d79c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/afba47c574dcde67afbb8b1b1ff887149b30198d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6551 processed earlier; will process 4478 files now Step #5: ==186016== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558a0220f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a08874898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a088575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a088574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a02215d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a02176b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a02171355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a02207c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a051d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a051d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a051d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a051d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a051d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a051d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a051d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a051d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a051d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a051d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a0746bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a04198b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a041a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a03f4fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a03f4fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a03f50738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a03f4f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a03f4f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a03f4f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a08859abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a08862928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a0884a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a08875112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27c41ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a0216fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-894009a7ae9ecde140087adf09cda1f2b596eadc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5166 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 58864566 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d77f78810, 0x563d7816201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d78162020,0x563d79ffa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/894009a7ae9ecde140087adf09cda1f2b596eadc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6552 processed earlier; will process 4477 files now Step #5: ==186052== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563d6ea6d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d750d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d750b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d750b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d6ea73d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d6e9d4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d6e9cf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d6ea65c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d71a34f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d71a34f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d71a34f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d71a34f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d71a34f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d71a34f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d71a34f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d71a34f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d71a34f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d71a34f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d73cc9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d709f6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d70a01be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d707adc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d707adc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d707ae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d707ad874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d707ad874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d707ad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d750b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d750c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d750a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d750d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb362396082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d6e9cdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e97178614ef23fb949394d93aa27506fb65a8b65 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5167 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 59406736 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea28280810, 0x55ea2846a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea2846a020,0x55ea2a3020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e97178614ef23fb949394d93aa27506fb65a8b65' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6553 processed earlier; will process 4476 files now Step #5: ==186088== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ea1ed759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea253da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea253bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea253bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea1ed7bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea1ecdcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea1ecd7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea1ed6dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea21d3cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea21d3cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea21d3cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea21d3cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea21d3cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea21d3cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea21d3cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea21d3cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea21d3cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea21d3cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea23fd1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea20cfeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea20d09be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea20ab5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea20ab5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea20ab6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea20ab5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea20ab5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea20ab5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea253bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea253c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea253b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea253db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b1ffdc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea1ecd5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b3ffc522c2e46bdf7b081f46d308dfe03bb14dd6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5168 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 59942435 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564e742f8810, 0x564e744e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564e744e2020,0x564e7637a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3ffc522c2e46bdf7b081f46d308dfe03bb14dd6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6554 processed earlier; will process 4475 files now Step #5: ==186124== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564e6aded9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564e71452898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564e714355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564e714354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564e6adf3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564e6ad54b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564e6ad4f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564e6ade5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564e6ddb4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564e6ddb4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564e6ddb4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564e6ddb4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564e6ddb4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564e6ddb4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564e6ddb4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564e6ddb4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564e6ddb4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564e6ddb4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564e70049f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564e6cd76b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564e6cd81be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564e6cb2dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564e6cb2dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564e6cb2e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564e6cb2d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564e6cb2d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564e6cb2d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564e71437abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564e71440928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564e71428699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564e71453112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f670eb94082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564e6ad4db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-72d4350bcf631fc1ed6315f4b7e9496aed3ee58f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5169 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 60493972 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557f3f10b810, 0x557f3f2f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557f3f2f5020,0x557f4118d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/72d4350bcf631fc1ed6315f4b7e9496aed3ee58f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6555 processed earlier; will process 4474 files now Step #5: ==186160== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557f35c009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f3c265898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f3c2485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f3c2484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f35c06d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f35b67b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f35b62355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f35bf8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f38bc7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f38bc7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f38bc7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f38bc7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f38bc7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f38bc7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f38bc7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f38bc7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f38bc7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f38bc7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f3ae5cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f37b89b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f37b94be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f37940c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f37940c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f37941738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f37940874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f37940874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f37940874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f3c24aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f3c253928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f3c23b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f3c266112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa8a7784082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f35b60b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2f8d25a542522b732e7cbaa8d370a7a459951387 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5170 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 61034421 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55792aa56810, 0x55792ac4001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55792ac40020,0x55792cad80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f8d25a542522b732e7cbaa8d370a7a459951387' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6556 processed earlier; will process 4473 files now Step #5: ==186196== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55792154b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557927bb0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557927b935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557927b934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557921551d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5579214b2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5579214ad355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557921543c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557924512f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557924512f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557924512f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557924512f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557924512f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557924512f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557924512f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557924512f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557924512f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557924512f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579267a7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5579234d4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5579234dfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55792328bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55792328bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55792328c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55792328b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55792328b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55792328b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557927b95abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557927b9e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557927b86699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557927bb1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0255c97082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5579214abb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2cc41f599f9291d5e1d2c8c6ed93c79b9b1b6d29 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5171 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 61695063 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f3a0c27810, 0x55f3a0e1101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f3a0e11020,0x55f3a2ca90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2cc41f599f9291d5e1d2c8c6ed93c79b9b1b6d29' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6557 processed earlier; will process 4472 files now Step #5: #1 pulse cov: 3790 ft: 3791 exec/s: 0 rss: 179Mb Step #5: ==186232== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f39771c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f39dd81898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f39dd645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f39dd644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f397722d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f397683b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f39767e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f397714c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f39a6e3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f39a6e3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f39a6e3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f39a6e3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f39a6e3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f39a6e3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f39a6e3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f39a6e3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f39a6e3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f39a6e3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f39c978f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f3996a5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f3996b0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f39945cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f39945cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f39945d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f39945c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f39945c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f39945c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f39dd66abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f39dd6f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f39dd57699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f39dd82112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa161bf8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f39767cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e4f7c80a6d0cac668a8fb4209d7c09ae8c55a1d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5172 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 62275552 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e030a8f810, 0x55e030c7901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e030c79020,0x55e032b110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e4f7c80a6d0cac668a8fb4209d7c09ae8c55a1d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6559 processed earlier; will process 4470 files now Step #5: ==186268== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e0275849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e02dbe9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e02dbcc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e02dbcc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e02758ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e0274ebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e0274e6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e02757cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e02a54bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e02a54bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e02a54bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e02a54bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e02a54bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e02a54bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e02a54bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e02a54bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e02a54bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e02a54bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e02c7e0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e02950db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e029518be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e0292c4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e0292c4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e0292c5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e0292c4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e0292c4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e0292c4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e02dbceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e02dbd7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e02dbbf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e02dbea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fccd764a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e0274e4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec882bf78baeabd3eb808c6dbcbb8ba860339733 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5173 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 62925144 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56160d203810, 0x56160d3ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56160d3ed020,0x56160f2850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec882bf78baeabd3eb808c6dbcbb8ba860339733' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6560 processed earlier; will process 4469 files now Step #5: ==186304== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561603cf89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56160a35d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56160a3405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56160a3404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561603cfed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561603c5fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561603c5a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561603cf0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561606cbff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561606cbff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561606cbff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561606cbff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561606cbff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561606cbff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561606cbff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561606cbff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561606cbff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561606cbff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561608f54f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561605c81b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561605c8cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561605a38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561605a38c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561605a39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561605a38874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561605a38874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561605a38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56160a342abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56160a34b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56160a333699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56160a35e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f19fd0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561603c58b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-abae679b681e817fb74e560f3845d4ea91d7a3b8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5174 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 63462402 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c447dd5810, 0x55c447fbf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c447fbf020,0x55c449e570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/abae679b681e817fb74e560f3845d4ea91d7a3b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6561 processed earlier; will process 4468 files now Step #5: #1 pulse cov: 4159 ft: 4160 exec/s: 0 rss: 177Mb Step #5: ==186340== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c43e8ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c444f2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c444f125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c444f124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c43e8d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c43e831b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c43e82c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c43e8c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c441891f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c441891f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c441891f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c441891f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c441891f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c441891f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c441891f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c441891f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c441891f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c441891f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c443b26f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c440853b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c44085ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c44060ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c44060ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c44060b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c44060a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c44060a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c44060a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c444f14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c444f1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c444f05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c444f30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e7e6d6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c43e82ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-caed6406cbeaa43020e9765468e4e0947608a1a0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5175 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 64044922 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e0aaa7d810, 0x55e0aac6701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e0aac67020,0x55e0acaff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/caed6406cbeaa43020e9765468e4e0947608a1a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6563 processed earlier; will process 4466 files now Step #5: ==186376== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e0a15729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e0a7bd7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e0a7bba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e0a7bba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e0a1578d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e0a14d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e0a14d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e0a156ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e0a4539f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e0a4539f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e0a4539f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e0a4539f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e0a4539f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e0a4539f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e0a4539f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e0a4539f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e0a4539f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e0a4539f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e0a67cef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e0a34fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e0a3506be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e0a32b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e0a32b2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e0a32b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e0a32b2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e0a32b2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e0a32b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e0a7bbcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e0a7bc5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e0a7bad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e0a7bd8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf38740082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e0a14d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-41d7a547dc977c9168dc4e283afda89df33c8c48 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5176 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 64575525 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5576c47b1810, 0x5576c499b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5576c499b020,0x5576c68330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/41d7a547dc977c9168dc4e283afda89df33c8c48' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6564 processed earlier; will process 4465 files now Step #5: ==186412== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5576bb2a69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5576c190b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5576c18ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5576c18ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5576bb2acd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5576bb20db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5576bb208355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5576bb29ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576be26df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576be26df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576be26df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576be26df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576be26df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576be26df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576be26df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576be26df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576be26df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576be26df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5576c0502f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5576bd22fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5576bd23abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5576bcfe6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5576bcfe6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5576bcfe7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5576bcfe6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5576bcfe6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5576bcfe6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5576c18f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5576c18f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5576c18e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5576c190c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9776d82082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5576bb206b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5e84318657296141cf83a5bdf5f58da31f3caa23 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5177 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 65122928 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562b5e434810, 0x562b5e61e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562b5e61e020,0x562b604b60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e84318657296141cf83a5bdf5f58da31f3caa23' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6565 processed earlier; will process 4464 files now Step #5: ==186448== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562b54f299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562b5b58e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562b5b5715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562b5b5714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b54f2fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b54e90b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b54e8b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b54f21c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b57ef0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b57ef0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b57ef0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b57ef0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b57ef0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b57ef0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b57ef0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b57ef0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b57ef0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b57ef0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562b5a185f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b56eb2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b56ebdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b56c69c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b56c69c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b56c6a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b56c69874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b56c69874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b56c69874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562b5b573abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562b5b57c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562b5b564699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562b5b58f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a7c31e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b54e89b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c8d5074788fdb91d567db5cb2a2e2765cbdb782b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5178 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 65654552 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab28b20810, 0x55ab28d0a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab28d0a020,0x55ab2aba20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c8d5074788fdb91d567db5cb2a2e2765cbdb782b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6566 processed earlier; will process 4463 files now Step #5: #1 pulse cov: 4092 ft: 4093 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4701 ft: 5330 exec/s: 0 rss: 177Mb Step #5: ==186484== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ab1f6159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab25c7a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab25c5d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab25c5d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab1f61bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab1f57cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab1f577355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab1f60dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab225dcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab225dcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab225dcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab225dcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab225dcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab225dcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab225dcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab225dcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab225dcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab225dcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab24871f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab2159eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab215a9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab21355c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab21355c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab21356738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab21355874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab21355874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab21355874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab25c5fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab25c68928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab25c50699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab25c7b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8365e4f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab1f575b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4e66c41619026af0a2c1b0d4f7050c86c8c0db07 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5179 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 66274633 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565522106810, 0x5655222f001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5655222f0020,0x5655241880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e66c41619026af0a2c1b0d4f7050c86c8c0db07' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6569 processed earlier; will process 4460 files now Step #5: ==186520== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565518bfb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56551f260898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56551f2435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56551f2434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565518c01d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565518b62b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565518b5d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565518bf3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56551bbc2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56551bbc2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56551bbc2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56551bbc2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56551bbc2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56551bbc2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56551bbc2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56551bbc2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56551bbc2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56551bbc2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56551de57f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56551ab84b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56551ab8fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56551a93bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56551a93bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56551a93c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56551a93b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56551a93b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56551a93b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56551f245abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56551f24e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56551f236699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56551f261112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6d8d0ef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565518b5bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-71d4ec1a7123a44dc4141234d8f3f38181cc1af9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5180 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 66818589 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55da33713810, 0x55da338fd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55da338fd020,0x55da357950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/71d4ec1a7123a44dc4141234d8f3f38181cc1af9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6570 processed earlier; will process 4459 files now Step #5: #1 pulse cov: 4072 ft: 4073 exec/s: 0 rss: 176Mb Step #5: ==186556== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55da2a2089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55da3086d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55da308505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55da308504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55da2a20ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55da2a16fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55da2a16a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55da2a200c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55da2d1cff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55da2d1cff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55da2d1cff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55da2d1cff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55da2d1cff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55da2d1cff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55da2d1cff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55da2d1cff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55da2d1cff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55da2d1cff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55da2f464f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55da2c191b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55da2c19cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55da2bf48c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55da2bf48c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55da2bf49738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55da2bf48874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55da2bf48874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55da2bf48874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55da30852abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55da3085b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55da30843699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55da3086e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f05f7cbe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55da2a168b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1c4bb101050512396b2eff685e6cc7e624bac7db Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5181 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 67424983 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562f9572b810, 0x562f9591501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562f95915020,0x562f977ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c4bb101050512396b2eff685e6cc7e624bac7db' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6572 processed earlier; will process 4457 files now Step #5: ==186592== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562f8c2209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562f92885898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562f928685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562f928684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562f8c226d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562f8c187b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562f8c182355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562f8c218c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562f8f1e7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562f8f1e7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562f8f1e7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562f8f1e7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562f8f1e7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562f8f1e7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562f8f1e7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562f8f1e7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562f8f1e7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562f8f1e7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562f9147cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562f8e1a9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562f8e1b4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562f8df60c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562f8df60c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562f8df61738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562f8df60874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562f8df60874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562f8df60874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562f9286aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562f92873928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562f9285b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562f92886112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbb3c232082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562f8c180b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d8a08e9f7d0310c73a4570318083b7983960130a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5182 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 67967433 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f6838f5810, 0x55f683adf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f683adf020,0x55f6859770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d8a08e9f7d0310c73a4570318083b7983960130a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6573 processed earlier; will process 4456 files now Step #5: ==186628== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f67a3ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f680a4f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f680a325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f680a324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f67a3f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f67a351b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f67a34c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f67a3e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f67d3b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f67d3b1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f67d3b1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f67d3b1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f67d3b1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f67d3b1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f67d3b1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f67d3b1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f67d3b1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f67d3b1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f67f646f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f67c373b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f67c37ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f67c12ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f67c12ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f67c12b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f67c12a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f67c12a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f67c12a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f680a34abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f680a3d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f680a25699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f680a50112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa93210082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f67a34ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a68ca284900e2e89d2a07f92e8a587ccb9d22280 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5183 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 68521838 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56470d792810, 0x56470d97c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56470d97c020,0x56470f8140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a68ca284900e2e89d2a07f92e8a587ccb9d22280' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6574 processed earlier; will process 4455 files now Step #5: ==186664== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647042879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56470a8ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56470a8cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56470a8cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56470428dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647041eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647041e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56470427fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56470724ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56470724ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56470724ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56470724ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56470724ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56470724ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56470724ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56470724ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56470724ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56470724ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647094e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564706210b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56470621bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564705fc7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564705fc7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564705fc8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564705fc7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564705fc7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564705fc7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56470a8d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56470a8da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56470a8c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56470a8ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5acbb8e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647041e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-50b064181a1f454249d2a9c6e2f96f873e228814 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5184 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 69115650 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559386d70810, 0x559386f5a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559386f5a020,0x559388df20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/50b064181a1f454249d2a9c6e2f96f873e228814' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6575 processed earlier; will process 4454 files now Step #5: #1 pulse cov: 4009 ft: 4010 exec/s: 0 rss: 177Mb Step #5: ==186700== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55937d8659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559383eca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559383ead5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559383ead4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55937d86bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55937d7ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55937d7c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55937d85dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55938082cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55938082cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55938082cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55938082cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55938082cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55938082cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55938082cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55938082cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55938082cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55938082cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559382ac1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55937f7eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55937f7f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55937f5a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55937f5a5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55937f5a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55937f5a5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55937f5a5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55937f5a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559383eafabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559383eb8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559383ea0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559383ecb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f61db2f2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55937d7c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-95542ef3124a1ab773da3c647a768abfdb1ab91e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5185 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 69736591 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e0ff07810, 0x563e100f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e100f1020,0x563e11f890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/95542ef3124a1ab773da3c647a768abfdb1ab91e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6577 processed earlier; will process 4452 files now Step #5: #1 pulse cov: 3635 ft: 3636 exec/s: 0 rss: 178Mb Step #5: ==186736== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563e069fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e0d061898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e0d0445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e0d0444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e06a02d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e06963b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e0695e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e069f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e099c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e099c3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e099c3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e099c3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e099c3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e099c3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e099c3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e099c3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e099c3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e099c3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e0bc58f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e08985b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e08990be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e0873cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e0873cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e0873d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e0873c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e0873c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e0873c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e0d046abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e0d04f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e0d037699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e0d062112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f171217a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e0695cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0332b7fb1ea2f600b78387da312b90622c072cf7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5186 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 70324347 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560e34f99810, 0x560e3518301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560e35183020,0x560e3701b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0332b7fb1ea2f600b78387da312b90622c072cf7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6579 processed earlier; will process 4450 files now Step #5: ==186772== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560e2ba8e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560e320f3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560e320d65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560e320d64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560e2ba94d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560e2b9f5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560e2b9f0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560e2ba86c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560e2ea55f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560e2ea55f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560e2ea55f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560e2ea55f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560e2ea55f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560e2ea55f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560e2ea55f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560e2ea55f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560e2ea55f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560e2ea55f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560e30ceaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560e2da17b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560e2da22be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560e2d7cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560e2d7cec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560e2d7cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560e2d7ce874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560e2d7ce874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560e2d7ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560e320d8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560e320e1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560e320c9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560e320f4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d6b5ed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560e2b9eeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-471bb1171981097fa477b7ea17d28e292f82b1a9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5187 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 70868504 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643e480c810, 0x5643e49f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643e49f6020,0x5643e688e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/471bb1171981097fa477b7ea17d28e292f82b1a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6580 processed earlier; will process 4449 files now Step #5: ==186808== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643db3019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643e1966898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643e19495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643e19494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643db307d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643db268b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643db263355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643db2f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643de2c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643de2c8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643de2c8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643de2c8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643de2c8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643de2c8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643de2c8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643de2c8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643de2c8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643de2c8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643e055df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643dd28ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643dd295be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643dd041c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643dd041c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643dd042738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643dd041874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643dd041874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643dd041874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643e194babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643e1954928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643e193c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643e1967112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd5b658a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643db261b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b0660c1ef75f020a80a3701edce4a1b9f1691117 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5188 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 71404110 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b5f5d62810, 0x55b5f5f4c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b5f5f4c020,0x55b5f7de40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b0660c1ef75f020a80a3701edce4a1b9f1691117' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6581 processed earlier; will process 4448 files now Step #5: #1 pulse cov: 4003 ft: 4004 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4118 ft: 4559 exec/s: 0 rss: 180Mb Step #5: ==186844== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b5ec8579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b5f2ebc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b5f2e9f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b5f2e9f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b5ec85dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b5ec7beb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b5ec7b9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b5ec84fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b5ef81ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b5ef81ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b5ef81ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b5ef81ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b5ef81ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b5ef81ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b5ef81ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b5ef81ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b5ef81ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b5ef81ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b5f1ab3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b5ee7e0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b5ee7ebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b5ee597c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b5ee597c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b5ee598738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b5ee597874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b5ee597874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b5ee597874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b5f2ea1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b5f2eaa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b5f2e92699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b5f2ebd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5b80750082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b5ec7b7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-35db84705b0708f2712372efdff449c4fae3941a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5189 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 72023866 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55604e9b4810, 0x55604eb9e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55604eb9e020,0x556050a360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/35db84705b0708f2712372efdff449c4fae3941a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6584 processed earlier; will process 4445 files now Step #5: #1 pulse cov: 3548 ft: 3549 exec/s: 0 rss: 176Mb Step #5: ==186880== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5560454a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55604bb0e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55604baf15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55604baf14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5560454afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556045410b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55604540b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5560454a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556048470f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556048470f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556048470f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556048470f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556048470f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556048470f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556048470f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556048470f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556048470f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556048470f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55604a705f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556047432b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55604743dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5560471e9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5560471e9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5560471ea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5560471e9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5560471e9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5560471e9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55604baf3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55604bafc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55604bae4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55604bb0f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6776531082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556045409b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9eeb79280744a7acf44073da71de48d8662ad6ac Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5190 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 72603688 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bda9963810, 0x55bda9b4d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bda9b4d020,0x55bdab9e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9eeb79280744a7acf44073da71de48d8662ad6ac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6586 processed earlier; will process 4443 files now Step #5: ==186916== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bda04589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bda6abd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bda6aa05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bda6aa04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bda045ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bda03bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bda03ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bda0450c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bda341ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bda341ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bda341ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bda341ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bda341ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bda341ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bda341ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bda341ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bda341ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bda341ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bda56b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bda23e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bda23ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bda2198c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bda2198c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bda2199738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bda2198874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bda2198874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bda2198874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bda6aa2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bda6aab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bda6a93699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bda6abe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f00eabdf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bda03b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3be605358df0037e2aead8ef89836faf4c648f58 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5191 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 73137980 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f297cfa810, 0x55f297ee401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f297ee4020,0x55f299d7c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3be605358df0037e2aead8ef89836faf4c648f58' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6587 processed earlier; will process 4442 files now Step #5: ==186952== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f28e7ef9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f294e54898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f294e375dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f294e374fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f28e7f5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f28e756b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f28e751355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f28e7e7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f2917b6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f2917b6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f2917b6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f2917b6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f2917b6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f2917b6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f2917b6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f2917b6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f2917b6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f2917b6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f293a4bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f290778b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f290783be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f29052fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f29052fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f290530738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f29052f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f29052f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f29052f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f294e39abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f294e42928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f294e2a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f294e55112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf5cddb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f28e74fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-84bad60f7003d55331d314ea3c1f6a0c47e8b560 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5192 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 73805539 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5608ef28b810, 0x5608ef47501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5608ef475020,0x5608f130d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/84bad60f7003d55331d314ea3c1f6a0c47e8b560' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6588 processed earlier; will process 4441 files now Step #5: ==186988== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5608e5d809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5608ec3e5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608ec3c85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608ec3c84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5608e5d86d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5608e5ce7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5608e5ce2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5608e5d78c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5608e8d47f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5608e8d47f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5608e8d47f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5608e8d47f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5608e8d47f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5608e8d47f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5608e8d47f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5608e8d47f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5608e8d47f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5608e8d47f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608eafdcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5608e7d09b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5608e7d14be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5608e7ac0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5608e7ac0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5608e7ac1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5608e7ac0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5608e7ac0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5608e7ac0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5608ec3caabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5608ec3d3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5608ec3bb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5608ec3e6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff12e280082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5608e5ce0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-93abd5bdd1fcb8471faaa24a44ec66aa47edd10a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5193 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 74344259 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558391caf810, 0x558391e9901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558391e99020,0x558393d310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93abd5bdd1fcb8471faaa24a44ec66aa47edd10a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6589 processed earlier; will process 4440 files now Step #5: ==187024== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5583887a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55838ee09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55838edec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55838edec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5583887aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55838870bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558388706355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55838879cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55838b76bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55838b76bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55838b76bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55838b76bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55838b76bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55838b76bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55838b76bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55838b76bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55838b76bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55838b76bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55838da00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55838a72db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55838a738be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55838a4e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55838a4e4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55838a4e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55838a4e4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55838a4e4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55838a4e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55838edeeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55838edf7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55838eddf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55838ee0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fec6a97c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558388704b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-36f96b4cc08043ab9b21e633f1d20f5985341abb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5194 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 74894043 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db77260810, 0x55db7744a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db7744a020,0x55db792e20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/36f96b4cc08043ab9b21e633f1d20f5985341abb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6590 processed earlier; will process 4439 files now Step #5: ==187060== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db6dd559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db743ba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db7439d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db7439d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db6dd5bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db6dcbcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db6dcb7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db6dd4dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db70d1cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db70d1cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db70d1cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db70d1cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db70d1cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db70d1cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db70d1cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db70d1cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db70d1cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db70d1cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db72fb1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db6fcdeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db6fce9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db6fa95c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db6fa95c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db6fa96738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db6fa95874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db6fa95874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db6fa95874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db7439fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db743a8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db74390699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db743bb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a869c2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db6dcb5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c53bf84e74a66261cee4f9d6f5cedd22fee4183d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5195 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 75560298 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561e26268810, 0x561e2645201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561e26452020,0x561e282ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c53bf84e74a66261cee4f9d6f5cedd22fee4183d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6591 processed earlier; will process 4438 files now Step #5: ==187096== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561e1cd5d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561e233c2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561e233a55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561e233a54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561e1cd63d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561e1ccc4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561e1ccbf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561e1cd55c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561e1fd24f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561e1fd24f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561e1fd24f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561e1fd24f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561e1fd24f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561e1fd24f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561e1fd24f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561e1fd24f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561e1fd24f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561e1fd24f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561e21fb9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561e1ece6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561e1ecf1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561e1ea9dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561e1ea9dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561e1ea9e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561e1ea9d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561e1ea9d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561e1ea9d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561e233a7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561e233b0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561e23398699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561e233c3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9afc9f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561e1ccbdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-de575fa8ac137377b243f58d815af599f76950e7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5196 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 76117184 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f629d09810, 0x55f629ef301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f629ef3020,0x55f62bd8b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de575fa8ac137377b243f58d815af599f76950e7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6592 processed earlier; will process 4437 files now Step #5: #1 pulse cov: 3765 ft: 3766 exec/s: 0 rss: 178Mb Step #5: ==187132== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f6207fe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f626e63898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f626e465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f626e464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f620804d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f620765b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f620760355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f6207f6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f6237c5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f6237c5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f6237c5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f6237c5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f6237c5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f6237c5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f6237c5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f6237c5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f6237c5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f6237c5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f625a5af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f622787b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f622792be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f62253ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f62253ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f62253f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f62253e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f62253e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f62253e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f626e48abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f626e51928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f626e39699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f626e64112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2cf162b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f62075eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fc0819f809ec5934213ef72268a6b96a799b7623 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5197 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 76837620 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5587e331e810, 0x5587e350801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5587e3508020,0x5587e53a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc0819f809ec5934213ef72268a6b96a799b7623' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6594 processed earlier; will process 4435 files now Step #5: ==187168== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5587d9e139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5587e0478898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5587e045b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5587e045b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5587d9e19d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5587d9d7ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5587d9d75355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5587d9e0bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5587dcddaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5587dcddaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5587dcddaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5587dcddaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5587dcddaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5587dcddaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5587dcddaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5587dcddaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5587dcddaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5587dcddaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5587df06ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5587dbd9cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5587dbda7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5587dbb53c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5587dbb53c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5587dbb54738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5587dbb53874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5587dbb53874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5587dbb53874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5587e045dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5587e0466928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5587e044e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5587e0479112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a21de6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5587d9d73b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-98e67835254a753aab80b5d4c676f9efc37b1112 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5198 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 77376774 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f3c7dd5810, 0x55f3c7fbf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f3c7fbf020,0x55f3c9e570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/98e67835254a753aab80b5d4c676f9efc37b1112' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6595 processed earlier; will process 4434 files now Step #5: ==187204== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f3be8ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f3c4f2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f3c4f125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f3c4f124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f3be8d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f3be831b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f3be82c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f3be8c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f3c1891f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f3c1891f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f3c1891f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f3c1891f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f3c1891f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f3c1891f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f3c1891f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f3c1891f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f3c1891f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f3c1891f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f3c3b26f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f3c0853b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f3c085ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f3c060ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f3c060ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f3c060b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f3c060a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f3c060a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f3c060a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f3c4f14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f3c4f1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f3c4f05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f3c4f30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f98a1902082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f3be82ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-531332ff584f6b7c6f94b5d2fed46881168177c7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5199 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 77905466 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a3b2e7810, 0x561a3b4d101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a3b4d1020,0x561a3d3690e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/531332ff584f6b7c6f94b5d2fed46881168177c7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6596 processed earlier; will process 4433 files now Step #5: ==187240== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561a31ddc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561a38441898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561a384245dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561a384244fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561a31de2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561a31d43b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561a31d3e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561a31dd4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561a34da3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561a34da3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561a34da3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561a34da3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561a34da3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561a34da3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561a34da3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561a34da3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561a34da3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561a34da3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561a37038f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561a33d65b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561a33d70be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561a33b1cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561a33b1cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561a33b1d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561a33b1c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561a33b1c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561a33b1c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561a38426abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561a3842f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561a38417699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561a38442112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa1a22e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561a31d3cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9a7fed8707cef37f069626da47570b01801d2c3f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5200 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 78434737 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5583b7f72810, 0x5583b815c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5583b815c020,0x5583b9ff40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9a7fed8707cef37f069626da47570b01801d2c3f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6597 processed earlier; will process 4432 files now Step #5: ==187276== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5583aea679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5583b50cc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583b50af5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583b50af4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5583aea6dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5583ae9ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5583ae9c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5583aea5fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5583b1a2ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5583b1a2ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5583b1a2ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5583b1a2ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5583b1a2ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5583b1a2ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5583b1a2ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5583b1a2ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5583b1a2ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5583b1a2ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5583b3cc3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5583b09f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5583b09fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5583b07a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5583b07a7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5583b07a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5583b07a7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5583b07a7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5583b07a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5583b50b1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5583b50ba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5583b50a2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5583b50cd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe700905082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5583ae9c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8022e91dcc2e7191310bcda66765c8cdf6d85b1b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5201 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 78962622 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5601cc56d810, 0x5601cc75701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5601cc757020,0x5601ce5ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8022e91dcc2e7191310bcda66765c8cdf6d85b1b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6598 processed earlier; will process 4431 files now Step #5: #1 pulse cov: 3773 ft: 3774 exec/s: 0 rss: 177Mb Step #5: ==187312== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5601c30629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601c96c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601c96aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601c96aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5601c3068d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601c2fc9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601c2fc4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5601c305ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601c6029f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601c6029f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601c6029f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601c6029f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601c6029f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601c6029f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601c6029f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601c6029f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601c6029f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601c6029f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5601c82bef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601c4febb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601c4ff6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5601c4da2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5601c4da2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5601c4da3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5601c4da2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5601c4da2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5601c4da2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5601c96acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5601c96b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5601c969d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601c96c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc52a44c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601c2fc2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-261c7793b6b4ae4dd28bf022f3124311304f3c02 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5202 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 79543540 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5588c7c75810, 0x5588c7e5f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5588c7e5f020,0x5588c9cf70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/261c7793b6b4ae4dd28bf022f3124311304f3c02' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6600 processed earlier; will process 4429 files now Step #5: ==187348== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5588be76a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5588c4dcf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588c4db25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588c4db24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588be770d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588be6d1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588be6cc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588be762c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5588c1731f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5588c1731f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5588c1731f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5588c1731f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5588c1731f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5588c1731f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5588c1731f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5588c1731f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5588c1731f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5588c1731f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5588c39c6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588c06f3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588c06febe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588c04aac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588c04aac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588c04ab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588c04aa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588c04aa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588c04aa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5588c4db4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5588c4dbd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5588c4da5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5588c4dd0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9498dcf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588be6cab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3cbd1638aa23ee12bec539b755e2ddfd89679e74 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5203 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 80075578 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564ef6c1c810, 0x564ef6e0601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564ef6e06020,0x564ef8c9e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3cbd1638aa23ee12bec539b755e2ddfd89679e74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6601 processed earlier; will process 4428 files now Step #5: #1 pulse cov: 3876 ft: 3877 exec/s: 0 rss: 177Mb Step #5: ==187384== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564eed7119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564ef3d76898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564ef3d595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564ef3d594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564eed717d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564eed678b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564eed673355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564eed709c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564ef06d8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564ef06d8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564ef06d8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564ef06d8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564ef06d8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564ef06d8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564ef06d8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564ef06d8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564ef06d8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564ef06d8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564ef296df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564eef69ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564eef6a5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564eef451c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564eef451c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564eef452738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564eef451874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564eef451874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564eef451874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564ef3d5babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564ef3d64928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564ef3d4c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564ef3d77112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe7802c0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564eed671b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a700a1b80a8a8b70ad72e210599493b4cd6c26bb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5204 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 80708006 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1dc664810, 0x55a1dc84e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1dc84e020,0x55a1de6e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a700a1b80a8a8b70ad72e210599493b4cd6c26bb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6603 processed earlier; will process 4426 files now Step #5: ==187420== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1d31599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1d97be898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1d97a15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1d97a14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1d315fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1d30c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1d30bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1d3151c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1d6120f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1d6120f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1d6120f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1d6120f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1d6120f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1d6120f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1d6120f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1d6120f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1d6120f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1d6120f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1d83b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1d50e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1d50edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1d4e99c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1d4e99c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1d4e9a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1d4e99874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1d4e99874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1d4e99874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a1d97a3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a1d97ac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1d9794699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1d97bf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f47d1293082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1d30b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-39f52792564cc77c89a1eecc8f7d2e97df2798a2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5205 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 81243877 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a47aff7810, 0x55a47b1e101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a47b1e1020,0x55a47d0790e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/39f52792564cc77c89a1eecc8f7d2e97df2798a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6604 processed earlier; will process 4425 files now Step #5: ==187456== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a471aec9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a478151898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a4781345dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a4781344fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a471af2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a471a53b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a471a4e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a471ae4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a474ab3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a474ab3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a474ab3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a474ab3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a474ab3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a474ab3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a474ab3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a474ab3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a474ab3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a474ab3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a476d48f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a473a75b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a473a80be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a47382cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a47382cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a47382d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a47382c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a47382c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a47382c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a478136abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a47813f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a478127699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a478152112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1ebf845082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a471a4cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aaebbd89632f02f57cd7a6fcecfaefc72a5ffdfa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5206 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 81789248 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a296da810, 0x558a298c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a298c4020,0x558a2b75c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aaebbd89632f02f57cd7a6fcecfaefc72a5ffdfa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6605 processed earlier; will process 4424 files now Step #5: ==187492== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558a201cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a26834898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a268175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a268174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a201d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a20136b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a20131355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a201c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a23196f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a23196f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a23196f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a23196f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a23196f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a23196f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a23196f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a23196f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a23196f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a23196f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a2542bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a22158b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a22163be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a21f0fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a21f0fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a21f10738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a21f0f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a21f0f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a21f0f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a26819abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a26822928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a2680a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a26835112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff974803082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a2012fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4ed9834051efaa3984dc0c6289fc9c65f0b20c37 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5207 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 82331295 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5594a6d8c810, 0x5594a6f7601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5594a6f76020,0x5594a8e0e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4ed9834051efaa3984dc0c6289fc9c65f0b20c37' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6606 processed earlier; will process 4423 files now Step #5: ==187528== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55949d8819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5594a3ee6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5594a3ec95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5594a3ec94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55949d887d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55949d7e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55949d7e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55949d879c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5594a0848f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5594a0848f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5594a0848f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5594a0848f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5594a0848f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5594a0848f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5594a0848f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5594a0848f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5594a0848f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5594a0848f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5594a2addf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55949f80ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55949f815be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55949f5c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55949f5c1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55949f5c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55949f5c1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55949f5c1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55949f5c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5594a3ecbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5594a3ed4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5594a3ebc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5594a3ee7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7dadfab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55949d7e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9c23a3d126eea8fe7648af26d465331f93d07baf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5208 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 82869149 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc25e17810, 0x55fc2600101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc26001020,0x55fc27e990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c23a3d126eea8fe7648af26d465331f93d07baf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6607 processed earlier; will process 4422 files now Step #5: ==187564== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fc1c90c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc22f71898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc22f545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc22f544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc1c912d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc1c873b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc1c86e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc1c904c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc1f8d3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc1f8d3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc1f8d3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc1f8d3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc1f8d3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc1f8d3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc1f8d3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc1f8d3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc1f8d3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc1f8d3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc21b68f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc1e895b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc1e8a0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc1e64cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc1e64cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc1e64d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc1e64c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc1e64c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc1e64c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc22f56abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc22f5f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc22f47699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc22f72112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0e89c42082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc1c86cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fc8e774587705e95a857407fea1227c99d81e847 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5209 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 83418408 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5580ee52b810, 0x5580ee71501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5580ee715020,0x5580f05ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc8e774587705e95a857407fea1227c99d81e847' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6608 processed earlier; will process 4421 files now Step #5: ==187600== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5580e50209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5580eb685898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5580eb6685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5580eb6684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5580e5026d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5580e4f87b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5580e4f82355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5580e5018c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5580e7fe7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5580e7fe7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5580e7fe7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5580e7fe7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5580e7fe7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5580e7fe7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5580e7fe7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5580e7fe7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5580e7fe7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5580e7fe7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5580ea27cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5580e6fa9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5580e6fb4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580e6d60c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580e6d60c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580e6d61738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580e6d60874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580e6d60874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580e6d60874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5580eb66aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5580eb673928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5580eb65b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5580eb686112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa30a5c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5580e4f80b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ccdfe02365bc572a8ec107f25d6e5d0698018825 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5210 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 83957837 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c88a223810, 0x55c88a40d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c88a40d020,0x55c88c2a50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ccdfe02365bc572a8ec107f25d6e5d0698018825' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6609 processed earlier; will process 4420 files now Step #5: ==187636== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c880d189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c88737d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8873605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8873604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c880d1ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c880c7fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c880c7a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c880d10c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c883cdff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c883cdff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c883cdff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c883cdff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c883cdff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c883cdff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c883cdff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c883cdff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c883cdff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c883cdff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c885f74f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c882ca1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c882cacbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c882a58c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c882a58c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c882a59738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c882a58874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c882a58874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c882a58874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c887362abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c88736b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c887353699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c88737e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0f33f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c880c78b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5af8d947904ba37981772ff2ad52730ef8b230ec Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5211 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 84491803 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55faa73a0810, 0x55faa758a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55faa758a020,0x55faa94220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5af8d947904ba37981772ff2ad52730ef8b230ec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6610 processed earlier; will process 4419 files now Step #5: ==187672== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fa9de959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55faa44fa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55faa44dd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55faa44dd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fa9de9bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fa9ddfcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fa9ddf7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fa9de8dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55faa0e5cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55faa0e5cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55faa0e5cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55faa0e5cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55faa0e5cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55faa0e5cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55faa0e5cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55faa0e5cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55faa0e5cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55faa0e5cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55faa30f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fa9fe1eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fa9fe29be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fa9fbd5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fa9fbd5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fa9fbd6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fa9fbd5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fa9fbd5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fa9fbd5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55faa44dfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55faa44e8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55faa44d0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55faa44fb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd8b7fb7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fa9ddf5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ba561ed290a6724a0d5be570fc9319b5e38cb901 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5212 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 85022836 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555f84549810, 0x555f8473301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555f84733020,0x555f865cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba561ed290a6724a0d5be570fc9319b5e38cb901' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6611 processed earlier; will process 4418 files now Step #5: ==187708== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555f7b03e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555f816a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555f816865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555f816864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555f7b044d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555f7afa5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555f7afa0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555f7b036c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555f7e005f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555f7e005f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555f7e005f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555f7e005f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555f7e005f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555f7e005f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555f7e005f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555f7e005f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555f7e005f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555f7e005f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555f8029af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555f7cfc7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555f7cfd2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555f7cd7ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555f7cd7ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555f7cd7f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555f7cd7e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555f7cd7e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555f7cd7e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555f81688abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555f81691928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555f81679699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555f816a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff7b39ea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555f7af9eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-16274131472f774710305f62c47f3c008f5b9e29 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5213 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 85549018 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b4676da810, 0x55b4678c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b4678c4020,0x55b46975c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16274131472f774710305f62c47f3c008f5b9e29' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6612 processed earlier; will process 4417 files now Step #5: ==187744== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b45e1cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b464834898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b4648175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b4648174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b45e1d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b45e136b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b45e131355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b45e1c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b461196f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b461196f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b461196f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b461196f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b461196f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b461196f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b461196f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b461196f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b461196f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b461196f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b46342bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b460158b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b460163be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b45ff0fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b45ff0fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b45ff10738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b45ff0f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b45ff0f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b45ff0f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b464819abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b464822928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b46480a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b464835112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff6c3361082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b45e12fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9a0b89880adb3f93f28650974ffa3dbcb2cfe8fa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5214 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 86081056 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55de87bcc810, 0x55de87db601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55de87db6020,0x55de89c4e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9a0b89880adb3f93f28650974ffa3dbcb2cfe8fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6613 processed earlier; will process 4416 files now Step #5: ==187780== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55de7e6c19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55de84d26898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55de84d095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55de84d094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55de7e6c7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55de7e628b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55de7e623355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55de7e6b9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55de81688f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55de81688f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55de81688f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55de81688f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55de81688f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55de81688f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55de81688f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55de81688f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55de81688f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55de81688f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55de8391df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55de8064ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55de80655be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55de80401c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55de80401c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55de80402738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55de80401874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55de80401874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55de80401874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55de84d0babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55de84d14928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55de84cfc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55de84d27112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9d7abcf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55de7e621b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a1a874590da2f5bfd7002ebf7b52f2900a358e3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5215 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 86615962 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f4a93a2810, 0x55f4a958c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f4a958c020,0x55f4ab4240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a1a874590da2f5bfd7002ebf7b52f2900a358e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6614 processed earlier; will process 4415 files now Step #5: ==187816== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f49fe979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f4a64fc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f4a64df5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f4a64df4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f49fe9dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f49fdfeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f49fdf9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f49fe8fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f4a2e5ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f4a2e5ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f4a2e5ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f4a2e5ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f4a2e5ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f4a2e5ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f4a2e5ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f4a2e5ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f4a2e5ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f4a2e5ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4a50f3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4a1e20b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4a1e2bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f4a1bd7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f4a1bd7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f4a1bd8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f4a1bd7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f4a1bd7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f4a1bd7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f4a64e1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f4a64ea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f4a64d2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f4a64fd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd8cf53a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f49fdf7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6bdcce405e3824d3d9e49177c6d7fdc1d430f2fd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5216 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 87155311 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca8033f810, 0x55ca8052901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca80529020,0x55ca823c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bdcce405e3824d3d9e49177c6d7fdc1d430f2fd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6615 processed earlier; will process 4414 files now Step #5: #1 pulse cov: 3985 ft: 3986 exec/s: 0 rss: 178Mb Step #5: ==187852== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ca76e349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca7d499898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca7d47c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca7d47c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca76e3ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca76d9bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca76d96355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca76e2cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca79dfbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca79dfbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca79dfbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca79dfbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca79dfbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca79dfbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca79dfbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca79dfbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca79dfbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca79dfbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca7c090f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca78dbdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca78dc8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca78b74c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca78b74c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca78b75738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca78b74874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca78b74874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca78b74874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca7d47eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca7d487928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca7d46f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca7d49a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e64ba6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca76d94b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-39f134aef7770f9424fb2019ae82145394400294 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5217 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 87746918 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563ee53d6810, 0x563ee55c001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563ee55c0020,0x563ee74580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/39f134aef7770f9424fb2019ae82145394400294' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6617 processed earlier; will process 4412 files now Step #5: ==187888== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563edbecb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563ee2530898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563ee25135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563ee25134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563edbed1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563edbe32b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563edbe2d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563edbec3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563edee92f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563edee92f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563edee92f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563edee92f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563edee92f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563edee92f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563edee92f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563edee92f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563edee92f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563edee92f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563ee1127f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563edde54b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563edde5fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563eddc0bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563eddc0bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563eddc0c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563eddc0b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563eddc0b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563eddc0b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563ee2515abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563ee251e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563ee2506699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563ee2531112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c5aff6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563edbe2bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-023277ac2e4e7adf2480f63c9863559e7a8ba77a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5218 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 88283332 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56185537c810, 0x56185556601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561855566020,0x5618573fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/023277ac2e4e7adf2480f63c9863559e7a8ba77a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6618 processed earlier; will process 4411 files now Step #5: ==187924== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56184be719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5618524d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5618524b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5618524b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56184be77d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56184bdd8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56184bdd3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56184be69c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56184ee38f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56184ee38f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56184ee38f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56184ee38f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56184ee38f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56184ee38f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56184ee38f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56184ee38f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56184ee38f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56184ee38f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5618510cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56184ddfab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56184de05be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56184dbb1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56184dbb1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56184dbb2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56184dbb1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56184dbb1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56184dbb1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5618524bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5618524c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5618524ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5618524d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4d2c32f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56184bdd1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-35c517125087abbf261a58c7512340c9c9fd957b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5219 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 88804559 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564618b91810, 0x564618d7b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564618d7b020,0x56461ac130e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/35c517125087abbf261a58c7512340c9c9fd957b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6619 processed earlier; will process 4410 files now Step #5: #1 pulse cov: 4121 ft: 4122 exec/s: 0 rss: 176Mb Step #5: ==187960== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56460f6869c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564615ceb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564615cce5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564615cce4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56460f68cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56460f5edb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56460f5e8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56460f67ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56461264df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56461264df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56461264df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56461264df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56461264df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56461264df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56461264df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56461264df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56461264df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56461264df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5646148e2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56461160fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56461161abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5646113c6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5646113c6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5646113c7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5646113c6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5646113c6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5646113c6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564615cd0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564615cd9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564615cc1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564615cec112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f512a718082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56460f5e6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6892ad6f83abf53daccc571af01200e22afca159 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5220 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 89392760 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fca882c810, 0x55fca8a1601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fca8a16020,0x55fcaa8ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6892ad6f83abf53daccc571af01200e22afca159' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6621 processed earlier; will process 4408 files now Step #5: ==187996== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fc9f3219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fca5986898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fca59695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fca59694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc9f327d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc9f288b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc9f283355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc9f319c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fca22e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fca22e8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fca22e8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fca22e8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fca22e8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fca22e8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fca22e8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fca22e8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fca22e8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fca22e8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fca457df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fca12aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fca12b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fca1061c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fca1061c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fca1062738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fca1061874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fca1061874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fca1061874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fca596babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fca5974928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fca595c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fca5987112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f038b8b5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc9f281b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-333c9e51310af09e3587fcda7e49d82907114ec2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5221 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 89923587 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55585a07c810, 0x55585a26601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55585a266020,0x55585c0fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/333c9e51310af09e3587fcda7e49d82907114ec2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6622 processed earlier; will process 4407 files now Step #5: ==188032== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555850b719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5558571d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5558571b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5558571b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555850b77d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555850ad8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555850ad3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555850b69c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555853b38f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555853b38f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555853b38f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555853b38f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555853b38f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555853b38f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555853b38f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555853b38f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555853b38f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555853b38f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555855dcdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555852afab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555852b05be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5558528b1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5558528b1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5558528b2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5558528b1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5558528b1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5558528b1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5558571bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5558571c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5558571ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5558571d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e3bb10082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555850ad1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-870957513d848a093272a6a3f0cc0de682a48323 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5222 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 90448709 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e0d3c4d810, 0x55e0d3e3701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e0d3e37020,0x55e0d5ccf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/870957513d848a093272a6a3f0cc0de682a48323' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6623 processed earlier; will process 4406 files now Step #5: ==188068== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e0ca7429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e0d0da7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e0d0d8a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e0d0d8a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e0ca748d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e0ca6a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e0ca6a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e0ca73ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e0cd709f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e0cd709f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e0cd709f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e0cd709f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e0cd709f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e0cd709f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e0cd709f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e0cd709f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e0cd709f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e0cd709f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e0cf99ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e0cc6cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e0cc6d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e0cc482c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e0cc482c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e0cc483738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e0cc482874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e0cc482874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e0cc482874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e0d0d8cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e0d0d95928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e0d0d7d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e0d0da8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1e0ae2c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e0ca6a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4ed472d4439c549a77d64383ff5d76c94284dd31 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5223 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 90982941 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56229bce1810, 0x56229becb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56229becb020,0x56229dd630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4ed472d4439c549a77d64383ff5d76c94284dd31' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6624 processed earlier; will process 4405 files now Step #5: #1 pulse cov: 3728 ft: 3729 exec/s: 0 rss: 178Mb Step #5: ==188104== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5622927d69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562298e3b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562298e1e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562298e1e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5622927dcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56229273db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562292738355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5622927cec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56229579df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56229579df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56229579df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56229579df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56229579df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56229579df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56229579df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56229579df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56229579df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56229579df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562297a32f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56229475fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56229476abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562294516c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562294516c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562294517738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562294516874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562294516874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562294516874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562298e20abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562298e29928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562298e11699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562298e3c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f04bf78f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562292736b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-af456d01d13a77f7c58a4b76eae1843027d4bb1b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5224 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 91692297 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb2a554810, 0x55cb2a73e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb2a73e020,0x55cb2c5d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af456d01d13a77f7c58a4b76eae1843027d4bb1b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6626 processed earlier; will process 4403 files now Step #5: ==188140== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cb210499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb276ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb276915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb276914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb2104fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb20fb0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb20fab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb21041c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb24010f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb24010f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb24010f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb24010f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb24010f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb24010f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb24010f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb24010f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb24010f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb24010f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb262a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb22fd2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb22fddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb22d89c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb22d89c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb22d8a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb22d89874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb22d89874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb22d89874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb27693abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb2769c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb27684699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb276af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f257956b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb20fa9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b76acc156e3fea49a0c21ac924c32e9128144f6d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5225 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 92260588 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560edd1b3810, 0x560edd39d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560edd39d020,0x560edf2350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b76acc156e3fea49a0c21ac924c32e9128144f6d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6627 processed earlier; will process 4402 files now Step #5: ==188176== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560ed3ca89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560eda30d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560eda2f05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560eda2f04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560ed3caed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560ed3c0fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560ed3c0a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560ed3ca0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560ed6c6ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560ed6c6ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560ed6c6ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560ed6c6ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560ed6c6ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560ed6c6ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560ed6c6ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560ed6c6ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560ed6c6ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560ed6c6ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560ed8f04f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560ed5c31b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560ed5c3cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560ed59e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560ed59e8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560ed59e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560ed59e8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560ed59e8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560ed59e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560eda2f2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560eda2fb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560eda2e3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560eda30e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f75a1eb6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560ed3c08b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a87be211c04f0f5f5512df421733d19e0d8d9721 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5226 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 92793067 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c16f84d810, 0x55c16fa3701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c16fa37020,0x55c1718cf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a87be211c04f0f5f5512df421733d19e0d8d9721' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6628 processed earlier; will process 4401 files now Step #5: ==188212== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c1663429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c16c9a7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c16c98a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c16c98a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c166348d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c1662a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c1662a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c16633ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c169309f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c169309f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c169309f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c169309f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c169309f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c169309f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c169309f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c169309f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c169309f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c169309f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c16b59ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c1682cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c1682d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c168082c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c168082c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c168083738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c168082874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c168082874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c168082874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c16c98cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c16c995928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c16c97d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c16c9a8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb909aae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c1662a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9af2eff803c1c53982994c9d29800f0f26b25b23 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5227 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 93322232 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f0611b9810, 0x55f0613a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f0613a3020,0x55f06323b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9af2eff803c1c53982994c9d29800f0f26b25b23' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6629 processed earlier; will process 4400 files now Step #5: #1 pulse cov: 3693 ft: 3694 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 3913 ft: 4426 exec/s: 0 rss: 177Mb Step #5: ==188248== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f057cae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f05e313898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f05e2f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f05e2f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f057cb4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f057c15b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f057c10355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f057ca6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f05ac75f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f05ac75f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f05ac75f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f05ac75f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f05ac75f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f05ac75f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f05ac75f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f05ac75f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f05ac75f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f05ac75f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f05cf0af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f059c37b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f059c42be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f0599eec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f0599eec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f0599ef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f0599ee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f0599ee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f0599ee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f05e2f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f05e301928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f05e2e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f05e314112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88ad66d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f057c0eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-457910b9f93d15900a0d1164753a831a325f69f3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5228 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 93977773 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557dc26fc810, 0x557dc28e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557dc28e6020,0x557dc477e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/457910b9f93d15900a0d1164753a831a325f69f3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6632 processed earlier; will process 4397 files now Step #5: ==188284== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557db91f19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557dbf856898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557dbf8395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557dbf8394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557db91f7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557db9158b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557db9153355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557db91e9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557dbc1b8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557dbc1b8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557dbc1b8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557dbc1b8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557dbc1b8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557dbc1b8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557dbc1b8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557dbc1b8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557dbc1b8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557dbc1b8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557dbe44df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557dbb17ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557dbb185be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557dbaf31c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557dbaf31c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557dbaf32738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557dbaf31874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557dbaf31874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557dbaf31874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557dbf83babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557dbf844928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557dbf82c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557dbf857112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcaaeb12082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557db9151b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8c309ecc2f6a417b3be6c07bb8fdd7d8edc8c71 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5229 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 94514268 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab6ee00810, 0x55ab6efea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab6efea020,0x55ab70e820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8c309ecc2f6a417b3be6c07bb8fdd7d8edc8c71' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6633 processed earlier; will process 4396 files now Step #5: #1 pulse cov: 3984 ft: 3985 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4215 ft: 4808 exec/s: 0 rss: 179Mb Step #5: ==188320== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ab658f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab6bf5a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab6bf3d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab6bf3d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab658fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab6585cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab65857355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab658edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab688bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab688bcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab688bcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab688bcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab688bcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab688bcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab688bcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab688bcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab688bcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab688bcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab6ab51f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab6787eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab67889be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab67635c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab67635c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab67636738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab67635874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab67635874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab67635874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab6bf3fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab6bf48928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab6bf30699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab6bf5b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e92bcb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab65855b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-00223ffa0391af818ae45105b852354da8b8c394 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5230 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 95129164 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c4e735b810, 0x55c4e754501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c4e7545020,0x55c4e93dd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/00223ffa0391af818ae45105b852354da8b8c394' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6636 processed earlier; will process 4393 files now Step #5: ==188356== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c4dde509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c4e44b5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c4e44985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c4e44984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c4dde56d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c4dddb7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c4dddb2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c4dde48c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c4e0e17f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c4e0e17f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c4e0e17f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c4e0e17f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c4e0e17f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c4e0e17f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c4e0e17f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c4e0e17f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c4e0e17f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c4e0e17f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c4e30acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c4dfdd9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c4dfde4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c4dfb90c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c4dfb90c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c4dfb91738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c4dfb90874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c4dfb90874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c4dfb90874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c4e449aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c4e44a3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c4e448b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c4e44b6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa083a40082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c4dddb0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cbe5517363fb5cf45a0dc527584417c48db94979 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5231 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 95676908 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cf2160b810, 0x55cf217f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cf217f5020,0x55cf2368d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cbe5517363fb5cf45a0dc527584417c48db94979' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6637 processed earlier; will process 4392 files now Step #5: #1 pulse cov: 4028 ft: 4029 exec/s: 0 rss: 179Mb Step #5: ==188392== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cf181009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cf1e765898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cf1e7485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cf1e7484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cf18106d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cf18067b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cf18062355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cf180f8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cf1b0c7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cf1b0c7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cf1b0c7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cf1b0c7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cf1b0c7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cf1b0c7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cf1b0c7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cf1b0c7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cf1b0c7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cf1b0c7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cf1d35cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cf1a089b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cf1a094be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cf19e40c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cf19e40c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cf19e41738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cf19e40874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cf19e40874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cf19e40874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cf1e74aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cf1e753928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cf1e73b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cf1e766112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe44a823082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cf18060b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-44dc4988d32b0d9ef79ca364f9546dcabfe20cbe Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5232 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 96265192 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ef72b50810, 0x55ef72d3a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ef72d3a020,0x55ef74bd20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/44dc4988d32b0d9ef79ca364f9546dcabfe20cbe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6639 processed earlier; will process 4390 files now Step #5: #1 pulse cov: 11152 ft: 11153 exec/s: 0 rss: 203Mb Step #5: ==188428== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ef696459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ef6fcaa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ef6fc8d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ef6fc8d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef6964bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef695acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef695a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef6963dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef6c60cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef6c60cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef6c60cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef6c60cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef6c60cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef6c60cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef6c60cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef6c60cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef6c60cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef6c60cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef6e8a1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef6b5ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef6b5d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef6b385c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef6b385c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef6b386738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef6b385874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef6b385874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef6b385874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ef6fc8fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ef6fc98928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ef6fc80699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ef6fcab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb79c781082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef695a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2cb6874f42c2cdb5c01f691065cabb19f7befd66 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5233 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 97046106 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5574d246d810, 0x5574d265701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5574d2657020,0x5574d44ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2cb6874f42c2cdb5c01f691065cabb19f7befd66' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6641 processed earlier; will process 4388 files now Step #5: ==188464== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5574c8f629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5574cf5c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5574cf5aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5574cf5aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5574c8f68d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5574c8ec9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5574c8ec4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5574c8f5ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5574cbf29f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5574cbf29f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5574cbf29f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5574cbf29f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5574cbf29f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5574cbf29f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5574cbf29f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5574cbf29f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5574cbf29f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5574cbf29f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5574ce1bef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5574caeebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5574caef6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5574caca2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5574caca2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5574caca3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5574caca2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5574caca2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5574caca2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5574cf5acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5574cf5b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5574cf59d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5574cf5c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f161a022082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5574c8ec2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1c183db0d4b1fe746ceea7aff26665ad86b7e63a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5234 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 97570657 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c3d1b13810, 0x55c3d1cfd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c3d1cfd020,0x55c3d3b950e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c183db0d4b1fe746ceea7aff26665ad86b7e63a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6642 processed earlier; will process 4387 files now Step #5: #1 pulse cov: 3882 ft: 3883 exec/s: 0 rss: 176Mb Step #5: ==188500== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c3c86089c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c3cec6d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c3cec505dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c3cec504fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c3c860ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c3c856fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c3c856a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c3c8600c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c3cb5cff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c3cb5cff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c3cb5cff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c3cb5cff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c3cb5cff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c3cb5cff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c3cb5cff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c3cb5cff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c3cb5cff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c3cb5cff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c3cd864f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c3ca591b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c3ca59cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c3ca348c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c3ca348c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c3ca349738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c3ca348874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c3ca348874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c3ca348874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c3cec52abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c3cec5b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c3cec43699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c3cec6e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbc96c52082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c3c8568b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2b888d50b41b6f6004feedeebe538a57b8613b64 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5235 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 98313130 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5615c31eb810, 0x5615c33d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5615c33d5020,0x5615c526d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2b888d50b41b6f6004feedeebe538a57b8613b64' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6644 processed earlier; will process 4385 files now Step #5: ==188536== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5615b9ce09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5615c0345898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5615c03285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5615c03284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5615b9ce6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5615b9c47b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5615b9c42355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5615b9cd8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5615bcca7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5615bcca7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5615bcca7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5615bcca7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5615bcca7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5615bcca7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5615bcca7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5615bcca7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5615bcca7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5615bcca7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5615bef3cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5615bbc69b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5615bbc74be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5615bba20c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5615bba20c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5615bba21738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5615bba20874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5615bba20874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5615bba20874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5615c032aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5615c0333928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5615c031b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5615c0346112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f662de59082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5615b9c40b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aebb1e909d4d154524ba1882c5b376abfe81bb80 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5236 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 98870592 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5581ac62f810, 0x5581ac81901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5581ac819020,0x5581ae6b10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aebb1e909d4d154524ba1882c5b376abfe81bb80' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6645 processed earlier; will process 4384 files now Step #5: ==188572== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5581a31249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5581a9789898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5581a976c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5581a976c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5581a312ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5581a308bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5581a3086355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5581a311cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5581a60ebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5581a60ebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5581a60ebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5581a60ebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5581a60ebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5581a60ebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5581a60ebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5581a60ebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5581a60ebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5581a60ebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5581a8380f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5581a50adb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5581a50b8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5581a4e64c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5581a4e64c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5581a4e65738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5581a4e64874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5581a4e64874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5581a4e64874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5581a976eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5581a9777928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5581a975f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5581a978a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f91d2621082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5581a3084b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-600303f5786af2b945519a4ba6d8ea0f511dc94a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5237 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 99408808 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5636a8604810, 0x5636a87ee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5636a87ee020,0x5636aa6860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/600303f5786af2b945519a4ba6d8ea0f511dc94a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6646 processed earlier; will process 4383 files now Step #5: #1 pulse cov: 11478 ft: 11479 exec/s: 0 rss: 200Mb Step #5: #2 pulse cov: 12208 ft: 13212 exec/s: 0 rss: 202Mb Step #5: ==188608== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56369f0f99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5636a575e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636a57415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636a57414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56369f0ffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56369f060b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56369f05b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56369f0f1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5636a20c0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5636a20c0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5636a20c0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5636a20c0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5636a20c0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5636a20c0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5636a20c0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5636a20c0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5636a20c0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5636a20c0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5636a4355f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5636a1082b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5636a108dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5636a0e39c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5636a0e39c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5636a0e3a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5636a0e39874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5636a0e39874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5636a0e39874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5636a5743abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5636a574c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5636a5734699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5636a575f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c07e14082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56369f059b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-66b281e038c98e96601306d1287bfe4fc96c210b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5238 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 100119312 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5591065ae810, 0x55910679801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559106798020,0x5591086300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/66b281e038c98e96601306d1287bfe4fc96c210b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6649 processed earlier; will process 4380 files now Step #5: ==188644== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5590fd0a39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559103708898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5591036eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5591036eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5590fd0a9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5590fd00ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5590fd005355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5590fd09bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55910006af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55910006af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55910006af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55910006af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55910006af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55910006af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55910006af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55910006af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55910006af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55910006af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5591022fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5590ff02cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5590ff037be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5590fede3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5590fede3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5590fede4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5590fede3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5590fede3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5590fede3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5591036edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5591036f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5591036de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559103709112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fea3591f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5590fd003b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8eda5da9cf386cebedbe3d4d043f45d971afb1fc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5239 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 100779063 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647debf5810, 0x5647deddf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5647deddf020,0x5647e0c770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8eda5da9cf386cebedbe3d4d043f45d971afb1fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6650 processed earlier; will process 4379 files now Step #5: ==188680== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647d56ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647dbd4f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647dbd325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647dbd324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647d56f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647d5651b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647d564c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647d56e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647d86b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647d86b1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647d86b1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647d86b1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647d86b1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647d86b1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647d86b1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647d86b1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647d86b1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647d86b1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647da946f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647d7673b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647d767ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647d742ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647d742ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647d742b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647d742a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647d742a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647d742a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647dbd34abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647dbd3d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647dbd25699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647dbd50112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c96f53082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647d564ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2835572fa689ed41cd30a6c2adde26180a063260 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5240 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 101314167 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55747d87d810, 0x55747da6701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55747da67020,0x55747f8ff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2835572fa689ed41cd30a6c2adde26180a063260' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6651 processed earlier; will process 4378 files now Step #5: #1 pulse cov: 4017 ft: 4018 exec/s: 0 rss: 177Mb Step #5: ==188716== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5574743729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55747a9d7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55747a9ba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55747a9ba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557474378d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5574742d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5574742d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55747436ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557477339f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557477339f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557477339f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557477339f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557477339f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557477339f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557477339f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557477339f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557477339f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557477339f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5574795cef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5574762fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557476306be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5574760b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5574760b2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5574760b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5574760b2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5574760b2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5574760b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55747a9bcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55747a9c5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55747a9ad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55747a9d8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f3d24d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5574742d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-284bad463a452663754de01016fbd730ae19ef94 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5241 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 101981644 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557703b74810, 0x557703d5e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557703d5e020,0x557705bf60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/284bad463a452663754de01016fbd730ae19ef94' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6653 processed earlier; will process 4376 files now Step #5: #1 pulse cov: 3581 ft: 3582 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4186 ft: 4632 exec/s: 0 rss: 177Mb Step #5: ==188752== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5576fa6699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557700cce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557700cb15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557700cb14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5576fa66fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5576fa5d0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5576fa5cb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5576fa661c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576fd630f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576fd630f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576fd630f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576fd630f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576fd630f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576fd630f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576fd630f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576fd630f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576fd630f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576fd630f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5576ff8c5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5576fc5f2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5576fc5fdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5576fc3a9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5576fc3a9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5576fc3aa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5576fc3a9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5576fc3a9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5576fc3a9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557700cb3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557700cbc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557700ca4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557700ccf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9aef0c6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5576fa5c9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-05cd77cfe1af7b214797731684bb5fc60949655d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5242 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 102591424 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fbc8f90810, 0x55fbc917a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fbc917a020,0x55fbcb0120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/05cd77cfe1af7b214797731684bb5fc60949655d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6656 processed earlier; will process 4373 files now Step #5: #1 pulse cov: 3655 ft: 3656 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 3809 ft: 3932 exec/s: 0 rss: 179Mb Step #5: #4 pulse cov: 4531 ft: 5437 exec/s: 0 rss: 181Mb Step #5: ==188788== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fbbfa859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fbc60ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fbc60cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fbc60cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fbbfa8bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fbbf9ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fbbf9e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fbbfa7dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fbc2a4cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fbc2a4cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fbc2a4cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fbc2a4cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fbc2a4cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fbc2a4cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fbc2a4cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fbc2a4cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fbc2a4cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fbc2a4cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fbc4ce1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fbc1a0eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fbc1a19be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fbc17c5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fbc17c5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fbc17c6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fbc17c5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fbc17c5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fbc17c5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fbc60cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fbc60d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fbc60c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fbc60eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f62f5b9f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fbbf9e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-44ec00a9a4a26f9871d1a38663a083812b5ad3a8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5243 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 103266886 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55991e8ff810, 0x55991eae901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55991eae9020,0x5599209810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/44ec00a9a4a26f9871d1a38663a083812b5ad3a8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6661 processed earlier; will process 4368 files now Step #5: #1 pulse cov: 3832 ft: 3833 exec/s: 0 rss: 177Mb Step #5: ==188824== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5599153f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55991ba59898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55991ba3c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55991ba3c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5599153fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55991535bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559915356355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5599153ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5599183bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5599183bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5599183bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5599183bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5599183bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5599183bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5599183bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5599183bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5599183bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5599183bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55991a650f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55991737db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559917388be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559917134c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559917134c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559917135738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559917134874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559917134874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559917134874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55991ba3eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55991ba47928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55991ba2f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55991ba5a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0123cca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559915354b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3272928607f3de9ca0040068ebd7b5beb33a07d8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5244 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 103841688 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db3ba4d810, 0x55db3bc3701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db3bc37020,0x55db3dacf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3272928607f3de9ca0040068ebd7b5beb33a07d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6663 processed earlier; will process 4366 files now Step #5: #1 pulse cov: 3654 ft: 3655 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4116 ft: 4556 exec/s: 0 rss: 177Mb Step #5: ==188860== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db325429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db38ba7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db38b8a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db38b8a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db32548d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db324a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db324a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db3253ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db35509f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db35509f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db35509f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db35509f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db35509f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db35509f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db35509f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db35509f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db35509f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db35509f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db3779ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db344cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db344d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db34282c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db34282c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db34283738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db34282874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db34282874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db34282874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db38b8cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db38b95928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db38b7d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db38ba8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0a8d29f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db324a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-afb8fdddb30107c4aa9ecf6917b83fca77a4e43d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5245 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 104446989 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558143f00810, 0x5581440ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5581440ea020,0x558145f820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/afb8fdddb30107c4aa9ecf6917b83fca77a4e43d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6666 processed earlier; will process 4363 files now Step #5: ==188896== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55813a9f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55814105a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55814103d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55814103d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55813a9fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55813a95cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55813a957355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55813a9edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55813d9bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55813d9bcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55813d9bcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55813d9bcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55813d9bcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55813d9bcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55813d9bcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55813d9bcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55813d9bcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55813d9bcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55813fc51f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55813c97eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55813c989be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55813c735c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55813c735c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55813c736738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55813c735874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55813c735874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55813c735874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55814103fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558141048928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558141030699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55814105b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff224436082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55813a955b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9a5b2f9ac3eccaa4ed9189162987056092ea2734 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5246 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 104977093 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c659a58810, 0x55c659c4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c659c42020,0x55c65bada0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9a5b2f9ac3eccaa4ed9189162987056092ea2734' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6667 processed earlier; will process 4362 files now Step #5: #1 pulse cov: 10714 ft: 10715 exec/s: 0 rss: 201Mb Step #5: ==188932== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c65054d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c656bb2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c656b955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c656b954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c650553d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6504b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6504af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c650545c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c653514f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c653514f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c653514f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c653514f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c653514f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c653514f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c653514f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c653514f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c653514f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c653514f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c6557a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6524d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c6524e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c65228dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c65228dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c65228e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c65228d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c65228d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c65228d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c656b97abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c656ba0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c656b88699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c656bb3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbef80f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6504adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-07531233b0e8301ed00365fd625b7e6adbcfe571 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5247 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 105625145 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5581984ae810, 0x55819869801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558198698020,0x55819a5300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/07531233b0e8301ed00365fd625b7e6adbcfe571' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6669 processed earlier; will process 4360 files now Step #5: ==188968== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55818efa39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558195608898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5581955eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5581955eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55818efa9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55818ef0ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55818ef05355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55818ef9bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558191f6af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558191f6af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558191f6af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558191f6af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558191f6af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558191f6af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558191f6af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558191f6af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558191f6af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558191f6af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5581941fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558190f2cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558190f37be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558190ce3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558190ce3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558190ce4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558190ce3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558190ce3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558190ce3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5581955edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5581955f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5581955de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558195609112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7eff9e9a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55818ef03b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fc1290f3dffec551f6d09e8e154e09b3539c9d97 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5248 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 106144598 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5645a353f810, 0x5645a372901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5645a3729020,0x5645a55c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc1290f3dffec551f6d09e8e154e09b3539c9d97' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6670 processed earlier; will process 4359 files now Step #5: ==189004== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56459a0349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5645a0699898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5645a067c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5645a067c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56459a03ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564599f9bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564599f96355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56459a02cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56459cffbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56459cffbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56459cffbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56459cffbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56459cffbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56459cffbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56459cffbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56459cffbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56459cffbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56459cffbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56459f290f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56459bfbdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56459bfc8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56459bd74c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56459bd74c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56459bd75738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56459bd74874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56459bd74874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56459bd74874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5645a067eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5645a0687928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5645a066f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5645a069a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f66c1f00082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564599f94b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-772b4b103decdc1b5bc0aac5ab18e74872b69d9b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5249 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 106698532 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f763477810, 0x55f76366101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f763661020,0x55f7654f90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/772b4b103decdc1b5bc0aac5ab18e74872b69d9b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6671 processed earlier; will process 4358 files now Step #5: ==189040== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f759f6c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7605d1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7605b45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7605b44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f759f72d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f759ed3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f759ece355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f759f64c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f75cf33f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f75cf33f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f75cf33f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f75cf33f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f75cf33f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f75cf33f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f75cf33f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f75cf33f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f75cf33f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f75cf33f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f75f1c8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f75bef5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f75bf00be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f75bcacc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f75bcacc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f75bcad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f75bcac874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f75bcac874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f75bcac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7605b6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7605bf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7605a7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7605d2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7eff19017082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f759eccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c7d34fe4c38cfcda4d9a1e512ad2d449d31d5f39 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5250 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 107220826 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559682379810, 0x55968256301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559682563020,0x5596843fb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c7d34fe4c38cfcda4d9a1e512ad2d449d31d5f39' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6672 processed earlier; will process 4357 files now Step #5: #1 pulse cov: 3958 ft: 3959 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4892 ft: 5240 exec/s: 0 rss: 179Mb Step #5: ==189076== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559678e6e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55967f4d3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55967f4b65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55967f4b64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559678e74d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559678dd5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559678dd0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559678e66c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55967be35f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55967be35f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55967be35f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55967be35f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55967be35f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55967be35f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55967be35f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55967be35f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55967be35f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55967be35f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55967e0caf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55967adf7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55967ae02be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55967abaec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55967abaec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55967abaf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55967abae874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55967abae874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55967abae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55967f4b8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55967f4c1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55967f4a9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55967f4d4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd608a96082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559678dceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7b35eac1fe54ba0fc6b69150b9989bca8f935033 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5251 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 107824528 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5641e0277810, 0x5641e046101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5641e0461020,0x5641e22f90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7b35eac1fe54ba0fc6b69150b9989bca8f935033' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6675 processed earlier; will process 4354 files now Step #5: ==189112== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5641d6d6c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5641dd3d1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5641dd3b45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5641dd3b44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5641d6d72d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641d6cd3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641d6cce355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5641d6d64c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5641d9d33f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5641d9d33f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5641d9d33f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5641d9d33f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5641d9d33f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5641d9d33f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5641d9d33f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5641d9d33f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5641d9d33f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5641d9d33f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5641dbfc8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5641d8cf5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5641d8d00be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5641d8aacc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5641d8aacc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5641d8aad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5641d8aac874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5641d8aac874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5641d8aac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5641dd3b6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5641dd3bf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5641dd3a7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5641dd3d2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0b673b7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641d6cccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-01079d0361506c9dd5e7f7940c7b479d24207f91 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5252 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 108514058 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5580aa9ed810, 0x5580aabd701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5580aabd7020,0x5580aca6f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01079d0361506c9dd5e7f7940c7b479d24207f91' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6676 processed earlier; will process 4353 files now Step #5: ==189148== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5580a14e29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5580a7b47898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5580a7b2a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5580a7b2a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5580a14e8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5580a1449b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5580a1444355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5580a14dac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5580a44a9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5580a44a9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5580a44a9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5580a44a9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5580a44a9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5580a44a9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5580a44a9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5580a44a9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5580a44a9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5580a44a9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5580a673ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5580a346bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5580a3476be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580a3222c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580a3222c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580a3223738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580a3222874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580a3222874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580a3222874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5580a7b2cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5580a7b35928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5580a7b1d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5580a7b48112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbd54213082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5580a1442b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c143388b733e9799c2f2d407e7edfa99f6b9cc77 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5253 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 109160951 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559eaab86810, 0x559eaad7001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559eaad70020,0x559eacc080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c143388b733e9799c2f2d407e7edfa99f6b9cc77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6677 processed earlier; will process 4352 files now Step #5: ==189184== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559ea167b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ea7ce0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ea7cc35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ea7cc34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ea1681d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ea15e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ea15dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ea1673c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ea4642f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ea4642f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ea4642f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ea4642f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ea4642f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ea4642f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ea4642f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ea4642f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ea4642f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ea4642f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ea68d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559ea3604b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559ea360fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559ea33bbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559ea33bbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559ea33bc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559ea33bb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559ea33bb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559ea33bb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ea7cc5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ea7cce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ea7cb6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ea7ce1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8487eef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ea15dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a95b3a3ed123477e8453788f030cc50d427280b2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5254 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 109824725 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bc7edda810, 0x55bc7efc401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bc7efc4020,0x55bc80e5c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a95b3a3ed123477e8453788f030cc50d427280b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6678 processed earlier; will process 4351 files now Step #5: ==189220== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bc758cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bc7bf34898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bc7bf175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bc7bf174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bc758d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bc75836b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bc75831355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bc758c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bc78896f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bc78896f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bc78896f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bc78896f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bc78896f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bc78896f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bc78896f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bc78896f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bc78896f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bc78896f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bc7ab2bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bc77858b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bc77863be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bc7760fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bc7760fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bc77610738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bc7760f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bc7760f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bc7760f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bc7bf19abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bc7bf22928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bc7bf0a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bc7bf35112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c8fb60082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bc7582fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7b51ec2df4043a19cf7b353eda69b4f53ec57b13 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5255 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 110347367 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e41f9ea810, 0x55e41fbd401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e41fbd4020,0x55e421a6c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7b51ec2df4043a19cf7b353eda69b4f53ec57b13' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6679 processed earlier; will process 4350 files now Step #5: ==189256== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e4164df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e41cb44898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e41cb275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e41cb274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4164e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e416446b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e416441355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4164d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4194a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4194a6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4194a6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4194a6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4194a6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4194a6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4194a6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4194a6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4194a6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4194a6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e41b73bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e418468b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e418473be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e41821fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e41821fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e418220738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e41821f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e41821f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e41821f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e41cb29abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e41cb32928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e41cb1a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e41cb45112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67dda38082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e41643fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3d2273a980e001d4c7f8811220db8c3cead8bb83 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5256 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 110873399 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555f02a40810, 0x555f02c2a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555f02c2a020,0x555f04ac20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3d2273a980e001d4c7f8811220db8c3cead8bb83' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6680 processed earlier; will process 4349 files now Step #5: ==189292== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555ef95359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555effb9a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555effb7d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555effb7d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ef953bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ef949cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ef9497355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ef952dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555efc4fcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555efc4fcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555efc4fcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555efc4fcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555efc4fcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555efc4fcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555efc4fcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555efc4fcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555efc4fcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555efc4fcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555efe791f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555efb4beb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555efb4c9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555efb275c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555efb275c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555efb276738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555efb275874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555efb275874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555efb275874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555effb7fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555effb88928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555effb70699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555effb9b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbb03061082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ef9495b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7b9e438d7bc5ca9a347b67231bb57ef63cab31b0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5257 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 111402026 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561df589b810, 0x561df5a8501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561df5a85020,0x561df791d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7b9e438d7bc5ca9a347b67231bb57ef63cab31b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6681 processed earlier; will process 4348 files now Step #5: ==189328== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561dec3909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561df29f5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561df29d85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561df29d84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561dec396d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561dec2f7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561dec2f2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561dec388c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561def357f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561def357f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561def357f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561def357f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561def357f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561def357f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561def357f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561def357f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561def357f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561def357f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561df15ecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561dee319b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561dee324be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561dee0d0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561dee0d0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561dee0d1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561dee0d0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561dee0d0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561dee0d0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561df29daabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561df29e3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561df29cb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561df29f6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efe1758e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561dec2f0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-92c91ba8cab0c1bf572b0a31827f1514b59a9ca0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5258 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 111958664 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5556e1e28810, 0x5556e201201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5556e2012020,0x5556e3eaa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92c91ba8cab0c1bf572b0a31827f1514b59a9ca0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6682 processed earlier; will process 4347 files now Step #5: #1 pulse cov: 3655 ft: 3656 exec/s: 0 rss: 177Mb Step #5: ==189364== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5556d891d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5556def82898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556def655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556def654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5556d8923d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5556d8884b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5556d887f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5556d8915c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5556db8e4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5556db8e4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5556db8e4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5556db8e4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5556db8e4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5556db8e4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5556db8e4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5556db8e4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5556db8e4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5556db8e4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5556ddb79f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5556da8a6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5556da8b1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5556da65dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5556da65dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5556da65e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5556da65d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5556da65d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5556da65d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5556def67abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5556def70928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5556def58699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5556def83112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff8f8125082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5556d887db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9e6f748a51dbca4d6d73304c1dbb8aecfb9c8a4e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5259 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 112522834 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3f0c90810, 0x55a3f0e7a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3f0e7a020,0x55a3f2d120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9e6f748a51dbca4d6d73304c1dbb8aecfb9c8a4e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6684 processed earlier; will process 4345 files now Step #5: #1 pulse cov: 3856 ft: 3857 exec/s: 0 rss: 178Mb Step #5: ==189400== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a3e77859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3eddea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3eddcd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3eddcd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3e778bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a3e76ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a3e76e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3e777dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a3ea74cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a3ea74cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a3ea74cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a3ea74cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a3ea74cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a3ea74cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a3ea74cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a3ea74cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a3ea74cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a3ea74cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3ec9e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3e970eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3e9719be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3e94c5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3e94c5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3e94c6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3e94c5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3e94c5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3e94c5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a3eddcfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a3eddd8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3eddc0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3eddeb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5b72739082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a3e76e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-dea26ac079d87b8e4241a70bcaa11105e418273d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5260 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 113103850 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb7bec1810, 0x55cb7c0ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb7c0ab020,0x55cb7df430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dea26ac079d87b8e4241a70bcaa11105e418273d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6686 processed earlier; will process 4343 files now Step #5: ==189436== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cb729b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb7901b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb78ffe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb78ffe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb729bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb7291db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb72918355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb729aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb7597df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb7597df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb7597df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb7597df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb7597df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb7597df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb7597df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb7597df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb7597df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb7597df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb77c12f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb7493fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb7494abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb746f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb746f6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb746f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb746f6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb746f6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb746f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb79000abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb79009928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb78ff1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb7901c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3adc06c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb72916b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d8958543a4fb68237a9243c538b11d2eb3dc6bc7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5261 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 113623279 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56300e7f9810, 0x56300e9e301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56300e9e3020,0x56301087b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d8958543a4fb68237a9243c538b11d2eb3dc6bc7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6687 processed earlier; will process 4342 files now Step #5: ==189472== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5630052ee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56300b953898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56300b9365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56300b9364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5630052f4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563005255b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563005250355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5630052e6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5630082b5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5630082b5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5630082b5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5630082b5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5630082b5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5630082b5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5630082b5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5630082b5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5630082b5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5630082b5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56300a54af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563007277b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563007282be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56300702ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56300702ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56300702f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56300702e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56300702e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56300702e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56300b938abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56300b941928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56300b929699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56300b954112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fad0c24c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56300524eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b421c7f827425893834c432cd5ff8a482f421965 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5262 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 114150673 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f967eab810, 0x55f96809501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f968095020,0x55f969f2d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b421c7f827425893834c432cd5ff8a482f421965' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6688 processed earlier; will process 4341 files now Step #5: ==189508== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f95e9a09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f965005898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f964fe85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f964fe84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f95e9a6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f95e907b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f95e902355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f95e998c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f961967f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f961967f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f961967f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f961967f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f961967f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f961967f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f961967f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f961967f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f961967f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f961967f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f963bfcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f960929b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f960934be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f9606e0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f9606e0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f9606e1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f9606e0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f9606e0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f9606e0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f964feaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f964ff3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f964fdb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f965006112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2a16ab8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f95e900b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-80b0824af52be7def2b4c0b426f0d3b76f9a55f1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5263 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 114669057 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5588c7712810, 0x5588c78fc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5588c78fc020,0x5588c97940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/80b0824af52be7def2b4c0b426f0d3b76f9a55f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6689 processed earlier; will process 4340 files now Step #5: ==189544== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5588be2079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5588c486c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588c484f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588c484f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588be20dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588be16eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588be169355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588be1ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5588c11cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5588c11cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5588c11cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5588c11cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5588c11cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5588c11cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5588c11cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5588c11cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5588c11cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5588c11cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5588c3463f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588c0190b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588c019bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588bff47c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588bff47c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588bff48738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588bff47874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588bff47874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588bff47874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5588c4851abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5588c485a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5588c4842699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5588c486d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f01867d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588be167b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f4d72a49dc0eaba301b1e33618f6050fe87fa9a0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5264 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 115196232 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56431bb02810, 0x56431bcec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56431bcec020,0x56431db840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f4d72a49dc0eaba301b1e33618f6050fe87fa9a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6690 processed earlier; will process 4339 files now Step #5: ==189580== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643125f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564318c5c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564318c3f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564318c3f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643125fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56431255eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564312559355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643125efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643155bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643155bef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643155bef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643155bef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643155bef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643155bef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643155bef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643155bef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643155bef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643155bef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564317853f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564314580b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56431458bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564314337c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564314337c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564314338738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564314337874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564314337874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564314337874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564318c41abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564318c4a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564318c32699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564318c5d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2cd5531082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564312557b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2f0f3b1ea8e8d153d0f8a5827cccef84e2755a74 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5265 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 115735648 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c0a2b4810, 0x562c0a49e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c0a49e020,0x562c0c3360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f0f3b1ea8e8d153d0f8a5827cccef84e2755a74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6691 processed earlier; will process 4338 files now Step #5: #1 pulse cov: 3817 ft: 3818 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4218 ft: 4629 exec/s: 0 rss: 180Mb Step #5: ==189616== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562c00da99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c0740e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c073f15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c073f14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c00dafd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c00d10b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c00d0b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c00da1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c03d70f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c03d70f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c03d70f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c03d70f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c03d70f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c03d70f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c03d70f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c03d70f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c03d70f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c03d70f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c06005f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562c02d32b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562c02d3dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562c02ae9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562c02ae9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562c02aea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562c02ae9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562c02ae9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562c02ae9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c073f3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c073fc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c073e4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c0740f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a359c9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c00d09b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6eecbd7fbd05d17b2ecad4145aef34141fb26b1b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5266 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 116336044 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563646c0b810, 0x563646df501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563646df5020,0x563648c8d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6eecbd7fbd05d17b2ecad4145aef34141fb26b1b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6694 processed earlier; will process 4335 files now Step #5: #1 pulse cov: 3722 ft: 3723 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 3885 ft: 4203 exec/s: 0 rss: 178Mb Step #5: ==189652== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56363d7009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563643d65898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563643d485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563643d484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56363d706d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56363d667b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56363d662355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56363d6f8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5636406c7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5636406c7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5636406c7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5636406c7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5636406c7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5636406c7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5636406c7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5636406c7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5636406c7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5636406c7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56364295cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56363f689b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56363f694be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56363f440c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56363f440c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56363f441738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56363f440874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56363f440874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56363f440874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563643d4aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563643d53928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563643d3b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563643d66112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f72e1083082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56363d660b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7a9f611ce0d642c20294a4bbe863357e777d375f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5267 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 116940424 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643d2830810, 0x5643d2a1a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643d2a1a020,0x5643d48b20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7a9f611ce0d642c20294a4bbe863357e777d375f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6697 processed earlier; will process 4332 files now Step #5: #1 pulse cov: 3889 ft: 3890 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 3936 ft: 4509 exec/s: 0 rss: 180Mb Step #5: ==189688== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643c93259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643cf98a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643cf96d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643cf96d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643c932bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643c928cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643c9287355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643c931dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643cc2ecf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643cc2ecf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643cc2ecf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643cc2ecf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643cc2ecf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643cc2ecf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643cc2ecf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643cc2ecf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643cc2ecf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643cc2ecf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643ce581f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643cb2aeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643cb2b9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643cb065c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643cb065c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643cb066738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643cb065874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643cb065874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643cb065874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643cf96fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643cf978928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643cf960699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643cf98b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2684def082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643c9285b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1f7bd628e4103ebbde7d87374ddcac050d0d04b8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5268 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 117658384 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed9818e810, 0x55ed9837801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed98378020,0x55ed9a2100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f7bd628e4103ebbde7d87374ddcac050d0d04b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6700 processed earlier; will process 4329 files now Step #5: ==189724== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed8ec839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed952e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed952cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed952cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed8ec89d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed8ebeab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed8ebe5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed8ec7bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed91c4af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed91c4af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed91c4af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed91c4af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed91c4af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed91c4af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed91c4af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed91c4af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed91c4af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed91c4af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed93edff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed90c0cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed90c17be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed909c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed909c3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed909c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed909c3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed909c3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed909c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed952cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed952d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed952be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed952e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa218ad9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed8ebe3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a9346edf9cd5bf56621482371e88b54859b787cb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5269 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 118180886 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565193f22810, 0x56519410c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56519410c020,0x565195fa40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9346edf9cd5bf56621482371e88b54859b787cb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6701 processed earlier; will process 4328 files now Step #5: ==189760== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56518aa179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56519107c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56519105f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56519105f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56518aa1dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56518a97eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56518a979355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56518aa0fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56518d9def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56518d9def10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56518d9def10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56518d9def10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56518d9def10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56518d9def10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56518d9def10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56518d9def10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56518d9def10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56518d9def10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56518fc73f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56518c9a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56518c9abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56518c757c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56518c757c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56518c758738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56518c757874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56518c757874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56518c757874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565191061abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56519106a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565191052699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56519107d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7effdbe75082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56518a977b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-078df9d86c6e457a212681baac7e5134b1acb2f4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5270 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 118697076 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564fe143b810, 0x564fe162501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564fe1625020,0x564fe34bd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/078df9d86c6e457a212681baac7e5134b1acb2f4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6702 processed earlier; will process 4327 files now Step #5: ==189796== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564fd7f309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564fde595898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564fde5785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564fde5784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564fd7f36d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564fd7e97b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564fd7e92355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564fd7f28c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564fdaef7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564fdaef7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564fdaef7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564fdaef7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564fdaef7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564fdaef7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564fdaef7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564fdaef7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564fdaef7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564fdaef7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564fdd18cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564fd9eb9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564fd9ec4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564fd9c70c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564fd9c70c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564fd9c71738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564fd9c70874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564fd9c70874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564fd9c70874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564fde57aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564fde583928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564fde56b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564fde596112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc7b2c37082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564fd7e90b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d9df679165b1eae2362c1c20bc636c90ee693c11 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5271 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 119216833 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55876a88e810, 0x55876aa7801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55876aa78020,0x55876c9100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d9df679165b1eae2362c1c20bc636c90ee693c11' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6703 processed earlier; will process 4326 files now Step #5: ==189832== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5587613839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5587679e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5587679cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5587679cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558761389d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5587612eab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5587612e5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55876137bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55876434af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55876434af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55876434af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55876434af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55876434af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55876434af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55876434af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55876434af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55876434af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55876434af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5587665dff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55876330cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558763317be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5587630c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5587630c3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5587630c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5587630c3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5587630c3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5587630c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5587679cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5587679d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5587679be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5587679e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdae6d81082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5587612e3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-edf4d7635991eee08378dac2dfc3dc982cde53a1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5272 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 119747592 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562740d04810, 0x562740eee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562740eee020,0x562742d860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/edf4d7635991eee08378dac2dfc3dc982cde53a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6704 processed earlier; will process 4325 files now Step #5: ==189868== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5627377f99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56273de5e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56273de415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56273de414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5627377ffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562737760b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56273775b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5627377f1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56273a7c0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56273a7c0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56273a7c0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56273a7c0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56273a7c0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56273a7c0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56273a7c0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56273a7c0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56273a7c0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56273a7c0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56273ca55f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562739782b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56273978dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562739539c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562739539c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56273953a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562739539874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562739539874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562739539874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56273de43abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56273de4c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56273de34699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56273de5f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4d6b692082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562737759b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-425349f632a951709372b1a1e2c3333d83ff3441 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5273 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 120275868 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c5a6234810, 0x55c5a641e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c5a641e020,0x55c5a82b60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/425349f632a951709372b1a1e2c3333d83ff3441' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6705 processed earlier; will process 4324 files now Step #5: #1 pulse cov: 3807 ft: 3808 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4568 ft: 5032 exec/s: 0 rss: 179Mb Step #5: ==189904== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c59cd299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c5a338e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c5a33715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c5a33714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c59cd2fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c59cc90b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c59cc8b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c59cd21c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c59fcf0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c59fcf0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c59fcf0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c59fcf0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c59fcf0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c59fcf0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c59fcf0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c59fcf0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c59fcf0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c59fcf0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c5a1f85f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c59ecb2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c59ecbdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c59ea69c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c59ea69c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c59ea6a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c59ea69874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c59ea69874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c59ea69874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c5a3373abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c5a337c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c5a3364699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c5a338f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7febf2910082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c59cc89b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-de234ed32b57040e7d69d45828a480941496806a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5274 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 120874915 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ac78ef810, 0x562ac7ad901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ac7ad9020,0x562ac99710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de234ed32b57040e7d69d45828a480941496806a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6708 processed earlier; will process 4321 files now Step #5: ==189940== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562abe3e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ac4a49898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ac4a2c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ac4a2c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562abe3ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562abe34bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562abe346355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562abe3dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ac13abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ac13abf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ac13abf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ac13abf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ac13abf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ac13abf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ac13abf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ac13abf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ac13abf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ac13abf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ac3640f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ac036db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ac0378be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ac0124c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ac0124c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ac0125738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ac0124874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ac0124874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ac0124874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ac4a2eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ac4a37928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ac4a1f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ac4a4a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6fa4fde082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562abe344b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6f17b0fd3ac1fc32e96b706eebcaf4b9a4c4ec1c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5275 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 121390645 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ffffbd4810, 0x55ffffdbe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ffffdbe020,0x560001c560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6f17b0fd3ac1fc32e96b706eebcaf4b9a4c4ec1c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6709 processed earlier; will process 4320 files now Step #5: ==189976== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fff66c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fffcd2e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fffcd115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fffcd114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fff66cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fff6630b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fff662b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fff66c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fff9690f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fff9690f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fff9690f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fff9690f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fff9690f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fff9690f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fff9690f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fff9690f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fff9690f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fff9690f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fffb925f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fff8652b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fff865dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fff8409c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fff8409c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fff840a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fff8409874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fff8409874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fff8409874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fffcd13abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fffcd1c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fffcd04699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fffcd2f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1153a91082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fff6629b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8bdfeff2c124dd748c2a6d0a9aaf5c60b7322cb1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5276 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 121914888 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56148cc99810, 0x56148ce8301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56148ce83020,0x56148ed1b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8bdfeff2c124dd748c2a6d0a9aaf5c60b7322cb1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6710 processed earlier; will process 4319 files now Step #5: ==190012== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56148378e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561489df3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561489dd65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561489dd64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561483794d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5614836f5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5614836f0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561483786c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561486755f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561486755f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561486755f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561486755f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561486755f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561486755f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561486755f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561486755f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561486755f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561486755f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5614889eaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561485717b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561485722be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5614854cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5614854cec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5614854cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5614854ce874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5614854ce874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5614854ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561489dd8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561489de1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561489dc9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561489df4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f727b885082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5614836eeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-67dc7b76100ed1d9d48a36d444b246ed34490aaa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5277 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 122479847 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f01d268810, 0x55f01d45201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f01d452020,0x55f01f2ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/67dc7b76100ed1d9d48a36d444b246ed34490aaa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6711 processed earlier; will process 4318 files now Step #5: ==190048== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f013d5d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f01a3c2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f01a3a55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f01a3a54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f013d63d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f013cc4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f013cbf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f013d55c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f016d24f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f016d24f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f016d24f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f016d24f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f016d24f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f016d24f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f016d24f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f016d24f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f016d24f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f016d24f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f018fb9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f015ce6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f015cf1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f015a9dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f015a9dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f015a9e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f015a9d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f015a9d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f015a9d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f01a3a7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f01a3b0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f01a398699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f01a3c3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7514926082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f013cbdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-88b0a343889c3c067be2ff2a590cea63dab32358 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5278 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 122989755 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed1d7f1810, 0x55ed1d9db01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed1d9db020,0x55ed1f8730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88b0a343889c3c067be2ff2a590cea63dab32358' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6712 processed earlier; will process 4317 files now Step #5: #1 pulse cov: 3933 ft: 3934 exec/s: 0 rss: 178Mb Step #5: ==190084== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed142e69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed1a94b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed1a92e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed1a92e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed142ecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed1424db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed14248355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed142dec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed172adf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed172adf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed172adf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed172adf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed172adf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed172adf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed172adf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed172adf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed172adf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed172adf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed19542f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed1626fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed1627abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed16026c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed16026c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed16027738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed16026874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed16026874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed16026874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed1a930abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed1a939928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed1a921699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed1a94c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f386cd73082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed14246b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e8c1ab9a911bb9707dedd9e849e75707ef1c3e98 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5279 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 123696615 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ccf7bc7810, 0x55ccf7db101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ccf7db1020,0x55ccf9c490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e8c1ab9a911bb9707dedd9e849e75707ef1c3e98' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6714 processed earlier; will process 4315 files now Step #5: ==190120== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ccee6bc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ccf4d21898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ccf4d045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ccf4d044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ccee6c2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ccee623b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ccee61e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ccee6b4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ccf1683f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ccf1683f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ccf1683f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ccf1683f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ccf1683f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ccf1683f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ccf1683f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ccf1683f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ccf1683f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ccf1683f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ccf3918f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ccf0645b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ccf0650be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ccf03fcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ccf03fcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ccf03fd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ccf03fc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ccf03fc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ccf03fc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ccf4d06abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ccf4d0f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ccf4cf7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ccf4d22112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc1bbbf6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ccee61cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a38fedf9cb93041d1807d75676dd94ebcece66d5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5280 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 124213613 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b05fbe2810, 0x55b05fdcc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b05fdcc020,0x55b061c640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a38fedf9cb93041d1807d75676dd94ebcece66d5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6715 processed earlier; will process 4314 files now Step #5: ==190156== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b0566d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b05cd3c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b05cd1f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b05cd1f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0566ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b05663eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b056639355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0566cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b05969ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b05969ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b05969ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b05969ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b05969ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b05969ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b05969ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b05969ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b05969ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b05969ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b05b933f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b058660b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b05866bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b058417c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b058417c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b058418738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b058417874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b058417874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b058417874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b05cd21abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b05cd2a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b05cd12699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b05cd3d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2118262082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b056637b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a82496ed74b2b0b7ee641c7464a2035f022ad442 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5281 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 124726478 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e09cb94810, 0x55e09cd7e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e09cd7e020,0x55e09ec160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a82496ed74b2b0b7ee641c7464a2035f022ad442' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6716 processed earlier; will process 4313 files now Step #5: ==190192== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e0936899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e099cee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e099cd15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e099cd14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e09368fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e0935f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e0935eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e093681c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e096650f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e096650f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e096650f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e096650f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e096650f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e096650f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e096650f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e096650f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e096650f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e096650f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e0988e5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e095612b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e09561dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e0953c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e0953c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e0953ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e0953c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e0953c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e0953c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e099cd3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e099cdc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e099cc4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e099cef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe0609f8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e0935e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ccbfc7a90c258a0e440e50f23d9e529fb1a262f3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5282 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 125254011 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5607c7a3e810, 0x5607c7c2801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5607c7c28020,0x5607c9ac00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ccbfc7a90c258a0e440e50f23d9e529fb1a262f3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6717 processed earlier; will process 4312 files now Step #5: #1 pulse cov: 4105 ft: 4106 exec/s: 0 rss: 177Mb Step #5: ==190228== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5607be5339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5607c4b98898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5607c4b7b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5607c4b7b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5607be539d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5607be49ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5607be495355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5607be52bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5607c14faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5607c14faf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5607c14faf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5607c14faf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5607c14faf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5607c14faf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5607c14faf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5607c14faf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5607c14faf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5607c14faf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5607c378ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5607c04bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5607c04c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5607c0273c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5607c0273c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5607c0274738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5607c0273874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5607c0273874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5607c0273874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5607c4b7dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5607c4b86928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5607c4b6e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5607c4b99112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8e224d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5607be493b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c6d0316ba58faed24d63d05897d115db7ffc193f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5283 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 125816409 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e1af6fe810, 0x55e1af8e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e1af8e8020,0x55e1b17800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c6d0316ba58faed24d63d05897d115db7ffc193f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6719 processed earlier; will process 4310 files now Step #5: #1 pulse cov: 4340 ft: 4341 exec/s: 0 rss: 180Mb Step #5: ==190264== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e1a61f39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e1ac858898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e1ac83b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e1ac83b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e1a61f9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e1a615ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e1a6155355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e1a61ebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e1a91baf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e1a91baf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e1a91baf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e1a91baf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e1a91baf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e1a91baf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e1a91baf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e1a91baf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e1a91baf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e1a91baf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e1ab44ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e1a817cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e1a8187be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e1a7f33c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e1a7f33c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e1a7f34738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e1a7f33874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e1a7f33874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e1a7f33874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e1ac83dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e1ac846928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e1ac82e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e1ac859112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3192600082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e1a6153b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ad6e1dfa0c842a4fcdd87671d3b5d9eb0c935d19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5284 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 126500999 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571e321c810, 0x5571e340601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571e3406020,0x5571e529e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad6e1dfa0c842a4fcdd87671d3b5d9eb0c935d19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6721 processed earlier; will process 4308 files now Step #5: ==190300== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571d9d119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571e0376898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571e03595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571e03594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571d9d17d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571d9c78b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571d9c73355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571d9d09c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571dccd8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571dccd8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571dccd8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571dccd8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571dccd8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571dccd8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571dccd8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571dccd8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571dccd8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571dccd8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571def6df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571dbc9ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571dbca5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571dba51c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571dba51c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571dba52738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571dba51874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571dba51874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571dba51874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571e035babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571e0364928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571e034c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571e0377112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f578815f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571d9c71b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5f0b36690336b9994b65e8e75104a15b45ef0af5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5285 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 127023410 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56205eec0810, 0x56205f0aa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56205f0aa020,0x562060f420e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f0b36690336b9994b65e8e75104a15b45ef0af5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6722 processed earlier; will process 4307 files now Step #5: #1 pulse cov: 4098 ft: 4099 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4538 ft: 5058 exec/s: 0 rss: 179Mb Step #5: ==190336== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5620559b59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56205c01a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56205bffd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56205bffd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5620559bbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56205591cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562055917355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5620559adc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56205897cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56205897cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56205897cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56205897cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56205897cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56205897cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56205897cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56205897cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56205897cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56205897cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56205ac11f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56205793eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562057949be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5620576f5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5620576f5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5620576f6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5620576f5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5620576f5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5620576f5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56205bfffabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56205c008928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56205bff0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56205c01b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac6c4b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562055915b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-76081256142f2f7dcdb504ec2076c0da275fe3f6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5286 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 127639602 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cd46473810, 0x55cd4665d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cd4665d020,0x55cd484f50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/76081256142f2f7dcdb504ec2076c0da275fe3f6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6725 processed earlier; will process 4304 files now Step #5: ==190372== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cd3cf689c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cd435cd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cd435b05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cd435b04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cd3cf6ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cd3cecfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cd3ceca355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cd3cf60c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cd3ff2ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cd3ff2ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cd3ff2ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cd3ff2ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cd3ff2ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cd3ff2ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cd3ff2ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cd3ff2ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cd3ff2ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cd3ff2ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cd421c4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cd3eef1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cd3eefcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cd3eca8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cd3eca8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cd3eca9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cd3eca8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cd3eca8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cd3eca8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cd435b2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cd435bb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cd435a3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cd435ce112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f237aec2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cd3cec8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2d44b079a8be2d963f71f8721f27ac2e6eba57f7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5287 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 128169398 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a883ae810, 0x558a8859801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a88598020,0x558a8a4300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2d44b079a8be2d963f71f8721f27ac2e6eba57f7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6726 processed earlier; will process 4303 files now Step #5: #1 pulse cov: 12112 ft: 12113 exec/s: 0 rss: 197Mb Step #5: #2 pulse cov: 12689 ft: 13510 exec/s: 0 rss: 199Mb Step #5: ==190408== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558a7eea39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a85508898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a854eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a854eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a7eea9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a7ee0ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a7ee05355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a7ee9bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a81e6af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a81e6af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a81e6af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a81e6af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a81e6af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a81e6af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a81e6af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a81e6af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a81e6af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a81e6af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a840fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a80e2cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a80e37be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a80be3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a80be3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a80be4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a80be3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a80be3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a80be3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a854edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a854f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a854de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a85509112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d458f4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a7ee03b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c19ae30630e7230bb348b0930f1e0cd9ca2e151d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5288 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 128847165 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec25e01810, 0x55ec25feb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec25feb020,0x55ec27e830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c19ae30630e7230bb348b0930f1e0cd9ca2e151d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6729 processed earlier; will process 4300 files now Step #5: ==190444== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec1c8f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec22f5b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec22f3e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec22f3e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec1c8fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec1c85db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec1c858355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec1c8eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec1f8bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec1f8bdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec1f8bdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec1f8bdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec1f8bdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec1f8bdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec1f8bdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec1f8bdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec1f8bdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec1f8bdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec21b52f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec1e87fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec1e88abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec1e636c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec1e636c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec1e637738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec1e636874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec1e636874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec1e636874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec22f40abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec22f49928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec22f31699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec22f5c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2da9bb7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec1c856b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a1735e45a0c46e346b24c781f0b8f15343cb2b72 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5289 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 129483356 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55edc4fc3810, 0x55edc51ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55edc51ad020,0x55edc70450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a1735e45a0c46e346b24c781f0b8f15343cb2b72' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6730 processed earlier; will process 4299 files now Step #5: ==190480== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55edbbab89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55edc211d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55edc21005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55edc21004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55edbbabed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55edbba1fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55edbba1a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55edbbab0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55edbea7ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55edbea7ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55edbea7ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55edbea7ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55edbea7ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55edbea7ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55edbea7ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55edbea7ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55edbea7ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55edbea7ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55edc0d14f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55edbda41b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55edbda4cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55edbd7f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55edbd7f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55edbd7f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55edbd7f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55edbd7f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55edbd7f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55edc2102abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55edc210b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55edc20f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55edc211e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1da316e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55edbba18b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-41ec7e145e45ba41eb908e29b4626365d0b58354 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5290 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 130021329 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561332dea810, 0x561332fd401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561332fd4020,0x561334e6c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/41ec7e145e45ba41eb908e29b4626365d0b58354' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6731 processed earlier; will process 4298 files now Step #5: ==190516== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5613298df9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56132ff44898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56132ff275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56132ff274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5613298e5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561329846b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561329841355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5613298d7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56132c8a6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56132c8a6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56132c8a6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56132c8a6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56132c8a6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56132c8a6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56132c8a6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56132c8a6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56132c8a6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56132c8a6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56132eb3bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56132b868b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56132b873be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56132b61fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56132b61fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56132b620738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56132b61f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56132b61f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56132b61f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56132ff29abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56132ff32928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56132ff1a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56132ff45112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9b8d2b3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56132983fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-dcca070dad4aa6308b067050f403f91b29ce230c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5291 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 130658911 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559f04107810, 0x559f042f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559f042f1020,0x559f061890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dcca070dad4aa6308b067050f403f91b29ce230c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6732 processed earlier; will process 4297 files now Step #5: #1 pulse cov: 3824 ft: 3825 exec/s: 0 rss: 178Mb Step #5: ==190552== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559efabfc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559f01261898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559f012445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559f012444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559efac02d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559efab63b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559efab5e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559efabf4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559efdbc3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559efdbc3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559efdbc3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559efdbc3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559efdbc3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559efdbc3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559efdbc3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559efdbc3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559efdbc3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559efdbc3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559effe58f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559efcb85b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559efcb90be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559efc93cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559efc93cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559efc93d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559efc93c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559efc93c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559efc93c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559f01246abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559f0124f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559f01237699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559f01262112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f39595de082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559efab5cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-201cbbe79b8d83802d28cf8f7b67343082ca93e5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5292 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 131253158 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5612915ab810, 0x56129179501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561291795020,0x56129362d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/201cbbe79b8d83802d28cf8f7b67343082ca93e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6734 processed earlier; will process 4295 files now Step #5: ==190588== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5612880a09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56128e705898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56128e6e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56128e6e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5612880a6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561288007b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561288002355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561288098c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56128b067f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56128b067f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56128b067f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56128b067f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56128b067f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56128b067f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56128b067f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56128b067f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56128b067f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56128b067f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56128d2fcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56128a029b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56128a034be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561289de0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561289de0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561289de1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561289de0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561289de0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561289de0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56128e6eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56128e6f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56128e6db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56128e706112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc95a357082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561288000b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1911fa169d1fe28854cf6f4b57e833463f754107 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5293 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 131763221 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55844d068810, 0x55844d25201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55844d252020,0x55844f0ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1911fa169d1fe28854cf6f4b57e833463f754107' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6735 processed earlier; will process 4294 files now Step #5: ==190624== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558443b5d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55844a1c2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55844a1a55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55844a1a54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558443b63d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558443ac4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558443abf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558443b55c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558446b24f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558446b24f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558446b24f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558446b24f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558446b24f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558446b24f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558446b24f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558446b24f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558446b24f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558446b24f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558448db9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558445ae6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558445af1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55844589dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55844589dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55844589e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55844589d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55844589d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55844589d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55844a1a7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55844a1b0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55844a198699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55844a1c3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc012b8d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558443abdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-08cf018f5bbf0b85131dc29e60f01350ad05fb6a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5294 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 132396050 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557baf90c810, 0x557bafaf601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557bafaf6020,0x557bb198e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08cf018f5bbf0b85131dc29e60f01350ad05fb6a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6736 processed earlier; will process 4293 files now Step #5: #1 pulse cov: 4255 ft: 4256 exec/s: 0 rss: 177Mb Step #5: ==190660== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557ba64019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557baca66898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557baca495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557baca494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557ba6407d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557ba6368b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557ba6363355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557ba63f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557ba93c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557ba93c8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557ba93c8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557ba93c8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557ba93c8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557ba93c8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557ba93c8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557ba93c8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557ba93c8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557ba93c8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557bab65df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557ba838ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557ba8395be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557ba8141c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557ba8141c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557ba8142738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557ba8141874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557ba8141874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557ba8141874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557baca4babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557baca54928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557baca3c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557baca67112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd7a6c7e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557ba6361b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8aaa9e16a9e8b48ef5f4e43196e578b9acd2997f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5295 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 132957032 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd25f85810, 0x55dd2616f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd2616f020,0x55dd280070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8aaa9e16a9e8b48ef5f4e43196e578b9acd2997f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6738 processed earlier; will process 4291 files now Step #5: ==190696== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dd1ca7a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd230df898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd230c25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd230c24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dd1ca80d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dd1c9e1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dd1c9dc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dd1ca72c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd1fa41f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd1fa41f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd1fa41f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd1fa41f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd1fa41f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd1fa41f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd1fa41f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd1fa41f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd1fa41f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd1fa41f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd21cd6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dd1ea03b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dd1ea0ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dd1e7bac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dd1e7bac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dd1e7bb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dd1e7ba874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dd1e7ba874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dd1e7ba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd230c4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd230cd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd230b5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd230e0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f39665af082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dd1c9dab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0c42e6399222eb811a6f73bfbcf4e50b40990253 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5296 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 133481331 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf73982810, 0x55bf73b6c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf73b6c020,0x55bf75a040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0c42e6399222eb811a6f73bfbcf4e50b40990253' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6739 processed earlier; will process 4290 files now Step #5: ==190732== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bf6a4779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf70adc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf70abf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf70abf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf6a47dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf6a3deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf6a3d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf6a46fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf6d43ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf6d43ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf6d43ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf6d43ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf6d43ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf6d43ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf6d43ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf6d43ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf6d43ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf6d43ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf6f6d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf6c400b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf6c40bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf6c1b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf6c1b7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf6c1b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf6c1b7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf6c1b7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf6c1b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf70ac1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf70aca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf70ab2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf70add112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8e55787082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf6a3d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-da03d685935ce890184ac46aa8f5f4d6b57bb69e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5297 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 134028973 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564b42d3c810, 0x564b42f2601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564b42f26020,0x564b44dbe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/da03d685935ce890184ac46aa8f5f4d6b57bb69e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6740 processed earlier; will process 4289 files now Step #5: ==190768== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564b398319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564b3fe96898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564b3fe795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564b3fe794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564b39837d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564b39798b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564b39793355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564b39829c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564b3c7f8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564b3c7f8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564b3c7f8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564b3c7f8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564b3c7f8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564b3c7f8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564b3c7f8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564b3c7f8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564b3c7f8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564b3c7f8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564b3ea8df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564b3b7bab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564b3b7c5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564b3b571c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564b3b571c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564b3b572738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564b3b571874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564b3b571874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564b3b571874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564b3fe7babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564b3fe84928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564b3fe6c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564b3fe97112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4752e23082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564b39791b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6f464e2efb6195a815f50ff121967462ebcbf6c6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5298 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 134549461 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c01ea8b810, 0x55c01ec7501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c01ec75020,0x55c020b0d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6f464e2efb6195a815f50ff121967462ebcbf6c6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6741 processed earlier; will process 4288 files now Step #5: ==190804== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c0155809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c01bbe5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c01bbc85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c01bbc84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c015586d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c0154e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c0154e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c015578c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c018547f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c018547f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c018547f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c018547f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c018547f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c018547f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c018547f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c018547f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c018547f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c018547f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c01a7dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c017509b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c017514be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c0172c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c0172c0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c0172c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c0172c0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c0172c0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c0172c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c01bbcaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c01bbd3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c01bbbb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c01bbe6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53bc816082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c0154e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-35de6ea5152430a21b4d68f149ba17d30802c750 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5299 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 135097404 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611b17db810, 0x5611b19c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5611b19c5020,0x5611b385d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/35de6ea5152430a21b4d68f149ba17d30802c750' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6742 processed earlier; will process 4287 files now Step #5: ==190840== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5611a82d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5611ae935898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611ae9185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611ae9184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5611a82d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5611a8237b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5611a8232355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5611a82c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5611ab297f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5611ab297f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5611ab297f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5611ab297f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5611ab297f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5611ab297f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5611ab297f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5611ab297f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5611ab297f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5611ab297f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5611ad52cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611aa259b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5611aa264be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611aa010c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611aa010c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611aa011738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611aa010874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611aa010874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611aa010874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5611ae91aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5611ae923928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611ae90b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5611ae936112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ea9e05082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5611a8230b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2cf0a3ccff2f70728e9e5077871eb53dc4192759 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5300 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 135740609 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56514a2b7810, 0x56514a4a101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56514a4a1020,0x56514c3390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2cf0a3ccff2f70728e9e5077871eb53dc4192759' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6743 processed earlier; will process 4286 files now Step #5: ==190876== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565140dac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565147411898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651473f45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651473f44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565140db2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565140d13b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565140d0e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565140da4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565143d73f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565143d73f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565143d73f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565143d73f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565143d73f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565143d73f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565143d73f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565143d73f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565143d73f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565143d73f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565146008f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565142d35b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565142d40be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565142aecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565142aecc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565142aed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565142aec874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565142aec874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565142aec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5651473f6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5651473ff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5651473e7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565147412112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f772b549082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565140d0cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8c53f787499321a99ac790dd6e3527305362a9ce Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5301 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 136265541 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5617aeb34810, 0x5617aed1e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5617aed1e020,0x5617b0bb60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c53f787499321a99ac790dd6e3527305362a9ce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6744 processed earlier; will process 4285 files now Step #5: ==190912== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5617a56299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5617abc8e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5617abc715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5617abc714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5617a562fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5617a5590b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5617a558b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5617a5621c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5617a85f0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5617a85f0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5617a85f0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5617a85f0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5617a85f0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5617a85f0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5617a85f0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5617a85f0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5617a85f0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5617a85f0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5617aa885f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5617a75b2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5617a75bdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5617a7369c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5617a7369c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5617a736a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5617a7369874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5617a7369874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5617a7369874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5617abc73abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5617abc7c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5617abc64699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5617abc8f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa08076c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5617a5589b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-957d88c1323bdf87a4e0dd15810e9d46465e0c65 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5302 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 136899202 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56114bfe5810, 0x56114c1cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56114c1cf020,0x56114e0670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/957d88c1323bdf87a4e0dd15810e9d46465e0c65' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6745 processed earlier; will process 4284 files now Step #5: ==190948== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561142ada9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56114913f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611491225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611491224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561142ae0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561142a41b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561142a3c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561142ad2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561145aa1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561145aa1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561145aa1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561145aa1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561145aa1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561145aa1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561145aa1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561145aa1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561145aa1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561145aa1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561147d36f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561144a63b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561144a6ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56114481ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56114481ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56114481b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56114481a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56114481a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56114481a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561149124abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56114912d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561149115699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561149140112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd61ab86082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561142a3ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fa0265e7312cd298bdf807a785078da8ef369762 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5303 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 137447936 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5626a147a810, 0x5626a166401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5626a1664020,0x5626a34fc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fa0265e7312cd298bdf807a785078da8ef369762' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6746 processed earlier; will process 4283 files now Step #5: ==190984== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562697f6f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56269e5d4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56269e5b75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56269e5b74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562697f75d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562697ed6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562697ed1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562697f67c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56269af36f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56269af36f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56269af36f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56269af36f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56269af36f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56269af36f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56269af36f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56269af36f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56269af36f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56269af36f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56269d1cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562699ef8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562699f03be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562699cafc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562699cafc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562699cb0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562699caf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562699caf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562699caf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56269e5b9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56269e5c2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56269e5aa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56269e5d5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f592d653082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562697ecfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9f578cf82c9280cb8d0dbc44c07d509f6a47db81 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5304 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 138081418 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555838fa0810, 0x55583918a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55583918a020,0x55583b0220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f578cf82c9280cb8d0dbc44c07d509f6a47db81' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6747 processed earlier; will process 4282 files now Step #5: ==191020== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55582fa959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5558360fa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5558360dd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5558360dd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55582fa9bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55582f9fcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55582f9f7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55582fa8dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555832a5cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555832a5cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555832a5cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555832a5cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555832a5cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555832a5cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555832a5cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555832a5cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555832a5cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555832a5cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555834cf1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555831a1eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555831a29be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5558317d5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5558317d5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5558317d6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5558317d5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5558317d5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5558317d5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5558360dfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5558360e8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5558360d0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5558360fb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc007a87082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55582f9f5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3c7a74600e728d12a7ec49456b30a3455d435464 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5305 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 138727096 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564df202e810, 0x564df221801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564df2218020,0x564df40b00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3c7a74600e728d12a7ec49456b30a3455d435464' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6748 processed earlier; will process 4281 files now Step #5: ==191056== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564de8b239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564def188898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564def16b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564def16b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564de8b29d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564de8a8ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564de8a85355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564de8b1bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564debaeaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564debaeaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564debaeaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564debaeaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564debaeaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564debaeaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564debaeaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564debaeaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564debaeaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564debaeaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564dedd7ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564deaaacb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564deaab7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564dea863c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564dea863c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564dea864738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564dea863874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564dea863874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564dea863874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564def16dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564def176928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564def15e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564def189112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fab58df5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564de8a83b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-90e731a19ffd1977ff275dffe5599e512e710d6a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5306 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 139377064 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557774f83810, 0x55777516d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55777516d020,0x5577770050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/90e731a19ffd1977ff275dffe5599e512e710d6a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6749 processed earlier; will process 4280 files now Step #5: ==191092== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55776ba789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5577720dd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5577720c05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5577720c04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55776ba7ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55776b9dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55776b9da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55776ba70c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55776ea3ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55776ea3ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55776ea3ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55776ea3ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55776ea3ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55776ea3ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55776ea3ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55776ea3ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55776ea3ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55776ea3ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557770cd4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55776da01b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55776da0cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55776d7b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55776d7b8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55776d7b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55776d7b8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55776d7b8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55776d7b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5577720c2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5577720cb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5577720b3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5577720de112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc6bea5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55776b9d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-58ce631c6070c881ea0b8ce6af8524ca1a1b047b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5307 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 139891658 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5606bb49c810, 0x5606bb68601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5606bb686020,0x5606bd51e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58ce631c6070c881ea0b8ce6af8524ca1a1b047b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6750 processed earlier; will process 4279 files now Step #5: ==191128== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5606b1f919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5606b85f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606b85d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606b85d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5606b1f97d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5606b1ef8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5606b1ef3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5606b1f89c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5606b4f58f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5606b4f58f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5606b4f58f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5606b4f58f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5606b4f58f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5606b4f58f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5606b4f58f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5606b4f58f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5606b4f58f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5606b4f58f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606b71edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5606b3f1ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5606b3f25be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5606b3cd1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5606b3cd1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5606b3cd2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5606b3cd1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5606b3cd1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5606b3cd1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5606b85dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5606b85e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5606b85cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5606b85f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffb3db46082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5606b1ef1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ad8d106e81e0f3a9288e00a2eacc60591ce81669 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5308 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 140404547 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56127c730810, 0x56127c91a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56127c91a020,0x56127e7b20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad8d106e81e0f3a9288e00a2eacc60591ce81669' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6751 processed earlier; will process 4278 files now Step #5: ==191164== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5612732259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56127988a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56127986d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56127986d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56127322bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56127318cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561273187355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56127321dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5612761ecf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5612761ecf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5612761ecf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5612761ecf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5612761ecf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5612761ecf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5612761ecf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5612761ecf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5612761ecf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5612761ecf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561278481f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5612751aeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5612751b9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561274f65c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561274f65c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561274f66738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561274f65874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561274f65874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561274f65874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56127986fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561279878928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561279860699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56127988b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f82f8a53082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561273185b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-91f4865ccf4720d00d0f4963adc748ba3993462d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5309 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 140928487 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c284cd6810, 0x55c284ec001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c284ec0020,0x55c286d580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/91f4865ccf4720d00d0f4963adc748ba3993462d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6752 processed earlier; will process 4277 files now Step #5: #1 pulse cov: 4014 ft: 4015 exec/s: 0 rss: 176Mb Step #5: ==191200== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c27b7cb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c281e30898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c281e135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c281e134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c27b7d1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c27b732b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c27b72d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c27b7c3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c27e792f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c27e792f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c27e792f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c27e792f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c27e792f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c27e792f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c27e792f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c27e792f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c27e792f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c27e792f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c280a27f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c27d754b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c27d75fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c27d50bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c27d50bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c27d50c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c27d50b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c27d50b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c27d50b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c281e15abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c281e1e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c281e06699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c281e31112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f70b76c8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c27b72bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d91bfbe4e9d41dd5a808540a30d4cc1f683aadd5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5310 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 141508511 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b760c9810, 0x561b762b301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b762b3020,0x561b7814b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d91bfbe4e9d41dd5a808540a30d4cc1f683aadd5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6754 processed earlier; will process 4275 files now Step #5: ==191236== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561b6cbbe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b73223898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b732065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b732064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b6cbc4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b6cb25b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b6cb20355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b6cbb6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b6fb85f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b6fb85f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b6fb85f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b6fb85f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b6fb85f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b6fb85f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b6fb85f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b6fb85f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b6fb85f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b6fb85f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b71e1af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b6eb47b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b6eb52be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b6e8fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b6e8fec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b6e8ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b6e8fe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b6e8fe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b6e8fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b73208abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b73211928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b731f9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b73224112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efe42455082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b6cb1eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3a18dfb561706f22acaf3891e5f3f70435f2e35b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5311 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 142153593 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561f72285810, 0x561f7246f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561f7246f020,0x561f743070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a18dfb561706f22acaf3891e5f3f70435f2e35b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6755 processed earlier; will process 4274 files now Step #5: #1 pulse cov: 3808 ft: 3809 exec/s: 0 rss: 176Mb Step #5: ==191272== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561f68d7a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561f6f3df898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561f6f3c25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561f6f3c24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561f68d80d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561f68ce1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561f68cdc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561f68d72c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561f6bd41f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561f6bd41f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561f6bd41f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561f6bd41f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561f6bd41f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561f6bd41f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561f6bd41f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561f6bd41f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561f6bd41f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561f6bd41f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561f6dfd6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561f6ad03b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561f6ad0ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561f6aabac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561f6aabac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561f6aabb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561f6aaba874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561f6aaba874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561f6aaba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561f6f3c4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561f6f3cd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561f6f3b5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561f6f3e0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0b400ba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561f68cdab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e575252ab37aca40153b885668cd94e8945c400b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5312 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 142722496 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55efd3b8d810, 0x55efd3d7701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55efd3d77020,0x55efd5c0f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e575252ab37aca40153b885668cd94e8945c400b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6757 processed earlier; will process 4272 files now Step #5: ==191308== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55efca6829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55efd0ce7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55efd0cca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55efd0cca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55efca688d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55efca5e9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55efca5e4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55efca67ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55efcd649f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55efcd649f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55efcd649f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55efcd649f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55efcd649f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55efcd649f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55efcd649f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55efcd649f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55efcd649f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55efcd649f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55efcf8def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55efcc60bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55efcc616be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55efcc3c2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55efcc3c2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55efcc3c3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55efcc3c2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55efcc3c2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55efcc3c2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55efd0cccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55efd0cd5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55efd0cbd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55efd0ce8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc9aca9f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55efca5e2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-88226581bdf39650873657d72384c89bdc9e6397 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5313 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 143274323 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556291c8e810, 0x556291e7801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556291e78020,0x556293d100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88226581bdf39650873657d72384c89bdc9e6397' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6758 processed earlier; will process 4271 files now Step #5: ==191344== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5562887839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55628ede8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55628edcb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55628edcb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556288789d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5562886eab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5562886e5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55628877bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55628b74af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55628b74af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55628b74af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55628b74af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55628b74af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55628b74af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55628b74af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55628b74af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55628b74af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55628b74af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55628d9dff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55628a70cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55628a717be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55628a4c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55628a4c3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55628a4c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55628a4c3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55628a4c3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55628a4c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55628edcdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55628edd6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55628edbe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55628ede9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb5afb9b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5562886e3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-069ba508bba0b3ce43264e89131317e9b1e8e5f8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5314 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 143802611 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561be1c5c810, 0x561be1e4601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561be1e46020,0x561be3cde0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/069ba508bba0b3ce43264e89131317e9b1e8e5f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6759 processed earlier; will process 4270 files now Step #5: ==191380== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561bd87519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561bdedb6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561bded995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561bded994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561bd8757d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561bd86b8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561bd86b3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561bd8749c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561bdb718f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561bdb718f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561bdb718f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561bdb718f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561bdb718f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561bdb718f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561bdb718f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561bdb718f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561bdb718f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561bdb718f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561bdd9adf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561bda6dab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561bda6e5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561bda491c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561bda491c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561bda492738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561bda491874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561bda491874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561bda491874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561bded9babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561bdeda4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561bded8c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561bdedb7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fefdb195082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561bd86b1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-af91af6ebb158e6a390b243c4e5dd717cea1bd4b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5315 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 144449138 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b6e8631810, 0x55b6e881b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b6e881b020,0x55b6ea6b30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af91af6ebb158e6a390b243c4e5dd717cea1bd4b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6760 processed earlier; will process 4269 files now Step #5: #1 pulse cov: 4024 ft: 4025 exec/s: 0 rss: 179Mb Step #5: ==191416== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b6df1269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b6e578b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b6e576e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b6e576e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6df12cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6df08db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6df088355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6df11ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b6e20edf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b6e20edf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b6e20edf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b6e20edf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b6e20edf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b6e20edf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b6e20edf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b6e20edf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b6e20edf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b6e20edf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b6e4382f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6e10afb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6e10babe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6e0e66c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6e0e66c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6e0e67738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6e0e66874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6e0e66874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6e0e66874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b6e5770abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b6e5779928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b6e5761699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b6e578c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f34b09e0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6df086b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6bac3f48816cc3408cde76bf9ac1023a7e1317a6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5316 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 145030731 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5623a93ff810, 0x5623a95e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5623a95e9020,0x5623ab4810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bac3f48816cc3408cde76bf9ac1023a7e1317a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6762 processed earlier; will process 4267 files now Step #5: ==191452== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56239fef49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5623a6559898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5623a653c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5623a653c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56239fefad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56239fe5bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56239fe56355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56239feecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5623a2ebbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5623a2ebbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5623a2ebbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5623a2ebbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5623a2ebbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5623a2ebbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5623a2ebbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5623a2ebbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5623a2ebbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5623a2ebbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5623a5150f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5623a1e7db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5623a1e88be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5623a1c34c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5623a1c34c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5623a1c35738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5623a1c34874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5623a1c34874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5623a1c34874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5623a653eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5623a6547928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5623a652f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5623a655a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe775c38082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56239fe54b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-30975ab0b0ac1e641f6e9b30d7e19813fe884a61 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5317 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 145557020 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c073b2c810, 0x55c073d1601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c073d16020,0x55c075bae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/30975ab0b0ac1e641f6e9b30d7e19813fe884a61' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6763 processed earlier; will process 4266 files now Step #5: ==191488== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c06a6219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c070c86898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c070c695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c070c694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c06a627d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c06a588b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c06a583355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c06a619c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c06d5e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c06d5e8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c06d5e8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c06d5e8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c06d5e8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c06d5e8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c06d5e8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c06d5e8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c06d5e8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c06d5e8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c06f87df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c06c5aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c06c5b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c06c361c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c06c361c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c06c362738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c06c361874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c06c361874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c06c361874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c070c6babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c070c74928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c070c5c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c070c87112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7eff68c15082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c06a581b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-050d6f73486abb07b585c3604a95da2e843a2ae6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5318 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 146106514 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56523f0db810, 0x56523f2c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56523f2c5020,0x56524115d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/050d6f73486abb07b585c3604a95da2e843a2ae6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6764 processed earlier; will process 4265 files now Step #5: ==191524== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565235bd09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56523c235898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56523c2185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56523c2184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565235bd6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565235b37b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565235b32355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565235bc8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565238b97f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565238b97f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565238b97f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565238b97f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565238b97f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565238b97f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565238b97f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565238b97f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565238b97f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565238b97f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56523ae2cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565237b59b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565237b64be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565237910c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565237910c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565237911738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565237910874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565237910874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565237910874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56523c21aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56523c223928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56523c20b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56523c236112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a1ea1d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565235b30b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-edc770070320cf6b5ce49b9e683417e4794e13a2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5319 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 146633825 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56478bbdd810, 0x56478bdc701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56478bdc7020,0x56478dc5f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/edc770070320cf6b5ce49b9e683417e4794e13a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6765 processed earlier; will process 4264 files now Step #5: #1 pulse cov: 3794 ft: 3795 exec/s: 0 rss: 176Mb Step #5: ==191560== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647826d29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564788d37898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564788d1a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564788d1a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647826d8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564782639b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564782634355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647826cac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564785699f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564785699f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564785699f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564785699f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564785699f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564785699f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564785699f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564785699f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564785699f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564785699f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56478792ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56478465bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564784666be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564784412c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564784412c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564784413738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564784412874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564784412874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564784412874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564788d1cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564788d25928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564788d0d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564788d38112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1293afd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564782632b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-03ffa7b4d8c8762ea2a4aaf7c96271e6a249d6f4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5320 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 147197100 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55841a8b3810, 0x55841aa9d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55841aa9d020,0x55841c9350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03ffa7b4d8c8762ea2a4aaf7c96271e6a249d6f4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6767 processed earlier; will process 4262 files now Step #5: ==191596== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5584113a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558417a0d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5584179f05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5584179f04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5584113aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55841130fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55841130a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5584113a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55841436ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55841436ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55841436ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55841436ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55841436ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55841436ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55841436ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55841436ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55841436ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55841436ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558416604f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558413331b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55841333cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5584130e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5584130e8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5584130e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5584130e8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5584130e8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5584130e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5584179f2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5584179fb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5584179e3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558417a0e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe652bd3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558411308b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d0381e363643970c4fa8cc8736b4458f6c533343 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5321 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 147746729 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556038294810, 0x55603847e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55603847e020,0x55603a3160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d0381e363643970c4fa8cc8736b4458f6c533343' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6768 processed earlier; will process 4261 files now Step #5: ==191632== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55602ed899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5560353ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5560353d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5560353d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55602ed8fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55602ecf0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55602eceb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55602ed81c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556031d50f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556031d50f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556031d50f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556031d50f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556031d50f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556031d50f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556031d50f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556031d50f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556031d50f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556031d50f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556033fe5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556030d12b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556030d1dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556030ac9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556030ac9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556030aca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556030ac9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556030ac9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556030ac9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5560353d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5560353dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5560353c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5560353ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3d3660082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55602ece9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3159cf803e30641b51cc8aa8646d823bd78f1d26 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5322 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 148293286 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5651f7ac1810, 0x5651f7cab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5651f7cab020,0x5651f9b430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3159cf803e30641b51cc8aa8646d823bd78f1d26' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6769 processed earlier; will process 4260 files now Step #5: ==191668== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5651ee5b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5651f4c1b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651f4bfe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651f4bfe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5651ee5bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5651ee51db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5651ee518355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5651ee5aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5651f157df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5651f157df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5651f157df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5651f157df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5651f157df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5651f157df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5651f157df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5651f157df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5651f157df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5651f157df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5651f3812f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5651f053fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5651f054abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5651f02f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5651f02f6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5651f02f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5651f02f6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5651f02f6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5651f02f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5651f4c00abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5651f4c09928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5651f4bf1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5651f4c1c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe2e19e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5651ee516b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-17aa14fb7656275eaf5c793be011596311082eb8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5323 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 148830227 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ffa2449810, 0x55ffa263301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ffa2633020,0x55ffa44cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/17aa14fb7656275eaf5c793be011596311082eb8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6770 processed earlier; will process 4259 files now Step #5: ==191704== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ff98f3e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff9f5a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff9f5865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff9f5864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff98f44d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff98ea5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff98ea0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff98f36c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff9bf05f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff9bf05f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff9bf05f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff9bf05f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff9bf05f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff9bf05f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff9bf05f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff9bf05f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff9bf05f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff9bf05f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff9e19af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff9aec7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff9aed2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff9ac7ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff9ac7ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff9ac7f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff9ac7e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff9ac7e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff9ac7e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff9f588abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff9f591928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff9f579699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff9f5a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0055504082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff98e9eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-55208a2dcda5989b843cd7a4eb8daba59d7f0d57 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5324 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 149350997 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d2a942d810, 0x55d2a961701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d2a9617020,0x55d2ab4af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/55208a2dcda5989b843cd7a4eb8daba59d7f0d57' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6771 processed earlier; will process 4258 files now Step #5: #1 pulse cov: 4022 ft: 4023 exec/s: 0 rss: 177Mb Step #5: ==191740== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d29ff229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d2a6587898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d2a656a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d2a656a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d29ff28d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d29fe89b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d29fe84355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d29ff1ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d2a2ee9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d2a2ee9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d2a2ee9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d2a2ee9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d2a2ee9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d2a2ee9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d2a2ee9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d2a2ee9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d2a2ee9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d2a2ee9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d2a517ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d2a1eabb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d2a1eb6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d2a1c62c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d2a1c62c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d2a1c63738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d2a1c62874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d2a1c62874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d2a1c62874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d2a656cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d2a6575928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d2a655d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d2a6588112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f62234cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d29fe82b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-dd84bea25222ff6d5c7206eb231f2a2d2e0a00da Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5325 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 149903272 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d5cd4d0810, 0x55d5cd6ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d5cd6ba020,0x55d5cf5520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dd84bea25222ff6d5c7206eb231f2a2d2e0a00da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6773 processed earlier; will process 4256 files now Step #5: ==191776== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d5c3fc59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d5ca62a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d5ca60d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d5ca60d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d5c3fcbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d5c3f2cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d5c3f27355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d5c3fbdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d5c6f8cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d5c6f8cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d5c6f8cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d5c6f8cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d5c6f8cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d5c6f8cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d5c6f8cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d5c6f8cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d5c6f8cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d5c6f8cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d5c9221f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d5c5f4eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d5c5f59be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d5c5d05c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d5c5d05c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d5c5d06738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d5c5d05874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d5c5d05874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d5c5d05874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d5ca60fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d5ca618928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d5ca600699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d5ca62b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f70b9b52082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d5c3f25b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3c5bb58f75f84d22b982d828fd2439dfd8946549 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5326 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 150475530 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56469d342810, 0x56469d52c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56469d52c020,0x56469f3c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3c5bb58f75f84d22b982d828fd2439dfd8946549' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6774 processed earlier; will process 4255 files now Step #5: #1 pulse cov: 3951 ft: 3952 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4162 ft: 4578 exec/s: 0 rss: 179Mb Step #5: ==191812== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564693e379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56469a49c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56469a47f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56469a47f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564693e3dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564693d9eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564693d99355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564693e2fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564696dfef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564696dfef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564696dfef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564696dfef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564696dfef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564696dfef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564696dfef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564696dfef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564696dfef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564696dfef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564699093f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564695dc0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564695dcbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564695b77c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564695b77c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564695b78738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564695b77874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564695b77874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564695b77874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56469a481abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56469a48a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56469a472699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56469a49d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e1863b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564693d97b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5f5f9b5bda5ff6af75be7f7bd2ef945d7f3d0c37 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5327 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 151204413 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e4f8e6810, 0x559e4fad001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e4fad0020,0x559e519680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f5f9b5bda5ff6af75be7f7bd2ef945d7f3d0c37' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6777 processed earlier; will process 4252 files now Step #5: ==191848== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559e463db9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e4ca40898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e4ca235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e4ca234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e463e1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e46342b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e4633d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e463d3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e493a2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e493a2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e493a2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e493a2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e493a2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e493a2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e493a2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e493a2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e493a2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e493a2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e4b637f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e48364b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e4836fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e4811bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e4811bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e4811c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e4811b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e4811b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e4811b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e4ca25abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e4ca2e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e4ca16699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e4ca41112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f895e79e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e4633bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e7f8dfc8e0c554722fbc110183071fe9d8fe1d46 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5328 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 151718619 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fd73170810, 0x55fd7335a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fd7335a020,0x55fd751f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e7f8dfc8e0c554722fbc110183071fe9d8fe1d46' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6778 processed earlier; will process 4251 files now Step #5: ==191884== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fd69c659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fd702ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fd702ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fd702ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fd69c6bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fd69bccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fd69bc7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fd69c5dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fd6cc2cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fd6cc2cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fd6cc2cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fd6cc2cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fd6cc2cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fd6cc2cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fd6cc2cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fd6cc2cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fd6cc2cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fd6cc2cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fd6eec1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fd6bbeeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fd6bbf9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fd6b9a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fd6b9a5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fd6b9a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fd6b9a5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fd6b9a5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fd6b9a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fd702afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fd702b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fd702a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fd702cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffb3003a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fd69bc5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-99f441b42bbbd3075998328c3df1cec3449a65ca Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5329 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 152245312 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55580af95810, 0x55580b17f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55580b17f020,0x55580d0170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/99f441b42bbbd3075998328c3df1cec3449a65ca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6779 processed earlier; will process 4250 files now Step #5: #1 pulse cov: 3750 ft: 3751 exec/s: 0 rss: 178Mb Step #5: ==191920== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555801a8a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5558080ef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5558080d25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5558080d24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555801a90d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5558019f1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5558019ec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555801a82c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555804a51f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555804a51f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555804a51f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555804a51f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555804a51f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555804a51f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555804a51f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555804a51f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555804a51f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555804a51f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555806ce6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555803a13b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555803a1ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5558037cac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5558037cac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5558037cb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5558037ca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5558037ca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5558037ca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5558080d4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5558080dd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5558080c5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5558080f0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f40b9bd4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5558019eab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-eac6dd16556e3682c99d5a9e761415077fb92e3b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5330 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 152858580 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fde6aac810, 0x55fde6c9601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fde6c96020,0x55fde8b2e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eac6dd16556e3682c99d5a9e761415077fb92e3b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6781 processed earlier; will process 4248 files now Step #5: ==191956== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fddd5a19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fde3c06898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fde3be95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fde3be94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fddd5a7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fddd508b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fddd503355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fddd599c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fde0568f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fde0568f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fde0568f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fde0568f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fde0568f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fde0568f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fde0568f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fde0568f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fde0568f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fde0568f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fde27fdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fddf52ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fddf535be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fddf2e1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fddf2e1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fddf2e2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fddf2e1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fddf2e1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fddf2e1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fde3bebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fde3bf4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fde3bdc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fde3c07112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc96b0d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fddd501b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-44ee4eb8955c5a8c34eaa52a9dd99c8e3944c942 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5331 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 153404109 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643ad436810, 0x5643ad62001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643ad620020,0x5643af4b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/44ee4eb8955c5a8c34eaa52a9dd99c8e3944c942' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6782 processed earlier; will process 4247 files now Step #5: ==191992== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643a3f2b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643aa590898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643aa5735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643aa5734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643a3f31d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643a3e92b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643a3e8d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643a3f23c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643a6ef2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643a6ef2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643a6ef2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643a6ef2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643a6ef2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643a6ef2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643a6ef2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643a6ef2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643a6ef2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643a6ef2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643a9187f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643a5eb4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643a5ebfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643a5c6bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643a5c6bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643a5c6c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643a5c6b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643a5c6b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643a5c6b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643aa575abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643aa57e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643aa566699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643aa591112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f10bd88c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643a3e8bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ffca2c69fbd6fa8208a190f0dd6103551d97e33 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5332 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 153929558 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1dc316810, 0x55a1dc50001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1dc500020,0x55a1de3980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ffca2c69fbd6fa8208a190f0dd6103551d97e33' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6783 processed earlier; will process 4246 files now Step #5: ==192028== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1d2e0b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1d9470898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1d94535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1d94534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1d2e11d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1d2d72b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1d2d6d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1d2e03c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1d5dd2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1d5dd2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1d5dd2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1d5dd2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1d5dd2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1d5dd2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1d5dd2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1d5dd2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1d5dd2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1d5dd2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1d8067f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1d4d94b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1d4d9fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1d4b4bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1d4b4bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1d4b4c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1d4b4b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1d4b4b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1d4b4b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a1d9455abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a1d945e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1d9446699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1d9471112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fea8119f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1d2d6bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-debf61f8af828bb5c681d1ab8641e180c68e65b2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5333 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 154474894 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc15773810, 0x55fc1595d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc1595d020,0x55fc177f50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/debf61f8af828bb5c681d1ab8641e180c68e65b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6784 processed earlier; will process 4245 files now Step #5: #1 pulse cov: 12042 ft: 12043 exec/s: 0 rss: 200Mb Step #5: ==192064== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fc0c2689c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc128cd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc128b05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc128b04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc0c26ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc0c1cfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc0c1ca355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc0c260c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc0f22ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc0f22ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc0f22ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc0f22ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc0f22ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc0f22ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc0f22ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc0f22ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc0f22ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc0f22ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc114c4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc0e1f1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc0e1fcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc0dfa8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc0dfa8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc0dfa9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc0dfa8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc0dfa8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc0dfa8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc128b2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc128bb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc128a3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc128ce112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f03ba51e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc0c1c8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f64642264f28936fde2eb8db8b791138506a0c9e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5334 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 155080100 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5625be16f810, 0x5625be35901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625be359020,0x5625c01f10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f64642264f28936fde2eb8db8b791138506a0c9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6786 processed earlier; will process 4243 files now Step #5: #1 pulse cov: 3857 ft: 3858 exec/s: 0 rss: 178Mb Step #5: ==192100== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5625b4c649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5625bb2c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625bb2ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625bb2ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5625b4c6ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625b4bcbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625b4bc6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5625b4c5cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5625b7c2bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5625b7c2bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5625b7c2bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5625b7c2bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5625b7c2bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5625b7c2bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5625b7c2bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5625b7c2bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5625b7c2bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5625b7c2bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5625b9ec0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625b6bedb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5625b6bf8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5625b69a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5625b69a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5625b69a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5625b69a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5625b69a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5625b69a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5625bb2aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5625bb2b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5625bb29f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5625bb2ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6cbd341082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625b4bc4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-885623db30d75a022ad97bba4746a1bd3b0837e0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5335 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 155622789 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5562e0faf810, 0x5562e119901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5562e1199020,0x5562e30310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/885623db30d75a022ad97bba4746a1bd3b0837e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6788 processed earlier; will process 4241 files now Step #5: ==192136== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5562d7aa49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5562de109898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5562de0ec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5562de0ec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5562d7aaad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5562d7a0bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5562d7a06355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5562d7a9cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5562daa6bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5562daa6bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5562daa6bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5562daa6bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5562daa6bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5562daa6bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5562daa6bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5562daa6bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5562daa6bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5562daa6bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5562dcd00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5562d9a2db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5562d9a38be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5562d97e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5562d97e4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5562d97e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5562d97e4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5562d97e4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5562d97e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5562de0eeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5562de0f7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5562de0df699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5562de10a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f62491e8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5562d7a04b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8cd212e5be70b2d5b8dc0f0e3ed4458ad8490926 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5336 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 156146100 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e71809e810, 0x55e71828801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e718288020,0x55e71a1200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8cd212e5be70b2d5b8dc0f0e3ed4458ad8490926' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6789 processed earlier; will process 4240 files now Step #5: #1 pulse cov: 3901 ft: 3902 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4141 ft: 4907 exec/s: 0 rss: 181Mb Step #5: ==192172== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e70eb939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e7151f8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7151db5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7151db4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e70eb99d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e70eafab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e70eaf5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e70eb8bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e711b5af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e711b5af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e711b5af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e711b5af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e711b5af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e711b5af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e711b5af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e711b5af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e711b5af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e711b5af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e713deff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e710b1cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e710b27be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e7108d3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e7108d3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e7108d4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e7108d3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e7108d3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e7108d3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e7151ddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e7151e6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e7151ce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e7151f9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3f19b80082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e70eaf3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f19daffb19e1a4db9835e80bbb1668ab07085d22 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5337 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 156770945 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c256fcd810, 0x55c2571b701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c2571b7020,0x55c25904f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f19daffb19e1a4db9835e80bbb1668ab07085d22' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6792 processed earlier; will process 4237 files now Step #5: ==192208== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c24dac29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c254127898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c25410a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c25410a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c24dac8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c24da29b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c24da24355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c24dabac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c250a89f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c250a89f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c250a89f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c250a89f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c250a89f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c250a89f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c250a89f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c250a89f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c250a89f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c250a89f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c252d1ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c24fa4bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c24fa56be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c24f802c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c24f802c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c24f803738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c24f802874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c24f802874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c24f802874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c25410cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c254115928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c2540fd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c254128112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbba8a69082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c24da22b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fd60bd56ec3e3ff717bc3e2eab3300472771bd17 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5338 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 157416161 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56528e174810, 0x56528e35e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56528e35e020,0x5652901f60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fd60bd56ec3e3ff717bc3e2eab3300472771bd17' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6793 processed earlier; will process 4236 files now Step #5: ==192244== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565284c699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56528b2ce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56528b2b15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56528b2b14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565284c6fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565284bd0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565284bcb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565284c61c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565287c30f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565287c30f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565287c30f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565287c30f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565287c30f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565287c30f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565287c30f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565287c30f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565287c30f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565287c30f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565289ec5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565286bf2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565286bfdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652869a9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652869a9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652869aa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652869a9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652869a9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652869a9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56528b2b3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56528b2bc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56528b2a4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56528b2cf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88b3390082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565284bc9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-93b0b0e88a00c26fa866ddc2a3794901166ae641 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5339 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 157942587 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560cbd86f810, 0x560cbda5901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560cbda59020,0x560cbf8f10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93b0b0e88a00c26fa866ddc2a3794901166ae641' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6794 processed earlier; will process 4235 files now Step #5: ==192280== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560cb43649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560cba9c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560cba9ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560cba9ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560cb436ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560cb42cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560cb42c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560cb435cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560cb732bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560cb732bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560cb732bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560cb732bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560cb732bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560cb732bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560cb732bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560cb732bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560cb732bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560cb732bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560cb95c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560cb62edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560cb62f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560cb60a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560cb60a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560cb60a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560cb60a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560cb60a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560cb60a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560cba9aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560cba9b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560cba99f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560cba9ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6284bfe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560cb42c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-909bf8e02b454d42994d02addfb48fc447209def Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5340 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 158473697 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee58492810, 0x55ee5867c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee5867c020,0x55ee5a5140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/909bf8e02b454d42994d02addfb48fc447209def' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6795 processed earlier; will process 4234 files now Step #5: ==192316== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ee4ef879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee555ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee555cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee555cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee4ef8dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee4eeeeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee4eee9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee4ef7fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee51f4ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee51f4ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee51f4ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee51f4ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee51f4ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee51f4ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee51f4ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee51f4ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee51f4ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee51f4ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee541e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee50f10b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee50f1bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee50cc7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee50cc7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee50cc8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee50cc7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee50cc7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee50cc7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee555d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee555da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee555c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee555ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8016cb7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee4eee7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6fd8436c8f097a014d6897a40f38bb3fdf896f69 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5341 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 159019310 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ff7f0c810, 0x562ff80f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ff80f6020,0x562ff9f8e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6fd8436c8f097a014d6897a40f38bb3fdf896f69' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6796 processed earlier; will process 4233 files now Step #5: ==192352== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562feea019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ff5066898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ff50495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ff50494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562feea07d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562fee968b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562fee963355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562fee9f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ff19c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ff19c8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ff19c8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ff19c8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ff19c8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ff19c8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ff19c8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ff19c8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ff19c8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ff19c8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ff3c5df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ff098ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ff0995be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ff0741c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ff0741c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ff0742738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ff0741874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ff0741874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ff0741874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ff504babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ff5054928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ff503c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ff5067112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fed97794082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562fee961b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9679bc30be0d57b80f058c09b1b3053bf65ff115 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5342 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 159537620 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647fadae810, 0x5647faf9801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5647faf98020,0x5647fce300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9679bc30be0d57b80f058c09b1b3053bf65ff115' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6797 processed earlier; will process 4232 files now Step #5: #1 pulse cov: 3953 ft: 3954 exec/s: 0 rss: 177Mb Step #5: ==192388== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647f18a39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647f7f08898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647f7eeb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647f7eeb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647f18a9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647f180ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647f1805355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647f189bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647f486af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647f486af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647f486af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647f486af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647f486af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647f486af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647f486af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647f486af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647f486af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647f486af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647f6afff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647f382cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647f3837be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647f35e3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647f35e3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647f35e4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647f35e3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647f35e3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647f35e3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647f7eedabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647f7ef6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647f7ede699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647f7f09112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa94c8e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647f1803b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9292308efbd47af81a0dc3f0aa634cc92b8e0ce4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5343 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 160098608 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563f65922810, 0x563f65b0c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563f65b0c020,0x563f679a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9292308efbd47af81a0dc3f0aa634cc92b8e0ce4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6799 processed earlier; will process 4230 files now Step #5: #1 pulse cov: 11055 ft: 11056 exec/s: 0 rss: 198Mb Step #5: ==192424== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563f5c4179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563f62a7c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563f62a5f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563f62a5f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563f5c41dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563f5c37eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563f5c379355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563f5c40fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563f5f3def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563f5f3def10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563f5f3def10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563f5f3def10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563f5f3def10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563f5f3def10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563f5f3def10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563f5f3def10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563f5f3def10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563f5f3def10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563f61673f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563f5e3a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563f5e3abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563f5e157c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563f5e157c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563f5e158738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563f5e157874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563f5e157874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563f5e157874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563f62a61abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563f62a6a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563f62a52699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563f62a7d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f81bcbe4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563f5c377b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-944d78eb55a63b8306260a34cb98475ffdb33164 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5344 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 160703075 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5641a24cf810, 0x5641a26b901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5641a26b9020,0x5641a45510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/944d78eb55a63b8306260a34cb98475ffdb33164' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6801 processed earlier; will process 4228 files now Step #5: #1 pulse cov: 4268 ft: 4269 exec/s: 0 rss: 177Mb Step #5: ==192460== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564198fc49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56419f629898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56419f60c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56419f60c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564198fcad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564198f2bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564198f26355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564198fbcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56419bf8bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56419bf8bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56419bf8bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56419bf8bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56419bf8bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56419bf8bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56419bf8bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56419bf8bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56419bf8bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56419bf8bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56419e220f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56419af4db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56419af58be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56419ad04c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56419ad04c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56419ad05738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56419ad04874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56419ad04874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56419ad04874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56419f60eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56419f617928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56419f5ff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56419f62a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ce2c94082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564198f24b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-842ece20916d710cdf1343e226d273ccceb0459c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5345 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 161374153 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5618b8b0e810, 0x5618b8cf801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5618b8cf8020,0x5618bab900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/842ece20916d710cdf1343e226d273ccceb0459c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6803 processed earlier; will process 4226 files now Step #5: ==192496== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5618af6039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5618b5c68898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5618b5c4b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5618b5c4b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5618af609d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5618af56ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5618af565355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5618af5fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5618b25caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5618b25caf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5618b25caf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5618b25caf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5618b25caf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5618b25caf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5618b25caf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5618b25caf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5618b25caf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5618b25caf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5618b485ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5618b158cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5618b1597be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5618b1343c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5618b1343c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5618b1344738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5618b1343874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5618b1343874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5618b1343874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5618b5c4dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5618b5c56928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5618b5c3e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5618b5c69112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd9c2010082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5618af563b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-604bcd1cf23fbd9cba6b1137529ebb66ccba7e41 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5346 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 162011650 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5588cacd9810, 0x5588caec301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5588caec3020,0x5588ccd5b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/604bcd1cf23fbd9cba6b1137529ebb66ccba7e41' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6804 processed earlier; will process 4225 files now Step #5: ==192532== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5588c17ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5588c7e33898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588c7e165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588c7e164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588c17d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588c1735b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588c1730355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588c17c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5588c4795f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5588c4795f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5588c4795f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5588c4795f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5588c4795f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5588c4795f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5588c4795f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5588c4795f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5588c4795f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5588c4795f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5588c6a2af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588c3757b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588c3762be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588c350ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588c350ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588c350f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588c350e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588c350e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588c350e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5588c7e18abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5588c7e21928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5588c7e09699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5588c7e34112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbd4c1da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588c172eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2871d571ff542aa92d4d0abbf546494b141744b9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5347 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 162535812 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557a670fc810, 0x557a672e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557a672e6020,0x557a6917e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2871d571ff542aa92d4d0abbf546494b141744b9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6805 processed earlier; will process 4224 files now Step #5: #1 pulse cov: 3777 ft: 3778 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4086 ft: 4692 exec/s: 0 rss: 179Mb Step #5: ==192568== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557a5dbf19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557a64256898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557a642395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557a642394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557a5dbf7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557a5db58b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557a5db53355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557a5dbe9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557a60bb8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557a60bb8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557a60bb8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557a60bb8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557a60bb8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557a60bb8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557a60bb8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557a60bb8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557a60bb8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557a60bb8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557a62e4df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557a5fb7ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557a5fb85be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557a5f931c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557a5f931c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557a5f932738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557a5f931874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557a5f931874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557a5f931874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557a6423babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557a64244928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557a6422c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557a64257112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba713a1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557a5db51b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7e05f1f48820a79559f517adf940290b821a70c5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5348 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 163133040 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56448f29b810, 0x56448f48501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56448f485020,0x56449131d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7e05f1f48820a79559f517adf940290b821a70c5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6808 processed earlier; will process 4221 files now Step #5: ==192604== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564485d909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56448c3f5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56448c3d85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56448c3d84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564485d96d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564485cf7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564485cf2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564485d88c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564488d57f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564488d57f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564488d57f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564488d57f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564488d57f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564488d57f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564488d57f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564488d57f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564488d57f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564488d57f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56448afecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564487d19b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564487d24be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564487ad0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564487ad0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564487ad1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564487ad0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564487ad0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564487ad0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56448c3daabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56448c3e3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56448c3cb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56448c3f6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb69b8ad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564485cf0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-662cc5a8b97c8d02f4fc5d2fa5b52202c0c10aa9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5349 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 163676725 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fbb9a3f810, 0x55fbb9c2901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fbb9c29020,0x55fbbbac10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/662cc5a8b97c8d02f4fc5d2fa5b52202c0c10aa9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6809 processed earlier; will process 4220 files now Step #5: ==192640== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fbb05349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fbb6b99898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fbb6b7c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fbb6b7c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fbb053ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fbb049bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fbb0496355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fbb052cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fbb34fbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fbb34fbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fbb34fbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fbb34fbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fbb34fbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fbb34fbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fbb34fbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fbb34fbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fbb34fbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fbb34fbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fbb5790f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fbb24bdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fbb24c8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fbb2274c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fbb2274c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fbb2275738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fbb2274874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fbb2274874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fbb2274874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fbb6b7eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fbb6b87928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fbb6b6f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fbb6b9a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6cded38082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fbb0494b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-11c13630eb18964d4f9b1b64d61445d14e58057d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5350 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 164322566 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bc9e8d2810, 0x55bc9eabc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bc9eabc020,0x55bca09540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/11c13630eb18964d4f9b1b64d61445d14e58057d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6810 processed earlier; will process 4219 files now Step #5: ==192676== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bc953c79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bc9ba2c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bc9ba0f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bc9ba0f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bc953cdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bc9532eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bc95329355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bc953bfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bc9838ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bc9838ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bc9838ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bc9838ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bc9838ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bc9838ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bc9838ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bc9838ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bc9838ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bc9838ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bc9a623f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bc97350b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bc9735bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bc97107c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bc97107c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bc97108738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bc97107874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bc97107874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bc97107874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bc9ba11abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bc9ba1a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bc9ba02699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bc9ba2d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5717cbc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bc95327b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cbd3b4f90fca4a5bdaddbabd6cbf56e22f169c8a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5351 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 164852778 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5596b151e810, 0x5596b170801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596b1708020,0x5596b35a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cbd3b4f90fca4a5bdaddbabd6cbf56e22f169c8a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6811 processed earlier; will process 4218 files now Step #5: #1 pulse cov: 3820 ft: 3821 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4462 ft: 4837 exec/s: 0 rss: 179Mb Step #5: ==192712== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5596a80139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5596ae678898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5596ae65b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5596ae65b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5596a8019d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5596a7f7ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5596a7f75355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5596a800bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5596aafdaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5596aafdaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5596aafdaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5596aafdaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5596aafdaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5596aafdaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5596aafdaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5596aafdaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5596aafdaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5596aafdaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596ad26ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5596a9f9cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5596a9fa7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5596a9d53c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5596a9d53c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5596a9d54738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5596a9d53874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5596a9d53874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5596a9d53874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5596ae65dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5596ae666928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5596ae64e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5596ae679112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6a24373082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5596a7f73b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-642fe3b8f2cb81d1f5eb265781f376fe5ce9531f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5352 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 165484648 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5591b61ab810, 0x5591b639501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5591b6395020,0x5591b822d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/642fe3b8f2cb81d1f5eb265781f376fe5ce9531f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6814 processed earlier; will process 4215 files now Step #5: ==192748== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5591acca09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5591b3305898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5591b32e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5591b32e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5591acca6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5591acc07b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5591acc02355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5591acc98c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5591afc67f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5591afc67f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5591afc67f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5591afc67f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5591afc67f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5591afc67f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5591afc67f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5591afc67f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5591afc67f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5591afc67f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5591b1efcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5591aec29b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5591aec34be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5591ae9e0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5591ae9e0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5591ae9e1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5591ae9e0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5591ae9e0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5591ae9e0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5591b32eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5591b32f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5591b32db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5591b3306112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa93354c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5591acc00b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d4c39c75c565154d238d1d8ff6d168d58d2518ac Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5353 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 166040386 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8f2992810, 0x55c8f2b7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c8f2b7c020,0x55c8f4a140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d4c39c75c565154d238d1d8ff6d168d58d2518ac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6815 processed earlier; will process 4214 files now Step #5: ==192784== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c8e94879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8efaec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8efacf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8efacf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c8e948dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c8e93eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c8e93e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c8e947fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c8ec44ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c8ec44ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c8ec44ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c8ec44ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c8ec44ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c8ec44ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c8ec44ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c8ec44ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c8ec44ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c8ec44ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c8ee6e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c8eb410b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c8eb41bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c8eb1c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c8eb1c7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c8eb1c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c8eb1c7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c8eb1c7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c8eb1c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8efad1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8efada928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8efac2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8efaed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fde0bf11082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c8e93e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2733e6eec1be33ce8ed06a2d100c5821c7df82f3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5354 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 166595820 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ba1011810, 0x561ba11fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ba11fb020,0x561ba30930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2733e6eec1be33ce8ed06a2d100c5821c7df82f3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6816 processed earlier; will process 4213 files now Step #5: ==192820== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561b97b069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b9e16b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b9e14e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b9e14e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b97b0cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b97a6db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b97a68355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b97afec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b9aacdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b9aacdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b9aacdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b9aacdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b9aacdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b9aacdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b9aacdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b9aacdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b9aacdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b9aacdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b9cd62f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b99a8fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b99a9abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b99846c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b99846c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b99847738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b99846874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b99846874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b99846874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b9e150abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b9e159928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b9e141699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b9e16c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf45134082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b97a66b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1eda20f08ae0d066694c3435d040d6f4bc9aa3b4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5355 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 167241148 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e73c7b0810, 0x55e73c99a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e73c99a020,0x55e73e8320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1eda20f08ae0d066694c3435d040d6f4bc9aa3b4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6817 processed earlier; will process 4212 files now Step #5: #1 pulse cov: 3905 ft: 3906 exec/s: 0 rss: 176Mb Step #5: #2 pulse cov: 4272 ft: 4732 exec/s: 0 rss: 178Mb Step #5: #4 pulse cov: 4573 ft: 5993 exec/s: 0 rss: 179Mb Step #5: ==192856== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e7332a59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e73990a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7398ed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7398ed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e7332abd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e73320cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e733207355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e73329dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e73626cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e73626cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e73626cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e73626cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e73626cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e73626cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e73626cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e73626cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e73626cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e73626cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e738501f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e73522eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e735239be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e734fe5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e734fe5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e734fe6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e734fe5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e734fe5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e734fe5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e7398efabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e7398f8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e7398e0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e73990b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f97caac5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e733205b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-52ba175beb5f3c746042cb93da8c069565734a4f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5356 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 168002486 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c17675810, 0x559c1785f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c1785f020,0x559c196f70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/52ba175beb5f3c746042cb93da8c069565734a4f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6822 processed earlier; will process 4207 files now Step #5: ==192892== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559c0e16a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c147cf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c147b25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c147b24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c0e170d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c0e0d1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c0e0cc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c0e162c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c11131f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c11131f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c11131f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c11131f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c11131f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c11131f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c11131f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c11131f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c11131f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c11131f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c133c6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c100f3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c100febe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c0feaac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c0feaac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c0feab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c0feaa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c0feaa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c0feaa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c147b4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c147bd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c147a5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c147d0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7effb894e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c0e0cab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-899995be3d94d0d8435db83b31fa4e4da56fcf0d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5357 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 168513374 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d1f2e2810, 0x556d1f4cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d1f4cc020,0x556d213640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/899995be3d94d0d8435db83b31fa4e4da56fcf0d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6823 processed earlier; will process 4206 files now Step #5: #1 pulse cov: 4103 ft: 4104 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4434 ft: 4985 exec/s: 0 rss: 178Mb Step #5: ==192928== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556d15dd79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d1c43c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d1c41f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d1c41f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d15dddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d15d3eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d15d39355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d15dcfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d18d9ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d18d9ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d18d9ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d18d9ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d18d9ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d18d9ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d18d9ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d18d9ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d18d9ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d18d9ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d1b033f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d17d60b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d17d6bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d17b17c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d17b17c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d17b18738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d17b17874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d17b17874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d17b17874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d1c421abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d1c42a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d1c412699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d1c43d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7ca3afb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d15d37b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9c311517d0a03654700999ad5c7190021b66ca64 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5358 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 169149259 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5602d7e45810, 0x5602d802f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5602d802f020,0x5602d9ec70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c311517d0a03654700999ad5c7190021b66ca64' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6827 processed earlier; will process 4202 files now Step #5: #1 pulse cov: 4280 ft: 4281 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4599 ft: 5198 exec/s: 0 rss: 178Mb Step #5: ==192964== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5602ce93a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5602d4f9f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602d4f825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602d4f824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5602ce940d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5602ce8a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5602ce89c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5602ce932c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5602d1901f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5602d1901f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5602d1901f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5602d1901f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5602d1901f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5602d1901f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5602d1901f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5602d1901f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5602d1901f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5602d1901f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5602d3b96f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5602d08c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5602d08cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5602d067ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5602d067ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5602d067b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5602d067a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5602d067a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5602d067a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5602d4f84abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5602d4f8d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5602d4f75699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5602d4fa0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d5bf0f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5602ce89ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7d31aa86788dcd9d5dbb3ecdeaea7aec68bf869f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5359 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 169739150 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56232864a810, 0x56232883401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562328834020,0x56232a6cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d31aa86788dcd9d5dbb3ecdeaea7aec68bf869f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6830 processed earlier; will process 4199 files now Step #5: ==193000== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56231f13f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5623257a4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5623257875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5623257874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56231f145d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56231f0a6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56231f0a1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56231f137c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562322106f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562322106f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562322106f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562322106f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562322106f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562322106f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562322106f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562322106f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562322106f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562322106f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56232439bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5623210c8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5623210d3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562320e7fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562320e7fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562320e80738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562320e7f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562320e7f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562320e7f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562325789abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562325792928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56232577a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5623257a5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f4f12c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56231f09fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f52b74a72dd1f7b3a18f504dea9a2136343ce2de Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5360 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 170257648 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5626901de810, 0x5626903c801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5626903c8020,0x5626922600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f52b74a72dd1f7b3a18f504dea9a2136343ce2de' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6831 processed earlier; will process 4198 files now Step #5: #1 pulse cov: 3985 ft: 3986 exec/s: 0 rss: 178Mb Step #5: ==193036== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562686cd39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56268d338898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56268d31b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56268d31b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562686cd9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562686c3ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562686c35355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562686ccbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562689c9af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562689c9af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562689c9af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562689c9af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562689c9af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562689c9af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562689c9af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562689c9af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562689c9af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562689c9af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56268bf2ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562688c5cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562688c67be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562688a13c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562688a13c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562688a14738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562688a13874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562688a13874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562688a13874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56268d31dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56268d326928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56268d30e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56268d339112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa4e49c9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562686c33b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fcaf9aef9c8493ae692cee180a7315b0de85ca4d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5361 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 170811803 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558416fb6810, 0x5584171a001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5584171a0020,0x5584190380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fcaf9aef9c8493ae692cee180a7315b0de85ca4d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6833 processed earlier; will process 4196 files now Step #5: ==193072== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55840daab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558414110898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5584140f35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5584140f34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55840dab1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55840da12b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55840da0d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55840daa3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558410a72f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558410a72f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558410a72f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558410a72f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558410a72f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558410a72f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558410a72f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558410a72f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558410a72f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558410a72f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558412d07f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55840fa34b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55840fa3fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55840f7ebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55840f7ebc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55840f7ec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55840f7eb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55840f7eb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55840f7eb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5584140f5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5584140fe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5584140e6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558414111112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e02525082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55840da0bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b32d6ee61816cb84144b47ae7667c89bc66ac560 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5362 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 171331226 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc58a12810, 0x55cc58bfc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc58bfc020,0x55cc5aa940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b32d6ee61816cb84144b47ae7667c89bc66ac560' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6834 processed earlier; will process 4195 files now Step #5: ==193108== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cc4f5079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc55b6c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc55b4f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc55b4f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc4f50dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc4f46eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc4f469355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc4f4ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc524cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc524cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc524cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc524cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc524cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc524cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc524cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc524cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc524cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc524cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc54763f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc51490b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc5149bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc51247c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc51247c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc51248738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc51247874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc51247874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc51247874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc55b51abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc55b5a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc55b42699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc55b6d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3620676082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc4f467b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-afc463938cab01c897046e86f61ace0c84d2bdf3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5363 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 171852523 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff7788b810, 0x55ff77a7501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff77a75020,0x55ff7990d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/afc463938cab01c897046e86f61ace0c84d2bdf3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6835 processed earlier; will process 4194 files now Step #5: ==193144== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ff6e3809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff749e5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff749c85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff749c84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff6e386d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff6e2e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff6e2e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff6e378c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff71347f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff71347f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff71347f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff71347f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff71347f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff71347f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff71347f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff71347f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff71347f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff71347f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff735dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff70309b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff70314be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff700c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff700c0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff700c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff700c0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff700c0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff700c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff749caabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff749d3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff749bb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff749e6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2be505f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff6e2e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1ebe8bba6e606c421eb8657e6bc87ac0378a2d66 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5364 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 172375234 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af5c135810, 0x55af5c31f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af5c31f020,0x55af5e1b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ebe8bba6e606c421eb8657e6bc87ac0378a2d66' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6836 processed earlier; will process 4193 files now Step #5: ==193180== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55af52c2a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af5928f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af592725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af592724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55af52c30d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55af52b91b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55af52b8c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55af52c22c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55af55bf1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55af55bf1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55af55bf1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55af55bf1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55af55bf1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55af55bf1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55af55bf1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55af55bf1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55af55bf1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55af55bf1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af57e86f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af54bb3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af54bbebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af5496ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af5496ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af5496b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af5496a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af5496a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af5496a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af59274abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af5927d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af59265699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af59290112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9cc14af082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55af52b8ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f69123432a0f31570eb6f75c87d062b3364ab847 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5365 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 172898574 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5635305e5810, 0x5635307cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5635307cf020,0x5635326670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f69123432a0f31570eb6f75c87d062b3364ab847' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6837 processed earlier; will process 4192 files now Step #5: ==193216== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5635270da9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56352d73f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56352d7225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56352d7224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5635270e0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563527041b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56352703c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5635270d2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56352a0a1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56352a0a1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56352a0a1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56352a0a1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56352a0a1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56352a0a1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56352a0a1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56352a0a1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56352a0a1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56352a0a1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56352c336f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563529063b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56352906ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563528e1ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563528e1ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563528e1b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563528e1a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563528e1a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563528e1a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56352d724abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56352d72d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56352d715699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56352d740112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5db391a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56352703ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f25893c62f46a7e55c39ad8f26740ef752082c02 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5366 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 173431621 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5621b01b9810, 0x5621b03a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5621b03a3020,0x5621b223b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f25893c62f46a7e55c39ad8f26740ef752082c02' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6838 processed earlier; will process 4191 files now Step #5: ==193252== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5621a6cae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5621ad313898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5621ad2f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5621ad2f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5621a6cb4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5621a6c15b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5621a6c10355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5621a6ca6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5621a9c75f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5621a9c75f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5621a9c75f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5621a9c75f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5621a9c75f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5621a9c75f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5621a9c75f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5621a9c75f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5621a9c75f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5621a9c75f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5621abf0af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5621a8c37b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5621a8c42be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5621a89eec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5621a89eec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5621a89ef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5621a89ee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5621a89ee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5621a89ee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5621ad2f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5621ad301928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5621ad2e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5621ad314112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc8d8bdc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5621a6c0eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ca18b01b864618b5e946bad9a0f9d4f10e96baee Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5367 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 173951001 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea566b3810, 0x55ea5689d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea5689d020,0x55ea587350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca18b01b864618b5e946bad9a0f9d4f10e96baee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6839 processed earlier; will process 4190 files now Step #5: ==193288== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ea4d1a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea5380d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea537f05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea537f04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea4d1aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea4d10fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea4d10a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea4d1a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea5016ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea5016ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea5016ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea5016ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea5016ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea5016ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea5016ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea5016ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea5016ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea5016ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea52404f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea4f131b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea4f13cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea4eee8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea4eee8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea4eee9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea4eee8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea4eee8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea4eee8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea537f2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea537fb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea537e3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea5380e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe7ef9e1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea4d108b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-613ff0a5e0294903f992b33c833403b6037a873b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5368 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 174476305 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557625926810, 0x557625b1001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557625b10020,0x5576279a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/613ff0a5e0294903f992b33c833403b6037a873b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6840 processed earlier; will process 4189 files now Step #5: ==193324== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55761c41b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557622a80898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557622a635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557622a634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55761c421d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55761c382b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55761c37d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55761c413c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55761f3e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55761f3e2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55761f3e2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55761f3e2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55761f3e2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55761f3e2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55761f3e2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55761f3e2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55761f3e2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55761f3e2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557621677f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55761e3a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55761e3afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55761e15bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55761e15bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55761e15c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55761e15b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55761e15b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55761e15b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557622a65abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557622a6e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557622a56699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557622a81112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0d7d81082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55761c37bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-34b1b1cc848cd524d040c9e0dbfeedcaa375e963 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5369 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 175011692 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556bfb954810, 0x556bfbb3e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556bfbb3e020,0x556bfd9d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/34b1b1cc848cd524d040c9e0dbfeedcaa375e963' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6841 processed earlier; will process 4188 files now Step #5: ==193360== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556bf24499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556bf8aae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556bf8a915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556bf8a914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556bf244fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556bf23b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556bf23ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556bf2441c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556bf5410f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556bf5410f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556bf5410f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556bf5410f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556bf5410f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556bf5410f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556bf5410f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556bf5410f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556bf5410f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556bf5410f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556bf76a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556bf43d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556bf43ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556bf4189c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556bf4189c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556bf418a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556bf4189874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556bf4189874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556bf4189874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556bf8a93abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556bf8a9c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556bf8a84699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556bf8aaf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f571b27e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556bf23a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7ae7603ad676592596ebff1d05b4af2127969360 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5370 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 175671367 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55711aa0d810, 0x55711abf701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55711abf7020,0x55711ca8f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ae7603ad676592596ebff1d05b4af2127969360' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6842 processed earlier; will process 4187 files now Step #5: #1 pulse cov: 3737 ft: 3738 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 3992 ft: 4332 exec/s: 0 rss: 180Mb Step #5: #4 pulse cov: 4292 ft: 5306 exec/s: 0 rss: 182Mb Step #5: ==193396== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571115029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557117b67898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557117b4a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557117b4a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557111508d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557111469b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557111464355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571114fac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571144c9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571144c9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571144c9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571144c9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571144c9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571144c9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571144c9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571144c9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571144c9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571144c9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55711675ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55711348bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557113496be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557113242c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557113242c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557113243738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557113242874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557113242874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557113242874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557117b4cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557117b55928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557117b3d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557117b68112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0e8afbf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557111462b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b117f7f316bfa75a6508799837d5483d72e6c9e9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5371 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 176333682 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55df0a445810, 0x55df0a62f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55df0a62f020,0x55df0c4c70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b117f7f316bfa75a6508799837d5483d72e6c9e9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6847 processed earlier; will process 4182 files now Step #5: ==193432== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55df00f3a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55df0759f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55df075825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55df075824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55df00f40d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55df00ea1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55df00e9c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55df00f32c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55df03f01f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55df03f01f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55df03f01f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55df03f01f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55df03f01f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55df03f01f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55df03f01f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55df03f01f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55df03f01f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55df03f01f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55df06196f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55df02ec3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55df02ecebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55df02c7ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55df02c7ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55df02c7b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55df02c7a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55df02c7a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55df02c7a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55df07584abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55df0758d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55df07575699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55df075a0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd563d7d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55df00e9ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d361188ad004ce707ff743f98e787d60cede2ff1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5372 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 176848863 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5617247fe810, 0x5617249e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5617249e8020,0x5617268800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d361188ad004ce707ff743f98e787d60cede2ff1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6848 processed earlier; will process 4181 files now Step #5: ==193468== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56171b2f39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561721958898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56172193b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56172193b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56171b2f9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56171b25ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56171b255355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56171b2ebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56171e2baf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56171e2baf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56171e2baf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56171e2baf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56171e2baf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56171e2baf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56171e2baf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56171e2baf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56171e2baf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56171e2baf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56172054ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56171d27cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56171d287be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56171d033c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56171d033c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56171d034738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56171d033874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56171d033874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56171d033874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56172193dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561721946928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56172192e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561721959112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9954669082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56171b253b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c38e6e33907b591425de096f694c20de6e1f69c4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5373 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 178108818 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f75888b810, 0x55f758a7501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f758a75020,0x55f75a90d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c38e6e33907b591425de096f694c20de6e1f69c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6849 processed earlier; will process 4180 files now Step #5: ==193504== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f74f3809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f7559e5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7559c85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7559c84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f74f386d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f74f2e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f74f2e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f74f378c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f752347f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f752347f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f752347f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f752347f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f752347f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f752347f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f752347f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f752347f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f752347f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f752347f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f7545dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f751309b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f751314be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f7510c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f7510c0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f7510c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f7510c0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f7510c0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f7510c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f7559caabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f7559d3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f7559bb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f7559e6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5eaebe3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f74f2e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8236df9057a2604b0991a1db104584443a64e624 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5374 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 178754151 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563666d9a810, 0x563666f8401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563666f84020,0x563668e1c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8236df9057a2604b0991a1db104584443a64e624' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6850 processed earlier; will process 4179 files now Step #5: #1 pulse cov: 4500 ft: 4501 exec/s: 0 rss: 178Mb Step #5: ==193540== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56365d88f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563663ef4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563663ed75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563663ed74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56365d895d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56365d7f6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56365d7f1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56365d887c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563660856f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563660856f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563660856f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563660856f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563660856f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563660856f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563660856f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563660856f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563660856f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563660856f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563662aebf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56365f818b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56365f823be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56365f5cfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56365f5cfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56365f5d0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56365f5cf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56365f5cf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56365f5cf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563663ed9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563663ee2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563663eca699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563663ef5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88da848082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56365d7efb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8751f98d00fc3f763b4c56f3dd74c38a5bff927 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5375 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 179335826 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c63de4810, 0x556c63fce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c63fce020,0x556c65e660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8751f98d00fc3f763b4c56f3dd74c38a5bff927' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6852 processed earlier; will process 4177 files now Step #5: #1 pulse cov: 4128 ft: 4129 exec/s: 0 rss: 179Mb Step #5: ==193576== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556c5a8d99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c60f3e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c60f215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c60f214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556c5a8dfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556c5a840b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556c5a83b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556c5a8d1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556c5d8a0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556c5d8a0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556c5d8a0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556c5d8a0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556c5d8a0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556c5d8a0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556c5d8a0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556c5d8a0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556c5d8a0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556c5d8a0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c5fb35f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556c5c862b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556c5c86dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556c5c619c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556c5c619c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556c5c61a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556c5c619874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556c5c619874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556c5c619874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c60f23abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c60f2c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c60f14699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c60f3f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8d1bfbc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556c5a839b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2d3137ed02dcf9ae6dca8f1ec3b80a884d3ceb90 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5376 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 180634705 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564fa0e9f810, 0x564fa108901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564fa1089020,0x564fa2f210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2d3137ed02dcf9ae6dca8f1ec3b80a884d3ceb90' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6854 processed earlier; will process 4175 files now Step #5: ==193612== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564f979949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f9dff9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f9dfdc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f9dfdc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f9799ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f978fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f978f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f9798cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f9a95bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f9a95bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f9a95bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f9a95bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f9a95bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f9a95bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f9a95bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f9a95bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f9a95bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f9a95bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f9cbf0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f9991db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f99928be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f996d4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f996d4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f996d5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f996d4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f996d4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f996d4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f9dfdeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f9dfe7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f9dfcf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f9dffa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f73899d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f978f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f68e3f39fff40ede473d2ede2d82949b151f2efb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5377 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 181902223 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563dbc9f6810, 0x563dbcbe001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563dbcbe0020,0x563dbea780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f68e3f39fff40ede473d2ede2d82949b151f2efb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6855 processed earlier; will process 4174 files now Step #5: #1 pulse cov: 3884 ft: 3885 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 3978 ft: 4208 exec/s: 0 rss: 179Mb Step #5: ==193648== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563db34eb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563db9b50898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563db9b335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563db9b334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563db34f1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563db3452b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563db344d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563db34e3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563db64b2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563db64b2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563db64b2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563db64b2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563db64b2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563db64b2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563db64b2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563db64b2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563db64b2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563db64b2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563db8747f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563db5474b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563db547fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563db522bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563db522bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563db522c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563db522b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563db522b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563db522b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563db9b35abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563db9b3e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563db9b26699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563db9b51112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff3b29bd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563db344bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f85d6da23e3d013d45791c55033a6e1907becefb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5378 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 182513682 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5630c269f810, 0x5630c288901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5630c2889020,0x5630c47210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f85d6da23e3d013d45791c55033a6e1907becefb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6858 processed earlier; will process 4171 files now Step #5: ==193684== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5630b91949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5630bf7f9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5630bf7dc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5630bf7dc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5630b919ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5630b90fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5630b90f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5630b918cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5630bc15bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5630bc15bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5630bc15bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5630bc15bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5630bc15bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5630bc15bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5630bc15bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5630bc15bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5630bc15bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5630bc15bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5630be3f0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5630bb11db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5630bb128be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5630baed4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5630baed4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5630baed5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5630baed4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5630baed4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5630baed4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5630bf7deabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5630bf7e7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5630bf7cf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5630bf7fa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4adb548082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5630b90f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ca1ff30f46b14daf2883bc2106cf55c78dca1751 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5379 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 183071249 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d92d49810, 0x564d92f3301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d92f33020,0x564d94dcb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca1ff30f46b14daf2883bc2106cf55c78dca1751' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6859 processed earlier; will process 4170 files now Step #5: ==193720== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d8983e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d8fea3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d8fe865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d8fe864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d89844d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d897a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d897a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d89836c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d8c805f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d8c805f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d8c805f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d8c805f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d8c805f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d8c805f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d8c805f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d8c805f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d8c805f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d8c805f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d8ea9af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d8b7c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d8b7d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d8b57ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d8b57ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d8b57f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d8b57e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d8b57e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d8b57e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d8fe88abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d8fe91928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d8fe79699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d8fea4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f663284c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d8979eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-93941e235586c372b78291d37f9f188db54906b8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5380 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 183600085 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ce557b810, 0x561ce576501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ce5765020,0x561ce75fd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93941e235586c372b78291d37f9f188db54906b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6860 processed earlier; will process 4169 files now Step #5: ==193756== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561cdc0709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561ce26d5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561ce26b85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561ce26b84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561cdc076d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561cdbfd7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561cdbfd2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561cdc068c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561cdf037f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561cdf037f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561cdf037f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561cdf037f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561cdf037f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561cdf037f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561cdf037f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561cdf037f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561cdf037f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561cdf037f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561ce12ccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561cddff9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561cde004be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561cdddb0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561cdddb0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561cdddb1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561cdddb0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561cdddb0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561cdddb0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561ce26baabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561ce26c3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561ce26ab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561ce26d6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f69ca727082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561cdbfd0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-186b973226524b89f22d23bd1dc4d7f0a4b0c742 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5381 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 184241466 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f6505a5810, 0x55f65078f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f65078f020,0x55f6526270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/186b973226524b89f22d23bd1dc4d7f0a4b0c742' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6861 processed earlier; will process 4168 files now Step #5: ==193792== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f64709a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f64d6ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f64d6e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f64d6e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f6470a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f647001b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f646ffc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f647092c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f64a061f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f64a061f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f64a061f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f64a061f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f64a061f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f64a061f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f64a061f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f64a061f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f64a061f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f64a061f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f64c2f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f649023b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f64902ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f648ddac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f648ddac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f648ddb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f648dda874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f648dda874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f648dda874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f64d6e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f64d6ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f64d6d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f64d700112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f90b62a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f646ffab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-83abf6cb51a51f8629dc5c5ef8b46587a3d62d7b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5382 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 184780030 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e5c033b810, 0x55e5c052501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e5c0525020,0x55e5c23bd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/83abf6cb51a51f8629dc5c5ef8b46587a3d62d7b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6862 processed earlier; will process 4167 files now Step #5: ==193828== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e5b6e309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e5bd495898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e5bd4785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e5bd4784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e5b6e36d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e5b6d97b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e5b6d92355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e5b6e28c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e5b9df7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e5b9df7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e5b9df7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e5b9df7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e5b9df7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e5b9df7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e5b9df7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e5b9df7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e5b9df7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e5b9df7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e5bc08cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e5b8db9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e5b8dc4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e5b8b70c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e5b8b70c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e5b8b71738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e5b8b70874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e5b8b70874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e5b8b70874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e5bd47aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e5bd483928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e5bd46b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e5bd496112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f50ef0a3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e5b6d90b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7315c8543b4c39d15cc3272026ab0eaa666f3e23 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5383 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 185303644 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56512f44f810, 0x56512f63901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56512f639020,0x5651314d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7315c8543b4c39d15cc3272026ab0eaa666f3e23' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6863 processed earlier; will process 4166 files now Step #5: ==193864== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565125f449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56512c5a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56512c58c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56512c58c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565125f4ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565125eabb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565125ea6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565125f3cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565128f0bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565128f0bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565128f0bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565128f0bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565128f0bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565128f0bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565128f0bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565128f0bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565128f0bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565128f0bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56512b1a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565127ecdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565127ed8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565127c84c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565127c84c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565127c85738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565127c84874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565127c84874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565127c84874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56512c58eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56512c597928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56512c57f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56512c5aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdbf9dc6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565125ea4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf3b0c135b3146e3d141790673940828989dd982 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5384 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 185947747 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5613cba7d810, 0x5613cbc6701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5613cbc67020,0x5613cdaff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf3b0c135b3146e3d141790673940828989dd982' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6864 processed earlier; will process 4165 files now Step #5: ==193900== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5613c25729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5613c8bd7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613c8bba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613c8bba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5613c2578d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5613c24d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5613c24d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5613c256ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5613c5539f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5613c5539f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5613c5539f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5613c5539f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5613c5539f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5613c5539f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5613c5539f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5613c5539f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5613c5539f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5613c5539f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5613c77cef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5613c44fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5613c4506be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5613c42b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5613c42b2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5613c42b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5613c42b2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5613c42b2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5613c42b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5613c8bbcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5613c8bc5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5613c8bad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5613c8bd8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2d0bdb6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5613c24d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ca748f1618c3311be04ca4a9cdc15cad4d577427 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5385 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 186478568 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1ae932810, 0x55a1aeb1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1aeb1c020,0x55a1b09b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca748f1618c3311be04ca4a9cdc15cad4d577427' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6865 processed earlier; will process 4164 files now Step #5: #1 pulse cov: 3914 ft: 3915 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4474 ft: 4882 exec/s: 0 rss: 180Mb Step #5: ==193936== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1a54279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1aba8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1aba6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1aba6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1a542dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1a538eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1a5389355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1a541fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1a83eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1a83eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1a83eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1a83eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1a83eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1a83eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1a83eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1a83eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1a83eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1a83eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1aa683f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1a73b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1a73bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1a7167c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1a7167c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1a7168738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1a7167874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1a7167874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1a7167874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a1aba71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a1aba7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1aba62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1aba8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1b19539082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1a5387b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-05533c4ed101a8c9d4cad6092bdd9e1d3af36bc2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5386 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 187204327 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55912ad76810, 0x55912af6001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55912af60020,0x55912cdf80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/05533c4ed101a8c9d4cad6092bdd9e1d3af36bc2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6868 processed earlier; will process 4161 files now Step #5: ==193972== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55912186b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559127ed0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559127eb35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559127eb34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559121871d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5591217d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5591217cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559121863c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559124832f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559124832f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559124832f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559124832f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559124832f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559124832f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559124832f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559124832f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559124832f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559124832f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559126ac7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5591237f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5591237ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5591235abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5591235abc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5591235ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5591235ab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5591235ab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5591235ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559127eb5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559127ebe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559127ea6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559127ed1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7fc7c8a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5591217cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-65762b735bbdfcda02484788fa21cc83f0744d34 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5387 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 187745705 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56285d336810, 0x56285d52001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56285d520020,0x56285f3b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/65762b735bbdfcda02484788fa21cc83f0744d34' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6869 processed earlier; will process 4160 files now Step #5: ==194008== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562853e2b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56285a490898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56285a4735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56285a4734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562853e31d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562853d92b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562853d8d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562853e23c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562856df2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562856df2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562856df2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562856df2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562856df2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562856df2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562856df2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562856df2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562856df2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562856df2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562859087f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562855db4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562855dbfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562855b6bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562855b6bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562855b6c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562855b6b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562855b6b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562855b6b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56285a475abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56285a47e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56285a466699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56285a491112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff405b12082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562853d8bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-da46135c82aa2025e4770a9187022220f74218fd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5388 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 188265605 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5592c7857810, 0x5592c7a4101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5592c7a41020,0x5592c98d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/da46135c82aa2025e4770a9187022220f74218fd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6870 processed earlier; will process 4159 files now Step #5: ==194044== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5592be34c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5592c49b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5592c49945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5592c49944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592be352d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592be2b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592be2ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592be344c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592c1313f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592c1313f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592c1313f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592c1313f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592c1313f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592c1313f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592c1313f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592c1313f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592c1313f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592c1313f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592c35a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592c02d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592c02e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5592c008cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5592c008cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5592c008d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5592c008c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5592c008c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5592c008c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5592c4996abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5592c499f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5592c4987699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5592c49b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27bc801082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592be2acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-221a6ada4d40ea15da11bb31e871aaed42236394 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5389 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 188799527 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555cef280810, 0x555cef46a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555cef46a020,0x555cf13020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/221a6ada4d40ea15da11bb31e871aaed42236394' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6871 processed earlier; will process 4158 files now Step #5: #1 pulse cov: 3851 ft: 3852 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 14965 ft: 15994 exec/s: 0 rss: 201Mb Step #5: ==194080== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555ce5d759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555cec3da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555cec3bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555cec3bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ce5d7bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ce5cdcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ce5cd7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ce5d6dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ce8d3cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ce8d3cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ce8d3cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ce8d3cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ce8d3cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ce8d3cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ce8d3cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ce8d3cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ce8d3cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ce8d3cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555ceafd1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ce7cfeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ce7d09be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ce7ab5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ce7ab5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ce7ab6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ce7ab5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ce7ab5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ce7ab5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555cec3bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555cec3c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555cec3b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555cec3db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8dcceb6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ce5cd5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fabd8f9d13d539c618b01f736cc3bb8578d35a32 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5390 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 189616964 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5595a2297810, 0x5595a248101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5595a2481020,0x5595a43190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fabd8f9d13d539c618b01f736cc3bb8578d35a32' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6875 processed earlier; will process 4154 files now Step #5: ==194116== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559598d8c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55959f3f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55959f3d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55959f3d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559598d92d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559598cf3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559598cee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559598d84c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55959bd53f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55959bd53f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55959bd53f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55959bd53f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55959bd53f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55959bd53f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55959bd53f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55959bd53f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55959bd53f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55959bd53f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55959dfe8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55959ad15b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55959ad20be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55959aaccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55959aaccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55959aacd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55959aacc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55959aacc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55959aacc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55959f3d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55959f3df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55959f3c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55959f3f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2bf5945082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559598cecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-db5a9b64278a3f6d4f354d605296b54d259ee921 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5391 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 190149064 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55591fcca810, 0x55591feb401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55591feb4020,0x555921d4c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/db5a9b64278a3f6d4f354d605296b54d259ee921' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6876 processed earlier; will process 4153 files now Step #5: #1 pulse cov: 4509 ft: 4510 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 5332 ft: 5711 exec/s: 0 rss: 183Mb Step #5: ==194152== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5559167bf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55591ce24898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55591ce075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55591ce074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5559167c5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555916726b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555916721355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5559167b7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555919786f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555919786f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555919786f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555919786f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555919786f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555919786f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555919786f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555919786f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555919786f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555919786f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55591ba1bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555918748b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555918753be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5559184ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5559184ffc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555918500738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5559184ff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5559184ff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5559184ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55591ce09abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55591ce12928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55591cdfa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55591ce25112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5cd1fa7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55591671fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-84dde34fd9734bc47a9961a46272243a6467ccee Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5392 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 190769235 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bfefd23810, 0x55bfeff0d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bfeff0d020,0x55bff1da50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/84dde34fd9734bc47a9961a46272243a6467ccee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6879 processed earlier; will process 4150 files now Step #5: ==194188== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bfe68189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bfece7d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bfece605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bfece604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bfe681ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bfe677fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bfe677a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bfe6810c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bfe97dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bfe97dff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bfe97dff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bfe97dff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bfe97dff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bfe97dff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bfe97dff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bfe97dff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bfe97dff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bfe97dff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bfeba74f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bfe87a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bfe87acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bfe8558c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bfe8558c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bfe8559738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bfe8558874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bfe8558874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bfe8558874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bfece62abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bfece6b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bfece53699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bfece7e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc52dbd0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bfe6778b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf0f310e685520ec2f8b3394bf57d2ef66c39f40 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5393 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 191321392 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560857019810, 0x56085720301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560857203020,0x56085909b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf0f310e685520ec2f8b3394bf57d2ef66c39f40' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6880 processed earlier; will process 4149 files now Step #5: ==194224== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56084db0e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560854173898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608541565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608541564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56084db14d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56084da75b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56084da70355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56084db06c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560850ad5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560850ad5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560850ad5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560850ad5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560850ad5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560850ad5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560850ad5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560850ad5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560850ad5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560850ad5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560852d6af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56084fa97b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56084faa2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56084f84ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56084f84ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56084f84f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56084f84e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56084f84e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56084f84e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560854158abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560854161928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560854149699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560854174112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c5b598082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56084da6eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-caf74ed07c4fc4751bbd3f044deeaa83bedb8055 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5394 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 191841918 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559077108810, 0x5590772f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5590772f2020,0x55907918a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/caf74ed07c4fc4751bbd3f044deeaa83bedb8055' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6881 processed earlier; will process 4148 files now Step #5: #1 pulse cov: 4122 ft: 4123 exec/s: 0 rss: 177Mb Step #5: ==194260== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55906dbfd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559074262898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5590742455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5590742454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55906dc03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55906db64b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55906db5f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55906dbf5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559070bc4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559070bc4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559070bc4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559070bc4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559070bc4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559070bc4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559070bc4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559070bc4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559070bc4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559070bc4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559072e59f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55906fb86b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55906fb91be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55906f93dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55906f93dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55906f93e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55906f93d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55906f93d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55906f93d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559074247abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559074250928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559074238699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559074263112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1431cee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55906db5db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fea9f402b6f5fb26ede514894c1ff073fa4ab387 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5395 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 192404368 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f0f9d20810, 0x55f0f9f0a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f0f9f0a020,0x55f0fbda20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fea9f402b6f5fb26ede514894c1ff073fa4ab387' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6883 processed earlier; will process 4146 files now Step #5: #1 pulse cov: 3899 ft: 3900 exec/s: 0 rss: 177Mb Step #5: ==194296== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f0f08159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f0f6e7a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f0f6e5d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f0f6e5d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f0f081bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f0f077cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f0f0777355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f0f080dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f0f37dcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f0f37dcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f0f37dcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f0f37dcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f0f37dcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f0f37dcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f0f37dcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f0f37dcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f0f37dcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f0f37dcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f0f5a71f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f0f279eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f0f27a9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f0f2555c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f0f2555c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f0f2556738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f0f2555874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f0f2555874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f0f2555874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f0f6e5fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f0f6e68928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f0f6e50699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f0f6e7b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff0bb4dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f0f0775b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4e0641e8c434b29b2a5ee76fed07d0d560d298af Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5396 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 192975377 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d7b28fb810, 0x55d7b2ae501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d7b2ae5020,0x55d7b497d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e0641e8c434b29b2a5ee76fed07d0d560d298af' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6885 processed earlier; will process 4144 files now Step #5: ==194332== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d7a93f09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d7afa55898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7afa385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7afa384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d7a93f6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d7a9357b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d7a9352355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d7a93e8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d7ac3b7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d7ac3b7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d7ac3b7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d7ac3b7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d7ac3b7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d7ac3b7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d7ac3b7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d7ac3b7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d7ac3b7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d7ac3b7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d7ae64cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d7ab379b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d7ab384be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d7ab130c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d7ab130c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d7ab131738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d7ab130874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d7ab130874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d7ab130874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d7afa3aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d7afa43928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d7afa2b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d7afa56112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f82e0aaf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d7a9350b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-12fd70a9b70b6a0940cb1f43ceb075a40ade6779 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5397 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 193521475 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652e9b6f810, 0x5652e9d5901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652e9d59020,0x5652ebbf10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/12fd70a9b70b6a0940cb1f43ceb075a40ade6779' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6886 processed earlier; will process 4143 files now Step #5: #1 pulse cov: 3866 ft: 3867 exec/s: 0 rss: 178Mb Step #5: ==194368== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5652e06649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652e6cc9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652e6cac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652e6cac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5652e066ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5652e05cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5652e05c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5652e065cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5652e362bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5652e362bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5652e362bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5652e362bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5652e362bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5652e362bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5652e362bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5652e362bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5652e362bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5652e362bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652e58c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5652e25edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5652e25f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652e23a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652e23a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652e23a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652e23a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652e23a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652e23a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652e6caeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652e6cb7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652e6c9f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652e6cca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88ae194082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5652e05c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0008f7bc719fbabaddb0ed8395935c961100af3f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5398 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 194531625 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571cd110810, 0x5571cd2fa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571cd2fa020,0x5571cf1920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0008f7bc719fbabaddb0ed8395935c961100af3f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6888 processed earlier; will process 4141 files now Step #5: #1 pulse cov: 3603 ft: 3604 exec/s: 0 rss: 178Mb Step #5: ==194404== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571c3c059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571ca26a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571ca24d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571ca24d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571c3c0bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571c3b6cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571c3b67355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571c3bfdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571c6bccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571c6bccf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571c6bccf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571c6bccf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571c6bccf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571c6bccf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571c6bccf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571c6bccf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571c6bccf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571c6bccf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571c8e61f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571c5b8eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571c5b99be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571c5945c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571c5945c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571c5946738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571c5945874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571c5945874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571c5945874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571ca24fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571ca258928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571ca240699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571ca26b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb27f60b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571c3b65b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c3a4591176c5ce746d3fc48de9d37722e7f97041 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5399 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 195119686 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56010b397810, 0x56010b58101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56010b581020,0x56010d4190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c3a4591176c5ce746d3fc48de9d37722e7f97041' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6890 processed earlier; will process 4139 files now Step #5: ==194440== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560101e8c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601084f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601084d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601084d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560101e92d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560101df3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560101dee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560101e84c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560104e53f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560104e53f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560104e53f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560104e53f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560104e53f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560104e53f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560104e53f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560104e53f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560104e53f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560104e53f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5601070e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560103e15b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560103e20be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560103bccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560103bccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560103bcd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560103bcc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560103bcc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560103bcc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5601084d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5601084df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5601084c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601084f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6159573082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560101decb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2121fb0810e00f97ef040013900523b247225890 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5400 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 195637221 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1ae687810, 0x55a1ae87101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1ae871020,0x55a1b07090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2121fb0810e00f97ef040013900523b247225890' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6891 processed earlier; will process 4138 files now Step #5: ==194476== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1a517c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1ab7e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1ab7c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1ab7c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1a5182d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1a50e3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1a50de355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1a5174c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1a8143f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1a8143f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1a8143f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1a8143f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1a8143f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1a8143f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1a8143f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1a8143f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1a8143f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1a8143f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1aa3d8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1a7105b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1a7110be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1a6ebcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1a6ebcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1a6ebd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1a6ebc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1a6ebc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1a6ebc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a1ab7c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a1ab7cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1ab7b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1ab7e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbad3bcf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1a50dcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0173f398d054bcfe7c0e0fd16ab2971c0e6ef3ef Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5401 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 196276536 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f0fc214810, 0x55f0fc3fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f0fc3fe020,0x55f0fe2960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0173f398d054bcfe7c0e0fd16ab2971c0e6ef3ef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6892 processed earlier; will process 4137 files now Step #5: #1 pulse cov: 4089 ft: 4090 exec/s: 0 rss: 180Mb Step #5: ==194512== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f0f2d099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f0f936e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f0f93515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f0f93514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f0f2d0fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f0f2c70b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f0f2c6b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f0f2d01c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f0f5cd0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f0f5cd0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f0f5cd0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f0f5cd0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f0f5cd0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f0f5cd0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f0f5cd0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f0f5cd0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f0f5cd0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f0f5cd0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f0f7f65f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f0f4c92b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f0f4c9dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f0f4a49c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f0f4a49c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f0f4a4a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f0f4a49874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f0f4a49874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f0f4a49874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f0f9353abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f0f935c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f0f9344699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f0f936f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9b347d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f0f2c69b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f69808a70b07e38a0213f872ac35493536e94559 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5402 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 196838868 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb12969810, 0x55cb12b5301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb12b53020,0x55cb149eb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f69808a70b07e38a0213f872ac35493536e94559' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6894 processed earlier; will process 4135 files now Step #5: ==194548== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cb0945e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb0fac3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb0faa65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb0faa64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb09464d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb093c5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb093c0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb09456c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb0c425f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb0c425f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb0c425f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb0c425f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb0c425f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb0c425f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb0c425f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb0c425f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb0c425f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb0c425f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb0e6baf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb0b3e7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb0b3f2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb0b19ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb0b19ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb0b19f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb0b19e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb0b19e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb0b19e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb0faa8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb0fab1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb0fa99699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb0fac4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7eff6881c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb093beb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-50fa2320a01fa664117fc28b9645bf344ba811aa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5403 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 197375422 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb23daf810, 0x55eb23f9901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb23f99020,0x55eb25e310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/50fa2320a01fa664117fc28b9645bf344ba811aa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6895 processed earlier; will process 4134 files now Step #5: ==194584== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eb1a8a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb20f09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb20eec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb20eec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb1a8aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb1a80bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb1a806355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb1a89cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb1d86bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb1d86bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb1d86bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb1d86bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb1d86bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb1d86bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb1d86bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb1d86bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb1d86bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb1d86bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb1fb00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb1c82db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb1c838be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb1c5e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb1c5e4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb1c5e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb1c5e4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb1c5e4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb1c5e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb20eeeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb20ef7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb20edf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb20f0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ae2eb2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb1a804b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b99e4e08f253a6be627aa1d60f0cd949d4041fde Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5404 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 198046933 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e6ca7ee810, 0x55e6ca9d801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e6ca9d8020,0x55e6cc8700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b99e4e08f253a6be627aa1d60f0cd949d4041fde' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6896 processed earlier; will process 4133 files now Step #5: ==194620== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e6c12e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e6c7948898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e6c792b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e6c792b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e6c12e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e6c124ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e6c1245355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e6c12dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e6c42aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e6c42aaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e6c42aaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e6c42aaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e6c42aaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e6c42aaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e6c42aaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e6c42aaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e6c42aaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e6c42aaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e6c653ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e6c326cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e6c3277be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e6c3023c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e6c3023c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e6c3024738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e6c3023874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e6c3023874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e6c3023874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e6c792dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e6c7936928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e6c791e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e6c7949112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f91c35e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e6c1243b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b13ac1ae91b300e4ae2b8c413fa3645611e85818 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5405 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 198569329 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f5bcecc810, 0x55f5bd0b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f5bd0b6020,0x55f5bef4e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b13ac1ae91b300e4ae2b8c413fa3645611e85818' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6897 processed earlier; will process 4132 files now Step #5: ==194656== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f5b39c19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f5ba026898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f5ba0095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f5ba0094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f5b39c7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f5b3928b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f5b3923355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f5b39b9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f5b6988f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f5b6988f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f5b6988f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f5b6988f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f5b6988f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f5b6988f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f5b6988f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f5b6988f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f5b6988f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f5b6988f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f5b8c1df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f5b594ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f5b5955be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f5b5701c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f5b5701c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f5b5702738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f5b5701874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f5b5701874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f5b5701874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f5ba00babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f5ba014928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f5b9ffc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f5ba027112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f695cb2c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f5b3921b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9812922012f649f68106602b1e498001f120074e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5406 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 199107374 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1dbfb9810, 0x55d1dc1a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1dc1a3020,0x55d1de03b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9812922012f649f68106602b1e498001f120074e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6898 processed earlier; will process 4131 files now Step #5: #1 pulse cov: 4020 ft: 4021 exec/s: 0 rss: 178Mb Step #5: ==194692== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d1d2aae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1d9113898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1d90f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1d90f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1d2ab4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1d2a15b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1d2a10355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1d2aa6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1d5a75f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1d5a75f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1d5a75f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1d5a75f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1d5a75f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1d5a75f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1d5a75f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1d5a75f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1d5a75f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1d5a75f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1d7d0af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1d4a37b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1d4a42be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1d47eec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1d47eec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1d47ef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1d47ee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1d47ee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1d47ee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1d90f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1d9101928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1d90e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1d9114112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd7a8a00082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1d2a0eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-23dc2b3ad2eeb59b2adc3b579201aeebfde3b707 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5407 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 199663341 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561012b98810, 0x561012d8201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561012d82020,0x561014c1a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/23dc2b3ad2eeb59b2adc3b579201aeebfde3b707' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6900 processed earlier; will process 4129 files now Step #5: ==194728== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56100968d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56100fcf2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56100fcd55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56100fcd54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561009693d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610095f4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610095ef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561009685c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56100c654f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56100c654f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56100c654f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56100c654f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56100c654f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56100c654f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56100c654f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56100c654f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56100c654f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56100c654f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56100e8e9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56100b616b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56100b621be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56100b3cdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56100b3cdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56100b3ce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56100b3cd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56100b3cd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56100b3cd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56100fcd7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56100fce0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56100fcc8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56100fcf3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f772e498082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610095edb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-06bb8aa1b6a521236d70740432ce63a7949570aa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5408 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 200189146 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5628751fe810, 0x5628753e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5628753e8020,0x5628772800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/06bb8aa1b6a521236d70740432ce63a7949570aa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6901 processed earlier; will process 4128 files now Step #5: ==194764== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56286bcf39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562872358898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56287233b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56287233b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56286bcf9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56286bc5ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56286bc55355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56286bcebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56286ecbaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56286ecbaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56286ecbaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56286ecbaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56286ecbaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56286ecbaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56286ecbaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56286ecbaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56286ecbaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56286ecbaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562870f4ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56286dc7cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56286dc87be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56286da33c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56286da33c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56286da34738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56286da33874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56286da33874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56286da33874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56287233dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562872346928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56287232e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562872359112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6a7df50082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56286bc53b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7d11288e26971e237407ae791d5381f1d45c1d30 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5409 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 200713163 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55612bc0f810, 0x55612bdf901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55612bdf9020,0x55612dc910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d11288e26971e237407ae791d5381f1d45c1d30' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6902 processed earlier; will process 4127 files now Step #5: #1 pulse cov: 4294 ft: 4295 exec/s: 0 rss: 178Mb Step #5: ==194800== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5561227049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556128d69898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556128d4c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556128d4c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55612270ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55612266bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556122666355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5561226fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5561256cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5561256cbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5561256cbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5561256cbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5561256cbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5561256cbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5561256cbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5561256cbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5561256cbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5561256cbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556127960f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55612468db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556124698be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556124444c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556124444c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556124445738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556124444874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556124444874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556124444874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556128d4eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556128d57928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556128d3f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556128d6a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f43c9b0b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556122664b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-edd692a427e1fdace6f569e3ecc20d87a226d92a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5410 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 201276295 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d69657810, 0x562d6984101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d69841020,0x562d6b6d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/edd692a427e1fdace6f569e3ecc20d87a226d92a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6904 processed earlier; will process 4125 files now Step #5: ==194836== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562d6014c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d667b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d667945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d667944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d60152d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d600b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d600ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d60144c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d63113f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d63113f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d63113f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d63113f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d63113f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d63113f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d63113f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d63113f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d63113f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d63113f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d653a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d620d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d620e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d61e8cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d61e8cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d61e8d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d61e8c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d61e8c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d61e8c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d66796abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d6679f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d66787699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d667b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f46db251082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d600acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ef5aaf7aae417fef2c31b6fc2c89135534cbc409 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5411 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 201800935 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562efcd6b810, 0x562efcf5501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562efcf55020,0x562efeded0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ef5aaf7aae417fef2c31b6fc2c89135534cbc409' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6905 processed earlier; will process 4124 files now Step #5: ==194872== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562ef38609c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ef9ec5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ef9ea85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ef9ea84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562ef3866d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562ef37c7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562ef37c2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562ef3858c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ef6827f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ef6827f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ef6827f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ef6827f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ef6827f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ef6827f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ef6827f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ef6827f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ef6827f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ef6827f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ef8abcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ef57e9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ef57f4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ef55a0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ef55a0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ef55a1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ef55a0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ef55a0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ef55a0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ef9eaaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ef9eb3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ef9e9b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ef9ec6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4bffad9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562ef37c0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-04ded6e2ecffefa70b72e60b76864da94397a237 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5412 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 202344793 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5608b0b68810, 0x5608b0d5201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5608b0d52020,0x5608b2bea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/04ded6e2ecffefa70b72e60b76864da94397a237' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6906 processed earlier; will process 4123 files now Step #5: #1 pulse cov: 4153 ft: 4154 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4842 ft: 5237 exec/s: 0 rss: 179Mb Step #5: #4 pulse cov: 5184 ft: 6434 exec/s: 0 rss: 181Mb Step #5: ==194908== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5608a765d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5608adcc2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608adca55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608adca54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5608a7663d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5608a75c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5608a75bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5608a7655c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5608aa624f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5608aa624f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5608aa624f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5608aa624f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5608aa624f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5608aa624f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5608aa624f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5608aa624f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5608aa624f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5608aa624f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608ac8b9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5608a95e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5608a95f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5608a939dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5608a939dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5608a939e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5608a939d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5608a939d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5608a939d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5608adca7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5608adcb0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5608adc98699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5608adcc3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0c2c319082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5608a75bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6597113020b6ff52ca898de9acc8953e5d43c707 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5413 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 203011098 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557c0f51d810, 0x557c0f70701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557c0f707020,0x557c1159f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6597113020b6ff52ca898de9acc8953e5d43c707' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6911 processed earlier; will process 4118 files now Step #5: ==194944== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557c060129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557c0c677898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557c0c65a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557c0c65a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557c06018d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557c05f79b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557c05f74355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557c0600ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557c08fd9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557c08fd9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557c08fd9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557c08fd9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557c08fd9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557c08fd9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557c08fd9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557c08fd9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557c08fd9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557c08fd9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557c0b26ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557c07f9bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557c07fa6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557c07d52c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557c07d52c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557c07d53738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557c07d52874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557c07d52874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557c07d52874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557c0c65cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557c0c665928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557c0c64d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557c0c678112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f58dbc03082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557c05f72b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-beaa6923bb07eac9bd9bb416405bf560fcfb9e8d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5414 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 203539000 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bfb667b810, 0x55bfb686501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bfb6865020,0x55bfb86fd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/beaa6923bb07eac9bd9bb416405bf560fcfb9e8d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6912 processed earlier; will process 4117 files now Step #5: ==194980== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bfad1709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bfb37d5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bfb37b85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bfb37b84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bfad176d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bfad0d7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bfad0d2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bfad168c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bfb0137f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bfb0137f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bfb0137f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bfb0137f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bfb0137f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bfb0137f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bfb0137f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bfb0137f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bfb0137f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bfb0137f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bfb23ccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bfaf0f9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bfaf104be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bfaeeb0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bfaeeb0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bfaeeb1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bfaeeb0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bfaeeb0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bfaeeb0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bfb37baabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bfb37c3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bfb37ab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bfb37d6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f04ff5d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bfad0d0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-376bf6a4164de6044a6c94f9c004e9c2edc3d067 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5415 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 204042912 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c60aa7a810, 0x55c60ac6401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c60ac64020,0x55c60cafc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/376bf6a4164de6044a6c94f9c004e9c2edc3d067' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6913 processed earlier; will process 4116 files now Step #5: ==195016== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c60156f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c607bd4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c607bb75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c607bb74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c601575d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6014d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6014d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c601567c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c604536f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c604536f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c604536f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c604536f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c604536f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c604536f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c604536f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c604536f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c604536f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c604536f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c6067cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6034f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c603503be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6032afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6032afc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6032b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6032af874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6032af874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6032af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c607bb9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c607bc2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c607baa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c607bd5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f174da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6014cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-581e457aeb68d8b0b6135afe91ace6eeb456ae52 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5416 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 204565640 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56069c3e5810, 0x56069c5cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56069c5cf020,0x56069e4670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/581e457aeb68d8b0b6135afe91ace6eeb456ae52' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6914 processed earlier; will process 4115 files now Step #5: ==195052== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560692eda9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56069953f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606995225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606995224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560692ee0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560692e41b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560692e3c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560692ed2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560695ea1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560695ea1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560695ea1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560695ea1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560695ea1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560695ea1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560695ea1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560695ea1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560695ea1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560695ea1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560698136f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560694e63b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560694e6ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560694c1ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560694c1ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560694c1b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560694c1a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560694c1a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560694c1a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560699524abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56069952d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560699515699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560699540112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff4583ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560692e3ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5e9d7190190479ff4b007d0a22d31f3a33903399 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5417 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 205109895 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561f0337f810, 0x561f0356901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561f03569020,0x561f054010e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e9d7190190479ff4b007d0a22d31f3a33903399' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6915 processed earlier; will process 4114 files now Step #5: ==195088== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561ef9e749c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561f004d9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561f004bc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561f004bc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561ef9e7ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561ef9ddbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561ef9dd6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561ef9e6cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561efce3bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561efce3bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561efce3bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561efce3bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561efce3bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561efce3bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561efce3bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561efce3bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561efce3bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561efce3bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561eff0d0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561efbdfdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561efbe08be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561efbbb4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561efbbb4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561efbbb5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561efbbb4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561efbbb4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561efbbb4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561f004beabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561f004c7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561f004af699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561f004da112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f92ce3e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561ef9dd4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bac35ad5c828197ca6ca442545461a856ead3a22 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5418 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 205756711 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56527c2d4810, 0x56527c4be01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56527c4be020,0x56527e3560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bac35ad5c828197ca6ca442545461a856ead3a22' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6916 processed earlier; will process 4113 files now Step #5: #1 pulse cov: 3896 ft: 3897 exec/s: 0 rss: 180Mb Step #5: ==195124== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565272dc99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56527942e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652794115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652794114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565272dcfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565272d30b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565272d2b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565272dc1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565275d90f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565275d90f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565275d90f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565275d90f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565275d90f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565275d90f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565275d90f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565275d90f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565275d90f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565275d90f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565278025f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565274d52b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565274d5dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565274b09c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565274b09c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565274b0a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565274b09874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565274b09874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565274b09874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565279413abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56527941c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565279404699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56527942f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f45023e0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565272d29b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-140dde969c5d1b0b1153cb4b3fec0807d8244e0f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5419 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 206295531 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dbd1057810, 0x55dbd124101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dbd1241020,0x55dbd30d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/140dde969c5d1b0b1153cb4b3fec0807d8244e0f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6918 processed earlier; will process 4111 files now Step #5: #1 pulse cov: 12545 ft: 12546 exec/s: 0 rss: 197Mb Step #5: ==195160== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dbc7b4c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dbce1b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dbce1945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dbce1944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dbc7b52d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dbc7ab3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dbc7aae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dbc7b44c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dbcab13f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dbcab13f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dbcab13f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dbcab13f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dbcab13f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dbcab13f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dbcab13f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dbcab13f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dbcab13f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dbcab13f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dbccda8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dbc9ad5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dbc9ae0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dbc988cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dbc988cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dbc988d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dbc988c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dbc988c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dbc988c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dbce196abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dbce19f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dbce187699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dbce1b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f18a6f27082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dbc7aacb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4e9f97bef3e43ce07495a6e7d3d77e5141ce3ff2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5420 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 206902226 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b1ca746810, 0x55b1ca93001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b1ca930020,0x55b1cc7c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e9f97bef3e43ce07495a6e7d3d77e5141ce3ff2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6920 processed earlier; will process 4109 files now Step #5: #1 pulse cov: 3758 ft: 3759 exec/s: 0 rss: 179Mb Step #5: ==195196== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b1c123b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b1c78a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1c78835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1c78834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b1c1241d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b1c11a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b1c119d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b1c1233c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b1c4202f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b1c4202f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b1c4202f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b1c4202f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b1c4202f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b1c4202f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b1c4202f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b1c4202f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b1c4202f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b1c4202f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b1c6497f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b1c31c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b1c31cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b1c2f7bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b1c2f7bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b1c2f7c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b1c2f7b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b1c2f7b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b1c2f7b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b1c7885abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b1c788e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b1c7876699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b1c78a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a68b8c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b1c119bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-92cffc70148790a56ccbaa2187b26cd2ddedf03c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5421 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 207478044 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f14415c810, 0x55f14434601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f144346020,0x55f1461de0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92cffc70148790a56ccbaa2187b26cd2ddedf03c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6922 processed earlier; will process 4107 files now Step #5: #1 pulse cov: 4425 ft: 4426 exec/s: 0 rss: 179Mb Step #5: ==195232== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f13ac519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f1412b6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1412995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1412994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f13ac57d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f13abb8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f13abb3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f13ac49c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f13dc18f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f13dc18f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f13dc18f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f13dc18f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f13dc18f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f13dc18f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f13dc18f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f13dc18f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f13dc18f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f13dc18f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f13feadf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f13cbdab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f13cbe5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f13c991c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f13c991c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f13c992738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f13c991874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f13c991874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f13c991874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f14129babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f1412a4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f14128c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f1412b7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8cd1391082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f13abb1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e41ff26e2f06f63f7baee23c93cf2f19ef9695e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5422 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 208052574 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56503c797810, 0x56503c98101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56503c981020,0x56503e8190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e41ff26e2f06f63f7baee23c93cf2f19ef9695e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6924 processed earlier; will process 4105 files now Step #5: #1 pulse cov: 11552 ft: 11553 exec/s: 0 rss: 197Mb Step #5: ==195268== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56503328c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5650398f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5650398d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5650398d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565033292d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5650331f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5650331ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565033284c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565036253f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565036253f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565036253f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565036253f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565036253f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565036253f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565036253f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565036253f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565036253f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565036253f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5650384e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565035215b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565035220be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565034fccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565034fccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565034fcd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565034fcc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565034fcc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565034fcc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5650398d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5650398df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5650398c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5650398f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb6bf736082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5650331ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-045b268065074abb886082494a8034c3d57631cc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5423 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 208644009 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563936efc810, 0x5639370e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5639370e6020,0x563938f7e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/045b268065074abb886082494a8034c3d57631cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6926 processed earlier; will process 4103 files now Step #5: ==195305== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56392d9f19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563934056898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5639340395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5639340394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56392d9f7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56392d958b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56392d953355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56392d9e9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5639309b8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5639309b8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5639309b8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5639309b8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5639309b8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5639309b8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5639309b8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5639309b8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5639309b8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5639309b8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563932c4df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56392f97ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56392f985be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56392f731c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56392f731c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56392f732738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56392f731874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56392f731874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56392f731874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56393403babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563934044928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56393402c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563934057112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fea09b4f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56392d951b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-524d0e9d0ff9e874ecb8bcd97965aa96e3658660 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5424 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 209282830 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b84a53810, 0x555b84c3d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b84c3d020,0x555b86ad50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/524d0e9d0ff9e874ecb8bcd97965aa96e3658660' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6927 processed earlier; will process 4102 files now Step #5: ==195342== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555b7b5489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b81bad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b81b905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b81b904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b7b54ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b7b4afb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b7b4aa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b7b540c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b7e50ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b7e50ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b7e50ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b7e50ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b7e50ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b7e50ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b7e50ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b7e50ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b7e50ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b7e50ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b807a4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b7d4d1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b7d4dcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b7d288c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b7d288c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b7d289738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b7d288874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b7d288874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b7d288874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b81b92abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b81b9b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b81b83699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b81bae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7603548082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b7b4a8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-573b22681375af98762132b4cfce21d301a047a0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5425 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 209807686 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5616d1ea9810, 0x5616d209301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5616d2093020,0x5616d3f2b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/573b22681375af98762132b4cfce21d301a047a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6928 processed earlier; will process 4101 files now Step #5: ==195378== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5616c899e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5616cf003898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5616cefe65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5616cefe64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5616c89a4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5616c8905b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5616c8900355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5616c8996c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5616cb965f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5616cb965f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5616cb965f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5616cb965f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5616cb965f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5616cb965f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5616cb965f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5616cb965f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5616cb965f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5616cb965f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5616cdbfaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5616ca927b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5616ca932be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5616ca6dec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5616ca6dec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5616ca6df738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5616ca6de874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5616ca6de874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5616ca6de874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5616cefe8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5616ceff1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5616cefd9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5616cf004112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ed8d98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5616c88feb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0fe387cb67295b90b19451c8387180e201bb8e2c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5426 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 210369776 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557fa7d83810, 0x557fa7f6d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557fa7f6d020,0x557fa9e050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0fe387cb67295b90b19451c8387180e201bb8e2c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6929 processed earlier; will process 4100 files now Step #5: ==195414== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557f9e8789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557fa4edd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557fa4ec05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557fa4ec04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f9e87ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f9e7dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f9e7da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f9e870c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557fa183ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557fa183ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557fa183ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557fa183ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557fa183ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557fa183ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557fa183ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557fa183ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557fa183ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557fa183ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557fa3ad4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557fa0801b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557fa080cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557fa05b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557fa05b8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557fa05b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557fa05b8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557fa05b8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557fa05b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557fa4ec2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557fa4ecb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557fa4eb3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557fa4ede112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f04ccbc8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f9e7d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1b86f7361078f916a4b15c614d4f5d8e9a6ed321 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5427 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 210999003 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bd9a9cf810, 0x55bd9abb901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bd9abb9020,0x55bd9ca510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b86f7361078f916a4b15c614d4f5d8e9a6ed321' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6930 processed earlier; will process 4099 files now Step #5: ==195450== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bd914c49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bd97b29898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bd97b0c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bd97b0c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bd914cad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bd9142bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bd91426355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bd914bcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bd9448bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bd9448bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bd9448bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bd9448bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bd9448bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bd9448bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bd9448bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bd9448bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bd9448bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bd9448bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bd96720f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bd9344db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bd93458be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bd93204c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bd93204c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bd93205738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bd93204874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bd93204874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bd93204874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bd97b0eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bd97b17928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bd97aff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bd97b2a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fab4c7ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bd91424b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f6c5b90973857d22b3ef43e43f8656f6e29501f6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5428 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 211522099 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564de055b810, 0x564de074501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564de0745020,0x564de25dd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f6c5b90973857d22b3ef43e43f8656f6e29501f6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6931 processed earlier; will process 4098 files now Step #5: #1 pulse cov: 3557 ft: 3558 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 3742 ft: 3873 exec/s: 0 rss: 178Mb Step #5: ==195488== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564dd70509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564ddd6b5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564ddd6985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564ddd6984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564dd7056d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564dd6fb7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564dd6fb2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564dd7048c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564dda017f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564dda017f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564dda017f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564dda017f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564dda017f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564dda017f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564dda017f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564dda017f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564dda017f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564dda017f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564ddc2acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564dd8fd9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564dd8fe4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564dd8d90c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564dd8d90c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564dd8d91738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564dd8d90874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564dd8d90874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564dd8d90874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564ddd69aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564ddd6a3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564ddd68b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564ddd6b6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3aa70dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564dd6fb0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-54b8d89389437d9224c6306862c7af66d8908176 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5429 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 212134179 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55719bba0810, 0x55719bd8a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55719bd8a020,0x55719dc220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/54b8d89389437d9224c6306862c7af66d8908176' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6934 processed earlier; will process 4095 files now Step #5: ==195550== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571926959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557198cfa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557198cdd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557198cdd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55719269bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571925fcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571925f7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55719268dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55719565cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55719565cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55719565cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55719565cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55719565cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55719565cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55719565cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55719565cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55719565cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55719565cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571978f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55719461eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557194629be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571943d5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571943d5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571943d6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571943d5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571943d5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571943d5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557198cdfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557198ce8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557198cd0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557198cfb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9d4503c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571925f5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a8f1b2697f7a8bee4b5afff0c08baff364848a7c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5430 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 212774651 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55578fd00810, 0x55578feea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55578feea020,0x555791d820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a8f1b2697f7a8bee4b5afff0c08baff364848a7c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6935 processed earlier; will process 4094 files now Step #5: ==195586== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5557867f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55578ce5a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55578ce3d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55578ce3d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557867fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55578675cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555786757355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557867edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557897bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557897bcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557897bcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557897bcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557897bcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557897bcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557897bcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557897bcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557897bcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557897bcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55578ba51f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55578877eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555788789be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555788535c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555788535c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555788536738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555788535874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555788535874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555788535874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55578ce3fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55578ce48928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55578ce30699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55578ce5b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff7dfb28082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555786755b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0c6abfb2aa665744464417a86f33fcf24ae62d96 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5431 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 213322379 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea11d61810, 0x55ea11f4b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea11f4b020,0x55ea13de30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0c6abfb2aa665744464417a86f33fcf24ae62d96' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6936 processed earlier; will process 4093 files now Step #5: #1 pulse cov: 16679 ft: 16680 exec/s: 0 rss: 208Mb Step #5: ==195622== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ea088569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea0eebb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea0ee9e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea0ee9e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea0885cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea087bdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea087b8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea0884ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea0b81df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea0b81df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea0b81df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea0b81df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea0b81df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea0b81df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea0b81df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea0b81df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea0b81df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea0b81df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea0dab2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea0a7dfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea0a7eabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea0a596c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea0a596c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea0a597738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea0a596874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea0a596874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea0a596874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea0eea0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea0eea9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea0ee91699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea0eebc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe2bfd49082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea087b6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-669be7aa1399f23230c0308981223a34b22196fb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5432 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 214071448 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dc2fcec810, 0x55dc2fed601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dc2fed6020,0x55dc31d6e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/669be7aa1399f23230c0308981223a34b22196fb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6938 processed earlier; will process 4091 files now Step #5: ==195658== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dc267e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dc2ce46898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dc2ce295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dc2ce294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dc267e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dc26748b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dc26743355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dc267d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dc297a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dc297a8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dc297a8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dc297a8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dc297a8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dc297a8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dc297a8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dc297a8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dc297a8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dc297a8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dc2ba3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dc2876ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dc28775be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dc28521c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dc28521c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dc28522738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dc28521874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dc28521874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dc28521874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dc2ce2babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dc2ce34928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dc2ce1c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dc2ce47112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf99901082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dc26741b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b217caf9f449a710afcff85826eaa51d2e0d6fc9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5433 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 214705149 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5589c5143810, 0x5589c532d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5589c532d020,0x5589c71c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b217caf9f449a710afcff85826eaa51d2e0d6fc9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6939 processed earlier; will process 4090 files now Step #5: ==195694== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5589bbc389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5589c229d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589c22805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589c22804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5589bbc3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5589bbb9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5589bbb9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5589bbc30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5589bebfff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5589bebfff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5589bebfff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5589bebfff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5589bebfff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5589bebfff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5589bebfff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5589bebfff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5589bebfff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5589bebfff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589c0e94f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5589bdbc1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5589bdbccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5589bd978c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5589bd978c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5589bd979738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5589bd978874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5589bd978874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5589bd978874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5589c2282abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5589c228b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5589c2273699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5589c229e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d28be7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5589bbb98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3df8ea4b3af5158c9ae9216bb68f08602ed82db1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5434 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 215242849 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b73ec3810, 0x557b740ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b740ad020,0x557b75f450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3df8ea4b3af5158c9ae9216bb68f08602ed82db1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6940 processed earlier; will process 4089 files now Step #5: ==195730== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557b6a9b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b7101d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b710005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b710004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b6a9bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b6a91fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b6a91a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b6a9b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b6d97ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b6d97ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b6d97ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b6d97ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b6d97ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b6d97ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b6d97ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b6d97ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b6d97ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b6d97ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b6fc14f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b6c941b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b6c94cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b6c6f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b6c6f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b6c6f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b6c6f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b6c6f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b6c6f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b71002abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b7100b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b70ff3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b7101e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe455744082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b6a918b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7fb01f122668cb236c1c9cc81a596172ac8a47b8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5435 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 215795278 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56186b546810, 0x56186b73001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56186b730020,0x56186d5c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7fb01f122668cb236c1c9cc81a596172ac8a47b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6941 processed earlier; will process 4088 files now Step #5: ==195766== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56186203b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5618686a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5618686835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5618686834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561862041d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561861fa2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561861f9d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561862033c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561865002f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561865002f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561865002f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561865002f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561865002f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561865002f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561865002f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561865002f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561865002f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561865002f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561867297f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561863fc4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561863fcfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561863d7bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561863d7bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561863d7c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561863d7b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561863d7b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561863d7b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561868685abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56186868e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561868676699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5618686a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8de62c2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561861f9bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-adeac2e9c487cf5290fb4026b5c5b6829d4923cc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5436 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 216324916 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564fcc6bd810, 0x564fcc8a701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564fcc8a7020,0x564fce73f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/adeac2e9c487cf5290fb4026b5c5b6829d4923cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6942 processed earlier; will process 4087 files now Step #5: ==195802== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564fc31b29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564fc9817898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564fc97fa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564fc97fa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564fc31b8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564fc3119b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564fc3114355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564fc31aac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564fc6179f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564fc6179f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564fc6179f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564fc6179f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564fc6179f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564fc6179f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564fc6179f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564fc6179f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564fc6179f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564fc6179f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564fc840ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564fc513bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564fc5146be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564fc4ef2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564fc4ef2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564fc4ef3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564fc4ef2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564fc4ef2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564fc4ef2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564fc97fcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564fc9805928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564fc97ed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564fc9818112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9e39aa9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564fc3112b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e3f07e8c6e1568b9de188899ce0e8e9461333893 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5437 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 217333120 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ba2dd57810, 0x55ba2df4101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ba2df41020,0x55ba2fdd90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e3f07e8c6e1568b9de188899ce0e8e9461333893' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6943 processed earlier; will process 4086 files now Step #5: #1 pulse cov: 3780 ft: 3781 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4547 ft: 5020 exec/s: 0 rss: 179Mb Step #5: ==195838== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ba2484c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ba2aeb1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ba2ae945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ba2ae944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ba24852d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ba247b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ba247ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ba24844c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ba27813f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ba27813f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ba27813f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ba27813f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ba27813f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ba27813f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ba27813f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ba27813f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ba27813f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ba27813f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ba29aa8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ba267d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ba267e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ba2658cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ba2658cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ba2658d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ba2658c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ba2658c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ba2658c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ba2ae96abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ba2ae9f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ba2ae87699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ba2aeb2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a0370e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ba247acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-31f3a7e0fc22ec5217bfe9d5a3a63c14f3f371e0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5438 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 217954937 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ac85914810, 0x55ac85afe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ac85afe020,0x55ac879960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/31f3a7e0fc22ec5217bfe9d5a3a63c14f3f371e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6946 processed earlier; will process 4083 files now Step #5: ==195874== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ac7c4099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ac82a6e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ac82a515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ac82a514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ac7c40fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ac7c370b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ac7c36b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ac7c401c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ac7f3d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ac7f3d0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ac7f3d0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ac7f3d0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ac7f3d0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ac7f3d0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ac7f3d0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ac7f3d0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ac7f3d0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ac7f3d0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ac81665f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ac7e392b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ac7e39dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ac7e149c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ac7e149c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ac7e14a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ac7e149874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ac7e149874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ac7e149874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ac82a53abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ac82a5c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ac82a44699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ac82a6f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f43d1239082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ac7c369b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c0a2885677addabaa5981ad8fb19ffa7e0a0d41f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5439 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 218477525 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5628e633b810, 0x5628e652501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5628e6525020,0x5628e83bd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c0a2885677addabaa5981ad8fb19ffa7e0a0d41f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6947 processed earlier; will process 4082 files now Step #5: ==195910== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5628dce309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5628e3495898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5628e34785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5628e34784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5628dce36d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5628dcd97b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5628dcd92355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5628dce28c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5628dfdf7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5628dfdf7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5628dfdf7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5628dfdf7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5628dfdf7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5628dfdf7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5628dfdf7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5628dfdf7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5628dfdf7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5628dfdf7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5628e208cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5628dedb9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5628dedc4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5628deb70c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5628deb70c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5628deb71738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5628deb70874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5628deb70874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5628deb70874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5628e347aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5628e3483928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5628e346b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5628e3496112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e432fb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5628dcd90b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-531391c9477240449420c0c29e36fbec50676395 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5440 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 219004064 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55972565b810, 0x55972584501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559725845020,0x5597276dd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/531391c9477240449420c0c29e36fbec50676395' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6948 processed earlier; will process 4081 files now Step #5: ==195946== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55971c1509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5597227b5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5597227985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5597227984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55971c156d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55971c0b7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55971c0b2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55971c148c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55971f117f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55971f117f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55971f117f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55971f117f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55971f117f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55971f117f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55971f117f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55971f117f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55971f117f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55971f117f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5597213acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55971e0d9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55971e0e4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55971de90c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55971de90c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55971de91738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55971de90874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55971de90874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55971de90874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55972279aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5597227a3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55972278b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5597227b6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1b2b69e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55971c0b0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3d8070a8f83b210d3a0b76a05ca12ea5ce85554f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5441 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 219533086 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5599bc4a4810, 0x5599bc68e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5599bc68e020,0x5599be5260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3d8070a8f83b210d3a0b76a05ca12ea5ce85554f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6949 processed earlier; will process 4080 files now Step #5: #1 pulse cov: 4301 ft: 4302 exec/s: 0 rss: 182Mb Step #5: ==195982== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5599b2f999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5599b95fe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5599b95e15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5599b95e14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5599b2f9fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5599b2f00b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5599b2efb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5599b2f91c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5599b5f60f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5599b5f60f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5599b5f60f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5599b5f60f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5599b5f60f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5599b5f60f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5599b5f60f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5599b5f60f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5599b5f60f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5599b5f60f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5599b81f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5599b4f22b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5599b4f2dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5599b4cd9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5599b4cd9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5599b4cda738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5599b4cd9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5599b4cd9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5599b4cd9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5599b95e3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5599b95ec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5599b95d4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5599b95ff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd7ad583082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5599b2ef9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-21c075676f46215808859110f0b0cf1324723c11 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5442 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 220098730 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559cdf067810, 0x559cdf25101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559cdf251020,0x559ce10e90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/21c075676f46215808859110f0b0cf1324723c11' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6951 processed earlier; will process 4078 files now Step #5: ==196018== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559cd5b5c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559cdc1c1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559cdc1a45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559cdc1a44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559cd5b62d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559cd5ac3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559cd5abe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559cd5b54c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559cd8b23f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559cd8b23f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559cd8b23f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559cd8b23f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559cd8b23f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559cd8b23f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559cd8b23f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559cd8b23f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559cd8b23f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559cd8b23f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559cdadb8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559cd7ae5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559cd7af0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559cd789cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559cd789cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559cd789d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559cd789c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559cd789c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559cd789c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559cdc1a6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559cdc1af928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559cdc197699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559cdc1c2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe0022f8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559cd5abcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f853cf4abca0ecd8e48f033a28e0863a9fa2a89e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5443 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 220620251 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f5a4842810, 0x55f5a4a2c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f5a4a2c020,0x55f5a68c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f853cf4abca0ecd8e48f033a28e0863a9fa2a89e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6952 processed earlier; will process 4077 files now Step #5: #1 pulse cov: 4282 ft: 4283 exec/s: 0 rss: 179Mb Step #5: ==196054== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f59b3379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f5a199c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f5a197f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f5a197f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f59b33dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f59b29eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f59b299355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f59b32fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f59e2fef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f59e2fef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f59e2fef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f59e2fef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f59e2fef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f59e2fef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f59e2fef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f59e2fef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f59e2fef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f59e2fef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f5a0593f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f59d2c0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f59d2cbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f59d077c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f59d077c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f59d078738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f59d077874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f59d077874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f59d077874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f5a1981abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f5a198a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f5a1972699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f5a199d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc58a8f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f59b297b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-53ab4638f64885fc98630800c6a03503717b2cda Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5444 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 221197559 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55774e3d3810, 0x55774e5bd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55774e5bd020,0x5577504550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/53ab4638f64885fc98630800c6a03503717b2cda' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6954 processed earlier; will process 4075 files now Step #5: ==196090== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557744ec89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55774b52d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55774b5105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55774b5104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557744eced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557744e2fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557744e2a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557744ec0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557747e8ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557747e8ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557747e8ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557747e8ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557747e8ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557747e8ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557747e8ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557747e8ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557747e8ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557747e8ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55774a124f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557746e51b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557746e5cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557746c08c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557746c08c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557746c09738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557746c08874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557746c08874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557746c08874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55774b512abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55774b51b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55774b503699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55774b52e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f07e9e3e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557744e28b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9b738b5e81e6520d31b2741b0c91075cc79ca72f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5445 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 221723034 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55da787de810, 0x55da789c801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55da789c8020,0x55da7a8600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9b738b5e81e6520d31b2741b0c91075cc79ca72f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6955 processed earlier; will process 4074 files now Step #5: ==196126== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55da6f2d39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55da75938898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55da7591b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55da7591b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55da6f2d9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55da6f23ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55da6f235355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55da6f2cbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55da7229af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55da7229af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55da7229af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55da7229af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55da7229af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55da7229af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55da7229af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55da7229af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55da7229af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55da7229af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55da7452ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55da7125cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55da71267be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55da71013c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55da71013c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55da71014738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55da71013874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55da71013874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55da71013874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55da7591dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55da75926928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55da7590e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55da75939112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4280173082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55da6f233b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5c8c28ba27959f6595cafd610364b19ea8f5e2ba Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5446 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 222371756 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558e7ab20810, 0x558e7ad0a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558e7ad0a020,0x558e7cba20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c8c28ba27959f6595cafd610364b19ea8f5e2ba' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6956 processed earlier; will process 4073 files now Step #5: ==196162== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558e716159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558e77c7a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558e77c5d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558e77c5d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558e7161bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558e7157cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558e71577355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558e7160dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558e745dcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558e745dcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558e745dcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558e745dcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558e745dcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558e745dcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558e745dcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558e745dcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558e745dcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558e745dcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558e76871f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558e7359eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558e735a9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558e73355c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558e73355c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558e73356738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558e73355874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558e73355874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558e73355874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558e77c5fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558e77c68928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558e77c50699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558e77c7b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb6a1c4f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558e71575b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ba84c0d17f0819c1a292af203a57e032d1ec00e4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5447 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 222897320 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55726c77e810, 0x55726c96801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55726c968020,0x55726e8000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba84c0d17f0819c1a292af203a57e032d1ec00e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6957 processed earlier; will process 4072 files now Step #5: ==196198== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5572632739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5572698d8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5572698bb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5572698bb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557263279d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5572631dab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5572631d5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55726326bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55726623af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55726623af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55726623af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55726623af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55726623af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55726623af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55726623af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55726623af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55726623af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55726623af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5572684cff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5572651fcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557265207be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557264fb3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557264fb3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557264fb4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557264fb3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557264fb3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557264fb3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5572698bdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5572698c6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5572698ae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5572698d9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4cc8510082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5572631d3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d922b72322009f5b15f35604959d655722c15247 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5448 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 223541491 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fea122a810, 0x55fea141401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fea1414020,0x55fea32ac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d922b72322009f5b15f35604959d655722c15247' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6958 processed earlier; will process 4071 files now Step #5: ==196234== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fe97d1f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe9e384898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe9e3675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe9e3674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe97d25d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe97c86b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe97c81355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe97d17c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe9ace6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe9ace6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe9ace6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe9ace6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe9ace6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe9ace6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe9ace6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe9ace6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe9ace6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe9ace6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe9cf7bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe99ca8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe99cb3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe99a5fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe99a5fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe99a60738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe99a5f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe99a5f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe99a5f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe9e369abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe9e372928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe9e35a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe9e385112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe1e6d66082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe97c7fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-162dcfe137862bb0f109f8acfedb6c75f41f0482 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5449 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 224055690 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5651f569c810, 0x5651f588601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5651f5886020,0x5651f771e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/162dcfe137862bb0f109f8acfedb6c75f41f0482' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6959 processed earlier; will process 4070 files now Step #5: ==196270== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5651ec1919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5651f27f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651f27d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651f27d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5651ec197d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5651ec0f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5651ec0f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5651ec189c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5651ef158f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5651ef158f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5651ef158f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5651ef158f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5651ef158f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5651ef158f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5651ef158f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5651ef158f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5651ef158f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5651ef158f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5651f13edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5651ee11ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5651ee125be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5651eded1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5651eded1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5651eded2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5651eded1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5651eded1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5651eded1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5651f27dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5651f27e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5651f27cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5651f27f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc587509082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5651ec0f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6aa8f7ea30893b1dcae4a6042f68374a66b45c76 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5450 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 224594930 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643b6d09810, 0x5643b6ef301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643b6ef3020,0x5643b8d8b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6aa8f7ea30893b1dcae4a6042f68374a66b45c76' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6960 processed earlier; will process 4069 files now Step #5: ==196306== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643ad7fe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643b3e63898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643b3e465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643b3e464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643ad804d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643ad765b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643ad760355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643ad7f6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643b07c5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643b07c5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643b07c5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643b07c5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643b07c5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643b07c5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643b07c5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643b07c5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643b07c5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643b07c5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643b2a5af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643af787b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643af792be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643af53ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643af53ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643af53f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643af53e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643af53e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643af53e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643b3e48abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643b3e51928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643b3e39699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643b3e64112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb33267e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643ad75eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-522ce639a10190c4f2c7d60313268bcd7bd74b51 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5451 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 225127141 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55671ca10810, 0x55671cbfa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55671cbfa020,0x55671ea920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/522ce639a10190c4f2c7d60313268bcd7bd74b51' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6961 processed earlier; will process 4068 files now Step #5: #1 pulse cov: 3585 ft: 3586 exec/s: 0 rss: 178Mb Step #5: ==196342== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5567135059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556719b6a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556719b4d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556719b4d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55671350bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55671346cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556713467355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5567134fdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5567164ccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5567164ccf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5567164ccf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5567164ccf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5567164ccf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5567164ccf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5567164ccf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5567164ccf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5567164ccf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5567164ccf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556718761f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55671548eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556715499be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556715245c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556715245c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556715246738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556715245874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556715245874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556715245874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556719b4fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556719b58928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556719b40699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556719b6b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe0624b3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556713465b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4325e5f1b1deaa265841a4555fd6dbdbd9ba3d77 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5452 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 225689638 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a167a7b810, 0x55a167c6501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a167c65020,0x55a169afd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4325e5f1b1deaa265841a4555fd6dbdbd9ba3d77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6963 processed earlier; will process 4066 files now Step #5: ==196378== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a15e5709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a164bd5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a164bb85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a164bb84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a15e576d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a15e4d7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a15e4d2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a15e568c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a161537f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a161537f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a161537f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a161537f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a161537f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a161537f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a161537f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a161537f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a161537f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a161537f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1637ccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1604f9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a160504be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1602b0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1602b0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1602b1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1602b0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1602b0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1602b0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a164bbaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a164bc3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a164bab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a164bd6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1812b91082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a15e4d0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-59f9c9147b7505b925124893447a5f5d850ca224 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5453 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 226209620 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fabbf3d810, 0x55fabc12701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fabc127020,0x55fabdfbf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/59f9c9147b7505b925124893447a5f5d850ca224' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6964 processed earlier; will process 4065 files now Step #5: ==196414== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fab2a329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fab9097898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fab907a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fab907a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fab2a38d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fab2999b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fab2994355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fab2a2ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fab59f9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fab59f9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fab59f9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fab59f9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fab59f9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fab59f9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fab59f9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fab59f9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fab59f9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fab59f9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fab7c8ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fab49bbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fab49c6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fab4772c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fab4772c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fab4773738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fab4772874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fab4772874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fab4772874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fab907cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fab9085928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fab906d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fab9098112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa5c12e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fab2992b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-67f1521b59001c5198ebb649fa395d2bb3b68d28 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5454 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 226741119 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5567a4c78810, 0x5567a4e6201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5567a4e62020,0x5567a6cfa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/67f1521b59001c5198ebb649fa395d2bb3b68d28' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6965 processed earlier; will process 4064 files now Step #5: ==196450== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55679b76d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5567a1dd2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5567a1db55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5567a1db54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55679b773d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55679b6d4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55679b6cf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55679b765c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55679e734f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55679e734f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55679e734f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55679e734f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55679e734f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55679e734f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55679e734f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55679e734f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55679e734f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55679e734f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5567a09c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55679d6f6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55679d701be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55679d4adc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55679d4adc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55679d4ae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55679d4ad874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55679d4ad874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55679d4ad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5567a1db7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5567a1dc0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5567a1da8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5567a1dd3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f84faf6f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55679b6cdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-864862cecd60f961ad916ba81fbef91f65135f72 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5455 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 227273467 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560209bb2810, 0x560209d9c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560209d9c020,0x56020bc340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/864862cecd60f961ad916ba81fbef91f65135f72' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6966 processed earlier; will process 4063 files now Step #5: ==196486== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5602006a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560206d0c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560206cef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560206cef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5602006add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56020060eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560200609355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56020069fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56020366ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56020366ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56020366ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56020366ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56020366ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56020366ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56020366ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56020366ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56020366ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56020366ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560205903f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560202630b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56020263bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5602023e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5602023e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5602023e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5602023e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5602023e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5602023e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560206cf1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560206cfa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560206ce2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560206d0d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f99e1dd0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560200607b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7b14c88edb8d1ee708e0c44b0933ef49e0de33f2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5456 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 227834401 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fb44116810, 0x55fb4430001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fb44300020,0x55fb461980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7b14c88edb8d1ee708e0c44b0933ef49e0de33f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6967 processed earlier; will process 4062 files now Step #5: ==196522== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fb3ac0b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fb41270898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fb412535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fb412534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fb3ac11d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fb3ab72b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fb3ab6d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fb3ac03c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fb3dbd2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fb3dbd2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fb3dbd2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fb3dbd2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fb3dbd2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fb3dbd2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fb3dbd2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fb3dbd2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fb3dbd2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fb3dbd2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fb3fe67f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fb3cb94b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fb3cb9fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fb3c94bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fb3c94bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fb3c94c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fb3c94b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fb3c94b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fb3c94b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fb41255abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fb4125e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fb41246699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fb41271112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8234993082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fb3ab6bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ddc6ad1800d4c888552a6c947b89f0a3314d0b0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5457 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 228368617 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563aaa644810, 0x563aaa82e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563aaa82e020,0x563aac6c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ddc6ad1800d4c888552a6c947b89f0a3314d0b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6968 processed earlier; will process 4061 files now Step #5: #1 pulse cov: 4021 ft: 4022 exec/s: 0 rss: 178Mb Step #5: ==196558== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563aa11399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563aa779e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563aa77815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563aa77814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563aa113fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563aa10a0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563aa109b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563aa1131c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563aa4100f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563aa4100f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563aa4100f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563aa4100f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563aa4100f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563aa4100f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563aa4100f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563aa4100f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563aa4100f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563aa4100f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563aa6395f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563aa30c2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563aa30cdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563aa2e79c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563aa2e79c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563aa2e7a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563aa2e79874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563aa2e79874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563aa2e79874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563aa7783abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563aa778c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563aa7774699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563aa779f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd92e8b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563aa1099b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2e90e08bff5cd0d1ac0e1ee2886d89ba2c1f0746 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5458 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 228952303 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557296748810, 0x55729693201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557296932020,0x5572987ca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2e90e08bff5cd0d1ac0e1ee2886d89ba2c1f0746' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6970 processed earlier; will process 4059 files now Step #5: #1 pulse cov: 4205 ft: 4206 exec/s: 0 rss: 179Mb Step #5: ==196594== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55728d23d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5572938a2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5572938855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5572938854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55728d243d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55728d1a4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55728d19f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55728d235c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557290204f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557290204f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557290204f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557290204f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557290204f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557290204f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557290204f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557290204f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557290204f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557290204f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557292499f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55728f1c6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55728f1d1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55728ef7dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55728ef7dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55728ef7e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55728ef7d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55728ef7d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55728ef7d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557293887abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557293890928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557293878699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5572938a3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c9036e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55728d19db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e76945d222e183e8ca9ba8d249b7ed09291986f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5459 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 229515886 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b59b5c810, 0x560b59d4601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b59d46020,0x560b5bbde0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e76945d222e183e8ca9ba8d249b7ed09291986f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6972 processed earlier; will process 4057 files now Step #5: ==196630== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560b506519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b56cb6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b56c995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b56c994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b50657d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b505b8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b505b3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b50649c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b53618f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b53618f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b53618f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b53618f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b53618f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b53618f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b53618f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b53618f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b53618f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b53618f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b558adf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b525dab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b525e5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b52391c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b52391c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b52392738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b52391874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b52391874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b52391874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b56c9babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b56ca4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b56c8c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b56cb7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6143a50082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b505b1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f892310bc998831d76aa47c311a784d8feb26891 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5460 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 230048464 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557df6255810, 0x557df643f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557df643f020,0x557df82d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f892310bc998831d76aa47c311a784d8feb26891' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6973 processed earlier; will process 4056 files now Step #5: ==196666== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557decd4a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557df33af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557df33925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557df33924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557decd50d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557deccb1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557deccac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557decd42c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557defd11f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557defd11f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557defd11f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557defd11f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557defd11f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557defd11f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557defd11f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557defd11f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557defd11f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557defd11f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557df1fa6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557deecd3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557deecdebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557deea8ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557deea8ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557deea8b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557deea8a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557deea8a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557deea8a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557df3394abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557df339d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557df3385699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557df33b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f06ba4b6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557deccaab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-33c7d00828e91e6ad27dce9328a664abce509bee Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5461 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 230584818 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56411e4e9810, 0x56411e6d301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56411e6d3020,0x56412056b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/33c7d00828e91e6ad27dce9328a664abce509bee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6974 processed earlier; will process 4055 files now Step #5: ==196702== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564114fde9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56411b643898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56411b6265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56411b6264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564114fe4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564114f45b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564114f40355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564114fd6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564117fa5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564117fa5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564117fa5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564117fa5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564117fa5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564117fa5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564117fa5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564117fa5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564117fa5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564117fa5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56411a23af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564116f67b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564116f72be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564116d1ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564116d1ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564116d1f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564116d1e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564116d1e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564116d1e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56411b628abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56411b631928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56411b619699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56411b644112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe839a03082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564114f3eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7c73faeb9a474a397fcf232676576e97486a74a2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5462 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 231146747 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564a9bf88810, 0x564a9c17201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564a9c172020,0x564a9e00a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7c73faeb9a474a397fcf232676576e97486a74a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6975 processed earlier; will process 4054 files now Step #5: ==196738== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564a92a7d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564a990e2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564a990c55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564a990c54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564a92a83d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564a929e4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564a929df355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564a92a75c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564a95a44f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564a95a44f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564a95a44f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564a95a44f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564a95a44f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564a95a44f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564a95a44f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564a95a44f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564a95a44f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564a95a44f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564a97cd9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564a94a06b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564a94a11be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564a947bdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564a947bdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564a947be738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564a947bd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564a947bd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564a947bd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564a990c7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564a990d0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564a990b8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564a990e3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4fe7d0c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564a929ddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3af3a868c900710a7b7206958f2b0b6f5d009f99 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5463 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 231669354 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db4e9c9810, 0x55db4ebb301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db4ebb3020,0x55db50a4b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3af3a868c900710a7b7206958f2b0b6f5d009f99' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6976 processed earlier; will process 4053 files now Step #5: #1 pulse cov: 11730 ft: 11731 exec/s: 0 rss: 200Mb Step #5: #2 pulse cov: 17029 ft: 20845 exec/s: 0 rss: 213Mb Step #5: ==196774== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db454be9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db4bb23898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db4bb065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db4bb064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db454c4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db45425b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db45420355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db454b6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db48485f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db48485f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db48485f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db48485f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db48485f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db48485f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db48485f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db48485f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db48485f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db48485f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db4a71af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db47447b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db47452be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db471fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db471fec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db471ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db471fe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db471fe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db471fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db4bb08abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db4bb11928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db4baf9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db4bb24112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f874a21f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db4541eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-33ea7e89d0d38322ff21a841385637907c03ed67 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5464 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 232443468 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe012b4810, 0x55fe0149e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe0149e020,0x55fe033360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/33ea7e89d0d38322ff21a841385637907c03ed67' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6979 processed earlier; will process 4050 files now Step #5: ==196810== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fdf7da99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fdfe40e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fdfe3f15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fdfe3f14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fdf7dafd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fdf7d10b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fdf7d0b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fdf7da1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fdfad70f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fdfad70f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fdfad70f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fdfad70f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fdfad70f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fdfad70f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fdfad70f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fdfad70f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fdfad70f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fdfad70f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fdfd005f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fdf9d32b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fdf9d3dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fdf9ae9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fdf9ae9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fdf9aea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fdf9ae9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fdf9ae9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fdf9ae9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fdfe3f3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fdfe3fc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fdfe3e4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fdfe40f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f50faad2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fdf7d09b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-346a6903acd2e22bf98a770a06cc82c7c5fd6720 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5465 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 232977778 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cd83619810, 0x55cd8380301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cd83803020,0x55cd8569b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/346a6903acd2e22bf98a770a06cc82c7c5fd6720' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6980 processed earlier; will process 4049 files now Step #5: #1 pulse cov: 11753 ft: 11754 exec/s: 0 rss: 199Mb Step #5: ==196846== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cd7a10e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cd80773898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cd807565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cd807564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cd7a114d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cd7a075b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cd7a070355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cd7a106c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cd7d0d5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cd7d0d5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cd7d0d5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cd7d0d5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cd7d0d5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cd7d0d5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cd7d0d5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cd7d0d5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cd7d0d5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cd7d0d5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cd7f36af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cd7c097b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cd7c0a2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cd7be4ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cd7be4ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cd7be4f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cd7be4e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cd7be4e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cd7be4e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cd80758abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cd80761928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cd80749699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cd80774112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f93c10fe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cd7a06eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-efdbfafbdc51007e50ff5baf5aba6c941e4314b4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5466 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 233603763 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb33e30810, 0x55bb3401a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb3401a020,0x55bb35eb20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/efdbfafbdc51007e50ff5baf5aba6c941e4314b4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6982 processed earlier; will process 4047 files now Step #5: #1 pulse cov: 3808 ft: 3809 exec/s: 0 rss: 178Mb Step #5: ==196882== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bb2a9259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb30f8a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb30f6d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb30f6d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb2a92bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb2a88cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb2a887355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb2a91dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb2d8ecf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb2d8ecf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb2d8ecf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb2d8ecf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb2d8ecf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb2d8ecf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb2d8ecf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb2d8ecf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb2d8ecf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb2d8ecf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb2fb81f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb2c8aeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb2c8b9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb2c665c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb2c665c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb2c666738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb2c665874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb2c665874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb2c665874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb30f6fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb30f78928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb30f60699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb30f8b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7790722082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb2a885b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aee6495821b1652bf34ac6f0bb95e88b3c112933 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5467 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 234226470 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562da5354810, 0x562da553e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562da553e020,0x562da73d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aee6495821b1652bf34ac6f0bb95e88b3c112933' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6984 processed earlier; will process 4045 files now Step #5: ==196918== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562d9be499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562da24ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562da24915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562da24914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d9be4fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d9bdb0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d9bdab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d9be41c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d9ee10f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d9ee10f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d9ee10f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d9ee10f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d9ee10f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d9ee10f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d9ee10f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d9ee10f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d9ee10f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d9ee10f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562da10a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d9ddd2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d9ddddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d9db89c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d9db89c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d9db8a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d9db89874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d9db89874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d9db89874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562da2493abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562da249c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562da2484699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562da24af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb88ab06082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d9bda9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8f1332019a2440721a71d1566cca6eda6705f30d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5468 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 234752485 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e25f51c810, 0x55e25f70601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e25f706020,0x55e26159e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8f1332019a2440721a71d1566cca6eda6705f30d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6985 processed earlier; will process 4044 files now Step #5: ==196954== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e2560119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e25c676898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e25c6595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e25c6594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e256017d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e255f78b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e255f73355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e256009c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e258fd8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e258fd8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e258fd8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e258fd8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e258fd8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e258fd8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e258fd8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e258fd8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e258fd8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e258fd8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e25b26df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e257f9ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e257fa5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e257d51c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e257d51c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e257d52738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e257d51874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e257d51874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e257d51874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e25c65babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e25c664928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e25c64c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e25c677112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8aef08b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e255f71b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5c65d255c2734e8005229cd791452d9a81c75c88 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5469 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 235301826 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643f98b9810, 0x5643f9aa301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643f9aa3020,0x5643fb93b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c65d255c2734e8005229cd791452d9a81c75c88' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6986 processed earlier; will process 4043 files now Step #5: ==196990== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643f03ae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643f6a13898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643f69f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643f69f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643f03b4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643f0315b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643f0310355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643f03a6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643f3375f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643f3375f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643f3375f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643f3375f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643f3375f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643f3375f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643f3375f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643f3375f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643f3375f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643f3375f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643f560af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643f2337b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643f2342be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643f20eec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643f20eec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643f20ef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643f20ee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643f20ee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643f20ee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643f69f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643f6a01928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643f69e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643f6a14112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f224faa4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643f030eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8457a4d2aaf5c9b56b6ecab6b6898db67ee3dda4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5470 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 235854435 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ce0a217810, 0x55ce0a40101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ce0a401020,0x55ce0c2990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8457a4d2aaf5c9b56b6ecab6b6898db67ee3dda4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6987 processed earlier; will process 4042 files now Step #5: #1 pulse cov: 4443 ft: 4444 exec/s: 0 rss: 178Mb Step #5: ==197026== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ce00d0c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ce07371898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ce073545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ce073544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ce00d12d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ce00c73b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ce00c6e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ce00d04c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ce03cd3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ce03cd3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ce03cd3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ce03cd3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ce03cd3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ce03cd3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ce03cd3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ce03cd3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ce03cd3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ce03cd3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ce05f68f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ce02c95b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ce02ca0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ce02a4cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ce02a4cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ce02a4d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ce02a4c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ce02a4c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ce02a4c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ce07356abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ce0735f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ce07347699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ce07372112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0aab714082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ce00c6cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-26c5d99ebbbf836bdeb976b9a4c7e70fc4a43bc4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5471 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 236446791 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5575d968d810, 0x5575d987701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5575d9877020,0x5575db70f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/26c5d99ebbbf836bdeb976b9a4c7e70fc4a43bc4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6989 processed earlier; will process 4040 files now Step #5: #1 pulse cov: 3622 ft: 3623 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 12492 ft: 13473 exec/s: 0 rss: 199Mb Step #5: ==197062== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5575d01829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5575d67e7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5575d67ca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5575d67ca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5575d0188d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5575d00e9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5575d00e4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5575d017ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5575d3149f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5575d3149f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5575d3149f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5575d3149f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5575d3149f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5575d3149f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5575d3149f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5575d3149f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5575d3149f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5575d3149f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5575d53def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5575d210bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5575d2116be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5575d1ec2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5575d1ec2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5575d1ec3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5575d1ec2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5575d1ec2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5575d1ec2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5575d67ccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5575d67d5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5575d67bd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5575d67e8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf76369082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5575d00e2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-27fe1a090e96a734bf42ee7bd164045299d8c801 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5472 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 237084783 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55640331f810, 0x55640350901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556403509020,0x5564053a10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/27fe1a090e96a734bf42ee7bd164045299d8c801' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6992 processed earlier; will process 4037 files now Step #5: ==197098== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5563f9e149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556400479898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55640045c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55640045c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5563f9e1ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5563f9d7bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5563f9d76355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5563f9e0cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5563fcddbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5563fcddbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5563fcddbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5563fcddbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5563fcddbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5563fcddbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5563fcddbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5563fcddbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5563fcddbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5563fcddbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5563ff070f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5563fbd9db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5563fbda8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5563fbb54c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5563fbb54c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5563fbb55738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5563fbb54874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5563fbb54874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5563fbb54874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55640045eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556400467928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55640044f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55640047a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f94310d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5563f9d74b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-77006ec653de12b08752e368301551e8511822ed Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5473 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 237613038 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a677d1810, 0x561a679bb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a679bb020,0x561a698530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/77006ec653de12b08752e368301551e8511822ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6993 processed earlier; will process 4036 files now Step #5: #1 pulse cov: 4330 ft: 4331 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4686 ft: 5232 exec/s: 0 rss: 179Mb Step #5: ==197134== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561a5e2c69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561a6492b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561a6490e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561a6490e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561a5e2ccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561a5e22db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561a5e228355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561a5e2bec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561a6128df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561a6128df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561a6128df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561a6128df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561a6128df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561a6128df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561a6128df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561a6128df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561a6128df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561a6128df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561a63522f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561a6024fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561a6025abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561a60006c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561a60006c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561a60007738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561a60006874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561a60006874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561a60006874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561a64910abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561a64919928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561a64901699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561a6492c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f00efe6e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561a5e226b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f56735ffd75c9209ecbbd01e04c084509d298cab Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5474 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 238320366 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bef9674810, 0x55bef985e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bef985e020,0x55befb6f60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f56735ffd75c9209ecbbd01e04c084509d298cab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6997 processed earlier; will process 4032 files now Step #5: #1 pulse cov: 3787 ft: 3788 exec/s: 0 rss: 177Mb Step #5: ==197170== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bef01699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bef67ce898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bef67b15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bef67b14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bef016fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bef00d0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bef00cb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bef0161c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bef3130f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bef3130f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bef3130f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bef3130f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bef3130f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bef3130f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bef3130f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bef3130f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bef3130f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bef3130f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bef53c5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bef20f2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bef20fdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bef1ea9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bef1ea9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bef1eaa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bef1ea9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bef1ea9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bef1ea9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bef67b3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bef67bc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bef67a4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bef67cf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba09682082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bef00c9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c2751f7c7601f808048f8347a2b9f051977e47a6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5475 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 238921163 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9d4980810, 0x55e9d4b6a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9d4b6a020,0x55e9d6a020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c2751f7c7601f808048f8347a2b9f051977e47a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 6999 processed earlier; will process 4030 files now Step #5: ==197206== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e9cb4759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9d1ada898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9d1abd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9d1abd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9cb47bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e9cb3dcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e9cb3d7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9cb46dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e9ce43cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e9ce43cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e9ce43cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e9ce43cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e9ce43cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e9ce43cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e9ce43cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e9ce43cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e9ce43cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e9ce43cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9d06d1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e9cd3feb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e9cd409be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9cd1b5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9cd1b5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9cd1b6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9cd1b5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9cd1b5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9cd1b5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e9d1abfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9d1ac8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e9d1ab0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e9d1adb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ccdf9e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e9cb3d5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1a08ba5baf2637f848b0d42bda8e4c8e3c80a44a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5476 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 239455196 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56167aecf810, 0x56167b0b901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56167b0b9020,0x56167cf510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1a08ba5baf2637f848b0d42bda8e4c8e3c80a44a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7000 processed earlier; will process 4029 files now Step #5: ==197242== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5616719c49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561678029898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56167800c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56167800c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5616719cad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56167192bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561671926355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5616719bcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56167498bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56167498bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56167498bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56167498bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56167498bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56167498bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56167498bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56167498bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56167498bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56167498bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561676c20f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56167394db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561673958be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561673704c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561673704c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561673705738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561673704874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561673704874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561673704874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56167800eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561678017928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561677fff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56167802a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feffb051082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561671924b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-57c2e29fd5408537ef2e7e6b2ed7eb4a5d4185c1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5477 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 239987848 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56194b3b2810, 0x56194b59c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56194b59c020,0x56194d4340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/57c2e29fd5408537ef2e7e6b2ed7eb4a5d4185c1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7001 processed earlier; will process 4028 files now Step #5: #1 pulse cov: 3986 ft: 3987 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4565 ft: 5176 exec/s: 0 rss: 182Mb Step #5: ==197278== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561941ea79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56194850c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5619484ef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5619484ef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561941eadd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561941e0eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561941e09355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561941e9fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561944e6ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561944e6ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561944e6ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561944e6ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561944e6ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561944e6ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561944e6ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561944e6ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561944e6ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561944e6ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561947103f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561943e30b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561943e3bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561943be7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561943be7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561943be8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561943be7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561943be7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561943be7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5619484f1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5619484fa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5619484e2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56194850d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f926dea0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561941e07b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a4d1b3f9e6bc45f34141d591b290794994d5d173 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5478 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 240620770 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55891310a810, 0x5589132f401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5589132f4020,0x55891518c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a4d1b3f9e6bc45f34141d591b290794994d5d173' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7004 processed earlier; will process 4025 files now Step #5: ==197314== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558909bff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558910264898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589102475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589102474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558909c05d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558909b66b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558909b61355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558909bf7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55890cbc6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55890cbc6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55890cbc6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55890cbc6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55890cbc6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55890cbc6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55890cbc6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55890cbc6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55890cbc6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55890cbc6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55890ee5bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55890bb88b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55890bb93be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55890b93fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55890b93fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55890b940738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55890b93f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55890b93f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55890b93f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558910249abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558910252928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55891023a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558910265112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe5375df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558909b5fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b48ed0c15cec79c348f7224b8ec43f80db7ea4df Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5479 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 241144882 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5654733aa810, 0x56547359401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565473594020,0x56547542c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b48ed0c15cec79c348f7224b8ec43f80db7ea4df' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7005 processed earlier; will process 4024 files now Step #5: #1 pulse cov: 3971 ft: 3972 exec/s: 0 rss: 179Mb Step #5: ==197350== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565469e9f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565470504898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5654704e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5654704e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565469ea5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565469e06b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565469e01355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565469e97c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56546ce66f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56546ce66f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56546ce66f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56546ce66f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56546ce66f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56546ce66f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56546ce66f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56546ce66f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56546ce66f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56546ce66f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56546f0fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56546be28b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56546be33be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56546bbdfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56546bbdfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56546bbe0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56546bbdf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56546bbdf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56546bbdf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5654704e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5654704f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5654704da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565470505112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a9e5cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565469dffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fbd21742ecf2878328c02ac8be07756b261ccfa3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5480 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 241705103 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55accac26810, 0x55accae1001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55accae10020,0x55acccca80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fbd21742ecf2878328c02ac8be07756b261ccfa3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7007 processed earlier; will process 4022 files now Step #5: ==197386== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55acc171b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55acc7d80898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55acc7d635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55acc7d634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55acc1721d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55acc1682b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55acc167d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55acc1713c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55acc46e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55acc46e2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55acc46e2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55acc46e2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55acc46e2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55acc46e2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55acc46e2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55acc46e2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55acc46e2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55acc46e2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55acc6977f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55acc36a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55acc36afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55acc345bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55acc345bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55acc345c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55acc345b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55acc345b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55acc345b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55acc7d65abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55acc7d6e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55acc7d56699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55acc7d81112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5b8dd98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55acc167bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-86d1694247b332c3b3e0260b1b9786041089cbea Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5481 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 242261042 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b6535e810, 0x558b6554801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b65548020,0x558b673e00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/86d1694247b332c3b3e0260b1b9786041089cbea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7008 processed earlier; will process 4021 files now Step #5: ==197422== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558b5be539c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b624b8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b6249b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b6249b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b5be59d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b5bdbab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b5bdb5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b5be4bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b5ee1af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b5ee1af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b5ee1af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b5ee1af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b5ee1af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b5ee1af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b5ee1af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b5ee1af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b5ee1af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b5ee1af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b610aff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b5dddcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b5dde7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b5db93c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b5db93c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b5db94738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b5db93874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b5db93874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b5db93874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b6249dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b624a6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b6248e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b624b9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faea81f4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b5bdb3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-433d567ec980a4ef9b381fe8126c1c5cc84df73b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5482 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 242902485 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b1defd810, 0x557b1e0e701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b1e0e7020,0x557b1ff7f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/433d567ec980a4ef9b381fe8126c1c5cc84df73b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7009 processed earlier; will process 4020 files now Step #5: #1 pulse cov: 4200 ft: 4201 exec/s: 0 rss: 177Mb Step #5: ==197458== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557b149f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b1b057898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b1b03a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b1b03a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b149f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b14959b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b14954355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b149eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b179b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b179b9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b179b9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b179b9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b179b9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b179b9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b179b9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b179b9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b179b9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b179b9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b19c4ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b1697bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b16986be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b16732c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b16732c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b16733738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b16732874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b16732874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b16732874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b1b03cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b1b045928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b1b02d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b1b058112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b7c437082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b14952b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-48c49367514f9a35d9869daa00db492b4a34b36d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5483 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 243467686 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd373b8810, 0x55dd375a201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd375a2020,0x55dd3943a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/48c49367514f9a35d9869daa00db492b4a34b36d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7011 processed earlier; will process 4018 files now Step #5: ==197494== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dd2dead9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd34512898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd344f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd344f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dd2deb3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dd2de14b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dd2de0f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dd2dea5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd30e74f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd30e74f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd30e74f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd30e74f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd30e74f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd30e74f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd30e74f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd30e74f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd30e74f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd30e74f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd33109f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dd2fe36b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dd2fe41be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dd2fbedc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dd2fbedc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dd2fbee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dd2fbed874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dd2fbed874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dd2fbed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd344f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd34500928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd344e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd34513112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe3c90e7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dd2de0db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d4fb933ccf32e7120ecd893d2ecf27b19bb3231b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5484 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 243991821 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56149cc19810, 0x56149ce0301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56149ce03020,0x56149ec9b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d4fb933ccf32e7120ecd893d2ecf27b19bb3231b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7012 processed earlier; will process 4017 files now Step #5: ==197530== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56149370e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561499d73898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561499d565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561499d564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561493714d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561493675b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561493670355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561493706c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5614966d5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5614966d5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5614966d5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5614966d5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5614966d5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5614966d5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5614966d5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5614966d5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5614966d5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5614966d5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56149896af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561495697b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5614956a2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56149544ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56149544ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56149544f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56149544e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56149544e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56149544e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561499d58abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561499d61928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561499d49699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561499d74112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1cc5fa4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56149366eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ae40785d7af58e15bab21758b0dd3422474d31b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5485 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 244523224 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643642d6810, 0x5643644c001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643644c0020,0x5643663580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ae40785d7af58e15bab21758b0dd3422474d31b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7013 processed earlier; will process 4016 files now Step #5: ==197566== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56435adcb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564361430898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643614135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643614134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56435add1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56435ad32b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56435ad2d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56435adc3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56435dd92f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56435dd92f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56435dd92f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56435dd92f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56435dd92f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56435dd92f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56435dd92f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56435dd92f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56435dd92f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56435dd92f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564360027f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56435cd54b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56435cd5fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56435cb0bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56435cb0bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56435cb0c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56435cb0b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56435cb0b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56435cb0b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564361415abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56436141e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564361406699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564361431112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f43e72c0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56435ad2bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-71b687f51dd151c9b3abb01d9726d0cc77517a4e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5486 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 245175947 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5601ba966810, 0x5601bab5001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5601bab50020,0x5601bc9e80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/71b687f51dd151c9b3abb01d9726d0cc77517a4e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7014 processed earlier; will process 4015 files now Step #5: ==197602== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5601b145b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601b7ac0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601b7aa35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601b7aa34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5601b1461d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601b13c2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601b13bd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5601b1453c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601b4422f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601b4422f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601b4422f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601b4422f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601b4422f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601b4422f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601b4422f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601b4422f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601b4422f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601b4422f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5601b66b7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601b33e4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601b33efbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5601b319bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5601b319bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5601b319c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5601b319b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5601b319b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5601b319b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5601b7aa5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5601b7aae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5601b7a96699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601b7ac1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f83aa865082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601b13bbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-62f59c0b3fecf35fc962b70784484c348bca74ae Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5487 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 245705388 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564f226bb810, 0x564f228a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564f228a5020,0x564f2473d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/62f59c0b3fecf35fc962b70784484c348bca74ae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7015 processed earlier; will process 4014 files now Step #5: #1 pulse cov: 4364 ft: 4365 exec/s: 0 rss: 180Mb Step #5: ==197638== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564f191b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564f1f815898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564f1f7f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564f1f7f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564f191b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564f19117b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564f19112355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564f191a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564f1c177f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564f1c177f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564f1c177f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564f1c177f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564f1c177f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564f1c177f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564f1c177f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564f1c177f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564f1c177f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564f1c177f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564f1e40cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564f1b139b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564f1b144be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564f1aef0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564f1aef0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564f1aef1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564f1aef0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564f1aef0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564f1aef0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564f1f7faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564f1f803928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564f1f7eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564f1f816112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f848e18f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564f19110b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1664b9ec5cb67170b852ecea434313e8f71bfde7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5488 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 246402718 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563dbefb1810, 0x563dbf19b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563dbf19b020,0x563dc10330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1664b9ec5cb67170b852ecea434313e8f71bfde7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7017 processed earlier; will process 4012 files now Step #5: ==197674== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563db5aa69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563dbc10b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563dbc0ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563dbc0ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563db5aacd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563db5a0db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563db5a08355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563db5a9ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563db8a6df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563db8a6df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563db8a6df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563db8a6df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563db8a6df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563db8a6df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563db8a6df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563db8a6df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563db8a6df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563db8a6df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563dbad02f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563db7a2fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563db7a3abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563db77e6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563db77e6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563db77e7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563db77e6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563db77e6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563db77e6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563dbc0f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563dbc0f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563dbc0e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563dbc10c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff28e055082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563db5a06b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ba69d20f60d1cb7bb34ef8b5a988cf856a3e36fb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5489 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 246927739 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556888b36810, 0x556888d2001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556888d20020,0x55688abb80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba69d20f60d1cb7bb34ef8b5a988cf856a3e36fb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7018 processed earlier; will process 4011 files now Step #5: ==197710== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55687f62b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556885c90898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556885c735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556885c734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55687f631d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55687f592b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55687f58d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55687f623c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5568825f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5568825f2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5568825f2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5568825f2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5568825f2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5568825f2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5568825f2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5568825f2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5568825f2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5568825f2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556884887f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5568815b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5568815bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55688136bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55688136bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55688136c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55688136b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55688136b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55688136b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556885c75abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556885c7e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556885c66699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556885c91112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68c49b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55687f58bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-668a9b37774fdde77662ef417e345537a4fce997 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5490 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 247456293 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b771dd810, 0x556b773c701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b773c7020,0x556b7925f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/668a9b37774fdde77662ef417e345537a4fce997' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7019 processed earlier; will process 4010 files now Step #5: ==197746== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556b6dcd29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b74337898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b7431a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b7431a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b6dcd8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b6dc39b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b6dc34355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b6dccac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b70c99f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b70c99f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b70c99f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b70c99f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b70c99f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b70c99f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b70c99f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b70c99f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b70c99f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b70c99f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b72f2ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b6fc5bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b6fc66be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b6fa12c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b6fa12c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b6fa13738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b6fa12874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b6fa12874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b6fa12874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b7431cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b74325928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b7430d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b74338112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe22fa56082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b6dc32b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f9d97b0218b608525244260669d1ee72b110f2b2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5491 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 247986106 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a56097810, 0x561a5628101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a56281020,0x561a581190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9d97b0218b608525244260669d1ee72b110f2b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7020 processed earlier; will process 4009 files now Step #5: #1 pulse cov: 3777 ft: 3778 exec/s: 0 rss: 180Mb Step #5: ==197782== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561a4cb8c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561a531f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561a531d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561a531d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561a4cb92d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561a4caf3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561a4caee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561a4cb84c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561a4fb53f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561a4fb53f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561a4fb53f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561a4fb53f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561a4fb53f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561a4fb53f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561a4fb53f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561a4fb53f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561a4fb53f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561a4fb53f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561a51de8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561a4eb15b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561a4eb20be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561a4e8ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561a4e8ccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561a4e8cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561a4e8cc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561a4e8cc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561a4e8cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561a531d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561a531df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561a531c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561a531f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf605e0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561a4caecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-523d1a3724fad66a678071a3ddd2b3ca0602fd64 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5492 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 248563676 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b8805a7810, 0x55b88079101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b880791020,0x55b8826290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/523d1a3724fad66a678071a3ddd2b3ca0602fd64' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7022 processed earlier; will process 4007 files now Step #5: ==197818== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b87709c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b87d701898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b87d6e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b87d6e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b8770a2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b877003b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b876ffe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b877094c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b87a063f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b87a063f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b87a063f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b87a063f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b87a063f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b87a063f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b87a063f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b87a063f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b87a063f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b87a063f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b87c2f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b879025b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b879030be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b878ddcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b878ddcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b878ddd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b878ddc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b878ddc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b878ddc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b87d6e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b87d6ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b87d6d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b87d702112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd37589b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b876ffcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-00cf80024fc67940c1c4b6f292bea6f4bb00cc40 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5493 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 249088860 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56089a63a810, 0x56089a82401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56089a824020,0x56089c6bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/00cf80024fc67940c1c4b6f292bea6f4bb00cc40' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7023 processed earlier; will process 4006 files now Step #5: ==197854== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56089112f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560897794898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608977775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608977774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560891135d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560891096b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560891091355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560891127c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5608940f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5608940f6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5608940f6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5608940f6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5608940f6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5608940f6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5608940f6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5608940f6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5608940f6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5608940f6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56089638bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5608930b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5608930c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560892e6fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560892e6fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560892e70738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560892e6f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560892e6f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560892e6f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560897779abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560897782928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56089776a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560897795112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdadf8d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56089108fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6dc87b0dd54d6211f09f9725b5f1fe4308eea5af Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5494 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 249618159 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b5fd0a2810, 0x55b5fd28c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b5fd28c020,0x55b5ff1240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6dc87b0dd54d6211f09f9725b5f1fe4308eea5af' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7024 processed earlier; will process 4005 files now Step #5: ==197890== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b5f3b979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b5fa1fc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b5fa1df5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b5fa1df4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b5f3b9dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b5f3afeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b5f3af9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b5f3b8fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b5f6b5ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b5f6b5ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b5f6b5ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b5f6b5ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b5f6b5ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b5f6b5ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b5f6b5ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b5f6b5ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b5f6b5ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b5f6b5ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b5f8df3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b5f5b20b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b5f5b2bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b5f58d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b5f58d7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b5f58d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b5f58d7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b5f58d7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b5f58d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b5fa1e1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b5fa1ea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b5fa1d2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b5fa1fd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa90736d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b5f3af7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-893aa79b2607e96b49c09e830979a2e6d0474c28 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5495 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 250160290 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b20cf75810, 0x55b20d15f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b20d15f020,0x55b20eff70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/893aa79b2607e96b49c09e830979a2e6d0474c28' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7025 processed earlier; will process 4004 files now Step #5: ==197926== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b203a6a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b20a0cf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b20a0b25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b20a0b24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b203a70d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b2039d1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b2039cc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b203a62c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b206a31f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b206a31f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b206a31f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b206a31f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b206a31f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b206a31f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b206a31f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b206a31f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b206a31f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b206a31f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b208cc6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b2059f3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b2059febe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b2057aac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b2057aac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b2057ab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b2057aa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b2057aa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b2057aa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b20a0b4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b20a0bd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b20a0a5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b20a0d0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9474d10082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b2039cab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1ac614376c406837620fd2874d0f45f5edbae538 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5496 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 252298954 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a85adf810, 0x559a85cc901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a85cc9020,0x559a87b610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ac614376c406837620fd2874d0f45f5edbae538' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7026 processed earlier; will process 4003 files now Step #5: ==197962== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559a7c5d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a82c39898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a82c1c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a82c1c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a7c5dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a7c53bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a7c536355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a7c5ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a7f59bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a7f59bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a7f59bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a7f59bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a7f59bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a7f59bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a7f59bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a7f59bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a7f59bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a7f59bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a81830f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a7e55db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a7e568be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a7e314c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a7e314c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a7e315738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a7e314874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a7e314874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a7e314874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a82c1eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a82c27928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a82c0f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a82c3a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f03e2aeb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a7c534b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e58aa84ae3403906deb4c59b025697883b7669e8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5497 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 252836118 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5566942ae810, 0x55669449801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556694498020,0x5566963300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e58aa84ae3403906deb4c59b025697883b7669e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7027 processed earlier; will process 4002 files now Step #5: ==197998== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55668ada39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556691408898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5566913eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5566913eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55668ada9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55668ad0ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55668ad05355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55668ad9bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55668dd6af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55668dd6af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55668dd6af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55668dd6af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55668dd6af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55668dd6af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55668dd6af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55668dd6af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55668dd6af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55668dd6af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55668fffff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55668cd2cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55668cd37be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55668cae3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55668cae3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55668cae4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55668cae3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55668cae3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55668cae3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5566913edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5566913f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5566913de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556691409112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f81af28b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55668ad03b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-71898c055aef5c26ae50d892f6dcf8dab1acbd0e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5498 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 253382313 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b805eb810, 0x556b807d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b807d5020,0x556b8266d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/71898c055aef5c26ae50d892f6dcf8dab1acbd0e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7028 processed earlier; will process 4001 files now Step #5: ==198034== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556b770e09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b7d745898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b7d7285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b7d7284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b770e6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b77047b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b77042355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b770d8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b7a0a7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b7a0a7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b7a0a7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b7a0a7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b7a0a7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b7a0a7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b7a0a7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b7a0a7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b7a0a7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b7a0a7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b7c33cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b79069b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b79074be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b78e20c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b78e20c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b78e21738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b78e20874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b78e20874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b78e20874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b7d72aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b7d733928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b7d71b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b7d746112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffacae69082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b77040b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8a2e117610cb606f012cd21fcdd97db0e36534c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5499 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 253907684 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d790ae810, 0x564d7929801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d79298020,0x564d7b1300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8a2e117610cb606f012cd21fcdd97db0e36534c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7029 processed earlier; will process 4000 files now Step #5: ==198070== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d6fba39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d76208898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d761eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d761eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d6fba9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d6fb0ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d6fb05355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d6fb9bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d72b6af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d72b6af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d72b6af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d72b6af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d72b6af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d72b6af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d72b6af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d72b6af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d72b6af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d72b6af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d74dfff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d71b2cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d71b37be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d718e3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d718e3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d718e4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d718e3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d718e3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d718e3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d761edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d761f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d761de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d76209112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f60c66fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d6fb03b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8df3b5eff3a317b3deac1edf45d8a9d6f9fdadab Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5500 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 254431396 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560bcaef8810, 0x560bcb0e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560bcb0e2020,0x560bccf7a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8df3b5eff3a317b3deac1edf45d8a9d6f9fdadab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7030 processed earlier; will process 3999 files now Step #5: ==198106== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560bc19ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560bc8052898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560bc80355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560bc80354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560bc19f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560bc1954b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560bc194f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560bc19e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560bc49b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560bc49b4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560bc49b4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560bc49b4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560bc49b4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560bc49b4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560bc49b4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560bc49b4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560bc49b4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560bc49b4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560bc6c49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560bc3976b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560bc3981be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560bc372dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560bc372dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560bc372e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560bc372d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560bc372d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560bc372d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560bc8037abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560bc8040928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560bc8028699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560bc8053112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3863f3a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560bc194db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aa721eb46de3acff11d1d3a75efa044c1fd46e44 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5501 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 254989255 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fdba470810, 0x55fdba65a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fdba65a020,0x55fdbc4f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aa721eb46de3acff11d1d3a75efa044c1fd46e44' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7031 processed earlier; will process 3998 files now Step #5: #1 pulse cov: 4263 ft: 4264 exec/s: 0 rss: 177Mb Step #5: ==198142== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fdb0f659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fdb75ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fdb75ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fdb75ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fdb0f6bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fdb0eccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fdb0ec7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fdb0f5dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fdb3f2cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fdb3f2cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fdb3f2cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fdb3f2cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fdb3f2cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fdb3f2cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fdb3f2cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fdb3f2cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fdb3f2cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fdb3f2cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fdb61c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fdb2eeeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fdb2ef9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fdb2ca5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fdb2ca5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fdb2ca6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fdb2ca5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fdb2ca5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fdb2ca5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fdb75afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fdb75b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fdb75a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fdb75cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f02a690b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fdb0ec5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f9cd53467a24b6fa3269c3cf4ba2b81f6afae29a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5502 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 255556111 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55611b242810, 0x55611b42c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55611b42c020,0x55611d2c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9cd53467a24b6fa3269c3cf4ba2b81f6afae29a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7033 processed earlier; will process 3996 files now Step #5: #1 pulse cov: 4107 ft: 4108 exec/s: 0 rss: 180Mb Step #5: ==198178== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556111d379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55611839c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55611837f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55611837f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556111d3dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556111c9eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556111c99355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556111d2fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556114cfef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556114cfef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556114cfef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556114cfef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556114cfef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556114cfef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556114cfef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556114cfef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556114cfef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556114cfef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556116f93f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556113cc0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556113ccbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556113a77c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556113a77c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556113a78738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556113a77874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556113a77874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556113a77874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556118381abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55611838a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556118372699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55611839d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f230bdda082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556111c97b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d0ce0e10ef88143bfa34edc2b22e28d53c29921a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5503 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 256135111 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5642c8a49810, 0x5642c8c3301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5642c8c33020,0x5642caacb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d0ce0e10ef88143bfa34edc2b22e28d53c29921a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7035 processed earlier; will process 3994 files now Step #5: #1 pulse cov: 4317 ft: 4318 exec/s: 0 rss: 178Mb Step #5: ==198214== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5642bf53e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5642c5ba3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5642c5b865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5642c5b864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642bf544d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5642bf4a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5642bf4a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5642bf536c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5642c2505f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5642c2505f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5642c2505f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5642c2505f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5642c2505f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5642c2505f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5642c2505f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5642c2505f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5642c2505f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5642c2505f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5642c479af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5642c14c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5642c14d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5642c127ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5642c127ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5642c127f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5642c127e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5642c127e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5642c127e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5642c5b88abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5642c5b91928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5642c5b79699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5642c5ba4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fec2cce4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5642bf49eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-16769fe8adf41962d5b6cf6a8a46463a04c61383 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5504 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 256818434 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a825696810, 0x55a82588001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a825880020,0x55a8277180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16769fe8adf41962d5b6cf6a8a46463a04c61383' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7037 processed earlier; will process 3992 files now Step #5: ==198250== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a81c18b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a8227f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a8227d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a8227d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a81c191d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a81c0f2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a81c0ed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a81c183c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a81f152f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a81f152f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a81f152f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a81f152f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a81f152f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a81f152f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a81f152f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a81f152f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a81f152f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a81f152f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a8213e7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a81e114b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a81e11fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a81decbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a81decbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a81decc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a81decb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a81decb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a81decb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a8227d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a8227de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a8227c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a8227f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdb7ffa8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a81c0ebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-90a3a573d7420f921d5ce2726ac6c25239867d8f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5505 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 257359613 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562481615810, 0x5624817ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5624817ff020,0x5624836970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/90a3a573d7420f921d5ce2726ac6c25239867d8f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7038 processed earlier; will process 3991 files now Step #5: ==198286== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56247810a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56247e76f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56247e7525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56247e7524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562478110d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562478071b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56247806c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562478102c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56247b0d1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56247b0d1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56247b0d1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56247b0d1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56247b0d1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56247b0d1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56247b0d1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56247b0d1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56247b0d1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56247b0d1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56247d366f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56247a093b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56247a09ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562479e4ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562479e4ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562479e4b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562479e4a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562479e4a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562479e4a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56247e754abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56247e75d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56247e745699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56247e770112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8f87a8c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56247806ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5a8fb2bd58d14ac0d4f3f4011379eba7ab5aacd3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5506 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 257907035 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5559a825c810, 0x5559a844601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5559a8446020,0x5559aa2de0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5a8fb2bd58d14ac0d4f3f4011379eba7ab5aacd3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7039 processed earlier; will process 3990 files now Step #5: ==198322== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55599ed519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5559a53b6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5559a53995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5559a53994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55599ed57d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55599ecb8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55599ecb3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55599ed49c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5559a1d18f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5559a1d18f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5559a1d18f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5559a1d18f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5559a1d18f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5559a1d18f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5559a1d18f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5559a1d18f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5559a1d18f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5559a1d18f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5559a3fadf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5559a0cdab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5559a0ce5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5559a0a91c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5559a0a91c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5559a0a92738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5559a0a91874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5559a0a91874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5559a0a91874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5559a539babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5559a53a4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5559a538c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5559a53b7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f93048b9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55599ecb1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6f9015548bf5e77e081396cfd1636fc02b25db08 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5507 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 258432913 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558eee61e810, 0x558eee80801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558eee808020,0x558ef06a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6f9015548bf5e77e081396cfd1636fc02b25db08' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7040 processed earlier; will process 3989 files now Step #5: ==198358== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558ee51139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558eeb778898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558eeb75b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558eeb75b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558ee5119d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558ee507ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558ee5075355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558ee510bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558ee80daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558ee80daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558ee80daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558ee80daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558ee80daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558ee80daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558ee80daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558ee80daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558ee80daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558ee80daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558eea36ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ee709cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ee70a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ee6e53c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ee6e53c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ee6e54738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ee6e53874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ee6e53874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ee6e53874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558eeb75dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558eeb766928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558eeb74e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558eeb779112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa1b6a71082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558ee5073b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-01b9b5f84b9e56b64b671dfc5df715268b3c5ebc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5508 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 258990349 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555647167810, 0x55564735101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555647351020,0x5556491e90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01b9b5f84b9e56b64b671dfc5df715268b3c5ebc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7041 processed earlier; will process 3988 files now Step #5: #1 pulse cov: 3919 ft: 3920 exec/s: 0 rss: 179Mb Step #5: ==198394== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55563dc5c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5556442c1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556442a45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556442a44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55563dc62d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55563dbc3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55563dbbe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55563dc54c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555640c23f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555640c23f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555640c23f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555640c23f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555640c23f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555640c23f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555640c23f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555640c23f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555640c23f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555640c23f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555642eb8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55563fbe5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55563fbf0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55563f99cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55563f99cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55563f99d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55563f99c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55563f99c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55563f99c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5556442a6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5556442af928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555644297699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5556442c2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fad75824082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55563dbbcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-50c8c6720f6e2a83a52f3eb1dd4b3df4eeed64b8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5509 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 259555385 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5639b4747810, 0x5639b493101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5639b4931020,0x5639b67c90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/50c8c6720f6e2a83a52f3eb1dd4b3df4eeed64b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7043 processed earlier; will process 3986 files now Step #5: ==198430== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5639ab23c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5639b18a1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5639b18845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5639b18844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5639ab242d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5639ab1a3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5639ab19e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5639ab234c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5639ae203f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5639ae203f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5639ae203f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5639ae203f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5639ae203f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5639ae203f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5639ae203f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5639ae203f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5639ae203f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5639ae203f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5639b0498f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5639ad1c5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5639ad1d0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5639acf7cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5639acf7cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5639acf7d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5639acf7c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5639acf7c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5639acf7c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5639b1886abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5639b188f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5639b1877699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5639b18a2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb6cfae2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5639ab19cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-337d996cb732264c57cf1eb18ebd6e2c11ba90b0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5510 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 260083178 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55909d8a5810, 0x55909da8f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55909da8f020,0x55909f9270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/337d996cb732264c57cf1eb18ebd6e2c11ba90b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7044 processed earlier; will process 3985 files now Step #5: ==198466== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55909439a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55909a9ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55909a9e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55909a9e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5590943a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559094301b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5590942fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559094392c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559097361f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559097361f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559097361f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559097361f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559097361f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559097361f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559097361f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559097361f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559097361f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559097361f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5590995f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559096323b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55909632ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5590960dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5590960dac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5590960db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5590960da874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5590960da874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5590960da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55909a9e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55909a9ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55909a9d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55909aa00112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0df6987082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5590942fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-738b780daa7113d224a02632f6bcbb24f785b3e2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5511 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 260624308 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d875f3810, 0x557d877dd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d877dd020,0x557d896750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/738b780daa7113d224a02632f6bcbb24f785b3e2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7045 processed earlier; will process 3984 files now Step #5: ==198502== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557d7e0e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557d8474d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557d847305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557d847304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557d7e0eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557d7e04fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557d7e04a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557d7e0e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557d810aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557d810aff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557d810aff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557d810aff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557d810aff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557d810aff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557d810aff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557d810aff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557d810aff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557d810aff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557d83344f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557d80071b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557d8007cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557d7fe28c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557d7fe28c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557d7fe29738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557d7fe28874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557d7fe28874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557d7fe28874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557d84732abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557d8473b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557d84723699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557d8474e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a99de4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557d7e048b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4fe4528c1655c26100638230674d026448031062 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5512 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 261166650 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555c2d3ba810, 0x555c2d5a401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555c2d5a4020,0x555c2f43c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4fe4528c1655c26100638230674d026448031062' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7046 processed earlier; will process 3983 files now Step #5: #1 pulse cov: 11175 ft: 11176 exec/s: 0 rss: 198Mb Step #5: #2 pulse cov: 12223 ft: 13037 exec/s: 0 rss: 200Mb Step #5: ==198538== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555c23eaf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555c2a514898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555c2a4f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555c2a4f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555c23eb5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555c23e16b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555c23e11355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555c23ea7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555c26e76f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555c26e76f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555c26e76f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555c26e76f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555c26e76f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555c26e76f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555c26e76f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555c26e76f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555c26e76f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555c26e76f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555c2910bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555c25e38b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555c25e43be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555c25befc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555c25befc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555c25bf0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555c25bef874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555c25bef874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555c25bef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555c2a4f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555c2a502928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555c2a4ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555c2a515112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f97a8a1e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555c23e0fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2095e1eb4c8bdcc4a1c4dc62fbb9ec5884b255e3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5513 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 261919806 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56074d21f810, 0x56074d40901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56074d409020,0x56074f2a10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2095e1eb4c8bdcc4a1c4dc62fbb9ec5884b255e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7049 processed earlier; will process 3980 files now Step #5: ==198574== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560743d149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56074a379898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56074a35c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56074a35c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560743d1ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560743c7bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560743c76355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560743d0cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560746cdbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560746cdbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560746cdbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560746cdbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560746cdbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560746cdbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560746cdbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560746cdbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560746cdbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560746cdbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560748f70f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560745c9db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560745ca8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560745a54c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560745a54c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560745a55738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560745a54874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560745a54874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560745a54874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56074a35eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56074a367928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56074a34f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56074a37a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8589712082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560743c74b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3f3f4a8a3ca7e849a9ac5d95b20d5129fb87be6d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5514 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 262486325 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d206f66810, 0x55d20715001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d207150020,0x55d208fe80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3f3f4a8a3ca7e849a9ac5d95b20d5129fb87be6d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7050 processed earlier; will process 3979 files now Step #5: #1 pulse cov: 4345 ft: 4346 exec/s: 0 rss: 179Mb Step #5: ==198610== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d1fda5b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d2040c0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d2040a35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d2040a34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1fda61d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1fd9c2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1fd9bd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1fda53c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d200a22f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d200a22f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d200a22f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d200a22f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d200a22f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d200a22f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d200a22f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d200a22f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d200a22f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d200a22f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d202cb7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1ff9e4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1ff9efbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1ff79bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1ff79bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1ff79c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1ff79b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1ff79b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1ff79b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d2040a5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d2040ae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d204096699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d2040c1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb97b3fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1fd9bbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ad8dae8c19c189289ed69331be200411fc76fee0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5515 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 263051787 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5634d89c3810, 0x5634d8bad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5634d8bad020,0x5634daa450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad8dae8c19c189289ed69331be200411fc76fee0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7052 processed earlier; will process 3977 files now Step #5: #1 pulse cov: 11034 ft: 11035 exec/s: 0 rss: 196Mb Step #5: ==198646== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5634cf4b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5634d5b1d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5634d5b005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5634d5b004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5634cf4bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5634cf41fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5634cf41a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5634cf4b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5634d247ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5634d247ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5634d247ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5634d247ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5634d247ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5634d247ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5634d247ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5634d247ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5634d247ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5634d247ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5634d4714f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5634d1441b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5634d144cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5634d11f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5634d11f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5634d11f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5634d11f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5634d11f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5634d11f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5634d5b02abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5634d5b0b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5634d5af3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5634d5b1e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4e0f06082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5634cf418b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ece66f4758ca626e8a8dd4e4e166dc83beb678c8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5516 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 263678745 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56527a773810, 0x56527a95d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56527a95d020,0x56527c7f50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ece66f4758ca626e8a8dd4e4e166dc83beb678c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7054 processed earlier; will process 3975 files now Step #5: ==198682== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5652712689c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652778cd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652778b05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652778b04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56527126ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5652711cfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5652711ca355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565271260c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56527422ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56527422ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56527422ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56527422ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56527422ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56527422ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56527422ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56527422ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56527422ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56527422ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652764c4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5652731f1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5652731fcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565272fa8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565272fa8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565272fa9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565272fa8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565272fa8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565272fa8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652778b2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652778bb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652778a3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652778ce112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4d7e018082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5652711c8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-16cdd3c3b862601a78a671b50699d270e9d3f14f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5517 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 264215882 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56481860b810, 0x5648187f501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5648187f5020,0x56481a68d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16cdd3c3b862601a78a671b50699d270e9d3f14f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7055 processed earlier; will process 3974 files now Step #5: #1 pulse cov: 3894 ft: 3895 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4157 ft: 4617 exec/s: 0 rss: 181Mb Step #5: ==198718== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56480f1009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564815765898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5648157485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5648157484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56480f106d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56480f067b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56480f062355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56480f0f8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5648120c7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5648120c7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5648120c7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5648120c7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5648120c7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5648120c7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5648120c7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5648120c7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5648120c7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5648120c7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56481435cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564811089b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564811094be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564810e40c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564810e40c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564810e41738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564810e40874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564810e40874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564810e40874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56481574aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564815753928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56481573b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564815766112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff65e5ae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56480f060b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d687806ce80ac52d30f2cf7588cc15910adffffa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5518 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 264966702 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f30412b810, 0x55f30431501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f304315020,0x55f3061ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d687806ce80ac52d30f2cf7588cc15910adffffa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7059 processed earlier; will process 3970 files now Step #5: #1 pulse cov: 3537 ft: 3538 exec/s: 0 rss: 177Mb Step #5: ==198754== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f2fac209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f301285898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f3012685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f3012684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f2fac26d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f2fab87b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f2fab82355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f2fac18c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f2fdbe7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f2fdbe7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f2fdbe7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f2fdbe7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f2fdbe7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f2fdbe7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f2fdbe7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f2fdbe7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f2fdbe7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f2fdbe7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f2ffe7cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f2fcba9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f2fcbb4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f2fc960c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f2fc960c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f2fc961738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f2fc960874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f2fc960874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f2fc960874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f30126aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f301273928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f30125b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f301286112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f82c4c41082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f2fab80b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ac4c48cc6e660833ad1627ef837bd0c9ca940c9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5519 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 265534757 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559eb8bb8810, 0x559eb8da201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559eb8da2020,0x559ebac3a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ac4c48cc6e660833ad1627ef837bd0c9ca940c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7061 processed earlier; will process 3968 files now Step #5: ==198790== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559eaf6ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559eb5d12898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559eb5cf55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559eb5cf54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559eaf6b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559eaf614b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559eaf60f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559eaf6a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559eb2674f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559eb2674f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559eb2674f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559eb2674f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559eb2674f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559eb2674f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559eb2674f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559eb2674f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559eb2674f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559eb2674f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559eb4909f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559eb1636b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559eb1641be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559eb13edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559eb13edc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559eb13ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559eb13ed874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559eb13ed874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559eb13ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559eb5cf7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559eb5d00928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559eb5ce8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559eb5d13112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27d3f35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559eaf60db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-100fea2298fc5bce9a5d0a096da941d429c0e099 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5520 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 266187261 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a18b9e9810, 0x55a18bbd301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a18bbd3020,0x55a18da6b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/100fea2298fc5bce9a5d0a096da941d429c0e099' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7062 processed earlier; will process 3967 files now Step #5: ==198826== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1824de9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a188b43898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a188b265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a188b264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1824e4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a182445b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a182440355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1824d6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1854a5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1854a5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1854a5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1854a5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1854a5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1854a5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1854a5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1854a5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1854a5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1854a5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a18773af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a184467b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a184472be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a18421ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a18421ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a18421f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a18421e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a18421e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a18421e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a188b28abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a188b31928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a188b19699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a188b44112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd5d51c5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a18243eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aef8eb46d2227025ec37039e2aa05d68d3ba6931 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5521 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 266722536 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560018cf2810, 0x560018edc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560018edc020,0x56001ad740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aef8eb46d2227025ec37039e2aa05d68d3ba6931' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7063 processed earlier; will process 3966 files now Step #5: ==198862== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56000f7e79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560015e4c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560015e2f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560015e2f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56000f7edd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56000f74eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56000f749355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56000f7dfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5600127aef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5600127aef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5600127aef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5600127aef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5600127aef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5600127aef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5600127aef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5600127aef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5600127aef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5600127aef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560014a43f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560011770b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56001177bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560011527c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560011527c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560011528738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560011527874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560011527874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560011527874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560015e31abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560015e3a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560015e22699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560015e4d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb3b8898082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56000f747b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9da94e8106941d10e16156489237b3f2fe848296 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5522 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 267252161 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556888247810, 0x55688843101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556888431020,0x55688a2c90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9da94e8106941d10e16156489237b3f2fe848296' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7064 processed earlier; will process 3965 files now Step #5: ==198898== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55687ed3c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5568853a1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5568853845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5568853844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55687ed42d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55687eca3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55687ec9e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55687ed34c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556881d03f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556881d03f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556881d03f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556881d03f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556881d03f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556881d03f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556881d03f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556881d03f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556881d03f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556881d03f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556883f98f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556880cc5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556880cd0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556880a7cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556880a7cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556880a7d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556880a7c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556880a7c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556880a7c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556885386abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55688538f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556885377699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5568853a2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7effc3473082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55687ec9cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-915386a1c141dbba73287dcb2d24c2f5c3c421f7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5523 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 267779289 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f85952e810, 0x55f85971801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f859718020,0x55f85b5b00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/915386a1c141dbba73287dcb2d24c2f5c3c421f7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7065 processed earlier; will process 3964 files now Step #5: ==198934== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8500239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f856688898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f85666b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f85666b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f850029d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f84ff8ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f84ff85355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f85001bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f852feaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f852feaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f852feaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f852feaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f852feaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f852feaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f852feaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f852feaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f852feaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f852feaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f85527ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f851facb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f851fb7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f851d63c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f851d63c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f851d64738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f851d63874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f851d63874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f851d63874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f85666dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f856676928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f85665e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f856689112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f37620e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f84ff83b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ff60578438d4e5853529d1caef9a7a5e8c3fa4f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5524 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 268303038 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563ae53ad810, 0x563ae559701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563ae5597020,0x563ae742f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ff60578438d4e5853529d1caef9a7a5e8c3fa4f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7066 processed earlier; will process 3963 files now Step #5: #1 pulse cov: 4224 ft: 4225 exec/s: 0 rss: 179Mb Step #5: ==198970== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563adbea29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563ae2507898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563ae24ea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563ae24ea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563adbea8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563adbe09b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563adbe04355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563adbe9ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563adee69f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563adee69f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563adee69f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563adee69f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563adee69f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563adee69f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563adee69f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563adee69f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563adee69f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563adee69f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563ae10fef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563adde2bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563adde36be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563addbe2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563addbe2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563addbe3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563addbe2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563addbe2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563addbe2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563ae24ecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563ae24f5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563ae24dd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563ae2508112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7eff61787082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563adbe02b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1bd6bdf90bf55bdcacc6fb7c9adae495933d0910 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5525 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 268890798 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55afe4327810, 0x55afe451101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55afe4511020,0x55afe63a90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1bd6bdf90bf55bdcacc6fb7c9adae495933d0910' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7068 processed earlier; will process 3961 files now Step #5: ==199006== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55afdae1c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55afe1481898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55afe14645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55afe14644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55afdae22d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55afdad83b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55afdad7e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55afdae14c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55afddde3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55afddde3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55afddde3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55afddde3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55afddde3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55afddde3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55afddde3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55afddde3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55afddde3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55afddde3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55afe0078f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55afdcda5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55afdcdb0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55afdcb5cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55afdcb5cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55afdcb5d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55afdcb5c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55afdcb5c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55afdcb5c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55afe1466abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55afe146f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55afe1457699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55afe1482112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d820a7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55afdad7cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e749350769af0de02b69a9ddb1d2af91f345d29 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5526 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 269429007 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56529f25b810, 0x56529f44501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56529f445020,0x5652a12dd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e749350769af0de02b69a9ddb1d2af91f345d29' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7069 processed earlier; will process 3960 files now Step #5: ==199042== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565295d509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56529c3b5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56529c3985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56529c3984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565295d56d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565295cb7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565295cb2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565295d48c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565298d17f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565298d17f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565298d17f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565298d17f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565298d17f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565298d17f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565298d17f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565298d17f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565298d17f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565298d17f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56529afacf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565297cd9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565297ce4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565297a90c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565297a90c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565297a91738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565297a90874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565297a90874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565297a90874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56529c39aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56529c3a3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56529c38b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56529c3b6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa824297082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565295cb0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-01bd8789d5cca477c1a2762da39c60562a991057 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5527 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 269954665 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558378ecb810, 0x5583790b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5583790b5020,0x55837af4d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01bd8789d5cca477c1a2762da39c60562a991057' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7070 processed earlier; will process 3959 files now Step #5: #1 pulse cov: 3839 ft: 3840 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 11984 ft: 12808 exec/s: 0 rss: 198Mb Step #5: ==199078== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55836f9c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558376025898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583760085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583760084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55836f9c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55836f927b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55836f922355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55836f9b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558372987f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558372987f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558372987f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558372987f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558372987f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558372987f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558372987f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558372987f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558372987f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558372987f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558374c1cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558371949b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558371954be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558371700c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558371700c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558371701738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558371700874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558371700874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558371700874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55837600aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558376013928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558375ffb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558376026112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa2f0d9a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55836f920b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d6d97e3eebbeb57243c8fb1772c807309c498f05 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5528 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 270636294 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563cbdd76810, 0x563cbdf6001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563cbdf60020,0x563cbfdf80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d6d97e3eebbeb57243c8fb1772c807309c498f05' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7074 processed earlier; will process 3955 files now Step #5: ==199114== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563cb486b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563cbaed0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563cbaeb35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563cbaeb34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563cb4871d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563cb47d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563cb47cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563cb4863c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563cb7832f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563cb7832f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563cb7832f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563cb7832f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563cb7832f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563cb7832f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563cb7832f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563cb7832f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563cb7832f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563cb7832f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563cb9ac7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563cb67f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563cb67ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563cb65abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563cb65abc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563cb65ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563cb65ab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563cb65ab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563cb65ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563cbaeb5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563cbaebe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563cbaea6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563cbaed1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc3bb1c8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563cb47cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-94ba8e6fc81ebfa3c18175f214668951a070ad90 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5529 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 271312926 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555966a62810, 0x555966c4c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555966c4c020,0x555968ae40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/94ba8e6fc81ebfa3c18175f214668951a070ad90' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7075 processed earlier; will process 3954 files now Step #5: #1 pulse cov: 11950 ft: 11951 exec/s: 0 rss: 203Mb Step #5: #2 pulse cov: 12570 ft: 13554 exec/s: 0 rss: 205Mb Step #5: ==199150== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55595d5579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555963bbc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555963b9f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555963b9f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55595d55dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55595d4beb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55595d4b9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55595d54fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55596051ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55596051ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55596051ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55596051ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55596051ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55596051ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55596051ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55596051ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55596051ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55596051ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5559627b3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55595f4e0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55595f4ebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55595f297c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55595f297c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55595f298738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55595f297874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55595f297874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55595f297874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555963ba1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555963baa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555963b92699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555963bbd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f79e11e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55595d4b7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-52d4ddfdd1fbc7779de11f20a952d7fbfb2f50f8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5530 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 272055741 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fccda3d810, 0x55fccdc2701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fccdc27020,0x55fccfabf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/52d4ddfdd1fbc7779de11f20a952d7fbfb2f50f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7079 processed earlier; will process 3950 files now Step #5: ==199186== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fcc45329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fccab97898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fccab7a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fccab7a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fcc4538d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fcc4499b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fcc4494355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fcc452ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fcc74f9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fcc74f9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fcc74f9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fcc74f9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fcc74f9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fcc74f9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fcc74f9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fcc74f9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fcc74f9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fcc74f9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fcc978ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fcc64bbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fcc64c6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fcc6272c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fcc6272c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fcc6273738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fcc6272874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fcc6272874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fcc6272874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fccab7cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fccab85928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fccab6d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fccab98112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd00e9d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fcc4492b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c3811269e63fa9acce8a45ddacbe9ca162fc652b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5531 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 272587001 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56078689e810, 0x560786a8801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560786a88020,0x5607889200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c3811269e63fa9acce8a45ddacbe9ca162fc652b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7080 processed earlier; will process 3949 files now Step #5: ==199222== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56077d3939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5607839f8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5607839db5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5607839db4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56077d399d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56077d2fab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56077d2f5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56077d38bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56078035af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56078035af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56078035af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56078035af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56078035af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56078035af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56078035af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56078035af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56078035af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56078035af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5607825eff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56077f31cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56077f327be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56077f0d3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56077f0d3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56077f0d4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56077f0d3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56077f0d3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56077f0d3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5607839ddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5607839e6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5607839ce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5607839f9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fae3da35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56077d2f3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a7dd043a83ec909e9187266bd70f3a9fb127a94 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5532 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 273118150 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fdbb665810, 0x55fdbb84f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fdbb84f020,0x55fdbd6e70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a7dd043a83ec909e9187266bd70f3a9fb127a94' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7081 processed earlier; will process 3948 files now Step #5: ==199258== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fdb215a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fdb87bf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fdb87a25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fdb87a24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fdb2160d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fdb20c1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fdb20bc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fdb2152c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fdb5121f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fdb5121f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fdb5121f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fdb5121f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fdb5121f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fdb5121f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fdb5121f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fdb5121f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fdb5121f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fdb5121f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fdb73b6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fdb40e3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fdb40eebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fdb3e9ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fdb3e9ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fdb3e9b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fdb3e9a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fdb3e9a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fdb3e9a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fdb87a4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fdb87ad928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fdb8795699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fdb87c0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f429950e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fdb20bab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e7e3d90626540893365fd4c72901a9438fa92972 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5533 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 273781241 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d82434810, 0x556d8261e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d8261e020,0x556d844b60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e7e3d90626540893365fd4c72901a9438fa92972' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7082 processed earlier; will process 3947 files now Step #5: ==199294== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556d78f299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d7f58e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d7f5715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d7f5714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d78f2fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d78e90b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d78e8b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d78f21c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d7bef0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d7bef0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d7bef0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d7bef0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d7bef0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d7bef0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d7bef0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d7bef0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d7bef0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d7bef0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d7e185f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d7aeb2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d7aebdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d7ac69c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d7ac69c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d7ac6a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d7ac69874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d7ac69874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d7ac69874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d7f573abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d7f57c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d7f564699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d7f58f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa6617ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d78e89b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5b9f1f4ce5b514d52c7cfe5f4ff023ff46ed0d17 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5534 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 274332077 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c6f498a810, 0x55c6f4b7401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c6f4b74020,0x55c6f6a0c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5b9f1f4ce5b514d52c7cfe5f4ff023ff46ed0d17' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7083 processed earlier; will process 3946 files now Step #5: ==199330== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c6eb47f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c6f1ae4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c6f1ac75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c6f1ac74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c6eb485d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6eb3e6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6eb3e1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c6eb477c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c6ee446f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c6ee446f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c6ee446f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c6ee446f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c6ee446f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c6ee446f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c6ee446f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c6ee446f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c6ee446f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c6ee446f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c6f06dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6ed408b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c6ed413be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6ed1bfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6ed1bfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6ed1c0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6ed1bf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6ed1bf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6ed1bf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c6f1ac9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c6f1ad2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c6f1aba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c6f1ae5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8f90ab3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6eb3dfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fed73e46ddfbd0db0366c519c61e730c5a706231 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5535 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 274860178 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5604d5f1c810, 0x5604d610601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604d6106020,0x5604d7f9e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fed73e46ddfbd0db0366c519c61e730c5a706231' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7084 processed earlier; will process 3945 files now Step #5: #1 pulse cov: 3929 ft: 3930 exec/s: 0 rss: 179Mb Step #5: ==199366== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5604cca119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5604d3076898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5604d30595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5604d30594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5604cca17d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5604cc978b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5604cc973355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5604cca09c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5604cf9d8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5604cf9d8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5604cf9d8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5604cf9d8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5604cf9d8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5604cf9d8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5604cf9d8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5604cf9d8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5604cf9d8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5604cf9d8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5604d1c6df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5604ce99ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5604ce9a5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5604ce751c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5604ce751c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5604ce752738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5604ce751874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5604ce751874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5604ce751874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5604d305babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5604d3064928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5604d304c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5604d3077112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa0cabfb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5604cc971b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-96194ba8022fa8913e390f833473e367e0784703 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5536 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 275558685 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a09ad2f810, 0x55a09af1901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a09af19020,0x55a09cdb10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/96194ba8022fa8913e390f833473e367e0784703' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7086 processed earlier; will process 3943 files now Step #5: ==199402== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0918249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a097e89898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a097e6c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a097e6c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a09182ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a09178bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a091786355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a09181cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0947ebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0947ebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0947ebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0947ebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0947ebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0947ebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0947ebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0947ebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0947ebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0947ebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a096a80f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0937adb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0937b8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a093564c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a093564c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a093565738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a093564874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a093564874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a093564874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a097e6eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a097e77928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a097e5f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a097e8a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efeb69c6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a091784b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a0c9cf32b2503f926c640e3dc9cf8e42d8ae1c48 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5537 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 276138487 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5562ab1ad810, 0x5562ab39701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5562ab397020,0x5562ad22f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a0c9cf32b2503f926c640e3dc9cf8e42d8ae1c48' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7087 processed earlier; will process 3942 files now Step #5: #1 pulse cov: 4012 ft: 4013 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 12336 ft: 13323 exec/s: 0 rss: 197Mb Step #5: ==199438== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5562a1ca29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5562a8307898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5562a82ea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5562a82ea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5562a1ca8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5562a1c09b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5562a1c04355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5562a1c9ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5562a4c69f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5562a4c69f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5562a4c69f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5562a4c69f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5562a4c69f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5562a4c69f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5562a4c69f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5562a4c69f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5562a4c69f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5562a4c69f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5562a6efef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5562a3c2bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5562a3c36be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5562a39e2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5562a39e2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5562a39e3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5562a39e2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5562a39e2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5562a39e2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5562a82ecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5562a82f5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5562a82dd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5562a8308112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac04662082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5562a1c02b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ab2dbed2d3ec6e0760e4d205737a41a4b84f0164 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5538 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 276778461 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55be9b6f0810, 0x55be9b8da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55be9b8da020,0x55be9d7720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ab2dbed2d3ec6e0760e4d205737a41a4b84f0164' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7090 processed earlier; will process 3939 files now Step #5: #1 pulse cov: 3713 ft: 3714 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4223 ft: 4633 exec/s: 0 rss: 180Mb Step #5: ==199474== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55be921e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55be9884a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55be9882d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55be9882d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55be921ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55be9214cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55be92147355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55be921ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55be951acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55be951acf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55be951acf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55be951acf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55be951acf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55be951acf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55be951acf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55be951acf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55be951acf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55be951acf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55be97441f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55be9416eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55be94179be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55be93f25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55be93f25c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55be93f26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55be93f25874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55be93f25874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55be93f25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55be9882fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55be98838928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55be98820699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55be9884b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d7eb3c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55be92145b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1ba4752eea30030384451255ef969338da5f00bb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5539 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 277414549 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564778b82810, 0x564778d6c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564778d6c020,0x56477ac040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ba4752eea30030384451255ef969338da5f00bb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7094 processed earlier; will process 3935 files now Step #5: ==199510== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56476f6779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564775cdc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564775cbf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564775cbf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56476f67dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56476f5deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56476f5d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56476f66fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56477263ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56477263ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56477263ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56477263ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56477263ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56477263ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56477263ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56477263ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56477263ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56477263ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647748d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564771600b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56477160bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647713b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647713b7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647713b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647713b7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647713b7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647713b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564775cc1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564775cca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564775cb2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564775cdd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f52bf8f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56476f5d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f5bda064a7b6ac40cb24dc551f38d181e9f3bfa0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5540 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 277948090 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a228f52810, 0x55a22913c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a22913c020,0x55a22afd40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f5bda064a7b6ac40cb24dc551f38d181e9f3bfa0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7095 processed earlier; will process 3934 files now Step #5: #1 pulse cov: 3784 ft: 3785 exec/s: 0 rss: 179Mb Step #5: ==199546== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a21fa479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a2260ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a22608f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a22608f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a21fa4dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a21f9aeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a21f9a9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a21fa3fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a222a0ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a222a0ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a222a0ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a222a0ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a222a0ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a222a0ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a222a0ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a222a0ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a222a0ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a222a0ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a224ca3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a2219d0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a2219dbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a221787c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a221787c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a221788738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a221787874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a221787874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a221787874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a226091abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a22609a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a226082699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a2260ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbb755d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a21f9a7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9822e2d256917a4e6ab59147d75a55e39d21d6b2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5541 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 278509320 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559796fda810, 0x5597971c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5597971c4020,0x55979905c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9822e2d256917a4e6ab59147d75a55e39d21d6b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7097 processed earlier; will process 3932 files now Step #5: #1 pulse cov: 4051 ft: 4052 exec/s: 0 rss: 178Mb Step #5: ==199582== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55978dacf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559794134898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5597941175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5597941174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55978dad5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55978da36b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55978da31355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55978dac7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559790a96f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559790a96f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559790a96f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559790a96f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559790a96f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559790a96f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559790a96f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559790a96f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559790a96f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559790a96f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559792d2bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55978fa58b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55978fa63be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55978f80fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55978f80fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55978f810738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55978f80f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55978f80f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55978f80f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559794119abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559794122928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55979410a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559794135112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f092568d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55978da2fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-648fea7de2f6e1ca5b3c6d6a77d7d00c1adcd3a4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5542 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 279098766 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5609150ce810, 0x5609152b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5609152b8020,0x5609171500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/648fea7de2f6e1ca5b3c6d6a77d7d00c1adcd3a4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7099 processed earlier; will process 3930 files now Step #5: ==199618== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56090bbc39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560912228898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56091220b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56091220b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56090bbc9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56090bb2ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56090bb25355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56090bbbbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56090eb8af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56090eb8af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56090eb8af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56090eb8af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56090eb8af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56090eb8af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56090eb8af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56090eb8af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56090eb8af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56090eb8af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560910e1ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56090db4cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56090db57be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56090d903c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56090d903c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56090d904738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56090d903874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56090d903874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56090d903874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56091220dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560912216928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5609121fe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560912229112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c97cd7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56090bb23b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3e6927a5bd7cede0024fbf93abf2373dd5addd2c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5543 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 279639916 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d789e05810, 0x55d789fef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d789fef020,0x55d78be870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3e6927a5bd7cede0024fbf93abf2373dd5addd2c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7100 processed earlier; will process 3929 files now Step #5: #1 pulse cov: 3753 ft: 3754 exec/s: 0 rss: 177Mb Step #5: ==199654== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d7808fa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d786f5f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d786f425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d786f424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d780900d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d780861b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d78085c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d7808f2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d7838c1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d7838c1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d7838c1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d7838c1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d7838c1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d7838c1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d7838c1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d7838c1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d7838c1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d7838c1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d785b56f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d782883b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d78288ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d78263ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d78263ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d78263b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d78263a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d78263a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d78263a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d786f44abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d786f4d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d786f35699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d786f60112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faded92d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d78085ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb9402c4222cf573eeb8af4fd3ef05d05573ac40 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5544 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 280353141 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5566ad002810, 0x5566ad1ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5566ad1ec020,0x5566af0840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb9402c4222cf573eeb8af4fd3ef05d05573ac40' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7102 processed earlier; will process 3927 files now Step #5: ==199690== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5566a3af79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5566aa15c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5566aa13f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5566aa13f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5566a3afdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5566a3a5eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5566a3a59355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5566a3aefc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5566a6abef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5566a6abef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5566a6abef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5566a6abef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5566a6abef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5566a6abef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5566a6abef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5566a6abef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5566a6abef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5566a6abef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5566a8d53f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5566a5a80b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5566a5a8bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5566a5837c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5566a5837c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5566a5838738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5566a5837874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5566a5837874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5566a5837874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5566aa141abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5566aa14a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5566aa132699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5566aa15d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba61d97082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5566a3a57b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d662f16ee0f72ce739cb2e52152262ab82f4f09c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5545 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 280894240 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56428baa8810, 0x56428bc9201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56428bc92020,0x56428db2a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d662f16ee0f72ce739cb2e52152262ab82f4f09c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7103 processed earlier; will process 3926 files now Step #5: ==199726== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56428259d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564288c02898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564288be55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564288be54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642825a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564282504b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5642824ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564282595c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564285564f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564285564f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564285564f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564285564f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564285564f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564285564f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564285564f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564285564f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564285564f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564285564f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5642877f9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564284526b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564284531be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5642842ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5642842ddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5642842de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5642842dd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5642842dd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5642842dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564288be7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564288bf0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564288bd8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564288c03112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcbc31f5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5642824fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-637b64f91c93aba6a958603fc05d6f20e76ed4e3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5546 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 281532375 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b0f5d4810, 0x556b0f7be01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b0f7be020,0x556b116560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/637b64f91c93aba6a958603fc05d6f20e76ed4e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7104 processed earlier; will process 3925 files now Step #5: ==199762== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556b060c99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b0c72e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b0c7115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b0c7114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b060cfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b06030b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b0602b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b060c1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b09090f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b09090f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b09090f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b09090f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b09090f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b09090f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b09090f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b09090f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b09090f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b09090f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b0b325f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b08052b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b0805dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b07e09c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b07e09c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b07e0a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b07e09874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b07e09874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b07e09874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b0c713abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b0c71c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b0c704699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b0c72f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f61f4b9b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b06029b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-21e1f101a2dd4b453ff8ee5512e573c659aa7a38 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5547 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 282081626 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55686130c810, 0x5568614f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5568614f6020,0x55686338e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/21e1f101a2dd4b453ff8ee5512e573c659aa7a38' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7105 processed earlier; will process 3924 files now Step #5: ==199798== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556857e019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55685e466898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55685e4495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55685e4494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556857e07d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556857d68b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556857d63355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556857df9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55685adc8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55685adc8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55685adc8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55685adc8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55685adc8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55685adc8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55685adc8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55685adc8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55685adc8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55685adc8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55685d05df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556859d8ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556859d95be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556859b41c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556859b41c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556859b42738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556859b41874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556859b41874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556859b41874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55685e44babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55685e454928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55685e43c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55685e467112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e7c1cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556857d61b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d5f1eb44515cd4337d6eda2d1957df20d6b2ce63 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5548 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 282757932 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f1aecb7810, 0x55f1aeea101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f1aeea1020,0x55f1b0d390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d5f1eb44515cd4337d6eda2d1957df20d6b2ce63' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7106 processed earlier; will process 3923 files now Step #5: ==199834== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f1a57ac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f1abe11898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1abdf45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1abdf44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f1a57b2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f1a5713b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f1a570e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f1a57a4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f1a8773f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f1a8773f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f1a8773f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f1a8773f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f1a8773f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f1a8773f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f1a8773f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f1a8773f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f1a8773f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f1a8773f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f1aaa08f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f1a7735b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f1a7740be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f1a74ecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f1a74ecc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f1a74ed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f1a74ec874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f1a74ec874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f1a74ec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f1abdf6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f1abdff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f1abde7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f1abe12112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f96c4c48082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f1a570cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-076201f6310ccc38b7d4aa7569947fdf16e7e904 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5549 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 283304273 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5607960a4810, 0x56079628e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56079628e020,0x5607981260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/076201f6310ccc38b7d4aa7569947fdf16e7e904' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7107 processed earlier; will process 3922 files now Step #5: #1 pulse cov: 4061 ft: 4062 exec/s: 0 rss: 179Mb Step #5: ==199870== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56078cb999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5607931fe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5607931e15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5607931e14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56078cb9fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56078cb00b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56078cafb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56078cb91c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56078fb60f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56078fb60f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56078fb60f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56078fb60f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56078fb60f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56078fb60f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56078fb60f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56078fb60f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56078fb60f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56078fb60f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560791df5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56078eb22b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56078eb2dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56078e8d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56078e8d9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56078e8da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56078e8d9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56078e8d9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56078e8d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5607931e3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5607931ec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5607931d4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5607931ff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f8140b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56078caf9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f6a14b1847c0965e8e63931796e5e9dbbe530b87 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5550 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 283889014 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b163f29810, 0x55b16411301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b164113020,0x55b165fab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f6a14b1847c0965e8e63931796e5e9dbbe530b87' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7109 processed earlier; will process 3920 files now Step #5: #1 pulse cov: 4028 ft: 4029 exec/s: 0 rss: 177Mb Step #5: ==199906== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b15aa1e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b161083898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1610665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1610664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b15aa24d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b15a985b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b15a980355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b15aa16c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b15d9e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b15d9e5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b15d9e5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b15d9e5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b15d9e5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b15d9e5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b15d9e5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b15d9e5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b15d9e5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b15d9e5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b15fc7af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b15c9a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b15c9b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b15c75ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b15c75ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b15c75f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b15c75e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b15c75e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b15c75e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b161068abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b161071928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b161059699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b161084112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53e72de082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b15a97eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e2bd9cf8f70e3f98c1e37ff2f796966324f5c817 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5551 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 284459739 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e272318810, 0x55e27250201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e272502020,0x55e27439a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e2bd9cf8f70e3f98c1e37ff2f796966324f5c817' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7111 processed earlier; will process 3918 files now Step #5: ==199942== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e268e0d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e26f472898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e26f4555dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e26f4554fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e268e13d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e268d74b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e268d6f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e268e05c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e26bdd4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e26bdd4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e26bdd4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e26bdd4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e26bdd4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e26bdd4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e26bdd4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e26bdd4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e26bdd4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e26bdd4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e26e069f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e26ad96b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e26ada1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e26ab4dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e26ab4dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e26ab4e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e26ab4d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e26ab4d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e26ab4d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e26f457abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e26f460928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e26f448699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e26f473112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ebeba3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e268d6db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bdc7098b24d8e8cb32015ce2523d2165648db706 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5552 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 285015452 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5587be61a810, 0x5587be80401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5587be804020,0x5587c069c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bdc7098b24d8e8cb32015ce2523d2165648db706' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7112 processed earlier; will process 3917 files now Step #5: #1 pulse cov: 4142 ft: 4143 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4442 ft: 5335 exec/s: 0 rss: 179Mb Step #5: ==199978== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5587b510f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5587bb774898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5587bb7575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5587bb7574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5587b5115d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5587b5076b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5587b5071355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5587b5107c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5587b80d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5587b80d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5587b80d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5587b80d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5587b80d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5587b80d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5587b80d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5587b80d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5587b80d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5587b80d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5587ba36bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5587b7098b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5587b70a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5587b6e4fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5587b6e4fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5587b6e50738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5587b6e4f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5587b6e4f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5587b6e4f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5587bb759abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5587bb762928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5587bb74a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5587bb775112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f810926b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5587b506fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c6e650dda5c381322fd180c3aa2c97232f7f6e4e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5553 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 285636434 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5636db2d7810, 0x5636db4c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5636db4c1020,0x5636dd3590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c6e650dda5c381322fd180c3aa2c97232f7f6e4e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7115 processed earlier; will process 3914 files now Step #5: ==200014== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5636d1dcc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5636d8431898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636d84145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636d84144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5636d1dd2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5636d1d33b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5636d1d2e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5636d1dc4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5636d4d93f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5636d4d93f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5636d4d93f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5636d4d93f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5636d4d93f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5636d4d93f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5636d4d93f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5636d4d93f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5636d4d93f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5636d4d93f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5636d7028f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5636d3d55b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5636d3d60be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5636d3b0cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5636d3b0cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5636d3b0d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5636d3b0c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5636d3b0c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5636d3b0c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5636d8416abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5636d841f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5636d8407699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5636d8432112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb531173082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5636d1d2cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ca29a8abb052b4c533c52e3a05fcb5293854dbd0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5554 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 286171452 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a69247a810, 0x55a69266401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a692664020,0x55a6944fc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca29a8abb052b4c533c52e3a05fcb5293854dbd0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7116 processed earlier; will process 3913 files now Step #5: ==200050== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a688f6f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a68f5d4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a68f5b75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a68f5b74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a688f75d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a688ed6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a688ed1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a688f67c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a68bf36f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a68bf36f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a68bf36f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a68bf36f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a68bf36f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a68bf36f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a68bf36f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a68bf36f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a68bf36f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a68bf36f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a68e1cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a68aef8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a68af03be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a68acafc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a68acafc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a68acb0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a68acaf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a68acaf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a68acaf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a68f5b9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a68f5c2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a68f5aa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a68f5d5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5a013e7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a688ecfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a72f6d7643016ea844e4c809fe755867f67480bf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5555 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 287387098 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561495990810, 0x561495b7a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561495b7a020,0x561497a120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a72f6d7643016ea844e4c809fe755867f67480bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7117 processed earlier; will process 3912 files now Step #5: #1 pulse cov: 4099 ft: 4100 exec/s: 0 rss: 179Mb Step #5: ==200086== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56148c4859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561492aea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561492acd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561492acd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56148c48bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56148c3ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56148c3e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56148c47dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56148f44cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56148f44cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56148f44cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56148f44cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56148f44cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56148f44cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56148f44cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56148f44cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56148f44cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56148f44cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5614916e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56148e40eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56148e419be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56148e1c5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56148e1c5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56148e1c6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56148e1c5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56148e1c5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56148e1c5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561492acfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561492ad8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561492ac0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561492aeb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f974881d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56148c3e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-97bb7ba835f1198ba656e920ecb9a0dc164e9de8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5556 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 287953131 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56526e053810, 0x56526e23d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56526e23d020,0x5652700d50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/97bb7ba835f1198ba656e920ecb9a0dc164e9de8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7119 processed earlier; will process 3910 files now Step #5: ==200122== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565264b489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56526b1ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56526b1905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56526b1904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565264b4ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565264aafb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565264aaa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565264b40c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565267b0ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565267b0ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565267b0ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565267b0ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565267b0ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565267b0ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565267b0ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565267b0ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565267b0ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565267b0ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565269da4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565266ad1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565266adcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565266888c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565266888c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565266889738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565266888874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565266888874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565266888874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56526b192abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56526b19b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56526b183699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56526b1ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efd19456082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565264aa8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8c2d8090bc2468ba7118328b5a5a5ed2f949a644 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5557 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 288502861 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56315cfcb810, 0x56315d1b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56315d1b5020,0x56315f04d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c2d8090bc2468ba7118328b5a5a5ed2f949a644' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7120 processed earlier; will process 3909 files now Step #5: ==200158== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563153ac09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56315a125898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56315a1085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56315a1084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563153ac6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563153a27b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563153a22355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563153ab8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563156a87f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563156a87f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563156a87f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563156a87f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563156a87f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563156a87f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563156a87f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563156a87f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563156a87f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563156a87f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563158d1cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563155a49b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563155a54be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563155800c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563155800c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563155801738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563155800874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563155800874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563155800874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56315a10aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56315a113928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56315a0fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56315a126112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f17c044a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563153a20b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-adc31392c7df21a7b545be70bd38895c1da8bdd2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5558 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 289029390 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562f52e2b810, 0x562f5301501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562f53015020,0x562f54ead0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/adc31392c7df21a7b545be70bd38895c1da8bdd2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7121 processed earlier; will process 3908 files now Step #5: #1 pulse cov: 3878 ft: 3879 exec/s: 0 rss: 178Mb Step #5: ==200194== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562f499209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562f4ff85898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562f4ff685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562f4ff684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562f49926d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562f49887b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562f49882355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562f49918c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562f4c8e7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562f4c8e7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562f4c8e7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562f4c8e7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562f4c8e7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562f4c8e7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562f4c8e7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562f4c8e7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562f4c8e7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562f4c8e7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562f4eb7cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562f4b8a9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562f4b8b4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562f4b660c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562f4b660c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562f4b661738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562f4b660874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562f4b660874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562f4b660874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562f4ff6aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562f4ff73928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562f4ff5b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562f4ff86112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f30ff125082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562f49880b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6bdccbd43220a5aae0a74d00783ed62531b4aa19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5559 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 289611075 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ed5370810, 0x559ed555a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ed555a020,0x559ed73f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bdccbd43220a5aae0a74d00783ed62531b4aa19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7123 processed earlier; will process 3906 files now Step #5: #1 pulse cov: 4280 ft: 4281 exec/s: 0 rss: 177Mb Step #5: ==200230== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559ecbe659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ed24ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ed24ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ed24ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ecbe6bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ecbdccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ecbdc7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ecbe5dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ecee2cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ecee2cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ecee2cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ecee2cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ecee2cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ecee2cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ecee2cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ecee2cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ecee2cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ecee2cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ed10c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559ecddeeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559ecddf9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559ecdba5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559ecdba5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559ecdba6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559ecdba5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559ecdba5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559ecdba5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ed24afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ed24b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ed24a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ed24cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf86d35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ecbdc5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-47a95ee4a32b16024361321975fe1e564cfb5c85 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5560 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 290205242 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5644afda1810, 0x5644aff8b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5644aff8b020,0x5644b1e230e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/47a95ee4a32b16024361321975fe1e564cfb5c85' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7125 processed earlier; will process 3904 files now Step #5: ==200266== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5644a68969c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5644acefb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5644acede5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5644acede4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5644a689cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5644a67fdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5644a67f8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5644a688ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5644a985df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5644a985df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5644a985df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5644a985df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5644a985df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5644a985df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5644a985df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5644a985df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5644a985df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5644a985df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5644abaf2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5644a881fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5644a882abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5644a85d6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5644a85d6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5644a85d7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5644a85d6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5644a85d6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5644a85d6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5644acee0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5644acee9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5644aced1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5644acefc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbf8c6b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5644a67f6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b3f334a44dc939ade3dc1c2897456daedb8f682f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5561 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 290750226 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bfca194810, 0x55bfca37e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bfca37e020,0x55bfcc2160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3f334a44dc939ade3dc1c2897456daedb8f682f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7126 processed earlier; will process 3903 files now Step #5: ==200302== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bfc0c899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bfc72ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bfc72d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bfc72d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bfc0c8fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bfc0bf0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bfc0beb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bfc0c81c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bfc3c50f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bfc3c50f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bfc3c50f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bfc3c50f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bfc3c50f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bfc3c50f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bfc3c50f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bfc3c50f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bfc3c50f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bfc3c50f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bfc5ee5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bfc2c12b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bfc2c1dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bfc29c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bfc29c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bfc29ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bfc29c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bfc29c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bfc29c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bfc72d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bfc72dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bfc72c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bfc72ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f92c3f45082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bfc0be9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-76cafb9aae94db127287e2950d663ecdd01b0911 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5562 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 291301912 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56279a663810, 0x56279a84d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56279a84d020,0x56279c6e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/76cafb9aae94db127287e2950d663ecdd01b0911' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7127 processed earlier; will process 3902 files now Step #5: ==200338== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5627911589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5627977bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5627977a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5627977a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56279115ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5627910bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5627910ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562791150c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56279411ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56279411ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56279411ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56279411ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56279411ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56279411ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56279411ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56279411ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56279411ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56279411ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5627963b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5627930e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5627930ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562792e98c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562792e98c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562792e99738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562792e98874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562792e98874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562792e98874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5627977a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5627977ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562797793699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5627977be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f98e48c8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5627910b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c44b3540675c0b849bd1f3c74e6904fa1b3073cc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5563 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 291834203 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a485e6c810, 0x55a48605601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a486056020,0x55a487eee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c44b3540675c0b849bd1f3c74e6904fa1b3073cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7128 processed earlier; will process 3901 files now Step #5: #1 pulse cov: 3628 ft: 3629 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4194 ft: 4670 exec/s: 0 rss: 179Mb Step #5: ==200374== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a47c9619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a482fc6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a482fa95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a482fa94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a47c967d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a47c8c8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a47c8c3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a47c959c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a47f928f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a47f928f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a47f928f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a47f928f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a47f928f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a47f928f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a47f928f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a47f928f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a47f928f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a47f928f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a481bbdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a47e8eab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a47e8f5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a47e6a1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a47e6a1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a47e6a2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a47e6a1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a47e6a1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a47e6a1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a482fababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a482fb4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a482f9c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a482fc7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68cc6aa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a47c8c1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-60e52234614f107bb0d09a2f336696cf0d2b7ff9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5564 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 292439770 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5617168a4810, 0x561716a8e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561716a8e020,0x5617189260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/60e52234614f107bb0d09a2f336696cf0d2b7ff9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7131 processed earlier; will process 3898 files now Step #5: #1 pulse cov: 3507 ft: 3508 exec/s: 0 rss: 179Mb Step #5: ==200410== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56170d3999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5617139fe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5617139e15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5617139e14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56170d39fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56170d300b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56170d2fb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56170d391c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561710360f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561710360f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561710360f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561710360f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561710360f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561710360f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561710360f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561710360f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561710360f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561710360f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5617125f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56170f322b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56170f32dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56170f0d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56170f0d9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56170f0da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56170f0d9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56170f0d9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56170f0d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5617139e3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5617139ec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5617139d4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5617139ff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa433145082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56170d2f9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1cfca2864d18483c6282166cd74a38f8f1c44abf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5565 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 293008546 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559cefe35810, 0x559cf001f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559cf001f020,0x559cf1eb70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1cfca2864d18483c6282166cd74a38f8f1c44abf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7133 processed earlier; will process 3896 files now Step #5: #1 pulse cov: 3975 ft: 3976 exec/s: 0 rss: 180Mb Step #5: ==200446== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559ce692a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559cecf8f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559cecf725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559cecf724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ce6930d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ce6891b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ce688c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ce6922c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ce98f1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ce98f1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ce98f1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ce98f1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ce98f1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ce98f1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ce98f1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ce98f1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ce98f1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ce98f1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559cebb86f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559ce88b3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559ce88bebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559ce866ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559ce866ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559ce866b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559ce866a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559ce866a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559ce866a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559cecf74abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559cecf7d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559cecf65699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559cecf90112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe66613d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ce688ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-45637e656c2b6930078a48a9c81d0f2a9ad3f807 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5566 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 293591091 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ff948f810, 0x562ff967901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ff9679020,0x562ffb5110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/45637e656c2b6930078a48a9c81d0f2a9ad3f807' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7135 processed earlier; will process 3894 files now Step #5: ==200482== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562feff849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562ff65e9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562ff65cc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562ff65cc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562feff8ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562fefeebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562fefee6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562feff7cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ff2f4bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ff2f4bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ff2f4bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ff2f4bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ff2f4bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ff2f4bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ff2f4bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ff2f4bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ff2f4bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ff2f4bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ff51e0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ff1f0db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ff1f18be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ff1cc4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ff1cc4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ff1cc5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ff1cc4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ff1cc4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ff1cc4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562ff65ceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562ff65d7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562ff65bf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562ff65ea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7faf3c0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562fefee4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ba17c2b5ff47c8f7648e6cd7d0672d05c8f4bb7b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5567 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 294118008 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565254992810, 0x565254b7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565254b7c020,0x565256a140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba17c2b5ff47c8f7648e6cd7d0672d05c8f4bb7b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7136 processed earlier; will process 3893 files now Step #5: ==200518== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56524b4879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565251aec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565251acf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565251acf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56524b48dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56524b3eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56524b3e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56524b47fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56524e44ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56524e44ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56524e44ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56524e44ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56524e44ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56524e44ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56524e44ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56524e44ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56524e44ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56524e44ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652506e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56524d410b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56524d41bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56524d1c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56524d1c7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56524d1c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56524d1c7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56524d1c7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56524d1c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565251ad1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565251ada928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565251ac2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565251aed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff50a5dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56524b3e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4fa3bf16337d6f5c1d954e9c510d78222df5bee2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5568 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 294657867 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56233148c810, 0x56233167601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562331676020,0x56233350e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4fa3bf16337d6f5c1d954e9c510d78222df5bee2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7137 processed earlier; will process 3892 files now Step #5: ==200554== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562327f819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56232e5e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56232e5c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56232e5c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562327f87d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562327ee8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562327ee3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562327f79c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56232af48f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56232af48f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56232af48f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56232af48f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56232af48f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56232af48f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56232af48f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56232af48f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56232af48f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56232af48f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56232d1ddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562329f0ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562329f15be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562329cc1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562329cc1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562329cc2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562329cc1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562329cc1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562329cc1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56232e5cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56232e5d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56232e5bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56232e5e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff6bed15082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562327ee1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d789c21bc4f04372f192f742770ed2a0c0b3e2d8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5569 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 295315682 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564339ee2810, 0x56433a0cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56433a0cc020,0x56433bf640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d789c21bc4f04372f192f742770ed2a0c0b3e2d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7138 processed earlier; will process 3891 files now Step #5: #1 pulse cov: 4129 ft: 4130 exec/s: 0 rss: 180Mb Step #5: ==200590== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643309d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56433703c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56433701f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56433701f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643309ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56433093eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564330939355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643309cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56433399ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56433399ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56433399ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56433399ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56433399ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56433399ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56433399ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56433399ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56433399ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56433399ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564335c33f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564332960b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56433296bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564332717c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564332717c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564332718738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564332717874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564332717874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564332717874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564337021abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56433702a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564337012699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56433703d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0e73b86082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564330937b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d0a2998ca6fed66e3b6cce223e6a5a1d90fc4a14 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5570 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 295862417 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565504c2d810, 0x565504e1701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565504e17020,0x565506caf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d0a2998ca6fed66e3b6cce223e6a5a1d90fc4a14' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7140 processed earlier; will process 3889 files now Step #5: ==200626== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5654fb7229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565501d87898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565501d6a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565501d6a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5654fb728d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5654fb689b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5654fb684355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5654fb71ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5654fe6e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5654fe6e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5654fe6e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5654fe6e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5654fe6e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5654fe6e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5654fe6e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5654fe6e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5654fe6e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5654fe6e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56550097ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5654fd6abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5654fd6b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5654fd462c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5654fd462c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5654fd463738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5654fd462874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5654fd462874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5654fd462874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565501d6cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565501d75928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565501d5d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565501d88112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4eeebe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5654fb682b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f17d91ef4ca591272f9d363dd2525e6f4e6fa949 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5571 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 296387019 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56172a367810, 0x56172a55101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56172a551020,0x56172c3e90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f17d91ef4ca591272f9d363dd2525e6f4e6fa949' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7141 processed earlier; will process 3888 files now Step #5: ==200662== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561720e5c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5617274c1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5617274a45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5617274a44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561720e62d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561720dc3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561720dbe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561720e54c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561723e23f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561723e23f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561723e23f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561723e23f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561723e23f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561723e23f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561723e23f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561723e23f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561723e23f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561723e23f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5617260b8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561722de5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561722df0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561722b9cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561722b9cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561722b9d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561722b9c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561722b9c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561722b9c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5617274a6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5617274af928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561727497699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5617274c2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f70fe652082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561720dbcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ec7a14d6e14bd2e4ee60898cea2828a5cddf56c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5572 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 296885469 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5649844bf810, 0x5649846a901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5649846a9020,0x5649865410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ec7a14d6e14bd2e4ee60898cea2828a5cddf56c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7142 processed earlier; will process 3887 files now Step #5: ==200698== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56497afb49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564981619898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5649815fc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5649815fc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56497afbad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56497af1bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56497af16355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56497afacc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56497df7bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56497df7bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56497df7bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56497df7bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56497df7bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56497df7bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56497df7bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56497df7bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56497df7bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56497df7bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564980210f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56497cf3db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56497cf48be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56497ccf4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56497ccf4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56497ccf5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56497ccf4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56497ccf4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56497ccf4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5649815feabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564981607928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5649815ef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56498161a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc7e59d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56497af14b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b61fad94b9de9aa47761ba3ee07e88465b45dffd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5573 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 297435103 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56093c866810, 0x56093ca5001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56093ca50020,0x56093e8e80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b61fad94b9de9aa47761ba3ee07e88465b45dffd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7143 processed earlier; will process 3886 files now Step #5: ==200734== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56093335b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5609399c0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5609399a35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5609399a34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560933361d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5609332c2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5609332bd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560933353c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560936322f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560936322f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560936322f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560936322f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560936322f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560936322f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560936322f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560936322f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560936322f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560936322f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5609385b7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5609352e4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5609352efbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56093509bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56093509bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56093509c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56093509b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56093509b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56093509b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5609399a5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5609399ae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560939996699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5609399c1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7342438082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5609332bbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6c3b31e6505305a90e4b718cf764ab2cd9b557d9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5574 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 297959043 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564646cf1810, 0x564646edb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564646edb020,0x564648d730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6c3b31e6505305a90e4b718cf764ab2cd9b557d9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7144 processed earlier; will process 3885 files now Step #5: ==200770== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56463d7e69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564643e4b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564643e2e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564643e2e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56463d7ecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56463d74db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56463d748355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56463d7dec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5646407adf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5646407adf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5646407adf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5646407adf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5646407adf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5646407adf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5646407adf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5646407adf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5646407adf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5646407adf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564642a42f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56463f76fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56463f77abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56463f526c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56463f526c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56463f527738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56463f526874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56463f526874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56463f526874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564643e30abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564643e39928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564643e21699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564643e4c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fae0dd72082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56463d746b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4a3ebb896bb19a3ec69badb4e277f56512ed0e15 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5575 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 298506865 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa5799a810, 0x55aa57b8401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa57b84020,0x55aa59a1c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4a3ebb896bb19a3ec69badb4e277f56512ed0e15' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7145 processed earlier; will process 3884 files now Step #5: ==200806== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aa4e48f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa54af4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa54ad75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa54ad74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa4e495d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa4e3f6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa4e3f1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa4e487c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa51456f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa51456f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa51456f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa51456f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa51456f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa51456f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa51456f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa51456f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa51456f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa51456f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa536ebf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa50418b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa50423be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa501cfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa501cfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa501d0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa501cf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa501cf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa501cf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa54ad9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa54ae2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa54aca699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa54af5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f290d97b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa4e3efb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3a7d5c0f8aada98355d367d560e90b22b54fcc43 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5576 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 299050321 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d9bc596810, 0x55d9bc78001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d9bc780020,0x55d9be6180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a7d5c0f8aada98355d367d560e90b22b54fcc43' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7146 processed earlier; will process 3883 files now Step #5: ==200842== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d9b308b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d9b96f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d9b96d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d9b96d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d9b3091d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d9b2ff2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d9b2fed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d9b3083c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d9b6052f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d9b6052f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d9b6052f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d9b6052f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d9b6052f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d9b6052f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d9b6052f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d9b6052f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d9b6052f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d9b6052f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d9b82e7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d9b5014b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d9b501fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d9b4dcbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d9b4dcbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d9b4dcc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d9b4dcb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d9b4dcb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d9b4dcb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d9b96d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d9b96de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d9b96c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d9b96f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9a5e981082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d9b2febb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e89a0bddb7c8e737b24f204223e1d194860cfc72 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5577 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 299664555 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5557f42ac810, 0x5557f449601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5557f4496020,0x5557f632e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e89a0bddb7c8e737b24f204223e1d194860cfc72' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7147 processed earlier; will process 3882 files now Step #5: ==200878== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5557eada19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5557f1406898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557f13e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557f13e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557eada7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557ead08b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5557ead03355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557ead99c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557edd68f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557edd68f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557edd68f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557edd68f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557edd68f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557edd68f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557edd68f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557edd68f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557edd68f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557edd68f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5557efffdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557ecd2ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557ecd35be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5557ecae1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5557ecae1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5557ecae2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5557ecae1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5557ecae1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5557ecae1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557f13ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557f13f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557f13dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5557f1407112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f70502ba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5557ead01b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ebd8ab3df918bc31460ea159ac05b95d8e529071 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5578 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 300188825 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5653116ff810, 0x5653118e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5653118e9020,0x5653137810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ebd8ab3df918bc31460ea159ac05b95d8e529071' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7148 processed earlier; will process 3881 files now Step #5: ==200914== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5653081f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56530e859898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56530e83c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56530e83c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5653081fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56530815bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565308156355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5653081ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56530b1bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56530b1bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56530b1bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56530b1bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56530b1bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56530b1bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56530b1bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56530b1bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56530b1bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56530b1bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56530d450f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56530a17db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56530a188be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565309f34c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565309f34c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565309f35738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565309f34874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565309f34874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565309f34874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56530e83eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56530e847928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56530e82f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56530e85a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa25cecd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565308154b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2e26d3476d70a9c4e2938e1fda0c1e254cbe2ec8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5579 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 300707159 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea384bb810, 0x55ea386a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea386a5020,0x55ea3a53d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2e26d3476d70a9c4e2938e1fda0c1e254cbe2ec8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7149 processed earlier; will process 3880 files now Step #5: ==200950== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ea2efb09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea35615898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea355f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea355f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea2efb6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea2ef17b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea2ef12355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea2efa8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea31f77f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea31f77f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea31f77f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea31f77f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea31f77f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea31f77f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea31f77f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea31f77f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea31f77f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea31f77f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea3420cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea30f39b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea30f44be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea30cf0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea30cf0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea30cf1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea30cf0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea30cf0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea30cf0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea355faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea35603928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea355eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea35616112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f75e7e37082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea2ef10b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-38da037d33794ce081384b32ba96310d6b1398b4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5580 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 301234916 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c003da810, 0x556c005c401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c005c4020,0x556c0245c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/38da037d33794ce081384b32ba96310d6b1398b4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7150 processed earlier; will process 3879 files now Step #5: #1 pulse cov: 3456 ft: 3457 exec/s: 0 rss: 179Mb Step #5: ==200986== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556bf6ecf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556bfd534898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556bfd5175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556bfd5174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556bf6ed5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556bf6e36b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556bf6e31355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556bf6ec7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556bf9e96f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556bf9e96f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556bf9e96f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556bf9e96f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556bf9e96f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556bf9e96f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556bf9e96f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556bf9e96f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556bf9e96f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556bf9e96f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556bfc12bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556bf8e58b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556bf8e63be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556bf8c0fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556bf8c0fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556bf8c10738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556bf8c0f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556bf8c0f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556bf8c0f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556bfd519abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556bfd522928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556bfd50a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556bfd535112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc5803e0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556bf6e2fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-99fe1851bf256dba243653fc89f4ec61e6e04318 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5581 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 301823236 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a7a891a810, 0x55a7a8b0401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a7a8b04020,0x55a7aa99c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/99fe1851bf256dba243653fc89f4ec61e6e04318' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7152 processed earlier; will process 3877 files now Step #5: ==201022== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a79f40f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a7a5a74898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a7a5a575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a7a5a574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a79f415d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a79f376b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a79f371355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a79f407c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a7a23d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a7a23d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a7a23d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a7a23d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a7a23d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a7a23d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a7a23d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a7a23d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a7a23d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a7a23d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a7a466bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a7a1398b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a7a13a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a7a114fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a7a114fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a7a1150738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a7a114f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a7a114f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a7a114f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a7a5a59abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a7a5a62928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a7a5a4a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a7a5a75112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8c8243c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a79f36fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b3dd644f85b392683d2096947b08bd382bb22a77 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5582 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 302330384 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5620665a8810, 0x56206679201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562066792020,0x56206862a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3dd644f85b392683d2096947b08bd382bb22a77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7153 processed earlier; will process 3876 files now Step #5: ==201058== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56205d09d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562063702898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5620636e55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5620636e54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56205d0a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56205d004b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56205cfff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56205d095c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562060064f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562060064f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562060064f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562060064f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562060064f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562060064f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562060064f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562060064f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562060064f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562060064f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5620622f9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56205f026b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56205f031be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56205edddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56205edddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56205edde738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56205eddd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56205eddd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56205eddd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5620636e7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5620636f0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5620636d8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562063703112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fef758cb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56205cffdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5acb69c2399efff65482dc0479bbb367f9b5f6ee Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5583 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 302858416 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a91e1ec810, 0x55a91e3d601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a91e3d6020,0x55a92026e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5acb69c2399efff65482dc0479bbb367f9b5f6ee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7154 processed earlier; will process 3875 files now Step #5: ==201094== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a914ce19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a91b346898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a91b3295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a91b3294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a914ce7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a914c48b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a914c43355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a914cd9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a917ca8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a917ca8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a917ca8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a917ca8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a917ca8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a917ca8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a917ca8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a917ca8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a917ca8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a917ca8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a919f3df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a916c6ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a916c75be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a916a21c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a916a21c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a916a22738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a916a21874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a916a21874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a916a21874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a91b32babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a91b334928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a91b31c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a91b347112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa96fe1c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a914c41b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-608e1a4a565bdca0cbb47c702df70cc7291c599b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5584 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 303392363 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5588aa36a810, 0x5588aa55401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5588aa554020,0x5588ac3ec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/608e1a4a565bdca0cbb47c702df70cc7291c599b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7155 processed earlier; will process 3874 files now Step #5: ==201130== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5588a0e5f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5588a74c4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588a74a75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588a74a74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588a0e65d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588a0dc6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588a0dc1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588a0e57c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5588a3e26f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5588a3e26f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5588a3e26f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5588a3e26f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5588a3e26f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5588a3e26f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5588a3e26f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5588a3e26f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5588a3e26f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5588a3e26f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5588a60bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588a2de8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588a2df3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588a2b9fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588a2b9fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588a2ba0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588a2b9f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588a2b9f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588a2b9f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5588a74a9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5588a74b2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5588a749a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5588a74c5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0693319082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588a0dbfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a940d5cdc623ba78afbcc4df9a4c2d4259de8942 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5585 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 303921502 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c5bfd5810, 0x559c5c1bf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c5c1bf020,0x559c5e0570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a940d5cdc623ba78afbcc4df9a4c2d4259de8942' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7156 processed earlier; will process 3873 files now Step #5: ==201166== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559c52aca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c5912f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c591125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c591124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c52ad0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c52a31b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c52a2c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c52ac2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c55a91f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c55a91f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c55a91f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c55a91f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c55a91f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c55a91f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c55a91f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c55a91f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c55a91f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c55a91f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c57d26f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c54a53b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c54a5ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c5480ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c5480ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c5480b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c5480a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c5480a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c5480a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c59114abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c5911d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c59105699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c59130112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0030d56082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c52a2ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1bb7fd76dccf482e1df1a4eae92904d2d1c8a1ee Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5586 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 304447437 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560f245b8810, 0x560f247a201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560f247a2020,0x560f2663a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1bb7fd76dccf482e1df1a4eae92904d2d1c8a1ee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7157 processed earlier; will process 3872 files now Step #5: ==201202== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560f1b0ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560f21712898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560f216f55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560f216f54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560f1b0b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560f1b014b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560f1b00f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560f1b0a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560f1e074f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560f1e074f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560f1e074f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560f1e074f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560f1e074f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560f1e074f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560f1e074f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560f1e074f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560f1e074f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560f1e074f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560f20309f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560f1d036b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560f1d041be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560f1cdedc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560f1cdedc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560f1cdee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560f1cded874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560f1cded874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560f1cded874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560f216f7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560f21700928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560f216e8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560f21713112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0657f64082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560f1b00db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1477f5d645690c8cd844314f0e257b0ffdf3cbdf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5587 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 304977814 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559f1841e810, 0x559f1860801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559f18608020,0x559f1a4a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1477f5d645690c8cd844314f0e257b0ffdf3cbdf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7158 processed earlier; will process 3871 files now Step #5: ==201238== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559f0ef139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559f15578898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559f1555b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559f1555b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559f0ef19d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559f0ee7ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559f0ee75355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559f0ef0bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559f11edaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559f11edaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559f11edaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559f11edaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559f11edaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559f11edaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559f11edaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559f11edaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559f11edaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559f11edaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559f1416ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559f10e9cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559f10ea7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559f10c53c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559f10c53c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559f10c54738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559f10c53874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559f10c53874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559f10c53874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559f1555dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559f15566928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559f1554e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559f15579112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6a9e093082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559f0ee73b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ce00a7579371f240b19ee68ef2db93874089027a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5588 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 305519068 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cf97341810, 0x55cf9752b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cf9752b020,0x55cf993c30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce00a7579371f240b19ee68ef2db93874089027a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7159 processed earlier; will process 3870 files now Step #5: ==201274== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cf8de369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cf9449b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cf9447e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cf9447e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cf8de3cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cf8dd9db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cf8dd98355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cf8de2ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cf90dfdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cf90dfdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cf90dfdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cf90dfdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cf90dfdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cf90dfdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cf90dfdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cf90dfdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cf90dfdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cf90dfdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cf93092f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cf8fdbfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cf8fdcabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cf8fb76c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cf8fb76c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cf8fb77738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cf8fb76874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cf8fb76874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cf8fb76874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cf94480abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cf94489928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cf94471699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cf9449c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fedb855e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cf8dd96b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aff0af2f3a7efe52cf3290c39d58085a10282741 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5589 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 306048034 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557e4f879810, 0x557e4fa6301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557e4fa63020,0x557e518fb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aff0af2f3a7efe52cf3290c39d58085a10282741' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7160 processed earlier; will process 3869 files now Step #5: #1 pulse cov: 3735 ft: 3736 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 12548 ft: 13406 exec/s: 0 rss: 199Mb Step #5: ==201310== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557e4636e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557e4c9d3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557e4c9b65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557e4c9b64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557e46374d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557e462d5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557e462d0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557e46366c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557e49335f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557e49335f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557e49335f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557e49335f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557e49335f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557e49335f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557e49335f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557e49335f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557e49335f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557e49335f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557e4b5caf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557e482f7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557e48302be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557e480aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557e480aec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557e480af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557e480ae874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557e480ae874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557e480ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557e4c9b8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557e4c9c1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557e4c9a9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557e4c9d4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f28623ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557e462ceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-238bbe2b80dd8ae61f90af4439dd15755dcc0eec Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5590 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 306671282 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556413c65810, 0x556413e4f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556413e4f020,0x556415ce70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/238bbe2b80dd8ae61f90af4439dd15755dcc0eec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7163 processed earlier; will process 3866 files now Step #5: #1 pulse cov: 4285 ft: 4286 exec/s: 0 rss: 179Mb Step #5: ==201346== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55640a75a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556410dbf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556410da25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556410da24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55640a760d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55640a6c1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55640a6bc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55640a752c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55640d721f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55640d721f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55640d721f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55640d721f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55640d721f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55640d721f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55640d721f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55640d721f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55640d721f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55640d721f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55640f9b6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55640c6e3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55640c6eebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55640c49ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55640c49ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55640c49b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55640c49a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55640c49a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55640c49a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556410da4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556410dad928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556410d95699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556410dc0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd82eb55082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55640a6bab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8c3ed729810a228d9546bd643a4567dbe646e0f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5591 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 307242290 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe0af21810, 0x55fe0b10b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe0b10b020,0x55fe0cfa30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8c3ed729810a228d9546bd643a4567dbe646e0f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7165 processed earlier; will process 3864 files now Step #5: ==201382== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fe01a169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe0807b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe0805e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe0805e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe01a1cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe0197db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe01978355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe01a0ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe049ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe049ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe049ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe049ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe049ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe049ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe049ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe049ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe049ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe049ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe06c72f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe0399fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe039aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe03756c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe03756c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe03757738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe03756874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe03756874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe03756874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe08060abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe08069928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe08051699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe0807c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7fbaf6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe01976b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-99a1b8412b02a60e759bc6a07d9c30593558ac70 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5592 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 307770528 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564003203810, 0x5640033ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640033ed020,0x5640052850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/99a1b8412b02a60e759bc6a07d9c30593558ac70' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7166 processed earlier; will process 3863 files now Step #5: ==201418== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563ff9cf89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56400035d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640003405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640003404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563ff9cfed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563ff9c5fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563ff9c5a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563ff9cf0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563ffccbff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563ffccbff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563ffccbff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563ffccbff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563ffccbff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563ffccbff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563ffccbff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563ffccbff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563ffccbff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563ffccbff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563ffef54f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563ffbc81b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563ffbc8cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563ffba38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563ffba38c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563ffba39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563ffba38874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563ffba38874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563ffba38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564000342abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56400034b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564000333699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56400035e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8cc8952082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563ff9c58b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-895d97b45e65bfe81a2e261104c25cf3e6856a8d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5593 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 308299780 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556a87fae810, 0x556a8819801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556a88198020,0x556a8a0300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/895d97b45e65bfe81a2e261104c25cf3e6856a8d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7167 processed earlier; will process 3862 files now Step #5: #1 pulse cov: 3648 ft: 3649 exec/s: 0 rss: 179Mb Step #5: ==201454== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556a7eaa39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556a85108898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556a850eb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556a850eb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556a7eaa9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556a7ea0ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556a7ea05355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556a7ea9bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556a81a6af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556a81a6af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556a81a6af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556a81a6af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556a81a6af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556a81a6af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556a81a6af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556a81a6af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556a81a6af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556a81a6af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556a83cfff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556a80a2cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556a80a37be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556a807e3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556a807e3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556a807e4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556a807e3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556a807e3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556a807e3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556a850edabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556a850f6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556a850de699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556a85109112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f859362f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556a7ea03b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e7943e6bd307ad3b557e2dbf48dded29f1db156d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5594 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 308859679 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b980e43810, 0x55b98102d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b98102d020,0x55b982ec50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e7943e6bd307ad3b557e2dbf48dded29f1db156d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7169 processed earlier; will process 3860 files now Step #5: ==201490== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b9779389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b97df9d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b97df805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b97df804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b97793ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b97789fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b97789a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b977930c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b97a8fff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b97a8fff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b97a8fff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b97a8fff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b97a8fff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b97a8fff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b97a8fff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b97a8fff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b97a8fff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b97a8fff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b97cb94f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b9798c1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b9798ccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b979678c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b979678c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b979679738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b979678874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b979678874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b979678874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b97df82abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b97df8b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b97df73699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b97df9e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f747fe4b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b977898b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-baf05d2df727d2df02410d4f4dbf53187d8f52fc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5595 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 309376162 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5599c2563810, 0x5599c274d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5599c274d020,0x5599c45e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/baf05d2df727d2df02410d4f4dbf53187d8f52fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7170 processed earlier; will process 3859 files now Step #5: ==201526== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5599b90589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5599bf6bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5599bf6a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5599bf6a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5599b905ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5599b8fbfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5599b8fba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5599b9050c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5599bc01ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5599bc01ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5599bc01ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5599bc01ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5599bc01ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5599bc01ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5599bc01ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5599bc01ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5599bc01ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5599bc01ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5599be2b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5599bafe1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5599bafecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5599bad98c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5599bad98c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5599bad99738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5599bad98874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5599bad98874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5599bad98874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5599bf6a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5599bf6ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5599bf693699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5599bf6be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa8e4756082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5599b8fb8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-807101329203f6434c871bb6fb69404ad37c68d9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5596 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 309916910 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555d7874f810, 0x555d7893901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555d78939020,0x555d7a7d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/807101329203f6434c871bb6fb69404ad37c68d9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7171 processed earlier; will process 3858 files now Step #5: #1 pulse cov: 3659 ft: 3660 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4229 ft: 4674 exec/s: 0 rss: 181Mb Step #5: ==201562== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555d6f2449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555d758a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555d7588c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555d7588c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555d6f24ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555d6f1abb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555d6f1a6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555d6f23cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555d7220bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555d7220bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555d7220bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555d7220bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555d7220bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555d7220bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555d7220bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555d7220bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555d7220bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555d7220bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555d744a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555d711cdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555d711d8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555d70f84c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555d70f84c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555d70f85738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555d70f84874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555d70f84874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555d70f84874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555d7588eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555d75897928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555d7587f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555d758aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa5e33d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555d6f1a4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec6c1b2e145458ea63f239bd503b941acdeca168 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5597 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 310520202 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55de813ab810, 0x55de8159501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55de81595020,0x55de8342d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec6c1b2e145458ea63f239bd503b941acdeca168' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7174 processed earlier; will process 3855 files now Step #5: ==201598== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55de77ea09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55de7e505898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55de7e4e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55de7e4e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55de77ea6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55de77e07b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55de77e02355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55de77e98c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55de7ae67f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55de7ae67f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55de7ae67f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55de7ae67f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55de7ae67f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55de7ae67f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55de7ae67f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55de7ae67f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55de7ae67f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55de7ae67f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55de7d0fcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55de79e29b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55de79e34be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55de79be0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55de79be0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55de79be1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55de79be0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55de79be0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55de79be0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55de7e4eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55de7e4f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55de7e4db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55de7e506112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f63ee9f4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55de77e00b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-96e0e32921db77842ff92f7be32e38c87af76525 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5598 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 311042791 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5633470a5810, 0x56334728f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56334728f020,0x5633491270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/96e0e32921db77842ff92f7be32e38c87af76525' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7175 processed earlier; will process 3854 files now Step #5: ==201634== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56333db9a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5633441ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5633441e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5633441e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56333dba0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56333db01b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56333dafc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56333db92c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563340b61f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563340b61f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563340b61f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563340b61f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563340b61f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563340b61f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563340b61f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563340b61f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563340b61f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563340b61f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563342df6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56333fb23b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56333fb2ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56333f8dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56333f8dac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56333f8db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56333f8da874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56333f8da874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56333f8da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5633441e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5633441ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5633441d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563344200112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffafe0b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56333dafab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bbcbe70ba39f46c61df14d09cdee08c793d244e4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5599 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 311684814 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b711802810, 0x55b7119ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7119ec020,0x55b7138840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bbcbe70ba39f46c61df14d09cdee08c793d244e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7176 processed earlier; will process 3853 files now Step #5: ==201670== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b7082f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b70e95c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b70e93f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b70e93f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b7082fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b70825eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b708259355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b7082efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b70b2bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b70b2bef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b70b2bef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b70b2bef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b70b2bef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b70b2bef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b70b2bef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b70b2bef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b70b2bef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b70b2bef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b70d553f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b70a280b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b70a28bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b70a037c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b70a037c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b70a038738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b70a037874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b70a037874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b70a037874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b70e941abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b70e94a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b70e932699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b70e95d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e5f07d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b708257b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-064c5f91f50ce101688b248102d804a5434242bb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5600 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 312207238 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d0317e0810, 0x55d0319ca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d0319ca020,0x55d0338620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/064c5f91f50ce101688b248102d804a5434242bb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7177 processed earlier; will process 3852 files now Step #5: ==201706== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d0282d59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d02e93a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d02e91d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d02e91d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d0282dbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d02823cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d028237355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d0282cdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d02b29cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d02b29cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d02b29cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d02b29cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d02b29cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d02b29cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d02b29cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d02b29cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d02b29cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d02b29cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d02d531f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d02a25eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d02a269be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d02a015c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d02a015c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d02a016738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d02a015874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d02a015874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d02a015874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d02e91fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d02e928928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d02e910699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d02e93b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0086589082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d028235b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4e7cb50e16e43b913eb1050a8645668ba1d8ec35 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5601 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 312748810 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dac079d810, 0x55dac098701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dac0987020,0x55dac281f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e7cb50e16e43b913eb1050a8645668ba1d8ec35' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7178 processed earlier; will process 3851 files now Step #5: ==201742== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dab72929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dabd8f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dabd8da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dabd8da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dab7298d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dab71f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dab71f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dab728ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55daba259f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55daba259f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55daba259f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55daba259f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55daba259f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55daba259f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55daba259f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55daba259f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55daba259f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55daba259f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dabc4eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dab921bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dab9226be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dab8fd2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dab8fd2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dab8fd3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dab8fd2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dab8fd2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dab8fd2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dabd8dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dabd8e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dabd8cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dabd8f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0e1bb61082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dab71f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0988146b84508f290fb94894eadb4d3019450444 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5602 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 313282238 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562109ab6810, 0x562109ca001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562109ca0020,0x56210bb380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0988146b84508f290fb94894eadb4d3019450444' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7179 processed earlier; will process 3850 files now Step #5: ==201778== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5621005ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562106c10898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562106bf35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562106bf34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5621005b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562100512b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56210050d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5621005a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562103572f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562103572f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562103572f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562103572f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562103572f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562103572f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562103572f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562103572f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562103572f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562103572f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562105807f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562102534b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56210253fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5621022ebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5621022ebc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5621022ec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5621022eb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5621022eb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5621022eb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562106bf5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562106bfe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562106be6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562106c11112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7cee8d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56210050bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a3bb1636e90cec8c1542c2a250ec8118d5743ee Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5603 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 313804560 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3f1208810, 0x55a3f13f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3f13f2020,0x55a3f328a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a3bb1636e90cec8c1542c2a250ec8118d5743ee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7180 processed earlier; will process 3849 files now Step #5: ==201814== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a3e7cfd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3ee362898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3ee3455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3ee3454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3e7d03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a3e7c64b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a3e7c5f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3e7cf5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a3eacc4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a3eacc4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a3eacc4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a3eacc4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a3eacc4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a3eacc4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a3eacc4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a3eacc4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a3eacc4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a3eacc4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3ecf59f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3e9c86b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3e9c91be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3e9a3dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3e9a3dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3e9a3e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3e9a3d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3e9a3d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3e9a3d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a3ee347abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a3ee350928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3ee338699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3ee363112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff70c351082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a3e7c5db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5d5b19d95e9c02d60b4b33f79f0dae0b95c244d3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5604 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 314333855 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a26b3c8810, 0x55a26b5b201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a26b5b2020,0x55a26d44a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5d5b19d95e9c02d60b4b33f79f0dae0b95c244d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7181 processed earlier; will process 3848 files now Step #5: ==201850== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a261ebd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a268522898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2685055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2685054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a261ec3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a261e24b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a261e1f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a261eb5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a264e84f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a264e84f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a264e84f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a264e84f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a264e84f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a264e84f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a264e84f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a264e84f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a264e84f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a264e84f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a267119f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a263e46b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a263e51be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a263bfdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a263bfdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a263bfe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a263bfd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a263bfd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a263bfd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a268507abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a268510928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2684f8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a268523112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0bf8d39082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a261e1db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-15513b5629ccbb750579ba81436eb57ea5470be1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5605 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 314868706 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56517ee9b810, 0x56517f08501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56517f085020,0x565180f1d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/15513b5629ccbb750579ba81436eb57ea5470be1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7182 processed earlier; will process 3847 files now Step #5: #1 pulse cov: 11442 ft: 11443 exec/s: 0 rss: 196Mb Step #5: ==201886== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5651759909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56517bff5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56517bfd85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56517bfd84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565175996d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5651758f7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5651758f2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565175988c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565178957f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565178957f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565178957f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565178957f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565178957f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565178957f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565178957f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565178957f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565178957f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565178957f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56517abecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565177919b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565177924be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5651776d0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5651776d0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5651776d1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5651776d0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5651776d0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5651776d0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56517bfdaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56517bfe3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56517bfcb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56517bff6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbd53acc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5651758f0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-027d8b511d793e5c4151ff4566c9e74f1df710ab Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5606 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 315527243 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562b52fd4810, 0x562b531be01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562b531be020,0x562b550560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/027d8b511d793e5c4151ff4566c9e74f1df710ab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7184 processed earlier; will process 3845 files now Step #5: ==201922== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562b49ac99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562b5012e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562b501115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562b501114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b49acfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b49a30b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b49a2b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b49ac1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b4ca90f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b4ca90f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b4ca90f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b4ca90f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b4ca90f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b4ca90f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b4ca90f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b4ca90f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b4ca90f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b4ca90f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562b4ed25f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b4ba52b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b4ba5dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b4b809c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b4b809c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b4b80a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b4b809874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b4b809874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b4b809874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562b50113abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562b5011c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562b50104699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562b5012f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4570a19082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b49a29b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a2ae43db4276e0285bfbea10a4de41934a1a0c77 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5607 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 316061462 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555823e32810, 0x55582401c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55582401c020,0x555825eb40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a2ae43db4276e0285bfbea10a4de41934a1a0c77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7185 processed earlier; will process 3844 files now Step #5: #1 pulse cov: 3897 ft: 3898 exec/s: 0 rss: 180Mb Step #5: ==201958== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55581a9279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555820f8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555820f6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555820f6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55581a92dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55581a88eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55581a889355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55581a91fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55581d8eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55581d8eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55581d8eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55581d8eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55581d8eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55581d8eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55581d8eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55581d8eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55581d8eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55581d8eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55581fb83f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55581c8b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55581c8bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55581c667c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55581c667c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55581c668738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55581c667874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55581c667874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55581c667874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555820f71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555820f7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555820f62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555820f8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb857e1d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55581a887b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5187600ffd7a928c57dd0c8606342ec688b9c224 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5608 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 316625673 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5591b5796810, 0x5591b598001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5591b5980020,0x5591b78180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5187600ffd7a928c57dd0c8606342ec688b9c224' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7187 processed earlier; will process 3842 files now Step #5: #1 pulse cov: 3611 ft: 3612 exec/s: 0 rss: 176Mb Step #5: ==201994== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5591ac28b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5591b28f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5591b28d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5591b28d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5591ac291d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5591ac1f2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5591ac1ed355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5591ac283c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5591af252f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5591af252f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5591af252f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5591af252f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5591af252f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5591af252f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5591af252f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5591af252f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5591af252f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5591af252f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5591b14e7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5591ae214b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5591ae21fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5591adfcbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5591adfcbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5591adfcc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5591adfcb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5591adfcb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5591adfcb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5591b28d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5591b28de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5591b28c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5591b28f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f195990b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5591ac1ebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-894c8f92da6c66f27c681486c358ab8885efe929 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5609 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 317209693 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5563e2c8b810, 0x5563e2e7501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5563e2e75020,0x5563e4d0d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/894c8f92da6c66f27c681486c358ab8885efe929' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7189 processed earlier; will process 3840 files now Step #5: ==202030== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5563d97809c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5563dfde5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5563dfdc85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5563dfdc84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5563d9786d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5563d96e7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5563d96e2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5563d9778c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5563dc747f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5563dc747f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5563dc747f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5563dc747f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5563dc747f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5563dc747f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5563dc747f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5563dc747f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5563dc747f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5563dc747f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5563de9dcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5563db709b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5563db714be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5563db4c0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5563db4c0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5563db4c1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5563db4c0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5563db4c0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5563db4c0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5563dfdcaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5563dfdd3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5563dfdbb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5563dfde6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8fe335d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5563d96e0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bfd3d636c7901ecb13a092271b7dc416a9a50924 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5610 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 317739199 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5563db123810, 0x5563db30d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5563db30d020,0x5563dd1a50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bfd3d636c7901ecb13a092271b7dc416a9a50924' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7190 processed earlier; will process 3839 files now Step #5: ==202066== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5563d1c189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5563d827d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5563d82605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5563d82604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5563d1c1ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5563d1b7fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5563d1b7a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5563d1c10c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5563d4bdff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5563d4bdff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5563d4bdff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5563d4bdff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5563d4bdff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5563d4bdff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5563d4bdff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5563d4bdff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5563d4bdff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5563d4bdff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5563d6e74f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5563d3ba1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5563d3bacbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5563d3958c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5563d3958c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5563d3959738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5563d3958874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5563d3958874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5563d3958874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5563d8262abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5563d826b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5563d8253699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5563d827e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda29afa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5563d1b78b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d5896dd9b0d7dc1f26ffbc9ca62bd2082877ee65 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5611 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 318442786 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564e5a581810, 0x564e5a76b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564e5a76b020,0x564e5c6030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d5896dd9b0d7dc1f26ffbc9ca62bd2082877ee65' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7191 processed earlier; will process 3838 files now Step #5: ==202102== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564e510769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564e576db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564e576be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564e576be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564e5107cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564e50fddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564e50fd8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564e5106ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564e5403df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564e5403df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564e5403df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564e5403df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564e5403df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564e5403df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564e5403df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564e5403df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564e5403df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564e5403df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564e562d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564e52fffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564e5300abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564e52db6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564e52db6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564e52db7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564e52db6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564e52db6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564e52db6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564e576c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564e576c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564e576b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564e576dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6252fa6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564e50fd6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d4d7b2131aa473d87a8fc1b2b2b5999b3b96d531 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5612 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 319108205 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557497adf810, 0x557497cc901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557497cc9020,0x557499b610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d4d7b2131aa473d87a8fc1b2b2b5999b3b96d531' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7192 processed earlier; will process 3837 files now Step #5: ==202138== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55748e5d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557494c39898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557494c1c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557494c1c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55748e5dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55748e53bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55748e536355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55748e5ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55749159bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55749159bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55749159bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55749159bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55749159bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55749159bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55749159bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55749159bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55749159bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55749159bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557493830f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55749055db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557490568be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557490314c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557490314c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557490315738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557490314874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557490314874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557490314874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557494c1eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557494c27928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557494c0f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557494c3a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8fc3a70082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55748e534b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-81aaa1431d1f6dab822a1f262b6e4224fe16509f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5613 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 319649228 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556f2936f810, 0x556f2955901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556f29559020,0x556f2b3f10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/81aaa1431d1f6dab822a1f262b6e4224fe16509f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7193 processed earlier; will process 3836 files now Step #5: ==202174== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556f1fe649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556f264c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556f264ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556f264ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556f1fe6ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556f1fdcbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556f1fdc6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556f1fe5cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556f22e2bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556f22e2bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556f22e2bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556f22e2bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556f22e2bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556f22e2bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556f22e2bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556f22e2bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556f22e2bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556f22e2bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556f250c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556f21dedb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556f21df8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556f21ba4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556f21ba4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556f21ba5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556f21ba4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556f21ba4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556f21ba4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556f264aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556f264b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556f2649f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556f264ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb0ec4c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556f1fdc4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f55d527f87244090784f888afb774cddfb023365 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5614 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 320350914 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56471edaa810, 0x56471ef9401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56471ef94020,0x564720e2c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f55d527f87244090784f888afb774cddfb023365' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7194 processed earlier; will process 3835 files now Step #5: #1 pulse cov: 3996 ft: 3997 exec/s: 0 rss: 179Mb Step #5: ==202210== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56471589f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56471bf04898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56471bee75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56471bee74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647158a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564715806b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564715801355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564715897c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564718866f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564718866f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564718866f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564718866f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564718866f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564718866f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564718866f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564718866f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564718866f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564718866f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56471aafbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564717828b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564717833be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647175dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647175dfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647175e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647175df874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647175df874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647175df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56471bee9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56471bef2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56471beda699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56471bf05112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7eff28402082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647157ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6229583066817a34a2d36a2f7f065c2f84188464 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5615 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 321598838 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bcf3558810, 0x55bcf374201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bcf3742020,0x55bcf55da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6229583066817a34a2d36a2f7f065c2f84188464' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7196 processed earlier; will process 3833 files now Step #5: ==202246== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bcea04d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bcf06b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bcf06955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bcf06954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bcea053d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bce9fb4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bce9faf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bcea045c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bced014f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bced014f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bced014f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bced014f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bced014f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bced014f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bced014f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bced014f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bced014f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bced014f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bcef2a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bcebfd6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bcebfe1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bcebd8dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bcebd8dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bcebd8e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bcebd8d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bcebd8d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bcebd8d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bcf0697abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bcf06a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bcf0688699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bcf06b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa5d2d5c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bce9fadb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a0a7418b18f0de1bc8dc3b4179b2b54202dfbefe Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5616 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 322834793 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558692d01810, 0x558692eeb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558692eeb020,0x558694d830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a0a7418b18f0de1bc8dc3b4179b2b54202dfbefe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7197 processed earlier; will process 3832 files now Step #5: ==202282== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5586897f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55868fe5b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55868fe3e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55868fe3e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5586897fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55868975db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558689758355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5586897eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55868c7bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55868c7bdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55868c7bdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55868c7bdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55868c7bdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55868c7bdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55868c7bdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55868c7bdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55868c7bdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55868c7bdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55868ea52f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55868b77fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55868b78abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55868b536c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55868b536c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55868b537738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55868b536874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55868b536874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55868b536874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55868fe40abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55868fe49928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55868fe31699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55868fe5c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f56a5ff4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558689756b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a020906428e6e706d755ffa8c1ab98bc89009d9a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5617 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 323383869 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bc9b054810, 0x55bc9b23e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bc9b23e020,0x55bc9d0d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a020906428e6e706d755ffa8c1ab98bc89009d9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7198 processed earlier; will process 3831 files now Step #5: ==202318== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bc91b499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bc981ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bc981915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bc981914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bc91b4fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bc91ab0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bc91aab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bc91b41c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bc94b10f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bc94b10f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bc94b10f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bc94b10f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bc94b10f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bc94b10f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bc94b10f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bc94b10f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bc94b10f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bc94b10f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bc96da5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bc93ad2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bc93addbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bc93889c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bc93889c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bc9388a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bc93889874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bc93889874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bc93889874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bc98193abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bc9819c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bc98184699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bc981af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12737f8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bc91aa9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c52419d2e8495a95afdada4e2d7d87699183e6ea Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5618 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 323978037 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e5349b810, 0x563e5368501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e53685020,0x563e5551d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c52419d2e8495a95afdada4e2d7d87699183e6ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7199 processed earlier; will process 3830 files now Step #5: ==202354== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563e49f909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e505f5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e505d85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e505d84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e49f96d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e49ef7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e49ef2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e49f88c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e4cf57f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e4cf57f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e4cf57f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e4cf57f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e4cf57f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e4cf57f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e4cf57f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e4cf57f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e4cf57f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e4cf57f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e4f1ecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e4bf19b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e4bf24be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e4bcd0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e4bcd0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e4bcd1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e4bcd0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e4bcd0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e4bcd0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e505daabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e505e3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e505cb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e505f6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5d10f10082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e49ef0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8d470b8a32fc5172290dcbb3741253e11356a425 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5619 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 324511907 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5561330f6810, 0x5561332e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5561332e0020,0x5561351780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d470b8a32fc5172290dcbb3741253e11356a425' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7200 processed earlier; will process 3829 files now Step #5: ==202390== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556129beb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556130250898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5561302335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5561302334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556129bf1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556129b52b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556129b4d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556129be3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55612cbb2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55612cbb2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55612cbb2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55612cbb2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55612cbb2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55612cbb2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55612cbb2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55612cbb2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55612cbb2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55612cbb2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55612ee47f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55612bb74b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55612bb7fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55612b92bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55612b92bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55612b92c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55612b92b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55612b92b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55612b92b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556130235abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55613023e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556130226699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556130251112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f420ac60082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556129b4bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f52a492217f0048c212dc57578f14370b73148a8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5620 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 325046579 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c81b1e8810, 0x55c81b3d201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c81b3d2020,0x55c81d26a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f52a492217f0048c212dc57578f14370b73148a8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7201 processed earlier; will process 3828 files now Step #5: ==202426== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c811cdd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c818342898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8183255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8183254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c811ce3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c811c44b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c811c3f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c811cd5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c814ca4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c814ca4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c814ca4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c814ca4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c814ca4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c814ca4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c814ca4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c814ca4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c814ca4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c814ca4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c816f39f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c813c66b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c813c71be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c813a1dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c813a1dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c813a1e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c813a1d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c813a1d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c813a1d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c818327abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c818330928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c818318699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c818343112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa9e545082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c811c3db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-545a6b66290c931b9e4186ee53a3b940b9e52c73 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5621 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 325620833 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560c2426b810, 0x560c2445501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560c24455020,0x560c262ed0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/545a6b66290c931b9e4186ee53a3b940b9e52c73' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7202 processed earlier; will process 3827 files now Step #5: ==202462== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560c1ad609c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560c213c5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560c213a85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560c213a84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560c1ad66d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560c1acc7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560c1acc2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560c1ad58c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560c1dd27f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560c1dd27f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560c1dd27f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560c1dd27f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560c1dd27f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560c1dd27f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560c1dd27f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560c1dd27f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560c1dd27f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560c1dd27f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560c1ffbcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560c1cce9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560c1ccf4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560c1caa0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560c1caa0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560c1caa1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560c1caa0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560c1caa0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560c1caa0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560c213aaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560c213b3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560c2139b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560c213c6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5bda2da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560c1acc0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8d68338d73ce1a609f75b1e00b7953ff894c7a7c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5622 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 326386387 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c5e444b810, 0x55c5e463501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c5e4635020,0x55c5e64cd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d68338d73ce1a609f75b1e00b7953ff894c7a7c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7203 processed earlier; will process 3826 files now Step #5: ==202498== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c5daf409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c5e15a5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c5e15885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c5e15884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c5daf46d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c5daea7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c5daea2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c5daf38c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c5ddf07f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c5ddf07f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c5ddf07f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c5ddf07f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c5ddf07f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c5ddf07f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c5ddf07f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c5ddf07f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c5ddf07f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c5ddf07f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c5e019cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c5dcec9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c5dced4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c5dcc80c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c5dcc80c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c5dcc81738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c5dcc80874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c5dcc80874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c5dcc80874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c5e158aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c5e1593928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c5e157b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c5e15a6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f79c50b6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c5daea0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6a818e8f5a29bd726f1fa0e19ff8aed8629b58e1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5623 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 326918726 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564facb7b810, 0x564facd6501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564facd65020,0x564faebfd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a818e8f5a29bd726f1fa0e19ff8aed8629b58e1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7204 processed earlier; will process 3825 files now Step #5: ==202534== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564fa36709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564fa9cd5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564fa9cb85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564fa9cb84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564fa3676d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564fa35d7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564fa35d2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564fa3668c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564fa6637f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564fa6637f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564fa6637f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564fa6637f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564fa6637f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564fa6637f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564fa6637f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564fa6637f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564fa6637f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564fa6637f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564fa88ccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564fa55f9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564fa5604be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564fa53b0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564fa53b0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564fa53b1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564fa53b0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564fa53b0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564fa53b0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564fa9cbaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564fa9cc3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564fa9cab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564fa9cd6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f60d9bed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564fa35d0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-26a4cf50e69e332938a3d6e2154d8c9dda78f8bd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5624 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 327451253 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c6bfe95810, 0x55c6c007f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c6c007f020,0x55c6c1f170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/26a4cf50e69e332938a3d6e2154d8c9dda78f8bd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7205 processed earlier; will process 3824 files now Step #5: #1 pulse cov: 4018 ft: 4019 exec/s: 0 rss: 180Mb Step #5: ==202570== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c6b698a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c6bcfef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c6bcfd25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c6bcfd24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c6b6990d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6b68f1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6b68ec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c6b6982c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c6b9951f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c6b9951f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c6b9951f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c6b9951f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c6b9951f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c6b9951f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c6b9951f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c6b9951f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c6b9951f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c6b9951f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c6bbbe6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6b8913b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c6b891ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6b86cac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6b86cac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6b86cb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6b86ca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6b86ca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6b86ca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c6bcfd4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c6bcfdd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c6bcfc5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c6bcff0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1fb9a0b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6b68eab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-03705e25c619cf0716a9c5fca9a7953457402391 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5625 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 328040391 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558cfff7a810, 0x558d0016401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558d00164020,0x558d01ffc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03705e25c619cf0716a9c5fca9a7953457402391' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7207 processed earlier; will process 3822 files now Step #5: ==202606== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558cf6a6f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558cfd0d4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558cfd0b75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558cfd0b74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558cf6a75d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558cf69d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558cf69d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558cf6a67c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558cf9a36f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558cf9a36f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558cf9a36f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558cf9a36f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558cf9a36f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558cf9a36f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558cf9a36f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558cf9a36f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558cf9a36f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558cf9a36f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558cfbccbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558cf89f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558cf8a03be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558cf87afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558cf87afc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558cf87b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558cf87af874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558cf87af874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558cf87af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558cfd0b9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558cfd0c2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558cfd0aa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558cfd0d5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb45e708082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558cf69cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b7810e8f18b7735b30e87874ded74a38db0c942c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5626 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 328724155 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562ddd3f4810, 0x562ddd5de01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562ddd5de020,0x562ddf4760e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7810e8f18b7735b30e87874ded74a38db0c942c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7208 processed earlier; will process 3821 files now Step #5: #1 pulse cov: 4135 ft: 4136 exec/s: 0 rss: 179Mb Step #5: ==202642== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562dd3ee99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562dda54e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562dda5315dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562dda5314fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562dd3eefd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562dd3e50b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562dd3e4b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562dd3ee1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562dd6eb0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562dd6eb0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562dd6eb0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562dd6eb0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562dd6eb0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562dd6eb0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562dd6eb0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562dd6eb0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562dd6eb0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562dd6eb0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562dd9145f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562dd5e72b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562dd5e7dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562dd5c29c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562dd5c29c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562dd5c2a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562dd5c29874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562dd5c29874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562dd5c29874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562dda533abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562dda53c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562dda524699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562dda54f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9a4c57d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562dd3e49b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-36d094bd83f35ca995d2241cac79f3a9e3291bfc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5627 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 329300314 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5564bb763810, 0x5564bb94d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564bb94d020,0x5564bd7e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/36d094bd83f35ca995d2241cac79f3a9e3291bfc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7210 processed earlier; will process 3819 files now Step #5: ==202678== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5564b22589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564b88bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564b88a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564b88a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564b225ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5564b21bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5564b21ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564b2250c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564b521ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564b521ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564b521ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564b521ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564b521ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564b521ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564b521ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564b521ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564b521ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564b521ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5564b74b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5564b41e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5564b41ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5564b3f98c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5564b3f98c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5564b3f99738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5564b3f98874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5564b3f98874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5564b3f98874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564b88a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564b88ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564b8893699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564b88be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9980ee0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5564b21b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3d5d6b78e3ffee11dc5ee45b5b881d6ca2aa0d5f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5628 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 329829891 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f1d1fba810, 0x55f1d21a401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f1d21a4020,0x55f1d403c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3d5d6b78e3ffee11dc5ee45b5b881d6ca2aa0d5f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7211 processed earlier; will process 3818 files now Step #5: ==202714== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f1c8aaf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f1cf114898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1cf0f75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1cf0f74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f1c8ab5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f1c8a16b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f1c8a11355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f1c8aa7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f1cba76f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f1cba76f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f1cba76f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f1cba76f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f1cba76f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f1cba76f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f1cba76f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f1cba76f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f1cba76f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f1cba76f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f1cdd0bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f1caa38b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f1caa43be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f1ca7efc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f1ca7efc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f1ca7f0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f1ca7ef874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f1ca7ef874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f1ca7ef874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f1cf0f9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f1cf102928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f1cf0ea699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f1cf115112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f128a855082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f1c8a0fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-befbceaf52c626b731ed976ba4d16cdba888b5a7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5629 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 330542424 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647604a0810, 0x56476068a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56476068a020,0x5647625220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/befbceaf52c626b731ed976ba4d16cdba888b5a7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7212 processed earlier; will process 3817 files now Step #5: ==202750== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564756f959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56475d5fa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56475d5dd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56475d5dd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564756f9bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564756efcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564756ef7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564756f8dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564759f5cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564759f5cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564759f5cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564759f5cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564759f5cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564759f5cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564759f5cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564759f5cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564759f5cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564759f5cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56475c1f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564758f1eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564758f29be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564758cd5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564758cd5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564758cd6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564758cd5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564758cd5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564758cd5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56475d5dfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56475d5e8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56475d5d0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56475d5fb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f15c1fc6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564756ef5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ad82add771530412d16604aaf3a6342a3d9297ae Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5630 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 331079627 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5585b79b3810, 0x5585b7b9d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5585b7b9d020,0x5585b9a350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad82add771530412d16604aaf3a6342a3d9297ae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7213 processed earlier; will process 3816 files now Step #5: #1 pulse cov: 3899 ft: 3900 exec/s: 0 rss: 179Mb Step #5: ==202786== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5585ae4a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5585b4b0d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5585b4af05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5585b4af04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5585ae4aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5585ae40fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5585ae40a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5585ae4a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5585b146ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5585b146ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5585b146ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5585b146ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5585b146ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5585b146ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5585b146ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5585b146ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5585b146ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5585b146ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5585b3704f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5585b0431b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5585b043cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5585b01e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5585b01e8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5585b01e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5585b01e8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5585b01e8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5585b01e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5585b4af2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5585b4afb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5585b4ae3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5585b4b0e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8cc8e14082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5585ae408b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e2cde200ea04fd83be0c04f691707e01cdc5437b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5631 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 331653515 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5592fb131810, 0x5592fb31b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5592fb31b020,0x5592fd1b30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e2cde200ea04fd83be0c04f691707e01cdc5437b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7215 processed earlier; will process 3814 files now Step #5: ==202822== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5592f1c269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5592f828b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5592f826e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5592f826e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5592f1c2cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5592f1b8db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5592f1b88355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5592f1c1ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5592f4bedf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5592f4bedf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5592f4bedf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5592f4bedf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5592f4bedf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5592f4bedf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5592f4bedf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5592f4bedf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5592f4bedf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5592f4bedf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5592f6e82f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5592f3bafb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5592f3bbabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5592f3966c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5592f3966c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5592f3967738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5592f3966874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5592f3966874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5592f3966874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5592f8270abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5592f8279928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5592f8261699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5592f828c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f343d196082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5592f1b86b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2019221608b3accad56063b94d8c22f1f8ff61e6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5632 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 332727723 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5632d6b6f810, 0x5632d6d5901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5632d6d59020,0x5632d8bf10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2019221608b3accad56063b94d8c22f1f8ff61e6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7216 processed earlier; will process 3813 files now Step #5: ==202858== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5632cd6649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5632d3cc9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5632d3cac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5632d3cac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5632cd66ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5632cd5cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5632cd5c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5632cd65cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5632d062bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5632d062bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5632d062bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5632d062bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5632d062bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5632d062bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5632d062bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5632d062bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5632d062bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5632d062bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5632d28c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5632cf5edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5632cf5f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5632cf3a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5632cf3a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5632cf3a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5632cf3a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5632cf3a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5632cf3a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5632d3caeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5632d3cb7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5632d3c9f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5632d3cca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5b7c97d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5632cd5c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-acd37e523d4716599b6479c2f392bb9f6a930772 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5633 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 333395698 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5587c6b64810, 0x5587c6d4e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5587c6d4e020,0x5587c8be60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/acd37e523d4716599b6479c2f392bb9f6a930772' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7217 processed earlier; will process 3812 files now Step #5: ==202894== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5587bd6599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5587c3cbe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5587c3ca15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5587c3ca14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5587bd65fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5587bd5c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5587bd5bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5587bd651c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5587c0620f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5587c0620f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5587c0620f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5587c0620f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5587c0620f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5587c0620f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5587c0620f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5587c0620f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5587c0620f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5587c0620f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5587c28b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5587bf5e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5587bf5edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5587bf399c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5587bf399c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5587bf39a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5587bf399874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5587bf399874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5587bf399874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5587c3ca3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5587c3cac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5587c3c94699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5587c3cbf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f932d903082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5587bd5b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-77a619aa93345390a588984c14f7c710f95ca2aa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5634 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 333967698 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5619ab022810, 0x5619ab20c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5619ab20c020,0x5619ad0a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/77a619aa93345390a588984c14f7c710f95ca2aa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7218 processed earlier; will process 3811 files now Step #5: #1 pulse cov: 3802 ft: 3803 exec/s: 0 rss: 178Mb Step #5: ==202930== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5619a1b179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5619a817c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5619a815f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5619a815f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5619a1b1dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5619a1a7eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5619a1a79355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5619a1b0fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5619a4adef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5619a4adef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5619a4adef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5619a4adef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5619a4adef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5619a4adef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5619a4adef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5619a4adef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5619a4adef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5619a4adef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5619a6d73f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5619a3aa0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5619a3aabbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5619a3857c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5619a3857c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5619a3858738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5619a3857874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5619a3857874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5619a3857874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5619a8161abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5619a816a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5619a8152699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5619a817d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ec3a38082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5619a1a77b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-49b143c1eccec1ec900cab47f449fca3ba7f67a0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5635 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 335237998 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d443d2810, 0x561d445bc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d445bc020,0x561d464540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/49b143c1eccec1ec900cab47f449fca3ba7f67a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7220 processed earlier; will process 3809 files now Step #5: #1 pulse cov: 3650 ft: 3651 exec/s: 0 rss: 177Mb Step #5: ==202966== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d3aec79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d4152c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d4150f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d4150f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d3aecdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d3ae2eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d3ae29355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d3aebfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d3de8ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d3de8ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d3de8ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d3de8ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d3de8ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d3de8ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d3de8ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d3de8ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d3de8ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d3de8ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d40123f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d3ce50b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d3ce5bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d3cc07c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d3cc07c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d3cc08738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d3cc07874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d3cc07874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d3cc07874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d41511abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d4151a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d41502699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d4152d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f031ca78082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d3ae27b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9100a7293a2bc222385fccc65764fa6d4b23d39d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5636 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 335905568 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55731c398810, 0x55731c58201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55731c582020,0x55731e41a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9100a7293a2bc222385fccc65764fa6d4b23d39d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7222 processed earlier; will process 3807 files now Step #5: ==203002== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557312e8d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5573194f2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5573194d55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5573194d54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557312e93d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557312df4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557312def355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557312e85c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557315e54f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557315e54f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557315e54f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557315e54f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557315e54f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557315e54f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557315e54f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557315e54f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557315e54f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557315e54f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5573180e9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557314e16b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557314e21be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557314bcdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557314bcdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557314bce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557314bcd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557314bcd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557314bcd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5573194d7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5573194e0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5573194c8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5573194f3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb3ea81f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557312dedb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-320826fe736cf504c34cc7db614e27348e19780f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5637 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 336542834 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647c72ee810, 0x5647c74d801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5647c74d8020,0x5647c93700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/320826fe736cf504c34cc7db614e27348e19780f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7223 processed earlier; will process 3806 files now Step #5: ==203038== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647bdde39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647c4448898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647c442b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647c442b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647bdde9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647bdd4ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647bdd45355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647bdddbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647c0daaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647c0daaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647c0daaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647c0daaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647c0daaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647c0daaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647c0daaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647c0daaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647c0daaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647c0daaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647c303ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647bfd6cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647bfd77be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647bfb23c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647bfb23c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647bfb24738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647bfb23874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647bfb23874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647bfb23874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647c442dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647c4436928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647c441e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647c4449112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efd9704e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647bdd43b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0bba4d470959642d05a1f5f934d348bf05ff4e33 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5638 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 337066465 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563454ab2810, 0x563454c9c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563454c9c020,0x563456b340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0bba4d470959642d05a1f5f934d348bf05ff4e33' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7224 processed earlier; will process 3805 files now Step #5: ==203074== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56344b5a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563451c0c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563451bef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563451bef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56344b5add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56344b50eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56344b509355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56344b59fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56344e56ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56344e56ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56344e56ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56344e56ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56344e56ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56344e56ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56344e56ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56344e56ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56344e56ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56344e56ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563450803f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56344d530b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56344d53bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56344d2e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56344d2e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56344d2e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56344d2e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56344d2e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56344d2e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563451bf1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563451bfa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563451be2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563451c0d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8214a09082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56344b507b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-eb81ef1051ebbbc02ccd7ff8f9493b9c5b54d7ed Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5639 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 337765604 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d98c7bc810, 0x55d98c9a601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d98c9a6020,0x55d98e83e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eb81ef1051ebbbc02ccd7ff8f9493b9c5b54d7ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7225 processed earlier; will process 3804 files now Step #5: ==203110== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d9832b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d989916898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d9898f95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d9898f94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d9832b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d983218b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d983213355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d9832a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d986278f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d986278f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d986278f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d986278f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d986278f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d986278f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d986278f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d986278f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d986278f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d986278f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d98850df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d98523ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d985245be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d984ff1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d984ff1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d984ff2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d984ff1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d984ff1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d984ff1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d9898fbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d989904928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d9898ec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d989917112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe7b36b5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d983211b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bf91260a61caa1b22607c2060a7e139cd4fa8933 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5640 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 338407599 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af4d897810, 0x55af4da8101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af4da81020,0x55af4f9190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf91260a61caa1b22607c2060a7e139cd4fa8933' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7226 processed earlier; will process 3803 files now Step #5: ==203146== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55af4438c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af4a9f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af4a9d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af4a9d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55af44392d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55af442f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55af442ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55af44384c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55af47353f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55af47353f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55af47353f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55af47353f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55af47353f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55af47353f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55af47353f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55af47353f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55af47353f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55af47353f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af495e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af46315b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af46320be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af460ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af460ccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af460cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af460cc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af460cc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af460cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af4a9d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af4a9df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af4a9c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af4a9f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ccabe0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55af442ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-05f93d2d25864940ee4ae99f1e3ea2ff1de0f745 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5641 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 339062295 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560eb949c810, 0x560eb968601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560eb9686020,0x560ebb51e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/05f93d2d25864940ee4ae99f1e3ea2ff1de0f745' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7227 processed earlier; will process 3802 files now Step #5: ==203182== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560eaff919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560eb65f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560eb65d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560eb65d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560eaff97d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560eafef8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560eafef3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560eaff89c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560eb2f58f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560eb2f58f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560eb2f58f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560eb2f58f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560eb2f58f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560eb2f58f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560eb2f58f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560eb2f58f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560eb2f58f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560eb2f58f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560eb51edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560eb1f1ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560eb1f25be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560eb1cd1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560eb1cd1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560eb1cd2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560eb1cd1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560eb1cd1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560eb1cd1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560eb65dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560eb65e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560eb65cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560eb65f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdac507a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560eafef1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-977f1a700b75ffe478ee5efa3407b898630e302a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5642 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 339588627 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a2c736810, 0x560a2c92001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a2c920020,0x560a2e7b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/977f1a700b75ffe478ee5efa3407b898630e302a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7228 processed earlier; will process 3801 files now Step #5: ==203218== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560a2322b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a29890898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a298735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a298734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a23231d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a23192b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a2318d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a23223c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a261f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a261f2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a261f2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a261f2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a261f2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a261f2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a261f2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a261f2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a261f2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a261f2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a28487f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a251b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a251bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a24f6bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a24f6bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a24f6c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a24f6b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a24f6b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a24f6b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a29875abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a2987e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a29866699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a29891112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3eb9da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a2318bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-acda1d4260e003163faebfb0b0b041ada03795e8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5643 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 340129567 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f50d2f8810, 0x55f50d4e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f50d4e2020,0x55f50f37a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/acda1d4260e003163faebfb0b0b041ada03795e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7229 processed earlier; will process 3800 files now Step #5: #1 pulse cov: 11064 ft: 11065 exec/s: 0 rss: 198Mb Step #5: ==203254== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f503ded9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f50a452898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f50a4355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f50a4354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f503df3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f503d54b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f503d4f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f503de5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f506db4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f506db4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f506db4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f506db4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f506db4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f506db4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f506db4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f506db4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f506db4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f506db4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f509049f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f505d76b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f505d81be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f505b2dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f505b2dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f505b2e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f505b2d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f505b2d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f505b2d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f50a437abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f50a440928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f50a428699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f50a453112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6102172082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f503d4db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-708c850953b1ccf092f5b4551c4836d861183436 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5644 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 340753960 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c70b9f810, 0x562c70d8901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c70d89020,0x562c72c210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/708c850953b1ccf092f5b4551c4836d861183436' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7231 processed earlier; will process 3798 files now Step #5: #1 pulse cov: 3782 ft: 3783 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4731 ft: 5237 exec/s: 0 rss: 179Mb Step #5: ==203290== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562c676949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c6dcf9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c6dcdc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c6dcdc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c6769ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c675fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c675f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c6768cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c6a65bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c6a65bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c6a65bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c6a65bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c6a65bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c6a65bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c6a65bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c6a65bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c6a65bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c6a65bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c6c8f0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562c6961db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562c69628be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562c693d4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562c693d4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562c693d5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562c693d4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562c693d4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562c693d4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c6dcdeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c6dce7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c6dccf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c6dcfa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf8803a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c675f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7d9c553e264bec01a82cffb5ee2c9e444ee3606 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5645 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 342069593 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ac0ce2810, 0x555ac0ecc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ac0ecc020,0x555ac2d640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7d9c553e264bec01a82cffb5ee2c9e444ee3606' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7234 processed earlier; will process 3795 files now Step #5: ==203326== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555ab77d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555abde3c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555abde1f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555abde1f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555ab77ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555ab773eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555ab7739355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555ab77cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555aba79ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555aba79ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555aba79ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555aba79ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555aba79ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555aba79ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555aba79ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555aba79ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555aba79ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555aba79ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555abca33f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ab9760b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ab976bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ab9517c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ab9517c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ab9518738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ab9517874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ab9517874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ab9517874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555abde21abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555abde2a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555abde12699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555abde3d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2df8c52082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555ab7737b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d2ad712574ee815e5a9c70fd9749f0c5e6a51525 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5646 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 342619540 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e6800cd810, 0x55e6802b701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e6802b7020,0x55e68214f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d2ad712574ee815e5a9c70fd9749f0c5e6a51525' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7235 processed earlier; will process 3794 files now Step #5: ==203362== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e676bc29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e67d227898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e67d20a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e67d20a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e676bc8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e676b29b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e676b24355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e676bbac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e679b89f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e679b89f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e679b89f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e679b89f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e679b89f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e679b89f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e679b89f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e679b89f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e679b89f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e679b89f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e67be1ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e678b4bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e678b56be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e678902c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e678902c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e678903738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e678902874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e678902874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e678902874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e67d20cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e67d215928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e67d1fd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e67d228112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd56012f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e676b22b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5500a7a4a19741e6fcba0e0e6105755f4c75596a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5647 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 343150699 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559612027810, 0x55961221101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559612211020,0x5596140a90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5500a7a4a19741e6fcba0e0e6105755f4c75596a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7236 processed earlier; will process 3793 files now Step #5: ==203398== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559608b1c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55960f181898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55960f1645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55960f1644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559608b22d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559608a83b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559608a7e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559608b14c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55960bae3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55960bae3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55960bae3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55960bae3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55960bae3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55960bae3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55960bae3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55960bae3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55960bae3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55960bae3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55960dd78f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55960aaa5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55960aab0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55960a85cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55960a85cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55960a85d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55960a85c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55960a85c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55960a85c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55960f166abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55960f16f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55960f157699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55960f182112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5df092c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559608a7cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-af2795e27f6a2fd655e701d5dad718fdd3bb494c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5648 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 343714948 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56101ae55810, 0x56101b03f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56101b03f020,0x56101ced70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af2795e27f6a2fd655e701d5dad718fdd3bb494c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7237 processed earlier; will process 3792 files now Step #5: ==203434== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56101194a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561017faf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561017f925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561017f924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561011950d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610118b1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610118ac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561011942c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561014911f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561014911f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561014911f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561014911f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561014911f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561014911f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561014911f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561014911f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561014911f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561014911f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561016ba6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610138d3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610138debe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56101368ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56101368ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56101368b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56101368a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56101368a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56101368a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561017f94abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561017f9d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561017f85699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561017fb0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f31637e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610118aab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d956326d16fe1995ebaa6bd1a5cb9493cc714e52 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5649 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 344300932 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a2db684810, 0x55a2db86e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a2db86e020,0x55a2dd7060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d956326d16fe1995ebaa6bd1a5cb9493cc714e52' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7238 processed earlier; will process 3791 files now Step #5: ==203470== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a2d21799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a2d87de898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2d87c15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2d87c14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a2d217fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a2d20e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a2d20db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a2d2171c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a2d5140f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a2d5140f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a2d5140f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a2d5140f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a2d5140f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a2d5140f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a2d5140f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a2d5140f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a2d5140f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a2d5140f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a2d73d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a2d4102b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a2d410dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a2d3eb9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a2d3eb9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a2d3eba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a2d3eb9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a2d3eb9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a2d3eb9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a2d87c3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a2d87cc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2d87b4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a2d87df112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac80e85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a2d20d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9f43e10bab135826b1900ab64f224db30c15f8e1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5650 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 344838129 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ef900cd810, 0x55ef902b701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ef902b7020,0x55ef9214f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f43e10bab135826b1900ab64f224db30c15f8e1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7239 processed earlier; will process 3790 files now Step #5: #1 pulse cov: 3827 ft: 3828 exec/s: 0 rss: 180Mb Step #5: ==203506== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ef86bc29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ef8d227898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ef8d20a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ef8d20a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef86bc8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef86b29b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef86b24355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef86bbac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef89b89f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef89b89f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef89b89f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef89b89f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef89b89f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef89b89f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef89b89f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef89b89f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef89b89f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef89b89f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef8be1ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef88b4bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef88b56be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef88902c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef88902c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef88903738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef88902874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef88902874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef88902874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ef8d20cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ef8d215928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ef8d1fd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ef8d228112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe08a746082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef86b22b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bb5a3ce5bd0e95b3c07c734c8d856ac343fca082 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5651 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 345547419 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556ee42b2810, 0x556ee449c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556ee449c020,0x556ee63340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bb5a3ce5bd0e95b3c07c734c8d856ac343fca082' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7241 processed earlier; will process 3788 files now Step #5: ==203542== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556edada79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556ee140c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556ee13ef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556ee13ef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556edadadd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556edad0eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556edad09355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556edad9fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556eddd6ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556eddd6ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556eddd6ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556eddd6ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556eddd6ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556eddd6ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556eddd6ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556eddd6ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556eddd6ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556eddd6ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556ee0003f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556edcd30b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556edcd3bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556edcae7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556edcae7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556edcae8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556edcae7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556edcae7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556edcae7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556ee13f1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556ee13fa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556ee13e2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556ee140d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5f5de81082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556edad07b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-af60b6a1a099742f6c6d2f17b83681d3d17fd4ad Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5652 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 346113331 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55de18999810, 0x55de18b8301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55de18b83020,0x55de1aa1b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af60b6a1a099742f6c6d2f17b83681d3d17fd4ad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7242 processed earlier; will process 3787 files now Step #5: ==203578== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55de0f48e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55de15af3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55de15ad65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55de15ad64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55de0f494d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55de0f3f5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55de0f3f0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55de0f486c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55de12455f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55de12455f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55de12455f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55de12455f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55de12455f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55de12455f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55de12455f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55de12455f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55de12455f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55de12455f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55de146eaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55de11417b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55de11422be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55de111cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55de111cec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55de111cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55de111ce874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55de111ce874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55de111ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55de15ad8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55de15ae1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55de15ac9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55de15af4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f069fdf8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55de0f3eeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a3b830b521f690527cc19f8849e3e5b801282af0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5653 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 346636312 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fafa284810, 0x55fafa46e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fafa46e020,0x55fafc3060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a3b830b521f690527cc19f8849e3e5b801282af0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7243 processed earlier; will process 3786 files now Step #5: #1 pulse cov: 3588 ft: 3589 exec/s: 0 rss: 180Mb Step #5: ==203614== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55faf0d799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55faf73de898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55faf73c15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55faf73c14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55faf0d7fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55faf0ce0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55faf0cdb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55faf0d71c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55faf3d40f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55faf3d40f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55faf3d40f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55faf3d40f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55faf3d40f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55faf3d40f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55faf3d40f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55faf3d40f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55faf3d40f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55faf3d40f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55faf5fd5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55faf2d02b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55faf2d0dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55faf2ab9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55faf2ab9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55faf2aba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55faf2ab9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55faf2ab9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55faf2ab9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55faf73c3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55faf73cc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55faf73b4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55faf73df112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb329db082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55faf0cd9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-77da0baf34ffb8573c26794cba00a0bc797ab6f5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5654 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 347209577 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ba257be810, 0x55ba259a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ba259a8020,0x55ba278400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/77da0baf34ffb8573c26794cba00a0bc797ab6f5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7245 processed earlier; will process 3784 files now Step #5: ==203650== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ba1c2b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ba22918898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ba228fb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ba228fb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ba1c2b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ba1c21ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ba1c215355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ba1c2abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ba1f27af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ba1f27af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ba1f27af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ba1f27af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ba1f27af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ba1f27af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ba1f27af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ba1f27af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ba1f27af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ba1f27af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ba2150ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ba1e23cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ba1e247be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ba1dff3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ba1dff3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ba1dff4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ba1dff3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ba1dff3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ba1dff3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ba228fdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ba22906928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ba228ee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ba22919112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5ee68d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ba1c213b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-27f286ef81bacafeb9819300b982ed5978d432fc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5655 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 348466308 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55da84783810, 0x55da8496d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55da8496d020,0x55da868050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/27f286ef81bacafeb9819300b982ed5978d432fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7246 processed earlier; will process 3783 files now Step #5: ==203686== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55da7b2789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55da818dd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55da818c05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55da818c04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55da7b27ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55da7b1dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55da7b1da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55da7b270c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55da7e23ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55da7e23ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55da7e23ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55da7e23ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55da7e23ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55da7e23ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55da7e23ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55da7e23ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55da7e23ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55da7e23ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55da804d4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55da7d201b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55da7d20cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55da7cfb8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55da7cfb8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55da7cfb9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55da7cfb8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55da7cfb8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55da7cfb8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55da818c2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55da818cb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55da818b3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55da818de112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c2a698082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55da7b1d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-89c1e3a7d7357c5a00d42dde6a437bfb93828580 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5656 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 348999032 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e699c48810, 0x55e699e3201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e699e32020,0x55e69bcca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/89c1e3a7d7357c5a00d42dde6a437bfb93828580' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7247 processed earlier; will process 3782 files now Step #5: ==203722== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e69073d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e696da2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e696d855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e696d854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e690743d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e6906a4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e69069f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e690735c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e693704f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e693704f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e693704f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e693704f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e693704f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e693704f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e693704f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e693704f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e693704f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e693704f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e695999f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e6926c6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e6926d1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e69247dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e69247dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e69247e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e69247d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e69247d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e69247d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e696d87abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e696d90928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e696d78699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e696da3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe753365082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e69069db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-72c3ab415a87244a7541c7bd73eebc3ecf583b68 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5657 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 350249743 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d3a2ea9810, 0x55d3a309301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d3a3093020,0x55d3a4f2b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/72c3ab415a87244a7541c7bd73eebc3ecf583b68' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7248 processed earlier; will process 3781 files now Step #5: ==203758== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d39999e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d3a0003898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d39ffe65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d39ffe64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d3999a4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d399905b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d399900355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d399996c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d39c965f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d39c965f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d39c965f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d39c965f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d39c965f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d39c965f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d39c965f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d39c965f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d39c965f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d39c965f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d39ebfaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d39b927b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d39b932be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d39b6dec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d39b6dec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d39b6df738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d39b6de874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d39b6de874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d39b6de874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d39ffe8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d39fff1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d39ffd9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d3a0004112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8268346082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d3998feb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d3a65946bd5b9755f6834b51f77731388c6e6d23 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5658 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 350768563 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56204b609810, 0x56204b7f301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56204b7f3020,0x56204d68b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d3a65946bd5b9755f6834b51f77731388c6e6d23' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7249 processed earlier; will process 3780 files now Step #5: ==203794== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5620420fe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562048763898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5620487465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5620487464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562042104d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562042065b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562042060355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5620420f6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5620450c5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5620450c5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5620450c5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5620450c5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5620450c5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5620450c5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5620450c5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5620450c5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5620450c5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5620450c5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56204735af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562044087b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562044092be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562043e3ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562043e3ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562043e3f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562043e3e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562043e3e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562043e3e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562048748abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562048751928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562048739699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562048764112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f382c090082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56204205eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-17f586c8dcda16f3acd8054ba0a37fb390724aa7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5659 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 351303134 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564b1133a810, 0x564b1152401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564b11524020,0x564b133bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/17f586c8dcda16f3acd8054ba0a37fb390724aa7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7250 processed earlier; will process 3779 files now Step #5: #1 pulse cov: 3765 ft: 3766 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 3899 ft: 4219 exec/s: 0 rss: 180Mb Step #5: ==203830== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564b07e2f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564b0e494898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564b0e4775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564b0e4774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564b07e35d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564b07d96b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564b07d91355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564b07e27c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564b0adf6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564b0adf6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564b0adf6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564b0adf6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564b0adf6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564b0adf6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564b0adf6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564b0adf6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564b0adf6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564b0adf6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564b0d08bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564b09db8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564b09dc3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564b09b6fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564b09b6fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564b09b70738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564b09b6f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564b09b6f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564b09b6f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564b0e479abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564b0e482928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564b0e46a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564b0e495112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9911bc1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564b07d8fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-350f90b9b25f027dcfcf387f8e07162c5d2b29c2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5660 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 352031141 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565412f61810, 0x56541314b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56541314b020,0x565414fe30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/350f90b9b25f027dcfcf387f8e07162c5d2b29c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7253 processed earlier; will process 3776 files now Step #5: #1 pulse cov: 10937 ft: 10938 exec/s: 0 rss: 197Mb Step #5: ==203866== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565409a569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5654100bb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56541009e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56541009e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565409a5cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5654099bdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5654099b8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565409a4ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56540ca1df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56540ca1df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56540ca1df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56540ca1df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56540ca1df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56540ca1df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56540ca1df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56540ca1df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56540ca1df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56540ca1df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56540ecb2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56540b9dfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56540b9eabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56540b796c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56540b796c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56540b797738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56540b796874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56540b796874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56540b796874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5654100a0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5654100a9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565410091699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5654100bc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2220dfd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5654099b6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3b1d36f4096d19fe82f9711a67687a1d85744c9d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5661 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 352732967 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560853f90810, 0x56085417a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56085417a020,0x5608560120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3b1d36f4096d19fe82f9711a67687a1d85744c9d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7255 processed earlier; will process 3774 files now Step #5: ==203902== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56084aa859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5608510ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608510cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608510cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56084aa8bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56084a9ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56084a9e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56084aa7dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56084da4cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56084da4cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56084da4cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56084da4cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56084da4cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56084da4cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56084da4cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56084da4cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56084da4cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56084da4cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56084fce1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56084ca0eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56084ca19be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56084c7c5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56084c7c5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56084c7c6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56084c7c5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56084c7c5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56084c7c5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5608510cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5608510d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5608510c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5608510eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff1ddf5d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56084a9e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8bb4ff8170da2d76aa712987dc47fd55a131aa7a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5662 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 353305164 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ef704aa810, 0x55ef7069401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ef70694020,0x55ef7252c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8bb4ff8170da2d76aa712987dc47fd55a131aa7a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7256 processed earlier; will process 3773 files now Step #5: #1 pulse cov: 11932 ft: 11933 exec/s: 0 rss: 199Mb Step #5: ==203938== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ef66f9f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ef6d604898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ef6d5e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ef6d5e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef66fa5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef66f06b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef66f01355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef66f97c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef69f66f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef69f66f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef69f66f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef69f66f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef69f66f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef69f66f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef69f66f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef69f66f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef69f66f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef69f66f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef6c1fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef68f28b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef68f33be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef68cdfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef68cdfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef68ce0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef68cdf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef68cdf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef68cdf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ef6d5e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ef6d5f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ef6d5da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ef6d605112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd5f9df0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef66effb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-614c7980c8d1ea909d1444c95b4b62652efb74cf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5663 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 353903865 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5583e5959810, 0x5583e5b4301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5583e5b43020,0x5583e79db0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/614c7980c8d1ea909d1444c95b4b62652efb74cf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7258 processed earlier; will process 3771 files now Step #5: ==203974== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5583dc44e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5583e2ab3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583e2a965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583e2a964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5583dc454d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5583dc3b5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5583dc3b0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5583dc446c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5583df415f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5583df415f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5583df415f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5583df415f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5583df415f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5583df415f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5583df415f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5583df415f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5583df415f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5583df415f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5583e16aaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5583de3d7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5583de3e2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5583de18ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5583de18ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5583de18f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5583de18e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5583de18e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5583de18e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5583e2a98abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5583e2aa1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5583e2a89699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5583e2ab4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6552ff8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5583dc3aeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-544caf2ac856092ad8d69310f263fe4d1a1b348a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5664 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 354437773 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f67909c810, 0x55f67928601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f679286020,0x55f67b11e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/544caf2ac856092ad8d69310f263fe4d1a1b348a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7259 processed earlier; will process 3770 files now Step #5: ==204010== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f66fb919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f6761f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f6761d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f6761d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f66fb97d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f66faf8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f66faf3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f66fb89c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f672b58f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f672b58f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f672b58f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f672b58f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f672b58f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f672b58f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f672b58f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f672b58f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f672b58f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f672b58f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f674dedf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f671b1ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f671b25be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f6718d1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f6718d1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f6718d2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f6718d1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f6718d1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f6718d1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f6761dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f6761e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f6761cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f6761f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c560d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f66faf1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1ee3457ca210a20853bd372b74d7a05198b0ae97 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5665 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 355004725 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5620878a3810, 0x562087a8d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562087a8d020,0x5620899250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ee3457ca210a20853bd372b74d7a05198b0ae97' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7260 processed earlier; will process 3769 files now Step #5: #1 pulse cov: 3770 ft: 3771 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 3980 ft: 4231 exec/s: 0 rss: 180Mb Step #5: ==204046== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56207e3989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5620849fd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5620849e05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5620849e04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56207e39ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56207e2ffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56207e2fa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56207e390c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56208135ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56208135ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56208135ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56208135ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56208135ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56208135ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56208135ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56208135ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56208135ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56208135ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5620835f4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562080321b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56208032cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5620800d8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5620800d8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5620800d9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5620800d8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5620800d8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5620800d8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5620849e2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5620849eb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5620849d3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5620849fe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f779118e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56207e2f8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ad34633b1fe0c117a1ac522bddb63aa82f940b84 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5666 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 355741107 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5561e19af810, 0x5561e1b9901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5561e1b99020,0x5561e3a310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad34633b1fe0c117a1ac522bddb63aa82f940b84' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7263 processed earlier; will process 3766 files now Step #5: ==204082== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5561d84a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5561deb09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5561deaec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5561deaec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5561d84aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5561d840bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5561d8406355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5561d849cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5561db46bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5561db46bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5561db46bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5561db46bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5561db46bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5561db46bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5561db46bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5561db46bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5561db46bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5561db46bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5561dd700f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5561da42db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5561da438be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5561da1e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5561da1e4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5561da1e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5561da1e4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5561da1e4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5561da1e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5561deaeeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5561deaf7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5561deadf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5561deb0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f998b419082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5561d8404b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bfee17ad782757e073c35b66bdb071e3f1fa601f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5667 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 356300377 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5583d9ebc810, 0x5583da0a601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5583da0a6020,0x5583dbf3e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bfee17ad782757e073c35b66bdb071e3f1fa601f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7264 processed earlier; will process 3765 files now Step #5: #1 pulse cov: 3726 ft: 3727 exec/s: 0 rss: 179Mb Step #5: ==204118== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5583d09b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5583d7016898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583d6ff95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583d6ff94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5583d09b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5583d0918b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5583d0913355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5583d09a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5583d3978f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5583d3978f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5583d3978f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5583d3978f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5583d3978f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5583d3978f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5583d3978f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5583d3978f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5583d3978f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5583d3978f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5583d5c0df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5583d293ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5583d2945be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5583d26f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5583d26f1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5583d26f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5583d26f1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5583d26f1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5583d26f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5583d6ffbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5583d7004928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5583d6fec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5583d7017112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0772a23082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5583d0911b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-35c952440bccb21b5acd09967ad5e02b46f84e56 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5668 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 356881419 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560774079810, 0x56077426301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560774263020,0x5607760fb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/35c952440bccb21b5acd09967ad5e02b46f84e56' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7266 processed earlier; will process 3763 files now Step #5: ==204154== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56076ab6e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5607711d3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5607711b65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5607711b64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56076ab74d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56076aad5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56076aad0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56076ab66c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56076db35f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56076db35f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56076db35f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56076db35f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56076db35f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56076db35f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56076db35f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56076db35f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56076db35f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56076db35f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56076fdcaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56076caf7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56076cb02be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56076c8aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56076c8aec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56076c8af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56076c8ae874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56076c8ae874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56076c8ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5607711b8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5607711c1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5607711a9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5607711d4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5a675d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56076aaceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-46029cef9957b432048600b890fdaebaf1f48791 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5669 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 357546825 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555fb61d3810, 0x555fb63bd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555fb63bd020,0x555fb82550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/46029cef9957b432048600b890fdaebaf1f48791' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7267 processed earlier; will process 3762 files now Step #5: ==204190== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555faccc89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555fb332d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555fb33105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555fb33104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555faccced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555facc2fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555facc2a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555faccc0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555fafc8ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555fafc8ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555fafc8ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555fafc8ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555fafc8ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555fafc8ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555fafc8ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555fafc8ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555fafc8ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555fafc8ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555fb1f24f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555faec51b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555faec5cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555faea08c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555faea08c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555faea09738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555faea08874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555faea08874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555faea08874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555fb3312abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555fb331b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555fb3303699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555fb332e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2951dd1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555facc28b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-734447c6667b4bd9baf4008a71fcad56a01d6c3f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5670 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 358106381 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c86b240810, 0x55c86b42a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c86b42a020,0x55c86d2c20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/734447c6667b4bd9baf4008a71fcad56a01d6c3f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7268 processed earlier; will process 3761 files now Step #5: ==204226== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c861d359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c86839a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c86837d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c86837d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c861d3bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c861c9cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c861c97355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c861d2dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c864cfcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c864cfcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c864cfcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c864cfcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c864cfcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c864cfcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c864cfcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c864cfcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c864cfcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c864cfcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c866f91f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c863cbeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c863cc9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c863a75c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c863a75c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c863a76738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c863a75874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c863a75874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c863a75874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c86837fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c868388928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c868370699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c86839b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc28bc93082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c861c95b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8871d96d60770da7b9cd086d3364514a4059c935 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5671 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 358805502 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5602d4cf5810, 0x5602d4edf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5602d4edf020,0x5602d6d770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8871d96d60770da7b9cd086d3364514a4059c935' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7269 processed earlier; will process 3760 files now Step #5: ==204262== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5602cb7ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5602d1e4f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602d1e325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602d1e324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5602cb7f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5602cb751b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5602cb74c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5602cb7e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5602ce7b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5602ce7b1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5602ce7b1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5602ce7b1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5602ce7b1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5602ce7b1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5602ce7b1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5602ce7b1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5602ce7b1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5602ce7b1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5602d0a46f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5602cd773b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5602cd77ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5602cd52ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5602cd52ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5602cd52b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5602cd52a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5602cd52a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5602cd52a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5602d1e34abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5602d1e3d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5602d1e25699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5602d1e50112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efd9aa7f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5602cb74ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-31d2f3f2a8cd3d3ca6a1a4446015c81f505842af Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5672 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 359338120 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555dedf89810, 0x555dee17301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555dee173020,0x555df000b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/31d2f3f2a8cd3d3ca6a1a4446015c81f505842af' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7270 processed earlier; will process 3759 files now Step #5: ==204298== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555de4a7e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555deb0e3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555deb0c65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555deb0c64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555de4a84d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555de49e5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555de49e0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555de4a76c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555de7a45f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555de7a45f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555de7a45f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555de7a45f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555de7a45f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555de7a45f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555de7a45f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555de7a45f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555de7a45f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555de7a45f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555de9cdaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555de6a07b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555de6a12be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555de67bec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555de67bec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555de67bf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555de67be874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555de67be874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555de67be874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555deb0c8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555deb0d1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555deb0b9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555deb0e4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f813c3e7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555de49deb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6dd697be5d8f4fe5aa44b5c0f0311577461e1eea Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5673 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 359881506 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed11504810, 0x55ed116ee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed116ee020,0x55ed135860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6dd697be5d8f4fe5aa44b5c0f0311577461e1eea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7271 processed earlier; will process 3758 files now Step #5: ==204334== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed07ff99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed0e65e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed0e6415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed0e6414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed07fffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed07f60b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed07f5b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed07ff1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed0afc0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed0afc0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed0afc0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed0afc0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed0afc0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed0afc0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed0afc0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed0afc0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed0afc0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed0afc0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed0d255f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed09f82b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed09f8dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed09d39c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed09d39c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed09d3a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed09d39874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed09d39874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed09d39874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed0e643abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed0e64c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed0e634699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed0e65f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f918ae31082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed07f59b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c7ac31cdccccb3cffe64f95abb1960287a29f7ce Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5674 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 360412795 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55abd1a3d810, 0x55abd1c2701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55abd1c27020,0x55abd3abf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c7ac31cdccccb3cffe64f95abb1960287a29f7ce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7272 processed earlier; will process 3757 files now Step #5: #1 pulse cov: 4210 ft: 4211 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4284 ft: 4923 exec/s: 0 rss: 180Mb Step #5: ==204370== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55abc85329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55abceb97898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55abceb7a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55abceb7a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55abc8538d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55abc8499b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55abc8494355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55abc852ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55abcb4f9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55abcb4f9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55abcb4f9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55abcb4f9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55abcb4f9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55abcb4f9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55abcb4f9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55abcb4f9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55abcb4f9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55abcb4f9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55abcd78ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55abca4bbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55abca4c6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55abca272c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55abca272c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55abca273738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55abca272874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55abca272874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55abca272874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55abceb7cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55abceb85928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55abceb6d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55abceb98112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc2dce3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55abc8492b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-94879066d1f8c7be6a121d8c4ac700090de30c06 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5675 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 361139071 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5575fd77a810, 0x5575fd96401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5575fd964020,0x5575ff7fc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/94879066d1f8c7be6a121d8c4ac700090de30c06' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7275 processed earlier; will process 3754 files now Step #5: ==204406== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5575f426f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5575fa8d4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5575fa8b75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5575fa8b74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5575f4275d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5575f41d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5575f41d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5575f4267c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5575f7236f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5575f7236f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5575f7236f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5575f7236f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5575f7236f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5575f7236f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5575f7236f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5575f7236f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5575f7236f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5575f7236f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5575f94cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5575f61f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5575f6203be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5575f5fafc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5575f5fafc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5575f5fb0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5575f5faf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5575f5faf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5575f5faf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5575fa8b9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5575fa8c2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5575fa8aa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5575fa8d5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f25cf333082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5575f41cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-59a9660842fc9716f1249727c11279402956bbbe Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5676 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 361673897 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c6c3c5f810, 0x55c6c3e4901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c6c3e49020,0x55c6c5ce10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/59a9660842fc9716f1249727c11279402956bbbe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7276 processed earlier; will process 3753 files now Step #5: ==204442== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c6ba7549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c6c0db9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c6c0d9c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c6c0d9c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c6ba75ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c6ba6bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c6ba6b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c6ba74cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c6bd71bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c6bd71bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c6bd71bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c6bd71bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c6bd71bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c6bd71bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c6bd71bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c6bd71bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c6bd71bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c6bd71bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c6bf9b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c6bc6ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c6bc6e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c6bc494c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c6bc494c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c6bc495738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c6bc494874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c6bc494874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c6bc494874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c6c0d9eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c6c0da7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c6c0d8f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c6c0dba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f33eed46082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c6ba6b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf7895982173d5a188eb3b98588967e260806f16 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5677 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 362227842 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ad1686810, 0x559ad187001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ad1870020,0x559ad37080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf7895982173d5a188eb3b98588967e260806f16' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7277 processed earlier; will process 3752 files now Step #5: ==204478== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559ac817b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ace7e0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ace7c35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ace7c34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ac8181d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ac80e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ac80dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ac8173c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559acb142f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559acb142f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559acb142f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559acb142f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559acb142f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559acb142f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559acb142f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559acb142f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559acb142f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559acb142f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559acd3d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559aca104b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559aca10fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559ac9ebbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559ac9ebbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559ac9ebc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559ac9ebb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559ac9ebb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559ac9ebb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ace7c5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ace7ce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ace7b6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ace7e1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbded1cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ac80dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-099b476a863d504796b9a1f5df8e2fecb446be18 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5678 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 362773705 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5591275a6810, 0x55912779001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559127790020,0x5591296280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/099b476a863d504796b9a1f5df8e2fecb446be18' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7278 processed earlier; will process 3751 files now Step #5: ==204514== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55911e09b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559124700898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5591246e35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5591246e34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55911e0a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55911e002b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55911dffd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55911e093c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559121062f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559121062f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559121062f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559121062f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559121062f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559121062f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559121062f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559121062f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559121062f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559121062f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5591232f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559120024b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55912002fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55911fddbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55911fddbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55911fddc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55911fddb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55911fddb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55911fddb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5591246e5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5591246ee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5591246d6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559124701112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a0facc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55911dffbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-298d2bfcfeca6fbd6502b77ab6aca05fd1f6335c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5679 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 363305279 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5613762b3810, 0x56137649d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56137649d020,0x5613783350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/298d2bfcfeca6fbd6502b77ab6aca05fd1f6335c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7279 processed earlier; will process 3750 files now Step #5: ==204550== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56136cda89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56137340d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613733f05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613733f04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56136cdaed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56136cd0fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56136cd0a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56136cda0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56136fd6ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56136fd6ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56136fd6ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56136fd6ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56136fd6ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56136fd6ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56136fd6ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56136fd6ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56136fd6ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56136fd6ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561372004f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56136ed31b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56136ed3cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56136eae8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56136eae8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56136eae9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56136eae8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56136eae8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56136eae8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5613733f2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5613733fb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5613733e3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56137340e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f63df6d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56136cd08b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ed89c568f1e56c62e9d590ebbe1dca773e35bedd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5680 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 363925346 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b32eb72810, 0x55b32ed5c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b32ed5c020,0x55b330bf40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ed89c568f1e56c62e9d590ebbe1dca773e35bedd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7280 processed earlier; will process 3749 files now Step #5: ==204586== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b3256679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b32bccc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b32bcaf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b32bcaf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b32566dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b3255ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b3255c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b32565fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b32862ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b32862ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b32862ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b32862ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b32862ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b32862ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b32862ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b32862ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b32862ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b32862ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b32a8c3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b3275f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b3275fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b3273a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b3273a7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b3273a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b3273a7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b3273a7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b3273a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b32bcb1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b32bcba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b32bca2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b32bccd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0260e0b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b3255c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5f0e2460a5fca96f48becd566c81d8ada4878408 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5681 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 364459854 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b58638810, 0x557b5882201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b58822020,0x557b5a6ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f0e2460a5fca96f48becd566c81d8ada4878408' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7281 processed earlier; will process 3748 files now Step #5: #1 pulse cov: 4065 ft: 4066 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4471 ft: 5193 exec/s: 0 rss: 181Mb Step #5: ==204622== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557b4f12d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b55792898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b557755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b557754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b4f133d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b4f094b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b4f08f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b4f125c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b520f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b520f4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b520f4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b520f4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b520f4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b520f4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b520f4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b520f4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b520f4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b520f4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b54389f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b510b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b510c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b50e6dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b50e6dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b50e6e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b50e6d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b50e6d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b50e6d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b55777abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b55780928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b55768699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b55793112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd0d3b67082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b4f08db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4ac9a056c48358692106c967db93f4e2ce8f5c92 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5682 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 365093893 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e08cd45810, 0x55e08cf2f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e08cf2f020,0x55e08edc70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4ac9a056c48358692106c967db93f4e2ce8f5c92' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7284 processed earlier; will process 3745 files now Step #5: ==204658== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e08383a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e089e9f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e089e825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e089e824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e083840d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e0837a1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e08379c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e083832c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e086801f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e086801f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e086801f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e086801f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e086801f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e086801f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e086801f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e086801f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e086801f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e086801f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e088a96f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e0857c3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e0857cebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e08557ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e08557ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e08557b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e08557a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e08557a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e08557a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e089e84abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e089e8d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e089e75699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e089ea0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f8521a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e08379ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3d7f92435dee580540b3ee0f79da3d9405eba50f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5683 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 365642298 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556cf9291810, 0x556cf947b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556cf947b020,0x556cfb3130e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3d7f92435dee580540b3ee0f79da3d9405eba50f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7285 processed earlier; will process 3744 files now Step #5: #1 pulse cov: 3936 ft: 3937 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4723 ft: 5266 exec/s: 0 rss: 180Mb Step #5: ==204694== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556cefd869c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556cf63eb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556cf63ce5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556cf63ce4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556cefd8cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556cefcedb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556cefce8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556cefd7ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556cf2d4df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556cf2d4df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556cf2d4df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556cf2d4df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556cf2d4df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556cf2d4df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556cf2d4df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556cf2d4df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556cf2d4df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556cf2d4df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556cf4fe2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556cf1d0fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556cf1d1abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556cf1ac6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556cf1ac6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556cf1ac7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556cf1ac6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556cf1ac6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556cf1ac6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556cf63d0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556cf63d9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556cf63c1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556cf63ec112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f442baf1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556cefce6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d4a5db540fd358d10cb9d9c2617a0a8edda89e22 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5684 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 366317546 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a8eeb1810, 0x561a8f09b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a8f09b020,0x561a90f330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d4a5db540fd358d10cb9d9c2617a0a8edda89e22' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7289 processed earlier; will process 3740 files now Step #5: #1 pulse cov: 3790 ft: 3791 exec/s: 0 rss: 177Mb Step #5: ==204730== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561a859a69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561a8c00b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561a8bfee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561a8bfee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561a859acd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561a8590db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561a85908355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561a8599ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561a8896df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561a8896df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561a8896df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561a8896df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561a8896df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561a8896df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561a8896df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561a8896df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561a8896df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561a8896df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561a8ac02f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561a8792fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561a8793abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561a876e6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561a876e6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561a876e7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561a876e6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561a876e6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561a876e6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561a8bff0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561a8bff9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561a8bfe1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561a8c00c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f64f9262082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561a85906b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0d36a51547faa5ffca73a874f4b671fc35d7786c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5685 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 366896389 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cad9254810, 0x55cad943e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cad943e020,0x55cadb2d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0d36a51547faa5ffca73a874f4b671fc35d7786c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7291 processed earlier; will process 3738 files now Step #5: ==204766== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cacfd499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cad63ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cad63915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cad63914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cacfd4fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cacfcb0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cacfcab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cacfd41c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cad2d10f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cad2d10f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cad2d10f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cad2d10f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cad2d10f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cad2d10f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cad2d10f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cad2d10f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cad2d10f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cad2d10f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cad4fa5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cad1cd2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cad1cddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cad1a89c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cad1a89c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cad1a8a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cad1a89874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cad1a89874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cad1a89874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cad6393abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cad639c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cad6384699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cad63af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f35a0c64082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cacfca9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-175bed4b48f7e477d88dc71b67db880ff40991d0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5686 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 367457683 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a55b31810, 0x563a55d1b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a55d1b020,0x563a57bb30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/175bed4b48f7e477d88dc71b67db880ff40991d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7292 processed earlier; will process 3737 files now Step #5: ==204802== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563a4c6269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a52c8b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a52c6e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a52c6e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a4c62cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a4c58db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a4c588355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a4c61ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a4f5edf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a4f5edf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a4f5edf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a4f5edf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a4f5edf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a4f5edf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a4f5edf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a4f5edf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a4f5edf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a4f5edf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a51882f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a4e5afb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a4e5babe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a4e366c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a4e366c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a4e367738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a4e366874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a4e366874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a4e366874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a52c70abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a52c79928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a52c61699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a52c8c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba7727e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a4c586b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4e7d5010b62ff345573acb9ccbed30ac791f7910 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5687 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 367993454 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b3fd5eb810, 0x55b3fd7d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b3fd7d5020,0x55b3ff66d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e7d5010b62ff345573acb9ccbed30ac791f7910' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7293 processed earlier; will process 3736 files now Step #5: ==204838== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b3f40e09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b3fa745898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b3fa7285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b3fa7284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b3f40e6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b3f4047b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b3f4042355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b3f40d8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b3f70a7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b3f70a7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b3f70a7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b3f70a7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b3f70a7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b3f70a7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b3f70a7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b3f70a7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b3f70a7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b3f70a7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b3f933cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b3f6069b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b3f6074be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b3f5e20c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b3f5e20c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b3f5e21738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b3f5e20874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b3f5e20874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b3f5e20874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b3fa72aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b3fa733928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b3fa71b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b3fa746112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6424f42082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b3f4040b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-130834018e294b32d19f6cb97d5b0f48d321d472 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5688 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 368517490 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d7c3934810, 0x55d7c3b1e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d7c3b1e020,0x55d7c59b60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/130834018e294b32d19f6cb97d5b0f48d321d472' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7294 processed earlier; will process 3735 files now Step #5: ==204874== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d7ba4299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d7c0a8e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7c0a715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7c0a714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d7ba42fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d7ba390b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d7ba38b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d7ba421c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d7bd3f0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d7bd3f0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d7bd3f0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d7bd3f0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d7bd3f0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d7bd3f0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d7bd3f0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d7bd3f0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d7bd3f0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d7bd3f0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d7bf685f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d7bc3b2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d7bc3bdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d7bc169c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d7bc169c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d7bc16a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d7bc169874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d7bc169874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d7bc169874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d7c0a73abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d7c0a7c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d7c0a64699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d7c0a8f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f087c796082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d7ba389b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c3e26fd1585d40321616c0fd9d9b65e703a20c7a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5689 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 369165852 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dbf0f62810, 0x55dbf114c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dbf114c020,0x55dbf2fe40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c3e26fd1585d40321616c0fd9d9b65e703a20c7a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7295 processed earlier; will process 3734 files now Step #5: ==204910== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dbe7a579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dbee0bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dbee09f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dbee09f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dbe7a5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dbe79beb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dbe79b9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dbe7a4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dbeaa1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dbeaa1ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dbeaa1ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dbeaa1ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dbeaa1ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dbeaa1ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dbeaa1ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dbeaa1ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dbeaa1ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dbeaa1ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dbeccb3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dbe99e0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dbe99ebbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dbe9797c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dbe9797c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dbe9798738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dbe9797874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dbe9797874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dbe9797874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dbee0a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dbee0aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dbee092699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dbee0bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f690b34a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dbe79b7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9985c1556b71162494224383ae4c477cbe120068 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5690 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 370332677 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a81f18810, 0x555a8210201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a82102020,0x555a83f9a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9985c1556b71162494224383ae4c477cbe120068' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7296 processed earlier; will process 3733 files now Step #5: ==204946== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555a78a0d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a7f072898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a7f0555dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a7f0554fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a78a13d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a78974b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a7896f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a78a05c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a7b9d4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a7b9d4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a7b9d4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a7b9d4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a7b9d4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a7b9d4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a7b9d4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a7b9d4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a7b9d4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a7b9d4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a7dc69f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a7a996b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a7a9a1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a7a74dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a7a74dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a7a74e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a7a74d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a7a74d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a7a74d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a7f057abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a7f060928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a7f048699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a7f073112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fab4c37e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a7896db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7325b9d4795c1e6dba7a91a76783dfa2fb0bf708 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5691 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 371513502 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea58281810, 0x55ea5846b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea5846b020,0x55ea5a3030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7325b9d4795c1e6dba7a91a76783dfa2fb0bf708' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7297 processed earlier; will process 3732 files now Step #5: ==204982== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ea4ed769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea553db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea553be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea553be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea4ed7cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea4ecddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea4ecd8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea4ed6ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea51d3df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea51d3df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea51d3df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea51d3df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea51d3df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea51d3df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea51d3df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea51d3df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea51d3df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea51d3df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea53fd2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea50cffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea50d0abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea50ab6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea50ab6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea50ab7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea50ab6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea50ab6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea50ab6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea553c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea553c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea553b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea553dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff7fb84c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea4ecd6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f24b2fdf3269d13ae00b938f574d789ce619d185 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5692 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 372651403 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f3f8422810, 0x55f3f860c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f3f860c020,0x55f3fa4a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f24b2fdf3269d13ae00b938f574d789ce619d185' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7298 processed earlier; will process 3731 files now Step #5: ==205018== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f3eef179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f3f557c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f3f555f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f3f555f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f3eef1dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f3eee7eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f3eee79355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f3eef0fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f3f1edef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f3f1edef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f3f1edef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f3f1edef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f3f1edef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f3f1edef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f3f1edef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f3f1edef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f3f1edef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f3f1edef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f3f4173f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f3f0ea0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f3f0eabbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f3f0c57c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f3f0c57c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f3f0c58738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f3f0c57874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f3f0c57874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f3f0c57874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f3f5561abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f3f556a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f3f5552699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f3f557d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f76d6a4d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f3eee77b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6faff5384cb2bda9cb42ba5e500c88365a34c8d8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5693 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 373710332 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563f78009810, 0x563f781f301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563f781f3020,0x563f7a08b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6faff5384cb2bda9cb42ba5e500c88365a34c8d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7299 processed earlier; will process 3730 files now Step #5: ==205054== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563f6eafe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563f75163898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563f751465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563f751464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563f6eb04d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563f6ea65b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563f6ea60355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563f6eaf6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563f71ac5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563f71ac5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563f71ac5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563f71ac5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563f71ac5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563f71ac5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563f71ac5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563f71ac5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563f71ac5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563f71ac5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563f73d5af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563f70a87b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563f70a92be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563f7083ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563f7083ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563f7083f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563f7083e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563f7083e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563f7083e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563f75148abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563f75151928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563f75139699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563f75164112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa31dc83082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563f6ea5eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-30f5a1bf7e0290f9f1e85f53e0b14f674e192e26 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5694 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 374917882 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559567c23810, 0x559567e0d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559567e0d020,0x559569ca50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/30f5a1bf7e0290f9f1e85f53e0b14f674e192e26' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7300 processed earlier; will process 3729 files now Step #5: ==205090== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55955e7189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559564d7d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559564d605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559564d604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55955e71ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55955e67fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55955e67a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55955e710c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5595616dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5595616dff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5595616dff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5595616dff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5595616dff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5595616dff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5595616dff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5595616dff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5595616dff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5595616dff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559563974f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5595606a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5595606acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559560458c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559560458c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559560459738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559560458874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559560458874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559560458874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559564d62abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559564d6b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559564d53699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559564d7e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4df0b7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55955e678b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-74a949b19ac5620b018a449d91054871627c75e5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5695 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 376113408 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564651143810, 0x56465132d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56465132d020,0x5646531c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/74a949b19ac5620b018a449d91054871627c75e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7301 processed earlier; will process 3728 files now Step #5: ==205126== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564647c389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56464e29d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56464e2805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56464e2804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564647c3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564647b9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564647b9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564647c30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56464abfff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56464abfff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56464abfff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56464abfff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56464abfff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56464abfff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56464abfff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56464abfff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56464abfff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56464abfff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56464ce94f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564649bc1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564649bccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564649978c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564649978c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564649979738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564649978874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564649978874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564649978874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56464e282abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56464e28b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56464e273699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56464e29e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a20f88082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564647b98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d53957246905f8e69bbdb49d98e2313e21d491cd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5696 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 377170286 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557fcd1d4810, 0x557fcd3be01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557fcd3be020,0x557fcf2560e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d53957246905f8e69bbdb49d98e2313e21d491cd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7302 processed earlier; will process 3727 files now Step #5: ==205162== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557fc3cc99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557fca32e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557fca3115dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557fca3114fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557fc3ccfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557fc3c30b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557fc3c2b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557fc3cc1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557fc6c90f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557fc6c90f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557fc6c90f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557fc6c90f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557fc6c90f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557fc6c90f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557fc6c90f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557fc6c90f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557fc6c90f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557fc6c90f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557fc8f25f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557fc5c52b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557fc5c5dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557fc5a09c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557fc5a09c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557fc5a0a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557fc5a09874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557fc5a09874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557fc5a09874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557fca313abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557fca31c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557fca304699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557fca32f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f97b8c16082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557fc3c29b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a27b7ab35139bf61d39d02ae108eb7b6891edbee Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5697 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 377709179 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571cc0db810, 0x5571cc2c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571cc2c5020,0x5571ce15d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a27b7ab35139bf61d39d02ae108eb7b6891edbee' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7303 processed earlier; will process 3726 files now Step #5: ==205198== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571c2bd09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571c9235898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571c92185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571c92184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571c2bd6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571c2b37b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571c2b32355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571c2bc8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571c5b97f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571c5b97f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571c5b97f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571c5b97f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571c5b97f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571c5b97f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571c5b97f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571c5b97f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571c5b97f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571c5b97f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571c7e2cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571c4b59b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571c4b64be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571c4910c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571c4910c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571c4911738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571c4910874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571c4910874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571c4910874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571c921aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571c9223928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571c920b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571c9236112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7bb488a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571c2b30b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ef060a75341509fb66f2b68b0f85fe63e5179e05 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5698 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 378941085 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d40850a810, 0x55d4086f401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d4086f4020,0x55d40a58c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ef060a75341509fb66f2b68b0f85fe63e5179e05' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7304 processed earlier; will process 3725 files now Step #5: ==205234== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d3fefff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d405664898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d4056475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d4056474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d3ff005d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d3fef66b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d3fef61355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d3feff7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d401fc6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d401fc6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d401fc6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d401fc6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d401fc6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d401fc6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d401fc6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d401fc6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d401fc6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d401fc6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d40425bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d400f88b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d400f93be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d400d3fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d400d3fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d400d40738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d400d3f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d400d3f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d400d3f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d405649abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d405652928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d40563a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d405665112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3a30065082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d3fef5fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7c04813353ee2b72eb0e9d6eb972c623eeb43e17 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5699 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 379480609 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b40862d810, 0x55b40881701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b408817020,0x55b40a6af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7c04813353ee2b72eb0e9d6eb972c623eeb43e17' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7305 processed earlier; will process 3724 files now Step #5: ==205270== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b3ff1229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b405787898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b40576a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b40576a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b3ff128d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b3ff089b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b3ff084355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b3ff11ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b4020e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b4020e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b4020e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b4020e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b4020e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b4020e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b4020e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b4020e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b4020e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b4020e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b40437ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b4010abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b4010b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b400e62c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b400e62c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b400e63738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b400e62874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b400e62874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b400e62874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b40576cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b405775928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b40575d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b405788112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d192c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b3ff082b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-735aaa004340eb2e9e028616c330804f760d4991 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5700 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 380072786 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56040524a810, 0x56040543401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560405434020,0x5604072cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/735aaa004340eb2e9e028616c330804f760d4991' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7306 processed earlier; will process 3723 files now Step #5: ==205306== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5603fbd3f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5604023a4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5604023875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5604023874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5603fbd45d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5603fbca6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5603fbca1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5603fbd37c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5603fed06f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5603fed06f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5603fed06f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5603fed06f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5603fed06f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5603fed06f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5603fed06f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5603fed06f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5603fed06f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5603fed06f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560400f9bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5603fdcc8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5603fdcd3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5603fda7fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5603fda7fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5603fda80738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5603fda7f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5603fda7f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5603fda7f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560402389abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560402392928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56040237a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5604023a5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e1804b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5603fbc9fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2a44b4999c6645f7a7426a0737c5d6db7509ea42 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5701 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 381437560 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5627ecddf810, 0x5627ecfc901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5627ecfc9020,0x5627eee610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2a44b4999c6645f7a7426a0737c5d6db7509ea42' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7307 processed earlier; will process 3722 files now Step #5: #1 pulse cov: 3911 ft: 3912 exec/s: 0 rss: 177Mb Step #5: ==205342== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5627e38d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5627e9f39898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5627e9f1c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5627e9f1c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5627e38dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5627e383bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5627e3836355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5627e38ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5627e689bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5627e689bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5627e689bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5627e689bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5627e689bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5627e689bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5627e689bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5627e689bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5627e689bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5627e689bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5627e8b30f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5627e585db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5627e5868be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5627e5614c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5627e5614c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5627e5615738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5627e5614874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5627e5614874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5627e5614874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5627e9f1eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5627e9f27928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5627e9f0f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5627e9f3a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe8fe2a2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5627e3834b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7dbf38a67467494e2cc3b73ec17bc27ed4df4404 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5702 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 382025000 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d3e77c810, 0x561d3e96601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d3e966020,0x561d407fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7dbf38a67467494e2cc3b73ec17bc27ed4df4404' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7309 processed earlier; will process 3720 files now Step #5: ==205378== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d352719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d3b8d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d3b8b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d3b8b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d35277d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d351d8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d351d3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d35269c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d38238f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d38238f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d38238f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d38238f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d38238f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d38238f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d38238f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d38238f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d38238f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d38238f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d3a4cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d371fab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d37205be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d36fb1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d36fb1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d36fb2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d36fb1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d36fb1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d36fb1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d3b8bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d3b8c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d3b8ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d3b8d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efe0e006082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d351d1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2673e7b19991caa52c58748ecf46beaccfdb161d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5703 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 382562715 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5597d1f40810, 0x5597d212a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5597d212a020,0x5597d3fc20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2673e7b19991caa52c58748ecf46beaccfdb161d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7310 processed earlier; will process 3719 files now Step #5: ==205414== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5597c8a359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5597cf09a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5597cf07d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5597cf07d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5597c8a3bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5597c899cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5597c8997355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5597c8a2dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5597cb9fcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5597cb9fcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5597cb9fcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5597cb9fcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5597cb9fcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5597cb9fcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5597cb9fcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5597cb9fcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5597cb9fcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5597cb9fcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5597cdc91f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5597ca9beb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5597ca9c9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5597ca775c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5597ca775c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5597ca776738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5597ca775874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5597ca775874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5597ca775874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5597cf07fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5597cf088928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5597cf070699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5597cf09b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f66a604e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5597c8995b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7a4b03d774f33af1094d09e76014a4ebb151a4ea Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5704 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 383423412 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5561098cb810, 0x556109ab501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556109ab5020,0x55610b94d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7a4b03d774f33af1094d09e76014a4ebb151a4ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7311 processed earlier; will process 3718 files now Step #5: #1 pulse cov: 3747 ft: 3748 exec/s: 0 rss: 182Mb Step #5: ==205450== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5561003c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556106a25898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556106a085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556106a084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5561003c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556100327b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556100322355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5561003b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556103387f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556103387f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556103387f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556103387f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556103387f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556103387f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556103387f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556103387f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556103387f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556103387f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55610561cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556102349b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556102354be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556102100c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556102100c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556102101738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556102100874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556102100874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556102100874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556106a0aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556106a13928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5561069fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556106a26112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f52383d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556100320b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3796211053a902fafa79f25822473238f35df194 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5705 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 384516397 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5641914b9810, 0x5641916a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5641916a3020,0x56419353b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3796211053a902fafa79f25822473238f35df194' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7313 processed earlier; will process 3716 files now Step #5: #1 pulse cov: 18267 ft: 18268 exec/s: 0 rss: 211Mb Step #5: ==205486== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564187fae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56418e613898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56418e5f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56418e5f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564187fb4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564187f15b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564187f10355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564187fa6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56418af75f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56418af75f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56418af75f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56418af75f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56418af75f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56418af75f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56418af75f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56418af75f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56418af75f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56418af75f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56418d20af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564189f37b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564189f42be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564189ceec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564189ceec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564189cef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564189cee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564189cee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564189cee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56418e5f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56418e601928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56418e5e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56418e614112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f084dcc8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564187f0eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-94605c5aad70f3f7f0df1ca94e4aecedb5cf92a6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5706 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 385302102 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c268346810, 0x55c26853001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c268530020,0x55c26a3c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/94605c5aad70f3f7f0df1ca94e4aecedb5cf92a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7315 processed earlier; will process 3714 files now Step #5: ==205522== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c25ee3b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c2654a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c2654835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c2654834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c25ee41d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c25eda2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c25ed9d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c25ee33c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c261e02f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c261e02f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c261e02f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c261e02f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c261e02f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c261e02f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c261e02f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c261e02f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c261e02f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c261e02f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c264097f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c260dc4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c260dcfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c260b7bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c260b7bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c260b7c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c260b7b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c260b7b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c260b7b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c265485abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c26548e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c265476699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c2654a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d719f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c25ed9bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb9b2e18301c05aee6724040033e6b93106cc784 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5707 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 385848449 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c5e4044810, 0x55c5e422e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c5e422e020,0x55c5e60c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb9b2e18301c05aee6724040033e6b93106cc784' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7316 processed earlier; will process 3713 files now Step #5: ==205558== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c5dab399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c5e119e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c5e11815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c5e11814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c5dab3fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c5daaa0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c5daa9b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c5dab31c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c5ddb00f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c5ddb00f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c5ddb00f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c5ddb00f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c5ddb00f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c5ddb00f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c5ddb00f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c5ddb00f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c5ddb00f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c5ddb00f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c5dfd95f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c5dcac2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c5dcacdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c5dc879c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c5dc879c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c5dc87a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c5dc879874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c5dc879874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c5dc879874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c5e1183abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c5e118c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c5e1174699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c5e119f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f22f18d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c5daa99b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fcb4b5ec70ae45fd6c3942189ef0c7bd0df36b56 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5708 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 386377228 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557e4081b810, 0x557e40a0501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557e40a05020,0x557e4289d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fcb4b5ec70ae45fd6c3942189ef0c7bd0df36b56' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7317 processed earlier; will process 3712 files now Step #5: ==205594== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557e373109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557e3d975898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557e3d9585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557e3d9584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557e37316d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557e37277b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557e37272355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557e37308c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557e3a2d7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557e3a2d7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557e3a2d7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557e3a2d7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557e3a2d7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557e3a2d7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557e3a2d7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557e3a2d7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557e3a2d7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557e3a2d7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557e3c56cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557e39299b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557e392a4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557e39050c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557e39050c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557e39051738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557e39050874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557e39050874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557e39050874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557e3d95aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557e3d963928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557e3d94b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557e3d976112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f422fc85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557e37270b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-02001bd5f240633fe38ba239a16121720e7e5469 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5709 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 386907151 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ea611f810, 0x559ea630901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ea6309020,0x559ea81a10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/02001bd5f240633fe38ba239a16121720e7e5469' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7318 processed earlier; will process 3711 files now Step #5: ==205630== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559e9cc149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ea3279898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ea325c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ea325c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e9cc1ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e9cb7bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e9cb76355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e9cc0cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e9fbdbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e9fbdbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e9fbdbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e9fbdbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e9fbdbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e9fbdbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e9fbdbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e9fbdbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e9fbdbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e9fbdbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ea1e70f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e9eb9db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e9eba8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e9e954c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e9e954c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e9e955738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e9e954874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e9e954874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e9e954874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ea325eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ea3267928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ea324f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ea327a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9a1046a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e9cb74b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-21a85de48788f3b56e89cbfdf485334860b5f5a7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5710 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 388180030 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a743b88810, 0x55a743d7201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a743d72020,0x55a745c0a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/21a85de48788f3b56e89cbfdf485334860b5f5a7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7319 processed earlier; will process 3710 files now Step #5: ==205666== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a73a67d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a740ce2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a740cc55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a740cc54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a73a683d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a73a5e4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a73a5df355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a73a675c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a73d644f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a73d644f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a73d644f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a73d644f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a73d644f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a73d644f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a73d644f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a73d644f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a73d644f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a73d644f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a73f8d9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a73c606b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a73c611be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a73c3bdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a73c3bdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a73c3be738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a73c3bd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a73c3bd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a73c3bd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a740cc7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a740cd0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a740cb8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a740ce3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f35a92b6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a73a5ddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c84ed1ce1225689253a398b04f0e0972769bf7c3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5711 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 388704202 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55753ec12810, 0x55753edfc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55753edfc020,0x557540c940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c84ed1ce1225689253a398b04f0e0972769bf7c3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7320 processed earlier; will process 3709 files now Step #5: ==205702== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5575357079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55753bd6c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55753bd4f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55753bd4f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55753570dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55753566eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557535669355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5575356ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5575386cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5575386cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5575386cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5575386cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5575386cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5575386cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5575386cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5575386cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5575386cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5575386cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55753a963f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557537690b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55753769bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557537447c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557537447c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557537448738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557537447874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557537447874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557537447874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55753bd51abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55753bd5a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55753bd42699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55753bd6d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1829afa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557535667b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-641429e99e5499f3d17d72a3b2e0209ce67e7deb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5712 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 389248678 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c883875810, 0x55c883a5f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c883a5f020,0x55c8858f70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/641429e99e5499f3d17d72a3b2e0209ce67e7deb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7321 processed earlier; will process 3708 files now Step #5: #1 pulse cov: 3699 ft: 3700 exec/s: 0 rss: 180Mb Step #5: ==205738== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c87a36a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8809cf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8809b25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8809b24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c87a370d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c87a2d1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c87a2cc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c87a362c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c87d331f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c87d331f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c87d331f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c87d331f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c87d331f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c87d331f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c87d331f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c87d331f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c87d331f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c87d331f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c87f5c6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c87c2f3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c87c2febe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c87c0aac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c87c0aac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c87c0ab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c87c0aa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c87c0aa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c87c0aa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8809b4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8809bd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8809a5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8809d0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5098597082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c87a2cab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7513b93b011fd502ca1caf72874961b169341656 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5713 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 389944920 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e10869c810, 0x55e10888601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e108886020,0x55e10a71e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7513b93b011fd502ca1caf72874961b169341656' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7323 processed earlier; will process 3706 files now Step #5: ==205774== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e0ff1919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e1057f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e1057d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e1057d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e0ff197d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e0ff0f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e0ff0f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e0ff189c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e102158f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e102158f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e102158f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e102158f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e102158f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e102158f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e102158f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e102158f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e102158f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e102158f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e1043edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e10111ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e101125be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e100ed1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e100ed1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e100ed2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e100ed1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e100ed1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e100ed1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e1057dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e1057e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e1057cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e1057f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9c47007082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e0ff0f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c39ae4c234cf86c9938cd2b0925705c39f1f5a9f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5714 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 390512694 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b7b177810, 0x556b7b36101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b7b361020,0x556b7d1f90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c39ae4c234cf86c9938cd2b0925705c39f1f5a9f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7324 processed earlier; will process 3705 files now Step #5: ==205810== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556b71c6c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b782d1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b782b45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b782b44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b71c72d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b71bd3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b71bce355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b71c64c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b74c33f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b74c33f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b74c33f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b74c33f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b74c33f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b74c33f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b74c33f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b74c33f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b74c33f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b74c33f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b76ec8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b73bf5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b73c00be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b739acc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b739acc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b739ad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b739ac874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b739ac874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b739ac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b782b6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b782bf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b782a7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b782d2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5f8e287082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b71bccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b7ffac34b4f16cf7ef2059fa96bff00976f22f54 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5715 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 391053026 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560e5b176810, 0x560e5b36001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560e5b360020,0x560e5d1f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7ffac34b4f16cf7ef2059fa96bff00976f22f54' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7325 processed earlier; will process 3704 files now Step #5: ==205846== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560e51c6b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560e582d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560e582b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560e582b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560e51c71d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560e51bd2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560e51bcd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560e51c63c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560e54c32f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560e54c32f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560e54c32f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560e54c32f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560e54c32f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560e54c32f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560e54c32f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560e54c32f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560e54c32f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560e54c32f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560e56ec7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560e53bf4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560e53bffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560e539abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560e539abc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560e539ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560e539ab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560e539ab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560e539ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560e582b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560e582be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560e582a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560e582d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9782a60082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560e51bcbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cdb5c41589fe3f16bc685372808033281321e1b7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5716 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 391599685 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e7388e810, 0x559e73a7801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e73a78020,0x559e759100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cdb5c41589fe3f16bc685372808033281321e1b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7326 processed earlier; will process 3703 files now Step #5: ==205882== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559e6a3839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e709e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e709cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e709cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e6a389d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e6a2eab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e6a2e5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e6a37bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e6d34af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e6d34af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e6d34af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e6d34af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e6d34af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e6d34af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e6d34af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e6d34af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e6d34af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e6d34af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e6f5dff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e6c30cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e6c317be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e6c0c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e6c0c3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e6c0c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e6c0c3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e6c0c3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e6c0c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e709cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e709d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e709be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e709e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efc08a59082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e6a2e3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-197669ef54987a19daced1733e23591ef29a8455 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5717 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 392664384 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5619cfcc5810, 0x5619cfeaf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5619cfeaf020,0x5619d1d470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/197669ef54987a19daced1733e23591ef29a8455' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7327 processed earlier; will process 3702 files now Step #5: ==205918== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5619c67ba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5619cce1f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5619cce025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5619cce024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5619c67c0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5619c6721b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5619c671c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5619c67b2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5619c9781f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5619c9781f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5619c9781f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5619c9781f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5619c9781f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5619c9781f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5619c9781f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5619c9781f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5619c9781f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5619c9781f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5619cba16f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5619c8743b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5619c874ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5619c84fac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5619c84fac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5619c84fb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5619c84fa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5619c84fa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5619c84fa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5619cce04abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5619cce0d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5619ccdf5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5619cce20112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc7f17cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5619c671ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e68344aa25199f374d78c2d9cbe3966f81c12799 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5718 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 393199544 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559577533810, 0x55957771d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55957771d020,0x5595795b50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e68344aa25199f374d78c2d9cbe3966f81c12799' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7328 processed earlier; will process 3701 files now Step #5: ==205954== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55956e0289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55957468d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5595746705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5595746704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55956e02ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55956df8fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55956df8a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55956e020c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559570feff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559570feff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559570feff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559570feff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559570feff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559570feff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559570feff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559570feff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559570feff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559570feff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559573284f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55956ffb1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55956ffbcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55956fd68c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55956fd68c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55956fd69738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55956fd68874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55956fd68874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55956fd68874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559574672abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55957467b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559574663699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55957468e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc2c85f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55956df88b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fea111b8c00f9b0a3b8c307b3baa5249756d440a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5719 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 393728296 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc24f94810, 0x55fc2517e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc2517e020,0x55fc270160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fea111b8c00f9b0a3b8c307b3baa5249756d440a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7329 processed earlier; will process 3700 files now Step #5: ==205990== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fc1ba899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc220ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc220d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc220d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc1ba8fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc1b9f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc1b9eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc1ba81c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc1ea50f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc1ea50f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc1ea50f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc1ea50f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc1ea50f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc1ea50f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc1ea50f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc1ea50f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc1ea50f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc1ea50f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc20ce5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc1da12b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc1da1dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc1d7c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc1d7c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc1d7ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc1d7c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc1d7c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc1d7c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc220d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc220dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc220c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc220ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c01d0c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc1b9e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0b535adb88e390082cc11b9b458ba97d899508d1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5720 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 394266086 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5602e0f8a810, 0x5602e117401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5602e1174020,0x5602e300c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0b535adb88e390082cc11b9b458ba97d899508d1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7330 processed earlier; will process 3699 files now Step #5: ==206026== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5602d7a7f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5602de0e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602de0c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602de0c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5602d7a85d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5602d79e6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5602d79e1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5602d7a77c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5602daa46f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5602daa46f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5602daa46f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5602daa46f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5602daa46f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5602daa46f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5602daa46f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5602daa46f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5602daa46f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5602daa46f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5602dccdbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5602d9a08b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5602d9a13be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5602d97bfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5602d97bfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5602d97c0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5602d97bf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5602d97bf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5602d97bf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5602de0c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5602de0d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5602de0ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5602de0e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3f74027082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5602d79dfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1093dbb3171970571b10cdccf84eea6da19e3004 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5721 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 394837424 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559a72a5d810, 0x559a72c4701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559a72c47020,0x559a74adf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1093dbb3171970571b10cdccf84eea6da19e3004' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7331 processed earlier; will process 3698 files now Step #5: ==206062== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559a695529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559a6fbb7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559a6fb9a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559a6fb9a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559a69558d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559a694b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559a694b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559a6954ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559a6c519f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559a6c519f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559a6c519f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559a6c519f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559a6c519f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559a6c519f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559a6c519f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559a6c519f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559a6c519f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559a6c519f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559a6e7aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559a6b4dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559a6b4e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559a6b292c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559a6b292c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559a6b293738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559a6b292874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559a6b292874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559a6b292874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559a6fb9cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559a6fba5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559a6fb8d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559a6fbb8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0e95c14082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559a694b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8f4b53b7f83cf17852b4c732827a6fbc2151fb00 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5722 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 396084000 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5618146a4810, 0x56181488e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56181488e020,0x5618167260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8f4b53b7f83cf17852b4c732827a6fbc2151fb00' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7332 processed earlier; will process 3697 files now Step #5: ==206098== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56180b1999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5618117fe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5618117e15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5618117e14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56180b19fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56180b100b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56180b0fb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56180b191c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56180e160f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56180e160f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56180e160f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56180e160f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56180e160f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56180e160f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56180e160f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56180e160f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56180e160f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56180e160f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5618103f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56180d122b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56180d12dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56180ced9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56180ced9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56180ceda738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56180ced9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56180ced9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56180ced9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5618117e3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5618117ec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5618117d4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5618117ff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f818a26a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56180b0f9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fac33cf542d068da6a6ca47038926e3006f2d9a9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5723 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 397439872 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555fcc1b1810, 0x555fcc39b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555fcc39b020,0x555fce2330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fac33cf542d068da6a6ca47038926e3006f2d9a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7333 processed earlier; will process 3696 files now Step #5: ==206134== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555fc2ca69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555fc930b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555fc92ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555fc92ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555fc2cacd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555fc2c0db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555fc2c08355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555fc2c9ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555fc5c6df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555fc5c6df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555fc5c6df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555fc5c6df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555fc5c6df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555fc5c6df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555fc5c6df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555fc5c6df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555fc5c6df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555fc5c6df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555fc7f02f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555fc4c2fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555fc4c3abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555fc49e6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555fc49e6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555fc49e7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555fc49e6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555fc49e6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555fc49e6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555fc92f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555fc92f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555fc92e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555fc930c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8db3d2d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555fc2c06b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-15884df8d3b194453f34e532b29e4b02c8794ad7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5724 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 398649624 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56522f140810, 0x56522f32a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56522f32a020,0x5652311c20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/15884df8d3b194453f34e532b29e4b02c8794ad7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7334 processed earlier; will process 3695 files now Step #5: ==206170== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565225c359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56522c29a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56522c27d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56522c27d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565225c3bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565225b9cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565225b97355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565225c2dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565228bfcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565228bfcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565228bfcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565228bfcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565228bfcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565228bfcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565228bfcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565228bfcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565228bfcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565228bfcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56522ae91f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565227bbeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565227bc9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x565227975c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x565227975c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x565227976738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x565227975874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x565227975874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x565227975874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56522c27fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56522c288928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56522c270699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56522c29b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd882d48082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565225b95b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1604157f49cd585b8dc178bc48963ddf33c6adf8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5725 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 399186605 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e030050810, 0x55e03023a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e03023a020,0x55e0320d20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1604157f49cd585b8dc178bc48963ddf33c6adf8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7335 processed earlier; will process 3694 files now Step #5: ==206206== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e026b459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e02d1aa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e02d18d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e02d18d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e026b4bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e026aacb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e026aa7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e026b3dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e029b0cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e029b0cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e029b0cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e029b0cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e029b0cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e029b0cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e029b0cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e029b0cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e029b0cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e029b0cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e02bda1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e028aceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e028ad9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e028885c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e028885c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e028886738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e028885874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e028885874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e028885874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e02d18fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e02d198928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e02d180699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e02d1ab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff181abe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e026aa5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-64407297cd46ecb8975676818ed8d65709eb95e9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5726 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 400503669 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5577720ab810, 0x55777229501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557772295020,0x55777412d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/64407297cd46ecb8975676818ed8d65709eb95e9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7336 processed earlier; will process 3693 files now Step #5: #1 pulse cov: 4321 ft: 4322 exec/s: 0 rss: 181Mb Step #5: ==206242== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557768ba09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55776f205898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55776f1e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55776f1e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557768ba6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557768b07b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557768b02355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557768b98c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55776bb67f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55776bb67f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55776bb67f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55776bb67f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55776bb67f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55776bb67f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55776bb67f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55776bb67f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55776bb67f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55776bb67f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55776ddfcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55776ab29b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55776ab34be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55776a8e0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55776a8e0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55776a8e1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55776a8e0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55776a8e0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55776a8e0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55776f1eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55776f1f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55776f1db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55776f206112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6703f4d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557768b00b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e56f8a5d6253614b284585d32106b2b7ab2aee63 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5727 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 401874541 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556267822810, 0x556267a0c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556267a0c020,0x5562698a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e56f8a5d6253614b284585d32106b2b7ab2aee63' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7338 processed earlier; will process 3691 files now Step #5: ==206278== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55625e3179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55626497c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55626495f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55626495f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55625e31dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55625e27eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55625e279355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55625e30fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5562612def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5562612def10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5562612def10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5562612def10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5562612def10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5562612def10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5562612def10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5562612def10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5562612def10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5562612def10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556263573f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5562602a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5562602abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556260057c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556260057c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556260058738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556260057874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556260057874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556260057874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556264961abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55626496a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556264952699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55626497d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa5eb56a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55625e277b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f1135a43597889d967fad645c17be8739cffb87c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5728 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 402465602 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dedfd5d810, 0x55dedff4701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dedff47020,0x55dee1ddf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f1135a43597889d967fad645c17be8739cffb87c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7339 processed earlier; will process 3690 files now Step #5: ==206314== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ded68529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dedceb7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dedce9a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dedce9a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ded6858d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ded67b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ded67b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ded684ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ded9819f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ded9819f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ded9819f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ded9819f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ded9819f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ded9819f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ded9819f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ded9819f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ded9819f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ded9819f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dedbaaef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ded87dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ded87e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ded8592c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ded8592c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ded8593738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ded8592874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ded8592874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ded8592874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dedce9cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dedcea5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dedce8d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dedceb8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f301b6bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ded67b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-638d3ef53abc4bec5fbf8fc4298e54c4ce9566fb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5729 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 402996620 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56095f545810, 0x56095f72f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56095f72f020,0x5609615c70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/638d3ef53abc4bec5fbf8fc4298e54c4ce9566fb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7340 processed earlier; will process 3689 files now Step #5: ==206350== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56095603a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56095c69f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56095c6825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56095c6824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560956040d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560955fa1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560955f9c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560956032c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560959001f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560959001f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560959001f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560959001f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560959001f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560959001f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560959001f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560959001f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560959001f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560959001f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56095b296f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560957fc3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560957fcebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560957d7ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560957d7ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560957d7b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560957d7a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560957d7a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560957d7a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56095c684abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56095c68d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56095c675699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56095c6a0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa46b4c5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560955f9ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0ae37d0e0bf16ea8abc42e6300aa4e05eb2b3fc1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5730 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 404371068 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8c541d810, 0x55c8c560701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c8c5607020,0x55c8c749f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0ae37d0e0bf16ea8abc42e6300aa4e05eb2b3fc1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7341 processed earlier; will process 3688 files now Step #5: ==206386== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c8bbf129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8c2577898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8c255a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8c255a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c8bbf18d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c8bbe79b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c8bbe74355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c8bbf0ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c8beed9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c8beed9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c8beed9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c8beed9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c8beed9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c8beed9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c8beed9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c8beed9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c8beed9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c8beed9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c8c116ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c8bde9bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c8bdea6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c8bdc52c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c8bdc52c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c8bdc53738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c8bdc52874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c8bdc52874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c8bdc52874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8c255cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8c2565928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8c254d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8c2578112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27d27ef082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c8bbe72b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1d916081cc9096189bc947818fc7ba3a1cdaf857 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5731 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 404932635 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557fc9d35810, 0x557fc9f1f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557fc9f1f020,0x557fcbdb70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1d916081cc9096189bc947818fc7ba3a1cdaf857' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7342 processed earlier; will process 3687 files now Step #5: ==206422== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557fc082a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557fc6e8f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557fc6e725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557fc6e724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557fc0830d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557fc0791b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557fc078c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557fc0822c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557fc37f1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557fc37f1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557fc37f1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557fc37f1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557fc37f1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557fc37f1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557fc37f1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557fc37f1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557fc37f1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557fc37f1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557fc5a86f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557fc27b3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557fc27bebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557fc256ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557fc256ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557fc256b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557fc256a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557fc256a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557fc256a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557fc6e74abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557fc6e7d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557fc6e65699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557fc6e90112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd96b322082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557fc078ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-de990d8ac5ed3f850fc5820e61a342d4a1c8aaab Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5732 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 405476142 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562e1610d810, 0x562e162f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562e162f7020,0x562e1818f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de990d8ac5ed3f850fc5820e61a342d4a1c8aaab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7343 processed earlier; will process 3686 files now Step #5: ==206458== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562e0cc029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562e13267898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562e1324a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562e1324a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562e0cc08d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562e0cb69b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562e0cb64355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562e0cbfac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562e0fbc9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562e0fbc9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562e0fbc9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562e0fbc9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562e0fbc9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562e0fbc9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562e0fbc9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562e0fbc9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562e0fbc9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562e0fbc9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562e11e5ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562e0eb8bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562e0eb96be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562e0e942c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562e0e942c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562e0e943738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562e0e942874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562e0e942874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562e0e942874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562e1324cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562e13255928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562e1323d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562e13268112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa9fedea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562e0cb62b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb45e0220468fc9c9365c1c9307d36182d5deecd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5733 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 406689730 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e1e186810, 0x563e1e37001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e1e370020,0x563e202080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb45e0220468fc9c9365c1c9307d36182d5deecd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7344 processed earlier; will process 3685 files now Step #5: ==206494== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563e14c7b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e1b2e0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e1b2c35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e1b2c34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563e14c81d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563e14be2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563e14bdd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563e14c73c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563e17c42f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563e17c42f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563e17c42f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563e17c42f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563e17c42f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563e17c42f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563e17c42f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563e17c42f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563e17c42f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563e17c42f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e19ed7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563e16c04b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563e16c0fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563e169bbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563e169bbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563e169bc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563e169bb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563e169bb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563e169bb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e1b2c5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e1b2ce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e1b2b6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e1b2e1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffbdac25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563e14bdbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7ddb18d11b07212d47a1c01ec2926ecfbe627404 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5734 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 407230817 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a26de3b810, 0x55a26e02501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a26e025020,0x55a26febd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ddb18d11b07212d47a1c01ec2926ecfbe627404' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7345 processed earlier; will process 3684 files now Step #5: ==206530== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a2649309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a26af95898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a26af785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a26af784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a264936d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a264897b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a264892355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a264928c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a2678f7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a2678f7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a2678f7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a2678f7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a2678f7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a2678f7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a2678f7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a2678f7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a2678f7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a2678f7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a269b8cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a2668b9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a2668c4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a266670c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a266670c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a266671738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a266670874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a266670874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a266670874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a26af7aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a26af83928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a26af6b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a26af96112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0586a96082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a264890b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-65df78f6a83e772e606a4d2cade1130fd42d9804 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5735 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 408457691 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c9f89ae810, 0x55c9f8b9801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c9f8b98020,0x55c9faa300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/65df78f6a83e772e606a4d2cade1130fd42d9804' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7346 processed earlier; will process 3683 files now Step #5: #1 pulse cov: 4084 ft: 4085 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4480 ft: 5054 exec/s: 0 rss: 180Mb Step #5: ==206566== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c9ef4a39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c9f5b08898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9f5aeb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9f5aeb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9ef4a9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9ef40ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c9ef405355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9ef49bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c9f246af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c9f246af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c9f246af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c9f246af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c9f246af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c9f246af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c9f246af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c9f246af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c9f246af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c9f246af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c9f46fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9f142cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9f1437be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c9f11e3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c9f11e3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c9f11e4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c9f11e3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c9f11e3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c9f11e3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c9f5aedabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c9f5af6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c9f5ade699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c9f5b09112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf956ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c9ef403b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-11bae1c1255c5fda6ebd7e0a4103e5e908b09a80 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5736 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 409810364 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56340ecb7810, 0x56340eea101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56340eea1020,0x563410d390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/11bae1c1255c5fda6ebd7e0a4103e5e908b09a80' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7349 processed earlier; will process 3680 files now Step #5: ==206602== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5634057ac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56340be11898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56340bdf45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56340bdf44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5634057b2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563405713b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56340570e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5634057a4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563408773f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563408773f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563408773f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563408773f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563408773f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563408773f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563408773f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563408773f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563408773f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563408773f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56340aa08f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563407735b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563407740be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5634074ecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5634074ecc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5634074ed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5634074ec874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5634074ec874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5634074ec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56340bdf6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56340bdff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56340bde7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56340be12112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8bef8d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56340570cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a665c1e5c4a4a2e938028212bede38b525444be Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5737 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 411109816 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56528899f810, 0x565288b8901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565288b89020,0x56528aa210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a665c1e5c4a4a2e938028212bede38b525444be' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7350 processed earlier; will process 3679 files now Step #5: ==206638== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56527f4949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565285af9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565285adc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565285adc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56527f49ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56527f3fbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56527f3f6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56527f48cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56528245bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56528245bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56528245bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56528245bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56528245bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56528245bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56528245bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56528245bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56528245bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56528245bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652846f0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56528141db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565281428be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652811d4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652811d4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652811d5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652811d4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652811d4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652811d4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565285adeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565285ae7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565285acf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565285afa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f07e21c2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56527f3f4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1f9c60dedcd1a0d546ddb434c76e437ebfd86ea5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5738 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 411648072 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b3daf9b810, 0x55b3db18501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b3db185020,0x55b3dd01d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f9c60dedcd1a0d546ddb434c76e437ebfd86ea5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7351 processed earlier; will process 3678 files now Step #5: #1 pulse cov: 4109 ft: 4110 exec/s: 0 rss: 177Mb Step #5: ==206674== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b3d1a909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b3d80f5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b3d80d85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b3d80d84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b3d1a96d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b3d19f7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b3d19f2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b3d1a88c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b3d4a57f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b3d4a57f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b3d4a57f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b3d4a57f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b3d4a57f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b3d4a57f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b3d4a57f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b3d4a57f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b3d4a57f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b3d4a57f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b3d6cecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b3d3a19b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b3d3a24be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b3d37d0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b3d37d0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b3d37d1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b3d37d0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b3d37d0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b3d37d0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b3d80daabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b3d80e3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b3d80cb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b3d80f6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fed7e50e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b3d19f0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aebd086742ffbe9985162a7342605def1f1020ac Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5739 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 412346516 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611ef2fd810, 0x5611ef4e701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5611ef4e7020,0x5611f137f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aebd086742ffbe9985162a7342605def1f1020ac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7353 processed earlier; will process 3676 files now Step #5: #1 pulse cov: 4348 ft: 4349 exec/s: 0 rss: 178Mb Step #5: ==206710== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5611e5df29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5611ec457898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611ec43a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611ec43a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5611e5df8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5611e5d59b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5611e5d54355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5611e5deac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5611e8db9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5611e8db9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5611e8db9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5611e8db9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5611e8db9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5611e8db9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5611e8db9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5611e8db9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5611e8db9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5611e8db9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5611eb04ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611e7d7bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5611e7d86be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611e7b32c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611e7b32c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611e7b33738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611e7b32874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611e7b32874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611e7b32874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5611ec43cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5611ec445928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611ec42d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5611ec458112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efd2c8f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5611e5d52b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-74e36450b3fdbc3fe9439f82abb377f30f62fcb6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5740 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 412914649 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c71c90a810, 0x55c71caf401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c71caf4020,0x55c71e98c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/74e36450b3fdbc3fe9439f82abb377f30f62fcb6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7355 processed earlier; will process 3674 files now Step #5: #1 pulse cov: 4033 ft: 4034 exec/s: 0 rss: 179Mb Step #5: ==206746== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c7133ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c719a64898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c719a475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c719a474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c713405d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c713366b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c713361355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c7133f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7163c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7163c6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7163c6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7163c6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7163c6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7163c6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7163c6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7163c6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7163c6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7163c6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c71865bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c715388b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c715393be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c71513fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c71513fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c715140738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c71513f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c71513f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c71513f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c719a49abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c719a52928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c719a3a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c719a65112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f65fdbd4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c71335fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0fc0db686fcc2e30cafe77c6ad4835d4af32d120 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5741 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 413525820 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5605c3329810, 0x5605c351301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5605c3513020,0x5605c53ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0fc0db686fcc2e30cafe77c6ad4835d4af32d120' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7357 processed earlier; will process 3672 files now Step #5: #1 pulse cov: 3696 ft: 3697 exec/s: 0 rss: 179Mb Step #5: ==206782== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5605b9e1e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5605c0483898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605c04665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605c04664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5605b9e24d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5605b9d85b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5605b9d80355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5605b9e16c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5605bcde5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5605bcde5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5605bcde5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5605bcde5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5605bcde5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5605bcde5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5605bcde5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5605bcde5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5605bcde5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5605bcde5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5605bf07af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5605bbda7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5605bbdb2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5605bbb5ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5605bbb5ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5605bbb5f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5605bbb5e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5605bbb5e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5605bbb5e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605c0468abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5605c0471928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605c0459699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5605c0484112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f14d0b98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5605b9d7eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b8997cdee9965614a665122fc01a36978f088a46 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5742 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 414089927 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564bb1619810, 0x564bb180301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564bb1803020,0x564bb369b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b8997cdee9965614a665122fc01a36978f088a46' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7359 processed earlier; will process 3670 files now Step #5: #1 pulse cov: 11954 ft: 11955 exec/s: 0 rss: 203Mb Step #5: ==206818== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564ba810e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564bae773898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564bae7565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564bae7564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ba8114d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ba8075b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ba8070355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ba8106c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564bab0d5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564bab0d5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564bab0d5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564bab0d5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564bab0d5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564bab0d5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564bab0d5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564bab0d5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564bab0d5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564bab0d5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564bad36af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564baa097b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564baa0a2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564ba9e4ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564ba9e4ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564ba9e4f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564ba9e4e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564ba9e4e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564ba9e4e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564bae758abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564bae761928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564bae749699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564bae774112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3865ebb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ba806eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9daf609a7dccf7fee4274fc0cfe08109d8877740 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5743 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 414745406 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643ee38a810, 0x5643ee57401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643ee574020,0x5643f040c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9daf609a7dccf7fee4274fc0cfe08109d8877740' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7361 processed earlier; will process 3668 files now Step #5: #1 pulse cov: 3855 ft: 3856 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4362 ft: 4776 exec/s: 0 rss: 181Mb Step #5: ==206854== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643e4e7f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643eb4e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643eb4c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643eb4c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643e4e85d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643e4de6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643e4de1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643e4e77c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643e7e46f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643e7e46f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643e7e46f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643e7e46f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643e7e46f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643e7e46f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643e7e46f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643e7e46f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643e7e46f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643e7e46f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643ea0dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643e6e08b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643e6e13be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643e6bbfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643e6bbfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643e6bc0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643e6bbf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643e6bbf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643e6bbf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643eb4c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643eb4d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643eb4ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643eb4e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa8713d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643e4ddfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-65282e33ba65d7d33798144a28c39c80768b4feb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5744 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 415483858 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab3cf6f810, 0x55ab3d15901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab3d159020,0x55ab3eff10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/65282e33ba65d7d33798144a28c39c80768b4feb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7364 processed earlier; will process 3665 files now Step #5: #1 pulse cov: 3661 ft: 3662 exec/s: 0 rss: 180Mb Step #5: ==206890== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ab33a649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab3a0c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab3a0ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab3a0ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab33a6ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab339cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab339c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab33a5cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab36a2bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab36a2bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab36a2bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab36a2bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab36a2bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab36a2bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab36a2bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab36a2bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab36a2bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab36a2bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab38cc0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab359edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab359f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab357a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab357a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab357a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab357a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab357a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab357a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab3a0aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab3a0b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab3a09f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab3a0ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f156eb58082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab339c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-69afbd47933cb0aed0bc3079f4b08155d4ff566f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5745 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 416236308 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ad53ed810, 0x561ad55d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ad55d7020,0x561ad746f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/69afbd47933cb0aed0bc3079f4b08155d4ff566f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7366 processed earlier; will process 3663 files now Step #5: #1 pulse cov: 4131 ft: 4132 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 4482 ft: 5004 exec/s: 0 rss: 182Mb Step #5: ==206926== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561acbee29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561ad2547898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561ad252a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561ad252a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561acbee8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561acbe49b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561acbe44355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561acbedac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561aceea9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561aceea9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561aceea9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561aceea9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561aceea9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561aceea9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561aceea9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561aceea9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561aceea9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561aceea9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561ad113ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561acde6bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561acde76be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561acdc22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561acdc22c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561acdc23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561acdc22874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561acdc22874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561acdc22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561ad252cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561ad2535928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561ad251d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561ad2548112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95f4393082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561acbe42b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-81f8f652f17a7da25f82084da81b6a8a01c4a4f0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5746 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 416905069 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bee32eb810, 0x55bee34d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bee34d5020,0x55bee536d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/81f8f652f17a7da25f82084da81b6a8a01c4a4f0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7369 processed earlier; will process 3660 files now Step #5: #1 pulse cov: 4197 ft: 4198 exec/s: 0 rss: 179Mb Step #5: ==206962== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bed9de09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bee0445898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bee04285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bee04284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bed9de6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bed9d47b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bed9d42355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bed9dd8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bedcda7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bedcda7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bedcda7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bedcda7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bedcda7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bedcda7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bedcda7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bedcda7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bedcda7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bedcda7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bedf03cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bedbd69b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bedbd74be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bedbb20c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bedbb20c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bedbb21738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bedbb20874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bedbb20874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bedbb20874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bee042aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bee0433928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bee041b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bee0446112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdcca3ea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bed9d40b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c96e46ee32b3d3b7c4a95c3f7e812e8530f52c03 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5747 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 417511369 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e2f1059810, 0x55e2f124301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e2f1243020,0x55e2f30db0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c96e46ee32b3d3b7c4a95c3f7e812e8530f52c03' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7371 processed earlier; will process 3658 files now Step #5: ==206998== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e2e7b4e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e2ee1b3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e2ee1965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e2ee1964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e2e7b54d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e2e7ab5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e2e7ab0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e2e7b46c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e2eab15f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e2eab15f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e2eab15f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e2eab15f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e2eab15f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e2eab15f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e2eab15f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e2eab15f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e2eab15f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e2eab15f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e2ecdaaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e2e9ad7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e2e9ae2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e2e988ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e2e988ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e2e988f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e2e988e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e2e988e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e2e988e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e2ee198abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e2ee1a1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e2ee189699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e2ee1b4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa190a6f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e2e7aaeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8e7341e8d335bafadbb1b3f4bda8b762cc63cc59 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5748 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 418059358 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559273d8e810, 0x559273f7801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559273f78020,0x559275e100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8e7341e8d335bafadbb1b3f4bda8b762cc63cc59' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7372 processed earlier; will process 3657 files now Step #5: ==207034== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55926a8839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559270ee8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559270ecb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559270ecb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55926a889d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55926a7eab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55926a7e5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55926a87bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55926d84af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55926d84af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55926d84af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55926d84af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55926d84af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55926d84af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55926d84af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55926d84af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55926d84af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55926d84af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55926fadff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55926c80cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55926c817be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55926c5c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55926c5c3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55926c5c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55926c5c3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55926c5c3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55926c5c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559270ecdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559270ed6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559270ebe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559270ee9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53dbff8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55926a7e3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fb9dafbb31e5202f51da8d80bf2514daf7ddddd7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5749 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 418742611 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4c8908810, 0x55e4c8af201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4c8af2020,0x55e4ca98a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fb9dafbb31e5202f51da8d80bf2514daf7ddddd7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7373 processed earlier; will process 3656 files now Step #5: ==207070== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e4bf3fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4c5a62898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4c5a455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4c5a454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4bf403d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4bf364b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4bf35f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4bf3f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4c23c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4c23c4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4c23c4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4c23c4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4c23c4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4c23c4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4c23c4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4c23c4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4c23c4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4c23c4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4c4659f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4c1386b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4c1391be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4c113dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4c113dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4c113e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4c113d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4c113d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4c113d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4c5a47abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4c5a50928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4c5a38699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4c5a63112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f35d6c2c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4bf35db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8d856bd206fa3ae1fde0f5171bb6d66bebcb7f58 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5750 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 419292072 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564bd1829810, 0x564bd1a1301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564bd1a13020,0x564bd38ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d856bd206fa3ae1fde0f5171bb6d66bebcb7f58' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7374 processed earlier; will process 3655 files now Step #5: ==207106== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564bc831e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564bce983898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564bce9665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564bce9664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564bc8324d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564bc8285b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564bc8280355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564bc8316c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564bcb2e5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564bcb2e5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564bcb2e5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564bcb2e5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564bcb2e5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564bcb2e5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564bcb2e5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564bcb2e5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564bcb2e5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564bcb2e5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564bcd57af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564bca2a7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564bca2b2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564bca05ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564bca05ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564bca05f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564bca05e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564bca05e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564bca05e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564bce968abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564bce971928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564bce959699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564bce984112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f688e11e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564bc827eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-559490189481ef4acd171b74404dbbb6d8282a5f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5751 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 419816903 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558946016810, 0x55894620001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558946200020,0x5589480980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/559490189481ef4acd171b74404dbbb6d8282a5f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7375 processed earlier; will process 3654 files now Step #5: ==207142== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55893cb0b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558943170898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589431535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589431534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55893cb11d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55893ca72b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55893ca6d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55893cb03c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55893fad2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55893fad2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55893fad2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55893fad2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55893fad2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55893fad2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55893fad2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55893fad2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55893fad2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55893fad2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558941d67f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55893ea94b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55893ea9fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55893e84bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55893e84bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55893e84c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55893e84b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55893e84b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55893e84b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558943155abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55894315e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558943146699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558943171112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f42b5675082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55893ca6bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7f8c3416bd5cd227847b73d8a5a62d88a8d9da8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5752 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 420368804 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5585f600f810, 0x5585f61f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5585f61f9020,0x5585f80910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7f8c3416bd5cd227847b73d8a5a62d88a8d9da8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7376 processed earlier; will process 3653 files now Step #5: ==207178== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5585ecb049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5585f3169898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5585f314c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5585f314c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5585ecb0ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5585eca6bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5585eca66355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5585ecafcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5585efacbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5585efacbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5585efacbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5585efacbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5585efacbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5585efacbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5585efacbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5585efacbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5585efacbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5585efacbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5585f1d60f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5585eea8db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5585eea98be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5585ee844c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5585ee844c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5585ee845738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5585ee844874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5585ee844874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5585ee844874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5585f314eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5585f3157928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5585f313f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5585f316a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe176b3f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5585eca64b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c99d5a78bc98abf647bc3cede33775d59533d80d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5753 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 420904360 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5587a40d0810, 0x5587a42ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5587a42ba020,0x5587a61520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c99d5a78bc98abf647bc3cede33775d59533d80d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7377 processed earlier; will process 3652 files now Step #5: ==207214== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55879abc59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5587a122a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5587a120d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5587a120d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55879abcbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55879ab2cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55879ab27355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55879abbdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55879db8cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55879db8cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55879db8cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55879db8cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55879db8cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55879db8cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55879db8cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55879db8cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55879db8cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55879db8cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55879fe21f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55879cb4eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55879cb59be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55879c905c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55879c905c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55879c906738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55879c905874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55879c905874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55879c905874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5587a120fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5587a1218928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5587a1200699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5587a122b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fde10fc2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55879ab25b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6392f1cedec7ef3b140ebf0524711466aa34dea7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5754 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 421453144 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56250bdef810, 0x56250bfd901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56250bfd9020,0x56250de710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6392f1cedec7ef3b140ebf0524711466aa34dea7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7378 processed earlier; will process 3651 files now Step #5: ==207250== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5625028e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562508f49898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562508f2c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562508f2c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5625028ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56250284bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562502846355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5625028dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5625058abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5625058abf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5625058abf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5625058abf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5625058abf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5625058abf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5625058abf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5625058abf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5625058abf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5625058abf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562507b40f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56250486db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562504878be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562504624c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562504624c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562504625738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562504624874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562504624874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562504624874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562508f2eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562508f37928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562508f1f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562508f4a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f72afc26082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562502844b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3bfaed2ca608a096b3e543d89060cac5eb8cef04 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5755 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 421998538 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555afc5cb810, 0x555afc7b501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555afc7b5020,0x555afe64d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3bfaed2ca608a096b3e543d89060cac5eb8cef04' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7379 processed earlier; will process 3650 files now Step #5: #1 pulse cov: 4250 ft: 4251 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4548 ft: 5076 exec/s: 0 rss: 179Mb Step #5: ==207286== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555af30c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555af9725898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555af97085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555af97084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555af30c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555af3027b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555af3022355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555af30b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555af6087f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555af6087f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555af6087f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555af6087f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555af6087f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555af6087f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555af6087f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555af6087f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555af6087f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555af6087f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555af831cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555af5049b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555af5054be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555af4e00c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555af4e00c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555af4e01738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555af4e00874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555af4e00874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555af4e00874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555af970aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555af9713928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555af96fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555af9726112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2e4c2b5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555af3020b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bbd3934c1c31a775ea109d4d8e99ac139bd1ad0f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5756 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 422672613 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec64abe810, 0x55ec64ca801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec64ca8020,0x55ec66b400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bbd3934c1c31a775ea109d4d8e99ac139bd1ad0f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7383 processed earlier; will process 3646 files now Step #5: ==207322== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec5b5b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec61c18898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec61bfb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec61bfb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec5b5b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec5b51ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec5b515355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec5b5abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec5e57af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec5e57af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec5e57af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec5e57af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec5e57af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec5e57af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec5e57af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec5e57af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec5e57af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec5e57af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec6080ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec5d53cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec5d547be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec5d2f3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec5d2f3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec5d2f4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec5d2f3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec5d2f3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec5d2f3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec61bfdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec61c06928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec61bee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec61c19112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2478bcd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec5b513b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ccbaf3e64b027520ca45c45c157bb09c51593f1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5757 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 423328113 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5636455f2810, 0x5636457dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5636457dc020,0x5636476740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ccbaf3e64b027520ca45c45c157bb09c51593f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7384 processed earlier; will process 3645 files now Step #5: #1 pulse cov: 3743 ft: 3744 exec/s: 0 rss: 177Mb Step #5: ==207358== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56363c0e79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56364274c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56364272f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56364272f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56363c0edd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56363c04eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56363c049355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56363c0dfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56363f0aef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56363f0aef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56363f0aef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56363f0aef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56363f0aef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56363f0aef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56363f0aef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56363f0aef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56363f0aef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56363f0aef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563641343f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56363e070b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56363e07bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56363de27c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56363de27c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56363de28738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56363de27874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56363de27874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56363de27874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563642731abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56364273a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563642722699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56364274d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0703504082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56363c047b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-399837fabbd86772c2ab0b4354f183f7f6cfd262 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5758 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 423905284 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561bb37d9810, 0x561bb39c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561bb39c3020,0x561bb585b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/399837fabbd86772c2ab0b4354f183f7f6cfd262' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7386 processed earlier; will process 3643 files now Step #5: ==207394== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561baa2ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561bb0933898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561bb09165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561bb09164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561baa2d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561baa235b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561baa230355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561baa2c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561bad295f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561bad295f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561bad295f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561bad295f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561bad295f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561bad295f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561bad295f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561bad295f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561bad295f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561bad295f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561baf52af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561bac257b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561bac262be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561bac00ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561bac00ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561bac00f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561bac00e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561bac00e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561bac00e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561bb0918abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561bb0921928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561bb0909699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561bb0934112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa4c103082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561baa22eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1b10e34971ad7603f6ca5577faeb3b9e9d11f929 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5759 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 424457872 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e260ffe810, 0x55e2611e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e2611e8020,0x55e2630800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b10e34971ad7603f6ca5577faeb3b9e9d11f929' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7387 processed earlier; will process 3642 files now Step #5: ==207430== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e257af39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e25e158898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e25e13b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e25e13b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e257af9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e257a5ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e257a55355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e257aebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e25aabaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e25aabaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e25aabaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e25aabaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e25aabaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e25aabaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e25aabaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e25aabaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e25aabaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e25aabaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e25cd4ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e259a7cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e259a87be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e259833c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e259833c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e259834738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e259833874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e259833874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e259833874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e25e13dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e25e146928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e25e12e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e25e159112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f23f0a69082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e257a53b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e3e1d6c2288dc6cb966f49c4d72694ea13c364d1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5760 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 425006810 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563204ca4810, 0x563204e8e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563204e8e020,0x563206d260e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e3e1d6c2288dc6cb966f49c4d72694ea13c364d1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7388 processed earlier; will process 3641 files now Step #5: ==207466== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5631fb7999c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563201dfe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563201de15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563201de14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5631fb79fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5631fb700b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5631fb6fb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5631fb791c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5631fe760f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5631fe760f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5631fe760f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5631fe760f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5631fe760f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5631fe760f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5631fe760f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5631fe760f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5631fe760f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5631fe760f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5632009f5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5631fd722b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5631fd72dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5631fd4d9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5631fd4d9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5631fd4da738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5631fd4d9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5631fd4d9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5631fd4d9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563201de3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563201dec928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563201dd4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563201dff112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f71054e1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5631fb6f9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5d59bcaa6cacbeb5e5c236ab1be28414e09195da Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5761 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 425700475 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557602854810, 0x557602a3e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557602a3e020,0x5576048d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5d59bcaa6cacbeb5e5c236ab1be28414e09195da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7389 processed earlier; will process 3640 files now Step #5: ==207502== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5575f93499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5575ff9ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5575ff9915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5575ff9914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5575f934fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5575f92b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5575f92ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5575f9341c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5575fc310f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5575fc310f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5575fc310f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5575fc310f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5575fc310f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5575fc310f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5575fc310f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5575fc310f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5575fc310f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5575fc310f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5575fe5a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5575fb2d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5575fb2ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5575fb089c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5575fb089c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5575fb08a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5575fb089874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5575fb089874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5575fb089874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5575ff993abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5575ff99c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5575ff984699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5575ff9af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7aa54f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5575f92a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-88d604ca5be068d0764cc95e919d957264e3c4d7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5762 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 426235343 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640aab6c810, 0x5640aad5601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640aad56020,0x5640acbee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88d604ca5be068d0764cc95e919d957264e3c4d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7390 processed earlier; will process 3639 files now Step #5: ==207538== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5640a16619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5640a7cc6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640a7ca95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640a7ca94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5640a1667d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5640a15c8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5640a15c3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5640a1659c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5640a4628f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5640a4628f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5640a4628f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5640a4628f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5640a4628f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5640a4628f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5640a4628f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5640a4628f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5640a4628f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5640a4628f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5640a68bdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5640a35eab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5640a35f5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5640a33a1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5640a33a1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5640a33a2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5640a33a1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5640a33a1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5640a33a1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5640a7cababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5640a7cb4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5640a7c9c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5640a7cc7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f48d2237082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5640a15c1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-185da167379c660fce2ca952a87258fc3bd31697 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5763 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 426786902 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56203cd00810, 0x56203ceea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56203ceea020,0x56203ed820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/185da167379c660fce2ca952a87258fc3bd31697' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7391 processed earlier; will process 3638 files now Step #5: ==207574== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5620337f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562039e5a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562039e3d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562039e3d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5620337fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56203375cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562033757355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5620337edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5620367bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5620367bcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5620367bcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5620367bcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5620367bcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5620367bcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5620367bcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5620367bcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5620367bcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5620367bcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562038a51f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56203577eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562035789be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562035535c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562035535c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562035536738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562035535874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562035535874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562035535874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562039e3fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562039e48928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562039e30699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562039e5b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe3efa97082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562033755b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e582ec932c90f10f81471ef58cbc9e85f0543918 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5764 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 427339522 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561e09aa5810, 0x561e09c8f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561e09c8f020,0x561e0bb270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e582ec932c90f10f81471ef58cbc9e85f0543918' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7392 processed earlier; will process 3637 files now Step #5: ==207610== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561e0059a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561e06bff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561e06be25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561e06be24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561e005a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561e00501b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561e004fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561e00592c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561e03561f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561e03561f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561e03561f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561e03561f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561e03561f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561e03561f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561e03561f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561e03561f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561e03561f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561e03561f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561e057f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561e02523b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561e0252ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561e022dac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561e022dac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561e022db738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561e022da874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561e022da874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561e022da874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561e06be4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561e06bed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561e06bd5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561e06c00112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68a7366082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561e004fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8646e44d708512d2f3a62e33875ba925d33b0028 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5765 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 427873264 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dbdd984810, 0x55dbddb6e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dbddb6e020,0x55dbdfa060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8646e44d708512d2f3a62e33875ba925d33b0028' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7393 processed earlier; will process 3636 files now Step #5: ==207646== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dbd44799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dbdaade898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dbdaac15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dbdaac14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dbd447fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dbd43e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dbd43db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dbd4471c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dbd7440f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dbd7440f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dbd7440f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dbd7440f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dbd7440f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dbd7440f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dbd7440f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dbd7440f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dbd7440f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dbd7440f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dbd96d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dbd6402b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dbd640dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dbd61b9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dbd61b9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dbd61ba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dbd61b9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dbd61b9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dbd61b9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dbdaac3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dbdaacc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dbdaab4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dbdaadf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1044303082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dbd43d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b3df9c34d9b2d0e7addd1ddff1ca9bd291286967 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5766 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 428408944 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563f058b0810, 0x563f05a9a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563f05a9a020,0x563f079320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3df9c34d9b2d0e7addd1ddff1ca9bd291286967' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7394 processed earlier; will process 3635 files now Step #5: #1 pulse cov: 4358 ft: 4359 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 4662 ft: 5177 exec/s: 0 rss: 182Mb Step #5: ==207682== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563efc3a59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563f02a0a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563f029ed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563f029ed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563efc3abd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563efc30cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563efc307355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563efc39dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563eff36cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563eff36cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563eff36cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563eff36cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563eff36cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563eff36cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563eff36cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563eff36cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563eff36cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563eff36cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563f01601f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563efe32eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563efe339be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563efe0e5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563efe0e5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563efe0e6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563efe0e5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563efe0e5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563efe0e5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563f029efabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563f029f8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563f029e0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563f02a0b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb9377a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563efc305b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-552270d39797dd52e45f99eb9ef0bbb3a3cc19e8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5767 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 429248357 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e030384810, 0x55e03056e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e03056e020,0x55e0324060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/552270d39797dd52e45f99eb9ef0bbb3a3cc19e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7398 processed earlier; will process 3631 files now Step #5: ==207718== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e026e799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e02d4de898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e02d4c15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e02d4c14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e026e7fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e026de0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e026ddb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e026e71c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e029e40f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e029e40f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e029e40f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e029e40f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e029e40f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e029e40f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e029e40f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e029e40f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e029e40f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e029e40f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e02c0d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e028e02b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e028e0dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e028bb9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e028bb9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e028bba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e028bb9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e028bb9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e028bb9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e02d4c3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e02d4cc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e02d4b4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e02d4df112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5925f4e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e026dd9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-944f85b4565d7b34748ebcb116c862133c248b1c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5768 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 429931046 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5635e6fc7810, 0x5635e71b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5635e71b1020,0x5635e90490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/944f85b4565d7b34748ebcb116c862133c248b1c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7399 processed earlier; will process 3630 files now Step #5: ==207754== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5635ddabc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5635e4121898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5635e41045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5635e41044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5635ddac2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5635dda23b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5635dda1e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5635ddab4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5635e0a83f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5635e0a83f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5635e0a83f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5635e0a83f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5635e0a83f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5635e0a83f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5635e0a83f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5635e0a83f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5635e0a83f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5635e0a83f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5635e2d18f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5635dfa45b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5635dfa50be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5635df7fcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5635df7fcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5635df7fd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5635df7fc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5635df7fc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5635df7fc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5635e4106abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5635e410f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5635e40f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5635e4122112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa2473b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5635dda1cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a7314df2e6ede7034bf4f57bc153675b302131e3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5769 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 430494206 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55da9b123810, 0x55da9b30d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55da9b30d020,0x55da9d1a50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a7314df2e6ede7034bf4f57bc153675b302131e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7400 processed earlier; will process 3629 files now Step #5: #1 pulse cov: 4093 ft: 4094 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4564 ft: 5169 exec/s: 0 rss: 179Mb Step #5: ==207790== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55da91c189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55da9827d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55da982605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55da982604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55da91c1ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55da91b7fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55da91b7a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55da91c10c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55da94bdff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55da94bdff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55da94bdff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55da94bdff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55da94bdff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55da94bdff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55da94bdff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55da94bdff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55da94bdff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55da94bdff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55da96e74f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55da93ba1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55da93bacbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55da93958c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55da93958c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55da93959738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55da93958874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55da93958874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55da93958874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55da98262abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55da9826b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55da98253699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55da9827e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5dc1d19082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55da91b78b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f2b49cf768371c39e3d5f80dcf8095ead5049c04 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5770 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 431109572 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5584e206d810, 0x5584e225701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5584e2257020,0x5584e40ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f2b49cf768371c39e3d5f80dcf8095ead5049c04' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7403 processed earlier; will process 3626 files now Step #5: ==207826== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5584d8b629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5584df1c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5584df1aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5584df1aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5584d8b68d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5584d8ac9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5584d8ac4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5584d8b5ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5584dbb29f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5584dbb29f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5584dbb29f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5584dbb29f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5584dbb29f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5584dbb29f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5584dbb29f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5584dbb29f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5584dbb29f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5584dbb29f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5584dddbef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5584daaebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5584daaf6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5584da8a2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5584da8a2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5584da8a3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5584da8a2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5584da8a2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5584da8a2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5584df1acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5584df1b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5584df19d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5584df1c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc4fdb23082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5584d8ac2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-16a77d9dc12a2d9a1812ee90b3756be5fc54ce1d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5771 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 431701215 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56112cd77810, 0x56112cf6101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56112cf61020,0x56112edf90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16a77d9dc12a2d9a1812ee90b3756be5fc54ce1d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7404 processed earlier; will process 3625 files now Step #5: ==207862== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56112386c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561129ed1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561129eb45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561129eb44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561123872d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5611237d3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5611237ce355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561123864c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561126833f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561126833f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561126833f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561126833f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561126833f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561126833f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561126833f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561126833f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561126833f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561126833f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561128ac8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611257f5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561125800be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611255acc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611255acc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611255ad738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611255ac874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611255ac874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611255ac874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561129eb6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561129ebf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561129ea7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561129ed2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88018f4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5611237ccb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c9bd381bcf9ab59c658942394097744aade5a20d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5772 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 432236740 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d7fb302810, 0x55d7fb4ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d7fb4ec020,0x55d7fd3840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9bd381bcf9ab59c658942394097744aade5a20d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7405 processed earlier; will process 3624 files now Step #5: ==207898== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d7f1df79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d7f845c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7f843f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7f843f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d7f1dfdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d7f1d5eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d7f1d59355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d7f1defc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d7f4dbef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d7f4dbef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d7f4dbef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d7f4dbef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d7f4dbef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d7f4dbef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d7f4dbef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d7f4dbef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d7f4dbef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d7f4dbef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d7f7053f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d7f3d80b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d7f3d8bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d7f3b37c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d7f3b37c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d7f3b38738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d7f3b37874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d7f3b37874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d7f3b37874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d7f8441abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d7f844a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d7f8432699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d7f845d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc1f4391082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d7f1d57b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4ab96345d5eb750ef9bf6a3d7043f30a1a40d87f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5773 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 433412922 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec2d0c8810, 0x55ec2d2b201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec2d2b2020,0x55ec2f14a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4ab96345d5eb750ef9bf6a3d7043f30a1a40d87f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7406 processed earlier; will process 3623 files now Step #5: ==207934== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec23bbd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec2a222898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec2a2055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec2a2054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec23bc3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec23b24b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec23b1f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec23bb5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec26b84f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec26b84f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec26b84f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec26b84f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec26b84f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec26b84f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec26b84f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec26b84f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec26b84f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec26b84f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec28e19f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec25b46b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec25b51be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec258fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec258fdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec258fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec258fd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec258fd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec258fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec2a207abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec2a210928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec2a1f8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec2a223112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7ae1df6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec23b1db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0bb33b8e481e2c7d5f7029726932f39ec80a2fdf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5774 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 434767283 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d459ec3810, 0x55d45a0ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d45a0ad020,0x55d45bf450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0bb33b8e481e2c7d5f7029726932f39ec80a2fdf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7407 processed earlier; will process 3622 files now Step #5: ==207970== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d4509b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d45701d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d4570005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d4570004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d4509bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d45091fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d45091a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d4509b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d45397ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d45397ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d45397ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d45397ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d45397ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d45397ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d45397ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d45397ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d45397ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d45397ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d455c14f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d452941b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d45294cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d4526f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d4526f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d4526f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d4526f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d4526f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d4526f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d457002abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d45700b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d456ff3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d45701e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc37406c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d450918b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cdba46dbcf11469e1ec62bc738f4dff493a91a06 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5775 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 435427046 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cad19d5810, 0x55cad1bbf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cad1bbf020,0x55cad3a570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cdba46dbcf11469e1ec62bc738f4dff493a91a06' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7408 processed earlier; will process 3621 files now Step #5: ==208006== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cac84ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55caceb2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55caceb125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55caceb124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cac84d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cac8431b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cac842c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cac84c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cacb491f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cacb491f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cacb491f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cacb491f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cacb491f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cacb491f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cacb491f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cacb491f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cacb491f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cacb491f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cacd726f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55caca453b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55caca45ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55caca20ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55caca20ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55caca20b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55caca20a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55caca20a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55caca20a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55caceb14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55caceb1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55caceb05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55caceb30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff295d2f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cac842ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-796c0667756ba9483df158aac54de6328618e3e6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5776 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 435967417 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559801ce0810, 0x559801eca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559801eca020,0x559803d620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/796c0667756ba9483df158aac54de6328618e3e6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7409 processed earlier; will process 3620 files now Step #5: ==208042== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5597f87d59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5597fee3a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5597fee1d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5597fee1d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5597f87dbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5597f873cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5597f8737355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5597f87cdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5597fb79cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5597fb79cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5597fb79cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5597fb79cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5597fb79cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5597fb79cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5597fb79cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5597fb79cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5597fb79cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5597fb79cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5597fda31f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5597fa75eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5597fa769be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5597fa515c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5597fa515c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5597fa516738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5597fa515874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5597fa515874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5597fa515874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5597fee1fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5597fee28928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5597fee10699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5597fee3b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7b31192082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5597f8735b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-12b7ee9d1cf6e31ba20af4145a37d729547de2ea Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5777 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 436510408 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5638ea2f3810, 0x5638ea4dd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5638ea4dd020,0x5638ec3750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/12b7ee9d1cf6e31ba20af4145a37d729547de2ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7410 processed earlier; will process 3619 files now Step #5: ==208078== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5638e0de89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5638e744d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5638e74305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5638e74304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5638e0deed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5638e0d4fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5638e0d4a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5638e0de0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5638e3daff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5638e3daff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5638e3daff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5638e3daff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5638e3daff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5638e3daff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5638e3daff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5638e3daff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5638e3daff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5638e3daff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5638e6044f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5638e2d71b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5638e2d7cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5638e2b28c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5638e2b28c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5638e2b29738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5638e2b28874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5638e2b28874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5638e2b28874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5638e7432abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5638e743b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5638e7423699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5638e744e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f25b791e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5638e0d48b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8a37853800c415b62d5a90814d9f36c9f4b7a25a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5778 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 437738608 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56490682b810, 0x564906a1501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564906a15020,0x5649088ad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8a37853800c415b62d5a90814d9f36c9f4b7a25a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7411 processed earlier; will process 3618 files now Step #5: ==208114== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5648fd3209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564903985898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5649039685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5649039684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5648fd326d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5648fd287b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5648fd282355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5648fd318c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5649002e7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5649002e7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5649002e7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5649002e7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5649002e7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5649002e7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5649002e7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5649002e7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5649002e7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5649002e7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56490257cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5648ff2a9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5648ff2b4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5648ff060c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5648ff060c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5648ff061738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5648ff060874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5648ff060874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5648ff060874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56490396aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564903973928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56490395b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564903986112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a19752082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5648fd280b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-50aa28aedc0476b927dd4d00d955a0e59e92d2a1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5779 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 438278744 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55908208c810, 0x55908227601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559082276020,0x55908410e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/50aa28aedc0476b927dd4d00d955a0e59e92d2a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7412 processed earlier; will process 3617 files now Step #5: ==208150== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559078b819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55907f1e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55907f1c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55907f1c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559078b87d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559078ae8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559078ae3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559078b79c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55907bb48f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55907bb48f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55907bb48f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55907bb48f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55907bb48f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55907bb48f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55907bb48f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55907bb48f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55907bb48f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55907bb48f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55907ddddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55907ab0ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55907ab15be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55907a8c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55907a8c1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55907a8c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55907a8c1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55907a8c1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55907a8c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55907f1cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55907f1d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55907f1bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55907f1e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f01a9d3c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559078ae1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-127a7e9b6c031c574bddd3b6e9b4f0310f1d0f0c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5780 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 438866143 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563baabf6810, 0x563baade001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563baade0020,0x563bacc780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/127a7e9b6c031c574bddd3b6e9b4f0310f1d0f0c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7413 processed earlier; will process 3616 files now Step #5: ==208186== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563ba16eb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563ba7d50898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563ba7d335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563ba7d334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563ba16f1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563ba1652b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563ba164d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563ba16e3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563ba46b2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563ba46b2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563ba46b2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563ba46b2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563ba46b2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563ba46b2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563ba46b2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563ba46b2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563ba46b2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563ba46b2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563ba6947f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563ba3674b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563ba367fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563ba342bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563ba342bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563ba342c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563ba342b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563ba342b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563ba342b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563ba7d35abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563ba7d3e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563ba7d26699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563ba7d51112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc7abcfa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563ba164bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aa0c652ccbe68dfcc0f7a51b03f6a6f0021f473c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5781 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 439398123 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b68e79c810, 0x55b68e98601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b68e986020,0x55b69081e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aa0c652ccbe68dfcc0f7a51b03f6a6f0021f473c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7414 processed earlier; will process 3615 files now Step #5: ==208222== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b6852919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b68b8f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b68b8d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b68b8d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b685297d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6851f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6851f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b685289c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b688258f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b688258f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b688258f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b688258f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b688258f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b688258f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b688258f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b688258f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b688258f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b688258f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b68a4edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b68721ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b687225be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b686fd1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b686fd1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b686fd2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b686fd1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b686fd1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b686fd1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b68b8dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b68b8e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b68b8cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b68b8f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb69c6d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6851f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2f58d57dae616a74c166314b5458c4f8bc19ab64 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5782 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 439924200 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556dfafe6810, 0x556dfb1d001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556dfb1d0020,0x556dfd0680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f58d57dae616a74c166314b5458c4f8bc19ab64' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7415 processed earlier; will process 3614 files now Step #5: ==208258== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556df1adb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556df8140898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556df81235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556df81234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556df1ae1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556df1a42b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556df1a3d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556df1ad3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556df4aa2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556df4aa2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556df4aa2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556df4aa2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556df4aa2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556df4aa2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556df4aa2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556df4aa2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556df4aa2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556df4aa2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556df6d37f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556df3a64b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556df3a6fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556df381bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556df381bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556df381c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556df381b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556df381b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556df381b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556df8125abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556df812e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556df8116699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556df8141112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0c4687082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556df1a3bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-68e5b83fc2819eb12d0055f8ad9b37e04646be23 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5783 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 440477733 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b9094c810, 0x561b90b3601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b90b36020,0x561b929ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/68e5b83fc2819eb12d0055f8ad9b37e04646be23' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7416 processed earlier; will process 3613 files now Step #5: #1 pulse cov: 3720 ft: 3721 exec/s: 0 rss: 179Mb Step #5: ==208294== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561b874419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b8daa6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b8da895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b8da894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b87447d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b873a8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b873a3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b87439c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b8a408f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b8a408f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b8a408f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b8a408f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b8a408f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b8a408f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b8a408f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b8a408f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b8a408f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b8a408f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b8c69df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b893cab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b893d5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b89181c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b89181c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b89182738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b89181874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b89181874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b89181874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b8da8babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b8da94928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b8da7c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b8daa7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f19eb7d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b873a1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7ad06eaf1c59bb20e0cc67c8bd7c4509325fb18c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5784 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 441703317 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56399ca32810, 0x56399cc1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56399cc1c020,0x56399eab40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ad06eaf1c59bb20e0cc67c8bd7c4509325fb18c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7418 processed earlier; will process 3611 files now Step #5: ==208330== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5639935279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563999b8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563999b6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563999b6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56399352dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56399348eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563993489355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56399351fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5639964eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5639964eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5639964eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5639964eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5639964eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5639964eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5639964eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5639964eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5639964eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5639964eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563998783f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5639954b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5639954bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563995267c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563995267c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563995268738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563995267874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563995267874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563995267874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563999b71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563999b7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563999b62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563999b8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc50a033082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563993487b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1145dd19be5418e3dbb3e5c42be2dbf92fbfd906 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5785 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 442254365 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c1c2839810, 0x55c1c2a2301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c1c2a23020,0x55c1c48bb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1145dd19be5418e3dbb3e5c42be2dbf92fbfd906' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7419 processed earlier; will process 3610 files now Step #5: #1 pulse cov: 3762 ft: 3763 exec/s: 0 rss: 178Mb Step #5: ==208366== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c1b932e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c1bf993898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c1bf9765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c1bf9764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c1b9334d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c1b9295b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c1b9290355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c1b9326c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c1bc2f5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c1bc2f5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c1bc2f5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c1bc2f5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c1bc2f5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c1bc2f5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c1bc2f5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c1bc2f5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c1bc2f5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c1bc2f5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c1be58af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c1bb2b7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c1bb2c2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c1bb06ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c1bb06ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c1bb06f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c1bb06e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c1bb06e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c1bb06e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c1bf978abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c1bf981928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c1bf969699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c1bf994112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba03113082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c1b928eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bfb84e566926c4823d55ac3d41dfb274affb806f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5786 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 443649642 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a803126810, 0x55a80331001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a803310020,0x55a8051a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bfb84e566926c4823d55ac3d41dfb274affb806f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7421 processed earlier; will process 3608 files now Step #5: ==208402== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a7f9c1b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a800280898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a8002635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a8002634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a7f9c21d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a7f9b82b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a7f9b7d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a7f9c13c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a7fcbe2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a7fcbe2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a7fcbe2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a7fcbe2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a7fcbe2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a7fcbe2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a7fcbe2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a7fcbe2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a7fcbe2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a7fcbe2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a7fee77f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a7fbba4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a7fbbafbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a7fb95bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a7fb95bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a7fb95c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a7fb95b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a7fb95b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a7fb95b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a800265abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a80026e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a800256699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a800281112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdec5c49082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a7f9b7bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-737d8ef16b13a4003937c9b110a597a73c4f4367 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5787 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 444196958 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ba7c8a810, 0x555ba7e7401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ba7e74020,0x555ba9d0c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/737d8ef16b13a4003937c9b110a597a73c4f4367' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7422 processed earlier; will process 3607 files now Step #5: ==208438== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555b9e77f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ba4de4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ba4dc75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ba4dc74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b9e785d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b9e6e6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b9e6e1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b9e777c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ba1746f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ba1746f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ba1746f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ba1746f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ba1746f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ba1746f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ba1746f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ba1746f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ba1746f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ba1746f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555ba39dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ba0708b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ba0713be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ba04bfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ba04bfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ba04c0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ba04bf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ba04bf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ba04bf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ba4dc9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ba4dd2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ba4dba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ba4de5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4f3349082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b9e6dfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-db23dc9300184cfe91137900f378cddab34bd046 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5788 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 445560395 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55adace38810, 0x55adad02201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55adad022020,0x55adaeeba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/db23dc9300184cfe91137900f378cddab34bd046' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7423 processed earlier; will process 3606 files now Step #5: ==208474== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ada392d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ada9f92898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ada9f755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ada9f754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ada3933d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ada3894b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ada388f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ada3925c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ada68f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ada68f4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ada68f4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ada68f4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ada68f4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ada68f4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ada68f4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ada68f4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ada68f4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ada68f4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ada8b89f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ada58b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ada58c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ada566dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ada566dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ada566e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ada566d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ada566d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ada566d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ada9f77abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ada9f80928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ada9f68699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ada9f93112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9323018082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ada388db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fe8fccf45878fe4265686dc75f107caabac91379 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5789 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 446864443 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55757f8f6810, 0x55757fae001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55757fae0020,0x5575819780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fe8fccf45878fe4265686dc75f107caabac91379' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7424 processed earlier; will process 3605 files now Step #5: #1 pulse cov: 4121 ft: 4122 exec/s: 0 rss: 180Mb Step #5: ==208510== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5575763eb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55757ca50898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55757ca335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55757ca334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5575763f1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557576352b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55757634d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5575763e3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5575793b2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5575793b2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5575793b2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5575793b2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5575793b2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5575793b2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5575793b2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5575793b2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5575793b2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5575793b2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55757b647f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557578374b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55757837fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55757812bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55757812bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55757812c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55757812b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55757812b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55757812b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55757ca35abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55757ca3e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55757ca26699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55757ca51112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe1d7d44082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55757634bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7832c736aabec20a916bf0ceb0c9dfe67c075274 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5790 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 447587130 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d4f0fa810, 0x563d4f2e401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d4f2e4020,0x563d5117c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7832c736aabec20a916bf0ceb0c9dfe67c075274' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7426 processed earlier; will process 3603 files now Step #5: ==208546== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563d45bef9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d4c254898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d4c2375dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d4c2374fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d45bf5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d45b56b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d45b51355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d45be7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d48bb6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d48bb6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d48bb6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d48bb6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d48bb6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d48bb6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d48bb6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d48bb6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d48bb6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d48bb6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d4ae4bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d47b78b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d47b83be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d4792fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d4792fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d47930738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d4792f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d4792f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d4792f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d4c239abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d4c242928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d4c22a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d4c255112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f307e02c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d45b4fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cdd96643beb1e6d4560674ddbad85936704691d0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5791 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 448181128 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d197fa810, 0x556d199e401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d199e4020,0x556d1b87c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cdd96643beb1e6d4560674ddbad85936704691d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7427 processed earlier; will process 3602 files now Step #5: ==208582== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556d102ef9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d16954898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d169375dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d169374fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d102f5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d10256b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d10251355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d102e7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d132b6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d132b6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d132b6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d132b6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d132b6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d132b6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d132b6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d132b6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d132b6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d132b6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d1554bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d12278b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d12283be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d1202fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d1202fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d12030738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d1202f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d1202f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d1202f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d16939abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d16942928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d1692a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d16955112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f38126b7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d1024fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-08de2c14bbff6afa8515eb98f6f3b9517fdf9aa0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5792 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 448717240 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb1cdaf810, 0x55cb1cf9901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb1cf99020,0x55cb1ee310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08de2c14bbff6afa8515eb98f6f3b9517fdf9aa0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7428 processed earlier; will process 3601 files now Step #5: ==208618== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cb138a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb19f09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb19eec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb19eec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb138aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb1380bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb13806355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb1389cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb1686bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb1686bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb1686bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb1686bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb1686bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb1686bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb1686bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb1686bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb1686bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb1686bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb18b00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb1582db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb15838be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb155e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb155e4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb155e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb155e4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb155e4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb155e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb19eeeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb19ef7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb19edf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb19f0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdefe24f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb13804b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7d2c660ae90fe34a78859b92bfb30277da90a156 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5793 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 449424495 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee9edfd810, 0x55ee9efe701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee9efe7020,0x55eea0e7f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d2c660ae90fe34a78859b92bfb30277da90a156' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7429 processed earlier; will process 3600 files now Step #5: #1 pulse cov: 3930 ft: 3931 exec/s: 0 rss: 179Mb Step #5: ==208654== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ee958f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee9bf57898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee9bf3a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee9bf3a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee958f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee95859b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee95854355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee958eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee988b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee988b9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee988b9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee988b9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee988b9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee988b9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee988b9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee988b9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee988b9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee988b9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee9ab4ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee9787bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee97886be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee97632c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee97632c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee97633738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee97632874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee97632874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee97632874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee9bf3cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee9bf45928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee9bf2d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee9bf58112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f85317f4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee95852b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e1c4378700224915700e60f8787e0bb5d812157f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5794 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 450009483 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564141c7c810, 0x564141e6601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564141e66020,0x564143cfe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e1c4378700224915700e60f8787e0bb5d812157f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7431 processed earlier; will process 3598 files now Step #5: #1 pulse cov: 3877 ft: 3878 exec/s: 0 rss: 180Mb Step #5: ==208690== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5641387719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56413edd6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56413edb95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56413edb94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564138777d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641386d8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641386d3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564138769c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56413b738f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56413b738f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56413b738f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56413b738f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56413b738f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56413b738f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56413b738f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56413b738f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56413b738f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56413b738f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56413d9cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56413a6fab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56413a705be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56413a4b1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56413a4b1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56413a4b2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56413a4b1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56413a4b1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56413a4b1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56413edbbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56413edc4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56413edac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56413edd7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f55a3a19082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641386d1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-75cc60552a8c54e4699a6d047ae0875db1399e09 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5795 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 450619791 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5598bb201810, 0x5598bb3eb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5598bb3eb020,0x5598bd2830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/75cc60552a8c54e4699a6d047ae0875db1399e09' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7433 processed earlier; will process 3596 files now Step #5: ==208726== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5598b1cf69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5598b835b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5598b833e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5598b833e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5598b1cfcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5598b1c5db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5598b1c58355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5598b1ceec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5598b4cbdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5598b4cbdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5598b4cbdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5598b4cbdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5598b4cbdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5598b4cbdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5598b4cbdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5598b4cbdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5598b4cbdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5598b4cbdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5598b6f52f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5598b3c7fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5598b3c8abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5598b3a36c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5598b3a36c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5598b3a37738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5598b3a36874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5598b3a36874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5598b3a36874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5598b8340abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5598b8349928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5598b8331699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5598b835c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fef57eb1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5598b1c56b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-51c11ae10a9c5aa980e278903f96003e3e7a5215 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5796 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 451161532 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561717bde810, 0x561717dc801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561717dc8020,0x561719c600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/51c11ae10a9c5aa980e278903f96003e3e7a5215' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7434 processed earlier; will process 3595 files now Step #5: ==208762== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56170e6d39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561714d38898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561714d1b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561714d1b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56170e6d9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56170e63ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56170e635355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56170e6cbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56171169af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56171169af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56171169af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56171169af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56171169af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56171169af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56171169af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56171169af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56171169af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56171169af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56171392ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56171065cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561710667be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561710413c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561710413c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561710414738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561710413874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561710413874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561710413874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561714d1dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561714d26928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561714d0e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561714d39112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc6f31e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56170e633b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e91bb75209809e6f117954b9772c67b4fe87045e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5797 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 451760410 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc7a806810, 0x55cc7a9f001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc7a9f0020,0x55cc7c8880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e91bb75209809e6f117954b9772c67b4fe87045e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7435 processed earlier; will process 3594 files now Step #5: #1 pulse cov: 11201 ft: 11202 exec/s: 0 rss: 199Mb Step #5: ==208798== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cc712fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc77960898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc779435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc779434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc71301d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc71262b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc7125d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc712f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc742c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc742c2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc742c2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc742c2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc742c2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc742c2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc742c2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc742c2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc742c2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc742c2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc76557f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc73284b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc7328fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc7303bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc7303bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc7303c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc7303b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc7303b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc7303b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc77945abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc7794e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc77936699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc77961112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ce0958082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc7125bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bfacc76aaf65b6b57450c1c68c8a780fa5bd38fb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5798 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 452387936 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562f4aee6810, 0x562f4b0d001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562f4b0d0020,0x562f4cf680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bfacc76aaf65b6b57450c1c68c8a780fa5bd38fb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7437 processed earlier; will process 3592 files now Step #5: #1 pulse cov: 4084 ft: 4085 exec/s: 0 rss: 178Mb Step #5: ==208834== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562f419db9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562f48040898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562f480235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562f480234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562f419e1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562f41942b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562f4193d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562f419d3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562f449a2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562f449a2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562f449a2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562f449a2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562f449a2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562f449a2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562f449a2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562f449a2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562f449a2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562f449a2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562f46c37f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562f43964b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562f4396fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562f4371bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562f4371bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562f4371c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562f4371b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562f4371b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562f4371b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562f48025abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562f4802e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562f48016699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562f48041112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbbd0715082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562f4193bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-71f802ddfde51a38e909c08169855f1985e8222b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5799 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 452998616 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5590eef1b810, 0x5590ef10501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5590ef105020,0x5590f0f9d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/71f802ddfde51a38e909c08169855f1985e8222b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7439 processed earlier; will process 3590 files now Step #5: ==208870== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5590e5a109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5590ec075898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5590ec0585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5590ec0584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5590e5a16d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5590e5977b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5590e5972355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5590e5a08c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5590e89d7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5590e89d7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5590e89d7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5590e89d7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5590e89d7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5590e89d7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5590e89d7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5590e89d7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5590e89d7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5590e89d7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5590eac6cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5590e7999b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5590e79a4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5590e7750c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5590e7750c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5590e7751738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5590e7750874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5590e7750874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5590e7750874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5590ec05aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5590ec063928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5590ec04b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5590ec076112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9e90ccb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5590e5970b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3be70fdd8a0965b7f828b19119be2f447db88705 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5800 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 453646031 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c518c3a810, 0x55c518e2401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c518e24020,0x55c51acbc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3be70fdd8a0965b7f828b19119be2f447db88705' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7440 processed earlier; will process 3589 files now Step #5: #1 pulse cov: 3569 ft: 3570 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 3734 ft: 4102 exec/s: 0 rss: 180Mb Step #5: #4 pulse cov: 12022 ft: 13397 exec/s: 0 rss: 200Mb Step #5: ==208906== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c50f72f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c515d94898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c515d775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c515d774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c50f735d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c50f696b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c50f691355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c50f727c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c5126f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c5126f6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c5126f6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c5126f6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c5126f6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c5126f6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c5126f6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c5126f6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c5126f6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c5126f6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c51498bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c5116b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c5116c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c51146fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c51146fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c511470738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c51146f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c51146f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c51146f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c515d79abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c515d82928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c515d6a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c515d95112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b45eca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c50f68fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-446e03af8b19aded2c9752714ff3f8a40a286af2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5801 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 454369932 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dac4571810, 0x55dac475b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dac475b020,0x55dac65f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/446e03af8b19aded2c9752714ff3f8a40a286af2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7445 processed earlier; will process 3584 files now Step #5: ==208942== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dabb0669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dac16cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dac16ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dac16ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dabb06cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dabafcdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dabafc8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dabb05ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dabe02df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dabe02df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dabe02df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dabe02df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dabe02df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dabe02df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dabe02df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dabe02df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dabe02df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dabe02df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dac02c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dabcfefb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dabcffabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dabcda6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dabcda6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dabcda7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dabcda6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dabcda6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dabcda6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dac16b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dac16b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dac16a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dac16cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f883b396082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dabafc6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7a504bac30c191688e26ac81b3223cf05a2155d3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5802 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 454934334 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c45527810, 0x564c4571101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c45711020,0x564c475a90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7a504bac30c191688e26ac81b3223cf05a2155d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7446 processed earlier; will process 3583 files now Step #5: #1 pulse cov: 4354 ft: 4355 exec/s: 0 rss: 179Mb Step #5: ==208978== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564c3c01c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c42681898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c426645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c426644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c3c022d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c3bf83b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c3bf7e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c3c014c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c3efe3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c3efe3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c3efe3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c3efe3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c3efe3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c3efe3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c3efe3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c3efe3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c3efe3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c3efe3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c41278f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c3dfa5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c3dfb0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c3dd5cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c3dd5cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c3dd5d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c3dd5c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c3dd5c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c3dd5c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c42666abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c4266f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c42657699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c42682112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f894637e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c3bf7cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8323fb7828898265565df67800e62b701ac7f74 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5803 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 455526300 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d49d668810, 0x55d49d85201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d49d852020,0x55d49f6ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8323fb7828898265565df67800e62b701ac7f74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7448 processed earlier; will process 3581 files now Step #5: ==209014== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d49415d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d49a7c2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d49a7a55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d49a7a54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d494163d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d4940c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d4940bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d494155c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d497124f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d497124f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d497124f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d497124f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d497124f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d497124f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d497124f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d497124f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d497124f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d497124f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d4993b9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d4960e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d4960f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d495e9dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d495e9dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d495e9e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d495e9d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d495e9d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d495e9d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d49a7a7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d49a7b0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d49a798699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d49a7c3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feceb5f4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d4940bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b6bf242495aec331ab354a858450ec3fecd75bbe Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5804 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 456067194 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a8e741e810, 0x55a8e760801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a8e7608020,0x55a8e94a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b6bf242495aec331ab354a858450ec3fecd75bbe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7449 processed earlier; will process 3580 files now Step #5: ==209050== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a8ddf139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a8e4578898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a8e455b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a8e455b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a8ddf19d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a8dde7ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a8dde75355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a8ddf0bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a8e0edaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a8e0edaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a8e0edaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a8e0edaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a8e0edaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a8e0edaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a8e0edaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a8e0edaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a8e0edaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a8e0edaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a8e316ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a8dfe9cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a8dfea7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a8dfc53c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a8dfc53c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a8dfc54738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a8dfc53874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a8dfc53874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a8dfc53874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a8e455dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a8e4566928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a8e454e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a8e4579112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f783e865082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a8dde73b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c24142c9992d6b7b1e7378aac0f936ccb3176fdd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5805 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 456620701 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0b4f6f810, 0x55a0b515901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0b5159020,0x55a0b6ff10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c24142c9992d6b7b1e7378aac0f936ccb3176fdd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7450 processed earlier; will process 3579 files now Step #5: ==209086== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0aba649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0b20c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0b20ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0b20ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0aba6ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0ab9cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0ab9c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0aba5cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0aea2bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0aea2bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0aea2bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0aea2bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0aea2bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0aea2bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0aea2bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0aea2bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0aea2bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0aea2bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0b0cc0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0ad9edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0ad9f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0ad7a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0ad7a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0ad7a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0ad7a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0ad7a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0ad7a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0b20aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0b20b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0b209f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0b20ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2883a01082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0ab9c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aab489ed0848dee70c51cd95e8765d72abbd5fea Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5806 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 457175641 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564448520810, 0x56444870a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56444870a020,0x56444a5a20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aab489ed0848dee70c51cd95e8765d72abbd5fea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7451 processed earlier; will process 3578 files now Step #5: #1 pulse cov: 3783 ft: 3784 exec/s: 0 rss: 179Mb Step #5: ==209122== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56443f0159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56444567a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56444565d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56444565d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56443f01bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56443ef7cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56443ef77355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56443f00dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564441fdcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564441fdcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564441fdcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564441fdcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564441fdcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564441fdcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564441fdcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564441fdcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564441fdcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564441fdcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564444271f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564440f9eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564440fa9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564440d55c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564440d55c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564440d56738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564440d55874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564440d55874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564440d55874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56444565fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564445668928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564445650699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56444567b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f47c33ac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56443ef75b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0682087a995d5a0d4aa31cae9063d8bc8aa4b5a9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5807 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 457889092 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e258f87810, 0x55e25917101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e259171020,0x55e25b0090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0682087a995d5a0d4aa31cae9063d8bc8aa4b5a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7453 processed earlier; will process 3576 files now Step #5: ==209158== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e24fa7c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e2560e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e2560c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e2560c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e24fa82d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e24f9e3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e24f9de355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e24fa74c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e252a43f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e252a43f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e252a43f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e252a43f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e252a43f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e252a43f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e252a43f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e252a43f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e252a43f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e252a43f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e254cd8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e251a05b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e251a10be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e2517bcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e2517bcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e2517bd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e2517bc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e2517bc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e2517bc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e2560c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e2560cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e2560b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e2560e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc5faa85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e24f9dcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-03b191dd01d7dd9e8ea83a9ba4698aba761cfaa9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5808 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 459203548 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56547282a810, 0x565472a1401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565472a14020,0x5654748ac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03b191dd01d7dd9e8ea83a9ba4698aba761cfaa9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7454 processed earlier; will process 3575 files now Step #5: ==209194== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56546931f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56546f984898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56546f9675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56546f9674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565469325d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565469286b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565469281355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565469317c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56546c2e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56546c2e6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56546c2e6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56546c2e6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56546c2e6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56546c2e6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56546c2e6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56546c2e6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56546c2e6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56546c2e6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56546e57bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56546b2a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56546b2b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56546b05fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56546b05fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56546b060738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56546b05f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56546b05f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56546b05f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56546f969abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56546f972928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56546f95a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56546f985112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f66c3857082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56546927fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1b385ee1cf142452463180dd041ef0f5f0f0774d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5809 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 459746980 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558c520ea810, 0x558c522d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558c522d4020,0x558c5416c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b385ee1cf142452463180dd041ef0f5f0f0774d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7455 processed earlier; will process 3574 files now Step #5: ==209230== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558c48bdf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558c4f244898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558c4f2275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558c4f2274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558c48be5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558c48b46b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558c48b41355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558c48bd7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558c4bba6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558c4bba6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558c4bba6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558c4bba6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558c4bba6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558c4bba6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558c4bba6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558c4bba6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558c4bba6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558c4bba6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558c4de3bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558c4ab68b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558c4ab73be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558c4a91fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558c4a91fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558c4a920738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558c4a91f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558c4a91f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558c4a91f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558c4f229abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558c4f232928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558c4f21a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558c4f245112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c0b253082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558c48b3fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-caca5bb3125d68e35bdfaab38262a1687eb5b002 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5810 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 460293470 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b18349d810, 0x55b18368701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b183687020,0x55b18551f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/caca5bb3125d68e35bdfaab38262a1687eb5b002' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7456 processed earlier; will process 3573 files now Step #5: ==209266== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b179f929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b1805f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1805da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1805da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b179f98d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b179ef9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b179ef4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b179f8ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b17cf59f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b17cf59f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b17cf59f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b17cf59f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b17cf59f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b17cf59f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b17cf59f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b17cf59f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b17cf59f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b17cf59f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b17f1eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b17bf1bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b17bf26be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b17bcd2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b17bcd2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b17bcd3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b17bcd2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b17bcd2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b17bcd2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b1805dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b1805e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b1805cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b1805f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f2ee9d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b179ef2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e1fe41d82e0d88eef1778ab21afc97778e87d4a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5811 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 460882741 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f8e4e57810, 0x55f8e504101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f8e5041020,0x55f8e6ed90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e1fe41d82e0d88eef1778ab21afc97778e87d4a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7457 processed earlier; will process 3572 files now Step #5: #1 pulse cov: 11602 ft: 11603 exec/s: 0 rss: 198Mb Step #5: #2 pulse cov: 11741 ft: 13406 exec/s: 0 rss: 200Mb Step #5: ==209302== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8db94c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f8e1fb1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8e1f945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8e1f944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8db952d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8db8b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8db8ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8db944c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8de913f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8de913f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8de913f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8de913f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8de913f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8de913f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8de913f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8de913f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8de913f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8de913f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f8e0ba8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f8dd8d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f8dd8e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8dd68cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8dd68cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8dd68d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8dd68c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8dd68c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8dd68c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f8e1f96abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f8e1f9f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f8e1f87699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f8e1fb2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0663fc4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8db8acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a6a2f0a6c98e356fc39adf14eb24f23ceb12e7d9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5812 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 461612491 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b7b947810, 0x557b7bb3101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b7bb31020,0x557b7d9c90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a6a2f0a6c98e356fc39adf14eb24f23ceb12e7d9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7461 processed earlier; will process 3568 files now Step #5: #1 pulse cov: 4398 ft: 4399 exec/s: 0 rss: 177Mb Step #5: ==209338== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557b7243c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b78aa1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b78a845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b78a844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b72442d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b723a3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b7239e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b72434c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b75403f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b75403f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b75403f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b75403f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b75403f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b75403f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b75403f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b75403f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b75403f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b75403f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b77698f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b743c5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b743d0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b7417cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b7417cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b7417d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b7417c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b7417c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b7417c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b78a86abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b78a8f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b78a77699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b78aa2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b7b0dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b7239cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cd9f84562023712f6b9e7331521aaf06575c4b1d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5813 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 462195059 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b8d66f9810, 0x55b8d68e301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b8d68e3020,0x55b8d877b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd9f84562023712f6b9e7331521aaf06575c4b1d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7463 processed earlier; will process 3566 files now Step #5: #1 pulse cov: 15666 ft: 15667 exec/s: 0 rss: 202Mb Step #5: ==209374== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b8cd1ee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b8d3853898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b8d38365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b8d38364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b8cd1f4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b8cd155b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b8cd150355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b8cd1e6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b8d01b5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b8d01b5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b8d01b5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b8d01b5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b8d01b5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b8d01b5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b8d01b5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b8d01b5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b8d01b5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b8d01b5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b8d244af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b8cf177b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b8cf182be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b8cef2ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b8cef2ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b8cef2f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b8cef2e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b8cef2e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b8cef2e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b8d3838abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b8d3841928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b8d3829699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b8d3854112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0cb94b9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b8cd14eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-dea547192d19664246bbc9e759aad57f94838492 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5814 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 462970641 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56143fe72810, 0x56144005c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56144005c020,0x561441ef40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dea547192d19664246bbc9e759aad57f94838492' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7465 processed earlier; will process 3564 files now Step #5: #1 pulse cov: 4252 ft: 4253 exec/s: 0 rss: 178Mb Step #5: ==209410== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5614369679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56143cfcc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56143cfaf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56143cfaf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56143696dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5614368ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5614368c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56143695fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56143992ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56143992ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56143992ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56143992ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56143992ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56143992ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56143992ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56143992ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56143992ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56143992ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56143bbc3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5614388f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5614388fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5614386a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5614386a7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5614386a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5614386a7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5614386a7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5614386a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56143cfb1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56143cfba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56143cfa2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56143cfcd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f749ead6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5614368c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4badeea1dfc69a032937dbde25e7981118b9d7b9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5815 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 463609126 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559757b7c810, 0x559757d6601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559757d66020,0x559759bfe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4badeea1dfc69a032937dbde25e7981118b9d7b9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7467 processed earlier; will process 3562 files now Step #5: ==209446== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55974e6719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559754cd6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559754cb95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559754cb94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55974e677d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55974e5d8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55974e5d3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55974e669c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559751638f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559751638f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559751638f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559751638f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559751638f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559751638f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559751638f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559751638f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559751638f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559751638f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5597538cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5597505fab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559750605be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5597503b1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5597503b1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5597503b2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5597503b1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5597503b1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5597503b1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559754cbbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559754cc4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559754cac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559754cd7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe6fb840082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55974e5d1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d7ea1cb1da60bd7bcfd89bb0b4dee1321f040e2e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5816 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 464140846 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55639c9a8810, 0x55639cb9201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55639cb92020,0x55639ea2a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d7ea1cb1da60bd7bcfd89bb0b4dee1321f040e2e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7468 processed earlier; will process 3561 files now Step #5: ==209482== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55639349d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556399b02898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556399ae55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556399ae54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5563934a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556393404b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5563933ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556393495c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556396464f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556396464f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556396464f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556396464f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556396464f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556396464f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556396464f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556396464f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556396464f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556396464f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5563986f9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556395426b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556395431be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5563951ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5563951ddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5563951de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5563951dd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5563951dd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5563951dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556399ae7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556399af0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556399ad8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556399b03112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc827a1f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5563933fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-357b9e93a448dd2bb1670b2c1f08248b71768c9c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5817 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 464695744 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56316bc63810, 0x56316be4d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56316be4d020,0x56316dce50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/357b9e93a448dd2bb1670b2c1f08248b71768c9c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7469 processed earlier; will process 3560 files now Step #5: ==209518== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5631627589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563168dbd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563168da05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563168da04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56316275ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5631626bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5631626ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563162750c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56316571ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56316571ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56316571ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56316571ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56316571ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56316571ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56316571ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56316571ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56316571ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56316571ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5631679b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5631646e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5631646ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563164498c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563164498c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563164499738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563164498874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563164498874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563164498874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563168da2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563168dab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563168d93699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563168dbe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5749b25082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5631626b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7010e4094541e4fd2cef6e414df1cb04d90fa352 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5818 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 465255244 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562a5a0fe810, 0x562a5a2e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562a5a2e8020,0x562a5c1800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7010e4094541e4fd2cef6e414df1cb04d90fa352' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7470 processed earlier; will process 3559 files now Step #5: #1 pulse cov: 4392 ft: 4393 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 13009 ft: 13937 exec/s: 0 rss: 200Mb Step #5: ==209554== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562a50bf39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562a57258898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562a5723b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562a5723b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562a50bf9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562a50b5ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562a50b55355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562a50bebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562a53bbaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562a53bbaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562a53bbaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562a53bbaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562a53bbaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562a53bbaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562a53bbaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562a53bbaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562a53bbaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562a53bbaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562a55e4ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562a52b7cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562a52b87be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562a52933c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562a52933c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562a52934738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562a52933874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562a52933874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562a52933874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562a5723dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562a57246928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562a5722e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562a57259112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f253eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562a50b53b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8fa89dac81a307dd2dcbb122ebdd5c3e488c7883 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5819 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 465910119 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea2b710810, 0x55ea2b8fa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea2b8fa020,0x55ea2d7920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8fa89dac81a307dd2dcbb122ebdd5c3e488c7883' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7473 processed earlier; will process 3556 files now Step #5: ==209590== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ea222059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea2886a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea2884d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea2884d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea2220bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea2216cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea22167355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea221fdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea251ccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea251ccf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea251ccf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea251ccf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea251ccf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea251ccf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea251ccf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea251ccf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea251ccf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea251ccf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea27461f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea2418eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea24199be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea23f45c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea23f45c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea23f46738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea23f45874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea23f45874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea23f45874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea2884fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea28858928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea28840699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea2886b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6874391082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea22165b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-80fe5615978d1de3c50556333db1c8e39d7454ea Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5820 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 466449529 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5628a46d8810, 0x5628a48c201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5628a48c2020,0x5628a675a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/80fe5615978d1de3c50556333db1c8e39d7454ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7474 processed earlier; will process 3555 files now Step #5: ==209626== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56289b1cd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5628a1832898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5628a18155dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5628a18154fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56289b1d3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56289b134b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56289b12f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56289b1c5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56289e194f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56289e194f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56289e194f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56289e194f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56289e194f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56289e194f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56289e194f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56289e194f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56289e194f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56289e194f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5628a0429f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56289d156b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56289d161be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56289cf0dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56289cf0dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56289cf0e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56289cf0d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56289cf0d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56289cf0d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5628a1817abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5628a1820928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5628a1808699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5628a1833112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f08ca4be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56289b12db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9a0fb9f4107d0890af17b697d265cf5961cb4098 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5821 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 467027145 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55abc886c810, 0x55abc8a5601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55abc8a56020,0x55abca8ee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9a0fb9f4107d0890af17b697d265cf5961cb4098' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7475 processed earlier; will process 3554 files now Step #5: #1 pulse cov: 3998 ft: 3999 exec/s: 0 rss: 180Mb Step #5: ==209662== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55abbf3619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55abc59c6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55abc59a95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55abc59a94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55abbf367d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55abbf2c8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55abbf2c3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55abbf359c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55abc2328f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55abc2328f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55abc2328f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55abc2328f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55abc2328f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55abc2328f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55abc2328f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55abc2328f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55abc2328f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55abc2328f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55abc45bdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55abc12eab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55abc12f5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55abc10a1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55abc10a1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55abc10a2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55abc10a1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55abc10a1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55abc10a1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55abc59ababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55abc59b4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55abc599c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55abc59c7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5b4af4a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55abbf2c1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1d00877e425e5c8867038942465a0d9f878d6f19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5822 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 467629180 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f9f8b84810, 0x55f9f8d6e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f9f8d6e020,0x55f9fac060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1d00877e425e5c8867038942465a0d9f878d6f19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7477 processed earlier; will process 3552 files now Step #5: ==209698== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f9ef6799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f9f5cde898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f9f5cc15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f9f5cc14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f9ef67fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f9ef5e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f9ef5db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f9ef671c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f9f2640f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f9f2640f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f9f2640f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f9f2640f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f9f2640f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f9f2640f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f9f2640f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f9f2640f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f9f2640f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f9f2640f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f9f48d5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f9f1602b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f9f160dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f9f13b9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f9f13b9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f9f13ba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f9f13b9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f9f13b9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f9f13b9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f9f5cc3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f9f5ccc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f9f5cb4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f9f5cdf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f14e5cac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f9ef5d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6636821dbe4294a80e61dd517132dd4fbe656662 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5823 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 468201503 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5572e1253810, 0x5572e143d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5572e143d020,0x5572e32d50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6636821dbe4294a80e61dd517132dd4fbe656662' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7478 processed earlier; will process 3551 files now Step #5: ==209734== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5572d7d489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5572de3ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5572de3905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5572de3904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5572d7d4ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5572d7cafb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5572d7caa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5572d7d40c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5572dad0ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5572dad0ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5572dad0ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5572dad0ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5572dad0ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5572dad0ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5572dad0ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5572dad0ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5572dad0ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5572dad0ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5572dcfa4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5572d9cd1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5572d9cdcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5572d9a88c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5572d9a88c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5572d9a89738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5572d9a88874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5572d9a88874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5572d9a88874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5572de392abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5572de39b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5572de383699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5572de3ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa59854e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5572d7ca8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3260eba225487aaa410ace23e13f46f3ee5db4b3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5824 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 468752783 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56493ad7f810, 0x56493af6901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56493af69020,0x56493ce010e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3260eba225487aaa410ace23e13f46f3ee5db4b3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7479 processed earlier; will process 3550 files now Step #5: ==209770== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5649318749c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564937ed9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564937ebc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564937ebc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56493187ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649317dbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649317d6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56493186cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56493483bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56493483bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56493483bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56493483bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56493483bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56493483bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56493483bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56493483bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56493483bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56493483bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564936ad0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649337fdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564933808be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5649335b4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5649335b4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5649335b5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5649335b4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5649335b4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5649335b4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564937ebeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564937ec7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564937eaf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564937eda112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0dbad6d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649317d4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0fd7d1e165d9d3d7e9f427e8d139f462b7abfc37 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5825 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 469308734 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557f253e2810, 0x557f255cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557f255cc020,0x557f274640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0fd7d1e165d9d3d7e9f427e8d139f462b7abfc37' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7480 processed earlier; will process 3549 files now Step #5: ==209806== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557f1bed79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f2253c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f2251f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f2251f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f1beddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f1be3eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f1be39355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f1becfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f1ee9ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f1ee9ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f1ee9ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f1ee9ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f1ee9ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f1ee9ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f1ee9ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f1ee9ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f1ee9ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f1ee9ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f21133f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f1de60b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f1de6bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f1dc17c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f1dc17c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f1dc18738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f1dc17874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f1dc17874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f1dc17874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f22521abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f2252a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f22512699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f2253d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc29f1a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f1be37b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-435c0ec7e241f98fb8f9186c9dcfa1347e839da2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5826 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 469856362 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5594e60fc810, 0x5594e62e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5594e62e6020,0x5594e817e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/435c0ec7e241f98fb8f9186c9dcfa1347e839da2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7481 processed earlier; will process 3548 files now Step #5: ==209842== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5594dcbf19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5594e3256898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5594e32395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5594e32394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5594dcbf7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5594dcb58b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5594dcb53355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5594dcbe9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5594dfbb8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5594dfbb8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5594dfbb8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5594dfbb8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5594dfbb8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5594dfbb8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5594dfbb8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5594dfbb8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5594dfbb8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5594dfbb8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5594e1e4df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5594deb7ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5594deb85be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5594de931c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5594de931c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5594de932738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5594de931874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5594de931874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5594de931874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5594e323babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5594e3244928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5594e322c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5594e3257112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe66e05082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5594dcb51b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f3df80228e7614a5469d757770a7403984741155 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5827 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 470571344 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b38a92810, 0x561b38c7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b38c7c020,0x561b3ab140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f3df80228e7614a5469d757770a7403984741155' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7482 processed earlier; will process 3547 files now Step #5: ==209878== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561b2f5879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b35bec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b35bcf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b35bcf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b2f58dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b2f4eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b2f4e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b2f57fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b3254ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b3254ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b3254ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b3254ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b3254ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b3254ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b3254ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b3254ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b3254ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b3254ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b347e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b31510b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b3151bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b312c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b312c7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b312c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b312c7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b312c7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b312c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b35bd1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b35bda928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b35bc2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b35bed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2417cbb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b2f4e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-36ab0d9727c66c6fbea65adc4e5f2b8c62a18920 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5828 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 471136923 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557c0e58d810, 0x557c0e77701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557c0e777020,0x557c1060f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/36ab0d9727c66c6fbea65adc4e5f2b8c62a18920' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7483 processed earlier; will process 3546 files now Step #5: ==209914== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557c050829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557c0b6e7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557c0b6ca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557c0b6ca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557c05088d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557c04fe9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557c04fe4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557c0507ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557c08049f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557c08049f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557c08049f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557c08049f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557c08049f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557c08049f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557c08049f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557c08049f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557c08049f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557c08049f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557c0a2def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557c0700bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557c07016be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557c06dc2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557c06dc2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557c06dc3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557c06dc2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557c06dc2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557c06dc2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557c0b6ccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557c0b6d5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557c0b6bd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557c0b6e8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f50a44b8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557c04fe2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a9a58940b05623b13dc6ae4a43e92ebb37094da Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5829 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 471672705 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a122079810, 0x55a12226301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a122263020,0x55a1240fb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a9a58940b05623b13dc6ae4a43e92ebb37094da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7484 processed earlier; will process 3545 files now Step #5: #1 pulse cov: 4006 ft: 4007 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4143 ft: 4759 exec/s: 0 rss: 180Mb Step #5: ==209950== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a118b6e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a11f1d3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a11f1b65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a11f1b64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a118b74d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a118ad5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a118ad0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a118b66c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a11bb35f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a11bb35f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a11bb35f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a11bb35f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a11bb35f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a11bb35f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a11bb35f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a11bb35f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a11bb35f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a11bb35f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a11ddcaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a11aaf7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a11ab02be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a11a8aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a11a8aec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a11a8af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a11a8ae874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a11a8ae874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a11a8ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a11f1b8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a11f1c1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a11f1a9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a11f1d4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff2a0764082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a118aceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c78a0070e316c00d2a0398716dc4c3f300da9a47 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5830 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 472346609 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5609b9f3a810, 0x5609ba12401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5609ba124020,0x5609bbfbc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c78a0070e316c00d2a0398716dc4c3f300da9a47' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7487 processed earlier; will process 3542 files now Step #5: ==209986== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5609b0a2f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5609b7094898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5609b70775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5609b70774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5609b0a35d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5609b0996b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5609b0991355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5609b0a27c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5609b39f6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5609b39f6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5609b39f6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5609b39f6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5609b39f6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5609b39f6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5609b39f6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5609b39f6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5609b39f6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5609b39f6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5609b5c8bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5609b29b8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5609b29c3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5609b276fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5609b276fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5609b2770738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5609b276f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5609b276f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5609b276f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5609b7079abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5609b7082928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5609b706a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5609b7095112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff775522082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5609b098fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ae9502d3b571748c7659684cc3c8395db0e3d3de Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5831 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 473444212 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5630bdd64810, 0x5630bdf4e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5630bdf4e020,0x5630bfde60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ae9502d3b571748c7659684cc3c8395db0e3d3de' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7488 processed earlier; will process 3541 files now Step #5: ==210022== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5630b48599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5630baebe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5630baea15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5630baea14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5630b485fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5630b47c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5630b47bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5630b4851c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5630b7820f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5630b7820f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5630b7820f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5630b7820f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5630b7820f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5630b7820f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5630b7820f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5630b7820f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5630b7820f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5630b7820f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5630b9ab5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5630b67e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5630b67edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5630b6599c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5630b6599c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5630b659a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5630b6599874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5630b6599874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5630b6599874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5630baea3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5630baeac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5630bae94699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5630baebf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f17a58b8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5630b47b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-344fdce76936d967fa0054ec5499e494709c8981 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5832 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 474031953 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe2e3ed810, 0x55fe2e5d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe2e5d7020,0x55fe3046f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/344fdce76936d967fa0054ec5499e494709c8981' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7489 processed earlier; will process 3540 files now Step #5: ==210058== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fe24ee29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe2b547898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe2b52a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe2b52a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe24ee8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe24e49b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe24e44355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe24edac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe27ea9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe27ea9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe27ea9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe27ea9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe27ea9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe27ea9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe27ea9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe27ea9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe27ea9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe27ea9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe2a13ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe26e6bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe26e76be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe26c22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe26c22c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe26c23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe26c22874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe26c22874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe26c22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe2b52cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe2b535928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe2b51d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe2b548112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f017df8b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe24e42b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-16ba1f130e3bd5638f6122f6d33a15f40dc3a3ea Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5833 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 474594984 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55780b2f1810, 0x55780b4db01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55780b4db020,0x55780d3730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16ba1f130e3bd5638f6122f6d33a15f40dc3a3ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7490 processed earlier; will process 3539 files now Step #5: ==210094== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557801de69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55780844b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55780842e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55780842e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557801decd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557801d4db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557801d48355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557801ddec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557804dadf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557804dadf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557804dadf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557804dadf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557804dadf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557804dadf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557804dadf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557804dadf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557804dadf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557804dadf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557807042f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557803d6fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557803d7abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557803b26c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557803b26c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557803b27738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557803b26874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557803b26874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557803b26874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557808430abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557808439928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557808421699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55780844c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b28950082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557801d46b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4bacce30182fb4fa961a700c18ae9e80b9efe05d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5834 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 475161609 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56454f831810, 0x56454fa1b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56454fa1b020,0x5645518b30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4bacce30182fb4fa961a700c18ae9e80b9efe05d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7491 processed earlier; will process 3538 files now Step #5: #1 pulse cov: 3904 ft: 3905 exec/s: 0 rss: 179Mb Step #5: ==210130== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5645463269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56454c98b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56454c96e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56454c96e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56454632cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56454628db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564546288355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56454631ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5645492edf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5645492edf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5645492edf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5645492edf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5645492edf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5645492edf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5645492edf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5645492edf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5645492edf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5645492edf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56454b582f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5645482afb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5645482babe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564548066c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564548066c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564548067738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564548066874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564548066874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564548066874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56454c970abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56454c979928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56454c961699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56454c98c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f74ff4ba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564546286b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4cedc91bb0a737bf2b944e245b9c29277f84db61 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5835 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 475943207 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f4642ff810, 0x55f4644e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f4644e9020,0x55f4663810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4cedc91bb0a737bf2b944e245b9c29277f84db61' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7493 processed earlier; will process 3536 files now Step #5: ==210166== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f45adf49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f461459898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f46143c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f46143c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f45adfad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f45ad5bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f45ad56355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f45adecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f45ddbbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f45ddbbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f45ddbbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f45ddbbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f45ddbbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f45ddbbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f45ddbbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f45ddbbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f45ddbbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f45ddbbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f460050f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f45cd7db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f45cd88be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f45cb34c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f45cb34c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f45cb35738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f45cb34874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f45cb34874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f45cb34874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f46143eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f461447928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f46142f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f46145a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff2c3586082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f45ad54b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-27dc5b1bfacf9e1810c03f61d44b65782270309d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5836 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 476508648 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560bbe78e810, 0x560bbe97801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560bbe978020,0x560bc08100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/27dc5b1bfacf9e1810c03f61d44b65782270309d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7494 processed earlier; will process 3535 files now Step #5: #1 pulse cov: 3931 ft: 3932 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4405 ft: 5096 exec/s: 0 rss: 181Mb Step #5: ==210202== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560bb52839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560bbb8e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560bbb8cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560bbb8cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560bb5289d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560bb51eab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560bb51e5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560bb527bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560bb824af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560bb824af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560bb824af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560bb824af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560bb824af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560bb824af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560bb824af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560bb824af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560bb824af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560bb824af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560bba4dff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560bb720cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560bb7217be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560bb6fc3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560bb6fc3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560bb6fc4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560bb6fc3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560bb6fc3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560bb6fc3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560bbb8cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560bbb8d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560bbb8be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560bbb8e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a79188082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560bb51e3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ab79a0797e3a728b8c59a9e3083c917142868167 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5837 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 477179211 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561878816810, 0x561878a0001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561878a00020,0x56187a8980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ab79a0797e3a728b8c59a9e3083c917142868167' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7497 processed earlier; will process 3532 files now Step #5: ==210238== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56186f30b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561875970898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5618759535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5618759534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56186f311d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56186f272b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56186f26d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56186f303c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5618722d2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5618722d2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5618722d2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5618722d2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5618722d2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5618722d2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5618722d2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5618722d2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5618722d2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5618722d2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561874567f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561871294b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56187129fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56187104bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56187104bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56187104c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56187104b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56187104b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56187104b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561875955abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56187595e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561875946699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561875971112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3251b39082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56186f26bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-27fbeddcc5a54d9eac53f92148a6863ae6e420c4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5838 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 477747278 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564373168810, 0x56437335201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564373352020,0x5643751ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/27fbeddcc5a54d9eac53f92148a6863ae6e420c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7498 processed earlier; will process 3531 files now Step #5: #1 pulse cov: 3881 ft: 3882 exec/s: 0 rss: 177Mb Step #5: ==210274== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564369c5d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643702c2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643702a55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643702a54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564369c63d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564369bc4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564369bbf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564369c55c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56436cc24f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56436cc24f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56436cc24f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56436cc24f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56436cc24f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56436cc24f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56436cc24f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56436cc24f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56436cc24f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56436cc24f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56436eeb9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56436bbe6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56436bbf1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56436b99dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56436b99dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56436b99e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56436b99d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56436b99d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56436b99d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643702a7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643702b0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564370298699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643702c3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa690bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564369bbdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aec8b9eab1218bf2eb00a592dcf76b6064120bcc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5839 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 478342467 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5641949c8810, 0x564194bb201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564194bb2020,0x564196a4a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aec8b9eab1218bf2eb00a592dcf76b6064120bcc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7500 processed earlier; will process 3529 files now Step #5: #1 pulse cov: 3836 ft: 3837 exec/s: 0 rss: 179Mb Step #5: ==210310== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56418b4bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564191b22898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564191b055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564191b054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56418b4c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56418b424b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56418b41f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56418b4b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56418e484f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56418e484f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56418e484f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56418e484f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56418e484f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56418e484f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56418e484f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56418e484f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56418e484f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56418e484f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564190719f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56418d446b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56418d451be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56418d1fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56418d1fdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56418d1fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56418d1fd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56418d1fd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56418d1fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564191b07abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564191b10928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564191af8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564191b23112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1fb1be0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56418b41db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a57c616d05bc34f4d5236187400dcea1bee55842 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5840 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 478947817 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1b01dd810, 0x55d1b03c701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1b03c7020,0x55d1b225f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a57c616d05bc34f4d5236187400dcea1bee55842' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7502 processed earlier; will process 3527 files now Step #5: ==210346== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d1a6cd29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1ad337898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1ad31a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1ad31a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1a6cd8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1a6c39b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1a6c34355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1a6ccac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1a9c99f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1a9c99f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1a9c99f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1a9c99f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1a9c99f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1a9c99f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1a9c99f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1a9c99f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1a9c99f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1a9c99f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1abf2ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1a8c5bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1a8c66be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1a8a12c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1a8a12c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1a8a13738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1a8a12874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1a8a12874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1a8a12874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1ad31cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1ad325928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1ad30d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1ad338112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa83f447082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1a6c32b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-157409c5da40aca40f41e0fb879049a4b23a5927 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5841 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 479663013 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5637aa846810, 0x5637aaa3001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5637aaa30020,0x5637ac8c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/157409c5da40aca40f41e0fb879049a4b23a5927' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7503 processed earlier; will process 3526 files now Step #5: ==210382== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5637a133b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5637a79a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5637a79835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5637a79834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5637a1341d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5637a12a2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5637a129d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5637a1333c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5637a4302f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5637a4302f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5637a4302f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5637a4302f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5637a4302f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5637a4302f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5637a4302f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5637a4302f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5637a4302f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5637a4302f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5637a6597f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5637a32c4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5637a32cfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5637a307bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5637a307bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5637a307c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5637a307b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5637a307b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5637a307b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5637a7985abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5637a798e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5637a7976699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5637a79a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b017f8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5637a129bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-68923653fca06ff11f0f47a5d3aeb70dce1b31d8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5842 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 480217881 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561382c0c810, 0x561382df601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561382df6020,0x561384c8e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/68923653fca06ff11f0f47a5d3aeb70dce1b31d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7504 processed earlier; will process 3525 files now Step #5: #1 pulse cov: 3734 ft: 3735 exec/s: 0 rss: 178Mb Step #5: ==210418== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5613797019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56137fd66898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56137fd495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56137fd494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561379707d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561379668b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561379663355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5613796f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56137c6c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56137c6c8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56137c6c8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56137c6c8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56137c6c8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56137c6c8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56137c6c8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56137c6c8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56137c6c8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56137c6c8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56137e95df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56137b68ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56137b695be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56137b441c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56137b441c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56137b442738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56137b441874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56137b441874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56137b441874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56137fd4babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56137fd54928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56137fd3c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56137fd67112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f752592f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561379661b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f69a7db80072a41981b60708546be3fb7ee185ca Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5843 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 480804834 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e41cd67810, 0x55e41cf5101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e41cf51020,0x55e41ede90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f69a7db80072a41981b60708546be3fb7ee185ca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7506 processed earlier; will process 3523 files now Step #5: ==210454== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e41385c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e419ec1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e419ea45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e419ea44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e413862d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4137c3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4137be355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e413854c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e416823f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e416823f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e416823f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e416823f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e416823f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e416823f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e416823f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e416823f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e416823f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e416823f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e418ab8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4157e5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4157f0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e41559cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e41559cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e41559d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e41559c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e41559c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e41559c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e419ea6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e419eaf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e419e97699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e419ec2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4948dcc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4137bcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-266d64fee0e97c39ee49fb487bdf3ff702941a31 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5844 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 481496396 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9a9219810, 0x55a9a940301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a9a9403020,0x55a9ab29b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/266d64fee0e97c39ee49fb487bdf3ff702941a31' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7507 processed earlier; will process 3522 files now Step #5: ==210490== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a99fd0e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a9a6373898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9a63565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9a63564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a99fd14d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a99fc75b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a99fc70355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a99fd06c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9a2cd5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9a2cd5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9a2cd5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9a2cd5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9a2cd5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9a2cd5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9a2cd5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9a2cd5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9a2cd5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9a2cd5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a9a4f6af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a9a1c97b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a9a1ca2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a9a1a4ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a9a1a4ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a9a1a4f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a9a1a4e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a9a1a4e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a9a1a4e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a9a6358abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a9a6361928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a9a6349699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a9a6374112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f57029f8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a99fc6eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-919eaa81ea5b4d1c898fad4c434e83430cc1f127 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5845 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 482056621 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc94723810, 0x55cc9490d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc9490d020,0x55cc967a50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/919eaa81ea5b4d1c898fad4c434e83430cc1f127' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7508 processed earlier; will process 3521 files now Step #5: #1 pulse cov: 3977 ft: 3978 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4387 ft: 4896 exec/s: 0 rss: 179Mb Step #5: ==210526== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cc8b2189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc9187d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc918605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc918604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc8b21ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc8b17fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc8b17a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc8b210c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc8e1dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc8e1dff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc8e1dff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc8e1dff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc8e1dff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc8e1dff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc8e1dff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc8e1dff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc8e1dff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc8e1dff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc90474f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc8d1a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc8d1acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc8cf58c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc8cf58c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc8cf59738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc8cf58874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc8cf58874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc8cf58874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc91862abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc9186b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc91853699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc9187e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f65764d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc8b178b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b7cbe6f52c3afc4e48b4b4cdab810314c8fec42f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5846 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 482686762 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55981738f810, 0x55981757901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559817579020,0x5598194110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7cbe6f52c3afc4e48b4b4cdab810314c8fec42f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7511 processed earlier; will process 3518 files now Step #5: ==210562== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55980de849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5598144e9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5598144cc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5598144cc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55980de8ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55980ddebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55980dde6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55980de7cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559810e4bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559810e4bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559810e4bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559810e4bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559810e4bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559810e4bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559810e4bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559810e4bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559810e4bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559810e4bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5598130e0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55980fe0db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55980fe18be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55980fbc4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55980fbc4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55980fbc5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55980fbc4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55980fbc4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55980fbc4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5598144ceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5598144d7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5598144bf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5598144ea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7facb3ef5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55980dde4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f63076f90374e6821ae828b6bc55e09af7ca9728 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5847 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 483959380 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ff43437810, 0x55ff4362101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ff43621020,0x55ff454b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f63076f90374e6821ae828b6bc55e09af7ca9728' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7512 processed earlier; will process 3517 files now Step #5: ==210598== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ff39f2c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ff40591898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ff405745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ff405744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ff39f32d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ff39e93b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ff39e8e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ff39f24c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ff3cef3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ff3cef3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ff3cef3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ff3cef3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ff3cef3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ff3cef3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ff3cef3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ff3cef3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ff3cef3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ff3cef3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ff3f188f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ff3beb5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ff3bec0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ff3bc6cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ff3bc6cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ff3bc6d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ff3bc6c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ff3bc6c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ff3bc6c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ff40576abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ff4057f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ff40567699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ff40592112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fae6da05082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ff39e8cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a42a6c43fe8b016c11cc66ab29a5e57caed5fd3f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5848 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 484511239 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5589ecca8810, 0x5589ece9201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5589ece92020,0x5589eed2a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a42a6c43fe8b016c11cc66ab29a5e57caed5fd3f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7513 processed earlier; will process 3516 files now Step #5: ==210634== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5589e379d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5589e9e02898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589e9de55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589e9de54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5589e37a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5589e3704b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5589e36ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5589e3795c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5589e6764f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5589e6764f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5589e6764f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5589e6764f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5589e6764f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5589e6764f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5589e6764f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5589e6764f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5589e6764f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5589e6764f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589e89f9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5589e5726b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5589e5731be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5589e54ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5589e54ddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5589e54de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5589e54dd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5589e54dd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5589e54dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5589e9de7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5589e9df0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5589e9dd8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5589e9e03112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff446dca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5589e36fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-49af236f5eea9273fe0ee55d4b7489d43f1ff821 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5849 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 485176956 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55911de12810, 0x55911dffc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55911dffc020,0x55911fe940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/49af236f5eea9273fe0ee55d4b7489d43f1ff821' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7514 processed earlier; will process 3515 files now Step #5: #1 pulse cov: 3927 ft: 3928 exec/s: 0 rss: 181Mb Step #5: ==210670== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5591149079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55911af6c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55911af4f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55911af4f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55911490dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55911486eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559114869355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5591148ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5591178cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5591178cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5591178cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5591178cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5591178cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5591178cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5591178cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5591178cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5591178cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5591178cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559119b63f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559116890b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55911689bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559116647c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559116647c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559116648738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559116647874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559116647874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559116647874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55911af51abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55911af5a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55911af42699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55911af6d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe4f65a7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559114867b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4671b4b59d70ced35cb6c071471aaf31455f5373 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5850 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 485769113 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558f944ab810, 0x558f9469501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558f94695020,0x558f9652d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4671b4b59d70ced35cb6c071471aaf31455f5373' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7516 processed earlier; will process 3513 files now Step #5: #1 pulse cov: 4180 ft: 4181 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4686 ft: 5341 exec/s: 0 rss: 180Mb Step #5: ==210706== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558f8afa09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558f91605898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558f915e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558f915e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f8afa6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f8af07b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f8af02355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f8af98c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f8df67f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f8df67f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f8df67f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f8df67f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f8df67f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f8df67f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f8df67f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f8df67f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f8df67f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f8df67f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558f901fcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f8cf29b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f8cf34be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f8cce0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f8cce0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f8cce1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f8cce0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f8cce0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f8cce0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558f915eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558f915f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558f915db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558f91606112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9a40e55082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f8af00b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4fc899a01ef98dd8aa58367cc543236fb1aca483 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5851 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 486589048 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558e58542810, 0x558e5872c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558e5872c020,0x558e5a5c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4fc899a01ef98dd8aa58367cc543236fb1aca483' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7519 processed earlier; will process 3510 files now Step #5: ==210742== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558e4f0379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558e5569c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558e5567f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558e5567f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558e4f03dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558e4ef9eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558e4ef99355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558e4f02fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558e51ffef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558e51ffef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558e51ffef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558e51ffef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558e51ffef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558e51ffef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558e51ffef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558e51ffef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558e51ffef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558e51ffef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558e54293f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558e50fc0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558e50fcbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558e50d77c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558e50d77c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558e50d78738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558e50d77874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558e50d77874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558e50d77874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558e55681abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558e5568a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558e55672699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558e5569d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4e02bf3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558e4ef97b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9f8ea3231213d1a367fdc129eee2744375c5d68d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5852 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 487174165 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c8ca60810, 0x564c8cc4a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c8cc4a020,0x564c8eae20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f8ea3231213d1a367fdc129eee2744375c5d68d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7520 processed earlier; will process 3509 files now Step #5: ==210778== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564c835559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c89bba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c89b9d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c89b9d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c8355bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c834bcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c834b7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c8354dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c8651cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c8651cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c8651cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c8651cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c8651cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c8651cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c8651cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c8651cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c8651cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c8651cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c887b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c854deb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c854e9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c85295c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c85295c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c85296738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c85295874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c85295874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c85295874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c89b9fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c89ba8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c89b90699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c89bbb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f84c1072082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c834b5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fcfb78286b9baaf26ee9ace67bb4ba58d143ddfa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5853 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 487768714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea6c076810, 0x55ea6c26001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea6c260020,0x55ea6e0f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fcfb78286b9baaf26ee9ace67bb4ba58d143ddfa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7521 processed earlier; will process 3508 files now Step #5: ==210814== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ea62b6b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea691d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea691b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea691b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea62b71d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea62ad2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea62acd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea62b63c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea65b32f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea65b32f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea65b32f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea65b32f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea65b32f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea65b32f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea65b32f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea65b32f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea65b32f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea65b32f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea67dc7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea64af4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea64affbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea648abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea648abc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea648ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea648ab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea648ab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea648ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea691b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea691be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea691a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea691d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd46d412082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea62acbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-575b143df34eed7ed0ebe8a0d8b4adcfabac0ab1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5854 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 488316969 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a9dfbb810, 0x560a9e1a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a9e1a5020,0x560aa003d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/575b143df34eed7ed0ebe8a0d8b4adcfabac0ab1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7522 processed earlier; will process 3507 files now Step #5: ==210850== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560a94ab09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a9b115898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a9b0f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a9b0f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a94ab6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a94a17b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a94a12355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a94aa8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a97a77f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a97a77f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a97a77f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a97a77f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a97a77f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a97a77f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a97a77f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a97a77f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a97a77f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a97a77f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a99d0cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a96a39b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a96a44be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a967f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a967f0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a967f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a967f0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a967f0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a967f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a9b0faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a9b103928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a9b0eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a9b116112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe6ccbac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a94a10b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-49c86e69c4966be191981d462e8155ca10d7c7ca Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5855 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 488880871 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cabe96e810, 0x55cabeb5801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cabeb58020,0x55cac09f00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/49c86e69c4966be191981d462e8155ca10d7c7ca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7523 processed earlier; will process 3506 files now Step #5: ==210886== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cab54639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cabbac8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cabbaab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cabbaab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cab5469d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cab53cab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cab53c5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cab545bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cab842af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cab842af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cab842af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cab842af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cab842af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cab842af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cab842af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cab842af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cab842af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cab842af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55caba6bff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cab73ecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cab73f7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cab71a3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cab71a3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cab71a4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cab71a3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cab71a3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cab71a3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cabbaadabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cabbab6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cabba9e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cabbac9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ee217a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cab53c3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-29fe6c7d9016ebdae96959caca59ab82e278e22c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5856 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 489429448 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563005163810, 0x56300534d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56300534d020,0x5630071e50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/29fe6c7d9016ebdae96959caca59ab82e278e22c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7524 processed earlier; will process 3505 files now Step #5: ==210922== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562ffbc589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5630022bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5630022a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5630022a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562ffbc5ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562ffbbbfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562ffbbba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562ffbc50c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562ffec1ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562ffec1ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562ffec1ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562ffec1ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562ffec1ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562ffec1ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562ffec1ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562ffec1ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562ffec1ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562ffec1ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563000eb4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562ffdbe1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562ffdbecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562ffd998c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562ffd998c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562ffd999738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562ffd998874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562ffd998874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562ffd998874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5630022a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5630022ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563002293699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5630022be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f41d5b37082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562ffbbb8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b7031716a2b2308fbe8e824e14dd72b35963126c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5857 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 489968701 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561bae199810, 0x561bae38301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561bae383020,0x561bb021b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b7031716a2b2308fbe8e824e14dd72b35963126c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7525 processed earlier; will process 3504 files now Step #5: #1 pulse cov: 3987 ft: 3988 exec/s: 0 rss: 177Mb Step #5: ==210958== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561ba4c8e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561bab2f3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561bab2d65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561bab2d64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561ba4c94d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561ba4bf5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561ba4bf0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561ba4c86c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561ba7c55f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561ba7c55f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561ba7c55f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561ba7c55f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561ba7c55f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561ba7c55f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561ba7c55f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561ba7c55f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561ba7c55f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561ba7c55f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561ba9eeaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561ba6c17b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561ba6c22be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561ba69cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561ba69cec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561ba69cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561ba69ce874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561ba69ce874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561ba69ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561bab2d8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561bab2e1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561bab2c9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561bab2f4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a0ecd3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561ba4beeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-24a78285925df9bce41502f630a9f9f6cfbf5a36 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5858 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 490586080 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b34e94e810, 0x55b34eb3801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b34eb38020,0x55b3509d00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/24a78285925df9bce41502f630a9f9f6cfbf5a36' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7527 processed earlier; will process 3502 files now Step #5: ==210994== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b3454439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b34baa8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b34ba8b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b34ba8b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b345449d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b3453aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b3453a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b34543bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b34840af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b34840af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b34840af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b34840af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b34840af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b34840af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b34840af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b34840af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b34840af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b34840af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b34a69ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b3473ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b3473d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b347183c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b347183c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b347184738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b347183874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b347183874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b347183874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b34ba8dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b34ba96928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b34ba7e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b34baa9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f968a019082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b3453a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-19a3833a58b7c30549a8996a7d8eb010d0874976 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5859 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 491274614 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3ab6bf810, 0x55a3ab8a901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3ab8a9020,0x55a3ad7410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/19a3833a58b7c30549a8996a7d8eb010d0874976' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7528 processed earlier; will process 3501 files now Step #5: #1 pulse cov: 4087 ft: 4088 exec/s: 0 rss: 181Mb Step #5: ==211030== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a3a21b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3a8819898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3a87fc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3a87fc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3a21bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a3a211bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a3a2116355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3a21acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a3a517bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a3a517bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a3a517bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a3a517bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a3a517bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a3a517bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a3a517bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a3a517bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a3a517bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a3a517bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3a7410f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3a413db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3a4148be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3a3ef4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3a3ef4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3a3ef5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3a3ef4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3a3ef4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3a3ef4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a3a87feabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a3a8807928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3a87ef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3a881a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f129721b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a3a2114b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-29d9df27b3013ac24a279595654b264f1f8d7d2b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5860 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 491878917 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5633557b5810, 0x56335599f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56335599f020,0x5633578370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/29d9df27b3013ac24a279595654b264f1f8d7d2b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7530 processed earlier; will process 3499 files now Step #5: #1 pulse cov: 3989 ft: 3990 exec/s: 0 rss: 177Mb Step #5: ==211066== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56334c2aa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56335290f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5633528f25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5633528f24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56334c2b0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56334c211b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56334c20c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56334c2a2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56334f271f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56334f271f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56334f271f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56334f271f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56334f271f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56334f271f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56334f271f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56334f271f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56334f271f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56334f271f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563351506f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56334e233b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56334e23ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56334dfeac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56334dfeac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56334dfeb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56334dfea874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56334dfea874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56334dfea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5633528f4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5633528fd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5633528e5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563352910112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0afa83082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56334c20ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-08bdc7623aac58e2bf806416fb7055edc431a07a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5861 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 492503784 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556b27a64810, 0x556b27c4e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556b27c4e020,0x556b29ae60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08bdc7623aac58e2bf806416fb7055edc431a07a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7532 processed earlier; will process 3497 files now Step #5: ==211102== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556b1e5599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556b24bbe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556b24ba15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556b24ba14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556b1e55fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556b1e4c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556b1e4bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556b1e551c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556b21520f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556b21520f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556b21520f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556b21520f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556b21520f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556b21520f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556b21520f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556b21520f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556b21520f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556b21520f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556b237b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556b204e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556b204edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556b20299c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556b20299c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556b2029a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556b20299874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556b20299874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556b20299874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556b24ba3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556b24bac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556b24b94699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556b24bbf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8f1c434082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556b1e4b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a7f766fed3402b0bad6573afb1eadbf1d5c6b252 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5862 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 493060172 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5561a8544810, 0x5561a872e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5561a872e020,0x5561aa5c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a7f766fed3402b0bad6573afb1eadbf1d5c6b252' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7533 processed earlier; will process 3496 files now Step #5: #1 pulse cov: 4287 ft: 4288 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4678 ft: 5142 exec/s: 0 rss: 179Mb Step #5: ==211138== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55619f0399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5561a569e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5561a56815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5561a56814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55619f03fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55619efa0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55619ef9b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55619f031c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5561a2000f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5561a2000f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5561a2000f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5561a2000f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5561a2000f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5561a2000f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5561a2000f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5561a2000f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5561a2000f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5561a2000f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5561a4295f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5561a0fc2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5561a0fcdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5561a0d79c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5561a0d79c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5561a0d7a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5561a0d79874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5561a0d79874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5561a0d79874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5561a5683abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5561a568c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5561a5674699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5561a569f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e8131d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55619ef99b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-de892c1c4fb50e837bcbfd146346b80516ce4f19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5863 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 493761311 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555f1e635810, 0x555f1e81f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555f1e81f020,0x555f206b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de892c1c4fb50e837bcbfd146346b80516ce4f19' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7536 processed earlier; will process 3493 files now Step #5: ==211174== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555f1512a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555f1b78f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555f1b7725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555f1b7724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555f15130d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555f15091b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555f1508c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555f15122c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555f180f1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555f180f1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555f180f1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555f180f1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555f180f1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555f180f1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555f180f1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555f180f1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555f180f1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555f180f1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555f1a386f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555f170b3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555f170bebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555f16e6ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555f16e6ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555f16e6b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555f16e6a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555f16e6a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555f16e6a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555f1b774abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555f1b77d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555f1b765699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555f1b790112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b58a2f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555f1508ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-21215c168a6252b560a426b1159e68fc8cfc139a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5864 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 494357799 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d7552c810, 0x562d7571601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d75716020,0x562d775ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/21215c168a6252b560a426b1159e68fc8cfc139a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7537 processed earlier; will process 3492 files now Step #5: ==211210== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562d6c0219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d72686898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d726695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d726694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d6c027d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d6bf88b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d6bf83355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d6c019c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d6efe8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d6efe8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d6efe8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d6efe8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d6efe8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d6efe8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d6efe8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d6efe8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d6efe8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d6efe8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d7127df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d6dfaab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d6dfb5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d6dd61c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d6dd61c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d6dd62738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d6dd61874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d6dd61874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d6dd61874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d7266babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d72674928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d7265c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d72687112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd933795082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d6bf81b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0faabb3c0b0ec5ca7945683a8ebe11ac130b3e25 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5865 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 495053243 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e65c309810, 0x55e65c4f301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e65c4f3020,0x55e65e38b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0faabb3c0b0ec5ca7945683a8ebe11ac130b3e25' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7538 processed earlier; will process 3491 files now Step #5: ==211246== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e652dfe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e659463898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e6594465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e6594464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e652e04d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e652d65b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e652d60355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e652df6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e655dc5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e655dc5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e655dc5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e655dc5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e655dc5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e655dc5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e655dc5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e655dc5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e655dc5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e655dc5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e65805af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e654d87b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e654d92be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e654b3ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e654b3ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e654b3f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e654b3e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e654b3e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e654b3e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e659448abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e659451928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e659439699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e659464112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c0bb2c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e652d5eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f2396694eaeec00f3f570b0bc0eb7e32b4232213 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5866 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 495609231 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b61732810, 0x560b6191c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b6191c020,0x560b637b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f2396694eaeec00f3f570b0bc0eb7e32b4232213' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7539 processed earlier; will process 3490 files now Step #5: ==211282== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560b582279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b5e88c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b5e86f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b5e86f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b5822dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b5818eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b58189355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b5821fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b5b1eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b5b1eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b5b1eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b5b1eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b5b1eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b5b1eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b5b1eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b5b1eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b5b1eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b5b1eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b5d483f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b5a1b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b5a1bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b59f67c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b59f67c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b59f68738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b59f67874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b59f67874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b59f67874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b5e871abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b5e87a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b5e862699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b5e88d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b2a68c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b58187b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6112ebdc9bf5ba844226409585892ef901febe79 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5867 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 496143602 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5576fc143810, 0x5576fc32d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5576fc32d020,0x5576fe1c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6112ebdc9bf5ba844226409585892ef901febe79' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7540 processed earlier; will process 3489 files now Step #5: #1 pulse cov: 4382 ft: 4383 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4724 ft: 5212 exec/s: 0 rss: 181Mb Step #5: ==211318== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5576f2c389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5576f929d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5576f92805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5576f92804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5576f2c3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5576f2b9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5576f2b9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5576f2c30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576f5bfff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576f5bfff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576f5bfff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576f5bfff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576f5bfff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576f5bfff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576f5bfff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576f5bfff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576f5bfff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576f5bfff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5576f7e94f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5576f4bc1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5576f4bccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5576f4978c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5576f4978c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5576f4979738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5576f4978874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5576f4978874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5576f4978874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5576f9282abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5576f928b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5576f9273699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5576f929e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe03798c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5576f2b98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-950e076dc40cc98b36b539066942197b16d34743 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5868 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 496774018 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e043651810, 0x55e04383b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e04383b020,0x55e0456d30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/950e076dc40cc98b36b539066942197b16d34743' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7543 processed earlier; will process 3486 files now Step #5: ==211354== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e03a1469c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e0407ab898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e04078e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e04078e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e03a14cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e03a0adb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e03a0a8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e03a13ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e03d10df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e03d10df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e03d10df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e03d10df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e03d10df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e03d10df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e03d10df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e03d10df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e03d10df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e03d10df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e03f3a2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e03c0cfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e03c0dabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e03be86c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e03be86c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e03be87738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e03be86874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e03be86874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e03be86874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e040790abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e040799928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e040781699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e0407ac112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4dc41b6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e03a0a6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9d4f96b6c9211780e2ae3cb98a97941fc0c1ff1b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5869 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 497386908 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d69c01810, 0x561d69deb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d69deb020,0x561d6bc830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9d4f96b6c9211780e2ae3cb98a97941fc0c1ff1b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7544 processed earlier; will process 3485 files now Step #5: #1 pulse cov: 4016 ft: 4017 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4193 ft: 4617 exec/s: 0 rss: 179Mb Step #5: ==211390== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d606f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d66d5b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d66d3e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d66d3e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d606fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d6065db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d60658355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d606eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d636bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d636bdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d636bdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d636bdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d636bdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d636bdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d636bdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d636bdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d636bdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d636bdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d65952f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d6267fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d6268abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d62436c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d62436c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d62437738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d62436874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d62436874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d62436874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d66d40abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d66d49928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d66d31699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d66d5c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f16a908c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d60656b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e96f9c1bfd407e3078b2e6a1391b96fbdc24e6ed Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5870 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 498041714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e38d578810, 0x55e38d76201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e38d762020,0x55e38f5fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e96f9c1bfd407e3078b2e6a1391b96fbdc24e6ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7548 processed earlier; will process 3481 files now Step #5: #1 pulse cov: 4145 ft: 4146 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4320 ft: 4996 exec/s: 0 rss: 180Mb Step #5: ==211426== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e38406d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e38a6d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e38a6b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e38a6b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e384073d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e383fd4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e383fcf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e384065c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e387034f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e387034f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e387034f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e387034f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e387034f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e387034f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e387034f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e387034f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e387034f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e387034f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e3892c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e385ff6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e386001be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e385dadc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e385dadc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e385dae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e385dad874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e385dad874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e385dad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e38a6b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e38a6c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e38a6a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e38a6d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f484355a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e383fcdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fc5352deb0eea2a04aae420d5bb2230cf39425c9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5871 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 498682874 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555f6efdb810, 0x555f6f1c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555f6f1c5020,0x555f7105d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc5352deb0eea2a04aae420d5bb2230cf39425c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7551 processed earlier; will process 3478 files now Step #5: ==211462== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555f65ad09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555f6c135898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555f6c1185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555f6c1184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555f65ad6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555f65a37b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555f65a32355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555f65ac8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555f68a97f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555f68a97f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555f68a97f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555f68a97f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555f68a97f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555f68a97f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555f68a97f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555f68a97f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555f68a97f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555f68a97f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555f6ad2cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555f67a59b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555f67a64be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555f67810c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555f67810c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555f67811738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555f67810874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555f67810874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555f67810874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555f6c11aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555f6c123928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555f6c10b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555f6c136112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f549282b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555f65a30b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-13d6d4bd3967c4e1efed5235a4ce9b459fba175d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5872 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 499231674 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e39fb63810, 0x55e39fd4d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e39fd4d020,0x55e3a1be50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/13d6d4bd3967c4e1efed5235a4ce9b459fba175d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7552 processed earlier; will process 3477 files now Step #5: ==211498== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e3966589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e39ccbd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e39cca05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e39cca04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e39665ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e3965bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e3965ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e396650c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e39961ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e39961ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e39961ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e39961ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e39961ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e39961ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e39961ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e39961ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e39961ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e39961ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e39b8b4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e3985e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e3985ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e398398c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e398398c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e398399738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e398398874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e398398874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e398398874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e39cca2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e39ccab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e39cc93699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e39ccbe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f522a4d5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e3965b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4d292ef732ea88048944f39c9ccd08158ebd5693 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5873 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 499810989 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557ea142d810, 0x557ea161701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557ea1617020,0x557ea34af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4d292ef732ea88048944f39c9ccd08158ebd5693' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7553 processed earlier; will process 3476 files now Step #5: ==211534== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557e97f229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557e9e587898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557e9e56a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557e9e56a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557e97f28d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557e97e89b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557e97e84355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557e97f1ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557e9aee9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557e9aee9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557e9aee9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557e9aee9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557e9aee9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557e9aee9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557e9aee9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557e9aee9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557e9aee9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557e9aee9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557e9d17ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557e99eabb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557e99eb6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557e99c62c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557e99c62c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557e99c63738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557e99c62874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557e99c62874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557e99c62874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557e9e56cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557e9e575928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557e9e55d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557e9e588112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f30a4aad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557e97e82b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-699cc8b086851a8c760f0a0e59d19c6ea0c87404 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5874 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 500366914 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55def527d810, 0x55def546701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55def5467020,0x55def72ff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/699cc8b086851a8c760f0a0e59d19c6ea0c87404' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7554 processed earlier; will process 3475 files now Step #5: ==211570== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55deebd729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55def23d7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55def23ba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55def23ba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55deebd78d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55deebcd9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55deebcd4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55deebd6ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55deeed39f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55deeed39f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55deeed39f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55deeed39f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55deeed39f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55deeed39f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55deeed39f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55deeed39f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55deeed39f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55deeed39f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55def0fcef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55deedcfbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55deedd06be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55deedab2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55deedab2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55deedab3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55deedab2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55deedab2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55deedab2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55def23bcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55def23c5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55def23ad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55def23d8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4b1f23082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55deebcd2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-af366438215f949cb489fbd9437724b4bc1b2c98 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5875 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 501034217 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5650fab6e810, 0x5650fad5801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5650fad58020,0x5650fcbf00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af366438215f949cb489fbd9437724b4bc1b2c98' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7555 processed earlier; will process 3474 files now Step #5: #1 pulse cov: 3593 ft: 3594 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4232 ft: 4605 exec/s: 0 rss: 181Mb Step #5: ==211606== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5650f16639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5650f7cc8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5650f7cab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5650f7cab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5650f1669d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5650f15cab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5650f15c5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5650f165bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5650f462af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5650f462af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5650f462af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5650f462af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5650f462af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5650f462af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5650f462af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5650f462af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5650f462af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5650f462af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5650f68bff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5650f35ecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5650f35f7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5650f33a3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5650f33a3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5650f33a4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5650f33a3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5650f33a3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5650f33a3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5650f7cadabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5650f7cb6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5650f7c9e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5650f7cc9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf465ae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5650f15c3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ee1b24706ff1714c748f2829bea26069bfaf89bf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5876 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 501663473 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5616d4e38810, 0x5616d502201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5616d5022020,0x5616d6eba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee1b24706ff1714c748f2829bea26069bfaf89bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7558 processed earlier; will process 3471 files now Step #5: ==211642== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5616cb92d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5616d1f92898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5616d1f755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5616d1f754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5616cb933d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5616cb894b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5616cb88f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5616cb925c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5616ce8f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5616ce8f4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5616ce8f4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5616ce8f4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5616ce8f4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5616ce8f4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5616ce8f4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5616ce8f4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5616ce8f4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5616ce8f4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5616d0b89f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5616cd8b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5616cd8c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5616cd66dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5616cd66dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5616cd66e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5616cd66d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5616cd66d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5616cd66d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5616d1f77abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5616d1f80928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5616d1f68699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5616d1f93112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdcf6df1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5616cb88db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f72b9d9a2ca5885fdf216ca5fcbb6b6050b3836d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5877 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 502216808 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559d6f88a810, 0x559d6fa7401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559d6fa74020,0x559d7190c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f72b9d9a2ca5885fdf216ca5fcbb6b6050b3836d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7559 processed earlier; will process 3470 files now Step #5: #1 pulse cov: 3949 ft: 3950 exec/s: 0 rss: 177Mb Step #5: ==211678== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559d6637f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559d6c9e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559d6c9c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559d6c9c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559d66385d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559d662e6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559d662e1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559d66377c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559d69346f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559d69346f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559d69346f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559d69346f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559d69346f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559d69346f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559d69346f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559d69346f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559d69346f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559d69346f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559d6b5dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559d68308b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559d68313be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559d680bfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559d680bfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559d680c0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559d680bf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559d680bf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559d680bf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559d6c9c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559d6c9d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559d6c9ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559d6c9e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1806449082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559d662dfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-554f29007ce74c68dfa3c35165924a62532461ad Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5878 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 502956163 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5636bf80a810, 0x5636bf9f401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5636bf9f4020,0x5636c188c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/554f29007ce74c68dfa3c35165924a62532461ad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7561 processed earlier; will process 3468 files now Step #5: ==211714== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5636b62ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5636bc964898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636bc9475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636bc9474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5636b6305d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5636b6266b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5636b6261355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5636b62f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5636b92c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5636b92c6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5636b92c6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5636b92c6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5636b92c6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5636b92c6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5636b92c6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5636b92c6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5636b92c6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5636b92c6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5636bb55bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5636b8288b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5636b8293be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5636b803fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5636b803fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5636b8040738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5636b803f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5636b803f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5636b803f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5636bc949abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5636bc952928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5636bc93a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5636bc965112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4c31cee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5636b625fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1a774b8c00ee2bf7efdd99ca37f7fa9d3560bdde Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5879 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 503497475 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c231cd2810, 0x55c231ebc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c231ebc020,0x55c233d540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1a774b8c00ee2bf7efdd99ca37f7fa9d3560bdde' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7562 processed earlier; will process 3467 files now Step #5: #1 pulse cov: 3632 ft: 3633 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 12316 ft: 13263 exec/s: 0 rss: 199Mb Step #5: ==211750== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c2287c79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c22ee2c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c22ee0f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c22ee0f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c2287cdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c22872eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c228729355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c2287bfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c22b78ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c22b78ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c22b78ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c22b78ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c22b78ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c22b78ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c22b78ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c22b78ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c22b78ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c22b78ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c22da23f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c22a750b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c22a75bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c22a507c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c22a507c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c22a508738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c22a507874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c22a507874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c22a507874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c22ee11abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c22ee1a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c22ee02699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c22ee2d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8d3e64a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c228727b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-09571779b5b9b1be53f7d3dd805b3b94b30998ad Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5880 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 504163876 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9e4bc0810, 0x55e9e4daa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9e4daa020,0x55e9e6c420e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/09571779b5b9b1be53f7d3dd805b3b94b30998ad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7565 processed earlier; will process 3464 files now Step #5: ==211786== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e9db6b59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9e1d1a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9e1cfd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9e1cfd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9db6bbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e9db61cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e9db617355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9db6adc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e9de67cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e9de67cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e9de67cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e9de67cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e9de67cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e9de67cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e9de67cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e9de67cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e9de67cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e9de67cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9e0911f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e9dd63eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e9dd649be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9dd3f5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9dd3f5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9dd3f6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9dd3f5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9dd3f5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9dd3f5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e9e1cffabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9e1d08928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e9e1cf0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e9e1d1b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe921861082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e9db615b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2de3d08c72611a97461c11e4d431f22d2931f7f5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5881 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 504705903 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560aa653e810, 0x560aa672801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560aa6728020,0x560aa85c00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2de3d08c72611a97461c11e4d431f22d2931f7f5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7566 processed earlier; will process 3463 files now Step #5: #1 pulse cov: 12465 ft: 12466 exec/s: 0 rss: 199Mb Step #5: ==211822== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560a9d0339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560aa3698898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560aa367b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560aa367b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a9d039d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a9cf9ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a9cf95355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a9d02bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a9fffaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a9fffaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a9fffaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a9fffaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a9fffaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a9fffaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a9fffaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a9fffaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a9fffaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a9fffaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560aa228ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a9efbcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a9efc7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a9ed73c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a9ed73c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a9ed74738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a9ed73874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a9ed73874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a9ed73874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560aa367dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560aa3686928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560aa366e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560aa3699112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f57a21ba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a9cf93b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ebc3d34614c147353ecb7754f1e9f9be07e834f1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5882 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 505358990 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1af008810, 0x55a1af1f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1af1f2020,0x55a1b108a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ebc3d34614c147353ecb7754f1e9f9be07e834f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7568 processed earlier; will process 3461 files now Step #5: ==211858== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1a5afd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1ac162898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1ac1455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1ac1454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1a5b03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1a5a64b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1a5a5f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1a5af5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1a8ac4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1a8ac4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1a8ac4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1a8ac4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1a8ac4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1a8ac4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1a8ac4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1a8ac4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1a8ac4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1a8ac4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1aad59f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1a7a86b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1a7a91be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1a783dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1a783dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1a783e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1a783d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1a783d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1a783d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a1ac147abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a1ac150928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1ac138699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1ac163112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff874634082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1a5a5db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6753d3da37a2976e8e41aea4b20c86754a9eabc3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5883 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 505913551 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563448362810, 0x56344854c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56344854c020,0x56344a3e40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6753d3da37a2976e8e41aea4b20c86754a9eabc3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7569 processed earlier; will process 3460 files now Step #5: ==211894== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56343ee579c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5634454bc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56344549f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56344549f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56343ee5dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56343edbeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56343edb9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56343ee4fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563441e1ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563441e1ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563441e1ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563441e1ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563441e1ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563441e1ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563441e1ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563441e1ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563441e1ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563441e1ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5634440b3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563440de0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563440debbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563440b97c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563440b97c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563440b98738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563440b97874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563440b97874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563440b97874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5634454a1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5634454aa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563445492699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5634454bd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbcd979a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56343edb7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f4626491ef810929d2d1e5a986a48c5454130102 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5884 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 506469502 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c39c902810, 0x55c39caec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c39caec020,0x55c39e9840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f4626491ef810929d2d1e5a986a48c5454130102' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7570 processed earlier; will process 3459 files now Step #5: ==211930== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c3933f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c399a5c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c399a3f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c399a3f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c3933fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c39335eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c393359355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c3933efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c3963bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c3963bef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c3963bef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c3963bef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c3963bef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c3963bef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c3963bef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c3963bef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c3963bef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c3963bef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c398653f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c395380b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c39538bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c395137c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c395137c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c395138738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c395137874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c395137874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c395137874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c399a41abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c399a4a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c399a32699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c399a5d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ef3df1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c393357b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ac6b931dcb075e2b2869f7844e54fd67af2715d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5885 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 507064711 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f0c107a810, 0x55f0c126401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f0c1264020,0x55f0c30fc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ac6b931dcb075e2b2869f7844e54fd67af2715d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7571 processed earlier; will process 3458 files now Step #5: ==211966== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f0b7b6f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f0be1d4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f0be1b75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f0be1b74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f0b7b75d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f0b7ad6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f0b7ad1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f0b7b67c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f0bab36f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f0bab36f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f0bab36f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f0bab36f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f0bab36f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f0bab36f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f0bab36f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f0bab36f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f0bab36f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f0bab36f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f0bcdcbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f0b9af8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f0b9b03be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f0b98afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f0b98afc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f0b98b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f0b98af874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f0b98af874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f0b98af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f0be1b9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f0be1c2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f0be1aa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f0be1d5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6581006082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f0b7acfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-eb71fbad2f6a24571ea78a1984430a257bc99ed7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5886 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 507653349 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5631d0490810, 0x5631d067a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5631d067a020,0x5631d25120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eb71fbad2f6a24571ea78a1984430a257bc99ed7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7572 processed earlier; will process 3457 files now Step #5: #1 pulse cov: 4159 ft: 4160 exec/s: 0 rss: 180Mb Step #5: ==212002== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5631c6f859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5631cd5ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5631cd5cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5631cd5cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5631c6f8bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5631c6eecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5631c6ee7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5631c6f7dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5631c9f4cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5631c9f4cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5631c9f4cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5631c9f4cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5631c9f4cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5631c9f4cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5631c9f4cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5631c9f4cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5631c9f4cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5631c9f4cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5631cc1e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5631c8f0eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5631c8f19be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5631c8cc5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5631c8cc5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5631c8cc6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5631c8cc5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5631c8cc5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5631c8cc5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5631cd5cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5631cd5d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5631cd5c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5631cd5eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff10235f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5631c6ee5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fd8913d62b5b498b92b2d4b4cf04d1297fea5044 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5887 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 508251730 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5625f28ec810, 0x5625f2ad601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625f2ad6020,0x5625f496e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fd8913d62b5b498b92b2d4b4cf04d1297fea5044' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7574 processed earlier; will process 3455 files now Step #5: ==212038== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5625e93e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5625efa46898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625efa295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625efa294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5625e93e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625e9348b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625e9343355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5625e93d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5625ec3a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5625ec3a8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5625ec3a8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5625ec3a8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5625ec3a8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5625ec3a8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5625ec3a8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5625ec3a8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5625ec3a8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5625ec3a8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5625ee63df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625eb36ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5625eb375be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5625eb121c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5625eb121c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5625eb122738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5625eb121874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5625eb121874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5625eb121874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5625efa2babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5625efa34928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5625efa1c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5625efa47112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff8644e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625e9341b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0155904aa96b65649fe882bb5aec29e21533f040 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5888 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 508814385 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5631abaff810, 0x5631abce901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5631abce9020,0x5631adb810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0155904aa96b65649fe882bb5aec29e21533f040' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7575 processed earlier; will process 3454 files now Step #5: ==212074== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5631a25f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5631a8c59898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5631a8c3c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5631a8c3c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5631a25fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5631a255bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5631a2556355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5631a25ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5631a55bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5631a55bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5631a55bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5631a55bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5631a55bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5631a55bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5631a55bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5631a55bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5631a55bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5631a55bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5631a7850f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5631a457db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5631a4588be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5631a4334c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5631a4334c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5631a4335738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5631a4334874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5631a4334874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5631a4334874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5631a8c3eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5631a8c47928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5631a8c2f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5631a8c5a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcbfb245082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5631a2554b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ed1f61c5e7e164a2dddcce07b79df29995c93b72 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5889 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 509487820 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563f79635810, 0x563f7981f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563f7981f020,0x563f7b6b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ed1f61c5e7e164a2dddcce07b79df29995c93b72' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7576 processed earlier; will process 3453 files now Step #5: #1 pulse cov: 3645 ft: 3646 exec/s: 0 rss: 178Mb Step #5: ==212110== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563f7012a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563f7678f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563f767725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563f767724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563f70130d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563f70091b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563f7008c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563f70122c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563f730f1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563f730f1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563f730f1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563f730f1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563f730f1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563f730f1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563f730f1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563f730f1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563f730f1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563f730f1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563f75386f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563f720b3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563f720bebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563f71e6ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563f71e6ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563f71e6b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563f71e6a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563f71e6a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563f71e6a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563f76774abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563f7677d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563f76765699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563f76790112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9abac39082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563f7008ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3486b8319a3c4936aa35c18758273e06274fbaa4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5890 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 510086405 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5612e4c87810, 0x5612e4e7101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5612e4e71020,0x5612e6d090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3486b8319a3c4936aa35c18758273e06274fbaa4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7578 processed earlier; will process 3451 files now Step #5: ==212146== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5612db77c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5612e1de1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5612e1dc45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5612e1dc44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5612db782d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5612db6e3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5612db6de355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5612db774c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5612de743f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5612de743f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5612de743f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5612de743f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5612de743f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5612de743f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5612de743f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5612de743f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5612de743f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5612de743f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5612e09d8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5612dd705b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5612dd710be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5612dd4bcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5612dd4bcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5612dd4bd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5612dd4bc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5612dd4bc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5612dd4bc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5612e1dc6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5612e1dcf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5612e1db7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5612e1de2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc3036cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5612db6dcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-809fff8e25d7517aa56ab9e0cfc0504ba38a4741 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5891 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 510682476 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5581a5764810, 0x5581a594e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5581a594e020,0x5581a77e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/809fff8e25d7517aa56ab9e0cfc0504ba38a4741' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7579 processed earlier; will process 3450 files now Step #5: ==212182== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55819c2599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5581a28be898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5581a28a15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5581a28a14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55819c25fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55819c1c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55819c1bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55819c251c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55819f220f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55819f220f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55819f220f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55819f220f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55819f220f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55819f220f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55819f220f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55819f220f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55819f220f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55819f220f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5581a14b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55819e1e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55819e1edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55819df99c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55819df99c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55819df9a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55819df99874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55819df99874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55819df99874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5581a28a3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5581a28ac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5581a2894699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5581a28bf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa1cc090082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55819c1b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-22e92b4cafe55e3b04060f22a7c92af010281baa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5892 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 511355798 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56440102c810, 0x56440121601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564401216020,0x5644030ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/22e92b4cafe55e3b04060f22a7c92af010281baa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7580 processed earlier; will process 3449 files now Step #5: ==212218== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643f7b219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643fe186898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643fe1695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643fe1694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643f7b27d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643f7a88b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643f7a83355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643f7b19c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643faae8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643faae8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643faae8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643faae8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643faae8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643faae8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643faae8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643faae8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643faae8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643faae8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643fcd7df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643f9aaab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643f9ab5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643f9861c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643f9861c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643f9862738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643f9861874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643f9861874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643f9861874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643fe16babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643fe174928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643fe15c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643fe187112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f04fda1b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643f7a81b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fde28b96500872f63ea9f6d8ec40c481ab0c50f8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5893 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 511896561 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556628fde810, 0x5566291c801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5566291c8020,0x55662b0600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fde28b96500872f63ea9f6d8ec40c481ab0c50f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7581 processed earlier; will process 3448 files now Step #5: ==212254== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55661fad39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556626138898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55662611b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55662611b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55661fad9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55661fa3ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55661fa35355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55661facbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556622a9af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556622a9af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556622a9af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556622a9af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556622a9af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556622a9af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556622a9af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556622a9af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556622a9af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556622a9af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556624d2ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556621a5cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556621a67be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556621813c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556621813c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556621814738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556621813874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556621813874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556621813874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55662611dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556626126928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55662610e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556626139112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8266784082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55661fa33b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f1876cba2f672e8c023a6efcf523a03cd5a772c4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5894 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 512514161 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca4b411810, 0x55ca4b5fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca4b5fb020,0x55ca4d4930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f1876cba2f672e8c023a6efcf523a03cd5a772c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7582 processed earlier; will process 3447 files now Step #5: #1 pulse cov: 3894 ft: 3895 exec/s: 0 rss: 179Mb Step #5: ==212290== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ca41f069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca4856b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca4854e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca4854e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca41f0cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca41e6db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca41e68355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca41efec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca44ecdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca44ecdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca44ecdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca44ecdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca44ecdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca44ecdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca44ecdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca44ecdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca44ecdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca44ecdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca47162f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca43e8fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca43e9abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca43c46c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca43c46c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca43c47738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca43c46874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca43c46874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca43c46874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca48550abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca48559928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca48541699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca4856c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f903e0d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca41e66b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8b7478dfa3ee044d1b49fac27c3353e4af160a49 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5895 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 513105301 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564557e7d810, 0x56455806701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564558067020,0x564559eff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8b7478dfa3ee044d1b49fac27c3353e4af160a49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7584 processed earlier; will process 3445 files now Step #5: ==212326== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56454e9729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564554fd7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564554fba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564554fba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56454e978d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56454e8d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56454e8d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56454e96ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564551939f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564551939f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564551939f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564551939f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564551939f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564551939f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564551939f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564551939f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564551939f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564551939f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564553bcef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5645508fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564550906be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5645506b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5645506b2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5645506b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5645506b2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5645506b2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5645506b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564554fbcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564554fc5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564554fad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564554fd8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5fe0207082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56454e8d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5e3cc8d7c1c84876c65995dae6a589b333448b1c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5896 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 513831564 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ea1df2810, 0x559ea1fdc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ea1fdc020,0x559ea3e740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e3cc8d7c1c84876c65995dae6a589b333448b1c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7585 processed earlier; will process 3444 files now Step #5: ==212362== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559e988e79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e9ef4c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e9ef2f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e9ef2f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e988edd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e9884eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e98849355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e988dfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e9b8aef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e9b8aef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e9b8aef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e9b8aef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e9b8aef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e9b8aef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e9b8aef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e9b8aef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e9b8aef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e9b8aef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e9db43f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e9a870b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e9a87bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e9a627c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e9a627c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e9a628738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e9a627874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e9a627874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e9a627874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e9ef31abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e9ef3a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e9ef22699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e9ef4d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff848d55082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e98847b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-77d1f86b481fde017c069b35fda8dccf40baf295 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5897 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 514372274 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f94f3a2810, 0x55f94f58c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f94f58c020,0x55f9514240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/77d1f86b481fde017c069b35fda8dccf40baf295' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7586 processed earlier; will process 3443 files now Step #5: ==212398== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f945e979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f94c4fc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f94c4df5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f94c4df4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f945e9dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f945dfeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f945df9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f945e8fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f948e5ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f948e5ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f948e5ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f948e5ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f948e5ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f948e5ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f948e5ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f948e5ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f948e5ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f948e5ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f94b0f3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f947e20b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f947e2bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f947bd7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f947bd7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f947bd8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f947bd7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f947bd7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f947bd7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f94c4e1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f94c4ea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f94c4d2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f94c4fd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdfd4fe6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f945df7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8cb6e4f44256937a8841ddc1ed80af50aaae8153 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5898 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 514941985 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d7f30ca810, 0x55d7f32b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d7f32b4020,0x55d7f514c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8cb6e4f44256937a8841ddc1ed80af50aaae8153' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7587 processed earlier; will process 3442 files now Step #5: ==212434== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d7e9bbf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d7f0224898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d7f02075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d7f02074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d7e9bc5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d7e9b26b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d7e9b21355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d7e9bb7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d7ecb86f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d7ecb86f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d7ecb86f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d7ecb86f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d7ecb86f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d7ecb86f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d7ecb86f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d7ecb86f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d7ecb86f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d7ecb86f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d7eee1bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d7ebb48b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d7ebb53be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d7eb8ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d7eb8ffc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d7eb900738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d7eb8ff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d7eb8ff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d7eb8ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d7f0209abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d7f0212928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d7f01fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d7f0225112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdd7f319082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d7e9b1fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-26c75c7c550c51e15948b9a27e8545add1fa9c00 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5899 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 515600551 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dae964c810, 0x55dae983601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dae9836020,0x55daeb6ce0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/26c75c7c550c51e15948b9a27e8545add1fa9c00' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7588 processed earlier; will process 3441 files now Step #5: ==212470== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dae01419c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dae67a6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dae67895dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dae67894fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dae0147d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dae00a8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dae00a3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dae0139c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dae3108f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dae3108f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dae3108f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dae3108f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dae3108f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dae3108f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dae3108f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dae3108f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dae3108f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dae3108f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dae539df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dae20cab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dae20d5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dae1e81c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dae1e81c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dae1e82738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dae1e81874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dae1e81874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dae1e81874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dae678babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dae6794928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dae677c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dae67a7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9c7b4a3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dae00a1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9a23fcd4eef4a8f5d6cc896135991b6ebaf6c27f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5900 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 516137872 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f89cbd3810, 0x55f89cdbd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f89cdbd020,0x55f89ec550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9a23fcd4eef4a8f5d6cc896135991b6ebaf6c27f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7589 processed earlier; will process 3440 files now Step #5: #1 pulse cov: 4375 ft: 4376 exec/s: 0 rss: 180Mb Step #5: ==212506== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8936c89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f899d2d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f899d105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f899d104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8936ced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f89362fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f89362a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8936c0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f89668ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f89668ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f89668ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f89668ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f89668ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f89668ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f89668ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f89668ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f89668ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f89668ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f898924f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f895651b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f89565cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f895408c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f895408c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f895409738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f895408874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f895408874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f895408874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f899d12abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f899d1b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f899d03699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f899d2e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fea46b3d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f893628b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cab82fcf07ed582a4bcc179e0161ff68134f9e64 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5901 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 516719515 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a8828c810, 0x563a8847601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a88476020,0x563a8a30e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cab82fcf07ed582a4bcc179e0161ff68134f9e64' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7591 processed earlier; will process 3438 files now Step #5: ==212542== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563a7ed819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a853e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a853c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a853c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a7ed87d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a7ece8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a7ece3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a7ed79c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a81d48f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a81d48f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a81d48f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a81d48f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a81d48f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a81d48f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a81d48f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a81d48f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a81d48f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a81d48f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a83fddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a80d0ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a80d15be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a80ac1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a80ac1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a80ac2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a80ac1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a80ac1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a80ac1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a853cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a853d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a853bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a853e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a38e15082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a7ece1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d0c95a764513425b46234b8df71d877bb5dd9c5a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5902 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 517814742 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f901378810, 0x55f90156201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f901562020,0x55f9033fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d0c95a764513425b46234b8df71d877bb5dd9c5a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7592 processed earlier; will process 3437 files now Step #5: ==212578== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8f7e6d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f8fe4d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8fe4b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8fe4b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8f7e73d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8f7dd4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8f7dcf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8f7e65c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8fae34f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8fae34f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8fae34f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8fae34f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8fae34f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8fae34f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8fae34f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8fae34f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8fae34f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8fae34f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f8fd0c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f8f9df6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f8f9e01be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8f9badc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8f9badc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8f9bae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8f9bad874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8f9bad874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8f9bad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f8fe4b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f8fe4c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f8fe4a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f8fe4d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f75220f3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8f7dcdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-51d4bd1ebc5247f1f2991d4fdf1f4c5a43f9fd8d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5903 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 518367505 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a6b3cc4810, 0x55a6b3eae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a6b3eae020,0x55a6b5d460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/51d4bd1ebc5247f1f2991d4fdf1f4c5a43f9fd8d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7593 processed earlier; will process 3436 files now Step #5: ==212614== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a6aa7b99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a6b0e1e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a6b0e015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a6b0e014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a6aa7bfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a6aa720b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a6aa71b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a6aa7b1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a6ad780f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a6ad780f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a6ad780f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a6ad780f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a6ad780f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a6ad780f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a6ad780f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a6ad780f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a6ad780f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a6ad780f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a6afa15f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a6ac742b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a6ac74dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a6ac4f9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a6ac4f9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a6ac4fa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a6ac4f9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a6ac4f9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a6ac4f9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a6b0e03abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a6b0e0c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a6b0df4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a6b0e1f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f474144e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a6aa719b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c91138c0efd6e08f8a332128ccaa01a3a0bb410e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5904 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 518960846 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa8d6db810, 0x55aa8d8c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa8d8c5020,0x55aa8f75d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c91138c0efd6e08f8a332128ccaa01a3a0bb410e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7594 processed earlier; will process 3435 files now Step #5: ==212650== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aa841d09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa8a835898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa8a8185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa8a8184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa841d6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa84137b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa84132355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa841c8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa87197f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa87197f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa87197f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa87197f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa87197f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa87197f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa87197f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa87197f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa87197f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa87197f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa8942cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa86159b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa86164be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa85f10c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa85f10c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa85f11738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa85f10874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa85f10874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa85f10874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa8a81aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa8a823928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa8a80b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa8a836112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbd9c9d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa84130b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec9b1211e00ed9b2fc01350927506fbc495d9562 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5905 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 520381895 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557dec63f810, 0x557dec82901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557dec829020,0x557dee6c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec9b1211e00ed9b2fc01350927506fbc495d9562' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7595 processed earlier; will process 3434 files now Step #5: #1 pulse cov: 4319 ft: 4320 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4429 ft: 4956 exec/s: 0 rss: 180Mb Step #5: ==212686== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557de31349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557de9799898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557de977c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557de977c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557de313ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557de309bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557de3096355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557de312cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557de60fbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557de60fbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557de60fbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557de60fbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557de60fbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557de60fbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557de60fbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557de60fbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557de60fbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557de60fbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557de8390f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557de50bdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557de50c8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557de4e74c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557de4e74c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557de4e75738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557de4e74874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557de4e74874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557de4e74874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557de977eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557de9787928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557de976f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557de979a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f1d04d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557de3094b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8d563d5bf288011b1d590980e77a9661f9d68a39 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5906 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 521055926 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cdc44cf810, 0x55cdc46b901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cdc46b9020,0x55cdc65510e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8d563d5bf288011b1d590980e77a9661f9d68a39' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7599 processed earlier; will process 3430 files now Step #5: #1 pulse cov: 3981 ft: 3982 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 13868 ft: 15031 exec/s: 0 rss: 205Mb Step #5: #4 pulse cov: 14040 ft: 15794 exec/s: 0 rss: 207Mb Step #5: ==212722== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cdbafc49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cdc1629898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cdc160c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cdc160c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cdbafcad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cdbaf2bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cdbaf26355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cdbafbcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cdbdf8bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cdbdf8bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cdbdf8bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cdbdf8bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cdbdf8bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cdbdf8bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cdbdf8bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cdbdf8bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cdbdf8bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cdbdf8bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cdc0220f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cdbcf4db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cdbcf58be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cdbcd04c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cdbcd04c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cdbcd05738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cdbcd04874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cdbcd04874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cdbcd04874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cdc160eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cdc1617928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cdc15ff699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cdc162a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5418303082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cdbaf24b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d2828b0d5b184ee4e162ca8f12b1a469747c6c62 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5907 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 521835939 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e82b237810, 0x55e82b42101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e82b421020,0x55e82d2b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d2828b0d5b184ee4e162ca8f12b1a469747c6c62' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7604 processed earlier; will process 3425 files now Step #5: ==212758== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e821d2c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e828391898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e8283745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e8283744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e821d32d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e821c93b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e821c8e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e821d24c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e824cf3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e824cf3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e824cf3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e824cf3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e824cf3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e824cf3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e824cf3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e824cf3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e824cf3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e824cf3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e826f88f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e823cb5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e823cc0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e823a6cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e823a6cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e823a6d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e823a6c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e823a6c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e823a6c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e828376abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e82837f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e828367699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e828392112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc4f729b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e821c8cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-daaff585ad54507957a2621fef4e6febc3b9c29c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5908 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 522388110 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee5a0e8810, 0x55ee5a2d201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee5a2d2020,0x55ee5c16a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/daaff585ad54507957a2621fef4e6febc3b9c29c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7605 processed earlier; will process 3424 files now Step #5: #1 pulse cov: 3786 ft: 3787 exec/s: 0 rss: 179Mb Step #5: ==212794== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ee50bdd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee57242898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee572255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee572254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee50be3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee50b44b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee50b3f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee50bd5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee53ba4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee53ba4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee53ba4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee53ba4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee53ba4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee53ba4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee53ba4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee53ba4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee53ba4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee53ba4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee55e39f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee52b66b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee52b71be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee5291dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee5291dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee5291e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee5291d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee5291d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee5291d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee57227abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee57230928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee57218699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee57243112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f98b801d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee50b3db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3ee3747a69ee7cdcfb98ce1a51d77ab2653858a5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5909 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 522975817 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55812e2a3810, 0x55812e48d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55812e48d020,0x5581303250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3ee3747a69ee7cdcfb98ce1a51d77ab2653858a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7607 processed earlier; will process 3422 files now Step #5: ==212830== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558124d989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55812b3fd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55812b3e05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55812b3e04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558124d9ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558124cffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558124cfa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558124d90c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558127d5ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558127d5ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558127d5ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558127d5ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558127d5ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558127d5ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558127d5ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558127d5ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558127d5ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558127d5ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558129ff4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558126d21b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558126d2cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558126ad8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558126ad8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558126ad9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558126ad8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558126ad8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558126ad8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55812b3e2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55812b3eb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55812b3d3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55812b3fe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f625c0a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558124cf8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8ae3c2571b9beeeff96654cc61e4dd448e5e0d35 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5910 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 524226464 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558c219b2810, 0x558c21b9c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558c21b9c020,0x558c23a340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ae3c2571b9beeeff96654cc61e4dd448e5e0d35' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7608 processed earlier; will process 3421 files now Step #5: ==212866== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558c184a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558c1eb0c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558c1eaef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558c1eaef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558c184add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558c1840eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558c18409355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558c1849fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558c1b46ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558c1b46ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558c1b46ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558c1b46ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558c1b46ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558c1b46ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558c1b46ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558c1b46ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558c1b46ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558c1b46ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558c1d703f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558c1a430b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558c1a43bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558c1a1e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558c1a1e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558c1a1e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558c1a1e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558c1a1e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558c1a1e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558c1eaf1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558c1eafa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558c1eae2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558c1eb0d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f684723a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558c18407b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-08dbcde0b48abc651c5441ca10be07a5cb2fe09e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5911 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 525315724 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558b45092810, 0x558b4527c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558b4527c020,0x558b471140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08dbcde0b48abc651c5441ca10be07a5cb2fe09e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7609 processed earlier; will process 3420 files now Step #5: #1 pulse cov: 4170 ft: 4171 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4424 ft: 5009 exec/s: 0 rss: 181Mb Step #5: ==212902== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558b3bb879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558b421ec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558b421cf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558b421cf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558b3bb8dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558b3baeeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558b3bae9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558b3bb7fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558b3eb4ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558b3eb4ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558b3eb4ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558b3eb4ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558b3eb4ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558b3eb4ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558b3eb4ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558b3eb4ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558b3eb4ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558b3eb4ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558b40de3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558b3db10b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558b3db1bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558b3d8c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558b3d8c7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558b3d8c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558b3d8c7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558b3d8c7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558b3d8c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558b421d1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558b421da928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558b421c2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558b421ed112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b4ca00082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558b3bae7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-451393e1d3eead06e0137c107997bc1cec5cca80 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5912 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 525938269 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560e3e1c9810, 0x560e3e3b301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560e3e3b3020,0x560e4024b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/451393e1d3eead06e0137c107997bc1cec5cca80' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7612 processed earlier; will process 3417 files now Step #5: ==212938== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560e34cbe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560e3b323898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560e3b3065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560e3b3064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560e34cc4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560e34c25b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560e34c20355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560e34cb6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560e37c85f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560e37c85f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560e37c85f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560e37c85f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560e37c85f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560e37c85f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560e37c85f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560e37c85f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560e37c85f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560e37c85f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560e39f1af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560e36c47b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560e36c52be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560e369fec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560e369fec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560e369ff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560e369fe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560e369fe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560e369fe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560e3b308abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560e3b311928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560e3b2f9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560e3b324112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f767fbfa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560e34c1eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-896bd0919c9e9865295553a5b22788a343dc6d76 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5913 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 526604999 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc72682810, 0x55cc7286c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc7286c020,0x55cc747040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/896bd0919c9e9865295553a5b22788a343dc6d76' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7613 processed earlier; will process 3416 files now Step #5: #1 pulse cov: 3950 ft: 3951 exec/s: 0 rss: 179Mb Step #5: ==212974== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cc691779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc6f7dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc6f7bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc6f7bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc6917dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc690deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc690d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc6916fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc6c13ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc6c13ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc6c13ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc6c13ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc6c13ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc6c13ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc6c13ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc6c13ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc6c13ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc6c13ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc6e3d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc6b100b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc6b10bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc6aeb7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc6aeb7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc6aeb8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc6aeb7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc6aeb7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc6aeb7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc6f7c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc6f7ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc6f7b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc6f7dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7bbaa8c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc690d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aee00e7fadf09abca84c28a7f09b75ab44e4eb9a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5914 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 527192669 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55564cedc810, 0x55564d0c601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55564d0c6020,0x55564ef5e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aee00e7fadf09abca84c28a7f09b75ab44e4eb9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7615 processed earlier; will process 3414 files now Step #5: ==213010== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5556439d19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55564a036898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55564a0195dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55564a0194fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5556439d7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555643938b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555643933355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5556439c9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555646998f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555646998f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555646998f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555646998f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555646998f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555646998f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555646998f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555646998f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555646998f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555646998f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555648c2df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55564595ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555645965be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555645711c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555645711c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555645712738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555645711874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555645711874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555645711874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55564a01babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55564a024928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55564a00c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55564a037112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa32abb1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555643931b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-083e5bee61264f9ac440702306dbc2572025020c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5915 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 527883799 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5633fa91e810, 0x5633fab0801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5633fab08020,0x5633fc9a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/083e5bee61264f9ac440702306dbc2572025020c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7616 processed earlier; will process 3413 files now Step #5: #1 pulse cov: 3791 ft: 3792 exec/s: 0 rss: 177Mb Step #5: ==213046== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5633f14139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5633f7a78898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5633f7a5b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5633f7a5b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5633f1419d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5633f137ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5633f1375355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5633f140bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5633f43daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5633f43daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5633f43daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5633f43daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5633f43daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5633f43daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5633f43daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5633f43daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5633f43daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5633f43daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5633f666ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5633f339cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5633f33a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5633f3153c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5633f3153c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5633f3154738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5633f3153874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5633f3153874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5633f3153874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5633f7a5dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5633f7a66928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5633f7a4e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5633f7a79112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f972e2cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5633f1373b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb78c44b5f783c7daf5b8d6e5ba23d82ef76f47c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5916 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 528470511 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3ff1c7810, 0x55a3ff3b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3ff3b1020,0x55a4012490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb78c44b5f783c7daf5b8d6e5ba23d82ef76f47c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7618 processed earlier; will process 3411 files now Step #5: ==213082== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a3f5cbc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a3fc321898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a3fc3045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a3fc3044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3f5cc2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a3f5c23b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a3f5c1e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3f5cb4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a3f8c83f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a3f8c83f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a3f8c83f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a3f8c83f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a3f8c83f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a3f8c83f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a3f8c83f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a3f8c83f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a3f8c83f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a3f8c83f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3faf18f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3f7c45b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3f7c50be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3f79fcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3f79fcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3f79fd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3f79fc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3f79fc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3f79fc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a3fc306abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a3fc30f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a3fc2f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a3fc322112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ee91c6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a3f5c1cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1dfeb85c1f39c7323241396e297a1f09e8a27329 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5917 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 529001426 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55abca958810, 0x55abcab4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55abcab42020,0x55abcc9da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1dfeb85c1f39c7323241396e297a1f09e8a27329' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7619 processed earlier; will process 3410 files now Step #5: ==213118== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55abc144d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55abc7ab2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55abc7a955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55abc7a954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55abc1453d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55abc13b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55abc13af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55abc1445c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55abc4414f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55abc4414f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55abc4414f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55abc4414f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55abc4414f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55abc4414f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55abc4414f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55abc4414f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55abc4414f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55abc4414f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55abc66a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55abc33d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55abc33e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55abc318dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55abc318dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55abc318e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55abc318d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55abc318d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55abc318d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55abc7a97abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55abc7aa0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55abc7a88699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55abc7ab3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa4b5722082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55abc13adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e560c259942b58f433692f46c8746ae5ff1526e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5918 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 529575948 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd8a11f810, 0x55dd8a30901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd8a309020,0x55dd8c1a10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e560c259942b58f433692f46c8746ae5ff1526e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7620 processed earlier; will process 3409 files now Step #5: ==213154== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dd80c149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd87279898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd8725c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd8725c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dd80c1ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dd80b7bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dd80b76355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dd80c0cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd83bdbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd83bdbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd83bdbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd83bdbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd83bdbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd83bdbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd83bdbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd83bdbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd83bdbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd83bdbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd85e70f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dd82b9db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dd82ba8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dd82954c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dd82954c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dd82955738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dd82954874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dd82954874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dd82954874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd8725eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd87267928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd8724f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd8727a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f779cc74082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dd80b74b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a8b1eb537339819aa56dbda2e8a71c2fc535e197 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5919 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 530166360 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c09cd1810, 0x561c09ebb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c09ebb020,0x561c0bd530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a8b1eb537339819aa56dbda2e8a71c2fc535e197' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7621 processed earlier; will process 3408 files now Step #5: ==213190== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561c007c69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c06e2b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c06e0e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c06e0e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c007ccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c0072db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c00728355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c007bec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c0378df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c0378df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c0378df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c0378df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c0378df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c0378df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c0378df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c0378df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c0378df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c0378df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c05a22f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c0274fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c0275abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c02506c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c02506c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c02507738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c02506874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c02506874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c02506874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c06e10abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c06e19928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c06e01699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c06e2c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3795ffe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c00726b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-398783dd13a83d8d37f56ed031db6291f0be3560 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5920 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 531474031 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c387d7810, 0x556c389c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c389c1020,0x556c3a8590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/398783dd13a83d8d37f56ed031db6291f0be3560' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7622 processed earlier; will process 3407 files now Step #5: ==213226== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556c2f2cc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c35931898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c359145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c359144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556c2f2d2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556c2f233b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556c2f22e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556c2f2c4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556c32293f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556c32293f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556c32293f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556c32293f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556c32293f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556c32293f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556c32293f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556c32293f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556c32293f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556c32293f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c34528f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556c31255b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556c31260be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556c3100cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556c3100cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556c3100d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556c3100c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556c3100c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556c3100c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c35916abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c3591f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c35907699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c35932112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f36ddafa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556c2f22cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bdfa9560e09854e14e4a840c5f10c8d0b4b3a729 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5921 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 532176515 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5622570f1810, 0x5622572db01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5622572db020,0x5622591730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bdfa9560e09854e14e4a840c5f10c8d0b4b3a729' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7623 processed earlier; will process 3406 files now Step #5: #1 pulse cov: 3762 ft: 3763 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4135 ft: 4504 exec/s: 0 rss: 179Mb Step #5: #4 pulse cov: 5173 ft: 6485 exec/s: 0 rss: 181Mb Step #5: ==213262== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56224dbe69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56225424b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56225422e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56225422e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56224dbecd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56224db4db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56224db48355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56224dbdec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562250badf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562250badf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562250badf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562250badf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562250badf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562250badf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562250badf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562250badf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562250badf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562250badf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562252e42f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56224fb6fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56224fb7abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56224f926c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56224f926c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56224f927738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56224f926874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56224f926874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56224f926874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562254230abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562254239928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562254221699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56225424c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0f732fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56224db46b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f93605e56e710e613b06dd4be2cb8f113615b22f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5922 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 533045307 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559d7b0b2810, 0x559d7b29c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559d7b29c020,0x559d7d1340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f93605e56e710e613b06dd4be2cb8f113615b22f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7629 processed earlier; will process 3400 files now Step #5: ==213298== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559d71ba79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559d7820c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559d781ef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559d781ef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559d71badd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559d71b0eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559d71b09355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559d71b9fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559d74b6ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559d74b6ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559d74b6ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559d74b6ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559d74b6ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559d74b6ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559d74b6ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559d74b6ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559d74b6ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559d74b6ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559d76e03f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559d73b30b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559d73b3bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559d738e7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559d738e7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559d738e8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559d738e7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559d738e7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559d738e7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559d781f1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559d781fa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559d781e2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559d7820d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c25892082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559d71b07b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c5f87f7f4ca4d62b12d55a224a3ac266f032dd49 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5923 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 533592047 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b4425a5810, 0x55b44278f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b44278f020,0x55b4446270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c5f87f7f4ca4d62b12d55a224a3ac266f032dd49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7630 processed earlier; will process 3399 files now Step #5: ==213334== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b43909a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b43f6ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b43f6e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b43f6e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b4390a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b439001b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b438ffc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b439092c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b43c061f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b43c061f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b43c061f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b43c061f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b43c061f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b43c061f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b43c061f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b43c061f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b43c061f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b43c061f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b43e2f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b43b023b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b43b02ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b43addac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b43addac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b43addb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b43adda874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b43adda874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b43adda874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b43f6e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b43f6ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b43f6d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b43f700112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faba5552082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b438ffab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-48a77897a49899ae8a5899fe238826a430cb1719 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5924 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 534144126 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c54bf4e810, 0x55c54c13801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c54c138020,0x55c54dfd00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/48a77897a49899ae8a5899fe238826a430cb1719' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7631 processed earlier; will process 3398 files now Step #5: ==213370== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c542a439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c5490a8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c54908b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c54908b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c542a49d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c5429aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c5429a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c542a3bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c545a0af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c545a0af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c545a0af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c545a0af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c545a0af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c545a0af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c545a0af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c545a0af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c545a0af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c545a0af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c547c9ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c5449ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c5449d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c544783c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c544783c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c544784738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c544783874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c544783874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c544783874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c54908dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c549096928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c54907e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c5490a9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efecab29082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c5429a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bf30b836148aa3e9367ce680cdf581974cc2b15d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5925 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 534688746 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d06f48e810, 0x55d06f67801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d06f678020,0x55d0715100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf30b836148aa3e9367ce680cdf581974cc2b15d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7632 processed earlier; will process 3397 files now Step #5: ==213406== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d065f839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d06c5e8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d06c5cb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d06c5cb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d065f89d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d065eeab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d065ee5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d065f7bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d068f4af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d068f4af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d068f4af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d068f4af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d068f4af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d068f4af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d068f4af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d068f4af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d068f4af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d068f4af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d06b1dff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d067f0cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d067f17be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d067cc3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d067cc3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d067cc4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d067cc3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d067cc3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d067cc3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d06c5cdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d06c5d6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d06c5be699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d06c5e9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb5a4238082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d065ee3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-97c369011c63d74a53ecafd955b28845f3c2b642 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5926 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 535284831 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55686b90a810, 0x55686baf401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55686baf4020,0x55686d98c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/97c369011c63d74a53ecafd955b28845f3c2b642' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7633 processed earlier; will process 3396 files now Step #5: #1 pulse cov: 3793 ft: 3794 exec/s: 0 rss: 179Mb Step #5: ==213442== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5568623ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556868a64898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556868a475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556868a474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556862405d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556862366b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556862361355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5568623f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5568653c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5568653c6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5568653c6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5568653c6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5568653c6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5568653c6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5568653c6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5568653c6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5568653c6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5568653c6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55686765bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556864388b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556864393be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55686413fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55686413fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556864140738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55686413f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55686413f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55686413f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556868a49abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556868a52928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556868a3a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556868a65112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8392fd8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55686235fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-182fb4dc92d43e2f657a5d14bf92f62201e14e41 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5927 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 535913402 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564cd44fd810, 0x564cd46e701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564cd46e7020,0x564cd657f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/182fb4dc92d43e2f657a5d14bf92f62201e14e41' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7635 processed earlier; will process 3394 files now Step #5: ==213478== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564ccaff29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564cd1657898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564cd163a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564cd163a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564ccaff8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564ccaf59b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564ccaf54355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564ccafeac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564ccdfb9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564ccdfb9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564ccdfb9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564ccdfb9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564ccdfb9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564ccdfb9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564ccdfb9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564ccdfb9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564ccdfb9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564ccdfb9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564cd024ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564cccf7bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564cccf86be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564cccd32c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564cccd32c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564cccd33738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564cccd32874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564cccd32874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564cccd32874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564cd163cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564cd1645928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564cd162d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564cd1658112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ba29f0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564ccaf52b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-21b819ca2810e72bc632b2871169b3ed572c88da Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5928 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 536493649 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56549fc58810, 0x56549fe4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56549fe42020,0x5654a1cda0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/21b819ca2810e72bc632b2871169b3ed572c88da' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7636 processed earlier; will process 3393 files now Step #5: ==213514== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56549674d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56549cdb2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56549cd955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56549cd954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565496753d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5654966b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5654966af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565496745c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565499714f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565499714f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565499714f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565499714f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565499714f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565499714f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565499714f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565499714f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565499714f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565499714f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56549b9a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5654986d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5654986e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56549848dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56549848dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56549848e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56549848d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56549848d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56549848d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56549cd97abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56549cda0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56549cd88699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56549cdb3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fee526f4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5654966adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-190ebc8babf03be60c186152b6ea653e197236e2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5929 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 537151345 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e969eeb810, 0x55e96a0d501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e96a0d5020,0x55e96bf6d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/190ebc8babf03be60c186152b6ea653e197236e2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7637 processed earlier; will process 3392 files now Step #5: ==213550== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e9609e09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e967045898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9670285dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9670284fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9609e6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e960947b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e960942355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9609d8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e9639a7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e9639a7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e9639a7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e9639a7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e9639a7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e9639a7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e9639a7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e9639a7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e9639a7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e9639a7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e965c3cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e962969b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e962974be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e962720c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e962720c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e962721738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e962720874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e962720874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e962720874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e96702aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e967033928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e96701b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e967046112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8fd6307082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e960940b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c02365db3d300451454ced5894f532004e73653f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5930 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 537699451 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55677af84810, 0x55677b16e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55677b16e020,0x55677d0060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c02365db3d300451454ced5894f532004e73653f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7638 processed earlier; will process 3391 files now Step #5: ==213586== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556771a799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5567780de898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5567780c15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5567780c14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556771a7fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5567719e0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5567719db355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556771a71c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556774a40f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556774a40f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556774a40f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556774a40f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556774a40f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556774a40f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556774a40f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556774a40f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556774a40f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556774a40f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556776cd5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556773a02b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556773a0dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5567737b9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5567737b9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5567737ba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5567737b9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5567737b9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5567737b9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5567780c3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5567780cc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5567780b4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5567780df112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f63772d8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5567719d9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6c6456ca27ec6c0d492379c2dc9432a10a9489f7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5931 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 538252632 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e53e1dd810, 0x55e53e3c701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e53e3c7020,0x55e54025f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6c6456ca27ec6c0d492379c2dc9432a10a9489f7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7639 processed earlier; will process 3390 files now Step #5: ==213622== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e534cd29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e53b337898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e53b31a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e53b31a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e534cd8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e534c39b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e534c34355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e534ccac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e537c99f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e537c99f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e537c99f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e537c99f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e537c99f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e537c99f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e537c99f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e537c99f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e537c99f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e537c99f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e539f2ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e536c5bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e536c66be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e536a12c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e536a12c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e536a13738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e536a12874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e536a12874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e536a12874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e53b31cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e53b325928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e53b30d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e53b338112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f028e01a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e534c32b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6bc2e1589c5ffda261dcef122bddfed8166918f7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5932 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 538786897 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56410ee95810, 0x56410f07f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56410f07f020,0x564110f170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bc2e1589c5ffda261dcef122bddfed8166918f7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7640 processed earlier; will process 3389 files now Step #5: #1 pulse cov: 4341 ft: 4342 exec/s: 0 rss: 179Mb Step #5: ==213658== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56410598a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56410bfef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56410bfd25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56410bfd24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564105990d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641058f1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641058ec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564105982c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564108951f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564108951f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564108951f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564108951f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564108951f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564108951f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564108951f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564108951f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564108951f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564108951f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56410abe6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564107913b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56410791ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5641076cac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5641076cac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5641076cb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5641076ca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5641076ca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5641076ca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56410bfd4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56410bfdd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56410bfc5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56410bff0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9e1750c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641058eab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0d8ec63256c83fe0351fdc88586928254c667acd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5933 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 539341588 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a457781810, 0x55a45796b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a45796b020,0x55a4598030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0d8ec63256c83fe0351fdc88586928254c667acd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7642 processed earlier; will process 3387 files now Step #5: ==213694== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a44e2769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a4548db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a4548be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a4548be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a44e27cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a44e1ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a44e1d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a44e26ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a45123df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a45123df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a45123df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a45123df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a45123df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a45123df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a45123df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a45123df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a45123df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a45123df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a4534d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a4501ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a45020abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a44ffb6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a44ffb6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a44ffb7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a44ffb6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a44ffb6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a44ffb6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a4548c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a4548c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a4548b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a4548dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efcbdbe1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a44e1d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-dc1f0aac667ea3216f87edad8ecb101e4892de12 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5934 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 539896887 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55664f6e5810, 0x55664f8cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55664f8cf020,0x5566517670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dc1f0aac667ea3216f87edad8ecb101e4892de12' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7643 processed earlier; will process 3386 files now Step #5: #1 pulse cov: 3653 ft: 3654 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4607 ft: 5092 exec/s: 0 rss: 179Mb Step #5: ==213730== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5566461da9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55664c83f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55664c8225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55664c8224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5566461e0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556646141b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55664613c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5566461d2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5566491a1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5566491a1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5566491a1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5566491a1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5566491a1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5566491a1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5566491a1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5566491a1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5566491a1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5566491a1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55664b436f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556648163b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55664816ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556647f1ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556647f1ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556647f1b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556647f1a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556647f1a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556647f1a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55664c824abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55664c82d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55664c815699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55664c840112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcf28713082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55664613ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-69d8f32f73845ccdfc81a7ef7cdaa267ce7b1f70 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5935 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 540521937 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a94a6fb810, 0x55a94a8e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a94a8e5020,0x55a94c77d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/69d8f32f73845ccdfc81a7ef7cdaa267ce7b1f70' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7646 processed earlier; will process 3383 files now Step #5: #1 pulse cov: 4424 ft: 4425 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4838 ft: 5388 exec/s: 0 rss: 179Mb Step #5: ==213766== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a9411f09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a947855898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9478385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9478384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a9411f6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a941157b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a941152355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a9411e8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9441b7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9441b7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9441b7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9441b7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9441b7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9441b7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9441b7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9441b7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9441b7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9441b7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a94644cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a943179b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a943184be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a942f30c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a942f30c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a942f31738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a942f30874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a942f30874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a942f30874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a94783aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a947843928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a94782b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a947856112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc69ccc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a941150b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4d5dc2a1d09a456b106613d113d12419ef004a16 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5936 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 541145388 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559dc9661810, 0x559dc984b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559dc984b020,0x559dcb6e30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4d5dc2a1d09a456b106613d113d12419ef004a16' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7649 processed earlier; will process 3380 files now Step #5: ==213802== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559dc01569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559dc67bb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559dc679e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559dc679e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559dc015cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559dc00bdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559dc00b8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559dc014ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559dc311df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559dc311df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559dc311df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559dc311df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559dc311df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559dc311df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559dc311df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559dc311df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559dc311df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559dc311df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559dc53b2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559dc20dfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559dc20eabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559dc1e96c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559dc1e96c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559dc1e97738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559dc1e96874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559dc1e96874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559dc1e96874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559dc67a0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559dc67a9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559dc6791699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559dc67bc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc99578c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559dc00b6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9ffdd0929834e82d92d2a3f9112f2bb446f29155 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5937 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 541887735 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559098446810, 0x55909863001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559098630020,0x55909a4c80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9ffdd0929834e82d92d2a3f9112f2bb446f29155' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7650 processed earlier; will process 3379 files now Step #5: ==213838== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55908ef3b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5590955a0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5590955835dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5590955834fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55908ef41d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55908eea2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55908ee9d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55908ef33c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559091f02f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559091f02f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559091f02f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559091f02f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559091f02f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559091f02f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559091f02f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559091f02f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559091f02f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559091f02f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559094197f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559090ec4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559090ecfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559090c7bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559090c7bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559090c7c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559090c7b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559090c7b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559090c7b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559095585abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55909558e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559095576699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5590955a1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f155d6c1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55908ee9bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2f2f989707321ef585a5092fd060374c7d139ec9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5938 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 542405006 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56533dbc8810, 0x56533ddb201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56533ddb2020,0x56533fc4a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f2f989707321ef585a5092fd060374c7d139ec9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7651 processed earlier; will process 3378 files now Step #5: ==213874== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5653346bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56533ad22898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56533ad055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56533ad054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5653346c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565334624b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56533461f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5653346b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565337684f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565337684f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565337684f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565337684f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565337684f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565337684f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565337684f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565337684f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565337684f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565337684f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565339919f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x565336646b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x565336651be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5653363fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5653363fdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5653363fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5653363fd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5653363fd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5653363fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56533ad07abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56533ad10928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56533acf8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56533ad23112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8bdc898082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56533461db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-57e5d1d4b1b9882abbb71eb1d6733438fd0481fa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5939 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 542967677 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a880fdb810, 0x55a8811c501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a8811c5020,0x55a88305d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/57e5d1d4b1b9882abbb71eb1d6733438fd0481fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7652 processed earlier; will process 3377 files now Step #5: ==213910== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a877ad09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a87e135898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a87e1185dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a87e1184fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a877ad6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a877a37b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a877a32355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a877ac8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a87aa97f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a87aa97f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a87aa97f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a87aa97f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a87aa97f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a87aa97f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a87aa97f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a87aa97f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a87aa97f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a87aa97f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a87cd2cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a879a59b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a879a64be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a879810c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a879810c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a879811738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a879810874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a879810874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a879810874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a87e11aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a87e123928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a87e10b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a87e136112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5974dfd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a877a30b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9f6bb182c896d97c785fae9496b852d59ab8d631 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5940 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 543564665 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652322b7810, 0x5652324a101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652324a1020,0x5652343390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f6bb182c896d97c785fae9496b852d59ab8d631' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7653 processed earlier; will process 3376 files now Step #5: ==213946== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x565228dac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56522f411898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56522f3f45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56522f3f44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x565228db2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x565228d13b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x565228d0e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x565228da4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56522bd73f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56522bd73f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56522bd73f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56522bd73f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56522bd73f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56522bd73f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56522bd73f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56522bd73f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56522bd73f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56522bd73f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56522e008f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56522ad35b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56522ad40be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56522aaecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56522aaecc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56522aaed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56522aaec874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56522aaec874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56522aaec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56522f3f6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56522f3ff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56522f3e7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56522f412112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f634be40082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x565228d0cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-576e442e7828a8697db82a1992ce76119535d619 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5941 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 544124013 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c49c6bb810, 0x55c49c8a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c49c8a5020,0x55c49e73d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/576e442e7828a8697db82a1992ce76119535d619' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7654 processed earlier; will process 3375 files now Step #5: #1 pulse cov: 3489 ft: 3490 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4047 ft: 4417 exec/s: 0 rss: 182Mb Step #5: ==213982== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c4931b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c499815898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c4997f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c4997f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c4931b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c493117b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c493112355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c4931a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c496177f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c496177f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c496177f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c496177f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c496177f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c496177f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c496177f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c496177f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c496177f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c496177f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c49840cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c495139b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c495144be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c494ef0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c494ef0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c494ef1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c494ef0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c494ef0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c494ef0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c4997faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c499803928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c4997eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c499816112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fab885ed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c493110b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7f01053bcf27bb82a9521d8edf485a2b6b5541db Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5942 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 544744944 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ac6847810, 0x559ac6a3101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ac6a31020,0x559ac88c90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f01053bcf27bb82a9521d8edf485a2b6b5541db' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7657 processed earlier; will process 3372 files now Step #5: ==214018== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559abd33c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ac39a1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ac39845dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ac39844fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559abd342d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559abd2a3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559abd29e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559abd334c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ac0303f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ac0303f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ac0303f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ac0303f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ac0303f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ac0303f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ac0303f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ac0303f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ac0303f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ac0303f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ac2598f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559abf2c5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559abf2d0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559abf07cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559abf07cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559abf07d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559abf07c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559abf07c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559abf07c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ac3986abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ac398f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ac3977699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ac39a2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa4ea40082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559abd29cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-279c225f7427d72cd58d9c02e4737332e64fb970 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5943 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 545332748 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5564f9335810, 0x5564f951f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564f951f020,0x5564fb3b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/279c225f7427d72cd58d9c02e4737332e64fb970' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7658 processed earlier; will process 3371 files now Step #5: ==214054== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5564efe2a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564f648f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564f64725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564f64724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564efe30d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5564efd91b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5564efd8c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564efe22c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564f2df1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564f2df1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564f2df1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564f2df1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564f2df1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564f2df1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564f2df1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564f2df1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564f2df1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564f2df1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5564f5086f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5564f1db3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5564f1dbebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5564f1b6ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5564f1b6ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5564f1b6b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5564f1b6a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5564f1b6a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5564f1b6a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564f6474abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564f647d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564f6465699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564f6490112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6688a32082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5564efd8ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-caf50b46918dc660ebf45010d83d1c0fb1b779f9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5944 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 545919368 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562bcdcf7810, 0x562bcdee101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562bcdee1020,0x562bcfd790e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/caf50b46918dc660ebf45010d83d1c0fb1b779f9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7659 processed earlier; will process 3370 files now Step #5: ==214090== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562bc47ec9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562bcae51898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562bcae345dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562bcae344fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562bc47f2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562bc4753b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562bc474e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562bc47e4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562bc77b3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562bc77b3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562bc77b3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562bc77b3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562bc77b3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562bc77b3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562bc77b3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562bc77b3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562bc77b3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562bc77b3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562bc9a48f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562bc6775b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562bc6780be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562bc652cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562bc652cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562bc652d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562bc652c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562bc652c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562bc652c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562bcae36abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562bcae3f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562bcae27699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562bcae52112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f77a015f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562bc474cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8e2077b1faadc120a3106cd515c600fecd5bd857 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5945 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 547197951 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56284e5c7810, 0x56284e7b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56284e7b1020,0x5628506490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8e2077b1faadc120a3106cd515c600fecd5bd857' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7660 processed earlier; will process 3369 files now Step #5: ==214126== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5628450bc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56284b721898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56284b7045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56284b7044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5628450c2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562845023b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56284501e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5628450b4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562848083f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562848083f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562848083f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562848083f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562848083f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562848083f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562848083f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562848083f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562848083f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562848083f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56284a318f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562847045b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562847050be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562846dfcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562846dfcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562846dfd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562846dfc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562846dfc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562846dfc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56284b706abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56284b70f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56284b6f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56284b722112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2a9e2cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56284501cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-49ec40cdf6281f0336e668e1072dd8659eac429c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5946 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 547794363 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563fd1f8c810, 0x563fd217601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563fd2176020,0x563fd400e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/49ec40cdf6281f0336e668e1072dd8659eac429c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7661 processed earlier; will process 3368 files now Step #5: ==214162== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563fc8a819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563fcf0e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563fcf0c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563fcf0c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563fc8a87d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563fc89e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563fc89e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563fc8a79c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563fcba48f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563fcba48f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563fcba48f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563fcba48f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563fcba48f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563fcba48f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563fcba48f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563fcba48f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563fcba48f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563fcba48f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563fcdcddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563fcaa0ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563fcaa15be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563fca7c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563fca7c1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563fca7c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563fca7c1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563fca7c1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563fca7c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563fcf0cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563fcf0d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563fcf0bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563fcf0e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f08b0599082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563fc89e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cfa56bdb964f00e4b8e2ab24db6a55673d718c06 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5947 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 548353785 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56279640f810, 0x5627965f901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5627965f9020,0x5627984910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cfa56bdb964f00e4b8e2ab24db6a55673d718c06' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7662 processed earlier; will process 3367 files now Step #5: ==214198== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56278cf049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562793569898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56279354c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56279354c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56278cf0ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56278ce6bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56278ce66355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56278cefcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56278fecbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56278fecbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56278fecbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56278fecbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56278fecbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56278fecbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56278fecbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56278fecbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56278fecbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56278fecbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562792160f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56278ee8db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56278ee98be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56278ec44c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56278ec44c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56278ec45738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56278ec44874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56278ec44874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56278ec44874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56279354eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562793557928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56279353f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56279356a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f756b559082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56278ce64b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-41ebd42e3278b2cca05ca1e1e4a53b90882f51a5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5948 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 549596967 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56007a095810, 0x56007a27f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56007a27f020,0x56007c1170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/41ebd42e3278b2cca05ca1e1e4a53b90882f51a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7663 processed earlier; will process 3366 files now Step #5: ==214234== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560070b8a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5600771ef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5600771d25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5600771d24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560070b90d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560070af1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560070aec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560070b82c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560073b51f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560073b51f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560073b51f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560073b51f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560073b51f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560073b51f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560073b51f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560073b51f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560073b51f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560073b51f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560075de6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560072b13b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560072b1ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5600728cac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5600728cac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5600728cb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5600728ca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5600728ca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5600728ca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5600771d4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5600771dd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5600771c5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5600771f0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fce3b62a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560070aeab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-034a80bd0767e02b90cd3e5ef0051b90784838d2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5949 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 550191532 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560aea706810, 0x560aea8f001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560aea8f0020,0x560aec7880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/034a80bd0767e02b90cd3e5ef0051b90784838d2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7664 processed earlier; will process 3365 files now Step #5: ==214270== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560ae11fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560ae7860898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560ae78435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560ae78434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560ae1201d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560ae1162b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560ae115d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560ae11f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560ae41c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560ae41c2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560ae41c2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560ae41c2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560ae41c2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560ae41c2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560ae41c2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560ae41c2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560ae41c2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560ae41c2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560ae6457f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560ae3184b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560ae318fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560ae2f3bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560ae2f3bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560ae2f3c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560ae2f3b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560ae2f3b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560ae2f3b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560ae7845abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560ae784e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560ae7836699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560ae7861112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1371b01082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560ae115bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-88852e1651cbf461ae64b2c139170c95a3c437cb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5950 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 550728130 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5619d61a0810, 0x5619d638a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5619d638a020,0x5619d82220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/88852e1651cbf461ae64b2c139170c95a3c437cb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7665 processed earlier; will process 3364 files now Step #5: ==214306== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5619ccc959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5619d32fa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5619d32dd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5619d32dd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5619ccc9bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5619ccbfcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5619ccbf7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5619ccc8dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5619cfc5cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5619cfc5cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5619cfc5cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5619cfc5cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5619cfc5cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5619cfc5cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5619cfc5cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5619cfc5cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5619cfc5cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5619cfc5cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5619d1ef1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5619cec1eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5619cec29be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5619ce9d5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5619ce9d5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5619ce9d6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5619ce9d5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5619ce9d5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5619ce9d5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5619d32dfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5619d32e8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5619d32d0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5619d32fb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f13a0d85082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5619ccbf5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4f1fba64816202edadd908e9805b8bc0a6f98d43 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5951 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 551307334 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563646626810, 0x56364681001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563646810020,0x5636486a80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f1fba64816202edadd908e9805b8bc0a6f98d43' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7666 processed earlier; will process 3363 files now Step #5: ==214342== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56363d11b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563643780898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636437635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636437634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56363d121d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56363d082b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56363d07d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56363d113c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5636400e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5636400e2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5636400e2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5636400e2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5636400e2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5636400e2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5636400e2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5636400e2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5636400e2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5636400e2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563642377f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56363f0a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56363f0afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56363ee5bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56363ee5bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56363ee5c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56363ee5b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56363ee5b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56363ee5b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563643765abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56364376e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563643756699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563643781112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ca2f41082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56363d07bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7e6d725924f84c642f5648a02ff772561981057a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5952 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 552099313 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56280ce50810, 0x56280d03a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56280d03a020,0x56280eed20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7e6d725924f84c642f5648a02ff772561981057a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7667 processed earlier; will process 3362 files now Step #5: ==214378== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5628039459c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562809faa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562809f8d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562809f8d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56280394bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5628038acb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5628038a7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56280393dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56280690cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56280690cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56280690cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56280690cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56280690cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56280690cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56280690cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56280690cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56280690cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56280690cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562808ba1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5628058ceb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5628058d9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562805685c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562805685c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562805686738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562805685874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562805685874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562805685874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562809f8fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562809f98928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562809f80699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562809fab112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f11f681a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5628038a5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2940b88a030beed1056bec1cb6b4d02d39fbd57a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5953 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 552685029 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d300719810, 0x55d30090301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d300903020,0x55d30279b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2940b88a030beed1056bec1cb6b4d02d39fbd57a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7668 processed earlier; will process 3361 files now Step #5: #1 pulse cov: 11569 ft: 11570 exec/s: 0 rss: 198Mb Step #5: ==214414== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d2f720e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d2fd873898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d2fd8565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d2fd8564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d2f7214d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d2f7175b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d2f7170355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d2f7206c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d2fa1d5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d2fa1d5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d2fa1d5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d2fa1d5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d2fa1d5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d2fa1d5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d2fa1d5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d2fa1d5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d2fa1d5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d2fa1d5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d2fc46af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d2f9197b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d2f91a2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d2f8f4ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d2f8f4ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d2f8f4f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d2f8f4e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d2f8f4e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d2f8f4e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d2fd858abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d2fd861928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d2fd849699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d2fd874112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e7ed30082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d2f716eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c9a41f800ebec03df2516dc160772698d8c9bfcb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5954 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 554047361 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55adfdffb810, 0x55adfe1e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55adfe1e5020,0x55ae0007d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9a41f800ebec03df2516dc160772698d8c9bfcb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7670 processed earlier; will process 3359 files now Step #5: #1 pulse cov: 13587 ft: 13588 exec/s: 0 rss: 211Mb Step #5: ==214450== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55adf4af09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55adfb155898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55adfb1385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55adfb1384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55adf4af6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55adf4a57b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55adf4a52355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55adf4ae8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55adf7ab7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55adf7ab7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55adf7ab7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55adf7ab7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55adf7ab7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55adf7ab7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55adf7ab7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55adf7ab7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55adf7ab7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55adf7ab7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55adf9d4cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55adf6a79b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55adf6a84be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55adf6830c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55adf6830c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55adf6831738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55adf6830874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55adf6830874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55adf6830874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55adfb13aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55adfb143928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55adfb12b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55adfb156112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7da45e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55adf4a50b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3915e6db28657cb1bd813a32140ed2f1c9296acf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5955 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 554859778 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fd38c2a810, 0x55fd38e1401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fd38e14020,0x55fd3acac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3915e6db28657cb1bd813a32140ed2f1c9296acf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7672 processed earlier; will process 3357 files now Step #5: ==214486== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fd2f71f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fd35d84898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fd35d675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fd35d674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fd2f725d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fd2f686b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fd2f681355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fd2f717c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fd326e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fd326e6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fd326e6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fd326e6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fd326e6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fd326e6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fd326e6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fd326e6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fd326e6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fd326e6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fd3497bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fd316a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fd316b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fd3145fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fd3145fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fd31460738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fd3145f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fd3145f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fd3145f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fd35d69abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fd35d72928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fd35d5a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fd35d85112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f018f689082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fd2f67fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-327b7e634110a9686f1a47bc8b5460d80f537af8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5956 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 555433064 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b15413c810, 0x55b15432601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b154326020,0x55b1561be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/327b7e634110a9686f1a47bc8b5460d80f537af8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7673 processed earlier; will process 3356 files now Step #5: ==214522== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b14ac319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b151296898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1512795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1512794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b14ac37d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b14ab98b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b14ab93355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b14ac29c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b14dbf8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b14dbf8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b14dbf8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b14dbf8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b14dbf8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b14dbf8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b14dbf8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b14dbf8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b14dbf8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b14dbf8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b14fe8df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b14cbbab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b14cbc5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b14c971c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b14c971c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b14c972738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b14c971874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b14c971874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b14c971874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b15127babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b151284928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b15126c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b151297112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f22ab91a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b14ab91b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4e6bc9c60c1d95bf9723b7d9b44ab0ee76538997 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5957 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 555989045 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563dd3e5c810, 0x563dd404601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563dd4046020,0x563dd5ede0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e6bc9c60c1d95bf9723b7d9b44ab0ee76538997' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7674 processed earlier; will process 3355 files now Step #5: ==214558== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563dca9519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563dd0fb6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563dd0f995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563dd0f994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563dca957d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563dca8b8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563dca8b3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563dca949c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563dcd918f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563dcd918f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563dcd918f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563dcd918f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563dcd918f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563dcd918f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563dcd918f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563dcd918f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563dcd918f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563dcd918f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563dcfbadf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563dcc8dab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563dcc8e5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563dcc691c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563dcc691c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563dcc692738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563dcc691874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563dcc691874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563dcc691874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563dd0f9babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563dd0fa4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563dd0f8c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563dd0fb7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe67a515082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563dca8b1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-52ae4ffc83bcc976d917285847a5a48018648340 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5958 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 556690651 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7af70c810, 0x55b7af8f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7af8f6020,0x55b7b178e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/52ae4ffc83bcc976d917285847a5a48018648340' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7675 processed earlier; will process 3354 files now Step #5: #1 pulse cov: 3529 ft: 3530 exec/s: 0 rss: 179Mb Step #5: ==214594== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b7a62019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b7ac866898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b7ac8495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b7ac8494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b7a6207d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b7a6168b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b7a6163355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b7a61f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b7a91c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b7a91c8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b7a91c8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b7a91c8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b7a91c8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b7a91c8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b7a91c8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b7a91c8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b7a91c8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b7a91c8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b7ab45df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b7a818ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b7a8195be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b7a7f41c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b7a7f41c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b7a7f42738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b7a7f41874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b7a7f41874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b7a7f41874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b7ac84babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b7ac854928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b7ac83c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b7ac867112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdbc716d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b7a6161b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6900ac3f6e94b43ad0f2968df12423d17103824d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5959 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 557342101 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56049ff58810, 0x5604a014201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604a0142020,0x5604a1fda0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6900ac3f6e94b43ad0f2968df12423d17103824d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7677 processed earlier; will process 3352 files now Step #5: ==214630== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560496a4d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56049d0b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56049d0955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56049d0954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560496a53d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5604969b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5604969af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560496a45c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560499a14f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560499a14f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560499a14f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560499a14f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560499a14f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560499a14f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560499a14f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560499a14f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560499a14f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560499a14f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56049bca9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5604989d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5604989e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56049878dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56049878dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56049878e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56049878d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56049878d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56049878d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56049d097abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56049d0a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56049d088699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56049d0b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fabece11082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5604969adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-30d800e293a27f9a5b59e5b5becbaf5c9d1ff67a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5960 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 558611288 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5643ab5fc810, 0x5643ab7e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5643ab7e6020,0x5643ad67e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/30d800e293a27f9a5b59e5b5becbaf5c9d1ff67a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7678 processed earlier; will process 3351 files now Step #5: ==214666== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643a20f19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5643a8756898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5643a87395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5643a87394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643a20f7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5643a2058b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5643a2053355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643a20e9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643a50b8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643a50b8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643a50b8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643a50b8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643a50b8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643a50b8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643a50b8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643a50b8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643a50b8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643a50b8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5643a734df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5643a407ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5643a4085be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643a3e31c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643a3e31c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643a3e32738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643a3e31874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643a3e31874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643a3e31874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5643a873babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5643a8744928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5643a872c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5643a8757112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1657bd1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5643a2051b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-00e298490feda4413be752219b90ed3113c36937 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5961 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 559159513 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5580d6138810, 0x5580d632201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5580d6322020,0x5580d81ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/00e298490feda4413be752219b90ed3113c36937' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7679 processed earlier; will process 3350 files now Step #5: ==214702== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5580ccc2d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5580d3292898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5580d32755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5580d32754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5580ccc33d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5580ccb94b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5580ccb8f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5580ccc25c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5580cfbf4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5580cfbf4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5580cfbf4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5580cfbf4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5580cfbf4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5580cfbf4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5580cfbf4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5580cfbf4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5580cfbf4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5580cfbf4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5580d1e89f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5580cebb6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5580cebc1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580ce96dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580ce96dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580ce96e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580ce96d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580ce96d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580ce96d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5580d3277abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5580d3280928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5580d3268699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5580d3293112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbfa17c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5580ccb8db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb52136aea680c17ac7d8dc0fcf8237e2eb68221 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5962 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 560520994 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563a5911e810, 0x563a5930801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563a59308020,0x563a5b1a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb52136aea680c17ac7d8dc0fcf8237e2eb68221' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7680 processed earlier; will process 3349 files now Step #5: #1 pulse cov: 4042 ft: 4043 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4431 ft: 4961 exec/s: 0 rss: 179Mb Step #5: ==214738== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563a4fc139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563a56278898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563a5625b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563a5625b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563a4fc19d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563a4fb7ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563a4fb75355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563a4fc0bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563a52bdaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563a52bdaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563a52bdaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563a52bdaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563a52bdaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563a52bdaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563a52bdaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563a52bdaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563a52bdaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563a52bdaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563a54e6ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563a51b9cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563a51ba7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563a51953c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563a51953c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563a51954738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563a51953874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563a51953874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563a51953874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563a5625dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563a56266928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563a5624e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563a56279112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f82f2d12082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563a4fb73b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-08096af98a8809ef790c967fab46371115982339 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5963 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 561277446 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5639a7ece810, 0x5639a80b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5639a80b8020,0x5639a9f500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08096af98a8809ef790c967fab46371115982339' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7683 processed earlier; will process 3346 files now Step #5: ==214774== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56399e9c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5639a5028898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5639a500b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5639a500b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56399e9c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56399e92ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56399e925355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56399e9bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5639a198af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5639a198af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5639a198af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5639a198af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5639a198af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5639a198af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5639a198af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5639a198af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5639a198af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5639a198af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5639a3c1ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5639a094cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5639a0957be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5639a0703c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5639a0703c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5639a0704738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5639a0703874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5639a0703874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5639a0703874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5639a500dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5639a5016928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5639a4ffe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5639a5029112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5cc7e7e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56399e923b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-510f0e0643b390e824f1d38a7a9236f070887b0d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5964 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 561819630 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55876c935810, 0x55876cb1f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55876cb1f020,0x55876e9b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/510f0e0643b390e824f1d38a7a9236f070887b0d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7684 processed earlier; will process 3345 files now Step #5: ==214810== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55876342a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558769a8f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558769a725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558769a724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558763430d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558763391b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55876338c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558763422c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5587663f1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5587663f1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5587663f1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5587663f1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5587663f1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5587663f1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5587663f1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5587663f1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5587663f1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5587663f1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558768686f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5587653b3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5587653bebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55876516ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55876516ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55876516b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55876516a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55876516a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55876516a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558769a74abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558769a7d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558769a65699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558769a90112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3ccfba6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55876338ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-84b89f0d20cb979128e972caaead746c5c1962f7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5965 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 562426500 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55568f5e3810, 0x55568f7cd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55568f7cd020,0x5556916650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/84b89f0d20cb979128e972caaead746c5c1962f7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7685 processed earlier; will process 3344 files now Step #5: ==214846== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5556860d89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55568c73d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55568c7205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55568c7204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5556860ded42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55568603fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55568603a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5556860d0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55568909ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55568909ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55568909ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55568909ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55568909ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55568909ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55568909ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55568909ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55568909ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55568909ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55568b334f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555688061b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55568806cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555687e18c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555687e18c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555687e19738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555687e18874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555687e18874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555687e18874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55568c722abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55568c72b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55568c713699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55568c73e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e57c66082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555686038b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8fe1cd1ed9b4ad0575114610544d944d5f0eb6cd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5966 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 563762714 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5648d6557810, 0x5648d674101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5648d6741020,0x5648d85d90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8fe1cd1ed9b4ad0575114610544d944d5f0eb6cd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7686 processed earlier; will process 3343 files now Step #5: ==214882== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5648cd04c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5648d36b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5648d36945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5648d36944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5648cd052d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5648ccfb3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5648ccfae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5648cd044c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5648d0013f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5648d0013f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5648d0013f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5648d0013f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5648d0013f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5648d0013f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5648d0013f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5648d0013f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5648d0013f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5648d0013f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5648d22a8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5648cefd5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5648cefe0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5648ced8cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5648ced8cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5648ced8d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5648ced8c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5648ced8c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5648ced8c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5648d3696abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5648d369f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5648d3687699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5648d36b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8bd57f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5648ccfacb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-658fce8d9f09098c5bf478e32c067a270e3d4b3f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5967 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 564543408 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aa7ad12810, 0x55aa7aefc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aa7aefc020,0x55aa7cd940e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/658fce8d9f09098c5bf478e32c067a270e3d4b3f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7687 processed earlier; will process 3342 files now Step #5: ==214918== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aa718079c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aa77e6c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aa77e4f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aa77e4f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aa7180dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aa7176eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aa71769355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aa717ffc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aa747cef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aa747cef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aa747cef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aa747cef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aa747cef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aa747cef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aa747cef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aa747cef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aa747cef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aa747cef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aa76a63f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aa73790b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aa7379bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aa73547c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aa73547c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aa73548738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aa73547874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aa73547874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aa73547874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aa77e51abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aa77e5a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aa77e42699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aa77e6d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c8ac08082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aa71767b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ad4bce9aed7b3035883ad8b6f098731275ee87a5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5968 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 565109487 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5635fdeb8810, 0x5635fe0a201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5635fe0a2020,0x5635fff3a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad4bce9aed7b3035883ad8b6f098731275ee87a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7688 processed earlier; will process 3341 files now Step #5: ==214954== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5635f49ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5635fb012898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5635faff55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5635faff54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5635f49b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5635f4914b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5635f490f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5635f49a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5635f7974f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5635f7974f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5635f7974f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5635f7974f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5635f7974f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5635f7974f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5635f7974f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5635f7974f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5635f7974f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5635f7974f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5635f9c09f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5635f6936b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5635f6941be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5635f66edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5635f66edc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5635f66ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5635f66ed874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5635f66ed874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5635f66ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5635faff7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5635fb000928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5635fafe8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5635fb013112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2192fd0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5635f490db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8ff884f1296b4833ac99c0c80c1efebe8edde7c1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5969 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 565720463 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc7d997810, 0x55fc7db8101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc7db81020,0x55fc7fa190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ff884f1296b4833ac99c0c80c1efebe8edde7c1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7689 processed earlier; will process 3340 files now Step #5: #1 pulse cov: 4084 ft: 4085 exec/s: 0 rss: 180Mb Step #5: ==214990== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fc7448c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc7aaf1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc7aad45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc7aad44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc74492d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc743f3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc743ee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc74484c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc77453f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc77453f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc77453f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc77453f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc77453f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc77453f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc77453f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc77453f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc77453f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc77453f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc796e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc76415b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc76420be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc761ccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc761ccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc761cd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc761cc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc761cc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc761cc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc7aad6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc7aadf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc7aac7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc7aaf2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faba780d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc743ecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8035b57bf56442f65615dea603de20be4000b0b5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5970 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 566440584 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5624b6029810, 0x5624b621301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5624b6213020,0x5624b80ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8035b57bf56442f65615dea603de20be4000b0b5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7691 processed earlier; will process 3338 files now Step #5: ==215026== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5624acb1e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5624b3183898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5624b31665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5624b31664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5624acb24d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5624aca85b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5624aca80355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5624acb16c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5624afae5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5624afae5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5624afae5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5624afae5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5624afae5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5624afae5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5624afae5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5624afae5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5624afae5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5624afae5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5624b1d7af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5624aeaa7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5624aeab2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5624ae85ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5624ae85ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5624ae85f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5624ae85e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5624ae85e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5624ae85e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5624b3168abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5624b3171928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5624b3159699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5624b3184112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12b0da1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5624aca7eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b2be428a5e7fba369ab0626afb6d009ab17ff607 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5971 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 567151596 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56212aafd810, 0x56212ace701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56212ace7020,0x56212cb7f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b2be428a5e7fba369ab0626afb6d009ab17ff607' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7692 processed earlier; will process 3337 files now Step #5: #1 pulse cov: 4082 ft: 4083 exec/s: 0 rss: 179Mb Step #5: ==215062== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5621215f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562127c57898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562127c3a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562127c3a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5621215f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562121559b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562121554355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5621215eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5621245b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5621245b9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5621245b9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5621245b9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5621245b9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5621245b9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5621245b9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5621245b9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5621245b9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5621245b9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56212684ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56212357bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562123586be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562123332c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562123332c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562123333738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562123332874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562123332874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562123332874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562127c3cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562127c45928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562127c2d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562127c58112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd43b483082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562121552b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4d0512ca21a96d173101307cc7b6310978845865 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5972 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 568550434 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b4ee64810, 0x557b4f04e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b4f04e020,0x557b50ee60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4d0512ca21a96d173101307cc7b6310978845865' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7694 processed earlier; will process 3335 files now Step #5: #1 pulse cov: 4133 ft: 4134 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 4712 ft: 5165 exec/s: 0 rss: 182Mb Step #5: ==215098== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557b459599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b4bfbe898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b4bfa15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b4bfa14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b4595fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b458c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b458bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b45951c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b48920f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b48920f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b48920f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b48920f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b48920f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b48920f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b48920f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b48920f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b48920f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b48920f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b4abb5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b478e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b478edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b47699c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b47699c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b4769a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b47699874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b47699874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b47699874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b4bfa3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b4bfac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b4bf94699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b4bfbf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3ca606082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b458b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-51f4d13c679cdc5e71d8a67af60bc91a331b21dd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5973 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 569204420 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b6f26cc810, 0x55b6f28b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b6f28b6020,0x55b6f474e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/51f4d13c679cdc5e71d8a67af60bc91a331b21dd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7697 processed earlier; will process 3332 files now Step #5: ==215134== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b6e91c19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b6ef826898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b6ef8095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b6ef8094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6e91c7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6e9128b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6e9123355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6e91b9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b6ec188f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b6ec188f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b6ec188f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b6ec188f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b6ec188f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b6ec188f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b6ec188f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b6ec188f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b6ec188f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b6ec188f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b6ee41df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6eb14ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6eb155be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6eaf01c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6eaf01c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6eaf02738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6eaf01874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6eaf01874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6eaf01874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b6ef80babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b6ef814928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b6ef7fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b6ef827112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff6c667e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6e9121b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1d9d7b7e39b029d05f39591da7acca1fe85387f7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5974 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 569752290 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558e6f1de810, 0x558e6f3c801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558e6f3c8020,0x558e712600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1d9d7b7e39b029d05f39591da7acca1fe85387f7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7698 processed earlier; will process 3331 files now Step #5: #1 pulse cov: 4005 ft: 4006 exec/s: 0 rss: 179Mb Step #5: ==215170== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558e65cd39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558e6c338898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558e6c31b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558e6c31b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558e65cd9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558e65c3ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558e65c35355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558e65ccbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558e68c9af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558e68c9af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558e68c9af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558e68c9af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558e68c9af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558e68c9af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558e68c9af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558e68c9af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558e68c9af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558e68c9af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558e6af2ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558e67c5cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558e67c67be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558e67a13c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558e67a13c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558e67a14738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558e67a13874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558e67a13874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558e67a13874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558e6c31dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558e6c326928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558e6c30e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558e6c339112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd97a769082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558e65c33b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0fb92ab8ae3a5edc71561967bd8de7be96cab419 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5975 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 570334542 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db3399e810, 0x55db33b8801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db33b88020,0x55db35a200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0fb92ab8ae3a5edc71561967bd8de7be96cab419' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7700 processed earlier; will process 3329 files now Step #5: ==215206== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db2a4939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db30af8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db30adb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db30adb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db2a499d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db2a3fab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db2a3f5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db2a48bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db2d45af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db2d45af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db2d45af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db2d45af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db2d45af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db2d45af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db2d45af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db2d45af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db2d45af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db2d45af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db2f6eff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db2c41cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db2c427be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db2c1d3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db2c1d3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db2c1d4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db2c1d3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db2c1d3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db2c1d3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db30addabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db30ae6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db30ace699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db30af9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fee2459f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db2a3f3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-673cf4ce77eafd8f292dba9890889f6da1f6fa9a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5976 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 571694723 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c74804e810, 0x55c74823801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c748238020,0x55c74a0d00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/673cf4ce77eafd8f292dba9890889f6da1f6fa9a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7701 processed earlier; will process 3328 files now Step #5: ==215242== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c73eb439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7451a8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c74518b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c74518b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c73eb49d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c73eaaab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c73eaa5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c73eb3bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c741b0af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c741b0af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c741b0af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c741b0af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c741b0af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c741b0af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c741b0af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c741b0af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c741b0af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c741b0af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c743d9ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c740accb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c740ad7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c740883c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c740883c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c740884738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c740883874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c740883874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c740883874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c74518dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c745196928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c74517e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7451a9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6c99a80082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c73eaa3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1f7f47f1e7188e9048430de5340446f7c33186b6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5977 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 572296952 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5585ce452810, 0x5585ce63c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5585ce63c020,0x5585d04d40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f7f47f1e7188e9048430de5340446f7c33186b6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7702 processed earlier; will process 3327 files now Step #5: ==215278== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5585c4f479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5585cb5ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5585cb58f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5585cb58f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5585c4f4dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5585c4eaeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5585c4ea9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5585c4f3fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5585c7f0ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5585c7f0ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5585c7f0ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5585c7f0ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5585c7f0ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5585c7f0ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5585c7f0ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5585c7f0ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5585c7f0ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5585c7f0ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5585ca1a3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5585c6ed0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5585c6edbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5585c6c87c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5585c6c87c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5585c6c88738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5585c6c87874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5585c6c87874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5585c6c87874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5585cb591abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5585cb59a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5585cb582699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5585cb5ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdfd2f68082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5585c4ea7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-16f47e1c0e3e72a27a939f5e4a2e9ce9a3f9a95f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5978 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 572896909 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d59b686810, 0x55d59b87001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d59b870020,0x55d59d7080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16f47e1c0e3e72a27a939f5e4a2e9ce9a3f9a95f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7703 processed earlier; will process 3326 files now Step #5: ==215314== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d59217b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d5987e0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d5987c35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d5987c34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d592181d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d5920e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d5920dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d592173c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d595142f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d595142f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d595142f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d595142f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d595142f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d595142f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d595142f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d595142f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d595142f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d595142f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d5973d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d594104b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d59410fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d593ebbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d593ebbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d593ebc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d593ebb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d593ebb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d593ebb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d5987c5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d5987ce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d5987b6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d5987e1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f50872be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d5920dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-97ac340e720a31ec09f495636290b219195c1816 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5979 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 573494745 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f3a41e7810, 0x55f3a43d101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f3a43d1020,0x55f3a62690e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/97ac340e720a31ec09f495636290b219195c1816' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7704 processed earlier; will process 3325 files now Step #5: #1 pulse cov: 4192 ft: 4193 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4306 ft: 4973 exec/s: 0 rss: 178Mb Step #5: ==215350== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f39acdc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f3a1341898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f3a13245dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f3a13244fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f39ace2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f39ac43b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f39ac3e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f39acd4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f39dca3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f39dca3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f39dca3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f39dca3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f39dca3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f39dca3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f39dca3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f39dca3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f39dca3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f39dca3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f39ff38f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f39cc65b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f39cc70be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f39ca1cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f39ca1cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f39ca1d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f39ca1c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f39ca1c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f39ca1c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f3a1326abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f3a132f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f3a1317699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f3a1342112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1be8ef8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f39ac3cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-462511009f9a2b93a56f396bbcadd3de08ee2681 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5980 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 574973735 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564b4ec0b810, 0x564b4edf501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564b4edf5020,0x564b50c8d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/462511009f9a2b93a56f396bbcadd3de08ee2681' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7708 processed earlier; will process 3321 files now Step #5: #1 pulse cov: 3943 ft: 3944 exec/s: 0 rss: 181Mb Step #5: ==215386== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564b457009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564b4bd65898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564b4bd485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564b4bd484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564b45706d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564b45667b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564b45662355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564b456f8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564b486c7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564b486c7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564b486c7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564b486c7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564b486c7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564b486c7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564b486c7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564b486c7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564b486c7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564b486c7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564b4a95cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564b47689b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564b47694be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564b47440c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564b47440c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564b47441738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564b47440874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564b47440874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564b47440874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564b4bd4aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564b4bd53928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564b4bd3b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564b4bd66112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4af91ae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564b45660b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-03763f4069a1aa25b26e2b1fc0bdc3e347721fd5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5981 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 576258639 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a1ebf7810, 0x555a1ede101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a1ede1020,0x555a20c790e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03763f4069a1aa25b26e2b1fc0bdc3e347721fd5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7710 processed earlier; will process 3319 files now Step #5: ==215422== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555a156ec9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a1bd51898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a1bd345dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a1bd344fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a156f2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a15653b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a1564e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a156e4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a186b3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a186b3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a186b3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a186b3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a186b3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a186b3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a186b3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a186b3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a186b3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a186b3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a1a948f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a17675b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a17680be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a1742cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a1742cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a1742d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a1742c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a1742c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a1742c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a1bd36abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a1bd3f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a1bd27699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a1bd52112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc3a7365082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a1564cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6c5fac4d8ead0c405f2b8a913bf0218acbd656e6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5982 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 577624815 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dad77e9810, 0x55dad79d301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dad79d3020,0x55dad986b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6c5fac4d8ead0c405f2b8a913bf0218acbd656e6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7711 processed earlier; will process 3318 files now Step #5: ==215458== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dace2de9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dad4943898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dad49265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dad49264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dace2e4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dace245b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dace240355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dace2d6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dad12a5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dad12a5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dad12a5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dad12a5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dad12a5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dad12a5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dad12a5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dad12a5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dad12a5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dad12a5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dad353af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dad0267b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dad0272be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dad001ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dad001ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dad001f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dad001e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dad001e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dad001e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dad4928abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dad4931928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dad4919699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dad4944112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe22f80f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dace23eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-85e17f511329ea9aa8d94d6d28364235286253c7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5983 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 579045838 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f3ff02f810, 0x55f3ff21901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f3ff219020,0x55f4010b10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/85e17f511329ea9aa8d94d6d28364235286253c7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7712 processed earlier; will process 3317 files now Step #5: ==215494== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f3f5b249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f3fc189898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f3fc16c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f3fc16c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f3f5b2ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f3f5a8bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f3f5a86355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f3f5b1cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f3f8aebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f3f8aebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f3f8aebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f3f8aebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f3f8aebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f3f8aebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f3f8aebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f3f8aebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f3f8aebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f3f8aebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f3fad80f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f3f7aadb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f3f7ab8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f3f7864c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f3f7864c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f3f7865738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f3f7864874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f3f7864874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f3f7864874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f3fc16eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f3fc177928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f3fc15f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f3fc18a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67addce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f3f5a84b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8bfaf807f5fd332659f2267f083c6c8b6044241c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5984 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 580319581 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d77afce810, 0x55d77b1b801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d77b1b8020,0x55d77d0500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8bfaf807f5fd332659f2267f083c6c8b6044241c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7713 processed earlier; will process 3316 files now Step #5: ==215530== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d771ac39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d778128898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d77810b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d77810b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d771ac9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d771a2ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d771a25355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d771abbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d774a8af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d774a8af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d774a8af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d774a8af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d774a8af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d774a8af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d774a8af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d774a8af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d774a8af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d774a8af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d776d1ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d773a4cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d773a57be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d773803c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d773803c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d773804738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d773803874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d773803874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d773803874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d77810dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d778116928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d7780fe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d778129112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc7ee0d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d771a23b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0eea4168bdcda3374f32436d0d817c40e364116e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5985 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 580889405 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a7806f2810, 0x55a7808dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a7808dc020,0x55a7827740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0eea4168bdcda3374f32436d0d817c40e364116e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7714 processed earlier; will process 3315 files now Step #5: ==215566== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a7771e79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a77d84c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a77d82f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a77d82f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a7771edd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a77714eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a777149355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a7771dfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a77a1aef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a77a1aef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a77a1aef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a77a1aef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a77a1aef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a77a1aef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a77a1aef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a77a1aef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a77a1aef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a77a1aef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a77c443f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a779170b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a77917bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a778f27c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a778f27c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a778f28738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a778f27874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a778f27874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a778f27874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a77d831abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a77d83a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a77d822699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a77d84d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f69d216a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a777147b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7d8cbe90c32c0c2500c043501e2978aaef6ce3d7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5986 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 581473271 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f2360e9810, 0x55f2362d301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f2362d3020,0x55f23816b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d8cbe90c32c0c2500c043501e2978aaef6ce3d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7715 processed earlier; will process 3314 files now Step #5: #1 pulse cov: 3963 ft: 3964 exec/s: 0 rss: 179Mb Step #5: ==215602== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f22cbde9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f233243898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f2332265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f2332264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f22cbe4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f22cb45b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f22cb40355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f22cbd6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f22fba5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f22fba5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f22fba5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f22fba5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f22fba5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f22fba5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f22fba5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f22fba5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f22fba5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f22fba5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f231e3af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f22eb67b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f22eb72be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f22e91ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f22e91ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f22e91f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f22e91e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f22e91e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f22e91e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f233228abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f233231928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f233219699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f233244112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff9833c5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f22cb3eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4f921d8e970df970121796d1720621ee326c87ef Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5987 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 582071779 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563976ccb810, 0x563976eb501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563976eb5020,0x563978d4d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4f921d8e970df970121796d1720621ee326c87ef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7717 processed earlier; will process 3312 files now Step #5: #1 pulse cov: 3802 ft: 3803 exec/s: 0 rss: 179Mb Step #5: ==215638== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56396d7c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563973e25898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563973e085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563973e084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56396d7c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56396d727b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56396d722355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56396d7b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563970787f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563970787f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563970787f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563970787f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563970787f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563970787f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563970787f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563970787f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563970787f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563970787f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563972a1cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56396f749b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56396f754be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56396f500c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56396f500c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56396f501738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56396f500874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56396f500874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56396f500874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563973e0aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563973e13928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563973dfb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563973e26112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f22523b2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56396d720b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7aad15ef2e381c3fb0303d0dc25414b1c04f3b5d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5988 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 582721967 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563eb9d04810, 0x563eb9eee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563eb9eee020,0x563ebbd860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7aad15ef2e381c3fb0303d0dc25414b1c04f3b5d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7719 processed earlier; will process 3310 files now Step #5: ==215674== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563eb07f99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563eb6e5e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563eb6e415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563eb6e414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563eb07ffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563eb0760b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563eb075b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563eb07f1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563eb37c0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563eb37c0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563eb37c0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563eb37c0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563eb37c0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563eb37c0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563eb37c0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563eb37c0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563eb37c0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563eb37c0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563eb5a55f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563eb2782b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563eb278dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563eb2539c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563eb2539c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563eb253a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563eb2539874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563eb2539874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563eb2539874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563eb6e43abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563eb6e4c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563eb6e34699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563eb6e5f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd42a2e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563eb0759b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6c0fa720231c306af7e310b8cd9a4c3fd6ef87fe Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5989 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 583280036 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55943a4e6810, 0x55943a6d001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55943a6d0020,0x55943c5680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6c0fa720231c306af7e310b8cd9a4c3fd6ef87fe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7720 processed earlier; will process 3309 files now Step #5: ==215710== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559430fdb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559437640898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5594376235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5594376234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559430fe1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559430f42b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559430f3d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559430fd3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559433fa2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559433fa2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559433fa2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559433fa2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559433fa2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559433fa2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559433fa2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559433fa2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559433fa2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559433fa2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559436237f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559432f64b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559432f6fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559432d1bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559432d1bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559432d1c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559432d1b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559432d1b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559432d1b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559437625abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55943762e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559437616699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559437641112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf2047c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559430f3bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf769e85c01c0e66ef4473e2c1e1d5a689272bad Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5990 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 583869131 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559d773e0810, 0x559d775ca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559d775ca020,0x559d794620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf769e85c01c0e66ef4473e2c1e1d5a689272bad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7721 processed earlier; will process 3308 files now Step #5: ==215746== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559d6ded59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559d7453a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559d7451d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559d7451d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559d6dedbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559d6de3cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559d6de37355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559d6decdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559d70e9cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559d70e9cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559d70e9cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559d70e9cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559d70e9cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559d70e9cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559d70e9cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559d70e9cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559d70e9cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559d70e9cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559d73131f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559d6fe5eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559d6fe69be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559d6fc15c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559d6fc15c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559d6fc16738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559d6fc15874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559d6fc15874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559d6fc15874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559d7451fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559d74528928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559d74510699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559d7453b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f02a78fd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559d6de35b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6a15c88fa6861790849b35e9a75f246539e70fb1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5991 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 584469986 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563efeae7810, 0x563efecd101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563efecd1020,0x563f00b690e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a15c88fa6861790849b35e9a75f246539e70fb1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7722 processed earlier; will process 3307 files now Step #5: ==215782== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563ef55dc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563efbc41898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563efbc245dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563efbc244fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563ef55e2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563ef5543b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563ef553e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563ef55d4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563ef85a3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563ef85a3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563ef85a3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563ef85a3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563ef85a3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563ef85a3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563ef85a3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563ef85a3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563ef85a3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563ef85a3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563efa838f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563ef7565b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563ef7570be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563ef731cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563ef731cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563ef731d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563ef731c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563ef731c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563ef731c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563efbc26abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563efbc2f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563efbc17699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563efbc42112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb56a3e2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563ef553cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-87d2c4402a93af29d9f9a4197d44cd2b65590c24 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5992 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 585071186 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55be71eb9810, 0x55be720a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55be720a3020,0x55be73f3b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87d2c4402a93af29d9f9a4197d44cd2b65590c24' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7723 processed earlier; will process 3306 files now Step #5: ==215818== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55be689ae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55be6f013898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55be6eff65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55be6eff64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55be689b4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55be68915b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55be68910355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55be689a6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55be6b975f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55be6b975f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55be6b975f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55be6b975f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55be6b975f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55be6b975f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55be6b975f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55be6b975f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55be6b975f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55be6b975f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55be6dc0af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55be6a937b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55be6a942be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55be6a6eec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55be6a6eec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55be6a6ef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55be6a6ee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55be6a6ee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55be6a6ee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55be6eff8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55be6f001928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55be6efe9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55be6f014112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9a1bb2e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55be6890eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ce64cfd26933c1217e49d0489f4f3f0473b6481f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5993 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 585624008 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5614714b3810, 0x56147169d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56147169d020,0x5614735350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce64cfd26933c1217e49d0489f4f3f0473b6481f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7724 processed earlier; will process 3305 files now Step #5: ==215854== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561467fa89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56146e60d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56146e5f05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56146e5f04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561467faed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561467f0fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561467f0a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561467fa0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56146af6ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56146af6ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56146af6ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56146af6ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56146af6ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56146af6ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56146af6ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56146af6ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56146af6ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56146af6ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56146d204f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561469f31b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561469f3cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561469ce8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561469ce8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561469ce9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561469ce8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561469ce8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561469ce8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56146e5f2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56146e5fb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56146e5e3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56146e60e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc4be5da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561467f08b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fa366734413a5875d09c3f9d9e8bd3f76861af0b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5994 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 586220566 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ddf3d85810, 0x55ddf3f6f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ddf3f6f020,0x55ddf5e070e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fa366734413a5875d09c3f9d9e8bd3f76861af0b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7725 processed earlier; will process 3304 files now Step #5: ==215890== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ddea87a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ddf0edf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ddf0ec25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ddf0ec24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ddea880d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ddea7e1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ddea7dc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ddea872c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dded841f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dded841f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dded841f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dded841f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dded841f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dded841f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dded841f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dded841f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dded841f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dded841f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ddefad6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ddec803b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ddec80ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ddec5bac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ddec5bac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ddec5bb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ddec5ba874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ddec5ba874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ddec5ba874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ddf0ec4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ddf0ecd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ddf0eb5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ddf0ee0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e7e490082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ddea7dab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-181dae9a7a6c72c1f9508743b5f55b564aa6f788 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5995 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 586765954 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557816776810, 0x55781696001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557816960020,0x5578187f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/181dae9a7a6c72c1f9508743b5f55b564aa6f788' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7726 processed earlier; will process 3303 files now Step #5: ==215926== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55780d26b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5578138d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5578138b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5578138b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55780d271d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55780d1d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55780d1cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55780d263c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557810232f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557810232f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557810232f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557810232f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557810232f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557810232f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557810232f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557810232f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557810232f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557810232f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5578124c7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55780f1f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55780f1ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55780efabc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55780efabc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55780efac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55780efab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55780efab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55780efab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5578138b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5578138be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5578138a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5578138d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b2e8d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55780d1cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d548ddeb68232b67e66f3c4787155952df939cc7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5996 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 587477538 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c494558810, 0x55c49474201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c494742020,0x55c4965da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d548ddeb68232b67e66f3c4787155952df939cc7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7727 processed earlier; will process 3302 files now Step #5: ==215962== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c48b04d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c4916b2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c4916955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c4916954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c48b053d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c48afb4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c48afaf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c48b045c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c48e014f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c48e014f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c48e014f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c48e014f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c48e014f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c48e014f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c48e014f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c48e014f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c48e014f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c48e014f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c4902a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c48cfd6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c48cfe1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c48cd8dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c48cd8dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c48cd8e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c48cd8d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c48cd8d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c48cd8d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c491697abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c4916a0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c491688699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c4916b3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdab6b74082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c48afadb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7125e3c4d0a81f935a8fbb575885e34845d0a050 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5997 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 588195462 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560106418810, 0x56010660201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560106602020,0x56010849a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7125e3c4d0a81f935a8fbb575885e34845d0a050' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7728 processed earlier; will process 3301 files now Step #5: #1 pulse cov: 11756 ft: 11757 exec/s: 0 rss: 199Mb Step #5: ==215998== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5600fcf0d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560103572898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601035555dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601035554fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5600fcf13d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5600fce74b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5600fce6f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5600fcf05c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5600ffed4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5600ffed4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5600ffed4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5600ffed4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5600ffed4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5600ffed4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5600ffed4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5600ffed4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5600ffed4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5600ffed4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560102169f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5600fee96b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5600feea1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5600fec4dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5600fec4dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5600fec4e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5600fec4d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5600fec4d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5600fec4d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560103557abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560103560928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560103548699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560103573112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc9904cb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5600fce6db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-492e2f6ef9ab0b8fdb3475a374264323e563d422 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5998 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 588825154 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d5f223810, 0x563d5f40d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d5f40d020,0x563d612a50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/492e2f6ef9ab0b8fdb3475a374264323e563d422' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7730 processed earlier; will process 3299 files now Step #5: #1 pulse cov: 3909 ft: 3910 exec/s: 0 rss: 179Mb Step #5: ==216034== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563d55d189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d5c37d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d5c3605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d5c3604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d55d1ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d55c7fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d55c7a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d55d10c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d58cdff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d58cdff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d58cdff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d58cdff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d58cdff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d58cdff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d58cdff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d58cdff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d58cdff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d58cdff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d5af74f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d57ca1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d57cacbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d57a58c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d57a58c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d57a59738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d57a58874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d57a58874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d57a58874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d5c362abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d5c36b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d5c353699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d5c37e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f34cfe082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d55c78b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b93586b9b953eb16241a40e169f806a106116313 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5999 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 589435845 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558c1b4d9810, 0x558c1b6c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558c1b6c3020,0x558c1d55b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b93586b9b953eb16241a40e169f806a106116313' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7732 processed earlier; will process 3297 files now Step #5: ==216070== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558c11fce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558c18633898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558c186165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558c186164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558c11fd4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558c11f35b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558c11f30355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558c11fc6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558c14f95f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558c14f95f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558c14f95f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558c14f95f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558c14f95f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558c14f95f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558c14f95f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558c14f95f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558c14f95f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558c14f95f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558c1722af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558c13f57b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558c13f62be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558c13d0ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558c13d0ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558c13d0f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558c13d0e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558c13d0e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558c13d0e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558c18618abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558c18621928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558c18609699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558c18634112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a623c4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558c11f2eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cc33ed9b1af06f8a345c7bed502f2310db751e58 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6000 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 590009416 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561aba65f810, 0x561aba84901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561aba849020,0x561abc6e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cc33ed9b1af06f8a345c7bed502f2310db751e58' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7733 processed earlier; will process 3296 files now Step #5: ==216106== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561ab11549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561ab77b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561ab779c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561ab779c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561ab115ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561ab10bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561ab10b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561ab114cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561ab411bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561ab411bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561ab411bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561ab411bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561ab411bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561ab411bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561ab411bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561ab411bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561ab411bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561ab411bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561ab63b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561ab30ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561ab30e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561ab2e94c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561ab2e94c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561ab2e95738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561ab2e94874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561ab2e94874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561ab2e94874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561ab779eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561ab77a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561ab778f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561ab77ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2960d98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561ab10b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-998ec64b92090792c94fa3cd76ed6b988c8b0dfb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6001 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 590720369 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5614a02af810, 0x5614a049901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5614a0499020,0x5614a23310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/998ec64b92090792c94fa3cd76ed6b988c8b0dfb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7734 processed earlier; will process 3295 files now Step #5: ==216142== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561496da49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56149d409898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56149d3ec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56149d3ec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561496daad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561496d0bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561496d06355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561496d9cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561499d6bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561499d6bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561499d6bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561499d6bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561499d6bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561499d6bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561499d6bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561499d6bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561499d6bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561499d6bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56149c000f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561498d2db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561498d38be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561498ae4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561498ae4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561498ae5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561498ae4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561498ae4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561498ae4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56149d3eeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56149d3f7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56149d3df699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56149d40a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e02a63082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561496d04b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6a976786d0045dcf75d0b96838a3fa19684e5614 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6002 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 591328958 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5568dd520810, 0x5568dd70a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5568dd70a020,0x5568df5a20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a976786d0045dcf75d0b96838a3fa19684e5614' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7735 processed earlier; will process 3294 files now Step #5: #1 pulse cov: 3752 ft: 3753 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 3982 ft: 4540 exec/s: 0 rss: 178Mb Step #5: ==216178== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5568d40159c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5568da67a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5568da65d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5568da65d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5568d401bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5568d3f7cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5568d3f77355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5568d400dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5568d6fdcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5568d6fdcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5568d6fdcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5568d6fdcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5568d6fdcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5568d6fdcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5568d6fdcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5568d6fdcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5568d6fdcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5568d6fdcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5568d9271f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5568d5f9eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5568d5fa9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5568d5d55c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5568d5d55c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5568d5d56738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5568d5d55874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5568d5d55874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5568d5d55874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5568da65fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5568da668928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5568da650699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5568da67b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3978c7a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5568d3f75b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3255068b0a09ec8dd75fedf9272bbf8e28fda166 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6003 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 591933836 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5556d1dfd810, 0x5556d1fe701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5556d1fe7020,0x5556d3e7f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3255068b0a09ec8dd75fedf9272bbf8e28fda166' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7738 processed earlier; will process 3291 files now Step #5: #1 pulse cov: 4069 ft: 4070 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4422 ft: 4843 exec/s: 0 rss: 181Mb Step #5: ==216214== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5556c88f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5556cef57898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556cef3a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556cef3a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5556c88f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5556c8859b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5556c8854355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5556c88eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5556cb8b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5556cb8b9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5556cb8b9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5556cb8b9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5556cb8b9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5556cb8b9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5556cb8b9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5556cb8b9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5556cb8b9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5556cb8b9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5556cdb4ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5556ca87bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5556ca886be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5556ca632c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5556ca632c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5556ca633738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5556ca632874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5556ca632874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5556ca632874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5556cef3cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5556cef45928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5556cef2d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5556cef58112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f529bded082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5556c8852b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cfe1c77eda26d018ed5079bd4bfc059ad15b7446 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6004 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 592557676 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555cfffbc810, 0x555d001a601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555d001a6020,0x555d0203e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cfe1c77eda26d018ed5079bd4bfc059ad15b7446' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7741 processed earlier; will process 3288 files now Step #5: ==216250== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555cf6ab19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555cfd116898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555cfd0f95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555cfd0f94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555cf6ab7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555cf6a18b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555cf6a13355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555cf6aa9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555cf9a78f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555cf9a78f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555cf9a78f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555cf9a78f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555cf9a78f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555cf9a78f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555cf9a78f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555cf9a78f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555cf9a78f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555cf9a78f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555cfbd0df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555cf8a3ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555cf8a45be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555cf87f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555cf87f1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555cf87f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555cf87f1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555cf87f1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555cf87f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555cfd0fbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555cfd104928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555cfd0ec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555cfd117112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1359aaa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555cf6a11b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-231941f23b580d71f231d3abce4df27a75744474 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6005 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 593932218 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563e05cb6810, 0x563e05ea001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563e05ea0020,0x563e07d380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/231941f23b580d71f231d3abce4df27a75744474' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7742 processed earlier; will process 3287 files now Step #5: #1 pulse cov: 4122 ft: 4123 exec/s: 0 rss: 180Mb Step #5: ==216286== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563dfc7ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563e02e10898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563e02df35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563e02df34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563dfc7b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563dfc712b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563dfc70d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563dfc7a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563dff772f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563dff772f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563dff772f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563dff772f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563dff772f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563dff772f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563dff772f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563dff772f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563dff772f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563dff772f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563e01a07f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563dfe734b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563dfe73fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563dfe4ebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563dfe4ebc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563dfe4ec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563dfe4eb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563dfe4eb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563dfe4eb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563e02df5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563e02dfe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563e02de6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563e02e11112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcfeb61c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563dfc70bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e21e9dde1b5bc9030ea02983cb6a18c2dcf7272 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6006 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 594515259 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ad8b05810, 0x561ad8cef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ad8cef020,0x561adab870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e21e9dde1b5bc9030ea02983cb6a18c2dcf7272' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7744 processed earlier; will process 3285 files now Step #5: ==216322== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561acf5fa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561ad5c5f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561ad5c425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561ad5c424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561acf600d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561acf561b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561acf55c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561acf5f2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561ad25c1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561ad25c1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561ad25c1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561ad25c1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561ad25c1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561ad25c1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561ad25c1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561ad25c1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561ad25c1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561ad25c1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561ad4856f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561ad1583b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561ad158ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561ad133ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561ad133ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561ad133b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561ad133a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561ad133a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561ad133a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561ad5c44abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561ad5c4d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561ad5c35699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561ad5c60112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ede4fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561acf55ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9f75809401374525b55f51ad2333cd8fe1c0178a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6007 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 595064566 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e2fb44f810, 0x55e2fb63901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e2fb639020,0x55e2fd4d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f75809401374525b55f51ad2333cd8fe1c0178a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7745 processed earlier; will process 3284 files now Step #5: ==216358== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e2f1f449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e2f85a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e2f858c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e2f858c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e2f1f4ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e2f1eabb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e2f1ea6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e2f1f3cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e2f4f0bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e2f4f0bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e2f4f0bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e2f4f0bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e2f4f0bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e2f4f0bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e2f4f0bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e2f4f0bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e2f4f0bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e2f4f0bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e2f71a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e2f3ecdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e2f3ed8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e2f3c84c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e2f3c84c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e2f3c85738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e2f3c84874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e2f3c84874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e2f3c84874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e2f858eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e2f8597928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e2f857f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e2f85aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efed0a65082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e2f1ea4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-01b90a1c6306e89765609d4dbcd14eadb4e6e815 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6008 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 595599283 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557214e21810, 0x55721500b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55721500b020,0x557216ea30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/01b90a1c6306e89765609d4dbcd14eadb4e6e815' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7746 processed earlier; will process 3283 files now Step #5: ==216394== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55720b9169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557211f7b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557211f5e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557211f5e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55720b91cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55720b87db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55720b878355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55720b90ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55720e8ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55720e8ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55720e8ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55720e8ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55720e8ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55720e8ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55720e8ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55720e8ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55720e8ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55720e8ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557210b72f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55720d89fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55720d8aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55720d656c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55720d656c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55720d657738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55720d656874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55720d656874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55720d656874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557211f60abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557211f69928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557211f51699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557211f7c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe6ab05a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55720b876b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f432f3bf110a43d3e92934a793156e0fc8062950 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6009 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 596276503 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5556e193b810, 0x5556e1b2501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5556e1b25020,0x5556e39bd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f432f3bf110a43d3e92934a793156e0fc8062950' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7747 processed earlier; will process 3282 files now Step #5: #1 pulse cov: 4016 ft: 4017 exec/s: 0 rss: 179Mb Step #5: ==216430== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5556d84309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5556dea95898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556dea785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556dea784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5556d8436d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5556d8397b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5556d8392355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5556d8428c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5556db3f7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5556db3f7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5556db3f7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5556db3f7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5556db3f7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5556db3f7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5556db3f7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5556db3f7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5556db3f7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5556db3f7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5556dd68cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5556da3b9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5556da3c4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5556da170c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5556da170c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5556da171738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5556da170874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5556da170874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5556da170874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5556dea7aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5556dea83928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5556dea6b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5556dea96112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efc97bd9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5556d8390b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e887631ad090127486746bdcc65fde04dbed0821 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6010 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 597013325 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56396aef8810, 0x56396b0e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56396b0e2020,0x56396cf7a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e887631ad090127486746bdcc65fde04dbed0821' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7749 processed earlier; will process 3280 files now Step #5: ==216466== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5639619ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563968052898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5639680355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5639680354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5639619f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563961954b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56396194f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5639619e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5639649b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5639649b4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5639649b4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5639649b4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5639649b4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5639649b4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5639649b4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5639649b4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5639649b4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5639649b4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563966c49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563963976b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563963981be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56396372dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56396372dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56396372e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56396372d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56396372d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56396372d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563968037abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563968040928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563968028699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563968053112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9243ccc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56396194db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6fa9a4fd015f3a39afa615a7fa1fed34dc06cc36 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6011 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 597686620 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a4c029c810, 0x55a4c048601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a4c0486020,0x55a4c231e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6fa9a4fd015f3a39afa615a7fa1fed34dc06cc36' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7750 processed earlier; will process 3279 files now Step #5: #1 pulse cov: 3721 ft: 3722 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4095 ft: 4453 exec/s: 0 rss: 181Mb Step #5: ==216502== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a4b6d919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a4bd3f6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a4bd3d95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a4bd3d94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a4b6d97d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a4b6cf8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a4b6cf3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a4b6d89c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a4b9d58f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a4b9d58f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a4b9d58f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a4b9d58f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a4b9d58f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a4b9d58f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a4b9d58f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a4b9d58f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a4b9d58f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a4b9d58f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a4bbfedf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a4b8d1ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a4b8d25be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a4b8ad1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a4b8ad1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a4b8ad2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a4b8ad1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a4b8ad1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a4b8ad1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a4bd3dbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a4bd3e4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a4bd3cc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a4bd3f7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd1047a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a4b6cf1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c81aa721bf1475a36c008c6bf63f70f3e4adcffc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6012 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 598437321 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0d4d6c810, 0x55b0d4f5601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b0d4f56020,0x55b0d6dee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c81aa721bf1475a36c008c6bf63f70f3e4adcffc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7753 processed earlier; will process 3276 files now Step #5: ==216538== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b0cb8619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b0d1ec6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b0d1ea95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b0d1ea94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0cb867d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0cb7c8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0cb7c3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0cb859c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b0ce828f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b0ce828f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b0ce828f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b0ce828f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b0ce828f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b0ce828f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b0ce828f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b0ce828f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b0ce828f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b0ce828f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b0d0abdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b0cd7eab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b0cd7f5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b0cd5a1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b0cd5a1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b0cd5a2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b0cd5a1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b0cd5a1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b0cd5a1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b0d1eababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b0d1eb4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b0d1e9c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b0d1ec7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe8282bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0cb7c1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9f7ced1baa2dbeba66657e62b70021affacf4cd1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6013 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 598974632 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3374e2810, 0x55a3376cc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a3376cc020,0x55a3395640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f7ced1baa2dbeba66657e62b70021affacf4cd1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7754 processed earlier; will process 3275 files now Step #5: ==216574== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a32dfd79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a33463c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a33461f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a33461f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a32dfddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a32df3eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a32df39355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a32dfcfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a330f9ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a330f9ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a330f9ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a330f9ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a330f9ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a330f9ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a330f9ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a330f9ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a330f9ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a330f9ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a333233f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a32ff60b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a32ff6bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a32fd17c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a32fd17c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a32fd18738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a32fd17874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a32fd17874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a32fd17874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a334621abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a33462a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a334612699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a33463d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6cddd24082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a32df37b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-50769770dc35252885976af0346b62e4551063fc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6014 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 599520694 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dc9efbe810, 0x55dc9f1a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dc9f1a8020,0x55dca10400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/50769770dc35252885976af0346b62e4551063fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7755 processed earlier; will process 3274 files now Step #5: ==216610== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dc95ab39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dc9c118898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dc9c0fb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dc9c0fb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dc95ab9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dc95a1ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dc95a15355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dc95aabc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dc98a7af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dc98a7af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dc98a7af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dc98a7af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dc98a7af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dc98a7af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dc98a7af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dc98a7af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dc98a7af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dc98a7af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dc9ad0ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dc97a3cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dc97a47be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dc977f3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dc977f3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dc977f4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dc977f3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dc977f3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dc977f3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dc9c0fdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dc9c106928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dc9c0ee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dc9c119112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f82bcec2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dc95a13b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d04178e35c890a1ab29dcca7c998f1452e58faed Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6015 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 600076264 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5620cd8cd810, 0x5620cdab701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5620cdab7020,0x5620cf94f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d04178e35c890a1ab29dcca7c998f1452e58faed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7756 processed earlier; will process 3273 files now Step #5: #1 pulse cov: 3818 ft: 3819 exec/s: 0 rss: 179Mb Step #5: ==216646== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5620c43c29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5620caa27898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5620caa0a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5620caa0a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5620c43c8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5620c4329b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5620c4324355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5620c43bac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5620c7389f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5620c7389f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5620c7389f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5620c7389f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5620c7389f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5620c7389f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5620c7389f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5620c7389f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5620c7389f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5620c7389f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5620c961ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5620c634bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5620c6356be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5620c6102c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5620c6102c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5620c6103738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5620c6102874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5620c6102874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5620c6102874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5620caa0cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5620caa15928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5620ca9fd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5620caa28112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff4fa9b5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5620c4322b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-eb95061193fdb8bb62f4936fdaae9a79b8c6b88e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6016 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 600663205 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557635c43810, 0x557635e2d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557635e2d020,0x557637cc50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eb95061193fdb8bb62f4936fdaae9a79b8c6b88e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7758 processed earlier; will process 3271 files now Step #5: ==216682== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55762c7389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557632d9d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557632d805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557632d804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55762c73ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55762c69fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55762c69a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55762c730c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55762f6fff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55762f6fff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55762f6fff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55762f6fff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55762f6fff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55762f6fff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55762f6fff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55762f6fff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55762f6fff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55762f6fff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557631994f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55762e6c1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55762e6ccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55762e478c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55762e478c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55762e479738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55762e478874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55762e478874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55762e478874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557632d82abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557632d8b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557632d73699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557632d9e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc736c8c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55762c698b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a1fccf8d0b1dded9e514071e93bec5d29ac526a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6017 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 601228815 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9112d1810, 0x55e9114bb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9114bb020,0x55e9133530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a1fccf8d0b1dded9e514071e93bec5d29ac526a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7759 processed earlier; will process 3270 files now Step #5: ==216718== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e907dc69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e90e42b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e90e40e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e90e40e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e907dccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e907d2db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e907d28355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e907dbec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e90ad8df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e90ad8df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e90ad8df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e90ad8df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e90ad8df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e90ad8df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e90ad8df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e90ad8df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e90ad8df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e90ad8df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e90d022f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e909d4fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e909d5abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e909b06c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e909b06c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e909b07738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e909b06874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e909b06874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e909b06874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e90e410abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e90e419928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e90e401699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e90e42c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a1b6a2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e907d26b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bdc8d1634e7bc7b0a8153b75be5973a7e38829c4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6018 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 601820885 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fef9207810, 0x55fef93f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fef93f1020,0x55fefb2890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bdc8d1634e7bc7b0a8153b75be5973a7e38829c4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7760 processed earlier; will process 3269 files now Step #5: #1 pulse cov: 4069 ft: 4070 exec/s: 0 rss: 180Mb Step #5: ==216754== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55feefcfc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fef6361898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fef63445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fef63444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55feefd02d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55feefc63b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55feefc5e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55feefcf4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fef2cc3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fef2cc3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fef2cc3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fef2cc3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fef2cc3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fef2cc3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fef2cc3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fef2cc3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fef2cc3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fef2cc3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fef4f58f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fef1c85b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fef1c90be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fef1a3cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fef1a3cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fef1a3d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fef1a3c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fef1a3c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fef1a3c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fef6346abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fef634f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fef6337699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fef6362112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f09d21d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55feefc5cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8a7261a54c3db530ada99ba479c476cf9cab5ccf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6019 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 602472723 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bc54087810, 0x55bc5427101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bc54271020,0x55bc561090e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8a7261a54c3db530ada99ba479c476cf9cab5ccf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7762 processed earlier; will process 3267 files now Step #5: ==216790== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bc4ab7c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bc511e1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bc511c45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bc511c44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bc4ab82d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bc4aae3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bc4aade355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bc4ab74c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bc4db43f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bc4db43f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bc4db43f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bc4db43f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bc4db43f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bc4db43f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bc4db43f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bc4db43f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bc4db43f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bc4db43f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bc4fdd8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bc4cb05b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bc4cb10be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bc4c8bcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bc4c8bcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bc4c8bd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bc4c8bc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bc4c8bc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bc4c8bc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bc511c6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bc511cf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bc511b7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bc511e2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e44aa8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bc4aadcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-75bac34fc806c6c6523d46b74f40258b7feee6e1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6020 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 603214671 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5569baad7810, 0x5569bacc101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5569bacc1020,0x5569bcb590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/75bac34fc806c6c6523d46b74f40258b7feee6e1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7763 processed earlier; will process 3266 files now Step #5: #1 pulse cov: 4514 ft: 4515 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 5339 ft: 5940 exec/s: 0 rss: 180Mb Step #5: ==216826== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5569b15cc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5569b7c31898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5569b7c145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5569b7c144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5569b15d2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5569b1533b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5569b152e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5569b15c4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5569b4593f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5569b4593f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5569b4593f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5569b4593f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5569b4593f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5569b4593f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5569b4593f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5569b4593f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5569b4593f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5569b4593f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5569b6828f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5569b3555b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5569b3560be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5569b330cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5569b330cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5569b330d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5569b330c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5569b330c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5569b330c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5569b7c16abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5569b7c1f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5569b7c07699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5569b7c32112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5440932082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5569b152cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-18649c3de6d4bbd533be35170c4d4f7eb5ec5d9e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6021 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 603937421 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559047ac8810, 0x559047cb201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559047cb2020,0x559049b4a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/18649c3de6d4bbd533be35170c4d4f7eb5ec5d9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7767 processed earlier; will process 3262 files now Step #5: #1 pulse cov: 11867 ft: 11868 exec/s: 0 rss: 197Mb Step #5: ==216862== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55903e5bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559044c22898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559044c055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559044c054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55903e5c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55903e524b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55903e51f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55903e5b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559041584f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559041584f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559041584f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559041584f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559041584f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559041584f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559041584f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559041584f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559041584f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559041584f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559043819f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559040546b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559040551be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5590402fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5590402fdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5590402fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5590402fd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5590402fd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5590402fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559044c07abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559044c10928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559044bf8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559044c23112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb7326cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55903e51db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1cf2588a62740a995532d9b22ccb33b34c59af9b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6022 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 604699456 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56473524b810, 0x56473543501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564735435020,0x5647372cd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1cf2588a62740a995532d9b22ccb33b34c59af9b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7769 processed earlier; will process 3260 files now Step #5: #1 pulse cov: 3936 ft: 3937 exec/s: 0 rss: 178Mb Step #5: ==216898== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56472bd409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647323a5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647323885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647323884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56472bd46d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56472bca7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56472bca2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56472bd38c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56472ed07f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56472ed07f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56472ed07f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56472ed07f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56472ed07f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56472ed07f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56472ed07f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56472ed07f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56472ed07f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56472ed07f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564730f9cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56472dcc9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56472dcd4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56472da80c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56472da80c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56472da81738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56472da80874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56472da80874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56472da80874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56473238aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564732393928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56473237b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647323a6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fea54456082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56472bca0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-50630d5dfbae03e861ca19117332eec493747355 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6023 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 605838475 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5555e10ca810, 0x5555e12b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5555e12b4020,0x5555e314c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/50630d5dfbae03e861ca19117332eec493747355' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7771 processed earlier; will process 3258 files now Step #5: #1 pulse cov: 11770 ft: 11771 exec/s: 0 rss: 199Mb Step #5: #2 pulse cov: 12433 ft: 13301 exec/s: 0 rss: 201Mb Step #5: ==216934== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5555d7bbf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5555de224898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5555de2075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5555de2074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5555d7bc5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5555d7b26b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5555d7b21355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5555d7bb7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5555dab86f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5555dab86f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5555dab86f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5555dab86f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5555dab86f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5555dab86f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5555dab86f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5555dab86f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5555dab86f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5555dab86f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5555dce1bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5555d9b48b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5555d9b53be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5555d98ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5555d98ffc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5555d9900738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5555d98ff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5555d98ff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5555d98ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5555de209abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5555de212928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5555de1fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5555de225112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc6f2108082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5555d7b1fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6bcde54df9917466476f3bc2e5e674c2519eb4c3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6024 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 606487548 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5633186ca810, 0x5633188b401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5633188b4020,0x56331a74c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bcde54df9917466476f3bc2e5e674c2519eb4c3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7774 processed earlier; will process 3255 files now Step #5: #1 pulse cov: 3813 ft: 3814 exec/s: 0 rss: 179Mb Step #5: ==216970== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56330f1bf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563315824898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5633158075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5633158074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56330f1c5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56330f126b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56330f121355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56330f1b7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563312186f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563312186f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563312186f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563312186f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563312186f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563312186f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563312186f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563312186f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563312186f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563312186f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56331441bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563311148b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563311153be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563310effc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563310effc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563310f00738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563310eff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563310eff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563310eff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563315809abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563315812928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5633157fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563315825112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9de9d6c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56330f11fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4819688c85c32e9814409553757a6b0299c6417c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6025 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 607092669 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5557b1323810, 0x5557b150d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5557b150d020,0x5557b33a50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4819688c85c32e9814409553757a6b0299c6417c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7776 processed earlier; will process 3253 files now Step #5: ==217006== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5557a7e189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5557ae47d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557ae4605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557ae4604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557a7e1ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557a7d7fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5557a7d7a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557a7e10c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557aaddff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557aaddff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557aaddff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557aaddff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557aaddff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557aaddff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557aaddff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557aaddff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557aaddff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557aaddff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5557ad074f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557a9da1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557a9dacbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5557a9b58c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5557a9b58c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5557a9b59738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5557a9b58874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5557a9b58874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5557a9b58874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557ae462abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557ae46b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557ae453699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5557ae47e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc9c79d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5557a7d78b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ad48f9c337b9bc33b3f003d2e5942e3e8af9b465 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6026 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 607654910 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55596189e810, 0x555961a8801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555961a88020,0x5559639200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad48f9c337b9bc33b3f003d2e5942e3e8af9b465' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7777 processed earlier; will process 3252 files now Step #5: ==217042== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5559583939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55595e9f8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55595e9db5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55595e9db4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555958399d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5559582fab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5559582f5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55595838bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55595b35af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55595b35af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55595b35af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55595b35af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55595b35af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55595b35af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55595b35af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55595b35af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55595b35af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55595b35af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55595d5eff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55595a31cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55595a327be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55595a0d3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55595a0d3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55595a0d4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55595a0d3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55595a0d3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55595a0d3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55595e9ddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55595e9e6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55595e9ce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55595e9f9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc4ed88082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5559582f3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9c377d129fb5dde59bee693f7ecaa8b391a9afa3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6027 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 609219089 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f25b989810, 0x55f25bb7301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f25bb73020,0x55f25da0b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c377d129fb5dde59bee693f7ecaa8b391a9afa3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7778 processed earlier; will process 3251 files now Step #5: ==217078== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f25247e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f258ae3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f258ac65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f258ac64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f252484d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f2523e5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f2523e0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f252476c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f255445f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f255445f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f255445f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f255445f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f255445f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f255445f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f255445f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f255445f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f255445f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f255445f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f2576daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f254407b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f254412be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f2541bec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f2541bec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f2541bf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f2541be874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f2541be874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f2541be874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f258ac8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f258ad1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f258ab9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f258ae4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5cc524b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f2523deb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f14426689d7760c1156eaba378c0ddf330fae056 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6028 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 609779736 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ab1bfe0810, 0x55ab1c1ca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ab1c1ca020,0x55ab1e0620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f14426689d7760c1156eaba378c0ddf330fae056' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7779 processed earlier; will process 3250 files now Step #5: ==217114== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ab12ad59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ab1913a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ab1911d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ab1911d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ab12adbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ab12a3cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ab12a37355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ab12acdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ab15a9cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ab15a9cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ab15a9cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ab15a9cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ab15a9cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ab15a9cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ab15a9cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ab15a9cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ab15a9cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ab15a9cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ab17d31f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ab14a5eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ab14a69be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ab14815c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ab14815c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ab14816738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ab14815874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ab14815874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ab14815874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ab1911fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ab19128928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ab19110699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ab1913b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f523abc6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ab12a35b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6a37e36eee12b414112c339d88b83ec5ce4f357c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6029 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 610307115 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c83f43810, 0x559c8412d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c8412d020,0x559c85fc50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6a37e36eee12b414112c339d88b83ec5ce4f357c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7780 processed earlier; will process 3249 files now Step #5: #1 pulse cov: 4158 ft: 4159 exec/s: 0 rss: 179Mb Step #5: ==217150== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559c7aa389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c8109d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c810805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c810804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c7aa3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c7a99fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c7a99a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c7aa30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c7d9fff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c7d9fff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c7d9fff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c7d9fff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c7d9fff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c7d9fff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c7d9fff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c7d9fff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c7d9fff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c7d9fff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c7fc94f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c7c9c1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c7c9ccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c7c778c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c7c778c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c7c779738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c7c778874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c7c778874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c7c778874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c81082abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c8108b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c81073699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c8109e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd34898e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c7a998b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e1f8b374a1be0beac704f2a1da4b71c80df45cf3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6030 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 610899402 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55704f343810, 0x55704f52d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55704f52d020,0x5570513c50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e1f8b374a1be0beac704f2a1da4b71c80df45cf3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7782 processed earlier; will process 3247 files now Step #5: ==217186== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557045e389c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55704c49d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55704c4805dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55704c4804fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557045e3ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557045d9fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557045d9a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557045e30c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557048dfff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557048dfff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557048dfff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557048dfff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557048dfff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557048dfff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557048dfff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557048dfff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557048dfff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557048dfff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55704b094f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557047dc1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557047dccbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557047b78c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557047b78c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557047b79738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557047b78874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557047b78874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557047b78874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55704c482abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55704c48b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55704c473699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55704c49e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f041c384082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557045d98b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-06e1e32cb0a11f3074713eba7d40b10608d2ded0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6031 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 611416002 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5576cc6b9810, 0x5576cc8a301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5576cc8a3020,0x5576ce73b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/06e1e32cb0a11f3074713eba7d40b10608d2ded0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7783 processed earlier; will process 3246 files now Step #5: ==217222== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5576c31ae9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5576c9813898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5576c97f65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5576c97f64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5576c31b4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5576c3115b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5576c3110355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5576c31a6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576c6175f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576c6175f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576c6175f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576c6175f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576c6175f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576c6175f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576c6175f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576c6175f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576c6175f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576c6175f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5576c840af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5576c5137b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5576c5142be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5576c4eeec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5576c4eeec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5576c4eef738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5576c4eee874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5576c4eee874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5576c4eee874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5576c97f8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5576c9801928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5576c97e9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5576c9814112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3c2e8f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5576c310eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8ee94c3dd3771654573dd5849a3e89cc077b7a5b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6032 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 612017427 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f9062a1810, 0x55f90648b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f90648b020,0x55f9083230e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ee94c3dd3771654573dd5849a3e89cc077b7a5b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7784 processed earlier; will process 3245 files now Step #5: ==217258== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8fcd969c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f9033fb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f9033de5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f9033de4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8fcd9cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8fccfdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8fccf8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8fcd8ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8ffd5df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8ffd5df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8ffd5df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8ffd5df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8ffd5df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8ffd5df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8ffd5df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8ffd5df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8ffd5df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8ffd5df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f901ff2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f8fed1fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f8fed2abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8fead6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8fead6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8fead7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8fead6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8fead6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8fead6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f9033e0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f9033e9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f9033d1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f9033fc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa04bbd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8fccf6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-755f22ace883bec9980bcd9b97ed5633a81e6b90 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6033 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 612556553 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5589a8c2a810, 0x5589a8e1401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5589a8e14020,0x5589aacac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/755f22ace883bec9980bcd9b97ed5633a81e6b90' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7785 processed earlier; will process 3244 files now Step #5: #1 pulse cov: 4214 ft: 4215 exec/s: 0 rss: 178Mb Step #5: ==217294== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55899f71f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5589a5d84898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589a5d675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589a5d674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55899f725d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55899f686b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55899f681355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55899f717c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5589a26e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5589a26e6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5589a26e6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5589a26e6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5589a26e6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5589a26e6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5589a26e6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5589a26e6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5589a26e6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5589a26e6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589a497bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5589a16a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5589a16b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5589a145fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5589a145fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5589a1460738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5589a145f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5589a145f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5589a145f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5589a5d69abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5589a5d72928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5589a5d5a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5589a5d85112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f424a1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55899f67fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b56908b9adfdb5ce5e21d379950118420debdda9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6034 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 613148225 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556aaf028810, 0x556aaf21201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556aaf212020,0x556ab10aa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b56908b9adfdb5ce5e21d379950118420debdda9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7787 processed earlier; will process 3242 files now Step #5: ==217330== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556aa5b1d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556aac182898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556aac1655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556aac1654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556aa5b23d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556aa5a84b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556aa5a7f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556aa5b15c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556aa8ae4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556aa8ae4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556aa8ae4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556aa8ae4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556aa8ae4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556aa8ae4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556aa8ae4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556aa8ae4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556aa8ae4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556aa8ae4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556aaad79f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556aa7aa6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556aa7ab1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556aa785dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556aa785dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556aa785e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556aa785d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556aa785d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556aa785d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556aac167abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556aac170928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556aac158699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556aac183112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f45e5702082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556aa5a7db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e680f7fa457a37c8204fbf057ddd25f8ed3b356b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6035 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 613804315 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55efdd5b1810, 0x55efdd79b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55efdd79b020,0x55efdf6330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e680f7fa457a37c8204fbf057ddd25f8ed3b356b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7788 processed earlier; will process 3241 files now Step #5: #1 pulse cov: 4769 ft: 4770 exec/s: 0 rss: 179Mb Step #5: ==217366== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55efd40a69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55efda70b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55efda6ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55efda6ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55efd40acd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55efd400db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55efd4008355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55efd409ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55efd706df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55efd706df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55efd706df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55efd706df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55efd706df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55efd706df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55efd706df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55efd706df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55efd706df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55efd706df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55efd9302f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55efd602fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55efd603abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55efd5de6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55efd5de6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55efd5de7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55efd5de6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55efd5de6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55efd5de6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55efda6f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55efda6f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55efda6e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55efda70c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9b8e509082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55efd4006b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-894209d3d48ae663611380511ef12411643927b7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6036 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 614407508 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a99ce2810, 0x558a99ecc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a99ecc020,0x558a9bd640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/894209d3d48ae663611380511ef12411643927b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7790 processed earlier; will process 3239 files now Step #5: ==217402== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558a907d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a96e3c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a96e1f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a96e1f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a907ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a9073eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a90739355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a907cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a9379ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a9379ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a9379ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a9379ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a9379ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a9379ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a9379ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a9379ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a9379ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a9379ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a95a33f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a92760b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a9276bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a92517c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a92517c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a92518738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a92517874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a92517874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a92517874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a96e21abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a96e2a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a96e12699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a96e3d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f38fcceb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a90737b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2de176e816fe167b111ee4f6999e8f0bd1ba879d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6037 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 614936483 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bdc2cc0810, 0x55bdc2eaa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bdc2eaa020,0x55bdc4d420e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2de176e816fe167b111ee4f6999e8f0bd1ba879d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7791 processed earlier; will process 3238 files now Step #5: ==217438== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bdb97b59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bdbfe1a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bdbfdfd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bdbfdfd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bdb97bbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bdb971cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bdb9717355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bdb97adc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bdbc77cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bdbc77cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bdbc77cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bdbc77cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bdbc77cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bdbc77cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bdbc77cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bdbc77cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bdbc77cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bdbc77cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bdbea11f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bdbb73eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bdbb749be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bdbb4f5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bdbb4f5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bdbb4f6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bdbb4f5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bdbb4f5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bdbb4f5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bdbfdffabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bdbfe08928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bdbfdf0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bdbfe1b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7332a1f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bdb9715b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a23e1bef4127728867e4f68140959948c4a8f316 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6038 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 615525453 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed6155a810, 0x55ed6174401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed61744020,0x55ed635dc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a23e1bef4127728867e4f68140959948c4a8f316' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7792 processed earlier; will process 3237 files now Step #5: ==217474== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed5804f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed5e6b4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed5e6975dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed5e6974fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed58055d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed57fb6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed57fb1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed58047c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed5b016f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed5b016f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed5b016f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed5b016f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed5b016f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed5b016f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed5b016f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed5b016f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed5b016f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed5b016f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed5d2abf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed59fd8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed59fe3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed59d8fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed59d8fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed59d90738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed59d8f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed59d8f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed59d8f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed5e699abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed5e6a2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed5e68a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed5e6b5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c2ea54082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed57fafb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7d1530ff91c88b50c22fa8c5c547a07b563ef34f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6039 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 616065002 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e875bc7810, 0x55e875db101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e875db1020,0x55e877c490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7d1530ff91c88b50c22fa8c5c547a07b563ef34f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7793 processed earlier; will process 3236 files now Step #5: ==217510== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e86c6bc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e872d21898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e872d045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e872d044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e86c6c2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e86c623b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e86c61e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e86c6b4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e86f683f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e86f683f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e86f683f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e86f683f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e86f683f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e86f683f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e86f683f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e86f683f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e86f683f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e86f683f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e871918f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e86e645b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e86e650be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e86e3fcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e86e3fcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e86e3fd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e86e3fc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e86e3fc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e86e3fc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e872d06abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e872d0f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e872cf7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e872d22112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb2f1a43082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e86c61cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e00d5e8e3fca6bb07852eadd18d6eb4caea262e5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6040 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 616704102 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5625e7b2f810, 0x5625e7d1901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5625e7d19020,0x5625e9bb10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e00d5e8e3fca6bb07852eadd18d6eb4caea262e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7794 processed earlier; will process 3235 files now Step #5: ==217546== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5625de6249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5625e4c89898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625e4c6c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625e4c6c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5625de62ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625de58bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625de586355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5625de61cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5625e15ebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5625e15ebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5625e15ebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5625e15ebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5625e15ebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5625e15ebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5625e15ebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5625e15ebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5625e15ebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5625e15ebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5625e3880f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625e05adb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5625e05b8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5625e0364c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5625e0364c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5625e0365738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5625e0364874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5625e0364874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5625e0364874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5625e4c6eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5625e4c77928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5625e4c5f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5625e4c8a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3be8b5b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5625de584b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb80272c0d8b0d443995162c0589744ea208f85e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6041 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 617977610 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558f83bb6810, 0x558f83da001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558f83da0020,0x558f85c380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb80272c0d8b0d443995162c0589744ea208f85e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7795 processed earlier; will process 3234 files now Step #5: #1 pulse cov: 11111 ft: 11112 exec/s: 0 rss: 195Mb Step #5: ==217582== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558f7a6ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558f80d10898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558f80cf35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558f80cf34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f7a6b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f7a612b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f7a60d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f7a6a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f7d672f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f7d672f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f7d672f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f7d672f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f7d672f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f7d672f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f7d672f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f7d672f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f7d672f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f7d672f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558f7f907f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f7c634b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f7c63fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f7c3ebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f7c3ebc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f7c3ec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f7c3eb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f7c3eb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f7c3eb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558f80cf5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558f80cfe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558f80ce6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558f80d11112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb198a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f7a60bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-42f2a06a698bbcbd4da68ed2f60fabf6b6fc0bc0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6042 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 618725828 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e3624a2810, 0x55e36268c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e36268c020,0x55e3645240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/42f2a06a698bbcbd4da68ed2f60fabf6b6fc0bc0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7797 processed earlier; will process 3232 files now Step #5: ==217618== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e358f979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e35f5fc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e35f5df5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e35f5df4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e358f9dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e358efeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e358ef9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e358f8fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e35bf5ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e35bf5ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e35bf5ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e35bf5ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e35bf5ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e35bf5ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e35bf5ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e35bf5ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e35bf5ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e35bf5ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e35e1f3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e35af20b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e35af2bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e35acd7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e35acd7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e35acd8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e35acd7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e35acd7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e35acd7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e35f5e1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e35f5ea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e35f5d2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e35f5fd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5521687082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e358ef7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b3346f5ed9f249e176911ccd5aeec5608171905a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6043 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 619265988 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b4156d810, 0x557b4175701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b41757020,0x557b435ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b3346f5ed9f249e176911ccd5aeec5608171905a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7798 processed earlier; will process 3231 files now Step #5: ==217654== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557b380629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b3e6c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b3e6aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b3e6aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b38068d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b37fc9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b37fc4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b3805ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b3b029f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b3b029f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b3b029f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b3b029f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b3b029f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b3b029f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b3b029f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b3b029f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b3b029f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b3b029f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b3d2bef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b39febb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b39ff6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b39da2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b39da2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b39da3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b39da2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b39da2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b39da2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b3e6acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b3e6b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b3e69d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b3e6c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ec7a31082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b37fc2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-63be52ac34302967069659a4ecffe7c423b99006 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6044 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 619812343 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5576cf54f810, 0x5576cf73901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5576cf739020,0x5576d15d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/63be52ac34302967069659a4ecffe7c423b99006' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7799 processed earlier; will process 3230 files now Step #5: ==217690== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5576c60449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5576cc6a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5576cc68c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5576cc68c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5576c604ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5576c5fabb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5576c5fa6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5576c603cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576c900bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576c900bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576c900bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576c900bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576c900bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576c900bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576c900bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576c900bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576c900bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576c900bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5576cb2a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5576c7fcdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5576c7fd8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5576c7d84c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5576c7d84c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5576c7d85738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5576c7d84874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5576c7d84874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5576c7d84874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5576cc68eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5576cc697928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5576cc67f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5576cc6aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdde836d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5576c5fa4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fae38cee1b96dfd80ffdbd7be8d4aba909f4d5e6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6045 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 620365649 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558d08a8f810, 0x558d08c7901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558d08c79020,0x558d0ab110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fae38cee1b96dfd80ffdbd7be8d4aba909f4d5e6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7800 processed earlier; will process 3229 files now Step #5: ==217726== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558cff5849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558d05be9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558d05bcc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558d05bcc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558cff58ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558cff4ebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558cff4e6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558cff57cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558d0254bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558d0254bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558d0254bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558d0254bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558d0254bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558d0254bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558d0254bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558d0254bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558d0254bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558d0254bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558d047e0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558d0150db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558d01518be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558d012c4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558d012c4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558d012c5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558d012c4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558d012c4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558d012c4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558d05bceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558d05bd7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558d05bbf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558d05bea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f152f1ed082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558cff4e4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-eeb50b972828ebd0d2a177556464cf58288d1808 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6046 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 621608444 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5596f3bde810, 0x5596f3dc801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596f3dc8020,0x5596f5c600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eeb50b972828ebd0d2a177556464cf58288d1808' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7801 processed earlier; will process 3228 files now Step #5: ==217762== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5596ea6d39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5596f0d38898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5596f0d1b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5596f0d1b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5596ea6d9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5596ea63ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5596ea635355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5596ea6cbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5596ed69af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5596ed69af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5596ed69af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5596ed69af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5596ed69af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5596ed69af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5596ed69af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5596ed69af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5596ed69af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5596ed69af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596ef92ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5596ec65cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5596ec667be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5596ec413c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5596ec413c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5596ec414738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5596ec413874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5596ec413874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5596ec413874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5596f0d1dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5596f0d26928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5596f0d0e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5596f0d39112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4607f9c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5596ea633b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-addd120aece8dab8cfbeb8511637aa2ac4108c5e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6047 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 622742596 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc27a70810, 0x55fc27c5a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc27c5a020,0x55fc29af20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/addd120aece8dab8cfbeb8511637aa2ac4108c5e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7802 processed earlier; will process 3227 files now Step #5: ==217798== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fc1e5659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc24bca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc24bad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc24bad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc1e56bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc1e4ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc1e4c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc1e55dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc2152cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc2152cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc2152cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc2152cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc2152cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc2152cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc2152cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc2152cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc2152cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc2152cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc237c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc204eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc204f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc202a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc202a5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc202a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc202a5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc202a5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc202a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc24bafabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc24bb8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc24ba0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc24bcb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1b72110082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc1e4c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-361c2e97cccf29373bf75c0c20aecf5c7025a5ba Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6048 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 623857932 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c74cf8810, 0x559c74ee201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c74ee2020,0x559c76d7a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/361c2e97cccf29373bf75c0c20aecf5c7025a5ba' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7803 processed earlier; will process 3226 files now Step #5: #1 pulse cov: 15530 ft: 15531 exec/s: 0 rss: 201Mb Step #5: ==217834== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559c6b7ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c71e52898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c71e355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c71e354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c6b7f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c6b754b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c6b74f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c6b7e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c6e7b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c6e7b4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c6e7b4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c6e7b4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c6e7b4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c6e7b4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c6e7b4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c6e7b4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c6e7b4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c6e7b4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c70a49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c6d776b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c6d781be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c6d52dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c6d52dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c6d52e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c6d52d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c6d52d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c6d52d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c71e37abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c71e40928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c71e28699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c71e53112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f873005d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c6b74db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bec28ed3306c1ac0e6b9900194e4622dc788462a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6049 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 624559918 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e1b482d810, 0x55e1b4a1701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e1b4a17020,0x55e1b68af0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bec28ed3306c1ac0e6b9900194e4622dc788462a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7805 processed earlier; will process 3224 files now Step #5: ==217870== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e1ab3229c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e1b1987898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e1b196a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e1b196a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e1ab328d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e1ab289b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e1ab284355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e1ab31ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e1ae2e9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e1ae2e9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e1ae2e9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e1ae2e9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e1ae2e9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e1ae2e9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e1ae2e9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e1ae2e9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e1ae2e9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e1ae2e9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e1b057ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e1ad2abb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e1ad2b6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e1ad062c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e1ad062c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e1ad063738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e1ad062874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e1ad062874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e1ad062874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e1b196cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e1b1975928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e1b195d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e1b1988112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1f57ded082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e1ab282b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b25eb838aa8c9e1227309c219899f8ada566f57c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6050 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 625861380 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562427793810, 0x56242797d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56242797d020,0x5624298150e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b25eb838aa8c9e1227309c219899f8ada566f57c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7806 processed earlier; will process 3223 files now Step #5: ==217906== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56241e2889c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5624248ed898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5624248d05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5624248d04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56241e28ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56241e1efb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56241e1ea355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56241e280c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56242124ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56242124ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56242124ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56242124ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56242124ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56242124ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56242124ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56242124ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56242124ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56242124ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5624234e4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562420211b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56242021cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56241ffc8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56241ffc8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56241ffc9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56241ffc8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56241ffc8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56241ffc8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5624248d2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5624248db928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5624248c3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5624248ee112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4382a0e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56241e1e8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-febf567570756af193ff70b4dd50f46f26d92407 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6051 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 626963074 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5620123a6810, 0x56201259001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562012590020,0x5620144280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/febf567570756af193ff70b4dd50f46f26d92407' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7807 processed earlier; will process 3222 files now Step #5: #1 pulse cov: 3808 ft: 3809 exec/s: 0 rss: 177Mb Step #5: ==217942== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562008e9b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56200f500898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56200f4e35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56200f4e34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562008ea1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562008e02b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562008dfd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562008e93c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56200be62f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56200be62f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56200be62f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56200be62f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56200be62f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56200be62f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56200be62f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56200be62f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56200be62f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56200be62f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56200e0f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56200ae24b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56200ae2fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56200abdbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56200abdbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56200abdc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56200abdb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56200abdb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56200abdb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56200f4e5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56200f4ee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56200f4d6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56200f501112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa73297082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562008dfbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f9a611ffbba332ba801fde0f90d2cb9aebe0f2dc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6052 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 627713354 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bbcfe89810, 0x55bbd007301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bbd0073020,0x55bbd1f0b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9a611ffbba332ba801fde0f90d2cb9aebe0f2dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7809 processed earlier; will process 3220 files now Step #5: ==217978== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bbc697e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bbccfe3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bbccfc65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bbccfc64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bbc6984d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bbc68e5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bbc68e0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bbc6976c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bbc9945f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bbc9945f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bbc9945f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bbc9945f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bbc9945f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bbc9945f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bbc9945f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bbc9945f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bbc9945f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bbc9945f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bbcbbdaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bbc8907b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bbc8912be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bbc86bec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bbc86bec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bbc86bf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bbc86be874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bbc86be874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bbc86be874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bbccfc8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bbccfd1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bbccfb9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bbccfe4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3e91ca4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bbc68deb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-17d77eb06b9b672fc47b05f089682727d0c5c5e7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6053 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 628267036 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561e362e0810, 0x561e364ca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561e364ca020,0x561e383620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/17d77eb06b9b672fc47b05f089682727d0c5c5e7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7810 processed earlier; will process 3219 files now Step #5: ==218014== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561e2cdd59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561e3343a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561e3341d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561e3341d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561e2cddbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561e2cd3cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561e2cd37355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561e2cdcdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561e2fd9cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561e2fd9cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561e2fd9cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561e2fd9cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561e2fd9cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561e2fd9cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561e2fd9cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561e2fd9cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561e2fd9cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561e2fd9cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561e32031f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561e2ed5eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561e2ed69be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561e2eb15c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561e2eb15c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561e2eb16738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561e2eb15874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561e2eb15874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561e2eb15874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561e3341fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561e33428928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561e33410699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561e3343b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a6dd45082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561e2cd35b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e40038f988b1eb2272e3195603b9d0249334272d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6054 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 629005738 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5648a650c810, 0x5648a66f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5648a66f6020,0x5648a858e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e40038f988b1eb2272e3195603b9d0249334272d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7811 processed earlier; will process 3218 files now Step #5: #1 pulse cov: 4208 ft: 4209 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 4876 ft: 5202 exec/s: 0 rss: 182Mb Step #5: ==218050== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56489d0019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5648a3666898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5648a36495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5648a36494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56489d007d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56489cf68b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56489cf63355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56489cff9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56489ffc8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56489ffc8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56489ffc8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56489ffc8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56489ffc8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56489ffc8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56489ffc8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56489ffc8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56489ffc8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56489ffc8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5648a225df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56489ef8ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56489ef95be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56489ed41c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56489ed41c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56489ed42738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56489ed41874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56489ed41874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56489ed41874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5648a364babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5648a3654928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5648a363c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5648a3667112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd2f2344082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56489cf61b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4022ee98af1d5edac3c1e17a720facc7ea0be7ad Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6055 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 629671588 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5648df437810, 0x5648df62101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5648df621020,0x5648e14b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4022ee98af1d5edac3c1e17a720facc7ea0be7ad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7814 processed earlier; will process 3215 files now Step #5: ==218086== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5648d5f2c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5648dc591898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5648dc5745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5648dc5744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5648d5f32d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5648d5e93b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5648d5e8e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5648d5f24c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5648d8ef3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5648d8ef3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5648d8ef3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5648d8ef3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5648d8ef3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5648d8ef3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5648d8ef3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5648d8ef3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5648d8ef3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5648d8ef3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5648db188f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5648d7eb5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5648d7ec0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5648d7c6cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5648d7c6cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5648d7c6d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5648d7c6c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5648d7c6c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5648d7c6c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5648dc576abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5648dc57f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5648dc567699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5648dc592112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f77ab7ac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5648d5e8cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0617438e0abf926322a08c86f49c439b1132bd20 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6056 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 630338739 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560657c4a810, 0x560657e3401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560657e34020,0x560659ccc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0617438e0abf926322a08c86f49c439b1132bd20' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7815 processed earlier; will process 3214 files now Step #5: #1 pulse cov: 3872 ft: 3873 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4401 ft: 4885 exec/s: 0 rss: 182Mb Step #5: ==218122== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56064e73f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560654da4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560654d875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560654d874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56064e745d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56064e6a6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56064e6a1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56064e737c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560651706f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560651706f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560651706f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560651706f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560651706f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560651706f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560651706f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560651706f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560651706f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560651706f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56065399bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5606506c8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5606506d3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56065047fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56065047fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560650480738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56065047f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56065047f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56065047f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560654d89abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560654d92928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560654d7a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560654da5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b01fa7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56064e69fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6c362993de64693568ff8e6fbf6e9c30fffbeb05 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6057 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 630988103 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b26cec3810, 0x55b26d0ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b26d0ad020,0x55b26ef450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6c362993de64693568ff8e6fbf6e9c30fffbeb05' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7818 processed earlier; will process 3211 files now Step #5: ==218158== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b2639b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b26a01d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b26a0005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b26a0004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b2639bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b26391fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b26391a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b2639b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b26697ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b26697ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b26697ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b26697ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b26697ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b26697ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b26697ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b26697ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b26697ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b26697ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b268c14f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b265941b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b26594cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b2656f8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b2656f8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b2656f9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b2656f8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b2656f8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b2656f8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b26a002abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b26a00b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b269ff3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b26a01e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53d2190082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b263918b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9431759244286612f4d9ed59a6beb37cd1c060ef Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6058 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 631542314 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55916109f810, 0x55916128901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559161289020,0x5591631210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9431759244286612f4d9ed59a6beb37cd1c060ef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7819 processed earlier; will process 3210 files now Step #5: #1 pulse cov: 4682 ft: 4683 exec/s: 0 rss: 178Mb Step #5: ==218194== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559157b949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55915e1f9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55915e1dc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55915e1dc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559157b9ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559157afbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559157af6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559157b8cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55915ab5bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55915ab5bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55915ab5bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55915ab5bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55915ab5bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55915ab5bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55915ab5bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55915ab5bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55915ab5bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55915ab5bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55915cdf0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559159b1db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559159b28be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5591598d4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5591598d4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5591598d5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5591598d4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5591598d4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5591598d4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55915e1deabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55915e1e7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55915e1cf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55915e1fa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f98df6d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559157af4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9546456c24fc63eace3a9421744969a77821785c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6059 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 632203266 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cdc5c3c810, 0x55cdc5e2601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cdc5e26020,0x55cdc7cbe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9546456c24fc63eace3a9421744969a77821785c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7821 processed earlier; will process 3208 files now Step #5: ==218230== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cdbc7319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cdc2d96898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cdc2d795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cdc2d794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cdbc737d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cdbc698b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cdbc693355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cdbc729c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cdbf6f8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cdbf6f8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cdbf6f8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cdbf6f8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cdbf6f8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cdbf6f8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cdbf6f8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cdbf6f8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cdbf6f8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cdbf6f8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cdc198df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cdbe6bab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cdbe6c5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cdbe471c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cdbe471c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cdbe472738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cdbe471874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cdbe471874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cdbe471874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cdc2d7babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cdc2d84928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cdc2d6c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cdc2d97112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b152e2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cdbc691b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5c21f35a88fa9fc226c7f9b32add8293507bde93 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6060 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 632739091 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a05dcf9810, 0x55a05dee301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a05dee3020,0x55a05fd7b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c21f35a88fa9fc226c7f9b32add8293507bde93' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7822 processed earlier; will process 3207 files now Step #5: ==218266== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0547ee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a05ae53898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a05ae365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a05ae364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0547f4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a054755b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a054750355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0547e6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0577b5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0577b5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0577b5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0577b5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0577b5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0577b5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0577b5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0577b5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0577b5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0577b5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a059a4af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a056777b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a056782be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a05652ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a05652ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a05652f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a05652e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a05652e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a05652e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a05ae38abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a05ae41928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a05ae29699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a05ae54112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f85668c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a05474eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-af2a5394487db1eb6957bfe40025b37b0068a9dc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6061 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 633298824 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ee44e79810, 0x55ee4506301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ee45063020,0x55ee46efb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/af2a5394487db1eb6957bfe40025b37b0068a9dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7823 processed earlier; will process 3206 files now Step #5: ==218302== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ee3b96e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ee41fd3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ee41fb65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ee41fb64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ee3b974d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ee3b8d5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ee3b8d0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ee3b966c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ee3e935f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ee3e935f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ee3e935f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ee3e935f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ee3e935f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ee3e935f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ee3e935f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ee3e935f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ee3e935f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ee3e935f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ee40bcaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ee3d8f7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ee3d902be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ee3d6aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ee3d6aec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ee3d6af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ee3d6ae874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ee3d6ae874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ee3d6ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ee41fb8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ee41fc1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ee41fa9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ee41fd4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95b847e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ee3b8ceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-45fe324b4063b8a27e4f58d54a14e87bf4d6bd41 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6062 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 633915530 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56365252c810, 0x56365271601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563652716020,0x5636545ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/45fe324b4063b8a27e4f58d54a14e87bf4d6bd41' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7824 processed earlier; will process 3205 files now Step #5: ==218338== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5636490219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56364f686898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56364f6695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56364f6694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563649027d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563648f88b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563648f83355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563649019c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56364bfe8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56364bfe8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56364bfe8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56364bfe8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56364bfe8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56364bfe8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56364bfe8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56364bfe8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56364bfe8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56364bfe8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56364e27df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56364afaab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56364afb5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56364ad61c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56364ad61c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56364ad62738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56364ad61874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56364ad61874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56364ad61874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56364f66babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56364f674928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56364f65c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56364f687112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbd5a634082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563648f81b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-05604e65b0b430c84f77db5c836dd43fc5454e9d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6063 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 634465918 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55661f6f5810, 0x55661f8df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55661f8df020,0x5566217770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/05604e65b0b430c84f77db5c836dd43fc5454e9d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7825 processed earlier; will process 3204 files now Step #5: ==218374== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5566161ea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55661c84f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55661c8325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55661c8324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5566161f0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556616151b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55661614c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5566161e2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5566191b1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5566191b1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5566191b1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5566191b1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5566191b1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5566191b1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5566191b1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5566191b1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5566191b1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5566191b1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55661b446f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556618173b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55661817ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556617f2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556617f2ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556617f2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556617f2a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556617f2a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556617f2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55661c834abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55661c83d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55661c825699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55661c850112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0c294cc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55661614ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ed50235707792bfceb93961adec3e7c5e45ad59 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6064 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 635138153 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e906a0810, 0x555e9088a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e9088a020,0x555e927220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ed50235707792bfceb93961adec3e7c5e45ad59' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7826 processed earlier; will process 3203 files now Step #5: ==218410== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555e871959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e8d7fa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e8d7dd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e8d7dd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e8719bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e870fcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e870f7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e8718dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e8a15cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e8a15cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e8a15cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e8a15cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e8a15cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e8a15cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e8a15cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e8a15cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e8a15cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e8a15cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e8c3f1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e8911eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e89129be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e88ed5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e88ed5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e88ed6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e88ed5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e88ed5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e88ed5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e8d7dfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e8d7e8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e8d7d0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e8d7fb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b71594082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e870f5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f5bbba6a015c064e5a08033b75520aa198d8ed2d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6065 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 635694407 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563807765810, 0x56380794f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56380794f020,0x5638097e70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f5bbba6a015c064e5a08033b75520aa198d8ed2d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7827 processed earlier; will process 3202 files now Step #5: ==218446== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5637fe25a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5638048bf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5638048a25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5638048a24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5637fe260d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5637fe1c1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5637fe1bc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5637fe252c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563801221f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563801221f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563801221f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563801221f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563801221f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563801221f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563801221f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563801221f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563801221f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563801221f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5638034b6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5638001e3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5638001eebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5637fff9ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5637fff9ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5637fff9b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5637fff9a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5637fff9a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5637fff9a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5638048a4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5638048ad928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563804895699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5638048c0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb174e9a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5637fe1bab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d31554e8e2fd724b1008fa7796ec6cf901187cf5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6066 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 636258795 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b962ca2810, 0x55b962e8c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b962e8c020,0x55b964d240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d31554e8e2fd724b1008fa7796ec6cf901187cf5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7828 processed earlier; will process 3201 files now Step #5: ==218482== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b9597979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b95fdfc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b95fddf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b95fddf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b95979dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b9596feb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b9596f9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b95978fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b95c75ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b95c75ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b95c75ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b95c75ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b95c75ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b95c75ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b95c75ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b95c75ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b95c75ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b95c75ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b95e9f3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b95b720b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b95b72bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b95b4d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b95b4d7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b95b4d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b95b4d7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b95b4d7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b95b4d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b95fde1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b95fdea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b95fdd2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b95fdfd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0f07c8d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b9596f7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9b0633c3ef5bdf70b9276770bf01bad163a6e9a2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6067 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 636815024 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0e396a810, 0x55b0e3b5401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b0e3b54020,0x55b0e59ec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9b0633c3ef5bdf70b9276770bf01bad163a6e9a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7829 processed earlier; will process 3200 files now Step #5: ==218518== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b0da45f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b0e0ac4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b0e0aa75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b0e0aa74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0da465d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0da3c6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0da3c1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0da457c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b0dd426f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b0dd426f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b0dd426f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b0dd426f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b0dd426f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b0dd426f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b0dd426f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b0dd426f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b0dd426f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b0dd426f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b0df6bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b0dc3e8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b0dc3f3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b0dc19fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b0dc19fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b0dc1a0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b0dc19f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b0dc19f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b0dc19f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b0e0aa9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b0e0ab2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b0e0a9a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b0e0ac5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbf4938a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0da3bfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f14f09173effa1b278d7856a86efe62be9ab1a48 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6068 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 637371838 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e5837b2810, 0x55e58399c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e58399c020,0x55e5858340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f14f09173effa1b278d7856a86efe62be9ab1a48' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7830 processed earlier; will process 3199 files now Step #5: #1 pulse cov: 13717 ft: 13718 exec/s: 0 rss: 198Mb Step #5: #2 pulse cov: 14258 ft: 15197 exec/s: 0 rss: 200Mb Step #5: ==218554== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e57a2a79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e58090c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e5808ef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e5808ef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e57a2add42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e57a20eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e57a209355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e57a29fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e57d26ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e57d26ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e57d26ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e57d26ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e57d26ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e57d26ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e57d26ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e57d26ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e57d26ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e57d26ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e57f503f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e57c230b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e57c23bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e57bfe7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e57bfe7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e57bfe8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e57bfe7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e57bfe7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e57bfe7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e5808f1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e5808fa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e5808e2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e58090d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f06e0d17082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e57a207b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8476eb06b63fda757017e3bcb3769cc4b3c0e9f9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6069 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 638095400 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f751fc2810, 0x55f7521ac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7521ac020,0x55f7540440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8476eb06b63fda757017e3bcb3769cc4b3c0e9f9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7834 processed earlier; will process 3195 files now Step #5: ==218590== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f748ab79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f74f11c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f74f0ff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f74f0ff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f748abdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f748a1eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f748a19355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f748aafc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f74ba7ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f74ba7ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f74ba7ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f74ba7ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f74ba7ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f74ba7ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f74ba7ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f74ba7ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f74ba7ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f74ba7ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f74dd13f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f74aa40b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f74aa4bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f74a7f7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f74a7f7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f74a7f8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f74a7f7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f74a7f7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f74a7f7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f74f101abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f74f10a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f74f0f2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f74f11d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f58a1740082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f748a17b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf6335bfa8a171c117c9bbbcd26d6068a1a1fc97 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6070 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 639557717 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5616efc1a810, 0x5616efe0401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5616efe04020,0x5616f1c9c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf6335bfa8a171c117c9bbbcd26d6068a1a1fc97' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7835 processed earlier; will process 3194 files now Step #5: #1 pulse cov: 3922 ft: 3923 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4601 ft: 5125 exec/s: 0 rss: 180Mb Step #5: ==218626== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5616e670f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5616ecd74898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5616ecd575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5616ecd574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5616e6715d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5616e6676b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5616e6671355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5616e6707c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5616e96d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5616e96d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5616e96d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5616e96d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5616e96d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5616e96d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5616e96d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5616e96d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5616e96d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5616e96d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5616eb96bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5616e8698b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5616e86a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5616e844fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5616e844fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5616e8450738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5616e844f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5616e844f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5616e844f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5616ecd59abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5616ecd62928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5616ecd4a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5616ecd75112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6700edd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5616e666fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6fc6516fdde37c168cff4fc5d209aba3a00941bf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6071 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 640971386 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d005b1b810, 0x55d005d0501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d005d05020,0x55d007b9d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6fc6516fdde37c168cff4fc5d209aba3a00941bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7838 processed earlier; will process 3191 files now Step #5: ==218662== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cffc6109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d002c75898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d002c585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d002c584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cffc616d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cffc577b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cffc572355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cffc608c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cfff5d7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cfff5d7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cfff5d7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cfff5d7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cfff5d7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cfff5d7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cfff5d7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cfff5d7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cfff5d7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cfff5d7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d00186cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cffe599b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cffe5a4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cffe350c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cffe350c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cffe351738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cffe350874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cffe350874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cffe350874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d002c5aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d002c63928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d002c4b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d002c76112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0c02bab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cffc570b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-93854dad6360940d961c4359802e56174fed12d7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6072 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 641525357 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559cf1e19810, 0x559cf200301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559cf2003020,0x559cf3e9b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93854dad6360940d961c4359802e56174fed12d7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7839 processed earlier; will process 3190 files now Step #5: ==218698== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559ce890e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ceef73898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ceef565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ceef564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ce8914d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ce8875b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ce8870355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ce8906c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ceb8d5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ceb8d5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ceb8d5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ceb8d5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ceb8d5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ceb8d5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ceb8d5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ceb8d5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ceb8d5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ceb8d5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559cedb6af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559cea897b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559cea8a2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559cea64ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559cea64ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559cea64f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559cea64e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559cea64e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559cea64e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ceef58abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ceef61928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ceef49699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ceef74112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7d594d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ce886eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e9bf12d80dfe653b65b26cd035dac62ea09c0eb1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6073 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 642089583 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c1b3b70810, 0x55c1b3d5a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c1b3d5a020,0x55c1b5bf20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e9bf12d80dfe653b65b26cd035dac62ea09c0eb1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7840 processed earlier; will process 3189 files now Step #5: ==218734== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c1aa6659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c1b0cca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c1b0cad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c1b0cad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c1aa66bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c1aa5ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c1aa5c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c1aa65dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c1ad62cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c1ad62cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c1ad62cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c1ad62cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c1ad62cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c1ad62cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c1ad62cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c1ad62cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c1ad62cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c1ad62cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c1af8c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c1ac5eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c1ac5f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c1ac3a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c1ac3a5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c1ac3a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c1ac3a5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c1ac3a5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c1ac3a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c1b0cafabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c1b0cb8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c1b0ca0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c1b0ccb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5f8266f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c1aa5c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-38fa4d3e1f6ef4a4793e2c11490c49c385e236ec Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6074 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 643531134 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565417437810, 0x56541762101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565417621020,0x5654194b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/38fa4d3e1f6ef4a4793e2c11490c49c385e236ec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7841 processed earlier; will process 3188 files now Step #5: ==218770== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56540df2c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565414591898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5654145745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5654145744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56540df32d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56540de93b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56540de8e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56540df24c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x565410ef3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x565410ef3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x565410ef3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x565410ef3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x565410ef3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x565410ef3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x565410ef3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x565410ef3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x565410ef3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x565410ef3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x565413188f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56540feb5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56540fec0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56540fc6cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56540fc6cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56540fc6d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56540fc6c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56540fc6c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56540fc6c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565414576abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56541457f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565414567699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565414592112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4909824082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56540de8cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d69ed21e8e9c2b3e7ba0afe8127742c721250737 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6075 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 644977983 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d1f7d6810, 0x564d1f9c001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d1f9c0020,0x564d218580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d69ed21e8e9c2b3e7ba0afe8127742c721250737' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7842 processed earlier; will process 3187 files now Step #5: ==218806== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d162cb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d1c930898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d1c9135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d1c9134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d162d1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d16232b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d1622d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d162c3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d19292f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d19292f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d19292f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d19292f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d19292f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d19292f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d19292f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d19292f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d19292f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d19292f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d1b527f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d18254b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d1825fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d1800bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d1800bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d1800c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d1800b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d1800b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d1800b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d1c915abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d1c91e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d1c906699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d1c931112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3e80a7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d1622bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3389e338a8bf619def7b99f15e875a77a5f36c3a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6076 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 646132370 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55abe95c2810, 0x55abe97ac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55abe97ac020,0x55abeb6440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3389e338a8bf619def7b99f15e875a77a5f36c3a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7843 processed earlier; will process 3186 files now Step #5: ==218842== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55abe00b79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55abe671c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55abe66ff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55abe66ff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55abe00bdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55abe001eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55abe0019355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55abe00afc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55abe307ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55abe307ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55abe307ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55abe307ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55abe307ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55abe307ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55abe307ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55abe307ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55abe307ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55abe307ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55abe5313f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55abe2040b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55abe204bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55abe1df7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55abe1df7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55abe1df8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55abe1df7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55abe1df7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55abe1df7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55abe6701abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55abe670a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55abe66f2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55abe671d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f10b6f3d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55abe0017b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-984ea7a8ae58bf2a3f8578b54924f4e1e9e56c12 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6077 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 647547695 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f133fb3810, 0x55f13419d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f13419d020,0x55f1360350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/984ea7a8ae58bf2a3f8578b54924f4e1e9e56c12' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7844 processed earlier; will process 3185 files now Step #5: ==218878== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f12aaa89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f13110d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f1310f05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f1310f04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f12aaaed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f12aa0fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f12aa0a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f12aaa0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f12da6ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f12da6ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f12da6ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f12da6ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f12da6ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f12da6ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f12da6ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f12da6ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f12da6ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f12da6ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f12fd04f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f12ca31b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f12ca3cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f12c7e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f12c7e8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f12c7e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f12c7e8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f12c7e8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f12c7e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f1310f2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f1310fb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f1310e3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f13110e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc6ab194082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f12aa08b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e5c21273c4b722ad4be4e35b29ac80951962576 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6078 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 648959275 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b2d943b810, 0x55b2d962501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b2d9625020,0x55b2db4bd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e5c21273c4b722ad4be4e35b29ac80951962576' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7845 processed earlier; will process 3184 files now Step #5: ==218914== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b2cff309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b2d6595898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b2d65785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b2d65784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b2cff36d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b2cfe97b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b2cfe92355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b2cff28c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b2d2ef7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b2d2ef7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b2d2ef7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b2d2ef7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b2d2ef7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b2d2ef7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b2d2ef7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b2d2ef7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b2d2ef7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b2d2ef7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b2d518cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b2d1eb9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b2d1ec4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b2d1c70c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b2d1c70c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b2d1c71738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b2d1c70874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b2d1c70874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b2d1c70874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b2d657aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b2d6583928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b2d656b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b2d6596112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5259105082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b2cfe90b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-198906a0d44a38047f46ddfc9bd5875fa927ed77 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6079 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 650372580 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556de6e2c810, 0x556de701601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556de7016020,0x556de8eae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/198906a0d44a38047f46ddfc9bd5875fa927ed77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7846 processed earlier; will process 3183 files now Step #5: ==218950== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556ddd9219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556de3f86898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556de3f695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556de3f694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556ddd927d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556ddd888b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556ddd883355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556ddd919c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556de08e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556de08e8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556de08e8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556de08e8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556de08e8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556de08e8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556de08e8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556de08e8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556de08e8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556de08e8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556de2b7df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556ddf8aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556ddf8b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556ddf661c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556ddf661c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556ddf662738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556ddf661874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556ddf661874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556ddf661874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556de3f6babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556de3f74928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556de3f5c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556de3f87112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4a55dda082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556ddd881b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5698078d5df064c234075d41bd6d099117547f93 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6080 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 651717221 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5563df894810, 0x5563dfa7e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5563dfa7e020,0x5563e19160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5698078d5df064c234075d41bd6d099117547f93' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7847 processed earlier; will process 3182 files now Step #5: ==218986== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5563d63899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5563dc9ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5563dc9d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5563dc9d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5563d638fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5563d62f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5563d62eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5563d6381c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5563d9350f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5563d9350f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5563d9350f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5563d9350f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5563d9350f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5563d9350f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5563d9350f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5563d9350f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5563d9350f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5563d9350f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5563db5e5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5563d8312b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5563d831dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5563d80c9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5563d80c9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5563d80ca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5563d80c9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5563d80c9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5563d80c9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5563dc9d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5563dc9dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5563dc9c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5563dc9ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff938830082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5563d62e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4e2d376db74fd3518cc4828f02387e32af209687 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6081 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 652332279 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c9eca58810, 0x55c9ecc4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c9ecc42020,0x55c9eeada0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e2d376db74fd3518cc4828f02387e32af209687' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7848 processed earlier; will process 3181 files now Step #5: ==219022== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c9e354d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c9e9bb2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9e9b955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9e9b954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9e3553d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9e34b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c9e34af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9e3545c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c9e6514f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c9e6514f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c9e6514f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c9e6514f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c9e6514f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c9e6514f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c9e6514f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c9e6514f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c9e6514f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c9e6514f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c9e87a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9e54d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9e54e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c9e528dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c9e528dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c9e528e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c9e528d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c9e528d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c9e528d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c9e9b97abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c9e9ba0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c9e9b88699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c9e9bb3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe15cea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c9e34adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ad37fe8830c6ffe3696dd419e2e95584ed3e7ad Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6082 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 653705966 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b9fbe0810, 0x560b9fdca01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b9fdca020,0x560ba1c620e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ad37fe8830c6ffe3696dd419e2e95584ed3e7ad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7849 processed earlier; will process 3180 files now Step #5: ==219058== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560b966d59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b9cd3a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b9cd1d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b9cd1d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b966dbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b9663cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b96637355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b966cdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b9969cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b9969cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b9969cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b9969cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b9969cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b9969cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b9969cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b9969cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b9969cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b9969cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b9b931f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b9865eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b98669be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b98415c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b98415c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b98416738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b98415874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b98415874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b98415874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b9cd1fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b9cd28928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b9cd10699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b9cd3b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c48a27082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b96635b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c88f7f167e7099de936161e795addfbe315920f9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6083 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 654256561 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55df43b21810, 0x55df43d0b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55df43d0b020,0x55df45ba30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c88f7f167e7099de936161e795addfbe315920f9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7850 processed earlier; will process 3179 files now Step #5: ==219094== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55df3a6169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55df40c7b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55df40c5e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55df40c5e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55df3a61cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55df3a57db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55df3a578355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55df3a60ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55df3d5ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55df3d5ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55df3d5ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55df3d5ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55df3d5ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55df3d5ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55df3d5ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55df3d5ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55df3d5ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55df3d5ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55df3f872f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55df3c59fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55df3c5aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55df3c356c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55df3c356c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55df3c357738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55df3c356874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55df3c356874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55df3c356874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55df40c60abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55df40c69928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55df40c51699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55df40c7c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd35f155082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55df3a576b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a4bdcf9d1b7f3407ec4613b1808a500d7c794801 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6084 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 655495659 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fd6ce16810, 0x55fd6d00001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fd6d000020,0x55fd6ee980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a4bdcf9d1b7f3407ec4613b1808a500d7c794801' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7851 processed earlier; will process 3178 files now Step #5: ==219130== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fd6390b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fd69f70898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fd69f535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fd69f534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fd63911d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fd63872b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fd6386d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fd63903c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fd668d2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fd668d2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fd668d2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fd668d2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fd668d2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fd668d2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fd668d2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fd668d2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fd668d2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fd668d2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fd68b67f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fd65894b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fd6589fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fd6564bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fd6564bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fd6564c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fd6564b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fd6564b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fd6564b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fd69f55abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fd69f5e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fd69f46699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fd69f71112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe7dfa7a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fd6386bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-29990667d08700dda2585712846e36bd5bcf4bfc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6085 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 656914232 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555d5b595810, 0x555d5b77f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555d5b77f020,0x555d5d6170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/29990667d08700dda2585712846e36bd5bcf4bfc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7852 processed earlier; will process 3177 files now Step #5: ==219166== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555d5208a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555d586ef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555d586d25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555d586d24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555d52090d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555d51ff1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555d51fec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555d52082c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555d55051f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555d55051f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555d55051f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555d55051f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555d55051f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555d55051f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555d55051f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555d55051f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555d55051f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555d55051f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555d572e6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555d54013b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555d5401ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555d53dcac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555d53dcac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555d53dcb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555d53dca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555d53dca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555d53dca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555d586d4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555d586dd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555d586c5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555d586f0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f390dd30082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555d51feab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a6de50d06f2bc0fc5e628ac1798b8c80cf2d9ccc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6086 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 658346561 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55856623f810, 0x55856642901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558566429020,0x5585682c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a6de50d06f2bc0fc5e628ac1798b8c80cf2d9ccc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7853 processed earlier; will process 3176 files now Step #5: ==219202== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55855cd349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558563399898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55856337c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55856337c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55855cd3ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55855cc9bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55855cc96355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55855cd2cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55855fcfbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55855fcfbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55855fcfbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55855fcfbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55855fcfbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55855fcfbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55855fcfbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55855fcfbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55855fcfbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55855fcfbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558561f90f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55855ecbdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55855ecc8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55855ea74c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55855ea74c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55855ea75738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55855ea74874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55855ea74874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55855ea74874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55856337eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558563387928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55856336f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55856339a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f662ff57082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55855cc94b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-dae986f5333cc09cfd7b1bd9a05c44ef9e8156e5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6087 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 658896610 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558c73cbd810, 0x558c73ea701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558c73ea7020,0x558c75d3f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dae986f5333cc09cfd7b1bd9a05c44ef9e8156e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7854 processed earlier; will process 3175 files now Step #5: ==219238== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558c6a7b29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558c70e17898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558c70dfa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558c70dfa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558c6a7b8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558c6a719b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558c6a714355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558c6a7aac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558c6d779f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558c6d779f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558c6d779f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558c6d779f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558c6d779f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558c6d779f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558c6d779f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558c6d779f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558c6d779f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558c6d779f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558c6fa0ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558c6c73bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558c6c746be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558c6c4f2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558c6c4f2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558c6c4f3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558c6c4f2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558c6c4f2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558c6c4f2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558c70dfcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558c70e05928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558c70ded699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558c70e18112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd5bb8e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558c6a712b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-945ae0b1ea547dad833e1ae5062bb69a48b847c0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6088 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 659478941 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f8180bc810, 0x55f8182a601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f8182a6020,0x55f81a13e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/945ae0b1ea547dad833e1ae5062bb69a48b847c0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7855 processed earlier; will process 3174 files now Step #5: ==219274== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f80ebb19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f815216898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f8151f95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f8151f94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f80ebb7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f80eb18b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f80eb13355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f80eba9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f811b78f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f811b78f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f811b78f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f811b78f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f811b78f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f811b78f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f811b78f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f811b78f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f811b78f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f811b78f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f813e0df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f810b3ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f810b45be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8108f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8108f1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8108f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8108f1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8108f1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8108f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f8151fbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f815204928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f8151ec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f815217112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcdc225e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f80eb11b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-22a8261ed0e6bf36b533345fdfe84864c57efc0f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6089 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 660921201 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564b7fb69810, 0x564b7fd5301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564b7fd53020,0x564b81beb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/22a8261ed0e6bf36b533345fdfe84864c57efc0f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7856 processed earlier; will process 3173 files now Step #5: ==219310== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564b7665e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564b7ccc3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564b7cca65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564b7cca64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564b76664d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564b765c5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564b765c0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564b76656c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564b79625f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564b79625f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564b79625f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564b79625f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564b79625f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564b79625f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564b79625f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564b79625f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564b79625f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564b79625f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564b7b8baf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564b785e7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564b785f2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564b7839ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564b7839ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564b7839f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564b7839e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564b7839e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564b7839e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564b7cca8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564b7ccb1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564b7cc99699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564b7ccc4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc2b5afa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564b765beb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6d89be6f235b61524d87f4f721511d5a1d86d50e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6090 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 662073753 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5595fc74d810, 0x5595fc93701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5595fc937020,0x5595fe7cf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6d89be6f235b61524d87f4f721511d5a1d86d50e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7857 processed earlier; will process 3172 files now Step #5: ==219346== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5595f32429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5595f98a7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5595f988a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5595f988a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5595f3248d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5595f31a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5595f31a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5595f323ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5595f6209f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5595f6209f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5595f6209f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5595f6209f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5595f6209f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5595f6209f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5595f6209f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5595f6209f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5595f6209f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5595f6209f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5595f849ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5595f51cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5595f51d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5595f4f82c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5595f4f82c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5595f4f83738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5595f4f82874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5595f4f82874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5595f4f82874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5595f988cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5595f9895928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5595f987d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5595f98a8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5ef0a74082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5595f31a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-02778b2049939635b35080a7ca7717cd21d9ddc0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6091 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 663441705 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ef985a9810, 0x55ef9879301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ef98793020,0x55ef9a62b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/02778b2049939635b35080a7ca7717cd21d9ddc0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7858 processed earlier; will process 3171 files now Step #5: #1 pulse cov: 13998 ft: 13999 exec/s: 0 rss: 201Mb Step #5: ==219382== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ef8f09e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ef95703898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ef956e65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ef956e64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef8f0a4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef8f005b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef8f000355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef8f096c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef92065f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef92065f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef92065f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef92065f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef92065f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef92065f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef92065f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef92065f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef92065f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef92065f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef942faf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef91027b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef91032be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef90ddec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef90ddec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef90ddf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef90dde874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef90dde874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef90dde874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ef956e8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ef956f1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ef956d9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ef95704112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f669d182082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef8effeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9c6f9ce6ea731da4b051e208262d91833e83914a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6092 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 664127118 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b62a8bc810, 0x55b62aaa601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b62aaa6020,0x55b62c93e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c6f9ce6ea731da4b051e208262d91833e83914a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7860 processed earlier; will process 3169 files now Step #5: ==219418== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b6213b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b627a16898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b6279f95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b6279f94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6213b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b621318b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b621313355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6213a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b624378f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b624378f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b624378f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b624378f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b624378f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b624378f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b624378f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b624378f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b624378f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b624378f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b62660df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b62333ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b623345be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6230f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6230f1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6230f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6230f1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6230f1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6230f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b6279fbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b627a04928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b6279ec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b627a17112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd402e33082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b621311b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c7a53e6a99f90a2fd4869a7e7b942ae0fa276e42 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6093 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 664918962 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a256ee3810, 0x55a2570cd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a2570cd020,0x55a258f650e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c7a53e6a99f90a2fd4869a7e7b942ae0fa276e42' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7861 processed earlier; will process 3168 files now Step #5: ==219454== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a24d9d89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a25403d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2540205dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2540204fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a24d9ded42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a24d93fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a24d93a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a24d9d0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a25099ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a25099ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a25099ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a25099ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a25099ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a25099ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a25099ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a25099ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a25099ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a25099ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a252c34f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a24f961b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a24f96cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a24f718c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a24f718c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a24f719738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a24f718874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a24f718874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a24f718874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a254022abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a25402b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a254013699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a25403e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdf57dce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a24d938b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bd2319bf48f9b4ca60124bfb8c8fe1de95a0d608 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6094 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 665590884 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b04f110810, 0x55b04f2fa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b04f2fa020,0x55b0511920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bd2319bf48f9b4ca60124bfb8c8fe1de95a0d608' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7862 processed earlier; will process 3167 files now Step #5: ==219490== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b045c059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b04c26a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b04c24d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b04c24d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b045c0bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b045b6cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b045b67355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b045bfdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b048bccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b048bccf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b048bccf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b048bccf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b048bccf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b048bccf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b048bccf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b048bccf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b048bccf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b048bccf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b04ae61f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b047b8eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b047b99be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b047945c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b047945c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b047946738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b047945874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b047945874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b047945874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b04c24fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b04c258928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b04c240699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b04c26b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb9a17e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b045b65b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a64d49d67e7f61fa4f9464b3b176fc0d3d82a133 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6095 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 666151793 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556819f6f810, 0x55681a15901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55681a159020,0x55681bff10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a64d49d67e7f61fa4f9464b3b176fc0d3d82a133' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7863 processed earlier; will process 3166 files now Step #5: ==219526== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556810a649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5568170c9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5568170ac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5568170ac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556810a6ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5568109cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5568109c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556810a5cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556813a2bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556813a2bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556813a2bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556813a2bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556813a2bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556813a2bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556813a2bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556813a2bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556813a2bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556813a2bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556815cc0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5568129edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5568129f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5568127a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5568127a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5568127a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5568127a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5568127a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5568127a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5568170aeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5568170b7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55681709f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5568170ca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5ac1d0d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5568109c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2f0466aea52802f573860cf38d29da478cb16ac2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6096 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 667584892 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db49e21810, 0x55db4a00b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db4a00b020,0x55db4bea30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f0466aea52802f573860cf38d29da478cb16ac2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7864 processed earlier; will process 3165 files now Step #5: ==219562== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db409169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db46f7b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db46f5e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db46f5e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db4091cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db4087db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db40878355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db4090ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db438ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db438ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db438ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db438ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db438ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db438ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db438ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db438ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db438ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db438ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db45b72f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db4289fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db428aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db42656c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db42656c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db42657738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db42656874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db42656874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db42656874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db46f60abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db46f69928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db46f51699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db46f7c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc60c89c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db40876b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3fb6d986274206f5c6489e3cdb64d00f4c6a24ae Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6097 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 668974803 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56422eb00810, 0x56422ecea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56422ecea020,0x564230b820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3fb6d986274206f5c6489e3cdb64d00f4c6a24ae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7865 processed earlier; will process 3164 files now Step #5: #1 pulse cov: 12009 ft: 12010 exec/s: 0 rss: 196Mb Step #5: ==219598== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5642255f59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56422bc5a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56422bc3d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56422bc3d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642255fbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56422555cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564225557355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5642255edc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5642285bcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5642285bcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5642285bcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5642285bcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5642285bcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5642285bcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5642285bcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5642285bcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5642285bcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5642285bcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56422a851f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56422757eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564227589be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564227335c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564227335c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564227336738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564227335874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564227335874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564227335874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56422bc3fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56422bc48928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56422bc30699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56422bc5b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb47c65082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564225555b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bc239b780d48a29a337057a8612734fa52afcc04 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6098 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 670469677 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db62e8f810, 0x55db6307901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db63079020,0x55db64f110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bc239b780d48a29a337057a8612734fa52afcc04' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7867 processed earlier; will process 3162 files now Step #5: #1 pulse cov: 4375 ft: 4376 exec/s: 0 rss: 180Mb Step #5: ==219634== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db599849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db5ffe9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db5ffcc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db5ffcc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db5998ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db598ebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db598e6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db5997cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db5c94bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db5c94bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db5c94bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db5c94bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db5c94bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db5c94bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db5c94bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db5c94bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db5c94bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db5c94bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db5ebe0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db5b90db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db5b918be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db5b6c4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db5b6c4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db5b6c5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db5b6c4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db5b6c4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db5b6c4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db5ffceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db5ffd7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db5ffbf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db5ffea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f551c5ea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db598e4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f70122721efa64d405da799d6f63b786fa84e9be Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6099 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 671873998 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aec3f63810, 0x55aec414d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aec414d020,0x55aec5fe50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f70122721efa64d405da799d6f63b786fa84e9be' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7869 processed earlier; will process 3160 files now Step #5: #1 pulse cov: 4268 ft: 4269 exec/s: 0 rss: 180Mb Step #5: ==219670== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aebaa589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aec10bd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aec10a05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aec10a04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aebaa5ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aeba9bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aeba9ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aebaa50c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aebda1ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aebda1ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aebda1ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aebda1ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aebda1ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aebda1ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aebda1ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aebda1ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aebda1ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aebda1ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aebfcb4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aebc9e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aebc9ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aebc798c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aebc798c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aebc799738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aebc798874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aebc798874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aebc798874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aec10a2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aec10ab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aec1093699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aec10be112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa1317da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aeba9b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-65f736e82a1597acc8b52f062812fd017c52cb44 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6100 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 673230107 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bd2042f810, 0x55bd2061901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bd20619020,0x55bd224b10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/65f736e82a1597acc8b52f062812fd017c52cb44' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7871 processed earlier; will process 3158 files now Step #5: ==219706== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bd16f249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bd1d589898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bd1d56c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bd1d56c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bd16f2ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bd16e8bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bd16e86355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bd16f1cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bd19eebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bd19eebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bd19eebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bd19eebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bd19eebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bd19eebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bd19eebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bd19eebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bd19eebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bd19eebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bd1c180f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bd18eadb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bd18eb8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bd18c64c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bd18c64c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bd18c65738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bd18c64874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bd18c64874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bd18c64874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bd1d56eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bd1d577928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bd1d55f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bd1d58a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff0cf374082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bd16e84b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-87128c78837726ed7ef751dca02af97183c564c7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6101 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 673793641 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c27aaf9810, 0x55c27ace301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c27ace3020,0x55c27cb7b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87128c78837726ed7ef751dca02af97183c564c7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7872 processed earlier; will process 3157 files now Step #5: #1 pulse cov: 3733 ft: 3734 exec/s: 0 rss: 179Mb Step #5: ==219742== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c2715ee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c277c53898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c277c365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c277c364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c2715f4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c271555b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c271550355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c2715e6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c2745b5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c2745b5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c2745b5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c2745b5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c2745b5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c2745b5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c2745b5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c2745b5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c2745b5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c2745b5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c27684af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c273577b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c273582be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c27332ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c27332ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c27332f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c27332e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c27332e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c27332e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c277c38abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c277c41928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c277c29699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c277c54112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1263e1a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c27154eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-25c5848a751046a57012b0c8ae364f77a1fe5146 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6102 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 675025964 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ffb989810, 0x559ffbb7301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ffbb73020,0x559ffda0b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/25c5848a751046a57012b0c8ae364f77a1fe5146' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7874 processed earlier; will process 3155 files now Step #5: ==219778== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559ff247e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ff8ae3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ff8ac65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ff8ac64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ff2484d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ff23e5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ff23e0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ff2476c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ff5445f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ff5445f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ff5445f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ff5445f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ff5445f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ff5445f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ff5445f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ff5445f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ff5445f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ff5445f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ff76daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559ff4407b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559ff4412be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559ff41bec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559ff41bec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559ff41bf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559ff41be874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559ff41be874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559ff41be874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ff8ac8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ff8ad1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ff8ab9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ff8ae4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6f572b6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ff23deb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c69aeac12c3c346b38c5f3cac8210d3eb1225778 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6103 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 675659995 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8ff221810, 0x55c8ff40b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c8ff40b020,0x55c9012a30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c69aeac12c3c346b38c5f3cac8210d3eb1225778' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7875 processed earlier; will process 3154 files now Step #5: #1 pulse cov: 3967 ft: 3968 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4515 ft: 4931 exec/s: 0 rss: 182Mb Step #5: ==219814== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c8f5d169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8fc37b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8fc35e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8fc35e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c8f5d1cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c8f5c7db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c8f5c78355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c8f5d0ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c8f8cddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c8f8cddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c8f8cddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c8f8cddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c8f8cddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c8f8cddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c8f8cddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c8f8cddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c8f8cddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c8f8cddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c8faf72f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c8f7c9fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c8f7caabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c8f7a56c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c8f7a56c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c8f7a57738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c8f7a56874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c8f7a56874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c8f7a56874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8fc360abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8fc369928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8fc351699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8fc37c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba311e7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c8f5c76b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b246517b7e54591d9f68b62d0854cf219f6265c1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6104 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 676448876 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dff6632810, 0x55dff681c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dff681c020,0x55dff86b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b246517b7e54591d9f68b62d0854cf219f6265c1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7878 processed earlier; will process 3151 files now Step #5: #1 pulse cov: 4346 ft: 4347 exec/s: 0 rss: 181Mb Step #5: ==219850== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dfed1279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dff378c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dff376f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dff376f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dfed12dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dfed08eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dfed089355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dfed11fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dff00eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dff00eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dff00eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dff00eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dff00eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dff00eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dff00eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dff00eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dff00eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dff00eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dff2383f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dfef0b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dfef0bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dfeee67c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dfeee67c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dfeee68738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dfeee67874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dfeee67874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dfeee67874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dff3771abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dff377a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dff3762699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dff378d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f98aafc8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dfed087b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a70a8fab4d88a39ae3900547ac022726d882f446 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6105 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 677062162 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a51c41810, 0x560a51e2b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a51e2b020,0x560a53cc30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a70a8fab4d88a39ae3900547ac022726d882f446' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7880 processed earlier; will process 3149 files now Step #5: ==219886== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560a487369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a4ed9b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a4ed7e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a4ed7e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a4873cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a4869db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a48698355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a4872ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a4b6fdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a4b6fdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a4b6fdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a4b6fdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a4b6fdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a4b6fdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a4b6fdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a4b6fdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a4b6fdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a4b6fdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a4d992f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a4a6bfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a4a6cabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a4a476c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a4a476c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a4a477738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a4a476874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a4a476874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a4a476874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a4ed80abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a4ed89928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a4ed71699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a4ed9c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faaeba12082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a48696b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-84fab68ce13294bee370359063a41b1a132c9217 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6106 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 677855508 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564c0e3e5810, 0x564c0e5cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564c0e5cf020,0x564c104670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/84fab68ce13294bee370359063a41b1a132c9217' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7881 processed earlier; will process 3148 files now Step #5: #1 pulse cov: 3878 ft: 3879 exec/s: 0 rss: 179Mb Step #5: ==219922== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564c04eda9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564c0b53f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564c0b5225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564c0b5224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564c04ee0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564c04e41b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564c04e3c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564c04ed2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564c07ea1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564c07ea1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564c07ea1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564c07ea1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564c07ea1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564c07ea1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564c07ea1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564c07ea1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564c07ea1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564c07ea1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564c0a136f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564c06e63b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564c06e6ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564c06c1ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564c06c1ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564c06c1b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564c06c1a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564c06c1a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564c06c1a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564c0b524abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564c0b52d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564c0b515699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564c0b540112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcbbd41b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564c04e3ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7abf010a6e7d4c600454d4916bff7a96f767124b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6107 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 678700180 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558038b8e810, 0x558038d7801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558038d78020,0x55803ac100e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7abf010a6e7d4c600454d4916bff7a96f767124b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7883 processed earlier; will process 3146 files now Step #5: ==219958== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55802f6839c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558035ce8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558035ccb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558035ccb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55802f689d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55802f5eab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55802f5e5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55802f67bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55803264af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55803264af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55803264af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55803264af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55803264af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55803264af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55803264af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55803264af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55803264af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55803264af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5580348dff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55803160cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558031617be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580313c3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580313c3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580313c4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580313c3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580313c3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580313c3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558035ccdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558035cd6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558035cbe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558035ce9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5e5db15082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55802f5e3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a03843b860a441b36d0b5fa26280040c732451fe Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6108 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 679497698 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56297b827810, 0x56297ba1101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56297ba11020,0x56297d8a90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a03843b860a441b36d0b5fa26280040c732451fe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7884 processed earlier; will process 3145 files now Step #5: #1 pulse cov: 16631 ft: 16632 exec/s: 0 rss: 205Mb Step #5: ==219994== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56297231c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562978981898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5629789645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5629789644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562972322d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562972283b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56297227e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562972314c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5629752e3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5629752e3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5629752e3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5629752e3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5629752e3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5629752e3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5629752e3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5629752e3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5629752e3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5629752e3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562977578f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629742a5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629742b0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56297405cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56297405cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56297405d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56297405c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56297405c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56297405c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562978966abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56297896f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562978957699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562978982112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f400d596082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56297227cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fb6500efeb6ba10b26fe9300888aa0382c86f598 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6109 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 680419849 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5654c99da810, 0x5654c9bc401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5654c9bc4020,0x5654cba5c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fb6500efeb6ba10b26fe9300888aa0382c86f598' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7886 processed earlier; will process 3143 files now Step #5: ==220030== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5654c04cf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5654c6b34898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5654c6b175dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5654c6b174fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5654c04d5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5654c0436b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5654c0431355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5654c04c7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5654c3496f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5654c3496f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5654c3496f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5654c3496f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5654c3496f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5654c3496f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5654c3496f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5654c3496f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5654c3496f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5654c3496f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5654c572bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5654c2458b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5654c2463be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5654c220fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5654c220fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5654c2210738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5654c220f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5654c220f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5654c220f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5654c6b19abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5654c6b22928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5654c6b0a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5654c6b35112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f013807f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5654c042fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-09e1c01902bc424da8ca8a105b8cd19a5b6280af Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6110 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 680984373 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557f94bf8810, 0x557f94de201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557f94de2020,0x557f96c7a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/09e1c01902bc424da8ca8a105b8cd19a5b6280af' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7887 processed earlier; will process 3142 files now Step #5: ==220066== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557f8b6ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f91d52898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f91d355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f91d354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f8b6f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f8b654b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f8b64f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f8b6e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f8e6b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f8e6b4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f8e6b4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f8e6b4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f8e6b4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f8e6b4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f8e6b4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f8e6b4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f8e6b4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f8e6b4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f90949f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f8d676b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f8d681be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f8d42dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f8d42dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f8d42e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f8d42d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f8d42d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f8d42d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f91d37abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f91d40928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f91d28699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f91d53112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbd30a1e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f8b64db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d5c2ff589f88dcbbc9c7078afd91c2bda6d16886 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6111 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 682426558 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5579717f8810, 0x5579719e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5579719e2020,0x55797387a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d5c2ff589f88dcbbc9c7078afd91c2bda6d16886' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7888 processed earlier; will process 3141 files now Step #5: #1 pulse cov: 12519 ft: 12520 exec/s: 0 rss: 199Mb Step #5: ==220102== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5579682ed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55796e952898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55796e9355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55796e9354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5579682f3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557968254b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55796824f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5579682e5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55796b2b4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55796b2b4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55796b2b4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55796b2b4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55796b2b4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55796b2b4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55796b2b4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55796b2b4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55796b2b4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55796b2b4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55796d549f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55796a276b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55796a281be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55796a02dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55796a02dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55796a02e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55796a02d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55796a02d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55796a02d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55796e937abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55796e940928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55796e928699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55796e953112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac0e626082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55796824db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-472c275d29c7606a219bb61f475fedb0bac857c8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6112 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 683219209 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b85955d810, 0x55b85974701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b859747020,0x55b85b5df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/472c275d29c7606a219bb61f475fedb0bac857c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7890 processed earlier; will process 3139 files now Step #5: #1 pulse cov: 4091 ft: 4092 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4466 ft: 5053 exec/s: 0 rss: 179Mb Step #5: #4 pulse cov: 4756 ft: 6054 exec/s: 0 rss: 181Mb Step #5: ==220138== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b8500529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b8566b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b85669a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b85669a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b850058d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b84ffb9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b84ffb4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b85004ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b853019f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b853019f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b853019f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b853019f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b853019f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b853019f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b853019f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b853019f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b853019f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b853019f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b8552aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b851fdbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b851fe6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b851d92c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b851d92c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b851d93738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b851d92874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b851d92874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b851d92874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b85669cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b8566a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b85668d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b8566b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f839d328082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b84ffb2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8cd53199ddd81c338e5b820dc1bc7e70e3da72ff Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6113 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 684879046 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55625c97d810, 0x55625cb6701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55625cb67020,0x55625e9ff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8cd53199ddd81c338e5b820dc1bc7e70e3da72ff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7895 processed earlier; will process 3134 files now Step #5: ==220174== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5562534729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556259ad7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556259aba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556259aba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556253478d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5562533d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5562533d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55625346ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556256439f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556256439f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556256439f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556256439f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556256439f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556256439f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556256439f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556256439f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556256439f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556256439f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5562586cef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5562553fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556255406be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5562551b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5562551b2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5562551b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5562551b2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5562551b2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5562551b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556259abcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556259ac5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556259aad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556259ad8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f84d221d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5562533d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4332551c543377afc80134fcf304b96865e46c75 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6114 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 686399124 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5584d8435810, 0x5584d861f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5584d861f020,0x5584da4b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4332551c543377afc80134fcf304b96865e46c75' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7896 processed earlier; will process 3133 files now Step #5: ==220210== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5584cef2a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5584d558f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5584d55725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5584d55724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5584cef30d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5584cee91b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5584cee8c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5584cef22c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5584d1ef1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5584d1ef1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5584d1ef1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5584d1ef1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5584d1ef1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5584d1ef1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5584d1ef1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5584d1ef1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5584d1ef1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5584d1ef1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5584d4186f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5584d0eb3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5584d0ebebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5584d0c6ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5584d0c6ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5584d0c6b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5584d0c6a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5584d0c6a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5584d0c6a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5584d5574abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5584d557d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5584d5565699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5584d5590112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efdec9dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5584cee8ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-feff21d34a55f94a64e876fde8537ef72bcff052 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6115 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 687908445 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db4968c810, 0x55db4987601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db49876020,0x55db4b70e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/feff21d34a55f94a64e876fde8537ef72bcff052' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7897 processed earlier; will process 3132 files now Step #5: ==220246== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db401819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db467e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db467c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db467c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db40187d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db400e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db400e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db40179c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db43148f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db43148f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db43148f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db43148f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db43148f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db43148f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db43148f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db43148f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db43148f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db43148f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db453ddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db4210ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db42115be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db41ec1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db41ec1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db41ec2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db41ec1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db41ec1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db41ec1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db467cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db467d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db467bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db467e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffbf01fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db400e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b231ed5d6efe35042e5acba3af36ce284c25ae56 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6116 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 689416710 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f082d0a810, 0x55f082ef401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f082ef4020,0x55f084d8c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b231ed5d6efe35042e5acba3af36ce284c25ae56' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7898 processed earlier; will process 3131 files now Step #5: ==220282== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f0797ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f07fe64898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f07fe475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f07fe474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f079805d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f079766b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f079761355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f0797f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f07c7c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f07c7c6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f07c7c6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f07c7c6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f07c7c6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f07c7c6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f07c7c6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f07c7c6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f07c7c6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f07c7c6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f07ea5bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f07b788b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f07b793be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f07b53fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f07b53fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f07b540738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f07b53f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f07b53f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f07b53f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f07fe49abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f07fe52928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f07fe3a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f07fe65112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3b1792082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f07975fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2c85e89c4dcae465ab4b47164cfd438980fef975 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6117 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 690048061 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562948548810, 0x56294873201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562948732020,0x56294a5ca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2c85e89c4dcae465ab4b47164cfd438980fef975' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7899 processed earlier; will process 3130 files now Step #5: ==220318== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56293f03d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5629456a2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5629456855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5629456854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56293f043d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56293efa4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56293ef9f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56293f035c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562942004f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562942004f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562942004f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562942004f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562942004f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562942004f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562942004f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562942004f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562942004f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562942004f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562944299f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562940fc6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562940fd1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562940d7dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562940d7dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562940d7e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562940d7d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562940d7d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562940d7d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562945687abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562945690928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562945678699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5629456a3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d0cf76082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56293ef9db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ecc565522434e99e357aeef9c439664c747a6aca Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6118 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 690682493 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56439f53a810, 0x56439f72401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56439f724020,0x5643a15bc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ecc565522434e99e357aeef9c439664c747a6aca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7900 processed earlier; will process 3129 files now Step #5: #1 pulse cov: 3797 ft: 3798 exec/s: 0 rss: 177Mb Step #5: ==220354== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56439602f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56439c694898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56439c6775dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56439c6774fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564396035d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564395f96b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564395f91355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564396027c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564398ff6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564398ff6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564398ff6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564398ff6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564398ff6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564398ff6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564398ff6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564398ff6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564398ff6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564398ff6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56439b28bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564397fb8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564397fc3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564397d6fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564397d6fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564397d70738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564397d6f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564397d6f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564397d6f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56439c679abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56439c682928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56439c66a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56439c695112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdfe6ab0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564395f8fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9c33a79c31d94a8a6d4017824e198449702232ce Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6119 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 691329149 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5581275f0810, 0x5581277da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5581277da020,0x5581296720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9c33a79c31d94a8a6d4017824e198449702232ce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7902 processed earlier; will process 3127 files now Step #5: ==220390== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55811e0e59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55812474a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55812472d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55812472d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55811e0ebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55811e04cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55811e047355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55811e0ddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5581210acf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5581210acf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5581210acf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5581210acf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5581210acf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5581210acf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5581210acf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5581210acf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5581210acf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5581210acf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558123341f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55812006eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558120079be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55811fe25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55811fe25c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55811fe26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55811fe25874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55811fe25874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55811fe25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55812472fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558124738928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558124720699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55812474b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ad1838082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55811e045b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4d92dd74a0afe193cc989e6fc886ad6dc82dbf9e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6120 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 691946647 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8fe315810, 0x55c8fe4ff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c8fe4ff020,0x55c9003970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4d92dd74a0afe193cc989e6fc886ad6dc82dbf9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7903 processed earlier; will process 3126 files now Step #5: ==220426== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c8f4e0a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c8fb46f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c8fb4525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c8fb4524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c8f4e10d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c8f4d71b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c8f4d6c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c8f4e02c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c8f7dd1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c8f7dd1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c8f7dd1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c8f7dd1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c8f7dd1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c8f7dd1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c8f7dd1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c8f7dd1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c8f7dd1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c8f7dd1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c8fa066f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c8f6d93b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c8f6d9ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c8f6b4ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c8f6b4ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c8f6b4b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c8f6b4a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c8f6b4a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c8f6b4a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c8fb454abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c8fb45d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c8fb445699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c8fb470112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6afdd4a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c8f4d6ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b36b89625f27bb74a304bc3dcad69ebf1be48658 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6121 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 692532130 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5618e948a810, 0x5618e967401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5618e9674020,0x5618eb50c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b36b89625f27bb74a304bc3dcad69ebf1be48658' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7904 processed earlier; will process 3125 files now Step #5: ==220462== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5618dff7f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5618e65e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5618e65c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5618e65c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5618dff85d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5618dfee6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5618dfee1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5618dff77c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5618e2f46f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5618e2f46f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5618e2f46f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5618e2f46f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5618e2f46f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5618e2f46f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5618e2f46f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5618e2f46f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5618e2f46f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5618e2f46f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5618e51dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5618e1f08b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5618e1f13be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5618e1cbfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5618e1cbfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5618e1cc0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5618e1cbf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5618e1cbf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5618e1cbf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5618e65c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5618e65d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5618e65ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5618e65e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1587b98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5618dfedfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d58edc868de23eab150d8b9a4868e58f6a7efcd3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6122 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 693125086 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a71192f810, 0x55a711b1901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a711b19020,0x55a7139b10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d58edc868de23eab150d8b9a4868e58f6a7efcd3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7905 processed earlier; will process 3124 files now Step #5: #1 pulse cov: 11828 ft: 11829 exec/s: 0 rss: 201Mb Step #5: #2 pulse cov: 12155 ft: 16991 exec/s: 0 rss: 204Mb Step #5: ==220498== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a7084249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a70ea89898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a70ea6c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a70ea6c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a70842ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a70838bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a708386355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a70841cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a70b3ebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a70b3ebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a70b3ebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a70b3ebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a70b3ebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a70b3ebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a70b3ebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a70b3ebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a70b3ebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a70b3ebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a70d680f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a70a3adb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a70a3b8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a70a164c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a70a164c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a70a165738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a70a164874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a70a164874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a70a164874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a70ea6eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a70ea77928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a70ea5f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a70ea8a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdceab37082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a708384b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a977656b4daaf169bf7474ee0c6b9dd880ebf79c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6123 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 693900051 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5600708e2810, 0x560070acc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560070acc020,0x5600729640e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a977656b4daaf169bf7474ee0c6b9dd880ebf79c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7908 processed earlier; will process 3121 files now Step #5: ==220534== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5600673d79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56006da3c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56006da1f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56006da1f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5600673ddd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56006733eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560067339355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5600673cfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56006a39ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56006a39ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56006a39ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56006a39ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56006a39ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56006a39ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56006a39ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56006a39ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56006a39ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56006a39ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56006c633f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560069360b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56006936bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560069117c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560069117c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560069118738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560069117874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560069117874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560069117874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56006da21abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56006da2a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56006da12699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56006da3d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ab1d1c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560067337b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-504fa5bca1d45feec3523a6a9acea995cb330df7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6124 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 695615476 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e9db71e810, 0x55e9db90801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e9db908020,0x55e9dd7a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/504fa5bca1d45feec3523a6a9acea995cb330df7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7909 processed earlier; will process 3120 files now Step #5: #1 pulse cov: 4658 ft: 4659 exec/s: 0 rss: 182Mb Step #5: ==220570== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e9d22139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e9d8878898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e9d885b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e9d885b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e9d2219d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e9d217ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e9d2175355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e9d220bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e9d51daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e9d51daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e9d51daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e9d51daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e9d51daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e9d51daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e9d51daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e9d51daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e9d51daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e9d51daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e9d746ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e9d419cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e9d41a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e9d3f53c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e9d3f53c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e9d3f54738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e9d3f53874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e9d3f53874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e9d3f53874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e9d885dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e9d8866928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e9d884e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e9d8879112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b9a42a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e9d2173b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-abc531e55ab3277c45aa72b6cb8ffe8cada844c5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6125 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 696237531 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf5d3b4810, 0x55bf5d59e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf5d59e020,0x55bf5f4360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/abc531e55ab3277c45aa72b6cb8ffe8cada844c5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7911 processed earlier; will process 3118 files now Step #5: ==220606== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bf53ea99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf5a50e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf5a4f15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf5a4f14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf53eafd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf53e10b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf53e0b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf53ea1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf56e70f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf56e70f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf56e70f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf56e70f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf56e70f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf56e70f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf56e70f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf56e70f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf56e70f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf56e70f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf59105f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf55e32b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf55e3dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf55be9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf55be9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf55bea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf55be9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf55be9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf55be9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf5a4f3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf5a4fc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf5a4e4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf5a50f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f227d78a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf53e09b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3f1b48974709e3d730ef233bd14697319362e976 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6126 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 696785849 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56285baf3810, 0x56285bcdd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56285bcdd020,0x56285db750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3f1b48974709e3d730ef233bd14697319362e976' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7912 processed earlier; will process 3117 files now Step #5: ==220642== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5628525e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562858c4d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562858c305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562858c304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5628525eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56285254fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56285254a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5628525e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5628555aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5628555aff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5628555aff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5628555aff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5628555aff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5628555aff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5628555aff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5628555aff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5628555aff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5628555aff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562857844f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562854571b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56285457cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562854328c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562854328c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562854329738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562854328874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562854328874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562854328874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562858c32abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562858c3b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562858c23699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562858c4e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4160bee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562852548b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c8fdfb66c93f4f2f6ae20a7d7a2faf02b840e89b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6127 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 697350722 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5581bd466810, 0x5581bd65001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5581bd650020,0x5581bf4e80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c8fdfb66c93f4f2f6ae20a7d7a2faf02b840e89b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7913 processed earlier; will process 3116 files now Step #5: ==220678== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5581b3f5b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5581ba5c0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5581ba5a35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5581ba5a34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5581b3f61d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5581b3ec2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5581b3ebd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5581b3f53c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5581b6f22f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5581b6f22f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5581b6f22f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5581b6f22f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5581b6f22f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5581b6f22f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5581b6f22f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5581b6f22f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5581b6f22f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5581b6f22f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5581b91b7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5581b5ee4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5581b5eefbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5581b5c9bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5581b5c9bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5581b5c9c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5581b5c9b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5581b5c9b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5581b5c9b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5581ba5a5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5581ba5ae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5581ba596699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5581ba5c1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f10f3537082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5581b3ebbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-836726e9b1571a29fe360e0f4ecb8d25b0fe5a4d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6128 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 697908711 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561010c1c810, 0x561010e0601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561010e06020,0x561012c9e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/836726e9b1571a29fe360e0f4ecb8d25b0fe5a4d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7914 processed earlier; will process 3115 files now Step #5: #1 pulse cov: 11028 ft: 11029 exec/s: 0 rss: 198Mb Step #5: #2 pulse cov: 12359 ft: 13145 exec/s: 0 rss: 201Mb Step #5: #4 pulse cov: 12490 ft: 14228 exec/s: 0 rss: 202Mb Step #5: ==220714== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5610077119c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56100dd76898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56100dd595dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56100dd594fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561007717d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561007678b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561007673355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561007709c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56100a6d8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56100a6d8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56100a6d8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56100a6d8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56100a6d8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56100a6d8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56100a6d8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56100a6d8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56100a6d8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56100a6d8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56100c96df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56100969ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610096a5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561009451c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561009451c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561009452738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561009451874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561009451874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561009451874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56100dd5babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56100dd64928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56100dd4c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56100dd77112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ddc579082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561007671b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d459dd45a8f4bb2081a665d1272980db62467f9f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6129 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 698689229 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dd85394810, 0x55dd8557e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dd8557e020,0x55dd874160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d459dd45a8f4bb2081a665d1272980db62467f9f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7919 processed earlier; will process 3110 files now Step #5: ==220750== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dd7be899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dd824ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dd824d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dd824d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dd7be8fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dd7bdf0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dd7bdeb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dd7be81c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dd7ee50f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dd7ee50f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dd7ee50f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dd7ee50f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dd7ee50f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dd7ee50f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dd7ee50f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dd7ee50f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dd7ee50f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dd7ee50f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dd810e5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dd7de12b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dd7de1dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dd7dbc9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dd7dbc9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dd7dbca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dd7dbc9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dd7dbc9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dd7dbc9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dd824d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dd824dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dd824c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dd824ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f09a84082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dd7bde9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-dbdba04b96336d5c6aa42504f05ea1de4f1aabd7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6130 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 699373918 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571ed108810, 0x5571ed2f201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571ed2f2020,0x5571ef18a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dbdba04b96336d5c6aa42504f05ea1de4f1aabd7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7920 processed earlier; will process 3109 files now Step #5: ==220786== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571e3bfd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571ea262898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571ea2455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571ea2454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571e3c03d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571e3b64b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571e3b5f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571e3bf5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571e6bc4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571e6bc4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571e6bc4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571e6bc4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571e6bc4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571e6bc4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571e6bc4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571e6bc4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571e6bc4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571e6bc4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571e8e59f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571e5b86b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571e5b91be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571e593dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571e593dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571e593e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571e593d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571e593d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571e593d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571ea247abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571ea250928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571ea238699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571ea263112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f34f19e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571e3b5db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-43b4b3d9f8ffd4080394ecd039853130cc0d34fa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6131 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 699951239 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558584a7b810, 0x558584c6501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558584c65020,0x558586afd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/43b4b3d9f8ffd4080394ecd039853130cc0d34fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7921 processed earlier; will process 3108 files now Step #5: #1 pulse cov: 3694 ft: 3695 exec/s: 0 rss: 181Mb Step #5: ==220822== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55857b5709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558581bd5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558581bb85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558581bb84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55857b576d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55857b4d7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55857b4d2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55857b568c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55857e537f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55857e537f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55857e537f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55857e537f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55857e537f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55857e537f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55857e537f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55857e537f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55857e537f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55857e537f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5585807ccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55857d4f9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55857d504be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55857d2b0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55857d2b0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55857d2b1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55857d2b0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55857d2b0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55857d2b0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558581bbaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558581bc3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558581bab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558581bd6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8aa99a1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55857b4d0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d090eb84eb41db018144f1107bef2b24e7939887 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6132 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 700710387 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e022296810, 0x55e02248001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e022480020,0x55e0243180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d090eb84eb41db018144f1107bef2b24e7939887' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7923 processed earlier; will process 3106 files now Step #5: ==220858== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e018d8b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e01f3f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e01f3d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e01f3d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e018d91d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e018cf2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e018ced355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e018d83c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e01bd52f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e01bd52f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e01bd52f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e01bd52f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e01bd52f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e01bd52f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e01bd52f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e01bd52f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e01bd52f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e01bd52f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e01dfe7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e01ad14b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e01ad1fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e01aacbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e01aacbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e01aacc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e01aacb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e01aacb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e01aacb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e01f3d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e01f3de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e01f3c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e01f3f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f680bd13082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e018cebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5c3c9c5de1b3c8877ba51c97788c543360db1a74 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6133 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 701308730 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f75442e810, 0x55f75461801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f754618020,0x55f7564b00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5c3c9c5de1b3c8877ba51c97788c543360db1a74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7924 processed earlier; will process 3105 files now Step #5: #1 pulse cov: 4173 ft: 4174 exec/s: 0 rss: 182Mb Step #5: ==220894== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f74af239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f751588898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f75156b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f75156b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f74af29d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f74ae8ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f74ae85355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f74af1bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f74deeaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f74deeaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f74deeaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f74deeaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f74deeaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f74deeaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f74deeaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f74deeaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f74deeaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f74deeaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f75017ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f74ceacb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f74ceb7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f74cc63c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f74cc63c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f74cc64738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f74cc63874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f74cc63874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f74cc63874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f75156dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f751576928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f75155e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f751589112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe4f31dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f74ae83b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f3d999c45d34b6ec7366661bad99d818d0a5547b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6134 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 701933247 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ea3836d810, 0x55ea3855701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ea38557020,0x55ea3a3ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f3d999c45d34b6ec7366661bad99d818d0a5547b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7926 processed earlier; will process 3103 files now Step #5: ==220930== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ea2ee629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ea354c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ea354aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ea354aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ea2ee68d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ea2edc9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ea2edc4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ea2ee5ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ea31e29f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ea31e29f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ea31e29f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ea31e29f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ea31e29f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ea31e29f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ea31e29f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ea31e29f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ea31e29f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ea31e29f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ea340bef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ea30debb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ea30df6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ea30ba2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ea30ba2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ea30ba3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ea30ba2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ea30ba2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ea30ba2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ea354acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ea354b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ea3549d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ea354c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb59ed51082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ea2edc2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bcd51fcadb8ad18440cd320c53107dca2c3eafc5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6135 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 702506060 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a821dd5810, 0x55a821fbf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a821fbf020,0x55a823e570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bcd51fcadb8ad18440cd320c53107dca2c3eafc5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7927 processed earlier; will process 3102 files now Step #5: #1 pulse cov: 3552 ft: 3553 exec/s: 0 rss: 180Mb Step #5: ==220966== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a8188ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a81ef2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a81ef125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a81ef124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a8188d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a818831b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a81882c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a8188c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a81b891f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a81b891f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a81b891f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a81b891f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a81b891f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a81b891f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a81b891f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a81b891f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a81b891f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a81b891f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a81db26f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a81a853b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a81a85ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a81a60ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a81a60ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a81a60b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a81a60a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a81a60a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a81a60a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a81ef14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a81ef1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a81ef05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a81ef30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f27b7235082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a81882ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-305884e57b761ba736904821ee297e450b647ee6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6136 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 703192780 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55de8c3b1810, 0x55de8c59b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55de8c59b020,0x55de8e4330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/305884e57b761ba736904821ee297e450b647ee6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7929 processed earlier; will process 3100 files now Step #5: ==221002== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55de82ea69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55de8950b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55de894ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55de894ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55de82eacd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55de82e0db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55de82e08355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55de82e9ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55de85e6df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55de85e6df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55de85e6df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55de85e6df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55de85e6df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55de85e6df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55de85e6df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55de85e6df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55de85e6df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55de85e6df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55de88102f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55de84e2fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55de84e3abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55de84be6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55de84be6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55de84be7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55de84be6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55de84be6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55de84be6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55de894f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55de894f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55de894e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55de8950c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fea12225082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55de82e06b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f0c924da58ed54ffd75eb9940fa8df17b52a5c62 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6137 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 703757725 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ba5f70c810, 0x55ba5f8f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ba5f8f6020,0x55ba6178e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f0c924da58ed54ffd75eb9940fa8df17b52a5c62' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7930 processed earlier; will process 3099 files now Step #5: ==221038== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ba562019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ba5c866898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ba5c8495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ba5c8494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ba56207d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ba56168b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ba56163355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ba561f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ba591c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ba591c8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ba591c8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ba591c8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ba591c8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ba591c8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ba591c8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ba591c8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ba591c8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ba591c8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ba5b45df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ba5818ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ba58195be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ba57f41c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ba57f41c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ba57f42738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ba57f41874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ba57f41874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ba57f41874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ba5c84babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ba5c854928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ba5c83c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ba5c867112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4f481bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ba56161b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-408e5d31987691cd4b35f3f910f3ec3738220452 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6138 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 704391597 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557a3b252810, 0x557a3b43c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557a3b43c020,0x557a3d2d40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/408e5d31987691cd4b35f3f910f3ec3738220452' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7931 processed earlier; will process 3098 files now Step #5: ==221074== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557a31d479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557a383ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557a3838f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557a3838f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557a31d4dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557a31caeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557a31ca9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557a31d3fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557a34d0ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557a34d0ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557a34d0ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557a34d0ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557a34d0ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557a34d0ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557a34d0ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557a34d0ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557a34d0ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557a34d0ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557a36fa3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557a33cd0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557a33cdbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557a33a87c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557a33a87c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557a33a88738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557a33a87874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557a33a87874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557a33a87874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557a38391abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557a3839a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557a38382699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557a383ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdbff395082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557a31ca7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4e4a2e77fe03596e7f33d901b482524b516baff3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6139 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 704996920 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5604c1d0d810, 0x5604c1ef701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604c1ef7020,0x5604c3d8f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4e4a2e77fe03596e7f33d901b482524b516baff3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7932 processed earlier; will process 3097 files now Step #5: ==221110== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5604b88029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5604bee67898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5604bee4a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5604bee4a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5604b8808d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5604b8769b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5604b8764355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5604b87fac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5604bb7c9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5604bb7c9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5604bb7c9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5604bb7c9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5604bb7c9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5604bb7c9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5604bb7c9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5604bb7c9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5604bb7c9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5604bb7c9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5604bda5ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5604ba78bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5604ba796be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5604ba542c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5604ba542c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5604ba543738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5604ba542874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5604ba542874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5604ba542874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5604bee4cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5604bee55928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5604bee3d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5604bee68112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f569c775082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5604b8762b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-584e05d63c3ec99d003bac58cf60dab0d5a5ddca Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6140 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 705621148 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5588e255a810, 0x5588e274401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5588e2744020,0x5588e45dc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/584e05d63c3ec99d003bac58cf60dab0d5a5ddca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7933 processed earlier; will process 3096 files now Step #5: ==221146== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5588d904f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5588df6b4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5588df6975dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5588df6974fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5588d9055d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588d8fb6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588d8fb1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5588d9047c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5588dc016f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5588dc016f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5588dc016f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5588dc016f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5588dc016f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5588dc016f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5588dc016f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5588dc016f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5588dc016f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5588dc016f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5588de2abf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588dafd8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588dafe3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588dad8fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588dad8fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588dad90738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588dad8f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588dad8f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588dad8f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5588df699abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5588df6a2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5588df68a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5588df6b5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f56f1242082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588d8fafb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f809d6bd3228b0bf2b5080a27e4ce4778867d6ea Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6141 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 706193743 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55584240a810, 0x5558425f401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5558425f4020,0x55584448c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f809d6bd3228b0bf2b5080a27e4ce4778867d6ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7934 processed earlier; will process 3095 files now Step #5: ==221182== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555838eff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55583f564898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55583f5475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55583f5474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555838f05d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555838e66b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555838e61355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555838ef7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55583bec6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55583bec6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55583bec6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55583bec6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55583bec6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55583bec6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55583bec6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55583bec6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55583bec6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55583bec6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55583e15bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55583ae88b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55583ae93be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55583ac3fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55583ac3fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55583ac40738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55583ac3f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55583ac3f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55583ac3f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55583f549abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55583f552928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55583f53a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55583f565112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f66ab12c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555838e5fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e1c7020f72d015ec334bae4b11d7a61b0582a511 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6142 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 706910229 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5582dc1a8810, 0x5582dc39201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5582dc392020,0x5582de22a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e1c7020f72d015ec334bae4b11d7a61b0582a511' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7935 processed earlier; will process 3094 files now Step #5: ==221218== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5582d2c9d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5582d9302898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5582d92e55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5582d92e54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5582d2ca3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5582d2c04b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5582d2bff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5582d2c95c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5582d5c64f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5582d5c64f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5582d5c64f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5582d5c64f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5582d5c64f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5582d5c64f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5582d5c64f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5582d5c64f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5582d5c64f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5582d5c64f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5582d7ef9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5582d4c26b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5582d4c31be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5582d49ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5582d49ddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5582d49de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5582d49dd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5582d49dd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5582d49dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5582d92e7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5582d92f0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5582d92d8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5582d9303112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa6d653a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5582d2bfdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4cd3cb62cb7cfc1b91c90b59cb6768ff2c59cff8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6143 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 707495497 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5573c28bd810, 0x5573c2aa701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5573c2aa7020,0x5573c493f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4cd3cb62cb7cfc1b91c90b59cb6768ff2c59cff8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7936 processed earlier; will process 3093 files now Step #5: ==221254== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5573b93b29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5573bfa17898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5573bf9fa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5573bf9fa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5573b93b8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5573b9319b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5573b9314355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5573b93aac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5573bc379f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5573bc379f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5573bc379f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5573bc379f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5573bc379f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5573bc379f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5573bc379f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5573bc379f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5573bc379f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5573bc379f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5573be60ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5573bb33bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5573bb346be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5573bb0f2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5573bb0f2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5573bb0f3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5573bb0f2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5573bb0f2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5573bb0f2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5573bf9fcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5573bfa05928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5573bf9ed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5573bfa18112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f38e0dc8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5573b9312b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec228d1a0eb440f22fd6425d234e161db09e35af Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6144 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 708081463 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55703e3c4810, 0x55703e5ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55703e5ae020,0x5570404460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec228d1a0eb440f22fd6425d234e161db09e35af' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7937 processed earlier; will process 3092 files now Step #5: ==221290== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557034eb99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55703b51e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55703b5015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55703b5014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557034ebfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557034e20b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557034e1b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557034eb1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557037e80f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557037e80f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557037e80f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557037e80f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557037e80f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557037e80f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557037e80f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557037e80f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557037e80f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557037e80f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55703a115f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557036e42b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557036e4dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557036bf9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557036bf9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557036bfa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557036bf9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557036bf9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557036bf9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55703b503abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55703b50c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55703b4f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55703b51f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f790f839082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557034e19b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-efa74427c43314a9806a60b7f310251888e07df8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6145 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 708675382 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d90398810, 0x556d9058201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d90582020,0x556d9241a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/efa74427c43314a9806a60b7f310251888e07df8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7938 processed earlier; will process 3091 files now Step #5: ==221326== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556d86e8d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d8d4f2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d8d4d55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d8d4d54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d86e93d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d86df4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d86def355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d86e85c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d89e54f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d89e54f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d89e54f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d89e54f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d89e54f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d89e54f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d89e54f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d89e54f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d89e54f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d89e54f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d8c0e9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d88e16b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d88e21be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d88bcdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d88bcdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d88bce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d88bcd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d88bcd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d88bcd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d8d4d7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d8d4e0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d8d4c8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d8d4f3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4094dd4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d86dedb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d22f8648b39d10ad1d96502bd4cac868b4fa5b87 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6146 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 709240920 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c0624c7810, 0x55c0626b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c0626b1020,0x55c0645490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d22f8648b39d10ad1d96502bd4cac868b4fa5b87' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7939 processed earlier; will process 3090 files now Step #5: ==221362== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c058fbc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c05f621898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c05f6045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c05f6044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c058fc2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c058f23b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c058f1e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c058fb4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c05bf83f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c05bf83f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c05bf83f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c05bf83f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c05bf83f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c05bf83f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c05bf83f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c05bf83f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c05bf83f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c05bf83f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c05e218f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c05af45b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c05af50be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c05acfcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c05acfcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c05acfd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c05acfc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c05acfc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c05acfc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c05f606abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c05f60f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c05f5f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c05f622112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12f9c98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c058f1cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-32b30fbac086df7aa1c588c100a0531ed9b77ac5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6147 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 709833930 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a5a02b0810, 0x55a5a049a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a5a049a020,0x55a5a23320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/32b30fbac086df7aa1c588c100a0531ed9b77ac5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7940 processed earlier; will process 3089 files now Step #5: #1 pulse cov: 4067 ft: 4068 exec/s: 0 rss: 180Mb Step #5: ==221398== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a596da59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a59d40a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a59d3ed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a59d3ed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a596dabd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a596d0cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a596d07355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a596d9dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a599d6cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a599d6cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a599d6cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a599d6cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a599d6cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a599d6cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a599d6cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a599d6cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a599d6cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a599d6cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a59c001f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a598d2eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a598d39be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a598ae5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a598ae5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a598ae6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a598ae5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a598ae5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a598ae5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a59d3efabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a59d3f8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a59d3e0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a59d40b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7eff6f5a1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a596d05b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1f799a574da32d8201e425be15f06f03f300d898 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6148 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 710453067 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fedb345810, 0x55fedb52f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fedb52f020,0x55fedd3c70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f799a574da32d8201e425be15f06f03f300d898' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7942 processed earlier; will process 3087 files now Step #5: ==221434== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fed1e3a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fed849f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fed84825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fed84824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fed1e40d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fed1da1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fed1d9c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fed1e32c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fed4e01f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fed4e01f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fed4e01f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fed4e01f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fed4e01f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fed4e01f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fed4e01f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fed4e01f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fed4e01f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fed4e01f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fed7096f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fed3dc3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fed3dcebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fed3b7ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fed3b7ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fed3b7b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fed3b7a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fed3b7a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fed3b7a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fed8484abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fed848d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fed8475699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fed84a0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc718098082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fed1d9ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-16742fc36f8cd906ce6fd3ce2edc03fd8fb7e3d3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6149 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 711055684 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ebdd54a810, 0x55ebdd73401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ebdd734020,0x55ebdf5cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16742fc36f8cd906ce6fd3ce2edc03fd8fb7e3d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7943 processed earlier; will process 3086 files now Step #5: ==221470== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ebd403f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ebda6a4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ebda6875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ebda6874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ebd4045d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ebd3fa6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ebd3fa1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ebd4037c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ebd7006f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ebd7006f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ebd7006f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ebd7006f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ebd7006f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ebd7006f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ebd7006f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ebd7006f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ebd7006f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ebd7006f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ebd929bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ebd5fc8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ebd5fd3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ebd5d7fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ebd5d7fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ebd5d80738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ebd5d7f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ebd5d7f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ebd5d7f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ebda689abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ebda692928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ebda67a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ebda6a5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fec4c700082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ebd3f9fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-61b79d2903c70d89417a011e2b6b66d7aa03e354 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6150 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 711653402 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cdd8296810, 0x55cdd848001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cdd8480020,0x55cdda3180e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/61b79d2903c70d89417a011e2b6b66d7aa03e354' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7944 processed earlier; will process 3085 files now Step #5: ==221506== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cdced8b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cdd53f0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cdd53d35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cdd53d34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cdced91d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cdcecf2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cdceced355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cdced83c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cdd1d52f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cdd1d52f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cdd1d52f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cdd1d52f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cdd1d52f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cdd1d52f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cdd1d52f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cdd1d52f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cdd1d52f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cdd1d52f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cdd3fe7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cdd0d14b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cdd0d1fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cdd0acbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cdd0acbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cdd0acc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cdd0acb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cdd0acb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cdd0acb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cdd53d5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cdd53de928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cdd53c6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cdd53f1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffbd460b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cdcecebb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7af97407ab8d9a843e108d32ece2e592cb4281d4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6151 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 712903101 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c09eac6810, 0x55c09ecb001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c09ecb0020,0x55c0a0b480e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7af97407ab8d9a843e108d32ece2e592cb4281d4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7945 processed earlier; will process 3084 files now Step #5: ==221542== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c0955bb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c09bc20898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c09bc035dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c09bc034fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c0955c1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c095522b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c09551d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c0955b3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c098582f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c098582f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c098582f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c098582f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c098582f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c098582f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c098582f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c098582f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c098582f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c098582f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c09a817f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c097544b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c09754fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c0972fbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c0972fbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c0972fc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c0972fb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c0972fb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c0972fb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c09bc05abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c09bc0e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c09bbf6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c09bc21112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7847f84082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c09551bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f78aae8fd3ecb55fbc9b13b60d731dbc863034a0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6152 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 713492119 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565194355810, 0x56519453f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56519453f020,0x5651963d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f78aae8fd3ecb55fbc9b13b60d731dbc863034a0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7946 processed earlier; will process 3083 files now Step #5: ==221578== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56518ae4a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5651914af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651914925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651914924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56518ae50d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56518adb1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56518adac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56518ae42c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56518de11f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56518de11f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56518de11f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56518de11f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56518de11f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56518de11f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56518de11f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56518de11f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56518de11f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56518de11f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5651900a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56518cdd3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56518cddebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56518cb8ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56518cb8ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56518cb8b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56518cb8a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56518cb8a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56518cb8a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565191494abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56519149d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565191485699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5651914b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc38277d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56518adaab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-14b94607c6e981bf400a3d011b09d4df1d6b8be0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6153 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 714080451 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556a0095e810, 0x556a00b4801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556a00b48020,0x556a029e00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/14b94607c6e981bf400a3d011b09d4df1d6b8be0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7947 processed earlier; will process 3082 files now Step #5: ==221614== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5569f74539c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5569fdab8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5569fda9b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5569fda9b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5569f7459d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5569f73bab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5569f73b5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5569f744bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5569fa41af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5569fa41af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5569fa41af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5569fa41af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5569fa41af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5569fa41af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5569fa41af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5569fa41af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5569fa41af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5569fa41af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5569fc6aff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5569f93dcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5569f93e7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5569f9193c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5569f9193c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5569f9194738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5569f9193874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5569f9193874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5569f9193874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5569fda9dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5569fdaa6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5569fda8e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5569fdab9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc094de3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5569f73b3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e4fc3bf5a6b3e83a4d9e73a03b53234a30ddfb12 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6154 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 714734580 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55954a923810, 0x55954ab0d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55954ab0d020,0x55954c9a50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e4fc3bf5a6b3e83a4d9e73a03b53234a30ddfb12' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7948 processed earlier; will process 3081 files now Step #5: ==221650== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5595414189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559547a7d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559547a605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559547a604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55954141ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55954137fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55954137a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559541410c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5595443dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5595443dff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5595443dff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5595443dff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5595443dff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5595443dff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5595443dff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5595443dff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5595443dff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5595443dff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559546674f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5595433a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5595433acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559543158c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559543158c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559543159738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559543158874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559543158874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559543158874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559547a62abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559547a6b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559547a53699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559547a7e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fceb210c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559541378b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-19978203afbc78adfc5883707bdfa83b2f2c90c3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6155 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 715354494 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561708e76810, 0x56170906001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561709060020,0x56170aef80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/19978203afbc78adfc5883707bdfa83b2f2c90c3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7949 processed earlier; will process 3080 files now Step #5: #1 pulse cov: 3696 ft: 3697 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4373 ft: 5036 exec/s: 0 rss: 182Mb Step #5: ==221686== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5616ff96b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561705fd0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561705fb35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561705fb34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5616ff971d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5616ff8d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5616ff8cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5616ff963c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561702932f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561702932f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561702932f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561702932f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561702932f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561702932f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561702932f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561702932f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561702932f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561702932f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561704bc7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5617018f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5617018ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5617016abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5617016abc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5617016ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5617016ab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5617016ab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5617016ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561705fb5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561705fbe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561705fa6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561705fd1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9232f4e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5616ff8cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-686ecfc66e1877ad5ba37574bbc1e70c610a0a32 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6156 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 716015658 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5557d519b810, 0x5557d538501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5557d5385020,0x5557d721d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/686ecfc66e1877ad5ba37574bbc1e70c610a0a32' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7952 processed earlier; will process 3077 files now Step #5: #1 pulse cov: 6443 ft: 6444 exec/s: 0 rss: 191Mb Step #5: ==221722== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5557cbc909c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5557d22f5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557d22d85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557d22d84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557cbc96d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557cbbf7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5557cbbf2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557cbc88c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557cec57f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557cec57f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557cec57f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557cec57f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557cec57f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557cec57f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557cec57f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557cec57f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557cec57f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557cec57f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5557d0eecf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557cdc19b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557cdc24be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5557cd9d0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5557cd9d0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5557cd9d1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5557cd9d0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5557cd9d0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5557cd9d0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557d22daabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557d22e3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557d22cb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5557d22f6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbd5208b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5557cbbf0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-edb4d13dfa92f7d86c79f72fdd522a1e10182589 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6157 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 716681606 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564e5d4d7810, 0x564e5d6c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564e5d6c1020,0x564e5f5590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/edb4d13dfa92f7d86c79f72fdd522a1e10182589' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7954 processed earlier; will process 3075 files now Step #5: #1 pulse cov: 4395 ft: 4396 exec/s: 0 rss: 179Mb Step #5: ==221758== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564e53fcc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564e5a631898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564e5a6145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564e5a6144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564e53fd2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564e53f33b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564e53f2e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564e53fc4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564e56f93f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564e56f93f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564e56f93f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564e56f93f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564e56f93f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564e56f93f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564e56f93f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564e56f93f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564e56f93f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564e56f93f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564e59228f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564e55f55b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564e55f60be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564e55d0cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564e55d0cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564e55d0d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564e55d0c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564e55d0c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564e55d0c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564e5a616abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564e5a61f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564e5a607699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564e5a632112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9e8e68b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564e53f2cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-54fa594ea4918a8965a2ff47073832bc48f662d0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6158 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 717539326 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652cbf52810, 0x5652cc13c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652cc13c020,0x5652cdfd40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/54fa594ea4918a8965a2ff47073832bc48f662d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7956 processed earlier; will process 3073 files now Step #5: ==221794== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5652c2a479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652c90ac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652c908f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652c908f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5652c2a4dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5652c29aeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5652c29a9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5652c2a3fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5652c5a0ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5652c5a0ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5652c5a0ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5652c5a0ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5652c5a0ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5652c5a0ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5652c5a0ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5652c5a0ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5652c5a0ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5652c5a0ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652c7ca3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5652c49d0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5652c49dbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652c4787c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652c4787c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652c4788738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652c4787874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652c4787874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652c4787874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652c9091abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652c909a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652c9082699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652c90ad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f17bc3e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5652c29a7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-67366c02dc8ae4f333018667f227d8c19a165132 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6159 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 718111383 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562fe94c9810, 0x562fe96b301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562fe96b3020,0x562feb54b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/67366c02dc8ae4f333018667f227d8c19a165132' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7957 processed earlier; will process 3072 files now Step #5: #1 pulse cov: 3849 ft: 3850 exec/s: 0 rss: 180Mb Step #5: ==221830== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562fdffbe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562fe6623898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562fe66065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562fe66064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562fdffc4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562fdff25b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562fdff20355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562fdffb6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562fe2f85f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562fe2f85f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562fe2f85f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562fe2f85f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562fe2f85f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562fe2f85f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562fe2f85f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562fe2f85f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562fe2f85f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562fe2f85f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562fe521af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562fe1f47b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562fe1f52be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562fe1cfec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562fe1cfec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562fe1cff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562fe1cfe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562fe1cfe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562fe1cfe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562fe6608abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562fe6611928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562fe65f9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562fe6624112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f519efe4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562fdff1eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9be1c9465b06b308cb8c3fcfc55005c6d6130b67 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6160 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 718784317 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fc471f0810, 0x55fc473da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fc473da020,0x55fc492720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9be1c9465b06b308cb8c3fcfc55005c6d6130b67' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7959 processed earlier; will process 3070 files now Step #5: ==221866== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fc3dce59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fc4434a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fc4432d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fc4432d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fc3dcebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fc3dc4cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fc3dc47355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fc3dcddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fc40cacf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fc40cacf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fc40cacf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fc40cacf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fc40cacf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fc40cacf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fc40cacf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fc40cacf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fc40cacf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fc40cacf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fc42f41f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fc3fc6eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fc3fc79be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fc3fa25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fc3fa25c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fc3fa26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fc3fa25874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fc3fa25874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fc3fa25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fc4432fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fc44338928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fc44320699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fc4434b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff6713b0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fc3dc45b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-24a61c45b3cda664e2b3d9360ed479d90e2ea7a6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6161 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 719528025 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5607396c3810, 0x5607398ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5607398ad020,0x56073b7450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/24a61c45b3cda664e2b3d9360ed479d90e2ea7a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7960 processed earlier; will process 3069 files now Step #5: #1 pulse cov: 3911 ft: 3912 exec/s: 0 rss: 181Mb Step #5: ==221902== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5607301b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56073681d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5607368005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5607368004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5607301bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56073011fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56073011a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5607301b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56073317ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56073317ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56073317ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56073317ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56073317ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56073317ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56073317ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56073317ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56073317ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56073317ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560735414f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560732141b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56073214cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560731ef8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560731ef8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560731ef9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560731ef8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560731ef8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560731ef8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560736802abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56073680b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5607367f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56073681e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd71ffd9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560730118b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fe3dc427997412a7d7aee378d48c45010749ffbd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6162 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 720136199 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564078389810, 0x56407857301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564078573020,0x56407a40b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fe3dc427997412a7d7aee378d48c45010749ffbd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7962 processed earlier; will process 3067 files now Step #5: ==221938== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56406ee7e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5640754e3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640754c65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640754c64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56406ee84d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56406ede5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56406ede0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56406ee76c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564071e45f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564071e45f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564071e45f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564071e45f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564071e45f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564071e45f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564071e45f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564071e45f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564071e45f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564071e45f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5640740daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564070e07b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564070e12be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564070bbec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564070bbec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564070bbf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564070bbe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564070bbe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564070bbe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5640754c8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5640754d1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5640754b9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5640754e4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f966d581082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56406eddeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-94c28ff58534f3040bc7ca43ee87b95af709b5e5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6163 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 720729029 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a4d818810, 0x560a4da0201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a4da02020,0x560a4f89a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/94c28ff58534f3040bc7ca43ee87b95af709b5e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7963 processed earlier; will process 3066 files now Step #5: ==221974== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560a4430d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a4a972898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a4a9555dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a4a9554fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a44313d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a44274b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a4426f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a44305c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a472d4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a472d4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a472d4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a472d4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a472d4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a472d4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a472d4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a472d4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a472d4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a472d4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a49569f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a46296b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a462a1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a4604dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a4604dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a4604e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a4604d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a4604d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a4604d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a4a957abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a4a960928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a4a948699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a4a973112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fafa8d3c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a4426db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f111f46c4b1fb85cc14aad3c480546faca495045 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6164 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 721308580 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cefea21810, 0x55cefec0b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cefec0b020,0x55cf00aa30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f111f46c4b1fb85cc14aad3c480546faca495045' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7964 processed earlier; will process 3065 files now Step #5: ==222010== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cef55169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cefbb7b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cefbb5e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cefbb5e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cef551cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cef547db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cef5478355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cef550ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cef84ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cef84ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cef84ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cef84ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cef84ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cef84ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cef84ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cef84ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cef84ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cef84ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cefa772f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cef749fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cef74aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cef7256c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cef7256c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cef7257738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cef7256874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cef7256874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cef7256874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cefbb60abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cefbb69928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cefbb51699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cefbb7c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e293ce082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cef5476b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d51a29d997b1513ceb7fdbed90d0a5474e692b9b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6165 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 721878319 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559f22c22810, 0x559f22e0c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559f22e0c020,0x559f24ca40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d51a29d997b1513ceb7fdbed90d0a5474e692b9b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7965 processed earlier; will process 3064 files now Step #5: ==222046== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559f197179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559f1fd7c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559f1fd5f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559f1fd5f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559f1971dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559f1967eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559f19679355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559f1970fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559f1c6def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559f1c6def10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559f1c6def10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559f1c6def10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559f1c6def10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559f1c6def10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559f1c6def10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559f1c6def10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559f1c6def10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559f1c6def10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559f1e973f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559f1b6a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559f1b6abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559f1b457c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559f1b457c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559f1b458738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559f1b457874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559f1b457874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559f1b457874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559f1fd61abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559f1fd6a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559f1fd52699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559f1fd7d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd0f71d7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559f19677b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f2c981ead14faff6d1e3df29bfe33678ecdf6749 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6166 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 722520492 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555d024b7810, 0x555d026a101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555d026a1020,0x555d045390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f2c981ead14faff6d1e3df29bfe33678ecdf6749' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7966 processed earlier; will process 3063 files now Step #5: ==222082== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555cf8fac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555cff611898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555cff5f45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555cff5f44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555cf8fb2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555cf8f13b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555cf8f0e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555cf8fa4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555cfbf73f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555cfbf73f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555cfbf73f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555cfbf73f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555cfbf73f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555cfbf73f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555cfbf73f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555cfbf73f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555cfbf73f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555cfbf73f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555cfe208f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555cfaf35b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555cfaf40be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555cfacecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555cfacecc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555cfaced738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555cfacec874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555cfacec874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555cfacec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555cff5f6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555cff5ff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555cff5e7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555cff612112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc7af909082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555cf8f0cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6bf084697be610ab2a624310d0faae75f586080d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6167 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 723082625 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5558e47e4810, 0x5558e49ce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5558e49ce020,0x5558e68660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bf084697be610ab2a624310d0faae75f586080d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7967 processed earlier; will process 3062 files now Step #5: ==222118== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5558db2d99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5558e193e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5558e19215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5558e19214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5558db2dfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5558db240b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5558db23b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5558db2d1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5558de2a0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5558de2a0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5558de2a0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5558de2a0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5558de2a0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5558de2a0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5558de2a0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5558de2a0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5558de2a0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5558de2a0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5558e0535f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5558dd262b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5558dd26dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5558dd019c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5558dd019c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5558dd01a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5558dd019874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5558dd019874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5558dd019874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5558e1923abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5558e192c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5558e1914699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5558e193f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8a7d8d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5558db239b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e2a0724c9110754e574137e4caeab45df512caf1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6168 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 723801114 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d97fff810, 0x561d981e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d981e9020,0x561d9a0810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e2a0724c9110754e574137e4caeab45df512caf1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7968 processed earlier; will process 3061 files now Step #5: ==222154== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d8eaf49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d95159898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d9513c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d9513c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d8eafad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d8ea5bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d8ea56355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d8eaecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d91abbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d91abbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d91abbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d91abbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d91abbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d91abbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d91abbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d91abbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d91abbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d91abbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d93d50f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d90a7db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d90a88be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d90834c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d90834c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d90835738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d90834874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d90834874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d90834874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d9513eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d95147928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d9512f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d9515a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f50d768f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d8ea54b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5324cf82cc23b9050411ce0b605e8fc60cf2ad4b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6169 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 724437621 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556594b9c810, 0x556594d8601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556594d86020,0x556596c1e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5324cf82cc23b9050411ce0b605e8fc60cf2ad4b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7969 processed earlier; will process 3060 files now Step #5: #1 pulse cov: 3680 ft: 3681 exec/s: 0 rss: 180Mb Step #5: ==222190== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55658b6919c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556591cf6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556591cd95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556591cd94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55658b697d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55658b5f8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55658b5f3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55658b689c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55658e658f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55658e658f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55658e658f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55658e658f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55658e658f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55658e658f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55658e658f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55658e658f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55658e658f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55658e658f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5565908edf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55658d61ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55658d625be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55658d3d1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55658d3d1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55658d3d2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55658d3d1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55658d3d1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55658d3d1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556591cdbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556591ce4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556591ccc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556591cf7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f840f7e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55658b5f1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f5e6262345fa85f02409e9c1af6a25871e9b2e29 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6170 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 725186441 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5595b46c7810, 0x5595b48b101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5595b48b1020,0x5595b67490e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f5e6262345fa85f02409e9c1af6a25871e9b2e29' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7971 processed earlier; will process 3058 files now Step #5: #1 pulse cov: 4597 ft: 4598 exec/s: 0 rss: 180Mb Step #5: ==222226== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5595ab1bc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5595b1821898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5595b18045dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5595b18044fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5595ab1c2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5595ab123b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5595ab11e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5595ab1b4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5595ae183f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5595ae183f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5595ae183f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5595ae183f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5595ae183f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5595ae183f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5595ae183f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5595ae183f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5595ae183f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5595ae183f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5595b0418f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5595ad145b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5595ad150be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5595acefcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5595acefcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5595acefd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5595acefc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5595acefc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5595acefc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5595b1806abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5595b180f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5595b17f7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5595b1822112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0268612082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5595ab11cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9901f5b402315ae1feb236dd3645b40d011c1ca6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6171 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 726731002 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563933d81810, 0x563933f6b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563933f6b020,0x563935e030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9901f5b402315ae1feb236dd3645b40d011c1ca6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7973 processed earlier; will process 3056 files now Step #5: #1 pulse cov: 4201 ft: 4202 exec/s: 0 rss: 181Mb Step #5: ==222262== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56392a8769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563930edb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563930ebe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563930ebe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56392a87cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56392a7ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56392a7d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56392a86ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56392d83df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56392d83df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56392d83df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56392d83df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56392d83df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56392d83df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56392d83df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56392d83df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56392d83df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56392d83df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56392fad2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56392c7ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56392c80abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56392c5b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56392c5b6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56392c5b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56392c5b6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56392c5b6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56392c5b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563930ec0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563930ec9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563930eb1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563930edc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f44275d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56392a7d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-65d3ce679dd49d19f240cf7528768fe328cf73a8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6172 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 727916155 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5599ef67a810, 0x5599ef86401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5599ef864020,0x5599f16fc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/65d3ce679dd49d19f240cf7528768fe328cf73a8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7975 processed earlier; will process 3054 files now Step #5: ==222298== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5599e616f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5599ec7d4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5599ec7b75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5599ec7b74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5599e6175d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5599e60d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5599e60d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5599e6167c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5599e9136f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5599e9136f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5599e9136f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5599e9136f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5599e9136f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5599e9136f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5599e9136f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5599e9136f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5599e9136f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5599e9136f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5599eb3cbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5599e80f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5599e8103be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5599e7eafc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5599e7eafc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5599e7eb0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5599e7eaf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5599e7eaf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5599e7eaf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5599ec7b9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5599ec7c2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5599ec7aa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5599ec7d5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8ff0941082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5599e60cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9a4545d62a0186ee1d4ca9123750d046c104a5f0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6173 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 729577076 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55deb5821810, 0x55deb5a0b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55deb5a0b020,0x55deb78a30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9a4545d62a0186ee1d4ca9123750d046c104a5f0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7976 processed earlier; will process 3053 files now Step #5: ==222334== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55deac3169c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55deb297b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55deb295e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55deb295e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55deac31cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55deac27db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55deac278355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55deac30ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55deaf2ddf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55deaf2ddf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55deaf2ddf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55deaf2ddf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55deaf2ddf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55deaf2ddf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55deaf2ddf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55deaf2ddf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55deaf2ddf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55deaf2ddf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55deb1572f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55deae29fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55deae2aabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55deae056c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55deae056c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55deae057738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55deae056874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55deae056874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55deae056874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55deb2960abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55deb2969928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55deb2951699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55deb297c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f334011c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55deac276b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e1c008dae3476a3492e6d07ecc4281134600ee94 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6174 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 731262069 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c92732c810, 0x55c92751601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c927516020,0x55c9293ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e1c008dae3476a3492e6d07ecc4281134600ee94' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7977 processed earlier; will process 3052 files now Step #5: #1 pulse cov: 4582 ft: 4583 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4748 ft: 5380 exec/s: 0 rss: 180Mb Step #5: ==222370== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c91de219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c924486898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9244695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9244694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c91de27d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c91dd88b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c91dd83355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c91de19c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c920de8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c920de8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c920de8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c920de8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c920de8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c920de8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c920de8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c920de8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c920de8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c920de8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c92307df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c91fdaab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c91fdb5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c91fb61c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c91fb61c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c91fb62738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c91fb61874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c91fb61874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c91fb61874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c92446babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c924474928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c92445c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c924487112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe4d62b3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c91dd81b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6dbb7972f2a295221178b090f6e859ea357dbcfb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6175 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 731991111 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55de3b042810, 0x55de3b22c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55de3b22c020,0x55de3d0c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6dbb7972f2a295221178b090f6e859ea357dbcfb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7981 processed earlier; will process 3048 files now Step #5: #1 pulse cov: 3561 ft: 3562 exec/s: 0 rss: 181Mb Step #5: ==222406== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55de31b379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55de3819c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55de3817f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55de3817f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55de31b3dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55de31a9eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55de31a99355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55de31b2fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55de34afef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55de34afef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55de34afef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55de34afef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55de34afef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55de34afef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55de34afef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55de34afef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55de34afef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55de34afef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55de36d93f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55de33ac0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55de33acbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55de33877c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55de33877c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55de33878738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55de33877874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55de33877874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55de33877874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55de38181abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55de3818a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55de38172699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55de3819d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa49efdf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55de31a97b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d76dc7d984647f1698ce6db75de0097b3327a2e2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6176 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 733733640 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c42b355810, 0x55c42b53f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c42b53f020,0x55c42d3d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d76dc7d984647f1698ce6db75de0097b3327a2e2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7983 processed earlier; will process 3046 files now Step #5: #1 pulse cov: 4665 ft: 4666 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4760 ft: 5519 exec/s: 0 rss: 180Mb Step #5: ==222442== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c421e4a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c4284af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c4284925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c4284924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c421e50d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c421db1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c421dac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c421e42c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c424e11f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c424e11f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c424e11f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c424e11f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c424e11f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c424e11f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c424e11f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c424e11f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c424e11f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c424e11f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c4270a6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c423dd3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c423ddebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c423b8ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c423b8ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c423b8b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c423b8a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c423b8a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c423b8a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c428494abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c42849d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c428485699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c4284b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8911900082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c421daab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7f530018545584250164b8d23228d10210fc712a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6177 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 734395755 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f4b5b3d810, 0x55f4b5d2701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f4b5d27020,0x55f4b7bbf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7f530018545584250164b8d23228d10210fc712a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7986 processed earlier; will process 3043 files now Step #5: ==222478== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f4ac6329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f4b2c97898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f4b2c7a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f4b2c7a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f4ac638d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f4ac599b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f4ac594355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f4ac62ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f4af5f9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f4af5f9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f4af5f9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f4af5f9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f4af5f9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f4af5f9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f4af5f9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f4af5f9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f4af5f9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f4af5f9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4b188ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4ae5bbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4ae5c6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f4ae372c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f4ae372c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f4ae373738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f4ae372874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f4ae372874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f4ae372874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f4b2c7cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f4b2c85928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f4b2c6d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f4b2c98112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f765eda2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f4ac592b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-70a56affc46714ad3f3784f543731aafc6f3da5d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6178 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 735970267 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558081e95810, 0x55808207f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55808207f020,0x558083f170e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70a56affc46714ad3f3784f543731aafc6f3da5d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7987 processed earlier; will process 3042 files now Step #5: ==222514== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55807898a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55807efef898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55807efd25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55807efd24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558078990d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5580788f1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5580788ec355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558078982c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55807b951f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55807b951f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55807b951f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55807b951f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55807b951f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55807b951f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55807b951f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55807b951f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55807b951f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55807b951f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55807dbe6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55807a913b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55807a91ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55807a6cac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55807a6cac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55807a6cb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55807a6ca874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55807a6ca874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55807a6ca874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55807efd4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55807efdd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55807efc5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55807eff0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b52051082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5580788eab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-962173c51978e7f899d605f242e86c1d7ac4c7d9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6179 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 736689236 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55de805ff810, 0x55de807e901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55de807e9020,0x55de826810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/962173c51978e7f899d605f242e86c1d7ac4c7d9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7988 processed earlier; will process 3041 files now Step #5: #1 pulse cov: 3825 ft: 3826 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4053 ft: 4547 exec/s: 0 rss: 181Mb Step #5: #4 pulse cov: 4646 ft: 5898 exec/s: 0 rss: 183Mb Step #5: ==222550== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55de770f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55de7d759898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55de7d73c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55de7d73c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55de770fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55de7705bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55de77056355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55de770ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55de7a0bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55de7a0bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55de7a0bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55de7a0bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55de7a0bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55de7a0bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55de7a0bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55de7a0bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55de7a0bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55de7a0bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55de7c350f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55de7907db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55de79088be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55de78e34c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55de78e34c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55de78e35738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55de78e34874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55de78e34874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55de78e34874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55de7d73eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55de7d747928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55de7d72f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55de7d75a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc63fd52082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55de77054b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-09cfc57ffc24ce3cb4da8574892db0d4729fed6a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6180 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 737639985 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c2b41f8810, 0x55c2b43e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c2b43e2020,0x55c2b627a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/09cfc57ffc24ce3cb4da8574892db0d4729fed6a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7994 processed earlier; will process 3035 files now Step #5: ==222586== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c2aaced9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c2b1352898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c2b13355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c2b13354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c2aacf3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c2aac54b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c2aac4f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c2aace5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c2adcb4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c2adcb4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c2adcb4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c2adcb4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c2adcb4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c2adcb4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c2adcb4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c2adcb4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c2adcb4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c2adcb4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c2aff49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c2acc76b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c2acc81be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c2aca2dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c2aca2dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c2aca2e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c2aca2d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c2aca2d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c2aca2d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c2b1337abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c2b1340928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c2b1328699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c2b1353112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd54b5fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c2aac4db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-efe61eb5030ff9644ac71d03843b65f669937819 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6181 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 738229292 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d1c5459810, 0x55d1c564301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d1c5643020,0x55d1c74db0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/efe61eb5030ff9644ac71d03843b65f669937819' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7995 processed earlier; will process 3034 files now Step #5: ==222622== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d1bbf4e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d1c25b3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d1c25965dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d1c25964fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d1bbf54d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1bbeb5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1bbeb0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d1bbf46c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d1bef15f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d1bef15f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d1bef15f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d1bef15f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d1bef15f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d1bef15f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d1bef15f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d1bef15f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d1bef15f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d1bef15f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d1c11aaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d1bded7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d1bdee2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d1bdc8ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d1bdc8ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d1bdc8f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d1bdc8e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d1bdc8e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d1bdc8e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d1c2598abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d1c25a1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d1c2589699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d1c25b4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff820779082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1bbeaeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-70fe1ffab5c526c070b6c541adca58c983d3f601 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6182 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 738949331 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b4e28fc810, 0x55b4e2ae601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b4e2ae6020,0x55b4e497e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70fe1ffab5c526c070b6c541adca58c983d3f601' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7996 processed earlier; will process 3033 files now Step #5: #1 pulse cov: 11801 ft: 11802 exec/s: 0 rss: 199Mb Step #5: ==222658== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b4d93f19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b4dfa56898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b4dfa395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b4dfa394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b4d93f7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b4d9358b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b4d9353355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b4d93e9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b4dc3b8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b4dc3b8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b4dc3b8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b4dc3b8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b4dc3b8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b4dc3b8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b4dc3b8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b4dc3b8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b4dc3b8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b4dc3b8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b4de64df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b4db37ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b4db385be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b4db131c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b4db131c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b4db132738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b4db131874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b4db131874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b4db131874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b4dfa3babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b4dfa44928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b4dfa2c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b4dfa57112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7facd0b62082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b4d9351b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e67ddd938e25d1eec549aea2a8809ddb90b3153b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6183 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 739644172 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5631a7c07810, 0x5631a7df101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5631a7df1020,0x5631a9c890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e67ddd938e25d1eec549aea2a8809ddb90b3153b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7998 processed earlier; will process 3031 files now Step #5: ==222694== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56319e6fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5631a4d61898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5631a4d445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5631a4d444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56319e702d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56319e663b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56319e65e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56319e6f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5631a16c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5631a16c3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5631a16c3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5631a16c3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5631a16c3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5631a16c3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5631a16c3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5631a16c3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5631a16c3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5631a16c3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5631a3958f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5631a0685b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5631a0690be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5631a043cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5631a043cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5631a043d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5631a043c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5631a043c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5631a043c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5631a4d46abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5631a4d4f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5631a4d37699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5631a4d62112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f310ddea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56319e65cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6bf1fdc7323c9c44605d15b057ae65e6922dfc6c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6184 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 740348833 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a47318810, 0x555a4750201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a47502020,0x555a4939a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6bf1fdc7323c9c44605d15b057ae65e6922dfc6c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 7999 processed earlier; will process 3030 files now Step #5: ==222730== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555a3de0d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a44472898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a444555dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a444554fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a3de13d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a3dd74b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a3dd6f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a3de05c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a40dd4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a40dd4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a40dd4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a40dd4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a40dd4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a40dd4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a40dd4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a40dd4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a40dd4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a40dd4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a43069f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a3fd96b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a3fda1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a3fb4dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a3fb4dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a3fb4e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a3fb4d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a3fb4d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a3fb4d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a44457abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a44460928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a44448699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a44473112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f224b6ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a3dd6db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-959ae987edee2b3c3aeba2b9cabe787abd757b4a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6185 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 740962288 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556567110810, 0x5565672fa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5565672fa020,0x5565691920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/959ae987edee2b3c3aeba2b9cabe787abd757b4a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8000 processed earlier; will process 3029 files now Step #5: #1 pulse cov: 4046 ft: 4047 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4093 ft: 4614 exec/s: 0 rss: 180Mb Step #5: #4 pulse cov: 4749 ft: 6375 exec/s: 0 rss: 182Mb Step #5: ==222766== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55655dc059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55656426a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55656424d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55656424d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55655dc0bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55655db6cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55655db67355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55655dbfdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556560bccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556560bccf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556560bccf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556560bccf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556560bccf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556560bccf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556560bccf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556560bccf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556560bccf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556560bccf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556562e61f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55655fb8eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55655fb99be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55655f945c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55655f945c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55655f946738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55655f945874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55655f945874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55655f945874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55656424fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556564258928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556564240699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55656426b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5d98aad082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55655db65b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1241f3b3eb36d4e5f69d9339e73412170de8a93d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6186 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 741704075 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe83dff810, 0x55fe83fe901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe83fe9020,0x55fe85e810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1241f3b3eb36d4e5f69d9339e73412170de8a93d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8005 processed earlier; will process 3024 files now Step #5: ==222802== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fe7a8f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe80f59898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe80f3c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe80f3c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe7a8fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe7a85bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe7a856355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe7a8ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe7d8bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe7d8bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe7d8bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe7d8bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe7d8bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe7d8bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe7d8bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe7d8bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe7d8bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe7d8bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe7fb50f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe7c87db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe7c888be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe7c634c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe7c634c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe7c635738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe7c634874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe7c634874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe7c634874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe80f3eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe80f47928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe80f2f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe80f5a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8d6d0b8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe7a854b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-004519981b517985a326c83ce281d4b890482ffe Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6187 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 742274735 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558e35acb810, 0x558e35cb501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558e35cb5020,0x558e37b4d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/004519981b517985a326c83ce281d4b890482ffe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8006 processed earlier; will process 3023 files now Step #5: #1 pulse cov: 3806 ft: 3807 exec/s: 0 rss: 181Mb Step #5: ==222838== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558e2c5c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558e32c25898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558e32c085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558e32c084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558e2c5c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558e2c527b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558e2c522355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558e2c5b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558e2f587f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558e2f587f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558e2f587f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558e2f587f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558e2f587f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558e2f587f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558e2f587f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558e2f587f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558e2f587f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558e2f587f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558e3181cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558e2e549b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558e2e554be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558e2e300c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558e2e300c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558e2e301738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558e2e300874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558e2e300874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558e2e300874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558e32c0aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558e32c13928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558e32bfb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558e32c26112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a9cbc7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558e2c520b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e6f140b64a070b94f2b8faa80baea2ced3677618 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6188 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 743169084 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a213f8810, 0x555a215e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a215e2020,0x555a2347a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e6f140b64a070b94f2b8faa80baea2ced3677618' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8008 processed earlier; will process 3021 files now Step #5: ==222874== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555a17eed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a1e552898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a1e5355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a1e5354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a17ef3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a17e54b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a17e4f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a17ee5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a1aeb4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a1aeb4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a1aeb4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a1aeb4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a1aeb4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a1aeb4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a1aeb4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a1aeb4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a1aeb4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a1aeb4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a1d149f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a19e76b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a19e81be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a19c2dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a19c2dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a19c2e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a19c2d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a19c2d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a19c2d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a1e537abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a1e540928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a1e528699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a1e553112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2cc4870082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a17e4db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-801f9bb7e7e6561598132feaa4988b2965da432d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6189 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 743803978 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5644d7a49810, 0x5644d7c3301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5644d7c33020,0x5644d9acb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/801f9bb7e7e6561598132feaa4988b2965da432d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8009 processed earlier; will process 3020 files now Step #5: ==222910== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5644ce53e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5644d4ba3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5644d4b865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5644d4b864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5644ce544d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5644ce4a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5644ce4a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5644ce536c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5644d1505f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5644d1505f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5644d1505f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5644d1505f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5644d1505f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5644d1505f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5644d1505f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5644d1505f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5644d1505f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5644d1505f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5644d379af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5644d04c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5644d04d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5644d027ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5644d027ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5644d027f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5644d027e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5644d027e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5644d027e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5644d4b88abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5644d4b91928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5644d4b79699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5644d4ba4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f75c217c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5644ce49eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-680ef06a2db8ed2ac03c4a1bb6213cd44c194f41 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6190 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 744384824 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563d96a79810, 0x563d96c6301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563d96c63020,0x563d98afb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/680ef06a2db8ed2ac03c4a1bb6213cd44c194f41' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8010 processed earlier; will process 3019 files now Step #5: #1 pulse cov: 3901 ft: 3902 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4608 ft: 5150 exec/s: 0 rss: 182Mb Step #5: ==222946== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563d8d56e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d93bd3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d93bb65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d93bb64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d8d574d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d8d4d5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d8d4d0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d8d566c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d90535f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d90535f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d90535f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d90535f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d90535f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d90535f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d90535f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d90535f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d90535f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d90535f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d927caf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d8f4f7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d8f502be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d8f2aec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d8f2aec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d8f2af738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d8f2ae874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d8f2ae874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d8f2ae874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d93bb8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d93bc1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d93ba9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d93bd4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f44231e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d8d4ceb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec4d96c654c53f12d68fdbdf52ab59ba20c69d0d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6191 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 745059185 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560eec8d5810, 0x560eecabf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560eecabf020,0x560eee9570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec4d96c654c53f12d68fdbdf52ab59ba20c69d0d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8013 processed earlier; will process 3016 files now Step #5: ==222982== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560ee33ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560ee9a2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560ee9a125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560ee9a124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560ee33d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560ee3331b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560ee332c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560ee33c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560ee6391f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560ee6391f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560ee6391f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560ee6391f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560ee6391f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560ee6391f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560ee6391f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560ee6391f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560ee6391f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560ee6391f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560ee8626f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560ee5353b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560ee535ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560ee510ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560ee510ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560ee510b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560ee510a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560ee510a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560ee510a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560ee9a14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560ee9a1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560ee9a05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560ee9a30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6a5dfb0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560ee332ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-159b55ea911f6bd0b0b91432e20b67d5df112150 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6192 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 745626326 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559b6d4c2810, 0x559b6d6ac01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559b6d6ac020,0x559b6f5440e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/159b55ea911f6bd0b0b91432e20b67d5df112150' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8014 processed earlier; will process 3015 files now Step #5: #1 pulse cov: 4078 ft: 4079 exec/s: 0 rss: 179Mb Step #5: ==223018== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559b63fb79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559b6a61c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559b6a5ff5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559b6a5ff4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b63fbdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b63f1eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b63f19355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b63fafc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b66f7ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b66f7ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b66f7ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b66f7ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b66f7ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b66f7ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b66f7ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b66f7ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b66f7ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b66f7ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559b69213f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b65f40b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b65f4bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b65cf7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b65cf7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b65cf8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b65cf7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b65cf7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b65cf7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559b6a601abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559b6a60a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559b6a5f2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559b6a61d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f498471c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b63f17b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f745447faf4d9d38881cd00335220e39eace1cf1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6193 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 746267474 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d321c3b810, 0x55d321e2501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d321e25020,0x55d323cbd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f745447faf4d9d38881cd00335220e39eace1cf1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8016 processed earlier; will process 3013 files now Step #5: #1 pulse cov: 4248 ft: 4249 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 4811 ft: 5606 exec/s: 0 rss: 183Mb Step #5: ==223054== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d3187309c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d31ed95898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d31ed785dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d31ed784fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d318736d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d318697b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d318692355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d318728c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d31b6f7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d31b6f7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d31b6f7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d31b6f7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d31b6f7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d31b6f7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d31b6f7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d31b6f7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d31b6f7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d31b6f7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d31d98cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d31a6b9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d31a6c4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d31a470c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d31a470c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d31a471738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d31a470874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d31a470874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d31a470874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d31ed7aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d31ed83928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d31ed6b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d31ed96112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f904cfc7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d318690b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-09f14e4faf8f711f9873efba6c0060cf260e2dc0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6194 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 747027601 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5572aec0f810, 0x5572aedf901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5572aedf9020,0x5572b0c910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/09f14e4faf8f711f9873efba6c0060cf260e2dc0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8019 processed earlier; will process 3010 files now Step #5: ==223090== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5572a57049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5572abd69898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5572abd4c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5572abd4c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5572a570ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5572a566bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5572a5666355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5572a56fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5572a86cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5572a86cbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5572a86cbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5572a86cbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5572a86cbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5572a86cbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5572a86cbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5572a86cbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5572a86cbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5572a86cbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5572aa960f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5572a768db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5572a7698be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5572a7444c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5572a7444c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5572a7445738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5572a7444874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5572a7444874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5572a7444874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5572abd4eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5572abd57928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5572abd3f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5572abd6a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f728f79b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5572a5664b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4587cce5d7743fed672690d53c44a185da15fa0f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6195 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 747794524 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a686e5810, 0x560a688cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a688cf020,0x560a6a7670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4587cce5d7743fed672690d53c44a185da15fa0f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8020 processed earlier; will process 3009 files now Step #5: #1 pulse cov: 4184 ft: 4185 exec/s: 0 rss: 178Mb Step #5: ==223126== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560a5f1da9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a6583f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a658225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a658224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a5f1e0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a5f141b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a5f13c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a5f1d2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a621a1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a621a1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a621a1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a621a1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a621a1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a621a1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a621a1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a621a1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a621a1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a621a1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a64436f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a61163b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a6116ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a60f1ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a60f1ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a60f1b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a60f1a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a60f1a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a60f1a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a65824abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a6582d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a65815699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a65840112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f40a8ae9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a5f13ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d44e6e23822eeaab7e45ecb5a8779b10fe6cd907 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6196 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 748413680 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b126e0d810, 0x55b126ff701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b126ff7020,0x55b128e8f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d44e6e23822eeaab7e45ecb5a8779b10fe6cd907' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8022 processed earlier; will process 3007 files now Step #5: ==223162== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b11d9029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b123f67898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b123f4a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b123f4a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b11d908d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b11d869b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b11d864355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b11d8fac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b1208c9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b1208c9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b1208c9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b1208c9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b1208c9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b1208c9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b1208c9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b1208c9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b1208c9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b1208c9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b122b5ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b11f88bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b11f896be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b11f642c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b11f642c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b11f643738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b11f642874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b11f642874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b11f642874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b123f4cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b123f55928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b123f3d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b123f68112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f51ec3f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b11d862b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ada11ce780918baaeeeebf1ae96475ef6bf84e0f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6197 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 749983919 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55616c03c810, 0x55616c22601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55616c226020,0x55616e0be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ada11ce780918baaeeeebf1ae96475ef6bf84e0f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8023 processed earlier; will process 3006 files now Step #5: #1 pulse cov: 4164 ft: 4165 exec/s: 0 rss: 182Mb Step #5: #2 pulse cov: 4477 ft: 5314 exec/s: 0 rss: 183Mb Step #5: ==223198== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556162b319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556169196898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5561691795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5561691794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556162b37d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556162a98b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556162a93355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556162b29c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556165af8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556165af8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556165af8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556165af8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556165af8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556165af8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556165af8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556165af8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556165af8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556165af8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556167d8df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556164abab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556164ac5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556164871c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556164871c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556164872738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556164871874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556164871874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556164871874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55616917babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556169184928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55616916c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556169197112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f75fde2f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556162a91b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8531b60ca8896e803a0d34aed276cb412a59afec Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6198 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 750760948 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559402f57810, 0x55940314101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559403141020,0x559404fd90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8531b60ca8896e803a0d34aed276cb412a59afec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8026 processed earlier; will process 3003 files now Step #5: ==223234== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5593f9a4c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5594000b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5594000945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5594000944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5593f9a52d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5593f99b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5593f99ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5593f9a44c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5593fca13f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5593fca13f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5593fca13f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5593fca13f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5593fca13f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5593fca13f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5593fca13f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5593fca13f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5593fca13f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5593fca13f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5593feca8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5593fb9d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5593fb9e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5593fb78cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5593fb78cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5593fb78d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5593fb78c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5593fb78c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5593fb78c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559400096abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55940009f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559400087699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5594000b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f286b919082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5593f99acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1f27b0b755b6019a2040ce99a07f15b635927266 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6199 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 751332081 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5612786a5810, 0x56127888f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56127888f020,0x56127a7270e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f27b0b755b6019a2040ce99a07f15b635927266' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8027 processed earlier; will process 3002 files now Step #5: #1 pulse cov: 3828 ft: 3829 exec/s: 0 rss: 180Mb Step #5: ==223270== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56126f19a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5612757ff898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5612757e25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5612757e24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56126f1a0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56126f101b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56126f0fc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56126f192c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561272161f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561272161f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561272161f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561272161f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561272161f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561272161f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561272161f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561272161f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561272161f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561272161f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5612743f6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561271123b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56127112ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561270edac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561270edac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561270edb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561270eda874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561270eda874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561270eda874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5612757e4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5612757ed928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5612757d5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561275800112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2915db5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56126f0fab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a41b4380e1c2628834859f04be4dd130f04f54e0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6200 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 751950473 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5630568ca810, 0x563056ab401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563056ab4020,0x56305894c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a41b4380e1c2628834859f04be4dd130f04f54e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8029 processed earlier; will process 3000 files now Step #5: #1 pulse cov: 4199 ft: 4200 exec/s: 0 rss: 179Mb Step #5: ==223306== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56304d3bf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563053a24898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563053a075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563053a074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56304d3c5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56304d326b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56304d321355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56304d3b7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563050386f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563050386f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563050386f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563050386f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563050386f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563050386f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563050386f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563050386f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563050386f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563050386f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56305261bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56304f348b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56304f353be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56304f0ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56304f0ffc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56304f100738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56304f0ff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56304f0ff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56304f0ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563053a09abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563053a12928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5630539fa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563053a25112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f222c09d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56304d31fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ab1e67d2ef81e4dd8e0104f802492ada7c15735c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6201 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 752577424 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559b50983810, 0x559b50b6d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559b50b6d020,0x559b52a050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ab1e67d2ef81e4dd8e0104f802492ada7c15735c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8031 processed earlier; will process 2998 files now Step #5: ==223342== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559b474789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559b4dadd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559b4dac05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559b4dac04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b4747ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b473dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b473da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b47470c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b4a43ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b4a43ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b4a43ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b4a43ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b4a43ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b4a43ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b4a43ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b4a43ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b4a43ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b4a43ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559b4c6d4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b49401b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b4940cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b491b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b491b8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b491b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b491b8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b491b8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b491b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559b4dac2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559b4dacb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559b4dab3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559b4dade112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f34ed0b7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b473d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2e947dcc138065371e068b6c7bd9f8cc4b28d076 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6202 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 753276599 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a7b262f810, 0x55a7b281901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a7b2819020,0x55a7b46b10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2e947dcc138065371e068b6c7bd9f8cc4b28d076' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8032 processed earlier; will process 2997 files now Step #5: ==223378== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a7a91249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a7af789898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a7af76c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a7af76c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a7a912ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a7a908bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a7a9086355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a7a911cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a7ac0ebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a7ac0ebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a7ac0ebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a7ac0ebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a7ac0ebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a7ac0ebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a7ac0ebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a7ac0ebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a7ac0ebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a7ac0ebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a7ae380f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a7ab0adb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a7ab0b8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a7aae64c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a7aae64c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a7aae65738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a7aae64874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a7aae64874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a7aae64874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a7af76eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a7af777928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a7af75f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a7af78a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7facfe15e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a7a9084b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-075f38fc3410c7fbbbb7124d1848276086adaa16 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6203 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 753834354 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c545d7810, 0x561c547c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c547c1020,0x561c566590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/075f38fc3410c7fbbbb7124d1848276086adaa16' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8033 processed earlier; will process 2996 files now Step #5: #1 pulse cov: 4258 ft: 4259 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4552 ft: 5171 exec/s: 0 rss: 181Mb Step #5: ==223414== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561c4b0cc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c51731898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c517145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c517144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c4b0d2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c4b033b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c4b02e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c4b0c4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c4e093f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c4e093f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c4e093f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c4e093f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c4e093f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c4e093f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c4e093f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c4e093f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c4e093f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c4e093f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c50328f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c4d055b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c4d060be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c4ce0cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c4ce0cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c4ce0d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c4ce0c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c4ce0c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c4ce0c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c51716abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c5171f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c51707699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c51732112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1f423f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c4b02cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-26550b52e17d92d29b656f4e5e03de22b417f481 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6204 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 754614649 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55833f082810, 0x55833f26c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55833f26c020,0x5583411040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/26550b52e17d92d29b656f4e5e03de22b417f481' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8037 processed earlier; will process 2992 files now Step #5: #1 pulse cov: 3801 ft: 3802 exec/s: 0 rss: 178Mb Step #5: ==223450== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558335b779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55833c1dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55833c1bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55833c1bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558335b7dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558335adeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558335ad9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558335b6fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558338b3ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558338b3ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558338b3ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558338b3ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558338b3ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558338b3ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558338b3ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558338b3ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558338b3ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558338b3ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55833add3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558337b00b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558337b0bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5583378b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5583378b7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5583378b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5583378b7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5583378b7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5583378b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55833c1c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55833c1ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55833c1b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55833c1dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc9b751c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558335ad7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a448ca3cb3f276123f1ed5a52b8b224e8ceb18f3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6205 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 755286135 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56133723f810, 0x56133742901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561337429020,0x5613392c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a448ca3cb3f276123f1ed5a52b8b224e8ceb18f3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8039 processed earlier; will process 2990 files now Step #5: ==223486== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56132dd349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561334399898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56133437c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56133437c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56132dd3ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56132dc9bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56132dc96355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56132dd2cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561330cfbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561330cfbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561330cfbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561330cfbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561330cfbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561330cfbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561330cfbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561330cfbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561330cfbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561330cfbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561332f90f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56132fcbdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56132fcc8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56132fa74c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56132fa74c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56132fa75738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56132fa74874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56132fa74874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56132fa74874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56133437eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561334387928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56133436f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56133439a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fda1ea95082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56132dc94b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-143593d07830943b7e1b4305dc842804c435b83e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6206 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 755861684 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562f4c327810, 0x562f4c51101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562f4c511020,0x562f4e3a90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/143593d07830943b7e1b4305dc842804c435b83e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8040 processed earlier; will process 2989 files now Step #5: #1 pulse cov: 14369 ft: 14370 exec/s: 0 rss: 202Mb Step #5: ==223522== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562f42e1c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562f49481898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562f494645dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562f494644fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562f42e22d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562f42d83b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562f42d7e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562f42e14c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562f45de3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562f45de3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562f45de3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562f45de3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562f45de3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562f45de3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562f45de3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562f45de3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562f45de3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562f45de3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562f48078f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562f44da5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562f44db0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562f44b5cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562f44b5cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562f44b5d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562f44b5c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562f44b5c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562f44b5c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562f49466abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562f4946f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562f49457699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562f49482112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c79a57082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562f42d7cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-274d60d7bb37e63f7f68fc8ec0887c96dcc95609 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6207 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 756633545 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5558df1f5810, 0x5558df3df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5558df3df020,0x5558e12770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/274d60d7bb37e63f7f68fc8ec0887c96dcc95609' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8042 processed earlier; will process 2987 files now Step #5: ==223558== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5558d5cea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5558dc34f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5558dc3325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5558dc3324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5558d5cf0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5558d5c51b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5558d5c4c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5558d5ce2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5558d8cb1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5558d8cb1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5558d8cb1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5558d8cb1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5558d8cb1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5558d8cb1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5558d8cb1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5558d8cb1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5558d8cb1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5558d8cb1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5558daf46f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5558d7c73b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5558d7c7ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5558d7a2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5558d7a2ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5558d7a2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5558d7a2a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5558d7a2a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5558d7a2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5558dc334abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5558dc33d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5558dc325699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5558dc350112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f10416eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5558d5c4ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ad9cca132c1b1d43c78243c6d8c5342e8a08577 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6208 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 757261798 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c9ee007810, 0x55c9ee1f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c9ee1f1020,0x55c9f00890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ad9cca132c1b1d43c78243c6d8c5342e8a08577' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8043 processed earlier; will process 2986 files now Step #5: ==223594== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c9e4afc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c9eb161898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9eb1445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9eb1444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9e4b02d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9e4a63b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c9e4a5e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9e4af4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c9e7ac3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c9e7ac3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c9e7ac3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c9e7ac3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c9e7ac3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c9e7ac3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c9e7ac3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c9e7ac3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c9e7ac3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c9e7ac3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c9e9d58f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9e6a85b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9e6a90be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c9e683cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c9e683cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c9e683d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c9e683c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c9e683c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c9e683c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c9eb146abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c9eb14f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c9eb137699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c9eb162112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5602d53082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c9e4a5cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c21d831707110a57008e94c71789a97810d15104 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6209 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 758670952 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ca1a04a810, 0x55ca1a23401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ca1a234020,0x55ca1c0cc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c21d831707110a57008e94c71789a97810d15104' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8044 processed earlier; will process 2985 files now Step #5: #1 pulse cov: 4147 ft: 4148 exec/s: 0 rss: 181Mb Step #5: ==223630== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ca10b3f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ca171a4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ca171875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ca171874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca10b45d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca10aa6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca10aa1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca10b37c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ca13b06f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ca13b06f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ca13b06f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ca13b06f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ca13b06f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ca13b06f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ca13b06f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ca13b06f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ca13b06f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ca13b06f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ca15d9bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ca12ac8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ca12ad3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ca1287fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ca1287fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ca12880738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ca1287f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ca1287f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ca1287f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ca17189abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ca17192928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ca1717a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ca171a5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f495b814082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca10a9fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e5909f1ac7386c3729ad5d657d93cbd5c01ba7d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6210 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 759898351 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56296eb5a810, 0x56296ed4401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56296ed44020,0x562970bdc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e5909f1ac7386c3729ad5d657d93cbd5c01ba7d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8046 processed earlier; will process 2983 files now Step #5: ==223666== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56296564f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56296bcb4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56296bc975dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56296bc974fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562965655d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5629655b6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5629655b1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562965647c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562968616f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562968616f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562968616f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562968616f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562968616f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562968616f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562968616f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562968616f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562968616f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562968616f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56296a8abf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5629675d8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5629675e3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56296738fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56296738fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562967390738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56296738f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56296738f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56296738f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56296bc99abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56296bca2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56296bc8a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56296bcb5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6d1b0dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5629655afb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-deabb08db6d16b1ead349d6fcfd600c299753bef Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6211 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 761338097 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ddc5644810, 0x55ddc582e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ddc582e020,0x55ddc76c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/deabb08db6d16b1ead349d6fcfd600c299753bef' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8047 processed earlier; will process 2982 files now Step #5: ==223702== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ddbc1399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ddc279e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ddc27815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ddc27814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ddbc13fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ddbc0a0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ddbc09b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ddbc131c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ddbf100f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ddbf100f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ddbf100f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ddbf100f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ddbf100f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ddbf100f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ddbf100f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ddbf100f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ddbf100f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ddbf100f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ddc1395f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ddbe0c2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ddbe0cdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ddbde79c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ddbde79c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ddbde7a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ddbde79874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ddbde79874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ddbde79874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ddc2783abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ddc278c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ddc2774699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ddc279f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1d31ed9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ddbc099b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ed8d13c0312fc75cd7e04055c2eb5496147c04d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6212 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 762712782 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec63f99810, 0x55ec6418301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec64183020,0x55ec6601b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ed8d13c0312fc75cd7e04055c2eb5496147c04d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8048 processed earlier; will process 2981 files now Step #5: ==223738== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec5aa8e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec610f3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec610d65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec610d64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec5aa94d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec5a9f5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec5a9f0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec5aa86c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec5da55f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec5da55f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec5da55f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec5da55f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec5da55f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec5da55f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec5da55f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec5da55f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec5da55f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec5da55f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec5fceaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec5ca17b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec5ca22be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec5c7cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec5c7cec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec5c7cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec5c7ce874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec5c7ce874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec5c7ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec610d8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec610e1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec610c9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec610f4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9eed511082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec5a9eeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7b5bf2f96ceb41e9b734799ae22e81d9d09f29c0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6213 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 763309736 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a82a440810, 0x55a82a62a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a82a62a020,0x55a82c4c20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7b5bf2f96ceb41e9b734799ae22e81d9d09f29c0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8049 processed earlier; will process 2980 files now Step #5: #1 pulse cov: 4504 ft: 4505 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 12632 ft: 13546 exec/s: 0 rss: 199Mb Step #5: ==223774== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a820f359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a82759a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a82757d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a82757d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a820f3bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a820e9cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a820e97355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a820f2dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a823efcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a823efcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a823efcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a823efcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a823efcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a823efcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a823efcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a823efcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a823efcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a823efcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a826191f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a822ebeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a822ec9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a822c75c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a822c75c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a822c76738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a822c75874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a822c75874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a822c75874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a82757fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a827588928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a827570699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a82759b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe2c40a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a820e95b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c070e91cf916d88506e72e6617f7b0f7d6bb709c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6214 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 764048744 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555ce8449810, 0x555ce863301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555ce8633020,0x555cea4cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c070e91cf916d88506e72e6617f7b0f7d6bb709c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8052 processed earlier; will process 2977 files now Step #5: #1 pulse cov: 11691 ft: 11692 exec/s: 0 rss: 199Mb Step #5: ==223810== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555cdef3e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555ce55a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555ce55865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555ce55864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555cdef44d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555cdeea5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555cdeea0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555cdef36c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555ce1f05f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555ce1f05f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555ce1f05f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555ce1f05f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555ce1f05f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555ce1f05f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555ce1f05f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555ce1f05f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555ce1f05f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555ce1f05f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555ce419af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555ce0ec7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555ce0ed2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555ce0c7ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555ce0c7ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555ce0c7f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555ce0c7e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555ce0c7e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555ce0c7e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555ce5588abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555ce5591928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555ce5579699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555ce55a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f624263b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555cdee9eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-34969f8deacba7bcecbbd4fa977871f1cd3bdb0a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6215 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 764736381 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559106f7d810, 0x55910716701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559107167020,0x559108fff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/34969f8deacba7bcecbbd4fa977871f1cd3bdb0a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8054 processed earlier; will process 2975 files now Step #5: ==223846== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5590fda729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5591040d7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5591040ba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5591040ba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5590fda78d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5590fd9d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5590fd9d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5590fda6ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559100a39f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559100a39f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559100a39f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559100a39f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559100a39f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559100a39f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559100a39f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559100a39f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559100a39f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559100a39f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559102ccef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5590ff9fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5590ffa06be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5590ff7b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5590ff7b2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5590ff7b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5590ff7b2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5590ff7b2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5590ff7b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5591040bcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5591040c5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5591040ad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5591040d8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb2a786a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5590fd9d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bc8a51fbf01520b63fee543c54daf6155641ee8e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6216 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 765477997 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560f51ed1810, 0x560f520bb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560f520bb020,0x560f53f530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bc8a51fbf01520b63fee543c54daf6155641ee8e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8055 processed earlier; will process 2974 files now Step #5: ==223882== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560f489c69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560f4f02b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560f4f00e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560f4f00e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560f489ccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560f4892db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560f48928355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560f489bec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560f4b98df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560f4b98df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560f4b98df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560f4b98df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560f4b98df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560f4b98df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560f4b98df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560f4b98df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560f4b98df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560f4b98df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560f4dc22f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560f4a94fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560f4a95abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560f4a706c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560f4a706c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560f4a707738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560f4a706874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560f4a706874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560f4a706874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560f4f010abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560f4f019928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560f4f001699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560f4f02c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdbade61082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560f48926b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-40f5cf2262f6c4a740d0e72decc26994564f09e5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6217 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 766210479 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556920870810, 0x556920a5a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556920a5a020,0x5569228f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40f5cf2262f6c4a740d0e72decc26994564f09e5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8056 processed earlier; will process 2973 files now Step #5: #1 pulse cov: 4088 ft: 4089 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 4609 ft: 5197 exec/s: 0 rss: 182Mb Step #5: #4 pulse cov: 13766 ft: 15672 exec/s: 0 rss: 204Mb Step #5: ==223918== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5569173659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55691d9ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55691d9ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55691d9ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55691736bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5569172ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5569172c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55691735dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55691a32cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55691a32cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55691a32cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55691a32cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55691a32cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55691a32cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55691a32cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55691a32cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55691a32cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55691a32cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55691c5c1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5569192eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5569192f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5569190a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5569190a5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5569190a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5569190a5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5569190a5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5569190a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55691d9afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55691d9b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55691d9a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55691d9cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa918be7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5569172c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9650ce992bb91093549783b00ccd39b510691224 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6218 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 767164091 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559bef4a7810, 0x559bef69101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559bef691020,0x559bf15290e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9650ce992bb91093549783b00ccd39b510691224' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8062 processed earlier; will process 2967 files now Step #5: ==223954== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559be5f9c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559bec601898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559bec5e45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559bec5e44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559be5fa2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559be5f03b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559be5efe355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559be5f94c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559be8f63f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559be8f63f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559be8f63f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559be8f63f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559be8f63f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559be8f63f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559be8f63f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559be8f63f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559be8f63f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559be8f63f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559beb1f8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559be7f25b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559be7f30be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559be7cdcc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559be7cdcc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559be7cdd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559be7cdc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559be7cdc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559be7cdc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559bec5e6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559bec5ef928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559bec5d7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559bec602112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd4dc38d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559be5efcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7942754b481dab5b54070c5e5142a2a7ab0aedde Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6219 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 767745978 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555e8ed3f810, 0x555e8ef2901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555e8ef29020,0x555e90dc10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7942754b481dab5b54070c5e5142a2a7ab0aedde' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8063 processed earlier; will process 2966 files now Step #5: ==223990== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555e858349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555e8be99898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555e8be7c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555e8be7c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555e8583ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555e8579bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555e85796355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555e8582cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555e887fbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555e887fbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555e887fbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555e887fbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555e887fbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555e887fbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555e887fbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555e887fbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555e887fbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555e887fbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555e8aa90f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555e877bdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555e877c8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555e87574c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555e87574c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555e87575738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555e87574874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555e87574874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555e87574874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555e8be7eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555e8be87928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555e8be6f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555e8be9a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc7aea43082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555e85794b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-63132cc98ebf6b2736bed45057727633178d2df5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6220 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 768336077 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe1b597810, 0x55fe1b78101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe1b781020,0x55fe1d6190e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/63132cc98ebf6b2736bed45057727633178d2df5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8064 processed earlier; will process 2965 files now Step #5: #1 pulse cov: 4019 ft: 4020 exec/s: 0 rss: 180Mb Step #5: ==224026== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fe1208c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe186f1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe186d45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe186d44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe12092d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe11ff3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe11fee355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe12084c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe15053f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe15053f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe15053f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe15053f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe15053f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe15053f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe15053f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe15053f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe15053f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe15053f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe172e8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe14015b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe14020be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe13dccc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe13dccc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe13dcd738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe13dcc874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe13dcc874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe13dcc874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe186d6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe186df928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe186c7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe186f2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb77c599082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe11fecb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c8a40ea5eaeb95ccac68ce720f00492e94b93a77 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6221 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 769066424 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610b7a15810, 0x5610b7bff01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610b7bff020,0x5610b9a970e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c8a40ea5eaeb95ccac68ce720f00492e94b93a77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8066 processed earlier; will process 2963 files now Step #5: ==224062== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5610ae50a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610b4b6f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610b4b525dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610b4b524fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610ae510d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610ae471b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610ae46c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610ae502c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610b14d1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610b14d1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610b14d1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610b14d1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610b14d1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610b14d1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610b14d1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610b14d1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610b14d1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610b14d1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610b3766f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610b0493b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610b049ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610b024ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610b024ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610b024b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610b024a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610b024a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610b024a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610b4b54abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610b4b5d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610b4b45699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610b4b70112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9f0564c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610ae46ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a90e8c2367fb3016933d29962a37befd86b8c87f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6222 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 769781143 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e3f57e6810, 0x55e3f59d001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e3f59d0020,0x55e3f78680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a90e8c2367fb3016933d29962a37befd86b8c87f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8067 processed earlier; will process 2962 files now Step #5: ==224098== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e3ec2db9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e3f2940898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e3f29235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e3f29234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e3ec2e1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e3ec242b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e3ec23d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e3ec2d3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e3ef2a2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e3ef2a2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e3ef2a2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e3ef2a2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e3ef2a2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e3ef2a2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e3ef2a2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e3ef2a2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e3ef2a2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e3ef2a2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e3f1537f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e3ee264b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e3ee26fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e3ee01bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e3ee01bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e3ee01c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e3ee01b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e3ee01b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e3ee01b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e3f2925abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e3f292e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e3f2916699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e3f2941112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fce19d39082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e3ec23bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-74da72be2a832776055bd796bdae67b86e341c74 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6223 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 770390098 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563326668810, 0x56332685201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563326852020,0x5633286ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/74da72be2a832776055bd796bdae67b86e341c74' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8068 processed earlier; will process 2961 files now Step #5: ==224134== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56331d15d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5633237c2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5633237a55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5633237a54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56331d163d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56331d0c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56331d0bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56331d155c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563320124f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563320124f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563320124f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563320124f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563320124f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563320124f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563320124f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563320124f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563320124f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563320124f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5633223b9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56331f0e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56331f0f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56331ee9dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56331ee9dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56331ee9e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56331ee9d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56331ee9d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56331ee9d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5633237a7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5633237b0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563323798699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5633237c3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe562061082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56331d0bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-03614e0abecd0199928d3ff038b94665406b8ec4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6224 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 771045166 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5577c5e4e810, 0x5577c603801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5577c6038020,0x5577c7ed00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03614e0abecd0199928d3ff038b94665406b8ec4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8069 processed earlier; will process 2960 files now Step #5: #1 pulse cov: 4369 ft: 4370 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 16382 ft: 17614 exec/s: 0 rss: 204Mb Step #5: ==224170== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5577bc9439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5577c2fa8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5577c2f8b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5577c2f8b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5577bc949d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5577bc8aab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5577bc8a5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5577bc93bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5577bf90af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5577bf90af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5577bf90af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5577bf90af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5577bf90af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5577bf90af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5577bf90af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5577bf90af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5577bf90af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5577bf90af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5577c1b9ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5577be8ccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5577be8d7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5577be683c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5577be683c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5577be684738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5577be683874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5577be683874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5577be683874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5577c2f8dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5577c2f96928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5577c2f7e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5577c2fa9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8c8620b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5577bc8a3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6b9eb2948fa68789766acdba03bc64ba72f15c90 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6225 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 771805355 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c72ac24810, 0x55c72ae0e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c72ae0e020,0x55c72cca60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6b9eb2948fa68789766acdba03bc64ba72f15c90' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8072 processed earlier; will process 2957 files now Step #5: ==224206== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c7217199c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c727d7e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c727d615dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c727d614fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c72171fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c721680b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c72167b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c721711c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c7246e0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c7246e0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c7246e0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c7246e0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c7246e0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c7246e0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c7246e0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c7246e0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c7246e0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c7246e0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c726975f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c7236a2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c7236adbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c723459c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c723459c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c72345a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c723459874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c723459874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c723459874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c727d63abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c727d6c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c727d54699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c727d7f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f23abf1f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c721679b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d9fb5d09189f07d3e355721ceb17caca9d439699 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6226 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 772506643 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563ca5bb0810, 0x563ca5d9a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563ca5d9a020,0x563ca7c320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d9fb5d09189f07d3e355721ceb17caca9d439699' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8073 processed earlier; will process 2956 files now Step #5: ==224242== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563c9c6a59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563ca2d0a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563ca2ced5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563ca2ced4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563c9c6abd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563c9c60cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563c9c607355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563c9c69dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563c9f66cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563c9f66cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563c9f66cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563c9f66cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563c9f66cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563c9f66cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563c9f66cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563c9f66cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563c9f66cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563c9f66cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563ca1901f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563c9e62eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563c9e639be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563c9e3e5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563c9e3e5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563c9e3e6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563c9e3e5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563c9e3e5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563c9e3e5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563ca2cefabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563ca2cf8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563ca2ce0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563ca2d0b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb61e72f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563c9c605b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e87540d68c77f1cdfbd2754aaa825f2043f029b2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6227 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 773141956 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559b81e6e810, 0x559b8205801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559b82058020,0x559b83ef00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e87540d68c77f1cdfbd2754aaa825f2043f029b2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8074 processed earlier; will process 2955 files now Step #5: #1 pulse cov: 4519 ft: 4520 exec/s: 0 rss: 181Mb Step #5: ==224278== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559b789639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559b7efc8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559b7efab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559b7efab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559b78969d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559b788cab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559b788c5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559b7895bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559b7b92af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559b7b92af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559b7b92af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559b7b92af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559b7b92af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559b7b92af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559b7b92af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559b7b92af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559b7b92af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559b7b92af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559b7dbbff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559b7a8ecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559b7a8f7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559b7a6a3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559b7a6a3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559b7a6a4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559b7a6a3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559b7a6a3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559b7a6a3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559b7efadabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559b7efb6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559b7ef9e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559b7efc9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f581f541082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559b788c3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fecd5e1749bec33b81c26fb8ed99fa272f234afb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6228 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 773939963 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5608be756810, 0x5608be94001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5608be940020,0x5608c07d80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fecd5e1749bec33b81c26fb8ed99fa272f234afb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8076 processed earlier; will process 2953 files now Step #5: #1 pulse cov: 3917 ft: 3918 exec/s: 0 rss: 180Mb Step #5: ==224314== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5608b524b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5608bb8b0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5608bb8935dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5608bb8934fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5608b5251d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5608b51b2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5608b51ad355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5608b5243c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5608b8212f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5608b8212f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5608b8212f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5608b8212f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5608b8212f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5608b8212f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5608b8212f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5608b8212f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5608b8212f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5608b8212f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5608ba4a7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5608b71d4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5608b71dfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5608b6f8bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5608b6f8bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5608b6f8c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5608b6f8b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5608b6f8b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5608b6f8b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5608bb895abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5608bb89e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5608bb886699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5608bb8b1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd93735e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5608b51abb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c41d7bded9f37f84a85532c909615c8a97323200 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6229 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 775336468 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c86f8c810, 0x559c8717601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c87176020,0x559c8900e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c41d7bded9f37f84a85532c909615c8a97323200' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8078 processed earlier; will process 2951 files now Step #5: ==224350== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559c7da819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c840e6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c840c95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c840c94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c7da87d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c7d9e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c7d9e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c7da79c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c80a48f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c80a48f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c80a48f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c80a48f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c80a48f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c80a48f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c80a48f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c80a48f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c80a48f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c80a48f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c82cddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c7fa0ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c7fa15be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c7f7c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c7f7c1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c7f7c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c7f7c1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c7f7c1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c7f7c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c840cbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c840d4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c840bc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c840e7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8d46a6b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c7d9e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e821594e6d641859e32eb349b94f0a69bc4c0da5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6230 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 775917118 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5560f9832810, 0x5560f9a1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5560f9a1c020,0x5560fb8b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e821594e6d641859e32eb349b94f0a69bc4c0da5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8079 processed earlier; will process 2950 files now Step #5: ==224386== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5560f03279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5560f698c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5560f696f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5560f696f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5560f032dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5560f028eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5560f0289355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5560f031fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5560f32eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5560f32eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5560f32eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5560f32eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5560f32eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5560f32eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5560f32eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5560f32eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5560f32eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5560f32eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5560f5583f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5560f22b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5560f22bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5560f2067c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5560f2067c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5560f2068738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5560f2067874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5560f2067874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5560f2067874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5560f6971abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5560f697a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5560f6962699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5560f698d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0500d0a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5560f0287b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ed4cd480e8d675030c5d8ddf6bd31768a49b8f5b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6231 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 776624131 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9bad6e810, 0x55a9baf5801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a9baf58020,0x55a9bcdf00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ed4cd480e8d675030c5d8ddf6bd31768a49b8f5b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8080 processed earlier; will process 2949 files now Step #5: #1 pulse cov: 3779 ft: 3780 exec/s: 0 rss: 180Mb Step #5: ==224422== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a9b18639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a9b7ec8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9b7eab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9b7eab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a9b1869d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a9b17cab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a9b17c5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a9b185bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9b482af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9b482af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9b482af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9b482af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9b482af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9b482af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9b482af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9b482af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9b482af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9b482af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a9b6abff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a9b37ecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a9b37f7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a9b35a3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a9b35a3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a9b35a4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a9b35a3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a9b35a3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a9b35a3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a9b7eadabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a9b7eb6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a9b7e9e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a9b7ec9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68e2f48082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a9b17c3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-071b417f5bfbe50360500cd080afdd5aba0a43dc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6232 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 777332537 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e7f6ea0810, 0x55e7f708a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e7f708a020,0x55e7f8f220e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/071b417f5bfbe50360500cd080afdd5aba0a43dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8082 processed earlier; will process 2947 files now Step #5: #1 pulse cov: 3936 ft: 3937 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4475 ft: 5023 exec/s: 0 rss: 181Mb Step #5: #4 pulse cov: 18453 ft: 20590 exec/s: 0 rss: 212Mb Step #5: ==224458== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e7ed9959c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e7f3ffa898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e7f3fdd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e7f3fdd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e7ed99bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e7ed8fcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e7ed8f7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e7ed98dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e7f095cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e7f095cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e7f095cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e7f095cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e7f095cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e7f095cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e7f095cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e7f095cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e7f095cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e7f095cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e7f2bf1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e7ef91eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e7ef929be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e7ef6d5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e7ef6d5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e7ef6d6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e7ef6d5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e7ef6d5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e7ef6d5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e7f3fdfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e7f3fe8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e7f3fd0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e7f3ffb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd99fc4c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e7ed8f5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2b53e9eaff2a4c033ed192a1e1811d11ce18d0ca Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6233 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 778282349 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56474f7e1810, 0x56474f9cb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56474f9cb020,0x5647518630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2b53e9eaff2a4c033ed192a1e1811d11ce18d0ca' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8087 processed earlier; will process 2942 files now Step #5: #1 pulse cov: 4352 ft: 4353 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 4576 ft: 5240 exec/s: 0 rss: 182Mb Step #5: ==224494== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647462d69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56474c93b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56474c91e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56474c91e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647462dcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56474623db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564746238355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647462cec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56474929df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56474929df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56474929df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56474929df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56474929df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56474929df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56474929df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56474929df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56474929df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56474929df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56474b532f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56474825fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56474826abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564748016c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564748016c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564748017738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564748016874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564748016874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564748016874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56474c920abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56474c929928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56474c911699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56474c93c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f30d115c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564746236b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-704e5406aaab44d5d2a3ae332d09c3c8c9ea9635 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6234 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 778984934 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561f27a07810, 0x561f27bf101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561f27bf1020,0x561f29a890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/704e5406aaab44d5d2a3ae332d09c3c8c9ea9635' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8090 processed earlier; will process 2939 files now Step #5: ==224530== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561f1e4fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561f24b61898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561f24b445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561f24b444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561f1e502d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561f1e463b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561f1e45e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561f1e4f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561f214c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561f214c3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561f214c3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561f214c3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561f214c3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561f214c3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561f214c3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561f214c3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561f214c3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561f214c3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561f23758f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561f20485b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561f20490be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561f2023cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561f2023cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561f2023d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561f2023c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561f2023c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561f2023c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561f24b46abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561f24b4f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561f24b37699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561f24b62112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fed2ce5b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561f1e45cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-63ae4233b08f50a03e3add8f2b437e0402367b5a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6235 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 779565607 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a1f921e810, 0x55a1f940801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1f9408020,0x55a1fb2a00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/63ae4233b08f50a03e3add8f2b437e0402367b5a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8091 processed earlier; will process 2938 files now Step #5: ==224566== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a1efd139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a1f6378898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a1f635b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a1f635b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a1efd19d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a1efc7ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a1efc75355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a1efd0bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a1f2cdaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a1f2cdaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a1f2cdaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a1f2cdaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a1f2cdaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a1f2cdaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a1f2cdaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a1f2cdaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a1f2cdaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a1f2cdaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a1f4f6ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a1f1c9cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a1f1ca7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a1f1a53c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a1f1a53c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a1f1a54738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a1f1a53874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a1f1a53874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a1f1a53874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a1f635dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a1f6366928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a1f634e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a1f6379112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffab2524082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a1efc73b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0ac076342d45b1411e0cdbc63691b01bd950f8d0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6236 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 780276979 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56241b5d3810, 0x56241b7bd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56241b7bd020,0x56241d6550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0ac076342d45b1411e0cdbc63691b01bd950f8d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8092 processed earlier; will process 2937 files now Step #5: #1 pulse cov: 4381 ft: 4382 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 12336 ft: 13259 exec/s: 0 rss: 198Mb Step #5: ==224602== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5624120c89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56241872d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5624187105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5624187104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5624120ced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56241202fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56241202a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5624120c0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56241508ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56241508ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56241508ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56241508ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56241508ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56241508ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56241508ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56241508ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56241508ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56241508ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562417324f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562414051b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56241405cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562413e08c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562413e08c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562413e09738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562413e08874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562413e08874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562413e08874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562418712abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56241871b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562418703699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56241872e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95cdcd1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562412028b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-db97a944ba30a01e285e9e5e331bfe588a343fbe Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6237 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 781006472 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55de5de68810, 0x55de5e05201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55de5e052020,0x55de5feea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/db97a944ba30a01e285e9e5e331bfe588a343fbe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8096 processed earlier; will process 2933 files now Step #5: ==224638== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55de5495d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55de5afc2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55de5afa55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55de5afa54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55de54963d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55de548c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55de548bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55de54955c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55de57924f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55de57924f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55de57924f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55de57924f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55de57924f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55de57924f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55de57924f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55de57924f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55de57924f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55de57924f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55de59bb9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55de568e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55de568f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55de5669dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55de5669dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55de5669e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55de5669d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55de5669d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55de5669d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55de5afa7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55de5afb0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55de5af98699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55de5afc3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4ceed7b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55de548bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a0c2149b0aba329d014ed20c841fa3a0cfde77d9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6238 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 782539847 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e5476be810, 0x55e5478a801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e5478a8020,0x55e5497400e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a0c2149b0aba329d014ed20c841fa3a0cfde77d9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8097 processed earlier; will process 2932 files now Step #5: ==224674== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e53e1b39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e544818898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e5447fb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e5447fb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e53e1b9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e53e11ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e53e115355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e53e1abc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e54117af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e54117af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e54117af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e54117af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e54117af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e54117af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e54117af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e54117af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e54117af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e54117af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e54340ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e54013cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e540147be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e53fef3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e53fef3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e53fef4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e53fef3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e53fef3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e53fef3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e5447fdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e544806928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e5447ee699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e544819112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd1a0fcd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e53e113b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d1adfd3df78b1a9562092105891d08f3ecf31fe6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6239 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 783735215 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560295303810, 0x5602954ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5602954ed020,0x5602973850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d1adfd3df78b1a9562092105891d08f3ecf31fe6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8098 processed earlier; will process 2931 files now Step #5: ==224710== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56028bdf89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56029245d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602924405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602924404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56028bdfed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56028bd5fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56028bd5a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56028bdf0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56028edbff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56028edbff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56028edbff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56028edbff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56028edbff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56028edbff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56028edbff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56028edbff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56028edbff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56028edbff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560291054f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56028dd81b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56028dd8cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56028db38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56028db38c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56028db39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56028db38874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56028db38874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56028db38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560292442abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56029244b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560292433699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56029245e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa813994082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56028bd58b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f3844344ac074253137cdfc7f4d8d0adfbff7b3c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6240 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 785157706 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55726eb9d810, 0x55726ed8701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55726ed87020,0x557270c1f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f3844344ac074253137cdfc7f4d8d0adfbff7b3c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8099 processed earlier; will process 2930 files now Step #5: #1 pulse cov: 4247 ft: 4248 exec/s: 0 rss: 180Mb Step #5: ==224746== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5572656929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55726bcf7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55726bcda5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55726bcda4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557265698d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5572655f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5572655f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55726568ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557268659f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557268659f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557268659f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557268659f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557268659f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557268659f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557268659f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557268659f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557268659f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557268659f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55726a8eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55726761bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557267626be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5572673d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5572673d2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5572673d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5572673d2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5572673d2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5572673d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55726bcdcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55726bce5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55726bccd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55726bcf8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd181759082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5572655f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ce4da105060137d341d738c0572d6c8c0e10703d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6241 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 785808391 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559c527ad810, 0x559c5299701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559c52997020,0x559c5482f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce4da105060137d341d738c0572d6c8c0e10703d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8101 processed earlier; will process 2928 files now Step #5: ==224782== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559c492a29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559c4f907898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559c4f8ea5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559c4f8ea4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559c492a8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559c49209b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559c49204355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559c4929ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559c4c269f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559c4c269f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559c4c269f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559c4c269f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559c4c269f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559c4c269f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559c4c269f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559c4c269f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559c4c269f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559c4c269f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559c4e4fef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559c4b22bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559c4b236be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559c4afe2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559c4afe2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559c4afe3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559c4afe2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559c4afe2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559c4afe2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559c4f8ecabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559c4f8f5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559c4f8dd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559c4f908112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f10c5a4e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559c49202b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8c334049abd4535d76980740c825965b3d2303d5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6242 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 786427452 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557a7f9df810, 0x557a7fbc901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557a7fbc9020,0x557a81a610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c334049abd4535d76980740c825965b3d2303d5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8102 processed earlier; will process 2927 files now Step #5: ==224818== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557a764d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557a7cb39898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557a7cb1c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557a7cb1c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557a764dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557a7643bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557a76436355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557a764ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557a7949bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557a7949bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557a7949bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557a7949bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557a7949bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557a7949bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557a7949bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557a7949bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557a7949bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557a7949bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557a7b730f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557a7845db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557a78468be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557a78214c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557a78214c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557a78215738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557a78214874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557a78214874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557a78214874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557a7cb1eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557a7cb27928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557a7cb0f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557a7cb3a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb6b4388082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557a76434b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-68f93cfeb47385d4d1c418f193b0151cde42334c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6243 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 787048136 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560fb605c810, 0x560fb624601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560fb6246020,0x560fb80de0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/68f93cfeb47385d4d1c418f193b0151cde42334c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8103 processed earlier; will process 2926 files now Step #5: #1 pulse cov: 4236 ft: 4237 exec/s: 0 rss: 181Mb Step #5: ==224854== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560facb519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560fb31b6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560fb31995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560fb31994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560facb57d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560facab8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560facab3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560facb49c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560fafb18f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560fafb18f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560fafb18f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560fafb18f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560fafb18f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560fafb18f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560fafb18f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560fafb18f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560fafb18f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560fafb18f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560fb1dadf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560faeadab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560faeae5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560fae891c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560fae891c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560fae892738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560fae891874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560fae891874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560fae891874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560fb319babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560fb31a4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560fb318c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560fb31b7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2251a0f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560facab1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-09014574590fa61a7e9b2eaf1a994c573b25dcfc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6244 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 787697371 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5579169a2810, 0x557916b8c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557916b8c020,0x557918a240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/09014574590fa61a7e9b2eaf1a994c573b25dcfc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8105 processed earlier; will process 2924 files now Step #5: #1 pulse cov: 3964 ft: 3965 exec/s: 0 rss: 179Mb Step #5: ==224890== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55790d4979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557913afc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557913adf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557913adf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55790d49dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55790d3feb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55790d3f9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55790d48fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55791045ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55791045ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55791045ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55791045ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55791045ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55791045ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55791045ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55791045ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55791045ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55791045ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579126f3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55790f420b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55790f42bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55790f1d7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55790f1d7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55790f1d8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55790f1d7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55790f1d7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55790f1d7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557913ae1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557913aea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557913ad2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557913afd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1988e6f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55790d3f7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e165e00a0d48da52cb4a392c518db6a768078791 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6245 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 788326393 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5631dfd54810, 0x5631dff3e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5631dff3e020,0x5631e1dd60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e165e00a0d48da52cb4a392c518db6a768078791' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8107 processed earlier; will process 2922 files now Step #5: ==224926== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5631d68499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5631dceae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5631dce915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5631dce914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5631d684fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5631d67b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5631d67ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5631d6841c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5631d9810f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5631d9810f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5631d9810f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5631d9810f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5631d9810f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5631d9810f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5631d9810f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5631d9810f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5631d9810f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5631d9810f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5631dbaa5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5631d87d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5631d87ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5631d8589c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5631d8589c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5631d858a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5631d8589874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5631d8589874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5631d8589874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5631dce93abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5631dce9c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5631dce84699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5631dceaf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8849fab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5631d67a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7a57520dc9a5a8c79c1b5c10bdd0ccc5725029b0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6246 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 788902885 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562216a28810, 0x562216c1201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562216c12020,0x562218aaa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7a57520dc9a5a8c79c1b5c10bdd0ccc5725029b0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8108 processed earlier; will process 2921 files now Step #5: ==224962== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56220d51d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562213b82898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562213b655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562213b654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56220d523d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56220d484b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56220d47f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56220d515c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5622104e4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5622104e4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5622104e4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5622104e4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5622104e4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5622104e4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5622104e4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5622104e4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5622104e4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5622104e4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562212779f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56220f4a6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56220f4b1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56220f25dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56220f25dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56220f25e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56220f25d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56220f25d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56220f25d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562213b67abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562213b70928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562213b58699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562213b83112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b8d5c0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56220d47db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3d582341bb75433437984564976ee26a92c3c489 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6247 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 789512148 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5597d3bb0810, 0x5597d3d9a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5597d3d9a020,0x5597d5c320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3d582341bb75433437984564976ee26a92c3c489' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8109 processed earlier; will process 2920 files now Step #5: ==224998== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5597ca6a59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5597d0d0a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5597d0ced5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5597d0ced4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5597ca6abd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5597ca60cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5597ca607355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5597ca69dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5597cd66cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5597cd66cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5597cd66cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5597cd66cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5597cd66cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5597cd66cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5597cd66cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5597cd66cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5597cd66cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5597cd66cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5597cf901f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5597cc62eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5597cc639be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5597cc3e5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5597cc3e5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5597cc3e6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5597cc3e5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5597cc3e5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5597cc3e5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5597d0cefabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5597d0cf8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5597d0ce0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5597d0d0b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f015ab3d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5597ca605b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d34972dcc3559a7183b7c65835979705e8a5d489 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6248 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 790107031 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed5d661810, 0x55ed5d84b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed5d84b020,0x55ed5f6e30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d34972dcc3559a7183b7c65835979705e8a5d489' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8110 processed earlier; will process 2919 files now Step #5: ==225034== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed541569c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed5a7bb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed5a79e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed5a79e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed5415cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed540bdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed540b8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed5414ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed5711df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed5711df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed5711df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed5711df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed5711df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed5711df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed5711df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed5711df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed5711df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed5711df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed593b2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed560dfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed560eabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed55e96c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed55e96c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed55e97738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed55e96874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed55e96874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed55e96874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed5a7a0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed5a7a9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed5a791699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed5a7bc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f952623d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed540b6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-75935bf05087f95333885b8512964b394f9d7d2b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6249 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 790672223 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5573c03c5810, 0x5573c05af01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5573c05af020,0x5573c24470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/75935bf05087f95333885b8512964b394f9d7d2b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8111 processed earlier; will process 2918 files now Step #5: ==225070== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5573b6eba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5573bd51f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5573bd5025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5573bd5024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5573b6ec0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5573b6e21b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5573b6e1c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5573b6eb2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5573b9e81f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5573b9e81f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5573b9e81f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5573b9e81f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5573b9e81f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5573b9e81f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5573b9e81f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5573b9e81f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5573b9e81f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5573b9e81f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5573bc116f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5573b8e43b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5573b8e4ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5573b8bfac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5573b8bfac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5573b8bfb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5573b8bfa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5573b8bfa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5573b8bfa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5573bd504abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5573bd50d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5573bd4f5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5573bd520112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8cd1d31082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5573b6e1ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ab97a431f7ad371ea6d4cef18acb4128fe71dc2b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6250 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 791259439 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56462eb0b810, 0x56462ecf501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56462ecf5020,0x564630b8d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ab97a431f7ad371ea6d4cef18acb4128fe71dc2b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8112 processed earlier; will process 2917 files now Step #5: ==225106== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5646256009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56462bc65898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56462bc485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56462bc484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564625606d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564625567b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564625562355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5646255f8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5646285c7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5646285c7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5646285c7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5646285c7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5646285c7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5646285c7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5646285c7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5646285c7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5646285c7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5646285c7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56462a85cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564627589b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564627594be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564627340c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564627340c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564627341738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564627340874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564627340874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564627340874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56462bc4aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56462bc53928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56462bc3b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56462bc66112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7a6d1eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564625560b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1b8df398baec5c5f5ef292437d23d917fffc9288 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6251 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 792662002 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d0e110c810, 0x55d0e12f601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d0e12f6020,0x55d0e318e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b8df398baec5c5f5ef292437d23d917fffc9288' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8113 processed earlier; will process 2916 files now Step #5: #1 pulse cov: 3940 ft: 3941 exec/s: 0 rss: 178Mb Step #5: ==225142== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d0d7c019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d0de266898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d0de2495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d0de2494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d0d7c07d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d0d7b68b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d0d7b63355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d0d7bf9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d0dabc8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d0dabc8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d0dabc8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d0dabc8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d0dabc8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d0dabc8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d0dabc8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d0dabc8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d0dabc8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d0dabc8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d0dce5df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d0d9b8ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d0d9b95be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d0d9941c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d0d9941c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d0d9942738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d0d9941874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d0d9941874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d0d9941874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d0de24babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d0de254928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d0de23c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d0de267112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7669098082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d0d7b61b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f3d2755e27c2c7d4721c8a8ac79ea1652273d4c0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6252 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 793382358 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ac2e7a810, 0x561ac306401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ac3064020,0x561ac4efc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f3d2755e27c2c7d4721c8a8ac79ea1652273d4c0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8115 processed earlier; will process 2914 files now Step #5: ==225178== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561ab996f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561abffd4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561abffb75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561abffb74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561ab9975d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561ab98d6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561ab98d1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561ab9967c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561abc936f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561abc936f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561abc936f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561abc936f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561abc936f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561abc936f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561abc936f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561abc936f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561abc936f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561abc936f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561abebcbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561abb8f8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561abb903be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561abb6afc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561abb6afc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561abb6b0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561abb6af874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561abb6af874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561abb6af874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561abffb9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561abffc2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561abffaa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561abffd5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd899f1b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561ab98cfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9ed887b39b413e436b0d75452f33d951a8cf515c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6253 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 793958966 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558465b23810, 0x558465d0d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558465d0d020,0x558467ba50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9ed887b39b413e436b0d75452f33d951a8cf515c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8116 processed earlier; will process 2913 files now Step #5: ==225214== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55845c6189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558462c7d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558462c605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558462c604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55845c61ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55845c57fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55845c57a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55845c610c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55845f5dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55845f5dff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55845f5dff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55845f5dff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55845f5dff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55845f5dff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55845f5dff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55845f5dff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55845f5dff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55845f5dff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558461874f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55845e5a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55845e5acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55845e358c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55845e358c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55845e359738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55845e358874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55845e358874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55845e358874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558462c62abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558462c6b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558462c53699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558462c7e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7178437082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55845c578b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-912c1fb7608b777bffd54515b80d258a4d3a5765 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6254 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 794540764 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558632335810, 0x55863251f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55863251f020,0x5586343b70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/912c1fb7608b777bffd54515b80d258a4d3a5765' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8117 processed earlier; will process 2912 files now Step #5: ==225250== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558628e2a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55862f48f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55862f4725dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55862f4724fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558628e30d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558628d91b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558628d8c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558628e22c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55862bdf1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55862bdf1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55862bdf1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55862bdf1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55862bdf1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55862bdf1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55862bdf1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55862bdf1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55862bdf1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55862bdf1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55862e086f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55862adb3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55862adbebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55862ab6ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55862ab6ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55862ab6b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55862ab6a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55862ab6a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55862ab6a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55862f474abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55862f47d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55862f465699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55862f490112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f229b70c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558628d8ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-de0c99def3f3b0d1fc3cbcd9150fe6f8b4fc03a3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6255 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 795164194 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557680c31810, 0x557680e1b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557680e1b020,0x557682cb30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de0c99def3f3b0d1fc3cbcd9150fe6f8b4fc03a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8118 processed earlier; will process 2911 files now Step #5: #1 pulse cov: 3957 ft: 3958 exec/s: 0 rss: 182Mb Step #5: #2 pulse cov: 4688 ft: 5161 exec/s: 0 rss: 183Mb Step #5: ==225286== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5576777269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55767dd8b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55767dd6e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55767dd6e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55767772cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55767768db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557677688355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55767771ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55767a6edf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55767a6edf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55767a6edf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55767a6edf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55767a6edf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55767a6edf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55767a6edf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55767a6edf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55767a6edf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55767a6edf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55767c982f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5576796afb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5576796babe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557679466c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557679466c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557679467738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557679466874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557679466874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557679466874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55767dd70abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55767dd79928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55767dd61699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55767dd8c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb6ae9c4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557677686b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8a3696dbc3bb8d6d1fb4ef698d6fc4db7c71f71b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6256 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 795992862 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555f8dff2810, 0x555f8e1dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555f8e1dc020,0x555f900740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8a3696dbc3bb8d6d1fb4ef698d6fc4db7c71f71b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8121 processed earlier; will process 2908 files now Step #5: #1 pulse cov: 4289 ft: 4290 exec/s: 0 rss: 179Mb Step #5: ==225322== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555f84ae79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555f8b14c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555f8b12f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555f8b12f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555f84aedd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555f84a4eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555f84a49355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555f84adfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555f87aaef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555f87aaef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555f87aaef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555f87aaef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555f87aaef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555f87aaef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555f87aaef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555f87aaef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555f87aaef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555f87aaef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555f89d43f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555f86a70b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555f86a7bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555f86827c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555f86827c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555f86828738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555f86827874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555f86827874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555f86827874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555f8b131abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555f8b13a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555f8b122699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555f8b14d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f42d94ec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555f84a47b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6f0f655da1cc53e1ba432749320cb1f2414e0141 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6257 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 796698589 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f5bbd49810, 0x55f5bbf3301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f5bbf33020,0x55f5bddcb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6f0f655da1cc53e1ba432749320cb1f2414e0141' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8123 processed earlier; will process 2906 files now Step #5: ==225358== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f5b283e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f5b8ea3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f5b8e865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f5b8e864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f5b2844d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f5b27a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f5b27a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f5b2836c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f5b5805f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f5b5805f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f5b5805f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f5b5805f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f5b5805f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f5b5805f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f5b5805f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f5b5805f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f5b5805f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f5b5805f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f5b7a9af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f5b47c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f5b47d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f5b457ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f5b457ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f5b457f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f5b457e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f5b457e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f5b457e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f5b8e88abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f5b8e91928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f5b8e79699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f5b8ea4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4359a8f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f5b279eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4ad07504db1d58d6a0bb0bd8baa85ba7bc6fb603 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6258 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 797293434 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5604d9886810, 0x5604d9a7001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5604d9a70020,0x5604db9080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4ad07504db1d58d6a0bb0bd8baa85ba7bc6fb603' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8124 processed earlier; will process 2905 files now Step #5: #1 pulse cov: 4384 ft: 4385 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4543 ft: 4984 exec/s: 0 rss: 179Mb Step #5: ==225394== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5604d037b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5604d69e0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5604d69c35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5604d69c34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5604d0381d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5604d02e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5604d02dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5604d0373c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5604d3342f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5604d3342f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5604d3342f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5604d3342f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5604d3342f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5604d3342f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5604d3342f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5604d3342f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5604d3342f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5604d3342f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5604d55d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5604d2304b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5604d230fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5604d20bbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5604d20bbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5604d20bc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5604d20bb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5604d20bb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5604d20bb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5604d69c5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5604d69ce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5604d69b6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5604d69e1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fec09d00082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5604d02dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cf140d218df4a13c69501c1dd07a076960635275 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6259 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 797956273 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561013caf810, 0x561013e9901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561013e99020,0x561015d310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cf140d218df4a13c69501c1dd07a076960635275' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8127 processed earlier; will process 2902 files now Step #5: ==225430== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56100a7a49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561010e09898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561010dec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561010dec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56100a7aad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56100a70bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56100a706355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56100a79cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56100d76bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56100d76bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56100d76bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56100d76bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56100d76bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56100d76bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56100d76bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56100d76bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56100d76bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56100d76bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56100fa00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56100c72db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56100c738be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56100c4e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56100c4e4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56100c4e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56100c4e4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56100c4e4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56100c4e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561010deeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561010df7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561010ddf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561010e0a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff4304bd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56100a704b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-95724f33bf58143afc4e41f0fd6f956333a30ffc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6260 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 798555366 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d59a538810, 0x55d59a72201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d59a722020,0x55d59c5ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/95724f33bf58143afc4e41f0fd6f956333a30ffc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8128 processed earlier; will process 2901 files now Step #5: #1 pulse cov: 3782 ft: 3783 exec/s: 0 rss: 180Mb Step #5: ==225466== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d59102d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d597692898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d5976755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d5976754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d591033d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d590f94b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d590f8f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d591025c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d593ff4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d593ff4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d593ff4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d593ff4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d593ff4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d593ff4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d593ff4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d593ff4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d593ff4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d593ff4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d596289f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d592fb6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d592fc1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d592d6dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d592d6dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d592d6e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d592d6d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d592d6d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d592d6d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d597677abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d597680928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d597668699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d597693112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcca6bf0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d590f8db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7466604e5dc297d181de0ceb6d555f6265f9c4c8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6261 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 799324250 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562895978810, 0x562895b6201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562895b62020,0x5628979fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7466604e5dc297d181de0ceb6d555f6265f9c4c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8130 processed earlier; will process 2899 files now Step #5: ==225502== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56288c46d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562892ad2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562892ab55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562892ab54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56288c473d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56288c3d4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56288c3cf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56288c465c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56288f434f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56288f434f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56288f434f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56288f434f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56288f434f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56288f434f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56288f434f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56288f434f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56288f434f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56288f434f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5628916c9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56288e3f6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56288e401be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56288e1adc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56288e1adc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56288e1ae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56288e1ad874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56288e1ad874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56288e1ad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562892ab7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562892ac0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562892aa8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562892ad3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f90b045b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56288c3cdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1cfe4edac4852a07b0c232409a7e2b17cf410dcc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6262 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 800678900 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c0d21a810, 0x556c0d40401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c0d404020,0x556c0f29c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1cfe4edac4852a07b0c232409a7e2b17cf410dcc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8131 processed earlier; will process 2898 files now Step #5: ==225538== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556c03d0f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c0a374898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c0a3575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c0a3574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556c03d15d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556c03c76b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556c03c71355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556c03d07c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556c06cd6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556c06cd6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556c06cd6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556c06cd6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556c06cd6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556c06cd6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556c06cd6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556c06cd6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556c06cd6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556c06cd6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c08f6bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556c05c98b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556c05ca3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556c05a4fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556c05a4fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556c05a50738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556c05a4f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556c05a4f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556c05a4f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c0a359abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c0a362928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c0a34a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c0a375112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb7c5fa8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556c03c6fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-12c8e4afe3ea1dac53000cf4366447e8c02be9f1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6263 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 802133206 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5563d1d63810, 0x5563d1f4d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5563d1f4d020,0x5563d3de50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/12c8e4afe3ea1dac53000cf4366447e8c02be9f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8132 processed earlier; will process 2897 files now Step #5: ==225574== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5563c88589c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5563ceebd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5563ceea05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5563ceea04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5563c885ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5563c87bfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5563c87ba355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5563c8850c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5563cb81ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5563cb81ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5563cb81ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5563cb81ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5563cb81ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5563cb81ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5563cb81ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5563cb81ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5563cb81ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5563cb81ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5563cdab4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5563ca7e1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5563ca7ecbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5563ca598c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5563ca598c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5563ca599738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5563ca598874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5563ca598874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5563ca598874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5563ceea2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5563ceeab928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5563cee93699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5563ceebe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff723184082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5563c87b8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-73761bceb12e6508ff4b05a6c40fb6ab3bf35c27 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6264 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 803645500 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb06a09810, 0x55eb06bf301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb06bf3020,0x55eb08a8b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/73761bceb12e6508ff4b05a6c40fb6ab3bf35c27' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8133 processed earlier; will process 2896 files now Step #5: #1 pulse cov: 4198 ft: 4199 exec/s: 0 rss: 180Mb Step #5: ==225610== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eafd4fe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb03b63898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb03b465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb03b464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eafd504d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eafd465b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eafd460355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eafd4f6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb004c5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb004c5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb004c5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb004c5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb004c5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb004c5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb004c5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb004c5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb004c5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb004c5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb0275af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eaff487b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eaff492be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eaff23ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eaff23ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eaff23f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eaff23e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eaff23e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eaff23e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb03b48abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb03b51928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb03b39699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb03b64112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff2d5745082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eafd45eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2d08233dc5941d143f4ea9be0f5408f76ccbf299 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6265 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 805192185 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c460e5f810, 0x55c46104901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c461049020,0x55c462ee10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2d08233dc5941d143f4ea9be0f5408f76ccbf299' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8135 processed earlier; will process 2894 files now Step #5: ==225646== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c4579549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c45dfb9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c45df9c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c45df9c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c45795ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c4578bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c4578b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c45794cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c45a91bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c45a91bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c45a91bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c45a91bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c45a91bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c45a91bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c45a91bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c45a91bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c45a91bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c45a91bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c45cbb0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c4598ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c4598e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c459694c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c459694c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c459695738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c459694874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c459694874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c459694874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c45df9eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c45dfa7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c45df8f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c45dfba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9bb57eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c4578b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ae6682d3bc252beb1688d2529204c4e99c38c4cd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6266 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 805810090 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555a708c5810, 0x555a70aaf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555a70aaf020,0x555a729470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ae6682d3bc252beb1688d2529204c4e99c38c4cd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8136 processed earlier; will process 2893 files now Step #5: ==225682== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555a673ba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555a6da1f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555a6da025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555a6da024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555a673c0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555a67321b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555a6731c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555a673b2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555a6a381f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555a6a381f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555a6a381f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555a6a381f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555a6a381f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555a6a381f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555a6a381f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555a6a381f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555a6a381f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555a6a381f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555a6c616f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555a69343b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555a6934ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555a690fac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555a690fac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555a690fb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555a690fa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555a690fa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555a690fa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555a6da04abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555a6da0d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555a6d9f5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555a6da20112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ab669c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555a6731ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fe6e54b952c3bdc490f5402afaf7b42fdaa6429a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6267 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 807306360 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5637900bd810, 0x5637902a701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5637902a7020,0x56379213f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fe6e54b952c3bdc490f5402afaf7b42fdaa6429a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8137 processed earlier; will process 2892 files now Step #5: ==225718== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563786bb29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56378d217898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56378d1fa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56378d1fa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563786bb8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563786b19b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563786b14355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563786baac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563789b79f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563789b79f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563789b79f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563789b79f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563789b79f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563789b79f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563789b79f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563789b79f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563789b79f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563789b79f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56378be0ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563788b3bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563788b46be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5637888f2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5637888f2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5637888f3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5637888f2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5637888f2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5637888f2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56378d1fcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56378d205928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56378d1ed699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56378d218112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9e5e5b5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563786b12b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-40f0f71c0b2b1676d7c0d2d927df9da819382c47 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6268 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 807867746 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562739bca810, 0x562739db401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562739db4020,0x56273bc4c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40f0f71c0b2b1676d7c0d2d927df9da819382c47' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8138 processed earlier; will process 2891 files now Step #5: ==225754== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5627306bf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562736d24898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562736d075dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562736d074fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5627306c5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562730626b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562730621355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5627306b7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562733686f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562733686f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562733686f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562733686f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562733686f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562733686f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562733686f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562733686f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562733686f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562733686f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56273591bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562732648b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562732653be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5627323ffc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5627323ffc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562732400738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5627323ff874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5627323ff874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5627323ff874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562736d09abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562736d12928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562736cfa699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562736d25112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb839782082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56273061fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c93f16c590cca8d811a5a6bbdc5ec9698027b43a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6269 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 809329172 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55590d916810, 0x55590db0001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55590db00020,0x55590f9980e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c93f16c590cca8d811a5a6bbdc5ec9698027b43a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8139 processed earlier; will process 2890 files now Step #5: ==225790== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55590440b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55590aa70898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55590aa535dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55590aa534fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555904411d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555904372b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55590436d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555904403c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5559073d2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5559073d2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5559073d2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5559073d2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5559073d2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5559073d2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5559073d2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5559073d2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5559073d2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5559073d2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555909667f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555906394b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55590639fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55590614bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55590614bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55590614c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55590614b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55590614b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55590614b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55590aa55abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55590aa5e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55590aa46699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55590aa71112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f20cc4ea082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55590436bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bbb0f654ce21cde51a609facc105d22d8b86b35c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6270 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 810039915 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557322037810, 0x55732222101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557322221020,0x5573240b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bbb0f654ce21cde51a609facc105d22d8b86b35c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8140 processed earlier; will process 2889 files now Step #5: #1 pulse cov: 3560 ft: 3561 exec/s: 0 rss: 181Mb Step #5: ==225826== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557318b2c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55731f191898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55731f1745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55731f1744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557318b32d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557318a93b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557318a8e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557318b24c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55731baf3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55731baf3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55731baf3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55731baf3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55731baf3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55731baf3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55731baf3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55731baf3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55731baf3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55731baf3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55731dd88f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55731aab5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55731aac0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55731a86cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55731a86cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55731a86d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55731a86c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55731a86c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55731a86c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55731f176abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55731f17f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55731f167699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55731f192112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95cbdac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557318a8cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-81d2d4288ec7da9b27bf87b8716e6c09773e2c40 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6271 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 810817997 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561e41709810, 0x561e418f301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561e418f3020,0x561e4378b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/81d2d4288ec7da9b27bf87b8716e6c09773e2c40' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8142 processed earlier; will process 2887 files now Step #5: #1 pulse cov: 3508 ft: 3509 exec/s: 0 rss: 179Mb Step #5: ==225862== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561e381fe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561e3e863898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561e3e8465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561e3e8464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561e38204d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561e38165b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561e38160355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561e381f6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561e3b1c5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561e3b1c5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561e3b1c5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561e3b1c5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561e3b1c5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561e3b1c5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561e3b1c5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561e3b1c5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561e3b1c5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561e3b1c5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561e3d45af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561e3a187b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561e3a192be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561e39f3ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561e39f3ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561e39f3f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561e39f3e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561e39f3e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561e39f3e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561e3e848abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561e3e851928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561e3e839699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561e3e864112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f62aaa23082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561e3815eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-eab0bd15da2748f07a08fedd968a9f6f0d1e9c7c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6272 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 812299824 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ba317aa810, 0x55ba3199401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ba31994020,0x55ba3382c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eab0bd15da2748f07a08fedd968a9f6f0d1e9c7c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8144 processed earlier; will process 2885 files now Step #5: #1 pulse cov: 3890 ft: 3891 exec/s: 0 rss: 180Mb Step #5: ==225898== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ba2829f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ba2e904898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ba2e8e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ba2e8e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ba282a5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ba28206b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ba28201355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ba28297c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ba2b266f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ba2b266f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ba2b266f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ba2b266f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ba2b266f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ba2b266f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ba2b266f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ba2b266f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ba2b266f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ba2b266f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ba2d4fbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ba2a228b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ba2a233be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ba29fdfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ba29fdfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ba29fe0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ba29fdf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ba29fdf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ba29fdf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ba2e8e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ba2e8f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ba2e8da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ba2e905112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa779fb4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ba281ffb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3e003280fc99696748c82c977cfd1654fc4c348e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6273 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 812946340 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562b2fe06810, 0x562b2fff001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562b2fff0020,0x562b31e880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3e003280fc99696748c82c977cfd1654fc4c348e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8146 processed earlier; will process 2883 files now Step #5: ==225934== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562b268fb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562b2cf60898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562b2cf435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562b2cf434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562b26901d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562b26862b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562b2685d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562b268f3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562b298c2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562b298c2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562b298c2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562b298c2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562b298c2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562b298c2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562b298c2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562b298c2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562b298c2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562b298c2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562b2bb57f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562b28884b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562b2888fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562b2863bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562b2863bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562b2863c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562b2863b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562b2863b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562b2863b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562b2cf45abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562b2cf4e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562b2cf36699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562b2cf61112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb94c15d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562b2685bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec22c30ddaa77e8c37422762fa9ce2c4c4db635e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6274 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 813512446 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0fdbae810, 0x55a0fdd9801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0fdd98020,0x55a0ffc300e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec22c30ddaa77e8c37422762fa9ce2c4c4db635e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8147 processed earlier; will process 2882 files now Step #5: ==225970== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a0f46a39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0fad08898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0faceb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0faceb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a0f46a9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a0f460ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a0f4605355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a0f469bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a0f766af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a0f766af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a0f766af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a0f766af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a0f766af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a0f766af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a0f766af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a0f766af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a0f766af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a0f766af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a0f98fff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a0f662cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a0f6637be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a0f63e3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a0f63e3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a0f63e4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a0f63e3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a0f63e3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a0f63e3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0facedabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0facf6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0facde699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0fad09112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f66b4930082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a0f4603b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b56dfe304b9d744148663dd2f160b4b5e87f021f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6275 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 814926061 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55870a5c9810, 0x55870a7b301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55870a7b3020,0x55870c64b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b56dfe304b9d744148663dd2f160b4b5e87f021f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8148 processed earlier; will process 2881 files now Step #5: #1 pulse cov: 3934 ft: 3935 exec/s: 0 rss: 180Mb Step #5: ==226006== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5587010be9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558707723898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5587077065dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5587077064fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5587010c4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558701025b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558701020355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5587010b6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558704085f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558704085f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558704085f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558704085f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558704085f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558704085f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558704085f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558704085f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558704085f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558704085f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55870631af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558703047b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558703052be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558702dfec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558702dfec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558702dff738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558702dfe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558702dfe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558702dfe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558707708abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558707711928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5587076f9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558707724112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f755821f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55870101eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-89f87518f61af9ca14c4f560a66ddf5b364aa098 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6276 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 815600344 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b242f57810, 0x55b24314101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b243141020,0x55b244fd90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/89f87518f61af9ca14c4f560a66ddf5b364aa098' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8150 processed earlier; will process 2879 files now Step #5: #1 pulse cov: 4028 ft: 4029 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4130 ft: 4627 exec/s: 0 rss: 179Mb Step #5: ==226042== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b239a4c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b2400b1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b2400945dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b2400944fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b239a52d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b2399b3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b2399ae355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b239a44c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b23ca13f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b23ca13f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b23ca13f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b23ca13f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b23ca13f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b23ca13f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b23ca13f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b23ca13f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b23ca13f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b23ca13f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b23eca8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b23b9d5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b23b9e0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b23b78cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b23b78cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b23b78d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b23b78c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b23b78c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b23b78c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b240096abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b24009f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b240087699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b2400b2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f869f0a4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b2399acb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-66d865def0eb70de465ac5f998138e73ad15e1d0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6277 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 816417630 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640c4914810, 0x5640c4afe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640c4afe020,0x5640c69960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/66d865def0eb70de465ac5f998138e73ad15e1d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8153 processed earlier; will process 2876 files now Step #5: #1 pulse cov: 4162 ft: 4163 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4563 ft: 4884 exec/s: 0 rss: 180Mb Step #5: ==226078== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5640bb4099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5640c1a6e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640c1a515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640c1a514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5640bb40fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5640bb370b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5640bb36b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5640bb401c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5640be3d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5640be3d0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5640be3d0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5640be3d0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5640be3d0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5640be3d0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5640be3d0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5640be3d0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5640be3d0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5640be3d0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5640c0665f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5640bd392b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5640bd39dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5640bd149c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5640bd149c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5640bd14a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5640bd149874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5640bd149874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5640bd149874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5640c1a53abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5640c1a5c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5640c1a44699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5640c1a6f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f115f049082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5640bb369b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-da62db9306c5c829a04314d6b2517fd4584e3299 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6278 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 817273792 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec55d74810, 0x55ec55f5e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec55f5e020,0x55ec57df60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/da62db9306c5c829a04314d6b2517fd4584e3299' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8157 processed earlier; will process 2872 files now Step #5: #1 pulse cov: 3790 ft: 3791 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4210 ft: 4639 exec/s: 0 rss: 181Mb Step #5: ==226114== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec4c8699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec52ece898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec52eb15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec52eb14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec4c86fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec4c7d0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec4c7cb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec4c861c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec4f830f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec4f830f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec4f830f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec4f830f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec4f830f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec4f830f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec4f830f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec4f830f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec4f830f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec4f830f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec51ac5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec4e7f2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec4e7fdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec4e5a9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec4e5a9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec4e5aa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec4e5a9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec4e5a9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec4e5a9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec52eb3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec52ebc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec52ea4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec52ecf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b263df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec4c7c9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d95c2053852e1c6b880598424e2c03ca96b82036 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6279 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 818000495 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5579edf2c810, 0x5579ee11601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5579ee116020,0x5579effae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d95c2053852e1c6b880598424e2c03ca96b82036' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8161 processed earlier; will process 2868 files now Step #5: #1 pulse cov: 4201 ft: 4202 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 4720 ft: 5220 exec/s: 0 rss: 182Mb Step #5: ==226150== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5579e4a219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5579eb086898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5579eb0695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5579eb0694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5579e4a27d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5579e4988b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5579e4983355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5579e4a19c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5579e79e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5579e79e8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5579e79e8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5579e79e8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5579e79e8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5579e79e8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5579e79e8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5579e79e8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5579e79e8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5579e79e8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5579e9c7df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5579e69aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5579e69b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5579e6761c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5579e6761c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5579e6762738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5579e6761874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5579e6761874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5579e6761874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5579eb06babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5579eb074928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5579eb05c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5579eb087112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbcbe227082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5579e4981b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2873a948013f43d9e382966b1eb2c056874d5e6a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6280 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 818743955 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d69090c810, 0x55d690af601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d690af6020,0x55d69298e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2873a948013f43d9e382966b1eb2c056874d5e6a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8165 processed earlier; will process 2864 files now Step #5: #1 pulse cov: 4093 ft: 4094 exec/s: 0 rss: 180Mb Step #5: ==226186== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d6874019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d68da66898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d68da495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d68da494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d687407d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d687368b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d687363355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d6873f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d68a3c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d68a3c8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d68a3c8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d68a3c8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d68a3c8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d68a3c8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d68a3c8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d68a3c8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d68a3c8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d68a3c8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d68c65df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d68938ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d689395be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d689141c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d689141c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d689142738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d689141874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d689141874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d689141874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d68da4babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d68da54928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d68da3c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d68da67112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe0bf550082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d687361b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1665442a9e6b4e7b810c5d6549f4a4b52e7611e9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6281 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 820389145 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562cd7cf3810, 0x562cd7edd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562cd7edd020,0x562cd9d750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1665442a9e6b4e7b810c5d6549f4a4b52e7611e9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8167 processed earlier; will process 2862 files now Step #5: ==226222== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562cce7e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562cd4e4d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562cd4e305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562cd4e304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562cce7eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562cce74fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562cce74a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562cce7e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562cd17aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562cd17aff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562cd17aff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562cd17aff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562cd17aff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562cd17aff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562cd17aff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562cd17aff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562cd17aff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562cd17aff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562cd3a44f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562cd0771b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562cd077cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562cd0528c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562cd0528c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562cd0529738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562cd0528874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562cd0528874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562cd0528874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562cd4e32abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562cd4e3b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562cd4e23699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562cd4e4e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1802893082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562cce748b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e1b54b6257396a2b29946302d90d966bf6b40c49 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6282 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 820984713 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556bc545d810, 0x556bc564701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556bc5647020,0x556bc74df0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e1b54b6257396a2b29946302d90d966bf6b40c49' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8168 processed earlier; will process 2861 files now Step #5: ==226258== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556bbbf529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556bc25b7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556bc259a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556bc259a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556bbbf58d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556bbbeb9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556bbbeb4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556bbbf4ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556bbef19f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556bbef19f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556bbef19f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556bbef19f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556bbef19f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556bbef19f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556bbef19f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556bbef19f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556bbef19f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556bbef19f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556bc11aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556bbdedbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556bbdee6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556bbdc92c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556bbdc92c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556bbdc93738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556bbdc92874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556bbdc92874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556bbdc92874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556bc259cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556bc25a5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556bc258d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556bc25b8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68c4e11082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556bbbeb2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e3e3a8947576eedb1bc7fbd6c1ceedf55a8b11e6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6283 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 821556790 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bd3d4d1810, 0x55bd3d6bb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bd3d6bb020,0x55bd3f5530e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e3e3a8947576eedb1bc7fbd6c1ceedf55a8b11e6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8169 processed earlier; will process 2860 files now Step #5: ==226294== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bd33fc69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bd3a62b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bd3a60e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bd3a60e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bd33fccd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bd33f2db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bd33f28355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bd33fbec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bd36f8df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bd36f8df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bd36f8df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bd36f8df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bd36f8df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bd36f8df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bd36f8df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bd36f8df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bd36f8df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bd36f8df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bd39222f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bd35f4fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bd35f5abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bd35d06c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bd35d06c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bd35d07738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bd35d06874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bd35d06874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bd35d06874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bd3a610abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bd3a619928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bd3a601699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bd3a62c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe51273e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bd33f26b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6033f76eea1394846232e372be04af1f57d1e476 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6284 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 822128267 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ae0af7d810, 0x55ae0b16701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ae0b167020,0x55ae0cfff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6033f76eea1394846232e372be04af1f57d1e476' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8170 processed earlier; will process 2859 files now Step #5: #1 pulse cov: 4099 ft: 4100 exec/s: 0 rss: 179Mb Step #5: ==226330== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ae01a729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ae080d7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ae080ba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ae080ba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ae01a78d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ae019d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ae019d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ae01a6ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ae04a39f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ae04a39f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ae04a39f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ae04a39f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ae04a39f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ae04a39f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ae04a39f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ae04a39f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ae04a39f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ae04a39f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ae06ccef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ae039fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ae03a06be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ae037b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ae037b2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ae037b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ae037b2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ae037b2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ae037b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ae080bcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ae080c5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ae080ad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ae080d8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f35726ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ae019d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7468b522368961762cf21e3c869cf7a5c881e851 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6285 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 822900559 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f2a0c58810, 0x55f2a0e4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f2a0e42020,0x55f2a2cda0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7468b522368961762cf21e3c869cf7a5c881e851' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8172 processed earlier; will process 2857 files now Step #5: ==226366== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f29774d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f29ddb2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f29dd955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f29dd954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f297753d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f2976b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f2976af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f297745c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f29a714f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f29a714f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f29a714f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f29a714f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f29a714f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f29a714f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f29a714f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f29a714f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f29a714f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f29a714f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f29c9a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f2996d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f2996e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f29948dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f29948dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f29948e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f29948d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f29948d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f29948d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f29dd97abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f29dda0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f29dd88699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f29ddb3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6c6bde6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f2976adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-53b67db7225f402a6569be3e7f2d7f1ac40920ae Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6286 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 823503275 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5620848dd810, 0x562084ac701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562084ac7020,0x56208695f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/53b67db7225f402a6569be3e7f2d7f1ac40920ae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8173 processed earlier; will process 2856 files now Step #5: #1 pulse cov: 11792 ft: 11793 exec/s: 0 rss: 197Mb Step #5: ==226402== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56207b3d29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562081a37898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562081a1a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562081a1a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56207b3d8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56207b339b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56207b334355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56207b3cac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56207e399f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56207e399f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56207e399f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56207e399f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56207e399f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56207e399f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56207e399f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56207e399f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56207e399f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56207e399f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56208062ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56207d35bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56207d366be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56207d112c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56207d112c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56207d113738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56207d112874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56207d112874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56207d112874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562081a1cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562081a25928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562081a0d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562081a38112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2892c77082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56207b332b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-612d1fc58d162f939e9f8eb45c3a7ca977382323 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6287 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 824156917 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d33436d810, 0x55d33455701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d334557020,0x55d3363ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/612d1fc58d162f939e9f8eb45c3a7ca977382323' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8175 processed earlier; will process 2854 files now Step #5: ==226438== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d32ae629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d3314c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d3314aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d3314aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d32ae68d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d32adc9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d32adc4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d32ae5ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d32de29f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d32de29f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d32de29f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d32de29f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d32de29f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d32de29f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d32de29f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d32de29f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d32de29f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d32de29f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d3300bef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d32cdebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d32cdf6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d32cba2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d32cba2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d32cba3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d32cba2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d32cba2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d32cba2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d3314acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d3314b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d33149d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d3314c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0cf44df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d32adc2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a06cacf43e1bfbd5747a603fe019bdbe9aac8c64 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6288 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 824725326 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563bc1ae1810, 0x563bc1ccb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563bc1ccb020,0x563bc3b630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a06cacf43e1bfbd5747a603fe019bdbe9aac8c64' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8176 processed earlier; will process 2853 files now Step #5: ==226474== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563bb85d69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563bbec3b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563bbec1e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563bbec1e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563bb85dcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563bb853db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563bb8538355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563bb85cec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563bbb59df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563bbb59df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563bbb59df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563bbb59df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563bbb59df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563bbb59df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563bbb59df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563bbb59df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563bbb59df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563bbb59df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563bbd832f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563bba55fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563bba56abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563bba316c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563bba316c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563bba317738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563bba316874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563bba316874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563bba316874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563bbec20abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563bbec29928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563bbec11699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563bbec3c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f530dfb2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563bb8536b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6ead4f2524349fcd4ca4797e1106eba9142231f4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6289 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 825338038 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c78a06c810, 0x55c78a25601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c78a256020,0x55c78c0ee0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6ead4f2524349fcd4ca4797e1106eba9142231f4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8177 processed earlier; will process 2852 files now Step #5: ==226510== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c780b619c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c7871c6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7871a95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7871a94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c780b67d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c780ac8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c780ac3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c780b59c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c783b28f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c783b28f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c783b28f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c783b28f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c783b28f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c783b28f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c783b28f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c783b28f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c783b28f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c783b28f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c785dbdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c782aeab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c782af5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c7828a1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c7828a1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c7828a2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c7828a1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c7828a1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c7828a1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c7871ababd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c7871b4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c78719c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c7871c7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f53bebb4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c780ac1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2ae08f7c1f455eaa2fa868ca23ecf1e77105db9e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6290 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 826032143 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a404199810, 0x55a40438301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a404383020,0x55a40621b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2ae08f7c1f455eaa2fa868ca23ecf1e77105db9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8178 processed earlier; will process 2851 files now Step #5: ==226546== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a3fac8e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a4012f3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a4012d65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a4012d64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3fac94d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a3fabf5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a3fabf0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3fac86c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a3fdc55f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a3fdc55f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a3fdc55f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a3fdc55f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a3fdc55f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a3fdc55f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a3fdc55f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a3fdc55f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a3fdc55f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a3fdc55f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3ffeeaf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3fcc17b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3fcc22be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3fc9cec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3fc9cec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3fc9cf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3fc9ce874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3fc9ce874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3fc9ce874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a4012d8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a4012e1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a4012c9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a4012f4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc0e8174082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a3fabeeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d615038eaf8cb875b2d21c05253a9f1084fa38a3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6291 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 827473365 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f88564d810, 0x55f88583701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f885837020,0x55f8876cf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d615038eaf8cb875b2d21c05253a9f1084fa38a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8179 processed earlier; will process 2850 files now Step #5: #1 pulse cov: 3689 ft: 3690 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 4307 ft: 4955 exec/s: 0 rss: 182Mb Step #5: ==226582== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f87c1429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f8827a7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f88278a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f88278a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f87c148d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f87c0a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f87c0a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f87c13ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f87f109f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f87f109f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f87f109f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f87f109f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f87f109f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f87f109f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f87f109f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f87f109f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f87f109f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f87f109f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f88139ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f87e0cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f87e0d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f87de82c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f87de82c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f87de83738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f87de82874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f87de82874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f87de82874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f88278cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f882795928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f88277d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f8827a8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fca77dd1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f87c0a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4abab96c9b046b3c4c71392b074f61103eebec9b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6292 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 828114812 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cf74345810, 0x55cf7452f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cf7452f020,0x55cf763c70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4abab96c9b046b3c4c71392b074f61103eebec9b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8182 processed earlier; will process 2847 files now Step #5: ==226618== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cf6ae3a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cf7149f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cf714825dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cf714824fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cf6ae40d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cf6ada1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cf6ad9c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cf6ae32c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cf6de01f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cf6de01f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cf6de01f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cf6de01f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cf6de01f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cf6de01f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cf6de01f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cf6de01f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cf6de01f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cf6de01f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cf70096f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cf6cdc3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cf6cdcebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cf6cb7ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cf6cb7ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cf6cb7b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cf6cb7a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cf6cb7a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cf6cb7a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cf71484abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cf7148d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cf71475699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cf714a0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4d177d1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cf6ad9ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-41902c724a98f5bb08233263534e0e0944fba39c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6293 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 828699245 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56353290c810, 0x563532af601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563532af6020,0x56353498e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/41902c724a98f5bb08233263534e0e0944fba39c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8183 processed earlier; will process 2846 files now Step #5: #1 pulse cov: 4043 ft: 4044 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4531 ft: 5091 exec/s: 0 rss: 179Mb Step #5: ==226654== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5635294019c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56352fa66898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56352fa495dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56352fa494fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563529407d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563529368b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563529363355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5635293f9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56352c3c8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56352c3c8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56352c3c8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56352c3c8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56352c3c8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56352c3c8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56352c3c8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56352c3c8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56352c3c8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56352c3c8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56352e65df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56352b38ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56352b395be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56352b141c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56352b141c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56352b142738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56352b141874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56352b141874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56352b141874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56352fa4babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56352fa54928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56352fa3c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56352fa67112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12f7251082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563529361b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-df50d2c3222a2d2dd0b64eae301c15a7ff7806f2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6294 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 829385451 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d9adc90810, 0x55d9ade7a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d9ade7a020,0x55d9afd120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/df50d2c3222a2d2dd0b64eae301c15a7ff7806f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8187 processed earlier; will process 2842 files now Step #5: #1 pulse cov: 3948 ft: 3949 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4792 ft: 5316 exec/s: 0 rss: 179Mb Step #5: ==226690== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d9a47859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d9aadea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d9aadcd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d9aadcd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d9a478bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d9a46ecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d9a46e7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d9a477dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d9a774cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d9a774cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d9a774cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d9a774cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d9a774cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d9a774cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d9a774cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d9a774cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d9a774cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d9a774cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d9a99e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d9a670eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d9a6719be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d9a64c5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d9a64c5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d9a64c6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d9a64c5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d9a64c5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d9a64c5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d9aadcfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d9aadd8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d9aadc0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d9aadeb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f312f87e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d9a46e5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7e318bdffcc2fe97bcb98b6f626e82be43dd855 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6295 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 830229231 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55880dd74810, 0x55880df5e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55880df5e020,0x55880fdf60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7e318bdffcc2fe97bcb98b6f626e82be43dd855' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8190 processed earlier; will process 2839 files now Step #5: ==226726== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5588048699c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55880aece898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55880aeb15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55880aeb14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55880486fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5588047d0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5588047cb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558804861c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558807830f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558807830f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558807830f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558807830f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558807830f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558807830f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558807830f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558807830f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558807830f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558807830f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558809ac5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5588067f2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5588067fdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5588065a9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5588065a9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5588065aa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5588065a9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5588065a9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5588065a9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55880aeb3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55880aebc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55880aea4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55880aecf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f51603ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5588047c9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6d65fb07376aa990d5c13d3fb6dc22591dbca0eb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6296 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 830955853 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5589f70f6810, 0x5589f72e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5589f72e0020,0x5589f91780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6d65fb07376aa990d5c13d3fb6dc22591dbca0eb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8191 processed earlier; will process 2838 files now Step #5: #1 pulse cov: 3973 ft: 3974 exec/s: 0 rss: 180Mb Step #5: ==226762== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5589edbeb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5589f4250898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589f42335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589f42334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5589edbf1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5589edb52b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5589edb4d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5589edbe3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5589f0bb2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5589f0bb2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5589f0bb2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5589f0bb2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5589f0bb2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5589f0bb2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5589f0bb2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5589f0bb2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5589f0bb2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5589f0bb2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589f2e47f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5589efb74b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5589efb7fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5589ef92bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5589ef92bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5589ef92c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5589ef92b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5589ef92b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5589ef92b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5589f4235abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5589f423e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5589f4226699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5589f4251112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6072bd7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5589edb4bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-411fd738646fa37e4b5c5f0cd16de7840886f1c2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6297 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 831612213 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5631ad80a810, 0x5631ad9f401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5631ad9f4020,0x5631af88c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/411fd738646fa37e4b5c5f0cd16de7840886f1c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8193 processed earlier; will process 2836 files now Step #5: ==226798== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5631a42ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5631aa964898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5631aa9475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5631aa9474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5631a4305d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5631a4266b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5631a4261355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5631a42f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5631a72c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5631a72c6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5631a72c6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5631a72c6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5631a72c6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5631a72c6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5631a72c6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5631a72c6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5631a72c6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5631a72c6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5631a955bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5631a6288b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5631a6293be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5631a603fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5631a603fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5631a6040738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5631a603f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5631a603f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5631a603f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5631aa949abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5631aa952928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5631aa93a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5631aa965112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe64e229082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5631a425fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-928e84fae3598c9f3074997c86be6b85fdff9b84 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6298 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 833167338 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5558022f0810, 0x5558024da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5558024da020,0x5558043720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/928e84fae3598c9f3074997c86be6b85fdff9b84' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8194 processed earlier; will process 2835 files now Step #5: ==226834== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5557f8de59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5557ff44a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557ff42d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557ff42d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557f8debd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5557f8d4cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5557f8d47355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557f8dddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5557fbdacf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5557fbdacf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5557fbdacf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5557fbdacf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5557fbdacf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5557fbdacf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5557fbdacf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5557fbdacf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5557fbdacf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5557fbdacf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5557fe041f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5557fad6eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5557fad79be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5557fab25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5557fab25c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5557fab26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5557fab25874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5557fab25874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5557fab25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557ff42fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557ff438928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557ff420699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5557ff44b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c2e9fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5557f8d45b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb61b1db91d1392715a47a435ac081104987e7a1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6299 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 833760713 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b51171810, 0x561b5135b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b5135b020,0x561b531f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb61b1db91d1392715a47a435ac081104987e7a1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8195 processed earlier; will process 2834 files now Step #5: #1 pulse cov: 4247 ft: 4248 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4650 ft: 5370 exec/s: 0 rss: 180Mb Step #5: ==226870== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561b47c669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b4e2cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b4e2ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b4e2ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b47c6cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b47bcdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b47bc8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b47c5ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b4ac2df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b4ac2df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b4ac2df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b4ac2df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b4ac2df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b4ac2df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b4ac2df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b4ac2df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b4ac2df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b4ac2df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b4cec2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b49befb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b49bfabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b499a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b499a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b499a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b499a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b499a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b499a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b4e2b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b4e2b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b4e2a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b4e2cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcff2860082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b47bc6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-66dd08b4dc0463b4b822c018817b15c18c7efa44 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6300 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 834537416 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eaed9c8810, 0x55eaedbb201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eaedbb2020,0x55eaefa4a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/66dd08b4dc0463b4b822c018817b15c18c7efa44' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8199 processed earlier; will process 2830 files now Step #5: ==226906== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eae44bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eaeab22898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eaeab055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eaeab054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eae44c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eae4424b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eae441f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eae44b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eae7484f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eae7484f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eae7484f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eae7484f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eae7484f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eae7484f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eae7484f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eae7484f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eae7484f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eae7484f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eae9719f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eae6446b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eae6451be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eae61fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eae61fdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eae61fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eae61fd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eae61fd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eae61fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eaeab07abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eaeab10928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eaeaaf8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eaeab23112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f611b9bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eae441db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-32003296ba049c5630954709dcaaf1f31cd624c9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6301 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 835113349 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564802bbc810, 0x564802da601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564802da6020,0x564804c3e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/32003296ba049c5630954709dcaaf1f31cd624c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8200 processed earlier; will process 2829 files now Step #5: #1 pulse cov: 4045 ft: 4046 exec/s: 0 rss: 180Mb Step #5: ==226942== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647f96b19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5647ffd16898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5647ffcf95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5647ffcf94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647f96b7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5647f9618b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5647f9613355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647f96a9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5647fc678f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5647fc678f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5647fc678f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5647fc678f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5647fc678f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5647fc678f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5647fc678f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5647fc678f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5647fc678f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5647fc678f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5647fe90df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5647fb63ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5647fb645be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5647fb3f1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5647fb3f1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5647fb3f2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5647fb3f1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5647fb3f1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5647fb3f1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5647ffcfbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5647ffd04928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5647ffcec699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5647ffd17112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5ac27dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5647f9611b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4df6c30abe519355ad7e9e6e8406653b32f3f1c2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6302 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 836756339 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56418f676810, 0x56418f86001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56418f860020,0x5641916f80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4df6c30abe519355ad7e9e6e8406653b32f3f1c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8202 processed earlier; will process 2827 files now Step #5: ==226978== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56418616b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56418c7d0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56418c7b35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56418c7b34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564186171d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5641860d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5641860cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564186163c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564189132f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564189132f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564189132f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564189132f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564189132f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564189132f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564189132f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564189132f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564189132f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564189132f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56418b3c7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5641880f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5641880ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564187eabc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564187eabc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564187eac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564187eab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564187eab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564187eab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56418c7b5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56418c7be928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56418c7a6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56418c7d1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcaa7a3d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5641860cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b940e4df37eac20d2166aac695ab06684a2d7f85 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6303 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 837529691 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dad1a5b810, 0x55dad1c4501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dad1c45020,0x55dad3add0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b940e4df37eac20d2166aac695ab06684a2d7f85' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8203 processed earlier; will process 2826 files now Step #5: ==227014== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dac85509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dacebb5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55daceb985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55daceb984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dac8556d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dac84b7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dac84b2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dac8548c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dacb517f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dacb517f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dacb517f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dacb517f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dacb517f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dacb517f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dacb517f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dacb517f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dacb517f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dacb517f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dacd7acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55daca4d9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55daca4e4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55daca290c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55daca290c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55daca291738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55daca290874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55daca290874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55daca290874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55daceb9aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55daceba3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55daceb8b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dacebb6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6517f9b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dac84b0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-13375bac9e4424c9fd7957ea0638b80ebf781e5a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6304 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 838405099 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e40084d810, 0x55e400a3701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e400a37020,0x55e4028cf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/13375bac9e4424c9fd7957ea0638b80ebf781e5a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8204 processed earlier; will process 2825 files now Step #5: ==227050== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e3f73429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e3fd9a7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e3fd98a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e3fd98a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e3f7348d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e3f72a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e3f72a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e3f733ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e3fa309f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e3fa309f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e3fa309f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e3fa309f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e3fa309f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e3fa309f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e3fa309f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e3fa309f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e3fa309f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e3fa309f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e3fc59ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e3f92cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e3f92d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e3f9082c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e3f9082c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e3f9083738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e3f9082874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e3f9082874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e3f9082874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e3fd98cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e3fd995928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e3fd97d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e3fd9a8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbd3df74082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e3f72a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ceb7a1e56ebde979d53ce66f804d693d197a7d87 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6305 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 839283506 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e4ff96e810, 0x55e4ffb5801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e4ffb58020,0x55e5019f00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ceb7a1e56ebde979d53ce66f804d693d197a7d87' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8205 processed earlier; will process 2824 files now Step #5: ==227086== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e4f64639c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e4fcac8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e4fcaab5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e4fcaab4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e4f6469d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e4f63cab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e4f63c5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e4f645bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e4f942af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e4f942af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e4f942af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e4f942af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e4f942af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e4f942af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e4f942af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e4f942af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e4f942af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e4f942af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e4fb6bff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e4f83ecb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e4f83f7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e4f81a3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e4f81a3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e4f81a4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e4f81a3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e4f81a3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e4f81a3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e4fcaadabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e4fcab6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e4fca9e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e4fcac9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f04d7075082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e4f63c3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-937714bbe07e1206194a318411d2eec50a2c8a4b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6306 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 840167262 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a012107810, 0x55a0122f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0122f1020,0x55a0141890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/937714bbe07e1206194a318411d2eec50a2c8a4b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8206 processed earlier; will process 2823 files now Step #5: ==227122== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a008bfc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a00f261898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a00f2445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a00f2444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a008c02d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a008b63b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a008b5e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a008bf4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a00bbc3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a00bbc3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a00bbc3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a00bbc3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a00bbc3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a00bbc3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a00bbc3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a00bbc3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a00bbc3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a00bbc3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a00de58f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a00ab85b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a00ab90be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a00a93cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a00a93cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a00a93d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a00a93c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a00a93c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a00a93c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a00f246abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a00f24f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a00f237699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a00f262112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1201b19082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a008b5cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-dcd08b4b18273277c817062bbe470029b04c36a9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6307 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 841071655 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5606e9373810, 0x5606e955d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5606e955d020,0x5606eb3f50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dcd08b4b18273277c817062bbe470029b04c36a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8207 processed earlier; will process 2822 files now Step #5: ==227158== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5606dfe689c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5606e64cd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606e64b05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606e64b04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5606dfe6ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5606dfdcfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5606dfdca355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5606dfe60c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5606e2e2ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5606e2e2ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5606e2e2ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5606e2e2ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5606e2e2ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5606e2e2ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5606e2e2ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5606e2e2ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5606e2e2ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5606e2e2ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606e50c4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5606e1df1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5606e1dfcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5606e1ba8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5606e1ba8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5606e1ba9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5606e1ba8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5606e1ba8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5606e1ba8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5606e64b2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5606e64bb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5606e64a3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5606e64ce112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0184fca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5606dfdc8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b50f350ce77de5dbec6dae01a921fffbfbc984fa Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6308 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 841953329 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56004c681810, 0x56004c86b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56004c86b020,0x56004e7030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b50f350ce77de5dbec6dae01a921fffbfbc984fa' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8208 processed earlier; will process 2821 files now Step #5: ==227194== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5600431769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5600497db898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5600497be5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5600497be4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56004317cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5600430ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5600430d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56004316ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56004613df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56004613df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56004613df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56004613df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56004613df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56004613df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56004613df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56004613df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56004613df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56004613df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5600483d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5600450ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56004510abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560044eb6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560044eb6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560044eb7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560044eb6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560044eb6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560044eb6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5600497c0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5600497c9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5600497b1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5600497dc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8c344e7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5600430d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7bcae6cf5f70a3dc4863a1a31592047c809d20ba Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6309 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 842543127 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a7300bf810, 0x55a7302a901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a7302a9020,0x55a7321410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7bcae6cf5f70a3dc4863a1a31592047c809d20ba' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8209 processed earlier; will process 2820 files now Step #5: ==227230== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a726bb49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a72d219898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a72d1fc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a72d1fc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a726bbad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a726b1bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a726b16355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a726bacc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a729b7bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a729b7bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a729b7bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a729b7bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a729b7bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a729b7bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a729b7bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a729b7bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a729b7bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a729b7bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a72be10f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a728b3db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a728b48be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a7288f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a7288f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a7288f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a7288f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a7288f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a7288f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a72d1feabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a72d207928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a72d1ef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a72d21a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f34196e2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a726b14b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3fd2102de591a55e6f2c55ba7005f5b135eaba12 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6310 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 843147673 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fb8782c810, 0x55fb87a1601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fb87a16020,0x55fb898ae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3fd2102de591a55e6f2c55ba7005f5b135eaba12' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8210 processed earlier; will process 2819 files now Step #5: ==227266== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fb7e3219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fb84986898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fb849695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fb849694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fb7e327d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fb7e288b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fb7e283355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fb7e319c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fb812e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fb812e8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fb812e8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fb812e8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fb812e8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fb812e8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fb812e8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fb812e8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fb812e8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fb812e8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fb8357df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fb802aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fb802b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fb80061c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fb80061c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fb80062738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fb80061874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fb80061874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fb80061874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fb8496babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fb84974928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fb8495c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fb84987112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdc92cbc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fb7e281b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-35cf9f0fa525e6aa9b9da1e3f6847c9253dca171 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6311 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 843718083 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56270a24e810, 0x56270a43801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56270a438020,0x56270c2d00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/35cf9f0fa525e6aa9b9da1e3f6847c9253dca171' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8211 processed earlier; will process 2818 files now Step #5: ==227302== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562700d439c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5627073a8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56270738b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56270738b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562700d49d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562700caab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562700ca5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562700d3bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562703d0af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562703d0af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562703d0af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562703d0af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562703d0af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562703d0af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562703d0af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562703d0af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562703d0af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562703d0af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562705f9ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562702cccb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562702cd7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562702a83c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562702a83c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562702a84738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562702a83874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562702a83874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562702a83874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56270738dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562707396928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56270737e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5627073a9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff9992bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562700ca3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e718e3154c0188e401a20e03ee54c52635a55766 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6312 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 844307063 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557257bb5810, 0x557257d9f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557257d9f020,0x557259c370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e718e3154c0188e401a20e03ee54c52635a55766' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8212 processed earlier; will process 2817 files now Step #5: ==227338== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55724e6aa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557254d0f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557254cf25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557254cf24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55724e6b0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55724e611b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55724e60c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55724e6a2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557251671f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557251671f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557251671f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557251671f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557251671f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557251671f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557251671f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557251671f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557251671f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557251671f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557253906f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557250633b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55725063ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5572503eac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5572503eac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5572503eb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5572503ea874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5572503ea874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5572503ea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557254cf4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557254cfd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557254ce5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557254d10112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68e5cd5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55724e60ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-098934f9a07fedfeaa513d977dca9146576f419e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6313 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 844889938 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559eed6c1810, 0x559eed8ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559eed8ab020,0x559eef7430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/098934f9a07fedfeaa513d977dca9146576f419e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8213 processed earlier; will process 2816 files now Step #5: #1 pulse cov: 4501 ft: 4502 exec/s: 0 rss: 183Mb Step #5: #2 pulse cov: 5198 ft: 5869 exec/s: 0 rss: 184Mb Step #5: ==227374== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559ee41b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559eea81b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559eea7fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559eea7fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ee41bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ee411db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ee4118355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ee41aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ee717df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ee717df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ee717df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ee717df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ee717df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ee717df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ee717df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ee717df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ee717df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ee717df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ee9412f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559ee613fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559ee614abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559ee5ef6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559ee5ef6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559ee5ef7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559ee5ef6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559ee5ef6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559ee5ef6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559eea800abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559eea809928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559eea7f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559eea81c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efdd4428082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ee4116b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c9d973647622df88383b3d01a86ad580cd22ba0d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6314 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 845797453 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ef9a253810, 0x55ef9a43d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ef9a43d020,0x55ef9c2d50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9d973647622df88383b3d01a86ad580cd22ba0d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8216 processed earlier; will process 2813 files now Step #5: ==227410== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ef90d489c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ef973ad898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ef973905dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ef973904fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ef90d4ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ef90cafb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ef90caa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ef90d40c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ef93d0ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ef93d0ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ef93d0ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ef93d0ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ef93d0ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ef93d0ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ef93d0ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ef93d0ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ef93d0ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ef93d0ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ef95fa4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ef92cd1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ef92cdcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ef92a88c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ef92a88c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ef92a89738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ef92a88874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ef92a88874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ef92a88874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ef97392abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ef9739b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ef97383699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ef973ae112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9ca0ec8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ef90ca8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-529562526cb3caedee40905c007f606fad98cceb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6315 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 846385449 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56326109d810, 0x56326128701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563261287020,0x56326311f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/529562526cb3caedee40905c007f606fad98cceb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8217 processed earlier; will process 2812 files now Step #5: ==227446== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563257b929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56325e1f7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56325e1da5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56325e1da4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563257b98d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563257af9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563257af4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563257b8ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56325ab59f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56325ab59f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56325ab59f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56325ab59f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56325ab59f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56325ab59f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56325ab59f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56325ab59f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56325ab59f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56325ab59f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56325cdeef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563259b1bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563259b26be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5632598d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5632598d2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5632598d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5632598d2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5632598d2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5632598d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56325e1dcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56325e1e5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56325e1cd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56325e1f8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe118544082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563257af2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-77867445ed96c5e965f5c7fedcd6abd760aa4f71 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6316 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 846977841 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cd1d475810, 0x55cd1d65f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cd1d65f020,0x55cd1f4f70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/77867445ed96c5e965f5c7fedcd6abd760aa4f71' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8218 processed earlier; will process 2811 files now Step #5: ==227482== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cd13f6a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cd1a5cf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cd1a5b25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cd1a5b24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cd13f70d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cd13ed1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cd13ecc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cd13f62c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cd16f31f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cd16f31f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cd16f31f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cd16f31f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cd16f31f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cd16f31f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cd16f31f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cd16f31f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cd16f31f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cd16f31f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cd191c6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cd15ef3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cd15efebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cd15caac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cd15caac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cd15cab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cd15caa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cd15caa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cd15caa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cd1a5b4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cd1a5bd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cd1a5a5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cd1a5d0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc848406082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cd13ecab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c27c4908d82b8851af7320869a15be7c29b118d8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6317 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 847565335 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560225038810, 0x56022522201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560225222020,0x5602270ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c27c4908d82b8851af7320869a15be7c29b118d8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8219 processed earlier; will process 2810 files now Step #5: ==227518== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56021bb2d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560222192898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602221755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602221754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56021bb33d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56021ba94b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56021ba8f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56021bb25c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56021eaf4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56021eaf4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56021eaf4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56021eaf4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56021eaf4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56021eaf4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56021eaf4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56021eaf4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56021eaf4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56021eaf4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560220d89f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56021dab6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56021dac1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56021d86dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56021d86dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56021d86e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56021d86d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56021d86d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56021d86d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560222177abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560222180928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560222168699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560222193112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f17f0108082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56021ba8db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e7df099b712e0f5071015166242653f54b89dfa1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6318 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 848146955 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557f64537810, 0x557f6472101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557f64721020,0x557f665b90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e7df099b712e0f5071015166242653f54b89dfa1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8220 processed earlier; will process 2809 files now Step #5: ==227554== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557f5b02c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f61691898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f616745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f616744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f5b032d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f5af93b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f5af8e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f5b024c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f5dff3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f5dff3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f5dff3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f5dff3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f5dff3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f5dff3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f5dff3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f5dff3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f5dff3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f5dff3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f60288f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f5cfb5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f5cfc0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f5cd6cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f5cd6cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f5cd6d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f5cd6c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f5cd6c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f5cd6c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f61676abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f6167f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f61667699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f61692112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd2a5566082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f5af8cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-631e47c5ef3976871993c92c3a11a40e637c3bb1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6319 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 848706766 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b34fb52810, 0x55b34fd3c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b34fd3c020,0x55b351bd40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/631e47c5ef3976871993c92c3a11a40e637c3bb1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8221 processed earlier; will process 2808 files now Step #5: ==227590== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b3466479c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b34ccac898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b34cc8f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b34cc8f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b34664dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b3465aeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b3465a9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b34663fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b34960ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b34960ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b34960ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b34960ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b34960ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b34960ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b34960ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b34960ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b34960ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b34960ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b34b8a3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b3485d0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b3485dbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b348387c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b348387c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b348388738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b348387874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b348387874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b348387874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b34cc91abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b34cc9a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b34cc82699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b34ccad112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa9c4d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b3465a7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c8445a74ebaad5d1bf02e8f6a2317ef68e3c60ff Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6320 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 849480717 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5595e78b3810, 0x5595e7a9d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5595e7a9d020,0x5595e99350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c8445a74ebaad5d1bf02e8f6a2317ef68e3c60ff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8222 processed earlier; will process 2807 files now Step #5: ==227626== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5595de3a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5595e4a0d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5595e49f05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5595e49f04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5595de3aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5595de30fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5595de30a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5595de3a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5595e136ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5595e136ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5595e136ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5595e136ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5595e136ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5595e136ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5595e136ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5595e136ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5595e136ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5595e136ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5595e3604f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5595e0331b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5595e033cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5595e00e8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5595e00e8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5595e00e9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5595e00e8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5595e00e8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5595e00e8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5595e49f2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5595e49fb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5595e49e3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5595e4a0e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb473af8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5595de308b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-86ba5a5cd1f2a3c5999a1dd95078950b91fda9f9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6321 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 850085536 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55904ebbf810, 0x55904eda901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55904eda9020,0x559050c410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/86ba5a5cd1f2a3c5999a1dd95078950b91fda9f9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8223 processed earlier; will process 2806 files now Step #5: ==227662== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5590456b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55904bd19898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55904bcfc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55904bcfc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5590456bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55904561bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559045616355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5590456acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55904867bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55904867bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55904867bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55904867bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55904867bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55904867bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55904867bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55904867bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55904867bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55904867bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55904a910f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55904763db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559047648be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5590473f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5590473f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5590473f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5590473f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5590473f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5590473f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55904bcfeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55904bd07928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55904bcef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55904bd1a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc8cec04082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559045614b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-86005646c32620f48e096442bbd89e69a015a96f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6322 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 850810358 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558e00e42810, 0x558e0102c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558e0102c020,0x558e02ec40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/86005646c32620f48e096442bbd89e69a015a96f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8224 processed earlier; will process 2805 files now Step #5: ==227698== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558df79379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558dfdf9c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558dfdf7f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558dfdf7f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558df793dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558df789eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558df7899355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558df792fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558dfa8fef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558dfa8fef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558dfa8fef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558dfa8fef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558dfa8fef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558dfa8fef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558dfa8fef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558dfa8fef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558dfa8fef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558dfa8fef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558dfcb93f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558df98c0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558df98cbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558df9677c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558df9677c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558df9678738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558df9677874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558df9677874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558df9677874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558dfdf81abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558dfdf8a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558dfdf72699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558dfdf9d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f377fe98082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558df7897b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-16849112c348d30f8fb3a51f2a94ac9a362f295e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6323 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 852190909 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e0088fb810, 0x55e008ae501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e008ae5020,0x55e00a97d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/16849112c348d30f8fb3a51f2a94ac9a362f295e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8225 processed earlier; will process 2804 files now Step #5: ==227734== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dfff3f09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e005a55898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e005a385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e005a384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dfff3f6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dfff357b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dfff352355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dfff3e8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e0023b7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e0023b7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e0023b7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e0023b7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e0023b7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e0023b7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e0023b7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e0023b7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e0023b7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e0023b7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e00464cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e001379b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e001384be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e001130c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e001130c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e001131738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e001130874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e001130874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e001130874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e005a3aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e005a43928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e005a2b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e005a56112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f75f3068082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dfff350b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-89b8926f0677c72530728241d981ec4c89f4d4dc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6324 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 852807388 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55de1a0e9810, 0x55de1a2d301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55de1a2d3020,0x55de1c16b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/89b8926f0677c72530728241d981ec4c89f4d4dc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8226 processed earlier; will process 2803 files now Step #5: ==227770== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55de10bde9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55de17243898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55de172265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55de172264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55de10be4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55de10b45b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55de10b40355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55de10bd6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55de13ba5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55de13ba5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55de13ba5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55de13ba5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55de13ba5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55de13ba5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55de13ba5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55de13ba5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55de13ba5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55de13ba5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55de15e3af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55de12b67b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55de12b72be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55de1291ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55de1291ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55de1291f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55de1291e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55de1291e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55de1291e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55de17228abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55de17231928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55de17219699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55de17244112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe7689cb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55de10b3eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-87ac620dbdb606c4b4bbe494ba302b851ca54f55 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6325 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 853391724 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5589f7e30810, 0x5589f801a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5589f801a020,0x5589f9eb20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/87ac620dbdb606c4b4bbe494ba302b851ca54f55' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8227 processed earlier; will process 2802 files now Step #5: #1 pulse cov: 4136 ft: 4137 exec/s: 0 rss: 181Mb Step #5: ==227806== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5589ee9259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5589f4f8a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5589f4f6d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5589f4f6d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5589ee92bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5589ee88cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5589ee887355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5589ee91dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5589f18ecf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5589f18ecf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5589f18ecf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5589f18ecf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5589f18ecf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5589f18ecf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5589f18ecf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5589f18ecf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5589f18ecf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5589f18ecf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589f3b81f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5589f08aeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5589f08b9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5589f0665c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5589f0665c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5589f0666738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5589f0665874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5589f0665874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5589f0665874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5589f4f6fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5589f4f78928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5589f4f60699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5589f4f8b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa262402082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5589ee885b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a829b54b904c2ba1de446dd940e1125bf595f9a9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6326 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 853990584 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aaf61c4810, 0x55aaf63ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aaf63ae020,0x55aaf82460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a829b54b904c2ba1de446dd940e1125bf595f9a9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8229 processed earlier; will process 2800 files now Step #5: ==227842== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aaeccb99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aaf331e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aaf33015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aaf33014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aaeccbfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aaecc20b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aaecc1b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aaeccb1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aaefc80f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aaefc80f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aaefc80f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aaefc80f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aaefc80f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aaefc80f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aaefc80f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aaefc80f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aaefc80f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aaefc80f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aaf1f15f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aaeec42b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aaeec4dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aaee9f9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aaee9f9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aaee9fa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aaee9f9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aaee9f9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aaee9f9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aaf3303abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aaf330c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aaf32f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aaf331f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f87414eb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aaecc19b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-28478263da7a719143bb95a36abd248d8a08f759 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6327 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 854582657 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f76d80a810, 0x55f76d9f401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f76d9f4020,0x55f76f88c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/28478263da7a719143bb95a36abd248d8a08f759' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8230 processed earlier; will process 2799 files now Step #5: ==227878== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f7642ff9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f76a964898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f76a9475dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f76a9474fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f764305d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f764266b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f764261355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f7642f7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f7672c6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f7672c6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f7672c6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f7672c6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f7672c6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f7672c6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f7672c6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f7672c6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f7672c6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f7672c6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f76955bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f766288b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f766293be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f76603fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f76603fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f766040738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f76603f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f76603f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f76603f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f76a949abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f76a952928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f76a93a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f76a965112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fea1e619082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f76425fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-764597e361ea11e8dcecfbb47bffea98768b6498 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6328 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 855162181 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5607a00d3810, 0x5607a02bd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5607a02bd020,0x5607a21550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/764597e361ea11e8dcecfbb47bffea98768b6498' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8231 processed earlier; will process 2798 files now Step #5: ==227914== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560796bc89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56079d22d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56079d2105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56079d2104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560796bced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560796b2fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560796b2a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560796bc0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560799b8ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560799b8ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560799b8ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560799b8ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560799b8ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560799b8ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560799b8ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560799b8ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560799b8ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560799b8ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56079be24f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560798b51b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560798b5cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560798908c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560798908c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560798909738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560798908874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560798908874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560798908874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56079d212abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56079d21b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56079d203699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56079d22e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe45c67b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560796b28b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f86d2d50b2610a90fd919d6409656bcbf3f6f99c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6329 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 857057005 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555b103f6810, 0x555b105e001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555b105e0020,0x555b124780e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f86d2d50b2610a90fd919d6409656bcbf3f6f99c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8232 processed earlier; will process 2797 files now Step #5: #1 pulse cov: 3872 ft: 3873 exec/s: 0 rss: 177Mb Step #5: ==227950== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555b06eeb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555b0d550898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555b0d5335dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555b0d5334fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555b06ef1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555b06e52b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555b06e4d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555b06ee3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555b09eb2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555b09eb2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555b09eb2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555b09eb2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555b09eb2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555b09eb2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555b09eb2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555b09eb2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555b09eb2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555b09eb2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555b0c147f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555b08e74b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555b08e7fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555b08c2bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555b08c2bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555b08c2c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555b08c2b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555b08c2b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555b08c2b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555b0d535abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555b0d53e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555b0d526699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555b0d551112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe7c90a1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555b06e4bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ac79633673a33b6815781a7185812b1a497a464b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6330 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 857706409 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562dd0b4f810, 0x562dd0d3901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562dd0d39020,0x562dd2bd10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ac79633673a33b6815781a7185812b1a497a464b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8234 processed earlier; will process 2795 files now Step #5: ==227986== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562dc76449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562dcdca9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562dcdc8c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562dcdc8c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562dc764ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562dc75abb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562dc75a6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562dc763cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562dca60bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562dca60bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562dca60bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562dca60bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562dca60bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562dca60bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562dca60bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562dca60bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562dca60bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562dca60bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562dcc8a0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562dc95cdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562dc95d8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562dc9384c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562dc9384c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562dc9385738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562dc9384874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562dc9384874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562dc9384874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562dcdc8eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562dcdc97928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562dcdc7f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562dcdcaa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2d9cfe3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562dc75a4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-41c8330314e936d94067fa8749bcefd5f1a5ffac Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6331 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 858895233 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559f80958810, 0x559f80b4201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559f80b42020,0x559f829da0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/41c8330314e936d94067fa8749bcefd5f1a5ffac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8235 processed earlier; will process 2794 files now Step #5: ==228022== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559f7744d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559f7dab2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559f7da955dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559f7da954fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559f77453d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559f773b4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559f773af355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559f77445c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559f7a414f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559f7a414f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559f7a414f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559f7a414f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559f7a414f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559f7a414f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559f7a414f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559f7a414f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559f7a414f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559f7a414f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559f7c6a9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559f793d6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559f793e1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559f7918dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559f7918dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559f7918e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559f7918d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559f7918d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559f7918d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559f7da97abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559f7daa0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559f7da88699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559f7dab3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f664f69b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559f773adb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-46cfe73f24d69c5e59d28cdccf10667ca2d27a50 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6332 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 860455492 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610d46c8810, 0x5610d48b201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610d48b2020,0x5610d674a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/46cfe73f24d69c5e59d28cdccf10667ca2d27a50' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8236 processed earlier; will process 2793 files now Step #5: ==228058== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5610cb1bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610d1822898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610d18055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610d18054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610cb1c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610cb124b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610cb11f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610cb1b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610ce184f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610ce184f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610ce184f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610ce184f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610ce184f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610ce184f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610ce184f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610ce184f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610ce184f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610ce184f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610d0419f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610cd146b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610cd151be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610ccefdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610ccefdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610ccefe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610ccefd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610ccefd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610ccefd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610d1807abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610d1810928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610d17f8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610d1823112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f193621e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610cb11db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a063105926d2ed8d892821ef8de8f7c1bbdd415d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6333 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 861763763 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560c3049f810, 0x560c3068901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560c30689020,0x560c325210e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a063105926d2ed8d892821ef8de8f7c1bbdd415d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8237 processed earlier; will process 2792 files now Step #5: ==228094== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560c26f949c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560c2d5f9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560c2d5dc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560c2d5dc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560c26f9ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560c26efbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560c26ef6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560c26f8cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560c29f5bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560c29f5bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560c29f5bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560c29f5bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560c29f5bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560c29f5bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560c29f5bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560c29f5bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560c29f5bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560c29f5bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560c2c1f0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560c28f1db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560c28f28be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560c28cd4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560c28cd4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560c28cd5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560c28cd4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560c28cd4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560c28cd4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560c2d5deabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560c2d5e7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560c2d5cf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560c2d5fa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7e06242082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560c26ef4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ff8acf60d1e254645c17feb13314edbc11b2438 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6334 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 862376593 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555c17fb6810, 0x555c181a001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555c181a0020,0x555c1a0380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ff8acf60d1e254645c17feb13314edbc11b2438' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8238 processed earlier; will process 2791 files now Step #5: #1 pulse cov: 3721 ft: 3722 exec/s: 0 rss: 177Mb Step #5: #2 pulse cov: 4597 ft: 4893 exec/s: 0 rss: 180Mb Step #5: ==228130== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555c0eaab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555c15110898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555c150f35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555c150f34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555c0eab1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555c0ea12b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555c0ea0d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555c0eaa3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555c11a72f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555c11a72f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555c11a72f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555c11a72f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555c11a72f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555c11a72f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555c11a72f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555c11a72f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555c11a72f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555c11a72f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555c13d07f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555c10a34b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555c10a3fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555c107ebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555c107ebc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555c107ec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555c107eb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555c107eb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555c107eb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555c150f5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555c150fe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555c150e6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555c15111112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3244936082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555c0ea0bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-41d820adb63b06f0d2e1ff42539098ffa7cc51cb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6335 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 863053292 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a68b5e5810, 0x55a68b7cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a68b7cf020,0x55a68d6670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/41d820adb63b06f0d2e1ff42539098ffa7cc51cb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8241 processed earlier; will process 2788 files now Step #5: ==228166== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a6820da9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a68873f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a6887225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a6887224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a6820e0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a682041b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a68203c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a6820d2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a6850a1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a6850a1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a6850a1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a6850a1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a6850a1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a6850a1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a6850a1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a6850a1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a6850a1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a6850a1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a687336f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a684063b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a68406ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a683e1ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a683e1ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a683e1b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a683e1a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a683e1a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a683e1a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a688724abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a68872d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a688715699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a688740112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fee174e7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a68203ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ee7da4074fb29008dfcf3eb759fabe4354dfead1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6336 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 863673431 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f00d78f810, 0x55f00d97901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f00d979020,0x55f00f8110e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee7da4074fb29008dfcf3eb759fabe4354dfead1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8242 processed earlier; will process 2787 files now Step #5: ==228202== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f0042849c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f00a8e9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f00a8cc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f00a8cc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f00428ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f0041ebb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f0041e6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f00427cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f00724bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f00724bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f00724bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f00724bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f00724bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f00724bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f00724bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f00724bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f00724bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f00724bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f0094e0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f00620db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f006218be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f005fc4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f005fc4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f005fc5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f005fc4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f005fc4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f005fc4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f00a8ceabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f00a8d7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f00a8bf699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f00a8ea112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f77266b9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f0041e4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f71547af2217b318e32d9f11d6f37024e1a8c9e4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6337 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 864258089 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56106c38d810, 0x56106c57701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56106c577020,0x56106e40f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f71547af2217b318e32d9f11d6f37024e1a8c9e4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8243 processed earlier; will process 2786 files now Step #5: #1 pulse cov: 4163 ft: 4164 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4201 ft: 4694 exec/s: 0 rss: 181Mb Step #5: ==228238== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561062e829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610694e7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610694ca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610694ca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561062e88d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561062de9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561062de4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561062e7ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561065e49f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561065e49f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561065e49f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561065e49f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561065e49f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561065e49f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561065e49f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561065e49f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561065e49f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561065e49f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610680def7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561064e0bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561064e16be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561064bc2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561064bc2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561064bc3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561064bc2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561064bc2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561064bc2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610694ccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610694d5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610694bd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610694e8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f414d5cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561062de2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3a01932a9f628f530dd7e439997c407ca380e6c9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6338 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 864950443 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5624011f0810, 0x5624013da01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5624013da020,0x5624032720e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3a01932a9f628f530dd7e439997c407ca380e6c9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8246 processed earlier; will process 2783 files now Step #5: ==228274== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5623f7ce59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5623fe34a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5623fe32d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5623fe32d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5623f7cebd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5623f7c4cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5623f7c47355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5623f7cddc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5623facacf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5623facacf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5623facacf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5623facacf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5623facacf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5623facacf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5623facacf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5623facacf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5623facacf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5623facacf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5623fcf41f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5623f9c6eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5623f9c79be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5623f9a25c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5623f9a25c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5623f9a26738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5623f9a25874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5623f9a25874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5623f9a25874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5623fe32fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5623fe338928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5623fe320699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5623fe34b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f428c478082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5623f7c45b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e48e83d1c35e6accb0f689c747a9f723bc1163c8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6339 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 865569388 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a439a0b810, 0x55a439bf501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a439bf5020,0x55a43ba8d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e48e83d1c35e6accb0f689c747a9f723bc1163c8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8247 processed earlier; will process 2782 files now Step #5: ==228310== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a4305009c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a436b65898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a436b485dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a436b484fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a430506d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a430467b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a430462355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a4304f8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a4334c7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a4334c7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a4334c7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a4334c7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a4334c7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a4334c7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a4334c7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a4334c7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a4334c7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a4334c7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a43575cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a432489b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a432494be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a432240c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a432240c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a432241738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a432240874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a432240874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a432240874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a436b4aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a436b53928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a436b3b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a436b66112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa09f85e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a430460b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4ea7e8f3ed8a34e7f7511f06ec21555070526706 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6340 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 866146014 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55967a981810, 0x55967ab6b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55967ab6b020,0x55967ca030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4ea7e8f3ed8a34e7f7511f06ec21555070526706' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8248 processed earlier; will process 2781 files now Step #5: #1 pulse cov: 3864 ft: 3865 exec/s: 0 rss: 180Mb Step #5: ==228346== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5596714769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559677adb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559677abe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559677abe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55967147cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5596713ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5596713d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55967146ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55967443df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55967443df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55967443df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55967443df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55967443df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55967443df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55967443df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55967443df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55967443df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55967443df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596766d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5596733ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55967340abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5596731b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5596731b6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5596731b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5596731b6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5596731b6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5596731b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559677ac0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559677ac9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559677ab1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559677adc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5ebc7cb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5596713d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ea80f533498fdffd5e7127711863f218b1dcbd26 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6341 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 866974043 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562468ca8810, 0x562468e9201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562468e92020,0x56246ad2a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ea80f533498fdffd5e7127711863f218b1dcbd26' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8250 processed earlier; will process 2779 files now Step #5: #1 pulse cov: 3986 ft: 3987 exec/s: 0 rss: 178Mb Step #5: ==228382== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56245f79d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562465e02898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562465de55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562465de54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56245f7a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56245f704b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56245f6ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56245f795c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562462764f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562462764f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562462764f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562462764f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562462764f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562462764f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562462764f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562462764f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562462764f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562462764f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5624649f9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562461726b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562461731be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5624614ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5624614ddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5624614de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5624614dd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5624614dd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5624614dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562465de7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562465df0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562465dd8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562465e03112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc4fb91e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56245f6fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-218ec25574fbe692829dfa3fc169706bf981c60e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6342 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 867667866 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fb1d4f5810, 0x55fb1d6df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fb1d6df020,0x55fb1f5770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/218ec25574fbe692829dfa3fc169706bf981c60e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8252 processed earlier; will process 2777 files now Step #5: ==228418== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fb13fea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fb1a64f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fb1a6325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fb1a6324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fb13ff0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fb13f51b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fb13f4c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fb13fe2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fb16fb1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fb16fb1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fb16fb1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fb16fb1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fb16fb1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fb16fb1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fb16fb1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fb16fb1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fb16fb1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fb16fb1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fb19246f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fb15f73b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fb15f7ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fb15d2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fb15d2ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fb15d2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fb15d2a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fb15d2a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fb15d2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fb1a634abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fb1a63d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fb1a625699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fb1a650112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c0f55c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fb13f4ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c2a565e4e1ea659a2f863a345e4a8156608f08a6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6343 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 869036368 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564845b01810, 0x564845ceb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564845ceb020,0x564847b830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c2a565e4e1ea659a2f863a345e4a8156608f08a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8253 processed earlier; will process 2776 files now Step #5: ==228454== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56483c5f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564842c5b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564842c3e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564842c3e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56483c5fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56483c55db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56483c558355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56483c5eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56483f5bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56483f5bdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56483f5bdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56483f5bdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56483f5bdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56483f5bdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56483f5bdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56483f5bdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56483f5bdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56483f5bdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564841852f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56483e57fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56483e58abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56483e336c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56483e336c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56483e337738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56483e336874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56483e336874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56483e336874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564842c40abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564842c49928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564842c31699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564842c5c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7eff0a2d2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56483c556b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f9829d8617f65f25ea902c29c1cdc8cbb80e080f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6344 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 869620662 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56010d4d0810, 0x56010d6ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56010d6ba020,0x56010f5520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9829d8617f65f25ea902c29c1cdc8cbb80e080f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8254 processed earlier; will process 2775 files now Step #5: ==228490== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560103fc59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56010a62a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56010a60d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56010a60d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560103fcbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560103f2cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560103f27355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560103fbdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560106f8cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560106f8cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560106f8cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560106f8cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560106f8cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560106f8cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560106f8cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560106f8cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560106f8cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560106f8cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560109221f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560105f4eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560105f59be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560105d05c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560105d05c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560105d06738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560105d05874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560105d05874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560105d05874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56010a60fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56010a618928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56010a600699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56010a62b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3a35ee082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560103f25b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-194026b580c2de2c4caa021af93b832580cabc8e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6345 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 870220052 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55602dba6810, 0x55602dd9001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55602dd90020,0x55602fc280e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/194026b580c2de2c4caa021af93b832580cabc8e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8255 processed earlier; will process 2774 files now Step #5: ==228526== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55602469b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55602ad00898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55602ace35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55602ace34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5560246a1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556024602b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5560245fd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556024693c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556027662f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556027662f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556027662f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556027662f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556027662f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556027662f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556027662f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556027662f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556027662f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556027662f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5560298f7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556026624b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55602662fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5560263dbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5560263dbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5560263dc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5560263db874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5560263db874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5560263db874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55602ace5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55602acee928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55602acd6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55602ad01112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d4b989082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5560245fbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a9ba0ef49794f8b1bea0e884ed50a9c8947a5a25 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6346 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 870832076 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fa78078810, 0x55fa7826201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fa78262020,0x55fa7a0fa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9ba0ef49794f8b1bea0e884ed50a9c8947a5a25' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8256 processed earlier; will process 2773 files now Step #5: ==228562== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fa6eb6d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fa751d2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fa751b55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fa751b54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fa6eb73d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fa6ead4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fa6eacf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fa6eb65c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fa71b34f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fa71b34f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fa71b34f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fa71b34f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fa71b34f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fa71b34f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fa71b34f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fa71b34f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fa71b34f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fa71b34f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fa73dc9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fa70af6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fa70b01be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fa708adc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fa708adc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fa708ae738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fa708ad874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fa708ad874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fa708ad874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fa751b7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fa751c0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fa751a8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fa751d3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbac4623082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fa6eacdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ac461bd776718770e9776a067039af9c8d61ce6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6347 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 871607179 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558a42ed7810, 0x558a430c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558a430c1020,0x558a44f590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ac461bd776718770e9776a067039af9c8d61ce6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8257 processed earlier; will process 2772 files now Step #5: ==228598== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558a399cc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558a40031898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558a400145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558a400144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558a399d2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558a39933b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558a3992e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558a399c4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558a3c993f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558a3c993f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558a3c993f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558a3c993f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558a3c993f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558a3c993f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558a3c993f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558a3c993f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558a3c993f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558a3c993f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558a3ec28f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558a3b955b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558a3b960be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558a3b70cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558a3b70cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558a3b70d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558a3b70c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558a3b70c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558a3b70c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558a40016abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558a4001f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558a40007699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558a40032112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb3c059b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558a3992cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b55d0800ff7262eff762910abd5dc4789060927b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6348 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 872219860 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557ea07b0810, 0x557ea099a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557ea099a020,0x557ea28320e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b55d0800ff7262eff762910abd5dc4789060927b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8258 processed earlier; will process 2771 files now Step #5: ==228634== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557e972a59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557e9d90a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557e9d8ed5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557e9d8ed4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557e972abd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557e9720cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557e97207355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557e9729dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557e9a26cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557e9a26cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557e9a26cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557e9a26cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557e9a26cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557e9a26cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557e9a26cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557e9a26cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557e9a26cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557e9a26cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557e9c501f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557e9922eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557e99239be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557e98fe5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557e98fe5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557e98fe6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557e98fe5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557e98fe5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557e98fe5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557e9d8efabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557e9d8f8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557e9d8e0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557e9d90b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0b048c7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557e97205b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-43246f4e38d2920822684b5ca5d02f2b007e78b8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6349 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 873405666 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5647a26e8810, 0x5647a28d201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5647a28d2020,0x5647a476a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/43246f4e38d2920822684b5ca5d02f2b007e78b8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8259 processed earlier; will process 2770 files now Step #5: ==228670== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5647991dd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56479f842898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56479f8255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56479f8254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5647991e3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564799144b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56479913f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5647991d5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56479c1a4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56479c1a4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56479c1a4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56479c1a4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56479c1a4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56479c1a4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56479c1a4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56479c1a4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56479c1a4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56479c1a4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56479e439f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56479b166b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56479b171be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56479af1dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56479af1dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56479af1e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56479af1d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56479af1d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56479af1d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56479f827abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56479f830928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56479f818699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56479f843112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe8a6fa1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56479913db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-025502988733da79f0ded2cf024a43c1a2805e6b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6350 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 873996937 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e16fac4810, 0x55e16fcae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e16fcae020,0x55e171b460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/025502988733da79f0ded2cf024a43c1a2805e6b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8260 processed earlier; will process 2769 files now Step #5: ==228706== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e1665b99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e16cc1e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e16cc015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e16cc014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e1665bfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e166520b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e16651b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e1665b1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e169580f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e169580f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e169580f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e169580f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e169580f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e169580f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e169580f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e169580f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e169580f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e169580f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e16b815f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e168542b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e16854dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e1682f9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e1682f9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e1682fa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e1682f9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e1682f9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e1682f9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e16cc03abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e16cc0c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e16cbf4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e16cc1f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f073878f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e166519b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-90976c23d52cb6df0c6bad8460708aaf3a19012d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6351 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 874559482 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5636c6a2f810, 0x5636c6c1901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5636c6c19020,0x5636c8ab10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/90976c23d52cb6df0c6bad8460708aaf3a19012d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8261 processed earlier; will process 2768 files now Step #5: #1 pulse cov: 4425 ft: 4426 exec/s: 0 rss: 179Mb Step #5: ==228742== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5636bd5249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5636c3b89898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5636c3b6c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5636c3b6c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5636bd52ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5636bd48bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5636bd486355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5636bd51cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5636c04ebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5636c04ebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5636c04ebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5636c04ebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5636c04ebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5636c04ebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5636c04ebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5636c04ebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5636c04ebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5636c04ebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5636c2780f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5636bf4adb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5636bf4b8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5636bf264c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5636bf264c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5636bf265738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5636bf264874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5636bf264874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5636bf264874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5636c3b6eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5636c3b77928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5636c3b5f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5636c3b8a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd724249082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5636bd484b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-052f7a8ca43fde8b5d1b88a06d054032c80974fc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6352 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 875163153 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5580d8854810, 0x5580d8a3e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5580d8a3e020,0x5580da8d60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/052f7a8ca43fde8b5d1b88a06d054032c80974fc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8263 processed earlier; will process 2766 files now Step #5: ==228778== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5580cf3499c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5580d59ae898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5580d59915dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5580d59914fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5580cf34fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5580cf2b0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5580cf2ab355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5580cf341c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5580d2310f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5580d2310f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5580d2310f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5580d2310f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5580d2310f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5580d2310f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5580d2310f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5580d2310f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5580d2310f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5580d2310f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5580d45a5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5580d12d2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5580d12ddbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5580d1089c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5580d1089c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5580d108a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5580d1089874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5580d1089874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5580d1089874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5580d5993abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5580d599c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5580d5984699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5580d59af112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc411c26082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5580cf2a9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-824833751f169f6292b9fd1607a70be6b0ac5601 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6353 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 875873494 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563209968810, 0x563209b5201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563209b52020,0x56320b9ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/824833751f169f6292b9fd1607a70be6b0ac5601' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8264 processed earlier; will process 2765 files now Step #5: ==228814== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56320045d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563206ac2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563206aa55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563206aa54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563200463d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5632003c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5632003bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563200455c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563203424f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563203424f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563203424f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563203424f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563203424f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563203424f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563203424f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563203424f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563203424f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563203424f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5632056b9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5632023e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5632023f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56320219dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56320219dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56320219e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56320219d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56320219d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56320219d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563206aa7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563206ab0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563206a98699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563206ac3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f105ec35082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5632003bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-58745853b97af5d27b0073a066fec9c9701468ea Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6354 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 876474026 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562a506e4810, 0x562a508ce01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562a508ce020,0x562a527660e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/58745853b97af5d27b0073a066fec9c9701468ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8265 processed earlier; will process 2764 files now Step #5: ==228850== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562a471d99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562a4d83e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562a4d8215dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562a4d8214fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562a471dfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562a47140b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562a4713b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562a471d1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562a4a1a0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562a4a1a0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562a4a1a0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562a4a1a0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562a4a1a0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562a4a1a0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562a4a1a0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562a4a1a0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562a4a1a0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562a4a1a0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562a4c435f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562a49162b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562a4916dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562a48f19c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562a48f19c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562a48f1a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562a48f19874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562a48f19874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562a48f19874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562a4d823abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562a4d82c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562a4d814699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562a4d83f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdd37e66082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562a47139b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6cce64e5cb878245e7639c64922c0d96ee7cd9a4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6355 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 877909709 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55caa8aff810, 0x55caa8ce901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55caa8ce9020,0x55caaab810e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6cce64e5cb878245e7639c64922c0d96ee7cd9a4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8266 processed earlier; will process 2763 files now Step #5: ==228886== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ca9f5f49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55caa5c59898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55caa5c3c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55caa5c3c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ca9f5fad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ca9f55bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ca9f556355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ca9f5ecc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55caa25bbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55caa25bbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55caa25bbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55caa25bbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55caa25bbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55caa25bbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55caa25bbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55caa25bbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55caa25bbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55caa25bbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55caa4850f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55caa157db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55caa1588be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55caa1334c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55caa1334c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55caa1335738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55caa1334874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55caa1334874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55caa1334874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55caa5c3eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55caa5c47928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55caa5c2f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55caa5c5a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd1b39a2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ca9f554b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-06bb272eafb7a26e463959fc4f312e42bd59fc39 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6356 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 878495642 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5640e867d810, 0x5640e886701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5640e8867020,0x5640ea6ff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/06bb272eafb7a26e463959fc4f312e42bd59fc39' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8267 processed earlier; will process 2762 files now Step #5: ==228922== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5640df1729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5640e57d7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5640e57ba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5640e57ba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5640df178d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5640df0d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5640df0d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5640df16ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5640e2139f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5640e2139f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5640e2139f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5640e2139f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5640e2139f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5640e2139f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5640e2139f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5640e2139f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5640e2139f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5640e2139f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5640e43cef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5640e10fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5640e1106be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5640e0eb2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5640e0eb2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5640e0eb3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5640e0eb2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5640e0eb2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5640e0eb2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5640e57bcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5640e57c5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5640e57ad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5640e57d8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdaf7953082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5640df0d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7df96ab885f1cd551102117a9dcaaa6698b9e84d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6357 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 879954707 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56333900d810, 0x5633391f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5633391f7020,0x56333b08f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7df96ab885f1cd551102117a9dcaaa6698b9e84d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8268 processed earlier; will process 2761 files now Step #5: ==228958== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56332fb029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563336167898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56333614a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56333614a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56332fb08d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56332fa69b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56332fa64355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56332fafac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563332ac9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563332ac9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563332ac9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563332ac9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563332ac9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563332ac9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563332ac9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563332ac9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563332ac9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563332ac9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563334d5ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563331a8bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563331a96be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563331842c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563331842c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563331843738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563331842874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563331842874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563331842874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56333614cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563336155928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56333613d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563336168112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f13c7e36082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56332fa62b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a462b19a610c5440db86b5d507f6e47401f7b5b6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6358 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 881389251 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0554d7810, 0x55b0556c101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b0556c1020,0x55b0575590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a462b19a610c5440db86b5d507f6e47401f7b5b6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8269 processed earlier; will process 2760 files now Step #5: ==228994== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b04bfcc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b052631898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b0526145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b0526144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b04bfd2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b04bf33b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b04bf2e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b04bfc4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b04ef93f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b04ef93f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b04ef93f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b04ef93f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b04ef93f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b04ef93f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b04ef93f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b04ef93f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b04ef93f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b04ef93f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b051228f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b04df55b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b04df60be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b04dd0cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b04dd0cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b04dd0d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b04dd0c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b04dd0c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b04dd0c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b052616abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b05261f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b052607699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b052632112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff2f8936082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b04bf2cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a33344da881e11fe036b84148fd157635644bbb8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6359 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 881970485 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55648479e810, 0x55648498801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556484988020,0x5564868200e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a33344da881e11fe036b84148fd157635644bbb8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8270 processed earlier; will process 2759 files now Step #5: ==229030== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55647b2939c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564818f8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564818db5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564818db4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55647b299d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55647b1fab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55647b1f5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55647b28bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55647e25af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55647e25af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55647e25af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55647e25af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55647e25af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55647e25af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55647e25af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55647e25af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55647e25af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55647e25af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5564804eff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55647d21cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55647d227be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55647cfd3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55647cfd3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55647cfd4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55647cfd3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55647cfd3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55647cfd3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564818ddabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564818e6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564818ce699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564818f9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f21fac3b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55647b1f3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-db5ec10c99b43b9e527ac287c3788d7cd70eed8f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6360 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 882561127 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56201b9a9810, 0x56201bb9301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56201bb93020,0x56201da2b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/db5ec10c99b43b9e527ac287c3788d7cd70eed8f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8271 processed earlier; will process 2758 files now Step #5: ==229066== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56201249e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562018b03898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562018ae65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562018ae64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5620124a4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562012405b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562012400355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562012496c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562015465f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562015465f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562015465f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562015465f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562015465f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562015465f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562015465f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562015465f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562015465f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562015465f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5620176faf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562014427b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562014432be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5620141dec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5620141dec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5620141df738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5620141de874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5620141de874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5620141de874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562018ae8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562018af1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562018ad9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562018b04112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6fc4fcb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5620123feb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1156344b4f0e524a82ee9d1ccd724167a8b7841c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6361 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 883161337 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c190866810, 0x55c190a5001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c190a50020,0x55c1928e80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1156344b4f0e524a82ee9d1ccd724167a8b7841c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8272 processed earlier; will process 2757 files now Step #5: ==229102== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c18735b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c18d9c0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c18d9a35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c18d9a34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c187361d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c1872c2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c1872bd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c187353c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c18a322f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c18a322f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c18a322f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c18a322f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c18a322f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c18a322f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c18a322f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c18a322f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c18a322f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c18a322f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c18c5b7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c1892e4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c1892efbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c18909bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c18909bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c18909c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c18909b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c18909b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c18909b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c18d9a5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c18d9ae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c18d996699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c18d9c1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3efdef2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c1872bbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-08cbabb1c4fb8245f9cbea80e51b2571e9e5dba0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6362 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 883744222 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564178070810, 0x56417825a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56417825a020,0x56417a0f20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08cbabb1c4fb8245f9cbea80e51b2571e9e5dba0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8273 processed earlier; will process 2756 files now Step #5: #1 pulse cov: 4306 ft: 4307 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 15862 ft: 17157 exec/s: 0 rss: 204Mb Step #5: ==229138== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56416eb659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5641751ca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5641751ad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5641751ad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56416eb6bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56416eaccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56416eac7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56416eb5dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564171b2cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564171b2cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564171b2cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564171b2cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564171b2cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564171b2cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564171b2cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564171b2cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564171b2cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564171b2cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564173dc1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564170aeeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564170af9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5641708a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5641708a5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5641708a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5641708a5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5641708a5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5641708a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5641751afabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5641751b8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5641751a0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5641751cb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fdef414d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56416eac5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-203175baf3830ad5c0deb89064f6db556b5e6ddb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6363 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 884460787 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b817cc8810, 0x55b817eb201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b817eb2020,0x55b819d4a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/203175baf3830ad5c0deb89064f6db556b5e6ddb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8276 processed earlier; will process 2753 files now Step #5: #1 pulse cov: 15141 ft: 15142 exec/s: 0 rss: 204Mb Step #5: #2 pulse cov: 15625 ft: 16701 exec/s: 0 rss: 206Mb Step #5: ==229174== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b80e7bd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b814e22898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b814e055dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b814e054fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b80e7c3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b80e724b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b80e71f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b80e7b5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b811784f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b811784f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b811784f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b811784f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b811784f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b811784f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b811784f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b811784f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b811784f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b811784f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b813a19f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b810746b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b810751be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b8104fdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b8104fdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b8104fe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b8104fd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b8104fd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b8104fd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b814e07abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b814e10928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b814df8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b814e23112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f43aeb60082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b80e71db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-34c4c5432df479bcde705ee37841d95dcef762b7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6364 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 885891793 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563964e70810, 0x56396505a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56396505a020,0x563966ef20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/34c4c5432df479bcde705ee37841d95dcef762b7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8279 processed earlier; will process 2750 files now Step #5: ==229210== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56395b9659c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563961fca898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563961fad5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563961fad4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56395b96bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56395b8ccb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56395b8c7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56395b95dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56395e92cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56395e92cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56395e92cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56395e92cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56395e92cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56395e92cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56395e92cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56395e92cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56395e92cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56395e92cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563960bc1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56395d8eeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56395d8f9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56395d6a5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56395d6a5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56395d6a6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56395d6a5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56395d6a5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56395d6a5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563961fafabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563961fb8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563961fa0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563961fcb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f104fd84082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56395b8c5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a88e44c6886f5f38130d7033f31a46716ab8684c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6365 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 887181201 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b0d3ff9810, 0x55b0d41e301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b0d41e3020,0x55b0d607b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a88e44c6886f5f38130d7033f31a46716ab8684c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8280 processed earlier; will process 2749 files now Step #5: ==229246== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b0caaee9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b0d1153898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b0d11365dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b0d11364fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b0caaf4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b0caa55b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b0caa50355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b0caae6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b0cdab5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b0cdab5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b0cdab5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b0cdab5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b0cdab5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b0cdab5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b0cdab5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b0cdab5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b0cdab5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b0cdab5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b0cfd4af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b0cca77b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b0cca82be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b0cc82ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b0cc82ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b0cc82f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b0cc82e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b0cc82e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b0cc82e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b0d1138abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b0d1141928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b0d1129699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b0d1154112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f111b684082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b0caa4eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7cef84a9c28302a1da799111bdcd4242e35cfa28 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6366 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 887919070 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561c63842810, 0x561c63a2c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561c63a2c020,0x561c658c40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7cef84a9c28302a1da799111bdcd4242e35cfa28' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8281 processed earlier; will process 2748 files now Step #5: ==229282== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561c5a3379c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561c6099c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561c6097f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561c6097f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561c5a33dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561c5a29eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561c5a299355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561c5a32fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561c5d2fef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561c5d2fef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561c5d2fef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561c5d2fef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561c5d2fef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561c5d2fef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561c5d2fef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561c5d2fef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561c5d2fef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561c5d2fef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561c5f593f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561c5c2c0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561c5c2cbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561c5c077c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561c5c077c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561c5c078738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561c5c077874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561c5c077874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561c5c077874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561c60981abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561c6098a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561c60972699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561c6099d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9443a9e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561c5a297b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-362cd2d748b7b112f97607725ae751bf45114a77 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6367 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 888493948 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d431e8810, 0x564d433d201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d433d2020,0x564d4526a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/362cd2d748b7b112f97607725ae751bf45114a77' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8282 processed earlier; will process 2747 files now Step #5: ==229318== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d39cdd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d40342898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d403255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d403254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d39ce3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d39c44b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d39c3f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d39cd5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d3cca4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d3cca4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d3cca4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d3cca4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d3cca4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d3cca4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d3cca4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d3cca4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d3cca4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d3cca4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d3ef39f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d3bc66b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d3bc71be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d3ba1dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d3ba1dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d3ba1e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d3ba1d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d3ba1d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d3ba1d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d40327abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d40330928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d40318699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d40343112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f79620f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d39c3db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e79d1d242ccf1f2393577527c5ce27cec5dbe84b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6368 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 890282596 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f41ac6f810, 0x55f41ae5901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f41ae59020,0x55f41ccf10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e79d1d242ccf1f2393577527c5ce27cec5dbe84b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8283 processed earlier; will process 2746 files now Step #5: ==229354== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f4117649c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f417dc9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f417dac5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f417dac4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f41176ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f4116cbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f4116c6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f41175cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f41472bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f41472bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f41472bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f41472bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f41472bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f41472bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f41472bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f41472bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f41472bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f41472bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f4169c0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4136edb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4136f8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f4134a4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f4134a4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f4134a5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f4134a4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f4134a4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f4134a4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f417daeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f417db7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f417d9f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f417dca112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffbef1cd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f4116c4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bd48118c19b1ce1123e3767c61b7797ea38da8b1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6369 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 890885700 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c26d3f5810, 0x55c26d5df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c26d5df020,0x55c26f4770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bd48118c19b1ce1123e3767c61b7797ea38da8b1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8284 processed earlier; will process 2745 files now Step #5: #1 pulse cov: 4215 ft: 4216 exec/s: 0 rss: 179Mb Step #5: ==229390== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c263eea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c26a54f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c26a5325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c26a5324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c263ef0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c263e51b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c263e4c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c263ee2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c266eb1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c266eb1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c266eb1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c266eb1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c266eb1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c266eb1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c266eb1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c266eb1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c266eb1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c266eb1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c269146f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c265e73b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c265e7ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c265c2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c265c2ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c265c2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c265c2a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c265c2a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c265c2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c26a534abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c26a53d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c26a525699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c26a550112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1b45066082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c263e4ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b87e3d976d3187e4ec2ac9abeb2fda8dbad3019d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6370 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 891684683 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562aac389810, 0x562aac57301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562aac573020,0x562aae40b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b87e3d976d3187e4ec2ac9abeb2fda8dbad3019d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8286 processed earlier; will process 2743 files now Step #5: ==229426== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562aa2e7e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562aa94e3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562aa94c65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562aa94c64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562aa2e84d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562aa2de5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562aa2de0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562aa2e76c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562aa5e45f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562aa5e45f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562aa5e45f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562aa5e45f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562aa5e45f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562aa5e45f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562aa5e45f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562aa5e45f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562aa5e45f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562aa5e45f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562aa80daf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562aa4e07b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562aa4e12be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562aa4bbec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562aa4bbec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562aa4bbf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562aa4bbe874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562aa4bbe874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562aa4bbe874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562aa94c8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562aa94d1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562aa94b9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562aa94e4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3b3d189082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562aa2ddeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-30bc9589716bad5b35fcef710b3362793cf409f0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6371 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 892281096 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560c73149810, 0x560c7333301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560c73333020,0x560c751cb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/30bc9589716bad5b35fcef710b3362793cf409f0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8287 processed earlier; will process 2742 files now Step #5: ==229462== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560c69c3e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560c702a3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560c702865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560c702864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560c69c44d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560c69ba5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560c69ba0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560c69c36c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560c6cc05f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560c6cc05f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560c6cc05f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560c6cc05f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560c6cc05f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560c6cc05f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560c6cc05f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560c6cc05f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560c6cc05f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560c6cc05f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560c6ee9af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560c6bbc7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560c6bbd2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560c6b97ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560c6b97ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560c6b97f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560c6b97e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560c6b97e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560c6b97e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560c70288abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560c70291928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560c70279699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560c702a4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f75d7b63082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560c69b9eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b8db56fedc7c427347e5cef2350c1ba635a25e37 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6372 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 892883592 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557f5d3df810, 0x557f5d5c901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557f5d5c9020,0x557f5f4610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b8db56fedc7c427347e5cef2350c1ba635a25e37' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8288 processed earlier; will process 2741 files now Step #5: ==229498== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557f53ed49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557f5a539898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557f5a51c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557f5a51c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557f53edad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557f53e3bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557f53e36355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557f53eccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557f56e9bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557f56e9bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557f56e9bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557f56e9bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557f56e9bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557f56e9bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557f56e9bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557f56e9bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557f56e9bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557f56e9bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557f59130f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557f55e5db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557f55e68be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557f55c14c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557f55c14c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557f55c15738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557f55c14874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557f55c14874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557f55c14874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557f5a51eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557f5a527928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557f5a50f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557f5a53a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fef5ce33082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557f53e34b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c21e729d594ffdbc1c6f66e687f6b338b9d3fc5f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6373 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 893653842 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bf44007810, 0x55bf441f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bf441f1020,0x55bf460890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c21e729d594ffdbc1c6f66e687f6b338b9d3fc5f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8289 processed earlier; will process 2740 files now Step #5: #1 pulse cov: 11139 ft: 11140 exec/s: 0 rss: 197Mb Step #5: #2 pulse cov: 11580 ft: 12445 exec/s: 0 rss: 199Mb Step #5: ==229534== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bf3aafc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bf41161898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bf411445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bf411444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bf3ab02d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bf3aa63b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bf3aa5e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bf3aaf4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bf3dac3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bf3dac3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bf3dac3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bf3dac3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bf3dac3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bf3dac3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bf3dac3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bf3dac3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bf3dac3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bf3dac3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bf3fd58f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bf3ca85b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bf3ca90be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bf3c83cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bf3c83cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bf3c83d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bf3c83c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bf3c83c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bf3c83c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bf41146abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bf4114f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bf41137699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bf41162112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9373a83082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bf3aa5cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7141270ea0b5a6147c07df1a2f681ca6b63e7972 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6374 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 894531847 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5630f8711810, 0x5630f88fb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5630f88fb020,0x5630fa7930e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7141270ea0b5a6147c07df1a2f681ca6b63e7972' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8292 processed earlier; will process 2737 files now Step #5: #1 pulse cov: 4023 ft: 4024 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4450 ft: 5042 exec/s: 0 rss: 182Mb Step #5: ==229570== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5630ef2069c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5630f586b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5630f584e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5630f584e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5630ef20cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5630ef16db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5630ef168355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5630ef1fec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5630f21cdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5630f21cdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5630f21cdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5630f21cdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5630f21cdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5630f21cdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5630f21cdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5630f21cdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5630f21cdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5630f21cdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5630f4462f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5630f118fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5630f119abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5630f0f46c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5630f0f46c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5630f0f47738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5630f0f46874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5630f0f46874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5630f0f46874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5630f5850abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5630f5859928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5630f5841699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5630f586c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff3e4a09082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5630ef166b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-75316296ca2e85a2b4073a1566c315825bd48a6c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6375 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 896067674 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556a8dffe810, 0x556a8e1e801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556a8e1e8020,0x556a900800e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/75316296ca2e85a2b4073a1566c315825bd48a6c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8295 processed earlier; will process 2734 files now Step #5: #1 pulse cov: 25189 ft: 25190 exec/s: 1 rss: 229Mb Step #5: #2 pulse cov: 25511 ft: 31253 exec/s: 2 rss: 231Mb Step #5: #4 pulse cov: 26223 ft: 37626 exec/s: 2 rss: 239Mb Step #5: ==229606== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556a84af39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556a8b158898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556a8b13b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556a8b13b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556a84af9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556a84a5ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556a84a55355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556a84aebc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556a87abaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556a87abaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556a87abaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556a87abaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556a87abaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556a87abaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556a87abaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556a87abaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556a87abaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556a87abaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556a89d4ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556a86a7cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556a86a87be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556a86833c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556a86833c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556a86834738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556a86833874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556a86833874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556a86833874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556a8b13dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556a8b146928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556a8b12e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556a8b159112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f621d535082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556a84a53b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f8152d02b43474f90108d7bc904045f7120832ac Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6376 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 898570443 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ab8164810, 0x561ab834e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ab834e020,0x561aba1e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f8152d02b43474f90108d7bc904045f7120832ac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8301 processed earlier; will process 2728 files now Step #5: ==229642== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561aaec599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561ab52be898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561ab52a15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561ab52a14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561aaec5fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561aaebc0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561aaebbb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561aaec51c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561ab1c20f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561ab1c20f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561ab1c20f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561ab1c20f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561ab1c20f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561ab1c20f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561ab1c20f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561ab1c20f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561ab1c20f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561ab1c20f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561ab3eb5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561ab0be2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561ab0bedbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561ab0999c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561ab0999c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561ab099a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561ab0999874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561ab0999874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561ab0999874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561ab52a3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561ab52ac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561ab5294699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561ab52bf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f923016d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561aaebb9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-93262f969a18012a24df0b61435e074fdb3bcc6c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6377 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 899169253 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a958c1e810, 0x55a958e0801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a958e08020,0x55a95aca00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/93262f969a18012a24df0b61435e074fdb3bcc6c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8302 processed earlier; will process 2727 files now Step #5: ==229678== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a94f7139c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a955d78898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a955d5b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a955d5b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a94f719d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a94f67ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a94f675355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a94f70bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9526daf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9526daf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9526daf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9526daf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9526daf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9526daf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9526daf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9526daf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9526daf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9526daf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a95496ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a95169cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a9516a7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a951453c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a951453c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a951454738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a951453874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a951453874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a951453874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a955d5dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a955d66928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a955d4e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a955d79112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f35c2aaf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a94f673b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-742848555e99ec13f91e7cffbfdc52d6baca4730 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6378 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 899957790 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558d08122810, 0x558d0830c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558d0830c020,0x558d0a1a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/742848555e99ec13f91e7cffbfdc52d6baca4730' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8303 processed earlier; will process 2726 files now Step #5: #1 pulse cov: 12128 ft: 12129 exec/s: 0 rss: 199Mb Step #5: ==229714== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558cfec179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558d0527c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558d0525f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558d0525f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558cfec1dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558cfeb7eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558cfeb79355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558cfec0fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558d01bdef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558d01bdef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558d01bdef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558d01bdef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558d01bdef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558d01bdef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558d01bdef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558d01bdef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558d01bdef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558d01bdef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558d03e73f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558d00ba0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558d00babbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558d00957c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558d00957c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558d00958738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558d00957874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558d00957874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558d00957874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558d05261abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558d0526a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558d05252699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558d0527d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0b4c59c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558cfeb77b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3dbf68949836b341149a0410229d8aaaf76ea476 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6379 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 900663740 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5632b61f2810, 0x5632b63dc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5632b63dc020,0x5632b82740e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3dbf68949836b341149a0410229d8aaaf76ea476' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8305 processed earlier; will process 2724 files now Step #5: #1 pulse cov: 3851 ft: 3852 exec/s: 0 rss: 178Mb Step #5: ==229750== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5632acce79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5632b334c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5632b332f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5632b332f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5632accedd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5632acc4eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5632acc49355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5632accdfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5632afcaef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5632afcaef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5632afcaef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5632afcaef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5632afcaef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5632afcaef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5632afcaef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5632afcaef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5632afcaef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5632afcaef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5632b1f43f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5632aec70b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5632aec7bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5632aea27c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5632aea27c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5632aea28738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5632aea27874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5632aea27874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5632aea27874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5632b3331abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5632b333a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5632b3322699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5632b334d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f72b52e9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5632acc47b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d20bc6ceb57df72676f9e4209a6d1d4febae40cb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6380 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 901338121 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5591fdbd5810, 0x5591fddbf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5591fddbf020,0x5591ffc570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d20bc6ceb57df72676f9e4209a6d1d4febae40cb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8307 processed earlier; will process 2722 files now Step #5: ==229786== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5591f46ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5591fad2f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5591fad125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5591fad124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5591f46d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5591f4631b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5591f462c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5591f46c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5591f7691f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5591f7691f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5591f7691f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5591f7691f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5591f7691f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5591f7691f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5591f7691f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5591f7691f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5591f7691f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5591f7691f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5591f9926f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5591f6653b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5591f665ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5591f640ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5591f640ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5591f640b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5591f640a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5591f640a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5591f640a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5591fad14abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5591fad1d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5591fad05699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5591fad30112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5b61b0b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5591f462ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-568f16ed90964ca6139435b0fccd0b0b5cb8004d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6381 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 902041580 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c5257c810, 0x562c5276601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c52766020,0x562c545fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/568f16ed90964ca6139435b0fccd0b0b5cb8004d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8308 processed earlier; will process 2721 files now Step #5: ==229822== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562c490719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c4f6d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c4f6b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c4f6b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c49077d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c48fd8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c48fd3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c49069c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c4c038f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c4c038f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c4c038f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c4c038f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c4c038f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c4c038f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c4c038f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c4c038f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c4c038f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c4c038f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c4e2cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562c4affab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562c4b005be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562c4adb1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562c4adb1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562c4adb2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562c4adb1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562c4adb1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562c4adb1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c4f6bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c4f6c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c4f6ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c4f6d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7f6d981082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c48fd1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6d6c9f30e90e6ca8571afc375ebd70562a1dd92c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6382 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 902680643 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d44c52e810, 0x55d44c71801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d44c718020,0x55d44e5b00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6d6c9f30e90e6ca8571afc375ebd70562a1dd92c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8309 processed earlier; will process 2720 files now Step #5: #1 pulse cov: 4271 ft: 4272 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 12659 ft: 13612 exec/s: 0 rss: 201Mb Step #5: ==229858== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d4430239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d449688898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d44966b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d44966b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d443029d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d442f8ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d442f85355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d44301bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d445feaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d445feaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d445feaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d445feaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d445feaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d445feaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d445feaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d445feaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d445feaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d445feaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d44827ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d444facb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d444fb7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d444d63c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d444d63c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d444d64738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d444d63874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d444d63874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d444d63874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d44966dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d449676928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d44965e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d449689112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe96d97e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d442f83b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f78028c6f7c3c4c03d463dc15d01f28d74a2322f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6383 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 903428810 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5637904b2810, 0x56379069c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56379069c020,0x5637925340e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f78028c6f7c3c4c03d463dc15d01f28d74a2322f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8312 processed earlier; will process 2717 files now Step #5: ==229894== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563786fa79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56378d60c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56378d5ef5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56378d5ef4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563786fadd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563786f0eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563786f09355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563786f9fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563789f6ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563789f6ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563789f6ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563789f6ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563789f6ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563789f6ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563789f6ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563789f6ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563789f6ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563789f6ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56378c203f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563788f30b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563788f3bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563788ce7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563788ce7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563788ce8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563788ce7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563788ce7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563788ce7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56378d5f1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56378d5fa928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56378d5e2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56378d60d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f957e806082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563786f07b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ee5cb0bdf17e8df7b552930c7c1fe6ce03a5bf22 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6384 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 904036321 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559114dd2810, 0x559114fbc01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559114fbc020,0x559116e540e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee5cb0bdf17e8df7b552930c7c1fe6ce03a5bf22' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8313 processed earlier; will process 2716 files now Step #5: #1 pulse cov: 4118 ft: 4119 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4552 ft: 4985 exec/s: 0 rss: 180Mb Step #5: ==229930== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55910b8c79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559111f2c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559111f0f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559111f0f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55910b8cdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55910b82eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55910b829355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55910b8bfc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55910e88ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55910e88ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55910e88ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55910e88ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55910e88ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55910e88ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55910e88ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55910e88ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55910e88ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55910e88ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559110b23f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55910d850b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55910d85bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55910d607c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55910d607c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55910d608738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55910d607874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55910d607874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55910d607874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559111f11abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559111f1a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559111f02699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559111f2d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f997fe57082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55910b827b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f7381166d8ff836910dfdde012ac70872fd6c538 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6385 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 905664470 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ce80a04810, 0x55ce80bee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ce80bee020,0x55ce82a860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f7381166d8ff836910dfdde012ac70872fd6c538' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8317 processed earlier; will process 2712 files now Step #5: #1 pulse cov: 11648 ft: 11649 exec/s: 0 rss: 198Mb Step #5: ==229966== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ce774f99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ce7db5e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ce7db415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ce7db414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ce774ffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ce77460b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ce7745b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ce774f1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ce7a4c0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ce7a4c0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ce7a4c0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ce7a4c0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ce7a4c0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ce7a4c0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ce7a4c0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ce7a4c0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ce7a4c0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ce7a4c0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ce7c755f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ce79482b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ce7948dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ce79239c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ce79239c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ce7923a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ce79239874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ce79239874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ce79239874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ce7db43abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ce7db4c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ce7db34699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ce7db5f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f43742bc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ce77459b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4c0ba8fa9a92ab231a7b6f4d46745c899b6dad9e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6386 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 907809726 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c89f14810, 0x556c8a0fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c8a0fe020,0x556c8bf960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4c0ba8fa9a92ab231a7b6f4d46745c899b6dad9e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8319 processed earlier; will process 2710 files now Step #5: ==230002== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556c80a099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c8706e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c870515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c870514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556c80a0fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556c80970b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556c8096b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556c80a01c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556c839d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556c839d0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556c839d0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556c839d0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556c839d0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556c839d0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556c839d0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556c839d0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556c839d0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556c839d0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c85c65f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556c82992b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556c8299dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556c82749c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556c82749c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556c8274a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556c82749874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556c82749874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556c82749874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c87053abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c8705c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c87044699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c8706f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8b81825082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556c80969b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ad04ab6a25ed6cce2bfc9862cbc98e40f3e7680e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6387 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 908425781 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5628ec393810, 0x5628ec57d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5628ec57d020,0x5628ee4150e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ad04ab6a25ed6cce2bfc9862cbc98e40f3e7680e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8320 processed earlier; will process 2709 files now Step #5: ==230038== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5628e2e889c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5628e94ed898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5628e94d05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5628e94d04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5628e2e8ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5628e2defb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5628e2dea355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5628e2e80c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5628e5e4ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5628e5e4ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5628e5e4ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5628e5e4ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5628e5e4ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5628e5e4ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5628e5e4ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5628e5e4ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5628e5e4ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5628e5e4ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5628e80e4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5628e4e11b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5628e4e1cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5628e4bc8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5628e4bc8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5628e4bc9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5628e4bc8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5628e4bc8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5628e4bc8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5628e94d2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5628e94db928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5628e94c3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5628e94ee112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5ca4d8a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5628e2de8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-76b4fcddb7d140f6b479e7e4f3a156fed58d8336 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6388 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 910399527 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558377022810, 0x55837720c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55837720c020,0x5583790a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/76b4fcddb7d140f6b479e7e4f3a156fed58d8336' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8321 processed earlier; will process 2708 files now Step #5: ==230074== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55836db179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55837417c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55837415f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55837415f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55836db1dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55836da7eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55836da79355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55836db0fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558370adef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558370adef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558370adef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558370adef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558370adef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558370adef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558370adef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558370adef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558370adef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558370adef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558372d73f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55836faa0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55836faabbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55836f857c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55836f857c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55836f858738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55836f857874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55836f857874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55836f857874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558374161abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55837416a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558374152699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55837417d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f261d99c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55836da77b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c51144c871a6d9c00665b30139a4ebd1cbf9dddd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6389 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 912335136 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5613fb53d810, 0x5613fb72701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5613fb727020,0x5613fd5bf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c51144c871a6d9c00665b30139a4ebd1cbf9dddd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8322 processed earlier; will process 2707 files now Step #5: ==230110== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5613f20329c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5613f8697898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613f867a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613f867a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5613f2038d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5613f1f99b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5613f1f94355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5613f202ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5613f4ff9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5613f4ff9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5613f4ff9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5613f4ff9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5613f4ff9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5613f4ff9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5613f4ff9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5613f4ff9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5613f4ff9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5613f4ff9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5613f728ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5613f3fbbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5613f3fc6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5613f3d72c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5613f3d72c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5613f3d73738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5613f3d72874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5613f3d72874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5613f3d72874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5613f867cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5613f8685928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5613f866d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5613f8698112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f10ac06e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5613f1f92b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0f384bc72909c326846901ec350881ab14ae8e44 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6390 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 914236612 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5642798c1810, 0x564279aab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564279aab020,0x56427b9430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0f384bc72909c326846901ec350881ab14ae8e44' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8323 processed earlier; will process 2706 files now Step #5: ==230146== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5642703b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564276a1b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5642769fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5642769fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5642703bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56427031db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564270318355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5642703aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56427337df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56427337df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56427337df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56427337df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56427337df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56427337df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56427337df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56427337df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56427337df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56427337df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564275612f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56427233fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56427234abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5642720f6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5642720f6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5642720f7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5642720f6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5642720f6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5642720f6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564276a00abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564276a09928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5642769f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564276a1c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f14652fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564270316b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-05fd313afcca6092dfeecbaf0d4daeaeb7d4d76c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6391 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 915973149 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c8a27cc810, 0x55c8a29b601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c8a29b6020,0x55c8a484e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/05fd313afcca6092dfeecbaf0d4daeaeb7d4d76c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8324 processed earlier; will process 2705 files now Step #5: ==230182== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c8992c19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c89f926898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c89f9095dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c89f9094fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c8992c7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c899228b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c899223355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c8992b9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c89c288f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c89c288f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c89c288f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c89c288f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c89c288f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c89c288f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c89c288f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c89c288f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c89c288f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c89c288f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c89e51df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c89b24ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c89b255be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c89b001c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c89b001c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c89b002738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c89b001874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c89b001874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c89b001874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c89f90babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c89f914928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c89f8fc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c89f927112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd17fb83082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c899221b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-626ff5ed0f62c6727e3c0856cee25fdbfd54d676 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6392 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 917915282 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c9f04d9810, 0x55c9f06c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c9f06c3020,0x55c9f255b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/626ff5ed0f62c6727e3c0856cee25fdbfd54d676' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8325 processed earlier; will process 2704 files now Step #5: ==230218== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c9e6fce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c9ed633898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c9ed6165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c9ed6164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c9e6fd4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c9e6f35b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c9e6f30355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c9e6fc6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c9e9f95f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c9e9f95f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c9e9f95f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c9e9f95f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c9e9f95f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c9e9f95f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c9e9f95f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c9e9f95f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c9e9f95f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c9e9f95f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c9ec22af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c9e8f57b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c9e8f62be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c9e8d0ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c9e8d0ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c9e8d0f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c9e8d0e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c9e8d0e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c9e8d0e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c9ed618abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c9ed621928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c9ed609699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c9ed634112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff1d9e15082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c9e6f2eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e0c979d589de9a5ba3d1c39d7f1da5b2de5d0aad Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6393 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 919327319 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dec8664810, 0x55dec884e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dec884e020,0x55deca6e60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e0c979d589de9a5ba3d1c39d7f1da5b2de5d0aad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8326 processed earlier; will process 2703 files now Step #5: ==230254== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55debf1599c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dec57be898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dec57a15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dec57a14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55debf15fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55debf0c0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55debf0bb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55debf151c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dec2120f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dec2120f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dec2120f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dec2120f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dec2120f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dec2120f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dec2120f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dec2120f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dec2120f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dec2120f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dec43b5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dec10e2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dec10edbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dec0e99c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dec0e99c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dec0e9a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dec0e99874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dec0e99874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dec0e99874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dec57a3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dec57ac928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dec5794699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dec57bf112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff1d65df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55debf0b9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5da3222fec6f1f905f469203c2cbf13144a77698 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6394 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 920491483 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fe30831810, 0x55fe30a1b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fe30a1b020,0x55fe328b30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5da3222fec6f1f905f469203c2cbf13144a77698' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8327 processed earlier; will process 2702 files now Step #5: ==230290== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fe273269c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fe2d98b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fe2d96e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fe2d96e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fe2732cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fe2728db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fe27288355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fe2731ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fe2a2edf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fe2a2edf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fe2a2edf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fe2a2edf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fe2a2edf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fe2a2edf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fe2a2edf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fe2a2edf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fe2a2edf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fe2a2edf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fe2c582f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fe292afb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fe292babe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fe29066c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fe29066c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fe29067738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fe29066874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fe29066874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fe29066874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fe2d970abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fe2d979928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fe2d961699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fe2d98c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b5e261082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fe27286b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-31b3ffb6b3e90744bf91cec97d0a7537f31fd6d4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6395 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 921175336 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55643a1ed810, 0x55643a3d701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55643a3d7020,0x55643c26f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/31b3ffb6b3e90744bf91cec97d0a7537f31fd6d4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8328 processed earlier; will process 2701 files now Step #5: ==230326== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556430ce29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556437347898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55643732a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55643732a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556430ce8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556430c49b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556430c44355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556430cdac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556433ca9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556433ca9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556433ca9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556433ca9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556433ca9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556433ca9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556433ca9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556433ca9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556433ca9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556433ca9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556435f3ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556432c6bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556432c76be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556432a22c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556432a22c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556432a23738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556432a22874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556432a22874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556432a22874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55643732cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556437335928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55643731d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556437348112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb517603082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556430c42b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bdfef5418595a57fdaeed47766b1ac6c2cbc8685 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6396 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 921770544 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f427836810, 0x55f427a2001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f427a20020,0x55f4298b80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bdfef5418595a57fdaeed47766b1ac6c2cbc8685' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8329 processed earlier; will process 2700 files now Step #5: #1 pulse cov: 11757 ft: 11758 exec/s: 0 rss: 198Mb Step #5: ==230362== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f41e32b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f424990898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f4249735dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f4249734fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f41e331d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f41e292b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f41e28d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f41e323c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f4212f2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f4212f2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f4212f2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f4212f2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f4212f2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f4212f2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f4212f2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f4212f2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f4212f2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f4212f2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f423587f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f4202b4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f4202bfbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f42006bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f42006bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f42006c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f42006b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f42006b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f42006b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f424975abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f42497e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f424966699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f424991112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd91129e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f41e28bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3277f2d35859697222e4941279c416f62622ddeb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6397 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 923201141 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559433bb1810, 0x559433d9b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559433d9b020,0x559435c330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3277f2d35859697222e4941279c416f62622ddeb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8331 processed earlier; will process 2698 files now Step #5: ==230398== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55942a6a69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559430d0b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559430cee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559430cee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55942a6acd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55942a60db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55942a608355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55942a69ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55942d66df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55942d66df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55942d66df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55942d66df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55942d66df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55942d66df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55942d66df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55942d66df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55942d66df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55942d66df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55942f902f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55942c62fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55942c63abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55942c3e6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55942c3e6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55942c3e7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55942c3e6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55942c3e6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55942c3e6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559430cf0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559430cf9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559430ce1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559430d0c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcbcd54f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55942a606b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1c90a38b48f2c54e3cf4cd2ad1b0faf562fd1763 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6398 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 923818648 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562fa64d0810, 0x562fa66ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562fa66ba020,0x562fa85520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1c90a38b48f2c54e3cf4cd2ad1b0faf562fd1763' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8332 processed earlier; will process 2697 files now Step #5: #1 pulse cov: 4190 ft: 4191 exec/s: 0 rss: 181Mb Step #5: ==230434== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562f9cfc59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562fa362a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562fa360d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562fa360d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562f9cfcbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562f9cf2cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562f9cf27355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562f9cfbdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562f9ff8cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562f9ff8cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562f9ff8cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562f9ff8cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562f9ff8cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562f9ff8cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562f9ff8cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562f9ff8cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562f9ff8cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562f9ff8cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562fa2221f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562f9ef4eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562f9ef59be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562f9ed05c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562f9ed05c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562f9ed06738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562f9ed05874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562f9ed05874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562f9ed05874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562fa360fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562fa3618928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562fa3600699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562fa362b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f033181f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562f9cf25b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7ed215a9bfc8a4dee8e2f1263ee7282d47328eab Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6399 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 925061831 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ddecdfd810, 0x55ddecfe701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ddecfe7020,0x55ddeee7f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ed215a9bfc8a4dee8e2f1263ee7282d47328eab' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8334 processed earlier; will process 2695 files now Step #5: ==230470== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dde38f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dde9f57898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dde9f3a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dde9f3a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dde38f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dde3859b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dde3854355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dde38eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dde68b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dde68b9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dde68b9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dde68b9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dde68b9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dde68b9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dde68b9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dde68b9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dde68b9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dde68b9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dde8b4ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dde587bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dde5886be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dde5632c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dde5632c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dde5633738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dde5632874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dde5632874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dde5632874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dde9f3cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dde9f45928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dde9f2d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dde9f58112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f04d0367082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dde3852b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1e460767a4e982698adda49b67aea69e161da640 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6400 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 925700330 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b399a76810, 0x55b399c6001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b399c60020,0x55b39baf80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1e460767a4e982698adda49b67aea69e161da640' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8335 processed earlier; will process 2694 files now Step #5: ==230506== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b39056b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b396bd0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b396bb35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b396bb34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b390571d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b3904d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b3904cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b390563c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b393532f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b393532f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b393532f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b393532f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b393532f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b393532f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b393532f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b393532f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b393532f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b393532f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b3957c7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b3924f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b3924ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b3922abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b3922abc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b3922ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b3922ab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b3922ab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b3922ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b396bb5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b396bbe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b396ba6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b396bd1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4baa846082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b3904cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-54e06776ad0889b13c0e0d1a2e136bf3a1335eb3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6401 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 926344046 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5628bfafd810, 0x5628bfce701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5628bfce7020,0x5628c1b7f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/54e06776ad0889b13c0e0d1a2e136bf3a1335eb3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8336 processed earlier; will process 2693 files now Step #5: #1 pulse cov: 3706 ft: 3707 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4314 ft: 4711 exec/s: 0 rss: 180Mb Step #5: ==230542== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5628b65f29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5628bcc57898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5628bcc3a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5628bcc3a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5628b65f8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5628b6559b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5628b6554355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5628b65eac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5628b95b9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5628b95b9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5628b95b9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5628b95b9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5628b95b9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5628b95b9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5628b95b9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5628b95b9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5628b95b9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5628b95b9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5628bb84ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5628b857bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5628b8586be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5628b8332c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5628b8332c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5628b8333738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5628b8332874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5628b8332874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5628b8332874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5628bcc3cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5628bcc45928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5628bcc2d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5628bcc58112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd5a16ca082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5628b6552b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-59cd2c30159b62747e77748a1a27e363cac4aa5d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6402 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 927738989 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dbb717b810, 0x55dbb736501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dbb7365020,0x55dbb91fd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/59cd2c30159b62747e77748a1a27e363cac4aa5d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8339 processed earlier; will process 2690 files now Step #5: ==230578== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dbadc709c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dbb42d5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dbb42b85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dbb42b84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dbadc76d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dbadbd7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dbadbd2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dbadc68c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dbb0c37f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dbb0c37f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dbb0c37f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dbb0c37f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dbb0c37f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dbb0c37f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dbb0c37f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dbb0c37f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dbb0c37f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dbb0c37f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dbb2eccf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dbafbf9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dbafc04be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dbaf9b0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dbaf9b0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dbaf9b1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dbaf9b0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dbaf9b0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dbaf9b0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dbb42baabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dbb42c3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dbb42ab699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dbb42d6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb0d0e00082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dbadbd0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-715f6f0d0d15342d99b86ace47e26adaf290867c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6403 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 928413751 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a3299cd810, 0x55a329bb701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a329bb7020,0x55a32ba4f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/715f6f0d0d15342d99b86ace47e26adaf290867c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8340 processed earlier; will process 2689 files now Step #5: #1 pulse cov: 4124 ft: 4125 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 5025 ft: 5419 exec/s: 0 rss: 182Mb Step #5: ==230614== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a3204c29c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a326b27898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a326b0a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a326b0a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a3204c8d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a320429b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a320424355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a3204bac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a323489f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a323489f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a323489f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a323489f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a323489f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a323489f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a323489f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a323489f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a323489f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a323489f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a32571ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a32244bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a322456be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a322202c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a322202c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a322203738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a322202874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a322202874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a322202874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a326b0cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a326b15928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a326afd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a326b28112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4820e8d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a320422b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-078709ab1be5d7626f54c758f4df24e18e3d6d68 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6404 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 929224026 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a327a72810, 0x55a327c5c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a327c5c020,0x55a329af40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/078709ab1be5d7626f54c758f4df24e18e3d6d68' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8343 processed earlier; will process 2686 files now Step #5: #1 pulse cov: 11412 ft: 11413 exec/s: 0 rss: 202Mb Step #5: #2 pulse cov: 11713 ft: 13592 exec/s: 0 rss: 208Mb Step #5: ==230650== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a31e5679c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a324bcc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a324baf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a324baf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a31e56dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a31e4ceb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a31e4c9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a31e55fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a32152ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a32152ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a32152ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a32152ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a32152ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a32152ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a32152ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a32152ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a32152ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a32152ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a3237c3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a3204f0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a3204fbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a3202a7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a3202a7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a3202a8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a3202a7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a3202a7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a3202a7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a324bb1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a324bba928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a324ba2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a324bcd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e2b4c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a31e4c7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-36f672947a3848f4e54ca962f8d6aca99457c6f8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6405 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 930053504 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557804d18810, 0x557804f0201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557804f02020,0x557806d9a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/36f672947a3848f4e54ca962f8d6aca99457c6f8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8346 processed earlier; will process 2683 files now Step #5: #1 pulse cov: 3640 ft: 3641 exec/s: 0 rss: 178Mb Step #5: ==230686== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5577fb80d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557801e72898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557801e555dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557801e554fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5577fb813d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5577fb774b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5577fb76f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5577fb805c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5577fe7d4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5577fe7d4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5577fe7d4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5577fe7d4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5577fe7d4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5577fe7d4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5577fe7d4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5577fe7d4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5577fe7d4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5577fe7d4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557800a69f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5577fd796b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5577fd7a1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5577fd54dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5577fd54dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5577fd54e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5577fd54d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5577fd54d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5577fd54d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557801e57abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557801e60928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557801e48699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557801e73112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac81aa2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5577fb76db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ac280236f95757205462e6b22f1ea7d4c0461035 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6406 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 930804938 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55856895b810, 0x558568b4501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558568b45020,0x55856a9dd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ac280236f95757205462e6b22f1ea7d4c0461035' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8348 processed earlier; will process 2681 files now Step #5: ==230722== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55855f4509c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558565ab5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558565a985dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558565a984fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55855f456d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55855f3b7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55855f3b2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55855f448c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558562417f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558562417f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558562417f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558562417f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558562417f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558562417f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558562417f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558562417f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558562417f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558562417f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5585646acf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5585613d9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5585613e4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558561190c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558561190c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558561191738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558561190874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558561190874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558561190874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558565a9aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558565aa3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558565a8b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558565ab6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f056ff97082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55855f3b0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c81137db025ebcc5376d1a3f0eff879dc884cd0b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6407 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 932208028 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564bf1a76810, 0x564bf1c6001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564bf1c60020,0x564bf3af80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c81137db025ebcc5376d1a3f0eff879dc884cd0b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8349 processed earlier; will process 2680 files now Step #5: #1 pulse cov: 3857 ft: 3858 exec/s: 0 rss: 179Mb Step #5: ==230758== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564be856b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564beebd0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564beebb35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564beebb34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564be8571d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564be84d2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564be84cd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564be8563c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564beb532f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564beb532f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564beb532f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564beb532f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564beb532f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564beb532f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564beb532f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564beb532f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564beb532f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564beb532f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564bed7c7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564bea4f4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564bea4ffbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564bea2abc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564bea2abc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564bea2ac738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564bea2ab874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564bea2ab874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564bea2ab874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564beebb5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564beebbe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564beeba6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564beebd1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f46738d8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564be84cbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-25e7f7aaae0e37d1393dc218e1c22cbda11df3b1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6408 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 932860956 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5596bf234810, 0x5596bf41e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5596bf41e020,0x5596c12b60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/25e7f7aaae0e37d1393dc218e1c22cbda11df3b1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8351 processed earlier; will process 2678 files now Step #5: ==230794== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5596b5d299c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5596bc38e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5596bc3715dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5596bc3714fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5596b5d2fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5596b5c90b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5596b5c8b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5596b5d21c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5596b8cf0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5596b8cf0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5596b8cf0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5596b8cf0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5596b8cf0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5596b8cf0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5596b8cf0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5596b8cf0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5596b8cf0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5596b8cf0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5596baf85f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5596b7cb2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5596b7cbdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5596b7a69c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5596b7a69c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5596b7a6a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5596b7a69874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5596b7a69874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5596b7a69874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5596bc373abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5596bc37c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5596bc364699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5596bc38f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1227226082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5596b5c89b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-847e1f043c8bb8a32251081e17ba7e3d146115ac Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6409 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 934035112 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5651a4bd9810, 0x5651a4dc301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5651a4dc3020,0x5651a6c5b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/847e1f043c8bb8a32251081e17ba7e3d146115ac' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8352 processed earlier; will process 2677 files now Step #5: ==230830== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56519b6ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5651a1d33898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5651a1d165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5651a1d164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56519b6d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56519b635b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56519b630355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56519b6c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56519e695f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56519e695f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56519e695f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56519e695f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56519e695f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56519e695f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56519e695f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56519e695f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56519e695f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56519e695f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5651a092af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56519d657b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56519d662be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56519d40ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56519d40ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56519d40f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56519d40e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56519d40e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56519d40e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5651a1d18abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5651a1d21928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5651a1d09699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5651a1d34112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f12247c8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56519b62eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f43a42d46f0980ed003fc0c89692740e76804a05 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6410 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 935362758 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557b5353f810, 0x557b5372901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557b53729020,0x557b555c10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f43a42d46f0980ed003fc0c89692740e76804a05' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8353 processed earlier; will process 2676 files now Step #5: ==230866== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557b4a0349c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557b50699898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557b5067c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557b5067c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557b4a03ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557b49f9bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557b49f96355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557b4a02cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557b4cffbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557b4cffbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557b4cffbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557b4cffbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557b4cffbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557b4cffbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557b4cffbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557b4cffbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557b4cffbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557b4cffbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557b4f290f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557b4bfbdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557b4bfc8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557b4bd74c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557b4bd74c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557b4bd75738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557b4bd74874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557b4bd74874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557b4bd74874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557b5067eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557b50687928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557b5066f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557b5069a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7face53f7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557b49f94b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d9bc560c04dd1b1d8182c859d25fce2329e3c755 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6411 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 936071213 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5632c5991810, 0x5632c5b7b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5632c5b7b020,0x5632c7a130e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d9bc560c04dd1b1d8182c859d25fce2329e3c755' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8354 processed earlier; will process 2675 files now Step #5: ==230902== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5632bc4869c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5632c2aeb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5632c2ace5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5632c2ace4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5632bc48cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5632bc3edb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5632bc3e8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5632bc47ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5632bf44df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5632bf44df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5632bf44df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5632bf44df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5632bf44df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5632bf44df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5632bf44df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5632bf44df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5632bf44df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5632bf44df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5632c16e2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5632be40fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5632be41abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5632be1c6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5632be1c6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5632be1c7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5632be1c6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5632be1c6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5632be1c6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5632c2ad0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5632c2ad9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5632c2ac1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5632c2aec112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6b0856c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5632bc3e6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a9eb89f87499cc5cd6d66b329234977f2614f0e8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6412 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 936913318 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ec2e12a810, 0x55ec2e31401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ec2e314020,0x55ec301ac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9eb89f87499cc5cd6d66b329234977f2614f0e8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8355 processed earlier; will process 2674 files now Step #5: #1 pulse cov: 3688 ft: 3689 exec/s: 0 rss: 180Mb Step #5: ==230938== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ec24c1f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ec2b284898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ec2b2675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ec2b2674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ec24c25d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ec24b86b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ec24b81355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ec24c17c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ec27be6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ec27be6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ec27be6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ec27be6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ec27be6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ec27be6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ec27be6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ec27be6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ec27be6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ec27be6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ec29e7bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ec26ba8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ec26bb3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ec2695fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ec2695fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ec26960738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ec2695f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ec2695f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ec2695f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ec2b269abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ec2b272928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ec2b25a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ec2b285112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f48ddba4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ec24b7fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-20a2060f2268eceace1ca74b5cd35021022a7200 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6413 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 938286819 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d89da1a810, 0x55d89dc0401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d89dc04020,0x55d89fa9c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/20a2060f2268eceace1ca74b5cd35021022a7200' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8357 processed earlier; will process 2672 files now Step #5: ==230974== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d89450f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d89ab74898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d89ab575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d89ab574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d894515d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d894476b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d894471355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d894507c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d8974d6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d8974d6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d8974d6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d8974d6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d8974d6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d8974d6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d8974d6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d8974d6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d8974d6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d8974d6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d89976bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d896498b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d8964a3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d89624fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d89624fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d896250738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d89624f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d89624f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d89624f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d89ab59abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d89ab62928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d89ab4a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d89ab75112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc97f59c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d89446fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cd7edc857ed9f2c0e3c95233641acc9e9c1e2aed Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6414 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 939088993 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e6de4df810, 0x55e6de6c901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e6de6c9020,0x55e6e05610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd7edc857ed9f2c0e3c95233641acc9e9c1e2aed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8358 processed earlier; will process 2671 files now Step #5: ==231010== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e6d4fd49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e6db639898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e6db61c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e6db61c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e6d4fdad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e6d4f3bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e6d4f36355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e6d4fccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e6d7f9bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e6d7f9bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e6d7f9bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e6d7f9bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e6d7f9bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e6d7f9bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e6d7f9bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e6d7f9bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e6d7f9bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e6d7f9bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e6da230f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e6d6f5db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e6d6f68be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e6d6d14c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e6d6d14c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e6d6d15738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e6d6d14874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e6d6d14874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e6d6d14874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e6db61eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e6db627928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e6db60f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e6db63a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe5b4dec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e6d4f34b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e4b058f0877537ab95a1021947ca127d0f487bf9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6415 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 939729283 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e688871810, 0x55e688a5b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e688a5b020,0x55e68a8f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e4b058f0877537ab95a1021947ca127d0f487bf9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8359 processed earlier; will process 2670 files now Step #5: ==231046== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e67f3669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e6859cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e6859ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e6859ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e67f36cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e67f2cdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e67f2c8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e67f35ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e68232df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e68232df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e68232df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e68232df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e68232df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e68232df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e68232df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e68232df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e68232df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e68232df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e6845c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e6812efb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e6812fabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e6810a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e6810a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e6810a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e6810a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e6810a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e6810a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e6859b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e6859b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e6859a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e6859cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0428cb8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e67f2c6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ccd0f65a4e7995cf4557074ab4d4ec8abc72320d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6416 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 941386707 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5638e57c1810, 0x5638e59ab01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5638e59ab020,0x5638e78430e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ccd0f65a4e7995cf4557074ab4d4ec8abc72320d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8360 processed earlier; will process 2669 files now Step #5: ==231082== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5638dc2b69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5638e291b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5638e28fe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5638e28fe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5638dc2bcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5638dc21db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5638dc218355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5638dc2aec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5638df27df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5638df27df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5638df27df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5638df27df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5638df27df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5638df27df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5638df27df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5638df27df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5638df27df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5638df27df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5638e1512f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5638de23fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5638de24abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5638ddff6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5638ddff6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5638ddff7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5638ddff6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5638ddff6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5638ddff6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5638e2900abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5638e2909928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5638e28f1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5638e291c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcb85579082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5638dc216b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4267ae464781bbe8cbcbbb2ae23543a06f535a54 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6417 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 942189105 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x555d4b3af810, 0x555d4b59901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x555d4b599020,0x555d4d4310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4267ae464781bbe8cbcbbb2ae23543a06f535a54' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8361 processed earlier; will process 2668 files now Step #5: ==231118== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x555d41ea49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x555d48509898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x555d484ec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x555d484ec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555d41eaad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555d41e0bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555d41e06355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555d41e9cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x555d44e6bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x555d44e6bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x555d44e6bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x555d44e6bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x555d44e6bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x555d44e6bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x555d44e6bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x555d44e6bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x555d44e6bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x555d44e6bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555d47100f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555d43e2db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x555d43e38be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555d43be4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555d43be4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555d43be5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555d43be4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555d43be4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555d43be4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x555d484eeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x555d484f7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x555d484df699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x555d4850a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f530d077082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555d41e04b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b5463287b75c8fa05e18af4e625aeb86d3d57f60 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6418 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 944167794 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e6c09de810, 0x55e6c0bc801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e6c0bc8020,0x55e6c2a600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b5463287b75c8fa05e18af4e625aeb86d3d57f60' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8362 processed earlier; will process 2667 files now Step #5: #1 pulse cov: 4180 ft: 4181 exec/s: 0 rss: 181Mb Step #5: ==231154== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e6b74d39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e6bdb38898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e6bdb1b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e6bdb1b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e6b74d9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e6b743ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e6b7435355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e6b74cbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e6ba49af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e6ba49af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e6ba49af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e6ba49af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e6ba49af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e6ba49af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e6ba49af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e6ba49af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e6ba49af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e6ba49af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e6bc72ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e6b945cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e6b9467be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e6b9213c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e6b9213c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e6b9214738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e6b9213874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e6b9213874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e6b9213874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e6bdb1dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e6bdb26928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e6bdb0e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e6bdb39112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fee88806082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e6b7433b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f0c5a8db45c55111e1c526412482ed7e5316f7f0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6419 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 944935329 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e8d41fc810, 0x55e8d43e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e8d43e6020,0x55e8d627e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f0c5a8db45c55111e1c526412482ed7e5316f7f0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8364 processed earlier; will process 2665 files now Step #5: #1 pulse cov: 3929 ft: 3930 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4619 ft: 5003 exec/s: 0 rss: 183Mb Step #5: #4 pulse cov: 14749 ft: 16537 exec/s: 0 rss: 204Mb Step #5: ==231190== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e8cacf19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e8d1356898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e8d13395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e8d13394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e8cacf7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e8cac58b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e8cac53355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e8cace9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e8cdcb8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e8cdcb8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e8cdcb8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e8cdcb8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e8cdcb8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e8cdcb8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e8cdcb8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e8cdcb8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e8cdcb8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e8cdcb8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e8cff4df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e8ccc7ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e8ccc85be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e8cca31c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e8cca31c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e8cca32738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e8cca31874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e8cca31874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e8cca31874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e8d133babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e8d1344928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e8d132c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e8d1357112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1de100d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e8cac51b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1f93408c3176910951f0a8f2126fd3737138161e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6420 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 945843823 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55953c206810, 0x55953c3f001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55953c3f0020,0x55953e2880e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f93408c3176910951f0a8f2126fd3737138161e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8369 processed earlier; will process 2660 files now Step #5: #1 pulse cov: 3940 ft: 3941 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4503 ft: 5096 exec/s: 0 rss: 182Mb Step #5: ==231226== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559532cfb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559539360898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5595393435dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5595393434fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559532d01d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559532c62b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559532c5d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559532cf3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559535cc2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559535cc2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559535cc2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559535cc2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559535cc2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559535cc2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559535cc2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559535cc2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559535cc2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559535cc2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559537f57f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559534c84b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559534c8fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559534a3bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559534a3bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559534a3c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559534a3b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559534a3b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559534a3b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559539345abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55953934e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559539336699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559539361112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2ba3586082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559532c5bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aaab083a359f15e5ef58b1e4192a65e9b0516d7b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6421 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 946659697 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d0d2ab810, 0x557d0d49501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d0d495020,0x557d0f32d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aaab083a359f15e5ef58b1e4192a65e9b0516d7b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8372 processed earlier; will process 2657 files now Step #5: ==231262== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557d03da09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557d0a405898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557d0a3e85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557d0a3e84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557d03da6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557d03d07b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557d03d02355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557d03d98c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557d06d67f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557d06d67f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557d06d67f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557d06d67f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557d06d67f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557d06d67f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557d06d67f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557d06d67f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557d06d67f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557d06d67f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557d08ffcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557d05d29b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557d05d34be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557d05ae0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557d05ae0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557d05ae1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557d05ae0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557d05ae0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557d05ae0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557d0a3eaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557d0a3f3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557d0a3db699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557d0a406112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9beb9fd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557d03d00b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-15b077f50344f69a1640b820996a7b069b9c4e21 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6422 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 947273654 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56019c44b810, 0x56019c63501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56019c635020,0x56019e4cd0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/15b077f50344f69a1640b820996a7b069b9c4e21' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8373 processed earlier; will process 2656 files now Step #5: ==231298== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560192f409c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601995a5898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601995885dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601995884fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560192f46d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560192ea7b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560192ea2355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560192f38c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560195f07f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560195f07f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560195f07f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560195f07f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560195f07f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560195f07f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560195f07f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560195f07f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560195f07f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560195f07f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56019819cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560194ec9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560194ed4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560194c80c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560194c80c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560194c81738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560194c80874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560194c80874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560194c80874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56019958aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560199593928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56019957b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601995a6112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa9e58ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560192ea0b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fb5c75a045626a7d6bac55380caab81dccddbdf0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6423 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 947988437 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e177b2c810, 0x55e177d1601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e177d16020,0x55e179bae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fb5c75a045626a7d6bac55380caab81dccddbdf0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8374 processed earlier; will process 2655 files now Step #5: ==231334== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e16e6219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e174c86898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e174c695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e174c694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e16e627d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e16e588b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e16e583355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e16e619c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e1715e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e1715e8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e1715e8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e1715e8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e1715e8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e1715e8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e1715e8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e1715e8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e1715e8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e1715e8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e17387df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e1705aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e1705b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e170361c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e170361c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e170362738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e170361874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e170361874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e170361874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e174c6babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e174c74928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e174c5c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e174c87112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6484f11082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e16e581b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8ed55c4039e76c84329f5eaa5d69020d71669666 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6424 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 948817730 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56331a180810, 0x56331a36a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56331a36a020,0x56331c2020e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8ed55c4039e76c84329f5eaa5d69020d71669666' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8375 processed earlier; will process 2654 files now Step #5: ==231370== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563310c759c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5633172da898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5633172bd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5633172bd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563310c7bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563310bdcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563310bd7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563310c6dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563313c3cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563313c3cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563313c3cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563313c3cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563313c3cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563313c3cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563313c3cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563313c3cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563313c3cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563313c3cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563315ed1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563312bfeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563312c09be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5633129b5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5633129b5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5633129b6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5633129b5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5633129b5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5633129b5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5633172bfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5633172c8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5633172b0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5633172db112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbb55fe1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563310bd5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-582324fb27f5b5580daf6faf856e6b8cf02ad6c2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6425 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 949421517 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f337a23810, 0x55f337c0d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f337c0d020,0x55f339aa50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/582324fb27f5b5580daf6faf856e6b8cf02ad6c2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8376 processed earlier; will process 2653 files now Step #5: ==231406== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f32e5189c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f334b7d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f334b605dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f334b604fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f32e51ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f32e47fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f32e47a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f32e510c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f3314dff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f3314dff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f3314dff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f3314dff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f3314dff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f3314dff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f3314dff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f3314dff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f3314dff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f3314dff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f333774f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f3304a1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f3304acbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f330258c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f330258c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f330259738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f330258874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f330258874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f330258874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f334b62abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f334b6b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f334b53699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f334b7e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb743def082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f32e478b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8b21e1ef49df9a3eb952c8c8c9d5f3bc9cc5f319 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6426 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 950016926 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5565bf0b1810, 0x5565bf29b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5565bf29b020,0x5565c11330e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8b21e1ef49df9a3eb952c8c8c9d5f3bc9cc5f319' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8377 processed earlier; will process 2652 files now Step #5: ==231442== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5565b5ba69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5565bc20b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5565bc1ee5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5565bc1ee4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5565b5bacd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5565b5b0db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5565b5b08355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5565b5b9ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5565b8b6df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5565b8b6df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5565b8b6df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5565b8b6df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5565b8b6df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5565b8b6df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5565b8b6df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5565b8b6df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5565b8b6df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5565b8b6df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5565bae02f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5565b7b2fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5565b7b3abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5565b78e6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5565b78e6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5565b78e7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5565b78e6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5565b78e6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5565b78e6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5565bc1f0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5565bc1f9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5565bc1e1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5565bc20c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc0f1010082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5565b5b06b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a8178c1a0cf5c65b724798d18e9fd93ec80dd01d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6427 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 950747510 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55eb16bfb810, 0x55eb16de501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55eb16de5020,0x55eb18c7d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a8178c1a0cf5c65b724798d18e9fd93ec80dd01d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8378 processed earlier; will process 2651 files now Step #5: ==231478== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55eb0d6f09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55eb13d55898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55eb13d385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55eb13d384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55eb0d6f6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55eb0d657b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55eb0d652355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55eb0d6e8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55eb106b7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55eb106b7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55eb106b7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55eb106b7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55eb106b7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55eb106b7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55eb106b7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55eb106b7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55eb106b7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55eb106b7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55eb1294cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55eb0f679b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55eb0f684be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55eb0f430c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55eb0f430c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55eb0f431738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55eb0f430874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55eb0f430874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55eb0f430874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55eb13d3aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55eb13d43928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55eb13d2b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55eb13d56112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f415ece7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55eb0d650b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-08f25dc6f12d668d72c662c9ff46934da832cdbc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6428 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 952769775 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a804932810, 0x55a804b1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a804b1c020,0x55a8069b40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08f25dc6f12d668d72c662c9ff46934da832cdbc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8379 processed earlier; will process 2650 files now Step #5: #1 pulse cov: 4379 ft: 4380 exec/s: 0 rss: 179Mb Step #5: ==231514== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a7fb4279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a801a8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a801a6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a801a6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a7fb42dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a7fb38eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a7fb389355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a7fb41fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a7fe3eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a7fe3eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a7fe3eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a7fe3eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a7fe3eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a7fe3eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a7fe3eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a7fe3eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a7fe3eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a7fe3eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a800683f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a7fd3b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a7fd3bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a7fd167c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a7fd167c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a7fd168738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a7fd167874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a7fd167874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a7fd167874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a801a71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a801a7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a801a62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a801a8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f10b2a80082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a7fb387b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-15cafdd7b713dc45deafe53b59ab56e57b406c90 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6429 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 953682199 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558909b60810, 0x558909d4a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558909d4a020,0x55890bbe20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/15cafdd7b713dc45deafe53b59ab56e57b406c90' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8381 processed earlier; will process 2648 files now Step #5: ==231550== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5589006559c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558906cba898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558906c9d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558906c9d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55890065bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5589005bcb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5589005b7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55890064dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55890361cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55890361cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55890361cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55890361cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55890361cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55890361cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55890361cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55890361cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55890361cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55890361cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5589058b1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5589025deb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5589025e9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558902395c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558902395c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558902396738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558902395874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558902395874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558902395874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558906c9fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558906ca8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558906c90699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558906cbb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fea1e5da082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5589005b5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a55ce694690cc6609b2f4070ecd9add608c93562 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6430 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 955713164 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5593152c3810, 0x5593154ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5593154ad020,0x5593173450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a55ce694690cc6609b2f4070ecd9add608c93562' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8382 processed earlier; will process 2647 files now Step #5: ==231586== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55930bdb89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55931241d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5593124005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5593124004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55930bdbed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55930bd1fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55930bd1a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55930bdb0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55930ed7ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55930ed7ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55930ed7ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55930ed7ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55930ed7ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55930ed7ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55930ed7ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55930ed7ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55930ed7ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55930ed7ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559311014f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55930dd41b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55930dd4cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55930daf8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55930daf8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55930daf9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55930daf8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55930daf8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55930daf8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559312402abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55931240b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5593123f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55931241e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc5a0290082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55930bd18b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7e4f741cd53a2f128fa97fc069b27dc5c29ab661 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6431 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 956308893 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c3d0793810, 0x55c3d097d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c3d097d020,0x55c3d28150e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7e4f741cd53a2f128fa97fc069b27dc5c29ab661' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8383 processed earlier; will process 2646 files now Step #5: ==231622== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c3c72889c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c3cd8ed898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c3cd8d05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c3cd8d04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c3c728ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c3c71efb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c3c71ea355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c3c7280c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c3ca24ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c3ca24ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c3ca24ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c3ca24ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c3ca24ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c3ca24ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c3ca24ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c3ca24ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c3ca24ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c3ca24ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c3cc4e4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c3c9211b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c3c921cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c3c8fc8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c3c8fc8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c3c8fc9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c3c8fc8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c3c8fc8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c3c8fc8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c3cd8d2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c3cd8db928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c3cd8c3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c3cd8ee112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9d65897082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c3c71e8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8021d2b7f9e3f8da8a61956b4a9899cc7148c39d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6432 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 956981573 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5572161ea810, 0x5572163d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5572163d4020,0x55721826c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8021d2b7f9e3f8da8a61956b4a9899cc7148c39d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8384 processed earlier; will process 2645 files now Step #5: ==231658== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55720ccdf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557213344898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5572133275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5572133274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55720cce5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55720cc46b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55720cc41355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55720ccd7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55720fca6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55720fca6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55720fca6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55720fca6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55720fca6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55720fca6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55720fca6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55720fca6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55720fca6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55720fca6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557211f3bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55720ec68b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55720ec73be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55720ea1fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55720ea1fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55720ea20738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55720ea1f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55720ea1f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55720ea1f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557213329abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557213332928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55721331a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557213345112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7efede53c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55720cc3fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ca5386abdfe55e1927f11684bebb3bdab64fad4c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6433 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 957709411 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557d016b6810, 0x557d018a001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557d018a0020,0x557d037380e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ca5386abdfe55e1927f11684bebb3bdab64fad4c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8385 processed earlier; will process 2644 files now Step #5: #1 pulse cov: 4310 ft: 4311 exec/s: 0 rss: 180Mb Step #5: ==231694== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557cf81ab9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557cfe810898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557cfe7f35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557cfe7f34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557cf81b1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557cf8112b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557cf810d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557cf81a3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557cfb172f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557cfb172f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557cfb172f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557cfb172f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557cfb172f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557cfb172f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557cfb172f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557cfb172f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557cfb172f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557cfb172f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557cfd407f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557cfa134b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557cfa13fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557cf9eebc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557cf9eebc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557cf9eec738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557cf9eeb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557cf9eeb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557cf9eeb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557cfe7f5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557cfe7fe928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557cfe7e6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557cfe811112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5a233e4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557cf810bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7ee58e53d3f29bb6072a7993e10a8eb0e170402e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6434 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 959472810 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f160b7e810, 0x55f160d6801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f160d68020,0x55f162c000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7ee58e53d3f29bb6072a7993e10a8eb0e170402e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8387 processed earlier; will process 2642 files now Step #5: ==231730== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f1576739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f15dcd8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f15dcbb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f15dcbb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f157679d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f1575dab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f1575d5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f15766bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f15a63af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f15a63af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f15a63af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f15a63af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f15a63af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f15a63af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f15a63af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f15a63af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f15a63af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f15a63af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f15c8cff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f1595fcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f159607be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f1593b3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f1593b3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f1593b4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f1593b3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f1593b3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f1593b3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f15dcbdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f15dcc6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f15dcae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f15dcd9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7bff7f0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f1575d3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-515832c23893620f8f80d5092396757c2c0c7880 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6435 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 960174108 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cb4b694810, 0x55cb4b87e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cb4b87e020,0x55cb4d7160e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/515832c23893620f8f80d5092396757c2c0c7880' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8388 processed earlier; will process 2641 files now Step #5: ==231766== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cb421899c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cb487ee898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cb487d15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cb487d14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cb4218fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cb420f0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cb420eb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cb42181c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cb45150f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cb45150f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cb45150f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cb45150f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cb45150f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cb45150f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cb45150f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cb45150f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cb45150f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cb45150f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cb473e5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cb44112b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cb4411dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cb43ec9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cb43ec9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cb43eca738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cb43ec9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cb43ec9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cb43ec9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cb487d3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cb487dc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cb487c4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cb487ef112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc3be20c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cb420e9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c313e46e5fd65f7124c87d933e747d496d3228d0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6436 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 960737202 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e18cbee810, 0x55e18cdd801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e18cdd8020,0x55e18ec700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c313e46e5fd65f7124c87d933e747d496d3228d0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8389 processed earlier; will process 2640 files now Step #5: ==231802== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e1836e39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e189d48898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e189d2b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e189d2b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e1836e9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e18364ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e183645355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e1836dbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e1866aaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e1866aaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e1866aaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e1866aaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e1866aaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e1866aaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e1866aaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e1866aaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e1866aaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e1866aaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e18893ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e18566cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e185677be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e185423c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e185423c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e185424738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e185423874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e185423874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e185423874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e189d2dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e189d36928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e189d1e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e189d49112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa7c013c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e183643b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a9d0a9a0cf1b0fdd55c1c0a9689680b50351588a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6437 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 961454435 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ac8306d810, 0x55ac8325701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ac83257020,0x55ac850ef0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a9d0a9a0cf1b0fdd55c1c0a9689680b50351588a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8390 processed earlier; will process 2639 files now Step #5: ==231838== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ac79b629c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ac801c7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ac801aa5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ac801aa4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ac79b68d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ac79ac9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ac79ac4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ac79b5ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ac7cb29f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ac7cb29f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ac7cb29f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ac7cb29f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ac7cb29f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ac7cb29f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ac7cb29f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ac7cb29f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ac7cb29f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ac7cb29f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ac7edbef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ac7baebb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ac7baf6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ac7b8a2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ac7b8a2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ac7b8a3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ac7b8a2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ac7b8a2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ac7b8a2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ac801acabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ac801b5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ac8019d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ac801c8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2daaf93082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ac79ac2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c3d23b24349d5303bc2d30819a8d91dea8b68e81 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6438 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 962073479 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561738a26810, 0x561738c1001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561738c10020,0x56173aaa80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c3d23b24349d5303bc2d30819a8d91dea8b68e81' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8391 processed earlier; will process 2638 files now Step #5: ==231874== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56172f51b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561735b80898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561735b635dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561735b634fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56172f521d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56172f482b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56172f47d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56172f513c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5617324e2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5617324e2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5617324e2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5617324e2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5617324e2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5617324e2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5617324e2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5617324e2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5617324e2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5617324e2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561734777f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5617314a4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5617314afbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56173125bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56173125bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56173125c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56173125b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56173125b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56173125b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561735b65abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561735b6e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561735b56699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561735b81112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f710ec78082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56172f47bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9385a5314948823a28b894fbb6acd86a2ee32ade Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6439 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 962777468 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562d61b0e810, 0x562d61cf801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562d61cf8020,0x562d63b900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9385a5314948823a28b894fbb6acd86a2ee32ade' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8392 processed earlier; will process 2637 files now Step #5: ==231910== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562d586039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562d5ec68898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562d5ec4b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562d5ec4b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562d58609d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562d5856ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562d58565355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562d585fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562d5b5caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562d5b5caf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562d5b5caf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562d5b5caf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562d5b5caf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562d5b5caf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562d5b5caf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562d5b5caf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562d5b5caf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562d5b5caf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562d5d85ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562d5a58cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562d5a597be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562d5a343c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562d5a343c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562d5a344738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562d5a343874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562d5a343874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562d5a343874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562d5ec4dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562d5ec56928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562d5ec3e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562d5ec69112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f275221a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562d58563b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fabf58c1bca97bf4efd9a2276d0900c8bebb6d6a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6440 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 963386111 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b1b377c810, 0x55b1b396601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b1b3966020,0x55b1b57fe0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fabf58c1bca97bf4efd9a2276d0900c8bebb6d6a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8393 processed earlier; will process 2636 files now Step #5: ==231946== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b1aa2719c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b1b08d6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b1b08b95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b1b08b94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b1aa277d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b1aa1d8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b1aa1d3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b1aa269c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b1ad238f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b1ad238f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b1ad238f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b1ad238f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b1ad238f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b1ad238f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b1ad238f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b1ad238f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b1ad238f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b1ad238f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b1af4cdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b1ac1fab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b1ac205be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b1abfb1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b1abfb1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b1abfb2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b1abfb1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b1abfb1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b1abfb1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b1b08bbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b1b08c4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b1b08ac699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b1b08d7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd6da8e8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b1aa1d1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-aa81d53efc9e4e98a16a714fe8411af952540d17 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6441 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 963972961 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557ebf4f5810, 0x557ebf6df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557ebf6df020,0x557ec15770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/aa81d53efc9e4e98a16a714fe8411af952540d17' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8394 processed earlier; will process 2635 files now Step #5: ==231982== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557eb5fea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557ebc64f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557ebc6325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557ebc6324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557eb5ff0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557eb5f51b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557eb5f4c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557eb5fe2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557eb8fb1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557eb8fb1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557eb8fb1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557eb8fb1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557eb8fb1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557eb8fb1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557eb8fb1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557eb8fb1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557eb8fb1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557eb8fb1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557ebb246f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557eb7f73b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557eb7f7ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557eb7d2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557eb7d2ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557eb7d2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557eb7d2a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557eb7d2a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557eb7d2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557ebc634abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557ebc63d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557ebc625699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557ebc650112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7feaab498082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557eb5f4ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ffed3894752326f754f6d18b1369e26847eca7f2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6442 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 964576856 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5613eb62a810, 0x5613eb81401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5613eb814020,0x5613ed6ac0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ffed3894752326f754f6d18b1369e26847eca7f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8395 processed earlier; will process 2634 files now Step #5: #1 pulse cov: 4071 ft: 4072 exec/s: 0 rss: 181Mb Step #5: ==232018== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5613e211f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5613e8784898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5613e87675dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5613e87674fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5613e2125d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5613e2086b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5613e2081355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5613e2117c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5613e50e6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5613e50e6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5613e50e6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5613e50e6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5613e50e6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5613e50e6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5613e50e6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5613e50e6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5613e50e6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5613e50e6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5613e737bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5613e40a8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5613e40b3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5613e3e5fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5613e3e5fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5613e3e60738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5613e3e5f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5613e3e5f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5613e3e5f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5613e8769abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5613e8772928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5613e875a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5613e8785112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c239bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5613e207fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-56e3aaec9af968da8389724b9963ff062f41a248 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6443 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 966556552 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565044c92810, 0x565044e7c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565044e7c020,0x565046d140e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56e3aaec9af968da8389724b9963ff062f41a248' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8397 processed earlier; will process 2632 files now Step #5: ==232054== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56503b7879c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x565041dec898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x565041dcf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x565041dcf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56503b78dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56503b6eeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56503b6e9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56503b77fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56503e74ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56503e74ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56503e74ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56503e74ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56503e74ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56503e74ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56503e74ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56503e74ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56503e74ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56503e74ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5650409e3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56503d710b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56503d71bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56503d4c7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56503d4c7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56503d4c8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56503d4c7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56503d4c7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56503d4c7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x565041dd1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x565041dda928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x565041dc2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x565041ded112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faf78889082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56503b6e7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-018432a58ab14f04d3cd01425f38f636732256f6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6444 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 968526331 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a29c0c4810, 0x55a29c2ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a29c2ae020,0x55a29e1460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/018432a58ab14f04d3cd01425f38f636732256f6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8398 processed earlier; will process 2631 files now Step #5: ==232090== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a292bb99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a29921e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a2992015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a2992014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a292bbfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a292b20b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a292b1b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a292bb1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a295b80f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a295b80f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a295b80f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a295b80f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a295b80f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a295b80f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a295b80f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a295b80f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a295b80f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a295b80f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a297e15f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a294b42b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a294b4dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a2948f9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a2948f9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a2948fa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a2948f9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a2948f9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a2948f9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a299203abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a29920c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a2991f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a29921f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f77cdb0f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a292b19b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ed6d9d9f567c101d2057204f508624d23a217051 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6445 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 969094344 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bce2d32810, 0x55bce2f1c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bce2f1c020,0x55bce4db40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ed6d9d9f567c101d2057204f508624d23a217051' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8399 processed earlier; will process 2630 files now Step #5: #1 pulse cov: 3925 ft: 3926 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 3962 ft: 4003 exec/s: 0 rss: 179Mb Step #5: ==232126== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bcd98279c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bcdfe8c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bcdfe6f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bcdfe6f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bcd982dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bcd978eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bcd9789355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bcd981fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bcdc7eef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bcdc7eef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bcdc7eef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bcdc7eef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bcdc7eef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bcdc7eef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bcdc7eef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bcdc7eef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bcdc7eef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bcdc7eef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bcdea83f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bcdb7b0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bcdb7bbbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bcdb567c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bcdb567c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bcdb568738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bcdb567874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bcdb567874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bcdb567874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bcdfe71abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bcdfe7a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bcdfe62699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bcdfe8d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f94334de082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bcd9787b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2b7e0192ec8d4f38bcf476d45acea63f6772e4e3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6446 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 969779707 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5599d914f810, 0x5599d933901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5599d9339020,0x5599db1d10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2b7e0192ec8d4f38bcf476d45acea63f6772e4e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8403 processed earlier; will process 2626 files now Step #5: ==232162== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5599cfc449c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5599d62a9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5599d628c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5599d628c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5599cfc4ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5599cfbabb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5599cfba6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5599cfc3cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5599d2c0bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5599d2c0bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5599d2c0bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5599d2c0bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5599d2c0bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5599d2c0bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5599d2c0bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5599d2c0bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5599d2c0bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5599d2c0bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5599d4ea0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5599d1bcdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5599d1bd8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5599d1984c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5599d1984c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5599d1985738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5599d1984874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5599d1984874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5599d1984874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5599d628eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5599d6297928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5599d627f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5599d62aa112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2b41c89082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5599cfba4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5e9f7e108d7fcd5203ab7666f8851c0c2e851cb0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6447 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 971708227 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e854104810, 0x55e8542ee01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e8542ee020,0x55e8561860e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e9f7e108d7fcd5203ab7666f8851c0c2e851cb0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8404 processed earlier; will process 2625 files now Step #5: ==232198== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e84abf99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e85125e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e8512415dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e8512414fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e84abffd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e84ab60b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e84ab5b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e84abf1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e84dbc0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e84dbc0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e84dbc0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e84dbc0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e84dbc0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e84dbc0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e84dbc0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e84dbc0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e84dbc0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e84dbc0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e84fe55f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e84cb82b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e84cb8dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e84c939c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e84c939c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e84c93a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e84c939874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e84c939874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e84c939874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e851243abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e85124c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e851234699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e85125f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3d06aa9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e84ab59b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f9cee3bac5e1b9f60df83c33ca6c9309562f85a2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6448 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 973675586 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ddb18fa810, 0x55ddb1ae401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ddb1ae4020,0x55ddb397c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9cee3bac5e1b9f60df83c33ca6c9309562f85a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8405 processed earlier; will process 2624 files now Step #5: ==232234== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dda83ef9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ddaea54898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ddaea375dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ddaea374fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dda83f5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dda8356b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dda8351355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dda83e7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ddab3b6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ddab3b6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ddab3b6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ddab3b6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ddab3b6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ddab3b6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ddab3b6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ddab3b6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ddab3b6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ddab3b6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ddad64bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ddaa378b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ddaa383be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ddaa12fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ddaa12fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ddaa130738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ddaa12f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ddaa12f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ddaa12f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ddaea39abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ddaea42928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ddaea2a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ddaea55112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7da37fb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dda834fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-dfc9fa568302ba03c94674e4f7d53d0eebdabaa0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6449 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 974365375 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56157c6c6810, 0x56157c8b001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56157c8b0020,0x56157e7480e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/dfc9fa568302ba03c94674e4f7d53d0eebdabaa0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8406 processed earlier; will process 2623 files now Step #5: ==232270== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5615731bb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561579820898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5615798035dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5615798034fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5615731c1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561573122b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56157311d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5615731b3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561576182f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561576182f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561576182f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561576182f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561576182f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561576182f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561576182f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561576182f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561576182f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561576182f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561578417f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561575144b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56157514fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561574efbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561574efbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561574efc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561574efb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561574efb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561574efb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561579805abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56157980e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5615797f6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561579821112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff3a003b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56157311bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-768de2e373c005f1dd5a03f13d1a288eaf6b04cc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6450 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 976328481 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558ead0af810, 0x558ead29901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558ead299020,0x558eaf1310e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/768de2e373c005f1dd5a03f13d1a288eaf6b04cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8407 processed earlier; will process 2622 files now Step #5: ==232306== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558ea3ba49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558eaa209898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558eaa1ec5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558eaa1ec4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558ea3baad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558ea3b0bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558ea3b06355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558ea3b9cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558ea6b6bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558ea6b6bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558ea6b6bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558ea6b6bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558ea6b6bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558ea6b6bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558ea6b6bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558ea6b6bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558ea6b6bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558ea6b6bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558ea8e00f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558ea5b2db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558ea5b38be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558ea58e4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558ea58e4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558ea58e5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558ea58e4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558ea58e4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558ea58e4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558eaa1eeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558eaa1f7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558eaa1df699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558eaa20a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb16c8e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558ea3b04b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bcc44329561332f46cc56c91277ff8b34b34b900 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6451 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 976930053 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ac81c3e810, 0x55ac81e2801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ac81e28020,0x55ac83cc00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bcc44329561332f46cc56c91277ff8b34b34b900' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8408 processed earlier; will process 2621 files now Step #5: #1 pulse cov: 11325 ft: 11326 exec/s: 0 rss: 199Mb Step #5: #2 pulse cov: 12410 ft: 13239 exec/s: 0 rss: 202Mb Step #5: #4 pulse cov: 12659 ft: 16896 exec/s: 0 rss: 205Mb Step #5: ==232342== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ac787339c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ac7ed98898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ac7ed7b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ac7ed7b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ac78739d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ac7869ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ac78695355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ac7872bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ac7b6faf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ac7b6faf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ac7b6faf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ac7b6faf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ac7b6faf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ac7b6faf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ac7b6faf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ac7b6faf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ac7b6faf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ac7b6faf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ac7d98ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ac7a6bcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ac7a6c7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ac7a473c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ac7a473c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ac7a474738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ac7a473874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ac7a473874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ac7a473874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ac7ed7dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ac7ed86928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ac7ed6e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ac7ed99112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f365addc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ac78693b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8334c30a0bf504ab1c57cbeaea6618452c202b22 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6452 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 979141982 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55686b9b8810, 0x55686bba201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55686bba2020,0x55686da3a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8334c30a0bf504ab1c57cbeaea6618452c202b22' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8413 processed earlier; will process 2616 files now Step #5: ==232378== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5568624ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556868b12898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556868af55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556868af54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5568624b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556862414b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55686240f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5568624a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556865474f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556865474f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556865474f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556865474f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556865474f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556865474f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556865474f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556865474f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556865474f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556865474f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556867709f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556864436b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556864441be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5568641edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5568641edc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5568641ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5568641ed874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5568641ed874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5568641ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556868af7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556868b00928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556868ae8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556868b13112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6fd2153082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55686240db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8a2c0c549eeae34936efb44d3a4a6c148df7b7e3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6453 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 980585706 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5556d3d02810, 0x5556d3eec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5556d3eec020,0x5556d5d840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8a2c0c549eeae34936efb44d3a4a6c148df7b7e3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8414 processed earlier; will process 2615 files now Step #5: #1 pulse cov: 3568 ft: 3569 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4673 ft: 5181 exec/s: 0 rss: 182Mb Step #5: ==232414== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5556ca7f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5556d0e5c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556d0e3f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556d0e3f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5556ca7fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5556ca75eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5556ca759355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5556ca7efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5556cd7bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5556cd7bef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5556cd7bef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5556cd7bef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5556cd7bef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5556cd7bef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5556cd7bef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5556cd7bef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5556cd7bef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5556cd7bef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5556cfa53f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5556cc780b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5556cc78bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5556cc537c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5556cc537c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5556cc538738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5556cc537874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5556cc537874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5556cc537874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5556d0e41abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5556d0e4a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5556d0e32699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5556d0e5d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd799359082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5556ca757b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-40c8309e87532aec866603703e0f959caa5931cc Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6454 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 982151028 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5636320e9810, 0x5636322d301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5636322d3020,0x56363416b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40c8309e87532aec866603703e0f959caa5931cc' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8417 processed earlier; will process 2612 files now Step #5: ==232450== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563628bde9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56362f243898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56362f2265dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56362f2264fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563628be4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563628b45b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563628b40355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563628bd6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56362bba5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56362bba5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56362bba5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56362bba5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56362bba5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56362bba5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56362bba5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56362bba5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56362bba5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56362bba5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56362de3af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56362ab67b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56362ab72be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56362a91ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56362a91ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56362a91f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56362a91e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56362a91e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56362a91e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56362f228abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56362f231928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56362f219699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56362f244112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc574b86082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563628b3eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-40e114283cfce397a58a2d3f4e5cf3a8d6d98234 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6455 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 982850348 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5610ca603810, 0x5610ca7ed01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5610ca7ed020,0x5610cc6850e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/40e114283cfce397a58a2d3f4e5cf3a8d6d98234' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8418 processed earlier; will process 2611 files now Step #5: ==232486== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5610c10f89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5610c775d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5610c77405dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5610c77404fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610c10fed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5610c105fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5610c105a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610c10f0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5610c40bff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5610c40bff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5610c40bff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5610c40bff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5610c40bff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5610c40bff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5610c40bff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5610c40bff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5610c40bff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5610c40bff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5610c6354f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5610c3081b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5610c308cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5610c2e38c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5610c2e38c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5610c2e39738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5610c2e38874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5610c2e38874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5610c2e38874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5610c7742abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5610c774b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5610c7733699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5610c775e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcce43f9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5610c1058b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ce66974f414f94ec74f3ed7b85c34803bcff60ae Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6456 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 983439427 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55585dc2c810, 0x55585de1601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55585de16020,0x55585fcae0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ce66974f414f94ec74f3ed7b85c34803bcff60ae' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8419 processed earlier; will process 2610 files now Step #5: ==232522== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5558547219c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55585ad86898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55585ad695dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55585ad694fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x555854727d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x555854688b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x555854683355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x555854719c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5558576e8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5558576e8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5558576e8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5558576e8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5558576e8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5558576e8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5558576e8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5558576e8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5558576e8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5558576e8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55585997df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5558566aab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5558566b5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555856461c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555856461c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555856462738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555856461874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555856461874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555856461874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55585ad6babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55585ad74928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55585ad5c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55585ad87112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3473b58082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555854681b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-abba42bbad223f8396bdfe9b8293447760bb4dcd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6457 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 984832920 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5564e86b7810, 0x5564e88a101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5564e88a1020,0x5564ea7390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/abba42bbad223f8396bdfe9b8293447760bb4dcd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8420 processed earlier; will process 2609 files now Step #5: ==232558== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5564df1ac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5564e5811898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5564e57f45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5564e57f44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5564df1b2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5564df113b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5564df10e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5564df1a4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5564e2173f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5564e2173f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5564e2173f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5564e2173f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5564e2173f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5564e2173f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5564e2173f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5564e2173f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5564e2173f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5564e2173f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5564e4408f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5564e1135b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5564e1140be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5564e0eecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5564e0eecc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5564e0eed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5564e0eec874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5564e0eec874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5564e0eec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5564e57f6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5564e57ff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5564e57e7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5564e5812112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8d142af082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5564df10cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-642ce1f3959c696cb0d7a71862220b770cf75881 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6458 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 985399882 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ffb1288810, 0x55ffb147201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ffb1472020,0x55ffb330a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/642ce1f3959c696cb0d7a71862220b770cf75881' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8421 processed earlier; will process 2608 files now Step #5: #1 pulse cov: 4588 ft: 4589 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4730 ft: 5280 exec/s: 0 rss: 181Mb Step #5: ==232594== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ffa7d7d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ffae3e2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ffae3c55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ffae3c54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ffa7d83d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ffa7ce4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ffa7cdf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ffa7d75c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ffaad44f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ffaad44f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ffaad44f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ffaad44f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ffaad44f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ffaad44f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ffaad44f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ffaad44f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ffaad44f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ffaad44f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ffacfd9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ffa9d06b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ffa9d11be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ffa9abdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ffa9abdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ffa9abe738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ffa9abd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ffa9abd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ffa9abd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ffae3c7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ffae3d0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ffae3b8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ffae3e3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6928d39082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ffa7cddb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5b43e475a32cbf1fdc82dbc39184d4beb01efe3f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6459 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 986086686 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561cf13f3810, 0x561cf15dd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561cf15dd020,0x561cf34750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5b43e475a32cbf1fdc82dbc39184d4beb01efe3f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8424 processed earlier; will process 2605 files now Step #5: ==232630== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561ce7ee89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561cee54d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561cee5305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561cee5304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561ce7eeed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561ce7e4fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561ce7e4a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561ce7ee0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561ceaeaff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561ceaeaff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561ceaeaff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561ceaeaff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561ceaeaff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561ceaeaff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561ceaeaff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561ceaeaff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561ceaeaff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561ceaeaff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561ced144f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561ce9e71b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561ce9e7cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561ce9c28c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561ce9c28c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561ce9c29738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561ce9c28874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561ce9c28874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561ce9c28874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561cee532abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561cee53b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561cee523699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561cee54e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fac4b07d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561ce7e48b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-27f68eccec5e6bbb22096d72c36aec9cda1e32f3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6460 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 986783878 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556a241ea810, 0x556a243d401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556a243d4020,0x556a2626c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/27f68eccec5e6bbb22096d72c36aec9cda1e32f3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8425 processed earlier; will process 2604 files now Step #5: ==232666== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556a1acdf9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556a21344898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556a213275dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556a213274fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556a1ace5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556a1ac46b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556a1ac41355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556a1acd7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556a1dca6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556a1dca6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556a1dca6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556a1dca6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556a1dca6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556a1dca6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556a1dca6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556a1dca6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556a1dca6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556a1dca6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556a1ff3bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556a1cc68b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556a1cc73be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556a1ca1fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556a1ca1fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556a1ca20738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556a1ca1f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556a1ca1f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556a1ca1f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556a21329abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556a21332928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556a2131a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556a21345112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6d6e203082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556a1ac3fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cd13f9dc44bbe9eb5f8ba54abd2d44721e65635b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6461 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 987480833 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e259686810, 0x55e25987001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e259870020,0x55e25b7080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cd13f9dc44bbe9eb5f8ba54abd2d44721e65635b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8426 processed earlier; will process 2603 files now Step #5: #1 pulse cov: 4222 ft: 4223 exec/s: 0 rss: 181Mb Step #5: ==232702== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e25017b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e2567e0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e2567c35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e2567c34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e250181d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e2500e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e2500dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e250173c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e253142f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e253142f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e253142f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e253142f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e253142f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e253142f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e253142f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e253142f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e253142f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e253142f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e2553d7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e252104b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e25210fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e251ebbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e251ebbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e251ebc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e251ebb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e251ebb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e251ebb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e2567c5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e2567ce928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e2567b6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e2567e1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1200fd5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e2500dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b2d4d1fc197138d21d1c09c5490d085d43bc364b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6462 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 988116249 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f5c1055810, 0x55f5c123f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f5c123f020,0x55f5c30d70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b2d4d1fc197138d21d1c09c5490d085d43bc364b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8428 processed earlier; will process 2601 files now Step #5: ==232738== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f5b7b4a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f5be1af898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f5be1925dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f5be1924fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f5b7b50d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f5b7ab1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f5b7aac355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f5b7b42c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f5bab11f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f5bab11f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f5bab11f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f5bab11f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f5bab11f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f5bab11f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f5bab11f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f5bab11f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f5bab11f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f5bab11f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f5bcda6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f5b9ad3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f5b9adebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f5b988ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f5b988ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f5b988b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f5b988a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f5b988a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f5b988a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f5be194abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f5be19d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f5be185699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f5be1b0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8fea82b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f5b7aaab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ba92b89b58d1c6d39992e7255babdf5071fc7043 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6463 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 988807047 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55faef31f810, 0x55faef50901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55faef509020,0x55faf13a10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba92b89b58d1c6d39992e7255babdf5071fc7043' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8429 processed earlier; will process 2600 files now Step #5: ==232774== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fae5e149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55faec479898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55faec45c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55faec45c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fae5e1ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fae5d7bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fae5d76355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fae5e0cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fae8ddbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fae8ddbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fae8ddbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fae8ddbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fae8ddbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fae8ddbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fae8ddbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fae8ddbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fae8ddbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fae8ddbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55faeb070f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fae7d9db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fae7da8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fae7b54c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fae7b54c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fae7b55738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fae7b54874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fae7b54874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fae7b54874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55faec45eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55faec467928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55faec44f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55faec47a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa15603c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fae5d74b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2730ebbc6c4fe3d36c4195ebe34be7a5009a0f93 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6464 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 990789250 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55aacd1f5810, 0x55aacd3df01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55aacd3df020,0x55aacf2770e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2730ebbc6c4fe3d36c4195ebe34be7a5009a0f93' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8430 processed earlier; will process 2599 files now Step #5: ==232810== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55aac3cea9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55aaca34f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55aaca3325dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55aaca3324fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55aac3cf0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55aac3c51b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55aac3c4c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55aac3ce2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55aac6cb1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55aac6cb1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55aac6cb1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55aac6cb1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55aac6cb1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55aac6cb1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55aac6cb1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55aac6cb1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55aac6cb1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55aac6cb1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55aac8f46f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55aac5c73b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55aac5c7ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55aac5a2ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55aac5a2ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55aac5a2b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55aac5a2a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55aac5a2a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55aac5a2a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55aaca334abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55aaca33d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55aaca325699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55aaca350112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f30c60cf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55aac3c4ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0acbb4eef974d95937515805c6ab5c956cc45d5a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6465 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 991512795 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55feafe8c810, 0x55feb007601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55feb0076020,0x55feb1f0e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0acbb4eef974d95937515805c6ab5c956cc45d5a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8431 processed earlier; will process 2598 files now Step #5: ==232846== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fea69819c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55feacfe6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55feacfc95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55feacfc94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fea6987d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fea68e8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fea68e3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fea6979c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fea9948f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fea9948f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fea9948f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fea9948f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fea9948f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fea9948f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fea9948f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fea9948f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fea9948f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fea9948f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55feabbddf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fea890ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fea8915be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fea86c1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fea86c1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fea86c2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fea86c1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fea86c1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fea86c1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55feacfcbabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55feacfd4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55feacfbc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55feacfe7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3963531082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fea68e1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e418329426803adbf85e05892b9f05e0ccf4f12b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6466 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 992113053 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e029bbb810, 0x55e029da501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e029da5020,0x55e02bc3d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e418329426803adbf85e05892b9f05e0ccf4f12b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8432 processed earlier; will process 2597 files now Step #5: ==232882== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e0206b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e026d15898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e026cf85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e026cf84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e0206b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e020617b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e020612355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e0206a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e023677f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e023677f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e023677f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e023677f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e023677f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e023677f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e023677f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e023677f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e023677f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e023677f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e02590cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e022639b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e022644be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e0223f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e0223f0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e0223f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e0223f0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e0223f0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e0223f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e026cfaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e026d03928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e026ceb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e026d16112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fecefd20082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e020610b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-29865e1fe6cdd68155562b6a7def7ef92a88189b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6467 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 992690320 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562df1319810, 0x562df150301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562df1503020,0x562df339b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/29865e1fe6cdd68155562b6a7def7ef92a88189b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8433 processed earlier; will process 2596 files now Step #5: #1 pulse cov: 4409 ft: 4410 exec/s: 0 rss: 180Mb Step #5: ==232918== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562de7e0e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562dee473898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562dee4565dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562dee4564fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562de7e14d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562de7d75b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562de7d70355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562de7e06c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562deadd5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562deadd5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562deadd5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562deadd5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562deadd5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562deadd5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562deadd5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562deadd5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562deadd5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562deadd5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562ded06af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562de9d97b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562de9da2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562de9b4ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562de9b4ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562de9b4f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562de9b4e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562de9b4e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562de9b4e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562dee458abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562dee461928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562dee449699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562dee474112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0ebd585082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562de7d6eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c74ddf5d1df0a76fb7689f8ff6aff1aeb0d1d414 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6468 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 993462595 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556e7e25f810, 0x556e7e44901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556e7e449020,0x556e802e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c74ddf5d1df0a76fb7689f8ff6aff1aeb0d1d414' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8435 processed earlier; will process 2594 files now Step #5: #1 pulse cov: 3532 ft: 3533 exec/s: 0 rss: 180Mb Step #5: ==232954== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556e74d549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556e7b3b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556e7b39c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556e7b39c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556e74d5ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556e74cbbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556e74cb6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556e74d4cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556e77d1bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556e77d1bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556e77d1bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556e77d1bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556e77d1bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556e77d1bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556e77d1bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556e77d1bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556e77d1bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556e77d1bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556e79fb0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556e76cddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556e76ce8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556e76a94c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556e76a94c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556e76a95738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556e76a94874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556e76a94874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556e76a94874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556e7b39eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556e7b3a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556e7b38f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556e7b3ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f628a54a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556e74cb4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-56f024ae9b3789f18bd042bef1af461877927661 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6469 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 994078078 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5571e9d98810, 0x5571e9f8201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5571e9f82020,0x5571ebe1a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56f024ae9b3789f18bd042bef1af461877927661' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8437 processed earlier; will process 2592 files now Step #5: ==232990== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5571e088d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5571e6ef2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5571e6ed55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5571e6ed54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5571e0893d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5571e07f4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5571e07ef355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5571e0885c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5571e3854f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5571e3854f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5571e3854f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5571e3854f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5571e3854f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5571e3854f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5571e3854f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5571e3854f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5571e3854f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5571e3854f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5571e5ae9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5571e2816b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5571e2821be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5571e25cdc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5571e25cdc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5571e25ce738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5571e25cd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5571e25cd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5571e25cd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5571e6ed7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5571e6ee0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5571e6ec8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5571e6ef3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2789054082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5571e07edb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9f49fbcc2349dfe16055eeec744522b9a7a0bffe Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6470 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 995736038 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a48d78a810, 0x55a48d97401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a48d974020,0x55a48f80c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9f49fbcc2349dfe16055eeec744522b9a7a0bffe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8438 processed earlier; will process 2591 files now Step #5: ==233026== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a48427f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a48a8e4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a48a8c75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a48a8c74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a484285d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a4841e6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a4841e1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a484277c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a487246f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a487246f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a487246f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a487246f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a487246f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a487246f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a487246f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a487246f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a487246f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a487246f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a4894dbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a486208b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a486213be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a485fbfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a485fbfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a485fc0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a485fbf874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a485fbf874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a485fbf874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a48a8c9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a48a8d2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a48a8ba699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a48a8e5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f89ef3d0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a4841dfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3dcc3f3166a8534d687c363303cd3d8828f516ce Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6471 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 996455064 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557217883810, 0x557217a6d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557217a6d020,0x5572199050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3dcc3f3166a8534d687c363303cd3d8828f516ce' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8439 processed earlier; will process 2590 files now Step #5: ==233062== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55720e3789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5572149dd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5572149c05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5572149c04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55720e37ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55720e2dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55720e2da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55720e370c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55721133ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55721133ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55721133ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55721133ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55721133ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55721133ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55721133ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55721133ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55721133ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55721133ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5572135d4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557210301b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55721030cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5572100b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5572100b8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5572100b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5572100b8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5572100b8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5572100b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5572149c2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5572149cb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5572149b3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5572149de112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8f2060b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55720e2d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a382a31aee4ae1a91a5c5d6dd93a156692c06103 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6472 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 997646344 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e0cdf1b810, 0x55e0ce10501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e0ce105020,0x55e0cff9d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a382a31aee4ae1a91a5c5d6dd93a156692c06103' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8440 processed earlier; will process 2589 files now Step #5: ==233098== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e0c4a109c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e0cb075898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e0cb0585dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e0cb0584fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e0c4a16d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e0c4977b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e0c4972355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e0c4a08c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e0c79d7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e0c79d7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e0c79d7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e0c79d7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e0c79d7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e0c79d7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e0c79d7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e0c79d7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e0c79d7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e0c79d7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e0c9c6cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e0c6999b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e0c69a4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e0c6750c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e0c6750c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e0c6751738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e0c6750874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e0c6750874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e0c6750874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e0cb05aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e0cb063928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e0cb04b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e0cb076112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2dcad11082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e0c4970b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d9077f4922fb8fca3d4c20a6b50a3a06addb76d3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6473 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 998225696 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557a0901a810, 0x557a0920401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557a09204020,0x557a0b09c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d9077f4922fb8fca3d4c20a6b50a3a06addb76d3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8441 processed earlier; will process 2588 files now Step #5: ==233134== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5579ffb0f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557a06174898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557a061575dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557a061574fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5579ffb15d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5579ffa76b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5579ffa71355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5579ffb07c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557a02ad6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557a02ad6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557a02ad6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557a02ad6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557a02ad6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557a02ad6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557a02ad6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557a02ad6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557a02ad6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557a02ad6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557a04d6bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557a01a98b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557a01aa3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557a0184fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557a0184fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557a01850738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557a0184f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557a0184f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557a0184f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557a06159abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557a06162928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557a0614a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557a06175112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f916fbac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5579ffa6fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6303753b44af1a3eac7e1028e8e6b5b5c97be366 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6474 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 999689284 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564d1d084810, 0x564d1d26e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564d1d26e020,0x564d1f1060e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6303753b44af1a3eac7e1028e8e6b5b5c97be366' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8442 processed earlier; will process 2587 files now Step #5: ==233170== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564d13b799c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564d1a1de898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564d1a1c15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564d1a1c14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564d13b7fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564d13ae0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564d13adb355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564d13b71c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564d16b40f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564d16b40f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564d16b40f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564d16b40f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564d16b40f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564d16b40f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564d16b40f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564d16b40f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564d16b40f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564d16b40f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564d18dd5f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564d15b02b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564d15b0dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564d158b9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564d158b9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564d158ba738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564d158b9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564d158b9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564d158b9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564d1a1c3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564d1a1cc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564d1a1b4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564d1a1df112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1dd1723082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564d13ad9b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-92387e915fac187a25fef51fb8f1ab3a7367a5a2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6475 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1000401128 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561ac00f8810, 0x561ac02e201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561ac02e2020,0x561ac217a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92387e915fac187a25fef51fb8f1ab3a7367a5a2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8443 processed earlier; will process 2586 files now Step #5: #1 pulse cov: 4584 ft: 4585 exec/s: 0 rss: 179Mb Step #5: ==233206== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561ab6bed9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561abd252898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561abd2355dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561abd2354fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561ab6bf3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561ab6b54b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561ab6b4f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561ab6be5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561ab9bb4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561ab9bb4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561ab9bb4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561ab9bb4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561ab9bb4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561ab9bb4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561ab9bb4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561ab9bb4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561ab9bb4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561ab9bb4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561abbe49f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561ab8b76b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561ab8b81be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561ab892dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561ab892dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561ab892e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561ab892d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561ab892d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561ab892d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561abd237abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561abd240928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561abd228699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561abd253112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f237128f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561ab6b4db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b41e0c81e3976a26254865e513fc258cb37d0f76 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6476 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1001046658 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55db1117e810, 0x55db1136801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55db11368020,0x55db132000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b41e0c81e3976a26254865e513fc258cb37d0f76' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8445 processed earlier; will process 2584 files now Step #5: ==233242== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55db07c739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55db0e2d8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55db0e2bb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55db0e2bb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55db07c79d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55db07bdab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55db07bd5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55db07c6bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55db0ac3af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55db0ac3af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55db0ac3af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55db0ac3af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55db0ac3af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55db0ac3af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55db0ac3af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55db0ac3af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55db0ac3af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55db0ac3af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55db0cecff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55db09bfcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55db09c07be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55db099b3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55db099b3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55db099b4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55db099b3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55db099b3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55db099b3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55db0e2bdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55db0e2c6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55db0e2ae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55db0e2d9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f03a3ccd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55db07bd3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f42123c45cdcf58c9c2ad8152541039321637798 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6477 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1002278073 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5618926d6810, 0x5618928c001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5618928c0020,0x5618947580e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f42123c45cdcf58c9c2ad8152541039321637798' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8446 processed earlier; will process 2583 files now Step #5: ==233278== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5618891cb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56188f830898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56188f8135dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56188f8134fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5618891d1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561889132b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56188912d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5618891c3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56188c192f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56188c192f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56188c192f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56188c192f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56188c192f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56188c192f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56188c192f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56188c192f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56188c192f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56188c192f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56188e427f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56188b154b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56188b15fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56188af0bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56188af0bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56188af0c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56188af0b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56188af0b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56188af0b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56188f815abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56188f81e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56188f806699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56188f831112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f398e69e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56188912bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1f47a5411c9fa50c0bf7a1d3465d08c4371c7dc7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6478 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1003972092 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cef8d66810, 0x55cef8f5001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cef8f50020,0x55cefade80e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1f47a5411c9fa50c0bf7a1d3465d08c4371c7dc7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8447 processed earlier; will process 2582 files now Step #5: ==233314== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ceef85b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cef5ec0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cef5ea35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cef5ea34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ceef861d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ceef7c2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ceef7bd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ceef853c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cef2822f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cef2822f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cef2822f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cef2822f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cef2822f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cef2822f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cef2822f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cef2822f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cef2822f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cef2822f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cef4ab7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cef17e4b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cef17efbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cef159bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cef159bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cef159c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cef159b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cef159b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cef159b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cef5ea5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cef5eae928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cef5e96699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cef5ec1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6214701082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ceef7bbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-619522ff4e3ae07b8bb3634d2e593a07c811e07d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6479 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1005794224 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a9c6ae8810, 0x55a9c6cd201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a9c6cd2020,0x55a9c8b6a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/619522ff4e3ae07b8bb3634d2e593a07c811e07d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8448 processed earlier; will process 2581 files now Step #5: ==233350== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a9bd5dd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a9c3c42898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a9c3c255dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a9c3c254fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a9bd5e3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a9bd544b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a9bd53f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a9bd5d5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a9c05a4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a9c05a4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a9c05a4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a9c05a4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a9c05a4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a9c05a4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a9c05a4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a9c05a4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a9c05a4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a9c05a4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a9c2839f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a9bf566b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a9bf571be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a9bf31dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a9bf31dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a9bf31e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a9bf31d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a9bf31d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a9bf31d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a9c3c27abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a9c3c30928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a9c3c18699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a9c3c43112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f70d4822082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a9bd53db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5e1c4c24bd9554aaa97eb8402bf89c3c3c136ab0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6480 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1006453019 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55845ad2e810, 0x55845af1801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55845af18020,0x55845cdb00e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e1c4c24bd9554aaa97eb8402bf89c3c3c136ab0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8449 processed earlier; will process 2580 files now Step #5: ==233386== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5584518239c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558457e88898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558457e6b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558457e6b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558451829d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55845178ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558451785355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55845181bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5584547eaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5584547eaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5584547eaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5584547eaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5584547eaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5584547eaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5584547eaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5584547eaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5584547eaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5584547eaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558456a7ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5584537acb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5584537b7be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558453563c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558453563c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558453564738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558453563874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558453563874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558453563874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558457e6dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558457e76928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558457e5e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558457e89112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa203ede082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558451783b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2cfdd96521927d96f9198f7d7776c94fd6887682 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6481 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1007756784 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55be426bb810, 0x55be428a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55be428a5020,0x55be4473d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2cfdd96521927d96f9198f7d7776c94fd6887682' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8450 processed earlier; will process 2579 files now Step #5: ==233422== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55be391b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55be3f815898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55be3f7f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55be3f7f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55be391b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55be39117b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55be39112355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55be391a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55be3c177f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55be3c177f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55be3c177f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55be3c177f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55be3c177f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55be3c177f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55be3c177f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55be3c177f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55be3c177f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55be3c177f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55be3e40cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55be3b139b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55be3b144be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55be3aef0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55be3aef0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55be3aef1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55be3aef0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55be3aef0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55be3aef0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55be3f7faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55be3f803928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55be3f7eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55be3f816112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa3f55ac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55be39110b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e19f7a6288769f8ced77dfcf7a1d6a42f3dc0a26 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6482 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1008348781 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560534810810, 0x5605349fa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5605349fa020,0x5605368920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e19f7a6288769f8ced77dfcf7a1d6a42f3dc0a26' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8451 processed earlier; will process 2578 files now Step #5: #1 pulse cov: 3747 ft: 3748 exec/s: 0 rss: 180Mb Step #5: ==233458== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56052b3059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56053196a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56053194d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56053194d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56052b30bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56052b26cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56052b267355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56052b2fdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56052e2ccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56052e2ccf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56052e2ccf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56052e2ccf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56052e2ccf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56052e2ccf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56052e2ccf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56052e2ccf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56052e2ccf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56052e2ccf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560530561f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56052d28eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56052d299be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56052d045c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56052d045c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56052d046738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56052d045874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56052d045874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56052d045874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56053194fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560531958928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560531940699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56053196b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7cbeb2c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56052b265b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c2ec121ed888ea4d7aa677bf63c9a203b8183a16 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6483 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1008967026 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56116b8cb810, 0x56116bab501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56116bab5020,0x56116d94d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c2ec121ed888ea4d7aa677bf63c9a203b8183a16' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8453 processed earlier; will process 2576 files now Step #5: ==233494== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5611623c09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561168a25898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561168a085dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561168a084fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5611623c6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561162327b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561162322355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5611623b8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561165387f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561165387f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561165387f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561165387f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561165387f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561165387f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561165387f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561165387f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561165387f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561165387f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56116761cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561164349b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561164354be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561164100c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561164100c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561164101738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561164100874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561164100874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561164100874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561168a0aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561168a13928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611689fb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561168a26112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8436554082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561162320b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d73dd704a3d1153d8a6287f102b0d4f718e14f0d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6484 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1009554380 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cf9b3e1810, 0x55cf9b5cb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cf9b5cb020,0x55cf9d4630e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d73dd704a3d1153d8a6287f102b0d4f718e14f0d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8454 processed earlier; will process 2575 files now Step #5: ==233530== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cf91ed69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cf9853b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cf9851e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cf9851e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cf91edcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cf91e3db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cf91e38355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cf91ecec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cf94e9df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cf94e9df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cf94e9df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cf94e9df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cf94e9df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cf94e9df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cf94e9df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cf94e9df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cf94e9df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cf94e9df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cf97132f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cf93e5fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cf93e6abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cf93c16c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cf93c16c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cf93c17738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cf93c16874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cf93c16874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cf93c16874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cf98520abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cf98529928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cf98511699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cf9853c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7849af1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cf91e36b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-42c5ea0afc87deb6e5125c9924c2f361c63dfab5 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6485 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1010266704 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560ebc13c810, 0x560ebc32601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560ebc326020,0x560ebe1be0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/42c5ea0afc87deb6e5125c9924c2f361c63dfab5' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8455 processed earlier; will process 2574 files now Step #5: ==233566== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560eb2c319c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560eb9296898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560eb92795dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560eb92794fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560eb2c37d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560eb2b98b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560eb2b93355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560eb2c29c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560eb5bf8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560eb5bf8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560eb5bf8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560eb5bf8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560eb5bf8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560eb5bf8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560eb5bf8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560eb5bf8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560eb5bf8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560eb5bf8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560eb7e8df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560eb4bbab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560eb4bc5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560eb4971c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560eb4971c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560eb4972738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560eb4971874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560eb4971874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560eb4971874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560eb927babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560eb9284928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560eb926c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560eb9297112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f52dd9e6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560eb2b91b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0e42feb03c98ea64c7816c1c903e8fca45df09fe Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6486 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1011010063 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560571b33810, 0x560571d1d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560571d1d020,0x560573bb50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0e42feb03c98ea64c7816c1c903e8fca45df09fe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8456 processed earlier; will process 2573 files now Step #5: ==233602== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5605686289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56056ec8d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56056ec705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56056ec704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56056862ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56056858fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56056858a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560568620c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56056b5eff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56056b5eff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56056b5eff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56056b5eff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56056b5eff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56056b5eff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56056b5eff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56056b5eff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56056b5eff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56056b5eff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56056d884f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56056a5b1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56056a5bcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56056a368c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56056a368c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56056a369738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56056a368874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56056a368874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56056a368874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56056ec72abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56056ec7b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56056ec63699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56056ec8e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0f55b64082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560568588b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f69fbed3735c292912c05b449f890f1b710f604d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6487 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1012057076 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c23fd0f810, 0x55c23fef901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c23fef9020,0x55c241d910e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f69fbed3735c292912c05b449f890f1b710f604d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8457 processed earlier; will process 2572 files now Step #5: #1 pulse cov: 3906 ft: 3907 exec/s: 0 rss: 178Mb Step #5: ==233638== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c2368049c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c23ce69898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c23ce4c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c23ce4c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c23680ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c23676bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c236766355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c2367fcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c2397cbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c2397cbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c2397cbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c2397cbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c2397cbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c2397cbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c2397cbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c2397cbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c2397cbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c2397cbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c23ba60f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c23878db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c238798be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c238544c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c238544c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c238545738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c238544874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c238544874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c238544874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c23ce4eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c23ce57928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c23ce3f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c23ce6a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc941512082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c236764b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-18b28a407e3146b33880d2cc2d9af17e7a19ef86 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6488 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1012689000 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f20b9c0810, 0x55f20bbaa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f20bbaa020,0x55f20da420e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/18b28a407e3146b33880d2cc2d9af17e7a19ef86' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8459 processed earlier; will process 2570 files now Step #5: #1 pulse cov: 12015 ft: 12016 exec/s: 0 rss: 199Mb Step #5: ==233674== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f2024b59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f208b1a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f208afd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f208afd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f2024bbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f20241cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f202417355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f2024adc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f20547cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f20547cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f20547cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f20547cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f20547cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f20547cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f20547cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f20547cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f20547cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f20547cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f207711f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f20443eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f204449be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f2041f5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f2041f5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f2041f6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f2041f5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f2041f5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f2041f5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f208affabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f208b08928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f208af0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f208b1b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f726cab4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f202415b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-7da2f4abe66cc9676dafe485e2821e349b481446 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6489 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1014500076 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557a56fee810, 0x557a571d801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557a571d8020,0x557a590700e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/7da2f4abe66cc9676dafe485e2821e349b481446' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8461 processed earlier; will process 2568 files now Step #5: ==233710== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x557a4dae39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557a54148898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557a5412b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557a5412b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557a4dae9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557a4da4ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x557a4da45355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557a4dadbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x557a50aaaf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x557a50aaaf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x557a50aaaf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x557a50aaaf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x557a50aaaf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x557a50aaaf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x557a50aaaf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x557a50aaaf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x557a50aaaf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x557a50aaaf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557a52d3ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x557a4fa6cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x557a4fa77be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x557a4f823c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x557a4f823c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x557a4f824738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x557a4f823874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x557a4f823874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x557a4f823874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557a5412dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557a54136928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557a5411e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557a54149112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1e622e0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x557a4da43b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b434a98c9a1d2b323961356b4a37cba37101e484 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6490 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1016471728 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e07490810, 0x559e0767a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e0767a020,0x559e095120e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b434a98c9a1d2b323961356b4a37cba37101e484' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8462 processed earlier; will process 2567 files now Step #5: ==233746== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559dfdf859c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e045ea898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e045cd5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e045cd4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559dfdf8bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559dfdeecb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559dfdee7355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559dfdf7dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e00f4cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e00f4cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e00f4cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e00f4cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e00f4cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e00f4cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e00f4cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e00f4cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e00f4cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e00f4cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e031e1f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559dfff0eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559dfff19be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559dffcc5c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559dffcc5c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559dffcc6738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559dffcc5874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559dffcc5874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559dffcc5874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e045cfabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e045d8928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e045c0699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e045eb112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e89f6b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559dfdee5b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f9b3ed3421905e05fd038e0dd8162e403e20a131 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6491 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1017048325 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556d2eea8810, 0x556d2f09201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556d2f092020,0x556d30f2a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f9b3ed3421905e05fd038e0dd8162e403e20a131' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8463 processed earlier; will process 2566 files now Step #5: ==233782== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556d2599d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556d2c002898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556d2bfe55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556d2bfe54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556d259a3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556d25904b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556d258ff355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556d25995c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556d28964f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556d28964f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556d28964f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556d28964f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556d28964f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556d28964f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556d28964f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556d28964f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556d28964f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556d28964f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556d2abf9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556d27926b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556d27931be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556d276ddc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556d276ddc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556d276de738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556d276dd874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556d276dd874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556d276dd874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556d2bfe7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556d2bff0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556d2bfd8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556d2c003112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8e00bb2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556d258fdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2f3527b16e907dc2f0bbd5f8efaeb051fe1d23c6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6492 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1017670876 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56227cd86810, 0x56227cf7001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56227cf70020,0x56227ee080e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2f3527b16e907dc2f0bbd5f8efaeb051fe1d23c6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8464 processed earlier; will process 2565 files now Step #5: ==233818== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56227387b9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562279ee0898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562279ec35dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562279ec34fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562273881d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5622737e2b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5622737dd355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562273873c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562276842f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562276842f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562276842f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562276842f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562276842f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562276842f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562276842f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562276842f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562276842f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562276842f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562278ad7f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562275804b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56227580fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5622755bbc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5622755bbc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5622755bc738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5622755bb874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5622755bb874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5622755bb874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562279ec5abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562279ece928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562279eb6699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562279ee1112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3289eb9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5622737dbb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-de7a54db39a3d776aad9401f968cb0b48ac3fdc0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6493 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1018524296 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559ab0548810, 0x559ab073201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559ab0732020,0x559ab25ca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/de7a54db39a3d776aad9401f968cb0b48ac3fdc0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8465 processed earlier; will process 2564 files now Step #5: ==233854== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559aa703d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559aad6a2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559aad6855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559aad6854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559aa7043d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559aa6fa4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559aa6f9f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559aa7035c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559aaa004f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559aaa004f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559aaa004f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559aaa004f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559aaa004f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559aaa004f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559aaa004f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559aaa004f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559aaa004f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559aaa004f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559aac299f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559aa8fc6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559aa8fd1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559aa8d7dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559aa8d7dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559aa8d7e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559aa8d7d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559aa8d7d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559aa8d7d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559aad687abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559aad690928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559aad678699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559aad6a3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe47afdf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559aa6f9db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-64957668f5e128f63352db31e52dfcd965d2e72f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6494 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1019177430 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b97b1fb810, 0x55b97b3e501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b97b3e5020,0x55b97d27d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/64957668f5e128f63352db31e52dfcd965d2e72f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8466 processed earlier; will process 2563 files now Step #5: ==233890== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b971cf09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b978355898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b9783385dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b9783384fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b971cf6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b971c57b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b971c52355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b971ce8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b974cb7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b974cb7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b974cb7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b974cb7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b974cb7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b974cb7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b974cb7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b974cb7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b974cb7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b974cb7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b976f4cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b973c79b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b973c84be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b973a30c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b973a30c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b973a31738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b973a30874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b973a30874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b973a30874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b97833aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b978343928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b97832b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b978356112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7b26257082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b971c50b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9d465faefc6fd3357ef0236873afac84ce919713 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6495 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1019868633 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5649e0848810, 0x5649e0a3201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5649e0a32020,0x5649e28ca0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9d465faefc6fd3357ef0236873afac84ce919713' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8467 processed earlier; will process 2562 files now Step #5: #1 pulse cov: 16202 ft: 16203 exec/s: 0 rss: 205Mb Step #5: ==233926== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5649d733d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5649dd9a2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5649dd9855dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5649dd9854fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5649d7343d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5649d72a4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5649d729f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5649d7335c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5649da304f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5649da304f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5649da304f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5649da304f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5649da304f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5649da304f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5649da304f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5649da304f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5649da304f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5649da304f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5649dc599f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649d92c6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649d92d1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5649d907dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5649d907dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5649d907e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5649d907d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5649d907d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5649d907d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5649dd987abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5649dd990928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5649dd978699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5649dd9a3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2209f87082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5649d729db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d6dbcc6f749a16d048e324279af9083820e0f925 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6496 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1020589392 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ada95bb810, 0x55ada97a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ada97a5020,0x55adab63d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d6dbcc6f749a16d048e324279af9083820e0f925' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8469 processed earlier; will process 2560 files now Step #5: ==233962== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ada00b09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ada6715898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ada66f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ada66f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ada00b6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ada0017b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ada0012355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ada00a8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ada3077f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ada3077f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ada3077f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ada3077f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ada3077f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ada3077f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ada3077f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ada3077f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ada3077f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ada3077f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ada530cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ada2039b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ada2044be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ada1df0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ada1df0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ada1df1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ada1df0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ada1df0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ada1df0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ada66faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ada6703928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ada66eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ada6716112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff05db32082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ada0010b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9b0a09ff941b87e12211b524303468e018adaf3f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6497 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1021322226 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dc6bad7810, 0x55dc6bcc101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dc6bcc1020,0x55dc6db590e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9b0a09ff941b87e12211b524303468e018adaf3f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8470 processed earlier; will process 2559 files now Step #5: ==233998== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dc625cc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55dc68c31898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55dc68c145dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55dc68c144fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dc625d2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dc62533b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dc6252e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dc625c4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dc65593f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dc65593f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dc65593f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dc65593f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dc65593f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dc65593f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dc65593f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dc65593f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dc65593f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dc65593f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dc67828f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dc64555b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dc64560be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dc6430cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dc6430cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dc6430d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dc6430c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dc6430c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dc6430c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55dc68c16abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55dc68c1f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55dc68c07699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55dc68c32112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb4ad12b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dc6252cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-19d2e5d431630562cf40ae96c1021c74038d343a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6498 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1021905463 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b67b75f810, 0x55b67b94901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b67b949020,0x55b67d7e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/19d2e5d431630562cf40ae96c1021c74038d343a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8471 processed earlier; will process 2558 files now Step #5: ==234034== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b6722549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b6788b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b67889c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b67889c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b67225ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6721bbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6721b6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b67224cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b67521bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b67521bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b67521bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b67521bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b67521bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b67521bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b67521bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b67521bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b67521bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b67521bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b6774b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6741ddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6741e8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b673f94c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b673f94c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b673f95738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b673f94874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b673f94874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b673f94874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b67889eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b6788a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b67888f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b6788ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f949f4aa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6721b4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-38769e1749b34b492ee1fc8bbb76d3915a8fb819 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6499 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1022502356 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562c85b69810, 0x562c85d5301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562c85d53020,0x562c87beb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/38769e1749b34b492ee1fc8bbb76d3915a8fb819' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8472 processed earlier; will process 2557 files now Step #5: #1 pulse cov: 3898 ft: 3899 exec/s: 0 rss: 180Mb Step #5: ==234070== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562c7c65e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562c82cc3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562c82ca65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562c82ca64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562c7c664d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562c7c5c5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562c7c5c0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562c7c656c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562c7f625f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562c7f625f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562c7f625f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562c7f625f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562c7f625f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562c7f625f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562c7f625f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562c7f625f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562c7f625f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562c7f625f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562c818baf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562c7e5e7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562c7e5f2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562c7e39ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562c7e39ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562c7e39f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562c7e39e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562c7e39e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562c7e39e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562c82ca8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562c82cb1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562c82c99699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562c82cc4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f58eafdb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562c7c5beb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e9e9e0af9d80fe706fd0e3f91bb1a521a3dd2e84 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6500 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1024214800 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5585674d5810, 0x5585676bf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5585676bf020,0x5585695570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e9e9e0af9d80fe706fd0e3f91bb1a521a3dd2e84' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8474 processed earlier; will process 2555 files now Step #5: ==234106== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55855dfca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55856462f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5585646125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5585646124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55855dfd0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55855df31b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55855df2c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55855dfc2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558560f91f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558560f91f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558560f91f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558560f91f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558560f91f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558560f91f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558560f91f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558560f91f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558560f91f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558560f91f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558563226f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55855ff53b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55855ff5ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55855fd0ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55855fd0ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55855fd0b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55855fd0a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55855fd0a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55855fd0a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558564614abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55856461d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558564605699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558564630112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc43b458082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55855df2ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f08e4c3741d6bc1bbb802ffcdeb800824a3677cd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6501 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1025693118 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5578566df810, 0x5578568c901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5578568c9020,0x5578587610e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f08e4c3741d6bc1bbb802ffcdeb800824a3677cd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8475 processed earlier; will process 2554 files now Step #5: ==234142== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55784d1d49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557853839898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55785381c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55785381c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55784d1dad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55784d13bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55784d136355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55784d1ccc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55785019bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55785019bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55785019bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55785019bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55785019bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55785019bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55785019bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55785019bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55785019bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55785019bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557852430f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55784f15db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55784f168be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55784ef14c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55784ef14c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55784ef15738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55784ef14874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55784ef14874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55784ef14874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55785381eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557853827928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55785380f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55785383a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7bcddc2082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55784d134b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-749bfc7db84d4a1b84a8d0ee913d54797ab31b48 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6502 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1027384580 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564bed67e810, 0x564bed86801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564bed868020,0x564bef7000e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/749bfc7db84d4a1b84a8d0ee913d54797ab31b48' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8476 processed earlier; will process 2553 files now Step #5: ==234178== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x564be41739c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564bea7d8898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564bea7bb5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564bea7bb4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564be4179d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564be40dab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564be40d5355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x564be416bc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564be713af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564be713af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564be713af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564be713af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564be713af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564be713af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564be713af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564be713af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564be713af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564be713af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564be93cff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564be60fcb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564be6107be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x564be5eb3c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x564be5eb3c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564be5eb4738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x564be5eb3874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x564be5eb3874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x564be5eb3874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564bea7bdabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564bea7c6928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564bea7ae699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564bea7d9112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fba060b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564be40d3b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-66485c1a0e6237c0932ae8c57437e60d65ea017d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6503 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1027989498 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55dabcfbf810, 0x55dabd1a901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55dabd1a9020,0x55dabf0410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/66485c1a0e6237c0932ae8c57437e60d65ea017d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8477 processed earlier; will process 2552 files now Step #5: #1 pulse cov: 3860 ft: 3861 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 3936 ft: 4377 exec/s: 0 rss: 179Mb Step #5: ==234214== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55dab3ab49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55daba119898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55daba0fc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55daba0fc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55dab3abad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55dab3a1bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55dab3a16355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55dab3aacc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55dab6a7bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55dab6a7bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55dab6a7bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55dab6a7bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55dab6a7bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55dab6a7bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55dab6a7bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55dab6a7bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55dab6a7bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55dab6a7bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55dab8d10f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55dab5a3db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55dab5a48be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55dab57f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55dab57f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55dab57f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55dab57f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55dab57f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55dab57f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55daba0feabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55daba107928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55daba0ef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55daba11a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc371716082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55dab3a14b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-78659dc62053510413d218afc27fd76fbdfb0a7c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6504 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1028698722 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5577c89ec810, 0x5577c8bd601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5577c8bd6020,0x5577caa6e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/78659dc62053510413d218afc27fd76fbdfb0a7c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8481 processed earlier; will process 2548 files now Step #5: ==234250== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5577bf4e19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5577c5b46898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5577c5b295dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5577c5b294fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5577bf4e7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5577bf448b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5577bf443355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5577bf4d9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5577c24a8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5577c24a8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5577c24a8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5577c24a8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5577c24a8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5577c24a8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5577c24a8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5577c24a8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5577c24a8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5577c24a8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5577c473df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5577c146ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5577c1475be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5577c1221c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5577c1221c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5577c1222738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5577c1221874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5577c1221874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5577c1221874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5577c5b2babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5577c5b34928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5577c5b1c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5577c5b47112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fec96fdb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5577bf441b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-cb0710cfb7cb2946380c5bfbd54a71c88e276f5a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6505 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1029256897 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a6592b5810, 0x55a65949f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a65949f020,0x55a65b3370e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/cb0710cfb7cb2946380c5bfbd54a71c88e276f5a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8482 processed earlier; will process 2547 files now Step #5: ==234286== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a64fdaa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a65640f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a6563f25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a6563f24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a64fdb0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a64fd11b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a64fd0c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a64fda2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a652d71f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a652d71f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a652d71f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a652d71f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a652d71f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a652d71f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a652d71f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a652d71f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a652d71f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a652d71f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a655006f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a651d33b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a651d3ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a651aeac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a651aeac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a651aeb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a651aea874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a651aea874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a651aea874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a6563f4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a6563fd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a6563e5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a656410112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f67404a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a64fd0ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b401735d811e374d7c07658663d9a9c19423faad Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6506 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1029838570 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5575f597d810, 0x5575f5b6701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5575f5b67020,0x5575f79ff0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b401735d811e374d7c07658663d9a9c19423faad' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8483 processed earlier; will process 2546 files now Step #5: ==234322== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5575ec4729c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5575f2ad7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5575f2aba5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5575f2aba4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5575ec478d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5575ec3d9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5575ec3d4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5575ec46ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5575ef439f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5575ef439f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5575ef439f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5575ef439f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5575ef439f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5575ef439f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5575ef439f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5575ef439f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5575ef439f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5575ef439f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5575f16cef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5575ee3fbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5575ee406be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5575ee1b2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5575ee1b2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5575ee1b3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5575ee1b2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5575ee1b2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5575ee1b2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5575f2abcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5575f2ac5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5575f2aad699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5575f2ad8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fb5053dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5575ec3d2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d3fb9e210b164604a7adc51f685f8e689f00211b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6507 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1030871949 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7e0e67810, 0x55b7e105101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7e1051020,0x55b7e2ee90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d3fb9e210b164604a7adc51f685f8e689f00211b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8484 processed earlier; will process 2545 files now Step #5: #1 pulse cov: 4526 ft: 4527 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 14853 ft: 15963 exec/s: 0 rss: 208Mb Step #5: #4 pulse cov: 15307 ft: 17381 exec/s: 0 rss: 210Mb Step #5: ==234358== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b7d795c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b7ddfc1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b7ddfa45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b7ddfa44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b7d7962d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b7d78c3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b7d78be355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b7d7954c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b7da923f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b7da923f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b7da923f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b7da923f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b7da923f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b7da923f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b7da923f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b7da923f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b7da923f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b7da923f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b7dcbb8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b7d98e5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b7d98f0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b7d969cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b7d969cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b7d969d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b7d969c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b7d969c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b7d969c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b7ddfa6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b7ddfaf928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b7ddf97699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b7ddfc2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7eff4de91082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b7d78bcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-372c529605362d706e92a1d7be6c69123b102c93 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6508 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1031847520 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56076b001810, 0x56076b1eb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56076b1eb020,0x56076d0830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/372c529605362d706e92a1d7be6c69123b102c93' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8489 processed earlier; will process 2540 files now Step #5: ==234394== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560761af69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56076815b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56076813e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56076813e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560761afcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560761a5db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560761a58355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560761aeec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560764abdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560764abdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560764abdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560764abdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560764abdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560764abdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560764abdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560764abdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560764abdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560764abdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560766d52f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560763a7fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560763a8abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560763836c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560763836c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560763837738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560763836874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560763836874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560763836874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560768140abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560768149928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560768131699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56076815c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6476ea5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560761a56b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-854b4442539fddb27381c314abd7435bb292b3bf Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6509 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1032558635 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b70118d810, 0x55b70137701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b701377020,0x55b70320f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/854b4442539fddb27381c314abd7435bb292b3bf' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8490 processed earlier; will process 2539 files now Step #5: ==234430== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b6f7c829c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b6fe2e7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b6fe2ca5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b6fe2ca4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6f7c88d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6f7be9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6f7be4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6f7c7ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b6fac49f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b6fac49f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b6fac49f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b6fac49f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b6fac49f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b6fac49f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b6fac49f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b6fac49f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b6fac49f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b6fac49f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b6fcedef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6f9c0bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6f9c16be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6f99c2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6f99c2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6f99c3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6f99c2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6f99c2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6f99c2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b6fe2ccabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b6fe2d5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b6fe2bd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b6fe2e8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f7c30470082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6f7be2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0f3ee7aac08dfe59eaaac3727fd8b3e221d6c644 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6510 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1033153843 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bb3db75810, 0x55bb3dd5f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bb3dd5f020,0x55bb3fbf70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0f3ee7aac08dfe59eaaac3727fd8b3e221d6c644' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8491 processed earlier; will process 2538 files now Step #5: #1 pulse cov: 12007 ft: 12008 exec/s: 0 rss: 197Mb Step #5: ==234466== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bb3466a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bb3accf898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bb3acb25dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bb3acb24fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bb34670d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bb345d1b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bb345cc355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bb34662c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bb37631f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bb37631f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bb37631f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bb37631f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bb37631f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bb37631f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bb37631f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bb37631f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bb37631f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bb37631f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bb398c6f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bb365f3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bb365febe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bb363aac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bb363aac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bb363ab738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bb363aa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bb363aa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bb363aa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bb3acb4abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bb3acbd928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bb3aca5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bb3acd0112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6ac5ecf082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bb345cab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c1ae9eb92b6d2432720c63668b764fbf449e1e54 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6511 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1033822515 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5642a362f810, 0x5642a381901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5642a3819020,0x5642a56b10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c1ae9eb92b6d2432720c63668b764fbf449e1e54' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8493 processed earlier; will process 2536 files now Step #5: ==234502== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56429a1249c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5642a0789898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5642a076c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5642a076c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56429a12ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56429a08bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56429a086355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56429a11cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56429d0ebf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56429d0ebf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56429d0ebf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56429d0ebf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56429d0ebf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56429d0ebf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56429d0ebf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56429d0ebf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56429d0ebf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56429d0ebf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56429f380f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56429c0adb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56429c0b8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56429be64c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56429be64c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56429be65738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56429be64874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56429be64874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56429be64874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5642a076eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5642a0777928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5642a075f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5642a078a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4c6fb94082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56429a084b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5bba627ff7489ed3799dfab90e5867f41ca59dde Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6512 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1034395244 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562544668810, 0x56254485201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562544852020,0x5625466ea0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5bba627ff7489ed3799dfab90e5867f41ca59dde' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8494 processed earlier; will process 2535 files now Step #5: #1 pulse cov: 17222 ft: 17223 exec/s: 0 rss: 209Mb Step #5: ==234538== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56253b15d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5625417c2898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5625417a55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5625417a54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56253b163d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56253b0c4b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56253b0bf355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56253b155c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56253e124f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56253e124f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56253e124f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56253e124f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56253e124f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56253e124f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56253e124f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56253e124f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56253e124f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56253e124f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5625403b9f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56253d0e6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56253d0f1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56253ce9dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56253ce9dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56253ce9e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56253ce9d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56253ce9d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56253ce9d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5625417a7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5625417b0928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562541798699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5625417c3112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fab4d8dd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56253b0bdb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-17433a83fa9503f33b25a3c9bc69dd80d01197a6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6513 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1035161004 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5556f00f1810, 0x5556f02db01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5556f02db020,0x5556f21730e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/17433a83fa9503f33b25a3c9bc69dd80d01197a6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8496 processed earlier; will process 2533 files now Step #5: #1 pulse cov: 3919 ft: 3920 exec/s: 0 rss: 180Mb Step #5: ==234574== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5556e6be69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5556ed24b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5556ed22e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5556ed22e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5556e6becd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5556e6b4db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5556e6b48355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5556e6bdec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5556e9badf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5556e9badf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5556e9badf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5556e9badf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5556e9badf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5556e9badf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5556e9badf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5556e9badf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5556e9badf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5556e9badf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5556ebe42f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5556e8b6fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5556e8b7abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5556e8926c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5556e8926c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5556e8927738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5556e8926874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5556e8926874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5556e8926874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5556ed230abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5556ed239928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5556ed221699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5556ed24c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f541fd21082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5556e6b46b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f03462646388650296a7fa079de74e95314669b1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6514 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1035786488 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55763b838810, 0x55763ba2201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55763ba22020,0x55763d8ba0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f03462646388650296a7fa079de74e95314669b1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8498 processed earlier; will process 2531 files now Step #5: ==234610== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55763232d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557638992898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5576389755dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5576389754fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x557632333d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x557632294b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55763228f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x557632325c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5576352f4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5576352f4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5576352f4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5576352f4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5576352f4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5576352f4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5576352f4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5576352f4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5576352f4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5576352f4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x557637589f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5576342b6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5576342c1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55763406dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55763406dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55763406e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55763406d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55763406d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55763406d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557638977abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557638980928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557638968699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557638993112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff04921a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55763228db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-621cd6ee77dfcf131eb7abf4ae7bca96a9d31e96 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6515 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1036367039 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558c01871810, 0x558c01a5b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558c01a5b020,0x558c038f30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/621cd6ee77dfcf131eb7abf4ae7bca96a9d31e96' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8499 processed earlier; will process 2530 files now Step #5: #1 pulse cov: 12439 ft: 12440 exec/s: 0 rss: 199Mb Step #5: ==234646== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558bf83669c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558bfe9cb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558bfe9ae5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558bfe9ae4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558bf836cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558bf82cdb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558bf82c8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558bf835ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558bfb32df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558bfb32df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558bfb32df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558bfb32df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558bfb32df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558bfb32df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558bfb32df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558bfb32df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558bfb32df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558bfb32df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558bfd5c2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558bfa2efb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558bfa2fabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558bfa0a6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558bfa0a6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558bfa0a7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558bfa0a6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558bfa0a6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558bfa0a6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558bfe9b0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558bfe9b9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558bfe9a1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558bfe9cc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcc41d2a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558bf82c6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1fd26919f4bdde9f994bbed2e6b3737ab2edfd45 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6516 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1037115057 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b8be7ac810, 0x55b8be99601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b8be996020,0x55b8c082e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1fd26919f4bdde9f994bbed2e6b3737ab2edfd45' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8501 processed earlier; will process 2528 files now Step #5: #1 pulse cov: 3504 ft: 3505 exec/s: 0 rss: 178Mb Step #5: #2 pulse cov: 4054 ft: 4481 exec/s: 0 rss: 179Mb Step #5: ==234682== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b8b52a19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b8bb906898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b8bb8e95dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b8bb8e94fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b8b52a7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b8b5208b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b8b5203355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b8b5299c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b8b8268f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b8b8268f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b8b8268f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b8b8268f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b8b8268f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b8b8268f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b8b8268f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b8b8268f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b8b8268f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b8b8268f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b8ba4fdf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b8b722ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b8b7235be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b8b6fe1c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b8b6fe1c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b8b6fe2738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b8b6fe1874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b8b6fe1874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b8b6fe1874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b8bb8ebabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b8bb8f4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b8bb8dc699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b8bb907112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc819e61082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b8b5201b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5ca9114b01e4e247545fa9eea2e9da251f415a08 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6517 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1037783343 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5583d9fbb810, 0x5583da1a501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5583da1a5020,0x5583dc03d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5ca9114b01e4e247545fa9eea2e9da251f415a08' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8504 processed earlier; will process 2525 files now Step #5: ==234718== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5583d0ab09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5583d7115898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5583d70f85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5583d70f84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5583d0ab6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5583d0a17b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5583d0a12355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5583d0aa8c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5583d3a77f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5583d3a77f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5583d3a77f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5583d3a77f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5583d3a77f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5583d3a77f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5583d3a77f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5583d3a77f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5583d3a77f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5583d3a77f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5583d5d0cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5583d2a39b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5583d2a44be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5583d27f0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5583d27f0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5583d27f1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5583d27f0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5583d27f0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5583d27f0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5583d70faabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5583d7103928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5583d70eb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5583d7116112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe912c7082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5583d0a10b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ba88f87007b66a779c13a2e892b218cb32332a4b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6518 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1038346027 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b33711d810, 0x55b33730701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b337307020,0x55b33919f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ba88f87007b66a779c13a2e892b218cb32332a4b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8505 processed earlier; will process 2524 files now Step #5: ==234754== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b32dc129c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b334277898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b33425a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b33425a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b32dc18d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b32db79b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b32db74355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b32dc0ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b330bd9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b330bd9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b330bd9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b330bd9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b330bd9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b330bd9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b330bd9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b330bd9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b330bd9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b330bd9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b332e6ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b32fb9bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b32fba6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b32f952c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b32f952c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b32f953738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b32f952874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b32f952874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b32f952874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b33425cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b334265928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b33424d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b334278112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f84a6d74082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b32db72b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-b2dc314983f6be8e7fdabed7ad9de89e8fa918ea Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6519 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1038899486 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e61ef6a810, 0x55e61f15401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e61f154020,0x55e620fec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/b2dc314983f6be8e7fdabed7ad9de89e8fa918ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8506 processed earlier; will process 2523 files now Step #5: ==234790== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e615a5f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e61c0c4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e61c0a75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e61c0a74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e615a65d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e6159c6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e6159c1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e615a57c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e618a26f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e618a26f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e618a26f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e618a26f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e618a26f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e618a26f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e618a26f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e618a26f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e618a26f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e618a26f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e61acbbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e6179e8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e6179f3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e61779fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e61779fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e6177a0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e61779f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e61779f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e61779f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e61c0a9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e61c0b2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e61c09a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e61c0c5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa8fcec1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e6159bfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-86edaa00eadf2c48056c384ca30499e304e6f1c3 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6520 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1039483409 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5602fc90e810, 0x5602fcaf801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5602fcaf8020,0x5602fe9900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/86edaa00eadf2c48056c384ca30499e304e6f1c3' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8507 processed earlier; will process 2522 files now Step #5: #1 pulse cov: 3662 ft: 3663 exec/s: 0 rss: 181Mb Step #5: ==234826== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5602f34039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5602f9a68898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5602f9a4b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5602f9a4b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5602f3409d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5602f336ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5602f3365355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5602f33fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5602f63caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5602f63caf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5602f63caf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5602f63caf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5602f63caf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5602f63caf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5602f63caf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5602f63caf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5602f63caf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5602f63caf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5602f865ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5602f538cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5602f5397be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5602f5143c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5602f5143c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5602f5144738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5602f5143874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5602f5143874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5602f5143874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5602f9a4dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5602f9a56928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5602f9a3e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5602f9a69112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f055b1ac082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5602f3363b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5e05e61f8c83c42a6fa547cf304a58cf69edec47 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6521 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1040210426 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55c7142fc810, 0x55c7144e601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55c7144e6020,0x55c71637e0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5e05e61f8c83c42a6fa547cf304a58cf69edec47' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8509 processed earlier; will process 2520 files now Step #5: #1 pulse cov: 3728 ft: 3729 exec/s: 0 rss: 179Mb Step #5: ==234862== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55c70adf19c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55c711456898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55c7114395dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55c7114394fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55c70adf7d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55c70ad58b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55c70ad53355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55c70ade9c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55c70ddb8f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55c70ddb8f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55c70ddb8f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55c70ddb8f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55c70ddb8f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55c70ddb8f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55c70ddb8f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55c70ddb8f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55c70ddb8f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55c70ddb8f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55c71004df7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55c70cd7ab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55c70cd85be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55c70cb31c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55c70cb31c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55c70cb32738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55c70cb31874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55c70cb31874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55c70cb31874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55c71143babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55c711444928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55c71142c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55c711457112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f598d267082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55c70ad51b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5fab4dc25f6d1ace9ff36680c7bd8ea03a5c437a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6522 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1040816642 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5590a7ed0810, 0x5590a80ba01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5590a80ba020,0x5590a9f520e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5fab4dc25f6d1ace9ff36680c7bd8ea03a5c437a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8511 processed earlier; will process 2518 files now Step #5: #1 pulse cov: 3547 ft: 3548 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4475 ft: 4966 exec/s: 0 rss: 182Mb Step #5: ==234898== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55909e9c59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5590a502a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5590a500d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5590a500d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55909e9cbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55909e92cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55909e927355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55909e9bdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5590a198cf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5590a198cf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5590a198cf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5590a198cf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5590a198cf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5590a198cf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5590a198cf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5590a198cf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5590a198cf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5590a198cf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5590a3c21f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5590a094eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5590a0959be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5590a0705c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5590a0705c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5590a0706738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5590a0705874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5590a0705874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5590a0705874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5590a500fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5590a5018928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5590a5000699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5590a502b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd3253d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55909e925b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-56b82d9a98d99dd8543d5d874bdacfa953dcbbb0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6523 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1041465420 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5570c1a41810, 0x5570c1c2b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5570c1c2b020,0x5570c3ac30e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/56b82d9a98d99dd8543d5d874bdacfa953dcbbb0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8514 processed earlier; will process 2515 files now Step #5: #1 pulse cov: 4069 ft: 4070 exec/s: 0 rss: 180Mb Step #5: ==234934== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5570b85369c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5570beb9b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5570beb7e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5570beb7e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5570b853cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5570b849db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5570b8498355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5570b852ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5570bb4fdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5570bb4fdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5570bb4fdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5570bb4fdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5570bb4fdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5570bb4fdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5570bb4fdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5570bb4fdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5570bb4fdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5570bb4fdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5570bd792f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5570ba4bfb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5570ba4cabe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5570ba276c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5570ba276c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5570ba277738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5570ba276874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5570ba276874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5570ba276874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5570beb80abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5570beb89928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5570beb71699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5570beb9c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f43704a5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5570b8496b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-fc2d099366108db13d13f9a35e3922d0e291202c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6524 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1042105630 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x562cdf109810, 0x562cdf2f301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x562cdf2f3020,0x562ce118b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/fc2d099366108db13d13f9a35e3922d0e291202c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8516 processed earlier; will process 2513 files now Step #5: ==234970== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x562cd5bfe9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x562cdc263898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x562cdc2465dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x562cdc2464fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562cd5c04d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x562cd5b65b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x562cd5b60355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562cd5bf6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562cd8bc5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562cd8bc5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562cd8bc5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562cd8bc5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562cd8bc5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562cd8bc5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562cd8bc5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562cd8bc5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562cd8bc5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562cd8bc5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x562cdae5af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x562cd7b87b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x562cd7b92be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x562cd793ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x562cd793ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562cd793f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x562cd793e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x562cd793e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x562cd793e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x562cdc248abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x562cdc251928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x562cdc239699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x562cdc264112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68c2004082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x562cd5b5eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-615c7bbf730e3c0917768c131376979fd0a909b6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6525 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1042649700 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f9049de810, 0x55f904bc801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f904bc8020,0x55f906a600e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/615c7bbf730e3c0917768c131376979fd0a909b6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8517 processed earlier; will process 2512 files now Step #5: ==235006== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f8fb4d39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f901b38898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f901b1b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f901b1b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f8fb4d9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f8fb43ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f8fb435355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f8fb4cbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f8fe49af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f8fe49af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f8fe49af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f8fe49af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f8fe49af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f8fe49af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f8fe49af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f8fe49af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f8fe49af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f8fe49af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f90072ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f8fd45cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f8fd467be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f8fd213c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f8fd213c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f8fd214738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f8fd213874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f8fd213874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f8fd213874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f901b1dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f901b26928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f901b0e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f901b39112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0d2e3d3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f8fb433b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4ddfb27f1f3ec9910c9c564ddd5e0a4f11af57bb Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6526 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1043224288 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559e603a9810, 0x559e6059301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559e60593020,0x559e6242b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4ddfb27f1f3ec9910c9c564ddd5e0a4f11af57bb' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8518 processed earlier; will process 2511 files now Step #5: #1 pulse cov: 11043 ft: 11044 exec/s: 0 rss: 199Mb Step #5: ==235042== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559e56e9e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559e5d503898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559e5d4e65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559e5d4e64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559e56ea4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559e56e05b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559e56e00355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559e56e96c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559e59e65f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559e59e65f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559e59e65f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559e59e65f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559e59e65f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559e59e65f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559e59e65f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559e59e65f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559e59e65f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559e59e65f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559e5c0faf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559e58e27b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559e58e32be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559e58bdec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559e58bdec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559e58bdf738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559e58bde874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559e58bde874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559e58bde874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559e5d4e8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559e5d4f1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559e5d4d9699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559e5d504112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4965e62082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559e56dfeb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bade125869e16b623846c360e3d50a0646657be7 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6527 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1043931522 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b995c4810, 0x560b997ae01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b997ae020,0x560b9b6460e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bade125869e16b623846c360e3d50a0646657be7' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8520 processed earlier; will process 2509 files now Step #5: #1 pulse cov: 4108 ft: 4109 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 4601 ft: 5025 exec/s: 0 rss: 182Mb Step #5: #4 pulse cov: 5410 ft: 7233 exec/s: 0 rss: 185Mb Step #5: ==235078== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560b900b99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b9671e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b967015dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b967014fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b900bfd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b90020b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b9001b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b900b1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b93080f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b93080f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b93080f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b93080f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b93080f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b93080f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b93080f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b93080f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b93080f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b93080f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b95315f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b92042b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b9204dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b91df9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b91df9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b91dfa738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b91df9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b91df9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b91df9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b96703abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b9670c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b966f4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b9671f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f239c361082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b90019b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ff431fce56abebc27d1407bf2628528283c2179e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6528 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1046337938 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5611dac5c810, 0x5611dae4601c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5611dae46020,0x5611dccde0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ff431fce56abebc27d1407bf2628528283c2179e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8525 processed earlier; will process 2504 files now Step #5: #1 pulse cov: 10505 ft: 10506 exec/s: 0 rss: 200Mb Step #5: #2 pulse cov: 11773 ft: 12600 exec/s: 0 rss: 203Mb Step #5: ==235114== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5611d17519c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5611d7db6898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5611d7d995dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5611d7d994fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5611d1757d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5611d16b8b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5611d16b3355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5611d1749c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5611d4718f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5611d4718f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5611d4718f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5611d4718f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5611d4718f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5611d4718f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5611d4718f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5611d4718f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5611d4718f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5611d4718f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5611d69adf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5611d36dab78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5611d36e5be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5611d3491c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5611d3491c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5611d3492738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5611d3491874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5611d3491874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5611d3491874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5611d7d9babd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5611d7da4928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5611d7d8c699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5611d7db7112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa35ca19082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5611d16b1b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ec3695fa7576c6ad4ac18f136f2134009961a7e0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6529 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1047200167 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55af20afa810, 0x55af20ce401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55af20ce4020,0x55af22b7c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ec3695fa7576c6ad4ac18f136f2134009961a7e0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8529 processed earlier; will process 2500 files now Step #5: ==235150== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55af175ef9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55af1dc54898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55af1dc375dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55af1dc374fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55af175f5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55af17556b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55af17551355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55af175e7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55af1a5b6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55af1a5b6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55af1a5b6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55af1a5b6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55af1a5b6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55af1a5b6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55af1a5b6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55af1a5b6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55af1a5b6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55af1a5b6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55af1c84bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55af19578b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55af19583be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55af1932fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55af1932fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55af19330738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55af1932f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55af1932f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55af1932f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55af1dc39abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55af1dc42928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55af1dc2a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55af1dc55112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faa3a522082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55af1754fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6e3818d1931c5ee028680b0b0fe0fd82b3dc1894 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6530 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1047773970 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55cc16bbf810, 0x55cc16da901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55cc16da9020,0x55cc18c410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6e3818d1931c5ee028680b0b0fe0fd82b3dc1894' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8530 processed earlier; will process 2499 files now Step #5: ==235186== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cc0d6b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cc13d19898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cc13cfc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cc13cfc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cc0d6bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cc0d61bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cc0d616355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cc0d6acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cc1067bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cc1067bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cc1067bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cc1067bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cc1067bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cc1067bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cc1067bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cc1067bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cc1067bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cc1067bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55cc12910f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cc0f63db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cc0f648be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cc0f3f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cc0f3f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cc0f3f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cc0f3f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cc0f3f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cc0f3f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cc13cfeabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cc13d07928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cc13cef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cc13d1a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f377089b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cc0d614b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e429eb8ff4d64750d61840167c47f2a7ebcef7d6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6531 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1048333523 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563da0883810, 0x563da0a6d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563da0a6d020,0x563da29050e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e429eb8ff4d64750d61840167c47f2a7ebcef7d6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8531 processed earlier; will process 2498 files now Step #5: ==235222== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563d973789c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563d9d9dd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563d9d9c05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563d9d9c04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563d9737ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563d972dfb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563d972da355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563d97370c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563d9a33ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563d9a33ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563d9a33ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563d9a33ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563d9a33ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563d9a33ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563d9a33ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563d9a33ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563d9a33ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563d9a33ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563d9c5d4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563d99301b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563d9930cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563d990b8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563d990b8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563d990b9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563d990b8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563d990b8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563d990b8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563d9d9c2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563d9d9cb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563d9d9b3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563d9d9de112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f10c750f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563d972d8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-70549e3fdffa4722556cf6a0b6354a7e91b2f397 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6532 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1049345834 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556936cd3810, 0x556936ebd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556936ebd020,0x556938d550e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/70549e3fdffa4722556cf6a0b6354a7e91b2f397' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8532 processed earlier; will process 2497 files now Step #5: ==235258== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55692d7c89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556933e2d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556933e105dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556933e104fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55692d7ced42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55692d72fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55692d72a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55692d7c0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55693078ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55693078ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55693078ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55693078ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55693078ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55693078ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55693078ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55693078ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55693078ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55693078ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556932a24f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55692f751b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55692f75cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55692f508c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55692f508c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55692f509738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55692f508874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55692f508874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55692f508874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556933e12abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556933e1b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556933e03699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556933e2e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88c9976082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55692d728b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bfb13e23053c1a68c59b20adf0328d53c0fb0f33 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6533 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1050016793 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x563b4a824810, 0x563b4aa0e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x563b4aa0e020,0x563b4c8a60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bfb13e23053c1a68c59b20adf0328d53c0fb0f33' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8533 processed earlier; will process 2496 files now Step #5: ==235294== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x563b413199c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x563b4797e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x563b479615dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x563b479614fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563b4131fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x563b41280b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x563b4127b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563b41311c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563b442e0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563b442e0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563b442e0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563b442e0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563b442e0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563b442e0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563b442e0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563b442e0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563b442e0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563b442e0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x563b46575f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x563b432a2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x563b432adbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563b43059c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563b43059c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563b4305a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563b43059874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563b43059874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563b43059874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x563b47963abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x563b4796c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x563b47954699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x563b4797f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe0bf5d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x563b41279b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d571e26e9c0f6852ced9a5b7a84fab6fa482c140 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6534 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1051011835 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f2f2f40810, 0x55f2f312a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f2f312a020,0x55f2f4fc20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d571e26e9c0f6852ced9a5b7a84fab6fa482c140' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8534 processed earlier; will process 2495 files now Step #5: ==235330== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f2e9a359c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f2f009a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f2f007d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f2f007d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f2e9a3bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f2e999cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f2e9997355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f2e9a2dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f2ec9fcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f2ec9fcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f2ec9fcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f2ec9fcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f2ec9fcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f2ec9fcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f2ec9fcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f2ec9fcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f2ec9fcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f2ec9fcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f2eec91f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f2eb9beb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f2eb9c9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f2eb775c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f2eb775c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f2eb776738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f2eb775874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f2eb775874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f2eb775874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f2f007fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f2f0088928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f2f0070699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f2f009b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe830f5a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f2e9995b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-215018326cd11ec2bbc9ad292718c39558dfc37e Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6535 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1052017847 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561d74a05810, 0x561d74bef01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561d74bef020,0x561d76a870e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/215018326cd11ec2bbc9ad292718c39558dfc37e' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8535 processed earlier; will process 2494 files now Step #5: ==235366== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561d6b4fa9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561d71b5f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561d71b425dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561d71b424fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561d6b500d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561d6b461b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561d6b45c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561d6b4f2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561d6e4c1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561d6e4c1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561d6e4c1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561d6e4c1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561d6e4c1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561d6e4c1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561d6e4c1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561d6e4c1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561d6e4c1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561d6e4c1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561d70756f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561d6d483b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561d6d48ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561d6d23ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561d6d23ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561d6d23b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561d6d23a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561d6d23a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561d6d23a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561d71b44abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561d71b4d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561d71b35699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561d71b60112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f23ec284082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561d6b45ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-14e07739692b27074de41eead059a47700a860f6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6536 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1052624380 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558f25902810, 0x558f25aec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558f25aec020,0x558f279840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/14e07739692b27074de41eead059a47700a860f6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8536 processed earlier; will process 2493 files now Step #5: ==235402== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558f1c3f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558f22a5c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558f22a3f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558f22a3f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f1c3fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f1c35eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f1c359355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f1c3efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f1f3bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f1f3bef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f1f3bef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f1f3bef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f1f3bef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f1f3bef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f1f3bef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f1f3bef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f1f3bef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f1f3bef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558f21653f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f1e380b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f1e38bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f1e137c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f1e137c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f1e138738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f1e137874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f1e137874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f1e137874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558f22a41abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558f22a4a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558f22a32699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558f22a5d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe3ad3fa082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f1c357b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6edb6d9add41a17fe14f4e66f61bfb4e1a7d8f05 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6537 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1053172356 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5563cd425810, 0x5563cd60f01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5563cd60f020,0x5563cf4a70e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6edb6d9add41a17fe14f4e66f61bfb4e1a7d8f05' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8537 processed earlier; will process 2492 files now Step #5: #1 pulse cov: 4232 ft: 4233 exec/s: 0 rss: 182Mb Step #5: #2 pulse cov: 14559 ft: 15638 exec/s: 0 rss: 205Mb Step #5: ==235438== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5563c3f1a9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5563ca57f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5563ca5625dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5563ca5624fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5563c3f20d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5563c3e81b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5563c3e7c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5563c3f12c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5563c6ee1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5563c6ee1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5563c6ee1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5563c6ee1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5563c6ee1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5563c6ee1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5563c6ee1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5563c6ee1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5563c6ee1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5563c6ee1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5563c9176f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5563c5ea3b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5563c5eaebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5563c5c5ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5563c5c5ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5563c5c5b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5563c5c5a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5563c5c5a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5563c5c5a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5563ca564abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5563ca56d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5563ca555699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5563ca580112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3978bb4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5563c3e7ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2554146a810bc9c5ad639d9bda4d2fdbe1473364 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6538 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1053878164 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55f7835d9810, 0x55f7837c301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55f7837c3020,0x55f78565b0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2554146a810bc9c5ad639d9bda4d2fdbe1473364' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8540 processed earlier; will process 2489 files now Step #5: ==235474== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55f77a0ce9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55f780733898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55f7807165dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55f7807164fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55f77a0d4d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55f77a035b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55f77a030355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55f77a0c6c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55f77d095f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55f77d095f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55f77d095f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55f77d095f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55f77d095f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55f77d095f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55f77d095f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55f77d095f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55f77d095f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55f77d095f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55f77f32af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55f77c057b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55f77c062be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55f77be0ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55f77be0ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55f77be0f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55f77be0e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55f77be0e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55f77be0e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55f780718abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55f780721928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55f780709699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55f780734112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1077949082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55f77a02eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-9666c210d46dd96b39f1cb323833ddf788f952ec Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6539 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1054583273 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x565402a81810, 0x565402c6b01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x565402c6b020,0x565404b030e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/9666c210d46dd96b39f1cb323833ddf788f952ec' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8541 processed earlier; will process 2488 files now Step #5: ==235510== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5653f95769c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5653ffbdb898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5653ffbbe5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5653ffbbe4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5653f957cd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5653f94ddb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5653f94d8355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5653f956ec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5653fc53df10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5653fc53df10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5653fc53df10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5653fc53df10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5653fc53df10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5653fc53df10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5653fc53df10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5653fc53df10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5653fc53df10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5653fc53df10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5653fe7d2f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5653fb4ffb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5653fb50abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5653fb2b6c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5653fb2b6c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5653fb2b7738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5653fb2b6874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5653fb2b6874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5653fb2b6874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5653ffbc0abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5653ffbc9928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5653ffbb1699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5653ffbdc112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f289a1b4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5653f94d6b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-432e27c6d42df71f00761f3f680989f7ee7df93c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6540 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1055189010 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558f35339810, 0x558f3552301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558f35523020,0x558f373bb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/432e27c6d42df71f00761f3f680989f7ee7df93c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8542 processed earlier; will process 2487 files now Step #5: ==235546== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558f2be2e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558f32493898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558f324765dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558f324764fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558f2be34d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558f2bd95b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558f2bd90355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558f2be26c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558f2edf5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558f2edf5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558f2edf5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558f2edf5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558f2edf5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558f2edf5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558f2edf5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558f2edf5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558f2edf5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558f2edf5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558f3108af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558f2ddb7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558f2ddc2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558f2db6ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558f2db6ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558f2db6f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558f2db6e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558f2db6e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558f2db6e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558f32478abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558f32481928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558f32469699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558f32494112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f59978a0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558f2bd8eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-63f9df053053f1729a4b9583159203a013541363 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6541 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1055820214 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55fb9d45f810, 0x55fb9d64901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55fb9d649020,0x55fb9f4e10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/63f9df053053f1729a4b9583159203a013541363' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8543 processed earlier; will process 2486 files now Step #5: ==235582== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55fb93f549c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55fb9a5b9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55fb9a59c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55fb9a59c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55fb93f5ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55fb93ebbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55fb93eb6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55fb93f4cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55fb96f1bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55fb96f1bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55fb96f1bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55fb96f1bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55fb96f1bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55fb96f1bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55fb96f1bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55fb96f1bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55fb96f1bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55fb96f1bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55fb991b0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55fb95eddb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55fb95ee8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55fb95c94c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55fb95c94c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55fb95c95738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55fb95c94874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55fb95c94874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55fb95c94874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55fb9a59eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55fb9a5a7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55fb9a58f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55fb9a5ba112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9731444082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55fb93eb4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c9694b48966295677e8d96a9e7bb71ab6d6f9949 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6542 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1056426779 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5555cc533810, 0x5555cc71d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5555cc71d020,0x5555ce5b50e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c9694b48966295677e8d96a9e7bb71ab6d6f9949' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8544 processed earlier; will process 2485 files now Step #5: ==235618== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5555c30289c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5555c968d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5555c96705dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5555c96704fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5555c302ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5555c2f8fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5555c2f8a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5555c3020c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5555c5feff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5555c5feff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5555c5feff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5555c5feff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5555c5feff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5555c5feff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5555c5feff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5555c5feff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5555c5feff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5555c5feff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5555c8284f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5555c4fb1b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5555c4fbcbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5555c4d68c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5555c4d68c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5555c4d69738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5555c4d68874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5555c4d68874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5555c4d68874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5555c9672abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5555c967b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5555c9663699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5555c968e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8acd9ab082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5555c2f88b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4021d6d56f4c43d06cb2be0be155a47d840a9761 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6543 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1057417229 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5601ca2a3810, 0x5601ca48d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5601ca48d020,0x5601cc3250e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4021d6d56f4c43d06cb2be0be155a47d840a9761' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8545 processed earlier; will process 2484 files now Step #5: ==235654== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5601c0d989c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5601c73fd898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5601c73e05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5601c73e04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5601c0d9ed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5601c0cffb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5601c0cfa355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5601c0d90c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5601c3d5ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5601c3d5ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5601c3d5ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5601c3d5ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5601c3d5ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5601c3d5ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5601c3d5ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5601c3d5ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5601c3d5ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5601c3d5ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5601c5ff4f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5601c2d21b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5601c2d2cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5601c2ad8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5601c2ad8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5601c2ad9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5601c2ad8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5601c2ad8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5601c2ad8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5601c73e2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5601c73eb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5601c73d3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5601c73fe112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fbe96abd082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5601c0cf8b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4bc44c4fb4961a00ccd33d516e581fd6c8eed99d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6544 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1058154926 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b32ab1f810, 0x55b32ad0901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b32ad09020,0x55b32cba10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4bc44c4fb4961a00ccd33d516e581fd6c8eed99d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8546 processed earlier; will process 2483 files now Step #5: ==235690== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b3216149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b327c79898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b327c5c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b327c5c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b32161ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b32157bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b321576355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b32160cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b3245dbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b3245dbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b3245dbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b3245dbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b3245dbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b3245dbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b3245dbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b3245dbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b3245dbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b3245dbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b326870f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b32359db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b3235a8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b323354c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b323354c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b323355738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b323354874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b323354874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b323354874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b327c5eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b327c67928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b327c4f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b327c7a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f16725bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b321574b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d814ed540f69ad5dbc9ebf8edabfd58465a7c227 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6545 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1058722071 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561b61114810, 0x561b612fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561b612fe020,0x561b631960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d814ed540f69ad5dbc9ebf8edabfd58465a7c227' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8547 processed earlier; will process 2482 files now Step #5: ==235726== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561b57c099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561b5e26e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561b5e2515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561b5e2514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561b57c0fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561b57b70b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561b57b6b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561b57c01c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561b5abd0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561b5abd0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561b5abd0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561b5abd0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561b5abd0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561b5abd0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561b5abd0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561b5abd0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561b5abd0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561b5abd0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561b5ce65f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561b59b92b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561b59b9dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561b59949c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561b59949c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561b5994a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561b59949874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561b59949874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561b59949874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561b5e253abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561b5e25c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561b5e244699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561b5e26f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f38309d4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561b57b69b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1b777a968dac407f5674b7e004bfc801418310f1 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6546 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1059723765 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561a54b5d810, 0x561a54d4701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561a54d47020,0x561a56bdf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b777a968dac407f5674b7e004bfc801418310f1' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8548 processed earlier; will process 2481 files now Step #5: ==235762== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561a4b6529c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561a51cb7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561a51c9a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561a51c9a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561a4b658d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561a4b5b9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561a4b5b4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561a4b64ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561a4e619f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561a4e619f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561a4e619f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561a4e619f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561a4e619f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561a4e619f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561a4e619f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561a4e619f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561a4e619f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561a4e619f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561a508aef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561a4d5dbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561a4d5e6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561a4d392c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561a4d392c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561a4d393738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561a4d392874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561a4d392874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561a4d392874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561a51c9cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561a51ca5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561a51c8d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561a51cb8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f76df2ec082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561a4b5b2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f1e1b6fb13af039b3dfa61fa7b3f1eb8789fe51c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6547 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1060299340 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561565aef810, 0x561565cd901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561565cd9020,0x561567b710e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f1e1b6fb13af039b3dfa61fa7b3f1eb8789fe51c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8549 processed earlier; will process 2480 files now Step #5: ==235798== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56155c5e49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561562c49898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561562c2c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561562c2c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56155c5ead42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56155c54bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56155c546355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56155c5dcc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56155f5abf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56155f5abf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56155f5abf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56155f5abf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56155f5abf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56155f5abf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56155f5abf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56155f5abf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56155f5abf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56155f5abf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561561840f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56155e56db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56155e578be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56155e324c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56155e324c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56155e325738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56155e324874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56155e324874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56155e324874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561562c2eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561562c37928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561562c1f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561562c4a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1784742082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56155c544b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1877c577bde702173a3a8d405c36484636a74fb9 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6548 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1061365103 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ba047c3810, 0x55ba049ad01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ba049ad020,0x55ba068450e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1877c577bde702173a3a8d405c36484636a74fb9' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8550 processed earlier; will process 2479 files now Step #5: ==235834== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b9fb2b89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ba0191d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ba019005dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ba019004fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b9fb2bed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b9fb21fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b9fb21a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b9fb2b0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b9fe27ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b9fe27ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b9fe27ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b9fe27ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b9fe27ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b9fe27ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b9fe27ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b9fe27ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b9fe27ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b9fe27ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ba00514f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b9fd241b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b9fd24cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b9fcff8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b9fcff8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b9fcff9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b9fcff8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b9fcff8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b9fcff8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ba01902abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ba0190b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ba018f3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ba0191e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5c6c838082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b9fb218b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5f28dc29dacd6808d2f21ea66ce877464b31345c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6549 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1063432007 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d987c9d810, 0x55d987e8701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d987e87020,0x55d989d1f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5f28dc29dacd6808d2f21ea66ce877464b31345c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8551 processed earlier; will process 2478 files now Step #5: #1 pulse cov: 4388 ft: 4389 exec/s: 0 rss: 180Mb Step #5: #2 pulse cov: 4650 ft: 5211 exec/s: 0 rss: 181Mb Step #5: ==235870== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d97e7929c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d984df7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d984dda5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d984dda4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d97e798d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d97e6f9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d97e6f4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d97e78ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d981759f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d981759f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d981759f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d981759f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d981759f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d981759f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d981759f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d981759f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d981759f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d981759f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d9839eef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d98071bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d980726be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d9804d2c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d9804d2c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d9804d3738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d9804d2874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d9804d2874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d9804d2874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d984ddcabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d984de5928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d984dcd699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d984df8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f21c0d2f082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d97e6f2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-eb4ee149b3399c170fe1040452c3c1b8a226668c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6550 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1064106065 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55578b6b3810, 0x55578b89d01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55578b89d020,0x55578d7350e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/eb4ee149b3399c170fe1040452c3c1b8a226668c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8554 processed earlier; will process 2475 files now Step #5: ==235906== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5557821a89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55578880d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5557887f05dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5557887f04fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5557821aed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55578210fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55578210a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5557821a0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55578516ff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55578516ff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55578516ff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55578516ff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55578516ff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55578516ff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55578516ff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55578516ff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55578516ff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55578516ff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x555787404f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x555784131b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55578413cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x555783ee8c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x555783ee8c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x555783ee9738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x555783ee8874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x555783ee8874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x555783ee8874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5557887f2abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5557887fb928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5557887e3699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55578880e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa4c5a83082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x555782108b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4413aa347e537f5d8083c00e43a57fe850f2ff32 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6551 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1065461017 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b7a7317810, 0x55b7a750101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b7a7501020,0x55b7a93990e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4413aa347e537f5d8083c00e43a57fe850f2ff32' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8555 processed earlier; will process 2474 files now Step #5: ==235942== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b79de0c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b7a4471898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b7a44545dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b7a44544fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b79de12d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b79dd73b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b79dd6e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b79de04c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b7a0dd3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b7a0dd3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b7a0dd3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b7a0dd3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b7a0dd3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b7a0dd3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b7a0dd3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b7a0dd3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b7a0dd3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b7a0dd3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b7a3068f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b79fd95b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b79fda0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b79fb4cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b79fb4cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b79fb4d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b79fb4c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b79fb4c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b79fb4c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b7a4456abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b7a445f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b7a4447699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b7a4472112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f597d028082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b79dd6cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6c19607c104065d9cdc4a84b4680b6e321f97c55 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6552 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1067538386 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x558e04af3810, 0x558e04cdd01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x558e04cdd020,0x558e06b750e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6c19607c104065d9cdc4a84b4680b6e321f97c55' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8556 processed earlier; will process 2473 files now Step #5: #1 pulse cov: 4278 ft: 4279 exec/s: 0 rss: 180Mb Step #5: ==235978== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x558dfb5e89c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x558e01c4d898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x558e01c305dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x558e01c304fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x558dfb5eed42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558dfb54fb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558dfb54a355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558dfb5e0c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558dfe5aff10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558dfe5aff10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558dfe5aff10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558dfe5aff10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558dfe5aff10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558dfe5aff10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558dfe5aff10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558dfe5aff10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558dfe5aff10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558dfe5aff10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x558e00844f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558dfd571b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558dfd57cbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558dfd328c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558dfd328c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558dfd329738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558dfd328874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558dfd328874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558dfd328874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x558e01c32abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x558e01c3b928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x558e01c23699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x558e01c4e112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7faae84f6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558dfb548b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e6a87b1104c37c06f85b6c932a12e352b2b46254 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6553 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1068294620 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bafe2a2810, 0x55bafe48c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bafe48c020,0x55bb003240e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e6a87b1104c37c06f85b6c932a12e352b2b46254' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8558 processed earlier; will process 2471 files now Step #5: #1 pulse cov: 3856 ft: 3857 exec/s: 0 rss: 182Mb Step #5: #2 pulse cov: 4126 ft: 4586 exec/s: 0 rss: 183Mb Step #5: #4 pulse cov: 4372 ft: 5756 exec/s: 0 rss: 185Mb Step #5: ==236014== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55baf4d979c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bafb3fc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bafb3df5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bafb3df4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55baf4d9dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55baf4cfeb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55baf4cf9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55baf4d8fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55baf7d5ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55baf7d5ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55baf7d5ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55baf7d5ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55baf7d5ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55baf7d5ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55baf7d5ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55baf7d5ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55baf7d5ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55baf7d5ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55baf9ff3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55baf6d20b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55baf6d2bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55baf6ad7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55baf6ad7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55baf6ad8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55baf6ad7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55baf6ad7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55baf6ad7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bafb3e1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bafb3ea928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bafb3d2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bafb3fd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f8602226082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55baf4cf7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-d20c63f7801d07fe6523cd7c220b85858bfa0a63 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6554 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1069029655 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55829e544810, 0x55829e72e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55829e72e020,0x5582a05c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/d20c63f7801d07fe6523cd7c220b85858bfa0a63' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8563 processed earlier; will process 2466 files now Step #5: ==236050== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5582950399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55829b69e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55829b6815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55829b6814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55829503fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x558294fa0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x558294f9b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x558295031c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x558298000f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x558298000f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x558298000f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x558298000f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x558298000f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x558298000f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x558298000f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x558298000f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x558298000f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x558298000f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55829a295f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x558296fc2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x558296fcdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x558296d79c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x558296d79c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x558296d7a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x558296d79874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x558296d79874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x558296d79874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55829b683abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55829b68c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55829b674699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55829b69f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f6e9b9e5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x558294f99b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bf81a0f363da837349b4e2a87ebf28c6f3ade409 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6555 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1069633469 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560b3f5b4810, 0x560b3f79e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560b3f79e020,0x560b416360e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf81a0f363da837349b4e2a87ebf28c6f3ade409' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8564 processed earlier; will process 2465 files now Step #5: #1 pulse cov: 3805 ft: 3806 exec/s: 0 rss: 181Mb Step #5: #2 pulse cov: 4273 ft: 4730 exec/s: 0 rss: 182Mb Step #5: ==236086== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560b360a99c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560b3c70e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560b3c6f15dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560b3c6f14fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560b360afd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560b36010b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560b3600b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560b360a1c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560b39070f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560b39070f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560b39070f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560b39070f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560b39070f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560b39070f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560b39070f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560b39070f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560b39070f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560b39070f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560b3b305f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560b38032b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560b3803dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560b37de9c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560b37de9c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560b37dea738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560b37de9874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560b37de9874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560b37de9874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560b3c6f3abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560b3c6fc928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560b3c6e4699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560b3c70f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa666bd0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560b36009b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-81a96e4918ebdcdbf23c91bd186ced232e6ac7ea Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6556 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1071456321 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5652ce0aa810, 0x5652ce29401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5652ce294020,0x5652d012c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/81a96e4918ebdcdbf23c91bd186ced232e6ac7ea' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8567 processed earlier; will process 2462 files now Step #5: ==236122== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5652c4b9f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5652cb204898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5652cb1e75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5652cb1e74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5652c4ba5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5652c4b06b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5652c4b01355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5652c4b97c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5652c7b66f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5652c7b66f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5652c7b66f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5652c7b66f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5652c7b66f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5652c7b66f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5652c7b66f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5652c7b66f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5652c7b66f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5652c7b66f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5652c9dfbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5652c6b28b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5652c6b33be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5652c68dfc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5652c68dfc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5652c68e0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5652c68df874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5652c68df874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5652c68df874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5652cb1e9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5652cb1f2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5652cb1da699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5652cb205112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f2c58be5082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5652c4affb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e537dc86bc9c38037434eb17f5a924649641c0ff Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6557 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1072148483 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561dc8614810, 0x561dc87fe01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561dc87fe020,0x561dca6960e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e537dc86bc9c38037434eb17f5a924649641c0ff' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8568 processed earlier; will process 2461 files now Step #5: ==236158== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561dbf1099c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x561dc576e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x561dc57515dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x561dc57514fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561dbf10fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561dbf070b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561dbf06b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561dbf101c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561dc20d0f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561dc20d0f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561dc20d0f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561dc20d0f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561dc20d0f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561dc20d0f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561dc20d0f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561dc20d0f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561dc20d0f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561dc20d0f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x561dc4365f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561dc1092b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561dc109dbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561dc0e49c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561dc0e49c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561dc0e4a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561dc0e49874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561dc0e49874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561dc0e49874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x561dc5753abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x561dc575c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x561dc5744699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x561dc576f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f19fab2e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561dbf069b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-4a95a3fe58f9cfe1244b14ff8ce1326ca059502f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6558 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1073613557 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560794607810, 0x5607947f101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5607947f1020,0x5607966890e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/4a95a3fe58f9cfe1244b14ff8ce1326ca059502f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8569 processed earlier; will process 2460 files now Step #5: #1 pulse cov: 4374 ft: 4375 exec/s: 0 rss: 180Mb Step #5: ==236194== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56078b0fc9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560791761898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5607917445dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5607917444fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56078b102d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56078b063b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56078b05e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56078b0f4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56078e0c3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56078e0c3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56078e0c3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56078e0c3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56078e0c3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56078e0c3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56078e0c3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56078e0c3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56078e0c3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56078e0c3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560790358f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56078d085b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56078d090be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56078ce3cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56078ce3cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56078ce3d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56078ce3c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56078ce3c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56078ce3c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560791746abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56079174f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560791737699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560791762112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f90346b1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56078b05cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-03d4229fbea0e71799b2c31ebd82a06f52ea7f31 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6559 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1074222915 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed6280d810, 0x55ed629f701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed629f7020,0x55ed6488f0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/03d4229fbea0e71799b2c31ebd82a06f52ea7f31' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8571 processed earlier; will process 2458 files now Step #5: ==236230== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed593029c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed5f967898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed5f94a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed5f94a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed59308d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed59269b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed59264355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed592fac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed5c2c9f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed5c2c9f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed5c2c9f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed5c2c9f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed5c2c9f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed5c2c9f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed5c2c9f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed5c2c9f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed5c2c9f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed5c2c9f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed5e55ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed5b28bb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed5b296be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed5b042c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed5b042c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed5b043738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed5b042874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed5b042874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed5b042874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed5f94cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed5f955928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed5f93d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed5f968112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f00effa8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed59262b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bc55bac0de3d81a4b1ba14ccd8b38627d1973469 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6560 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1074789492 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56055b0e6810, 0x56055b2d001c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56055b2d0020,0x56055d1680e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bc55bac0de3d81a4b1ba14ccd8b38627d1973469' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8572 processed earlier; will process 2457 files now Step #5: #1 pulse cov: 4317 ft: 4318 exec/s: 0 rss: 181Mb Step #5: ==236266== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560551bdb9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560558240898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605582235dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605582234fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560551be1d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560551b42b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560551b3d355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560551bd3c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560554ba2f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560554ba2f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560554ba2f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560554ba2f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560554ba2f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560554ba2f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560554ba2f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560554ba2f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560554ba2f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560554ba2f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560556e37f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560553b64b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560553b6fbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56055391bc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56055391bc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56055391c738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56055391b874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56055391b874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56055391b874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560558225abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56055822e928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560558216699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560558241112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f88fdf51082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560551b3bb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-425ef64c5fa080b36d0a0ecf8a72e46c32a8c3ed Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6561 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1075420699 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d192882810, 0x55d192a6c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d192a6c020,0x55d1949040e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/425ef64c5fa080b36d0a0ecf8a72e46c32a8c3ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8574 processed earlier; will process 2455 files now Step #5: ==236302== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55d1893779c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55d18f9dc898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55d18f9bf5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55d18f9bf4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55d18937dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55d1892deb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55d1892d9355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55d18936fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55d18c33ef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55d18c33ef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55d18c33ef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55d18c33ef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55d18c33ef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55d18c33ef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55d18c33ef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55d18c33ef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55d18c33ef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55d18c33ef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55d18e5d3f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55d18b300b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55d18b30bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55d18b0b7c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55d18b0b7c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55d18b0b8738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55d18b0b7874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55d18b0b7874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55d18b0b7874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55d18f9c1abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55d18f9ca928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55d18f9b2699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55d18f9dd112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f07cd315082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55d1892d7b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8c4d85697e70f1c7849e0246d0875e9b0b41bcfd Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6562 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1075971341 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a154410810, 0x55a1545fa01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a1545fa020,0x55a1564920e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8c4d85697e70f1c7849e0246d0875e9b0b41bcfd' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8575 processed earlier; will process 2454 files now Step #5: #1 pulse cov: 4212 ft: 4213 exec/s: 0 rss: 182Mb Step #5: ==236338== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a14af059c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a15156a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a15154d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a15154d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a14af0bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a14ae6cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a14ae67355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a14aefdc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a14deccf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a14deccf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a14deccf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a14deccf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a14deccf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a14deccf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a14deccf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a14deccf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a14deccf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a14deccf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a150161f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a14ce8eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a14ce99be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a14cc45c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a14cc45c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a14cc46738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a14cc45874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a14cc45874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a14cc45874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a15154fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a151558928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a151540699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a15156b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1a9fe2e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a14ae65b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-09c96c5a2cec727337498c8cc9ceee6926e1f679 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6563 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1078054005 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560a0da4d810, 0x560a0dc3701c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560a0dc37020,0x560a0facf0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/09c96c5a2cec727337498c8cc9ceee6926e1f679' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8577 processed earlier; will process 2452 files now Step #5: ==236374== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560a045429c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560a0aba7898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560a0ab8a5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560a0ab8a4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560a04548d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560a044a9b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560a044a4355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560a0453ac85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560a07509f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560a07509f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560a07509f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560a07509f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560a07509f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560a07509f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560a07509f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560a07509f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560a07509f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560a07509f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560a0979ef7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560a064cbb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560a064d6be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560a06282c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560a06282c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560a06283738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560a06282874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560a06282874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560a06282874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560a0ab8cabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560a0ab95928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560a0ab7d699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560a0aba8112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f25a766a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560a044a2b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-92277ca68969d18fba782c0e85519a0212bafb6f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6564 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1078687041 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5619a86e5810, 0x5619a88cf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5619a88cf020,0x5619aa7670e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/92277ca68969d18fba782c0e85519a0212bafb6f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8578 processed earlier; will process 2451 files now Step #5: ==236410== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56199f1da9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5619a583f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5619a58225dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5619a58224fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56199f1e0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56199f141b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56199f13c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56199f1d2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5619a21a1f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5619a21a1f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5619a21a1f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5619a21a1f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5619a21a1f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5619a21a1f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5619a21a1f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5619a21a1f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5619a21a1f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5619a21a1f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5619a4436f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5619a1163b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5619a116ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5619a0f1ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5619a0f1ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5619a0f1b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5619a0f1a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5619a0f1a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5619a0f1a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5619a5824abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5619a582d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5619a5815699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5619a5840112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd8a1c56082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56199f13ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-594feea015bcf8b634c95e91ad2cce4bdc42b5f4 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6565 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1079269913 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55a0a3622810, 0x55a0a380c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55a0a380c020,0x55a0a56a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/594feea015bcf8b634c95e91ad2cce4bdc42b5f4' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8579 processed earlier; will process 2450 files now Step #5: #1 pulse cov: 3851 ft: 3852 exec/s: 0 rss: 182Mb Step #5: ==236446== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55a09a1179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55a0a077c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55a0a075f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55a0a075f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55a09a11dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55a09a07eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55a09a079355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55a09a10fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55a09d0def10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55a09d0def10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55a09d0def10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55a09d0def10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55a09d0def10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55a09d0def10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55a09d0def10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55a09d0def10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55a09d0def10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55a09d0def10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55a09f373f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55a09c0a0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55a09c0abbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55a09be57c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55a09be57c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55a09be58738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55a09be57874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55a09be57874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55a09be57874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55a0a0761abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55a0a076a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55a0a0752699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55a0a077d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0e86c26082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55a09a077b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1ef144b4547087e63adfc2a5d66d996c888b367c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6566 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1081430733 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x559abbdb7810, 0x559abbfa101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x559abbfa1020,0x559abde390e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1ef144b4547087e63adfc2a5d66d996c888b367c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8581 processed earlier; will process 2448 files now Step #5: #1 pulse cov: 4075 ft: 4076 exec/s: 0 rss: 181Mb Step #5: ==236482== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x559ab28ac9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x559ab8f11898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x559ab8ef45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x559ab8ef44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x559ab28b2d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x559ab2813b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x559ab280e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x559ab28a4c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x559ab5873f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x559ab5873f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x559ab5873f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x559ab5873f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x559ab5873f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x559ab5873f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x559ab5873f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x559ab5873f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x559ab5873f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x559ab5873f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x559ab7b08f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x559ab4835b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x559ab4840be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x559ab45ecc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x559ab45ecc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x559ab45ed738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x559ab45ec874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x559ab45ec874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x559ab45ec874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x559ab8ef6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x559ab8eff928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x559ab8ee7699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x559ab8f12112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ff2961fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x559ab280cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e65ccdb3ab2d48b9050c8d35fb359092506df81b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6567 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1082192943 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556c80667810, 0x556c8085101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556c80851020,0x556c826e90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e65ccdb3ab2d48b9050c8d35fb359092506df81b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8583 processed earlier; will process 2446 files now Step #5: #1 pulse cov: 4095 ft: 4096 exec/s: 0 rss: 182Mb Step #5: ==236518== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556c7715c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556c7d7c1898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556c7d7a45dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556c7d7a44fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556c77162d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556c770c3b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556c770be355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556c77154c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556c7a123f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556c7a123f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556c7a123f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556c7a123f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556c7a123f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556c7a123f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556c7a123f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556c7a123f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556c7a123f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556c7a123f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556c7c3b8f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556c790e5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556c790f0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556c78e9cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556c78e9cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556c78e9d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556c78e9c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556c78e9c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556c78e9c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556c7d7a6abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556c7d7af928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556c7d797699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556c7d7c2112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f09c9dba082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556c770bcb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-14f977c72e4bce8648ae58039689086da7918f2c Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6568 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1082930716 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56251ec4a810, 0x56251ee3401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56251ee34020,0x562520ccc0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/14f977c72e4bce8648ae58039689086da7918f2c' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8585 processed earlier; will process 2444 files now Step #5: ==236554== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56251573f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56251bda4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56251bd875dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56251bd874fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562515745d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5625156a6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5625156a1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562515737c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562518706f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562518706f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562518706f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562518706f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562518706f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562518706f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562518706f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562518706f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562518706f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562518706f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56251a99bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5625176c8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5625176d3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56251747fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56251747fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x562517480738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56251747f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56251747f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56251747f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56251bd89abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56251bd92928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56251bd7a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56251bda5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f3c79c9c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56251569fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e42ac6ff2c2b50e01a695d24345f9af513e70522 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6569 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1083497410 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56376d669810, 0x56376d85301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56376d853020,0x56376f6eb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e42ac6ff2c2b50e01a695d24345f9af513e70522' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8586 processed earlier; will process 2443 files now Step #5: #1 pulse cov: 11693 ft: 11694 exec/s: 0 rss: 199Mb Step #5: ==236590== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56376415e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56376a7c3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56376a7a65dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56376a7a64fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x563764164d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5637640c5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5637640c0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x563764156c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x563767125f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x563767125f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x563767125f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x563767125f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x563767125f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x563767125f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x563767125f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x563767125f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x563767125f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x563767125f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5637693baf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5637660e7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5637660f2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x563765e9ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x563765e9ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x563765e9f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x563765e9e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x563765e9e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x563765e9e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56376a7a8abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56376a7b1928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56376a799699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56376a7c4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f853a3df082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5637640beb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-8e5c746e5df63003b69d832572c2718dfe43251a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6570 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1084151522 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56431e7fa810, 0x56431e9e401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56431e9e4020,0x56432087c0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/8e5c746e5df63003b69d832572c2718dfe43251a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8588 processed earlier; will process 2441 files now Step #5: #1 pulse cov: 4022 ft: 4023 exec/s: 0 rss: 178Mb Step #5: ==236626== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5643152ef9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56431b954898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56431b9375dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56431b9374fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5643152f5d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x564315256b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564315251355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5643152e7c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5643182b6f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5643182b6f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5643182b6f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5643182b6f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5643182b6f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5643182b6f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5643182b6f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5643182b6f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5643182b6f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5643182b6f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56431a54bf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564317278b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564317283be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56431702fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56431702fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x564317030738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56431702f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56431702f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56431702f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56431b939abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56431b942928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56431b92a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56431b955112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd2cd875082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56431524fb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-3c1024a38336b0e74c2134108efe431444c5f00a Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6571 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1085570649 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e603902810, 0x55e603aec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e603aec020,0x55e6059840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/3c1024a38336b0e74c2134108efe431444c5f00a' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8590 processed earlier; will process 2439 files now Step #5: ==236662== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e5fa3f79c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e600a5c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e600a3f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e600a3f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e5fa3fdd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e5fa35eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e5fa359355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e5fa3efc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e5fd3bef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e5fd3bef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e5fd3bef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e5fd3bef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e5fd3bef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e5fd3bef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e5fd3bef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e5fd3bef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e5fd3bef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e5fd3bef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e5ff653f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e5fc380b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e5fc38bbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e5fc137c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e5fc137c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e5fc138738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e5fc137874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e5fc137874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e5fc137874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e600a41abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e600a4a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e600a32699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e600a5d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f685565e082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e5fa357b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-33a8226bfb67f1ae55de83c726b17806984d35d6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6572 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1086815280 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560e3cace810, 0x560e3ccb801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560e3ccb8020,0x560e3eb500e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/33a8226bfb67f1ae55de83c726b17806984d35d6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8591 processed earlier; will process 2438 files now Step #5: ==236698== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560e335c39c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560e39c28898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560e39c0b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560e39c0b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560e335c9d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560e3352ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560e33525355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560e335bbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560e3658af10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560e3658af10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560e3658af10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560e3658af10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560e3658af10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560e3658af10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560e3658af10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560e3658af10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560e3658af10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560e3658af10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560e3881ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560e3554cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560e35557be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560e35303c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560e35303c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560e35304738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560e35303874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560e35303874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560e35303874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560e39c0dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560e39c16928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560e39bfe699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560e39c29112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f95729ff082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560e33523b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-ee74f7092202da38f4554620f1437cb8ecf980be Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6573 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1087399169 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x557996b2b810, 0x557996d1501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x557996d15020,0x557998bad0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/ee74f7092202da38f4554620f1437cb8ecf980be' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8592 processed earlier; will process 2437 files now Step #5: ==236734== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55798d6209c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x557993c85898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x557993c685dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x557993c684fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55798d626d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55798d587b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55798d582355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55798d618c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5579905e7f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5579905e7f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5579905e7f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5579905e7f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5579905e7f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5579905e7f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5579905e7f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5579905e7f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5579905e7f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5579905e7f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55799287cf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55798f5a9b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55798f5b4be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55798f360c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55798f360c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55798f361738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55798f360874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55798f360874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55798f360874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x557993c6aabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x557993c73928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x557993c5b699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x557993c86112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f9b21782082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55798d580b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e872135fdb961c28ce5119c1159ebf43e51a761d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6574 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1088057349 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ccf0030810, 0x55ccf021a01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ccf021a020,0x55ccf20b20e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e872135fdb961c28ce5119c1159ebf43e51a761d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8593 processed earlier; will process 2436 files now Step #5: ==236770== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55cce6b259c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55cced18a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55cced16d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55cced16d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55cce6b2bd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55cce6a8cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55cce6a87355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55cce6b1dc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55cce9aecf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55cce9aecf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55cce9aecf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55cce9aecf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55cce9aecf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55cce9aecf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55cce9aecf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55cce9aecf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55cce9aecf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55cce9aecf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ccebd81f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55cce8aaeb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55cce8ab9be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55cce8865c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55cce8865c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55cce8866738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55cce8865874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55cce8865874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55cce8865874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55cced16fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55cced178928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55cced160699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55cced18b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f68facc8082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55cce6a85b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0e2b8e39cc540a71e1933b82282e662ebbd97eb0 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6575 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1088816335 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56245ee49810, 0x56245f03301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56245f033020,0x562460ecb0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0e2b8e39cc540a71e1933b82282e662ebbd97eb0' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8594 processed earlier; will process 2435 files now Step #5: ==236806== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56245593e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56245bfa3898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56245bf865dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56245bf864fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x562455944d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5624558a5b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5624558a0355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x562455936c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x562458905f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x562458905f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x562458905f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x562458905f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x562458905f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x562458905f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x562458905f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x562458905f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x562458905f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x562458905f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56245ab9af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5624578c7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5624578d2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56245767ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56245767ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56245767f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56245767e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56245767e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56245767e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56245bf88abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56245bf91928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56245bf79699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56245bfa4112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fc840854082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56245589eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-59cf406580c172c88606a0759fd9a6ac3845151d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6576 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1089844581 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5606f7328810, 0x5606f751201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5606f7512020,0x5606f93aa0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/59cf406580c172c88606a0759fd9a6ac3845151d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8595 processed earlier; will process 2434 files now Step #5: #1 pulse cov: 11755 ft: 11756 exec/s: 0 rss: 198Mb Step #5: #2 pulse cov: 12852 ft: 13718 exec/s: 0 rss: 201Mb Step #5: ==236842== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5606ede1d9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5606f4482898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5606f44655dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5606f44654fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5606ede23d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5606edd84b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5606edd7f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5606ede15c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5606f0de4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5606f0de4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5606f0de4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5606f0de4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5606f0de4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5606f0de4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5606f0de4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5606f0de4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5606f0de4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5606f0de4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5606f3079f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5606efda6b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5606efdb1be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5606efb5dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5606efb5dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5606efb5e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5606efb5d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5606efb5d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5606efb5d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5606f4467abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5606f4470928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5606f4458699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5606f4483112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7ffa6e8ae082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5606edd7db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-5fb5e9db72012d84251dd1e451435538220e0321 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6577 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1090637043 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x561052dc5810, 0x561052faf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x561052faf020,0x561054e470e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/5fb5e9db72012d84251dd1e451435538220e0321' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8599 processed earlier; will process 2430 files now Step #5: ==236878== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5610498ba9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56104ff1f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56104ff025dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56104ff024fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5610498c0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561049821b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56104981c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5610498b2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56104c881f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56104c881f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56104c881f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56104c881f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56104c881f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56104c881f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56104c881f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56104c881f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56104c881f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56104c881f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56104eb16f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56104b843b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56104b84ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56104b5fac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56104b5fac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56104b5fb738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56104b5fa874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56104b5fa874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56104b5fa874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56104ff04abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56104ff0d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56104fef5699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56104ff20112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fcfcd6be082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56104981ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-c7b3fb95eb52d012eb1492660e2587ccb83c5d5d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6578 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1091288344 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5605858bf810, 0x560585aa901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560585aa9020,0x5605879410e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/c7b3fb95eb52d012eb1492660e2587ccb83c5d5d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8600 processed earlier; will process 2429 files now Step #5: #1 pulse cov: 3687 ft: 3688 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 12174 ft: 13058 exec/s: 0 rss: 199Mb Step #5: ==236914== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56057c3b49c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560582a19898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5605829fc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5605829fc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56057c3bad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56057c31bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56057c316355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56057c3acc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56057f37bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56057f37bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56057f37bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56057f37bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56057f37bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56057f37bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56057f37bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56057f37bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56057f37bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56057f37bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560581610f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56057e33db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56057e348be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56057e0f4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56057e0f4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56057e0f5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56057e0f4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56057e0f4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56057e0f4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5605829feabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560582a07928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5605829ef699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560582a1a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fd63b51a082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56057c314b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2b03ef46b178c6c60496cbf86595db50a7a6ae55 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6579 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1092758002 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x556fcf86a810, 0x556fcfa5401c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x556fcfa54020,0x556fd18ec0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2b03ef46b178c6c60496cbf86595db50a7a6ae55' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8603 processed earlier; will process 2426 files now Step #5: #1 pulse cov: 4083 ft: 4084 exec/s: 0 rss: 179Mb Step #5: #2 pulse cov: 4215 ft: 4696 exec/s: 0 rss: 180Mb Step #5: #4 pulse cov: 5051 ft: 6314 exec/s: 0 rss: 182Mb Step #5: ==236950== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x556fc635f9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x556fcc9c4898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x556fcc9a75dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x556fcc9a74fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x556fc6365d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x556fc62c6b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x556fc62c1355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x556fc6357c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x556fc9326f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x556fc9326f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x556fc9326f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x556fc9326f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x556fc9326f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x556fc9326f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x556fc9326f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x556fc9326f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x556fc9326f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x556fc9326f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x556fcb5bbf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x556fc82e8b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x556fc82f3be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x556fc809fc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x556fc809fc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x556fc80a0738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x556fc809f874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x556fc809f874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x556fc809f874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x556fcc9a9abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x556fcc9b2928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x556fcc99a699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x556fcc9c5112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f5af48e3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x556fc62bfb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-0a085dfccf8c3df73f480a2f7d2bf6d474dddf44 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6580 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1093627114 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b6d39ab810, 0x55b6d3b9501c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b6d3b95020,0x55b6d5a2d0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/0a085dfccf8c3df73f480a2f7d2bf6d474dddf44' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8611 processed earlier; will process 2418 files now Step #5: ==236986== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b6ca4a09c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b6d0b05898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b6d0ae85dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b6d0ae84fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b6ca4a6d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b6ca407b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b6ca402355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b6ca498c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b6cd467f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b6cd467f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b6cd467f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b6cd467f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b6cd467f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b6cd467f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b6cd467f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b6cd467f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b6cd467f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b6cd467f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b6cf6fcf7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b6cc429b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b6cc434be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b6cc1e0c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b6cc1e0c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b6cc1e1738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b6cc1e0874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b6cc1e0874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b6cc1e0874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b6d0aeaabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b6d0af3928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b6d0adb699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b6d0b06112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f0f606b9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b6ca400b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-a8c2574debe15c7dfa8412381bb1c3d4ad0a1570 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6581 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1094643041 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5614d8c08810, 0x5614d8df201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5614d8df2020,0x5614dac8a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/a8c2574debe15c7dfa8412381bb1c3d4ad0a1570' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8612 processed earlier; will process 2417 files now Step #5: ==237022== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5614cf6fd9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x5614d5d62898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x5614d5d455dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x5614d5d454fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x5614cf703d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x5614cf664b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x5614cf65f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5614cf6f5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5614d26c4f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5614d26c4f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5614d26c4f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5614d26c4f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5614d26c4f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5614d26c4f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5614d26c4f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5614d26c4f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5614d26c4f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5614d26c4f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x5614d4959f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5614d1686b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5614d1691be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5614d143dc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5614d143dc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5614d143e738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5614d143d874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5614d143d874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5614d143d874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x5614d5d47abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x5614d5d50928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x5614d5d38699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x5614d5d63112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f33ffc14082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x5614cf65db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-1b8e506e96487079acf13d5145009d0ac24bdf4f Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6582 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1095251217 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55b95207f810, 0x55b95226901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55b952269020,0x55b9541010e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/1b8e506e96487079acf13d5145009d0ac24bdf4f' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8613 processed earlier; will process 2416 files now Step #5: ==237058== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55b948b749c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55b94f1d9898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55b94f1bc5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55b94f1bc4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55b948b7ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55b948adbb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55b948ad6355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55b948b6cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55b94bb3bf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55b94bb3bf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55b94bb3bf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55b94bb3bf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55b94bb3bf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55b94bb3bf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55b94bb3bf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55b94bb3bf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55b94bb3bf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55b94bb3bf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55b94ddd0f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55b94aafdb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55b94ab08be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55b94a8b4c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55b94a8b4c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55b94a8b5738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55b94a8b4874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55b94a8b4874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55b94a8b4874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55b94f1beabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55b94f1c7928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55b94f1af699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55b94f1da112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f86addf3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55b948ad4b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-972a7ed4cef5235352cd920d7912f6a9e0c6402d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6583 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1096203483 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564317cb8810, 0x564317ea201c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564317ea2020,0x564319d3a0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/972a7ed4cef5235352cd920d7912f6a9e0c6402d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8614 processed earlier; will process 2415 files now Step #5: ==237094== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56430e7ad9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564314e12898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564314df55dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564314df54fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56430e7b3d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56430e714b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56430e70f355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56430e7a5c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x564311774f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x564311774f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x564311774f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x564311774f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x564311774f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x564311774f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x564311774f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x564311774f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x564311774f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x564311774f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564313a09f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x564310736b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x564310741be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x5643104edc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x5643104edc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x5643104ee738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x5643104ed874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x5643104ed874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x5643104ed874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564314df7abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564314e00928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564314de8699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564314e13112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f4b960fc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56430e70db2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-f42e36b8f70a625e3d1aaaaf40c8ba242f86504b Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6584 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1096810857 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x560f23644810, 0x560f2382e01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x560f2382e020,0x560f256c60e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/f42e36b8f70a625e3d1aaaaf40c8ba242f86504b' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8615 processed earlier; will process 2414 files now Step #5: #1 pulse cov: 3983 ft: 3984 exec/s: 0 rss: 180Mb Step #5: ==237130== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x560f1a1399c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x560f2079e898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x560f207815dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x560f207814fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x560f1a13fd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x560f1a0a0b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x560f1a09b355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x560f1a131c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x560f1d100f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x560f1d100f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x560f1d100f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x560f1d100f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x560f1d100f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x560f1d100f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x560f1d100f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x560f1d100f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x560f1d100f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x560f1d100f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x560f1f395f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x560f1c0c2b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x560f1c0cdbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x560f1be79c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x560f1be79c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x560f1be7a738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x560f1be79874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x560f1be79874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x560f1be79874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x560f20783abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x560f2078c928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x560f20774699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x560f2079f112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1c2cb2d082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x560f1a099b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-6699a1797bd3a2bf78cd616caf9c4e137957c3fe Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6585 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1097466600 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x564998d37810, 0x564998f2101c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x564998f21020,0x56499adb90e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/6699a1797bd3a2bf78cd616caf9c4e137957c3fe' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8617 processed earlier; will process 2412 files now Step #5: #1 pulse cov: 4237 ft: 4238 exec/s: 0 rss: 181Mb Step #5: ==237166== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x56498f82c9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x564995e91898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x564995e745dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x564995e744fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x56498f832d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56498f793b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x56498f78e355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x56498f824c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x5649927f3f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x5649927f3f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x5649927f3f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x5649927f3f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x5649927f3f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x5649927f3f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x5649927f3f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x5649927f3f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x5649927f3f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x5649927f3f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x564994a88f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x5649917b5b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x5649917c0be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56499156cc6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56499156cc6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56499156d738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56499156c874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56499156c874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56499156c874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x564995e76abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x564995e7f928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x564995e67699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x564995e92112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f70f19d9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x56498f78cb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-2e8d2d8c70af277a8f28ba9b124b11b6c393f982 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6586 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1098454108 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bff95d5810, 0x55bff97bf01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bff97bf020,0x55bffb6570e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/2e8d2d8c70af277a8f28ba9b124b11b6c393f982' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8619 processed earlier; will process 2410 files now Step #5: ==237202== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bff00ca9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bff672f898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bff67125dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bff67124fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bff00d0d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bff0031b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bff002c355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bff00c2c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bff3091f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bff3091f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bff3091f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bff3091f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bff3091f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bff3091f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bff3091f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bff3091f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bff3091f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bff3091f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bff5326f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bff2053b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bff205ebe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bff1e0ac6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bff1e0ac6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bff1e0b738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bff1e0a874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bff1e0a874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bff1e0a874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bff6714abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bff671d928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bff6705699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bff6730112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f45e60c3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bff002ab2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-99d63d9fb41d70bb4ae95227de1031e1997592f2 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6587 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1100549965 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e24a400810, 0x55e24a5ea01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e24a5ea020,0x55e24c4820e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/99d63d9fb41d70bb4ae95227de1031e1997592f2' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8620 processed earlier; will process 2409 files now Step #5: ==237238== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e240ef59c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e24755a898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e24753d5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e24753d4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e240efbd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e240e5cb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e240e57355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e240eedc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e243ebcf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e243ebcf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e243ebcf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e243ebcf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e243ebcf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e243ebcf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e243ebcf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e243ebcf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e243ebcf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e243ebcf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e246151f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e242e7eb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e242e89be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e242c35c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e242c35c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e242c36738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e242c35874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e242c35874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e242c35874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e24753fabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e247548928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e247530699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e24755b112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f644411c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e240e55b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-47524fb265ff34e8c93c99bb8aa75af95c1e4bc6 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6588 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1101146765 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55e862529810, 0x55e86271301c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55e862713020,0x55e8645ab0e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/47524fb265ff34e8c93c99bb8aa75af95c1e4bc6' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8621 processed earlier; will process 2408 files now Step #5: ==237274== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55e85901e9c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55e85f683898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55e85f6665dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55e85f6664fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55e859024d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55e858f85b1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55e858f80355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55e859016c85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55e85bfe5f10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55e85bfe5f10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55e85bfe5f10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55e85bfe5f10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55e85bfe5f10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55e85bfe5f10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55e85bfe5f10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55e85bfe5f10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55e85bfe5f10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55e85bfe5f10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55e85e27af7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55e85afa7b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55e85afb2be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55e85ad5ec6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55e85ad5ec6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55e85ad5f738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55e85ad5e874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55e85ad5e874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55e85ad5e874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55e85f668abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55e85f671928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55e85f659699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55e85f684112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fa9828c9082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55e858f7eb2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-e35e5ed2bfc1f52b1dd6248f5c93489f5ab5daa8 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6589 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1101729142 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55ed21d1f810, 0x55ed21f0901c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55ed21f09020,0x55ed23da10e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/e35e5ed2bfc1f52b1dd6248f5c93489f5ab5daa8' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8622 processed earlier; will process 2407 files now Step #5: ==237310== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55ed188149c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55ed1ee79898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55ed1ee5c5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55ed1ee5c4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55ed1881ad42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55ed1877bb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55ed18776355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55ed1880cc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55ed1b7dbf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55ed1b7dbf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55ed1b7dbf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55ed1b7dbf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55ed1b7dbf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55ed1b7dbf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55ed1b7dbf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55ed1b7dbf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55ed1b7dbf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55ed1b7dbf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55ed1da70f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55ed1a79db78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55ed1a7a8be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55ed1a554c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55ed1a554c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55ed1a555738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55ed1a554874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55ed1a554874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55ed1a554874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55ed1ee5eabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55ed1ee67928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55ed1ee4f699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55ed1ee7a112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f1847317082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55ed18774b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-bf494112281920f79d42362a88be8b6b76d82727 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6590 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1102316217 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x56108f022810, 0x56108f20c01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x56108f20c020,0x5610910a40e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/bf494112281920f79d42362a88be8b6b76d82727' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8623 processed earlier; will process 2406 files now Step #5: #1 pulse cov: 4285 ft: 4286 exec/s: 0 rss: 183Mb Step #5: ==237346== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x561085b179c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56108c17c898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56108c15f5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56108c15f4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x561085b1dd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x561085a7eb1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x561085a79355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x561085b0fc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x561088adef10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x561088adef10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x561088adef10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x561088adef10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x561088adef10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x561088adef10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x561088adef10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x561088adef10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x561088adef10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x561088adef10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56108ad73f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x561087aa0b78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x561087aabbe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x561087857c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x561087857c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x561087858738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x561087857874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x561087857874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x561087857874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56108c161abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56108c16a928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56108c152699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56108c17d112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f74d7f91082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x561085a77b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-348390348601bb5e46c8b16fe362e202f4d6f48d Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6591 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1104421560 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55bcf9801810, 0x55bcf99eb01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55bcf99eb020,0x55bcfb8830e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/348390348601bb5e46c8b16fe362e202f4d6f48d' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8625 processed earlier; will process 2404 files now Step #5: ==237382== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x55bcf02f69c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x55bcf695b898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x55bcf693e5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x55bcf693e4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x55bcf02fcd42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x55bcf025db1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x55bcf0258355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x55bcf02eec85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x55bcf32bdf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x55bcf32bdf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x55bcf32bdf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x55bcf32bdf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x55bcf32bdf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x55bcf32bdf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x55bcf32bdf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x55bcf32bdf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x55bcf32bdf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x55bcf32bdf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x55bcf5552f7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x55bcf227fb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x55bcf228abe4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x55bcf2036c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x55bcf2036c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x55bcf2037738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x55bcf2036874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x55bcf2036874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x55bcf2036874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x55bcf6940abd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x55bcf6949928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x55bcf6931699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x55bcf695c112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7f81d3f6b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x55bcf0256b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-db96f0b549d48176795605b84bec34e720a5f898 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6592 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1105020227 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x5645a1a0e810, 0x5645a1bf801c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x5645a1bf8020,0x5645a3a900e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/db96f0b549d48176795605b84bec34e720a5f898' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8626 processed earlier; will process 2403 files now Step #5: #1 pulse cov: 3967 ft: 3968 exec/s: 0 rss: 180Mb Step #5: ==237418== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: #0 0x5645985039c1 in __sanitizer_print_stack_trace (out/libfuzzer-coverage-x86_64/paged+0x39239c1) Step #5: #1 0x56459eb68898 in fuzzer::PrintStackTrace() /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerUtil.cpp:210:5 Step #5: #2 0x56459eb4b5dd in fuzzer::Fuzzer::HandleMalloc(unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:131:3 Step #5: #3 0x56459eb4b4fb in fuzzer::MallocHook(void const volatile*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:100:6 Step #5: #4 0x564598509d42 in __sanitizer::RunMallocHooks(void*, unsigned long) (out/libfuzzer-coverage-x86_64/paged+0x3929d42) Step #5: #5 0x56459846ab1b in __asan::Allocator::AllocateImpl(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*, __asan::AllocType, bool, bool) (out/libfuzzer-coverage-x86_64/paged+0x388ab1b) Step #5: #6 0x564598465355 in __asan::asan_calloc(unsigned long, unsigned long, __sanitizer::BufferedStackTrace*) (out/libfuzzer-coverage-x86_64/paged+0x3885355) Step #5: #7 0x5645984fbc85 in calloc (out/libfuzzer-coverage-x86_64/paged+0x391bc85) Step #5: #8 0x56459b4caf10 in alloc::alloc::alloc_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:296:9 Step #5: #9 0x56459b4caf10 in <alloc::alloc::Global>::alloc_impl_runtime /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:308:43 Step #5: #10 0x56459b4caf10 in <alloc::alloc::Global>::alloc_impl /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:430:9 Step #5: #11 0x56459b4caf10 in <alloc::alloc::Global as core::alloc::Allocator>::allocate_zeroed /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/alloc.rs:554:14 Step #5: #12 0x56459b4caf10 in <alloc::raw_vec::RawVecInner>::try_allocate_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:479:40 Step #5: #13 0x56459b4caf10 in <alloc::raw_vec::RawVecInner>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:602:15 Step #5: #14 0x56459b4caf10 in <alloc::raw_vec::RawVec<u8>>::with_capacity_zeroed_in /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/raw_vec/mod.rs:223:20 Step #5: #15 0x56459b4caf10 in <u8 as alloc::vec::spec_from_elem::SpecFromElem>::from_elem::<alloc::alloc::Global> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/spec_from_elem.rs:52:31 Step #5: #16 0x56459b4caf10 in alloc::vec::from_elem::<u8> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/alloc/src/vec/mod.rs:3816:5 Step #5: #17 0x56459b4caf10 in <tiny_skia::pixmap::Pixmap>::new /rust/registry/src/index.crates.io-1949cf8c6b5b557f/tiny-skia-0.12.0/src/pixmap.rs:51:19 Step #5: #18 0x56459d75ff7a in typst_render::render /src/typst/crates/typst-render/src/lib.rs:36:22 Step #5: #19 0x56459a48cb78 in paged::_::__libfuzzer_sys_run /src/typst/tests/fuzz/src/bin/paged.rs:17:34 Step #5: #20 0x56459a497be4 in rust_fuzzer_test_input /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:359:60 Step #5: #21 0x56459a243c6c in libfuzzer_sys::test_input_wrap::{closure#0} /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:62:9 Step #5: #22 0x56459a243c6c in std::panicking::catch_unwind::do_call::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:573:43 Step #5: #23 0x56459a244738 in __rust_try libfuzzer_sys.af681647e854c068-cgu.0 Step #5: #24 0x56459a243874 in std::panicking::catch_unwind::<i32, libfuzzer_sys::test_input_wrap::{closure#0}> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panicking.rs:541:19 Step #5: #25 0x56459a243874 in std::panic::catch_unwind::<libfuzzer_sys::test_input_wrap::{closure#0}, i32> /rustc/574ff7d98bd6d037e5236a8453029173b32631fd/library/std/src/panic.rs:359:14 Step #5: #26 0x56459a243874 in LLVMFuzzerTestOneInput /rust/registry/src/index.crates.io-1949cf8c6b5b557f/libfuzzer-sys-0.4.9/src/lib.rs:60:22 Step #5: #27 0x56459eb4dabd in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #28 0x56459eb56928 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string<char, std::__Fuzzer::char_traits<char>, std::__Fuzzer::allocator<char>> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #29 0x56459eb3e699 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #30 0x56459eb69112 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #31 0x7fe60ee9b082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: #32 0x564598463b2d in _start (out/libfuzzer-coverage-x86_64/paged+0x3883b2d) Step #5: Step #5: DEDUP_TOKEN: __sanitizer_print_stack_trace--fuzzer::PrintStackTrace()--fuzzer::Fuzzer::HandleMalloc(unsigned long) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./oom-08c77d90426765bff2a85f7e3ed41fcc87922435 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6593 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 1105652931 Step #5: INFO: Loaded 1 modules (2005004 inline 8-bit counters): 2005004 [0x55d213402810, 0x55d2135ec01c), Step #5: INFO: Loaded 1 PC tables (2005004 PCs): 2005004 [0x55d2135ec020,0x55d2154840e0), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge55.txt' Step #5: MERGE-INNER: '/corpus/paged/08c77d90426765bff2a85f7e3ed41fcc87922435' caused a failure at the previous merge step Step #5: MERGE-INNER: 11029 total files; 8628 processed earlier; will process 2401 files now Step #5: #1 pulse cov: 3778 ft: 3779 exec/s: 0 rss: 179Mb Step #5: ==237454== ERROR: libFuzzer: out-of-memory (malloc(41568028160)) Step #5: To change the out-of-memory limit use -rss_limit_mb=<N> Step #5: Step #5: ==55== libFuzzer: run interrupted; exiting Step #5: ==237454== libFuzzer: run interrupted; exiting Step #5: du: cannot access '/workspace/out/libfuzzer-coverage-x86_64/dumps/paged.*.profraw': No such file or directory Step #5: error: /workspace/out/libfuzzer-coverage-x86_64/dumps/*.profdata: No such file or directory Step #5: ******************************************************************************** Step #5: Code coverage report generation failed. Step #5: To reproduce, run: Step #5: python infra/helper.py build_image typst Step #5: python infra/helper.py build_fuzzers --sanitizer coverage typst Step #5: python infra/helper.py coverage typst Step #5: ******************************************************************************** Finished Step #5 ERROR ERROR: build step 5 "gcr.io/oss-fuzz-base/base-runner" failed: step exited with non-zero status: 1